🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 629a4247fa8eeada99bc0325c0092e469cb14217ef071a5d11798038bd7f146e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Ngioweb


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 629a4247fa8eeada99bc0325c0092e469cb14217ef071a5d11798038bd7f146e
SHA3-384 hash: 22fde8ef9d19000eaac8ea52d08499e7eaa0bf73615f4d1de8519167797f6827a32e86520018b48b9bee2b04e473f65b
SHA1 hash: 83c45f8b4e802e1e962dac8d9201edb6b1d80090
MD5 hash: 98d16fb3df05787f66f224ab18e91058
humanhash: river-ohio-sweet-item
File name:629a4247fa8eeada99bc0325c0092e469cb14217ef071a5d11798038bd7f146e.sh
Download: download sample
Signature Ngioweb
File size:1'791 bytes
First seen:2026-09-17 14:00:25 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 24:cnnRUR8fAR256zl9HHIuCzCRpYdZe1KOujKujsBjl/H/+sCl/HESkkKl/HRkeN:cnRu9RjzfnB6g1KO/Tjl/msCl/8kKl/F
TLSH T1B231C5B021F148736A605580B3771F66ABF6DC47499362CC78DE5E39AF83B42B1AF412
Magika xml
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://193.243.147.115/avTECHbfb53568a2c7b74606886f9b1a535fe582a41c5d73149302e1c8331ea76c323f Ngiowebua-wget
http://146.19.191.207/lol.shn/an/amirai sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
67
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
busybox
Status:
terminated
Behavior Graph:
%3 guuid=fa1131bf-1b00-0000-ce9c-0ae286060000 pid=1670 /usr/bin/sudo guuid=fdaab6c2-1b00-0000-ce9c-0ae288060000 pid=1672 /tmp/sample.bin guuid=fa1131bf-1b00-0000-ce9c-0ae286060000 pid=1670->guuid=fdaab6c2-1b00-0000-ce9c-0ae288060000 pid=1672 execve
Threat name:
Script-BAT.Trojan.Heuristic
Status:
Malicious
First seen:
2026-09-17 14:01:14 UTC
File Type:
Text
AV detection:
8 of 23 (34.78%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
execution
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Executes a command shell one-liner
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Ngioweb

sh 629a4247fa8eeada99bc0325c0092e469cb14217ef071a5d11798038bd7f146e

(this sample)

  
Delivery method
Distributed via web download

Comments