MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4a1da07c178dc4c78e26ebfd1f0fb4a427a67370bf7af5c9ce349196f9478882. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 4a1da07c178dc4c78e26ebfd1f0fb4a427a67370bf7af5c9ce349196f9478882
SHA3-384 hash: e83d34930f5698788a6bfa1e63f9dd691a4311a2fa51d742b3cf40d0c418c312298038ed1f37983fe3fee15b6b069fa6
SHA1 hash: c5bc6d97950b72aeb4ece2d60b2292b6dc01d427
MD5 hash: b14917decb17129a4199c5f53b4c4832
humanhash: batman-sad-lithium-floor
File name:4a1da07c178dc4c78e26ebfd1f0fb4a427a67370bf7af5c9ce349196f9478882.sh
Download: download sample
File size:11'804 bytes
First seen:2026-02-22 13:18:16 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 96:cCu/mB657sht+O+v1fsn+h4+tIicqbA/GsGuTMkCxZIokpIZsMK2vJrpRpcpnX+:cCu/K65C4hvZ5mzjdwkCxZICx
TLSH T1C232697720F08B329BD021C8A27716655FB2E60B456714B8F4BE1B399F5DA0374EBB21
Magika xml
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://78.97.33.45/rvs6n/an/an/a
http://109.205.213.2/download.shn/an/an/a
http://59.127.196.190:880/d.shn/an/an/a
http://196.190.65.223:81/hiddenbin/dvr1.shn/an/an/a
http://194.69.203.32:81/hiddenbin/dvr1.shn/an/ageofenced opendir sh ua-wget USA

Intelligence


File Origin
# of uploads :
1
# of downloads :
4
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
busybox evasive
Result
Gathering data
Gathering data
Gathering data
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 4a1da07c178dc4c78e26ebfd1f0fb4a427a67370bf7af5c9ce349196f9478882

(this sample)

faf13e715e1d5c7401a341fab9efca5c1754b22a7bcc8f8405ab8e56dec91190

  
Delivery method
Distributed via web download
  
Dropping
MD5 bf9c16fbb53cb2e70df36493dea6180d
  
Dropping
SHA256 faf13e715e1d5c7401a341fab9efca5c1754b22a7bcc8f8405ab8e56dec91190

Comments