MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 cbe31dfe86ab712e2ad7bac0d2414087e43f246f4f5f97211e2fd587d7624760. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: cbe31dfe86ab712e2ad7bac0d2414087e43f246f4f5f97211e2fd587d7624760
SHA3-384 hash: 15cd8ca1572cab0ae826c3e99e0e0ae32328f2cd2eb800a74e16cdf6b863df9921bd6a3b287013ea67216c2ab2f47ac2
SHA1 hash: 179407fa8550bbdbe36fa9fd7a4d608c5e5ba9ef
MD5 hash: 488d98722346f8cd8191be0611f0b12f
humanhash: river-stairway-early-washington
File name:linux
Download: download sample
File size:1'385'736 bytes
First seen:2025-12-09 17:58:57 UTC
Last seen:Never
File type: elf
MIME type:application/x-executable
ssdeep 24576:dLk4PTA0WTtByWS7tCNcU478vK/1E9FvbeZ/qEvcU2FUKE8CNI4RxEnwZy661/3l:dLk4TA7RByWSV4C/sqEU2Yq4fEmy6K/V
TLSH T1745533D750AF51B7FFB791501E0F0527AA8BE9241FD05AB86850C2903AF4B1213E97BB
TrID 50.1% (.) ELF Executable and Linkable format (Linux) (4022/12)
49.8% (.O) ELF Executable and Linkable format (generic) (4000/1)
Magika elf
Reporter abuse_ch
Tags:elf

Intelligence


File Origin
# of uploads :
1
# of downloads :
34
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Result
Verdict:
Clean
Maliciousness:
Verdict:
Unknown
File Type:
elf.64.le
First seen:
2025-12-09T18:55:00Z UTC
Last seen:
2025-12-09T21:23:00Z UTC
Hits:
~10
Result
Threat name:
n/a
Detection:
malicious
Classification:
n/a
Score:
48 / 100
Signature
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1829763 Sample: linux.elf Startdate: 09/12/2025 Architecture: LINUX Score: 48 14 54.171.230.55, 443 AMAZON-02US United States 2->14 16 54.247.62.1, 43390, 443 AMAZON-02US United States 2->16 18 Multi AV Scanner detection for submitted file 2->18 6 dash rm 2->6         started        8 dash cat 2->8         started        10 dash cut 2->10         started        12 8 other processes 2->12 signatures3 process4
Threat name:
Linux.Trojan.Multiverze
Status:
Malicious
First seen:
2025-12-09 17:59:14 UTC
File Type:
ELF64 Little (Exe)
AV detection:
7 of 24 (29.17%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  5/10
Tags:
linux upx
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

elf cbe31dfe86ab712e2ad7bac0d2414087e43f246f4f5f97211e2fd587d7624760

(this sample)

  
Delivery method
Distributed via web download

Comments