Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
nuklear.ppc.elf

Overview

General Information

Sample name:nuklear.ppc.elf
Analysis ID:1550475
MD5:93d18049882fa37b5cb2cedfa8fd8427
SHA1:2678a442e53a5d26328ca8e9ef60d7dbf8bf0312
SHA256:f87f4f186dc972e3867f69dcf2ed9401b3986293affbffe78fc22980a3910742
Tags:elfuser-abuse_ch
Infos:

Detection

Mirai, Moobot
Score:80
Range:0 - 100
Whitelisted:false

Signatures

Antivirus / Scanner detection for submitted sample
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Yara detected Mirai
Yara detected Moobot
Executes the "rm" command used to delete files or directories
Sample has stripped symbol table
Uses the "uname" system call to query kernel version information (possible evasion)
Yara signature match

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1550475
Start date and time:2024-11-06 19:02:08 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 25s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:nuklear.ppc.elf
Detection:MAL
Classification:mal80.troj.linELF@0/0@2/0
  • VT rate limit hit for: nuklear.ppc.elf
Command:/tmp/nuklear.ppc.elf
PID:5423
Exit Code:139
Exit Code Info:SIGSEGV (11) Segmentation fault invalid memory reference
Killed:False
Standard Output:

Standard Error:qemu: uncaught target signal 11 (Segmentation fault) - core dumped
  • system is lnxubuntu20
  • nuklear.ppc.elf (PID: 5423, Parent: 5348, MD5: ae65271c943d3451b7f026d1fadccea6) Arguments: /tmp/nuklear.ppc.elf
  • dash New Fork (PID: 5458, Parent: 3586)
  • rm (PID: 5458, Parent: 3586, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.NSkCGimJ5W /tmp/tmp.kbWlMzuLrP /tmp/tmp.DBfmWT8WVO
  • dash New Fork (PID: 5459, Parent: 3586)
  • cat (PID: 5459, Parent: 3586, MD5: 7e9d213e404ad3bb82e4ebb2e1f2c1b3) Arguments: cat /tmp/tmp.NSkCGimJ5W
  • dash New Fork (PID: 5460, Parent: 3586)
  • head (PID: 5460, Parent: 3586, MD5: fd96a67145172477dd57131396fc9608) Arguments: head -n 10
  • dash New Fork (PID: 5461, Parent: 3586)
  • tr (PID: 5461, Parent: 3586, MD5: fbd1402dd9f72d8ebfff00ce7c3a7bb5) Arguments: tr -d \\000-\\011\\013\\014\\016-\\037
  • dash New Fork (PID: 5462, Parent: 3586)
  • cut (PID: 5462, Parent: 3586, MD5: d8ed0ea8f22c0de0f8692d4d9f1759d3) Arguments: cut -c -80
  • dash New Fork (PID: 5463, Parent: 3586)
  • cat (PID: 5463, Parent: 3586, MD5: 7e9d213e404ad3bb82e4ebb2e1f2c1b3) Arguments: cat /tmp/tmp.NSkCGimJ5W
  • dash New Fork (PID: 5464, Parent: 3586)
  • head (PID: 5464, Parent: 3586, MD5: fd96a67145172477dd57131396fc9608) Arguments: head -n 10
  • dash New Fork (PID: 5465, Parent: 3586)
  • tr (PID: 5465, Parent: 3586, MD5: fbd1402dd9f72d8ebfff00ce7c3a7bb5) Arguments: tr -d \\000-\\011\\013\\014\\016-\\037
  • dash New Fork (PID: 5466, Parent: 3586)
  • cut (PID: 5466, Parent: 3586, MD5: d8ed0ea8f22c0de0f8692d4d9f1759d3) Arguments: cut -c -80
  • dash New Fork (PID: 5467, Parent: 3586)
  • rm (PID: 5467, Parent: 3586, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.NSkCGimJ5W /tmp/tmp.kbWlMzuLrP /tmp/tmp.DBfmWT8WVO
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
MiraiMirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese. Nowadays it targets a wide range of networked embedded devices such as IP cameras, home routers (many vendors involved), and other IoT devices. Since the source code was published on "Hack Forums" many variants of the Mirai family appeared, infecting mostly home networks all around the world.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/elf.mirai
NameDescriptionAttributionBlogpost URLsLink
MooBotNo Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/elf.moobot
SourceRuleDescriptionAuthorStrings
nuklear.ppc.elfJoeSecurity_MoobotYara detected MoobotJoe Security
    nuklear.ppc.elfJoeSecurity_Mirai_8Yara detected MiraiJoe Security
      nuklear.ppc.elfLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
      • 0xf254:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xf268:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xf27c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xf290:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xf2a4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xf2b8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xf2cc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xf2e0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xf2f4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xf308:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xf31c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xf330:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xf344:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xf358:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xf36c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xf380:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xf394:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xf3a8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xf3bc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xf3d0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xf3e4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      nuklear.ppc.elfLinux_Trojan_Gafgyt_ea92cca8unknownunknown
      • 0xf114:$a: 53 65 6C 66 20 52 65 70 20 46 75 63 6B 69 6E 67 20 4E 65 54 69 53 20 61 6E 64
      SourceRuleDescriptionAuthorStrings
      5423.1.00007f35f8001000.00007f35f8012000.r-x.sdmpJoeSecurity_MoobotYara detected MoobotJoe Security
        5423.1.00007f35f8001000.00007f35f8012000.r-x.sdmpJoeSecurity_Mirai_8Yara detected MiraiJoe Security
          5423.1.00007f35f8001000.00007f35f8012000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
          • 0xf254:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xf268:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xf27c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xf290:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xf2a4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xf2b8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xf2cc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xf2e0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xf2f4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xf308:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xf31c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xf330:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xf344:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xf358:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xf36c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xf380:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xf394:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xf3a8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xf3bc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xf3d0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xf3e4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          5423.1.00007f35f8001000.00007f35f8012000.r-x.sdmpLinux_Trojan_Gafgyt_ea92cca8unknownunknown
          • 0xf114:$a: 53 65 6C 66 20 52 65 70 20 46 75 63 6B 69 6E 67 20 4E 65 54 69 53 20 61 6E 64
          Process Memory Space: nuklear.ppc.elf PID: 5423JoeSecurity_MoobotYara detected MoobotJoe Security
            Click to see the 3 entries
            No Suricata rule has matched

            Click to jump to signature section

            Show All Signature Results

            AV Detection

            barindex
            Source: nuklear.ppc.elfAvira: detected
            Source: nuklear.ppc.elfReversingLabs: Detection: 63%
            Source: unknownHTTPS traffic detected: 54.247.62.1:443 -> 192.168.2.13:57214 version: TLS 1.2
            Source: unknownTCP traffic detected without corresponding DNS query: 54.247.62.1
            Source: unknownTCP traffic detected without corresponding DNS query: 54.247.62.1
            Source: unknownTCP traffic detected without corresponding DNS query: 54.247.62.1
            Source: unknownTCP traffic detected without corresponding DNS query: 54.247.62.1
            Source: unknownTCP traffic detected without corresponding DNS query: 54.247.62.1
            Source: unknownTCP traffic detected without corresponding DNS query: 54.247.62.1
            Source: unknownTCP traffic detected without corresponding DNS query: 54.247.62.1
            Source: unknownTCP traffic detected without corresponding DNS query: 54.247.62.1
            Source: unknownTCP traffic detected without corresponding DNS query: 54.247.62.1
            Source: unknownTCP traffic detected without corresponding DNS query: 54.247.62.1
            Source: unknownTCP traffic detected without corresponding DNS query: 185.125.190.26
            Source: unknownTCP traffic detected without corresponding DNS query: 185.125.190.26
            Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
            Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
            Source: global trafficDNS traffic detected: DNS query: daisy.ubuntu.com
            Source: unknownNetwork traffic detected: HTTP traffic on port 48202 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 57214
            Source: unknownNetwork traffic detected: HTTP traffic on port 57214 -> 443
            Source: unknownHTTPS traffic detected: 54.247.62.1:443 -> 192.168.2.13:57214 version: TLS 1.2

            System Summary

            barindex
            Source: nuklear.ppc.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
            Source: nuklear.ppc.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown
            Source: 5423.1.00007f35f8001000.00007f35f8012000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
            Source: 5423.1.00007f35f8001000.00007f35f8012000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown
            Source: Process Memory Space: nuklear.ppc.elf PID: 5423, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
            Source: Process Memory Space: nuklear.ppc.elf PID: 5423, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown
            Source: ELF static info symbol of initial sample.symtab present: no
            Source: nuklear.ppc.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
            Source: nuklear.ppc.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16
            Source: 5423.1.00007f35f8001000.00007f35f8012000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
            Source: 5423.1.00007f35f8001000.00007f35f8012000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16
            Source: Process Memory Space: nuklear.ppc.elf PID: 5423, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
            Source: Process Memory Space: nuklear.ppc.elf PID: 5423, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16
            Source: classification engineClassification label: mal80.troj.linELF@0/0@2/0
            Source: /usr/bin/dash (PID: 5458)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.NSkCGimJ5W /tmp/tmp.kbWlMzuLrP /tmp/tmp.DBfmWT8WVOJump to behavior
            Source: /usr/bin/dash (PID: 5467)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.NSkCGimJ5W /tmp/tmp.kbWlMzuLrP /tmp/tmp.DBfmWT8WVOJump to behavior
            Source: /tmp/nuklear.ppc.elf (PID: 5423)Queries kernel information via 'uname': Jump to behavior
            Source: nuklear.ppc.elf, 5423.1.00007ffe4f6d6000.00007ffe4f6f7000.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-ppc/tmp/nuklear.ppc.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/nuklear.ppc.elf
            Source: nuklear.ppc.elf, 5423.1.000055603c6b4000.000055603c764000.rw-.sdmpBinary or memory string: !/etc/qemu-binfmt/ppc11!hotpluggableq
            Source: nuklear.ppc.elf, 5423.1.000055603c6b4000.000055603c764000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/ppc
            Source: nuklear.ppc.elf, 5423.1.00007ffe4f6d6000.00007ffe4f6f7000.rw-.sdmpBinary or memory string: /usr/bin/qemu-ppc
            Source: nuklear.ppc.elf, 5423.1.00007ffe4f6d6000.00007ffe4f6f7000.rw-.sdmpBinary or memory string: qemu: uncaught target signal 11 (Segmentation fault) - core dumped

            Stealing of Sensitive Information

            barindex
            Source: Yara matchFile source: nuklear.ppc.elf, type: SAMPLE
            Source: Yara matchFile source: 5423.1.00007f35f8001000.00007f35f8012000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: Process Memory Space: nuklear.ppc.elf PID: 5423, type: MEMORYSTR
            Source: Yara matchFile source: nuklear.ppc.elf, type: SAMPLE
            Source: Yara matchFile source: 5423.1.00007f35f8001000.00007f35f8012000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: Process Memory Space: nuklear.ppc.elf PID: 5423, type: MEMORYSTR

            Remote Access Functionality

            barindex
            Source: Yara matchFile source: nuklear.ppc.elf, type: SAMPLE
            Source: Yara matchFile source: 5423.1.00007f35f8001000.00007f35f8012000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: Process Memory Space: nuklear.ppc.elf PID: 5423, type: MEMORYSTR
            Source: Yara matchFile source: nuklear.ppc.elf, type: SAMPLE
            Source: Yara matchFile source: 5423.1.00007f35f8001000.00007f35f8012000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: Process Memory Space: nuklear.ppc.elf PID: 5423, type: MEMORYSTR
            ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
            Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception1
            File Deletion
            OS Credential Dumping11
            Security Software Discovery
            Remote ServicesData from Local System1
            Encrypted Channel
            Exfiltration Over Other Network MediumAbuse Accessibility Features
            CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
            Non-Application Layer Protocol
            Exfiltration Over BluetoothNetwork Denial of Service
            Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive2
            Application Layer Protocol
            Automated ExfiltrationData Encrypted for Impact
            No configs have been found
            Hide Legend

            Legend:

            • Process
            • Signature
            • Created File
            • DNS/IP Info
            • Is Dropped
            • Number of created Files
            • Is malicious
            • Internet
            SourceDetectionScannerLabelLink
            nuklear.ppc.elf63%ReversingLabsLinux.Backdoor.Mirai
            nuklear.ppc.elf100%AviraEXP/ELF.Mirai.Z.A
            No Antivirus matches
            No Antivirus matches
            No Antivirus matches
            NameIPActiveMaliciousAntivirus DetectionReputation
            daisy.ubuntu.com
            162.213.35.24
            truefalse
              high
              • No. of IPs < 25%
              • 25% < No. of IPs < 50%
              • 50% < No. of IPs < 75%
              • 75% < No. of IPs
              IPDomainCountryFlagASNASN NameMalicious
              185.125.190.26
              unknownUnited Kingdom
              41231CANONICAL-ASGBfalse
              54.247.62.1
              unknownUnited States
              16509AMAZON-02USfalse
              MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
              185.125.190.26jwwofba5.elfGet hashmaliciousMiraiBrowse
                vqsjh4.elfGet hashmaliciousMiraiBrowse
                  h0r0zx00x.arm.elfGet hashmaliciousUnknownBrowse
                    yakuza.arm7.elfGet hashmaliciousUnknownBrowse
                      dlr.arm7.elfGet hashmaliciousMirai, OkiruBrowse
                        dlr.x86.elfGet hashmaliciousOkiruBrowse
                          bot.arm5.elfGet hashmaliciousMirai, Gafgyt, OkiruBrowse
                            bot.arm.elfGet hashmaliciousMirai, Gafgyt, OkiruBrowse
                              bot.mpsl.elfGet hashmaliciousMirai, Gafgyt, OkiruBrowse
                                x86_64.elfGet hashmaliciousGafgyt, MiraiBrowse
                                  54.247.62.1686i.elfGet hashmaliciousMiraiBrowse
                                    hidakibest.arm7.elfGet hashmaliciousGafgyt, MiraiBrowse
                                      main_mpsl.elfGet hashmaliciousMiraiBrowse
                                        na.elfGet hashmaliciousUnknownBrowse
                                          na.elfGet hashmaliciousMiraiBrowse
                                            na.elfGet hashmaliciousUnknownBrowse
                                              arm6.nn.elfGet hashmaliciousMirai, OkiruBrowse
                                                boatnet.arc.elfGet hashmaliciousMiraiBrowse
                                                  bot.spc.elfGet hashmaliciousMirai, OkiruBrowse
                                                    a-r.m-7.GHOUL.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                      daisy.ubuntu.comwnbw86.elfGet hashmaliciousMiraiBrowse
                                                      • 162.213.35.24
                                                      jwwofba5.elfGet hashmaliciousMiraiBrowse
                                                      • 162.213.35.24
                                                      iwir64.elfGet hashmaliciousMiraiBrowse
                                                      • 162.213.35.24
                                                      kjsusa6.elfGet hashmaliciousMiraiBrowse
                                                      • 162.213.35.25
                                                      dvwkja7.elfGet hashmaliciousMiraiBrowse
                                                      • 162.213.35.25
                                                      vkjqpc.elfGet hashmaliciousMiraiBrowse
                                                      • 162.213.35.24
                                                      tftp.elfGet hashmaliciousUnknownBrowse
                                                      • 162.213.35.25
                                                      tftp.elfGet hashmaliciousUnknownBrowse
                                                      • 162.213.35.25
                                                      nuklear.x86-20241106-1556.elfGet hashmaliciousMirai, MoobotBrowse
                                                      • 162.213.35.25
                                                      nuklear.m68k.elfGet hashmaliciousMirai, MoobotBrowse
                                                      • 162.213.35.24
                                                      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                      AMAZON-02USUpdated Document-9875488675.pdfGet hashmaliciousCaptcha PhishBrowse
                                                      • 18.239.83.10
                                                      https://c8xomn7ab.cc.rs6.net/tn.jsp?f=001LVQvk_7YGMcWprvUGCjyoykkCp5wsj2DKX8CUElfqYjNAvoS5Vd-FoEHrnd3AGZcf8f3Kd6dmfeZCczxcmiETtRnb4EnTEVYlXoJaEA2uf64zzO8fbti6TAFwQHs1Q8omZVdwNNZakzxOS8a5W4YqJAoYIuHuCkce-Ul-fbQwZ0UfmkYHzUplX5bS_-X-WyNWeQU7HCDMgG4XZHASzyAJeR7AZc5jC156EPBJkioL6BzJCdOTGrYX814oKjdfqOcW35Q3zB4wU1aaSL6FPboUZykpQ-LNnwsP0WVZJf01y6DIpppglNQqDQeO91p1Ne44DRTrHGEcejCarJ3cn1Nl8N3TyDM7S_gMZywKefkaK6SYy38CV034CSrzs9CkEnZ&c=KHlGYD5qU3P8m6I_urIKUmkQCtlv0cORXD7xvPRFENyMvP7E79oUuQ==&ch=EBM3LyxhXOxw9y73KY8hT9M-iba87ypk2JYwx4NOQOkzUWrRR7W-Aw==Get hashmaliciousUnknownBrowse
                                                      • 18.245.46.10
                                                      kjsusa6.elfGet hashmaliciousMiraiBrowse
                                                      • 54.171.230.55
                                                      dvwkja7.elfGet hashmaliciousMiraiBrowse
                                                      • 54.171.230.55
                                                      Play_VM-NowSnickinsonAudiowav012.htmlGet hashmaliciousHTMLPhisherBrowse
                                                      • 143.204.215.5
                                                      file.exeGet hashmaliciousAmadey, Stealc, VidarBrowse
                                                      • 108.156.211.19
                                                      FmmYUD4pt7.wsfGet hashmaliciousUnknownBrowse
                                                      • 185.166.143.49
                                                      Shipping Documents.xlsGet hashmaliciousUnknownBrowse
                                                      • 54.66.50.104
                                                      Shipping Documents.xlsGet hashmaliciousUnknownBrowse
                                                      • 52.64.196.83
                                                      https://prezi.com/i/amopqalyrbyv/Get hashmaliciousUnknownBrowse
                                                      • 18.239.94.33
                                                      CANONICAL-ASGBwnbw86.elfGet hashmaliciousMiraiBrowse
                                                      • 91.189.91.42
                                                      jwwofba5.elfGet hashmaliciousMiraiBrowse
                                                      • 185.125.190.26
                                                      iwir64.elfGet hashmaliciousMiraiBrowse
                                                      • 91.189.91.42
                                                      dvwkja7.elfGet hashmaliciousMiraiBrowse
                                                      • 91.189.91.42
                                                      vqsjh4.elfGet hashmaliciousMiraiBrowse
                                                      • 185.125.190.26
                                                      vkjqpc.elfGet hashmaliciousMiraiBrowse
                                                      • 91.189.91.42
                                                      nuklear.arm5.elfGet hashmaliciousMiraiBrowse
                                                      • 91.189.91.42
                                                      nuklear.ppc.elfGet hashmaliciousMirai, MoobotBrowse
                                                      • 91.189.91.42
                                                      nuklear.x86_64.elfGet hashmaliciousMirai, MoobotBrowse
                                                      • 91.189.91.42
                                                      nuklear.mpsl.elfGet hashmaliciousMirai, MoobotBrowse
                                                      • 91.189.91.42
                                                      No context
                                                      No context
                                                      No created / dropped files found
                                                      File type:ELF 32-bit MSB executable, PowerPC or cisco 4500, version 1 (SYSV), statically linked, stripped
                                                      Entropy (8bit):6.352514489259601
                                                      TrID:
                                                      • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                                                      File name:nuklear.ppc.elf
                                                      File size:69'460 bytes
                                                      MD5:93d18049882fa37b5cb2cedfa8fd8427
                                                      SHA1:2678a442e53a5d26328ca8e9ef60d7dbf8bf0312
                                                      SHA256:f87f4f186dc972e3867f69dcf2ed9401b3986293affbffe78fc22980a3910742
                                                      SHA512:a33c3b469fb5e59606c664e9be9ea94eacc9a05926a07d2a5873212b6de72d96a151639e595e33f003069a0e108e4b025a2bbebe12765fe58b1b9c08be3a4601
                                                      SSDEEP:768:Qyl5cfRVd/xZMQgFFtAjF9VynkhUIe1tmRLUu67RQBv/A9hOOuMUatCmxNlEFhFC:3eN4Uvynk3HRLUPs6hrpBtRNspJZpof
                                                      TLSH:DF633901F2180A5BE8D31DB0253F2FE557BEEAC122E4BA85281FDB959672E331445F8D
                                                      File Content Preview:.ELF...........................4...t.....4. ...(.......................................................d..%.........dt.Q.............................!..|......$H...H..Y...$8!. |...N.. .!..|.......?.............../...@..\?........+../...A..$8...})......N..

                                                      ELF header

                                                      Class:ELF32
                                                      Data:2's complement, big endian
                                                      Version:1 (current)
                                                      Machine:PowerPC
                                                      Version Number:0x1
                                                      Type:EXEC (Executable file)
                                                      OS/ABI:UNIX - System V
                                                      ABI Version:0
                                                      Entry Point Address:0x100001f0
                                                      Flags:0x0
                                                      ELF Header Size:52
                                                      Program Header Offset:52
                                                      Program Header Size:32
                                                      Number of Program Headers:3
                                                      Section Header Offset:68980
                                                      Section Header Size:40
                                                      Number of Section Headers:12
                                                      Header String Table Index:11
                                                      NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                                      NULL0x00x00x00x00x0000
                                                      .initPROGBITS0x100000940x940x240x00x6AX004
                                                      .textPROGBITS0x100000b80xb80xe9b00x00x6AX004
                                                      .finiPROGBITS0x1000ea680xea680x200x00x6AX004
                                                      .rodataPROGBITS0x1000ea880xea880x1f380x00x2A008
                                                      .ctorsPROGBITS0x100209c40x109c40x80x00x3WA004
                                                      .dtorsPROGBITS0x100209cc0x109cc0x80x00x3WA004
                                                      .dataPROGBITS0x100209d80x109d80x3140x00x3WA008
                                                      .sdataPROGBITS0x10020cec0x10cec0x3c0x00x3WA004
                                                      .sbssNOBITS0x10020d280x10d280x700x00x3WA004
                                                      .bssNOBITS0x10020d980x10d280x22040x00x3WA004
                                                      .shstrtabSTRTAB0x00x10d280x4b0x00x0001
                                                      TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                      LOAD0x00x100000000x100000000x109c00x109c06.39790x5R E0x10000.init .text .fini .rodata
                                                      LOAD0x109c40x100209c40x100209c40x3640x25d82.82950x6RW 0x10000.ctors .dtors .data .sdata .sbss .bss
                                                      GNU_STACK0x00x00x00x00x00.00000x6RW 0x4
                                                      TimestampSource PortDest PortSource IPDest IP
                                                      Nov 6, 2024 19:02:51.000775099 CET4435721454.247.62.1192.168.2.13
                                                      Nov 6, 2024 19:02:51.000793934 CET4435721454.247.62.1192.168.2.13
                                                      Nov 6, 2024 19:02:51.000804901 CET4435721454.247.62.1192.168.2.13
                                                      Nov 6, 2024 19:02:51.000860929 CET4435721454.247.62.1192.168.2.13
                                                      Nov 6, 2024 19:02:51.000874043 CET57214443192.168.2.1354.247.62.1
                                                      Nov 6, 2024 19:02:51.000874043 CET57214443192.168.2.1354.247.62.1
                                                      Nov 6, 2024 19:02:51.000916004 CET57214443192.168.2.1354.247.62.1
                                                      Nov 6, 2024 19:02:51.001369953 CET57214443192.168.2.1354.247.62.1
                                                      Nov 6, 2024 19:02:51.001648903 CET57214443192.168.2.1354.247.62.1
                                                      Nov 6, 2024 19:02:51.006808043 CET4435721454.247.62.1192.168.2.13
                                                      Nov 6, 2024 19:02:51.259769917 CET4435721454.247.62.1192.168.2.13
                                                      Nov 6, 2024 19:02:51.261691093 CET57214443192.168.2.1354.247.62.1
                                                      Nov 6, 2024 19:02:51.261800051 CET57214443192.168.2.1354.247.62.1
                                                      Nov 6, 2024 19:02:51.266736031 CET4435721454.247.62.1192.168.2.13
                                                      Nov 6, 2024 19:02:51.515636921 CET4435721454.247.62.1192.168.2.13
                                                      Nov 6, 2024 19:02:51.515683889 CET57214443192.168.2.1354.247.62.1
                                                      Nov 6, 2024 19:02:51.516427040 CET57214443192.168.2.1354.247.62.1
                                                      Nov 6, 2024 19:02:51.521831989 CET4435721454.247.62.1192.168.2.13
                                                      Nov 6, 2024 19:02:51.521884918 CET57214443192.168.2.1354.247.62.1
                                                      Nov 6, 2024 19:03:01.737348080 CET48202443192.168.2.13185.125.190.26
                                                      Nov 6, 2024 19:03:33.993014097 CET48202443192.168.2.13185.125.190.26
                                                      TimestampSource PortDest PortSource IPDest IP
                                                      Nov 6, 2024 19:02:50.536432028 CET5413853192.168.2.131.1.1.1
                                                      Nov 6, 2024 19:02:50.536549091 CET4612853192.168.2.131.1.1.1
                                                      Nov 6, 2024 19:02:50.544152021 CET53541381.1.1.1192.168.2.13
                                                      Nov 6, 2024 19:02:50.544167042 CET53461281.1.1.1192.168.2.13
                                                      TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                                      Nov 6, 2024 19:02:50.536432028 CET192.168.2.131.1.1.10x5f10Standard query (0)daisy.ubuntu.comA (IP address)IN (0x0001)false
                                                      Nov 6, 2024 19:02:50.536549091 CET192.168.2.131.1.1.10x7968Standard query (0)daisy.ubuntu.com28IN (0x0001)false
                                                      TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                                      Nov 6, 2024 19:02:50.544152021 CET1.1.1.1192.168.2.130x5f10No error (0)daisy.ubuntu.com162.213.35.24A (IP address)IN (0x0001)false
                                                      Nov 6, 2024 19:02:50.544152021 CET1.1.1.1192.168.2.130x5f10No error (0)daisy.ubuntu.com162.213.35.25A (IP address)IN (0x0001)false
                                                      TimestampSource IPSource PortDest IPDest PortSubjectIssuerNot BeforeNot AfterJA3 SSL Client FingerprintJA3 SSL Client Digest
                                                      Nov 6, 2024 19:02:51.000804901 CET54.247.62.1443192.168.2.1357214CN=motd.ubuntu.com CN=R11, O=Let's Encrypt, C=USCN=R11, O=Let's Encrypt, C=US CN=ISRG Root X1, O=Internet Security Research Group, C=USMon Oct 21 10:21:37 CEST 2024 Wed Mar 13 01:00:00 CET 2024Sun Jan 19 09:21:36 CET 2025 Sat Mar 13 00:59:59 CET 2027
                                                      CN=R11, O=Let's Encrypt, C=USCN=ISRG Root X1, O=Internet Security Research Group, C=USWed Mar 13 01:00:00 CET 2024Sat Mar 13 00:59:59 CET 2027

                                                      System Behavior

                                                      Start time (UTC):18:02:48
                                                      Start date (UTC):06/11/2024
                                                      Path:/tmp/nuklear.ppc.elf
                                                      Arguments:/tmp/nuklear.ppc.elf
                                                      File size:5388968 bytes
                                                      MD5 hash:ae65271c943d3451b7f026d1fadccea6

                                                      Start time (UTC):18:02:50
                                                      Start date (UTC):06/11/2024
                                                      Path:/usr/bin/dash
                                                      Arguments:-
                                                      File size:129816 bytes
                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                      Start time (UTC):18:02:50
                                                      Start date (UTC):06/11/2024
                                                      Path:/usr/bin/rm
                                                      Arguments:rm -f /tmp/tmp.NSkCGimJ5W /tmp/tmp.kbWlMzuLrP /tmp/tmp.DBfmWT8WVO
                                                      File size:72056 bytes
                                                      MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b

                                                      Start time (UTC):18:02:50
                                                      Start date (UTC):06/11/2024
                                                      Path:/usr/bin/dash
                                                      Arguments:-
                                                      File size:129816 bytes
                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                      Start time (UTC):18:02:50
                                                      Start date (UTC):06/11/2024
                                                      Path:/usr/bin/cat
                                                      Arguments:cat /tmp/tmp.NSkCGimJ5W
                                                      File size:43416 bytes
                                                      MD5 hash:7e9d213e404ad3bb82e4ebb2e1f2c1b3

                                                      Start time (UTC):18:02:50
                                                      Start date (UTC):06/11/2024
                                                      Path:/usr/bin/dash
                                                      Arguments:-
                                                      File size:129816 bytes
                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                      Start time (UTC):18:02:50
                                                      Start date (UTC):06/11/2024
                                                      Path:/usr/bin/head
                                                      Arguments:head -n 10
                                                      File size:47480 bytes
                                                      MD5 hash:fd96a67145172477dd57131396fc9608

                                                      Start time (UTC):18:02:50
                                                      Start date (UTC):06/11/2024
                                                      Path:/usr/bin/dash
                                                      Arguments:-
                                                      File size:129816 bytes
                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                      Start time (UTC):18:02:50
                                                      Start date (UTC):06/11/2024
                                                      Path:/usr/bin/tr
                                                      Arguments:tr -d \\000-\\011\\013\\014\\016-\\037
                                                      File size:51544 bytes
                                                      MD5 hash:fbd1402dd9f72d8ebfff00ce7c3a7bb5

                                                      Start time (UTC):18:02:50
                                                      Start date (UTC):06/11/2024
                                                      Path:/usr/bin/dash
                                                      Arguments:-
                                                      File size:129816 bytes
                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                      Start time (UTC):18:02:50
                                                      Start date (UTC):06/11/2024
                                                      Path:/usr/bin/cut
                                                      Arguments:cut -c -80
                                                      File size:47480 bytes
                                                      MD5 hash:d8ed0ea8f22c0de0f8692d4d9f1759d3

                                                      Start time (UTC):18:02:50
                                                      Start date (UTC):06/11/2024
                                                      Path:/usr/bin/dash
                                                      Arguments:-
                                                      File size:129816 bytes
                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                      Start time (UTC):18:02:50
                                                      Start date (UTC):06/11/2024
                                                      Path:/usr/bin/cat
                                                      Arguments:cat /tmp/tmp.NSkCGimJ5W
                                                      File size:43416 bytes
                                                      MD5 hash:7e9d213e404ad3bb82e4ebb2e1f2c1b3

                                                      Start time (UTC):18:02:50
                                                      Start date (UTC):06/11/2024
                                                      Path:/usr/bin/dash
                                                      Arguments:-
                                                      File size:129816 bytes
                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                      Start time (UTC):18:02:50
                                                      Start date (UTC):06/11/2024
                                                      Path:/usr/bin/head
                                                      Arguments:head -n 10
                                                      File size:47480 bytes
                                                      MD5 hash:fd96a67145172477dd57131396fc9608

                                                      Start time (UTC):18:02:50
                                                      Start date (UTC):06/11/2024
                                                      Path:/usr/bin/dash
                                                      Arguments:-
                                                      File size:129816 bytes
                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                      Start time (UTC):18:02:50
                                                      Start date (UTC):06/11/2024
                                                      Path:/usr/bin/tr
                                                      Arguments:tr -d \\000-\\011\\013\\014\\016-\\037
                                                      File size:51544 bytes
                                                      MD5 hash:fbd1402dd9f72d8ebfff00ce7c3a7bb5

                                                      Start time (UTC):18:02:50
                                                      Start date (UTC):06/11/2024
                                                      Path:/usr/bin/dash
                                                      Arguments:-
                                                      File size:129816 bytes
                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                      Start time (UTC):18:02:50
                                                      Start date (UTC):06/11/2024
                                                      Path:/usr/bin/cut
                                                      Arguments:cut -c -80
                                                      File size:47480 bytes
                                                      MD5 hash:d8ed0ea8f22c0de0f8692d4d9f1759d3

                                                      Start time (UTC):18:02:50
                                                      Start date (UTC):06/11/2024
                                                      Path:/usr/bin/dash
                                                      Arguments:-
                                                      File size:129816 bytes
                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                      Start time (UTC):18:02:50
                                                      Start date (UTC):06/11/2024
                                                      Path:/usr/bin/rm
                                                      Arguments:rm -f /tmp/tmp.NSkCGimJ5W /tmp/tmp.kbWlMzuLrP /tmp/tmp.DBfmWT8WVO
                                                      File size:72056 bytes
                                                      MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b