🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e639dbe6f23bced41eceaba211c46b73037ea23994a3e3d3c9e9c5ceea233c06. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: e639dbe6f23bced41eceaba211c46b73037ea23994a3e3d3c9e9c5ceea233c06
SHA3-384 hash: deb930fddfb4596bf1685798563e440c6d0c94206f158b0c62e1fbcee4c32373509ec106f79956d6bcd19c85c34a256c
SHA1 hash: 37ec3c21b075438ae85e5eb60bdf7c854c785015
MD5 hash: cb3a99e974ef6a20aa2b7c621ed40918
humanhash: delaware-berlin-triple-table
File name:e639dbe6f23bced41eceaba211c46b73037ea23994a3e3d3c9e9c5ceea233c06
Download: download sample
File size:3'452 bytes
First seen:2026-09-09 14:14:57 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 96:wUs+Gz/pR4j6ug4lgU8789wgYQJYRFGxRc91A7XMYRiA7XMYFa:w3R1RGc08YR18YM
TLSH T136619593B45622F72365C5D84CDA35C8311E109B4EE83624BDFEBE0C3B39692B12920A
TrID 50.0% (.SH) Linux/UNIX shell script (7000/1)
28.5% (.PL) Perl script (4000/1/1)
21.4% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter Anonymous
Tags:sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
25
Origin country :
EG EG
Vendor Threat Intelligence
No detections
Status:
terminated
Behavior Graph:
%3 guuid=351ec168-1900-0000-cbaf-7469f7090000 pid=2551 /usr/bin/sudo guuid=e0fbb26a-1900-0000-cbaf-7469fe090000 pid=2558 /tmp/sample.bin guuid=351ec168-1900-0000-cbaf-7469f7090000 pid=2551->guuid=e0fbb26a-1900-0000-cbaf-7469fe090000 pid=2558 execve guuid=ff4a0d6b-1900-0000-cbaf-7469000a0000 pid=2560 /usr/bin/uname guuid=e0fbb26a-1900-0000-cbaf-7469fe090000 pid=2558->guuid=ff4a0d6b-1900-0000-cbaf-7469000a0000 pid=2560 execve guuid=dbe2566b-1900-0000-cbaf-7469030a0000 pid=2563 /usr/bin/bash guuid=e0fbb26a-1900-0000-cbaf-7469fe090000 pid=2558->guuid=dbe2566b-1900-0000-cbaf-7469030a0000 pid=2563 clone guuid=2060b16b-1900-0000-cbaf-7469060a0000 pid=2566 /usr/bin/bash guuid=e0fbb26a-1900-0000-cbaf-7469fe090000 pid=2558->guuid=2060b16b-1900-0000-cbaf-7469060a0000 pid=2566 clone guuid=0ab5d66b-1900-0000-cbaf-7469070a0000 pid=2567 /usr/bin/curl net send-data guuid=e0fbb26a-1900-0000-cbaf-7469fe090000 pid=2558->guuid=0ab5d66b-1900-0000-cbaf-7469070a0000 pid=2567 execve guuid=2671886b-1900-0000-cbaf-7469040a0000 pid=2564 /usr/bin/bash guuid=dbe2566b-1900-0000-cbaf-7469030a0000 pid=2563->guuid=2671886b-1900-0000-cbaf-7469040a0000 pid=2564 clone 81b97d64-96dc-5e75-a02c-ce4c884ef31c nodejs.org:443 guuid=0ab5d66b-1900-0000-cbaf-7469070a0000 pid=2567->81b97d64-96dc-5e75-a02c-ce4c884ef31c send: 807B guuid=0ab5d66b-1900-0000-cbaf-7469070a0000 pid=2593 /usr/bin/curl dns net send-data guuid=0ab5d66b-1900-0000-cbaf-7469070a0000 pid=2567->guuid=0ab5d66b-1900-0000-cbaf-7469070a0000 pid=2593 clone guuid=0ab5d66b-1900-0000-cbaf-7469070a0000 pid=2593->81b97d64-96dc-5e75-a02c-ce4c884ef31c con 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=0ab5d66b-1900-0000-cbaf-7469070a0000 pid=2593->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 56B
Threat name:
Script-BAT.Downloader.Heuristic
Status:
Malicious
First seen:
2026-02-12 03:40:12 UTC
File Type:
Text (Shell)
AV detection:
3 of 36 (8.33%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  4/10
Tags:
antivm discovery linux
Behaviour
Reads runtime system information
Checks CPU configuration
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments