MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 5f6b68f305dc363daaf18a05ce546813b4af9573a76ea46281648ff8a36e5dcd. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 5f6b68f305dc363daaf18a05ce546813b4af9573a76ea46281648ff8a36e5dcd
SHA3-384 hash: 994a4455910533ae4de88de8c412c929de3a2457d2ef23965f4313bfaf9236cd204c1f918744818ce1cea0c23d54e14d
SHA1 hash: 95015eaa768bb6e3e63ef78ffba63c09672f3ac4
MD5 hash: 8d4963a5be9e6d17c5f26880a4747c9d
humanhash: louisiana-double-west-south
File name:yukari.sh
Download: download sample
File size:1'089 bytes
First seen:2025-10-19 16:43:44 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 24:BjeNQZNNx7wGQSay56WQFGQSay53F1kq/FGQSayp:1jx9gs6EgsV1lgga
TLSH T16F11E68E6430DE303909A51E59D7A5C0624754378137B918789D35122F88718F1EA66E
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://192.142.10.111/n/an/an/a

Intelligence


File Origin
# of uploads :
1
# of downloads :
32
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
busybox opendir opendir
Verdict:
Malicious
File Type:
ps1
First seen:
2025-10-19T14:45:00Z UTC
Last seen:
2025-10-19T18:50:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=d511e1cf-1600-0000-5c64-75fc710d0000 pid=3441 /usr/bin/sudo guuid=a109aed2-1600-0000-5c64-75fc7a0d0000 pid=3450 /tmp/sample.bin guuid=d511e1cf-1600-0000-5c64-75fc710d0000 pid=3441->guuid=a109aed2-1600-0000-5c64-75fc7a0d0000 pid=3450 execve guuid=e0da1cd3-1600-0000-5c64-75fc7c0d0000 pid=3452 /usr/bin/wget net send-data write-file guuid=a109aed2-1600-0000-5c64-75fc7a0d0000 pid=3450->guuid=e0da1cd3-1600-0000-5c64-75fc7c0d0000 pid=3452 execve guuid=231f5ddc-1600-0000-5c64-75fc9b0d0000 pid=3483 /usr/bin/chmod guuid=a109aed2-1600-0000-5c64-75fc7a0d0000 pid=3450->guuid=231f5ddc-1600-0000-5c64-75fc9b0d0000 pid=3483 execve guuid=cb14d6dc-1600-0000-5c64-75fc9f0d0000 pid=3487 /usr/bin/dash guuid=a109aed2-1600-0000-5c64-75fc7a0d0000 pid=3450->guuid=cb14d6dc-1600-0000-5c64-75fc9f0d0000 pid=3487 clone guuid=8dfea6dd-1600-0000-5c64-75fca30d0000 pid=3491 /usr/bin/sleep guuid=a109aed2-1600-0000-5c64-75fc7a0d0000 pid=3450->guuid=8dfea6dd-1600-0000-5c64-75fca30d0000 pid=3491 execve guuid=ec10ca19-1700-0000-5c64-75fc0b0e0000 pid=3595 /usr/bin/ps guuid=a109aed2-1600-0000-5c64-75fc7a0d0000 pid=3450->guuid=ec10ca19-1700-0000-5c64-75fc0b0e0000 pid=3595 execve guuid=e06bd019-1700-0000-5c64-75fc0c0e0000 pid=3596 /usr/bin/grep guuid=a109aed2-1600-0000-5c64-75fc7a0d0000 pid=3450->guuid=e06bd019-1700-0000-5c64-75fc0c0e0000 pid=3596 execve guuid=de6ad419-1700-0000-5c64-75fc0d0e0000 pid=3597 /usr/bin/grep guuid=a109aed2-1600-0000-5c64-75fc7a0d0000 pid=3450->guuid=de6ad419-1700-0000-5c64-75fc0d0e0000 pid=3597 execve guuid=c564ff1e-1700-0000-5c64-75fc1a0e0000 pid=3610 /usr/bin/rm delete-file guuid=a109aed2-1600-0000-5c64-75fc7a0d0000 pid=3450->guuid=c564ff1e-1700-0000-5c64-75fc1a0e0000 pid=3610 execve guuid=0ca2501f-1700-0000-5c64-75fc1c0e0000 pid=3612 /usr/bin/wget net send-data write-file guuid=a109aed2-1600-0000-5c64-75fc7a0d0000 pid=3450->guuid=0ca2501f-1700-0000-5c64-75fc1c0e0000 pid=3612 execve guuid=ed6dfb26-1700-0000-5c64-75fc360e0000 pid=3638 /usr/bin/chmod guuid=a109aed2-1600-0000-5c64-75fc7a0d0000 pid=3450->guuid=ed6dfb26-1700-0000-5c64-75fc360e0000 pid=3638 execve guuid=a6d74d27-1700-0000-5c64-75fc380e0000 pid=3640 /usr/bin/dash guuid=a109aed2-1600-0000-5c64-75fc7a0d0000 pid=3450->guuid=a6d74d27-1700-0000-5c64-75fc380e0000 pid=3640 clone guuid=326fe927-1700-0000-5c64-75fc3c0e0000 pid=3644 /usr/bin/sleep guuid=a109aed2-1600-0000-5c64-75fc7a0d0000 pid=3450->guuid=326fe927-1700-0000-5c64-75fc3c0e0000 pid=3644 execve guuid=bdc0d063-1700-0000-5c64-75fcec0e0000 pid=3820 /usr/bin/ps guuid=a109aed2-1600-0000-5c64-75fc7a0d0000 pid=3450->guuid=bdc0d063-1700-0000-5c64-75fcec0e0000 pid=3820 execve guuid=7ecfd663-1700-0000-5c64-75fced0e0000 pid=3821 /usr/bin/grep guuid=a109aed2-1600-0000-5c64-75fc7a0d0000 pid=3450->guuid=7ecfd663-1700-0000-5c64-75fced0e0000 pid=3821 execve guuid=3ce9d963-1700-0000-5c64-75fcef0e0000 pid=3823 /usr/bin/grep guuid=a109aed2-1600-0000-5c64-75fc7a0d0000 pid=3450->guuid=3ce9d963-1700-0000-5c64-75fcef0e0000 pid=3823 execve guuid=8420c565-1700-0000-5c64-75fcfa0e0000 pid=3834 /usr/bin/rm delete-file guuid=a109aed2-1600-0000-5c64-75fc7a0d0000 pid=3450->guuid=8420c565-1700-0000-5c64-75fcfa0e0000 pid=3834 execve guuid=7171fd65-1700-0000-5c64-75fcfc0e0000 pid=3836 /usr/bin/wget net send-data write-file guuid=a109aed2-1600-0000-5c64-75fc7a0d0000 pid=3450->guuid=7171fd65-1700-0000-5c64-75fcfc0e0000 pid=3836 execve guuid=ca5c0e6b-1700-0000-5c64-75fc140f0000 pid=3860 /usr/bin/chmod guuid=a109aed2-1600-0000-5c64-75fc7a0d0000 pid=3450->guuid=ca5c0e6b-1700-0000-5c64-75fc140f0000 pid=3860 execve guuid=f7534b6b-1700-0000-5c64-75fc150f0000 pid=3861 /usr/bin/dash guuid=a109aed2-1600-0000-5c64-75fc7a0d0000 pid=3450->guuid=f7534b6b-1700-0000-5c64-75fc150f0000 pid=3861 clone guuid=192fc56b-1700-0000-5c64-75fc180f0000 pid=3864 /usr/bin/sleep guuid=a109aed2-1600-0000-5c64-75fc7a0d0000 pid=3450->guuid=192fc56b-1700-0000-5c64-75fc180f0000 pid=3864 execve guuid=03b4aaa7-1700-0000-5c64-75fcb00f0000 pid=4016 /usr/bin/ps guuid=a109aed2-1600-0000-5c64-75fc7a0d0000 pid=3450->guuid=03b4aaa7-1700-0000-5c64-75fcb00f0000 pid=4016 execve guuid=c630b1a7-1700-0000-5c64-75fcb10f0000 pid=4017 /usr/bin/grep guuid=a109aed2-1600-0000-5c64-75fc7a0d0000 pid=3450->guuid=c630b1a7-1700-0000-5c64-75fcb10f0000 pid=4017 execve guuid=0c8db8a7-1700-0000-5c64-75fcb30f0000 pid=4019 /usr/bin/grep guuid=a109aed2-1600-0000-5c64-75fc7a0d0000 pid=3450->guuid=0c8db8a7-1700-0000-5c64-75fcb30f0000 pid=4019 execve guuid=ef4e24ab-1700-0000-5c64-75fcba0f0000 pid=4026 /usr/bin/rm delete-file guuid=a109aed2-1600-0000-5c64-75fc7a0d0000 pid=3450->guuid=ef4e24ab-1700-0000-5c64-75fcba0f0000 pid=4026 execve guuid=cdb197ab-1700-0000-5c64-75fcbc0f0000 pid=4028 /usr/bin/wget net send-data write-file guuid=a109aed2-1600-0000-5c64-75fc7a0d0000 pid=3450->guuid=cdb197ab-1700-0000-5c64-75fcbc0f0000 pid=4028 execve guuid=2ac0d4b2-1700-0000-5c64-75fcd10f0000 pid=4049 /usr/bin/chmod guuid=a109aed2-1600-0000-5c64-75fc7a0d0000 pid=3450->guuid=2ac0d4b2-1700-0000-5c64-75fcd10f0000 pid=4049 execve guuid=9ca54eb3-1700-0000-5c64-75fcd30f0000 pid=4051 /usr/bin/dash guuid=a109aed2-1600-0000-5c64-75fc7a0d0000 pid=3450->guuid=9ca54eb3-1700-0000-5c64-75fcd30f0000 pid=4051 clone guuid=fdc250b5-1700-0000-5c64-75fcda0f0000 pid=4058 /usr/bin/sleep guuid=a109aed2-1600-0000-5c64-75fc7a0d0000 pid=3450->guuid=fdc250b5-1700-0000-5c64-75fcda0f0000 pid=4058 execve guuid=b4593cf1-1700-0000-5c64-75fc61100000 pid=4193 /usr/bin/ps guuid=a109aed2-1600-0000-5c64-75fc7a0d0000 pid=3450->guuid=b4593cf1-1700-0000-5c64-75fc61100000 pid=4193 execve guuid=a86741f1-1700-0000-5c64-75fc62100000 pid=4194 /usr/bin/grep guuid=a109aed2-1600-0000-5c64-75fc7a0d0000 pid=3450->guuid=a86741f1-1700-0000-5c64-75fc62100000 pid=4194 execve guuid=b51c47f1-1700-0000-5c64-75fc63100000 pid=4195 /usr/bin/grep guuid=a109aed2-1600-0000-5c64-75fc7a0d0000 pid=3450->guuid=b51c47f1-1700-0000-5c64-75fc63100000 pid=4195 execve guuid=244ba7f6-1700-0000-5c64-75fc75100000 pid=4213 /usr/bin/rm delete-file guuid=a109aed2-1600-0000-5c64-75fc7a0d0000 pid=3450->guuid=244ba7f6-1700-0000-5c64-75fc75100000 pid=4213 execve guuid=37d9eaf6-1700-0000-5c64-75fc79100000 pid=4217 /usr/bin/wget net send-data write-file guuid=a109aed2-1600-0000-5c64-75fc7a0d0000 pid=3450->guuid=37d9eaf6-1700-0000-5c64-75fc79100000 pid=4217 execve guuid=899022fc-1700-0000-5c64-75fc90100000 pid=4240 /usr/bin/chmod guuid=a109aed2-1600-0000-5c64-75fc7a0d0000 pid=3450->guuid=899022fc-1700-0000-5c64-75fc90100000 pid=4240 execve guuid=b9298efc-1700-0000-5c64-75fc91100000 pid=4241 /usr/bin/dash guuid=a109aed2-1600-0000-5c64-75fc7a0d0000 pid=3450->guuid=b9298efc-1700-0000-5c64-75fc91100000 pid=4241 clone guuid=d87d63fd-1700-0000-5c64-75fc95100000 pid=4245 /usr/bin/sleep guuid=a109aed2-1600-0000-5c64-75fc7a0d0000 pid=3450->guuid=d87d63fd-1700-0000-5c64-75fc95100000 pid=4245 execve guuid=7dac4c39-1800-0000-5c64-75fc4c110000 pid=4428 /usr/bin/ps guuid=a109aed2-1600-0000-5c64-75fc7a0d0000 pid=3450->guuid=7dac4c39-1800-0000-5c64-75fc4c110000 pid=4428 execve guuid=0eb15339-1800-0000-5c64-75fc4d110000 pid=4429 /usr/bin/grep guuid=a109aed2-1600-0000-5c64-75fc7a0d0000 pid=3450->guuid=0eb15339-1800-0000-5c64-75fc4d110000 pid=4429 execve guuid=c87e5939-1800-0000-5c64-75fc4e110000 pid=4430 /usr/bin/grep guuid=a109aed2-1600-0000-5c64-75fc7a0d0000 pid=3450->guuid=c87e5939-1800-0000-5c64-75fc4e110000 pid=4430 execve guuid=f94c423f-1800-0000-5c64-75fc66110000 pid=4454 /usr/bin/rm delete-file guuid=a109aed2-1600-0000-5c64-75fc7a0d0000 pid=3450->guuid=f94c423f-1800-0000-5c64-75fc66110000 pid=4454 execve guuid=028f8d3f-1800-0000-5c64-75fc68110000 pid=4456 /usr/bin/wget net send-data write-file guuid=a109aed2-1600-0000-5c64-75fc7a0d0000 pid=3450->guuid=028f8d3f-1800-0000-5c64-75fc68110000 pid=4456 execve guuid=4beed645-1800-0000-5c64-75fc84110000 pid=4484 /usr/bin/chmod guuid=a109aed2-1600-0000-5c64-75fc7a0d0000 pid=3450->guuid=4beed645-1800-0000-5c64-75fc84110000 pid=4484 execve guuid=8edf1246-1800-0000-5c64-75fc86110000 pid=4486 /usr/bin/dash guuid=a109aed2-1600-0000-5c64-75fc7a0d0000 pid=3450->guuid=8edf1246-1800-0000-5c64-75fc86110000 pid=4486 clone guuid=9951a246-1800-0000-5c64-75fc8c110000 pid=4492 /usr/bin/sleep guuid=a109aed2-1600-0000-5c64-75fc7a0d0000 pid=3450->guuid=9951a246-1800-0000-5c64-75fc8c110000 pid=4492 execve guuid=90297a82-1800-0000-5c64-75fc7a120000 pid=4730 /usr/bin/ps guuid=a109aed2-1600-0000-5c64-75fc7a0d0000 pid=3450->guuid=90297a82-1800-0000-5c64-75fc7a120000 pid=4730 execve guuid=d0a97e82-1800-0000-5c64-75fc7b120000 pid=4731 /usr/bin/grep guuid=a109aed2-1600-0000-5c64-75fc7a0d0000 pid=3450->guuid=d0a97e82-1800-0000-5c64-75fc7b120000 pid=4731 execve guuid=067f8282-1800-0000-5c64-75fc7c120000 pid=4732 /usr/bin/grep guuid=a109aed2-1600-0000-5c64-75fc7a0d0000 pid=3450->guuid=067f8282-1800-0000-5c64-75fc7c120000 pid=4732 execve guuid=bd547487-1800-0000-5c64-75fc92120000 pid=4754 /usr/bin/rm delete-file guuid=a109aed2-1600-0000-5c64-75fc7a0d0000 pid=3450->guuid=bd547487-1800-0000-5c64-75fc92120000 pid=4754 execve guuid=71b8b387-1800-0000-5c64-75fc93120000 pid=4755 /usr/bin/wget net send-data write-file guuid=a109aed2-1600-0000-5c64-75fc7a0d0000 pid=3450->guuid=71b8b387-1800-0000-5c64-75fc93120000 pid=4755 execve guuid=f528078d-1800-0000-5c64-75fcaa120000 pid=4778 /usr/bin/chmod guuid=a109aed2-1600-0000-5c64-75fc7a0d0000 pid=3450->guuid=f528078d-1800-0000-5c64-75fcaa120000 pid=4778 execve guuid=06a3638d-1800-0000-5c64-75fcac120000 pid=4780 /usr/bin/dash guuid=a109aed2-1600-0000-5c64-75fc7a0d0000 pid=3450->guuid=06a3638d-1800-0000-5c64-75fcac120000 pid=4780 clone guuid=3bf1288e-1800-0000-5c64-75fcb0120000 pid=4784 /usr/bin/sleep guuid=a109aed2-1600-0000-5c64-75fc7a0d0000 pid=3450->guuid=3bf1288e-1800-0000-5c64-75fcb0120000 pid=4784 execve guuid=ac9537ca-1800-0000-5c64-75fc68130000 pid=4968 /usr/bin/ps guuid=a109aed2-1600-0000-5c64-75fc7a0d0000 pid=3450->guuid=ac9537ca-1800-0000-5c64-75fc68130000 pid=4968 execve guuid=bd0c41ca-1800-0000-5c64-75fc69130000 pid=4969 /usr/bin/grep guuid=a109aed2-1600-0000-5c64-75fc7a0d0000 pid=3450->guuid=bd0c41ca-1800-0000-5c64-75fc69130000 pid=4969 execve guuid=5ef847ca-1800-0000-5c64-75fc6a130000 pid=4970 /usr/bin/grep guuid=a109aed2-1600-0000-5c64-75fc7a0d0000 pid=3450->guuid=5ef847ca-1800-0000-5c64-75fc6a130000 pid=4970 execve guuid=795c0dd0-1800-0000-5c64-75fc7c130000 pid=4988 /usr/bin/rm delete-file guuid=a109aed2-1600-0000-5c64-75fc7a0d0000 pid=3450->guuid=795c0dd0-1800-0000-5c64-75fc7c130000 pid=4988 execve guuid=f59150d0-1800-0000-5c64-75fc7d130000 pid=4989 /usr/bin/wget net send-data write-file guuid=a109aed2-1600-0000-5c64-75fc7a0d0000 pid=3450->guuid=f59150d0-1800-0000-5c64-75fc7d130000 pid=4989 execve guuid=53a5a4d8-1800-0000-5c64-75fc92130000 pid=5010 /usr/bin/chmod guuid=a109aed2-1600-0000-5c64-75fc7a0d0000 pid=3450->guuid=53a5a4d8-1800-0000-5c64-75fc92130000 pid=5010 execve guuid=545eded8-1800-0000-5c64-75fc94130000 pid=5012 /tmp/yuk net guuid=a109aed2-1600-0000-5c64-75fc7a0d0000 pid=3450->guuid=545eded8-1800-0000-5c64-75fc94130000 pid=5012 execve guuid=8a160dd9-1800-0000-5c64-75fc98130000 pid=5016 /usr/bin/sleep guuid=a109aed2-1600-0000-5c64-75fc7a0d0000 pid=3450->guuid=8a160dd9-1800-0000-5c64-75fc98130000 pid=5016 execve guuid=1117ee14-1900-0000-5c64-75fc2d140000 pid=5165 /usr/bin/ps guuid=a109aed2-1600-0000-5c64-75fc7a0d0000 pid=3450->guuid=1117ee14-1900-0000-5c64-75fc2d140000 pid=5165 execve guuid=684cf914-1900-0000-5c64-75fc2e140000 pid=5166 /usr/bin/grep guuid=a109aed2-1600-0000-5c64-75fc7a0d0000 pid=3450->guuid=684cf914-1900-0000-5c64-75fc2e140000 pid=5166 execve guuid=2dc80115-1900-0000-5c64-75fc2f140000 pid=5167 /usr/bin/grep guuid=a109aed2-1600-0000-5c64-75fc7a0d0000 pid=3450->guuid=2dc80115-1900-0000-5c64-75fc2f140000 pid=5167 execve guuid=7c59491b-1900-0000-5c64-75fc3b140000 pid=5179 /usr/bin/rm delete-file guuid=a109aed2-1600-0000-5c64-75fc7a0d0000 pid=3450->guuid=7c59491b-1900-0000-5c64-75fc3b140000 pid=5179 execve 731c8512-fd62-5662-bb47-58a1813c31ee 192.142.10.111:80 guuid=e0da1cd3-1600-0000-5c64-75fc7c0d0000 pid=3452->731c8512-fd62-5662-bb47-58a1813c31ee send: 136B guuid=0ca2501f-1700-0000-5c64-75fc1c0e0000 pid=3612->731c8512-fd62-5662-bb47-58a1813c31ee send: 136B guuid=7171fd65-1700-0000-5c64-75fcfc0e0000 pid=3836->731c8512-fd62-5662-bb47-58a1813c31ee send: 135B guuid=cdb197ab-1700-0000-5c64-75fcbc0f0000 pid=4028->731c8512-fd62-5662-bb47-58a1813c31ee send: 136B guuid=37d9eaf6-1700-0000-5c64-75fc79100000 pid=4217->731c8512-fd62-5662-bb47-58a1813c31ee send: 136B guuid=028f8d3f-1800-0000-5c64-75fc68110000 pid=4456->731c8512-fd62-5662-bb47-58a1813c31ee send: 136B guuid=71b8b387-1800-0000-5c64-75fc93120000 pid=4755->731c8512-fd62-5662-bb47-58a1813c31ee send: 135B guuid=f59150d0-1800-0000-5c64-75fc7d130000 pid=4989->731c8512-fd62-5662-bb47-58a1813c31ee send: 135B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=545eded8-1800-0000-5c64-75fc94130000 pid=5012->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=3476fcd8-1800-0000-5c64-75fc95130000 pid=5013 /tmp/yuk zombie guuid=545eded8-1800-0000-5c64-75fc94130000 pid=5012->guuid=3476fcd8-1800-0000-5c64-75fc95130000 pid=5013 clone guuid=f70effd8-1800-0000-5c64-75fc96130000 pid=5014 /tmp/yuk guuid=545eded8-1800-0000-5c64-75fc94130000 pid=5012->guuid=f70effd8-1800-0000-5c64-75fc96130000 pid=5014 clone guuid=605e01d9-1800-0000-5c64-75fc97130000 pid=5015 /tmp/yuk net send-data zombie guuid=545eded8-1800-0000-5c64-75fc94130000 pid=5012->guuid=605e01d9-1800-0000-5c64-75fc97130000 pid=5015 clone guuid=605e01d9-1800-0000-5c64-75fc97130000 pid=5015->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con ef1f1ab0-3133-5707-94b0-7c71c9786164 192.142.10.111:9506 guuid=605e01d9-1800-0000-5c64-75fc97130000 pid=5015->ef1f1ab0-3133-5707-94b0-7c71c9786164 send: 7B guuid=91c90ed9-1800-0000-5c64-75fc99130000 pid=5017 /tmp/yuk guuid=605e01d9-1800-0000-5c64-75fc97130000 pid=5015->guuid=91c90ed9-1800-0000-5c64-75fc99130000 pid=5017 clone guuid=162711d9-1800-0000-5c64-75fc9a130000 pid=5018 /tmp/yuk guuid=605e01d9-1800-0000-5c64-75fc97130000 pid=5015->guuid=162711d9-1800-0000-5c64-75fc9a130000 pid=5018 clone guuid=889613d9-1800-0000-5c64-75fc9b130000 pid=5019 /tmp/yuk net net-scan send-data guuid=605e01d9-1800-0000-5c64-75fc97130000 pid=5015->guuid=889613d9-1800-0000-5c64-75fc9b130000 pid=5019 clone guuid=889613d9-1800-0000-5c64-75fc9b130000 pid=5019->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con 36fc2c38-57fc-5cf9-ad06-3f31f3f01644 35.241.39.210:23 guuid=889613d9-1800-0000-5c64-75fc9b130000 pid=5019->36fc2c38-57fc-5cf9-ad06-3f31f3f01644 send: 40B 79759759-0c20-5843-aebc-d464301f63e3 34.36.17.247:23 guuid=889613d9-1800-0000-5c64-75fc9b130000 pid=5019->79759759-0c20-5843-aebc-d464301f63e3 send: 40B guuid=889613d9-1800-0000-5c64-75fc9b130000 pid=5019|send-data send-data to 4097 IP addresses review logs to see them all guuid=889613d9-1800-0000-5c64-75fc9b130000 pid=5019->guuid=889613d9-1800-0000-5c64-75fc9b130000 pid=5019|send-data send
Threat name:
Script-Shell.Trojan.Heuristic
Status:
Malicious
First seen:
2025-10-19 16:44:32 UTC
File Type:
Text (Shell)
AV detection:
7 of 24 (29.17%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 5f6b68f305dc363daaf18a05ce546813b4af9573a76ea46281648ff8a36e5dcd

(this sample)

  
Delivery method
Distributed via web download

Comments