MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f8505ecdb2dea102e48973a66a771f82d35e8ae8034fd8fc592f36aab4c72a07. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: f8505ecdb2dea102e48973a66a771f82d35e8ae8034fd8fc592f36aab4c72a07
SHA3-384 hash: 5e390176eca55649c16f04e29e2a54111fc3491a9050ffaa94cefe84032d802e7fb3fd37ad91f0570b74ebeeafb0a820
SHA1 hash: 80e0fd139347d4798e44b06c985f7da179e94c8d
MD5 hash: 10acf9dd1ca1f4d368ce0814791e3ad3
humanhash: white-east-may-purple
File name:301l
Download: download sample
File size:295 bytes
First seen:2026-07-16 04:28:39 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 6:UqLqhR47DcKULt1cK8MNIzXzGMNIcK8MNQkYcK8MN25FTEX3:UquhRADEt1VQXAVIVsQ
TLSH T1D7E07200E6213E1426B5E90EC3C0930E523017F0B94CBEBD8AC6C6F10E640C3308DF94
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://144.172.103.226/301/tokenlinux.shn/an/aua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
65
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Unknown
Threat level:
  2.5/10
Confidence:
100%
Tags:
bash lolbin
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-07-16T01:47:00Z UTC
Last seen:
2026-07-17T19:40:00Z UTC
Hits:
~100
Status:
terminated
Behavior Graph:
%3 guuid=4735de0b-1b00-0000-9d2d-c00ee40b0000 pid=3044 /usr/bin/sudo guuid=8aa39a0e-1b00-0000-9d2d-c00ee80b0000 pid=3048 /tmp/sample.bin guuid=4735de0b-1b00-0000-9d2d-c00ee40b0000 pid=3044->guuid=8aa39a0e-1b00-0000-9d2d-c00ee80b0000 pid=3048 execve guuid=cb9c0d10-1b00-0000-9d2d-c00eec0b0000 pid=3052 /usr/bin/mkdir guuid=8aa39a0e-1b00-0000-9d2d-c00ee80b0000 pid=3048->guuid=cb9c0d10-1b00-0000-9d2d-c00eec0b0000 pid=3052 execve guuid=2450c710-1b00-0000-9d2d-c00eee0b0000 pid=3054 /usr/bin/clear guuid=8aa39a0e-1b00-0000-9d2d-c00ee80b0000 pid=3048->guuid=2450c710-1b00-0000-9d2d-c00eee0b0000 pid=3054 execve
Result
Malware family:
n/a
Score:
  3/10
Tags:
discovery linux
Behaviour
Reads runtime system information
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh f8505ecdb2dea102e48973a66a771f82d35e8ae8034fd8fc592f36aab4c72a07

(this sample)

  
Delivery method
Distributed via web download

Comments