File cnc

Size 6.9MB
Type ELF 64-bit LSB executable, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/ld-linux-x86-64.so.2, Go BuildID=5rlhVMnn6VaCrmdV6vU0/5kVK9llJeenALZqs0g3S/LqnOb4ZkzocenBSN4f6u/1aneBCl380pO4WV_6vi6, with debug_info, not stripped
MD5 a2d000aeb5a09d2c29a7a811bc0c07be
SHA1 e5679b1213711438baf1dacf6f861d04aed4f6bb
SHA256 938efd737e40d9c7046664151d430dc838d8b776570f46119ff372e2fa02d098
SHA512
d16c858d67dbd94f7e59ea1bbc8046c315cec35b1dfa979c929361a545c40bbfcbc2f6671525618395b4aa47aaf8cc6b070bed9c8cf6e284110f7f2013c3af7f
CRC32 7B9D4B76
ssdeep None
Yara None matched

Score

This file is very suspicious, with a score of 10 out of 10!

Please notice: The scoring system is currently still in development and should be considered an alpha feature.


Feedback

Expecting different results? Send us this analysis and we will inspect it. Click here

Information on Execution

Analysis
Category Started Completed Duration Routing Logs
FILE July 6, 2025, 1:23 p.m. July 6, 2025, 1:24 p.m. 90 seconds internet Show Analyzer Log
Show Cuckoo Log

Analyzer Log

2025-07-06 13:22:55,007 [root] DEBUG: Starting analyzer from: /tmp/tmpwK3g2O
2025-07-06 13:22:55,007 [root] DEBUG: Storing results at: /tmp/lZErEY
2025-07-06 13:22:57,152 [modules.auxiliary.filecollector] INFO: FileCollector started v0.08
2025-07-06 13:22:57,654 [modules.auxiliary.human] INFO: Human started v0.02
2025-07-06 13:22:57,655 [modules.auxiliary.screenshots] INFO: Screenshots started v0.03
2025-07-06 13:23:04,717 [lib.core.packages] INFO: Process startup took 7.06 seconds
2025-07-06 13:23:04,720 [root] INFO: Added new process to list with pid: 3837
2025-07-06 13:23:10,737 [root] INFO: Process with pid 3837 has terminated
2025-07-06 13:23:10,738 [root] INFO: Process list is empty, terminating analysis.
2025-07-06 13:23:13,741 [lib.core.packages] INFO: Package requested stop
2025-07-06 13:23:13,742 [lib.core.packages] WARNING: Exception uploading log: [Errno 3] No such process

Cuckoo Log

2025-07-06 13:23:06,645 [cuckoo.core.scheduler] INFO: Task #6658938: acquired machine Ubuntu1904x644 (label=Ubuntu1904x644)
2025-07-06 13:23:06,646 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.104 for task #6658938
2025-07-06 13:23:07,080 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 1009926 (interface=vboxnet0, host=192.168.168.104)
2025-07-06 13:23:07,124 [cuckoo.machinery.virtualbox] DEBUG: Starting vm Ubuntu1904x644
2025-07-06 13:23:07,977 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine Ubuntu1904x644 to Snapshot
2025-07-06 13:23:20,271 [cuckoo.core.guest] INFO: Starting analysis #6658938 on guest (id=Ubuntu1904x644, ip=192.168.168.104)
2025-07-06 13:23:21,278 [cuckoo.core.guest] DEBUG: Ubuntu1904x644: not ready yet
2025-07-06 13:23:26,304 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=Ubuntu1904x644, ip=192.168.168.104)
2025-07-06 13:23:26,332 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=Ubuntu1904x644, ip=192.168.168.104, monitor=latest, size=73219)
2025-07-06 13:23:26,905 [cuckoo.core.resultserver] DEBUG: Task #6658938: live log analysis.log initialized.
2025-07-06 13:23:35,515 [cuckoo.core.resultserver] DEBUG: Task #6658938: File upload for 'shots/0001.jpg'
2025-07-06 13:23:35,552 [cuckoo.core.resultserver] DEBUG: Task #6658938 uploaded file length: 171485
2025-07-06 13:23:41,891 [cuckoo.core.guest] DEBUG: Ubuntu1904x644: analysis #6658938 still processing
2025-07-06 13:23:45,660 [cuckoo.core.resultserver] DEBUG: Task #6658938: File upload for 'logs/all.stap'
2025-07-06 13:23:45,663 [cuckoo.core.resultserver] DEBUG: Task #6658938 uploaded file length: 2684
2025-07-06 13:23:56,978 [cuckoo.core.guest] DEBUG: Ubuntu1904x644: analysis #6658938 still processing
2025-07-06 13:24:12,193 [cuckoo.core.guest] DEBUG: Ubuntu1904x644: analysis #6658938 still processing
2025-07-06 13:24:27,260 [cuckoo.core.guest] INFO: Ubuntu1904x644: end of analysis reached!
2025-07-06 13:24:27,274 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks
2025-07-06 13:24:27,309 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer
2025-07-06 13:24:28,488 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label Ubuntu1904x644 to path /srv/cuckoo/cwd/storage/analyses/6658938/memory.dmp
2025-07-06 13:24:28,489 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm Ubuntu1904x644
2025-07-06 13:24:36,248 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.104 for task #6658938
2025-07-06 13:24:36,249 [cuckoo.core.resultserver] DEBUG: Cancel <Context for LOG> for task 6658938
2025-07-06 13:24:36,568 [cuckoo.core.scheduler] DEBUG: Released database task #6658938
2025-07-06 13:24:36,588 [cuckoo.core.scheduler] INFO: Task #6658938: analysis procedure completed

Signatures

File has been identified by 3 AntiVirus engine on IRMA as malicious (3 events)
Avast Core Security (Linux) ELF:Agent-BVY [Trj]
ESET Security (Windows) a variant of Linux/HackTool.Mirai.F application
Kaspersky Standard (Windows) HEUR:HackTool.Linux.Mirai.a
File has been identified by 9 AntiVirus engines on VirusTotal as malicious (9 events)
ESET-NOD32 a variant of Linux/HackTool.Mirai.F
Avast ELF:Agent-BVY [Trj]
Kaspersky HEUR:HackTool.Linux.Mirai.a
Rising Hacktool.Mirai/Linux!8.1393C (CLOUD)
Kingsoft Linux.HackTool.Mirai.a
Microsoft Trojan:Script/Wacatac.B!ml
Tencent Linux.Hacktool.Mirai.Dkjl
AVG ELF:Agent-BVY [Trj]
alibabacloud DDoS:Linux/Mirai.F
Screenshots
Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action VT Location
No hosts contacted.
Cuckoo

We're processing your submission... This could take a few seconds.