Linux Analysis Report
5zKnElN0F2

Overview

General Information

Sample Name: 5zKnElN0F2
Analysis ID: 635411
MD5: d74bf4db8e2e43cbdc9c527ec15356b0
SHA1: 5de6b4e1a4b1f896ec6b3b6b473c8afb4d6f40a1
SHA256: c0b3f4b9a9a57965c0429b5199e634012e223a4617a13a89dc5e2508085e5575
Tags: 32elfmiraipowerpc
Infos:

Detection

Mirai
Score: 68
Range: 0 - 100
Whitelisted: false

Signatures

Yara detected Mirai
Multi AV Scanner detection for submitted file
Sample is packed with UPX
Uses known network protocols on non-standard ports
Sample tries to kill multiple processes (SIGKILL)
Sample contains only a LOAD segment without any section mappings
Yara signature match
Uses the "uname" system call to query kernel version information (possible evasion)
Enumerates processes within the "proc" file system
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Detected TCP or UDP traffic on non-standard ports
Sample listens on a socket
Sample tries to kill a process (SIGKILL)

Classification

AV Detection

barindex
Source: 5zKnElN0F2 ReversingLabs: Detection: 30%

Networking

barindex
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 50378
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 50380
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 50382
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 50384
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 50388
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 50392
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 50396
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 50400
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 50402
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 50414
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 50420
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 50422
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 50426
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 50430
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 50434
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 50436
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 50444
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 50448
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 50456
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 50462
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 50466
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 50468
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 50474
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 50478
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 50482
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 50488
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 50492
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 50494
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 54182
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 54188
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 54194
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 54200
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 54206
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 54212
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 54218
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 54222
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 54228
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 54232
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 54238
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 54244
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 54250
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 54258
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 54262
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 54274
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 54276
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 54288
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 54306
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 54332
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 54352
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 54366
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 54384
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 54408
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 54436
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 54460
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 54474
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 54486
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 57128
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 57136
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 57140
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 57142
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 57146
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 57156
Source: global traffic TCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
Source: global traffic TCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
Source: global traffic TCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
Source: global traffic TCP traffic: 192.168.2.23:39008 -> 45.95.169.139:9372
Source: /tmp/5zKnElN0F2 (PID: 6233) Socket: 0.0.0.0::23 Jump to behavior
Source: unknown Network traffic detected: HTTP traffic on port 43928 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 42836 -> 443
Source: unknown TCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknown TCP traffic detected without corresponding DNS query: 249.169.15.40
Source: unknown TCP traffic detected without corresponding DNS query: 104.199.228.40
Source: unknown TCP traffic detected without corresponding DNS query: 20.56.144.190
Source: unknown TCP traffic detected without corresponding DNS query: 103.176.96.40
Source: unknown TCP traffic detected without corresponding DNS query: 29.151.218.80
Source: unknown TCP traffic detected without corresponding DNS query: 192.5.233.79
Source: unknown TCP traffic detected without corresponding DNS query: 203.254.91.17
Source: unknown TCP traffic detected without corresponding DNS query: 197.68.217.22
Source: unknown TCP traffic detected without corresponding DNS query: 172.136.171.162
Source: unknown TCP traffic detected without corresponding DNS query: 84.169.157.116
Source: unknown TCP traffic detected without corresponding DNS query: 70.83.239.117
Source: unknown TCP traffic detected without corresponding DNS query: 189.56.57.181
Source: unknown TCP traffic detected without corresponding DNS query: 147.145.145.36
Source: unknown TCP traffic detected without corresponding DNS query: 124.80.238.203
Source: unknown TCP traffic detected without corresponding DNS query: 82.36.65.251
Source: unknown TCP traffic detected without corresponding DNS query: 201.154.224.153
Source: unknown TCP traffic detected without corresponding DNS query: 204.218.135.134
Source: unknown TCP traffic detected without corresponding DNS query: 126.67.223.153
Source: unknown TCP traffic detected without corresponding DNS query: 94.128.230.229
Source: unknown TCP traffic detected without corresponding DNS query: 240.228.179.208
Source: unknown TCP traffic detected without corresponding DNS query: 16.182.131.136
Source: unknown TCP traffic detected without corresponding DNS query: 44.65.107.245
Source: unknown TCP traffic detected without corresponding DNS query: 75.106.47.86
Source: unknown TCP traffic detected without corresponding DNS query: 137.127.90.198
Source: unknown TCP traffic detected without corresponding DNS query: 108.135.179.99
Source: unknown TCP traffic detected without corresponding DNS query: 252.151.202.166
Source: unknown TCP traffic detected without corresponding DNS query: 142.27.4.128
Source: unknown TCP traffic detected without corresponding DNS query: 32.150.0.9
Source: unknown TCP traffic detected without corresponding DNS query: 178.182.189.196
Source: unknown TCP traffic detected without corresponding DNS query: 247.142.150.14
Source: unknown TCP traffic detected without corresponding DNS query: 95.80.50.226
Source: unknown TCP traffic detected without corresponding DNS query: 145.119.160.167
Source: unknown TCP traffic detected without corresponding DNS query: 126.53.28.195
Source: unknown TCP traffic detected without corresponding DNS query: 60.37.188.179
Source: unknown TCP traffic detected without corresponding DNS query: 53.12.116.174
Source: unknown TCP traffic detected without corresponding DNS query: 8.47.163.205
Source: unknown TCP traffic detected without corresponding DNS query: 151.232.166.68
Source: unknown TCP traffic detected without corresponding DNS query: 254.203.17.44
Source: unknown TCP traffic detected without corresponding DNS query: 163.138.31.255
Source: unknown TCP traffic detected without corresponding DNS query: 204.211.151.168
Source: unknown TCP traffic detected without corresponding DNS query: 46.84.226.86
Source: unknown TCP traffic detected without corresponding DNS query: 82.73.227.91
Source: unknown TCP traffic detected without corresponding DNS query: 109.62.224.105
Source: unknown TCP traffic detected without corresponding DNS query: 217.116.246.176
Source: unknown TCP traffic detected without corresponding DNS query: 212.139.142.36
Source: unknown TCP traffic detected without corresponding DNS query: 245.8.37.2
Source: unknown TCP traffic detected without corresponding DNS query: 249.52.26.203
Source: unknown TCP traffic detected without corresponding DNS query: 187.217.81.167
Source: unknown TCP traffic detected without corresponding DNS query: 76.117.182.151
Source: 5zKnElN0F2 String found in binary or memory: http://upx.sf.net

System Summary

barindex
Source: /tmp/5zKnElN0F2 (PID: 6233) SIGKILL sent: pid: 658, result: successful Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) SIGKILL sent: pid: 720, result: successful Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) SIGKILL sent: pid: 759, result: successful Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) SIGKILL sent: pid: 772, result: successful Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) SIGKILL sent: pid: 789, result: successful Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) SIGKILL sent: pid: 800, result: successful Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) SIGKILL sent: pid: 904, result: successful Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) SIGKILL sent: pid: 936, result: successful Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) SIGKILL sent: pid: 1320, result: successful Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) SIGKILL sent: pid: 1334, result: successful Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) SIGKILL sent: pid: 1335, result: successful Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) SIGKILL sent: pid: 1389, result: successful Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) SIGKILL sent: pid: 1463, result: successful Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) SIGKILL sent: pid: 1465, result: successful Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) SIGKILL sent: pid: 1576, result: successful Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) SIGKILL sent: pid: 1809, result: successful Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) SIGKILL sent: pid: 1872, result: successful Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) SIGKILL sent: pid: 1888, result: successful Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) SIGKILL sent: pid: 1890, result: successful Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) SIGKILL sent: pid: 1983, result: successful Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) SIGKILL sent: pid: 2048, result: successful Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) SIGKILL sent: pid: 2062, result: successful Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) SIGKILL sent: pid: 6045, result: successful Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) SIGKILL sent: pid: 6189, result: successful Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) SIGKILL sent: pid: 6227, result: successful Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) SIGKILL sent: pid: 6238, result: successful Jump to behavior
Source: LOAD without section mappings Program segment: 0x100000
Source: 5zKnElN0F2, type: SAMPLE Matched rule: SUSP_ELF_LNX_UPX_Compressed_File date = 2018-12-12, author = Florian Roth, description = Detects a suspicious ELF binary with UPX compression, reference = Internal Research, score = 038ff8b2fef16f8ee9d70e6c219c5f380afe1a21761791e8cbda21fa4d09fdb4
Source: /tmp/5zKnElN0F2 (PID: 6233) SIGKILL sent: pid: 658, result: successful Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) SIGKILL sent: pid: 720, result: successful Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) SIGKILL sent: pid: 759, result: successful Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) SIGKILL sent: pid: 772, result: successful Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) SIGKILL sent: pid: 789, result: successful Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) SIGKILL sent: pid: 800, result: successful Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) SIGKILL sent: pid: 904, result: successful Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) SIGKILL sent: pid: 936, result: successful Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) SIGKILL sent: pid: 1320, result: successful Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) SIGKILL sent: pid: 1334, result: successful Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) SIGKILL sent: pid: 1335, result: successful Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) SIGKILL sent: pid: 1389, result: successful Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) SIGKILL sent: pid: 1463, result: successful Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) SIGKILL sent: pid: 1465, result: successful Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) SIGKILL sent: pid: 1576, result: successful Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) SIGKILL sent: pid: 1809, result: successful Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) SIGKILL sent: pid: 1872, result: successful Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) SIGKILL sent: pid: 1888, result: successful Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) SIGKILL sent: pid: 1890, result: successful Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) SIGKILL sent: pid: 1983, result: successful Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) SIGKILL sent: pid: 2048, result: successful Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) SIGKILL sent: pid: 2062, result: successful Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) SIGKILL sent: pid: 6045, result: successful Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) SIGKILL sent: pid: 6189, result: successful Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) SIGKILL sent: pid: 6227, result: successful Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) SIGKILL sent: pid: 6238, result: successful Jump to behavior
Source: classification engine Classification label: mal68.spre.troj.evad.lin@0/0@0/0

Data Obfuscation

barindex
Source: initial sample String containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $
Source: initial sample String containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $
Source: initial sample String containing UPX found: $Id: UPX 3.94 Copyright (C) 1996-2017 the UPX Team. All Rights Reserved. $
Source: /tmp/5zKnElN0F2 (PID: 6233) File opened: /proc/6235/exe Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) File opened: /proc/1582/exe Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) File opened: /proc/2033/exe Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) File opened: /proc/2275/exe Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) File opened: /proc/3088/exe Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) File opened: /proc/6194/exe Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) File opened: /proc/1612/exe Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) File opened: /proc/1579/exe Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) File opened: /proc/1699/exe Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) File opened: /proc/1335/exe Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) File opened: /proc/1698/exe Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) File opened: /proc/2028/exe Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) File opened: /proc/1334/exe Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) File opened: /proc/1576/exe Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) File opened: /proc/2302/exe Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) File opened: /proc/3236/exe Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) File opened: /proc/2025/exe Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) File opened: /proc/2146/exe Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) File opened: /proc/910/exe Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) File opened: /proc/6227/exe Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) File opened: /proc/912/exe Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) File opened: /proc/517/exe Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) File opened: /proc/759/exe Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) File opened: /proc/2307/exe Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) File opened: /proc/918/exe Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) File opened: /proc/1594/exe Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) File opened: /proc/2285/exe Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) File opened: /proc/2281/exe Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) File opened: /proc/1349/exe Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) File opened: /proc/1623/exe Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) File opened: /proc/761/exe Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) File opened: /proc/1622/exe Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) File opened: /proc/884/exe Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) File opened: /proc/1983/exe Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) File opened: /proc/2038/exe Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) File opened: /proc/1344/exe Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) File opened: /proc/1465/exe Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) File opened: /proc/1586/exe Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) File opened: /proc/1463/exe Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) File opened: /proc/2156/exe Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) File opened: /proc/800/exe Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) File opened: /proc/6238/exe Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) File opened: /proc/801/exe Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) File opened: /proc/1629/exe Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) File opened: /proc/1627/exe Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) File opened: /proc/1900/exe Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) File opened: /proc/3021/exe Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) File opened: /proc/491/exe Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) File opened: /proc/2294/exe Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) File opened: /proc/2050/exe Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) File opened: /proc/1877/exe Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) File opened: /proc/772/exe Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) File opened: /proc/1633/exe Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) File opened: /proc/1599/exe Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) File opened: /proc/1632/exe Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) File opened: /proc/774/exe Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) File opened: /proc/1477/exe Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) File opened: /proc/654/exe Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) File opened: /proc/896/exe Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) File opened: /proc/1476/exe Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) File opened: /proc/1872/exe Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) File opened: /proc/2048/exe Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) File opened: /proc/655/exe Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) File opened: /proc/1475/exe Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) File opened: /proc/2289/exe Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) File opened: /proc/656/exe Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) File opened: /proc/777/exe Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) File opened: /proc/657/exe Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) File opened: /proc/4466/exe Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) File opened: /proc/658/exe Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) File opened: /proc/4467/exe Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) File opened: /proc/4468/exe Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) File opened: /proc/4469/exe Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) File opened: /proc/4502/exe Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) File opened: /proc/419/exe Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) File opened: /proc/936/exe Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) File opened: /proc/1639/exe Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) File opened: /proc/1638/exe Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) File opened: /proc/2208/exe Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) File opened: /proc/2180/exe Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) File opened: /proc/1809/exe Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) File opened: /proc/1494/exe Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) File opened: /proc/1890/exe Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) File opened: /proc/2063/exe Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) File opened: /proc/2062/exe Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) File opened: /proc/1888/exe Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) File opened: /proc/1886/exe Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) File opened: /proc/420/exe Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) File opened: /proc/1489/exe Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) File opened: /proc/785/exe Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) File opened: /proc/1642/exe Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) File opened: /proc/788/exe Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) File opened: /proc/667/exe Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) File opened: /proc/789/exe Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) File opened: /proc/1648/exe Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) File opened: /proc/4495/exe Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) File opened: /proc/6156/exe Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) File opened: /proc/4498/exe Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) File opened: /proc/2078/exe Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) File opened: /proc/2077/exe Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) File opened: /proc/2074/exe Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) File opened: /proc/2195/exe Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) File opened: /proc/670/exe Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) File opened: /proc/4490/exe Jump to behavior
Source: /tmp/5zKnElN0F2 (PID: 6233) File opened: /proc/2746/exe Jump to behavior

Hooking and other Techniques for Hiding and Protection

barindex
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 50378
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 50380
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 50382
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 50384
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 50388
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 50392
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 50396
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 50400
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 50402
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 50414
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 50420
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 50422
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 50426
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 50430
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 50434
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 50436
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 50444
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 50448
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 50456
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 50462
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 50466
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 50468
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 50474
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 50478
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 50482
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 50488
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 50492
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 50494
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 54182
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 54188
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 54194
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 54200
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 54206
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 54212
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 54218
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 54222
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 54228
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 54232
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 54238
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 54244
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 54250
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 54258
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 54262
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 54274
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 54276
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 54288
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 54306
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 54332
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 54352
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 54366
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 54384
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 54408
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 54436
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 54460
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 54474
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 54486
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 57128
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 57136
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 57140
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 57142
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 57146
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 57156
Source: /tmp/5zKnElN0F2 (PID: 6225) Queries kernel information via 'uname': Jump to behavior
Source: 5zKnElN0F2, 6225.1.00000000e3b31b61.00000000feb11032.rw-.sdmp, 5zKnElN0F2, 6227.1.00000000e3b31b61.00000000feb11032.rw-.sdmp Binary or memory string: !/etc/qemu-binfmt/ppc11!hotpluggableq
Source: 5zKnElN0F2, 6225.1.00000000258270c1.0000000060d5cb64.rw-.sdmp, 5zKnElN0F2, 6227.1.00000000258270c1.0000000060d5cb64.rw-.sdmp, 5zKnElN0F2, 6229.1.00000000258270c1.0000000060d5cb64.rw-.sdmp, 5zKnElN0F2, 6236.1.00000000258270c1.0000000060d5cb64.rw-.sdmp, 5zKnElN0F2, 6238.1.00000000258270c1.0000000060d5cb64.rw-.sdmp Binary or memory string: x86_64/usr/bin/qemu-ppc/tmp/5zKnElN0F2SUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/5zKnElN0F2
Source: 5zKnElN0F2, 6229.1.00000000e3b31b61.00000000feb11032.rw-.sdmp, 5zKnElN0F2, 6236.1.00000000e3b31b61.00000000feb11032.rw-.sdmp, 5zKnElN0F2, 6238.1.00000000e3b31b61.00000000feb11032.rw-.sdmp Binary or memory string: !/etc/qemu-binfmt/ppc1
Source: 5zKnElN0F2, 6225.1.00000000e3b31b61.00000000feb11032.rw-.sdmp, 5zKnElN0F2, 6227.1.00000000e3b31b61.00000000feb11032.rw-.sdmp, 5zKnElN0F2, 6229.1.00000000e3b31b61.00000000feb11032.rw-.sdmp, 5zKnElN0F2, 6236.1.00000000e3b31b61.00000000feb11032.rw-.sdmp, 5zKnElN0F2, 6238.1.00000000e3b31b61.00000000feb11032.rw-.sdmp Binary or memory string: /etc/qemu-binfmt/ppc
Source: 5zKnElN0F2, 6225.1.00000000258270c1.0000000060d5cb64.rw-.sdmp, 5zKnElN0F2, 6227.1.00000000258270c1.0000000060d5cb64.rw-.sdmp, 5zKnElN0F2, 6229.1.00000000258270c1.0000000060d5cb64.rw-.sdmp, 5zKnElN0F2, 6236.1.00000000258270c1.0000000060d5cb64.rw-.sdmp, 5zKnElN0F2, 6238.1.00000000258270c1.0000000060d5cb64.rw-.sdmp Binary or memory string: /usr/bin/qemu-ppc

Stealing of Sensitive Information

barindex
Source: Yara match File source: dump.pcap, type: PCAP

Remote Access Functionality

barindex
Source: Yara match File source: dump.pcap, type: PCAP
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs