Source: unknown |
UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown |
UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: global traffic |
DNS traffic detected: DNS query: daisy.ubuntu.com |
Source: Initial sample |
String containing 'busybox' found: busybox_main |
Source: Initial sample |
String containing 'busybox' found: _fini__uClibc_mainbb_applet_namerun_applet_by_namebb_error_msg_and_diebeen_there_done_thatstderrbb_msg_full_versionappletsfputsbb_strlenmemmovememsetusage_messagesstrcmpbsearchfind_applet_by_namebb_show_usagebusybox_maintest_maincat_mainchmod_mainchown_mainclear_maincp_maindate_maindf_maindu_mainecho_mainenv_mainfalse_mainhalt_mainhostname_mainifconfig_maininit_maininsmod_mainkill_mainln_mainls_mainlsmod_mainmesg_mainmkdir_mainmknod_mainmodprobe_mainmore_mainmsh_mainmv_mainnetstat_mainnslookup_mainping_mainpoweroff_mainps_mainpwd_mainreboot_mainreset_mainrm_mainrmdir_mainrmmod_mainstart_stop_daemon_mainstty_maintail_maintelnet_maintftp_maintop_maintouch_maintrue_mainumount_mainuname_mainuptime_mainwhoami_mainbb_getopt_ulflagsoptindbb_wfopen_inputfilenobb_copyfd_eofbb_fclose_nonstdinbb_parse_modechmodbb_perror_msgrecursive_actionlchownstrchrget_ug_idmy_getgrnammy_getpwnamlstatcp_mv_stat2cp_mv_statbb_get_last_path_componentconcat_path_filecopy_filefreebb_opt_complementalyputenvbb_perror_msg_and_dielocaltimememc |
Source: classification engine |
Classification label: clean1.linELF@0/0@2/0 |
Source: /tmp/tftp.elf (PID: 5431) |
Queries kernel information via 'uname': |
Jump to behavior |
Source: tftp.elf, 5431.1.000055a3bb616000.000055a3bb67a000.rw-.sdmp |
Binary or memory string: U!/etc/qemu-binfmt/mips |
Source: tftp.elf, 5431.1.000055a3bb616000.000055a3bb67a000.rw-.sdmp |
Binary or memory string: /etc/qemu-binfmt/mips |
Source: tftp.elf, 5431.1.00007ffc4da1b000.00007ffc4da3c000.rw-.sdmp |
Binary or memory string: /usr/bin/qemu-mips |
Source: tftp.elf, 5431.1.00007ffc4da1b000.00007ffc4da3c000.rw-.sdmp |
Binary or memory string: x86_64/usr/bin/qemu-mips/tmp/tftp.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/tftp.elf |