MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 feed9b5bfeca6aac7d6a6bfba370ffacd25c6293ba8053550bb57d3a9c3f3caf. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: feed9b5bfeca6aac7d6a6bfba370ffacd25c6293ba8053550bb57d3a9c3f3caf
SHA3-384 hash: 67bb2c8bdb7a853f9f2fe779dc01f0b257cacaaa437da064d83cb2c8f2ae3cbd5368f03fbf178572a306e8c53fc46968
SHA1 hash: b949e6ffe6dc74f83090b4471594b0975f809184
MD5 hash: ef53643a3ada2249b7787d9ebd36c7bf
humanhash: carolina-april-fifteen-sixteen
File name:feed9b5bfeca6aac7d6a6bfba370ffacd25c6293ba8053550bb57d3a9c3f3caf.sh
Download: download sample
File size:14'897 bytes
First seen:2026-02-22 13:18:24 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 96:cCuRsht+O+v1fsn+h4+tIiKVC1ymyty6yPyVuKNpUj4waYvjFhGn0VcByNRc81FV:cCuo4hvZ5mu9QFQBKNpivD6Y
TLSH T13362153B21F08B32E7D410C9A2671A614EB2A70B856614B9F4FE57359F1DA0371EBF60
Magika xml
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://38.6.178.140/easy_cloud.shn/an/an/a
http://156.96.155.238/sh/easy_av_wget.shn/an/amirai shell

Intelligence


File Origin
# of uploads :
1
# of downloads :
6
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive
Result
Gathering data
Status:
terminated
Behavior Graph:
%3 guuid=5417c246-1a00-0000-9c49-97e7f2090000 pid=2546 /usr/bin/sudo guuid=ab868049-1a00-0000-9c49-97e7f9090000 pid=2553 /tmp/sample.bin guuid=5417c246-1a00-0000-9c49-97e7f2090000 pid=2546->guuid=ab868049-1a00-0000-9c49-97e7f9090000 pid=2553 execve
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh feed9b5bfeca6aac7d6a6bfba370ffacd25c6293ba8053550bb57d3a9c3f3caf

(this sample)

48d1db3b5f7c7a23f1b92475417269878629f0c313a4755195161154189b6cb7

  
Delivery method
Distributed via web download
  
Dropping
MD5 f32257bf9cccafde26b94ee207ede0d6
  
Dropping
SHA256 48d1db3b5f7c7a23f1b92475417269878629f0c313a4755195161154189b6cb7

Comments