MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b8380e2cd7a2164e8efa0bac32eda97f8b81084e6ba90d44a59d357b9461b6af. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: b8380e2cd7a2164e8efa0bac32eda97f8b81084e6ba90d44a59d357b9461b6af
SHA3-384 hash: e4851e3b1fb62ccb84a1a3a25e11bf63eec7b0aee2c002d26618ad442d1aee305deb3df6fcc75a10ee56bae37c001c54
SHA1 hash: 16c8fb41d83103a60e135f83abc55d79ffc84dc3
MD5 hash: 6f8a79918c78280aec401778564e3345
humanhash: mobile-ten-sink-nevada
File name:create.py
Download: download sample
File size:5'203 bytes
First seen:2024-10-31 10:36:24 UTC
Last seen:2024-10-31 17:00:57 UTC
File type:
MIME type:text/plain
ssdeep 96:1u6dhu6U4DUOVpcv9p1YHQC5tgbp+EcrxstP:BkPp1YHQC5qbp+frxstP
TLSH T176B177BA7A220BB20D64DF0AF361C4A5B053E1DA44589F0A35BD70BCBABFD55913094B
Magika txt
Reporter abuse_ch
Tags:py

Intelligence


File Origin
# of uploads :
2
# of downloads :
84
Origin country :
DE DE
Vendor Threat Intelligence
Result
Verdict:
UNKNOWN
Threat name:
Script-Shell.Downloader.Heuristic
Status:
Malicious
First seen:
2024-10-31 10:37:04 UTC
File Type:
Text (Shell)
AV detection:
9 of 38 (23.68%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
discovery
Behaviour
Modifies registry class
Suspicious behavior: GetForegroundWindowSpam
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

b8380e2cd7a2164e8efa0bac32eda97f8b81084e6ba90d44a59d357b9461b6af

(this sample)

  
Delivery method
Distributed via web download

Comments