Click to jump to signature section
Source: global traffic | TCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443 |
Source: global traffic | TCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80 |
Source: global traffic | TCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443 |
Source: global traffic | TCP traffic: 192.168.2.23:45728 -> 104.131.58.204:1312 |
Source: /tmp/sora.arm (PID: 6228) | Socket: 0.0.0.0::0 | Jump to behavior |
Source: /tmp/sora.arm (PID: 6228) | Socket: 0.0.0.0::53413 | Jump to behavior |
Source: /tmp/sora.arm (PID: 6228) | Socket: 0.0.0.0::80 | Jump to behavior |
Source: /tmp/sora.arm (PID: 6228) | Socket: 0.0.0.0::37215 | Jump to behavior |
Source: /tmp/sora.arm (PID: 6234) | Socket: 0.0.0.0::0 | Jump to behavior |
Source: unknown | Network traffic detected: HTTP traffic on port 43928 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 42836 -> 443 |
Source: unknown | TCP traffic detected without corresponding DNS query: 91.189.91.43 |
Source: unknown | TCP traffic detected without corresponding DNS query: 109.202.202.202 |
Source: unknown | TCP traffic detected without corresponding DNS query: 104.131.58.204 |
Source: unknown | TCP traffic detected without corresponding DNS query: 90.142.129.13 |
Source: unknown | TCP traffic detected without corresponding DNS query: 112.220.25.155 |
Source: unknown | TCP traffic detected without corresponding DNS query: 218.116.26.13 |
Source: unknown | TCP traffic detected without corresponding DNS query: 41.49.140.15 |
Source: unknown | TCP traffic detected without corresponding DNS query: 211.14.213.103 |
Source: unknown | TCP traffic detected without corresponding DNS query: 221.214.104.243 |
Source: unknown | TCP traffic detected without corresponding DNS query: 14.27.145.200 |
Source: unknown | TCP traffic detected without corresponding DNS query: 89.175.35.111 |
Source: unknown | TCP traffic detected without corresponding DNS query: 171.15.147.154 |
Source: unknown | TCP traffic detected without corresponding DNS query: 221.201.182.216 |
Source: unknown | TCP traffic detected without corresponding DNS query: 190.174.174.34 |
Source: unknown | TCP traffic detected without corresponding DNS query: 78.239.7.93 |
Source: unknown | TCP traffic detected without corresponding DNS query: 45.15.75.43 |
Source: unknown | TCP traffic detected without corresponding DNS query: 194.50.244.199 |
Source: unknown | TCP traffic detected without corresponding DNS query: 108.77.125.24 |
Source: unknown | TCP traffic detected without corresponding DNS query: 253.173.219.103 |
Source: unknown | TCP traffic detected without corresponding DNS query: 181.156.71.179 |
Source: unknown | TCP traffic detected without corresponding DNS query: 181.119.86.241 |
Source: unknown | TCP traffic detected without corresponding DNS query: 57.103.122.74 |
Source: unknown | TCP traffic detected without corresponding DNS query: 86.26.239.206 |
Source: unknown | TCP traffic detected without corresponding DNS query: 202.102.229.41 |
Source: unknown | TCP traffic detected without corresponding DNS query: 146.35.195.126 |
Source: unknown | TCP traffic detected without corresponding DNS query: 197.108.214.179 |
Source: unknown | TCP traffic detected without corresponding DNS query: 243.16.11.26 |
Source: unknown | TCP traffic detected without corresponding DNS query: 165.168.142.144 |
Source: unknown | TCP traffic detected without corresponding DNS query: 162.169.120.3 |
Source: unknown | TCP traffic detected without corresponding DNS query: 244.165.245.90 |
Source: unknown | TCP traffic detected without corresponding DNS query: 62.50.50.73 |
Source: unknown | TCP traffic detected without corresponding DNS query: 24.56.245.123 |
Source: unknown | TCP traffic detected without corresponding DNS query: 169.120.116.184 |
Source: unknown | TCP traffic detected without corresponding DNS query: 57.177.179.33 |
Source: unknown | TCP traffic detected without corresponding DNS query: 219.180.250.187 |
Source: unknown | TCP traffic detected without corresponding DNS query: 251.71.75.190 |
Source: unknown | TCP traffic detected without corresponding DNS query: 156.225.109.220 |
Source: unknown | TCP traffic detected without corresponding DNS query: 91.65.68.150 |
Source: unknown | TCP traffic detected without corresponding DNS query: 188.144.215.180 |
Source: unknown | TCP traffic detected without corresponding DNS query: 16.130.211.183 |
Source: unknown | TCP traffic detected without corresponding DNS query: 14.231.82.209 |
Source: unknown | TCP traffic detected without corresponding DNS query: 165.114.156.179 |
Source: unknown | TCP traffic detected without corresponding DNS query: 146.104.86.150 |
Source: unknown | TCP traffic detected without corresponding DNS query: 156.67.159.142 |
Source: unknown | TCP traffic detected without corresponding DNS query: 162.58.175.53 |
Source: unknown | TCP traffic detected without corresponding DNS query: 91.209.199.175 |
Source: unknown | TCP traffic detected without corresponding DNS query: 128.1.51.63 |
Source: unknown | TCP traffic detected without corresponding DNS query: 62.128.207.203 |
Source: unknown | TCP traffic detected without corresponding DNS query: 207.21.144.165 |
Source: unknown | TCP traffic detected without corresponding DNS query: 13.193.175.91 |
Source: sora.arm | String found in binary or memory: http://upx.sf.net |
Source: LOAD without section mappings | Program segment: 0x8000 |
Source: /tmp/sora.arm (PID: 6228) | SIGKILL sent: pid: 936, result: successful | Jump to behavior |
Source: /tmp/sora.arm (PID: 6234) | SIGKILL sent: pid: 936, result: successful | Jump to behavior |
Source: classification engine | Classification label: mal60.troj.evad.linARM@0/0@0/0 |
Source: initial sample | String containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $ |
Source: initial sample | String containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $ |
Source: initial sample | String containing UPX found: $Id: UPX 3.94 Copyright (C) 1996-2017 the UPX Team. All Rights Reserved. $ |
Source: /tmp/sora.arm (PID: 6234) | File opened: /proc/491/fd | Jump to behavior |
Source: /tmp/sora.arm (PID: 6234) | File opened: /proc/793/fd | Jump to behavior |
Source: /tmp/sora.arm (PID: 6234) | File opened: /proc/772/fd | Jump to behavior |
Source: /tmp/sora.arm (PID: 6234) | File opened: /proc/796/fd | Jump to behavior |
Source: /tmp/sora.arm (PID: 6234) | File opened: /proc/774/fd | Jump to behavior |
Source: /tmp/sora.arm (PID: 6234) | File opened: /proc/797/fd | Jump to behavior |
Source: /tmp/sora.arm (PID: 6234) | File opened: /proc/777/fd | Jump to behavior |
Source: /tmp/sora.arm (PID: 6234) | File opened: /proc/799/fd | Jump to behavior |
Source: /tmp/sora.arm (PID: 6234) | File opened: /proc/658/fd | Jump to behavior |
Source: /tmp/sora.arm (PID: 6234) | File opened: /proc/912/fd | Jump to behavior |
Source: /tmp/sora.arm (PID: 6234) | File opened: /proc/759/fd | Jump to behavior |
Source: /tmp/sora.arm (PID: 6234) | File opened: /proc/936/fd | Jump to behavior |
Source: /tmp/sora.arm (PID: 6234) | File opened: /proc/918/fd | Jump to behavior |
Source: /tmp/sora.arm (PID: 6234) | File opened: /proc/1/fd | Jump to behavior |
Source: /tmp/sora.arm (PID: 6234) | File opened: /proc/761/fd | Jump to behavior |
Source: /tmp/sora.arm (PID: 6234) | File opened: /proc/785/fd | Jump to behavior |
Source: /tmp/sora.arm (PID: 6234) | File opened: /proc/884/fd | Jump to behavior |
Source: /tmp/sora.arm (PID: 6234) | File opened: /proc/720/fd | Jump to behavior |
Source: /tmp/sora.arm (PID: 6234) | File opened: /proc/721/fd | Jump to behavior |
Source: /tmp/sora.arm (PID: 6234) | File opened: /proc/788/fd | Jump to behavior |
Source: /tmp/sora.arm (PID: 6234) | File opened: /proc/789/fd | Jump to behavior |
Source: /tmp/sora.arm (PID: 6234) | File opened: /proc/800/fd | Jump to behavior |
Source: /tmp/sora.arm (PID: 6234) | File opened: /proc/801/fd | Jump to behavior |
Source: /tmp/sora.arm (PID: 6234) | File opened: /proc/847/fd | Jump to behavior |
Source: /tmp/sora.arm (PID: 6234) | File opened: /proc/904/fd | Jump to behavior |
Source: /tmp/sora.arm (PID: 6228) | File opened: /proc/491/fd | Jump to behavior |
Source: /tmp/sora.arm (PID: 6228) | File opened: /proc/793/fd | Jump to behavior |
Source: /tmp/sora.arm (PID: 6228) | File opened: /proc/772/fd | Jump to behavior |
Source: /tmp/sora.arm (PID: 6228) | File opened: /proc/796/fd | Jump to behavior |
Source: /tmp/sora.arm (PID: 6228) | File opened: /proc/774/fd | Jump to behavior |
Source: /tmp/sora.arm (PID: 6228) | File opened: /proc/797/fd | Jump to behavior |
Source: /tmp/sora.arm (PID: 6228) | File opened: /proc/777/fd | Jump to behavior |
Source: /tmp/sora.arm (PID: 6228) | File opened: /proc/799/fd | Jump to behavior |
Source: /tmp/sora.arm (PID: 6228) | File opened: /proc/658/fd | Jump to behavior |
Source: /tmp/sora.arm (PID: 6228) | File opened: /proc/912/fd | Jump to behavior |
Source: /tmp/sora.arm (PID: 6228) | File opened: /proc/759/fd | Jump to behavior |
Source: /tmp/sora.arm (PID: 6228) | File opened: /proc/936/fd | Jump to behavior |
Source: /tmp/sora.arm (PID: 6228) | File opened: /proc/918/fd | Jump to behavior |
Source: /tmp/sora.arm (PID: 6228) | File opened: /proc/1/fd | Jump to behavior |
Source: /tmp/sora.arm (PID: 6228) | File opened: /proc/761/fd | Jump to behavior |
Source: /tmp/sora.arm (PID: 6228) | File opened: /proc/785/fd | Jump to behavior |
Source: /tmp/sora.arm (PID: 6228) | File opened: /proc/884/fd | Jump to behavior |
Source: /tmp/sora.arm (PID: 6228) | File opened: /proc/720/fd | Jump to behavior |
Source: /tmp/sora.arm (PID: 6228) | File opened: /proc/721/fd | Jump to behavior |
Source: /tmp/sora.arm (PID: 6228) | File opened: /proc/788/fd | Jump to behavior |
Source: /tmp/sora.arm (PID: 6228) | File opened: /proc/789/fd | Jump to behavior |
Source: /tmp/sora.arm (PID: 6228) | File opened: /proc/800/fd | Jump to behavior |
Source: /tmp/sora.arm (PID: 6228) | File opened: /proc/801/fd | Jump to behavior |
Source: /tmp/sora.arm (PID: 6228) | File opened: /proc/847/fd | Jump to behavior |
Source: /tmp/sora.arm (PID: 6228) | File opened: /proc/904/fd | Jump to behavior |
Source: /tmp/sora.arm (PID: 6226) | Queries kernel information via 'uname': | Jump to behavior |
Source: sora.arm, 6226.1.00000000a25b81b1.00000000ff87532e.rw-.sdmp, sora.arm, 6228.1.00000000a25b81b1.00000000ff87532e.rw-.sdmp, sora.arm, 6326.1.00000000a25b81b1.00000000ff87532e.rw-.sdmp, sora.arm, 6344.1.00000000a25b81b1.00000000ff87532e.rw-.sdmp, sora.arm, 6335.1.00000000a25b81b1.00000000ff87532e.rw-.sdmp, sora.arm, 6230.1.00000000a25b81b1.00000000ff87532e.rw-.sdmp, sora.arm, 6325.1.00000000a25b81b1.00000000ff87532e.rw-.sdmp, sora.arm, 6235.1.00000000a25b81b1.00000000ff87532e.rw-.sdmp | Binary or memory string: U!/etc/qemu-binfmt/arm |
Source: sora.arm, 6226.1.00000000d4f1622b.00000000bf8ca384.rw-.sdmp, sora.arm, 6228.1.00000000d4f1622b.00000000bf8ca384.rw-.sdmp, sora.arm, 6326.1.00000000d4f1622b.00000000bf8ca384.rw-.sdmp, sora.arm, 6344.1.00000000d4f1622b.00000000bf8ca384.rw-.sdmp, sora.arm, 6335.1.00000000d4f1622b.00000000bf8ca384.rw-.sdmp, sora.arm, 6230.1.00000000d4f1622b.00000000bf8ca384.rw-.sdmp, sora.arm, 6325.1.00000000d4f1622b.00000000bf8ca384.rw-.sdmp, sora.arm, 6235.1.00000000d4f1622b.00000000bf8ca384.rw-.sdmp | Binary or memory string: x86_64/usr/bin/qemu-arm/tmp/sora.armSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/sora.arm |
Source: sora.arm, 6226.1.00000000a25b81b1.00000000ff87532e.rw-.sdmp, sora.arm, 6228.1.00000000a25b81b1.00000000ff87532e.rw-.sdmp, sora.arm, 6326.1.00000000a25b81b1.00000000ff87532e.rw-.sdmp, sora.arm, 6344.1.00000000a25b81b1.00000000ff87532e.rw-.sdmp, sora.arm, 6335.1.00000000a25b81b1.00000000ff87532e.rw-.sdmp, sora.arm, 6230.1.00000000a25b81b1.00000000ff87532e.rw-.sdmp, sora.arm, 6325.1.00000000a25b81b1.00000000ff87532e.rw-.sdmp, sora.arm, 6235.1.00000000a25b81b1.00000000ff87532e.rw-.sdmp | Binary or memory string: /etc/qemu-binfmt/arm |
Source: sora.arm, 6226.1.00000000d4f1622b.00000000bf8ca384.rw-.sdmp, sora.arm, 6228.1.00000000d4f1622b.00000000bf8ca384.rw-.sdmp, sora.arm, 6326.1.00000000d4f1622b.00000000bf8ca384.rw-.sdmp, sora.arm, 6344.1.00000000d4f1622b.00000000bf8ca384.rw-.sdmp, sora.arm, 6335.1.00000000d4f1622b.00000000bf8ca384.rw-.sdmp, sora.arm, 6230.1.00000000d4f1622b.00000000bf8ca384.rw-.sdmp, sora.arm, 6325.1.00000000d4f1622b.00000000bf8ca384.rw-.sdmp, sora.arm, 6235.1.00000000d4f1622b.00000000bf8ca384.rw-.sdmp | Binary or memory string: /usr/bin/qemu-arm |
Source: Yara match | File source: dump.pcap, type: PCAP |
Source: Yara match | File source: dump.pcap, type: PCAP |