🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ddb85c701a7730bfce9fc63ba1e1c92c06a5bcdc13d0e9c7ee62c6b90899c87f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Ngioweb


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: ddb85c701a7730bfce9fc63ba1e1c92c06a5bcdc13d0e9c7ee62c6b90899c87f
SHA3-384 hash: c17b3412fef21fbbfbb0b7b1c9d504e3cb9b955f8021a705f358078d7c29c05d74263e9eac139758b1ed7dc0eaa4e3b4
SHA1 hash: 7fd21d93658797957136e2fa439acdfb738b8901
MD5 hash: 85a6bdea03b4c31f5cef10fbf12fb35a
humanhash: papa-arkansas-cup-stream
File name:ddb85c701a7730bfce9fc63ba1e1c92c06a5bcdc13d0e9c7ee62c6b90899c87f.sh
Download: download sample
Signature Ngioweb
File size:11'013 bytes
First seen:2026-09-17 17:17:35 UTC
Last seen:2026-09-18 16:59:05 UTC
File type: sh
MIME type:text/plain
ssdeep 192:cCuZ56p4hvZ5mrFoKNpivbUVazXlITPVP:q0p4hvZ5mrFoKNpivYMXlITPJ
TLSH T19C32763B11F08B32D3C460D952A65A610EB2AB0B452614F5F4FE972AAF2C90335E7F71
Magika xml
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://193.243.147.115/avTECHbfb53568a2c7b74606886f9b1a535fe582a41c5d73149302e1c8331ea76c323f NgiowebNgioweb ua-wget
http://130.12.180.20:36695/cat.sh40bec1ee86a5ba5ed620bbe546b09d072481d71356ba2025974c08a0e3f3fb0c Miraigeofenced mirai sh ua-wget USA
http://194.69.203.32:81/hiddenbin/dvr1.shn/an/ageofenced opendir sh ua-wget USA

Intelligence


File Origin
# of uploads :
2
# of downloads :
61
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive
Status:
terminated
Behavior Graph:
%3 guuid=e5ff603a-1f00-0000-e005-655d73090000 pid=2419 /usr/bin/sudo guuid=6fd8183d-1f00-0000-e005-655d79090000 pid=2425 /tmp/sample.bin guuid=e5ff603a-1f00-0000-e005-655d73090000 pid=2419->guuid=6fd8183d-1f00-0000-e005-655d79090000 pid=2425 execve
Threat name:
Script-BAT.Trojan.Heuristic
Status:
Malicious
First seen:
2026-09-17 17:18:13 UTC
File Type:
Text (HTML)
AV detection:
4 of 36 (11.11%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
execution
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Executes a command shell one-liner
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Ngioweb

sh ddb85c701a7730bfce9fc63ba1e1c92c06a5bcdc13d0e9c7ee62c6b90899c87f

(this sample)

  
Delivery method
Distributed via web download

Comments