.incoming_30584f13c0a9d0c8
Classification: Malicious
.incoming_30584f13c0a9d0c8 is a malicious file sample. Linked to Gomir malware. Reported by 2 threat sources, last seen 2026-07-06.
Detection summary
- 39 antivirus detections
- 0 IDS alerts
- 5 processes observed
- 0 contacted hosts
- 3 DNS requests
MITRE ATT&CK associations
Malware families: GOMIR (S1198)
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| Gomir | Triage | 2026-07-06 12:42:09 | 2026-07-06 12:42:09 | malicious-activity | S1198 Gomir |
| Generic Malware | Hybrid-Analysis | 2024-02-08 01:45:03 | 2024-05-17 15:15:13 |
Tags
evasive backdoor gomir apt43 kimsuky apt discovery linuxSample information
- Filenames
- .incoming_30584f13c0a9d0c8, 30584f13c0a9d0c86562c803de350432d5a0607a06b24481ad4d92cdf7288213
- File type
- ELF 32-bit LSB executable, Intel 80386, version 1 ...
- Size
- 5947392 bytes
- MD5
e562cf30d17d47347c7e6ffd249fc190- SHA-1
93edc15a20aac8b5193e5b22e35dbb09848e2ca0- SHA-256
30584f13c0a9d0c86562c803de350432d5a0607a06b24481ad4d92cdf7288213- First indexed
- 2024-02-08 01:31:59
- Last updated
- 2026-07-30 12:56:01
Antivirus detections
| Engine | Detection |
|---|---|
| Detected | |
| Ikarus | Trojan.Linux.DDoS |
| ALYac | Backdoor.Linux.Gomir |
| AVG | ELF:Agent-CTF [Trj] |
| AhnLab-V3 | Trojan/Linux.Agent.5947392 |
| Antiy-AVL | Trojan/Linux.Agent.zv |
| Arcabit | Trojan.Generic.D2194040 |
| Avast | ELF:Agent-CTF [Trj] |
| Avira | LINUX/AVF.Agent.tlpsh |
| BitDefender | Trojan.Generic.35209280 |
| CAT-QuickHeal | Elf.trojan.A12247344 |
| Cynet | Malicious (score: 99) |
| DrWeb | Linux.BackDoor.Siggen.514 |
| ESET-NOD32 | Linux/Agent.ZV |
| Elastic | Linux.Trojan.Springtail |
| Emsisoft | Trojan.Generic.35209280 (B) |
| F-Secure | Malware.LINUX/AVF.Agent.tlpsh |
| FireEye | Trojan.Generic.35209280 |
| Fortinet | Linux/Agent.ZV!tr |
| GData | Trojan.Generic.35209280 |
| Kaspersky | HEUR:Backdoor.Linux.Gomir.gen |
| Lionic | Trojan.Linux.Gomir.m!c |
| MAX | malware (ai score=99) |
| McAfee | Trojan-FVAE!E562CF30D17D |
| MicroWorld-eScan | Trojan.Generic.35209280 |
| Microsoft | Trojan:Linux/Multiverze |
| Rising | Backdoor.Gomir/Linux!8.1A3E2 (CLOUD) |
| SentinelOne | Static AI - Suspicious ELF |
| Skyhigh | Artemis!Trojan |
| Sophos | Mal/Generic-S |
| Symantec | Linux.Gomir |
| Tencent | Linux.Backdoor.Gomir.Ychl |
| TrendMicro | Backdoor.Linux.GOMIR.THEBABD |
| TrendMicro-HouseCall | Backdoor.Linux.GOMIR.THEBABD |
| VIPRE | Trojan.Generic.35209280 |
| Varist | E32/ABRisk.ABAO-71 |
| ViRobot | Linux.S.Agent.5947392 |
| ZoneAlarm | HEUR:Backdoor.Linux.Gomir.gen |
| alibabacloud | Backdoor:Linux/Gomir.gyf |
DNS requests
a978.i6g1.akamai.net canonical-lgw01.cdn.snapcraftcontent.com ipv6.msftncsi.com.edgesuite.net
Process list
| Name | Command line |
|---|---|
| 30584f13c0a9d0c86562c803de350432d5a0607a06b24481ad4d92cdf7288213 | /home/ubuntu/30584f13c0a9d0c86562c803de350432d5a0607a06b24481ad4d92cdf7288213 |
| 30584f13c0a9elf | |
| 30584f13c0a9elf | |
| 30584f13c0a9elf | |
| 30584f13c0a9elf | |