MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 93ffa6afdbc71c9f6a0a8752ccdbbf697a7e2cca5a146bf010cb885140287522. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 10


Intelligence 10 IOCs YARA 2 File information Comments

SHA256 hash: 93ffa6afdbc71c9f6a0a8752ccdbbf697a7e2cca5a146bf010cb885140287522
SHA3-384 hash: e56af0e85f45790b493f41833ac428a0459c5c6c5e62c869f1698b3fb44561bfd89f422fa592ed1534351ad7af291496
SHA1 hash: 0cc4f9faa92748317baa62940e8330dfe2318a7a
MD5 hash: 9ad75d170132c9f34760605fb7ec4196
humanhash: wyoming-lactose-earth-eleven
File name:vcimanagement.x86
Download: download sample
File size:3'929'396 bytes
First seen:2026-07-07 08:42:18 UTC
Last seen:2026-07-08 10:01:02 UTC
File type: elf
MIME type:application/x-executable
ssdeep 98304:ATeNHWZZLZFPIouXb660Bw4gTe2VBQBBjoJH+:ifLZFgWXBHzV
TLSH T1A70633F0CF932FBCD31414FEDA0AD988C5BC6544AD9B40626E926035E1CEB2C86E5D97
TrID 50.1% (.) ELF Executable and Linkable format (Linux) (4022/12)
49.8% (.O) ELF Executable and Linkable format (generic) (4000/1)
Magika elf
Reporter abuse_ch
Tags:elf UPX
File size (compressed) :3'929'396 bytes
File size (de-compressed) :13'085'296 bytes
Format:linux/amd64
Unpacked file: 793272436a619ecefc9a7e676b58553fe8b94f22fd95bf86c35ecdfba192224d

Intelligence


File Origin
# of uploads :
4
# of downloads :
92
Origin country :
DE DE
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Changes owner for a file
Creates or modifies symbolic links
Changes owner for a written file
Creating a file in the %temp% directory
Changes access rights for a written file
Creating a file
Sends data to a server
Gains root access
Connection attempt
Receives data from a server
Sets a written file as executable
Changes the time when the file was created, accessed, or modified
Launching a process
Deleting a recently created file
Creates directories
Substitutes an application name
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
masquerade packed upx
Verdict:
Malicious
Uses P2P?:
false
Uses anti-vm?:
false
Architecture:
x86
Packer:
UPX
Botnet:
unknown
Number of open files:
7
Number of processes launched:
3
Processes remaning?
false
Remote TCP ports scanned:
not identified
Behaviour
Information Gathering
Botnet C2s
TCP botnet C2(s):
not identified
UDP botnet C2(s):
not identified
Verdict:
Clean
File Type:
elf.64.le
First seen:
2026-07-07T06:07:00Z UTC
Last seen:
2026-07-07T14:10:00Z UTC
Hits:
~1000
Status:
terminated
Behavior Graph:
%3 guuid=74db9269-1e00-0000-9bb8-1c3634140000 pid=5172 /usr/bin/sudo guuid=9d7ba76b-1e00-0000-9bb8-1c3635140000 pid=5173 /tmp/sample.bin mprotect-exec net send-data write-file guuid=74db9269-1e00-0000-9bb8-1c3634140000 pid=5172->guuid=9d7ba76b-1e00-0000-9bb8-1c3635140000 pid=5173 execve e05ac331-4d6c-529a-b012-a8a5bfa6a257 94.154.43.42:8080 guuid=9d7ba76b-1e00-0000-9bb8-1c3635140000 pid=5173->e05ac331-4d6c-529a-b012-a8a5bfa6a257 send: 938B guuid=9d7ba76b-1e00-0000-9bb8-1c3635140000 pid=5180 /tmp/sample.bin guuid=9d7ba76b-1e00-0000-9bb8-1c3635140000 pid=5173->guuid=9d7ba76b-1e00-0000-9bb8-1c3635140000 pid=5180 clone guuid=9d7ba76b-1e00-0000-9bb8-1c3635140000 pid=5181 /tmp/sample.bin send-data guuid=9d7ba76b-1e00-0000-9bb8-1c3635140000 pid=5173->guuid=9d7ba76b-1e00-0000-9bb8-1c3635140000 pid=5181 clone guuid=9d7ba76b-1e00-0000-9bb8-1c3635140000 pid=5182 /tmp/sample.bin guuid=9d7ba76b-1e00-0000-9bb8-1c3635140000 pid=5173->guuid=9d7ba76b-1e00-0000-9bb8-1c3635140000 pid=5182 clone guuid=9d7ba76b-1e00-0000-9bb8-1c3635140000 pid=5183 /tmp/sample.bin guuid=9d7ba76b-1e00-0000-9bb8-1c3635140000 pid=5173->guuid=9d7ba76b-1e00-0000-9bb8-1c3635140000 pid=5183 clone guuid=157d8a15-1f00-0000-9bb8-1c3679140000 pid=5241 /usr/bin/sudo net guuid=9d7ba76b-1e00-0000-9bb8-1c3635140000 pid=5173->guuid=157d8a15-1f00-0000-9bb8-1c3679140000 pid=5241 execve guuid=47337728-1f00-0000-9bb8-1c3681140000 pid=5249 /usr/bin/sudo net guuid=9d7ba76b-1e00-0000-9bb8-1c3635140000 pid=5173->guuid=47337728-1f00-0000-9bb8-1c3681140000 pid=5249 execve guuid=9d7ba76b-1e00-0000-9bb8-1c3635140000 pid=5181->e05ac331-4d6c-529a-b012-a8a5bfa6a257 send: 183B guuid=3d7dd399-1e00-0000-9bb8-1c3640140000 pid=5184 /tmp/sample.bin guuid=9d7ba76b-1e00-0000-9bb8-1c3635140000 pid=5182->guuid=3d7dd399-1e00-0000-9bb8-1c3640140000 pid=5184 clone guuid=e482db99-1e00-0000-9bb8-1c3641140000 pid=5185 /usr/bin/sudo net guuid=9d7ba76b-1e00-0000-9bb8-1c3635140000 pid=5182->guuid=e482db99-1e00-0000-9bb8-1c3641140000 pid=5185 execve 0fd0acc8-dfb6-529f-8986-56cdc3ae41d6 10.0.2.15:0 guuid=e482db99-1e00-0000-9bb8-1c3641140000 pid=5185->0fd0acc8-dfb6-529f-8986-56cdc3ae41d6 con 558177e1-1f18-5f39-990b-d68b1c194e8a fec0::5054:ff:fe12:3456:0 guuid=e482db99-1e00-0000-9bb8-1c3641140000 pid=5185->558177e1-1f18-5f39-990b-d68b1c194e8a con cbc59886-1795-52e1-b014-449ae22fd09b fe80::5054:ff:fe12:3456:0 guuid=e482db99-1e00-0000-9bb8-1c3641140000 pid=5185->cbc59886-1795-52e1-b014-449ae22fd09b con guuid=bf21d29b-1e00-0000-9bb8-1c3642140000 pid=5186 /usr/sbin/adduser write-file guuid=e482db99-1e00-0000-9bb8-1c3641140000 pid=5185->guuid=bf21d29b-1e00-0000-9bb8-1c3642140000 pid=5186 execve guuid=52635aa2-1e00-0000-9bb8-1c3645140000 pid=5189 /usr/sbin/groupadd delete-file write-config guuid=bf21d29b-1e00-0000-9bb8-1c3642140000 pid=5186->guuid=52635aa2-1e00-0000-9bb8-1c3645140000 pid=5189 execve guuid=f1dec9c2-1e00-0000-9bb8-1c3651140000 pid=5201 /usr/sbin/useradd delete-file write-config guuid=bf21d29b-1e00-0000-9bb8-1c3642140000 pid=5186->guuid=f1dec9c2-1e00-0000-9bb8-1c3651140000 pid=5201 execve guuid=7cdf72e3-1e00-0000-9bb8-1c3663140000 pid=5219 /usr/bin/dash guuid=bf21d29b-1e00-0000-9bb8-1c3642140000 pid=5186->guuid=7cdf72e3-1e00-0000-9bb8-1c3663140000 pid=5219 execve guuid=1f586ae4-1e00-0000-9bb8-1c3667140000 pid=5223 /usr/bin/passwd write-config guuid=bf21d29b-1e00-0000-9bb8-1c3642140000 pid=5186->guuid=1f586ae4-1e00-0000-9bb8-1c3667140000 pid=5223 execve guuid=bc15dcf9-1e00-0000-9bb8-1c366d140000 pid=5229 /usr/bin/chfn delete-file write-config guuid=bf21d29b-1e00-0000-9bb8-1c3642140000 pid=5186->guuid=bc15dcf9-1e00-0000-9bb8-1c366d140000 pid=5229 execve guuid=e4245d04-1f00-0000-9bb8-1c3673140000 pid=5235 /usr/bin/gpasswd delete-file write-config guuid=bf21d29b-1e00-0000-9bb8-1c3642140000 pid=5186->guuid=e4245d04-1f00-0000-9bb8-1c3673140000 pid=5235 execve guuid=4f5902c2-1e00-0000-9bb8-1c364c140000 pid=5196 /usr/sbin/groupadd guuid=52635aa2-1e00-0000-9bb8-1c3645140000 pid=5189->guuid=4f5902c2-1e00-0000-9bb8-1c364c140000 pid=5196 clone guuid=0a0225c2-1e00-0000-9bb8-1c364d140000 pid=5197 /usr/sbin/groupadd guuid=52635aa2-1e00-0000-9bb8-1c3645140000 pid=5189->guuid=0a0225c2-1e00-0000-9bb8-1c364d140000 pid=5197 clone guuid=50953dc2-1e00-0000-9bb8-1c364e140000 pid=5198 /usr/sbin/groupadd guuid=52635aa2-1e00-0000-9bb8-1c3645140000 pid=5189->guuid=50953dc2-1e00-0000-9bb8-1c364e140000 pid=5198 clone guuid=ce2d62c2-1e00-0000-9bb8-1c364f140000 pid=5199 /usr/sbin/groupadd guuid=52635aa2-1e00-0000-9bb8-1c3645140000 pid=5189->guuid=ce2d62c2-1e00-0000-9bb8-1c364f140000 pid=5199 clone guuid=68907ac2-1e00-0000-9bb8-1c3650140000 pid=5200 /usr/sbin/groupadd guuid=52635aa2-1e00-0000-9bb8-1c3645140000 pid=5189->guuid=68907ac2-1e00-0000-9bb8-1c3650140000 pid=5200 clone guuid=a832c6e2-1e00-0000-9bb8-1c365d140000 pid=5213 /usr/sbin/useradd guuid=f1dec9c2-1e00-0000-9bb8-1c3651140000 pid=5201->guuid=a832c6e2-1e00-0000-9bb8-1c365d140000 pid=5213 clone guuid=15c1dee2-1e00-0000-9bb8-1c365e140000 pid=5214 /usr/sbin/useradd guuid=f1dec9c2-1e00-0000-9bb8-1c3651140000 pid=5201->guuid=15c1dee2-1e00-0000-9bb8-1c365e140000 pid=5214 clone guuid=c863f5e2-1e00-0000-9bb8-1c365f140000 pid=5215 /usr/sbin/useradd guuid=f1dec9c2-1e00-0000-9bb8-1c3651140000 pid=5201->guuid=c863f5e2-1e00-0000-9bb8-1c365f140000 pid=5215 clone guuid=e7bf0be3-1e00-0000-9bb8-1c3660140000 pid=5216 /usr/sbin/useradd guuid=f1dec9c2-1e00-0000-9bb8-1c3651140000 pid=5201->guuid=e7bf0be3-1e00-0000-9bb8-1c3660140000 pid=5216 clone guuid=472f22e3-1e00-0000-9bb8-1c3661140000 pid=5217 /usr/sbin/useradd guuid=f1dec9c2-1e00-0000-9bb8-1c3651140000 pid=5201->guuid=472f22e3-1e00-0000-9bb8-1c3661140000 pid=5217 clone guuid=678139e3-1e00-0000-9bb8-1c3662140000 pid=5218 /usr/sbin/useradd guuid=f1dec9c2-1e00-0000-9bb8-1c3651140000 pid=5201->guuid=678139e3-1e00-0000-9bb8-1c3662140000 pid=5218 clone guuid=e809bfe3-1e00-0000-9bb8-1c3665140000 pid=5221 /usr/bin/find guuid=7cdf72e3-1e00-0000-9bb8-1c3663140000 pid=5219->guuid=e809bfe3-1e00-0000-9bb8-1c3665140000 pid=5221 execve guuid=49e02b03-1f00-0000-9bb8-1c366e140000 pid=5230 /usr/bin/chfn guuid=bc15dcf9-1e00-0000-9bb8-1c366d140000 pid=5229->guuid=49e02b03-1f00-0000-9bb8-1c366e140000 pid=5230 clone guuid=e65c5f03-1f00-0000-9bb8-1c366f140000 pid=5231 /usr/bin/chfn guuid=bc15dcf9-1e00-0000-9bb8-1c366d140000 pid=5229->guuid=e65c5f03-1f00-0000-9bb8-1c366f140000 pid=5231 clone guuid=0d388603-1f00-0000-9bb8-1c3670140000 pid=5232 /usr/bin/chfn guuid=bc15dcf9-1e00-0000-9bb8-1c366d140000 pid=5229->guuid=0d388603-1f00-0000-9bb8-1c3670140000 pid=5232 clone guuid=964dc403-1f00-0000-9bb8-1c3671140000 pid=5233 /usr/bin/chfn guuid=bc15dcf9-1e00-0000-9bb8-1c366d140000 pid=5229->guuid=964dc403-1f00-0000-9bb8-1c3671140000 pid=5233 clone guuid=c383ee03-1f00-0000-9bb8-1c3672140000 pid=5234 /usr/bin/chfn guuid=bc15dcf9-1e00-0000-9bb8-1c366d140000 pid=5229->guuid=c383ee03-1f00-0000-9bb8-1c3672140000 pid=5234 clone guuid=b5679614-1f00-0000-9bb8-1c3674140000 pid=5236 /usr/bin/gpasswd guuid=e4245d04-1f00-0000-9bb8-1c3673140000 pid=5235->guuid=b5679614-1f00-0000-9bb8-1c3674140000 pid=5236 clone guuid=9a31ac14-1f00-0000-9bb8-1c3675140000 pid=5237 /usr/bin/gpasswd guuid=e4245d04-1f00-0000-9bb8-1c3673140000 pid=5235->guuid=9a31ac14-1f00-0000-9bb8-1c3675140000 pid=5237 clone guuid=7a40c314-1f00-0000-9bb8-1c3676140000 pid=5238 /usr/bin/gpasswd guuid=e4245d04-1f00-0000-9bb8-1c3673140000 pid=5235->guuid=7a40c314-1f00-0000-9bb8-1c3676140000 pid=5238 clone guuid=593be014-1f00-0000-9bb8-1c3677140000 pid=5239 /usr/bin/gpasswd guuid=e4245d04-1f00-0000-9bb8-1c3673140000 pid=5235->guuid=593be014-1f00-0000-9bb8-1c3677140000 pid=5239 clone guuid=4c2cf114-1f00-0000-9bb8-1c3678140000 pid=5240 /usr/bin/gpasswd guuid=e4245d04-1f00-0000-9bb8-1c3673140000 pid=5235->guuid=4c2cf114-1f00-0000-9bb8-1c3678140000 pid=5240 clone guuid=157d8a15-1f00-0000-9bb8-1c3679140000 pid=5241->0fd0acc8-dfb6-529f-8986-56cdc3ae41d6 con guuid=157d8a15-1f00-0000-9bb8-1c3679140000 pid=5241->558177e1-1f18-5f39-990b-d68b1c194e8a con guuid=157d8a15-1f00-0000-9bb8-1c3679140000 pid=5241->cbc59886-1795-52e1-b014-449ae22fd09b con guuid=6ee0e017-1f00-0000-9bb8-1c367a140000 pid=5242 /usr/sbin/usermod delete-file write-config guuid=157d8a15-1f00-0000-9bb8-1c3679140000 pid=5241->guuid=6ee0e017-1f00-0000-9bb8-1c367a140000 pid=5242 execve guuid=fe758027-1f00-0000-9bb8-1c367b140000 pid=5243 /usr/sbin/usermod guuid=6ee0e017-1f00-0000-9bb8-1c367a140000 pid=5242->guuid=fe758027-1f00-0000-9bb8-1c367b140000 pid=5243 clone guuid=be6e9927-1f00-0000-9bb8-1c367c140000 pid=5244 /usr/sbin/usermod guuid=6ee0e017-1f00-0000-9bb8-1c367a140000 pid=5242->guuid=be6e9927-1f00-0000-9bb8-1c367c140000 pid=5244 clone guuid=a474c227-1f00-0000-9bb8-1c367d140000 pid=5245 /usr/sbin/usermod guuid=6ee0e017-1f00-0000-9bb8-1c367a140000 pid=5242->guuid=a474c227-1f00-0000-9bb8-1c367d140000 pid=5245 clone guuid=1a7ceb27-1f00-0000-9bb8-1c367e140000 pid=5246 /usr/sbin/usermod guuid=6ee0e017-1f00-0000-9bb8-1c367a140000 pid=5242->guuid=1a7ceb27-1f00-0000-9bb8-1c367e140000 pid=5246 clone guuid=5ef0fe27-1f00-0000-9bb8-1c367f140000 pid=5247 /usr/sbin/usermod guuid=6ee0e017-1f00-0000-9bb8-1c367a140000 pid=5242->guuid=5ef0fe27-1f00-0000-9bb8-1c367f140000 pid=5247 clone guuid=c1fa2628-1f00-0000-9bb8-1c3680140000 pid=5248 /usr/sbin/usermod guuid=6ee0e017-1f00-0000-9bb8-1c367a140000 pid=5242->guuid=c1fa2628-1f00-0000-9bb8-1c3680140000 pid=5248 clone guuid=47337728-1f00-0000-9bb8-1c3681140000 pid=5249->0fd0acc8-dfb6-529f-8986-56cdc3ae41d6 con guuid=47337728-1f00-0000-9bb8-1c3681140000 pid=5249->558177e1-1f18-5f39-990b-d68b1c194e8a con guuid=47337728-1f00-0000-9bb8-1c3681140000 pid=5249->cbc59886-1795-52e1-b014-449ae22fd09b con guuid=f47cd229-1f00-0000-9bb8-1c3682140000 pid=5250 /usr/bin/chown guuid=47337728-1f00-0000-9bb8-1c3681140000 pid=5249->guuid=f47cd229-1f00-0000-9bb8-1c3682140000 pid=5250 execve
Result
Threat name:
n/a
Detection:
malicious
Classification:
evad
Score:
48 / 100
Signature
Modifies the '.bashrc' or '.bash_profile' file typically for persisting actions
Sample is packed with UPX
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1938376 Sample: vcimanagement.x86.elf Startdate: 07/07/2026 Architecture: LINUX Score: 48 64 94.154.43.42, 8080 CDNEXTGB Turkey 2->64 66 185.125.190.26, 443 CANONICAL-ASGB United Kingdom 2->66 68 Sample is packed with UPX 2->68 10 vcimanagement.x86.elf 2->10         started        signatures3 process4 process5 12 vcimanagement.x86.elf sudo 10->12         started        14 vcimanagement.x86.elf sudo 10->14         started        16 vcimanagement.x86.elf sudo 10->16         started        18 vcimanagement.x86.elf 10->18         started        process6 20 sudo adduser 12->20         started        24 sudo usermod 14->24         started        26 sudo chown 16->26         started        file7 62 /home/cursinq/.bashrc, ASCII 20->62 dropped 70 Modifies the '.bashrc' or '.bash_profile' file typically for persisting actions 20->70 28 adduser useradd 20->28         started        30 adduser groupadd 20->30         started        32 adduser chfn 20->32         started        40 3 other processes 20->40 34 usermod 24->34         started        36 usermod 24->36         started        38 usermod 24->38         started        42 3 other processes 24->42 signatures8 process9 process10 44 useradd pam_tally2 28->44         started        56 6 other processes 28->56 46 groupadd 30->46         started        48 groupadd 30->48         started        50 groupadd 30->50         started        58 2 other processes 30->58 60 5 other processes 32->60 52 sh find 40->52         started        54 sh 40->54         started       
Threat name:
Linux.Trojan.Generic
Status:
Suspicious
First seen:
2026-07-07 08:19:42 UTC
File Type:
ELF64 Little (Exe)
AV detection:
8 of 38 (21.05%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  8/10
Tags:
credential_access defense_evasion discovery execution linux persistence privilege_escalation upx
Behaviour
GoLang User-Agent
Enumerates kernel/hardware configuration
Reads runtime system information
Writes file to tmp directory
Changes its process name
Creates .desktop file
Modifies Bash startup script
Abuse Elevation Control Mechanism: Sudo and Sudo Caching
Adds a user to the system
Creates/modifies environment variables
OS Credential Dumping
Modifies password files for system users/ groups
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:TH_Generic_MassHunt_Linux_Malware_2026_CYFARE
Author:CYFARE
Description:Generic Linux malware mass-hunt rule - 2026
Reference:https://cyfare.net/
Rule name:upx_packed_elf_v1
Author:RandomMalware

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

elf 93ffa6afdbc71c9f6a0a8752ccdbbf697a7e2cca5a146bf010cb885140287522

(this sample)

  
Delivery method
Distributed via web download

Comments