MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d5558cd419c8d46bdc958064cb97f963d1ea793866414c025906ec15033512ed. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 1


Intelligence 1 IOCs YARA File information Comments

SHA256 hash: d5558cd419c8d46bdc958064cb97f963d1ea793866414c025906ec15033512ed
SHA3-384 hash: 94a1445e380f0c55bd589189aad17d1237b4a5f6fa93d81b00df70117b55db602b7f6950fc63bdcd0ded7622da6d20b9
SHA1 hash: 78fb38f212fa49029aff24c669a39648d9b4e68b
MD5 hash: 3be7b8b182ccd96e48989b4e57311193
humanhash: queen-johnny-beer-kansas
File name:d5558cd419c8d46bdc958064cb97f963d1ea793866414c025906ec15033512ed.bin
Download: download sample
File size:14 bytes
First seen:2026-07-18 19:27:41 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 3:eRbn:eRbn
TLSH TNULL
Magika txt
Reporter whack
Tags:sh whack.sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
53
Origin country :
US US
Vendor Threat Intelligence
No detections
Verdict:
Unknown
Threat level:
  2.5/10
Confidence:
100%
Tags:
masquerade
Verdict:
Clean
File Type:
text
First seen:
2013-09-27T04:15:00Z UTC
Last seen:
2026-07-20T16:33:00Z UTC
Hits:
~10000
Status:
terminated
Behavior Graph:
%3 guuid=5943bc01-1800-0000-5813-5e68480c0000 pid=3144 /usr/bin/sudo guuid=95ce0204-1800-0000-5813-5e684c0c0000 pid=3148 /tmp/sample.bin guuid=5943bc01-1800-0000-5813-5e68480c0000 pid=3144->guuid=95ce0204-1800-0000-5813-5e684c0c0000 pid=3148 execve
Gathering data
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh d5558cd419c8d46bdc958064cb97f963d1ea793866414c025906ec15033512ed

(this sample)

  
Delivery method
Distributed via web download

Comments