Linux Analysis Report
PPyJlaRy0K

Overview

General Information

Sample Name: PPyJlaRy0K
Analysis ID: 679491
MD5: 6e38620768d8b3cd84319f2ee3d4235d
SHA1: 64a0eb90426549c47177b6d3f927a6fa7cd19cba
SHA256: 0d69d7b91837715976e968862b79a944fe3d074713ce2d80f678af5993df75ed
Tags: 32elfmiraimotorola
Infos:

Detection

Mirai
Score: 68
Range: 0 - 100
Whitelisted: false

Signatures

Antivirus / Scanner detection for submitted sample
Yara detected Mirai
Multi AV Scanner detection for submitted file
Sample deletes itself
Sample has stripped symbol table
Uses the "uname" system call to query kernel version information (possible evasion)
Enumerates processes within the "proc" file system
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Detected TCP or UDP traffic on non-standard ports
Sample listens on a socket
Sample tries to kill a process (SIGKILL)

Classification

AV Detection

barindex
Source: PPyJlaRy0K Avira: detected
Source: PPyJlaRy0K Virustotal: Detection: 59% Perma Link
Source: global traffic TCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
Source: global traffic TCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
Source: global traffic TCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
Source: global traffic TCP traffic: 192.168.2.23:53692 -> 163.123.143.71:34241
Source: /tmp/PPyJlaRy0K (PID: 6234) Socket: 127.0.0.1::42516 Jump to behavior
Source: /tmp/PPyJlaRy0K (PID: 6236) Socket: 0.0.0.0::23 Jump to behavior
Source: /tmp/PPyJlaRy0K (PID: 6236) Socket: 0.0.0.0::0 Jump to behavior
Source: /tmp/PPyJlaRy0K (PID: 6236) Socket: 0.0.0.0::80 Jump to behavior
Source: /tmp/PPyJlaRy0K (PID: 6236) Socket: 0.0.0.0::81 Jump to behavior
Source: /tmp/PPyJlaRy0K (PID: 6236) Socket: 0.0.0.0::8443 Jump to behavior
Source: /tmp/PPyJlaRy0K (PID: 6236) Socket: 0.0.0.0::9009 Jump to behavior
Source: /tmp/PPyJlaRy0K (PID: 6249) Socket: 0.0.0.0::23 Jump to behavior
Source: /tmp/PPyJlaRy0K (PID: 6249) Socket: 0.0.0.0::0 Jump to behavior
Source: /tmp/PPyJlaRy0K (PID: 6249) Socket: 0.0.0.0::80 Jump to behavior
Source: /tmp/PPyJlaRy0K (PID: 6249) Socket: 0.0.0.0::81 Jump to behavior
Source: /tmp/PPyJlaRy0K (PID: 6249) Socket: 0.0.0.0::8443 Jump to behavior
Source: /tmp/PPyJlaRy0K (PID: 6249) Socket: 0.0.0.0::9009 Jump to behavior
Source: unknown Network traffic detected: HTTP traffic on port 43928 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 42836 -> 443
Source: unknown TCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknown TCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknown TCP traffic detected without corresponding DNS query: 100.217.179.67
Source: unknown TCP traffic detected without corresponding DNS query: 85.89.248.250
Source: unknown TCP traffic detected without corresponding DNS query: 73.188.248.66
Source: unknown TCP traffic detected without corresponding DNS query: 37.57.196.67
Source: unknown TCP traffic detected without corresponding DNS query: 24.226.175.162
Source: unknown TCP traffic detected without corresponding DNS query: 255.45.201.130
Source: unknown TCP traffic detected without corresponding DNS query: 118.6.202.2
Source: unknown TCP traffic detected without corresponding DNS query: 103.23.121.53
Source: unknown TCP traffic detected without corresponding DNS query: 37.16.119.250
Source: unknown TCP traffic detected without corresponding DNS query: 72.255.62.167
Source: unknown TCP traffic detected without corresponding DNS query: 250.44.70.188
Source: unknown TCP traffic detected without corresponding DNS query: 158.62.134.130
Source: unknown TCP traffic detected without corresponding DNS query: 69.240.254.252
Source: unknown TCP traffic detected without corresponding DNS query: 216.52.158.24
Source: unknown TCP traffic detected without corresponding DNS query: 149.245.247.81
Source: unknown TCP traffic detected without corresponding DNS query: 221.76.76.236
Source: unknown TCP traffic detected without corresponding DNS query: 90.119.253.21
Source: unknown TCP traffic detected without corresponding DNS query: 63.146.227.93
Source: unknown TCP traffic detected without corresponding DNS query: 20.255.244.64
Source: unknown TCP traffic detected without corresponding DNS query: 108.95.111.113
Source: unknown TCP traffic detected without corresponding DNS query: 24.7.228.58
Source: unknown TCP traffic detected without corresponding DNS query: 182.40.146.73
Source: unknown TCP traffic detected without corresponding DNS query: 101.168.167.150
Source: unknown TCP traffic detected without corresponding DNS query: 190.188.150.35
Source: unknown TCP traffic detected without corresponding DNS query: 67.164.195.154
Source: unknown TCP traffic detected without corresponding DNS query: 246.92.76.37
Source: unknown TCP traffic detected without corresponding DNS query: 14.138.46.56
Source: unknown TCP traffic detected without corresponding DNS query: 248.87.218.6
Source: unknown TCP traffic detected without corresponding DNS query: 62.64.250.35
Source: unknown TCP traffic detected without corresponding DNS query: 220.236.59.178
Source: unknown TCP traffic detected without corresponding DNS query: 222.97.96.168
Source: unknown TCP traffic detected without corresponding DNS query: 45.255.238.141
Source: unknown TCP traffic detected without corresponding DNS query: 68.21.122.98
Source: unknown TCP traffic detected without corresponding DNS query: 219.235.198.222
Source: unknown TCP traffic detected without corresponding DNS query: 71.61.180.90
Source: unknown TCP traffic detected without corresponding DNS query: 254.136.234.105
Source: unknown TCP traffic detected without corresponding DNS query: 87.239.133.13
Source: unknown TCP traffic detected without corresponding DNS query: 216.14.185.220
Source: unknown TCP traffic detected without corresponding DNS query: 94.142.216.192
Source: unknown TCP traffic detected without corresponding DNS query: 149.105.76.88
Source: unknown TCP traffic detected without corresponding DNS query: 157.45.195.215
Source: unknown TCP traffic detected without corresponding DNS query: 53.99.102.21
Source: unknown TCP traffic detected without corresponding DNS query: 5.75.255.80
Source: unknown TCP traffic detected without corresponding DNS query: 216.205.196.93
Source: unknown TCP traffic detected without corresponding DNS query: 158.76.172.152
Source: unknown TCP traffic detected without corresponding DNS query: 39.154.236.34
Source: unknown TCP traffic detected without corresponding DNS query: 213.170.199.110
Source: unknown TCP traffic detected without corresponding DNS query: 133.57.200.77
Source: ELF static info symbol of initial sample .symtab present: no
Source: /tmp/PPyJlaRy0K (PID: 6236) SIGKILL sent: pid: 936, result: successful Jump to behavior
Source: /tmp/PPyJlaRy0K (PID: 6249) SIGKILL sent: pid: 6236, result: successful Jump to behavior
Source: /tmp/PPyJlaRy0K (PID: 6249) SIGKILL sent: pid: 936, result: successful Jump to behavior
Source: /tmp/PPyJlaRy0K (PID: 6249) SIGKILL sent: pid: 759, result: successful Jump to behavior
Source: /tmp/PPyJlaRy0K (PID: 6249) SIGKILL sent: pid: 6239, result: successful Jump to behavior
Source: /tmp/PPyJlaRy0K (PID: 6249) SIGKILL sent: pid: 6253, result: successful Jump to behavior
Source: classification engine Classification label: mal68.troj.evad.lin@0/0@0/0
Source: /tmp/PPyJlaRy0K (PID: 6236) File opened: /proc/491/fd Jump to behavior
Source: /tmp/PPyJlaRy0K (PID: 6236) File opened: /proc/793/fd Jump to behavior
Source: /tmp/PPyJlaRy0K (PID: 6236) File opened: /proc/772/fd Jump to behavior
Source: /tmp/PPyJlaRy0K (PID: 6236) File opened: /proc/796/fd Jump to behavior
Source: /tmp/PPyJlaRy0K (PID: 6236) File opened: /proc/774/fd Jump to behavior
Source: /tmp/PPyJlaRy0K (PID: 6236) File opened: /proc/797/fd Jump to behavior
Source: /tmp/PPyJlaRy0K (PID: 6236) File opened: /proc/777/fd Jump to behavior
Source: /tmp/PPyJlaRy0K (PID: 6236) File opened: /proc/799/fd Jump to behavior
Source: /tmp/PPyJlaRy0K (PID: 6236) File opened: /proc/658/fd Jump to behavior
Source: /tmp/PPyJlaRy0K (PID: 6236) File opened: /proc/912/fd Jump to behavior
Source: /tmp/PPyJlaRy0K (PID: 6236) File opened: /proc/759/fd Jump to behavior
Source: /tmp/PPyJlaRy0K (PID: 6236) File opened: /proc/936/fd Jump to behavior
Source: /tmp/PPyJlaRy0K (PID: 6236) File opened: /proc/918/fd Jump to behavior
Source: /tmp/PPyJlaRy0K (PID: 6236) File opened: /proc/1/fd Jump to behavior
Source: /tmp/PPyJlaRy0K (PID: 6236) File opened: /proc/761/fd Jump to behavior
Source: /tmp/PPyJlaRy0K (PID: 6236) File opened: /proc/785/fd Jump to behavior
Source: /tmp/PPyJlaRy0K (PID: 6236) File opened: /proc/884/fd Jump to behavior
Source: /tmp/PPyJlaRy0K (PID: 6236) File opened: /proc/720/fd Jump to behavior
Source: /tmp/PPyJlaRy0K (PID: 6236) File opened: /proc/721/fd Jump to behavior
Source: /tmp/PPyJlaRy0K (PID: 6236) File opened: /proc/788/fd Jump to behavior
Source: /tmp/PPyJlaRy0K (PID: 6236) File opened: /proc/789/fd Jump to behavior
Source: /tmp/PPyJlaRy0K (PID: 6236) File opened: /proc/800/fd Jump to behavior
Source: /tmp/PPyJlaRy0K (PID: 6236) File opened: /proc/801/fd Jump to behavior
Source: /tmp/PPyJlaRy0K (PID: 6236) File opened: /proc/847/fd Jump to behavior
Source: /tmp/PPyJlaRy0K (PID: 6236) File opened: /proc/904/fd Jump to behavior
Source: /tmp/PPyJlaRy0K (PID: 6249) File opened: /proc/6236/fd Jump to behavior
Source: /tmp/PPyJlaRy0K (PID: 6249) File opened: /proc/2033/fd Jump to behavior
Source: /tmp/PPyJlaRy0K (PID: 6249) File opened: /proc/2033/exe Jump to behavior
Source: /tmp/PPyJlaRy0K (PID: 6249) File opened: /proc/1582/fd Jump to behavior
Source: /tmp/PPyJlaRy0K (PID: 6249) File opened: /proc/1582/exe Jump to behavior
Source: /tmp/PPyJlaRy0K (PID: 6249) File opened: /proc/2275/fd Jump to behavior
Source: /tmp/PPyJlaRy0K (PID: 6249) File opened: /proc/2275/exe Jump to behavior
Source: /tmp/PPyJlaRy0K (PID: 6249) File opened: /proc/3088/exe Jump to behavior
Source: /tmp/PPyJlaRy0K (PID: 6249) File opened: /proc/1612/fd Jump to behavior
Source: /tmp/PPyJlaRy0K (PID: 6249) File opened: /proc/1612/exe Jump to behavior
Source: /tmp/PPyJlaRy0K (PID: 6249) File opened: /proc/1579/fd Jump to behavior
Source: /tmp/PPyJlaRy0K (PID: 6249) File opened: /proc/1579/exe Jump to behavior
Source: /tmp/PPyJlaRy0K (PID: 6249) File opened: /proc/1699/fd Jump to behavior
Source: /tmp/PPyJlaRy0K (PID: 6249) File opened: /proc/1699/exe Jump to behavior
Source: /tmp/PPyJlaRy0K (PID: 6249) File opened: /proc/1335/fd Jump to behavior
Source: /tmp/PPyJlaRy0K (PID: 6249) File opened: /proc/1335/exe Jump to behavior
Source: /tmp/PPyJlaRy0K (PID: 6249) File opened: /proc/1698/fd Jump to behavior
Source: /tmp/PPyJlaRy0K (PID: 6249) File opened: /proc/1698/exe Jump to behavior
Source: /tmp/PPyJlaRy0K (PID: 6249) File opened: /proc/2028/fd Jump to behavior
Source: /tmp/PPyJlaRy0K (PID: 6249) File opened: /proc/2028/exe Jump to behavior
Source: /tmp/PPyJlaRy0K (PID: 6249) File opened: /proc/1334/fd Jump to behavior
Source: /tmp/PPyJlaRy0K (PID: 6249) File opened: /proc/1334/exe Jump to behavior
Source: /tmp/PPyJlaRy0K (PID: 6249) File opened: /proc/1576/fd Jump to behavior
Source: /tmp/PPyJlaRy0K (PID: 6249) File opened: /proc/1576/exe Jump to behavior
Source: /tmp/PPyJlaRy0K (PID: 6249) File opened: /proc/2302/fd Jump to behavior
Source: /tmp/PPyJlaRy0K (PID: 6249) File opened: /proc/2302/exe Jump to behavior
Source: /tmp/PPyJlaRy0K (PID: 6249) File opened: /proc/3236/fd Jump to behavior
Source: /tmp/PPyJlaRy0K (PID: 6249) File opened: /proc/3236/exe Jump to behavior
Source: /tmp/PPyJlaRy0K (PID: 6249) File opened: /proc/2025/fd Jump to behavior
Source: /tmp/PPyJlaRy0K (PID: 6249) File opened: /proc/2025/exe Jump to behavior
Source: /tmp/PPyJlaRy0K (PID: 6249) File opened: /proc/2146/fd Jump to behavior
Source: /tmp/PPyJlaRy0K (PID: 6249) File opened: /proc/2146/exe Jump to behavior
Source: /tmp/PPyJlaRy0K (PID: 6249) File opened: /proc/910/exe Jump to behavior
Source: /tmp/PPyJlaRy0K (PID: 6249) File opened: /proc/912/fd Jump to behavior
Source: /tmp/PPyJlaRy0K (PID: 6249) File opened: /proc/912/fd Jump to behavior
Source: /tmp/PPyJlaRy0K (PID: 6249) File opened: /proc/912/exe Jump to behavior
Source: /tmp/PPyJlaRy0K (PID: 6249) File opened: /proc/759/fd Jump to behavior
Source: /tmp/PPyJlaRy0K (PID: 6249) File opened: /proc/759/fd Jump to behavior
Source: /tmp/PPyJlaRy0K (PID: 6249) File opened: /proc/759/exe Jump to behavior
Source: /tmp/PPyJlaRy0K (PID: 6249) File opened: /proc/517/exe Jump to behavior
Source: /tmp/PPyJlaRy0K (PID: 6249) File opened: /proc/2307/fd Jump to behavior
Source: /tmp/PPyJlaRy0K (PID: 6249) File opened: /proc/2307/exe Jump to behavior
Source: /tmp/PPyJlaRy0K (PID: 6249) File opened: /proc/918/fd Jump to behavior
Source: /tmp/PPyJlaRy0K (PID: 6249) File opened: /proc/918/fd Jump to behavior
Source: /tmp/PPyJlaRy0K (PID: 6249) File opened: /proc/918/exe Jump to behavior
Source: /tmp/PPyJlaRy0K (PID: 6249) File opened: /proc/1594/fd Jump to behavior
Source: /tmp/PPyJlaRy0K (PID: 6249) File opened: /proc/1594/exe Jump to behavior
Source: /tmp/PPyJlaRy0K (PID: 6249) File opened: /proc/2285/fd Jump to behavior
Source: /tmp/PPyJlaRy0K (PID: 6249) File opened: /proc/2285/exe Jump to behavior
Source: /tmp/PPyJlaRy0K (PID: 6249) File opened: /proc/2281/fd Jump to behavior
Source: /tmp/PPyJlaRy0K (PID: 6249) File opened: /proc/2281/exe Jump to behavior
Source: /tmp/PPyJlaRy0K (PID: 6249) File opened: /proc/1349/fd Jump to behavior
Source: /tmp/PPyJlaRy0K (PID: 6249) File opened: /proc/1349/exe Jump to behavior
Source: /tmp/PPyJlaRy0K (PID: 6249) File opened: /proc/1/fd Jump to behavior
Source: /tmp/PPyJlaRy0K (PID: 6249) File opened: /proc/1/fd Jump to behavior
Source: /tmp/PPyJlaRy0K (PID: 6249) File opened: /proc/1623/fd Jump to behavior
Source: /tmp/PPyJlaRy0K (PID: 6249) File opened: /proc/1623/exe Jump to behavior
Source: /tmp/PPyJlaRy0K (PID: 6249) File opened: /proc/761/fd Jump to behavior
Source: /tmp/PPyJlaRy0K (PID: 6249) File opened: /proc/761/fd Jump to behavior
Source: /tmp/PPyJlaRy0K (PID: 6249) File opened: /proc/761/exe Jump to behavior
Source: /tmp/PPyJlaRy0K (PID: 6249) File opened: /proc/1622/fd Jump to behavior
Source: /tmp/PPyJlaRy0K (PID: 6249) File opened: /proc/1622/exe Jump to behavior
Source: /tmp/PPyJlaRy0K (PID: 6249) File opened: /proc/884/fd Jump to behavior
Source: /tmp/PPyJlaRy0K (PID: 6249) File opened: /proc/884/fd Jump to behavior
Source: /tmp/PPyJlaRy0K (PID: 6249) File opened: /proc/884/exe Jump to behavior
Source: /tmp/PPyJlaRy0K (PID: 6249) File opened: /proc/1983/fd Jump to behavior
Source: /tmp/PPyJlaRy0K (PID: 6249) File opened: /proc/1983/exe Jump to behavior
Source: /tmp/PPyJlaRy0K (PID: 6249) File opened: /proc/2038/fd Jump to behavior
Source: /tmp/PPyJlaRy0K (PID: 6249) File opened: /proc/2038/exe Jump to behavior
Source: /tmp/PPyJlaRy0K (PID: 6249) File opened: /proc/1586/fd Jump to behavior
Source: /tmp/PPyJlaRy0K (PID: 6249) File opened: /proc/1586/exe Jump to behavior
Source: /tmp/PPyJlaRy0K (PID: 6249) File opened: /proc/1465/fd Jump to behavior
Source: /tmp/PPyJlaRy0K (PID: 6249) File opened: /proc/1465/exe Jump to behavior
Source: /tmp/PPyJlaRy0K (PID: 6249) File opened: /proc/1344/fd Jump to behavior
Source: /tmp/PPyJlaRy0K (PID: 6249) File opened: /proc/1344/exe Jump to behavior
Source: /tmp/PPyJlaRy0K (PID: 6249) File opened: /proc/1860/fd Jump to behavior
Source: /tmp/PPyJlaRy0K (PID: 6249) File opened: /proc/1860/exe Jump to behavior
Source: /tmp/PPyJlaRy0K (PID: 6249) File opened: /proc/1463/fd Jump to behavior
Source: /tmp/PPyJlaRy0K (PID: 6249) File opened: /proc/1463/exe Jump to behavior
Source: /tmp/PPyJlaRy0K (PID: 6249) File opened: /proc/2156/fd Jump to behavior
Source: /tmp/PPyJlaRy0K (PID: 6249) File opened: /proc/2156/exe Jump to behavior

Hooking and other Techniques for Hiding and Protection

barindex
Source: /tmp/PPyJlaRy0K (PID: 6234) File: /tmp/PPyJlaRy0K Jump to behavior
Source: /tmp/PPyJlaRy0K (PID: 6234) Queries kernel information via 'uname': Jump to behavior
Source: PPyJlaRy0K, 6234.1.000055c62598f000.000055c625a14000.rw-.sdmp, PPyJlaRy0K, 6236.1.000055c62598f000.000055c625a14000.rw-.sdmp, PPyJlaRy0K, 6238.1.000055c62598f000.000055c625a14000.rw-.sdmp, PPyJlaRy0K, 6239.1.000055c62598f000.000055c625a14000.rw-.sdmp, PPyJlaRy0K, 6251.1.000055c62598f000.000055c625a14000.rw-.sdmp, PPyJlaRy0K, 6253.1.000055c62598f000.000055c625a14000.rw-.sdmp Binary or memory string: U!/etc/qemu-binfmt/m68k
Source: PPyJlaRy0K, 6234.1.00007ffdba0a2000.00007ffdba0c3000.rw-.sdmp, PPyJlaRy0K, 6236.1.00007ffdba0a2000.00007ffdba0c3000.rw-.sdmp, PPyJlaRy0K, 6238.1.00007ffdba0a2000.00007ffdba0c3000.rw-.sdmp, PPyJlaRy0K, 6239.1.00007ffdba0a2000.00007ffdba0c3000.rw-.sdmp, PPyJlaRy0K, 6251.1.00007ffdba0a2000.00007ffdba0c3000.rw-.sdmp, PPyJlaRy0K, 6253.1.00007ffdba0a2000.00007ffdba0c3000.rw-.sdmp Binary or memory string: /usr/bin/qemu-m68k
Source: PPyJlaRy0K, 6234.1.000055c62598f000.000055c625a14000.rw-.sdmp, PPyJlaRy0K, 6236.1.000055c62598f000.000055c625a14000.rw-.sdmp, PPyJlaRy0K, 6238.1.000055c62598f000.000055c625a14000.rw-.sdmp, PPyJlaRy0K, 6239.1.000055c62598f000.000055c625a14000.rw-.sdmp, PPyJlaRy0K, 6251.1.000055c62598f000.000055c625a14000.rw-.sdmp, PPyJlaRy0K, 6253.1.000055c62598f000.000055c625a14000.rw-.sdmp Binary or memory string: /etc/qemu-binfmt/m68k
Source: PPyJlaRy0K, 6234.1.00007ffdba0a2000.00007ffdba0c3000.rw-.sdmp, PPyJlaRy0K, 6236.1.00007ffdba0a2000.00007ffdba0c3000.rw-.sdmp, PPyJlaRy0K, 6238.1.00007ffdba0a2000.00007ffdba0c3000.rw-.sdmp, PPyJlaRy0K, 6239.1.00007ffdba0a2000.00007ffdba0c3000.rw-.sdmp, PPyJlaRy0K, 6251.1.00007ffdba0a2000.00007ffdba0c3000.rw-.sdmp, PPyJlaRy0K, 6253.1.00007ffdba0a2000.00007ffdba0c3000.rw-.sdmp Binary or memory string: 1?%/x86_64/usr/bin/qemu-m68k/tmp/PPyJlaRy0KSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/PPyJlaRy0K

Stealing of Sensitive Information

barindex
Source: Yara match File source: dump.pcap, type: PCAP

Remote Access Functionality

barindex
Source: Yara match File source: dump.pcap, type: PCAP
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs