MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 fab37cff9ba659a31e49083ed0a2ed9bab15925b122bf5b1bb0dce7ab33b54a2. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: fab37cff9ba659a31e49083ed0a2ed9bab15925b122bf5b1bb0dce7ab33b54a2
SHA3-384 hash: 89ce169e9874744b621efa06ad49f10b2328021e315a0783f03d59e24f7328ea43d6bd0924252da3d4819ade9feb2249
SHA1 hash: a124ecda899bec12bd9ef897451e725a39c6c0c9
MD5 hash: aefc0f1cd486cd1a1e0244b18f0e7588
humanhash: august-ink-artist-london
File name:run.sh
Download: download sample
File size:410 bytes
First seen:2026-05-05 00:05:44 UTC
Last seen:2026-05-05 15:27:53 UTC
File type: sh
MIME type:text/plain
ssdeep 12:OGG6fPa96fP26fP16fPz6fPl6fPv6fP+6fPBD2EHxn:I+y9+u+t+b+N+3+2+JqEHxn
TLSH T147E075C5D1C4B153E5AAFA94BB79A28CA20552D754FE2F1ECE413861DD88860F157702
Magika txt
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://176.65.139.166/ppc64n/an/a176-65-139-166 elf ua-wget

Intelligence


File Origin
# of uploads :
2
# of downloads :
46
Origin country :
DE DE
Vendor Threat Intelligence
Gathering data
Result
Gathering data
Status:
terminated
Behavior Graph:
%3 guuid=e68c390f-1700-0000-5c51-3c63b50d0000 pid=3509 /usr/bin/sudo guuid=087cc111-1700-0000-5c51-3c63bd0d0000 pid=3517 /tmp/sample.bin guuid=e68c390f-1700-0000-5c51-3c63b50d0000 pid=3509->guuid=087cc111-1700-0000-5c51-3c63bd0d0000 pid=3517 execve guuid=28290c12-1700-0000-5c51-3c63bf0d0000 pid=3519 /usr/bin/curl net send-data write-file guuid=087cc111-1700-0000-5c51-3c63bd0d0000 pid=3517->guuid=28290c12-1700-0000-5c51-3c63bf0d0000 pid=3519 execve guuid=14cc6522-1700-0000-5c51-3c63ec0d0000 pid=3564 /usr/bin/curl net send-data write-file guuid=087cc111-1700-0000-5c51-3c63bd0d0000 pid=3517->guuid=14cc6522-1700-0000-5c51-3c63ec0d0000 pid=3564 execve guuid=0768a525-1700-0000-5c51-3c63f90d0000 pid=3577 /usr/bin/curl net send-data write-file guuid=087cc111-1700-0000-5c51-3c63bd0d0000 pid=3517->guuid=0768a525-1700-0000-5c51-3c63f90d0000 pid=3577 execve guuid=45cdc028-1700-0000-5c51-3c63040e0000 pid=3588 /usr/bin/curl net send-data write-file guuid=087cc111-1700-0000-5c51-3c63bd0d0000 pid=3517->guuid=45cdc028-1700-0000-5c51-3c63040e0000 pid=3588 execve guuid=c6ebe32b-1700-0000-5c51-3c630e0e0000 pid=3598 /usr/bin/curl net send-data write-file guuid=087cc111-1700-0000-5c51-3c63bd0d0000 pid=3517->guuid=c6ebe32b-1700-0000-5c51-3c630e0e0000 pid=3598 execve guuid=8e827c45-1700-0000-5c51-3c63480e0000 pid=3656 /usr/bin/curl net send-data write-file guuid=087cc111-1700-0000-5c51-3c63bd0d0000 pid=3517->guuid=8e827c45-1700-0000-5c51-3c63480e0000 pid=3656 execve guuid=e2c1c968-1700-0000-5c51-3c637e0e0000 pid=3710 /usr/bin/curl net send-data write-file guuid=087cc111-1700-0000-5c51-3c63bd0d0000 pid=3517->guuid=e2c1c968-1700-0000-5c51-3c637e0e0000 pid=3710 execve guuid=15e89384-1700-0000-5c51-3c63d00e0000 pid=3792 /usr/bin/curl net send-data write-file guuid=087cc111-1700-0000-5c51-3c63bd0d0000 pid=3517->guuid=15e89384-1700-0000-5c51-3c63d00e0000 pid=3792 execve guuid=9fa453a2-1700-0000-5c51-3c632b0f0000 pid=3883 /usr/bin/chmod guuid=087cc111-1700-0000-5c51-3c63bd0d0000 pid=3517->guuid=9fa453a2-1700-0000-5c51-3c632b0f0000 pid=3883 execve guuid=69539aa2-1700-0000-5c51-3c632d0f0000 pid=3885 /tmp/x86 guuid=087cc111-1700-0000-5c51-3c63bd0d0000 pid=3517->guuid=69539aa2-1700-0000-5c51-3c632d0f0000 pid=3885 execve guuid=690d44a8-1700-0000-5c51-3c634c0f0000 pid=3916 /tmp/armv51 guuid=087cc111-1700-0000-5c51-3c63bd0d0000 pid=3517->guuid=690d44a8-1700-0000-5c51-3c634c0f0000 pid=3916 execve guuid=2f7d86a9-1700-0000-5c51-3c634f0f0000 pid=3919 /tmp/armv61 guuid=087cc111-1700-0000-5c51-3c63bd0d0000 pid=3517->guuid=2f7d86a9-1700-0000-5c51-3c634f0f0000 pid=3919 execve guuid=6f0acba9-1700-0000-5c51-3c63510f0000 pid=3921 /usr/bin/dash guuid=087cc111-1700-0000-5c51-3c63bd0d0000 pid=3517->guuid=6f0acba9-1700-0000-5c51-3c63510f0000 pid=3921 clone guuid=b1d1e4a9-1700-0000-5c51-3c63520f0000 pid=3922 /usr/bin/dash guuid=087cc111-1700-0000-5c51-3c63bd0d0000 pid=3517->guuid=b1d1e4a9-1700-0000-5c51-3c63520f0000 pid=3922 clone guuid=ca52f3aa-1700-0000-5c51-3c63570f0000 pid=3927 /usr/bin/dash guuid=087cc111-1700-0000-5c51-3c63bd0d0000 pid=3517->guuid=ca52f3aa-1700-0000-5c51-3c63570f0000 pid=3927 clone guuid=9207a4ab-1700-0000-5c51-3c635b0f0000 pid=3931 /usr/bin/dash guuid=087cc111-1700-0000-5c51-3c63bd0d0000 pid=3517->guuid=9207a4ab-1700-0000-5c51-3c635b0f0000 pid=3931 clone guuid=63d939ac-1700-0000-5c51-3c63600f0000 pid=3936 /tmp/i686 guuid=087cc111-1700-0000-5c51-3c63bd0d0000 pid=3517->guuid=63d939ac-1700-0000-5c51-3c63600f0000 pid=3936 execve 0bc49f61-5032-5c95-88ba-1a2ccc1056b3 176.65.139.166:80 guuid=28290c12-1700-0000-5c51-3c63bf0d0000 pid=3519->0bc49f61-5032-5c95-88ba-1a2ccc1056b3 send: 81B guuid=14cc6522-1700-0000-5c51-3c63ec0d0000 pid=3564->0bc49f61-5032-5c95-88ba-1a2ccc1056b3 send: 84B guuid=0768a525-1700-0000-5c51-3c63f90d0000 pid=3577->0bc49f61-5032-5c95-88ba-1a2ccc1056b3 send: 84B guuid=45cdc028-1700-0000-5c51-3c63040e0000 pid=3588->0bc49f61-5032-5c95-88ba-1a2ccc1056b3 send: 83B guuid=c6ebe32b-1700-0000-5c51-3c630e0e0000 pid=3598->0bc49f61-5032-5c95-88ba-1a2ccc1056b3 send: 82B guuid=8e827c45-1700-0000-5c51-3c63480e0000 pid=3656->0bc49f61-5032-5c95-88ba-1a2ccc1056b3 send: 82B guuid=e2c1c968-1700-0000-5c51-3c637e0e0000 pid=3710->0bc49f61-5032-5c95-88ba-1a2ccc1056b3 send: 84B guuid=15e89384-1700-0000-5c51-3c63d00e0000 pid=3792->0bc49f61-5032-5c95-88ba-1a2ccc1056b3 send: 83B guuid=69539aa2-1700-0000-5c51-3c632d0f0000 pid=3904 /tmp/x86 guuid=69539aa2-1700-0000-5c51-3c632d0f0000 pid=3885->guuid=69539aa2-1700-0000-5c51-3c632d0f0000 pid=3904 clone guuid=69539aa2-1700-0000-5c51-3c632d0f0000 pid=3905 /tmp/x86 guuid=69539aa2-1700-0000-5c51-3c632d0f0000 pid=3885->guuid=69539aa2-1700-0000-5c51-3c632d0f0000 pid=3905 clone guuid=69539aa2-1700-0000-5c51-3c632d0f0000 pid=3906 /tmp/x86 guuid=69539aa2-1700-0000-5c51-3c632d0f0000 pid=3885->guuid=69539aa2-1700-0000-5c51-3c632d0f0000 pid=3906 clone guuid=69539aa2-1700-0000-5c51-3c632d0f0000 pid=3908 /tmp/x86 guuid=69539aa2-1700-0000-5c51-3c632d0f0000 pid=3885->guuid=69539aa2-1700-0000-5c51-3c632d0f0000 pid=3908 clone guuid=69539aa2-1700-0000-5c51-3c632d0f0000 pid=3910 /tmp/x86 guuid=69539aa2-1700-0000-5c51-3c632d0f0000 pid=3885->guuid=69539aa2-1700-0000-5c51-3c632d0f0000 pid=3910 clone guuid=0d18a0a7-1700-0000-5c51-3c63470f0000 pid=3911 /tmp/x86 guuid=69539aa2-1700-0000-5c51-3c632d0f0000 pid=3885->guuid=0d18a0a7-1700-0000-5c51-3c63470f0000 pid=3911 clone guuid=3b10aaa7-1700-0000-5c51-3c63480f0000 pid=3912 /tmp/x86 zombie guuid=69539aa2-1700-0000-5c51-3c632d0f0000 pid=3885->guuid=3b10aaa7-1700-0000-5c51-3c63480f0000 pid=3912 execve guuid=3b10aaa7-1700-0000-5c51-3c63480f0000 pid=3937 /tmp/x86 zombie guuid=3b10aaa7-1700-0000-5c51-3c63480f0000 pid=3912->guuid=3b10aaa7-1700-0000-5c51-3c63480f0000 pid=3937 clone guuid=3b10aaa7-1700-0000-5c51-3c63480f0000 pid=3938 /tmp/x86 guuid=3b10aaa7-1700-0000-5c51-3c63480f0000 pid=3912->guuid=3b10aaa7-1700-0000-5c51-3c63480f0000 pid=3938 clone guuid=3b10aaa7-1700-0000-5c51-3c63480f0000 pid=3939 /tmp/x86 guuid=3b10aaa7-1700-0000-5c51-3c63480f0000 pid=3912->guuid=3b10aaa7-1700-0000-5c51-3c63480f0000 pid=3939 clone guuid=3b10aaa7-1700-0000-5c51-3c63480f0000 pid=3940 /tmp/x86 net zombie guuid=3b10aaa7-1700-0000-5c51-3c63480f0000 pid=3912->guuid=3b10aaa7-1700-0000-5c51-3c63480f0000 pid=3940 clone guuid=3b10aaa7-1700-0000-5c51-3c63480f0000 pid=3941 /tmp/x86 guuid=3b10aaa7-1700-0000-5c51-3c63480f0000 pid=3912->guuid=3b10aaa7-1700-0000-5c51-3c63480f0000 pid=3941 clone guuid=3b10aaa7-1700-0000-5c51-3c63480f0000 pid=3942 /tmp/x86 send-data zombie guuid=3b10aaa7-1700-0000-5c51-3c63480f0000 pid=3912->guuid=3b10aaa7-1700-0000-5c51-3c63480f0000 pid=3942 clone guuid=3b10aaa7-1700-0000-5c51-3c63480f0000 pid=3948 /tmp/x86 guuid=3b10aaa7-1700-0000-5c51-3c63480f0000 pid=3912->guuid=3b10aaa7-1700-0000-5c51-3c63480f0000 pid=3948 clone guuid=3b10aaa7-1700-0000-5c51-3c63480f0000 pid=3949 /tmp/x86 guuid=3b10aaa7-1700-0000-5c51-3c63480f0000 pid=3912->guuid=3b10aaa7-1700-0000-5c51-3c63480f0000 pid=3949 clone guuid=63d939ac-1700-0000-5c51-3c63600f0000 pid=3957 /tmp/i686 guuid=63d939ac-1700-0000-5c51-3c63600f0000 pid=3936->guuid=63d939ac-1700-0000-5c51-3c63600f0000 pid=3957 clone guuid=63d939ac-1700-0000-5c51-3c63600f0000 pid=3958 /tmp/i686 guuid=63d939ac-1700-0000-5c51-3c63600f0000 pid=3936->guuid=63d939ac-1700-0000-5c51-3c63600f0000 pid=3958 clone guuid=63d939ac-1700-0000-5c51-3c63600f0000 pid=3959 /tmp/i686 guuid=63d939ac-1700-0000-5c51-3c63600f0000 pid=3936->guuid=63d939ac-1700-0000-5c51-3c63600f0000 pid=3959 clone guuid=63d939ac-1700-0000-5c51-3c63600f0000 pid=3960 /tmp/i686 guuid=63d939ac-1700-0000-5c51-3c63600f0000 pid=3936->guuid=63d939ac-1700-0000-5c51-3c63600f0000 pid=3960 clone guuid=3b6cfbb0-1700-0000-5c51-3c63790f0000 pid=3961 /tmp/i686 guuid=63d939ac-1700-0000-5c51-3c63600f0000 pid=3936->guuid=3b6cfbb0-1700-0000-5c51-3c63790f0000 pid=3961 clone guuid=63d939ac-1700-0000-5c51-3c63600f0000 pid=3962 /tmp/i686 guuid=63d939ac-1700-0000-5c51-3c63600f0000 pid=3936->guuid=63d939ac-1700-0000-5c51-3c63600f0000 pid=3962 clone guuid=0e7c12b1-1700-0000-5c51-3c637c0f0000 pid=3964 /tmp/i686 zombie guuid=63d939ac-1700-0000-5c51-3c63600f0000 pid=3936->guuid=0e7c12b1-1700-0000-5c51-3c637c0f0000 pid=3964 execve 0bc42a23-7bc1-5f77-ad43-b9ae8823e62e 176.65.139.166:9111 guuid=3b10aaa7-1700-0000-5c51-3c63480f0000 pid=3940->0bc42a23-7bc1-5f77-ad43-b9ae8823e62e con guuid=3b10aaa7-1700-0000-5c51-3c63480f0000 pid=3942->0bc42a23-7bc1-5f77-ad43-b9ae8823e62e send: 21B guuid=0e7c12b1-1700-0000-5c51-3c637c0f0000 pid=3980 /tmp/i686 zombie guuid=0e7c12b1-1700-0000-5c51-3c637c0f0000 pid=3964->guuid=0e7c12b1-1700-0000-5c51-3c637c0f0000 pid=3980 clone guuid=0e7c12b1-1700-0000-5c51-3c637c0f0000 pid=3981 /tmp/i686 send-data zombie guuid=0e7c12b1-1700-0000-5c51-3c637c0f0000 pid=3964->guuid=0e7c12b1-1700-0000-5c51-3c637c0f0000 pid=3981 clone guuid=0e7c12b1-1700-0000-5c51-3c637c0f0000 pid=3982 /tmp/i686 zombie guuid=0e7c12b1-1700-0000-5c51-3c637c0f0000 pid=3964->guuid=0e7c12b1-1700-0000-5c51-3c637c0f0000 pid=3982 clone guuid=0e7c12b1-1700-0000-5c51-3c637c0f0000 pid=3983 /tmp/i686 send-data zombie guuid=0e7c12b1-1700-0000-5c51-3c637c0f0000 pid=3964->guuid=0e7c12b1-1700-0000-5c51-3c637c0f0000 pid=3983 clone guuid=0e7c12b1-1700-0000-5c51-3c637c0f0000 pid=3985 /tmp/i686 net send-data zombie guuid=0e7c12b1-1700-0000-5c51-3c637c0f0000 pid=3964->guuid=0e7c12b1-1700-0000-5c51-3c637c0f0000 pid=3985 clone guuid=0e7c12b1-1700-0000-5c51-3c637c0f0000 pid=3986 /tmp/i686 guuid=0e7c12b1-1700-0000-5c51-3c637c0f0000 pid=3964->guuid=0e7c12b1-1700-0000-5c51-3c637c0f0000 pid=3986 clone guuid=0e7c12b1-1700-0000-5c51-3c637c0f0000 pid=3988 /tmp/i686 guuid=0e7c12b1-1700-0000-5c51-3c637c0f0000 pid=3964->guuid=0e7c12b1-1700-0000-5c51-3c637c0f0000 pid=3988 clone guuid=0e7c12b1-1700-0000-5c51-3c637c0f0000 pid=3993 /tmp/i686 send-data zombie guuid=0e7c12b1-1700-0000-5c51-3c637c0f0000 pid=3964->guuid=0e7c12b1-1700-0000-5c51-3c637c0f0000 pid=3993 clone guuid=0e7c12b1-1700-0000-5c51-3c637c0f0000 pid=3994 /tmp/i686 send-data zombie guuid=0e7c12b1-1700-0000-5c51-3c637c0f0000 pid=3964->guuid=0e7c12b1-1700-0000-5c51-3c637c0f0000 pid=3994 clone guuid=0e7c12b1-1700-0000-5c51-3c637c0f0000 pid=3995 /tmp/i686 send-data zombie guuid=0e7c12b1-1700-0000-5c51-3c637c0f0000 pid=3964->guuid=0e7c12b1-1700-0000-5c51-3c637c0f0000 pid=3995 clone guuid=0e7c12b1-1700-0000-5c51-3c637c0f0000 pid=3981->0bc42a23-7bc1-5f77-ad43-b9ae8823e62e send: 2B guuid=0e7c12b1-1700-0000-5c51-3c637c0f0000 pid=3983->0bc42a23-7bc1-5f77-ad43-b9ae8823e62e send: 12B guuid=0e7c12b1-1700-0000-5c51-3c637c0f0000 pid=3985->0bc42a23-7bc1-5f77-ad43-b9ae8823e62e send: 5B guuid=0e7c12b1-1700-0000-5c51-3c637c0f0000 pid=3993->0bc42a23-7bc1-5f77-ad43-b9ae8823e62e send: 1B guuid=0e7c12b1-1700-0000-5c51-3c637c0f0000 pid=3994->0bc42a23-7bc1-5f77-ad43-b9ae8823e62e send: 5B guuid=0e7c12b1-1700-0000-5c51-3c637c0f0000 pid=3995->0bc42a23-7bc1-5f77-ad43-b9ae8823e62e send: 24B
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh fab37cff9ba659a31e49083ed0a2ed9bab15925b122bf5b1bb0dce7ab33b54a2

(this sample)

  
Delivery method
Distributed via web download

Comments