🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 98de96dc2fbd79e23eb6e07676cb453eb9efb14d54fb908f382775fda97d4bb0. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 98de96dc2fbd79e23eb6e07676cb453eb9efb14d54fb908f382775fda97d4bb0
SHA3-384 hash: 5a2e0f41d65b3d64119c0372e8cd0d90418ed4fe12fd070edb661a774aa0d3606718489b32bd42776a50eb2af2d8aa7b
SHA1 hash: 2f88354f27a5e25441b6c39054bd79ccec7d0924
MD5 hash: 4964da70645c4d0c49b6756786606d6b
humanhash: angel-table-bravo-red
File name:98de96dc2fbd79e23eb6e07676cb453eb9efb14d54fb908f382775fda97d4bb0.sh
Download: download sample
File size:12'386 bytes
First seen:2026-09-17 03:49:33 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 96:cCu3k0B6n7sht+O+v1fsn+h4+tIicqbA/GsGCuKNppjrwaaIBRIB0IBT7IBbVzbu:cCu0g6nC4hvZ5mzjqKNp02LG7Uixm+T
TLSH T12F42357721F08B3297C055C8A2771B614F72970B456714B8F4BE5B2A9F2DA0370EBB61
Magika xml
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://38.6.178.140/easy_pass.shn/an/an/a
http://38.6.178.140/easy_cloud.shn/an/an/a
http://38.6.178.140/easy_lan.shn/an/an/a
http://193.243.147.115/avTECHn/an/an/a
http://109.205.213.2/download.shn/an/abash curl elf mirai Mozi sh wget
http://194.156.102.210/bins/bins.shn/an/aascii bash sh ua-wget
http://116.129.7.63:81/hiddenbin/dvr1.shn/an/aua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
61
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Status:
terminated
Behavior Graph:
%3 guuid=6157a525-1a00-0000-6830-315e850c0000 pid=3205 /usr/bin/sudo guuid=e018352a-1a00-0000-6830-315e860c0000 pid=3206 /tmp/sample.bin guuid=6157a525-1a00-0000-6830-315e850c0000 pid=3205->guuid=e018352a-1a00-0000-6830-315e860c0000 pid=3206 execve
Threat name:
Script-BAT.Trojan.Heuristic
Status:
Malicious
First seen:
2026-09-17 03:50:26 UTC
File Type:
Text (HTML)
AV detection:
5 of 36 (13.89%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
execution
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Executes a command shell one-liner
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 98de96dc2fbd79e23eb6e07676cb453eb9efb14d54fb908f382775fda97d4bb0

(this sample)

  
Delivery method
Distributed via web download

Comments