MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 402303b0a4e2c959d18d3d9da44794016f389ce812cb23cccc1dfdc04db0796e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA 19 File information Comments

SHA256 hash: 402303b0a4e2c959d18d3d9da44794016f389ce812cb23cccc1dfdc04db0796e
SHA3-384 hash: 287a6daa050a45d8ff6a3a1133443fe40c85c9b93c49b2fe0bf3ecb3b085000cefa797702f8a720f9756829d1bb4026b
SHA1 hash: b8a2b5a1fb927e6c199a1d789409bb1ae9597402
MD5 hash: 6ae809b6081c12026de85f44cfba4b2f
humanhash: apart-mike-beryllium-apart
File name:amd64
Download: download sample
File size:3'473'592 bytes
First seen:2026-04-15 17:52:59 UTC
Last seen:Never
File type: elf
MIME type:application/x-executable
ssdeep 49152:6nLsSR90f2zdSAf2IlpdsteDDHdP5ES3vSEDic/:6LjWuhzcCrl5a6
TLSH T139F54913FCA119A9C0AEA23189669252BB71BC491F3123D73B50F7382F76BD0ADB5714
telfhash t1a2223a754dbd34b4b696da1073a2b4b4a63725a567f838b12063ed90ffc1e801ce2837
gimphash e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
TrID 50.1% (.) ELF Executable and Linkable format (Linux) (4022/12)
49.8% (.O) ELF Executable and Linkable format (generic) (4000/1)
Magika elf
Reporter abuse_ch
Tags:elf

Intelligence


File Origin
# of uploads :
1
# of downloads :
69
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Result
Verdict:
Suspicious
Maliciousness:

Behaviour
Receives data from a server
Sends data to a server
Creating a process from a recently created file
Collects information on the CPU
Collects information on the network activity
Connection attempt
Collects information on the OS
Verdict:
Unknown
Threat level:
  2.5/10
Confidence:
100%
Tags:
anti-vm base64 crypto golang
Verdict:
Malicious
Uses P2P?:
false
Uses anti-vm?:
true
Architecture:
x86
Packer:
not packed
Botnet:
unknown
Number of open files:
4
Number of processes launched:
8
Processes remaning?
false
Remote TCP ports scanned:
not identified
Behaviour
Anti-VM
Botnet C2s
TCP botnet C2(s):
not identified
UDP botnet C2(s):
not identified
Status:
terminated
Behavior Graph:
%3 guuid=7d26ea15-1c00-0000-27e4-17d2a20d0000 pid=3490 /usr/bin/sudo guuid=e127d217-1c00-0000-27e4-17d2a70d0000 pid=3495 /tmp/sample.bin guuid=7d26ea15-1c00-0000-27e4-17d2a20d0000 pid=3490->guuid=e127d217-1c00-0000-27e4-17d2a70d0000 pid=3495 execve guuid=e127d217-1c00-0000-27e4-17d2a70d0000 pid=3503 /tmp/sample.bin guuid=e127d217-1c00-0000-27e4-17d2a70d0000 pid=3495->guuid=e127d217-1c00-0000-27e4-17d2a70d0000 pid=3503 clone guuid=e127d217-1c00-0000-27e4-17d2a70d0000 pid=3504 /tmp/sample.bin guuid=e127d217-1c00-0000-27e4-17d2a70d0000 pid=3495->guuid=e127d217-1c00-0000-27e4-17d2a70d0000 pid=3504 clone guuid=e127d217-1c00-0000-27e4-17d2a70d0000 pid=3505 /tmp/sample.bin guuid=e127d217-1c00-0000-27e4-17d2a70d0000 pid=3495->guuid=e127d217-1c00-0000-27e4-17d2a70d0000 pid=3505 clone guuid=e127d217-1c00-0000-27e4-17d2a70d0000 pid=3506 /tmp/sample.bin guuid=e127d217-1c00-0000-27e4-17d2a70d0000 pid=3495->guuid=e127d217-1c00-0000-27e4-17d2a70d0000 pid=3506 clone guuid=e127d217-1c00-0000-27e4-17d2a70d0000 pid=3507 /tmp/sample.bin guuid=e127d217-1c00-0000-27e4-17d2a70d0000 pid=3495->guuid=e127d217-1c00-0000-27e4-17d2a70d0000 pid=3507 clone guuid=685df21c-1c00-0000-27e4-17d2b40d0000 pid=3508 /tmp/sample.bin guuid=e127d217-1c00-0000-27e4-17d2a70d0000 pid=3495->guuid=685df21c-1c00-0000-27e4-17d2b40d0000 pid=3508 clone guuid=2561fb1c-1c00-0000-27e4-17d2b50d0000 pid=3509 /tmp/sample.bin net send-data zombie guuid=e127d217-1c00-0000-27e4-17d2a70d0000 pid=3495->guuid=2561fb1c-1c00-0000-27e4-17d2b50d0000 pid=3509 execve f2626877-f2c1-50a2-bb19-9d47eb967f88 198.46.216.206:4132 guuid=2561fb1c-1c00-0000-27e4-17d2b50d0000 pid=3509->f2626877-f2c1-50a2-bb19-9d47eb967f88 send: 1059B guuid=2561fb1c-1c00-0000-27e4-17d2b50d0000 pid=3510 /tmp/sample.bin zombie guuid=2561fb1c-1c00-0000-27e4-17d2b50d0000 pid=3509->guuid=2561fb1c-1c00-0000-27e4-17d2b50d0000 pid=3510 clone guuid=2561fb1c-1c00-0000-27e4-17d2b50d0000 pid=3511 /tmp/sample.bin guuid=2561fb1c-1c00-0000-27e4-17d2b50d0000 pid=3509->guuid=2561fb1c-1c00-0000-27e4-17d2b50d0000 pid=3511 clone guuid=2561fb1c-1c00-0000-27e4-17d2b50d0000 pid=3512 /tmp/sample.bin net zombie guuid=2561fb1c-1c00-0000-27e4-17d2b50d0000 pid=3509->guuid=2561fb1c-1c00-0000-27e4-17d2b50d0000 pid=3512 clone guuid=2561fb1c-1c00-0000-27e4-17d2b50d0000 pid=3513 /tmp/sample.bin net send-data zombie guuid=2561fb1c-1c00-0000-27e4-17d2b50d0000 pid=3509->guuid=2561fb1c-1c00-0000-27e4-17d2b50d0000 pid=3513 clone guuid=2561fb1c-1c00-0000-27e4-17d2b50d0000 pid=3568 /tmp/sample.bin guuid=2561fb1c-1c00-0000-27e4-17d2b50d0000 pid=3509->guuid=2561fb1c-1c00-0000-27e4-17d2b50d0000 pid=3568 clone 51475a40-5531-5652-88be-7dda12342b64 8.8.8.8:80 guuid=2561fb1c-1c00-0000-27e4-17d2b50d0000 pid=3512->51475a40-5531-5652-88be-7dda12342b64 con guuid=020ffc29-1c00-0000-27e4-17d2d10d0000 pid=3537 /tmp/sample.bin guuid=2561fb1c-1c00-0000-27e4-17d2b50d0000 pid=3512->guuid=020ffc29-1c00-0000-27e4-17d2d10d0000 pid=3537 clone guuid=1385012a-1c00-0000-27e4-17d2d20d0000 pid=3538 /usr/bin/lsb_release guuid=2561fb1c-1c00-0000-27e4-17d2b50d0000 pid=3512->guuid=1385012a-1c00-0000-27e4-17d2d20d0000 pid=3538 execve guuid=2561fb1c-1c00-0000-27e4-17d2b50d0000 pid=3513->f2626877-f2c1-50a2-bb19-9d47eb967f88 send: 417B guuid=2561fb1c-1c00-0000-27e4-17d2b50d0000 pid=3513->51475a40-5531-5652-88be-7dda12342b64 con guuid=d39b9431-1c00-0000-27e4-17d2f20d0000 pid=3570 /usr/bin/lsb_release guuid=2561fb1c-1c00-0000-27e4-17d2b50d0000 pid=3513->guuid=d39b9431-1c00-0000-27e4-17d2f20d0000 pid=3570 execve guuid=8fca83d8-2700-0000-27e4-17d2c9140000 pid=5321 /usr/bin/lsb_release guuid=2561fb1c-1c00-0000-27e4-17d2b50d0000 pid=3513->guuid=8fca83d8-2700-0000-27e4-17d2c9140000 pid=5321 execve guuid=f3e52a2a-1c00-0000-27e4-17d2d30d0000 pid=3539 /usr/bin/getopt guuid=1385012a-1c00-0000-27e4-17d2d20d0000 pid=3538->guuid=f3e52a2a-1c00-0000-27e4-17d2d30d0000 pid=3539 execve guuid=785a952a-1c00-0000-27e4-17d2d50d0000 pid=3541 /usr/bin/dash guuid=1385012a-1c00-0000-27e4-17d2d20d0000 pid=3538->guuid=785a952a-1c00-0000-27e4-17d2d50d0000 pid=3541 clone guuid=72432a2b-1c00-0000-27e4-17d2db0d0000 pid=3547 /usr/bin/dash guuid=1385012a-1c00-0000-27e4-17d2d20d0000 pid=3538->guuid=72432a2b-1c00-0000-27e4-17d2db0d0000 pid=3547 clone guuid=fad68f2b-1c00-0000-27e4-17d2df0d0000 pid=3551 /usr/bin/dash guuid=1385012a-1c00-0000-27e4-17d2d20d0000 pid=3538->guuid=fad68f2b-1c00-0000-27e4-17d2df0d0000 pid=3551 clone guuid=eb77f32b-1c00-0000-27e4-17d2e40d0000 pid=3556 /usr/bin/dash guuid=1385012a-1c00-0000-27e4-17d2d20d0000 pid=3538->guuid=eb77f32b-1c00-0000-27e4-17d2e40d0000 pid=3556 clone guuid=d89c9f2a-1c00-0000-27e4-17d2d60d0000 pid=3542 /usr/bin/dash guuid=785a952a-1c00-0000-27e4-17d2d50d0000 pid=3541->guuid=d89c9f2a-1c00-0000-27e4-17d2d60d0000 pid=3542 clone guuid=505ba82a-1c00-0000-27e4-17d2d80d0000 pid=3544 /usr/bin/cut guuid=785a952a-1c00-0000-27e4-17d2d50d0000 pid=3541->guuid=505ba82a-1c00-0000-27e4-17d2d80d0000 pid=3544 execve guuid=a291ae2a-1c00-0000-27e4-17d2d90d0000 pid=3545 /usr/bin/tr guuid=785a952a-1c00-0000-27e4-17d2d50d0000 pid=3541->guuid=a291ae2a-1c00-0000-27e4-17d2d90d0000 pid=3545 execve guuid=13f03a2b-1c00-0000-27e4-17d2dc0d0000 pid=3548 /usr/bin/dash guuid=72432a2b-1c00-0000-27e4-17d2db0d0000 pid=3547->guuid=13f03a2b-1c00-0000-27e4-17d2dc0d0000 pid=3548 clone guuid=b02a432b-1c00-0000-27e4-17d2dd0d0000 pid=3549 /usr/bin/cut guuid=72432a2b-1c00-0000-27e4-17d2db0d0000 pid=3547->guuid=b02a432b-1c00-0000-27e4-17d2dd0d0000 pid=3549 execve guuid=dd12982b-1c00-0000-27e4-17d2e00d0000 pid=3552 /usr/bin/dash guuid=fad68f2b-1c00-0000-27e4-17d2df0d0000 pid=3551->guuid=dd12982b-1c00-0000-27e4-17d2e00d0000 pid=3552 clone guuid=9a60a02b-1c00-0000-27e4-17d2e10d0000 pid=3553 /usr/bin/tr guuid=fad68f2b-1c00-0000-27e4-17d2df0d0000 pid=3551->guuid=9a60a02b-1c00-0000-27e4-17d2e10d0000 pid=3553 execve guuid=2db4fb2b-1c00-0000-27e4-17d2e50d0000 pid=3557 /usr/bin/dash guuid=eb77f32b-1c00-0000-27e4-17d2e40d0000 pid=3556->guuid=2db4fb2b-1c00-0000-27e4-17d2e50d0000 pid=3557 clone guuid=a40d022c-1c00-0000-27e4-17d2e60d0000 pid=3558 /usr/bin/tr guuid=eb77f32b-1c00-0000-27e4-17d2e40d0000 pid=3556->guuid=a40d022c-1c00-0000-27e4-17d2e60d0000 pid=3558 execve guuid=ad03da31-1c00-0000-27e4-17d2f30d0000 pid=3571 /usr/bin/getopt guuid=d39b9431-1c00-0000-27e4-17d2f20d0000 pid=3570->guuid=ad03da31-1c00-0000-27e4-17d2f30d0000 pid=3571 execve guuid=c87c5032-1c00-0000-27e4-17d2f60d0000 pid=3574 /usr/bin/dash guuid=d39b9431-1c00-0000-27e4-17d2f20d0000 pid=3570->guuid=c87c5032-1c00-0000-27e4-17d2f60d0000 pid=3574 clone guuid=4524da32-1c00-0000-27e4-17d2fb0d0000 pid=3579 /usr/bin/dash guuid=d39b9431-1c00-0000-27e4-17d2f20d0000 pid=3570->guuid=4524da32-1c00-0000-27e4-17d2fb0d0000 pid=3579 clone guuid=13733133-1c00-0000-27e4-17d2ff0d0000 pid=3583 /usr/bin/dash guuid=d39b9431-1c00-0000-27e4-17d2f20d0000 pid=3570->guuid=13733133-1c00-0000-27e4-17d2ff0d0000 pid=3583 clone guuid=345e8b33-1c00-0000-27e4-17d2030e0000 pid=3587 /usr/bin/dash guuid=d39b9431-1c00-0000-27e4-17d2f20d0000 pid=3570->guuid=345e8b33-1c00-0000-27e4-17d2030e0000 pid=3587 clone guuid=ed885c32-1c00-0000-27e4-17d2f70d0000 pid=3575 /usr/bin/dash guuid=c87c5032-1c00-0000-27e4-17d2f60d0000 pid=3574->guuid=ed885c32-1c00-0000-27e4-17d2f70d0000 pid=3575 clone guuid=824b6832-1c00-0000-27e4-17d2f80d0000 pid=3576 /usr/bin/cut guuid=c87c5032-1c00-0000-27e4-17d2f60d0000 pid=3574->guuid=824b6832-1c00-0000-27e4-17d2f80d0000 pid=3576 execve guuid=4c497132-1c00-0000-27e4-17d2f90d0000 pid=3577 /usr/bin/tr guuid=c87c5032-1c00-0000-27e4-17d2f60d0000 pid=3574->guuid=4c497132-1c00-0000-27e4-17d2f90d0000 pid=3577 execve guuid=6161e232-1c00-0000-27e4-17d2fc0d0000 pid=3580 /usr/bin/dash guuid=4524da32-1c00-0000-27e4-17d2fb0d0000 pid=3579->guuid=6161e232-1c00-0000-27e4-17d2fc0d0000 pid=3580 clone guuid=90fbe832-1c00-0000-27e4-17d2fe0d0000 pid=3582 /usr/bin/cut guuid=4524da32-1c00-0000-27e4-17d2fb0d0000 pid=3579->guuid=90fbe832-1c00-0000-27e4-17d2fe0d0000 pid=3582 execve guuid=b1893833-1c00-0000-27e4-17d2010e0000 pid=3585 /usr/bin/dash guuid=13733133-1c00-0000-27e4-17d2ff0d0000 pid=3583->guuid=b1893833-1c00-0000-27e4-17d2010e0000 pid=3585 clone guuid=a0494533-1c00-0000-27e4-17d2020e0000 pid=3586 /usr/bin/tr guuid=13733133-1c00-0000-27e4-17d2ff0d0000 pid=3583->guuid=a0494533-1c00-0000-27e4-17d2020e0000 pid=3586 execve guuid=5c299933-1c00-0000-27e4-17d2050e0000 pid=3589 /usr/bin/dash guuid=345e8b33-1c00-0000-27e4-17d2030e0000 pid=3587->guuid=5c299933-1c00-0000-27e4-17d2050e0000 pid=3589 clone guuid=ad27a133-1c00-0000-27e4-17d2060e0000 pid=3590 /usr/bin/tr guuid=345e8b33-1c00-0000-27e4-17d2030e0000 pid=3587->guuid=ad27a133-1c00-0000-27e4-17d2060e0000 pid=3590 execve guuid=b8b8b2d8-2700-0000-27e4-17d2ca140000 pid=5322 /usr/bin/getopt guuid=8fca83d8-2700-0000-27e4-17d2c9140000 pid=5321->guuid=b8b8b2d8-2700-0000-27e4-17d2ca140000 pid=5322 execve guuid=f52041d9-2700-0000-27e4-17d2cb140000 pid=5323 /usr/bin/dash guuid=8fca83d8-2700-0000-27e4-17d2c9140000 pid=5321->guuid=f52041d9-2700-0000-27e4-17d2cb140000 pid=5323 clone guuid=e681a3d9-2700-0000-27e4-17d2cf140000 pid=5327 /usr/bin/dash guuid=8fca83d8-2700-0000-27e4-17d2c9140000 pid=5321->guuid=e681a3d9-2700-0000-27e4-17d2cf140000 pid=5327 clone guuid=263262da-2700-0000-27e4-17d2d2140000 pid=5330 /usr/bin/dash guuid=8fca83d8-2700-0000-27e4-17d2c9140000 pid=5321->guuid=263262da-2700-0000-27e4-17d2d2140000 pid=5330 clone guuid=66fbc4da-2700-0000-27e4-17d2d5140000 pid=5333 /usr/bin/dash guuid=8fca83d8-2700-0000-27e4-17d2c9140000 pid=5321->guuid=66fbc4da-2700-0000-27e4-17d2d5140000 pid=5333 clone guuid=83ee48d9-2700-0000-27e4-17d2cc140000 pid=5324 /usr/bin/dash guuid=f52041d9-2700-0000-27e4-17d2cb140000 pid=5323->guuid=83ee48d9-2700-0000-27e4-17d2cc140000 pid=5324 clone guuid=d43653d9-2700-0000-27e4-17d2cd140000 pid=5325 /usr/bin/cut guuid=f52041d9-2700-0000-27e4-17d2cb140000 pid=5323->guuid=d43653d9-2700-0000-27e4-17d2cd140000 pid=5325 execve guuid=086859d9-2700-0000-27e4-17d2ce140000 pid=5326 /usr/bin/tr guuid=f52041d9-2700-0000-27e4-17d2cb140000 pid=5323->guuid=086859d9-2700-0000-27e4-17d2ce140000 pid=5326 execve guuid=f233add9-2700-0000-27e4-17d2d0140000 pid=5328 /usr/bin/dash guuid=e681a3d9-2700-0000-27e4-17d2cf140000 pid=5327->guuid=f233add9-2700-0000-27e4-17d2d0140000 pid=5328 clone guuid=a0c4b4d9-2700-0000-27e4-17d2d1140000 pid=5329 /usr/bin/cut guuid=e681a3d9-2700-0000-27e4-17d2cf140000 pid=5327->guuid=a0c4b4d9-2700-0000-27e4-17d2d1140000 pid=5329 execve guuid=985a6fda-2700-0000-27e4-17d2d3140000 pid=5331 /usr/bin/dash guuid=263262da-2700-0000-27e4-17d2d2140000 pid=5330->guuid=985a6fda-2700-0000-27e4-17d2d3140000 pid=5331 clone guuid=420976da-2700-0000-27e4-17d2d4140000 pid=5332 /usr/bin/tr guuid=263262da-2700-0000-27e4-17d2d2140000 pid=5330->guuid=420976da-2700-0000-27e4-17d2d4140000 pid=5332 execve guuid=ad44d0da-2700-0000-27e4-17d2d6140000 pid=5334 /usr/bin/dash guuid=66fbc4da-2700-0000-27e4-17d2d5140000 pid=5333->guuid=ad44d0da-2700-0000-27e4-17d2d6140000 pid=5334 clone guuid=1af3d5da-2700-0000-27e4-17d2d7140000 pid=5335 /usr/bin/tr guuid=66fbc4da-2700-0000-27e4-17d2d5140000 pid=5333->guuid=1af3d5da-2700-0000-27e4-17d2d7140000 pid=5335 execve
Result
Threat name:
n/a
Detection:
clean
Classification:
n/a
Score:
2 / 100
Behaviour
Behavior Graph:
n/a
Threat name:
Linux.Trojan.Generic
Status:
Suspicious
First seen:
2026-04-15 17:53:59 UTC
File Type:
ELF64 Little (Exe)
AV detection:
4 of 37 (10.81%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  6/10
Tags:
antivm defense_evasion discovery linux
Behaviour
Enumerates kernel/hardware configuration
Reads runtime system information
Checks CPU configuration
Reads CPU attributes
Reads hardware information
Reads list of loaded kernel modules
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:DetectGoMethodSignatures
Author:Wyatt Tauber
Description:Detects Go method signatures in unpacked Go binaries
Rule name:Detect_Go_GOMAXPROCS
Author:Obscurity Labs LLC
Description:Detects Go binaries by the presence of runtime.GOMAXPROCS in the runtime metadata
Rule name:enterpriseapps2
Author:Tim Brown @timb_machine
Description:Enterprise apps
Rule name:F01_s1ckrule
Author:s1ckb017
Rule name:GoBinTest
Rule name:golang
Rule name:golang_binary_string
Description:Golang strings present
Rule name:golang_duffcopy_amd64
Rule name:Golang_Find_CSC846
Author:Ashar Siddiqui
Description:Find Go Signatuers
Rule name:Golang_Find_CSC846_Simple
Author:Ashar Siddiqui
Description:Find Go Signatuers
Rule name:identity_golang
Author:Eric Yocam
Description:find Golang malware
Rule name:ProgramLanguage_Golang
Author:albertzsigovits
Description:Application written in Golang programming language
Rule name:RANSOMWARE
Author:ToroGuitar
Rule name:setsockopt
Author:Tim Brown @timb_machine
Description:Hunts for setsockopt() red flags
Rule name:SHA512_Constants
Author:phoul (@phoul)
Description:Look for SHA384/SHA512 constants
Rule name:TH_Generic_MassHunt_Linux_Malware_2026_CYFARE
Author:CYFARE
Description:Generic Linux malware mass-hunt rule - 2026
Reference:https://cyfare.net/
Rule name:unixredflags3
Author:Tim Brown @timb_machine
Description:Hunts for UNIX red flags
Rule name:vmdetect
Author:nex
Description:Possibly employs anti-virtualization techniques

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

elf 402303b0a4e2c959d18d3d9da44794016f389ce812cb23cccc1dfdc04db0796e

(this sample)

  
Delivery method
Distributed via web download

Comments