MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b0145d6283981447cb4ccd3247a5855f95a77918922cb5daa5b869672d2e37cd. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 8


Intelligence 8 IOCs YARA 2 File information Comments

SHA256 hash: b0145d6283981447cb4ccd3247a5855f95a77918922cb5daa5b869672d2e37cd
SHA3-384 hash: 6a92c95700f5eebe5de9ff692b598ad19578d1dbf7396ad301d3c114e4403362bb244e152f49d7e5d5a955690f7127ca
SHA1 hash: 7cd9b5b054b7b9ab5e4cb53bd3b9b6da940d1df3
MD5 hash: ab640154862b9bedd70e63a3e18e0b47
humanhash: stairway-equal-mango-vegan
File name:px.x86_64
Download: download sample
File size:3'811'196 bytes
First seen:2026-07-07 05:21:59 UTC
Last seen:Never
File type: elf
MIME type:application/x-executable
ssdeep 98304:d4u5fnMeUpdtbiJsGedCqKcjabpay6d44sXKOvMU:esfnMeUP9iJfed/2phK4MU
TLSH T1E506338F6412B554B25CF47BEAA26224D789036E8EA0D9DFED5C93D8B02F199F0D01DC
TrID 50.1% (.) ELF Executable and Linkable format (Linux) (4022/12)
49.8% (.O) ELF Executable and Linkable format (generic) (4000/1)
Magika elf
Reporter abuse_ch
Tags:elf UPX
File size (compressed) :3'811'196 bytes
File size (de-compressed) :12'506'088 bytes
Format:linux/amd64
Unpacked file: 5ee23a446ab4425d7db8c87badf05812ed01a2fc2cfd20f5f0dc279afa2038ad

Intelligence


File Origin
# of uploads :
1
# of downloads :
98
Origin country :
DE DE
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Changes owner for a file
Creates or modifies symbolic links
Creating a file in the %temp% directory
Changes access rights for a written file
Launching a process
Creating a file
Sends data to a server
Gains root access
Connection attempt
Receives data from a server
Sets a written file as executable
Changes the time when the file was created, accessed, or modified
Changes owner for a written file
Deleting a recently created file
Creates directories
Substitutes an application name
Verdict:
Unknown
Threat level:
  2.5/10
Confidence:
100%
Tags:
packed upx
Verdict:
Malicious
Uses P2P?:
false
Uses anti-vm?:
false
Architecture:
x86
Packer:
UPX
Botnet:
unknown
Number of open files:
8
Number of processes launched:
4
Processes remaning?
false
Remote TCP ports scanned:
not identified
Behaviour
Information Gathering
Botnet C2s
TCP botnet C2(s):
not identified
UDP botnet C2(s):
not identified
Verdict:
Clean
File Type:
elf.64.le
First seen:
2026-07-07T02:37:00Z UTC
Last seen:
2026-07-07T02:52:00Z UTC
Hits:
~100
Status:
terminated
Behavior Graph:
%3 guuid=5888dfd7-1e00-0000-c8a8-62c43c140000 pid=5180 /usr/bin/sudo guuid=a82f4ddc-1e00-0000-c8a8-62c43d140000 pid=5181 /tmp/sample.bin mprotect-exec net write-file guuid=5888dfd7-1e00-0000-c8a8-62c43c140000 pid=5180->guuid=a82f4ddc-1e00-0000-c8a8-62c43d140000 pid=5181 execve e05ac331-4d6c-529a-b012-a8a5bfa6a257 94.154.43.42:8080 guuid=a82f4ddc-1e00-0000-c8a8-62c43d140000 pid=5181->e05ac331-4d6c-529a-b012-a8a5bfa6a257 con guuid=a82f4ddc-1e00-0000-c8a8-62c43d140000 pid=5182 /tmp/sample.bin guuid=a82f4ddc-1e00-0000-c8a8-62c43d140000 pid=5181->guuid=a82f4ddc-1e00-0000-c8a8-62c43d140000 pid=5182 clone guuid=a82f4ddc-1e00-0000-c8a8-62c43d140000 pid=5183 /tmp/sample.bin guuid=a82f4ddc-1e00-0000-c8a8-62c43d140000 pid=5181->guuid=a82f4ddc-1e00-0000-c8a8-62c43d140000 pid=5183 clone guuid=a82f4ddc-1e00-0000-c8a8-62c43d140000 pid=5184 /tmp/sample.bin guuid=a82f4ddc-1e00-0000-c8a8-62c43d140000 pid=5181->guuid=a82f4ddc-1e00-0000-c8a8-62c43d140000 pid=5184 clone guuid=a82f4ddc-1e00-0000-c8a8-62c43d140000 pid=5185 /tmp/sample.bin send-data guuid=a82f4ddc-1e00-0000-c8a8-62c43d140000 pid=5181->guuid=a82f4ddc-1e00-0000-c8a8-62c43d140000 pid=5185 clone guuid=406a5c3e-1f00-0000-c8a8-62c442140000 pid=5186 /tmp/sample.bin guuid=a82f4ddc-1e00-0000-c8a8-62c43d140000 pid=5181->guuid=406a5c3e-1f00-0000-c8a8-62c442140000 pid=5186 clone guuid=4dec693e-1f00-0000-c8a8-62c443140000 pid=5187 /usr/bin/sudo net guuid=a82f4ddc-1e00-0000-c8a8-62c43d140000 pid=5181->guuid=4dec693e-1f00-0000-c8a8-62c443140000 pid=5187 execve guuid=d2bfed41-2000-0000-c8a8-62c46e140000 pid=5230 /usr/bin/sudo net guuid=a82f4ddc-1e00-0000-c8a8-62c43d140000 pid=5181->guuid=d2bfed41-2000-0000-c8a8-62c46e140000 pid=5230 execve guuid=adaea15f-2000-0000-c8a8-62c479140000 pid=5241 /usr/bin/sudo net guuid=a82f4ddc-1e00-0000-c8a8-62c43d140000 pid=5181->guuid=adaea15f-2000-0000-c8a8-62c479140000 pid=5241 execve guuid=a82f4ddc-1e00-0000-c8a8-62c43d140000 pid=5185->e05ac331-4d6c-529a-b012-a8a5bfa6a257 send: 1120B 0fd0acc8-dfb6-529f-8986-56cdc3ae41d6 10.0.2.15:0 guuid=4dec693e-1f00-0000-c8a8-62c443140000 pid=5187->0fd0acc8-dfb6-529f-8986-56cdc3ae41d6 con 558177e1-1f18-5f39-990b-d68b1c194e8a fec0::5054:ff:fe12:3456:0 guuid=4dec693e-1f00-0000-c8a8-62c443140000 pid=5187->558177e1-1f18-5f39-990b-d68b1c194e8a con cbc59886-1795-52e1-b014-449ae22fd09b fe80::5054:ff:fe12:3456:0 guuid=4dec693e-1f00-0000-c8a8-62c443140000 pid=5187->cbc59886-1795-52e1-b014-449ae22fd09b con guuid=7ecc0e41-1f00-0000-c8a8-62c444140000 pid=5188 /usr/sbin/adduser write-file guuid=4dec693e-1f00-0000-c8a8-62c443140000 pid=5187->guuid=7ecc0e41-1f00-0000-c8a8-62c444140000 pid=5188 execve guuid=ae0e3950-1f00-0000-c8a8-62c445140000 pid=5189 /usr/sbin/groupadd delete-file write-config guuid=7ecc0e41-1f00-0000-c8a8-62c444140000 pid=5188->guuid=ae0e3950-1f00-0000-c8a8-62c445140000 pid=5189 execve guuid=abbc5069-1f00-0000-c8a8-62c44b140000 pid=5195 /usr/sbin/useradd delete-file write-config guuid=7ecc0e41-1f00-0000-c8a8-62c444140000 pid=5188->guuid=abbc5069-1f00-0000-c8a8-62c44b140000 pid=5195 execve guuid=a604898c-1f00-0000-c8a8-62c452140000 pid=5202 /usr/bin/dash guuid=7ecc0e41-1f00-0000-c8a8-62c444140000 pid=5188->guuid=a604898c-1f00-0000-c8a8-62c452140000 pid=5202 execve guuid=a998ef8d-1f00-0000-c8a8-62c454140000 pid=5204 /usr/bin/passwd write-config guuid=7ecc0e41-1f00-0000-c8a8-62c444140000 pid=5188->guuid=a998ef8d-1f00-0000-c8a8-62c454140000 pid=5204 execve guuid=ef918ca9-1f00-0000-c8a8-62c455140000 pid=5205 /usr/bin/chfn delete-file write-config guuid=7ecc0e41-1f00-0000-c8a8-62c444140000 pid=5188->guuid=ef918ca9-1f00-0000-c8a8-62c455140000 pid=5205 execve guuid=a9832fbc-1f00-0000-c8a8-62c461140000 pid=5217 /usr/bin/gpasswd delete-file write-config guuid=7ecc0e41-1f00-0000-c8a8-62c444140000 pid=5188->guuid=a9832fbc-1f00-0000-c8a8-62c461140000 pid=5217 execve guuid=6daa9466-1f00-0000-c8a8-62c446140000 pid=5190 /usr/sbin/groupadd guuid=ae0e3950-1f00-0000-c8a8-62c445140000 pid=5189->guuid=6daa9466-1f00-0000-c8a8-62c446140000 pid=5190 clone guuid=a921bd68-1f00-0000-c8a8-62c447140000 pid=5191 /usr/sbin/groupadd guuid=ae0e3950-1f00-0000-c8a8-62c445140000 pid=5189->guuid=a921bd68-1f00-0000-c8a8-62c447140000 pid=5191 clone guuid=1ec5d368-1f00-0000-c8a8-62c448140000 pid=5192 /usr/sbin/groupadd guuid=ae0e3950-1f00-0000-c8a8-62c445140000 pid=5189->guuid=1ec5d368-1f00-0000-c8a8-62c448140000 pid=5192 clone guuid=2458fb68-1f00-0000-c8a8-62c449140000 pid=5193 /usr/sbin/groupadd guuid=ae0e3950-1f00-0000-c8a8-62c445140000 pid=5189->guuid=2458fb68-1f00-0000-c8a8-62c449140000 pid=5193 clone guuid=d30c1969-1f00-0000-c8a8-62c44a140000 pid=5194 /usr/sbin/groupadd guuid=ae0e3950-1f00-0000-c8a8-62c445140000 pid=5189->guuid=d30c1969-1f00-0000-c8a8-62c44a140000 pid=5194 clone guuid=f19cc08b-1f00-0000-c8a8-62c44c140000 pid=5196 /usr/sbin/useradd guuid=abbc5069-1f00-0000-c8a8-62c44b140000 pid=5195->guuid=f19cc08b-1f00-0000-c8a8-62c44c140000 pid=5196 clone guuid=501dd58b-1f00-0000-c8a8-62c44d140000 pid=5197 /usr/sbin/useradd guuid=abbc5069-1f00-0000-c8a8-62c44b140000 pid=5195->guuid=501dd58b-1f00-0000-c8a8-62c44d140000 pid=5197 clone guuid=0e38f98b-1f00-0000-c8a8-62c44e140000 pid=5198 /usr/sbin/useradd guuid=abbc5069-1f00-0000-c8a8-62c44b140000 pid=5195->guuid=0e38f98b-1f00-0000-c8a8-62c44e140000 pid=5198 clone guuid=463a148c-1f00-0000-c8a8-62c44f140000 pid=5199 /usr/sbin/useradd guuid=abbc5069-1f00-0000-c8a8-62c44b140000 pid=5195->guuid=463a148c-1f00-0000-c8a8-62c44f140000 pid=5199 clone guuid=bb52338c-1f00-0000-c8a8-62c450140000 pid=5200 /usr/sbin/useradd guuid=abbc5069-1f00-0000-c8a8-62c44b140000 pid=5195->guuid=bb52338c-1f00-0000-c8a8-62c450140000 pid=5200 clone guuid=d922458c-1f00-0000-c8a8-62c451140000 pid=5201 /usr/sbin/useradd guuid=abbc5069-1f00-0000-c8a8-62c44b140000 pid=5195->guuid=d922458c-1f00-0000-c8a8-62c451140000 pid=5201 clone guuid=f6dcda8c-1f00-0000-c8a8-62c453140000 pid=5203 /usr/bin/find guuid=a604898c-1f00-0000-c8a8-62c452140000 pid=5202->guuid=f6dcda8c-1f00-0000-c8a8-62c453140000 pid=5203 execve guuid=9b8294bb-1f00-0000-c8a8-62c45c140000 pid=5212 /usr/bin/chfn guuid=ef918ca9-1f00-0000-c8a8-62c455140000 pid=5205->guuid=9b8294bb-1f00-0000-c8a8-62c45c140000 pid=5212 clone guuid=f817aebb-1f00-0000-c8a8-62c45d140000 pid=5213 /usr/bin/chfn guuid=ef918ca9-1f00-0000-c8a8-62c455140000 pid=5205->guuid=f817aebb-1f00-0000-c8a8-62c45d140000 pid=5213 clone guuid=49c1bfbb-1f00-0000-c8a8-62c45e140000 pid=5214 /usr/bin/chfn guuid=ef918ca9-1f00-0000-c8a8-62c455140000 pid=5205->guuid=49c1bfbb-1f00-0000-c8a8-62c45e140000 pid=5214 clone guuid=48edd6bb-1f00-0000-c8a8-62c45f140000 pid=5215 /usr/bin/chfn guuid=ef918ca9-1f00-0000-c8a8-62c455140000 pid=5205->guuid=48edd6bb-1f00-0000-c8a8-62c45f140000 pid=5215 clone guuid=8fd0febb-1f00-0000-c8a8-62c460140000 pid=5216 /usr/bin/chfn guuid=ef918ca9-1f00-0000-c8a8-62c455140000 pid=5205->guuid=8fd0febb-1f00-0000-c8a8-62c460140000 pid=5216 clone guuid=f21a5e40-2000-0000-c8a8-62c469140000 pid=5225 /usr/bin/gpasswd guuid=a9832fbc-1f00-0000-c8a8-62c461140000 pid=5217->guuid=f21a5e40-2000-0000-c8a8-62c469140000 pid=5225 clone guuid=186e8840-2000-0000-c8a8-62c46a140000 pid=5226 /usr/bin/gpasswd guuid=a9832fbc-1f00-0000-c8a8-62c461140000 pid=5217->guuid=186e8840-2000-0000-c8a8-62c46a140000 pid=5226 clone guuid=94f0a840-2000-0000-c8a8-62c46b140000 pid=5227 /usr/bin/gpasswd guuid=a9832fbc-1f00-0000-c8a8-62c461140000 pid=5217->guuid=94f0a840-2000-0000-c8a8-62c46b140000 pid=5227 clone guuid=801adf40-2000-0000-c8a8-62c46c140000 pid=5228 /usr/bin/gpasswd guuid=a9832fbc-1f00-0000-c8a8-62c461140000 pid=5217->guuid=801adf40-2000-0000-c8a8-62c46c140000 pid=5228 clone guuid=dd8bfc40-2000-0000-c8a8-62c46d140000 pid=5229 /usr/bin/gpasswd guuid=a9832fbc-1f00-0000-c8a8-62c461140000 pid=5217->guuid=dd8bfc40-2000-0000-c8a8-62c46d140000 pid=5229 clone guuid=d2bfed41-2000-0000-c8a8-62c46e140000 pid=5230->0fd0acc8-dfb6-529f-8986-56cdc3ae41d6 con guuid=d2bfed41-2000-0000-c8a8-62c46e140000 pid=5230->558177e1-1f18-5f39-990b-d68b1c194e8a con guuid=d2bfed41-2000-0000-c8a8-62c46e140000 pid=5230->cbc59886-1795-52e1-b014-449ae22fd09b con guuid=620c8744-2000-0000-c8a8-62c46f140000 pid=5231 /usr/sbin/usermod delete-file write-config guuid=d2bfed41-2000-0000-c8a8-62c46e140000 pid=5230->guuid=620c8744-2000-0000-c8a8-62c46f140000 pid=5231 execve guuid=79e4c55e-2000-0000-c8a8-62c473140000 pid=5235 /usr/sbin/usermod guuid=620c8744-2000-0000-c8a8-62c46f140000 pid=5231->guuid=79e4c55e-2000-0000-c8a8-62c473140000 pid=5235 clone guuid=9bb5e85e-2000-0000-c8a8-62c474140000 pid=5236 /usr/sbin/usermod guuid=620c8744-2000-0000-c8a8-62c46f140000 pid=5231->guuid=9bb5e85e-2000-0000-c8a8-62c474140000 pid=5236 clone guuid=7efd065f-2000-0000-c8a8-62c475140000 pid=5237 /usr/sbin/usermod guuid=620c8744-2000-0000-c8a8-62c46f140000 pid=5231->guuid=7efd065f-2000-0000-c8a8-62c475140000 pid=5237 clone guuid=9ed8255f-2000-0000-c8a8-62c476140000 pid=5238 /usr/sbin/usermod guuid=620c8744-2000-0000-c8a8-62c46f140000 pid=5231->guuid=9ed8255f-2000-0000-c8a8-62c476140000 pid=5238 clone guuid=68963f5f-2000-0000-c8a8-62c477140000 pid=5239 /usr/sbin/usermod guuid=620c8744-2000-0000-c8a8-62c46f140000 pid=5231->guuid=68963f5f-2000-0000-c8a8-62c477140000 pid=5239 clone guuid=e40d545f-2000-0000-c8a8-62c478140000 pid=5240 /usr/sbin/usermod guuid=620c8744-2000-0000-c8a8-62c46f140000 pid=5231->guuid=e40d545f-2000-0000-c8a8-62c478140000 pid=5240 clone guuid=adaea15f-2000-0000-c8a8-62c479140000 pid=5241->0fd0acc8-dfb6-529f-8986-56cdc3ae41d6 con guuid=adaea15f-2000-0000-c8a8-62c479140000 pid=5241->558177e1-1f18-5f39-990b-d68b1c194e8a con guuid=adaea15f-2000-0000-c8a8-62c479140000 pid=5241->cbc59886-1795-52e1-b014-449ae22fd09b con guuid=b0cd4a61-2000-0000-c8a8-62c47a140000 pid=5242 /usr/bin/chown guuid=adaea15f-2000-0000-c8a8-62c479140000 pid=5241->guuid=b0cd4a61-2000-0000-c8a8-62c47a140000 pid=5242 execve
Result
Threat name:
n/a
Detection:
malicious
Classification:
evad
Score:
48 / 100
Signature
Modifies the '.bashrc' or '.bash_profile' file typically for persisting actions
Sample is packed with UPX
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1938302 Sample: px.x86_64.elf Startdate: 07/07/2026 Architecture: LINUX Score: 48 68 109.202.202.202, 80 INIT7CH Switzerland 2->68 70 94.154.43.42, 44388, 8080 CDNEXTGB Turkey 2->70 72 3 other IPs or domains 2->72 74 Sample is packed with UPX 2->74 10 px.x86_64.elf 2->10         started        12 dash rm 2->12         started        14 dash rm 2->14         started        signatures3 process4 process5 16 px.x86_64.elf sudo 10->16         started        18 px.x86_64.elf sudo 10->18         started        20 px.x86_64.elf sudo 10->20         started        22 px.x86_64.elf 10->22         started        process6 24 sudo adduser 16->24         started        28 sudo usermod 18->28         started        30 sudo chown 20->30         started        file7 66 /home/cursinq/.bashrc, ASCII 24->66 dropped 76 Modifies the '.bashrc' or '.bash_profile' file typically for persisting actions 24->76 32 adduser useradd 24->32         started        34 adduser groupadd 24->34         started        36 adduser chfn 24->36         started        44 3 other processes 24->44 38 usermod 28->38         started        40 usermod 28->40         started        42 usermod 28->42         started        46 3 other processes 28->46 signatures8 process9 process10 48 useradd pam_tally2 32->48         started        60 6 other processes 32->60 50 groupadd 34->50         started        52 groupadd 34->52         started        54 groupadd 34->54         started        62 2 other processes 34->62 64 5 other processes 36->64 56 sh find 44->56         started        58 sh 44->58         started       
Threat name:
Linux.Trojan.Generic
Status:
Suspicious
First seen:
2026-07-07 05:22:46 UTC
File Type:
ELF64 Little (Exe)
AV detection:
6 of 38 (15.79%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  8/10
Tags:
credential_access defense_evasion discovery execution linux persistence privilege_escalation upx
Behaviour
GoLang User-Agent
Enumerates kernel/hardware configuration
Reads runtime system information
Writes file to tmp directory
Changes its process name
Creates .desktop file
Modifies Bash startup script
Abuse Elevation Control Mechanism: Sudo and Sudo Caching
Adds a user to the system
Creates/modifies environment variables
OS Credential Dumping
Modifies password files for system users/ groups
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:TH_Generic_MassHunt_Linux_Malware_2026_CYFARE
Author:CYFARE
Description:Generic Linux malware mass-hunt rule - 2026
Reference:https://cyfare.net/
Rule name:upx_packed_elf_v1
Author:RandomMalware

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

elf b0145d6283981447cb4ccd3247a5855f95a77918922cb5daa5b869672d2e37cd

(this sample)

  
Delivery method
Distributed via web download

Comments