Local reference
Suspicious dependency
Inferred
Well-known
hostile severity, 98% confident.
malware/backdoor
BPFDoor classic iptables PTY backdoor
Objectives
hostile severity, 96% confident.
command-and-control/backdoor
PTY backdoor with iptables redirect
hostile severity, 98% confident.
evasion/masquerade
BPFDoor-style process masquerading with anti-forensics
suspicious severity, 90% confident.
evasion/indicator-removal
MYSQL_HISTFILE=/dev/null redirection
suspicious severity, 90% confident.
impact/degrade
iptables PREROUTING REDIRECT rule
notable severity, 75% confident.
anti-static/obfuscation
Encoded /dev/null redirect
notable severity, 75% confident.
persistence/system/daemon
Unix daemon persistence mechanism
Micro-behaviors
notable severity, 86% confident.
communications/socket
Native socket packet filtering
notable severity, 70% confident.
fs/chmod
Shell chmod 7xx (executable)
notable severity, 75% confident.
hardware/input
Direct access to Linux input
notable severity, 80% confident.
os/env
Set HISTFILE to /dev/null
notable severity, 90% confident.
process/create
system() function call
notable severity, 95% confident.
process/tty
PTY with socket and fork operations
Metadata
suspicious severity, 100% confident.
lang/encoded
shell code encoded in string
baseline severity, 100% confident.
binary
ELF program interpreter present
baseline severity, 100% confident.
binary/linking
ELF needed library metadata
Third-party
hostile severity, 90% confident.
Sekoia/Backdoor/Lin
Detect the BPFDoor backdoor used by the Chinese TA Red Menshen
hostile severity, 90% confident.
SigBase/APT/MAL/LNX/Redmenshen/Bpfdoor/Controller
Detects unknown Linux implants (uploads from KR and MO)
hostile severity, 90% confident.
SigBase/APT/MAL/LNX/Redmenshen/Bpfdoor/Controller/Generic
Detects BPFDoor malware
hostile severity, 90% confident.
elastic/Linux_Trojan_BPFDoor/linux/trojan
20 of 42 traits shown
Identity
| SHA-256 | de472ed37e33b79e1aa37e67a680ee3a9d74628438c209543a06e916a0a86fba |
|---|---|
| Canonical SHA-256 | 3d254d5624fb40f48c4132482f1f3fcd158f76d7552f1041b73acc2f910777e9 |
| Filename | dbus-session.f |
Origin
| Source | harvest |
|---|---|
| Feed | dissect-malware |
| Ecosystem | elf_linux |
Timeline
| First seen | 28 Apr 2026 22:29 UTC |
|---|---|
| Last analyzed | 28 Apr 2026 22:43 UTC |
| Last updated | 28 Apr 2026 22:43 UTC |
Labeling
| Label | bad |
|---|---|
| Label source | harvest |
| Traits version | 113a4 |
Not seeing what you expected? Let us know