MALICIOUS — 11f8d35eb01d1d350b80ebcf49d949cdd9f7f58e6c8009a1c283a1956aa69359.elf
MALICIOUS — 11f8d35eb01d1d350b80ebcf49d949cdd9f7f58e6c8009a1c283a1956aa69359.elf is a elf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (99/100), attributed to the Sabsik family. 6 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
11f8d35eb01d1d350b80ebcf49d949cdd9f7f58e6c8009a1c283a1956aa69359 - SHA-1:
a48a597856b5240fffb65851938676b9d2cee89f - MD5:
f9832ff3b5d68ee877bfb085d66d3123 - ssdeep:
768:DjhJOAdeRX2gWGl/wm+RAj5QOx6OThR1Vl/Jy6dnbcuyD7UHQRju/:DjhJOAdohJoOp1R1VTyEnouy8HyM - TLSH:
T1E431E14E86D608F6DEFF78688156722C11694503E03A44BB85CE2358A5DF523D0EB5CF - Submitted as: 11f8d35eb01d1d350b80ebcf49d949cdd9f7f58e6c8009a1c283a1956aa69359.elf
- File type: elf · Size: 41832 bytes
- Verdict: malicious (99/100) · Family: Sabsik
Source: MalwareBazaar · first seen 2026-07-31T00:00:00.000Z · SHA-256 verified
Detections (6 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Unix.Dropper.Mirai-7135858-0
- YARA: Intezer community: INTEZER_ELF_UPX_Modified
- Microsoft Defender: Trojan:Script/Sabsik.EN.A!ml
- Emsisoft (Emergency Kit): Gen:Variant.Linux.DDoS.2
- Kaspersky (KVRT): HEUR:Backdoor.Linux.Mirai.r
MITRE ATT&CK
Why this verdict
The malicious score of 99/100 is the fusion of 9 weighted signals:
- ClamAV (daily) flagged Unix.Dropper.Mirai-7135858-0 (rule
Unix.Dropper.Mirai-7135858-0) - engine signal, weight 0.90, confidence 0.95 - Memory forensics: 4 finding(s), e.g. injected region in sample.bin (pid 693) (rule
linux.malfind.Malfind) - memory signal, weight 0.60, confidence 0.85 - Microsoft Defender flagged Trojan:Script/Sabsik.EN.A!ml (rule
Trojan:Script/Sabsik.EN.A!ml) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Gen:Variant.Linux.DDoS.2 (rule
Gen:Variant.Linux.DDoS.2) - engine signal, weight 0.55, confidence 0.85 - YARA: Intezer community flagged INTEZER_ELF_UPX_Modified (rule
INTEZER_ELF_UPX_Modified) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: http://upx.sf.net - static signal, weight 0.35, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Contacted 23 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
- Extracted generic config (1 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (linux)
850 behavior events · 0 ATT&CK techniques · 1 dropped files.
Runtime network
- wqok85qtq.net
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 252.0.0.224.in-addr.arpa
- ntp.ubuntu.com
- 250.255.255.239.in-addr.arpa
- ff02::1:3
- 224.0.0.252
- 31.56.209.153 GB · London · AS25369 AE-GOLDIP
- 8.8.8.8
- 65.222.202.53 US · AS701 UUNET - Verizon Business, US
- ff02::fb
- 224.0.0.251
- 52.168.117.170 US · Chantilly · AS8075 Microsoft Corporation
- 10.240.0.1
- 52.123.252.193 AU · Sydney · AS8075 Microsoft Corporation
- 91.189.91.157
- 224.0.0.22
- 135.234.160.245 US · Ashburn · AS8075 Microsoft Limited
Dropped files
- tmp_tmp.gar8BsPzlF -
0bdd7ecf215c365e20beed8d04628224e6b6ba941263d8e30efc285a8c220b33
Embedded URLs
- http://upx.sf.net
Embedded domains
- i.fi
- upx.sf.net
- wqok85qtq.net
Embedded IP addresses
- 31.56.209.153
- 65.222.202.53
- 52.168.117.170
- 52.123.252.193
- 135.234.160.245
- 135.232.92.34
- 20.42.65.88
- 135.233.45.222
- 40.79.141.154
- 52.182.143.212
- 40.84.97.4
- 172.215.188.232
- 20.184.175.11
- 85.210.193.152
- 4.247.188.224
- 135.234.160.244
- 172.178.240.162
- 135.233.95.144
- 4.207.44.68
More Sabsik samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report