MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ea1e42bef2a950fb52cad5b5cb68413ff511494b5122204de03f1e8fc745ad5d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: ea1e42bef2a950fb52cad5b5cb68413ff511494b5122204de03f1e8fc745ad5d
SHA3-384 hash: 05c4b12cdb03c47d117de84910ebcbf053dbaa63c48de331dd092281144ad5f836d8f7069762fe231b0847d372023971
SHA1 hash: 5cd3a49fb571a82c5d2772e246f79a5072d4f874
MD5 hash: 90d78ed04dcba1fe4132adaa2ff23e35
humanhash: wisconsin-charlie-wisconsin-eighteen
File name:c.sh
Download: download sample
File size:1'322 bytes
First seen:2025-12-24 15:37:58 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 12:3J3hr3h18gdhtNI2nhexKdGShhhnDvhdW/9dshdRJR8RzSR7hSa5aSF6SxhAGnPe:3J3hDZNITKdLGHGqHn
TLSH T130214BBC416274079D49CE44E11794CBC02CAEF6B49BC822F6BE1D3C4D946A228C5A3A
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://141.98.10.91/001010102020120254563/sumrak.armn/an/an/a
http://141.98.10.91/001010102020120254563/sumrak.arm5n/an/an/a
http://141.98.10.91/001010102020120254563/sumrak.arm6n/an/an/a
http://141.98.10.91/001010102020120254563/sumrak.arm7n/an/an/a
http://141.98.10.91/001010102020120254563/sumrak.sh4n/an/an/a
http://141.98.10.91/001010102020120254563/sumrak.arcn/an/an/a
http://141.98.10.91/001010102020120254563/sumrak.mipsn/an/an/a
http://141.98.10.91/001010102020120254563/sumrak.mipseln/an/an/a
http://141.98.10.91/001010102020120254563/sumrak.sparcn/an/an/a
http://141.98.10.91/001010102020120254563/sumrak.x86_64n/an/an/a
http://141.98.10.91/001010102020120254563/sumrak.i686n/an/an/a
http://141.98.10.91/001010102020120254563/sumrak.i586n/an/an/a

Intelligence


File Origin
# of uploads :
1
# of downloads :
27
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Result
Gathering data
Status:
terminated
Behavior Graph:
%3 guuid=4b844b9f-1800-0000-ca9a-d0f33c050000 pid=1340 /usr/bin/sudo guuid=09980ba2-1800-0000-ca9a-d0f344050000 pid=1348 /tmp/sample.bin guuid=4b844b9f-1800-0000-ca9a-d0f33c050000 pid=1340->guuid=09980ba2-1800-0000-ca9a-d0f344050000 pid=1348 execve guuid=3d6f67a2-1800-0000-ca9a-d0f346050000 pid=1350 /usr/bin/curl net send-data guuid=09980ba2-1800-0000-ca9a-d0f344050000 pid=1348->guuid=3d6f67a2-1800-0000-ca9a-d0f346050000 pid=1350 execve guuid=1a29ccaf-1800-0000-ca9a-d0f35c050000 pid=1372 /usr/bin/chmod guuid=09980ba2-1800-0000-ca9a-d0f344050000 pid=1348->guuid=1a29ccaf-1800-0000-ca9a-d0f35c050000 pid=1372 execve guuid=80cf78b0-1800-0000-ca9a-d0f35d050000 pid=1373 /usr/bin/dash guuid=09980ba2-1800-0000-ca9a-d0f344050000 pid=1348->guuid=80cf78b0-1800-0000-ca9a-d0f35d050000 pid=1373 clone guuid=b76592b0-1800-0000-ca9a-d0f35e050000 pid=1374 /usr/bin/curl net send-data guuid=09980ba2-1800-0000-ca9a-d0f344050000 pid=1348->guuid=b76592b0-1800-0000-ca9a-d0f35e050000 pid=1374 execve guuid=d0fe85b8-1800-0000-ca9a-d0f36d050000 pid=1389 /usr/bin/chmod guuid=09980ba2-1800-0000-ca9a-d0f344050000 pid=1348->guuid=d0fe85b8-1800-0000-ca9a-d0f36d050000 pid=1389 execve guuid=a342fcb8-1800-0000-ca9a-d0f36f050000 pid=1391 /usr/bin/dash guuid=09980ba2-1800-0000-ca9a-d0f344050000 pid=1348->guuid=a342fcb8-1800-0000-ca9a-d0f36f050000 pid=1391 clone guuid=cae60ab9-1800-0000-ca9a-d0f370050000 pid=1392 /usr/bin/curl net send-data guuid=09980ba2-1800-0000-ca9a-d0f344050000 pid=1348->guuid=cae60ab9-1800-0000-ca9a-d0f370050000 pid=1392 execve guuid=4b45fac2-1800-0000-ca9a-d0f384050000 pid=1412 /usr/bin/chmod guuid=09980ba2-1800-0000-ca9a-d0f344050000 pid=1348->guuid=4b45fac2-1800-0000-ca9a-d0f384050000 pid=1412 execve guuid=159067c3-1800-0000-ca9a-d0f386050000 pid=1414 /usr/bin/dash guuid=09980ba2-1800-0000-ca9a-d0f344050000 pid=1348->guuid=159067c3-1800-0000-ca9a-d0f386050000 pid=1414 clone guuid=06b787c3-1800-0000-ca9a-d0f388050000 pid=1416 /usr/bin/curl net send-data guuid=09980ba2-1800-0000-ca9a-d0f344050000 pid=1348->guuid=06b787c3-1800-0000-ca9a-d0f388050000 pid=1416 execve guuid=cd81fdce-1800-0000-ca9a-d0f39d050000 pid=1437 /usr/bin/chmod guuid=09980ba2-1800-0000-ca9a-d0f344050000 pid=1348->guuid=cd81fdce-1800-0000-ca9a-d0f39d050000 pid=1437 execve guuid=c78b66cf-1800-0000-ca9a-d0f39e050000 pid=1438 /usr/bin/dash guuid=09980ba2-1800-0000-ca9a-d0f344050000 pid=1348->guuid=c78b66cf-1800-0000-ca9a-d0f39e050000 pid=1438 clone guuid=ef9a6fcf-1800-0000-ca9a-d0f3a0050000 pid=1440 /usr/bin/curl net send-data guuid=09980ba2-1800-0000-ca9a-d0f344050000 pid=1348->guuid=ef9a6fcf-1800-0000-ca9a-d0f3a0050000 pid=1440 execve guuid=ea5163dc-1800-0000-ca9a-d0f3b8050000 pid=1464 /usr/bin/chmod guuid=09980ba2-1800-0000-ca9a-d0f344050000 pid=1348->guuid=ea5163dc-1800-0000-ca9a-d0f3b8050000 pid=1464 execve guuid=1b65a3dc-1800-0000-ca9a-d0f3ba050000 pid=1466 /usr/bin/dash guuid=09980ba2-1800-0000-ca9a-d0f344050000 pid=1348->guuid=1b65a3dc-1800-0000-ca9a-d0f3ba050000 pid=1466 clone guuid=2e8cabdc-1800-0000-ca9a-d0f3bb050000 pid=1467 /usr/bin/curl net send-data guuid=09980ba2-1800-0000-ca9a-d0f344050000 pid=1348->guuid=2e8cabdc-1800-0000-ca9a-d0f3bb050000 pid=1467 execve guuid=dc4b7ce4-1800-0000-ca9a-d0f3ce050000 pid=1486 /usr/bin/chmod guuid=09980ba2-1800-0000-ca9a-d0f344050000 pid=1348->guuid=dc4b7ce4-1800-0000-ca9a-d0f3ce050000 pid=1486 execve guuid=fe84e7e4-1800-0000-ca9a-d0f3cf050000 pid=1487 /usr/bin/dash guuid=09980ba2-1800-0000-ca9a-d0f344050000 pid=1348->guuid=fe84e7e4-1800-0000-ca9a-d0f3cf050000 pid=1487 clone guuid=31edf9e4-1800-0000-ca9a-d0f3d0050000 pid=1488 /usr/bin/curl net send-data guuid=09980ba2-1800-0000-ca9a-d0f344050000 pid=1348->guuid=31edf9e4-1800-0000-ca9a-d0f3d0050000 pid=1488 execve guuid=b93823ef-1800-0000-ca9a-d0f3e9050000 pid=1513 /usr/bin/chmod guuid=09980ba2-1800-0000-ca9a-d0f344050000 pid=1348->guuid=b93823ef-1800-0000-ca9a-d0f3e9050000 pid=1513 execve guuid=03958fef-1800-0000-ca9a-d0f3eb050000 pid=1515 /usr/bin/dash guuid=09980ba2-1800-0000-ca9a-d0f344050000 pid=1348->guuid=03958fef-1800-0000-ca9a-d0f3eb050000 pid=1515 clone guuid=5f879def-1800-0000-ca9a-d0f3ec050000 pid=1516 /usr/bin/curl net send-data guuid=09980ba2-1800-0000-ca9a-d0f344050000 pid=1348->guuid=5f879def-1800-0000-ca9a-d0f3ec050000 pid=1516 execve guuid=97ee41f8-1800-0000-ca9a-d0f303060000 pid=1539 /usr/bin/chmod guuid=09980ba2-1800-0000-ca9a-d0f344050000 pid=1348->guuid=97ee41f8-1800-0000-ca9a-d0f303060000 pid=1539 execve guuid=1e8981f8-1800-0000-ca9a-d0f305060000 pid=1541 /usr/bin/dash guuid=09980ba2-1800-0000-ca9a-d0f344050000 pid=1348->guuid=1e8981f8-1800-0000-ca9a-d0f305060000 pid=1541 clone guuid=b6fa8bf8-1800-0000-ca9a-d0f306060000 pid=1542 /usr/bin/curl net send-data guuid=09980ba2-1800-0000-ca9a-d0f344050000 pid=1348->guuid=b6fa8bf8-1800-0000-ca9a-d0f306060000 pid=1542 execve guuid=03fbd0ff-1800-0000-ca9a-d0f31b060000 pid=1563 /usr/bin/chmod guuid=09980ba2-1800-0000-ca9a-d0f344050000 pid=1348->guuid=03fbd0ff-1800-0000-ca9a-d0f31b060000 pid=1563 execve guuid=f4670a00-1900-0000-ca9a-d0f31d060000 pid=1565 /usr/bin/dash guuid=09980ba2-1800-0000-ca9a-d0f344050000 pid=1348->guuid=f4670a00-1900-0000-ca9a-d0f31d060000 pid=1565 clone guuid=e5830f00-1900-0000-ca9a-d0f31e060000 pid=1566 /usr/bin/curl net send-data guuid=09980ba2-1800-0000-ca9a-d0f344050000 pid=1348->guuid=e5830f00-1900-0000-ca9a-d0f31e060000 pid=1566 execve guuid=7263830a-1900-0000-ca9a-d0f33a060000 pid=1594 /usr/bin/chmod guuid=09980ba2-1800-0000-ca9a-d0f344050000 pid=1348->guuid=7263830a-1900-0000-ca9a-d0f33a060000 pid=1594 execve guuid=84f4cd0a-1900-0000-ca9a-d0f33c060000 pid=1596 /usr/bin/dash guuid=09980ba2-1800-0000-ca9a-d0f344050000 pid=1348->guuid=84f4cd0a-1900-0000-ca9a-d0f33c060000 pid=1596 clone guuid=d7a4e40a-1900-0000-ca9a-d0f33d060000 pid=1597 /usr/bin/curl net send-data guuid=09980ba2-1800-0000-ca9a-d0f344050000 pid=1348->guuid=d7a4e40a-1900-0000-ca9a-d0f33d060000 pid=1597 execve guuid=c04ba612-1900-0000-ca9a-d0f356060000 pid=1622 /usr/bin/chmod guuid=09980ba2-1800-0000-ca9a-d0f344050000 pid=1348->guuid=c04ba612-1900-0000-ca9a-d0f356060000 pid=1622 execve guuid=8f89e612-1900-0000-ca9a-d0f357060000 pid=1623 /usr/bin/dash guuid=09980ba2-1800-0000-ca9a-d0f344050000 pid=1348->guuid=8f89e612-1900-0000-ca9a-d0f357060000 pid=1623 clone guuid=5b9bf412-1900-0000-ca9a-d0f358060000 pid=1624 /usr/bin/curl net send-data guuid=09980ba2-1800-0000-ca9a-d0f344050000 pid=1348->guuid=5b9bf412-1900-0000-ca9a-d0f358060000 pid=1624 execve guuid=5f65031a-1900-0000-ca9a-d0f370060000 pid=1648 /usr/bin/chmod guuid=09980ba2-1800-0000-ca9a-d0f344050000 pid=1348->guuid=5f65031a-1900-0000-ca9a-d0f370060000 pid=1648 execve guuid=b89b3f1a-1900-0000-ca9a-d0f371060000 pid=1649 /usr/bin/dash guuid=09980ba2-1800-0000-ca9a-d0f344050000 pid=1348->guuid=b89b3f1a-1900-0000-ca9a-d0f371060000 pid=1649 clone guuid=470c461a-1900-0000-ca9a-d0f372060000 pid=1650 /usr/bin/rm delete-file guuid=09980ba2-1800-0000-ca9a-d0f344050000 pid=1348->guuid=470c461a-1900-0000-ca9a-d0f372060000 pid=1650 execve df7b537f-758f-5cbd-9393-addaae2cab06 141.98.10.91:80 guuid=3d6f67a2-1800-0000-ca9a-d0f346050000 pid=1350->df7b537f-758f-5cbd-9393-addaae2cab06 send: 108B guuid=b76592b0-1800-0000-ca9a-d0f35e050000 pid=1374->df7b537f-758f-5cbd-9393-addaae2cab06 send: 109B guuid=cae60ab9-1800-0000-ca9a-d0f370050000 pid=1392->df7b537f-758f-5cbd-9393-addaae2cab06 send: 109B guuid=06b787c3-1800-0000-ca9a-d0f388050000 pid=1416->df7b537f-758f-5cbd-9393-addaae2cab06 send: 109B guuid=ef9a6fcf-1800-0000-ca9a-d0f3a0050000 pid=1440->df7b537f-758f-5cbd-9393-addaae2cab06 send: 108B guuid=2e8cabdc-1800-0000-ca9a-d0f3bb050000 pid=1467->df7b537f-758f-5cbd-9393-addaae2cab06 send: 108B guuid=31edf9e4-1800-0000-ca9a-d0f3d0050000 pid=1488->df7b537f-758f-5cbd-9393-addaae2cab06 send: 109B guuid=5f879def-1800-0000-ca9a-d0f3ec050000 pid=1516->df7b537f-758f-5cbd-9393-addaae2cab06 send: 111B guuid=b6fa8bf8-1800-0000-ca9a-d0f306060000 pid=1542->df7b537f-758f-5cbd-9393-addaae2cab06 send: 110B guuid=e5830f00-1900-0000-ca9a-d0f31e060000 pid=1566->df7b537f-758f-5cbd-9393-addaae2cab06 send: 111B guuid=d7a4e40a-1900-0000-ca9a-d0f33d060000 pid=1597->df7b537f-758f-5cbd-9393-addaae2cab06 send: 109B guuid=5b9bf412-1900-0000-ca9a-d0f358060000 pid=1624->df7b537f-758f-5cbd-9393-addaae2cab06 send: 109B
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Linux.Downloader.Generic
Status:
Suspicious
First seen:
2025-12-24 15:39:14 UTC
File Type:
Text (Shell)
AV detection:
12 of 36 (33.33%)
Threat level:
  3/5
Gathering data
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh ea1e42bef2a950fb52cad5b5cb68413ff511494b5122204de03f1e8fc745ad5d

(this sample)

  
Delivery method
Distributed via web download

Comments