Linux Analysis Report
sQSqM58mvl.elf

Overview

General Information

Sample name: sQSqM58mvl.elf
renamed because original name is a hash value
Original sample name: 701c73178deca6e10971cf7792d5b0e6.elf
Analysis ID: 1432398
MD5: 701c73178deca6e10971cf7792d5b0e6
SHA1: c2c153c315dd3d1fa162d38623d86f80ba91a43a
SHA256: 4baf70c6fef0fcde4889f877944b9397bc507d6cd54b32bfa29784b4711b3753
Tags: 32armelfmirai
Infos:

Detection

Mirai, Moobot, Okiru
Score: 100
Range: 0 - 100
Whitelisted: false

Signatures

Antivirus / Scanner detection for submitted sample
Detected Mirai
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Snort IDS alert for network traffic
Yara detected Mirai
Yara detected Moobot
Yara detected Okiru
Sample deletes itself
Uses known network protocols on non-standard ports
Detected TCP or UDP traffic on non-standard ports
Sample contains strings indicative of BusyBox which embeds multiple Unix commands in a single executable
Sample has stripped symbol table
Sample listens on a socket
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Uses the "uname" system call to query kernel version information (possible evasion)
Yara signature match

Classification

Name Description Attribution Blogpost URLs Link
Mirai Mirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese. Nowadays it targets a wide range of networked embedded devices such as IP cameras, home routers (many vendors involved), and other IoT devices. Since the source code was published on "Hack Forums" many variants of the Mirai family appeared, infecting mostly home networks all around the world. No Attribution https://malpedia.caad.fkie.fraunhofer.de/details/elf.mirai
Name Description Attribution Blogpost URLs Link
MooBot No Attribution https://malpedia.caad.fkie.fraunhofer.de/details/elf.moobot

AV Detection

barindex
Source: sQSqM58mvl.elf Avira: detected
Source: sQSqM58mvl.elf ReversingLabs: Detection: 68%

Networking

barindex
Source: Traffic Snort IDS: 2027973 ET EXPLOIT HiSilicon DVR - Default Telnet Root Password Inbound 192.168.2.23:42958 -> 190.145.51.1:23
Source: Traffic Snort IDS: 2027973 ET EXPLOIT HiSilicon DVR - Default Telnet Root Password Inbound 192.168.2.23:54928 -> 187.58.219.65:23
Source: Traffic Snort IDS: 2027973 ET EXPLOIT HiSilicon DVR - Default Telnet Root Password Inbound 192.168.2.23:49534 -> 114.202.139.5:23
Source: Traffic Snort IDS: 2023444 ET TROJAN Possible Linux.Mirai Login Attempt (klv1234) 192.168.2.23:37274 -> 37.18.12.97:23
Source: Traffic Snort IDS: 2023333 ET TROJAN Linux.Mirai Login Attempt (xc3511) 192.168.2.23:37312 -> 37.18.12.97:23
Source: Traffic Snort IDS: 2027973 ET EXPLOIT HiSilicon DVR - Default Telnet Root Password Inbound 192.168.2.23:37312 -> 37.18.12.97:23
Source: Traffic Snort IDS: 2023433 ET TROJAN Possible Linux.Mirai Login Attempt (7ujMko0admin) 192.168.2.23:37430 -> 37.18.12.97:23
Source: Traffic Snort IDS: 2027973 ET EXPLOIT HiSilicon DVR - Default Telnet Root Password Inbound 192.168.2.23:37466 -> 37.18.12.97:23
Source: Traffic Snort IDS: 2027973 ET EXPLOIT HiSilicon DVR - Default Telnet Root Password Inbound 192.168.2.23:55828 -> 187.58.219.65:23
Source: Traffic Snort IDS: 2027973 ET EXPLOIT HiSilicon DVR - Default Telnet Root Password Inbound 192.168.2.23:37494 -> 37.18.12.97:23
Source: Traffic Snort IDS: 2023449 ET TROJAN Possible Linux.Mirai Login Attempt (vizxv) 192.168.2.23:37550 -> 37.18.12.97:23
Source: Traffic Snort IDS: 2023444 ET TROJAN Possible Linux.Mirai Login Attempt (klv1234) 192.168.2.23:37592 -> 37.18.12.97:23
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55094
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55096
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 42448
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55108
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55112
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 42460
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55128
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 42480
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55138
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 42494
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55150
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 42508
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55168
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 42528
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55184
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55122
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 42538
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55208
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 42560
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55226
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55194
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 42580
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55244
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55246
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 42602
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55266
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55264
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55274
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 42630
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55282
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55286
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55284
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 42642
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55294
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55298
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55296
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 42654
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55306
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55308
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55310
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55324
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55326
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 42672
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55338
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55340
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 42692
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55348
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55352
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 42704
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55362
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55364
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55378
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55380
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55390
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55328
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 42750
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55408
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55410
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55392
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 42770
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55422
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55424
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55432
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55440
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55442
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 42788
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55448
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55458
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55460
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 42812
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55468
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55478
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55476
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 42834
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55488
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55496
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55498
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 42850
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55502
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55508
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55510
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55516
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 42864
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55524
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55526
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55532
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 42886
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55542
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55550
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 42906
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55560
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55564
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 42922
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55578
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55560
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 42934
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55592
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55574
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 42950
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55602
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55608
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55540
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55618
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 42966
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55620
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55626
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 42982
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55636
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55644
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55652
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55656
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55674
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55688
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55702
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55712
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55724
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55668
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55742
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55748
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55768
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55772
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 60196
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 60212
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 60224
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 60230
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 60242
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 60252
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 60262
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 60270
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 60276
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 60284
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 60294
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 60298
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 60312
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 60338
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 60352
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 60368
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 60384
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 60388
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 60400
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 60418
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 60434
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 60448
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 60458
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 60472
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 60478
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 60496
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 60508
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 60516
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 60524
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 60526
Source: global traffic TCP traffic: 192.168.2.23:40064 -> 45.131.111.251:59666
Source: /tmp/sQSqM58mvl.elf (PID: 6230) Socket: 127.0.0.1::52380 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
Source: global traffic TCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
Source: global traffic TCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
Source: unknown TCP traffic detected without corresponding DNS query: 79.239.88.6
Source: unknown TCP traffic detected without corresponding DNS query: 162.174.95.7
Source: unknown TCP traffic detected without corresponding DNS query: 93.237.60.141
Source: unknown TCP traffic detected without corresponding DNS query: 187.48.133.164
Source: unknown TCP traffic detected without corresponding DNS query: 69.220.212.174
Source: unknown TCP traffic detected without corresponding DNS query: 120.93.79.2
Source: unknown TCP traffic detected without corresponding DNS query: 176.128.212.237
Source: unknown TCP traffic detected without corresponding DNS query: 187.166.6.19
Source: unknown TCP traffic detected without corresponding DNS query: 83.153.235.19
Source: unknown TCP traffic detected without corresponding DNS query: 168.72.114.249
Source: unknown TCP traffic detected without corresponding DNS query: 124.41.98.59
Source: unknown TCP traffic detected without corresponding DNS query: 32.74.37.25
Source: unknown TCP traffic detected without corresponding DNS query: 133.162.94.147
Source: unknown TCP traffic detected without corresponding DNS query: 123.106.171.39
Source: unknown TCP traffic detected without corresponding DNS query: 117.124.89.24
Source: unknown TCP traffic detected without corresponding DNS query: 216.128.187.70
Source: unknown TCP traffic detected without corresponding DNS query: 12.49.171.18
Source: unknown TCP traffic detected without corresponding DNS query: 147.39.53.181
Source: unknown TCP traffic detected without corresponding DNS query: 158.99.198.18
Source: unknown TCP traffic detected without corresponding DNS query: 160.120.109.136
Source: unknown TCP traffic detected without corresponding DNS query: 136.185.148.156
Source: unknown TCP traffic detected without corresponding DNS query: 206.63.21.45
Source: unknown TCP traffic detected without corresponding DNS query: 222.147.125.142
Source: unknown TCP traffic detected without corresponding DNS query: 81.51.37.234
Source: unknown TCP traffic detected without corresponding DNS query: 171.169.67.92
Source: unknown TCP traffic detected without corresponding DNS query: 67.0.233.73
Source: unknown TCP traffic detected without corresponding DNS query: 193.40.214.89
Source: unknown TCP traffic detected without corresponding DNS query: 57.127.171.95
Source: unknown TCP traffic detected without corresponding DNS query: 205.174.39.141
Source: unknown TCP traffic detected without corresponding DNS query: 57.46.86.106
Source: unknown TCP traffic detected without corresponding DNS query: 36.176.116.21
Source: unknown TCP traffic detected without corresponding DNS query: 160.221.100.47
Source: unknown TCP traffic detected without corresponding DNS query: 71.130.219.104
Source: unknown TCP traffic detected without corresponding DNS query: 58.146.26.78
Source: unknown TCP traffic detected without corresponding DNS query: 216.163.44.45
Source: unknown TCP traffic detected without corresponding DNS query: 173.231.241.107
Source: unknown TCP traffic detected without corresponding DNS query: 170.152.131.172
Source: unknown TCP traffic detected without corresponding DNS query: 42.206.129.69
Source: unknown TCP traffic detected without corresponding DNS query: 152.153.242.165
Source: unknown TCP traffic detected without corresponding DNS query: 109.114.2.118
Source: unknown TCP traffic detected without corresponding DNS query: 202.165.240.169
Source: unknown TCP traffic detected without corresponding DNS query: 180.89.214.147
Source: unknown TCP traffic detected without corresponding DNS query: 92.5.163.160
Source: unknown TCP traffic detected without corresponding DNS query: 118.48.136.238
Source: unknown TCP traffic detected without corresponding DNS query: 58.215.93.207
Source: unknown TCP traffic detected without corresponding DNS query: 1.46.88.192
Source: unknown TCP traffic detected without corresponding DNS query: 205.252.212.91
Source: unknown TCP traffic detected without corresponding DNS query: 2.112.233.100
Source: unknown TCP traffic detected without corresponding DNS query: 84.91.175.126
Source: unknown TCP traffic detected without corresponding DNS query: 119.153.113.54
Source: unknown Network traffic detected: HTTP traffic on port 43928 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 42836 -> 443

System Summary

barindex
Source: sQSqM58mvl.elf, type: SAMPLE Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: sQSqM58mvl.elf, type: SAMPLE Matched rule: Linux_Trojan_Mirai_0bce98a2 Author: unknown
Source: 6234.1.00007f94d0017000.00007f94d0037000.r-x.sdmp, type: MEMORY Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: 6234.1.00007f94d0017000.00007f94d0037000.r-x.sdmp, type: MEMORY Matched rule: Linux_Trojan_Mirai_0bce98a2 Author: unknown
Source: 6230.1.00007f94d0017000.00007f94d0037000.r-x.sdmp, type: MEMORY Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: 6230.1.00007f94d0017000.00007f94d0037000.r-x.sdmp, type: MEMORY Matched rule: Linux_Trojan_Mirai_0bce98a2 Author: unknown
Source: Process Memory Space: sQSqM58mvl.elf PID: 6230, type: MEMORYSTR Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: Process Memory Space: sQSqM58mvl.elf PID: 6234, type: MEMORYSTR Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: Initial sample String containing 'busybox' found: /bin/busybox
Source: Initial sample String containing 'busybox' found: /proc//proc/%s/exe/proc/self/exevar/Challengeapp/hi3511gmDVRiboxusr/dvr_main _8182T_1108mnt/mtd/app/guivar/Kylinl0 c/udevdanko-app/ankosample _8182T_1104var/tmp/soniahicorestm_hi3511_dvr/bin/busybox/usr/lib/systemd/systemd/usr/libexec/openssh/sftp-serverusr/shellmnt/sys/bin/boot/media/srv/var/run/sbin/lib/etc/dev/home/Davincitelnetsshwatchdog/var/spoolsshd/usr/compress/bin//compress/bin/compress/usr/bashhttpdtelnetddropbearropbearencodersystem/root/dvr_gui//root/dvr_app//anko-app//opt/abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ
Source: ELF static info symbol of initial sample .symtab present: no
Source: sQSqM58mvl.elf, type: SAMPLE Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: sQSqM58mvl.elf, type: SAMPLE Matched rule: Linux_Trojan_Mirai_0bce98a2 reference_sample = 1b20df8df7f84ad29d81ccbe276f49a6488c2214077b13da858656c027531c80, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 993d0d2e24152d0fb72cc5d5add395bed26671c3935f73386341398b91cb0e6e, id = 0bce98a2-113e-41e1-95c9-9e1852b26142, last_modified = 2021-09-16
Source: 6234.1.00007f94d0017000.00007f94d0037000.r-x.sdmp, type: MEMORY Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: 6234.1.00007f94d0017000.00007f94d0037000.r-x.sdmp, type: MEMORY Matched rule: Linux_Trojan_Mirai_0bce98a2 reference_sample = 1b20df8df7f84ad29d81ccbe276f49a6488c2214077b13da858656c027531c80, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 993d0d2e24152d0fb72cc5d5add395bed26671c3935f73386341398b91cb0e6e, id = 0bce98a2-113e-41e1-95c9-9e1852b26142, last_modified = 2021-09-16
Source: 6230.1.00007f94d0017000.00007f94d0037000.r-x.sdmp, type: MEMORY Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: 6230.1.00007f94d0017000.00007f94d0037000.r-x.sdmp, type: MEMORY Matched rule: Linux_Trojan_Mirai_0bce98a2 reference_sample = 1b20df8df7f84ad29d81ccbe276f49a6488c2214077b13da858656c027531c80, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 993d0d2e24152d0fb72cc5d5add395bed26671c3935f73386341398b91cb0e6e, id = 0bce98a2-113e-41e1-95c9-9e1852b26142, last_modified = 2021-09-16
Source: Process Memory Space: sQSqM58mvl.elf PID: 6230, type: MEMORYSTR Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: Process Memory Space: sQSqM58mvl.elf PID: 6234, type: MEMORYSTR Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: classification engine Classification label: mal100.troj.evad.linELF@0/0@0/0

Hooking and other Techniques for Hiding and Protection

barindex
Source: /tmp/sQSqM58mvl.elf (PID: 6230) File: /tmp/sQSqM58mvl.elf Jump to behavior
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55094
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55096
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 42448
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55108
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55112
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 42460
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55128
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 42480
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55138
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 42494
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55150
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 42508
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55168
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 42528
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55184
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55122
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 42538
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55208
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 42560
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55226
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55194
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 42580
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55244
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55246
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 42602
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55266
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55264
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55274
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 42630
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55282
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55286
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55284
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 42642
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55294
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55298
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55296
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 42654
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55306
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55308
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55310
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55324
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55326
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 42672
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55338
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55340
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 42692
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55348
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55352
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 42704
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55362
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55364
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55378
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55380
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55390
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55328
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 42750
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55408
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55410
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55392
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 42770
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55422
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55424
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55432
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55440
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55442
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 42788
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55448
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55458
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55460
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 42812
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55468
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55478
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55476
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 42834
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55488
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55496
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55498
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 42850
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55502
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55508
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55510
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55516
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 42864
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55524
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55526
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55532
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 42886
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55542
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55550
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 42906
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55560
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55564
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 42922
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55578
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55560
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 42934
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55592
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55574
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 42950
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55602
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55608
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55540
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55618
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 42966
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55620
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55626
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 42982
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55636
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55644
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55652
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55656
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55674
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55688
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55702
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55712
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55724
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55668
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55742
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55748
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55768
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55772
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 60196
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 60212
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 60224
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 60230
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 60242
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 60252
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 60262
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 60270
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 60276
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 60284
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 60294
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 60298
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 60312
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 60338
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 60352
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 60368
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 60384
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 60388
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 60400
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 60418
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 60434
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 60448
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 60458
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 60472
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 60478
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 60496
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 60508
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 60516
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 60524
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 60526
Source: /tmp/sQSqM58mvl.elf (PID: 6230) Queries kernel information via 'uname': Jump to behavior
Source: sQSqM58mvl.elf, 6230.1.000055f8ab04c000.000055f8ab17a000.rw-.sdmp, sQSqM58mvl.elf, 6234.1.000055f8ab04c000.000055f8ab17a000.rw-.sdmp Binary or memory string: U!/etc/qemu-binfmt/arm
Source: sQSqM58mvl.elf, 6230.1.00007ffc0f43e000.00007ffc0f45f000.rw-.sdmp, sQSqM58mvl.elf, 6234.1.00007ffc0f43e000.00007ffc0f45f000.rw-.sdmp Binary or memory string: x86_64/usr/bin/qemu-arm/tmp/sQSqM58mvl.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/sQSqM58mvl.elf
Source: sQSqM58mvl.elf, 6230.1.000055f8ab04c000.000055f8ab17a000.rw-.sdmp, sQSqM58mvl.elf, 6234.1.000055f8ab04c000.000055f8ab17a000.rw-.sdmp Binary or memory string: /etc/qemu-binfmt/arm
Source: sQSqM58mvl.elf, 6230.1.00007ffc0f43e000.00007ffc0f45f000.rw-.sdmp, sQSqM58mvl.elf, 6234.1.00007ffc0f43e000.00007ffc0f45f000.rw-.sdmp Binary or memory string: /usr/bin/qemu-arm

Stealing of Sensitive Information

barindex
Source: Yara match File source: dump.pcap, type: PCAP
Source: Yara match File source: sQSqM58mvl.elf, type: SAMPLE
Source: Yara match File source: 6234.1.00007f94d0017000.00007f94d0037000.r-x.sdmp, type: MEMORY
Source: Yara match File source: 6230.1.00007f94d0017000.00007f94d0037000.r-x.sdmp, type: MEMORY
Source: Yara match File source: Process Memory Space: sQSqM58mvl.elf PID: 6230, type: MEMORYSTR
Source: Yara match File source: sQSqM58mvl.elf, type: SAMPLE
Source: Yara match File source: 6234.1.00007f94d0017000.00007f94d0037000.r-x.sdmp, type: MEMORY
Source: Yara match File source: 6230.1.00007f94d0017000.00007f94d0037000.r-x.sdmp, type: MEMORY
Source: Yara match File source: Process Memory Space: sQSqM58mvl.elf PID: 6230, type: MEMORYSTR
Source: Yara match File source: Process Memory Space: sQSqM58mvl.elf PID: 6234, type: MEMORYSTR

Remote Access Functionality

barindex
Source: Traffic Snort IDS: ET TROJAN Possible Linux.Mirai Login Attempt (klv1234)
Source: Traffic Snort IDS: ET TROJAN Linux.Mirai Login Attempt (xc3511)
Source: Traffic Snort IDS: ET TROJAN Possible Linux.Mirai Login Attempt (7ujMko0admin)
Source: Traffic Snort IDS: ET TROJAN Possible Linux.Mirai Login Attempt (vizxv)
Source: Traffic Snort IDS: ET TROJAN Possible Linux.Mirai Login Attempt (klv1234)
Source: Yara match File source: dump.pcap, type: PCAP
Source: Yara match File source: sQSqM58mvl.elf, type: SAMPLE
Source: Yara match File source: 6234.1.00007f94d0017000.00007f94d0037000.r-x.sdmp, type: MEMORY
Source: Yara match File source: 6230.1.00007f94d0017000.00007f94d0037000.r-x.sdmp, type: MEMORY
Source: Yara match File source: Process Memory Space: sQSqM58mvl.elf PID: 6230, type: MEMORYSTR
Source: Yara match File source: sQSqM58mvl.elf, type: SAMPLE
Source: Yara match File source: 6234.1.00007f94d0017000.00007f94d0037000.r-x.sdmp, type: MEMORY
Source: Yara match File source: 6230.1.00007f94d0017000.00007f94d0037000.r-x.sdmp, type: MEMORY
Source: Yara match File source: Process Memory Space: sQSqM58mvl.elf PID: 6230, type: MEMORYSTR
Source: Yara match File source: Process Memory Space: sQSqM58mvl.elf PID: 6234, type: MEMORYSTR
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs