MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 fa5c7772f6328ce9c38ca91bee5e8b4fc5fc11c7bee88e076e1e8fab3bb855e9. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Tsunami


Vendor detections: 7


Intelligence 7 IOCs YARA 2 File information Comments

SHA256 hash: fa5c7772f6328ce9c38ca91bee5e8b4fc5fc11c7bee88e076e1e8fab3bb855e9
SHA3-384 hash: 0696a981d9c2719e61632b5061e6c2917ba61df8a27a8c314e3b62de1b416a1a3e47ecdf8a993e4b3a38d43560466cb8
SHA1 hash: f2cee838f1a299a57aabd1321003f77a726957c8
MD5 hash: 771f3441275c80e46bde3c04dbb0a1c0
humanhash: alanine-michigan-december-johnny
File name:pty2
Download: download sample
Signature Tsunami
File size:56'208 bytes
First seen:2026-06-08 13:53:55 UTC
Last seen:Never
File type: elf
MIME type:application/x-executable
ssdeep 768:UXBxiPXDuPmeqnQv0nSfQWqWGNlQezh1iinp7CEYHFrGMSNtaH1EmWk8OgYUqwZY:U2Cme7FfQWzOzDiiNC9GMAMPzrbUbFe
TLSH T17A430299ECEE4D85E27C0DB18136B26E770267027A85FA50BBC5E168253F704D4FD04B
TrID 50.1% (.) ELF Executable and Linkable format (Linux) (4022/12)
49.8% (.O) ELF Executable and Linkable format (generic) (4000/1)
Magika elf
Reporter abuse_ch
Tags:elf Tsunami

Intelligence


File Origin
# of uploads :
1
# of downloads :
52
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Result
Verdict:
Malware
Maliciousness:

Behaviour
Changes access rights for a written file
Locks files
Deleting a recently created file
Connection attempt
Creating a file
Launching a process
Opens a port
DNS request
Changes the time when the file was created, accessed, or modified
Creates or modifies files in /cron to set up autorun
Substitutes an application name
Creates or modifies files to set up autorun
Verdict:
Malicious
File Type:
elf.32.le
First seen:
2026-06-08T11:44:00Z UTC
Last seen:
2026-06-08T23:34:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=0854c89e-1a00-0000-c0df-68eddc0a0000 pid=2780 /usr/bin/sudo guuid=7ede7da1-1a00-0000-c0df-68ede20a0000 pid=2786 /tmp/sample.bin guuid=0854c89e-1a00-0000-c0df-68eddc0a0000 pid=2780->guuid=7ede7da1-1a00-0000-c0df-68ede20a0000 pid=2786 execve
Result
Threat name:
Muhstik, Tsunami
Detection:
malicious
Classification:
troj.evad
Score:
100 / 100
Signature
Executes the "crontab" command typically for achieving persistence
Explicitly modifies time stamps using the "touch" command
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Sample tries to persist itself using cron
Suricata IDS alerts for network traffic
Uses IRC for communication with a C&C
Uses known network protocols on non-standard ports
Writes identical ELF files to multiple locations
Yara detected Muhstik
Yara detected Tsunami
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1924483 Sample: pty2.elf Startdate: 08/06/2026 Architecture: LINUX Score: 100 109 p.shadow-mods.net 94.140.120.193, 59048, 8080 NANO-ASLV Latvia 2->109 111 irc.de-zahlung.eu 2->111 113 3 other IPs or domains 2->113 127 Suricata IDS alerts for network traffic 2->127 129 Malicious sample detected (through community Yara rule) 2->129 131 Multi AV Scanner detection for submitted file 2->131 133 4 other signatures 2->133 11 pty2.elf 2->11         started        13 python3.8 dpkg 2->13         started        signatures3 process4 process5 15 pty2.elf 11->15         started        17 pty2.elf 11->17         started        19 pty2.elf 11->19         started        21 8 other processes 11->21 process6 23 pty2.elf 15->23         started        25 pty2.elf 15->25         started        27 pty2.elf 15->27         started        38 25 other processes 15->38 29 pty2.elf sh 17->29         started        31 pty2.elf sh 19->31         started        33 sh touch 21->33         started        36 pty2.elf sh 21->36         started        40 6 other processes 21->40 signatures7 42 pty2.elf sh 23->42         started        44 pty2.elf sh 25->44         started        46 pty2.elf sh 27->46         started        48 sh crontab 29->48         started        58 4 other processes 29->58 52 sh crontab 31->52         started        115 Explicitly modifies time stamps using the "touch" command 33->115 54 sh uname 36->54         started        56 pty2.elf sh 38->56         started        60 24 other processes 38->60 process8 file9 62 sh crontab 42->62         started        74 4 other processes 42->74 66 sh crontab 44->66         started        76 4 other processes 44->76 68 sh crontab 46->68         started        78 4 other processes 46->78 91 /var/spool/cron/crontabs/tmp.Vy3Ol4, ASCII 48->91 dropped 117 Sample tries to persist itself using cron 48->117 119 Executes the "crontab" command typically for achieving persistence 48->119 70 sh crontab 56->70         started        80 4 other processes 56->80 72 sh crontab 58->72         started        93 /var/tmp/pty2.elf, ELF 60->93 dropped 95 /run/pty2.elf, ELF 60->95 dropped 97 /run/lock/pty2.elf, ELF 60->97 dropped 99 2 other malicious files 60->99 dropped 121 Writes identical ELF files to multiple locations 60->121 123 Explicitly modifies time stamps using the "touch" command 60->123 signatures10 process11 file12 101 /var/spool/cron/crontabs/tmp.3puYMb, ASCII 62->101 dropped 135 Sample tries to persist itself using cron 62->135 137 Executes the "crontab" command typically for achieving persistence 62->137 103 /var/spool/cron/crontabs/tmp.2IfR4K, ASCII 66->103 dropped 105 /var/spool/cron/crontabs/tmp.vVVdrl, ASCII 68->105 dropped 107 /var/spool/cron/crontabs/tmp.m8cSZC, ASCII 70->107 dropped 82 sh crontab 74->82         started        85 sh crontab 76->85         started        87 sh crontab 78->87         started        89 sh crontab 80->89         started        signatures13 process14 signatures15 125 Executes the "crontab" command typically for achieving persistence 82->125
Threat name:
Linux.Trojan.Tsunami
Status:
Malicious
First seen:
2026-06-08 13:54:40 UTC
File Type:
ELF32 Little (Exe)
AV detection:
16 of 24 (66.67%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  6/10
Tags:
defense_evasion discovery execution persistence privilege_escalation
Behaviour
Reads runtime system information
Writes file to shm directory
Writes file to tmp directory
Changes its process name
Indicator Removal: Timestomp
Creates/modifies Cron job
Enumerates running processes
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Linux_Trojan_Tsunami_97288af8
Author:Elastic Security
Rule name:TH_Generic_MassHunt_Linux_Malware_2026_CYFARE
Author:CYFARE
Description:Generic Linux malware mass-hunt rule - 2026
Reference:https://cyfare.net/

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Tsunami

elf fa5c7772f6328ce9c38ca91bee5e8b4fc5fc11c7bee88e076e1e8fab3bb855e9

(this sample)

  
Delivery method
Distributed via web download

Comments