Linux Analysis Report
QwVUcfwNd7.elf

Overview

General Information

Sample name: QwVUcfwNd7.elf
renamed because original name is a hash value
Original sample name: 20925b6892eb65df6d163098c8da0028.elf
Analysis ID: 1438529
MD5: 20925b6892eb65df6d163098c8da0028
SHA1: b6325bf889a571c30238ff0d84c79f14059cf20b
SHA256: f2ea3f2b3d2646fa484c2661193b9e2cbe31055d003b5aeda7ceeb5cdd077aa5
Tags: 32elfmipsmirai
Infos:

Detection

Score: 60
Range: 0 - 100
Whitelisted: false

Signatures

Antivirus / Scanner detection for submitted sample
Multi AV Scanner detection for submitted file
Connects to many ports of the same IP (likely port scanning)
Detected TCP or UDP traffic on non-standard ports
Enumerates processes within the "proc" file system
Executes the "rm" command used to delete files or directories
Sample has stripped symbol table
Sample listens on a socket
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

AV Detection

barindex
Source: QwVUcfwNd7.elf Avira: detected
Source: QwVUcfwNd7.elf ReversingLabs: Detection: 60%

Networking

barindex
Source: global traffic TCP traffic: 91.92.244.58 ports 0,1,5,6,9,60195
Source: global traffic TCP traffic: 192.168.2.23:54928 -> 91.92.244.58:60195
Source: /tmp/QwVUcfwNd7.elf (PID: 6209) Socket: 127.0.0.1::63841 Jump to behavior
Source: unknown TCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknown TCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknown TCP traffic detected without corresponding DNS query: 54.171.230.55
Source: unknown TCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknown TCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknown TCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknown TCP traffic detected without corresponding DNS query: 54.171.230.55
Source: unknown TCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknown TCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknown TCP traffic detected without corresponding DNS query: 91.189.91.43
Source: global traffic DNS traffic detected: DNS query: minuoddos.top
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 33608
Source: unknown Network traffic detected: HTTP traffic on port 43928 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 33608 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 42836 -> 443
Source: ELF static info symbol of initial sample .symtab present: no
Source: classification engine Classification label: mal60.troj.linELF@0/0@1/0
Source: /tmp/QwVUcfwNd7.elf (PID: 6217) File opened: /proc/1582/maps Jump to behavior
Source: /tmp/QwVUcfwNd7.elf (PID: 6217) File opened: /proc/2033/maps Jump to behavior
Source: /tmp/QwVUcfwNd7.elf (PID: 6217) File opened: /proc/1612/maps Jump to behavior
Source: /tmp/QwVUcfwNd7.elf (PID: 6217) File opened: /proc/1579/maps Jump to behavior
Source: /tmp/QwVUcfwNd7.elf (PID: 6217) File opened: /proc/1699/maps Jump to behavior
Source: /tmp/QwVUcfwNd7.elf (PID: 6217) File opened: /proc/1335/maps Jump to behavior
Source: /tmp/QwVUcfwNd7.elf (PID: 6217) File opened: /proc/1698/maps Jump to behavior
Source: /tmp/QwVUcfwNd7.elf (PID: 6217) File opened: /proc/2028/maps Jump to behavior
Source: /tmp/QwVUcfwNd7.elf (PID: 6217) File opened: /proc/1334/maps Jump to behavior
Source: /tmp/QwVUcfwNd7.elf (PID: 6217) File opened: /proc/1576/maps Jump to behavior
Source: /tmp/QwVUcfwNd7.elf (PID: 6217) File opened: /proc/2025/maps Jump to behavior
Source: /tmp/QwVUcfwNd7.elf (PID: 6217) File opened: /proc/2146/maps Jump to behavior
Source: /tmp/QwVUcfwNd7.elf (PID: 6217) File opened: /proc/910/maps Jump to behavior
Source: /tmp/QwVUcfwNd7.elf (PID: 6217) File opened: /proc/912/maps Jump to behavior
Source: /tmp/QwVUcfwNd7.elf (PID: 6217) File opened: /proc/517/maps Jump to behavior
Source: /tmp/QwVUcfwNd7.elf (PID: 6217) File opened: /proc/759/maps Jump to behavior
Source: /tmp/QwVUcfwNd7.elf (PID: 6217) File opened: /proc/918/maps Jump to behavior
Source: /tmp/QwVUcfwNd7.elf (PID: 6217) File opened: /proc/1594/maps Jump to behavior
Source: /tmp/QwVUcfwNd7.elf (PID: 6217) File opened: /proc/1349/maps Jump to behavior
Source: /tmp/QwVUcfwNd7.elf (PID: 6217) File opened: /proc/1623/maps Jump to behavior
Source: /tmp/QwVUcfwNd7.elf (PID: 6217) File opened: /proc/761/maps Jump to behavior
Source: /tmp/QwVUcfwNd7.elf (PID: 6217) File opened: /proc/1622/maps Jump to behavior
Source: /tmp/QwVUcfwNd7.elf (PID: 6217) File opened: /proc/884/maps Jump to behavior
Source: /tmp/QwVUcfwNd7.elf (PID: 6217) File opened: /proc/1983/maps Jump to behavior
Source: /tmp/QwVUcfwNd7.elf (PID: 6217) File opened: /proc/2038/maps Jump to behavior
Source: /tmp/QwVUcfwNd7.elf (PID: 6217) File opened: /proc/1344/maps Jump to behavior
Source: /tmp/QwVUcfwNd7.elf (PID: 6217) File opened: /proc/1465/maps Jump to behavior
Source: /tmp/QwVUcfwNd7.elf (PID: 6217) File opened: /proc/1586/maps Jump to behavior
Source: /tmp/QwVUcfwNd7.elf (PID: 6217) File opened: /proc/1860/maps Jump to behavior
Source: /tmp/QwVUcfwNd7.elf (PID: 6217) File opened: /proc/1463/maps Jump to behavior
Source: /tmp/QwVUcfwNd7.elf (PID: 6217) File opened: /proc/2156/maps Jump to behavior
Source: /tmp/QwVUcfwNd7.elf (PID: 6217) File opened: /proc/800/maps Jump to behavior
Source: /tmp/QwVUcfwNd7.elf (PID: 6217) File opened: /proc/801/maps Jump to behavior
Source: /tmp/QwVUcfwNd7.elf (PID: 6217) File opened: /proc/1629/maps Jump to behavior
Source: /tmp/QwVUcfwNd7.elf (PID: 6217) File opened: /proc/1627/maps Jump to behavior
Source: /tmp/QwVUcfwNd7.elf (PID: 6217) File opened: /proc/1900/maps Jump to behavior
Source: /tmp/QwVUcfwNd7.elf (PID: 6217) File opened: /proc/491/maps Jump to behavior
Source: /tmp/QwVUcfwNd7.elf (PID: 6217) File opened: /proc/2050/maps Jump to behavior
Source: /tmp/QwVUcfwNd7.elf (PID: 6217) File opened: /proc/1877/maps Jump to behavior
Source: /tmp/QwVUcfwNd7.elf (PID: 6217) File opened: /proc/772/maps Jump to behavior
Source: /tmp/QwVUcfwNd7.elf (PID: 6217) File opened: /proc/1633/maps Jump to behavior
Source: /tmp/QwVUcfwNd7.elf (PID: 6217) File opened: /proc/1599/maps Jump to behavior
Source: /tmp/QwVUcfwNd7.elf (PID: 6217) File opened: /proc/1632/maps Jump to behavior
Source: /tmp/QwVUcfwNd7.elf (PID: 6217) File opened: /proc/774/maps Jump to behavior
Source: /tmp/QwVUcfwNd7.elf (PID: 6217) File opened: /proc/1477/maps Jump to behavior
Source: /tmp/QwVUcfwNd7.elf (PID: 6217) File opened: /proc/654/maps Jump to behavior
Source: /tmp/QwVUcfwNd7.elf (PID: 6217) File opened: /proc/896/maps Jump to behavior
Source: /tmp/QwVUcfwNd7.elf (PID: 6217) File opened: /proc/1476/maps Jump to behavior
Source: /tmp/QwVUcfwNd7.elf (PID: 6217) File opened: /proc/1872/maps Jump to behavior
Source: /tmp/QwVUcfwNd7.elf (PID: 6217) File opened: /proc/2048/maps Jump to behavior
Source: /tmp/QwVUcfwNd7.elf (PID: 6217) File opened: /proc/655/maps Jump to behavior
Source: /tmp/QwVUcfwNd7.elf (PID: 6217) File opened: /proc/1475/maps Jump to behavior
Source: /tmp/QwVUcfwNd7.elf (PID: 6217) File opened: /proc/656/maps Jump to behavior
Source: /tmp/QwVUcfwNd7.elf (PID: 6217) File opened: /proc/777/maps Jump to behavior
Source: /tmp/QwVUcfwNd7.elf (PID: 6217) File opened: /proc/657/maps Jump to behavior
Source: /tmp/QwVUcfwNd7.elf (PID: 6217) File opened: /proc/658/maps Jump to behavior
Source: /tmp/QwVUcfwNd7.elf (PID: 6217) File opened: /proc/419/maps Jump to behavior
Source: /tmp/QwVUcfwNd7.elf (PID: 6217) File opened: /proc/936/maps Jump to behavior
Source: /tmp/QwVUcfwNd7.elf (PID: 6217) File opened: /proc/1639/maps Jump to behavior
Source: /tmp/QwVUcfwNd7.elf (PID: 6217) File opened: /proc/1638/maps Jump to behavior
Source: /tmp/QwVUcfwNd7.elf (PID: 6217) File opened: /proc/2180/maps Jump to behavior
Source: /tmp/QwVUcfwNd7.elf (PID: 6217) File opened: /proc/1809/maps Jump to behavior
Source: /tmp/QwVUcfwNd7.elf (PID: 6217) File opened: /proc/1494/maps Jump to behavior
Source: /tmp/QwVUcfwNd7.elf (PID: 6217) File opened: /proc/1890/maps Jump to behavior
Source: /tmp/QwVUcfwNd7.elf (PID: 6217) File opened: /proc/2063/maps Jump to behavior
Source: /tmp/QwVUcfwNd7.elf (PID: 6217) File opened: /proc/2062/maps Jump to behavior
Source: /tmp/QwVUcfwNd7.elf (PID: 6217) File opened: /proc/1888/maps Jump to behavior
Source: /tmp/QwVUcfwNd7.elf (PID: 6217) File opened: /proc/1886/maps Jump to behavior
Source: /tmp/QwVUcfwNd7.elf (PID: 6217) File opened: /proc/420/maps Jump to behavior
Source: /tmp/QwVUcfwNd7.elf (PID: 6217) File opened: /proc/1489/maps Jump to behavior
Source: /tmp/QwVUcfwNd7.elf (PID: 6217) File opened: /proc/785/maps Jump to behavior
Source: /tmp/QwVUcfwNd7.elf (PID: 6217) File opened: /proc/1642/maps Jump to behavior
Source: /tmp/QwVUcfwNd7.elf (PID: 6217) File opened: /proc/788/maps Jump to behavior
Source: /tmp/QwVUcfwNd7.elf (PID: 6217) File opened: /proc/667/maps Jump to behavior
Source: /tmp/QwVUcfwNd7.elf (PID: 6217) File opened: /proc/789/maps Jump to behavior
Source: /tmp/QwVUcfwNd7.elf (PID: 6217) File opened: /proc/1648/maps Jump to behavior
Source: /tmp/QwVUcfwNd7.elf (PID: 6217) File opened: /proc/2078/maps Jump to behavior
Source: /tmp/QwVUcfwNd7.elf (PID: 6217) File opened: /proc/2077/maps Jump to behavior
Source: /tmp/QwVUcfwNd7.elf (PID: 6217) File opened: /proc/2074/maps Jump to behavior
Source: /tmp/QwVUcfwNd7.elf (PID: 6217) File opened: /proc/670/maps Jump to behavior
Source: /tmp/QwVUcfwNd7.elf (PID: 6217) File opened: /proc/793/maps Jump to behavior
Source: /tmp/QwVUcfwNd7.elf (PID: 6217) File opened: /proc/1656/maps Jump to behavior
Source: /tmp/QwVUcfwNd7.elf (PID: 6217) File opened: /proc/1654/maps Jump to behavior
Source: /tmp/QwVUcfwNd7.elf (PID: 6217) File opened: /proc/674/maps Jump to behavior
Source: /tmp/QwVUcfwNd7.elf (PID: 6217) File opened: /proc/1532/maps Jump to behavior
Source: /tmp/QwVUcfwNd7.elf (PID: 6217) File opened: /proc/796/maps Jump to behavior
Source: /tmp/QwVUcfwNd7.elf (PID: 6217) File opened: /proc/675/maps Jump to behavior
Source: /tmp/QwVUcfwNd7.elf (PID: 6217) File opened: /proc/797/maps Jump to behavior
Source: /tmp/QwVUcfwNd7.elf (PID: 6217) File opened: /proc/676/maps Jump to behavior
Source: /tmp/QwVUcfwNd7.elf (PID: 6217) File opened: /proc/677/maps Jump to behavior
Source: /tmp/QwVUcfwNd7.elf (PID: 6217) File opened: /proc/2069/maps Jump to behavior
Source: /tmp/QwVUcfwNd7.elf (PID: 6217) File opened: /proc/2102/maps Jump to behavior
Source: /tmp/QwVUcfwNd7.elf (PID: 6217) File opened: /proc/799/maps Jump to behavior
Source: /tmp/QwVUcfwNd7.elf (PID: 6217) File opened: /proc/2080/maps Jump to behavior
Source: /tmp/QwVUcfwNd7.elf (PID: 6217) File opened: /proc/2084/maps Jump to behavior
Source: /tmp/QwVUcfwNd7.elf (PID: 6217) File opened: /proc/2083/maps Jump to behavior
Source: /tmp/QwVUcfwNd7.elf (PID: 6217) File opened: /proc/1668/maps Jump to behavior
Source: /tmp/QwVUcfwNd7.elf (PID: 6217) File opened: /proc/1664/maps Jump to behavior
Source: /tmp/QwVUcfwNd7.elf (PID: 6217) File opened: /proc/1389/maps Jump to behavior
Source: /tmp/QwVUcfwNd7.elf (PID: 6217) File opened: /proc/720/maps Jump to behavior
Source: /tmp/QwVUcfwNd7.elf (PID: 6217) File opened: /proc/2114/maps Jump to behavior
Source: /tmp/QwVUcfwNd7.elf (PID: 6217) File opened: /proc/721/maps Jump to behavior
Source: /tmp/QwVUcfwNd7.elf (PID: 6217) File opened: /proc/1661/maps Jump to behavior
Source: /tmp/QwVUcfwNd7.elf (PID: 6217) File opened: /proc/2079/maps Jump to behavior
Source: /tmp/QwVUcfwNd7.elf (PID: 6217) File opened: /proc/847/maps Jump to behavior
Source: /usr/bin/dash (PID: 6255) Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.c3ZtrnMGbs /tmp/tmp.Vv584LR7hS /tmp/tmp.ELtlvz5rg5 Jump to behavior
Source: /usr/bin/dash (PID: 6256) Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.c3ZtrnMGbs /tmp/tmp.Vv584LR7hS /tmp/tmp.ELtlvz5rg5 Jump to behavior
Source: /tmp/QwVUcfwNd7.elf (PID: 6209) Queries kernel information via 'uname': Jump to behavior
Source: QwVUcfwNd7.elf, 6209.1.000055ad86bec000.000055ad86c73000.rw-.sdmp, QwVUcfwNd7.elf, 6211.1.000055ad86bec000.000055ad86c73000.rw-.sdmp, QwVUcfwNd7.elf, 6214.1.000055ad86bec000.000055ad86c73000.rw-.sdmp Binary or memory string: U!/etc/qemu-binfmt/mips
Source: QwVUcfwNd7.elf, 6209.1.000055ad86bec000.000055ad86c73000.rw-.sdmp, QwVUcfwNd7.elf, 6211.1.000055ad86bec000.000055ad86c73000.rw-.sdmp, QwVUcfwNd7.elf, 6214.1.000055ad86bec000.000055ad86c73000.rw-.sdmp Binary or memory string: /etc/qemu-binfmt/mips
Source: QwVUcfwNd7.elf, 6209.1.00007ffce80a6000.00007ffce80c7000.rw-.sdmp, QwVUcfwNd7.elf, 6211.1.00007ffce80a6000.00007ffce80c7000.rw-.sdmp, QwVUcfwNd7.elf, 6214.1.00007ffce80a6000.00007ffce80c7000.rw-.sdmp Binary or memory string: /usr/bin/qemu-mips
Source: QwVUcfwNd7.elf, 6209.1.00007ffce80a6000.00007ffce80c7000.rw-.sdmp, QwVUcfwNd7.elf, 6211.1.00007ffce80a6000.00007ffce80c7000.rw-.sdmp, QwVUcfwNd7.elf, 6214.1.00007ffce80a6000.00007ffce80c7000.rw-.sdmp Binary or memory string: x86_64/usr/bin/qemu-mips/tmp/QwVUcfwNd7.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/QwVUcfwNd7.elf
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs