MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 af7d740565602b5318dc6b5cef6462741be7c38ebff035e2ea587d6fe82e464b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA 7 File information Comments

SHA256 hash: af7d740565602b5318dc6b5cef6462741be7c38ebff035e2ea587d6fe82e464b
SHA3-384 hash: 39c1343204f9173635a6b92d13fc36327f47841f681b016c8575c04947057c6c47b85a7f0a139ff22523f7449144bf99
SHA1 hash: e82174cb091f90df9b117bd6536e109429e52365
MD5 hash: cfb48e7256c34fca0447cd0e6bc7d1cd
humanhash: thirteen-jupiter-cold-johnny
File name:bot_x86_64
Download: download sample
File size:1'499'496 bytes
First seen:2026-06-07 07:25:27 UTC
Last seen:2026-06-07 22:07:51 UTC
File type: elf
MIME type:application/x-executable
ssdeep 24576:kTeszlIEvVsrjh6WwwDbFB1z71Zi5gq+kcnQHNjuc/Wl4Wr:meszlI6VsXh6WwwD9z71Zi5dD9ucuv
TLSH T173658D56F3F37CFEC1638131869BC7626936F86512022E3B6584A2342D3AEA41F45F67
telfhash t18d2105acddb559184b41b1000e97bf7382c8961b122479737f6151dc7ed312d554397e
TrID 50.1% (.) ELF Executable and Linkable format (Linux) (4022/12)
49.8% (.O) ELF Executable and Linkable format (generic) (4000/1)
Magika elf
Reporter abuse_ch
Tags:elf

Intelligence


File Origin
# of uploads :
6
# of downloads :
41
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Result
Verdict:
Malware
Maliciousness:

Behaviour
Sets a written file as executable
Launching a process
Runs as daemon
Collects information on the OS
Receives data from a server
Connection attempt
Sends data to a server
Collects information on the CPU
Creating a process from a recently created file
Writes files to system directory
Creates or modifies files in /cron to set up autorun
Substitutes an application name
Creates or modifies files in /init.d to set up autorun
Status:
terminated
Behavior Graph:
%3 guuid=1dece2be-1b00-0000-574c-11b8a50c0000 pid=3237 /usr/bin/sudo guuid=fb0866c1-1b00-0000-574c-11b8a70c0000 pid=3239 /tmp/sample.bin net send-data write-config guuid=1dece2be-1b00-0000-574c-11b8a50c0000 pid=3237->guuid=fb0866c1-1b00-0000-574c-11b8a70c0000 pid=3239 execve 98cf2512-4663-506b-aa59-5f72faf2dc73 176.65.139.41:443 guuid=fb0866c1-1b00-0000-574c-11b8a70c0000 pid=3239->98cf2512-4663-506b-aa59-5f72faf2dc73 send: 111B guuid=a31093c1-1b00-0000-574c-11b8a80c0000 pid=3240 /usr/bin/dash guuid=fb0866c1-1b00-0000-574c-11b8a70c0000 pid=3239->guuid=a31093c1-1b00-0000-574c-11b8a80c0000 pid=3240 execve guuid=c6296ac9-1b00-0000-574c-11b8ac0c0000 pid=3244 /usr/bin/dash guuid=fb0866c1-1b00-0000-574c-11b8a70c0000 pid=3239->guuid=c6296ac9-1b00-0000-574c-11b8ac0c0000 pid=3244 execve guuid=ace227ca-1b00-0000-574c-11b8b00c0000 pid=3248 /usr/bin/dash guuid=fb0866c1-1b00-0000-574c-11b8a70c0000 pid=3239->guuid=ace227ca-1b00-0000-574c-11b8b00c0000 pid=3248 execve guuid=6455b6cb-1b00-0000-574c-11b8b30c0000 pid=3251 /usr/bin/dash guuid=fb0866c1-1b00-0000-574c-11b8a70c0000 pid=3239->guuid=6455b6cb-1b00-0000-574c-11b8b30c0000 pid=3251 execve guuid=4f8fdbcd-1b00-0000-574c-11b8b90c0000 pid=3257 /usr/bin/dash guuid=fb0866c1-1b00-0000-574c-11b8a70c0000 pid=3239->guuid=4f8fdbcd-1b00-0000-574c-11b8b90c0000 pid=3257 execve guuid=fb0866c1-1b00-0000-574c-11b8a70c0000 pid=3260 /tmp/sample.bin guuid=fb0866c1-1b00-0000-574c-11b8a70c0000 pid=3239->guuid=fb0866c1-1b00-0000-574c-11b8a70c0000 pid=3260 clone guuid=fb0866c1-1b00-0000-574c-11b8a70c0000 pid=3261 /tmp/sample.bin guuid=fb0866c1-1b00-0000-574c-11b8a70c0000 pid=3239->guuid=fb0866c1-1b00-0000-574c-11b8a70c0000 pid=3261 clone guuid=fb0866c1-1b00-0000-574c-11b8a70c0000 pid=3262 /tmp/sample.bin guuid=fb0866c1-1b00-0000-574c-11b8a70c0000 pid=3239->guuid=fb0866c1-1b00-0000-574c-11b8a70c0000 pid=3262 clone guuid=ee9a03d1-1b00-0000-574c-11b8c00c0000 pid=3264 /usr/bin/dash guuid=fb0866c1-1b00-0000-574c-11b8a70c0000 pid=3239->guuid=ee9a03d1-1b00-0000-574c-11b8c00c0000 pid=3264 execve guuid=bb7422c2-1b00-0000-574c-11b8a90c0000 pid=3241 /usr/bin/cp guuid=a31093c1-1b00-0000-574c-11b8a80c0000 pid=3240->guuid=bb7422c2-1b00-0000-574c-11b8a90c0000 pid=3241 execve guuid=97f7c9c8-1b00-0000-574c-11b8ab0c0000 pid=3243 /usr/bin/chmod guuid=a31093c1-1b00-0000-574c-11b8a80c0000 pid=3240->guuid=97f7c9c8-1b00-0000-574c-11b8ab0c0000 pid=3243 execve guuid=16a0b8c9-1b00-0000-574c-11b8ad0c0000 pid=3245 /etc/init.d/S99sysupd guuid=c6296ac9-1b00-0000-574c-11b8ac0c0000 pid=3244->guuid=16a0b8c9-1b00-0000-574c-11b8ad0c0000 pid=3245 execve guuid=213e07ca-1b00-0000-574c-11b8ae0c0000 pid=3246 /usr/bin/dash zombie guuid=16a0b8c9-1b00-0000-574c-11b8ad0c0000 pid=3245->guuid=213e07ca-1b00-0000-574c-11b8ae0c0000 pid=3246 clone guuid=4d1e21ca-1b00-0000-574c-11b8af0c0000 pid=3247 /usr/bin/pgrep guuid=213e07ca-1b00-0000-574c-11b8ae0c0000 pid=3246->guuid=4d1e21ca-1b00-0000-574c-11b8af0c0000 pid=3247 execve guuid=318fc9ca-1b00-0000-574c-11b8b10c0000 pid=3249 /usr/bin/ln guuid=ace227ca-1b00-0000-574c-11b8b00c0000 pid=3248->guuid=318fc9ca-1b00-0000-574c-11b8b10c0000 pid=3249 execve guuid=ba6765cd-1b00-0000-574c-11b8b60c0000 pid=3254 /usr/bin/dash zombie guuid=6455b6cb-1b00-0000-574c-11b8b30c0000 pid=3251->guuid=ba6765cd-1b00-0000-574c-11b8b60c0000 pid=3254 clone guuid=085ed2cd-1b00-0000-574c-11b8b80c0000 pid=3256 /usr/bin/pgrep guuid=ba6765cd-1b00-0000-574c-11b8b60c0000 pid=3254->guuid=085ed2cd-1b00-0000-574c-11b8b80c0000 pid=3256 execve guuid=97b1dcd1-1b00-0000-574c-11b8c20c0000 pid=3266 /usr/bin/uname guuid=ee9a03d1-1b00-0000-574c-11b8c00c0000 pid=3264->guuid=97b1dcd1-1b00-0000-574c-11b8c20c0000 pid=3266 execve
Result
Threat name:
n/a
Detection:
malicious
Classification:
troj.evad
Score:
60 / 100
Signature
Drops files in suspicious directories
Drops invisible ELF files
Sample tries to persist itself using cron
Sample tries to persist itself using System V runlevels
Sample tries to set files in /etc globally writable
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1924082 Sample: bot_x86_64.elf Startdate: 07/06/2026 Architecture: LINUX Score: 60 57 169.254.169.254, 80 USDOS-USDepartmentofStateUS ZZ 2->57 59 176.65.139.41, 443, 57490, 57492 STORMINDUSTRIESHostingServicesUS Netherlands 2->59 61 2 other IPs or domains 2->61 9 bot_x86_64.elf 2->9         started        13 python3.8 dpkg 2->13         started        process3 file4 51 /var/spool/cron/crontabs/root, ASCII 9->51 dropped 53 /etc/rc.local, POSIX 9->53 dropped 55 /etc/init.d/S99sysupd, POSIX 9->55 dropped 69 Sample tries to set files in /etc globally writable 9->69 71 Drops files in suspicious directories 9->71 73 Sample tries to persist itself using cron 9->73 75 Sample tries to persist itself using System V runlevels 9->75 15 bot_x86_64.elf sh 9->15         started        17 bot_x86_64.elf sh 9->17         started        19 bot_x86_64.elf sh 9->19         started        21 10 other processes 9->21 signatures5 process6 process7 23 sh cp 15->23         started        27 sh chmod 15->27         started        29 sh ln 17->29         started        31 sh S99sysupd 19->31         started        33 sh 21->33         started        35 sh 21->35         started        37 sh grep 21->37         started        39 6 other processes 21->39 file8 49 /usr/bin/.sysupd, ELF 23->49 dropped 63 Drops invisible ELF files 23->63 65 Drops files in suspicious directories 23->65 67 Sample tries to persist itself using System V runlevels 29->67 41 S99sysupd nohup .sysupd 31->41         started        43 sh pgrep 33->43         started        45 sh pgrep 35->45         started        signatures9 process10 process11 47 S99sysupd pgrep 41->47         started       
Result
Malware family:
n/a
Score:
  7/10
Tags:
antivm defense_evasion discovery execution linux persistence privilege_escalation
Behaviour
Reads runtime system information
Changes its process name
Checks CPU configuration
Reads CPU attributes
Creates/modifies Cron job
Enumerates running processes
Modifies init.d
Modifies rc script
Reads MAC address of network interface
Write file to user bin folder
File and Directory Permissions Modification
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:F01_s1ckrule
Author:s1ckb017
Rule name:ldpreload
Author:xorseed
Reference:https://stuff.rop.io/
Rule name:malwareelf55503
Rule name:setsockopt
Author:Tim Brown @timb_machine
Description:Hunts for setsockopt() red flags
Rule name:TH_Generic_MassHunt_Linux_Malware_2026_CYFARE
Author:CYFARE
Description:Generic Linux malware mass-hunt rule - 2026
Reference:https://cyfare.net/
Rule name:unixredflags3
Author:Tim Brown @timb_machine
Description:Hunts for UNIX red flags

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

elf af7d740565602b5318dc6b5cef6462741be7c38ebff035e2ea587d6fe82e464b

(this sample)

  
Delivery method
Distributed via web download

Comments