MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 c8ae8d6d048de8ec039fae5d639c6f2c1912bf5971c1528ea9fdf07e4029093d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Threat unknown
Vendor detections: 4
| SHA256 hash: | c8ae8d6d048de8ec039fae5d639c6f2c1912bf5971c1528ea9fdf07e4029093d |
|---|---|
| SHA3-384 hash: | 2b295ed8be776a6dc29d1169ba8d359a62df0db6e4604240e922fd5d1e24b5d5865cf049eea58abe230380c219bfc419 |
| SHA1 hash: | 9e64c83419786a0456e565da03c891120c08ac7d |
| MD5 hash: | e8d7e136c3c660867e9a8b90e0972c3e |
| humanhash: | asparagus-stairway-maine-may |
| File name: | install_panel.sh |
| Download: | download sample |
| File size: | 94'170 bytes |
| First seen: | 2026-08-25 08:18:00 UTC |
| Last seen: | Never |
| File type: | sh |
| MIME type: | text/x-shellscript |
| ssdeep | 1536:Ttupz3qoD2DjYqhgLpevVnosI9fsQyeSxXeil3hLh8xLjfhQH7hrUh2+GS+khWzb:wpz3mILmVnosI9fsQyeSxXeil3hLh8xQ |
| TLSH | T187930796EF08C9F43850C27D5B414A4DFA0EA2D701197864B0DEB8A43F9CB73B97E616 |
| TrID | 50.0% (.SH) Linux/UNIX shell script (7000/1) 28.5% (.PL) Perl script (4000/1/1) 21.4% (.) Unix-like shebang (var.3) (gen) (3000/1) |
| Magika | shell |
| Reporter | |
| Tags: | sh |
Shell script dropper
This file seems to be a shell script dropper, using wget, ftpget and/or curl. More information about the corresponding payload URLs are shown below.
| URL | Malware sample (SHA256 hash) | Signature | Tags |
|---|---|---|---|
| https://www.bt.cn/api/wpanel/SetupCount | n/a | n/a | n/a |
| https://api.bt.cn/api/isCN | n/a | n/a | n/a |
| https://mirrors.aliyun.com/repo/Centos-vault-8.5.2111.repo | n/a | n/a | n/a |
| https://mirrors.aliyun.com/repo/epel-archive-8.repo | n/a | n/a | n/a |
| http://download.bt.cn/install/yumRepo_select.sh | n/a | n/a | n/a |
| https://www.bt.cn/api/index/get_time | n/a | n/a | n/a |
| https://download.bt.cn/install/plugin/oneav/install.sh | n/a | n/a | n/a |
| https://www.bt.cn/Api/getIpAddress | n/a | n/a | n/a |
| https://api.bt.cn/Api/getIpAddress | n/a | n/a | n/a |
| https://www.aapanel.com/api/common/getClientIP | n/a | n/a | n/a |
| https://www.bt.cn/Api/SetupCount | n/a | n/a | n/a |
| https://www.bt.cn/Api/SetupCountPre | n/a | n/a | n/a |
| https://www.bt.cn/Api/installationCount | n/a | n/a | n/a |
| https://www-node3.bt.cn/Api/installationCount | n/a | n/a | n/a |
Intelligence
File Origin
# of uploads :
1
# of downloads :
36
Origin country :
DEVendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
10/10
Confidence:
100%
Tags:
bash lolbin opendir
Verdict:
Unknown
File Type:
unix shell
Status:
terminated
Behavior Graph:
Score:
5%
Verdict:
Benign
File Type:
SCRIPT
Threat name:
Script-BAT.Dropper.Heuristic
Status:
Malicious
First seen:
2026-08-25 08:19:20 UTC
File Type:
Text (Shell)
AV detection:
8 of 24 (33.33%)
Threat level:
2/5
Detection(s):
Suspicious file
Result
Malware family:
n/a
Score:
4/10
Tags:
antivm discovery linux
Behaviour
Reads runtime system information
Writes file to tmp directory
Checks CPU configuration
Reads CPU attributes
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Suspicious File
Score:
0.34
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Web download
sh c8ae8d6d048de8ec039fae5d639c6f2c1912bf5971c1528ea9fdf07e4029093d
(this sample)
Delivery method
Distributed via web download
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.