MALICIOUS — d1cac82f44b54b0fd244a9e4122811e9ae108a197c7a65a20fd2e7552683e68e.bin
MALICIOUS — d1cac82f44b54b0fd244a9e4122811e9ae108a197c7a65a20fd2e7552683e68e.bin is a elf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (97/100). 5 of 56 detection engines flagged it.
Identification
- SHA-256:
d1cac82f44b54b0fd244a9e4122811e9ae108a197c7a65a20fd2e7552683e68e - SHA-1:
99be01382e567d68cb9f317fb3c039c17e4315eb - MD5:
0e0328dc8084e6203c09a3e5ea1539f8 - ssdeep:
24576:sc6qWRqqRfVMP7Cft/U1QNlMKDZB3EIq5WrSCv55LhFdmQ5Rp6bpgit1ggrcDmU2:4dFkP7ov3DZeoWCvnLDdJHik/DVLwz - TLSH:
T1355833884DFC3788F8C192A6FB40442E8F9E151457A47A1A546B1770E2A8EBE3DC50FD - Submitted as: d1cac82f44b54b0fd244a9e4122811e9ae108a197c7a65a20fd2e7552683e68e.bin
- File type: elf · Size: 1696412 bytes
- Verdict: malicious (97/100)
Source: MalShare · first seen 2026-09-16T06:37:34.443Z · SHA-256 verified
Detections (5 of 56 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Detect It Easy (packer/type): DIE:UPX 5.20
- Microsoft Defender: Trojan:Linux/CoinMiner!rfn
- Emsisoft (Emergency Kit): Trojan.Linux.GenericKD.60054709
- Kaspersky (KVRT): not-a-virus:HEUR:RiskTool.Linux.BitCoinMiner.n
Why this verdict
The malicious score of 97/100 is the fusion of 10 weighted signals:
- Memory forensics: 2 finding(s) attributed to the sample across 1 technique(s), e.g. injected region in nginx (pid 695) (rule
linux.malfind.Malfind) - memory signal, weight 0.60, confidence 0.85 - Microsoft Defender flagged Trojan:Linux/CoinMiner!rfn (rule
Trojan:Linux/CoinMiner!rfn) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Trojan.Linux.GenericKD.60054709 (rule
Trojan.Linux.GenericKD.60054709) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged not-a-virus:HEUR:RiskTool.Linux.BitCoinMiner.n (rule
not-a-virus:HEUR:RiskTool.Linux.BitCoinMiner.n) - engine signal, weight 0.55, confidence 0.85 - Detect It Easy (packer/type) flagged DIE:UPX 5.20 (rule
DIE:UPX 5.20) - engine signal, weight 0.35, confidence 0.70 - MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: http://upx.sf.net - static signal, weight 0.35, confidence 0.60
- Packing/obfuscation: high-entropy-blob, UPX 5.20 - static signal, weight 0.25, confidence 0.55
- Contacted 12 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
- Extracted generic config (1 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (linux)
834 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- ntp.ubuntu.com
- 95.215.19.53:853 SE · Malmö · AS39287 ab stract ltd
- 130.12.180.51:43782 DE · Virtualine Technologies
- 8.8.8.8:853
- 130.12.180.51:2137 DE · Virtualine Technologies
- 130.12.180.51 DE · Virtualine Technologies
- 95.215.19.53 SE · Malmö · AS39287 ab stract ltd
- 10.240.0.76
- 1.1.1.1
- 1.0.0.1
- 9.9.9.10 CH · Zürich · AS19281 Quad9
- 217.160.70.42 DE · Berlin · AS8560 IONOS SE
- 213.202.211.221 DE · Düsseldorf · AS24961 WIIT AG
- 8.8.4.4
- 81.169.136.222 DE · Berlin · AS6724 Strato Rechenzentrum, Berlin
- 185.181.61.24 NO · Oslo · AS56655 Gigahost AS
- 8.8.8.8
- 9.9.9.9
- 80.152.203.134 DE · Lüneburg · AS3320 Deutsche Telekom AG
- 109.91.184.21 DE · AS3209 VODANET - Vodafone GmbH, DE
Embedded URLs
- http://upx.sf.net
Embedded domains
- e.in
- upx.sf.net
Embedded IP addresses
- 130.12.180.51
- 95.215.19.53
- 9.9.9.10
- 217.160.70.42
- 213.202.211.221
- 81.169.136.222
- 185.181.61.24
- 80.152.203.134
- 109.91.184.21
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report