MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d4127b30b3ecc0707ec37128429e730d5a28c8a9cf90964c38682628c9cb1619. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: d4127b30b3ecc0707ec37128429e730d5a28c8a9cf90964c38682628c9cb1619
SHA3-384 hash: ffdd25bb1ade9ff8f62d264b47c6b49cd013a7ff3363905a2c3d178f3a08cf76ae54086283316dc439d98747963e84c5
SHA1 hash: ba7c3380610a2fd7b31df61ad97d2f686fb7d05e
MD5 hash: 67cd1e669c4197bd02cbb9faa020337f
humanhash: illinois-fish-music-georgia
File name:d4127b30b3ecc0707ec37128429e730d5a28c8a9cf90964c38682628c9cb1619.sh
Download: download sample
File size:12'545 bytes
First seen:2026-02-22 13:21:01 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 96:c5uUk0B6msht+O+v1fsn+h4+tIiKkC1ymysuKNpUj4waYvjOBQIB4IB/IBbIB97g:c5uDg6L4hvZ5mN9oKNpiv6iTAoo7OP
TLSH T12042663B21F08B3293C065C962771B614F72970B456714B8F4FE6A269F2DA0370EBB61
Magika xml
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://38.6.178.140/easy_pass.shn/an/an/a
http://38.6.178.140/easy_cloud.shn/an/an/a

Intelligence


File Origin
# of uploads :
1
# of downloads :
37
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
busybox evasive
Result
Gathering data
Status:
terminated
Behavior Graph:
%3 guuid=ff4bf5c8-1900-0000-e3e1-ed4454070000 pid=1876 /usr/bin/sudo guuid=048617cb-1900-0000-e3e1-ed445a070000 pid=1882 /tmp/sample.bin guuid=ff4bf5c8-1900-0000-e3e1-ed4454070000 pid=1876->guuid=048617cb-1900-0000-e3e1-ed445a070000 pid=1882 execve
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh d4127b30b3ecc0707ec37128429e730d5a28c8a9cf90964c38682628c9cb1619

(this sample)

  
Delivery method
Distributed via web download

Comments