MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 cabee0beea41e1b65b4a1fed0f26dd514b4f5518646d241e760bf2b9bb7d9c17. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 4


Intelligence 4 IOCs YARA 2 File information Comments

SHA256 hash: cabee0beea41e1b65b4a1fed0f26dd514b4f5518646d241e760bf2b9bb7d9c17
SHA3-384 hash: 7eabcf31fdef24d57e40c586e644085b46368906a5a520441a487533b138a8c420ba6203fedfb87bc511aa7a4e927733
SHA1 hash: 037faee6909a6768bd48d629140f25734864e27d
MD5 hash: 8f4cd550d2b5e7e91d3f48714084de36
humanhash: summer-fish-lion-lithium
File name:main.x86-core2
Download: download sample
File size:70'440 bytes
First seen:2026-08-11 03:23:58 UTC
Last seen:2026-08-11 16:14:41 UTC
File type: elf
MIME type:application/x-executable
ssdeep 1536:3ILwrsTcgNYNGQ5jHlRJDJmKyWl4JvhCxUrj:3ILR3NYNHpkK1KJJj
TLSH T14B633A81E653C0B0E19341B0099BFBE64530DF32945BEAE6EB9D7D61FC307828D9662D
telfhash t1db3105f76c6558ecb3d04442c39b66e38e7ae0176aa10e3a00b079903bf99639172c39
TrID 50.1% (.) ELF Executable and Linkable format (Linux) (4022/12)
49.8% (.O) ELF Executable and Linkable format (generic) (4000/1)
Magika elf
Reporter abuse_ch
Tags:elf

Intelligence


File Origin
# of uploads :
2
# of downloads :
59
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Result
Verdict:
Suspicious
Maliciousness:

Behaviour
Creating a file
Creating a file in the %temp% directory
Runs as daemon
Launching a process
Connection attempt
Verdict:
Unknown
Threat level:
  0/10
Confidence:
100%
Tags:
gcc rust
Status:
terminated
Behavior Graph:
%3 guuid=31ecb046-1a00-0000-49bd-c6e1060c0000 pid=3078 /usr/bin/sudo guuid=1b731349-1a00-0000-49bd-c6e10b0c0000 pid=3083 /tmp/sample.bin guuid=31ecb046-1a00-0000-49bd-c6e1060c0000 pid=3078->guuid=1b731349-1a00-0000-49bd-c6e10b0c0000 pid=3083 execve guuid=d5717e49-1a00-0000-49bd-c6e10c0c0000 pid=3084 /tmp/sample.bin guuid=1b731349-1a00-0000-49bd-c6e10b0c0000 pid=3083->guuid=d5717e49-1a00-0000-49bd-c6e10c0c0000 pid=3084 clone guuid=69d69e49-1a00-0000-49bd-c6e10d0c0000 pid=3085 /tmp/sample.bin net send-data zombie guuid=d5717e49-1a00-0000-49bd-c6e10c0c0000 pid=3084->guuid=69d69e49-1a00-0000-49bd-c6e10d0c0000 pid=3085 clone 879313db-9102-5ffc-8443-1eefa773f834 94.154.43.12:32 guuid=69d69e49-1a00-0000-49bd-c6e10d0c0000 pid=3085->879313db-9102-5ffc-8443-1eefa773f834 send: 78B guuid=6785ba49-1a00-0000-49bd-c6e10e0c0000 pid=3086 /tmp/sample.bin guuid=69d69e49-1a00-0000-49bd-c6e10d0c0000 pid=3085->guuid=6785ba49-1a00-0000-49bd-c6e10e0c0000 pid=3086 clone guuid=8643de49-1a00-0000-49bd-c6e10f0c0000 pid=3087 /usr/bin/bash guuid=69d69e49-1a00-0000-49bd-c6e10d0c0000 pid=3085->guuid=8643de49-1a00-0000-49bd-c6e10f0c0000 pid=3087 execve
Result
Threat name:
n/a
Detection:
clean
Classification:
n/a
Score:
3 / 100
Behaviour
Behavior Graph:
n/a
Gathering data
Result
Malware family:
n/a
Score:
  3/10
Tags:
discovery linux
Behaviour
System Network Configuration Discovery
Writes file to tmp directory
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:TH_Generic_MassHunt_Linux_Malware_2026_CYFARE
Author:CYFARE
Description:Generic Linux malware mass-hunt rule - 2026
Reference:https://cyfare.net/
Rule name:unixredflags3
Author:Tim Brown @timb_machine
Description:Hunts for UNIX red flags

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

elf cabee0beea41e1b65b4a1fed0f26dd514b4f5518646d241e760bf2b9bb7d9c17

(this sample)

  
Delivery method
Distributed via web download

Comments