MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2abd35fd795d67da415db22f417284c971a0968653a8512c52da473e1a681d9d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 2abd35fd795d67da415db22f417284c971a0968653a8512c52da473e1a681d9d
SHA3-384 hash: d9e338baafe2d212578982c28c207225bdbfbedd57d8b6fedee5dcfc68cd5114ab27436b96736013ab41ccb5b70c6d45
SHA1 hash: e573b64944ac64a6ab72be20a44f86d2362c1841
MD5 hash: a27c2f208844e43ed3da3a1e5bff8f36
humanhash: single-zulu-five-alaska
File name:g.sh
Download: download sample
File size:375 bytes
First seen:2025-05-14 04:47:30 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 6:ebgfr3w5/KjUAFjbKTRUCOGjFIcMgFuIcMgNLaFYCTIcMzFuIcMzaGpQ3FYQu:3rWKIw+9UCFjecMg7cMgca5cMz7cMzNj
TLSH T15DE0D8D965A0E93491865EE3B3248839BEC6CE4E65C00E58A0CF1473D81CC2DB699F77
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://103.149.29.68/gmips08a64007c9c4ea40fbad510fcb172bfb9fccfb56bfc5fec5e470069776c42553 Gafgytcensys elf gafgyt ua-wget
http://103.149.29.68/gmpsl619fe32d388a495a0d238e85d0eac6408f81a680bace689d9e6b5378d82086e0 Gafgytcensys elf gafgyt ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
86
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
busybox
Threat name:
Script-Shell.Downloader.Heuristic
Status:
Malicious
First seen:
2025-05-14 04:48:12 UTC
File Type:
Text (Shell)
AV detection:
3 of 37 (8.11%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 2abd35fd795d67da415db22f417284c971a0968653a8512c52da473e1a681d9d

(this sample)

  
Delivery method
Distributed via web download

Comments