MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e2fe38070742fd54e7a073147e4ed1daeeb28c5c4d33f541b956ec395176a16a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: e2fe38070742fd54e7a073147e4ed1daeeb28c5c4d33f541b956ec395176a16a
SHA3-384 hash: 722de7ee4b9fe78bf1353de4efdd9f4f18e73dfa5532be9405bd3386c6c4f799c5662b6e2048dfa286a8247838be46c1
SHA1 hash: b308f9776f136a95a4957b0260a098ced62508bb
MD5 hash: 791541e4a6afbf30dba09f7e8f90eb44
humanhash: south-bulldog-fish-summer
File name:e2fe38070742fd54e7a073147e4ed1daeeb28c5c4d33f541b956ec395176a16a.sh
Download: download sample
File size:21'850 bytes
First seen:2026-04-21 23:13:35 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 192:c5u5K6L4hvZ5mN9oKNpivjFV3+gukIFzITh5oeyeVeO:PL4hvZ5mN9oKNpivjF9+gukIFzITAXGL
TLSH T180A27D7620F08A735A9015C4B37317A15FB2955745A320B8B4FE2B399F69B03B4FF621
Magika xml
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://196.190.65.223:81/hiddenbin/dvr1.shn/an/aelf ua-wget
http://194.69.203.32:81/hiddenbin/dvr1.shn/an/ageofenced opendir sh ua-wget USA
http://194.69.203.32:81/hiddenbin/raisecom.shn/an/ageofenced opendir sh ua-wget USA
http://196.189.96.138:81/hiddenbin/dvr1.shn/an/aua-wget
http://116.129.7.63:81/hiddenbin/dvr1.shn/an/aua-wget
http://hxipzknrsojnitzv.zip/bins/bins.sh652285d260515c08cfe146ebdd2f5a4977ec490a608c57007abcb5b6f4fd4975 Miraibotnetdomain mirai opendir sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
44
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive
Status:
terminated
Behavior Graph:
%3 guuid=df366bb7-1900-0000-8ba7-48e1d10e0000 pid=3793 /usr/bin/sudo guuid=fbadddb9-1900-0000-8ba7-48e1e00e0000 pid=3808 /tmp/sample.bin guuid=df366bb7-1900-0000-8ba7-48e1d10e0000 pid=3793->guuid=fbadddb9-1900-0000-8ba7-48e1e00e0000 pid=3808 execve
Threat name:
Win32.Trojan.Ravartar
Status:
Malicious
First seen:
2026-04-21 23:14:23 UTC
File Type:
Text (HTML)
AV detection:
10 of 38 (26.32%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh e2fe38070742fd54e7a073147e4ed1daeeb28c5c4d33f541b956ec395176a16a

(this sample)

faf13e715e1d5c7401a341fab9efca5c1754b22a7bcc8f8405ab8e56dec91190

  
Delivery method
Distributed via web download
  
Dropping
MD5 bf9c16fbb53cb2e70df36493dea6180d
  
Dropping
SHA256 faf13e715e1d5c7401a341fab9efca5c1754b22a7bcc8f8405ab8e56dec91190

Comments