CLEAN — 93c61737dd78c0ff7934f70ed1290cfa2ca05718fd5ed3604e1d2c6844e40149.sh
CLEAN — 93c61737dd78c0ff7934f70ed1290cfa2ca05718fd5ed3604e1d2c6844e40149.sh is a shell sample analyzed by MalwareAnalyzer by Cyble with a clean verdict (30/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
93c61737dd78c0ff7934f70ed1290cfa2ca05718fd5ed3604e1d2c6844e40149 - SHA-1:
75572776555b7b6dd266b486d9f2933e8c7df3b3 - MD5:
9dd3f3cd9fb7cff012b0dff596c5a24f - ssdeep:
12:9GIWHQrOuwEnk9tFuGzLEGzD+jvzxMpZF5Nzw5F5NVwZF5NjkGI5:NWHQSurn23uGz4GzijvzxMfNGNsNgGI5 - TLSH:
T1DD0F46BB83712C1F53721252122290E84927E20ADE52FD067861C5432A36472F71B2BC - Submitted as: 93c61737dd78c0ff7934f70ed1290cfa2ca05718fd5ed3604e1d2c6844e40149.sh
- File type: shell · Size: 543 bytes
- Verdict: clean (30/100)
Source: MalwareBazaar · first seen 2026-08-02T00:00:00.000Z · SHA-256 verified
Detections (2 of 53 engines)
- Emsisoft (Emergency Kit): Trojan.Generic.40363035
- Kaspersky (KVRT): HEUR:Trojan-Downloader.Shell.Agent.a
Why this verdict
The clean score of 30/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: http://34.181.210.37/meow, http://34.181.210.37/meowarm64, 34.85.232.35 - static signal, weight 0.35, confidence 0.60
- Contacted 5 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
- Extracted generic config (4 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (linux)
804 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- 250.255.255.239.in-addr.arpa
- ntp.ubuntu.com
- desktop-hsgcbep
- desktop-hsgcbep._dosvc._tcp.local
- 34.181.210.37:80 US · AS396982 Google LLC
- 34.181.210.37 US · AS396982 Google LLC
- 224.0.0.251
- ff02::fb
- ff02::1:3
- 224.0.0.252
- 23.40.52.111
- 10.240.0.1
- ff02::16
- 10.240.0.255
- 74.178.240.61 NL · Amsterdam · AS8075 Microsoft Corporation
- ff02::1:2
- ff02::2
- 4.150.223.112 US · Des Moines · AS8075 Microsoft Corporation
- 224.0.0.22
- ff02::1
Embedded URLs
- http://34.181.210.37/meow
- http://34.181.210.37/meowarm64
Embedded IP addresses
- 34.85.232.35
- 34.181.210.37
- 74.178.240.61
- 4.150.223.112
- 4.150.223.109
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report