MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 e44ff951bda14076806b8ed24d6f512198d609e7812e5e1104b122f73699881e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Threat unknown
Vendor detections: 6
| SHA256 hash: | e44ff951bda14076806b8ed24d6f512198d609e7812e5e1104b122f73699881e |
|---|---|
| SHA3-384 hash: | 98fe0c27bf4517c316a1e6d66d9f8faf877a3c9e95e7fa0e4b5a6f45e31c8a2c38640230e4afba7f7f1a2c17b5e02e49 |
| SHA1 hash: | 57d8c71ac04c0dbe5e7f0d13c00660269fec78e5 |
| MD5 hash: | 24c4cc1856a43f691179d480c40d110c |
| humanhash: | cold-uncle-equal-happy |
| File name: | bwwg |
| Download: | download sample |
| File size: | 333 bytes |
| First seen: | 2025-09-08 16:34:33 UTC |
| Last seen: | Never |
| File type: | sh |
| MIME type: | text/x-shellscript |
| ssdeep | 6:honsEWQJAnAFKCwloeH6cD2QFs7smI9//PwfQ//D7B/+bZJbKXFs7Yjs:U0AYloeH6TPoTsJbKKEjs |
| TLSH | T12FE0C266A08B586644BF4B84B4322734F7119073BF18431CFF8685A0CAF0A36F0EC694 |
| Magika | shell |
| Reporter | |
| Tags: | sh |
Intelligence
File Origin
# of uploads :
1
# of downloads :
31
Origin country :
DEVendor Threat Intelligence
Verdict:
Suspicious
Threat level:
5/10
Confidence:
100%
Tags:
busybox
Verdict:
Malicious
Labled as:
Trojan[Downloader]/Shell.Agent
Verdict:
Unknown
File Type:
unix shell
First seen:
2025-09-08T14:02:00Z UTC
Last seen:
2025-09-08T14:02:00Z UTC
Hits:
~10
Status:
Failed
Score:
99%
Verdict:
Malware
File Type:
SCRIPT
Threat name:
Linux.Downloader.SAgnt
Status:
Malicious
First seen:
2025-09-08 17:13:53 UTC
File Type:
Text (Shell)
AV detection:
13 of 37 (35.14%)
Threat level:
3/5
Detection(s):
Suspicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Web download
sh e44ff951bda14076806b8ed24d6f512198d609e7812e5e1104b122f73699881e
(this sample)
Delivery method
Distributed via web download
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.