MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0a63590f5314fe26184e38c61552e6fecee109f762d74c3ef174a8ce0db5deca. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 0a63590f5314fe26184e38c61552e6fecee109f762d74c3ef174a8ce0db5deca
SHA3-384 hash: b55220f3995d8b55794642a891b7b980ca9d35facf591a8c6257e71c43d915297b941c099424ade6937174e775dbd410
SHA1 hash: 65089549d2f180127813d96da42118af6f1aabec
MD5 hash: 892a9aa71618036b6c29ba655eef4095
humanhash: nuts-winter-black-freddie
File name:0a63590f5314fe26184e38c61552e6fecee109f762d74c3ef174a8ce0db5deca.sh
Download: download sample
File size:9'334 bytes
First seen:2026-02-22 13:15:52 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 96:cLu/mB6wNEexE+cBhxnCGHoSISogV3uvJv56f9/k:cLu/K6QlHB
TLSH T1AA12B57525F208333A706944B3772BA2AB76D95345E3218C35CE2E266F87F02B5AE811
Magika xml
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://23.224.176.63/sh/easy_av_wget.shn/an/an/a
http://222.186.52.155:21541/sh/AV.shn/an/abash
http://222.186.52.155:21541/sh/5053.shn/an/an/a
http://5.16.162.140:81/hiddenbin/dvr1.shn/an/an/a

Intelligence


File Origin
# of uploads :
1
# of downloads :
11
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive soft-404
Result
Gathering data
Gathering data
Gathering data
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 0a63590f5314fe26184e38c61552e6fecee109f762d74c3ef174a8ce0db5deca

(this sample)

1fdfc6e3ae612b736236df4579ff7a10954d47d9e7be67e6ebe8da173b0671c8

  
Delivery method
Distributed via web download
  
Dropping
MD5 bc422233b2512d7d5eb5500daf8a7822
  
Dropping
SHA256 1fdfc6e3ae612b736236df4579ff7a10954d47d9e7be67e6ebe8da173b0671c8

Comments