MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 fb213b914b9d1cc262ff99e2c12226fc8e99034d5ed3b3bfaadbcbaf21efa8a7. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 4


Intelligence 4 IOCs YARA 2 File information Comments

SHA256 hash: fb213b914b9d1cc262ff99e2c12226fc8e99034d5ed3b3bfaadbcbaf21efa8a7
SHA3-384 hash: a719171f381277144ebf096d82d3de0802074c7b734e9ef90cbeba3ba92968ace91ae56a4613cf250bb36cd78a33a5ed
SHA1 hash: a3dc9b4030bdfea67112beedd62f494d95bf7874
MD5 hash: d298df01837caa7a692ea4a4ffffc978
humanhash: leopard-three-table-steak
File name:main.mips64-n32
Download: download sample
File size:140'364 bytes
First seen:2026-08-19 14:22:09 UTC
Last seen:Never
File type: elf
MIME type:application/x-executable
ssdeep 1536:oxNRHR8HuAeQ9NZuMYe/1nCFbLJtyKsQxWsx3XmPpjPWgyRFZ3dGrrb:EjAeaNZ11/1CFb1tfseNXmlWD3Ufb
TLSH T1EBD34C37B70AAF63C63D52B50EF2CA39D6E1264119E290856316CF1C6E3529C7C2EDE4
Magika elf
Reporter abuse_ch
Tags:elf

Intelligence


File Origin
# of uploads :
1
# of downloads :
49
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Result
Verdict:
Clean
Maliciousness:
Status:
terminated
Behavior Graph:
%3 guuid=ea8661c8-1b00-0000-6a2e-07b51d070000 pid=1821 /usr/bin/sudo guuid=9df6aecb-1b00-0000-6a2e-07b524070000 pid=1828 /tmp/sample.bin guuid=ea8661c8-1b00-0000-6a2e-07b51d070000 pid=1821->guuid=9df6aecb-1b00-0000-6a2e-07b524070000 pid=1828 execve
Result
Threat name:
n/a
Detection:
malicious
Classification:
n/a
Score:
48 / 100
Signature
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1960484 Sample: main.mips64-n32.elf Startdate: 19/08/2026 Architecture: LINUX Score: 48 36 94.154.43.12, 32, 45608 CDNEXTGB Turkey 2->36 38 daisy.ubuntu.com 2->38 40 Multi AV Scanner detection for submitted file 2->40 12 main.mips64-n32.elf 2->12         started        14 python3.8 dpkg 2->14         started        signatures3 process4 process5 16 main.mips64-n32.elf 12->16         started        process6 18 main.mips64-n32.elf 16->18         started        process7 20 main.mips64-n32.elf bash 18->20         started        22 main.mips64-n32.elf 18->22         started        process8 24 bash lesspipe 20->24         started        26 bash groups 20->26         started        28 bash dircolors 20->28         started        process9 30 lesspipe 24->30         started        32 lesspipe basename 24->32         started        process10 34 lesspipe dirname 30->34         started       
Gathering data
Result
Malware family:
n/a
Score:
  3/10
Tags:
discovery
Behaviour
System Network Configuration Discovery
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:TH_Generic_MassHunt_Linux_Malware_2026_CYFARE
Author:CYFARE
Description:Generic Linux malware mass-hunt rule - 2026
Reference:https://cyfare.net/
Rule name:unixredflags3
Author:Tim Brown @timb_machine
Description:Hunts for UNIX red flags

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

elf fb213b914b9d1cc262ff99e2c12226fc8e99034d5ed3b3bfaadbcbaf21efa8a7

(this sample)

  
Delivery method
Distributed via web download

Comments