SUSPICIOUS — 354e25b8537255b9ec4bf63c0cb833d6c7e8e4bb7518c9c11f8882e692fe446f.bin
SUSPICIOUS — 354e25b8537255b9ec4bf63c0cb833d6c7e8e4bb7518c9c11f8882e692fe446f.bin is a shell sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (68/100), attributed to the STRATO family. 1 of 53 detection engines flagged it.
Identification
- SHA-256:
354e25b8537255b9ec4bf63c0cb833d6c7e8e4bb7518c9c11f8882e692fe446f - SHA-1:
216fc19d7a7fc19bbabffea2e0cfd45e252359a1 - MD5:
f2d2cd251e1517ddde728b2a2e32c86c - ssdeep:
1536:pXYnXsje+9sKmKiUaXIDobSZLloiUFTyKRn2N3wjLHDzSRVk2Jr0jeS:p6S9loBTyK5H6dJAaS - TLSH:
T14D3AE735F3D93DFF978C1A998C1D10BF840361CB6A859BA1758E7A17410BD242C29ACE - Submitted as: 354e25b8537255b9ec4bf63c0cb833d6c7e8e4bb7518c9c11f8882e692fe446f.bin
- File type: shell · Size: 98704 bytes
- Verdict: suspicious (68/100) · Family: STRATO
Source: MalShare · first seen 2026-09-16T14:32:35.558Z · SHA-256 verified
Detections (1 of 53 engines)
- YARA: Stratosphere IPS: STRATO_Malicious_UserAgent
Why this verdict
The suspicious score of 68/100 is the fusion of 3 weighted signals:
- Obfuscated powershell script: download, dynamic-exec, shellcode-injection, defense-evasion (layers: base64) (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - YARA: Stratosphere IPS flagged STRATO_Malicious_UserAgent (rule
STRATO_Malicious_UserAgent) - engine signal, weight 0.45, confidence 0.70 - Embedded network infrastructure: http://rippr.cc/u, http://37.0.11.220/a/wget.sh, http://purenetworks.com/HNAP1/GetDeviceSettings/ - static signal, weight 0.35, confidence 0.60
Dynamic analysis (linux)
544 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- ntp.ubuntu.com
- 10.240.0.1
- ff02::16
- 255.255.255.255
- ff02::1:ff12:3456
- ff02::2
- 91.189.91.157
Embedded URLs
- http://rippr.cc/u
- http://37.0.11.220/a/wget.sh
- http://purenetworks.com/HNAP1/GetDeviceSettings/
Embedded domains
- wget.sh
- rippr.cc
- 20wget.sh
- 20splash.sh
- time.nist.gov
- www.google.com
- purenetworks.com
Embedded IP addresses
- 1.1.1.1
- 12.12.12.12
- 37.0.11.220
More STRATO samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report