Bushido malware family
Bushido is a malware family tracked by MalwareAnalyzer by Cyble across 4 publicly analyzed samples. First seen 2026-07-31, most recently 2026-08-10.
Corpus statistics
- Publicly analyzed samples: 4
- First seen: 2026-07-31
- Last seen: 2026-08-10
- Verdicts: malicious 4
- File types: elf 4
Extracted command-and-control infrastructure
- http://185.183.34.45/LjEZs/dlink;sh - 4 samples
- http://185.183.34.45/LjEZs/gpon80+-O+- - 4 samples
- http://185.183.34.45/LjEZs/gpon8080+-O+- - 4 samples
- http://185.183.34.45/LjEZs/hnap - 4 samples
- http://185.183.34.45/LjEZs/jaws;sh+/tmp/jaws - 4 samples
- http://185.183.34.45/LjEZs/netgear+-O+/tmp/netgear;sh+netgear&curpath=/¤tsetting.htm=1 - 4 samples
- http://185.183.34.45/LjEZs/realtek - 4 samples
- http://185.183.34.45/LjEZs/tr064 - 4 samples
- http://purenetworks.com/HNAP1/ - 4 samples
- http://217.60.195.187/sshex.sh - 2 samples
Recent Bushido samples
- 2d92d151af47fb2e7d569a5cbf5d3bac202add4a83807168469f1c2cc6e4cd0e.elf - malicious (2026-08-10)
- 1fbce250c4754a6ade5ab191b8274e77b59e501bbb0e7a20a578c182f11b94f4.elf - malicious (2026-08-09)
- 336ff5d2c361e594327c54a8a5398bc0255f152d175f99bf3a9efd621c51a3b0.elf - malicious (2026-07-31)
- 2f7ffce5d02499ed4f3801aa1433ce0dad003a1ab818659a1994da2059c942ea.elf - malicious (2026-07-31)
Frequently asked about Bushido
- What is Bushido?
- Bushido is a malware family tracked by MalwareAnalyzer by Cyble across 4 publicly analyzed samples. First seen 2026-07-31, most recently 2026-08-10.
- How many Bushido samples have been analyzed?
- MalwareAnalyzer by Cyble holds 4 publicly analyzed samples attributed to Bushido, first seen 2026-07-31 and most recently 2026-08-10. This counts public submissions to this platform only, so it is a measure of what we have seen rather than of the family's total prevalence.
- What file types does Bushido use?
- Bushido samples in this corpus are distributed as elf (4).
- Does Bushido use command-and-control infrastructure?
- Yes. 10 distinct command-and-control indicators have been extracted from Bushido samples, either from static configuration or from traffic captured during sandbox detonation. The full list is published on the family page.
- Is Bushido malicious?
- 4 of 4 analyzed Bushido samples were scored malicious by the fused verdict, which combines multi-engine static scanning, YARA and hash reputation with behavior captured during real sandbox detonation. Each report lists every signal that contributed to its score.
Latest analyzed threats · ATT&CK coverage across the corpus · Threat trends