MALICIOUS — 0275d7b76fb12f336927a089281b6b19edfdd5d6540f46b2b29e057a648549ad.elf
MALICIOUS — 0275d7b76fb12f336927a089281b6b19edfdd5d6540f46b2b29e057a648549ad.elf is a elf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (97/100), attributed to the Wacatac family. 4 of 53 detection engines flagged it.
Identification
- SHA-256:
0275d7b76fb12f336927a089281b6b19edfdd5d6540f46b2b29e057a648549ad - SHA-1:
0e5924c73f123635a4f6c722af43574998d5fc00 - MD5:
1896fdcd7fb94263dce24ed7c2c4bcbb - ssdeep:
768:TU3n2GTuXCxQOH4+sWARvJxQDTvboFnIIFT86UgBZEPb7+0H:S3dH4xbQsFD18h8C1H - TLSH:
T15532094F443C4762EED0A586B054CE6CFE26EE110A76CD7E52834FAB98C66F30520617 - Submitted as: 0275d7b76fb12f336927a089281b6b19edfdd5d6540f46b2b29e057a648549ad.elf
- File type: elf · Size: 43872 bytes
- Verdict: malicious (97/100) · Family: Wacatac
Source: MalwareBazaar · first seen 2026-07-28T00:00:00.000Z · SHA-256 verified
Detections (4 of 53 engines)
- ClamAV (daily): Unix.Trojan.Mirai-10056448-0
- Microsoft Defender: Trojan:Script/Wacatac.B!ml
- Emsisoft (Emergency Kit): Trojan.Generic.40343384
- Kaspersky (KVRT): HEUR:Backdoor.Linux.Agent.ei
Why this verdict
The malicious score of 97/100 is the fusion of 6 weighted signals:
- ClamAV (daily) flagged Unix.Trojan.Mirai-10056448-0 (rule
Unix.Trojan.Mirai-10056448-0) - engine signal, weight 0.90, confidence 0.95 - Microsoft Defender flagged Trojan:Script/Wacatac.B!ml (rule
Trojan:Script/Wacatac.B!ml) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Trojan.Generic.40343384 (rule
Trojan.Generic.40343384) - engine signal, weight 0.55, confidence 0.85 - Embedded network infrastructure: 94.154.43.88, 185.158.107.249 - static signal, weight 0.35, confidence 0.60
- Contacted 6 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
- Extracted generic config (2 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (linux)
919 behavior events · 0 ATT&CK techniques · 1 dropped files.
Runtime network
- desktop-hsgcbep(1)._dosvc._tcp.local
- _dosvc._tcp.local
- desktop-hsgcbep
- ntp.ubuntu.com
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 252.0.0.224.in-addr.arpa
- 224.0.0.251
- ff02::fb
- 203.26.79.13
- ff02::1:3
- 224.0.0.252
- 10.240.0.255
- 10.240.0.1
- 169.254.255.255
- ff02::16
- 10.240.0.77
- 23.40.52.123
- 224.0.0.22
Dropped files
- tmp_tmp.OvcQx7Cauq -
ddca65446d9a4739c4bcae1bc0b128824b5924d8f2b2369601d6bba0d437c6c7
Embedded domains
- telnet.sh
Embedded IP addresses
- 94.154.43.88
- 185.158.107.249
- 203.26.79.13
- 23.40.52.123
- 92.223.78.30
- 23.40.52.148
More Wacatac samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report