MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 6d138a98eba358f9eaf2ed87a360abb6d03a1710a83f814808db4ab63d089620. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 6d138a98eba358f9eaf2ed87a360abb6d03a1710a83f814808db4ab63d089620
SHA3-384 hash: 86d142a1ff8cd8b87c569657fedaa5b86a76b912921203fbafa270e9e75791a5e26b176e9cb0d1d23ea52f94626608da
SHA1 hash: 5d79af03e375960d08b9a512633ae13cb1cc653e
MD5 hash: 9d27fabe470de4ee8d53fe046d38da29
humanhash: maryland-paris-princess-paris
File name:c.sh
Download: download sample
File size:780 bytes
First seen:2025-11-18 17:40:46 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 24:3J3n9mI94l9MNI7D9UKI9jgi94N9faM9309KtB39Z9Q69mHA:yX5+7gPaoqg
TLSH T13201CC8D217596C21E4C8F0CB06AC09CA6FDB3DA78B49F55F02748F068D92446254BBA
Magika batch
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://139.59.247.208/armn/an/an/a
http://139.59.247.208/arm5n/an/an/a
http://139.59.247.208/arm6n/an/an/a
http://139.59.247.208/arm7n/an/an/a
http://139.59.247.208/m68kn/an/an/a
http://139.59.247.208/mipsn/an/an/a
http://139.59.247.208/mpsln/an/an/a
http://139.59.247.208/ppcn/an/an/a
http://139.59.247.208/sh4n/an/an/a
http://139.59.247.208/spcn/an/an/a
http://139.59.247.208/x86n/an/an/a
http://139.59.247.208/x86_64n/an/an/a

Intelligence


File Origin
# of uploads :
1
# of downloads :
29
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
mirai
Result
Gathering data
Status:
terminated
Behavior Graph:
%3 guuid=ec516da6-1a00-0000-974b-ab87b90b0000 pid=3001 /usr/bin/sudo guuid=f03f51a9-1a00-0000-974b-ab87bd0b0000 pid=3005 /tmp/sample.bin guuid=ec516da6-1a00-0000-974b-ab87b90b0000 pid=3001->guuid=f03f51a9-1a00-0000-974b-ab87bd0b0000 pid=3005 execve guuid=1cc9daa9-1a00-0000-974b-ab87c00b0000 pid=3008 /usr/bin/curl net guuid=f03f51a9-1a00-0000-974b-ab87bd0b0000 pid=3005->guuid=1cc9daa9-1a00-0000-974b-ab87c00b0000 pid=3008 execve fd5d93f1-116e-5a7c-ae20-f87d02612a73 139.59.247.208:80 guuid=1cc9daa9-1a00-0000-974b-ab87c00b0000 pid=3008->fd5d93f1-116e-5a7c-ae20-f87d02612a73 con
Gathering data
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 6d138a98eba358f9eaf2ed87a360abb6d03a1710a83f814808db4ab63d089620

(this sample)

  
Delivery method
Distributed via web download

Comments