MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 bf949f7ca54f37801b5ebf190792f2b3b858f3f535dd41c2005e511cab9dc819. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: bf949f7ca54f37801b5ebf190792f2b3b858f3f535dd41c2005e511cab9dc819
SHA3-384 hash: 9fb0a49af671c4447ec18f297ca67ff5b46d3de77f7be5e61834a51bbb65f18b2b2bb2cf7a3f6ebddca4fecb13257b05
SHA1 hash: 57e4910a9ed6c8809165af3c6e41f91f3e22ea28
MD5 hash: 8f08465a40e7ebf507724fe055274fa3
humanhash: muppet-earth-mississippi-white
File name:bf949f7ca54f37801b5ebf190792f2b3b858f3f535dd41c2005e511cab9dc819.sh
Download: download sample
File size:10'441 bytes
First seen:2026-02-22 13:20:07 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 96:cCuisht+O+v1fsn+h4+tIiKqC1yOysuKNpUj4waYvj1XIZrCoP6fDpC:cCu34hvZ5mrFoKNpivJ2
TLSH T17622783B21F08B32D3C420C992A61A654E72A70F452614B5F4FE633AAF2D90371E7F65
Magika xml
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://185.225.74.161/ahn/an/an/a
http://194.69.203.32:81/hiddenbin/dvr1.shn/an/ageofenced opendir sh ua-wget USA

Intelligence


File Origin
# of uploads :
1
# of downloads :
32
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive
Result
Gathering data
Status:
terminated
Behavior Graph:
%3 guuid=b877f33d-1a00-0000-9207-d4efa80b0000 pid=2984 /usr/bin/sudo guuid=15b42040-1a00-0000-9207-d4efae0b0000 pid=2990 /tmp/sample.bin guuid=b877f33d-1a00-0000-9207-d4efa80b0000 pid=2984->guuid=15b42040-1a00-0000-9207-d4efae0b0000 pid=2990 execve
Gathering data
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh bf949f7ca54f37801b5ebf190792f2b3b858f3f535dd41c2005e511cab9dc819

(this sample)

faf13e715e1d5c7401a341fab9efca5c1754b22a7bcc8f8405ab8e56dec91190

  
Delivery method
Distributed via web download
  
Dropping
MD5 bf9c16fbb53cb2e70df36493dea6180d
  
Dropping
SHA256 faf13e715e1d5c7401a341fab9efca5c1754b22a7bcc8f8405ab8e56dec91190

Comments