CLEAN — b552208b255cb64931d0a2765fd9971e86ab49f4d861eccfb2715aea08767019
CLEAN — b552208b255cb64931d0a2765fd9971e86ab49f4d861eccfb2715aea08767019 is a shell sample analyzed by MalwareAnalyzer by Cyble with a clean verdict (30/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
b552208b255cb64931d0a2765fd9971e86ab49f4d861eccfb2715aea08767019 - SHA-1:
13897934f706e82dc9b8b1df001769d3aec86ef6 - MD5:
ee399fcf8f56f150a1ceefe110cf3982 - ssdeep:
384:k8PHTw34DXLRZZmH7Up9ikFJFqidljCFdep:koTwGLPZOm78aluS - TLSH:
T1162694A1534128FF8EAB6A9D48916B3ED421E4DF105074F127DF5FA0BC26E62F02416B - Submitted as: b552208b255cb64931d0a2765fd9971e86ab49f4d861eccfb2715aea08767019
- File type: shell · Size: 14531 bytes
- Verdict: clean (30/100)
Detections (3 of 53 engines)
- Microsoft Defender: Trojan:Python/Stealer.A!MTB
- Emsisoft (Emergency Kit): Generic.PySpy.B.A217E414
- Kaspersky (KVRT): Trojan-PSW.Python.Stealer.gen
Why this verdict
The clean score of 30/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://discord.com/api/webhooks/908442371866374185/pRicV_u4n7endMBh_EFKBwJiK66iPL82m5twaER867DUM80m6AUEUerWSm5DILQUwrDS - static signal, weight 0.35, confidence 0.60
- Contacted 5 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
- Extracted generic config (1 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (linux)
898 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- 250.255.255.239.in-addr.arpa
- desktop-hsgcbep
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 252.0.0.224.in-addr.arpa
- ntp.ubuntu.com
- ff02::1:3
- 224.0.0.252
- 151.101.30.172
- 224.0.0.251
- ff02::fb
- 10.240.0.1
- 10.240.0.255
- 131.253.33.203
- 239.255.255.250
- ff02::16
- 72.145.35.104
- 185.125.190.56
- 185.125.190.57
Embedded URLs
- https://discord.com/api/webhooks/908442371866374185/pRicV_u4n7endMBh_EFKBwJiK66iPL82m5twaER867DUM80m6AUEUerWSm5DILQUwrDS
- https://github.com
Embedded domains
- discord.com
- os.name
- github.com
- discordapp.com
Embedded IP addresses
- 72.145.35.104
- 40.84.97.4
- 172.172.255.216
- 52.168.112.66
- 20.184.175.16
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report