MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 5bafaf6313b77eda8a32328f1a74ea7c7dc1e7092fa6455b904f471a735b5900. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 5bafaf6313b77eda8a32328f1a74ea7c7dc1e7092fa6455b904f471a735b5900
SHA3-384 hash: a0a196b6a374be3b7fdd983ab4dbaece498ec2ce7b5056802ad6d86883e6e4dc6c8381c2601c2ff26c7fdafe73fcb4a4
SHA1 hash: 33cb01e65edf0e0a2c053f894ab0758056b18a8c
MD5 hash: 02acfab23750c44aea7b4513931ebecc
humanhash: east-yellow-sierra-whiskey
File name:5bafaf6313b77eda8a32328f1a74ea7c7dc1e7092fa6455b904f471a735b5900.sh
Download: download sample
File size:1'755 bytes
First seen:2026-02-22 13:21:07 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 24:cnnRUR8fAR25bm09HHIuCzCRpYdZe1KOujKujsBjl/H/+sCl/HESkkKl/HRkeN:cnRu9Rf4nB6g1KO/Tjl/msCl/8kKl/F
TLSH T1EE31B6B021F148736A605580B3772F6AABF6DC47499361CC38DE5E396F83B42B1AF411
Magika xml
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://146.19.191.207/lol.shn/an/amirai sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
49
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
busybox
Status:
terminated
Behavior Graph:
%3 guuid=27f23395-1a00-0000-fb9c-2d095a0a0000 pid=2650 /usr/bin/sudo guuid=07171498-1a00-0000-fb9c-2d09630a0000 pid=2659 /tmp/sample.bin guuid=27f23395-1a00-0000-fb9c-2d095a0a0000 pid=2650->guuid=07171498-1a00-0000-fb9c-2d09630a0000 pid=2659 execve
Threat name:
Text.Trojan.Generic
Status:
Suspicious
First seen:
2026-02-22 13:25:41 UTC
File Type:
Text (HTML)
AV detection:
4 of 23 (17.39%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 5bafaf6313b77eda8a32328f1a74ea7c7dc1e7092fa6455b904f471a735b5900

(this sample)

  
Delivery method
Distributed via web download

Comments