MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0bfc5268e2acae858c0bb0e71d0a32756fd042ebb98427ae23f10bd1e2d5dd3e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 0bfc5268e2acae858c0bb0e71d0a32756fd042ebb98427ae23f10bd1e2d5dd3e
SHA3-384 hash: 1fd43d1f75a183dd40d24727a0927b63086cfe450211f4769e34ea713cc0bb93afe16d575247629d12d57b33e9617f90
SHA1 hash: f1b26345d5f1726be4e272163c2fadf0c2530a33
MD5 hash: cb5bd1b5a75eb1cf9db91e5a794a6af8
humanhash: oscar-magnesium-ohio-tennis
File name:arm6
Download: download sample
File size:1'259'493 bytes
First seen:2026-01-18 20:48:34 UTC
Last seen:Never
File type: elf
MIME type:application/x-executable
ssdeep 24576:i+Xvy2KqyvkmoMDRCXQ4d4lsloSlJAzZL1vLOOkF0rvQQpVv51ky3cqm:i0qYAnSQfljSlSdBaWPvDc5
TLSH T139453386B7F844ADF54B1536593E4FCCDA6A673146859B0201F3C86D0FA62BEB3607C8
Magika elf
Reporter abuse_ch
Tags:elf

Intelligence


File Origin
# of uploads :
1
# of downloads :
70
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Result
Gathering data
Status:
terminated
Behavior Graph:
%3 guuid=f2f0c51b-1700-0000-5bed-43969b0d0000 pid=3483 /usr/bin/sudo guuid=c5c84d1d-1700-0000-5bed-43969c0d0000 pid=3484 /tmp/sample.bin guuid=f2f0c51b-1700-0000-5bed-43969b0d0000 pid=3483->guuid=c5c84d1d-1700-0000-5bed-43969c0d0000 pid=3484 execve
Result
Threat name:
n/a
Detection:
clean
Classification:
n/a
Score:
2 / 100
Behaviour
Behavior Graph:
n/a
Result
Malware family:
n/a
Score:
  5/10
Tags:
upx
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

elf 0bfc5268e2acae858c0bb0e71d0a32756fd042ebb98427ae23f10bd1e2d5dd3e

(this sample)

  
Delivery method
Distributed via web download

Comments