MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 efde52b4e7854277a4511c3ae348aa80a602a2814e18452da3e46c1b12171dfb. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: efde52b4e7854277a4511c3ae348aa80a602a2814e18452da3e46c1b12171dfb
SHA3-384 hash: b0750194de0d02a0dc4616787263e0b5f63b2c2a16b376a01be10d5085ae1c7534121d17d5fa770e735766afd4aaba6a
SHA1 hash: 3a37546e77ab7e049085d2e0166e18cb2792a637
MD5 hash: d5de70d82c329b1467a9b463a9286c40
humanhash: magnesium-gee-river-stairway
File name:l
Download: download sample
File size:609 bytes
First seen:2026-03-02 08:39:10 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 12:8q0HsOt1VvhsYf2+AIfQgc/jveZEMTT3WykYV0VyVIVs6X:8RHsOt1xh1f2+AKQgcLveZ/T3/JmYCSa
TLSH T100F0DDD0A7517C186730DD0ED2C4764602340BF1B95CBD3E9AE09AD60FB99C33187794
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://ext-checkdin.vercel.app/api/tokenln/an/an/a

Intelligence


File Origin
# of uploads :
1
# of downloads :
70
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
base64 bash lolbin obfuscated
Result
Gathering data
Status:
terminated
Behavior Graph:
%3 guuid=45b53634-1700-0000-66ef-614fb60a0000 pid=2742 /usr/bin/sudo guuid=22cfe935-1700-0000-66ef-614fbc0a0000 pid=2748 /tmp/sample.bin guuid=45b53634-1700-0000-66ef-614fb60a0000 pid=2742->guuid=22cfe935-1700-0000-66ef-614fbc0a0000 pid=2748 execve guuid=5f371e36-1700-0000-66ef-614fbd0a0000 pid=2749 /usr/bin/clear guuid=22cfe935-1700-0000-66ef-614fbc0a0000 pid=2748->guuid=5f371e36-1700-0000-66ef-614fbd0a0000 pid=2749 execve
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh efde52b4e7854277a4511c3ae348aa80a602a2814e18452da3e46c1b12171dfb

(this sample)

  
Delivery method
Distributed via web download

Comments