MALICIOUS — d70f917e35813a7ae323e6b2b539d6dbbfc3a3a6599f1fed93430b14ca08b141.bin
MALICIOUS — d70f917e35813a7ae323e6b2b539d6dbbfc3a3a6599f1fed93430b14ca08b141.bin is a elf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (97/100). 5 of 57 detection engines flagged it.
Identification
- SHA-256:
d70f917e35813a7ae323e6b2b539d6dbbfc3a3a6599f1fed93430b14ca08b141 - SHA-1:
379d971c686dfd0d10ed8c1b6bd5fe1ae3dd4f7e - MD5:
1ed17cd8d521a329e62321797547a03c - ssdeep:
24576:5MVf5G045SzJ+M0xyHyZ+5OSSuBuAXrECblkU/es5QxxcbF/rVKBygNvdjraYUJr:5KMnaFBHh5O61Lblf2siyprfgFdU0ED/ - TLSH:
T19B563338B7A859E407A2984C80DC1FB780A106EE15F5F6D01ACF33997717CA5C84E97A - Submitted as: d70f917e35813a7ae323e6b2b539d6dbbfc3a3a6599f1fed93430b14ca08b141.bin
- File type: elf · Size: 1448252 bytes
- Verdict: malicious (97/100)
Source: MalShare · first seen 2026-09-16T06:27:34.429Z · SHA-256 verified
Detections (5 of 57 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Detect It Easy (packer/type): DIE:UPX 5.20
- Microsoft Defender: Trojan:Script/Sabsik.EN.A!ml
- Emsisoft (Emergency Kit): Trojan.Linux.GenericKD.60054708
- Kaspersky (KVRT): not-a-virus:HEUR:RiskTool.Linux.BitCoinMiner.n
Why this verdict
The malicious score of 97/100 is the fusion of 10 weighted signals:
- Memory forensics: 2 finding(s) attributed to the sample across 1 technique(s), e.g. injected region in apache2 (pid 712) (rule
linux.malfind.Malfind) - memory signal, weight 0.60, confidence 0.85 - Microsoft Defender flagged Trojan:Script/Sabsik.EN.A!ml (rule
Trojan:Script/Sabsik.EN.A!ml) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Trojan.Linux.GenericKD.60054708 (rule
Trojan.Linux.GenericKD.60054708) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged not-a-virus:HEUR:RiskTool.Linux.BitCoinMiner.n (rule
not-a-virus:HEUR:RiskTool.Linux.BitCoinMiner.n) - engine signal, weight 0.55, confidence 0.85 - Detect It Easy (packer/type) flagged DIE:UPX 5.20 (rule
DIE:UPX 5.20) - engine signal, weight 0.35, confidence 0.70 - MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: http://upx.sf.net - static signal, weight 0.35, confidence 0.60
- Packing/obfuscation: high-entropy-blob, UPX 5.20 - static signal, weight 0.25, confidence 0.55
- Contacted 11 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
- Extracted generic config (1 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (linux)
142 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- ntp.ubuntu.com
- 95.215.19.53:853 SE · Malmö · AS39287 ab stract ltd
- 130.12.180.51 DE · Virtualine Technologies
- 95.215.19.53 SE · Malmö · AS39287 ab stract ltd
- 9.9.9.10 CH · Zürich · AS19281 Quad9
- 217.160.70.42 DE · Berlin · AS8560 IONOS SE
- 1.1.1.1
- 213.202.211.221 DE · Düsseldorf · AS24961 WIIT AG
- 8.8.8.8
- 8.8.4.4
- 1.0.0.1
- 81.169.136.222 DE · Berlin · AS6724 Strato Rechenzentrum, Berlin
- 9.9.9.9
- 185.181.61.24 NO · Oslo · AS56655 Gigahost AS
- 80.152.203.134 DE · Lüneburg · AS3320 Deutsche Telekom AG
- 109.91.184.21 DE · AS3209 VODANET - Vodafone GmbH, DE
- 10.240.0.1
- ff02::16
- 255.255.255.255
- ff02::1:ff12:3456
Embedded URLs
- http://upx.sf.net
Embedded domains
- upx.sf.net
Embedded IP addresses
- 130.12.180.51
- 95.215.19.53
- 9.9.9.10
- 217.160.70.42
- 213.202.211.221
- 81.169.136.222
- 185.181.61.24
- 80.152.203.134
- 109.91.184.21
- 31.56.209.165
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report