MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 813543ee8a95b9d135553878c9956792fc1b7be6b6566adcb18aecde3fb495f4. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: 813543ee8a95b9d135553878c9956792fc1b7be6b6566adcb18aecde3fb495f4
SHA3-384 hash: 8763d4f1481cf74288faf8b98933223dfbb37366033b7c0c76f1d3fe4af0fdee7ca6af6d5fa83c7ce1960cd8ae3d8830
SHA1 hash: 4b1d4b92ed416e78701925b67997c62ba549713c
MD5 hash: 521a8e7c4a99b185e53f37c1bed1b362
humanhash: jupiter-michigan-connecticut-twenty
File name:fc
Download: download sample
File size:1'293 bytes
First seen:2025-06-02 01:11:25 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 24:wcKqv0m9Nn6soeFqSsoeFqXeFqXeFqXeFqWveFq/e4:3PDn6aqSaqkqkqkqWcqz
TLSH T11021D3631B0C79F0BE8E991AB6678B9A5CDED08F3D830A11D43083D6BC945645D34B70
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://185.142.53.233/arm7b530d6edb5659f75331fac721a888aaae428a06d6b3f658b1b0c9d23c4b75ba0 Miraimirai ua-wget
http://185.142.53.233/mips63e5d4c2ac320aa49bfc1c23e1a253c00ec5e51b4b64f0fb304c34f4d0a6fa56 Gafgytddos elf gafgyt mirai
http://185.142.53.233/mpsl1f20bd51306a7cd754a0d6864311ca2a4fc8def258607ba35285216eb39e6891 Gafgytddos elf gafgyt mirai

Intelligence


File Origin
# of uploads :
1
# of downloads :
95
Origin country :
DE DE
Vendor Threat Intelligence
Threat name:
Linux.Trojan.Generic
Status:
Suspicious
First seen:
2025-06-02 06:31:24 UTC
File Type:
Text (Shell)
AV detection:
8 of 36 (22.22%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 813543ee8a95b9d135553878c9956792fc1b7be6b6566adcb18aecde3fb495f4

(this sample)

  
Delivery method
Distributed via web download

Comments