MALICIOUS — Linux.Wirenet.elf
MALICIOUS — Linux.Wirenet.elf is a elf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100), attributed to the Wirenet family. 5 of 53 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
35ff79dd456fe3054a60fe0a16f38bf5fc3928e1e8439ca4d945573f8c48c0b8 - SHA-1:
5996d02c142588b6c1ed850e461845458bd94d17 - MD5:
9a0e765eecc5433af3dc726206ecc56e - ssdeep:
1536:CkdOMtSwcfp9f25MgHmtS+IekQiPT5cL:CkdOMtufO5MgmYxQiP - TLSH:
T1D636E4DE4128576BF2C46220A8775ABE801FB06A71331BDC02C1D12DF2FD56BE5BA056 - Submitted as: Linux.Wirenet.elf
- File type: elf · Size: 64400 bytes
- Verdict: malicious (92/100) · Family: Wirenet
Detections (5 of 53 engines)
- capa (capabilities): capability:credential-access
- ClamAV (daily): {MD5}bin.trojan.wirenet.9332.UNOFFICIAL
- Microsoft Defender: Backdoor:Linux/NetWiredRC.A
- Emsisoft (Emergency Kit): Trojan.Linux.Netweird.1
- Kaspersky (KVRT): Backdoor.Linux.Wirenet.a
MITRE ATT&CK
Why this verdict
The malicious score of 92/100 is the fusion of 3 weighted signals:
- ClamAV (daily) flagged {MD5}bin.trojan.wirenet.9332.UNOFFICIAL (rule
{MD5}bin.trojan.wirenet.9332.UNOFFICIAL) - engine signal, weight 0.90, confidence 0.95 - access stored credentials (rule
access stored credentials) - capa signal, weight 0.50, confidence 0.80 - Contacted 8 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
Dynamic analysis (linux)
873 behavior events · 0 ATT&CK techniques · 1 dropped files.
Runtime network
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- desktop-hsgcbep
- 250.255.255.239.in-addr.arpa
- 252.0.0.224.in-addr.arpa
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- ntp.ubuntu.com
- ff02::1:3
- 224.0.0.252
- 10.240.0.255
- 169.254.255.255
- 224.0.0.251
- ff02::fb
- ff02::1:ff4c:1d1d
- ff02::1
- ff02::16
- ff02::2
- 10.240.0.1
- 239.255.255.250
- 20.190.142.164
Dropped files
- tmp_tmp.iaaA6ptcGj -
8a8c07189b1a684a2bdf3b01aaa73d4794a8078a9f5544d7a4bfd03568503fde
Embedded IP addresses
- 74.178.76.128
- 104.18.38.233
More Wirenet samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report