🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 41baa062d7079b9595d9ec18ff35cdf5eb71265cfbcd1581d71c65d3a41b9b09. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 41baa062d7079b9595d9ec18ff35cdf5eb71265cfbcd1581d71c65d3a41b9b09
SHA3-384 hash: c8bd9c80fd04925d20918e5fdbdb4ad5d2ad7f935f8d4855dba1ed4f63463fea6c67fc7cce73fc3d31785784287c72c1
SHA1 hash: d7194a06e91e00480caf14bffe70b81af4da56fc
MD5 hash: 90c0ddfbab4fb26f49f2be2ade3e6cb8
humanhash: uniform-florida-fanta-friend
File name:41baa062d7079b9595d9ec18ff35cdf5eb71265cfbcd1581d71c65d3a41b9b09.sh
Download: download sample
File size:13'021 bytes
First seen:2026-09-17 03:54:24 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 96:cCuGB6n7sht+O+v1fsn+h4+tIicqbA/GsGCuKNppjrwaV+I+j+3+FIBmIBGIBXnx:cCuq6nC4hvZ5mzjqKNpHPQsmJ1Q0Rg
TLSH T18242453721F08B3297D065C4A2771BA14FB2970B456714B8F4FE5A269F6DA0370EBB21
Magika xml
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://38.6.178.140/easy.shn/an/an/a
http://38.6.178.140/easy_cloud.shn/an/an/a
http://23.224.176.63/sh/easy_av_wget.shn/an/an/a
http://193.243.147.115/avTECHn/an/an/a
http://116.129.7.63:81/hiddenbin/dvr1.shn/an/aua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
61
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive
Status:
terminated
Behavior Graph:
%3 guuid=fef0e696-1b00-0000-dae9-42987e090000 pid=2430 /usr/bin/sudo guuid=dc5b7f9c-1b00-0000-dae9-429889090000 pid=2441 /tmp/sample.bin guuid=fef0e696-1b00-0000-dae9-42987e090000 pid=2430->guuid=dc5b7f9c-1b00-0000-dae9-429889090000 pid=2441 execve
Gathering data
Result
Malware family:
n/a
Score:
  3/10
Tags:
execution
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Executes a command shell one-liner
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 41baa062d7079b9595d9ec18ff35cdf5eb71265cfbcd1581d71c65d3a41b9b09

(this sample)

1fdfc6e3ae612b736236df4579ff7a10954d47d9e7be67e6ebe8da173b0671c8

  
Delivery method
Distributed via web download
  
Dropping
MD5 bc422233b2512d7d5eb5500daf8a7822
  
Dropping
SHA256 1fdfc6e3ae612b736236df4579ff7a10954d47d9e7be67e6ebe8da173b0671c8

Comments