MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 dd0837bac538904c628bbdc0279da235e3c905f14b96acbfa5c07d244fbe3519. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: dd0837bac538904c628bbdc0279da235e3c905f14b96acbfa5c07d244fbe3519
SHA3-384 hash: 41bceef40469a82fd4240504bc8e54f2a67e1dc3ad6a67752b081565a3fc6ab0235528406a534fd20e2b78510fac87db
SHA1 hash: e35bf41e35126eb418951388826902921d96620c
MD5 hash: 28f238ec4152dcff36651f144f0b95a1
humanhash: lima-river-bacon-triple
File name:bins.sh
Download: download sample
File size:703 bytes
First seen:2026-01-29 20:18:50 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 12:ftYz7HTe092n2Py9kHfu/sAZaQu6fIqwjQ8Kw8rFy9qy/W:fMTe09HPyYG0AoQmq4Q8KwIye
TLSH T108017BB66601023A7C52449FD8E2C95874476233D880345478ECB586EFEAA2D7631F7D
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
33
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-01-29T17:25:00Z UTC
Last seen:
2026-01-30T12:53:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.p HEUR:Trojan-Downloader.Shell.Agent.gen
Status:
terminated
Behavior Graph:
%3 guuid=3863c066-1900-0000-067e-7c7709070000 pid=1801 /usr/bin/sudo guuid=f8734a69-1900-0000-067e-7c770e070000 pid=1806 /tmp/sample.bin guuid=3863c066-1900-0000-067e-7c7709070000 pid=1801->guuid=f8734a69-1900-0000-067e-7c770e070000 pid=1806 execve guuid=5a46a269-1900-0000-067e-7c770f070000 pid=1807 /usr/bin/rm guuid=f8734a69-1900-0000-067e-7c770e070000 pid=1806->guuid=5a46a269-1900-0000-067e-7c770f070000 pid=1807 execve guuid=e2b2106a-1900-0000-067e-7c7711070000 pid=1809 /usr/bin/wget net send-data write-file guuid=f8734a69-1900-0000-067e-7c770e070000 pid=1806->guuid=e2b2106a-1900-0000-067e-7c7711070000 pid=1809 execve guuid=ce8e9084-1900-0000-067e-7c7741070000 pid=1857 /usr/bin/chmod guuid=f8734a69-1900-0000-067e-7c770e070000 pid=1806->guuid=ce8e9084-1900-0000-067e-7c7741070000 pid=1857 execve guuid=b53ef384-1900-0000-067e-7c7742070000 pid=1858 /tmp/x.x86 net guuid=f8734a69-1900-0000-067e-7c770e070000 pid=1806->guuid=b53ef384-1900-0000-067e-7c7742070000 pid=1858 execve 1249eeca-2c45-5c5b-b198-11143da92011 178.16.54.242:80 guuid=e2b2106a-1900-0000-067e-7c7711070000 pid=1809->1249eeca-2c45-5c5b-b198-11143da92011 send: 138B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=b53ef384-1900-0000-067e-7c7742070000 pid=1858->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con aa5ae284-310f-5120-93c5-c763a8650dfa 178.16.54.242:2323 guuid=b53ef384-1900-0000-067e-7c7742070000 pid=1858->aa5ae284-310f-5120-93c5-c763a8650dfa con guuid=a434f3c0-1900-0000-067e-7c77c6070000 pid=1990 /tmp/x.x86 net guuid=b53ef384-1900-0000-067e-7c7742070000 pid=1858->guuid=a434f3c0-1900-0000-067e-7c77c6070000 pid=1990 clone guuid=681be4eb-1a00-0000-067e-7c77fe090000 pid=2558 /tmp/x.x86 guuid=b53ef384-1900-0000-067e-7c7742070000 pid=1858->guuid=681be4eb-1a00-0000-067e-7c77fe090000 pid=2558 clone guuid=0b3feceb-1a00-0000-067e-7c77ff090000 pid=2559 /tmp/x.x86 net guuid=b53ef384-1900-0000-067e-7c7742070000 pid=1858->guuid=0b3feceb-1a00-0000-067e-7c77ff090000 pid=2559 clone guuid=a434f3c0-1900-0000-067e-7c77c6070000 pid=1990->aa5ae284-310f-5120-93c5-c763a8650dfa con guuid=09f11bc1-1900-0000-067e-7c77c7070000 pid=1991 /tmp/x.x86 guuid=a434f3c0-1900-0000-067e-7c77c6070000 pid=1990->guuid=09f11bc1-1900-0000-067e-7c77c7070000 pid=1991 clone guuid=a86e37c1-1900-0000-067e-7c77c8070000 pid=1992 /tmp/x.x86 net guuid=a434f3c0-1900-0000-067e-7c77c6070000 pid=1990->guuid=a86e37c1-1900-0000-067e-7c77c8070000 pid=1992 clone guuid=a86e37c1-1900-0000-067e-7c77c8070000 pid=1992->aa5ae284-310f-5120-93c5-c763a8650dfa con guuid=0b3feceb-1a00-0000-067e-7c77ff090000 pid=2559->aa5ae284-310f-5120-93c5-c763a8650dfa con
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Linux.Trojan.SAgnt
Status:
Malicious
First seen:
2026-01-29 20:19:59 UTC
File Type:
Text (Shell)
AV detection:
8 of 24 (33.33%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
defense_evasion discovery linux
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Enumerates running processes
Writes file to system bin folder
File and Directory Permissions Modification
Executes dropped EXE
Modifies Watchdog functionality
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh dd0837bac538904c628bbdc0279da235e3c905f14b96acbfa5c07d244fbe3519

(this sample)

  
Delivery method
Distributed via web download

Comments