MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f15f864bfd637a9577813fa24e7a77b64a7a098bad8f020f09f7dc067305dbd4. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: f15f864bfd637a9577813fa24e7a77b64a7a098bad8f020f09f7dc067305dbd4
SHA3-384 hash: 5783f00918d483bdcac408d632ec46ea13932641eb64afcc6c516355eb1099ecc169804af0590e43505291893e63e1ba
SHA1 hash: e128960519cfefb20864aa24d7ca26d216769a85
MD5 hash: cb3376b896ddb0cbde792d51682dec96
humanhash: batman-north-nitrogen-high
File name:f15f864bfd637a9577813fa24e7a77b64a7a098bad8f020f09f7dc067305dbd4.sh
Download: download sample
File size:18'072 bytes
First seen:2026-02-27 15:03:45 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 192:cCuA6p4hvZ5m5FG4j4HKNphvn/TONVLxo8vhM3xL+B:Mp4hvZ5m5FGGoKNphvn/TONVLxoE
TLSH T10E82AC3621F08B339B9055C4B3772BA54F769617456720B8F4FE2A259F5AB03B0EB720
Magika xml
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://185.225.74.161/ahn/an/an/a
http://38.6.178.140/easy.shn/an/an/a
http://38.6.178.140/easy_cloud.shn/an/an/a
http://194.156.102.210/bins/bins.shn/an/an/a
http://116.129.7.63:81/hiddenbin/dvr1.shn/an/an/a

Intelligence


File Origin
# of uploads :
1
# of downloads :
78
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Result
Gathering data
Threat name:
Script-Shell.Trojan.Heuristic
Status:
Malicious
First seen:
2026-02-27 15:08:26 UTC
File Type:
Text (HTML)
AV detection:
3 of 36 (8.33%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh f15f864bfd637a9577813fa24e7a77b64a7a098bad8f020f09f7dc067305dbd4

(this sample)

  
Delivery method
Distributed via web download

Comments