MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 66cfedb8a0fbf80f79f803e2b7ec815db887298e0b16907a6b358efdf37789c2. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Ladvix


Vendor detections: 7


Intelligence 7 IOCs YARA 15 File information Comments

SHA256 hash: 66cfedb8a0fbf80f79f803e2b7ec815db887298e0b16907a6b358efdf37789c2
SHA3-384 hash: 368c28ceea9cd8e4f6d2f3ca03e90be37a7efb78c242493df5ac5e30597d5660af48052f473be534eb047c3e658e2102
SHA1 hash: 5c73606f62a842452d973f967418838e9c7ebc42
MD5 hash: b6eb4d62d72e2609f2fec322abfbf8d6
humanhash: friend-uniform-kansas-twelve
File name:main
Download: download sample
Signature Ladvix
File size:2'665'097 bytes
First seen:2026-08-11 11:56:56 UTC
Last seen:Never
File type: elf
MIME type:application/x-executable
ssdeep 49152:uhAPIoHwyHKx+pF/lHDYAMHajKBDPbAJeIz:uEX/lHDdODPbAJ7
TLSH T194C57B177CE118AAC0AA92328AB2A692BB71FC490B3123D73F50B37C2F767D45975744
telfhash t19c3372456cf31e9619c613a7ac3809c513bfe04f045ab9696e68c37429ef08c593fb6e
gimphash e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
TrID 50.1% (.) ELF Executable and Linkable format (Linux) (4022/12)
49.8% (.O) ELF Executable and Linkable format (generic) (4000/1)
Magika elf
Reporter abuse_ch
Tags:elf Ladvix

Intelligence


File Origin
# of uploads :
1
# of downloads :
80
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Result
Verdict:
Suspicious
Maliciousness:

Behaviour
Launching a process
Connection attempt
Creating a file in the %temp% directory
Locks files
Kills processes
Collects information on the OS
Receives data from a server
Collects information on the CPU
Sends data to a server
Verdict:
Unknown
Threat level:
  2.5/10
Confidence:
100%
Tags:
golang reconnaissance
Verdict:
Malicious
Uses P2P?:
false
Uses anti-vm?:
false
Architecture:
x86
Packer:
custom
Botnet:
unknown
Number of open files:
0
Number of processes launched:
5
Processes remaning?
false
Remote TCP ports scanned:
not identified
Behaviour
no suspicious findings
Botnet C2s
TCP botnet C2(s):
not identified
UDP botnet C2(s):
not identified
Status:
terminated
Behavior Graph:
%3 guuid=53ffdefc-1b00-0000-b59a-7921a8070000 pid=1960 /usr/bin/sudo guuid=1910de03-1c00-0000-b59a-7921b1070000 pid=1969 /tmp/sample.bin guuid=53ffdefc-1b00-0000-b59a-7921a8070000 pid=1960->guuid=1910de03-1c00-0000-b59a-7921b1070000 pid=1969 execve guuid=1910de03-1c00-0000-b59a-7921b1070000 pid=1976 /tmp/sample.bin guuid=1910de03-1c00-0000-b59a-7921b1070000 pid=1969->guuid=1910de03-1c00-0000-b59a-7921b1070000 pid=1976 clone guuid=1910de03-1c00-0000-b59a-7921b1070000 pid=1977 /tmp/sample.bin guuid=1910de03-1c00-0000-b59a-7921b1070000 pid=1969->guuid=1910de03-1c00-0000-b59a-7921b1070000 pid=1977 clone guuid=1910de03-1c00-0000-b59a-7921b1070000 pid=1978 /tmp/sample.bin guuid=1910de03-1c00-0000-b59a-7921b1070000 pid=1969->guuid=1910de03-1c00-0000-b59a-7921b1070000 pid=1978 clone guuid=1910de03-1c00-0000-b59a-7921b1070000 pid=1979 /tmp/sample.bin guuid=1910de03-1c00-0000-b59a-7921b1070000 pid=1969->guuid=1910de03-1c00-0000-b59a-7921b1070000 pid=1979 clone guuid=1910de03-1c00-0000-b59a-7921b1070000 pid=1980 /tmp/sample.bin guuid=1910de03-1c00-0000-b59a-7921b1070000 pid=1969->guuid=1910de03-1c00-0000-b59a-7921b1070000 pid=1980 clone guuid=c9781f0f-1c00-0000-b59a-7921bd070000 pid=1981 /tmp/sample.bin guuid=1910de03-1c00-0000-b59a-7921b1070000 pid=1969->guuid=c9781f0f-1c00-0000-b59a-7921bd070000 pid=1981 clone guuid=9d11300f-1c00-0000-b59a-7921be070000 pid=1982 /usr/bin/bash guuid=1910de03-1c00-0000-b59a-7921b1070000 pid=1969->guuid=9d11300f-1c00-0000-b59a-7921be070000 pid=1982 execve guuid=62553810-1c00-0000-b59a-7921bf070000 pid=1983 /usr/bin/pgrep guuid=9d11300f-1c00-0000-b59a-7921be070000 pid=1982->guuid=62553810-1c00-0000-b59a-7921bf070000 pid=1983 execve guuid=3fa93c19-1c00-0000-b59a-7921cb070000 pid=1995 /usr/bin/pgrep guuid=9d11300f-1c00-0000-b59a-7921be070000 pid=1982->guuid=3fa93c19-1c00-0000-b59a-7921cb070000 pid=1995 execve guuid=5b230c1f-1c00-0000-b59a-7921d3070000 pid=2003 /usr/bin/pgrep guuid=9d11300f-1c00-0000-b59a-7921be070000 pid=1982->guuid=5b230c1f-1c00-0000-b59a-7921d3070000 pid=2003 execve guuid=0ac6db24-1c00-0000-b59a-7921dc070000 pid=2012 /usr/bin/pgrep guuid=9d11300f-1c00-0000-b59a-7921be070000 pid=1982->guuid=0ac6db24-1c00-0000-b59a-7921dc070000 pid=2012 execve guuid=2b7cc529-1c00-0000-b59a-7921e4070000 pid=2020 /usr/bin/pgrep guuid=9d11300f-1c00-0000-b59a-7921be070000 pid=1982->guuid=2b7cc529-1c00-0000-b59a-7921e4070000 pid=2020 execve guuid=5082972f-1c00-0000-b59a-7921f1070000 pid=2033 /usr/bin/pgrep guuid=9d11300f-1c00-0000-b59a-7921be070000 pid=1982->guuid=5082972f-1c00-0000-b59a-7921f1070000 pid=2033 execve guuid=91e80935-1c00-0000-b59a-7921fd070000 pid=2045 /usr/bin/pgrep guuid=9d11300f-1c00-0000-b59a-7921be070000 pid=1982->guuid=91e80935-1c00-0000-b59a-7921fd070000 pid=2045 execve guuid=feb15a3a-1c00-0000-b59a-792106080000 pid=2054 /usr/bin/pgrep guuid=9d11300f-1c00-0000-b59a-7921be070000 pid=1982->guuid=feb15a3a-1c00-0000-b59a-792106080000 pid=2054 execve guuid=12b45b3f-1c00-0000-b59a-792110080000 pid=2064 /usr/bin/pgrep guuid=9d11300f-1c00-0000-b59a-7921be070000 pid=1982->guuid=12b45b3f-1c00-0000-b59a-792110080000 pid=2064 execve guuid=f1822645-1c00-0000-b59a-792117080000 pid=2071 /usr/bin/pgrep guuid=9d11300f-1c00-0000-b59a-7921be070000 pid=1982->guuid=f1822645-1c00-0000-b59a-792117080000 pid=2071 execve guuid=2cbd934a-1c00-0000-b59a-79211c080000 pid=2076 /usr/bin/pgrep guuid=9d11300f-1c00-0000-b59a-7921be070000 pid=1982->guuid=2cbd934a-1c00-0000-b59a-79211c080000 pid=2076 execve guuid=d728a74f-1c00-0000-b59a-792125080000 pid=2085 /usr/bin/pgrep guuid=9d11300f-1c00-0000-b59a-7921be070000 pid=1982->guuid=d728a74f-1c00-0000-b59a-792125080000 pid=2085 execve guuid=dc7b8f55-1c00-0000-b59a-792132080000 pid=2098 /usr/bin/pgrep guuid=9d11300f-1c00-0000-b59a-7921be070000 pid=1982->guuid=dc7b8f55-1c00-0000-b59a-792132080000 pid=2098 execve guuid=067ec759-1c00-0000-b59a-79213b080000 pid=2107 /usr/bin/pgrep guuid=9d11300f-1c00-0000-b59a-7921be070000 pid=1982->guuid=067ec759-1c00-0000-b59a-79213b080000 pid=2107 execve guuid=d99a795f-1c00-0000-b59a-792141080000 pid=2113 /usr/bin/pgrep guuid=9d11300f-1c00-0000-b59a-7921be070000 pid=1982->guuid=d99a795f-1c00-0000-b59a-792141080000 pid=2113 execve guuid=66bd6a64-1c00-0000-b59a-792145080000 pid=2117 /usr/bin/pgrep guuid=9d11300f-1c00-0000-b59a-7921be070000 pid=1982->guuid=66bd6a64-1c00-0000-b59a-792145080000 pid=2117 execve guuid=ee108d69-1c00-0000-b59a-79214e080000 pid=2126 /usr/bin/pgrep guuid=9d11300f-1c00-0000-b59a-7921be070000 pid=1982->guuid=ee108d69-1c00-0000-b59a-79214e080000 pid=2126 execve guuid=88d2426f-1c00-0000-b59a-792159080000 pid=2137 /usr/bin/wget net send-data write-file guuid=9d11300f-1c00-0000-b59a-7921be070000 pid=1982->guuid=88d2426f-1c00-0000-b59a-792159080000 pid=2137 execve 0eae001c-4ad4-599c-ab6a-77d3fac12203 176.65.139.211:80 guuid=88d2426f-1c00-0000-b59a-792159080000 pid=2137->0eae001c-4ad4-599c-ab6a-77d3fac12203 send: 135B
Result
Threat name:
Detection:
malicious
Classification:
troj
Score:
64 / 100
Signature
Antivirus detection for dropped file
Malicious sample detected (through community Yara rule)
Yara detected Ladvix
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1955920 Sample: main.elf Startdate: 11/08/2026 Architecture: LINUX Score: 64 33 176.65.139.211, 60232, 80 STORMINDUSTRIESHostingServicesUS Netherlands 2->33 35 Malicious sample detected (through community Yara rule) 2->35 37 Antivirus detection for dropped file 2->37 39 Yara detected Ladvix 2->39 8 main.elf 2->8         started        10 xfce4-panel wrapper-2.0 2->10         started        12 xfce4-panel wrapper-2.0 2->12         started        14 6 other processes 2->14 signatures3 process4 process5 16 main.elf bash 8->16         started        18 main.elf 8->18         started        20 wrapper-2.0 xfpm-power-backlight-helper 10->20         started        process6 22 bash wget 16->22         started        25 bash pkill 16->25         started        27 bash pkill 16->27         started        29 15 other processes 16->29 file7 31 /tmp/ffmpeg, ELF 22->31 dropped
Result
Malware family:
Score:
  10/10
Tags:
family:ladvix discovery infector linux trojan
Behaviour
Enumerates kernel/hardware configuration
Reads runtime system information
Writes file to tmp directory
Reads CPU attributes
Enumerates running processes
Family: Ladvix
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:DetectGoMethodSignatures
Author:Wyatt Tauber
Description:Detects Go method signatures in unpacked Go binaries
Rule name:Detect_Go_GOMAXPROCS
Author:Obscurity Labs LLC
Description:Detects Go binaries by the presence of runtime.GOMAXPROCS in the runtime metadata
Rule name:F01_s1ckrule
Author:s1ckb017
Rule name:GoBinTest
Rule name:golang
Rule name:golang_binary_string
Description:Golang strings present
Rule name:golang_duffcopy_amd64
Rule name:Golang_Find_CSC846
Author:Ashar Siddiqui
Description:Find Go Signatuers
Rule name:Golang_Find_CSC846_Simple
Author:Ashar Siddiqui
Description:Find Go Signatuers
Rule name:identity_golang
Author:Eric Yocam
Description:find Golang malware
Rule name:ProgramLanguage_Golang
Author:albertzsigovits
Description:Application written in Golang programming language
Rule name:Suspicious_Golang_Binary
Author:Tim Machac
Description:Triage: Golang-compiled binary with suspicious OS/persistence/network strings (not family-specific)
Rule name:TH_Generic_MassHunt_Linux_Malware_2026_CYFARE
Author:CYFARE
Description:Generic Linux malware mass-hunt rule - 2026
Reference:https://cyfare.net/
Rule name:unixredflags3
Author:Tim Brown @timb_machine
Description:Hunts for UNIX red flags

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Ladvix

elf 66cfedb8a0fbf80f79f803e2b7ec815db887298e0b16907a6b358efdf37789c2

(this sample)

Comments