MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 033dcb22a727ab8ddcae53eafedf19736a768267c50113108e2e9cb6c8b91848. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Threat unknown
Vendor detections: 5
| SHA256 hash: | 033dcb22a727ab8ddcae53eafedf19736a768267c50113108e2e9cb6c8b91848 |
|---|---|
| SHA3-384 hash: | 2aae53505c6a48d9bdbe5a5819932cbcc080b4c2967b2020f4d587df6bfaa526a36ffd3a2f15b9748e84d479355b18ce |
| SHA1 hash: | cac5546e85dadc28ffac9c252c67cec4ff94fe27 |
| MD5 hash: | 6eaafbf8befb414545b83748e7c9e03a |
| humanhash: | kilo-magnesium-emma-papa |
| File name: | o.xml |
| Download: | download sample |
| File size: | 739 bytes |
| First seen: | 2025-11-15 08:16:17 UTC |
| Last seen: | 2025-11-15 11:20:21 UTC |
| File type: | |
| MIME type: | text/plain |
| ssdeep | 12:FH8ioNJAC7ukxGWi2jU30+0K5+A+GSjRBk4DClk4DoBjZhG+E6:FH8j/wWi2jzCmIFSzf |
| TLSH | T1C401D6BDA1A88A5205B5C5C7B2F14546C490908BA2EE57E6F38E09276F28CDE3C5320D |
| Magika | xml |
| Reporter | |
| Tags: | xml |
Intelligence
File Origin
# of uploads :
2
# of downloads :
35
Origin country :
DEVendor Threat Intelligence
Verdict:
Clean
Score:
99.9%
Tags:
n/a
Verdict:
Malicious
Threat level:
10/10
Confidence:
100%
Tags:
masquerade opendir
Verdict:
Malicious
Labled as:
TrojanDownloader/Linux.NetLoader
Verdict:
Unknown
File Type:
text
Score:
0%
Verdict:
Benign
File Type:
SCRIPT
Threat name:
Script-JS.Trojan.Heuristic
Status:
Malicious
First seen:
2025-11-15 09:10:49 UTC
File Type:
Text
AV detection:
8 of 24 (33.33%)
Threat level:
2/5
Detection(s):
Suspicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Legit
Score:
0.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Web download
033dcb22a727ab8ddcae53eafedf19736a768267c50113108e2e9cb6c8b91848
(this sample)
Delivery method
Distributed via web download
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.