CLEAN — fb0d85544c744d598c72b69916e63441564932fdfa5940b1de6bc13f211d7419
CLEAN — fb0d85544c744d598c72b69916e63441564932fdfa5940b1de6bc13f211d7419 is a shell sample analyzed by MalwareAnalyzer by Cyble with a clean verdict (21/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
fb0d85544c744d598c72b69916e63441564932fdfa5940b1de6bc13f211d7419 - SHA-1:
34d3003eacbd38c89dcf074e7dd44a2fd07335ae - MD5:
7409d68f511f50faaebd7318a86f8a7e - ssdeep:
192:yNqYF2/BiKaS5+PqW5FvCffpQQQqit43rf38XEBrTwJ9f:yNqIqYgY5JGQQQqit43T38X4rTwJ9f - TLSH:
T10123D9CEB258DFE2F41C6AB967881EE6C983D52F418141FC0C4091C474985CAB9B916F - Submitted as: fb0d85544c744d598c72b69916e63441564932fdfa5940b1de6bc13f211d7419
- File type: shell · Size: 10354 bytes
- Verdict: clean (21/100)
Detections (2 of 53 engines)
- Microsoft Defender: Backdoor:PHP/Dirtelti.AB!MTB
- Kaspersky (KVRT): HEUR:Backdoor.PHP.WebShell.gen
Why this verdict
The clean score of 21/100 is the fusion of 1 weighted signal:
- Embedded network infrastructure: https://s.yimg.com/lq/i/mesg/emoticons7/19.gif - static signal, weight 0.35, confidence 0.60
Dynamic analysis (linux)
813 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- 250.255.255.239.in-addr.arpa
- ntp.ubuntu.com
- desktop-hsgcbep._dosvc._tcp.local
- desktop-hsgcbep
- 224.0.0.251
- ff02::fb
- ff02::1:3
- 224.0.0.252
- 20.165.94.63 US · San Antonio · AS8075 Microsoft Corporation
- 10.240.0.1
- 239.255.255.250
- ff02::1:ff12:3456
- 10.240.0.255
- ff02::16
- ff02::2
- ff02::1
- ff02::1:ff4c:1d1d
- 224.0.0.22
- 185.125.190.58
- 172.215.188.232 US · San Antonio · AS8075 Microsoft Limited
Embedded URLs
- https://s.yimg.com/lq/i/mesg/emoticons7/19.gif
- http://c.fastcompany.net/asset_files/-/2014/11/11/4F4.gif
Embedded domains
- s.yimg.com
- c.fastcompany.net
Embedded IP addresses
- 20.165.94.63
- 172.215.188.232
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report