MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 fd3147e1b9394e7c063eb8086f82e2ddade915c4b5030d17865ff1a0e670488f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: fd3147e1b9394e7c063eb8086f82e2ddade915c4b5030d17865ff1a0e670488f
SHA3-384 hash: 25a2a19a82491577d3d4063d3921db417d67d2f680be42f22aa9be458289d32eba4bc58413be5effd403516c32cf5ac0
SHA1 hash: 81f4de90e8e382b4bac6823deccba19e151ae433
MD5 hash: 215a41eb865a93817294a573e3fbd9b2
humanhash: table-harry-echo-tango
File name:raw
Download: download sample
File size:34'200 bytes
First seen:2026-07-29 13:52:41 UTC
Last seen:2026-07-29 14:00:40 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 384:EUl5Bo43w8FUFtFZFC6ygcaZW/o6aIjDNG:Ew5Bo43w8aXFZYI6ZjDNG
TLSH T1CDE2D9B174099631329DEF2D18F5AC49A616718BF6204900F41F3AD90FFEB58FD681BA
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
https://api.resend.com/emailsn/an/an/a

Intelligence


File Origin
# of uploads :
2
# of downloads :
52
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Result
Malware family:
n/a
Score:
  8/10
Tags:
antivm credential_access discovery linux persistence privilege_escalation
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Checks CPU configuration
Looks up external IP address via web service
OS Credential Dumping
Adds new SSH keys
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh fd3147e1b9394e7c063eb8086f82e2ddade915c4b5030d17865ff1a0e670488f

(this sample)

  
Delivery method
Distributed via web download

Comments