MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 8fc1dd646af809409c338487365d6484407b3a3f617ddc1c2e3198c4f5f6e0c0. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 8fc1dd646af809409c338487365d6484407b3a3f617ddc1c2e3198c4f5f6e0c0
SHA3-384 hash: 7adcb20a282e73304257aaf2ef64a12c981ffedb5d8317d2494d5c86fc646bdbfbde7fdc7d3f97076bc076d1be05aaf9
SHA1 hash: fe0f131e11fd5c5bd3c482f44426ec059c6d46fe
MD5 hash: d8a052d729bc5ad44e3bfcdc5e3068ff
humanhash: connecticut-coffee-twelve-hydrogen
File name:8fc1dd646af809409c338487365d6484407b3a3f617ddc1c2e3198c4f5f6e0c0.sh
Download: download sample
File size:18'579 bytes
First seen:2026-02-22 13:18:23 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 192:cCul4hvZ5m5FG4j4HKNphv1KLMW6MN7molZ3:a4hvZ5m5FGGoKNphv1KLMW6MN7mob
TLSH T106828D3621F08B335A9065C4B3772BA54F769607456720A8B4FE1E359F5AB03B0EBB21
Magika xml
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://38.6.178.140/easy.shn/an/an/a
http://38.6.178.140/easy_cloud.shn/an/an/a
http://38.6.178.140/easy_lan.shn/an/an/a
http://154.9.30.146/srb.shn/an/aelf mirai
http://196.189.96.138:81/hiddenbin/dvr1.shn/an/an/a
http://updater.zzux.com/mn/an/an/a
http://hxipzknrsojnitzv.zip/bins/bins.sh652285d260515c08cfe146ebdd2f5a4977ec490a608c57007abcb5b6f4fd4975 Miraibotnetdomain mirai opendir sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
6
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive
Result
Gathering data
Status:
terminated
Behavior Graph:
%3 guuid=3ed50f8a-1900-0000-5969-19c729080000 pid=2089 /usr/bin/sudo guuid=e65bd18c-1900-0000-5969-19c72f080000 pid=2095 /tmp/sample.bin guuid=3ed50f8a-1900-0000-5969-19c729080000 pid=2089->guuid=e65bd18c-1900-0000-5969-19c72f080000 pid=2095 execve
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 8fc1dd646af809409c338487365d6484407b3a3f617ddc1c2e3198c4f5f6e0c0

(this sample)

007f065e58d07a799a21a2849a3907334abca1a31392e638d9343126079ca9b5

  
Delivery method
Distributed via web download
  
Dropping
MD5 c488c5f8367ad4612d371973e8aed705
  
Dropping
SHA256 007f065e58d07a799a21a2849a3907334abca1a31392e638d9343126079ca9b5

Comments