🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 de64220fedde0b76bbd0bae7f6e02c30c026bc73c00cf915f9f15a45def229c7. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: de64220fedde0b76bbd0bae7f6e02c30c026bc73c00cf915f9f15a45def229c7
SHA3-384 hash: 98bb6c244ca5320e79cad138047a06a1c3ade6a647b99733b23ff7784845e1231898db071f55df03f93c99753fb34d1d
SHA1 hash: b0000d8a998fcd630edbdd7d470f5279c512a77d
MD5 hash: 15c1d2d2fe8fe173d12ea6f6f3293157
humanhash: tango-eighteen-arkansas-stream
File name:bins.sh
Download: download sample
File size:650 bytes
First seen:2026-09-19 20:11:36 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 12:8SmF3m+qNNvNMOcESkZWX4z5m3qsQFasroMPH1FHBHaOaouMX:8J36xWrESkZw4z+qs/sMM/11Zas
TLSH T1E6F0F4CB2BA360B3D68A55794B2A7144C143400A5166EA80F5AE78686F65E34F852E04
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter adliwahid
URLMalware sample (SHA256 hash)SignatureTags
http://89.106.83.171/bins/n/an/an/a

Intelligence


File Origin
# of uploads :
1
# of downloads :
58
Origin country :
NL NL
Vendor Threat Intelligence
No detections
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-09-19T18:38:00Z UTC
Last seen:
2026-09-21T14:58:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=db4cbf8d-1e00-0000-7e19-c1fcdc080000 pid=2268 /usr/bin/sudo guuid=8f4e3791-1e00-0000-7e19-c1fcdd080000 pid=2269 /tmp/sample.bin guuid=db4cbf8d-1e00-0000-7e19-c1fcdc080000 pid=2268->guuid=8f4e3791-1e00-0000-7e19-c1fcdd080000 pid=2269 execve guuid=d3710792-1e00-0000-7e19-c1fcde080000 pid=2270 /usr/bin/uname guuid=8f4e3791-1e00-0000-7e19-c1fcdd080000 pid=2269->guuid=d3710792-1e00-0000-7e19-c1fcde080000 pid=2270 execve guuid=5a928c92-1e00-0000-7e19-c1fcdf080000 pid=2271 /usr/bin/wget net send-data write-file guuid=8f4e3791-1e00-0000-7e19-c1fcdd080000 pid=2269->guuid=5a928c92-1e00-0000-7e19-c1fcdf080000 pid=2271 execve guuid=a3c27bc8-1e00-0000-7e19-c1fced080000 pid=2285 /usr/bin/chmod guuid=8f4e3791-1e00-0000-7e19-c1fcdd080000 pid=2269->guuid=a3c27bc8-1e00-0000-7e19-c1fced080000 pid=2285 execve guuid=ce5e16c9-1e00-0000-7e19-c1fcef080000 pid=2287 /tmp/rk mprotect-exec guuid=8f4e3791-1e00-0000-7e19-c1fcdd080000 pid=2269->guuid=ce5e16c9-1e00-0000-7e19-c1fcef080000 pid=2287 execve guuid=14f0b7ce-1e00-0000-7e19-c1fcf8080000 pid=2296 /usr/bin/rm delete-file guuid=8f4e3791-1e00-0000-7e19-c1fcdd080000 pid=2269->guuid=14f0b7ce-1e00-0000-7e19-c1fcf8080000 pid=2296 execve 710e5f8e-2c8f-5252-b300-4a6d62fc2bd8 89.106.83.171:80 guuid=5a928c92-1e00-0000-7e19-c1fcdf080000 pid=2271->710e5f8e-2c8f-5252-b300-4a6d62fc2bd8 send: 139B guuid=22089cce-1e00-0000-7e19-c1fcf7080000 pid=2295 /tmp/rk zombie guuid=ce5e16c9-1e00-0000-7e19-c1fcef080000 pid=2287->guuid=22089cce-1e00-0000-7e19-c1fcf7080000 pid=2295 clone guuid=a1adc5ce-1e00-0000-7e19-c1fcf9080000 pid=2297 /tmp/rk net send-data write-config write-file zombie guuid=22089cce-1e00-0000-7e19-c1fcf7080000 pid=2295->guuid=a1adc5ce-1e00-0000-7e19-c1fcf9080000 pid=2297 clone 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=a1adc5ce-1e00-0000-7e19-c1fcf9080000 pid=2297->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con 79c8db5b-41c3-5410-bac7-4db011360060 89.106.83.171:11121 guuid=a1adc5ce-1e00-0000-7e19-c1fcf9080000 pid=2297->79c8db5b-41c3-5410-bac7-4db011360060 send: 12B guuid=8e2bf4ce-1e00-0000-7e19-c1fcfa080000 pid=2298 /usr/bin/dash guuid=a1adc5ce-1e00-0000-7e19-c1fcf9080000 pid=2297->guuid=8e2bf4ce-1e00-0000-7e19-c1fcfa080000 pid=2298 execve guuid=edff15d2-1e00-0000-7e19-c1fc01090000 pid=2305 /usr/bin/dash guuid=a1adc5ce-1e00-0000-7e19-c1fcf9080000 pid=2297->guuid=edff15d2-1e00-0000-7e19-c1fc01090000 pid=2305 execve guuid=6062fed2-1e00-0000-7e19-c1fc05090000 pid=2309 /usr/bin/dash guuid=a1adc5ce-1e00-0000-7e19-c1fcf9080000 pid=2297->guuid=6062fed2-1e00-0000-7e19-c1fc05090000 pid=2309 execve guuid=dc38c39d-1f00-0000-7e19-c1fc340a0000 pid=2612 /usr/bin/dash write-config guuid=a1adc5ce-1e00-0000-7e19-c1fcf9080000 pid=2297->guuid=dc38c39d-1f00-0000-7e19-c1fc340a0000 pid=2612 execve guuid=e265229e-1f00-0000-7e19-c1fc350a0000 pid=2613 /usr/bin/dash write-file guuid=a1adc5ce-1e00-0000-7e19-c1fcf9080000 pid=2297->guuid=e265229e-1f00-0000-7e19-c1fc350a0000 pid=2613 execve guuid=ae3cd69f-1f00-0000-7e19-c1fc390a0000 pid=2617 /tmp/rk guuid=a1adc5ce-1e00-0000-7e19-c1fcf9080000 pid=2297->guuid=ae3cd69f-1f00-0000-7e19-c1fc390a0000 pid=2617 clone guuid=6e6467cf-1e00-0000-7e19-c1fcfc080000 pid=2300 /usr/bin/dash guuid=8e2bf4ce-1e00-0000-7e19-c1fcfa080000 pid=2298->guuid=6e6467cf-1e00-0000-7e19-c1fcfc080000 pid=2300 clone guuid=6d5a74cf-1e00-0000-7e19-c1fcfd080000 pid=2301 /usr/bin/dash guuid=8e2bf4ce-1e00-0000-7e19-c1fcfa080000 pid=2298->guuid=6d5a74cf-1e00-0000-7e19-c1fcfd080000 pid=2301 clone guuid=eef35cd2-1e00-0000-7e19-c1fc02090000 pid=2306 /usr/bin/mkdir guuid=edff15d2-1e00-0000-7e19-c1fc01090000 pid=2305->guuid=eef35cd2-1e00-0000-7e19-c1fc02090000 pid=2306 execve guuid=75504fd3-1e00-0000-7e19-c1fc06090000 pid=2310 /usr/bin/systemctl guuid=6062fed2-1e00-0000-7e19-c1fc05090000 pid=2309->guuid=75504fd3-1e00-0000-7e19-c1fc06090000 pid=2310 execve guuid=bfe9d54f-1f00-0000-7e19-c1fcc0090000 pid=2496 /usr/bin/systemctl guuid=6062fed2-1e00-0000-7e19-c1fc05090000 pid=2309->guuid=bfe9d54f-1f00-0000-7e19-c1fcc0090000 pid=2496 execve
Threat name:
Win32.Trojan.Generic
Status:
Suspicious
First seen:
2026-09-19 20:12:21 UTC
File Type:
Text (Shell)
AV detection:
8 of 24 (33.33%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
defense_evasion discovery execution linux persistence privilege_escalation upx
Behaviour
Enumerates kernel/hardware configuration
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Modifies Bash startup script
UPX packed file
Creates/modifies Cron job
Creates/modifies environment variables
Modifies rc script
Modifies systemd
File and Directory Permissions Modification
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments