MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 3b378846bc429fdf9bec08b9635885267d8d269f6d941ab1d6e526a03304331b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 3b378846bc429fdf9bec08b9635885267d8d269f6d941ab1d6e526a03304331b
SHA3-384 hash: efbcea9f0ba30d20d9c3e241e9e8ca2d12f44af3c3054dc211ba43e06c39634d004c657caf93d118fb486cc327655568
SHA1 hash: b97640a0de61d575b119b63a74b70d9f613f6123
MD5 hash: 1acb326773d6ba28d916871cb91af844
humanhash: london-hot-bulldog-oxygen
File name:3b378846bc429fdf9bec08b9635885267d8d269f6d941ab1d6e526a03304331b.elf
Download: download sample
File size:24'576 bytes
First seen:2021-01-07 00:26:22 UTC
Last seen:Never
File type: elf
MIME type:application/x-sharedlib
ssdeep 384:hBb5y9mJiD1gh8MOFgnUOS0/P087x2nJ8L6i594HgDJxj97c5:hBb5yQMRghEgC8L6IeEnc5
TLSH 3EB2B467B1E2CABDE0D6B63CB5CB91F6F2B0F8E45B27910B125116352E12EC00F4E596
telfhash f8e02608da1b1a18a9f92531d4ee8731a416216bab5a7f108ff9d4d0066951f317a61c
Reporter Arkbird_SOLG
Tags:apt AzazelFork elf rootkit Winnti


Avatar
ArkbirdDevil
Winnti rootkit based on the fork of Azazel rootkit

Intelligence


File Origin
# of uploads :
1
# of downloads :
307
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
MALICIOUS
Threat name:
Linux.Backdoor.WinNti
Status:
Malicious
First seen:
2021-01-05 18:25:27 UTC
AV detection:
19 of 46 (41.30%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
linux
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

  
Delivery method
Other

Comments