MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c0bb0b628b7de6bb9d047aeb608ec7a9a7cbf988b22df5f461c11f106249c57c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA 7 File information Comments

SHA256 hash: c0bb0b628b7de6bb9d047aeb608ec7a9a7cbf988b22df5f461c11f106249c57c
SHA3-384 hash: 803a6ef45e7a8da9fdaaa4e31eae079987d11a9f6eb1c8c6ddafe9b3dcedf512564672d6051f45d730a3a01b8a06096f
SHA1 hash: 6dc83b5cfc6efaae0aba1271526756c540e80de1
MD5 hash: 3cd5d09192bf0d0142c9f36da440fc3e
humanhash: river-mexico-march-eleven
File name:bot
Download: download sample
File size:2'740'944 bytes
First seen:2026-06-08 17:27:04 UTC
Last seen:2026-06-08 19:32:30 UTC
File type: elf
MIME type:application/x-sharedlib
ssdeep 49152:gfLW37fYZBs/lcFm5NNUgn1A5JUMt6oE5/p7SEi3+/xQaSk25s3nvL:gjcbYn8lcUvmMy5qUVkf3xQa52+3z
TLSH T127C51227B66224BCE55BC474479EC1B2AA39B06902257B3B7BD496303F39C718F1DB12
TrID 50.1% (.) ELF Executable and Linkable format (Linux) (4022/12)
49.8% (.O) ELF Executable and Linkable format (generic) (4000/1)
Magika elf
Reporter BlinkzSec

Intelligence


File Origin
# of uploads :
2
# of downloads :
30
Origin country :
GB GB
Vendor Threat Intelligence
Result
Verdict:
Clean
Maliciousness:
Status:
terminated
Behavior Graph:
%3 guuid=368ef037-1c00-0000-693b-84a53d0d0000 pid=3389 /usr/bin/sudo guuid=ea9df239-1c00-0000-693b-84a5420d0000 pid=3394 /tmp/sample.bin guuid=368ef037-1c00-0000-693b-84a53d0d0000 pid=3389->guuid=ea9df239-1c00-0000-693b-84a5420d0000 pid=3394 execve
Threat name:
Linux.Trojan.Generic
Status:
Suspicious
First seen:
2026-05-04 02:21:28 UTC
File Type:
ELF64 Little (SO)
AV detection:
17 of 36 (47.22%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  5/10
Tags:
linux upx
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:enterpriseapps2
Author:Tim Brown @timb_machine
Description:Enterprise apps
Rule name:enterpriseunix2
Author:Tim Brown @timb_machine
Description:Enterprise UNIX
Rule name:ProgramLanguage_Rust
Author:albertzsigovits
Description:Application written in Rust programming language
Rule name:Rustyloader_mem_loose
Author:James_inthe_box
Description:Corroded buerloader
Reference:https://app.any.run/tasks/83064edd-c7eb-4558-85e8-621db72b2a24
Rule name:unixredflags3
Author:Tim Brown @timb_machine
Description:Hunts for UNIX red flags
Rule name:upx_packed_elf_v1
Author:RandomMalware
Rule name:win_rust_hunt

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

elf c0bb0b628b7de6bb9d047aeb608ec7a9a7cbf988b22df5f461c11f106249c57c

(this sample)

  
Delivery method
Distributed via web download

Comments