MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a8843fe541de9e18997b79d6c65f446d66f1081ee2793963b99893649d733d6c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: a8843fe541de9e18997b79d6c65f446d66f1081ee2793963b99893649d733d6c
SHA3-384 hash: 179934510106a79ea0888af6eb1e2e4d928e339b8d63785ddc525d17e0eb03db3f73fccc38aef42b405d5dc8d29d1d6a
SHA1 hash: 2cbf85e479c5ee68ef87ec0ce037dac28b03d8c3
MD5 hash: 3f325f9e5bb62a059d4cf5b118e99083
humanhash: violet-yellow-equal-jersey
File name:rob
Download: download sample
File size:498 bytes
First seen:2025-12-21 15:13:39 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 12:/5949dJ37nBhBUFKoIOqZWgZesFrFBEGgbu+yfuT+JF8EquhHdiA:ha9X7WIO1WrTBEGjTuyLqg9j
TLSH T192F0E92FD10E8BBB6816A5592F693DFCA61E41585E8A0F54ADB90D0A74C8DB861C0075
Magika shell
Reporter abuse_ch
Tags:sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
30
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Verdict:
Malicious
File Type:
ps1
First seen:
2025-12-21T12:32:00Z UTC
Last seen:
2025-12-23T12:48:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=efd8334e-1800-0000-5c79-7e358e0f0000 pid=3982 /usr/bin/sudo guuid=7f18f64f-1800-0000-5c79-7e35970f0000 pid=3991 /tmp/sample.bin guuid=efd8334e-1800-0000-5c79-7e358e0f0000 pid=3982->guuid=7f18f64f-1800-0000-5c79-7e35970f0000 pid=3991 execve guuid=481b4250-1800-0000-5c79-7e35990f0000 pid=3993 /usr/bin/killall guuid=7f18f64f-1800-0000-5c79-7e35970f0000 pid=3991->guuid=481b4250-1800-0000-5c79-7e35990f0000 pid=3993 execve guuid=07117a51-1800-0000-5c79-7e359e0f0000 pid=3998 /usr/bin/killall guuid=7f18f64f-1800-0000-5c79-7e35970f0000 pid=3991->guuid=07117a51-1800-0000-5c79-7e359e0f0000 pid=3998 execve
Threat name:
Linux.Downloader.MiraiB
Status:
Malicious
First seen:
2025-12-21 15:31:27 UTC
File Type:
Text (Shell)
AV detection:
13 of 36 (36.11%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh a8843fe541de9e18997b79d6c65f446d66f1081ee2793963b99893649d733d6c

(this sample)

  
Delivery method
Distributed via web download

Comments