MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 1b1d43bfeb7ddf50b579fe3bdaf49504d2bb199972d01da5a6679ae78cb3abb9. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: 1b1d43bfeb7ddf50b579fe3bdaf49504d2bb199972d01da5a6679ae78cb3abb9
SHA3-384 hash: d31d33aa4e695505f92aff348abe2785e0fed30cf6e6869a550a7156b95438a5402cf88452e3900d4905d8ee43d34fe9
SHA1 hash: 256d89ffcda6588f0ab4dcdd57d6f5d93f139752
MD5 hash: 062c22deea864ad1320d9b4a2b8cdc35
humanhash: twenty-queen-whiskey-monkey
File name:wget.sh
Download: download sample
File size:4'705 bytes
First seen:2024-12-14 09:31:10 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 48:1tLHBLbmLoRdLxGLzYqLCDLR7WDa5DNvUURhd0PYgmH94MAR0rYum+q3FiqvJ1MB:1xFsoLescYRV5hsUzuQgA9yttfHkTFv
TLSH T19CA125C93F11BF334C91DF59F322866165B2D88148A34F1974EDB0BEA8BEE44B212947
Magika shell
Reporter abuse_ch
Tags:sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
78
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
Score:
94.9%
Tags:
backdoor botnet agent
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
anti-debug busybox
Result
Verdict:
MALICIOUS
Threat name:
Win32.Trojan.Generic
Status:
Malicious
First seen:
2024-12-14 09:32:05 UTC
File Type:
Text (Shell)
AV detection:
18 of 38 (47.37%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
discovery
Behaviour
Modifies registry class
Suspicious behavior: GetForegroundWindowSpam
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 1b1d43bfeb7ddf50b579fe3bdaf49504d2bb199972d01da5a6679ae78cb3abb9

(this sample)

  
Delivery method
Distributed via web download

Comments