Hello, friends.
I am investigating an intrusion. Some anti-rootkit solutions for Linux mention that these files from hybrid-analysis are suspicious.
However, when I analyze them in VirusTotal, the name “Eddie” appears. Does this mean that it is related to the Eddie client, or should I investigate further?
Thank you very much for responding to my security concerns!
1. https://hybrid-analysis.com/sample/2d877bed6f13810bc024cb5d53651d2c792f2047e1e2ccb6cea58b67460d418e
2. https://hybrid-analysis.com/sample/80a0e1625ed38e108e70708d119b58c8a3e94c448557922faaa6476830fd3739
3. https://hybrid-analysis.com/sample/9f33b6fa29396ef1e46082238076e61ef0064892dd84f008608abd09fa48b20a
--