MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 4a84d21194b584be67bebb9268e5f8cde55b65b51f81050cd16740548ee0e66e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Threat unknown
Vendor detections: 4
| SHA256 hash: | 4a84d21194b584be67bebb9268e5f8cde55b65b51f81050cd16740548ee0e66e |
|---|---|
| SHA3-384 hash: | f063ec1588520c5b43357f7c44ab6112032bffcfa68ef907bfb50b16f414b72d2eea3e107989ac6a511fa3c7d785757f |
| SHA1 hash: | 5c3d896ec3c6fe52359182ca403e3914c072cd4b |
| MD5 hash: | 87d418fb188a8ec8c8a4bbbadf573cd4 |
| humanhash: | black-fix-wolfram-fillet |
| File name: | 4a84d21194b584be67bebb9268e5f8cde55b65b51f81050cd16740548ee0e66e.sh |
| Download: | download sample |
| File size: | 2'812 bytes |
| First seen: | 2026-09-11 20:47:01 UTC |
| Last seen: | 2026-09-12 03:03:50 UTC |
| File type: | sh |
| MIME type: | text/plain |
| ssdeep | 48:cnRu9Rp9nB6gwUblrk+3l/BZpklrMZlClriZlClrXZlClrWZlClrRn:cRu7B6oxTcxHoDF |
| TLSH | T17651757024F04C332E656580F3372BA6ABB7E95349E3618C35DE1E396F87B12A5AF411 |
| Magika | xml |
| Reporter | |
| Tags: | sh |
Shell script dropper
This file seems to be a shell script dropper, using wget, ftpget and/or curl. More information about the corresponding payload URLs are shown below.
| URL | Malware sample (SHA256 hash) | Signature | Tags |
|---|---|---|---|
| http://ztccds.freesfocss.com/zt_arm | n/a | n/a | n/a |
Intelligence
File Origin
DEVendor Threat Intelligence
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Web download
sh 4a84d21194b584be67bebb9268e5f8cde55b65b51f81050cd16740548ee0e66e
(this sample)
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.