Static | ZeroBOX
/lib64/ld-linux-x86-64.so.2
libdl.so.2
_ITM_deregisterTMCloneTable
__gmon_start__
_ITM_registerTMCloneTable
dlclose
dlopen
libpthread.so.0
__errno_location
pthread_mutex_lock
pthread_create
pthread_attr_init
connect
pthread_mutex_unlock
pthread_attr_setdetachstate
waitpid
libc.so.6
socket
strcpy
gmtime_r
wordexp
wordfree
strrchr
cfmakeraw
statvfs64
getpwuid
closedir
inet_ntoa
__stack_chk_fail
unlink
select
realloc
getpid
setutxent
gmtime
strtol
setmntent
execlp
getppid
strstr
tcsetattr
grantpt
shutdown
ptsname
fclose
getmntent
setsockopt
malloc
strcat
realpath
asprintf
opendir
getenv
sscanf
gethostbyname
readlink
execvp
pclose
gethostname
usleep
getcwd
fwrite
rename
geteuid
unlockpt
localtime
endutxent
endmntent
readdir64
tcgetattr
getutxent
__cxa_finalize
setsid
fopen64
sysinfo
__libc_start_main
ferror
snprintf
sysconf
__xstat64
__lxstat64
GLIBC_2.2.5
GLIBC_2.3
GLIBC_2.4
[]A\A]
[]A\A]
[]A\A]A^A_
[]A\A]
[]A\A]A^
[]A\A]A^
dH34%(
[]A\A]A^
AWAVAUATUSH
[]A\A]A^A_
AVAUATUL
[]A\A]A^
AVAUATUH
[]A\A]A^
[]A\A]A^A_
AVAUATUSH
[]A\A]A^
[]A\A]A^
[]A\A]A^A_
[]A\A]
[]A\A]A^
T$HdH3
[]A\A]
[]A\A]A^
AWAVAUATUSH
[]A\A]A^A_
[]A\A]A^A_
[]A\A]
AVAUATI
[]A\A]A^
[]A\A]A^
D$xdH3
[]A\A]
AUATUS
ATAWAVP1
[]A\A]A^A_
D$(dH3
AUATUSH
[]A\A]A^A_
L$8dH3
AWAVE1
AUATUSH
[]A\A]A^A_
[]A\A]
[]A\A]
[]A\A]A^A_
D$(dH3
AVAUATUSH
[]A\A]A^
AUATUSH
[]A\A]
A]A^A_
]A\A]A^A_
|$(dH3<%(
8[]A\A]A^A_
dH3<%(
D$(dH3
[]A\A]
L$8dH3
[]A\A]
]A\A]A^A_
AVAUATUI
]A\A]A^
uEATUH
AWAVAUATI
[A\A]A^A_]
AUATUSH
[]A\A]A^A_
AUATUSH
[]A\A]A^A_
[]A\A]A^A_
[]A\A]A^A_
%c%.8x%s
%s @ %s
/tmp/%s
CONNECT %s:%d HTTP/1.0
Host: %s:%d
200 OK
%.2d/%.2d/%d %.2d:%.2d:%.2d
/proc/%i/exe
/proc/self/cmdline
%.4d-%.2d-%.2d %.2d:%.2d:%.2d
http://%s%s
GET %s HTTP/1.1
Host: %s
User-Agent: Mozilla/5.0 (Windows NT 6.3; WOW64; Trident/7.0; rv:11.0) like Gecko
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8
Accept-Language: en-US,en;q=0.8
Connection: close
/proc/
/proc/stat
btime
/proc/%s/stat
%s (%[^)]
/proc/%s/exe
/dev/ptmx
/bin/sh
/bin/bash
localhost
Unknown
version
/etc/%s
/etc/lsb-release
/etc/redhat-release
/proc/cpuinfo
model name
crontab -l 2>&1
/tmp/nctf.txt
@reboot "%s"
no crontab for
crontab /tmp/nctf.txt 2>&1
.Settings
/tmp/.%s
%Rand%
-m "%s"
{16:%s;
0:%llu:%s;
%c%llu
%.2d/%.2d/%d %.2d:%.2d:%.2d
socket:[
[0000]:
/proc/%s/fd
/proc/net/tcp
%d: %64[0-9A-Fa-f]:%X %64[0-9A-Fa-f]:%X %X %X:%X %X:%X %X %d %d %d %512s
/proc/net/udp
Established
SYN Sent
SYN Received
Fin Wait (1)
Fin Wait (2)
Time Wait
Closed
Close Wait
Last ACK
Listening...
Closing...
/etc/mtab
bO:rDSz
.shstrtab
.interp
.note.ABI-tag
.note.gnu.build-id
.gnu.hash
.dynsym
.dynstr
.gnu.version
.gnu.version_r
.rela.dyn
.rela.plt
.plt.got
.rodata
.eh_frame_hdr
.eh_frame
.init_array
.fini_array
.dynamic
Antivirus Signature
Bkav Clean
Lionic Trojan.Linux.Netweird.4!c
Elastic Linux.Trojan.Generic
ClamAV Unix.Malware.Netweird-10004258-0
CTX elf.trojan.netweird
CAT-QuickHeal Clean
Skyhigh GenericRXSE-EX!269A9C7B0E83
ALYac Trojan.Linux.Generic.312160
Malwarebytes Clean
Zillya Clean
Sangfor Trojan.Linux.Agent.Vaj4
CrowdStrike Clean
K7GW Clean
K7AntiVirus Clean
huorong Clean
Baidu Clean
VirIT Clean
Symantec Trojan.Gen.NPE
tehtris Clean
ESET-NOD32 a variant of Linux/Netweird.G
TrendMicro-HouseCall TROJ_GEN.R002C0DIS24
Avast ELF:Agent-BCR [Trj]
Cynet Malicious (score: 99)
Kaspersky HEUR:Trojan.Linux.Agent.jn
BitDefender Trojan.Linux.Generic.312160
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan Trojan.Linux.Generic.312160
Tencent Linux.Trojan.Agent.Ugil
Sophos Clean
F-Secure Malware.LINUX/Dldr.Agent.ywmak
DrWeb Clean
VIPRE Trojan.Linux.Generic.312160
TrendMicro TROJ_GEN.R002C0DIS24
CMC Clean
Emsisoft Trojan.Linux.Generic.312160 (B)
Ikarus Win32.Outbreak
FireEye Trojan.Linux.Generic.312160
Jiangmin Trojan.Linux.bof
Varist Clean
Avira LINUX/Dldr.Agent.ywmak
Fortinet Linux/Netweird.G!tr
Antiy-AVL Trojan/Linux.Netweird.g
Kingsoft Linux.Trojan.Agent.jn
Gridinsoft Clean
Xcitium Clean
Arcabit Trojan.Linux.Generic.D4C360
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan.Linux.Agent.jn
Avast-Mobile Clean
Microsoft Backdoor:Linux/Wirenet.B!xp
Google Detected
AhnLab-V3 Clean
Acronis Clean
McAfee GenericRXSE-EX!269A9C7B0E83
TACHYON Clean
VBA32 Clean
Zoner Clean
Rising Backdoor.Wirenet/Linux!8.13CED (TFE:14:WdJhJvwmLcU)
Yandex Clean
SentinelOne Static AI - Malicious ELF
MaxSecure Clean
GData Trojan.Linux.Generic.312160
AVG ELF:Agent-BCR [Trj]
Panda Clean
alibabacloud Backdoor:Linux/Netwiredrc.34a288ec
No IRMA results available.