Local reference
Suspicious dependency
Inferred
Mal-ecule
KO₅(C₂Er₄IAsP)H₃(Cm₅OsPo₇)Md₂(Bi₄He)Th₃
Well-known
hostile severity, 98% confident.
malware/backdoor
BPFDoor classic iptables PTY backdoor
Objectives
hostile severity, 96% confident.
command-and-control/backdoor
PTY backdoor with iptables redirect
hostile severity, 98% confident.
evasion/masquerade
BPFDoor-style process masquerading with anti-forensics
suspicious severity, 90% confident.
evasion/indicator-removal
MYSQL_HISTFILE=/dev/null redirection
suspicious severity, 90% confident.
impact/degrade
iptables PREROUTING REDIRECT rule
notable severity, 75% confident.
anti-static/obfuscation
Encoded /dev/null redirect
Micro-behaviors
notable severity, 86% confident.
communications/socket
Native socket packet filtering
notable severity, 80% confident.
os/env
Set HISTFILE to /dev/null
notable severity, 90% confident.
process/create
system() function call
notable severity, 95% confident.
process/tty
PTY with socket and fork operations
baseline severity, 100% confident.
fs/path
/dev/null (legitimate discard device)
baseline severity, 100% confident.
fs/path/device
/dev/ptmx PTY master
Metadata
notable severity, 80% confident.
binary
Artificially low entropy from padding
baseline severity, 100% confident.
binary/linking
ELF program interpreter metadata
baseline severity, 100% confident.
binary::binary-format-checked
Binary format is identified
baseline severity, 100% confident.
build
ELF GNU build-id note present
Third-party
hostile severity, 90% confident.
Sekoia/Backdoor/Lin
Detect the BPFDoor backdoor used by the Chinese TA Red Menshen
hostile severity, 90% confident.
SigBase/APT/MAL/LNX/Redmenshen/Bpfdoor/Controller
Detects unknown Linux implants (uploads from KR and MO)
hostile severity, 90% confident.
SigBase/APT/MAL/LNX/Redmenshen/Bpfdoor/Controller/Generic
Detects BPFDoor malware
hostile severity, 90% confident.
elastic/Linux_Trojan_BPFDoor/linux/trojan
20 of 36 traits shown
Identity
| SHA-256 | 2cc90edd9bc085f54851bed101f95ce2bace7c9a963380cfd11ea0bc60e71e0c |
|---|---|
| Filename | auth-session.f |
Origin
| Source | harvest |
|---|---|
| Feed | dissect-malware |
| Ecosystem | elf_linux |
Timeline
| First seen | 28 Apr 2026 22:29 UTC |
|---|---|
| Last analyzed | 28 Apr 2026 23:04 UTC |
| Last updated | 28 Apr 2026 23:04 UTC |
Labeling
| Label | bad |
|---|---|
| Label source | harvest |
| Traits version | 8eee0 |
Not seeing what you expected? Let us know