MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ea2b1c6fa88da27a58e92ee93b752180fb6ca0badb297c3771a0f0adb4e49f0b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: ea2b1c6fa88da27a58e92ee93b752180fb6ca0badb297c3771a0f0adb4e49f0b
SHA3-384 hash: b4c6acdc4f9402a61299252696b4421c5d152614da514ba6016d029cd584375717b1a817e29704dcb5043bfe201c6be7
SHA1 hash: adb94417d3aec78b7779161ba359ce18816a3e09
MD5 hash: e3a12d8a0dc98b06b548a766aa77dc9c
humanhash: freddie-network-don-fix
File name:init.sh
Download: download sample
File size:13'982 bytes
First seen:2026-06-21 15:27:42 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 192:5VtWxos/MbhrlqT8/2hEPVmhxZPKgjlhtOtHDmh5RDKlE3As+SU8x0PNIZXG8/Pm:dTlkES1LURYRQEw3FNnVUA
TLSH T15C529651ED26A270256D80F5BACB2501F50F412B460C7A05B1AFA254BF3CFAC61FD7BA
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
50
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
busybox opendir
Verdict:
Adware
File Type:
Script
Detections:
not-a-virus:HEUR:Downloader.Shell.Miner.a
Status:
terminated
Behavior Graph:
%3 guuid=2ca7de78-1900-0000-0fc2-fbf92c140000 pid=5164 /usr/bin/sudo guuid=48932c7b-1900-0000-0fc2-fbf92d140000 pid=5165 /tmp/sample.bin write-file guuid=2ca7de78-1900-0000-0fc2-fbf92c140000 pid=5164->guuid=48932c7b-1900-0000-0fc2-fbf92d140000 pid=5165 execve guuid=c7d87a7c-1900-0000-0fc2-fbf92e140000 pid=5166 /usr/bin/uname guuid=48932c7b-1900-0000-0fc2-fbf92d140000 pid=5165->guuid=c7d87a7c-1900-0000-0fc2-fbf92e140000 pid=5166 execve guuid=85ab127d-1900-0000-0fc2-fbf92f140000 pid=5167 /usr/bin/id guuid=48932c7b-1900-0000-0fc2-fbf92d140000 pid=5165->guuid=85ab127d-1900-0000-0fc2-fbf92f140000 pid=5167 execve guuid=27298b7d-1900-0000-0fc2-fbf930140000 pid=5168 /usr/bin/date guuid=48932c7b-1900-0000-0fc2-fbf92d140000 pid=5165->guuid=27298b7d-1900-0000-0fc2-fbf930140000 pid=5168 execve guuid=a0df9a85-1900-0000-0fc2-fbf931140000 pid=5169 /usr/bin/uname guuid=48932c7b-1900-0000-0fc2-fbf92d140000 pid=5165->guuid=a0df9a85-1900-0000-0fc2-fbf931140000 pid=5169 execve guuid=99601886-1900-0000-0fc2-fbf932140000 pid=5170 /usr/bin/grep guuid=48932c7b-1900-0000-0fc2-fbf92d140000 pid=5165->guuid=99601886-1900-0000-0fc2-fbf932140000 pid=5170 execve guuid=b217ac86-1900-0000-0fc2-fbf933140000 pid=5171 /usr/bin/date guuid=48932c7b-1900-0000-0fc2-fbf92d140000 pid=5165->guuid=b217ac86-1900-0000-0fc2-fbf933140000 pid=5171 execve guuid=a1981187-1900-0000-0fc2-fbf934140000 pid=5172 /usr/bin/date guuid=48932c7b-1900-0000-0fc2-fbf92d140000 pid=5165->guuid=a1981187-1900-0000-0fc2-fbf934140000 pid=5172 execve guuid=cf937e87-1900-0000-0fc2-fbf935140000 pid=5173 /usr/bin/grep guuid=48932c7b-1900-0000-0fc2-fbf92d140000 pid=5165->guuid=cf937e87-1900-0000-0fc2-fbf935140000 pid=5173 execve guuid=41390888-1900-0000-0fc2-fbf936140000 pid=5174 /usr/bin/date guuid=48932c7b-1900-0000-0fc2-fbf92d140000 pid=5165->guuid=41390888-1900-0000-0fc2-fbf936140000 pid=5174 execve guuid=c5bd8588-1900-0000-0fc2-fbf937140000 pid=5175 /usr/bin/chmod guuid=48932c7b-1900-0000-0fc2-fbf92d140000 pid=5165->guuid=c5bd8588-1900-0000-0fc2-fbf937140000 pid=5175 execve guuid=d8ade188-1900-0000-0fc2-fbf938140000 pid=5176 /usr/bin/bash guuid=48932c7b-1900-0000-0fc2-fbf92d140000 pid=5165->guuid=d8ade188-1900-0000-0fc2-fbf938140000 pid=5176 clone guuid=020c8489-1900-0000-0fc2-fbf93a140000 pid=5178 /usr/bin/rm delete-file guuid=48932c7b-1900-0000-0fc2-fbf92d140000 pid=5165->guuid=020c8489-1900-0000-0fc2-fbf93a140000 pid=5178 execve guuid=0379e789-1900-0000-0fc2-fbf93b140000 pid=5179 /usr/bin/date guuid=48932c7b-1900-0000-0fc2-fbf92d140000 pid=5165->guuid=0379e789-1900-0000-0fc2-fbf93b140000 pid=5179 execve guuid=28c25b8a-1900-0000-0fc2-fbf93c140000 pid=5180 /usr/bin/date guuid=48932c7b-1900-0000-0fc2-fbf92d140000 pid=5165->guuid=28c25b8a-1900-0000-0fc2-fbf93c140000 pid=5180 execve guuid=5f08d08a-1900-0000-0fc2-fbf93d140000 pid=5181 /usr/bin/wget net send-data write-file guuid=48932c7b-1900-0000-0fc2-fbf92d140000 pid=5165->guuid=5f08d08a-1900-0000-0fc2-fbf93d140000 pid=5181 execve guuid=aa771b91-1900-0000-0fc2-fbf93e140000 pid=5182 /usr/bin/bash guuid=48932c7b-1900-0000-0fc2-fbf92d140000 pid=5165->guuid=aa771b91-1900-0000-0fc2-fbf93e140000 pid=5182 clone guuid=c566b691-1900-0000-0fc2-fbf940140000 pid=5184 /usr/bin/date guuid=48932c7b-1900-0000-0fc2-fbf92d140000 pid=5165->guuid=c566b691-1900-0000-0fc2-fbf940140000 pid=5184 execve guuid=4e892792-1900-0000-0fc2-fbf941140000 pid=5185 /usr/bin/bash guuid=48932c7b-1900-0000-0fc2-fbf92d140000 pid=5165->guuid=4e892792-1900-0000-0fc2-fbf941140000 pid=5185 clone guuid=2db49292-1900-0000-0fc2-fbf943140000 pid=5187 /usr/bin/head guuid=48932c7b-1900-0000-0fc2-fbf92d140000 pid=5165->guuid=2db49292-1900-0000-0fc2-fbf943140000 pid=5187 execve guuid=26c79892-1900-0000-0fc2-fbf944140000 pid=5188 /usr/bin/grep guuid=48932c7b-1900-0000-0fc2-fbf92d140000 pid=5165->guuid=26c79892-1900-0000-0fc2-fbf944140000 pid=5188 execve guuid=4fca8493-1900-0000-0fc2-fbf945140000 pid=5189 /usr/bin/chmod guuid=48932c7b-1900-0000-0fc2-fbf92d140000 pid=5165->guuid=4fca8493-1900-0000-0fc2-fbf945140000 pid=5189 execve guuid=a120e193-1900-0000-0fc2-fbf946140000 pid=5190 /usr/bin/date guuid=48932c7b-1900-0000-0fc2-fbf92d140000 pid=5165->guuid=a120e193-1900-0000-0fc2-fbf946140000 pid=5190 execve guuid=f1504f94-1900-0000-0fc2-fbf947140000 pid=5191 /tmp/.d write-file guuid=48932c7b-1900-0000-0fc2-fbf92d140000 pid=5165->guuid=f1504f94-1900-0000-0fc2-fbf947140000 pid=5191 execve guuid=41c05e94-1900-0000-0fc2-fbf948140000 pid=5192 /usr/bin/date guuid=48932c7b-1900-0000-0fc2-fbf92d140000 pid=5165->guuid=41c05e94-1900-0000-0fc2-fbf948140000 pid=5192 execve guuid=53b53495-1900-0000-0fc2-fbf949140000 pid=5193 /usr/bin/sleep guuid=48932c7b-1900-0000-0fc2-fbf92d140000 pid=5165->guuid=53b53495-1900-0000-0fc2-fbf949140000 pid=5193 execve guuid=d3edb361-1c00-0000-0fc2-fbf9a9140000 pid=5289 /usr/bin/bash net send-data guuid=48932c7b-1900-0000-0fc2-fbf92d140000 pid=5165->guuid=d3edb361-1c00-0000-0fc2-fbf9a9140000 pid=5289 clone guuid=c1941662-1c00-0000-0fc2-fbf9aa140000 pid=5290 /usr/bin/date guuid=48932c7b-1900-0000-0fc2-fbf92d140000 pid=5165->guuid=c1941662-1c00-0000-0fc2-fbf9aa140000 pid=5290 execve guuid=def7c262-1c00-0000-0fc2-fbf9ab140000 pid=5291 /usr/bin/date guuid=48932c7b-1900-0000-0fc2-fbf92d140000 pid=5165->guuid=def7c262-1c00-0000-0fc2-fbf9ab140000 pid=5291 execve guuid=c98a7563-1c00-0000-0fc2-fbf9ac140000 pid=5292 /usr/bin/date guuid=48932c7b-1900-0000-0fc2-fbf92d140000 pid=5165->guuid=c98a7563-1c00-0000-0fc2-fbf9ac140000 pid=5292 execve guuid=2d2f2164-1c00-0000-0fc2-fbf9ad140000 pid=5293 /usr/bin/cat guuid=48932c7b-1900-0000-0fc2-fbf92d140000 pid=5165->guuid=2d2f2164-1c00-0000-0fc2-fbf9ad140000 pid=5293 execve guuid=795fc564-1c00-0000-0fc2-fbf9ae140000 pid=5294 /usr/bin/basename guuid=48932c7b-1900-0000-0fc2-fbf92d140000 pid=5165->guuid=795fc564-1c00-0000-0fc2-fbf9ae140000 pid=5294 execve guuid=956f4365-1c00-0000-0fc2-fbf9af140000 pid=5295 /usr/bin/rm delete-file guuid=48932c7b-1900-0000-0fc2-fbf92d140000 pid=5165->guuid=956f4365-1c00-0000-0fc2-fbf9af140000 pid=5295 execve guuid=f924f288-1900-0000-0fc2-fbf939140000 pid=5177 /tmp/.exectest.5165 guuid=d8ade188-1900-0000-0fc2-fbf938140000 pid=5176->guuid=f924f288-1900-0000-0fc2-fbf939140000 pid=5177 execve 859a4cbe-44a6-5949-a757-ee7cf89fbd69 91.239.211.89:80 guuid=5f08d08a-1900-0000-0fc2-fbf93d140000 pid=5181->859a4cbe-44a6-5949-a757-ee7cf89fbd69 send: 141B guuid=f1d42c91-1900-0000-0fc2-fbf93f140000 pid=5183 /usr/bin/wc guuid=aa771b91-1900-0000-0fc2-fbf93e140000 pid=5182->guuid=f1d42c91-1900-0000-0fc2-fbf93f140000 pid=5183 execve guuid=25ff3692-1900-0000-0fc2-fbf942140000 pid=5186 /usr/bin/wc guuid=4e892792-1900-0000-0fc2-fbf941140000 pid=5185->guuid=25ff3692-1900-0000-0fc2-fbf942140000 pid=5186 execve guuid=98936297-1900-0000-0fc2-fbf94a140000 pid=5194 /tmp/.d zombie guuid=f1504f94-1900-0000-0fc2-fbf947140000 pid=5191->guuid=98936297-1900-0000-0fc2-fbf94a140000 pid=5194 clone guuid=5f3c6c97-1900-0000-0fc2-fbf94b140000 pid=5195 /tmp/.d delete-file net send-data write-config write-file zombie guuid=98936297-1900-0000-0fc2-fbf94a140000 pid=5194->guuid=5f3c6c97-1900-0000-0fc2-fbf94b140000 pid=5195 clone ffee5cfb-bb94-52c2-8935-ae3a87e774db 127.0.0.1:42780 guuid=5f3c6c97-1900-0000-0fc2-fbf94b140000 pid=5195->ffee5cfb-bb94-52c2-8935-ae3a87e774db con 0a8043c9-917f-591f-8444-89639bba3210 91.239.211.89:8000 guuid=5f3c6c97-1900-0000-0fc2-fbf94b140000 pid=5195->0a8043c9-917f-591f-8444-89639bba3210 send: 272B 54d92a3b-1447-55af-b534-047898c60c8d 1.1.1.1:53 guuid=5f3c6c97-1900-0000-0fc2-fbf94b140000 pid=5195->54d92a3b-1447-55af-b534-047898c60c8d send: 80B guuid=5f3c6c97-1900-0000-0fc2-fbf94b140000 pid=5196 /tmp/.d guuid=5f3c6c97-1900-0000-0fc2-fbf94b140000 pid=5195->guuid=5f3c6c97-1900-0000-0fc2-fbf94b140000 pid=5196 clone guuid=b05a8899-1900-0000-0fc2-fbf94d140000 pid=5197 /usr/bin/dash guuid=5f3c6c97-1900-0000-0fc2-fbf94b140000 pid=5195->guuid=b05a8899-1900-0000-0fc2-fbf94d140000 pid=5197 execve guuid=7f779bce-1900-0000-0fc2-fbf963140000 pid=5219 /usr/bin/dash guuid=5f3c6c97-1900-0000-0fc2-fbf94b140000 pid=5195->guuid=7f779bce-1900-0000-0fc2-fbf963140000 pid=5219 execve guuid=16522a18-1a00-0000-0fc2-fbf984140000 pid=5252 /usr/bin/dash guuid=5f3c6c97-1900-0000-0fc2-fbf94b140000 pid=5195->guuid=16522a18-1a00-0000-0fc2-fbf984140000 pid=5252 execve guuid=e92a8b18-1a00-0000-0fc2-fbf986140000 pid=5254 /usr/bin/dash guuid=5f3c6c97-1900-0000-0fc2-fbf94b140000 pid=5195->guuid=e92a8b18-1a00-0000-0fc2-fbf986140000 pid=5254 execve guuid=5f3c6c97-1900-0000-0fc2-fbf94b140000 pid=5256 /tmp/.d guuid=5f3c6c97-1900-0000-0fc2-fbf94b140000 pid=5195->guuid=5f3c6c97-1900-0000-0fc2-fbf94b140000 pid=5256 clone guuid=c699bd99-1900-0000-0fc2-fbf94e140000 pid=5198 /usr/bin/systemctl guuid=b05a8899-1900-0000-0fc2-fbf94d140000 pid=5197->guuid=c699bd99-1900-0000-0fc2-fbf94e140000 pid=5198 execve guuid=f1b5cfce-1900-0000-0fc2-fbf964140000 pid=5220 /usr/bin/systemctl guuid=7f779bce-1900-0000-0fc2-fbf963140000 pid=5219->guuid=f1b5cfce-1900-0000-0fc2-fbf964140000 pid=5220 execve guuid=683e6118-1a00-0000-0fc2-fbf985140000 pid=5253 /usr/bin/dash guuid=16522a18-1a00-0000-0fc2-fbf984140000 pid=5252->guuid=683e6118-1a00-0000-0fc2-fbf985140000 pid=5253 clone guuid=c392b918-1a00-0000-0fc2-fbf987140000 pid=5255 /usr/bin/dash guuid=e92a8b18-1a00-0000-0fc2-fbf986140000 pid=5254->guuid=c392b918-1a00-0000-0fc2-fbf987140000 pid=5255 clone guuid=d3edb361-1c00-0000-0fc2-fbf9a9140000 pid=5289->ffee5cfb-bb94-52c2-8935-ae3a87e774db send: 1B
Result
Malware family:
n/a
Score:
  7/10
Tags:
antivm defense_evasion discovery execution linux persistence privilege_escalation upx
Behaviour
Enumerates kernel/hardware configuration
Reads runtime system information
System Network Configuration Discovery
Writes file to shm directory
Writes file to tmp directory
Changes its process name
Checks CPU configuration
Reads system network configuration
UPX packed file
Creates/modifies Cron job
Enumerates active TCP sockets
Enumerates running processes
Modifies systemd
Reads MAC address of network interface
File and Directory Permissions Modification
Deletes itself
Executes dropped EXE
Modifies Watchdog functionality
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh ea2b1c6fa88da27a58e92ee93b752180fb6ca0badb297c3771a0f0adb4e49f0b

(this sample)

  
Delivery method
Distributed via web download

Comments