MALICIOUS — 3f3bf218089d1488617d37f8a5116bb2791eb39ce06a1b5bc9a4cdfe5e94dd39.bin
MALICIOUS — 3f3bf218089d1488617d37f8a5116bb2791eb39ce06a1b5bc9a4cdfe5e94dd39.bin is a elf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 6 of 57 detection engines flagged it.
Identification
- SHA-256:
3f3bf218089d1488617d37f8a5116bb2791eb39ce06a1b5bc9a4cdfe5e94dd39 - SHA-1:
aa389c5fabc812bea68056224e3c58c6c5e43775 - MD5:
117dd0c3e5b37e2db85305cc57d34730 - ssdeep:
24576:25j9xYk56Ulw+g3kDqEMX8dKQVT2ZfZolXqr8OmF+AzM/qe8NFb8+GDGeMH:Gh/wFkDqEMM7KZo0ECqe8NHQ1K - TLSH:
T1FB5833BAB342F140819E62EE02B7E8DFF59F581641829892287D5A30FF45F7C69D8143 - Submitted as: 3f3bf218089d1488617d37f8a5116bb2791eb39ce06a1b5bc9a4cdfe5e94dd39.bin
- File type: elf · Size: 1759768 bytes
- Verdict: malicious (96/100)
Source: MalShare · first seen 2026-09-16T06:37:34.443Z · SHA-256 verified
Detections (6 of 57 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- YARA: Intezer community: INTEZER_ELF_UPX_Modified
- Detect It Easy (packer/type): DIE:UPX 5.20
- Microsoft Defender: Trojan:Win32/Malgent
- Emsisoft (Emergency Kit): Trojan.Linux.GenericKD.60054706
- Kaspersky (KVRT): HEUR:Trojan.Linux.Agent.gen
Why this verdict
The malicious score of 96/100 is the fusion of 8 weighted signals:
- Microsoft Defender flagged Trojan:Win32/Malgent (rule
Trojan:Win32/Malgent) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Trojan.Linux.GenericKD.60054706 (rule
Trojan.Linux.GenericKD.60054706) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Trojan.Linux.Agent.gen (rule
HEUR:Trojan.Linux.Agent.gen) - engine signal, weight 0.55, confidence 0.85 - YARA: Intezer community flagged INTEZER_ELF_UPX_Modified (rule
INTEZER_ELF_UPX_Modified) - engine signal, weight 0.40, confidence 0.70 - Detect It Easy (packer/type) flagged DIE:UPX 5.20 (rule
DIE:UPX 5.20) - engine signal, weight 0.35, confidence 0.70 - MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: http://upx.sf.net - static signal, weight 0.35, confidence 0.60
- Packing/obfuscation: high-entropy-blob, UPX 5.20 - static signal, weight 0.25, confidence 0.55
Dynamic analysis (linux)
837 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- ntp.ubuntu.com
- 10.240.0.76
- 10.240.0.1
- 185.125.190.57
- ff02::1
- ff02::2
- ff02::1:ff12:3456
- ff02::16
- 255.255.255.255
Embedded URLs
- http://upx.sf.net
Embedded domains
- p.fr
- 2y.cf
- upx.sf.net
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report