SUSPICIOUS — c91a6e3b85b511485e6d37c5e5b5329f8d111e14178ec9c1e0125f58454c08d2.elf
SUSPICIOUS — c91a6e3b85b511485e6d37c5e5b5329f8d111e14178ec9c1e0125f58454c08d2.elf is a elf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (61/100), attributed to the Modified family. 6 of 56 detection engines flagged it.
Identification
- SHA-256:
c91a6e3b85b511485e6d37c5e5b5329f8d111e14178ec9c1e0125f58454c08d2 - SHA-1:
a0dbd58e37c012f1c2818dd7025883a1854d9e0b - MD5:
2f41ab95b44b6858b1ca23f9e6cb6c9c - ssdeep:
1536:zAISVp6FX21s7QGGIWaL7eqowcQL9zBoSHBCz:zAIjFGWTWaG6jL9tHHBCz - TLSH:
T13035020E9018649BAC561CBC4095EA1CA352053AD9F227F34F981A3DB5910B7DDEBCE2 - Submitted as: c91a6e3b85b511485e6d37c5e5b5329f8d111e14178ec9c1e0125f58454c08d2.elf
- File type: elf · Size: 60308 bytes
- Verdict: suspicious (61/100) · Family: Modified
Source: MalwareBazaar · first seen 2026-08-02T00:00:00.000Z · SHA-256 verified
Detections (6 of 56 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- YARA: Intezer community: INTEZER_ELF_UPX_Modified
- Detect It Easy (packer/type): DIE:UPX 3.94
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): Trojan.Linux.Mirai.39487096
- Kaspersky (KVRT): HEUR:Backdoor.Linux.Mirai.hv
Why this verdict
The suspicious score of 61/100 is the fusion of 4 weighted signals:
- YARA: Intezer community flagged INTEZER_ELF_UPX_Modified (rule
INTEZER_ELF_UPX_Modified) - engine signal, weight 0.35, confidence 0.70 - Detect It Easy (packer/type) flagged DIE:UPX 3.94 (rule
DIE:UPX 3.94) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: http://upx.sf.net - static signal, weight 0.35, confidence 0.60
- Packing/obfuscation: high-entropy-blob, UPX 3.94 - static signal, weight 0.25, confidence 0.55
Dynamic analysis
This sample is built for ARM, which no sandbox guest in our fleet executes, so it was not detonated. The absence of runtime behaviour here is a coverage gap on our side, not a finding about the sample.
Embedded URLs
- http://upx.sf.net
Embedded domains
- upx.sf.net
More Modified samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report