MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2bbd7a1a1c2094a8a7836beafc7ff4450841de62987b69fb6e50e2c90e8049c2. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA 4 File information Comments

SHA256 hash: 2bbd7a1a1c2094a8a7836beafc7ff4450841de62987b69fb6e50e2c90e8049c2
SHA3-384 hash: a172db95629037c451a0d651432d8477a08321b8832eb108f6e3063697b4fc4253b36d3df6fe0df3faf6cc832dadd484
SHA1 hash: 2c8af63f6eb4bb329b4bb0aec4bcd584d8bd8221
MD5 hash: 1f2b11d84917000954a92de4226453b9
humanhash: winner-nebraska-mars-bacon
File name:dlr.POWERPC
Download: download sample
File size:243'392 bytes
First seen:2026-02-13 10:19:37 UTC
Last seen:2026-02-13 21:08:38 UTC
File type: elf
MIME type:application/x-executable
ssdeep 6144:JbnvGhoqRFijWE6VCkEscTzv+2UgNFpZ0GAwywrLXYZ75J:ZvGhhFijuVCUKm2UgNTukLXc75J
TLSH T1F93422BDE7345B729912B9BEF122DC7810731ADC73DCB7406FD801ABAC9E10A8445E16
TrID 50.1% (.) ELF Executable and Linkable format (Linux) (4022/12)
49.8% (.O) ELF Executable and Linkable format (generic) (4000/1)
Magika elf
Reporter abuse_ch
Tags:elf UPX
File size (compressed) :243'392 bytes
File size (de-compressed) :660'104 bytes
Format:linux/ppc32
Unpacked file: fdb991f6aaad78495c6641d93d616c8b777a57111bc35c5611549bd034457270

Intelligence


File Origin
# of uploads :
2
# of downloads :
45
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
packed upx
Result
Gathering data
Status:
terminated
Behavior Graph:
%3 guuid=edd93b4d-1a00-0000-b419-d075b60a0000 pid=2742 /usr/bin/sudo guuid=767dc54f-1a00-0000-b419-d075be0a0000 pid=2750 /tmp/sample.bin guuid=edd93b4d-1a00-0000-b419-d075b60a0000 pid=2742->guuid=767dc54f-1a00-0000-b419-d075be0a0000 pid=2750 execve
Result
Threat name:
n/a
Detection:
suspicious
Classification:
evad
Score:
22 / 100
Signature
Sample is packed with UPX
Behaviour
Behavior Graph:
Result
Malware family:
n/a
Score:
  5/10
Tags:
linux upx
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:linux_generic_ipv6_catcher
Author:@_lubiedo
Description:ELF samples using IPv6 addresses
Rule name:SUSP_ELF_LNX_UPX_Compressed_File
Author:Florian Roth (Nextron Systems)
Description:Detects a suspicious ELF binary with UPX compression
Reference:Internal Research
Rule name:upx_packed_elf_v1
Author:RandomMalware

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

elf 2bbd7a1a1c2094a8a7836beafc7ff4450841de62987b69fb6e50e2c90e8049c2

(this sample)

Comments