MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d1d5dacc6208b6698e7b6ddcab740f9d7a2fb15a106eacc1841a3d2a3824d1dc. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA 2 File information Comments

SHA256 hash: d1d5dacc6208b6698e7b6ddcab740f9d7a2fb15a106eacc1841a3d2a3824d1dc
SHA3-384 hash: d41b5b945177246c6b79509719ddf1b77112eb9c040db2462e09a89c206c440244107f1909724868a647c29ccd5728c4
SHA1 hash: 646e51db8d1eb0017c233600c8d5b52537a745b8
MD5 hash: a5b9ca0ffc2008d1f72b117d03e5002d
humanhash: oregon-arkansas-pasta-neptune
File name:x6.pdf
Download: download sample
File size:54'464 bytes
First seen:2026-01-25 01:37:52 UTC
Last seen:Never
File type: elf
MIME type:application/x-executable
ssdeep 768:TMHlRHJDtvaSyedC8pkxp0grSghD7HOcUEr+4:TCltJDh1LQ8expFBzOKr+
TLSH T185330B0BB59360FDC19FD474876B96276D32B89503343F7B2B98ED311E60E612AADB10
telfhash t119114cb156a638e1f29bd921a71df030c975297350d03af1ebb5bee4ef21f801a91c15
TrID 50.1% (.) ELF Executable and Linkable format (Linux) (4022/12)
49.8% (.O) ELF Executable and Linkable format (generic) (4000/1)
Magika elf
Reporter abuse_ch
Tags:elf

Intelligence


File Origin
# of uploads :
1
# of downloads :
42
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
anti-vm gcc masquerade
Verdict:
Malicious
Uses P2P?:
false
Uses anti-vm?:
false
Architecture:
x86
Packer:
not packed
Botnet:
unknown
Number of open files:
12
Number of processes launched:
6
Processes remaning?
true
Remote TCP ports scanned:
not identified
Behaviour
Persistence
Process Renaming
Botnet C2s
TCP botnet C2(s):
not identified
UDP botnet C2(s):
not identified
Result
Gathering data
Status:
terminated
Behavior Graph:
%3 guuid=d6308ba8-1600-0000-177c-bd97b90c0000 pid=3257 /usr/bin/sudo guuid=50af7faa-1600-0000-177c-bd97bd0c0000 pid=3261 /tmp/sample.bin write-file guuid=d6308ba8-1600-0000-177c-bd97b90c0000 pid=3257->guuid=50af7faa-1600-0000-177c-bd97bd0c0000 pid=3261 execve guuid=219fafaa-1600-0000-177c-bd97be0c0000 pid=3262 /usr/bin/dash guuid=50af7faa-1600-0000-177c-bd97bd0c0000 pid=3261->guuid=219fafaa-1600-0000-177c-bd97be0c0000 pid=3262 execve guuid=63d5fcab-1600-0000-177c-bd97c30c0000 pid=3267 /usr/bin/dash guuid=50af7faa-1600-0000-177c-bd97bd0c0000 pid=3261->guuid=63d5fcab-1600-0000-177c-bd97c30c0000 pid=3267 execve guuid=e2037eac-1600-0000-177c-bd97c70c0000 pid=3271 /usr/bin/dash write-file guuid=50af7faa-1600-0000-177c-bd97bd0c0000 pid=3261->guuid=e2037eac-1600-0000-177c-bd97c70c0000 pid=3271 execve guuid=43f6b3ac-1600-0000-177c-bd97c90c0000 pid=3273 /usr/bin/dash write-file guuid=50af7faa-1600-0000-177c-bd97bd0c0000 pid=3261->guuid=43f6b3ac-1600-0000-177c-bd97c90c0000 pid=3273 execve guuid=097ce6ac-1600-0000-177c-bd97cb0c0000 pid=3275 /usr/bin/dash guuid=50af7faa-1600-0000-177c-bd97bd0c0000 pid=3261->guuid=097ce6ac-1600-0000-177c-bd97cb0c0000 pid=3275 execve guuid=b6ff06af-1600-0000-177c-bd97d20c0000 pid=3282 /tmp/sample.bin write-file zombie guuid=50af7faa-1600-0000-177c-bd97bd0c0000 pid=3261->guuid=b6ff06af-1600-0000-177c-bd97d20c0000 pid=3282 clone guuid=ebea03ab-1600-0000-177c-bd97bf0c0000 pid=3263 /usr/bin/dash guuid=219fafaa-1600-0000-177c-bd97be0c0000 pid=3262->guuid=ebea03ab-1600-0000-177c-bd97bf0c0000 pid=3263 clone guuid=13ff11ab-1600-0000-177c-bd97c00c0000 pid=3264 /usr/bin/dash guuid=219fafaa-1600-0000-177c-bd97be0c0000 pid=3262->guuid=13ff11ab-1600-0000-177c-bd97c00c0000 pid=3264 clone guuid=138a18ab-1600-0000-177c-bd97c10c0000 pid=3265 /usr/bin/dash guuid=ebea03ab-1600-0000-177c-bd97bf0c0000 pid=3263->guuid=138a18ab-1600-0000-177c-bd97c10c0000 pid=3265 clone guuid=ab2522ab-1600-0000-177c-bd97c20c0000 pid=3266 /usr/bin/grep guuid=ebea03ab-1600-0000-177c-bd97bf0c0000 pid=3263->guuid=ab2522ab-1600-0000-177c-bd97c20c0000 pid=3266 execve guuid=a6ba28ac-1600-0000-177c-bd97c50c0000 pid=3269 /usr/bin/mkdir guuid=63d5fcab-1600-0000-177c-bd97c30c0000 pid=3267->guuid=a6ba28ac-1600-0000-177c-bd97c50c0000 pid=3269 execve guuid=d03b11ad-1600-0000-177c-bd97cc0c0000 pid=3276 /usr/bin/systemctl write-file guuid=097ce6ac-1600-0000-177c-bd97cb0c0000 pid=3275->guuid=d03b11ad-1600-0000-177c-bd97cc0c0000 pid=3276 execve guuid=b0f914af-1600-0000-177c-bd97d30c0000 pid=3283 memfd:udevr mprotect-exec write-file guuid=b6ff06af-1600-0000-177c-bd97d20c0000 pid=3282->guuid=b0f914af-1600-0000-177c-bd97d30c0000 pid=3283 execve guuid=855e22af-1600-0000-177c-bd97d40c0000 pid=3284 /usr/bin/dash guuid=b0f914af-1600-0000-177c-bd97d30c0000 pid=3283->guuid=855e22af-1600-0000-177c-bd97d40c0000 pid=3284 execve guuid=0bc5bfaf-1600-0000-177c-bd97dc0c0000 pid=3292 /usr/bin/dash guuid=b0f914af-1600-0000-177c-bd97d30c0000 pid=3283->guuid=0bc5bfaf-1600-0000-177c-bd97dc0c0000 pid=3292 execve guuid=c50838b0-1600-0000-177c-bd97e00c0000 pid=3296 /usr/bin/dash write-file guuid=b0f914af-1600-0000-177c-bd97d30c0000 pid=3283->guuid=c50838b0-1600-0000-177c-bd97e00c0000 pid=3296 execve guuid=460e7fb0-1600-0000-177c-bd97e20c0000 pid=3298 /usr/bin/dash write-file guuid=b0f914af-1600-0000-177c-bd97d30c0000 pid=3283->guuid=460e7fb0-1600-0000-177c-bd97e20c0000 pid=3298 execve guuid=2922c5b0-1600-0000-177c-bd97e40c0000 pid=3300 /usr/bin/dash guuid=b0f914af-1600-0000-177c-bd97d30c0000 pid=3283->guuid=2922c5b0-1600-0000-177c-bd97e40c0000 pid=3300 execve guuid=ed87e3b1-1600-0000-177c-bd97e90c0000 pid=3305 /usr/bin/dash guuid=b0f914af-1600-0000-177c-bd97d30c0000 pid=3283->guuid=ed87e3b1-1600-0000-177c-bd97e90c0000 pid=3305 execve guuid=91d16bb2-1600-0000-177c-bd97ed0c0000 pid=3309 /usr/bin/dash guuid=b0f914af-1600-0000-177c-bd97d30c0000 pid=3283->guuid=91d16bb2-1600-0000-177c-bd97ed0c0000 pid=3309 execve guuid=034597b2-1600-0000-177c-bd97ef0c0000 pid=3311 /usr/bin/dash guuid=b0f914af-1600-0000-177c-bd97d30c0000 pid=3283->guuid=034597b2-1600-0000-177c-bd97ef0c0000 pid=3311 execve guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=3497 memfd:udevr net send-data zombie guuid=b0f914af-1600-0000-177c-bd97d30c0000 pid=3283->guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=3497 clone guuid=868b54af-1600-0000-177c-bd97d60c0000 pid=3286 /usr/bin/dash guuid=855e22af-1600-0000-177c-bd97d40c0000 pid=3284->guuid=868b54af-1600-0000-177c-bd97d60c0000 pid=3286 clone guuid=86475aaf-1600-0000-177c-bd97d70c0000 pid=3287 /usr/bin/dash guuid=855e22af-1600-0000-177c-bd97d40c0000 pid=3284->guuid=86475aaf-1600-0000-177c-bd97d70c0000 pid=3287 clone guuid=e6835caf-1600-0000-177c-bd97d80c0000 pid=3288 /usr/bin/dash guuid=868b54af-1600-0000-177c-bd97d60c0000 pid=3286->guuid=e6835caf-1600-0000-177c-bd97d80c0000 pid=3288 clone guuid=08fd61af-1600-0000-177c-bd97d90c0000 pid=3289 /usr/bin/grep guuid=868b54af-1600-0000-177c-bd97d60c0000 pid=3286->guuid=08fd61af-1600-0000-177c-bd97d90c0000 pid=3289 execve guuid=c738e5af-1600-0000-177c-bd97dd0c0000 pid=3293 /usr/bin/mkdir guuid=0bc5bfaf-1600-0000-177c-bd97dc0c0000 pid=3292->guuid=c738e5af-1600-0000-177c-bd97dd0c0000 pid=3293 execve guuid=cbf9f2b0-1600-0000-177c-bd97e60c0000 pid=3302 /usr/bin/systemctl write-file guuid=2922c5b0-1600-0000-177c-bd97e40c0000 pid=3300->guuid=cbf9f2b0-1600-0000-177c-bd97e60c0000 pid=3302 execve guuid=1a3610b2-1600-0000-177c-bd97eb0c0000 pid=3307 /usr/bin/grep guuid=ed87e3b1-1600-0000-177c-bd97e90c0000 pid=3305->guuid=1a3610b2-1600-0000-177c-bd97eb0c0000 pid=3307 execve guuid=ccfbbab2-1600-0000-177c-bd97f00c0000 pid=3312 /usr/bin/curl net send-data guuid=034597b2-1600-0000-177c-bd97ef0c0000 pid=3311->guuid=ccfbbab2-1600-0000-177c-bd97f00c0000 pid=3312 execve 48626d9b-63c6-5d07-91e3-915918183433 77.90.185.76:80 guuid=ccfbbab2-1600-0000-177c-bd97f00c0000 pid=3312->48626d9b-63c6-5d07-91e3-915918183433 send: 83B 0dc3be2f-f74a-5399-94bd-5ef9d34e6ec0 77.90.185.76:3333 guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=3497->0dc3be2f-f74a-5399-94bd-5ef9d34e6ec0 send: 452B guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=3500 memfd:udevr write-file zombie guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=3497->guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=3500 clone guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=3501 memfd:udevr zombie guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=3497->guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=3501 clone guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=3502 memfd:udevr zombie guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=3497->guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=3502 clone guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=3503 memfd:udevr zombie guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=3497->guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=3503 clone guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=3504 memfd:udevr zombie guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=3497->guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=3504 clone guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=4343 memfd:udevr zombie guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=3497->guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=4343 clone guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=4344 memfd:udevr zombie guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=3497->guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=4344 clone guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=4345 memfd:udevr zombie guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=3497->guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=4345 clone guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=4346 memfd:udevr zombie guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=3497->guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=4346 clone guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=4367 memfd:udevr zombie guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=3497->guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=4367 clone guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=4368 memfd:udevr zombie guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=3497->guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=4368 clone guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=4369 memfd:udevr zombie guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=3497->guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=4369 clone guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=4370 memfd:udevr zombie guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=3497->guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=4370 clone guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=4393 memfd:udevr zombie guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=3497->guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=4393 clone guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=4394 memfd:udevr zombie guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=3497->guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=4394 clone guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=4395 memfd:udevr zombie guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=3497->guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=4395 clone guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=4396 memfd:udevr zombie guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=3497->guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=4396 clone guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=4416 memfd:udevr zombie guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=3497->guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=4416 clone guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=4417 memfd:udevr zombie guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=3497->guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=4417 clone guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=4418 memfd:udevr zombie guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=3497->guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=4418 clone guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=4419 memfd:udevr zombie guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=3497->guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=4419 clone guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=4441 memfd:udevr zombie guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=3497->guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=4441 clone guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=4442 memfd:udevr zombie guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=3497->guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=4442 clone guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=4443 memfd:udevr zombie guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=3497->guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=4443 clone guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=4444 memfd:udevr zombie guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=3497->guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=4444 clone guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=4474 memfd:udevr zombie guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=3497->guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=4474 clone guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=4475 memfd:udevr zombie guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=3497->guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=4475 clone guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=4477 memfd:udevr zombie guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=3497->guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=4477 clone guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=4478 memfd:udevr zombie guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=3497->guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=4478 clone guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=4517 memfd:udevr zombie guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=3497->guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=4517 clone guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=4518 memfd:udevr zombie guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=3497->guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=4518 clone guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=4519 memfd:udevr zombie guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=3497->guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=4519 clone guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=4520 memfd:udevr zombie guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=3497->guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=4520 clone guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=4539 memfd:udevr zombie guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=3497->guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=4539 clone guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=4540 memfd:udevr zombie guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=3497->guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=4540 clone guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=4541 memfd:udevr zombie guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=3497->guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=4541 clone guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=4543 memfd:udevr zombie guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=3497->guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=4543 clone guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=4555 memfd:udevr zombie guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=3497->guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=4555 clone guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=4556 memfd:udevr zombie guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=3497->guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=4556 clone guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=4557 memfd:udevr zombie guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=3497->guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=4557 clone guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=4558 memfd:udevr zombie guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=3497->guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=4558 clone guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=4572 memfd:udevr zombie guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=3497->guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=4572 clone guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=4573 memfd:udevr zombie guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=3497->guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=4573 clone guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=4574 memfd:udevr zombie guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=3497->guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=4574 clone guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=4575 memfd:udevr zombie guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=3497->guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=4575 clone guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=4598 memfd:udevr zombie guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=3497->guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=4598 clone guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=4599 memfd:udevr zombie guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=3497->guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=4599 clone guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=4600 memfd:udevr zombie guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=3497->guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=4600 clone guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=4601 memfd:udevr zombie guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=3497->guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=4601 clone guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=4639 memfd:udevr zombie guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=3497->guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=4639 clone guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=4640 memfd:udevr zombie guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=3497->guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=4640 clone guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=4641 memfd:udevr zombie guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=3497->guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=4641 clone guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=4642 memfd:udevr zombie guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=3497->guuid=e3809515-1700-0000-177c-bd97a90d0000 pid=4642 clone
Result
Threat name:
n/a
Detection:
malicious
Classification:
troj.evad
Score:
56 / 100
Signature
Executes the "crontab" command typically for achieving persistence
Modifies the '.bashrc' or '.bash_profile' file typically for persisting actions
Sample tries to persist itself using cron
Searches for VM related strings in files or piped streams (probably for evasion)
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1857069 Sample: x6.pdf.elf Startdate: 25/01/2026 Architecture: LINUX Score: 56 113 109.202.202.202, 80 INIT7CH Switzerland 2->113 115 91.189.91.42, 443 CANONICAL-ASGB United Kingdom 2->115 117 2 other IPs or domains 2->117 10 x6.pdf.elf 2->10         started        13 dash rm 2->13         started        15 dash rm 2->15         started        17 python3.8 dpkg 2->17         started        process3 signatures4 127 Modifies the '.bashrc' or '.bash_profile' file typically for persisting actions 10->127 19 x6.pdf.elf 10->19         started        21 x6.pdf.elf sh 10->21         started        23 x6.pdf.elf sh 10->23         started        25 3 other processes 10->25 process5 process6 27 x6.pdf.elf exe exe exe exe exe exe exe exe exe exe exe exe exe exe exe exe exe 19->27         started        31 sh crontab 21->31         started        33 sh 21->33         started        35 sh mkdir 23->35         started        37 sh systemctl 25->37         started        file7 109 /root/.bashrc, ASCII 27->109 dropped 129 Modifies the '.bashrc' or '.bash_profile' file typically for persisting actions 27->129 39 exe sh 27->39         started        41 exe sh 27->41         started        43 exe sh 27->43         started        50 99 other processes 27->50 111 /var/spool/cron/crontabs/tmp.S7jtkv, ASCII 31->111 dropped 131 Sample tries to persist itself using cron 31->131 133 Executes the "crontab" command typically for achieving persistence 31->133 45 sh crontab 33->45         started        48 sh grep 33->48         started        signatures8 process9 signatures10 52 sh crontab 39->52         started        56 sh 39->56         started        58 sh crontab 41->58         started        60 sh 41->60         started        62 sh crontab 43->62         started        64 sh 43->64         started        135 Executes the "crontab" command typically for achieving persistence 45->135 66 sh crontab 50->66         started        68 sh crontab 50->68         started        70 77 other processes 50->70 process11 file12 91 /var/spool/cron/crontabs/tmp.MnuTzv, ASCII 52->91 dropped 119 Sample tries to persist itself using cron 52->119 121 Executes the "crontab" command typically for achieving persistence 52->121 72 sh crontab 56->72         started        75 sh grep 56->75         started        93 /var/spool/cron/crontabs/tmp.j6i7YN, ASCII 58->93 dropped 77 sh crontab 60->77         started        79 sh grep 60->79         started        95 /var/spool/cron/crontabs/tmp.kgMmFS, ASCII 62->95 dropped 81 sh crontab 64->81         started        83 sh grep 64->83         started        97 /var/spool/cron/crontabs/tmp.WwBT09, ASCII 66->97 dropped 99 /var/spool/cron/crontabs/tmp.BCb0yr, ASCII 68->99 dropped 101 /var/spool/cron/crontabs/tmp.s6Vtfj, ASCII 70->101 dropped 103 /var/spool/cron/crontabs/tmp.lgTttK, ASCII 70->103 dropped 105 /var/spool/cron/crontabs/tmp.g46YzY, ASCII 70->105 dropped 107 9 other malicious files 70->107 dropped 123 Searches for VM related strings in files or piped streams (probably for evasion) 70->123 85 sh crontab 70->85         started        87 sh crontab 70->87         started        89 26 other processes 70->89 signatures13 process14 signatures15 125 Executes the "crontab" command typically for achieving persistence 72->125
Result
Malware family:
n/a
Score:
  7/10
Tags:
antivm discovery execution linux persistence privilege_escalation
Behaviour
Enumerates kernel/hardware configuration
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Checks CPU configuration
Reads CPU attributes
Checks hardware identifiers (DMI)
Creates/modifies Cron job
Reads hardware information
Runs EXE from memory
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:linux_generic_ipv6_catcher
Author:@_lubiedo
Description:ELF samples using IPv6 addresses
Rule name:unixredflags3
Author:Tim Brown @timb_machine
Description:Hunts for UNIX red flags

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

elf d1d5dacc6208b6698e7b6ddcab740f9d7a2fb15a106eacc1841a3d2a3824d1dc

(this sample)

  
Delivery method
Distributed via web download

Comments