🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ffb02c26ebdba947820e567bf366cb7add4ddbdb4f5993c62360c087e41294ec. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: ffb02c26ebdba947820e567bf366cb7add4ddbdb4f5993c62360c087e41294ec
SHA3-384 hash: 776763f4f9c218be2f600e3a28b9245fa3b1e4d455d6a17e8890e37b4d2cd7bca08401d4600f7b8cfa0578a23018138e
SHA1 hash: b21e37a87f1263ea3492fe5555d6239bd54a2809
MD5 hash: 769a7c90034d10f09ec9d3454fd609e5
humanhash: nine-maryland-stairway-mike
File name:se.sh
Download: download sample
File size:476 bytes
First seen:2024-11-15 04:32:08 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 12:v0FMQFXNpBeo0FMQFXsQAMo0FMQFX6NISpo0FMQFXHtxKF:U3XFeJ3X3AMJ3X6NI+J3XbKF
TLSH T1A8F0A5D9205346762EE56E93326AC40479D2B18586E8EF0EADEC34F5159DF04702AEE3
Magika shell
Reporter abuse_ch
Tags:sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
72
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
Score:
94.9%
Tags:
mirai agent hype sage
Threat name:
Linux.Trojan.Multiverze
Status:
Malicious
First seen:
2024-11-15 04:33:11 UTC
File Type:
Text (Shell)
AV detection:
11 of 24 (45.83%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
discovery
Behaviour
Modifies registry class
Suspicious behavior: GetForegroundWindowSpam
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh ffb02c26ebdba947820e567bf366cb7add4ddbdb4f5993c62360c087e41294ec

(this sample)

  
Delivery method
Distributed via web download

Comments