MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4aa45d6226f2eaac188e253134bf4b12a7ce7d8f9167ec477ad3bc83a8feab48. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Tsunami


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: 4aa45d6226f2eaac188e253134bf4b12a7ce7d8f9167ec477ad3bc83a8feab48
SHA3-384 hash: 980f1909ea7f5c9179f01a64ac7ea91d6045c73ced3b8c92a398d1414379430cd408fd5f972380be9d5cc07a05aee310
SHA1 hash: aa7885303fbca2cac1a35cb307f5bb49456c0cce
MD5 hash: fd7f61eb110b8a621faa042f41ad8698
humanhash: fifteen-friend-single-cat
File name:1sh
Download: download sample
Signature Tsunami
File size:2'638 bytes
First seen:2025-03-01 04:07:15 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 48:yfagLayZgQgUH9jUcjFgag+oKN+WGBwXfyIa:yHXEL
TLSH T1D2519EED56361C5478F90D2B32BB0860E2DFE6C810D9DB58A1D6A9F085FC534F092BAC
Magika shell
Reporter abuse_ch
Tags:sh Tsunami
URLMalware sample (SHA256 hash)SignatureTags
http://61.215.151.173/x/ptyd6f7fa3acf502d0b6e11197d80d305748999225be6f4eaf28e05a7c94facd432 TsunamiTsunami
http://61.215.151.173/x/irq0a64ddaa1e3747b10863af3b60e79bbef1295a71ffdf3dd15a390d5926a6c3c13 TsunamiTsunami
http://61.215.151.173/x/irq1a1f211877e5ac29682f07d0b97d02ee936ed02f3355b68d7163b3336164d85f6 TsunamiTsunami
http://61.215.151.173/x/irq28e9cd77c31ba14b925208fa5e3d9f5675909f0a5ebc2399bdd9e36279314abd1 TsunamiTsunami

Intelligence


File Origin
# of uploads :
1
# of downloads :
563
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
Score:
99.9%
Tags:
ransomware agent virus
Threat name:
Script.Browser.Heuristic
Status:
Malicious
First seen:
2025-02-28 09:09:04 UTC
File Type:
Text (Shell)
AV detection:
7 of 24 (29.17%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Tsunami

sh 4aa45d6226f2eaac188e253134bf4b12a7ce7d8f9167ec477ad3bc83a8feab48

(this sample)

  
Delivery method
Distributed via web download

Comments