MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 dd03c2bc55c3d4fc739f3584634772d71a0465d1b0f85a22022cab2da643db34. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: dd03c2bc55c3d4fc739f3584634772d71a0465d1b0f85a22022cab2da643db34
SHA3-384 hash: 3e85aa3a08a4b6cb726d804fe537536ea94daba3479ea57a4ed9d17d89f52d03485124f13776d447d1bc2182d98b0f84
SHA1 hash: 9bdbd977c11674a4be24a4881624a64f27e1dbfa
MD5 hash: 3d3d2466a6d5f6c57820ca1ae502d202
humanhash: california-tennis-nevada-ohio
File name:dd03c2bc55c3d4fc739f3584634772d71a0465d1b0f85a22022cab2da643db34.sh
Download: download sample
File size:12'703 bytes
First seen:2026-02-22 13:19:13 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 192:cCul4hvZ5m5FG4j4HKNpivINuVskuX97IhBWiE:a4hvZ5m5FGGoKNpivINuWkuX97IhBWiE
TLSH T1CE42683B21F08B32E7C051C9A3661A614F72A70B456714B8F4FE5B269F2DA0370E7B65
Magika xml
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://38.6.178.140/easy_pass.shn/an/an/a
http://38.6.178.140/easy_cloud.shn/an/an/a
http://38.6.178.140/easy_lan.shn/an/an/a
http://23.224.176.63/sh/easy_av_wget.shn/an/an/a

Intelligence


File Origin
# of uploads :
1
# of downloads :
5
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive soft-404
Result
Gathering data
Status:
terminated
Behavior Graph:
%3 guuid=fc3a3360-1a00-0000-47c3-6c1cdf0a0000 pid=2783 /usr/bin/sudo guuid=b5ee5662-1a00-0000-47c3-6c1ce30a0000 pid=2787 /tmp/sample.bin guuid=fc3a3360-1a00-0000-47c3-6c1cdf0a0000 pid=2783->guuid=b5ee5662-1a00-0000-47c3-6c1ce30a0000 pid=2787 execve
Gathering data
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh dd03c2bc55c3d4fc739f3584634772d71a0465d1b0f85a22022cab2da643db34

(this sample)

1fdfc6e3ae612b736236df4579ff7a10954d47d9e7be67e6ebe8da173b0671c8

  
Delivery method
Distributed via web download
  
Dropping
MD5 bc422233b2512d7d5eb5500daf8a7822
  
Dropping
SHA256 1fdfc6e3ae612b736236df4579ff7a10954d47d9e7be67e6ebe8da173b0671c8

Comments