MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 417ca0ddd9398718b4f6923db99859900fae7d7e56bd3d4825c62068850bec19. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 417ca0ddd9398718b4f6923db99859900fae7d7e56bd3d4825c62068850bec19
SHA3-384 hash: 2c060238112d0fa0e011c2daf83bc01eac224c7579af410a9a6dde6ecaad8a9c6069cd5ea15a54249d22dcc178d1bc71
SHA1 hash: 26f161fd9643aa8eac632d7a0ef6dd532a9a420b
MD5 hash: afed654b07689fbaca1d4b65cf836c7f
humanhash: enemy-angel-eighteen-spaghetti
File name:417ca0ddd9398718b4f6923db99859900fae7d7e56bd3d4825c62068850bec19.sh
Download: download sample
File size:3'972 bytes
First seen:2026-02-22 13:19:12 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 48:cniRxuGRy/+DdvnSfr7lwnYJ/dl/B4Tilwn8Gs7wnizLI7wnE/+ol3+L+ol3Mt+r:cWu47kQMaXv+R1mhm/IBRIBxIBC
TLSH T13281967035F04D732E616A80F3372B96ABB6995344E3318C35DD2E265F86B12A5FF411
Magika xml
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://38.6.178.140/easy_pass.shn/an/an/a
http://217.12.199.67/avtech.shn/an/an/a
http://38.6.178.140/easy_cloud.shn/an/an/a

Intelligence


File Origin
# of uploads :
1
# of downloads :
6
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive
Status:
terminated
Behavior Graph:
%3 guuid=669cfa19-1b00-0000-fb0b-0b81600c0000 pid=3168 /usr/bin/sudo guuid=605fa41b-1b00-0000-fb0b-0b81650c0000 pid=3173 /tmp/sample.bin guuid=669cfa19-1b00-0000-fb0b-0b81600c0000 pid=3168->guuid=605fa41b-1b00-0000-fb0b-0b81650c0000 pid=3173 execve
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 417ca0ddd9398718b4f6923db99859900fae7d7e56bd3d4825c62068850bec19

(this sample)

  
Delivery method
Distributed via web download

Comments