MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 526c830542c17e6883da850de8dc2c3c2ffc35b446f33c61892b193e50f8d8ed. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA 14 File information Comments

SHA256 hash: 526c830542c17e6883da850de8dc2c3c2ffc35b446f33c61892b193e50f8d8ed
SHA3-384 hash: a3393b4793cae0984d936d31e54fb0d53d2c4a216cf7640c03042b5649e0db1a0ca26297d50f34c8769f402e2a50dbc1
SHA1 hash: 1c925188b92a927308d8d3175918fd5265efdcde
MD5 hash: e9293ff954fa84237c62f50a5b651744
humanhash: crazy-william-robert-blue
File name:x86_64
Download: download sample
File size:174'377 bytes
First seen:2026-06-25 19:11:37 UTC
Last seen:2026-06-26 09:21:41 UTC
File type: elf
MIME type:application/x-executable
ssdeep 3072:CW/v0uzxl8Z96a7h6v5eJzqySjoGXiQqJvNUGSjsb7syWAYYNuP:C+ZxWt4eJzq45JvNUGSjsb7syWAYYNuP
TLSH T1E3043C0365918AFBC4D68FF91BDB91228533F8391B32620673A8FCA51F4DED86E1D650
telfhash t1be511258943d05d9ef231c1aa8696be35997e13a22e5bb58ff0bddc0084e42df254e0f
TrID 50.1% (.) ELF Executable and Linkable format (Linux) (4022/12)
49.8% (.O) ELF Executable and Linkable format (generic) (4000/1)
Magika elf
Reporter abuse_ch
Tags:elf

Intelligence


File Origin
# of uploads :
7
# of downloads :
59
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Result
Verdict:
Clean
Maliciousness:

Behaviour
Runs as daemon
Sends data to a server
Creating a file in the %temp% directory
Receives data from a server
Connection attempt
Verdict:
Unknown
Threat level:
  0/10
Confidence:
100%
Tags:
gcc
Status:
terminated
Behavior Graph:
%3 guuid=6646a7a5-1e00-0000-5211-3ec537140000 pid=5175 /usr/bin/sudo guuid=700e83aa-1e00-0000-5211-3ec538140000 pid=5176 /tmp/sample.bin guuid=6646a7a5-1e00-0000-5211-3ec537140000 pid=5175->guuid=700e83aa-1e00-0000-5211-3ec538140000 pid=5176 execve guuid=e6d9aaaa-1e00-0000-5211-3ec539140000 pid=5177 /tmp/sample.bin net send-data write-file zombie guuid=700e83aa-1e00-0000-5211-3ec538140000 pid=5176->guuid=e6d9aaaa-1e00-0000-5211-3ec539140000 pid=5177 clone 844ce394-ee6f-5676-8d5f-892f0a6f7d91 51.158.248.123:9001 guuid=e6d9aaaa-1e00-0000-5211-3ec539140000 pid=5177->844ce394-ee6f-5676-8d5f-892f0a6f7d91 send: 4B guuid=e80bb5aa-1e00-0000-5211-3ec53a140000 pid=5178 /tmp/sample.bin net send-data write-file guuid=e6d9aaaa-1e00-0000-5211-3ec539140000 pid=5177->guuid=e80bb5aa-1e00-0000-5211-3ec53a140000 pid=5178 clone guuid=e80bb5aa-1e00-0000-5211-3ec53a140000 pid=5178->844ce394-ee6f-5676-8d5f-892f0a6f7d91 send: 4B
Result
Threat name:
n/a
Detection:
malicious
Classification:
n/a
Score:
64 / 100
Signature
Antivirus / Scanner detection for submitted sample
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
Threat name:
Linux.PUA.Generic
Status:
Suspicious
First seen:
2026-06-25 07:44:18 UTC
File Type:
ELF64 Little (Exe)
AV detection:
12 of 36 (33.33%)
Threat level:
  1/5
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:ELF_Toriilike_persist
Author:4r4
Description:Detects Torii IoT Botnet (stealthier Mirai alternative)
Reference:Identified via researched data
Rule name:Linux_Trojan_Gafgyt_0cd591cd
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_33b4111a
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_620087b9
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_807911a2
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_9e9530a7
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_a33a8363
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_d0c57a2e
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_d4227dbf
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_d996d335
Author:Elastic Security
Rule name:setsockopt
Author:Tim Brown @timb_machine
Description:Hunts for setsockopt() red flags
Rule name:TH_Generic_MassHunt_Linux_Malware_2026_CYFARE
Author:CYFARE
Description:Generic Linux malware mass-hunt rule - 2026
Reference:https://cyfare.net/
Rule name:unixredflags3
Author:Tim Brown @timb_machine
Description:Hunts for UNIX red flags

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

elf 526c830542c17e6883da850de8dc2c3c2ffc35b446f33c61892b193e50f8d8ed

(this sample)

  
Delivery method
Distributed via web download

Comments