MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 1a4c899ab46cb593cb021221fcd3df358f1446c5b35eeb06e2d400a065027858. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 1a4c899ab46cb593cb021221fcd3df358f1446c5b35eeb06e2d400a065027858
SHA3-384 hash: 6db194d01d5fc43c4dc54da523ce2cd338d419b60fddd41d3481611f2da44926396983adf297103b58bb28acb93d36a8
SHA1 hash: ead760438607010d092c9666f43273690d07ad77
MD5 hash: 0afc3604b0d291e0358fdbc8ad6ca710
humanhash: robin-enemy-blue-speaker
File name:bot
Download: download sample
File size:464'541 bytes
First seen:2026-01-05 19:39:21 UTC
Last seen:Never
File type: elf
MIME type:application/x-sharedlib
ssdeep 12288:T6GdkHxx6jLsVSv/6IPHs811nohBBrLXa2s0U1jSAm22Rq4ZeT:HkHn6jLIo/HPHsYmjrLXa2s51jRYRhZo
TLSH T1FDA423F850B798B5E72753AEA80B52B59B8DB240F3181F795AB405112B36C3B0C9CD6F
TrID 50.1% (.) ELF Executable and Linkable format (Linux) (4022/12)
49.8% (.O) ELF Executable and Linkable format (generic) (4000/1)
Magika elf
Reporter abuse_ch
Tags:elf

Intelligence


File Origin
# of uploads :
1
# of downloads :
33
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Result
Verdict:
Clean
Maliciousness:
Status:
terminated
Behavior Graph:
%3 guuid=ec228b16-1800-0000-a507-6c9b120d0000 pid=3346 /usr/bin/sudo guuid=1e978419-1800-0000-a507-6c9b1a0d0000 pid=3354 /tmp/sample.bin guuid=ec228b16-1800-0000-a507-6c9b120d0000 pid=3346->guuid=1e978419-1800-0000-a507-6c9b1a0d0000 pid=3354 execve
Result
Threat name:
n/a
Detection:
clean
Classification:
n/a
Score:
1 / 100
Behaviour
Behavior Graph:
n/a
Threat name:
Linux.Trojan.Generic
Status:
Suspicious
First seen:
2026-01-05 19:40:22 UTC
File Type:
ELF64 Little (SO)
AV detection:
4 of 24 (16.67%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
linux
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

elf 1a4c899ab46cb593cb021221fcd3df358f1446c5b35eeb06e2d400a065027858

(this sample)

  
Delivery method
Distributed via web download

Comments