File 4f19bc25999c862fc4ba7305a4f38fa4f0d9e5377a58146a188379292e8d3060

Size 22.2KB
Type ELF 64-bit LSB pie executable, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/ld-linux-x86-64.so.2, BuildID[sha1]=79940469819965d3372ab03c356f0bad4ad6c075, for GNU/Linux 3.2.0, stripped
MD5 124dea269e869183b90e6d9d0745b8a0
SHA1 a280074146f5ca4e4122e125ae4cf0babb0b7766
SHA256 4f19bc25999c862fc4ba7305a4f38fa4f0d9e5377a58146a188379292e8d3060
SHA512
e931dc7327ace141bbac0091bee207611006dfaa015d4635d5ab1debb7222450cae0e62913145bdec4e49181086326c2b90f9a45625606ae0a32b661d644795b
CRC32 5FC29C44
ssdeep None
Yara None matched

Score

This file is very suspicious, with a score of 5.7 out of 10!

Please notice: The scoring system is currently still in development and should be considered an alpha feature.


Feedback

Expecting different results? Send us this analysis and we will inspect it. Click here

Information on Execution

Analysis
Category Started Completed Duration Routing Logs
FILE April 6, 2025, 2:30 a.m. April 6, 2025, 2:37 a.m. 438 seconds internet Show Analyzer Log
Show Cuckoo Log

Analyzer Log

2025-04-06 02:29:58,001 [root] DEBUG: Starting analyzer from: /tmp/tmpebOyAI
2025-04-06 02:29:58,003 [root] DEBUG: Storing results at: /tmp/lLPOKHyg
2025-04-06 02:30:00,186 [modules.auxiliary.filecollector] INFO: FileCollector started v0.08
2025-04-06 02:30:00,190 [modules.auxiliary.human] INFO: Human started v0.02
2025-04-06 02:30:00,693 [modules.auxiliary.screenshots] INFO: Screenshots started v0.03
2025-04-06 02:30:06,657 [lib.core.packages] INFO: Process startup took 5.96 seconds
2025-04-06 02:30:06,662 [root] INFO: Added new process to list with pid: 3841
2025-04-06 02:30:15,679 [root] INFO: Process with pid 3841 has terminated
2025-04-06 02:30:15,680 [root] INFO: Process list is empty, terminating analysis.
2025-04-06 02:30:18,685 [lib.core.packages] INFO: Package requested stop
2025-04-06 02:30:18,687 [lib.core.packages] WARNING: Exception uploading log: [Errno 3] No such process
2025-04-06 02:33:52,666 [root] INFO: Terminating remaining processes before shutdown.
2025-04-06 02:33:52,666 [root] INFO: Analysis completed.

Cuckoo Log

2025-04-06 02:30:14,111 [cuckoo.core.scheduler] INFO: Task #6242867: acquired machine Ubuntu1904x644 (label=Ubuntu1904x644)
2025-04-06 02:30:14,122 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.104 for task #6242867
2025-04-06 02:30:14,500 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 1366385 (interface=vboxnet0, host=192.168.168.104)
2025-04-06 02:30:14,569 [cuckoo.machinery.virtualbox] DEBUG: Starting vm Ubuntu1904x644
2025-04-06 02:30:15,274 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine Ubuntu1904x644 to Snapshot
2025-04-06 02:33:04,571 [cuckoo.core.guest] INFO: Starting analysis #6242867 on guest (id=Ubuntu1904x644, ip=192.168.168.104)
2025-04-06 02:33:05,617 [cuckoo.core.guest] DEBUG: Ubuntu1904x644: not ready yet
2025-04-06 02:33:10,838 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=Ubuntu1904x644, ip=192.168.168.104)
2025-04-06 02:33:10,878 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=Ubuntu1904x644, ip=192.168.168.104, monitor=latest, size=73219)
2025-04-06 02:33:11,360 [cuckoo.core.resultserver] DEBUG: Task #6242867: live log analysis.log initialized.
2025-04-06 02:33:20,599 [cuckoo.core.resultserver] DEBUG: Task #6242867: File upload for 'shots/0001.jpg'
2025-04-06 02:33:20,665 [cuckoo.core.resultserver] DEBUG: Task #6242867 uploaded file length: 171514
2025-04-06 02:33:26,326 [cuckoo.core.guest] DEBUG: Ubuntu1904x644: analysis #6242867 still processing
2025-04-06 02:33:31,815 [cuckoo.core.resultserver] DEBUG: Task #6242867: File upload for 'logs/all.stap'
2025-04-06 02:33:31,821 [cuckoo.core.resultserver] DEBUG: Task #6242867 uploaded file length: 2964
2025-04-06 02:33:41,660 [cuckoo.core.guest] DEBUG: Ubuntu1904x644: analysis #6242867 still processing
2025-04-06 02:33:57,121 [cuckoo.core.guest] DEBUG: Ubuntu1904x644: analysis #6242867 still processing
2025-04-06 02:34:12,657 [cuckoo.core.guest] INFO: Ubuntu1904x644: end of analysis reached!
2025-04-06 02:34:12,676 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks
2025-04-06 02:34:12,703 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer
2025-04-06 02:34:13,714 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label Ubuntu1904x644 to path /srv/cuckoo/cwd/storage/analyses/6242867/memory.dmp
2025-04-06 02:34:13,718 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm Ubuntu1904x644
2025-04-06 02:37:18,956 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.104 for task #6242867
2025-04-06 02:37:20,183 [cuckoo.core.scheduler] DEBUG: Released database task #6242867
2025-04-06 02:37:26,834 [cuckoo.core.scheduler] INFO: Task #6242867: analysis procedure completed

Signatures

File has been identified by 2 AntiVirus engine on IRMA as malicious (2 events)
Avast Core Security (Linux) ELF:Agent-DIY [Trj]
ESET Security (Windows) a variant of Linux/Flooder.Agent.IG trojan
File has been identified by 3 AntiVirus engines on VirusTotal as malicious (3 events)
ESET-NOD32 a variant of Linux/Flooder.Agent.IG
Avast ELF:Agent-DIY [Trj]
AVG ELF:Agent-DIY [Trj]
Screenshots
Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action VT Location
No hosts contacted.
Cuckoo

We're processing your submission... This could take a few seconds.