CLEAN — 1756d6f4348931af8d3029384ccee8d7281673a627ca753d7c3ea3e7881356d8.elf
CLEAN — 1756d6f4348931af8d3029384ccee8d7281673a627ca753d7c3ea3e7881356d8.elf is a elf sample analyzed by MalwareAnalyzer by Cyble with a clean verdict (30/100). 3 of 56 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
1756d6f4348931af8d3029384ccee8d7281673a627ca753d7c3ea3e7881356d8 - SHA-1:
d275fde856caf6965a6103ab7bb626b4e08ddb16 - MD5:
4af09feda9882d137c97d6705bc718d0 - ssdeep:
1536:bcjItMqvZLDWtw9cp650lF8C1lgam4KcmZXVNE4IdoordB:bciMmDWtws6ylFd1Oam4oRXE4GBdB - TLSH:
T1BB345C9981A9870FF290E5B0F8615EEE815FF9A933754FCC4613E01C72A84CB9067547 - Submitted as: 1756d6f4348931af8d3029384ccee8d7281673a627ca753d7c3ea3e7881356d8.elf
- File type: elf · Size: 54276 bytes
- Verdict: clean (30/100)
Source: MalwareBazaar · first seen 2026-08-02T00:00:00.000Z · SHA-256 verified
Detections (3 of 56 engines)
- Microsoft Defender: Trojan:Win32/Malgent
- Emsisoft (Emergency Kit): Trojan.Linux.GenericKD.60054803
- Kaspersky (KVRT): HEUR:Backdoor.Linux.Mirai.mz
MITRE ATT&CK
Why this verdict
The clean score of 30/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: 8.8.8.8, 8.8.4.4, 1.1.1.1 - static signal, weight 0.35, confidence 0.60
- Contacted 1 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
- Extracted generic config (1 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (linux)
620 behavior events · 0 ATT&CK techniques · 1 dropped files.
Runtime network
- desktop-hsgcbep
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 252.0.0.224.in-addr.arpa
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 250.255.255.239.in-addr.arpa
- 79.243.254.169.in-addr.arpa
- 255.255.254.169.in-addr.arpa
- 127.243.204.64
- ff02::1:3
- 224.0.0.252
- 10.240.0.255
- 169.254.255.255
- 10.240.0.1
- ff02::16
- 224.0.0.251
- ff02::fb
- 239.255.255.250
- ff02::1
- 224.0.0.22
Dropped files
- tmp_.sc -
1b328c570fc1a9a51d6585e58bf8d94c843922c26cd190b6a25b0c6e221aa26c
Embedded IP addresses
- 8.8.8.8
- 8.8.4.4
- 1.1.1.1
- 1.0.0.1
- 9.9.9.9
- 149.112.112.112
- 208.67.222.222
- 208.67.220.220
- 77.88.8.8
- 77.88.8.1
- 74.178.232.29
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report