MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d4071813870a7e1b68e622dc6afc573cc67c937bbd0164873a87dfd1afb96cc0. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Ladvix


Vendor detections: 11


Intelligence 11 IOCs YARA 15 File information Comments

SHA256 hash: d4071813870a7e1b68e622dc6afc573cc67c937bbd0164873a87dfd1afb96cc0
SHA3-384 hash: 562c88036da0719058a7be79d135b28dcfb2f85a98da359e482a2ea75895141d5fef32f2c8f9105071dcc00f460a1eb7
SHA1 hash: e03938c34c36927ad1d5da0de88994dbfd4f65a7
MD5 hash: 999aa1ed98ea2b72671a76af95e8632a
humanhash: december-mississippi-august-arkansas
File name:boss
Download: download sample
Signature Ladvix
File size:2'391'513 bytes
First seen:2026-08-11 14:43:37 UTC
Last seen:2026-08-11 16:52:22 UTC
File type: elf
MIME type:application/x-executable
ssdeep 49152:2/nWnNxAfQ03yTWP9Z/EWQJottSsAd7Mqy:2f4PsAZMb
TLSH T179B57C077CE118AAC0AA93328DB651A27BB2FC490B7123D72E50B3782F727D45E75794
telfhash t1952362416ce71e9a19c61367bc381ad613afe04f086a75296f64c37029eb08c553fb7e
gimphash e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
TrID 50.1% (.) ELF Executable and Linkable format (Linux) (4022/12)
49.8% (.O) ELF Executable and Linkable format (generic) (4000/1)
Magika elf
Reporter abuse_ch
Tags:elf Ladvix

Intelligence


File Origin
# of uploads :
3
# of downloads :
57
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Result
Verdict:
Malware
Maliciousness:

Behaviour
Deletes a file
Removes directories
Receives data from a server
Locks files
Manages services
Launching a process
Sends data to a server
Connection attempt
Changes the time when the file was created, accessed, or modified
Sets a written file as executable
Collects information on the CPU
Creating a file in the %temp% directory
Collects information on the OS
Creating a file
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
base64 bash golang lolbin reconnaissance
Verdict:
Malicious
Uses P2P?:
false
Uses anti-vm?:
false
Architecture:
x86
Packer:
custom
Botnet:
unknown
Number of open files:
10
Number of processes launched:
6
Processes remaning?
true
Remote TCP ports scanned:
not identified
Behaviour
Persistence
Process Renaming
Botnet C2s
TCP botnet C2(s):
not identified
UDP botnet C2(s):
not identified
Verdict:
Malicious
File Type:
elf.64.le
First seen:
2026-08-11T12:55:00Z UTC
Last seen:
2026-08-13T10:15:00Z UTC
Hits:
~100
Status:
terminated
Behavior Graph:
%3 guuid=c5313506-2200-0000-ef41-747f680c0000 pid=3176 /usr/bin/sudo guuid=b6993509-2200-0000-ef41-747f6f0c0000 pid=3183 /tmp/sample.bin guuid=c5313506-2200-0000-ef41-747f680c0000 pid=3176->guuid=b6993509-2200-0000-ef41-747f6f0c0000 pid=3183 execve guuid=b6993509-2200-0000-ef41-747f6f0c0000 pid=3198 /tmp/sample.bin guuid=b6993509-2200-0000-ef41-747f6f0c0000 pid=3183->guuid=b6993509-2200-0000-ef41-747f6f0c0000 pid=3198 clone guuid=b6993509-2200-0000-ef41-747f6f0c0000 pid=3199 /tmp/sample.bin guuid=b6993509-2200-0000-ef41-747f6f0c0000 pid=3183->guuid=b6993509-2200-0000-ef41-747f6f0c0000 pid=3199 clone guuid=b6993509-2200-0000-ef41-747f6f0c0000 pid=3200 /tmp/sample.bin guuid=b6993509-2200-0000-ef41-747f6f0c0000 pid=3183->guuid=b6993509-2200-0000-ef41-747f6f0c0000 pid=3200 clone guuid=b6993509-2200-0000-ef41-747f6f0c0000 pid=3201 /tmp/sample.bin write-config guuid=b6993509-2200-0000-ef41-747f6f0c0000 pid=3183->guuid=b6993509-2200-0000-ef41-747f6f0c0000 pid=3201 clone guuid=d14fe10e-2200-0000-ef41-747f830c0000 pid=3203 /tmp/sample.bin guuid=b6993509-2200-0000-ef41-747f6f0c0000 pid=3183->guuid=d14fe10e-2200-0000-ef41-747f830c0000 pid=3203 clone guuid=b747e60e-2200-0000-ef41-747f840c0000 pid=3204 /usr/bin/uname guuid=b6993509-2200-0000-ef41-747f6f0c0000 pid=3183->guuid=b747e60e-2200-0000-ef41-747f840c0000 pid=3204 execve guuid=b6993509-2200-0000-ef41-747f6f0c0000 pid=3205 /tmp/sample.bin guuid=b6993509-2200-0000-ef41-747f6f0c0000 pid=3183->guuid=b6993509-2200-0000-ef41-747f6f0c0000 pid=3205 clone guuid=596c0e10-2200-0000-ef41-747f880c0000 pid=3208 /usr/bin/chmod guuid=b6993509-2200-0000-ef41-747f6f0c0000 pid=3201->guuid=596c0e10-2200-0000-ef41-747f880c0000 pid=3208 execve guuid=41b6593a-2200-0000-ef41-747fbe0c0000 pid=3262 /usr/bin/systemctl guuid=b6993509-2200-0000-ef41-747f6f0c0000 pid=3201->guuid=41b6593a-2200-0000-ef41-747fbe0c0000 pid=3262 execve guuid=a23af082-2200-0000-ef41-747f5d0d0000 pid=3421 /usr/bin/systemctl guuid=b6993509-2200-0000-ef41-747f6f0c0000 pid=3201->guuid=a23af082-2200-0000-ef41-747f5d0d0000 pid=3421 execve guuid=917a54d6-2200-0000-ef41-747fd30d0000 pid=3539 /usr/bin/systemctl guuid=b6993509-2200-0000-ef41-747f6f0c0000 pid=3201->guuid=917a54d6-2200-0000-ef41-747fd30d0000 pid=3539 execve guuid=dfc74ddd-2200-0000-ef41-747fdf0d0000 pid=3551 /usr/bin/pgrep guuid=b6993509-2200-0000-ef41-747f6f0c0000 pid=3201->guuid=dfc74ddd-2200-0000-ef41-747fdf0d0000 pid=3551 execve guuid=544e10e3-2200-0000-ef41-747ff90d0000 pid=3577 /usr/bin/bash guuid=b6993509-2200-0000-ef41-747f6f0c0000 pid=3201->guuid=544e10e3-2200-0000-ef41-747ff90d0000 pid=3577 execve guuid=223f29e5-2200-0000-ef41-747f020e0000 pid=3586 /usr/bin/bash guuid=b6993509-2200-0000-ef41-747f6f0c0000 pid=3201->guuid=223f29e5-2200-0000-ef41-747f020e0000 pid=3586 execve guuid=7e5ea9e5-2200-0000-ef41-747f030e0000 pid=3587 /usr/bin/rm delete-file guuid=b6993509-2200-0000-ef41-747f6f0c0000 pid=3201->guuid=7e5ea9e5-2200-0000-ef41-747f030e0000 pid=3587 execve guuid=46c30aec-2200-0000-ef41-747f150e0000 pid=3605 /usr/bin/bash zombie guuid=b6993509-2200-0000-ef41-747f6f0c0000 pid=3201->guuid=46c30aec-2200-0000-ef41-747f150e0000 pid=3605 execve guuid=5f36ff10-2200-0000-ef41-747f890c0000 pid=3209 /usr/bin/curl net send-data write-file guuid=596c0e10-2200-0000-ef41-747f880c0000 pid=3208->guuid=5f36ff10-2200-0000-ef41-747f890c0000 pid=3209 execve a633da7e-6415-55fb-93ef-5ee209767fd5 2.57.241.243:80 guuid=5f36ff10-2200-0000-ef41-747f890c0000 pid=3209->a633da7e-6415-55fb-93ef-5ee209767fd5 send: 82B guuid=490f88e3-2200-0000-ef41-747ffa0d0000 pid=3578 /usr/bin/rm delete-file guuid=544e10e3-2200-0000-ef41-747ff90d0000 pid=3577->guuid=490f88e3-2200-0000-ef41-747ffa0d0000 pid=3578 execve guuid=b77715e4-2200-0000-ef41-747ffc0d0000 pid=3580 /usr/bin/rm delete-file guuid=544e10e3-2200-0000-ef41-747ff90d0000 pid=3577->guuid=b77715e4-2200-0000-ef41-747ffc0d0000 pid=3580 execve guuid=feeea3e4-2200-0000-ef41-747ffe0d0000 pid=3582 /usr/bin/rm guuid=544e10e3-2200-0000-ef41-747ff90d0000 pid=3577->guuid=feeea3e4-2200-0000-ef41-747ffe0d0000 pid=3582 execve guuid=430268ed-2200-0000-ef41-747f190e0000 pid=3609 /usr/bin/wget net send-data write-file guuid=46c30aec-2200-0000-ef41-747f150e0000 pid=3605->guuid=430268ed-2200-0000-ef41-747f190e0000 pid=3609 execve guuid=967dc90a-2300-0000-ef41-747f5c0e0000 pid=3676 /usr/bin/chmod guuid=46c30aec-2200-0000-ef41-747f150e0000 pid=3605->guuid=967dc90a-2300-0000-ef41-747f5c0e0000 pid=3676 execve guuid=a0f6400b-2300-0000-ef41-747f5d0e0000 pid=3677 /usr/bin/bash zombie guuid=46c30aec-2200-0000-ef41-747f150e0000 pid=3605->guuid=a0f6400b-2300-0000-ef41-747f5d0e0000 pid=3677 clone 0eae001c-4ad4-599c-ab6a-77d3fac12203 176.65.139.211:80 guuid=430268ed-2200-0000-ef41-747f190e0000 pid=3609->0eae001c-4ad4-599c-ab6a-77d3fac12203 send: 132B guuid=596a8f0b-2300-0000-ef41-747f5f0e0000 pid=3679 /usr/bin/pgrep guuid=a0f6400b-2300-0000-ef41-747f5d0e0000 pid=3677->guuid=596a8f0b-2300-0000-ef41-747f5f0e0000 pid=3679 execve
Result
Threat name:
Ladvix, Xmrig
Detection:
malicious
Classification:
troj.evad.mine
Score:
100 / 100
Signature
Antivirus / Scanner detection for submitted sample
Antivirus detection for dropped file
Deletes system log files
Detected Stratum mining protocol
Drops files in suspicious directories
Executes the "crontab" command typically for achieving persistence
Executes the "iptables" command to insert, remove and/or manipulate rules
Found strings related to Crypto-Mining
Malicious sample detected (through community Yara rule)
Modifies the '.bashrc' or '.bash_profile' file typically for persisting actions
Multi AV Scanner detection for submitted file
Protects files from modification
Sample deletes itself
Sample tries to persist itself using cron
Sample tries to set files in /etc globally writable
Tries to load the MSR kernel module used for reading/writing to CPUs model specific register
Writes to CPU model specific registers (MSR) (e.g. miners improve performance by disabling HW prefetcher)
Yara detected Ladvix
Yara detected Xmrig cryptocurrency miner
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1956058 Sample: boss.elf Startdate: 11/08/2026 Architecture: LINUX Score: 100 97 141.94.96.71 OVHFR France 2->97 99 2.57.241.243, 43582, 43584, 43588 TRUNKNETWORKS-ASSC Singapore 2->99 101 176.65.139.211, 60236, 80 STORMINDUSTRIESHostingServicesUS Netherlands 2->101 105 Malicious sample detected (through community Yara rule) 2->105 107 Antivirus detection for dropped file 2->107 109 Antivirus / Scanner detection for submitted sample 2->109 111 4 other signatures 2->111 11 systemd log 2->11         started        15 boss.elf 2->15         started        17 systemd snapd-env-generator 2->17         started        19 17 other processes 2->19 signatures3 process4 file5 95 /usr/log, ELF 11->95 dropped 135 Sample tries to set files in /etc globally writable 11->135 21 log sh 11->21         started        23 log sh 11->23         started        25 log sh 11->25         started        33 140 other processes 11->33 27 boss.elf bash chmod 15->27         started        29 boss.elf bash 15->29         started        31 boss.elf bash 15->31         started        35 8 other processes 15->35 signatures6 process7 process8 37 sh log 21->37         started        41 sh crontab 23->41         started        43 sh useradd 25->43         started        45 bash curl 27->45         started        51 3 other processes 29->51 53 3 other processes 31->53 47 sh log 33->47         started        49 sh log 33->49         started        55 144 other processes 33->55 file9 83 /usr/bin/foo2hp, ELF 37->83 dropped 85 /tmp/filepJKBCs, ELF 37->85 dropped 113 Sample tries to set files in /etc globally writable 37->113 115 Drops files in suspicious directories 37->115 117 Sample tries to persist itself using cron 37->117 87 /var/spool/cron/crontabs/tmp.RBAkjM, ASCII 41->87 dropped 119 Executes the "crontab" command typically for achieving persistence 41->119 89 /home/systemd/.bashrc, ASCII 43->89 dropped 121 Modifies the '.bashrc' or '.bash_profile' file typically for persisting actions 43->121 57 useradd pam_tally2 43->57         started        70 7 other processes 43->70 91 /usr/bin/log, ELF 45->91 dropped 123 Found strings related to Crypto-Mining 47->123 59 log 47->59         started        62 log iptables 49->62         started        64 log iptables 49->64         started        66 log ip6tables 49->66         started        72 5 other processes 49->72 125 Deletes system log files 51->125 93 /var/tmp/cli, ELF 53->93 dropped 68 bash pgrep 53->68         started        127 Protects files from modification 55->127 129 Sample deletes itself 55->129 74 2 other processes 55->74 signatures10 process11 signatures12 131 Writes to CPU model specific registers (MSR) (e.g. miners improve performance by disabling HW prefetcher) 59->131 76 log sh 59->76         started        133 Executes the "iptables" command to insert, remove and/or manipulate rules 62->133 78 ip6tables modprobe 66->78         started        process13 process14 80 sh modprobe 76->80         started        signatures15 103 Tries to load the MSR kernel module used for reading/writing to CPUs model specific register 80->103
Threat name:
Linux.Trojan.Generic
Status:
Suspicious
First seen:
2026-08-11 14:44:37 UTC
File Type:
ELF64 Little (Exe)
AV detection:
9 of 38 (23.68%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:ladvix defense_evasion discovery infector linux persistence privilege_escalation trojan
Behaviour
Enumerates kernel/hardware configuration
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Reads CPU attributes
Deletes log files
Enumerates running processes
Modifies systemd
Write file to user bin folder
File and Directory Permissions Modification
Family: Ladvix
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:DetectGoMethodSignatures
Author:Wyatt Tauber
Description:Detects Go method signatures in unpacked Go binaries
Rule name:Detect_Go_GOMAXPROCS
Author:Obscurity Labs LLC
Description:Detects Go binaries by the presence of runtime.GOMAXPROCS in the runtime metadata
Rule name:F01_s1ckrule
Author:s1ckb017
Rule name:GoBinTest
Rule name:golang
Rule name:golang_binary_string
Description:Golang strings present
Rule name:golang_duffcopy_amd64
Rule name:Golang_Find_CSC846
Author:Ashar Siddiqui
Description:Find Go Signatuers
Rule name:Golang_Find_CSC846_Simple
Author:Ashar Siddiqui
Description:Find Go Signatuers
Rule name:identity_golang
Author:Eric Yocam
Description:find Golang malware
Rule name:ProgramLanguage_Golang
Author:albertzsigovits
Description:Application written in Golang programming language
Rule name:Suspicious_Golang_Binary
Author:Tim Machac
Description:Triage: Golang-compiled binary with suspicious OS/persistence/network strings (not family-specific)
Rule name:TH_Generic_MassHunt_Linux_Malware_2026_CYFARE
Author:CYFARE
Description:Generic Linux malware mass-hunt rule - 2026
Reference:https://cyfare.net/
Rule name:unixredflags3
Author:Tim Brown @timb_machine
Description:Hunts for UNIX red flags

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Ladvix

elf d4071813870a7e1b68e622dc6afc573cc67c937bbd0164873a87dfd1afb96cc0

(this sample)

  
Delivery method
Distributed via web download

Comments