MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 5ee23a446ab4425d7db8c87badf05812ed01a2fc2cfd20f5f0dc279afa2038ad. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA 16 File information Comments

SHA256 hash: 5ee23a446ab4425d7db8c87badf05812ed01a2fc2cfd20f5f0dc279afa2038ad
SHA3-384 hash: 9a9e8a419fa09cf296d8567e6cec0ecf0d405cc24c3f12a61eb933528052d1e82acb48e8c3bef7534cd998a747abeb5e
SHA1 hash: 8167ed630c458a6421d08ae2cb811359361e67b1
MD5 hash: bcda8f6db00dcbdbae5105b975179aab
humanhash: alaska-idaho-queen-thirteen
File name:px.x86_64
Download: download sample
File size:12'506'088 bytes
First seen:2026-07-07 05:23:45 UTC
Last seen:Never
File type: elf
MIME type:application/x-executable
ssdeep 98304:22ybO5yn1PnnkuBPcWBevZWBJt7spF9wYs1E:25gy2kDdPiF9wG
TLSH T171C63963E8D21694C8EE8570D772813BBA713C491B7823D716E0F3256B37BE09AB6741
telfhash t16d82f2b05bb870f5a296ca51f3f27474e67718b553e474b10027b8a2efe1f481ca6863
TrID 50.1% (.) ELF Executable and Linkable format (Linux) (4022/12)
49.8% (.O) ELF Executable and Linkable format (generic) (4000/1)
Magika elf
Reporter abuse_ch
Tags:elf upx-dec


Avatar
abuse_ch
UPX decompressed file, sourced from SHA256 b0145d6283981447cb4ccd3247a5855f95a77918922cb5daa5b869672d2e37cd
File size (compressed) :3'811'196 bytes
File size (de-compressed) :12'506'088 bytes
Format:linux/amd64
Packed file: b0145d6283981447cb4ccd3247a5855f95a77918922cb5daa5b869672d2e37cd

Intelligence


File Origin
# of uploads :
1
# of downloads :
213
Origin country :
NL NL
Vendor Threat Intelligence
No detections
Result
Verdict:
Malware
Maliciousness:

Behaviour
Sends data to a server
Sets a written file as executable
Changes access rights for a written file
Gains root access
Creating a file in the %temp% directory
Receives data from a server
Changes owner for a file
Deleting a recently created file
Launching a process
Connection attempt
Creating a file
Changes the time when the file was created, accessed, or modified
Changes owner for a written file
Creates or modifies symbolic links
Creates directories
Substitutes an application name
Verdict:
Malicious
Uses P2P?:
false
Uses anti-vm?:
false
Architecture:
x86
Packer:
not packed
Botnet:
unknown
Number of open files:
8
Number of processes launched:
3
Processes remaning?
false
Remote TCP ports scanned:
not identified
Behaviour
Information Gathering
Botnet C2s
TCP botnet C2(s):
not identified
UDP botnet C2(s):
not identified
Status:
terminated
Behavior Graph:
%3 guuid=dc20c720-1f00-0000-0d86-e5aa3d140000 pid=5181 /usr/bin/sudo guuid=ebc69425-1f00-0000-0d86-e5aa3e140000 pid=5182 /tmp/sample.bin net write-file guuid=dc20c720-1f00-0000-0d86-e5aa3d140000 pid=5181->guuid=ebc69425-1f00-0000-0d86-e5aa3e140000 pid=5182 execve e05ac331-4d6c-529a-b012-a8a5bfa6a257 94.154.43.42:8080 guuid=ebc69425-1f00-0000-0d86-e5aa3e140000 pid=5182->e05ac331-4d6c-529a-b012-a8a5bfa6a257 con guuid=ebc69425-1f00-0000-0d86-e5aa3e140000 pid=5183 /tmp/sample.bin guuid=ebc69425-1f00-0000-0d86-e5aa3e140000 pid=5182->guuid=ebc69425-1f00-0000-0d86-e5aa3e140000 pid=5183 clone guuid=ebc69425-1f00-0000-0d86-e5aa3e140000 pid=5184 /tmp/sample.bin guuid=ebc69425-1f00-0000-0d86-e5aa3e140000 pid=5182->guuid=ebc69425-1f00-0000-0d86-e5aa3e140000 pid=5184 clone guuid=ebc69425-1f00-0000-0d86-e5aa3e140000 pid=5185 /tmp/sample.bin guuid=ebc69425-1f00-0000-0d86-e5aa3e140000 pid=5182->guuid=ebc69425-1f00-0000-0d86-e5aa3e140000 pid=5185 clone guuid=ebc69425-1f00-0000-0d86-e5aa3e140000 pid=5186 /tmp/sample.bin send-data guuid=ebc69425-1f00-0000-0d86-e5aa3e140000 pid=5182->guuid=ebc69425-1f00-0000-0d86-e5aa3e140000 pid=5186 clone guuid=55245f73-2000-0000-0d86-e5aa87140000 pid=5255 /usr/bin/sudo net guuid=ebc69425-1f00-0000-0d86-e5aa3e140000 pid=5182->guuid=55245f73-2000-0000-0d86-e5aa87140000 pid=5255 execve guuid=73b1844c-1f00-0000-0d86-e5aa43140000 pid=5187 /tmp/sample.bin guuid=ebc69425-1f00-0000-0d86-e5aa3e140000 pid=5184->guuid=73b1844c-1f00-0000-0d86-e5aa43140000 pid=5187 clone guuid=bb72974c-1f00-0000-0d86-e5aa44140000 pid=5188 /usr/bin/sudo net guuid=ebc69425-1f00-0000-0d86-e5aa3e140000 pid=5184->guuid=bb72974c-1f00-0000-0d86-e5aa44140000 pid=5188 execve guuid=ebc69425-1f00-0000-0d86-e5aa3e140000 pid=5186->e05ac331-4d6c-529a-b012-a8a5bfa6a257 send: 1122B guuid=25d33552-2000-0000-0d86-e5aa70140000 pid=5232 /usr/bin/sudo net guuid=ebc69425-1f00-0000-0d86-e5aa3e140000 pid=5186->guuid=25d33552-2000-0000-0d86-e5aa70140000 pid=5232 execve 0fd0acc8-dfb6-529f-8986-56cdc3ae41d6 10.0.2.15:0 guuid=bb72974c-1f00-0000-0d86-e5aa44140000 pid=5188->0fd0acc8-dfb6-529f-8986-56cdc3ae41d6 con 558177e1-1f18-5f39-990b-d68b1c194e8a fec0::5054:ff:fe12:3456:0 guuid=bb72974c-1f00-0000-0d86-e5aa44140000 pid=5188->558177e1-1f18-5f39-990b-d68b1c194e8a con cbc59886-1795-52e1-b014-449ae22fd09b fe80::5054:ff:fe12:3456:0 guuid=bb72974c-1f00-0000-0d86-e5aa44140000 pid=5188->cbc59886-1795-52e1-b014-449ae22fd09b con guuid=91d7cf52-1f00-0000-0d86-e5aa45140000 pid=5189 /usr/sbin/adduser write-file guuid=bb72974c-1f00-0000-0d86-e5aa44140000 pid=5188->guuid=91d7cf52-1f00-0000-0d86-e5aa45140000 pid=5189 execve guuid=f8a44a70-1f00-0000-0d86-e5aa46140000 pid=5190 /usr/sbin/groupadd delete-file write-config guuid=91d7cf52-1f00-0000-0d86-e5aa45140000 pid=5189->guuid=f8a44a70-1f00-0000-0d86-e5aa46140000 pid=5190 execve guuid=1503208c-1f00-0000-0d86-e5aa4c140000 pid=5196 /usr/sbin/useradd delete-file write-config guuid=91d7cf52-1f00-0000-0d86-e5aa45140000 pid=5189->guuid=1503208c-1f00-0000-0d86-e5aa4c140000 pid=5196 execve guuid=79e421b2-1f00-0000-0d86-e5aa53140000 pid=5203 /usr/bin/dash guuid=91d7cf52-1f00-0000-0d86-e5aa45140000 pid=5189->guuid=79e421b2-1f00-0000-0d86-e5aa53140000 pid=5203 execve guuid=0f197ab3-1f00-0000-0d86-e5aa55140000 pid=5205 /usr/bin/passwd write-config guuid=91d7cf52-1f00-0000-0d86-e5aa45140000 pid=5189->guuid=0f197ab3-1f00-0000-0d86-e5aa55140000 pid=5205 execve guuid=c75deef3-1f00-0000-0d86-e5aa5c140000 pid=5212 /usr/bin/chfn delete-file write-config guuid=91d7cf52-1f00-0000-0d86-e5aa45140000 pid=5189->guuid=c75deef3-1f00-0000-0d86-e5aa5c140000 pid=5212 execve guuid=3487ad2a-2000-0000-0d86-e5aa69140000 pid=5225 /usr/bin/gpasswd delete-file write-config guuid=91d7cf52-1f00-0000-0d86-e5aa45140000 pid=5189->guuid=3487ad2a-2000-0000-0d86-e5aa69140000 pid=5225 execve guuid=3fe8e586-1f00-0000-0d86-e5aa47140000 pid=5191 /usr/sbin/groupadd guuid=f8a44a70-1f00-0000-0d86-e5aa46140000 pid=5190->guuid=3fe8e586-1f00-0000-0d86-e5aa47140000 pid=5191 clone guuid=18032a87-1f00-0000-0d86-e5aa48140000 pid=5192 /usr/sbin/groupadd guuid=f8a44a70-1f00-0000-0d86-e5aa46140000 pid=5190->guuid=18032a87-1f00-0000-0d86-e5aa48140000 pid=5192 clone guuid=3ca6908a-1f00-0000-0d86-e5aa49140000 pid=5193 /usr/sbin/groupadd guuid=f8a44a70-1f00-0000-0d86-e5aa46140000 pid=5190->guuid=3ca6908a-1f00-0000-0d86-e5aa49140000 pid=5193 clone guuid=4369128b-1f00-0000-0d86-e5aa4a140000 pid=5194 /usr/sbin/groupadd guuid=f8a44a70-1f00-0000-0d86-e5aa46140000 pid=5190->guuid=4369128b-1f00-0000-0d86-e5aa4a140000 pid=5194 clone guuid=1344848b-1f00-0000-0d86-e5aa4b140000 pid=5195 /usr/sbin/groupadd guuid=f8a44a70-1f00-0000-0d86-e5aa46140000 pid=5190->guuid=1344848b-1f00-0000-0d86-e5aa4b140000 pid=5195 clone guuid=f43ddeb0-1f00-0000-0d86-e5aa4d140000 pid=5197 /usr/sbin/useradd guuid=1503208c-1f00-0000-0d86-e5aa4c140000 pid=5196->guuid=f43ddeb0-1f00-0000-0d86-e5aa4d140000 pid=5197 clone guuid=776d00b1-1f00-0000-0d86-e5aa4e140000 pid=5198 /usr/sbin/useradd guuid=1503208c-1f00-0000-0d86-e5aa4c140000 pid=5196->guuid=776d00b1-1f00-0000-0d86-e5aa4e140000 pid=5198 clone guuid=7c956eb1-1f00-0000-0d86-e5aa4f140000 pid=5199 /usr/sbin/useradd guuid=1503208c-1f00-0000-0d86-e5aa4c140000 pid=5196->guuid=7c956eb1-1f00-0000-0d86-e5aa4f140000 pid=5199 clone guuid=3ec494b1-1f00-0000-0d86-e5aa50140000 pid=5200 /usr/sbin/useradd guuid=1503208c-1f00-0000-0d86-e5aa4c140000 pid=5196->guuid=3ec494b1-1f00-0000-0d86-e5aa50140000 pid=5200 clone guuid=62fcb7b1-1f00-0000-0d86-e5aa51140000 pid=5201 /usr/sbin/useradd guuid=1503208c-1f00-0000-0d86-e5aa4c140000 pid=5196->guuid=62fcb7b1-1f00-0000-0d86-e5aa51140000 pid=5201 clone guuid=9435d6b1-1f00-0000-0d86-e5aa52140000 pid=5202 /usr/sbin/useradd guuid=1503208c-1f00-0000-0d86-e5aa4c140000 pid=5196->guuid=9435d6b1-1f00-0000-0d86-e5aa52140000 pid=5202 clone guuid=316a78b2-1f00-0000-0d86-e5aa54140000 pid=5204 /usr/bin/find guuid=79e421b2-1f00-0000-0d86-e5aa53140000 pid=5203->guuid=316a78b2-1f00-0000-0d86-e5aa54140000 pid=5204 execve guuid=37286d29-2000-0000-0d86-e5aa64140000 pid=5220 /usr/bin/chfn guuid=c75deef3-1f00-0000-0d86-e5aa5c140000 pid=5212->guuid=37286d29-2000-0000-0d86-e5aa64140000 pid=5220 clone guuid=06a29929-2000-0000-0d86-e5aa65140000 pid=5221 /usr/bin/chfn guuid=c75deef3-1f00-0000-0d86-e5aa5c140000 pid=5212->guuid=06a29929-2000-0000-0d86-e5aa65140000 pid=5221 clone guuid=12f5c129-2000-0000-0d86-e5aa66140000 pid=5222 /usr/bin/chfn guuid=c75deef3-1f00-0000-0d86-e5aa5c140000 pid=5212->guuid=12f5c129-2000-0000-0d86-e5aa66140000 pid=5222 clone guuid=484d0d2a-2000-0000-0d86-e5aa67140000 pid=5223 /usr/bin/chfn guuid=c75deef3-1f00-0000-0d86-e5aa5c140000 pid=5212->guuid=484d0d2a-2000-0000-0d86-e5aa67140000 pid=5223 clone guuid=facf322a-2000-0000-0d86-e5aa68140000 pid=5224 /usr/bin/chfn guuid=c75deef3-1f00-0000-0d86-e5aa5c140000 pid=5212->guuid=facf322a-2000-0000-0d86-e5aa68140000 pid=5224 clone guuid=130a3b51-2000-0000-0d86-e5aa6b140000 pid=5227 /usr/bin/gpasswd guuid=3487ad2a-2000-0000-0d86-e5aa69140000 pid=5225->guuid=130a3b51-2000-0000-0d86-e5aa6b140000 pid=5227 clone guuid=1e5f5951-2000-0000-0d86-e5aa6c140000 pid=5228 /usr/bin/gpasswd guuid=3487ad2a-2000-0000-0d86-e5aa69140000 pid=5225->guuid=1e5f5951-2000-0000-0d86-e5aa6c140000 pid=5228 clone guuid=d5bf7351-2000-0000-0d86-e5aa6d140000 pid=5229 /usr/bin/gpasswd guuid=3487ad2a-2000-0000-0d86-e5aa69140000 pid=5225->guuid=d5bf7351-2000-0000-0d86-e5aa6d140000 pid=5229 clone guuid=840e9451-2000-0000-0d86-e5aa6e140000 pid=5230 /usr/bin/gpasswd guuid=3487ad2a-2000-0000-0d86-e5aa69140000 pid=5225->guuid=840e9451-2000-0000-0d86-e5aa6e140000 pid=5230 clone guuid=f9afa951-2000-0000-0d86-e5aa6f140000 pid=5231 /usr/bin/gpasswd guuid=3487ad2a-2000-0000-0d86-e5aa69140000 pid=5225->guuid=f9afa951-2000-0000-0d86-e5aa6f140000 pid=5231 clone guuid=25d33552-2000-0000-0d86-e5aa70140000 pid=5232->0fd0acc8-dfb6-529f-8986-56cdc3ae41d6 con guuid=25d33552-2000-0000-0d86-e5aa70140000 pid=5232->558177e1-1f18-5f39-990b-d68b1c194e8a con guuid=25d33552-2000-0000-0d86-e5aa70140000 pid=5232->cbc59886-1795-52e1-b014-449ae22fd09b con guuid=6ae51654-2000-0000-0d86-e5aa72140000 pid=5234 /usr/sbin/usermod delete-file write-config guuid=25d33552-2000-0000-0d86-e5aa70140000 pid=5232->guuid=6ae51654-2000-0000-0d86-e5aa72140000 pid=5234 execve guuid=ae16c372-2000-0000-0d86-e5aa80140000 pid=5248 /usr/sbin/usermod guuid=6ae51654-2000-0000-0d86-e5aa72140000 pid=5234->guuid=ae16c372-2000-0000-0d86-e5aa80140000 pid=5248 clone guuid=8181d572-2000-0000-0d86-e5aa81140000 pid=5249 /usr/sbin/usermod guuid=6ae51654-2000-0000-0d86-e5aa72140000 pid=5234->guuid=8181d572-2000-0000-0d86-e5aa81140000 pid=5249 clone guuid=3fd0e872-2000-0000-0d86-e5aa82140000 pid=5250 /usr/sbin/usermod guuid=6ae51654-2000-0000-0d86-e5aa72140000 pid=5234->guuid=3fd0e872-2000-0000-0d86-e5aa82140000 pid=5250 clone guuid=8335fa72-2000-0000-0d86-e5aa83140000 pid=5251 /usr/sbin/usermod guuid=6ae51654-2000-0000-0d86-e5aa72140000 pid=5234->guuid=8335fa72-2000-0000-0d86-e5aa83140000 pid=5251 clone guuid=4dd71473-2000-0000-0d86-e5aa85140000 pid=5253 /usr/sbin/usermod guuid=6ae51654-2000-0000-0d86-e5aa72140000 pid=5234->guuid=4dd71473-2000-0000-0d86-e5aa85140000 pid=5253 clone guuid=2f9c2473-2000-0000-0d86-e5aa86140000 pid=5254 /usr/sbin/usermod guuid=6ae51654-2000-0000-0d86-e5aa72140000 pid=5234->guuid=2f9c2473-2000-0000-0d86-e5aa86140000 pid=5254 clone guuid=55245f73-2000-0000-0d86-e5aa87140000 pid=5255->0fd0acc8-dfb6-529f-8986-56cdc3ae41d6 con guuid=55245f73-2000-0000-0d86-e5aa87140000 pid=5255->558177e1-1f18-5f39-990b-d68b1c194e8a con guuid=55245f73-2000-0000-0d86-e5aa87140000 pid=5255->cbc59886-1795-52e1-b014-449ae22fd09b con guuid=a52b8974-2000-0000-0d86-e5aa8b140000 pid=5259 /usr/bin/chown guuid=55245f73-2000-0000-0d86-e5aa87140000 pid=5255->guuid=a52b8974-2000-0000-0d86-e5aa8b140000 pid=5259 execve
Result
Threat name:
n/a
Detection:
suspicious
Classification:
n/a
Score:
27 / 100
Signature
Modifies the '.bashrc' or '.bash_profile' file typically for persisting actions
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1938303 Sample: px.x86_64.elf Startdate: 07/07/2026 Architecture: LINUX Score: 27 63 94.154.43.42, 41586, 8080 CDNEXTGB Turkey 2->63 9 px.x86_64.elf 2->9         started        process3 process4 11 px.x86_64.elf sudo 9->11         started        13 px.x86_64.elf sudo 9->13         started        15 px.x86_64.elf sudo 9->15         started        17 px.x86_64.elf 9->17         started        process5 19 sudo adduser 11->19         started        23 sudo usermod 13->23         started        25 sudo chown 15->25         started        file6 61 /home/cursinq/.bashrc, ASCII 19->61 dropped 65 Modifies the '.bashrc' or '.bash_profile' file typically for persisting actions 19->65 27 adduser useradd 19->27         started        29 adduser groupadd 19->29         started        31 adduser chfn 19->31         started        39 3 other processes 19->39 33 usermod 23->33         started        35 usermod 23->35         started        37 usermod 23->37         started        41 3 other processes 23->41 signatures7 process8 process9 43 useradd pam_tally2 27->43         started        55 6 other processes 27->55 45 groupadd 29->45         started        47 groupadd 29->47         started        49 groupadd 29->49         started        57 2 other processes 29->57 59 5 other processes 31->59 51 sh find 39->51         started        53 sh 39->53         started       
Threat name:
Linux.Trojan.Generic
Status:
Suspicious
First seen:
2026-07-07 05:25:52 UTC
File Type:
ELF64 Little (Exe)
AV detection:
8 of 38 (21.05%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  8/10
Tags:
credential_access defense_evasion discovery execution linux persistence privilege_escalation
Behaviour
GoLang User-Agent
Enumerates kernel/hardware configuration
Reads runtime system information
Writes file to tmp directory
Changes its process name
Creates .desktop file
Modifies Bash startup script
Abuse Elevation Control Mechanism: Sudo and Sudo Caching
Adds a user to the system
Creates/modifies environment variables
OS Credential Dumping
Modifies password files for system users/ groups
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:DetectEncryptedVariants
Author:Zinyth
Description:Detects 'encrypted' in ASCII, Unicode, base64, or hex-encoded
Rule name:DetectGoMethodSignatures
Author:Wyatt Tauber
Description:Detects Go method signatures in unpacked Go binaries
Rule name:Detect_Go_GOMAXPROCS
Author:Obscurity Labs LLC
Description:Detects Go binaries by the presence of runtime.GOMAXPROCS in the runtime metadata
Rule name:enterpriseapps2
Author:Tim Brown @timb_machine
Description:Enterprise apps
Rule name:GoBinTest
Rule name:golang_binary_string
Description:Golang strings present
Rule name:Golang_Find_CSC846_Simple
Author:Ashar Siddiqui
Description:Find Go Signatuers
Rule name:MD5_Constants
Author:phoul (@phoul)
Description:Look for MD5 constants
Rule name:ProgramLanguage_Golang
Author:albertzsigovits
Description:Application written in Golang programming language
Rule name:RANSOMWARE
Author:ToroGuitar
Rule name:RIPEMD160_Constants
Author:phoul (@phoul)
Description:Look for RIPEMD-160 constants
Rule name:SHA1_Constants
Author:phoul (@phoul)
Description:Look for SHA1 constants
Rule name:SHA512_Constants
Author:phoul (@phoul)
Description:Look for SHA384/SHA512 constants
Rule name:TH_Generic_MassHunt_Linux_Malware_2026_CYFARE
Author:CYFARE
Description:Generic Linux malware mass-hunt rule - 2026
Reference:https://cyfare.net/
Rule name:unixredflags3
Author:Tim Brown @timb_machine
Description:Hunts for UNIX red flags

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

elf 5ee23a446ab4425d7db8c87badf05812ed01a2fc2cfd20f5f0dc279afa2038ad

(this sample)

  
Delivery method
Distributed via web download

Comments