MALICIOUS — 105_EarthKrahang_20240404.bin
MALICIOUS — 105_EarthKrahang_20240404.bin is a elf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the Dinodasrat family. 4 of 52 detection engines flagged it.
Identification
- SHA-256:
15412d1a6b7f79fad45bcd32cf82f9d651d9ccca082f98a0cca3ad5335284e45 - SHA-1:
74b1da190d670fa4c207afb0fbca4d7df701538a - MD5:
8138f1af1dc51cde924aa2360f12d650 - ssdeep:
6144:pP+dv39axq0rT+DnuokS63QeYqn3b6gu+vG/US8NvVkN2Jy8zcvd:k39aVSq7JYq3GgbeT8NvVru - TLSH:
T16944F8560623312AD1DA8F03F056BABE4C63F1198CAA5E9F8106590F50653CFF9F9C4A - Submitted as: 105_EarthKrahang_20240404.bin
- File type: elf · Size: 261344 bytes
- Verdict: malicious (100/100) · Family: Dinodasrat
Detections (4 of 52 engines)
- ClamAV (daily): {MD5}bin.trojan.dinodasrat.7868.UNOFFICIAL
- Cyble Vision: Cyble Vision: DinodasRAT
- Microsoft Defender: Backdoor:Linux/DinodasRAT!MTB
- Emsisoft (Emergency Kit): Trojan.Linux.DinodasRAT.A
Why this verdict
The malicious score of 100/100 is the fusion of 6 weighted signals:
- ClamAV (daily) flagged {MD5}bin.trojan.dinodasrat.7868.UNOFFICIAL (rule
{MD5}bin.trojan.dinodasrat.7868.UNOFFICIAL) - engine signal, weight 0.90, confidence 0.95 - Cyble Vision flagged Cyble Vision: DinodasRAT (rule
Cyble Vision: DinodasRAT) - engine signal, weight 0.90, confidence 0.95 - Microsoft Defender flagged Backdoor:Linux/DinodasRAT!MTB (rule
Backdoor:Linux/DinodasRAT!MTB) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Trojan.Linux.DinodasRAT.A (rule
Trojan.Linux.DinodasRAT.A) - engine signal, weight 0.55, confidence 0.85 - Embedded network infrastructure: 8.8.8.8 - static signal, weight 0.35, confidence 0.60
- Contacted 9 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
Dynamic analysis (linux)
865 behavior events · 0 ATT&CK techniques · 3 dropped files.
Runtime network
- _dosvc._tcp.local
- desktop-hsgcbep._dosvc._tcp.local
- desktop-hsgcbep(1)._dosvc._tcp.local
- ntp.ubuntu.com
- update.centos-yum.com
- 250.255.255.239.in-addr.arpa
- 224.0.0.251
- ff02::fb
- 10.240.0.1
- 8.8.8.8
- ff02::1:3
- 224.0.0.252
- 255.255.255.255
- 91.189.91.157
- 20.165.94.46
- ff02::1:ff12:3456
- 23.40.52.148
- ff02::2
- 203.26.79.13
- 52.168.112.66
Dropped files
- tmp_.netc.ini -
66a6abc558c0d61631f1bbce2b2c4b208ada42567334778743a0e97aa2aba67c - tmp_.sample.bin.mu -
e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 - tmp_tmp.CWVL2e4xbo -
7f543754883bf437b2ba495f944de6526a60d14958944ba5d0d86a0e7d7a121b
Embedded domains
- ch.sh
- update.centos-yum.com
Embedded IP addresses
- 8.8.8.8
- 20.165.94.46
- 23.40.52.148
- 203.26.79.13
- 52.168.112.66
- 20.165.94.63
- 20.184.175.11
- 57.155.101.212
More Dinodasrat samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report