File i

Size 95.1KB
Type ELF 32-bit LSB executable, MIPS, MIPS-I version 1 (SYSV), statically linked, no section header
MD5 dd516aa327c6414d931227c52875f60f
SHA1 ea8cd22efa3cf57d12182a9f93a37cdbb563afed
SHA256 454e40f8b839f7f148239d63f88fffbf951f8b53997b16e13ac751a5aed64e30
SHA512
a7f3ccde3c447db9522611a67f65fb55aaf85f8abc782a6609611b51e70b51967e09dd3e05d19f8f3f0dc0735c9d305b26b2530715367ac26d0ffc349f39d4ba
CRC32 24FFC157
ssdeep None
Yara None matched

Score

This file is very suspicious, with a score of 8.6 out of 10!

Please notice: The scoring system is currently still in development and should be considered an alpha feature.


Feedback

Expecting different results? Send us this analysis and we will inspect it. Click here

Information on Execution

Analysis
Category Started Completed Duration Routing Logs
FILE Nov. 26, 2025, 1:28 a.m. Nov. 26, 2025, 1:30 a.m. 86 seconds internet Show Analyzer Log
Show Cuckoo Log

Analyzer Log

2025-11-26 01:28:41,007 [root] DEBUG: Starting analyzer from: /tmp/tmpV4mq8x
2025-11-26 01:28:41,007 [root] DEBUG: Storing results at: /tmp/RBhFPp
2025-11-26 01:28:42,983 [modules.auxiliary.filecollector] INFO: FileCollector started v0.08
2025-11-26 01:28:43,488 [modules.auxiliary.human] INFO: Human started v0.02
2025-11-26 01:28:43,994 [modules.auxiliary.screenshots] INFO: Screenshots started v0.03
2025-11-26 01:28:49,180 [lib.core.packages] INFO: Process startup took 5.18 seconds
2025-11-26 01:28:49,181 [root] INFO: Added new process to list with pid: 2061
2025-11-26 01:28:55,198 [root] INFO: Process with pid 2061 has terminated
2025-11-26 01:28:55,199 [root] INFO: Process list is empty, terminating analysis.
2025-11-26 01:28:58,205 [lib.core.packages] INFO: Package requested stop
2025-11-26 01:28:58,206 [lib.core.packages] WARNING: Exception uploading log: [Errno 3] No such process

Cuckoo Log

2025-11-26 01:28:50,904 [cuckoo.core.scheduler] INFO: Task #7203847: acquired machine Ubuntu1904x641 (label=Ubuntu1904x641)
2025-11-26 01:28:50,905 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.101 for task #7203847
2025-11-26 01:28:51,227 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 996696 (interface=vboxnet0, host=192.168.168.101)
2025-11-26 01:28:51,255 [cuckoo.machinery.virtualbox] DEBUG: Starting vm Ubuntu1904x641
2025-11-26 01:28:52,628 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine Ubuntu1904x641 to Snapshot
2025-11-26 01:29:01,080 [cuckoo.core.guest] INFO: Starting analysis #7203847 on guest (id=Ubuntu1904x641, ip=192.168.168.101)
2025-11-26 01:29:02,085 [cuckoo.core.guest] DEBUG: Ubuntu1904x641: not ready yet
2025-11-26 01:29:07,111 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=Ubuntu1904x641, ip=192.168.168.101)
2025-11-26 01:29:07,136 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=Ubuntu1904x641, ip=192.168.168.101, monitor=latest, size=73219)
2025-11-26 01:29:07,367 [cuckoo.core.resultserver] DEBUG: Task #7203847: live log analysis.log initialized.
2025-11-26 01:29:12,621 [cuckoo.core.resultserver] DEBUG: Task #7203847: File upload for 'shots/0001.jpg'
2025-11-26 01:29:12,627 [cuckoo.core.resultserver] DEBUG: Task #7203847 uploaded file length: 171642
2025-11-26 01:29:22,327 [cuckoo.core.guest] DEBUG: Ubuntu1904x641: analysis #7203847 still processing
2025-11-26 01:29:24,586 [cuckoo.core.resultserver] DEBUG: Task #7203847: File upload for 'logs/all.stap'
2025-11-26 01:29:24,589 [cuckoo.core.resultserver] DEBUG: Task #7203847 uploaded file length: 18872
2025-11-26 01:29:37,412 [cuckoo.core.guest] DEBUG: Ubuntu1904x641: analysis #7203847 still processing
2025-11-26 01:29:52,496 [cuckoo.core.guest] DEBUG: Ubuntu1904x641: analysis #7203847 still processing
2025-11-26 01:30:07,563 [cuckoo.core.guest] INFO: Ubuntu1904x641: end of analysis reached!
2025-11-26 01:30:07,578 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks
2025-11-26 01:30:07,606 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer
2025-11-26 01:30:08,765 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label Ubuntu1904x641 to path /srv/cuckoo/cwd/storage/analyses/7203847/memory.dmp
2025-11-26 01:30:08,766 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm Ubuntu1904x641
2025-11-26 01:30:17,179 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.101 for task #7203847
2025-11-26 01:30:17,179 [cuckoo.core.resultserver] DEBUG: Cancel <Context for LOG> for task 7203847
2025-11-26 01:30:17,479 [cuckoo.core.scheduler] DEBUG: Released database task #7203847
2025-11-26 01:30:17,497 [cuckoo.core.scheduler] INFO: Task #7203847: analysis procedure completed

Signatures

File has been identified by 9 AntiVirus engine on IRMA as malicious (9 events)
G Data Antivirus (Windows) Virus: Trojan.Linux.Mirai.GJN (Engine A)
Avast Core Security (Linux) ELF:Agent-BMN [Trj]
C4S ClamAV (Linux) Unix.Malware.Generic-10008314-0
Trellix (Linux) GenericRXPH-BZ
eScan Antivirus (Linux) Trojan.Linux.Mirai.GJN(DB)
DrWeb Antivirus (Linux) Linux.Packed.1255
ClamAV (Linux) Unix.Malware.Generic-10008314-0
Bitdefender Antivirus (Linux) Trojan.Linux.Mirai.GJN
Emsisoft Commandline Scanner (Windows) Trojan.Linux.Mirai.GJN (B)
Screenshots
Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action VT Location
No hosts contacted.
Cuckoo

We're processing your submission... This could take a few seconds.