SUSPICIOUS — tmp_busybox
SUSPICIOUS — tmp_busybox is a elf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (55/100), attributed to the Result family. 2 of 53 detection engines flagged it.
Identification
- SHA-256:
b3c1009e1b5c927e537487c80639cdf404f69e3eb49371d9be5d841672be3ff9 - SHA-1:
e18f21562b5ed0d3719db6814840b1777a088309 - MD5:
1bd46b6ade24f2f4f8a09cc85bb1c0ec - ssdeep:
49152:47hiT1KzAk4xHozP4ta1C2fLfR5ocettiLGHSciq6qaVk5:m01WP4tL2LLZuiaycY - TLSH:
T1225B5C7400277212E1B9AE44B06510ED640BF994F1787CAE420F6D2D92A83EFE6F59D3 - Submitted as: tmp_busybox
- File type: elf · Size: 2193272 bytes
- Verdict: suspicious (55/100) · Family: Result
Detections (2 of 53 engines)
- YARA: PhishingKit (t4d): PK_Result_Mailer
- YARA: Stratosphere IPS: STRATO_Malicious_UserAgent
Why this verdict
The suspicious score of 55/100 is the fusion of 3 weighted signals:
- YARA: PhishingKit (t4d) flagged PK_Result_Mailer (rule
PK_Result_Mailer) - engine signal, weight 0.35, confidence 0.70 - YARA: Stratosphere IPS flagged STRATO_Malicious_UserAgent (rule
STRATO_Malicious_UserAgent) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://bugs.launchpad.net/ubuntu/+source/glibc/+bugs - static signal, weight 0.35, confidence 0.60
Dynamic analysis (linux)
1078 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- desktop-hsgcbep
- ntp.ubuntu.com
- 250.255.255.239.in-addr.arpa
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 252.0.0.224.in-addr.arpa
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- ff02::1:3
- 224.0.0.252
- 224.0.0.251
- ff02::fb
- 10.240.0.255
- 10.240.0.1
- ff02::16
- 169.254.255.255
- 185.125.190.56
- 239.255.255.250
- ff02::1:ff4c:1d1d
- ff02::1:2
- 255.255.255.255
Embedded URLs
- https://bugs.launchpad.net/ubuntu/+source/glibc/+bugs
- https://github.com/gavinhoward/bc
Embedded domains
- bugs.launchpad.net
- github.com
- issue.net
Embedded IP addresses
- 192.168.0.20
- 192.168.0.254
More Result samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report