🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 cf4c6ac09be225112faaef95316a137eff30e91c0f5f8e7aaf0a4bcc6c76f477. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Kinsing


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: cf4c6ac09be225112faaef95316a137eff30e91c0f5f8e7aaf0a4bcc6c76f477
SHA3-384 hash: 91af0affc8be0001c9abb6a012e65e4f1f9a5bc9ed8456d757dd4a600e7ee6db1960971eb76176a6d52d57e6110d7611
SHA1 hash: 78e6731430c3e4eb96cfd790b2e7820a04ebae92
MD5 hash: 708db30d5e8489f5243f025cdbdc16c2
humanhash: indigo-sixteen-north-robin
File name:exp.so
Download: download sample
Signature Kinsing
File size:44'320 bytes
First seen:2026-10-07 16:48:37 UTC
Last seen:Never
File type: elf
MIME type:application/x-sharedlib
ssdeep 384:eH7/6+Tke+q1VRFCTgALc5z3sYAqJZoQSbZzrqoAu0yVagrXHVhHkhNnFrwod:X+T0gpWi57HoPZzwej8
TLSH T1FD13AB1E6F01555FD0240F3AC97E8932CEF0246C5C694EA3890E98F42B5ED88B76DAF5
telfhash t1ceb02b52dafa541051af44108c28040064c3c306fe0c0543412c9cc080310070110640
TrID 50.1% (.) ELF Executable and Linkable format (Linux) (4022/12)
49.8% (.O) ELF Executable and Linkable format (generic) (4000/1)
Magika elf
Reporter BlinkzSec
Tags:Kinsing

Intelligence


File Origin
# of uploads :
1
# of downloads :
65
Origin country :
IN IN
Vendor Threat Intelligence
No detections
Result
Verdict:
Malware
Maliciousness:
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
gcc masquerade
Verdict:
Malicious
Uses P2P?:
false
Uses anti-vm?:
false
Architecture:
x86
Packer:
not packed
Botnet:
unknown
Number of open files:
0
Number of processes launched:
1
Processes remaning?
false
Remote TCP ports scanned:
not identified
Behaviour
no suspicious findings
Botnet C2s
TCP botnet C2(s):
not identified
UDP botnet C2(s):
not identified
Verdict:
Malicious
File Type:
elf.64.le
First seen:
2022-09-26T22:58:00Z UTC
Last seen:
2026-10-09T02:03:00Z UTC
Hits:
~10000
Status:
terminated
Behavior Graph:
%3 guuid=9289d5a5-1a00-0000-0a89-763ae6080000 pid=2278 /usr/bin/sudo guuid=142b0ba8-1a00-0000-0a89-763aea080000 pid=2282 /tmp/sample.bin guuid=9289d5a5-1a00-0000-0a89-763ae6080000 pid=2278->guuid=142b0ba8-1a00-0000-0a89-763aea080000 pid=2282 execve
Malware family:
Kinsing Rootkit
Verdict:
Malicious
Threat name:
Linux.Trojan.Generic
Status:
Suspicious
First seen:
2019-11-03 21:58:20 UTC
File Type:
ELF64 Little (SO)
AV detection:
14 of 36 (38.89%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
linux
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Kinsing

elf cf4c6ac09be225112faaef95316a137eff30e91c0f5f8e7aaf0a4bcc6c76f477

(this sample)

  
Delivery method
Distributed via web download

Comments