MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d393a37fb960f9adb7243ebbb38f3e19890bb39a05ee389daacf23fedf6cdb77. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: d393a37fb960f9adb7243ebbb38f3e19890bb39a05ee389daacf23fedf6cdb77
SHA3-384 hash: ccc6724b0f648256351d5958856610f1453b1f1225cedd546bb233ca52f4ff11240c16878de3d8ad94afff7f778068b4
SHA1 hash: 2d0728594a044be25b79a09843077db86f070d2b
MD5 hash: 81021989c4833e0dd594b005b1d60fbb
humanhash: bakerloo-august-uncle-oregon
File name:violetppc
Download: download sample
File size:22'500 bytes
First seen:2026-03-14 08:22:29 UTC
Last seen:2026-03-14 15:12:54 UTC
File type: elf
MIME type:application/x-executable
ssdeep 384:jlDNhLEb4WcaQdRShVRg/1ZaUP8SOrCmg6ATqGdlN7S0gatyyd:zWRQdRS7KOBrCm7AeGPJS3Q
TLSH T104A2E856A20E0997C8671E703E3EB3DC971FAED522D4D189300E9E4A82BAD32514DDDF
Magika elf
Reporter abuse_ch
Tags:elf

Intelligence


File Origin
# of uploads :
2
# of downloads :
116
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
mirai
Status:
terminated
Behavior Graph:
%3 guuid=ff3cbd33-1700-0000-d69c-038a9e0e0000 pid=3742 /usr/bin/sudo guuid=4eb48735-1700-0000-d69c-038aa50e0000 pid=3749 /tmp/sample.bin guuid=ff3cbd33-1700-0000-d69c-038a9e0e0000 pid=3742->guuid=4eb48735-1700-0000-d69c-038aa50e0000 pid=3749 execve
Result
Threat name:
n/a
Detection:
clean
Classification:
n/a
Score:
1 / 100
Behaviour
Behavior Graph:
n/a
Threat name:
Linux.Trojan.Generic
Status:
Suspicious
First seen:
2026-03-14 08:23:18 UTC
File Type:
ELF32 Big (Exe)
AV detection:
8 of 24 (33.33%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
linux
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

elf d393a37fb960f9adb7243ebbb38f3e19890bb39a05ee389daacf23fedf6cdb77

(this sample)

  
Delivery method
Distributed via web download

Comments