Open-source atomic malware analysis

Analyze another

71e446c7cb1e7eb7bd7c11a08ec7f37d7b65db00eb0e0c525775d9f2c2d8dc2f.elf

ELF
Verdict: SUSPICIOUS
Mal-ecule
O₈(C₉Ca₂Er₅Eu₂As₅Dy₂I₅La)H₆(Cm₁₀Cr₂F₅Os₄PoDb₂)Md₃(Bi₂BkPa)Th
Size 11.0 MB download
First seen 118 days ago
Analyzed 116 days ago
Ecosystem linux

Objectives

suspicious severity, 100% confident.
command-and-control Hardcoded Discord webhook URL
suspicious severity, 92% confident.
command-and-control/remote-command Go SSH server command channel
suspicious severity, 80% confident.
command-and-control/reverse-shell SSH service setup
suspicious severity, 90% confident.
credential-access/discord Discord webhook exfiltration endpoint
suspicious severity, 90% confident.
evasion/file-hiding Hidden file in staging directory
suspicious severity, 90% confident.
exfiltration Discord webhook URL
notable severity, 80% confident.
anti-static/obfuscation/control-flow Abnormally low logic density for binary size
notable severity, 90% confident.
command-and-control/channel Discord API URL
notable severity, 75% confident.
command-and-control/infrastructure Go decryption key symbol
notable severity, 80% confident.
discovery/system/fingerprint Machine ID collection for victim tracking
notable severity, 80% confident.
evasion pkill with kill -9 signal

Micro-behaviors

suspicious severity, 90% confident.
communications/http Multiple IP discovery services (stealer behavior)
suspicious severity, 86% confident.
communications/ssh Permissive Go SSH server auth
notable severity, 88% confident.
communications OPC UA library or module reference
notable severity, 90% confident.
crypto/asymmetric Embedded PEM RSA public key block
notable severity, 75% confident.
fs/chmod chmod +x (make executable)
notable severity, 85% confident.
os/service Systemd /lib service file path

Metadata

suspicious severity, 95% confident.
binary ELF binary without section headers

Third-party

hostile severity, 90% confident.
elastic/Linux_Generic_Threat/linux

anti-analysis

suspicious severity, 100% confident.
malformed Malformed ELF header or section headers: bad offset 30302232

20 of 52 traits shown

Identity

SHA-256 71e446c7cb1e7eb7bd7c11a08ec7f37d7b65db00eb0e0c525775d9f2c2d8dc2f
Filename 71e446c7cb1e7eb7bd7c11a08ec7f37d7b65db00eb0e0c525775d9f2c2d8dc2f.elf

Origin

Source harvest
Feed malwarebazaar
Ecosystem linux

Timeline

First seen 24 Apr 2026 16:14 UTC
Last analyzed 26 Apr 2026 09:14 UTC
Last updated 26 Apr 2026 09:14 UTC

Labeling

Label bad
Label source harvest
Traits version bf48d