MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 e7e966a76cea9864e2df8e598f20be4a461e087aa634e9d854f5bf6e9811f2ef. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Threat unknown
Vendor detections: 8
| SHA256 hash: | e7e966a76cea9864e2df8e598f20be4a461e087aa634e9d854f5bf6e9811f2ef |
|---|---|
| SHA3-384 hash: | 53249f493cb8779f9becd3eeceb3003d1bc091bcdbd769d7ea90adcacf030a162caf34977fe07e5d9ff6e2464a6cfe14 |
| SHA1 hash: | f98384442307d128291262933d4975c5746fffcb |
| MD5 hash: | b2c870ba5b3fce012d998c9bfa35ef73 |
| humanhash: | quebec-pluto-michigan-two |
| File name: | dl17 |
| Download: | download sample |
| File size: | 5'050 bytes |
| First seen: | 2025-04-30 09:18:43 UTC |
| Last seen: | 2025-04-30 12:56:34 UTC |
| File type: | sh |
| MIME type: | text/plain |
| ssdeep | 96:nMLo0CTqUW0dHiCT+4eg+C6f2fGB4R3huXsFJuyxlKLwbnJuOWMaq2SP2CoSREfK:zxRz4YtrsGJXnKRE |
| TLSH | T1ABA1E79903D109314502720FB6E9BFA0ECA586B16E334F96BDB4CEE99C70958F920B5C |
| Magika | shell |
| Reporter | |
| Tags: | sh |
Shell script dropper
This file seems to be a shell script dropper, using wget, ftpget and/or curl. More information about the corresponding payload URLs are shown below.
Intelligence
File Origin
# of uploads :
2
# of downloads :
108
Origin country :
DEVendor Threat Intelligence
Verdict:
Malicious
Score:
93.3%
Link:
Tags:
downloader packed agent
Verdict:
Malicious
Threat level:
10/10
Confidence:
100%
Verdict:
Malicious
Labled as:
Linux/Downloader.p
Score:
100%
Verdict:
Malware
File Type:
SCRIPT
Threat name:
Linux.Trojan.Generic
Status:
Suspicious
First seen:
2025-04-30 10:26:07 UTC
File Type:
Text (Shell)
AV detection:
6 of 24 (25.00%)
Threat level:
5/5
Detection(s):
Suspicious file
Result
Malware family:
n/a
Score:
3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Malicious File
Score:
1.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Web download
sh e7e966a76cea9864e2df8e598f20be4a461e087aa634e9d854f5bf6e9811f2ef
(this sample)
Delivery method
Distributed via web download
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.