Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
b6.elf

Overview

General Information

Sample name:b6.elf
Analysis ID:1619037
MD5:6c5f331d84d27c0a8f5f03f4d637c33a
SHA1:df387bcab281fd8a83cdeb25d05bf4aaabb50ec0
SHA256:bf5c0277928a3045128cddcc086508b33b65e07c36b944ae894c6f15be29f175
Tags:elfuser-abuse_ch
Infos:

Detection

Score:52
Range:0 - 100

Signatures

Multi AV Scanner detection for submitted file
Sample tries to kill multiple processes (SIGKILL)
Detected TCP or UDP traffic on non-standard ports
Detected non-DNS traffic on DNS port
Enumerates processes within the "proc" file system
Executes the "rm" command used to delete files or directories
Reads system information from the proc file system
Sample contains strings that are user agent strings indicative of HTTP manipulation
Sample has stripped symbol table
Sample tries to kill a process (SIGKILL)
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

Joe Sandbox version:42.0.0 Malachite
Analysis ID:1619037
Start date and time:2025-02-19 14:12:22 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 45s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:b6.elf
Detection:MAL
Classification:mal52.spre.linELF@0/1@0/0
  • VT rate limit hit for: http://1/wget.sh
Command:/tmp/b6.elf
PID:6239
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
Segmentation fault
Standard Error:
  • system is lnxubuntu20
  • dash New Fork (PID: 6205, Parent: 4331)
  • rm (PID: 6205, Parent: 4331, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.NfV2IbpYCe /tmp/tmp.cl7u7Wzlp9 /tmp/tmp.weBqiO12zx
  • dash New Fork (PID: 6206, Parent: 4331)
  • cat (PID: 6206, Parent: 4331, MD5: 7e9d213e404ad3bb82e4ebb2e1f2c1b3) Arguments: cat /tmp/tmp.NfV2IbpYCe
  • dash New Fork (PID: 6207, Parent: 4331)
  • head (PID: 6207, Parent: 4331, MD5: fd96a67145172477dd57131396fc9608) Arguments: head -n 10
  • dash New Fork (PID: 6208, Parent: 4331)
  • tr (PID: 6208, Parent: 4331, MD5: fbd1402dd9f72d8ebfff00ce7c3a7bb5) Arguments: tr -d \\000-\\011\\013\\014\\016-\\037
  • dash New Fork (PID: 6209, Parent: 4331)
  • cut (PID: 6209, Parent: 4331, MD5: d8ed0ea8f22c0de0f8692d4d9f1759d3) Arguments: cut -c -80
  • dash New Fork (PID: 6210, Parent: 4331)
  • cat (PID: 6210, Parent: 4331, MD5: 7e9d213e404ad3bb82e4ebb2e1f2c1b3) Arguments: cat /tmp/tmp.NfV2IbpYCe
  • dash New Fork (PID: 6211, Parent: 4331)
  • head (PID: 6211, Parent: 4331, MD5: fd96a67145172477dd57131396fc9608) Arguments: head -n 10
  • dash New Fork (PID: 6212, Parent: 4331)
  • tr (PID: 6212, Parent: 4331, MD5: fbd1402dd9f72d8ebfff00ce7c3a7bb5) Arguments: tr -d \\000-\\011\\013\\014\\016-\\037
  • dash New Fork (PID: 6213, Parent: 4331)
  • cut (PID: 6213, Parent: 4331, MD5: d8ed0ea8f22c0de0f8692d4d9f1759d3) Arguments: cut -c -80
  • dash New Fork (PID: 6214, Parent: 4331)
  • rm (PID: 6214, Parent: 4331, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.NfV2IbpYCe /tmp/tmp.cl7u7Wzlp9 /tmp/tmp.weBqiO12zx
  • b6.elf (PID: 6239, Parent: 6129, MD5: 5ebfcae4fe2471fcc5695c2394773ff1) Arguments: /tmp/b6.elf
    • b6.elf New Fork (PID: 6252, Parent: 6239)
      • b6.elf New Fork (PID: 6254, Parent: 6252)
        • b6.elf New Fork (PID: 6262, Parent: 6254)
        • b6.elf New Fork (PID: 6264, Parent: 6254)
  • wrapper-2.0 (PID: 6241, Parent: 2063, MD5: ac0b8a906f359a8ae102244738682e76) Arguments: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libsystray.so 6 12582920 systray "Notification Area" "Area where notification icons appear"
  • wrapper-2.0 (PID: 6242, Parent: 2063, MD5: ac0b8a906f359a8ae102244738682e76) Arguments: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libstatusnotifier.so 7 12582921 statusnotifier "Status Notifier Plugin" "Provides a panel area for status notifier items (application indicators)"
  • wrapper-2.0 (PID: 6243, Parent: 2063, MD5: ac0b8a906f359a8ae102244738682e76) Arguments: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libpulseaudio-plugin.so 8 12582922 pulseaudio "PulseAudio Plugin" "Adjust the audio volume of the PulseAudio sound system"
  • wrapper-2.0 (PID: 6244, Parent: 2063, MD5: ac0b8a906f359a8ae102244738682e76) Arguments: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libxfce4powermanager.so 9 12582923 power-manager-plugin "Power Manager Plugin" "Display the battery levels of your devices and control the brightness of your display"
  • wrapper-2.0 (PID: 6245, Parent: 2063, MD5: ac0b8a906f359a8ae102244738682e76) Arguments: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libactions.so 14 12582925 actions "Action Buttons" "Log out, lock or other system actions"
  • wrapper-2.0 (PID: 6246, Parent: 2063, MD5: ac0b8a906f359a8ae102244738682e76) Arguments: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libnotification-plugin.so 10 12582924 notification-plugin "Notification Plugin" "Notification plugin for the Xfce panel"
  • cleanup
No yara matches
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: b6.elfReversingLabs: Detection: 28%
Source: global trafficTCP traffic: 192.168.2.23:50418 -> 5.231.70.214:1252
Source: global trafficTCP traffic: 192.168.2.23:50425 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
Source: global trafficTCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
Source: global trafficTCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 5.231.70.214
Source: unknownTCP traffic detected without corresponding DNS query: 5.231.70.214
Source: unknownTCP traffic detected without corresponding DNS query: 5.231.70.214
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 5.231.70.214
Source: unknownTCP traffic detected without corresponding DNS query: 5.231.70.214
Source: b6.elf, 6239.1.00007ff158042000.00007ff158069000.rw-.sdmp, b6.elf, 6252.1.00007ff158042000.00007ff158069000.rw-.sdmpString found in binary or memory: http://1/wget.sh
Source: b6.elf, 6239.1.00007ff158042000.00007ff158069000.rw-.sdmp, b6.elf, 6252.1.00007ff158042000.00007ff158069000.rw-.sdmpString found in binary or memory: http://9/curl.sh
Source: b6.elf, 6252.1.00007ff158042000.00007ff158069000.rw-.sdmpString found in binary or memory: http://schemas.xmlsoap.org/soap/encoding/
Source: b6.elf, 6252.1.00007ff158042000.00007ff158069000.rw-.sdmpString found in binary or memory: http://schemas.xmlsoap.org/soap/envelope/
Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443

System Summary

barindex
Source: /tmp/b6.elf (PID: 6239)SIGKILL sent: pid: 2018, result: successfulJump to behavior
Source: /tmp/b6.elf (PID: 6239)SIGKILL sent: pid: 2077, result: successfulJump to behavior
Source: /tmp/b6.elf (PID: 6239)SIGKILL sent: pid: 2078, result: successfulJump to behavior
Source: /tmp/b6.elf (PID: 6239)SIGKILL sent: pid: 2079, result: successfulJump to behavior
Source: /tmp/b6.elf (PID: 6239)SIGKILL sent: pid: 2080, result: successfulJump to behavior
Source: /tmp/b6.elf (PID: 6239)SIGKILL sent: pid: 2083, result: successfulJump to behavior
Source: /tmp/b6.elf (PID: 6239)SIGKILL sent: pid: 2084, result: successfulJump to behavior
Source: /tmp/b6.elf (PID: 6239)SIGKILL sent: pid: 2156, result: successfulJump to behavior
Source: /tmp/b6.elf (PID: 6239)SIGKILL sent: pid: 6241, result: successfulJump to behavior
Source: /tmp/b6.elf (PID: 6239)SIGKILL sent: pid: 6242, result: successfulJump to behavior
Source: /tmp/b6.elf (PID: 6239)SIGKILL sent: pid: 6243, result: successfulJump to behavior
Source: /tmp/b6.elf (PID: 6239)SIGKILL sent: pid: 6244, result: successfulJump to behavior
Source: /tmp/b6.elf (PID: 6239)SIGKILL sent: pid: 6245, result: successfulJump to behavior
Source: /tmp/b6.elf (PID: 6239)SIGKILL sent: pid: 6246, result: successfulJump to behavior
Source: ELF static info symbol of initial sample.symtab present: no
Source: /tmp/b6.elf (PID: 6239)SIGKILL sent: pid: 2018, result: successfulJump to behavior
Source: /tmp/b6.elf (PID: 6239)SIGKILL sent: pid: 2077, result: successfulJump to behavior
Source: /tmp/b6.elf (PID: 6239)SIGKILL sent: pid: 2078, result: successfulJump to behavior
Source: /tmp/b6.elf (PID: 6239)SIGKILL sent: pid: 2079, result: successfulJump to behavior
Source: /tmp/b6.elf (PID: 6239)SIGKILL sent: pid: 2080, result: successfulJump to behavior
Source: /tmp/b6.elf (PID: 6239)SIGKILL sent: pid: 2083, result: successfulJump to behavior
Source: /tmp/b6.elf (PID: 6239)SIGKILL sent: pid: 2084, result: successfulJump to behavior
Source: /tmp/b6.elf (PID: 6239)SIGKILL sent: pid: 2156, result: successfulJump to behavior
Source: /tmp/b6.elf (PID: 6239)SIGKILL sent: pid: 6241, result: successfulJump to behavior
Source: /tmp/b6.elf (PID: 6239)SIGKILL sent: pid: 6242, result: successfulJump to behavior
Source: /tmp/b6.elf (PID: 6239)SIGKILL sent: pid: 6243, result: successfulJump to behavior
Source: /tmp/b6.elf (PID: 6239)SIGKILL sent: pid: 6244, result: successfulJump to behavior
Source: /tmp/b6.elf (PID: 6239)SIGKILL sent: pid: 6245, result: successfulJump to behavior
Source: /tmp/b6.elf (PID: 6239)SIGKILL sent: pid: 6246, result: successfulJump to behavior
Source: classification engineClassification label: mal52.spre.linELF@0/1@0/0
Source: /tmp/b6.elf (PID: 6264)File opened: /proc/1582/cmdlineJump to behavior
Source: /tmp/b6.elf (PID: 6264)File opened: /proc/1582/cmdlineJump to behavior
Source: /tmp/b6.elf (PID: 6264)File opened: /proc/1582/cmdlineJump to behavior
Source: /tmp/b6.elf (PID: 6264)File opened: /proc/1582/cmdlineJump to behavior
Source: /tmp/b6.elf (PID: 6264)File opened: /proc/1582/cmdlineJump to behavior
Source: /tmp/b6.elf (PID: 6264)File opened: /proc/2033/cmdlineJump to behavior
Source: /tmp/b6.elf (PID: 6264)File opened: /proc/2033/cmdlineJump to behavior
Source: /tmp/b6.elf (PID: 6264)File opened: /proc/2033/cmdlineJump to behavior
Source: /tmp/b6.elf (PID: 6264)File opened: /proc/2033/cmdlineJump to behavior
Source: /tmp/b6.elf (PID: 6264)File opened: /proc/2033/cmdlineJump to behavior
Source: /tmp/b6.elf (PID: 6264)File opened: /proc/2275/cmdlineJump to behavior
Source: /tmp/b6.elf (PID: 6264)File opened: /proc/2275/cmdlineJump to behavior
Source: /tmp/b6.elf (PID: 6264)File opened: /proc/2275/cmdlineJump to behavior
Source: /tmp/b6.elf (PID: 6264)File opened: /proc/2275/cmdlineJump to behavior
Source: /tmp/b6.elf (PID: 6264)File opened: /proc/2275/cmdlineJump to behavior
Source: /tmp/b6.elf (PID: 6264)File opened: /proc/6191/cmdlineJump to behavior
Source: /tmp/b6.elf (PID: 6264)File opened: /proc/6191/cmdlineJump to behavior
Source: /tmp/b6.elf (PID: 6264)File opened: /proc/6191/cmdlineJump to behavior
Source: /tmp/b6.elf (PID: 6264)File opened: /proc/6191/cmdlineJump to behavior
Source: /tmp/b6.elf (PID: 6264)File opened: /proc/1612/cmdlineJump to behavior
Source: /tmp/b6.elf (PID: 6264)File opened: /proc/1612/cmdlineJump to behavior
Source: /tmp/b6.elf (PID: 6264)File opened: /proc/1612/cmdlineJump to behavior
Source: /tmp/b6.elf (PID: 6264)File opened: /proc/1612/cmdlineJump to behavior
Source: /tmp/b6.elf (PID: 6264)File opened: /proc/1612/cmdlineJump to behavior
Source: /tmp/b6.elf (PID: 6264)File opened: /proc/1579/cmdlineJump to behavior
Source: /tmp/b6.elf (PID: 6264)File opened: /proc/1579/cmdlineJump to behavior
Source: /tmp/b6.elf (PID: 6264)File opened: /proc/1579/cmdlineJump to behavior
Source: /tmp/b6.elf (PID: 6264)File opened: /proc/1579/cmdlineJump to behavior
Source: /tmp/b6.elf (PID: 6264)File opened: /proc/1579/cmdlineJump to behavior
Source: /tmp/b6.elf (PID: 6264)File opened: /proc/1699/cmdlineJump to behavior
Source: /tmp/b6.elf (PID: 6264)File opened: /proc/1699/cmdlineJump to behavior
Source: /tmp/b6.elf (PID: 6264)File opened: /proc/1699/cmdlineJump to behavior
Source: /tmp/b6.elf (PID: 6264)File opened: /proc/1699/cmdlineJump to behavior
Source: /tmp/b6.elf (PID: 6264)File opened: /proc/1699/cmdlineJump to behavior
Source: /tmp/b6.elf (PID: 6264)File opened: /proc/1335/cmdlineJump to behavior
Source: /tmp/b6.elf (PID: 6264)File opened: /proc/1335/cmdlineJump to behavior
Source: /tmp/b6.elf (PID: 6264)File opened: /proc/1335/cmdlineJump to behavior
Source: /tmp/b6.elf (PID: 6264)File opened: /proc/1335/cmdlineJump to behavior
Source: /tmp/b6.elf (PID: 6264)File opened: /proc/1335/cmdlineJump to behavior
Source: /tmp/b6.elf (PID: 6264)File opened: /proc/1698/cmdlineJump to behavior
Source: /tmp/b6.elf (PID: 6264)File opened: /proc/1698/cmdlineJump to behavior
Source: /tmp/b6.elf (PID: 6264)File opened: /proc/1698/cmdlineJump to behavior
Source: /tmp/b6.elf (PID: 6264)File opened: /proc/1698/cmdlineJump to behavior
Source: /tmp/b6.elf (PID: 6264)File opened: /proc/1698/cmdlineJump to behavior
Source: /tmp/b6.elf (PID: 6264)File opened: /proc/2028/cmdlineJump to behavior
Source: /tmp/b6.elf (PID: 6264)File opened: /proc/2028/cmdlineJump to behavior
Source: /tmp/b6.elf (PID: 6264)File opened: /proc/2028/cmdlineJump to behavior
Source: /tmp/b6.elf (PID: 6264)File opened: /proc/2028/cmdlineJump to behavior
Source: /tmp/b6.elf (PID: 6264)File opened: /proc/2028/cmdlineJump to behavior
Source: /tmp/b6.elf (PID: 6264)File opened: /proc/1334/cmdlineJump to behavior
Source: /tmp/b6.elf (PID: 6264)File opened: /proc/1334/cmdlineJump to behavior
Source: /tmp/b6.elf (PID: 6264)File opened: /proc/1334/cmdlineJump to behavior
Source: /tmp/b6.elf (PID: 6264)File opened: /proc/1334/cmdlineJump to behavior
Source: /tmp/b6.elf (PID: 6264)File opened: /proc/1334/cmdlineJump to behavior
Source: /tmp/b6.elf (PID: 6264)File opened: /proc/1576/cmdlineJump to behavior
Source: /tmp/b6.elf (PID: 6264)File opened: /proc/1576/cmdlineJump to behavior
Source: /tmp/b6.elf (PID: 6264)File opened: /proc/1576/cmdlineJump to behavior
Source: /tmp/b6.elf (PID: 6264)File opened: /proc/1576/cmdlineJump to behavior
Source: /tmp/b6.elf (PID: 6264)File opened: /proc/1576/cmdlineJump to behavior
Source: /tmp/b6.elf (PID: 6264)File opened: /proc/2302/cmdlineJump to behavior
Source: /tmp/b6.elf (PID: 6264)File opened: /proc/2302/cmdlineJump to behavior
Source: /tmp/b6.elf (PID: 6264)File opened: /proc/2302/cmdlineJump to behavior
Source: /tmp/b6.elf (PID: 6264)File opened: /proc/2302/cmdlineJump to behavior
Source: /tmp/b6.elf (PID: 6264)File opened: /proc/2302/cmdlineJump to behavior
Source: /tmp/b6.elf (PID: 6264)File opened: /proc/3236/cmdlineJump to behavior
Source: /tmp/b6.elf (PID: 6264)File opened: /proc/3236/cmdlineJump to behavior
Source: /tmp/b6.elf (PID: 6264)File opened: /proc/3236/cmdlineJump to behavior
Source: /tmp/b6.elf (PID: 6264)File opened: /proc/3236/cmdlineJump to behavior
Source: /tmp/b6.elf (PID: 6264)File opened: /proc/3236/cmdlineJump to behavior
Source: /tmp/b6.elf (PID: 6264)File opened: /proc/2025/cmdlineJump to behavior
Source: /tmp/b6.elf (PID: 6264)File opened: /proc/2025/cmdlineJump to behavior
Source: /tmp/b6.elf (PID: 6264)File opened: /proc/2025/cmdlineJump to behavior
Source: /tmp/b6.elf (PID: 6264)File opened: /proc/2025/cmdlineJump to behavior
Source: /tmp/b6.elf (PID: 6264)File opened: /proc/2025/cmdlineJump to behavior
Source: /tmp/b6.elf (PID: 6264)File opened: /proc/2146/cmdlineJump to behavior
Source: /tmp/b6.elf (PID: 6264)File opened: /proc/2146/cmdlineJump to behavior
Source: /tmp/b6.elf (PID: 6264)File opened: /proc/2146/cmdlineJump to behavior
Source: /tmp/b6.elf (PID: 6264)File opened: /proc/2146/cmdlineJump to behavior
Source: /tmp/b6.elf (PID: 6264)File opened: /proc/2146/cmdlineJump to behavior
Source: /tmp/b6.elf (PID: 6264)File opened: /proc/912/cmdlineJump to behavior
Source: /tmp/b6.elf (PID: 6264)File opened: /proc/912/cmdlineJump to behavior
Source: /tmp/b6.elf (PID: 6264)File opened: /proc/912/cmdlineJump to behavior
Source: /tmp/b6.elf (PID: 6264)File opened: /proc/912/cmdlineJump to behavior
Source: /tmp/b6.elf (PID: 6264)File opened: /proc/912/cmdlineJump to behavior
Source: /tmp/b6.elf (PID: 6264)File opened: /proc/759/cmdlineJump to behavior
Source: /tmp/b6.elf (PID: 6264)File opened: /proc/759/cmdlineJump to behavior
Source: /tmp/b6.elf (PID: 6264)File opened: /proc/759/cmdlineJump to behavior
Source: /tmp/b6.elf (PID: 6264)File opened: /proc/759/cmdlineJump to behavior
Source: /tmp/b6.elf (PID: 6264)File opened: /proc/759/cmdlineJump to behavior
Source: /tmp/b6.elf (PID: 6264)File opened: /proc/2307/cmdlineJump to behavior
Source: /tmp/b6.elf (PID: 6264)File opened: /proc/2307/cmdlineJump to behavior
Source: /tmp/b6.elf (PID: 6264)File opened: /proc/2307/cmdlineJump to behavior
Source: /tmp/b6.elf (PID: 6264)File opened: /proc/2307/cmdlineJump to behavior
Source: /tmp/b6.elf (PID: 6264)File opened: /proc/2307/cmdlineJump to behavior
Source: /tmp/b6.elf (PID: 6264)File opened: /proc/918/cmdlineJump to behavior
Source: /tmp/b6.elf (PID: 6264)File opened: /proc/918/cmdlineJump to behavior
Source: /tmp/b6.elf (PID: 6264)File opened: /proc/918/cmdlineJump to behavior
Source: /tmp/b6.elf (PID: 6264)File opened: /proc/918/cmdlineJump to behavior
Source: /tmp/b6.elf (PID: 6264)File opened: /proc/918/cmdlineJump to behavior
Source: /tmp/b6.elf (PID: 6264)File opened: /proc/1594/cmdlineJump to behavior
Source: /tmp/b6.elf (PID: 6264)File opened: /proc/1594/cmdlineJump to behavior
Source: /tmp/b6.elf (PID: 6264)File opened: /proc/1594/cmdlineJump to behavior
Source: /tmp/b6.elf (PID: 6264)File opened: /proc/1594/cmdlineJump to behavior
Source: /tmp/b6.elf (PID: 6264)File opened: /proc/1594/cmdlineJump to behavior
Source: /tmp/b6.elf (PID: 6264)File opened: /proc/2285/cmdlineJump to behavior
Source: /tmp/b6.elf (PID: 6264)File opened: /proc/2285/cmdlineJump to behavior
Source: /tmp/b6.elf (PID: 6264)File opened: /proc/2285/cmdlineJump to behavior
Source: /tmp/b6.elf (PID: 6264)File opened: /proc/2285/cmdlineJump to behavior
Source: /tmp/b6.elf (PID: 6264)File opened: /proc/2285/cmdlineJump to behavior
Source: /usr/bin/dash (PID: 6205)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.NfV2IbpYCe /tmp/tmp.cl7u7Wzlp9 /tmp/tmp.weBqiO12zxJump to behavior
Source: /usr/bin/dash (PID: 6214)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.NfV2IbpYCe /tmp/tmp.cl7u7Wzlp9 /tmp/tmp.weBqiO12zxJump to behavior
Source: /tmp/b6.elf (PID: 6239)Reads from proc file: /proc/statJump to behavior
Source: /tmp/b6.elf (PID: 6239)Queries kernel information via 'uname': Jump to behavior
Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6241)Queries kernel information via 'uname': Jump to behavior
Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6242)Queries kernel information via 'uname': Jump to behavior
Source: b6.elf, 6239.1.000055bec39a5000.000055bec3af3000.rw-.sdmp, b6.elf, 6252.1.000055bec39a5000.000055bec3af3000.rw-.sdmpBinary or memory string: U!/etc/qemu-binfmt/arm
Source: b6.elf, 6239.1.00007fff8c54e000.00007fff8c56f000.rw-.sdmp, b6.elf, 6252.1.00007fff8c54e000.00007fff8c56f000.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-arm/tmp/b6.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/b6.elf
Source: b6.elf, 6239.1.000055bec39a5000.000055bec3af3000.rw-.sdmp, b6.elf, 6252.1.000055bec39a5000.000055bec3af3000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/arm
Source: b6.elf, 6239.1.00007fff8c54e000.00007fff8c56f000.rw-.sdmp, b6.elf, 6252.1.00007fff8c54e000.00007fff8c56f000.rw-.sdmpBinary or memory string: /usr/bin/qemu-arm
Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/42.0.2311.135 Safari/537.36 Edge/12.246
Source: Initial sampleUser agent string found: Mozilla/5.0 (X11; CrOS x86_64 8172.45.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.64 Safari/537.36
Source: Initial sampleUser agent string found: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_2) AppleWebKit/601.3.9 (KHTML, like Gecko) Version/9.0.2 Safari/601.3.9
Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/47.0.2526.111 Safari/537.36
Source: Initial sampleUser agent string found: Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:15.0) Gecko/20100101 Firefox/15.0.1
Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Safari/537.36
Source: Initial sampleUser agent string found: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Safari/537.36
Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:109.0) Gecko/20100101 Firefox/117.0
Source: Initial sampleUser agent string found: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
Source: Initial sampleUser agent string found: Mozilla/5.0 (X11; Linux x86_64; rv:109.0) Gecko/20100101 Firefox/117.0
Source: Initial sampleUser agent string found: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Safari/605.1.15
Source: Initial sampleUser agent string found: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Safari/537.36
Source: Initial sampleUser agent string found: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:109.0) Gecko/20100101 Firefox/117.0
Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:109.0) Gecko/20100101 Firefox/118.0
Source: Initial sampleUser agent string found: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
Source: Initial sampleUser agent string found: Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:109.0) Gecko/20100101 Firefox/117.0
Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 10.0; rv:109.0) Gecko/20100101 Firefox/117.0
Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Safari/537.36
Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Safari/537.36 Edg/116.0.1938.69
Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Safari/537.36 OPR/102.0.0.0
Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Safari/537.36 Edg/116.0.1938.76
Source: Initial sampleUser agent string found: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/115.0.0.0 Safari/537.36
Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36
Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36 Edg/117.0.2045.31
Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/115.0.0.0 Safari/537.36 OPR/101.0.0.0
Source: Initial sampleUser agent string found: Mozilla/5.0 (X11; Linux x86_64; rv:109.0) Gecko/20100101 Firefox/118.0
Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Safari/537.36 Edg/116.0.1938.81
Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/115.0.0.0 Safari/537.36
Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36 Edg/117.0.2045.36
Source: Initial sampleUser agent string found: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0 Safari/605.1.15
Source: Initial sampleUser agent string found: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/115.0.0.0 Safari/537.36
Source: Initial sampleUser agent string found: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:109.0) Gecko/20100101 Firefox/118.0
Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36 Edg/117.0.2045.43
Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:109.0) Gecko/20100101 Firefox/116.0
Source: Initial sampleUser agent string found: Mozilla/5.0 (X11; Linux x86_64; rv:102.0) Gecko/20100101 Firefox/102.0
Source: Initial sampleUser agent string found: Mozilla/5.0 (X11; Linux x86_64; rv:109.0) Gecko/20100101 Firefox/115.0
Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:109.0) Gecko/20100101 Firefox/115.0
Source: Initial sampleUser agent string found: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/77.0.3865.75 Safari/537.36
Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:109.0) Gecko/20100101 Firefox/115.0
Source: Initial sampleUser agent string found: Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:109.0) Gecko/20100101 Firefox/116.0
Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 10.0; rv:102.0) Gecko/20100101 Firefox/102.0
Source: Initial sampleUser agent string found: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36
Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/113.0.0.0 Safari/537.36
Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:102.0) Gecko/20100101 Firefox/102.0
Source: Initial sampleUser agent string found: Mozilla/5.0 (X11; Linux x86_64; rv:109.0) Gecko/20100101 Firefox/116.0
Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36 Edg/117.0.2045.41
Source: Initial sampleUser agent string found: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36
Source: Initial sampleUser agent string found: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:109.0) Gecko/20100101 Firefox/116.0
Source: Initial sampleUser agent string found: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.5.2 Safari/605.1.15
Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 10.0; rv:109.0) Gecko/20100101 Firefox/118.0
Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Safari/537.36 Edg/116.0.1938.62
Source: Initial sampleUser agent string found: Mozilla/5.0 (X11; CrOS x86_64 14541.0.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Safari/537.36
Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 YaBrowser/23.7.5.734 Yowser/2.5 Safari/537.36
Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) HeadlessChrome/117.0.0.0 Safari/537.36
Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Safari/537.36
Source: Initial sampleUser agent string found: Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:109.0) Gecko/20100101 Firefox/118.0
Source: Initial sampleUser agent string found: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.4 Safari/605.1.15
Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/112.0.0.0 Safari/537.36
Source: Initial sampleUser agent string found: Mozilla/5.0 (iPhone; CPU iPhone OS 16_0 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) CriOS/99.0.4844.47 Mobile/15E148 Safari/604.1
Source: Initial sampleUser agent string found: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.5 Safari/605.1.15
Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36 Edg/117.0.2045.47
Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 YaBrowser/23.7.4.971 Yowser/2.5 Safari/537.36
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception1
File Deletion
1
OS Credential Dumping
11
Security Software Discovery
Remote ServicesData from Local System1
Data Obfuscation
Exfiltration Over Other Network Medium1
Service Stop
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS Memory1
System Information Discovery
Remote Desktop ProtocolData from Removable Media1
Encrypted Channel
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
Non-Standard Port
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture1
Application Layer Protocol
Traffic DuplicationData Destruction
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1619037 Sample: b6.elf Startdate: 19/02/2025 Architecture: LINUX Score: 52 26 109.202.202.202, 80 INIT7CH Switzerland 2->26 28 1.1.1.1, 50425, 53 CLOUDFLARENETUS Australia 2->28 30 3 other IPs or domains 2->30 32 Multi AV Scanner detection for submitted file 2->32 9 dash rm b6.elf 2->9         started        12 dash rm 2->12         started        14 dash head 2->14         started        16 13 other processes 2->16 signatures3 process4 signatures5 34 Sample tries to kill multiple processes (SIGKILL) 9->34 18 b6.elf 9->18         started        process6 process7 20 b6.elf 18->20         started        process8 22 b6.elf 20->22         started        24 b6.elf 20->24         started       

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
b6.elf29%ReversingLabsLinux.Backdoor.Mirai
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
http://1/wget.sh0%Avira URL Cloudsafe
No contacted domains info
NameSourceMaliciousAntivirus DetectionReputation
http://1/wget.shb6.elf, 6239.1.00007ff158042000.00007ff158069000.rw-.sdmp, b6.elf, 6252.1.00007ff158042000.00007ff158069000.rw-.sdmpfalse
  • Avira URL Cloud: safe
unknown
http://schemas.xmlsoap.org/soap/encoding/b6.elf, 6252.1.00007ff158042000.00007ff158069000.rw-.sdmpfalse
    high
    http://9/curl.shb6.elf, 6239.1.00007ff158042000.00007ff158069000.rw-.sdmp, b6.elf, 6252.1.00007ff158042000.00007ff158069000.rw-.sdmpfalse
      high
      http://schemas.xmlsoap.org/soap/envelope/b6.elf, 6252.1.00007ff158042000.00007ff158069000.rw-.sdmpfalse
        high
        • No. of IPs < 25%
        • 25% < No. of IPs < 50%
        • 50% < No. of IPs < 75%
        • 75% < No. of IPs
        IPDomainCountryFlagASNASN NameMalicious
        5.231.70.214
        unknownGermany
        12586ASGHOSTNETDEfalse
        1.1.1.1
        unknownAustralia
        13335CLOUDFLARENETUSfalse
        109.202.202.202
        unknownSwitzerland
        13030INIT7CHfalse
        91.189.91.43
        unknownUnited Kingdom
        41231CANONICAL-ASGBfalse
        91.189.91.42
        unknownUnited Kingdom
        41231CANONICAL-ASGBfalse
        MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
        5.231.70.214b3.elfGet hashmaliciousUnknownBrowse
          b2.elfGet hashmaliciousUnknownBrowse
            b1.elfGet hashmaliciousUnknownBrowse
              b3.elfGet hashmaliciousUnknownBrowse
                b1.elfGet hashmaliciousUnknownBrowse
                  b3.elfGet hashmaliciousUnknownBrowse
                    b1.elfGet hashmaliciousUnknownBrowse
                      b2.elfGet hashmaliciousUnknownBrowse
                        b2.elfGet hashmaliciousUnknownBrowse
                          b2.elfGet hashmaliciousUnknownBrowse
                            1.1.1.1watchdog.elfGet hashmaliciousXmrigBrowse
                            • 1.1.1.1:8080/
                            6fW0GedR6j.xlsGet hashmaliciousUnknownBrowse
                            • 1.1.1.1/ctrl/playback.php
                            PO-230821_pdf.exeGet hashmaliciousFormBook, NSISDropperBrowse
                            • www.974dp.com/sn26/?kJBLpb8=qaEGeuQorcUQurUZCuE8d9pas+Z0M0brqtX248JBolEfq8j8F1R9i1jKZexhxY54UlRG&ML0tl=NZlpi
                            AFfv8HpACF.exeGet hashmaliciousUnknownBrowse
                            • 1.1.1.1/
                            109.202.202.202kpLwzBouH4.elfGet hashmaliciousUnknownBrowse
                            • ch.archive.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_92.0%2bbuild3-0ubuntu0.20.04.1_amd64.deb
                            No context
                            MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                            CLOUDFLARENETUSb3.elfGet hashmaliciousUnknownBrowse
                            • 1.1.1.1
                            b2.elfGet hashmaliciousUnknownBrowse
                            • 1.1.1.1
                            b1.elfGet hashmaliciousUnknownBrowse
                            • 1.1.1.1
                            https://malvinasrock.com/%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%202/Get hashmaliciousHTMLPhisherBrowse
                            • 104.21.27.125
                            https://app.powerbi.com/view?r=eyJrIjoiZmVlZTQ2MzYtNjAyNC00NmIzLTljNjYtYmI2NDA2NjgzYTBkIiwidCI6IjcxOGNiYTc5LTYzNTAtNDMyZS04YjYwLTk2MDFiM2VhNDNiYSJ9Get hashmaliciousEvilProxy, HTMLPhisherBrowse
                            • 172.67.74.152
                            https://app.powerbi.com/view?r=eyJrIjoiZmVlZTQ2MzYtNjAyNC00NmIzLTljNjYtYmI2NDA2NjgzYTBkIiwidCI6IjcxOGNiYTc5LTYzNTAtNDMyZS04YjYwLTk2MDFiM2VhNDNiYSJ9Get hashmaliciousEvilProxy, HTMLPhisherBrowse
                            • 104.26.13.205
                            Order confirmation.exeGet hashmaliciousFormBookBrowse
                            • 104.21.16.1
                            https://app.powerbi.com/view?r=eyJrIjoiZmVlZTQ2MzYtNjAyNC00NmIzLTljNjYtYmI2NDA2NjgzYTBkIiwidCI6IjcxOGNiYTc5LTYzNTAtNDMyZS04YjYwLTk2MDFiM2VhNDNiYSJ9Get hashmaliciousEvilProxy, HTMLPhisherBrowse
                            • 172.67.74.152
                            https://app.powerbi.com/view?r=eyJrIjoiZmVlZTQ2MzYtNjAyNC00NmIzLTljNjYtYmI2NDA2NjgzYTBkIiwidCI6IjcxOGNiYTc5LTYzNTAtNDMyZS04YjYwLTk2MDFiM2VhNDNiYSJ9Get hashmaliciousHTMLPhisherBrowse
                            • 188.114.97.3
                            http://deletion.docx.zip/Get hashmaliciousUnknownBrowse
                            • 1.1.1.1
                            CANONICAL-ASGBb3.elfGet hashmaliciousUnknownBrowse
                            • 91.189.91.42
                            b2.elfGet hashmaliciousUnknownBrowse
                            • 185.125.190.26
                            b1.elfGet hashmaliciousUnknownBrowse
                            • 91.189.91.42
                            na.elfGet hashmaliciousPrometeiBrowse
                            • 91.189.91.42
                            Seconddate_CnC.elfGet hashmaliciousUnknownBrowse
                            • 91.189.91.42
                            na.elfGet hashmaliciousPrometeiBrowse
                            • 91.189.91.42
                            na.elfGet hashmaliciousPrometeiBrowse
                            • 91.189.91.42
                            .i.elfGet hashmaliciousUnknownBrowse
                            • 91.189.91.42
                            na.elfGet hashmaliciousPrometeiBrowse
                            • 91.189.91.42
                            na.elfGet hashmaliciousPrometeiBrowse
                            • 91.189.91.42
                            ASGHOSTNETDEb3.elfGet hashmaliciousUnknownBrowse
                            • 5.231.70.214
                            b2.elfGet hashmaliciousUnknownBrowse
                            • 5.231.70.214
                            b1.elfGet hashmaliciousUnknownBrowse
                            • 5.231.70.214
                            SFT20020117.exeGet hashmaliciousFormBookBrowse
                            • 5.83.145.167
                            QUOTATION REQUEST.exeGet hashmaliciousFormBookBrowse
                            • 5.83.145.167
                            res.mips.elfGet hashmaliciousUnknownBrowse
                            • 89.144.41.136
                            UPDATED SOA.pdf.exeGet hashmaliciousFormBookBrowse
                            • 5.83.145.167
                            SFT20020117.exeGet hashmaliciousFormBookBrowse
                            • 5.83.145.167
                            oHMjowwwKG.exeGet hashmaliciousUnknownBrowse
                            • 77.90.38.170
                            biFR2LEnQo.exeGet hashmaliciousUnknownBrowse
                            • 77.90.38.170
                            INIT7CHb3.elfGet hashmaliciousUnknownBrowse
                            • 109.202.202.202
                            b1.elfGet hashmaliciousUnknownBrowse
                            • 109.202.202.202
                            na.elfGet hashmaliciousPrometeiBrowse
                            • 109.202.202.202
                            Seconddate_CnC.elfGet hashmaliciousUnknownBrowse
                            • 109.202.202.202
                            na.elfGet hashmaliciousPrometeiBrowse
                            • 109.202.202.202
                            na.elfGet hashmaliciousPrometeiBrowse
                            • 109.202.202.202
                            .i.elfGet hashmaliciousUnknownBrowse
                            • 109.202.202.202
                            na.elfGet hashmaliciousPrometeiBrowse
                            • 109.202.202.202
                            na.elfGet hashmaliciousPrometeiBrowse
                            • 109.202.202.202
                            na.elfGet hashmaliciousPrometeiBrowse
                            • 109.202.202.202
                            No context
                            No context
                            Process:/tmp/b6.elf
                            File Type:zlib compressed data
                            Category:dropped
                            Size (bytes):259
                            Entropy (8bit):3.4029149832095573
                            Encrypted:false
                            SSDEEP:6:ngDFp/T/VYDFp5zUT/VjmsVot/VOArB/VF:nY7/q75zZ/
                            MD5:99F1F45AE2892F743F00AB58B6C2243C
                            SHA1:CF52B256D46FA648DD8250C90EB475FA3584388C
                            SHA-256:E5F891619A1C5BBB0696CCD03561E9CCDCA03EE98E1A27C0AA31F3E371D506E5
                            SHA-512:3B685FB81977E1AEBFCCDB8C6C431971153DDE30CA6A2C97EA15759B2A974FF87B06B939228E4FF3AD91BB63DFD12434C113792F931F20380BA2AC20430C1212
                            Malicious:false
                            Reputation:low
                            Preview:8000-2b000 r-xp 00000000 fd:00 531606 /tmp/b6.elf.32000-33000 rw-p 00022000 fd:00 531606 /tmp/b6.elf.33000-5a000 rw-p 00000000 00:00 0 .ff7ef000-ff7f0000 ---p 00000000 00:00 0 .ff7f0000-ffff0000 rw-p 00000000 00:00 0 [stack]..
                            File type:ELF 32-bit LSB executable, ARM, EABI4 version 1 (SYSV), statically linked, stripped
                            Entropy (8bit):6.167171103603247
                            TrID:
                            • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                            File name:b6.elf
                            File size:141'704 bytes
                            MD5:6c5f331d84d27c0a8f5f03f4d637c33a
                            SHA1:df387bcab281fd8a83cdeb25d05bf4aaabb50ec0
                            SHA256:bf5c0277928a3045128cddcc086508b33b65e07c36b944ae894c6f15be29f175
                            SHA512:da2a48c373ae16d9dbf3f57077b1a81b4057f94b120f749e1e12f7713c6cbe4e6f0bcf161edf7512bcb562f2d242f35fc6b02efff83871ba111dfbf96fd669de
                            SSDEEP:3072:LwKE3PRTAzpOaSjB0kO2keESamFkPU/w03H:oJAzpKSCESamFyUI0
                            TLSH:56D3D449E9546B2CC3F176FFFA4812CE723B0BA9B3E63022DE32061537C9B1A5935564
                            File Content Preview:.ELF..............(.........4....'......4. ...(........p............(...(............................ ... ............... ... ... ......@................ ... ... ..................Q.td..................................-...L..................G.F.G.F.G.F.G.

                            ELF header

                            Class:ELF32
                            Data:2's complement, little endian
                            Version:1 (current)
                            Machine:ARM
                            Version Number:0x1
                            Type:EXEC (Executable file)
                            OS/ABI:UNIX - System V
                            ABI Version:0
                            Entry Point Address:0x81d0
                            Flags:0x4000002
                            ELF Header Size:52
                            Program Header Offset:52
                            Program Header Size:32
                            Number of Program Headers:5
                            Section Header Offset:141064
                            Section Header Size:40
                            Number of Section Headers:16
                            Header String Table Index:15
                            NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                            NULL0x00x00x00x00x0000
                            .initPROGBITS0x80d40xd40x100x00x6AX004
                            .textPROGBITS0x80f00xf00x1d89c0x00x6AX0016
                            .finiPROGBITS0x2598c0x1d98c0x100x00x6AX004
                            .rodataPROGBITS0x2599c0x1d99c0x46100x00x2A004
                            .ARM.extabPROGBITS0x29fac0x21fac0x180x00x2A004
                            .ARM.exidxARM_EXIDX0x29fc40x21fc40x1280x00x82AL204
                            .eh_framePROGBITS0x320ec0x220ec0x40x00x3WA004
                            .tbssNOBITS0x320f00x220f00x80x00x403WAT004
                            .init_arrayINIT_ARRAY0x320f00x220f00x40x00x3WA004
                            .fini_arrayFINI_ARRAY0x320f40x220f40x40x00x3WA004
                            .gotPROGBITS0x320fc0x220fc0xac0x40x3WA004
                            .dataPROGBITS0x321a80x221a80x4c40x00x3WA004
                            .bssNOBITS0x3266c0x2266c0x228c00x00x3WA004
                            .ARM.attributesARM_ATTRIBUTES0x00x2266c0x160x00x0001
                            .shstrtabSTRTAB0x00x226820x830x00x0001
                            TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                            EXIDX0x21fc40x29fc40x29fc40x1280x1284.52740x4R 0x4.ARM.exidx
                            LOAD0x00x80000x80000x220ec0x220ec6.16410x5R E0x8000.init .text .fini .rodata .ARM.extab .ARM.exidx
                            LOAD0x220ec0x320ec0x320ec0x5800x22e406.08920x6RW 0x8000.eh_frame .tbss .init_array .fini_array .got .data .bss
                            TLS0x220f00x320f00x320f00x00x80.00000x4R 0x4.tbss
                            GNU_STACK0x00x00x00x00x00.00000x7RWE0x4
                            TimestampSource PortDest PortSource IPDest IP
                            Feb 19, 2025 14:13:03.593585014 CET43928443192.168.2.2391.189.91.42
                            Feb 19, 2025 14:13:08.968938112 CET42836443192.168.2.2391.189.91.43
                            Feb 19, 2025 14:13:09.992650032 CET4251680192.168.2.23109.202.202.202
                            Feb 19, 2025 14:13:12.691847086 CET5042553192.168.2.231.1.1.1
                            Feb 19, 2025 14:13:12.700087070 CET53504251.1.1.1192.168.2.23
                            Feb 19, 2025 14:13:12.700298071 CET5042553192.168.2.231.1.1.1
                            Feb 19, 2025 14:13:12.700336933 CET5042553192.168.2.231.1.1.1
                            Feb 19, 2025 14:13:12.708153963 CET53504251.1.1.1192.168.2.23
                            Feb 19, 2025 14:13:12.708268881 CET5042553192.168.2.231.1.1.1
                            Feb 19, 2025 14:13:12.939352036 CET504181252192.168.2.235.231.70.214
                            Feb 19, 2025 14:13:12.944464922 CET1252504185.231.70.214192.168.2.23
                            Feb 19, 2025 14:13:12.944519997 CET504181252192.168.2.235.231.70.214
                            Feb 19, 2025 14:13:12.948367119 CET504181252192.168.2.235.231.70.214
                            Feb 19, 2025 14:13:12.953386068 CET1252504185.231.70.214192.168.2.23
                            Feb 19, 2025 14:13:23.814780951 CET43928443192.168.2.2391.189.91.42
                            Feb 19, 2025 14:13:36.100944996 CET42836443192.168.2.2391.189.91.43
                            Feb 19, 2025 14:13:40.196382046 CET4251680192.168.2.23109.202.202.202
                            Feb 19, 2025 14:14:04.769068956 CET43928443192.168.2.2391.189.91.42
                            Feb 19, 2025 14:14:22.990454912 CET504181252192.168.2.235.231.70.214
                            Feb 19, 2025 14:14:22.995590925 CET1252504185.231.70.214192.168.2.23
                            Feb 19, 2025 14:14:23.170209885 CET1252504185.231.70.214192.168.2.23
                            Feb 19, 2025 14:14:23.170311928 CET504181252192.168.2.235.231.70.214

                            System Behavior

                            Start time (UTC):13:12:58
                            Start date (UTC):19/02/2025
                            Path:/usr/bin/dash
                            Arguments:-
                            File size:129816 bytes
                            MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                            Start time (UTC):13:12:58
                            Start date (UTC):19/02/2025
                            Path:/usr/bin/rm
                            Arguments:rm -f /tmp/tmp.NfV2IbpYCe /tmp/tmp.cl7u7Wzlp9 /tmp/tmp.weBqiO12zx
                            File size:72056 bytes
                            MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b

                            Start time (UTC):13:12:58
                            Start date (UTC):19/02/2025
                            Path:/usr/bin/dash
                            Arguments:-
                            File size:129816 bytes
                            MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                            Start time (UTC):13:12:58
                            Start date (UTC):19/02/2025
                            Path:/usr/bin/cat
                            Arguments:cat /tmp/tmp.NfV2IbpYCe
                            File size:43416 bytes
                            MD5 hash:7e9d213e404ad3bb82e4ebb2e1f2c1b3

                            Start time (UTC):13:12:58
                            Start date (UTC):19/02/2025
                            Path:/usr/bin/dash
                            Arguments:-
                            File size:129816 bytes
                            MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                            Start time (UTC):13:12:58
                            Start date (UTC):19/02/2025
                            Path:/usr/bin/head
                            Arguments:head -n 10
                            File size:47480 bytes
                            MD5 hash:fd96a67145172477dd57131396fc9608

                            Start time (UTC):13:12:58
                            Start date (UTC):19/02/2025
                            Path:/usr/bin/dash
                            Arguments:-
                            File size:129816 bytes
                            MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                            Start time (UTC):13:12:58
                            Start date (UTC):19/02/2025
                            Path:/usr/bin/tr
                            Arguments:tr -d \\000-\\011\\013\\014\\016-\\037
                            File size:51544 bytes
                            MD5 hash:fbd1402dd9f72d8ebfff00ce7c3a7bb5

                            Start time (UTC):13:12:58
                            Start date (UTC):19/02/2025
                            Path:/usr/bin/dash
                            Arguments:-
                            File size:129816 bytes
                            MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                            Start time (UTC):13:12:58
                            Start date (UTC):19/02/2025
                            Path:/usr/bin/cut
                            Arguments:cut -c -80
                            File size:47480 bytes
                            MD5 hash:d8ed0ea8f22c0de0f8692d4d9f1759d3

                            Start time (UTC):13:12:58
                            Start date (UTC):19/02/2025
                            Path:/usr/bin/dash
                            Arguments:-
                            File size:129816 bytes
                            MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                            Start time (UTC):13:12:58
                            Start date (UTC):19/02/2025
                            Path:/usr/bin/cat
                            Arguments:cat /tmp/tmp.NfV2IbpYCe
                            File size:43416 bytes
                            MD5 hash:7e9d213e404ad3bb82e4ebb2e1f2c1b3

                            Start time (UTC):13:12:58
                            Start date (UTC):19/02/2025
                            Path:/usr/bin/dash
                            Arguments:-
                            File size:129816 bytes
                            MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                            Start time (UTC):13:12:58
                            Start date (UTC):19/02/2025
                            Path:/usr/bin/head
                            Arguments:head -n 10
                            File size:47480 bytes
                            MD5 hash:fd96a67145172477dd57131396fc9608

                            Start time (UTC):13:12:58
                            Start date (UTC):19/02/2025
                            Path:/usr/bin/dash
                            Arguments:-
                            File size:129816 bytes
                            MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                            Start time (UTC):13:12:58
                            Start date (UTC):19/02/2025
                            Path:/usr/bin/tr
                            Arguments:tr -d \\000-\\011\\013\\014\\016-\\037
                            File size:51544 bytes
                            MD5 hash:fbd1402dd9f72d8ebfff00ce7c3a7bb5

                            Start time (UTC):13:12:58
                            Start date (UTC):19/02/2025
                            Path:/usr/bin/dash
                            Arguments:-
                            File size:129816 bytes
                            MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                            Start time (UTC):13:12:58
                            Start date (UTC):19/02/2025
                            Path:/usr/bin/cut
                            Arguments:cut -c -80
                            File size:47480 bytes
                            MD5 hash:d8ed0ea8f22c0de0f8692d4d9f1759d3

                            Start time (UTC):13:12:59
                            Start date (UTC):19/02/2025
                            Path:/usr/bin/dash
                            Arguments:-
                            File size:129816 bytes
                            MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                            Start time (UTC):13:12:59
                            Start date (UTC):19/02/2025
                            Path:/usr/bin/rm
                            Arguments:rm -f /tmp/tmp.NfV2IbpYCe /tmp/tmp.cl7u7Wzlp9 /tmp/tmp.weBqiO12zx
                            File size:72056 bytes
                            MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b

                            Start time (UTC):13:13:03
                            Start date (UTC):19/02/2025
                            Path:/tmp/b6.elf
                            Arguments:/tmp/b6.elf
                            File size:4956856 bytes
                            MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                            Start time (UTC):13:13:11
                            Start date (UTC):19/02/2025
                            Path:/tmp/b6.elf
                            Arguments:-
                            File size:4956856 bytes
                            MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                            Start time (UTC):13:13:11
                            Start date (UTC):19/02/2025
                            Path:/tmp/b6.elf
                            Arguments:-
                            File size:4956856 bytes
                            MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                            Start time (UTC):13:13:11
                            Start date (UTC):19/02/2025
                            Path:/tmp/b6.elf
                            Arguments:-
                            File size:4956856 bytes
                            MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                            Start time (UTC):13:13:11
                            Start date (UTC):19/02/2025
                            Path:/tmp/b6.elf
                            Arguments:-
                            File size:4956856 bytes
                            MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                            Start time (UTC):13:13:04
                            Start date (UTC):19/02/2025
                            Path:/usr/bin/xfce4-panel
                            Arguments:-
                            File size:375768 bytes
                            MD5 hash:a15b657c7d54ac1385f1f15004ea6784

                            Start time (UTC):13:13:04
                            Start date (UTC):19/02/2025
                            Path:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
                            Arguments:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libsystray.so 6 12582920 systray "Notification Area" "Area where notification icons appear"
                            File size:35136 bytes
                            MD5 hash:ac0b8a906f359a8ae102244738682e76

                            Start time (UTC):13:13:04
                            Start date (UTC):19/02/2025
                            Path:/usr/bin/xfce4-panel
                            Arguments:-
                            File size:375768 bytes
                            MD5 hash:a15b657c7d54ac1385f1f15004ea6784

                            Start time (UTC):13:13:04
                            Start date (UTC):19/02/2025
                            Path:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
                            Arguments:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libstatusnotifier.so 7 12582921 statusnotifier "Status Notifier Plugin" "Provides a panel area for status notifier items (application indicators)"
                            File size:35136 bytes
                            MD5 hash:ac0b8a906f359a8ae102244738682e76

                            Start time (UTC):13:13:04
                            Start date (UTC):19/02/2025
                            Path:/usr/bin/xfce4-panel
                            Arguments:-
                            File size:375768 bytes
                            MD5 hash:a15b657c7d54ac1385f1f15004ea6784

                            Start time (UTC):13:13:04
                            Start date (UTC):19/02/2025
                            Path:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
                            Arguments:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libpulseaudio-plugin.so 8 12582922 pulseaudio "PulseAudio Plugin" "Adjust the audio volume of the PulseAudio sound system"
                            File size:35136 bytes
                            MD5 hash:ac0b8a906f359a8ae102244738682e76

                            Start time (UTC):13:13:04
                            Start date (UTC):19/02/2025
                            Path:/usr/bin/xfce4-panel
                            Arguments:-
                            File size:375768 bytes
                            MD5 hash:a15b657c7d54ac1385f1f15004ea6784

                            Start time (UTC):13:13:04
                            Start date (UTC):19/02/2025
                            Path:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
                            Arguments:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libxfce4powermanager.so 9 12582923 power-manager-plugin "Power Manager Plugin" "Display the battery levels of your devices and control the brightness of your display"
                            File size:35136 bytes
                            MD5 hash:ac0b8a906f359a8ae102244738682e76

                            Start time (UTC):13:13:04
                            Start date (UTC):19/02/2025
                            Path:/usr/bin/xfce4-panel
                            Arguments:-
                            File size:375768 bytes
                            MD5 hash:a15b657c7d54ac1385f1f15004ea6784

                            Start time (UTC):13:13:04
                            Start date (UTC):19/02/2025
                            Path:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
                            Arguments:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libactions.so 14 12582925 actions "Action Buttons" "Log out, lock or other system actions"
                            File size:35136 bytes
                            MD5 hash:ac0b8a906f359a8ae102244738682e76

                            Start time (UTC):13:13:04
                            Start date (UTC):19/02/2025
                            Path:/usr/bin/xfce4-panel
                            Arguments:-
                            File size:375768 bytes
                            MD5 hash:a15b657c7d54ac1385f1f15004ea6784

                            Start time (UTC):13:13:04
                            Start date (UTC):19/02/2025
                            Path:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
                            Arguments:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libnotification-plugin.so 10 12582924 notification-plugin "Notification Plugin" "Notification plugin for the Xfce panel"
                            File size:35136 bytes
                            MD5 hash:ac0b8a906f359a8ae102244738682e76