MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 4b8884a5bf023d35920a8554d4b3d56deeaf9c5ca8b629bd691e22e25a22c8be. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Threat unknown
Vendor detections: 4
| SHA256 hash: | 4b8884a5bf023d35920a8554d4b3d56deeaf9c5ca8b629bd691e22e25a22c8be |
|---|---|
| SHA3-384 hash: | a5c1fe0b40c9b0e84e4659ca8e213383e67cd9b6c55e8cf6ea3e1c387afa3c7f6f99ff077808d7f21ed73ed260b7ac3e |
| SHA1 hash: | 306687edeed5d9c95f8b7a65b74384cd705a8081 |
| MD5 hash: | 5e46fd3497480b4cecdbe52088935782 |
| humanhash: | grey-music-asparagus-river |
| File name: | payload_wget.txt |
| Download: | download sample |
| File size: | 120 bytes |
| First seen: | 2026-01-11 06:38:38 UTC |
| Last seen: | Never |
| File type: | sh |
| MIME type: | text/plain |
| ssdeep | 3:GRFJNCiKNRUQ1Vgk9u2QyBFOde9u2QfVKCE99:SJo7qG3u5yNu549 |
| TLSH | T19FB092EDD6208253314FD538304D94381CBB589A10AC35099053ABF210BA08DE20ABE5 |
| Magika | batch |
| Reporter | |
| Tags: | sh |
Shell script dropper
This file seems to be a shell script dropper, using wget, ftpget and/or curl. More information about the corresponding payload URLs are shown below.
| URL | Malware sample (SHA256 hash) | Signature | Tags |
|---|---|---|---|
| http://boberkurwa.phoneparts.icu:80/gay.sh | n/a | n/a | n/a |
Intelligence
File Origin
# of uploads :
1
# of downloads :
31
Origin country :
DEVendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
10/10
Confidence:
100%
Tags:
masquerade
Verdict:
Suspicious
Labled as:
TrojanDownloader/Linux.Agent
Result
Gathering data
Status:
terminated
Behavior Graph:
Detection(s):
Suspicious file
Result
Malware family:
n/a
Score:
3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Legit
Score:
0.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Web download
sh 4b8884a5bf023d35920a8554d4b3d56deeaf9c5ca8b629bd691e22e25a22c8be
(this sample)
Delivery method
Distributed via web download
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.