MALICIOUS — 1a749712883354d7da407004b49ece6ae638a22314ed70a095316429b5c41c22.elf
MALICIOUS — 1a749712883354d7da407004b49ece6ae638a22314ed70a095316429b5c41c22.elf is a elf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (88/100), attributed to the RiskTool family. 2 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
1a749712883354d7da407004b49ece6ae638a22314ed70a095316429b5c41c22 - SHA-1:
5bddb39f613c06e3b34bcdccfd99b78ebdd70a05 - MD5:
faf28bb3aa7b6606a7f23e1a162751f9 - ssdeep:
1536:atIyZNif03dqcTTM5QP7BxPGlmVS2HflwUiNeK/S/O9bCbW4UorTC/:WxZ48Qgbwe4Uql5EbZT - TLSH:
T1DD3C4C6143136614D2F0EF60B4114EEDA047B4AA613428ED020B671EF6F973BDAF3992 - Submitted as: 1a749712883354d7da407004b49ece6ae638a22314ed70a095316429b5c41c22.elf
- File type: elf · Size: 119096 bytes
- Verdict: malicious (88/100) · Family: RiskTool
Detections (2 of 53 engines)
- Microsoft Defender: Trojan:Script/Sabsik.EN.A!ml
- Kaspersky (KVRT): not-a-virus:HEUR:RiskTool.Linux.Alien.gen
MITRE ATT&CK
Why this verdict
The malicious score of 88/100 is the fusion of 4 weighted signals:
- 1 behavioral detection(s): Cryptominer (stratum pool / miner binary) [high] (rule
tl-crypto-miner) - dynamic signal, weight 0.60, confidence 0.90 - Microsoft Defender flagged Trojan:Script/Sabsik.EN.A!ml (rule
Trojan:Script/Sabsik.EN.A!ml) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged not-a-virus:HEUR:RiskTool.Linux.Alien.gen (rule
not-a-virus:HEUR:RiskTool.Linux.Alien.gen) - engine signal, weight 0.55, confidence 0.85 - Contacted 15 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
Dynamic analysis (linux)
863 behavior events · 0 ATT&CK techniques · 1 dropped files.
Runtime network
- pool.supportxmr.com
- 250.255.255.239.in-addr.arpa
- ntp.ubuntu.com
- 15.235.234.220:3333 SG · Singapore · AS16276 OVH Singapore PTE. LTD
- ff02::1:3
- 224.0.0.252
- 10.240.0.1
- ff02::fb
- 224.0.0.251
- 20.42.65.90 US · Flint Hill · AS8075 Microsoft Corporation
- ff02::16
- 239.255.255.250
- ff02::1
- 20.165.94.46 US · San Antonio · AS8075 Microsoft Corporation
- 20.190.142.166
- 15.235.234.220 SG · Singapore · AS16276 OVH Singapore PTE. LTD
- ff02::1:ff12:3456
- 23.214.88.41
- 72.153.5.137 US · Boydton · AS8075 Microsoft Corporation
- 135.233.95.144 US · Des Moines · AS8075 Microsoft Limited
Dropped files
- tmp_tmp.54UsEwpBER -
ba434767d5658c2d1b88af056fc48121c1c159571dcfab870da2176faf8436c2
Embedded domains
- pool.supportxmr.com
- pool.minexmr.com
- xmr.pool.minergate.com
- monero.herominers.com
Embedded IP addresses
- 20.42.65.90
- 20.165.94.46
- 15.235.234.220
- 72.153.5.137
- 135.233.95.144
- 15.235.234.199
More RiskTool samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report