File 449847d4fdf4e61628d905ae696709563a144742224ef05df043f7bef715c35b

Size 40.4KB
Type ELF 32-bit MSB executable, Motorola m68k, 68020, version 1 (SYSV), statically linked, missing section headers at 60620
MD5 d8f4543c67326d50c067b1a469391b38
SHA1 75f2a2a6c66773a1af64f965579d51268ab174e4
SHA256 449847d4fdf4e61628d905ae696709563a144742224ef05df043f7bef715c35b
SHA512
07890b963852bc68ecf67ab31498a827b7fa5f9af7e30d1474976edcffb4bb8e621df8dd90a1ccd967fd1e9dcd76bdb1bd052080ea4132df1eac2a03113108bd
CRC32 E7A65913
ssdeep None
Yara None matched

Score

This file is very suspicious, with a score of 10 out of 10!

Please notice: The scoring system is currently still in development and should be considered an alpha feature.


Feedback

Expecting different results? Send us this analysis and we will inspect it. Click here

Information on Execution

Analysis
Category Started Completed Duration Routing Logs
FILE July 18, 2025, 4:36 a.m. July 18, 2025, 4:41 a.m. 272 seconds internet Show Analyzer Log
Show Cuckoo Log

Analyzer Log

2025-07-18 04:24:37,003 [root] DEBUG: Starting analyzer from: /tmp/tmpWwsrjJ
2025-07-18 04:24:37,004 [root] DEBUG: Storing results at: /tmp/frLZTHCFhQ
2025-07-18 04:24:38,470 [modules.auxiliary.filecollector] INFO: FileCollector started v0.08
2025-07-18 04:24:38,473 [modules.auxiliary.human] INFO: Human started v0.02
2025-07-18 04:24:38,974 [modules.auxiliary.screenshots] INFO: Screenshots started v0.03
2025-07-18 04:24:44,732 [lib.core.packages] INFO: Process startup took 5.75 seconds
2025-07-18 04:24:44,732 [root] INFO: Added new process to list with pid: 2073
2025-07-18 04:24:53,745 [root] INFO: Process with pid 2073 has terminated
2025-07-18 04:24:53,746 [root] INFO: Process list is empty, terminating analysis.
2025-07-18 04:24:56,843 [lib.core.packages] INFO: Package requested stop
2025-07-18 04:24:56,843 [lib.core.packages] WARNING: Exception uploading log: [Errno 3] No such process

Cuckoo Log

2025-07-18 04:36:46,841 [cuckoo.core.scheduler] INFO: Task #6743196: acquired machine Ubuntu1904x646 (label=Ubuntu1904x646)
2025-07-18 04:36:46,841 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.106 for task #6743196
2025-07-18 04:36:47,121 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 1711729 (interface=vboxnet0, host=192.168.168.106)
2025-07-18 04:36:47,164 [cuckoo.machinery.virtualbox] DEBUG: Starting vm Ubuntu1904x646
2025-07-18 04:36:48,047 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine Ubuntu1904x646 to Snapshot
2025-07-18 04:38:16,608 [cuckoo.core.guest] INFO: Starting analysis #6743196 on guest (id=Ubuntu1904x646, ip=192.168.168.106)
2025-07-18 04:38:17,613 [cuckoo.core.guest] DEBUG: Ubuntu1904x646: not ready yet
2025-07-18 04:38:22,649 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=Ubuntu1904x646, ip=192.168.168.106)
2025-07-18 04:38:22,721 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=Ubuntu1904x646, ip=192.168.168.106, monitor=latest, size=73219)
2025-07-18 04:38:23,334 [cuckoo.core.resultserver] DEBUG: Task #6743196: live log analysis.log initialized.
2025-07-18 04:38:27,578 [cuckoo.core.resultserver] DEBUG: Task #6743196: File upload for 'shots/0001.jpg'
2025-07-18 04:38:27,595 [cuckoo.core.resultserver] DEBUG: Task #6743196 uploaded file length: 171553
2025-07-18 04:38:37,985 [cuckoo.core.guest] DEBUG: Ubuntu1904x646: analysis #6743196 still processing
2025-07-18 04:38:42,771 [cuckoo.core.resultserver] DEBUG: Task #6743196: File upload for 'logs/all.stap'
2025-07-18 04:38:42,778 [cuckoo.core.resultserver] DEBUG: Task #6743196 uploaded file length: 19334
2025-07-18 04:38:53,061 [cuckoo.core.guest] DEBUG: Ubuntu1904x646: analysis #6743196 still processing
2025-07-18 04:39:08,137 [cuckoo.core.guest] DEBUG: Ubuntu1904x646: analysis #6743196 still processing
2025-07-18 04:39:23,345 [cuckoo.core.guest] INFO: Ubuntu1904x646: end of analysis reached!
2025-07-18 04:39:23,361 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks
2025-07-18 04:39:23,386 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer
2025-07-18 04:39:24,745 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label Ubuntu1904x646 to path /srv/cuckoo/cwd/storage/analyses/6743196/memory.dmp
2025-07-18 04:39:24,746 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm Ubuntu1904x646
2025-07-18 04:41:18,452 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.106 for task #6743196
2025-07-18 04:41:18,481 [cuckoo.core.resultserver] DEBUG: Cancel <Context for LOG> for task 6743196
2025-07-18 04:41:18,916 [cuckoo.core.scheduler] DEBUG: Released database task #6743196
2025-07-18 04:41:18,936 [cuckoo.core.scheduler] INFO: Task #6743196: analysis procedure completed

Signatures

File has been identified by 6 AntiVirus engine on IRMA as malicious (6 events)
Avast Core Security (Linux) ELF:Mirai-PB [Trj]
C4S ClamAV (Linux) Unix.Trojan.Mirai-6981989-0
WithSecure (Linux) Malware.LINUX/AVI.Mirai.ledgt
Sophos Anti-Virus (Linux) Mal/Generic-S
ClamAV (Linux) Unix.Trojan.Mirai-6981989-0
Kaspersky Standard (Windows) HEUR:Backdoor.Linux.Mirai.b
File has been identified by 10 AntiVirus engines on VirusTotal as malicious (10 events)
Sangfor Suspicious.Linux.Save.a
Avast ELF:Mirai-PB [Trj]
ClamAV Unix.Trojan.Mirai-6981989-0
Kaspersky HEUR:Backdoor.Linux.Mirai.b
Ikarus Backdoor.Linux.Mirai
Google Detected
Microsoft Trojan:Script/Wacatac.B!ml
Varist E32/Mirai.DT.gen!Eldorado
Tencent Backdoor.Linux.Mirai.wcz
AVG ELF:Mirai-PB [Trj]
Screenshots
Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action VT Location
No hosts contacted.
Cuckoo

We're processing your submission... This could take a few seconds.