2024-07-02 11:41:17 +00:00
|
|
|
# Sample Information
|
|
|
|
|
|
|
|
<table>
|
|
|
|
<tr>
|
|
|
|
<td><b>VirusTotal Threat Label</b></td>
|
|
|
|
<td><b><span style="color: red">ransomware.hive/filecoderhive</span></b></td>
|
|
|
|
</tr>
|
|
|
|
<tr>
|
|
|
|
<td><b>md5</b></td>
|
|
|
|
<td>171d2a50c6d7e69281d1c3ef98d510f2</td>
|
|
|
|
</tr>
|
|
|
|
<tr>
|
|
|
|
<td><b>sha1</b></td>
|
|
|
|
<td>322db4ca435004a127acd4171cc52be9edaf5338</td>
|
|
|
|
</tr>
|
|
|
|
<tr>
|
|
|
|
<td><b>sha256</b></td>
|
|
|
|
<td>713b699c04f21000fca981e698e1046d4595f423bd5741d712fd7e0bc358c771</td>
|
|
|
|
</tr>
|
|
|
|
<tr>
|
|
|
|
<td><b>sha512</b></td>
|
|
|
|
<td>2226d1a5e9c8a2920fa8d327b53e10f135e9b30c8c3d1e7fbb3a59a51df782f106f41f60ad8140a1de4a81ef6b230418126ffb24bd75eab3c3a298ada2f58913</td>
|
|
|
|
</tr>
|
|
|
|
</table>
|
|
|
|
|
|
|
|
**VirusTotal**: https://www.virustotal.com/gui/file/713b699c04f21000fca981e698e1046d4595f423bd5741d712fd7e0bc358c771
|
|
|
|
|
2024-07-02 14:18:24 +00:00
|
|
|
## Analysis
|
|
|
|
|
|
|
|
![analysis](analysis/sample.svg)
|
|
|
|
|
2024-07-02 11:41:17 +00:00
|
|
|
## Detection Names
|
|
|
|
|
|
|
|
Detected
|
|
|
|
E64/DCFilcdr.JVGT-
|
|
|
|
ELF:Filecoder-CT [Trj]
|
|
|
|
ELF/TrojanGen.A
|
|
|
|
HEUR:Trojan-Ransom.Linux.Hive.b
|
|
|
|
Linux.Encoder.119
|
|
|
|
LINUX/Filecoder.gijrz
|
|
|
|
Linux/Filecoder_Hive.A!tr
|
|
|
|
Linux/Filecoder.Hive.D
|
|
|
|
Linux.Ransomware.Hive
|
|
|
|
Linux.Trojan-Ransom.Hive.Jqil
|
|
|
|
Linux.Troj.Generic.v
|
|
|
|
Mal/Generic-S
|
|
|
|
Malicious (score: 99)
|
|
|
|
malware (ai score=90)
|
|
|
|
Malware.LINUX/Filecoder.gijrz
|
|
|
|
Ransom-Hive!171D2A50C6D7
|
|
|
|
Ransom.Hive!8.12EEE (CLOUD)
|
|
|
|
Ransom:Linux/Filecoder!MTB
|
|
|
|
Ransom.U.Hive.bot
|
|
|
|
RansomWare
|
|
|
|
Ransomware/Linux.Hive.2367488
|
|
|
|
Trojan.Elf64.Ransom.jyhqzy
|
|
|
|
Trojan.Filecoder.Linux.78
|
|
|
|
Trojan Horse
|
|
|
|
Trojan.Linux.btf
|
|
|
|
Trojan.Linux.FILECODERHIVE.USELVL521
|
|
|
|
Trojan.Linux.Hive.j!c
|
|
|
|
Trojan.Linux.Ransom.224225
|
|
|
|
Trojan.Linux.Ransom.224225 (B)
|
|
|
|
Trojan.Linux.Ransom.D36BE1
|
|
|
|
Trojan-Ransom.Hive
|
|
|
|
Trojan.Ransom.Linux.Gen
|
|
|
|
Trojan[Ransom]/Linux.Hive.d
|
|
|
|
Unix.Ransomware.Deadbolt-9959009-0
|