MALICIOUS — 212da075160d4822800ad3b7a6eabfe77561b1efed9413fbac7aa985550efe1a.elf
MALICIOUS — 212da075160d4822800ad3b7a6eabfe77561b1efed9413fbac7aa985550efe1a.elf is a elf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (93/100). 2 of 54 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
212da075160d4822800ad3b7a6eabfe77561b1efed9413fbac7aa985550efe1a - SHA-1:
9586210edce225d4a1df4c8eebfec400ef2a1659 - MD5:
29620bc82c8f45c448b84eaf1f934f06 - ssdeep:
768:TMwoKeVbjkbl1y0ls+9v3OQoi8Fs8GMzG4iSV9UkP31ABA0xi6Rh42qD8oL+EQE:Tg9X0lURx39UO31ABA0xi8BI+cr - TLSH:
T1A5356B46657C8B0BE7F2E0B4E47D8FAD4013B565A37A4EC88307429CB0D989795BE092 - Submitted as: 212da075160d4822800ad3b7a6eabfe77561b1efed9413fbac7aa985550efe1a.elf
- File type: elf · Size: 58108 bytes
- Verdict: malicious (93/100)
Source: MalwareBazaar · first seen 2026-07-27T00:00:00.000Z · SHA-256 verified
Detections (2 of 54 engines)
- Emsisoft (Emergency Kit): Trojan.Generic.40317714
- Kaspersky (KVRT): HEUR:Backdoor.Linux.Mirai.gen
MITRE ATT&CK
Why this verdict
The malicious score of 93/100 is the fusion of 8 weighted signals:
- 1 behavioral detection(s): Download-and-execute dropper (wget/curl + chmod) [high] (rule
tl-linux-download-exec) - dynamic signal, weight 0.60, confidence 0.90 - 1 behavioral detection(s): Download-and-execute dropper (wget/curl + chmod) [high] (rule
tl-linux-download-exec) - dynamic signal, weight 0.60, confidence 0.90 - Emsisoft (Emergency Kit) flagged Trojan.Generic.40317714 (rule
Trojan.Generic.40317714) - engine signal, weight 0.55, confidence 0.85 - Embedded network infrastructure: 217.60.195.143 - static signal, weight 0.35, confidence 0.60
- Contacted 5 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
- Contacted 5 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
- Extracted generic config (1 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
- Extracted generic config (1 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (linux)
883 behavior events · 0 ATT&CK techniques · 1 dropped files.
Runtime network
- entropy.ubuntu.com
- ntp.ubuntu.com
- desktop-hsgcbep
- 185.125.189.54:443
- 217.60.195.143:5221
- 185.125.189.54
- 10.240.0.1
- ff02::1:3
- 224.0.0.252
- 10.240.0.255
- ff02::16
- ff02::1
- ff02::2
- ff02::1:2
- 185.125.190.56
- 217.60.195.143
- 224.0.0.22
- ff02::1:ff4c:1d1d
- ff02::1:ff12:3456
- 255.255.255.255
Dropped files
- tmp_tmp.lcDXDs55Sq -
e382094d1e9b20f42af0d93991313878ca4146c4671eed9f544717fdb157044f
Embedded IP addresses
- 217.60.195.143
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report