🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 6edbf7cf9096032aced5be03ae2667bc149579f7a5ea45016a1a5a08b1b73ee4. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA 2 File information Comments

SHA256 hash: 6edbf7cf9096032aced5be03ae2667bc149579f7a5ea45016a1a5a08b1b73ee4
SHA3-384 hash: 13ed6180eea6af0323258a1bceeaacebf4a4ccfa4b17820d70f2cf8d05fd9872d44c094dde5ba75c9d93fb043234b67e
SHA1 hash: cdb28a65e70b9b686fe21cebf607f2c50360f6c8
MD5 hash: 24eb8c05e7e4633390959afb63953195
humanhash: ohio-william-alpha-zebra
File name:i686
Download: download sample
File size:25'600 bytes
First seen:2026-09-23 23:27:46 UTC
Last seen:Never
File type: elf
MIME type:application/x-executable
ssdeep 768:YNAiuYEgHskm7vllyanuUWhpDk95qgYgt:YGwEg+plNuUC85ggt
TLSH T149B21A80E587E0F4D82B46B980E2B63E9331D5197514D91AFF719BBDEE23D429B0B309
telfhash t11f01c8a97e2524f1f7c2bc4c8b1d5703e3369ef6462274b584f5121137d2245d172545
TrID 50.1% (.) ELF Executable and Linkable format (Linux) (4022/12)
49.8% (.O) ELF Executable and Linkable format (generic) (4000/1)
Magika elf
Reporter abuse_ch
Tags:elf upx-dec


Avatar
abuse_ch
UPX decompressed file, sourced from SHA256 810aa7094f177ecddc775ce80484a60207cc3e00ab0b70edc8d1235ff3793513
File size (compressed) :16'232 bytes
File size (de-compressed) :25'600 bytes
Format:linux/i386
Packed file: 810aa7094f177ecddc775ce80484a60207cc3e00ab0b70edc8d1235ff3793513

Intelligence


File Origin
# of uploads :
1
# of downloads :
55
Origin country :
NL NL
Vendor Threat Intelligence
No detections
Result
Verdict:
Clean
Maliciousness:

Behaviour
Connection attempt
Runs as daemon
Verdict:
Malicious
Uses P2P?:
false
Uses anti-vm?:
false
Architecture:
x86
Packer:
not packed
Botnet:
unknown
Number of open files:
0
Number of processes launched:
3
Processes remaning?
false
Remote TCP ports scanned:
not identified
Behaviour
no suspicious findings
Botnet C2s
TCP botnet C2(s):
not identified
UDP botnet C2(s):
not identified
Status:
terminated
Behavior Graph:
%3 guuid=3144181e-1d00-0000-28bb-b67700080000 pid=2048 /usr/bin/sudo guuid=94251623-1d00-0000-28bb-b67707080000 pid=2055 /tmp/sample.bin guuid=3144181e-1d00-0000-28bb-b67700080000 pid=2048->guuid=94251623-1d00-0000-28bb-b67707080000 pid=2055 execve guuid=055a5623-1d00-0000-28bb-b67708080000 pid=2056 /tmp/sample.bin guuid=94251623-1d00-0000-28bb-b67707080000 pid=2055->guuid=055a5623-1d00-0000-28bb-b67708080000 pid=2056 clone guuid=379a6c23-1d00-0000-28bb-b6770a080000 pid=2058 /tmp/sample.bin net zombie guuid=055a5623-1d00-0000-28bb-b67708080000 pid=2056->guuid=379a6c23-1d00-0000-28bb-b6770a080000 pid=2058 clone 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=379a6c23-1d00-0000-28bb-b6770a080000 pid=2058->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con 360be839-7be4-574d-ba18-54d785054f9d 176.65.139.158:6722 guuid=379a6c23-1d00-0000-28bb-b6770a080000 pid=2058->360be839-7be4-574d-ba18-54d785054f9d con
Gathering data
Result
Threat name:
n/a
Detection:
malicious
Classification:
n/a
Score:
48 / 100
Signature
Malicious sample detected (through community Yara rule)
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1977089 Sample: i686.elf Startdate: 24/09/2026 Architecture: LINUX Score: 48 16 176.65.139.158, 49178, 49180, 49182 STORMINDUSTRIESHostingServicesUS Netherlands 2->16 18 daisy.ubuntu.com 2->18 20 Malicious sample detected (through community Yara rule) 2->20 8 i686.elf 2->8         started        10 python3.8 dpkg 2->10         started        signatures3 process4 process5 12 i686.elf 8->12         started        process6 14 i686.elf 12->14         started       
Result
Malware family:
n/a
Score:
  1/10
Tags:
linux
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Linux_Trojan_Mirai_cc93863b
Author:Elastic Security
Rule name:TH_Generic_MassHunt_Linux_Malware_2026_CYFARE
Author:CYFARE
Description:Generic Linux malware mass-hunt rule - 2026
Reference:https://cyfare.net/

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

elf 6edbf7cf9096032aced5be03ae2667bc149579f7a5ea45016a1a5a08b1b73ee4

(this sample)

  
Delivery method
Distributed via web download

Comments