MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b7f12308abca0d7e33829495666ce9d0c1f892596a0fb33b184a831e4c20b497. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: b7f12308abca0d7e33829495666ce9d0c1f892596a0fb33b184a831e4c20b497
SHA3-384 hash: e4cdec5716bf5abf3c06c46e7601e6756fe91c57c18156732dc5582bd15be966664ae8d28ac4d28fb2cb267d51c991d2
SHA1 hash: abf268b21adb8be9b3f3c211e2396f19d4186df8
MD5 hash: 1c82ce2a713fb8646f0b4d24d2504beb
humanhash: magazine-march-carbon-magnesium
File name:phi.sh
Download: download sample
File size:580 bytes
First seen:2025-02-24 09:02:37 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 6:LwWgr17k2mw2ezgwWgr1RjvwT+iwWgr1wHg0Mw1twWgr1+aLU+6w1tyLwWgr18Fq:Gj2eFkT+c7aLBHTyMNITt9FTW5J
TLSH T1E4F086AD0026EF03CC5C6E5635667177B232C5D8408F8AC5AFC4207C544C921A121E55
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://193.143.1.116/splmipsn/an/an/a
http://193.143.1.116/splmpsln/an/an/a
http://193.143.1.116/splarmn/an/an/a
http://193.143.1.116/splarm5n/an/an/a
http://193.143.1.116/splarm6n/an/an/a
http://193.143.1.116/splarm7n/an/an/a

Intelligence


File Origin
# of uploads :
1
# of downloads :
25
Origin country :
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive
Result
Verdict:
UNKNOWN
Threat name:
Linux.Trojan.Generic
Status:
Suspicious
First seen:
2025-02-24 09:03:12 UTC
File Type:
Text (Shell)
AV detection:
13 of 38 (34.21%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
discovery
Behaviour
Modifies registry class
Suspicious behavior: GetForegroundWindowSpam
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh b7f12308abca0d7e33829495666ce9d0c1f892596a0fb33b184a831e4c20b497

(this sample)

  
Delivery method
Distributed via web download

Comments