MB-df77fa417aee26c656609dfb92a3f982dc70077e24de46915bb0360b40bd837a
high
📛 Threat Title
Unknown: df77fa417aee26c656609dfb92a3f982dc70077e24de46915bb0360b40bd837a
Description
File type: elf. Size: 3899392 bytes. Tags: elf, wraith. Reporter: c2hunter. First seen: 2026-05-14 15:50:52.
Indicators of Compromise (3)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
hash_sha256
df77fa417aee26c656609dfb92a3f982dc70077e24de46915bb0360b40bd837a
VT 42 / 75
1 feed
IOC database
- Type
- hash_sha256
- Value
df77fa417aee26c656609dfb92a3f982dc70077e24de46915bb0360b40bd837a- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- Unknown
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →
Flagged by 42 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| AhnLab-V3 | malicious | CoinMiner/Linux.Agent.30304472 |
| alibabacloud | malicious | Trojan:Linux/Sshscan.X |
| ALYac | malicious | Application.Linux.Miner.68 |
| Antiy-AVL | malicious | Trojan/Linux.Multiverze |
| Arcabit | malicious | Application.Linux.Miner.68 |
| Avast | malicious | ELF:Agent-CXA [Trj] |
| AVG | malicious | ELF:Agent-CXA [Trj] |
| Avira | malicious | EXP/ELF.Coinminer.A |
| BitDefender | malicious | Application.Linux.Miner.68 |
| ClamAV | malicious | Unix.Trojan.Coinminer-10007864-0 |
| CTX | malicious | elf.trojan.multiverze |
| Cynet | malicious | Malicious (score: 99) |
| DrWeb | malicious | Linux.Siggen.8622 |
| Elastic | malicious | Linux.Generic.Threat |
| Emsisoft | malicious | Application.Linux.Miner.68 (B) |
| ESET-NOD32 | malicious | Linux/CoinMiner.ABF trojan |
| F-Secure | malicious | Exploit.EXP/ELF.Coinminer.A |
| Fortinet | malicious | Adware/Miner |
| GData | malicious | Application.Linux.Miner.68 |
| malicious | Detected |
|
| huorong | malicious | Trojan/Linux.CoinMiner.ah |
| Ikarus | malicious | Trojan.Linux.Generic |
| Jiangmin | malicious | Trojan.Linux.dsm |
| K7GW | malicious | Trojan ( 0040f1571 ) |
| Kaspersky | malicious | HEUR:Trojan.Linux.Miner.gen |
| Kingsoft | malicious | Linux.Trojan.Miner.gen |
| Lionic | malicious | Trojan.Linux.Multiverze.4!c |
| McAfeeD | malicious | Trojan:Linux/Multiverze.EAB |
| Microsoft | malicious | Trojan:Linux/Multiverze!rfn |
| MicroWorld-eScan | malicious | Application.Linux.Miner.68 |
| Panda | malicious | ELF/TrojanGen.A |
| Rising | malicious | HackTool.NBMiner/Linux!1.E357 (CLASSIC) |
| SentinelOne | malicious | Static AI - Suspicious ELF |
| Sophos | malicious | Generic Reputation PUA (PUA) |
| Symantec | malicious | Trojan.Gen.NPE |
| Tencent | malicious | Risktool.Linux.Miner.ck |
| TrendMicro | malicious | TROJ_GEN.R002C0DE926 |
| TrendMicro-HouseCall | malicious | TROJ_GEN.R002C0DE926 |
| Varist | malicious | E64/ABRisk.TWOJ-8 |
| VBA32 | malicious | Trojan.Linux.Agent |
| VIPRE | malicious | Application.Linux.Miner.68 |
| Zillya | malicious | Trojan.252279.Linux.1 |
Details From VirusTotal
Basic Properties
| MD5 | bc82bd5bf53539ec839ec38c5481df02 |
| SHA-1 | 5a4c776e54db8e959ccd2f5a57c3b31782ec3899 |
| SHA-256 | df77fa417aee26c656609dfb92a3f982dc70077e24de46915bb0360b40bd837a |
| VHash | f9be67d2dc44f42d7291f61515380330 |
| SSDEEP | 49152:c8nxDgC7g9rb/TBvO90dL3BmAFd4A64nsfJ7QQzjFHWkMNRCdQqzB0dSyG2VjMQv:cqYUQuVDt0TZEQ |
| TLSH | T17A060873E59441E4C1EED174C625A213BEE0389B173423D77BE1A6E11B76FE46AB8320 |
| File type | ELF |
| File type tag | elf |
| Magic | ELF 64-bit LSB executable, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/ld-linux-x86-64.so.2, missing section headers at jd |
| File size | 3.7 MB |
History
| First seen on VirusTotal | 2024-06-24 07:12 UTC |
| Last submission | 2026-05-09 19:55 UTC |
| Last analysis | 2026-05-16 20:09 UTC |
| Last modified on VirusTotal | 2026-05-16 22:10 UTC |
Known Names
20251224-172923_sftp__root__9086614530093524940_sshddf77fa417aee26c656609dfb92a3f982dc70077e24de46915bb0360b40bd837a20251204-035929_sftp__root__2294925276888378699_sshd20241220-154256_sftp__root__7943207372659807273_sshd20241208-151931_sftp__root__2038388120944801955_sshd20240811-031945_sftp__root__147354133388462907_sshdbc82bd5bf53539ec839ec38c5481df02
hash_sha1
5a4c776e54db8e959ccd2f5a57c3b31782ec3899
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/5a4c776e54db8e959ccd2f5a57c3b31782ec3899
2 feeds
IOC database
- Type
- hash_sha1
- Value
5a4c776e54db8e959ccd2f5a57c3b31782ec3899- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
Threat Hunt — feed corroboration
Listed by 2 threat-intel feed vendors: Abuse.ch, threatview.io. Open in Threat Hunt →
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/5a4c776e54db8e959ccd2f5a57c3b31782ec3899
hash_md5
bc82bd5bf53539ec839ec38c5481df02
VT 42 / 75
2 feeds
IOC database
- Type
- hash_md5
- Value
bc82bd5bf53539ec839ec38c5481df02- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
Threat Hunt — feed corroboration
Listed by 2 threat-intel feed vendors: Abuse.ch, threatview.io. Open in Threat Hunt →
Flagged by 42 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| AhnLab-V3 | malicious | CoinMiner/Linux.Agent.30304472 |
| alibabacloud | malicious | Trojan:Linux/Sshscan.X |
| ALYac | malicious | Application.Linux.Miner.68 |
| Antiy-AVL | malicious | Trojan/Linux.Multiverze |
| Arcabit | malicious | Application.Linux.Miner.68 |
| Avast | malicious | ELF:Agent-CXA [Trj] |
| AVG | malicious | ELF:Agent-CXA [Trj] |
| Avira | malicious | EXP/ELF.Coinminer.A |
| BitDefender | malicious | Application.Linux.Miner.68 |
| ClamAV | malicious | Unix.Trojan.Coinminer-10007864-0 |
| CTX | malicious | elf.trojan.multiverze |
| Cynet | malicious | Malicious (score: 99) |
| DrWeb | malicious | Linux.Siggen.8622 |
| Elastic | malicious | Linux.Generic.Threat |
| Emsisoft | malicious | Application.Linux.Miner.68 (B) |
| ESET-NOD32 | malicious | Linux/CoinMiner.ABF trojan |
| F-Secure | malicious | Exploit.EXP/ELF.Coinminer.A |
| Fortinet | malicious | Adware/Miner |
| GData | malicious | Application.Linux.Miner.68 |
| malicious | Detected |
|
| huorong | malicious | Trojan/Linux.CoinMiner.ah |
| Ikarus | malicious | Trojan.Linux.Generic |
| Jiangmin | malicious | Trojan.Linux.dsm |
| K7GW | malicious | Trojan ( 0040f1571 ) |
| Kaspersky | malicious | HEUR:Trojan.Linux.Miner.gen |
| Kingsoft | malicious | Linux.Trojan.Miner.gen |
| Lionic | malicious | Trojan.Linux.Multiverze.4!c |
| McAfeeD | malicious | Trojan:Linux/Multiverze.EAB |
| Microsoft | malicious | Trojan:Linux/Multiverze!rfn |
| MicroWorld-eScan | malicious | Application.Linux.Miner.68 |
| Panda | malicious | ELF/TrojanGen.A |
| Rising | malicious | HackTool.NBMiner/Linux!1.E357 (CLASSIC) |
| SentinelOne | malicious | Static AI - Suspicious ELF |
| Sophos | malicious | Generic Reputation PUA (PUA) |
| Symantec | malicious | Trojan.Gen.NPE |
| Tencent | malicious | Risktool.Linux.Miner.ck |
| TrendMicro | malicious | TROJ_GEN.R002C0DE926 |
| TrendMicro-HouseCall | malicious | TROJ_GEN.R002C0DE926 |
| Varist | malicious | E64/ABRisk.TWOJ-8 |
| VBA32 | malicious | Trojan.Linux.Agent |
| VIPRE | malicious | Application.Linux.Miner.68 |
| Zillya | malicious | Trojan.252279.Linux.1 |
Details From VirusTotal
Basic Properties
| MD5 | bc82bd5bf53539ec839ec38c5481df02 |
| SHA-1 | 5a4c776e54db8e959ccd2f5a57c3b31782ec3899 |
| SHA-256 | df77fa417aee26c656609dfb92a3f982dc70077e24de46915bb0360b40bd837a |
| VHash | f9be67d2dc44f42d7291f61515380330 |
| SSDEEP | 49152:c8nxDgC7g9rb/TBvO90dL3BmAFd4A64nsfJ7QQzjFHWkMNRCdQqzB0dSyG2VjMQv:cqYUQuVDt0TZEQ |
| TLSH | T17A060873E59441E4C1EED174C625A213BEE0389B173423D77BE1A6E11B76FE46AB8320 |
| File type | ELF |
| File type tag | elf |
| Magic | ELF 64-bit LSB executable, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/ld-linux-x86-64.so.2, missing section headers at jd |
| File size | 3.7 MB |
History
| First seen on VirusTotal | 2024-06-24 07:12 UTC |
| Last submission | 2026-05-09 19:55 UTC |
| Last analysis | 2026-05-16 20:09 UTC |
| Last modified on VirusTotal | 2026-05-16 22:10 UTC |
Known Names
20251224-172923_sftp__root__9086614530093524940_sshddf77fa417aee26c656609dfb92a3f982dc70077e24de46915bb0360b40bd837a20251204-035929_sftp__root__2294925276888378699_sshd20241220-154256_sftp__root__7943207372659807273_sshd20241208-151931_sftp__root__2038388120944801955_sshd20240811-031945_sftp__root__147354133388462907_sshdbc82bd5bf53539ec839ec38c5481df02
References (1)
-
MalwareBazaar sample page
Abuse.ch
File type: elf. Size: 3899392 bytes. Tags: elf, wraith. Reporter: c2hunter. First seen: 2026-05-14 15:50:52.
Remediations (9)
-
web:askubuntu.com
9 Update: Kernel 6.8.-117.117 is released now and features a kernel-level fix for CVE-2026-31431. While the website may be down, the security email list continues to work apparently and they have emailed about a mitigation there in an email from 30.04.2026 18:06 CET. The issue should be mitigated for now thanks to USN-8226-1 and USN-8226-2.
-
web:techcommunity.microsoft.com
After some time, this is replaced by 0x87D127DB (" Unknown "). I have purchased new apps via Apple Business Manager, successfully synced them to Intune, and assigned them to test devices — but unfortunately, the apps are not being installed.
-
web:www.bitrecover.com
The archive is either in unknown format or damaged fix using different techniques. Get step-by-step instructions and best ways to resolve it.
-
web:www.blackhillsinfosec.com
In PART ONE and PART TWO of this blog series, we discussed common misconfigurations of Active Directory certificate templates. In this post, we will walk through exploitation of the Web Enrollment feature. Active Directory Certificate Services (ADCS) supports HTTP-based enrollment methods. If enabled, HTTP-based certificate enrollment interfaces can be vulnerable to NTLM relay attacks. If an ...
-
web:www.minitool.com
How to open unknown file extensions in Windows? This article will mainly resolve this issue and help you protect your data.
-
web:www.reddit.com
If you don't have the in house staff to perform the threat analysis or threat hunting, you need a SOC. You could look at black point cyber since your are a PAX 8 customer. You currently have the detection portion of EDR, but not the analysis and remediation piece. You can't compare Symantec to Sentinel One, they aren't the same. Sentinel One IMO, is a far superior product, and in the years we ...
-
web:www.thewindowsclub.com
Get a more generic solution to identifying unknown or unrecognized file types & extensions with these free tools for Windows 11/10 computer.
-
web:www.toolsley.com
Free browser tool to identify unknown files based on their contents. Recognizes over 2000 file formats using libmagic. No installation necessary. Just drag & drop!
-
web:www.youtube.com
There have been reports by users where they are encountering the error message "The archive is either in unknown format or Damaged" when they try to open a ZIP or RAR archived file downloaded ...
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.