Open-source atomic malware analysis

Analyze another

dbus-session.f

ELF
Verdict: HOSTILE
Mal-ecule
KO₅(C₂Er₄IAsP)H₄(Cm₆HfOsPo₇)Md₂(HeBi₃)Th₃
Size 23.1 KB download unavailable
First seen 109 days ago
Analyzed 109 days ago
Ecosystem elf_linux

Well-known

hostile severity, 98% confident.
malware/backdoor BPFDoor classic iptables PTY backdoor

Objectives

hostile severity, 96% confident.
command-and-control/backdoor PTY backdoor with iptables redirect
hostile severity, 98% confident.
evasion/masquerade BPFDoor-style process masquerading with anti-forensics
suspicious severity, 90% confident.
evasion/indicator-removal MYSQL_HISTFILE=/dev/null redirection
suspicious severity, 90% confident.
impact/degrade iptables PREROUTING REDIRECT rule
notable severity, 75% confident.
anti-static/obfuscation Encoded /dev/null redirect
notable severity, 75% confident.
persistence/system/daemon Unix daemon persistence mechanism

Micro-behaviors

notable severity, 86% confident.
communications/socket Native socket packet filtering
notable severity, 70% confident.
fs/chmod Shell chmod 7xx (executable)
notable severity, 75% confident.
hardware/input Direct access to Linux input
notable severity, 80% confident.
os/env Set HISTFILE to /dev/null
notable severity, 90% confident.
process/create system() function call
notable severity, 95% confident.
process/tty PTY with socket and fork operations

Metadata

suspicious severity, 100% confident.
lang/encoded shell code encoded in string
baseline severity, 100% confident.
binary ELF program interpreter present
baseline severity, 100% confident.
binary/linking ELF needed library metadata

Third-party

hostile severity, 90% confident.
Sekoia/Backdoor/Lin Detect the BPFDoor backdoor used by the Chinese TA Red Menshen
hostile severity, 90% confident.
SigBase/APT/MAL/LNX/Redmenshen/Bpfdoor/Controller Detects unknown Linux implants (uploads from KR and MO)
hostile severity, 90% confident.
SigBase/APT/MAL/LNX/Redmenshen/Bpfdoor/Controller/Generic Detects BPFDoor malware
hostile severity, 90% confident.
elastic/Linux_Trojan_BPFDoor/linux/trojan

20 of 42 traits shown

Identity

SHA-256 de472ed37e33b79e1aa37e67a680ee3a9d74628438c209543a06e916a0a86fba
Canonical SHA-256 3d254d5624fb40f48c4132482f1f3fcd158f76d7552f1041b73acc2f910777e9
Filename dbus-session.f

Origin

Source harvest
Feed dissect-malware
Ecosystem elf_linux

Timeline

First seen 28 Apr 2026 22:29 UTC
Last analyzed 28 Apr 2026 22:43 UTC
Last updated 28 Apr 2026 22:43 UTC

Labeling

Label bad
Label source harvest
Traits version 113a4