MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 da92fef44bc35bd1da5e8d6390ebd4619a2fec5986ca1e80f353923a41ad60df. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: da92fef44bc35bd1da5e8d6390ebd4619a2fec5986ca1e80f353923a41ad60df
SHA3-384 hash: fe4057522caa9a6e1d16e554fb2a27ff0b6478e6263e6455edb636b2d69fb31815eab376278a78025a8699daf3d8e72d
SHA1 hash: 5b594d9fa8a65dbf6b031073dfc4c994db0fb75d
MD5 hash: 3e142777c501640d348af38d7f318765
humanhash: equal-one-spring-hawaii
File name:pam_backdoor.so
Download: download sample
File size:13'800 bytes
First seen:2026-07-30 14:47:41 UTC
Last seen:Never
File type: elf
MIME type:application/x-sharedlib
ssdeep 24:RdkGonHaQNIuc/Gu3A74xwkCQEga/tSLszcqtz+XX:RdkGonHaQNU/Gd8C4a/tkn
TLSH T14652CB17ABE08E6ACD2C137D51DF43B563F6EC654BF75327264156200C8338D0F65A99
telfhash t122900401cd5d0711c3440d31775f054003d74d7c30d5fd0dc4001500340454cc75cc53
TrID 50.1% (.) ELF Executable and Linkable format (Linux) (4022/12)
49.8% (.O) ELF Executable and Linkable format (generic) (4000/1)
Magika elf
Reporter smica83
Tags:backdoor elf PAM

Intelligence


File Origin
# of uploads :
1
# of downloads :
80
Origin country :
HU HU
Vendor Threat Intelligence
No detections
Result
Verdict:
Clean
Maliciousness:
Verdict:
Unknown
Threat level:
  2.5/10
Confidence:
100%
Tags:
gcc masquerade
Verdict:
Malicious
Uses P2P?:
false
Uses anti-vm?:
false
Architecture:
x86
Packer:
not packed
Botnet:
unknown
Number of open files:
0
Number of processes launched:
1
Processes remaning?
false
Remote TCP ports scanned:
not identified
Behaviour
no suspicious findings
Botnet C2s
TCP botnet C2(s):
not identified
UDP botnet C2(s):
not identified
Verdict:
Malicious
File Type:
elf.64.le
First seen:
2026-08-01T07:06:00Z UTC
Last seen:
2026-08-01T13:05:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=b8e2a21a-1c00-0000-39f5-cc1de9090000 pid=2537 /usr/bin/sudo guuid=7a4de71c-1c00-0000-39f5-cc1def090000 pid=2543 /tmp/sample.bin guuid=b8e2a21a-1c00-0000-39f5-cc1de9090000 pid=2537->guuid=7a4de71c-1c00-0000-39f5-cc1def090000 pid=2543 execve
Result
Threat name:
n/a
Detection:
clean
Classification:
n/a
Score:
0 / 100
Behaviour
Behavior Graph:
n/a
Result
Malware family:
n/a
Score:
  1/10
Tags:
linux
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments