SUSPICIOUS — a2bf687d8dee6a3a4d1531a46a3291e2f17a7a165ae40647621a72322b432e0e.elf
SUSPICIOUS — a2bf687d8dee6a3a4d1531a46a3291e2f17a7a165ae40647621a72322b432e0e.elf is a elf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (47/100), attributed to the mimban family. 3 of 56 detection engines flagged it.
Identification
- SHA-256:
a2bf687d8dee6a3a4d1531a46a3291e2f17a7a165ae40647621a72322b432e0e - SHA-1:
f2314f43f7fc53d4dde9523c70921785e1d03dd9 - MD5:
6ee6967ec03d02d3f25be3dd9a9f672e - ssdeep:
24576:tC7+cWufxGPdVHf+6YVN3JLl3UiifSJXSFi9xYv4yC28uEUyo:tJc9fxGFVFY3ZLl3UjfsXSFi9xYeJ - TLSH:
T183585CA804673311D2B9AE01B06114EDA107F958B17C7CAA420B693991F93EFDAF1DD3 - Submitted as: a2bf687d8dee6a3a4d1531a46a3291e2f17a7a165ae40647621a72322b432e0e.elf
- File type: elf · Size: 1727016 bytes
- Verdict: suspicious (47/100) · Family: mimban
Source: MalwareBazaar · first seen 2026-08-02T00:00:00.000Z · SHA-256 verified
Detections (3 of 56 engines)
- YARA: ESET research: mimban
- Emsisoft (Emergency Kit): Trojan.Linux.GenericKD.60054801
- Kaspersky (KVRT): HEUR:Trojan.Linux.Agent.gen
Why this verdict
The suspicious score of 47/100 is the fusion of 4 weighted signals:
- YARA: ESET research flagged mimban (rule
mimban) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://www.bing.com/, https://duckduckgo.com/, https://www.facebook.com/ - static signal, weight 0.35, confidence 0.60
- Contacted 4 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
- Extracted generic config (14 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (linux)
916 behavior events · 0 ATT&CK techniques · 1 dropped files.
Runtime network
- desktop-hsgcbep
- 250.255.255.239.in-addr.arpa
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 252.0.0.224.in-addr.arpa
- 255.255.254.169.in-addr.arpa
- 79.243.254.169.in-addr.arpa
- ff02::1:3
- 224.0.0.252
- ff02::fb
- 224.0.0.251
- 169.254.255.255
- 10.240.0.255
- 10.240.0.1
- ff02::16
- 239.255.255.250
- ff02::1:ff12:3456
- ff02::1
- ff02::2
Dropped files
- var_tmp_.eclipse -
a2bf687d8dee6a3a4d1531a46a3291e2f17a7a165ae40647621a72322b432e0e
Embedded URLs
- https://www.google.com/
- https://www.bing.com/
- https://duckduckgo.com/
- https://www.facebook.com/
- https://twitter.com/
- https://bugs.launchpad.net/ubuntu/+source/glibc/+bugs
Embedded domains
- www.google.com
- www.bing.com
- duckduckgo.com
- www.facebook.com
- twitter.com
- bugs.launchpad.net
Embedded IP addresses
- 2.26.48.37
- 217.181.80.244
- 217.181.80.107
- 217.181.80.196
- 217.181.81.7
- 217.181.81.190
- 217.181.81.32
- 217.181.82.186
- 217.181.82.108
- 217.181.82.25
- 217.181.83.61
- 217.181.83.222
- 217.181.83.33
- 195.63.16.122
- 195.63.16.71
- 195.63.16.221
- 195.63.17.155
- 195.63.17.42
- 195.63.17.190
- 195.63.18.150
- 195.63.18.180
- 195.63.19.229
- 195.63.19.195
- 195.63.19.182
- 195.63.20.5
More mimban samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report