MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 fa6a261a4736de0bcd9b28ca81e8217fdaf9a7e5ffc5dd9ca1ca3469fc7ab71f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: fa6a261a4736de0bcd9b28ca81e8217fdaf9a7e5ffc5dd9ca1ca3469fc7ab71f
SHA3-384 hash: 99fb3274cd7ff40ed30f4dca427356fa7a30f69432b60bd1dbc4c678c0669e47a3aa624749eb147b723e4ed9ef93819c
SHA1 hash: 60a9efdca7e7e560e776b090e54fb5c35dbc786b
MD5 hash: 83d3a69f3e20f17d5b9403f1e29eb67e
humanhash: arizona-march-bravo-blue
File name:fa6a261a4736de0bcd9b28ca81e8217fdaf9a7e5ffc5dd9ca1ca3469fc7ab71f.sh
Download: download sample
File size:808 bytes
First seen:2026-02-22 13:19:34 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 24:cniRHRURCxO0tbmN2M1sLobHxlc9HHveN:cniRxuGRys01lwn+
TLSH T182019C7026F159332A901540B3732B1D7F31D84B809311DCB1EE9A314F87B82A1BF001
Magika xml
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://31.57.112.130/a7le0n/an/an/a

Intelligence


File Origin
# of uploads :
1
# of downloads :
21
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Status:
terminated
Behavior Graph:
%3 guuid=838a2698-1900-0000-6627-5e66de080000 pid=2270 /usr/bin/sudo guuid=b63a309a-1900-0000-6627-5e66e4080000 pid=2276 /tmp/sample.bin guuid=838a2698-1900-0000-6627-5e66de080000 pid=2270->guuid=b63a309a-1900-0000-6627-5e66e4080000 pid=2276 execve
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh fa6a261a4736de0bcd9b28ca81e8217fdaf9a7e5ffc5dd9ca1ca3469fc7ab71f

(this sample)

  
Delivery method
Distributed via web download

Comments