MALICIOUS — ad19b70c4e523ef24baf5e062d2200e139b619b56049219d41cd0397faff2c40.bin
MALICIOUS — ad19b70c4e523ef24baf5e062d2200e139b619b56049219d41cd0397faff2c40.bin is a shell sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (95/100). 2 of 54 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
ad19b70c4e523ef24baf5e062d2200e139b619b56049219d41cd0397faff2c40 - SHA-1:
45fb55faaa52f0414ac97c99d5e326ebc5496b63 - MD5:
18e1fdc1ae09894301b4c1655b3c5f66 - ssdeep:
48:4CCpOCmhpi0p2BpaUGzp2V22G9TezXqD90ooWwuLtrGxzGzZ4tFB07:yQFcAf3wuLtrGxzGzZ4tFB07 - TLSH:
T1F915B2195C9B24796BEEB25FFC8988E4C9B273C9FA7197495282F00049ABCC64E4C445 - Submitted as: ad19b70c4e523ef24baf5e062d2200e139b619b56049219d41cd0397faff2c40.bin
- File type: shell · Size: 2107 bytes
- Verdict: malicious (95/100)
Source: MalShare · first seen 2026-08-23T16:10:06.766Z · SHA-256 verified
Detections (2 of 54 engines)
- Microsoft Defender: flagged
- Kaspersky (KVRT): UDS:Trojan-Downloader.Shell.Agent
MITRE ATT&CK
Why this verdict
The malicious score of 95/100 is the fusion of 7 weighted signals:
- Microsoft Defender flagged flagged (rule
flagged) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged UDS:Trojan-Downloader.Shell.Agent (rule
UDS:Trojan-Downloader.Shell.Agent) - engine signal, weight 0.55, confidence 0.85 - Obfuscated unknown script: download (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - 1 behavioral detection(s) across 1 rule(s): Remote payload download (wget/curl) [medium] (rule
tl-linux-download-cradle) - dynamic signal, weight 0.40, confidence 0.90 - Contacted 6 external host(s) and 1 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- Embedded network infrastructure: http://176.65.139.202/daredevil.armv7l, http://176.65.139.202/daredevil.mips, http://176.65.139.202/daredevil.mipsel - static signal, weight 0.35, confidence 0.60
- Extracted generic config (15 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (linux)
886 behavior events · 0 ATT&CK techniques · 1 dropped files.
Runtime network
- desktop-hsgcbep
- ntp.ubuntu.com
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 252.0.0.224.in-addr.arpa
- _dosvc._tcp.local
- 176.65.139.202/daredevil.armv7l
- 176.65.139.202:80 DE · AS219502 STORMCLOUD-AS - Storm Industries LLC, US
- ff02::1:3
- 224.0.0.252
- 10.240.0.255
- 10.240.0.1
- ff02::fb
- 224.0.0.251
- 20.42.179.204 US · Moses Lake · AS8075 Microsoft Corporation
- 4.247.188.224 IN · Pune · AS8075 Microsoft Corporation
- 91.189.91.157
- ff02::16
- 224.0.0.22
Dropped files
- tmp_daredevil.armv7l -
651c6e0e9767b11427b38ee907ae193a99e39de95261596c52db8f86f80e0d5b
Embedded URLs
- http://176.65.139.202/daredevil.armv7l
- http://176.65.139.202/daredevil.mips
- http://176.65.139.202/daredevil.mipsel
- http://176.65.139.202/daredevil.armv5l
- http://176.65.139.202/daredevil.armv6l
- http://176.65.139.202/daredevil.x86_64
- http://176.65.139.202/daredevil.armv4l
- http://176.65.139.202/daredevil.arc
- http://176.65.139.202/daredevil.i486
- http://176.65.139.202/daredevil.m68k
- http://176.65.139.202/daredevil.mipsrouter
- http://176.65.139.202/daredevil.powerpc
- http://176.65.139.202/daredevil.sh4
- http://176.65.139.202/daredevil.sparc
Embedded IP addresses
- 176.65.139.202
- 20.42.179.204
- 4.247.188.224
- 4.150.223.111
- 74.178.76.44
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report