MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 1355716dafbae892d3eb5b0cb39e6ac9acf796b25d4a048b6c778a0f2a0c3e58. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: 1355716dafbae892d3eb5b0cb39e6ac9acf796b25d4a048b6c778a0f2a0c3e58
SHA3-384 hash: 0fd4abfbeec33d9d4024d9bd250a350306e6f1280463b14f010071b0f5963b35544a2055c2bb44c4f7ec94b1254ac35b
SHA1 hash: da6425bf3f7a6249be8859f3fa6fa2f2ce4f32e1
MD5 hash: b67c34714262229aab296bcc76263353
humanhash: double-triple-uniform-thirteen
File name:bj
Download: download sample
File size:11'428 bytes
First seen:2025-02-24 09:12:28 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 192:IbW7SRYba5gN09OofsTzzhmZCCJC7IMVZ4bcS:ISmO+mG4g+/hmZFJC7IMVZoL
TLSH T18D323E9E4625AF118CBC4ABA311B9435B223C6E9B0DFDBC57FCC12B8658CE507025F99
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://193.143.1.116/splx86n/an/an/a
http://193.143.1.116/splmipsn/an/an/a
http://193.143.1.116/splmpsln/an/an/a
http://193.143.1.116/splarmn/an/an/a
http://193.143.1.116/splarm5n/an/an/a
http://193.143.1.116/splarm6n/an/an/a
http://193.143.1.116/splarm7n/an/an/a
http://193.143.1.116/splppcn/an/an/a
http://193.143.1.116/splm68kn/an/an/a
http://193.143.1.116/splsh4n/an/an/a

Intelligence


File Origin
# of uploads :
1
# of downloads :
25
Origin country :
Vendor Threat Intelligence
Verdict:
Malicious
Score:
99.1%
Tags:
mirai agent virus shell
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive
Result
Verdict:
UNKNOWN
Threat name:
Script-Shell.Trojan.Heuristic
Status:
Malicious
First seen:
2025-02-24 10:07:15 UTC
File Type:
Text (Shell)
AV detection:
9 of 24 (37.50%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
discovery
Behaviour
Modifies registry class
Suspicious behavior: GetForegroundWindowSpam
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 1355716dafbae892d3eb5b0cb39e6ac9acf796b25d4a048b6c778a0f2a0c3e58

(this sample)

  
Delivery method
Distributed via web download

Comments