MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 fb135ab48d8d8568e3983afbfc70ba4651f77d4e5af89e09e6fb62157bb43eaf. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Threat unknown
Vendor detections: 6
| SHA256 hash: | fb135ab48d8d8568e3983afbfc70ba4651f77d4e5af89e09e6fb62157bb43eaf |
|---|---|
| SHA3-384 hash: | 446ebd7e3b7472c77876b89f8d2bae526db55fcf2a3c6328f4e89ffcba37d875fed186832c0e11c0ce8b600e0ace5092 |
| SHA1 hash: | 30f9dc79b93d60303c388cbdef2c83a287647f7a |
| MD5 hash: | 1e18b8803dfd73c3bdaeb864cac518cd |
| humanhash: | venus-skylark-nuts-don |
| File name: | update.sh |
| Download: | download sample |
| File size: | 18'993 bytes |
| First seen: | 2026-07-21 05:15:18 UTC |
| Last seen: | 2026-07-21 20:55:29 UTC |
| File type: | sh |
| MIME type: | text/plain |
| ssdeep | 192:8OYYUVG+nlI31Bv/03msROeczEKskxjp0Ai4DrQCLKDTyo:nUbIbv/2pROeczekFB3QCL2 |
| TLSH | T1088285BD9F60F9D45A19162B38E20D447610C077A2AC16BFF9CFB2260F5E5382E9D816 |
| Magika | powershell |
| Reporter | |
| Tags: | sh |
Intelligence
File Origin
# of uploads :
4
# of downloads :
69
Origin country :
DEVendor Threat Intelligence
No detections
Detection(s):
Verdict:
Likely Malicious
Threat level:
7.5/10
Confidence:
100%
Tags:
base64 obfuscated stealer
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-07-21T03:58:00Z UTC
Last seen:
2026-07-21T08:36:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
Score:
61%
Verdict:
Susipicious
File Type:
SCRIPT
Threat name:
MacOS.Infostealer.Generic
Status:
Suspicious
First seen:
2026-07-18 15:16:48 UTC
File Type:
Text
AV detection:
6 of 36 (16.67%)
Threat level:
5/5
Detection(s):
Suspicious file
Result
Malware family:
n/a
Score:
3/10
Tags:
execution
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Executes a command shell one-liner
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Legit
Score:
0.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Web download
sh fb135ab48d8d8568e3983afbfc70ba4651f77d4e5af89e09e6fb62157bb43eaf
(this sample)
Delivery method
Distributed via web download
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.