MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 776c62041bd45809187c56446118464323d0cf97cb82c65a243ddff54c3edbbf. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 776c62041bd45809187c56446118464323d0cf97cb82c65a243ddff54c3edbbf
SHA3-384 hash: 839b3b126d31ca96cb1a3b46fa5d6bb22ae8289ac9f81deb113717b222bf0fdc29715e1118b2d48e3bf557197e9bcf8e
SHA1 hash: fcb028fea07817e89e45d765037eee13d0a4f2d7
MD5 hash: e867275dda871d0bfc5539f4e618f17d
humanhash: twenty-artist-low-charlie
File name:ppowerpc
Download: download sample
File size:184'753 bytes
First seen:2026-01-26 00:55:15 UTC
Last seen:2026-01-26 10:44:56 UTC
File type: elf
MIME type:application/x-sharedlib
ssdeep 3072:ozdurayQy5HEcMf3oocl1ElUEfS6t9VuDLZ9GGE50XfZLYGH/tdjGJ75W+:ozdurafekcMwocl1ElUEfTV0sEdYYt89
TLSH T129040211FF0C442BD5864DB98E7B07A6E77C0C330479E62D960AFB961BB26370587B85
Magika elf
Reporter abuse_ch
Tags:elf

Intelligence


File Origin
# of uploads :
4
# of downloads :
74
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Result
Gathering data
Status:
terminated
Behavior Graph:
%3 guuid=492dbf2b-1a00-0000-0ce4-0ffff1090000 pid=2545 /usr/bin/sudo guuid=893c032f-1a00-0000-0ce4-0ffff8090000 pid=2552 /tmp/sample.bin guuid=492dbf2b-1a00-0000-0ce4-0ffff1090000 pid=2545->guuid=893c032f-1a00-0000-0ce4-0ffff8090000 pid=2552 execve
Result
Threat name:
n/a
Detection:
suspicious
Classification:
evad
Score:
22 / 100
Signature
Spawns processes using file descriptor names (likely to hide the executable path or fileless malware)
Behaviour
Behavior Graph:
Result
Malware family:
n/a
Score:
  1/10
Tags:
linux
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

elf 776c62041bd45809187c56446118464323d0cf97cb82c65a243ddff54c3edbbf

(this sample)

  
Delivery method
Distributed via web download

Comments