MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d254df8e3edee032aaa3e40e845fa351154a031d3fe1fe68cf36d02bab71d51e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: d254df8e3edee032aaa3e40e845fa351154a031d3fe1fe68cf36d02bab71d51e
SHA3-384 hash: eaaecd716cbcf42ffc5444371c700b015d5727bf349e57a6d8148bb6258bd359170db55ac6bc1bbbc22eef9eba6a86e5
SHA1 hash: 8d17470b1e66d9f02a6a1846ab5f8b7757f102b3
MD5 hash: ae0777bcb35ab8267b4f374530bd2559
humanhash: uncle-skylark-arkansas-beer
File name:x
Download: download sample
File size:356 bytes
First seen:2026-06-20 15:03:34 UTC
Last seen:2026-06-21 06:55:55 UTC
File type: sh
MIME type:text/plain
ssdeep 6:ebgy3yj3w5/KjoWXAsjbFPAjnQtDWQiTa9jwrObhgkhxn:myjWKrvRVDWTWldgWxn
TLSH T102E0D8D790D99834308B8EFA7F2EC82019C2EA420A411D0858C619F3904CDD83167F71
Magika batch
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://91.92.42.203/nvmsUpdate856d0ba434b020bb3b3f94f4e1bedca8a04c96c48a3aac7f9e1c51f416af8e05 Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
369
# of downloads :
4
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
File Type:
text
First seen:
2026-06-20T12:34:00Z UTC
Last seen:
2026-06-20T12:43:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=e4a0bfae-1a00-0000-ac3a-e1db1b0a0000 pid=2587 /usr/bin/sudo guuid=75d76db1-1a00-0000-ac3a-e1db220a0000 pid=2594 /tmp/sample.bin guuid=e4a0bfae-1a00-0000-ac3a-e1db1b0a0000 pid=2587->guuid=75d76db1-1a00-0000-ac3a-e1db220a0000 pid=2594 execve guuid=7f9ef2b1-1a00-0000-ac3a-e1db230a0000 pid=2595 /usr/bin/dash guuid=75d76db1-1a00-0000-ac3a-e1db220a0000 pid=2594->guuid=7f9ef2b1-1a00-0000-ac3a-e1db230a0000 pid=2595 clone guuid=948891b7-1a00-0000-ac3a-e1db330a0000 pid=2611 /usr/bin/chmod guuid=75d76db1-1a00-0000-ac3a-e1db220a0000 pid=2594->guuid=948891b7-1a00-0000-ac3a-e1db330a0000 pid=2611 execve guuid=71bb39b8-1a00-0000-ac3a-e1db350a0000 pid=2613 /usr/bin/dash guuid=75d76db1-1a00-0000-ac3a-e1db220a0000 pid=2594->guuid=71bb39b8-1a00-0000-ac3a-e1db350a0000 pid=2613 clone guuid=8d25cfb8-1a00-0000-ac3a-e1db390a0000 pid=2617 /usr/bin/mount guuid=75d76db1-1a00-0000-ac3a-e1db220a0000 pid=2594->guuid=8d25cfb8-1a00-0000-ac3a-e1db390a0000 pid=2617 execve guuid=778a03ba-1a00-0000-ac3a-e1db3d0a0000 pid=2621 /usr/bin/mount guuid=75d76db1-1a00-0000-ac3a-e1db220a0000 pid=2594->guuid=778a03ba-1a00-0000-ac3a-e1db3d0a0000 pid=2621 execve guuid=2f9004b2-1a00-0000-ac3a-e1db240a0000 pid=2596 /usr/bin/wget net send-data write-file guuid=7f9ef2b1-1a00-0000-ac3a-e1db230a0000 pid=2595->guuid=2f9004b2-1a00-0000-ac3a-e1db240a0000 pid=2596 execve 05fe6c94-f1f3-543e-9353-a857481e99ba 91.92.42.203:80 guuid=2f9004b2-1a00-0000-ac3a-e1db240a0000 pid=2596->05fe6c94-f1f3-543e-9353-a857481e99ba send: 137B
Gathering data
Threat name:
Script-BAT.Downloader.Heuristic
Status:
Malicious
First seen:
2026-06-20 18:10:03 UTC
File Type:
Text (Shell)
AV detection:
5 of 24 (20.83%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh d254df8e3edee032aaa3e40e845fa351154a031d3fe1fe68cf36d02bab71d51e

(this sample)

  
Delivery method
Distributed via web download

Comments