MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b9abb0d816c3120183107ddfee09b6ffc36485655448cdb724b74a9b1314dfdd. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 9


Intelligence 9 IOCs YARA 3 File information Comments

SHA256 hash: b9abb0d816c3120183107ddfee09b6ffc36485655448cdb724b74a9b1314dfdd
SHA3-384 hash: 8249edb54314451f11d1f95bd654f2388888a3c14d4a3b1ee73f1a3fe127674ad86a5b45054f2b41790ae54a2590880c
SHA1 hash: 45eaddcf16dba097f5874b748429b4809774ad6a
MD5 hash: 3b80b6d860eac37244840fe1a8b50826
humanhash: romeo-november-carolina-five
File name:i686
Download: download sample
File size:587'764 bytes
First seen:2025-06-21 04:48:25 UTC
Last seen:2025-06-21 19:39:42 UTC
File type: elf
MIME type:application/x-executable
ssdeep 12288:5D+Azf/CVCW3ISw+hRNb3W/aTyA9VV/cZWLnR98V+:5D+AznCVNIZ+vNbG/WYWrR98V
TLSH T134C42241EAB7C1F2F65349320103E7BF8F33C9099165D2A2D742F661EDB1B424A9E66C
TrID 50.1% (.) ELF Executable and Linkable format (Linux) (4022/12)
49.8% (.O) ELF Executable and Linkable format (generic) (4000/1)
Magika elf
Reporter abuse_ch
Tags:elf

Intelligence


File Origin
# of uploads :
3
# of downloads :
67
Origin country :
DE DE
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Launching a process
Creates directories
Creating a process from a recently created file
Changes the time when the file was created, accessed, or modified
Creating a file in the %temp% directory
Creating a file
Connection attempt
Locks files
Opens a port
Changes access rights for a written file
Collects information on the CPU
Receives data from a server
Sends data to a server
DNS request
Runs as daemon
Creates or modifies files in /cron to set up autorun
Verdict:
Unknown
Threat level:
  2.5/10
Confidence:
100%
Tags:
base64 exploit gcc lolbin remote
Verdict:
Malicious
Uses P2P?:
true
Uses anti-vm?:
true
Architecture:
x86
Packer:
custom
Botnet:
unknown
Number of open files:
72
Number of processes launched:
10
Processes remaning?
false
Remote TCP ports scanned:
50651
Behaviour
Anti-VM
Botnet C2s
TCP botnet C2(s):
not identified
UDP botnet C2(s):
type: 162.159.200.123:123
type: 130.239.18.158:6881
type: 67.215.246.10:6881
type: 91.225.20.2:6881
type: 192.145.1.202:6881
type: 178.69.209.93:6881
type: 93.176.180.96:6881
type: 176.125.139.123:6881
type: 89.207.71.47:6881
type: 188.42.55.92:6881
type: 85.154.13.73:6881
type: 172.218.233.78:6881
type: 82.64.102.72:6881
type: 82.71.90.130:6881
type: 89.135.206.214:6881
type: 80.220.218.186:6881
type: 46.147.175.105:6881
type: 115.187.44.131:6881
type: 90.250.137.76:6881
type: 18.190.61.127:6881
type: 82.100.245.98:6881
type: 72.14.148.48:6881
type: 141.98.154.145:6881
type: 167.99.72.189:6881
type: 75.119.138.164:6881
type: 69.180.6.249:6881
type: 188.165.230.194:6881
type: 58.177.125.207:6881
type: 176.59.192.177:6881
type: 54.70.28.180:6881
type: 54.214.62.55:6881
type: 93.49.250.183:6881
type: 91.49.171.105:6881
type: 86.69.252.196:6881
type: 18.223.137.220:6881
type: 54.214.105.212:6881
type: 62.33.210.114:6881
type: 118.31.116.208:6881
type: 117.202.169.178:6881
type: 193.253.106.84:6881
type: 189.32.122.17:6881
type: 89.168.99.211:6881
type: 81.234.50.136:6881
type: 189.217.106.18:6881
type: 73.209.184.72:6881
type: 130.239.18.158:8516
type: 142.132.203.125:50000
type: 95.216.14.159:50000
type: 144.76.167.48:50000
type: 37.27.119.184:50000
type: 65.21.33.208:50000
type: 65.21.125.170:50000
type: 142.132.207.124:50000
type: 65.108.194.42:50000
type: 148.251.120.40:50000
type: 162.55.82.246:50000
type: 144.76.166.157:50000
type: 142.132.197.32:50000
type: 37.27.103.245:50000
type: 65.21.34.43:50000
type: 135.181.227.244:50000
type: 144.76.182.235:50000
type: 135.181.238.57:50000
type: 135.181.238.116:50000
type: 142.132.207.126:50000
type: 95.216.0.253:50000
type: 37.27.103.248:50000
type: 116.202.166.145:50000
type: 142.132.200.42:50000
type: 162.55.81.226:50000
type: 95.216.14.254:50000
type: 148.251.123.99:50000
type: 135.181.223.148:50000
type: 37.27.117.249:50000
type: 95.216.3.151:50000
type: 162.55.86.187:50000
type: 95.217.114.221:50000
type: 142.132.206.187:50000
type: 162.55.85.94:50000
type: 188.40.39.55:50000
type: 148.251.49.174:50000
type: 144.76.164.145:50000
type: 142.132.203.124:50000
type: 37.27.120.48:50000
type: 65.21.125.180:50000
type: 37.27.107.60:50000
type: 37.27.119.123:50000
type: 65.21.128.229:50000
type: 95.217.196.239:50000
type: 65.109.25.152:50000
type: 95.216.13.87:50000
type: 135.181.227.251:50000
type: 195.154.233.74:6880
type: 18.119.148.203:6880
type: 18.117.46.179:6880
type: 52.21.231.83:6880
type: 173.230.130.111:6880
type: 54.144.88.168:6880
type: 185.196.61.129:6880
type: 18.188.239.31:6880
type: 154.202.133.136:6880
type: 3.130.60.88:6880
type: 45.203.206.54:6880
type: 52.201.45.189:6880
type: 45.203.211.20:6880
type: 130.239.18.158:8580
type: 130.239.18.158:8513
type: 178.128.114.125:51413
type: 147.135.115.191:51413
type: 104.244.73.2:51413
type: 37.187.1.102:51413
type: 185.107.44.197:51413
type: 119.83.98.79:51413
type: 45.38.17.243:51413
type: 87.106.120.127:51413
type: 193.239.124.133:51413
type: 198.100.145.51:51413
type: 65.108.100.183:51413
type: 147.30.235.216:51413
type: 94.228.198.197:51413
type: 212.7.202.40:28030
type: 178.162.174.222:28014
type: 178.162.174.106:28014
type: 178.162.173.104:28014
type: 178.79.189.177:55460
type: 82.172.167.161:6889
type: 193.80.1.17:6889
type: 99.151.15.244:6889
type: 90.248.171.21:6889
type: 185.142.208.105:6889
type: 31.210.173.50:27520
type: 84.247.173.42:8081
type: 67.220.85.41:11875
type: 211.33.151.186:7942
type: 5.135.156.163:56843
type: 51.210.179.31:49048
type: 130.239.18.158:8554
type: 178.162.173.102:28005
type: 178.162.173.228:28005
type: 85.17.31.172:28005
type: 178.162.174.238:28005
type: 178.162.174.5:28005
type: 178.162.174.234:28000
type: 178.162.174.230:28000
type: 178.162.144.51:21183
type: 130.239.18.158:8510
type: 178.162.174.170:28001
type: 178.162.173.231:28001
type: 178.162.174.81:28001
type: 178.162.174.43:28004
type: 81.171.6.41:28004
type: 130.239.18.158:8524
type: 130.239.18.158:8515
type: 185.149.91.21:51118
type: 130.239.18.158:8520
type: 95.168.162.161:42670
type: 178.162.174.178:28003
type: 178.162.173.91:28003
type: 130.239.18.158:8539
type: 112.91.94.70:6882
type: 116.251.192.15:6882
type: 178.162.173.222:28002
type: 92.34.55.248:16108
type: 178.162.173.15:28006
type: 178.162.173.156:28006
type: 178.162.174.101:28007
type: 178.162.173.205:28015
type: 178.162.174.101:28015
type: 185.203.56.49:17129
type: 89.149.202.3:28028
type: 89.149.202.3:28072
type: 89.149.202.17:28036
type: 65.21.118.113:16401
type: 27.93.18.132:26893
type: 38.49.85.98:55863
type: 185.107.45.9:7246
type: 61.84.74.112:33097
type: 61.120.224.248:26113
type: 193.32.23.252:64274
type: 185.149.91.167:51082
type: 178.162.173.145:28016
type: 57.129.45.79:8665
type: 172.103.162.171:28277
type: 169.150.223.227:64115
type: 112.160.178.245:32965
type: 115.22.139.242:8043
type: 122.117.11.180:55555
type: 185.203.56.71:32621
type: 185.255.236.42:27538
type: 51.159.104.85:8410
type: 103.140.3.3:64403
type: 211.248.109.192:7798
type: 192.154.97.194:58356
type: 23.233.105.233:22234
type: 82.159.1.216:29061
type: 89.117.1.188:54072
type: 185.107.71.98:20613
type: 62.210.201.217:8673
type: 185.107.71.99:38759
type: 192.98.121.164:60807
type: 211.34.62.131:33087
type: 177.81.218.237:37321
type: 173.206.124.50:60102
type: 191.241.200.110:35368
type: 24.177.216.147:48451
type: 162.157.59.71:56995
type: 45.128.27.245:62299
type: 182.70.36.57:17017
type: 185.70.17.8:32000
type: 178.54.179.100:41963
type: 82.10.30.151:10029
type: 218.155.95.247:8999
type: 62.133.62.109:55128
type: 176.9.138.253:56881
type: 87.27.183.185:64668
type: 193.32.2.1:37809
type: 76.94.28.165:33458
type: 98.96.174.51:52818
type: 91.181.195.157:27199
type: 94.31.70.95:5233
type: 180.147.58.64:58963
type: 93.123.127.143:27076
type: 188.163.50.204:19526
type: 176.31.182.150:58415
type: 65.108.143.34:44441
type: 45.183.90.221:49947
type: 149.22.89.94:57308
type: 172.124.208.204:34712
type: 97.118.151.218:15423
type: 112.146.243.181:36321
type: 223.184.233.43:30069
type: 188.165.231.168:57673
type: 46.232.210.231:64072
type: 46.232.210.231:64144
type: 94.248.146.231:5173
type: 54.39.52.64:32205
type: 23.95.11.50:65524
type: 176.31.183.98:18102
type: 162.55.243.114:1910
type: 194.29.101.83:10240
type: 152.53.104.128:10240
type: 195.170.172.38:10240
type: 175.208.164.32:36235
type: 128.0.104.15:8666
type: 68.186.19.81:51259
type: 173.181.34.212:58756
type: 92.37.78.5:44794
type: 106.163.73.85:22297
type: 188.79.165.224:23123
type: 168.121.202.228:44754
type: 37.27.113.233:40139
type: 181.132.177.134:54989
type: 190.108.79.147:25089
type: 49.206.35.155:34896
type: 46.235.121.63:25806
type: 70.29.166.47:49001
type: 46.232.210.231:64155
type: 89.134.27.189:44207
type: 178.162.174.104:28012
type: 178.162.174.6:28012
type: 71.215.214.45:17191
type: 41.107.224.38:44166
type: 216.39.249.244:60632
type: 46.4.250.108:53753
type: 45.87.251.6:28049
type: 89.149.202.3:28080
type: 67.183.120.119:55240
type: 115.77.251.150:65321
type: 178.162.174.26:28013
type: 178.162.174.6:28011
type: 188.163.14.239:34849
type: 115.124.180.75:25298
type: 138.19.5.28:9862
type: 218.102.114.48:26567
type: 27.123.138.63:7007
type: 46.232.210.223:64048
type: 65.48.243.71:50321
type: 115.164.202.113:32929
type: 115.124.178.122:42587
type: 38.39.164.78:52981
type: 121.129.133.68:7673
type: 62.102.148.169:40833
type: 174.83.112.128:6895
type: 38.25.53.168:46717
type: 68.192.59.26:37345
type: 192.42.116.243:45497
Status:
terminated
Behavior Graph:
%3 guuid=4820f5c5-1900-0000-092e-08797c0c0000 pid=3196 /usr/bin/sudo guuid=ff5dedc7-1900-0000-092e-08797e0c0000 pid=3198 /root/.sys/configuration guuid=4820f5c5-1900-0000-092e-08797c0c0000 pid=3196->guuid=ff5dedc7-1900-0000-092e-08797e0c0000 pid=3198 execve guuid=4db41ec8-1900-0000-092e-08797f0c0000 pid=3199 /usr/bin/dash guuid=ff5dedc7-1900-0000-092e-08797e0c0000 pid=3198->guuid=4db41ec8-1900-0000-092e-08797f0c0000 pid=3199 execve guuid=070cd3c8-1900-0000-092e-0879810c0000 pid=3201 /usr/bin/dash guuid=ff5dedc7-1900-0000-092e-08797e0c0000 pid=3198->guuid=070cd3c8-1900-0000-092e-0879810c0000 pid=3201 execve guuid=cae557c9-1900-0000-092e-0879840c0000 pid=3204 /root/.sys/configuration zombie guuid=ff5dedc7-1900-0000-092e-08797e0c0000 pid=3198->guuid=cae557c9-1900-0000-092e-0879840c0000 pid=3204 clone guuid=65251cc9-1900-0000-092e-0879820c0000 pid=3202 /usr/bin/dash guuid=070cd3c8-1900-0000-092e-0879810c0000 pid=3201->guuid=65251cc9-1900-0000-092e-0879820c0000 pid=3202 clone guuid=22e721c9-1900-0000-092e-0879830c0000 pid=3203 /usr/bin/dash guuid=070cd3c8-1900-0000-092e-0879810c0000 pid=3201->guuid=22e721c9-1900-0000-092e-0879830c0000 pid=3203 clone guuid=9afe28d0-1900-0000-092e-08798f0c0000 pid=3215 /root/.sys/configuration guuid=cae557c9-1900-0000-092e-0879840c0000 pid=3204->guuid=9afe28d0-1900-0000-092e-08798f0c0000 pid=3215 clone guuid=9d223fd0-1900-0000-092e-0879900c0000 pid=3216 /root/.sys/configuration guuid=9afe28d0-1900-0000-092e-08798f0c0000 pid=3215->guuid=9d223fd0-1900-0000-092e-0879900c0000 pid=3216 clone guuid=96f552d0-1900-0000-092e-0879910c0000 pid=3217 /root/.sys/configuration dns net net-scan send-data guuid=9d223fd0-1900-0000-092e-0879900c0000 pid=3216->guuid=96f552d0-1900-0000-092e-0879910c0000 pid=3217 clone d316b2ae-0a7e-5b43-8de6-745900c90c54 127.0.0.1:65535 guuid=96f552d0-1900-0000-092e-0879910c0000 pid=3217->d316b2ae-0a7e-5b43-8de6-745900c90c54 con 38a4910e-6f05-5afe-a8e3-398c2eb18329 time.cloudflare.com:123 guuid=96f552d0-1900-0000-092e-0879910c0000 pid=3217->38a4910e-6f05-5afe-a8e3-398c2eb18329 send: 48B b6df9c3f-8ac4-5431-bcf0-187403ce8b20 31.200.249.178:31803 guuid=96f552d0-1900-0000-092e-0879910c0000 pid=3217->b6df9c3f-8ac4-5431-bcf0-187403ce8b20 send: 68B 8cdccce7-667a-5ba4-89d7-97e2a201f111 149.88.26.220:46050 guuid=96f552d0-1900-0000-092e-0879910c0000 pid=3217->8cdccce7-667a-5ba4-89d7-97e2a201f111 send: 68B guuid=96f552d0-1900-0000-092e-0879910c0000 pid=3217|send-data send-data to 287 IP addresses review logs to see them all guuid=96f552d0-1900-0000-092e-0879910c0000 pid=3217->guuid=96f552d0-1900-0000-092e-0879910c0000 pid=3217|send-data send
Result
Threat name:
n/a
Detection:
malicious
Classification:
troj.spyw
Score:
64 / 100
Signature
Executes the "crontab" command typically for achieving persistence
Multi AV Scanner detection for submitted file
Opens /sys/class/net/* files useful for querying network interface information
Sample reads /proc/mounts (often used for finding a writable filesystem)
Sample tries to persist itself using cron
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1719775 Sample: i686.elf Startdate: 21/06/2025 Architecture: LINUX Score: 64 38 46.232.210.29, 63353, 6881 V4ESCROW-ASRO Romania 2->38 40 46.232.211.239, 64084, 6881 V4ESCROW-ASRO Romania 2->40 42 102 other IPs or domains 2->42 44 Multi AV Scanner detection for submitted file 2->44 10 i686.elf configuration 2->10         started        signatures3 process4 process5 12 i686.elf sh 10->12         started        14 configuration 10->14         started        17 i686.elf sh 10->17         started        signatures6 19 sh crontab 12->19         started        23 sh 12->23         started        52 Opens /sys/class/net/* files useful for querying network interface information 14->52 54 Sample reads /proc/mounts (often used for finding a writable filesystem) 14->54 25 configuration 14->25         started        27 sh crontab 17->27         started        process7 file8 36 /var/spool/cron/crontabs/tmp.9A8kGB, ASCII 19->36 dropped 46 Sample tries to persist itself using cron 19->46 48 Executes the "crontab" command typically for achieving persistence 19->48 29 sh crontab 23->29         started        32 configuration 25->32         started        signatures9 process10 signatures11 50 Executes the "crontab" command typically for achieving persistence 29->50 34 configuration 32->34         started        process12
Threat name:
Linux.Trojan.Multiverze
Status:
Malicious
First seen:
2025-06-21 04:49:33 UTC
File Type:
ELF32 Little (Exe)
AV detection:
14 of 24 (58.33%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
antivm defense_evasion discovery execution linux persistence privilege_escalation
Behaviour
Enumerates kernel/hardware configuration
Reads runtime system information
Writes file to tmp directory
Checks CPU configuration
Checks hardware identifiers (DMI)
Creates/modifies Cron job
Enumerates running processes
Reads MAC address of network interface
Reads hardware information
Renames itself
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:linux_generic_ipv6_catcher
Author:@_lubiedo
Description:ELF samples using IPv6 addresses
Rule name:Sus_Obf_Enc_Spoof_Hide_PE
Author:XiAnzheng
Description:Check for Overlay, Obfuscating, Encrypting, Spoofing, Hiding, or Entropy Technique(can create FP)
Rule name:unixredflags3
Author:Tim Brown @timb_machine
Description:Hunts for UNIX red flags

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

elf b9abb0d816c3120183107ddfee09b6ffc36485655448cdb724b74a9b1314dfdd

(this sample)

  
Delivery method
Distributed via web download

Comments