SUSPICIOUS — 2ae7dc16ca036cb5c2c7ce2cd8099edb07d96b8846188c92eb39a7feba2fec08.elf
SUSPICIOUS — 2ae7dc16ca036cb5c2c7ce2cd8099edb07d96b8846188c92eb39a7feba2fec08.elf is a elf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (66/100), attributed to the Persistence family. 3 of 49 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
2ae7dc16ca036cb5c2c7ce2cd8099edb07d96b8846188c92eb39a7feba2fec08 - SHA-1:
ea9170467efb19648bbe4514097a5ebe6a734ca5 - MD5:
b02e178ecf7de81dd8653a2eb2adc11f - File type: elf · Size: 1206876 bytes
- Verdict: suspicious (66/100) · Family: Persistence
Detections (3 of 49 engines)
- YARA: Intezer community: INTEZER_Linux_Persistence
- YARA: Trellix/McAfee ATR: ATR_REvil_Sodinokibi
- YARA: Stratosphere IPS: STRATO_IRC_Botnet
MITRE ATT&CK
Dynamic analysis (linux)
766 behavior events · 0 ATT&CK techniques · 4 dropped files.
Runtime network
- desktop-hsgcbep
- 250.255.255.239.in-addr.arpa
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 252.0.0.224.in-addr.arpa
- ff02::1:3
- 224.0.0.252
- 169.254.255.255
- 224.0.0.251
- ff02::fb
- 10.240.0.255
- 224.0.0.22
- 10.240.0.1
- 239.255.255.250
- ff02::2
- ff02::16
- 255.255.255.255
- 72.145.35.111 IE · Dublin · AS8075 Microsoft Corporation
- ff02::1:ff12:3456
Dropped files
- home_.network-dispatch —
2ae7dc16ca036cb5c2c7ce2cd8099edb07d96b8846188c92eb39a7feba2fec08 - root_.ashrc —
e89e5301a59ce3fb142a5e91407aa628339ca08123fb850acfea056ee059db91 - root_.config_systemd_user_network-dispatch.service —
8493e90ac274688355fba972b6898b69fa003b1c742ad77b026a3518fbbea18d - tmp_tmp.LvLjeLjDlO —
c002ff9367d6a9db5738b8a7a71309d89005d109095dcf4ecba22187030300a4
Embedded URLs
- https://bugs.launchpad.net/ubuntu/+source/glibc/+bugs
Embedded domains
- 00-net.sh
- cdn-edge-updates.hostcloud-eu.net
- bins.sh
- api-relay-3.metrics-collector.io
- sync.softwaremirror.workers.dev
- beacon.systemd-notify-service.co
- mgmt-panel.serverstats-daemon.com
- openssh.com
- bugs.launchpad.net
Embedded IP addresses
- 185.199.108.153
- 104.21.234.17
- 192.0.2.14
- 198.51.100.42
- 203.0.113.77
- 192.0.2.201
- 198.51.100.13
- 45.83.140.28
- 51.15.68.114
- 94.130.53.201
- 5.101.221.87
- 195.201.24.6
- 45.61.161.207
- 72.145.35.111
- 135.233.95.80
- 85.210.196.11
More Persistence samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report