MALICIOUS — ab106f6ec3f5a63ce5d6ca9c2d7ba785348cfa93b68c6f0bb0827fc49011ee75.bin
MALICIOUS — ab106f6ec3f5a63ce5d6ca9c2d7ba785348cfa93b68c6f0bb0827fc49011ee75.bin is a shell sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (84/100), attributed to the Shell family. 1 of 53 detection engines flagged it.
Identification
- SHA-256:
ab106f6ec3f5a63ce5d6ca9c2d7ba785348cfa93b68c6f0bb0827fc49011ee75 - SHA-1:
7e48200b4bd3bf02b8bbf9681bdc891eb5404862 - MD5:
f1a53465f4cc8d50959ecdfbdc2f74b9 - ssdeep:
24:aqgEm6llrru3DJ1TZ4uFJ8kdh1QXN8BLK0F/CfXO:Pllry3DJ1WuFhHCNzC/Cfe - TLSH:
T111148637E20172CA23275711952ADCF007B75E49DF723D0E11A2150EDD47A27EE2B16A - Submitted as: ab106f6ec3f5a63ce5d6ca9c2d7ba785348cfa93b68c6f0bb0827fc49011ee75.bin
- File type: shell · Size: 1608 bytes
- Verdict: malicious (84/100) · Family: Shell
Source: MalShare · first seen 2026-09-08T11:35:21.456Z · SHA-256 verified
Detections (1 of 53 engines)
- Kaspersky (KVRT): HEUR:Trojan-Downloader.Shell.Agent.a
Why this verdict
The malicious score of 84/100 is the fusion of 5 weighted signals:
- Kaspersky (KVRT) flagged HEUR:Trojan-Downloader.Shell.Agent.a (rule
HEUR:Trojan-Downloader.Shell.Agent.a) - engine signal, weight 0.55, confidence 0.85 - Obfuscated unknown script: download (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Contacted 2 external host(s) and 12 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- Embedded network infrastructure: http://5.182.210.174/83af79, http://5.182.210.174/09f349, http://5.182.210.174/29c60c - static signal, weight 0.35, confidence 0.60
- Extracted generic config (13 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (linux)
535 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- ntp.ubuntu.com
- 5.182.210.174/83af79
- 5.182.210.174/09f349
- 5.182.210.174/29c60c
- 5.182.210.174/78d7b3
- 5.182.210.174/d58ebc
- 5.182.210.174/971c2a
- 5.182.210.174/bbcf8c
- 5.182.210.174/6fdf60
- 5.182.210.174/bc8782
- 5.182.210.174/4dc39a
- 5.182.210.174/32e510
- 5.182.210.174/82e167
- 5.182.210.174:80 NL · Amsterdam · AS64425 SKB Enterprise B.V.
- 5.182.210.174 NL · Amsterdam · AS64425 SKB Enterprise B.V.
- 10.240.0.1
- 185.125.190.58
- ff02::16
- 255.255.255.255
- ff02::1:ff12:3456
Embedded URLs
- http://5.182.210.174/83af79
- http://5.182.210.174/09f349
- http://5.182.210.174/29c60c
- http://5.182.210.174/78d7b3
- http://5.182.210.174/d58ebc
- http://5.182.210.174/971c2a
- http://5.182.210.174/bbcf8c
- http://5.182.210.174/6fdf60
- http://5.182.210.174/bc8782
- http://5.182.210.174/4dc39a
- http://5.182.210.174/32e510
- http://5.182.210.174/82e167
Embedded IP addresses
- 5.182.210.174
More Shell samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report