SUSPICIOUS — 9ea600a96c3d6950bfbf5b98980bad957a88441307a1cb8e3c6a21b3bdc65d12.elf
SUSPICIOUS — 9ea600a96c3d6950bfbf5b98980bad957a88441307a1cb8e3c6a21b3bdc65d12.elf is a elf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (55/100), attributed to the REvil family. 4 of 53 detection engines flagged it.
Identification
- SHA-256:
9ea600a96c3d6950bfbf5b98980bad957a88441307a1cb8e3c6a21b3bdc65d12 - SHA-1:
e9a14e56848eebb309e8a5ec3230a63ae53f9afc - MD5:
94ec77ae0de759460f4fb1a4544dc302 - ssdeep:
24576:smmoodEfzjvFMnVIH06iyGyOxDRIv6nLXmSNTOmtYSeeBCtCVGvY:smRVwIU6i/VIv6nrmSNRtYSFBCtCV - TLSH:
T18C597C5542937368C6EAAE43A471CD9DE045F44CE2712EC59107A36FA2E830FEAF04B5 - Submitted as: 9ea600a96c3d6950bfbf5b98980bad957a88441307a1cb8e3c6a21b3bdc65d12.elf
- File type: elf · Size: 1916896 bytes
- Verdict: suspicious (55/100) · Family: REvil
Source: MalwareBazaar · first seen 2026-08-01T00:00:00.000Z · SHA-256 verified
Detections (4 of 53 engines)
- YARA: Trellix/McAfee ATR: ATR_REvil_Sodinokibi
- YARA: Stratosphere IPS: STRATO_Tor_Onion_C2
- Emsisoft (Emergency Kit): Trojan.Linux.GenericKD.60054769
- Kaspersky (KVRT): HEUR:Trojan-PSW.Linux.Agent.c
Why this verdict
The suspicious score of 55/100 is the fusion of 3 weighted signals:
- YARA: Trellix/McAfee ATR flagged ATR_REvil_Sodinokibi (rule
ATR_REvil_Sodinokibi) - engine signal, weight 0.35, confidence 0.70 - YARA: Stratosphere IPS flagged STRATO_Tor_Onion_C2 (rule
STRATO_Tor_Onion_C2) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: http://127.0.0.1:8738, https://registry.npmjs.org/, https://server.exodus.io/connect-src - static signal, weight 0.35, confidence 0.60
Dynamic analysis (linux)
969 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- desktop-hsgcbep
- ntp.ubuntu.com
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 252.0.0.224.in-addr.arpa
- 255.255.254.169.in-addr.arpa
- 79.243.254.169.in-addr.arpa
- 250.255.255.239.in-addr.arpa
- ff02::1:3
- 224.0.0.252
- 169.254.255.255
- 10.240.0.1
- 10.240.0.255
- ff02::fb
- 224.0.0.251
- ff02::16
- 185.125.190.58
- 239.255.255.250
- ff02::1
Embedded URLs
- http://127.0.0.1:8738
- https://registry.npmjs.org/
- https://server.exodus.io/connect-src
- https://docs.rs/rustls/latest/rustls/manual/_03_howto/index.html#unexpected-eofkey
Embedded domains
- temp.sh
- registry.npmjs.org
- users.noreply.github.com
- server.exodus.io
- openssl.org
- docs.rs
More REvil samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report