MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f60e4a7e84732d37a9bcc3d57e985dd6e27bda062ae978e3531b109d7ed2dc72. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA 5 File information Comments

SHA256 hash: f60e4a7e84732d37a9bcc3d57e985dd6e27bda062ae978e3531b109d7ed2dc72
SHA3-384 hash: 1d17c0647090f3d57b8444e14c59a1e8e7921f96a8563aebed23f94435f5936aad6acae34a14a513ba8ddc9e957f54bc
SHA1 hash: 0d813b79846e27a960042e0c302aca85258e4c5c
MD5 hash: 4d8bb9f094fdbd6d79da3ec22d8099ed
humanhash: carolina-jupiter-butter-sink
File name:cloud
Download: download sample
File size:4'312'978 bytes
First seen:2026-01-05 19:36:52 UTC
Last seen:Never
File type: elf
MIME type:application/x-executable
ssdeep 98304:m68fgJsvjKnz0KV3kgFq+CZShee/ZcITk9GP4CfQXBTjlHo+JmsN0Xk0H540z1P0:ySu40Kw+ht/Zcr9dCf0lHtkXkT0z1P0
TLSH T1511633C6044462A13A57EB31A266F9C0371E7A6B4E6CF0604E1AC9DD043CEF2DBD6BD5
TrID 50.1% (.) ELF Executable and Linkable format (Linux) (4022/12)
49.8% (.O) ELF Executable and Linkable format (generic) (4000/1)
Magika elf
Reporter cydave
Tags:elf


Avatar
cydave
Delivered via docker engine api request:

6:48PM INF
PUT /v1.41/containers/qc4geg9zic3u/archive?noOverwriteDirNonDir=true&path=%2Fusr%2Fbin%2F HTTP/1.1
Host: *:2375
Transfer-Encoding: chunked
Content-Type: text/plain
User-Agent: Docker-Client/20.10.21 (linux)

41d600
cloud00000000000000000000...

remote_ip=183.81.72.167 uri=/v1.41/containers/qc4geg9zic3u/archive?noOverwriteDirNonDir=true&path=%2Fusr%2Fbin%2F method=PUT referer= status=200 tags=[] user_agent="Docker-Client/20.10.21 (linux)"

Intelligence


File Origin
# of uploads :
1
# of downloads :
54
Origin country :
CH CH
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Connection attempt
Sends data to a server
Creates directories
Creating a file in the %temp% directory
Receives data from a server
DNS request
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
coinminer packed packed upx
Verdict:
Unknown
File Type:
elf.64.le
First seen:
2026-01-05T18:58:00Z UTC
Last seen:
2026-01-05T19:14:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=a9f993bd-1800-0000-2010-6598760e0000 pid=3702 /usr/bin/sudo guuid=3c8130bf-1800-0000-2010-65987c0e0000 pid=3708 /tmp/sample.bin mprotect-exec guuid=a9f993bd-1800-0000-2010-6598760e0000 pid=3702->guuid=3c8130bf-1800-0000-2010-65987c0e0000 pid=3708 execve guuid=3c8130bf-1800-0000-2010-65987c0e0000 pid=3803 /tmp/sample.bin guuid=3c8130bf-1800-0000-2010-65987c0e0000 pid=3708->guuid=3c8130bf-1800-0000-2010-65987c0e0000 pid=3803 clone guuid=3c8130bf-1800-0000-2010-65987c0e0000 pid=3804 /tmp/sample.bin dns net send-data guuid=3c8130bf-1800-0000-2010-65987c0e0000 pid=3708->guuid=3c8130bf-1800-0000-2010-65987c0e0000 pid=3804 clone guuid=3c8130bf-1800-0000-2010-65987c0e0000 pid=3805 /tmp/sample.bin dns net send-data guuid=3c8130bf-1800-0000-2010-65987c0e0000 pid=3708->guuid=3c8130bf-1800-0000-2010-65987c0e0000 pid=3805 clone guuid=3c8130bf-1800-0000-2010-65987c0e0000 pid=3816 /tmp/sample.bin guuid=3c8130bf-1800-0000-2010-65987c0e0000 pid=3708->guuid=3c8130bf-1800-0000-2010-65987c0e0000 pid=3816 clone guuid=3c8130bf-1800-0000-2010-65987c0e0000 pid=3858 /tmp/sample.bin dns net send-data guuid=3c8130bf-1800-0000-2010-65987c0e0000 pid=3708->guuid=3c8130bf-1800-0000-2010-65987c0e0000 pid=3858 clone guuid=3c8130bf-1800-0000-2010-65987c0e0000 pid=3860 /tmp/sample.bin guuid=3c8130bf-1800-0000-2010-65987c0e0000 pid=3708->guuid=3c8130bf-1800-0000-2010-65987c0e0000 pid=3860 clone guuid=3c8130bf-1800-0000-2010-65987c0e0000 pid=3881 /tmp/sample.bin dns guuid=3c8130bf-1800-0000-2010-65987c0e0000 pid=3708->guuid=3c8130bf-1800-0000-2010-65987c0e0000 pid=3881 clone guuid=3c8130bf-1800-0000-2010-65987c0e0000 pid=4733 /tmp/sample.bin guuid=3c8130bf-1800-0000-2010-65987c0e0000 pid=3708->guuid=3c8130bf-1800-0000-2010-65987c0e0000 pid=4733 clone guuid=3c8130bf-1800-0000-2010-65987c0e0000 pid=4734 /tmp/sample.bin guuid=3c8130bf-1800-0000-2010-65987c0e0000 pid=3708->guuid=3c8130bf-1800-0000-2010-65987c0e0000 pid=4734 clone guuid=3c8130bf-1800-0000-2010-65987c0e0000 pid=4735 /tmp/sample.bin guuid=3c8130bf-1800-0000-2010-65987c0e0000 pid=3708->guuid=3c8130bf-1800-0000-2010-65987c0e0000 pid=4735 clone guuid=3c8130bf-1800-0000-2010-65987c0e0000 pid=4747 /tmp/sample.bin guuid=3c8130bf-1800-0000-2010-65987c0e0000 pid=3708->guuid=3c8130bf-1800-0000-2010-65987c0e0000 pid=4747 clone fecc0d18-7ab7-560c-ac36-35b136bafc26 64.6.64.6:53 guuid=3c8130bf-1800-0000-2010-65987c0e0000 pid=3804->fecc0d18-7ab7-560c-ac36-35b136bafc26 send: 90B guuid=3c8130bf-1800-0000-2010-65987c0e0000 pid=3805->fecc0d18-7ab7-560c-ac36-35b136bafc26 send: 135B c493a42f-c32a-53cc-b7d2-5f4949c52772 dero-node-ch4k1pu.mysrv.cloud:10300 guuid=3c8130bf-1800-0000-2010-65987c0e0000 pid=3805->c493a42f-c32a-53cc-b7d2-5f4949c52772 send: 177B guuid=3c8130bf-1800-0000-2010-65987c0e0000 pid=3858->fecc0d18-7ab7-560c-ac36-35b136bafc26 send: 45B guuid=3c8130bf-1800-0000-2010-65987c0e0000 pid=3858->c493a42f-c32a-53cc-b7d2-5f4949c52772 send: 588B
Threat name:
Linux.Trojan.Generic
Status:
Suspicious
First seen:
2026-01-05 19:37:16 UTC
File Type:
ELF64 Little (Exe)
AV detection:
8 of 24 (33.33%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
discovery linux upx
Behaviour
Enumerates kernel/hardware configuration
Reads runtime system information
Writes file to tmp directory
Unexpected DNS network traffic destination
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:GoBinTest
Rule name:golang_binary_string
Description:Golang strings present
Rule name:ProgramLanguage_Golang
Author:albertzsigovits
Description:Application written in Golang programming language
Rule name:SHA512_Constants
Author:phoul (@phoul)
Description:Look for SHA384/SHA512 constants
Rule name:upx_packed_elf_v1
Author:RandomMalware

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments