MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d8053eac8cf5de22b3c331615f309228913c7118d5baa4c298227834244e8fb3. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: d8053eac8cf5de22b3c331615f309228913c7118d5baa4c298227834244e8fb3
SHA3-384 hash: 2d988ec13f721054e560a0552cd22c3f567f9cc3e5dbc5abcb39d766307d1c0d72543105fafeea795be0e53de649aa3a
SHA1 hash: 272dcab11d42e361257dfa1d7fc0f2f71d3fa5da
MD5 hash: b5d343756e50f53aac48570159d9928f
humanhash: skylark-william-sodium-nuts
File name:sh
Download: download sample
File size:265 bytes
First seen:2025-10-19 20:48:24 UTC
Last seen:2025-10-22 06:51:31 UTC
File type: sh
MIME type:text/plain
ssdeep 6:/VJ+pUKUF2RVYx8iHYf53IUy5p3FsDKVKAOXqIKa03IKq1IEE1IKBKW:/VJ+jRE8KY5WgAsONI08W
TLSH T1FAD02E1CF8030CB3B4388CB9F7DF2495DA0FA20C2B0F66CD2188021FA8F0860A060823
Magika shell
Reporter juroots
Tags:sh

Intelligence


File Origin
# of uploads :
2
# of downloads :
37
Origin country :
CH CH
Vendor Threat Intelligence
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Verdict:
Malicious
File Type:
ps1
First seen:
2025-10-19T18:53:00Z UTC
Last seen:
2025-10-21T18:33:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=63e983de-1a00-0000-ca94-2454650b0000 pid=2917 /usr/bin/sudo guuid=ae906ae0-1a00-0000-ca94-24546d0b0000 pid=2925 /tmp/sample.bin guuid=63e983de-1a00-0000-ca94-2454650b0000 pid=2917->guuid=ae906ae0-1a00-0000-ca94-24546d0b0000 pid=2925 execve guuid=3e5bb9e0-1a00-0000-ca94-24546e0b0000 pid=2926 /usr/bin/wget net send-data write-file guuid=ae906ae0-1a00-0000-ca94-24546d0b0000 pid=2925->guuid=3e5bb9e0-1a00-0000-ca94-24546e0b0000 pid=2926 execve guuid=10846ff0-1a00-0000-ca94-2454760b0000 pid=2934 /usr/bin/chmod guuid=ae906ae0-1a00-0000-ca94-24546d0b0000 pid=2925->guuid=10846ff0-1a00-0000-ca94-2454760b0000 pid=2934 execve guuid=fb377cf1-1a00-0000-ca94-2454770b0000 pid=2935 /usr/bin/dash guuid=ae906ae0-1a00-0000-ca94-24546d0b0000 pid=2925->guuid=fb377cf1-1a00-0000-ca94-2454770b0000 pid=2935 clone guuid=e6864bf2-1a00-0000-ca94-2454790b0000 pid=2937 /usr/bin/rm delete-file guuid=ae906ae0-1a00-0000-ca94-24546d0b0000 pid=2925->guuid=e6864bf2-1a00-0000-ca94-2454790b0000 pid=2937 execve guuid=1057c2f2-1a00-0000-ca94-24547b0b0000 pid=2939 /usr/bin/wget net send-data write-file guuid=ae906ae0-1a00-0000-ca94-24546d0b0000 pid=2925->guuid=1057c2f2-1a00-0000-ca94-24547b0b0000 pid=2939 execve guuid=02322c01-1b00-0000-ca94-2454920b0000 pid=2962 /usr/bin/chmod guuid=ae906ae0-1a00-0000-ca94-24546d0b0000 pid=2925->guuid=02322c01-1b00-0000-ca94-2454920b0000 pid=2962 execve guuid=c818a401-1b00-0000-ca94-2454930b0000 pid=2963 /usr/bin/dash guuid=ae906ae0-1a00-0000-ca94-24546d0b0000 pid=2925->guuid=c818a401-1b00-0000-ca94-2454930b0000 pid=2963 clone guuid=1d7c9503-1b00-0000-ca94-2454960b0000 pid=2966 /usr/bin/rm delete-file guuid=ae906ae0-1a00-0000-ca94-24546d0b0000 pid=2925->guuid=1d7c9503-1b00-0000-ca94-2454960b0000 pid=2966 execve guuid=e556ec03-1b00-0000-ca94-2454980b0000 pid=2968 /usr/bin/wget net send-data write-file guuid=ae906ae0-1a00-0000-ca94-24546d0b0000 pid=2925->guuid=e556ec03-1b00-0000-ca94-2454980b0000 pid=2968 execve guuid=47fa3a10-1b00-0000-ca94-2454b20b0000 pid=2994 /usr/bin/chmod guuid=ae906ae0-1a00-0000-ca94-24546d0b0000 pid=2925->guuid=47fa3a10-1b00-0000-ca94-2454b20b0000 pid=2994 execve guuid=47bd9d10-1b00-0000-ca94-2454b40b0000 pid=2996 /usr/bin/dash guuid=ae906ae0-1a00-0000-ca94-24546d0b0000 pid=2925->guuid=47bd9d10-1b00-0000-ca94-2454b40b0000 pid=2996 clone guuid=50af3211-1b00-0000-ca94-2454b80b0000 pid=3000 /usr/bin/rm delete-file guuid=ae906ae0-1a00-0000-ca94-24546d0b0000 pid=2925->guuid=50af3211-1b00-0000-ca94-2454b80b0000 pid=3000 execve guuid=54ca7511-1b00-0000-ca94-2454b90b0000 pid=3001 /usr/bin/wget net send-data write-file guuid=ae906ae0-1a00-0000-ca94-24546d0b0000 pid=2925->guuid=54ca7511-1b00-0000-ca94-2454b90b0000 pid=3001 execve guuid=1d894c1d-1b00-0000-ca94-2454d70b0000 pid=3031 /usr/bin/chmod guuid=ae906ae0-1a00-0000-ca94-24546d0b0000 pid=2925->guuid=1d894c1d-1b00-0000-ca94-2454d70b0000 pid=3031 execve guuid=12e08c1d-1b00-0000-ca94-2454d80b0000 pid=3032 /usr/bin/dash guuid=ae906ae0-1a00-0000-ca94-24546d0b0000 pid=2925->guuid=12e08c1d-1b00-0000-ca94-2454d80b0000 pid=3032 clone guuid=9e3d1e1e-1b00-0000-ca94-2454db0b0000 pid=3035 /usr/bin/rm delete-file guuid=ae906ae0-1a00-0000-ca94-24546d0b0000 pid=2925->guuid=9e3d1e1e-1b00-0000-ca94-2454db0b0000 pid=3035 execve guuid=a71e921e-1b00-0000-ca94-2454dc0b0000 pid=3036 /usr/bin/wget net send-data write-file guuid=ae906ae0-1a00-0000-ca94-24546d0b0000 pid=2925->guuid=a71e921e-1b00-0000-ca94-2454dc0b0000 pid=3036 execve guuid=928cff2c-1b00-0000-ca94-2454ff0b0000 pid=3071 /usr/bin/chmod guuid=ae906ae0-1a00-0000-ca94-24546d0b0000 pid=2925->guuid=928cff2c-1b00-0000-ca94-2454ff0b0000 pid=3071 execve guuid=a33d472d-1b00-0000-ca94-2454010c0000 pid=3073 /usr/bin/dash guuid=ae906ae0-1a00-0000-ca94-24546d0b0000 pid=2925->guuid=a33d472d-1b00-0000-ca94-2454010c0000 pid=3073 clone guuid=ec75212e-1b00-0000-ca94-2454060c0000 pid=3078 /usr/bin/rm delete-file guuid=ae906ae0-1a00-0000-ca94-24546d0b0000 pid=2925->guuid=ec75212e-1b00-0000-ca94-2454060c0000 pid=3078 execve guuid=2218782e-1b00-0000-ca94-2454070c0000 pid=3079 /usr/bin/wget net send-data write-file guuid=ae906ae0-1a00-0000-ca94-24546d0b0000 pid=2925->guuid=2218782e-1b00-0000-ca94-2454070c0000 pid=3079 execve guuid=4d23a13c-1b00-0000-ca94-24542f0c0000 pid=3119 /usr/bin/chmod guuid=ae906ae0-1a00-0000-ca94-24546d0b0000 pid=2925->guuid=4d23a13c-1b00-0000-ca94-24542f0c0000 pid=3119 execve guuid=4356f23c-1b00-0000-ca94-2454310c0000 pid=3121 /usr/bin/dash guuid=ae906ae0-1a00-0000-ca94-24546d0b0000 pid=2925->guuid=4356f23c-1b00-0000-ca94-2454310c0000 pid=3121 clone guuid=b914813d-1b00-0000-ca94-2454340c0000 pid=3124 /usr/bin/rm delete-file guuid=ae906ae0-1a00-0000-ca94-24546d0b0000 pid=2925->guuid=b914813d-1b00-0000-ca94-2454340c0000 pid=3124 execve guuid=4cfd273e-1b00-0000-ca94-2454360c0000 pid=3126 /usr/bin/wget net send-data write-file guuid=ae906ae0-1a00-0000-ca94-24546d0b0000 pid=2925->guuid=4cfd273e-1b00-0000-ca94-2454360c0000 pid=3126 execve guuid=e126454a-1b00-0000-ca94-2454480c0000 pid=3144 /usr/bin/chmod guuid=ae906ae0-1a00-0000-ca94-24546d0b0000 pid=2925->guuid=e126454a-1b00-0000-ca94-2454480c0000 pid=3144 execve guuid=fe1da54a-1b00-0000-ca94-24544a0c0000 pid=3146 /usr/bin/dash guuid=ae906ae0-1a00-0000-ca94-24546d0b0000 pid=2925->guuid=fe1da54a-1b00-0000-ca94-24544a0c0000 pid=3146 clone guuid=89cd434b-1b00-0000-ca94-24544e0c0000 pid=3150 /usr/bin/rm delete-file guuid=ae906ae0-1a00-0000-ca94-24546d0b0000 pid=2925->guuid=89cd434b-1b00-0000-ca94-24544e0c0000 pid=3150 execve guuid=1a3ba14b-1b00-0000-ca94-2454500c0000 pid=3152 /usr/bin/wget net send-data write-file guuid=ae906ae0-1a00-0000-ca94-24546d0b0000 pid=2925->guuid=1a3ba14b-1b00-0000-ca94-2454500c0000 pid=3152 execve guuid=bdcd1b57-1b00-0000-ca94-24546b0c0000 pid=3179 /usr/bin/chmod guuid=ae906ae0-1a00-0000-ca94-24546d0b0000 pid=2925->guuid=bdcd1b57-1b00-0000-ca94-24546b0c0000 pid=3179 execve guuid=a2bb5457-1b00-0000-ca94-24546c0c0000 pid=3180 /usr/bin/dash guuid=ae906ae0-1a00-0000-ca94-24546d0b0000 pid=2925->guuid=a2bb5457-1b00-0000-ca94-24546c0c0000 pid=3180 clone guuid=716ee357-1b00-0000-ca94-2454700c0000 pid=3184 /usr/bin/rm delete-file guuid=ae906ae0-1a00-0000-ca94-24546d0b0000 pid=2925->guuid=716ee357-1b00-0000-ca94-2454700c0000 pid=3184 execve guuid=e41e2d58-1b00-0000-ca94-2454710c0000 pid=3185 /usr/bin/wget net send-data write-file guuid=ae906ae0-1a00-0000-ca94-24546d0b0000 pid=2925->guuid=e41e2d58-1b00-0000-ca94-2454710c0000 pid=3185 execve guuid=5ee56c64-1b00-0000-ca94-2454850c0000 pid=3205 /usr/bin/chmod guuid=ae906ae0-1a00-0000-ca94-24546d0b0000 pid=2925->guuid=5ee56c64-1b00-0000-ca94-2454850c0000 pid=3205 execve guuid=3ab9bf64-1b00-0000-ca94-2454870c0000 pid=3207 /tmp/cron.kvariant guuid=ae906ae0-1a00-0000-ca94-24546d0b0000 pid=2925->guuid=3ab9bf64-1b00-0000-ca94-2454870c0000 pid=3207 execve guuid=5029de64-1b00-0000-ca94-24548b0c0000 pid=3211 /usr/bin/rm delete-file guuid=ae906ae0-1a00-0000-ca94-24546d0b0000 pid=2925->guuid=5029de64-1b00-0000-ca94-24548b0c0000 pid=3211 execve guuid=abd33865-1b00-0000-ca94-24548c0c0000 pid=3212 /usr/bin/wget net send-data write-file guuid=ae906ae0-1a00-0000-ca94-24546d0b0000 pid=2925->guuid=abd33865-1b00-0000-ca94-24548c0c0000 pid=3212 execve guuid=5c3fa671-1b00-0000-ca94-24549e0c0000 pid=3230 /usr/bin/chmod guuid=ae906ae0-1a00-0000-ca94-24546d0b0000 pid=2925->guuid=5c3fa671-1b00-0000-ca94-24549e0c0000 pid=3230 execve guuid=c2de7672-1b00-0000-ca94-24549f0c0000 pid=3231 /usr/bin/dash guuid=ae906ae0-1a00-0000-ca94-24546d0b0000 pid=2925->guuid=c2de7672-1b00-0000-ca94-24549f0c0000 pid=3231 clone guuid=4a917373-1b00-0000-ca94-2454a10c0000 pid=3233 /usr/bin/rm delete-file guuid=ae906ae0-1a00-0000-ca94-24546d0b0000 pid=2925->guuid=4a917373-1b00-0000-ca94-2454a10c0000 pid=3233 execve ce2040a6-1382-57a9-8f72-87c510446939 91.92.241.8:80 guuid=3e5bb9e0-1a00-0000-ca94-24546e0b0000 pid=2926->ce2040a6-1382-57a9-8f72-87c510446939 send: 140B guuid=1057c2f2-1a00-0000-ca94-24547b0b0000 pid=2939->ce2040a6-1382-57a9-8f72-87c510446939 send: 140B guuid=e556ec03-1b00-0000-ca94-2454980b0000 pid=2968->ce2040a6-1382-57a9-8f72-87c510446939 send: 139B guuid=54ca7511-1b00-0000-ca94-2454b90b0000 pid=3001->ce2040a6-1382-57a9-8f72-87c510446939 send: 140B guuid=a71e921e-1b00-0000-ca94-2454dc0b0000 pid=3036->ce2040a6-1382-57a9-8f72-87c510446939 send: 140B guuid=2218782e-1b00-0000-ca94-2454070c0000 pid=3079->ce2040a6-1382-57a9-8f72-87c510446939 send: 140B guuid=4cfd273e-1b00-0000-ca94-2454360c0000 pid=3126->ce2040a6-1382-57a9-8f72-87c510446939 send: 139B guuid=1a3ba14b-1b00-0000-ca94-2454500c0000 pid=3152->ce2040a6-1382-57a9-8f72-87c510446939 send: 139B guuid=e41e2d58-1b00-0000-ca94-2454710c0000 pid=3185->ce2040a6-1382-57a9-8f72-87c510446939 send: 139B guuid=ced6d164-1b00-0000-ca94-2454890c0000 pid=3209 /tmp/cron.kvariant zombie guuid=3ab9bf64-1b00-0000-ca94-2454870c0000 pid=3207->guuid=ced6d164-1b00-0000-ca94-2454890c0000 pid=3209 clone guuid=eb46dc64-1b00-0000-ca94-24548a0c0000 pid=3210 /tmp/cron.kvariant dns net send-data zombie guuid=ced6d164-1b00-0000-ca94-2454890c0000 pid=3209->guuid=eb46dc64-1b00-0000-ca94-24548a0c0000 pid=3210 clone 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=eb46dc64-1b00-0000-ca94-24548a0c0000 pid=3210->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 35B 3eea8321-7a1a-53e3-8cc5-fd3fbfba42a6 auth.binaries.lol:41323 guuid=eb46dc64-1b00-0000-ca94-24548a0c0000 pid=3210->3eea8321-7a1a-53e3-8cc5-fd3fbfba42a6 send: 11B guuid=e88f4daf-1b00-0000-ca94-2454c60c0000 pid=3270 /tmp/cron.kvariant net net-scan send-data guuid=eb46dc64-1b00-0000-ca94-24548a0c0000 pid=3210->guuid=e88f4daf-1b00-0000-ca94-2454c60c0000 pid=3270 clone guuid=aa7656af-1b00-0000-ca94-2454c70c0000 pid=3271 /tmp/cron.kvariant net net-scan send-data guuid=eb46dc64-1b00-0000-ca94-24548a0c0000 pid=3210->guuid=aa7656af-1b00-0000-ca94-2454c70c0000 pid=3271 clone 5747732c-f603-51c6-9252-e264289619bd auth.binaries.lol:80 guuid=abd33865-1b00-0000-ca94-24548c0c0000 pid=3212->5747732c-f603-51c6-9252-e264289619bd send: 139B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=e88f4daf-1b00-0000-ca94-2454c60c0000 pid=3270->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=e88f4daf-1b00-0000-ca94-2454c60c0000 pid=3270|send-data send-data to 4097 IP addresses review logs to see them all guuid=e88f4daf-1b00-0000-ca94-2454c60c0000 pid=3270->guuid=e88f4daf-1b00-0000-ca94-2454c60c0000 pid=3270|send-data send guuid=aa7656af-1b00-0000-ca94-2454c70c0000 pid=3271->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=aa7656af-1b00-0000-ca94-2454c70c0000 pid=3271|send-data send-data to 4096 IP addresses review logs to see them all guuid=aa7656af-1b00-0000-ca94-2454c70c0000 pid=3271->guuid=aa7656af-1b00-0000-ca94-2454c70c0000 pid=3271|send-data send
Threat name:
Linux.Trojan.Multiverze
Status:
Malicious
First seen:
2025-10-19 21:10:21 UTC
File Type:
Text (Shell)
AV detection:
13 of 24 (54.17%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh d8053eac8cf5de22b3c331615f309228913c7118d5baa4c298227834244e8fb3

(this sample)

  
Delivery method
Distributed via web download

Comments