MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e3df07460477dc19617e3e815fbd3c8493dce75d447a49eb3bc04d09cc79eb70. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: e3df07460477dc19617e3e815fbd3c8493dce75d447a49eb3bc04d09cc79eb70
SHA3-384 hash: aeee85d001adbe1cbfd1b66874c7247542af1d71e8d7ed02bb5cf696510a4a5c0663e56119999244803e7f2cbc087634
SHA1 hash: 0fbaacc233392313e3117f155383b5c47dc20643
MD5 hash: dfe6c6d8620413f75a914a2d82a825a1
humanhash: snake-wyoming-jersey-monkey
File name:bins.sh
Download: download sample
File size:1'605 bytes
First seen:2025-11-22 22:30:48 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 24:lYq8ogBc4obxCNIdBPGYVfdxbpXssoKxpamafNaoPv:lZ8og64obxdBOYtdxbpXsso6wrfEoX
TLSH T16731A1C471725AB68AE0FEB7B0A9B58CBBE540CF2907EEAE78C025ED405DD0469003E1
Magika batch
Reporter abuse_ch
Tags:sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
27
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
evasive
Result
Gathering data
Status:
terminated
Behavior Graph:
%3 guuid=5d1d80f6-1900-0000-1ba9-dd2eba090000 pid=2490 /usr/bin/sudo guuid=972facf9-1900-0000-1ba9-dd2ec1090000 pid=2497 /tmp/sample.bin guuid=5d1d80f6-1900-0000-1ba9-dd2eba090000 pid=2490->guuid=972facf9-1900-0000-1ba9-dd2ec1090000 pid=2497 execve guuid=2a570ffa-1900-0000-1ba9-dd2ec3090000 pid=2499 /usr/bin/dash guuid=972facf9-1900-0000-1ba9-dd2ec1090000 pid=2497->guuid=2a570ffa-1900-0000-1ba9-dd2ec3090000 pid=2499 clone guuid=872525fa-1900-0000-1ba9-dd2ec4090000 pid=2500 /usr/bin/chmod guuid=972facf9-1900-0000-1ba9-dd2ec1090000 pid=2497->guuid=872525fa-1900-0000-1ba9-dd2ec4090000 pid=2500 execve guuid=ff7872fa-1900-0000-1ba9-dd2ec6090000 pid=2502 /usr/bin/dash guuid=972facf9-1900-0000-1ba9-dd2ec1090000 pid=2497->guuid=ff7872fa-1900-0000-1ba9-dd2ec6090000 pid=2502 clone guuid=ca0e7efa-1900-0000-1ba9-dd2ec7090000 pid=2503 /usr/bin/rm guuid=972facf9-1900-0000-1ba9-dd2ec1090000 pid=2497->guuid=ca0e7efa-1900-0000-1ba9-dd2ec7090000 pid=2503 execve guuid=737623fb-1900-0000-1ba9-dd2eca090000 pid=2506 /usr/bin/dash guuid=972facf9-1900-0000-1ba9-dd2ec1090000 pid=2497->guuid=737623fb-1900-0000-1ba9-dd2eca090000 pid=2506 clone guuid=5f3239fb-1900-0000-1ba9-dd2ecb090000 pid=2507 /usr/bin/chmod guuid=972facf9-1900-0000-1ba9-dd2ec1090000 pid=2497->guuid=5f3239fb-1900-0000-1ba9-dd2ecb090000 pid=2507 execve guuid=592298fb-1900-0000-1ba9-dd2ecc090000 pid=2508 /usr/bin/dash guuid=972facf9-1900-0000-1ba9-dd2ec1090000 pid=2497->guuid=592298fb-1900-0000-1ba9-dd2ecc090000 pid=2508 clone guuid=9cf2aefb-1900-0000-1ba9-dd2ecd090000 pid=2509 /usr/bin/rm guuid=972facf9-1900-0000-1ba9-dd2ec1090000 pid=2497->guuid=9cf2aefb-1900-0000-1ba9-dd2ecd090000 pid=2509 execve guuid=2db0f2fb-1900-0000-1ba9-dd2ecf090000 pid=2511 /usr/bin/dash guuid=972facf9-1900-0000-1ba9-dd2ec1090000 pid=2497->guuid=2db0f2fb-1900-0000-1ba9-dd2ecf090000 pid=2511 clone guuid=40f7fdfb-1900-0000-1ba9-dd2ed0090000 pid=2512 /usr/bin/chmod guuid=972facf9-1900-0000-1ba9-dd2ec1090000 pid=2497->guuid=40f7fdfb-1900-0000-1ba9-dd2ed0090000 pid=2512 execve guuid=287957fc-1900-0000-1ba9-dd2ed1090000 pid=2513 /usr/bin/dash guuid=972facf9-1900-0000-1ba9-dd2ec1090000 pid=2497->guuid=287957fc-1900-0000-1ba9-dd2ed1090000 pid=2513 clone guuid=5f6069fc-1900-0000-1ba9-dd2ed2090000 pid=2514 /usr/bin/rm guuid=972facf9-1900-0000-1ba9-dd2ec1090000 pid=2497->guuid=5f6069fc-1900-0000-1ba9-dd2ed2090000 pid=2514 execve guuid=3374b6fc-1900-0000-1ba9-dd2ed4090000 pid=2516 /usr/bin/dash guuid=972facf9-1900-0000-1ba9-dd2ec1090000 pid=2497->guuid=3374b6fc-1900-0000-1ba9-dd2ed4090000 pid=2516 clone guuid=e9a3bdfc-1900-0000-1ba9-dd2ed5090000 pid=2517 /usr/bin/chmod guuid=972facf9-1900-0000-1ba9-dd2ec1090000 pid=2497->guuid=e9a3bdfc-1900-0000-1ba9-dd2ed5090000 pid=2517 execve guuid=3fcc28fd-1900-0000-1ba9-dd2ed7090000 pid=2519 /usr/bin/dash guuid=972facf9-1900-0000-1ba9-dd2ec1090000 pid=2497->guuid=3fcc28fd-1900-0000-1ba9-dd2ed7090000 pid=2519 clone guuid=89e235fd-1900-0000-1ba9-dd2ed9090000 pid=2521 /usr/bin/rm guuid=972facf9-1900-0000-1ba9-dd2ec1090000 pid=2497->guuid=89e235fd-1900-0000-1ba9-dd2ed9090000 pid=2521 execve guuid=e6b67ffd-1900-0000-1ba9-dd2eda090000 pid=2522 /usr/bin/dash guuid=972facf9-1900-0000-1ba9-dd2ec1090000 pid=2497->guuid=e6b67ffd-1900-0000-1ba9-dd2eda090000 pid=2522 clone guuid=356c84fd-1900-0000-1ba9-dd2edb090000 pid=2523 /usr/bin/chmod guuid=972facf9-1900-0000-1ba9-dd2ec1090000 pid=2497->guuid=356c84fd-1900-0000-1ba9-dd2edb090000 pid=2523 execve guuid=f24bbbfd-1900-0000-1ba9-dd2edd090000 pid=2525 /usr/bin/dash guuid=972facf9-1900-0000-1ba9-dd2ec1090000 pid=2497->guuid=f24bbbfd-1900-0000-1ba9-dd2edd090000 pid=2525 clone guuid=23cebffd-1900-0000-1ba9-dd2ede090000 pid=2526 /usr/bin/rm guuid=972facf9-1900-0000-1ba9-dd2ec1090000 pid=2497->guuid=23cebffd-1900-0000-1ba9-dd2ede090000 pid=2526 execve guuid=eac2f4fd-1900-0000-1ba9-dd2edf090000 pid=2527 /usr/bin/dash guuid=972facf9-1900-0000-1ba9-dd2ec1090000 pid=2497->guuid=eac2f4fd-1900-0000-1ba9-dd2edf090000 pid=2527 clone guuid=1b9dfefd-1900-0000-1ba9-dd2ee1090000 pid=2529 /usr/bin/chmod guuid=972facf9-1900-0000-1ba9-dd2ec1090000 pid=2497->guuid=1b9dfefd-1900-0000-1ba9-dd2ee1090000 pid=2529 execve guuid=c4e95ffe-1900-0000-1ba9-dd2ee3090000 pid=2531 /usr/bin/dash guuid=972facf9-1900-0000-1ba9-dd2ec1090000 pid=2497->guuid=c4e95ffe-1900-0000-1ba9-dd2ee3090000 pid=2531 clone guuid=48d978fe-1900-0000-1ba9-dd2ee5090000 pid=2533 /usr/bin/rm guuid=972facf9-1900-0000-1ba9-dd2ec1090000 pid=2497->guuid=48d978fe-1900-0000-1ba9-dd2ee5090000 pid=2533 execve guuid=758eb6fe-1900-0000-1ba9-dd2ee6090000 pid=2534 /usr/bin/dash guuid=972facf9-1900-0000-1ba9-dd2ec1090000 pid=2497->guuid=758eb6fe-1900-0000-1ba9-dd2ee6090000 pid=2534 clone guuid=51c8c0fe-1900-0000-1ba9-dd2ee7090000 pid=2535 /usr/bin/chmod guuid=972facf9-1900-0000-1ba9-dd2ec1090000 pid=2497->guuid=51c8c0fe-1900-0000-1ba9-dd2ee7090000 pid=2535 execve guuid=f46803ff-1900-0000-1ba9-dd2ee9090000 pid=2537 /usr/bin/dash guuid=972facf9-1900-0000-1ba9-dd2ec1090000 pid=2497->guuid=f46803ff-1900-0000-1ba9-dd2ee9090000 pid=2537 clone guuid=56380fff-1900-0000-1ba9-dd2eea090000 pid=2538 /usr/bin/rm guuid=972facf9-1900-0000-1ba9-dd2ec1090000 pid=2497->guuid=56380fff-1900-0000-1ba9-dd2eea090000 pid=2538 execve guuid=ce6d4aff-1900-0000-1ba9-dd2eec090000 pid=2540 /usr/bin/dash guuid=972facf9-1900-0000-1ba9-dd2ec1090000 pid=2497->guuid=ce6d4aff-1900-0000-1ba9-dd2eec090000 pid=2540 clone guuid=a2f34fff-1900-0000-1ba9-dd2eed090000 pid=2541 /usr/bin/chmod guuid=972facf9-1900-0000-1ba9-dd2ec1090000 pid=2497->guuid=a2f34fff-1900-0000-1ba9-dd2eed090000 pid=2541 execve guuid=b02c96ff-1900-0000-1ba9-dd2eef090000 pid=2543 /usr/bin/dash guuid=972facf9-1900-0000-1ba9-dd2ec1090000 pid=2497->guuid=b02c96ff-1900-0000-1ba9-dd2eef090000 pid=2543 clone guuid=8ce4a1ff-1900-0000-1ba9-dd2ef0090000 pid=2544 /usr/bin/rm guuid=972facf9-1900-0000-1ba9-dd2ec1090000 pid=2497->guuid=8ce4a1ff-1900-0000-1ba9-dd2ef0090000 pid=2544 execve guuid=fa55e3ff-1900-0000-1ba9-dd2ef1090000 pid=2545 /usr/bin/dash guuid=972facf9-1900-0000-1ba9-dd2ec1090000 pid=2497->guuid=fa55e3ff-1900-0000-1ba9-dd2ef1090000 pid=2545 clone guuid=558af1ff-1900-0000-1ba9-dd2ef2090000 pid=2546 /usr/bin/chmod guuid=972facf9-1900-0000-1ba9-dd2ec1090000 pid=2497->guuid=558af1ff-1900-0000-1ba9-dd2ef2090000 pid=2546 execve guuid=af4d2900-1a00-0000-1ba9-dd2ef4090000 pid=2548 /usr/bin/dash guuid=972facf9-1900-0000-1ba9-dd2ec1090000 pid=2497->guuid=af4d2900-1a00-0000-1ba9-dd2ef4090000 pid=2548 clone guuid=792b3000-1a00-0000-1ba9-dd2ef5090000 pid=2549 /usr/bin/rm guuid=972facf9-1900-0000-1ba9-dd2ec1090000 pid=2497->guuid=792b3000-1a00-0000-1ba9-dd2ef5090000 pid=2549 execve guuid=63d69a00-1a00-0000-1ba9-dd2ef6090000 pid=2550 /usr/bin/dash guuid=972facf9-1900-0000-1ba9-dd2ec1090000 pid=2497->guuid=63d69a00-1a00-0000-1ba9-dd2ef6090000 pid=2550 clone guuid=bafea100-1a00-0000-1ba9-dd2ef7090000 pid=2551 /usr/bin/chmod guuid=972facf9-1900-0000-1ba9-dd2ec1090000 pid=2497->guuid=bafea100-1a00-0000-1ba9-dd2ef7090000 pid=2551 execve guuid=36c9e900-1a00-0000-1ba9-dd2ef8090000 pid=2552 /usr/bin/dash guuid=972facf9-1900-0000-1ba9-dd2ec1090000 pid=2497->guuid=36c9e900-1a00-0000-1ba9-dd2ef8090000 pid=2552 clone guuid=d279f200-1a00-0000-1ba9-dd2ef9090000 pid=2553 /usr/bin/rm guuid=972facf9-1900-0000-1ba9-dd2ec1090000 pid=2497->guuid=d279f200-1a00-0000-1ba9-dd2ef9090000 pid=2553 execve guuid=08fa3501-1a00-0000-1ba9-dd2efa090000 pid=2554 /usr/bin/dash guuid=972facf9-1900-0000-1ba9-dd2ec1090000 pid=2497->guuid=08fa3501-1a00-0000-1ba9-dd2efa090000 pid=2554 clone guuid=d56e3d01-1a00-0000-1ba9-dd2efb090000 pid=2555 /usr/bin/chmod guuid=972facf9-1900-0000-1ba9-dd2ec1090000 pid=2497->guuid=d56e3d01-1a00-0000-1ba9-dd2efb090000 pid=2555 execve guuid=89f89101-1a00-0000-1ba9-dd2efc090000 pid=2556 /usr/bin/dash guuid=972facf9-1900-0000-1ba9-dd2ec1090000 pid=2497->guuid=89f89101-1a00-0000-1ba9-dd2efc090000 pid=2556 clone guuid=3540aa01-1a00-0000-1ba9-dd2efd090000 pid=2557 /usr/bin/rm guuid=972facf9-1900-0000-1ba9-dd2ec1090000 pid=2497->guuid=3540aa01-1a00-0000-1ba9-dd2efd090000 pid=2557 execve guuid=d22fea01-1a00-0000-1ba9-dd2eff090000 pid=2559 /usr/bin/dash guuid=972facf9-1900-0000-1ba9-dd2ec1090000 pid=2497->guuid=d22fea01-1a00-0000-1ba9-dd2eff090000 pid=2559 clone guuid=3061f201-1a00-0000-1ba9-dd2e000a0000 pid=2560 /usr/bin/chmod guuid=972facf9-1900-0000-1ba9-dd2ec1090000 pid=2497->guuid=3061f201-1a00-0000-1ba9-dd2e000a0000 pid=2560 execve guuid=3b9e4d02-1a00-0000-1ba9-dd2e020a0000 pid=2562 /usr/bin/dash guuid=972facf9-1900-0000-1ba9-dd2ec1090000 pid=2497->guuid=3b9e4d02-1a00-0000-1ba9-dd2e020a0000 pid=2562 clone guuid=e8f55d02-1a00-0000-1ba9-dd2e040a0000 pid=2564 /usr/bin/rm guuid=972facf9-1900-0000-1ba9-dd2ec1090000 pid=2497->guuid=e8f55d02-1a00-0000-1ba9-dd2e040a0000 pid=2564 execve guuid=bdba9802-1a00-0000-1ba9-dd2e050a0000 pid=2565 /usr/bin/dash guuid=972facf9-1900-0000-1ba9-dd2ec1090000 pid=2497->guuid=bdba9802-1a00-0000-1ba9-dd2e050a0000 pid=2565 clone guuid=3d9ea502-1a00-0000-1ba9-dd2e070a0000 pid=2567 /usr/bin/chmod guuid=972facf9-1900-0000-1ba9-dd2ec1090000 pid=2497->guuid=3d9ea502-1a00-0000-1ba9-dd2e070a0000 pid=2567 execve guuid=4fc5e202-1a00-0000-1ba9-dd2e080a0000 pid=2568 /usr/bin/dash guuid=972facf9-1900-0000-1ba9-dd2ec1090000 pid=2497->guuid=4fc5e202-1a00-0000-1ba9-dd2e080a0000 pid=2568 clone guuid=0955eb02-1a00-0000-1ba9-dd2e090a0000 pid=2569 /usr/bin/rm guuid=972facf9-1900-0000-1ba9-dd2ec1090000 pid=2497->guuid=0955eb02-1a00-0000-1ba9-dd2e090a0000 pid=2569 execve guuid=d0332b03-1a00-0000-1ba9-dd2e0b0a0000 pid=2571 /usr/bin/dash guuid=972facf9-1900-0000-1ba9-dd2ec1090000 pid=2497->guuid=d0332b03-1a00-0000-1ba9-dd2e0b0a0000 pid=2571 clone guuid=5a4e3103-1a00-0000-1ba9-dd2e0c0a0000 pid=2572 /usr/bin/chmod guuid=972facf9-1900-0000-1ba9-dd2ec1090000 pid=2497->guuid=5a4e3103-1a00-0000-1ba9-dd2e0c0a0000 pid=2572 execve guuid=7b407803-1a00-0000-1ba9-dd2e0d0a0000 pid=2573 /usr/bin/dash guuid=972facf9-1900-0000-1ba9-dd2ec1090000 pid=2497->guuid=7b407803-1a00-0000-1ba9-dd2e0d0a0000 pid=2573 clone guuid=a10d8803-1a00-0000-1ba9-dd2e0e0a0000 pid=2574 /usr/bin/rm guuid=972facf9-1900-0000-1ba9-dd2ec1090000 pid=2497->guuid=a10d8803-1a00-0000-1ba9-dd2e0e0a0000 pid=2574 execve
Threat name:
Script-Shell.Worm.Mirai
Status:
Malicious
First seen:
2025-11-22 22:31:24 UTC
File Type:
Text (Shell)
AV detection:
5 of 36 (13.89%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh e3df07460477dc19617e3e815fbd3c8493dce75d447a49eb3bc04d09cc79eb70

(this sample)

  
Delivery method
Distributed via web download

Comments