2024-07-02 11:41:17 +00:00
|
|
|
# Sample Information
|
|
|
|
|
|
|
|
<table>
|
|
|
|
<tr>
|
|
|
|
<td><b>VirusTotal Threat Label</b></td>
|
|
|
|
<td><b><span style="color: red">unknown</span></b></td>
|
|
|
|
</tr>
|
|
|
|
<tr>
|
|
|
|
<td><b>md5</b></td>
|
|
|
|
<td>a0e1c1e0a2c5cdc8af60beda2b581ee1</td>
|
|
|
|
</tr>
|
|
|
|
<tr>
|
|
|
|
<td><b>sha1</b></td>
|
|
|
|
<td>555c3d3b9ca1010ccfa9533487e264ad7fe34ecd</td>
|
|
|
|
</tr>
|
|
|
|
<tr>
|
|
|
|
<td><b>sha256</b></td>
|
|
|
|
<td>17d8569d683f39d71f051cc0d2d33a662e549635cd74460c72ba1e49224bc35c</td>
|
|
|
|
</tr>
|
|
|
|
<tr>
|
|
|
|
<td><b>sha512</b></td>
|
|
|
|
<td>3492b67643a97e7dd607f4d4edc97a36380ed2a85f87fba3ff3e817debff7aa7ad84f7ea884b3340fefe3b0ab37327b789640d3fa6ef1f40acd3b195306a414b</td>
|
|
|
|
</tr>
|
|
|
|
</table>
|
|
|
|
|
|
|
|
**VirusTotal**: https://www.virustotal.com/gui/file/17d8569d683f39d71f051cc0d2d33a662e549635cd74460c72ba1e49224bc35c
|
|
|
|
|
2024-07-02 12:51:39 +00:00
|
|
|
## Analysis
|
|
|
|
|
2024-07-02 13:19:57 +00:00
|
|
|
[<img src="analysis/sample.svg" style="max-width:800em;"/>](analysis/sample.svg)
|
2024-07-02 12:51:39 +00:00
|
|
|
|
2024-07-02 11:41:17 +00:00
|
|
|
## Detection Names
|
|
|
|
|
|
|
|
Artemis!Trojan
|
|
|
|
Backdoor.linux.ganiw.h
|
|
|
|
Backdoor/Linux.ku
|
|
|
|
Backdoor.Linux.Tsunami.CK
|
|
|
|
Backdoor.Linux.Tsunami.CK (B)
|
|
|
|
Backdoor.Setag/Linux!1.A3E5 (CLOUD)
|
|
|
|
Detected
|
|
|
|
ELF:Elknot-AD [Cryp]
|
|
|
|
ELF/Setag.B!tr
|
|
|
|
ELF_SETAG.DM
|
|
|
|
HEUR:Backdoor.Linux.Ganiw.d
|
|
|
|
Linux.BackDoor.Gates.9
|
|
|
|
Linux.BackDoor.Gates.G
|
|
|
|
Linux.Chikdos.B!gen2
|
|
|
|
Linux/DDoS-BD
|
|
|
|
Linux/Elknot.525288
|
|
|
|
LINUX/Setag.332
|
|
|
|
Linux/Setag.B
|
|
|
|
Malicious (score: 99)
|
|
|
|
Malware@#1fpleign4a7nr
|
|
|
|
malware (ai score=100)
|
|
|
|
Malware.LINUX/Setag.332
|
|
|
|
Static AI - Malicious ELF
|
|
|
|
Suspicious.Linux.Save.a
|
|
|
|
Trojan[Backdoor]/Linux.Ganiw.d
|
|
|
|
Trojan.Elf32.Ganiw.eksrqh
|
|
|
|
Trojan.Linux.Agent
|
|
|
|
Trojan.Linux.Ganiw.m!c
|
|
|
|
Trojan:Linux/Multiverze
|
|
|
|
Trojan.Setag.Linux.79
|
|
|
|
Unix.Malware.Agent-1639378
|