SUSPICIOUS — 896f63d1435cd22055e0e9c1d240fb51291d8e870ce4e1df89c2922ffdd713ff.bin
SUSPICIOUS — 896f63d1435cd22055e0e9c1d240fb51291d8e870ce4e1df89c2922ffdd713ff.bin is a elf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (61/100), attributed to the Modified family. 5 of 53 detection engines flagged it.
Identification
- SHA-256:
896f63d1435cd22055e0e9c1d240fb51291d8e870ce4e1df89c2922ffdd713ff - SHA-1:
cef2a70afcf5d074de08414de40e31fea15819dc - MD5:
a2ff1a31fae2e5c6121706b5fe448abe - ssdeep:
1536:IcZ8/5tZ0/7qz3L7JgR/2lPSjmlSmVJu8:IR/r1vJ3jlSmVQ8 - TLSH:
T1CD33E19B7714A282E77B0C62548309AFB270660FDBA35D76F895948733CC05F8474AD4 - Submitted as: 896f63d1435cd22055e0e9c1d240fb51291d8e870ce4e1df89c2922ffdd713ff.bin
- File type: elf · Size: 51104 bytes
- Verdict: suspicious (61/100) · Family: Modified
Source: MalShare · first seen 2026-08-15T01:25:58.002Z · SHA-256 verified
Detections (5 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- YARA: Intezer community: INTEZER_ELF_UPX_Modified
- Detect It Easy (packer/type): DIE:UPX 3.94
- Microsoft Defender: Trojan:Script/Sabsik.EN.A!ml
- Kaspersky (KVRT): HEUR:Backdoor.Linux.Mirai.b
Why this verdict
The suspicious score of 61/100 is the fusion of 4 weighted signals:
- YARA: Intezer community flagged INTEZER_ELF_UPX_Modified (rule
INTEZER_ELF_UPX_Modified) - engine signal, weight 0.35, confidence 0.70 - Detect It Easy (packer/type) flagged DIE:UPX 3.94 (rule
DIE:UPX 3.94) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: http://upx.sf.net - static signal, weight 0.35, confidence 0.60
- Packing/obfuscation: high-entropy-blob, UPX 3.94 - static signal, weight 0.25, confidence 0.55
Dynamic analysis (linux)
893 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- desktop-hsgcbep._dosvc._tcp.local
- desktop-hsgcbep(1)._dosvc._tcp.local
- desktop-hsgcbep(2)._dosvc._tcp.local
- desktop-hsgcbep(3)._dosvc._tcp.local
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 252.0.0.224.in-addr.arpa
- desktop-hsgcbep
- 250.255.255.239.in-addr.arpa
- desktop-hsgcbep(4)._dosvc._tcp.local
- ntp.ubuntu.com
- ff02::1:3
- 224.0.0.252
- 224.0.0.251
- ff02::fb
- 10.240.0.1
- ff02::16
- 169.254.255.255
- 10.240.0.255
Embedded URLs
- http://upx.sf.net
Embedded domains
- upx.sf.net
Embedded IP addresses
- 135.233.95.144
More Modified samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report