MALICIOUS — 62391b72b68d578789af3b829120049600cf70243c274e8680f43e693495b222
MALICIOUS — 62391b72b68d578789af3b829120049600cf70243c274e8680f43e693495b222 is a script sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (88/100), attributed to the AMTB family. 3 of 51 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
62391b72b68d578789af3b829120049600cf70243c274e8680f43e693495b222 - SHA-1:
b17aff09b07c38998b79ec432b2abd0d14284583 - MD5:
decc19c950973f8faac31c6e351b81bf - ssdeep:
48:2FFFFFFFFFFFi+FFlFFFFFFFFFFFi+FFlFFFFFFFFFFFi+FFlF2FFFFFFFFFFFil:fllgl - TLSH:
T16F1A01D01E8DC871E668E04F1F69DC4D73121182EECEB066FB59F31A124E78624A6660 - Submitted as: 62391b72b68d578789af3b829120049600cf70243c274e8680f43e693495b222
- File type: script · Size: 4416 bytes
- Verdict: malicious (88/100) · Family: AMTB
Detections (3 of 51 engines)
- Microsoft Defender: Trojan:BAT/Bomb!AMTB
- Emsisoft (Emergency Kit): Gen:Heur.Bat.1
- Kaspersky (KVRT): Trojan.BAT.Bomb.f
MITRE ATT&CK
Why this verdict
The malicious score of 88/100 is the fusion of 5 weighted signals:
- Microsoft Defender flagged Trojan:BAT/Bomb!AMTB (rule
Trojan:BAT/Bomb!AMTB) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Gen:Heur.Bat.1 (rule
Gen:Heur.Bat.1) - engine signal, weight 0.55, confidence 0.85 - 1 behavioral detection(s): Remote payload download (wget/curl) [medium] (rule
tl-linux-download-cradle) - dynamic signal, weight 0.40, confidence 0.90 - Anti-analysis: T1497 - dynamic signal, weight 0.40, confidence 0.75
- Contacted 8 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
Dynamic analysis (linux)
884 behavior events · 0 ATT&CK techniques · 1 dropped files.
Runtime network
- entropy.ubuntu.com
- _dosvc._tcp.local
- desktop-hsgcbep._dosvc._tcp.local
- desktop-hsgcbep(1)._dosvc._tcp.local
- ntp.ubuntu.com
- 185.125.189.54:443
- 10.240.0.1
- ff02::fb
- 224.0.0.251
- 255.255.255.255
- ff02::16
- ff02::1:ff12:3456
- 85.210.196.11
- 203.26.79.13
- 185.125.190.57
- 185.125.190.56
- ff02::2
- 185.125.189.54
- 172.215.188.232
- 185.125.190.58
Dropped files
- tmp_tmp.5z9ItlX57O -
2b4f8f95e78afc474cd62a1617e78f8e570e63435e482d5a71bee21125226bc2
Embedded IP addresses
- 85.210.196.11
- 203.26.79.13
- 172.215.188.232
More AMTB samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report