SUSPICIOUS — 7ef712f0c5bd347223fa2fbb93e9181e54265fc9a72e35118b25032b3ff93b79.sh
SUSPICIOUS — 7ef712f0c5bd347223fa2fbb93e9181e54265fc9a72e35118b25032b3ff93b79.sh is a shell sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (47/100), attributed to the Reverse family. 2 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
7ef712f0c5bd347223fa2fbb93e9181e54265fc9a72e35118b25032b3ff93b79 - SHA-1:
00bd77ae0166dd892f3177bb0d205d535e03c6e1 - MD5:
c57acc0e25d3205963f31e551d267932 - ssdeep:
12:jahiAnyaa/b3Z3WKVP//yy+yfnc/yrgsf/yQfmIYEB+WqwReEB+WZEO1EB+W/DxT:+IArazpH/Dc/e7/PftBNqmBNQBNOBNK - TLSH:
T1A50F9910116BB72CACEF9A28B638C46B8985C03075F067D1005E2A1B2E2E0D530CD8C7 - Submitted as: 7ef712f0c5bd347223fa2fbb93e9181e54265fc9a72e35118b25032b3ff93b79.sh
- File type: shell · Size: 635 bytes
- Verdict: suspicious (47/100) · Family: Reverse
Source: MalwareBazaar · first seen 2026-08-02T00:00:00.000Z · SHA-256 verified
Detections (2 of 53 engines)
- YARA: MalwareAnalyser community pack: TL_Linux_Reverse_Shell
- Kaspersky (KVRT): HEUR:Trojan-Downloader.Shell.Agent.bc
MITRE ATT&CK
Why this verdict
The suspicious score of 47/100 is the fusion of 4 weighted signals:
- YARA: MalwareAnalyser community pack flagged TL_Linux_Reverse_Shell (rule
TL_Linux_Reverse_Shell) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: http://evil.ru/payload.sh - static signal, weight 0.35, confidence 0.60
- Contacted 3 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
- Extracted generic config (1 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (linux)
826 behavior events · 0 ATT&CK techniques · 2 dropped files.
Runtime network
- desktop-hsgcbep
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 252.0.0.224.in-addr.arpa
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 251.0.0.224.in-addr.arpa
- 79.243.254.169.in-addr.arpa
- ff02::1:3
- 224.0.0.252
- 10.240.0.255
- 169.254.255.255
- ff02::fb
- 224.0.0.251
- 10.240.0.1
- ff02::16
- 255.255.255.255
- 52.123.129.14
- 224.0.0.22
- ff02::1:2
- 150.171.110.145
Dropped files
- tmp_.shadow_backup -
ce0293531e74e9f3d7f640d144c0f6539e9f81578911f69aaa53001e2dcfca8f - tmp_tools.tar.gz -
e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
Embedded URLs
- http://malicious.example.com/tools.tar.gz
- http://evil.ru/payload.sh
Embedded domains
- malicious.example.com
- evil.ru
- payload.sh
Embedded IP addresses
- 192.168.1.100
- 52.123.129.14
- 74.178.240.61
- 4.150.223.112
More Reverse samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report