Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
shAwKMD85K

Overview

General Information

Sample Name:shAwKMD85K
Analysis ID:635419
MD5:e0c4f532b0a9fda3ee7d800775deb908
SHA1:63f144f5b1f316e34510f15d4f93c3fc41d0b73e
SHA256:aa18cc657da907f749d8bf4aae9867152acc7320f518aa1f9a33bba195e19328
Tags:32elfmirairenesas
Infos:

Detection

Mirai
Score:68
Range:0 - 100
Whitelisted:false

Signatures

Yara detected Mirai
Multi AV Scanner detection for submitted file
Uses known network protocols on non-standard ports
Sample tries to kill multiple processes (SIGKILL)
Connects to many ports of the same IP (likely port scanning)
Sample has stripped symbol table
Uses the "uname" system call to query kernel version information (possible evasion)
Enumerates processes within the "proc" file system
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Detected TCP or UDP traffic on non-standard ports
Sample listens on a socket
Sample tries to kill a process (SIGKILL)

Classification

Analysis Advice

Static ELF header machine description suggests that the sample might not execute correctly on this machine.
All HTTP servers contacted by the sample do not answer. The sample is likely an old dropper which does no longer work.
Joe Sandbox Version:34.0.0 Boulder Opal
Analysis ID:635419
Start date and time: 27/05/202221:26:322022-05-27 21:26:32 +02:00
Joe Sandbox Product:CloudBasic
Overall analysis duration:0h 5m 53s
Hypervisor based Inspection enabled:false
Report type:light
Sample file name:shAwKMD85K
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Detection:MAL
Classification:mal68.spre.troj.lin@0/0@0/0
  • Report size exceeded maximum capacity and may have missing network information.
  • TCP Packets have been reduced to 100
Command:/tmp/shAwKMD85K
PID:6232
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
Infected
Standard Error:
  • system is lnxubuntu20
  • shAwKMD85K (PID: 6232, Parent: 6126, MD5: 8943e5f8f8c280467b4472c15ae93ba9) Arguments: /tmp/shAwKMD85K
  • cleanup
SourceRuleDescriptionAuthorStrings
dump.pcapJoeSecurity_Mirai_12Yara detected MiraiJoe Security
    No Snort rule has matched

    Click to jump to signature section

    Show All Signature Results

    AV Detection

    barindex
    Source: shAwKMD85KVirustotal: Detection: 43%Perma Link
    Source: shAwKMD85KReversingLabs: Detection: 41%

    Networking

    barindex
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57286
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57292
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57300
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57306
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57314
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57320
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57330
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57336
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57342
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57348
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57354
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57360
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57366
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57372
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57376
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57378
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57384
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57386
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57388
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57390
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57392
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57398
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57400
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57402
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57406
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57410
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57428
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57456
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 53624
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 53634
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 53646
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 53658
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 53686
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 53726
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 53770
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 53800
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 53814
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 53824
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 53832
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 53846
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 53866
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 53888
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 53900
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 53906
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 53916
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 53922
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 53938
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 53946
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 53960
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 53972
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 53982
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 53994
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 54012
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 54032
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 54048
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 54066
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 60628
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 60644
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 60662
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 60682
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 60702
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 60714
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 60724
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 60732
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 60746
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 60756
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 60770
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 60778
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 60792
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 60800
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 60816
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 60834
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 60854
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 60872
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 60890
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 60912
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 60924
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 60936
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 60948
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 60958
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 60968
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 60982
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 60996
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 32774
    Source: global trafficTCP traffic: 45.95.169.139 ports 17244,9372,2,3,7,9
    Source: global trafficTCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
    Source: global trafficTCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
    Source: global trafficTCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
    Source: global trafficTCP traffic: 192.168.2.23:39008 -> 45.95.169.139:9372
    Source: /tmp/shAwKMD85K (PID: 6239)Socket: 0.0.0.0::23
    Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443
    Source: unknownTCP traffic detected without corresponding DNS query: 194.156.189.65
    Source: unknownTCP traffic detected without corresponding DNS query: 141.20.85.65
    Source: unknownTCP traffic detected without corresponding DNS query: 194.245.158.69
    Source: unknownTCP traffic detected without corresponding DNS query: 103.96.209.65
    Source: unknownTCP traffic detected without corresponding DNS query: 181.208.1.221
    Source: unknownTCP traffic detected without corresponding DNS query: 114.8.240.128
    Source: unknownTCP traffic detected without corresponding DNS query: 83.35.133.32
    Source: unknownTCP traffic detected without corresponding DNS query: 144.9.72.233
    Source: unknownTCP traffic detected without corresponding DNS query: 181.178.20.236
    Source: unknownTCP traffic detected without corresponding DNS query: 140.195.233.234
    Source: unknownTCP traffic detected without corresponding DNS query: 180.173.150.183
    Source: unknownTCP traffic detected without corresponding DNS query: 28.24.156.119
    Source: unknownTCP traffic detected without corresponding DNS query: 12.241.246.22
    Source: unknownTCP traffic detected without corresponding DNS query: 96.116.137.210
    Source: unknownTCP traffic detected without corresponding DNS query: 152.56.21.23
    Source: unknownTCP traffic detected without corresponding DNS query: 246.186.28.56
    Source: unknownTCP traffic detected without corresponding DNS query: 171.178.159.27
    Source: unknownTCP traffic detected without corresponding DNS query: 220.244.29.31
    Source: unknownTCP traffic detected without corresponding DNS query: 80.99.200.10
    Source: unknownTCP traffic detected without corresponding DNS query: 81.0.246.54
    Source: unknownTCP traffic detected without corresponding DNS query: 62.117.198.20
    Source: unknownTCP traffic detected without corresponding DNS query: 212.14.185.185
    Source: unknownTCP traffic detected without corresponding DNS query: 108.101.134.238
    Source: unknownTCP traffic detected without corresponding DNS query: 196.169.98.41
    Source: unknownTCP traffic detected without corresponding DNS query: 163.6.218.171
    Source: unknownTCP traffic detected without corresponding DNS query: 167.118.252.130
    Source: unknownTCP traffic detected without corresponding DNS query: 244.40.132.89
    Source: unknownTCP traffic detected without corresponding DNS query: 165.67.34.79
    Source: unknownTCP traffic detected without corresponding DNS query: 66.186.117.133
    Source: unknownTCP traffic detected without corresponding DNS query: 121.221.93.12
    Source: unknownTCP traffic detected without corresponding DNS query: 40.182.92.158
    Source: unknownTCP traffic detected without corresponding DNS query: 48.137.15.209
    Source: unknownTCP traffic detected without corresponding DNS query: 71.40.177.108
    Source: unknownTCP traffic detected without corresponding DNS query: 133.102.245.142
    Source: unknownTCP traffic detected without corresponding DNS query: 16.232.69.155
    Source: unknownTCP traffic detected without corresponding DNS query: 51.123.209.80
    Source: unknownTCP traffic detected without corresponding DNS query: 193.109.103.86
    Source: unknownTCP traffic detected without corresponding DNS query: 201.125.108.181
    Source: unknownTCP traffic detected without corresponding DNS query: 132.72.140.4
    Source: unknownTCP traffic detected without corresponding DNS query: 139.27.139.59
    Source: unknownTCP traffic detected without corresponding DNS query: 189.153.132.49
    Source: unknownTCP traffic detected without corresponding DNS query: 116.202.39.34
    Source: unknownTCP traffic detected without corresponding DNS query: 207.254.36.225
    Source: unknownTCP traffic detected without corresponding DNS query: 207.101.157.127
    Source: unknownTCP traffic detected without corresponding DNS query: 118.7.221.236
    Source: unknownTCP traffic detected without corresponding DNS query: 81.39.106.72
    Source: unknownTCP traffic detected without corresponding DNS query: 188.81.96.224
    Source: unknownTCP traffic detected without corresponding DNS query: 39.101.200.132
    Source: unknownTCP traffic detected without corresponding DNS query: 70.4.209.210
    Source: unknownTCP traffic detected without corresponding DNS query: 211.36.92.160

    System Summary

    barindex
    Source: /tmp/shAwKMD85K (PID: 6239)SIGKILL sent: pid: 658, result: successful
    Source: /tmp/shAwKMD85K (PID: 6239)SIGKILL sent: pid: 720, result: successful
    Source: /tmp/shAwKMD85K (PID: 6239)SIGKILL sent: pid: 759, result: successful
    Source: /tmp/shAwKMD85K (PID: 6239)SIGKILL sent: pid: 772, result: successful
    Source: /tmp/shAwKMD85K (PID: 6239)SIGKILL sent: pid: 789, result: successful
    Source: /tmp/shAwKMD85K (PID: 6239)SIGKILL sent: pid: 800, result: successful
    Source: /tmp/shAwKMD85K (PID: 6239)SIGKILL sent: pid: 904, result: successful
    Source: /tmp/shAwKMD85K (PID: 6239)SIGKILL sent: pid: 936, result: successful
    Source: /tmp/shAwKMD85K (PID: 6239)SIGKILL sent: pid: 1320, result: successful
    Source: /tmp/shAwKMD85K (PID: 6239)SIGKILL sent: pid: 1334, result: successful
    Source: /tmp/shAwKMD85K (PID: 6239)SIGKILL sent: pid: 1335, result: successful
    Source: /tmp/shAwKMD85K (PID: 6239)SIGKILL sent: pid: 1389, result: successful
    Source: /tmp/shAwKMD85K (PID: 6239)SIGKILL sent: pid: 1463, result: successful
    Source: /tmp/shAwKMD85K (PID: 6239)SIGKILL sent: pid: 1465, result: successful
    Source: /tmp/shAwKMD85K (PID: 6239)SIGKILL sent: pid: 1576, result: successful
    Source: /tmp/shAwKMD85K (PID: 6239)SIGKILL sent: pid: 1809, result: successful
    Source: /tmp/shAwKMD85K (PID: 6239)SIGKILL sent: pid: 1872, result: successful
    Source: /tmp/shAwKMD85K (PID: 6239)SIGKILL sent: pid: 1888, result: successful
    Source: /tmp/shAwKMD85K (PID: 6239)SIGKILL sent: pid: 1890, result: successful
    Source: /tmp/shAwKMD85K (PID: 6239)SIGKILL sent: pid: 1983, result: successful
    Source: /tmp/shAwKMD85K (PID: 6239)SIGKILL sent: pid: 2048, result: successful
    Source: /tmp/shAwKMD85K (PID: 6239)SIGKILL sent: pid: 2062, result: successful
    Source: /tmp/shAwKMD85K (PID: 6239)SIGKILL sent: pid: 6039, result: successful
    Source: /tmp/shAwKMD85K (PID: 6239)SIGKILL sent: pid: 6192, result: successful
    Source: /tmp/shAwKMD85K (PID: 6239)SIGKILL sent: pid: 6234, result: successful
    Source: /tmp/shAwKMD85K (PID: 6239)SIGKILL sent: pid: 6243, result: successful
    Source: ELF static info symbol of initial sample.symtab present: no
    Source: /tmp/shAwKMD85K (PID: 6239)SIGKILL sent: pid: 658, result: successful
    Source: /tmp/shAwKMD85K (PID: 6239)SIGKILL sent: pid: 720, result: successful
    Source: /tmp/shAwKMD85K (PID: 6239)SIGKILL sent: pid: 759, result: successful
    Source: /tmp/shAwKMD85K (PID: 6239)SIGKILL sent: pid: 772, result: successful
    Source: /tmp/shAwKMD85K (PID: 6239)SIGKILL sent: pid: 789, result: successful
    Source: /tmp/shAwKMD85K (PID: 6239)SIGKILL sent: pid: 800, result: successful
    Source: /tmp/shAwKMD85K (PID: 6239)SIGKILL sent: pid: 904, result: successful
    Source: /tmp/shAwKMD85K (PID: 6239)SIGKILL sent: pid: 936, result: successful
    Source: /tmp/shAwKMD85K (PID: 6239)SIGKILL sent: pid: 1320, result: successful
    Source: /tmp/shAwKMD85K (PID: 6239)SIGKILL sent: pid: 1334, result: successful
    Source: /tmp/shAwKMD85K (PID: 6239)SIGKILL sent: pid: 1335, result: successful
    Source: /tmp/shAwKMD85K (PID: 6239)SIGKILL sent: pid: 1389, result: successful
    Source: /tmp/shAwKMD85K (PID: 6239)SIGKILL sent: pid: 1463, result: successful
    Source: /tmp/shAwKMD85K (PID: 6239)SIGKILL sent: pid: 1465, result: successful
    Source: /tmp/shAwKMD85K (PID: 6239)SIGKILL sent: pid: 1576, result: successful
    Source: /tmp/shAwKMD85K (PID: 6239)SIGKILL sent: pid: 1809, result: successful
    Source: /tmp/shAwKMD85K (PID: 6239)SIGKILL sent: pid: 1872, result: successful
    Source: /tmp/shAwKMD85K (PID: 6239)SIGKILL sent: pid: 1888, result: successful
    Source: /tmp/shAwKMD85K (PID: 6239)SIGKILL sent: pid: 1890, result: successful
    Source: /tmp/shAwKMD85K (PID: 6239)SIGKILL sent: pid: 1983, result: successful
    Source: /tmp/shAwKMD85K (PID: 6239)SIGKILL sent: pid: 2048, result: successful
    Source: /tmp/shAwKMD85K (PID: 6239)SIGKILL sent: pid: 2062, result: successful
    Source: /tmp/shAwKMD85K (PID: 6239)SIGKILL sent: pid: 6039, result: successful
    Source: /tmp/shAwKMD85K (PID: 6239)SIGKILL sent: pid: 6192, result: successful
    Source: /tmp/shAwKMD85K (PID: 6239)SIGKILL sent: pid: 6234, result: successful
    Source: /tmp/shAwKMD85K (PID: 6239)SIGKILL sent: pid: 6243, result: successful
    Source: classification engineClassification label: mal68.spre.troj.lin@0/0@0/0
    Source: /tmp/shAwKMD85K (PID: 6239)File opened: /proc/6234/exe
    Source: /tmp/shAwKMD85K (PID: 6239)File opened: /proc/1582/exe
    Source: /tmp/shAwKMD85K (PID: 6239)File opened: /proc/2033/exe
    Source: /tmp/shAwKMD85K (PID: 6239)File opened: /proc/2275/exe
    Source: /tmp/shAwKMD85K (PID: 6239)File opened: /proc/3088/exe
    Source: /tmp/shAwKMD85K (PID: 6239)File opened: /proc/6193/exe
    Source: /tmp/shAwKMD85K (PID: 6239)File opened: /proc/6192/exe
    Source: /tmp/shAwKMD85K (PID: 6239)File opened: /proc/1612/exe
    Source: /tmp/shAwKMD85K (PID: 6239)File opened: /proc/1579/exe
    Source: /tmp/shAwKMD85K (PID: 6239)File opened: /proc/1699/exe
    Source: /tmp/shAwKMD85K (PID: 6239)File opened: /proc/1335/exe
    Source: /tmp/shAwKMD85K (PID: 6239)File opened: /proc/1698/exe
    Source: /tmp/shAwKMD85K (PID: 6239)File opened: /proc/2028/exe
    Source: /tmp/shAwKMD85K (PID: 6239)File opened: /proc/1334/exe
    Source: /tmp/shAwKMD85K (PID: 6239)File opened: /proc/1576/exe
    Source: /tmp/shAwKMD85K (PID: 6239)File opened: /proc/2302/exe
    Source: /tmp/shAwKMD85K (PID: 6239)File opened: /proc/3236/exe
    Source: /tmp/shAwKMD85K (PID: 6239)File opened: /proc/2025/exe
    Source: /tmp/shAwKMD85K (PID: 6239)File opened: /proc/2146/exe
    Source: /tmp/shAwKMD85K (PID: 6239)File opened: /proc/910/exe
    Source: /tmp/shAwKMD85K (PID: 6239)File opened: /proc/912/exe
    Source: /tmp/shAwKMD85K (PID: 6239)File opened: /proc/517/exe
    Source: /tmp/shAwKMD85K (PID: 6239)File opened: /proc/759/exe
    Source: /tmp/shAwKMD85K (PID: 6239)File opened: /proc/2307/exe
    Source: /tmp/shAwKMD85K (PID: 6239)File opened: /proc/918/exe
    Source: /tmp/shAwKMD85K (PID: 6239)File opened: /proc/6243/exe
    Source: /tmp/shAwKMD85K (PID: 6239)File opened: /proc/4465/exe
    Source: /tmp/shAwKMD85K (PID: 6239)File opened: /proc/1594/exe
    Source: /tmp/shAwKMD85K (PID: 6239)File opened: /proc/2285/exe
    Source: /tmp/shAwKMD85K (PID: 6239)File opened: /proc/2281/exe
    Source: /tmp/shAwKMD85K (PID: 6239)File opened: /proc/1349/exe
    Source: /tmp/shAwKMD85K (PID: 6239)File opened: /proc/1623/exe
    Source: /tmp/shAwKMD85K (PID: 6239)File opened: /proc/761/exe
    Source: /tmp/shAwKMD85K (PID: 6239)File opened: /proc/1622/exe
    Source: /tmp/shAwKMD85K (PID: 6239)File opened: /proc/884/exe
    Source: /tmp/shAwKMD85K (PID: 6239)File opened: /proc/1983/exe
    Source: /tmp/shAwKMD85K (PID: 6239)File opened: /proc/2038/exe
    Source: /tmp/shAwKMD85K (PID: 6239)File opened: /proc/1344/exe
    Source: /tmp/shAwKMD85K (PID: 6239)File opened: /proc/1465/exe
    Source: /tmp/shAwKMD85K (PID: 6239)File opened: /proc/1586/exe
    Source: /tmp/shAwKMD85K (PID: 6239)File opened: /proc/1463/exe
    Source: /tmp/shAwKMD85K (PID: 6239)File opened: /proc/2156/exe
    Source: /tmp/shAwKMD85K (PID: 6239)File opened: /proc/800/exe
    Source: /tmp/shAwKMD85K (PID: 6239)File opened: /proc/801/exe
    Source: /tmp/shAwKMD85K (PID: 6239)File opened: /proc/6116/exe
    Source: /tmp/shAwKMD85K (PID: 6239)File opened: /proc/1629/exe
    Source: /tmp/shAwKMD85K (PID: 6239)File opened: /proc/1627/exe
    Source: /tmp/shAwKMD85K (PID: 6239)File opened: /proc/1900/exe
    Source: /tmp/shAwKMD85K (PID: 6239)File opened: /proc/3021/exe
    Source: /tmp/shAwKMD85K (PID: 6239)File opened: /proc/491/exe
    Source: /tmp/shAwKMD85K (PID: 6239)File opened: /proc/2294/exe
    Source: /tmp/shAwKMD85K (PID: 6239)File opened: /proc/2050/exe
    Source: /tmp/shAwKMD85K (PID: 6239)File opened: /proc/1877/exe
    Source: /tmp/shAwKMD85K (PID: 6239)File opened: /proc/772/exe
    Source: /tmp/shAwKMD85K (PID: 6239)File opened: /proc/1633/exe
    Source: /tmp/shAwKMD85K (PID: 6239)File opened: /proc/1599/exe
    Source: /tmp/shAwKMD85K (PID: 6239)File opened: /proc/1632/exe
    Source: /tmp/shAwKMD85K (PID: 6239)File opened: /proc/774/exe
    Source: /tmp/shAwKMD85K (PID: 6239)File opened: /proc/1477/exe
    Source: /tmp/shAwKMD85K (PID: 6239)File opened: /proc/654/exe
    Source: /tmp/shAwKMD85K (PID: 6239)File opened: /proc/896/exe
    Source: /tmp/shAwKMD85K (PID: 6239)File opened: /proc/1476/exe
    Source: /tmp/shAwKMD85K (PID: 6239)File opened: /proc/1872/exe
    Source: /tmp/shAwKMD85K (PID: 6239)File opened: /proc/2048/exe
    Source: /tmp/shAwKMD85K (PID: 6239)File opened: /proc/655/exe
    Source: /tmp/shAwKMD85K (PID: 6239)File opened: /proc/1475/exe
    Source: /tmp/shAwKMD85K (PID: 6239)File opened: /proc/2289/exe
    Source: /tmp/shAwKMD85K (PID: 6239)File opened: /proc/656/exe
    Source: /tmp/shAwKMD85K (PID: 6239)File opened: /proc/777/exe
    Source: /tmp/shAwKMD85K (PID: 6239)File opened: /proc/657/exe
    Source: /tmp/shAwKMD85K (PID: 6239)File opened: /proc/4466/exe
    Source: /tmp/shAwKMD85K (PID: 6239)File opened: /proc/658/exe
    Source: /tmp/shAwKMD85K (PID: 6239)File opened: /proc/4467/exe
    Source: /tmp/shAwKMD85K (PID: 6239)File opened: /proc/4468/exe
    Source: /tmp/shAwKMD85K (PID: 6239)File opened: /proc/419/exe
    Source: /tmp/shAwKMD85K (PID: 6239)File opened: /proc/936/exe
    Source: /tmp/shAwKMD85K (PID: 6239)File opened: /proc/1639/exe
    Source: /tmp/shAwKMD85K (PID: 6239)File opened: /proc/1638/exe
    Source: /tmp/shAwKMD85K (PID: 6239)File opened: /proc/2208/exe
    Source: /tmp/shAwKMD85K (PID: 6239)File opened: /proc/2180/exe
    Source: /tmp/shAwKMD85K (PID: 6239)File opened: /proc/1809/exe
    Source: /tmp/shAwKMD85K (PID: 6239)File opened: /proc/1494/exe
    Source: /tmp/shAwKMD85K (PID: 6239)File opened: /proc/1890/exe
    Source: /tmp/shAwKMD85K (PID: 6239)File opened: /proc/2063/exe
    Source: /tmp/shAwKMD85K (PID: 6239)File opened: /proc/2062/exe
    Source: /tmp/shAwKMD85K (PID: 6239)File opened: /proc/1888/exe
    Source: /tmp/shAwKMD85K (PID: 6239)File opened: /proc/1886/exe
    Source: /tmp/shAwKMD85K (PID: 6239)File opened: /proc/420/exe
    Source: /tmp/shAwKMD85K (PID: 6239)File opened: /proc/1489/exe
    Source: /tmp/shAwKMD85K (PID: 6239)File opened: /proc/785/exe
    Source: /tmp/shAwKMD85K (PID: 6239)File opened: /proc/1642/exe
    Source: /tmp/shAwKMD85K (PID: 6239)File opened: /proc/788/exe
    Source: /tmp/shAwKMD85K (PID: 6239)File opened: /proc/667/exe
    Source: /tmp/shAwKMD85K (PID: 6239)File opened: /proc/789/exe
    Source: /tmp/shAwKMD85K (PID: 6239)File opened: /proc/1648/exe
    Source: /tmp/shAwKMD85K (PID: 6239)File opened: /proc/6157/exe
    Source: /tmp/shAwKMD85K (PID: 6239)File opened: /proc/6310/exe
    Source: /tmp/shAwKMD85K (PID: 6239)File opened: /proc/4498/exe
    Source: /tmp/shAwKMD85K (PID: 6239)File opened: /proc/2078/exe
    Source: /tmp/shAwKMD85K (PID: 6239)File opened: /proc/2077/exe
    Source: /tmp/shAwKMD85K (PID: 6239)File opened: /proc/2074/exe
    Source: /tmp/shAwKMD85K (PID: 6239)File opened: /proc/2195/exe
    Source: /tmp/shAwKMD85K (PID: 6239)File opened: /proc/670/exe
    Source: /tmp/shAwKMD85K (PID: 6239)File opened: /proc/2746/exe
    Source: /tmp/shAwKMD85K (PID: 6239)File opened: /proc/793/exe

    Hooking and other Techniques for Hiding and Protection

    barindex
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57286
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57292
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57300
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57306
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57314
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57320
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57330
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57336
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57342
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57348
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57354
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57360
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57366
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57372
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57376
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57378
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57384
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57386
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57388
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57390
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57392
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57398
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57400
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57402
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57406
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57410
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57428
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57456
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 53624
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 53634
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 53646
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 53658
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 53686
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 53726
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 53770
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 53800
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 53814
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 53824
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 53832
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 53846
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 53866
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 53888
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 53900
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 53906
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 53916
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 53922
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 53938
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 53946
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 53960
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 53972
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 53982
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 53994
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 54012
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 54032
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 54048
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 54066
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 60628
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 60644
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 60662
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 60682
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 60702
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 60714
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 60724
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 60732
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 60746
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 60756
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 60770
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 60778
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 60792
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 60800
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 60816
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 60834
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 60854
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 60872
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 60890
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 60912
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 60924
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 60936
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 60948
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 60958
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 60968
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 60982
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 60996
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 32774
    Source: /tmp/shAwKMD85K (PID: 6232)Queries kernel information via 'uname':
    Source: shAwKMD85K, 6232.1.00000000a1b01e61.00000000e0dd4486.rw-.sdmp, shAwKMD85K, 6234.1.00000000a1b01e61.00000000e0dd4486.rw-.sdmp, shAwKMD85K, 6310.1.00000000a1b01e61.00000000e0dd4486.rw-.sdmp, shAwKMD85K, 6235.1.00000000a1b01e61.00000000e0dd4486.rw-.sdmp, shAwKMD85K, 6241.1.00000000a1b01e61.00000000e0dd4486.rw-.sdmp, shAwKMD85K, 6243.1.00000000a1b01e61.00000000e0dd4486.rw-.sdmpBinary or memory string: r}x86_64/usr/bin/qemu-sh4/tmp/shAwKMD85KSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/shAwKMD85K
    Source: shAwKMD85K, 6232.1.00000000a1b01e61.00000000e0dd4486.rw-.sdmp, shAwKMD85K, 6234.1.00000000a1b01e61.00000000e0dd4486.rw-.sdmp, shAwKMD85K, 6310.1.00000000a1b01e61.00000000e0dd4486.rw-.sdmp, shAwKMD85K, 6235.1.00000000a1b01e61.00000000e0dd4486.rw-.sdmp, shAwKMD85K, 6241.1.00000000a1b01e61.00000000e0dd4486.rw-.sdmp, shAwKMD85K, 6243.1.00000000a1b01e61.00000000e0dd4486.rw-.sdmpBinary or memory string: /usr/bin/qemu-sh4
    Source: shAwKMD85K, 6232.1.00000000d75652a9.000000006ca34ec5.rw-.sdmp, shAwKMD85K, 6234.1.00000000d75652a9.000000006ca34ec5.rw-.sdmp, shAwKMD85K, 6310.1.00000000d75652a9.000000006ca34ec5.rw-.sdmp, shAwKMD85K, 6235.1.00000000d75652a9.000000006ca34ec5.rw-.sdmp, shAwKMD85K, 6241.1.00000000d75652a9.000000006ca34ec5.rw-.sdmp, shAwKMD85K, 6243.1.00000000d75652a9.000000006ca34ec5.rw-.sdmpBinary or memory string: U5!/etc/qemu-binfmt/sh4
    Source: shAwKMD85K, 6232.1.00000000d75652a9.000000006ca34ec5.rw-.sdmp, shAwKMD85K, 6234.1.00000000d75652a9.000000006ca34ec5.rw-.sdmp, shAwKMD85K, 6310.1.00000000d75652a9.000000006ca34ec5.rw-.sdmp, shAwKMD85K, 6235.1.00000000d75652a9.000000006ca34ec5.rw-.sdmp, shAwKMD85K, 6241.1.00000000d75652a9.000000006ca34ec5.rw-.sdmp, shAwKMD85K, 6243.1.00000000d75652a9.000000006ca34ec5.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/sh4

    Stealing of Sensitive Information

    barindex
    Source: Yara matchFile source: dump.pcap, type: PCAP

    Remote Access Functionality

    barindex
    Source: Yara matchFile source: dump.pcap, type: PCAP
    Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
    Valid AccountsWindows Management InstrumentationPath InterceptionPath InterceptionDirect Volume Access1
    OS Credential Dumping
    11
    Security Software Discovery
    Remote ServicesData from Local SystemExfiltration Over Other Network Medium1
    Encrypted Channel
    Eavesdrop on Insecure Network CommunicationRemotely Track Device Without Authorization1
    Service Stop
    Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over Bluetooth11
    Non-Standard Port
    Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
    Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated Exfiltration1
    Application Layer Protocol
    Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
    No configs have been found
    Hide Legend

    Legend:

    • Process
    • Signature
    • Created File
    • DNS/IP Info
    • Is Dropped
    • Number of created Files
    • Is malicious
    • Internet
    behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 635419 Sample: shAwKMD85K Startdate: 27/05/2022 Architecture: LINUX Score: 68 24 197.191.38.224 zain-asGH Ghana 2->24 26 196.154.22.45 Vodafone-EG Egypt 2->26 28 98 other IPs or domains 2->28 30 Multi AV Scanner detection for submitted file 2->30 32 Yara detected Mirai 2->32 34 Connects to many ports of the same IP (likely port scanning) 2->34 36 Uses known network protocols on non-standard ports 2->36 9 shAwKMD85K 2->9         started        signatures3 process4 process5 11 shAwKMD85K 9->11         started        13 shAwKMD85K 9->13         started        process6 15 shAwKMD85K 11->15         started        18 shAwKMD85K 11->18         started        20 shAwKMD85K 13->20         started        signatures7 38 Sample tries to kill multiple processes (SIGKILL) 15->38 22 shAwKMD85K 18->22         started        process8
    SourceDetectionScannerLabelLink
    shAwKMD85K44%VirustotalBrowse
    shAwKMD85K41%ReversingLabsLinux.Trojan.Mirai
    No Antivirus matches
    No Antivirus matches
    No Antivirus matches
    No contacted domains info
    • No. of IPs < 25%
    • 25% < No. of IPs < 50%
    • 50% < No. of IPs < 75%
    • 75% < No. of IPs
    IPDomainCountryFlagASNASN NameMalicious
    136.254.214.133
    unknownUnited States
    72SCHLUMBERGER-ASUSfalse
    28.228.21.175
    unknownUnited States
    7922COMCAST-7922USfalse
    195.29.138.1
    unknownCroatia (LOCAL Name: Hrvatska)
    5391T-HTCroatianTelecomIncHRfalse
    174.70.114.79
    unknownUnited States
    22773ASN-CXA-ALL-CCI-22773-RDCUSfalse
    53.59.26.92
    unknownGermany
    31399DAIMLER-ASITIGNGlobalNetworkDEfalse
    192.56.173.43
    unknownUnited States
    20804ASN-TELENERGOulPERKUNA47WARSZAWAPLfalse
    248.201.75.77
    unknownReserved
    unknownunknownfalse
    194.67.57.227
    unknownRussian Federation
    3216SOVAM-ASRUfalse
    119.162.54.226
    unknownChina
    4837CHINA169-BACKBONECHINAUNICOMChina169BackboneCNfalse
    199.163.235.129
    unknownUnited States
    4152USDA-1USfalse
    23.117.172.126
    unknownUnited States
    7018ATT-INTERNET4USfalse
    150.205.154.182
    unknownSwitzerland
    786JANETJiscServicesLimitedGBfalse
    6.212.101.86
    unknownUnited States
    3356LEVEL3USfalse
    54.138.90.26
    unknownUnited States
    14618AMAZON-AESUSfalse
    248.213.170.174
    unknownReserved
    unknownunknownfalse
    160.226.233.205
    unknownSouth Africa
    37542Iclix-CCZAfalse
    86.126.4.50
    unknownRomania
    8708RCS-RDS73-75DrStaicoviciROfalse
    253.14.220.175
    unknownReserved
    unknownunknownfalse
    198.242.181.154
    unknownUnited States
    174COGENT-174USfalse
    195.133.157.153
    unknownRussian Federation
    48347MTW-ASRUfalse
    68.207.70.127
    unknownUnited States
    11427TWC-11427-TEXASUSfalse
    126.214.54.224
    unknownJapan17676GIGAINFRASoftbankBBCorpJPfalse
    104.189.55.132
    unknownUnited States
    7018ATT-INTERNET4USfalse
    183.186.246.100
    unknownChina
    4837CHINA169-BACKBONECHINAUNICOMChina169BackboneCNfalse
    125.171.111.182
    unknownChina
    4134CHINANET-BACKBONENo31Jin-rongStreetCNfalse
    51.236.88.62
    unknownUnited States
    2686ATGS-MMD-ASUSfalse
    205.103.66.165
    unknownUnited States
    721DNIC-ASBLK-00721-00726USfalse
    98.81.120.23
    unknownUnited States
    11351TWC-11351-NORTHEASTUSfalse
    175.74.138.216
    unknownChina
    9394CTTNETChinaTieTongTelecommunicationsCorporationCNfalse
    118.167.170.25
    unknownTaiwan; Republic of China (ROC)
    3462HINETDataCommunicationBusinessGroupTWfalse
    104.150.9.208
    unknownUnited States
    1832SMUUSfalse
    136.138.233.92
    unknownUnited States
    60311ONEFMCHfalse
    172.212.107.176
    unknownUnited States
    18747IFX18747USfalse
    18.30.220.199
    unknownUnited States
    3MIT-GATEWAYSUSfalse
    79.85.94.147
    unknownFrance
    15557LDCOMNETFRfalse
    77.19.124.193
    unknownNorway
    2119TELENOR-NEXTELTelenorNorgeASNOfalse
    177.159.140.161
    unknownBrazil
    10429TELEFONICABRASILSABRfalse
    81.43.163.136
    unknownSpain
    3352TELEFONICA_DE_ESPANAESfalse
    161.152.221.235
    unknownAustralia
    9328DATACOM-AUDATACOMSYSTEMSAUPTYLTDAUfalse
    169.246.49.42
    unknownUnited States
    557UMAINE-SYS-ASUSfalse
    144.73.195.181
    unknownUnited States
    14349KCPLASN-1USfalse
    221.20.125.203
    unknownJapan17676GIGAINFRASoftbankBBCorpJPfalse
    177.44.205.251
    unknownBrazil
    262907AVATOTECNOLOGIABRfalse
    3.164.141.135
    unknownUnited States
    16509AMAZON-02USfalse
    150.135.225.41
    unknownUnited States
    1706UNIV-ARIZUSfalse
    159.178.244.61
    unknownUnited States
    6356NERDCNETUSfalse
    164.137.126.173
    unknownUnited Kingdom
    3303SWISSCOMSwisscomSwitzerlandLtdCHfalse
    184.226.57.208
    unknownUnited States
    10507SPCSUSfalse
    40.57.240.237
    unknownUnited States
    4249LILLY-ASUSfalse
    137.55.229.174
    unknownNetherlands
    225VIRGINIA-ASUSfalse
    89.126.163.87
    unknownIreland
    25441IBIS-ASImagineGroupLtdIEfalse
    75.35.144.106
    unknownUnited States
    7018ATT-INTERNET4USfalse
    210.27.170.113
    unknownChina
    4538ERX-CERNET-BKBChinaEducationandResearchNetworkCenterfalse
    3.221.46.249
    unknownUnited States
    14618AMAZON-AESUSfalse
    197.191.38.224
    unknownGhana
    37140zain-asGHfalse
    164.184.8.109
    unknownUnited States
    37717EL-KhawarizmiTNfalse
    15.246.89.191
    unknownUnited States
    71HP-INTERNET-ASUSfalse
    219.205.35.16
    unknownJapan17676GIGAINFRASoftbankBBCorpJPfalse
    218.148.64.29
    unknownKorea Republic of
    4766KIXS-AS-KRKoreaTelecomKRfalse
    166.130.159.187
    unknownUnited States
    20057ATT-MOBILITY-LLC-AS20057USfalse
    49.239.222.105
    unknownChina
    58834GCABLENETGuangdongCableCorporationLimitedCNfalse
    60.186.225.144
    unknownChina
    4134CHINANET-BACKBONENo31Jin-rongStreetCNfalse
    201.43.5.197
    unknownBrazil
    27699TELEFONICABRASILSABRfalse
    86.93.169.12
    unknownNetherlands
    1136KPNKPNNationalEUfalse
    180.68.95.71
    unknownKorea Republic of
    9318SKB-ASSKBroadbandCoLtdKRfalse
    105.143.188.13
    unknownMorocco
    6713IAM-ASMAfalse
    108.194.245.34
    unknownUnited States
    7018ATT-INTERNET4USfalse
    29.103.97.167
    unknownUnited States
    7922COMCAST-7922USfalse
    150.97.135.253
    unknownJapan2907SINET-ASResearchOrganizationofInformationandSystemsNfalse
    92.63.171.7
    unknownNetherlands
    48635ASTRALUSNLfalse
    180.131.171.17
    unknownHong Kong
    9304HUTCHISON-AS-APHGCGlobalCommunicationsLimitedHKfalse
    59.213.224.239
    unknownChina
    2516KDDIKDDICORPORATIONJPfalse
    118.82.150.187
    unknownNew Zealand
    55872BAYCITY-AS-APBayCityCommunicationsLimitedNZfalse
    165.239.233.2
    unknownUnited States
    11663SUG-1USfalse
    201.19.125.109
    unknownBrazil
    7738TelemarNorteLesteSABRfalse
    196.233.130.47
    unknownTunisia
    37492ORANGE-TNfalse
    66.67.247.157
    unknownUnited States
    11351TWC-11351-NORTHEASTUSfalse
    100.154.190.21
    unknownUnited States
    21928T-MOBILE-AS21928USfalse
    190.239.136.114
    unknownPeru
    6147TelefonicadelPeruSAAPEfalse
    91.0.219.10
    unknownGermany
    3320DTAGInternetserviceprovideroperationsDEfalse
    144.192.204.109
    unknownUnited States
    58541CHINATELECOM-SHANDONG-QINGDAO-IDCQingdao266000CNfalse
    188.2.186.193
    unknownSerbia
    31042SERBIA-BROADBAND-ASSerbiaBroadBand-SrpskeKablovskemrezefalse
    253.81.9.10
    unknownReserved
    unknownunknownfalse
    50.49.184.122
    unknownUnited States
    7011FRONTIER-AND-CITIZENSUSfalse
    167.248.94.90
    unknownUnited States
    209CENTURYLINK-US-LEGACY-QWESTUSfalse
    41.125.243.153
    unknownSouth Africa
    16637MTNNS-ASZAfalse
    4.69.47.250
    unknownUnited States
    3356LEVEL3USfalse
    39.6.249.2
    unknownKorea Republic of
    4766KIXS-AS-KRKoreaTelecomKRfalse
    188.131.137.206
    unknownChina
    45090CNNIC-TENCENT-NET-APShenzhenTencentComputerSystemsCompafalse
    141.192.80.40
    unknownFinland
    1342FujitsuInviaFinlandIP-networkEUfalse
    120.135.246.182
    unknownChina
    4835CHINANET-IDC-SNChinaTelecomGroupCNfalse
    150.84.99.173
    unknownJapan2907SINET-ASResearchOrganizationofInformationandSystemsNfalse
    84.218.165.36
    unknownSweden
    2119TELENOR-NEXTELTelenorNorgeASNOfalse
    37.12.240.43
    unknownSpain
    3352TELEFONICA_DE_ESPANAESfalse
    158.16.70.229
    unknownUnited States
    1504DNIC-AS-01504USfalse
    196.154.22.45
    unknownEgypt
    36935Vodafone-EGfalse
    202.235.239.206
    unknownJapan4686BEKKOAMEBEKKOAMEINTERNETINCJPfalse
    211.91.48.181
    unknownChina
    4837CHINA169-BACKBONECHINAUNICOMChina169BackboneCNfalse
    28.216.162.76
    unknownUnited States
    7922COMCAST-7922USfalse
    143.153.23.32
    unknownUnited States
    385AFCONC-BLOCK1-ASUSfalse
    No context
    No context
    No context
    No context
    No context
    No created / dropped files found
    File type:ELF 32-bit LSB executable, Renesas SH, version 1 (SYSV), statically linked, stripped
    Entropy (8bit):6.850028202347492
    TrID:
    • ELF Executable and Linkable format (generic) (4004/1) 100.00%
    File name:shAwKMD85K
    File size:71048
    MD5:e0c4f532b0a9fda3ee7d800775deb908
    SHA1:63f144f5b1f316e34510f15d4f93c3fc41d0b73e
    SHA256:aa18cc657da907f749d8bf4aae9867152acc7320f518aa1f9a33bba195e19328
    SHA512:ab7823425c62434dce0c8ad2f68869c1c35a2bb870dd1cdc854eea105f89992e57ab51c1e66ac10840ced143bc81fce04b22454a82312704c84064a72099c2a7
    SSDEEP:1536:5ce4L4A9NKgIBiZeCjvhCRKbo9YlE9zXTVmAv6fED:5OlzKxTCjvhpbuYfK
    TLSH:67637B32EC762E44D11A8AB2B4F0DE349363944096476EFD95A2C7A99043FCDF61A3F4
    File Content Preview:.ELF..............*.......@.4...........4. ...(...............@...@...........................B...B......f..........Q.td............................././"O.n........#.*@........#.*@,....o&O.n...l..............................././.../.a"O.!...n...a.b("...q.

    ELF header

    Class:ELF32
    Data:2's complement, little endian
    Version:1 (current)
    Machine:<unknown>
    Version Number:0x1
    Type:EXEC (Executable file)
    OS/ABI:UNIX - System V
    ABI Version:0
    Entry Point Address:0x4001a0
    Flags:0x9
    ELF Header Size:52
    Program Header Offset:52
    Program Header Size:32
    Number of Program Headers:3
    Section Header Offset:70648
    Section Header Size:40
    Number of Section Headers:10
    Header String Table Index:9
    NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
    NULL0x00x00x00x00x0000
    .initPROGBITS0x4000940x940x300x00x6AX004
    .textPROGBITS0x4000e00xe00xf1400x00x6AX0032
    .finiPROGBITS0x40f2200xf2200x240x00x6AX004
    .rodataPROGBITS0x40f2440xf2440x1d480x00x2A004
    .ctorsPROGBITS0x4210000x110000x80x00x3WA004
    .dtorsPROGBITS0x4210080x110080x80x00x3WA004
    .dataPROGBITS0x4210140x110140x3a40x00x3WA004
    .bssNOBITS0x4213b80x113b80x631c0x00x3WA004
    .shstrtabSTRTAB0x00x113b80x3e0x00x0001
    TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
    LOAD0x00x4000000x4000000x10f8c0x10f8c4.73330x5R E0x10000.init .text .fini .rodata
    LOAD0x110000x4210000x4210000x3b80x66d41.72730x6RW 0x10000.ctors .dtors .data .bss
    GNU_STACK0x00x00x00x00x00.00000x7RWE0x4
    TimestampSource PortDest PortSource IPDest IP
    May 27, 2022 21:27:24.967916012 CEST3997023192.168.2.23194.156.189.65
    May 27, 2022 21:27:24.967936039 CEST3997023192.168.2.23141.20.85.65
    May 27, 2022 21:27:24.967966080 CEST3997023192.168.2.23194.245.158.69
    May 27, 2022 21:27:24.967963934 CEST3997023192.168.2.23103.96.209.65
    May 27, 2022 21:27:24.967993021 CEST3997023192.168.2.23181.208.1.221
    May 27, 2022 21:27:24.967998028 CEST3997023192.168.2.23249.210.251.211
    May 27, 2022 21:27:24.968000889 CEST3997023192.168.2.23114.8.240.128
    May 27, 2022 21:27:24.968002081 CEST3997023192.168.2.2383.35.133.32
    May 27, 2022 21:27:24.968009949 CEST3997023192.168.2.23144.9.72.233
    May 27, 2022 21:27:24.968019009 CEST3997023192.168.2.23181.178.20.236
    May 27, 2022 21:27:24.968025923 CEST3997023192.168.2.23140.195.233.234
    May 27, 2022 21:27:24.968025923 CEST3997023192.168.2.23180.173.150.183
    May 27, 2022 21:27:24.968028069 CEST3997023192.168.2.2328.24.156.119
    May 27, 2022 21:27:24.968029976 CEST3997023192.168.2.23209.3.110.90
    May 27, 2022 21:27:24.968031883 CEST3997023192.168.2.2312.241.246.22
    May 27, 2022 21:27:24.968043089 CEST3997023192.168.2.2396.116.137.210
    May 27, 2022 21:27:24.968050957 CEST3997023192.168.2.23152.56.21.23
    May 27, 2022 21:27:24.968050957 CEST3997023192.168.2.23246.186.28.56
    May 27, 2022 21:27:24.968055010 CEST3997023192.168.2.23171.178.159.27
    May 27, 2022 21:27:24.968055010 CEST3997023192.168.2.23220.244.29.31
    May 27, 2022 21:27:24.968060017 CEST3997023192.168.2.2380.99.200.10
    May 27, 2022 21:27:24.968063116 CEST3997023192.168.2.2381.0.246.54
    May 27, 2022 21:27:24.968070030 CEST3997023192.168.2.2362.117.198.20
    May 27, 2022 21:27:24.968070984 CEST3997023192.168.2.23212.14.185.185
    May 27, 2022 21:27:24.968077898 CEST3997023192.168.2.23108.101.134.238
    May 27, 2022 21:27:24.968081951 CEST3997023192.168.2.23196.169.98.41
    May 27, 2022 21:27:24.968100071 CEST3997023192.168.2.23163.6.218.171
    May 27, 2022 21:27:24.968102932 CEST3997023192.168.2.23167.118.252.130
    May 27, 2022 21:27:24.968121052 CEST3997023192.168.2.23244.40.132.89
    May 27, 2022 21:27:24.968126059 CEST3997023192.168.2.23165.67.34.79
    May 27, 2022 21:27:24.968131065 CEST3997023192.168.2.2366.186.117.133
    May 27, 2022 21:27:24.968131065 CEST3997023192.168.2.23121.221.93.12
    May 27, 2022 21:27:24.968132019 CEST3997023192.168.2.2340.182.92.158
    May 27, 2022 21:27:24.968137980 CEST3997023192.168.2.2348.137.15.209
    May 27, 2022 21:27:24.968146086 CEST3997023192.168.2.2371.40.177.108
    May 27, 2022 21:27:24.968146086 CEST3997023192.168.2.23133.102.245.142
    May 27, 2022 21:27:24.968149900 CEST3997023192.168.2.2316.232.69.155
    May 27, 2022 21:27:24.968162060 CEST3997023192.168.2.2351.123.209.80
    May 27, 2022 21:27:24.968170881 CEST3997023192.168.2.23193.109.103.86
    May 27, 2022 21:27:24.968179941 CEST3997023192.168.2.23201.125.108.181
    May 27, 2022 21:27:24.968182087 CEST3997023192.168.2.23132.72.140.4
    May 27, 2022 21:27:24.968188047 CEST3997023192.168.2.23139.27.139.59
    May 27, 2022 21:27:24.968190908 CEST3997023192.168.2.23189.153.132.49
    May 27, 2022 21:27:24.968198061 CEST3997023192.168.2.2310.90.214.237
    May 27, 2022 21:27:24.968197107 CEST3997023192.168.2.23116.202.39.34
    May 27, 2022 21:27:24.968199015 CEST3997023192.168.2.23207.254.36.225
    May 27, 2022 21:27:24.968202114 CEST3997023192.168.2.23207.101.157.127
    May 27, 2022 21:27:24.968206882 CEST3997023192.168.2.23118.7.221.236
    May 27, 2022 21:27:24.968208075 CEST3997023192.168.2.2381.39.106.72
    May 27, 2022 21:27:24.968230009 CEST3997023192.168.2.23188.81.96.224
    May 27, 2022 21:27:24.968240976 CEST3997023192.168.2.2339.101.200.132
    May 27, 2022 21:27:24.968245029 CEST3997023192.168.2.2370.4.209.210
    May 27, 2022 21:27:24.968247890 CEST3997023192.168.2.23211.36.92.160
    May 27, 2022 21:27:24.968249083 CEST3997023192.168.2.23116.170.33.202
    May 27, 2022 21:27:24.968265057 CEST3997023192.168.2.2355.86.175.216
    May 27, 2022 21:27:24.968266964 CEST3997023192.168.2.23112.46.210.180
    May 27, 2022 21:27:24.968274117 CEST3997023192.168.2.23213.135.102.82
    May 27, 2022 21:27:24.968282938 CEST3997023192.168.2.23205.70.105.77
    May 27, 2022 21:27:24.968285084 CEST3997023192.168.2.2362.1.120.216
    May 27, 2022 21:27:24.968288898 CEST3997023192.168.2.2327.237.103.210
    May 27, 2022 21:27:24.968291044 CEST3997023192.168.2.23170.212.255.146
    May 27, 2022 21:27:24.968291998 CEST3997023192.168.2.23140.240.183.60
    May 27, 2022 21:27:24.968292952 CEST3997023192.168.2.23155.101.240.215
    May 27, 2022 21:27:24.968300104 CEST3997023192.168.2.23125.113.240.188
    May 27, 2022 21:27:24.968307018 CEST3997023192.168.2.23166.111.24.189
    May 27, 2022 21:27:24.968307972 CEST3997023192.168.2.23142.26.60.86
    May 27, 2022 21:27:24.968322039 CEST3997023192.168.2.2314.25.140.170
    May 27, 2022 21:27:24.968322039 CEST3997023192.168.2.23183.196.195.37
    May 27, 2022 21:27:24.968331099 CEST3997023192.168.2.23218.220.48.158
    May 27, 2022 21:27:24.968338013 CEST3997023192.168.2.2391.98.195.103
    May 27, 2022 21:27:24.968338966 CEST3997023192.168.2.2372.143.7.46
    May 27, 2022 21:27:24.968350887 CEST3997023192.168.2.2373.4.153.151
    May 27, 2022 21:27:24.968352079 CEST3997023192.168.2.23103.129.217.249
    May 27, 2022 21:27:24.968364000 CEST3997023192.168.2.23122.186.30.96
    May 27, 2022 21:27:24.968364954 CEST3997023192.168.2.23161.221.140.1
    May 27, 2022 21:27:24.968375921 CEST3997023192.168.2.23255.105.11.24
    May 27, 2022 21:27:24.968383074 CEST3997023192.168.2.23145.223.251.74
    May 27, 2022 21:27:24.968385935 CEST3997023192.168.2.23209.123.249.216
    May 27, 2022 21:27:24.968420982 CEST3997023192.168.2.23182.52.92.245
    May 27, 2022 21:27:24.968420982 CEST3997023192.168.2.2338.64.22.136
    May 27, 2022 21:27:24.968425035 CEST3997023192.168.2.23134.216.91.251
    May 27, 2022 21:27:24.968430996 CEST3997023192.168.2.23252.15.157.78
    May 27, 2022 21:27:24.968446970 CEST3997023192.168.2.23122.187.59.96
    May 27, 2022 21:27:24.968455076 CEST3997023192.168.2.23171.39.246.150
    May 27, 2022 21:27:24.968456030 CEST3997023192.168.2.23188.104.26.31
    May 27, 2022 21:27:24.968485117 CEST3997023192.168.2.2377.49.65.19
    May 27, 2022 21:27:24.968492031 CEST3997023192.168.2.23188.204.68.189
    May 27, 2022 21:27:24.968494892 CEST3997023192.168.2.2344.78.44.81
    May 27, 2022 21:27:24.968496084 CEST3997023192.168.2.2319.176.58.43
    May 27, 2022 21:27:24.968497992 CEST3997023192.168.2.2357.93.184.66
    May 27, 2022 21:27:24.968503952 CEST3997023192.168.2.23193.168.111.179
    May 27, 2022 21:27:24.968509912 CEST3997023192.168.2.23254.132.185.153
    May 27, 2022 21:27:24.968509912 CEST3997023192.168.2.23254.137.2.107
    May 27, 2022 21:27:24.968530893 CEST3997023192.168.2.23217.143.212.210
    May 27, 2022 21:27:24.968539953 CEST3997023192.168.2.23148.67.105.230
    May 27, 2022 21:27:24.968539953 CEST3997023192.168.2.2387.146.188.8
    May 27, 2022 21:27:24.968543053 CEST3997023192.168.2.23176.92.161.236
    May 27, 2022 21:27:24.968554974 CEST3997023192.168.2.23128.170.13.129
    May 27, 2022 21:27:24.968560934 CEST3997023192.168.2.2380.254.214.225
    May 27, 2022 21:27:24.968564034 CEST3997023192.168.2.2393.167.34.19

    System Behavior

    Start time:21:27:23
    Start date:27/05/2022
    Path:/tmp/shAwKMD85K
    Arguments:/tmp/shAwKMD85K
    File size:4139976 bytes
    MD5 hash:8943e5f8f8c280467b4472c15ae93ba9
    Start time:21:27:24
    Start date:27/05/2022
    Path:/tmp/shAwKMD85K
    Arguments:n/a
    File size:4139976 bytes
    MD5 hash:8943e5f8f8c280467b4472c15ae93ba9
    Start time:21:29:40
    Start date:27/05/2022
    Path:/tmp/shAwKMD85K
    Arguments:n/a
    File size:4139976 bytes
    MD5 hash:8943e5f8f8c280467b4472c15ae93ba9
    Start time:21:27:24
    Start date:27/05/2022
    Path:/tmp/shAwKMD85K
    Arguments:n/a
    File size:4139976 bytes
    MD5 hash:8943e5f8f8c280467b4472c15ae93ba9
    Start time:21:27:24
    Start date:27/05/2022
    Path:/tmp/shAwKMD85K
    Arguments:n/a
    File size:4139976 bytes
    MD5 hash:8943e5f8f8c280467b4472c15ae93ba9
    Start time:21:27:24
    Start date:27/05/2022
    Path:/tmp/shAwKMD85K
    Arguments:n/a
    File size:4139976 bytes
    MD5 hash:8943e5f8f8c280467b4472c15ae93ba9
    Start time:21:27:24
    Start date:27/05/2022
    Path:/tmp/shAwKMD85K
    Arguments:n/a
    File size:4139976 bytes
    MD5 hash:8943e5f8f8c280467b4472c15ae93ba9