MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 fb135ab48d8d8568e3983afbfc70ba4651f77d4e5af89e09e6fb62157bb43eaf. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: fb135ab48d8d8568e3983afbfc70ba4651f77d4e5af89e09e6fb62157bb43eaf
SHA3-384 hash: 446ebd7e3b7472c77876b89f8d2bae526db55fcf2a3c6328f4e89ffcba37d875fed186832c0e11c0ce8b600e0ace5092
SHA1 hash: 30f9dc79b93d60303c388cbdef2c83a287647f7a
MD5 hash: 1e18b8803dfd73c3bdaeb864cac518cd
humanhash: venus-skylark-nuts-don
File name:update.sh
Download: download sample
File size:18'993 bytes
First seen:2026-07-21 05:15:18 UTC
Last seen:2026-07-21 20:55:29 UTC
File type: sh
MIME type:text/plain
ssdeep 192:8OYYUVG+nlI31Bv/03msROeczEKskxjp0Ai4DrQCLKDTyo:nUbIbv/2pROeczekFB3QCL2
TLSH T1088285BD9F60F9D45A19162B38E20D447610C077A2AC16BFF9CFB2260F5E5382E9D816
Magika powershell
Reporter abuse_ch
Tags:sh

Intelligence


File Origin
# of uploads :
4
# of downloads :
69
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
base64 obfuscated stealer
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-07-21T03:58:00Z UTC
Last seen:
2026-07-21T08:36:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=e55840b9-1800-0000-6440-9ade160c0000 pid=3094 /usr/bin/sudo guuid=10a034bb-1800-0000-6440-9ade1d0c0000 pid=3101 /tmp/sample.bin guuid=e55840b9-1800-0000-6440-9ade160c0000 pid=3094->guuid=10a034bb-1800-0000-6440-9ade1d0c0000 pid=3101 execve guuid=884070bb-1800-0000-6440-9ade1e0c0000 pid=3102 /usr/bin/dash guuid=10a034bb-1800-0000-6440-9ade1d0c0000 pid=3101->guuid=884070bb-1800-0000-6440-9ade1e0c0000 pid=3102 clone guuid=941e7dbb-1800-0000-6440-9ade1f0c0000 pid=3103 /usr/bin/dash guuid=884070bb-1800-0000-6440-9ade1e0c0000 pid=3102->guuid=941e7dbb-1800-0000-6440-9ade1f0c0000 pid=3103 clone guuid=7a1f83bb-1800-0000-6440-9ade200c0000 pid=3104 /usr/bin/base64 guuid=884070bb-1800-0000-6440-9ade1e0c0000 pid=3102->guuid=7a1f83bb-1800-0000-6440-9ade200c0000 pid=3104 execve
Threat name:
MacOS.Infostealer.Generic
Status:
Suspicious
First seen:
2026-07-18 15:16:48 UTC
File Type:
Text
AV detection:
6 of 36 (16.67%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
execution
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Executes a command shell one-liner
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh fb135ab48d8d8568e3983afbfc70ba4651f77d4e5af89e09e6fb62157bb43eaf

(this sample)

  
Delivery method
Distributed via web download

Comments