Size | 110.8KB |
---|---|
Type | ELF 32-bit LSB executable, Renesas SH, version 1 (SYSV), statically linked, stripped |
MD5 | ee1541a760dca618b7d3affde1ed7587 |
SHA1 | ca5851fd5cd7b0c13f8e83c84a786c1e52b09438 |
SHA256 | 291645ff9db29f1f06675fa70e6615fb2c13e66e0b57fee6a2600724b776c80d |
SHA512 |
2efc0504cee17e6b47e7f4067e60c635a75ec68ab3a99e1370f3fddcc2ae261630b9242271ac4563914f341b6b2152f34caa0ea1006b7996c450784977a97ae3
|
CRC32 | EF803BED |
ssdeep | None |
Yara | None matched |
This file is very suspicious, with a score of 8.6 out of 10!
Please notice: The scoring system is currently still in development and should be considered an alpha feature.
Expecting different results? Send us this analysis and we will inspect it. Click here
Category | Started | Completed | Duration | Routing | Logs |
---|---|---|---|---|---|
FILE | July 13, 2025, 6:59 a.m. | July 13, 2025, 7:03 a.m. | 237 seconds | internet |
Show Analyzer Log Show Cuckoo Log |
2025-07-13 06:56:04,006 [root] DEBUG: Starting analyzer from: /tmp/tmpjExh_W 2025-07-13 06:56:04,007 [root] DEBUG: Storing results at: /tmp/NqYIauFdm 2025-07-13 06:56:05,815 [modules.auxiliary.filecollector] INFO: FileCollector started v0.08 2025-07-13 06:56:05,817 [modules.auxiliary.human] INFO: Human started v0.02 2025-07-13 06:56:05,819 [modules.auxiliary.screenshots] INFO: Screenshots started v0.03 2025-07-13 06:56:14,768 [lib.core.packages] INFO: Process startup took 8.94 seconds 2025-07-13 06:56:14,776 [root] INFO: Added new process to list with pid: 2078 2025-07-13 06:56:23,789 [root] INFO: Process with pid 2078 has terminated 2025-07-13 06:56:23,791 [root] INFO: Process list is empty, terminating analysis. 2025-07-13 06:56:26,795 [lib.core.packages] INFO: Package requested stop 2025-07-13 06:56:26,797 [lib.core.packages] WARNING: Exception uploading log: [Errno 3] No such process 2025-07-13 06:56:31,636 [root] INFO: Terminating remaining processes before shutdown. 2025-07-13 06:56:31,639 [root] INFO: Analysis completed.
2025-07-13 06:59:41,566 [cuckoo.core.scheduler] INFO: Task #6725392: acquired machine Ubuntu1904x643 (label=Ubuntu1904x643) 2025-07-13 06:59:41,566 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.103 for task #6725392 2025-07-13 06:59:41,809 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 3022620 (interface=vboxnet0, host=192.168.168.103) 2025-07-13 06:59:41,841 [cuckoo.machinery.virtualbox] DEBUG: Starting vm Ubuntu1904x643 2025-07-13 06:59:42,590 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine Ubuntu1904x643 to Snapshot 2025-07-13 07:00:50,603 [cuckoo.core.guest] INFO: Starting analysis #6725392 on guest (id=Ubuntu1904x643, ip=192.168.168.103) 2025-07-13 07:00:51,608 [cuckoo.core.guest] DEBUG: Ubuntu1904x643: not ready yet 2025-07-13 07:00:56,639 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=Ubuntu1904x643, ip=192.168.168.103) 2025-07-13 07:00:56,665 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=Ubuntu1904x643, ip=192.168.168.103, monitor=latest, size=73219) 2025-07-13 07:00:56,915 [cuckoo.core.resultserver] DEBUG: Task #6725392: live log analysis.log initialized. 2025-07-13 07:01:02,036 [cuckoo.core.resultserver] DEBUG: Task #6725392: File upload for 'shots/0001.jpg' 2025-07-13 07:01:02,044 [cuckoo.core.resultserver] DEBUG: Task #6725392 uploaded file length: 171543 2025-07-13 07:01:12,170 [cuckoo.core.guest] DEBUG: Ubuntu1904x643: analysis #6725392 still processing 2025-07-13 07:01:19,714 [cuckoo.core.resultserver] DEBUG: Task #6725392: File upload for 'logs/all.stap' 2025-07-13 07:01:19,721 [cuckoo.core.resultserver] DEBUG: Task #6725392 uploaded file length: 98659 2025-07-13 07:01:27,280 [cuckoo.core.guest] INFO: Ubuntu1904x643: analysis completed successfully 2025-07-13 07:01:27,307 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks 2025-07-13 07:01:27,336 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer 2025-07-13 07:01:28,232 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label Ubuntu1904x643 to path /srv/cuckoo/cwd/storage/analyses/6725392/memory.dmp 2025-07-13 07:01:28,234 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm Ubuntu1904x643 2025-07-13 07:03:38,090 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.103 for task #6725392 2025-07-13 07:03:38,470 [cuckoo.core.scheduler] DEBUG: Released database task #6725392 2025-07-13 07:03:38,491 [cuckoo.core.scheduler] INFO: Task #6725392: analysis procedure completed
Avast Core Security (Linux) | ELF:Mirai-ATL [Trj] |
C4S ClamAV (Linux) | Unix.Dropper.Mirai-7136288-0 |
Trellix (Linux) | GenericRXUA-QE |
WithSecure (Linux) | Exploit.EXP/ELF.Mirai.Z.A |
ESET Security (Windows) | a variant of Linux/Mirai.CEA trojan |
DrWeb Antivirus (Linux) | Linux.Siggen.9999 |
ClamAV (Linux) | Unix.Dropper.Mirai-7136288-0 |
Kaspersky Standard (Windows) | HEUR:Backdoor.Linux.Mirai.cw |