MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 5b15dcff5b4960235476057ddb138c7b2539bd253be814100fd2e36215fcdc61. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA 20 File information Comments

SHA256 hash: 5b15dcff5b4960235476057ddb138c7b2539bd253be814100fd2e36215fcdc61
SHA3-384 hash: 061fc9bf01ccd9fe13a3d7cd491d6b3d4e726ab04374ef2d1e8ab8ff5122dc13873afc8f98e155278d98df1e9ac34a58
SHA1 hash: 060888d2aa87367da7eab9154c298a48839b1f36
MD5 hash: 01ca29c105774bd2416945b8203d8a2d
humanhash: eighteen-ink-georgia-arizona
File name:linux_amd64
Download: download sample
File size:5'275'648 bytes
First seen:2026-04-04 15:00:48 UTC
Last seen:2026-04-04 16:42:06 UTC
File type: elf
MIME type:application/x-executable
ssdeep 49152:sWJtAgZD0rb/TivO90d7HjmAFd4A64nsfJm+pskbwNIjdzmZZgeg8htzRBFjUhxd:5JX8mLRhXjwEvM0Y
TLSH T131364C57F85151F8E1BEE270C5565223F6703C881F3223E72B01F2E52A36BD49A797A8
telfhash t163427d7049bc34b5b2aac911f3a3b5b4953728a566fc34b45063ad85ffc1e812ce6837
gimphash e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
TrID 50.1% (.) ELF Executable and Linkable format (Linux) (4022/12)
49.8% (.O) ELF Executable and Linkable format (generic) (4000/1)
Magika elf
Reporter abuse_ch
Tags:elf

Intelligence


File Origin
# of uploads :
2
# of downloads :
34
Origin country :
DE DE
Vendor Threat Intelligence
Gathering data
Result
Verdict:
Malware
Maliciousness:

Behaviour
Changes the time when the file was created, accessed, or modified
Unmounts file systems
Manages services
Creates directories
Receives data from a server
Collects information on the OS
Sends data to a server
Deleting a recently created file
Launching a process
Connection attempt
Creating a file
Changes access rights for a written file
Mounts file systems
Runs as daemon
Creating a process from a recently created file
Creating a file in the %temp% directory
Writes files to system directory
Creates or modifies files in /cron to set up autorun
Deletes a system binary file
Substitutes an application name
Creates or modifies symbolic links in /init.d to set up autorun
Creates or modifies files in /init.d to set up autorun
Creates or modifies files to set up autorun
Verdict:
Malicious
Uses P2P?:
false
Uses anti-vm?:
false
Architecture:
x86
Packer:
not packed
Botnet:
unknown
Number of open files:
2
Number of processes launched:
4
Processes remaning?
false
Remote TCP ports scanned:
not identified
Behaviour
no suspicious findings
Botnet C2s
TCP botnet C2(s):
not identified
UDP botnet C2(s):
not identified
Result
Gathering data
Status:
terminated
Behavior Graph:
%3 guuid=96493d71-1500-0000-ba49-82c6150c0000 pid=3093 /usr/bin/sudo guuid=67439473-1500-0000-ba49-82c61a0c0000 pid=3098 /tmp/sample.bin guuid=96493d71-1500-0000-ba49-82c6150c0000 pid=3093->guuid=67439473-1500-0000-ba49-82c61a0c0000 pid=3098 execve guuid=67439473-1500-0000-ba49-82c61a0c0000 pid=3110 /tmp/sample.bin guuid=67439473-1500-0000-ba49-82c61a0c0000 pid=3098->guuid=67439473-1500-0000-ba49-82c61a0c0000 pid=3110 clone guuid=67439473-1500-0000-ba49-82c61a0c0000 pid=3111 /tmp/sample.bin guuid=67439473-1500-0000-ba49-82c61a0c0000 pid=3098->guuid=67439473-1500-0000-ba49-82c61a0c0000 pid=3111 clone guuid=67439473-1500-0000-ba49-82c61a0c0000 pid=3112 /tmp/sample.bin guuid=67439473-1500-0000-ba49-82c61a0c0000 pid=3098->guuid=67439473-1500-0000-ba49-82c61a0c0000 pid=3112 clone guuid=67439473-1500-0000-ba49-82c61a0c0000 pid=3114 /tmp/sample.bin guuid=67439473-1500-0000-ba49-82c61a0c0000 pid=3098->guuid=67439473-1500-0000-ba49-82c61a0c0000 pid=3114 clone guuid=467e1178-1500-0000-ba49-82c62c0c0000 pid=3116 /tmp/sample.bin delete-file dns net send-data write-file zombie guuid=67439473-1500-0000-ba49-82c61a0c0000 pid=3098->guuid=467e1178-1500-0000-ba49-82c62c0c0000 pid=3116 execve 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=467e1178-1500-0000-ba49-82c62c0c0000 pid=3116->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 38B 1587f3f2-bbce-5218-958c-1dc50cb35907 ak.504.su:28588 guuid=467e1178-1500-0000-ba49-82c62c0c0000 pid=3116->1587f3f2-bbce-5218-958c-1dc50cb35907 send: 237B guuid=467e1178-1500-0000-ba49-82c62c0c0000 pid=3119 /tmp/sample.bin zombie guuid=467e1178-1500-0000-ba49-82c62c0c0000 pid=3116->guuid=467e1178-1500-0000-ba49-82c62c0c0000 pid=3119 clone guuid=467e1178-1500-0000-ba49-82c62c0c0000 pid=3120 /tmp/sample.bin net send-data zombie guuid=467e1178-1500-0000-ba49-82c62c0c0000 pid=3116->guuid=467e1178-1500-0000-ba49-82c62c0c0000 pid=3120 clone guuid=467e1178-1500-0000-ba49-82c62c0c0000 pid=3121 /tmp/sample.bin delete-file dns net send-data write-config write-file zombie guuid=467e1178-1500-0000-ba49-82c62c0c0000 pid=3116->guuid=467e1178-1500-0000-ba49-82c62c0c0000 pid=3121 clone guuid=467e1178-1500-0000-ba49-82c62c0c0000 pid=3122 /tmp/sample.bin guuid=467e1178-1500-0000-ba49-82c62c0c0000 pid=3116->guuid=467e1178-1500-0000-ba49-82c62c0c0000 pid=3122 clone guuid=467e1178-1500-0000-ba49-82c62c0c0000 pid=3137 /tmp/sample.bin delete-file dns net send-data write-config write-file zombie guuid=467e1178-1500-0000-ba49-82c62c0c0000 pid=3116->guuid=467e1178-1500-0000-ba49-82c62c0c0000 pid=3137 clone guuid=467e1178-1500-0000-ba49-82c62c0c0000 pid=3138 /tmp/sample.bin net send-data zombie guuid=467e1178-1500-0000-ba49-82c62c0c0000 pid=3116->guuid=467e1178-1500-0000-ba49-82c62c0c0000 pid=3138 clone guuid=467e1178-1500-0000-ba49-82c62c0c0000 pid=3120->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 38B guuid=467e1178-1500-0000-ba49-82c62c0c0000 pid=3120->1587f3f2-bbce-5218-958c-1dc50cb35907 send: 237B guuid=467e1178-1500-0000-ba49-82c62c0c0000 pid=3121->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 76B guuid=467e1178-1500-0000-ba49-82c62c0c0000 pid=3121->1587f3f2-bbce-5218-958c-1dc50cb35907 send: 1088B guuid=8aef97e7-1d00-0000-ba49-82c6a6150000 pid=5542 /usr/bin/systemctl guuid=467e1178-1500-0000-ba49-82c62c0c0000 pid=3121->guuid=8aef97e7-1d00-0000-ba49-82c6a6150000 pid=5542 execve guuid=2822f102-1e00-0000-ba49-82c6bb150000 pid=5563 /usr/bin/systemctl guuid=467e1178-1500-0000-ba49-82c62c0c0000 pid=3121->guuid=2822f102-1e00-0000-ba49-82c6bb150000 pid=5563 execve guuid=6398601e-1e00-0000-ba49-82c6d0150000 pid=5584 /usr/bin/systemctl guuid=467e1178-1500-0000-ba49-82c62c0c0000 pid=3121->guuid=6398601e-1e00-0000-ba49-82c6d0150000 pid=5584 execve guuid=467e1178-1500-0000-ba49-82c62c0c0000 pid=3137->1587f3f2-bbce-5218-958c-1dc50cb35907 send: 43B guuid=30481990-1500-0000-ba49-82c6650c0000 pid=3173 /usr/bin/dash guuid=467e1178-1500-0000-ba49-82c62c0c0000 pid=3137->guuid=30481990-1500-0000-ba49-82c6650c0000 pid=3173 execve guuid=8213a790-1500-0000-ba49-82c6670c0000 pid=3175 /usr/bin/systemctl guuid=467e1178-1500-0000-ba49-82c62c0c0000 pid=3137->guuid=8213a790-1500-0000-ba49-82c6670c0000 pid=3175 execve guuid=ab9ee0c6-1500-0000-ba49-82c6a50c0000 pid=3237 /usr/bin/systemctl guuid=467e1178-1500-0000-ba49-82c62c0c0000 pid=3137->guuid=ab9ee0c6-1500-0000-ba49-82c6a50c0000 pid=3237 execve guuid=852a8bf9-1500-0000-ba49-82c60f0d0000 pid=3343 /usr/bin/systemctl guuid=467e1178-1500-0000-ba49-82c62c0c0000 pid=3137->guuid=852a8bf9-1500-0000-ba49-82c60f0d0000 pid=3343 execve guuid=2c1f4002-1600-0000-ba49-82c6310d0000 pid=3377 /usr/sbin/update-rc.d guuid=467e1178-1500-0000-ba49-82c62c0c0000 pid=3137->guuid=2c1f4002-1600-0000-ba49-82c6310d0000 pid=3377 execve guuid=a048122d-1600-0000-ba49-82c6af0d0000 pid=3503 /usr/sbin/update-rc.d guuid=467e1178-1500-0000-ba49-82c62c0c0000 pid=3137->guuid=a048122d-1600-0000-ba49-82c6af0d0000 pid=3503 execve guuid=2bd0ba5e-1600-0000-ba49-82c64d0e0000 pid=3661 /etc/init.d/systemd-logind guuid=467e1178-1500-0000-ba49-82c62c0c0000 pid=3137->guuid=2bd0ba5e-1600-0000-ba49-82c64d0e0000 pid=3661 execve guuid=eebc3d6d-1600-0000-ba49-82c6770e0000 pid=3703 /usr/bin/dash guuid=467e1178-1500-0000-ba49-82c62c0c0000 pid=3137->guuid=eebc3d6d-1600-0000-ba49-82c6770e0000 pid=3703 execve guuid=0224866d-1600-0000-ba49-82c67a0e0000 pid=3706 /usr/sbin/update-rc.d guuid=467e1178-1500-0000-ba49-82c62c0c0000 pid=3137->guuid=0224866d-1600-0000-ba49-82c67a0e0000 pid=3706 execve guuid=5cd40a9f-1600-0000-ba49-82c6fe0e0000 pid=3838 /usr/sbin/update-rc.d guuid=467e1178-1500-0000-ba49-82c62c0c0000 pid=3137->guuid=5cd40a9f-1600-0000-ba49-82c6fe0e0000 pid=3838 execve guuid=90c1f6cc-1600-0000-ba49-82c6ac0f0000 pid=4012 /etc/init.d/network-manger guuid=467e1178-1500-0000-ba49-82c62c0c0000 pid=3137->guuid=90c1f6cc-1600-0000-ba49-82c6ac0f0000 pid=4012 execve guuid=09aeb4d2-1600-0000-ba49-82c6ca0f0000 pid=4042 /usr/bin/dash guuid=467e1178-1500-0000-ba49-82c62c0c0000 pid=3137->guuid=09aeb4d2-1600-0000-ba49-82c6ca0f0000 pid=4042 execve guuid=fb22f0d2-1600-0000-ba49-82c6cd0f0000 pid=4045 /usr/sbin/update-rc.d guuid=467e1178-1500-0000-ba49-82c62c0c0000 pid=3137->guuid=fb22f0d2-1600-0000-ba49-82c6cd0f0000 pid=4045 execve guuid=7a1ddefc-1600-0000-ba49-82c680100000 pid=4224 /usr/sbin/update-rc.d guuid=467e1178-1500-0000-ba49-82c62c0c0000 pid=3137->guuid=7a1ddefc-1600-0000-ba49-82c680100000 pid=4224 execve guuid=86f3fd2d-1700-0000-ba49-82c63e110000 pid=4414 /etc/init.d/udev-teriger-net guuid=467e1178-1500-0000-ba49-82c62c0c0000 pid=3137->guuid=86f3fd2d-1700-0000-ba49-82c63e110000 pid=4414 execve guuid=3bf6f530-1700-0000-ba49-82c64f110000 pid=4431 /usr/bin/dash guuid=467e1178-1500-0000-ba49-82c62c0c0000 pid=3137->guuid=3bf6f530-1700-0000-ba49-82c64f110000 pid=4431 execve guuid=467e1178-1500-0000-ba49-82c62c0c0000 pid=3138->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 76B guuid=467e1178-1500-0000-ba49-82c62c0c0000 pid=3138->1587f3f2-bbce-5218-958c-1dc50cb35907 send: 43B guuid=e6f1b1b5-1500-0000-ba49-82c6a40c0000 pid=3236 /usr/bin/uname guuid=467e1178-1500-0000-ba49-82c62c0c0000 pid=3138->guuid=e6f1b1b5-1500-0000-ba49-82c6a40c0000 pid=3236 execve guuid=444c8790-1500-0000-ba49-82c6660c0000 pid=3174 /boot/System zombie guuid=30481990-1500-0000-ba49-82c6650c0000 pid=3173->guuid=444c8790-1500-0000-ba49-82c6660c0000 pid=3174 execve guuid=1ca6db90-1500-0000-ba49-82c6690c0000 pid=3177 /usr/bin/sleep guuid=444c8790-1500-0000-ba49-82c6660c0000 pid=3174->guuid=1ca6db90-1500-0000-ba49-82c6690c0000 pid=3177 execve guuid=71cc9ae1-1e00-0000-ba49-82c6d6150000 pid=5590 /boot/System.img-6.8.0-8 delete-file write-file guuid=444c8790-1500-0000-ba49-82c6660c0000 pid=3174->guuid=71cc9ae1-1e00-0000-ba49-82c6d6150000 pid=5590 execve guuid=31483ee3-1e00-0000-ba49-82c6db150000 pid=5595 /usr/bin/sleep guuid=444c8790-1500-0000-ba49-82c6660c0000 pid=3174->guuid=31483ee3-1e00-0000-ba49-82c6db150000 pid=5595 execve guuid=2fdaba13-0000-0000-ba49-82c601000000 pid=1 /usr/lib/systemd/systemd guuid=1765f8fa-1500-0000-ba49-82c6140d0000 pid=3348 /boot/System.img-6.8.0-8 guuid=2fdaba13-0000-0000-ba49-82c601000000 pid=1->guuid=1765f8fa-1500-0000-ba49-82c6140d0000 pid=3348 execve guuid=af9c845b-1800-0000-ba49-82c6db140000 pid=5339 /boot/System.img-6.8.0-8 guuid=2fdaba13-0000-0000-ba49-82c601000000 pid=1->guuid=af9c845b-1800-0000-ba49-82c6db140000 pid=5339 execve guuid=ff47a0be-1a00-0000-ba49-82c690150000 pid=5520 /boot/System.img-6.8.0-8 guuid=2fdaba13-0000-0000-ba49-82c601000000 pid=1->guuid=ff47a0be-1a00-0000-ba49-82c690150000 pid=5520 execve guuid=083c5321-1d00-0000-ba49-82c69a150000 pid=5530 /boot/System.img-6.8.0-8 guuid=2fdaba13-0000-0000-ba49-82c601000000 pid=1->guuid=083c5321-1d00-0000-ba49-82c69a150000 pid=5530 execve guuid=fe7c1184-1f00-0000-ba49-82c6dc150000 pid=5596 /boot/System.img-6.8.0-8 guuid=2fdaba13-0000-0000-ba49-82c601000000 pid=1->guuid=fe7c1184-1f00-0000-ba49-82c6dc150000 pid=5596 execve guuid=24b86be7-2100-0000-ba49-82c6e8150000 pid=5608 /boot/System.img-6.8.0-8 guuid=2fdaba13-0000-0000-ba49-82c601000000 pid=1->guuid=24b86be7-2100-0000-ba49-82c6e8150000 pid=5608 execve guuid=1765f8fa-1500-0000-ba49-82c6140d0000 pid=3364 /boot/System.img-6.8.0-8 guuid=1765f8fa-1500-0000-ba49-82c6140d0000 pid=3348->guuid=1765f8fa-1500-0000-ba49-82c6140d0000 pid=3364 clone guuid=1765f8fa-1500-0000-ba49-82c6140d0000 pid=3365 /boot/System.img-6.8.0-8 guuid=1765f8fa-1500-0000-ba49-82c6140d0000 pid=3348->guuid=1765f8fa-1500-0000-ba49-82c6140d0000 pid=3365 clone guuid=1765f8fa-1500-0000-ba49-82c6140d0000 pid=3366 /boot/System.img-6.8.0-8 guuid=1765f8fa-1500-0000-ba49-82c6140d0000 pid=3348->guuid=1765f8fa-1500-0000-ba49-82c6140d0000 pid=3366 clone guuid=1765f8fa-1500-0000-ba49-82c6140d0000 pid=3367 /boot/System.img-6.8.0-8 guuid=1765f8fa-1500-0000-ba49-82c6140d0000 pid=3348->guuid=1765f8fa-1500-0000-ba49-82c6140d0000 pid=3367 clone guuid=1765f8fa-1500-0000-ba49-82c6140d0000 pid=3369 /boot/System.img-6.8.0-8 guuid=1765f8fa-1500-0000-ba49-82c6140d0000 pid=3348->guuid=1765f8fa-1500-0000-ba49-82c6140d0000 pid=3369 clone guuid=30790601-1600-0000-ba49-82c62a0d0000 pid=3370 /boot/System.img-6.8.0-8 delete-file write-file zombie guuid=1765f8fa-1500-0000-ba49-82c6140d0000 pid=3367->guuid=30790601-1600-0000-ba49-82c62a0d0000 pid=3370 execve guuid=30790601-1600-0000-ba49-82c62a0d0000 pid=3372 /boot/System.img-6.8.0-8 guuid=30790601-1600-0000-ba49-82c62a0d0000 pid=3370->guuid=30790601-1600-0000-ba49-82c62a0d0000 pid=3372 clone guuid=30790601-1600-0000-ba49-82c62a0d0000 pid=3373 /boot/System.img-6.8.0-8 guuid=30790601-1600-0000-ba49-82c62a0d0000 pid=3370->guuid=30790601-1600-0000-ba49-82c62a0d0000 pid=3373 clone guuid=30790601-1600-0000-ba49-82c62a0d0000 pid=3374 /boot/System.img-6.8.0-8 guuid=30790601-1600-0000-ba49-82c62a0d0000 pid=3370->guuid=30790601-1600-0000-ba49-82c62a0d0000 pid=3374 clone guuid=30790601-1600-0000-ba49-82c62a0d0000 pid=3375 /boot/System.img-6.8.0-8 guuid=30790601-1600-0000-ba49-82c62a0d0000 pid=3370->guuid=30790601-1600-0000-ba49-82c62a0d0000 pid=3375 clone guuid=1c7a5504-1600-0000-ba49-82c6380d0000 pid=3384 /usr/bin/systemctl guuid=2c1f4002-1600-0000-ba49-82c6310d0000 pid=3377->guuid=1c7a5504-1600-0000-ba49-82c6380d0000 pid=3384 execve guuid=2b3df72e-1600-0000-ba49-82c6b70d0000 pid=3511 /usr/bin/systemctl guuid=a048122d-1600-0000-ba49-82c6af0d0000 pid=3503->guuid=2b3df72e-1600-0000-ba49-82c6b70d0000 pid=3511 execve guuid=16a1ea2f-1600-0000-ba49-82c6bb0d0000 pid=3515 /usr/bin/systemctl guuid=a048122d-1600-0000-ba49-82c6af0d0000 pid=3503->guuid=16a1ea2f-1600-0000-ba49-82c6bb0d0000 pid=3515 execve guuid=8e7b325f-1600-0000-ba49-82c64f0e0000 pid=3663 /boot/System.img-6.8.0-8 delete-file write-file guuid=2bd0ba5e-1600-0000-ba49-82c64d0e0000 pid=3661->guuid=8e7b325f-1600-0000-ba49-82c64f0e0000 pid=3663 execve guuid=8e7b325f-1600-0000-ba49-82c64f0e0000 pid=3673 /boot/System.img-6.8.0-8 guuid=8e7b325f-1600-0000-ba49-82c64f0e0000 pid=3663->guuid=8e7b325f-1600-0000-ba49-82c64f0e0000 pid=3673 clone guuid=8e7b325f-1600-0000-ba49-82c64f0e0000 pid=3674 /boot/System.img-6.8.0-8 guuid=8e7b325f-1600-0000-ba49-82c64f0e0000 pid=3663->guuid=8e7b325f-1600-0000-ba49-82c64f0e0000 pid=3674 clone guuid=8e7b325f-1600-0000-ba49-82c64f0e0000 pid=3675 /boot/System.img-6.8.0-8 guuid=8e7b325f-1600-0000-ba49-82c64f0e0000 pid=3663->guuid=8e7b325f-1600-0000-ba49-82c64f0e0000 pid=3675 clone guuid=8e7b325f-1600-0000-ba49-82c64f0e0000 pid=3676 /boot/System.img-6.8.0-8 guuid=8e7b325f-1600-0000-ba49-82c64f0e0000 pid=3663->guuid=8e7b325f-1600-0000-ba49-82c64f0e0000 pid=3676 clone guuid=1aab6b6d-1600-0000-ba49-82c6790e0000 pid=3705 /usr/bin/killai zombie guuid=eebc3d6d-1600-0000-ba49-82c6770e0000 pid=3703->guuid=1aab6b6d-1600-0000-ba49-82c6790e0000 pid=3705 execve guuid=2a03a66d-1600-0000-ba49-82c67b0e0000 pid=3707 /usr/bin/sleep guuid=1aab6b6d-1600-0000-ba49-82c6790e0000 pid=3705->guuid=2a03a66d-1600-0000-ba49-82c67b0e0000 pid=3707 execve guuid=455d5812-2200-0000-ba49-82c6f4150000 pid=5620 /usr/local/sbin/nginx-1 delete-file write-file guuid=1aab6b6d-1600-0000-ba49-82c6790e0000 pid=3705->guuid=455d5812-2200-0000-ba49-82c6f4150000 pid=5620 execve guuid=a012a326-2200-0000-ba49-82c6fa150000 pid=5626 /usr/bin/sleep guuid=1aab6b6d-1600-0000-ba49-82c6790e0000 pid=3705->guuid=a012a326-2200-0000-ba49-82c6fa150000 pid=5626 execve guuid=86364770-1600-0000-ba49-82c6810e0000 pid=3713 /usr/bin/systemctl guuid=0224866d-1600-0000-ba49-82c67a0e0000 pid=3706->guuid=86364770-1600-0000-ba49-82c6810e0000 pid=3713 execve guuid=16daeba0-1600-0000-ba49-82c6090f0000 pid=3849 /usr/bin/systemctl guuid=5cd40a9f-1600-0000-ba49-82c6fe0e0000 pid=3838->guuid=16daeba0-1600-0000-ba49-82c6090f0000 pid=3849 execve guuid=2a4dcba1-1600-0000-ba49-82c60f0f0000 pid=3855 /usr/bin/systemctl guuid=5cd40a9f-1600-0000-ba49-82c6fe0e0000 pid=3838->guuid=2a4dcba1-1600-0000-ba49-82c60f0f0000 pid=3855 execve guuid=946758cd-1600-0000-ba49-82c6ae0f0000 pid=4014 /usr/local/sbin/nginx-1 delete-file write-file guuid=90c1f6cc-1600-0000-ba49-82c6ac0f0000 pid=4012->guuid=946758cd-1600-0000-ba49-82c6ae0f0000 pid=4014 execve guuid=946758cd-1600-0000-ba49-82c6ae0f0000 pid=4031 /usr/local/sbin/nginx-1 guuid=946758cd-1600-0000-ba49-82c6ae0f0000 pid=4014->guuid=946758cd-1600-0000-ba49-82c6ae0f0000 pid=4031 clone guuid=946758cd-1600-0000-ba49-82c6ae0f0000 pid=4032 /usr/local/sbin/nginx-1 guuid=946758cd-1600-0000-ba49-82c6ae0f0000 pid=4014->guuid=946758cd-1600-0000-ba49-82c6ae0f0000 pid=4032 clone guuid=946758cd-1600-0000-ba49-82c6ae0f0000 pid=4033 /usr/local/sbin/nginx-1 guuid=946758cd-1600-0000-ba49-82c6ae0f0000 pid=4014->guuid=946758cd-1600-0000-ba49-82c6ae0f0000 pid=4033 clone guuid=946758cd-1600-0000-ba49-82c6ae0f0000 pid=4034 /usr/local/sbin/nginx-1 guuid=946758cd-1600-0000-ba49-82c6ae0f0000 pid=4014->guuid=946758cd-1600-0000-ba49-82c6ae0f0000 pid=4034 clone guuid=381ad9d2-1600-0000-ba49-82c6cb0f0000 pid=4043 /usr/sbin/.at.atloy zombie guuid=09aeb4d2-1600-0000-ba49-82c6ca0f0000 pid=4042->guuid=381ad9d2-1600-0000-ba49-82c6cb0f0000 pid=4043 execve guuid=600f5cd3-1600-0000-ba49-82c6cf0f0000 pid=4047 /usr/bin/sleep guuid=381ad9d2-1600-0000-ba49-82c6cb0f0000 pid=4043->guuid=600f5cd3-1600-0000-ba49-82c6cf0f0000 pid=4047 execve guuid=36ea46d4-1600-0000-ba49-82c6d60f0000 pid=4054 /usr/bin/systemctl guuid=fb22f0d2-1600-0000-ba49-82c6cd0f0000 pid=4045->guuid=36ea46d4-1600-0000-ba49-82c6d60f0000 pid=4054 execve guuid=07a773fe-1600-0000-ba49-82c688100000 pid=4232 /usr/bin/systemctl guuid=7a1ddefc-1600-0000-ba49-82c680100000 pid=4224->guuid=07a773fe-1600-0000-ba49-82c688100000 pid=4232 execve guuid=d0686c02-1700-0000-ba49-82c698100000 pid=4248 /usr/bin/systemctl guuid=7a1ddefc-1600-0000-ba49-82c680100000 pid=4224->guuid=d0686c02-1700-0000-ba49-82c698100000 pid=4248 execve guuid=93422a2e-1700-0000-ba49-82c63f110000 pid=4415 /usr/lib/id.sericer.conf delete-file write-file guuid=86f3fd2d-1700-0000-ba49-82c63e110000 pid=4414->guuid=93422a2e-1700-0000-ba49-82c63f110000 pid=4415 execve guuid=93422a2e-1700-0000-ba49-82c63f110000 pid=4416 /usr/lib/id.sericer.conf guuid=93422a2e-1700-0000-ba49-82c63f110000 pid=4415->guuid=93422a2e-1700-0000-ba49-82c63f110000 pid=4416 clone guuid=93422a2e-1700-0000-ba49-82c63f110000 pid=4417 /usr/lib/id.sericer.conf guuid=93422a2e-1700-0000-ba49-82c63f110000 pid=4415->guuid=93422a2e-1700-0000-ba49-82c63f110000 pid=4417 clone guuid=93422a2e-1700-0000-ba49-82c63f110000 pid=4418 /usr/lib/id.sericer.conf guuid=93422a2e-1700-0000-ba49-82c63f110000 pid=4415->guuid=93422a2e-1700-0000-ba49-82c63f110000 pid=4418 clone guuid=93422a2e-1700-0000-ba49-82c63f110000 pid=4419 /usr/lib/id.sericer.conf guuid=93422a2e-1700-0000-ba49-82c63f110000 pid=4415->guuid=93422a2e-1700-0000-ba49-82c63f110000 pid=4419 clone guuid=b6e64c31-1700-0000-ba49-82c650110000 pid=4432 /tmp/.font-unix-helpver zombie guuid=3bf6f530-1700-0000-ba49-82c64f110000 pid=4431->guuid=b6e64c31-1700-0000-ba49-82c650110000 pid=4432 execve guuid=15137931-1700-0000-ba49-82c652110000 pid=4434 /usr/bin/sleep guuid=b6e64c31-1700-0000-ba49-82c650110000 pid=4432->guuid=15137931-1700-0000-ba49-82c652110000 pid=4434 execve guuid=af9c845b-1800-0000-ba49-82c6db140000 pid=5355 /boot/System.img-6.8.0-8 guuid=af9c845b-1800-0000-ba49-82c6db140000 pid=5339->guuid=af9c845b-1800-0000-ba49-82c6db140000 pid=5355 clone guuid=af9c845b-1800-0000-ba49-82c6db140000 pid=5356 /boot/System.img-6.8.0-8 guuid=af9c845b-1800-0000-ba49-82c6db140000 pid=5339->guuid=af9c845b-1800-0000-ba49-82c6db140000 pid=5356 clone guuid=af9c845b-1800-0000-ba49-82c6db140000 pid=5358 /boot/System.img-6.8.0-8 guuid=af9c845b-1800-0000-ba49-82c6db140000 pid=5339->guuid=af9c845b-1800-0000-ba49-82c6db140000 pid=5358 clone guuid=af9c845b-1800-0000-ba49-82c6db140000 pid=5359 /boot/System.img-6.8.0-8 guuid=af9c845b-1800-0000-ba49-82c6db140000 pid=5339->guuid=af9c845b-1800-0000-ba49-82c6db140000 pid=5359 clone guuid=af9c845b-1800-0000-ba49-82c6db140000 pid=5360 /boot/System.img-6.8.0-8 guuid=af9c845b-1800-0000-ba49-82c6db140000 pid=5339->guuid=af9c845b-1800-0000-ba49-82c6db140000 pid=5360 clone guuid=cec4f061-1800-0000-ba49-82c6f1140000 pid=5361 /boot/System.img-6.8.0-8 delete-file write-file zombie guuid=af9c845b-1800-0000-ba49-82c6db140000 pid=5339->guuid=cec4f061-1800-0000-ba49-82c6f1140000 pid=5361 execve guuid=cec4f061-1800-0000-ba49-82c6f1140000 pid=5367 /boot/System.img-6.8.0-8 guuid=cec4f061-1800-0000-ba49-82c6f1140000 pid=5361->guuid=cec4f061-1800-0000-ba49-82c6f1140000 pid=5367 clone guuid=cec4f061-1800-0000-ba49-82c6f1140000 pid=5368 /boot/System.img-6.8.0-8 guuid=cec4f061-1800-0000-ba49-82c6f1140000 pid=5361->guuid=cec4f061-1800-0000-ba49-82c6f1140000 pid=5368 clone guuid=cec4f061-1800-0000-ba49-82c6f1140000 pid=5369 /boot/System.img-6.8.0-8 guuid=cec4f061-1800-0000-ba49-82c6f1140000 pid=5361->guuid=cec4f061-1800-0000-ba49-82c6f1140000 pid=5369 clone guuid=cec4f061-1800-0000-ba49-82c6f1140000 pid=5370 /boot/System.img-6.8.0-8 guuid=cec4f061-1800-0000-ba49-82c6f1140000 pid=5361->guuid=cec4f061-1800-0000-ba49-82c6f1140000 pid=5370 clone guuid=ff47a0be-1a00-0000-ba49-82c690150000 pid=5521 /boot/System.img-6.8.0-8 guuid=ff47a0be-1a00-0000-ba49-82c690150000 pid=5520->guuid=ff47a0be-1a00-0000-ba49-82c690150000 pid=5521 clone guuid=ff47a0be-1a00-0000-ba49-82c690150000 pid=5522 /boot/System.img-6.8.0-8 guuid=ff47a0be-1a00-0000-ba49-82c690150000 pid=5520->guuid=ff47a0be-1a00-0000-ba49-82c690150000 pid=5522 clone guuid=ff47a0be-1a00-0000-ba49-82c690150000 pid=5523 /boot/System.img-6.8.0-8 guuid=ff47a0be-1a00-0000-ba49-82c690150000 pid=5520->guuid=ff47a0be-1a00-0000-ba49-82c690150000 pid=5523 clone guuid=ff47a0be-1a00-0000-ba49-82c690150000 pid=5524 /boot/System.img-6.8.0-8 guuid=ff47a0be-1a00-0000-ba49-82c690150000 pid=5520->guuid=ff47a0be-1a00-0000-ba49-82c690150000 pid=5524 clone guuid=003f98c1-1a00-0000-ba49-82c695150000 pid=5525 /boot/System.img-6.8.0-8 delete-file write-file zombie guuid=ff47a0be-1a00-0000-ba49-82c690150000 pid=5520->guuid=003f98c1-1a00-0000-ba49-82c695150000 pid=5525 execve guuid=003f98c1-1a00-0000-ba49-82c695150000 pid=5526 /boot/System.img-6.8.0-8 zombie guuid=003f98c1-1a00-0000-ba49-82c695150000 pid=5525->guuid=003f98c1-1a00-0000-ba49-82c695150000 pid=5526 clone guuid=003f98c1-1a00-0000-ba49-82c695150000 pid=5527 /boot/System.img-6.8.0-8 guuid=003f98c1-1a00-0000-ba49-82c695150000 pid=5525->guuid=003f98c1-1a00-0000-ba49-82c695150000 pid=5527 clone guuid=003f98c1-1a00-0000-ba49-82c695150000 pid=5528 /boot/System.img-6.8.0-8 guuid=003f98c1-1a00-0000-ba49-82c695150000 pid=5525->guuid=003f98c1-1a00-0000-ba49-82c695150000 pid=5528 clone guuid=003f98c1-1a00-0000-ba49-82c695150000 pid=5529 /boot/System.img-6.8.0-8 guuid=003f98c1-1a00-0000-ba49-82c695150000 pid=5525->guuid=003f98c1-1a00-0000-ba49-82c695150000 pid=5529 clone guuid=083c5321-1d00-0000-ba49-82c69a150000 pid=5531 /boot/System.img-6.8.0-8 guuid=083c5321-1d00-0000-ba49-82c69a150000 pid=5530->guuid=083c5321-1d00-0000-ba49-82c69a150000 pid=5531 clone guuid=083c5321-1d00-0000-ba49-82c69a150000 pid=5532 /boot/System.img-6.8.0-8 guuid=083c5321-1d00-0000-ba49-82c69a150000 pid=5530->guuid=083c5321-1d00-0000-ba49-82c69a150000 pid=5532 clone guuid=083c5321-1d00-0000-ba49-82c69a150000 pid=5533 /boot/System.img-6.8.0-8 guuid=083c5321-1d00-0000-ba49-82c69a150000 pid=5530->guuid=083c5321-1d00-0000-ba49-82c69a150000 pid=5533 clone guuid=083c5321-1d00-0000-ba49-82c69a150000 pid=5534 /boot/System.img-6.8.0-8 guuid=083c5321-1d00-0000-ba49-82c69a150000 pid=5530->guuid=083c5321-1d00-0000-ba49-82c69a150000 pid=5534 clone guuid=083c5321-1d00-0000-ba49-82c69a150000 pid=5535 /boot/System.img-6.8.0-8 guuid=083c5321-1d00-0000-ba49-82c69a150000 pid=5530->guuid=083c5321-1d00-0000-ba49-82c69a150000 pid=5535 clone guuid=bd227a24-1d00-0000-ba49-82c6a0150000 pid=5536 /boot/System.img-6.8.0-8 delete-file write-file zombie guuid=083c5321-1d00-0000-ba49-82c69a150000 pid=5530->guuid=bd227a24-1d00-0000-ba49-82c6a0150000 pid=5536 execve guuid=bd227a24-1d00-0000-ba49-82c6a0150000 pid=5537 /boot/System.img-6.8.0-8 guuid=bd227a24-1d00-0000-ba49-82c6a0150000 pid=5536->guuid=bd227a24-1d00-0000-ba49-82c6a0150000 pid=5537 clone guuid=bd227a24-1d00-0000-ba49-82c6a0150000 pid=5538 /boot/System.img-6.8.0-8 guuid=bd227a24-1d00-0000-ba49-82c6a0150000 pid=5536->guuid=bd227a24-1d00-0000-ba49-82c6a0150000 pid=5538 clone guuid=bd227a24-1d00-0000-ba49-82c6a0150000 pid=5539 /boot/System.img-6.8.0-8 guuid=bd227a24-1d00-0000-ba49-82c6a0150000 pid=5536->guuid=bd227a24-1d00-0000-ba49-82c6a0150000 pid=5539 clone guuid=bd227a24-1d00-0000-ba49-82c6a0150000 pid=5540 /boot/System.img-6.8.0-8 guuid=bd227a24-1d00-0000-ba49-82c6a0150000 pid=5536->guuid=bd227a24-1d00-0000-ba49-82c6a0150000 pid=5540 clone guuid=bd227a24-1d00-0000-ba49-82c6a0150000 pid=5541 /boot/System.img-6.8.0-8 guuid=bd227a24-1d00-0000-ba49-82c6a0150000 pid=5536->guuid=bd227a24-1d00-0000-ba49-82c6a0150000 pid=5541 clone guuid=71cc9ae1-1e00-0000-ba49-82c6d6150000 pid=5591 /boot/System.img-6.8.0-8 guuid=71cc9ae1-1e00-0000-ba49-82c6d6150000 pid=5590->guuid=71cc9ae1-1e00-0000-ba49-82c6d6150000 pid=5591 clone guuid=71cc9ae1-1e00-0000-ba49-82c6d6150000 pid=5592 /boot/System.img-6.8.0-8 guuid=71cc9ae1-1e00-0000-ba49-82c6d6150000 pid=5590->guuid=71cc9ae1-1e00-0000-ba49-82c6d6150000 pid=5592 clone guuid=71cc9ae1-1e00-0000-ba49-82c6d6150000 pid=5593 /boot/System.img-6.8.0-8 guuid=71cc9ae1-1e00-0000-ba49-82c6d6150000 pid=5590->guuid=71cc9ae1-1e00-0000-ba49-82c6d6150000 pid=5593 clone guuid=71cc9ae1-1e00-0000-ba49-82c6d6150000 pid=5594 /boot/System.img-6.8.0-8 guuid=71cc9ae1-1e00-0000-ba49-82c6d6150000 pid=5590->guuid=71cc9ae1-1e00-0000-ba49-82c6d6150000 pid=5594 clone guuid=fe7c1184-1f00-0000-ba49-82c6dc150000 pid=5597 /boot/System.img-6.8.0-8 guuid=fe7c1184-1f00-0000-ba49-82c6dc150000 pid=5596->guuid=fe7c1184-1f00-0000-ba49-82c6dc150000 pid=5597 clone guuid=fe7c1184-1f00-0000-ba49-82c6dc150000 pid=5598 /boot/System.img-6.8.0-8 guuid=fe7c1184-1f00-0000-ba49-82c6dc150000 pid=5596->guuid=fe7c1184-1f00-0000-ba49-82c6dc150000 pid=5598 clone guuid=fe7c1184-1f00-0000-ba49-82c6dc150000 pid=5599 /boot/System.img-6.8.0-8 guuid=fe7c1184-1f00-0000-ba49-82c6dc150000 pid=5596->guuid=fe7c1184-1f00-0000-ba49-82c6dc150000 pid=5599 clone guuid=fe7c1184-1f00-0000-ba49-82c6dc150000 pid=5600 /boot/System.img-6.8.0-8 guuid=fe7c1184-1f00-0000-ba49-82c6dc150000 pid=5596->guuid=fe7c1184-1f00-0000-ba49-82c6dc150000 pid=5600 clone guuid=fe7c1184-1f00-0000-ba49-82c6dc150000 pid=5601 /boot/System.img-6.8.0-8 guuid=fe7c1184-1f00-0000-ba49-82c6dc150000 pid=5596->guuid=fe7c1184-1f00-0000-ba49-82c6dc150000 pid=5601 clone guuid=5026c886-1f00-0000-ba49-82c6e2150000 pid=5602 /boot/System.img-6.8.0-8 delete-file write-file zombie guuid=fe7c1184-1f00-0000-ba49-82c6dc150000 pid=5596->guuid=5026c886-1f00-0000-ba49-82c6e2150000 pid=5602 execve guuid=5026c886-1f00-0000-ba49-82c6e2150000 pid=5603 /boot/System.img-6.8.0-8 zombie guuid=5026c886-1f00-0000-ba49-82c6e2150000 pid=5602->guuid=5026c886-1f00-0000-ba49-82c6e2150000 pid=5603 clone guuid=5026c886-1f00-0000-ba49-82c6e2150000 pid=5604 /boot/System.img-6.8.0-8 guuid=5026c886-1f00-0000-ba49-82c6e2150000 pid=5602->guuid=5026c886-1f00-0000-ba49-82c6e2150000 pid=5604 clone guuid=5026c886-1f00-0000-ba49-82c6e2150000 pid=5605 /boot/System.img-6.8.0-8 guuid=5026c886-1f00-0000-ba49-82c6e2150000 pid=5602->guuid=5026c886-1f00-0000-ba49-82c6e2150000 pid=5605 clone guuid=5026c886-1f00-0000-ba49-82c6e2150000 pid=5606 /boot/System.img-6.8.0-8 guuid=5026c886-1f00-0000-ba49-82c6e2150000 pid=5602->guuid=5026c886-1f00-0000-ba49-82c6e2150000 pid=5606 clone guuid=5026c886-1f00-0000-ba49-82c6e2150000 pid=5607 /boot/System.img-6.8.0-8 guuid=5026c886-1f00-0000-ba49-82c6e2150000 pid=5602->guuid=5026c886-1f00-0000-ba49-82c6e2150000 pid=5607 clone guuid=24b86be7-2100-0000-ba49-82c6e8150000 pid=5609 /boot/System.img-6.8.0-8 guuid=24b86be7-2100-0000-ba49-82c6e8150000 pid=5608->guuid=24b86be7-2100-0000-ba49-82c6e8150000 pid=5609 clone guuid=24b86be7-2100-0000-ba49-82c6e8150000 pid=5610 /boot/System.img-6.8.0-8 guuid=24b86be7-2100-0000-ba49-82c6e8150000 pid=5608->guuid=24b86be7-2100-0000-ba49-82c6e8150000 pid=5610 clone guuid=24b86be7-2100-0000-ba49-82c6e8150000 pid=5611 /boot/System.img-6.8.0-8 guuid=24b86be7-2100-0000-ba49-82c6e8150000 pid=5608->guuid=24b86be7-2100-0000-ba49-82c6e8150000 pid=5611 clone guuid=24b86be7-2100-0000-ba49-82c6e8150000 pid=5612 /boot/System.img-6.8.0-8 guuid=24b86be7-2100-0000-ba49-82c6e8150000 pid=5608->guuid=24b86be7-2100-0000-ba49-82c6e8150000 pid=5612 clone guuid=24b86be7-2100-0000-ba49-82c6e8150000 pid=5613 /boot/System.img-6.8.0-8 guuid=24b86be7-2100-0000-ba49-82c6e8150000 pid=5608->guuid=24b86be7-2100-0000-ba49-82c6e8150000 pid=5613 clone guuid=f21681eb-2100-0000-ba49-82c6ee150000 pid=5614 /boot/System.img-6.8.0-8 delete-file write-file zombie guuid=24b86be7-2100-0000-ba49-82c6e8150000 pid=5608->guuid=f21681eb-2100-0000-ba49-82c6ee150000 pid=5614 execve guuid=f21681eb-2100-0000-ba49-82c6ee150000 pid=5615 /boot/System.img-6.8.0-8 zombie guuid=f21681eb-2100-0000-ba49-82c6ee150000 pid=5614->guuid=f21681eb-2100-0000-ba49-82c6ee150000 pid=5615 clone guuid=f21681eb-2100-0000-ba49-82c6ee150000 pid=5616 /boot/System.img-6.8.0-8 guuid=f21681eb-2100-0000-ba49-82c6ee150000 pid=5614->guuid=f21681eb-2100-0000-ba49-82c6ee150000 pid=5616 clone guuid=f21681eb-2100-0000-ba49-82c6ee150000 pid=5617 /boot/System.img-6.8.0-8 guuid=f21681eb-2100-0000-ba49-82c6ee150000 pid=5614->guuid=f21681eb-2100-0000-ba49-82c6ee150000 pid=5617 clone guuid=f21681eb-2100-0000-ba49-82c6ee150000 pid=5618 /boot/System.img-6.8.0-8 guuid=f21681eb-2100-0000-ba49-82c6ee150000 pid=5614->guuid=f21681eb-2100-0000-ba49-82c6ee150000 pid=5618 clone guuid=f21681eb-2100-0000-ba49-82c6ee150000 pid=5619 /boot/System.img-6.8.0-8 guuid=f21681eb-2100-0000-ba49-82c6ee150000 pid=5614->guuid=f21681eb-2100-0000-ba49-82c6ee150000 pid=5619 clone guuid=455d5812-2200-0000-ba49-82c6f4150000 pid=5621 /usr/local/sbin/nginx-1 guuid=455d5812-2200-0000-ba49-82c6f4150000 pid=5620->guuid=455d5812-2200-0000-ba49-82c6f4150000 pid=5621 clone guuid=455d5812-2200-0000-ba49-82c6f4150000 pid=5622 /usr/local/sbin/nginx-1 guuid=455d5812-2200-0000-ba49-82c6f4150000 pid=5620->guuid=455d5812-2200-0000-ba49-82c6f4150000 pid=5622 clone guuid=455d5812-2200-0000-ba49-82c6f4150000 pid=5623 /usr/local/sbin/nginx-1 guuid=455d5812-2200-0000-ba49-82c6f4150000 pid=5620->guuid=455d5812-2200-0000-ba49-82c6f4150000 pid=5623 clone guuid=455d5812-2200-0000-ba49-82c6f4150000 pid=5624 /usr/local/sbin/nginx-1 guuid=455d5812-2200-0000-ba49-82c6f4150000 pid=5620->guuid=455d5812-2200-0000-ba49-82c6f4150000 pid=5624 clone guuid=455d5812-2200-0000-ba49-82c6f4150000 pid=5625 /usr/local/sbin/nginx-1 guuid=455d5812-2200-0000-ba49-82c6f4150000 pid=5620->guuid=455d5812-2200-0000-ba49-82c6f4150000 pid=5625 clone
Result
Threat name:
n/a
Detection:
malicious
Classification:
spre.troj.evad
Score:
84 / 100
Signature
Drops files in suspicious directories
Drops invisible ELF files
Executes the "crontab" command typically for achieving persistence
Modifies the '.bashrc' or '.bash_profile' file typically for persisting actions
Multi AV Scanner detection for submitted file
Sample tries to persist itself using /etc/profile
Sample tries to persist itself using cron
Sample tries to persist itself using System V runlevels
Writes ELF files to hidden directories
Writes identical ELF files to multiple locations
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1893469 Sample: linux_amd64.elf Startdate: 04/04/2026 Architecture: LINUX Score: 84 84 ak.504.su 82.27.11.165, 28588, 54642 NTLGB United Kingdom 2->84 86 109.202.202.202, 80 INIT7CH Switzerland 2->86 88 3 other IPs or domains 2->88 90 Multi AV Scanner detection for submitted file 2->90 10 linux_amd64.elf 2->10         started        12 systemd System.img-6.8.0-8 2->12         started        14 systemd System.img-6.8.0-8 2->14         started        16 25 other processes 2->16 signatures3 process4 process5 18 linux_amd64.elf linux_amd64.elf 10->18         started        22 System.img-6.8.0-8 System.img-6.8.0-8 12->22         started        24 System.img-6.8.0-8 System.img-6.8.0-8 14->24         started        26 System.img-6.8.0-8 System.img-6.8.0-8 16->26         started        28 System.img-6.8.0-8 System.img-6.8.0-8 16->28         started        30 System.img-6.8.0-8 System.img-6.8.0-8 16->30         started        32 7 other processes 16->32 file6 72 /usr/sbin/.write_test_x37l, ASCII 18->72 dropped 74 /usr/sbin/.write_test_tmej, ASCII 18->74 dropped 76 /usr/sbin/.write_test_kt2j, ASCII 18->76 dropped 78 50 other malicious files 18->78 dropped 92 Writes ELF files to hidden directories 18->92 94 Writes identical ELF files to multiple locations 18->94 96 Sample tries to persist itself using /etc/profile 18->96 98 5 other signatures 18->98 34 linux_amd64.elf crontab 18->34         started        38 linux_amd64.elf crontab 18->38         started        40 linux_amd64.elf sh 18->40         started        42 26 other processes 18->42 signatures7 process8 file9 80 /var/spool/cron/crontabs/tmp.ZSdcM3, ASCII 34->80 dropped 100 Sample tries to persist itself using cron 34->100 102 Executes the "crontab" command typically for achieving persistence 34->102 82 /var/spool/cron/crontabs/tmp.MpxlWe, ASCII 38->82 dropped 44 sh System 40->44         started        104 Sample tries to persist itself using System V runlevels 42->104 46 sh killai 42->46         started        48 sh .at.atloy 42->48         started        50 sh .font-unix-helpver 42->50         started        52 12 other processes 42->52 signatures10 process11 process12 54 System sleep 44->54         started        56 System System.img-6.8.0-8 44->56         started        64 5 other processes 44->64 58 killai sleep 46->58         started        66 4 other processes 46->66 60 .at.atloy sleep 48->60         started        68 2 other processes 48->68 62 .font-unix-helpver sleep 50->62         started        70 2 other processes 50->70
Threat name:
Linux.Trojan.Generic
Status:
Suspicious
First seen:
2026-04-04 15:01:29 UTC
File Type:
ELF64 Little (Exe)
AV detection:
4 of 36 (11.11%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  6/10
Tags:
defense_evasion discovery execution linux persistence privilege_escalation
Behaviour
Enumerates kernel/hardware configuration
Reads runtime system information
Writes file to tmp directory
Changes its process name
Modifies Bash startup script
Creates/modifies Cron job
Creates/modifies environment variables
Enumerates running processes
Modifies init.d
Modifies rc script
Reads list of loaded kernel modules
Write file to user bin folder
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:DetectGoMethodSignatures
Author:Wyatt Tauber
Description:Detects Go method signatures in unpacked Go binaries
Rule name:Detect_Go_GOMAXPROCS
Author:Obscurity Labs LLC
Description:Detects Go binaries by the presence of runtime.GOMAXPROCS in the runtime metadata
Rule name:enterpriseapps2
Author:Tim Brown @timb_machine
Description:Enterprise apps
Rule name:F01_s1ckrule
Author:s1ckb017
Rule name:GoBinTest
Rule name:golang_binary_string
Description:Golang strings present
Rule name:golang_duffcopy_amd64
Rule name:Golang_Find_CSC846
Author:Ashar Siddiqui
Description:Find Go Signatuers
Rule name:Golang_Find_CSC846_Simple
Author:Ashar Siddiqui
Description:Find Go Signatuers
Rule name:MD5_Constants
Author:phoul (@phoul)
Description:Look for MD5 constants
Rule name:ProgramLanguage_Golang
Author:albertzsigovits
Description:Application written in Golang programming language
Rule name:RANSOMWARE
Author:ToroGuitar
Rule name:RIPEMD160_Constants
Author:phoul (@phoul)
Description:Look for RIPEMD-160 constants
Rule name:setsockopt
Author:Tim Brown @timb_machine
Description:Hunts for setsockopt() red flags
Rule name:SHA1_Constants
Author:phoul (@phoul)
Description:Look for SHA1 constants
Rule name:SHA512_Constants
Author:phoul (@phoul)
Description:Look for SHA384/SHA512 constants
Rule name:TH_Generic_MassHunt_Linux_Malware_2026_CYFARE
Author:CYFARE
Description:Generic Linux malware mass-hunt rule - 2026
Reference:https://cyfare.net/
Rule name:unixredflags3
Author:Tim Brown @timb_machine
Description:Hunts for UNIX red flags
Rule name:vmdetect
Author:nex
Description:Possibly employs anti-virtualization techniques

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

elf 5b15dcff5b4960235476057ddb138c7b2539bd253be814100fd2e36215fcdc61

(this sample)

  
Delivery method
Distributed via web download

Comments