MALICIOUS — 9a868e1a9d35dcf8b2f27125310a0ccfb3881dea817ccdff6156b975a59d0ab7
MALICIOUS — 9a868e1a9d35dcf8b2f27125310a0ccfb3881dea817ccdff6156b975a59d0ab7 is a elf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100), attributed to the Vmsplice family. 4 of 57 detection engines flagged it.
Identification
- SHA-256:
9a868e1a9d35dcf8b2f27125310a0ccfb3881dea817ccdff6156b975a59d0ab7 - SHA-1:
3fcc4f3595620a297eab84fe6b95574e61e9bf1f - MD5:
77a2e362c329048edb4952ba2332e170 - ssdeep:
192:fOqKS3cM0tP+VJdPLXXQRP8J6vch9nRFbtKB:fX3cMcUHToPyAa9nRFbW - TLSH:
T18E24525746356B15CC9DB824544A8D3E2403B2BA2DBB86EC80D2DA2EF4B523745F306E - Submitted as: 9a868e1a9d35dcf8b2f27125310a0ccfb3881dea817ccdff6156b975a59d0ab7
- File type: elf · Size: 11674 bytes
- Verdict: malicious (98/100) · Family: Vmsplice
Detections (4 of 57 engines)
- ClamAV (daily): Unix.Exploit.Vmsplice-9832960-0
- Microsoft Defender: Exploit:Linux/Vmsplice.A!xp
- Emsisoft (Emergency Kit): Trojan.Linux.Generic.222661
- Kaspersky (KVRT): HEUR:Trojan.Linux.Agent.gen
Why this verdict
The malicious score of 98/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Unix.Exploit.Vmsplice-9832960-0 (rule
Unix.Exploit.Vmsplice-9832960-0) - engine signal, weight 0.90, confidence 0.95 - Microsoft Defender flagged Exploit:Linux/Vmsplice.A!xp (rule
Exploit:Linux/Vmsplice.A!xp) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Trojan.Linux.Generic.222661 (rule
Trojan.Linux.Generic.222661) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Trojan.Linux.Agent.gen (rule
HEUR:Trojan.Linux.Agent.gen) - engine signal, weight 0.55, confidence 0.85 - Embedded network infrastructure: 2.15.92.0 - static signal, weight 0.35, confidence 0.60
Dynamic analysis (linux)
869 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- desktop-hsgcbep
- ntp.ubuntu.com
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 252.0.0.224.in-addr.arpa
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- _dosvc._tcp.local
- ff02::1:3
- 224.0.0.252
- 10.240.0.255
- 10.240.0.1
- 224.0.0.251
- ff02::fb
- ff02::1:ff12:3456
- ff02::16
- 185.125.190.58
- 4.150.223.114 US · Des Moines · AS8075 Microsoft Corporation
- ff02::1
- 255.255.255.255
- 4.247.188.224 IN · Pune · AS8075 Microsoft Corporation
Embedded IP addresses
- 2.15.92.0
- 4.150.223.114
- 4.247.188.224
- 74.178.232.29
- 172.172.255.217
More Vmsplice samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report