Linux Analysis Report
shAwKMD85K

Overview

General Information

Sample Name: shAwKMD85K
Analysis ID: 635419
MD5: e0c4f532b0a9fda3ee7d800775deb908
SHA1: 63f144f5b1f316e34510f15d4f93c3fc41d0b73e
SHA256: aa18cc657da907f749d8bf4aae9867152acc7320f518aa1f9a33bba195e19328
Tags: 32elfmirairenesas
Infos:

Detection

Mirai
Score: 68
Range: 0 - 100
Whitelisted: false

Signatures

Yara detected Mirai
Multi AV Scanner detection for submitted file
Uses known network protocols on non-standard ports
Sample tries to kill multiple processes (SIGKILL)
Connects to many ports of the same IP (likely port scanning)
Sample has stripped symbol table
Uses the "uname" system call to query kernel version information (possible evasion)
Enumerates processes within the "proc" file system
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Detected TCP or UDP traffic on non-standard ports
Sample listens on a socket
Sample tries to kill a process (SIGKILL)

Classification

AV Detection

barindex
Source: shAwKMD85K Virustotal: Detection: 43% Perma Link
Source: shAwKMD85K ReversingLabs: Detection: 41%

Networking

barindex
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 57286
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 57292
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 57300
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 57306
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 57314
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 57320
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 57330
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 57336
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 57342
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 57348
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 57354
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 57360
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 57366
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 57372
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 57376
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 57378
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 57384
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 57386
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 57388
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 57390
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 57392
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 57398
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 57400
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 57402
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 57406
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 57410
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 57428
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 57456
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 53624
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 53634
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 53646
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 53658
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 53686
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 53726
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 53770
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 53800
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 53814
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 53824
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 53832
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 53846
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 53866
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 53888
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 53900
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 53906
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 53916
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 53922
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 53938
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 53946
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 53960
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 53972
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 53982
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 53994
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 54012
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 54032
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 54048
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 54066
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 60628
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 60644
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 60662
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 60682
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 60702
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 60714
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 60724
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 60732
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 60746
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 60756
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 60770
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 60778
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 60792
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 60800
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 60816
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 60834
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 60854
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 60872
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 60890
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 60912
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 60924
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 60936
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 60948
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 60958
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 60968
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 60982
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 60996
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 32774
Source: global traffic TCP traffic: 45.95.169.139 ports 17244,9372,2,3,7,9
Source: global traffic TCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
Source: global traffic TCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
Source: global traffic TCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
Source: global traffic TCP traffic: 192.168.2.23:39008 -> 45.95.169.139:9372
Source: /tmp/shAwKMD85K (PID: 6239) Socket: 0.0.0.0::23 Jump to behavior
Source: unknown Network traffic detected: HTTP traffic on port 43928 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 42836 -> 443
Source: unknown TCP traffic detected without corresponding DNS query: 194.156.189.65
Source: unknown TCP traffic detected without corresponding DNS query: 141.20.85.65
Source: unknown TCP traffic detected without corresponding DNS query: 194.245.158.69
Source: unknown TCP traffic detected without corresponding DNS query: 103.96.209.65
Source: unknown TCP traffic detected without corresponding DNS query: 181.208.1.221
Source: unknown TCP traffic detected without corresponding DNS query: 114.8.240.128
Source: unknown TCP traffic detected without corresponding DNS query: 83.35.133.32
Source: unknown TCP traffic detected without corresponding DNS query: 144.9.72.233
Source: unknown TCP traffic detected without corresponding DNS query: 181.178.20.236
Source: unknown TCP traffic detected without corresponding DNS query: 140.195.233.234
Source: unknown TCP traffic detected without corresponding DNS query: 180.173.150.183
Source: unknown TCP traffic detected without corresponding DNS query: 28.24.156.119
Source: unknown TCP traffic detected without corresponding DNS query: 12.241.246.22
Source: unknown TCP traffic detected without corresponding DNS query: 96.116.137.210
Source: unknown TCP traffic detected without corresponding DNS query: 152.56.21.23
Source: unknown TCP traffic detected without corresponding DNS query: 246.186.28.56
Source: unknown TCP traffic detected without corresponding DNS query: 171.178.159.27
Source: unknown TCP traffic detected without corresponding DNS query: 220.244.29.31
Source: unknown TCP traffic detected without corresponding DNS query: 80.99.200.10
Source: unknown TCP traffic detected without corresponding DNS query: 81.0.246.54
Source: unknown TCP traffic detected without corresponding DNS query: 62.117.198.20
Source: unknown TCP traffic detected without corresponding DNS query: 212.14.185.185
Source: unknown TCP traffic detected without corresponding DNS query: 108.101.134.238
Source: unknown TCP traffic detected without corresponding DNS query: 196.169.98.41
Source: unknown TCP traffic detected without corresponding DNS query: 163.6.218.171
Source: unknown TCP traffic detected without corresponding DNS query: 167.118.252.130
Source: unknown TCP traffic detected without corresponding DNS query: 244.40.132.89
Source: unknown TCP traffic detected without corresponding DNS query: 165.67.34.79
Source: unknown TCP traffic detected without corresponding DNS query: 66.186.117.133
Source: unknown TCP traffic detected without corresponding DNS query: 121.221.93.12
Source: unknown TCP traffic detected without corresponding DNS query: 40.182.92.158
Source: unknown TCP traffic detected without corresponding DNS query: 48.137.15.209
Source: unknown TCP traffic detected without corresponding DNS query: 71.40.177.108
Source: unknown TCP traffic detected without corresponding DNS query: 133.102.245.142
Source: unknown TCP traffic detected without corresponding DNS query: 16.232.69.155
Source: unknown TCP traffic detected without corresponding DNS query: 51.123.209.80
Source: unknown TCP traffic detected without corresponding DNS query: 193.109.103.86
Source: unknown TCP traffic detected without corresponding DNS query: 201.125.108.181
Source: unknown TCP traffic detected without corresponding DNS query: 132.72.140.4
Source: unknown TCP traffic detected without corresponding DNS query: 139.27.139.59
Source: unknown TCP traffic detected without corresponding DNS query: 189.153.132.49
Source: unknown TCP traffic detected without corresponding DNS query: 116.202.39.34
Source: unknown TCP traffic detected without corresponding DNS query: 207.254.36.225
Source: unknown TCP traffic detected without corresponding DNS query: 207.101.157.127
Source: unknown TCP traffic detected without corresponding DNS query: 118.7.221.236
Source: unknown TCP traffic detected without corresponding DNS query: 81.39.106.72
Source: unknown TCP traffic detected without corresponding DNS query: 188.81.96.224
Source: unknown TCP traffic detected without corresponding DNS query: 39.101.200.132
Source: unknown TCP traffic detected without corresponding DNS query: 70.4.209.210
Source: unknown TCP traffic detected without corresponding DNS query: 211.36.92.160

System Summary

barindex
Source: /tmp/shAwKMD85K (PID: 6239) SIGKILL sent: pid: 658, result: successful Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) SIGKILL sent: pid: 720, result: successful Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) SIGKILL sent: pid: 759, result: successful Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) SIGKILL sent: pid: 772, result: successful Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) SIGKILL sent: pid: 789, result: successful Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) SIGKILL sent: pid: 800, result: successful Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) SIGKILL sent: pid: 904, result: successful Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) SIGKILL sent: pid: 936, result: successful Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) SIGKILL sent: pid: 1320, result: successful Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) SIGKILL sent: pid: 1334, result: successful Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) SIGKILL sent: pid: 1335, result: successful Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) SIGKILL sent: pid: 1389, result: successful Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) SIGKILL sent: pid: 1463, result: successful Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) SIGKILL sent: pid: 1465, result: successful Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) SIGKILL sent: pid: 1576, result: successful Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) SIGKILL sent: pid: 1809, result: successful Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) SIGKILL sent: pid: 1872, result: successful Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) SIGKILL sent: pid: 1888, result: successful Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) SIGKILL sent: pid: 1890, result: successful Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) SIGKILL sent: pid: 1983, result: successful Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) SIGKILL sent: pid: 2048, result: successful Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) SIGKILL sent: pid: 2062, result: successful Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) SIGKILL sent: pid: 6039, result: successful Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) SIGKILL sent: pid: 6192, result: successful Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) SIGKILL sent: pid: 6234, result: successful Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) SIGKILL sent: pid: 6243, result: successful Jump to behavior
Source: ELF static info symbol of initial sample .symtab present: no
Source: /tmp/shAwKMD85K (PID: 6239) SIGKILL sent: pid: 658, result: successful Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) SIGKILL sent: pid: 720, result: successful Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) SIGKILL sent: pid: 759, result: successful Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) SIGKILL sent: pid: 772, result: successful Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) SIGKILL sent: pid: 789, result: successful Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) SIGKILL sent: pid: 800, result: successful Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) SIGKILL sent: pid: 904, result: successful Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) SIGKILL sent: pid: 936, result: successful Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) SIGKILL sent: pid: 1320, result: successful Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) SIGKILL sent: pid: 1334, result: successful Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) SIGKILL sent: pid: 1335, result: successful Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) SIGKILL sent: pid: 1389, result: successful Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) SIGKILL sent: pid: 1463, result: successful Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) SIGKILL sent: pid: 1465, result: successful Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) SIGKILL sent: pid: 1576, result: successful Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) SIGKILL sent: pid: 1809, result: successful Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) SIGKILL sent: pid: 1872, result: successful Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) SIGKILL sent: pid: 1888, result: successful Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) SIGKILL sent: pid: 1890, result: successful Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) SIGKILL sent: pid: 1983, result: successful Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) SIGKILL sent: pid: 2048, result: successful Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) SIGKILL sent: pid: 2062, result: successful Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) SIGKILL sent: pid: 6039, result: successful Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) SIGKILL sent: pid: 6192, result: successful Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) SIGKILL sent: pid: 6234, result: successful Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) SIGKILL sent: pid: 6243, result: successful Jump to behavior
Source: classification engine Classification label: mal68.spre.troj.lin@0/0@0/0
Source: /tmp/shAwKMD85K (PID: 6239) File opened: /proc/6234/exe Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) File opened: /proc/1582/exe Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) File opened: /proc/2033/exe Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) File opened: /proc/2275/exe Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) File opened: /proc/3088/exe Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) File opened: /proc/6193/exe Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) File opened: /proc/6192/exe Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) File opened: /proc/1612/exe Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) File opened: /proc/1579/exe Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) File opened: /proc/1699/exe Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) File opened: /proc/1335/exe Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) File opened: /proc/1698/exe Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) File opened: /proc/2028/exe Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) File opened: /proc/1334/exe Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) File opened: /proc/1576/exe Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) File opened: /proc/2302/exe Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) File opened: /proc/3236/exe Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) File opened: /proc/2025/exe Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) File opened: /proc/2146/exe Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) File opened: /proc/910/exe Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) File opened: /proc/912/exe Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) File opened: /proc/517/exe Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) File opened: /proc/759/exe Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) File opened: /proc/2307/exe Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) File opened: /proc/918/exe Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) File opened: /proc/6243/exe Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) File opened: /proc/4465/exe Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) File opened: /proc/1594/exe Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) File opened: /proc/2285/exe Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) File opened: /proc/2281/exe Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) File opened: /proc/1349/exe Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) File opened: /proc/1623/exe Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) File opened: /proc/761/exe Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) File opened: /proc/1622/exe Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) File opened: /proc/884/exe Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) File opened: /proc/1983/exe Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) File opened: /proc/2038/exe Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) File opened: /proc/1344/exe Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) File opened: /proc/1465/exe Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) File opened: /proc/1586/exe Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) File opened: /proc/1463/exe Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) File opened: /proc/2156/exe Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) File opened: /proc/800/exe Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) File opened: /proc/801/exe Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) File opened: /proc/6116/exe Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) File opened: /proc/1629/exe Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) File opened: /proc/1627/exe Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) File opened: /proc/1900/exe Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) File opened: /proc/3021/exe Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) File opened: /proc/491/exe Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) File opened: /proc/2294/exe Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) File opened: /proc/2050/exe Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) File opened: /proc/1877/exe Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) File opened: /proc/772/exe Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) File opened: /proc/1633/exe Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) File opened: /proc/1599/exe Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) File opened: /proc/1632/exe Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) File opened: /proc/774/exe Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) File opened: /proc/1477/exe Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) File opened: /proc/654/exe Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) File opened: /proc/896/exe Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) File opened: /proc/1476/exe Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) File opened: /proc/1872/exe Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) File opened: /proc/2048/exe Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) File opened: /proc/655/exe Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) File opened: /proc/1475/exe Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) File opened: /proc/2289/exe Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) File opened: /proc/656/exe Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) File opened: /proc/777/exe Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) File opened: /proc/657/exe Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) File opened: /proc/4466/exe Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) File opened: /proc/658/exe Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) File opened: /proc/4467/exe Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) File opened: /proc/4468/exe Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) File opened: /proc/419/exe Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) File opened: /proc/936/exe Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) File opened: /proc/1639/exe Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) File opened: /proc/1638/exe Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) File opened: /proc/2208/exe Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) File opened: /proc/2180/exe Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) File opened: /proc/1809/exe Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) File opened: /proc/1494/exe Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) File opened: /proc/1890/exe Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) File opened: /proc/2063/exe Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) File opened: /proc/2062/exe Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) File opened: /proc/1888/exe Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) File opened: /proc/1886/exe Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) File opened: /proc/420/exe Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) File opened: /proc/1489/exe Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) File opened: /proc/785/exe Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) File opened: /proc/1642/exe Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) File opened: /proc/788/exe Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) File opened: /proc/667/exe Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) File opened: /proc/789/exe Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) File opened: /proc/1648/exe Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) File opened: /proc/6157/exe Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) File opened: /proc/6310/exe Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) File opened: /proc/4498/exe Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) File opened: /proc/2078/exe Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) File opened: /proc/2077/exe Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) File opened: /proc/2074/exe Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) File opened: /proc/2195/exe Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) File opened: /proc/670/exe Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) File opened: /proc/2746/exe Jump to behavior
Source: /tmp/shAwKMD85K (PID: 6239) File opened: /proc/793/exe Jump to behavior

Hooking and other Techniques for Hiding and Protection

barindex
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 57286
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 57292
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 57300
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 57306
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 57314
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 57320
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 57330
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 57336
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 57342
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 57348
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 57354
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 57360
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 57366
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 57372
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 57376
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 57378
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 57384
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 57386
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 57388
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 57390
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 57392
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 57398
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 57400
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 57402
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 57406
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 57410
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 57428
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 57456
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 53624
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 53634
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 53646
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 53658
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 53686
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 53726
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 53770
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 53800
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 53814
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 53824
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 53832
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 53846
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 53866
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 53888
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 53900
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 53906
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 53916
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 53922
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 53938
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 53946
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 53960
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 53972
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 53982
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 53994
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 54012
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 54032
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 54048
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 54066
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 60628
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 60644
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 60662
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 60682
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 60702
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 60714
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 60724
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 60732
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 60746
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 60756
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 60770
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 60778
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 60792
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 60800
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 60816
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 60834
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 60854
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 60872
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 60890
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 60912
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 60924
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 60936
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 60948
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 60958
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 60968
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 60982
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 60996
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 32774
Source: /tmp/shAwKMD85K (PID: 6232) Queries kernel information via 'uname': Jump to behavior
Source: shAwKMD85K, 6232.1.00000000a1b01e61.00000000e0dd4486.rw-.sdmp, shAwKMD85K, 6234.1.00000000a1b01e61.00000000e0dd4486.rw-.sdmp, shAwKMD85K, 6310.1.00000000a1b01e61.00000000e0dd4486.rw-.sdmp, shAwKMD85K, 6235.1.00000000a1b01e61.00000000e0dd4486.rw-.sdmp, shAwKMD85K, 6241.1.00000000a1b01e61.00000000e0dd4486.rw-.sdmp, shAwKMD85K, 6243.1.00000000a1b01e61.00000000e0dd4486.rw-.sdmp Binary or memory string: r}x86_64/usr/bin/qemu-sh4/tmp/shAwKMD85KSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/shAwKMD85K
Source: shAwKMD85K, 6232.1.00000000a1b01e61.00000000e0dd4486.rw-.sdmp, shAwKMD85K, 6234.1.00000000a1b01e61.00000000e0dd4486.rw-.sdmp, shAwKMD85K, 6310.1.00000000a1b01e61.00000000e0dd4486.rw-.sdmp, shAwKMD85K, 6235.1.00000000a1b01e61.00000000e0dd4486.rw-.sdmp, shAwKMD85K, 6241.1.00000000a1b01e61.00000000e0dd4486.rw-.sdmp, shAwKMD85K, 6243.1.00000000a1b01e61.00000000e0dd4486.rw-.sdmp Binary or memory string: /usr/bin/qemu-sh4
Source: shAwKMD85K, 6232.1.00000000d75652a9.000000006ca34ec5.rw-.sdmp, shAwKMD85K, 6234.1.00000000d75652a9.000000006ca34ec5.rw-.sdmp, shAwKMD85K, 6310.1.00000000d75652a9.000000006ca34ec5.rw-.sdmp, shAwKMD85K, 6235.1.00000000d75652a9.000000006ca34ec5.rw-.sdmp, shAwKMD85K, 6241.1.00000000d75652a9.000000006ca34ec5.rw-.sdmp, shAwKMD85K, 6243.1.00000000d75652a9.000000006ca34ec5.rw-.sdmp Binary or memory string: U5!/etc/qemu-binfmt/sh4
Source: shAwKMD85K, 6232.1.00000000d75652a9.000000006ca34ec5.rw-.sdmp, shAwKMD85K, 6234.1.00000000d75652a9.000000006ca34ec5.rw-.sdmp, shAwKMD85K, 6310.1.00000000d75652a9.000000006ca34ec5.rw-.sdmp, shAwKMD85K, 6235.1.00000000d75652a9.000000006ca34ec5.rw-.sdmp, shAwKMD85K, 6241.1.00000000d75652a9.000000006ca34ec5.rw-.sdmp, shAwKMD85K, 6243.1.00000000d75652a9.000000006ca34ec5.rw-.sdmp Binary or memory string: /etc/qemu-binfmt/sh4

Stealing of Sensitive Information

barindex
Source: Yara match File source: dump.pcap, type: PCAP

Remote Access Functionality

barindex
Source: Yara match File source: dump.pcap, type: PCAP
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs