🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 920d4127eab982c98b0962ff09ef19f84bc10e6ca76c8d49993ce2fcb2d3474f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA 2 File information Comments

SHA256 hash: 920d4127eab982c98b0962ff09ef19f84bc10e6ca76c8d49993ce2fcb2d3474f
SHA3-384 hash: a640fc25abe698c6e30137bf71ed0878222e89fdbd623d16d18de278981ad0c81c99f015bdd99593d19358c5aaff2dbb
SHA1 hash: 1458d18b4f9f57e2659f99198374a07ef290f7e4
MD5 hash: f4434ae8f83f91b8cfa6890a482d151b
humanhash: triple-blue-uniform-spring
File name:x86
Download: download sample
File size:25'600 bytes
First seen:2026-09-11 01:15:29 UTC
Last seen:Never
File type: elf
MIME type:application/x-executable
ssdeep 384:fORoHGlOvCRVvpnzR3sGzBWl7uRI9BcwQZU8c1j9v4IFWkS+UGuyD:kYGlOvCRVvpnV3NAH9YU8cL4IFNStZ
TLSH T1DAB23B91E7C3E0F7E88401FD1152D7516336F438216AFD4BEB2026BBB812921E757BA9
telfhash t1d4f046c23daa01e8fa80fe4dd31f2a43db2a6ab8173570ef4cf5b20632c111481a141a
TrID 50.1% (.) ELF Executable and Linkable format (Linux) (4022/12)
49.8% (.O) ELF Executable and Linkable format (generic) (4000/1)
Magika elf
Reporter abuse_ch
Tags:elf upx-dec


Avatar
abuse_ch
UPX decompressed file, sourced from SHA256 74109e2ad03f4b3d057a41b8a720378d58405604c5e2d8828e15d601c5a0bd28
File size (compressed) :15'860 bytes
File size (de-compressed) :25'600 bytes
Format:linux/i386
Packed file: 74109e2ad03f4b3d057a41b8a720378d58405604c5e2d8828e15d601c5a0bd28

Intelligence


File Origin
# of uploads :
1
# of downloads :
31
Origin country :
NL NL
Vendor Threat Intelligence
No detections
Result
Verdict:
Clean
Maliciousness:

Behaviour
Connection attempt
Runs as daemon
Verdict:
Malicious
Uses P2P?:
false
Uses anti-vm?:
false
Architecture:
x86
Packer:
not packed
Botnet:
unknown
Number of open files:
0
Number of processes launched:
3
Processes remaning?
false
Remote TCP ports scanned:
not identified
Behaviour
no suspicious findings
Botnet C2s
TCP botnet C2(s):
not identified
UDP botnet C2(s):
not identified
Verdict:
Malicious
File Type:
elf.32.le
First seen:
2026-09-11T13:23:00Z UTC
Last seen:
2026-09-12T20:06:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=a8497c1b-1700-0000-1d9d-f12f0a0d0000 pid=3338 /usr/bin/sudo guuid=657ed621-1700-0000-1d9d-f12f120d0000 pid=3346 /tmp/sample.bin guuid=a8497c1b-1700-0000-1d9d-f12f0a0d0000 pid=3338->guuid=657ed621-1700-0000-1d9d-f12f120d0000 pid=3346 execve guuid=f0a71623-1700-0000-1d9d-f12f150d0000 pid=3349 /tmp/sample.bin guuid=657ed621-1700-0000-1d9d-f12f120d0000 pid=3346->guuid=f0a71623-1700-0000-1d9d-f12f150d0000 pid=3349 clone guuid=c16a8f23-1700-0000-1d9d-f12f170d0000 pid=3351 /tmp/sample.bin net zombie guuid=f0a71623-1700-0000-1d9d-f12f150d0000 pid=3349->guuid=c16a8f23-1700-0000-1d9d-f12f170d0000 pid=3351 clone 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=c16a8f23-1700-0000-1d9d-f12f170d0000 pid=3351->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con
Gathering data
Result
Threat name:
n/a
Detection:
malicious
Classification:
n/a
Score:
48 / 100
Signature
Malicious sample detected (through community Yara rule)
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1971731 Sample: x86.elf Startdate: 11/09/2026 Architecture: LINUX Score: 48 16 169.254.169.254, 80 USDOS-USDepartmentofStateUS ZZ 2->16 18 94.249.188.204, 11121 THREATOFFDE Germany 2->18 20 Malicious sample detected (through community Yara rule) 2->20 8 x86.elf 2->8         started        10 python3.8 dpkg 2->10         started        signatures3 process4 process5 12 x86.elf 8->12         started        process6 14 x86.elf 12->14         started       
Result
Malware family:
n/a
Score:
  1/10
Tags:
linux
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Linux_Trojan_Mirai_cc93863b
Author:Elastic Security
Rule name:TH_Generic_MassHunt_Linux_Malware_2026_CYFARE
Author:CYFARE
Description:Generic Linux malware mass-hunt rule - 2026
Reference:https://cyfare.net/

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

elf 920d4127eab982c98b0962ff09ef19f84bc10e6ca76c8d49993ce2fcb2d3474f

(this sample)

  
Delivery method
Distributed via web download

Comments