Open-source atomic malware analysis

Analyze another

drop3_mod.sh

SHELL
Verdict: SUSPICIOUS
Mal-ecule
O₂(C₃S)H₃(CmPoTi)
Size 133 B download
First seen 118 days ago
Analyzed 116 days ago
Ecosystem malcontent-samples

Objectives

suspicious severity, 100% confident.
command-and-control Shell script C2 variable
notable severity, 75% confident.
command-and-control/infrastructure Direct IP address in URL
component severity, 100% confident.
command-and-control/botnet http:// protocol prefix
component severity, 100% confident.
supply-chain/install-hook/dropper Shell rm -f command

Micro-behaviors

suspicious severity, 95% confident.
communications HTTP URL with IP address
notable severity, 100% confident.
process/create Executes a file from current directory
notable severity, 80% confident.
time/sleep Trailing sleep command
baseline severity, 90% confident.
communications/http HTTP protocol prefix

Metadata

baseline severity, 80% confident.
binary High density of shell commands
baseline severity, 75% confident.
file Tiny multi-line text script

Identity

SHA-256 31955a8cd698f0554362208084fb7c3f266a1e6cef3560616cdebd02eca223f6
Filename drop3_mod.sh

Origin

Source harvest
Feed datasets
Ecosystem malcontent-samples

Timeline

First seen 24 Apr 2026 16:18 UTC
Last analyzed 26 Apr 2026 18:51 UTC
Last updated 26 Apr 2026 18:51 UTC

Labeling

Label bad
Label source harvest
Traits version bf48d