Edit tour

Linux Analysis Report
SecuriteInfo.com.Trojan.Linux.Mirai.FSO.12529.11645.elf

Overview

General Information

Sample name:SecuriteInfo.com.Trojan.Linux.Mirai.FSO.12529.11645.elf
Analysis ID:1366514
MD5:37300c8d7fc632c3a672108cb902b17a
SHA1:98ff0d2dcdffa836849c36a2845e94f3dfcaaaab
SHA256:34664366f414e4f6580cfc3a55b664e98e3ca2cb28e91e1d3b5040a6a0761b30
Tags:elf
Infos:

Detection

Score:48
Range:0 - 100
Whitelisted:false

Signatures

Multi AV Scanner detection for submitted file
ELF contains segments with high entropy indicating compressed/encrypted content
Sample contains only a LOAD segment without any section mappings
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious

Analysis Advice

Static ELF header machine description suggests that the sample might not execute correctly on this machine.
Exit code information suggests that the sample terminated abnormally, try to lookup the sample's target architecture.
All HTTP servers contacted by the sample do not answer. The sample is likely an old dropper which does no longer work.
Non-zero exit code suggests an error during the execution. Lookup the error code for hints.
Static ELF header machine description suggests that the sample might only run correctly on MIPS or ARM architectures.
Joe Sandbox version:38.0.0 Ammolite
Analysis ID:1366514
Start date and time:2023-12-23 19:18:07 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 23s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:SecuriteInfo.com.Trojan.Linux.Mirai.FSO.12529.11645.elf
Detection:MAL
Classification:mal48.linELF@0/0@0/0
Command:/tmp/SecuriteInfo.com.Trojan.Linux.Mirai.FSO.12529.11645.elf
PID:6205
Exit Code:139
Exit Code Info:SIGSEGV (11) Segmentation fault invalid memory reference
Killed:False
Standard Output:

Standard Error:qemu: uncaught target signal 11 (Segmentation fault) - core dumped
  • system is lnxubuntu20
  • cleanup
No yara matches
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: SecuriteInfo.com.Trojan.Linux.Mirai.FSO.12529.11645.elfReversingLabs: Detection: 43%
Source: global trafficTCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
Source: global trafficTCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
Source: global trafficTCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443
Source: LOAD without section mappingsProgram segment: 0x10000
Source: classification engineClassification label: mal48.linELF@0/0@0/0
Source: SecuriteInfo.com.Trojan.Linux.Mirai.FSO.12529.11645.elfSubmission file: segment LOAD with 7.9622 entropy (max. 8.0)
Source: /tmp/SecuriteInfo.com.Trojan.Linux.Mirai.FSO.12529.11645.elf (PID: 6205)Queries kernel information via 'uname': Jump to behavior
Source: SecuriteInfo.com.Trojan.Linux.Mirai.FSO.12529.11645.elf, 6205.1.000055da7c5c4000.000055da7c6f2000.rw-.sdmpBinary or memory string: U!/etc/qemu-binfmt/arm
Source: SecuriteInfo.com.Trojan.Linux.Mirai.FSO.12529.11645.elf, 6205.1.000055da7c5c4000.000055da7c6f2000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/arm
Source: SecuriteInfo.com.Trojan.Linux.Mirai.FSO.12529.11645.elf, 6205.1.00007ffe5a393000.00007ffe5a3b4000.rw-.sdmpBinary or memory string: /usr/bin/qemu-arm
Source: SecuriteInfo.com.Trojan.Linux.Mirai.FSO.12529.11645.elf, 6205.1.00007ffe5a393000.00007ffe5a3b4000.rw-.sdmpBinary or memory string: 6#\x86_64/usr/bin/qemu-arm/tmp/SecuriteInfo.com.Trojan.Linux.Mirai.FSO.12529.11645.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/SecuriteInfo.com.Trojan.Linux.Mirai.FSO.12529.11645.elf
Source: SecuriteInfo.com.Trojan.Linux.Mirai.FSO.12529.11645.elf, 6205.1.00007ffe5a393000.00007ffe5a3b4000.rw-.sdmpBinary or memory string: qemu: uncaught target signal 11 (Segmentation fault) - core dumped
Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpactResource DevelopmentReconnaissance
Valid AccountsWindows Management InstrumentationPath InterceptionPath Interception1
Obfuscated Files or Information
OS Credential Dumping11
Security Software Discovery
Remote ServicesData from Local SystemExfiltration Over Other Network Medium1
Encrypted Channel
Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationAbuse Accessibility FeaturesAcquire InfrastructureGather Victim Identity Information
Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over Bluetooth1
Application Layer Protocol
SIM Card SwapObtain Device Cloud BackupsNetwork Denial of ServiceDomainsCredentials
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1366514 Sample: SecuriteInfo.com.Trojan.Lin... Startdate: 23/12/2023 Architecture: LINUX Score: 48 8 109.202.202.202, 80 INIT7CH Switzerland 2->8 10 91.189.91.42, 443 CANONICAL-ASGB United Kingdom 2->10 12 91.189.91.43, 443 CANONICAL-ASGB United Kingdom 2->12 14 Multi AV Scanner detection for submitted file 2->14 6 SecuriteInfo.com.Trojan.Linux.Mirai.FSO.12529.11645.elf 2->6         started        signatures3 process4

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
SecuriteInfo.com.Trojan.Linux.Mirai.FSO.12529.11645.elf43%ReversingLabsLinux.Trojan.Mirai
SecuriteInfo.com.Trojan.Linux.Mirai.FSO.12529.11645.elf5%VirustotalBrowse
No Antivirus matches
No Antivirus matches
No Antivirus matches

Download Network PCAP: filteredfull

No contacted domains info
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs
IPDomainCountryFlagASNASN NameMalicious
109.202.202.202
unknownSwitzerland
13030INIT7CHfalse
91.189.91.43
unknownUnited Kingdom
41231CANONICAL-ASGBfalse
91.189.91.42
unknownUnited Kingdom
41231CANONICAL-ASGBfalse
MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
109.202.202.202bash.arm7-20231223-1416.elfGet hashmaliciousUnknownBrowse
    arm7-20231223-1253.elfGet hashmaliciousUnknownBrowse
      jKCoavAQ1j.elfGet hashmaliciousUnknownBrowse
        rtn_default.elfGet hashmaliciousUnknownBrowse
          j97aAiZbCj.elfGet hashmaliciousGafgyt, MiraiBrowse
            18jcpEb42I.elfGet hashmaliciousGafgyt, MiraiBrowse
              vT1aLJ5iWl.elfGet hashmaliciousGafgyt, MiraiBrowse
                MLJk9g6EVB.elfGet hashmaliciousGafgyt, MiraiBrowse
                  B2Oybf6uLe.elfGet hashmaliciousUnknownBrowse
                    syNWek7VtA.elfGet hashmaliciousGafgyt, MiraiBrowse
                      jQRJFIgCXV.elfGet hashmaliciousUnknownBrowse
                        4jwoH8kn0E.elfGet hashmaliciousUnknownBrowse
                          iFAaP0n1iJ.elfGet hashmaliciousUnknownBrowse
                            E6Jmu60HTh.elfGet hashmaliciousMiraiBrowse
                              x86-20231220-1231.elfGet hashmaliciousUnknownBrowse
                                TOEoYNH3Vh.elfGet hashmaliciousMiraiBrowse
                                  404Get hashmaliciousUnknownBrowse
                                    http://31.184.194.114/404Get hashmaliciousUnknownBrowse
                                      fatniggarm7-20231220-0021.elfGet hashmaliciousMiraiBrowse
                                        SecuriteInfo.com.ELF.Mirai-CFR.9566.32745.elfGet hashmaliciousUnknownBrowse
                                          91.189.91.43bash.arm7-20231223-1416.elfGet hashmaliciousUnknownBrowse
                                            arm7-20231223-1253.elfGet hashmaliciousUnknownBrowse
                                              jKCoavAQ1j.elfGet hashmaliciousUnknownBrowse
                                                rtn_default.elfGet hashmaliciousUnknownBrowse
                                                  j97aAiZbCj.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                    18jcpEb42I.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                      vT1aLJ5iWl.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                        B2Oybf6uLe.elfGet hashmaliciousUnknownBrowse
                                                          jQRJFIgCXV.elfGet hashmaliciousUnknownBrowse
                                                            4jwoH8kn0E.elfGet hashmaliciousUnknownBrowse
                                                              iFAaP0n1iJ.elfGet hashmaliciousUnknownBrowse
                                                                E6Jmu60HTh.elfGet hashmaliciousMiraiBrowse
                                                                  x86-20231220-1231.elfGet hashmaliciousUnknownBrowse
                                                                    TOEoYNH3Vh.elfGet hashmaliciousMiraiBrowse
                                                                      404Get hashmaliciousUnknownBrowse
                                                                        http://31.184.194.114/404Get hashmaliciousUnknownBrowse
                                                                          fatniggarm7-20231220-0021.elfGet hashmaliciousMiraiBrowse
                                                                            SecuriteInfo.com.ELF.Mirai-CFR.9566.32745.elfGet hashmaliciousUnknownBrowse
                                                                              8uomuNljhC.elfGet hashmaliciousUnknownBrowse
                                                                                SecuriteInfo.com.ELF.Mirai-CFR.1015.13556.elfGet hashmaliciousUnknownBrowse
                                                                                  91.189.91.42bash.arm7-20231223-1416.elfGet hashmaliciousUnknownBrowse
                                                                                    arm7-20231223-1253.elfGet hashmaliciousUnknownBrowse
                                                                                      jKCoavAQ1j.elfGet hashmaliciousUnknownBrowse
                                                                                        rtn_default.elfGet hashmaliciousUnknownBrowse
                                                                                          j97aAiZbCj.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                                                            18jcpEb42I.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                                                              vT1aLJ5iWl.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                                                                MLJk9g6EVB.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                                                                  B2Oybf6uLe.elfGet hashmaliciousUnknownBrowse
                                                                                                    syNWek7VtA.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                                                                      jQRJFIgCXV.elfGet hashmaliciousUnknownBrowse
                                                                                                        4jwoH8kn0E.elfGet hashmaliciousUnknownBrowse
                                                                                                          iFAaP0n1iJ.elfGet hashmaliciousUnknownBrowse
                                                                                                            E6Jmu60HTh.elfGet hashmaliciousMiraiBrowse
                                                                                                              x86-20231220-1231.elfGet hashmaliciousUnknownBrowse
                                                                                                                TOEoYNH3Vh.elfGet hashmaliciousMiraiBrowse
                                                                                                                  404Get hashmaliciousUnknownBrowse
                                                                                                                    http://31.184.194.114/404Get hashmaliciousUnknownBrowse
                                                                                                                      fatniggarm7-20231220-0021.elfGet hashmaliciousMiraiBrowse
                                                                                                                        SecuriteInfo.com.ELF.Mirai-CFR.9566.32745.elfGet hashmaliciousUnknownBrowse
                                                                                                                          No context
                                                                                                                          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                                                                          CANONICAL-ASGBbash.arm7-20231223-1416.elfGet hashmaliciousUnknownBrowse
                                                                                                                          • 91.189.91.42
                                                                                                                          arm7-20231223-1253.elfGet hashmaliciousUnknownBrowse
                                                                                                                          • 91.189.91.42
                                                                                                                          jKCoavAQ1j.elfGet hashmaliciousUnknownBrowse
                                                                                                                          • 91.189.91.42
                                                                                                                          rtn_default.elfGet hashmaliciousUnknownBrowse
                                                                                                                          • 91.189.91.42
                                                                                                                          j97aAiZbCj.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                                                                                          • 91.189.91.42
                                                                                                                          18jcpEb42I.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                                                                                          • 91.189.91.42
                                                                                                                          7ZIrfAGPjO.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                                                                                          • 185.125.190.26
                                                                                                                          6JaiNILodd.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                                                                                          • 185.125.190.26
                                                                                                                          oN934vVkuR.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                                                                                          • 185.125.190.26
                                                                                                                          vT1aLJ5iWl.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                                                                                          • 91.189.91.42
                                                                                                                          MLJk9g6EVB.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                                                                                          • 91.189.91.42
                                                                                                                          B2Oybf6uLe.elfGet hashmaliciousUnknownBrowse
                                                                                                                          • 91.189.91.42
                                                                                                                          syNWek7VtA.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                                                                                          • 91.189.91.42
                                                                                                                          S6Pe8KR7Ej.elfGet hashmaliciousUnknownBrowse
                                                                                                                          • 185.125.190.26
                                                                                                                          jQRJFIgCXV.elfGet hashmaliciousUnknownBrowse
                                                                                                                          • 91.189.91.42
                                                                                                                          4jwoH8kn0E.elfGet hashmaliciousUnknownBrowse
                                                                                                                          • 91.189.91.42
                                                                                                                          iFAaP0n1iJ.elfGet hashmaliciousUnknownBrowse
                                                                                                                          • 91.189.91.42
                                                                                                                          93cN3WxdN2.elfGet hashmaliciousMiraiBrowse
                                                                                                                          • 185.125.190.26
                                                                                                                          J0eiWEw7mS.elfGet hashmaliciousMiraiBrowse
                                                                                                                          • 185.125.190.26
                                                                                                                          E6Jmu60HTh.elfGet hashmaliciousMiraiBrowse
                                                                                                                          • 91.189.91.42
                                                                                                                          CANONICAL-ASGBbash.arm7-20231223-1416.elfGet hashmaliciousUnknownBrowse
                                                                                                                          • 91.189.91.42
                                                                                                                          arm7-20231223-1253.elfGet hashmaliciousUnknownBrowse
                                                                                                                          • 91.189.91.42
                                                                                                                          jKCoavAQ1j.elfGet hashmaliciousUnknownBrowse
                                                                                                                          • 91.189.91.42
                                                                                                                          rtn_default.elfGet hashmaliciousUnknownBrowse
                                                                                                                          • 91.189.91.42
                                                                                                                          j97aAiZbCj.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                                                                                          • 91.189.91.42
                                                                                                                          18jcpEb42I.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                                                                                          • 91.189.91.42
                                                                                                                          7ZIrfAGPjO.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                                                                                          • 185.125.190.26
                                                                                                                          6JaiNILodd.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                                                                                          • 185.125.190.26
                                                                                                                          oN934vVkuR.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                                                                                          • 185.125.190.26
                                                                                                                          vT1aLJ5iWl.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                                                                                          • 91.189.91.42
                                                                                                                          MLJk9g6EVB.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                                                                                          • 91.189.91.42
                                                                                                                          B2Oybf6uLe.elfGet hashmaliciousUnknownBrowse
                                                                                                                          • 91.189.91.42
                                                                                                                          syNWek7VtA.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                                                                                          • 91.189.91.42
                                                                                                                          S6Pe8KR7Ej.elfGet hashmaliciousUnknownBrowse
                                                                                                                          • 185.125.190.26
                                                                                                                          jQRJFIgCXV.elfGet hashmaliciousUnknownBrowse
                                                                                                                          • 91.189.91.42
                                                                                                                          4jwoH8kn0E.elfGet hashmaliciousUnknownBrowse
                                                                                                                          • 91.189.91.42
                                                                                                                          iFAaP0n1iJ.elfGet hashmaliciousUnknownBrowse
                                                                                                                          • 91.189.91.42
                                                                                                                          93cN3WxdN2.elfGet hashmaliciousMiraiBrowse
                                                                                                                          • 185.125.190.26
                                                                                                                          J0eiWEw7mS.elfGet hashmaliciousMiraiBrowse
                                                                                                                          • 185.125.190.26
                                                                                                                          E6Jmu60HTh.elfGet hashmaliciousMiraiBrowse
                                                                                                                          • 91.189.91.42
                                                                                                                          INIT7CHbash.arm7-20231223-1416.elfGet hashmaliciousUnknownBrowse
                                                                                                                          • 109.202.202.202
                                                                                                                          arm7-20231223-1253.elfGet hashmaliciousUnknownBrowse
                                                                                                                          • 109.202.202.202
                                                                                                                          jKCoavAQ1j.elfGet hashmaliciousUnknownBrowse
                                                                                                                          • 109.202.202.202
                                                                                                                          xqz8sQ4mZB.exeGet hashmaliciousGlupteba, SmokeLoaderBrowse
                                                                                                                          • 213.144.142.24
                                                                                                                          rtn_default.elfGet hashmaliciousUnknownBrowse
                                                                                                                          • 109.202.202.202
                                                                                                                          j97aAiZbCj.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                                                                                          • 109.202.202.202
                                                                                                                          18jcpEb42I.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                                                                                          • 109.202.202.202
                                                                                                                          vT1aLJ5iWl.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                                                                                          • 109.202.202.202
                                                                                                                          MLJk9g6EVB.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                                                                                          • 109.202.202.202
                                                                                                                          B2Oybf6uLe.elfGet hashmaliciousUnknownBrowse
                                                                                                                          • 109.202.202.202
                                                                                                                          syNWek7VtA.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                                                                                          • 109.202.202.202
                                                                                                                          jQRJFIgCXV.elfGet hashmaliciousUnknownBrowse
                                                                                                                          • 109.202.202.202
                                                                                                                          4jwoH8kn0E.elfGet hashmaliciousUnknownBrowse
                                                                                                                          • 109.202.202.202
                                                                                                                          iFAaP0n1iJ.elfGet hashmaliciousUnknownBrowse
                                                                                                                          • 109.202.202.202
                                                                                                                          E6Jmu60HTh.elfGet hashmaliciousMiraiBrowse
                                                                                                                          • 109.202.202.202
                                                                                                                          x86-20231220-1231.elfGet hashmaliciousUnknownBrowse
                                                                                                                          • 109.202.202.202
                                                                                                                          TOEoYNH3Vh.elfGet hashmaliciousMiraiBrowse
                                                                                                                          • 109.202.202.202
                                                                                                                          404Get hashmaliciousUnknownBrowse
                                                                                                                          • 109.202.202.202
                                                                                                                          http://31.184.194.114/404Get hashmaliciousUnknownBrowse
                                                                                                                          • 109.202.202.202
                                                                                                                          fatniggarm7-20231220-0021.elfGet hashmaliciousMiraiBrowse
                                                                                                                          • 109.202.202.202
                                                                                                                          No context
                                                                                                                          No context
                                                                                                                          No created / dropped files found
                                                                                                                          File type:ELF 32-bit LSB executable, ARM, EABI5 version 1 (GNU/Linux), statically linked, no section header
                                                                                                                          Entropy (8bit):7.96223725583323
                                                                                                                          TrID:
                                                                                                                          • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                                                                                                                          File name:SecuriteInfo.com.Trojan.Linux.Mirai.FSO.12529.11645.elf
                                                                                                                          File size:8'688 bytes
                                                                                                                          MD5:37300c8d7fc632c3a672108cb902b17a
                                                                                                                          SHA1:98ff0d2dcdffa836849c36a2845e94f3dfcaaaab
                                                                                                                          SHA256:34664366f414e4f6580cfc3a55b664e98e3ca2cb28e91e1d3b5040a6a0761b30
                                                                                                                          SHA512:5b62bb31b6a3db401dd121035076e1ca85feb833fe3d135c840ed9052c0b83d253e54ad7a60e6881d362c63df5f2c4e85380923834b396c01635cd8805466c3c
                                                                                                                          SSDEEP:192:KXs4Lyi82so2yzXtb1MQFGKVeKJRT6XXmBrdIQy:yb2eX3zAKuiNy
                                                                                                                          TLSH:1E02BFA13B1123C2F522EFB57B98742BD52D9635708C5A217629828BC06E72D14BF62E
                                                                                                                          File Content Preview:.ELF..............(......'..4...........4. ...(......................7...7.............................................c........................i..........?.E.h;....#..$..O.%.......y.A.U"......-R..e....<l>=).!...O........u.....`o..*ziy"......R..~@....x2'_

                                                                                                                          ELF header

                                                                                                                          Class:ELF32
                                                                                                                          Data:2's complement, little endian
                                                                                                                          Version:1 (current)
                                                                                                                          Machine:ARM
                                                                                                                          Version Number:0x1
                                                                                                                          Type:EXEC (Executable file)
                                                                                                                          OS/ABI:UNIX - Linux
                                                                                                                          ABI Version:0
                                                                                                                          Entry Point Address:0x22718
                                                                                                                          Flags:0x5000202
                                                                                                                          ELF Header Size:52
                                                                                                                          Program Header Offset:52
                                                                                                                          Program Header Size:32
                                                                                                                          Number of Program Headers:2
                                                                                                                          Section Header Offset:0
                                                                                                                          Section Header Size:40
                                                                                                                          Number of Section Headers:0
                                                                                                                          Header String Table Index:0
                                                                                                                          TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                                                                                          LOAD0x00x100000x100000x137e90x137e97.96220x5R E0x10000
                                                                                                                          LOAD0x6fc0x506fc0x506fc0x00x00.00000x6RW 0x10000

                                                                                                                          Download Network PCAP: filteredfull

                                                                                                                          • Total Packets: 8
                                                                                                                          • 443 (HTTPS)
                                                                                                                          • 80 (HTTP)
                                                                                                                          TimestampSource PortDest PortSource IPDest IP
                                                                                                                          Dec 23, 2023 19:18:45.384651899 CET43928443192.168.2.2391.189.91.42
                                                                                                                          Dec 23, 2023 19:18:50.759872913 CET42836443192.168.2.2391.189.91.43
                                                                                                                          Dec 23, 2023 19:18:52.295782089 CET4251680192.168.2.23109.202.202.202
                                                                                                                          Dec 23, 2023 19:19:06.373709917 CET43928443192.168.2.2391.189.91.42
                                                                                                                          Dec 23, 2023 19:19:16.612251043 CET42836443192.168.2.2391.189.91.43
                                                                                                                          Dec 23, 2023 19:19:22.755443096 CET4251680192.168.2.23109.202.202.202
                                                                                                                          Dec 23, 2023 19:19:47.327919006 CET43928443192.168.2.2391.189.91.42
                                                                                                                          Dec 23, 2023 19:20:07.805078983 CET42836443192.168.2.2391.189.91.43

                                                                                                                          System Behavior

                                                                                                                          Start time (UTC):18:18:41
                                                                                                                          Start date (UTC):23/12/2023
                                                                                                                          Path:/tmp/SecuriteInfo.com.Trojan.Linux.Mirai.FSO.12529.11645.elf
                                                                                                                          Arguments:/tmp/SecuriteInfo.com.Trojan.Linux.Mirai.FSO.12529.11645.elf
                                                                                                                          File size:4956856 bytes
                                                                                                                          MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1