MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e4fae98c77604d952ec2b3d42f83744bb94ece922eef5af44272c5a53be4fa09. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA 2 File information Comments

SHA256 hash: e4fae98c77604d952ec2b3d42f83744bb94ece922eef5af44272c5a53be4fa09
SHA3-384 hash: 52e53aeae84ab94d4d6f763c55be2637b9ef989f5a5df53a339e851f547f5e323c8a79a557fae3bfa8ab2b2387d6b4d5
SHA1 hash: 3de3cd3e9994c9682231b122a298fbbca282a06c
MD5 hash: 4d454002a3ed4d44dcee1c83f329fcec
humanhash: purple-blue-shade-london
File name:bot_linux_x86_64
Download: download sample
File size:3'858'160 bytes
First seen:2026-09-01 16:41:30 UTC
Last seen:Never
File type: elf
MIME type:application/x-executable
ssdeep 98304:XlRqXC3oCfzygFs2Bl8hJaFZ75JW4irf6+AA0YC9SuwZ:XbSC3oC7drqan75E4irf6eXuwZ
TLSH T1200633259DA9C3CA7EC4FF73BEB988ED5198E890C8D4006785EE255BC6F414B30A746C
TrID 50.1% (.) ELF Executable and Linkable format (Linux) (4022/12)
49.8% (.O) ELF Executable and Linkable format (generic) (4000/1)
Magika elf
Reporter BlinkzSec
Tags:UPX
File size (compressed) :3'858'160 bytes
File size (de-compressed) :13'422'776 bytes
Format:linux/amd64
Unpacked file: 8ebd4341557cbc07f22255689f8e0d1332117e17962d5eec8f93329c5399eefb

Intelligence


File Origin
# of uploads :
1
# of downloads :
46
Origin country :
AT AT
Vendor Threat Intelligence
Result
Verdict:
Suspicious
Maliciousness:

Behaviour
Creating a file in the %temp% subdirectories
Receives data from a server
Connection attempt
Collects information on the network activity
Sends data to a server
Collects information on the CPU
Creates directories in a temporary directory
Creating a file
Collects information on the RAM
Creates directories in a subdirectory of a temporary directory
Creates directories
Verdict:
Malicious
Uses P2P?:
false
Uses anti-vm?:
true
Architecture:
x86
Packer:
UPX
Botnet:
unknown
Number of open files:
4
Number of processes launched:
4
Processes remaning?
true
Remote TCP ports scanned:
not identified
Behaviour
Anti-VM
Process Renaming
Botnet C2s
TCP botnet C2(s):
not identified
UDP botnet C2(s):
not identified
Status:
terminated
Behavior Graph:
%3 guuid=3b268980-1a00-0000-f39e-f88b2b080000 pid=2091 /usr/bin/sudo guuid=b5586782-1a00-0000-f39e-f88b31080000 pid=2097 /tmp/sample.bin write-file guuid=3b268980-1a00-0000-f39e-f88b2b080000 pid=2091->guuid=b5586782-1a00-0000-f39e-f88b31080000 pid=2097 execve guuid=b5586782-1a00-0000-f39e-f88b31080000 pid=2261 /tmp/sample.bin guuid=b5586782-1a00-0000-f39e-f88b31080000 pid=2097->guuid=b5586782-1a00-0000-f39e-f88b31080000 pid=2261 clone guuid=b5586782-1a00-0000-f39e-f88b31080000 pid=2262 /tmp/sample.bin net send-data write-file guuid=b5586782-1a00-0000-f39e-f88b31080000 pid=2097->guuid=b5586782-1a00-0000-f39e-f88b31080000 pid=2262 clone guuid=b5586782-1a00-0000-f39e-f88b31080000 pid=2263 /tmp/sample.bin net guuid=b5586782-1a00-0000-f39e-f88b31080000 pid=2097->guuid=b5586782-1a00-0000-f39e-f88b31080000 pid=2263 clone guuid=b5586782-1a00-0000-f39e-f88b31080000 pid=2264 /tmp/sample.bin dns net send-data guuid=b5586782-1a00-0000-f39e-f88b31080000 pid=2097->guuid=b5586782-1a00-0000-f39e-f88b31080000 pid=2264 clone guuid=b5586782-1a00-0000-f39e-f88b31080000 pid=2554 /tmp/sample.bin guuid=b5586782-1a00-0000-f39e-f88b31080000 pid=2097->guuid=b5586782-1a00-0000-f39e-f88b31080000 pid=2554 clone guuid=b5586782-1a00-0000-f39e-f88b31080000 pid=2555 /tmp/sample.bin net guuid=b5586782-1a00-0000-f39e-f88b31080000 pid=2097->guuid=b5586782-1a00-0000-f39e-f88b31080000 pid=2555 clone guuid=b5586782-1a00-0000-f39e-f88b31080000 pid=2557 /tmp/sample.bin net guuid=b5586782-1a00-0000-f39e-f88b31080000 pid=2097->guuid=b5586782-1a00-0000-f39e-f88b31080000 pid=2557 clone 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=b5586782-1a00-0000-f39e-f88b31080000 pid=2262->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 39B b60edd83-de97-543e-8c12-c815cb088ff2 ip-api.com:80 guuid=b5586782-1a00-0000-f39e-f88b31080000 pid=2262->b60edd83-de97-543e-8c12-c815cb088ff2 send: 137B guuid=b5586782-1a00-0000-f39e-f88b31080000 pid=2263->b60edd83-de97-543e-8c12-c815cb088ff2 con guuid=b5586782-1a00-0000-f39e-f88b31080000 pid=2264->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 39B 4152bbe3-358f-5709-8be0-f3318d15beb6 62.60.131.233:443 guuid=b5586782-1a00-0000-f39e-f88b31080000 pid=2264->4152bbe3-358f-5709-8be0-f3318d15beb6 con guuid=b5586782-1a00-0000-f39e-f88b31080000 pid=2555->4152bbe3-358f-5709-8be0-f3318d15beb6 con guuid=b5586782-1a00-0000-f39e-f88b31080000 pid=2557->4152bbe3-358f-5709-8be0-f3318d15beb6 con
Result
Malware family:
n/a
Score:
  6/10
Tags:
antivm discovery execution linux persistence upx
Behaviour
Enumerates kernel/hardware configuration
Reads runtime system information
Writes file to tmp directory
Checks CPU configuration
Creates a desktop entry file
Reads CPU attributes
Reads system network configuration
Looks up external IP address via web service
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:TH_Generic_MassHunt_Linux_Malware_2026_CYFARE
Author:CYFARE
Description:Generic Linux malware mass-hunt rule - 2026
Reference:https://cyfare.net/
Rule name:upx_packed_elf_v1
Author:RandomMalware

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

elf e4fae98c77604d952ec2b3d42f83744bb94ece922eef5af44272c5a53be4fa09

(this sample)

  
Delivery method
Distributed via web download

Comments