🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 1bb5fb6dc26609f60dffad5a3155bb44e5d96a509a789b2b4b11d3ff336f0cb9. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 1bb5fb6dc26609f60dffad5a3155bb44e5d96a509a789b2b4b11d3ff336f0cb9
SHA3-384 hash: 910dbeb1221c0735aba7cecdc793b5bbde7aae72db47ebe7e6e423bfb90babf5c19c2588f148494e8bc9b1e6f909dceb
SHA1 hash: 70ecf37788bc40f7dfa6f62667c94a7cf3456233
MD5 hash: 9b4d287d3aec334cd5667fadae9dd3ae
humanhash: india-north-glucose-november
File name:dvr.sh
Download: download sample
File size:141 bytes
First seen:2026-08-29 17:28:45 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 3:QnQpKlCvQOBFmQLIlKtVZ7KS/ULEIg1EITaKid2DSNO59:lYlsQOHpLIli7wEIgSnKP0O59
TLSH T1E0C08C96623412383A695C89A40A2104B4C480C406996E0864E814E398CCB05B114E1A
Magika txt
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://130.12.182.77/main.n/an/an/a

Intelligence


File Origin
# of uploads :
1
# of downloads :
78
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
File Type:
text
First seen:
2026-08-29T15:24:00Z UTC
Last seen:
2026-08-31T07:51:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=8f629adf-1600-0000-900d-e3973a0d0000 pid=3386 /usr/bin/sudo guuid=0b7ea2e3-1600-0000-900d-e397410d0000 pid=3393 /tmp/sample.bin guuid=8f629adf-1600-0000-900d-e3973a0d0000 pid=3386->guuid=0b7ea2e3-1600-0000-900d-e397410d0000 pid=3393 execve guuid=ad0bf4e3-1600-0000-900d-e397420d0000 pid=3394 /usr/bin/mkdir guuid=0b7ea2e3-1600-0000-900d-e397410d0000 pid=3393->guuid=ad0bf4e3-1600-0000-900d-e397420d0000 pid=3394 execve guuid=63afb7e4-1600-0000-900d-e397450d0000 pid=3397 /usr/bin/rm guuid=0b7ea2e3-1600-0000-900d-e397410d0000 pid=3393->guuid=63afb7e4-1600-0000-900d-e397450d0000 pid=3397 execve guuid=afef26e5-1600-0000-900d-e397470d0000 pid=3399 /usr/bin/uname guuid=0b7ea2e3-1600-0000-900d-e397410d0000 pid=3393->guuid=afef26e5-1600-0000-900d-e397470d0000 pid=3399 execve guuid=beac6fe5-1600-0000-900d-e397490d0000 pid=3401 /usr/bin/wget net send-data write-file guuid=0b7ea2e3-1600-0000-900d-e397410d0000 pid=3393->guuid=beac6fe5-1600-0000-900d-e397490d0000 pid=3401 execve guuid=05ab34f2-1600-0000-900d-e3975b0d0000 pid=3419 /usr/bin/chmod guuid=0b7ea2e3-1600-0000-900d-e397410d0000 pid=3393->guuid=05ab34f2-1600-0000-900d-e3975b0d0000 pid=3419 execve guuid=8fa878f2-1600-0000-900d-e3975d0d0000 pid=3421 /.n/d delete-file guuid=0b7ea2e3-1600-0000-900d-e397410d0000 pid=3393->guuid=8fa878f2-1600-0000-900d-e3975d0d0000 pid=3421 execve 6bb63a09-5140-5e45-a32a-aa1de3f42ba5 130.12.182.77:80 guuid=beac6fe5-1600-0000-900d-e397490d0000 pid=3401->6bb63a09-5140-5e45-a32a-aa1de3f42ba5 send: 139B guuid=f3888df2-1600-0000-900d-e3975e0d0000 pid=3422 /.n/d zombie guuid=8fa878f2-1600-0000-900d-e3975d0d0000 pid=3421->guuid=f3888df2-1600-0000-900d-e3975e0d0000 pid=3422 clone guuid=4afa98f2-1600-0000-900d-e3975f0d0000 pid=3423 /.n/d net send-data zombie guuid=f3888df2-1600-0000-900d-e3975e0d0000 pid=3422->guuid=4afa98f2-1600-0000-900d-e3975f0d0000 pid=3423 clone 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=4afa98f2-1600-0000-900d-e3975f0d0000 pid=3423->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con 879313db-9102-5ffc-8443-1eefa773f834 94.154.43.12:32 guuid=4afa98f2-1600-0000-900d-e3975f0d0000 pid=3423->879313db-9102-5ffc-8443-1eefa773f834 send: 508B guuid=4cbab4f2-1600-0000-900d-e397600d0000 pid=3424 /.n/d guuid=4afa98f2-1600-0000-900d-e3975f0d0000 pid=3423->guuid=4cbab4f2-1600-0000-900d-e397600d0000 pid=3424 clone guuid=7a8ac1f2-1600-0000-900d-e397610d0000 pid=3425 /usr/bin/bash guuid=4afa98f2-1600-0000-900d-e3975f0d0000 pid=3423->guuid=7a8ac1f2-1600-0000-900d-e397610d0000 pid=3425 execve
Result
Malware family:
n/a
Score:
  3/10
Tags:
execution
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Executes a command shell one-liner
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 1bb5fb6dc26609f60dffad5a3155bb44e5d96a509a789b2b4b11d3ff336f0cb9

(this sample)

  
Delivery method
Distributed via web download

Comments