MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f278a86c15f3bf05a94455387178aafa99e4b2aca3e23f1990ff81d22aa0fd0c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



JackSkid


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments

SHA256 hash: f278a86c15f3bf05a94455387178aafa99e4b2aca3e23f1990ff81d22aa0fd0c
SHA3-384 hash: 4f09884ea97bfa20495360ab912c7196e5d3777996a4efbcac58c0e03c35d42142ccf53d07ed7ba923a17a2a53ff5533
SHA1 hash: 9d33497c47e6aca2553a432429865c63f84644d2
MD5 hash: b3114235d4448fc85f6264904cee37b4
humanhash: batman-tango-alpha-five
File name:stager.sh
Download: download sample
Signature JackSkid
File size:606 bytes
First seen:2026-07-26 07:33:16 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 12:9pcgaOWpcgaOxcgaONyFQcgay2H5v+aQCROLvmPjwvmGSpvmPjm:94OW4OwOyyS5v+aQfbm8mGSZmC
TLSH T1C7F0786122B10E712E46086D16C36846611A0C443DF61DC6A2ED3860968F8AEE3A38AF
Magika shell
Reporter deepfield
Tags:ddos elf.jackskid jackskid rctea sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
63
Origin country :
FR FR
Vendor Threat Intelligence
No detections
Verdict:
Unknown
Threat level:
  2.5/10
Confidence:
100%
Tags:
busybox
Status:
terminated
Behavior Graph:
%3 guuid=5ab8bd67-1a00-0000-9e89-6d7ccb080000 pid=2251 /usr/bin/sudo guuid=46bf2f6a-1a00-0000-9e89-6d7cd2080000 pid=2258 /tmp/sample.bin guuid=5ab8bd67-1a00-0000-9e89-6d7ccb080000 pid=2251->guuid=46bf2f6a-1a00-0000-9e89-6d7cd2080000 pid=2258 execve guuid=e169946a-1a00-0000-9e89-6d7cd4080000 pid=2260 /usr/bin/dash guuid=46bf2f6a-1a00-0000-9e89-6d7cd2080000 pid=2258->guuid=e169946a-1a00-0000-9e89-6d7cd4080000 pid=2260 clone guuid=4b3ea26a-1a00-0000-9e89-6d7cd5080000 pid=2261 /usr/bin/dd guuid=46bf2f6a-1a00-0000-9e89-6d7cd2080000 pid=2258->guuid=4b3ea26a-1a00-0000-9e89-6d7cd5080000 pid=2261 execve guuid=8fec086f-1a00-0000-9e89-6d7cdd080000 pid=2269 /usr/bin/rm guuid=46bf2f6a-1a00-0000-9e89-6d7cd2080000 pid=2258->guuid=8fec086f-1a00-0000-9e89-6d7cdd080000 pid=2269 execve guuid=7d6cb76a-1a00-0000-9e89-6d7cd6080000 pid=2262 /usr/bin/busybox net guuid=e169946a-1a00-0000-9e89-6d7cd4080000 pid=2260->guuid=7d6cb76a-1a00-0000-9e89-6d7cd6080000 pid=2262 execve 92f94ca8-138c-5613-b8db-c06a787569d4 162.249.125.141:20198 guuid=7d6cb76a-1a00-0000-9e89-6d7cd6080000 pid=2262->92f94ca8-138c-5613-b8db-c06a787569d4 con
Gathering data
Result
Malware family:
n/a
Score:
  3/10
Tags:
execution
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Executes a command shell one-liner
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

  
Delivery method
Other

Comments