MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 55aab6191041e2b5bbe8524a3aa09e2a8c553f3820a28efda8582e13e041f39a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 55aab6191041e2b5bbe8524a3aa09e2a8c553f3820a28efda8582e13e041f39a
SHA3-384 hash: e4075c268a26004ecdf918b433bfe75925dcd4941932fa3ad9bd7281bcb443e85e6f2e6cff7cf95702e6acb51c3a8804
SHA1 hash: db9f06248235b6735660c62d70294904d4f621a5
MD5 hash: 45531fa0808071c008f17322ec1f18d9
humanhash: green-ink-dakota-angel
File name:wop
Download: download sample
File size:548 bytes
First seen:2025-01-23 15:01:02 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 6:LwWgrPNZAn6+zgwWgrYNPV9TxYWiwWgrgCwWgre3GxcoDwWgrKNNICegWwWgr+aS:qPAnL6NjfXG3NNImVwoC
TLSH T156F096994C53260304EDBCF6B9F394157163FECCA08F8ECD7E46583AD8A9621F915E44
Magika txt
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://193.143.1.54/kmipsn/an/an/a
http://193.143.1.54/kmpsln/an/an/a
http://193.143.1.54/karmn/an/an/a
http://193.143.1.54/karm5n/an/an/a
http://193.143.1.54/karm6n/an/an/a
http://193.143.1.54/karm7n/an/an/a

Intelligence


File Origin
# of uploads :
1
# of downloads :
100
Origin country :
DE DE
Vendor Threat Intelligence
Result
Verdict:
UNKNOWN
Threat name:
Linux.Downloader.Generic
Status:
Suspicious
First seen:
2025-01-23 18:51:05 UTC
File Type:
Text (Shell)
AV detection:
10 of 24 (41.67%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
discovery
Behaviour
Modifies registry class
Suspicious behavior: GetForegroundWindowSpam
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 55aab6191041e2b5bbe8524a3aa09e2a8c553f3820a28efda8582e13e041f39a

(this sample)

Comments