MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2cae7d56c3063a8d27c5a3b5792cca771560ee844f82da521c49bb64c88252f0. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 2cae7d56c3063a8d27c5a3b5792cca771560ee844f82da521c49bb64c88252f0
SHA3-384 hash: fbdcb4aa0f28557c30978fd18f5bc7dadee3fe0e92ecd2b766b4f414860864f473c14a7ae5c9e4bde56565e101089f86
SHA1 hash: f450f7edd284edf37bda6f1dbc40189afb1b1cf6
MD5 hash: 7b3ecd466fbd66f0624acb84721e5f04
humanhash: tennessee-burger-harry-illinois
File name:2cae7d56c3063a8d27c5a3b5792cca771560ee844f82da521c49bb64c88252f0.sh
Download: download sample
File size:7'016 bytes
First seen:2026-02-22 13:20:36 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 96:cCu7B6wNEOSwxkEgUEKEVqEorlrypEpjpPFsgX:cCul6axvhD
TLSH T1B6E1C57121F14C336D605984B3772BA6ABB6D95389E3218C35DE2E356F96F02B0BF412
Magika xml
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://194.156.102.210/bins/bins.shn/an/an/a
http://222.186.52.155:21541/sh/AV.shn/an/abash
http://222.186.52.155:21541/sh/5053.shn/an/an/a
http://2.194.96.97:81/hiddenbin/bins.shn/an/an/a
http://2.194.96.97:81/hiddenbin/dvr1.shn/an/an/a
http://194.69.203.32:81/hiddenbin/dvr1.shn/an/ageofenced opendir sh ua-wget USA
http://5.16.162.140:81/hiddenbin/dvr1.shn/an/aelf ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
33
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive mirai
Verdict:
Malicious
File Type:
text
Detections:
HEUR:Trojan-Downloader.Shell.Agent.p HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=c753e81c-1900-0000-7d60-d5889b080000 pid=2203 /usr/bin/sudo guuid=3ea9a51e-1900-0000-7d60-d588a2080000 pid=2210 /tmp/sample.bin guuid=c753e81c-1900-0000-7d60-d5889b080000 pid=2203->guuid=3ea9a51e-1900-0000-7d60-d588a2080000 pid=2210 execve
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 2cae7d56c3063a8d27c5a3b5792cca771560ee844f82da521c49bb64c88252f0

(this sample)

6f62167f649c5f698b409b90313d4774ae315604dc19a4279322ef2bfce84a83

  
Delivery method
Distributed via web download
  
Dropping
MD5 ced37376359e40861e83a118e4234423
  
Dropping
SHA256 6f62167f649c5f698b409b90313d4774ae315604dc19a4279322ef2bfce84a83

Comments