MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4ad616e69c44ec02ab7f1a35de0bad65d5ceab158f3a7478e7a9b8cbcc8ed1ed. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 4ad616e69c44ec02ab7f1a35de0bad65d5ceab158f3a7478e7a9b8cbcc8ed1ed
SHA3-384 hash: 04f68da335c811daf4af6a97dbb9bf311337b0df94884b068edf91cda179c9166891501f9cf5b1cf06666940cd131dfc
SHA1 hash: 452fd2b8f2cbb6e847b2cf9f468c725fc9bd0056
MD5 hash: e7b5a1b874da8cad06cff9603e27a0d4
humanhash: harry-undress-burger-fifteen
File name:test.sh
Download: download sample
File size:230 bytes
First seen:2026-07-20 13:50:11 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 6:yVWglOKF1KG0RQ7rwVw5HQWiFx8JKx8J8Gx8J4MyDBt:G5lOzWv6xFCYC6GC6M6Bt
TLSH T1F1D0A7E1F2F6164D7F7040656086C0A67FE8A21507D98CD0093C8A81EB1702400E8566
Magika javascript
Reporter BlinkzSec

Intelligence


File Origin
# of uploads :
1
# of downloads :
100
Origin country :
IN IN
Vendor Threat Intelligence
No detections
Verdict:
Malicious
File Type:
text
First seen:
2026-07-20T11:08:00Z UTC
Last seen:
2026-07-21T17:25:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=5de9a464-1700-0000-c227-3096b00c0000 pid=3248 /usr/bin/sudo guuid=c24f6766-1700-0000-c227-3096b40c0000 pid=3252 /tmp/sample.bin guuid=5de9a464-1700-0000-c227-3096b00c0000 pid=3248->guuid=c24f6766-1700-0000-c227-3096b40c0000 pid=3252 execve
Threat name:
Win32.Backdoor.GetShell
Status:
Malicious
First seen:
2026-07-20 13:47:18 UTC
File Type:
Text (Shell)
AV detection:
7 of 24 (29.17%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
execution
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Executes a command shell one-liner
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments