Edit tour
Linux
Analysis Report
ryidtyjrh
Overview
General Information
Detection
Score: | 60 |
Range: | 0 - 100 |
Whitelisted: | false |
Signatures
Found C&C like URL pattern
Uses known network protocols on non-standard ports
Sample and/or dropped files likely contain functionality related to malicious behavior
Found strings indicative of a multi-platform dropper
Performs DNS queries to domains with low reputation
HTTP GET or POST without a user agent
Uses the "uname" system call to query kernel version information (possible evasion)
Connects to many different domains
Detected TCP or UDP traffic on non-standard ports
Sample and/or dropped files contains symbols with suspicious names
Classification
Analysis Advice
Some HTTP requests failed (404). It is likely that the sample will exhibit less behavior. |
Joe Sandbox Version: | 38.0.0 Beryl |
Analysis ID: | 1275216 |
Start date and time: | 2023-07-18 16:50:38 +02:00 |
Joe Sandbox Product: | CloudBasic |
Overall analysis duration: | 0h 12m 30s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultlinuxfilecookbook.jbs |
Analysis system description: | Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11) |
Analysis Mode: | default |
Sample file name: | ryidtyjrh |
Detection: | MAL |
Classification: | mal60.spre.troj.lin@0/0@670/0 |
- Report size exceeded maximum capacity and may have missing network information.
- VT rate limit hit for: ryidtyjrh
Command: | /tmp/ryidtyjrh |
PID: | 6218 |
Exit Code: | |
Exit Code Info: | |
Killed: | True |
Standard Output: | start egypost.xyz egyppd.com egyprimevision.com egyprinting.com egypro.com egyprocto.com egy-pro.com egyprojects.org egyprovoyages.com egypsiem.com egyproperty.org egypt140.com egypt-24.com egypt15965.com egypt2016.com egypt2023.blog egypt2.com egypt2daytours.com egypt2export.com egypt2gate.com egypt360.travel egypt3dprinting.com egyptologue.fr egyptorientaltours.com https://www.egypt2.com - startwav egytal-co.com ehabamri.com https://www.egypost.xyz - startwav ehfpilates.com ehkuisnukisinanoya.net https://egyprimevision.com - startwav ehotelsguide.com eh-production.com ehssi.com eh-tc.de eib-systeme.de eichlerelektro.cz eicraxina.es eidedataservice.com eidemt.com eidmattegge.heilsarmee.ch eidsberg.org https://www.ehssi.com - jsonwav eiei.design eifainstitut.de eifel-ai.com eifelschenke.de https://eidmattegge.heilsarmee.ch - startwav eiffelabos.com eiffelrealestate.co.uk eiganote.com eigen.co eigendauer.com eight-fifty.com https://eiei.design - jsonwav eightswansaswimming.blog eighty5distributors.com eignatik.space eigo-ac-media.com eigo-ac.com eigotadoku.net eihire-ag.com eikekopsch.de eikoniksolutions.com eilebrecht.de eileencoates.com eileenkellyflynn-newjersey.sites.cbmoxi.com eileenkphoto.com eileenscooking.com eilis.org eimadventures.com eimantas-red.lt eimc.us eimpactconsulting.com einara.is https://eimpactconsulting.com - startwav https://eileenscooking.com - startwav einfach-besonders.com einfachda.de einfach-in-ordnung.de einfach-website-erstellen-lassen.de |
Standard Error: |
- system is lnxubuntu20
- cleanup
⊘No yara matches
⊘No Snort rule has matched
Click to jump to signature section
Show All Signature Results
Spreading |
---|
Source: | String: |