MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d36c9cf32cf563d57e1ed4ba6bc75cb00ef0b77ecb74ce9c26b500fffea5a623. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: d36c9cf32cf563d57e1ed4ba6bc75cb00ef0b77ecb74ce9c26b500fffea5a623
SHA3-384 hash: 5106afa9a8d0de492d62686b463bec144733c64600b2e77af35773727053df23ad99f96c34e117d89df27383222ca10d
SHA1 hash: 78622aaeb270696f7c11e46e3fcf359085ff1bdc
MD5 hash: e1edff81f3622bd98e74d5321ee2d893
humanhash: salami-foxtrot-ten-potato
File name:chomp
Download: download sample
File size:146 bytes
First seen:2025-05-08 20:07:41 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 3:LxAjWl0SaGBzSEyLTUWuEHzGzKVxAjWl01NBzSE8eU9Muzn:L70SNIWuzCg701NNuzn
TLSH T166C08C8D0C96A3409114FCF83876CB2EB08DD2C460D00F2E52A000F2C9C9720F8A8E20
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://185.142.53.233/mips63e5d4c2ac320aa49bfc1c23e1a253c00ec5e51b4b64f0fb304c34f4d0a6fa56 Gafgytddos elf gafgyt mirai
http://185.142.53.233/mpsl1f20bd51306a7cd754a0d6864311ca2a4fc8def258607ba35285216eb39e6891 Gafgytddos elf gafgyt mirai

Intelligence


File Origin
# of uploads :
1
# of downloads :
84
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
Score:
99.9%
Tags:
trojandownloader trojan virus
Threat name:
Linux.Downloader.SAgnt
Status:
Malicious
First seen:
2025-05-08 20:53:25 UTC
File Type:
Text (Shell)
AV detection:
5 of 24 (20.83%)
Threat level:
  3/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh d36c9cf32cf563d57e1ed4ba6bc75cb00ef0b77ecb74ce9c26b500fffea5a623

(this sample)

  
Delivery method
Distributed via web download

Comments