MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c38c21120d8c17688f9aeb2af5bdafb6b75e1d2673b025b720e50232f888808a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Kinsing


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments 1

SHA256 hash: c38c21120d8c17688f9aeb2af5bdafb6b75e1d2673b025b720e50232f888808a
SHA3-384 hash: 68534225f1bf56c81b273d714ef0c5efd98fe5e32c4538d4cd8f33660c353e8fc8a3f2bfa50e5eaaf41b8c8e3580c553
SHA1 hash: 38c56b5e1489092b80c9908f04379e5a16876f01
MD5 hash: ccef46c7edf9131ccffc47bd69eb743b
humanhash: mango-maryland-march-mobile
File name:libsystem.so
Download: download sample
Signature Kinsing
File size:26'800 bytes
First seen:2020-10-20 18:02:43 UTC
Last seen:2021-12-11 12:07:56 UTC
File type: elf
MIME type:application/x-sharedlib
ssdeep 384:GkV8prsuhCY63B9dBRi9JsdgUa/Q1NXJZ6Cb1b:ZaLOVT6E
TLSH 9EC2C637B9D2CAB5C0C0E238A5D79276F1F5B0F14B22931BA294457E3E927C81F4EA45
telfhash 26d09507db4d1d0d6aa5e912ec7b53396485001357b1c771cf5874c00f0d11d7a00c8f
Reporter r3dbU7z
Tags:elf Kinsing log4j rootkit

Intelligence


File Origin
# of uploads :
3
# of downloads :
262
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Linux.Hacktool.ProcHider
Status:
Malicious
First seen:
2020-08-12 02:54:12 UTC
AV detection:
9 of 29 (31.03%)
Threat level:
  1/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

2101671ce97b2d61b18f20da8021bc11b70969d24ab0c325eae3ab9f3c2381dd

Kinsing

elf c38c21120d8c17688f9aeb2af5bdafb6b75e1d2673b025b720e50232f888808a

(this sample)

Comments



Avatar
commented on 2020-11-28 00:30:10 UTC

Reference: "Analysis of Kinsing Malware's Use of Rootkit"

https://www.trendmicro.com/en_us/research/20/k/analysis-of-kinsing-malwares-use-of-rootkit.html