File top1miku.sh4

Size 110.8KB
Type ELF 32-bit LSB executable, Renesas SH, version 1 (SYSV), statically linked, stripped
MD5 ee1541a760dca618b7d3affde1ed7587
SHA1 ca5851fd5cd7b0c13f8e83c84a786c1e52b09438
SHA256 291645ff9db29f1f06675fa70e6615fb2c13e66e0b57fee6a2600724b776c80d
SHA512
2efc0504cee17e6b47e7f4067e60c635a75ec68ab3a99e1370f3fddcc2ae261630b9242271ac4563914f341b6b2152f34caa0ea1006b7996c450784977a97ae3
CRC32 EF803BED
ssdeep None
Yara None matched

Score

This file is very suspicious, with a score of 8.6 out of 10!

Please notice: The scoring system is currently still in development and should be considered an alpha feature.


Feedback

Expecting different results? Send us this analysis and we will inspect it. Click here

Information on Execution

Analysis
Category Started Completed Duration Routing Logs
FILE July 13, 2025, 6:59 a.m. July 13, 2025, 7:03 a.m. 237 seconds internet Show Analyzer Log
Show Cuckoo Log

Analyzer Log

2025-07-13 06:56:04,006 [root] DEBUG: Starting analyzer from: /tmp/tmpjExh_W
2025-07-13 06:56:04,007 [root] DEBUG: Storing results at: /tmp/NqYIauFdm
2025-07-13 06:56:05,815 [modules.auxiliary.filecollector] INFO: FileCollector started v0.08
2025-07-13 06:56:05,817 [modules.auxiliary.human] INFO: Human started v0.02
2025-07-13 06:56:05,819 [modules.auxiliary.screenshots] INFO: Screenshots started v0.03
2025-07-13 06:56:14,768 [lib.core.packages] INFO: Process startup took 8.94 seconds
2025-07-13 06:56:14,776 [root] INFO: Added new process to list with pid: 2078
2025-07-13 06:56:23,789 [root] INFO: Process with pid 2078 has terminated
2025-07-13 06:56:23,791 [root] INFO: Process list is empty, terminating analysis.
2025-07-13 06:56:26,795 [lib.core.packages] INFO: Package requested stop
2025-07-13 06:56:26,797 [lib.core.packages] WARNING: Exception uploading log: [Errno 3] No such process
2025-07-13 06:56:31,636 [root] INFO: Terminating remaining processes before shutdown.
2025-07-13 06:56:31,639 [root] INFO: Analysis completed.

Cuckoo Log

2025-07-13 06:59:41,566 [cuckoo.core.scheduler] INFO: Task #6725392: acquired machine Ubuntu1904x643 (label=Ubuntu1904x643)
2025-07-13 06:59:41,566 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.103 for task #6725392
2025-07-13 06:59:41,809 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 3022620 (interface=vboxnet0, host=192.168.168.103)
2025-07-13 06:59:41,841 [cuckoo.machinery.virtualbox] DEBUG: Starting vm Ubuntu1904x643
2025-07-13 06:59:42,590 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine Ubuntu1904x643 to Snapshot
2025-07-13 07:00:50,603 [cuckoo.core.guest] INFO: Starting analysis #6725392 on guest (id=Ubuntu1904x643, ip=192.168.168.103)
2025-07-13 07:00:51,608 [cuckoo.core.guest] DEBUG: Ubuntu1904x643: not ready yet
2025-07-13 07:00:56,639 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=Ubuntu1904x643, ip=192.168.168.103)
2025-07-13 07:00:56,665 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=Ubuntu1904x643, ip=192.168.168.103, monitor=latest, size=73219)
2025-07-13 07:00:56,915 [cuckoo.core.resultserver] DEBUG: Task #6725392: live log analysis.log initialized.
2025-07-13 07:01:02,036 [cuckoo.core.resultserver] DEBUG: Task #6725392: File upload for 'shots/0001.jpg'
2025-07-13 07:01:02,044 [cuckoo.core.resultserver] DEBUG: Task #6725392 uploaded file length: 171543
2025-07-13 07:01:12,170 [cuckoo.core.guest] DEBUG: Ubuntu1904x643: analysis #6725392 still processing
2025-07-13 07:01:19,714 [cuckoo.core.resultserver] DEBUG: Task #6725392: File upload for 'logs/all.stap'
2025-07-13 07:01:19,721 [cuckoo.core.resultserver] DEBUG: Task #6725392 uploaded file length: 98659
2025-07-13 07:01:27,280 [cuckoo.core.guest] INFO: Ubuntu1904x643: analysis completed successfully
2025-07-13 07:01:27,307 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks
2025-07-13 07:01:27,336 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer
2025-07-13 07:01:28,232 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label Ubuntu1904x643 to path /srv/cuckoo/cwd/storage/analyses/6725392/memory.dmp
2025-07-13 07:01:28,234 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm Ubuntu1904x643
2025-07-13 07:03:38,090 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.103 for task #6725392
2025-07-13 07:03:38,470 [cuckoo.core.scheduler] DEBUG: Released database task #6725392
2025-07-13 07:03:38,491 [cuckoo.core.scheduler] INFO: Task #6725392: analysis procedure completed

Signatures

File has been identified by 8 AntiVirus engine on IRMA as malicious (8 events)
Avast Core Security (Linux) ELF:Mirai-ATL [Trj]
C4S ClamAV (Linux) Unix.Dropper.Mirai-7136288-0
Trellix (Linux) GenericRXUA-QE
WithSecure (Linux) Exploit.EXP/ELF.Mirai.Z.A
ESET Security (Windows) a variant of Linux/Mirai.CEA trojan
DrWeb Antivirus (Linux) Linux.Siggen.9999
ClamAV (Linux) Unix.Dropper.Mirai-7136288-0
Kaspersky Standard (Windows) HEUR:Backdoor.Linux.Mirai.cw
Screenshots
Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action VT Location
No hosts contacted.
Cuckoo

We're processing your submission... This could take a few seconds.