MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 dadc5d82ded96e1cb2a84c273ee24cb3255d92875f187ec84d6f03f3227fbae5. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: dadc5d82ded96e1cb2a84c273ee24cb3255d92875f187ec84d6f03f3227fbae5
SHA3-384 hash: e1ab48e9d6437598a60469aca6edd29a8e99cec6cc6c8df6a9e505685b7efaff871772db2e8449cba0d78e9ed21b014d
SHA1 hash: 30267887259506058ec80916eb8d7d8424dd88ae
MD5 hash: 02b4d37dffd7a21b52001d544f65a31a
humanhash: paris-gee-nineteen-spaghetti
File name:bins.sh
Download: download sample
File size:319 bytes
First seen:2026-04-26 10:48:41 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 6:hdcGr6Uc+crmTRQ5xymY2s1aFZnElYVsgeafaIg+l5blzY0W:XA6DTRQ5xyL2s1OxxVsXaCR+l5blzY0W
TLSH T13BE0C284049280085EF3563D8AE651E0D043300134307E79E1B6C3539BE82C03B72B8C
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter BlinkzSec

Intelligence


File Origin
# of uploads :
1
# of downloads :
36
Origin country :
SK SK
Vendor Threat Intelligence
No detections
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-04-03T19:37:00Z UTC
Last seen:
2026-04-27T01:36:00Z UTC
Hits:
~10
Detections:
Trojan-Downloader.Shell.Agent.bi
Status:
terminated
Behavior Graph:
%3 guuid=375074d0-1600-0000-aa03-3b3d890e0000 pid=3721 /usr/bin/sudo guuid=1a0433d2-1600-0000-aa03-3b3d920e0000 pid=3730 /tmp/sample.bin guuid=375074d0-1600-0000-aa03-3b3d890e0000 pid=3721->guuid=1a0433d2-1600-0000-aa03-3b3d920e0000 pid=3730 execve guuid=dea47ed2-1600-0000-aa03-3b3d960e0000 pid=3734 /usr/bin/wget net send-data write-file guuid=1a0433d2-1600-0000-aa03-3b3d920e0000 pid=3730->guuid=dea47ed2-1600-0000-aa03-3b3d960e0000 pid=3734 execve guuid=c520bcfc-1600-0000-aa03-3b3d3b0f0000 pid=3899 /usr/bin/chmod guuid=1a0433d2-1600-0000-aa03-3b3d920e0000 pid=3730->guuid=c520bcfc-1600-0000-aa03-3b3d3b0f0000 pid=3899 execve guuid=fa7f04fd-1600-0000-aa03-3b3d3c0f0000 pid=3900 /usr/bin/dash guuid=1a0433d2-1600-0000-aa03-3b3d920e0000 pid=3730->guuid=fa7f04fd-1600-0000-aa03-3b3d3c0f0000 pid=3900 clone guuid=0d0e9afe-1600-0000-aa03-3b3d3f0f0000 pid=3903 /usr/bin/wget net send-data write-file guuid=1a0433d2-1600-0000-aa03-3b3d920e0000 pid=3730->guuid=0d0e9afe-1600-0000-aa03-3b3d3f0f0000 pid=3903 execve guuid=5806f926-1700-0000-aa03-3b3dc70f0000 pid=4039 /usr/bin/chmod guuid=1a0433d2-1600-0000-aa03-3b3d920e0000 pid=3730->guuid=5806f926-1700-0000-aa03-3b3dc70f0000 pid=4039 execve guuid=2acb3627-1700-0000-aa03-3b3dc90f0000 pid=4041 /usr/bin/dash guuid=1a0433d2-1600-0000-aa03-3b3d920e0000 pid=3730->guuid=2acb3627-1700-0000-aa03-3b3dc90f0000 pid=4041 clone guuid=27f2af27-1700-0000-aa03-3b3dce0f0000 pid=4046 /usr/bin/wget net send-data write-file guuid=1a0433d2-1600-0000-aa03-3b3d920e0000 pid=3730->guuid=27f2af27-1700-0000-aa03-3b3dce0f0000 pid=4046 execve guuid=1ca83e51-1700-0000-aa03-3b3d86100000 pid=4230 /usr/bin/chmod guuid=1a0433d2-1600-0000-aa03-3b3d920e0000 pid=3730->guuid=1ca83e51-1700-0000-aa03-3b3d86100000 pid=4230 execve guuid=9bb18151-1700-0000-aa03-3b3d88100000 pid=4232 /usr/bin/dash guuid=1a0433d2-1600-0000-aa03-3b3d920e0000 pid=3730->guuid=9bb18151-1700-0000-aa03-3b3d88100000 pid=4232 clone guuid=49620752-1700-0000-aa03-3b3d8c100000 pid=4236 /usr/bin/wget net send-data write-file guuid=1a0433d2-1600-0000-aa03-3b3d920e0000 pid=3730->guuid=49620752-1700-0000-aa03-3b3d8c100000 pid=4236 execve guuid=6a61df7b-1700-0000-aa03-3b3d2d110000 pid=4397 /usr/bin/chmod guuid=1a0433d2-1600-0000-aa03-3b3d920e0000 pid=3730->guuid=6a61df7b-1700-0000-aa03-3b3d2d110000 pid=4397 execve guuid=a8be1b7c-1700-0000-aa03-3b3d2e110000 pid=4398 /usr/bin/dash guuid=1a0433d2-1600-0000-aa03-3b3d920e0000 pid=3730->guuid=a8be1b7c-1700-0000-aa03-3b3d2e110000 pid=4398 clone guuid=e3fab37c-1700-0000-aa03-3b3d35110000 pid=4405 /usr/bin/wget net send-data write-file guuid=1a0433d2-1600-0000-aa03-3b3d920e0000 pid=3730->guuid=e3fab37c-1700-0000-aa03-3b3d35110000 pid=4405 execve guuid=3dc51fa3-1700-0000-aa03-3b3de6110000 pid=4582 /usr/bin/chmod guuid=1a0433d2-1600-0000-aa03-3b3d920e0000 pid=3730->guuid=3dc51fa3-1700-0000-aa03-3b3de6110000 pid=4582 execve guuid=b81667a3-1700-0000-aa03-3b3dea110000 pid=4586 /usr/bin/dash guuid=1a0433d2-1600-0000-aa03-3b3d920e0000 pid=3730->guuid=b81667a3-1700-0000-aa03-3b3dea110000 pid=4586 clone guuid=6044f6a3-1700-0000-aa03-3b3def110000 pid=4591 /usr/bin/wget net send-data write-file guuid=1a0433d2-1600-0000-aa03-3b3d920e0000 pid=3730->guuid=6044f6a3-1700-0000-aa03-3b3def110000 pid=4591 execve guuid=639aa5cb-1700-0000-aa03-3b3d89120000 pid=4745 /usr/bin/chmod guuid=1a0433d2-1600-0000-aa03-3b3d920e0000 pid=3730->guuid=639aa5cb-1700-0000-aa03-3b3d89120000 pid=4745 execve guuid=943de6cb-1700-0000-aa03-3b3d8a120000 pid=4746 /home/sandbox/alyssaa net guuid=1a0433d2-1600-0000-aa03-3b3d920e0000 pid=3730->guuid=943de6cb-1700-0000-aa03-3b3d8a120000 pid=4746 execve guuid=bc5101cc-1700-0000-aa03-3b3d8c120000 pid=4748 /usr/bin/wget guuid=1a0433d2-1600-0000-aa03-3b3d920e0000 pid=3730->guuid=bc5101cc-1700-0000-aa03-3b3d8c120000 pid=4748 execve guuid=a40ae6cd-1700-0000-aa03-3b3d8d120000 pid=4749 /usr/bin/chmod guuid=1a0433d2-1600-0000-aa03-3b3d920e0000 pid=3730->guuid=a40ae6cd-1700-0000-aa03-3b3d8d120000 pid=4749 execve guuid=bd4b56ce-1700-0000-aa03-3b3d8e120000 pid=4750 /home/sandbox/alyssaa guuid=1a0433d2-1600-0000-aa03-3b3d920e0000 pid=3730->guuid=bd4b56ce-1700-0000-aa03-3b3d8e120000 pid=4750 execve guuid=2b7a71ce-1700-0000-aa03-3b3d8f120000 pid=4751 /usr/bin/wget guuid=1a0433d2-1600-0000-aa03-3b3d920e0000 pid=3730->guuid=2b7a71ce-1700-0000-aa03-3b3d8f120000 pid=4751 execve guuid=679da1cf-1700-0000-aa03-3b3d93120000 pid=4755 /usr/bin/chmod guuid=1a0433d2-1600-0000-aa03-3b3d920e0000 pid=3730->guuid=679da1cf-1700-0000-aa03-3b3d93120000 pid=4755 execve guuid=cfd20bd0-1700-0000-aa03-3b3d96120000 pid=4758 /home/sandbox/alyssaa guuid=1a0433d2-1600-0000-aa03-3b3d920e0000 pid=3730->guuid=cfd20bd0-1700-0000-aa03-3b3d96120000 pid=4758 execve guuid=4d1926d0-1700-0000-aa03-3b3d97120000 pid=4759 /usr/bin/wget guuid=1a0433d2-1600-0000-aa03-3b3d920e0000 pid=3730->guuid=4d1926d0-1700-0000-aa03-3b3d97120000 pid=4759 execve guuid=fe3340d1-1700-0000-aa03-3b3d9c120000 pid=4764 /usr/bin/chmod guuid=1a0433d2-1600-0000-aa03-3b3d920e0000 pid=3730->guuid=fe3340d1-1700-0000-aa03-3b3d9c120000 pid=4764 execve guuid=cc347fd1-1700-0000-aa03-3b3d9e120000 pid=4766 /home/sandbox/alyssaa guuid=1a0433d2-1600-0000-aa03-3b3d920e0000 pid=3730->guuid=cc347fd1-1700-0000-aa03-3b3d9e120000 pid=4766 execve guuid=cf6e97d1-1700-0000-aa03-3b3d9f120000 pid=4767 /usr/bin/wget guuid=1a0433d2-1600-0000-aa03-3b3d920e0000 pid=3730->guuid=cf6e97d1-1700-0000-aa03-3b3d9f120000 pid=4767 execve guuid=d6d46dd2-1700-0000-aa03-3b3da2120000 pid=4770 /usr/bin/chmod guuid=1a0433d2-1600-0000-aa03-3b3d920e0000 pid=3730->guuid=d6d46dd2-1700-0000-aa03-3b3da2120000 pid=4770 execve guuid=bb34b0d2-1700-0000-aa03-3b3da4120000 pid=4772 /home/sandbox/alyssaa guuid=1a0433d2-1600-0000-aa03-3b3d920e0000 pid=3730->guuid=bb34b0d2-1700-0000-aa03-3b3da4120000 pid=4772 execve guuid=0cd7c4d2-1700-0000-aa03-3b3da5120000 pid=4773 /usr/bin/wget guuid=1a0433d2-1600-0000-aa03-3b3d920e0000 pid=3730->guuid=0cd7c4d2-1700-0000-aa03-3b3da5120000 pid=4773 execve guuid=9249dbd3-1700-0000-aa03-3b3daa120000 pid=4778 /usr/bin/chmod guuid=1a0433d2-1600-0000-aa03-3b3d920e0000 pid=3730->guuid=9249dbd3-1700-0000-aa03-3b3daa120000 pid=4778 execve guuid=eb6f2bd4-1700-0000-aa03-3b3dac120000 pid=4780 /home/sandbox/alyssaa guuid=1a0433d2-1600-0000-aa03-3b3d920e0000 pid=3730->guuid=eb6f2bd4-1700-0000-aa03-3b3dac120000 pid=4780 execve guuid=99f93bd4-1700-0000-aa03-3b3dad120000 pid=4781 /usr/bin/wget guuid=1a0433d2-1600-0000-aa03-3b3d920e0000 pid=3730->guuid=99f93bd4-1700-0000-aa03-3b3dad120000 pid=4781 execve guuid=dc974bd5-1700-0000-aa03-3b3db3120000 pid=4787 /usr/bin/chmod guuid=1a0433d2-1600-0000-aa03-3b3d920e0000 pid=3730->guuid=dc974bd5-1700-0000-aa03-3b3db3120000 pid=4787 execve guuid=ae749bd5-1700-0000-aa03-3b3db5120000 pid=4789 /home/sandbox/alyssaa guuid=1a0433d2-1600-0000-aa03-3b3d920e0000 pid=3730->guuid=ae749bd5-1700-0000-aa03-3b3db5120000 pid=4789 execve a5127b7a-2d2a-5e1d-8251-011ca88bb959 156.229.165.225:80 guuid=dea47ed2-1600-0000-aa03-3b3d960e0000 pid=3734->a5127b7a-2d2a-5e1d-8251-011ca88bb959 send: 143B guuid=0d0e9afe-1600-0000-aa03-3b3d3f0f0000 pid=3903->a5127b7a-2d2a-5e1d-8251-011ca88bb959 send: 141B guuid=27f2af27-1700-0000-aa03-3b3dce0f0000 pid=4046->a5127b7a-2d2a-5e1d-8251-011ca88bb959 send: 141B guuid=49620752-1700-0000-aa03-3b3d8c100000 pid=4236->a5127b7a-2d2a-5e1d-8251-011ca88bb959 send: 141B guuid=e3fab37c-1700-0000-aa03-3b3d35110000 pid=4405->a5127b7a-2d2a-5e1d-8251-011ca88bb959 send: 140B guuid=6044f6a3-1700-0000-aa03-3b3def110000 pid=4591->a5127b7a-2d2a-5e1d-8251-011ca88bb959 send: 141B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=943de6cb-1700-0000-aa03-3b3d8a120000 pid=4746->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=f118fccb-1700-0000-aa03-3b3d8b120000 pid=4747 /home/sandbox/alyssaa dns net send-data zombie guuid=943de6cb-1700-0000-aa03-3b3d8a120000 pid=4746->guuid=f118fccb-1700-0000-aa03-3b3d8b120000 pid=4747 clone guuid=f118fccb-1700-0000-aa03-3b3d8b120000 pid=4747->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 494B 263fbaf6-0d6a-52a6-91b1-489bb72b5959 alyssaaaa.camdvr.org:3114 guuid=f118fccb-1700-0000-aa03-3b3d8b120000 pid=4747->263fbaf6-0d6a-52a6-91b1-489bb72b5959 con 6c402f36-6bd6-5d39-9b2c-0a33ceb2e239 alyssaaaa.camdvr.org:2221 guuid=f118fccb-1700-0000-aa03-3b3d8b120000 pid=4747->6c402f36-6bd6-5d39-9b2c-0a33ceb2e239 con 01f95142-f12e-5740-9ded-107755cf2fe6 alyssaaaa.camdvr.org:5418 guuid=f118fccb-1700-0000-aa03-3b3d8b120000 pid=4747->01f95142-f12e-5740-9ded-107755cf2fe6 con cb509612-fb19-5aa0-890d-34110de886b2 alyssaaaa.camdvr.org:1314 guuid=f118fccb-1700-0000-aa03-3b3d8b120000 pid=4747->cb509612-fb19-5aa0-890d-34110de886b2 con 44429916-0e14-57b9-b8d5-b4f6243fcdc9 alyssaaaa.camdvr.org:1474 guuid=f118fccb-1700-0000-aa03-3b3d8b120000 pid=4747->44429916-0e14-57b9-b8d5-b4f6243fcdc9 con f0f5a59f-a013-5e7f-8bf4-8361513e7708 alyssaaaa.camdvr.org:3314 guuid=f118fccb-1700-0000-aa03-3b3d8b120000 pid=4747->f0f5a59f-a013-5e7f-8bf4-8361513e7708 con bf168dd6-cdf7-5d0a-b452-ea2525d8fd96 alyssaaaa.camdvr.org:2411 guuid=f118fccb-1700-0000-aa03-3b3d8b120000 pid=4747->bf168dd6-cdf7-5d0a-b452-ea2525d8fd96 con e23d20e5-50c7-538c-a8b7-02dda75e094a alyssaaaa.camdvr.org:6661 guuid=f118fccb-1700-0000-aa03-3b3d8b120000 pid=4747->e23d20e5-50c7-538c-a8b7-02dda75e094a con
Threat name:
Document-HTML.Downloader.Heuristic
Status:
Malicious
First seen:
2026-03-31 23:58:43 UTC
File Type:
Text (Shell)
AV detection:
10 of 24 (41.67%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
defense_evasion discovery linux
Behaviour
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
File and Directory Permissions Modification
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh dadc5d82ded96e1cb2a84c273ee24cb3255d92875f187ec84d6f03f3227fbae5

(this sample)

  
Delivery method
Distributed via web download

Comments