MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 18f8e2ee5bcf5ff764f5fb24b74cbb58f54e85981fc70835a23d0d135843170c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 18f8e2ee5bcf5ff764f5fb24b74cbb58f54e85981fc70835a23d0d135843170c
SHA3-384 hash: 783cc1107fba65e3156afd52d9b9fd61d409bf150d4d07e286ee0f20fab6f5f0ec4c075283a629181cb20bf5bb2c3066
SHA1 hash: 858feb83f7eff762e33a2c90a366195ce3f85d9b
MD5 hash: 0c9ea37be35f6d9ff7277b8688769256
humanhash: spaghetti-green-fifteen-maine
File name:bot
Download: download sample
File size:3'716'476 bytes
First seen:2025-12-17 23:17:35 UTC
Last seen:Never
File type: elf
MIME type:application/x-sharedlib
ssdeep 98304:xtwkcwvxVBs/+BX0DLI218I/9ZRv5Y2UfU:c+TU+cI2jXRBS8
TLSH T1070633F82333E4B7A340AC39D4170562451A02A518CF737DCB68852BDE369F11AEA5FB
TrID 50.1% (.) ELF Executable and Linkable format (Linux) (4022/12)
49.8% (.O) ELF Executable and Linkable format (generic) (4000/1)
Magika elf
Reporter abuse_ch
Tags:elf

Intelligence


File Origin
# of uploads :
1
# of downloads :
39
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Result
Verdict:
Clean
Maliciousness:

Behaviour
Creating a file
Verdict:
Adware
File Type:
elf.64.le
First seen:
2025-12-17T12:42:00Z UTC
Last seen:
2025-12-18T00:30:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=a7f6e9b7-1900-0000-9b1e-ac4565140000 pid=5221 /usr/bin/sudo guuid=09e771ba-1900-0000-9b1e-ac4566140000 pid=5222 /tmp/sample.bin write-file guuid=a7f6e9b7-1900-0000-9b1e-ac4565140000 pid=5221->guuid=09e771ba-1900-0000-9b1e-ac4566140000 pid=5222 execve
Result
Threat name:
n/a
Detection:
clean
Classification:
n/a
Score:
1 / 100
Behaviour
Behavior Graph:
n/a
Threat name:
Linux.Trojan.SAgnt
Status:
Malicious
First seen:
2025-12-17 22:56:59 UTC
File Type:
ELF64 Little (SO)
AV detection:
7 of 24 (29.17%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
discovery linux
Behaviour
Reads runtime system information
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

elf 18f8e2ee5bcf5ff764f5fb24b74cbb58f54e85981fc70835a23d0d135843170c

(this sample)

  
Delivery method
Distributed via web download

Comments