× Cookies are disabled! This site requires cookies to be enabled to work properly
SHA256: aadb2c3df170432943581c4c79665e614cc4802526c3184aca2da1aac62d72d1
File name: VirusShare_5d10bcb15bedb4b94092c4c2e4d245b6
Detection ratio: 38 / 55
Analysis date: 2017-05-17 23:31:18 UTC ( 5 months ago )
Antivirus Result Update
Ad-Aware Trojan.Linux.Rootkit.SU 20170518
AegisLab Backdoor.Linux.Mayday.f!c 20170517
AhnLab-V3 Linux/Ddosagent.1524643 20170517
ALYac Backdoor.Linux.Mayday 20170518
Arcabit Trojan.Linux.Rootkit.SU 20170518
Avast ELF:Elknot-BY [Trj] 20170517
AVG Linux/Generic_c.QZ 20170517
BitDefender Trojan.Linux.Rootkit.SU 20170517
CAT-QuickHeal Trojan.Linux.Elknot.C 20170517
ClamAV Unix.Trojan.Elknot-1 20170517
Comodo UnclassifiedMalware 20170517
DrWeb Linux.DDoS.11 20170517
Emsisoft Trojan.Linux.Rootkit.SU (B) 20170517
ESET-NOD32 Linux/Elknot.B 20170517
F-Secure Trojan.Linux.Rootkit.SU 20170517
Fortinet ELF/DDOS.BA!tr.bdr 20170517
GData Trojan.Linux.Rootkit.SU 20170517
Ikarus ELF.Agent 20170517
Jiangmin Backdoor/Linux.hw 20170517
K7AntiVirus Trojan ( 0001140e1 ) 20170517
K7GW Trojan ( 0001140e1 ) 20170517
Kaspersky Backdoor.Linux.Mayday.f 20170517
McAfee Linux/BackDoor 20170517
McAfee-GW-Edition Linux/BackDoor 20170517
Microsoft DoS:Linux/Elknot!rfn 20170517
eScan Trojan.Linux.Rootkit.SU 20170517
NANO-Antivirus Trojan.Unix.DDoS.dnckxa 20170517
Qihoo-360 Win32/Trojan.Flooder.092 20170518
Sophos AV Linux/DDoS-AZ 20170517
Symantec Linux.Chikdos.B 20170517
Tencent Linux.Backdoor.Mayday.Sway 20170518
TotalDefense Linux/Mayday.A 20170517
TrendMicro ELF_ELKNOT.TNI 20170517
TrendMicro-HouseCall ELF_ELKNOT.TNI 20170517
VBA32 Trojan.Linux.DDoSer 20170517
ViRobot Trojan.Linux.S.Agent.1524643[h] 20170517
Zillya Downloader.OpenConnection.JS.93127 20170517
ZoneAlarm by Check Point Backdoor.Linux.Mayday.f 20170518
Alibaba 20170517
Avira (no cloud) 20170517
AVware 20170517
Baidu 20170503
CMC 20170517
CrowdStrike Falcon (ML) 20170130
Cyren 20170517
Endgame 20170515
F-Prot 20170517
Sophos ML 20170516
Kingsoft 20170518
Malwarebytes 20170517
nProtect 20170517
Palo Alto Networks (Known Signatures) 20170518
Panda 20170517
Rising 20170517
SentinelOne (Static ML) 20170516
SUPERAntiSpyware 20170517
Symantec Mobile Insight 20170517
TheHacker 20170516
Trustlook 20170518
VIPRE 20170517
Webroot 20170518
WhiteArmor 20170517
Yandex 20170517
Zoner 20170517
The file being studied is an ELF! More specifically, it is a EXEC (Executable file) ELF for Unix systems running on Intel 80386 machines.
ELF Header
Class ELF32
Data 2's complement, little endian
Header version 1 (current)
OS ABI UNIX - System V
ABI version 0
Object file type EXEC (Executable file)
Required architecture Intel 80386
Object file version 0x1
Program headers 5
Section headers 28
ELF sections
ELF Segments
.note.ABI-tag
.init
.text
__libc_freeres_fn
__libc_thread_freeres_fn
.fini
.rodata
__libc_subfreeres
__libc_atexit
__libc_thread_subfreeres
.eh_frame
.gcc_except_table
.ctors
.dtors
.jcr
.data.rel.ro
.got
.got.plt
.data
.bss
__libc_freeres_ptrs
.note.ABI-tag
Segment without sections
Segment without sections
Imported symbols
Exported symbols
ExifTool file metadata
MIMEType
application/octet-stream

CPUByteOrder
Little endian

CPUArchitecture
32 bit

FileType
ELF executable

ObjectFileType
Executable file

CPUType
i386

File identification
MD5 5d10bcb15bedb4b94092c4c2e4d245b6
SHA1 6eba031ec658aeb82aed5b94c4ba829da38553f4
SHA256 aadb2c3df170432943581c4c79665e614cc4802526c3184aca2da1aac62d72d1
ssdeep
24576:hNJp/2SkgT4KUAopmhDO2Aan9XgnU6tZAf4Nzbm6g+qF2SdYOrhGQ+bL+cH8y6LL:hNvOx/Vp/2bn9XgnNtmf28rhfbccIwhL

File size 1.5 MB ( 1524643 bytes )
File type ELF
Magic literal
ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, for GNU/Linux 2.2.5, not stripped

TrID ELF Executable and Linkable format (Linux) (50.1%)
ELF Executable and Linkable format (generic) (49.8%)
Tags
elf

VirusTotal metadata
First submission 2013-12-09 16:59:48 UTC ( 3 years, 10 months ago )
Last submission 2017-02-25 01:10:01 UTC ( 7 months, 3 weeks ago )
File names aadb2c3df170432943581c4c79665e614cc4802526c3184aca2da1aac62d72d1
atddd.1
codex-gigas_0c1cac2a019aa1cc2dcc0d3b17fc4477
aa
mDEOKG.xlt
6eba031ec658aeb82aed5b94c4ba829da38553f4_atdd
sdmfdsfhjfe
VirusShare_5d10bcb15bedb4b94092c4c2e4d245b6
sdmfdsfhjfe
atdd
download.1398159629
file-7133735_
download.1397326078
atddd
5d10bcb15bedb4b94092c4c2e4d245b6
No comments. No VirusTotal Community member has commented on this item yet, be the first one to do so!

Leave your comment...

?
Post comment

You have not signed in. Only registered users can leave comments, sign in and have a voice!

No votes. No one has voted on this item yet, be the first one to do so!