MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 16e71c80c657abc64fe317314e1f7499eb6d1c0a9589658a47b0f8551684f5ab. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 16e71c80c657abc64fe317314e1f7499eb6d1c0a9589658a47b0f8551684f5ab
SHA3-384 hash: 4afd314ab10d6a7acfd2a793bb68147d438b64fd405f49ad09f5153e38817608a985882f324165d2243be557cb97a96d
SHA1 hash: e54bab593470fefe55b8fe3488a0d1b274acd79a
MD5 hash: f9e90fe2bd72aed5f91f5fb02bc750f2
humanhash: monkey-early-india-music
File name:77.sh
Download: download sample
File size:203 bytes
First seen:2026-02-07 13:34:25 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 6:lOnFfl1zoVLUIj1DF3JoVLUIjKUAzGhwQ:iXIJdJIjKHnQ
TLSH T116D0225310100BB03DDEC9F6F3E10CC4B0A66B4A81BECB21F0CC3890804CC08B228E61
Magika batch
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://77.90.185.76/f33.pngn/an/aelf geofenced mirai ua-wget USA x86

Intelligence


File Origin
# of uploads :
1
# of downloads :
23
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Result
Gathering data
Threat name:
Script.Downloader.Heuristic
Status:
Malicious
First seen:
2026-02-05 13:31:41 UTC
File Type:
Text (Shell)
AV detection:
4 of 36 (11.11%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 16e71c80c657abc64fe317314e1f7499eb6d1c0a9589658a47b0f8551684f5ab

(this sample)

  
Delivery method
Distributed via web download

Comments