SUSPICIOUS — 64c90fb3d1fb2582d3d978e7bc8d960ada8dad8443a6f9156454ab5d30e7f5dd
SUSPICIOUS — 64c90fb3d1fb2582d3d978e7bc8d960ada8dad8443a6f9156454ab5d30e7f5dd is a elf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (47/100). 1 of 57 detection engines flagged it.
Identification
- SHA-256:
64c90fb3d1fb2582d3d978e7bc8d960ada8dad8443a6f9156454ab5d30e7f5dd - SHA-1:
37eaa2db420e413fd94be28a2fc2866ad1b5e392 - MD5:
2ea437a9ea82377f20bc558c30b042f9 - ssdeep:
96:ClcTnzSahljV7Xt+QAT9SKupvBoJdg5JPhzU8zyDZMO2zlWNMkrCMxZPTBd9ljTK:ClcTnOaDjV79bAT9SK0WIyDZA0LB9XYd - TLSH:
T15A1CC6468E6555E5F42E01EDCCA2063C006A15CE0D14DEA803DF5C7B0AE1BC79DB21BE - Submitted as: 64c90fb3d1fb2582d3d978e7bc8d960ada8dad8443a6f9156454ab5d30e7f5dd
- File type: elf · Size: 5744 bytes
- Verdict: suspicious (47/100)
Detections (1 of 57 engines)
- Emsisoft (Emergency Kit): Trojan.Linux.Mozi.19
Why this verdict
The suspicious score of 47/100 is the fusion of 1 weighted signal:
- Emsisoft (Emergency Kit) flagged Trojan.Linux.Mozi.19 (rule
Trojan.Linux.Mozi.19) - engine signal, weight 0.55, confidence 0.85
Dynamic analysis (linux)
844 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- desktop-hsgcbep
- ntp.ubuntu.com
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 252.0.0.224.in-addr.arpa
- ff02::1:3
- 224.0.0.252
- 10.240.0.255
- 10.240.0.1
- 224.0.0.251
- ff02::fb
- 20.42.72.131 US · Ashburn · AS8075 Microsoft Corporation
- 185.125.190.56
- 4.207.44.76 IE · Dublin · AS8075 Microsoft Corporation
- 4.247.188.224 IN · Pune · AS8075 Microsoft Corporation
- 85.210.196.11 GB · London · AS8075 Microsoft Limited
- ff02::2
- 4.150.223.96 US · Des Moines · AS8075 Microsoft Corporation
- 255.255.255.255
Embedded IP addresses
- 20.42.72.131
- 4.207.44.76
- 4.247.188.224
- 85.210.196.11
- 4.150.223.96
- 20.42.179.192
- 57.155.104.224
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report