MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 69b89845c4f4d92ac33a7cecb47b1eee08e626966ca63b2c537dbe39940ca0b3. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA 2 File information Comments

SHA256 hash: 69b89845c4f4d92ac33a7cecb47b1eee08e626966ca63b2c537dbe39940ca0b3
SHA3-384 hash: 0f2324367cb811b91e5eade0804477ef4ac8500b50c378dfa1692ca049916996444bcadac872b71aac7f2dd037afbbb2
SHA1 hash: b0327beb3de77d276c735d0e66c3b8ec652951ea
MD5 hash: d6aa4e0a37dc990ea0fd934f2e9e11f5
humanhash: south-green-march-carpet
File name:systemdd
Download: download sample
File size:62'760 bytes
First seen:2026-04-28 18:49:11 UTC
Last seen:Never
File type: elf
MIME type:application/x-executable
ssdeep 1536:fTpKcj0X4y3Z2JAv+btwrag7dwlMd34AD0iUr:f1KbIy3ZuAmbtgelMdo/
TLSH T191532A07A1D360FCC18BD1748A6BD523AE32789412343A7F2BCCEE752E55E52276DB24
telfhash t156216fb159d624e461fbee22a315f0748c351d6212f032f196797caada61b410a81c22
TrID 50.1% (.) ELF Executable and Linkable format (Linux) (4022/12)
49.8% (.O) ELF Executable and Linkable format (generic) (4000/1)
Magika elf
Reporter smica83
Tags:elf

Intelligence


File Origin
# of uploads :
1
# of downloads :
52
Origin country :
HU HU
Vendor Threat Intelligence
No detections
Result
Verdict:
Clean
Maliciousness:

Behaviour
Launching a process
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
base64 bash gcc lolbin
Verdict:
Malicious
Uses P2P?:
false
Uses anti-vm?:
false
Architecture:
x86
Packer:
not packed
Botnet:
unknown
Number of open files:
14
Number of processes launched:
150
Processes remaning?
true
Remote TCP ports scanned:
not identified
Behaviour
Process Renaming
Botnet C2s
TCP botnet C2(s):
not identified
UDP botnet C2(s):
not identified
Verdict:
Unknown
File Type:
elf.64.le
First seen:
2026-04-26T17:30:00Z UTC
Last seen:
2026-04-26T17:49:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=5953452b-1700-0000-8f9a-9b8c520e0000 pid=3666 /usr/bin/sudo guuid=7db1052d-1700-0000-8f9a-9b8c570e0000 pid=3671 /tmp/sample.bin net send-data guuid=5953452b-1700-0000-8f9a-9b8c520e0000 pid=3666->guuid=7db1052d-1700-0000-8f9a-9b8c570e0000 pid=3671 execve 1cfe7a81-a679-59ee-b435-26af80e95ce4 176.125.240.169:80 guuid=7db1052d-1700-0000-8f9a-9b8c570e0000 pid=3671->1cfe7a81-a679-59ee-b435-26af80e95ce4 send: 256B guuid=10b7282d-1700-0000-8f9a-9b8c5b0e0000 pid=3675 /usr/bin/dash guuid=7db1052d-1700-0000-8f9a-9b8c570e0000 pid=3671->guuid=10b7282d-1700-0000-8f9a-9b8c5b0e0000 pid=3675 execve guuid=6ab9f62d-1700-0000-8f9a-9b8c5e0e0000 pid=3678 /usr/bin/dash guuid=7db1052d-1700-0000-8f9a-9b8c570e0000 pid=3671->guuid=6ab9f62d-1700-0000-8f9a-9b8c5e0e0000 pid=3678 execve guuid=9951b22a-2500-0000-8f9a-9b8c9a140000 pid=5274 /usr/bin/dash guuid=7db1052d-1700-0000-8f9a-9b8c570e0000 pid=3671->guuid=9951b22a-2500-0000-8f9a-9b8c9a140000 pid=5274 execve guuid=6c83a92b-2500-0000-8f9a-9b8c9c140000 pid=5276 /usr/bin/dash guuid=7db1052d-1700-0000-8f9a-9b8c570e0000 pid=3671->guuid=6c83a92b-2500-0000-8f9a-9b8c9c140000 pid=5276 execve guuid=df3c462c-2500-0000-8f9a-9b8c9f140000 pid=5279 /usr/bin/dash guuid=7db1052d-1700-0000-8f9a-9b8c570e0000 pid=3671->guuid=df3c462c-2500-0000-8f9a-9b8c9f140000 pid=5279 execve guuid=3b13522d-1700-0000-8f9a-9b8c5c0e0000 pid=3676 /usr/bin/whoami guuid=10b7282d-1700-0000-8f9a-9b8c5b0e0000 pid=3675->guuid=3b13522d-1700-0000-8f9a-9b8c5c0e0000 pid=3676 execve guuid=04bd1f2e-1700-0000-8f9a-9b8c600e0000 pid=3680 /usr/bin/whoami guuid=6ab9f62d-1700-0000-8f9a-9b8c5e0e0000 pid=3678->guuid=04bd1f2e-1700-0000-8f9a-9b8c600e0000 pid=3680 execve guuid=0baa022b-2500-0000-8f9a-9b8c9b140000 pid=5275 /usr/bin/whoami guuid=9951b22a-2500-0000-8f9a-9b8c9a140000 pid=5274->guuid=0baa022b-2500-0000-8f9a-9b8c9b140000 pid=5275 execve guuid=e421db2b-2500-0000-8f9a-9b8c9d140000 pid=5277 /usr/bin/hostname guuid=6c83a92b-2500-0000-8f9a-9b8c9c140000 pid=5276->guuid=e421db2b-2500-0000-8f9a-9b8c9d140000 pid=5277 execve guuid=91f2802c-2500-0000-8f9a-9b8ca0140000 pid=5280 /usr/bin/cat guuid=df3c462c-2500-0000-8f9a-9b8c9f140000 pid=5279->guuid=91f2802c-2500-0000-8f9a-9b8ca0140000 pid=5280 execve guuid=7bab862c-2500-0000-8f9a-9b8ca1140000 pid=5281 /usr/bin/grep guuid=df3c462c-2500-0000-8f9a-9b8c9f140000 pid=5279->guuid=7bab862c-2500-0000-8f9a-9b8ca1140000 pid=5281 execve guuid=afb58c2c-2500-0000-8f9a-9b8ca2140000 pid=5282 /usr/bin/cut guuid=df3c462c-2500-0000-8f9a-9b8c9f140000 pid=5279->guuid=afb58c2c-2500-0000-8f9a-9b8ca2140000 pid=5282 execve guuid=1933912c-2500-0000-8f9a-9b8ca3140000 pid=5283 /usr/bin/tr guuid=df3c462c-2500-0000-8f9a-9b8c9f140000 pid=5279->guuid=1933912c-2500-0000-8f9a-9b8ca3140000 pid=5283 execve
Malware family:
Gunra Ransomware
Verdict:
Malicious
Result
Threat name:
n/a
Detection:
clean
Classification:
n/a
Score:
3 / 100
Behaviour
Behavior Graph:
n/a
Result
Malware family:
n/a
Score:
  1/10
Tags:
linux
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:TH_Generic_MassHunt_Linux_Malware_2026_CYFARE
Author:CYFARE
Description:Generic Linux malware mass-hunt rule - 2026
Reference:https://cyfare.net/
Rule name:unixredflags3
Author:Tim Brown @timb_machine
Description:Hunts for UNIX red flags

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments