🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4d5fac03a3eddfb2acb130ae622a9273cd7dca20db71a3d30f234aee3cfea191. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 4d5fac03a3eddfb2acb130ae622a9273cd7dca20db71a3d30f234aee3cfea191
SHA3-384 hash: bbad55a51cc9ffb3d1f57d8fbf41ca036092609264e71aff6e3f0f88d19e8b4658b9a00573017f9c9a5ec36e2fa490b3
SHA1 hash: bb2ec07c0e89c1745fc683808bbb3ef3c18f1d25
MD5 hash: 6cd95b73218e25bc05634a7484b8eab5
humanhash: north-colorado-magnesium-lion
File name:4d5fac03a3eddfb2acb130ae622a9273cd7dca20db71a3d30f234aee3cfea191
Download: download sample
File size:5'913 bytes
First seen:2026-09-14 06:09:26 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 96:w/bsSf9gvuhjbn1jbnv3/majqza9Vg6IgIMZjTmqAoOJs0pSbij:w/q6FvumZvmq8FpSbA
TLSH T105C15407BD9212F121ACC5B95C8620C1F616111B1D547D38B46FFE883F18EE176BC3AA
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter Anonymous
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
https://nodejs.org/dist/index.jsonn/an/an/a

Intelligence


File Origin
# of uploads :
1
# of downloads :
62
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-09-14T05:10:00Z UTC
Last seen:
2026-09-14T05:25:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=35dd17c6-1900-0000-7766-4f19290c0000 pid=3113 /usr/bin/sudo guuid=a6abd3c8-1900-0000-7766-4f192a0c0000 pid=3114 /tmp/sample.bin guuid=35dd17c6-1900-0000-7766-4f19290c0000 pid=3113->guuid=a6abd3c8-1900-0000-7766-4f192a0c0000 pid=3114 execve guuid=2ded60c9-1900-0000-7766-4f192b0c0000 pid=3115 /usr/bin/uname guuid=a6abd3c8-1900-0000-7766-4f192a0c0000 pid=3114->guuid=2ded60c9-1900-0000-7766-4f192b0c0000 pid=3115 execve
Threat name:
Script-BAT.Downloader.Heuristic
Status:
Malicious
First seen:
2026-01-28 03:09:00 UTC
File Type:
Text (Shell)
AV detection:
4 of 36 (11.11%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
linux
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments