MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 6a9e550f1ab8a1ce3c2ad9381f4d1d793939bc4ed0949208ddae4c91d71e56c3. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 9


Intelligence 9 IOCs YARA 3 File information Comments

SHA256 hash: 6a9e550f1ab8a1ce3c2ad9381f4d1d793939bc4ed0949208ddae4c91d71e56c3
SHA3-384 hash: 931e71a382de9b4d4091431eccd7ee61b3465ec6a043e3abcc67beb563dbac42f44284937060db4e31c8322b06d40e0d
SHA1 hash: 1c5b3d8554b8e45e9824f45564037dc009d50ba6
MD5 hash: db9fa9d96bc21525e630f8aea018da6e
humanhash: india-september-connecticut-west
File name:i686
Download: download sample
File size:587'764 bytes
First seen:2025-07-15 05:19:23 UTC
Last seen:Never
File type: elf
MIME type:application/x-executable
ssdeep 12288:5D+Azf/CVCW3ISw+hRNb3W/aTyA9VV/cZWLnR98V+:5D+AznCVNIZ+vNbG/WYWrR98V
TLSH T1B9C42241EAB7C0F2F65349320103E7BF8F33C9099165D2A6D742F661EDB1B424A9E66C
TrID 50.1% (.) ELF Executable and Linkable format (Linux) (4022/12)
49.8% (.O) ELF Executable and Linkable format (generic) (4000/1)
Magika elf
Reporter abuse_ch
Tags:elf

Intelligence


File Origin
# of uploads :
1
# of downloads :
20
Origin country :
DE DE
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
DNS request
Creates directories
Locks files
Changes access rights for a written file
Changes the time when the file was created, accessed, or modified
Creating a process from a recently created file
Collects information on the CPU
Receives data from a server
Runs as daemon
Creating a file
Creating a file in the %temp% directory
Opens a port
Launching a process
Sends data to a server
Connection attempt
Creates or modifies files in /cron to set up autorun
Verdict:
Unknown
Threat level:
  2.5/10
Confidence:
100%
Tags:
exploit gcc rust
Verdict:
Malicious
Uses P2P?:
true
Uses anti-vm?:
true
Architecture:
x86
Packer:
custom
Botnet:
unknown
Number of open files:
72
Number of processes launched:
10
Processes remaning?
false
Remote TCP ports scanned:
not identified
Behaviour
Anti-VM
Botnet C2s
TCP botnet C2(s):
not identified
UDP botnet C2(s):
type: 162.159.200.123:123
type: 130.239.18.158:6881
type: 67.215.246.10:6881
type: 176.110.250.22:6881
type: 24.121.1.151:6881
type: 46.147.189.73:6881
type: 95.79.69.93:6881
type: 46.0.52.88:6881
type: 84.28.2.133:6881
type: 194.8.131.111:6881
type: 151.80.28.149:6881
type: 68.32.240.34:6881
type: 176.125.139.123:6881
type: 89.207.71.47:6881
type: 188.42.55.92:6881
type: 151.67.121.40:6881
type: 87.98.162.88:6881
type: 31.135.107.212:6881
type: 81.42.195.81:6881
type: 185.21.217.78:6881
type: 176.195.106.252:6881
type: 170.253.62.66:6881
type: 126.79.42.70:6881
type: 77.106.75.130:6881
type: 46.0.14.81:6881
type: 46.35.235.1:6881
type: 35.155.156.153:6881
type: 88.175.238.147:6881
type: 54.70.174.84:6881
type: 91.164.29.12:6881
type: 78.62.16.93:6881
type: 196.210.4.37:6881
type: 18.221.7.72:6881
type: 18.188.31.0:6881
type: 90.253.57.211:6881
type: 186.39.109.30:6881
type: 104.15.228.85:6881
type: 106.249.226.130:6881
type: 142.171.58.199:6881
type: 23.95.192.22:6881
type: 171.120.217.242:6881
type: 185.182.207.31:6881
type: 54.214.62.55:6881
type: 18.191.2.28:6881
type: 223.85.54.241:6881
type: 35.163.251.58:6881
type: 54.214.105.212:6881
type: 13.58.27.33:6881
type: 59.34.57.200:6881
type: 77.249.250.251:6881
type: 59.14.40.115:6881
type: 31.210.192.186:6881
type: 93.226.139.30:6881
type: 78.22.2.120:6881
type: 94.62.162.156:6881
type: 93.108.220.44:6881
type: 218.218.39.42:6881
type: 130.239.18.158:8516
type: 69.164.203.179:6880
type: 195.154.233.74:6880
type: 100.24.111.119:6880
type: 154.202.133.136:6880
type: 148.153.188.242:6880
type: 3.130.60.88:6880
type: 54.144.88.168:6880
type: 185.196.61.129:6880
type: 18.188.239.31:6880
type: 45.203.206.54:6880
type: 173.230.130.111:6880
type: 52.15.134.118:6880
type: 3.15.85.168:6880
type: 185.196.61.72:6880
type: 3.233.84.65:6880
type: 45.56.122.13:6880
type: 23.95.73.62:6880
type: 198.100.145.91:51413
type: 217.182.78.204:51413
type: 109.194.107.65:51413
type: 193.32.16.100:51413
type: 51.15.64.45:51413
type: 65.108.70.96:51413
type: 94.75.250.165:51413
type: 5.35.114.10:51413
type: 81.171.3.160:51413
type: 95.236.44.165:51413
type: 82.174.219.137:51413
type: 5.79.102.206:51413
type: 106.139.76.249:51413
type: 73.43.171.22:51413
type: 77.126.4.23:51413
type: 108.180.109.252:51413
type: 106.166.78.98:51413
type: 125.63.26.109:51413
type: 107.191.101.251:51413
type: 188.165.216.84:51413
type: 188.165.235.164:51413
type: 51.38.57.48:51413
type: 83.6.63.156:51413
type: 178.169.108.200:51413
type: 46.126.171.41:51413
type: 109.238.137.97:51413
type: 176.22.41.80:51413
type: 185.203.56.35:31844
type: 130.239.18.158:8580
type: 178.162.173.157:28003
type: 178.162.174.178:28003
type: 178.162.173.91:28003
type: 178.162.173.218:28003
type: 178.162.174.26:28003
type: 130.239.18.158:8597
type: 62.212.81.233:28009
type: 178.162.173.24:28009
type: 95.211.247.101:28002
type: 95.168.170.152:28002
type: 178.162.173.199:28002
type: 137.220.67.138:60280
type: 178.162.173.231:28001
type: 178.162.174.149:28001
type: 178.162.173.16:28001
type: 95.168.162.161:42670
type: 185.156.42.10:64610
type: 130.239.18.158:8500
type: 130.239.18.158:8603
type: 178.162.174.9:28004
type: 178.162.174.43:28004
type: 37.48.71.221:28004
type: 95.211.198.83:28004
type: 140.245.76.181:9081
type: 135.181.227.244:50000
type: 135.181.238.57:50000
type: 178.162.174.222:28014
type: 178.162.174.229:28014
type: 178.162.174.241:28014
type: 130.239.18.158:8524
type: 130.239.18.158:8515
type: 185.149.91.13:51005
type: 5.79.74.28:44423
type: 185.203.56.57:32593
type: 202.61.254.66:11505
type: 212.7.209.208:28006
type: 75.156.24.185:59786
type: 5.79.87.194:28013
type: 178.162.173.91:28013
type: 178.162.173.75:28013
type: 178.162.173.205:28013
type: 178.162.174.43:28013
type: 130.239.18.158:8539
type: 162.251.63.120:10022
type: 178.162.174.5:28015
type: 193.32.2.180:51389
type: 185.220.69.92:51389
type: 162.251.63.120:10054
type: 179.42.109.190:4595
type: 172.111.38.128:26064
type: 49.206.245.162:37706
type: 80.220.70.119:37085
type: 182.233.97.138:22526
type: 24.117.247.25:36199
type: 62.210.209.154:30725
type: 178.162.174.165:28007
type: 178.162.173.149:28007
type: 178.162.173.232:28007
type: 178.162.173.36:28007
type: 212.7.203.229:53574
type: 178.162.174.40:28012
type: 178.162.173.139:28012
type: 95.211.198.95:28011
type: 178.162.174.75:28011
type: 217.215.86.26:56740
type: 69.50.95.40:12031
type: 69.50.95.40:10085
type: 211.224.92.61:41056
type: 178.162.174.38:28005
type: 212.7.209.208:28005
type: 178.162.174.239:28008
type: 178.162.174.165:28008
type: 178.162.173.161:28008
type: 152.67.73.166:32822
type: 69.50.95.40:10014
type: 193.23.250.51:55935
type: 95.217.59.70:8999
type: 185.149.91.147:51112
type: 178.162.173.166:28000
type: 158.69.27.241:43789
type: 130.239.18.158:8526
type: 130.239.18.158:8513
type: 27.93.18.132:26893
type: 195.154.184.71:56006
type: 164.160.48.50:35885
type: 85.235.66.132:23334
type: 70.53.61.43:20657
type: 177.230.98.33:7340
type: 116.88.136.183:23630
type: 188.149.109.39:7103
type: 104.254.90.218:29958
type: 178.168.220.45:20492
type: 62.112.10.81:6885
type: 43.129.42.197:10020
type: 36.88.103.26:6889
type: 93.232.70.66:6889
type: 220.212.26.165:6889
type: 45.45.127.92:6889
type: 89.188.242.205:6889
type: 80.86.151.81:6889
type: 80.121.248.174:6889
type: 46.232.210.32:64022
type: 178.162.173.51:28010
type: 94.140.5.57:64125
type: 80.2.81.31:31715
type: 57.129.45.79:8654
type: 195.154.172.179:27928
type: 38.25.29.233:5626
type: 156.57.106.48:19344
type: 176.98.17.31:23071
type: 60.122.250.158:9835
type: 154.70.25.66:61377
type: 178.61.176.35:55795
type: 54.194.135.233:6992
type: 82.150.169.66:63580
type: 45.87.251.11:28160
type: 118.217.236.130:8005
type: 175.143.230.167:19836
type: 220.70.227.235:38882
type: 186.235.38.206:45542
type: 69.243.154.205:60885
type: 182.218.135.20:41157
type: 182.161.246.16:7777
type: 124.59.63.4:15147
type: 175.34.1.42:49001
type: 89.107.33.5:49001
type: 181.28.244.232:64820
type: 223.187.23.140:44489
type: 131.161.79.177:22774
type: 124.177.207.160:56247
type: 158.174.48.28:55026
type: 70.162.191.223:13999
type: 78.160.81.134:29798
type: 54.39.52.64:23883
type: 208.87.240.21:11158
type: 31.134.188.131:2150
type: 68.108.141.73:11061
type: 5.79.66.16:52210
type: 95.211.247.106:28016
type: 162.251.63.79:55379
type: 213.134.167.61:14204
type: 150.242.87.41:5142
type: 37.27.113.233:58011
type: 186.128.217.163:43504
type: 212.129.77.234:20839
type: 185.149.91.63:51059
type: 195.154.172.179:26536
type: 18.196.86.103:6892
type: 72.21.17.103:17383
type: 185.149.91.73:51017
type: 81.201.49.4:57436
type: 84.115.232.107:5846
type: 46.232.211.96:25109
type: 195.154.167.107:8641
type: 150.230.32.254:12580
type: 185.21.216.137:50177
type: 185.107.71.107:18875
type: 182.48.210.35:28056
type: 85.225.5.18:50962
type: 38.59.187.120:18792
type: 45.159.91.9:63712
type: 45.128.27.110:54058
type: 186.177.184.213:58349
type: 5.178.170.143:59071
type: 51.75.68.29:8655
type: 37.187.102.195:5959
type: 185.203.56.49:21240
type: 92.180.8.142:18395
type: 118.45.38.47:33220
type: 98.159.234.70:56712
type: 46.117.112.179:22244
type: 176.31.251.132:61164
type: 102.158.50.255:46509
type: 119.47.168.137:14034
type: 45.91.208.120:57648
type: 183.83.216.207:17468
type: 213.230.92.217:3044
type: 188.165.198.14:52946
type: 176.59.100.232:39457
Status:
terminated
Behavior Graph:
%3 guuid=71d62ddc-1a00-0000-d7e3-3967710a0000 pid=2673 /usr/bin/sudo guuid=cf1df2de-1a00-0000-d7e3-39677a0a0000 pid=2682 /root/.sys/configuration guuid=71d62ddc-1a00-0000-d7e3-3967710a0000 pid=2673->guuid=cf1df2de-1a00-0000-d7e3-39677a0a0000 pid=2682 execve guuid=cbce2edf-1a00-0000-d7e3-39677b0a0000 pid=2683 /usr/bin/dash guuid=cf1df2de-1a00-0000-d7e3-39677a0a0000 pid=2682->guuid=cbce2edf-1a00-0000-d7e3-39677b0a0000 pid=2683 execve guuid=685eaadf-1a00-0000-d7e3-39677d0a0000 pid=2685 /usr/bin/dash guuid=cf1df2de-1a00-0000-d7e3-39677a0a0000 pid=2682->guuid=685eaadf-1a00-0000-d7e3-39677d0a0000 pid=2685 execve guuid=cf9c0be0-1a00-0000-d7e3-3967820a0000 pid=2690 /root/.sys/configuration zombie guuid=cf1df2de-1a00-0000-d7e3-39677a0a0000 pid=2682->guuid=cf9c0be0-1a00-0000-d7e3-3967820a0000 pid=2690 clone guuid=548ad8df-1a00-0000-d7e3-39677f0a0000 pid=2687 /usr/bin/dash guuid=685eaadf-1a00-0000-d7e3-39677d0a0000 pid=2685->guuid=548ad8df-1a00-0000-d7e3-39677f0a0000 pid=2687 clone guuid=f6a3dddf-1a00-0000-d7e3-3967800a0000 pid=2688 /usr/bin/dash guuid=685eaadf-1a00-0000-d7e3-39677d0a0000 pid=2685->guuid=f6a3dddf-1a00-0000-d7e3-3967800a0000 pid=2688 clone guuid=ff177ce8-1a00-0000-d7e3-39679d0a0000 pid=2717 /root/.sys/configuration guuid=cf9c0be0-1a00-0000-d7e3-3967820a0000 pid=2690->guuid=ff177ce8-1a00-0000-d7e3-39679d0a0000 pid=2717 clone guuid=da2696e8-1a00-0000-d7e3-39679e0a0000 pid=2718 /root/.sys/configuration guuid=ff177ce8-1a00-0000-d7e3-39679d0a0000 pid=2717->guuid=da2696e8-1a00-0000-d7e3-39679e0a0000 pid=2718 clone guuid=4475a8e8-1a00-0000-d7e3-3967a00a0000 pid=2720 /root/.sys/configuration dns net net-scan send-data guuid=da2696e8-1a00-0000-d7e3-39679e0a0000 pid=2718->guuid=4475a8e8-1a00-0000-d7e3-3967a00a0000 pid=2720 clone d316b2ae-0a7e-5b43-8de6-745900c90c54 127.0.0.1:65535 guuid=4475a8e8-1a00-0000-d7e3-3967a00a0000 pid=2720->d316b2ae-0a7e-5b43-8de6-745900c90c54 con 38a4910e-6f05-5afe-a8e3-398c2eb18329 time.cloudflare.com:123 guuid=4475a8e8-1a00-0000-d7e3-3967a00a0000 pid=2720->38a4910e-6f05-5afe-a8e3-398c2eb18329 send: 48B fcb96f4d-9c5e-57eb-9e6d-be4bd470f299 31.200.249.146:31924 guuid=4475a8e8-1a00-0000-d7e3-3967a00a0000 pid=2720->fcb96f4d-9c5e-57eb-9e6d-be4bd470f299 send: 68B 432f8184-be06-5a9c-a2ca-14ea69242dec 31.200.249.146:31972 guuid=4475a8e8-1a00-0000-d7e3-3967a00a0000 pid=2720->432f8184-be06-5a9c-a2ca-14ea69242dec send: 68B guuid=4475a8e8-1a00-0000-d7e3-3967a00a0000 pid=2720|send-data send-data to 270 IP addresses review logs to see them all guuid=4475a8e8-1a00-0000-d7e3-3967a00a0000 pid=2720->guuid=4475a8e8-1a00-0000-d7e3-3967a00a0000 pid=2720|send-data send
Result
Threat name:
n/a
Detection:
malicious
Classification:
troj.spyw
Score:
68 / 100
Signature
Connects to many ports of the same IP (likely port scanning)
Executes the "crontab" command typically for achieving persistence
Multi AV Scanner detection for submitted file
Opens /sys/class/net/* files useful for querying network interface information
Sample reads /proc/mounts (often used for finding a writable filesystem)
Sample tries to persist itself using cron
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1736716 Sample: i686.elf Startdate: 15/07/2025 Architecture: LINUX Score: 68 44 31.200.249.146, 31924, 48170 NETRACK-ASRU Russian Federation 2->44 46 14.103.100.175, 60020 WORLDPHONE-INASNumberforInterdomainRoutingIN China 2->46 48 101 other IPs or domains 2->48 50 Multi AV Scanner detection for submitted file 2->50 52 Connects to many ports of the same IP (likely port scanning) 2->52 10 dash rm i686.elf configuration 2->10         started        12 dash rm 2->12         started        14 dash head 2->14         started        16 7 other processes 2->16 signatures3 process4 process5 18 i686.elf sh 10->18         started        20 configuration 10->20         started        23 i686.elf sh 10->23         started        signatures6 25 sh crontab 18->25         started        29 sh 18->29         started        56 Opens /sys/class/net/* files useful for querying network interface information 20->56 58 Sample reads /proc/mounts (often used for finding a writable filesystem) 20->58 31 configuration 20->31         started        33 sh crontab 23->33         started        process7 file8 42 /var/spool/cron/crontabs/tmp.vR2hxH, ASCII 25->42 dropped 60 Sample tries to persist itself using cron 25->60 62 Executes the "crontab" command typically for achieving persistence 25->62 35 sh crontab 29->35         started        38 configuration 31->38         started        signatures9 process10 signatures11 54 Executes the "crontab" command typically for achieving persistence 35->54 40 configuration 38->40         started        process12
Threat name:
Linux.Trojan.Multiverze
Status:
Malicious
First seen:
2025-07-15 05:20:36 UTC
File Type:
ELF32 Little (Exe)
AV detection:
15 of 24 (62.50%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
execution linux persistence privilege_escalation rootkit
Behaviour
Creates/modifies Cron job
Loads a kernel module
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:linux_generic_ipv6_catcher
Author:@_lubiedo
Description:ELF samples using IPv6 addresses
Rule name:Sus_Obf_Enc_Spoof_Hide_PE
Author:XiAnzheng
Description:Check for Overlay, Obfuscating, Encrypting, Spoofing, Hiding, or Entropy Technique(can create FP)
Rule name:unixredflags3
Author:Tim Brown @timb_machine
Description:Hunts for UNIX red flags

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

elf 6a9e550f1ab8a1ce3c2ad9381f4d1d793939bc4ed0949208ddae4c91d71e56c3

(this sample)

  
Delivery method
Distributed via web download

Comments