Open-source atomic malware analysis

Analyze another

auth-session.f

ELF
Verdict: HOSTILE
Mal-ecule
KO₅(C₂Er₄IAsP)H₃(Cm₅OsPo₇)Md₂(Bi₄He)Th₃
Size 19.1 KB download unavailable
First seen 109 days ago
Analyzed 109 days ago
Ecosystem elf_linux

Well-known

hostile severity, 98% confident.
malware/backdoor BPFDoor classic iptables PTY backdoor

Objectives

hostile severity, 96% confident.
command-and-control/backdoor PTY backdoor with iptables redirect
hostile severity, 98% confident.
evasion/masquerade BPFDoor-style process masquerading with anti-forensics
suspicious severity, 90% confident.
evasion/indicator-removal MYSQL_HISTFILE=/dev/null redirection
suspicious severity, 90% confident.
impact/degrade iptables PREROUTING REDIRECT rule
notable severity, 75% confident.
anti-static/obfuscation Encoded /dev/null redirect

Micro-behaviors

notable severity, 86% confident.
communications/socket Native socket packet filtering
notable severity, 80% confident.
os/env Set HISTFILE to /dev/null
notable severity, 90% confident.
process/create system() function call
notable severity, 95% confident.
process/tty PTY with socket and fork operations
baseline severity, 100% confident.
fs/path /dev/null (legitimate discard device)
baseline severity, 100% confident.
fs/path/device /dev/ptmx PTY master

Metadata

notable severity, 80% confident.
binary Artificially low entropy from padding
baseline severity, 100% confident.
binary/linking ELF program interpreter metadata
baseline severity, 100% confident.
binary::binary-format-checked Binary format is identified
baseline severity, 100% confident.
build ELF GNU build-id note present

Third-party

hostile severity, 90% confident.
Sekoia/Backdoor/Lin Detect the BPFDoor backdoor used by the Chinese TA Red Menshen
hostile severity, 90% confident.
SigBase/APT/MAL/LNX/Redmenshen/Bpfdoor/Controller Detects unknown Linux implants (uploads from KR and MO)
hostile severity, 90% confident.
SigBase/APT/MAL/LNX/Redmenshen/Bpfdoor/Controller/Generic Detects BPFDoor malware
hostile severity, 90% confident.
elastic/Linux_Trojan_BPFDoor/linux/trojan

20 of 36 traits shown

Identity

SHA-256 2cc90edd9bc085f54851bed101f95ce2bace7c9a963380cfd11ea0bc60e71e0c
Filename auth-session.f

Origin

Source harvest
Feed dissect-malware
Ecosystem elf_linux

Timeline

First seen 28 Apr 2026 22:29 UTC
Last analyzed 28 Apr 2026 23:04 UTC
Last updated 28 Apr 2026 23:04 UTC

Labeling

Label bad
Label source harvest
Traits version 8eee0