MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 6fddaa099096c0caee183e4bb95e9fe79003e6ae6dc41d6b1aa3b4aec221bd38. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



BillGates


Vendor detections: 11


Intelligence 11 IOCs YARA 11 File information Comments

SHA256 hash: 6fddaa099096c0caee183e4bb95e9fe79003e6ae6dc41d6b1aa3b4aec221bd38
SHA3-384 hash: 4dcb6035e6afa0fdfd310b606b3875613cce8a97ccebd00ae5c601d1060e2d6fd832f790e0317a659a4995db52411156
SHA1 hash: 72137e0ed1aa66fb200a55d0404801549af58776
MD5 hash: fece4fd024cd968522e2450c1cc4420f
humanhash: butter-burger-alpha-sierra
File name:kswpad
Download: download sample
Signature BillGates
File size:1'223'123 bytes
First seen:2026-03-14 08:37:12 UTC
Last seen:Never
File type: elf
MIME type:application/x-executable
ssdeep 24576:e845rGHu6gVJKG75oFpA0VWeX4Q2y1q2rJp0:745vRVJKGtSA0VWeonu9p0
TLSH T1DC456B12FBD0CCB1D84616F5100FDA35D5229677A01BCA4FEA5DCD38BB29181AB1A37E
telfhash t1e3018946923c19882ea2ed54cc6127d354dbc16a2691e768fb8acdc4994e80af574c0f
TrID 50.1% (.) ELF Executable and Linkable format (Linux) (4022/12)
49.8% (.O) ELF Executable and Linkable format (generic) (4000/1)
Magika elf
Reporter abuse_ch
Tags:BillGates elf

Intelligence


File Origin
# of uploads :
1
# of downloads :
93
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
billgates elknot gcc
Verdict:
Malicious
Uses P2P?:
false
Uses anti-vm?:
true
Architecture:
x86
Packer:
not packed
Botnet:
unknown
Number of open files:
34
Number of processes launched:
61
Processes remaning?
false
Remote TCP ports scanned:
not identified
Behaviour
Anti-VM
Persistence
Information Gathering
Kernel Modules
Botnet C2s
TCP botnet C2(s):
not identified
UDP botnet C2(s):
not identified
Verdict:
Malicious
File Type:
elf.32.le
Detections:
HEUR:Backdoor.Linux.Ganiw.d HEUR:Backdoor.Linux.Ganiw.a
Status:
terminated
Behavior Graph:
%3 guuid=ac164677-1a00-0000-2a0c-81b02e090000 pid=2350 /usr/bin/sudo guuid=537b2579-1a00-0000-2a0c-81b033090000 pid=2355 /tmp/sample.bin guuid=ac164677-1a00-0000-2a0c-81b02e090000 pid=2350->guuid=537b2579-1a00-0000-2a0c-81b033090000 pid=2355 execve guuid=42ed878b-1a00-0000-2a0c-81b05d090000 pid=2397 /tmp/sample.bin write-config write-file zombie guuid=537b2579-1a00-0000-2a0c-81b033090000 pid=2355->guuid=42ed878b-1a00-0000-2a0c-81b05d090000 pid=2397 clone guuid=bdd60f3f-1b00-0000-2a0c-81b0ca0a0000 pid=2762 /usr/bin/dash guuid=42ed878b-1a00-0000-2a0c-81b05d090000 pid=2397->guuid=bdd60f3f-1b00-0000-2a0c-81b0ca0a0000 pid=2762 execve guuid=0f9f1040-1b00-0000-2a0c-81b0cf0a0000 pid=2767 /usr/bin/dash guuid=42ed878b-1a00-0000-2a0c-81b05d090000 pid=2397->guuid=0f9f1040-1b00-0000-2a0c-81b0cf0a0000 pid=2767 execve guuid=95bbef40-1b00-0000-2a0c-81b0d10a0000 pid=2769 /usr/bin/dash guuid=42ed878b-1a00-0000-2a0c-81b05d090000 pid=2397->guuid=95bbef40-1b00-0000-2a0c-81b0d10a0000 pid=2769 execve guuid=1dd8f241-1b00-0000-2a0c-81b0d40a0000 pid=2772 /usr/bin/dash guuid=42ed878b-1a00-0000-2a0c-81b05d090000 pid=2397->guuid=1dd8f241-1b00-0000-2a0c-81b0d40a0000 pid=2772 execve guuid=c643b742-1b00-0000-2a0c-81b0d80a0000 pid=2776 /usr/bin/dash guuid=42ed878b-1a00-0000-2a0c-81b05d090000 pid=2397->guuid=c643b742-1b00-0000-2a0c-81b0d80a0000 pid=2776 execve guuid=c65892ba-1b00-0000-2a0c-81b0a20b0000 pid=2978 /usr/bin/dash guuid=42ed878b-1a00-0000-2a0c-81b05d090000 pid=2397->guuid=c65892ba-1b00-0000-2a0c-81b0a20b0000 pid=2978 execve guuid=515ac4bb-1b00-0000-2a0c-81b0a70b0000 pid=2983 /usr/bin/dash guuid=42ed878b-1a00-0000-2a0c-81b05d090000 pid=2397->guuid=515ac4bb-1b00-0000-2a0c-81b0a70b0000 pid=2983 execve guuid=6ec860bc-1b00-0000-2a0c-81b0aa0b0000 pid=2986 /usr/bin/dash guuid=42ed878b-1a00-0000-2a0c-81b05d090000 pid=2397->guuid=6ec860bc-1b00-0000-2a0c-81b0aa0b0000 pid=2986 execve guuid=63c0d4fb-1b00-0000-2a0c-81b0350c0000 pid=3125 /tmp/sample.bin guuid=42ed878b-1a00-0000-2a0c-81b05d090000 pid=2397->guuid=63c0d4fb-1b00-0000-2a0c-81b0350c0000 pid=3125 clone guuid=1fb34a0e-1c00-0000-2a0c-81b06b0c0000 pid=3179 /usr/bin/dash guuid=42ed878b-1a00-0000-2a0c-81b05d090000 pid=2397->guuid=1fb34a0e-1c00-0000-2a0c-81b06b0c0000 pid=3179 execve guuid=16fa000f-1c00-0000-2a0c-81b06f0c0000 pid=3183 /usr/bin/dash guuid=42ed878b-1a00-0000-2a0c-81b05d090000 pid=2397->guuid=16fa000f-1c00-0000-2a0c-81b06f0c0000 pid=3183 execve guuid=7083970f-1c00-0000-2a0c-81b0720c0000 pid=3186 /usr/bin/dash guuid=42ed878b-1a00-0000-2a0c-81b05d090000 pid=2397->guuid=7083970f-1c00-0000-2a0c-81b0720c0000 pid=3186 execve guuid=f3dd4d4c-1c00-0000-2a0c-81b0c80c0000 pid=3272 /tmp/sample.bin guuid=42ed878b-1a00-0000-2a0c-81b05d090000 pid=2397->guuid=f3dd4d4c-1c00-0000-2a0c-81b0c80c0000 pid=3272 clone guuid=3aca13d9-1c00-0000-2a0c-81b0030e0000 pid=3587 /usr/bin/dash guuid=42ed878b-1a00-0000-2a0c-81b05d090000 pid=2397->guuid=3aca13d9-1c00-0000-2a0c-81b0030e0000 pid=3587 execve guuid=42ed878b-1a00-0000-2a0c-81b05d090000 pid=3589 /tmp/sample.bin guuid=42ed878b-1a00-0000-2a0c-81b05d090000 pid=2397->guuid=42ed878b-1a00-0000-2a0c-81b05d090000 pid=3589 clone guuid=42ed878b-1a00-0000-2a0c-81b05d090000 pid=3590 /tmp/sample.bin guuid=42ed878b-1a00-0000-2a0c-81b05d090000 pid=2397->guuid=42ed878b-1a00-0000-2a0c-81b05d090000 pid=3590 clone guuid=42ed878b-1a00-0000-2a0c-81b05d090000 pid=3591 /tmp/sample.bin guuid=42ed878b-1a00-0000-2a0c-81b05d090000 pid=2397->guuid=42ed878b-1a00-0000-2a0c-81b05d090000 pid=3591 clone guuid=42ed878b-1a00-0000-2a0c-81b05d090000 pid=3592 /tmp/sample.bin guuid=42ed878b-1a00-0000-2a0c-81b05d090000 pid=2397->guuid=42ed878b-1a00-0000-2a0c-81b05d090000 pid=3592 clone guuid=42ed878b-1a00-0000-2a0c-81b05d090000 pid=3593 /tmp/sample.bin guuid=42ed878b-1a00-0000-2a0c-81b05d090000 pid=2397->guuid=42ed878b-1a00-0000-2a0c-81b05d090000 pid=3593 clone guuid=42ed878b-1a00-0000-2a0c-81b05d090000 pid=3594 /tmp/sample.bin guuid=42ed878b-1a00-0000-2a0c-81b05d090000 pid=2397->guuid=42ed878b-1a00-0000-2a0c-81b05d090000 pid=3594 clone guuid=42ed878b-1a00-0000-2a0c-81b05d090000 pid=3595 /tmp/sample.bin guuid=42ed878b-1a00-0000-2a0c-81b05d090000 pid=2397->guuid=42ed878b-1a00-0000-2a0c-81b05d090000 pid=3595 clone guuid=42ed878b-1a00-0000-2a0c-81b05d090000 pid=3596 /tmp/sample.bin guuid=42ed878b-1a00-0000-2a0c-81b05d090000 pid=2397->guuid=42ed878b-1a00-0000-2a0c-81b05d090000 pid=3596 clone guuid=42ed878b-1a00-0000-2a0c-81b05d090000 pid=3597 /tmp/sample.bin dns net send-data write-file zombie guuid=42ed878b-1a00-0000-2a0c-81b05d090000 pid=2397->guuid=42ed878b-1a00-0000-2a0c-81b05d090000 pid=3597 clone guuid=c06b593f-1b00-0000-2a0c-81b0cc0a0000 pid=2764 /usr/bin/ln guuid=bdd60f3f-1b00-0000-2a0c-81b0ca0a0000 pid=2762->guuid=c06b593f-1b00-0000-2a0c-81b0cc0a0000 pid=2764 execve guuid=35c66440-1b00-0000-2a0c-81b0d00a0000 pid=2768 /usr/bin/ln guuid=0f9f1040-1b00-0000-2a0c-81b0cf0a0000 pid=2767->guuid=35c66440-1b00-0000-2a0c-81b0d00a0000 pid=2768 execve guuid=82c24941-1b00-0000-2a0c-81b0d30a0000 pid=2771 /usr/bin/ln guuid=95bbef40-1b00-0000-2a0c-81b0d10a0000 pid=2769->guuid=82c24941-1b00-0000-2a0c-81b0d30a0000 pid=2771 execve guuid=b8703142-1b00-0000-2a0c-81b0d50a0000 pid=2773 /usr/bin/ln guuid=1dd8f241-1b00-0000-2a0c-81b0d40a0000 pid=2772->guuid=b8703142-1b00-0000-2a0c-81b0d50a0000 pid=2773 execve guuid=328ee442-1b00-0000-2a0c-81b0d90a0000 pid=2777 /usr/bin/ln guuid=c643b742-1b00-0000-2a0c-81b0d80a0000 pid=2776->guuid=328ee442-1b00-0000-2a0c-81b0d90a0000 pid=2777 execve guuid=f3b5d0ba-1b00-0000-2a0c-81b0a40b0000 pid=2980 /usr/bin/mkdir guuid=c65892ba-1b00-0000-2a0c-81b0a20b0000 pid=2978->guuid=f3b5d0ba-1b00-0000-2a0c-81b0a40b0000 pid=2980 execve guuid=342ef7bb-1b00-0000-2a0c-81b0a80b0000 pid=2984 /usr/bin/mkdir guuid=515ac4bb-1b00-0000-2a0c-81b0a70b0000 pid=2983->guuid=342ef7bb-1b00-0000-2a0c-81b0a80b0000 pid=2984 execve guuid=b47a8cbc-1b00-0000-2a0c-81b0ac0b0000 pid=2988 /usr/bin/cp guuid=6ec860bc-1b00-0000-2a0c-81b0aa0b0000 pid=2986->guuid=b47a8cbc-1b00-0000-2a0c-81b0ac0b0000 pid=2988 execve guuid=3e14e0fb-1b00-0000-2a0c-81b0370c0000 pid=3127 /usr/bin/dash guuid=63c0d4fb-1b00-0000-2a0c-81b0350c0000 pid=3125->guuid=3e14e0fb-1b00-0000-2a0c-81b0370c0000 pid=3127 execve guuid=a5b456fc-1b00-0000-2a0c-81b0390c0000 pid=3129 /usr/bin/bsd-port/getty guuid=3e14e0fb-1b00-0000-2a0c-81b0370c0000 pid=3127->guuid=a5b456fc-1b00-0000-2a0c-81b0390c0000 pid=3129 execve guuid=69fc130e-1c00-0000-2a0c-81b06a0c0000 pid=3178 /usr/bin/bsd-port/getty write-config write-file zombie guuid=a5b456fc-1b00-0000-2a0c-81b0390c0000 pid=3129->guuid=69fc130e-1c00-0000-2a0c-81b06a0c0000 pid=3178 clone guuid=14d3f249-1c00-0000-2a0c-81b0bc0c0000 pid=3260 /usr/bin/dash guuid=69fc130e-1c00-0000-2a0c-81b06a0c0000 pid=3178->guuid=14d3f249-1c00-0000-2a0c-81b0bc0c0000 pid=3260 execve guuid=cb1b904a-1c00-0000-2a0c-81b0be0c0000 pid=3262 /usr/bin/dash guuid=69fc130e-1c00-0000-2a0c-81b06a0c0000 pid=3178->guuid=cb1b904a-1c00-0000-2a0c-81b0be0c0000 pid=3262 execve guuid=a2f2214b-1c00-0000-2a0c-81b0c00c0000 pid=3264 /usr/bin/dash guuid=69fc130e-1c00-0000-2a0c-81b06a0c0000 pid=3178->guuid=a2f2214b-1c00-0000-2a0c-81b0c00c0000 pid=3264 execve guuid=109cb64b-1c00-0000-2a0c-81b0c40c0000 pid=3268 /usr/bin/dash guuid=69fc130e-1c00-0000-2a0c-81b06a0c0000 pid=3178->guuid=109cb64b-1c00-0000-2a0c-81b0c40c0000 pid=3268 execve guuid=befe4d4c-1c00-0000-2a0c-81b0c90c0000 pid=3273 /usr/bin/dash guuid=69fc130e-1c00-0000-2a0c-81b06a0c0000 pid=3178->guuid=befe4d4c-1c00-0000-2a0c-81b0c90c0000 pid=3273 execve guuid=ec0cf64c-1c00-0000-2a0c-81b0cf0c0000 pid=3279 /usr/bin/dash guuid=69fc130e-1c00-0000-2a0c-81b06a0c0000 pid=3178->guuid=ec0cf64c-1c00-0000-2a0c-81b0cf0c0000 pid=3279 execve guuid=b1b2874d-1c00-0000-2a0c-81b0d20c0000 pid=3282 /usr/bin/dash guuid=69fc130e-1c00-0000-2a0c-81b06a0c0000 pid=3178->guuid=b1b2874d-1c00-0000-2a0c-81b0d20c0000 pid=3282 execve guuid=69af1f4f-1c00-0000-2a0c-81b0d90c0000 pid=3289 /usr/bin/dash guuid=69fc130e-1c00-0000-2a0c-81b06a0c0000 pid=3178->guuid=69af1f4f-1c00-0000-2a0c-81b0d90c0000 pid=3289 execve guuid=d9d6d24f-1c00-0000-2a0c-81b0dc0c0000 pid=3292 /usr/bin/dash guuid=69fc130e-1c00-0000-2a0c-81b06a0c0000 pid=3178->guuid=d9d6d24f-1c00-0000-2a0c-81b0dc0c0000 pid=3292 execve guuid=22e0f950-1c00-0000-2a0c-81b0df0c0000 pid=3295 /usr/bin/dash guuid=69fc130e-1c00-0000-2a0c-81b06a0c0000 pid=3178->guuid=22e0f950-1c00-0000-2a0c-81b0df0c0000 pid=3295 execve guuid=23309c54-1c00-0000-2a0c-81b0e70c0000 pid=3303 /usr/bin/dash guuid=69fc130e-1c00-0000-2a0c-81b06a0c0000 pid=3178->guuid=23309c54-1c00-0000-2a0c-81b0e70c0000 pid=3303 execve guuid=96237355-1c00-0000-2a0c-81b0e90c0000 pid=3305 /usr/bin/dash guuid=69fc130e-1c00-0000-2a0c-81b06a0c0000 pid=3178->guuid=96237355-1c00-0000-2a0c-81b0e90c0000 pid=3305 execve guuid=838a7558-1c00-0000-2a0c-81b0eb0c0000 pid=3307 /usr/bin/dash guuid=69fc130e-1c00-0000-2a0c-81b06a0c0000 pid=3178->guuid=838a7558-1c00-0000-2a0c-81b0eb0c0000 pid=3307 execve guuid=e1004459-1c00-0000-2a0c-81b0ed0c0000 pid=3309 /usr/bin/dash guuid=69fc130e-1c00-0000-2a0c-81b06a0c0000 pid=3178->guuid=e1004459-1c00-0000-2a0c-81b0ed0c0000 pid=3309 execve guuid=762cd459-1c00-0000-2a0c-81b0ef0c0000 pid=3311 /usr/bin/dash guuid=69fc130e-1c00-0000-2a0c-81b06a0c0000 pid=3178->guuid=762cd459-1c00-0000-2a0c-81b0ef0c0000 pid=3311 execve guuid=e387bc5d-1c00-0000-2a0c-81b0f40c0000 pid=3316 /usr/bin/dash guuid=69fc130e-1c00-0000-2a0c-81b06a0c0000 pid=3178->guuid=e387bc5d-1c00-0000-2a0c-81b0f40c0000 pid=3316 execve guuid=bba0a25e-1c00-0000-2a0c-81b0f80c0000 pid=3320 /usr/bin/dash guuid=69fc130e-1c00-0000-2a0c-81b06a0c0000 pid=3178->guuid=bba0a25e-1c00-0000-2a0c-81b0f80c0000 pid=3320 execve guuid=458c585f-1c00-0000-2a0c-81b0fc0c0000 pid=3324 /usr/bin/dash guuid=69fc130e-1c00-0000-2a0c-81b06a0c0000 pid=3178->guuid=458c585f-1c00-0000-2a0c-81b0fc0c0000 pid=3324 execve guuid=7d3f3360-1c00-0000-2a0c-81b0000d0000 pid=3328 /usr/bin/dash guuid=69fc130e-1c00-0000-2a0c-81b06a0c0000 pid=3178->guuid=7d3f3360-1c00-0000-2a0c-81b0000d0000 pid=3328 execve guuid=f45c2161-1c00-0000-2a0c-81b0050d0000 pid=3333 /usr/bin/dash guuid=69fc130e-1c00-0000-2a0c-81b06a0c0000 pid=3178->guuid=f45c2161-1c00-0000-2a0c-81b0050d0000 pid=3333 execve guuid=e3b1bd61-1c00-0000-2a0c-81b00a0d0000 pid=3338 /usr/bin/dash guuid=69fc130e-1c00-0000-2a0c-81b06a0c0000 pid=3178->guuid=e3b1bd61-1c00-0000-2a0c-81b00a0d0000 pid=3338 execve guuid=969b7162-1c00-0000-2a0c-81b00e0d0000 pid=3342 /usr/bin/dash guuid=69fc130e-1c00-0000-2a0c-81b06a0c0000 pid=3178->guuid=969b7162-1c00-0000-2a0c-81b00e0d0000 pid=3342 execve guuid=91ce1a63-1c00-0000-2a0c-81b0110d0000 pid=3345 /usr/bin/dash guuid=69fc130e-1c00-0000-2a0c-81b06a0c0000 pid=3178->guuid=91ce1a63-1c00-0000-2a0c-81b0110d0000 pid=3345 execve guuid=f7ca1b64-1c00-0000-2a0c-81b0160d0000 pid=3350 /usr/bin/dash guuid=69fc130e-1c00-0000-2a0c-81b06a0c0000 pid=3178->guuid=f7ca1b64-1c00-0000-2a0c-81b0160d0000 pid=3350 execve guuid=36c664dc-1c00-0000-2a0c-81b00f0e0000 pid=3599 /usr/bin/dash guuid=69fc130e-1c00-0000-2a0c-81b06a0c0000 pid=3178->guuid=36c664dc-1c00-0000-2a0c-81b00f0e0000 pid=3599 execve guuid=69fc130e-1c00-0000-2a0c-81b06a0c0000 pid=3603 /usr/bin/bsd-port/getty guuid=69fc130e-1c00-0000-2a0c-81b06a0c0000 pid=3178->guuid=69fc130e-1c00-0000-2a0c-81b06a0c0000 pid=3603 clone guuid=69fc130e-1c00-0000-2a0c-81b06a0c0000 pid=3604 /usr/bin/bsd-port/getty guuid=69fc130e-1c00-0000-2a0c-81b06a0c0000 pid=3178->guuid=69fc130e-1c00-0000-2a0c-81b06a0c0000 pid=3604 clone guuid=69fc130e-1c00-0000-2a0c-81b06a0c0000 pid=3605 /usr/bin/bsd-port/getty guuid=69fc130e-1c00-0000-2a0c-81b06a0c0000 pid=3178->guuid=69fc130e-1c00-0000-2a0c-81b06a0c0000 pid=3605 clone guuid=69fc130e-1c00-0000-2a0c-81b06a0c0000 pid=3606 /usr/bin/bsd-port/getty guuid=69fc130e-1c00-0000-2a0c-81b06a0c0000 pid=3178->guuid=69fc130e-1c00-0000-2a0c-81b06a0c0000 pid=3606 clone guuid=69fc130e-1c00-0000-2a0c-81b06a0c0000 pid=3607 /usr/bin/bsd-port/getty guuid=69fc130e-1c00-0000-2a0c-81b06a0c0000 pid=3178->guuid=69fc130e-1c00-0000-2a0c-81b06a0c0000 pid=3607 clone guuid=69fc130e-1c00-0000-2a0c-81b06a0c0000 pid=3609 /usr/bin/bsd-port/getty guuid=69fc130e-1c00-0000-2a0c-81b06a0c0000 pid=3178->guuid=69fc130e-1c00-0000-2a0c-81b06a0c0000 pid=3609 clone guuid=69fc130e-1c00-0000-2a0c-81b06a0c0000 pid=3610 /usr/bin/bsd-port/getty guuid=69fc130e-1c00-0000-2a0c-81b06a0c0000 pid=3178->guuid=69fc130e-1c00-0000-2a0c-81b06a0c0000 pid=3610 clone guuid=69fc130e-1c00-0000-2a0c-81b06a0c0000 pid=3611 /usr/bin/bsd-port/getty guuid=69fc130e-1c00-0000-2a0c-81b06a0c0000 pid=3178->guuid=69fc130e-1c00-0000-2a0c-81b06a0c0000 pid=3611 clone guuid=69fc130e-1c00-0000-2a0c-81b06a0c0000 pid=3612 /usr/bin/bsd-port/getty dns send-data zombie guuid=69fc130e-1c00-0000-2a0c-81b06a0c0000 pid=3178->guuid=69fc130e-1c00-0000-2a0c-81b06a0c0000 pid=3612 clone guuid=8819930e-1c00-0000-2a0c-81b06d0c0000 pid=3181 /usr/bin/mkdir guuid=1fb34a0e-1c00-0000-2a0c-81b06b0c0000 pid=3179->guuid=8819930e-1c00-0000-2a0c-81b06d0c0000 pid=3181 execve guuid=5eeb2e0f-1c00-0000-2a0c-81b0710c0000 pid=3185 /usr/bin/mkdir guuid=16fa000f-1c00-0000-2a0c-81b06f0c0000 pid=3183->guuid=5eeb2e0f-1c00-0000-2a0c-81b0710c0000 pid=3185 execve guuid=6858c70f-1c00-0000-2a0c-81b0740c0000 pid=3188 /usr/bin/cp guuid=7083970f-1c00-0000-2a0c-81b0720c0000 pid=3186->guuid=6858c70f-1c00-0000-2a0c-81b0740c0000 pid=3188 execve guuid=0f85314a-1c00-0000-2a0c-81b0bd0c0000 pid=3261 /usr/bin/ln guuid=14d3f249-1c00-0000-2a0c-81b0bc0c0000 pid=3260->guuid=0f85314a-1c00-0000-2a0c-81b0bd0c0000 pid=3261 execve guuid=91d7c94a-1c00-0000-2a0c-81b0bf0c0000 pid=3263 /usr/bin/ln guuid=cb1b904a-1c00-0000-2a0c-81b0be0c0000 pid=3262->guuid=91d7c94a-1c00-0000-2a0c-81b0bf0c0000 pid=3263 execve guuid=9a5f594b-1c00-0000-2a0c-81b0c20c0000 pid=3266 /usr/bin/ln guuid=a2f2214b-1c00-0000-2a0c-81b0c00c0000 pid=3264->guuid=9a5f594b-1c00-0000-2a0c-81b0c20c0000 pid=3266 execve guuid=6d15f14b-1c00-0000-2a0c-81b0c60c0000 pid=3270 /usr/bin/ln guuid=109cb64b-1c00-0000-2a0c-81b0c40c0000 pid=3268->guuid=6d15f14b-1c00-0000-2a0c-81b0c60c0000 pid=3270 execve guuid=db91574c-1c00-0000-2a0c-81b0ca0c0000 pid=3274 /usr/bin/dash guuid=f3dd4d4c-1c00-0000-2a0c-81b0c80c0000 pid=3272->guuid=db91574c-1c00-0000-2a0c-81b0ca0c0000 pid=3274 execve guuid=42997f4c-1c00-0000-2a0c-81b0cc0c0000 pid=3276 /usr/bin/ln guuid=befe4d4c-1c00-0000-2a0c-81b0c90c0000 pid=3273->guuid=42997f4c-1c00-0000-2a0c-81b0cc0c0000 pid=3276 execve guuid=9ea08b4c-1c00-0000-2a0c-81b0cd0c0000 pid=3277 /usr/bin/.sshd guuid=db91574c-1c00-0000-2a0c-81b0ca0c0000 pid=3274->guuid=9ea08b4c-1c00-0000-2a0c-81b0cd0c0000 pid=3277 execve guuid=54205761-1c00-0000-2a0c-81b0070d0000 pid=3335 /usr/bin/.sshd delete-file write-file zombie guuid=9ea08b4c-1c00-0000-2a0c-81b0cd0c0000 pid=3277->guuid=54205761-1c00-0000-2a0c-81b0070d0000 pid=3335 clone guuid=dd03214d-1c00-0000-2a0c-81b0d10c0000 pid=3281 /usr/bin/mkdir guuid=ec0cf64c-1c00-0000-2a0c-81b0cf0c0000 pid=3279->guuid=dd03214d-1c00-0000-2a0c-81b0d10c0000 pid=3281 execve guuid=0b55b14d-1c00-0000-2a0c-81b0d30c0000 pid=3283 /usr/bin/cp guuid=b1b2874d-1c00-0000-2a0c-81b0d20c0000 pid=3282->guuid=0b55b14d-1c00-0000-2a0c-81b0d30c0000 pid=3283 execve guuid=61c2514f-1c00-0000-2a0c-81b0db0c0000 pid=3291 /usr/bin/mkdir guuid=69af1f4f-1c00-0000-2a0c-81b0d90c0000 pid=3289->guuid=61c2514f-1c00-0000-2a0c-81b0db0c0000 pid=3291 execve guuid=177e2e50-1c00-0000-2a0c-81b0de0c0000 pid=3294 /usr/bin/mkdir guuid=d9d6d24f-1c00-0000-2a0c-81b0dc0c0000 pid=3292->guuid=177e2e50-1c00-0000-2a0c-81b0de0c0000 pid=3294 execve guuid=2d622e51-1c00-0000-2a0c-81b0e00c0000 pid=3296 /usr/bin/cp guuid=22e0f950-1c00-0000-2a0c-81b0df0c0000 pid=3295->guuid=2d622e51-1c00-0000-2a0c-81b0e00c0000 pid=3296 execve guuid=4e5adb54-1c00-0000-2a0c-81b0e80c0000 pid=3304 /usr/bin/chmod guuid=23309c54-1c00-0000-2a0c-81b0e70c0000 pid=3303->guuid=4e5adb54-1c00-0000-2a0c-81b0e80c0000 pid=3304 execve guuid=6307d155-1c00-0000-2a0c-81b0ea0c0000 pid=3306 /usr/bin/cp guuid=96237355-1c00-0000-2a0c-81b0e90c0000 pid=3305->guuid=6307d155-1c00-0000-2a0c-81b0ea0c0000 pid=3306 execve guuid=dfecd258-1c00-0000-2a0c-81b0ec0c0000 pid=3308 /usr/bin/mkdir guuid=838a7558-1c00-0000-2a0c-81b0eb0c0000 pid=3307->guuid=dfecd258-1c00-0000-2a0c-81b0ec0c0000 pid=3308 execve guuid=98967459-1c00-0000-2a0c-81b0ee0c0000 pid=3310 /usr/bin/mkdir guuid=e1004459-1c00-0000-2a0c-81b0ed0c0000 pid=3309->guuid=98967459-1c00-0000-2a0c-81b0ee0c0000 pid=3310 execve guuid=7f5d075a-1c00-0000-2a0c-81b0f00c0000 pid=3312 /usr/bin/cp guuid=762cd459-1c00-0000-2a0c-81b0ef0c0000 pid=3311->guuid=7f5d075a-1c00-0000-2a0c-81b0f00c0000 pid=3312 execve guuid=8045025e-1c00-0000-2a0c-81b0f50c0000 pid=3317 /usr/bin/chmod guuid=e387bc5d-1c00-0000-2a0c-81b0f40c0000 pid=3316->guuid=8045025e-1c00-0000-2a0c-81b0f50c0000 pid=3317 execve guuid=d17edb5e-1c00-0000-2a0c-81b0fa0c0000 pid=3322 /usr/bin/mkdir guuid=bba0a25e-1c00-0000-2a0c-81b0f80c0000 pid=3320->guuid=d17edb5e-1c00-0000-2a0c-81b0fa0c0000 pid=3322 execve guuid=ca77855f-1c00-0000-2a0c-81b0fd0c0000 pid=3325 /usr/bin/mkdir guuid=458c585f-1c00-0000-2a0c-81b0fc0c0000 pid=3324->guuid=ca77855f-1c00-0000-2a0c-81b0fd0c0000 pid=3325 execve guuid=4f896760-1c00-0000-2a0c-81b0020d0000 pid=3330 /usr/bin/cp guuid=7d3f3360-1c00-0000-2a0c-81b0000d0000 pid=3328->guuid=4f896760-1c00-0000-2a0c-81b0020d0000 pid=3330 execve guuid=ddf15c61-1c00-0000-2a0c-81b0080d0000 pid=3336 /usr/bin/chmod guuid=f45c2161-1c00-0000-2a0c-81b0050d0000 pid=3333->guuid=ddf15c61-1c00-0000-2a0c-81b0080d0000 pid=3336 execve guuid=54205761-1c00-0000-2a0c-81b0070d0000 pid=3337 /usr/bin/.sshd guuid=54205761-1c00-0000-2a0c-81b0070d0000 pid=3335->guuid=54205761-1c00-0000-2a0c-81b0070d0000 pid=3337 clone guuid=f99d1162-1c00-0000-2a0c-81b00c0d0000 pid=3340 /usr/bin/mkdir guuid=e3b1bd61-1c00-0000-2a0c-81b00a0d0000 pid=3338->guuid=f99d1162-1c00-0000-2a0c-81b00c0d0000 pid=3340 execve guuid=757eba62-1c00-0000-2a0c-81b0100d0000 pid=3344 /usr/bin/mkdir guuid=969b7162-1c00-0000-2a0c-81b00e0d0000 pid=3342->guuid=757eba62-1c00-0000-2a0c-81b0100d0000 pid=3344 execve guuid=7cc55063-1c00-0000-2a0c-81b0130d0000 pid=3347 /usr/bin/cp guuid=91ce1a63-1c00-0000-2a0c-81b0110d0000 pid=3345->guuid=7cc55063-1c00-0000-2a0c-81b0130d0000 pid=3347 execve guuid=dc4c6064-1c00-0000-2a0c-81b0170d0000 pid=3351 /usr/bin/chmod guuid=f7ca1b64-1c00-0000-2a0c-81b0160d0000 pid=3350->guuid=dc4c6064-1c00-0000-2a0c-81b0170d0000 pid=3351 execve guuid=8ec653d9-1c00-0000-2a0c-81b0040e0000 pid=3588 /usr/bin/kmod guuid=3aca13d9-1c00-0000-2a0c-81b0030e0000 pid=3587->guuid=8ec653d9-1c00-0000-2a0c-81b0040e0000 pid=3588 execve 681cd30e-785c-5cf5-a4e5-dacffa54ec9e else.u27v.me:6001 guuid=42ed878b-1a00-0000-2a0c-81b05d090000 pid=3597->681cd30e-785c-5cf5-a4e5-dacffa54ec9e con 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=42ed878b-1a00-0000-2a0c-81b05d090000 pid=3597->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 30B ec2cfece-76b1-58fb-b398-29a45929310e 127.0.0.1:6001 guuid=42ed878b-1a00-0000-2a0c-81b05d090000 pid=3597->ec2cfece-76b1-58fb-b398-29a45929310e send: 540672B guuid=9351b9dc-1c00-0000-2a0c-81b0100e0000 pid=3600 /usr/bin/kmod guuid=36c664dc-1c00-0000-2a0c-81b00f0e0000 pid=3599->guuid=9351b9dc-1c00-0000-2a0c-81b0100e0000 pid=3600 execve guuid=69fc130e-1c00-0000-2a0c-81b06a0c0000 pid=3612->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 1500B
Result
Threat name:
BillGates
Detection:
malicious
Classification:
spre.troj.evad
Score:
100 / 100
Signature
Antivirus / Scanner detection for submitted sample
Antivirus detection for dropped file
Contains symbols with names commonly found in malware
Detected Linux BillGates botnet
Drops files in suspicious directories
Drops invisible ELF files
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Opens /proc/net/* files useful for finding connected devices and routers
Sample and/or dropped files likely contain functionality related to malicious behavior
Sample tries to persist itself using System V runlevels
Writes identical ELF files to multiple locations
Yara detected BillGates
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1883653 Sample: kswpad.elf Startdate: 14/03/2026 Architecture: LINUX Score: 100 103 web.yk4s.com 2->103 105 else.u27v.me 2->105 117 Malicious sample detected (through community Yara rule) 2->117 119 Antivirus detection for dropped file 2->119 121 Antivirus / Scanner detection for submitted sample 2->121 123 4 other signatures 2->123 13 kswpad.elf 2->13         started        signatures3 process4 process5 15 kswpad.elf 13->15         started        file6 93 /tmp/gates.lod, ASCII 15->93 dropped 95 /etc/init.d/DbSecuritySpt, Bourne-Again 15->95 dropped 107 Detected Linux BillGates botnet 15->107 109 Drops files in suspicious directories 15->109 111 Opens /proc/net/* files useful for finding connected devices and routers 15->111 19 kswpad.elf 15->19         started        21 kswpad.elf sh 15->21         started        23 kswpad.elf sh 15->23         started        25 11 other processes 15->25 signatures7 process8 process9 27 kswpad.elf sh 19->27         started        29 sh cp 21->29         started        33 sh cp 23->33         started        35 kswpad.elf sh 25->35         started        37 sh ln 25->37         started        39 sh ln 25->39         started        41 8 other processes 25->41 file10 43 sh getty 27->43         started        89 /usr/bin/.sshd, ELF 29->89 dropped 131 Writes identical ELF files to multiple locations 29->131 133 Drops invisible ELF files 29->133 135 Drops files in suspicious directories 29->135 91 /usr/bin/bsd-port/getty, ELF 33->91 dropped 45 sh .sshd 35->45         started        137 Sample tries to persist itself using System V runlevels 37->137 signatures11 process12 process13 47 getty 43->47         started        51 .sshd 45->51         started        file14 97 /usr/bin/bsd-port/getty.lock, ASCII 47->97 dropped 99 /etc/init.d/selinux, Bourne-Again 47->99 dropped 113 Drops files in suspicious directories 47->113 53 getty sh 47->53         started        55 getty sh 47->55         started        57 getty sh 47->57         started        59 40 other processes 47->59 101 /tmp/moni.lod, ASCII 51->101 dropped 115 Detected Linux BillGates botnet 51->115 signatures15 process16 process17 61 sh cp 53->61         started        64 sh cp 55->64         started        66 sh cp 57->66         started        68 sh cp 59->68         started        70 sh cp 59->70         started        73 sh cp 59->73         started        75 37 other processes 59->75 file18 125 Writes identical ELF files to multiple locations 61->125 127 Drops files in suspicious directories 61->127 77 /usr/bin/dpkgd/netstat, ELF 70->77 dropped 79 /usr/bin/dpkgd/lsof, ELF 73->79 dropped 81 /usr/bin/ss, ELF 75->81 dropped 83 /usr/bin/ps, ELF 75->83 dropped 85 /usr/bin/netstat, ELF 75->85 dropped 87 3 other malicious files 75->87 dropped 129 Sample tries to persist itself using System V runlevels 75->129 signatures19
Threat name:
Linux.Trojan.Gates
Status:
Malicious
First seen:
2026-03-01 02:06:26 UTC
File Type:
ELF32 Little (Exe)
AV detection:
29 of 36 (80.56%)
Threat level:
  5/5
Result
Malware family:
billgates
Score:
  10/10
Tags:
family:billgates antivm botnet defense_evasion discovery linux persistence
Behaviour
Reads runtime system information
Writes file to tmp directory
Checks CPU configuration
Reads system network configuration
Modifies init.d
Reads system routing table
Write file to user bin folder
Writes file to system bin folder
File and Directory Permissions Modification
Executes dropped EXE
BillGates
Billgates family
Detects BillGates payload
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:Detect_PowerShell_Obfuscation
Author:daniyyell
Description:Detects obfuscated PowerShell commands commonly used in malicious scripts.
Rule name:F01_s1ckrule
Author:s1ckb017
Rule name:ldpreload
Author:xorseed
Reference:https://stuff.rop.io/
Rule name:LinuxBillGates
Rule name:Linux_Trojan_Ganiw_b9f045aa
Author:Elastic Security
Rule name:Linux_Trojan_Setag_01e2f79b
Author:Elastic Security
Rule name:Linux_Trojan_Setag_351eeb76
Author:Elastic Security
Rule name:setsockopt
Author:Tim Brown @timb_machine
Description:Hunts for setsockopt() red flags
Rule name:telebot_framework
Author:vietdx.mb
Rule name:unixredflags3
Author:Tim Brown @timb_machine
Description:Hunts for UNIX red flags

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

BillGates

elf 6fddaa099096c0caee183e4bb95e9fe79003e6ae6dc41d6b1aa3b4aec221bd38

(this sample)

  
Delivery method
Distributed via web download

Comments