🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d8ad38405aefd6ee641d2296182d3c6eb51fa8c9b802e8586fc3f415fdfec8a9. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA 2 File information Comments

SHA256 hash: d8ad38405aefd6ee641d2296182d3c6eb51fa8c9b802e8586fc3f415fdfec8a9
SHA3-384 hash: 0615f706fa43d0af92833d2adaff280cd03acdad37a0d6dad8eacd59e09e5ba0472506db1403cc8df861a4b5803256c4
SHA1 hash: 5701d320b5bb09d7c3220989695543301752f85c
MD5 hash: 29baac2455b464cd9525b0d8bf978cf8
humanhash: magnesium-oxygen-september-dakota
File name:x86_64
Download: download sample
File size:16'728 bytes
First seen:2026-09-13 16:23:51 UTC
Last seen:Never
File type: elf
MIME type:application/x-executable
ssdeep 384:fSKLVQF90Pxt043pq2du652nUxaVXALp0b+OMe:fXVQP0Pxt043phQ652hb+Ob
TLSH T14672C0E7417AE0B8C137BF326B5911D0EA91EC2561138F9B289063FF7CF59561A20E92
TrID 50.1% (.) ELF Executable and Linkable format (Linux) (4022/12)
49.8% (.O) ELF Executable and Linkable format (generic) (4000/1)
Magika elf
Reporter abuse_ch
Tags:elf UPX
File size (compressed) :16'728 bytes
File size (de-compressed) :26'288 bytes
Format:linux/amd64
Unpacked file: 5ba0603622fdad7ee5253a1e52f3d461888bd8df41f7187575a2731094e0c946

Intelligence


File Origin
# of uploads :
1
# of downloads :
55
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
Uses P2P?:
false
Uses anti-vm?:
false
Architecture:
x86
Packer:
UPX
Botnet:
unknown
Number of open files:
1
Number of processes launched:
4
Processes remaning?
false
Remote TCP ports scanned:
not identified
Behaviour
no suspicious findings
Botnet C2s
TCP botnet C2(s):
not identified
UDP botnet C2(s):
not identified
Status:
terminated
Behavior Graph:
%3 guuid=18b76f4e-1a00-0000-a8e4-783fcb070000 pid=1995 /usr/bin/sudo guuid=2a1c0951-1a00-0000-a8e4-783fce070000 pid=1998 /tmp/sample.bin mprotect-exec guuid=18b76f4e-1a00-0000-a8e4-783fcb070000 pid=1995->guuid=2a1c0951-1a00-0000-a8e4-783fce070000 pid=1998 execve guuid=bf396951-1a00-0000-a8e4-783fd0070000 pid=2000 /tmp/sample.bin zombie guuid=2a1c0951-1a00-0000-a8e4-783fce070000 pid=1998->guuid=bf396951-1a00-0000-a8e4-783fd0070000 pid=2000 clone guuid=33836f51-1a00-0000-a8e4-783fd1070000 pid=2001 /tmp/sample.bin net send-data zombie guuid=bf396951-1a00-0000-a8e4-783fd0070000 pid=2000->guuid=33836f51-1a00-0000-a8e4-783fd1070000 pid=2001 clone 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=33836f51-1a00-0000-a8e4-783fd1070000 pid=2001->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con ce90c105-84ee-5300-a313-29389217557b 2.27.248.149:11121 guuid=33836f51-1a00-0000-a8e4-783fd1070000 pid=2001->ce90c105-84ee-5300-a313-29389217557b send: 10B guuid=6670fa51-1a00-0000-a8e4-783fd2070000 pid=2002 /tmp/sample.bin guuid=33836f51-1a00-0000-a8e4-783fd1070000 pid=2001->guuid=6670fa51-1a00-0000-a8e4-783fd2070000 pid=2002 clone
Result
Threat name:
n/a
Detection:
malicious
Classification:
evad
Score:
60 / 100
Signature
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Sample is packed with UPX
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1972369 Sample: x86_64.elf Startdate: 13/09/2026 Architecture: LINUX Score: 60 19 169.254.169.254, 80 USDOS-USDepartmentofStateUS ZZ 2->19 21 2.27.248.149, 11121, 37710 DEDIK-IODEDIKSERVICESLIMITEDDEDIKIOGB Germany 2->21 23 Malicious sample detected (through community Yara rule) 2->23 25 Multi AV Scanner detection for submitted file 2->25 27 Sample is packed with UPX 2->27 9 x86_64.elf 2->9         started        11 python3.8 dpkg 2->11         started        signatures3 process4 process5 13 x86_64.elf 9->13         started        process6 15 x86_64.elf 13->15         started        process7 17 x86_64.elf 15->17         started       
Result
Malware family:
n/a
Score:
  5/10
Tags:
discovery linux upx
Behaviour
Reads runtime system information
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:TH_Generic_MassHunt_Linux_Malware_2026_CYFARE
Author:CYFARE
Description:Generic Linux malware mass-hunt rule - 2026
Reference:https://cyfare.net/
Rule name:upx_packed_elf_v1
Author:RandomMalware

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

elf d8ad38405aefd6ee641d2296182d3c6eb51fa8c9b802e8586fc3f415fdfec8a9

(this sample)

  
Delivery method
Distributed via web download

Comments