Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
debug.dbg.elf

Overview

General Information

Sample name:debug.dbg.elf
Analysis ID:1567743
MD5:b826f579cc0d33fd5a73f19c1340c61b
SHA1:aad3318fe083cda969b0eed1d7a33a7ae50b5efd
SHA256:e4aafe787b05ef696763687cec61e83a2cb5e6a7f597c2701a7e6892e42f7d46
Tags:elfuser-abuse_ch
Infos:

Detection

Mirai
Score:96
Range:0 - 100
Whitelisted:false

Signatures

Antivirus / Scanner detection for submitted sample
Detected Mirai
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Suricata IDS alerts for network traffic
Yara detected Mirai
Machine Learning detection for sample
Sample tries to kill multiple processes (SIGKILL)
Creates hidden files and/or directories
Detected TCP or UDP traffic on non-standard ports
Enumerates processes within the "proc" file system
Found strings indicative of a multi-platform dropper
Sample contains strings indicative of BusyBox which embeds multiple Unix commands in a single executable
Sample has stripped symbol table
Sample tries to kill a process (SIGKILL)
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Uses the "uname" system call to query kernel version information (possible evasion)
Yara signature match

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1567743
Start date and time:2024-12-03 20:51:08 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 5m 34s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:debug.dbg.elf
Detection:MAL
Classification:mal96.spre.troj.linELF@0/0@1/0
  • VT rate limit hit for: debug.dbg.elf
Command:/tmp/debug.dbg.elf
PID:5439
Exit Code:
Exit Code Info:
Killed:True
Standard Output:
mosts
Standard Error:[main] cant remove reboot function.: No such file or directory
[main] cant remove reboot function.: No such file or directory
[main] cant remove reboot function.: No such file or directory
[main] cant remove reboot function.: No such file or directory
[main] cant remove reboot function.: No such file or directory
[main] cant remove reboot function.: No such file or directory
[main] cant remove reboot function.: No such file or directory
[main] cant remove reboot function.: No such file or directory
[main] cant remove reboot function.: No such file or directory
[main] cant remove reboot function.: No such file or directory
[main] cant remove reboot function.: No such file or directory
[main] cant remove reboot function.: No such file or directory
  • system is lnxubuntu20
  • debug.dbg.elf (PID: 5439, Parent: 5359, MD5: b826f579cc0d33fd5a73f19c1340c61b) Arguments: /tmp/debug.dbg.elf
  • xfdesktop (PID: 5460, Parent: 2984, MD5: dfb13e1581f80065dcea16f2476f16f2) Arguments: xfdesktop --display :1.0 --sm-client-id 260d40b3c-9c6a-4cb1-bbe4-3557725aa528
  • xfdesktop (PID: 5461, Parent: 2984, MD5: dfb13e1581f80065dcea16f2476f16f2) Arguments: xfdesktop --display :1.0 --sm-client-id 260d40b3c-9c6a-4cb1-bbe4-3557725aa528
  • xfdesktop (PID: 5464, Parent: 2984, MD5: dfb13e1581f80065dcea16f2476f16f2) Arguments: xfdesktop --display :1.0 --sm-client-id 260d40b3c-9c6a-4cb1-bbe4-3557725aa528
  • xfdesktop (PID: 5469, Parent: 2984, MD5: dfb13e1581f80065dcea16f2476f16f2) Arguments: xfdesktop --display :1.0 --sm-client-id 260d40b3c-9c6a-4cb1-bbe4-3557725aa528
  • xfdesktop (PID: 5472, Parent: 2984, MD5: dfb13e1581f80065dcea16f2476f16f2) Arguments: xfdesktop --display :1.0 --sm-client-id 260d40b3c-9c6a-4cb1-bbe4-3557725aa528
  • systemd New Fork (PID: 5576, Parent: 1)
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
MiraiMirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese. Nowadays it targets a wide range of networked embedded devices such as IP cameras, home routers (many vendors involved), and other IoT devices. Since the source code was published on "Hack Forums" many variants of the Mirai family appeared, infecting mostly home networks all around the world.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/elf.mirai
SourceRuleDescriptionAuthorStrings
debug.dbg.elfJoeSecurity_Mirai_8Yara detected MiraiJoe Security
    debug.dbg.elfLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
    • 0x13150:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x13164:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x13178:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x1318c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x131a0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x131b4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x131c8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x131dc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x131f0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x13204:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x13218:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x1322c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x13240:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x13254:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x13268:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x1327c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x13290:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x132a4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x132b8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x132cc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x132e0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    debug.dbg.elfLinux_Trojan_Mirai_b14f4c5dunknownunknown
    • 0x4b50:$a: 53 31 DB 8B 4C 24 0C 8B 54 24 08 83 F9 01 76 15 66 8B 02 83 E9 02 25 FF FF 00 00 83 C2 02 01 C3 83 F9 01 77 EB 49 75 05 0F BE 02 01 C3
    debug.dbg.elfLinux_Trojan_Mirai_5f7b67b8unknownunknown
    • 0xc303:$a: 89 38 83 CF FF 89 F8 5A 59 5F C3 57 56 83 EC 04 8B 7C 24 10 8B 4C
    debug.dbg.elfLinux_Trojan_Mirai_88de437funknownunknown
    • 0x8752:$a: 24 08 8B 4C 24 04 85 D2 74 0D 31 C0 89 F6 C6 04 08 00 40 39 D0
    Click to see the 3 entries
    SourceRuleDescriptionAuthorStrings
    5439.1.0000000008048000.000000000805e000.r-x.sdmpJoeSecurity_Mirai_8Yara detected MiraiJoe Security
      5439.1.0000000008048000.000000000805e000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
      • 0x13150:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x13164:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x13178:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x1318c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x131a0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x131b4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x131c8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x131dc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x131f0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x13204:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x13218:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x1322c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x13240:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x13254:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x13268:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x1327c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x13290:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x132a4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x132b8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x132cc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x132e0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      5439.1.0000000008048000.000000000805e000.r-x.sdmpLinux_Trojan_Mirai_b14f4c5dunknownunknown
      • 0x4b50:$a: 53 31 DB 8B 4C 24 0C 8B 54 24 08 83 F9 01 76 15 66 8B 02 83 E9 02 25 FF FF 00 00 83 C2 02 01 C3 83 F9 01 77 EB 49 75 05 0F BE 02 01 C3
      5439.1.0000000008048000.000000000805e000.r-x.sdmpLinux_Trojan_Mirai_5f7b67b8unknownunknown
      • 0xc303:$a: 89 38 83 CF FF 89 F8 5A 59 5F C3 57 56 83 EC 04 8B 7C 24 10 8B 4C
      5439.1.0000000008048000.000000000805e000.r-x.sdmpLinux_Trojan_Mirai_88de437funknownunknown
      • 0x8752:$a: 24 08 8B 4C 24 04 85 D2 74 0D 31 C0 89 F6 C6 04 08 00 40 39 D0
      Click to see the 15 entries
      TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
      2024-12-03T20:51:49.769558+010020304901Malware Command and Control Activity Detected192.168.2.1356784103.229.52.722023TCP
      TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
      2024-12-03T20:51:51.192935+010020304891Malware Command and Control Activity Detected103.229.52.722023192.168.2.1356784TCP
      2024-12-03T20:51:53.339977+010020304891Malware Command and Control Activity Detected103.229.52.722023192.168.2.1356784TCP
      2024-12-03T20:52:13.358850+010020304891Malware Command and Control Activity Detected103.229.52.722023192.168.2.1356784TCP
      2024-12-03T20:52:33.368452+010020304891Malware Command and Control Activity Detected103.229.52.722023192.168.2.1356784TCP

      Click to jump to signature section

      Show All Signature Results

      AV Detection

      barindex
      Source: debug.dbg.elfAvira: detected
      Source: debug.dbg.elfReversingLabs: Detection: 55%
      Source: debug.dbg.elfJoe Sandbox ML: detected
      Source: debug.dbg.elfString: ./dvr_gui./upnp_server./dvr_app/proc/proc/%s/cmdline./pkillkillallwgetbusyboxtopcurltftppgrepxargsawktoyboxKh

      Networking

      barindex
      Source: Network trafficSuricata IDS: 2030490 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) : 192.168.2.13:56784 -> 103.229.52.72:2023
      Source: Network trafficSuricata IDS: 2030489 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant Server Response : 103.229.52.72:2023 -> 192.168.2.13:56784
      Source: global trafficTCP traffic: 192.168.2.13:56784 -> 103.229.52.72:2023
      Source: global trafficTCP traffic: 192.168.2.13:48202 -> 185.125.190.26:443
      Source: unknownTCP traffic detected without corresponding DNS query: 185.125.190.26
      Source: unknownTCP traffic detected without corresponding DNS query: 185.125.190.26
      Source: global trafficDNS traffic detected: DNS query: net-killer.ooguy.com
      Source: unknownNetwork traffic detected: HTTP traffic on port 48202 -> 443

      System Summary

      barindex
      Source: debug.dbg.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
      Source: debug.dbg.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_b14f4c5d Author: unknown
      Source: debug.dbg.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_5f7b67b8 Author: unknown
      Source: debug.dbg.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_88de437f Author: unknown
      Source: debug.dbg.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_389ee3e9 Author: unknown
      Source: debug.dbg.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_cc93863b Author: unknown
      Source: debug.dbg.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_8aa7b5d3 Author: unknown
      Source: 5439.1.0000000008048000.000000000805e000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
      Source: 5439.1.0000000008048000.000000000805e000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_b14f4c5d Author: unknown
      Source: 5439.1.0000000008048000.000000000805e000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_5f7b67b8 Author: unknown
      Source: 5439.1.0000000008048000.000000000805e000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_88de437f Author: unknown
      Source: 5439.1.0000000008048000.000000000805e000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_389ee3e9 Author: unknown
      Source: 5439.1.0000000008048000.000000000805e000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_cc93863b Author: unknown
      Source: 5439.1.0000000008048000.000000000805e000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_8aa7b5d3 Author: unknown
      Source: 5441.1.0000000008048000.000000000805e000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
      Source: 5441.1.0000000008048000.000000000805e000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_b14f4c5d Author: unknown
      Source: 5441.1.0000000008048000.000000000805e000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_5f7b67b8 Author: unknown
      Source: 5441.1.0000000008048000.000000000805e000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_88de437f Author: unknown
      Source: 5441.1.0000000008048000.000000000805e000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_389ee3e9 Author: unknown
      Source: 5441.1.0000000008048000.000000000805e000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_cc93863b Author: unknown
      Source: 5441.1.0000000008048000.000000000805e000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_8aa7b5d3 Author: unknown
      Source: Process Memory Space: debug.dbg.elf PID: 5439, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
      Source: Process Memory Space: debug.dbg.elf PID: 5441, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
      Source: /tmp/debug.dbg.elf (PID: 5440)SIGKILL sent: pid: 914, result: successfulJump to behavior
      Source: /tmp/debug.dbg.elf (PID: 5440)SIGKILL sent: pid: 917, result: successfulJump to behavior
      Source: /tmp/debug.dbg.elf (PID: 5440)SIGKILL sent: pid: 936, result: successfulJump to behavior
      Source: /tmp/debug.dbg.elf (PID: 5440)SIGKILL sent: pid: 1238, result: successfulJump to behavior
      Source: /tmp/debug.dbg.elf (PID: 5440)SIGKILL sent: pid: 1320, result: successfulJump to behavior
      Source: /tmp/debug.dbg.elf (PID: 5440)SIGKILL sent: pid: 3158, result: successfulJump to behavior
      Source: /tmp/debug.dbg.elf (PID: 5440)SIGKILL sent: pid: 5460, result: successfulJump to behavior
      Source: /tmp/debug.dbg.elf (PID: 5440)SIGKILL sent: pid: 5461, result: successfulJump to behavior
      Source: /tmp/debug.dbg.elf (PID: 5440)SIGKILL sent: pid: 5464, result: successfulJump to behavior
      Source: /tmp/debug.dbg.elf (PID: 5440)SIGKILL sent: pid: 5469, result: successfulJump to behavior
      Source: /tmp/debug.dbg.elf (PID: 5440)SIGKILL sent: pid: 5472, result: successfulJump to behavior
      Source: Initial sampleString containing 'busybox' found: busybox
      Source: Initial sampleString containing 'busybox' found: ./dvr_gui./upnp_server./dvr_app/proc/proc/%s/cmdline./pkillkillallwgetbusyboxtopcurltftppgrepxargsawktoyboxKh
      Source: ELF static info symbol of initial sample.symtab present: no
      Source: /tmp/debug.dbg.elf (PID: 5440)SIGKILL sent: pid: 914, result: successfulJump to behavior
      Source: /tmp/debug.dbg.elf (PID: 5440)SIGKILL sent: pid: 917, result: successfulJump to behavior
      Source: /tmp/debug.dbg.elf (PID: 5440)SIGKILL sent: pid: 936, result: successfulJump to behavior
      Source: /tmp/debug.dbg.elf (PID: 5440)SIGKILL sent: pid: 1238, result: successfulJump to behavior
      Source: /tmp/debug.dbg.elf (PID: 5440)SIGKILL sent: pid: 1320, result: successfulJump to behavior
      Source: /tmp/debug.dbg.elf (PID: 5440)SIGKILL sent: pid: 3158, result: successfulJump to behavior
      Source: /tmp/debug.dbg.elf (PID: 5440)SIGKILL sent: pid: 5460, result: successfulJump to behavior
      Source: /tmp/debug.dbg.elf (PID: 5440)SIGKILL sent: pid: 5461, result: successfulJump to behavior
      Source: /tmp/debug.dbg.elf (PID: 5440)SIGKILL sent: pid: 5464, result: successfulJump to behavior
      Source: /tmp/debug.dbg.elf (PID: 5440)SIGKILL sent: pid: 5469, result: successfulJump to behavior
      Source: /tmp/debug.dbg.elf (PID: 5440)SIGKILL sent: pid: 5472, result: successfulJump to behavior
      Source: debug.dbg.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
      Source: debug.dbg.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_b14f4c5d os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = a70d052918dd2fbc66db241da6438015130f0fb6929229bfe573546fe98da817, id = b14f4c5d-054f-46e6-9fa8-3588f1ef68b7, last_modified = 2021-09-16
      Source: debug.dbg.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_5f7b67b8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 6cb5fb0b7c132e9c11ac72da43278025b60810ea3733c9c6d6ca966163185940, id = 5f7b67b8-3d7b-48a4-8f03-b6f2c92be92e, last_modified = 2021-09-16
      Source: debug.dbg.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_88de437f reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = c19eb595c2b444a809bef8500c20342c9f46694d3018e268833f9b884133a1ea, id = 88de437f-9c98-4e1d-96c0-7b433c99886a, last_modified = 2021-09-16
      Source: debug.dbg.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_389ee3e9 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 59f2359dc1f41d385d639d157b4cd9fc73d76d8abb7cc09d47632bb4c9a39e6e, id = 389ee3e9-70c1-4c93-a999-292cf6ff1652, last_modified = 2022-01-26
      Source: debug.dbg.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_cc93863b reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = f3ecd30f0b511a8e92cfa642409d559e7612c3f57a1659ca46c77aca809a00ac, id = cc93863b-1050-40ba-9d02-5ec9ce6a3a28, last_modified = 2022-01-26
      Source: debug.dbg.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_8aa7b5d3 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 02a2c18c362df4b1fceb33f3b605586514ba9a00c7afedf71c04fa54d8146444, id = 8aa7b5d3-e1eb-4b55-b36a-0d3a242c06e9, last_modified = 2022-01-26
      Source: 5439.1.0000000008048000.000000000805e000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
      Source: 5439.1.0000000008048000.000000000805e000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_b14f4c5d os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = a70d052918dd2fbc66db241da6438015130f0fb6929229bfe573546fe98da817, id = b14f4c5d-054f-46e6-9fa8-3588f1ef68b7, last_modified = 2021-09-16
      Source: 5439.1.0000000008048000.000000000805e000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_5f7b67b8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 6cb5fb0b7c132e9c11ac72da43278025b60810ea3733c9c6d6ca966163185940, id = 5f7b67b8-3d7b-48a4-8f03-b6f2c92be92e, last_modified = 2021-09-16
      Source: 5439.1.0000000008048000.000000000805e000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_88de437f reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = c19eb595c2b444a809bef8500c20342c9f46694d3018e268833f9b884133a1ea, id = 88de437f-9c98-4e1d-96c0-7b433c99886a, last_modified = 2021-09-16
      Source: 5439.1.0000000008048000.000000000805e000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_389ee3e9 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 59f2359dc1f41d385d639d157b4cd9fc73d76d8abb7cc09d47632bb4c9a39e6e, id = 389ee3e9-70c1-4c93-a999-292cf6ff1652, last_modified = 2022-01-26
      Source: 5439.1.0000000008048000.000000000805e000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_cc93863b reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = f3ecd30f0b511a8e92cfa642409d559e7612c3f57a1659ca46c77aca809a00ac, id = cc93863b-1050-40ba-9d02-5ec9ce6a3a28, last_modified = 2022-01-26
      Source: 5439.1.0000000008048000.000000000805e000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_8aa7b5d3 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 02a2c18c362df4b1fceb33f3b605586514ba9a00c7afedf71c04fa54d8146444, id = 8aa7b5d3-e1eb-4b55-b36a-0d3a242c06e9, last_modified = 2022-01-26
      Source: 5441.1.0000000008048000.000000000805e000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
      Source: 5441.1.0000000008048000.000000000805e000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_b14f4c5d os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = a70d052918dd2fbc66db241da6438015130f0fb6929229bfe573546fe98da817, id = b14f4c5d-054f-46e6-9fa8-3588f1ef68b7, last_modified = 2021-09-16
      Source: 5441.1.0000000008048000.000000000805e000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_5f7b67b8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 6cb5fb0b7c132e9c11ac72da43278025b60810ea3733c9c6d6ca966163185940, id = 5f7b67b8-3d7b-48a4-8f03-b6f2c92be92e, last_modified = 2021-09-16
      Source: 5441.1.0000000008048000.000000000805e000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_88de437f reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = c19eb595c2b444a809bef8500c20342c9f46694d3018e268833f9b884133a1ea, id = 88de437f-9c98-4e1d-96c0-7b433c99886a, last_modified = 2021-09-16
      Source: 5441.1.0000000008048000.000000000805e000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_389ee3e9 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 59f2359dc1f41d385d639d157b4cd9fc73d76d8abb7cc09d47632bb4c9a39e6e, id = 389ee3e9-70c1-4c93-a999-292cf6ff1652, last_modified = 2022-01-26
      Source: 5441.1.0000000008048000.000000000805e000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_cc93863b reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = f3ecd30f0b511a8e92cfa642409d559e7612c3f57a1659ca46c77aca809a00ac, id = cc93863b-1050-40ba-9d02-5ec9ce6a3a28, last_modified = 2022-01-26
      Source: 5441.1.0000000008048000.000000000805e000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_8aa7b5d3 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 02a2c18c362df4b1fceb33f3b605586514ba9a00c7afedf71c04fa54d8146444, id = 8aa7b5d3-e1eb-4b55-b36a-0d3a242c06e9, last_modified = 2022-01-26
      Source: Process Memory Space: debug.dbg.elf PID: 5439, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
      Source: Process Memory Space: debug.dbg.elf PID: 5441, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
      Source: classification engineClassification label: mal96.spre.troj.linELF@0/0@1/0
      Source: /usr/bin/xfdesktop (PID: 5461)Directory: /home/saturnino/.Xdefaults-galassiaJump to behavior
      Source: /usr/bin/xfdesktop (PID: 5464)Directory: /home/saturnino/.Xdefaults-galassiaJump to behavior
      Source: /usr/bin/xfdesktop (PID: 5469)Directory: /home/saturnino/.Xdefaults-galassiaJump to behavior
      Source: /usr/bin/xfdesktop (PID: 5472)Directory: /home/saturnino/.Xdefaults-galassiaJump to behavior
      Source: /tmp/debug.dbg.elf (PID: 5440)File opened: /proc/5383/cmdlineJump to behavior
      Source: /tmp/debug.dbg.elf (PID: 5440)File opened: /proc/230/cmdlineJump to behavior
      Source: /tmp/debug.dbg.elf (PID: 5440)File opened: /proc/110/cmdlineJump to behavior
      Source: /tmp/debug.dbg.elf (PID: 5440)File opened: /proc/231/cmdlineJump to behavior
      Source: /tmp/debug.dbg.elf (PID: 5440)File opened: /proc/111/cmdlineJump to behavior
      Source: /tmp/debug.dbg.elf (PID: 5440)File opened: /proc/232/cmdlineJump to behavior
      Source: /tmp/debug.dbg.elf (PID: 5440)File opened: /proc/112/cmdlineJump to behavior
      Source: /tmp/debug.dbg.elf (PID: 5440)File opened: /proc/233/cmdlineJump to behavior
      Source: /tmp/debug.dbg.elf (PID: 5440)File opened: /proc/113/cmdlineJump to behavior
      Source: /tmp/debug.dbg.elf (PID: 5440)File opened: /proc/234/cmdlineJump to behavior
      Source: /tmp/debug.dbg.elf (PID: 5440)File opened: /proc/114/cmdlineJump to behavior
      Source: /tmp/debug.dbg.elf (PID: 5440)File opened: /proc/235/cmdlineJump to behavior
      Source: /tmp/debug.dbg.elf (PID: 5440)File opened: /proc/115/cmdlineJump to behavior
      Source: /tmp/debug.dbg.elf (PID: 5440)File opened: /proc/236/cmdlineJump to behavior
      Source: /tmp/debug.dbg.elf (PID: 5440)File opened: /proc/116/cmdlineJump to behavior
      Source: /tmp/debug.dbg.elf (PID: 5440)File opened: /proc/237/cmdlineJump to behavior
      Source: /tmp/debug.dbg.elf (PID: 5440)File opened: /proc/117/cmdlineJump to behavior
      Source: /tmp/debug.dbg.elf (PID: 5440)File opened: /proc/238/cmdlineJump to behavior
      Source: /tmp/debug.dbg.elf (PID: 5440)File opened: /proc/118/cmdlineJump to behavior
      Source: /tmp/debug.dbg.elf (PID: 5440)File opened: /proc/239/cmdlineJump to behavior
      Source: /tmp/debug.dbg.elf (PID: 5440)File opened: /proc/119/cmdlineJump to behavior
      Source: /tmp/debug.dbg.elf (PID: 5440)File opened: /proc/914/cmdlineJump to behavior
      Source: /tmp/debug.dbg.elf (PID: 5440)File opened: /proc/10/cmdlineJump to behavior
      Source: /tmp/debug.dbg.elf (PID: 5440)File opened: /proc/917/cmdlineJump to behavior
      Source: /tmp/debug.dbg.elf (PID: 5440)File opened: /proc/3637/cmdlineJump to behavior
      Source: /tmp/debug.dbg.elf (PID: 5440)File opened: /proc/11/cmdlineJump to behavior
      Source: /tmp/debug.dbg.elf (PID: 5440)File opened: /proc/12/cmdlineJump to behavior
      Source: /tmp/debug.dbg.elf (PID: 5440)File opened: /proc/13/cmdlineJump to behavior
      Source: /tmp/debug.dbg.elf (PID: 5440)File opened: /proc/14/cmdlineJump to behavior
      Source: /tmp/debug.dbg.elf (PID: 5440)File opened: /proc/15/cmdlineJump to behavior
      Source: /tmp/debug.dbg.elf (PID: 5440)File opened: /proc/5276/cmdlineJump to behavior
      Source: /tmp/debug.dbg.elf (PID: 5440)File opened: /proc/16/cmdlineJump to behavior
      Source: /tmp/debug.dbg.elf (PID: 5440)File opened: /proc/17/cmdlineJump to behavior
      Source: /tmp/debug.dbg.elf (PID: 5440)File opened: /proc/18/cmdlineJump to behavior
      Source: /tmp/debug.dbg.elf (PID: 5440)File opened: /proc/19/cmdlineJump to behavior
      Source: /tmp/debug.dbg.elf (PID: 5440)File opened: /proc/240/cmdlineJump to behavior
      Source: /tmp/debug.dbg.elf (PID: 5440)File opened: /proc/3095/cmdlineJump to behavior
      Source: /tmp/debug.dbg.elf (PID: 5440)File opened: /proc/120/cmdlineJump to behavior
      Source: /tmp/debug.dbg.elf (PID: 5440)File opened: /proc/241/cmdlineJump to behavior
      Source: /tmp/debug.dbg.elf (PID: 5440)File opened: /proc/121/cmdlineJump to behavior
      Source: /tmp/debug.dbg.elf (PID: 5440)File opened: /proc/242/cmdlineJump to behavior
      Source: /tmp/debug.dbg.elf (PID: 5440)File opened: /proc/1/cmdlineJump to behavior
      Source: /tmp/debug.dbg.elf (PID: 5440)File opened: /proc/122/cmdlineJump to behavior
      Source: /tmp/debug.dbg.elf (PID: 5440)File opened: /proc/243/cmdlineJump to behavior
      Source: /tmp/debug.dbg.elf (PID: 5440)File opened: /proc/2/cmdlineJump to behavior
      Source: /tmp/debug.dbg.elf (PID: 5440)File opened: /proc/123/cmdlineJump to behavior
      Source: /tmp/debug.dbg.elf (PID: 5440)File opened: /proc/244/cmdlineJump to behavior
      Source: /tmp/debug.dbg.elf (PID: 5440)File opened: /proc/3/cmdlineJump to behavior
      Source: /tmp/debug.dbg.elf (PID: 5440)File opened: /proc/124/cmdlineJump to behavior
      Source: /tmp/debug.dbg.elf (PID: 5440)File opened: /proc/245/cmdlineJump to behavior
      Source: /tmp/debug.dbg.elf (PID: 5440)File opened: /proc/1588/cmdlineJump to behavior
      Source: /tmp/debug.dbg.elf (PID: 5440)File opened: /proc/125/cmdlineJump to behavior
      Source: /tmp/debug.dbg.elf (PID: 5440)File opened: /proc/4/cmdlineJump to behavior
      Source: /tmp/debug.dbg.elf (PID: 5440)File opened: /proc/246/cmdlineJump to behavior
      Source: /tmp/debug.dbg.elf (PID: 5440)File opened: /proc/126/cmdlineJump to behavior
      Source: /tmp/debug.dbg.elf (PID: 5440)File opened: /proc/5/cmdlineJump to behavior
      Source: /tmp/debug.dbg.elf (PID: 5440)File opened: /proc/247/cmdlineJump to behavior
      Source: /tmp/debug.dbg.elf (PID: 5440)File opened: /proc/127/cmdlineJump to behavior
      Source: /tmp/debug.dbg.elf (PID: 5440)File opened: /proc/6/cmdlineJump to behavior
      Source: /tmp/debug.dbg.elf (PID: 5440)File opened: /proc/248/cmdlineJump to behavior
      Source: /tmp/debug.dbg.elf (PID: 5440)File opened: /proc/128/cmdlineJump to behavior
      Source: /tmp/debug.dbg.elf (PID: 5440)File opened: /proc/7/cmdlineJump to behavior
      Source: /tmp/debug.dbg.elf (PID: 5440)File opened: /proc/249/cmdlineJump to behavior
      Source: /tmp/debug.dbg.elf (PID: 5440)File opened: /proc/129/cmdlineJump to behavior
      Source: /tmp/debug.dbg.elf (PID: 5440)File opened: /proc/8/cmdlineJump to behavior
      Source: /tmp/debug.dbg.elf (PID: 5440)File opened: /proc/800/cmdlineJump to behavior
      Source: /tmp/debug.dbg.elf (PID: 5440)File opened: /proc/9/cmdlineJump to behavior
      Source: /tmp/debug.dbg.elf (PID: 5440)File opened: /proc/1906/cmdlineJump to behavior
      Source: /tmp/debug.dbg.elf (PID: 5440)File opened: /proc/802/cmdlineJump to behavior
      Source: /tmp/debug.dbg.elf (PID: 5440)File opened: /proc/803/cmdlineJump to behavior
      Source: /tmp/debug.dbg.elf (PID: 5440)File opened: /proc/3765/cmdlineJump to behavior
      Source: /tmp/debug.dbg.elf (PID: 5440)File opened: /proc/20/cmdlineJump to behavior
      Source: /tmp/debug.dbg.elf (PID: 5440)File opened: /proc/21/cmdlineJump to behavior
      Source: /tmp/debug.dbg.elf (PID: 5440)File opened: /proc/22/cmdlineJump to behavior
      Source: /tmp/debug.dbg.elf (PID: 5440)File opened: /proc/23/cmdlineJump to behavior
      Source: /tmp/debug.dbg.elf (PID: 5440)File opened: /proc/24/cmdlineJump to behavior
      Source: /tmp/debug.dbg.elf (PID: 5440)File opened: /proc/25/cmdlineJump to behavior
      Source: /tmp/debug.dbg.elf (PID: 5440)File opened: /proc/26/cmdlineJump to behavior
      Source: /tmp/debug.dbg.elf (PID: 5440)File opened: /proc/27/cmdlineJump to behavior
      Source: /tmp/debug.dbg.elf (PID: 5440)File opened: /proc/28/cmdlineJump to behavior
      Source: /tmp/debug.dbg.elf (PID: 5440)File opened: /proc/29/cmdlineJump to behavior
      Source: /tmp/debug.dbg.elf (PID: 5440)File opened: /proc/3420/cmdlineJump to behavior
      Source: /tmp/debug.dbg.elf (PID: 5440)File opened: /proc/1482/cmdlineJump to behavior
      Source: /tmp/debug.dbg.elf (PID: 5440)File opened: /proc/490/cmdlineJump to behavior
      Source: /tmp/debug.dbg.elf (PID: 5440)File opened: /proc/1480/cmdlineJump to behavior
      Source: /tmp/debug.dbg.elf (PID: 5440)File opened: /proc/250/cmdlineJump to behavior
      Source: /tmp/debug.dbg.elf (PID: 5440)File opened: /proc/371/cmdlineJump to behavior
      Source: /tmp/debug.dbg.elf (PID: 5440)File opened: /proc/130/cmdlineJump to behavior
      Source: /tmp/debug.dbg.elf (PID: 5440)File opened: /proc/251/cmdlineJump to behavior
      Source: /tmp/debug.dbg.elf (PID: 5440)File opened: /proc/131/cmdlineJump to behavior
      Source: /tmp/debug.dbg.elf (PID: 5440)File opened: /proc/252/cmdlineJump to behavior
      Source: /tmp/debug.dbg.elf (PID: 5440)File opened: /proc/132/cmdlineJump to behavior
      Source: /tmp/debug.dbg.elf (PID: 5440)File opened: /proc/253/cmdlineJump to behavior
      Source: /tmp/debug.dbg.elf (PID: 5440)File opened: /proc/254/cmdlineJump to behavior
      Source: /tmp/debug.dbg.elf (PID: 5440)File opened: /proc/1238/cmdlineJump to behavior
      Source: /tmp/debug.dbg.elf (PID: 5440)File opened: /proc/134/cmdlineJump to behavior
      Source: /tmp/debug.dbg.elf (PID: 5440)File opened: /proc/255/cmdlineJump to behavior
      Source: /tmp/debug.dbg.elf (PID: 5440)File opened: /proc/256/cmdlineJump to behavior
      Source: /tmp/debug.dbg.elf (PID: 5440)File opened: /proc/257/cmdlineJump to behavior
      Source: /tmp/debug.dbg.elf (PID: 5440)File opened: /proc/378/cmdlineJump to behavior
      Source: /tmp/debug.dbg.elf (PID: 5440)File opened: /proc/3413/cmdlineJump to behavior
      Source: /tmp/debug.dbg.elf (PID: 5440)File opened: /proc/258/cmdlineJump to behavior
      Source: /tmp/debug.dbg.elf (PID: 5440)File opened: /proc/259/cmdlineJump to behavior
      Source: /tmp/debug.dbg.elf (PID: 5440)File opened: /proc/1475/cmdlineJump to behavior
      Source: /tmp/debug.dbg.elf (PID: 5440)File opened: /proc/936/cmdlineJump to behavior
      Source: /usr/bin/xfdesktop (PID: 5461)Queries kernel information via 'uname': Jump to behavior
      Source: /usr/bin/xfdesktop (PID: 5464)Queries kernel information via 'uname': Jump to behavior
      Source: /usr/bin/xfdesktop (PID: 5469)Queries kernel information via 'uname': Jump to behavior
      Source: /usr/bin/xfdesktop (PID: 5472)Queries kernel information via 'uname': Jump to behavior

      Stealing of Sensitive Information

      barindex
      Source: Yara matchFile source: debug.dbg.elf, type: SAMPLE
      Source: Yara matchFile source: 5439.1.0000000008048000.000000000805e000.r-x.sdmp, type: MEMORY
      Source: Yara matchFile source: 5441.1.0000000008048000.000000000805e000.r-x.sdmp, type: MEMORY
      Source: Yara matchFile source: Process Memory Space: debug.dbg.elf PID: 5439, type: MEMORYSTR
      Source: Yara matchFile source: Process Memory Space: debug.dbg.elf PID: 5441, type: MEMORYSTR

      Remote Access Functionality

      barindex
      Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)
      Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant Server Response
      Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant Server Response
      Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant Server Response
      Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant Server Response
      Source: Yara matchFile source: debug.dbg.elf, type: SAMPLE
      Source: Yara matchFile source: 5439.1.0000000008048000.000000000805e000.r-x.sdmp, type: MEMORY
      Source: Yara matchFile source: 5441.1.0000000008048000.000000000805e000.r-x.sdmp, type: MEMORY
      Source: Yara matchFile source: Process Memory Space: debug.dbg.elf PID: 5439, type: MEMORYSTR
      Source: Yara matchFile source: Process Memory Space: debug.dbg.elf PID: 5441, type: MEMORYSTR
      ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
      Gather Victim Identity Information1
      Scripting
      Valid AccountsWindows Management Instrumentation1
      Scripting
      Path Interception1
      Hidden Files and Directories
      1
      OS Credential Dumping
      1
      Security Software Discovery
      Remote ServicesData from Local System1
      Encrypted Channel
      Exfiltration Over Other Network Medium1
      Service Stop
      CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
      Non-Standard Port
      Exfiltration Over BluetoothNetwork Denial of Service
      Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
      Non-Application Layer Protocol
      Automated ExfiltrationData Encrypted for Impact
      Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture2
      Application Layer Protocol
      Traffic DuplicationData Destruction
      No configs have been found
      Hide Legend

      Legend:

      • Process
      • Signature
      • Created File
      • DNS/IP Info
      • Is Dropped
      • Number of created Files
      • Is malicious
      • Internet

      This section contains all screenshots as thumbnails, including those not shown in the slideshow.


      windows-stand
      SourceDetectionScannerLabelLink
      debug.dbg.elf55%ReversingLabsLinux.Backdoor.Mirai
      debug.dbg.elf100%AviraEXP/ELF.Mirai.Z.A
      debug.dbg.elf100%Joe Sandbox ML
      No Antivirus matches
      No Antivirus matches
      No Antivirus matches
      NameIPActiveMaliciousAntivirus DetectionReputation
      net-killer.ooguy.com
      103.229.52.72
      truetrue
        unknown
        • No. of IPs < 25%
        • 25% < No. of IPs < 50%
        • 50% < No. of IPs < 75%
        • 75% < No. of IPs
        IPDomainCountryFlagASNASN NameMalicious
        185.125.190.26
        unknownUnited Kingdom
        41231CANONICAL-ASGBfalse
        103.229.52.72
        net-killer.ooguy.comunknown
        59346AIS-AS-APAustralianITSolutionsGroupAUtrue
        MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
        185.125.190.26most-m68k.elfGet hashmaliciousMiraiBrowse
          xd.arm6.elfGet hashmaliciousMiraiBrowse
            SwiftSec.x86.elfGet hashmaliciousMiraiBrowse
              ub8ehJSePAfc9FYqZIT6.mips.elfGet hashmaliciousUnknownBrowse
                Demon.i586.elfGet hashmaliciousMirai, GafgytBrowse
                  sora.x86.elfGet hashmaliciousMiraiBrowse
                    la.bot.m68k.elfGet hashmaliciousMiraiBrowse
                      la.bot.powerpc.elfGet hashmaliciousMiraiBrowse
                        boatnet.arm.elfGet hashmaliciousMiraiBrowse
                          boatnet.arm6.elfGet hashmaliciousMiraiBrowse
                            103.229.52.72most-m68k.elfGet hashmaliciousMiraiBrowse
                              MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                              net-killer.ooguy.commost-m68k.elfGet hashmaliciousMiraiBrowse
                              • 103.229.52.72
                              most-x86.elfGet hashmaliciousMiraiBrowse
                              • 103.151.239.121
                              XxOe9bDTpp.elfGet hashmaliciousMiraiBrowse
                              • 103.151.239.121
                              MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                              CANONICAL-ASGBarm5.elfGet hashmaliciousMiraiBrowse
                              • 91.189.91.42
                              most-m68k.elfGet hashmaliciousMiraiBrowse
                              • 185.125.190.26
                              xd.m68k.elfGet hashmaliciousMiraiBrowse
                              • 91.189.91.42
                              xd.arm6.elfGet hashmaliciousMiraiBrowse
                              • 185.125.190.26
                              JUfxu4JbqY.elfGet hashmaliciousUnknownBrowse
                              • 91.189.91.42
                              QuBcacr1uG.elfGet hashmaliciousUnknownBrowse
                              • 91.189.91.42
                              a-r.m-6.SNOOPY.elfGet hashmaliciousGafgytBrowse
                              • 91.189.91.42
                              SwiftSec.arm.elfGet hashmaliciousMiraiBrowse
                              • 91.189.91.42
                              SwiftSec.x86.elfGet hashmaliciousMiraiBrowse
                              • 185.125.190.26
                              tarm6.elfGet hashmaliciousUnknownBrowse
                              • 91.189.91.42
                              AIS-AS-APAustralianITSolutionsGroupAUmost-m68k.elfGet hashmaliciousMiraiBrowse
                              • 103.229.52.72
                              lvyr5dba4iGet hashmaliciousMiraiBrowse
                              • 103.229.53.11
                              No context
                              No context
                              No created / dropped files found
                              File type:ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, stripped
                              Entropy (8bit):5.8537725879128875
                              TrID:
                              • ELF Executable and Linkable format (Linux) (4029/14) 50.16%
                              • ELF Executable and Linkable format (generic) (4004/1) 49.84%
                              File name:debug.dbg.elf
                              File size:108'676 bytes
                              MD5:b826f579cc0d33fd5a73f19c1340c61b
                              SHA1:aad3318fe083cda969b0eed1d7a33a7ae50b5efd
                              SHA256:e4aafe787b05ef696763687cec61e83a2cb5e6a7f597c2701a7e6892e42f7d46
                              SHA512:b95ecc47136ca0abcbe8c18f85f3ce61795ad426671e7deaa66623ee0de0374e09c85f2ad5e0e9f16277c975052e52227461e76bd00f748e9268fe597b198ea7
                              SSDEEP:3072:fXw76ePGL1eJN/UVCkMzz7tcWC3ki7/7FgY:fXw76ePGL1eT/UVZCtE0GjFgY
                              TLSH:3BB36C89F283D4F2E84715B06037E77AAE76D06A2119FB42C7289931FCC7541D617BAC
                              File Content Preview:.ELF....................d...4...........4. ...(......................Z...Z...............`...........F..L...........Q.td............................U..S.......{_...h.....-..[]...$.............U......=.&...t..5....D......D.......u........t....h............

                              ELF header

                              Class:ELF32
                              Data:2's complement, little endian
                              Version:1 (current)
                              Machine:Intel 80386
                              Version Number:0x1
                              Type:EXEC (Executable file)
                              OS/ABI:UNIX - System V
                              ABI Version:0
                              Entry Point Address:0x8048164
                              Flags:0x0
                              ELF Header Size:52
                              Program Header Offset:52
                              Program Header Size:32
                              Number of Program Headers:3
                              Section Header Offset:108276
                              Section Header Size:40
                              Number of Section Headers:10
                              Header String Table Index:9
                              NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                              NULL0x00x00x00x00x0000
                              .initPROGBITS0x80480940x940x1c0x00x6AX001
                              .textPROGBITS0x80480b00xb00x12da60x00x6AX0016
                              .finiPROGBITS0x805ae560x12e560x170x00x6AX001
                              .rodataPROGBITS0x805ae800x12e800x2c680x00x2A0032
                              .ctorsPROGBITS0x805e0000x160000xc0x00x3WA004
                              .dtorsPROGBITS0x805e00c0x1600c0x80x00x3WA004
                              .dataPROGBITS0x805e0400x160400x46740x00x3WA0032
                              .bssNOBITS0x80626c00x1a6b40x488c0x00x3WA0032
                              .shstrtabSTRTAB0x00x1a6b40x3e0x00x0001
                              TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                              LOAD0x00x80480000x80480000x15ae80x15ae86.61510x5R E0x1000.init .text .fini .rodata
                              LOAD0x160000x805e0000x805e0000x46b40x8f4c0.25310x6RW 0x1000.ctors .dtors .data .bss
                              GNU_STACK0x00x00x00x00x00.00000x6RW 0x4
                              TimestampSIDSignatureSeveritySource IPSource PortDest IPDest PortProtocol
                              2024-12-03T20:51:49.769558+01002030490ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)1192.168.2.1356784103.229.52.722023TCP
                              2024-12-03T20:51:51.192935+01002030489ET MALWARE ELF/MooBot Mirai DDoS Variant Server Response1103.229.52.722023192.168.2.1356784TCP
                              2024-12-03T20:51:53.339977+01002030489ET MALWARE ELF/MooBot Mirai DDoS Variant Server Response1103.229.52.722023192.168.2.1356784TCP
                              2024-12-03T20:52:13.358850+01002030489ET MALWARE ELF/MooBot Mirai DDoS Variant Server Response1103.229.52.722023192.168.2.1356784TCP
                              2024-12-03T20:52:33.368452+01002030489ET MALWARE ELF/MooBot Mirai DDoS Variant Server Response1103.229.52.722023192.168.2.1356784TCP
                              TimestampSource PortDest PortSource IPDest IP
                              Dec 3, 2024 20:51:49.649353027 CET567842023192.168.2.13103.229.52.72
                              Dec 3, 2024 20:51:49.769448996 CET202356784103.229.52.72192.168.2.13
                              Dec 3, 2024 20:51:49.769536972 CET567842023192.168.2.13103.229.52.72
                              Dec 3, 2024 20:51:49.769557953 CET567842023192.168.2.13103.229.52.72
                              Dec 3, 2024 20:51:49.900820971 CET202356784103.229.52.72192.168.2.13
                              Dec 3, 2024 20:51:51.192934990 CET202356784103.229.52.72192.168.2.13
                              Dec 3, 2024 20:51:51.192997932 CET567842023192.168.2.13103.229.52.72
                              Dec 3, 2024 20:51:53.339977026 CET202356784103.229.52.72192.168.2.13
                              Dec 3, 2024 20:51:53.340059042 CET567842023192.168.2.13103.229.52.72
                              Dec 3, 2024 20:51:59.401505947 CET48202443192.168.2.13185.125.190.26
                              Dec 3, 2024 20:52:03.517594099 CET567842023192.168.2.13103.229.52.72
                              Dec 3, 2024 20:52:03.637847900 CET202356784103.229.52.72192.168.2.13
                              Dec 3, 2024 20:52:13.358850002 CET202356784103.229.52.72192.168.2.13
                              Dec 3, 2024 20:52:13.358916998 CET567842023192.168.2.13103.229.52.72
                              Dec 3, 2024 20:52:30.117572069 CET48202443192.168.2.13185.125.190.26
                              Dec 3, 2024 20:52:33.368452072 CET202356784103.229.52.72192.168.2.13
                              Dec 3, 2024 20:52:33.368510008 CET567842023192.168.2.13103.229.52.72
                              Dec 3, 2024 20:52:33.766555071 CET567842023192.168.2.13103.229.52.72
                              Dec 3, 2024 20:52:33.886964083 CET202356784103.229.52.72192.168.2.13
                              Dec 3, 2024 20:52:33.887021065 CET567842023192.168.2.13103.229.52.72
                              TimestampSource PortDest PortSource IPDest IP
                              Dec 3, 2024 20:51:48.953463078 CET3997153192.168.2.138.8.8.8
                              Dec 3, 2024 20:51:49.568367004 CET53399718.8.8.8192.168.2.13
                              TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                              Dec 3, 2024 20:51:48.953463078 CET192.168.2.138.8.8.80x9ea1Standard query (0)net-killer.ooguy.comA (IP address)IN (0x0001)false
                              TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                              Dec 3, 2024 20:51:49.568367004 CET8.8.8.8192.168.2.130x9ea1No error (0)net-killer.ooguy.com103.229.52.72A (IP address)IN (0x0001)false

                              System Behavior

                              Start time (UTC):19:51:48
                              Start date (UTC):03/12/2024
                              Path:/tmp/debug.dbg.elf
                              Arguments:/tmp/debug.dbg.elf
                              File size:108676 bytes
                              MD5 hash:b826f579cc0d33fd5a73f19c1340c61b

                              Start time (UTC):19:51:48
                              Start date (UTC):03/12/2024
                              Path:/tmp/debug.dbg.elf
                              Arguments:-
                              File size:108676 bytes
                              MD5 hash:b826f579cc0d33fd5a73f19c1340c61b

                              Start time (UTC):19:51:48
                              Start date (UTC):03/12/2024
                              Path:/tmp/debug.dbg.elf
                              Arguments:-
                              File size:108676 bytes
                              MD5 hash:b826f579cc0d33fd5a73f19c1340c61b
                              Start time (UTC):19:51:49
                              Start date (UTC):03/12/2024
                              Path:/usr/bin/xfce4-session
                              Arguments:-
                              File size:264752 bytes
                              MD5 hash:648919f03ad356720c8c27f5aaaf75d1

                              Start time (UTC):19:51:49
                              Start date (UTC):03/12/2024
                              Path:/usr/bin/xfdesktop
                              Arguments:xfdesktop --display :1.0 --sm-client-id 260d40b3c-9c6a-4cb1-bbe4-3557725aa528
                              File size:473520 bytes
                              MD5 hash:dfb13e1581f80065dcea16f2476f16f2

                              Start time (UTC):19:51:49
                              Start date (UTC):03/12/2024
                              Path:/usr/bin/xfce4-session
                              Arguments:-
                              File size:264752 bytes
                              MD5 hash:648919f03ad356720c8c27f5aaaf75d1

                              Start time (UTC):19:51:50
                              Start date (UTC):03/12/2024
                              Path:/usr/bin/xfdesktop
                              Arguments:xfdesktop --display :1.0 --sm-client-id 260d40b3c-9c6a-4cb1-bbe4-3557725aa528
                              File size:473520 bytes
                              MD5 hash:dfb13e1581f80065dcea16f2476f16f2

                              Start time (UTC):19:51:52
                              Start date (UTC):03/12/2024
                              Path:/usr/bin/xfce4-session
                              Arguments:-
                              File size:264752 bytes
                              MD5 hash:648919f03ad356720c8c27f5aaaf75d1

                              Start time (UTC):19:51:52
                              Start date (UTC):03/12/2024
                              Path:/usr/bin/xfdesktop
                              Arguments:xfdesktop --display :1.0 --sm-client-id 260d40b3c-9c6a-4cb1-bbe4-3557725aa528
                              File size:473520 bytes
                              MD5 hash:dfb13e1581f80065dcea16f2476f16f2

                              Start time (UTC):19:51:54
                              Start date (UTC):03/12/2024
                              Path:/usr/bin/xfce4-session
                              Arguments:-
                              File size:264752 bytes
                              MD5 hash:648919f03ad356720c8c27f5aaaf75d1

                              Start time (UTC):19:51:54
                              Start date (UTC):03/12/2024
                              Path:/usr/bin/xfdesktop
                              Arguments:xfdesktop --display :1.0 --sm-client-id 260d40b3c-9c6a-4cb1-bbe4-3557725aa528
                              File size:473520 bytes
                              MD5 hash:dfb13e1581f80065dcea16f2476f16f2

                              Start time (UTC):19:51:56
                              Start date (UTC):03/12/2024
                              Path:/usr/bin/xfce4-session
                              Arguments:-
                              File size:264752 bytes
                              MD5 hash:648919f03ad356720c8c27f5aaaf75d1

                              Start time (UTC):19:51:56
                              Start date (UTC):03/12/2024
                              Path:/usr/bin/xfdesktop
                              Arguments:xfdesktop --display :1.0 --sm-client-id 260d40b3c-9c6a-4cb1-bbe4-3557725aa528
                              File size:473520 bytes
                              MD5 hash:dfb13e1581f80065dcea16f2476f16f2

                              Start time (UTC):19:54:32
                              Start date (UTC):03/12/2024
                              Path:/usr/lib/systemd/systemd
                              Arguments:-
                              File size:1620224 bytes
                              MD5 hash:9b2bec7092a40488108543f9334aab75