MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 fd5be47fb03156253897fdc1b78ae6ecfc20bc09afd35360ad5981358e86f259. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: fd5be47fb03156253897fdc1b78ae6ecfc20bc09afd35360ad5981358e86f259
SHA3-384 hash: 853ba52fd06a64b75d3c1ee697d39b585c4c5926611813265337fbf95dd38c8ca4b58f37bf3fede6f3ac6b5e5d1ef49f
SHA1 hash: 11f641f14494dd940352aa8b7da152b0a73fb02e
MD5 hash: 6207a270b58360f83605ca277159e4e4
humanhash: south-one-chicken-twenty
File name:fd5be47fb03156253897fdc1b78ae6ecfc20bc09afd35360ad5981358e86f259.sh
Download: download sample
File size:10'706 bytes
First seen:2026-02-22 13:19:22 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 96:cCuUk0B6csht+O+v1fsn+h4+tIiKqC1yOysuKNpUj4waYvj/5kn7IB0IBNpb:cCuDg6p4hvZ5mrFoKNpivk7vy
TLSH T11B22673B21F08B32D3C461C952661B614EB2A70B492614B5F4FE673AAF2C90371E7B65
Magika xml
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://38.6.178.140/easy_pass.shn/an/an/a
http://38.6.178.140/easy_cloud.shn/an/an/a
http://196.189.96.138:81/hiddenbin/dvr1.shn/an/an/a

Intelligence


File Origin
# of uploads :
1
# of downloads :
7
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive
Result
Gathering data
Status:
terminated
Behavior Graph:
%3 guuid=39bc6cc4-1900-0000-92bb-aecef1090000 pid=2545 /usr/bin/sudo guuid=0b8ac0c7-1900-0000-92bb-aecef7090000 pid=2551 /tmp/sample.bin guuid=39bc6cc4-1900-0000-92bb-aecef1090000 pid=2545->guuid=0b8ac0c7-1900-0000-92bb-aecef7090000 pid=2551 execve
Gathering data
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh fd5be47fb03156253897fdc1b78ae6ecfc20bc09afd35360ad5981358e86f259

(this sample)

  
Delivery method
Distributed via web download

Comments