× Cookies are disabled! This site requires cookies to be enabled to work properly
SHA256: 5bf2ce360dce155b291f7c7f6dc0d5e1e40929f189c1d03cf5b39a71f436c062
File name: duh
Detection ratio: 24 / 43
Analysis date: 2011-03-03 14:44:55 UTC ( 4 years, 5 months ago ) View latest
Antivirus Result Update
AntiVir Worm/IphoneOS.Ike.b 20110303
Antiy-AVL Worm/IphoneOS.Ike 20110303
BitDefender IPhoneOS.Worm.Ikee.B 20110303
Commtouch IphoneOS/Ikee.A 20110303
Comodo UnclassifiedMalware 20110303
Emsisoft Net-Worm.IphoneOS!IK 20110303
F-Prot IphoneOS/Ikee.A 20110302
F-Secure Worm:iPhoneOS/Ikee.B 20110303
GData IPhoneOS.Worm.Ikee.B 20110303
Ikarus Net-Worm.IphoneOS 20110303
Kaspersky Net-Worm.IphoneOS.Ike.b 20110303
Microsoft Worm:iPhoneOS/Ikee.B!A 20110303
NOD32 probably a variant of Win32/Agent.DAZJDMW 20110303
Norman Suspicious_Gen3.IEGC 20110303
PCTools Worm.iPhoneOS 20110303
Rising Worm.Mac.iPhoneIkee.b 20110303
Sophos iPh/Duh-A 20110303
Symantec iPhoneOS.Ikee.B 20110303
TrendMicro IOS_IKEE.A 20110303
TrendMicro-HouseCall IOS_IKEE.A 20110303
ViRobot IphoneOS.S.Ike.13872 20110303
VirusBuster iPhoneOS.Ikee.C 20110303
eSafe Win32.IPhoneOS.Ikee 20110303
eTrust-Vet iPhoneOS/Duh.A 20110303
AVG 20110303
AhnLab-V3 20110303
Avast 20110223
Avast5 20110303
CAT-QuickHeal 20110303
ClamAV 20110303
DrWeb 20110303
Fortinet 20110303
Jiangmin 20110303
K7AntiVirus 20110302
McAfee 20110303
McAfee-GW-Edition 20110302
Panda 20110302
Prevx 20110303
SUPERAntiSpyware 20110303
TheHacker 20110302
VBA32 20110302
VIPRE 20110303
nProtect 20110215
The file being studied is a Mac OS X executable! More specifically it is a executable file Mach-O for ARM based machines.
File header
File type executable file
Magic 0xfeedface
Required architecture ARM
Sub-architecture ARM_ALL12
Load commands 14
Load commands size 1336
Flags DYLDLINK
NOUNDEFS
SUBSECTIONS_VIA_SYMBOLS
TWOLEVEL
File segments
Shared libraries
Load commands
Compressed bundles
File identification
MD5 2a73926229457a3ec9611ec53a2e2249
SHA1 e8087763c05c85bb43f07e4b861d0785c543ae42
SHA256 5bf2ce360dce155b291f7c7f6dc0d5e1e40929f189c1d03cf5b39a71f436c062
ssdeep
96:auFKF058rjM+/8lnzv+sUH3XHsoUfCGZH0k:6a8PM+svJUHHH6fC27

File size 13.5 KB ( 13872 bytes )
File type Mach-O
Magic literal
Mach-O executable acorn

TrID Mac OS X Mach-O 32bit ARM executable (little endian) (50.0%)
Mac OS X Mach-O 32bit Intel executable (49.9%)
Tags
macho arm

VirusTotal metadata
First submission 2009-11-23 19:19:59 UTC ( 5 years, 8 months ago )
Last submission 2014-11-10 01:46:24 UTC ( 8 months, 4 weeks ago )
File names duh
file-3492377_
duh.txt
2a73926229457a3ec9611ec53a2e2249.virus
5bf2ce360dce155b291f7c7f6dc0d5e1e40929f189c1d03cf5b39a71f436c062
No comments. No VirusTotal Community member has commented on this item yet, be the first one to do so!

Leave your comment...

?
Post comment

You have not signed in. Only registered users can leave comments, sign in and have a voice!

No votes. No one has voted on this item yet, be the first one to do so!