MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 933ec42a0288b33fb552db33f80901a5bccbe098d914d3f5ea55cc9e3347867d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: 933ec42a0288b33fb552db33f80901a5bccbe098d914d3f5ea55cc9e3347867d
SHA3-384 hash: 6cbe0d28f4fbd0e7ff618200f5f90a02de55ff98b678e713f720a73eb775991b58572951c9ee73b46fd4c0428f1a7d63
SHA1 hash: 09cdf6fbba08634aa1e4c57b997d252e71f40a7c
MD5 hash: a09269999a420cc42f06889a2ef301eb
humanhash: finch-harry-two-illinois
File name:w.sh
Download: download sample
File size:874 bytes
First seen:2025-05-06 12:56:29 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 24:b1g7377hNI757xKg1iJD0a8IE5tBlcba1HR:pgr7o5FL1i90a8PBlcO1x
TLSH T1F91100CE169952611E4C8F60B06E94AD66448BD030544FDDEE8C88F26DDA928739BF4C
Magika txt
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://62.171.138.173/armn/an/an/a
http://62.171.138.173/arm5n/an/an/a
http://62.171.138.173/arm6n/an/an/a
http://62.171.138.173/arm7n/an/an/a
http://62.171.138.173/m68kn/an/an/a
http://62.171.138.173/mipsn/an/an/a
http://62.171.138.173/mpsln/an/an/a
http://62.171.138.173/ppcn/an/an/a
http://62.171.138.173/sh4n/an/an/a
http://62.171.138.173/spcn/an/an/a
http://62.171.138.173/x86n/an/an/a
http://62.171.138.173/x86_64n/an/an/a

Intelligence


File Origin
# of uploads :
1
# of downloads :
65
Origin country :
DE DE
Vendor Threat Intelligence
Threat name:
Script-Shell.Worm.Mirai
Status:
Malicious
First seen:
2025-05-04 05:23:00 UTC
File Type:
Text (Shell)
AV detection:
19 of 37 (51.35%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 933ec42a0288b33fb552db33f80901a5bccbe098d914d3f5ea55cc9e3347867d

(this sample)

  
Delivery method
Distributed via web download

Comments