MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 640b82f6941327dd907ba66c6a4e79f864ebebc57fc3c8edd448ce07e64d6d55. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA 7 File information Comments

SHA256 hash: 640b82f6941327dd907ba66c6a4e79f864ebebc57fc3c8edd448ce07e64d6d55
SHA3-384 hash: d75e402c5555ba31ba6199b69dcb62d251abb4de2b4ddb93f3516677e5938116b0e0fb4f6e40943d255e4be5b432850f
SHA1 hash: 63cfb404773bed21982c64c3dfb952bb06e0af0a
MD5 hash: 87dbddc4d75978764479ca16725678af
humanhash: iowa-mars-east-single
File name:agent_linux_mipsle
Download: download sample
File size:2'574'504 bytes
First seen:2026-07-23 07:52:55 UTC
Last seen:Never
File type: elf
MIME type:application/x-executable
ssdeep 49152:6+VlEmcd2tqQB9uTA/RQfNRFYw8u/WL21e31pC76oDa3K/QpDD:plEb2RD+a0+qU3bC7caIp/
TLSH T13DC533E9CEC2C80F7E948641D7FE2C51D0DA51EB66DC983263EDEAD1807F6A4D422385
Magika elf
Reporter 1ZRR4H
Tags:elf UPX
File size (compressed) :2'574'504 bytes
File size (de-compressed) :7'274'689 bytes
Format:linux/mipsel
Unpacked file: 915e9b907527b27d9f1f9a55440150d1a6695dc91c92f680e83c1e084da4bfeb

Intelligence


File Origin
# of uploads :
1
# of downloads :
86
Origin country :
CL CL
Vendor Threat Intelligence
Result
Verdict:
Suspicious
Maliciousness:

Behaviour
Collects information on the network activity
Receives data from a server
Connection attempt
Sends data to a server
Collects information on the CPU
Collects information on the RAM
Substitutes an application name
Result
Malware family:
n/a
Score:
  6/10
Tags:
antivm discovery upx
Behaviour
GoLang User-Agent
Enumerates kernel/hardware configuration
Reads runtime system information
System Network Configuration Discovery
Changes its process name
Checks CPU configuration
Looks up external IP address via web service
Reads hardware information
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:GoBinTest
Rule name:golang_binary_string
Description:Golang strings present
Rule name:identity_golang
Author:Eric Yocam
Description:find Golang malware
Rule name:ProgramLanguage_Golang
Author:albertzsigovits
Description:Application written in Golang programming language
Rule name:SHA512_Constants
Author:phoul (@phoul)
Description:Look for SHA384/SHA512 constants
Rule name:TH_Generic_MassHunt_Linux_Malware_2026_CYFARE
Author:CYFARE
Description:Generic Linux malware mass-hunt rule - 2026
Reference:https://cyfare.net/
Rule name:upx_packed_elf_v1
Author:RandomMalware

File information


The table below shows additional information about this malware sample such as delivery method and external references.

elf 640b82f6941327dd907ba66c6a4e79f864ebebc57fc3c8edd448ce07e64d6d55

(this sample)

Comments