MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 247bc7b4c84be6fb0841a5e0007c20b9c8bacdfd2facacb2df0367b6ff83ce14. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 247bc7b4c84be6fb0841a5e0007c20b9c8bacdfd2facacb2df0367b6ff83ce14
SHA3-384 hash: fc0bcca19f6a8850c542caaccc36a64e43811feb79adc9f4ffd0f85999ed912a1d53f5534c2a95afe1116d962b43f2eb
SHA1 hash: c51225778f2dc67734abde8ea09cd2802bab69f8
MD5 hash: 23a0173a38ea91eb3d7640884a3d4e18
humanhash: potato-utah-three-papa
File name:247bc7b4c84be6fb0841a5e0007c20b9c8bacdfd2facacb2df0367b6ff83ce14.sh
Download: download sample
File size:6'950 bytes
First seen:2026-02-22 13:15:46 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 48:cnRu9R1V6ylwnmu1lwndeP9lwnh+E69lrimE69lrBZLlrMZLlriZLlrXZLlrWZLG:cRuXGmn36fI6fdSITMcckkEE6pb
TLSH T136E1037435F20C732E611680F23727A5ABB6A45749E3708C35DE2D29EF9BB16A5BF001
Magika xml
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://196.190.65.223:81/hiddenbin/dvr1.shn/an/aelf ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
12
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive
Result
Gathering data
Status:
terminated
Behavior Graph:
%3 guuid=c6251373-1900-0000-c16d-dcf313040000 pid=1043 /usr/bin/sudo guuid=0f885e75-1900-0000-c16d-dcf31a040000 pid=1050 /tmp/sample.bin guuid=c6251373-1900-0000-c16d-dcf313040000 pid=1043->guuid=0f885e75-1900-0000-c16d-dcf31a040000 pid=1050 execve
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 247bc7b4c84be6fb0841a5e0007c20b9c8bacdfd2facacb2df0367b6ff83ce14

(this sample)

  
Delivery method
Distributed via web download

Comments