MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 dcbf7b7f32b4f9b326b3bf7c8f2548f642b294b8dbe01e02154d8fcc27b7da84. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Threat unknown
Vendor detections: 3
| SHA256 hash: | dcbf7b7f32b4f9b326b3bf7c8f2548f642b294b8dbe01e02154d8fcc27b7da84 |
|---|---|
| SHA3-384 hash: | 081546211aaf5985080a619ad3f81be1bafc17fa466fdcdd52f6a45ddc10d1ae4094b7d6f10b621b6fc85167bfce44c3 |
| SHA1 hash: | 24f8285af55de781dc9ad661e1868727b59162b3 |
| MD5 hash: | 79978a6ee9076a50bb55b52ffde5ffd1 |
| humanhash: | papa-fanta-xray-stream |
| File name: | shai.quarantine.bin |
| Download: | download sample |
| File size: | 94'677'120 bytes |
| First seen: | 2026-08-11 02:18:46 UTC |
| Last seen: | Never |
| File type: | elf |
| MIME type: | application/x-executable |
| ssdeep | 393216:RHSegzG1n6veww3d1zmjVhXxOVB1siXUxpWJ9IWlY3IDUl2nogg9WbkxyBtS//Jn:R3z0lxO+xCPE0PYnKgXUvoKerkVJbe |
| TLSH | T197288D12A2E29444F5B781706BEA83639632FC7A5B3164DB32885B362F33DD05776723 |
| telfhash | t1e0328361bb38c6cb46803836586a3b455087a33f9e207a55dfd0f9d84d794cdf42ae8e |
| TrID | 50.1% (.) ELF Executable and Linkable format (Linux) (4022/12) 49.8% (.O) ELF Executable and Linkable format (generic) (4000/1) |
| Magika | elf |
| Reporter | |
| Tags: | aws bun credential-harvester elf kubernetes Shai-Hulud stealer vault |
bitbison
Bun-compiled standalone port of the Shai-Hulud credential harvester, built as a native Linux x64 executable rather than an npm package. Self-identifying: bunfs root /$bunfs/root/shai-hulud-linux-x64, bundled module paths under ../Shai-Hulud-Standalone/src/, runtime banner '=== Shai-Hulud Standalone Discovery Mode ==='. The npm campaign's markers survive in cleartext because the scramble() helper is stubbed to identity: SEARCH_STRING 'IfYouRevokeThisTokenItWillWipeTheComputerOfTheOwner', PACKAGE_NAME 'github:opensearch-project/opensearch-js#d446803f4c3bc116263faa3499a1d3f95b2825de', plus the worm's embedded npm target-package list. Capability: local filesystem and shell harvest, then AWS (SSM Parameter Store, Secrets Manager, STS, IMDS 169.254.169.254, ECS credentials 169.254.170.2, SigV4-signed), GitHub (validates discovered tokens against api.github.com/user, then recursively enumerates Actions, repos, secrets, workflows and self-hosted runners), Kubernetes (KUBECONFIG and in-cluster service account) and HashiCorp Vault. Note this build prints results to stdout and performs no exfiltration of its own.Intelligence
File Origin
USVendor Threat Intelligence
Result
Result
Behaviour
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Web download
elf dcbf7b7f32b4f9b326b3bf7c8f2548f642b294b8dbe01e02154d8fcc27b7da84
(this sample)
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.https://bitbison.io/blog/shai-hulud-standalone/ has deeper analysis