Open-source atomic malware analysis

Analyze another

3ccd0fcffb9b689bc3b53bd0ef2e1c9b619b896f54f3886d3eb69ae64bccd670.elf

ELF
Verdict: SUSPICIOUS
Mal-ecule
O₂(AsS)H(Po)Md₂(Bi₂He)
Size 97.7 KB download
First seen 101 days ago
Analyzed 94 days ago

Objectives

suspicious severity, 75% confident.
anti-static/obfuscation/binary-metrics Has extremely large functions (>64KB)
suspicious severity, 90% confident.
supply-chain/trojanized Many huge functions (>64KB) -
baseline severity, 80% confident.
anti-static/obfuscation Executable section with very low entropy
component severity, 95% confident.
evasion/anti-av __vdso exported symbol string

Micro-behaviors

baseline severity, 100% confident.
fs/path/device /dev/null (legitimate discard device)
component severity, 90% confident.
communications/proxy SOCKS5 client greeting bytes

Metadata

notable severity, 96% confident.
binary ELF binary has trailing overlay data
notable severity, 80% confident.
hardening No full symbol table (likely stripped)
baseline severity, 90% confident.
binary/linking ELF imports zero needed libraries
baseline severity, 100% confident.
binary/metrics Binary has low average complexity
baseline severity, 95% confident.
lang/compiler Rust-compiled binary
baseline severity, 100% confident.
unsigned Binary is not digitally signed
component severity, 70% confident.
binary/anomaly ELF symbol tables stripped from binary

Identity

SHA-256 3ccd0fcffb9b689bc3b53bd0ef2e1c9b619b896f54f3886d3eb69ae64bccd670
Filename 3ccd0fcffb9b689bc3b53bd0ef2e1c9b619b896f54f3886d3eb69ae64bccd670.elf

Origin

Source harvest

Timeline

First seen 17 May 2026 21:02 UTC
First analyzed 24 May 2026 22:59 UTC
Last analyzed 24 May 2026 22:59 UTC
Last updated 24 May 2026 22:59 UTC

Labeling

Label bad
Label source harvest
Traits version 9ea7c