MALICIOUS — 4a9665680fe3a301eb6d2a0f63a3e4e7e656bb44380450cc24e0162fa5915211.elf
MALICIOUS — 4a9665680fe3a301eb6d2a0f63a3e4e7e656bb44380450cc24e0162fa5915211.elf is a elf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (97/100), attributed to the Multiverze family. 6 of 54 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
4a9665680fe3a301eb6d2a0f63a3e4e7e656bb44380450cc24e0162fa5915211 - SHA-1:
9daaaa1a7216add77a52aac77ffca2bfb810e482 - MD5:
5240d5c601906582a96468d27b3b6f14 - ssdeep:
3072:HkHGaKri/9fKF9OeZUV9/jgcT5offv7FdlFGlTmd:Hk3/dK7MccifQyd - TLSH:
T1863D12B8D1016757DD15EC6665C510BC1083EE4A343DCF2CA054DAC6BAEB8278BE862B - Submitted as: 4a9665680fe3a301eb6d2a0f63a3e4e7e656bb44380450cc24e0162fa5915211.elf
- File type: elf · Size: 127988 bytes
- Verdict: malicious (97/100) · Family: Multiverze
Source: MalwareBazaar · first seen 2026-07-27T00:00:00.000Z · SHA-256 verified
Detections (6 of 54 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- YARA: Intezer community: INTEZER_ELF_UPX_Modified
- Detect It Easy (packer/type): DIE:UPX 4.00
- Microsoft Defender: Trojan:Linux/Multiverze!rfn
- Emsisoft (Emergency Kit): Trojan.Linux.Mirai.39415609
- Kaspersky (KVRT): HEUR:Trojan.Linux.Alien.gen
MITRE ATT&CK
Why this verdict
The malicious score of 97/100 is the fusion of 10 weighted signals:
- Memory forensics: 1 finding(s), e.g. injected region in w1wl3s43gmgrjv6 (pid 728) (rule
linux.malfind.Malfind) - memory signal, weight 0.60, confidence 0.85 - Microsoft Defender flagged Trojan:Linux/Multiverze!rfn (rule
Trojan:Linux/Multiverze!rfn) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Trojan.Linux.Mirai.39415609 (rule
Trojan.Linux.Mirai.39415609) - engine signal, weight 0.55, confidence 0.85 - 1 behavioral detection(s): Remote payload download (wget/curl) [medium] (rule
tl-linux-download-cradle) - dynamic signal, weight 0.40, confidence 0.90 - YARA: Intezer community flagged INTEZER_ELF_UPX_Modified (rule
INTEZER_ELF_UPX_Modified) - engine signal, weight 0.35, confidence 0.70 - Detect It Easy (packer/type) flagged DIE:UPX 4.00 (rule
DIE:UPX 4.00) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: http://upx.sf.net - static signal, weight 0.35, confidence 0.60
- Packing/obfuscation: high-entropy-blob, UPX 4.00 - static signal, weight 0.25, confidence 0.55
- Contacted 12 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
- Extracted generic config (1 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (linux)
881 behavior events · 0 ATT&CK techniques · 1 dropped files.
Runtime network
- desktop-hsgcbep._dosvc._tcp.local
- desktop-hsgcbep(1)._dosvc._tcp.local
- entropy.ubuntu.com
- poop.garden
- _dosvc._tcp.local
- ntp.ubuntu.com
- 1.1.1.1:53
- 178.83.206.213:80
- 185.125.189.54
- 1.1.1.1
- 10.240.0.76
- 10.240.0.1
- 178.83.206.213
- 224.0.0.251
- ff02::fb
- 203.26.79.13
- 185.125.190.57
- 172.172.255.217
- 20.190.142.167
- 91.189.91.157
Dropped files
- tmp_tmp.bIGkQXADqF -
c4ed1d6417c8cb31753e41f6ab6d952d9b5c716d9f00c9a06838dec0e3a179ec
Embedded URLs
- http://upx.sf.net
Embedded domains
- upx.sf.net
- poop.garden
Embedded IP addresses
- 178.83.206.213
- 203.26.79.13
- 172.172.255.217
- 20.190.142.167
- 13.89.179.12
- 172.172.255.216
More Multiverze samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report