🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e63cf3ce1a71ea69d596056cb212337c38ee4740b22f73b5bd64ffd47cbc0d7a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: e63cf3ce1a71ea69d596056cb212337c38ee4740b22f73b5bd64ffd47cbc0d7a
SHA3-384 hash: 7533f936f8aad8299f2006dfc90485e20f986bae482730c23f06410c0b660943fd1409135b8aa3bdd6aa4926d6b12887
SHA1 hash: b5620eda4313f368514fc39d64f226357395c6e9
MD5 hash: 68bac6bee1eea4a6b306af3577cd8264
humanhash: avocado-sierra-mike-finch
File name:dl.sh
Download: download sample
File size:622 bytes
First seen:2026-09-30 15:55:00 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 12:B/Ka4ZoJ2HT7HvC53nUF+YXnUF+J3nUF+tqhHHvBuQgLOWgevIn:J914vHvA3UzXUi3UoqNHvJgLOWgevI
TLSH T19AF0F9F1FC624471768D853FF6AD0286B6C25C7F10996E09344BFC226B6C4A4B09E633
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter adliwahid

Intelligence


File Origin
# of uploads :
1
# of downloads :
80
Origin country :
NL NL
Vendor Threat Intelligence
No detections
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-09-28T23:54:00Z UTC
Last seen:
2026-10-01T21:20:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=3fcac548-1900-0000-b74b-d9a4860c0000 pid=3206 /usr/bin/sudo guuid=0ba6ed4c-1900-0000-b74b-d9a4890c0000 pid=3209 /tmp/sample.bin guuid=3fcac548-1900-0000-b74b-d9a4860c0000 pid=3206->guuid=0ba6ed4c-1900-0000-b74b-d9a4890c0000 pid=3209 execve guuid=90e2904d-1900-0000-b74b-d9a48b0c0000 pid=3211 /usr/bin/uname guuid=0ba6ed4c-1900-0000-b74b-d9a4890c0000 pid=3209->guuid=90e2904d-1900-0000-b74b-d9a48b0c0000 pid=3211 execve guuid=c713b54e-1900-0000-b74b-d9a48e0c0000 pid=3214 /usr/bin/rm guuid=0ba6ed4c-1900-0000-b74b-d9a4890c0000 pid=3209->guuid=c713b54e-1900-0000-b74b-d9a48e0c0000 pid=3214 execve guuid=3316f54e-1900-0000-b74b-d9a48f0c0000 pid=3215 /usr/bin/wget net send-data write-file guuid=0ba6ed4c-1900-0000-b74b-d9a4890c0000 pid=3209->guuid=3316f54e-1900-0000-b74b-d9a48f0c0000 pid=3215 execve guuid=07ba856a-1900-0000-b74b-d9a4c60c0000 pid=3270 /usr/bin/chmod guuid=0ba6ed4c-1900-0000-b74b-d9a4890c0000 pid=3209->guuid=07ba856a-1900-0000-b74b-d9a4c60c0000 pid=3270 execve guuid=6033c56a-1900-0000-b74b-d9a4c80c0000 pid=3272 /tmp/w delete-file mprotect-exec guuid=0ba6ed4c-1900-0000-b74b-d9a4890c0000 pid=3209->guuid=6033c56a-1900-0000-b74b-d9a4c80c0000 pid=3272 execve guuid=2a67a96b-1900-0000-b74b-d9a4cc0c0000 pid=3276 /usr/bin/rm delete-file guuid=0ba6ed4c-1900-0000-b74b-d9a4890c0000 pid=3209->guuid=2a67a96b-1900-0000-b74b-d9a4cc0c0000 pid=3276 execve guuid=65e1dd6e-1900-0000-b74b-d9a4d40c0000 pid=3284 /usr/bin/rm delete-file guuid=0ba6ed4c-1900-0000-b74b-d9a4890c0000 pid=3209->guuid=65e1dd6e-1900-0000-b74b-d9a4d40c0000 pid=3284 execve 8b186663-0abc-5bc1-898f-57098d77ef5c 23.95.228.20:80 guuid=3316f54e-1900-0000-b74b-d9a48f0c0000 pid=3215->8b186663-0abc-5bc1-898f-57098d77ef5c send: 138B guuid=39caa06b-1900-0000-b74b-d9a4cb0c0000 pid=3275 /tmp/w zombie guuid=6033c56a-1900-0000-b74b-d9a4c80c0000 pid=3272->guuid=39caa06b-1900-0000-b74b-d9a4cb0c0000 pid=3275 clone guuid=1971ac6b-1900-0000-b74b-d9a4cd0c0000 pid=3277 /tmp/w delete-file dns net send-data write-config write-file zombie guuid=39caa06b-1900-0000-b74b-d9a4cb0c0000 pid=3275->guuid=1971ac6b-1900-0000-b74b-d9a4cd0c0000 pid=3277 clone 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=1971ac6b-1900-0000-b74b-d9a4cd0c0000 pid=3277->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 62B 3d46da88-d94f-5894-9cc2-13cbe20c65e0 bot.3.9.f.e.a.2.8.f.0.7.4.0.1.0.0.2.ip6.arpa:1337 guuid=1971ac6b-1900-0000-b74b-d9a4cd0c0000 pid=3277->3d46da88-d94f-5894-9cc2-13cbe20c65e0 send: 32B d93b5911-7e33-573b-b6da-b01954a6f3e6 9.9.9.9:12345 guuid=1971ac6b-1900-0000-b74b-d9a4cd0c0000 pid=3277->d93b5911-7e33-573b-b6da-b01954a6f3e6 send: 4193280B guuid=151d4570-1900-0000-b74b-d9a4d90c0000 pid=3289 /tmp/w guuid=1971ac6b-1900-0000-b74b-d9a4cd0c0000 pid=3277->guuid=151d4570-1900-0000-b74b-d9a4d90c0000 pid=3289 clone guuid=79bca4fa-1b00-0000-b74b-d9a4f1130000 pid=5105 /tmp/w guuid=1971ac6b-1900-0000-b74b-d9a4cd0c0000 pid=3277->guuid=79bca4fa-1b00-0000-b74b-d9a4f1130000 pid=5105 clone guuid=04e2a7fa-1b00-0000-b74b-d9a4f2130000 pid=5106 /tmp/w guuid=79bca4fa-1b00-0000-b74b-d9a4f1130000 pid=5105->guuid=04e2a7fa-1b00-0000-b74b-d9a4f2130000 pid=5106 clone guuid=5f7eadfa-1b00-0000-b74b-d9a4f3130000 pid=5107 /tmp/w guuid=79bca4fa-1b00-0000-b74b-d9a4f1130000 pid=5105->guuid=5f7eadfa-1b00-0000-b74b-d9a4f3130000 pid=5107 clone
Result
Malware family:
n/a
Score:
  7/10
Tags:
antivm defense_evasion discovery execution linux persistence privilege_escalation upx
Behaviour
Enumerates kernel/hardware configuration
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Checks CPU configuration
Reads system network configuration
Modifies Bash startup script
UPX packed file
Creates/modifies Cron job
Creates/modifies environment variables
Enumerates active TCP sockets
Enumerates running processes
Modifies init.d
Modifies rc script
Modifies systemd
Write file to user bin folder
File and Directory Permissions Modification
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments