File err

Size 999.0KB
Type ELF 64-bit LSB executable, x86-64, version 1 (GNU/Linux), statically linked, BuildID[sha1]=d30a80e55b8fa9af1581b4dc3fd9a0db3895ff07, for GNU/Linux 3.2.0, not stripped
MD5 fe0ae9ef911bbbba8c1657336f355a9f
SHA1 f9e5cd317e5d56d39a84a41ac3663f14f1b3e90e
SHA256 0c130916ff8e1426603352d2f63564c08522c9d5054f7d09b1c45655d2c5020a
SHA512
e9024e689634c86d82f60d8bfbb9fbb745c7ef7dabbc5ae760633395b62c28208a422d04516d6578924dfb3df735f6538ccc2e7e1f4615450237c106e28ba7ce
CRC32 4ECEBE95
ssdeep None
Yara None matched

Score

This file is very suspicious, with a score of 10 out of 10!

Please notice: The scoring system is currently still in development and should be considered an alpha feature.


Feedback

Expecting different results? Send us this analysis and we will inspect it. Click here

Information on Execution

Analysis
Category Started Completed Duration Routing Logs
FILE Feb. 9, 2026, 12:31 a.m. Feb. 9, 2026, 12:32 a.m. 83 seconds internet Show Analyzer Log
Show Cuckoo Log

Analyzer Log

2026-02-09 00:31:28,004 [root] DEBUG: Starting analyzer from: /tmp/tmprOaMMR
2026-02-09 00:31:28,005 [root] DEBUG: Storing results at: /tmp/uODJKXO
2026-02-09 00:31:29,611 [modules.auxiliary.filecollector] INFO: FileCollector started v0.08
2026-02-09 00:31:30,115 [modules.auxiliary.human] INFO: Human started v0.02
2026-02-09 00:31:30,116 [modules.auxiliary.screenshots] INFO: Screenshots started v0.03
2026-02-09 00:31:35,470 [lib.core.packages] INFO: Process startup took 5.35 seconds
2026-02-09 00:31:35,472 [root] INFO: Added new process to list with pid: 2072
2026-02-09 00:31:44,483 [root] INFO: Process with pid 2072 has terminated
2026-02-09 00:31:44,483 [root] INFO: Process list is empty, terminating analysis.
2026-02-09 00:31:47,493 [lib.core.packages] INFO: Package requested stop
2026-02-09 00:31:47,494 [lib.core.packages] WARNING: Exception uploading log: [Errno 3] No such process

Cuckoo Log

2026-02-09 00:31:29,091 [cuckoo.core.scheduler] INFO: Task #7452501: acquired machine Ubuntu1904x646 (label=Ubuntu1904x646)
2026-02-09 00:31:29,091 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.106 for task #7452501
2026-02-09 00:31:29,421 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 1542611 (interface=vboxnet0, host=192.168.168.106)
2026-02-09 00:31:29,452 [cuckoo.machinery.virtualbox] DEBUG: Starting vm Ubuntu1904x646
2026-02-09 00:31:30,021 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine Ubuntu1904x646 to Snapshot
2026-02-09 00:31:37,098 [cuckoo.core.guest] INFO: Starting analysis #7452501 on guest (id=Ubuntu1904x646, ip=192.168.168.106)
2026-02-09 00:31:38,103 [cuckoo.core.guest] DEBUG: Ubuntu1904x646: not ready yet
2026-02-09 00:31:43,130 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=Ubuntu1904x646, ip=192.168.168.106)
2026-02-09 00:31:43,157 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=Ubuntu1904x646, ip=192.168.168.106, monitor=latest, size=73219)
2026-02-09 00:31:43,455 [cuckoo.core.resultserver] DEBUG: Task #7452501: live log analysis.log initialized.
2026-02-09 00:31:48,490 [cuckoo.core.resultserver] DEBUG: Task #7452501: File upload for 'shots/0001.jpg'
2026-02-09 00:31:48,537 [cuckoo.core.resultserver] DEBUG: Task #7452501 uploaded file length: 171518
2026-02-09 00:31:58,604 [cuckoo.core.guest] DEBUG: Ubuntu1904x646: analysis #7452501 still processing
2026-02-09 00:32:02,961 [cuckoo.core.resultserver] DEBUG: Task #7452501: File upload for 'logs/all.stap'
2026-02-09 00:32:03,018 [cuckoo.core.resultserver] DEBUG: Task #7452501 uploaded file length: 943086
2026-02-09 00:32:13,689 [cuckoo.core.guest] DEBUG: Ubuntu1904x646: analysis #7452501 still processing
2026-02-09 00:32:28,786 [cuckoo.core.guest] DEBUG: Ubuntu1904x646: analysis #7452501 still processing
2026-02-09 00:32:43,853 [cuckoo.core.guest] INFO: Ubuntu1904x646: end of analysis reached!
2026-02-09 00:32:43,864 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks
2026-02-09 00:32:43,906 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer
2026-02-09 00:32:44,862 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label Ubuntu1904x646 to path /srv/cuckoo/cwd/storage/analyses/7452501/memory.dmp
2026-02-09 00:32:44,863 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm Ubuntu1904x646
2026-02-09 00:32:52,402 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.106 for task #7452501
2026-02-09 00:32:52,403 [cuckoo.core.resultserver] DEBUG: Cancel <Context for LOG> for task 7452501
2026-02-09 00:32:52,740 [cuckoo.core.scheduler] DEBUG: Released database task #7452501
2026-02-09 00:32:52,756 [cuckoo.core.scheduler] INFO: Task #7452501: analysis procedure completed

Signatures

Raised Snort alerts (3 events)
snort ET INFO curl User-Agent to Dotted Quad
snort ET POLICY Executable and linking format (ELF) file download Over HTTP
snort COMMUNITY MISC BAD-SSL tcp detect
File has been identified by 3 AntiVirus engine on IRMA as malicious (3 events)
Trellix (Linux) GenericRXUG-XK
WithSecure (Linux) Trojan:W32/Generic.abch!mind
Kaspersky Standard (Windows) UDS:HackTool.Linux.Gsnetcat.gen
File has been identified by 5 AntiVirus engines on VirusTotal as malicious (5 events)
Skyhigh GenericRXUG-XK!FE0AE9EF911B
Rising Trojan.CoinMiner/Linux!8.132F9 (TFE:1C:fhj8gLLjMmH)
SentinelOne Static AI - Suspicious ELF
TrellixENS GenericRXUG-XK!FE0AE9EF911B
alibabacloud Miner:Linux/XMRigLoader
Screenshots
Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action VT Location
No hosts contacted.
Cuckoo

We're processing your submission... This could take a few seconds.