MALICIOUS — 78d5460db4f6d3b4ea29595b7f8077d3aa73922fe33ce3a4f18547e73c02d60e.sh
MALICIOUS — 78d5460db4f6d3b4ea29595b7f8077d3aa73922fe33ce3a4f18547e73c02d60e.sh is a shell sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100), attributed to the Bash family. 2 of 51 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
78d5460db4f6d3b4ea29595b7f8077d3aa73922fe33ce3a4f18547e73c02d60e - SHA-1:
88f8eeefa2c5510464c062f983b41674a68cc28e - MD5:
50dd20682ce8c11ece4a3dc1e571b30b - ssdeep:
12:ZCVWp7Tyyy0yowq9Ov0GyVpoQGy76ULnI+yLd+JM+0RwbFUO:ZCC7Tyyy0ytq9Ov0GyVpoQ976ULI+c+R - TLSH:
T1B00FA0DC4FE392AAD8001230F0052CB9DEA3E0527AAA974350A1D1C4C2084D0E914EE8 - Submitted as: 78d5460db4f6d3b4ea29595b7f8077d3aa73922fe33ce3a4f18547e73c02d60e.sh
- File type: shell · Size: 451 bytes
- Verdict: malicious (98/100) · Family: Bash
Source: MalwareBazaar · first seen 2026-07-26T00:00:00.000Z · SHA-256 verified
Detections (2 of 51 engines)
- Emsisoft (Emergency Kit): Generic.Bash.MiraiB.9BBFEB0F
- Kaspersky (KVRT): HEUR:Trojan-Downloader.Shell.Agent.p
MITRE ATT&CK
Why this verdict
The malicious score of 98/100 is the fusion of 10 weighted signals:
- 1 behavioral detection(s): Download-and-execute dropper (wget/curl + chmod) [high] (rule
tl-linux-download-exec) - dynamic signal, weight 0.60, confidence 0.90 - 1 behavioral detection(s): Download-and-execute dropper (wget/curl + chmod) [high] (rule
tl-linux-download-exec) - dynamic signal, weight 0.60, confidence 0.90 - Emsisoft (Emergency Kit) flagged Generic.Bash.MiraiB.9BBFEB0F (rule
Generic.Bash.MiraiB.9BBFEB0F) - engine signal, weight 0.55, confidence 0.85 - Contacted 15 external host(s) at runtime (1 HTTP) - network signal, weight 0.40, confidence 0.80
- Contacted 15 external host(s) at runtime (1 HTTP) - network signal, weight 0.40, confidence 0.80
- Anti-analysis: T1497 - dynamic signal, weight 0.40, confidence 0.75
- Anti-analysis: T1497 - dynamic signal, weight 0.40, confidence 0.75
- Embedded network infrastructure: 94.154.43.80 - static signal, weight 0.35, confidence 0.60
- Extracted generic config (1 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
- Extracted generic config (1 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (linux)
882 behavior events · 0 ATT&CK techniques · 1 dropped files.
Runtime network
- ntp.ubuntu.com
- entropy.ubuntu.com
- _dosvc._tcp.local
- 94.154.43.80/hiddenbin/boatnet.x86
- 185.125.189.53:443
- 94.154.43.80:80
- 185.125.189.53
- 10.240.0.1
- 94.154.43.80
- 40.84.97.4
- 224.0.0.251
- ff02::fb
- ff02::16
- 255.255.255.255
- 185.125.190.58
- 4.150.223.110
- 52.168.112.67
- ff02::2
- ff02::1
- 135.234.160.245
Dropped files
- tmp_tmp.PzdsDCd2fe -
0c2b52ac965dfb1104d894e8536b9d11f33f2b3038cf2107a587743d9c6fd733
Embedded URLs
- http://94.154.43.80/hiddenbin/boatnet.x86
Embedded domains
- bin.sh
- ntp.ubuntu.com
- entropy.ubuntu.com
- _dosvc._tcp.local
Embedded IP addresses
- 94.154.43.80
- 185.125.189.53
- 40.84.97.4
- 185.125.190.58
- 4.150.223.110
- 52.168.112.67
- 135.234.160.245
- 57.155.104.224
- 91.189.91.157
- 13.69.116.107
- 4.247.188.224
- 74.178.232.29
- 20.42.179.192
More Bash samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report