MALICIOUS — 2d8b09556b0e45a68e466079e1b3e9446c94d3e671d84aeef4ea5c200d8f6255.elf
MALICIOUS — 2d8b09556b0e45a68e466079e1b3e9446c94d3e671d84aeef4ea5c200d8f6255.elf is a elf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the AsyncRAT family. 8 of 54 detection engines flagged it.
Identification
- SHA-256:
2d8b09556b0e45a68e466079e1b3e9446c94d3e671d84aeef4ea5c200d8f6255 - SHA-1:
56397acb2f138d61feba218c6207c684ce1da84f - MD5:
8295e858eaa1d0a69137e105df6dd690 - ssdeep:
49152:FGKPMxchyyTrCXDMrTZ3+tVNfEP2KmpAX5EWOigY/zA95xwR:TMmhyyTSe3+BnUExvxa - TLSH:
T1AA646CA552573512D1F5CE08F031C0DC9887B85AD2B11E8E034BE57A41DEFAFAAF10A9 - Submitted as: 2d8b09556b0e45a68e466079e1b3e9446c94d3e671d84aeef4ea5c200d8f6255.elf
- File type: elf · Size: 5234688 bytes
- Verdict: malicious (100/100) · Family: AsyncRAT
Source: MalwareBazaar · first seen 2026-07-29T00:00:00.000Z · SHA-256 verified
Detections (8 of 54 engines)
- ClamAV (daily): Unix.Malware.Kaiji-10003917-0
- YARA: Intezer community: INTEZER_Linux_Persistence
- YARA: Trellix/McAfee ATR: ATR_REvil_Sodinokibi
- YARA: ReversingLabs: RL_Formbook_XLoader
- YARA: Stratosphere IPS: STRATO_Tor_Onion_C2
- Microsoft Defender: Trojan:Linux/Kaiji.A!MTB
- Emsisoft (Emergency Kit): Trojan.Linux.GenericKD.20756
- Kaspersky (KVRT): HEUR:Trojan.Linux.Agent.ql
Why this verdict
The malicious score of 100/100 is the fusion of 10 weighted signals:
- ClamAV (daily) flagged Unix.Malware.Kaiji-10003917-0 (rule
Unix.Malware.Kaiji-10003917-0) - engine signal, weight 0.90, confidence 0.95 - Extracted AsyncRAT config (1 C2) - engine signal, weight 0.80, confidence 0.65
- Microsoft Defender flagged Trojan:Linux/Kaiji.A!MTB (rule
Trojan:Linux/Kaiji.A!MTB) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Trojan.Linux.GenericKD.20756 (rule
Trojan.Linux.GenericKD.20756) - engine signal, weight 0.55, confidence 0.85 - YARA: Intezer community flagged INTEZER_Linux_Persistence (rule
INTEZER_Linux_Persistence) - engine signal, weight 0.35, confidence 0.70 - YARA: Trellix/McAfee ATR flagged ATR_REvil_Sodinokibi (rule
ATR_REvil_Sodinokibi) - engine signal, weight 0.35, confidence 0.70 - YARA: ReversingLabs flagged RL_Formbook_XLoader (rule
RL_Formbook_XLoader) - engine signal, weight 0.35, confidence 0.70 - YARA: Stratosphere IPS flagged STRATO_Tor_Onion_C2 (rule
STRATO_Tor_Onion_C2) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: http://www.years, http://.jpg, http://www.interpretation - static signal, weight 0.35, confidence 0.60
- Contacted 6 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
Dynamic analysis (linux)
944 behavior events · 0 ATT&CK techniques · 1 dropped files.
Runtime network
- desktop-hsgcbep._dosvc._tcp.local
- desktop-hsgcbep(1)._dosvc._tcp.local
- desktop-hsgcbep(2)._dosvc._tcp.local
- desktop-hsgcbep
- ntp.ubuntu.com
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 252.0.0.224.in-addr.arpa
- 224.0.0.251
- ff02::fb
- ff02::1:3
- 224.0.0.252
- 169.254.255.255
- 10.240.0.1
- 10.240.0.255
- ff02::16
- 185.125.190.58
- ff02::2
- ff02::1:ff4c:1d1d
Dropped files
- tmp_tmp.AT2LRf5tXF -
24cc689a322ce9651ecf0b424d53eb8f14d80ba356f18d05672d83f2d1038692
Embedded URLs
- http://www.years
- http://.jpg
- http://www.interpretation
- https://www.recent
- http://www.wencodeURIComponent
- http://www.icon
- http://www.hortcut
- http://www.w3.org/shortcut
- http://.css
- http://www.css
Embedded domains
- big.int
- abi.name
- pkix.name
- godebugs.info
- dnsmessage.name
- golang.org
- v.to
- reflectlite.rtype.name
- unicode.to
- eq.io
- eq.net
- main.ws
- thing.org
- dressclipsroomsonkeymobilmain.name
- tos.org
- people.in
- the.com
- proprietaryoriginatingprestigiousgrammaticalexperience.to
- www.world
- w3.org
- www.w3.org
- www.years
- .jpg
- www.interpretation
- www.recent
Embedded IP addresses
- 5.4.62.5
- 4.32.5.4
- 52.5.4.72
- 5.4.82.5
- 5.4.102.5
- 4.112.5.4
- 8.8.8.8
- 4.14.2.1
- 4.14.1.1
- 4.12.1.1
- 4.9.1.1
- 4.1.1.1
- 2.3.1.1
- 2.2.1.1
- 1.1.1.1
- 20.42.179.192
- 4.247.188.233
- 74.178.76.44
- 4.150.223.99
File paths
- C:\Program
More AsyncRAT samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report