MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a30ff63dc4951d23a690906117e0ce4516d3710ca68cd4c1cc1b2f69bfbf36b2. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: a30ff63dc4951d23a690906117e0ce4516d3710ca68cd4c1cc1b2f69bfbf36b2
SHA3-384 hash: f9691cad27928170ef5459cb3130c18333b6357ae840db07aa89377a501386856fafae4711d4e51d76c9b26775b55bbf
SHA1 hash: d172a779d4968fd49b999100517fc71cd0746f9f
MD5 hash: 89cb6a45b90fe7290eeea13b6495d5c6
humanhash: arizona-robin-may-beryllium
File name:a30ff63dc4951d23a690906117e0ce4516d3710ca68cd4c1cc1b2f69bfbf36b2.sh
Download: download sample
File size:2'131 bytes
First seen:2022-06-01 06:44:26 UTC
Last seen:2022-07-16 05:06:29 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 48:vnqc9Wap6BxCQByvJBjAOBgRzC6DSLmY/QA:vnqc9WG6rGTgC6DSLmY/QA
TLSH T1A1414CE8029125F56EB5D9A6726EC414B8C0D1A798F82B0475C939FD82ACF5E30A1ED3
Reporter nyyuzyou
Tags:sh

Intelligence


File Origin
# of uploads :
2
# of downloads :
201
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
MALICIOUS
Threat name:
Script-Shell.Trojan.Vigorf
Status:
Malicious
First seen:
2022-05-25 12:41:10 UTC
AV detection:
14 of 26 (53.85%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  9/10
Tags:
discovery linux
Behaviour
Reads runtime system information
Reads system network configuration
Enumerates active TCP sockets
Contacts a large (126200) amount of remote hosts
Contacts a large (139936) amount of remote hosts
Contacts a large (323266) amount of remote hosts
Contacts a large (345288) amount of remote hosts
Creates a large amount of network flows
Modifies the Watchdog daemon
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

  
Delivery method
Other

Comments