MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d8594a58ab4ba0b54ad430223cec193789627d70523d2508c19c68c294cd55ec. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: d8594a58ab4ba0b54ad430223cec193789627d70523d2508c19c68c294cd55ec
SHA3-384 hash: 9b8152d1bfc7393808596dc3ba13c34d0b0231b2fccad06f5d7866abb3ae0e1a91cad27016a7745920624425662d68ca
SHA1 hash: 6cc52bae22faff8c79529dae5f82a11bfc85075e
MD5 hash: f4f0107f1570b84e1d42784a29b5171a
humanhash: iowa-king-one-blossom
File name:ah
Download: download sample
File size:382 bytes
First seen:2025-03-11 08:46:40 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 6:/VJ+pcjVYkLCbEJ3FMjQfZVKMTyesFrFBEGVKMTfuRVs+y4uVj7NiVVNDYJF8QRh:/VJ+IG8gZesFrFBEGgbu+yfuT+JF8EBf
TLSH T13BE0DF5DD64987BBB053CCDF3FA8BCCC620E90984E8F0F18A6391D6BA894C5834C0421
Magika shell
Reporter abuse_ch
Tags:sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
77
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
Score:
99.9%
Tags:
mirai agent virus shell
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Result
Verdict:
MALICIOUS
Threat name:
Script-Shell.Trojan.Multiverze
Status:
Malicious
First seen:
2025-03-11 09:24:24 UTC
File Type:
Text (Shell)
AV detection:
14 of 24 (58.33%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
discovery
Behaviour
Modifies registry class
Suspicious behavior: GetForegroundWindowSpam
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh d8594a58ab4ba0b54ad430223cec193789627d70523d2508c19c68c294cd55ec

(this sample)

  
Delivery method
Distributed via web download

Comments