🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 abdc8f915c149e5ca265a40dbafa59b92159a1d40478ced199e4e384060cbe3f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 3


Intelligence 3 IOCs YARA 1 File information Comments

SHA256 hash: abdc8f915c149e5ca265a40dbafa59b92159a1d40478ced199e4e384060cbe3f
SHA3-384 hash: e595881dece6b7acfc02f0b85cd37e5ec02720ca938f14f89144f28404a2278b34e1889b119450aa1048b0892e975062
SHA1 hash: 74d2464aac6ea7afd96d731412a56b74c7faba24
MD5 hash: 654612c0c9ffa69cb3783d7f96defd2b
humanhash: twenty-solar-jupiter-monkey
File name:abdc8f915c149e5ca265a40dbafa59b92159a1d40478ced199e4e384060cbe3f.elf
Download: download sample
File size:34'818'868 bytes
First seen:2026-09-28 20:53:16 UTC
Last seen:Never
File type: elf
MIME type:application/x-sharedlib
ssdeep 786432:30Tn1zXtkej56gYIzLeuvbX3ZPhYnePEJDpwQ2:gn1Dtl56gY+L1PEJDh2
TLSH T1E57733B744EA86E5F3E8BBFBBC539609EFC4B3E0A1258D153D415C3A02D060C666467B
TrID 50.1% (.) ELF Executable and Linkable format (Linux) (4022/12)
49.8% (.O) ELF Executable and Linkable format (generic) (4000/1)
Magika elf
Reporter Kejult
Tags:CoinMiner elf

Intelligence


File Origin
# of uploads :
1
# of downloads :
75
Origin country :
GR GR
Vendor Threat Intelligence
No detections
Result
Verdict:
Clean
Maliciousness:
Verdict:
Unknown
File Type:
elf.64.le
First seen:
2026-09-25T16:01:00Z UTC
Last seen:
2026-09-30T17:59:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=05de9a08-1700-0000-fbbd-7662420d0000 pid=3394 /usr/bin/sudo guuid=ce350a0b-1700-0000-fbbd-76624c0d0000 pid=3404 /tmp/sample.bin mprotect-exec guuid=05de9a08-1700-0000-fbbd-7662420d0000 pid=3394->guuid=ce350a0b-1700-0000-fbbd-76624c0d0000 pid=3404 execve guuid=ce350a0b-1700-0000-fbbd-76624c0d0000 pid=4400 /tmp/sample.bin guuid=ce350a0b-1700-0000-fbbd-76624c0d0000 pid=3404->guuid=ce350a0b-1700-0000-fbbd-76624c0d0000 pid=4400 clone guuid=ce350a0b-1700-0000-fbbd-76624c0d0000 pid=4401 /tmp/sample.bin guuid=ce350a0b-1700-0000-fbbd-76624c0d0000 pid=3404->guuid=ce350a0b-1700-0000-fbbd-76624c0d0000 pid=4401 clone guuid=ce350a0b-1700-0000-fbbd-76624c0d0000 pid=4402 /tmp/sample.bin guuid=ce350a0b-1700-0000-fbbd-76624c0d0000 pid=3404->guuid=ce350a0b-1700-0000-fbbd-76624c0d0000 pid=4402 clone guuid=ce350a0b-1700-0000-fbbd-76624c0d0000 pid=4403 /tmp/sample.bin guuid=ce350a0b-1700-0000-fbbd-76624c0d0000 pid=3404->guuid=ce350a0b-1700-0000-fbbd-76624c0d0000 pid=4403 clone guuid=ce350a0b-1700-0000-fbbd-76624c0d0000 pid=4404 /tmp/sample.bin guuid=ce350a0b-1700-0000-fbbd-76624c0d0000 pid=3404->guuid=ce350a0b-1700-0000-fbbd-76624c0d0000 pid=4404 clone guuid=ce350a0b-1700-0000-fbbd-76624c0d0000 pid=4405 /tmp/sample.bin guuid=ce350a0b-1700-0000-fbbd-76624c0d0000 pid=3404->guuid=ce350a0b-1700-0000-fbbd-76624c0d0000 pid=4405 clone
Gathering data
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:upx_antiunpack_elf64
Author:JPCERT/CC Incident Response Group
Description:UPX Anti-Unpacking technique to magic renamed for ELF64

File information


The table below shows additional information about this malware sample such as delivery method and external references.

  
Delivery method
Distributed via drive-by

Comments