CLEAN — get_ss.py
CLEAN — get_ss.py is a shell sample analyzed by MalwareAnalyzer by Cyble with a clean verdict (21/100). 0 of 53 detection engines flagged it.
Identification
- SHA-256:
52ceb58ed78277277a5d724ee179bee2fc4ce23f221c2acb880402b05a73213d - SHA-1:
08d1a58b952e54bec82bc8ace6585c77fa5b0768 - MD5:
0c7285fcdb753bf64478e9b2565325f4 - ssdeep:
96:hKBw6fjABI0xlNWxmhvowagw3AtioHP+1UXmTv:Yf8umfwCEY/MUXmz - TLSH:
T1B6172138D049B89F65C82DAA2D98417C44A5D1F8629134D35FE867007A22ED8F04F7AE - Submitted as: get_ss.py
- File type: shell · Size: 3449 bytes
- Verdict: clean (21/100)
Detections (0 of 53 engines)
No engine flagged this sample.
Why this verdict
The clean score of 21/100 is the fusion of 1 weighted signal:
- Embedded network infrastructure: https://html.duckduckgo.com/html/ - static signal, weight 0.35, confidence 0.60
Dynamic analysis (linux)
866 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 252.0.0.224.in-addr.arpa
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- desktop-hsgcbep
- ntp.ubuntu.com
- 250.255.255.239.in-addr.arpa
- 199.232.138.172
- ff02::1:3
- 224.0.0.252
- ff02::fb
- 224.0.0.251
- 10.240.0.255
- 10.240.0.1
- 239.255.255.250
- 91.189.91.157
- 52.123.128.14 US · Redmond · AS8075 Microsoft Corporation
- 224.0.0.22
- 20.42.179.204 US · Moses Lake · AS8075 Microsoft Corporation
- 185.125.190.58
Embedded URLs
- https://html.duckduckgo.com/html/
Embedded domains
- duckduckgo.com
- youtube.com
- wikipedia.org
- linkedin.com
- facebook.com
- instagram.com
- x.com
- twitter.com
- leadiq.com
- html.duckduckgo.com
Embedded IP addresses
- 52.123.128.14
- 20.42.179.204
- 52.168.117.175
- 72.145.35.108
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report