🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 8973b3766aea5694e051e28310b6be7ff346ae295c82efd20a25892d6fb409d4. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 8973b3766aea5694e051e28310b6be7ff346ae295c82efd20a25892d6fb409d4
SHA3-384 hash: 580ffa3cae50f6af0209e4956294cc2fc8a50cbe85f174ce5893ff0a94cb86d18c8739e745a6ca50d92975f3c978ad43
SHA1 hash: 9d208bd2fb18ef00c5da666bbea9af3613e474a0
MD5 hash: 2aedda2c4cd437d8ce56e6b76124c932
humanhash: louisiana-quiet-speaker-mississippi
File name:8973b3766aea5694e051e28310b6be7ff346ae295c82efd20a25892d6fb409d4.sh
Download: download sample
File size:11'958 bytes
First seen:2026-02-22 13:19:29 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 96:cCuO3B6csht+O+v1fsn+h4+tIiKqCTyOysYtujtuHKNpUj4waHv6+26fS6fE6fOK:cCuG6p4hvZ5m5FG4j4HKNphv3
TLSH T1F232893721F08B32D3D010C9A2A61FA54F76A70B492614B5F4BE6739AF2DA4374D7B60
Magika xml
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://185.225.74.161/ahn/an/an/a
http://94.156.79.13/wget.shn/an/aelf shellscript ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
22
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
busybox evasive
Status:
terminated
Behavior Graph:
%3 guuid=dbca5cb9-1a00-0000-9ad5-607d3f0b0000 pid=2879 /usr/bin/sudo guuid=d8f970bb-1a00-0000-9ad5-607d450b0000 pid=2885 /tmp/sample.bin guuid=dbca5cb9-1a00-0000-9ad5-607d3f0b0000 pid=2879->guuid=d8f970bb-1a00-0000-9ad5-607d450b0000 pid=2885 execve
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 8973b3766aea5694e051e28310b6be7ff346ae295c82efd20a25892d6fb409d4

(this sample)

8ddd9b0a5b42f7d6fd1a9a3d6157ba0a6476c06030d75dc5988d4cb127c74709

  
Delivery method
Distributed via web download
  
Dropping
MD5 1080c288c309a0009290d1fa8b8d2aeb
  
Dropping
SHA256 8ddd9b0a5b42f7d6fd1a9a3d6157ba0a6476c06030d75dc5988d4cb127c74709

Comments