Source: dNLKZA6IVs |
Virustotal: Detection: 43% |
Perma Link |
Source: dNLKZA6IVs |
Metadefender: Detection: 34% |
Perma Link |
Source: dNLKZA6IVs |
ReversingLabs: Detection: 73% |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 43848 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 43854 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 43864 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 43892 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 43900 |
Source: global traffic |
TCP traffic: 192.168.2.23:52808 -> 105.110.101.85:7547 |
Source: global traffic |
TCP traffic: 192.168.2.23:53436 -> 46.23.109.40:1312 |
Source: global traffic |
TCP traffic: 192.168.2.23:41062 -> 160.177.155.129:7547 |
Source: /tmp/dNLKZA6IVs (PID: 6231) |
Socket: 127.0.0.1::1312 |
Jump to behavior |
Source: /tmp/dNLKZA6IVs (PID: 6242) |
Socket: 0.0.0.0::0 |
Jump to behavior |
Source: /tmp/dNLKZA6IVs (PID: 6242) |
Socket: 0.0.0.0::53413 |
Jump to behavior |
Source: /tmp/dNLKZA6IVs (PID: 6242) |
Socket: 0.0.0.0::80 |
Jump to behavior |
Source: /tmp/dNLKZA6IVs (PID: 6242) |
Socket: 0.0.0.0::37215 |
Jump to behavior |
Source: unknown |
DNS traffic detected: queries for: arcticboatz.cz |
Source: unknown |
Network traffic detected: HTTP traffic on port 43928 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 33186 |
Source: unknown |
Network traffic detected: HTTP traffic on port 42836 -> 443 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 202.183.87.80 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 36.42.218.83 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 194.196.235.203 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 13.73.112.158 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 150.164.107.187 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 216.199.69.80 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 173.207.17.142 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 213.127.78.7 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 203.182.69.185 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 205.173.56.210 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 85.228.242.238 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 1.74.17.104 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 249.5.201.220 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 177.139.176.115 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 124.42.216.148 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 58.28.185.231 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 106.155.249.145 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 158.216.238.194 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 250.119.196.96 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 141.250.43.84 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 198.17.151.16 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 125.125.170.224 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 136.235.223.149 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 160.227.81.22 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 156.87.251.190 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 87.127.18.159 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 35.49.77.188 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 255.92.209.243 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 192.232.208.136 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 31.100.170.253 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 185.17.188.238 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 89.194.161.18 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 86.246.249.152 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 164.133.121.43 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 91.156.255.156 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 153.12.230.92 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 5.41.66.217 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 211.27.62.93 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 155.33.13.129 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 243.162.254.159 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 92.118.213.235 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 240.121.246.82 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 196.137.131.205 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 246.162.150.3 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 151.130.194.29 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 207.80.114.120 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 17.254.113.95 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 78.160.7.163 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 90.27.52.240 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 42.119.61.176 |
Source: ELF static info symbol of initial sample |
.symtab present: no |
Source: /tmp/dNLKZA6IVs (PID: 6242) |
SIGKILL sent: pid: 936, result: successful |
Jump to behavior |
Source: Initial sample |
String containing 'busybox' found: /bin/busybox AK1K2 |
Source: Initial sample |
String containing 'busybox' found: /bin/busybox cp /bin/busybox retrieve && >retrieve && /bin/busybox chmod 777 retrieve && /bin/busybox cp /bin/busybox .t && >.t && /bin/busybox chmod 777 .t |
Source: Initial sample |
String containing 'busybox' found: /bin/busybox echo -en '%s' %s %s && /bin/busybox echo -en '\x45\x43\x48\x4f\x44\x4f\x4e\x45' |
Source: Initial sample |
String containing 'busybox' found: >%st && cd %s && >retrieve; >.t/bin/busybox cp /bin/busybox retrieve && >retrieve && /bin/busybox chmod 777 retrieve && /bin/busybox cp /bin/busybox .t && >.t && /bin/busybox chmod 777 .t |
Source: Initial sample |
String containing 'busybox' found: >>>/bin/busybox echo -en '%s' %s %s && /bin/busybox echo -en '\x45\x43\x48\x4f\x44\x4f\x4e\x45' |
Source: classification engine |
Classification label: mal76.troj.lin@0/0@46/0 |
Source: /tmp/dNLKZA6IVs (PID: 6242) |
File opened: /proc/491/fd |
Jump to behavior |
Source: /tmp/dNLKZA6IVs (PID: 6242) |
File opened: /proc/793/fd |
Jump to behavior |
Source: /tmp/dNLKZA6IVs (PID: 6242) |
File opened: /proc/772/fd |
Jump to behavior |
Source: /tmp/dNLKZA6IVs (PID: 6242) |
File opened: /proc/796/fd |
Jump to behavior |
Source: /tmp/dNLKZA6IVs (PID: 6242) |
File opened: /proc/774/fd |
Jump to behavior |
Source: /tmp/dNLKZA6IVs (PID: 6242) |
File opened: /proc/797/fd |
Jump to behavior |
Source: /tmp/dNLKZA6IVs (PID: 6242) |
File opened: /proc/777/fd |
Jump to behavior |
Source: /tmp/dNLKZA6IVs (PID: 6242) |
File opened: /proc/799/fd |
Jump to behavior |
Source: /tmp/dNLKZA6IVs (PID: 6242) |
File opened: /proc/658/fd |
Jump to behavior |
Source: /tmp/dNLKZA6IVs (PID: 6242) |
File opened: /proc/912/fd |
Jump to behavior |
Source: /tmp/dNLKZA6IVs (PID: 6242) |
File opened: /proc/759/fd |
Jump to behavior |
Source: /tmp/dNLKZA6IVs (PID: 6242) |
File opened: /proc/936/fd |
Jump to behavior |
Source: /tmp/dNLKZA6IVs (PID: 6242) |
File opened: /proc/918/fd |
Jump to behavior |
Source: /tmp/dNLKZA6IVs (PID: 6242) |
File opened: /proc/1/fd |
Jump to behavior |
Source: /tmp/dNLKZA6IVs (PID: 6242) |
File opened: /proc/761/fd |
Jump to behavior |
Source: /tmp/dNLKZA6IVs (PID: 6242) |
File opened: /proc/785/fd |
Jump to behavior |
Source: /tmp/dNLKZA6IVs (PID: 6242) |
File opened: /proc/884/fd |
Jump to behavior |
Source: /tmp/dNLKZA6IVs (PID: 6242) |
File opened: /proc/720/fd |
Jump to behavior |
Source: /tmp/dNLKZA6IVs (PID: 6242) |
File opened: /proc/721/fd |
Jump to behavior |
Source: /tmp/dNLKZA6IVs (PID: 6242) |
File opened: /proc/788/fd |
Jump to behavior |
Source: /tmp/dNLKZA6IVs (PID: 6242) |
File opened: /proc/789/fd |
Jump to behavior |
Source: /tmp/dNLKZA6IVs (PID: 6242) |
File opened: /proc/800/fd |
Jump to behavior |
Source: /tmp/dNLKZA6IVs (PID: 6242) |
File opened: /proc/801/fd |
Jump to behavior |
Source: /tmp/dNLKZA6IVs (PID: 6242) |
File opened: /proc/847/fd |
Jump to behavior |
Source: /tmp/dNLKZA6IVs (PID: 6242) |
File opened: /proc/904/fd |
Jump to behavior |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 43848 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 43854 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 43864 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 43892 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 43900 |
Source: /tmp/dNLKZA6IVs (PID: 6231) |
Queries kernel information via 'uname': |
Jump to behavior |
Source: dNLKZA6IVs, 6231.1.000055d649b2a000.000055d649c58000.rw-.sdmp, dNLKZA6IVs, 6329.1.000055d649b2a000.000055d649c58000.rw-.sdmp, dNLKZA6IVs, 6243.1.000055d649b2a000.000055d649c58000.rw-.sdmp |
Binary or memory string: U!/etc/qemu-binfmt/arm |
Source: dNLKZA6IVs, 6231.1.00007ffce2172000.00007ffce2193000.rw-.sdmp, dNLKZA6IVs, 6329.1.00007ffce2172000.00007ffce2193000.rw-.sdmp, dNLKZA6IVs, 6243.1.00007ffce2172000.00007ffce2193000.rw-.sdmp |
Binary or memory string: x86_64/usr/bin/qemu-arm/tmp/dNLKZA6IVsSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/dNLKZA6IVs |
Source: dNLKZA6IVs, 6231.1.000055d649b2a000.000055d649c58000.rw-.sdmp, dNLKZA6IVs, 6329.1.000055d649b2a000.000055d649c58000.rw-.sdmp, dNLKZA6IVs, 6243.1.000055d649b2a000.000055d649c58000.rw-.sdmp |
Binary or memory string: /etc/qemu-binfmt/arm |
Source: dNLKZA6IVs, 6231.1.00007ffce2172000.00007ffce2193000.rw-.sdmp, dNLKZA6IVs, 6329.1.00007ffce2172000.00007ffce2193000.rw-.sdmp, dNLKZA6IVs, 6243.1.00007ffce2172000.00007ffce2193000.rw-.sdmp |
Binary or memory string: /usr/bin/qemu-arm |
Source: Yara match |
File source: dump.pcap, type: PCAP |
Source: Yara match |
File source: dNLKZA6IVs, type: SAMPLE |
Source: Yara match |
File source: 6329.1.00007f5c4c017000.00007f5c4c02e000.r-x.sdmp, type: MEMORY |
Source: Yara match |
File source: 6231.1.00007f5c4c017000.00007f5c4c02e000.r-x.sdmp, type: MEMORY |
Source: Yara match |
File source: 6243.1.00007f5c4c017000.00007f5c4c02e000.r-x.sdmp, type: MEMORY |
Source: Yara match |
File source: dump.pcap, type: PCAP |
Source: Yara match |
File source: dNLKZA6IVs, type: SAMPLE |
Source: Yara match |
File source: 6329.1.00007f5c4c017000.00007f5c4c02e000.r-x.sdmp, type: MEMORY |
Source: Yara match |
File source: 6231.1.00007f5c4c017000.00007f5c4c02e000.r-x.sdmp, type: MEMORY |
Source: Yara match |
File source: 6243.1.00007f5c4c017000.00007f5c4c02e000.r-x.sdmp, type: MEMORY |