MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f105f24cb9b6c7b6e0195bbe162d4b469795343a4c8c7b38374601ccbc898143. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: f105f24cb9b6c7b6e0195bbe162d4b469795343a4c8c7b38374601ccbc898143
SHA3-384 hash: 4bb7341e18a222bbf0b405fc9c1f023c2921ca5972fb2c9fa0cea82392bbccf4cdf21a0f7bb0ff7f594ba2c873d733bb
SHA1 hash: 8995d980b3c1b3649f460d0d05cf806da06e8461
MD5 hash: 0035e6f62985cd33560daa835ee4d63e
humanhash: don-colorado-mobile-football
File name:zxc.sh
Download: download sample
File size:636 bytes
First seen:2024-11-22 15:51:52 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 6:LCerXV234YnOVCerXojbuYnOVCerbzHgAOjXtLnOVCerb9aLU+kt2nOVCerbhFGf:s3xnDXuYnJBnMaLBm2nVNITRYnGTWnN
TLSH T1EAF019AA026BAF06D41CEE2B7575B8FBF071D389044B8784BEC851FD908C9567224D93
Magika shell
Reporter abuse_ch
Tags:sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
64
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive
Threat name:
Linux.Trojan.Generic
Status:
Suspicious
First seen:
2024-11-22 15:52:07 UTC
File Type:
Text (Shell)
AV detection:
18 of 38 (47.37%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
discovery
Behaviour
Modifies registry class
Suspicious behavior: GetForegroundWindowSpam
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh f105f24cb9b6c7b6e0195bbe162d4b469795343a4c8c7b38374601ccbc898143

(this sample)

  
Delivery method
Distributed via web download

Comments