Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
oKukKTcgxV

Overview

General Information

Sample Name:oKukKTcgxV
Analysis ID:557425
MD5:5ca61982c3626a6a6317eb28b301c00b
SHA1:ffde6d29d70c9a8471f0b0c86ca1438662183e8a
SHA256:e1250ce224b971ff719ba2532e2de4b317aa90a9f82ddc18843d5d7f9a2b6b39
Tags:32elfmiraimotorola
Infos:

Detection

Mirai
Score:68
Range:0 - 100
Whitelisted:false

Signatures

Snort IDS alert for network traffic (e.g. based on Emerging Threat rules)
Yara detected Mirai
Multi AV Scanner detection for submitted file
Uses known network protocols on non-standard ports
Sample has stripped symbol table
Uses the "uname" system call to query kernel version information (possible evasion)
Enumerates processes within the "proc" file system
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Detected TCP or UDP traffic on non-standard ports
Sample listens on a socket
Sample tries to kill a process (SIGKILL)

Classification

Analysis Advice

All HTTP servers contacted by the sample do not answer. Likely the sample is an old dropper which does no longer work
Static ELF header machine description suggests that the sample might not execute correctly on this machine
Joe Sandbox Version:34.0.0 Boulder Opal
Analysis ID:557425
Start date:21.01.2022
Start time:04:37:19
Joe Sandbox Product:CloudBasic
Overall analysis duration:0h 6m 41s
Hypervisor based Inspection enabled:false
Report type:light
Sample file name:oKukKTcgxV
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Detection:MAL
Classification:mal68.troj.lin@0/0@0/0
  • Report size exceeded maximum capacity and may have missing network information.
  • TCP Packets have been reduced to 100
Command:/tmp/oKukKTcgxV
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
DaddyL33T Infected Your Shit
Standard Error:
  • system is lnxubuntu20
  • cleanup
SourceRuleDescriptionAuthorStrings
dump.pcapJoeSecurity_Mirai_12Yara detected MiraiJoe Security

    Click to jump to signature section

    Show All Signature Results

    AV Detection

    barindex
    Source: oKukKTcgxVVirustotal: Detection: 49%Perma Link
    Source: oKukKTcgxVReversingLabs: Detection: 55%

    Networking

    barindex
    Source: TrafficSnort IDS: 716 INFO TELNET access 223.84.156.86:23 -> 192.168.2.23:34252
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 223.84.156.86:23 -> 192.168.2.23:34252
    Source: TrafficSnort IDS: 2027973 ET EXPLOIT HiSilicon DVR - Default Telnet Root Password Inbound 192.168.2.23:34536 -> 163.20.8.254:23
    Source: TrafficSnort IDS: 716 INFO TELNET access 223.84.156.86:23 -> 192.168.2.23:34322
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 223.84.156.86:23 -> 192.168.2.23:34322
    Source: TrafficSnort IDS: 716 INFO TELNET access 223.84.156.86:23 -> 192.168.2.23:34370
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 223.84.156.86:23 -> 192.168.2.23:34370
    Source: TrafficSnort IDS: 716 INFO TELNET access 223.84.156.86:23 -> 192.168.2.23:34428
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 41.139.199.98:23 -> 192.168.2.23:59412
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 223.84.156.86:23 -> 192.168.2.23:34428
    Source: TrafficSnort IDS: 716 INFO TELNET access 223.84.156.86:23 -> 192.168.2.23:34450
    Source: TrafficSnort IDS: 2027973 ET EXPLOIT HiSilicon DVR - Default Telnet Root Password Inbound 192.168.2.23:56472 -> 201.143.220.133:23
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 201.143.220.133:23 -> 192.168.2.23:56472
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 223.84.156.86:23 -> 192.168.2.23:34450
    Source: TrafficSnort IDS: 716 INFO TELNET access 223.84.156.86:23 -> 192.168.2.23:34472
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 223.13.63.210:23 -> 192.168.2.23:55314
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 223.84.156.86:23 -> 192.168.2.23:34472
    Source: TrafficSnort IDS: 716 INFO TELNET access 223.84.156.86:23 -> 192.168.2.23:34498
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 223.84.156.86:23 -> 192.168.2.23:34498
    Source: TrafficSnort IDS: 716 INFO TELNET access 223.84.156.86:23 -> 192.168.2.23:34554
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 223.84.156.86:23 -> 192.168.2.23:34554
    Source: TrafficSnort IDS: 716 INFO TELNET access 223.84.156.86:23 -> 192.168.2.23:34594
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 223.84.156.86:23 -> 192.168.2.23:34594
    Source: TrafficSnort IDS: 716 INFO TELNET access 46.43.81.150:23 -> 192.168.2.23:49872
    Source: TrafficSnort IDS: 716 INFO TELNET access 223.84.156.86:23 -> 192.168.2.23:34636
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 46.43.81.150:23 -> 192.168.2.23:49872
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 46.43.81.150:23 -> 192.168.2.23:49872
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 223.84.156.86:23 -> 192.168.2.23:34636
    Source: TrafficSnort IDS: 716 INFO TELNET access 46.43.81.150:23 -> 192.168.2.23:49922
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 46.43.81.150:23 -> 192.168.2.23:49922
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 46.43.81.150:23 -> 192.168.2.23:49922
    Source: TrafficSnort IDS: 2027973 ET EXPLOIT HiSilicon DVR - Default Telnet Root Password Inbound 192.168.2.23:57254 -> 201.249.168.9:23
    Source: TrafficSnort IDS: 716 INFO TELNET access 46.43.81.150:23 -> 192.168.2.23:49968
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 46.43.81.150:23 -> 192.168.2.23:49968
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 46.43.81.150:23 -> 192.168.2.23:49968
    Source: TrafficSnort IDS: 716 INFO TELNET access 46.43.81.150:23 -> 192.168.2.23:50010
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 201.227.16.158:23 -> 192.168.2.23:53540
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 201.227.16.158:23 -> 192.168.2.23:53540
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 46.43.81.150:23 -> 192.168.2.23:50010
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 46.43.81.150:23 -> 192.168.2.23:50010
    Source: TrafficSnort IDS: 716 INFO TELNET access 46.43.81.150:23 -> 192.168.2.23:50110
    Source: TrafficSnort IDS: 716 INFO TELNET access 119.112.222.99:23 -> 192.168.2.23:49100
    Source: TrafficSnort IDS: 716 INFO TELNET access 121.161.89.156:23 -> 192.168.2.23:35852
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 46.43.81.150:23 -> 192.168.2.23:50110
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 46.43.81.150:23 -> 192.168.2.23:50110
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 121.161.89.156:23 -> 192.168.2.23:35852
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 121.161.89.156:23 -> 192.168.2.23:35852
    Source: TrafficSnort IDS: 716 INFO TELNET access 46.43.81.150:23 -> 192.168.2.23:50184
    Source: TrafficSnort IDS: 2027973 ET EXPLOIT HiSilicon DVR - Default Telnet Root Password Inbound 192.168.2.23:56152 -> 210.10.143.115:23
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 46.43.81.150:23 -> 192.168.2.23:50184
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 46.43.81.150:23 -> 192.168.2.23:50184
    Source: TrafficSnort IDS: 716 INFO TELNET access 121.161.89.156:23 -> 192.168.2.23:35920
    Source: TrafficSnort IDS: 716 INFO TELNET access 119.112.222.99:23 -> 192.168.2.23:49132
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 121.161.89.156:23 -> 192.168.2.23:35920
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 121.161.89.156:23 -> 192.168.2.23:35920
    Source: TrafficSnort IDS: 716 INFO TELNET access 46.43.81.150:23 -> 192.168.2.23:50258
    Source: TrafficSnort IDS: 716 INFO TELNET access 119.112.222.99:23 -> 192.168.2.23:49276
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 46.43.81.150:23 -> 192.168.2.23:50258
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 46.43.81.150:23 -> 192.168.2.23:50258
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 201.227.16.158:23 -> 192.168.2.23:53832
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 201.227.16.158:23 -> 192.168.2.23:53832
    Source: TrafficSnort IDS: 716 INFO TELNET access 119.112.222.99:23 -> 192.168.2.23:49314
    Source: TrafficSnort IDS: 716 INFO TELNET access 121.161.89.156:23 -> 192.168.2.23:36052
    Source: TrafficSnort IDS: 716 INFO TELNET access 46.43.81.150:23 -> 192.168.2.23:50344
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 121.161.89.156:23 -> 192.168.2.23:36052
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 121.161.89.156:23 -> 192.168.2.23:36052
    Source: TrafficSnort IDS: 716 INFO TELNET access 119.112.222.99:23 -> 192.168.2.23:49350
    Source: TrafficSnort IDS: 2027973 ET EXPLOIT HiSilicon DVR - Default Telnet Root Password Inbound 192.168.2.23:49350 -> 119.112.222.99:23
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 46.43.81.150:23 -> 192.168.2.23:50344
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 46.43.81.150:23 -> 192.168.2.23:50344
    Source: TrafficSnort IDS: 716 INFO TELNET access 119.112.222.99:23 -> 192.168.2.23:49390
    Source: TrafficSnort IDS: 716 INFO TELNET access 121.161.89.156:23 -> 192.168.2.23:36178
    Source: TrafficSnort IDS: 716 INFO TELNET access 46.43.81.150:23 -> 192.168.2.23:50472
    Source: TrafficSnort IDS: 716 INFO TELNET access 119.112.222.99:23 -> 192.168.2.23:49470
    Source: TrafficSnort IDS: 716 INFO TELNET access 46.148.45.209:23 -> 192.168.2.23:43770
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 121.161.89.156:23 -> 192.168.2.23:36178
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 121.161.89.156:23 -> 192.168.2.23:36178
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 46.43.81.150:23 -> 192.168.2.23:50472
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 46.43.81.150:23 -> 192.168.2.23:50472
    Source: TrafficSnort IDS: 716 INFO TELNET access 153.201.89.42:23 -> 192.168.2.23:40488
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 60.171.241.43:23 -> 192.168.2.23:46126
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 60.171.241.43:23 -> 192.168.2.23:46126
    Source: TrafficSnort IDS: 404 ICMP Destination Unreachable Protocol Unreachable 83.148.236.126: -> 192.168.2.23:
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 110.225.224.254:23 -> 192.168.2.23:40780
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 110.225.224.254:23 -> 192.168.2.23:40780
    Source: TrafficSnort IDS: 716 INFO TELNET access 119.112.222.99:23 -> 192.168.2.23:49536
    Source: TrafficSnort IDS: 716 INFO TELNET access 153.201.89.42:23 -> 192.168.2.23:40550
    Source: TrafficSnort IDS: 716 INFO TELNET access 153.201.89.42:23 -> 192.168.2.23:40580
    Source: TrafficSnort IDS: 716 INFO TELNET access 153.201.89.42:23 -> 192.168.2.23:40610
    Source: TrafficSnort IDS: 716 INFO TELNET access 125.93.192.47:23 -> 192.168.2.23:55888
    Source: TrafficSnort IDS: 716 INFO TELNET access 46.43.81.150:23 -> 192.168.2.23:50648
    Source: TrafficSnort IDS: 716 INFO TELNET access 153.201.89.42:23 -> 192.168.2.23:40630
    Source: TrafficSnort IDS: 716 INFO TELNET access 119.112.222.99:23 -> 192.168.2.23:49644
    Source: TrafficSnort IDS: 716 INFO TELNET access 121.161.89.156:23 -> 192.168.2.23:36398
    Source: TrafficSnort IDS: 716 INFO TELNET access 153.201.89.42:23 -> 192.168.2.23:40664
    Source: TrafficSnort IDS: 716 INFO TELNET access 153.201.89.42:23 -> 192.168.2.23:40676
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 125.93.192.47:23 -> 192.168.2.23:55888
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 46.43.81.150:23 -> 192.168.2.23:50648
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 46.43.81.150:23 -> 192.168.2.23:50648
    Source: TrafficSnort IDS: 716 INFO TELNET access 153.201.89.42:23 -> 192.168.2.23:40708
    Source: TrafficSnort IDS: 716 INFO TELNET access 153.201.89.42:23 -> 192.168.2.23:40754
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 121.161.89.156:23 -> 192.168.2.23:36398
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 121.161.89.156:23 -> 192.168.2.23:36398
    Source: TrafficSnort IDS: 716 INFO TELNET access 119.112.222.99:23 -> 192.168.2.23:49798
    Source: TrafficSnort IDS: 716 INFO TELNET access 153.201.89.42:23 -> 192.168.2.23:40810
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 47.181.103.153:23 -> 192.168.2.23:37648
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 47.181.103.153:23 -> 192.168.2.23:37648
    Source: TrafficSnort IDS: 716 INFO TELNET access 125.93.192.47:23 -> 192.168.2.23:56090
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 60.171.241.43:23 -> 192.168.2.23:46338
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 60.171.241.43:23 -> 192.168.2.23:46338
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 59.28.36.54:23 -> 192.168.2.23:58384
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 59.28.36.54:23 -> 192.168.2.23:58384
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 125.93.192.47:23 -> 192.168.2.23:56090
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 201.227.16.158:23 -> 192.168.2.23:54428
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 201.227.16.158:23 -> 192.168.2.23:54428
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 36.65.75.239:23 -> 192.168.2.23:44246
    Source: TrafficSnort IDS: 716 INFO TELNET access 125.93.192.47:23 -> 192.168.2.23:56190
    Source: TrafficSnort IDS: 716 INFO TELNET access 121.161.89.156:23 -> 192.168.2.23:36672
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 125.93.192.47:23 -> 192.168.2.23:56190
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 121.161.89.156:23 -> 192.168.2.23:36672
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 121.161.89.156:23 -> 192.168.2.23:36672
    Source: TrafficSnort IDS: 716 INFO TELNET access 106.243.74.174:23 -> 192.168.2.23:43714
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 47.181.103.153:23 -> 192.168.2.23:37922
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 47.181.103.153:23 -> 192.168.2.23:37922
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 59.28.36.54:23 -> 192.168.2.23:58668
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 59.28.36.54:23 -> 192.168.2.23:58668
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 60.171.241.43:23 -> 192.168.2.23:46634
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 60.171.241.43:23 -> 192.168.2.23:46634
    Source: TrafficSnort IDS: 716 INFO TELNET access 125.93.192.47:23 -> 192.168.2.23:56272
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 177.87.68.118:23 -> 192.168.2.23:58160
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 177.87.68.118:23 -> 192.168.2.23:58160
    Source: TrafficSnort IDS: 2027973 ET EXPLOIT HiSilicon DVR - Default Telnet Root Password Inbound 192.168.2.23:56272 -> 125.93.192.47:23
    Source: TrafficSnort IDS: 716 INFO TELNET access 46.148.45.209:23 -> 192.168.2.23:44324
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 125.93.192.47:23 -> 192.168.2.23:56272
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 44276
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 44280
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 44282
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 44286
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 44292
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 44294
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 44296
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 44302
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 44304
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 44308
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 48124
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 48130
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 48138
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 48142
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 48180
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 48184
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 48190
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 48192
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 48194
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 48202
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 41660
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 41662
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 41666
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 41672
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 41678
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 41692
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 41708
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 41716
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 41718
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 41722
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 60138
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 60142
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 60148
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 60154
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 60160
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 60170
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 60182
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 60196
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 60200
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 60206
    Source: global trafficTCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
    Source: global trafficTCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
    Source: global trafficTCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
    Source: global trafficTCP traffic: 192.168.2.23:59584 -> 45.88.181.48:420
    Source: /tmp/oKukKTcgxV (PID: 5220)Socket: 0.0.0.0::0
    Source: /tmp/oKukKTcgxV (PID: 5226)Socket: 0.0.0.0::0
    Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443
    Source: unknownTCP traffic detected without corresponding DNS query: 45.88.181.48
    Source: unknownTCP traffic detected without corresponding DNS query: 207.113.52.250
    Source: unknownTCP traffic detected without corresponding DNS query: 201.70.4.250
    Source: unknownTCP traffic detected without corresponding DNS query: 76.236.252.105
    Source: unknownTCP traffic detected without corresponding DNS query: 58.226.131.74
    Source: unknownTCP traffic detected without corresponding DNS query: 105.233.1.110
    Source: unknownTCP traffic detected without corresponding DNS query: 151.55.201.50
    Source: unknownTCP traffic detected without corresponding DNS query: 138.213.114.78
    Source: unknownTCP traffic detected without corresponding DNS query: 197.96.89.107
    Source: unknownTCP traffic detected without corresponding DNS query: 40.42.3.64
    Source: unknownTCP traffic detected without corresponding DNS query: 197.93.170.176
    Source: unknownTCP traffic detected without corresponding DNS query: 147.255.122.60
    Source: unknownTCP traffic detected without corresponding DNS query: 164.199.129.100
    Source: unknownTCP traffic detected without corresponding DNS query: 163.180.126.127
    Source: unknownTCP traffic detected without corresponding DNS query: 164.25.83.183
    Source: unknownTCP traffic detected without corresponding DNS query: 162.179.224.235
    Source: unknownTCP traffic detected without corresponding DNS query: 60.243.149.221
    Source: unknownTCP traffic detected without corresponding DNS query: 31.189.66.165
    Source: unknownTCP traffic detected without corresponding DNS query: 126.164.233.51
    Source: unknownTCP traffic detected without corresponding DNS query: 180.71.167.183
    Source: unknownTCP traffic detected without corresponding DNS query: 139.177.81.128
    Source: unknownTCP traffic detected without corresponding DNS query: 162.248.239.245
    Source: unknownTCP traffic detected without corresponding DNS query: 85.124.192.213
    Source: unknownTCP traffic detected without corresponding DNS query: 179.221.149.60
    Source: unknownTCP traffic detected without corresponding DNS query: 34.90.84.202
    Source: unknownTCP traffic detected without corresponding DNS query: 206.121.154.70
    Source: unknownTCP traffic detected without corresponding DNS query: 39.193.246.9
    Source: unknownTCP traffic detected without corresponding DNS query: 12.228.206.205
    Source: unknownTCP traffic detected without corresponding DNS query: 251.179.20.180
    Source: unknownTCP traffic detected without corresponding DNS query: 8.141.61.249
    Source: unknownTCP traffic detected without corresponding DNS query: 180.51.22.138
    Source: unknownTCP traffic detected without corresponding DNS query: 27.144.21.206
    Source: unknownTCP traffic detected without corresponding DNS query: 34.39.144.126
    Source: unknownTCP traffic detected without corresponding DNS query: 203.135.193.89
    Source: unknownTCP traffic detected without corresponding DNS query: 98.253.228.202
    Source: unknownTCP traffic detected without corresponding DNS query: 60.25.233.210
    Source: unknownTCP traffic detected without corresponding DNS query: 220.201.185.122
    Source: unknownTCP traffic detected without corresponding DNS query: 91.34.6.106
    Source: unknownTCP traffic detected without corresponding DNS query: 170.194.232.15
    Source: unknownTCP traffic detected without corresponding DNS query: 90.45.224.213
    Source: unknownTCP traffic detected without corresponding DNS query: 213.192.194.67
    Source: unknownTCP traffic detected without corresponding DNS query: 92.145.29.117
    Source: unknownTCP traffic detected without corresponding DNS query: 133.76.106.179
    Source: unknownTCP traffic detected without corresponding DNS query: 43.249.194.223
    Source: unknownTCP traffic detected without corresponding DNS query: 9.116.56.236
    Source: unknownTCP traffic detected without corresponding DNS query: 189.221.133.22
    Source: unknownTCP traffic detected without corresponding DNS query: 107.148.165.246
    Source: unknownTCP traffic detected without corresponding DNS query: 16.27.229.69
    Source: unknownTCP traffic detected without corresponding DNS query: 88.166.126.226
    Source: unknownTCP traffic detected without corresponding DNS query: 195.148.16.89
    Source: ELF static info symbol of initial sample.symtab present: no
    Source: /tmp/oKukKTcgxV (PID: 5220)SIGKILL sent: pid: 936, result: successful
    Source: /tmp/oKukKTcgxV (PID: 5226)SIGKILL sent: pid: 936, result: successful
    Source: classification engineClassification label: mal68.troj.lin@0/0@0/0
    Source: /tmp/oKukKTcgxV (PID: 5220)File opened: /proc/491/fd
    Source: /tmp/oKukKTcgxV (PID: 5220)File opened: /proc/793/fd
    Source: /tmp/oKukKTcgxV (PID: 5220)File opened: /proc/772/fd
    Source: /tmp/oKukKTcgxV (PID: 5220)File opened: /proc/796/fd
    Source: /tmp/oKukKTcgxV (PID: 5220)File opened: /proc/774/fd
    Source: /tmp/oKukKTcgxV (PID: 5220)File opened: /proc/797/fd
    Source: /tmp/oKukKTcgxV (PID: 5220)File opened: /proc/777/fd
    Source: /tmp/oKukKTcgxV (PID: 5220)File opened: /proc/799/fd
    Source: /tmp/oKukKTcgxV (PID: 5220)File opened: /proc/658/fd
    Source: /tmp/oKukKTcgxV (PID: 5220)File opened: /proc/912/fd
    Source: /tmp/oKukKTcgxV (PID: 5220)File opened: /proc/759/fd
    Source: /tmp/oKukKTcgxV (PID: 5220)File opened: /proc/936/fd
    Source: /tmp/oKukKTcgxV (PID: 5220)File opened: /proc/918/fd
    Source: /tmp/oKukKTcgxV (PID: 5220)File opened: /proc/1/fd
    Source: /tmp/oKukKTcgxV (PID: 5220)File opened: /proc/761/fd
    Source: /tmp/oKukKTcgxV (PID: 5220)File opened: /proc/785/fd
    Source: /tmp/oKukKTcgxV (PID: 5220)File opened: /proc/884/fd
    Source: /tmp/oKukKTcgxV (PID: 5220)File opened: /proc/720/fd
    Source: /tmp/oKukKTcgxV (PID: 5220)File opened: /proc/721/fd
    Source: /tmp/oKukKTcgxV (PID: 5220)File opened: /proc/788/fd
    Source: /tmp/oKukKTcgxV (PID: 5220)File opened: /proc/789/fd
    Source: /tmp/oKukKTcgxV (PID: 5220)File opened: /proc/800/fd
    Source: /tmp/oKukKTcgxV (PID: 5220)File opened: /proc/801/fd
    Source: /tmp/oKukKTcgxV (PID: 5220)File opened: /proc/847/fd
    Source: /tmp/oKukKTcgxV (PID: 5220)File opened: /proc/904/fd
    Source: /tmp/oKukKTcgxV (PID: 5226)File opened: /proc/491/fd
    Source: /tmp/oKukKTcgxV (PID: 5226)File opened: /proc/793/fd
    Source: /tmp/oKukKTcgxV (PID: 5226)File opened: /proc/772/fd
    Source: /tmp/oKukKTcgxV (PID: 5226)File opened: /proc/796/fd
    Source: /tmp/oKukKTcgxV (PID: 5226)File opened: /proc/774/fd
    Source: /tmp/oKukKTcgxV (PID: 5226)File opened: /proc/797/fd
    Source: /tmp/oKukKTcgxV (PID: 5226)File opened: /proc/777/fd
    Source: /tmp/oKukKTcgxV (PID: 5226)File opened: /proc/799/fd
    Source: /tmp/oKukKTcgxV (PID: 5226)File opened: /proc/658/fd
    Source: /tmp/oKukKTcgxV (PID: 5226)File opened: /proc/912/fd
    Source: /tmp/oKukKTcgxV (PID: 5226)File opened: /proc/759/fd
    Source: /tmp/oKukKTcgxV (PID: 5226)File opened: /proc/936/fd
    Source: /tmp/oKukKTcgxV (PID: 5226)File opened: /proc/918/fd
    Source: /tmp/oKukKTcgxV (PID: 5226)File opened: /proc/1/fd
    Source: /tmp/oKukKTcgxV (PID: 5226)File opened: /proc/761/fd
    Source: /tmp/oKukKTcgxV (PID: 5226)File opened: /proc/785/fd
    Source: /tmp/oKukKTcgxV (PID: 5226)File opened: /proc/884/fd
    Source: /tmp/oKukKTcgxV (PID: 5226)File opened: /proc/720/fd
    Source: /tmp/oKukKTcgxV (PID: 5226)File opened: /proc/721/fd
    Source: /tmp/oKukKTcgxV (PID: 5226)File opened: /proc/788/fd
    Source: /tmp/oKukKTcgxV (PID: 5226)File opened: /proc/789/fd
    Source: /tmp/oKukKTcgxV (PID: 5226)File opened: /proc/800/fd
    Source: /tmp/oKukKTcgxV (PID: 5226)File opened: /proc/801/fd
    Source: /tmp/oKukKTcgxV (PID: 5226)File opened: /proc/847/fd
    Source: /tmp/oKukKTcgxV (PID: 5226)File opened: /proc/904/fd

    Hooking and other Techniques for Hiding and Protection

    barindex
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 44276
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 44280
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 44282
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 44286
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 44292
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 44294
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 44296
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 44302
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 44304
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 44308
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 48124
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 48130
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 48138
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 48142
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 48180
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 48184
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 48190
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 48192
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 48194
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 48202
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 41660
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 41662
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 41666
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 41672
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 41678
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 41692
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 41708
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 41716
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 41718
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 41722
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 60138
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 60142
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 60148
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 60154
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 60160
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 60170
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 60182
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 60196
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 60200
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 60206
    Source: /tmp/oKukKTcgxV (PID: 5218)Queries kernel information via 'uname':
    Source: oKukKTcgxV, 5218.1.000000001b10963a.00000000395e0ea2.rw-.sdmp, oKukKTcgxV, 5220.1.000000001b10963a.00000000395e0ea2.rw-.sdmp, oKukKTcgxV, 5318.1.000000001b10963a.00000000395e0ea2.rw-.sdmp, oKukKTcgxV, 5335.1.000000001b10963a.00000000395e0ea2.rw-.sdmp, oKukKTcgxV, 5328.1.000000001b10963a.00000000395e0ea2.rw-.sdmp, oKukKTcgxV, 5221.1.000000001b10963a.00000000395e0ea2.rw-.sdmp, oKukKTcgxV, 5319.1.000000001b10963a.00000000395e0ea2.rw-.sdmp, oKukKTcgxV, 5227.1.000000001b10963a.00000000395e0ea2.rw-.sdmpBinary or memory string: /usr/bin/qemu-m68k
    Source: oKukKTcgxV, 5218.1.000000001b10963a.00000000395e0ea2.rw-.sdmp, oKukKTcgxV, 5220.1.000000001b10963a.00000000395e0ea2.rw-.sdmp, oKukKTcgxV, 5318.1.000000001b10963a.00000000395e0ea2.rw-.sdmp, oKukKTcgxV, 5335.1.000000001b10963a.00000000395e0ea2.rw-.sdmp, oKukKTcgxV, 5328.1.000000001b10963a.00000000395e0ea2.rw-.sdmp, oKukKTcgxV, 5221.1.000000001b10963a.00000000395e0ea2.rw-.sdmp, oKukKTcgxV, 5319.1.000000001b10963a.00000000395e0ea2.rw-.sdmp, oKukKTcgxV, 5227.1.000000001b10963a.00000000395e0ea2.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-m68k/tmp/oKukKTcgxVSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/oKukKTcgxV
    Source: oKukKTcgxV, 5218.1.0000000046d61b23.0000000064d68725.rw-.sdmp, oKukKTcgxV, 5220.1.0000000046d61b23.0000000064d68725.rw-.sdmp, oKukKTcgxV, 5318.1.0000000046d61b23.0000000064d68725.rw-.sdmp, oKukKTcgxV, 5335.1.0000000046d61b23.0000000064d68725.rw-.sdmp, oKukKTcgxV, 5328.1.0000000046d61b23.0000000064d68725.rw-.sdmp, oKukKTcgxV, 5221.1.0000000046d61b23.0000000064d68725.rw-.sdmp, oKukKTcgxV, 5319.1.0000000046d61b23.0000000064d68725.rw-.sdmp, oKukKTcgxV, 5227.1.0000000046d61b23.0000000064d68725.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/m68k
    Source: oKukKTcgxV, 5218.1.0000000046d61b23.0000000064d68725.rw-.sdmp, oKukKTcgxV, 5220.1.0000000046d61b23.0000000064d68725.rw-.sdmp, oKukKTcgxV, 5318.1.0000000046d61b23.0000000064d68725.rw-.sdmp, oKukKTcgxV, 5335.1.0000000046d61b23.0000000064d68725.rw-.sdmp, oKukKTcgxV, 5328.1.0000000046d61b23.0000000064d68725.rw-.sdmp, oKukKTcgxV, 5221.1.0000000046d61b23.0000000064d68725.rw-.sdmp, oKukKTcgxV, 5319.1.0000000046d61b23.0000000064d68725.rw-.sdmp, oKukKTcgxV, 5227.1.0000000046d61b23.0000000064d68725.rw-.sdmpBinary or memory string: V!/etc/qemu-binfmt/m68k

    Stealing of Sensitive Information

    barindex
    Source: Yara matchFile source: dump.pcap, type: PCAP

    Remote Access Functionality

    barindex
    Source: Yara matchFile source: dump.pcap, type: PCAP
    Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
    Valid AccountsWindows Management InstrumentationPath InterceptionPath InterceptionDirect Volume Access1
    OS Credential Dumping
    11
    Security Software Discovery
    Remote ServicesData from Local SystemExfiltration Over Other Network Medium1
    Encrypted Channel
    Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
    Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over Bluetooth11
    Non-Standard Port
    Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
    Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated Exfiltration1
    Application Layer Protocol
    Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
    No configs have been found
    Hide Legend

    Legend:

    • Process
    • Signature
    • Created File
    • DNS/IP Info
    • Is Dropped
    • Number of created Files
    • Is malicious
    • Internet
    behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 557425 Sample: oKukKTcgxV Startdate: 21/01/2022 Architecture: LINUX Score: 68 42 219.115.43.189 ZAQJupiterTelecommunicationsCoLtdJP Japan 2->42 44 114.195.229.235 XEPHIONNTT-MECorporationJP Japan 2->44 46 98 other IPs or domains 2->46 48 Snort IDS alert for network traffic (e.g. based on Emerging Threat rules) 2->48 50 Multi AV Scanner detection for submitted file 2->50 52 Yara detected Mirai 2->52 54 Uses known network protocols on non-standard ports 2->54 10 oKukKTcgxV 2->10         started        signatures3 process4 process5 12 oKukKTcgxV 10->12         started        14 oKukKTcgxV 10->14         started        16 oKukKTcgxV 10->16         started        process6 18 oKukKTcgxV 12->18         started        20 oKukKTcgxV 12->20         started        22 oKukKTcgxV 14->22         started        24 oKukKTcgxV 14->24         started        26 oKukKTcgxV 14->26         started        process7 28 oKukKTcgxV 18->28         started        30 oKukKTcgxV 18->30         started        32 oKukKTcgxV 18->32         started        34 oKukKTcgxV 22->34         started        36 oKukKTcgxV 22->36         started        process8 38 oKukKTcgxV 28->38         started        40 oKukKTcgxV 28->40         started       
    SourceDetectionScannerLabelLink
    oKukKTcgxV49%VirustotalBrowse
    oKukKTcgxV56%ReversingLabsLinux.Trojan.Mirai
    No Antivirus matches
    No Antivirus matches
    No Antivirus matches
    No contacted domains info
    • No. of IPs < 25%
    • 25% < No. of IPs < 50%
    • 50% < No. of IPs < 75%
    • 75% < No. of IPs
    IPDomainCountryFlagASNASN NameMalicious
    87.178.105.232
    unknownGermany
    3320DTAGInternetserviceprovideroperationsDEfalse
    201.238.73.157
    unknownTrinidad and Tobago
    5639TelecommunicationServicesofTrinidadandTobagoTTfalse
    98.45.237.215
    unknownUnited States
    7922COMCAST-7922USfalse
    61.238.120.145
    unknownHong Kong
    10103HKBN-AS-APHKBroadbandNetworkLtdHKfalse
    87.90.192.199
    unknownFrance
    5410BOUYGTEL-ISPFRfalse
    24.163.73.173
    unknownUnited States
    11426TWC-11426-CAROLINASUSfalse
    208.7.208.76
    unknownUnited States
    5778CENTURYLINK-LEGACY-EMBARQ-RCMTUSfalse
    160.20.71.196
    unknownBrazil
    266146I9TelecomBRfalse
    220.242.193.145
    unknownChina
    54994QUANTILNETWORKSUSfalse
    158.56.76.54
    unknownUnited States
    32577KROGERUSfalse
    162.138.241.67
    unknownUnited States
    26229US-SECUSfalse
    31.63.90.209
    unknownPoland
    5617TPNETPLfalse
    115.163.3.19
    unknownJapan2527SO-NETSo-netEntertainmentCorporationJPfalse
    254.126.128.179
    unknownReserved
    unknownunknownfalse
    17.246.210.159
    unknownUnited States
    714APPLE-ENGINEERINGUSfalse
    125.138.168.93
    unknownKorea Republic of
    4766KIXS-AS-KRKoreaTelecomKRfalse
    188.98.111.150
    unknownGermany
    3209VODANETInternationalIP-BackboneofVodafoneDEfalse
    73.193.212.197
    unknownUnited States
    7922COMCAST-7922USfalse
    174.49.111.97
    unknownUnited States
    7922COMCAST-7922USfalse
    94.58.218.209
    unknownUnited Arab Emirates
    5384EMIRATES-INTERNETEmiratesInternetAEfalse
    253.206.239.115
    unknownReserved
    unknownunknownfalse
    45.145.30.151
    unknownTurkey
    197328INETLTDTRfalse
    117.119.192.198
    unknownChina
    4847CNIX-APChinaNetworksInter-ExchangeCNfalse
    1.168.57.177
    unknownTaiwan; Republic of China (ROC)
    3462HINETDataCommunicationBusinessGroupTWfalse
    17.34.22.45
    unknownUnited States
    714APPLE-ENGINEERINGUSfalse
    46.93.81.106
    unknownGermany
    3320DTAGInternetserviceprovideroperationsDEfalse
    219.115.43.189
    unknownJapan9617ZAQJupiterTelecommunicationsCoLtdJPfalse
    124.67.174.18
    unknownChina
    4837CHINA169-BACKBONECHINAUNICOMChina169BackboneCNfalse
    4.166.177.80
    unknownUnited States
    3356LEVEL3USfalse
    73.115.126.227
    unknownUnited States
    7922COMCAST-7922USfalse
    46.202.131.132
    unknownUkraine
    6877AS6877UAfalse
    20.3.3.115
    unknownUnited States
    8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
    120.139.14.125
    unknownMalaysia
    38322WEBE-MY-AS-APWEBEDIGITALSDNBHDMYfalse
    94.159.171.133
    unknownIsrael
    12400PARTNER-ASILfalse
    240.22.210.193
    unknownReserved
    unknownunknownfalse
    78.67.219.214
    unknownSweden
    3301TELIANET-SWEDENTeliaCompanySEfalse
    18.208.17.53
    unknownUnited States
    14618AMAZON-AESUSfalse
    221.8.138.8
    unknownChina
    4837CHINA169-BACKBONECHINAUNICOMChina169BackboneCNfalse
    73.125.49.108
    unknownUnited States
    7922COMCAST-7922USfalse
    123.72.218.85
    unknownChina
    9394CTTNETChinaTieTongTelecommunicationsCorporationCNfalse
    141.179.178.73
    unknownSaudi Arabia
    197921HBTFJOfalse
    162.129.150.111
    unknownUnited States
    5723JHUUSfalse
    179.29.8.245
    unknownUruguay
    6057AdministracionNacionaldeTelecomunicacionesUYfalse
    203.239.210.179
    unknownKorea Republic of
    9524HMC-ASAutoEverSystemsCorpKRfalse
    59.216.130.118
    unknownChina
    2516KDDIKDDICORPORATIONJPfalse
    105.181.97.103
    unknownEgypt
    37069MOBINILEGfalse
    48.142.166.164
    unknownUnited States
    2686ATGS-MMD-ASUSfalse
    177.180.36.51
    unknownBrazil
    28573CLAROSABRfalse
    69.17.129.60
    unknownCanada
    812ROGERS-COMMUNICATIONSCAfalse
    210.65.20.211
    unknownTaiwan; Republic of China (ROC)
    3462HINETDataCommunicationBusinessGroupTWfalse
    146.158.247.125
    unknownSpain
    12479UNI2-ASESfalse
    243.125.138.235
    unknownReserved
    unknownunknownfalse
    198.15.24.95
    unknownunknown
    53823SMTAUSfalse
    172.89.139.42
    unknownUnited States
    20001TWC-20001-PACWESTUSfalse
    254.252.138.151
    unknownReserved
    unknownunknownfalse
    103.29.16.191
    unknownChina
    4808CHINA169-BJChinaUnicomBeijingProvinceNetworkCNfalse
    39.156.153.72
    unknownChina
    9808CMNET-GDGuangdongMobileCommunicationCoLtdCNfalse
    136.76.251.132
    unknownUnited States
    60311ONEFMCHfalse
    97.46.211.173
    unknownUnited States
    22394CELLCOUSfalse
    248.15.245.77
    unknownReserved
    unknownunknownfalse
    196.233.130.49
    unknownTunisia
    37492ORANGE-TNfalse
    151.179.132.97
    unknownUnited States
    45025EDN-ASUAfalse
    179.3.182.229
    unknownChile
    27836SmartcomCLfalse
    203.82.90.135
    unknownMalaysia
    10030CELCOMNET-APCelcomAxiataBerhadMYfalse
    47.142.207.252
    unknownUnited States
    5650FRONTIER-FRTRUSfalse
    60.53.67.247
    unknownMalaysia
    4788TMNET-AS-APTMNetInternetServiceProviderMYfalse
    87.173.108.228
    unknownGermany
    3320DTAGInternetserviceprovideroperationsDEfalse
    5.149.171.110
    unknownIreland
    199256LTH-ASIEfalse
    156.55.53.187
    unknownUnited States
    22146LANDAMUSfalse
    36.208.187.89
    unknownChina
    9394CTTNETChinaTieTongTelecommunicationsCorporationCNfalse
    34.225.88.139
    unknownUnited States
    14618AMAZON-AESUSfalse
    61.255.138.227
    unknownKorea Republic of
    9318SKB-ASSKBroadbandCoLtdKRfalse
    180.73.236.247
    unknownMalaysia
    38322WEBE-MY-AS-APWEBEDIGITALSDNBHDMYfalse
    24.138.125.167
    unknownCanada
    5690VIANET-NOCAfalse
    219.205.35.83
    unknownJapan17676GIGAINFRASoftbankBBCorpJPfalse
    200.26.11.61
    unknownArgentina
    10834TelefonicadeArgentinaARfalse
    114.195.229.235
    unknownJapan9595XEPHIONNTT-MECorporationJPfalse
    149.120.38.127
    unknownUnited States
    174COGENT-174USfalse
    88.61.50.242
    unknownItaly
    3269ASN-IBSNAZITfalse
    80.236.69.38
    unknownFrance
    21502ASN-NUMERICABLEFRfalse
    182.101.83.74
    unknownChina
    4134CHINANET-BACKBONENo31Jin-rongStreetCNfalse
    152.204.126.179
    unknownColombia
    3816COLOMBIATELECOMUNICACIONESSAESPCOfalse
    111.105.27.147
    unknownJapan2516KDDIKDDICORPORATIONJPfalse
    254.79.34.34
    unknownReserved
    unknownunknownfalse
    255.108.231.35
    unknownReserved
    unknownunknownfalse
    57.242.191.202
    unknownBelgium
    2686ATGS-MMD-ASUSfalse
    159.249.187.130
    unknownUnited States
    29899GEISINGERUSfalse
    63.175.2.187
    unknownUnited States
    18618WCENTRALNUSfalse
    47.148.105.15
    unknownUnited States
    5650FRONTIER-FRTRUSfalse
    35.45.255.30
    unknownUnited States
    36375UMICH-AS-5USfalse
    216.224.252.94
    unknownUnited States
    39948INIT-PHXUSfalse
    246.77.91.71
    unknownReserved
    unknownunknownfalse
    197.231.80.80
    unknownGabon
    37582ANINFGAfalse
    172.114.8.196
    unknownUnited States
    20001TWC-20001-PACWESTUSfalse
    222.198.149.227
    unknownChina
    4538ERX-CERNET-BKBChinaEducationandResearchNetworkCenterfalse
    179.154.27.220
    unknownBrazil
    28573CLAROSABRfalse
    189.225.7.203
    unknownMexico
    8151UninetSAdeCVMXfalse
    110.111.162.76
    unknownChina
    38341CNNIC-HCENET-APHEXIEInformationtechnologyCoLtdCNfalse
    176.199.129.103
    unknownGermany
    6830LIBERTYGLOBALLibertyGlobalformerlyUPCBroadbandHoldingfalse
    47.136.192.219
    unknownUnited States
    5650FRONTIER-FRTRUSfalse
    No context
    No context
    No context
    No context
    No context
    No created / dropped files found
    File type:ELF 32-bit MSB executable, Motorola m68k, 68020, version 1 (SYSV), statically linked, stripped
    Entropy (8bit):6.211114798485053
    TrID:
    • ELF Executable and Linkable format (generic) (4004/1) 100.00%
    File name:oKukKTcgxV
    File size:52884
    MD5:5ca61982c3626a6a6317eb28b301c00b
    SHA1:ffde6d29d70c9a8471f0b0c86ca1438662183e8a
    SHA256:e1250ce224b971ff719ba2532e2de4b317aa90a9f82ddc18843d5d7f9a2b6b39
    SHA512:7b0c1320e4193773c89e2b0cdbdcc9ad3f4ff9fae34e4debf378ec1070ee141ee5a1cbc6029d727aa2b9c56df4fd932db2e4b942ecf35b5029ce4ac3e121994e
    SSDEEP:768:wjeK74YNIHchFK0076BhBQeJF/gFHw5/Sfu3We/npgajRJT2YOnI8FL:8FMYiHcHGVFwtSW3pRgajRJiYOI85
    File Content Preview:.ELF.......................D...4.........4. ...(.......................N...N...... ........T...T...T...p.......... .dt.Q............................NV..a....da....<N^NuNV..J9....f>"y...l QJ.g.X.#....lN."y...l QJ.f.A.....J.g.Hy...PN.X.........N^NuNV..N^NuN

    ELF header

    Class:ELF32
    Data:2's complement, big endian
    Version:1 (current)
    Machine:MC68000
    Version Number:0x1
    Type:EXEC (Executable file)
    OS/ABI:UNIX - System V
    ABI Version:0
    Entry Point Address:0x80000144
    Flags:0x0
    ELF Header Size:52
    Program Header Offset:52
    Program Header Size:32
    Number of Program Headers:3
    Section Header Offset:52484
    Section Header Size:40
    Number of Section Headers:10
    Header String Table Index:9
    NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
    NULL0x00x00x00x00x0000
    .initPROGBITS0x800000940x940x140x00x6AX002
    .textPROGBITS0x800000a80xa80xc5660x00x6AX004
    .finiPROGBITS0x8000c60e0xc60e0xe0x00x6AX002
    .rodataPROGBITS0x8000c61c0xc61c0x5320x00x2A002
    .ctorsPROGBITS0x8000eb540xcb540x80x00x3WA004
    .dtorsPROGBITS0x8000eb5c0xcb5c0x80x00x3WA004
    .dataPROGBITS0x8000eb680xcb680x15c0x00x3WA004
    .bssNOBITS0x8000ecc40xccc40x23c0x00x3WA004
    .shstrtabSTRTAB0x00xccc40x3e0x00x0001
    TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
    LOAD0x00x800000000x800000000xcb4e0xcb4e4.24050x5R E0x2000.init .text .fini .rodata
    LOAD0xcb540x8000eb540x8000eb540x1700x3ac0.31840x6RW 0x2000.ctors .dtors .data .bss
    GNU_STACK0x00x00x00x00x00.00000x6RW 0x4
    TimestampSource PortDest PortSource IPDest IP
    Jan 21, 2022 04:38:01.892458916 CET59584420192.168.2.2345.88.181.48
    Jan 21, 2022 04:38:01.907440901 CET2453023192.168.2.23207.113.52.250
    Jan 21, 2022 04:38:01.907754898 CET2453023192.168.2.23201.70.4.250
    Jan 21, 2022 04:38:01.907766104 CET2453023192.168.2.2376.236.252.105
    Jan 21, 2022 04:38:01.907855034 CET2453023192.168.2.2358.226.131.74
    Jan 21, 2022 04:38:01.907876015 CET2453023192.168.2.23105.233.1.110
    Jan 21, 2022 04:38:01.907881021 CET2453023192.168.2.23151.55.201.50
    Jan 21, 2022 04:38:01.907928944 CET2453023192.168.2.23138.213.114.78
    Jan 21, 2022 04:38:01.907980919 CET2453023192.168.2.23197.96.89.107
    Jan 21, 2022 04:38:01.908004999 CET2453023192.168.2.2340.42.3.64
    Jan 21, 2022 04:38:01.908006907 CET2453023192.168.2.23197.93.170.176
    Jan 21, 2022 04:38:01.908010960 CET2453023192.168.2.23147.255.122.60
    Jan 21, 2022 04:38:01.908011913 CET2453023192.168.2.23164.199.129.100
    Jan 21, 2022 04:38:01.908030033 CET2453023192.168.2.23163.180.126.127
    Jan 21, 2022 04:38:01.908030033 CET2453023192.168.2.23164.25.83.183
    Jan 21, 2022 04:38:01.908037901 CET2453023192.168.2.23162.179.224.235
    Jan 21, 2022 04:38:01.908039093 CET2453023192.168.2.2360.243.149.221
    Jan 21, 2022 04:38:01.908041000 CET2453023192.168.2.2331.189.66.165
    Jan 21, 2022 04:38:01.908065081 CET2453023192.168.2.23126.164.233.51
    Jan 21, 2022 04:38:01.908068895 CET2453023192.168.2.23180.71.167.183
    Jan 21, 2022 04:38:01.908077002 CET2453023192.168.2.23139.177.81.128
    Jan 21, 2022 04:38:01.908077955 CET2453023192.168.2.23162.248.239.245
    Jan 21, 2022 04:38:01.908082008 CET2453023192.168.2.2385.124.192.213
    Jan 21, 2022 04:38:01.908097029 CET2453023192.168.2.23179.221.149.60
    Jan 21, 2022 04:38:01.908107996 CET2453023192.168.2.2334.90.84.202
    Jan 21, 2022 04:38:01.908202887 CET2453023192.168.2.23206.121.154.70
    Jan 21, 2022 04:38:01.908221960 CET2453023192.168.2.2339.193.246.9
    Jan 21, 2022 04:38:01.908224106 CET2453023192.168.2.2312.228.206.205
    Jan 21, 2022 04:38:01.908227921 CET2453023192.168.2.23251.179.20.180
    Jan 21, 2022 04:38:01.908231974 CET2453023192.168.2.238.141.61.249
    Jan 21, 2022 04:38:01.908233881 CET2453023192.168.2.23180.51.22.138
    Jan 21, 2022 04:38:01.908235073 CET2453023192.168.2.2327.144.21.206
    Jan 21, 2022 04:38:01.908238888 CET2453023192.168.2.2334.39.144.126
    Jan 21, 2022 04:38:01.908241034 CET2453023192.168.2.23203.135.193.89
    Jan 21, 2022 04:38:01.908242941 CET2453023192.168.2.2398.253.228.202
    Jan 21, 2022 04:38:01.908243895 CET2453023192.168.2.2360.25.233.210
    Jan 21, 2022 04:38:01.908251047 CET2453023192.168.2.23220.201.185.122
    Jan 21, 2022 04:38:01.908252001 CET2453023192.168.2.2391.34.6.106
    Jan 21, 2022 04:38:01.908262014 CET2453023192.168.2.23170.194.232.15
    Jan 21, 2022 04:38:01.908267021 CET2453023192.168.2.2390.45.224.213
    Jan 21, 2022 04:38:01.908267975 CET2453023192.168.2.23213.192.194.67
    Jan 21, 2022 04:38:01.908269882 CET2453023192.168.2.2392.145.29.117
    Jan 21, 2022 04:38:01.908272982 CET2453023192.168.2.23133.76.106.179
    Jan 21, 2022 04:38:01.908277035 CET2453023192.168.2.2343.249.194.223
    Jan 21, 2022 04:38:01.908277988 CET2453023192.168.2.239.116.56.236
    Jan 21, 2022 04:38:01.908281088 CET2453023192.168.2.23189.221.133.22
    Jan 21, 2022 04:38:01.908283949 CET2453023192.168.2.23107.148.165.246
    Jan 21, 2022 04:38:01.908291101 CET2453023192.168.2.2316.27.229.69
    Jan 21, 2022 04:38:01.908297062 CET2453023192.168.2.2388.166.126.226
    Jan 21, 2022 04:38:01.908299923 CET2453023192.168.2.23195.148.16.89
    Jan 21, 2022 04:38:01.908315897 CET2453023192.168.2.23192.213.204.248
    Jan 21, 2022 04:38:01.908329964 CET2453023192.168.2.23117.81.58.101
    Jan 21, 2022 04:38:01.908333063 CET2453023192.168.2.23220.225.50.155
    Jan 21, 2022 04:38:01.908397913 CET2453023192.168.2.23182.168.189.163
    Jan 21, 2022 04:38:01.908397913 CET2453023192.168.2.23165.84.180.205
    Jan 21, 2022 04:38:01.908400059 CET2453023192.168.2.23208.216.172.134
    Jan 21, 2022 04:38:01.908402920 CET2453023192.168.2.23221.90.22.48
    Jan 21, 2022 04:38:01.908415079 CET2453023192.168.2.23201.52.134.175
    Jan 21, 2022 04:38:01.908416033 CET2453023192.168.2.23247.5.22.111
    Jan 21, 2022 04:38:01.908533096 CET2453023192.168.2.2317.177.146.250
    Jan 21, 2022 04:38:01.908533096 CET2453023192.168.2.23161.80.51.225
    Jan 21, 2022 04:38:01.908536911 CET2453023192.168.2.23204.154.249.86
    Jan 21, 2022 04:38:01.908540010 CET2453023192.168.2.2360.14.41.37
    Jan 21, 2022 04:38:01.908543110 CET2453023192.168.2.2361.15.163.163
    Jan 21, 2022 04:38:01.908541918 CET2453023192.168.2.23122.0.81.157
    Jan 21, 2022 04:38:01.908554077 CET2453023192.168.2.23247.95.35.206
    Jan 21, 2022 04:38:01.908557892 CET2453023192.168.2.23120.253.95.231
    Jan 21, 2022 04:38:01.908555031 CET2453023192.168.2.2371.110.58.18
    Jan 21, 2022 04:38:01.908569098 CET2453023192.168.2.23221.242.227.17
    Jan 21, 2022 04:38:01.908571959 CET2453023192.168.2.23101.94.51.84
    Jan 21, 2022 04:38:01.908574104 CET2453023192.168.2.23153.128.117.220
    Jan 21, 2022 04:38:01.908576965 CET2453023192.168.2.2323.220.102.200
    Jan 21, 2022 04:38:01.908584118 CET2453023192.168.2.23161.68.104.172
    Jan 21, 2022 04:38:01.908588886 CET2453023192.168.2.2392.64.140.122
    Jan 21, 2022 04:38:01.908588886 CET2453023192.168.2.23110.54.24.67
    Jan 21, 2022 04:38:01.908591032 CET2453023192.168.2.23187.96.209.56
    Jan 21, 2022 04:38:01.908610106 CET2453023192.168.2.2334.209.167.56
    Jan 21, 2022 04:38:01.908611059 CET2453023192.168.2.23183.79.84.150
    Jan 21, 2022 04:38:01.908612967 CET2453023192.168.2.2384.134.65.224
    Jan 21, 2022 04:38:01.908615112 CET2453023192.168.2.2389.226.86.136
    Jan 21, 2022 04:38:01.908620119 CET2453023192.168.2.2340.150.127.108
    Jan 21, 2022 04:38:01.908627987 CET2453023192.168.2.2358.152.219.37
    Jan 21, 2022 04:38:01.908627987 CET2453023192.168.2.23108.129.207.127
    Jan 21, 2022 04:38:01.908631086 CET2453023192.168.2.23124.171.165.153
    Jan 21, 2022 04:38:01.908634901 CET2453023192.168.2.2354.31.251.222
    Jan 21, 2022 04:38:01.908634901 CET2453023192.168.2.2354.98.94.148
    Jan 21, 2022 04:38:01.908641100 CET2453023192.168.2.23175.145.227.51
    Jan 21, 2022 04:38:01.908646107 CET2453023192.168.2.2398.189.246.41
    Jan 21, 2022 04:38:01.908646107 CET2453023192.168.2.2319.195.52.117
    Jan 21, 2022 04:38:01.908651114 CET2453023192.168.2.23148.116.169.60
    Jan 21, 2022 04:38:01.908660889 CET2453023192.168.2.2366.12.245.65
    Jan 21, 2022 04:38:01.908677101 CET2453023192.168.2.2354.51.88.16
    Jan 21, 2022 04:38:01.908689976 CET2453023192.168.2.2390.117.142.79
    Jan 21, 2022 04:38:01.908691883 CET2453023192.168.2.23149.146.70.249
    Jan 21, 2022 04:38:01.908709049 CET2453023192.168.2.2370.116.161.130
    Jan 21, 2022 04:38:01.908710957 CET2453023192.168.2.2384.243.21.118
    Jan 21, 2022 04:38:01.908715963 CET2453023192.168.2.2389.187.208.22
    Jan 21, 2022 04:38:01.908716917 CET2453023192.168.2.2367.116.103.58
    Jan 21, 2022 04:38:01.908730030 CET2453023192.168.2.23219.237.200.57
    Jan 21, 2022 04:38:01.908734083 CET2453023192.168.2.23255.49.239.199

    System Behavior

    Start time:04:38:01
    Start date:21/01/2022
    Path:/tmp/oKukKTcgxV
    Arguments:/tmp/oKukKTcgxV
    File size:4463432 bytes
    MD5 hash:cd177594338c77b895ae27c33f8f86cc
    Start time:04:38:01
    Start date:21/01/2022
    Path:/tmp/oKukKTcgxV
    Arguments:n/a
    File size:4463432 bytes
    MD5 hash:cd177594338c77b895ae27c33f8f86cc
    Start time:04:40:53
    Start date:21/01/2022
    Path:/tmp/oKukKTcgxV
    Arguments:n/a
    File size:4463432 bytes
    MD5 hash:cd177594338c77b895ae27c33f8f86cc
    Start time:04:40:53
    Start date:21/01/2022
    Path:/tmp/oKukKTcgxV
    Arguments:n/a
    File size:4463432 bytes
    MD5 hash:cd177594338c77b895ae27c33f8f86cc
    Start time:04:40:53
    Start date:21/01/2022
    Path:/tmp/oKukKTcgxV
    Arguments:n/a
    File size:4463432 bytes
    MD5 hash:cd177594338c77b895ae27c33f8f86cc
    Start time:04:40:58
    Start date:21/01/2022
    Path:/tmp/oKukKTcgxV
    Arguments:n/a
    File size:4463432 bytes
    MD5 hash:cd177594338c77b895ae27c33f8f86cc
    Start time:04:40:58
    Start date:21/01/2022
    Path:/tmp/oKukKTcgxV
    Arguments:n/a
    File size:4463432 bytes
    MD5 hash:cd177594338c77b895ae27c33f8f86cc
    Start time:04:40:53
    Start date:21/01/2022
    Path:/tmp/oKukKTcgxV
    Arguments:n/a
    File size:4463432 bytes
    MD5 hash:cd177594338c77b895ae27c33f8f86cc
    Start time:04:40:53
    Start date:21/01/2022
    Path:/tmp/oKukKTcgxV
    Arguments:n/a
    File size:4463432 bytes
    MD5 hash:cd177594338c77b895ae27c33f8f86cc
    Start time:04:38:01
    Start date:21/01/2022
    Path:/tmp/oKukKTcgxV
    Arguments:n/a
    File size:4463432 bytes
    MD5 hash:cd177594338c77b895ae27c33f8f86cc
    Start time:04:38:01
    Start date:21/01/2022
    Path:/tmp/oKukKTcgxV
    Arguments:n/a
    File size:4463432 bytes
    MD5 hash:cd177594338c77b895ae27c33f8f86cc
    Start time:04:38:01
    Start date:21/01/2022
    Path:/tmp/oKukKTcgxV
    Arguments:n/a
    File size:4463432 bytes
    MD5 hash:cd177594338c77b895ae27c33f8f86cc
    Start time:04:40:53
    Start date:21/01/2022
    Path:/tmp/oKukKTcgxV
    Arguments:n/a
    File size:4463432 bytes
    MD5 hash:cd177594338c77b895ae27c33f8f86cc
    Start time:04:40:53
    Start date:21/01/2022
    Path:/tmp/oKukKTcgxV
    Arguments:n/a
    File size:4463432 bytes
    MD5 hash:cd177594338c77b895ae27c33f8f86cc
    Start time:04:38:01
    Start date:21/01/2022
    Path:/tmp/oKukKTcgxV
    Arguments:n/a
    File size:4463432 bytes
    MD5 hash:cd177594338c77b895ae27c33f8f86cc
    Start time:04:38:01
    Start date:21/01/2022
    Path:/tmp/oKukKTcgxV
    Arguments:n/a
    File size:4463432 bytes
    MD5 hash:cd177594338c77b895ae27c33f8f86cc