MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 df4fe36ee361e1507c096e54d46ecea644c962ae3aaad9b03cb5aa4f5eb7785e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: df4fe36ee361e1507c096e54d46ecea644c962ae3aaad9b03cb5aa4f5eb7785e
SHA3-384 hash: cce33a26c8880be59e0418b242bf00ab43f2baf020ec8355756d9f248d4a33485a81122a1ee7d7ec3a0735eb8b2008fb
SHA1 hash: f688a1b6ef3595ab83f2f4f83c8b8f90e204ed36
MD5 hash: 78634c03070d851b37e4ce6dfee092fd
humanhash: cup-nitrogen-red-oklahoma
File name:wwg
Download: download sample
File size:306 bytes
First seen:2025-11-20 20:38:49 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 6:ho58ziyZzw0yh/Fj/6DV/j7YFs7smI9//P6Q//D7B/+bZJbKXFs7Yjs:1aV/6DV37GTsJbKKEjs
TLSH T175E0C256C0971C1A38BE8584F0BD04A0E6196833FF1D452C3A9FFB9D4B782247568899
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
36
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
Labled as:
TrojanDownloader/Linux.CoinMiner.w
Verdict:
Malicious
File Type:
unix shell
First seen:
2025-11-20T17:58:00Z UTC
Last seen:
2025-11-22T10:20:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.bc
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Linux.Downloader.SAgnt
Status:
Malicious
First seen:
2025-11-20 20:54:17 UTC
File Type:
Text (Shell)
AV detection:
11 of 38 (28.95%)
Threat level:
  3/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh df4fe36ee361e1507c096e54d46ecea644c962ae3aaad9b03cb5aa4f5eb7785e

(this sample)

  
Delivery method
Distributed via web download

Comments