MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4bbb6bb94343c2eb9a2de93be956043456c732a2bf3c2549bbb7dc9c31d9c31d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA 1 File information Comments

SHA256 hash: 4bbb6bb94343c2eb9a2de93be956043456c732a2bf3c2549bbb7dc9c31d9c31d
SHA3-384 hash: 1acf47799cf78bd6b4e5b6e3e93454fc0b11ab56aa76f9b3bf228bd5ae1c110345c2da8b3299ea657aad304ec1801ddb
SHA1 hash: fb8efce6fb9c1cba8ef635ad3370744f672c9032
MD5 hash: 6482a3711098d3756a7a25e10f79e0cf
humanhash: asparagus-vegan-video-lion
File name:cgnty_carrier.ahk
Download: download sample
File size:666'864 bytes
First seen:2026-08-06 18:29:14 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 12288:y9PkpNuoyQa/yZw5Rkih5IF7new+LqXrVZZseh43XiAnnqwW10jlXamBIfU+PPLr:y98Tuopa/yZyJmdnew+Lq77ZU3Xi70jE
TLSH T139E4B0FC76047DD6666F536BDA96ACDD13B626238ACBA4CC80647BC305A3375EE01C09
Magika autohotkey
Reporter BlinkzSec
Tags:sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
10
Origin country :
CH CH
Vendor Threat Intelligence
No detections
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
evasive masquerade
Status:
terminated
Behavior Graph:
%3 guuid=a94bb556-1a00-0000-e5cd-1aa158080000 pid=2136 /usr/bin/sudo guuid=364dbe5a-1a00-0000-e5cd-1aa15e080000 pid=2142 /tmp/sample.bin guuid=a94bb556-1a00-0000-e5cd-1aa158080000 pid=2136->guuid=364dbe5a-1a00-0000-e5cd-1aa15e080000 pid=2142 execve
Result
Malware family:
n/a
Score:
  3/10
Tags:
execution
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Executes a command shell one-liner
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:FreddyBearDropper
Author:Dwarozh Hoshiar
Description:Freddy Bear Dropper is dropping a malware through base63 encoded powershell scrip.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments