MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 bce8ba5b7e6598c15c5ec258199e148272087fde2cd0690ed9b42ba89f2aacea. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: bce8ba5b7e6598c15c5ec258199e148272087fde2cd0690ed9b42ba89f2aacea
SHA3-384 hash: 3faddda2c78504719676ef199cd17fe3a1d2d3ad3eef6c5aeb285075f08d33e379737ac071fd2a3d23484d398af96d15
SHA1 hash: 15ce50ceb31609009a8755a2d85488db447430be
MD5 hash: cf6de79e40b91e44b62770f17c3f8b80
humanhash: winter-michigan-equal-butter
File name:cf6de79e40b91e44b62770f17c3f8b80
Download: download sample
File size:4'680'960 bytes
First seen:2021-03-25 15:31:40 UTC
Last seen:Never
File type: elf
MIME type:application/x-executable
ssdeep 49152:T8FWH8y/gahO9FcIXKtqEJnerv41WHrFq44gP1T1WPmoFjPnMB:ooHdgaMX1JLFv1opfM
TLSH 2226F713F9D608DBD5BFE13087A66322BE7134AA433177D36F914A561A2AFE4693D300
Reporter Arkbird_SOLG
Tags:APT29 elf wellmess


Avatar
ArkbirdDevil
Thanks to @c3rb3ru5d3d53c for the sample

Intelligence


File Origin
# of uploads :
1
# of downloads :
211
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
MALICIOUS
Threat name:
Linux.Trojan.WellMess
Status:
Malicious
First seen:
2021-03-25 15:32:08 UTC
AV detection:
12 of 29 (41.38%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  5/10
Tags:
linux
Behaviour
Reads runtime system information
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments