Open-source atomic malware analysis

Analyze another

poolrat

ELF
Verdict: HOSTILE
Mal-ecule
KO₈(C₅AlAs₆CoDyErI₂P)H₇(Cm₁₁Cr₄Db₃Ds₂F₂Po₇Os)Md₃(HeBi₂Pa)Th
Size 2.7 MB download
First seen 114 days ago
Analyzed 113 days ago
Ecosystem elf_linux

Objectives

hostile severity, 95% confident.
command-and-control/reverse-shell POSIX shell with socket fd redirection
notable severity, 70% confident.
anti-static/obfuscation Encoded Mozilla user agent string
notable severity, 70% confident.
anti-static/obfuscation/payload Large .data section (16KB+)
notable severity, 80% confident.
collection/network SSL function as hook target
notable severity, 95% confident.
command-and-control/backdoor/binary libcurl version string
notable severity, 75% confident.
command-and-control/infrastructure PHP URL endpoint (often used for C2)

Micro-behaviors

notable severity, 75% confident.
communications Enumerates interfaces with getifaddrs
notable severity, 75% confident.
communications/http Proxy-Connection keep-alive header
notable severity, 85% confident.
communications/http/download libcurl with custom HTTP headers
notable severity, 75% confident.
communications/socket Bind socket to address
notable severity, 90% confident.
crypto OpenSSL EVP encryption functions
notable severity, 90% confident.
crypto/asymmetric Embedded PEM RSA public key block
notable severity, 95% confident.
crypto/hash SHA256 hashing functions
notable severity, 75% confident.
crypto/kdf PBKDF2 key derivation
notable severity, 80% confident.
data/compress inflate function
notable severity, 90% confident.
dylib Dynamic library loading via dlopen
notable severity, 80% confident.
fs/file Read file status and metadata (core)
notable severity, 95% confident.
process/create Executes command and captures output
notable severity, 75% confident.
process/tty Set terminal attributes

Third-party

hostile severity, 90% confident.
Ditekshen/Multi Detects POOLRAT

20 of 58 traits shown

Identity

SHA-256 85045d9898d28c9cdc4ed0ca5d76eceb457d741c5ca84bb753dde1bea980b516
Filename poolrat

Origin

Source harvest
Feed dissect-malware
Ecosystem elf_linux

Timeline

First seen 24 Apr 2026 16:11 UTC
Last analyzed 26 Apr 2026 01:16 UTC
Last updated 17 Jun 2026 14:39 UTC

Labeling

Label bad
Traits version bf48d