🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4a84d21194b584be67bebb9268e5f8cde55b65b51f81050cd16740548ee0e66e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 4a84d21194b584be67bebb9268e5f8cde55b65b51f81050cd16740548ee0e66e
SHA3-384 hash: f063ec1588520c5b43357f7c44ab6112032bffcfa68ef907bfb50b16f414b72d2eea3e107989ac6a511fa3c7d785757f
SHA1 hash: 5c3d896ec3c6fe52359182ca403e3914c072cd4b
MD5 hash: 87d418fb188a8ec8c8a4bbbadf573cd4
humanhash: black-fix-wolfram-fillet
File name:4a84d21194b584be67bebb9268e5f8cde55b65b51f81050cd16740548ee0e66e.sh
Download: download sample
File size:2'812 bytes
First seen:2026-09-11 20:47:01 UTC
Last seen:2026-09-12 03:03:50 UTC
File type: sh
MIME type:text/plain
ssdeep 48:cnRu9Rp9nB6gwUblrk+3l/BZpklrMZlClriZlClrXZlClrWZlClrRn:cRu7B6oxTcxHoDF
TLSH T17651757024F04C332E656580F3372BA6ABB7E95349E3618C35DE1E396F87B12A5AF411
Magika xml
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://ztccds.freesfocss.com/zt_armn/an/an/a

Intelligence


File Origin
# of uploads :
2
# of downloads :
62
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive
Status:
terminated
Behavior Graph:
%3 guuid=d8e2a13a-1700-0000-44a8-f8fb740d0000 pid=3444 /usr/bin/sudo guuid=9fca093d-1700-0000-44a8-f8fb7c0d0000 pid=3452 /tmp/sample.bin guuid=d8e2a13a-1700-0000-44a8-f8fb740d0000 pid=3444->guuid=9fca093d-1700-0000-44a8-f8fb7c0d0000 pid=3452 execve
Threat name:
Script-BAT.Trojan.Heuristic
Status:
Malicious
First seen:
2026-09-11 20:47:17 UTC
File Type:
Text (HTML)
AV detection:
5 of 36 (13.89%)
Threat level:
  2/5
Gathering data
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 4a84d21194b584be67bebb9268e5f8cde55b65b51f81050cd16740548ee0e66e

(this sample)

  
Delivery method
Distributed via web download

Comments