MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 5a8cafc1f3f4e565319eafae377e68a5aa9b7c5c0be66c61a543f501dc519ca1. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA 2 File information Comments

SHA256 hash: 5a8cafc1f3f4e565319eafae377e68a5aa9b7c5c0be66c61a543f501dc519ca1
SHA3-384 hash: 4bc62060501e8a0e854424abcff911c82be1eb21facdff65f3f293439670986f0d70f6ba07663fc7c8d9b41866429641
SHA1 hash: e2de1a4f00dc20987e4b9bd5289ca148d1f7dd1e
MD5 hash: 56c25c3250592ec1aff00baf57d355cb
humanhash: enemy-colorado-washington-ohio
File name:systemd-cgroupwatch
Download: download sample
File size:59'562 bytes
First seen:2026-04-28 21:56:46 UTC
Last seen:Never
File type: elf
MIME type:application/x-sharedlib
ssdeep 768:5AZkDA9BLkfC8WeYPM/BBr1RAA/xxeKIycQasFXM/GYxxSRJh9noXo5bJJQfzV:5AG8nY5BZG2xxmLQLS/S7hHnQfzV
TLSH T19D43F7433AD289B5C4C1D770CACFD12AFA20BD51A531BA1E2A08473AAD16B645F1FF17
telfhash t165e0d885fa754e3d8dd381b0dc564ab25197a2164163c7148f91d2c4993e041e208e5b
TrID 50.1% (.) ELF Executable and Linkable format (Linux) (4022/12)
49.8% (.O) ELF Executable and Linkable format (generic) (4000/1)
Magika elf
Reporter BastianHein
Tags:elf

Intelligence


File Origin
# of uploads :
1
# of downloads :
76
Origin country :
CL CL
Vendor Threat Intelligence
No detections
Result
Verdict:
Malware
Maliciousness:

Behaviour
Connection attempt
Kills processes
Sends data to a server
Launching a process
Creating a file in the %temp% directory
Receives data from a server
Manages services
Creating a file
Sets a written file as executable
Runs as daemon
Changes the time when the file was created, accessed, or modified
DNS request
Writes files to system subdirectory
Substitutes an application name
Writes files to system directory
Creates or modifies files in /init.d to set up autorun
Creates or modifies symbolic links in /init.d to set up autorun
Gathering data
Status:
terminated
Behavior Graph:
%3 guuid=bfcefe18-1800-0000-0e75-5407660c0000 pid=3174 /usr/bin/sudo guuid=57bab81a-1800-0000-0e75-5407670c0000 pid=3175 /tmp/sample.bin guuid=bfcefe18-1800-0000-0e75-5407660c0000 pid=3174->guuid=57bab81a-1800-0000-0e75-5407670c0000 pid=3175 execve guuid=3025401b-1800-0000-0e75-5407680c0000 pid=3176 /tmp/sample.bin zombie guuid=57bab81a-1800-0000-0e75-5407670c0000 pid=3175->guuid=3025401b-1800-0000-0e75-5407680c0000 pid=3176 clone guuid=9d6f521b-1800-0000-0e75-5407690c0000 pid=3177 /tmp/sample.bin dns net send-data write-file zombie guuid=3025401b-1800-0000-0e75-5407680c0000 pid=3176->guuid=9d6f521b-1800-0000-0e75-5407690c0000 pid=3177 clone 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=9d6f521b-1800-0000-0e75-5407690c0000 pid=3177->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 74B c2f526bb-1e17-5ff6-8991-28e78c0f77e8 centralcoretech.com:8443 guuid=9d6f521b-1800-0000-0e75-5407690c0000 pid=3177->c2f526bb-1e17-5ff6-8991-28e78c0f77e8 send: 7B guuid=39a7801b-1800-0000-0e75-54076a0c0000 pid=3178 /tmp/sample.bin guuid=9d6f521b-1800-0000-0e75-5407690c0000 pid=3177->guuid=39a7801b-1800-0000-0e75-54076a0c0000 pid=3178 clone guuid=69818d1b-1800-0000-0e75-54076c0c0000 pid=3180 /tmp/sample.bin guuid=9d6f521b-1800-0000-0e75-5407690c0000 pid=3177->guuid=69818d1b-1800-0000-0e75-54076c0c0000 pid=3180 clone guuid=796fec5a-1800-0000-0e75-5407bc0c0000 pid=3260 /tmp/sample.bin guuid=9d6f521b-1800-0000-0e75-5407690c0000 pid=3177->guuid=796fec5a-1800-0000-0e75-5407bc0c0000 pid=3260 clone guuid=6927861b-1800-0000-0e75-54076b0c0000 pid=3179 /tmp/sample.bin write-config write-file zombie guuid=39a7801b-1800-0000-0e75-54076a0c0000 pid=3178->guuid=6927861b-1800-0000-0e75-54076b0c0000 pid=3179 clone guuid=e7833528-1800-0000-0e75-5407750c0000 pid=3189 /usr/bin/dash guuid=6927861b-1800-0000-0e75-54076b0c0000 pid=3179->guuid=e7833528-1800-0000-0e75-5407750c0000 pid=3189 execve guuid=87773a6e-1800-0000-0e75-5407e90c0000 pid=3305 /usr/bin/dash guuid=6927861b-1800-0000-0e75-54076b0c0000 pid=3179->guuid=87773a6e-1800-0000-0e75-5407e90c0000 pid=3305 execve guuid=b0f44871-1800-0000-0e75-5407f90c0000 pid=3321 /usr/bin/dash guuid=6927861b-1800-0000-0e75-54076b0c0000 pid=3179->guuid=b0f44871-1800-0000-0e75-5407f90c0000 pid=3321 execve guuid=f8ffffa4-1800-0000-0e75-54076b0d0000 pid=3435 /usr/bin/dash guuid=6927861b-1800-0000-0e75-54076b0c0000 pid=3179->guuid=f8ffffa4-1800-0000-0e75-54076b0d0000 pid=3435 execve guuid=56898fa7-1800-0000-0e75-54077d0d0000 pid=3453 /usr/bin/dash guuid=6927861b-1800-0000-0e75-54076b0c0000 pid=3179->guuid=56898fa7-1800-0000-0e75-54077d0d0000 pid=3453 execve guuid=018b5dd4-1800-0000-0e75-5407f80d0000 pid=3576 /usr/bin/dash guuid=6927861b-1800-0000-0e75-54076b0c0000 pid=3179->guuid=018b5dd4-1800-0000-0e75-5407f80d0000 pid=3576 execve guuid=bda768dd-1800-0000-0e75-5407110e0000 pid=3601 /usr/bin/dash guuid=6927861b-1800-0000-0e75-54076b0c0000 pid=3179->guuid=bda768dd-1800-0000-0e75-5407110e0000 pid=3601 execve guuid=54094105-1900-0000-0e75-5407930e0000 pid=3731 /usr/bin/dash guuid=6927861b-1800-0000-0e75-54076b0c0000 pid=3179->guuid=54094105-1900-0000-0e75-5407930e0000 pid=3731 execve guuid=f072fd07-1900-0000-0e75-5407a30e0000 pid=3747 /usr/bin/dash guuid=6927861b-1800-0000-0e75-54076b0c0000 pid=3179->guuid=f072fd07-1900-0000-0e75-5407a30e0000 pid=3747 execve guuid=e7cbbb36-1900-0000-0e75-54072b0f0000 pid=3883 /usr/bin/dash guuid=6927861b-1800-0000-0e75-54076b0c0000 pid=3179->guuid=e7cbbb36-1900-0000-0e75-54072b0f0000 pid=3883 execve guuid=ad71c239-1900-0000-0e75-5407450f0000 pid=3909 /usr/bin/dash guuid=6927861b-1800-0000-0e75-54076b0c0000 pid=3179->guuid=ad71c239-1900-0000-0e75-5407450f0000 pid=3909 execve guuid=46cb13be-1900-0000-0e75-540765110000 pid=4453 /usr/bin/dash guuid=6927861b-1800-0000-0e75-54076b0c0000 pid=3179->guuid=46cb13be-1900-0000-0e75-540765110000 pid=4453 execve guuid=557799e4-1900-0000-0e75-5407ff110000 pid=4607 /usr/bin/dash guuid=6927861b-1800-0000-0e75-54076b0c0000 pid=3179->guuid=557799e4-1900-0000-0e75-5407ff110000 pid=4607 execve guuid=06c5f373-1a00-0000-0e75-54072f140000 pid=5167 /usr/bin/dash guuid=6927861b-1800-0000-0e75-54076b0c0000 pid=3179->guuid=06c5f373-1a00-0000-0e75-54072f140000 pid=5167 execve guuid=fbe1849c-1a00-0000-0e75-5407b9140000 pid=5305 /usr/bin/dash guuid=6927861b-1800-0000-0e75-54076b0c0000 pid=3179->guuid=fbe1849c-1a00-0000-0e75-5407b9140000 pid=5305 execve guuid=cebefc1c-1b00-0000-0e75-54071b160000 pid=5659 /usr/bin/dash guuid=6927861b-1800-0000-0e75-54076b0c0000 pid=3179->guuid=cebefc1c-1b00-0000-0e75-54071b160000 pid=5659 execve guuid=6cb6d751-1b00-0000-0e75-54073f160000 pid=5695 /usr/bin/dash guuid=6927861b-1800-0000-0e75-54076b0c0000 pid=3179->guuid=6cb6d751-1b00-0000-0e75-54073f160000 pid=5695 execve guuid=94e775f0-1b00-0000-0e75-540786160000 pid=5766 /usr/bin/dash guuid=6927861b-1800-0000-0e75-54076b0c0000 pid=3179->guuid=94e775f0-1b00-0000-0e75-540786160000 pid=5766 execve guuid=1dc5d05b-1c00-0000-0e75-5407a3160000 pid=5795 /usr/bin/dash guuid=6927861b-1800-0000-0e75-54076b0c0000 pid=3179->guuid=1dc5d05b-1c00-0000-0e75-5407a3160000 pid=5795 execve guuid=30d68e3f-1d00-0000-0e75-5407e8160000 pid=5864 /usr/bin/dash guuid=6927861b-1800-0000-0e75-54076b0c0000 pid=3179->guuid=30d68e3f-1d00-0000-0e75-5407e8160000 pid=5864 execve guuid=b292b76b-1d00-0000-0e75-5407ff160000 pid=5887 /usr/bin/dash guuid=6927861b-1800-0000-0e75-54076b0c0000 pid=3179->guuid=b292b76b-1d00-0000-0e75-5407ff160000 pid=5887 execve guuid=6bd33557-1800-0000-0e75-5407b30c0000 pid=3251 /tmp/sample.bin zombie guuid=69818d1b-1800-0000-0e75-54076c0c0000 pid=3180->guuid=6bd33557-1800-0000-0e75-5407b30c0000 pid=3251 clone guuid=1dea6c28-1800-0000-0e75-5407770c0000 pid=3191 /usr/sbin/update-rc.d guuid=e7833528-1800-0000-0e75-5407750c0000 pid=3189->guuid=1dea6c28-1800-0000-0e75-5407770c0000 pid=3191 execve guuid=dd435f2d-1800-0000-0e75-5407830c0000 pid=3203 /usr/bin/systemctl guuid=1dea6c28-1800-0000-0e75-5407770c0000 pid=3191->guuid=dd435f2d-1800-0000-0e75-5407830c0000 pid=3203 execve guuid=a93e4257-1800-0000-0e75-5407b40c0000 pid=3252 /tmp/sample.bin guuid=6bd33557-1800-0000-0e75-5407b30c0000 pid=3251->guuid=a93e4257-1800-0000-0e75-5407b40c0000 pid=3252 clone guuid=8181f35a-1800-0000-0e75-5407bd0c0000 pid=3261 /tmp/sample.bin dns net send-data zombie guuid=796fec5a-1800-0000-0e75-5407bc0c0000 pid=3260->guuid=8181f35a-1800-0000-0e75-5407bd0c0000 pid=3261 clone guuid=8181f35a-1800-0000-0e75-5407bd0c0000 pid=3261->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 37B guuid=8181f35a-1800-0000-0e75-5407bd0c0000 pid=3261->c2f526bb-1e17-5ff6-8991-28e78c0f77e8 send: 1024B guuid=d74c636e-1800-0000-0e75-5407eb0c0000 pid=3307 /usr/bin/find guuid=87773a6e-1800-0000-0e75-5407e90c0000 pid=3305->guuid=d74c636e-1800-0000-0e75-5407eb0c0000 pid=3307 execve guuid=1295aa6e-1800-0000-0e75-5407ec0c0000 pid=3308 /usr/bin/touch guuid=d74c636e-1800-0000-0e75-5407eb0c0000 pid=3307->guuid=1295aa6e-1800-0000-0e75-5407ec0c0000 pid=3308 execve guuid=d3f5f66e-1800-0000-0e75-5407ed0c0000 pid=3309 /usr/bin/touch guuid=d74c636e-1800-0000-0e75-5407eb0c0000 pid=3307->guuid=d3f5f66e-1800-0000-0e75-5407ed0c0000 pid=3309 execve guuid=fe02786f-1800-0000-0e75-5407f00c0000 pid=3312 /usr/bin/touch guuid=d74c636e-1800-0000-0e75-5407eb0c0000 pid=3307->guuid=fe02786f-1800-0000-0e75-5407f00c0000 pid=3312 execve guuid=ee123170-1800-0000-0e75-5407f20c0000 pid=3314 /usr/bin/touch guuid=d74c636e-1800-0000-0e75-5407eb0c0000 pid=3307->guuid=ee123170-1800-0000-0e75-5407f20c0000 pid=3314 execve guuid=76b18370-1800-0000-0e75-5407f40c0000 pid=3316 /usr/bin/touch guuid=d74c636e-1800-0000-0e75-5407eb0c0000 pid=3307->guuid=76b18370-1800-0000-0e75-5407f40c0000 pid=3316 execve guuid=e519c370-1800-0000-0e75-5407f60c0000 pid=3318 /usr/bin/touch guuid=d74c636e-1800-0000-0e75-5407eb0c0000 pid=3307->guuid=e519c370-1800-0000-0e75-5407f60c0000 pid=3318 execve guuid=fa81fc70-1800-0000-0e75-5407f80c0000 pid=3320 /usr/bin/touch guuid=d74c636e-1800-0000-0e75-5407eb0c0000 pid=3307->guuid=fa81fc70-1800-0000-0e75-5407f80c0000 pid=3320 execve guuid=66277271-1800-0000-0e75-5407fb0c0000 pid=3323 /usr/sbin/update-rc.d guuid=b0f44871-1800-0000-0e75-5407f90c0000 pid=3321->guuid=66277271-1800-0000-0e75-5407fb0c0000 pid=3323 execve guuid=fc46c472-1800-0000-0e75-5407ff0c0000 pid=3327 /usr/bin/systemctl guuid=66277271-1800-0000-0e75-5407fb0c0000 pid=3323->guuid=fc46c472-1800-0000-0e75-5407ff0c0000 pid=3327 execve guuid=f65a2ca5-1800-0000-0e75-54076c0d0000 pid=3436 /usr/bin/find guuid=f8ffffa4-1800-0000-0e75-54076b0d0000 pid=3435->guuid=f65a2ca5-1800-0000-0e75-54076c0d0000 pid=3436 execve guuid=ce237ea5-1800-0000-0e75-54076d0d0000 pid=3437 /usr/bin/touch guuid=f65a2ca5-1800-0000-0e75-54076c0d0000 pid=3436->guuid=ce237ea5-1800-0000-0e75-54076d0d0000 pid=3437 execve guuid=0741b8a5-1800-0000-0e75-54076f0d0000 pid=3439 /usr/bin/touch guuid=f65a2ca5-1800-0000-0e75-54076c0d0000 pid=3436->guuid=0741b8a5-1800-0000-0e75-54076f0d0000 pid=3439 execve guuid=cf53f5a5-1800-0000-0e75-5407710d0000 pid=3441 /usr/bin/touch guuid=f65a2ca5-1800-0000-0e75-54076c0d0000 pid=3436->guuid=cf53f5a5-1800-0000-0e75-5407710d0000 pid=3441 execve guuid=b12036a6-1800-0000-0e75-5407730d0000 pid=3443 /usr/bin/touch guuid=f65a2ca5-1800-0000-0e75-54076c0d0000 pid=3436->guuid=b12036a6-1800-0000-0e75-5407730d0000 pid=3443 execve guuid=3c7d70a6-1800-0000-0e75-5407750d0000 pid=3445 /usr/bin/touch guuid=f65a2ca5-1800-0000-0e75-54076c0d0000 pid=3436->guuid=3c7d70a6-1800-0000-0e75-5407750d0000 pid=3445 execve guuid=214cafa6-1800-0000-0e75-5407770d0000 pid=3447 /usr/bin/touch guuid=f65a2ca5-1800-0000-0e75-54076c0d0000 pid=3436->guuid=214cafa6-1800-0000-0e75-5407770d0000 pid=3447 execve guuid=ca06efa6-1800-0000-0e75-5407790d0000 pid=3449 /usr/bin/touch guuid=f65a2ca5-1800-0000-0e75-54076c0d0000 pid=3436->guuid=ca06efa6-1800-0000-0e75-5407790d0000 pid=3449 execve guuid=d43ed0a7-1800-0000-0e75-54077e0d0000 pid=3454 /usr/sbin/update-rc.d guuid=56898fa7-1800-0000-0e75-54077d0d0000 pid=3453->guuid=d43ed0a7-1800-0000-0e75-54077e0d0000 pid=3454 execve guuid=ecdf23a9-1800-0000-0e75-5407810d0000 pid=3457 /usr/bin/systemctl guuid=d43ed0a7-1800-0000-0e75-54077e0d0000 pid=3454->guuid=ecdf23a9-1800-0000-0e75-5407810d0000 pid=3457 execve guuid=52a8a2d4-1800-0000-0e75-5407fa0d0000 pid=3578 /usr/bin/find guuid=018b5dd4-1800-0000-0e75-5407f80d0000 pid=3576->guuid=52a8a2d4-1800-0000-0e75-5407fa0d0000 pid=3578 execve guuid=bff387d5-1800-0000-0e75-5407fe0d0000 pid=3582 /usr/bin/touch guuid=52a8a2d4-1800-0000-0e75-5407fa0d0000 pid=3578->guuid=bff387d5-1800-0000-0e75-5407fe0d0000 pid=3582 execve guuid=ae4762d6-1800-0000-0e75-5407030e0000 pid=3587 /usr/bin/touch guuid=52a8a2d4-1800-0000-0e75-5407fa0d0000 pid=3578->guuid=ae4762d6-1800-0000-0e75-5407030e0000 pid=3587 execve guuid=da261cd8-1800-0000-0e75-54070a0e0000 pid=3594 /usr/bin/touch guuid=52a8a2d4-1800-0000-0e75-5407fa0d0000 pid=3578->guuid=da261cd8-1800-0000-0e75-54070a0e0000 pid=3594 execve guuid=95c0c2d8-1800-0000-0e75-54070b0e0000 pid=3595 /usr/bin/touch guuid=52a8a2d4-1800-0000-0e75-5407fa0d0000 pid=3578->guuid=95c0c2d8-1800-0000-0e75-54070b0e0000 pid=3595 execve guuid=51b5c7d9-1800-0000-0e75-54070d0e0000 pid=3597 /usr/bin/touch guuid=52a8a2d4-1800-0000-0e75-5407fa0d0000 pid=3578->guuid=51b5c7d9-1800-0000-0e75-54070d0e0000 pid=3597 execve guuid=1682ffda-1800-0000-0e75-54070f0e0000 pid=3599 /usr/bin/touch guuid=52a8a2d4-1800-0000-0e75-5407fa0d0000 pid=3578->guuid=1682ffda-1800-0000-0e75-54070f0e0000 pid=3599 execve guuid=bbcd22dc-1800-0000-0e75-5407100e0000 pid=3600 /usr/bin/touch guuid=52a8a2d4-1800-0000-0e75-5407fa0d0000 pid=3578->guuid=bbcd22dc-1800-0000-0e75-5407100e0000 pid=3600 execve guuid=eb5563de-1800-0000-0e75-5407150e0000 pid=3605 /usr/sbin/update-rc.d guuid=bda768dd-1800-0000-0e75-5407110e0000 pid=3601->guuid=eb5563de-1800-0000-0e75-5407150e0000 pid=3605 execve guuid=fe4e18e0-1800-0000-0e75-54071c0e0000 pid=3612 /usr/bin/systemctl guuid=eb5563de-1800-0000-0e75-5407150e0000 pid=3605->guuid=fe4e18e0-1800-0000-0e75-54071c0e0000 pid=3612 execve guuid=25ef8505-1900-0000-0e75-5407940e0000 pid=3732 /usr/bin/find guuid=54094105-1900-0000-0e75-5407930e0000 pid=3731->guuid=25ef8505-1900-0000-0e75-5407940e0000 pid=3732 execve guuid=43110806-1900-0000-0e75-5407970e0000 pid=3735 /usr/bin/touch guuid=25ef8505-1900-0000-0e75-5407940e0000 pid=3732->guuid=43110806-1900-0000-0e75-5407970e0000 pid=3735 execve guuid=b9ed6d06-1900-0000-0e75-5407980e0000 pid=3736 /usr/bin/touch guuid=25ef8505-1900-0000-0e75-5407940e0000 pid=3732->guuid=b9ed6d06-1900-0000-0e75-5407980e0000 pid=3736 execve guuid=9ce7af06-1900-0000-0e75-54079a0e0000 pid=3738 /usr/bin/touch guuid=25ef8505-1900-0000-0e75-5407940e0000 pid=3732->guuid=9ce7af06-1900-0000-0e75-54079a0e0000 pid=3738 execve guuid=b345ec06-1900-0000-0e75-54079b0e0000 pid=3739 /usr/bin/touch guuid=25ef8505-1900-0000-0e75-5407940e0000 pid=3732->guuid=b345ec06-1900-0000-0e75-54079b0e0000 pid=3739 execve guuid=f0252907-1900-0000-0e75-54079d0e0000 pid=3741 /usr/bin/touch guuid=25ef8505-1900-0000-0e75-5407940e0000 pid=3732->guuid=f0252907-1900-0000-0e75-54079d0e0000 pid=3741 execve guuid=b5356907-1900-0000-0e75-54079f0e0000 pid=3743 /usr/bin/touch guuid=25ef8505-1900-0000-0e75-5407940e0000 pid=3732->guuid=b5356907-1900-0000-0e75-54079f0e0000 pid=3743 execve guuid=c198a407-1900-0000-0e75-5407a10e0000 pid=3745 /usr/bin/touch guuid=25ef8505-1900-0000-0e75-5407940e0000 pid=3732->guuid=c198a407-1900-0000-0e75-5407a10e0000 pid=3745 execve guuid=08e32408-1900-0000-0e75-5407a40e0000 pid=3748 /usr/sbin/update-rc.d guuid=f072fd07-1900-0000-0e75-5407a30e0000 pid=3747->guuid=08e32408-1900-0000-0e75-5407a40e0000 pid=3748 execve guuid=11898009-1900-0000-0e75-5407a80e0000 pid=3752 /usr/bin/systemctl guuid=08e32408-1900-0000-0e75-5407a40e0000 pid=3748->guuid=11898009-1900-0000-0e75-5407a80e0000 pid=3752 execve guuid=112a0837-1900-0000-0e75-54072f0f0000 pid=3887 /usr/bin/find guuid=e7cbbb36-1900-0000-0e75-54072b0f0000 pid=3883->guuid=112a0837-1900-0000-0e75-54072f0f0000 pid=3887 execve guuid=8d629037-1900-0000-0e75-5407330f0000 pid=3891 /usr/bin/touch guuid=112a0837-1900-0000-0e75-54072f0f0000 pid=3887->guuid=8d629037-1900-0000-0e75-5407330f0000 pid=3891 execve guuid=e47c0e38-1900-0000-0e75-5407370f0000 pid=3895 /usr/bin/touch guuid=112a0837-1900-0000-0e75-54072f0f0000 pid=3887->guuid=e47c0e38-1900-0000-0e75-5407370f0000 pid=3895 execve guuid=8c444838-1900-0000-0e75-5407390f0000 pid=3897 /usr/bin/touch guuid=112a0837-1900-0000-0e75-54072f0f0000 pid=3887->guuid=8c444838-1900-0000-0e75-5407390f0000 pid=3897 execve guuid=a4078238-1900-0000-0e75-54073b0f0000 pid=3899 /usr/bin/touch guuid=112a0837-1900-0000-0e75-54072f0f0000 pid=3887->guuid=a4078238-1900-0000-0e75-54073b0f0000 pid=3899 execve guuid=5033bd38-1900-0000-0e75-54073f0f0000 pid=3903 /usr/bin/touch guuid=112a0837-1900-0000-0e75-54072f0f0000 pid=3887->guuid=5033bd38-1900-0000-0e75-54073f0f0000 pid=3903 execve guuid=2faffa38-1900-0000-0e75-5407400f0000 pid=3904 /usr/bin/touch guuid=112a0837-1900-0000-0e75-54072f0f0000 pid=3887->guuid=2faffa38-1900-0000-0e75-5407400f0000 pid=3904 execve guuid=6eb96439-1900-0000-0e75-5407440f0000 pid=3908 /usr/bin/touch guuid=112a0837-1900-0000-0e75-54072f0f0000 pid=3887->guuid=6eb96439-1900-0000-0e75-5407440f0000 pid=3908 execve guuid=bdd5f039-1900-0000-0e75-5407470f0000 pid=3911 /usr/bin/systemctl guuid=ad71c239-1900-0000-0e75-5407450f0000 pid=3909->guuid=bdd5f039-1900-0000-0e75-5407470f0000 pid=3911 execve guuid=1174c03a-1900-0000-0e75-54074c0f0000 pid=3916 /usr/lib/systemd/systemd-sysv-install guuid=bdd5f039-1900-0000-0e75-5407470f0000 pid=3911->guuid=1174c03a-1900-0000-0e75-54074c0f0000 pid=3916 execve guuid=23e41a3b-1900-0000-0e75-5407500f0000 pid=3920 /usr/bin/getopt guuid=1174c03a-1900-0000-0e75-54074c0f0000 pid=3916->guuid=23e41a3b-1900-0000-0e75-5407500f0000 pid=3920 execve guuid=94b15a3b-1900-0000-0e75-5407510f0000 pid=3921 /usr/sbin/update-rc.d guuid=1174c03a-1900-0000-0e75-54074c0f0000 pid=3916->guuid=94b15a3b-1900-0000-0e75-5407510f0000 pid=3921 execve guuid=528ce466-1900-0000-0e75-540701100000 pid=4097 /usr/sbin/update-rc.d guuid=1174c03a-1900-0000-0e75-54074c0f0000 pid=3916->guuid=528ce466-1900-0000-0e75-540701100000 pid=4097 execve guuid=f01d913c-1900-0000-0e75-5407570f0000 pid=3927 /usr/bin/systemctl guuid=94b15a3b-1900-0000-0e75-5407510f0000 pid=3921->guuid=f01d913c-1900-0000-0e75-5407570f0000 pid=3927 execve guuid=23ce0f68-1900-0000-0e75-540707100000 pid=4103 /usr/bin/systemctl guuid=528ce466-1900-0000-0e75-540701100000 pid=4097->guuid=23ce0f68-1900-0000-0e75-540707100000 pid=4103 execve guuid=99695abe-1900-0000-0e75-540766110000 pid=4454 /usr/bin/systemctl guuid=46cb13be-1900-0000-0e75-540765110000 pid=4453->guuid=99695abe-1900-0000-0e75-540766110000 pid=4454 execve guuid=3ed4c4e4-1900-0000-0e75-540701120000 pid=4609 /usr/bin/systemctl guuid=557799e4-1900-0000-0e75-5407ff110000 pid=4607->guuid=3ed4c4e4-1900-0000-0e75-540701120000 pid=4609 execve guuid=4a8f35e6-1900-0000-0e75-54070b120000 pid=4619 /usr/lib/systemd/systemd-sysv-install guuid=3ed4c4e4-1900-0000-0e75-540701120000 pid=4609->guuid=4a8f35e6-1900-0000-0e75-54070b120000 pid=4619 execve guuid=45f19be6-1900-0000-0e75-54070e120000 pid=4622 /usr/bin/getopt guuid=4a8f35e6-1900-0000-0e75-54070b120000 pid=4619->guuid=45f19be6-1900-0000-0e75-54070e120000 pid=4622 execve guuid=582e0be7-1900-0000-0e75-540712120000 pid=4626 /usr/sbin/update-rc.d guuid=4a8f35e6-1900-0000-0e75-54070b120000 pid=4619->guuid=582e0be7-1900-0000-0e75-540712120000 pid=4626 execve guuid=6c71ee16-1a00-0000-0e75-5407bb120000 pid=4795 /usr/sbin/update-rc.d guuid=4a8f35e6-1900-0000-0e75-54070b120000 pid=4619->guuid=6c71ee16-1a00-0000-0e75-5407bb120000 pid=4795 execve guuid=90bf9ee8-1900-0000-0e75-540719120000 pid=4633 /usr/bin/systemctl guuid=582e0be7-1900-0000-0e75-540712120000 pid=4626->guuid=90bf9ee8-1900-0000-0e75-540719120000 pid=4633 execve guuid=6513e318-1a00-0000-0e75-5407c0120000 pid=4800 /usr/bin/systemctl guuid=6c71ee16-1a00-0000-0e75-5407bb120000 pid=4795->guuid=6513e318-1a00-0000-0e75-5407c0120000 pid=4800 execve guuid=cbe71874-1a00-0000-0e75-540730140000 pid=5168 /usr/bin/systemctl guuid=06c5f373-1a00-0000-0e75-54072f140000 pid=5167->guuid=cbe71874-1a00-0000-0e75-540730140000 pid=5168 execve guuid=daafaf9c-1a00-0000-0e75-5407ba140000 pid=5306 /usr/bin/systemctl guuid=fbe1849c-1a00-0000-0e75-5407b9140000 pid=5305->guuid=daafaf9c-1a00-0000-0e75-5407ba140000 pid=5306 execve guuid=5631ab9d-1a00-0000-0e75-5407be140000 pid=5310 /usr/lib/systemd/systemd-sysv-install guuid=daafaf9c-1a00-0000-0e75-5407ba140000 pid=5306->guuid=5631ab9d-1a00-0000-0e75-5407be140000 pid=5310 execve guuid=c0a5f99d-1a00-0000-0e75-5407bf140000 pid=5311 /usr/bin/getopt guuid=5631ab9d-1a00-0000-0e75-5407be140000 pid=5310->guuid=c0a5f99d-1a00-0000-0e75-5407bf140000 pid=5311 execve guuid=8ed0469e-1a00-0000-0e75-5407c1140000 pid=5313 /usr/sbin/update-rc.d guuid=5631ab9d-1a00-0000-0e75-5407be140000 pid=5310->guuid=8ed0469e-1a00-0000-0e75-5407c1140000 pid=5313 execve guuid=c05a79ca-1a00-0000-0e75-540757150000 pid=5463 /usr/sbin/update-rc.d guuid=5631ab9d-1a00-0000-0e75-5407be140000 pid=5310->guuid=c05a79ca-1a00-0000-0e75-540757150000 pid=5463 execve guuid=d57ae39f-1a00-0000-0e75-5407c7140000 pid=5319 /usr/bin/systemctl guuid=8ed0469e-1a00-0000-0e75-5407c1140000 pid=5313->guuid=d57ae39f-1a00-0000-0e75-5407c7140000 pid=5319 execve guuid=c54fcfcb-1a00-0000-0e75-54075d150000 pid=5469 /usr/bin/systemctl guuid=c05a79ca-1a00-0000-0e75-540757150000 pid=5463->guuid=c54fcfcb-1a00-0000-0e75-54075d150000 pid=5469 execve guuid=cfca3c1d-1b00-0000-0e75-54071c160000 pid=5660 /usr/bin/systemctl guuid=cebefc1c-1b00-0000-0e75-54071b160000 pid=5659->guuid=cfca3c1d-1b00-0000-0e75-54071c160000 pid=5660 execve guuid=228d2952-1b00-0000-0e75-540741160000 pid=5697 /usr/bin/systemctl guuid=6cb6d751-1b00-0000-0e75-54073f160000 pid=5695->guuid=228d2952-1b00-0000-0e75-540741160000 pid=5697 execve guuid=22195253-1b00-0000-0e75-540742160000 pid=5698 /usr/lib/systemd/systemd-sysv-install guuid=228d2952-1b00-0000-0e75-540741160000 pid=5697->guuid=22195253-1b00-0000-0e75-540742160000 pid=5698 execve guuid=0dcf8f53-1b00-0000-0e75-540743160000 pid=5699 /usr/bin/getopt guuid=22195253-1b00-0000-0e75-540742160000 pid=5698->guuid=0dcf8f53-1b00-0000-0e75-540743160000 pid=5699 execve guuid=f3eece53-1b00-0000-0e75-540744160000 pid=5700 /usr/sbin/update-rc.d guuid=22195253-1b00-0000-0e75-540742160000 pid=5698->guuid=f3eece53-1b00-0000-0e75-540744160000 pid=5700 execve guuid=d16ebe8e-1b00-0000-0e75-54075c160000 pid=5724 /usr/sbin/update-rc.d guuid=22195253-1b00-0000-0e75-540742160000 pid=5698->guuid=d16ebe8e-1b00-0000-0e75-54075c160000 pid=5724 execve guuid=073f0f55-1b00-0000-0e75-540747160000 pid=5703 /usr/bin/systemctl guuid=f3eece53-1b00-0000-0e75-540744160000 pid=5700->guuid=073f0f55-1b00-0000-0e75-540747160000 pid=5703 execve guuid=9a2a0590-1b00-0000-0e75-54075d160000 pid=5725 /usr/bin/systemctl guuid=d16ebe8e-1b00-0000-0e75-54075c160000 pid=5724->guuid=9a2a0590-1b00-0000-0e75-54075d160000 pid=5725 execve guuid=b1be9ff0-1b00-0000-0e75-540787160000 pid=5767 /usr/bin/systemctl guuid=94e775f0-1b00-0000-0e75-540786160000 pid=5766->guuid=b1be9ff0-1b00-0000-0e75-540787160000 pid=5767 execve guuid=76f1185c-1c00-0000-0e75-5407a4160000 pid=5796 /usr/bin/systemctl guuid=1dc5d05b-1c00-0000-0e75-5407a3160000 pid=5795->guuid=76f1185c-1c00-0000-0e75-5407a4160000 pid=5796 execve guuid=39315e5d-1c00-0000-0e75-5407a5160000 pid=5797 /usr/lib/systemd/systemd-sysv-install guuid=76f1185c-1c00-0000-0e75-5407a4160000 pid=5796->guuid=39315e5d-1c00-0000-0e75-5407a5160000 pid=5797 execve guuid=c0b2775e-1c00-0000-0e75-5407a6160000 pid=5798 /usr/bin/getopt guuid=39315e5d-1c00-0000-0e75-5407a5160000 pid=5797->guuid=c0b2775e-1c00-0000-0e75-5407a6160000 pid=5798 execve guuid=86a81f5f-1c00-0000-0e75-5407a7160000 pid=5799 /usr/sbin/update-rc.d guuid=39315e5d-1c00-0000-0e75-5407a5160000 pid=5797->guuid=86a81f5f-1c00-0000-0e75-5407a7160000 pid=5799 execve guuid=ac1597b0-1c00-0000-0e75-5407bd160000 pid=5821 /usr/sbin/update-rc.d guuid=39315e5d-1c00-0000-0e75-5407a5160000 pid=5797->guuid=ac1597b0-1c00-0000-0e75-5407bd160000 pid=5821 execve guuid=60c2ff61-1c00-0000-0e75-5407a8160000 pid=5800 /usr/bin/systemctl guuid=86a81f5f-1c00-0000-0e75-5407a7160000 pid=5799->guuid=60c2ff61-1c00-0000-0e75-5407a8160000 pid=5800 execve guuid=2515a0b2-1c00-0000-0e75-5407bf160000 pid=5823 /usr/bin/systemctl guuid=ac1597b0-1c00-0000-0e75-5407bd160000 pid=5821->guuid=2515a0b2-1c00-0000-0e75-5407bf160000 pid=5823 execve guuid=b19ebc3f-1d00-0000-0e75-5407e9160000 pid=5865 /usr/bin/systemctl guuid=30d68e3f-1d00-0000-0e75-5407e8160000 pid=5864->guuid=b19ebc3f-1d00-0000-0e75-5407e9160000 pid=5865 execve guuid=2058076c-1d00-0000-0e75-540701170000 pid=5889 /usr/bin/systemctl guuid=b292b76b-1d00-0000-0e75-5407ff160000 pid=5887->guuid=2058076c-1d00-0000-0e75-540701170000 pid=5889 execve
Threat name:
Linux.Trojan.Generic
Status:
Suspicious
First seen:
2026-04-28 21:57:50 UTC
File Type:
ELF64 Little (SO)
AV detection:
4 of 24 (16.67%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
credential_access defense_evasion discovery linux persistence privilege_escalation
Behaviour
Reads runtime system information
Writes file to tmp directory
Changes its process name
Modifies init.d
Modifies systemd
Write file to user bin folder
Modifies PAM framework files
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:setsockopt
Author:Tim Brown @timb_machine
Description:Hunts for setsockopt() red flags
Rule name:unixredflags3
Author:Tim Brown @timb_machine
Description:Hunts for UNIX red flags

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments