MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 933ec42a0288b33fb552db33f80901a5bccbe098d914d3f5ea55cc9e3347867d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Threat unknown
Vendor detections: 7
| SHA256 hash: | 933ec42a0288b33fb552db33f80901a5bccbe098d914d3f5ea55cc9e3347867d |
|---|---|
| SHA3-384 hash: | 6cbe0d28f4fbd0e7ff618200f5f90a02de55ff98b678e713f720a73eb775991b58572951c9ee73b46fd4c0428f1a7d63 |
| SHA1 hash: | 09cdf6fbba08634aa1e4c57b997d252e71f40a7c |
| MD5 hash: | a09269999a420cc42f06889a2ef301eb |
| humanhash: | finch-harry-two-illinois |
| File name: | w.sh |
| Download: | download sample |
| File size: | 874 bytes |
| First seen: | 2025-05-06 12:56:29 UTC |
| Last seen: | Never |
| File type: | sh |
| MIME type: | text/plain |
| ssdeep | 24:b1g7377hNI757xKg1iJD0a8IE5tBlcba1HR:pgr7o5FL1i90a8PBlcO1x |
| TLSH | T1F91100CE169952611E4C8F60B06E94AD66448BD030544FDDEE8C88F26DDA928739BF4C |
| Magika | txt |
| Reporter | |
| Tags: | sh |
Shell script dropper
This file seems to be a shell script dropper, using wget, ftpget and/or curl. More information about the corresponding payload URLs are shown below.
| URL | Malware sample (SHA256 hash) | Signature | Tags |
|---|---|---|---|
| http://62.171.138.173/arm | n/a | n/a | n/a |
| http://62.171.138.173/arm5 | n/a | n/a | n/a |
| http://62.171.138.173/arm6 | n/a | n/a | n/a |
| http://62.171.138.173/arm7 | n/a | n/a | n/a |
| http://62.171.138.173/m68k | n/a | n/a | n/a |
| http://62.171.138.173/mips | n/a | n/a | n/a |
| http://62.171.138.173/mpsl | n/a | n/a | n/a |
| http://62.171.138.173/ppc | n/a | n/a | n/a |
| http://62.171.138.173/sh4 | n/a | n/a | n/a |
| http://62.171.138.173/spc | n/a | n/a | n/a |
| http://62.171.138.173/x86 | n/a | n/a | n/a |
| http://62.171.138.173/x86_64 | n/a | n/a | n/a |
Intelligence
File Origin
# of uploads :
1
# of downloads :
65
Origin country :
DEVendor Threat Intelligence
Detection(s):
Verdict:
Malicious
Score:
92.5%
Link:
Tags:
trojan hype sage
Verdict:
Suspicious
Threat level:
5/10
Confidence:
100%
Score:
100%
Verdict:
Malware
File Type:
SCRIPT
Threat name:
Script-Shell.Worm.Mirai
Status:
Malicious
First seen:
2025-05-04 05:23:00 UTC
File Type:
Text (Shell)
AV detection:
19 of 37 (51.35%)
Threat level:
5/5
Detection(s):
Suspicious file
Result
Malware family:
n/a
Score:
3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Malicious File
Score:
1.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Web download
sh 933ec42a0288b33fb552db33f80901a5bccbe098d914d3f5ea55cc9e3347867d
(this sample)
Delivery method
Distributed via web download
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.