MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b5aef7ade103fd04b5b7e91bfcbba029565488b39d931d979a8c685595bc7009. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Ladvix


Vendor detections: 9


Intelligence 9 IOCs YARA 15 File information Comments

SHA256 hash: b5aef7ade103fd04b5b7e91bfcbba029565488b39d931d979a8c685595bc7009
SHA3-384 hash: b65e6f13e2d7d1f70836a1f096a4129e8f7104e82398b091a9b39850c2a844196a0fd1e7b31b6f6fae6a5f9ea2aecd2e
SHA1 hash: c65ea5840a337bed8ce1222a2c94d20dc34c21e0
MD5 hash: a3d2db00af34cef563efc18ded1249e6
humanhash: harry-emma-rugby-lithium
File name:boss
Download: download sample
Signature Ladvix
File size:2'391'513 bytes
First seen:2026-08-11 11:56:55 UTC
Last seen:2026-08-11 13:40:31 UTC
File type: elf
MIME type:application/x-executable
ssdeep 49152:94JKONGJFtO3E8/q9Z/EyQJottSsAd7Mpy:9EdPsAZMw
TLSH T11DB57C077CE118AAC0AA93328DB751A27BB1FC490B7123D72E50B3782F726D46E79754
telfhash t1952362416ce71e9a19c61367bc381ad613afe04f086a75296f64c37029eb08c553fb7e
gimphash e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
TrID 50.1% (.) ELF Executable and Linkable format (Linux) (4022/12)
49.8% (.O) ELF Executable and Linkable format (generic) (4000/1)
Magika elf
Reporter abuse_ch
Tags:elf Ladvix

Intelligence


File Origin
# of uploads :
2
# of downloads :
52
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Result
Verdict:
Malware
Maliciousness:

Behaviour
Deletes a file
Removes directories
Sets a written file as executable
Launching a process
Manages services
Locks files
Receives data from a server
Sends data to a server
Connection attempt
Changes the time when the file was created, accessed, or modified
Collects information on the CPU
Creating a file in the %temp% directory
Collects information on the OS
Creating a file
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
base64 bash golang lolbin reconnaissance
Verdict:
Malicious
Uses P2P?:
false
Uses anti-vm?:
false
Architecture:
x86
Packer:
custom
Botnet:
unknown
Number of open files:
10
Number of processes launched:
6
Processes remaning?
false
Remote TCP ports scanned:
not identified
Behaviour
Persistence
Botnet C2s
TCP botnet C2(s):
not identified
UDP botnet C2(s):
not identified
Status:
terminated
Behavior Graph:
%3 guuid=17ef3c06-1d00-0000-d6fe-8960b0080000 pid=2224 /usr/bin/sudo guuid=9ca4f50a-1d00-0000-d6fe-8960b8080000 pid=2232 /tmp/sample.bin write-config guuid=17ef3c06-1d00-0000-d6fe-8960b0080000 pid=2224->guuid=9ca4f50a-1d00-0000-d6fe-8960b8080000 pid=2232 execve guuid=9ca4f50a-1d00-0000-d6fe-8960b8080000 pid=2235 /tmp/sample.bin guuid=9ca4f50a-1d00-0000-d6fe-8960b8080000 pid=2232->guuid=9ca4f50a-1d00-0000-d6fe-8960b8080000 pid=2235 clone guuid=9ca4f50a-1d00-0000-d6fe-8960b8080000 pid=2236 /tmp/sample.bin guuid=9ca4f50a-1d00-0000-d6fe-8960b8080000 pid=2232->guuid=9ca4f50a-1d00-0000-d6fe-8960b8080000 pid=2236 clone guuid=9ca4f50a-1d00-0000-d6fe-8960b8080000 pid=2237 /tmp/sample.bin guuid=9ca4f50a-1d00-0000-d6fe-8960b8080000 pid=2232->guuid=9ca4f50a-1d00-0000-d6fe-8960b8080000 pid=2237 clone guuid=9ca4f50a-1d00-0000-d6fe-8960b8080000 pid=2239 /tmp/sample.bin guuid=9ca4f50a-1d00-0000-d6fe-8960b8080000 pid=2232->guuid=9ca4f50a-1d00-0000-d6fe-8960b8080000 pid=2239 clone guuid=7b1e5613-1d00-0000-d6fe-8960c0080000 pid=2240 /tmp/sample.bin guuid=9ca4f50a-1d00-0000-d6fe-8960b8080000 pid=2232->guuid=7b1e5613-1d00-0000-d6fe-8960c0080000 pid=2240 clone guuid=61c76713-1d00-0000-d6fe-8960c1080000 pid=2241 /usr/bin/uname guuid=9ca4f50a-1d00-0000-d6fe-8960b8080000 pid=2232->guuid=61c76713-1d00-0000-d6fe-8960c1080000 pid=2241 execve guuid=cd7d0814-1d00-0000-d6fe-8960c3080000 pid=2243 /usr/bin/chmod guuid=9ca4f50a-1d00-0000-d6fe-8960b8080000 pid=2232->guuid=cd7d0814-1d00-0000-d6fe-8960c3080000 pid=2243 execve guuid=17b82450-1d00-0000-d6fe-8960f9080000 pid=2297 /usr/bin/systemctl guuid=9ca4f50a-1d00-0000-d6fe-8960b8080000 pid=2232->guuid=17b82450-1d00-0000-d6fe-8960f9080000 pid=2297 execve guuid=5e2194ca-1d00-0000-d6fe-896086090000 pid=2438 /usr/bin/systemctl guuid=9ca4f50a-1d00-0000-d6fe-8960b8080000 pid=2239->guuid=5e2194ca-1d00-0000-d6fe-896086090000 pid=2438 execve guuid=ebc5cc37-1e00-0000-d6fe-89600a0a0000 pid=2570 /usr/bin/systemctl guuid=9ca4f50a-1d00-0000-d6fe-8960b8080000 pid=2239->guuid=ebc5cc37-1e00-0000-d6fe-89600a0a0000 pid=2570 execve guuid=207c473e-1e00-0000-d6fe-8960170a0000 pid=2583 /usr/bin/pgrep guuid=9ca4f50a-1d00-0000-d6fe-8960b8080000 pid=2239->guuid=207c473e-1e00-0000-d6fe-8960170a0000 pid=2583 execve guuid=2dae7b44-1e00-0000-d6fe-8960250a0000 pid=2597 /usr/bin/bash guuid=9ca4f50a-1d00-0000-d6fe-8960b8080000 pid=2239->guuid=2dae7b44-1e00-0000-d6fe-8960250a0000 pid=2597 execve guuid=e2558b47-1e00-0000-d6fe-8960310a0000 pid=2609 /usr/bin/bash guuid=9ca4f50a-1d00-0000-d6fe-8960b8080000 pid=2239->guuid=e2558b47-1e00-0000-d6fe-8960310a0000 pid=2609 execve guuid=1ead1548-1e00-0000-d6fe-8960330a0000 pid=2611 /usr/bin/rm delete-file guuid=9ca4f50a-1d00-0000-d6fe-8960b8080000 pid=2239->guuid=1ead1548-1e00-0000-d6fe-8960330a0000 pid=2611 execve guuid=6af5114d-1e00-0000-d6fe-89603c0a0000 pid=2620 /usr/bin/bash zombie guuid=9ca4f50a-1d00-0000-d6fe-8960b8080000 pid=2239->guuid=6af5114d-1e00-0000-d6fe-89603c0a0000 pid=2620 execve guuid=b01efb16-1d00-0000-d6fe-8960c8080000 pid=2248 /usr/bin/curl net send-data write-file guuid=cd7d0814-1d00-0000-d6fe-8960c3080000 pid=2243->guuid=b01efb16-1d00-0000-d6fe-8960c8080000 pid=2248 execve a633da7e-6415-55fb-93ef-5ee209767fd5 2.57.241.243:80 guuid=b01efb16-1d00-0000-d6fe-8960c8080000 pid=2248->a633da7e-6415-55fb-93ef-5ee209767fd5 send: 82B guuid=29150d46-1e00-0000-d6fe-89602b0a0000 pid=2603 /usr/bin/rm delete-file guuid=2dae7b44-1e00-0000-d6fe-8960250a0000 pid=2597->guuid=29150d46-1e00-0000-d6fe-89602b0a0000 pid=2603 execve guuid=59a46c46-1e00-0000-d6fe-89602d0a0000 pid=2605 /usr/bin/rm delete-file guuid=2dae7b44-1e00-0000-d6fe-8960250a0000 pid=2597->guuid=59a46c46-1e00-0000-d6fe-89602d0a0000 pid=2605 execve guuid=d96bdf46-1e00-0000-d6fe-89602f0a0000 pid=2607 /usr/bin/rm guuid=2dae7b44-1e00-0000-d6fe-8960250a0000 pid=2597->guuid=d96bdf46-1e00-0000-d6fe-89602f0a0000 pid=2607 execve guuid=6839a84d-1e00-0000-d6fe-89603d0a0000 pid=2621 /usr/bin/wget net send-data write-file guuid=6af5114d-1e00-0000-d6fe-89603c0a0000 pid=2620->guuid=6839a84d-1e00-0000-d6fe-89603d0a0000 pid=2621 execve guuid=3df0d046-2100-0000-d6fe-8960f70c0000 pid=3319 /usr/bin/chmod guuid=6af5114d-1e00-0000-d6fe-89603c0a0000 pid=2620->guuid=3df0d046-2100-0000-d6fe-8960f70c0000 pid=3319 execve guuid=e20b5847-2100-0000-d6fe-8960f90c0000 pid=3321 /usr/bin/bash zombie guuid=6af5114d-1e00-0000-d6fe-89603c0a0000 pid=2620->guuid=e20b5847-2100-0000-d6fe-8960f90c0000 pid=3321 clone 0eae001c-4ad4-599c-ab6a-77d3fac12203 176.65.139.211:80 guuid=6839a84d-1e00-0000-d6fe-89603d0a0000 pid=2621->0eae001c-4ad4-599c-ab6a-77d3fac12203 send: 132B guuid=b6f27e47-2100-0000-d6fe-8960fa0c0000 pid=3322 /usr/bin/pgrep guuid=e20b5847-2100-0000-d6fe-8960f90c0000 pid=3321->guuid=b6f27e47-2100-0000-d6fe-8960fa0c0000 pid=3322 execve
Result
Threat name:
Ladvix, Xmrig
Detection:
malicious
Classification:
troj.evad.mine
Score:
100 / 100
Signature
Antivirus / Scanner detection for submitted sample
Antivirus detection for dropped file
Deletes system log files
Detected Stratum mining protocol
Drops files in suspicious directories
Executes the "crontab" command typically for achieving persistence
Executes the "iptables" command to insert, remove and/or manipulate rules
Found strings related to Crypto-Mining
Malicious sample detected (through community Yara rule)
Modifies the '.bashrc' or '.bash_profile' file typically for persisting actions
Multi AV Scanner detection for submitted file
Protects files from modification
Sample deletes itself
Sample reads /proc/mounts (often used for finding a writable filesystem)
Sample tries to persist itself using cron
Sample tries to set files in /etc globally writable
Tries to load the MSR kernel module used for reading/writing to CPUs model specific register
Writes to CPU model specific registers (MSR) (e.g. miners improve performance by disabling HW prefetcher)
Yara detected Ladvix
Yara detected Xmrig cryptocurrency miner
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1955921 Sample: boss.elf Startdate: 11/08/2026 Architecture: LINUX Score: 100 155 141.94.96.71 OVHFR France 2->155 157 2.57.241.243, 43704, 43706, 43710 TRUNKNETWORKS-ASSC Singapore 2->157 159 2 other IPs or domains 2->159 175 Malicious sample detected (through community Yara rule) 2->175 177 Antivirus detection for dropped file 2->177 179 Antivirus / Scanner detection for submitted sample 2->179 181 4 other signatures 2->181 14 systemd log 2->14         started        18 gdm3 gdm-session-worker 2->18         started        20 boss.elf 2->20         started        22 60 other processes 2->22 signatures3 process4 file5 153 /usr/log, ELF 14->153 dropped 207 Sample tries to set files in /etc globally writable 14->207 24 log sh 14->24         started        26 log sh 14->26         started        28 log sh 14->28         started        38 32 other processes 14->38 30 gdm-session-worker gdm-x-session 18->30         started        32 boss.elf bash chmod 20->32         started        34 boss.elf bash 20->34         started        40 9 other processes 20->40 36 accounts-daemon language-validate 22->36         started        signatures6 process7 process8 42 sh log 24->42         started        46 sh crontab 26->46         started        48 sh useradd 28->48         started        54 3 other processes 30->54 50 bash curl 32->50         started        56 3 other processes 34->56 52 language-validate language-options 36->52         started        58 38 other processes 38->58 60 3 other processes 40->60 file9 141 /usr/bin/foo2hp, ELF 42->141 dropped 143 /tmp/filesmxjim, ELF 42->143 dropped 189 Sample tries to set files in /etc globally writable 42->189 191 Drops files in suspicious directories 42->191 193 Sample tries to persist itself using cron 42->193 145 /var/spool/cron/crontabs/tmp.BigFJG, ASCII 46->145 dropped 195 Executes the "crontab" command typically for achieving persistence 46->195 147 /home/systemd/.bashrc, ASCII 48->147 dropped 197 Modifies the '.bashrc' or '.bash_profile' file typically for persisting actions 48->197 75 8 other processes 48->75 149 /usr/bin/log, ELF 50->149 dropped 62 language-options sh 52->62         started        64 dbus-run-session gnome-session gnome-session-binary 54->64         started        66 dbus-run-session dbus-daemon 54->66         started        77 2 other processes 54->77 199 Deletes system log files 56->199 201 Found strings related to Crypto-Mining 58->201 203 Protects files from modification 58->203 205 Sample deletes itself 58->205 69 log 58->69         started        71 log iptables 58->71         started        79 9 other processes 58->79 151 /var/tmp/cli, ELF 60->151 dropped 73 bash pgrep 60->73         started        signatures10 process11 signatures12 93 2 other processes 62->93 81 gnome-session-binary session-migration 64->81         started        95 16 other processes 64->95 161 Sample reads /proc/mounts (often used for finding a writable filesystem) 66->161 85 dbus-daemon 66->85         started        87 dbus-daemon 66->87         started        97 9 other processes 66->97 163 Writes to CPU model specific registers (MSR) (e.g. miners improve performance by disabling HW prefetcher) 69->163 89 log sh 69->89         started        165 Executes the "iptables" command to insert, remove and/or manipulate rules 71->165 99 2 other processes 77->99 91 ip6tables modprobe 79->91         started        process13 file14 137 /tmp/filesynSkl, ELF 81->137 dropped 139 /etc/cron.hourly/0, POSIX 81->139 dropped 167 Sample tries to set files in /etc globally writable 81->167 169 Sample deletes itself 81->169 171 Sample tries to persist itself using cron 81->171 101 session-migration filesynSkl 81->101         started        103 dbus-daemon at-spi-bus-launcher 85->103         started        105 dbus-daemon gjs 87->105         started        108 sh modprobe 89->108         started        173 Sample reads /proc/mounts (often used for finding a writable filesystem) 95->173 110 gnome-shell ibus-daemon 95->110         started        112 gsd-print-notifications 95->112         started        114 gnome-session-check-accelerated gnome-session-check-accelerated-gl-helper 95->114         started        116 gnome-session-check-accelerated gnome-session-check-accelerated-gles-helper 95->116         started        118 9 other processes 97->118 signatures15 process16 signatures17 120 at-spi-bus-launcher dbus-daemon 103->120         started        185 Sample reads /proc/mounts (often used for finding a writable filesystem) 105->185 187 Tries to load the MSR kernel module used for reading/writing to CPUs model specific register 108->187 123 ibus-daemon 110->123         started        125 ibus-daemon ibus-memconf 110->125         started        127 ibus-daemon ibus-engine-simple 110->127         started        129 gsd-print-notifications gsd-printer 112->129         started        process18 signatures19 183 Sample reads /proc/mounts (often used for finding a writable filesystem) 120->183 131 dbus-daemon 120->131         started        133 ibus-daemon ibus-x11 123->133         started        process20 process21 135 dbus-daemon at-spi2-registryd 131->135         started       
Gathering data
Result
Malware family:
Score:
  10/10
Tags:
family:ladvix defense_evasion discovery execution infector linux persistence privilege_escalation trojan
Behaviour
Enumerates kernel/hardware configuration
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Reads CPU attributes
Creates/modifies Cron job
Deletes log files
Enumerates running processes
Modifies systemd
Write file to user bin folder
File and Directory Permissions Modification
Family: Ladvix
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:DetectGoMethodSignatures
Author:Wyatt Tauber
Description:Detects Go method signatures in unpacked Go binaries
Rule name:Detect_Go_GOMAXPROCS
Author:Obscurity Labs LLC
Description:Detects Go binaries by the presence of runtime.GOMAXPROCS in the runtime metadata
Rule name:F01_s1ckrule
Author:s1ckb017
Rule name:GoBinTest
Rule name:golang
Rule name:golang_binary_string
Description:Golang strings present
Rule name:golang_duffcopy_amd64
Rule name:Golang_Find_CSC846
Author:Ashar Siddiqui
Description:Find Go Signatuers
Rule name:Golang_Find_CSC846_Simple
Author:Ashar Siddiqui
Description:Find Go Signatuers
Rule name:identity_golang
Author:Eric Yocam
Description:find Golang malware
Rule name:ProgramLanguage_Golang
Author:albertzsigovits
Description:Application written in Golang programming language
Rule name:Suspicious_Golang_Binary
Author:Tim Machac
Description:Triage: Golang-compiled binary with suspicious OS/persistence/network strings (not family-specific)
Rule name:TH_Generic_MassHunt_Linux_Malware_2026_CYFARE
Author:CYFARE
Description:Generic Linux malware mass-hunt rule - 2026
Reference:https://cyfare.net/
Rule name:unixredflags3
Author:Tim Brown @timb_machine
Description:Hunts for UNIX red flags

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Ladvix

elf b5aef7ade103fd04b5b7e91bfcbba029565488b39d931d979a8c685595bc7009

(this sample)

Comments