Linux
Analysis Report
6gIL6GLh9R
Overview
General Information
Sample Name: | 6gIL6GLh9R |
Analysis ID: | 635071 |
MD5: | 6dfcca37a6b1468fcaf3addab827b850 |
SHA1: | d96baef8427ad98a42e418e49fbcf440b173fc3a |
SHA256: | eed19f89eba4f0ca0b1f7ef5f02080b5839f076652aeb277c59e3b6e85f18c4a |
Tags: | 32armelfgafgyt |
Infos: |
Detection
Mirai
Score: | 72 |
Range: | 0 - 100 |
Whitelisted: | false |
Signatures
Yara detected Mirai
Multi AV Scanner detection for submitted file
Reads system files that contain records of logged in users
Contains symbols with names commonly found in malware
Sample tries to kill multiple processes (SIGKILL)
Sample reads /proc/mounts (often used for finding a writable filesystem)
Executes the "kill" or "pkill" command typically used to terminate processes
Reads CPU information from /sys indicative of miner or evasive malware
Yara signature match
Executes the "grep" command used to find patterns in files or piped streams
Reads system information from the proc file system
Uses the "uname" system call to query kernel version information (possible evasion)
Enumerates processes within the "proc" file system
Executes the "systemctl" command used for controlling the systemd system and service manager
Detected TCP or UDP traffic on non-standard ports
Sample listens on a socket
Sample tries to kill a process (SIGKILL)
Sample contains symbols with suspicious names
Deletes log files
Creates hidden files and/or directories
Sample tries to set the executable flag
Executes commands using a shell command-line interpreter
Classification
Analysis Advice
Static ELF header machine description suggests that the sample might not execute correctly on this machine. |
Static ELF header machine description suggests that the sample might only run correctly on MIPS or ARM architectures. |
Joe Sandbox Version: | 34.0.0 Boulder Opal |
Analysis ID: | 635071 |
Start date and time: 27/05/202212:24:05 | 2022-05-27 12:24:05 +02:00 |
Joe Sandbox Product: | CloudBasic |
Overall analysis duration: | 0h 5m 38s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Sample file name: | 6gIL6GLh9R |
Cookbook file name: | defaultlinuxfilecookbook.jbs |
Analysis system description: | Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11) |
Analysis Mode: | default |
Detection: | MAL |
Classification: | mal72.spre.troj.lin@0/161@7/0 |
- Connection to analysis system has been lost, crash info: Unknown
- Report size exceeded maximum capacity and may have missing behavior information.
- Report size exceeded maximum capacity and may have missing network information.
Command: | /tmp/6gIL6GLh9R |
PID: | 6234 |
Exit Code: | 0 |
Exit Code Info: | |
Killed: | False |
Standard Output: | VegaSec-KATANA001 |
Standard Error: |
- system is lnxubuntu20
- 6gIL6GLh9R New Fork (PID: 6236, Parent: 6234)
- 6gIL6GLh9R New Fork (PID: 6237, Parent: 6234)
- 6gIL6GLh9R New Fork (PID: 6240, Parent: 6237)
- 6gIL6GLh9R New Fork (PID: 6241, Parent: 6237)
- 6gIL6GLh9R New Fork (PID: 6242, Parent: 6237)
- systemd New Fork (PID: 6249, Parent: 1)
- systemd New Fork (PID: 6266, Parent: 1)
- systemd New Fork (PID: 6270, Parent: 1)
- systemd New Fork (PID: 6323, Parent: 1)
- systemd New Fork (PID: 6327, Parent: 1)
- systemd New Fork (PID: 6328, Parent: 1860)
- systemd New Fork (PID: 6333, Parent: 1)
- systemd New Fork (PID: 6336, Parent: 1)
- systemd New Fork (PID: 6399, Parent: 1)
- systemd New Fork (PID: 6404, Parent: 1)
- systemd New Fork (PID: 6406, Parent: 1)
- gdm3 New Fork (PID: 6408, Parent: 1320)
- systemd-udevd New Fork (PID: 6409, Parent: 6306)
- gdm3 New Fork (PID: 6410, Parent: 1320)
- gdm3 New Fork (PID: 6411, Parent: 1320)
- systemd New Fork (PID: 6417, Parent: 1)
- gpu-manager New Fork (PID: 6418, Parent: 6417)
- sh New Fork (PID: 6419, Parent: 6418)
- gpu-manager New Fork (PID: 6420, Parent: 6417)
- sh New Fork (PID: 6421, Parent: 6420)
- gpu-manager New Fork (PID: 6422, Parent: 6417)
- sh New Fork (PID: 6423, Parent: 6422)
- gpu-manager New Fork (PID: 6424, Parent: 6417)
- sh New Fork (PID: 6425, Parent: 6424)
- gpu-manager New Fork (PID: 6426, Parent: 6417)
- sh New Fork (PID: 6427, Parent: 6426)
- gpu-manager New Fork (PID: 6428, Parent: 6417)
- sh New Fork (PID: 6429, Parent: 6428)
- gpu-manager New Fork (PID: 6430, Parent: 6417)
- sh New Fork (PID: 6431, Parent: 6430)
- gpu-manager New Fork (PID: 6433, Parent: 6417)
- sh New Fork (PID: 6435, Parent: 6433)
- systemd New Fork (PID: 6439, Parent: 1)
- generate-config New Fork (PID: 6440, Parent: 6439)
- systemd New Fork (PID: 6441, Parent: 1)
- systemd New Fork (PID: 6446, Parent: 1)
- gdm3 New Fork (PID: 6451, Parent: 6446)
- gdm3 New Fork (PID: 6470, Parent: 6446)
- gdm-session-worker New Fork (PID: 6474, Parent: 6470)
- gdm-wayland-session New Fork (PID: 6476, Parent: 6474)
- dbus-daemon New Fork (PID: 6480, Parent: 6476)
- dbus-daemon New Fork (PID: 6481, Parent: 6480)
- gdm-wayland-session New Fork (PID: 6482, Parent: 6474)
- dbus-run-session New Fork (PID: 6483, Parent: 6482)
- gdm3 New Fork (PID: 6484, Parent: 6446)
- gdm3 New Fork (PID: 6485, Parent: 6446)
- systemd New Fork (PID: 6452, Parent: 1)
- accounts-daemon New Fork (PID: 6465, Parent: 6452)
- language-validate New Fork (PID: 6466, Parent: 6465)
- language-options New Fork (PID: 6467, Parent: 6466)
- gvfsd-fuse New Fork (PID: 6493, Parent: 2038)
- systemd New Fork (PID: 6515, Parent: 1)
- systemd New Fork (PID: 6516, Parent: 1)
- systemd New Fork (PID: 6517, Parent: 1)
- systemd New Fork (PID: 6520, Parent: 1)
- systemd New Fork (PID: 6522, Parent: 1860)
- systemd New Fork (PID: 6526, Parent: 1)
- systemd New Fork (PID: 6584, Parent: 1)
- systemd New Fork (PID: 6585, Parent: 1)
- gpu-manager New Fork (PID: 6589, Parent: 6585)
- sh New Fork (PID: 6590, Parent: 6589)
- gpu-manager New Fork (PID: 6596, Parent: 6585)
- sh New Fork (PID: 6597, Parent: 6596)
- gpu-manager New Fork (PID: 6599, Parent: 6585)
- sh New Fork (PID: 6601, Parent: 6599)
- gpu-manager New Fork (PID: 6602, Parent: 6585)
- sh New Fork (PID: 6604, Parent: 6602)
- gpu-manager New Fork (PID: 6605, Parent: 6585)
- sh New Fork (PID: 6606, Parent: 6605)
- gpu-manager New Fork (PID: 6607, Parent: 6585)
- sh New Fork (PID: 6608, Parent: 6607)
- gpu-manager New Fork (PID: 6610, Parent: 6585)
- sh New Fork (PID: 6611, Parent: 6610)
- gpu-manager New Fork (PID: 6615, Parent: 6585)
- sh New Fork (PID: 6616, Parent: 6615)
- systemd New Fork (PID: 6588, Parent: 1)
- systemd New Fork (PID: 6598, Parent: 1)
- systemd New Fork (PID: 6600, Parent: 1)
- systemd New Fork (PID: 6609, Parent: 1)
- systemd New Fork (PID: 6620, Parent: 1)
- generate-config New Fork (PID: 6623, Parent: 6620)
- systemd New Fork (PID: 6622, Parent: 1)
- systemd New Fork (PID: 6624, Parent: 1860)
- systemd New Fork (PID: 6625, Parent: 1)
- systemd New Fork (PID: 6628, Parent: 1)
- systemd New Fork (PID: 6629, Parent: 1)
- systemd New Fork (PID: 6634, Parent: 1)
- systemd New Fork (PID: 6635, Parent: 1860)
- systemd New Fork (PID: 6636, Parent: 1)
- systemd New Fork (PID: 6641, Parent: 1)
- systemd New Fork (PID: 6698, Parent: 1)
- systemd New Fork (PID: 6703, Parent: 1)
- systemd New Fork (PID: 6707, Parent: 1)
- systemd New Fork (PID: 6709, Parent: 1)
- systemd New Fork (PID: 6716, Parent: 1)
- gdm3 New Fork (PID: 6719, Parent: 6716)
- gdm3 New Fork (PID: 6729, Parent: 6716)
- gdm-session-worker New Fork (PID: 6739, Parent: 6729)
- gdm-wayland-session New Fork (PID: 6741, Parent: 6739)
- dbus-daemon New Fork (PID: 6751, Parent: 6741)
- dbus-daemon New Fork (PID: 6752, Parent: 6751)
- gdm-wayland-session New Fork (PID: 6753, Parent: 6739)
- gdm3 New Fork (PID: 6754, Parent: 6716)
- gdm3 New Fork (PID: 6756, Parent: 6716)
- systemd New Fork (PID: 6720, Parent: 1)
- accounts-daemon New Fork (PID: 6724, Parent: 6720)
- language-validate New Fork (PID: 6725, Parent: 6724)
- language-options New Fork (PID: 6726, Parent: 6725)
- systemd New Fork (PID: 6730, Parent: 1)
- systemd New Fork (PID: 6734, Parent: 1)
- systemd New Fork (PID: 6737, Parent: 1)
- systemd New Fork (PID: 6744, Parent: 1)
- systemd New Fork (PID: 6757, Parent: 1)
- systemd New Fork (PID: 6759, Parent: 1860)
- systemd New Fork (PID: 6762, Parent: 1)
- systemd New Fork (PID: 6821, Parent: 1)
- systemd New Fork (PID: 6824, Parent: 1)
- systemd New Fork (PID: 6825, Parent: 1)
- gpu-manager New Fork (PID: 6827, Parent: 6825)
- sh New Fork (PID: 6828, Parent: 6827)
- gpu-manager New Fork (PID: 6832, Parent: 6825)
- sh New Fork (PID: 6833, Parent: 6832)
- gpu-manager New Fork (PID: 6834, Parent: 6825)
- sh New Fork (PID: 6835, Parent: 6834)
- gpu-manager New Fork (PID: 6837, Parent: 6825)
- sh New Fork (PID: 6838, Parent: 6837)
- gpu-manager New Fork (PID: 6845, Parent: 6825)
- sh New Fork (PID: 6846, Parent: 6845)
- gpu-manager New Fork (PID: 6847, Parent: 6825)
- sh New Fork (PID: 6848, Parent: 6847)
- gpu-manager New Fork (PID: 6851, Parent: 6825)
- sh New Fork (PID: 6852, Parent: 6851)
- gpu-manager New Fork (PID: 6853, Parent: 6825)
- sh New Fork (PID: 6854, Parent: 6853)
- systemd New Fork (PID: 6826, Parent: 1)
- systemd New Fork (PID: 6836, Parent: 1)
- systemd New Fork (PID: 6841, Parent: 1)
- systemd New Fork (PID: 6856, Parent: 1)
- systemd New Fork (PID: 6857, Parent: 1)
- systemd New Fork (PID: 6862, Parent: 1860)
- systemd New Fork (PID: 6863, Parent: 1)
- generate-config New Fork (PID: 6864, Parent: 6863)
- systemd New Fork (PID: 6867, Parent: 1)
- systemd New Fork (PID: 6868, Parent: 1)
- systemd New Fork (PID: 6870, Parent: 1)
- systemd New Fork (PID: 6871, Parent: 1860)
- systemd New Fork (PID: 6874, Parent: 1)
- systemd New Fork (PID: 6932, Parent: 1)
- systemd New Fork (PID: 6935, Parent: 1)
- systemd New Fork (PID: 6939, Parent: 1)
- systemd New Fork (PID: 6944, Parent: 1)
- systemd New Fork (PID: 6945, Parent: 1)
- systemd New Fork (PID: 6952, Parent: 1)
- systemd New Fork (PID: 6953, Parent: 1)
- systemd New Fork (PID: 6954, Parent: 1)
- systemd New Fork (PID: 6958, Parent: 1)
- accounts-daemon New Fork (PID: 6964, Parent: 6958)
- language-validate New Fork (PID: 6965, Parent: 6964)
- language-options New Fork (PID: 6966, Parent: 6965)
- systemd New Fork (PID: 6973, Parent: 1)
- cleanup
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
SUSP_XORed_Mozilla | Detects suspicious single byte XORed keyword \'Mozilla/5.0\' - it uses yara\'s XOR modifier and therefore cannot print the XOR key. You can use the CyberChef recipe linked in the reference field to brute force the used key. | Florian Roth |
| |
JoeSecurity_Mirai_8 | Yara detected Mirai | Joe Security |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
SUSP_XORed_Mozilla | Detects suspicious single byte XORed keyword \'Mozilla/5.0\' - it uses yara\'s XOR modifier and therefore cannot print the XOR key. You can use the CyberChef recipe linked in the reference field to brute force the used key. | Florian Roth |
| |
SUSP_XORed_Mozilla | Detects suspicious single byte XORed keyword \'Mozilla/5.0\' - it uses yara\'s XOR modifier and therefore cannot print the XOR key. You can use the CyberChef recipe linked in the reference field to brute force the used key. | Florian Roth |
| |
SUSP_XORed_Mozilla | Detects suspicious single byte XORed keyword \'Mozilla/5.0\' - it uses yara\'s XOR modifier and therefore cannot print the XOR key. You can use the CyberChef recipe linked in the reference field to brute force the used key. | Florian Roth |
| |
SUSP_XORed_Mozilla | Detects suspicious single byte XORed keyword \'Mozilla/5.0\' - it uses yara\'s XOR modifier and therefore cannot print the XOR key. You can use the CyberChef recipe linked in the reference field to brute force the used key. | Florian Roth |
| |
SUSP_XORed_Mozilla | Detects suspicious single byte XORed keyword \'Mozilla/5.0\' - it uses yara\'s XOR modifier and therefore cannot print the XOR key. You can use the CyberChef recipe linked in the reference field to brute force the used key. | Florian Roth |
| |
Click to see the 5 entries |
⊘No Snort rule has matched
Click to jump to signature section
Show All Signature Results
AV Detection |
---|
Source: | Virustotal: | Perma Link |
Source: | Reads CPU info from /sys: | Jump to behavior | ||
Source: | Reads CPU info from /sys: | Jump to behavior | ||
Source: | Reads CPU info from /sys: | Jump to behavior | ||
Source: | Reads CPU info from /sys: | Jump to behavior | ||
Source: | Reads CPU info from /sys: | Jump to behavior | ||
Source: | Reads CPU info from /sys: | |||
Source: | Reads CPU info from /sys: | |||
Source: | Reads CPU info from /sys: |
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: |