MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 493afb9076ae87474cdb1eac45057ffe4b2e2c75726864d8ab7e8197c5569504. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: 493afb9076ae87474cdb1eac45057ffe4b2e2c75726864d8ab7e8197c5569504
SHA3-384 hash: aa7028e017224322cd59382b48f8836288f193dabb56108eeae76bc1e3c5930157335df6ca270820d2c1bfe6953a9a11
SHA1 hash: 7a3e9c025d51c3c78bf6ec9cb759f3ea88939c8d
MD5 hash: fbc6219b83c398958aec3b4ad5f1eee6
humanhash: ack-two-nevada-september
File name:cn
Download: download sample
File size:540 bytes
First seen:2024-10-27 07:56:49 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 12:VA85TNXzUNm2XhcDeXwBXZ2NNIbMXvcP7XI:N5TFQNjhaIOQNNIbWv4I
TLSH T146F06288A92AFE42022CEDAD737715CEB454C38C29675B9D6EC744B98C59E44B42CE14
Magika txt
Reporter abuse_ch
Tags:sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
65
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
Score:
97.4%
Tags:
Trojan Mirai Agent Shell
Result
Verdict:
MALICIOUS
Threat name:
Script.Trojan.Heuristic
Status:
Malicious
First seen:
2024-10-27 08:20:25 UTC
File Type:
Text (Shell)
AV detection:
12 of 24 (50.00%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
discovery
Behaviour
Modifies registry class
Suspicious behavior: GetForegroundWindowSpam
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 493afb9076ae87474cdb1eac45057ffe4b2e2c75726864d8ab7e8197c5569504

(this sample)

Comments