MALICIOUS — 1e64187b5e3b5fe71d34ea555ff31961404adad83f8e0bd1ce0aad056a878d73
MALICIOUS — 1e64187b5e3b5fe71d34ea555ff31961404adad83f8e0bd1ce0aad056a878d73 is a elf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (86/100), attributed to the Gafgyt family. 4 of 56 detection engines flagged it.
Identification
- SHA-256:
1e64187b5e3b5fe71d34ea555ff31961404adad83f8e0bd1ce0aad056a878d73 - SHA-1:
5fabbf7a6d524fc6283103664363737c83403a47 - MD5:
600d890e993355b8f9306164183867a0 - ssdeep:
384:w8c1FStuxlBZCQLkdrjHmPdax3gZ98F+n:QPStebZDLkpS1ax3Q9S+ - TLSH:
T15829A52F222D6A74E8FDCA10900795EC14B3D8BF2937A78CA257A11E2172757D53203E - Submitted as: 1e64187b5e3b5fe71d34ea555ff31961404adad83f8e0bd1ce0aad056a878d73
- File type: elf · Size: 19128 bytes
- Verdict: malicious (86/100) · Family: Gafgyt
Detections (4 of 56 engines)
- ClamAV (daily): Unix.Trojan.Gafgyt-10033578-0
- Microsoft Defender: Trojan:Linux/Multiverze
- Emsisoft (Emergency Kit): Trojan.Linux.Generic.222837
- Kaspersky (KVRT): HEUR:Backdoor.Linux.Gafgyt.b
Why this verdict
The malicious score of 86/100 is the fusion of 1 weighted signal:
- ClamAV (daily) flagged Unix.Trojan.Gafgyt-10033578-0 (rule
Unix.Trojan.Gafgyt-10033578-0) - engine signal, weight 0.90, confidence 0.95
Dynamic analysis (linux)
894 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- desktop-hsgcbep
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 252.0.0.224.in-addr.arpa
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- ntp.ubuntu.com
- ff02::1:3
- 224.0.0.252
- 10.240.0.255
- 239.255.255.250
- 10.240.0.1
- ff02::16
- 224.0.0.251
- ff02::fb
- ff02::2
- ff02::1
- 224.0.0.22
- 185.125.190.58
- 20.42.73.24 US · Ashburn · AS8075 Microsoft Corporation
- 185.125.190.57
Embedded URLs
- https://github.com/heroims/obfuscator.git
Embedded domains
- github.com
Embedded IP addresses
- 20.42.73.24
- 4.150.223.102
- 20.42.65.84
- 4.150.223.96
- 172.215.188.232
- 172.172.255.218
More Gafgyt samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report