Linux Analysis Report
IsQzUGbu7m

Overview

General Information

Sample Name: IsQzUGbu7m
Analysis ID: 626493
MD5: f7aa71fcfc26a997be27cbbcbefe0178
SHA1: 97e1d4f09e6452f51b069673b9a25b61e59e35a8
SHA256: 986ec0cf250a130140e912d37abd078d45a0ae03749db84f133d43d380c0ea78
Tags: 32elfmiraisparc
Infos:

Detection

Mirai
Score: 60
Range: 0 - 100
Whitelisted: false

Signatures

Yara detected Mirai
Multi AV Scanner detection for submitted file
Uses known network protocols on non-standard ports
Sample has stripped symbol table
Uses the "uname" system call to query kernel version information (possible evasion)
Enumerates processes within the "proc" file system
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Detected TCP or UDP traffic on non-standard ports
Sample listens on a socket
Sample tries to kill a process (SIGKILL)

Classification

AV Detection

barindex
Source: IsQzUGbu7m Virustotal: Detection: 50% Perma Link

Networking

barindex
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 44060
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 44884
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 45824
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 46700
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 47530
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 44562
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 44600
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 44628
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 44660
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 44696
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 44734
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 44764
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 44800
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 44838
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 44880
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 48480
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 46134
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 46168
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 46208
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 46234
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 46264
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 46286
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 46310
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 46340
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 46376
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 46406
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 49378
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 50284
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 51190
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 52036
Source: global traffic TCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
Source: global traffic TCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
Source: global traffic TCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
Source: global traffic TCP traffic: 192.168.2.23:60988 -> 107.172.197.117:1312
Source: /tmp/IsQzUGbu7m (PID: 6235) Socket: 0.0.0.0::0 Jump to behavior
Source: /tmp/IsQzUGbu7m (PID: 6241) Socket: 0.0.0.0::0 Jump to behavior
Source: /tmp/IsQzUGbu7m (PID: 6241) Socket: 0.0.0.0::23 Jump to behavior
Source: /tmp/IsQzUGbu7m (PID: 6241) Socket: 0.0.0.0::53413 Jump to behavior
Source: /tmp/IsQzUGbu7m (PID: 6241) Socket: 0.0.0.0::80 Jump to behavior
Source: /tmp/IsQzUGbu7m (PID: 6241) Socket: 0.0.0.0::52869 Jump to behavior
Source: /tmp/IsQzUGbu7m (PID: 6241) Socket: 0.0.0.0::37215 Jump to behavior
Source: unknown Network traffic detected: HTTP traffic on port 43928 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 42836 -> 443
Source: unknown TCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknown TCP traffic detected without corresponding DNS query: 107.172.197.117
Source: unknown TCP traffic detected without corresponding DNS query: 91.160.26.149
Source: unknown TCP traffic detected without corresponding DNS query: 72.176.227.158
Source: unknown TCP traffic detected without corresponding DNS query: 145.240.131.5
Source: unknown TCP traffic detected without corresponding DNS query: 212.112.175.12
Source: unknown TCP traffic detected without corresponding DNS query: 81.182.152.203
Source: unknown TCP traffic detected without corresponding DNS query: 76.166.153.29
Source: unknown TCP traffic detected without corresponding DNS query: 104.137.71.145
Source: unknown TCP traffic detected without corresponding DNS query: 118.51.19.207
Source: unknown TCP traffic detected without corresponding DNS query: 9.124.78.196
Source: unknown TCP traffic detected without corresponding DNS query: 18.113.38.234
Source: unknown TCP traffic detected without corresponding DNS query: 45.190.96.73
Source: unknown TCP traffic detected without corresponding DNS query: 246.192.251.239
Source: unknown TCP traffic detected without corresponding DNS query: 116.78.119.81
Source: unknown TCP traffic detected without corresponding DNS query: 202.136.235.247
Source: unknown TCP traffic detected without corresponding DNS query: 116.187.69.12
Source: unknown TCP traffic detected without corresponding DNS query: 31.2.93.252
Source: unknown TCP traffic detected without corresponding DNS query: 196.18.142.193
Source: unknown TCP traffic detected without corresponding DNS query: 72.214.248.45
Source: unknown TCP traffic detected without corresponding DNS query: 153.153.244.240
Source: unknown TCP traffic detected without corresponding DNS query: 113.173.204.100
Source: unknown TCP traffic detected without corresponding DNS query: 241.254.59.246
Source: unknown TCP traffic detected without corresponding DNS query: 165.238.35.244
Source: unknown TCP traffic detected without corresponding DNS query: 39.113.51.236
Source: unknown TCP traffic detected without corresponding DNS query: 72.157.59.232
Source: unknown TCP traffic detected without corresponding DNS query: 47.174.234.169
Source: unknown TCP traffic detected without corresponding DNS query: 194.185.174.186
Source: unknown TCP traffic detected without corresponding DNS query: 173.159.22.86
Source: unknown TCP traffic detected without corresponding DNS query: 196.118.234.121
Source: unknown TCP traffic detected without corresponding DNS query: 180.66.37.195
Source: unknown TCP traffic detected without corresponding DNS query: 72.91.152.195
Source: unknown TCP traffic detected without corresponding DNS query: 100.48.208.186
Source: unknown TCP traffic detected without corresponding DNS query: 124.202.200.248
Source: unknown TCP traffic detected without corresponding DNS query: 19.186.225.227
Source: unknown TCP traffic detected without corresponding DNS query: 60.131.156.196
Source: unknown TCP traffic detected without corresponding DNS query: 200.74.78.189
Source: unknown TCP traffic detected without corresponding DNS query: 218.6.181.33
Source: unknown TCP traffic detected without corresponding DNS query: 66.60.220.247
Source: unknown TCP traffic detected without corresponding DNS query: 193.205.99.14
Source: unknown TCP traffic detected without corresponding DNS query: 99.206.2.88
Source: unknown TCP traffic detected without corresponding DNS query: 90.166.185.88
Source: unknown TCP traffic detected without corresponding DNS query: 181.74.224.48
Source: unknown TCP traffic detected without corresponding DNS query: 198.175.72.235
Source: unknown TCP traffic detected without corresponding DNS query: 20.80.238.203
Source: unknown TCP traffic detected without corresponding DNS query: 156.240.217.32
Source: unknown TCP traffic detected without corresponding DNS query: 99.205.40.193
Source: unknown TCP traffic detected without corresponding DNS query: 135.98.94.210
Source: unknown TCP traffic detected without corresponding DNS query: 247.243.0.194
Source: unknown TCP traffic detected without corresponding DNS query: 112.205.216.169
Source: ELF static info symbol of initial sample .symtab present: no
Source: /tmp/IsQzUGbu7m (PID: 6235) SIGKILL sent: pid: 936, result: successful Jump to behavior
Source: /tmp/IsQzUGbu7m (PID: 6241) SIGKILL sent: pid: 936, result: successful Jump to behavior
Source: classification engine Classification label: mal60.troj.lin@0/0@0/0
Source: /tmp/IsQzUGbu7m (PID: 6241) File opened: /proc/491/fd Jump to behavior
Source: /tmp/IsQzUGbu7m (PID: 6241) File opened: /proc/793/fd Jump to behavior
Source: /tmp/IsQzUGbu7m (PID: 6241) File opened: /proc/772/fd Jump to behavior
Source: /tmp/IsQzUGbu7m (PID: 6241) File opened: /proc/796/fd Jump to behavior
Source: /tmp/IsQzUGbu7m (PID: 6241) File opened: /proc/774/fd Jump to behavior
Source: /tmp/IsQzUGbu7m (PID: 6241) File opened: /proc/797/fd Jump to behavior
Source: /tmp/IsQzUGbu7m (PID: 6241) File opened: /proc/777/fd Jump to behavior
Source: /tmp/IsQzUGbu7m (PID: 6241) File opened: /proc/799/fd Jump to behavior
Source: /tmp/IsQzUGbu7m (PID: 6241) File opened: /proc/658/fd Jump to behavior
Source: /tmp/IsQzUGbu7m (PID: 6241) File opened: /proc/912/fd Jump to behavior
Source: /tmp/IsQzUGbu7m (PID: 6241) File opened: /proc/759/fd Jump to behavior
Source: /tmp/IsQzUGbu7m (PID: 6241) File opened: /proc/936/fd Jump to behavior
Source: /tmp/IsQzUGbu7m (PID: 6241) File opened: /proc/918/fd Jump to behavior
Source: /tmp/IsQzUGbu7m (PID: 6241) File opened: /proc/1/fd Jump to behavior
Source: /tmp/IsQzUGbu7m (PID: 6241) File opened: /proc/761/fd Jump to behavior
Source: /tmp/IsQzUGbu7m (PID: 6241) File opened: /proc/785/fd Jump to behavior
Source: /tmp/IsQzUGbu7m (PID: 6241) File opened: /proc/884/fd Jump to behavior
Source: /tmp/IsQzUGbu7m (PID: 6241) File opened: /proc/720/fd Jump to behavior
Source: /tmp/IsQzUGbu7m (PID: 6241) File opened: /proc/721/fd Jump to behavior
Source: /tmp/IsQzUGbu7m (PID: 6241) File opened: /proc/788/fd Jump to behavior
Source: /tmp/IsQzUGbu7m (PID: 6241) File opened: /proc/789/fd Jump to behavior
Source: /tmp/IsQzUGbu7m (PID: 6241) File opened: /proc/800/fd Jump to behavior
Source: /tmp/IsQzUGbu7m (PID: 6241) File opened: /proc/801/fd Jump to behavior
Source: /tmp/IsQzUGbu7m (PID: 6241) File opened: /proc/847/fd Jump to behavior
Source: /tmp/IsQzUGbu7m (PID: 6241) File opened: /proc/904/fd Jump to behavior
Source: /tmp/IsQzUGbu7m (PID: 6235) File opened: /proc/491/fd Jump to behavior
Source: /tmp/IsQzUGbu7m (PID: 6235) File opened: /proc/793/fd Jump to behavior
Source: /tmp/IsQzUGbu7m (PID: 6235) File opened: /proc/772/fd Jump to behavior
Source: /tmp/IsQzUGbu7m (PID: 6235) File opened: /proc/796/fd Jump to behavior
Source: /tmp/IsQzUGbu7m (PID: 6235) File opened: /proc/774/fd Jump to behavior
Source: /tmp/IsQzUGbu7m (PID: 6235) File opened: /proc/797/fd Jump to behavior
Source: /tmp/IsQzUGbu7m (PID: 6235) File opened: /proc/777/fd Jump to behavior
Source: /tmp/IsQzUGbu7m (PID: 6235) File opened: /proc/799/fd Jump to behavior
Source: /tmp/IsQzUGbu7m (PID: 6235) File opened: /proc/658/fd Jump to behavior
Source: /tmp/IsQzUGbu7m (PID: 6235) File opened: /proc/912/fd Jump to behavior
Source: /tmp/IsQzUGbu7m (PID: 6235) File opened: /proc/759/fd Jump to behavior
Source: /tmp/IsQzUGbu7m (PID: 6235) File opened: /proc/936/fd Jump to behavior
Source: /tmp/IsQzUGbu7m (PID: 6235) File opened: /proc/918/fd Jump to behavior
Source: /tmp/IsQzUGbu7m (PID: 6235) File opened: /proc/1/fd Jump to behavior
Source: /tmp/IsQzUGbu7m (PID: 6235) File opened: /proc/761/fd Jump to behavior
Source: /tmp/IsQzUGbu7m (PID: 6235) File opened: /proc/785/fd Jump to behavior
Source: /tmp/IsQzUGbu7m (PID: 6235) File opened: /proc/884/fd Jump to behavior
Source: /tmp/IsQzUGbu7m (PID: 6235) File opened: /proc/720/fd Jump to behavior
Source: /tmp/IsQzUGbu7m (PID: 6235) File opened: /proc/721/fd Jump to behavior
Source: /tmp/IsQzUGbu7m (PID: 6235) File opened: /proc/788/fd Jump to behavior
Source: /tmp/IsQzUGbu7m (PID: 6235) File opened: /proc/789/fd Jump to behavior
Source: /tmp/IsQzUGbu7m (PID: 6235) File opened: /proc/800/fd Jump to behavior
Source: /tmp/IsQzUGbu7m (PID: 6235) File opened: /proc/801/fd Jump to behavior
Source: /tmp/IsQzUGbu7m (PID: 6235) File opened: /proc/847/fd Jump to behavior
Source: /tmp/IsQzUGbu7m (PID: 6235) File opened: /proc/904/fd Jump to behavior

Hooking and other Techniques for Hiding and Protection

barindex
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 44060
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 44884
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 45824
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 46700
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 47530
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 44562
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 44600
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 44628
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 44660
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 44696
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 44734
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 44764
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 44800
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 44838
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 44880
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 48480
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 46134
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 46168
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 46208
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 46234
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 46264
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 46286
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 46310
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 46340
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 46376
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 46406
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 49378
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 50284
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 51190
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 52036
Source: /tmp/IsQzUGbu7m (PID: 6233) Queries kernel information via 'uname': Jump to behavior
Source: IsQzUGbu7m, 6233.1.0000000023051e42.0000000062fa4c5b.rw-.sdmp, IsQzUGbu7m, 6235.1.0000000023051e42.0000000062fa4c5b.rw-.sdmp, IsQzUGbu7m, 6256.1.0000000023051e42.0000000062fa4c5b.rw-.sdmp, IsQzUGbu7m, 6270.1.0000000023051e42.0000000062fa4c5b.rw-.sdmp, IsQzUGbu7m, 6266.1.0000000023051e42.0000000062fa4c5b.rw-.sdmp, IsQzUGbu7m, 6237.1.0000000023051e42.0000000062fa4c5b.rw-.sdmp, IsQzUGbu7m, 6253.1.0000000023051e42.0000000062fa4c5b.rw-.sdmp, IsQzUGbu7m, 6243.1.0000000023051e42.0000000062fa4c5b.rw-.sdmp Binary or memory string: /etc/qemu-binfmt/sparc
Source: IsQzUGbu7m, 6233.1.0000000023051e42.0000000062fa4c5b.rw-.sdmp, IsQzUGbu7m, 6235.1.0000000023051e42.0000000062fa4c5b.rw-.sdmp, IsQzUGbu7m, 6256.1.0000000023051e42.0000000062fa4c5b.rw-.sdmp, IsQzUGbu7m, 6270.1.0000000023051e42.0000000062fa4c5b.rw-.sdmp, IsQzUGbu7m, 6266.1.0000000023051e42.0000000062fa4c5b.rw-.sdmp, IsQzUGbu7m, 6237.1.0000000023051e42.0000000062fa4c5b.rw-.sdmp, IsQzUGbu7m, 6253.1.0000000023051e42.0000000062fa4c5b.rw-.sdmp, IsQzUGbu7m, 6243.1.0000000023051e42.0000000062fa4c5b.rw-.sdmp Binary or memory string: U!/etc/qemu-binfmt/sparc
Source: IsQzUGbu7m, 6233.1.00000000961148e3.0000000065c7861b.rw-.sdmp, IsQzUGbu7m, 6235.1.00000000961148e3.0000000065c7861b.rw-.sdmp, IsQzUGbu7m, 6256.1.00000000961148e3.0000000065c7861b.rw-.sdmp, IsQzUGbu7m, 6270.1.00000000961148e3.0000000065c7861b.rw-.sdmp, IsQzUGbu7m, 6266.1.00000000961148e3.0000000065c7861b.rw-.sdmp, IsQzUGbu7m, 6237.1.00000000961148e3.0000000065c7861b.rw-.sdmp, IsQzUGbu7m, 6253.1.00000000961148e3.0000000065c7861b.rw-.sdmp, IsQzUGbu7m, 6243.1.00000000961148e3.0000000065c7861b.rw-.sdmp Binary or memory string: x86_64/usr/bin/qemu-sparc/tmp/IsQzUGbu7mSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/IsQzUGbu7m
Source: IsQzUGbu7m, 6233.1.00000000961148e3.0000000065c7861b.rw-.sdmp, IsQzUGbu7m, 6235.1.00000000961148e3.0000000065c7861b.rw-.sdmp, IsQzUGbu7m, 6256.1.00000000961148e3.0000000065c7861b.rw-.sdmp, IsQzUGbu7m, 6270.1.00000000961148e3.0000000065c7861b.rw-.sdmp, IsQzUGbu7m, 6266.1.00000000961148e3.0000000065c7861b.rw-.sdmp, IsQzUGbu7m, 6237.1.00000000961148e3.0000000065c7861b.rw-.sdmp, IsQzUGbu7m, 6253.1.00000000961148e3.0000000065c7861b.rw-.sdmp, IsQzUGbu7m, 6243.1.00000000961148e3.0000000065c7861b.rw-.sdmp Binary or memory string: /usr/bin/qemu-sparc

Stealing of Sensitive Information

barindex
Source: Yara match File source: dump.pcap, type: PCAP

Remote Access Functionality

barindex
Source: Yara match File source: dump.pcap, type: PCAP
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs