MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 3b2cbd1dd7e0e78cab544fa6c5b97fa500f092e3c4fbe62adbbbbf1af79564c9. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Ladvix


Vendor detections: 10


Intelligence 10 IOCs YARA 15 File information Comments

SHA256 hash: 3b2cbd1dd7e0e78cab544fa6c5b97fa500f092e3c4fbe62adbbbbf1af79564c9
SHA3-384 hash: be9e96681361e351b7a7dd4378a198d428c40253dc7e79c26a59e38a53a31f20ff4f2a0501660d3bc4f5ed9e5cf318ef
SHA1 hash: 14e9dfa21242aa4ff85e31916d6babb1a32d6da3
MD5 hash: b4903db61f079f87aec5693ddc68f033
humanhash: venus-pizza-king-artist
File name:3b2cbd1dd7e0e78cab544fa6c5b97fa500f092e3c4fbe62adbbbbf1af79564c9.elf
Download: download sample
Signature Ladvix
File size:2'391'513 bytes
First seen:2026-08-15 03:09:35 UTC
Last seen:Never
File type: elf
MIME type:application/x-executable
ssdeep 49152:iUZDkNfJAxz390aw9ZnEwuytWOG4+Ad7MPy:i0M+4+AZM6
TLSH T17CB57C077CE158AAC0AA93328DB651A27BB2FC490B3123D72E50B3782F727D46D75794
telfhash t1952362416ce71e9a19c61367bc381ad613afe04f086a75296f64c37029eb08c553fb7e
gimphash e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
TrID 50.1% (.) ELF Executable and Linkable format (Linux) (4022/12)
49.8% (.O) ELF Executable and Linkable format (generic) (4000/1)
Magika elf
Reporter whack_sh
Tags:elf exe Ladvix whack.sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
177
Origin country :
US US
Vendor Threat Intelligence
No detections
Result
Verdict:
Malware
Maliciousness:

Behaviour
Deletes a file
Removes directories
Sets a written file as executable
Locks files
Manages services
Launching a process
Receives data from a server
Sends data to a server
Connection attempt
Changes the time when the file was created, accessed, or modified
Collects information on the CPU
Creating a file in the %temp% directory
Collects information on the OS
Creating a file
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
base64 bash golang lolbin reconnaissance
Verdict:
Malicious
Uses P2P?:
false
Uses anti-vm?:
false
Architecture:
x86
Packer:
custom
Botnet:
unknown
Number of open files:
10
Number of processes launched:
6
Processes remaning?
false
Remote TCP ports scanned:
not identified
Behaviour
Persistence
Botnet C2s
TCP botnet C2(s):
not identified
UDP botnet C2(s):
not identified
Verdict:
Malicious
File Type:
elf.64.le
First seen:
2026-08-15T01:29:00Z UTC
Last seen:
2026-08-15T01:58:00Z UTC
Hits:
~100
Status:
terminated
Behavior Graph:
%3 guuid=26aa890b-1700-0000-33e7-3c01d10d0000 pid=3537 /usr/bin/sudo guuid=167a5211-1700-0000-33e7-3c01d30d0000 pid=3539 /tmp/sample.bin write-config guuid=26aa890b-1700-0000-33e7-3c01d10d0000 pid=3537->guuid=167a5211-1700-0000-33e7-3c01d30d0000 pid=3539 execve guuid=167a5211-1700-0000-33e7-3c01d30d0000 pid=3554 /tmp/sample.bin guuid=167a5211-1700-0000-33e7-3c01d30d0000 pid=3539->guuid=167a5211-1700-0000-33e7-3c01d30d0000 pid=3554 clone guuid=167a5211-1700-0000-33e7-3c01d30d0000 pid=3555 /tmp/sample.bin guuid=167a5211-1700-0000-33e7-3c01d30d0000 pid=3539->guuid=167a5211-1700-0000-33e7-3c01d30d0000 pid=3555 clone guuid=167a5211-1700-0000-33e7-3c01d30d0000 pid=3556 /tmp/sample.bin guuid=167a5211-1700-0000-33e7-3c01d30d0000 pid=3539->guuid=167a5211-1700-0000-33e7-3c01d30d0000 pid=3556 clone guuid=167a5211-1700-0000-33e7-3c01d30d0000 pid=3560 /tmp/sample.bin guuid=167a5211-1700-0000-33e7-3c01d30d0000 pid=3539->guuid=167a5211-1700-0000-33e7-3c01d30d0000 pid=3560 clone guuid=7b675418-1700-0000-33e7-3c01e90d0000 pid=3561 /tmp/sample.bin guuid=167a5211-1700-0000-33e7-3c01d30d0000 pid=3539->guuid=7b675418-1700-0000-33e7-3c01e90d0000 pid=3561 clone guuid=cc8d7a18-1700-0000-33e7-3c01ea0d0000 pid=3562 /usr/bin/uname guuid=167a5211-1700-0000-33e7-3c01d30d0000 pid=3539->guuid=cc8d7a18-1700-0000-33e7-3c01ea0d0000 pid=3562 execve guuid=167a5211-1700-0000-33e7-3c01d30d0000 pid=3563 /tmp/sample.bin guuid=167a5211-1700-0000-33e7-3c01d30d0000 pid=3539->guuid=167a5211-1700-0000-33e7-3c01d30d0000 pid=3563 clone guuid=58cb6e19-1700-0000-33e7-3c01ed0d0000 pid=3565 /usr/bin/chmod guuid=167a5211-1700-0000-33e7-3c01d30d0000 pid=3539->guuid=58cb6e19-1700-0000-33e7-3c01ed0d0000 pid=3565 execve guuid=861bc943-1700-0000-33e7-3c01710e0000 pid=3697 /usr/bin/systemctl guuid=167a5211-1700-0000-33e7-3c01d30d0000 pid=3539->guuid=861bc943-1700-0000-33e7-3c01710e0000 pid=3697 execve guuid=6c89357d-1700-0000-33e7-3c01120f0000 pid=3858 /usr/bin/systemctl guuid=167a5211-1700-0000-33e7-3c01d30d0000 pid=3539->guuid=6c89357d-1700-0000-33e7-3c01120f0000 pid=3858 execve guuid=075afbd2-1700-0000-33e7-3c01f30f0000 pid=4083 /usr/bin/systemctl guuid=167a5211-1700-0000-33e7-3c01d30d0000 pid=3539->guuid=075afbd2-1700-0000-33e7-3c01f30f0000 pid=4083 execve guuid=acc23fda-1700-0000-33e7-3c0100100000 pid=4096 /usr/bin/pgrep guuid=167a5211-1700-0000-33e7-3c01d30d0000 pid=3539->guuid=acc23fda-1700-0000-33e7-3c0100100000 pid=4096 execve guuid=d8786adf-1700-0000-33e7-3c010c100000 pid=4108 /usr/bin/bash guuid=167a5211-1700-0000-33e7-3c01d30d0000 pid=3539->guuid=d8786adf-1700-0000-33e7-3c010c100000 pid=4108 execve guuid=e8043ae3-1700-0000-33e7-3c011b100000 pid=4123 /usr/bin/bash guuid=167a5211-1700-0000-33e7-3c01d30d0000 pid=3539->guuid=e8043ae3-1700-0000-33e7-3c011b100000 pid=4123 execve guuid=9d0a90e4-1700-0000-33e7-3c0122100000 pid=4130 /usr/bin/rm delete-file guuid=167a5211-1700-0000-33e7-3c01d30d0000 pid=3539->guuid=9d0a90e4-1700-0000-33e7-3c0122100000 pid=4130 execve guuid=344e9ceb-1700-0000-33e7-3c013a100000 pid=4154 /usr/bin/bash zombie guuid=167a5211-1700-0000-33e7-3c01d30d0000 pid=3539->guuid=344e9ceb-1700-0000-33e7-3c013a100000 pid=4154 execve guuid=50d2d61a-1700-0000-33e7-3c01f20d0000 pid=3570 /usr/bin/curl net send-data write-file guuid=58cb6e19-1700-0000-33e7-3c01ed0d0000 pid=3565->guuid=50d2d61a-1700-0000-33e7-3c01f20d0000 pid=3570 execve a633da7e-6415-55fb-93ef-5ee209767fd5 2.57.241.243:80 guuid=50d2d61a-1700-0000-33e7-3c01f20d0000 pid=3570->a633da7e-6415-55fb-93ef-5ee209767fd5 send: 82B guuid=f4fee7e0-1700-0000-33e7-3c0111100000 pid=4113 /usr/bin/rm delete-file guuid=d8786adf-1700-0000-33e7-3c010c100000 pid=4108->guuid=f4fee7e0-1700-0000-33e7-3c0111100000 pid=4113 execve guuid=4d85f2e1-1700-0000-33e7-3c0115100000 pid=4117 /usr/bin/rm delete-file guuid=d8786adf-1700-0000-33e7-3c010c100000 pid=4108->guuid=4d85f2e1-1700-0000-33e7-3c0115100000 pid=4117 execve guuid=f7276ee2-1700-0000-33e7-3c0117100000 pid=4119 /usr/bin/rm guuid=d8786adf-1700-0000-33e7-3c010c100000 pid=4108->guuid=f7276ee2-1700-0000-33e7-3c0117100000 pid=4119 execve guuid=1f33a6ec-1700-0000-33e7-3c013e100000 pid=4158 /usr/bin/wget net send-data write-file guuid=344e9ceb-1700-0000-33e7-3c013a100000 pid=4154->guuid=1f33a6ec-1700-0000-33e7-3c013e100000 pid=4158 execve guuid=d7204609-1800-0000-33e7-3c0190100000 pid=4240 /usr/bin/chmod guuid=344e9ceb-1700-0000-33e7-3c013a100000 pid=4154->guuid=d7204609-1800-0000-33e7-3c0190100000 pid=4240 execve guuid=31eabc09-1800-0000-33e7-3c0192100000 pid=4242 /usr/bin/bash zombie guuid=344e9ceb-1700-0000-33e7-3c013a100000 pid=4154->guuid=31eabc09-1800-0000-33e7-3c0192100000 pid=4242 clone 0eae001c-4ad4-599c-ab6a-77d3fac12203 176.65.139.211:80 guuid=1f33a6ec-1700-0000-33e7-3c013e100000 pid=4158->0eae001c-4ad4-599c-ab6a-77d3fac12203 send: 132B guuid=ff29f209-1800-0000-33e7-3c0193100000 pid=4243 /usr/bin/pgrep guuid=31eabc09-1800-0000-33e7-3c0192100000 pid=4242->guuid=ff29f209-1800-0000-33e7-3c0193100000 pid=4243 execve
Threat name:
Linux.Trojan.Generic
Status:
Suspicious
First seen:
2026-08-15 03:10:24 UTC
File Type:
ELF64 Little (Exe)
AV detection:
4 of 38 (10.53%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:ladvix defense_evasion discovery infector linux persistence privilege_escalation trojan
Behaviour
Enumerates kernel/hardware configuration
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Reads CPU attributes
Deletes log files
Enumerates running processes
Modifies systemd
Write file to user bin folder
File and Directory Permissions Modification
Family: Ladvix
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:DetectGoMethodSignatures
Author:Wyatt Tauber
Description:Detects Go method signatures in unpacked Go binaries
Rule name:Detect_Go_GOMAXPROCS
Author:Obscurity Labs LLC
Description:Detects Go binaries by the presence of runtime.GOMAXPROCS in the runtime metadata
Rule name:F01_s1ckrule
Author:s1ckb017
Rule name:GoBinTest
Rule name:golang
Rule name:golang_binary_string
Description:Golang strings present
Rule name:golang_duffcopy_amd64
Rule name:Golang_Find_CSC846
Author:Ashar Siddiqui
Description:Find Go Signatuers
Rule name:Golang_Find_CSC846_Simple
Author:Ashar Siddiqui
Description:Find Go Signatuers
Rule name:identity_golang
Author:Eric Yocam
Description:find Golang malware
Rule name:ProgramLanguage_Golang
Author:albertzsigovits
Description:Application written in Golang programming language
Rule name:Suspicious_Golang_Binary
Author:Tim Machac
Description:Triage: Golang-compiled binary with suspicious OS/persistence/network strings (not family-specific)
Rule name:TH_Generic_MassHunt_Linux_Malware_2026_CYFARE
Author:CYFARE
Description:Generic Linux malware mass-hunt rule - 2026
Reference:https://cyfare.net/
Rule name:unixredflags3
Author:Tim Brown @timb_machine
Description:Hunts for UNIX red flags

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Ladvix

elf 3b2cbd1dd7e0e78cab544fa6c5b97fa500f092e3c4fbe62adbbbbf1af79564c9

(this sample)

  
Delivery method
Distributed via web download

Comments