Size | 21.4KB |
---|---|
Type | ELF 32-bit MSB executable, PowerPC or cisco 4500, version 1 (GNU/Linux), statically linked, no section header |
MD5 | c646ac6b824f0c8010968b2011740331 |
SHA1 | 57c76c3182df7c551d73c6ab81d088308f9370cf |
SHA256 | f3107fb28edbff96b2bb5bf2ff247642fb37fcfb3f267593da3a253fde16381f |
SHA512 |
98aaa30fa4bd40745fb48cf523249c46e665aa4e09bdd39bd241fa49702f634a12089670e1a41798657954d971148279b1e4823eb67f27888fa0e0e88b512b0d
|
CRC32 | FC5FCED5 |
ssdeep | None |
Yara | None matched |
This file is very suspicious, with a score of 10 out of 10!
Please notice: The scoring system is currently still in development and should be considered an alpha feature.
Expecting different results? Send us this analysis and we will inspect it. Click here
Category | Started | Completed | Duration | Routing | Logs |
---|---|---|---|---|---|
FILE | Dec. 25, 2024, 9:33 p.m. | Dec. 25, 2024, 9:35 p.m. | 121 seconds | internet |
Show Analyzer Log Show Cuckoo Log |
2024-12-25 21:32:34,005 [root] DEBUG: Starting analyzer from: /tmp/tmpAqMrj5 2024-12-25 21:32:34,006 [root] DEBUG: Storing results at: /tmp/rKnUCCK 2024-12-25 21:32:35,638 [modules.auxiliary.filecollector] INFO: FileCollector started v0.08 2024-12-25 21:32:35,640 [modules.auxiliary.human] INFO: Human started v0.02 2024-12-25 21:32:35,643 [modules.auxiliary.screenshots] INFO: Screenshots started v0.03 2024-12-25 21:32:40,831 [lib.core.packages] INFO: Process startup took 5.18 seconds 2024-12-25 21:32:40,831 [root] INFO: Added new process to list with pid: 2075 2024-12-25 21:32:49,941 [root] INFO: Process with pid 2075 has terminated 2024-12-25 21:32:49,943 [root] INFO: Process list is empty, terminating analysis. 2024-12-25 21:32:52,957 [lib.core.packages] INFO: Package requested stop 2024-12-25 21:32:52,959 [lib.core.packages] WARNING: Exception uploading log: [Errno 3] No such process
2024-12-25 21:33:28,561 [cuckoo.core.scheduler] DEBUG: Task #5695915: no machine available yet 2024-12-25 21:33:29,579 [cuckoo.core.scheduler] DEBUG: Task #5695915: no machine available yet 2024-12-25 21:33:30,603 [cuckoo.core.scheduler] DEBUG: Task #5695915: no machine available yet 2024-12-25 21:33:31,628 [cuckoo.core.scheduler] DEBUG: Task #5695915: no machine available yet 2024-12-25 21:33:32,652 [cuckoo.core.scheduler] DEBUG: Task #5695915: no machine available yet 2024-12-25 21:33:33,672 [cuckoo.core.scheduler] DEBUG: Task #5695915: no machine available yet 2024-12-25 21:33:34,691 [cuckoo.core.scheduler] DEBUG: Task #5695915: no machine available yet 2024-12-25 21:33:35,714 [cuckoo.core.scheduler] DEBUG: Task #5695915: no machine available yet 2024-12-25 21:33:36,732 [cuckoo.core.scheduler] DEBUG: Task #5695915: no machine available yet 2024-12-25 21:33:37,751 [cuckoo.core.scheduler] DEBUG: Task #5695915: no machine available yet 2024-12-25 21:33:38,773 [cuckoo.core.scheduler] DEBUG: Task #5695915: no machine available yet 2024-12-25 21:33:39,800 [cuckoo.core.scheduler] DEBUG: Task #5695915: no machine available yet 2024-12-25 21:33:40,822 [cuckoo.core.scheduler] DEBUG: Task #5695915: no machine available yet 2024-12-25 21:33:41,841 [cuckoo.core.scheduler] DEBUG: Task #5695915: no machine available yet 2024-12-25 21:33:42,859 [cuckoo.core.scheduler] DEBUG: Task #5695915: no machine available yet 2024-12-25 21:33:43,879 [cuckoo.core.scheduler] DEBUG: Task #5695915: no machine available yet 2024-12-25 21:33:44,894 [cuckoo.core.scheduler] DEBUG: Task #5695915: no machine available yet 2024-12-25 21:33:45,912 [cuckoo.core.scheduler] DEBUG: Task #5695915: no machine available yet 2024-12-25 21:33:46,930 [cuckoo.core.scheduler] DEBUG: Task #5695915: no machine available yet 2024-12-25 21:33:47,953 [cuckoo.core.scheduler] DEBUG: Task #5695915: no machine available yet 2024-12-25 21:33:48,976 [cuckoo.core.scheduler] DEBUG: Task #5695915: no machine available yet 2024-12-25 21:33:50,013 [cuckoo.core.scheduler] DEBUG: Task #5695915: no machine available yet 2024-12-25 21:33:51,048 [cuckoo.core.scheduler] DEBUG: Task #5695915: no machine available yet 2024-12-25 21:33:52,103 [cuckoo.core.scheduler] DEBUG: Task #5695915: no machine available yet 2024-12-25 21:33:53,143 [cuckoo.core.scheduler] DEBUG: Task #5695915: no machine available yet 2024-12-25 21:33:54,182 [cuckoo.core.scheduler] DEBUG: Task #5695915: no machine available yet 2024-12-25 21:33:55,250 [cuckoo.core.scheduler] DEBUG: Task #5695915: no machine available yet 2024-12-25 21:33:56,285 [cuckoo.core.scheduler] DEBUG: Task #5695915: no machine available yet 2024-12-25 21:33:57,321 [cuckoo.core.scheduler] DEBUG: Task #5695915: no machine available yet 2024-12-25 21:33:58,354 [cuckoo.core.scheduler] DEBUG: Task #5695915: no machine available yet 2024-12-25 21:33:59,406 [cuckoo.core.scheduler] DEBUG: Task #5695915: no machine available yet 2024-12-25 21:34:00,451 [cuckoo.core.scheduler] DEBUG: Task #5695915: no machine available yet 2024-12-25 21:34:01,481 [cuckoo.core.scheduler] DEBUG: Task #5695915: no machine available yet 2024-12-25 21:34:02,693 [cuckoo.core.scheduler] DEBUG: Task #5695915: no machine available yet 2024-12-25 21:34:03,722 [cuckoo.core.scheduler] DEBUG: Task #5695915: no machine available yet 2024-12-25 21:34:04,740 [cuckoo.core.scheduler] DEBUG: Task #5695915: no machine available yet 2024-12-25 21:34:05,761 [cuckoo.core.scheduler] DEBUG: Task #5695915: no machine available yet 2024-12-25 21:34:06,788 [cuckoo.core.scheduler] DEBUG: Task #5695915: no machine available yet 2024-12-25 21:34:07,824 [cuckoo.core.scheduler] INFO: Task #5695915: acquired machine Ubuntu1904x646 (label=Ubuntu1904x646) 2024-12-25 21:34:07,827 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.106 for task #5695915 2024-12-25 21:34:08,068 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 311743 (interface=vboxnet0, host=192.168.168.106) 2024-12-25 21:34:08,091 [cuckoo.machinery.virtualbox] DEBUG: Starting vm Ubuntu1904x646 2024-12-25 21:34:08,552 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine Ubuntu1904x646 to Snapshot 2024-12-25 21:34:15,228 [cuckoo.core.guest] INFO: Starting analysis #5695915 on guest (id=Ubuntu1904x646, ip=192.168.168.106) 2024-12-25 21:34:16,284 [cuckoo.core.guest] DEBUG: Ubuntu1904x646: not ready yet 2024-12-25 21:34:21,315 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=Ubuntu1904x646, ip=192.168.168.106) 2024-12-25 21:34:21,341 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=Ubuntu1904x646, ip=192.168.168.106, monitor=latest, size=73219) 2024-12-25 21:34:21,516 [cuckoo.core.resultserver] DEBUG: Task #5695915: live log analysis.log initialized. 2024-12-25 21:34:25,951 [cuckoo.core.resultserver] DEBUG: Task #5695915: File upload for 'shots/0001.jpg' 2024-12-25 21:34:26,022 [cuckoo.core.resultserver] DEBUG: Task #5695915 uploaded file length: 171573 2024-12-25 21:34:36,522 [cuckoo.core.guest] DEBUG: Ubuntu1904x646: analysis #5695915 still processing 2024-12-25 21:34:40,486 [cuckoo.core.resultserver] DEBUG: Task #5695915: File upload for 'logs/all.stap' 2024-12-25 21:34:40,490 [cuckoo.core.resultserver] DEBUG: Task #5695915 uploaded file length: 66839 2024-12-25 21:34:51,602 [cuckoo.core.guest] DEBUG: Ubuntu1904x646: analysis #5695915 still processing 2024-12-25 21:35:06,695 [cuckoo.core.guest] DEBUG: Ubuntu1904x646: analysis #5695915 still processing 2024-12-25 21:35:21,782 [cuckoo.core.guest] INFO: Ubuntu1904x646: end of analysis reached! 2024-12-25 21:35:21,794 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks 2024-12-25 21:35:21,821 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer 2024-12-25 21:35:22,529 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label Ubuntu1904x646 to path /srv/cuckoo/cwd/storage/analyses/5695915/memory.dmp 2024-12-25 21:35:22,530 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm Ubuntu1904x646 2024-12-25 21:35:29,649 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.106 for task #5695915 2024-12-25 21:35:29,650 [cuckoo.core.resultserver] DEBUG: Cancel <Context for LOG> for task 5695915 2024-12-25 21:35:29,932 [cuckoo.core.scheduler] DEBUG: Released database task #5695915 2024-12-25 21:35:29,951 [cuckoo.core.scheduler] INFO: Task #5695915: analysis procedure completed
G Data Antivirus (Windows) | Virus: Trojan.Linux.GenericKDZ.199 (Engine A) |
Avast Core Security (Linux) | ELF:Mirai-GG [Trj] |
C4S ClamAV (Linux) | Unix.Trojan.Mirai-9936831-0 |
F-Secure Antivirus (Linux) | Exploit.EXP/ELF.Agent.F.118 [Aquarius] |
Windows Defender (Windows) | Trojan:Linux/Multiverze |
Forticlient (Linux) | ELF/Mirai.GG!tr |
Sophos Anti-Virus (Linux) | Linux/DDoS-CI |
eScan Antivirus (Linux) | Trojan.Linux.GenericKDZ.199(DB) |
ESET Security (Windows) | a variant of Linux/Mirai.A trojan |
McAfee CLI scanner (Linux) | GenericRXVU-US |
DrWeb Antivirus (Linux) | Linux.Siggen.9999 |
ClamAV (Linux) | Unix.Trojan.Mirai-9936831-0 |
Bitdefender Antivirus (Linux) | Trojan.Linux.GenericKDZ.199 |
Kaspersky Standard (Windows) | HEUR:Backdoor.Linux.Mirai.h |
Emsisoft Commandline Scanner (Windows) | Trojan.Linux.GenericKDZ.199 (B) |
Lionic | Trojan.Linux.Mirai.K!c |
Cynet | Malicious (score: 99) |
CTX | elf.trojan.mirai |
Skyhigh | GenericRXVU-US!C646AC6B824F |
McAfee | GenericRXVU-US!C646AC6B824F |
VIPRE | Trojan.Linux.GenericKDZ.199 |
Sangfor | Backdoor.Linux.Mirai.V9yw |
Arcabit | Trojan.Linux.Generic.199 |
Symantec | Linux.Mirai |
ESET-NOD32 | a variant of Linux/Mirai.A |
Avast | ELF:Mirai-GG [Trj] |
ClamAV | Unix.Trojan.Mirai-9936831-0 |
Kaspersky | HEUR:Backdoor.Linux.Mirai.h |
BitDefender | Trojan.Linux.GenericKDZ.199 |
MicroWorld-eScan | Trojan.Linux.GenericKDZ.199 |
Rising | Backdoor.Mirai/Linux!1.DAED (CLOUD) |
Emsisoft | Trojan.Linux.GenericKDZ.199 (B) |
F-Secure | Exploit.EXP/ELF.Agent.F.118 |
DrWeb | Linux.Siggen.9999 |
Sophos | Linux/DDoS-CI |
Ikarus | Trojan.Linux.Mirai |
FireEye | Trojan.Linux.GenericKDZ.199 |
Jiangmin | Backdoor.Linux.hzqw |
Detected | |
Avira | EXP/ELF.Agent.F.118 |
Antiy-AVL | Trojan[Backdoor]/Linux.Mirai.b |
Kingsoft | Linux.Backdoor.Mirai.h |
Microsoft | Trojan:Linux/Multiverze |
GData | Trojan.Linux.GenericKDZ.199 |
Varist | E32/Mirai.BMP |
Tencent | Backdoor.Linux.Mirai.was |
huorong | Trojan/Linux.Mirai.g |
Fortinet | ELF/Mirai.GG!tr |
AVG | ELF:Mirai-GG [Trj] |