MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e44ff951bda14076806b8ed24d6f512198d609e7812e5e1104b122f73699881e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: e44ff951bda14076806b8ed24d6f512198d609e7812e5e1104b122f73699881e
SHA3-384 hash: 98fe0c27bf4517c316a1e6d66d9f8faf877a3c9e95e7fa0e4b5a6f45e31c8a2c38640230e4afba7f7f1a2c17b5e02e49
SHA1 hash: 57d8c71ac04c0dbe5e7f0d13c00660269fec78e5
MD5 hash: 24c4cc1856a43f691179d480c40d110c
humanhash: cold-uncle-equal-happy
File name:bwwg
Download: download sample
File size:333 bytes
First seen:2025-09-08 16:34:33 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 6:honsEWQJAnAFKCwloeH6cD2QFs7smI9//PwfQ//D7B/+bZJbKXFs7Yjs:U0AYloeH6TPoTsJbKKEjs
TLSH T12FE0C266A08B586644BF4B84B4322734F7119073BF18431CFF8685A0CAF0A36F0EC694
Magika shell
Reporter abuse_ch
Tags:sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
31
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
busybox
Verdict:
Malicious
Labled as:
Trojan[Downloader]/Shell.Agent
Verdict:
Unknown
File Type:
unix shell
First seen:
2025-09-08T14:02:00Z UTC
Last seen:
2025-09-08T14:02:00Z UTC
Hits:
~10
Threat name:
Linux.Downloader.SAgnt
Status:
Malicious
First seen:
2025-09-08 17:13:53 UTC
File Type:
Text (Shell)
AV detection:
13 of 37 (35.14%)
Threat level:
  3/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh e44ff951bda14076806b8ed24d6f512198d609e7812e5e1104b122f73699881e

(this sample)

  
Delivery method
Distributed via web download

Comments