MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e67a634cb2d96d28e3138a64bd659a3bc0d2640094f825d820bfbb080dca0b12. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: e67a634cb2d96d28e3138a64bd659a3bc0d2640094f825d820bfbb080dca0b12
SHA3-384 hash: 643c8363360a539c2c9c248436748063a35b739280227e7cd33b70674e0fa711830f12534d1afa3818ff9cadbc8d5bbf
SHA1 hash: 320e8b6b18ddd1519cc83839c0521a3e95fcae0b
MD5 hash: b755d8aacf897adcf2a8918940c3ff4a
humanhash: nitrogen-island-uniform-west
File name:skid.mips
Download: download sample
File size:4'498 bytes
First seen:2026-01-03 10:53:02 UTC
Last seen:2026-01-04 08:51:36 UTC
File type: elf
MIME type:application/x-executable
ssdeep 96:G3xBoCUHclW49mrxCPa/2QbgFeQHnAe2Y4DT7j4lSg3+hq9TG:G3HpdlWcsCi/9epHnATD4lY
TLSH T19A915CA0F7B90863D44CF53DF0DA40D9598C5A85A08025EC9D9BAD7AA045F5DF525007
TrID 50.1% (.) ELF Executable and Linkable format (Linux) (4022/12)
49.8% (.O) ELF Executable and Linkable format (generic) (4000/1)
Magika xar
Reporter abuse_ch
Tags:elf

Intelligence


File Origin
# of uploads :
2
# of downloads :
65
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Result
Verdict:
Clean
Maliciousness:
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
masquerade mirai
Verdict:
Unknown
File Type:
elf.32.be
First seen:
2026-01-03T11:16:00Z UTC
Last seen:
2026-01-03T11:26:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=9985e950-1900-0000-cb23-0e326a140000 pid=5226 /usr/bin/sudo guuid=f4366353-1900-0000-cb23-0e326b140000 pid=5227 /tmp/sample.bin guuid=9985e950-1900-0000-cb23-0e326a140000 pid=5226->guuid=f4366353-1900-0000-cb23-0e326b140000 pid=5227 execve
Result
Threat name:
n/a
Detection:
clean
Classification:
n/a
Score:
2 / 100
Behaviour
Behavior Graph:
n/a
Threat name:
Linux.Backdoor.Multiverze
Status:
Malicious
First seen:
2026-01-03 10:53:11 UTC
File Type:
ELF32 Big (Exe)
AV detection:
9 of 24 (37.50%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  5/10
Tags:
discovery upx
Behaviour
System Network Configuration Discovery
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

elf e67a634cb2d96d28e3138a64bd659a3bc0d2640094f825d820bfbb080dca0b12

(this sample)

  
Delivery method
Distributed via web download

Comments