MB-5fd226531f4cdf51e5e108aa61815816b5ede3f922da8a6148a849bbed1e5eca
high
📛 Threat Title
Unknown: 5fd226531f4cdf51e5e108aa61815816b5ede3f922da8a6148a849bbed1e5eca
Description
File type: elf. Size: 294912 bytes. Reporter: Hassan_Pouladi. First seen: 2026-05-15 06:50:04.
Indicators of Compromise (3)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
hash_sha256
5fd226531f4cdf51e5e108aa61815816b5ede3f922da8a6148a849bbed1e5eca
VT 22 / 75
1 feed
IOC database
- Type
- hash_sha256
- Value
5fd226531f4cdf51e5e108aa61815816b5ede3f922da8a6148a849bbed1e5eca- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- Unknown
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →
Flagged by 22 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| alibabacloud | malicious | Trojan |
| ALYac | malicious | Trojan.Linux.GenericKD.67307 |
| Antiy-AVL | malicious | Trojan/Linux.Multiverze |
| Arcabit | malicious | Trojan.Linux.Generic.D106EB |
| BitDefender | malicious | Trojan.Linux.GenericKD.67307 |
| CTX | malicious | elf.trojan.multiverze |
| DrWeb | malicious | Linux.Packed.2127 |
| Emsisoft | malicious | Trojan.Linux.GenericKD.67307 (B) |
| Fortinet | malicious | PossibleThreat |
| GData | malicious | Trojan.Linux.GenericKD.67307 |
| malicious | Detected |
|
| Ikarus | malicious | Trojan.Linux.Multiverze |
| Lionic | malicious | Trojan.Linux.Multiverze.4!c |
| McAfeeD | malicious | ti!5FD226531F4C |
| Microsoft | malicious | Trojan:Linux/Multiverze!rfn |
| MicroWorld-eScan | malicious | Trojan.Linux.GenericKD.67307 |
| Sophos | malicious | Mal/Generic-S |
| Symantec | malicious | Trojan.Gen.NPE |
| TrendMicro | malicious | Trojan.Win32.ZYX.USBLE726 |
| TrendMicro-HouseCall | malicious | Trojan.Win32.ZYX.USBLE726 |
| Varist | malicious | E64/ABTrojan.GLNS- |
| VIPRE | malicious | Trojan.Linux.GenericKD.67307 |
Details From VirusTotal
Basic Properties
| MD5 | ad9b64794d09aeb0451d0a9cf5c04921 |
| SHA-1 | c1d765d22d455a6a3b7d4f1af38d5591d5cefb01 |
| SHA-256 | 5fd226531f4cdf51e5e108aa61815816b5ede3f922da8a6148a849bbed1e5eca |
| VHash | b88755125b79714d2f79ba4b4de2c124 |
| SSDEEP | 6144:4Fq3qYcWvV7ljfTkYvzuzhokcfFJidztRASUFYvdDPA0xeokj7G1ty:Cq3fzffTItBUXwVdDPOjS1ty |
| TLSH | T1825423103BB43AB5C3B46CFE04CCFACC9D948A29981D6DE3DA6090F51A851471EDBDAC |
| File type | ELF |
| File type tag | elf |
| Magic | ELF 64-bit LSB executable, ARM aarch64, version 1 (SYSV), statically linked, no section header |
| File size | 288.0 KB |
History
| First seen on VirusTotal | 2026-01-15 16:21 UTC |
| Last submission | 2026-05-16 22:22 UTC |
| Last analysis | 2026-05-18 05:41 UTC |
| Last modified on VirusTotal | 2026-05-18 07:45 UTC |
Known Names
5fd226531f4cdf51e5e108aa61815816b5ede3f922da8a6148a849bbed1e5eca.elf_5fd226531f4cdf51e5e108aa61815816b5ede3f922da8a6148a849bbed1e5eca.elfhnbbc.exeep1a7.exem99jm.exe
hash_sha1
c1d765d22d455a6a3b7d4f1af38d5591d5cefb01
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/c1d765d22d455a6a3b7d4f1af38d5591d5cefb01
1 feed
IOC database
- Type
- hash_sha1
- Value
c1d765d22d455a6a3b7d4f1af38d5591d5cefb01- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/c1d765d22d455a6a3b7d4f1af38d5591d5cefb01
hash_md5
ad9b64794d09aeb0451d0a9cf5c04921
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/ad9b64794d09aeb0451d0a9cf5c04921
1 feed
IOC database
- Type
- hash_md5
- Value
ad9b64794d09aeb0451d0a9cf5c04921- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/ad9b64794d09aeb0451d0a9cf5c04921
References (1)
-
MalwareBazaar sample page
Abuse.ch
File type: elf. Size: 294912 bytes. Reporter: Hassan_Pouladi. First seen: 2026-05-15 06:50:04.
Remediations (10)
-
web:askubuntu.com
9 Update: Kernel 6.8.-117.117 is released now and features a kernel-level fix for CVE-2026-31431. While the website may be down, the security email list continues to work apparently and they have emailed about a mitigation there in an email from 30.04.2026 18:06 CET. The issue should be mitigated for now thanks to USN-8226-1 and USN-8226-2.
-
web:maclookup.app
Fast and easy MAC address lookup on IEEE directory and Wireshark manufacturer database. Search vendor, manufacturer or organization of a device by MAC/OUI address. Fast REST API
-
web:tools.iplocation.net
A MAC address is known as the Ethernet hardware address, and it is comprised of 6-bytes. An unique MAC address is assigned to a Network Interface Card (NIC) to communicate with other devices in a network. IEEE is the authority managing MAC Addresses, and each hardware manufacturers must register with IEEE to allocate the MAC Prefix to be used by the vendor. By examining the first few bytes of ...
-
web:windowsforum.com
Microsoft's Security Update Guide is the canonical place to verify which specific Windows builds and KBs include the fix for CVE-2025-53803; the general remediation pattern for kernel information-disclosure CVEs is: vendor advisory → cumulative update or security-only KB → distribution via Windows Update/WSUS and the Microsoft Update Catalog.
-
web:woshub.com
After a clean installation or reinstalling Windows, many unknown devices may appear in Device Manager. This article explains how to identify unknown devices in Windows, find the latest up-to-date drivers,…
-
web:www.epa.gov
Learn about the health effects of lead, who is at risk, how to test for lead in paint or other areas of your home, how to find or become a lead-safe certified firm, and more about the Lead Renovation Repair and Painting (RRP) rule.
-
web:www.esd.whs.mil
Ensure configuration, asset, remediation , and mitigation management supports vulnerability management within the DODIN in accordance with DoD Instruction (DoDI) 8510.01. Support all systems, subsystems, and system components owned by or operated on behalf of DoD with efficient vulnerability assessment techniques, procedures, and capabilities.
-
web:www.macaddresslookup.org
Enter a MAC address (or OUI) to lookup the device manufacturer, including city, state and zip code. Search across a public database of 30,000+ vendors!
-
web:www.meridianoutpost.com
Identify the vendor of your network devices! Find the company that manufactured a network card with this MAC address (OUI) lookup tool.
-
web:www.whatsmyip.org
MAC Address Lookups, search by full address, OUI prefix or by vendor name. Database updated daily.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.