MALICIOUS — f88d9094a90f7000a3fb2cd7c981e03357ce2b39df9de5ee1d0742e619e3860f.bin
MALICIOUS — f88d9094a90f7000a3fb2cd7c981e03357ce2b39df9de5ee1d0742e619e3860f.bin is a script sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (93/100), attributed to the execute family. 5 of 51 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
f88d9094a90f7000a3fb2cd7c981e03357ce2b39df9de5ee1d0742e619e3860f - SHA-1:
da190ccb0e6cdb6b55f40532a0ee7064d31ba760 - MD5:
2ec5a4d805472352a10492d311a80fa7 - ssdeep:
24576:QYuC2NrO/LXTGqatNo3sk/mUjIo/f8YpQneRZQ5msYFFXNBYWuXT1I365ZaL47Hn:75J0r+D93O - TLSH:
T1E764AFCEA5CF7369D67B6967A6644A21321583CCB52316187092C803ED5FEBEE3CC484 - Submitted as: f88d9094a90f7000a3fb2cd7c981e03357ce2b39df9de5ee1d0742e619e3860f.bin
- File type: script · Size: 5506178 bytes
- Verdict: malicious (93/100) · Family: execute
Source: MalShare · first seen 2026-07-28T22:14:33.735Z · SHA-256 verified
Detections (5 of 51 engines)
- capa (capabilities): execute via PowerShell
- YARA: Trellix/McAfee ATR: ATR_BlackCat_ALPHV
- Microsoft Defender: Trojan:Win32/Leonem!rfn
- Emsisoft (Emergency Kit): Trojan.GenericKD.80948809
- Kaspersky (KVRT): Trojan.PowerShell.Agent.bis
MITRE ATT&CK
Why this verdict
The malicious score of 93/100 is the fusion of 7 weighted signals:
- Microsoft Defender flagged Trojan:Win32/Leonem!rfn (rule
Trojan:Win32/Leonem!rfn) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Trojan.GenericKD.80948809 (rule
Trojan.GenericKD.80948809) - engine signal, weight 0.55, confidence 0.85 - Obfuscated powershell script: dynamic-exec, encoded-command, defense-evasion (layers: base64) (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - execute via PowerShell (rule
execute via PowerShell) - capa signal, weight 0.40, confidence 0.80 - YARA: Trellix/McAfee ATR flagged ATR_BlackCat_ALPHV (rule
ATR_BlackCat_ALPHV) - engine signal, weight 0.35, confidence 0.70 - Contacted 5 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
- Contacted 5 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
Dynamic analysis (linux)
841 behavior events · 0 ATT&CK techniques · 1 dropped files.
Runtime network
- entropy.ubuntu.com
- desktop-hsgcbep
- ntp.ubuntu.com
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 252.0.0.224.in-addr.arpa
- 185.125.189.54
- 10.240.0.1
- ff02::1:3
- 224.0.0.252
- 10.240.0.255
- 142.250.195.142
- 20.42.65.91
- 224.0.0.251
- ff02::fb
- 4.247.188.224
- 91.189.91.157
- ff02::2
- ff02::1:ff4c:1d1d
Dropped files
- tmp_tmp.6ETSv1Qm9Y -
71e2997c1e19620e5f8aa8576afed3ee692ed4ea19e058e936ee50f1e0f97fcd
Embedded IP addresses
- 142.250.195.142
- 20.42.65.91
- 4.247.188.224
More execute samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report