MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c1f6f312624cb597d0101545cf5cf6874d83bb36ce89870335371a3990dfbf05. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: c1f6f312624cb597d0101545cf5cf6874d83bb36ce89870335371a3990dfbf05
SHA3-384 hash: 894e38dd7241b83585f5d04180235a6bb53dddac66f754a38764efdc1ca60e550928518767bee88f58dc240eea618507
SHA1 hash: 5ce01ba73eb895f541931a491e466b41bdb24c4c
MD5 hash: b13ef76e87963304c7a8af2d0ee5285c
humanhash: ten-king-magnesium-steak
File name:w.sh
Download: download sample
File size:175 bytes
First seen:2025-01-08 17:16:19 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 3:GRFjLXbFGlRdLiVaH3FDzDLXbFGlRdLiVaiXsUIVeVaWd8oFaG1OdmMWRE1nsF/l:Sjf2nH31Df2n0szJA8PsFd
TLSH T17DC012A6BB600ED0BF8B8AA03D13EB4244905D682DD5E23DD8C205C07878068B6A8A90
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://77.221.157.206/zhoung/temp.tarn/an/an/a

Intelligence


File Origin
# of uploads :
1
# of downloads :
87
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
expand lolbin
Result
Malware family:
n/a
Score:
  3/10
Tags:
discovery
Behaviour
Modifies registry class
Suspicious behavior: GetForegroundWindowSpam
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh c1f6f312624cb597d0101545cf5cf6874d83bb36ce89870335371a3990dfbf05

(this sample)

7fb302eda8f482f71adcef0adff11c4351f63e5c56b6cb3b9d7bf1ee7012b335

  
Delivery method
Distributed via web download
  
Dropping
MD5 ed1df6c755168971a11fd72828b508cf
  
Dropping
SHA256 7fb302eda8f482f71adcef0adff11c4351f63e5c56b6cb3b9d7bf1ee7012b335

Comments