MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 46517d21e5b3b5b8e1779b350546c91d0fbcd7657cd14a04bfcf794628ce7219. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Threat unknown
Vendor detections: 5
| SHA256 hash: | 46517d21e5b3b5b8e1779b350546c91d0fbcd7657cd14a04bfcf794628ce7219 |
|---|---|
| SHA3-384 hash: | 663ba87001c7e5e158a499d78c0242ea9c620f8410add98cc498eb30264ac7e1f965ac2fea5872feeb201cc6fde15738 |
| SHA1 hash: | 976d66c9a2721c32b5f8574e5c0e9e5e3312679c |
| MD5 hash: | 94d078d01ed948bbc91f8499527ea04e |
| humanhash: | bacon-pip-twelve-seven |
| File name: | wget.sh |
| Download: | download sample |
| File size: | 147 bytes |
| First seen: | 2025-02-21 16:21:44 UTC |
| Last seen: | Never |
| File type: | sh |
| MIME type: | text/plain |
| ssdeep | 3:JnFSXiLdjX4wgOSEhWEWoDjiLdjX41Le5OSE8qa72:JoXoZX4wgnoXoZX41Le5ML |
| TLSH | T142C04CE948A01F54D0DEE94936A78E2B5003C7ECACC7C79E6C9A06364C85600FDA4EC9 |
| Magika | shell |
| Reporter | |
| Tags: | sh |
Shell script dropper
This file seems to be a shell script dropper, using wget, ftpget and/or curl. More information about the corresponding payload URLs are shown below.
| URL | Malware sample (SHA256 hash) | Signature | Tags |
|---|---|---|---|
| http://94.156.227.74/mips | n/a | n/a | 32-bit elf mirai |
| http://94.156.227.74/mpsl | n/a | n/a | elf mirai ua-wget |
Intelligence
File Origin
# of uploads :
1
# of downloads :
9
Origin country :
USVendor Threat Intelligence
Verdict:
Malicious
Score:
70%
Link:
Tags:
trojan agent hype
Verdict:
Malicious
Threat level:
10/10
Confidence:
100%
Tags:
evasive
Result
Verdict:
UNKNOWN
Score:
0%
Verdict:
Benign
File Type:
SCRIPT
Detection(s):
Suspicious file
Result
Malware family:
n/a
Score:
3/10
Tags:
discovery
Behaviour
Modifies registry class
Suspicious behavior: GetForegroundWindowSpam
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Malicious File
Score:
1.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Web download
sh 46517d21e5b3b5b8e1779b350546c91d0fbcd7657cd14a04bfcf794628ce7219
(this sample)
Delivery method
Distributed via web download
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.