Linux Analysis Report
gmjJxVFJKQ

Overview

General Information

Sample Name: gmjJxVFJKQ
Analysis ID: 635404
MD5: a8fbc7563fe019ca689573d43d7797f3
SHA1: d9842c2d31a7357d8c92414edbff9e60fce317b2
SHA256: e92cdc162e5091c4916d12d2f4a5f7e7e9ffdb4dae8a18427d81f97ed08edcef
Tags: 32elfmipsmirai
Infos:

Detection

Mirai
Score: 68
Range: 0 - 100
Whitelisted: false

Signatures

Yara detected Mirai
Multi AV Scanner detection for submitted file
Sample is packed with UPX
Uses known network protocols on non-standard ports
Sample tries to kill multiple processes (SIGKILL)
Sample contains only a LOAD segment without any section mappings
Yara signature match
Uses the "uname" system call to query kernel version information (possible evasion)
Enumerates processes within the "proc" file system
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Detected TCP or UDP traffic on non-standard ports
Sample listens on a socket
Sample tries to kill a process (SIGKILL)

Classification

AV Detection

barindex
Source: gmjJxVFJKQ Virustotal: Detection: 23% Perma Link
Source: gmjJxVFJKQ ReversingLabs: Detection: 25%

Networking

barindex
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 34194
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 34196
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 34200
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 34216
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 34240
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 34262
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 34270
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 34272
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 34274
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 34276
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 34278
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 34284
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 34290
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 34296
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 34314
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 34336
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 34362
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 34380
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 34384
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 34390
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 34400
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 34406
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 34416
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 34422
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 34428
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 34432
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 34440
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 34444
Source: global traffic TCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
Source: global traffic TCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
Source: global traffic TCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
Source: global traffic TCP traffic: 192.168.2.23:39008 -> 45.95.169.139:9372
Source: /tmp/gmjJxVFJKQ (PID: 6231) Socket: 0.0.0.0::23 Jump to behavior
Source: unknown Network traffic detected: HTTP traffic on port 43928 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 42836 -> 443
Source: unknown TCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknown TCP traffic detected without corresponding DNS query: 218.86.102.45
Source: unknown TCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknown TCP traffic detected without corresponding DNS query: 89.164.70.101
Source: unknown TCP traffic detected without corresponding DNS query: 217.177.184.187
Source: unknown TCP traffic detected without corresponding DNS query: 137.203.173.101
Source: unknown TCP traffic detected without corresponding DNS query: 155.99.22.98
Source: unknown TCP traffic detected without corresponding DNS query: 46.217.120.146
Source: unknown TCP traffic detected without corresponding DNS query: 186.170.70.118
Source: unknown TCP traffic detected without corresponding DNS query: 254.28.163.74
Source: unknown TCP traffic detected without corresponding DNS query: 245.178.131.122
Source: unknown TCP traffic detected without corresponding DNS query: 71.50.252.6
Source: unknown TCP traffic detected without corresponding DNS query: 247.241.101.225
Source: unknown TCP traffic detected without corresponding DNS query: 169.103.254.33
Source: unknown TCP traffic detected without corresponding DNS query: 217.149.131.222
Source: unknown TCP traffic detected without corresponding DNS query: 50.29.87.192
Source: unknown TCP traffic detected without corresponding DNS query: 154.78.128.153
Source: unknown TCP traffic detected without corresponding DNS query: 196.71.251.245
Source: unknown TCP traffic detected without corresponding DNS query: 182.198.255.62
Source: unknown TCP traffic detected without corresponding DNS query: 194.1.19.128
Source: unknown TCP traffic detected without corresponding DNS query: 184.80.135.250
Source: unknown TCP traffic detected without corresponding DNS query: 40.108.39.88
Source: unknown TCP traffic detected without corresponding DNS query: 58.131.100.205
Source: unknown TCP traffic detected without corresponding DNS query: 55.22.119.253
Source: unknown TCP traffic detected without corresponding DNS query: 123.60.253.41
Source: unknown TCP traffic detected without corresponding DNS query: 24.223.94.97
Source: unknown TCP traffic detected without corresponding DNS query: 124.255.49.41
Source: unknown TCP traffic detected without corresponding DNS query: 51.121.140.119
Source: unknown TCP traffic detected without corresponding DNS query: 174.66.91.90
Source: unknown TCP traffic detected without corresponding DNS query: 81.127.88.64
Source: unknown TCP traffic detected without corresponding DNS query: 146.138.186.154
Source: unknown TCP traffic detected without corresponding DNS query: 153.133.26.3
Source: unknown TCP traffic detected without corresponding DNS query: 5.246.6.138
Source: unknown TCP traffic detected without corresponding DNS query: 40.7.92.121
Source: unknown TCP traffic detected without corresponding DNS query: 168.213.213.48
Source: unknown TCP traffic detected without corresponding DNS query: 107.58.152.236
Source: unknown TCP traffic detected without corresponding DNS query: 106.140.190.10
Source: unknown TCP traffic detected without corresponding DNS query: 45.40.92.114
Source: unknown TCP traffic detected without corresponding DNS query: 38.118.238.219
Source: unknown TCP traffic detected without corresponding DNS query: 102.68.131.199
Source: unknown TCP traffic detected without corresponding DNS query: 153.58.190.192
Source: unknown TCP traffic detected without corresponding DNS query: 82.23.27.208
Source: unknown TCP traffic detected without corresponding DNS query: 42.80.232.227
Source: unknown TCP traffic detected without corresponding DNS query: 58.218.67.178
Source: unknown TCP traffic detected without corresponding DNS query: 178.186.128.30
Source: unknown TCP traffic detected without corresponding DNS query: 202.67.70.191
Source: unknown TCP traffic detected without corresponding DNS query: 107.229.100.210
Source: unknown TCP traffic detected without corresponding DNS query: 51.169.126.77
Source: unknown TCP traffic detected without corresponding DNS query: 18.233.116.93
Source: unknown TCP traffic detected without corresponding DNS query: 17.130.24.122
Source: gmjJxVFJKQ String found in binary or memory: http://upx.sf.net

System Summary

barindex
Source: /tmp/gmjJxVFJKQ (PID: 6231) SIGKILL sent: pid: 658, result: successful Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) SIGKILL sent: pid: 720, result: successful Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) SIGKILL sent: pid: 759, result: successful Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) SIGKILL sent: pid: 772, result: successful Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) SIGKILL sent: pid: 789, result: successful Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) SIGKILL sent: pid: 800, result: successful Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) SIGKILL sent: pid: 904, result: successful Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) SIGKILL sent: pid: 936, result: successful Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) SIGKILL sent: pid: 1320, result: successful Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) SIGKILL sent: pid: 1334, result: successful Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) SIGKILL sent: pid: 1335, result: successful Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) SIGKILL sent: pid: 1389, result: successful Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) SIGKILL sent: pid: 1463, result: successful Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) SIGKILL sent: pid: 1465, result: successful Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) SIGKILL sent: pid: 1576, result: successful Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) SIGKILL sent: pid: 1809, result: successful Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) SIGKILL sent: pid: 1872, result: successful Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) SIGKILL sent: pid: 1888, result: successful Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) SIGKILL sent: pid: 1890, result: successful Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) SIGKILL sent: pid: 1983, result: successful Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) SIGKILL sent: pid: 2048, result: successful Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) SIGKILL sent: pid: 2062, result: successful Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) SIGKILL sent: pid: 6045, result: successful Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) SIGKILL sent: pid: 6192, result: successful Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) SIGKILL sent: pid: 6225, result: successful Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) SIGKILL sent: pid: 6235, result: successful Jump to behavior
Source: LOAD without section mappings Program segment: 0x100000
Source: gmjJxVFJKQ, type: SAMPLE Matched rule: SUSP_ELF_LNX_UPX_Compressed_File date = 2018-12-12, author = Florian Roth, description = Detects a suspicious ELF binary with UPX compression, reference = Internal Research, score = 038ff8b2fef16f8ee9d70e6c219c5f380afe1a21761791e8cbda21fa4d09fdb4
Source: /tmp/gmjJxVFJKQ (PID: 6231) SIGKILL sent: pid: 658, result: successful Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) SIGKILL sent: pid: 720, result: successful Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) SIGKILL sent: pid: 759, result: successful Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) SIGKILL sent: pid: 772, result: successful Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) SIGKILL sent: pid: 789, result: successful Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) SIGKILL sent: pid: 800, result: successful Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) SIGKILL sent: pid: 904, result: successful Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) SIGKILL sent: pid: 936, result: successful Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) SIGKILL sent: pid: 1320, result: successful Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) SIGKILL sent: pid: 1334, result: successful Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) SIGKILL sent: pid: 1335, result: successful Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) SIGKILL sent: pid: 1389, result: successful Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) SIGKILL sent: pid: 1463, result: successful Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) SIGKILL sent: pid: 1465, result: successful Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) SIGKILL sent: pid: 1576, result: successful Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) SIGKILL sent: pid: 1809, result: successful Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) SIGKILL sent: pid: 1872, result: successful Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) SIGKILL sent: pid: 1888, result: successful Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) SIGKILL sent: pid: 1890, result: successful Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) SIGKILL sent: pid: 1983, result: successful Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) SIGKILL sent: pid: 2048, result: successful Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) SIGKILL sent: pid: 2062, result: successful Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) SIGKILL sent: pid: 6045, result: successful Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) SIGKILL sent: pid: 6192, result: successful Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) SIGKILL sent: pid: 6225, result: successful Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) SIGKILL sent: pid: 6235, result: successful Jump to behavior
Source: classification engine Classification label: mal68.spre.troj.evad.lin@0/0@0/0

Data Obfuscation

barindex
Source: initial sample String containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $
Source: initial sample String containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $
Source: initial sample String containing UPX found: $Id: UPX 3.94 Copyright (C) 1996-2017 the UPX Team. All Rights Reserved. $
Source: /tmp/gmjJxVFJKQ (PID: 6231) File opened: /proc/6235/exe Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) File opened: /proc/1582/exe Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) File opened: /proc/2033/exe Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) File opened: /proc/2275/exe Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) File opened: /proc/3088/exe Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) File opened: /proc/6193/exe Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) File opened: /proc/6192/exe Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) File opened: /proc/1612/exe Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) File opened: /proc/1579/exe Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) File opened: /proc/1699/exe Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) File opened: /proc/1335/exe Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) File opened: /proc/1698/exe Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) File opened: /proc/2028/exe Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) File opened: /proc/1334/exe Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) File opened: /proc/1576/exe Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) File opened: /proc/2302/exe Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) File opened: /proc/3236/exe Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) File opened: /proc/2025/exe Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) File opened: /proc/2146/exe Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) File opened: /proc/910/exe Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) File opened: /proc/912/exe Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) File opened: /proc/517/exe Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) File opened: /proc/759/exe Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) File opened: /proc/2307/exe Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) File opened: /proc/918/exe Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) File opened: /proc/1594/exe Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) File opened: /proc/2285/exe Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) File opened: /proc/2281/exe Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) File opened: /proc/1349/exe Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) File opened: /proc/1623/exe Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) File opened: /proc/761/exe Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) File opened: /proc/1622/exe Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) File opened: /proc/884/exe Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) File opened: /proc/1983/exe Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) File opened: /proc/2038/exe Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) File opened: /proc/1344/exe Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) File opened: /proc/1465/exe Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) File opened: /proc/1586/exe Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) File opened: /proc/1463/exe Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) File opened: /proc/2156/exe Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) File opened: /proc/800/exe Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) File opened: /proc/801/exe Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) File opened: /proc/1629/exe Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) File opened: /proc/1627/exe Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) File opened: /proc/1900/exe Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) File opened: /proc/3021/exe Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) File opened: /proc/491/exe Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) File opened: /proc/2294/exe Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) File opened: /proc/2050/exe Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) File opened: /proc/1877/exe Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) File opened: /proc/772/exe Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) File opened: /proc/1633/exe Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) File opened: /proc/1599/exe Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) File opened: /proc/1632/exe Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) File opened: /proc/774/exe Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) File opened: /proc/1477/exe Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) File opened: /proc/654/exe Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) File opened: /proc/896/exe Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) File opened: /proc/1476/exe Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) File opened: /proc/1872/exe Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) File opened: /proc/2048/exe Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) File opened: /proc/655/exe Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) File opened: /proc/1475/exe Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) File opened: /proc/2289/exe Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) File opened: /proc/656/exe Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) File opened: /proc/777/exe Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) File opened: /proc/657/exe Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) File opened: /proc/4466/exe Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) File opened: /proc/658/exe Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) File opened: /proc/4467/exe Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) File opened: /proc/4500/exe Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) File opened: /proc/4468/exe Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) File opened: /proc/4469/exe Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) File opened: /proc/4502/exe Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) File opened: /proc/419/exe Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) File opened: /proc/936/exe Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) File opened: /proc/1639/exe Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) File opened: /proc/1638/exe Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) File opened: /proc/2208/exe Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) File opened: /proc/2180/exe Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) File opened: /proc/1809/exe Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) File opened: /proc/1494/exe Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) File opened: /proc/1890/exe Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) File opened: /proc/2063/exe Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) File opened: /proc/2062/exe Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) File opened: /proc/1888/exe Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) File opened: /proc/1886/exe Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) File opened: /proc/420/exe Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) File opened: /proc/1489/exe Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) File opened: /proc/785/exe Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) File opened: /proc/1642/exe Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) File opened: /proc/788/exe Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) File opened: /proc/667/exe Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) File opened: /proc/789/exe Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) File opened: /proc/1648/exe Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) File opened: /proc/4492/exe Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) File opened: /proc/6157/exe Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) File opened: /proc/2078/exe Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) File opened: /proc/2077/exe Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) File opened: /proc/2074/exe Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) File opened: /proc/2195/exe Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) File opened: /proc/670/exe Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) File opened: /proc/4490/exe Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) File opened: /proc/2746/exe Jump to behavior
Source: /tmp/gmjJxVFJKQ (PID: 6231) File opened: /proc/793/exe Jump to behavior

Hooking and other Techniques for Hiding and Protection

barindex
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 34194
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 34196
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 34200
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 34216
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 34240
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 34262
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 34270
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 34272
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 34274
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 34276
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 34278
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 34284
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 34290
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 34296
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 34314
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 34336
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 34362
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 34380
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 34384
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 34390
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 34400
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 34406
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 34416
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 34422
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 34428
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 34432
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 34440
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 34444
Source: /tmp/gmjJxVFJKQ (PID: 6223) Queries kernel information via 'uname': Jump to behavior
Source: gmjJxVFJKQ, 6223.1.0000000001028965.00000000829b0766.rw-.sdmp, gmjJxVFJKQ, 6225.1.0000000001028965.00000000829b0766.rw-.sdmp, gmjJxVFJKQ, 6226.1.0000000001028965.00000000829b0766.rw-.sdmp, gmjJxVFJKQ, 6233.1.0000000001028965.00000000829b0766.rw-.sdmp, gmjJxVFJKQ, 6235.1.0000000001028965.00000000829b0766.rw-.sdmp Binary or memory string: /etc/qemu-binfmt/mipsel
Source: gmjJxVFJKQ, 6223.1.0000000043b059e0.00000000b73dc09b.rw-.sdmp, gmjJxVFJKQ, 6225.1.0000000043b059e0.00000000b73dc09b.rw-.sdmp, gmjJxVFJKQ, 6226.1.0000000043b059e0.00000000b73dc09b.rw-.sdmp, gmjJxVFJKQ, 6233.1.0000000043b059e0.00000000b73dc09b.rw-.sdmp, gmjJxVFJKQ, 6235.1.0000000043b059e0.00000000b73dc09b.rw-.sdmp Binary or memory string: x86_64/usr/bin/qemu-mipsel/tmp/gmjJxVFJKQSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/gmjJxVFJKQ
Source: gmjJxVFJKQ, 6223.1.0000000001028965.00000000829b0766.rw-.sdmp, gmjJxVFJKQ, 6225.1.0000000001028965.00000000829b0766.rw-.sdmp, gmjJxVFJKQ, 6226.1.0000000001028965.00000000829b0766.rw-.sdmp, gmjJxVFJKQ, 6233.1.0000000001028965.00000000829b0766.rw-.sdmp, gmjJxVFJKQ, 6235.1.0000000001028965.00000000829b0766.rw-.sdmp Binary or memory string: &V!/etc/qemu-binfmt/mipsel
Source: gmjJxVFJKQ, 6223.1.0000000043b059e0.00000000b73dc09b.rw-.sdmp, gmjJxVFJKQ, 6225.1.0000000043b059e0.00000000b73dc09b.rw-.sdmp, gmjJxVFJKQ, 6226.1.0000000043b059e0.00000000b73dc09b.rw-.sdmp, gmjJxVFJKQ, 6233.1.0000000043b059e0.00000000b73dc09b.rw-.sdmp, gmjJxVFJKQ, 6235.1.0000000043b059e0.00000000b73dc09b.rw-.sdmp Binary or memory string: /usr/bin/qemu-mipsel

Stealing of Sensitive Information

barindex
Source: Yara match File source: dump.pcap, type: PCAP

Remote Access Functionality

barindex
Source: Yara match File source: dump.pcap, type: PCAP
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs