MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 bd03aa955617ad86e37e649e1d4c466a5666cb0cd08ea58d2aaf072ffa9ff3cf. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: bd03aa955617ad86e37e649e1d4c466a5666cb0cd08ea58d2aaf072ffa9ff3cf
SHA3-384 hash: b7b6c181ad8777cd6d1b9e23bfdcb73de202aa647b9f369178ba2dd388edf2fcc02d0abc1dd0a7df221b80921a21367b
SHA1 hash: c8cc7f5698db48bb57c3514032e43c040ed40f38
MD5 hash: d397a11c3c8f8543bc016295bcc648d2
humanhash: venus-bravo-maine-white
File name:bd03aa955617ad86e37e649e1d4c466a5666cb0cd08ea58d2aaf072ffa9ff3cf.sh
Download: download sample
File size:7'543 bytes
First seen:2026-02-22 13:19:53 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 96:cRuJY8kQX+YT++GkV4jJwIBvIBXIBiIBRIBsIyX:cRuYOdmGUIta3b
TLSH T1D0F109B425F14D332E20AA80F33727B6ABB7D45349E3218C35DE1D25AF96B12B4BE415
Magika xml
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://38.6.178.140/easy_pass.shn/an/an/a
http://38.6.178.140/easy_cloud.shn/an/an/a

Intelligence


File Origin
# of uploads :
1
# of downloads :
41
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
busybox evasive
Status:
terminated
Behavior Graph:
%3 guuid=72bcc653-1900-0000-9440-a1f3ab0a0000 pid=2731 /usr/bin/sudo guuid=31f5d055-1900-0000-9440-a1f3af0a0000 pid=2735 /tmp/sample.bin guuid=72bcc653-1900-0000-9440-a1f3ab0a0000 pid=2731->guuid=31f5d055-1900-0000-9440-a1f3af0a0000 pid=2735 execve
Threat name:
Linux.Trojan.Generic
Status:
Suspicious
First seen:
2026-02-22 13:27:20 UTC
File Type:
Text (Shell)
AV detection:
4 of 24 (16.67%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh bd03aa955617ad86e37e649e1d4c466a5666cb0cd08ea58d2aaf072ffa9ff3cf

(this sample)

  
Delivery method
Distributed via web download

Comments