Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
SBNGwWC7Wb

Overview

General Information

Sample Name:SBNGwWC7Wb
Analysis ID:635393
MD5:275c6e393dcacee32b9ddd8bb4ad8196
SHA1:64a8605d5f69142a08385b359d3a6fd73120880d
SHA256:bb0fea23f67c783d1b0d3f8f92e1fd91f1c5d85f7782bc135f0269057e2ab4c3
Tags:32elfmipsmirai
Infos:

Detection

Mirai
Score:68
Range:0 - 100
Whitelisted:false

Signatures

Yara detected Mirai
Multi AV Scanner detection for submitted file
Sample is packed with UPX
Uses known network protocols on non-standard ports
Sample tries to kill multiple processes (SIGKILL)
Sample contains only a LOAD segment without any section mappings
Yara signature match
Uses the "uname" system call to query kernel version information (possible evasion)
Enumerates processes within the "proc" file system
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Detected TCP or UDP traffic on non-standard ports
Sample listens on a socket
Sample tries to kill a process (SIGKILL)

Classification

Analysis Advice

Static ELF header machine description suggests that the sample might not execute correctly on this machine.
All HTTP servers contacted by the sample do not answer. The sample is likely an old dropper which does no longer work.
Static ELF header machine description suggests that the sample might only run correctly on MIPS or ARM architectures.
Joe Sandbox Version:34.0.0 Boulder Opal
Analysis ID:635393
Start date and time: 27/05/202220:58:412022-05-27 20:58:41 +02:00
Joe Sandbox Product:CloudBasic
Overall analysis duration:0h 6m 12s
Hypervisor based Inspection enabled:false
Report type:light
Sample file name:SBNGwWC7Wb
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Detection:MAL
Classification:mal68.spre.troj.evad.lin@0/0@0/0
  • Report size exceeded maximum capacity and may have missing network information.
  • TCP Packets have been reduced to 100
Command:/tmp/SBNGwWC7Wb
PID:6224
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
Infected
Standard Error:
  • system is lnxubuntu20
  • SBNGwWC7Wb (PID: 6224, Parent: 6122, MD5: 0083f1f0e77be34ad27f849842bbb00c) Arguments: /tmp/SBNGwWC7Wb
  • cleanup
SourceRuleDescriptionAuthorStrings
SBNGwWC7WbSUSP_ELF_LNX_UPX_Compressed_FileDetects a suspicious ELF binary with UPX compressionFlorian Roth
  • 0x9cf0:$s1: PROT_EXEC|PROT_WRITE failed.
  • 0x9d5f:$s2: $Id: UPX
  • 0x9d10:$s3: $Info: This file is packed with the UPX executable packer
SourceRuleDescriptionAuthorStrings
dump.pcapJoeSecurity_Mirai_12Yara detected MiraiJoe Security
    No Snort rule has matched

    Click to jump to signature section

    Show All Signature Results

    AV Detection

    barindex
    Source: SBNGwWC7WbVirustotal: Detection: 21%Perma Link
    Source: SBNGwWC7WbReversingLabs: Detection: 25%

    Networking

    barindex
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 38050
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 38054
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 38056
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 38062
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 38064
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 38066
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 38072
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 38076
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 38078
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 38080
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 38082
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 38088
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 38092
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 38096
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 38100
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 38104
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 38110
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 38112
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 38120
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 38124
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 38128
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 38174
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 38218
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 38242
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 38260
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 38266
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 38282
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 38304
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 48138
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 48146
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 48156
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 48164
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 48176
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 48188
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 48214
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 48230
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 48250
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 48270
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 48288
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 48312
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 48330
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 48350
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 48368
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 48396
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 48420
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 48458
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 48480
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 48502
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 48524
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 48550
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 36132
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 48568
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 36152
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 36170
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 48594
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 36196
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 48626
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 36222
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 48652
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 36246
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 48684
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 36274
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 48718
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 36302
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 36318
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 36328
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 36346
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 36360
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 36382
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 36402
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 36424
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 36474
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 36514
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 36526
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 36534
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 36542
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 36546
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 36554
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 36568
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 36588
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 36608
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 36636
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 36662
    Source: global trafficTCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
    Source: global trafficTCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
    Source: global trafficTCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
    Source: global trafficTCP traffic: 192.168.2.23:39008 -> 45.95.169.139:9372
    Source: /tmp/SBNGwWC7Wb (PID: 6234)Socket: 0.0.0.0::23
    Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443
    Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
    Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
    Source: unknownTCP traffic detected without corresponding DNS query: 63.71.236.63
    Source: unknownTCP traffic detected without corresponding DNS query: 114.11.7.63
    Source: unknownTCP traffic detected without corresponding DNS query: 139.141.47.182
    Source: unknownTCP traffic detected without corresponding DNS query: 95.124.131.63
    Source: unknownTCP traffic detected without corresponding DNS query: 213.120.200.66
    Source: unknownTCP traffic detected without corresponding DNS query: 166.43.190.18
    Source: unknownTCP traffic detected without corresponding DNS query: 38.53.114.202
    Source: unknownTCP traffic detected without corresponding DNS query: 11.232.197.117
    Source: unknownTCP traffic detected without corresponding DNS query: 96.168.229.181
    Source: unknownTCP traffic detected without corresponding DNS query: 137.11.225.229
    Source: unknownTCP traffic detected without corresponding DNS query: 23.32.199.1
    Source: unknownTCP traffic detected without corresponding DNS query: 242.149.47.248
    Source: unknownTCP traffic detected without corresponding DNS query: 252.85.7.122
    Source: unknownTCP traffic detected without corresponding DNS query: 47.234.140.22
    Source: unknownTCP traffic detected without corresponding DNS query: 173.94.178.226
    Source: unknownTCP traffic detected without corresponding DNS query: 52.139.163.1
    Source: unknownTCP traffic detected without corresponding DNS query: 43.120.4.1
    Source: unknownTCP traffic detected without corresponding DNS query: 195.141.98.39
    Source: unknownTCP traffic detected without corresponding DNS query: 44.155.181.185
    Source: unknownTCP traffic detected without corresponding DNS query: 248.164.162.83
    Source: unknownTCP traffic detected without corresponding DNS query: 251.88.185.91
    Source: unknownTCP traffic detected without corresponding DNS query: 119.86.111.240
    Source: unknownTCP traffic detected without corresponding DNS query: 251.53.225.130
    Source: unknownTCP traffic detected without corresponding DNS query: 96.65.139.164
    Source: unknownTCP traffic detected without corresponding DNS query: 102.51.242.244
    Source: unknownTCP traffic detected without corresponding DNS query: 249.0.64.154
    Source: unknownTCP traffic detected without corresponding DNS query: 21.27.160.173
    Source: unknownTCP traffic detected without corresponding DNS query: 143.72.214.224
    Source: unknownTCP traffic detected without corresponding DNS query: 139.247.185.140
    Source: unknownTCP traffic detected without corresponding DNS query: 3.79.46.235
    Source: unknownTCP traffic detected without corresponding DNS query: 129.249.147.96
    Source: unknownTCP traffic detected without corresponding DNS query: 123.212.21.227
    Source: unknownTCP traffic detected without corresponding DNS query: 90.240.50.9
    Source: unknownTCP traffic detected without corresponding DNS query: 60.106.246.77
    Source: unknownTCP traffic detected without corresponding DNS query: 8.168.135.183
    Source: unknownTCP traffic detected without corresponding DNS query: 143.70.171.206
    Source: unknownTCP traffic detected without corresponding DNS query: 80.204.106.229
    Source: unknownTCP traffic detected without corresponding DNS query: 3.63.126.132
    Source: unknownTCP traffic detected without corresponding DNS query: 159.6.169.8
    Source: unknownTCP traffic detected without corresponding DNS query: 161.83.96.126
    Source: unknownTCP traffic detected without corresponding DNS query: 140.65.55.67
    Source: unknownTCP traffic detected without corresponding DNS query: 23.150.236.123
    Source: unknownTCP traffic detected without corresponding DNS query: 28.116.95.220
    Source: unknownTCP traffic detected without corresponding DNS query: 53.3.91.208
    Source: unknownTCP traffic detected without corresponding DNS query: 196.192.149.130
    Source: unknownTCP traffic detected without corresponding DNS query: 141.71.20.212
    Source: unknownTCP traffic detected without corresponding DNS query: 132.41.22.128
    Source: unknownTCP traffic detected without corresponding DNS query: 11.178.47.154
    Source: SBNGwWC7WbString found in binary or memory: http://upx.sf.net

    System Summary

    barindex
    Source: /tmp/SBNGwWC7Wb (PID: 6234)SIGKILL sent: pid: 658, result: successful
    Source: /tmp/SBNGwWC7Wb (PID: 6234)SIGKILL sent: pid: 720, result: successful
    Source: /tmp/SBNGwWC7Wb (PID: 6234)SIGKILL sent: pid: 759, result: successful
    Source: /tmp/SBNGwWC7Wb (PID: 6234)SIGKILL sent: pid: 772, result: successful
    Source: /tmp/SBNGwWC7Wb (PID: 6234)SIGKILL sent: pid: 789, result: successful
    Source: /tmp/SBNGwWC7Wb (PID: 6234)SIGKILL sent: pid: 800, result: successful
    Source: /tmp/SBNGwWC7Wb (PID: 6234)SIGKILL sent: pid: 904, result: successful
    Source: /tmp/SBNGwWC7Wb (PID: 6234)SIGKILL sent: pid: 936, result: successful
    Source: /tmp/SBNGwWC7Wb (PID: 6234)SIGKILL sent: pid: 1320, result: successful
    Source: /tmp/SBNGwWC7Wb (PID: 6234)SIGKILL sent: pid: 1334, result: successful
    Source: /tmp/SBNGwWC7Wb (PID: 6234)SIGKILL sent: pid: 1335, result: successful
    Source: /tmp/SBNGwWC7Wb (PID: 6234)SIGKILL sent: pid: 1389, result: successful
    Source: /tmp/SBNGwWC7Wb (PID: 6234)SIGKILL sent: pid: 1463, result: successful
    Source: /tmp/SBNGwWC7Wb (PID: 6234)SIGKILL sent: pid: 1465, result: successful
    Source: /tmp/SBNGwWC7Wb (PID: 6234)SIGKILL sent: pid: 1576, result: successful
    Source: /tmp/SBNGwWC7Wb (PID: 6234)SIGKILL sent: pid: 1809, result: successful
    Source: /tmp/SBNGwWC7Wb (PID: 6234)SIGKILL sent: pid: 1872, result: successful
    Source: /tmp/SBNGwWC7Wb (PID: 6234)SIGKILL sent: pid: 1888, result: successful
    Source: /tmp/SBNGwWC7Wb (PID: 6234)SIGKILL sent: pid: 1890, result: successful
    Source: /tmp/SBNGwWC7Wb (PID: 6234)SIGKILL sent: pid: 1983, result: successful
    Source: /tmp/SBNGwWC7Wb (PID: 6234)SIGKILL sent: pid: 2048, result: successful
    Source: /tmp/SBNGwWC7Wb (PID: 6234)SIGKILL sent: pid: 2062, result: successful
    Source: /tmp/SBNGwWC7Wb (PID: 6234)SIGKILL sent: pid: 6042, result: successful
    Source: /tmp/SBNGwWC7Wb (PID: 6234)SIGKILL sent: pid: 6187, result: successful
    Source: /tmp/SBNGwWC7Wb (PID: 6234)SIGKILL sent: pid: 6226, result: successful
    Source: /tmp/SBNGwWC7Wb (PID: 6234)SIGKILL sent: pid: 6238, result: successful
    Source: LOAD without section mappingsProgram segment: 0x100000
    Source: SBNGwWC7Wb, type: SAMPLEMatched rule: SUSP_ELF_LNX_UPX_Compressed_File date = 2018-12-12, author = Florian Roth, description = Detects a suspicious ELF binary with UPX compression, reference = Internal Research, score = 038ff8b2fef16f8ee9d70e6c219c5f380afe1a21761791e8cbda21fa4d09fdb4
    Source: /tmp/SBNGwWC7Wb (PID: 6234)SIGKILL sent: pid: 658, result: successful
    Source: /tmp/SBNGwWC7Wb (PID: 6234)SIGKILL sent: pid: 720, result: successful
    Source: /tmp/SBNGwWC7Wb (PID: 6234)SIGKILL sent: pid: 759, result: successful
    Source: /tmp/SBNGwWC7Wb (PID: 6234)SIGKILL sent: pid: 772, result: successful
    Source: /tmp/SBNGwWC7Wb (PID: 6234)SIGKILL sent: pid: 789, result: successful
    Source: /tmp/SBNGwWC7Wb (PID: 6234)SIGKILL sent: pid: 800, result: successful
    Source: /tmp/SBNGwWC7Wb (PID: 6234)SIGKILL sent: pid: 904, result: successful
    Source: /tmp/SBNGwWC7Wb (PID: 6234)SIGKILL sent: pid: 936, result: successful
    Source: /tmp/SBNGwWC7Wb (PID: 6234)SIGKILL sent: pid: 1320, result: successful
    Source: /tmp/SBNGwWC7Wb (PID: 6234)SIGKILL sent: pid: 1334, result: successful
    Source: /tmp/SBNGwWC7Wb (PID: 6234)SIGKILL sent: pid: 1335, result: successful
    Source: /tmp/SBNGwWC7Wb (PID: 6234)SIGKILL sent: pid: 1389, result: successful
    Source: /tmp/SBNGwWC7Wb (PID: 6234)SIGKILL sent: pid: 1463, result: successful
    Source: /tmp/SBNGwWC7Wb (PID: 6234)SIGKILL sent: pid: 1465, result: successful
    Source: /tmp/SBNGwWC7Wb (PID: 6234)SIGKILL sent: pid: 1576, result: successful
    Source: /tmp/SBNGwWC7Wb (PID: 6234)SIGKILL sent: pid: 1809, result: successful
    Source: /tmp/SBNGwWC7Wb (PID: 6234)SIGKILL sent: pid: 1872, result: successful
    Source: /tmp/SBNGwWC7Wb (PID: 6234)SIGKILL sent: pid: 1888, result: successful
    Source: /tmp/SBNGwWC7Wb (PID: 6234)SIGKILL sent: pid: 1890, result: successful
    Source: /tmp/SBNGwWC7Wb (PID: 6234)SIGKILL sent: pid: 1983, result: successful
    Source: /tmp/SBNGwWC7Wb (PID: 6234)SIGKILL sent: pid: 2048, result: successful
    Source: /tmp/SBNGwWC7Wb (PID: 6234)SIGKILL sent: pid: 2062, result: successful
    Source: /tmp/SBNGwWC7Wb (PID: 6234)SIGKILL sent: pid: 6042, result: successful
    Source: /tmp/SBNGwWC7Wb (PID: 6234)SIGKILL sent: pid: 6187, result: successful
    Source: /tmp/SBNGwWC7Wb (PID: 6234)SIGKILL sent: pid: 6226, result: successful
    Source: /tmp/SBNGwWC7Wb (PID: 6234)SIGKILL sent: pid: 6238, result: successful
    Source: classification engineClassification label: mal68.spre.troj.evad.lin@0/0@0/0

    Data Obfuscation

    barindex
    Source: initial sampleString containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $
    Source: initial sampleString containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $
    Source: initial sampleString containing UPX found: $Id: UPX 3.94 Copyright (C) 1996-2017 the UPX Team. All Rights Reserved. $
    Source: /tmp/SBNGwWC7Wb (PID: 6234)File opened: /proc/1582/exe
    Source: /tmp/SBNGwWC7Wb (PID: 6234)File opened: /proc/2033/exe
    Source: /tmp/SBNGwWC7Wb (PID: 6234)File opened: /proc/2275/exe
    Source: /tmp/SBNGwWC7Wb (PID: 6234)File opened: /proc/3088/exe
    Source: /tmp/SBNGwWC7Wb (PID: 6234)File opened: /proc/1612/exe
    Source: /tmp/SBNGwWC7Wb (PID: 6234)File opened: /proc/1579/exe
    Source: /tmp/SBNGwWC7Wb (PID: 6234)File opened: /proc/1699/exe
    Source: /tmp/SBNGwWC7Wb (PID: 6234)File opened: /proc/1335/exe
    Source: /tmp/SBNGwWC7Wb (PID: 6234)File opened: /proc/1698/exe
    Source: /tmp/SBNGwWC7Wb (PID: 6234)File opened: /proc/2028/exe
    Source: /tmp/SBNGwWC7Wb (PID: 6234)File opened: /proc/1334/exe
    Source: /tmp/SBNGwWC7Wb (PID: 6234)File opened: /proc/1576/exe
    Source: /tmp/SBNGwWC7Wb (PID: 6234)File opened: /proc/2302/exe
    Source: /tmp/SBNGwWC7Wb (PID: 6234)File opened: /proc/3236/exe
    Source: /tmp/SBNGwWC7Wb (PID: 6234)File opened: /proc/2025/exe
    Source: /tmp/SBNGwWC7Wb (PID: 6234)File opened: /proc/2146/exe
    Source: /tmp/SBNGwWC7Wb (PID: 6234)File opened: /proc/910/exe
    Source: /tmp/SBNGwWC7Wb (PID: 6234)File opened: /proc/6226/exe
    Source: /tmp/SBNGwWC7Wb (PID: 6234)File opened: /proc/912/exe
    Source: /tmp/SBNGwWC7Wb (PID: 6234)File opened: /proc/517/exe
    Source: /tmp/SBNGwWC7Wb (PID: 6234)File opened: /proc/759/exe
    Source: /tmp/SBNGwWC7Wb (PID: 6234)File opened: /proc/2307/exe
    Source: /tmp/SBNGwWC7Wb (PID: 6234)File opened: /proc/918/exe
    Source: /tmp/SBNGwWC7Wb (PID: 6234)File opened: /proc/6240/exe
    Source: /tmp/SBNGwWC7Wb (PID: 6234)File opened: /proc/1594/exe
    Source: /tmp/SBNGwWC7Wb (PID: 6234)File opened: /proc/2285/exe
    Source: /tmp/SBNGwWC7Wb (PID: 6234)File opened: /proc/2281/exe
    Source: /tmp/SBNGwWC7Wb (PID: 6234)File opened: /proc/1349/exe
    Source: /tmp/SBNGwWC7Wb (PID: 6234)File opened: /proc/1623/exe
    Source: /tmp/SBNGwWC7Wb (PID: 6234)File opened: /proc/761/exe
    Source: /tmp/SBNGwWC7Wb (PID: 6234)File opened: /proc/1622/exe
    Source: /tmp/SBNGwWC7Wb (PID: 6234)File opened: /proc/884/exe
    Source: /tmp/SBNGwWC7Wb (PID: 6234)File opened: /proc/1983/exe
    Source: /tmp/SBNGwWC7Wb (PID: 6234)File opened: /proc/2038/exe
    Source: /tmp/SBNGwWC7Wb (PID: 6234)File opened: /proc/1344/exe
    Source: /tmp/SBNGwWC7Wb (PID: 6234)File opened: /proc/1465/exe
    Source: /tmp/SBNGwWC7Wb (PID: 6234)File opened: /proc/1586/exe
    Source: /tmp/SBNGwWC7Wb (PID: 6234)File opened: /proc/1463/exe
    Source: /tmp/SBNGwWC7Wb (PID: 6234)File opened: /proc/2156/exe
    Source: /tmp/SBNGwWC7Wb (PID: 6234)File opened: /proc/800/exe
    Source: /tmp/SBNGwWC7Wb (PID: 6234)File opened: /proc/6238/exe
    Source: /tmp/SBNGwWC7Wb (PID: 6234)File opened: /proc/801/exe
    Source: /tmp/SBNGwWC7Wb (PID: 6234)File opened: /proc/1629/exe
    Source: /tmp/SBNGwWC7Wb (PID: 6234)File opened: /proc/1627/exe
    Source: /tmp/SBNGwWC7Wb (PID: 6234)File opened: /proc/1900/exe
    Source: /tmp/SBNGwWC7Wb (PID: 6234)File opened: /proc/3021/exe
    Source: /tmp/SBNGwWC7Wb (PID: 6234)File opened: /proc/491/exe
    Source: /tmp/SBNGwWC7Wb (PID: 6234)File opened: /proc/2294/exe
    Source: /tmp/SBNGwWC7Wb (PID: 6234)File opened: /proc/2050/exe
    Source: /tmp/SBNGwWC7Wb (PID: 6234)File opened: /proc/1877/exe
    Source: /tmp/SBNGwWC7Wb (PID: 6234)File opened: /proc/772/exe
    Source: /tmp/SBNGwWC7Wb (PID: 6234)File opened: /proc/1633/exe
    Source: /tmp/SBNGwWC7Wb (PID: 6234)File opened: /proc/1599/exe
    Source: /tmp/SBNGwWC7Wb (PID: 6234)File opened: /proc/1632/exe
    Source: /tmp/SBNGwWC7Wb (PID: 6234)File opened: /proc/774/exe
    Source: /tmp/SBNGwWC7Wb (PID: 6234)File opened: /proc/1477/exe
    Source: /tmp/SBNGwWC7Wb (PID: 6234)File opened: /proc/654/exe
    Source: /tmp/SBNGwWC7Wb (PID: 6234)File opened: /proc/896/exe
    Source: /tmp/SBNGwWC7Wb (PID: 6234)File opened: /proc/1476/exe
    Source: /tmp/SBNGwWC7Wb (PID: 6234)File opened: /proc/1872/exe
    Source: /tmp/SBNGwWC7Wb (PID: 6234)File opened: /proc/2048/exe
    Source: /tmp/SBNGwWC7Wb (PID: 6234)File opened: /proc/655/exe
    Source: /tmp/SBNGwWC7Wb (PID: 6234)File opened: /proc/1475/exe
    Source: /tmp/SBNGwWC7Wb (PID: 6234)File opened: /proc/2289/exe
    Source: /tmp/SBNGwWC7Wb (PID: 6234)File opened: /proc/656/exe
    Source: /tmp/SBNGwWC7Wb (PID: 6234)File opened: /proc/777/exe
    Source: /tmp/SBNGwWC7Wb (PID: 6234)File opened: /proc/657/exe
    Source: /tmp/SBNGwWC7Wb (PID: 6234)File opened: /proc/4466/exe
    Source: /tmp/SBNGwWC7Wb (PID: 6234)File opened: /proc/658/exe
    Source: /tmp/SBNGwWC7Wb (PID: 6234)File opened: /proc/4467/exe
    Source: /tmp/SBNGwWC7Wb (PID: 6234)File opened: /proc/4468/exe
    Source: /tmp/SBNGwWC7Wb (PID: 6234)File opened: /proc/4469/exe
    Source: /tmp/SBNGwWC7Wb (PID: 6234)File opened: /proc/419/exe
    Source: /tmp/SBNGwWC7Wb (PID: 6234)File opened: /proc/936/exe
    Source: /tmp/SBNGwWC7Wb (PID: 6234)File opened: /proc/1639/exe
    Source: /tmp/SBNGwWC7Wb (PID: 6234)File opened: /proc/1638/exe
    Source: /tmp/SBNGwWC7Wb (PID: 6234)File opened: /proc/2208/exe
    Source: /tmp/SBNGwWC7Wb (PID: 6234)File opened: /proc/2180/exe
    Source: /tmp/SBNGwWC7Wb (PID: 6234)File opened: /proc/1809/exe
    Source: /tmp/SBNGwWC7Wb (PID: 6234)File opened: /proc/1494/exe
    Source: /tmp/SBNGwWC7Wb (PID: 6234)File opened: /proc/1890/exe
    Source: /tmp/SBNGwWC7Wb (PID: 6234)File opened: /proc/2063/exe
    Source: /tmp/SBNGwWC7Wb (PID: 6234)File opened: /proc/2062/exe
    Source: /tmp/SBNGwWC7Wb (PID: 6234)File opened: /proc/1888/exe
    Source: /tmp/SBNGwWC7Wb (PID: 6234)File opened: /proc/1886/exe
    Source: /tmp/SBNGwWC7Wb (PID: 6234)File opened: /proc/420/exe
    Source: /tmp/SBNGwWC7Wb (PID: 6234)File opened: /proc/1489/exe
    Source: /tmp/SBNGwWC7Wb (PID: 6234)File opened: /proc/785/exe
    Source: /tmp/SBNGwWC7Wb (PID: 6234)File opened: /proc/1642/exe
    Source: /tmp/SBNGwWC7Wb (PID: 6234)File opened: /proc/788/exe
    Source: /tmp/SBNGwWC7Wb (PID: 6234)File opened: /proc/667/exe
    Source: /tmp/SBNGwWC7Wb (PID: 6234)File opened: /proc/789/exe
    Source: /tmp/SBNGwWC7Wb (PID: 6234)File opened: /proc/1648/exe
    Source: /tmp/SBNGwWC7Wb (PID: 6234)File opened: /proc/6152/exe
    Source: /tmp/SBNGwWC7Wb (PID: 6234)File opened: /proc/4495/exe
    Source: /tmp/SBNGwWC7Wb (PID: 6234)File opened: /proc/6159/exe
    Source: /tmp/SBNGwWC7Wb (PID: 6234)File opened: /proc/4498/exe
    Source: /tmp/SBNGwWC7Wb (PID: 6234)File opened: /proc/2078/exe
    Source: /tmp/SBNGwWC7Wb (PID: 6234)File opened: /proc/2077/exe
    Source: /tmp/SBNGwWC7Wb (PID: 6234)File opened: /proc/2074/exe
    Source: /tmp/SBNGwWC7Wb (PID: 6234)File opened: /proc/2195/exe
    Source: /tmp/SBNGwWC7Wb (PID: 6234)File opened: /proc/670/exe
    Source: /tmp/SBNGwWC7Wb (PID: 6234)File opened: /proc/2746/exe
    Source: /tmp/SBNGwWC7Wb (PID: 6234)File opened: /proc/793/exe
    Source: /tmp/SBNGwWC7Wb (PID: 6234)File opened: /proc/1656/exe

    Hooking and other Techniques for Hiding and Protection

    barindex
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 38050
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 38054
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 38056
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 38062
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 38064
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 38066
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 38072
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 38076
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 38078
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 38080
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 38082
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 38088
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 38092
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 38096
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 38100
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 38104
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 38110
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 38112
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 38120
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 38124
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 38128
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 38174
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 38218
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 38242
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 38260
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 38266
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 38282
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 38304
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 48138
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 48146
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 48156
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 48164
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 48176
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 48188
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 48214
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 48230
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 48250
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 48270
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 48288
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 48312
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 48330
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 48350
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 48368
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 48396
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 48420
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 48458
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 48480
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 48502
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 48524
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 48550
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 36132
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 48568
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 36152
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 36170
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 48594
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 36196
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 48626
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 36222
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 48652
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 36246
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 48684
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 36274
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 48718
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 36302
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 36318
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 36328
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 36346
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 36360
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 36382
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 36402
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 36424
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 36474
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 36514
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 36526
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 36534
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 36542
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 36546
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 36554
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 36568
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 36588
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 36608
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 36636
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 36662
    Source: /tmp/SBNGwWC7Wb (PID: 6224)Queries kernel information via 'uname':
    Source: SBNGwWC7Wb, 6224.1.00000000e275f183.00000000a359d085.rw-.sdmp, SBNGwWC7Wb, 6226.1.00000000e275f183.00000000a359d085.rw-.sdmp, SBNGwWC7Wb, 6227.1.00000000e275f183.00000000a359d085.rw-.sdmp, SBNGwWC7Wb, 6236.1.00000000e275f183.00000000a359d085.rw-.sdmp, SBNGwWC7Wb, 6238.1.00000000e275f183.00000000a359d085.rw-.sdmpBinary or memory string: V!/etc/qemu-binfmt/mips
    Source: SBNGwWC7Wb, 6224.1.00000000e275f183.00000000a359d085.rw-.sdmp, SBNGwWC7Wb, 6226.1.00000000e275f183.00000000a359d085.rw-.sdmp, SBNGwWC7Wb, 6227.1.00000000e275f183.00000000a359d085.rw-.sdmp, SBNGwWC7Wb, 6236.1.00000000e275f183.00000000a359d085.rw-.sdmp, SBNGwWC7Wb, 6238.1.00000000e275f183.00000000a359d085.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/mips
    Source: SBNGwWC7Wb, 6224.1.00000000d4b4c6bb.00000000a7343375.rw-.sdmp, SBNGwWC7Wb, 6226.1.00000000d4b4c6bb.00000000a7343375.rw-.sdmp, SBNGwWC7Wb, 6227.1.00000000d4b4c6bb.00000000a7343375.rw-.sdmp, SBNGwWC7Wb, 6236.1.00000000d4b4c6bb.00000000a7343375.rw-.sdmp, SBNGwWC7Wb, 6238.1.00000000d4b4c6bb.00000000a7343375.rw-.sdmpBinary or memory string: /usr/bin/qemu-mips
    Source: SBNGwWC7Wb, 6224.1.00000000d4b4c6bb.00000000a7343375.rw-.sdmp, SBNGwWC7Wb, 6226.1.00000000d4b4c6bb.00000000a7343375.rw-.sdmp, SBNGwWC7Wb, 6227.1.00000000d4b4c6bb.00000000a7343375.rw-.sdmp, SBNGwWC7Wb, 6236.1.00000000d4b4c6bb.00000000a7343375.rw-.sdmp, SBNGwWC7Wb, 6238.1.00000000d4b4c6bb.00000000a7343375.rw-.sdmpBinary or memory string: r#x86_64/usr/bin/qemu-mips/tmp/SBNGwWC7WbSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/SBNGwWC7Wb

    Stealing of Sensitive Information

    barindex
    Source: Yara matchFile source: dump.pcap, type: PCAP

    Remote Access Functionality

    barindex
    Source: Yara matchFile source: dump.pcap, type: PCAP
    Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
    Valid AccountsWindows Management InstrumentationPath InterceptionPath Interception1
    Obfuscated Files or Information
    1
    OS Credential Dumping
    11
    Security Software Discovery
    Remote ServicesData from Local SystemExfiltration Over Other Network Medium1
    Encrypted Channel
    Eavesdrop on Insecure Network CommunicationRemotely Track Device Without Authorization1
    Service Stop
    Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over Bluetooth11
    Non-Standard Port
    Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
    Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated Exfiltration1
    Application Layer Protocol
    Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
    No configs have been found
    Hide Legend

    Legend:

    • Process
    • Signature
    • Created File
    • DNS/IP Info
    • Is Dropped
    • Number of created Files
    • Is malicious
    • Internet
    behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 635393 Sample: SBNGwWC7Wb Startdate: 27/05/2022 Architecture: LINUX Score: 68 22 168.182.95.198, 23 YUMBRANDSUS United States 2->22 24 140.104.76.138 WISCNET1-ASUS United States 2->24 26 98 other IPs or domains 2->26 28 Multi AV Scanner detection for submitted file 2->28 30 Yara detected Mirai 2->30 32 Uses known network protocols on non-standard ports 2->32 34 Sample is packed with UPX 2->34 9 SBNGwWC7Wb 2->9         started        signatures3 process4 process5 11 SBNGwWC7Wb 9->11         started        13 SBNGwWC7Wb 9->13         started        process6 15 SBNGwWC7Wb 11->15         started        18 SBNGwWC7Wb 11->18         started        signatures7 36 Sample tries to kill multiple processes (SIGKILL) 15->36 20 SBNGwWC7Wb 18->20         started        process8
    SourceDetectionScannerLabelLink
    SBNGwWC7Wb22%VirustotalBrowse
    SBNGwWC7Wb25%ReversingLabsLinux.Trojan.Mirai
    No Antivirus matches
    No Antivirus matches
    No Antivirus matches
    No contacted domains info
    NameSourceMaliciousAntivirus DetectionReputation
    http://upx.sf.netSBNGwWC7Wbfalse
      high
      • No. of IPs < 25%
      • 25% < No. of IPs < 50%
      • 50% < No. of IPs < 75%
      • 75% < No. of IPs
      IPDomainCountryFlagASNASN NameMalicious
      64.232.31.217
      unknownUnited States
      7029WINDSTREAMUSfalse
      63.184.206.219
      unknownUnited States
      1239SPRINTLINKUSfalse
      246.132.172.181
      unknownReserved
      unknownunknownfalse
      207.32.216.34
      unknownUnited States
      143151GSERVERSUSfalse
      28.242.55.33
      unknownUnited States
      7922COMCAST-7922USfalse
      220.21.234.141
      unknownJapan17676GIGAINFRASoftbankBBCorpJPfalse
      168.182.95.198
      unknownUnited States
      18522YUMBRANDSUSfalse
      45.25.228.59
      unknownUnited States
      7018ATT-INTERNET4USfalse
      98.19.126.234
      unknownUnited States
      7029WINDSTREAMUSfalse
      255.84.172.156
      unknownReserved
      unknownunknownfalse
      46.172.163.178
      unknownRussian Federation
      48044CHITA-ON-LINE-ASRUfalse
      214.169.204.9
      unknownUnited States
      721DNIC-ASBLK-00721-00726USfalse
      100.227.43.9
      unknownUnited States
      21928T-MOBILE-AS21928USfalse
      43.118.46.72
      unknownJapan4249LILLY-ASUSfalse
      50.181.162.86
      unknownUnited States
      7922COMCAST-7922USfalse
      22.246.2.216
      unknownUnited States
      8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
      67.96.186.6
      unknownUnited States
      6977IAC-ASUSfalse
      160.42.218.209
      unknownUnited States
      1761TDIR-CAPNETUSfalse
      247.238.59.67
      unknownReserved
      unknownunknownfalse
      69.109.26.14
      unknownUnited States
      7018ATT-INTERNET4USfalse
      85.35.1.143
      unknownItaly
      3269ASN-IBSNAZITfalse
      120.188.79.134
      unknownIndonesia
      4761INDOSAT-INP-APINDOSATInternetNetworkProviderIDfalse
      47.195.167.195
      unknownUnited States
      5650FRONTIER-FRTRUSfalse
      171.67.143.13
      unknownUnited States
      32STANFORDUSfalse
      255.56.220.95
      unknownReserved
      unknownunknownfalse
      159.1.39.145
      unknownUnited States
      4193WA-STATE-GOVUSfalse
      113.247.214.242
      unknownChina
      4134CHINANET-BACKBONENo31Jin-rongStreetCNfalse
      252.251.81.4
      unknownReserved
      unknownunknownfalse
      172.32.220.45
      unknownUnited States
      21928T-MOBILE-AS21928USfalse
      140.211.52.231
      unknownUnited States
      3701NERONETUSfalse
      220.14.193.199
      unknownJapan17676GIGAINFRASoftbankBBCorpJPfalse
      150.199.109.75
      unknownUnited States
      2572MORENETUSfalse
      18.213.221.156
      unknownUnited States
      14618AMAZON-AESUSfalse
      246.131.18.105
      unknownReserved
      unknownunknownfalse
      253.93.243.136
      unknownReserved
      unknownunknownfalse
      28.77.143.29
      unknownUnited States
      7922COMCAST-7922USfalse
      217.113.75.78
      unknownBelgium
      3491BTN-ASNUSfalse
      145.83.208.94
      unknownNetherlands
      1103SURFNET-NLSURFnetTheNetherlandsNLfalse
      201.111.171.232
      unknownMexico
      8151UninetSAdeCVMXfalse
      98.89.244.96
      unknownUnited States
      11351TWC-11351-NORTHEASTUSfalse
      117.55.179.250
      unknownKorea Republic of
      9770SPEEDONSTV-AS-KRLGHelloVisionCorpKRfalse
      176.177.113.98
      unknownFrance
      5410BOUYGTEL-ISPFRfalse
      112.213.114.218
      unknownHong Kong
      38197SUNHK-DATA-AS-APSunNetworkHongKongLimited-HongKongfalse
      140.104.76.138
      unknownUnited States
      2381WISCNET1-ASUSfalse
      252.202.169.243
      unknownReserved
      unknownunknownfalse
      47.178.236.161
      unknownUnited States
      5650FRONTIER-FRTRUSfalse
      137.41.141.14
      unknownUnited States
      721DNIC-ASBLK-00721-00726USfalse
      120.87.46.212
      unknownChina
      17623CNCGROUP-SZChinaUnicomShenzennetworkCNfalse
      12.69.83.54
      unknownUnited States
      7018ATT-INTERNET4USfalse
      92.38.145.170
      unknownAustria
      199524GCOREATfalse
      122.4.122.51
      unknownChina
      4134CHINANET-BACKBONENo31Jin-rongStreetCNfalse
      172.203.97.144
      unknownUnited States
      18747IFX18747USfalse
      185.38.220.182
      unknownPoland
      56523AMELEKTRONIKPLfalse
      251.179.142.95
      unknownReserved
      unknownunknownfalse
      248.231.10.213
      unknownReserved
      unknownunknownfalse
      199.245.173.166
      unknownUnited States
      10653MVANETUSfalse
      170.174.174.89
      unknownUnited States
      11685HNBCOL-ASUSfalse
      189.105.20.33
      unknownBrazil
      7738TelemarNorteLesteSABRfalse
      43.121.222.110
      unknownJapan4249LILLY-ASUSfalse
      2.163.103.53
      unknownGermany
      3320DTAGInternetserviceprovideroperationsDEfalse
      182.119.170.127
      unknownChina
      4837CHINA169-BACKBONECHINAUNICOMChina169BackboneCNfalse
      145.85.202.109
      unknownNetherlands
      1103SURFNET-NLSURFnetTheNetherlandsNLfalse
      188.78.234.108
      unknownSpain
      12479UNI2-ASESfalse
      135.4.62.162
      unknownUnited States
      10455LUCENT-CIOUSfalse
      215.174.150.203
      unknownUnited States
      721DNIC-ASBLK-00721-00726USfalse
      103.237.107.133
      unknownAustralia
      53580MARKETOUSfalse
      66.229.157.194
      unknownUnited States
      7922COMCAST-7922USfalse
      180.237.67.211
      unknownKorea Republic of
      9658ETPI-IDS-AS-APEasternTelecomsPhilsIncPHfalse
      3.102.75.253
      unknownUnited States
      16509AMAZON-02USfalse
      98.233.96.179
      unknownUnited States
      7922COMCAST-7922USfalse
      168.108.37.33
      unknownUnited States
      3597FundacionInnovaTARfalse
      142.31.146.109
      unknownCanada
      3633PROVINCE-OF-BRITISH-COLUMBIACAfalse
      33.236.64.10
      unknownUnited States
      2686ATGS-MMD-ASUSfalse
      114.241.91.184
      unknownChina
      4808CHINA169-BJChinaUnicomBeijingProvinceNetworkCNfalse
      134.244.73.128
      unknownUnited States
      3479PEACHNET-AS1USfalse
      149.176.228.12
      unknownAustralia
      87INDIANA-ASUSfalse
      101.83.244.147
      unknownChina
      4812CHINANET-SH-APChinaTelecomGroupCNfalse
      16.165.211.152
      unknownUnited States
      unknownunknownfalse
      142.80.215.163
      unknownCanada
      5769VIDEOTRONCAfalse
      57.62.64.136
      unknownBelgium
      2686ATGS-MMD-ASUSfalse
      123.69.92.169
      unknownChina
      9394CTTNETChinaTieTongTelecommunicationsCorporationCNfalse
      72.152.89.199
      unknownUnited States
      8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
      98.107.192.151
      unknownUnited States
      6167CELLCO-PARTUSfalse
      40.69.202.47
      unknownUnited States
      8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
      31.91.224.64
      unknownUnited Kingdom
      12576EELtdGBfalse
      196.147.8.25
      unknownEgypt
      36935Vodafone-EGfalse
      220.138.127.69
      unknownTaiwan; Republic of China (ROC)
      3462HINETDataCommunicationBusinessGroupTWfalse
      211.226.202.75
      unknownKorea Republic of
      4766KIXS-AS-KRKoreaTelecomKRfalse
      17.8.137.173
      unknownUnited States
      714APPLE-ENGINEERINGUSfalse
      145.107.128.126
      unknownNetherlands
      1103SURFNET-NLSURFnetTheNetherlandsNLfalse
      37.27.84.41
      unknownIran (ISLAMIC Republic Of)
      39232UNINETAZfalse
      91.215.129.120
      unknownRussian Federation
      41082URALTRANSCOM-ASUAfalse
      185.126.207.167
      unknownItaly
      208920ROCKETWAY-ASITfalse
      215.228.201.148
      unknownUnited States
      721DNIC-ASBLK-00721-00726USfalse
      212.22.245.89
      unknownGibraltar
      12798VCW-ASGibraltarGIfalse
      65.180.56.237
      unknownUnited States
      1239SPRINTLINKUSfalse
      7.138.173.10
      unknownUnited States
      3356LEVEL3USfalse
      179.137.207.90
      unknownBrazil
      26599TELEFONICABRASILSABRfalse
      69.128.229.182
      unknownUnited States
      4181TDS-ASUSfalse
      149.160.93.171
      unknownUnited States
      87INDIANA-ASUSfalse
      No context
      No context
      No context
      No context
      No context
      No created / dropped files found
      File type:ELF 32-bit MSB executable, MIPS, MIPS-I version 1 (SYSV), statically linked, stripped
      Entropy (8bit):7.940001959669167
      TrID:
      • ELF Executable and Linkable format (Linux) (4029/14) 50.16%
      • ELF Executable and Linkable format (generic) (4004/1) 49.84%
      File name:SBNGwWC7Wb
      File size:42432
      MD5:275c6e393dcacee32b9ddd8bb4ad8196
      SHA1:64a8605d5f69142a08385b359d3a6fd73120880d
      SHA256:bb0fea23f67c783d1b0d3f8f92e1fd91f1c5d85f7782bc135f0269057e2ab4c3
      SHA512:55a1f799d6f70f71201ff6eadfb06b773f962217bb2138b276aaf823fe601bec605ad8098c485103cd8f6f9912f34b0c4b70768368110f32856cd2c572ca6754
      SSDEEP:768:kBngnCJnfsrVyYfvYdu80skETund52DdwyX2uxPvxfG6sNEx/vjE88VPwqJgGlzg:kBgnwUVy8v0u83TunTL8v4653jE88eOu
      TLSH:B513F277DE1991B6EE5992720ACCC6879C56A9D07B03D88BE825D7E02EC70163203AF1
      File Content Preview:.ELF.......................@...4.........4. ...(...........................................\.F.\.F.\....................UPX!.d.........p...p.......T.......?.E.h4...@b..) ..]....E..$u..s...x..b.bU.ZN.S.#.W).........7........i... .AT...Y....L...............

      ELF header

      Class:ELF32
      Data:2's complement, big endian
      Version:1 (current)
      Machine:MIPS R3000
      Version Number:0x1
      Type:EXEC (Executable file)
      OS/ABI:UNIX - System V
      ABI Version:0
      Entry Point Address:0x109140
      Flags:0x1007
      ELF Header Size:52
      Program Header Offset:52
      Program Header Size:32
      Number of Program Headers:2
      Section Header Offset:0
      Section Header Size:40
      Number of Section Headers:0
      Header String Table Index:0
      TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
      LOAD0x00x1000000x1000000xa4840xa4844.13260x5R E0x10000
      LOAD0xd5c0x460d5c0x460d5c0x00x00.00000x6RW 0x10000
      TimestampSource PortDest PortSource IPDest IP
      May 27, 2022 20:59:29.559732914 CEST42836443192.168.2.2391.189.91.43
      May 27, 2022 20:59:29.815722942 CEST4251680192.168.2.23109.202.202.202
      May 27, 2022 20:59:31.904124022 CEST5916323192.168.2.2363.71.236.63
      May 27, 2022 20:59:31.904172897 CEST5916323192.168.2.23114.11.7.63
      May 27, 2022 20:59:31.904171944 CEST5916323192.168.2.23139.141.47.182
      May 27, 2022 20:59:31.904185057 CEST5916323192.168.2.2395.124.131.63
      May 27, 2022 20:59:31.904218912 CEST5916323192.168.2.23213.120.200.66
      May 27, 2022 20:59:31.904223919 CEST5916323192.168.2.23166.43.190.18
      May 27, 2022 20:59:31.904226065 CEST5916323192.168.2.2338.53.114.202
      May 27, 2022 20:59:31.904226065 CEST5916323192.168.2.2311.232.197.117
      May 27, 2022 20:59:31.904238939 CEST5916323192.168.2.2396.168.229.181
      May 27, 2022 20:59:31.904252052 CEST5916323192.168.2.23137.11.225.229
      May 27, 2022 20:59:31.904257059 CEST5916323192.168.2.2323.32.199.1
      May 27, 2022 20:59:31.904257059 CEST5916323192.168.2.23242.149.47.248
      May 27, 2022 20:59:31.904257059 CEST5916323192.168.2.23252.85.7.122
      May 27, 2022 20:59:31.904258013 CEST5916323192.168.2.2347.234.140.22
      May 27, 2022 20:59:31.904258013 CEST5916323192.168.2.23173.94.178.226
      May 27, 2022 20:59:31.904266119 CEST5916323192.168.2.2352.139.163.1
      May 27, 2022 20:59:31.904267073 CEST5916323192.168.2.2343.120.4.1
      May 27, 2022 20:59:31.904290915 CEST5916323192.168.2.23195.141.98.39
      May 27, 2022 20:59:31.904721975 CEST5916323192.168.2.2344.155.181.185
      May 27, 2022 20:59:31.904725075 CEST5916323192.168.2.23248.164.162.83
      May 27, 2022 20:59:31.904769897 CEST5916323192.168.2.23251.88.185.91
      May 27, 2022 20:59:31.904773951 CEST5916323192.168.2.23119.86.111.240
      May 27, 2022 20:59:31.904767036 CEST5916323192.168.2.23251.53.225.130
      May 27, 2022 20:59:31.904774904 CEST5916323192.168.2.2396.65.139.164
      May 27, 2022 20:59:31.904776096 CEST5916323192.168.2.23102.51.242.244
      May 27, 2022 20:59:31.904776096 CEST5916323192.168.2.23249.0.64.154
      May 27, 2022 20:59:31.904779911 CEST5916323192.168.2.2321.27.160.173
      May 27, 2022 20:59:31.904786110 CEST5916323192.168.2.23143.72.214.224
      May 27, 2022 20:59:31.904788971 CEST5916323192.168.2.23139.247.185.140
      May 27, 2022 20:59:31.904789925 CEST5916323192.168.2.233.79.46.235
      May 27, 2022 20:59:31.904793024 CEST5916323192.168.2.23129.249.147.96
      May 27, 2022 20:59:31.904793978 CEST5916323192.168.2.23123.212.21.227
      May 27, 2022 20:59:31.904797077 CEST5916323192.168.2.2390.240.50.9
      May 27, 2022 20:59:31.904798985 CEST5916323192.168.2.2360.106.246.77
      May 27, 2022 20:59:31.904799938 CEST5916323192.168.2.238.168.135.183
      May 27, 2022 20:59:31.904800892 CEST5916323192.168.2.23143.70.171.206
      May 27, 2022 20:59:31.904802084 CEST5916323192.168.2.2380.204.106.229
      May 27, 2022 20:59:31.904804945 CEST5916323192.168.2.233.63.126.132
      May 27, 2022 20:59:31.904814005 CEST5916323192.168.2.23159.6.169.8
      May 27, 2022 20:59:31.904822111 CEST5916323192.168.2.23161.83.96.126
      May 27, 2022 20:59:31.904827118 CEST5916323192.168.2.23140.65.55.67
      May 27, 2022 20:59:31.904828072 CEST5916323192.168.2.2323.150.236.123
      May 27, 2022 20:59:31.904824018 CEST5916323192.168.2.2328.116.95.220
      May 27, 2022 20:59:31.904834986 CEST5916323192.168.2.2353.3.91.208
      May 27, 2022 20:59:31.904838085 CEST5916323192.168.2.23196.192.149.130
      May 27, 2022 20:59:31.904839039 CEST5916323192.168.2.23141.71.20.212
      May 27, 2022 20:59:31.904839993 CEST5916323192.168.2.23132.41.22.128
      May 27, 2022 20:59:31.904839993 CEST5916323192.168.2.2311.178.47.154
      May 27, 2022 20:59:31.904848099 CEST5916323192.168.2.23140.168.223.167
      May 27, 2022 20:59:31.904853106 CEST5916323192.168.2.23252.22.171.143
      May 27, 2022 20:59:31.904854059 CEST5916323192.168.2.2374.33.244.230
      May 27, 2022 20:59:31.904884100 CEST5916323192.168.2.23200.107.112.46
      May 27, 2022 20:59:31.904884100 CEST5916323192.168.2.23117.248.64.225
      May 27, 2022 20:59:31.904885054 CEST5916323192.168.2.23218.9.248.9
      May 27, 2022 20:59:31.904885054 CEST5916323192.168.2.23254.54.180.98
      May 27, 2022 20:59:31.904887915 CEST5916323192.168.2.23103.5.164.28
      May 27, 2022 20:59:31.904889107 CEST5916323192.168.2.23202.185.34.249
      May 27, 2022 20:59:31.904898882 CEST5916323192.168.2.2374.43.146.15
      May 27, 2022 20:59:31.904902935 CEST5916323192.168.2.2351.30.207.35
      May 27, 2022 20:59:31.904905081 CEST5916323192.168.2.23130.186.208.227
      May 27, 2022 20:59:31.904906988 CEST5916323192.168.2.23163.194.144.223
      May 27, 2022 20:59:31.904906034 CEST5916323192.168.2.2365.151.197.186
      May 27, 2022 20:59:31.904912949 CEST5916323192.168.2.2342.10.28.214
      May 27, 2022 20:59:31.904913902 CEST5916323192.168.2.2315.193.58.107
      May 27, 2022 20:59:31.904916048 CEST5916323192.168.2.2336.188.49.158
      May 27, 2022 20:59:31.904925108 CEST5916323192.168.2.2317.167.67.237
      May 27, 2022 20:59:31.904926062 CEST5916323192.168.2.23125.195.135.148
      May 27, 2022 20:59:31.904928923 CEST5916323192.168.2.23177.52.26.48
      May 27, 2022 20:59:31.904932976 CEST5916323192.168.2.23192.249.143.184
      May 27, 2022 20:59:31.904934883 CEST5916323192.168.2.23172.85.122.86
      May 27, 2022 20:59:31.904937029 CEST5916323192.168.2.2371.1.79.62
      May 27, 2022 20:59:31.904939890 CEST5916323192.168.2.2319.184.3.37
      May 27, 2022 20:59:31.904942989 CEST5916323192.168.2.2358.255.35.252
      May 27, 2022 20:59:31.904943943 CEST5916323192.168.2.2361.183.79.215
      May 27, 2022 20:59:31.904958963 CEST5916323192.168.2.2387.150.83.200
      May 27, 2022 20:59:31.904969931 CEST5916323192.168.2.23194.84.237.61
      May 27, 2022 20:59:31.904969931 CEST5916323192.168.2.2356.47.127.149
      May 27, 2022 20:59:31.904983044 CEST5916323192.168.2.23182.156.255.199
      May 27, 2022 20:59:31.904985905 CEST5916323192.168.2.2316.183.21.54
      May 27, 2022 20:59:31.904989004 CEST5916323192.168.2.23187.230.138.114
      May 27, 2022 20:59:31.904995918 CEST5916323192.168.2.23160.185.116.207
      May 27, 2022 20:59:31.905004978 CEST5916323192.168.2.2331.91.126.33
      May 27, 2022 20:59:31.905010939 CEST5916323192.168.2.23189.135.10.226
      May 27, 2022 20:59:31.905013084 CEST5916323192.168.2.23174.56.120.205
      May 27, 2022 20:59:31.905025959 CEST5916323192.168.2.2340.106.209.63
      May 27, 2022 20:59:31.905038118 CEST5916323192.168.2.2351.138.158.248
      May 27, 2022 20:59:31.905047894 CEST5916323192.168.2.2374.204.236.68
      May 27, 2022 20:59:31.905052900 CEST5916323192.168.2.2386.108.114.106
      May 27, 2022 20:59:31.905055046 CEST5916323192.168.2.23101.92.75.123
      May 27, 2022 20:59:31.905076981 CEST5916323192.168.2.23128.74.83.40
      May 27, 2022 20:59:31.905086994 CEST5916323192.168.2.23120.132.2.85
      May 27, 2022 20:59:31.905090094 CEST5916323192.168.2.23104.114.13.58
      May 27, 2022 20:59:31.905164957 CEST5916323192.168.2.2344.178.251.226
      May 27, 2022 20:59:31.905179024 CEST5916323192.168.2.23137.52.223.250
      May 27, 2022 20:59:31.905214071 CEST5916323192.168.2.23131.114.237.214
      May 27, 2022 20:59:31.905575037 CEST5916323192.168.2.23219.162.93.148
      May 27, 2022 20:59:31.905594110 CEST5916323192.168.2.2326.49.180.6
      May 27, 2022 20:59:31.905601978 CEST5916323192.168.2.23210.107.167.197

      System Behavior

      Start time:20:59:30
      Start date:27/05/2022
      Path:/tmp/SBNGwWC7Wb
      Arguments:/tmp/SBNGwWC7Wb
      File size:5777432 bytes
      MD5 hash:0083f1f0e77be34ad27f849842bbb00c
      Start time:20:59:30
      Start date:27/05/2022
      Path:/tmp/SBNGwWC7Wb
      Arguments:n/a
      File size:5777432 bytes
      MD5 hash:0083f1f0e77be34ad27f849842bbb00c
      Start time:20:59:30
      Start date:27/05/2022
      Path:/tmp/SBNGwWC7Wb
      Arguments:n/a
      File size:5777432 bytes
      MD5 hash:0083f1f0e77be34ad27f849842bbb00c
      Start time:20:59:30
      Start date:27/05/2022
      Path:/tmp/SBNGwWC7Wb
      Arguments:n/a
      File size:5777432 bytes
      MD5 hash:0083f1f0e77be34ad27f849842bbb00c
      Start time:20:59:30
      Start date:27/05/2022
      Path:/tmp/SBNGwWC7Wb
      Arguments:n/a
      File size:5777432 bytes
      MD5 hash:0083f1f0e77be34ad27f849842bbb00c
      Start time:20:59:30
      Start date:27/05/2022
      Path:/tmp/SBNGwWC7Wb
      Arguments:n/a
      File size:5777432 bytes
      MD5 hash:0083f1f0e77be34ad27f849842bbb00c