MB-ce9339d71e87611fe05ac222453c73fa0c1ddcb275b3abe242c38cd5be8b3a83
high
📛 Threat Title
Unknown: sys_users
Description
File type: elf. Size: 832784 bytes. Reporter: adliwahid. First seen: 2026-05-15 13:20:19.
Indicators of Compromise (3)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
hash_md5
b6e74eb45f3a4fd66f98c3fdaf0752e1
1 feed
IOC database
- Type
- hash_md5
- Value
b6e74eb45f3a4fd66f98c3fdaf0752e1- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- Imported from threat-intel feed: Abuse.ch
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_sha1
5d4e3a1eeebd7ce5b6486315d8371ad07f93816d
1 feed
IOC database
- Type
- hash_sha1
- Value
5d4e3a1eeebd7ce5b6486315d8371ad07f93816d- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- Imported from threat-intel feed: Abuse.ch
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_sha256
ce9339d71e87611fe05ac222453c73fa0c1ddcb275b3abe242c38cd5be8b3a83
VT 13 / 75
1 feed
IOC database
- Type
- hash_sha256
- Value
ce9339d71e87611fe05ac222453c73fa0c1ddcb275b3abe242c38cd5be8b3a83- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- Imported from threat-intel feed: Abuse.ch
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →
Flagged by 13 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| alibabacloud | malicious | Suspicious |
| ESET-NOD32 | malicious | Linux/Agent.AZT trojan |
| Fortinet | malicious | Linux/Agent.AZT!tr |
| malicious | Detected |
|
| huorong | malicious | Trojan/Linux.Mirai.ao!crit |
| McAfeeD | malicious | ti!CE9339D71E87 |
| Microsoft | malicious | Trojan:Script/Wacatac.B!ml |
| Rising | malicious | Trojan.Agent/Linux!8.13268 (CLOUD) |
| Skyhigh | malicious | ELF/Agent!B6E74EB45F3A |
| Sophos | malicious | Mal/Generic-S |
| Symantec | malicious | Trojan.Gen.NPE |
| TrendMicro-HouseCall | malicious | Trojan.Linux.Gen.TL0101F326ZY |
| Varist | malicious | E64/ABRisk.IFMF-3 |
Details From VirusTotal
Basic Properties
| MD5 | b6e74eb45f3a4fd66f98c3fdaf0752e1 |
| SHA-1 | 5d4e3a1eeebd7ce5b6486315d8371ad07f93816d |
| SHA-256 | ce9339d71e87611fe05ac222453c73fa0c1ddcb275b3abe242c38cd5be8b3a83 |
| VHash | 54a62dee3dbebdbaa01b9b5101db86eb |
| SSDEEP | 6144:+iCByuT7xh+1kqO+4+bYBIO8jxT1WrwPzd56rY3NdLL8VR7z8vVFFk755ymxUC0K:aX+vxIezb3/L8VR7f5yseYY+ |
| TLSH | T154055A5AB2B3B4E9C553C030039BEB726D39F47902126D7B3281AA353D52EA11F19F67 |
| File type | ELF |
| File type tag | elf |
| Magic | ELF 64-bit LSB executable, x86-64, version 1 (GNU/Linux), statically linked, for GNU/Linux 2.6.24, BuildID[sha1]=505f072c37c529e28ada2352811567ebb6715c93, stripped |
| File size | 813.3 KB |
History
| First seen on VirusTotal | 2026-05-15 13:24 UTC |
| Last submission | 2026-05-15 14:24 UTC |
| Last analysis | 2026-06-03 18:00 UTC |
| Last modified on VirusTotal | 2026-06-03 20:00 UTC |
Known Names
ce9339d71e87611fe05ac222453c73fa0c1ddcb275b3abe242c38cd5be8b3a83.elfsys_users13.71.2.244_sample.bintyxmllmny.execopy
References (1)
-
MalwareBazaar sample page
Abuse.ch
File type: elf. Size: 832784 bytes. Reporter: adliwahid. First seen: 2026-05-15 13:20:19.
Remediations (10)
-
web:github.com
BYOVD research use cases featuring vulnerable driver discovery and reverse engineering methodology. (CVE-2025-52915, CVE-2025-1055,). - BlackSnufkin/BYOVD
-
web:hackyboiz.github.io
After last month's Part 1 introducing Windows Kernel Mitigation , we're back with Part 2, and this time it's time to dive into kCFG bypassing. We'll analyze the Local Privilege Escalation vulnerability CVE-2024-21338 in appid.sys, which was patched in February 2024, and introduce three post-exploitation techniques to bypass kCFG. CVE-2024-21338 - appid.sys Untrusted Pointer Dereference ...
-
web:learn.microsoft.com
Learn how to configure user self- remediation and manually remediate risky users in Microsoft Entra ID Protection.
-
web:scloud.work
When a proactive remediation script fails to work as expected, it's much faster to test it locally than wait for the next sync from Intune. In this post, I'll show you how I troubleshoot Intune remediation scripts directly on a Windows device. This includes script locations, relevant logs, and registry entries that help verify what […]
-
web:windowsforum.com
Microsoft's March cumulative update for Windows 11, KB5079473 (released March 10, 2026), is rolling out with a familiar mix of new features and security fixes — but a growing number of users now say the patch is also triggering severe instability on some machines, including hard freezes...
-
web:www.cisa.gov
The following recommendations and best practices may be helpful during the investigation and remediation process. Note: Although this guidance provides best practices to mitigate common attack vectors, organizations should tailor mitigations to their network. General Mitigation Guidance Restrict or Discontinue Use of FTP and Telnet Services The FTP and Telnet protocols transmit credentials in ...
-
web:www.dell.com
Dell Enterprise Sonic Distribution mitigation is available for multiple security vulnerabilities that could be exploited by malicious users to compromise the affected system.
-
web:www.esd.whs.mil
Ensure configuration, asset, remediation , and mitigation management supports vulnerability management within the DODIN in accordance with DoD Instruction (DoDI) 8510.01. Support all systems, subsystems, and system components owned by or operated on behalf of DoD with efficient vulnerability assessment techniques, procedures, and capabilities.
-
web:www.windowsdigitals.com
Why do I see "Account Unknown " on my computer? You see "Account Unknown " entries when a user account once linked to your files or folders is deleted but the system still has the account's Security Identifier (SID).
-
web:x.com
Fix my PC Store™ (@FIXMYPCSTORE). 824 views. CrowdStrike Falcon Update Residual Issues: Fix Lingering PC Problems in 2026 CROWDSTRIKE FALCON UPDATE RESIDUAL ISSUES: FIX LINGERING PC PROBLEMS IN 2026 TL;DR: The infamous CrowdStrike Falcon update disaster of 2024 is still haunting PCs in 2026. Orphaned kernel drivers, corrupted recovery environments, and remnant sensor files are causing BSODs ...
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.