MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 628b0d7e2efe6a29dcb3ab66405a79571bde8a2b2b38499dbe5f17e392b6efad. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 628b0d7e2efe6a29dcb3ab66405a79571bde8a2b2b38499dbe5f17e392b6efad
SHA3-384 hash: 706312713bfeb84ac768231ff3c4ec93737d56cccb6a111d67d43ff24bc71a3d5d3ebad871e8c4e08b51147099d50ec7
SHA1 hash: 2043a1bd56b905bf8acf09e074120c059fd02c46
MD5 hash: 21a9ee16b36ba83f547c6cd0b56764cf
humanhash: arkansas-music-oklahoma-kitten
File name:628b0d7e2efe6a29dcb3ab66405a79571bde8a2b2b38499dbe5f17e392b6efad.sh
Download: download sample
File size:3'334 bytes
First seen:2026-03-13 21:01:56 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 48:csRu9+J9nB6gHrJilrmAE69lr8z6E69lriFE69lrElEHlEzl/+hUm0l/w:cCuIB66Si6fA6fv6fiEFEl3Nw
TLSH T1CF613A7025F00C736E201944F3772BA6ABB7E8574A97618C388E2E396F97F42A5DF411
Magika xml
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://194.156.102.210/bins/bins.shn/an/aascii bash sh ua-wget
http://222.186.52.155:21541/sh/5053.shn/an/an/a
http://45.225.187.6:81/hiddenbin/dvr1.shn/an/aascii bash sh ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
62
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Status:
terminated
Behavior Graph:
%3 guuid=8a665ae8-1600-0000-4afc-b662290f0000 pid=3881 /usr/bin/sudo guuid=1c8a1aeb-1600-0000-4afc-b662350f0000 pid=3893 /tmp/sample.bin guuid=8a665ae8-1600-0000-4afc-b662290f0000 pid=3881->guuid=1c8a1aeb-1600-0000-4afc-b662350f0000 pid=3893 execve
Threat name:
Win32.Trojan.Egairtigado
Status:
Malicious
First seen:
2026-03-13 21:02:19 UTC
File Type:
Text
AV detection:
8 of 24 (33.33%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 628b0d7e2efe6a29dcb3ab66405a79571bde8a2b2b38499dbe5f17e392b6efad

(this sample)

  
Delivery method
Distributed via web download

Comments