Click to jump to signature section
Source: qeekk7ISVq.elf | Virustotal: Detection: 24% | Perma Link |
Source: qeekk7ISVq.elf | ReversingLabs: Detection: 18% |
Source: global traffic | TCP traffic: 192.168.2.23:49466 -> 43.228.124.184:8084 |
Source: global traffic | TCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443 |
Source: global traffic | TCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443 |
Source: global traffic | TCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80 |
Source: unknown | TCP traffic detected without corresponding DNS query: 43.228.124.184 |
Source: unknown | TCP traffic detected without corresponding DNS query: 43.228.124.184 |
Source: unknown | TCP traffic detected without corresponding DNS query: 43.228.124.184 |
Source: unknown | TCP traffic detected without corresponding DNS query: 43.228.124.184 |
Source: unknown | TCP traffic detected without corresponding DNS query: 43.228.124.184 |
Source: unknown | TCP traffic detected without corresponding DNS query: 43.228.124.184 |
Source: unknown | TCP traffic detected without corresponding DNS query: 43.228.124.184 |
Source: unknown | TCP traffic detected without corresponding DNS query: 43.228.124.184 |
Source: unknown | TCP traffic detected without corresponding DNS query: 43.228.124.184 |
Source: unknown | TCP traffic detected without corresponding DNS query: 43.228.124.184 |
Source: unknown | TCP traffic detected without corresponding DNS query: 43.228.124.184 |
Source: unknown | TCP traffic detected without corresponding DNS query: 43.228.124.184 |
Source: unknown | TCP traffic detected without corresponding DNS query: 43.228.124.184 |
Source: unknown | TCP traffic detected without corresponding DNS query: 43.228.124.184 |
Source: unknown | TCP traffic detected without corresponding DNS query: 43.228.124.184 |
Source: unknown | TCP traffic detected without corresponding DNS query: 43.228.124.184 |
Source: unknown | TCP traffic detected without corresponding DNS query: 43.228.124.184 |
Source: unknown | TCP traffic detected without corresponding DNS query: 43.228.124.184 |
Source: unknown | TCP traffic detected without corresponding DNS query: 43.228.124.184 |
Source: unknown | TCP traffic detected without corresponding DNS query: 43.228.124.184 |
Source: unknown | TCP traffic detected without corresponding DNS query: 43.228.124.184 |
Source: unknown | TCP traffic detected without corresponding DNS query: 43.228.124.184 |
Source: unknown | TCP traffic detected without corresponding DNS query: 43.228.124.184 |
Source: unknown | TCP traffic detected without corresponding DNS query: 43.228.124.184 |
Source: unknown | TCP traffic detected without corresponding DNS query: 43.228.124.184 |
Source: unknown | TCP traffic detected without corresponding DNS query: 43.228.124.184 |
Source: unknown | TCP traffic detected without corresponding DNS query: 43.228.124.184 |
Source: unknown | TCP traffic detected without corresponding DNS query: 43.228.124.184 |
Source: unknown | TCP traffic detected without corresponding DNS query: 43.228.124.184 |
Source: unknown | TCP traffic detected without corresponding DNS query: 43.228.124.184 |
Source: unknown | TCP traffic detected without corresponding DNS query: 43.228.124.184 |
Source: unknown | TCP traffic detected without corresponding DNS query: 43.228.124.184 |
Source: unknown | TCP traffic detected without corresponding DNS query: 43.228.124.184 |
Source: unknown | TCP traffic detected without corresponding DNS query: 43.228.124.184 |
Source: unknown | TCP traffic detected without corresponding DNS query: 43.228.124.184 |
Source: unknown | TCP traffic detected without corresponding DNS query: 43.228.124.184 |
Source: unknown | TCP traffic detected without corresponding DNS query: 43.228.124.184 |
Source: unknown | TCP traffic detected without corresponding DNS query: 43.228.124.184 |
Source: unknown | TCP traffic detected without corresponding DNS query: 43.228.124.184 |
Source: unknown | TCP traffic detected without corresponding DNS query: 43.228.124.184 |
Source: unknown | TCP traffic detected without corresponding DNS query: 43.228.124.184 |
Source: unknown | TCP traffic detected without corresponding DNS query: 43.228.124.184 |
Source: unknown | TCP traffic detected without corresponding DNS query: 43.228.124.184 |
Source: unknown | TCP traffic detected without corresponding DNS query: 43.228.124.184 |
Source: unknown | TCP traffic detected without corresponding DNS query: 43.228.124.184 |
Source: unknown | TCP traffic detected without corresponding DNS query: 43.228.124.184 |
Source: unknown | TCP traffic detected without corresponding DNS query: 43.228.124.184 |
Source: unknown | TCP traffic detected without corresponding DNS query: 43.228.124.184 |
Source: unknown | TCP traffic detected without corresponding DNS query: 43.228.124.184 |
Source: unknown | TCP traffic detected without corresponding DNS query: 43.228.124.184 |
Source: memfd_a (deleted).12.dr | String found in binary or memory: http:///bin/sh/tmp/shbusybox0.0.0.0recvmsgsendmsgconnectlookup |
Source: unknown | Network traffic detected: HTTP traffic on port 43928 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 42836 -> 443 |
Source: classification engine | Classification label: mal48.linELF@0/1@0/0 |
Source: ELF file section | Dropped file: memfd_a (deleted).12.dr |
Source: /tmp/qeekk7ISVq.elf (PID: 6240) | File written: /memfd:a (deleted) | Jump to dropped file |
Source: ELF symbol in initial sample | Symbol name: sleep |
Source: /tmp/qeekk7ISVq.elf (PID: 6240) | Queries kernel information via 'uname': | Jump to behavior |
Source: /memfd:a (deleted)/ (PID: 6240) | Queries kernel information via 'uname': | Jump to behavior |
Source: memfd_a (deleted).12.dr | Binary or memory string: short buffermultipathtcp127.0.0.1:53no such hostCIDR addressunknown portinvalid portimage/x-iconContent-TypeCookie.Valuecontent-typemax-forwardshttp2debug=1http2debug=2out of range100-continuerecv_goaway_status code Multi-StatusNot ModifiedUnauthorizedI'm a teapotNot ExtendedproxyconnectPUSH_PROMISECONTINUATIONsweepWaiterstraceStringsspanSetSpinemspanSpecialgcBitsArenasmheapSpecialgcpacertracemadvdontneedharddecommitdumping heapchan receivecan't happenlfstack.pushbad flushGentimer_deletebad recoverybad g statusentersyscallcas64 failedGOTRACEBACK=abi mismatch has no name has no typereflect.Copyillegal seekinvalid slothost is downchild exitedI/O possiblenot pollableCypro_MinoanMeetei_MayekPahawh_HmongSora_SompengSyloti_Nagri152587890625762939453125LD_PARAMS=%sudfImageDesccallback-vaross-cloudboxHeader info:oss-go-temp-%s://%s%s?%saudio/x-aiffaudio/amr-wbimage/x-calsaudio/melodyaudio/x-epactext/x-vcardlinux-openrcunix-systemv/etc/inittabOpenRCScript/etc/init.d/LogDirectory/proc/1/commReloadSignalthreadcreateRCodeSuccessRCodeRefusedremote errorc hs traffics hs trafficc ap traffics ap trafficclose notifyMime-VersionX-ImforwardsX-Powered-By/dev/urandomrandautoseed (sensitive)> but have <invalid kind/var/run/logDuration: %vtcmalloc::.*{{continue}}block clauseInstAltMatchunexpected )altmatch -> anynotnl -> ECDSA-SHA256ECDSA-SHA384ECDSA-SHA512SSL_CERT_DIRinvalid basecaller error/.XauthoritySequence: %dBadValue: %dDrawable: %dCompletion {Colormap: %dKeyRelease {MapRequest {NoExposure {BadRequest {Property: %dAMDisbetter!AuthenticAMDCentaurHaulsGenuineIntelTransmetaCPUGenuineTMx86Geode by NSCVIA VIA VIA KVMKVMKVMKVMMicrosoft HvVMwareVMwareXenVMMXenVMMbhyve bhyve HygonGenuineVortex86 SoCSiS SiS SiS RiseRiseRiseGenuine RDCSERIALNUMBERavx5124fmapsavx512bitalg[kworker/0:2]stop signal: Authorizationmysql_close1receive errormux: Pack errlame referral/etc/servicesAccept-RangesIf-None-MatchLast-Modified[FrameHeader invalid base accept-rangesauthorizationcache-controlcontent-rangeif-none-matchlast-modifiedCache-ControlFQDN too longsocks connectReset ContentLoop DetectedSTREAM_CLOSEDCONNECT_ERRORWINDOW_UPDATEprofMemActiveprofMemFuturetraceStackTabGC sweep waitSIGQUIT: quitSIGKILL: killout of memory is nil, not value method bad map state, not pointerdouble unlockmin too largetimer_settimeload64 failedxadd64 failedxchg64 failednil stackbase/etc/zoneinfoparsing time out of range is too largedalTLDpSugct?level 3 resetexchange fulltimer expiredsrmoun |