🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 6b700b6ed41413e36dcffb50d8d9f0b082e8b2f514a123636ba715fde1bc7487. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 6b700b6ed41413e36dcffb50d8d9f0b082e8b2f514a123636ba715fde1bc7487
SHA3-384 hash: c7b12ea6c9a5ba1d5761daa3011ed791bf0c4378f0cc0466b68b961c916ada5a64ce957777aa9981a7123ab31cb6323c
SHA1 hash: 07fab5ef09adcc3849b7694e1f7221cc976dcc27
MD5 hash: 530141c5000a7c335d3b301f0b2115cb
humanhash: foxtrot-fix-table-mike
File name:6b700b6ed41413e36dcffb50d8d9f0b082e8b2f514a123636ba715fde1bc7487.sh
Download: download sample
File size:10'464 bytes
First seen:2026-09-13 03:05:54 UTC
Last seen:2026-09-13 20:33:20 UTC
File type: sh
MIME type:text/plain
ssdeep 192:cCu7e1OJi1OyPsN8GsNDM6p4hvZ5m5FoKNpivm:ye1OJi1OyPsN8GsND3p4hvZ5m5FoKNp1
TLSH T17622477B21F08B32D3D450C953660EA14E72AB4B996618B5F4BE93369F2C90331E7F61
Magika xml
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://45.63.77.220/linux-mipsn/an/an/a
http://181.197.159.183:8888/in/an/an/a

Intelligence


File Origin
# of uploads :
3
# of downloads :
62
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
busybox evasive
Status:
terminated
Behavior Graph:
%3 guuid=5a4011e8-1600-0000-ae49-8d99d30d0000 pid=3539 /usr/bin/sudo guuid=0b856fec-1600-0000-ae49-8d99df0d0000 pid=3551 /tmp/sample.bin guuid=5a4011e8-1600-0000-ae49-8d99d30d0000 pid=3539->guuid=0b856fec-1600-0000-ae49-8d99df0d0000 pid=3551 execve
Threat name:
Script-BAT.Trojan.Heuristic
Status:
Malicious
First seen:
2026-09-13 03:06:26 UTC
File Type:
Text (HTML)
AV detection:
5 of 36 (13.89%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
execution
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Executes a command shell one-liner
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 6b700b6ed41413e36dcffb50d8d9f0b082e8b2f514a123636ba715fde1bc7487

(this sample)

  
Delivery method
Distributed via web download

Comments