🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 1e3eb765015fd335cfdcb0ddd020565690b5a2f15a2a62406d750bcb21b6d77b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA 25 File information Comments

SHA256 hash: 1e3eb765015fd335cfdcb0ddd020565690b5a2f15a2a62406d750bcb21b6d77b
SHA3-384 hash: b1b2b9bc5de523bd26ef9b320b2a4436d239aa073a9b1f729a2e67f4fcf92e384f7645bcfe754dab6c3e2e45133640ea
SHA1 hash: 42cb9b12c6287225772e040bf8b151c8935bc7e8
MD5 hash: fa83031a6964319843f67713fdd56b80
humanhash: florida-missouri-ceiling-twenty
File name:amd64
Download: download sample
File size:5'242'880 bytes
First seen:2026-03-14 07:35:17 UTC
Last seen:2026-09-15 13:52:02 UTC
File type: elf
MIME type:application/x-executable
ssdeep 49152:IJPpsCDvmLCyk8NbrRpeGICkKhhbnRL5EWOiGr9Y/zA95xwEhO:CpsAvmLCc/e6RXEBrPvxJ
TLSH T1E7364A57FCA545E9C0AED1348A629252BA717C485B3123D72F90F7383F72BD0AA7A344
telfhash t1bd2259744a7d34b5baa6d920b363b5b4957319a262f834b15023ed90ffc1e801ce6c7b
gimphash e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
TrID 50.1% (.) ELF Executable and Linkable format (Linux) (4022/12)
49.8% (.O) ELF Executable and Linkable format (generic) (4000/1)
Magika elf
Reporter Skynet11
Tags:elf

Intelligence


File Origin
# of uploads :
12
# of downloads :
107
Origin country :
AU AU
Vendor Threat Intelligence
No detections
Gathering data
Status:
terminated
Behavior Graph:
%3 guuid=d378e46d-1800-0000-efd6-ac84ee0d0000 pid=3566 /usr/bin/sudo guuid=0fee8b6f-1800-0000-efd6-ac84f40d0000 pid=3572 /tmp/sample.bin guuid=d378e46d-1800-0000-efd6-ac84ee0d0000 pid=3566->guuid=0fee8b6f-1800-0000-efd6-ac84f40d0000 pid=3572 execve guuid=0fee8b6f-1800-0000-efd6-ac84f40d0000 pid=3585 /tmp/sample.bin guuid=0fee8b6f-1800-0000-efd6-ac84f40d0000 pid=3572->guuid=0fee8b6f-1800-0000-efd6-ac84f40d0000 pid=3585 clone guuid=0fee8b6f-1800-0000-efd6-ac84f40d0000 pid=3586 /tmp/sample.bin guuid=0fee8b6f-1800-0000-efd6-ac84f40d0000 pid=3572->guuid=0fee8b6f-1800-0000-efd6-ac84f40d0000 pid=3586 clone guuid=0fee8b6f-1800-0000-efd6-ac84f40d0000 pid=3587 /tmp/sample.bin guuid=0fee8b6f-1800-0000-efd6-ac84f40d0000 pid=3572->guuid=0fee8b6f-1800-0000-efd6-ac84f40d0000 pid=3587 clone guuid=0fee8b6f-1800-0000-efd6-ac84f40d0000 pid=3588 /tmp/sample.bin guuid=0fee8b6f-1800-0000-efd6-ac84f40d0000 pid=3572->guuid=0fee8b6f-1800-0000-efd6-ac84f40d0000 pid=3588 clone guuid=1c520674-1800-0000-efd6-ac84050e0000 pid=3589 /tmp/sample.bin delete-file dns net send-data write-config write-file zombie guuid=0fee8b6f-1800-0000-efd6-ac84f40d0000 pid=3572->guuid=1c520674-1800-0000-efd6-ac84050e0000 pid=3589 execve cd1e13fc-e338-52a2-99d9-63be1d9b9f9c www.google.com:9 guuid=1c520674-1800-0000-efd6-ac84050e0000 pid=3589->cd1e13fc-e338-52a2-99d9-63be1d9b9f9c con 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=1c520674-1800-0000-efd6-ac84050e0000 pid=3589->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 40B guuid=1c520674-1800-0000-efd6-ac84050e0000 pid=3591 /tmp/sample.bin zombie guuid=1c520674-1800-0000-efd6-ac84050e0000 pid=3589->guuid=1c520674-1800-0000-efd6-ac84050e0000 pid=3591 clone guuid=1c520674-1800-0000-efd6-ac84050e0000 pid=3592 /tmp/sample.bin guuid=1c520674-1800-0000-efd6-ac84050e0000 pid=3589->guuid=1c520674-1800-0000-efd6-ac84050e0000 pid=3592 clone guuid=1c520674-1800-0000-efd6-ac84050e0000 pid=3593 /tmp/sample.bin net send-data zombie guuid=1c520674-1800-0000-efd6-ac84050e0000 pid=3589->guuid=1c520674-1800-0000-efd6-ac84050e0000 pid=3593 clone guuid=1c520674-1800-0000-efd6-ac84050e0000 pid=3594 /tmp/sample.bin dns net send-data zombie guuid=1c520674-1800-0000-efd6-ac84050e0000 pid=3589->guuid=1c520674-1800-0000-efd6-ac84050e0000 pid=3594 clone guuid=66f0c07a-1800-0000-efd6-ac841b0e0000 pid=3611 /usr/bin/journalctl guuid=1c520674-1800-0000-efd6-ac84050e0000 pid=3589->guuid=66f0c07a-1800-0000-efd6-ac841b0e0000 pid=3611 execve guuid=7b40c8df-1800-0000-efd6-ac84740f0000 pid=3956 /usr/bin/bash guuid=1c520674-1800-0000-efd6-ac84050e0000 pid=3589->guuid=7b40c8df-1800-0000-efd6-ac84740f0000 pid=3956 execve guuid=301decf0-1800-0000-efd6-ac84b10f0000 pid=4017 /usr/bin/bash write-config guuid=1c520674-1800-0000-efd6-ac84050e0000 pid=3589->guuid=301decf0-1800-0000-efd6-ac84b10f0000 pid=4017 execve guuid=12fa490c-1900-0000-efd6-ac8408100000 pid=4104 /usr/sbin/update-rc.d guuid=1c520674-1800-0000-efd6-ac84050e0000 pid=3589->guuid=12fa490c-1900-0000-efd6-ac8408100000 pid=4104 execve guuid=73e71b45-1900-0000-efd6-ac84f2100000 pid=4338 /usr/bin/mount guuid=1c520674-1800-0000-efd6-ac84050e0000 pid=3589->guuid=73e71b45-1900-0000-efd6-ac84f2100000 pid=4338 execve guuid=52f52646-1900-0000-efd6-ac84fa100000 pid=4346 /usr/bin/systemctl guuid=1c520674-1800-0000-efd6-ac84050e0000 pid=3589->guuid=52f52646-1900-0000-efd6-ac84fa100000 pid=4346 execve guuid=be4c5dd3-1900-0000-efd6-ac8438130000 pid=4920 /usr/bin/systemctl guuid=1c520674-1800-0000-efd6-ac84050e0000 pid=3589->guuid=be4c5dd3-1900-0000-efd6-ac8438130000 pid=4920 execve guuid=1c520674-1800-0000-efd6-ac84050e0000 pid=3593->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 40B guuid=1c520674-1800-0000-efd6-ac84050e0000 pid=3594->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 86B 1e24fb12-1f5c-52f2-b85d-d40028bb6896 web.2k5u.ru:2070 guuid=1c520674-1800-0000-efd6-ac84050e0000 pid=3594->1e24fb12-1f5c-52f2-b85d-d40028bb6896 con guuid=c29b297b-1800-0000-efd6-ac841d0e0000 pid=3613 /usr/bin/systemctl guuid=66f0c07a-1800-0000-efd6-ac841b0e0000 pid=3611->guuid=c29b297b-1800-0000-efd6-ac841d0e0000 pid=3613 execve guuid=595ca9af-1800-0000-efd6-ac84c70e0000 pid=3783 /usr/bin/systemctl guuid=66f0c07a-1800-0000-efd6-ac841b0e0000 pid=3611->guuid=595ca9af-1800-0000-efd6-ac84c70e0000 pid=3783 execve guuid=066626d9-1800-0000-efd6-ac84590f0000 pid=3929 /usr/bin/systemctl guuid=66f0c07a-1800-0000-efd6-ac841b0e0000 pid=3611->guuid=066626d9-1800-0000-efd6-ac84590f0000 pid=3929 execve guuid=31a472e0-1800-0000-efd6-ac84770f0000 pid=3959 /usr/bin/bash guuid=7b40c8df-1800-0000-efd6-ac84740f0000 pid=3956->guuid=31a472e0-1800-0000-efd6-ac84770f0000 pid=3959 clone guuid=b9287ce0-1800-0000-efd6-ac84780f0000 pid=3960 /usr/bin/bash guuid=7b40c8df-1800-0000-efd6-ac84740f0000 pid=3956->guuid=b9287ce0-1800-0000-efd6-ac84780f0000 pid=3960 clone guuid=2182cb10-1900-0000-efd6-ac841a100000 pid=4122 /usr/bin/systemctl guuid=12fa490c-1900-0000-efd6-ac8408100000 pid=4104->guuid=2182cb10-1900-0000-efd6-ac841a100000 pid=4122 execve guuid=e9c09446-1900-0000-efd6-ac84fc100000 pid=4348 /usr/bin/basename guuid=52f52646-1900-0000-efd6-ac84fa100000 pid=4346->guuid=e9c09446-1900-0000-efd6-ac84fc100000 pid=4348 execve guuid=447ecf46-1900-0000-efd6-ac84ff100000 pid=4351 /usr/bin/basename guuid=52f52646-1900-0000-efd6-ac84fa100000 pid=4346->guuid=447ecf46-1900-0000-efd6-ac84ff100000 pid=4351 execve guuid=ea200e47-1900-0000-efd6-ac8400110000 pid=4352 /usr/bin/dash guuid=52f52646-1900-0000-efd6-ac84fa100000 pid=4346->guuid=ea200e47-1900-0000-efd6-ac8400110000 pid=4352 clone guuid=6b451447-1900-0000-efd6-ac8402110000 pid=4354 /usr/bin/systemctl guuid=ea200e47-1900-0000-efd6-ac8400110000 pid=4352->guuid=6b451447-1900-0000-efd6-ac8402110000 pid=4354 execve guuid=e4411a47-1900-0000-efd6-ac8403110000 pid=4355 /usr/bin/sed guuid=ea200e47-1900-0000-efd6-ac8400110000 pid=4352->guuid=e4411a47-1900-0000-efd6-ac8403110000 pid=4355 execve
Threat name:
Linux.Trojan.Kaiji
Status:
Malicious
First seen:
2026-02-26 18:17:30 UTC
File Type:
ELF64 Little (Exe)
AV detection:
18 of 36 (50.00%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
defense_evasion discovery linux persistence privilege_escalation
Behaviour
Enumerates kernel/hardware configuration
Reads runtime system information
Modifies Bash startup script
Creates/modifies environment variables
Modifies init.d
Modifies Watchdog functionality
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:DetectEncryptedVariants
Author:Zinyth
Description:Detects 'encrypted' in ASCII, Unicode, base64, or hex-encoded
Rule name:DetectGoMethodSignatures
Author:Wyatt Tauber
Description:Detects Go method signatures in unpacked Go binaries
Rule name:Detect_Go_GOMAXPROCS
Author:Obscurity Labs LLC
Description:Detects Go binaries by the presence of runtime.GOMAXPROCS in the runtime metadata
Rule name:enterpriseapps2
Author:Tim Brown @timb_machine
Description:Enterprise apps
Rule name:F01_s1ckrule
Author:s1ckb017
Rule name:GoBinTest
Rule name:golang
Rule name:golang_binary_string
Description:Golang strings present
Rule name:golang_duffcopy_amd64
Rule name:Golang_Find_CSC846
Author:Ashar Siddiqui
Description:Find Go Signatuers
Rule name:Golang_Find_CSC846_Simple
Author:Ashar Siddiqui
Description:Find Go Signatuers
Rule name:identity_golang
Author:Eric Yocam
Description:find Golang malware
Rule name:Linux_Generic_Threat_a40aaa96
Author:Elastic Security
Rule name:MD5_Constants
Author:phoul (@phoul)
Description:Look for MD5 constants
Rule name:ProgramLanguage_Golang
Author:albertzsigovits
Description:Application written in Golang programming language
Rule name:RANSOMWARE
Author:ToroGuitar
Rule name:RIPEMD160_Constants
Author:phoul (@phoul)
Description:Look for RIPEMD-160 constants
Rule name:setsockopt
Author:Tim Brown @timb_machine
Description:Hunts for setsockopt() red flags
Rule name:SHA1_Constants
Author:phoul (@phoul)
Description:Look for SHA1 constants
Rule name:SHA512_Constants
Author:phoul (@phoul)
Description:Look for SHA384/SHA512 constants
Rule name:Suspicious_Golang_Binary
Author:Tim Machac
Description:Triage: Golang-compiled binary with suspicious OS/persistence/network strings (not family-specific)
Rule name:telebot_framework
Author:vietdx.mb
Rule name:test_Malaysia
Author:rectifyq
Description:Detects file containing malaysia string
Rule name:unixredflags3
Author:Tim Brown @timb_machine
Description:Hunts for UNIX red flags

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

elf 1e3eb765015fd335cfdcb0ddd020565690b5a2f15a2a62406d750bcb21b6d77b

(this sample)

  
Delivery method
Distributed via web download

Comments