Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
linux_mips64el_softfloat.elf

Overview

General Information

Sample name:linux_mips64el_softfloat.elf
Analysis ID:1546468
MD5:006fe86e7c4b72bd8625d87b69d5ffe6
SHA1:f56e08fd9b40da25535fa6e38e1fc97914999bdd
SHA256:a5ad53df08876877c86a4044b1662770570cfedb87f27ff15aa0c2f65650ed7e
Tags:elfuser-abuse_ch
Infos:

Detection

Chaos
Score:56
Range:0 - 100
Whitelisted:false

Signatures

Multi AV Scanner detection for submitted file
Yara detected Chaos
Executes the "rm" command used to delete files or directories
Sample has stripped symbol table
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1546468
Start date and time:2024-11-01 00:02:07 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 37s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:linux_mips64el_softfloat.elf
Detection:MAL
Classification:mal56.troj.linELF@0/2@0/0
  • VT rate limit hit for: linux_mips64el_softfloat.elf
Command:/tmp/linux_mips64el_softfloat.elf
PID:6229
Exit Code:2
Exit Code Info:
Killed:False
Standard Output:

Standard Error:fatal error: sigaction failed

runtime stack:
runtime.throw({0x39ae60, 0x10})
/usr/lib/go-1.18/src/runtime/panic.go:992 +0x6c
runtime.sysSigaction.func1()
/usr/lib/go-1.18/src/runtime/os_linux.go:529 +0x4c
runtime.sysSigaction(0x41, 0x4000800ba0, 0x0)
/usr/lib/go-1.18/src/runtime/os_linux.go:528 +0x88
runtime.sigaction(0x41, 0x4000800ba0, 0x0)
/usr/lib/go-1.18/src/runtime/sigaction.go:15 +0x28
runtime.setsig(0x41, 0x6ecf0)
/usr/lib/go-1.18/src/runtime/os_linux.go:478 +0xb0
runtime.initsig(0x0)
/usr/lib/go-1.18/src/runtime/signal_unix.go:147 +0x348
runtime.mstartm0()
/usr/lib/go-1.18/src/runtime/proc.go:1442 +0x78
runtime.mstart1()
/usr/lib/go-1.18/src/runtime/proc.go:1414 +0x94
runtime.mstart0()
/usr/lib/go-1.18/src/runtime/proc.go:1376 +0x74
runtime.mstart()
/usr/lib/go-1.18/src/runtime/asm_mips64x.s:88 +0x10

goroutine 1 [runnable]:
runtime.main()
/usr/lib/go-1.18/src/runtime/proc.go:145
runtime.goexit()
/usr/lib/go-1.18/src/runtime/asm_mips64x.s:617 +0x4
  • system is lnxubuntu20
  • dash New Fork (PID: 6263, Parent: 4331)
  • rm (PID: 6263, Parent: 4331, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.LkCmKdQBBO /tmp/tmp.MMImyIRFhD /tmp/tmp.7Yjo1CueSR
  • dash New Fork (PID: 6264, Parent: 4331)
  • rm (PID: 6264, Parent: 4331, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.LkCmKdQBBO /tmp/tmp.MMImyIRFhD /tmp/tmp.7Yjo1CueSR
  • sshd New Fork (PID: 6286, Parent: 936)
  • sshd (PID: 6286, Parent: 936, MD5: dbca7a6bbf7bf57fedac243d4b2cb340) Arguments: /usr/sbin/sshd -D -R
  • sshd New Fork (PID: 6293, Parent: 936)
  • sshd (PID: 6293, Parent: 936, MD5: dbca7a6bbf7bf57fedac243d4b2cb340) Arguments: /usr/sbin/sshd -D -R
    • sshd New Fork (PID: 6294, Parent: 6293)
  • sshd New Fork (PID: 6297, Parent: 936)
  • sshd (PID: 6297, Parent: 936, MD5: dbca7a6bbf7bf57fedac243d4b2cb340) Arguments: /usr/sbin/sshd -D -R
    • sshd New Fork (PID: 6298, Parent: 6297)
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
ChaosMulti-functional malware written in Go, targeting both Linux and Windows, evolved from elf.kaiji.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/elf.chaos
SourceRuleDescriptionAuthorStrings
linux_mips64el_softfloat.elfJoeSecurity_ChaosGoYara detected ChaosJoe Security
    No Suricata rule has matched

    Click to jump to signature section

    Show All Signature Results

    AV Detection

    barindex
    Source: linux_mips64el_softfloat.elfReversingLabs: Detection: 52%
    Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
    Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
    Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
    Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
    Source: unknownTCP traffic detected without corresponding DNS query: 54.171.230.55
    Source: unknownTCP traffic detected without corresponding DNS query: 54.171.230.55
    Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
    Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
    Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
    Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
    Source: linux_mips64el_softfloat.elfString found in binary or memory: http2: Transport conn %p received error from processing frame %v: %vhttp2: Transport received unsolicited DATA frame; closing connectionhttp: message cannot contain multiple Content-Length headers; got %qpadding bytes must all be zeros unless AllowIllegalWrites is enabledreflect: reflect.Value.UnsafePointer on an invalid notinheap pointerhttp2: Transport closing idle conn %p (forSingleUse=%v, maxStream=%v)tls: handshake message of length %d bytes exceeds maximum of %d bytestls: peer doesn't support the certificate custom signature algorithmsbytes.Buffer: UnreadByte: previous operation was not a successful readcannot convert slice with length %y to pointer to array with length %xgot %s for stream %d; expected CONTINUATION following %s for stream %dx509: PKCS#8 wrapping contained private key with unknown algorithm: %vx509: certificate relies on legacy Common Name field, use SANs insteadMozilla/5.0 (compatible; bingbot/2.0; +http://www.bing.com/bingbot.htm)Sogou Pic Spider/3.0(+http://www.sogou.com/docs/help/webmasters.htm#07)Sogou web spider/4.0(+http://www.sogou.com/docs/help/webmasters.htm#07)dynamic table size update MUST occur at the beginning of a header blockssh: no common algorithm for %s; client offered: %v, server offered: %vtls: peer doesn't support any of the certificate's signature algorithmstoo many concurrent operations on a single file or socket (max 1048575)x509: issuer has name constraints but leaf doesn't have a SAN extensionMozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)tls: server's certificate contains an unsupported type of public key: %Ttls: received unexpected handshake message of type %T when waiting for %T91289437fa036b34da55d57af6192768c27bd433fa012169d626d934e0051b24dd67dd3cf49d7cc827bc012d259d7ac226e70829239d7ac226e7082968de60d520eb433722c07fd236f6crypto/elliptic: internal error: Unmarshal rejected a valid point encodingmalformed response from server: malformed non-numeric status pseudo headernet/http: server replied with more than declared Content-Length; truncatedtls: certificate RSA key size too small for supported signature algorithmsUnsolicited response received on idle HTTP channel starting with %q; err=%vtls: internal error: attempted to read record with pending application datatls: failed to send closeNotify alert (but connection was closed anyway): %wtls: server certificate contains incorrect key type for selected ciphersuite((2(5[0-5]|[0-4]\d))|[0-1]?\d{1,2})(\.((2(5[0-5]|[0-4]\d))|[0-1]?\d{1,2})){3}MapIter.Next called on an iterator that does not have an associated map Valuecrypto/tls: ExportKeyingMaterial is unavailable when renegotiation is enabled115792089210356248762697446949407573529996955224135760342422259061068512044369115792089210356248762697446949407573530086143415290314195533631308867097853951ssh: internal error: algorithmSignerWrapper invoked with non-default algorithmssh: unable to authenticate, attempted methods %v, no supported methods remainx509: signature check attempt
    Source: linux_mips64el_softfloat.elfString found in binary or memory: http: RoundTripper implementation (%T) returned a nil *Response with a nil errortls: either ServerName or InsecureSkipVerify must be specified in the tls.Configx509: invalid signature: parent certificate cannot sign this kind of certificaterefusing to use HTTP_PROXY value in CGI environment; see golang.org/s/cgihttpproxyx509: a root or intermediate certificate is not authorized to sign for this name: (possibly because of %q while trying to verify candidate authority certificate %q)Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)Mozilla/5.0 (compatible; Yahoo! Slurp; http://help.yahoo.com/help/us/ysearch/slurp)x509: issuer has name constraints but leaf contains unknown or unconstrained name: tls: downgrade attempt detected, possibly due to a MitM attack or a broken middleboxx509: signature algorithm specifies an %s public key, but have public key of type %Treflect.Value.Interface: cannot return value obtained from unexported field or methodx509: failed to parse private key (use ParseECPrivateKey instead for this key format)Mozilla/5.0 (compatible; YoudaoBot/1.0; http://www.youdao.com/help/webmaster/spider/;)reflect: New of type that may not be allocated in heap (possibly undefined cgo C type)x509: a root or intermediate certificate is not authorized for an extended key usage: fxfzUc6gtMGc/i26ld3KydGKy1k7QqyMMyxjbU1Rlk+F9LQxnaTeCHGHsDUpaBeOWDeY6l+2kHlB7EWTLcGwfg==whv+Kf1cEtOXzr+zuvmef2as0WfbUDm8l2LMWBMel10NDnbShg9CsMUt327VJhOTbXLoPYJVTKy8MBPCVwoT8A==x509: failed to parse private key (use ParsePKCS1PrivateKey instead for this key format)x509: failed to parse private key (use ParsePKCS8PrivateKey instead for this key format)Mozilla/5.0 (compatible; Baiduspider-render/2.0; +http://www.baidu.com/search/spider.html)http2: server sent GOAWAY and closed the connection; LastStreamID=%v, ErrCode=%v, debug=%qapplication/xml,application/xhtml+xml,text/html;q=0.9, text/plain;q=0.8,image/png,*/*;q=0.5tls: handshake hash for a client certificate requested after discarding the handshake buffertls: unsupported certificate: private key is *ed25519.PrivateKey, expected ed25519.PrivateKey3617de4a96262c6f5d9e98bf9292dc29f8f41dbd289a147ce9da3113b5f0b8c00a60b1ce1d7e819d7a431d7c90ea0e5faa87ca22be8b05378eb1c71ef320ad746e1d3b628ba79b9859f741e082542a385502f25dbf55296c3a545e3872760ab7b3312fa7e23ee7e4988e056be3f82d19181d9c6efe8141120314088f5013875ac656398d8a2ed19d2a85c8edd3ec2aefhttp: RoundTripper implementation (%T) returned a *Response with content length %d but a nil BodyNoClientCertRequestClientCertRequireAnyClientCertVerifyClientCertIfGivenRequireAndVerifyClientCertcipher: the nonce can't have zero length, or the security of the key will be immediately compromised1.0.3<<RMS>> equals www.yahoo.com (Yahoo)
    Source: linux_mips64el_softfloat.elfString found in binary or memory: http://help.yahoo.com/help/us/ysearch/slurp)x509:
    Source: linux_mips64el_softfloat.elfString found in binary or memory: http://search.msn.com/msnbot.htm
    Source: linux_mips64el_softfloat.elfString found in binary or memory: http://www.baidu.com/search/spider.html)
    Source: linux_mips64el_softfloat.elfString found in binary or memory: http://www.baidu.com/search/spider.html)000102030405060708091011121314151617181920212223242526272829
    Source: linux_mips64el_softfloat.elfString found in binary or memory: http://www.baidu.com/search/spider.html)Mozilla/5.0
    Source: linux_mips64el_softfloat.elfString found in binary or memory: http://www.baidu.com/search/spider.html)http2:
    Source: linux_mips64el_softfloat.elfString found in binary or memory: http://www.entireweb.com/about/search_tech/speedy_spider/)text/html
    Source: linux_mips64el_softfloat.elfString found in binary or memory: http://www.google.com/mobile/adsbot.html)
    Source: linux_mips64el_softfloat.elfString found in binary or memory: http://www.haosou.com/help/help_3_2.htmlMozilla/5.0
    Source: linux_mips64el_softfloat.elfString found in binary or memory: http://www.huaweisymantec.com/cn/IRL/spider)Mozilla/5.0
    Source: linux_mips64el_softfloat.elfString found in binary or memory: http://www.youdao.com/help/webmaster/spider/;)reflect:
    Source: linux_mips64el_softfloat.elfString found in binary or memory: http://yandex.com/bots)http:
    Source: linux_mips64el_softfloat.elfString found in binary or memory: https://search.yahoo.com/search?p=illegal
    Source: linux_mips64el_softfloat.elfString found in binary or memory: https://www.baidu.com/s?wd=insufficient
    Source: linux_mips64el_softfloat.elfString found in binary or memory: https://www.so.com/s?q=index
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 33606
    Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 33606 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443
    Source: ELF static info symbol of initial sample.symtab present: no
    Source: classification engineClassification label: mal56.troj.linELF@0/2@0/0
    Source: ELF file sectionSubmission: linux_mips64el_softfloat.elf
    Source: /usr/bin/dash (PID: 6263)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.LkCmKdQBBO /tmp/tmp.MMImyIRFhD /tmp/tmp.7Yjo1CueSRJump to behavior
    Source: /usr/bin/dash (PID: 6264)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.LkCmKdQBBO /tmp/tmp.MMImyIRFhD /tmp/tmp.7Yjo1CueSRJump to behavior
    Source: /tmp/linux_mips64el_softfloat.elf (PID: 6229)Queries kernel information via 'uname': Jump to behavior
    Source: linux_mips64el_softfloat.elf, 6229.1.00007ffc29f90000.00007ffc29fb1000.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-mips64el/tmp/linux_mips64el_softfloat.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/linux_mips64el_softfloat.elf
    Source: linux_mips64el_softfloat.elf, 6229.1.00007ffc29f90000.00007ffc29fb1000.rw-.sdmpBinary or memory string: /usr/bin/qemu-mips64el
    Source: linux_mips64el_softfloat.elf, 6229.1.000055d30fbdd000.000055d30ff52000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/mips64el
    Source: linux_mips64el_softfloat.elf, 6229.1.000055d30fbdd000.000055d30ff52000.rw-.sdmpBinary or memory string: U1MIPS64R2-generic-mips64-cpu1/etc/qemu-binfmt/mips64elu

    Stealing of Sensitive Information

    barindex
    Source: Yara matchFile source: linux_mips64el_softfloat.elf, type: SAMPLE

    Remote Access Functionality

    barindex
    Source: Yara matchFile source: linux_mips64el_softfloat.elf, type: SAMPLE
    ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
    Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception1
    File Deletion
    OS Credential Dumping11
    Security Software Discovery
    Remote ServicesData from Local System1
    Encrypted Channel
    Exfiltration Over Other Network MediumAbuse Accessibility Features
    CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
    Application Layer Protocol
    Exfiltration Over BluetoothNetwork Denial of Service
    No configs have been found
    Hide Legend

    Legend:

    • Process
    • Signature
    • Created File
    • DNS/IP Info
    • Is Dropped
    • Number of created Files
    • Is malicious
    • Internet
    behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1546468 Sample: linux_mips64el_softfloat.elf Startdate: 01/11/2024 Architecture: LINUX Score: 56 19 109.202.202.202, 80 INIT7CH Switzerland 2->19 21 91.189.91.42, 443 CANONICAL-ASGB United Kingdom 2->21 23 2 other IPs or domains 2->23 25 Multi AV Scanner detection for submitted file 2->25 27 Yara detected Chaos 2->27 7 sshd sshd 2->7         started        9 sshd sshd 2->9         started        11 dash rm 2->11         started        13 3 other processes 2->13 signatures3 process4 process5 15 sshd 7->15         started        17 sshd 9->17         started       
    SourceDetectionScannerLabelLink
    linux_mips64el_softfloat.elf53%ReversingLabsLinux.Trojan.Kaiji
    No Antivirus matches
    No Antivirus matches
    No Antivirus matches
    No contacted domains info
    NameSourceMaliciousAntivirus DetectionReputation
    http://www.baidu.com/search/spider.html)linux_mips64el_softfloat.elffalse
      unknown
      http://search.msn.com/msnbot.htmlinux_mips64el_softfloat.elffalse
        unknown
        http://www.baidu.com/search/spider.html)000102030405060708091011121314151617181920212223242526272829linux_mips64el_softfloat.elffalse
          unknown
          https://www.so.com/s?q=indexlinux_mips64el_softfloat.elffalse
            unknown
            http://help.yahoo.com/help/us/ysearch/slurp)x509:linux_mips64el_softfloat.elffalse
              unknown
              http://www.google.com/mobile/adsbot.html)linux_mips64el_softfloat.elffalse
                unknown
                http://www.huaweisymantec.com/cn/IRL/spider)Mozilla/5.0linux_mips64el_softfloat.elffalse
                  unknown
                  http://www.baidu.com/search/spider.html)http2:linux_mips64el_softfloat.elffalse
                    unknown
                    http://yandex.com/bots)http:linux_mips64el_softfloat.elffalse
                      unknown
                      http://www.baidu.com/search/spider.html)Mozilla/5.0linux_mips64el_softfloat.elffalse
                        unknown
                        http://www.entireweb.com/about/search_tech/speedy_spider/)text/htmllinux_mips64el_softfloat.elffalse
                          unknown
                          http://www.haosou.com/help/help_3_2.htmlMozilla/5.0linux_mips64el_softfloat.elffalse
                            unknown
                            https://www.baidu.com/s?wd=insufficientlinux_mips64el_softfloat.elffalse
                              unknown
                              http://www.youdao.com/help/webmaster/spider/;)reflect:linux_mips64el_softfloat.elffalse
                                unknown
                                https://search.yahoo.com/search?p=illegallinux_mips64el_softfloat.elffalse
                                  unknown
                                  • No. of IPs < 25%
                                  • 25% < No. of IPs < 50%
                                  • 50% < No. of IPs < 75%
                                  • 75% < No. of IPs
                                  IPDomainCountryFlagASNASN NameMalicious
                                  54.171.230.55
                                  unknownUnited States
                                  16509AMAZON-02USfalse
                                  109.202.202.202
                                  unknownSwitzerland
                                  13030INIT7CHfalse
                                  91.189.91.43
                                  unknownUnited Kingdom
                                  41231CANONICAL-ASGBfalse
                                  91.189.91.42
                                  unknownUnited Kingdom
                                  41231CANONICAL-ASGBfalse
                                  MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                  54.171.230.55x.rar.elfGet hashmaliciousXmrigBrowse
                                    tyo2831qq.arm7.elfGet hashmaliciousGafgyt, MiraiBrowse
                                      tyo2831qq.m68k.elfGet hashmaliciousGafgyt, MiraiBrowse
                                        .i.elfGet hashmaliciousUnknownBrowse
                                          la.bot.sh4.elfGet hashmaliciousUnknownBrowse
                                            la.bot.mipsel.elfGet hashmaliciousUnknownBrowse
                                              ppc.elfGet hashmaliciousUnknownBrowse
                                                zmap.x86_64.elfGet hashmaliciousOkiruBrowse
                                                  na.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                    qkehusl.elfGet hashmaliciousGafgyt, Mirai, OkiruBrowse
                                                      109.202.202.202kpLwzBouH4.elfGet hashmaliciousUnknownBrowse
                                                      • ch.archive.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_92.0%2bbuild3-0ubuntu0.20.04.1_amd64.deb
                                                      91.189.91.43linux_amd64.elfGet hashmaliciousChaosBrowse
                                                        .i.elfGet hashmaliciousUnknownBrowse
                                                          linux_arm6.elfGet hashmaliciousChaosBrowse
                                                            linux_mips64.elfGet hashmaliciousChaosBrowse
                                                              linux_arm5.elfGet hashmaliciousChaosBrowse
                                                                Mozi.m.elfGet hashmaliciousUnknownBrowse
                                                                  x.rar.elfGet hashmaliciousXmrigBrowse
                                                                    boatnet.arm.elfGet hashmaliciousMiraiBrowse
                                                                      boatnet.m68k.elfGet hashmaliciousMiraiBrowse
                                                                        boatnet.x86.elfGet hashmaliciousMiraiBrowse
                                                                          91.189.91.42linux_amd64.elfGet hashmaliciousChaosBrowse
                                                                            .i.elfGet hashmaliciousUnknownBrowse
                                                                              linux_arm6.elfGet hashmaliciousChaosBrowse
                                                                                linux_mips64.elfGet hashmaliciousChaosBrowse
                                                                                  linux_arm5.elfGet hashmaliciousChaosBrowse
                                                                                    Mozi.m.elfGet hashmaliciousUnknownBrowse
                                                                                      x.rar.elfGet hashmaliciousXmrigBrowse
                                                                                        boatnet.arm.elfGet hashmaliciousMiraiBrowse
                                                                                          boatnet.m68k.elfGet hashmaliciousMiraiBrowse
                                                                                            boatnet.x86.elfGet hashmaliciousMiraiBrowse
                                                                                              No context
                                                                                              MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                                              CANONICAL-ASGBlinux_amd64.elfGet hashmaliciousChaosBrowse
                                                                                              • 91.189.91.42
                                                                                              .i.elfGet hashmaliciousUnknownBrowse
                                                                                              • 91.189.91.42
                                                                                              linux_arm6.elfGet hashmaliciousChaosBrowse
                                                                                              • 91.189.91.42
                                                                                              linux_mips64.elfGet hashmaliciousChaosBrowse
                                                                                              • 91.189.91.42
                                                                                              linux_arm5.elfGet hashmaliciousChaosBrowse
                                                                                              • 91.189.91.42
                                                                                              Mozi.m.elfGet hashmaliciousUnknownBrowse
                                                                                              • 91.189.91.42
                                                                                              x.rar.elfGet hashmaliciousXmrigBrowse
                                                                                              • 91.189.91.42
                                                                                              boatnet.arm6.elfGet hashmaliciousMiraiBrowse
                                                                                              • 185.125.190.26
                                                                                              boatnet.arm.elfGet hashmaliciousMiraiBrowse
                                                                                              • 91.189.91.42
                                                                                              boatnet.mpsl.elfGet hashmaliciousMiraiBrowse
                                                                                              • 185.125.190.26
                                                                                              CANONICAL-ASGBlinux_amd64.elfGet hashmaliciousChaosBrowse
                                                                                              • 91.189.91.42
                                                                                              .i.elfGet hashmaliciousUnknownBrowse
                                                                                              • 91.189.91.42
                                                                                              linux_arm6.elfGet hashmaliciousChaosBrowse
                                                                                              • 91.189.91.42
                                                                                              linux_mips64.elfGet hashmaliciousChaosBrowse
                                                                                              • 91.189.91.42
                                                                                              linux_arm5.elfGet hashmaliciousChaosBrowse
                                                                                              • 91.189.91.42
                                                                                              Mozi.m.elfGet hashmaliciousUnknownBrowse
                                                                                              • 91.189.91.42
                                                                                              x.rar.elfGet hashmaliciousXmrigBrowse
                                                                                              • 91.189.91.42
                                                                                              boatnet.arm6.elfGet hashmaliciousMiraiBrowse
                                                                                              • 185.125.190.26
                                                                                              boatnet.arm.elfGet hashmaliciousMiraiBrowse
                                                                                              • 91.189.91.42
                                                                                              boatnet.mpsl.elfGet hashmaliciousMiraiBrowse
                                                                                              • 185.125.190.26
                                                                                              AMAZON-02UShttps://www.dropbox.com/l/scl/AAATBuomd5HmxEQWOFFl7juYr5pumA9OT78Get hashmaliciousUnknownBrowse
                                                                                              • 34.249.87.52
                                                                                              https://www.dropbox.com/l/scl/AAATBuomd5HmxEQWOFFl7juYr5pumA9OT78Get hashmaliciousUnknownBrowse
                                                                                              • 143.204.95.12
                                                                                              https://www.dropbox.com/l/scl/AAATBuomd5HmxEQWOFFl7juYr5pumA9OT78Get hashmaliciousUnknownBrowse
                                                                                              • 143.204.95.12
                                                                                              https://www.dropbox.com/scl/fi/ghbickob35cseupehrevo/A-file-has-been-sent-to-you-via-DROPBOX.pdf?oref=e&r=ACTqvRbsSp0aGfWJ258Mnmig2JSiZYPEXawWQbeoOGqhLQ0A_g08q_6x9uCS3GDD06X2I92wp1DOmKpzocpy-33mPeFHFTHNUnOplz6Tt7UNKnGCY5hdeIU9t4fHEX4CzcseX3o9vxkcg76RpGddDTfgU6DIWzrB6Y3NN3SHwd0oXjHE8-2WVTMkcFhAlN56hFRzwFRs7uWEYIbpWWN2yfXr&sm=1&dl=0Get hashmaliciousUnknownBrowse
                                                                                              • 143.204.95.12
                                                                                              https://www.phsinc.com/?bwfan-track-action=click&bwfan-track-id=0ecdd1bdf2276cad3fa2d27ffa918e84&bwfan-uid=e2dffed46dd69d19d18bc527d6255bd5&bwfan-link=%68%74%74%70%73%3A%2F%2F%6D%61%69%6C%2E%72%69%67%6F%74%69%6C%65%73%2E%63%6F%6D%2F%6A%50%73%51%57%55%63%42Get hashmaliciousHTMLPhisher, ReCaptcha PhishBrowse
                                                                                              • 3.132.253.175
                                                                                              file.exeGet hashmaliciousStealc, VidarBrowse
                                                                                              • 18.238.171.119
                                                                                              https://hotmail.pizza4you.com.br/Get hashmaliciousMamba2FABrowse
                                                                                              • 13.227.219.11
                                                                                              x.rar.elfGet hashmaliciousXmrigBrowse
                                                                                              • 54.171.230.55
                                                                                              file.exeGet hashmaliciousStealc, VidarBrowse
                                                                                              • 18.244.18.32
                                                                                              El9HaBFrFM.exeGet hashmaliciousBlank GrabberBrowse
                                                                                              • 54.170.20.205
                                                                                              INIT7CHlinux_amd64.elfGet hashmaliciousChaosBrowse
                                                                                              • 109.202.202.202
                                                                                              .i.elfGet hashmaliciousUnknownBrowse
                                                                                              • 109.202.202.202
                                                                                              linux_arm6.elfGet hashmaliciousChaosBrowse
                                                                                              • 109.202.202.202
                                                                                              linux_mips64.elfGet hashmaliciousChaosBrowse
                                                                                              • 109.202.202.202
                                                                                              linux_arm5.elfGet hashmaliciousChaosBrowse
                                                                                              • 109.202.202.202
                                                                                              Mozi.m.elfGet hashmaliciousUnknownBrowse
                                                                                              • 109.202.202.202
                                                                                              x.rar.elfGet hashmaliciousXmrigBrowse
                                                                                              • 109.202.202.202
                                                                                              boatnet.arm.elfGet hashmaliciousMiraiBrowse
                                                                                              • 109.202.202.202
                                                                                              boatnet.m68k.elfGet hashmaliciousMiraiBrowse
                                                                                              • 109.202.202.202
                                                                                              boatnet.x86.elfGet hashmaliciousMiraiBrowse
                                                                                              • 109.202.202.202
                                                                                              No context
                                                                                              No context
                                                                                              Process:/usr/sbin/sshd
                                                                                              File Type:data
                                                                                              Category:dropped
                                                                                              Size (bytes):384
                                                                                              Entropy (8bit):0.8735982127940438
                                                                                              Encrypted:false
                                                                                              SSDEEP:3:SXNfuaDLwbUylPCXlN4lt:wNfPMbUyl61GX
                                                                                              MD5:F77A67AFC5BD1B697C7AEDB43A8C0D0C
                                                                                              SHA1:C9C3B4CB3A852C8DAEC7EBAD597D1CBD9772C852
                                                                                              SHA-256:68F912A0ED073455B16DC5E894EFB02D40CBE933D2B7EB2C6DAC62DC25F82799
                                                                                              SHA-512:D29AADB9A85086822F4C9450B8CBCA1EB67270A897C95930BD7063E33EE6095F6518E00CBC3BE1DA2182F5DBA2202346E1B4C0C54D58F11CF217D4E30C821631
                                                                                              Malicious:false
                                                                                              Reputation:low
                                                                                              Preview:........ssh:notty...........................root............................192.168.2.13..............................................................................................................................................................................................................................................................$g........................................
                                                                                              File type:ELF 64-bit LSB executable, MIPS, MIPS-III version 1 (SYSV), statically linked, Go BuildID=OV9vJ_v-2bk2dNGiGNDb/tPrAvdGyl8BJf7x33Esm/iDXarW29IcMj1bLws34V/gUJG7wBB8_mq3uT_Ccfc, stripped
                                                                                              Entropy (8bit):5.374974260830418
                                                                                              TrID:
                                                                                              • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                                                                                              File name:linux_mips64el_softfloat.elf
                                                                                              File size:5'963'776 bytes
                                                                                              MD5:006fe86e7c4b72bd8625d87b69d5ffe6
                                                                                              SHA1:f56e08fd9b40da25535fa6e38e1fc97914999bdd
                                                                                              SHA256:a5ad53df08876877c86a4044b1662770570cfedb87f27ff15aa0c2f65650ed7e
                                                                                              SHA512:31a03189512ca40f5ed45725bca728a63f8cfddea51068eadaeece42175e9c1a46250350840585f8f3a2eed090e65f023948ee65f90c349eebb15ab21116d11a
                                                                                              SSDEEP:98304:Z9mVusEEQ4kVIb0IamIIkmrIGDeII8jOSPWo:bu8VIb0IamIIkmrIGDeII8HWo
                                                                                              TLSH:CF560902EEC26E66C5CC037485FE979672507E085B951B2313A8EBA8397773DEF4684C
                                                                                              File Content Preview:.ELF............................@.................. @.8...@.............@.......@.......@...............................................................d.......d...............................................@.0.....@.0.......................1.......2....

                                                                                              ELF header

                                                                                              Class:ELF64
                                                                                              Data:2's complement, little endian
                                                                                              Version:1 (current)
                                                                                              Machine:MIPS R3000
                                                                                              Version Number:0x1
                                                                                              Type:EXEC (Executable file)
                                                                                              OS/ABI:UNIX - System V
                                                                                              ABI Version:0
                                                                                              Entry Point Address:0x8ffe0
                                                                                              Flags:0x20000004
                                                                                              ELF Header Size:64
                                                                                              Program Header Offset:64
                                                                                              Program Header Size:56
                                                                                              Number of Program Headers:7
                                                                                              Section Header Offset:456
                                                                                              Section Header Size:64
                                                                                              Number of Section Headers:14
                                                                                              Header String Table Index:3
                                                                                              NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                                                                              NULL0x00x00x00x00x0000
                                                                                              .textPROGBITS0x110000x10000x30db400x00x6AX008
                                                                                              .rodataPROGBITS0x3200000x3100000xf91140x00x2A0032
                                                                                              .shstrtabSTRTAB0x00x4091200xa50x00x0001
                                                                                              .typelinkPROGBITS0x4191e00x4091e00x17c80x00x2A0032
                                                                                              .itablinkPROGBITS0x41a9c00x40a9c00x9480x00x2A0032
                                                                                              .gosymtabPROGBITS0x41b3080x40b3080x00x00x2A001
                                                                                              .gopclntabPROGBITS0x41b3200x40b3200x14bc200x00x2A0032
                                                                                              .go.buildinfoPROGBITS0x5700000x5600000xf00x00x3WA0016
                                                                                              .noptrdataPROGBITS0x5701000x5601000x31e180x00x3WA0032
                                                                                              .dataPROGBITS0x5a1f200x591f200xfe800x00x3WA0032
                                                                                              .bssNOBITS0x5b1da00x5a1da00x301000x00x3WA0032
                                                                                              .noptrbssNOBITS0x5e1ea00x5d1ea00xf5700x00x3WA0032
                                                                                              .note.go.buildidNOTE0x10f9c0xf9c0x640x00x2A004
                                                                                              TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                                                              PHDR0x400x100400x100400x1880x1881.47520x4R 0x10000
                                                                                              NOTE0xf9c0x10f9c0x10f9c0x640x645.35720x4R 0x4.note.go.buildid
                                                                                              LOAD0x00x100000x100000x30eb400x30eb405.13620x5R E0x10000.text .note.go.buildid
                                                                                              LOAD0x3100000x3200000x3200000x246f400x246f405.39920x4R 0x10000.rodata .typelink .itablink .gosymtab .gopclntab
                                                                                              LOAD0x5600000x5700000x5700000x41da00x814105.04950x6RW 0x10000.go.buildinfo .noptrdata .data .bss .noptrbss
                                                                                              GNU_STACK0x00x00x00x00x00.00000x6RW 0x8
                                                                                              LOOS+50415800x00x00x00x00x00.00000x2a00 0x8
                                                                                              TimestampSource PortDest PortSource IPDest IP
                                                                                              Nov 1, 2024 00:02:53.300358057 CET43928443192.168.2.2391.189.91.42
                                                                                              Nov 1, 2024 00:02:58.931689978 CET42836443192.168.2.2391.189.91.43
                                                                                              Nov 1, 2024 00:02:59.955355883 CET4251680192.168.2.23109.202.202.202
                                                                                              Nov 1, 2024 00:03:14.545411110 CET43928443192.168.2.2391.189.91.42
                                                                                              Nov 1, 2024 00:03:22.585812092 CET33606443192.168.2.2354.171.230.55
                                                                                              Nov 1, 2024 00:03:22.591968060 CET4433360654.171.230.55192.168.2.23
                                                                                              Nov 1, 2024 00:03:22.592056990 CET33606443192.168.2.2354.171.230.55
                                                                                              Nov 1, 2024 00:03:24.783896923 CET42836443192.168.2.2391.189.91.43
                                                                                              Nov 1, 2024 00:03:30.927160978 CET4251680192.168.2.23109.202.202.202
                                                                                              Nov 1, 2024 00:03:55.499670982 CET43928443192.168.2.2391.189.91.42
                                                                                              Nov 1, 2024 00:04:15.977229118 CET42836443192.168.2.2391.189.91.43

                                                                                              System Behavior

                                                                                              Start time (UTC):23:02:49
                                                                                              Start date (UTC):31/10/2024
                                                                                              Path:/tmp/linux_mips64el_softfloat.elf
                                                                                              Arguments:/tmp/linux_mips64el_softfloat.elf
                                                                                              File size:5822264 bytes
                                                                                              MD5 hash:bba92fd1c51079d6ff2478396026936a

                                                                                              Start time (UTC):23:03:21
                                                                                              Start date (UTC):31/10/2024
                                                                                              Path:/usr/bin/dash
                                                                                              Arguments:-
                                                                                              File size:129816 bytes
                                                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                              Start time (UTC):23:03:21
                                                                                              Start date (UTC):31/10/2024
                                                                                              Path:/usr/bin/rm
                                                                                              Arguments:rm -f /tmp/tmp.LkCmKdQBBO /tmp/tmp.MMImyIRFhD /tmp/tmp.7Yjo1CueSR
                                                                                              File size:72056 bytes
                                                                                              MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b

                                                                                              Start time (UTC):23:03:21
                                                                                              Start date (UTC):31/10/2024
                                                                                              Path:/usr/bin/dash
                                                                                              Arguments:-
                                                                                              File size:129816 bytes
                                                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                              Start time (UTC):23:03:21
                                                                                              Start date (UTC):31/10/2024
                                                                                              Path:/usr/bin/rm
                                                                                              Arguments:rm -f /tmp/tmp.LkCmKdQBBO /tmp/tmp.MMImyIRFhD /tmp/tmp.7Yjo1CueSR
                                                                                              File size:72056 bytes
                                                                                              MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b

                                                                                              Start time (UTC):23:03:25
                                                                                              Start date (UTC):31/10/2024
                                                                                              Path:/usr/sbin/sshd
                                                                                              Arguments:-
                                                                                              File size:876328 bytes
                                                                                              MD5 hash:dbca7a6bbf7bf57fedac243d4b2cb340

                                                                                              Start time (UTC):23:03:25
                                                                                              Start date (UTC):31/10/2024
                                                                                              Path:/usr/sbin/sshd
                                                                                              Arguments:/usr/sbin/sshd -D -R
                                                                                              File size:876328 bytes
                                                                                              MD5 hash:dbca7a6bbf7bf57fedac243d4b2cb340

                                                                                              Start time (UTC):23:03:25
                                                                                              Start date (UTC):31/10/2024
                                                                                              Path:/usr/sbin/sshd
                                                                                              Arguments:-
                                                                                              File size:876328 bytes
                                                                                              MD5 hash:dbca7a6bbf7bf57fedac243d4b2cb340

                                                                                              Start time (UTC):23:03:25
                                                                                              Start date (UTC):31/10/2024
                                                                                              Path:/usr/sbin/sshd
                                                                                              Arguments:/usr/sbin/sshd -D -R
                                                                                              File size:876328 bytes
                                                                                              MD5 hash:dbca7a6bbf7bf57fedac243d4b2cb340

                                                                                              Start time (UTC):23:03:25
                                                                                              Start date (UTC):31/10/2024
                                                                                              Path:/usr/sbin/sshd
                                                                                              Arguments:-
                                                                                              File size:876328 bytes
                                                                                              MD5 hash:dbca7a6bbf7bf57fedac243d4b2cb340

                                                                                              Start time (UTC):23:03:28
                                                                                              Start date (UTC):31/10/2024
                                                                                              Path:/usr/sbin/sshd
                                                                                              Arguments:-
                                                                                              File size:876328 bytes
                                                                                              MD5 hash:dbca7a6bbf7bf57fedac243d4b2cb340

                                                                                              Start time (UTC):23:03:28
                                                                                              Start date (UTC):31/10/2024
                                                                                              Path:/usr/sbin/sshd
                                                                                              Arguments:/usr/sbin/sshd -D -R
                                                                                              File size:876328 bytes
                                                                                              MD5 hash:dbca7a6bbf7bf57fedac243d4b2cb340

                                                                                              Start time (UTC):23:03:28
                                                                                              Start date (UTC):31/10/2024
                                                                                              Path:/usr/sbin/sshd
                                                                                              Arguments:-
                                                                                              File size:876328 bytes
                                                                                              MD5 hash:dbca7a6bbf7bf57fedac243d4b2cb340