MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 cfe4e22fecd13f3a0ddafa6cbc45150938b4a3241d2052db6ee0abc90e16d781. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 8


Intelligence 8 IOCs YARA 18 File information Comments

SHA256 hash: cfe4e22fecd13f3a0ddafa6cbc45150938b4a3241d2052db6ee0abc90e16d781
SHA3-384 hash: c822141be3e0e424eae33eb3719ca4d4a0fd91db28d6f763dc6285ab6082c17d0f8b0f5827a15737a86c76970da8235d
SHA1 hash: 7844d4e36012e95ac713509ba505399d328ddede
MD5 hash: 70cd8ada5f6e4ed596e2978923800934
humanhash: thirteen-one-salami-ohio
File name:linux_amd64
Download: download sample
File size:4'202'496 bytes
First seen:2026-05-20 12:53:32 UTC
Last seen:2026-05-22 13:40:02 UTC
File type: elf
MIME type:application/x-executable
ssdeep 49152:8OAbe3qegxXrb/TAvO90d7HjmAFd4A64nsfJUMrQpWUhDOiYl1hmWVQg4r+55Edi:t3ediDO5lLvEZ1JU
TLSH T137163B07F89151E9C0AED134C6269263BA717C885B3023D32B51F7B82B77BD4AEB9354
telfhash t1f7326b744dbc39b5b6aaca20b393b5b49637186562f834b15063ed90ffc1e812cd6837
gimphash e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
TrID 50.1% (.) ELF Executable and Linkable format (Linux) (4022/12)
49.8% (.O) ELF Executable and Linkable format (generic) (4000/1)
Magika elf
Reporter abuse_ch
Tags:elf

Intelligence


File Origin
# of uploads :
3
# of downloads :
49
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a file in the %temp% directory
Mounts file systems
Connection attempt
Collects information on the OS
Changes access rights for a written file
Receives data from a server
Changes the time when the file was created, accessed, or modified
Runs as daemon
Unmounts file systems
Deleting a recently created file
Manages services
Creating a file
Sends data to a server
Creates directories
Launching a process
Creating a process from a recently created file
Creates or modifies files in /cron to set up autorun
Substitutes an application name
Deletes a system binary file
Writes files to system directory
Creates or modifies files to set up autorun
Creates or modifies symbolic links in /init.d to set up autorun
Creates or modifies files in /init.d to set up autorun
Verdict:
Unknown
Threat level:
  0/10
Confidence:
100%
Tags:
base64 crypto expand golang lolbin obfuscated
Verdict:
Malicious
File Type:
elf.64.le
First seen:
2026-05-20T10:27:00Z UTC
Last seen:
2026-05-20T10:40:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=a7a20e0e-1b00-0000-83fb-17931b0d0000 pid=3355 /usr/bin/sudo guuid=d217d80f-1b00-0000-83fb-1793200d0000 pid=3360 /tmp/sample.bin guuid=a7a20e0e-1b00-0000-83fb-17931b0d0000 pid=3355->guuid=d217d80f-1b00-0000-83fb-1793200d0000 pid=3360 execve guuid=d217d80f-1b00-0000-83fb-1793200d0000 pid=3370 /tmp/sample.bin guuid=d217d80f-1b00-0000-83fb-1793200d0000 pid=3360->guuid=d217d80f-1b00-0000-83fb-1793200d0000 pid=3370 clone guuid=d217d80f-1b00-0000-83fb-1793200d0000 pid=3371 /tmp/sample.bin guuid=d217d80f-1b00-0000-83fb-1793200d0000 pid=3360->guuid=d217d80f-1b00-0000-83fb-1793200d0000 pid=3371 clone guuid=d217d80f-1b00-0000-83fb-1793200d0000 pid=3372 /tmp/sample.bin guuid=d217d80f-1b00-0000-83fb-1793200d0000 pid=3360->guuid=d217d80f-1b00-0000-83fb-1793200d0000 pid=3372 clone guuid=d217d80f-1b00-0000-83fb-1793200d0000 pid=3373 /tmp/sample.bin guuid=d217d80f-1b00-0000-83fb-1793200d0000 pid=3360->guuid=d217d80f-1b00-0000-83fb-1793200d0000 pid=3373 clone guuid=d217d80f-1b00-0000-83fb-1793200d0000 pid=3374 /tmp/sample.bin guuid=d217d80f-1b00-0000-83fb-1793200d0000 pid=3360->guuid=d217d80f-1b00-0000-83fb-1793200d0000 pid=3374 clone guuid=cf75ae15-1b00-0000-83fb-17932f0d0000 pid=3375 /tmp/sample.bin delete-file send-data write-config write-file zombie guuid=d217d80f-1b00-0000-83fb-1793200d0000 pid=3360->guuid=cf75ae15-1b00-0000-83fb-17932f0d0000 pid=3375 execve 1587f3f2-bbce-5218-958c-1dc50cb35907 ak.504.su:28588 guuid=cf75ae15-1b00-0000-83fb-17932f0d0000 pid=3375->1587f3f2-bbce-5218-958c-1dc50cb35907 send: 129B guuid=cf75ae15-1b00-0000-83fb-17932f0d0000 pid=3385 /tmp/sample.bin zombie guuid=cf75ae15-1b00-0000-83fb-17932f0d0000 pid=3375->guuid=cf75ae15-1b00-0000-83fb-17932f0d0000 pid=3385 clone guuid=cf75ae15-1b00-0000-83fb-17932f0d0000 pid=3386 /tmp/sample.bin send-data zombie guuid=cf75ae15-1b00-0000-83fb-17932f0d0000 pid=3375->guuid=cf75ae15-1b00-0000-83fb-17932f0d0000 pid=3386 clone guuid=cf75ae15-1b00-0000-83fb-17932f0d0000 pid=3387 /tmp/sample.bin delete-file send-data write-config write-file zombie guuid=cf75ae15-1b00-0000-83fb-17932f0d0000 pid=3375->guuid=cf75ae15-1b00-0000-83fb-17932f0d0000 pid=3387 clone guuid=cf75ae15-1b00-0000-83fb-17932f0d0000 pid=3388 /tmp/sample.bin delete-file net send-data write-config write-file zombie guuid=cf75ae15-1b00-0000-83fb-17932f0d0000 pid=3375->guuid=cf75ae15-1b00-0000-83fb-17932f0d0000 pid=3388 clone guuid=cf75ae15-1b00-0000-83fb-17932f0d0000 pid=3390 /tmp/sample.bin send-data zombie guuid=cf75ae15-1b00-0000-83fb-17932f0d0000 pid=3375->guuid=cf75ae15-1b00-0000-83fb-17932f0d0000 pid=3390 clone guuid=cf75ae15-1b00-0000-83fb-17932f0d0000 pid=3392 /tmp/sample.bin dns net zombie guuid=cf75ae15-1b00-0000-83fb-17932f0d0000 pid=3375->guuid=cf75ae15-1b00-0000-83fb-17932f0d0000 pid=3392 clone guuid=8fb2e707-1c00-0000-83fb-17931e100000 pid=4126 /usr/bin/dash guuid=cf75ae15-1b00-0000-83fb-17932f0d0000 pid=3375->guuid=8fb2e707-1c00-0000-83fb-17931e100000 pid=4126 execve guuid=8eab2808-1c00-0000-83fb-179320100000 pid=4128 /usr/sbin/update-rc.d guuid=cf75ae15-1b00-0000-83fb-17932f0d0000 pid=3375->guuid=8eab2808-1c00-0000-83fb-179320100000 pid=4128 execve guuid=60514929-1c00-0000-83fb-1793bb100000 pid=4283 /usr/sbin/update-rc.d guuid=cf75ae15-1b00-0000-83fb-17932f0d0000 pid=3375->guuid=60514929-1c00-0000-83fb-1793bb100000 pid=4283 execve guuid=98bc2651-1c00-0000-83fb-179361110000 pid=4449 /etc/init.d/network-manger guuid=cf75ae15-1b00-0000-83fb-17932f0d0000 pid=3375->guuid=98bc2651-1c00-0000-83fb-179361110000 pid=4449 execve guuid=0763745f-1c00-0000-83fb-17939d110000 pid=4509 /usr/bin/dash guuid=cf75ae15-1b00-0000-83fb-17932f0d0000 pid=3375->guuid=0763745f-1c00-0000-83fb-17939d110000 pid=4509 execve guuid=5b44cb5f-1c00-0000-83fb-1793a0110000 pid=4512 /usr/sbin/update-rc.d guuid=cf75ae15-1b00-0000-83fb-17932f0d0000 pid=3375->guuid=5b44cb5f-1c00-0000-83fb-1793a0110000 pid=4512 execve guuid=0dd42c92-1c00-0000-83fb-179363120000 pid=4707 /usr/sbin/update-rc.d guuid=cf75ae15-1b00-0000-83fb-17932f0d0000 pid=3375->guuid=0dd42c92-1c00-0000-83fb-179363120000 pid=4707 execve guuid=b24842bf-1c00-0000-83fb-17931b130000 pid=4891 /etc/init.d/udev-teriger-net guuid=cf75ae15-1b00-0000-83fb-17932f0d0000 pid=3375->guuid=b24842bf-1c00-0000-83fb-17931b130000 pid=4891 execve guuid=60bd99c5-1c00-0000-83fb-17933a130000 pid=4922 /usr/bin/dash guuid=cf75ae15-1b00-0000-83fb-17932f0d0000 pid=3375->guuid=60bd99c5-1c00-0000-83fb-17933a130000 pid=4922 execve guuid=cf75ae15-1b00-0000-83fb-17932f0d0000 pid=3386->1587f3f2-bbce-5218-958c-1dc50cb35907 send: 235B guuid=4fb86462-1b00-0000-83fb-1793f00d0000 pid=3568 /usr/bin/uname guuid=cf75ae15-1b00-0000-83fb-17932f0d0000 pid=3386->guuid=4fb86462-1b00-0000-83fb-1793f00d0000 pid=3568 execve guuid=cf75ae15-1b00-0000-83fb-17932f0d0000 pid=3387->1587f3f2-bbce-5218-958c-1dc50cb35907 send: 43B guuid=3e6a462b-1b00-0000-83fb-1793660d0000 pid=3430 /usr/bin/dash guuid=cf75ae15-1b00-0000-83fb-17932f0d0000 pid=3387->guuid=3e6a462b-1b00-0000-83fb-1793660d0000 pid=3430 execve guuid=42f68d2b-1b00-0000-83fb-1793690d0000 pid=3433 /usr/bin/systemctl guuid=cf75ae15-1b00-0000-83fb-17932f0d0000 pid=3387->guuid=42f68d2b-1b00-0000-83fb-1793690d0000 pid=3433 execve guuid=6116e96a-1b00-0000-83fb-1793020e0000 pid=3586 /usr/bin/systemctl guuid=cf75ae15-1b00-0000-83fb-17932f0d0000 pid=3387->guuid=6116e96a-1b00-0000-83fb-1793020e0000 pid=3586 execve guuid=1d85c88e-1b00-0000-83fb-17937c0e0000 pid=3708 /usr/bin/systemctl guuid=cf75ae15-1b00-0000-83fb-17932f0d0000 pid=3387->guuid=1d85c88e-1b00-0000-83fb-17937c0e0000 pid=3708 execve guuid=94e7279a-1b00-0000-83fb-1793970e0000 pid=3735 /usr/sbin/update-rc.d guuid=cf75ae15-1b00-0000-83fb-17932f0d0000 pid=3387->guuid=94e7279a-1b00-0000-83fb-1793970e0000 pid=3735 execve guuid=cce8ffc9-1b00-0000-83fb-1793410f0000 pid=3905 /usr/sbin/update-rc.d guuid=cf75ae15-1b00-0000-83fb-17932f0d0000 pid=3387->guuid=cce8ffc9-1b00-0000-83fb-1793410f0000 pid=3905 execve guuid=473958fc-1b00-0000-83fb-1793f30f0000 pid=4083 /etc/init.d/systemd-logind guuid=cf75ae15-1b00-0000-83fb-17932f0d0000 pid=3387->guuid=473958fc-1b00-0000-83fb-1793f30f0000 pid=4083 execve guuid=cf75ae15-1b00-0000-83fb-17932f0d0000 pid=3388->1587f3f2-bbce-5218-958c-1dc50cb35907 send: 43B 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=cf75ae15-1b00-0000-83fb-17932f0d0000 pid=3388->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 76B guuid=01c97d8a-2300-0000-83fb-1793a1150000 pid=5537 /usr/bin/systemctl guuid=cf75ae15-1b00-0000-83fb-17932f0d0000 pid=3388->guuid=01c97d8a-2300-0000-83fb-1793a1150000 pid=5537 execve guuid=e35ac9aa-2300-0000-83fb-1793b6150000 pid=5558 /usr/bin/systemctl guuid=cf75ae15-1b00-0000-83fb-17932f0d0000 pid=3388->guuid=e35ac9aa-2300-0000-83fb-1793b6150000 pid=5558 execve guuid=cad928c8-2300-0000-83fb-1793cb150000 pid=5579 /usr/bin/systemctl guuid=cf75ae15-1b00-0000-83fb-17932f0d0000 pid=3388->guuid=cad928c8-2300-0000-83fb-1793cb150000 pid=5579 execve guuid=cf75ae15-1b00-0000-83fb-17932f0d0000 pid=3390->1587f3f2-bbce-5218-958c-1dc50cb35907 send: 239B guuid=cf75ae15-1b00-0000-83fb-17932f0d0000 pid=3392->1587f3f2-bbce-5218-958c-1dc50cb35907 con guuid=968a722b-1b00-0000-83fb-1793680d0000 pid=3432 /boot/System zombie guuid=3e6a462b-1b00-0000-83fb-1793660d0000 pid=3430->guuid=968a722b-1b00-0000-83fb-1793680d0000 pid=3432 execve guuid=ae47b82b-1b00-0000-83fb-17936b0d0000 pid=3435 /usr/bin/sleep guuid=968a722b-1b00-0000-83fb-1793680d0000 pid=3432->guuid=ae47b82b-1b00-0000-83fb-17936b0d0000 pid=3435 execve guuid=f1c7987c-2400-0000-83fb-1793d0150000 pid=5584 /boot/System.img-6.8.0-8 delete-file write-file guuid=968a722b-1b00-0000-83fb-1793680d0000 pid=3432->guuid=f1c7987c-2400-0000-83fb-1793d0150000 pid=5584 execve guuid=670a2c7d-2400-0000-83fb-1793d5150000 pid=5589 /usr/bin/sleep guuid=968a722b-1b00-0000-83fb-1793680d0000 pid=3432->guuid=670a2c7d-2400-0000-83fb-1793d5150000 pid=5589 execve guuid=2fdaba13-0000-0000-83fb-179301000000 pid=1 /usr/lib/systemd/systemd guuid=41bd7c90-1b00-0000-83fb-1793860e0000 pid=3718 /boot/System.img-6.8.0-8 guuid=2fdaba13-0000-0000-83fb-179301000000 pid=1->guuid=41bd7c90-1b00-0000-83fb-1793860e0000 pid=3718 execve guuid=177306f2-1d00-0000-83fb-179358150000 pid=5464 /boot/System.img-6.8.0-8 guuid=2fdaba13-0000-0000-83fb-179301000000 pid=1->guuid=177306f2-1d00-0000-83fb-179358150000 pid=5464 execve guuid=bf651355-2000-0000-83fb-17938a150000 pid=5514 /boot/System.img-6.8.0-8 guuid=2fdaba13-0000-0000-83fb-179301000000 pid=1->guuid=bf651355-2000-0000-83fb-17938a150000 pid=5514 execve guuid=fb80aeb7-2200-0000-83fb-179395150000 pid=5525 /boot/System.img-6.8.0-8 guuid=2fdaba13-0000-0000-83fb-179301000000 pid=1->guuid=fb80aeb7-2200-0000-83fb-179395150000 pid=5525 execve guuid=27e7fb1a-2500-0000-83fb-1793d6150000 pid=5590 /boot/System.img-6.8.0-8 guuid=2fdaba13-0000-0000-83fb-179301000000 pid=1->guuid=27e7fb1a-2500-0000-83fb-1793d6150000 pid=5590 execve guuid=d8208b7d-2700-0000-83fb-1793e0150000 pid=5600 /boot/System.img-6.8.0-8 guuid=2fdaba13-0000-0000-83fb-179301000000 pid=1->guuid=d8208b7d-2700-0000-83fb-1793e0150000 pid=5600 execve guuid=41bd7c90-1b00-0000-83fb-1793860e0000 pid=3725 /boot/System.img-6.8.0-8 guuid=41bd7c90-1b00-0000-83fb-1793860e0000 pid=3718->guuid=41bd7c90-1b00-0000-83fb-1793860e0000 pid=3725 clone guuid=41bd7c90-1b00-0000-83fb-1793860e0000 pid=3726 /boot/System.img-6.8.0-8 guuid=41bd7c90-1b00-0000-83fb-1793860e0000 pid=3718->guuid=41bd7c90-1b00-0000-83fb-1793860e0000 pid=3726 clone guuid=41bd7c90-1b00-0000-83fb-1793860e0000 pid=3727 /boot/System.img-6.8.0-8 guuid=41bd7c90-1b00-0000-83fb-1793860e0000 pid=3718->guuid=41bd7c90-1b00-0000-83fb-1793860e0000 pid=3727 clone guuid=41bd7c90-1b00-0000-83fb-1793860e0000 pid=3728 /boot/System.img-6.8.0-8 guuid=41bd7c90-1b00-0000-83fb-1793860e0000 pid=3718->guuid=41bd7c90-1b00-0000-83fb-1793860e0000 pid=3728 clone guuid=81c61097-1b00-0000-83fb-1793910e0000 pid=3729 /boot/System.img-6.8.0-8 delete-file write-file zombie guuid=41bd7c90-1b00-0000-83fb-1793860e0000 pid=3718->guuid=81c61097-1b00-0000-83fb-1793910e0000 pid=3729 execve guuid=81c61097-1b00-0000-83fb-1793910e0000 pid=3740 /boot/System.img-6.8.0-8 guuid=81c61097-1b00-0000-83fb-1793910e0000 pid=3729->guuid=81c61097-1b00-0000-83fb-1793910e0000 pid=3740 clone guuid=81c61097-1b00-0000-83fb-1793910e0000 pid=3741 /boot/System.img-6.8.0-8 guuid=81c61097-1b00-0000-83fb-1793910e0000 pid=3729->guuid=81c61097-1b00-0000-83fb-1793910e0000 pid=3741 clone guuid=81c61097-1b00-0000-83fb-1793910e0000 pid=3742 /boot/System.img-6.8.0-8 guuid=81c61097-1b00-0000-83fb-1793910e0000 pid=3729->guuid=81c61097-1b00-0000-83fb-1793910e0000 pid=3742 clone guuid=81c61097-1b00-0000-83fb-1793910e0000 pid=3743 /boot/System.img-6.8.0-8 guuid=81c61097-1b00-0000-83fb-1793910e0000 pid=3729->guuid=81c61097-1b00-0000-83fb-1793910e0000 pid=3743 clone guuid=5d46ce9c-1b00-0000-83fb-1793a30e0000 pid=3747 /usr/bin/systemctl guuid=94e7279a-1b00-0000-83fb-1793970e0000 pid=3735->guuid=5d46ce9c-1b00-0000-83fb-1793a30e0000 pid=3747 execve guuid=8f0c8ccc-1b00-0000-83fb-17934b0f0000 pid=3915 /usr/bin/systemctl guuid=cce8ffc9-1b00-0000-83fb-1793410f0000 pid=3905->guuid=8f0c8ccc-1b00-0000-83fb-17934b0f0000 pid=3915 execve guuid=5368e2cd-1b00-0000-83fb-1793500f0000 pid=3920 /usr/bin/systemctl guuid=cce8ffc9-1b00-0000-83fb-1793410f0000 pid=3905->guuid=5368e2cd-1b00-0000-83fb-1793500f0000 pid=3920 execve guuid=2a5db6fc-1b00-0000-83fb-1793f50f0000 pid=4085 /boot/System.img-6.8.0-8 delete-file write-file guuid=473958fc-1b00-0000-83fb-1793f30f0000 pid=4083->guuid=2a5db6fc-1b00-0000-83fb-1793f50f0000 pid=4085 execve guuid=2a5db6fc-1b00-0000-83fb-1793f50f0000 pid=4097 /boot/System.img-6.8.0-8 guuid=2a5db6fc-1b00-0000-83fb-1793f50f0000 pid=4085->guuid=2a5db6fc-1b00-0000-83fb-1793f50f0000 pid=4097 clone guuid=2a5db6fc-1b00-0000-83fb-1793f50f0000 pid=4098 /boot/System.img-6.8.0-8 guuid=2a5db6fc-1b00-0000-83fb-1793f50f0000 pid=4085->guuid=2a5db6fc-1b00-0000-83fb-1793f50f0000 pid=4098 clone guuid=2a5db6fc-1b00-0000-83fb-1793f50f0000 pid=4099 /boot/System.img-6.8.0-8 guuid=2a5db6fc-1b00-0000-83fb-1793f50f0000 pid=4085->guuid=2a5db6fc-1b00-0000-83fb-1793f50f0000 pid=4099 clone guuid=2a5db6fc-1b00-0000-83fb-1793f50f0000 pid=4101 /boot/System.img-6.8.0-8 guuid=2a5db6fc-1b00-0000-83fb-1793f50f0000 pid=4085->guuid=2a5db6fc-1b00-0000-83fb-1793f50f0000 pid=4101 clone guuid=2a5db6fc-1b00-0000-83fb-1793f50f0000 pid=4102 /boot/System.img-6.8.0-8 guuid=2a5db6fc-1b00-0000-83fb-1793f50f0000 pid=4085->guuid=2a5db6fc-1b00-0000-83fb-1793f50f0000 pid=4102 clone guuid=4a3f1108-1c00-0000-83fb-17931f100000 pid=4127 /rootfs-ext/bin/killai zombie guuid=8fb2e707-1c00-0000-83fb-17931e100000 pid=4126->guuid=4a3f1108-1c00-0000-83fb-17931f100000 pid=4127 execve guuid=4bdd8708-1c00-0000-83fb-179323100000 pid=4131 /usr/bin/sleep guuid=4a3f1108-1c00-0000-83fb-17931f100000 pid=4127->guuid=4bdd8708-1c00-0000-83fb-179323100000 pid=4131 execve guuid=332b73ad-2700-0000-83fb-1793ed150000 pid=5613 /rootfs-ext/sbin/nginx-1 delete-file write-file guuid=4a3f1108-1c00-0000-83fb-17931f100000 pid=4127->guuid=332b73ad-2700-0000-83fb-1793ed150000 pid=5613 execve guuid=ecc7eaae-2700-0000-83fb-1793f2150000 pid=5618 /usr/bin/sleep guuid=4a3f1108-1c00-0000-83fb-17931f100000 pid=4127->guuid=ecc7eaae-2700-0000-83fb-1793f2150000 pid=5618 execve guuid=47d06709-1c00-0000-83fb-179328100000 pid=4136 /usr/bin/systemctl guuid=8eab2808-1c00-0000-83fb-179320100000 pid=4128->guuid=47d06709-1c00-0000-83fb-179328100000 pid=4136 execve guuid=bc63022b-1c00-0000-83fb-1793c4100000 pid=4292 /usr/bin/systemctl guuid=60514929-1c00-0000-83fb-1793bb100000 pid=4283->guuid=bc63022b-1c00-0000-83fb-1793c4100000 pid=4292 execve guuid=3975e82b-1c00-0000-83fb-1793ca100000 pid=4298 /usr/bin/systemctl guuid=60514929-1c00-0000-83fb-1793bb100000 pid=4283->guuid=3975e82b-1c00-0000-83fb-1793ca100000 pid=4298 execve guuid=6aad6251-1c00-0000-83fb-179363110000 pid=4451 /rootfs-ext/sbin/nginx-1 delete-file write-file guuid=98bc2651-1c00-0000-83fb-179361110000 pid=4449->guuid=6aad6251-1c00-0000-83fb-179363110000 pid=4451 execve guuid=6aad6251-1c00-0000-83fb-179363110000 pid=4472 /rootfs-ext/sbin/nginx-1 guuid=6aad6251-1c00-0000-83fb-179363110000 pid=4451->guuid=6aad6251-1c00-0000-83fb-179363110000 pid=4472 clone guuid=6aad6251-1c00-0000-83fb-179363110000 pid=4473 /rootfs-ext/sbin/nginx-1 guuid=6aad6251-1c00-0000-83fb-179363110000 pid=4451->guuid=6aad6251-1c00-0000-83fb-179363110000 pid=4473 clone guuid=6aad6251-1c00-0000-83fb-179363110000 pid=4474 /rootfs-ext/sbin/nginx-1 guuid=6aad6251-1c00-0000-83fb-179363110000 pid=4451->guuid=6aad6251-1c00-0000-83fb-179363110000 pid=4474 clone guuid=6aad6251-1c00-0000-83fb-179363110000 pid=4475 /rootfs-ext/sbin/nginx-1 guuid=6aad6251-1c00-0000-83fb-179363110000 pid=4451->guuid=6aad6251-1c00-0000-83fb-179363110000 pid=4475 clone guuid=ab3aaf5f-1c00-0000-83fb-17939f110000 pid=4511 /usr/sbin/.at.atloy zombie guuid=0763745f-1c00-0000-83fb-17939d110000 pid=4509->guuid=ab3aaf5f-1c00-0000-83fb-17939f110000 pid=4511 execve guuid=68a3f25f-1c00-0000-83fb-1793a4110000 pid=4516 /usr/bin/sleep guuid=ab3aaf5f-1c00-0000-83fb-17939f110000 pid=4511->guuid=68a3f25f-1c00-0000-83fb-1793a4110000 pid=4516 execve guuid=6a950c61-1c00-0000-83fb-1793aa110000 pid=4522 /usr/bin/systemctl guuid=5b44cb5f-1c00-0000-83fb-1793a0110000 pid=4512->guuid=6a950c61-1c00-0000-83fb-1793aa110000 pid=4522 execve guuid=790e5e93-1c00-0000-83fb-179367120000 pid=4711 /usr/bin/systemctl guuid=0dd42c92-1c00-0000-83fb-179363120000 pid=4707->guuid=790e5e93-1c00-0000-83fb-179367120000 pid=4711 execve guuid=a7f0d794-1c00-0000-83fb-179369120000 pid=4713 /usr/bin/systemctl guuid=0dd42c92-1c00-0000-83fb-179363120000 pid=4707->guuid=a7f0d794-1c00-0000-83fb-179369120000 pid=4713 execve guuid=2a2a08c0-1c00-0000-83fb-17931f130000 pid=4895 /usr/lib/id.sericer.conf delete-file write-file guuid=b24842bf-1c00-0000-83fb-17931b130000 pid=4891->guuid=2a2a08c0-1c00-0000-83fb-17931f130000 pid=4895 execve guuid=2a2a08c0-1c00-0000-83fb-17931f130000 pid=4912 /usr/lib/id.sericer.conf guuid=2a2a08c0-1c00-0000-83fb-17931f130000 pid=4895->guuid=2a2a08c0-1c00-0000-83fb-17931f130000 pid=4912 clone guuid=2a2a08c0-1c00-0000-83fb-17931f130000 pid=4913 /usr/lib/id.sericer.conf guuid=2a2a08c0-1c00-0000-83fb-17931f130000 pid=4895->guuid=2a2a08c0-1c00-0000-83fb-17931f130000 pid=4913 clone guuid=2a2a08c0-1c00-0000-83fb-17931f130000 pid=4914 /usr/lib/id.sericer.conf guuid=2a2a08c0-1c00-0000-83fb-17931f130000 pid=4895->guuid=2a2a08c0-1c00-0000-83fb-17931f130000 pid=4914 clone guuid=2a2a08c0-1c00-0000-83fb-17931f130000 pid=4915 /usr/lib/id.sericer.conf guuid=2a2a08c0-1c00-0000-83fb-17931f130000 pid=4895->guuid=2a2a08c0-1c00-0000-83fb-17931f130000 pid=4915 clone guuid=2a2a08c0-1c00-0000-83fb-17931f130000 pid=4917 /usr/lib/id.sericer.conf guuid=2a2a08c0-1c00-0000-83fb-17931f130000 pid=4895->guuid=2a2a08c0-1c00-0000-83fb-17931f130000 pid=4917 clone guuid=11abbfc5-1c00-0000-83fb-17933b130000 pid=4923 /tmp/.font-unix-helpver zombie guuid=60bd99c5-1c00-0000-83fb-17933a130000 pid=4922->guuid=11abbfc5-1c00-0000-83fb-17933b130000 pid=4923 execve guuid=f779ebc5-1c00-0000-83fb-17933d130000 pid=4925 /usr/bin/sleep guuid=11abbfc5-1c00-0000-83fb-17933b130000 pid=4923->guuid=f779ebc5-1c00-0000-83fb-17933d130000 pid=4925 execve guuid=177306f2-1d00-0000-83fb-179358150000 pid=5465 /boot/System.img-6.8.0-8 guuid=177306f2-1d00-0000-83fb-179358150000 pid=5464->guuid=177306f2-1d00-0000-83fb-179358150000 pid=5465 clone guuid=177306f2-1d00-0000-83fb-179358150000 pid=5466 /boot/System.img-6.8.0-8 guuid=177306f2-1d00-0000-83fb-179358150000 pid=5464->guuid=177306f2-1d00-0000-83fb-179358150000 pid=5466 clone guuid=177306f2-1d00-0000-83fb-179358150000 pid=5467 /boot/System.img-6.8.0-8 guuid=177306f2-1d00-0000-83fb-179358150000 pid=5464->guuid=177306f2-1d00-0000-83fb-179358150000 pid=5467 clone guuid=177306f2-1d00-0000-83fb-179358150000 pid=5468 /boot/System.img-6.8.0-8 guuid=177306f2-1d00-0000-83fb-179358150000 pid=5464->guuid=177306f2-1d00-0000-83fb-179358150000 pid=5468 clone guuid=314509f9-1d00-0000-83fb-17935d150000 pid=5469 /boot/System.img-6.8.0-8 delete-file write-file zombie guuid=177306f2-1d00-0000-83fb-179358150000 pid=5464->guuid=314509f9-1d00-0000-83fb-17935d150000 pid=5469 execve guuid=314509f9-1d00-0000-83fb-17935d150000 pid=5470 /boot/System.img-6.8.0-8 zombie guuid=314509f9-1d00-0000-83fb-17935d150000 pid=5469->guuid=314509f9-1d00-0000-83fb-17935d150000 pid=5470 clone guuid=314509f9-1d00-0000-83fb-17935d150000 pid=5471 /boot/System.img-6.8.0-8 guuid=314509f9-1d00-0000-83fb-17935d150000 pid=5469->guuid=314509f9-1d00-0000-83fb-17935d150000 pid=5471 clone guuid=314509f9-1d00-0000-83fb-17935d150000 pid=5472 /boot/System.img-6.8.0-8 guuid=314509f9-1d00-0000-83fb-17935d150000 pid=5469->guuid=314509f9-1d00-0000-83fb-17935d150000 pid=5472 clone guuid=314509f9-1d00-0000-83fb-17935d150000 pid=5473 /boot/System.img-6.8.0-8 guuid=314509f9-1d00-0000-83fb-17935d150000 pid=5469->guuid=314509f9-1d00-0000-83fb-17935d150000 pid=5473 clone guuid=314509f9-1d00-0000-83fb-17935d150000 pid=5474 /boot/System.img-6.8.0-8 guuid=314509f9-1d00-0000-83fb-17935d150000 pid=5469->guuid=314509f9-1d00-0000-83fb-17935d150000 pid=5474 clone guuid=bf651355-2000-0000-83fb-17938a150000 pid=5515 /boot/System.img-6.8.0-8 guuid=bf651355-2000-0000-83fb-17938a150000 pid=5514->guuid=bf651355-2000-0000-83fb-17938a150000 pid=5515 clone guuid=bf651355-2000-0000-83fb-17938a150000 pid=5516 /boot/System.img-6.8.0-8 guuid=bf651355-2000-0000-83fb-17938a150000 pid=5514->guuid=bf651355-2000-0000-83fb-17938a150000 pid=5516 clone guuid=bf651355-2000-0000-83fb-17938a150000 pid=5517 /boot/System.img-6.8.0-8 guuid=bf651355-2000-0000-83fb-17938a150000 pid=5514->guuid=bf651355-2000-0000-83fb-17938a150000 pid=5517 clone guuid=bf651355-2000-0000-83fb-17938a150000 pid=5518 /boot/System.img-6.8.0-8 guuid=bf651355-2000-0000-83fb-17938a150000 pid=5514->guuid=bf651355-2000-0000-83fb-17938a150000 pid=5518 clone guuid=bf651355-2000-0000-83fb-17938a150000 pid=5519 /boot/System.img-6.8.0-8 guuid=bf651355-2000-0000-83fb-17938a150000 pid=5514->guuid=bf651355-2000-0000-83fb-17938a150000 pid=5519 clone guuid=30df8859-2000-0000-83fb-179390150000 pid=5520 /boot/System.img-6.8.0-8 delete-file write-file zombie guuid=bf651355-2000-0000-83fb-17938a150000 pid=5514->guuid=30df8859-2000-0000-83fb-179390150000 pid=5520 execve guuid=30df8859-2000-0000-83fb-179390150000 pid=5521 /boot/System.img-6.8.0-8 zombie guuid=30df8859-2000-0000-83fb-179390150000 pid=5520->guuid=30df8859-2000-0000-83fb-179390150000 pid=5521 clone guuid=30df8859-2000-0000-83fb-179390150000 pid=5522 /boot/System.img-6.8.0-8 guuid=30df8859-2000-0000-83fb-179390150000 pid=5520->guuid=30df8859-2000-0000-83fb-179390150000 pid=5522 clone guuid=30df8859-2000-0000-83fb-179390150000 pid=5523 /boot/System.img-6.8.0-8 guuid=30df8859-2000-0000-83fb-179390150000 pid=5520->guuid=30df8859-2000-0000-83fb-179390150000 pid=5523 clone guuid=30df8859-2000-0000-83fb-179390150000 pid=5524 /boot/System.img-6.8.0-8 guuid=30df8859-2000-0000-83fb-179390150000 pid=5520->guuid=30df8859-2000-0000-83fb-179390150000 pid=5524 clone guuid=fb80aeb7-2200-0000-83fb-179395150000 pid=5526 /boot/System.img-6.8.0-8 guuid=fb80aeb7-2200-0000-83fb-179395150000 pid=5525->guuid=fb80aeb7-2200-0000-83fb-179395150000 pid=5526 clone guuid=fb80aeb7-2200-0000-83fb-179395150000 pid=5527 /boot/System.img-6.8.0-8 guuid=fb80aeb7-2200-0000-83fb-179395150000 pid=5525->guuid=fb80aeb7-2200-0000-83fb-179395150000 pid=5527 clone guuid=fb80aeb7-2200-0000-83fb-179395150000 pid=5528 /boot/System.img-6.8.0-8 guuid=fb80aeb7-2200-0000-83fb-179395150000 pid=5525->guuid=fb80aeb7-2200-0000-83fb-179395150000 pid=5528 clone guuid=fb80aeb7-2200-0000-83fb-179395150000 pid=5529 /boot/System.img-6.8.0-8 guuid=fb80aeb7-2200-0000-83fb-179395150000 pid=5525->guuid=fb80aeb7-2200-0000-83fb-179395150000 pid=5529 clone guuid=fb80aeb7-2200-0000-83fb-179395150000 pid=5530 /boot/System.img-6.8.0-8 guuid=fb80aeb7-2200-0000-83fb-179395150000 pid=5525->guuid=fb80aeb7-2200-0000-83fb-179395150000 pid=5530 clone guuid=997592b9-2200-0000-83fb-17939b150000 pid=5531 /boot/System.img-6.8.0-8 delete-file write-file zombie guuid=fb80aeb7-2200-0000-83fb-179395150000 pid=5525->guuid=997592b9-2200-0000-83fb-17939b150000 pid=5531 execve guuid=997592b9-2200-0000-83fb-17939b150000 pid=5532 /boot/System.img-6.8.0-8 guuid=997592b9-2200-0000-83fb-17939b150000 pid=5531->guuid=997592b9-2200-0000-83fb-17939b150000 pid=5532 clone guuid=997592b9-2200-0000-83fb-17939b150000 pid=5533 /boot/System.img-6.8.0-8 guuid=997592b9-2200-0000-83fb-17939b150000 pid=5531->guuid=997592b9-2200-0000-83fb-17939b150000 pid=5533 clone guuid=997592b9-2200-0000-83fb-17939b150000 pid=5534 /boot/System.img-6.8.0-8 guuid=997592b9-2200-0000-83fb-17939b150000 pid=5531->guuid=997592b9-2200-0000-83fb-17939b150000 pid=5534 clone guuid=997592b9-2200-0000-83fb-17939b150000 pid=5535 /boot/System.img-6.8.0-8 guuid=997592b9-2200-0000-83fb-17939b150000 pid=5531->guuid=997592b9-2200-0000-83fb-17939b150000 pid=5535 clone guuid=997592b9-2200-0000-83fb-17939b150000 pid=5536 /boot/System.img-6.8.0-8 guuid=997592b9-2200-0000-83fb-17939b150000 pid=5531->guuid=997592b9-2200-0000-83fb-17939b150000 pid=5536 clone guuid=f1c7987c-2400-0000-83fb-1793d0150000 pid=5585 /boot/System.img-6.8.0-8 guuid=f1c7987c-2400-0000-83fb-1793d0150000 pid=5584->guuid=f1c7987c-2400-0000-83fb-1793d0150000 pid=5585 clone guuid=f1c7987c-2400-0000-83fb-1793d0150000 pid=5586 /boot/System.img-6.8.0-8 guuid=f1c7987c-2400-0000-83fb-1793d0150000 pid=5584->guuid=f1c7987c-2400-0000-83fb-1793d0150000 pid=5586 clone guuid=f1c7987c-2400-0000-83fb-1793d0150000 pid=5587 /boot/System.img-6.8.0-8 guuid=f1c7987c-2400-0000-83fb-1793d0150000 pid=5584->guuid=f1c7987c-2400-0000-83fb-1793d0150000 pid=5587 clone guuid=f1c7987c-2400-0000-83fb-1793d0150000 pid=5588 /boot/System.img-6.8.0-8 guuid=f1c7987c-2400-0000-83fb-1793d0150000 pid=5584->guuid=f1c7987c-2400-0000-83fb-1793d0150000 pid=5588 clone guuid=27e7fb1a-2500-0000-83fb-1793d6150000 pid=5591 /boot/System.img-6.8.0-8 guuid=27e7fb1a-2500-0000-83fb-1793d6150000 pid=5590->guuid=27e7fb1a-2500-0000-83fb-1793d6150000 pid=5591 clone guuid=27e7fb1a-2500-0000-83fb-1793d6150000 pid=5592 /boot/System.img-6.8.0-8 guuid=27e7fb1a-2500-0000-83fb-1793d6150000 pid=5590->guuid=27e7fb1a-2500-0000-83fb-1793d6150000 pid=5592 clone guuid=27e7fb1a-2500-0000-83fb-1793d6150000 pid=5593 /boot/System.img-6.8.0-8 guuid=27e7fb1a-2500-0000-83fb-1793d6150000 pid=5590->guuid=27e7fb1a-2500-0000-83fb-1793d6150000 pid=5593 clone guuid=27e7fb1a-2500-0000-83fb-1793d6150000 pid=5594 /boot/System.img-6.8.0-8 guuid=27e7fb1a-2500-0000-83fb-1793d6150000 pid=5590->guuid=27e7fb1a-2500-0000-83fb-1793d6150000 pid=5594 clone guuid=3cf7311e-2500-0000-83fb-1793db150000 pid=5595 /boot/System.img-6.8.0-8 delete-file write-file zombie guuid=27e7fb1a-2500-0000-83fb-1793d6150000 pid=5590->guuid=3cf7311e-2500-0000-83fb-1793db150000 pid=5595 execve guuid=3cf7311e-2500-0000-83fb-1793db150000 pid=5596 /boot/System.img-6.8.0-8 guuid=3cf7311e-2500-0000-83fb-1793db150000 pid=5595->guuid=3cf7311e-2500-0000-83fb-1793db150000 pid=5596 clone guuid=3cf7311e-2500-0000-83fb-1793db150000 pid=5597 /boot/System.img-6.8.0-8 guuid=3cf7311e-2500-0000-83fb-1793db150000 pid=5595->guuid=3cf7311e-2500-0000-83fb-1793db150000 pid=5597 clone guuid=3cf7311e-2500-0000-83fb-1793db150000 pid=5598 /boot/System.img-6.8.0-8 guuid=3cf7311e-2500-0000-83fb-1793db150000 pid=5595->guuid=3cf7311e-2500-0000-83fb-1793db150000 pid=5598 clone guuid=3cf7311e-2500-0000-83fb-1793db150000 pid=5599 /boot/System.img-6.8.0-8 guuid=3cf7311e-2500-0000-83fb-1793db150000 pid=5595->guuid=3cf7311e-2500-0000-83fb-1793db150000 pid=5599 clone guuid=d8208b7d-2700-0000-83fb-1793e0150000 pid=5601 /boot/System.img-6.8.0-8 guuid=d8208b7d-2700-0000-83fb-1793e0150000 pid=5600->guuid=d8208b7d-2700-0000-83fb-1793e0150000 pid=5601 clone guuid=d8208b7d-2700-0000-83fb-1793e0150000 pid=5602 /boot/System.img-6.8.0-8 guuid=d8208b7d-2700-0000-83fb-1793e0150000 pid=5600->guuid=d8208b7d-2700-0000-83fb-1793e0150000 pid=5602 clone guuid=d8208b7d-2700-0000-83fb-1793e0150000 pid=5603 /boot/System.img-6.8.0-8 guuid=d8208b7d-2700-0000-83fb-1793e0150000 pid=5600->guuid=d8208b7d-2700-0000-83fb-1793e0150000 pid=5603 clone guuid=d8208b7d-2700-0000-83fb-1793e0150000 pid=5604 /boot/System.img-6.8.0-8 guuid=d8208b7d-2700-0000-83fb-1793e0150000 pid=5600->guuid=d8208b7d-2700-0000-83fb-1793e0150000 pid=5604 clone guuid=d8208b7d-2700-0000-83fb-1793e0150000 pid=5605 /boot/System.img-6.8.0-8 guuid=d8208b7d-2700-0000-83fb-1793e0150000 pid=5600->guuid=d8208b7d-2700-0000-83fb-1793e0150000 pid=5605 clone guuid=d0ac967f-2700-0000-83fb-1793e6150000 pid=5606 /boot/System.img-6.8.0-8 delete-file write-file zombie guuid=d8208b7d-2700-0000-83fb-1793e0150000 pid=5600->guuid=d0ac967f-2700-0000-83fb-1793e6150000 pid=5606 execve guuid=d0ac967f-2700-0000-83fb-1793e6150000 pid=5607 /boot/System.img-6.8.0-8 zombie guuid=d0ac967f-2700-0000-83fb-1793e6150000 pid=5606->guuid=d0ac967f-2700-0000-83fb-1793e6150000 pid=5607 clone guuid=d0ac967f-2700-0000-83fb-1793e6150000 pid=5608 /boot/System.img-6.8.0-8 guuid=d0ac967f-2700-0000-83fb-1793e6150000 pid=5606->guuid=d0ac967f-2700-0000-83fb-1793e6150000 pid=5608 clone guuid=d0ac967f-2700-0000-83fb-1793e6150000 pid=5609 /boot/System.img-6.8.0-8 guuid=d0ac967f-2700-0000-83fb-1793e6150000 pid=5606->guuid=d0ac967f-2700-0000-83fb-1793e6150000 pid=5609 clone guuid=d0ac967f-2700-0000-83fb-1793e6150000 pid=5610 /boot/System.img-6.8.0-8 guuid=d0ac967f-2700-0000-83fb-1793e6150000 pid=5606->guuid=d0ac967f-2700-0000-83fb-1793e6150000 pid=5610 clone guuid=d0ac967f-2700-0000-83fb-1793e6150000 pid=5611 /boot/System.img-6.8.0-8 guuid=d0ac967f-2700-0000-83fb-1793e6150000 pid=5606->guuid=d0ac967f-2700-0000-83fb-1793e6150000 pid=5611 clone guuid=332b73ad-2700-0000-83fb-1793ed150000 pid=5614 /rootfs-ext/sbin/nginx-1 guuid=332b73ad-2700-0000-83fb-1793ed150000 pid=5613->guuid=332b73ad-2700-0000-83fb-1793ed150000 pid=5614 clone guuid=332b73ad-2700-0000-83fb-1793ed150000 pid=5615 /rootfs-ext/sbin/nginx-1 guuid=332b73ad-2700-0000-83fb-1793ed150000 pid=5613->guuid=332b73ad-2700-0000-83fb-1793ed150000 pid=5615 clone guuid=332b73ad-2700-0000-83fb-1793ed150000 pid=5616 /rootfs-ext/sbin/nginx-1 guuid=332b73ad-2700-0000-83fb-1793ed150000 pid=5613->guuid=332b73ad-2700-0000-83fb-1793ed150000 pid=5616 clone guuid=332b73ad-2700-0000-83fb-1793ed150000 pid=5617 /rootfs-ext/sbin/nginx-1 guuid=332b73ad-2700-0000-83fb-1793ed150000 pid=5613->guuid=332b73ad-2700-0000-83fb-1793ed150000 pid=5617 clone
Result
Threat name:
n/a
Detection:
malicious
Classification:
spre.troj.evad
Score:
80 / 100
Signature
Drops files in suspicious directories
Drops invisible ELF files
Executes the "crontab" command typically for achieving persistence
Found Tor onion address
Modifies the '.bashrc' or '.bash_profile' file typically for persisting actions
Sample tries to persist itself using /etc/profile
Sample tries to persist itself using cron
Sample tries to persist itself using System V runlevels
Writes ELF files to hidden directories
Writes identical ELF files to multiple locations
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1916372 Sample: linux_amd64.elf Startdate: 20/05/2026 Architecture: LINUX Score: 80 84 ak.504.su 82.27.11.165, 28588, 45186 WAP-AC-WAPACLLCUS Hong Kong SAR China 2->84 86 Found Tor onion address 2->86 10 linux_amd64.elf 2->10         started        12 systemd System.img-6.8.0-8 2->12         started        14 systemd System.img-6.8.0-8 2->14         started        16 23 other processes 2->16 signatures3 process4 process5 18 linux_amd64.elf linux_amd64.elf 10->18         started        22 System.img-6.8.0-8 System.img-6.8.0-8 12->22         started        24 System.img-6.8.0-8 System.img-6.8.0-8 14->24         started        26 System.img-6.8.0-8 System.img-6.8.0-8 16->26         started        28 System.img-6.8.0-8 System.img-6.8.0-8 16->28         started        30 System.img-6.8.0-8 System.img-6.8.0-8 16->30         started        32 7 other processes 16->32 file6 72 /usr/sbin/.write_test_ynto, ASCII 18->72 dropped 74 /usr/sbin/.write_test_uyhw, ASCII 18->74 dropped 76 /usr/sbin/.write_test_s6c6, ASCII 18->76 dropped 78 45 other malicious files 18->78 dropped 88 Writes ELF files to hidden directories 18->88 90 Writes identical ELF files to multiple locations 18->90 92 Sample tries to persist itself using /etc/profile 18->92 94 5 other signatures 18->94 34 linux_amd64.elf crontab 18->34         started        38 linux_amd64.elf crontab 18->38         started        40 linux_amd64.elf sh 18->40         started        42 26 other processes 18->42 signatures7 process8 file9 80 /var/spool/cron/crontabs/tmp.jk3ugP, ASCII 34->80 dropped 96 Sample tries to persist itself using cron 34->96 98 Executes the "crontab" command typically for achieving persistence 34->98 82 /var/spool/cron/crontabs/tmp.7EjwSs, ASCII 38->82 dropped 44 sh System 40->44         started        100 Sample tries to persist itself using System V runlevels 42->100 46 sh killai 42->46         started        48 sh .at.atloy 42->48         started        50 sh .font-unix-helpver 42->50         started        52 12 other processes 42->52 signatures10 process11 process12 54 System sleep 44->54         started        56 System System.img-6.8.0-8 44->56         started        64 5 other processes 44->64 58 killai sleep 46->58         started        66 4 other processes 46->66 60 .at.atloy sleep 48->60         started        68 2 other processes 48->68 62 .font-unix-helpver sleep 50->62         started        70 2 other processes 50->70
Threat name:
Linux.PUA.Multiverze
Status:
Malicious
First seen:
2026-05-20 12:54:42 UTC
File Type:
ELF64 Little (Exe)
AV detection:
13 of 24 (54.17%)
Threat level:
  1/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
defense_evasion discovery execution linux persistence privilege_escalation
Behaviour
Enumerates kernel/hardware configuration
Reads runtime system information
Writes file to tmp directory
Changes its process name
Modifies Bash startup script
Creates/modifies Cron job
Creates/modifies environment variables
Enumerates running processes
Modifies init.d
Modifies rc script
Reads list of loaded kernel modules
Write file to user bin folder
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:DetectGoMethodSignatures
Author:Wyatt Tauber
Description:Detects Go method signatures in unpacked Go binaries
Rule name:Detect_Go_GOMAXPROCS
Author:Obscurity Labs LLC
Description:Detects Go binaries by the presence of runtime.GOMAXPROCS in the runtime metadata
Rule name:enterpriseapps2
Author:Tim Brown @timb_machine
Description:Enterprise apps
Rule name:GoBinTest
Rule name:golang_binary_string
Description:Golang strings present
Rule name:golang_duffcopy_amd64
Rule name:Golang_Find_CSC846
Author:Ashar Siddiqui
Description:Find Go Signatuers
Rule name:Golang_Find_CSC846_Simple
Author:Ashar Siddiqui
Description:Find Go Signatuers
Rule name:MD5_Constants
Author:phoul (@phoul)
Description:Look for MD5 constants
Rule name:ProgramLanguage_Golang
Author:albertzsigovits
Description:Application written in Golang programming language
Rule name:RANSOMWARE
Author:ToroGuitar
Rule name:RIPEMD160_Constants
Author:phoul (@phoul)
Description:Look for RIPEMD-160 constants
Rule name:setsockopt
Author:Tim Brown @timb_machine
Description:Hunts for setsockopt() red flags
Rule name:SHA1_Constants
Author:phoul (@phoul)
Description:Look for SHA1 constants
Rule name:SHA512_Constants
Author:phoul (@phoul)
Description:Look for SHA384/SHA512 constants
Rule name:TH_Generic_MassHunt_Linux_Malware_2026_CYFARE
Author:CYFARE
Description:Generic Linux malware mass-hunt rule - 2026
Reference:https://cyfare.net/
Rule name:unixredflags3
Author:Tim Brown @timb_machine
Description:Hunts for UNIX red flags

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

elf cfe4e22fecd13f3a0ddafa6cbc45150938b4a3241d2052db6ee0abc90e16d781

(this sample)

  
Delivery method
Distributed via web download

Comments