MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 5776dcbb421d104f239d02a0b819245c00c6aa4fb5d8ca23835af9e6db0fa756. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 5776dcbb421d104f239d02a0b819245c00c6aa4fb5d8ca23835af9e6db0fa756
SHA3-384 hash: e7615bf674bc409d3c1cdfdb972cc80e8558eb50a9f3421ca2cc2a51154042ed80e7b2a0aa08a42ed5166074f5cbad05
SHA1 hash: 3f3e907e7c53533c5b9d837c5ca2bbe286c48e48
MD5 hash: 77c23d350f68d40b4a04a50c8a5c2afd
humanhash: fish-sierra-oregon-twenty
File name:c.sh
Download: download sample
File size:564 bytes
First seen:2026-07-11 10:25:02 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 6:+49gGLFKmYD6QdXmrhEMXfR3uec7DuFOTp3ahJIo0qKIiOljugiZlg3FZNuHA/s6:V9DofLcR3vuD9IHuqKUDFXGoKU
TLSH T112F0F049E67C027390D1046CBF0C86E10FE34472EB822AA9F083ED631DB99B8B542A01
Magika html
Reporter BlinkzSec
URLMalware sample (SHA256 hash)SignatureTags
http://45.94.31.70/bins/n/an/an/a

Intelligence


File Origin
# of uploads :
1
# of downloads :
52
Origin country :
SE SE
Vendor Threat Intelligence
No detections
Verdict:
Clean
File Type:
ps1
First seen:
2026-07-05T10:12:00Z UTC
Last seen:
2026-07-11T08:55:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=bda76890-1e00-0000-ae26-041a35140000 pid=5173 /usr/bin/sudo guuid=c4e56d92-1e00-0000-ae26-041a36140000 pid=5174 /tmp/sample.bin guuid=bda76890-1e00-0000-ae26-041a35140000 pid=5173->guuid=c4e56d92-1e00-0000-ae26-041a36140000 pid=5174 execve guuid=74d7c292-1e00-0000-ae26-041a37140000 pid=5175 /usr/bin/uname guuid=c4e56d92-1e00-0000-ae26-041a36140000 pid=5174->guuid=74d7c292-1e00-0000-ae26-041a37140000 pid=5175 execve guuid=a5cb3993-1e00-0000-ae26-041a38140000 pid=5176 /usr/bin/wget net send-data write-file guuid=c4e56d92-1e00-0000-ae26-041a36140000 pid=5174->guuid=a5cb3993-1e00-0000-ae26-041a38140000 pid=5176 execve guuid=c7f0a298-1e00-0000-ae26-041a39140000 pid=5177 /usr/bin/chmod guuid=c4e56d92-1e00-0000-ae26-041a36140000 pid=5174->guuid=c7f0a298-1e00-0000-ae26-041a39140000 pid=5177 execve guuid=9c15f398-1e00-0000-ae26-041a3a140000 pid=5178 /tmp/bot net guuid=c4e56d92-1e00-0000-ae26-041a36140000 pid=5174->guuid=9c15f398-1e00-0000-ae26-041a3a140000 pid=5178 execve c490ea45-05d0-53ee-b656-375b9ff31268 45.94.31.70:80 guuid=a5cb3993-1e00-0000-ae26-041a38140000 pid=5176->c490ea45-05d0-53ee-b656-375b9ff31268 send: 139B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=9c15f398-1e00-0000-ae26-041a3a140000 pid=5178->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=7c471799-1e00-0000-ae26-041a3b140000 pid=5179 /tmp/bot net send-data zombie guuid=9c15f398-1e00-0000-ae26-041a3a140000 pid=5178->guuid=7c471799-1e00-0000-ae26-041a3b140000 pid=5179 clone 748cf6d7-bbff-5b73-956e-f911b9d3f5ef 45.94.31.70:37212 guuid=7c471799-1e00-0000-ae26-041a3b140000 pid=5179->748cf6d7-bbff-5b73-956e-f911b9d3f5ef send: 2B guuid=08172499-1e00-0000-ae26-041a3c140000 pid=5180 /tmp/bot guuid=7c471799-1e00-0000-ae26-041a3b140000 pid=5179->guuid=08172499-1e00-0000-ae26-041a3c140000 pid=5180 clone guuid=4ed92799-1e00-0000-ae26-041a3d140000 pid=5181 /tmp/bot net net-scan send-data guuid=7c471799-1e00-0000-ae26-041a3b140000 pid=5179->guuid=4ed92799-1e00-0000-ae26-041a3d140000 pid=5181 clone guuid=55082c99-1e00-0000-ae26-041a3e140000 pid=5182 /tmp/bot net net-scan send-data guuid=7c471799-1e00-0000-ae26-041a3b140000 pid=5179->guuid=55082c99-1e00-0000-ae26-041a3e140000 pid=5182 clone guuid=73b82f99-1e00-0000-ae26-041a3f140000 pid=5183 /tmp/bot net net-scan send-data guuid=7c471799-1e00-0000-ae26-041a3b140000 pid=5179->guuid=73b82f99-1e00-0000-ae26-041a3f140000 pid=5183 clone guuid=4ed92799-1e00-0000-ae26-041a3d140000 pid=5181->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con 50f68266-20a2-5b55-a4f4-9a196bf1fb85 200.69.77.142:23 guuid=4ed92799-1e00-0000-ae26-041a3d140000 pid=5181->50f68266-20a2-5b55-a4f4-9a196bf1fb85 send: 100B guuid=4ed92799-1e00-0000-ae26-041a3d140000 pid=5181|send-data send-data to 4082 IP addresses review logs to see them all guuid=4ed92799-1e00-0000-ae26-041a3d140000 pid=5181->guuid=4ed92799-1e00-0000-ae26-041a3d140000 pid=5181|send-data send guuid=55082c99-1e00-0000-ae26-041a3e140000 pid=5182->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=55082c99-1e00-0000-ae26-041a3e140000 pid=5182|send-data send-data to 4097 IP addresses review logs to see them all guuid=55082c99-1e00-0000-ae26-041a3e140000 pid=5182->guuid=55082c99-1e00-0000-ae26-041a3e140000 pid=5182|send-data send guuid=73b82f99-1e00-0000-ae26-041a3f140000 pid=5183->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con 6a59230f-abd5-5ccf-a459-63046105743c 213.189.201.94:80 guuid=73b82f99-1e00-0000-ae26-041a3f140000 pid=5183->6a59230f-abd5-5ccf-a459-63046105743c send: 40B 87af7719-d085-560c-8908-3d112efd7592 82.78.103.45:80 guuid=73b82f99-1e00-0000-ae26-041a3f140000 pid=5183->87af7719-d085-560c-8908-3d112efd7592 send: 40B 54279fbb-a4db-59aa-a5ad-13b76196906b 82.166.144.155:80 guuid=73b82f99-1e00-0000-ae26-041a3f140000 pid=5183->54279fbb-a4db-59aa-a5ad-13b76196906b send: 40B 458b66c4-ac84-50bb-8906-49e3d827fd51 83.228.232.28:80 guuid=73b82f99-1e00-0000-ae26-041a3f140000 pid=5183->458b66c4-ac84-50bb-8906-49e3d827fd51 send: 40B guuid=73b82f99-1e00-0000-ae26-041a3f140000 pid=5183|send-data send-data to 4097 IP addresses review logs to see them all guuid=73b82f99-1e00-0000-ae26-041a3f140000 pid=5183->guuid=73b82f99-1e00-0000-ae26-041a3f140000 pid=5183|send-data send
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments