Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 48628 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 48632 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 48636 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 48640 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 48642 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 48644 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 48646 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 48648 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 48650 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 48656 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 33518 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 33524 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 33532 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 33554 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 33570 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 33582 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 33598 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 33612 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 33626 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 33630 |
Source: global traffic |
TCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443 |
Source: global traffic |
TCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443 |
Source: global traffic |
TCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80 |
Source: global traffic |
TCP traffic: 192.168.2.23:45728 -> 104.131.58.204:1312 |
Source: unknown |
Network traffic detected: HTTP traffic on port 43928 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 42836 -> 443 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 104.131.58.204 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 147.90.130.90 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 201.115.11.88 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 168.183.253.152 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 169.17.72.41 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 70.41.126.72 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 206.86.190.170 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 54.125.78.236 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 102.164.184.245 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 111.225.54.176 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 103.178.194.150 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 162.65.244.93 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 247.206.45.219 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 122.98.143.130 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 24.173.174.99 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 107.51.108.10 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 66.24.90.51 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 69.240.67.229 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 125.22.22.195 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 151.106.68.40 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 116.32.79.218 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 219.11.182.128 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 74.222.152.155 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 244.223.188.78 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 79.254.242.106 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 73.158.16.171 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 46.40.199.102 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 252.187.91.63 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 206.52.153.7 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 221.207.132.32 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 249.174.106.133 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 209.152.198.90 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 213.221.221.58 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 125.223.238.229 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 183.252.212.185 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 111.57.57.230 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 44.91.219.197 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 189.225.250.246 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 66.198.60.234 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 166.25.186.173 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 5.157.253.240 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 19.250.241.195 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 241.125.130.132 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 187.117.138.193 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 146.117.255.83 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 19.160.122.0 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 18.154.92.193 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 126.11.207.77 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 201.105.75.126 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 220.130.75.25 |
Source: sora.arm7 |
String found in binary or memory: http://upx.sf.net |
Source: LOAD without section mappings |
Program segment: 0x8000 |
Source: sora.arm7, type: SAMPLE |
Matched rule: SUSP_ELF_LNX_UPX_Compressed_File date = 2018-12-12, author = Florian Roth, description = Detects a suspicious ELF binary with UPX compression, reference = Internal Research, score = 038ff8b2fef16f8ee9d70e6c219c5f380afe1a21761791e8cbda21fa4d09fdb4 |
Source: /tmp/sora.arm7 (PID: 6240) |
SIGKILL sent: pid: 936, result: successful |
Jump to behavior |
Source: /tmp/sora.arm7 (PID: 6246) |
SIGKILL sent: pid: 936, result: successful |
Jump to behavior |
Source: classification engine |
Classification label: mal56.troj.evad.linARM7@0/0@0/0 |
Source: initial sample |
String containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $ |
Source: initial sample |
String containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $ |
Source: initial sample |
String containing UPX found: $Id: UPX 3.94 Copyright (C) 1996-2017 the UPX Team. All Rights Reserved. $ |
Source: /tmp/sora.arm7 (PID: 6240) |
File opened: /proc/491/fd |
Jump to behavior |
Source: /tmp/sora.arm7 (PID: 6240) |
File opened: /proc/793/fd |
Jump to behavior |
Source: /tmp/sora.arm7 (PID: 6240) |
File opened: /proc/772/fd |
Jump to behavior |
Source: /tmp/sora.arm7 (PID: 6240) |
File opened: /proc/796/fd |
Jump to behavior |
Source: /tmp/sora.arm7 (PID: 6240) |
File opened: /proc/774/fd |
Jump to behavior |
Source: /tmp/sora.arm7 (PID: 6240) |
File opened: /proc/797/fd |
Jump to behavior |
Source: /tmp/sora.arm7 (PID: 6240) |
File opened: /proc/777/fd |
Jump to behavior |
Source: /tmp/sora.arm7 (PID: 6240) |
File opened: /proc/799/fd |
Jump to behavior |
Source: /tmp/sora.arm7 (PID: 6240) |
File opened: /proc/658/fd |
Jump to behavior |
Source: /tmp/sora.arm7 (PID: 6240) |
File opened: /proc/912/fd |
Jump to behavior |
Source: /tmp/sora.arm7 (PID: 6240) |
File opened: /proc/759/fd |
Jump to behavior |
Source: /tmp/sora.arm7 (PID: 6240) |
File opened: /proc/936/fd |
Jump to behavior |
Source: /tmp/sora.arm7 (PID: 6240) |
File opened: /proc/918/fd |
Jump to behavior |
Source: /tmp/sora.arm7 (PID: 6240) |
File opened: /proc/1/fd |
Jump to behavior |
Source: /tmp/sora.arm7 (PID: 6240) |
File opened: /proc/761/fd |
Jump to behavior |
Source: /tmp/sora.arm7 (PID: 6240) |
File opened: /proc/785/fd |
Jump to behavior |
Source: /tmp/sora.arm7 (PID: 6240) |
File opened: /proc/884/fd |
Jump to behavior |
Source: /tmp/sora.arm7 (PID: 6240) |
File opened: /proc/720/fd |
Jump to behavior |
Source: /tmp/sora.arm7 (PID: 6240) |
File opened: /proc/721/fd |
Jump to behavior |
Source: /tmp/sora.arm7 (PID: 6240) |
File opened: /proc/788/fd |
Jump to behavior |
Source: /tmp/sora.arm7 (PID: 6240) |
File opened: /proc/789/fd |
Jump to behavior |
Source: /tmp/sora.arm7 (PID: 6240) |
File opened: /proc/800/fd |
Jump to behavior |
Source: /tmp/sora.arm7 (PID: 6240) |
File opened: /proc/801/fd |
Jump to behavior |
Source: /tmp/sora.arm7 (PID: 6240) |
File opened: /proc/847/fd |
Jump to behavior |
Source: /tmp/sora.arm7 (PID: 6240) |
File opened: /proc/904/fd |
Jump to behavior |
Source: /tmp/sora.arm7 (PID: 6246) |
File opened: /proc/491/fd |
Jump to behavior |
Source: /tmp/sora.arm7 (PID: 6246) |
File opened: /proc/793/fd |
Jump to behavior |
Source: /tmp/sora.arm7 (PID: 6246) |
File opened: /proc/772/fd |
Jump to behavior |
Source: /tmp/sora.arm7 (PID: 6246) |
File opened: /proc/796/fd |
Jump to behavior |
Source: /tmp/sora.arm7 (PID: 6246) |
File opened: /proc/774/fd |
Jump to behavior |
Source: /tmp/sora.arm7 (PID: 6246) |
File opened: /proc/797/fd |
Jump to behavior |
Source: /tmp/sora.arm7 (PID: 6246) |
File opened: /proc/777/fd |
Jump to behavior |
Source: /tmp/sora.arm7 (PID: 6246) |
File opened: /proc/799/fd |
Jump to behavior |
Source: /tmp/sora.arm7 (PID: 6246) |
File opened: /proc/658/fd |
Jump to behavior |
Source: /tmp/sora.arm7 (PID: 6246) |
File opened: /proc/912/fd |
Jump to behavior |
Source: /tmp/sora.arm7 (PID: 6246) |
File opened: /proc/759/fd |
Jump to behavior |
Source: /tmp/sora.arm7 (PID: 6246) |
File opened: /proc/936/fd |
Jump to behavior |
Source: /tmp/sora.arm7 (PID: 6246) |
File opened: /proc/918/fd |
Jump to behavior |
Source: /tmp/sora.arm7 (PID: 6246) |
File opened: /proc/1/fd |
Jump to behavior |
Source: /tmp/sora.arm7 (PID: 6246) |
File opened: /proc/761/fd |
Jump to behavior |
Source: /tmp/sora.arm7 (PID: 6246) |
File opened: /proc/785/fd |
Jump to behavior |
Source: /tmp/sora.arm7 (PID: 6246) |
File opened: /proc/884/fd |
Jump to behavior |
Source: /tmp/sora.arm7 (PID: 6246) |
File opened: /proc/720/fd |
Jump to behavior |
Source: /tmp/sora.arm7 (PID: 6246) |
File opened: /proc/721/fd |
Jump to behavior |
Source: /tmp/sora.arm7 (PID: 6246) |
File opened: /proc/788/fd |
Jump to behavior |
Source: /tmp/sora.arm7 (PID: 6246) |
File opened: /proc/789/fd |
Jump to behavior |
Source: /tmp/sora.arm7 (PID: 6246) |
File opened: /proc/800/fd |
Jump to behavior |
Source: /tmp/sora.arm7 (PID: 6246) |
File opened: /proc/801/fd |
Jump to behavior |
Source: /tmp/sora.arm7 (PID: 6246) |
File opened: /proc/847/fd |
Jump to behavior |
Source: /tmp/sora.arm7 (PID: 6246) |
File opened: /proc/904/fd |
Jump to behavior |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 48628 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 48632 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 48636 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 48640 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 48642 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 48644 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 48646 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 48648 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 48650 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 48656 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 33518 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 33524 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 33532 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 33554 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 33570 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 33582 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 33598 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 33612 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 33626 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 33630 |
Source: /tmp/sora.arm7 (PID: 6237) |
Queries kernel information via 'uname': |
Jump to behavior |
Source: sora.arm7, 6237.1.0000000026c28b2d.000000007e79824a.rw-.sdmp, sora.arm7, 6240.1.0000000026c28b2d.000000007e79824a.rw-.sdmp, sora.arm7, 6344.1.0000000026c28b2d.000000007e79824a.rw-.sdmp, sora.arm7, 6358.1.0000000026c28b2d.000000007e79824a.rw-.sdmp, sora.arm7, 6351.1.0000000026c28b2d.000000007e79824a.rw-.sdmp, sora.arm7, 6241.1.0000000026c28b2d.000000007e79824a.rw-.sdmp, sora.arm7, 6341.1.0000000026c28b2d.000000007e79824a.rw-.sdmp, sora.arm7, 6247.1.0000000026c28b2d.000000007e79824a.rw-.sdmp |
Binary or memory string: x86_64/usr/bin/qemu-arm/tmp/sora.arm7SUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/sora.arm7 |
Source: sora.arm7, 6237.1.0000000002bd700b.00000000241738ea.rw-.sdmp, sora.arm7, 6240.1.0000000002bd700b.00000000241738ea.rw-.sdmp, sora.arm7, 6344.1.0000000002bd700b.00000000241738ea.rw-.sdmp, sora.arm7, 6358.1.0000000002bd700b.00000000241738ea.rw-.sdmp, sora.arm7, 6351.1.0000000002bd700b.00000000241738ea.rw-.sdmp, sora.arm7, 6241.1.0000000002bd700b.00000000241738ea.rw-.sdmp, sora.arm7, 6341.1.0000000002bd700b.00000000241738ea.rw-.sdmp, sora.arm7, 6247.1.0000000002bd700b.00000000241738ea.rw-.sdmp |
Binary or memory string: /etc/qemu-binfmt/arm |
Source: sora.arm7, 6237.1.0000000026c28b2d.000000007e79824a.rw-.sdmp, sora.arm7, 6240.1.0000000026c28b2d.000000007e79824a.rw-.sdmp, sora.arm7, 6344.1.0000000026c28b2d.000000007e79824a.rw-.sdmp, sora.arm7, 6358.1.0000000026c28b2d.000000007e79824a.rw-.sdmp, sora.arm7, 6351.1.0000000026c28b2d.000000007e79824a.rw-.sdmp, sora.arm7, 6241.1.0000000026c28b2d.000000007e79824a.rw-.sdmp, sora.arm7, 6341.1.0000000026c28b2d.000000007e79824a.rw-.sdmp, sora.arm7, 6247.1.0000000026c28b2d.000000007e79824a.rw-.sdmp |
Binary or memory string: /usr/bin/qemu-arm |
Source: sora.arm7, 6237.1.0000000002bd700b.00000000241738ea.rw-.sdmp, sora.arm7, 6240.1.0000000002bd700b.00000000241738ea.rw-.sdmp, sora.arm7, 6344.1.0000000002bd700b.00000000241738ea.rw-.sdmp, sora.arm7, 6358.1.0000000002bd700b.00000000241738ea.rw-.sdmp, sora.arm7, 6351.1.0000000002bd700b.00000000241738ea.rw-.sdmp, sora.arm7, 6241.1.0000000002bd700b.00000000241738ea.rw-.sdmp, sora.arm7, 6341.1.0000000002bd700b.00000000241738ea.rw-.sdmp, sora.arm7, 6247.1.0000000002bd700b.00000000241738ea.rw-.sdmp |
Binary or memory string: &V!/etc/qemu-binfmt/arm |
Source: Yara match |
File source: dump.pcap, type: PCAP |
Source: Yara match |
File source: dump.pcap, type: PCAP |