Report #3686 cancel

Binary
ABI
ELFOSABI_SYSV
Size
1.34KB
Type
ET_EXEC
trid
50.1% ELF Executable and Linkable format
49.8% ELF Executable and Linkable format
type
ELF
Wordsize
32
Architecture
x86
Hashes
md5
aeee5373c4f34a6e37b9681a0e6be1de
sha1
243e3e448cfa4399219473b239d801fd30c12eb8
crc32
0xed50a027
sha224
3e72e529b7af7445d9f4392a6e01a3c04007e743a087ce9978f6a002
sha256
5c66af93484887250cb2c15b7ea1ec6d086538509de7e13fa5839086f565166f
sha384
88e9f1b94c26a9c2d9d67eb22136dddae679016a1cf4f1a2bf7cab1e965b37981b7f962ddbb9174755fd9873aa1e0bdb
sha512
64cb108f172fb677420f8e24aaee97f7fc758d36bcc92f113ad732b98b22b6bf7b29dc7383116d308fdf66c454860d7469db830424615ce9b2519c537ea5298c
ssdeep
24:FlOjDFHxgxilyZdaqZS+NYxvv/9wyGues9OgTtEruQvTX3TSSXuvRbNfj:f6TlUda8S+exX/Jqss9HLX3esWNNL
Community
Google
True check_circle
HashLib
False cancel
YARA
Matches
domain, is__elf

Suspicious
True check_circle

Dwarf
List

Number
0
Files
Sys

Home

Proc

Password

Suspicious
False cancel
Flags
Flags
0
Packer
List
None
Packed
False cancel
Network
IPs

URLs

Mails

Suspicious
False cancel
Strings
List
GET /pein.x86 HTTP/1.0
./bigbotPein
.shstrtab
.rodata
Ninja
[^_]=
Done
[^_]
RPSW
UWVS
.text
.bss

Symbols
List

Number
0
Reason
Stripped
Suspicious
True check_circle
Version
Version
EV_CURRENT
Foremost
Matches
None
Suspicious
False cancel
Sections
List
, .text, .rodata, .bss, .shstrtab
Number
5
Suspicious
False cancel
Segments
Number
3
Suspicious
False cancel
Compilers
List

Identified
0
Suspicious
False cancel
Functions
List

Present
True check_circle
Anti-Debug
Ptrace
False cancel
Anti-disasm
False cancel
Entry Point
Address
0x8048338
Suspicious
False cancel
Embedded ELF
List
None
Identified
0
Program Header
Size
32
Number
3
Offset
52
Section Header
Size
40
Number
5
Offset
1168
AVclass
mirai
1
VirusTotal
md5
aeee5373c4f34a6e37b9681a0e6be1de
sha1
243e3e448cfa4399219473b239d801fd30c12eb8
SCANS (DETECTION RATE = 40.00%)
AVG
result: ELF:Mirai-CK [Trj]
update: 20190530
version: 18.4.3895.0
detected: True check_circle

CMC
update: 20190321
version: 1.1.0.977
detected: False cancel

MAX
update: 20190530
version: 2018.9.12.1
detected: False cancel

Bkav
update: 20190529
version: 1.3.0.10239
detected: False cancel

K7GW
update: 20190530
version: 11.46.31064
detected: False cancel

ALYac
update: 20190530
version: 1.1.1.5
detected: False cancel

Avast
result: ELF:Mirai-CK [Trj]
update: 20190530
version: 18.4.3895.0
detected: True check_circle

Avira
result: LINUX/Dldr.Mirai.bczil
update: 20190530
version: 8.3.3.8
detected: True check_circle

Baidu
update: 20190318
version: 1.0.0.2
detected: False cancel

Cyren
update: 20190530
version: 6.2.0.1
detected: False cancel

DrWeb
result: Linux.Siggen.179
update: 20190530
version: 7.0.34.11020
detected: True check_circle

GData
update: 20190530
version: A:25.22167B:25.15201
detected: False cancel

Panda
update: 20190529
version: 4.6.4.2
detected: False cancel

VBA32
update: 20190529
version: 4.0.0
detected: False cancel

VIPRE
update: 20190529
version: 75372
detected: False cancel

Zoner
update: 20190529
version: 1.0
detected: False cancel

ClamAV
update: 20190529
version: 0.101.2.0
detected: False cancel

Comodo
result: Malware@#2rzuvuiuz4cvp
update: 20190530
version: 30943
detected: True check_circle

F-Prot
update: 20190530
version: 4.7.1.166
detected: False cancel

Ikarus
result: Linux.Trojan-Downloader.Mirai
update: 20190529
version: 0.1.5.2
detected: True check_circle

McAfee
result: RDN/Generic Downloader.x
update: 20190530
version: 6.0.6.653
detected: True check_circle

Rising
update: 20190530
version: 25.0.0.24
detected: False cancel

Sophos
result: Mal/Generic-S
update: 20190530
version: 4.98.0
detected: True check_circle

Zillya
result: Downloader.Mirai.Linux.67
update: 20190529
version: 2.0.0.3821
detected: True check_circle

Arcabit
update: 20190530
version: 1.0.0.846
detected: False cancel

Babable
update: 20190424
version: 9107201
detected: False cancel

FireEye
update: 20190530
version: 29.7.0.0
detected: False cancel

TACHYON
update: 20190530
version: 2019-05-30.02
detected: False cancel

Tencent
result: Backdoor.Linux.Mirai.l
update: 20190530
version: 1.0.0.1
detected: True check_circle

ViRobot
update: 20190530
version: 2014.3.20.0
detected: False cancel

Ad-Aware
update: 20190530
version: 3.0.5.370
detected: False cancel

AegisLab
result: Trojan.Linux.Mirai.4!c
update: 20190530
version: 4.2
detected: True check_circle

Emsisoft
update: 20190530
version: 2018.4.0.1029
detected: False cancel

F-Secure
result: Malware.LINUX/Dldr.Mirai.bczil
update: 20190530
version: 12.0.86.52
detected: True check_circle

Fortinet
result: ELF/Mirai.D
update: 20190530
version: 5.4.247.0
detected: True check_circle

Jiangmin
update: 20190529
version: 16.0.100
detected: False cancel

Kingsoft
update: 20190530
version: 2013.8.14.323
detected: False cancel

Symantec
result: Trojan.Gen.NPE
update: 20190530
version: 1.9.0.0
detected: True check_circle

AhnLab-V3
update: 20190530
version: 3.15.2.24252
detected: False cancel

Antiy-AVL
result: Trojan[Downloader]/Linux.Mirai.d
update: 20190530
version: 3.0.0.1
detected: True check_circle

Kaspersky
result: HEUR:Trojan-Downloader.Linux.Mirai.d
update: 20190530
version: 15.0.1.13
detected: True check_circle

MaxSecure
update: 20190529
version: 1.0.0.1
detected: False cancel

Microsoft
update: 20190530
version: 1.1.15900.4
detected: False cancel

Qihoo-360
result: Win32/Trojan.Downloader.fef
update: 20190530
version: 1.0.0.1120
detected: True check_circle

TheHacker
update: 20190530
version: 6.8.0.5.4241
detected: False cancel

ZoneAlarm
result: HEUR:Trojan-Downloader.Linux.Mirai.d
update: 20190530
version: 1.0
detected: True check_circle

ESET-NOD32
result: a variant of Generik.LFXDPFR
update: 20190530
version: 19439
detected: True check_circle

TrendMicro
result: TROJ_GEN.F04JC00BN19
update: 20190530
version: 10.0.0.1040
detected: True check_circle

BitDefender
update: 20190530
version: 7.2
detected: False cancel

K7AntiVirus
update: 20190529
version: 11.46.31063
detected: False cancel

SentinelOne
result: DFI - Suspicious ELF
update: 20190511
version: 1.0.26.329
detected: True check_circle

Avast-Mobile
update: 20190529
version: 190529-04
detected: False cancel

Malwarebytes
update: 20190530
version: 2.1.1.1115
detected: False cancel

TotalDefense
update: 20190530
version: 37.1.62.1
detected: False cancel

CAT-QuickHeal
update: 20190529
version: 14.00
detected: False cancel

NANO-Antivirus
result: Trojan.Elf32.TrjGen.eqolvh
update: 20190529
version: 1.0.134.24826
detected: True check_circle

MicroWorld-eScan
update: 20190530
version: 14.0.297.0
detected: False cancel

SUPERAntiSpyware
update: 20190528
version: 5.6.0.1032
detected: False cancel

McAfee-GW-Edition
result: RDN/Generic Downloader.x
update: 20190530
version: v2017.3010
detected: True check_circle

TrendMicro-HouseCall
result: TROJ_GEN.F04JC00BN19
update: 20190530
version: 10.0.0.1040
detected: True check_circle

total
60
sha256
5c66af93484887250cb2c15b7ea1ec6d086538509de7e13fa5839086f565166f
scan_id
5c66af93484887250cb2c15b7ea1ec6d086538509de7e13fa5839086f565166f-1559198159
resource
aeee5373c4f34a6e37b9681a0e6be1de
positives
24
scan_date
2019-05-30 06:35:59
verbose_msg
Scan finished, information embedded
response_code
1
Binary
RF
confidence: 100.00%
suspicious: True check_circle
MLP
confidence: 99.51%
suspicious: True check_circle
SVM
confidence: 77.64%
suspicious: True check_circle