MALICIOUS — 1d471fb55a817e1c4a8188c9cd9432640df171afb9da62f1cb3c3b667532959a
MALICIOUS — 1d471fb55a817e1c4a8188c9cd9432640df171afb9da62f1cb3c3b667532959a is a elf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (97/100). 5 of 57 detection engines flagged it.
Identification
- SHA-256:
1d471fb55a817e1c4a8188c9cd9432640df171afb9da62f1cb3c3b667532959a - SHA-1:
5e0d1c9fa0db31df9c8c3a800dfd04ddca551900 - MD5:
dff145aab139566ad5ffc9f077eda917 - ssdeep:
49152:QQKJbgyGb1S8iMXBtUtw/L074gU6f9ZjRis6QxdcUkr0EaKNQ:QQKRgQ8xRtQGLINP9JRv6xbr0E/Q - TLSH:
T12D5C33C2C419433E46BEC5F8BCDA447EB0745D663A3C6C4D582626234FD21BAA0A35BD - Submitted as: 1d471fb55a817e1c4a8188c9cd9432640df171afb9da62f1cb3c3b667532959a
- File type: elf · Size: 2414368 bytes
- Verdict: malicious (97/100)
Detections (5 of 57 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- YARA: Intezer community: INTEZER_ELF_UPX_Modified
- Detect It Easy (packer/type): DIE:UPX 3.96
- Microsoft Defender: Trojan:Linux/Multiverze
- Emsisoft (Emergency Kit): Trojan.Linux.Generic.222755
Why this verdict
The malicious score of 97/100 is the fusion of 10 weighted signals:
- Memory forensics: 1 finding(s) attributed to the sample across 1 technique(s), e.g. injected region in sample.bin (pid 684) (rule
linux.malfind.Malfind) - memory signal, weight 0.60, confidence 0.85 - Microsoft Defender flagged Trojan:Linux/Multiverze (rule
Trojan:Linux/Multiverze) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Trojan.Linux.Generic.222755 (rule
Trojan.Linux.Generic.222755) - engine signal, weight 0.55, confidence 0.85 - YARA: Intezer community flagged INTEZER_ELF_UPX_Modified (rule
INTEZER_ELF_UPX_Modified) - engine signal, weight 0.40, confidence 0.70 - Detect It Easy (packer/type) flagged DIE:UPX 3.96 (rule
DIE:UPX 3.96) - engine signal, weight 0.35, confidence 0.70 - MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: http://upx.sf.net - static signal, weight 0.35, confidence 0.60
- Packing/obfuscation: high-entropy-blob, UPX 3.96 - static signal, weight 0.25, confidence 0.55
- Contacted 14 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
- Extracted generic config (1 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (linux)
906 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- api.my-ip.io
- desktop-hsgcbep
- _dosvc._tcp.local
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- ntp.ubuntu.com
- discord.com
- gateway.discord.gg
- 252.0.0.224.in-addr.arpa
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 49.13.52.64:443 DE · Falkenstein · AS24940 Hetzner Online GmbH
- 162.159.136.232:443 US · San Francisco · AS13335 Cloudflare, Inc.
- 162.159.133.234:443 US · San Francisco · AS13335 Cloudflare, Inc.
- 49.13.52.64 DE · Falkenstein · AS24940 Hetzner Online GmbH
- ff02::1:3
- 224.0.0.252
- 10.240.0.1
- 10.240.0.255
- 224.0.0.251
- ff02::fb
Embedded URLs
- http://upx.sf.net
Embedded domains
- utf8.de
- upx.sf.net
- api.my-ip.io
- discord.com
- gateway.discord.gg
Embedded IP addresses
- 49.13.52.64
- 162.159.133.234
- 57.155.104.224
- 4.150.223.112
- 85.210.196.11
- 162.159.136.232
- 203.26.79.13
- 57.154.63.210
- 172.172.255.217
- 20.42.179.204
- 48.211.4.16
File paths
- c:\P
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report