| Size | 999.0KB |
|---|---|
| Type | ELF 64-bit LSB executable, x86-64, version 1 (GNU/Linux), statically linked, BuildID[sha1]=d30a80e55b8fa9af1581b4dc3fd9a0db3895ff07, for GNU/Linux 3.2.0, not stripped |
| MD5 | fe0ae9ef911bbbba8c1657336f355a9f |
| SHA1 | f9e5cd317e5d56d39a84a41ac3663f14f1b3e90e |
| SHA256 | 0c130916ff8e1426603352d2f63564c08522c9d5054f7d09b1c45655d2c5020a |
| SHA512 |
e9024e689634c86d82f60d8bfbb9fbb745c7ef7dabbc5ae760633395b62c28208a422d04516d6578924dfb3df735f6538ccc2e7e1f4615450237c106e28ba7ce
|
| CRC32 | 4ECEBE95 |
| ssdeep | None |
| Yara | None matched |
This file is very suspicious, with a score of 10 out of 10!
Please notice: The scoring system is currently still in development and should be considered an alpha feature.
Expecting different results? Send us this analysis and we will inspect it. Click here
| Category | Started | Completed | Duration | Routing | Logs |
|---|---|---|---|---|---|
| FILE | Feb. 9, 2026, 12:31 a.m. | Feb. 9, 2026, 12:32 a.m. | 83 seconds | internet |
Show Analyzer Log Show Cuckoo Log |
2026-02-09 00:31:28,004 [root] DEBUG: Starting analyzer from: /tmp/tmprOaMMR 2026-02-09 00:31:28,005 [root] DEBUG: Storing results at: /tmp/uODJKXO 2026-02-09 00:31:29,611 [modules.auxiliary.filecollector] INFO: FileCollector started v0.08 2026-02-09 00:31:30,115 [modules.auxiliary.human] INFO: Human started v0.02 2026-02-09 00:31:30,116 [modules.auxiliary.screenshots] INFO: Screenshots started v0.03 2026-02-09 00:31:35,470 [lib.core.packages] INFO: Process startup took 5.35 seconds 2026-02-09 00:31:35,472 [root] INFO: Added new process to list with pid: 2072 2026-02-09 00:31:44,483 [root] INFO: Process with pid 2072 has terminated 2026-02-09 00:31:44,483 [root] INFO: Process list is empty, terminating analysis. 2026-02-09 00:31:47,493 [lib.core.packages] INFO: Package requested stop 2026-02-09 00:31:47,494 [lib.core.packages] WARNING: Exception uploading log: [Errno 3] No such process
2026-02-09 00:31:29,091 [cuckoo.core.scheduler] INFO: Task #7452501: acquired machine Ubuntu1904x646 (label=Ubuntu1904x646) 2026-02-09 00:31:29,091 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.106 for task #7452501 2026-02-09 00:31:29,421 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 1542611 (interface=vboxnet0, host=192.168.168.106) 2026-02-09 00:31:29,452 [cuckoo.machinery.virtualbox] DEBUG: Starting vm Ubuntu1904x646 2026-02-09 00:31:30,021 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine Ubuntu1904x646 to Snapshot 2026-02-09 00:31:37,098 [cuckoo.core.guest] INFO: Starting analysis #7452501 on guest (id=Ubuntu1904x646, ip=192.168.168.106) 2026-02-09 00:31:38,103 [cuckoo.core.guest] DEBUG: Ubuntu1904x646: not ready yet 2026-02-09 00:31:43,130 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=Ubuntu1904x646, ip=192.168.168.106) 2026-02-09 00:31:43,157 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=Ubuntu1904x646, ip=192.168.168.106, monitor=latest, size=73219) 2026-02-09 00:31:43,455 [cuckoo.core.resultserver] DEBUG: Task #7452501: live log analysis.log initialized. 2026-02-09 00:31:48,490 [cuckoo.core.resultserver] DEBUG: Task #7452501: File upload for 'shots/0001.jpg' 2026-02-09 00:31:48,537 [cuckoo.core.resultserver] DEBUG: Task #7452501 uploaded file length: 171518 2026-02-09 00:31:58,604 [cuckoo.core.guest] DEBUG: Ubuntu1904x646: analysis #7452501 still processing 2026-02-09 00:32:02,961 [cuckoo.core.resultserver] DEBUG: Task #7452501: File upload for 'logs/all.stap' 2026-02-09 00:32:03,018 [cuckoo.core.resultserver] DEBUG: Task #7452501 uploaded file length: 943086 2026-02-09 00:32:13,689 [cuckoo.core.guest] DEBUG: Ubuntu1904x646: analysis #7452501 still processing 2026-02-09 00:32:28,786 [cuckoo.core.guest] DEBUG: Ubuntu1904x646: analysis #7452501 still processing 2026-02-09 00:32:43,853 [cuckoo.core.guest] INFO: Ubuntu1904x646: end of analysis reached! 2026-02-09 00:32:43,864 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks 2026-02-09 00:32:43,906 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer 2026-02-09 00:32:44,862 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label Ubuntu1904x646 to path /srv/cuckoo/cwd/storage/analyses/7452501/memory.dmp 2026-02-09 00:32:44,863 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm Ubuntu1904x646 2026-02-09 00:32:52,402 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.106 for task #7452501 2026-02-09 00:32:52,403 [cuckoo.core.resultserver] DEBUG: Cancel <Context for LOG> for task 7452501 2026-02-09 00:32:52,740 [cuckoo.core.scheduler] DEBUG: Released database task #7452501 2026-02-09 00:32:52,756 [cuckoo.core.scheduler] INFO: Task #7452501: analysis procedure completed
| snort | ET INFO curl User-Agent to Dotted Quad |
| snort | ET POLICY Executable and linking format (ELF) file download Over HTTP |
| snort | COMMUNITY MISC BAD-SSL tcp detect |
| Trellix (Linux) | GenericRXUG-XK |
| WithSecure (Linux) | Trojan:W32/Generic.abch!mind |
| Kaspersky Standard (Windows) | UDS:HackTool.Linux.Gsnetcat.gen |
| Skyhigh | GenericRXUG-XK!FE0AE9EF911B |
| Rising | Trojan.CoinMiner/Linux!8.132F9 (TFE:1C:fhj8gLLjMmH) |
| SentinelOne | Static AI - Suspicious ELF |
| TrellixENS | GenericRXUG-XK!FE0AE9EF911B |
| alibabacloud | Miner:Linux/XMRigLoader |