MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f30e03097ae62592bb401cd68745c6b9bfa66a7bb06458adbabe499a9af635af. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: f30e03097ae62592bb401cd68745c6b9bfa66a7bb06458adbabe499a9af635af
SHA3-384 hash: a0b13fdbe20f68450e9a2e7a3496f74c8b7ad9f69f9c3a88dddc21e8c325930620a2036a4f33536e8187f8d9b440445d
SHA1 hash: e8534b86c44e04e9acfaa1d6a2bcfb1fd1268aa0
MD5 hash: 034a16eaeb79fa985f09d0e2eabdd759
humanhash: tennis-mirror-cold-carolina
File name:tbk
Download: download sample
File size:661 bytes
First seen:2026-08-06 13:47:32 UTC
Last seen:2026-08-06 13:59:55 UTC
File type: sh
MIME type:text/plain
ssdeep 6:B2FrB2GLp0TFrAAz4ARFFFrI0eFK0K70TFrlfzCWkSn+uB0FrB2GLviLFrAAzNFv:BynZoF5ewEOWNn+08nviKkewtgZt+JGy
TLSH T1EA01D6DE03225551F094AF15B3A14DAA83CFAE8C21A82F8D7C770AD3044DCB8B101B9B
Magika txt
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://103.83.86.215/n2/armv5ln/an/aarm elf ua-wget

Intelligence


File Origin
# of uploads :
7
# of downloads :
36
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
busybox downloader evasive
Status:
terminated
Behavior Graph:
%3 guuid=6b816eea-1600-0000-019b-4e21360d0000 pid=3382 /usr/bin/sudo guuid=94cd36ee-1600-0000-019b-4e213f0d0000 pid=3391 /tmp/sample.bin guuid=6b816eea-1600-0000-019b-4e21360d0000 pid=3382->guuid=94cd36ee-1600-0000-019b-4e213f0d0000 pid=3391 execve guuid=2dd683ef-1600-0000-019b-4e21410d0000 pid=3393 /usr/bin/wget net send-data write-file guuid=94cd36ee-1600-0000-019b-4e213f0d0000 pid=3391->guuid=2dd683ef-1600-0000-019b-4e21410d0000 pid=3393 execve guuid=57a2ab03-1700-0000-019b-4e21640d0000 pid=3428 /usr/bin/chmod guuid=94cd36ee-1600-0000-019b-4e213f0d0000 pid=3391->guuid=57a2ab03-1700-0000-019b-4e21640d0000 pid=3428 execve guuid=909ff103-1700-0000-019b-4e21660d0000 pid=3430 /usr/bin/dash guuid=94cd36ee-1600-0000-019b-4e213f0d0000 pid=3391->guuid=909ff103-1700-0000-019b-4e21660d0000 pid=3430 clone guuid=b2e7aa04-1700-0000-019b-4e21690d0000 pid=3433 /usr/bin/wget net send-data write-file guuid=94cd36ee-1600-0000-019b-4e213f0d0000 pid=3391->guuid=b2e7aa04-1700-0000-019b-4e21690d0000 pid=3433 execve guuid=a8fb9614-1700-0000-019b-4e21890d0000 pid=3465 /usr/bin/chmod guuid=94cd36ee-1600-0000-019b-4e213f0d0000 pid=3391->guuid=a8fb9614-1700-0000-019b-4e21890d0000 pid=3465 execve guuid=c26f2115-1700-0000-019b-4e218b0d0000 pid=3467 /usr/bin/dash guuid=94cd36ee-1600-0000-019b-4e213f0d0000 pid=3391->guuid=c26f2115-1700-0000-019b-4e218b0d0000 pid=3467 clone guuid=df504d16-1700-0000-019b-4e218e0d0000 pid=3470 /usr/bin/wget net send-data write-file guuid=94cd36ee-1600-0000-019b-4e213f0d0000 pid=3391->guuid=df504d16-1700-0000-019b-4e218e0d0000 pid=3470 execve guuid=e591f125-1700-0000-019b-4e21a40d0000 pid=3492 /usr/bin/chmod guuid=94cd36ee-1600-0000-019b-4e213f0d0000 pid=3391->guuid=e591f125-1700-0000-019b-4e21a40d0000 pid=3492 execve guuid=20643d26-1700-0000-019b-4e21a50d0000 pid=3493 /dev/x86 net guuid=94cd36ee-1600-0000-019b-4e213f0d0000 pid=3391->guuid=20643d26-1700-0000-019b-4e21a50d0000 pid=3493 execve guuid=d763ea2a-1700-0000-019b-4e21af0d0000 pid=3503 /usr/bin/wget net send-data write-file guuid=94cd36ee-1600-0000-019b-4e213f0d0000 pid=3391->guuid=d763ea2a-1700-0000-019b-4e21af0d0000 pid=3503 execve guuid=72d53c3b-1700-0000-019b-4e21d30d0000 pid=3539 /usr/bin/chmod guuid=94cd36ee-1600-0000-019b-4e213f0d0000 pid=3391->guuid=72d53c3b-1700-0000-019b-4e21d30d0000 pid=3539 execve guuid=0e78a13b-1700-0000-019b-4e21d50d0000 pid=3541 /usr/bin/dash guuid=94cd36ee-1600-0000-019b-4e213f0d0000 pid=3391->guuid=0e78a13b-1700-0000-019b-4e21d50d0000 pid=3541 clone guuid=a691843c-1700-0000-019b-4e21d90d0000 pid=3545 /usr/bin/rm delete-file guuid=94cd36ee-1600-0000-019b-4e213f0d0000 pid=3391->guuid=a691843c-1700-0000-019b-4e21d90d0000 pid=3545 execve guuid=2aa2fc3c-1700-0000-019b-4e21dc0d0000 pid=3548 /usr/bin/busybox net send-data write-file guuid=94cd36ee-1600-0000-019b-4e213f0d0000 pid=3391->guuid=2aa2fc3c-1700-0000-019b-4e21dc0d0000 pid=3548 execve guuid=dd27514d-1700-0000-019b-4e210a0e0000 pid=3594 /usr/bin/chmod guuid=94cd36ee-1600-0000-019b-4e213f0d0000 pid=3391->guuid=dd27514d-1700-0000-019b-4e210a0e0000 pid=3594 execve guuid=9b88924d-1700-0000-019b-4e210b0e0000 pid=3595 /usr/bin/dash guuid=94cd36ee-1600-0000-019b-4e213f0d0000 pid=3391->guuid=9b88924d-1700-0000-019b-4e210b0e0000 pid=3595 clone guuid=94b3574e-1700-0000-019b-4e21100e0000 pid=3600 /usr/bin/busybox net send-data write-file guuid=94cd36ee-1600-0000-019b-4e213f0d0000 pid=3391->guuid=94b3574e-1700-0000-019b-4e21100e0000 pid=3600 execve guuid=4052545c-1700-0000-019b-4e21450e0000 pid=3653 /usr/bin/chmod guuid=94cd36ee-1600-0000-019b-4e213f0d0000 pid=3391->guuid=4052545c-1700-0000-019b-4e21450e0000 pid=3653 execve guuid=53a6c55c-1700-0000-019b-4e21470e0000 pid=3655 /usr/bin/dash guuid=94cd36ee-1600-0000-019b-4e213f0d0000 pid=3391->guuid=53a6c55c-1700-0000-019b-4e21470e0000 pid=3655 clone guuid=0ea6305e-1700-0000-019b-4e214c0e0000 pid=3660 /usr/bin/busybox net send-data write-file guuid=94cd36ee-1600-0000-019b-4e213f0d0000 pid=3391->guuid=0ea6305e-1700-0000-019b-4e214c0e0000 pid=3660 execve guuid=8076ba71-1700-0000-019b-4e21860e0000 pid=3718 /usr/bin/chmod guuid=94cd36ee-1600-0000-019b-4e213f0d0000 pid=3391->guuid=8076ba71-1700-0000-019b-4e21860e0000 pid=3718 execve guuid=d20a2c72-1700-0000-019b-4e21880e0000 pid=3720 /dev/x86 net guuid=94cd36ee-1600-0000-019b-4e213f0d0000 pid=3391->guuid=d20a2c72-1700-0000-019b-4e21880e0000 pid=3720 execve guuid=d82e0d78-1700-0000-019b-4e21950e0000 pid=3733 /usr/bin/busybox net send-data write-file guuid=94cd36ee-1600-0000-019b-4e213f0d0000 pid=3391->guuid=d82e0d78-1700-0000-019b-4e21950e0000 pid=3733 execve guuid=4f79d285-1700-0000-019b-4e21bf0e0000 pid=3775 /usr/bin/chmod guuid=94cd36ee-1600-0000-019b-4e213f0d0000 pid=3391->guuid=4f79d285-1700-0000-019b-4e21bf0e0000 pid=3775 execve guuid=c92b7d86-1700-0000-019b-4e21c10e0000 pid=3777 /usr/bin/dash guuid=94cd36ee-1600-0000-019b-4e213f0d0000 pid=3391->guuid=c92b7d86-1700-0000-019b-4e21c10e0000 pid=3777 clone guuid=c6be2588-1700-0000-019b-4e21c90e0000 pid=3785 /usr/bin/rm delete-file guuid=94cd36ee-1600-0000-019b-4e213f0d0000 pid=3391->guuid=c6be2588-1700-0000-019b-4e21c90e0000 pid=3785 execve 7f92713c-8f9e-5eb7-b970-9ec612fa7ab9 103.83.86.215:80 guuid=2dd683ef-1600-0000-019b-4e21410d0000 pid=3393->7f92713c-8f9e-5eb7-b970-9ec612fa7ab9 send: 135B guuid=b2e7aa04-1700-0000-019b-4e21690d0000 pid=3433->7f92713c-8f9e-5eb7-b970-9ec612fa7ab9 send: 135B guuid=df504d16-1700-0000-019b-4e218e0d0000 pid=3470->7f92713c-8f9e-5eb7-b970-9ec612fa7ab9 send: 134B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=20643d26-1700-0000-019b-4e21a50d0000 pid=3493->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=5e54db2a-1700-0000-019b-4e21ae0d0000 pid=3502 /dev/x86 dns net send-data zombie guuid=20643d26-1700-0000-019b-4e21a50d0000 pid=3493->guuid=5e54db2a-1700-0000-019b-4e21ae0d0000 pid=3502 clone guuid=5e54db2a-1700-0000-019b-4e21ae0d0000 pid=3502->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con 54d92a3b-1447-55af-b534-047898c60c8d 1.1.1.1:53 guuid=5e54db2a-1700-0000-019b-4e21ae0d0000 pid=3502->54d92a3b-1447-55af-b534-047898c60c8d send: 31B 33bc2458-f65c-5f09-9812-ce59832687a4 216.9.226.211:80 guuid=5e54db2a-1700-0000-019b-4e21ae0d0000 pid=3502->33bc2458-f65c-5f09-9812-ce59832687a4 send: 4B 7d2225dc-879f-55ba-bcd4-4ed0de8d670c 216.9.226.211:123 guuid=5e54db2a-1700-0000-019b-4e21ae0d0000 pid=3502->7d2225dc-879f-55ba-bcd4-4ed0de8d670c send: 146B 79fe191c-2dcd-580d-8b00-a652ea3954da 216.9.226.211:0 guuid=5e54db2a-1700-0000-019b-4e21ae0d0000 pid=3502->79fe191c-2dcd-580d-8b00-a652ea3954da send: 64B guuid=e62f052b-1700-0000-019b-4e21b00d0000 pid=3504 /dev/x86 guuid=5e54db2a-1700-0000-019b-4e21ae0d0000 pid=3502->guuid=e62f052b-1700-0000-019b-4e21b00d0000 pid=3504 clone guuid=ac868867-1f00-0000-019b-4e213e140000 pid=5182 /dev/x86 guuid=5e54db2a-1700-0000-019b-4e21ae0d0000 pid=3502->guuid=ac868867-1f00-0000-019b-4e213e140000 pid=5182 clone guuid=d763ea2a-1700-0000-019b-4e21af0d0000 pid=3503->7f92713c-8f9e-5eb7-b970-9ec612fa7ab9 send: 137B guuid=3bc5ad2b-1700-0000-019b-4e21b20d0000 pid=3506 /dev/x86 send-data guuid=e62f052b-1700-0000-019b-4e21b00d0000 pid=3504->guuid=3bc5ad2b-1700-0000-019b-4e21b20d0000 pid=3506 clone 119fdfbb-af05-553e-93e0-4a8214b03fe0 127.0.0.1:58012 guuid=3bc5ad2b-1700-0000-019b-4e21b20d0000 pid=3506->119fdfbb-af05-553e-93e0-4a8214b03fe0 send: 1B guuid=2aa2fc3c-1700-0000-019b-4e21dc0d0000 pid=3548->7f92713c-8f9e-5eb7-b970-9ec612fa7ab9 send: 83B guuid=94b3574e-1700-0000-019b-4e21100e0000 pid=3600->7f92713c-8f9e-5eb7-b970-9ec612fa7ab9 send: 83B guuid=0ea6305e-1700-0000-019b-4e214c0e0000 pid=3660->7f92713c-8f9e-5eb7-b970-9ec612fa7ab9 send: 82B guuid=d20a2c72-1700-0000-019b-4e21880e0000 pid=3720->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=ace40278-1700-0000-019b-4e21930e0000 pid=3731 /dev/x86 net send-data zombie guuid=d20a2c72-1700-0000-019b-4e21880e0000 pid=3720->guuid=ace40278-1700-0000-019b-4e21930e0000 pid=3731 clone 307db2dd-32a0-52fe-a412-5478b0ff6eae 127.0.0.1:63464 guuid=ace40278-1700-0000-019b-4e21930e0000 pid=3731->307db2dd-32a0-52fe-a412-5478b0ff6eae send: 2B guuid=d82e0d78-1700-0000-019b-4e21950e0000 pid=3733->7f92713c-8f9e-5eb7-b970-9ec612fa7ab9 send: 85B guuid=1e2e9767-1f00-0000-019b-4e213f140000 pid=5183 /dev/x86 send-data zombie guuid=ac868867-1f00-0000-019b-4e213e140000 pid=5182->guuid=1e2e9767-1f00-0000-019b-4e213f140000 pid=5183 clone guuid=7ca39c67-1f00-0000-019b-4e2140140000 pid=5184 /dev/x86 guuid=ac868867-1f00-0000-019b-4e213e140000 pid=5182->guuid=7ca39c67-1f00-0000-019b-4e2140140000 pid=5184 clone 9aca0e4f-d95f-5be2-8025-e754069a0d44 31.77.227.128:80 guuid=1e2e9767-1f00-0000-019b-4e213f140000 pid=5183->9aca0e4f-d95f-5be2-8025-e754069a0d44 send: 262208B
Threat name:
Script-BAT.Downloader.Heuristic
Status:
Malicious
First seen:
2026-08-06 14:01:59 UTC
File Type:
Text (Shell)
AV detection:
6 of 36 (16.67%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
execution
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Executes a command shell one-liner
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh f30e03097ae62592bb401cd68745c6b9bfa66a7bb06458adbabe499a9af635af

(this sample)

  
Delivery method
Distributed via web download

Comments