tmp2pucppke
Classification: Malicious
tmp2pucppke is a malicious file sample. Linked to Pupy malware. Reported by 2 threat sources, last seen 2023-09-20. Detected by 54 antivirus engines.
Detection summary
- 54 antivirus detections (56% detection ratio)
- 0 IDS alerts
- 5 processes observed
- 0 contacted hosts
- 2 DNS requests
MITRE ATT&CK associations
Malware families: PUPY (S0192)
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| pupy | ThreatFox Abuse.ch | 2023-09-20 16:25:15 | 2023-09-20 17:17:08 | S0192 Pupy | |
| Generic Malware | Hybrid-Analysis | 2023-07-25 17:45:03 | 2023-07-25 17:45:03 |
Tags
win.pupy patpoopy backdoorSample information
- Filenames
- tmp2pucppke
- File type
- ELF 64-bit LSB shared object, x86-64, version 1 (S ...
- Size
- 4194224 bytes
- MD5
bb04bac638e35775b93ddfa30f0a3b09- SHA-1
b7a20a3064c9eb0e0f332dd25df5e4609393b44c- SHA-256
4996180b2fa1045aab5d36f46983e91dadeebfd4f765d69fa50eba4edf310acf- First indexed
- 2023-07-25 17:21:45
- Last updated
- 2025-10-01 01:37:11
Antivirus detections
| Engine | Detection |
|---|---|
| Lionic | Trojan.Linux.Pupy.4!c |
| Cynet | Malicious (score: 99) |
| VIPRE | Trojan.Linux.Generic.269904 |
| K7AntiVirus | Trojan ( 0001140e1 ) |
| K7GW | Trojan ( 0001140e1 ) |
| Arcabit | Trojan.Linux.Generic.D41E50 |
| Cyren | E64/ABRisk.YRQN-7 |
| Symantec | Trojan Horse |
| ESET-NOD32 | a variant of Linux/Patpooty.B |
| TrendMicro-HouseCall | TROJ_GEN.R002C0DDO23 |
| Avast | ELF:Agent-VH [Trj] |
| Kaspersky | HEUR:Trojan.Linux.Pupy.a |
| BitDefender | Trojan.Linux.Generic.269904 |
| MicroWorld-eScan | Trojan.Linux.Generic.269904 |
| Tencent | Linux.Trojan.Pupy.Dnhl |
| Emsisoft | Trojan.Linux.Generic.269904 (B) |
| F-Secure | Malware.LINUX/Patpooty.hopky |
| DrWeb | Linux.Siggen.9999 |
| TrendMicro | TROJ_GEN.R002C0DDO23 |
| McAfee-GW-Edition | LINUX/Agent.bl |
| FireEye | Trojan.Linux.Generic.269904 |
| Sophos | ATK/Pupy-G |
| Ikarus | Trojan.Linux.Patpooty |
| GData | Trojan.Linux.Generic.269904 |
| Avira | LINUX/Patpooty.hopky |
| MAX | malware (ai score=85) |
| Antiy-AVL | Trojan/Linux.Patpooty.b |
| Microsoft | Trojan:Linux/Pupy.B!MTB |
| ZoneAlarm | HEUR:Trojan.Linux.Pupy.a |
| Detected | |
| AhnLab-V3 | Trojan/Linux.Pupy.4194224 |
| ALYac | Trojan.Linux.Pupy |
| Rising | Trojan.Patpooty/Linux!8.13FDD (CLOUD) |
| SentinelOne | Static AI - Malicious ELF |
| AVG | ELF:Agent-VH [Trj] |
| Arcabit | Trojan.Trojan.Linux.Pupy.1 |
| BitDefender | Gen:Variant.Trojan.Linux.Pupy.1 |
| CAT-QuickHeal | ELF.Trojan.47711.GC |
| CTX | elf.trojan.pupy |
| Emsisoft | Gen:Variant.Trojan.Linux.Pupy.1 (B) |
| FireEye | Gen:Variant.Trojan.Linux.Pupy.1 |
| Fortinet | ELF/Pupy.1!tr |
| GData | Gen:Variant.Trojan.Linux.Pupy.1 |
| Jiangmin | Trojan.Linux.die |
| Kingsoft | Linux.Trojan.Pupy.a |
| Lionic | Trojan.Linux.Patpooty.4!c |
| MicroWorld-eScan | Gen:Variant.Trojan.Linux.Pupy.1 |
| Rising | Trojan.Patpooty/Linux!8.13FDD (TFE:1B:YgKBfEFo64G) |
| Skyhigh | LINUX/Agent.bl |
| Tencent | Trojan.Linux.Pupy.bil |
| VIPRE | Gen:Variant.Trojan.Linux.Pupy.1 |
| Varist | E64/ABTrojan.YRQN- |
| ZoneAlarm | ATK/Pupy-G |
| huorong | Backdoor/Linux.PupyRat.a |
DNS requests
es2ocxmx4nxdlen1imekhbuv26ia9999.2ipx1sdg1y999999.cbox4.ignorelist.com ts01-gyr-maverick.cloudsink.net
Process list
| Name | Command line |
|---|---|
| sudo | sudo /home/ubuntu/tmp2pucppke |
| tmp2pucppke | /home/ubuntu/tmp2pucppke |
| ldconfig.real | /sbin/ldconfig.real -p |
| tmp2pucppke | /usr/sbin/atd |
| dash | /bin/sh /sbin/ldconfig -p |