MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 96856b7814c5af4ee984aac9ded443fd7d6ebd8c2f2df7e47b0ae65b75639722. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Threat unknown
Vendor detections: 5
| SHA256 hash: | 96856b7814c5af4ee984aac9ded443fd7d6ebd8c2f2df7e47b0ae65b75639722 |
|---|---|
| SHA3-384 hash: | 50c49d62d410c225f6838383cbd7d5b88a53edd3953598793ef70bd4881e623b9719e4bb81b91ef864816e00c9611081 |
| SHA1 hash: | 266cf0f6842a5e2766c21480019416a5a208b5c1 |
| MD5 hash: | 2bc2c43a63e92b9b0a9d8b426ef5cca7 |
| humanhash: | december-robert-diet-kansas |
| File name: | w |
| Download: | download sample |
| File size: | 584 bytes |
| First seen: | 2026-07-26 12:12:20 UTC |
| Last seen: | Never |
| File type: | sh |
| MIME type: | text/x-shellscript |
| ssdeep | 6:hoewVyipIbxa0EUDmpG8xa0EUDmps3Mxa0EUDmpGVxa0EUDmp1xa0EUDmpRMxa0h:G0EeVr0Ee5370Ee720Eeb0EeA70EeL |
| TLSH | T118F03CCD0163AA318E43CCF7B5638578A450E8C87B928BDDEC8E96605180A90F862E88 |
| TrID | 70.0% (.SH) Linux/UNIX shell script (7000/1) 30.0% (.) Unix-like shebang (var.3) (gen) (3000/1) |
| Magika | shell |
| Reporter |
Shell script dropper
This file seems to be a shell script dropper, using wget, ftpget and/or curl. More information about the corresponding payload URLs are shown below.
| URL | Malware sample (SHA256 hash) | Signature | Tags |
|---|---|---|---|
| http://45.150.195.235/tmips | 0e8bb412e1556aade8266d990c840a45b282c53e25da22c10693cd113781b9b1 | Mirai | elf gafgyt mips mirai ua-wget |
| http://45.150.195.235/tmpsl | af1e82d30143a16d33b00585dd9ad8ff7f158b9d53774fd5c0e722e109681425 | Mirai | elf gafgyt mips mirai ua-wget |
| http://45.150.195.235/tarm | 176420754571f94f9f35614adb262679607614a7d800544f8c1363f2d26c82cc | Mirai | arm elf gafgyt mirai ua-wget |
| http://45.150.195.235/tarm5 | f5da1dbae5783d577deae9325824e55b3f4a3e0c46d20b617927eaab2d43aac7 | Mirai | arm elf gafgyt mirai ua-wget |
| http://45.150.195.235/tarm6 | 4567314381f574bcee9d4fc608cdd94eee362ca77ba49027c4c4a912e3b731f1 | Mirai | arm elf gafgyt mirai ua-wget |
| http://45.150.195.235/tarm7 | 2454883c623ef51854d9f5d85e45050cc2330f826ddf34bcdf09d2f3f8f9c7db | Mirai | arm elf gafgyt mirai ua-wget |
Intelligence
File Origin
# of uploads :
1
# of downloads :
52
Origin country :
GBVendor Threat Intelligence
No detections
Detection(s):
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-06-30T06:33:00Z UTC
Last seen:
2026-07-27T03:33:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
Score:
100%
Verdict:
Malware
File Type:
SCRIPT
Threat name:
Win32.Trojan.Vigorf
Status:
Malicious
First seen:
2026-06-30 11:27:02 UTC
File Type:
Text (Shell)
AV detection:
12 of 38 (31.58%)
Threat level:
5/5
Detection(s):
Suspicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Web download
sh 96856b7814c5af4ee984aac9ded443fd7d6ebd8c2f2df7e47b0ae65b75639722
(this sample)
Delivery method
Distributed via web download
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.