MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 900937aaa419fa3bf3358cd06bb6ccc26740a1183dbc43e4c6ff33801be889e4. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 9


Intelligence 9 IOCs YARA 5 File information Comments

SHA256 hash: 900937aaa419fa3bf3358cd06bb6ccc26740a1183dbc43e4c6ff33801be889e4
SHA3-384 hash: 3a317bd82627feb6e4b49a75c1dc7eece83baeeb39a787037b4855cefd5692feb0280cc1fb155f1a666a9221a3149b30
SHA1 hash: 914af51b8da1aa385fc1c53ac9ce9a9e461e4873
MD5 hash: b362923d022504b76e61ead69ddd5716
humanhash: leopard-floor-red-berlin
File name:amd64
Download: download sample
File size:482'032 bytes
First seen:2025-06-21 16:42:06 UTC
Last seen:2025-06-21 18:18:48 UTC
File type: elf
MIME type:application/x-executable
ssdeep 12288:iD6LPBCvMk0O9na1M80cLt9i5aIaTtpc4W:2+QGO9naz0Szi5anTtR
TLSH T1C3A41212E290D8FEC4CAC170429FD27BFD76BC544234BC6B6198F7322B3AE601B16A55
TrID 50.1% (.) ELF Executable and Linkable format (Linux) (4022/12)
49.8% (.O) ELF Executable and Linkable format (generic) (4000/1)
Magika elf
Reporter abuse_ch
Tags:elf

Intelligence


File Origin
# of uploads :
2
# of downloads :
83
Origin country :
DE DE
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creates directories
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
exploit gcc lolbin remote similar-threat
Verdict:
Malicious
Uses P2P?:
true
Uses anti-vm?:
true
Architecture:
x86
Packer:
custom
Botnet:
unknown
Number of open files:
70
Number of processes launched:
10
Processes remaning?
false
Remote TCP ports scanned:
not identified
Behaviour
Anti-VM
Botnet C2s
TCP botnet C2(s):
not identified
UDP botnet C2(s):
type: 162.159.200.123:123
type: 130.239.18.158:6881
type: 67.215.246.10:6881
type: 178.69.209.93:6881
type: 217.102.172.55:6881
type: 95.211.162.131:6881
type: 37.187.121.149:6881
type: 64.251.172.36:6881
type: 24.135.61.45:6881
type: 89.204.26.6:6881
type: 88.124.123.149:6881
type: 45.87.143.60:6881
type: 86.163.42.108:6881
type: 85.240.21.218:6881
type: 178.18.3.107:6881
type: 59.88.0.128:6881
type: 69.117.218.161:6881
type: 188.187.147.69:6881
type: 160.155.169.12:6881
type: 35.163.251.58:6881
type: 18.220.82.190:6881
type: 176.122.201.113:6881
type: 18.221.7.72:6881
type: 67.220.72.41:6881
type: 129.146.73.26:6881
type: 54.70.174.84:6881
type: 203.211.98.223:6881
type: 37.193.197.118:6881
type: 94.43.229.220:6881
type: 89.133.42.97:6881
type: 37.194.118.150:6881
type: 86.31.64.76:6881
type: 54.214.62.55:6881
type: 178.162.174.222:28014
type: 178.162.173.199:28014
type: 178.162.174.77:28014
type: 178.162.174.231:28014
type: 178.162.173.12:28014
type: 141.95.53.34:8648
type: 5.135.156.163:56843
type: 5.79.66.11:54337
type: 213.232.235.11:8999
type: 71.68.37.255:8999
type: 130.239.18.158:8515
type: 135.181.227.244:50000
type: 65.21.128.232:50000
type: 135.181.227.187:50000
type: 37.27.119.186:50000
type: 37.27.107.124:50000
type: 65.21.125.172:50000
type: 65.21.125.161:50000
type: 37.27.117.124:50000
type: 37.27.117.182:50000
type: 135.181.238.57:50000
type: 37.27.104.52:50000
type: 159.69.143.182:50000
type: 37.27.104.57:50000
type: 162.55.85.164:50000
type: 37.27.120.59:50000
type: 65.21.128.246:50000
type: 178.162.174.43:28004
type: 178.162.174.228:28004
type: 5.135.178.12:53659
type: 185.149.91.145:51509
type: 216.39.248.235:51509
type: 2.236.169.3:51413
type: 130.89.163.82:51413
type: 45.83.232.30:51413
type: 104.244.73.2:51413
type: 5.135.158.154:51413
type: 5.39.95.146:51413
type: 176.31.255.89:51413
type: 168.138.13.18:51413
type: 207.136.105.89:51413
type: 81.171.1.144:51413
type: 46.232.211.193:58017
type: 87.155.86.227:65432
type: 95.211.247.101:28009
type: 178.162.174.102:28009
type: 44.216.7.139:6880
type: 195.154.233.74:6880
type: 54.144.88.168:6880
type: 50.17.19.6:6880
type: 45.203.208.35:6880
type: 62.60.149.243:39674
type: 31.10.158.193:54413
type: 95.168.168.234:52277
type: 178.162.174.222:28011
type: 178.162.173.232:28011
type: 45.136.230.98:51589
type: 178.162.174.116:28012
type: 178.162.174.92:28012
type: 69.50.95.40:10085
type: 71.192.211.146:8200
type: 142.202.48.88:12037
type: 79.11.107.190:6889
type: 175.158.185.180:6889
type: 84.28.15.171:6889
type: 31.178.229.173:6889
type: 47.40.144.147:6889
type: 91.17.16.218:6889
type: 178.162.174.227:28003
type: 178.162.173.91:28003
type: 185.149.91.185:51059
type: 130.239.18.158:8580
type: 144.76.175.153:33473
type: 130.239.18.158:8516
type: 130.239.18.158:8513
type: 221.150.194.231:40870
type: 80.42.231.187:56211
type: 222.120.94.87:33048
type: 116.46.125.132:40854
type: 37.48.89.181:48531
type: 178.162.174.235:28015
type: 178.162.173.222:28015
type: 178.162.173.9:28015
type: 83.159.31.91:6887
type: 89.39.81.206:53756
type: 176.63.14.214:59695
type: 86.182.127.118:38462
type: 94.31.109.109:14070
type: 185.203.56.70:55836
type: 46.232.211.211:64183
type: 187.181.72.157:50321
type: 178.162.173.204:28013
type: 59.15.169.111:32889
type: 114.25.152.79:21236
type: 219.77.201.38:9010
type: 81.101.131.48:9010
type: 45.91.208.243:51936
type: 178.162.173.141:28000
type: 185.107.71.103:44737
type: 178.162.174.228:28007
type: 188.163.80.147:25184
type: 38.242.208.115:62709
type: 62.171.169.210:60630
type: 86.58.123.121:60630
type: 213.227.153.16:28005
type: 23.162.56.83:14036
type: 152.53.22.181:32482
type: 185.149.91.21:51118
type: 130.239.18.158:8524
type: 212.102.53.38:36506
type: 217.119.74.32:16714
type: 2.51.2.48:24635
type: 220.74.6.160:64895
type: 144.76.175.153:33668
type: 185.145.245.116:8665
type: 81.171.17.71:54516
type: 37.27.113.233:33667
type: 189.35.1.211:5881
type: 99.92.188.140:5881
type: 95.18.140.7:5881
type: 155.4.128.65:1092
type: 217.30.199.18:41398
type: 211.105.169.63:10607
type: 185.21.216.196:65164
type: 193.23.249.180:50171
type: 45.158.186.97:50171
type: 178.162.174.141:28002
type: 178.162.174.76:28002
type: 119.206.161.157:7646
type: 181.192.81.232:27171
type: 58.27.232.143:13709
type: 121.132.209.174:33111
type: 84.186.29.59:53837
type: 138.201.137.81:42791
type: 120.152.156.111:31916
type: 95.90.185.78:20831
type: 112.172.129.7:8090
type: 220.75.250.160:33066
type: 175.211.72.163:40981
type: 185.149.91.67:51091
type: 75.82.48.25:50478
type: 185.164.142.127:13314
type: 31.3.152.213:60301
type: 87.71.18.153:53805
type: 161.142.70.22:33671
type: 119.229.118.111:30947
type: 84.196.26.109:44506
type: 78.68.187.231:14082
type: 71.205.170.227:14082
type: 91.117.22.124:39525
type: 176.31.183.108:58266
type: 169.224.64.144:63619
type: 90.94.230.20:51415
type: 88.95.178.93:33753
type: 208.30.115.61:37321
type: 91.146.78.141:44450
type: 220.255.113.149:40460
type: 176.63.27.204:49406
type: 72.21.17.50:27612
type: 211.63.141.207:40757
type: 59.7.185.142:33008
type: 217.194.180.117:10273
type: 58.174.81.183:44822
type: 175.177.49.117:23208
type: 93.35.139.188:34005
type: 203.166.254.203:49295
type: 187.73.24.20:7121
type: 46.117.155.154:43305
type: 168.194.26.8:48470
type: 45.246.215.168:55733
type: 88.202.137.113:14903
type: 45.87.251.11:28117
type: 92.37.47.174:54191
type: 14.63.14.180:56213
type: 212.5.142.87:43312
type: 201.124.23.12:7185
type: 144.76.175.153:27600
type: 201.225.5.54:1258
type: 105.196.163.77:39935
type: 67.218.250.204:6287
type: 95.19.14.55:22657
type: 213.177.206.213:4973
type: 84.43.233.12:20481
type: 1.239.86.217:41056
type: 69.50.95.40:10071
type: 183.103.128.87:32891
type: 78.25.7.145:41226
type: 185.203.56.37:65355
type: 2.82.9.4:17950
type: 95.211.127.53:28008
type: 168.70.119.31:20049
type: 141.95.53.34:8650
type: 194.9.15.101:43640
type: 195.154.172.179:22894
type: 154.209.94.20:60020
type: 72.224.187.54:6061
type: 78.117.62.65:58687
type: 14.45.224.46:7994
type: 185.203.56.55:29691
type: 213.227.136.72:51410
type: 61.74.135.122:33101
type: 47.205.61.236:16579
type: 195.206.105.17:59764
type: 89.240.87.205:13072
type: 89.134.0.245:9006
type: 181.214.153.137:25139
type: 98.59.155.145:57352
type: 181.41.202.133:48262
type: 185.246.211.200:61675
type: 188.150.110.232:63050
type: 213.170.133.231:33974
type: 156.146.63.157:41258
type: 79.112.16.70:49915
Status:
terminated
Behavior Graph:
%3 guuid=d8bf259a-1800-0000-d67c-5515ed060000 pid=1773 /usr/bin/sudo guuid=1bab229c-1800-0000-d67c-5515f3060000 pid=1779 /tmp/sample.bin guuid=d8bf259a-1800-0000-d67c-5515ed060000 pid=1773->guuid=1bab229c-1800-0000-d67c-5515f3060000 pid=1779 execve guuid=da5f3c9c-1800-0000-d67c-5515f4060000 pid=1780 /usr/bin/dash guuid=1bab229c-1800-0000-d67c-5515f3060000 pid=1779->guuid=da5f3c9c-1800-0000-d67c-5515f4060000 pid=1780 execve guuid=c1c3869c-1800-0000-d67c-5515f6060000 pid=1782 /usr/bin/dash guuid=1bab229c-1800-0000-d67c-5515f3060000 pid=1779->guuid=c1c3869c-1800-0000-d67c-5515f6060000 pid=1782 execve guuid=bdb2f99c-1800-0000-d67c-5515f9060000 pid=1785 /tmp/sample.bin mprotect-exec zombie guuid=1bab229c-1800-0000-d67c-5515f3060000 pid=1779->guuid=bdb2f99c-1800-0000-d67c-5515f9060000 pid=1785 clone guuid=fb43cf9c-1800-0000-d67c-5515f7060000 pid=1783 /usr/bin/dash guuid=c1c3869c-1800-0000-d67c-5515f6060000 pid=1782->guuid=fb43cf9c-1800-0000-d67c-5515f7060000 pid=1783 clone guuid=71f7d89c-1800-0000-d67c-5515f8060000 pid=1784 /usr/bin/dash guuid=c1c3869c-1800-0000-d67c-5515f6060000 pid=1782->guuid=71f7d89c-1800-0000-d67c-5515f8060000 pid=1784 clone guuid=d00ef0a0-1800-0000-d67c-551502070000 pid=1794 /tmp/sample.bin zombie guuid=bdb2f99c-1800-0000-d67c-5515f9060000 pid=1785->guuid=d00ef0a0-1800-0000-d67c-551502070000 pid=1794 clone guuid=801effa0-1800-0000-d67c-551503070000 pid=1795 /tmp/sample.bin guuid=d00ef0a0-1800-0000-d67c-551502070000 pid=1794->guuid=801effa0-1800-0000-d67c-551503070000 pid=1795 clone guuid=8e6506a1-1800-0000-d67c-551504070000 pid=1796 /tmp/sample.bin dns net net-scan send-data guuid=801effa0-1800-0000-d67c-551503070000 pid=1795->guuid=8e6506a1-1800-0000-d67c-551504070000 pid=1796 clone d316b2ae-0a7e-5b43-8de6-745900c90c54 127.0.0.1:65535 guuid=8e6506a1-1800-0000-d67c-551504070000 pid=1796->d316b2ae-0a7e-5b43-8de6-745900c90c54 con 38a4910e-6f05-5afe-a8e3-398c2eb18329 time.cloudflare.com:123 guuid=8e6506a1-1800-0000-d67c-551504070000 pid=1796->38a4910e-6f05-5afe-a8e3-398c2eb18329 send: 48B 2d752d5e-5dfa-5bf1-a89f-d1ded8e3be97 31.200.249.178:31995 guuid=8e6506a1-1800-0000-d67c-551504070000 pid=1796->2d752d5e-5dfa-5bf1-a89f-d1ded8e3be97 send: 68B 1100160e-b456-554d-97f6-6b4f7e534e20 31.200.249.162:31982 guuid=8e6506a1-1800-0000-d67c-551504070000 pid=1796->1100160e-b456-554d-97f6-6b4f7e534e20 send: 68B 21bbdb49-d96a-550b-b6f8-b5587fd6e6f5 89.23.148.246:60945 guuid=8e6506a1-1800-0000-d67c-551504070000 pid=1796->21bbdb49-d96a-550b-b6f8-b5587fd6e6f5 con guuid=8e6506a1-1800-0000-d67c-551504070000 pid=1796|send-data send-data to 296 IP addresses review logs to see them all guuid=8e6506a1-1800-0000-d67c-551504070000 pid=1796->guuid=8e6506a1-1800-0000-d67c-551504070000 pid=1796|send-data send
Result
Threat name:
n/a
Detection:
malicious
Classification:
troj.spyw
Score:
64 / 100
Signature
Executes the "crontab" command typically for achieving persistence
Multi AV Scanner detection for submitted file
Opens /sys/class/net/* files useful for querying network interface information
Sample reads /proc/mounts (often used for finding a writable filesystem)
Sample tries to persist itself using cron
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1719926 Sample: amd64.elf Startdate: 21/06/2025 Architecture: LINUX Score: 64 44 91.208.35.20, 3075, 6881 YUG-SVYAZ-SERVICE-ASRU Russian Federation 2->44 46 177.8.54.50, 1193, 6881 WebbyTecnologiaLtdaBR Brazil 2->46 48 102 other IPs or domains 2->48 50 Multi AV Scanner detection for submitted file 2->50 10 amd64.elf 2->10         started        12 dash rm 2->12         started        14 dash head 2->14         started        16 8 other processes 2->16 signatures3 process4 process5 18 amd64.elf sh 10->18         started        20 amd64.elf 10->20         started        23 amd64.elf sh 10->23         started        signatures6 25 sh crontab 18->25         started        29 sh 18->29         started        54 Opens /sys/class/net/* files useful for querying network interface information 20->54 56 Sample reads /proc/mounts (often used for finding a writable filesystem) 20->56 31 amd64.elf 20->31         started        33 sh crontab 23->33         started        process7 file8 42 /var/spool/cron/crontabs/tmp.KaaqNX, ASCII 25->42 dropped 58 Sample tries to persist itself using cron 25->58 60 Executes the "crontab" command typically for achieving persistence 25->60 35 sh crontab 29->35         started        38 amd64.elf 31->38         started        signatures9 process10 signatures11 52 Executes the "crontab" command typically for achieving persistence 35->52 40 amd64.elf 38->40         started        process12
Threat name:
Linux.Trojan.Multiverze
Status:
Malicious
First seen:
2025-06-21 16:44:31 UTC
File Type:
ELF64 Little (Exe)
AV detection:
14 of 24 (58.33%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  6/10
Tags:
antivm defense_evasion discovery execution linux persistence privilege_escalation
Behaviour
Enumerates kernel/hardware configuration
Reads runtime system information
Writes file to tmp directory
Checks CPU configuration
Checks hardware identifiers (DMI)
Creates/modifies Cron job
Enumerates running processes
Reads MAC address of network interface
Reads hardware information
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:enterpriseapps2
Author:Tim Brown @timb_machine
Description:Enterprise apps
Rule name:enterpriseunix2
Author:Tim Brown @timb_machine
Description:Enterprise UNIX
Rule name:linux_generic_ipv6_catcher
Author:@_lubiedo
Description:ELF samples using IPv6 addresses
Rule name:Sus_Obf_Enc_Spoof_Hide_PE
Author:XiAnzheng
Description:Check for Overlay, Obfuscating, Encrypting, Spoofing, Hiding, or Entropy Technique(can create FP)
Rule name:unixredflags3
Author:Tim Brown @timb_machine
Description:Hunts for UNIX red flags

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

elf 900937aaa419fa3bf3358cd06bb6ccc26740a1183dbc43e4c6ff33801be889e4

(this sample)

  
Delivery method
Distributed via web download

Comments