MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 e8a6cb4a34df14c8e3e918dd50016e3ae34d29fa8996fb8a39d64d6c1a0620b6. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Threat unknown
Vendor detections: 5
| SHA256 hash: | e8a6cb4a34df14c8e3e918dd50016e3ae34d29fa8996fb8a39d64d6c1a0620b6 |
|---|---|
| SHA3-384 hash: | 75ea860c11750e2bbd436e827cfc5a33a216e78e78b1c5e4d928b993f09b6805747587d2a4087a3e7b8b8531d1a98367 |
| SHA1 hash: | 74d4345e92db1e04da5e066f5ded80ec378300b3 |
| MD5 hash: | 91de2a5728a9a8f25d2bc5711b5d02d4 |
| humanhash: | wisconsin-skylark-beer-fillet |
| File name: | b.sh |
| Download: | download sample |
| File size: | 613 bytes |
| First seen: | 2026-09-29 14:47:16 UTC |
| Last seen: | Never |
| File type: | sh |
| MIME type: | text/x-shellscript |
| ssdeep | 12:xy9cPWn/znsHvY48qnsrgBexScFZv7GUFdrUFu81OXyoFsWBexQVCcFaz:o9cunjsPY0srwMvFZv7GOG1OXZhMcfF6 |
| TLSH | T15DF07DF4F034CD35770DCA59FA5A05A454CB65BF14363898C8E78CA4090C658B30BA53 |
| TrID | 70.0% (.SH) Linux/UNIX shell script (7000/1) 30.0% (.) Unix-like shebang (var.3) (gen) (3000/1) |
| Magika | shell |
| Reporter | |
| Tags: | sh |
Shell script dropper
This file seems to be a shell script dropper, using wget, ftpget and/or curl. More information about the corresponding payload URLs are shown below.
| URL | Malware sample (SHA256 hash) | Signature | Tags |
|---|---|---|---|
| http://131.123.43.239/up | n/a | n/a | elf ua-wget |
| http://131.123.43.239:8123/pldq.sh | n/a | n/a | ascii bash sh ua-wget |
Intelligence
File Origin
HUVendor Threat Intelligence
Result
Behaviour
File information
The table below shows additional information about this malware sample such as delivery method and external references.
sh e8a6cb4a34df14c8e3e918dd50016e3ae34d29fa8996fb8a39d64d6c1a0620b6
(this sample)
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.