Loading ...

Play interactive tourEdit tour

Linux Analysis Report mirkatclpb.arm

Overview

General Information

Sample Name:mirkatclpb.arm
Analysis ID:491830
MD5:f11d4deb3dc156310b53b21e22c5663a
SHA1:f785ac4c47b99459a8ce236aa76df115af76dd7f
SHA256:64e0601e1a0a1bb7f8f170ea14efa55b1f17aaefad94edf0b96cfdbebeb689e8
Infos:

Most interesting Screenshot:

Detection

Mirai
Score:68
Range:0 - 100
Whitelisted:false

Signatures

Snort IDS alert for network traffic (e.g. based on Emerging Threat rules)
Yara detected Mirai
Sample is packed with UPX
Uses known network protocols on non-standard ports
Sample tries to kill many processes (SIGKILL)
Sample contains only a LOAD segment without any section mappings
Uses the "uname" system call to query kernel version information (possible evasion)
Enumerates processes within the "proc" file system
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Detected TCP or UDP traffic on non-standard ports
Sample listens on a socket
Sample tries to kill a process (SIGKILL)

Classification

Analysis Advice

Static ELF header machine description suggests that the sample might only run correctly on MIPS or ARM architectures
All HTTP servers contacted by the sample do not answer. Likely the sample is an old dropper which does no longer work
Static ELF header machine description suggests that the sample might not execute correctly on this machine

General Information

Joe Sandbox Version:33.0.0 White Diamond
Analysis ID:491830
Start date:27.09.2021
Start time:23:50:38
Joe Sandbox Product:CloudBasic
Overall analysis duration:0h 7m 35s
Hypervisor based Inspection enabled:false
Report type:light
Sample file name:mirkatclpb.arm
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Detection:MAL
Classification:mal68.spre.troj.evad.linARM@0/6@0/0
Warnings:
Show All
  • Report size exceeded maximum capacity and may have missing network information.
  • TCP Packets have been reduced to 100
  • VT rate limit hit for: /opt/package/joesandbox/database/analysis/491830/sample/mirkatclpb.arm

Process Tree

  • system is lnxubuntu20
  • systemd New Fork (PID: 5261, Parent: 1)
  • sshd (PID: 5261, Parent: 1, MD5: dbca7a6bbf7bf57fedac243d4b2cb340) Arguments: /usr/sbin/sshd -t
  • systemd New Fork (PID: 5262, Parent: 1)
  • sshd (PID: 5262, Parent: 1, MD5: dbca7a6bbf7bf57fedac243d4b2cb340) Arguments: /usr/sbin/sshd -D
  • systemd New Fork (PID: 5356, Parent: 1)
  • sshd (PID: 5356, Parent: 1, MD5: dbca7a6bbf7bf57fedac243d4b2cb340) Arguments: /usr/sbin/sshd -t
  • systemd New Fork (PID: 5357, Parent: 1)
  • sshd (PID: 5357, Parent: 1, MD5: dbca7a6bbf7bf57fedac243d4b2cb340) Arguments: /usr/sbin/sshd -D
  • systemd New Fork (PID: 5358, Parent: 1)
  • sshd (PID: 5358, Parent: 1, MD5: dbca7a6bbf7bf57fedac243d4b2cb340) Arguments: /usr/sbin/sshd -t
  • systemd New Fork (PID: 5359, Parent: 1)
  • sshd (PID: 5359, Parent: 1, MD5: dbca7a6bbf7bf57fedac243d4b2cb340) Arguments: /usr/sbin/sshd -D
  • cleanup

Yara Overview

PCAP (Network Traffic)

SourceRuleDescriptionAuthorStrings
dump.pcapJoeSecurity_Mirai_12Yara detected MiraiJoe Security

    Jbx Signature Overview

    Click to jump to signature section

    Show All Signature Results

    Networking:

    barindex
    Snort IDS alert for network traffic (e.g. based on Emerging Threat rules)Show sources
    Source: TrafficSnort IDS: 716 INFO TELNET access 222.254.23.45:23 -> 192.168.2.23:34420
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 186.65.67.208:23 -> 192.168.2.23:46262
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 186.65.67.208:23 -> 192.168.2.23:46262
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 37.122.159.153:23 -> 192.168.2.23:50944
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 37.122.159.153:23 -> 192.168.2.23:50944
    Source: TrafficSnort IDS: 716 INFO TELNET access 222.254.23.45:23 -> 192.168.2.23:34516
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 37.122.159.153:23 -> 192.168.2.23:51036
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 37.122.159.153:23 -> 192.168.2.23:51036
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 37.122.159.153:23 -> 192.168.2.23:51094
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 37.122.159.153:23 -> 192.168.2.23:51094
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 37.122.159.153:23 -> 192.168.2.23:51138
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 37.122.159.153:23 -> 192.168.2.23:51138
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 190.186.58.151:23 -> 192.168.2.23:54810
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 190.186.58.151:23 -> 192.168.2.23:54810
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 186.65.67.208:23 -> 192.168.2.23:46488
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 186.65.67.208:23 -> 192.168.2.23:46488
    Source: TrafficSnort IDS: 716 INFO TELNET access 222.254.23.45:23 -> 192.168.2.23:34680
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 216.123.70.174:23 -> 192.168.2.23:34200
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 216.123.70.174:23 -> 192.168.2.23:34200
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 190.186.58.151:23 -> 192.168.2.23:54824
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 190.186.58.151:23 -> 192.168.2.23:54824
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 37.122.159.153:23 -> 192.168.2.23:51182
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 37.122.159.153:23 -> 192.168.2.23:51182
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 190.186.58.151:23 -> 192.168.2.23:54842
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 190.186.58.151:23 -> 192.168.2.23:54842
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 190.186.58.151:23 -> 192.168.2.23:54864
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 190.186.58.151:23 -> 192.168.2.23:54864
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 190.186.58.151:23 -> 192.168.2.23:54870
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 190.186.58.151:23 -> 192.168.2.23:54870
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 37.122.159.153:23 -> 192.168.2.23:51216
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 37.122.159.153:23 -> 192.168.2.23:51216
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 190.186.58.151:23 -> 192.168.2.23:54874
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 190.186.58.151:23 -> 192.168.2.23:54874
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 190.186.58.151:23 -> 192.168.2.23:54900
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 190.186.58.151:23 -> 192.168.2.23:54900
    Source: TrafficSnort IDS: 2023434 ET TROJAN Possible Linux.Mirai Login Attempt (7ujMko0vizxv) 192.168.2.23:41368 -> 81.136.190.29:23
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 37.122.159.153:23 -> 192.168.2.23:51244
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 37.122.159.153:23 -> 192.168.2.23:51244
    Source: TrafficSnort IDS: 2023434 ET TROJAN Possible Linux.Mirai Login Attempt (7ujMko0vizxv) 192.168.2.23:41376 -> 81.136.190.29:23
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 190.186.58.151:23 -> 192.168.2.23:54930
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 190.186.58.151:23 -> 192.168.2.23:54930
    Source: TrafficSnort IDS: 716 INFO TELNET access 222.254.23.45:23 -> 192.168.2.23:34798
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 82.166.85.146:23 -> 192.168.2.23:38080
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 82.166.85.146:23 -> 192.168.2.23:38080
    Source: TrafficSnort IDS: 2023443 ET TROJAN Possible Linux.Mirai Login Attempt (klv123) 192.168.2.23:41416 -> 81.136.190.29:23
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 190.186.58.151:23 -> 192.168.2.23:54954
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 190.186.58.151:23 -> 192.168.2.23:54954
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 216.123.70.174:23 -> 192.168.2.23:34346
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 216.123.70.174:23 -> 192.168.2.23:34346
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 37.122.159.153:23 -> 192.168.2.23:51308
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 37.122.159.153:23 -> 192.168.2.23:51308
    Source: TrafficSnort IDS: 2023449 ET TROJAN Possible Linux.Mirai Login Attempt (vizxv) 192.168.2.23:41442 -> 81.136.190.29:23
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 186.65.67.208:23 -> 192.168.2.23:46644
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 186.65.67.208:23 -> 192.168.2.23:46644
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 190.186.58.151:23 -> 192.168.2.23:54986
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 190.186.58.151:23 -> 192.168.2.23:54986
    Source: TrafficSnort IDS: 2023448 ET TROJAN Possible Linux.Mirai Login Attempt (ubnt) 192.168.2.23:41458 -> 81.136.190.29:23
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 82.166.85.146:23 -> 192.168.2.23:38130
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 82.166.85.146:23 -> 192.168.2.23:38130
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 37.122.159.153:23 -> 192.168.2.23:51350
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 37.122.159.153:23 -> 192.168.2.23:51350
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 82.166.85.146:23 -> 192.168.2.23:38146
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 82.166.85.146:23 -> 192.168.2.23:38146
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 37.122.159.153:23 -> 192.168.2.23:51366
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 37.122.159.153:23 -> 192.168.2.23:51366
    Source: TrafficSnort IDS: 716 INFO TELNET access 222.254.23.45:23 -> 192.168.2.23:34904
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 82.166.85.146:23 -> 192.168.2.23:38188
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 82.166.85.146:23 -> 192.168.2.23:38188
    Source: TrafficSnort IDS: 716 INFO TELNET access 197.230.97.166:23 -> 192.168.2.23:39634
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 216.123.70.174:23 -> 192.168.2.23:34438
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 216.123.70.174:23 -> 192.168.2.23:34438
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 82.166.85.146:23 -> 192.168.2.23:38202
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 82.166.85.146:23 -> 192.168.2.23:38202
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 186.65.67.208:23 -> 192.168.2.23:46756
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 186.65.67.208:23 -> 192.168.2.23:46756
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 82.166.85.146:23 -> 192.168.2.23:38258
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 82.166.85.146:23 -> 192.168.2.23:38258
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 116.101.239.225:23 -> 192.168.2.23:54246
    Source: TrafficSnort IDS: 716 INFO TELNET access 222.254.23.45:23 -> 192.168.2.23:35022
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 82.166.85.146:23 -> 192.168.2.23:38316
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 82.166.85.146:23 -> 192.168.2.23:38316
    Source: TrafficSnort IDS: 716 INFO TELNET access 197.230.97.166:23 -> 192.168.2.23:39776
    Uses known network protocols on non-standard portsShow sources
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57766
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57768
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57770
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57772
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57776
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57778
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57780
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57782
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57782
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57784
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57786
    Source: global trafficTCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
    Source: global trafficTCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
    Source: global trafficTCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
    Source: global trafficTCP traffic: 192.168.2.23:58880 -> 178.17.171.119:1312
    Source: /tmp/mirkatclpb.arm (PID: 5227)Socket: 0.0.0.0::0
    Source: /tmp/mirkatclpb.arm (PID: 5227)Socket: 0.0.0.0::53413
    Source: /tmp/mirkatclpb.arm (PID: 5227)Socket: 0.0.0.0::80
    Source: /tmp/mirkatclpb.arm (PID: 5227)Socket: 0.0.0.0::37215
    Source: /tmp/mirkatclpb.arm (PID: 5233)Socket: 0.0.0.0::0
    Source: /tmp/mirkatclpb.arm (PID: 5233)Socket: 0.0.0.0::53413
    Source: /tmp/mirkatclpb.arm (PID: 5233)Socket: 0.0.0.0::80
    Source: /tmp/mirkatclpb.arm (PID: 5233)Socket: 0.0.0.0::37215
    Source: /usr/sbin/sshd (PID: 5262)Socket: 0.0.0.0::22
    Source: /usr/sbin/sshd (PID: 5262)Socket: [::]::22
    Source: /usr/sbin/sshd (PID: 5357)Socket: 0.0.0.0::22
    Source: /usr/sbin/sshd (PID: 5357)Socket: [::]::22
    Source: /usr/sbin/sshd (PID: 5359)Socket: 0.0.0.0::22
    Source: /usr/sbin/sshd (PID: 5359)Socket: [::]::22
    Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443
    Source: unknownTCP traffic detected without corresponding DNS query: 178.17.171.119
    Source: unknownTCP traffic detected without corresponding DNS query: 157.244.232.49
    Source: unknownTCP traffic detected without corresponding DNS query: 16.97.27.49
    Source: unknownTCP traffic detected without corresponding DNS query: 167.9.80.221
    Source: unknownTCP traffic detected without corresponding DNS query: 120.147.64.147
    Source: unknownTCP traffic detected without corresponding DNS query: 186.26.214.182
    Source: unknownTCP traffic detected without corresponding DNS query: 174.156.200.69
    Source: unknownTCP traffic detected without corresponding DNS query: 177.189.106.136
    Source: unknownTCP traffic detected without corresponding DNS query: 192.54.70.123
    Source: unknownTCP traffic detected without corresponding DNS query: 251.216.174.83
    Source: unknownTCP traffic detected without corresponding DNS query: 242.55.149.52
    Source: unknownTCP traffic detected without corresponding DNS query: 123.1.221.60
    Source: unknownTCP traffic detected without corresponding DNS query: 222.73.47.199
    Source: unknownTCP traffic detected without corresponding DNS query: 192.33.255.19
    Source: unknownTCP traffic detected without corresponding DNS query: 34.163.178.160
    Source: unknownTCP traffic detected without corresponding DNS query: 185.255.203.225
    Source: unknownTCP traffic detected without corresponding DNS query: 34.43.160.4
    Source: unknownTCP traffic detected without corresponding DNS query: 162.214.84.250
    Source: unknownTCP traffic detected without corresponding DNS query: 44.233.22.48
    Source: unknownTCP traffic detected without corresponding DNS query: 222.223.18.206
    Source: unknownTCP traffic detected without corresponding DNS query: 14.181.67.143
    Source: unknownTCP traffic detected without corresponding DNS query: 255.126.135.108
    Source: unknownTCP traffic detected without corresponding DNS query: 242.202.103.217
    Source: unknownTCP traffic detected without corresponding DNS query: 208.61.6.39
    Source: unknownTCP traffic detected without corresponding DNS query: 5.167.107.2
    Source: unknownTCP traffic detected without corresponding DNS query: 133.14.99.172
    Source: unknownTCP traffic detected without corresponding DNS query: 40.116.49.252
    Source: unknownTCP traffic detected without corresponding DNS query: 251.195.164.19
    Source: unknownTCP traffic detected without corresponding DNS query: 151.201.57.149
    Source: unknownTCP traffic detected without corresponding DNS query: 161.239.178.112
    Source: unknownTCP traffic detected without corresponding DNS query: 98.255.179.129
    Source: unknownTCP traffic detected without corresponding DNS query: 190.113.190.218
    Source: unknownTCP traffic detected without corresponding DNS query: 128.20.146.8
    Source: unknownTCP traffic detected without corresponding DNS query: 158.226.127.73
    Source: unknownTCP traffic detected without corresponding DNS query: 223.251.207.176
    Source: unknownTCP traffic detected without corresponding DNS query: 45.43.122.180
    Source: unknownTCP traffic detected without corresponding DNS query: 72.81.87.166
    Source: unknownTCP traffic detected without corresponding DNS query: 16.177.38.233
    Source: unknownTCP traffic detected without corresponding DNS query: 172.212.42.214
    Source: unknownTCP traffic detected without corresponding DNS query: 205.227.206.146
    Source: unknownTCP traffic detected without corresponding DNS query: 130.227.21.218
    Source: unknownTCP traffic detected without corresponding DNS query: 122.28.41.35
    Source: unknownTCP traffic detected without corresponding DNS query: 109.9.22.37
    Source: unknownTCP traffic detected without corresponding DNS query: 165.129.204.87
    Source: unknownTCP traffic detected without corresponding DNS query: 245.32.54.73
    Source: unknownTCP traffic detected without corresponding DNS query: 74.154.55.160
    Source: unknownTCP traffic detected without corresponding DNS query: 9.109.62.135
    Source: unknownTCP traffic detected without corresponding DNS query: 2.184.102.57
    Source: unknownTCP traffic detected without corresponding DNS query: 157.38.170.228
    Source: unknownTCP traffic detected without corresponding DNS query: 65.8.95.139
    Source: mirkatclpb.armString found in binary or memory: http://upx.sf.net

    System Summary:

    barindex
    Sample tries to kill many processes (SIGKILL)Show sources
    Source: /tmp/mirkatclpb.arm (PID: 5227)SIGKILL sent: pid: 5233, result: successful
    Source: /tmp/mirkatclpb.arm (PID: 5227)SIGKILL sent: pid: 720, result: successful
    Source: /tmp/mirkatclpb.arm (PID: 5227)SIGKILL sent: pid: 759, result: successful
    Source: /tmp/mirkatclpb.arm (PID: 5227)SIGKILL sent: pid: 788, result: successful
    Source: /tmp/mirkatclpb.arm (PID: 5227)SIGKILL sent: pid: 800, result: successful
    Source: /tmp/mirkatclpb.arm (PID: 5227)SIGKILL sent: pid: 847, result: successful
    Source: /tmp/mirkatclpb.arm (PID: 5227)SIGKILL sent: pid: 884, result: successful
    Source: /tmp/mirkatclpb.arm (PID: 5227)SIGKILL sent: pid: 1334, result: successful
    Source: /tmp/mirkatclpb.arm (PID: 5227)SIGKILL sent: pid: 1335, result: successful
    Source: /tmp/mirkatclpb.arm (PID: 5227)SIGKILL sent: pid: 1872, result: successful
    Source: /tmp/mirkatclpb.arm (PID: 5227)SIGKILL sent: pid: 2096, result: successful
    Source: /tmp/mirkatclpb.arm (PID: 5227)SIGKILL sent: pid: 2097, result: successful
    Source: /tmp/mirkatclpb.arm (PID: 5227)SIGKILL sent: pid: 2102, result: successful
    Source: /tmp/mirkatclpb.arm (PID: 5227)SIGKILL sent: pid: 2180, result: successful
    Source: /tmp/mirkatclpb.arm (PID: 5227)SIGKILL sent: pid: 2208, result: successful
    Source: /tmp/mirkatclpb.arm (PID: 5227)SIGKILL sent: pid: 2275, result: successful
    Source: /tmp/mirkatclpb.arm (PID: 5227)SIGKILL sent: pid: 2281, result: successful
    Source: /tmp/mirkatclpb.arm (PID: 5227)SIGKILL sent: pid: 2285, result: successful
    Source: /tmp/mirkatclpb.arm (PID: 5227)SIGKILL sent: pid: 2289, result: successful
    Source: /tmp/mirkatclpb.arm (PID: 5227)SIGKILL sent: pid: 2294, result: successful
    Source: /tmp/mirkatclpb.arm (PID: 5227)SIGKILL sent: pid: 5231, result: successful
    Source: /tmp/mirkatclpb.arm (PID: 5227)SIGKILL sent: pid: 5237, result: successful
    Source: /tmp/mirkatclpb.arm (PID: 5227)SIGKILL sent: pid: 5262, result: successful
    Source: /tmp/mirkatclpb.arm (PID: 5227)SIGKILL sent: pid: 5357, result: successful
    Source: /tmp/mirkatclpb.arm (PID: 5227)SIGKILL sent: pid: 5227, result: unknown
    Source: /tmp/mirkatclpb.arm (PID: 5233)SIGKILL sent: pid: 936, result: successful
    Source: LOAD without section mappingsProgram segment: 0x8000
    Source: /tmp/mirkatclpb.arm (PID: 5227)SIGKILL sent: pid: 5233, result: successful
    Source: /tmp/mirkatclpb.arm (PID: 5227)SIGKILL sent: pid: 720, result: successful
    Source: /tmp/mirkatclpb.arm (PID: 5227)SIGKILL sent: pid: 759, result: successful
    Source: /tmp/mirkatclpb.arm (PID: 5227)SIGKILL sent: pid: 788, result: successful
    Source: /tmp/mirkatclpb.arm (PID: 5227)SIGKILL sent: pid: 800, result: successful
    Source: /tmp/mirkatclpb.arm (PID: 5227)SIGKILL sent: pid: 847, result: successful
    Source: /tmp/mirkatclpb.arm (PID: 5227)SIGKILL sent: pid: 884, result: successful
    Source: /tmp/mirkatclpb.arm (PID: 5227)SIGKILL sent: pid: 1334, result: successful
    Source: /tmp/mirkatclpb.arm (PID: 5227)SIGKILL sent: pid: 1335, result: successful
    Source: /tmp/mirkatclpb.arm (PID: 5227)SIGKILL sent: pid: 1872, result: successful
    Source: /tmp/mirkatclpb.arm (PID: 5227)SIGKILL sent: pid: 2096, result: successful
    Source: /tmp/mirkatclpb.arm (PID: 5227)SIGKILL sent: pid: 2097, result: successful
    Source: /tmp/mirkatclpb.arm (PID: 5227)SIGKILL sent: pid: 2102, result: successful
    Source: /tmp/mirkatclpb.arm (PID: 5227)SIGKILL sent: pid: 2180, result: successful
    Source: /tmp/mirkatclpb.arm (PID: 5227)SIGKILL sent: pid: 2208, result: successful
    Source: /tmp/mirkatclpb.arm (PID: 5227)SIGKILL sent: pid: 2275, result: successful
    Source: /tmp/mirkatclpb.arm (PID: 5227)SIGKILL sent: pid: 2281, result: successful
    Source: /tmp/mirkatclpb.arm (PID: 5227)SIGKILL sent: pid: 2285, result: successful
    Source: /tmp/mirkatclpb.arm (PID: 5227)SIGKILL sent: pid: 2289, result: successful
    Source: /tmp/mirkatclpb.arm (PID: 5227)SIGKILL sent: pid: 2294, result: successful
    Source: /tmp/mirkatclpb.arm (PID: 5227)SIGKILL sent: pid: 5231, result: successful
    Source: /tmp/mirkatclpb.arm (PID: 5227)SIGKILL sent: pid: 5237, result: successful
    Source: /tmp/mirkatclpb.arm (PID: 5227)SIGKILL sent: pid: 5262, result: successful
    Source: /tmp/mirkatclpb.arm (PID: 5227)SIGKILL sent: pid: 5357, result: successful
    Source: /tmp/mirkatclpb.arm (PID: 5227)SIGKILL sent: pid: 5227, result: unknown
    Source: /tmp/mirkatclpb.arm (PID: 5233)SIGKILL sent: pid: 936, result: successful
    Source: classification engineClassification label: mal68.spre.troj.evad.linARM@0/6@0/0

    Data Obfuscation:

    barindex
    Sample is packed with UPXShow sources
    Source: initial sampleString containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $
    Source: initial sampleString containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $
    Source: initial sampleString containing UPX found: $Id: UPX 3.94 Copyright (C) 1996-2017 the UPX Team. All Rights Reserved. $
    Source: /tmp/mirkatclpb.arm (PID: 5233)File opened: /proc/491/fd
    Source: /tmp/mirkatclpb.arm (PID: 5233)File opened: /proc/793/fd
    Source: /tmp/mirkatclpb.arm (PID: 5233)File opened: /proc/772/fd
    Source: /tmp/mirkatclpb.arm (PID: 5233)File opened: /proc/796/fd
    Source: /tmp/mirkatclpb.arm (PID: 5233)File opened: /proc/774/fd
    Source: /tmp/mirkatclpb.arm (PID: 5233)File opened: /proc/797/fd
    Source: /tmp/mirkatclpb.arm (PID: 5233)File opened: /proc/777/fd
    Source: /tmp/mirkatclpb.arm (PID: 5233)File opened: /proc/799/fd
    Source: /tmp/mirkatclpb.arm (PID: 5233)File opened: /proc/658/fd
    Source: /tmp/mirkatclpb.arm (PID: 5233)File opened: /proc/912/fd
    Source: /tmp/mirkatclpb.arm (PID: 5233)File opened: /proc/759/fd
    Source: /tmp/mirkatclpb.arm (PID: 5233)File opened: /proc/936/fd
    Source: /tmp/mirkatclpb.arm (PID: 5233)File opened: /proc/918/fd
    Source: /tmp/mirkatclpb.arm (PID: 5233)File opened: /proc/1/fd
    Source: /tmp/mirkatclpb.arm (PID: 5233)File opened: /proc/761/fd
    Source: /tmp/mirkatclpb.arm (PID: 5233)File opened: /proc/785/fd
    Source: /tmp/mirkatclpb.arm (PID: 5233)File opened: /proc/884/fd
    Source: /tmp/mirkatclpb.arm (PID: 5233)File opened: /proc/720/fd
    Source: /tmp/mirkatclpb.arm (PID: 5233)File opened: /proc/721/fd
    Source: /tmp/mirkatclpb.arm (PID: 5233)File opened: /proc/788/fd
    Source: /tmp/mirkatclpb.arm (PID: 5233)File opened: /proc/789/fd
    Source: /tmp/mirkatclpb.arm (PID: 5233)File opened: /proc/800/fd
    Source: /tmp/mirkatclpb.arm (PID: 5233)File opened: /proc/801/fd
    Source: /tmp/mirkatclpb.arm (PID: 5233)File opened: /proc/847/fd
    Source: /tmp/mirkatclpb.arm (PID: 5233)File opened: /proc/904/fd
    Source: /tmp/mirkatclpb.arm (PID: 5227)File opened: /proc/5262/fd
    Source: /tmp/mirkatclpb.arm (PID: 5227)File opened: /proc/5262/exe
    Source: /tmp/mirkatclpb.arm (PID: 5227)File opened: /proc/2033/fd
    Source: /tmp/mirkatclpb.arm (PID: 5227)File opened: /proc/2033/fd
    Source: /tmp/mirkatclpb.arm (PID: 5227)File opened: /proc/2033/exe
    Source: /tmp/mirkatclpb.arm (PID: 5227)File opened: /proc/2033/fd
    Source: /tmp/mirkatclpb.arm (PID: 5227)File opened: /proc/2033/fd
    Source: /tmp/mirkatclpb.arm (PID: 5227)File opened: /proc/1582/fd
    Source: /tmp/mirkatclpb.arm (PID: 5227)File opened: /proc/1582/fd
    Source: /tmp/mirkatclpb.arm (PID: 5227)File opened: /proc/1582/exe
    Source: /tmp/mirkatclpb.arm (PID: 5227)File opened: /proc/1582/fd
    Source: /tmp/mirkatclpb.arm (PID: 5227)File opened: /proc/1582/fd
    Source: /tmp/mirkatclpb.arm (PID: 5227)File opened: /proc/2275/fd
    Source: /tmp/mirkatclpb.arm (PID: 5227)File opened: /proc/2275/fd
    Source: /tmp/mirkatclpb.arm (PID: 5227)File opened: /proc/2275/exe
    Source: /tmp/mirkatclpb.arm (PID: 5227)File opened: /proc/3088/exe
    Source: /tmp/mirkatclpb.arm (PID: 5227)File opened: /proc/5260/fd
    Source: /tmp/mirkatclpb.arm (PID: 5227)File opened: /proc/1612/fd
    Source: /tmp/mirkatclpb.arm (PID: 5227)File opened: /proc/1612/fd
    Source: /tmp/mirkatclpb.arm (PID: 5227)File opened: /proc/1612/exe
    Source: /tmp/mirkatclpb.arm (PID: 5227)File opened: /proc/1612/fd
    Source: /tmp/mirkatclpb.arm (PID: 5227)File opened: /proc/1612/fd
    Source: /tmp/mirkatclpb.arm (PID: 5227)File opened: /proc/1579/fd
    Source: /tmp/mirkatclpb.arm (PID: 5227)File opened: /proc/1579/fd
    Source: /tmp/mirkatclpb.arm (PID: 5227)File opened: /proc/1579/exe
    Source: /tmp/mirkatclpb.arm (PID: 5227)File opened: /proc/1579/fd
    Source: /tmp/mirkatclpb.arm (PID: 5227)File opened: /proc/1579/fd
    Source: /tmp/mirkatclpb.arm (PID: 5227)File opened: /proc/1699/fd
    Source: /tmp/mirkatclpb.arm (PID: 5227)File opened: /proc/1699/fd
    Source: /tmp/mirkatclpb.arm (PID: 5227)File opened: /proc/1699/exe
    Source: /tmp/mirkatclpb.arm (PID: 5227)File opened: /proc/1699/fd
    Source: /tmp/mirkatclpb.arm (PID: 5227)File opened: /proc/1699/fd
    Source: /tmp/mirkatclpb.arm (PID: 5227)File opened: /proc/1335/fd
    Source: /tmp/mirkatclpb.arm (PID: 5227)File opened: /proc/1335/fd
    Source: /tmp/mirkatclpb.arm (PID: 5227)File opened: /proc/1335/exe
    Source: /tmp/mirkatclpb.arm (PID: 5227)File opened: /proc/1698/fd
    Source: /tmp/mirkatclpb.arm (PID: 5227)File opened: /proc/1698/fd
    Source: /tmp/mirkatclpb.arm (PID: 5227)File opened: /proc/1698/exe
    Source: /tmp/mirkatclpb.arm (PID: 5227)File opened: /proc/1698/fd
    Source: /tmp/mirkatclpb.arm (PID: 5227)File opened: /proc/1698/fd
    Source: /tmp/mirkatclpb.arm (PID: 5227)File opened: /proc/2028/fd
    Source: /tmp/mirkatclpb.arm (PID: 5227)File opened: /proc/2028/fd
    Source: /tmp/mirkatclpb.arm (PID: 5227)File opened: /proc/2028/exe
    Source: /tmp/mirkatclpb.arm (PID: 5227)File opened: /proc/2028/fd
    Source: /tmp/mirkatclpb.arm (PID: 5227)File opened: /proc/2028/fd
    Source: /tmp/mirkatclpb.arm (PID: 5227)File opened: /proc/1334/fd
    Source: /tmp/mirkatclpb.arm (PID: 5227)File opened: /proc/1334/fd
    Source: /tmp/mirkatclpb.arm (PID: 5227)File opened: /proc/1334/exe
    Source: /tmp/mirkatclpb.arm (PID: 5227)File opened: /proc/1334/fd
    Source: /tmp/mirkatclpb.arm (PID: 5227)File opened: /proc/1334/fd
    Source: /tmp/mirkatclpb.arm (PID: 5227)File opened: /proc/1576/fd
    Source: /tmp/mirkatclpb.arm (PID: 5227)File opened: /proc/1576/fd
    Source: /tmp/mirkatclpb.arm (PID: 5227)File opened: /proc/1576/exe
    Source: /tmp/mirkatclpb.arm (PID: 5227)File opened: /proc/1576/fd
    Source: /tmp/mirkatclpb.arm (PID: 5227)File opened: /proc/1576/fd
    Source: /tmp/mirkatclpb.arm (PID: 5227)File opened: /proc/2302/fd
    Source: /tmp/mirkatclpb.arm (PID: 5227)File opened: /proc/2302/fd
    Source: /tmp/mirkatclpb.arm (PID: 5227)File opened: /proc/2302/exe
    Source: /tmp/mirkatclpb.arm (PID: 5227)File opened: /proc/2302/fd
    Source: /tmp/mirkatclpb.arm (PID: 5227)File opened: /proc/2302/fd
    Source: /tmp/mirkatclpb.arm (PID: 5227)File opened: /proc/3236/fd
    Source: /tmp/mirkatclpb.arm (PID: 5227)File opened: /proc/3236/fd
    Source: /tmp/mirkatclpb.arm (PID: 5227)File opened: /proc/3236/exe
    Source: /tmp/mirkatclpb.arm (PID: 5227)File opened: /proc/3236/fd
    Source: /tmp/mirkatclpb.arm (PID: 5227)File opened: /proc/3236/fd
    Source: /tmp/mirkatclpb.arm (PID: 5227)File opened: /proc/2025/fd
    Source: /tmp/mirkatclpb.arm (PID: 5227)File opened: /proc/2025/fd
    Source: /tmp/mirkatclpb.arm (PID: 5227)File opened: /proc/2025/exe
    Source: /tmp/mirkatclpb.arm (PID: 5227)File opened: /proc/2025/fd
    Source: /tmp/mirkatclpb.arm (PID: 5227)File opened: /proc/2025/fd
    Source: /tmp/mirkatclpb.arm (PID: 5227)File opened: /proc/2146/fd
    Source: /tmp/mirkatclpb.arm (PID: 5227)File opened: /proc/2146/fd
    Source: /tmp/mirkatclpb.arm (PID: 5227)File opened: /proc/2146/exe
    Source: /tmp/mirkatclpb.arm (PID: 5227)File opened: /proc/2146/fd
    Source: /tmp/mirkatclpb.arm (PID: 5227)File opened: /proc/2146/fd
    Source: /tmp/mirkatclpb.arm (PID: 5227)File opened: /proc/5258/fd
    Source: /tmp/mirkatclpb.arm (PID: 5227)File opened: /proc/910/exe
    Source: /tmp/mirkatclpb.arm (PID: 5227)File opened: /proc/5259/fd
    Source: /tmp/mirkatclpb.arm (PID: 5227)File opened: /proc/912/fd
    Source: /tmp/mirkatclpb.arm (PID: 5227)File opened: /proc/912/fd
    Source: /tmp/mirkatclpb.arm (PID: 5227)File opened: /proc/912/exe
    Source: /tmp/mirkatclpb.arm (PID: 5227)File opened: /proc/912/fd
    Source: /tmp/mirkatclpb.arm (PID: 5227)File opened: /proc/912/fd

    Hooking and other Techniques for Hiding and Protection:

    barindex
    Uses known network protocols on non-standard portsShow sources
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57766
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57768
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57770
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57772
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57776
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57778
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57780
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57782
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57782
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57784
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57786
    Source: /tmp/mirkatclpb.arm (PID: 5225)Queries kernel information via 'uname':
    Source: mirkatclpb.arm, 5227.1.00000000c45ccceb.000000004da30319.rw-.sdmpBinary or memory string: Uu-binfmt/arm/0!/proc/1654/fd/3!/proc/5251/exe/arm/pro1/usr/bin/qemu-armrm/0!/proc/1654/fd/4!/proc/5250/fd/14arm/pro1
    Source: mirkatclpb.arm, 5225.1.000000006ea636fc.00000000c45ccceb.rw-.sdmpBinary or memory string: U!/etc/qemu-binfmt/arm
    Source: mirkatclpb.arm, 5227.1.00000000c45ccceb.000000004da30319.rw-.sdmpBinary or memory string: U!/proc/5258/fd/..arm/pro1/usr/bin/vmtoolsdrm/
    Source: mirkatclpb.arm, 5225.1.000000000d06bf85.00000000e32b960c.rw-.sdmpBinary or memory string: Bx86_64/usr/bin/qemu-arm/tmp/mirkatclpb.armSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/mirkatclpb.arm
    Source: mirkatclpb.arm, 5227.1.00000000c45ccceb.000000004da30319.rw-.sdmpBinary or memory string: /usr/bin/vmtoolsd
    Source: mirkatclpb.arm, 5225.1.000000006ea636fc.00000000c45ccceb.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/arm
    Source: mirkatclpb.arm, 5225.1.000000000d06bf85.00000000e32b960c.rw-.sdmpBinary or memory string: /usr/bin/qemu-arm

    Stealing of Sensitive Information:

    barindex
    Yara detected MiraiShow sources
    Source: Yara matchFile source: dump.pcap, type: PCAP

    Remote Access Functionality:

    barindex
    Yara detected MiraiShow sources
    Source: Yara matchFile source: dump.pcap, type: PCAP

    Mitre Att&ck Matrix

    Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
    Valid AccountsWindows Management InstrumentationPath InterceptionPath InterceptionObfuscated Files or Information1OS Credential Dumping1Security Software Discovery11Remote ServicesData from Local SystemExfiltration Over Other Network MediumEncrypted Channel1Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
    Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over BluetoothNon-Standard Port11Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
    Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated ExfiltrationApplication Layer Protocol1Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data

    Malware Configuration

    No configs have been found

    Behavior Graph

    Hide Legend

    Legend:

    • Process
    • Signature
    • Created File
    • DNS/IP Info
    • Is Dropped
    • Number of created Files
    • Is malicious
    • Internet
    behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 491830 Sample: mirkatclpb.arm Startdate: 27/09/2021 Architecture: LINUX Score: 68 30 66.147.85.178 WINDSTREAMUS United States 2->30 32 200.152.162.49 VerizonMediadoBrasilInternetLtdaBR Brazil 2->32 34 98 other IPs or domains 2->34 38 Snort IDS alert for network traffic (e.g. based on Emerging Threat rules) 2->38 40 Yara detected Mirai 2->40 42 Uses known network protocols on non-standard ports 2->42 44 Sample is packed with UPX 2->44 8 mirkatclpb.arm 2->8         started        10 systemd sshd 2->10         started        12 systemd sshd 2->12         started        14 4 other processes 2->14 signatures3 process4 process5 16 mirkatclpb.arm 8->16         started        18 mirkatclpb.arm 8->18         started        21 mirkatclpb.arm 8->21         started        signatures6 23 mirkatclpb.arm 16->23         started        26 mirkatclpb.arm 16->26         started        28 mirkatclpb.arm 16->28         started        36 Sample tries to kill many processes (SIGKILL) 18->36 process7 signatures8 46 Sample tries to kill many processes (SIGKILL) 23->46

    Screenshots

    Thumbnails

    This section contains all screenshots as thumbnails, including those not shown in the slideshow.

    windows-stand

    Antivirus, Machine Learning and Genetic Malware Detection

    Initial Sample

    No Antivirus matches

    Dropped Files

    No Antivirus matches

    Domains

    No Antivirus matches

    URLs

    No Antivirus matches

    Domains and IPs

    Contacted Domains

    No contacted domains info

    URLs from Memory and Binaries

    NameSourceMaliciousAntivirus DetectionReputation
    http://upx.sf.netmirkatclpb.armfalse
      high

      Contacted IPs

      • No. of IPs < 25%
      • 25% < No. of IPs < 50%
      • 50% < No. of IPs < 75%
      • 75% < No. of IPs

      Public

      IPDomainCountryFlagASNASN NameMalicious
      213.31.71.244
      unknownBelgium
      6871PLUSNETUKInternetServiceProviderGBfalse
      166.29.74.82
      unknownUnited States
      206CSC-IGN-AMERUSfalse
      14.143.23.189
      unknownIndia
      4755TATACOMM-ASTATACommunicationsformerlyVSNLisLeadingISPfalse
      200.152.162.49
      unknownBrazil
      28122VerizonMediadoBrasilInternetLtdaBRfalse
      206.67.127.12
      unknownUnited States
      701UUNETUSfalse
      158.34.190.147
      unknownUnited States
      721DNIC-ASBLK-00721-00726USfalse
      247.118.145.156
      unknownReserved
      unknownunknownfalse
      23.179.6.168
      unknownReserved
      63297PACIFIC-SERVERSCAfalse
      202.236.115.3
      unknownJapan17676GIGAINFRASoftbankBBCorpJPfalse
      245.114.66.174
      unknownReserved
      unknownunknownfalse
      87.81.175.34
      unknownUnited Kingdom
      5607BSKYB-BROADBAND-ASGBfalse
      188.97.180.64
      unknownGermany
      3209VODANETInternationalIP-BackboneofVodafoneDEfalse
      159.173.54.239
      unknownFrance
      28686AVECTRIS-ASCHfalse
      188.248.166.141
      unknownSaudi Arabia
      48695ATHEEB-ASSAfalse
      253.254.231.181
      unknownReserved
      unknownunknownfalse
      102.241.34.87
      unknownTunisia
      36926CKL1-ASNKEfalse
      57.67.217.115
      unknownBelgium
      51964ORANGE-BUSINESS-SERVICES-IPSN-ASNFRfalse
      197.131.99.208
      unknownMorocco
      6713IAM-ASMAfalse
      14.139.237.177
      unknownIndia
      55824NKN-CORE-NWNKNCoreNetworkINfalse
      173.70.19.51
      unknownUnited States
      701UUNETUSfalse
      102.114.79.239
      unknownMauritius
      23889MauritiusTelecomMUfalse
      139.196.56.182
      unknownChina
      37963CNNIC-ALIBABA-CN-NET-APHangzhouAlibabaAdvertisingCoLtdfalse
      73.207.81.45
      unknownUnited States
      7922COMCAST-7922USfalse
      194.128.173.25
      unknownUnited Kingdom
      702UUNETUSfalse
      242.249.209.192
      unknownReserved
      unknownunknownfalse
      87.51.208.65
      unknownDenmark
      3292TDCTDCASDKfalse
      63.148.159.88
      unknownUnited States
      209CENTURYLINK-US-LEGACY-QWESTUSfalse
      2.103.215.131
      unknownUnited Kingdom
      13285OPALTELECOM-ASTalkTalkCommunicationsLimitedGBfalse
      108.243.173.4
      unknownUnited States
      7018ATT-INTERNET4USfalse
      207.90.126.129
      unknownUnited States
      7321LNET-ASNUSfalse
      193.245.131.64
      unknownBelgium
      3549LVLT-3549USfalse
      242.63.95.89
      unknownReserved
      unknownunknownfalse
      195.229.184.171
      unknownUnited Arab Emirates
      5384EMIRATES-INTERNETEmiratesInternetAEfalse
      180.170.25.215
      unknownChina
      4812CHINANET-SH-APChinaTelecomGroupCNfalse
      174.64.2.29
      unknownUnited States
      22773ASN-CXA-ALL-CCI-22773-RDCUSfalse
      86.52.29.10
      unknownDenmark
      197288STOFANETDKfalse
      254.91.231.74
      unknownReserved
      unknownunknownfalse
      246.141.80.184
      unknownReserved
      unknownunknownfalse
      36.90.232.64
      unknownIndonesia
      7713TELKOMNET-AS-APPTTelekomunikasiIndonesiaIDfalse
      135.205.221.76
      unknownUnited States
      6431ATT-RESEARCHUSfalse
      250.51.173.213
      unknownReserved
      unknownunknownfalse
      84.116.116.140
      unknownNetherlands
      6830LIBERTYGLOBALLibertyGlobalformerlyUPCBroadbandHoldingfalse
      69.90.190.99
      unknownCanada
      13768COGECO-PEER1CAfalse
      157.72.178.5
      unknownJapan131932JEIS-NETJREastInformationSystemsCompanyJPfalse
      110.125.97.65
      unknownChina
      9808CMNET-GDGuangdongMobileCommunicationCoLtdCNfalse
      20.21.196.35
      unknownUnited States
      8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
      125.73.254.169
      unknownChina
      4134CHINANET-BACKBONENo31Jin-rongStreetCNfalse
      1.99.146.64
      unknownKorea Republic of
      4766KIXS-AS-KRKoreaTelecomKRfalse
      206.9.187.110
      unknownUnited States
      5006VOYANTUSfalse
      65.201.108.229
      unknownUnited States
      701UUNETUSfalse
      179.48.209.102
      unknownunknown
      3816COLOMBIATELECOMUNICACIONESSAESPCOfalse
      59.166.150.107
      unknownJapan9824JTCL-JP-ASJupiterTelecommunicationCoLtdJPfalse
      120.161.3.29
      unknownIndonesia
      4761INDOSAT-INP-APINDOSATInternetNetworkProviderIDfalse
      170.73.197.190
      unknownUnited States
      16761FEDMOG-ASN-01USfalse
      23.42.205.247
      unknownUnited States
      16625AKAMAI-ASUSfalse
      17.103.205.219
      unknownUnited States
      714APPLE-ENGINEERINGUSfalse
      66.147.85.178
      unknownUnited States
      7029WINDSTREAMUSfalse
      102.74.168.118
      unknownMorocco
      6713IAM-ASMAfalse
      149.210.199.62
      unknownNetherlands
      20857TRANSIP-ASAmsterdamtheNetherlandsNLfalse
      221.248.80.1
      unknownJapan17506UCOMARTERIANetworksCorporationJPfalse
      60.16.183.22
      unknownChina
      4837CHINA169-BACKBONECHINAUNICOMChina169BackboneCNfalse
      107.134.158.250
      unknownUnited States
      7018ATT-INTERNET4USfalse
      202.200.196.12
      unknownChina
      4538ERX-CERNET-BKBChinaEducationandResearchNetworkCenterfalse
      184.5.225.222
      unknownUnited States
      5778CENTURYLINK-LEGACY-EMBARQ-RCMTUSfalse
      151.246.218.21
      unknownIran (ISLAMIC Republic Of)
      31549RASANAIRfalse
      117.219.36.68
      unknownIndia
      9829BSNL-NIBNationalInternetBackboneINfalse
      220.138.36.103
      unknownTaiwan; Republic of China (ROC)
      3462HINETDataCommunicationBusinessGroupTWfalse
      16.225.121.0
      unknownUnited States
      unknownunknownfalse
      66.12.192.156
      unknownUnited States
      5650FRONTIER-FRTRUSfalse
      106.90.12.33
      unknownChina
      4134CHINANET-BACKBONENo31Jin-rongStreetCNfalse
      216.46.212.245
      unknownUnited States
      19945GRANBURYISDUSfalse
      146.123.208.124
      unknownUnited States
      2158HPESUSfalse
      250.53.18.17
      unknownReserved
      unknownunknownfalse
      159.201.91.21
      unknownUnited States
      1906NORTHROP-GRUMMANUSfalse
      165.133.204.80
      unknownKorea Republic of
      4961DISC-AS-KRDaewooInformationSystemsKRfalse
      31.61.177.115
      unknownPoland
      5617TPNETPLfalse
      204.233.222.220
      unknownUnited States
      2914NTT-COMMUNICATIONS-2914USfalse
      47.90.213.32
      unknownUnited States
      45102CNNIC-ALIBABA-US-NET-APAlibabaUSTechnologyCoLtdCfalse
      12.50.93.239
      unknownUnited States
      7018ATT-INTERNET4USfalse
      140.220.168.137
      unknownUnited States
      600OARNET-ASUSfalse
      221.87.174.160
      unknownJapan17676GIGAINFRASoftbankBBCorpJPfalse
      217.202.195.230
      unknownItaly
      16232ASN-TIMServiceProviderITfalse
      173.80.22.227
      unknownUnited States
      19108SUDDENLINK-COMMUNICATIONSUSfalse
      1.146.71.43
      unknownAustralia
      1221ASN-TELSTRATelstraCorporationLtdAUfalse
      217.95.63.172
      unknownGermany
      3320DTAGInternetserviceprovideroperationsDEfalse
      114.253.135.30
      unknownChina
      4808CHINA169-BJChinaUnicomBeijingProvinceNetworkCNfalse
      243.220.176.106
      unknownReserved
      unknownunknownfalse
      38.49.227.144
      unknownUnited States
      174COGENT-174USfalse
      254.89.164.115
      unknownReserved
      unknownunknownfalse
      175.248.208.227
      unknownKorea Republic of
      4766KIXS-AS-KRKoreaTelecomKRfalse
      95.27.203.251
      unknownRussian Federation
      8402CORBINA-ASOJSCVimpelcomRUfalse
      61.32.110.154
      unknownKorea Republic of
      3786LGDACOMLGDACOMCorporationKRfalse
      87.4.93.209
      unknownItaly
      3269ASN-IBSNAZITfalse
      158.214.59.15
      unknownJapan2907SINET-ASResearchOrganizationofInformationandSystemsNfalse
      192.248.174.124
      unknownFrance
      20473AS-CHOOPAUSfalse
      9.35.128.167
      unknownUnited States
      3356LEVEL3USfalse
      143.236.35.245
      unknownUnited States
      3128BRUWS-AS3128USfalse
      252.4.195.138
      unknownReserved
      unknownunknownfalse
      173.197.253.115
      unknownUnited States
      10796TWC-10796-MIDWESTUSfalse
      216.224.227.28
      unknownUnited States
      39948INIT-PHXUSfalse


      Runtime Messages

      Command:/tmp/mirkatclpb.arm
      Exit Code:0
      Exit Code Info:
      Killed:False
      Standard Output:
      Connected To CNC
      Standard Error:

      Joe Sandbox View / Context

      IPs

      No context

      Domains

      No context

      ASN

      MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
      CSC-IGN-AMERUSsoramrk.arm7Get hashmaliciousBrowse
      • 166.18.138.122
      4czqYWTUq8Get hashmaliciousBrowse
      • 166.28.2.6
      dark.x86Get hashmaliciousBrowse
      • 166.24.237.116
      sora.x86Get hashmaliciousBrowse
      • 20.137.104.111
      jew.x86Get hashmaliciousBrowse
      • 166.26.105.225
      RIkJg4Hr71Get hashmaliciousBrowse
      • 166.25.76.134
      sora.x86Get hashmaliciousBrowse
      • 20.132.107.100
      sora.armGet hashmaliciousBrowse
      • 166.25.76.133
      ayx5kFWYmZGet hashmaliciousBrowse
      • 20.137.104.115
      x86_64Get hashmaliciousBrowse
      • 166.29.182.33
      4nLik56DrDGet hashmaliciousBrowse
      • 166.26.55.116
      b3astmode.arm7Get hashmaliciousBrowse
      • 166.26.55.112
      x86Get hashmaliciousBrowse
      • 166.17.196.159
      K6s3wEt8UaGet hashmaliciousBrowse
      • 166.26.55.100
      r6ZMm6XiWcGet hashmaliciousBrowse
      • 166.18.138.185
      M2hPt9E5FkGet hashmaliciousBrowse
      • 166.28.244.239
      RYlggrmClJGet hashmaliciousBrowse
      • 166.29.98.78
      vWV3GzP3vRGet hashmaliciousBrowse
      • 166.24.102.124
      vHVNRpNhIsGet hashmaliciousBrowse
      • 20.132.231.166
      1isequal9.x86Get hashmaliciousBrowse
      • 166.29.121.84
      PLUSNETUKInternetServiceProviderGB8LdKQIRfZGGet hashmaliciousBrowse
      • 91.125.96.99
      soramrk.arm7Get hashmaliciousBrowse
      • 195.213.49.51
      R4j2V50iCQGet hashmaliciousBrowse
      • 81.141.31.72
      VRVgDYWUEDGet hashmaliciousBrowse
      • 84.92.157.60
      PNv1wwpUowGet hashmaliciousBrowse
      • 80.229.218.105
      sora.x86Get hashmaliciousBrowse
      • 209.93.111.137
      UnHAnaAW.x86Get hashmaliciousBrowse
      • 31.185.55.182
      TsHIdFKafFGet hashmaliciousBrowse
      • 84.92.108.96
      I6l48v5NQDGet hashmaliciousBrowse
      • 81.141.79.14
      BLBHEA8kndGet hashmaliciousBrowse
      • 84.92.157.59
      Wrg7vnHm5AGet hashmaliciousBrowse
      • 195.166.145.100
      uxHuQqDuZcGet hashmaliciousBrowse
      • 195.99.43.175
      b3astmode.armGet hashmaliciousBrowse
      • 84.93.18.172
      aXyZQ9O8iBGet hashmaliciousBrowse
      • 80.229.86.18
      AJK7j832D2Get hashmaliciousBrowse
      • 81.140.202.98
      x86Get hashmaliciousBrowse
      • 195.166.145.114
      arm5Get hashmaliciousBrowse
      • 80.229.2.221
      dark.sh4Get hashmaliciousBrowse
      • 80.229.2.247
      tW7pu9B8A0Get hashmaliciousBrowse
      • 84.93.0.213
      77QZ81W0pZGet hashmaliciousBrowse
      • 81.141.55.50

      JA3 Fingerprints

      No context

      Dropped Files

      No context

      Created / dropped Files

      /proc/5262/oom_score_adj
      Process:/usr/sbin/sshd
      File Type:ASCII text
      Category:dropped
      Size (bytes):6
      Entropy (8bit):1.7924812503605778
      Encrypted:false
      SSDEEP:3:ptn:Dn
      MD5:CBF282CC55ED0792C33D10003D1F760A
      SHA1:007DD8BD75468E6B7ABA4285E9B267202C7EAEED
      SHA-256:FCDBAB99FCC0F4409E5F9D7D6FC497780288B4C441698126BB62832412774D22
      SHA-512:4643A8675D213C7DA35CC0C2BFB3B6F20324F9C48AEA7BA79F470615698C9A0CEFDA45CAA1957FC29110EE746BC8458AB8AB1E43EB513912A5E1E8858812CC00
      Malicious:false
      Reputation:moderate, very likely benign file
      Preview: -1000.
      /proc/5357/oom_score_adj
      Process:/usr/sbin/sshd
      File Type:ASCII text
      Category:dropped
      Size (bytes):6
      Entropy (8bit):1.7924812503605778
      Encrypted:false
      SSDEEP:3:ptn:Dn
      MD5:CBF282CC55ED0792C33D10003D1F760A
      SHA1:007DD8BD75468E6B7ABA4285E9B267202C7EAEED
      SHA-256:FCDBAB99FCC0F4409E5F9D7D6FC497780288B4C441698126BB62832412774D22
      SHA-512:4643A8675D213C7DA35CC0C2BFB3B6F20324F9C48AEA7BA79F470615698C9A0CEFDA45CAA1957FC29110EE746BC8458AB8AB1E43EB513912A5E1E8858812CC00
      Malicious:false
      Reputation:moderate, very likely benign file
      Preview: -1000.
      /proc/5359/oom_score_adj
      Process:/usr/sbin/sshd
      File Type:ASCII text
      Category:dropped
      Size (bytes):6
      Entropy (8bit):1.7924812503605778
      Encrypted:false
      SSDEEP:3:ptn:Dn
      MD5:CBF282CC55ED0792C33D10003D1F760A
      SHA1:007DD8BD75468E6B7ABA4285E9B267202C7EAEED
      SHA-256:FCDBAB99FCC0F4409E5F9D7D6FC497780288B4C441698126BB62832412774D22
      SHA-512:4643A8675D213C7DA35CC0C2BFB3B6F20324F9C48AEA7BA79F470615698C9A0CEFDA45CAA1957FC29110EE746BC8458AB8AB1E43EB513912A5E1E8858812CC00
      Malicious:false
      Reputation:moderate, very likely benign file
      Preview: -1000.
      /run/sshd.pid
      Process:/usr/sbin/sshd
      File Type:ASCII text
      Category:dropped
      Size (bytes):5
      Entropy (8bit):1.9219280948873623
      Encrypted:false
      SSDEEP:3:DQe:t
      MD5:D58EE3FB1678D38519A28E681026FE91
      SHA1:DA5269859F42E02B8C6E870022B15E6656B7C425
      SHA-256:E42E7906AE58FC4C8B70F912EC415D0FB2A49A3F54C9FB9D84C66731A1ED0DE6
      SHA-512:DDEA99F3C15931102CF7EAF551FEED190B762F7B597DEF5329CCA576ADD6F5E59885BAAE14D7483BE141B24DBD5D05E2C877DE1C5F978AF60276C28CAC3EBFAC
      Malicious:false
      Reputation:low
      Preview: 5359.

      Static File Info

      General

      File type:ELF 32-bit LSB executable, ARM, version 1 (ARM), statically linked, stripped
      Entropy (8bit):7.929079875154064
      TrID:
      • ELF Executable and Linkable format (generic) (4004/1) 100.00%
      File name:mirkatclpb.arm
      File size:25004
      MD5:f11d4deb3dc156310b53b21e22c5663a
      SHA1:f785ac4c47b99459a8ce236aa76df115af76dd7f
      SHA256:64e0601e1a0a1bb7f8f170ea14efa55b1f17aaefad94edf0b96cfdbebeb689e8
      SHA512:158581447fc598aa5139b8d93c96b09b82b0b442f6704a4a2fbbe816e8df57e10471899ac9f38d3d34e23d637723d1462e44857db1208b9c57bc507564db18d6
      SSDEEP:768:QX9nxn8o9wnBoWzEQf2EjKb3pWz9s3Uoz2:Qtn+o9wjfBAZWcz2
      File Content Preview:.ELF...a..........(.........4...........4. ...(......................`...`...............^..........................Q.td..............................CvUPX!........0...0.......R..........?.E.h;.}...^..........f.Z.6..(fw....&.x:.E.......oe.`.S..T.......n..

      Static ELF Info

      ELF header

      Class:ELF32
      Data:2's complement, little endian
      Version:1 (current)
      Machine:ARM
      Version Number:0x1
      Type:EXEC (Executable file)
      OS/ABI:ARM - ABI
      ABI Version:0
      Entry Point Address:0xcf10
      Flags:0x202
      ELF Header Size:52
      Program Header Offset:52
      Program Header Size:32
      Number of Program Headers:3
      Section Header Offset:0
      Section Header Size:40
      Number of Section Headers:0
      Header String Table Index:0

      Program Segments

      TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
      LOAD0x00x80000x80000x60bf0x60bf4.04770x5R E0x8000
      LOAD0x5ee00x1dee00x1dee00x00x00.00000x6RW 0x8000
      GNU_STACK0x00x00x00x00x00.00000x7RWE0x4

      Network Behavior

      Network Port Distribution

      TCP Packets

      TimestampSource PortDest PortSource IPDest IP
      Sep 27, 2021 23:51:25.822817087 CEST588801312192.168.2.23178.17.171.119
      Sep 27, 2021 23:51:25.842024088 CEST2230923192.168.2.23157.244.232.49
      Sep 27, 2021 23:51:25.842102051 CEST2230923192.168.2.2316.97.27.49
      Sep 27, 2021 23:51:25.842128038 CEST2230923192.168.2.23167.9.80.221
      Sep 27, 2021 23:51:25.842230082 CEST2230923192.168.2.23120.147.64.147
      Sep 27, 2021 23:51:25.842252970 CEST2230923192.168.2.23186.26.214.182
      Sep 27, 2021 23:51:25.842281103 CEST2230923192.168.2.23174.156.200.69
      Sep 27, 2021 23:51:25.842297077 CEST2230923192.168.2.23177.189.106.136
      Sep 27, 2021 23:51:25.842309952 CEST2230923192.168.2.23192.54.70.123
      Sep 27, 2021 23:51:25.842312098 CEST2230923192.168.2.23251.216.174.83
      Sep 27, 2021 23:51:25.842339039 CEST2230923192.168.2.23242.55.149.52
      Sep 27, 2021 23:51:25.842456102 CEST2230923192.168.2.23123.1.221.60
      Sep 27, 2021 23:51:25.842466116 CEST2230923192.168.2.23222.73.47.199
      Sep 27, 2021 23:51:25.842482090 CEST2230923192.168.2.23192.33.255.19
      Sep 27, 2021 23:51:25.842483997 CEST2230923192.168.2.2334.163.178.160
      Sep 27, 2021 23:51:25.842485905 CEST2230923192.168.2.23185.255.203.225
      Sep 27, 2021 23:51:25.842516899 CEST2230923192.168.2.2334.43.160.4
      Sep 27, 2021 23:51:25.842523098 CEST2230923192.168.2.23162.214.84.250
      Sep 27, 2021 23:51:25.842525959 CEST2230923192.168.2.2344.233.22.48
      Sep 27, 2021 23:51:25.842526913 CEST2230923192.168.2.23222.223.18.206
      Sep 27, 2021 23:51:25.842539072 CEST2230923192.168.2.2314.181.67.143
      Sep 27, 2021 23:51:25.842555046 CEST2230923192.168.2.23255.126.135.108
      Sep 27, 2021 23:51:25.842565060 CEST2230923192.168.2.23242.202.103.217
      Sep 27, 2021 23:51:25.842583895 CEST2230923192.168.2.23208.61.6.39
      Sep 27, 2021 23:51:25.842658043 CEST2230923192.168.2.235.167.107.2
      Sep 27, 2021 23:51:25.842688084 CEST2230923192.168.2.23133.14.99.172
      Sep 27, 2021 23:51:25.842688084 CEST2230923192.168.2.2340.116.49.252
      Sep 27, 2021 23:51:25.842704058 CEST2230923192.168.2.23251.195.164.19
      Sep 27, 2021 23:51:25.842773914 CEST2230923192.168.2.23151.201.57.149
      Sep 27, 2021 23:51:25.842814922 CEST2230923192.168.2.23161.239.178.112
      Sep 27, 2021 23:51:25.842833996 CEST2230923192.168.2.2398.255.179.129
      Sep 27, 2021 23:51:25.842853069 CEST2230923192.168.2.23190.113.190.218
      Sep 27, 2021 23:51:25.842868090 CEST2230923192.168.2.23128.20.146.8
      Sep 27, 2021 23:51:25.842895031 CEST2230923192.168.2.23158.226.127.73
      Sep 27, 2021 23:51:25.842911959 CEST2230923192.168.2.23223.251.207.176
      Sep 27, 2021 23:51:25.842942953 CEST2230923192.168.2.2345.43.122.180
      Sep 27, 2021 23:51:25.842962980 CEST2230923192.168.2.2372.81.87.166
      Sep 27, 2021 23:51:25.842967033 CEST2230923192.168.2.2316.177.38.233
      Sep 27, 2021 23:51:25.842993021 CEST2230923192.168.2.23172.212.42.214
      Sep 27, 2021 23:51:25.843008995 CEST2230923192.168.2.23117.97.110.196
      Sep 27, 2021 23:51:25.843055010 CEST2230923192.168.2.23205.227.206.146
      Sep 27, 2021 23:51:25.843055964 CEST2230923192.168.2.23130.227.21.218
      Sep 27, 2021 23:51:25.843066931 CEST2230923192.168.2.23122.28.41.35
      Sep 27, 2021 23:51:25.843080044 CEST2230923192.168.2.23109.9.22.37
      Sep 27, 2021 23:51:25.843111992 CEST2230923192.168.2.23165.129.204.87
      Sep 27, 2021 23:51:25.843156099 CEST2230923192.168.2.23245.32.54.73
      Sep 27, 2021 23:51:25.843180895 CEST2230923192.168.2.2374.154.55.160
      Sep 27, 2021 23:51:25.843194962 CEST2230923192.168.2.239.109.62.135
      Sep 27, 2021 23:51:25.843199968 CEST2230923192.168.2.232.184.102.57
      Sep 27, 2021 23:51:25.843205929 CEST2230923192.168.2.23157.38.170.228
      Sep 27, 2021 23:51:25.843206882 CEST2230923192.168.2.2365.8.95.139
      Sep 27, 2021 23:51:25.843215942 CEST2230923192.168.2.23248.169.206.236
      Sep 27, 2021 23:51:25.843226910 CEST2230923192.168.2.23205.213.64.100
      Sep 27, 2021 23:51:25.843254089 CEST2230923192.168.2.23202.54.68.56
      Sep 27, 2021 23:51:25.843297958 CEST2230923192.168.2.2313.79.119.101
      Sep 27, 2021 23:51:25.843344927 CEST2230923192.168.2.2389.183.187.102
      Sep 27, 2021 23:51:25.843365908 CEST2230923192.168.2.23109.168.100.101
      Sep 27, 2021 23:51:25.843384027 CEST2230923192.168.2.23201.181.33.169
      Sep 27, 2021 23:51:25.843393087 CEST2230923192.168.2.23101.234.19.32
      Sep 27, 2021 23:51:25.843447924 CEST2230923192.168.2.23112.163.199.171
      Sep 27, 2021 23:51:25.843461990 CEST2230923192.168.2.2397.103.84.164
      Sep 27, 2021 23:51:25.843478918 CEST2230923192.168.2.23242.1.216.205
      Sep 27, 2021 23:51:25.843492985 CEST2230923192.168.2.23201.165.156.227
      Sep 27, 2021 23:51:25.843518972 CEST2230923192.168.2.23244.13.0.200
      Sep 27, 2021 23:51:25.843540907 CEST2230923192.168.2.23135.52.67.108
      Sep 27, 2021 23:51:25.843576908 CEST2230923192.168.2.23138.195.13.172
      Sep 27, 2021 23:51:25.843589067 CEST2230923192.168.2.2387.206.18.90
      Sep 27, 2021 23:51:25.843599081 CEST2230923192.168.2.23142.29.211.209
      Sep 27, 2021 23:51:25.843611956 CEST2230923192.168.2.23144.93.68.143
      Sep 27, 2021 23:51:25.843631029 CEST2230923192.168.2.2312.4.233.129
      Sep 27, 2021 23:51:25.843714952 CEST2230923192.168.2.23217.92.5.51
      Sep 27, 2021 23:51:25.843770027 CEST2230923192.168.2.23211.159.114.219
      Sep 27, 2021 23:51:25.843827009 CEST2230923192.168.2.2374.20.185.208
      Sep 27, 2021 23:51:25.843830109 CEST2230923192.168.2.23147.179.174.114
      Sep 27, 2021 23:51:25.843831062 CEST2230923192.168.2.23122.211.250.37
      Sep 27, 2021 23:51:25.843857050 CEST2230923192.168.2.2337.173.187.97
      Sep 27, 2021 23:51:25.843858957 CEST2230923192.168.2.23106.2.178.127
      Sep 27, 2021 23:51:25.843859911 CEST2230923192.168.2.2374.246.87.251
      Sep 27, 2021 23:51:25.843863010 CEST2230923192.168.2.23219.196.157.236
      Sep 27, 2021 23:51:25.843864918 CEST2230923192.168.2.23223.30.92.214
      Sep 27, 2021 23:51:25.843867064 CEST2230923192.168.2.23169.59.70.53
      Sep 27, 2021 23:51:25.843890905 CEST2230923192.168.2.238.16.191.246
      Sep 27, 2021 23:51:25.843892097 CEST2230923192.168.2.23208.137.107.67
      Sep 27, 2021 23:51:25.843957901 CEST2230923192.168.2.232.198.211.186
      Sep 27, 2021 23:51:25.843966007 CEST2230923192.168.2.2368.26.243.150
      Sep 27, 2021 23:51:25.843975067 CEST2230923192.168.2.23171.4.2.2
      Sep 27, 2021 23:51:25.843974113 CEST2230923192.168.2.2383.208.109.15
      Sep 27, 2021 23:51:25.843975067 CEST2230923192.168.2.23171.247.226.151
      Sep 27, 2021 23:51:25.843975067 CEST2230923192.168.2.2365.196.160.121
      Sep 27, 2021 23:51:25.843998909 CEST2230923192.168.2.2366.177.255.100
      Sep 27, 2021 23:51:25.844001055 CEST2230923192.168.2.23100.209.99.65
      Sep 27, 2021 23:51:25.844008923 CEST2230923192.168.2.23184.90.69.131
      Sep 27, 2021 23:51:25.844008923 CEST2230923192.168.2.2331.145.155.218
      Sep 27, 2021 23:51:25.844008923 CEST2230923192.168.2.23111.100.154.90
      Sep 27, 2021 23:51:25.844010115 CEST2230923192.168.2.2396.166.55.128
      Sep 27, 2021 23:51:25.844014883 CEST2230923192.168.2.2384.183.124.17
      Sep 27, 2021 23:51:25.844048023 CEST2230923192.168.2.23114.7.51.176
      Sep 27, 2021 23:51:25.844049931 CEST2230923192.168.2.23200.147.212.176
      Sep 27, 2021 23:51:25.844063044 CEST2230923192.168.2.23146.27.47.142
      Sep 27, 2021 23:51:25.844064951 CEST2230923192.168.2.23220.181.27.219

      System Behavior

      General

      Start time:23:51:24
      Start date:27/09/2021
      Path:/tmp/mirkatclpb.arm
      Arguments:/tmp/mirkatclpb.arm
      File size:4956856 bytes
      MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

      General

      Start time:23:51:25
      Start date:27/09/2021
      Path:/tmp/mirkatclpb.arm
      Arguments:n/a
      File size:4956856 bytes
      MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

      General

      Start time:23:51:25
      Start date:27/09/2021
      Path:/tmp/mirkatclpb.arm
      Arguments:n/a
      File size:4956856 bytes
      MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

      General

      Start time:23:51:25
      Start date:27/09/2021
      Path:/tmp/mirkatclpb.arm
      Arguments:n/a
      File size:4956856 bytes
      MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

      General

      Start time:23:51:25
      Start date:27/09/2021
      Path:/tmp/mirkatclpb.arm
      Arguments:n/a
      File size:4956856 bytes
      MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

      General

      Start time:23:51:25
      Start date:27/09/2021
      Path:/tmp/mirkatclpb.arm
      Arguments:n/a
      File size:4956856 bytes
      MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

      General

      Start time:23:51:25
      Start date:27/09/2021
      Path:/tmp/mirkatclpb.arm
      Arguments:n/a
      File size:4956856 bytes
      MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

      General

      Start time:23:51:40
      Start date:27/09/2021
      Path:/usr/lib/systemd/systemd
      Arguments:n/a
      File size:1620224 bytes
      MD5 hash:9b2bec7092a40488108543f9334aab75

      General

      Start time:23:51:40
      Start date:27/09/2021
      Path:/usr/sbin/sshd
      Arguments:/usr/sbin/sshd -t
      File size:876328 bytes
      MD5 hash:dbca7a6bbf7bf57fedac243d4b2cb340

      General

      Start time:23:51:42
      Start date:27/09/2021
      Path:/usr/lib/systemd/systemd
      Arguments:n/a
      File size:1620224 bytes
      MD5 hash:9b2bec7092a40488108543f9334aab75

      General

      Start time:23:51:42
      Start date:27/09/2021
      Path:/usr/sbin/sshd
      Arguments:/usr/sbin/sshd -D
      File size:876328 bytes
      MD5 hash:dbca7a6bbf7bf57fedac243d4b2cb340

      General

      Start time:23:54:23
      Start date:27/09/2021
      Path:/usr/lib/systemd/systemd
      Arguments:n/a
      File size:1620224 bytes
      MD5 hash:9b2bec7092a40488108543f9334aab75

      General

      Start time:23:54:23
      Start date:27/09/2021
      Path:/usr/sbin/sshd
      Arguments:/usr/sbin/sshd -t
      File size:876328 bytes
      MD5 hash:dbca7a6bbf7bf57fedac243d4b2cb340

      General

      Start time:23:54:24
      Start date:27/09/2021
      Path:/usr/lib/systemd/systemd
      Arguments:n/a
      File size:1620224 bytes
      MD5 hash:9b2bec7092a40488108543f9334aab75

      General

      Start time:23:54:24
      Start date:27/09/2021
      Path:/usr/sbin/sshd
      Arguments:/usr/sbin/sshd -D
      File size:876328 bytes
      MD5 hash:dbca7a6bbf7bf57fedac243d4b2cb340

      General

      Start time:23:54:26
      Start date:27/09/2021
      Path:/usr/lib/systemd/systemd
      Arguments:n/a
      File size:1620224 bytes
      MD5 hash:9b2bec7092a40488108543f9334aab75

      General

      Start time:23:54:26
      Start date:27/09/2021
      Path:/usr/sbin/sshd
      Arguments:/usr/sbin/sshd -t
      File size:876328 bytes
      MD5 hash:dbca7a6bbf7bf57fedac243d4b2cb340

      General

      Start time:23:54:26
      Start date:27/09/2021
      Path:/usr/lib/systemd/systemd
      Arguments:n/a
      File size:1620224 bytes
      MD5 hash:9b2bec7092a40488108543f9334aab75

      General

      Start time:23:54:26
      Start date:27/09/2021
      Path:/usr/sbin/sshd
      Arguments:/usr/sbin/sshd -D
      File size:876328 bytes
      MD5 hash:dbca7a6bbf7bf57fedac243d4b2cb340