MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2bd04baefb1f340e0c7d816c96db0078c4eb8b7cfce6689fbb187e5696bc7a3a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA 1 File information Comments

SHA256 hash: 2bd04baefb1f340e0c7d816c96db0078c4eb8b7cfce6689fbb187e5696bc7a3a
SHA3-384 hash: 01a0f4e0232717777b926f2914389717f17680d399a9dcb0ee6ef45a8caae49ba8c5f93277a5588cb76c9b8f89a8f7b2
SHA1 hash: 8e187058c73ea0ff5c7c20a06f2ffc6c09da4051
MD5 hash: 486c8fa64b8d20d789a32a363531c322
humanhash: saturn-oven-double-triple
File name:bot.x86_64
Download: download sample
File size:589'183 bytes
First seen:2026-08-03 02:09:18 UTC
Last seen:2026-08-03 14:58:36 UTC
File type: elf
MIME type:application/x-sharedlib
ssdeep 12288:LYt8cChCRDDJPnKG4olirFdk+hVyT0QJ9D3ZjHUIhGW:KHRDHwhVI0c3ZjHToW
TLSH T1F8C4AE07FAB114E8D9AECC348A1A9133EA29BCD8421676777FD45B213F25A10EF0E751
telfhash t13081b7348fac5461ebd70ce0a5f792656cba149ee3c469e18782aebc6df2dc01035d23
TrID 50.1% (.) ELF Executable and Linkable format (Linux) (4022/12)
49.8% (.O) ELF Executable and Linkable format (generic) (4000/1)
Magika elf
Reporter abuse_ch
Tags:elf

Intelligence


File Origin
# of uploads :
3
# of downloads :
60
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a process from a recently created file
Launching a process
Changes the time when the file was created, accessed, or modified
Changes access rights for a written file
Creating a file
Substitutes an application name
Creates or modifies files in /cron to set up autorun
Deleting of the original file
Verdict:
Malicious
Uses P2P?:
false
Uses anti-vm?:
true
Architecture:
x86
Packer:
custom
Botnet:
unknown
Number of open files:
66
Number of processes launched:
15
Processes remaning?
true
Remote TCP ports scanned:
not identified
Behaviour
Anti-VM
Persistence
Process Renaming
Information Gathering
Botnet C2s
TCP botnet C2(s):
not identified
UDP botnet C2(s):
not identified
Status:
terminated
Behavior Graph:
%3 guuid=06e1c1ed-1b00-0000-ec85-5db7ce080000 pid=2254 /usr/bin/sudo guuid=abd150f2-1b00-0000-ec85-5db7d2080000 pid=2258 memfd: delete-file net write-file guuid=06e1c1ed-1b00-0000-ec85-5db7ce080000 pid=2254->guuid=abd150f2-1b00-0000-ec85-5db7d2080000 pid=2258 execve cc0ac6be-7bea-5e42-bee5-f132cb1dd4d5 192.0.2.1:80 guuid=abd150f2-1b00-0000-ec85-5db7d2080000 pid=2258->cc0ac6be-7bea-5e42-bee5-f132cb1dd4d5 con guuid=5b6ae538-1c00-0000-ec85-5db70a090000 pid=2314 memfd: guuid=abd150f2-1b00-0000-ec85-5db7d2080000 pid=2258->guuid=5b6ae538-1c00-0000-ec85-5db70a090000 pid=2314 clone guuid=24ed4439-1c00-0000-ec85-5db70b090000 pid=2315 memfd: guuid=abd150f2-1b00-0000-ec85-5db7d2080000 pid=2258->guuid=24ed4439-1c00-0000-ec85-5db70b090000 pid=2315 clone guuid=a46a9139-1c00-0000-ec85-5db70d090000 pid=2317 memfd: guuid=abd150f2-1b00-0000-ec85-5db7d2080000 pid=2258->guuid=a46a9139-1c00-0000-ec85-5db70d090000 pid=2317 clone guuid=8f93a739-1c00-0000-ec85-5db70e090000 pid=2318 memfd: guuid=abd150f2-1b00-0000-ec85-5db7d2080000 pid=2258->guuid=8f93a739-1c00-0000-ec85-5db70e090000 pid=2318 clone guuid=2c3e293a-1c00-0000-ec85-5db70f090000 pid=2319 memfd: guuid=abd150f2-1b00-0000-ec85-5db7d2080000 pid=2258->guuid=2c3e293a-1c00-0000-ec85-5db70f090000 pid=2319 clone guuid=4d92553a-1c00-0000-ec85-5db710090000 pid=2320 memfd: guuid=abd150f2-1b00-0000-ec85-5db7d2080000 pid=2258->guuid=4d92553a-1c00-0000-ec85-5db710090000 pid=2320 clone guuid=16f8b03a-1c00-0000-ec85-5db712090000 pid=2322 memfd: zombie guuid=abd150f2-1b00-0000-ec85-5db7d2080000 pid=2258->guuid=16f8b03a-1c00-0000-ec85-5db712090000 pid=2322 clone guuid=8fcdcf3a-1c00-0000-ec85-5db713090000 pid=2323 memfd: guuid=16f8b03a-1c00-0000-ec85-5db712090000 pid=2322->guuid=8fcdcf3a-1c00-0000-ec85-5db713090000 pid=2323 clone guuid=7931ea3a-1c00-0000-ec85-5db714090000 pid=2324 memfd: dns net send-data write-file guuid=8fcdcf3a-1c00-0000-ec85-5db713090000 pid=2323->guuid=7931ea3a-1c00-0000-ec85-5db714090000 pid=2324 clone 7c418115-42c4-5502-a7cd-d0db86569c5e iemgrouphere.st:38 guuid=7931ea3a-1c00-0000-ec85-5db714090000 pid=2324->7c418115-42c4-5502-a7cd-d0db86569c5e send: 253B a0528efd-1018-56b4-b518-221acb0fa7ca 9.9.9.9:53 guuid=7931ea3a-1c00-0000-ec85-5db714090000 pid=2324->a0528efd-1018-56b4-b518-221acb0fa7ca send: 33B guuid=7931ea3a-1c00-0000-ec85-5db714090000 pid=2325 memfd: guuid=7931ea3a-1c00-0000-ec85-5db714090000 pid=2324->guuid=7931ea3a-1c00-0000-ec85-5db714090000 pid=2325 clone guuid=7931ea3a-1c00-0000-ec85-5db714090000 pid=2326 memfd: delete-file guuid=7931ea3a-1c00-0000-ec85-5db714090000 pid=2324->guuid=7931ea3a-1c00-0000-ec85-5db714090000 pid=2326 clone guuid=7931ea3a-1c00-0000-ec85-5db714090000 pid=2327 memfd: delete-file write-file guuid=7931ea3a-1c00-0000-ec85-5db714090000 pid=2324->guuid=7931ea3a-1c00-0000-ec85-5db714090000 pid=2327 clone guuid=7931ea3a-1c00-0000-ec85-5db714090000 pid=2328 memfd: guuid=7931ea3a-1c00-0000-ec85-5db714090000 pid=2324->guuid=7931ea3a-1c00-0000-ec85-5db714090000 pid=2328 clone guuid=7931ea3a-1c00-0000-ec85-5db714090000 pid=2329 memfd: guuid=7931ea3a-1c00-0000-ec85-5db714090000 pid=2324->guuid=7931ea3a-1c00-0000-ec85-5db714090000 pid=2329 clone guuid=7931ea3a-1c00-0000-ec85-5db714090000 pid=2343 memfd: guuid=7931ea3a-1c00-0000-ec85-5db714090000 pid=2324->guuid=7931ea3a-1c00-0000-ec85-5db714090000 pid=2343 clone guuid=3d61de24-2700-0000-ec85-5db70e140000 pid=5134 memfd: guuid=7931ea3a-1c00-0000-ec85-5db714090000 pid=2327->guuid=3d61de24-2700-0000-ec85-5db70e140000 pid=5134 clone guuid=c64e322a-2700-0000-ec85-5db70f140000 pid=5135 memfd: guuid=7931ea3a-1c00-0000-ec85-5db714090000 pid=2327->guuid=c64e322a-2700-0000-ec85-5db70f140000 pid=5135 clone guuid=b2fa642a-2700-0000-ec85-5db710140000 pid=5136 memfd: guuid=7931ea3a-1c00-0000-ec85-5db714090000 pid=2327->guuid=b2fa642a-2700-0000-ec85-5db710140000 pid=5136 clone guuid=a145882a-2700-0000-ec85-5db711140000 pid=5137 memfd: guuid=7931ea3a-1c00-0000-ec85-5db714090000 pid=2327->guuid=a145882a-2700-0000-ec85-5db711140000 pid=5137 clone guuid=a7f7aa2a-2700-0000-ec85-5db712140000 pid=5138 memfd: guuid=7931ea3a-1c00-0000-ec85-5db714090000 pid=2327->guuid=a7f7aa2a-2700-0000-ec85-5db712140000 pid=5138 clone guuid=b950d72a-2700-0000-ec85-5db713140000 pid=5139 memfd: guuid=7931ea3a-1c00-0000-ec85-5db714090000 pid=2327->guuid=b950d72a-2700-0000-ec85-5db713140000 pid=5139 clone guuid=5f3afd30-2700-0000-ec85-5db71b140000 pid=5147 memfd: guuid=7931ea3a-1c00-0000-ec85-5db714090000 pid=2327->guuid=5f3afd30-2700-0000-ec85-5db71b140000 pid=5147 clone guuid=25f0b052-2700-0000-ec85-5db71c140000 pid=5148 memfd: guuid=7931ea3a-1c00-0000-ec85-5db714090000 pid=2327->guuid=25f0b052-2700-0000-ec85-5db71c140000 pid=5148 clone guuid=bd800553-2700-0000-ec85-5db71d140000 pid=5149 memfd: guuid=7931ea3a-1c00-0000-ec85-5db714090000 pid=2327->guuid=bd800553-2700-0000-ec85-5db71d140000 pid=5149 clone guuid=21aa6553-2700-0000-ec85-5db71e140000 pid=5150 memfd: guuid=7931ea3a-1c00-0000-ec85-5db714090000 pid=2327->guuid=21aa6553-2700-0000-ec85-5db71e140000 pid=5150 clone guuid=99127b53-2700-0000-ec85-5db71f140000 pid=5151 memfd: guuid=7931ea3a-1c00-0000-ec85-5db714090000 pid=2327->guuid=99127b53-2700-0000-ec85-5db71f140000 pid=5151 clone guuid=ef6a8e53-2700-0000-ec85-5db720140000 pid=5152 memfd: guuid=7931ea3a-1c00-0000-ec85-5db714090000 pid=2327->guuid=ef6a8e53-2700-0000-ec85-5db720140000 pid=5152 clone
Result
Threat name:
n/a
Detection:
malicious
Classification:
troj.spyw.evad
Score:
68 / 100
Signature
Drops files in suspicious directories
Executes the "crontab" command typically for achieving persistence
Opens /sys/class/net/* files useful for querying network interface information
Sample deletes itself
Sample tries to persist itself using cron
Sample tries to set files in /etc globally writable
Spawns processes using file descriptor names (likely to hide the executable path or fileless malware)
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1951133 Sample: bot.x86_64.elf Startdate: 03/08/2026 Architecture: LINUX Score: 68 54 iemgrouphere.st 95.164.53.73, 38, 41342 QWINS-LTDQWINSAS-SETAS213702AS-CUSTOMERSGB Germany 2->54 56 192.0.2.1, 80 unknown ZZ 2->56 9 bot.x86_64.elf 3 2->9         started        process3 signatures4 58 Sample tries to set files in /etc globally writable 9->58 60 Spawns processes using file descriptor names (likely to hide the executable path or fileless malware) 9->60 62 Opens /sys/class/net/* files useful for querying network interface information 9->62 64 2 other signatures 9->64 12 3 9->12         started        14 3 crontab 9->14         started        18 3 crontab 9->18         started        20 4 other processes 9->20 process5 file6 22 3 12->22         started        48 /var/spool/cron/crontabs/tmp.bgujKN, ASCII 14->48 dropped 74 Sample tries to persist itself using cron 14->74 76 Executes the "crontab" command typically for achieving persistence 14->76 50 /var/spool/cron/crontabs/tmp.M1Q3WV, ASCII 18->50 dropped 52 /var/spool/cron/crontabs/tmp.655Lk5, ASCII 20->52 dropped signatures7 process8 process9 24 3 22->24         started        file10 38 /tmp/.cron_tmp, ASCII 24->38 dropped 40 /etc/init.d/.kworker, POSIX 24->40 dropped 66 Sample tries to set files in /etc globally writable 24->66 68 Drops files in suspicious directories 24->68 28 3 crontab 24->28         started        32 3 crontab 24->32         started        34 3 crontab 24->34         started        36 3 other processes 24->36 signatures11 process12 file13 42 /var/spool/cron/crontabs/tmp.idZGlt, ASCII 28->42 dropped 70 Sample tries to persist itself using cron 28->70 72 Executes the "crontab" command typically for achieving persistence 28->72 44 /var/spool/cron/crontabs/tmp.5anChE, ASCII 32->44 dropped 46 /var/spool/cron/crontabs/tmp.IdAa0O, ASCII 34->46 dropped signatures14
Result
Malware family:
n/a
Score:
  7/10
Tags:
credential_access defense_evasion discovery execution linux persistence privilege_escalation upx
Behaviour
Enumerates kernel/hardware configuration
Reads runtime system information
Writes file to tmp directory
Changes its process name
Reads process memory
UPX packed file
Creates/modifies Cron job
Enumerates running processes
Modifies init.d
Reads MAC address of network interface
Deletes itself
Executes dropped EXE
Runs EXE from memory
Unexpected DNS network traffic destination
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ProgramLanguage_Rust
Author:albertzsigovits
Description:Application written in Rust programming language

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

elf 2bd04baefb1f340e0c7d816c96db0078c4eb8b7cfce6689fbb187e5696bc7a3a

(this sample)

  
Delivery method
Distributed via web download

Comments