Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
e6

Overview

General Information

Sample name:e6
Analysis ID:1430717
MD5:8d7aee78e82865f035bc1bc34552cdbd
SHA1:d59c885ba7deef2a3574c10526aa374f3712b28e
SHA256:a1bc4dcc43c2a6f64c941c2af0c18299a1c44bb700e6f676cb675e38aeb77785
Infos:

Detection

Score:22
Range:0 - 100
Whitelisted:false

Signatures

Found Tor onion address
Reads CPU information from /sys indicative of miner or evasive malware
Sample contains only a LOAD segment without any section mappings
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

Analysis Advice

All HTTP servers contacted by the sample do not answer. The sample is likely an old dropper which does no longer work.
Joe Sandbox version:40.0.0 Tourmaline
Analysis ID:1430717
Start date and time:2024-04-24 04:55:47 +02:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 29s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Run name:Potential for more IOCs and behavior
Analysis Mode:default
Sample name:e6
Detection:SUS
Classification:sus22.evad.lin@0/0@0/0
Command:/tmp/e6
PID:6223
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
Detected number of cpus = 2
No path to encrypt
10ms
Standard Error:
  • system is lnxubuntu20
  • e6 (PID: 6223, Parent: 6138, MD5: 8d7aee78e82865f035bc1bc34552cdbd) Arguments: /tmp/e6
  • cleanup
No yara matches
No Snort rule has matched

Click to jump to signature section

Show All Signature Results
Source: /tmp/e6 (PID: 6223)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior

Networking

barindex
Source: e6, 6223.1.00000000006a7000.00000000006ae000.rw-.sdmpString found in binary or memory: 4. As for your data, if we fail to agree, we will try to sell personal information/trade secrets/databases/source codes - generally speaking, everything that has a value on the darkmarket - to multiple threat actors at ones. Then all of this will be published in our blog - https://akiral2iz6a7qgd3ayp3l6yub7xx2uep76idk3u2kollpj5z3z636bad.onion.
Source: e6, 6223.1.00000000006a7000.00000000006ae000.rw-.sdmpString found in binary or memory: 2. Paste this link - https://akiralkzxzq2dsrzsrvbr2xgbbu2wgsmxryd4csgfameg52n7efvr2id.onion.
Source: e6String found in binary or memory: 4. As for your data, if we fail to agree, we will try to sell personal information/trade secrets/databases/source codes - generally speaking, everything that has a value on the darkmarket - to multiple threat actors at ones. Then all of this will be published in our blog - https://akiral2iz6a7qgd3ayp3l6yub7xx2uep76idk3u2kollpj5z3z636bad.onion.
Source: e6String found in binary or memory: 2. Paste this link - https://akiralkzxzq2dsrzsrvbr2xgbbu2wgsmxryd4csgfameg52n7efvr2id.onion.
Source: global trafficTCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
Source: global trafficTCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
Source: global trafficTCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: e6String found in binary or memory: https://akiral2iz6a7qgd3ayp3l6yub7xx2uep76idk3u2kollpj5z3z636bad.onion.
Source: e6String found in binary or memory: https://akiralkzxzq2dsrzsrvbr2xgbbu2wgsmxryd4csgfameg52n7efvr2id.onion.
Source: e6String found in binary or memory: https://bugs.launchpad.net/ubuntu/
Source: e6String found in binary or memory: https://gcc.gnu.org/bugsNSt7__cxx1115basic_stringbufIcSt11char_traitsIcESaIcEEE
Source: e6String found in binary or memory: https://gcc.gnu.org/bugsNSt7__cxx1115basic_stringbufIcSt11char_traitsIcESaIcEEENSt7__cxx1119basic_is
Source: e6String found in binary or memory: https://www.torproject.org/download/.
Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443
Source: LOAD without section mappingsProgram segment: 0x400000
Source: classification engineClassification label: sus22.evad.lin@0/0@0/0
Source: /tmp/e6 (PID: 6223)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
Source: /tmp/e6 (PID: 6223)Queries kernel information via 'uname': Jump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath InterceptionDirect Volume AccessOS Credential Dumping1
Security Software Discovery
Remote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS Memory1
System Information Discovery
Remote Desktop ProtocolData from Removable Media1
Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
Proxy
Automated ExfiltrationData Encrypted for Impact
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
No contacted domains info
NameSourceMaliciousAntivirus DetectionReputation
https://www.torproject.org/download/.e6false
    high
    https://bugs.launchpad.net/ubuntu/e6false
      high
      https://akiral2iz6a7qgd3ayp3l6yub7xx2uep76idk3u2kollpj5z3z636bad.onion.e6true
        unknown
        https://gcc.gnu.org/bugsNSt7__cxx1115basic_stringbufIcSt11char_traitsIcESaIcEEENSt7__cxx1119basic_ise6false
          high
          https://gcc.gnu.org/bugsNSt7__cxx1115basic_stringbufIcSt11char_traitsIcESaIcEEEe6false
            high
            https://akiralkzxzq2dsrzsrvbr2xgbbu2wgsmxryd4csgfameg52n7efvr2id.onion.e6true
              unknown
              • No. of IPs < 25%
              • 25% < No. of IPs < 50%
              • 50% < No. of IPs < 75%
              • 75% < No. of IPs
              IPDomainCountryFlagASNASN NameMalicious
              109.202.202.202
              unknownSwitzerland
              13030INIT7CHfalse
              91.189.91.43
              unknownUnited Kingdom
              41231CANONICAL-ASGBfalse
              91.189.91.42
              unknownUnited Kingdom
              41231CANONICAL-ASGBfalse
              MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
              109.202.202.2028awpc7GpMh.elfGet hashmaliciousUnknownBrowse
                6WfrjCTjs8.elfGet hashmaliciousUnknownBrowse
                  cG1d8L6E2V.elfGet hashmaliciousUnknownBrowse
                    SecuriteInfo.com.Linux.Siggen.9999.14268.13066.elfGet hashmaliciousMiraiBrowse
                      nQ95n6pvWY.elfGet hashmaliciousMiraiBrowse
                        SecuriteInfo.com.Linux.Siggen.9999.3492.13032.elfGet hashmaliciousUnknownBrowse
                          quv5jvj4v0.elfGet hashmaliciousUnknownBrowse
                            2s4fTHXEwm.elfGet hashmaliciousUnknownBrowse
                              cqy0lIeLds.elfGet hashmaliciousUnknownBrowse
                                X0ckMzxoy9.elfGet hashmaliciousUnknownBrowse
                                  91.189.91.438awpc7GpMh.elfGet hashmaliciousUnknownBrowse
                                    6WfrjCTjs8.elfGet hashmaliciousUnknownBrowse
                                      cG1d8L6E2V.elfGet hashmaliciousUnknownBrowse
                                        SecuriteInfo.com.Linux.Siggen.9999.14268.13066.elfGet hashmaliciousMiraiBrowse
                                          nQ95n6pvWY.elfGet hashmaliciousMiraiBrowse
                                            SecuriteInfo.com.Linux.Siggen.9999.3492.13032.elfGet hashmaliciousUnknownBrowse
                                              quv5jvj4v0.elfGet hashmaliciousUnknownBrowse
                                                2s4fTHXEwm.elfGet hashmaliciousUnknownBrowse
                                                  cqy0lIeLds.elfGet hashmaliciousUnknownBrowse
                                                    X0ckMzxoy9.elfGet hashmaliciousUnknownBrowse
                                                      91.189.91.428awpc7GpMh.elfGet hashmaliciousUnknownBrowse
                                                        6WfrjCTjs8.elfGet hashmaliciousUnknownBrowse
                                                          cG1d8L6E2V.elfGet hashmaliciousUnknownBrowse
                                                            SecuriteInfo.com.Linux.Siggen.9999.14268.13066.elfGet hashmaliciousMiraiBrowse
                                                              nQ95n6pvWY.elfGet hashmaliciousMiraiBrowse
                                                                SecuriteInfo.com.Linux.Siggen.9999.3492.13032.elfGet hashmaliciousUnknownBrowse
                                                                  quv5jvj4v0.elfGet hashmaliciousUnknownBrowse
                                                                    2s4fTHXEwm.elfGet hashmaliciousUnknownBrowse
                                                                      cqy0lIeLds.elfGet hashmaliciousUnknownBrowse
                                                                        X0ckMzxoy9.elfGet hashmaliciousUnknownBrowse
                                                                          No context
                                                                          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                          CANONICAL-ASGB8awpc7GpMh.elfGet hashmaliciousUnknownBrowse
                                                                          • 91.189.91.42
                                                                          6WfrjCTjs8.elfGet hashmaliciousUnknownBrowse
                                                                          • 91.189.91.42
                                                                          cG1d8L6E2V.elfGet hashmaliciousUnknownBrowse
                                                                          • 91.189.91.42
                                                                          SecuriteInfo.com.Linux.Siggen.9999.14268.13066.elfGet hashmaliciousMiraiBrowse
                                                                          • 91.189.91.42
                                                                          nQ95n6pvWY.elfGet hashmaliciousMiraiBrowse
                                                                          • 91.189.91.42
                                                                          SecuriteInfo.com.Linux.Siggen.9999.3492.13032.elfGet hashmaliciousUnknownBrowse
                                                                          • 91.189.91.42
                                                                          quv5jvj4v0.elfGet hashmaliciousUnknownBrowse
                                                                          • 91.189.91.42
                                                                          2s4fTHXEwm.elfGet hashmaliciousUnknownBrowse
                                                                          • 91.189.91.42
                                                                          cqy0lIeLds.elfGet hashmaliciousUnknownBrowse
                                                                          • 91.189.91.42
                                                                          X0ckMzxoy9.elfGet hashmaliciousUnknownBrowse
                                                                          • 91.189.91.42
                                                                          CANONICAL-ASGB8awpc7GpMh.elfGet hashmaliciousUnknownBrowse
                                                                          • 91.189.91.42
                                                                          6WfrjCTjs8.elfGet hashmaliciousUnknownBrowse
                                                                          • 91.189.91.42
                                                                          cG1d8L6E2V.elfGet hashmaliciousUnknownBrowse
                                                                          • 91.189.91.42
                                                                          SecuriteInfo.com.Linux.Siggen.9999.14268.13066.elfGet hashmaliciousMiraiBrowse
                                                                          • 91.189.91.42
                                                                          nQ95n6pvWY.elfGet hashmaliciousMiraiBrowse
                                                                          • 91.189.91.42
                                                                          SecuriteInfo.com.Linux.Siggen.9999.3492.13032.elfGet hashmaliciousUnknownBrowse
                                                                          • 91.189.91.42
                                                                          quv5jvj4v0.elfGet hashmaliciousUnknownBrowse
                                                                          • 91.189.91.42
                                                                          2s4fTHXEwm.elfGet hashmaliciousUnknownBrowse
                                                                          • 91.189.91.42
                                                                          cqy0lIeLds.elfGet hashmaliciousUnknownBrowse
                                                                          • 91.189.91.42
                                                                          X0ckMzxoy9.elfGet hashmaliciousUnknownBrowse
                                                                          • 91.189.91.42
                                                                          INIT7CH8awpc7GpMh.elfGet hashmaliciousUnknownBrowse
                                                                          • 109.202.202.202
                                                                          6WfrjCTjs8.elfGet hashmaliciousUnknownBrowse
                                                                          • 109.202.202.202
                                                                          cG1d8L6E2V.elfGet hashmaliciousUnknownBrowse
                                                                          • 109.202.202.202
                                                                          SecuriteInfo.com.Linux.Siggen.9999.14268.13066.elfGet hashmaliciousMiraiBrowse
                                                                          • 109.202.202.202
                                                                          nQ95n6pvWY.elfGet hashmaliciousMiraiBrowse
                                                                          • 109.202.202.202
                                                                          SecuriteInfo.com.Linux.Siggen.9999.3492.13032.elfGet hashmaliciousUnknownBrowse
                                                                          • 109.202.202.202
                                                                          quv5jvj4v0.elfGet hashmaliciousUnknownBrowse
                                                                          • 109.202.202.202
                                                                          2s4fTHXEwm.elfGet hashmaliciousUnknownBrowse
                                                                          • 109.202.202.202
                                                                          cqy0lIeLds.elfGet hashmaliciousUnknownBrowse
                                                                          • 109.202.202.202
                                                                          X0ckMzxoy9.elfGet hashmaliciousUnknownBrowse
                                                                          • 109.202.202.202
                                                                          No context
                                                                          No context
                                                                          No created / dropped files found
                                                                          File type:ELF 64-bit LSB executable, x86-64, version 1 (GNU/Linux), BuildID[sha1]=ced0399c628f99c4d4044d9a6143bd4a9bad16a9, for GNU/Linux 3.2.0, statically linked, no section header
                                                                          Entropy (8bit):6.301329753072254
                                                                          TrID:
                                                                          • ELF Executable and Linkable format (Linux) (4029/14) 50.16%
                                                                          • ELF Executable and Linkable format (generic) (4004/1) 49.84%
                                                                          File name:e6
                                                                          File size:2'805'488 bytes
                                                                          MD5:8d7aee78e82865f035bc1bc34552cdbd
                                                                          SHA1:d59c885ba7deef2a3574c10526aa374f3712b28e
                                                                          SHA256:a1bc4dcc43c2a6f64c941c2af0c18299a1c44bb700e6f676cb675e38aeb77785
                                                                          SHA512:8d51a7be4b3c2193f9489dd50879ce340564434f96c071d7af4890aca9e2acea2cc1d162aff495678e82dffbb009630225f79bb0192c6c0f160e05f027d67c17
                                                                          SSDEEP:49152:/GCZiXJiHe6/EICNLx2DGzvvdl/vi527254XjqzqpEmBCpoESOS2Oo:K2YtdU4jBCpoOS7o
                                                                          TLSH:1BD54B2BF2F291ECD04BD5345A8FC6939C24B4F42231393B27969D351D62DA40BBDB62
                                                                          File Content Preview:.ELF..............>.....pk@.....@...................@.8...@.......................@.......@.....h.......h.................................@.......@......Q!......Q!......................p!......pa......pa......1.......1........................).......i....

                                                                          ELF header

                                                                          Class:ELF64
                                                                          Data:2's complement, little endian
                                                                          Version:1 (current)
                                                                          Machine:Advanced Micro Devices X86-64
                                                                          Version Number:0x1
                                                                          Type:EXEC (Executable file)
                                                                          OS/ABI:UNIX - Linux
                                                                          ABI Version:0
                                                                          Entry Point Address:0x406b70
                                                                          Flags:0x0
                                                                          ELF Header Size:64
                                                                          Program Header Offset:64
                                                                          Program Header Size:56
                                                                          Number of Program Headers:10
                                                                          Section Header Offset:0
                                                                          Section Header Size:64
                                                                          Number of Section Headers:0
                                                                          Header String Table Index:0
                                                                          TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                                          LOAD0x00x4000000x4000000x6680x6682.44260x4R 0x1000
                                                                          LOAD0x10000x4010000x4010000x2151050x2151056.31180x5R E0x1000
                                                                          LOAD0x2170000x6170000x6170000x831e90x831e95.63280x4R 0x1000
                                                                          LOAD0x29a7f00x69b7f00x69b7f00x127000x1be403.76700x6RW 0x1000
                                                                          NOTE0x2700x4002700x4002700x200x201.87160x4R 0x8
                                                                          NOTE0x2900x4002900x4002900x440x443.35620x4R 0x4
                                                                          TLS0x29a7f00x69b7f00x69b7f00x700xd01.96410x4R 0x8
                                                                          GNU_PROPERTY0x2700x4002700x4002700x200x201.87160x4R 0x8
                                                                          GNU_STACK0x00x00x00x00x00.00000x6RW 0x10
                                                                          GNU_RELRO0x29a7f00x69b7f00x69b7f00xb8100xb8102.98720x4R 0x1
                                                                          TimestampSource PortDest PortSource IPDest IP
                                                                          Apr 24, 2024 04:56:27.219247103 CEST43928443192.168.2.2391.189.91.42
                                                                          Apr 24, 2024 04:56:32.850423098 CEST42836443192.168.2.2391.189.91.43
                                                                          Apr 24, 2024 04:56:34.386272907 CEST4251680192.168.2.23109.202.202.202
                                                                          Apr 24, 2024 04:56:47.184348106 CEST43928443192.168.2.2391.189.91.42
                                                                          Apr 24, 2024 04:56:59.470717907 CEST42836443192.168.2.2391.189.91.43
                                                                          Apr 24, 2024 04:57:05.613893032 CEST4251680192.168.2.23109.202.202.202
                                                                          Apr 24, 2024 04:57:28.138844013 CEST43928443192.168.2.2391.189.91.42

                                                                          System Behavior

                                                                          Start time (UTC):02:56:25
                                                                          Start date (UTC):24/04/2024
                                                                          Path:/tmp/e6
                                                                          Arguments:/tmp/e6
                                                                          File size:2805488 bytes
                                                                          MD5 hash:8d7aee78e82865f035bc1bc34552cdbd