Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
5zKnElN0F2

Overview

General Information

Sample Name:5zKnElN0F2
Analysis ID:635411
MD5:d74bf4db8e2e43cbdc9c527ec15356b0
SHA1:5de6b4e1a4b1f896ec6b3b6b473c8afb4d6f40a1
SHA256:c0b3f4b9a9a57965c0429b5199e634012e223a4617a13a89dc5e2508085e5575
Tags:32elfmiraipowerpc
Infos:

Detection

Mirai
Score:68
Range:0 - 100
Whitelisted:false

Signatures

Yara detected Mirai
Multi AV Scanner detection for submitted file
Sample is packed with UPX
Uses known network protocols on non-standard ports
Sample tries to kill multiple processes (SIGKILL)
Sample contains only a LOAD segment without any section mappings
Yara signature match
Uses the "uname" system call to query kernel version information (possible evasion)
Enumerates processes within the "proc" file system
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Detected TCP or UDP traffic on non-standard ports
Sample listens on a socket
Sample tries to kill a process (SIGKILL)

Classification

Analysis Advice

Static ELF header machine description suggests that the sample might not execute correctly on this machine.
All HTTP servers contacted by the sample do not answer. The sample is likely an old dropper which does no longer work.
Joe Sandbox Version:34.0.0 Boulder Opal
Analysis ID:635411
Start date and time: 27/05/202221:16:422022-05-27 21:16:42 +02:00
Joe Sandbox Product:CloudBasic
Overall analysis duration:0h 6m 3s
Hypervisor based Inspection enabled:false
Report type:light
Sample file name:5zKnElN0F2
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Detection:MAL
Classification:mal68.spre.troj.evad.lin@0/0@0/0
  • Report size exceeded maximum capacity and may have missing network information.
  • TCP Packets have been reduced to 100
  • VT rate limit hit for: 5zKnElN0F2
Command:/tmp/5zKnElN0F2
PID:6225
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
Infected
Standard Error:
  • system is lnxubuntu20
  • 5zKnElN0F2 (PID: 6225, Parent: 6126, MD5: ae65271c943d3451b7f026d1fadccea6) Arguments: /tmp/5zKnElN0F2
  • cleanup
SourceRuleDescriptionAuthorStrings
5zKnElN0F2SUSP_ELF_LNX_UPX_Compressed_FileDetects a suspicious ELF binary with UPX compressionFlorian Roth
  • 0x9154:$s1: PROT_EXEC|PROT_WRITE failed.
  • 0x91c3:$s2: $Id: UPX
  • 0x9174:$s3: $Info: This file is packed with the UPX executable packer
SourceRuleDescriptionAuthorStrings
dump.pcapJoeSecurity_Mirai_12Yara detected MiraiJoe Security
    No Snort rule has matched

    Click to jump to signature section

    Show All Signature Results

    AV Detection

    barindex
    Source: 5zKnElN0F2ReversingLabs: Detection: 30%

    Networking

    barindex
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 50378
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 50380
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 50382
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 50384
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 50388
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 50392
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 50396
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 50400
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 50402
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 50414
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 50420
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 50422
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 50426
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 50430
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 50434
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 50436
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 50444
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 50448
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 50456
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 50462
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 50466
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 50468
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 50474
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 50478
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 50482
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 50488
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 50492
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 50494
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 54182
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 54188
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 54194
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 54200
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 54206
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 54212
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 54218
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 54222
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 54228
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 54232
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 54238
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 54244
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 54250
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 54258
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 54262
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 54274
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 54276
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 54288
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 54306
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 54332
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 54352
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 54366
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 54384
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 54408
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 54436
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 54460
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 54474
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 54486
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57128
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57136
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57140
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57142
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57146
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57156
    Source: global trafficTCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
    Source: global trafficTCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
    Source: global trafficTCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
    Source: global trafficTCP traffic: 192.168.2.23:39008 -> 45.95.169.139:9372
    Source: /tmp/5zKnElN0F2 (PID: 6233)Socket: 0.0.0.0::23
    Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443
    Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
    Source: unknownTCP traffic detected without corresponding DNS query: 249.169.15.40
    Source: unknownTCP traffic detected without corresponding DNS query: 104.199.228.40
    Source: unknownTCP traffic detected without corresponding DNS query: 20.56.144.190
    Source: unknownTCP traffic detected without corresponding DNS query: 103.176.96.40
    Source: unknownTCP traffic detected without corresponding DNS query: 29.151.218.80
    Source: unknownTCP traffic detected without corresponding DNS query: 192.5.233.79
    Source: unknownTCP traffic detected without corresponding DNS query: 203.254.91.17
    Source: unknownTCP traffic detected without corresponding DNS query: 197.68.217.22
    Source: unknownTCP traffic detected without corresponding DNS query: 172.136.171.162
    Source: unknownTCP traffic detected without corresponding DNS query: 84.169.157.116
    Source: unknownTCP traffic detected without corresponding DNS query: 70.83.239.117
    Source: unknownTCP traffic detected without corresponding DNS query: 189.56.57.181
    Source: unknownTCP traffic detected without corresponding DNS query: 147.145.145.36
    Source: unknownTCP traffic detected without corresponding DNS query: 124.80.238.203
    Source: unknownTCP traffic detected without corresponding DNS query: 82.36.65.251
    Source: unknownTCP traffic detected without corresponding DNS query: 201.154.224.153
    Source: unknownTCP traffic detected without corresponding DNS query: 204.218.135.134
    Source: unknownTCP traffic detected without corresponding DNS query: 126.67.223.153
    Source: unknownTCP traffic detected without corresponding DNS query: 94.128.230.229
    Source: unknownTCP traffic detected without corresponding DNS query: 240.228.179.208
    Source: unknownTCP traffic detected without corresponding DNS query: 16.182.131.136
    Source: unknownTCP traffic detected without corresponding DNS query: 44.65.107.245
    Source: unknownTCP traffic detected without corresponding DNS query: 75.106.47.86
    Source: unknownTCP traffic detected without corresponding DNS query: 137.127.90.198
    Source: unknownTCP traffic detected without corresponding DNS query: 108.135.179.99
    Source: unknownTCP traffic detected without corresponding DNS query: 252.151.202.166
    Source: unknownTCP traffic detected without corresponding DNS query: 142.27.4.128
    Source: unknownTCP traffic detected without corresponding DNS query: 32.150.0.9
    Source: unknownTCP traffic detected without corresponding DNS query: 178.182.189.196
    Source: unknownTCP traffic detected without corresponding DNS query: 247.142.150.14
    Source: unknownTCP traffic detected without corresponding DNS query: 95.80.50.226
    Source: unknownTCP traffic detected without corresponding DNS query: 145.119.160.167
    Source: unknownTCP traffic detected without corresponding DNS query: 126.53.28.195
    Source: unknownTCP traffic detected without corresponding DNS query: 60.37.188.179
    Source: unknownTCP traffic detected without corresponding DNS query: 53.12.116.174
    Source: unknownTCP traffic detected without corresponding DNS query: 8.47.163.205
    Source: unknownTCP traffic detected without corresponding DNS query: 151.232.166.68
    Source: unknownTCP traffic detected without corresponding DNS query: 254.203.17.44
    Source: unknownTCP traffic detected without corresponding DNS query: 163.138.31.255
    Source: unknownTCP traffic detected without corresponding DNS query: 204.211.151.168
    Source: unknownTCP traffic detected without corresponding DNS query: 46.84.226.86
    Source: unknownTCP traffic detected without corresponding DNS query: 82.73.227.91
    Source: unknownTCP traffic detected without corresponding DNS query: 109.62.224.105
    Source: unknownTCP traffic detected without corresponding DNS query: 217.116.246.176
    Source: unknownTCP traffic detected without corresponding DNS query: 212.139.142.36
    Source: unknownTCP traffic detected without corresponding DNS query: 245.8.37.2
    Source: unknownTCP traffic detected without corresponding DNS query: 249.52.26.203
    Source: unknownTCP traffic detected without corresponding DNS query: 187.217.81.167
    Source: unknownTCP traffic detected without corresponding DNS query: 76.117.182.151
    Source: 5zKnElN0F2String found in binary or memory: http://upx.sf.net

    System Summary

    barindex
    Source: /tmp/5zKnElN0F2 (PID: 6233)SIGKILL sent: pid: 658, result: successful
    Source: /tmp/5zKnElN0F2 (PID: 6233)SIGKILL sent: pid: 720, result: successful
    Source: /tmp/5zKnElN0F2 (PID: 6233)SIGKILL sent: pid: 759, result: successful
    Source: /tmp/5zKnElN0F2 (PID: 6233)SIGKILL sent: pid: 772, result: successful
    Source: /tmp/5zKnElN0F2 (PID: 6233)SIGKILL sent: pid: 789, result: successful
    Source: /tmp/5zKnElN0F2 (PID: 6233)SIGKILL sent: pid: 800, result: successful
    Source: /tmp/5zKnElN0F2 (PID: 6233)SIGKILL sent: pid: 904, result: successful
    Source: /tmp/5zKnElN0F2 (PID: 6233)SIGKILL sent: pid: 936, result: successful
    Source: /tmp/5zKnElN0F2 (PID: 6233)SIGKILL sent: pid: 1320, result: successful
    Source: /tmp/5zKnElN0F2 (PID: 6233)SIGKILL sent: pid: 1334, result: successful
    Source: /tmp/5zKnElN0F2 (PID: 6233)SIGKILL sent: pid: 1335, result: successful
    Source: /tmp/5zKnElN0F2 (PID: 6233)SIGKILL sent: pid: 1389, result: successful
    Source: /tmp/5zKnElN0F2 (PID: 6233)SIGKILL sent: pid: 1463, result: successful
    Source: /tmp/5zKnElN0F2 (PID: 6233)SIGKILL sent: pid: 1465, result: successful
    Source: /tmp/5zKnElN0F2 (PID: 6233)SIGKILL sent: pid: 1576, result: successful
    Source: /tmp/5zKnElN0F2 (PID: 6233)SIGKILL sent: pid: 1809, result: successful
    Source: /tmp/5zKnElN0F2 (PID: 6233)SIGKILL sent: pid: 1872, result: successful
    Source: /tmp/5zKnElN0F2 (PID: 6233)SIGKILL sent: pid: 1888, result: successful
    Source: /tmp/5zKnElN0F2 (PID: 6233)SIGKILL sent: pid: 1890, result: successful
    Source: /tmp/5zKnElN0F2 (PID: 6233)SIGKILL sent: pid: 1983, result: successful
    Source: /tmp/5zKnElN0F2 (PID: 6233)SIGKILL sent: pid: 2048, result: successful
    Source: /tmp/5zKnElN0F2 (PID: 6233)SIGKILL sent: pid: 2062, result: successful
    Source: /tmp/5zKnElN0F2 (PID: 6233)SIGKILL sent: pid: 6045, result: successful
    Source: /tmp/5zKnElN0F2 (PID: 6233)SIGKILL sent: pid: 6189, result: successful
    Source: /tmp/5zKnElN0F2 (PID: 6233)SIGKILL sent: pid: 6227, result: successful
    Source: /tmp/5zKnElN0F2 (PID: 6233)SIGKILL sent: pid: 6238, result: successful
    Source: LOAD without section mappingsProgram segment: 0x100000
    Source: 5zKnElN0F2, type: SAMPLEMatched rule: SUSP_ELF_LNX_UPX_Compressed_File date = 2018-12-12, author = Florian Roth, description = Detects a suspicious ELF binary with UPX compression, reference = Internal Research, score = 038ff8b2fef16f8ee9d70e6c219c5f380afe1a21761791e8cbda21fa4d09fdb4
    Source: /tmp/5zKnElN0F2 (PID: 6233)SIGKILL sent: pid: 658, result: successful
    Source: /tmp/5zKnElN0F2 (PID: 6233)SIGKILL sent: pid: 720, result: successful
    Source: /tmp/5zKnElN0F2 (PID: 6233)SIGKILL sent: pid: 759, result: successful
    Source: /tmp/5zKnElN0F2 (PID: 6233)SIGKILL sent: pid: 772, result: successful
    Source: /tmp/5zKnElN0F2 (PID: 6233)SIGKILL sent: pid: 789, result: successful
    Source: /tmp/5zKnElN0F2 (PID: 6233)SIGKILL sent: pid: 800, result: successful
    Source: /tmp/5zKnElN0F2 (PID: 6233)SIGKILL sent: pid: 904, result: successful
    Source: /tmp/5zKnElN0F2 (PID: 6233)SIGKILL sent: pid: 936, result: successful
    Source: /tmp/5zKnElN0F2 (PID: 6233)SIGKILL sent: pid: 1320, result: successful
    Source: /tmp/5zKnElN0F2 (PID: 6233)SIGKILL sent: pid: 1334, result: successful
    Source: /tmp/5zKnElN0F2 (PID: 6233)SIGKILL sent: pid: 1335, result: successful
    Source: /tmp/5zKnElN0F2 (PID: 6233)SIGKILL sent: pid: 1389, result: successful
    Source: /tmp/5zKnElN0F2 (PID: 6233)SIGKILL sent: pid: 1463, result: successful
    Source: /tmp/5zKnElN0F2 (PID: 6233)SIGKILL sent: pid: 1465, result: successful
    Source: /tmp/5zKnElN0F2 (PID: 6233)SIGKILL sent: pid: 1576, result: successful
    Source: /tmp/5zKnElN0F2 (PID: 6233)SIGKILL sent: pid: 1809, result: successful
    Source: /tmp/5zKnElN0F2 (PID: 6233)SIGKILL sent: pid: 1872, result: successful
    Source: /tmp/5zKnElN0F2 (PID: 6233)SIGKILL sent: pid: 1888, result: successful
    Source: /tmp/5zKnElN0F2 (PID: 6233)SIGKILL sent: pid: 1890, result: successful
    Source: /tmp/5zKnElN0F2 (PID: 6233)SIGKILL sent: pid: 1983, result: successful
    Source: /tmp/5zKnElN0F2 (PID: 6233)SIGKILL sent: pid: 2048, result: successful
    Source: /tmp/5zKnElN0F2 (PID: 6233)SIGKILL sent: pid: 2062, result: successful
    Source: /tmp/5zKnElN0F2 (PID: 6233)SIGKILL sent: pid: 6045, result: successful
    Source: /tmp/5zKnElN0F2 (PID: 6233)SIGKILL sent: pid: 6189, result: successful
    Source: /tmp/5zKnElN0F2 (PID: 6233)SIGKILL sent: pid: 6227, result: successful
    Source: /tmp/5zKnElN0F2 (PID: 6233)SIGKILL sent: pid: 6238, result: successful
    Source: classification engineClassification label: mal68.spre.troj.evad.lin@0/0@0/0

    Data Obfuscation

    barindex
    Source: initial sampleString containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $
    Source: initial sampleString containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $
    Source: initial sampleString containing UPX found: $Id: UPX 3.94 Copyright (C) 1996-2017 the UPX Team. All Rights Reserved. $
    Source: /tmp/5zKnElN0F2 (PID: 6233)File opened: /proc/6235/exe
    Source: /tmp/5zKnElN0F2 (PID: 6233)File opened: /proc/1582/exe
    Source: /tmp/5zKnElN0F2 (PID: 6233)File opened: /proc/2033/exe
    Source: /tmp/5zKnElN0F2 (PID: 6233)File opened: /proc/2275/exe
    Source: /tmp/5zKnElN0F2 (PID: 6233)File opened: /proc/3088/exe
    Source: /tmp/5zKnElN0F2 (PID: 6233)File opened: /proc/6194/exe
    Source: /tmp/5zKnElN0F2 (PID: 6233)File opened: /proc/1612/exe
    Source: /tmp/5zKnElN0F2 (PID: 6233)File opened: /proc/1579/exe
    Source: /tmp/5zKnElN0F2 (PID: 6233)File opened: /proc/1699/exe
    Source: /tmp/5zKnElN0F2 (PID: 6233)File opened: /proc/1335/exe
    Source: /tmp/5zKnElN0F2 (PID: 6233)File opened: /proc/1698/exe
    Source: /tmp/5zKnElN0F2 (PID: 6233)File opened: /proc/2028/exe
    Source: /tmp/5zKnElN0F2 (PID: 6233)File opened: /proc/1334/exe
    Source: /tmp/5zKnElN0F2 (PID: 6233)File opened: /proc/1576/exe
    Source: /tmp/5zKnElN0F2 (PID: 6233)File opened: /proc/2302/exe
    Source: /tmp/5zKnElN0F2 (PID: 6233)File opened: /proc/3236/exe
    Source: /tmp/5zKnElN0F2 (PID: 6233)File opened: /proc/2025/exe
    Source: /tmp/5zKnElN0F2 (PID: 6233)File opened: /proc/2146/exe
    Source: /tmp/5zKnElN0F2 (PID: 6233)File opened: /proc/910/exe
    Source: /tmp/5zKnElN0F2 (PID: 6233)File opened: /proc/6227/exe
    Source: /tmp/5zKnElN0F2 (PID: 6233)File opened: /proc/912/exe
    Source: /tmp/5zKnElN0F2 (PID: 6233)File opened: /proc/517/exe
    Source: /tmp/5zKnElN0F2 (PID: 6233)File opened: /proc/759/exe
    Source: /tmp/5zKnElN0F2 (PID: 6233)File opened: /proc/2307/exe
    Source: /tmp/5zKnElN0F2 (PID: 6233)File opened: /proc/918/exe
    Source: /tmp/5zKnElN0F2 (PID: 6233)File opened: /proc/1594/exe
    Source: /tmp/5zKnElN0F2 (PID: 6233)File opened: /proc/2285/exe
    Source: /tmp/5zKnElN0F2 (PID: 6233)File opened: /proc/2281/exe
    Source: /tmp/5zKnElN0F2 (PID: 6233)File opened: /proc/1349/exe
    Source: /tmp/5zKnElN0F2 (PID: 6233)File opened: /proc/1623/exe
    Source: /tmp/5zKnElN0F2 (PID: 6233)File opened: /proc/761/exe
    Source: /tmp/5zKnElN0F2 (PID: 6233)File opened: /proc/1622/exe
    Source: /tmp/5zKnElN0F2 (PID: 6233)File opened: /proc/884/exe
    Source: /tmp/5zKnElN0F2 (PID: 6233)File opened: /proc/1983/exe
    Source: /tmp/5zKnElN0F2 (PID: 6233)File opened: /proc/2038/exe
    Source: /tmp/5zKnElN0F2 (PID: 6233)File opened: /proc/1344/exe
    Source: /tmp/5zKnElN0F2 (PID: 6233)File opened: /proc/1465/exe
    Source: /tmp/5zKnElN0F2 (PID: 6233)File opened: /proc/1586/exe
    Source: /tmp/5zKnElN0F2 (PID: 6233)File opened: /proc/1463/exe
    Source: /tmp/5zKnElN0F2 (PID: 6233)File opened: /proc/2156/exe
    Source: /tmp/5zKnElN0F2 (PID: 6233)File opened: /proc/800/exe
    Source: /tmp/5zKnElN0F2 (PID: 6233)File opened: /proc/6238/exe
    Source: /tmp/5zKnElN0F2 (PID: 6233)File opened: /proc/801/exe
    Source: /tmp/5zKnElN0F2 (PID: 6233)File opened: /proc/1629/exe
    Source: /tmp/5zKnElN0F2 (PID: 6233)File opened: /proc/1627/exe
    Source: /tmp/5zKnElN0F2 (PID: 6233)File opened: /proc/1900/exe
    Source: /tmp/5zKnElN0F2 (PID: 6233)File opened: /proc/3021/exe
    Source: /tmp/5zKnElN0F2 (PID: 6233)File opened: /proc/491/exe
    Source: /tmp/5zKnElN0F2 (PID: 6233)File opened: /proc/2294/exe
    Source: /tmp/5zKnElN0F2 (PID: 6233)File opened: /proc/2050/exe
    Source: /tmp/5zKnElN0F2 (PID: 6233)File opened: /proc/1877/exe
    Source: /tmp/5zKnElN0F2 (PID: 6233)File opened: /proc/772/exe
    Source: /tmp/5zKnElN0F2 (PID: 6233)File opened: /proc/1633/exe
    Source: /tmp/5zKnElN0F2 (PID: 6233)File opened: /proc/1599/exe
    Source: /tmp/5zKnElN0F2 (PID: 6233)File opened: /proc/1632/exe
    Source: /tmp/5zKnElN0F2 (PID: 6233)File opened: /proc/774/exe
    Source: /tmp/5zKnElN0F2 (PID: 6233)File opened: /proc/1477/exe
    Source: /tmp/5zKnElN0F2 (PID: 6233)File opened: /proc/654/exe
    Source: /tmp/5zKnElN0F2 (PID: 6233)File opened: /proc/896/exe
    Source: /tmp/5zKnElN0F2 (PID: 6233)File opened: /proc/1476/exe
    Source: /tmp/5zKnElN0F2 (PID: 6233)File opened: /proc/1872/exe
    Source: /tmp/5zKnElN0F2 (PID: 6233)File opened: /proc/2048/exe
    Source: /tmp/5zKnElN0F2 (PID: 6233)File opened: /proc/655/exe
    Source: /tmp/5zKnElN0F2 (PID: 6233)File opened: /proc/1475/exe
    Source: /tmp/5zKnElN0F2 (PID: 6233)File opened: /proc/2289/exe
    Source: /tmp/5zKnElN0F2 (PID: 6233)File opened: /proc/656/exe
    Source: /tmp/5zKnElN0F2 (PID: 6233)File opened: /proc/777/exe
    Source: /tmp/5zKnElN0F2 (PID: 6233)File opened: /proc/657/exe
    Source: /tmp/5zKnElN0F2 (PID: 6233)File opened: /proc/4466/exe
    Source: /tmp/5zKnElN0F2 (PID: 6233)File opened: /proc/658/exe
    Source: /tmp/5zKnElN0F2 (PID: 6233)File opened: /proc/4467/exe
    Source: /tmp/5zKnElN0F2 (PID: 6233)File opened: /proc/4468/exe
    Source: /tmp/5zKnElN0F2 (PID: 6233)File opened: /proc/4469/exe
    Source: /tmp/5zKnElN0F2 (PID: 6233)File opened: /proc/4502/exe
    Source: /tmp/5zKnElN0F2 (PID: 6233)File opened: /proc/419/exe
    Source: /tmp/5zKnElN0F2 (PID: 6233)File opened: /proc/936/exe
    Source: /tmp/5zKnElN0F2 (PID: 6233)File opened: /proc/1639/exe
    Source: /tmp/5zKnElN0F2 (PID: 6233)File opened: /proc/1638/exe
    Source: /tmp/5zKnElN0F2 (PID: 6233)File opened: /proc/2208/exe
    Source: /tmp/5zKnElN0F2 (PID: 6233)File opened: /proc/2180/exe
    Source: /tmp/5zKnElN0F2 (PID: 6233)File opened: /proc/1809/exe
    Source: /tmp/5zKnElN0F2 (PID: 6233)File opened: /proc/1494/exe
    Source: /tmp/5zKnElN0F2 (PID: 6233)File opened: /proc/1890/exe
    Source: /tmp/5zKnElN0F2 (PID: 6233)File opened: /proc/2063/exe
    Source: /tmp/5zKnElN0F2 (PID: 6233)File opened: /proc/2062/exe
    Source: /tmp/5zKnElN0F2 (PID: 6233)File opened: /proc/1888/exe
    Source: /tmp/5zKnElN0F2 (PID: 6233)File opened: /proc/1886/exe
    Source: /tmp/5zKnElN0F2 (PID: 6233)File opened: /proc/420/exe
    Source: /tmp/5zKnElN0F2 (PID: 6233)File opened: /proc/1489/exe
    Source: /tmp/5zKnElN0F2 (PID: 6233)File opened: /proc/785/exe
    Source: /tmp/5zKnElN0F2 (PID: 6233)File opened: /proc/1642/exe
    Source: /tmp/5zKnElN0F2 (PID: 6233)File opened: /proc/788/exe
    Source: /tmp/5zKnElN0F2 (PID: 6233)File opened: /proc/667/exe
    Source: /tmp/5zKnElN0F2 (PID: 6233)File opened: /proc/789/exe
    Source: /tmp/5zKnElN0F2 (PID: 6233)File opened: /proc/1648/exe
    Source: /tmp/5zKnElN0F2 (PID: 6233)File opened: /proc/4495/exe
    Source: /tmp/5zKnElN0F2 (PID: 6233)File opened: /proc/6156/exe
    Source: /tmp/5zKnElN0F2 (PID: 6233)File opened: /proc/4498/exe
    Source: /tmp/5zKnElN0F2 (PID: 6233)File opened: /proc/2078/exe
    Source: /tmp/5zKnElN0F2 (PID: 6233)File opened: /proc/2077/exe
    Source: /tmp/5zKnElN0F2 (PID: 6233)File opened: /proc/2074/exe
    Source: /tmp/5zKnElN0F2 (PID: 6233)File opened: /proc/2195/exe
    Source: /tmp/5zKnElN0F2 (PID: 6233)File opened: /proc/670/exe
    Source: /tmp/5zKnElN0F2 (PID: 6233)File opened: /proc/4490/exe
    Source: /tmp/5zKnElN0F2 (PID: 6233)File opened: /proc/2746/exe

    Hooking and other Techniques for Hiding and Protection

    barindex
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 50378
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 50380
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 50382
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 50384
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 50388
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 50392
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 50396
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 50400
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 50402
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 50414
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 50420
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 50422
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 50426
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 50430
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 50434
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 50436
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 50444
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 50448
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 50456
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 50462
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 50466
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 50468
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 50474
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 50478
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 50482
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 50488
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 50492
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 50494
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 54182
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 54188
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 54194
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 54200
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 54206
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 54212
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 54218
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 54222
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 54228
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 54232
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 54238
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 54244
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 54250
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 54258
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 54262
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 54274
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 54276
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 54288
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 54306
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 54332
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 54352
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 54366
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 54384
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 54408
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 54436
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 54460
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 54474
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 54486
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57128
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57136
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57140
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57142
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57146
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57156
    Source: /tmp/5zKnElN0F2 (PID: 6225)Queries kernel information via 'uname':
    Source: 5zKnElN0F2, 6225.1.00000000e3b31b61.00000000feb11032.rw-.sdmp, 5zKnElN0F2, 6227.1.00000000e3b31b61.00000000feb11032.rw-.sdmpBinary or memory string: !/etc/qemu-binfmt/ppc11!hotpluggableq
    Source: 5zKnElN0F2, 6225.1.00000000258270c1.0000000060d5cb64.rw-.sdmp, 5zKnElN0F2, 6227.1.00000000258270c1.0000000060d5cb64.rw-.sdmp, 5zKnElN0F2, 6229.1.00000000258270c1.0000000060d5cb64.rw-.sdmp, 5zKnElN0F2, 6236.1.00000000258270c1.0000000060d5cb64.rw-.sdmp, 5zKnElN0F2, 6238.1.00000000258270c1.0000000060d5cb64.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-ppc/tmp/5zKnElN0F2SUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/5zKnElN0F2
    Source: 5zKnElN0F2, 6229.1.00000000e3b31b61.00000000feb11032.rw-.sdmp, 5zKnElN0F2, 6236.1.00000000e3b31b61.00000000feb11032.rw-.sdmp, 5zKnElN0F2, 6238.1.00000000e3b31b61.00000000feb11032.rw-.sdmpBinary or memory string: !/etc/qemu-binfmt/ppc1
    Source: 5zKnElN0F2, 6225.1.00000000e3b31b61.00000000feb11032.rw-.sdmp, 5zKnElN0F2, 6227.1.00000000e3b31b61.00000000feb11032.rw-.sdmp, 5zKnElN0F2, 6229.1.00000000e3b31b61.00000000feb11032.rw-.sdmp, 5zKnElN0F2, 6236.1.00000000e3b31b61.00000000feb11032.rw-.sdmp, 5zKnElN0F2, 6238.1.00000000e3b31b61.00000000feb11032.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/ppc
    Source: 5zKnElN0F2, 6225.1.00000000258270c1.0000000060d5cb64.rw-.sdmp, 5zKnElN0F2, 6227.1.00000000258270c1.0000000060d5cb64.rw-.sdmp, 5zKnElN0F2, 6229.1.00000000258270c1.0000000060d5cb64.rw-.sdmp, 5zKnElN0F2, 6236.1.00000000258270c1.0000000060d5cb64.rw-.sdmp, 5zKnElN0F2, 6238.1.00000000258270c1.0000000060d5cb64.rw-.sdmpBinary or memory string: /usr/bin/qemu-ppc

    Stealing of Sensitive Information

    barindex
    Source: Yara matchFile source: dump.pcap, type: PCAP

    Remote Access Functionality

    barindex
    Source: Yara matchFile source: dump.pcap, type: PCAP
    Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
    Valid AccountsWindows Management InstrumentationPath InterceptionPath Interception1
    Obfuscated Files or Information
    1
    OS Credential Dumping
    11
    Security Software Discovery
    Remote ServicesData from Local SystemExfiltration Over Other Network Medium1
    Encrypted Channel
    Eavesdrop on Insecure Network CommunicationRemotely Track Device Without Authorization1
    Service Stop
    Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over Bluetooth11
    Non-Standard Port
    Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
    Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated Exfiltration1
    Application Layer Protocol
    Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
    No configs have been found
    Hide Legend

    Legend:

    • Process
    • Signature
    • Created File
    • DNS/IP Info
    • Is Dropped
    • Number of created Files
    • Is malicious
    • Internet
    behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 635411 Sample: 5zKnElN0F2 Startdate: 27/05/2022 Architecture: LINUX Score: 68 22 209.219.101.83 WINDSTREAMUS United States 2->22 24 209.248.243.235 WINDSTREAMUS United States 2->24 26 98 other IPs or domains 2->26 28 Multi AV Scanner detection for submitted file 2->28 30 Yara detected Mirai 2->30 32 Uses known network protocols on non-standard ports 2->32 34 Sample is packed with UPX 2->34 9 5zKnElN0F2 2->9         started        signatures3 process4 process5 11 5zKnElN0F2 9->11         started        13 5zKnElN0F2 9->13         started        process6 15 5zKnElN0F2 11->15         started        18 5zKnElN0F2 11->18         started        signatures7 36 Sample tries to kill multiple processes (SIGKILL) 15->36 20 5zKnElN0F2 18->20         started        process8
    SourceDetectionScannerLabelLink
    5zKnElN0F230%ReversingLabsLinux.Trojan.Mirai
    No Antivirus matches
    No Antivirus matches
    No Antivirus matches
    No contacted domains info
    NameSourceMaliciousAntivirus DetectionReputation
    http://upx.sf.net5zKnElN0F2false
      high
      • No. of IPs < 25%
      • 25% < No. of IPs < 50%
      • 50% < No. of IPs < 75%
      • 75% < No. of IPs
      IPDomainCountryFlagASNASN NameMalicious
      248.213.59.144
      unknownReserved
      unknownunknownfalse
      251.130.127.226
      unknownReserved
      unknownunknownfalse
      88.75.6.154
      unknownGermany
      3209VODANETInternationalIP-BackboneofVodafoneDEfalse
      152.40.102.106
      unknownUnited States
      53785UNC-GREENSBOROUSfalse
      152.38.121.52
      unknownUnited States
      81NCRENUSfalse
      202.218.0.155
      unknownJapan4694IDCFIDCFrontierIncJPfalse
      85.84.124.101
      unknownSpain
      12338EUSKALTELESfalse
      181.242.239.177
      unknownColombia
      26611COMCELSACOfalse
      166.17.196.160
      unknownUnited States
      206CSC-IGN-AMERUSfalse
      6.71.232.135
      unknownUnited States
      1479DNIC-ASBLK-01478-01479USfalse
      215.140.101.179
      unknownUnited States
      721DNIC-ASBLK-00721-00726USfalse
      131.67.195.233
      unknownUnited States
      138DNIC-AS-00138USfalse
      216.47.114.137
      unknownUnited States
      397187NHN-GLOBALUSfalse
      175.44.191.61
      unknownChina
      4837CHINA169-BACKBONECHINAUNICOMChina169BackboneCNfalse
      57.95.244.181
      unknownBelgium
      51964ORANGE-BUSINESS-SERVICES-IPSN-ASNFRfalse
      182.181.115.112
      unknownPakistan
      45595PKTELECOM-AS-PKPakistanTelecomCompanyLimitedPKfalse
      147.36.189.252
      unknownUnited States
      1559DNIC-ASBLK-01550-01601USfalse
      16.163.191.244
      unknownUnited States
      unknownunknownfalse
      102.125.211.85
      unknownSudan
      36972MTNSDfalse
      242.207.165.243
      unknownReserved
      unknownunknownfalse
      220.146.79.49
      unknownJapan2510INFOWEBFUJITSULIMITEDJPfalse
      59.204.179.210
      unknownChina
      2516KDDIKDDICORPORATIONJPfalse
      176.67.118.196
      unknownPalestinian Territory Occupied
      51407MADA-ASPSfalse
      95.225.107.120
      unknownItaly
      3269ASN-IBSNAZITfalse
      7.179.30.152
      unknownUnited States
      3356LEVEL3USfalse
      209.248.243.235
      unknownUnited States
      7029WINDSTREAMUSfalse
      21.7.113.27
      unknownUnited States
      8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
      17.3.87.47
      unknownUnited States
      714APPLE-ENGINEERINGUSfalse
      72.97.169.89
      unknownUnited States
      22394CELLCOUSfalse
      57.141.231.103
      unknownBelgium
      2686ATGS-MMD-ASUSfalse
      91.220.89.64
      unknownAustria
      51767JOHANNITER-UNFALL-HILFEATfalse
      11.33.204.40
      unknownUnited States
      3356LEVEL3USfalse
      70.30.247.30
      unknownCanada
      577BACOMCAfalse
      98.19.126.216
      unknownUnited States
      7029WINDSTREAMUSfalse
      173.7.4.52
      unknownUnited States
      10507SPCSUSfalse
      64.123.49.206
      unknownUnited States
      7018ATT-INTERNET4USfalse
      71.161.139.71
      unknownUnited States
      701UUNETUSfalse
      221.27.57.106
      unknownJapan17676GIGAINFRASoftbankBBCorpJPfalse
      57.252.101.85
      unknownBelgium
      2686ATGS-MMD-ASUSfalse
      221.239.50.117
      unknownChina
      17638CHINATELECOM-TJ-AS-APASNforTIANJINProvincialNetofCTfalse
      60.26.69.53
      unknownChina
      4837CHINA169-BACKBONECHINAUNICOMChina169BackboneCNfalse
      67.116.193.63
      unknownUnited States
      7018ATT-INTERNET4USfalse
      160.184.16.245
      unknownSouth Africa
      36903MT-MPLSMAfalse
      251.16.126.103
      unknownReserved
      unknownunknownfalse
      193.245.180.21
      unknownBelgium
      3549LVLT-3549USfalse
      8.188.45.192
      unknownSingapore
      37963CNNIC-ALIBABA-CN-NET-APHangzhouAlibabaAdvertisingCoLtdfalse
      125.143.119.66
      unknownKorea Republic of
      4766KIXS-AS-KRKoreaTelecomKRfalse
      152.31.80.240
      unknownUnited States
      6559NCIHUSfalse
      12.92.121.104
      unknownUnited States
      7018ATT-INTERNET4USfalse
      215.126.53.189
      unknownUnited States
      721DNIC-ASBLK-00721-00726USfalse
      3.131.241.119
      unknownUnited States
      16509AMAZON-02USfalse
      191.92.238.155
      unknownColombia
      27831ColombiaMovilCOfalse
      24.26.58.217
      unknownUnited States
      10796TWC-10796-MIDWESTUSfalse
      63.72.64.154
      unknownUnited States
      701UUNETUSfalse
      9.115.4.121
      unknownUnited States
      3356LEVEL3USfalse
      57.25.76.38
      unknownBelgium
      2686ATGS-MMD-ASUSfalse
      167.38.155.197
      unknownCanada
      2665CDAGOVNCAfalse
      163.151.39.36
      unknownUnited States
      36161WESTCHESTERCOUNTY-NYUSfalse
      82.224.120.126
      unknownFrance
      12322PROXADFRfalse
      53.72.59.103
      unknownGermany
      31399DAIMLER-ASITIGNGlobalNetworkDEfalse
      171.130.11.59
      unknownUnited States
      9874STARHUB-MOBILEStarHubLtdSGfalse
      215.91.18.89
      unknownUnited States
      721DNIC-ASBLK-00721-00726USfalse
      25.254.25.135
      unknownUnited Kingdom
      199055UKCLOUD-ASGBfalse
      71.192.101.169
      unknownUnited States
      7922COMCAST-7922USfalse
      85.196.199.247
      unknownEstonia
      61307EE-AS-STVEEfalse
      91.250.181.214
      unknownSpain
      12479UNI2-ASESfalse
      215.55.124.124
      unknownUnited States
      721DNIC-ASBLK-00721-00726USfalse
      109.218.10.173
      unknownFrance
      3215FranceTelecom-OrangeFRfalse
      100.188.108.206
      unknownUnited States
      21928T-MOBILE-AS21928USfalse
      181.66.216.170
      unknownPeru
      6147TelefonicadelPeruSAAPEfalse
      18.107.223.195
      unknownUnited States
      3MIT-GATEWAYSUSfalse
      119.80.115.135
      unknownChina
      17858POWERVIS-AS-KRLGPOWERCOMMKRfalse
      176.151.103.215
      unknownFrance
      5410BOUYGTEL-ISPFRfalse
      96.105.107.122
      unknownUnited States
      7922COMCAST-7922USfalse
      160.95.83.51
      unknownUnited States
      217UMN-SYSTEMUSfalse
      209.219.101.83
      unknownUnited States
      7029WINDSTREAMUSfalse
      159.197.33.178
      unknownUnited Kingdom
      1273CWVodafoneGroupPLCEUfalse
      141.238.20.159
      unknownUnited States
      395015SUNY-FREDONIAUSfalse
      100.63.227.120
      unknownUnited States
      701UUNETUSfalse
      163.226.55.140
      unknownJapan24297FCNUniversityPublicCorporationOsakaJPfalse
      189.166.254.5
      unknownMexico
      8151UninetSAdeCVMXfalse
      130.247.179.246
      unknownUnited States
      786JANETJiscServicesLimitedGBfalse
      40.196.42.224
      unknownUnited States
      4249LILLY-ASUSfalse
      134.214.79.249
      unknownFrance
      2060FR-RENATERRENATER_ASNBLOCK1EUfalse
      244.140.81.28
      unknownReserved
      unknownunknownfalse
      86.176.103.153
      unknownUnited Kingdom
      2856BT-UK-ASBTnetUKRegionalnetworkGBfalse
      145.208.19.23
      unknownNetherlands
      1101IP-EEND-ASIP-EENDBVNLfalse
      113.105.159.164
      unknownChina
      134763CT-DONGGUAN-IDCCHINANETGuangdongprovincenetworkCNfalse
      105.91.86.94
      unknownEgypt
      36992ETISALAT-MISREGfalse
      12.141.232.110
      unknownUnited States
      7018ATT-INTERNET4USfalse
      31.172.254.55
      unknownUnited Kingdom
      34920SIMPLY-ROMFORDGBfalse
      76.144.187.104
      unknownUnited States
      7922COMCAST-7922USfalse
      4.0.229.194
      unknownUnited States
      3356LEVEL3USfalse
      48.35.173.172
      unknownUnited States
      2686ATGS-MMD-ASUSfalse
      170.178.42.2
      unknownUnited States
      11685HNBCOL-ASUSfalse
      61.207.245.49
      unknownJapan4713OCNNTTCommunicationsCorporationJPfalse
      195.189.238.150
      unknownRussian Federation
      41654INETRARUfalse
      1.5.141.51
      unknownJapan4725ODNSoftBankMobileCorpJPfalse
      186.224.149.70
      unknownBrazil
      28580CILNETComunicacaoeInformaticaLTDABRfalse
      255.150.73.125
      unknownReserved
      unknownunknownfalse
      No context
      No context
      No context
      No context
      No context
      No created / dropped files found
      File type:ELF 32-bit MSB executable, PowerPC or cisco 4500, version 1 (GNU/Linux), statically linked, stripped
      Entropy (8bit):7.9643107024054975
      TrID:
      • ELF Executable and Linkable format (Linux) (4029/14) 50.16%
      • ELF Executable and Linkable format (generic) (4004/1) 49.84%
      File name:5zKnElN0F2
      File size:39372
      MD5:d74bf4db8e2e43cbdc9c527ec15356b0
      SHA1:5de6b4e1a4b1f896ec6b3b6b473c8afb4d6f40a1
      SHA256:c0b3f4b9a9a57965c0429b5199e634012e223a4617a13a89dc5e2508085e5575
      SHA512:d262f391e46bf85eabadd74dfc74d78a2eb1fd25d32b45b8f9b6e2cbaeed624a1a32237897014bf26346bbbe27d71e0a3a5d7fad1d12dbcbfc86086b5fb22a1f
      SSDEEP:768:FdCZnhT/jFCaEQd4RC8he9+QZu3ckO7jTlZKhnHdM9i285BE4uVcqgw09M:O5hnFOQURhCZtB7j/oHdAijQ4u+qgw0W
      TLSH:F903F1BDD0B90DC1EB6BED6C8C77C2A82EE15F9AF2E6CDA4329C6F5149060395345D40
      File Content Preview:.ELF...........................4.........4. ...(....................................................................dt.Q................................UPX!..........E...E........W.......?.E.h4...@b..................d/%.....)..2x....F...NUu....]<fh.u...B.

      ELF header

      Class:ELF32
      Data:2's complement, big endian
      Version:1 (current)
      Machine:PowerPC
      Version Number:0x1
      Type:EXEC (Executable file)
      OS/ABI:UNIX - Linux
      ABI Version:0
      Entry Point Address:0x1086d8
      Flags:0x0
      ELF Header Size:52
      Program Header Offset:52
      Program Header Size:32
      Number of Program Headers:3
      Section Header Offset:0
      Section Header Size:40
      Number of Section Headers:0
      Header String Table Index:0
      TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
      LOAD0x00x1000000x1000000x98c00x98c04.13100x5R E0x10000
      LOAD0xa6e00x1002a6e00x1002a6e00x00x00.00000x6RW 0x10000
      GNU_STACK0x00x00x00x00x00.00000x6RW 0x4
      TimestampSource PortDest PortSource IPDest IP
      May 27, 2022 21:17:30.366656065 CEST42836443192.168.2.2391.189.91.43
      May 27, 2022 21:17:30.629111052 CEST655623192.168.2.23249.169.15.40
      May 27, 2022 21:17:30.629196882 CEST655623192.168.2.23104.199.228.40
      May 27, 2022 21:17:30.629240990 CEST655623192.168.2.2320.56.144.190
      May 27, 2022 21:17:30.629249096 CEST655623192.168.2.23103.176.96.40
      May 27, 2022 21:17:30.629260063 CEST655623192.168.2.23159.38.110.212
      May 27, 2022 21:17:30.629281044 CEST655623192.168.2.2329.151.218.80
      May 27, 2022 21:17:30.629290104 CEST655623192.168.2.23192.5.233.79
      May 27, 2022 21:17:30.629291058 CEST655623192.168.2.23203.254.91.17
      May 27, 2022 21:17:30.629333973 CEST655623192.168.2.23197.68.217.22
      May 27, 2022 21:17:30.629347086 CEST655623192.168.2.23172.136.171.162
      May 27, 2022 21:17:30.629360914 CEST655623192.168.2.2384.169.157.116
      May 27, 2022 21:17:30.629373074 CEST655623192.168.2.2370.83.239.117
      May 27, 2022 21:17:30.629398108 CEST655623192.168.2.23189.56.57.181
      May 27, 2022 21:17:30.629414082 CEST655623192.168.2.23147.145.145.36
      May 27, 2022 21:17:30.629421949 CEST655623192.168.2.23124.80.238.203
      May 27, 2022 21:17:30.629425049 CEST655623192.168.2.2382.36.65.251
      May 27, 2022 21:17:30.629445076 CEST655623192.168.2.23201.154.224.153
      May 27, 2022 21:17:30.629451036 CEST655623192.168.2.23204.218.135.134
      May 27, 2022 21:17:30.629452944 CEST655623192.168.2.23126.67.223.153
      May 27, 2022 21:17:30.629468918 CEST655623192.168.2.2394.128.230.229
      May 27, 2022 21:17:30.629489899 CEST655623192.168.2.23249.110.130.18
      May 27, 2022 21:17:30.629511118 CEST655623192.168.2.23240.228.179.208
      May 27, 2022 21:17:30.629512072 CEST655623192.168.2.2316.182.131.136
      May 27, 2022 21:17:30.629523993 CEST655623192.168.2.2344.65.107.245
      May 27, 2022 21:17:30.629534960 CEST655623192.168.2.2375.106.47.86
      May 27, 2022 21:17:30.629547119 CEST655623192.168.2.23137.127.90.198
      May 27, 2022 21:17:30.629569054 CEST655623192.168.2.23108.135.179.99
      May 27, 2022 21:17:30.629611015 CEST655623192.168.2.23252.151.202.166
      May 27, 2022 21:17:30.629616022 CEST655623192.168.2.23142.27.4.128
      May 27, 2022 21:17:30.629620075 CEST655623192.168.2.2332.150.0.9
      May 27, 2022 21:17:30.629627943 CEST655623192.168.2.23178.182.189.196
      May 27, 2022 21:17:30.629637957 CEST655623192.168.2.23247.142.150.14
      May 27, 2022 21:17:30.629642963 CEST655623192.168.2.2395.80.50.226
      May 27, 2022 21:17:30.629683971 CEST655623192.168.2.23145.119.160.167
      May 27, 2022 21:17:30.629695892 CEST655623192.168.2.23126.53.28.195
      May 27, 2022 21:17:30.629719973 CEST655623192.168.2.2360.37.188.179
      May 27, 2022 21:17:30.629725933 CEST655623192.168.2.2353.12.116.174
      May 27, 2022 21:17:30.629736900 CEST655623192.168.2.238.47.163.205
      May 27, 2022 21:17:30.629740953 CEST655623192.168.2.23151.232.166.68
      May 27, 2022 21:17:30.629746914 CEST655623192.168.2.23254.203.17.44
      May 27, 2022 21:17:30.629781008 CEST655623192.168.2.23163.138.31.255
      May 27, 2022 21:17:30.629789114 CEST655623192.168.2.23204.211.151.168
      May 27, 2022 21:17:30.629805088 CEST655623192.168.2.2346.84.226.86
      May 27, 2022 21:17:30.629820108 CEST655623192.168.2.2382.73.227.91
      May 27, 2022 21:17:30.629832983 CEST655623192.168.2.23109.62.224.105
      May 27, 2022 21:17:30.629838943 CEST655623192.168.2.23217.116.246.176
      May 27, 2022 21:17:30.629841089 CEST655623192.168.2.23212.139.142.36
      May 27, 2022 21:17:30.629843950 CEST655623192.168.2.23245.8.37.2
      May 27, 2022 21:17:30.629857063 CEST655623192.168.2.23252.210.205.85
      May 27, 2022 21:17:30.629900932 CEST655623192.168.2.23249.52.26.203
      May 27, 2022 21:17:30.629905939 CEST655623192.168.2.23187.217.81.167
      May 27, 2022 21:17:30.629920959 CEST655623192.168.2.2376.117.182.151
      May 27, 2022 21:17:30.629930019 CEST655623192.168.2.2388.212.159.97
      May 27, 2022 21:17:30.629931927 CEST655623192.168.2.23129.137.42.228
      May 27, 2022 21:17:30.629933119 CEST655623192.168.2.2316.158.157.65
      May 27, 2022 21:17:30.629940033 CEST655623192.168.2.23107.216.249.0
      May 27, 2022 21:17:30.629951000 CEST655623192.168.2.23119.40.70.174
      May 27, 2022 21:17:30.629956007 CEST655623192.168.2.23211.85.191.32
      May 27, 2022 21:17:30.629976988 CEST655623192.168.2.23120.194.72.39
      May 27, 2022 21:17:30.629976988 CEST655623192.168.2.23192.174.238.76
      May 27, 2022 21:17:30.629987955 CEST655623192.168.2.238.76.40.7
      May 27, 2022 21:17:30.630007982 CEST655623192.168.2.2352.174.56.117
      May 27, 2022 21:17:30.630013943 CEST655623192.168.2.2355.121.115.12
      May 27, 2022 21:17:30.630038977 CEST655623192.168.2.2337.200.247.184
      May 27, 2022 21:17:30.630048037 CEST655623192.168.2.23135.58.77.194
      May 27, 2022 21:17:30.630068064 CEST655623192.168.2.23163.122.20.77
      May 27, 2022 21:17:30.630070925 CEST655623192.168.2.23206.238.108.62
      May 27, 2022 21:17:30.630078077 CEST655623192.168.2.2399.254.174.201
      May 27, 2022 21:17:30.630089045 CEST655623192.168.2.23142.99.153.246
      May 27, 2022 21:17:30.630100012 CEST655623192.168.2.2388.87.151.32
      May 27, 2022 21:17:30.630105972 CEST655623192.168.2.2387.115.45.179
      May 27, 2022 21:17:30.630109072 CEST655623192.168.2.2365.48.6.131
      May 27, 2022 21:17:30.630125999 CEST655623192.168.2.2371.120.238.122
      May 27, 2022 21:17:30.630131006 CEST655623192.168.2.2397.85.157.217
      May 27, 2022 21:17:30.630139112 CEST655623192.168.2.23243.87.59.254
      May 27, 2022 21:17:30.630155087 CEST655623192.168.2.23201.222.18.219
      May 27, 2022 21:17:30.630156994 CEST655623192.168.2.23185.62.130.249
      May 27, 2022 21:17:30.630161047 CEST655623192.168.2.23181.68.156.195
      May 27, 2022 21:17:30.630167007 CEST655623192.168.2.2310.75.188.229
      May 27, 2022 21:17:30.630175114 CEST655623192.168.2.23158.242.96.240
      May 27, 2022 21:17:30.630187035 CEST655623192.168.2.23188.122.174.85
      May 27, 2022 21:17:30.630198002 CEST655623192.168.2.23141.30.129.227
      May 27, 2022 21:17:30.630218983 CEST655623192.168.2.23221.246.44.42
      May 27, 2022 21:17:30.630222082 CEST655623192.168.2.2363.193.103.194
      May 27, 2022 21:17:30.630242109 CEST655623192.168.2.23191.41.246.11
      May 27, 2022 21:17:30.630245924 CEST655623192.168.2.23185.187.69.16
      May 27, 2022 21:17:30.630254030 CEST655623192.168.2.2398.177.3.225
      May 27, 2022 21:17:30.630260944 CEST655623192.168.2.2353.215.171.143
      May 27, 2022 21:17:30.630274057 CEST655623192.168.2.23147.198.19.62
      May 27, 2022 21:17:30.630280972 CEST655623192.168.2.23206.50.72.44
      May 27, 2022 21:17:30.630295038 CEST655623192.168.2.23172.156.237.113
      May 27, 2022 21:17:30.630299091 CEST655623192.168.2.2324.118.115.187
      May 27, 2022 21:17:30.630306959 CEST655623192.168.2.2389.157.112.32
      May 27, 2022 21:17:30.630317926 CEST655623192.168.2.2325.32.0.209
      May 27, 2022 21:17:30.630330086 CEST655623192.168.2.2354.187.56.99
      May 27, 2022 21:17:30.630357027 CEST655623192.168.2.2353.226.188.88
      May 27, 2022 21:17:30.630364895 CEST655623192.168.2.23252.202.111.10
      May 27, 2022 21:17:30.630376101 CEST655623192.168.2.2318.209.39.93
      May 27, 2022 21:17:30.630383968 CEST655623192.168.2.2356.73.4.196

      System Behavior

      Start time:21:17:29
      Start date:27/05/2022
      Path:/tmp/5zKnElN0F2
      Arguments:/tmp/5zKnElN0F2
      File size:5388968 bytes
      MD5 hash:ae65271c943d3451b7f026d1fadccea6
      Start time:21:17:29
      Start date:27/05/2022
      Path:/tmp/5zKnElN0F2
      Arguments:n/a
      File size:5388968 bytes
      MD5 hash:ae65271c943d3451b7f026d1fadccea6
      Start time:21:17:29
      Start date:27/05/2022
      Path:/tmp/5zKnElN0F2
      Arguments:n/a
      File size:5388968 bytes
      MD5 hash:ae65271c943d3451b7f026d1fadccea6
      Start time:21:17:29
      Start date:27/05/2022
      Path:/tmp/5zKnElN0F2
      Arguments:n/a
      File size:5388968 bytes
      MD5 hash:ae65271c943d3451b7f026d1fadccea6
      Start time:21:17:29
      Start date:27/05/2022
      Path:/tmp/5zKnElN0F2
      Arguments:n/a
      File size:5388968 bytes
      MD5 hash:ae65271c943d3451b7f026d1fadccea6
      Start time:21:17:29
      Start date:27/05/2022
      Path:/tmp/5zKnElN0F2
      Arguments:n/a
      File size:5388968 bytes
      MD5 hash:ae65271c943d3451b7f026d1fadccea6