MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 dd8f2a253ce3aa8a0d8cecc1914749b96039a26573914f202db35f14e0bdd09e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: dd8f2a253ce3aa8a0d8cecc1914749b96039a26573914f202db35f14e0bdd09e
SHA3-384 hash: 43b8101b91665118f2af033b21d6d2695924cd7ad45160d129bc90a0a546287e2832c390af7b02ed7e9adba969941278
SHA1 hash: 9bc7ba720ed714c0c9306307a143b4167e202ca7
MD5 hash: 406c3678af22f77de5513522c2758a44
humanhash: ohio-mike-beer-single
File name:x
Download: download sample
File size:92 bytes
First seen:2025-02-10 16:41:29 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 3:GRFiLdgoK3aGN3zSTASUKoSaXcX+v1FA:SoRaqA5FXmGA
TLSH T152B0125803433C07443DCC3972710F892041B3CD904777806845442ED4885983834244
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://94.156.167.35/zerarm7n/an/an/a

Intelligence


File Origin
# of uploads :
1
# of downloads :
66
Origin country :
DE DE
Vendor Threat Intelligence
Result
Verdict:
UNKNOWN
Result
Malware family:
n/a
Score:
  3/10
Tags:
discovery
Behaviour
Modifies registry class
Suspicious behavior: GetForegroundWindowSpam
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh dd8f2a253ce3aa8a0d8cecc1914749b96039a26573914f202db35f14e0bdd09e

(this sample)

  
Delivery method
Distributed via web download

Comments