🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 df3b308b62e63f71f2d8e46931380fd9bfce0eec3c37300ae4833aafc7e7dfa9. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 3


Intelligence 3 IOCs YARA 2 File information Comments

SHA256 hash: df3b308b62e63f71f2d8e46931380fd9bfce0eec3c37300ae4833aafc7e7dfa9
SHA3-384 hash: 61631ddaf958ed9dfeade977c06eb904ff8693d0e4246c37c95997edb7ecb2b24052f68f4ea5b9b9e8a87865ec97beea
SHA1 hash: a17108cc5e30bf87850fc3eeb95fa59634bfdb2d
MD5 hash: a15c1b4df0dde4e7e3c9f52c9613d289
humanhash: muppet-leopard-ohio-one
File name:.bia
Download: download sample
File size:10'770 bytes
First seen:2026-10-04 07:04:23 UTC
Last seen:2026-10-04 11:43:27 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 192:gOfoMn6IonuPM/Y4KpXE2OpsOMkIE2b5fAS9M:gKOY4KNE2nO64
TLSH T1EF22467370300E317FD8066A685B680016D199AB0A5B7E58B1DC7468FF4B38CA3F9DAD
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh

Intelligence


File Origin
# of uploads :
2
# of downloads :
61
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Gathering data
Status:
terminated
Behavior Graph:
%3 guuid=264c6dbd-1c00-0000-f722-b382a50b0000 pid=2981 /usr/bin/sudo guuid=278a5ec0-1c00-0000-f722-b382aa0b0000 pid=2986 /tmp/sample.bin write-file guuid=264c6dbd-1c00-0000-f722-b382a50b0000 pid=2981->guuid=278a5ec0-1c00-0000-f722-b382aa0b0000 pid=2986 execve guuid=4013acc1-1c00-0000-f722-b382ac0b0000 pid=2988 /usr/bin/curl net send-data write-file guuid=278a5ec0-1c00-0000-f722-b382aa0b0000 pid=2986->guuid=4013acc1-1c00-0000-f722-b382ac0b0000 pid=2988 execve guuid=da7d40c3-1d00-0000-f722-b382ca0c0000 pid=3274 /usr/bin/rm delete-file guuid=278a5ec0-1c00-0000-f722-b382aa0b0000 pid=2986->guuid=da7d40c3-1d00-0000-f722-b382ca0c0000 pid=3274 execve guuid=ef2344c4-1d00-0000-f722-b382cd0c0000 pid=3277 /usr/bin/whoami guuid=278a5ec0-1c00-0000-f722-b382aa0b0000 pid=2986->guuid=ef2344c4-1d00-0000-f722-b382cd0c0000 pid=3277 execve guuid=060c16c5-1d00-0000-f722-b382cf0c0000 pid=3279 /usr/bin/date guuid=278a5ec0-1c00-0000-f722-b382aa0b0000 pid=2986->guuid=060c16c5-1d00-0000-f722-b382cf0c0000 pid=3279 execve guuid=1d7851c6-1d00-0000-f722-b382d20c0000 pid=3282 /usr/bin/bash guuid=278a5ec0-1c00-0000-f722-b382aa0b0000 pid=2986->guuid=1d7851c6-1d00-0000-f722-b382d20c0000 pid=3282 clone guuid=b97486c6-1d00-0000-f722-b382d30c0000 pid=3283 /usr/bin/mkdir guuid=278a5ec0-1c00-0000-f722-b382aa0b0000 pid=2986->guuid=b97486c6-1d00-0000-f722-b382d30c0000 pid=3283 execve guuid=524636c7-1d00-0000-f722-b382d50c0000 pid=3285 /usr/bin/id guuid=278a5ec0-1c00-0000-f722-b382aa0b0000 pid=2986->guuid=524636c7-1d00-0000-f722-b382d50c0000 pid=3285 execve guuid=63cc0ec8-1d00-0000-f722-b382d80c0000 pid=3288 /usr/bin/sleep guuid=278a5ec0-1c00-0000-f722-b382aa0b0000 pid=2986->guuid=63cc0ec8-1d00-0000-f722-b382d80c0000 pid=3288 execve guuid=33ec60e6-1d00-0000-f722-b382180d0000 pid=3352 /usr/bin/cat guuid=278a5ec0-1c00-0000-f722-b382aa0b0000 pid=2986->guuid=33ec60e6-1d00-0000-f722-b382180d0000 pid=3352 execve guuid=fc9ddfe6-1d00-0000-f722-b3821a0d0000 pid=3354 /usr/bin/uname guuid=278a5ec0-1c00-0000-f722-b382aa0b0000 pid=2986->guuid=fc9ddfe6-1d00-0000-f722-b3821a0d0000 pid=3354 execve guuid=b2714be7-1d00-0000-f722-b3821c0d0000 pid=3356 /usr/bin/wget guuid=278a5ec0-1c00-0000-f722-b382aa0b0000 pid=2986->guuid=b2714be7-1d00-0000-f722-b3821c0d0000 pid=3356 execve 95db98eb-9240-58c6-96b0-642f7e901c2e 0.0.0.4:80 guuid=4013acc1-1c00-0000-f722-b382ac0b0000 pid=2988->95db98eb-9240-58c6-96b0-642f7e901c2e con 1d928190-961a-5d8b-9877-fa3ff0ab3522 ifconfig.co:80 guuid=4013acc1-1c00-0000-f722-b382ac0b0000 pid=2988->1d928190-961a-5d8b-9877-fa3ff0ab3522 send: 75B guuid=4013acc1-1c00-0000-f722-b382ac0b0000 pid=3264 /usr/bin/curl dns net send-data guuid=4013acc1-1c00-0000-f722-b382ac0b0000 pid=2988->guuid=4013acc1-1c00-0000-f722-b382ac0b0000 pid=3264 clone guuid=4013acc1-1c00-0000-f722-b382ac0b0000 pid=3264->1d928190-961a-5d8b-9877-fa3ff0ab3522 con 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=4013acc1-1c00-0000-f722-b382ac0b0000 pid=3264->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 58B
Gathering data
Result
Malware family:
n/a
Score:
  6/10
Tags:
antivm discovery linux persistence
Behaviour
Reads runtime system information
System Network Configuration Discovery
Checks CPU configuration
Looks up external IP address via web service
Write file to user bin folder
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:dsc
Author:Aaron DeVera
Description:Discord domains
Rule name:LIN_Sample_Unique_586960df
Author:Marjoriefort
Description:Specimen unique (soumission Bazaar) - strings distinctifs propres au sample
Reference:586960df8bf559ffbba600f11917a99baed4a875cb7faa5eabc060bcde67277b.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh df3b308b62e63f71f2d8e46931380fd9bfce0eec3c37300ae4833aafc7e7dfa9

(this sample)

  
Delivery method
Distributed via web download

Comments