Open-source atomic malware analysis

Analyze another

httpd.26

ELF
Verdict: HOSTILE
Mal-ecule
KO₅(C₂ErAs₄CaI)H₄(Os₂CmCrDb₂)Md₃(HeBi₃Pa)
Size 599.8 KB download unavailable
First seen 109 days ago
Analyzed 109 days ago
Ecosystem elf_linux

Objectives

hostile severity, 98% confident.
command-and-control/dropper/staging RC4 embedded ELF loader
hostile severity, 97% confident.
evasion/masquerade Trojanized service binary loader
suspicious severity, 95% confident.
credential-access/capture BIG-IP Apache auth interception
notable severity, 90% confident.
anti-static/obfuscation/payload Encrypted data section (very high)
notable severity, 90% confident.
anti-static/polyglot ELF binary appended to file

Micro-behaviors

suspicious severity, 90% confident.
os/syscall x86 int80 syscall wrapper
notable severity, 78% confident.
communications Hardcoded loopback IPv4 address
notable severity, 80% confident.
os/group Resolve group name to GID (getgrnam)
notable severity, 70% confident.
os/service httpd daemon reference
notable severity, 70% confident.
process/fd freopen stream redirection import
baseline severity, 100% confident.
fs/path /dev/null (legitimate discard device)

Metadata

suspicious severity, 85% confident.
hardening::no-mitigations ELF lacks key security mitigations (no canary + no NX + no RELRO)
notable severity, 80% confident.
binary Statically linked binary
notable severity, 90% confident.
hardening::nx-disabled NX/DEP disabled (stack is executable)
notable severity, 75% confident.
hardening::static-linked-heuristic ELF lacks dynamic linker sections
baseline severity, 100% confident.
binary/linking ELF program interpreter metadata
baseline severity, 100% confident.
binary::binary-format-checked Binary format is identified
baseline severity, 100% confident.
build ELF GNU build-id note present
baseline severity, 100% confident.
hardening::no-pie Binary is not position-independent (fixed load address)

binary

notable severity, 90% confident.
embedded Embedded ELF binary at file offset 0x5430 (~592636 bytes)

20 of 43 traits shown

Identity

SHA-256 26bd5b0722d1dbab5db749a063c49bc8638653ac2addfead7a9cb3d6d57bccc9
Filename httpd.26

Origin

Source harvest
Feed dissect-malware
Ecosystem elf_linux

Timeline

First seen 28 Apr 2026 22:29 UTC
Last analyzed 29 Apr 2026 14:13 UTC
Last updated 29 Apr 2026 14:13 UTC

Labeling

Label bad
Label source harvest
Traits version 2e0a8