🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b16cc916e03569d81ad30983a1b2be8a707ee056fd25e2db4b454fabd097a41a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 4


Intelligence 4 IOCs YARA 2 File information Comments

SHA256 hash: b16cc916e03569d81ad30983a1b2be8a707ee056fd25e2db4b454fabd097a41a
SHA3-384 hash: 565acbdd5dc489a422876ef0e19df3ecaa798dea9ef957eb58976f14ca640dfc2f58470c08c727cf47b6388554a3f3b8
SHA1 hash: 0554dee61c4519afdc79d59af2a7edc7b1eb286d
MD5 hash: 215e71df738e27387cd8e388619cb3a4
humanhash: iowa-indigo-happy-beer
File name:i686
Download: download sample
File size:25'600 bytes
First seen:2026-09-18 14:53:32 UTC
Last seen:Never
File type: elf
MIME type:application/x-executable
ssdeep 768:YNAiuYEgHskm7vllyqnuUWhpDk95qgYgt:YGwEg+plduUC85ggt
TLSH T1C3B22A80E587E4F4D82B46B980E2B63E9331D5197514D91AFF719BBDEE23D029B0B209
telfhash t11f01c8a97e2524f1f7c2bc4c8b1d5703e3369ef6462274b584f5121137d2245d172545
TrID 50.1% (.) ELF Executable and Linkable format (Linux) (4022/12)
49.8% (.O) ELF Executable and Linkable format (generic) (4000/1)
Magika elf
Reporter abuse_ch
Tags:elf upx-dec


Avatar
abuse_ch
UPX decompressed file, sourced from SHA256 1fdcac457a1d26dbf62f5822c5b325ca8180f7719ab894b0bca09022409040be
File size (compressed) :16'232 bytes
File size (de-compressed) :25'600 bytes
Format:linux/i386
Packed file: 1fdcac457a1d26dbf62f5822c5b325ca8180f7719ab894b0bca09022409040be

Intelligence


File Origin
# of uploads :
1
# of downloads :
63
Origin country :
NL NL
Vendor Threat Intelligence
No detections
Result
Verdict:
Clean
Maliciousness:

Behaviour
Sends data to a server
Receives data from a server
Runs as daemon
Kills processes
Connection attempt
Status:
terminated
Behavior Graph:
%3 guuid=cc171712-2000-0000-9fba-baa5dd090000 pid=2525 /usr/bin/sudo guuid=9f479d1a-2000-0000-9fba-baa5ee090000 pid=2542 /tmp/sample.bin guuid=cc171712-2000-0000-9fba-baa5dd090000 pid=2525->guuid=9f479d1a-2000-0000-9fba-baa5ee090000 pid=2542 execve guuid=9ac0da1a-2000-0000-9fba-baa5ef090000 pid=2543 /tmp/sample.bin guuid=9f479d1a-2000-0000-9fba-baa5ee090000 pid=2542->guuid=9ac0da1a-2000-0000-9fba-baa5ef090000 pid=2543 clone guuid=9e31ee1a-2000-0000-9fba-baa5f1090000 pid=2545 /tmp/sample.bin net send-data zombie guuid=9ac0da1a-2000-0000-9fba-baa5ef090000 pid=2543->guuid=9e31ee1a-2000-0000-9fba-baa5f1090000 pid=2545 clone 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=9e31ee1a-2000-0000-9fba-baa5f1090000 pid=2545->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con ea9aec56-574a-5b53-9938-31a01de77f69 94.154.43.241:11121 guuid=9e31ee1a-2000-0000-9fba-baa5f1090000 pid=2545->ea9aec56-574a-5b53-9938-31a01de77f69 send: 12B guuid=74770e1c-2000-0000-9fba-baa5f3090000 pid=2547 /tmp/sample.bin guuid=9e31ee1a-2000-0000-9fba-baa5f1090000 pid=2545->guuid=74770e1c-2000-0000-9fba-baa5f3090000 pid=2547 clone
Gathering data
Result
Threat name:
n/a
Detection:
malicious
Classification:
n/a
Score:
48 / 100
Signature
Malicious sample detected (through community Yara rule)
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1974835 Sample: i686.elf Startdate: 18/09/2026 Architecture: LINUX Score: 48 21 94.154.43.241, 11121, 54166, 54168 CDNEXTGB Netherlands 2->21 23 Malicious sample detected (through community Yara rule) 2->23 9 i686.elf 2->9         started        11 python3.8 dpkg 2->11         started        signatures3 process4 process5 13 i686.elf 9->13         started        process6 15 i686.elf 13->15         started        process7 17 i686.elf 15->17         started        19 i686.elf 15->19         started       
Result
Malware family:
n/a
Score:
  1/10
Tags:
linux
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Linux_Trojan_Mirai_cc93863b
Author:Elastic Security
Rule name:TH_Generic_MassHunt_Linux_Malware_2026_CYFARE
Author:CYFARE
Description:Generic Linux malware mass-hunt rule - 2026
Reference:https://cyfare.net/

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

elf b16cc916e03569d81ad30983a1b2be8a707ee056fd25e2db4b454fabd097a41a

(this sample)

  
Delivery method
Distributed via web download

Comments