MALICIOUS — 859ee2ee778782c9274bd3c892be60ad1b4a9cd7c87a17fc8dc7a8c4565e31e3.bin
MALICIOUS — 859ee2ee778782c9274bd3c892be60ad1b4a9cd7c87a17fc8dc7a8c4565e31e3.bin is a elf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100). 5 of 57 detection engines flagged it.
Identification
- SHA-256:
859ee2ee778782c9274bd3c892be60ad1b4a9cd7c87a17fc8dc7a8c4565e31e3 - SHA-1:
0eb6fbd15a2588f3ff8469e5c7a8911e22f2c62f - MD5:
db4b18e58bdb9eee360c8d94a65b1c5e - ssdeep:
196608:+zb9nnB77ZiO5bCaEbm2t2CTLXn8PqAZkHTJ:+zpB75Tc2Y2kH1 - TLSH:
T12A6B33E4108D8AB225952B077B6D73C590964C3D7CD28AD31881F4ABACE3345DCE4E7A - Submitted as: 859ee2ee778782c9274bd3c892be60ad1b4a9cd7c87a17fc8dc7a8c4565e31e3.bin
- File type: elf · Size: 10582868 bytes
- Verdict: malicious (92/100)
Source: MalShare · first seen 2026-09-16T06:17:34.516Z · SHA-256 verified
Detections (5 of 57 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- YARA: Intezer community: INTEZER_ELF_UPX_Modified
- Detect It Easy (packer/type): DIE:UPX 5.11
- Microsoft Defender: HackTool:Linux/Fscan!rfn
- Kaspersky (KVRT): HEUR:HackTool.Linux.Agent.gen
Why this verdict
The malicious score of 92/100 is the fusion of 7 weighted signals:
- Microsoft Defender flagged HackTool:Linux/Fscan!rfn (rule
HackTool:Linux/Fscan!rfn) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:HackTool.Linux.Agent.gen (rule
HEUR:HackTool.Linux.Agent.gen) - engine signal, weight 0.55, confidence 0.85 - YARA: Intezer community flagged INTEZER_ELF_UPX_Modified (rule
INTEZER_ELF_UPX_Modified) - engine signal, weight 0.40, confidence 0.70 - Detect It Easy (packer/type) flagged DIE:UPX 5.11 (rule
DIE:UPX 5.11) - engine signal, weight 0.35, confidence 0.70 - MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: http://upx.sf.net - static signal, weight 0.35, confidence 0.60
- Packing/obfuscation: high-entropy-blob, UPX 5.11 - static signal, weight 0.25, confidence 0.55
Dynamic analysis (linux)
821 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- ntp.ubuntu.com
- 10.240.0.1
- 185.125.190.56
- ff02::2
- ff02::1
- ff02::1:ff12:3456
- ff02::16
- 255.255.255.255
Embedded URLs
- http://upx.sf.net
Embedded domains
- 8.us
- pi.be
- 2rhp.mx
- i0.tw
- 5dff4d3.it
- z.eu
- 0.tv
- y.mx
- z.nl
- x0o.in
- ub.com
- ippo.io
- upx.sf.net
File paths
- v:\^:
- H:\((hn7
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report