Open-source atomic malware analysis

Analyze another

umount_22032026

ELF
Verdict: HOSTILE
Mal-ecule
KO₄(CErAs₂I₂)H₄(Os₂F₂HfCr)Md₂(HeBi₃)
Size 76.9 KB download
First seen 110 days ago
Analyzed 110 days ago
Ecosystem elf_linux

Objectives

hostile severity, 98% confident.
command-and-control/dropper/staging RC4 embedded ELF loader
hostile severity, 97% confident.
evasion/masquerade Trojanized service binary loader
notable severity, 90% confident.
anti-static/obfuscation/payload Encrypted data section (very high)
notable severity, 90% confident.
anti-static/polyglot ELF binary appended to file

Micro-behaviors

suspicious severity, 90% confident.
os/syscall x86-64 raw syscall wrapper
notable severity, 66% confident.
fs/path Reference to key /usr/sbin daemon binaries
notable severity, 66% confident.
fs/proc Read mount info from /proc/self/mountinfo
notable severity, 70% confident.
hardware/block Uses device mapper framework
notable severity, 70% confident.
os/service httpd daemon reference
baseline severity, 100% confident.
process/create Line-based file reading (fgets)

Metadata

suspicious severity, 85% confident.
hardening::no-mitigations ELF lacks key security mitigations (no canary + no NX + no RELRO)
notable severity, 80% confident.
binary Statically linked binary
notable severity, 90% confident.
hardening::nx-disabled NX/DEP disabled (stack is executable)
notable severity, 75% confident.
hardening::static-linked-heuristic ELF lacks dynamic linker sections
baseline severity, 100% confident.
binary/linking ELF program interpreter metadata
baseline severity, 100% confident.
binary::binary-format-checked Binary format is identified
baseline severity, 100% confident.
build ELF GNU build-id note present
baseline severity, 100% confident.
hardening::no-pie Binary is not position-independent (fixed load address)
baseline severity, 100% confident.
unsigned Binary is not digitally signed

binary

notable severity, 90% confident.
embedded Embedded ELF binary at file offset 0xb6e0 (~31968 bytes)

20 of 36 traits shown

Identity

SHA-256 06565a0786425cbc6a28926f30fb69207473690aa538b8d85c71f5df28981781
Filename umount_22032026

Origin

Source harvest
Feed dissect-malware
Ecosystem elf_linux

Timeline

First seen 28 Apr 2026 22:29 UTC
Last analyzed 28 Apr 2026 23:04 UTC
Last updated 28 Apr 2026 23:04 UTC

Labeling

Label bad
Label source harvest
Traits version 8eee0