MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ef00e6c907776b9bfc1a73a1faa71228c0a3927376dab088b801d1654377d812. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: ef00e6c907776b9bfc1a73a1faa71228c0a3927376dab088b801d1654377d812
SHA3-384 hash: 17388455bb00b51e88368800da727d655bc6b4f4948de90326ca8e69e95f346f3755eee3f9fac84b585dc5fc3c83ef01
SHA1 hash: a479a98f510f42f9694ed2681744c1abb0962b79
MD5 hash: 2af21d0758ad4a7b0ec2138e65a2c240
humanhash: equal-georgia-black-whiskey
File name:tftp.sh
Download: download sample
File size:485 bytes
First seen:2025-05-02 14:32:02 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 12:rrn9MzpnVVPhnt7yXVnh5akJhPnFLKHVnNe2:H9c/Rt7yXFfak3xKHFNl
TLSH T117F0BEB2A2204336C1003D0EA16AD5F1B8F362574E33CD6536B571FAEA38838BC60438
Magika shell
Reporter abuse_ch
Tags:sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
63
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
evasive
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh ef00e6c907776b9bfc1a73a1faa71228c0a3927376dab088b801d1654377d812

(this sample)

  
Delivery method
Distributed via web download

Comments