MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 3af831e0b4875278ade73b8c5f1583776982fa1d89aed8c10ddef7819024c45e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 3af831e0b4875278ade73b8c5f1583776982fa1d89aed8c10ddef7819024c45e
SHA3-384 hash: b2a8cb3e9722e6f8e67777cf8c6d85b3c28f0f8e41506b8a27322670055e148f67c8a438bb5b051e6c5672a1256fec8f
SHA1 hash: fcf033e71b3eb548a6e2187b41c407de16d02499
MD5 hash: f62ab214bcbdf974cc079faa10bada17
humanhash: artist-fifteen-delta-minnesota
File name:3af831e0b4875278ade73b8c5f1583776982fa1d89aed8c10ddef7819024c45e.sh
Download: download sample
File size:12'328 bytes
First seen:2026-02-22 13:18:56 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 96:cCu2k0B6n7sht+O+v1fsn+h4+tIicqbA/GsGCuKNppjrwa3v+LIBJIBSIB/IBhIO:cCuFg6nC4hvZ5mzjqKNp1Y25cOT
TLSH T13F42453721F08B3297C065C4A2771B614FB2A70B456714B8F4FE5A269F2DA0370EBB65
Magika xml
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://38.6.178.140/easy_pass.shn/an/an/a
http://38.6.178.140/easy.shn/an/an/a
http://38.6.178.140/easy_cloud.shn/an/an/a
http://38.6.178.140/easy_lan.shn/an/an/a

Intelligence


File Origin
# of uploads :
1
# of downloads :
5
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
busybox evasive
Status:
terminated
Behavior Graph:
%3 guuid=0052d411-1b00-0000-d1f4-ee8d900c0000 pid=3216 /usr/bin/sudo guuid=af4f8e15-1b00-0000-d1f4-ee8d910c0000 pid=3217 /tmp/sample.bin guuid=0052d411-1b00-0000-d1f4-ee8d900c0000 pid=3216->guuid=af4f8e15-1b00-0000-d1f4-ee8d910c0000 pid=3217 execve
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 3af831e0b4875278ade73b8c5f1583776982fa1d89aed8c10ddef7819024c45e

(this sample)

  
Delivery method
Distributed via web download

Comments