MALICIOUS — 9608f95f1a521ea315c54f68c2f9dadbab4bf695ca3845b1dfacd8ea5a2c275f.sh
MALICIOUS — 9608f95f1a521ea315c54f68c2f9dadbab4bf695ca3845b1dfacd8ea5a2c275f.sh is a shell sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (83/100), attributed to the Phonzy family. 3 of 39 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
9608f95f1a521ea315c54f68c2f9dadbab4bf695ca3845b1dfacd8ea5a2c275f - SHA-1:
027e11bf93b324930e8cb1bca49033fc98ea14f2 - MD5:
bcb8a6f290c95c434f0a7c2e6dace769 - ssdeep:
24:kXCKysE2hi0ziQvZohasF/2St5fy9b8kX:e9Qp+MssFuStZy9okX - TLSH:
T128116F26507483EF035FA7902048F56E184F73C69D32D45F5352DD1A8693F52A0376AE - Submitted as: 9608f95f1a521ea315c54f68c2f9dadbab4bf695ca3845b1dfacd8ea5a2c275f.sh
- File type: shell · Size: 848 bytes
- Verdict: malicious (83/100) · Family: Phonzy
Detections (3 of 39 engines)
- Microsoft Defender: Trojan:Script/Phonzy.B!ml
- Emsisoft (Emergency Kit): Trojan.GenericKD.80919377
- Kaspersky (KVRT): HEUR:Trojan-Downloader.Shell.Agent.a
MITRE ATT&CK
Why this verdict
The malicious score of 83/100 is the fusion of 5 weighted signals:
- 1 behavioral detection(s): Download-and-execute dropper (wget/curl + chmod) [high] (rule
tl-linux-download-exec) - dynamic signal, weight 0.60, confidence 0.90 - Microsoft Defender flagged Trojan:Script/Phonzy.B!ml (rule
Trojan:Script/Phonzy.B!ml) - engine signal, weight 0.55, confidence 0.85 - Embedded network infrastructure: http://129.121.114.124/CcDE, http://129.121.114.124/RGno, http://129.121.114.124/GD8 - static signal, weight 0.35, confidence 0.60
- Contacted 1 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
- Extracted generic config (6 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (linux)
768 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- 129.121.114.124:80
Embedded URLs
- http://129.121.114.124/CcDE
- http://129.121.114.124/RGno
- http://129.121.114.124/GD8
- http://129.121.114.124/iZ5O
- http://129.121.114.124/QRV
Embedded IP addresses
- 129.121.114.124
More Phonzy samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report