MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a8d227e608ceb4d8460e57da5c3e775f2e4170e60ee379c03f94efd648f78507. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: a8d227e608ceb4d8460e57da5c3e775f2e4170e60ee379c03f94efd648f78507
SHA3-384 hash: a3922e211afd3839ecd1923f9a6dff24e559910a4c9af766d9433d1e08f766b87d160f157b158817408a8828705ec3c0
SHA1 hash: a3a37b573286f1de0d1cbad5bc1b47fc8c38f0e1
MD5 hash: f5651fe760ece4de960a15dac2ec8cbc
humanhash: bakerloo-mobile-pasta-pip
File name:curl.sh
Download: download sample
File size:972 bytes
First seen:2025-06-05 09:58:28 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 24:3J3vzvTUxNIIVdKSfWIozIMTl9xWIo97/TEKcI/t/nz6g:tzvTUlVdxfWIozIMx9oIo9jTEKcI/t/B
TLSH T1C0111CCC47E5D2063D99DE1D70E98E0C9631A2D771B19BA6ED2808A3949B1183C3A7AD
Magika txt
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://31.171.131.21/armn/an/an/a
http://31.171.131.21/arm5n/an/an/a
http://31.171.131.21/arm6n/an/an/a
http://31.171.131.21/arm7n/an/an/a
http://31.171.131.21/m68kn/an/an/a
http://31.171.131.21/mipsn/an/an/a
http://31.171.131.21/mpsln/an/an/a
http://31.171.131.21/ppcn/an/an/a
http://31.171.131.21/sh4n/an/an/a
http://31.171.131.21/spcn/an/an/a
http://31.171.131.21/x86n/an/an/a
http://31.171.131.21/x86_64n/an/an/a

Intelligence


File Origin
# of uploads :
1
# of downloads :
64
Origin country :
DE DE
Vendor Threat Intelligence
Threat name:
Linux.Trojan.Generic
Status:
Suspicious
First seen:
2025-06-05 09:25:46 UTC
File Type:
Text (Shell)
AV detection:
14 of 24 (58.33%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh a8d227e608ceb4d8460e57da5c3e775f2e4170e60ee379c03f94efd648f78507

(this sample)

  
Delivery method
Distributed via web download

Comments