MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 45b2368510c8b71d2a4ba279c437ed6506f0c52c6eee5d07a8c999dcaa28972a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 45b2368510c8b71d2a4ba279c437ed6506f0c52c6eee5d07a8c999dcaa28972a
SHA3-384 hash: 7b866b353a62460aec1f7c7717d1e6e8d430b7a00c69dd4bc146f7d38e7cee5eea42c6a803eee2d221dc8a16ba29eac2
SHA1 hash: deab0c98ad35cf2ffb8f26d3fca7cb747f0152e3
MD5 hash: ea1e6e7a2307500894d23634c9cb6d2b
humanhash: early-september-sierra-bulldog
File name:gig.sh
Download: download sample
File size:214 bytes
First seen:2025-02-02 07:41:41 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 3:L+BcqRvLdgoKxV7GBzSEyLTUWaXwADzKV+BcqRvLdgoKoaBzSE8eU61wAg:L68VCIywazg6YL1wD
TLSH T121D09ECD08513E508848E8AE7267427E650183CCB11747BA9C8924398D4C650F8A0A80
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://94.156.167.35/mips4fc73b02bd0cc4d44ee8da03ce5ab8b74fb67409fb223c3f36b06dc22dc0dd74 Gafgytelf gafgyt ua-wget
http://94.156.167.35/mpsl18c99e6db38118a4d50a0bca8dd475f700d3ff172a73fb6a48bdd599d4abae95 Gafgytelf gafgyt ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
97
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
busybox
Result
Verdict:
UNKNOWN
Threat name:
Script-Shell.Browser.Tsunami
Status:
Malicious
First seen:
2025-02-02 07:20:55 UTC
File Type:
Text (Shell)
AV detection:
7 of 24 (29.17%)
Threat level:
  4/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
discovery
Behaviour
Modifies registry class
Suspicious behavior: GetForegroundWindowSpam
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 45b2368510c8b71d2a4ba279c437ed6506f0c52c6eee5d07a8c999dcaa28972a

(this sample)

  
Delivery method
Distributed via web download

Comments