MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 6a9f16440b9319f427825bb12d7a0cda89b101cf7b8b15ec7dd620b4d68db514. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 6a9f16440b9319f427825bb12d7a0cda89b101cf7b8b15ec7dd620b4d68db514
SHA3-384 hash: f9f2c388f3f5a46dff66534bf043e6b638bf780f7b733c140299dbec8680e4d3c46d848e0b193b2719e38e271d1e5e07
SHA1 hash: cb26f73433b1c88ad9facaef31136aee3a88265d
MD5 hash: 4278ab79c34ea92788259fb43e535aa3
humanhash: spring-solar-zulu-sierra
File name:6a9f16440b9319f427825bb12d7a0cda89b101cf7b8b15ec7dd620b4d68db514
Download: download sample
File size:54'282 bytes
First seen:2020-09-23 13:12:30 UTC
Last seen:2021-03-11 07:40:29 UTC
File type: elf
MIME type:application/x-executable
ssdeep 384:EOFPL6one8+NhmKDhov3pjWaUOwVzGSCBOJAR/JXDHxmyRd3Bsd8SVY/tedIB689:E4zJm8nvGp6O4LlpXKbbOuvxe4SP7yQ
TLSH C633C527B9418A7CC09AF1B45EDF85B4A4A375F09B22720F33041BAA7851FD88F3E655
telfhash d6f0c042b93eab0501f748708df447e60187a14354711b15df10eac1483ea06e618e4d
Reporter JAMESWT_WT
Tags:PWNLNX tool RedXOR Winnti

Intelligence


File Origin
# of uploads :
3
# of downloads :
168
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Linux.Trojan.WinNti
Status:
Malicious
First seen:
2020-09-15 17:53:25 UTC
File Type:
ELF64 Little (Exe)
AV detection:
16 of 29 (55.17%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments