Classification: Malicious
0004 is a malicious file sample. Linked to Hellokitty malware. Reported by 2 threat sources, last seen 2023-06-13. Detected by 41 antivirus engines.
Detection summary
- 41 antivirus detections (54% detection ratio)
- 0 IDS alerts
- 1 processes observed
- 0 contacted hosts
- 0 DNS requests
Blacklist sightings
| Description |
Source |
First seen |
Last seen |
Labels |
MITRE ATT&CK |
| Generic Malware |
Hybrid-Analysis |
2023-06-13 13:45:03 |
2023-06-13 13:45:03 |
|
|
| HelloKitty |
Abuse.ch |
2021-08-14 14:06:33 |
2021-08-14 14:06:33 |
malicious-activity
|
S0617 HELLOKITTY
|
Sample information
- Filenames
- 0004, ca607e431062ee49a21d69d722750e5edbd8ffabcb54fa92b231814101756041.bin
- File type
- ELF 64-bit LSB executable, x86-64, version 1 (SYSV ...
- Size
- 86480 bytes
- MD5
5716a136538ec546ef591d5aa143c153
- SHA-1
0b3c3402edbed6a7a8530607c4eafcee85184ffe
- SHA-256
ca607e431062ee49a21d69d722750e5edbd8ffabcb54fa92b231814101756041
- First indexed
- 2021-08-14 15:15:05
- Last updated
- 2026-06-27 05:35:05
Antivirus detections
| Engine | Detection |
| Lionic | Trojan.Linux.Generic.4!c |
| Cynet | Malicious (score: 99) |
| CAT-QuickHeal | ELF.Trojan.44135.GC |
| ALYac | Trojan.Ransom.Linux.Gen |
| Arcabit | Trojan.Ransom.Agent.CA |
| Cyren | E64/Trojan.UPNL-6 |
| Symantec | Trojan.Gen.NPE |
| ESET-NOD32 | a variant of Linux/Filecoder.HelloKitty.A |
| TrendMicro-HouseCall | Trojan.Linux.FILECODER.USDSEHC21 |
| Avast | ELF:Filecoder-BS [Trj] |
| Kaspersky | HEUR:Trojan-Ransom.Linux.Hellokit.a |
| BitDefender | Trojan.Ransom.Agent.CA |
| NANO-Antivirus | Trojan.Elf64.Ransom.ixtiyo |
| MicroWorld-eScan | Trojan.Ransom.Agent.CA |
| Ad-Aware | Trojan.Ransom.Agent.CA |
| Comodo | Malware@#3vhdeelwzsgp5 |
| DrWeb | Linux.Encoder.103 |
| TrendMicro | Trojan.Linux.FILECODER.USDSEHC21 |
| McAfee-GW-Edition | RDN/Ransom |
| FireEye | Trojan.Ransom.Agent.CA |
| Emsisoft | Trojan.Ransom.Agent.CA (B) |
| Ikarus | Trojan-Ransom.Hellokitty |
| GData | Trojan.Ransom.Agent.CA |
| Jiangmin | Trojan.Linux.blz |
| Avira | LINUX/Ransom.ownot |
| MAX | malware (ai score=100) |
| Gridinsoft | Ransom.U.Heur.oa |
| Microsoft | Ransom:Linux/HelloKitty.A |
| ZoneAlarm | HEUR:Trojan-Ransom.Linux.Hellokit.a |
| AhnLab-V3 | Ransomware/Linux.HelloKitty.86480 |
| McAfee | RDN/Ransom |
| Tencent | Win32.Trojan.Ransom.Stuc |
| Fortinet | Linux/Filecoder.AH!tr |
| AVG | ELF:Filecoder-BS [Trj] |
| CAT-QuickHeal | Elf.Trojan.A1712983 |
| ESET-NOD32 | a variant of Linux/Filecoder.AH |
| TrendMicro-HouseCall | Ransom_HelloKitty.R002C0DGI21 |
| Kaspersky | HEUR:Trojan-Ransom.Linux.Hellokit.gen |
| TrendMicro | Ransom_HelloKitty.R002C0DGI21 |
| ALYac | Trojan.Ransom.Agent.CA |
| Ikarus | Trojan-Ransom.Agent |
Process list
| Name | Command line |
| 0004.elf | |