🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d420221d5506609ea8072adb71ca7dbd41b3bf5631dbbca9d651cb0fa8cf25c4. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 3


Intelligence 3 IOCs YARA 1 File information Comments

SHA256 hash: d420221d5506609ea8072adb71ca7dbd41b3bf5631dbbca9d651cb0fa8cf25c4
SHA3-384 hash: d0dd859c27d3ec12edace4a805d9a164b4ff93f5c2710c0973607df002d107d097053e7c38926135ddb03588a8c3dde3
SHA1 hash: b50fe4c4ea25698fdfe7911aff6db96610f36120
MD5 hash: 77cafe9ad88d83bf9927cdfc8ef038f6
humanhash: iowa-charlie-two-sierra
File name:rev.sh
Download: download sample
File size:1'179 bytes
First seen:2026-10-10 06:23:20 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 24:w1NLde/UJUXr+SrNvNSL5lOK70TGz5lOK70TGP:wTZbaX6SuOK70TGGK70TGP
TLSH T11121ACB1E2F16D757F3084A86206D13037EA3B864FDC5CE2887C5AE17723554E190F61
TrID 50.0% (.SH) Linux/UNIX shell script (7000/1)
28.5% (.PL) Perl script (4000/1/1)
21.4% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
71
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Unknown
Threat level:
  2.5/10
Confidence:
100%
Tags:
bash evasive lolbin
Status:
terminated
Behavior Graph:
%3 guuid=d1829666-1f00-0000-b082-a7f67d080000 pid=2173 /usr/bin/sudo guuid=d3198e6d-1f00-0000-b082-a7f680080000 pid=2176 /tmp/sample.bin guuid=d1829666-1f00-0000-b082-a7f67d080000 pid=2173->guuid=d3198e6d-1f00-0000-b082-a7f680080000 pid=2176 execve guuid=a640bc6e-1f00-0000-b082-a7f681080000 pid=2177 /usr/bin/bash net guuid=d3198e6d-1f00-0000-b082-a7f680080000 pid=2176->guuid=a640bc6e-1f00-0000-b082-a7f681080000 pid=2177 clone guuid=239a0c70-1f00-0000-b082-a7f684080000 pid=2180 /usr/bin/bash net guuid=d3198e6d-1f00-0000-b082-a7f680080000 pid=2176->guuid=239a0c70-1f00-0000-b082-a7f684080000 pid=2180 clone guuid=1357c570-1f00-0000-b082-a7f685080000 pid=2181 /usr/bin/perl net guuid=d3198e6d-1f00-0000-b082-a7f680080000 pid=2176->guuid=1357c570-1f00-0000-b082-a7f685080000 pid=2181 execve guuid=5edaa27e-1f00-0000-b082-a7f68a080000 pid=2186 /usr/bin/python3.11 net guuid=d3198e6d-1f00-0000-b082-a7f680080000 pid=2176->guuid=5edaa27e-1f00-0000-b082-a7f68a080000 pid=2186 execve e70942b6-9eb9-5e8f-81a2-3fa671f03d61 159.89.25.196:5656 guuid=a640bc6e-1f00-0000-b082-a7f681080000 pid=2177->e70942b6-9eb9-5e8f-81a2-3fa671f03d61 con guuid=239a0c70-1f00-0000-b082-a7f684080000 pid=2180->e70942b6-9eb9-5e8f-81a2-3fa671f03d61 con guuid=1357c570-1f00-0000-b082-a7f685080000 pid=2181->e70942b6-9eb9-5e8f-81a2-3fa671f03d61 con guuid=5edaa27e-1f00-0000-b082-a7f68a080000 pid=2186->e70942b6-9eb9-5e8f-81a2-3fa671f03d61 con
Threat name:
Script-Python.Trojan.ReverseShell
Status:
Malicious
First seen:
2026-10-10 06:24:15 UTC
File Type:
Text (Shell)
AV detection:
6 of 36 (16.67%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
discovery linux
Behaviour
Reads runtime system information
Writes file to tmp directory
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:SUSP_shellpop_Bash
Author:Tobias Michalski
Description:Detects susupicious bash command
Reference:https://github.com/0x00-0x00/ShellPop

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh d420221d5506609ea8072adb71ca7dbd41b3bf5631dbbca9d651cb0fa8cf25c4

(this sample)

  
Delivery method
Distributed via web download

Comments