Click to jump to signature section
Source: WKKdXepXFi.elf | Virustotal: Detection: 36% | Perma Link |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 57344 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 57366 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 57370 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 57376 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 57380 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 57384 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 57388 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 57390 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 57394 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 57396 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 37836 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 37852 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 37918 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 37932 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 37964 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 37980 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 37964 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 37994 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 38004 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 38016 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 38028 |
Source: global traffic | TCP traffic: 192.168.2.14:44456 -> 80.76.51.165:1312 |
Source: unknown | DNS traffic detected: queries for: daisy.ubuntu.com |
Source: unknown | TCP traffic detected without corresponding DNS query: 80.76.51.165 |
Source: unknown | TCP traffic detected without corresponding DNS query: 80.76.51.165 |
Source: unknown | TCP traffic detected without corresponding DNS query: 80.76.51.165 |
Source: unknown | TCP traffic detected without corresponding DNS query: 183.240.199.247 |
Source: unknown | TCP traffic detected without corresponding DNS query: 201.230.158.14 |
Source: unknown | TCP traffic detected without corresponding DNS query: 91.4.42.8 |
Source: unknown | TCP traffic detected without corresponding DNS query: 106.193.195.203 |
Source: unknown | TCP traffic detected without corresponding DNS query: 112.8.215.144 |
Source: unknown | TCP traffic detected without corresponding DNS query: 44.205.104.178 |
Source: unknown | TCP traffic detected without corresponding DNS query: 97.226.143.118 |
Source: unknown | TCP traffic detected without corresponding DNS query: 136.243.57.219 |
Source: unknown | TCP traffic detected without corresponding DNS query: 1.117.247.174 |
Source: unknown | TCP traffic detected without corresponding DNS query: 156.89.239.50 |
Source: unknown | TCP traffic detected without corresponding DNS query: 48.228.202.111 |
Source: unknown | TCP traffic detected without corresponding DNS query: 213.198.236.63 |
Source: unknown | TCP traffic detected without corresponding DNS query: 111.178.61.116 |
Source: unknown | TCP traffic detected without corresponding DNS query: 203.132.249.247 |
Source: unknown | TCP traffic detected without corresponding DNS query: 201.243.253.43 |
Source: unknown | TCP traffic detected without corresponding DNS query: 175.143.105.48 |
Source: unknown | TCP traffic detected without corresponding DNS query: 107.145.71.202 |
Source: unknown | TCP traffic detected without corresponding DNS query: 179.189.66.110 |
Source: unknown | TCP traffic detected without corresponding DNS query: 197.208.33.76 |
Source: unknown | TCP traffic detected without corresponding DNS query: 192.177.122.119 |
Source: unknown | TCP traffic detected without corresponding DNS query: 164.191.184.63 |
Source: unknown | TCP traffic detected without corresponding DNS query: 182.26.59.12 |
Source: unknown | TCP traffic detected without corresponding DNS query: 252.143.108.104 |
Source: unknown | TCP traffic detected without corresponding DNS query: 103.78.200.8 |
Source: unknown | TCP traffic detected without corresponding DNS query: 115.20.72.62 |
Source: unknown | TCP traffic detected without corresponding DNS query: 67.214.24.203 |
Source: unknown | TCP traffic detected without corresponding DNS query: 32.200.132.207 |
Source: unknown | TCP traffic detected without corresponding DNS query: 79.11.85.70 |
Source: unknown | TCP traffic detected without corresponding DNS query: 211.245.132.87 |
Source: unknown | TCP traffic detected without corresponding DNS query: 165.243.213.129 |
Source: unknown | TCP traffic detected without corresponding DNS query: 104.117.222.77 |
Source: unknown | TCP traffic detected without corresponding DNS query: 209.40.98.249 |
Source: unknown | TCP traffic detected without corresponding DNS query: 86.188.46.255 |
Source: unknown | TCP traffic detected without corresponding DNS query: 43.77.47.136 |
Source: unknown | TCP traffic detected without corresponding DNS query: 185.220.233.111 |
Source: unknown | TCP traffic detected without corresponding DNS query: 189.111.251.142 |
Source: unknown | TCP traffic detected without corresponding DNS query: 114.146.180.188 |
Source: unknown | TCP traffic detected without corresponding DNS query: 177.6.155.94 |
Source: unknown | TCP traffic detected without corresponding DNS query: 18.73.206.147 |
Source: unknown | TCP traffic detected without corresponding DNS query: 116.71.197.23 |
Source: unknown | TCP traffic detected without corresponding DNS query: 23.206.242.13 |
Source: unknown | TCP traffic detected without corresponding DNS query: 44.13.194.255 |
Source: unknown | TCP traffic detected without corresponding DNS query: 249.57.27.222 |
Source: unknown | TCP traffic detected without corresponding DNS query: 58.12.87.64 |
Source: unknown | TCP traffic detected without corresponding DNS query: 255.5.152.52 |
Source: unknown | TCP traffic detected without corresponding DNS query: 5.143.107.178 |
Source: unknown | TCP traffic detected without corresponding DNS query: 161.237.208.102 |
Source: WKKdXepXFi.elf | String found in binary or memory: http://upx.sf.net |
Source: LOAD without section mappings | Program segment: 0x8000 |
Source: /tmp/WKKdXepXFi.elf (PID: 5579) | SIGKILL sent: pid: 940, result: successful | Jump to behavior |
Source: /tmp/WKKdXepXFi.elf (PID: 5585) | SIGKILL sent: pid: 940, result: successful | Jump to behavior |
Source: classification engine | Classification label: mal64.troj.evad.linELF@0/53@2/0 |
Source: initial sample | String containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $ |
Source: initial sample | String containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $ |
Source: initial sample | String containing UPX found: $Id: UPX 3.94 Copyright (C) 1996-2017 the UPX Team. All Rights Reserved. $ |
Source: /tmp/WKKdXepXFi.elf (PID: 5585) | File opened: /proc/490/fd | Jump to behavior |
Source: /tmp/WKKdXepXFi.elf (PID: 5585) | File opened: /proc/791/fd | Jump to behavior |
Source: /tmp/WKKdXepXFi.elf (PID: 5585) | File opened: /proc/794/fd | Jump to behavior |
Source: /tmp/WKKdXepXFi.elf (PID: 5585) | File opened: /proc/795/fd | Jump to behavior |
Source: /tmp/WKKdXepXFi.elf (PID: 5585) | File opened: /proc/797/fd | Jump to behavior |
Source: /tmp/WKKdXepXFi.elf (PID: 5585) | File opened: /proc/853/fd | Jump to behavior |
Source: /tmp/WKKdXepXFi.elf (PID: 5585) | File opened: /proc/917/fd | Jump to behavior |
Source: /tmp/WKKdXepXFi.elf (PID: 5585) | File opened: /proc/780/fd | Jump to behavior |
Source: /tmp/WKKdXepXFi.elf (PID: 5585) | File opened: /proc/1/fd | Jump to behavior |
Source: /tmp/WKKdXepXFi.elf (PID: 5585) | File opened: /proc/661/fd | Jump to behavior |
Source: /tmp/WKKdXepXFi.elf (PID: 5585) | File opened: /proc/782/fd | Jump to behavior |
Source: /tmp/WKKdXepXFi.elf (PID: 5585) | File opened: /proc/785/fd | Jump to behavior |
Source: /tmp/WKKdXepXFi.elf (PID: 5585) | File opened: /proc/940/fd | Jump to behavior |
Source: /tmp/WKKdXepXFi.elf (PID: 5585) | File opened: /proc/767/fd | Jump to behavior |
Source: /tmp/WKKdXepXFi.elf (PID: 5585) | File opened: /proc/800/fd | Jump to behavior |
Source: /tmp/WKKdXepXFi.elf (PID: 5585) | File opened: /proc/888/fd | Jump to behavior |
Source: /tmp/WKKdXepXFi.elf (PID: 5585) | File opened: /proc/801/fd | Jump to behavior |
Source: /tmp/WKKdXepXFi.elf (PID: 5585) | File opened: /proc/725/fd | Jump to behavior |
Source: /tmp/WKKdXepXFi.elf (PID: 5585) | File opened: /proc/769/fd | Jump to behavior |
Source: /tmp/WKKdXepXFi.elf (PID: 5585) | File opened: /proc/726/fd | Jump to behavior |
Source: /tmp/WKKdXepXFi.elf (PID: 5585) | File opened: /proc/803/fd | Jump to behavior |
Source: /tmp/WKKdXepXFi.elf (PID: 5585) | File opened: /proc/806/fd | Jump to behavior |
Source: /tmp/WKKdXepXFi.elf (PID: 5585) | File opened: /proc/807/fd | Jump to behavior |
Source: /tmp/WKKdXepXFi.elf (PID: 5585) | File opened: /proc/928/fd | Jump to behavior |
Source: /tmp/WKKdXepXFi.elf (PID: 5579) | File opened: /proc/490/fd | Jump to behavior |
Source: /tmp/WKKdXepXFi.elf (PID: 5579) | File opened: /proc/791/fd | Jump to behavior |
Source: /tmp/WKKdXepXFi.elf (PID: 5579) | File opened: /proc/794/fd | Jump to behavior |
Source: /tmp/WKKdXepXFi.elf (PID: 5579) | File opened: /proc/795/fd | Jump to behavior |
Source: /tmp/WKKdXepXFi.elf (PID: 5579) | File opened: /proc/797/fd | Jump to behavior |
Source: /tmp/WKKdXepXFi.elf (PID: 5579) | File opened: /proc/853/fd | Jump to behavior |
Source: /tmp/WKKdXepXFi.elf (PID: 5579) | File opened: /proc/917/fd | Jump to behavior |
Source: /tmp/WKKdXepXFi.elf (PID: 5579) | File opened: /proc/780/fd | Jump to behavior |
Source: /tmp/WKKdXepXFi.elf (PID: 5579) | File opened: /proc/1/fd | Jump to behavior |
Source: /tmp/WKKdXepXFi.elf (PID: 5579) | File opened: /proc/661/fd | Jump to behavior |
Source: /tmp/WKKdXepXFi.elf (PID: 5579) | File opened: /proc/782/fd | Jump to behavior |
Source: /tmp/WKKdXepXFi.elf (PID: 5579) | File opened: /proc/785/fd | Jump to behavior |
Source: /tmp/WKKdXepXFi.elf (PID: 5579) | File opened: /proc/940/fd | Jump to behavior |
Source: /tmp/WKKdXepXFi.elf (PID: 5579) | File opened: /proc/767/fd | Jump to behavior |
Source: /tmp/WKKdXepXFi.elf (PID: 5579) | File opened: /proc/800/fd | Jump to behavior |
Source: /tmp/WKKdXepXFi.elf (PID: 5579) | File opened: /proc/888/fd | Jump to behavior |
Source: /tmp/WKKdXepXFi.elf (PID: 5579) | File opened: /proc/801/fd | Jump to behavior |
Source: /tmp/WKKdXepXFi.elf (PID: 5579) | File opened: /proc/725/fd | Jump to behavior |
Source: /tmp/WKKdXepXFi.elf (PID: 5579) | File opened: /proc/769/fd | Jump to behavior |
Source: /tmp/WKKdXepXFi.elf (PID: 5579) | File opened: /proc/726/fd | Jump to behavior |
Source: /tmp/WKKdXepXFi.elf (PID: 5579) | File opened: /proc/803/fd | Jump to behavior |
Source: /tmp/WKKdXepXFi.elf (PID: 5579) | File opened: /proc/806/fd | Jump to behavior |
Source: /tmp/WKKdXepXFi.elf (PID: 5579) | File opened: /proc/807/fd | Jump to behavior |
Source: /tmp/WKKdXepXFi.elf (PID: 5579) | File opened: /proc/928/fd | Jump to behavior |
Source: /usr/sbin/logrotate (PID: 5531) | Shell command executed: sh -c "\n\t\tinvoke-rc.d --quiet cups restart > /dev/null\n" logrotate_script "/var/log/cups/*log " | Jump to behavior |
Source: /usr/sbin/logrotate (PID: 5541) | Shell command executed: sh -c /usr/lib/rsyslog/rsyslog-rotate logrotate_script /var/log/syslog | Jump to behavior |
Source: /usr/sbin/invoke-rc.d (PID: 5536) | Systemctl executable: /usr/bin/systemctl -> systemctl --quiet is-enabled cups.service | Jump to behavior |
Source: /usr/sbin/invoke-rc.d (PID: 5539) | Systemctl executable: /usr/bin/systemctl -> systemctl --quiet is-active cups.service | Jump to behavior |
Source: /usr/lib/rsyslog/rsyslog-rotate (PID: 5543) | Systemctl executable: /usr/bin/systemctl -> systemctl kill -s HUP rsyslog.service | Jump to behavior |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 57344 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 57366 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 57370 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 57376 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 57380 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 57384 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 57388 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 57390 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 57394 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 57396 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 37836 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 37852 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 37918 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 37932 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 37964 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 37980 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 37964 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 37994 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 38004 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 38016 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 38028 |
Source: WKKdXepXFi.elf | Submission file: segment LOAD with 7.9655 entropy (max. 8.0) |
Source: /usr/sbin/logrotate (PID: 5467) | Truncated file: /var/log/cups/access_log.1 | Jump to behavior |
Source: /usr/sbin/logrotate (PID: 5467) | Truncated file: /var/log/syslog.1 | Jump to behavior |
Source: /usr/bin/find (PID: 5529) | Queries kernel information via 'uname': | Jump to behavior |
Source: /tmp/WKKdXepXFi.elf (PID: 5577) | Queries kernel information via 'uname': | Jump to behavior |
Source: 5537.20.dr | Binary or memory string: -9915837702310A--gzvmware kernel module |
Source: 5537.20.dr | Binary or memory string: -1116261022170A--gzQEMU User Emulator |
Source: 5537.20.dr | Binary or memory string: qemu-or1k |
Source: 5537.20.dr | Binary or memory string: qemu-riscv64 |
Source: 5537.20.dr | Binary or memory string: qemu-arm |
Source: 5537.20.dr | Binary or memory string: (qemu |
Source: 5537.20.dr | Binary or memory string: qemu-tilegx |
Source: 5537.20.dr | Binary or memory string: qemu-hppa |
Source: 5537.20.dr | Binary or memory string: q{rqemu% |
Source: 5537.20.dr | Binary or memory string: )qemu |
Source: 5537.20.dr | Binary or memory string: vmware-toolbox-cmd |
Source: 5537.20.dr | Binary or memory string: qemu-ppc |
Source: 5537.20.dr | Binary or memory string: Tqemu9 |
Source: 5537.20.dr | Binary or memory string: qemu-aarch64_be |
Source: 5537.20.dr | Binary or memory string: 0qemu9 |
Source: 5537.20.dr | Binary or memory string: qemu-sparc64 |
Source: 5537.20.dr | Binary or memory string: qemu-mips64 |
Source: 5537.20.dr | Binary or memory string: vV:qemu9 |
Source: 5537.20.dr | Binary or memory string: <prezip-bin-1116269780060A--gzprefix zip delta word list compressor/decompressornameif-8815490444730A--gzname network interfaces based on MAC addressesxdg-user-dirs-update-1115483406210A--gzUpdate XDG user dir configurationip-link-8815816145190A--gznetwork device configurationhpsa-4415812813670A--gzHP Smart Array SCSI driverhd4-4415812813670A--gzMFM/IDE hard disk devicessane-canon630u-5516003468200A--gzSANE backend for the Canon 630u USB flatbed scannersg_copy_results-8815825816070A--gzsend SCSI RECEIVE COPY RESULTS command (XCOPY related)grub-macbless-8816214898500A--gzbless a mac file/directoryntfstruncate-8815568625640A-tgztruncate a file on an NTFS volumelessfile-1115936459130B--gz"input preprocessor" for less.sane-artec-5516003468200A--gzSANE backend for Artec flatbed scannersrmdir-1115676799200A--gzremove empty directoriessystemd-networkd-wait-online.service-8816268940210A--gzWait for network to come onlinemkfs.ntfs-8815568625640B-tgzcreate an NTFS file systemsg_inq-8815825816070A--gzissue SCSI INQUIRY command and/or decode its responseradattr.so-8815955079440Cpppd-radattr-gzc_rehash-1ssl116164130370B--gzCreate symbolic links to files named by the hash valuestc-htb-8815816145190A--gzHierarchy Token Bucketgvfs-open-1115868766090A--gzsg_rbuf-8815825816070A--gzreads data using SCSI READ BUFFER commandglib-compile-schemas-1116155671180A--gzGSettings schema compileropenssl-srp-1ssl116164130370B--gzmaintain SRP password fileopenssl-rehash-1ssl116164130370B--gzCreate symbolic links to files named by the hash valueslibvmtools-3315837702310A--gzvmware shared librarypasswd5-5515906478670A--gzthe password filenet::dbus::dumperNet::DBus::Dumper3pm315773746310A--gzStringify Net::DBus objects suitable for printingsane-hp4200-5516003468200A--gzSANE backend for Hewlett-Packard 4200 scannersposixoptions-7715812813670A--gzoptional parts of the POSIX standardnetworkmanager.confNetworkManager.conf5516002723180A--gzNetworkManager configuration fileownership-8815771238010A--gzCompaq ownership tag retrieveroakdecode-1115804162510A--gzDecode an OAKT printer stream into human readable form.gvfs-save-1115868766090A--gzmkfs.minix-8815953177680A--gzmake a Minix filesystemuri7-7715812813670A--gzuniform resource identifier (URI), including a URL or URNedit-1115714399500B--gzexecute programs via entries in the mailcap filegit-diff-files-1116148628880A--gzCompares files in the working tree and the index.ldaprc-5516136581350Cldap.conf-gzpactl-1116219586 |