Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
most-x86_64.elf

Overview

General Information

Sample name:most-x86_64.elf
Analysis ID:1580820
MD5:16b764a6f05d307a39d5700276a5b045
SHA1:b20e01c604baf8048104976b1be425b51c66e5b2
SHA256:0084e80f57fffae677137645ec0a3a728f345b6b93397b4877eb48e5cdfa009d
Tags:elfuser-abuse_ch
Infos:

Detection

Mirai
Score:76
Range:0 - 100
Whitelisted:false

Signatures

Antivirus / Scanner detection for submitted sample
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Yara detected Mirai
Machine Learning detection for sample
Executes the "rm" command used to delete files or directories
Found strings indicative of a multi-platform dropper
Sample contains strings indicative of BusyBox which embeds multiple Unix commands in a single executable
Yara signature match

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1580820
Start date and time:2024-12-26 10:02:05 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 25s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:most-x86_64.elf
Detection:MAL
Classification:mal76.troj.linELF@0/0@0/0
Command:/tmp/most-x86_64.elf
PID:6233
Exit Code:139
Exit Code Info:SIGSEGV (11) Segmentation fault invalid memory reference
Killed:False
Standard Output:

Standard Error:
  • system is lnxubuntu20
  • dash New Fork (PID: 6260, Parent: 4331)
  • rm (PID: 6260, Parent: 4331, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.FlsIgEvZ3C /tmp/tmp.nJUaRX1JcV /tmp/tmp.4pvzDqUXO5
  • dash New Fork (PID: 6261, Parent: 4331)
  • cat (PID: 6261, Parent: 4331, MD5: 7e9d213e404ad3bb82e4ebb2e1f2c1b3) Arguments: cat /tmp/tmp.FlsIgEvZ3C
  • dash New Fork (PID: 6262, Parent: 4331)
  • head (PID: 6262, Parent: 4331, MD5: fd96a67145172477dd57131396fc9608) Arguments: head -n 10
  • dash New Fork (PID: 6263, Parent: 4331)
  • tr (PID: 6263, Parent: 4331, MD5: fbd1402dd9f72d8ebfff00ce7c3a7bb5) Arguments: tr -d \\000-\\011\\013\\014\\016-\\037
  • dash New Fork (PID: 6264, Parent: 4331)
  • cut (PID: 6264, Parent: 4331, MD5: d8ed0ea8f22c0de0f8692d4d9f1759d3) Arguments: cut -c -80
  • dash New Fork (PID: 6265, Parent: 4331)
  • cat (PID: 6265, Parent: 4331, MD5: 7e9d213e404ad3bb82e4ebb2e1f2c1b3) Arguments: cat /tmp/tmp.FlsIgEvZ3C
  • dash New Fork (PID: 6266, Parent: 4331)
  • head (PID: 6266, Parent: 4331, MD5: fd96a67145172477dd57131396fc9608) Arguments: head -n 10
  • dash New Fork (PID: 6267, Parent: 4331)
  • tr (PID: 6267, Parent: 4331, MD5: fbd1402dd9f72d8ebfff00ce7c3a7bb5) Arguments: tr -d \\000-\\011\\013\\014\\016-\\037
  • dash New Fork (PID: 6268, Parent: 4331)
  • cut (PID: 6268, Parent: 4331, MD5: d8ed0ea8f22c0de0f8692d4d9f1759d3) Arguments: cut -c -80
  • dash New Fork (PID: 6269, Parent: 4331)
  • rm (PID: 6269, Parent: 4331, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.FlsIgEvZ3C /tmp/tmp.nJUaRX1JcV /tmp/tmp.4pvzDqUXO5
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
MiraiMirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese. Nowadays it targets a wide range of networked embedded devices such as IP cameras, home routers (many vendors involved), and other IoT devices. Since the source code was published on "Hack Forums" many variants of the Mirai family appeared, infecting mostly home networks all around the world.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/elf.mirai
SourceRuleDescriptionAuthorStrings
most-x86_64.elfJoeSecurity_Mirai_8Yara detected MiraiJoe Security
    most-x86_64.elfLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
    • 0x17a48:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x17a5c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x17a70:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x17a84:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x17a98:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x17aac:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x17ac0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x17ad4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x17ae8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x17afc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x17b10:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x17b24:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x17b38:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x17b4c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x17b60:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x17b74:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x17b88:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x17b9c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x17bb0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x17bc4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x17bd8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    most-x86_64.elfLinux_Trojan_Gafgyt_9e9530a7unknownunknown
    • 0xdefc:$a: F6 48 63 FF B8 36 00 00 00 0F 05 48 3D 00 F0 FF FF 48 89 C3
    most-x86_64.elfLinux_Trojan_Gafgyt_d4227dbfunknownunknown
    • 0xb40e:$a: FF 48 81 EC D0 00 00 00 48 8D 84 24 E0 00 00 00 48 89 54 24 30 C7 04 24 18 00
    • 0xb472:$a: FF 48 81 EC D0 00 00 00 48 8D 84 24 E0 00 00 00 48 89 54 24 30 C7 04 24 18 00
    • 0x10665:$a: FF 48 81 EC D0 00 00 00 48 8D 84 24 E0 00 00 00 48 89 54 24 30 C7 04 24 18 00
    most-x86_64.elfLinux_Trojan_Gafgyt_d996d335unknownunknown
    • 0x11a8e:$a: D0 EB 0F 40 38 37 75 04 48 89 F8 C3 49 FF C8 48 FF C7 4D 85 C0
    Click to see the 3 entries
    No Suricata rule has matched

    Click to jump to signature section

    Show All Signature Results

    AV Detection

    barindex
    Source: most-x86_64.elfAvira: detected
    Source: most-x86_64.elfReversingLabs: Detection: 34%
    Source: most-x86_64.elfJoe Sandbox ML: detected
    Source: unknownHTTPS traffic detected: 54.171.230.55:443 -> 192.168.2.23:33606 version: TLS 1.2
    Source: most-x86_64.elfString: HTTP/1.1 200 OKmost-armmost-arm5most-arm6most-arm7most-mipsmost-mpslmost-x86_64most-sh4./pkillkillallwgetbusyboxtopcurltftppgrepxargsawktoybox./dvr_gui./upnp_server./dvr_app/proc/proc/%s/cmdlineKh
    Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
    Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
    Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
    Source: unknownTCP traffic detected without corresponding DNS query: 54.171.230.55
    Source: unknownTCP traffic detected without corresponding DNS query: 54.171.230.55
    Source: unknownTCP traffic detected without corresponding DNS query: 54.171.230.55
    Source: unknownTCP traffic detected without corresponding DNS query: 54.171.230.55
    Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
    Source: unknownTCP traffic detected without corresponding DNS query: 54.171.230.55
    Source: unknownTCP traffic detected without corresponding DNS query: 54.171.230.55
    Source: unknownTCP traffic detected without corresponding DNS query: 54.171.230.55
    Source: unknownTCP traffic detected without corresponding DNS query: 54.171.230.55
    Source: unknownTCP traffic detected without corresponding DNS query: 54.171.230.55
    Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
    Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
    Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 33606
    Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 33606 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443
    Source: unknownHTTPS traffic detected: 54.171.230.55:443 -> 192.168.2.23:33606 version: TLS 1.2

    System Summary

    barindex
    Source: most-x86_64.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
    Source: most-x86_64.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_9e9530a7 Author: unknown
    Source: most-x86_64.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_d4227dbf Author: unknown
    Source: most-x86_64.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_d996d335 Author: unknown
    Source: most-x86_64.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_620087b9 Author: unknown
    Source: most-x86_64.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_33b4111a Author: unknown
    Source: most-x86_64.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_564b8eda Author: unknown
    Source: Initial sampleString containing 'busybox' found: busybox
    Source: Initial sampleString containing 'busybox' found: HTTP/1.1 200 OKmost-armmost-arm5most-arm6most-arm7most-mipsmost-mpslmost-x86_64most-sh4./pkillkillallwgetbusyboxtopcurltftppgrepxargsawktoybox./dvr_gui./upnp_server./dvr_app/proc/proc/%s/cmdlineKh
    Source: most-x86_64.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
    Source: most-x86_64.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_9e9530a7 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = d6ad6512051e87c8c35dc168d82edd071b122d026dce21d39b9782b3d6a01e50, id = 9e9530a7-ad4d-4a44-b764-437b7621052f, last_modified = 2021-09-16
    Source: most-x86_64.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_d4227dbf reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 58c4b1d4d167876b64cfa10f609911a80284180e4db093917fea16fae8ccd4e3, id = d4227dbf-6ab4-4637-a6ba-0e604acaafb4, last_modified = 2021-09-16
    Source: most-x86_64.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_d996d335 reference_sample = b511eacd4b44744c8cf82d1b4a9bc6f1022fe6be7c5d17356b171f727ddc6eda, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = e9ccb8412f32187c309b0e9afcc3a6da21ad2f1ffa251c27f9f720ccb284e3ac, id = d996d335-e049-4052-bf36-6cd07c911a8b, last_modified = 2021-09-16
    Source: most-x86_64.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_620087b9 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 06cd7e6eb62352ec2ccb9ed48e58c0583c02fefd137cd048d053ab30b5330307, id = 620087b9-c87d-4752-89e8-ca1c16486b28, last_modified = 2021-09-16
    Source: most-x86_64.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_33b4111a reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 9c3b63b9a0f54006bae12abcefdb518904a85f78be573f0780f0a265b12d2d6e, id = 33b4111a-e59e-48db-9d74-34ca44fcd9f5, last_modified = 2021-09-16
    Source: most-x86_64.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_564b8eda reference_sample = ff04921d7bf9ca01ae33a9fc0743dce9ca250e42a33547c5665b1c9a0b5260ee, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 63a9e43902e7db0b7a20498b5a860e36201bacc407e9e336faca0b7cfbc37819, id = 564b8eda-6f0e-45b8-bef6-d61b0f090a36, last_modified = 2021-09-16
    Source: classification engineClassification label: mal76.troj.linELF@0/0@0/0
    Source: /usr/bin/dash (PID: 6260)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.FlsIgEvZ3C /tmp/tmp.nJUaRX1JcV /tmp/tmp.4pvzDqUXO5Jump to behavior
    Source: /usr/bin/dash (PID: 6269)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.FlsIgEvZ3C /tmp/tmp.nJUaRX1JcV /tmp/tmp.4pvzDqUXO5Jump to behavior

    Stealing of Sensitive Information

    barindex
    Source: Yara matchFile source: most-x86_64.elf, type: SAMPLE

    Remote Access Functionality

    barindex
    Source: Yara matchFile source: most-x86_64.elf, type: SAMPLE
    ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
    Gather Victim Identity Information1
    Scripting
    Valid AccountsWindows Management Instrumentation1
    Scripting
    Path Interception1
    File Deletion
    OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
    Encrypted Channel
    Exfiltration Over Other Network MediumAbuse Accessibility Features
    CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
    Application Layer Protocol
    Exfiltration Over BluetoothNetwork Denial of Service
    No configs have been found
    Hide Legend

    Legend:

    • Process
    • Signature
    • Created File
    • DNS/IP Info
    • Is Dropped
    • Number of created Files
    • Is malicious
    • Internet
    SourceDetectionScannerLabelLink
    most-x86_64.elf34%ReversingLabsLinux.Exploit.Mirai
    most-x86_64.elf100%AviraEXP/ELF.Mirai.Z.A
    most-x86_64.elf100%Joe Sandbox ML
    No Antivirus matches
    No Antivirus matches
    No Antivirus matches
    No contacted domains info
    • No. of IPs < 25%
    • 25% < No. of IPs < 50%
    • 50% < No. of IPs < 75%
    • 75% < No. of IPs
    IPDomainCountryFlagASNASN NameMalicious
    54.171.230.55
    unknownUnited States
    16509AMAZON-02USfalse
    109.202.202.202
    unknownSwitzerland
    13030INIT7CHfalse
    91.189.91.43
    unknownUnited Kingdom
    41231CANONICAL-ASGBfalse
    91.189.91.42
    unknownUnited Kingdom
    41231CANONICAL-ASGBfalse
    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
    54.171.230.55Mozi.m.elfGet hashmaliciousMiraiBrowse
      byte.x86.elfGet hashmaliciousMirai, OkiruBrowse
        armv4eb.elfGet hashmaliciousUnknownBrowse
          armv4eb.elfGet hashmaliciousMiraiBrowse
            zmap.mpsl.elfGet hashmaliciousMirai, OkiruBrowse
              x86_64.nn.elfGet hashmaliciousOkiruBrowse
                nsharm5.elfGet hashmaliciousUnknownBrowse
                  sh4.nn.elfGet hashmaliciousOkiruBrowse
                    mipsel.nn.elfGet hashmaliciousOkiruBrowse
                      zerarm6.elfGet hashmaliciousUnknownBrowse
                        109.202.202.202kpLwzBouH4.elfGet hashmaliciousUnknownBrowse
                        • ch.archive.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_92.0%2bbuild3-0ubuntu0.20.04.1_amd64.deb
                        91.189.91.43keksec.x86.elfGet hashmaliciousGafgyt, MiraiBrowse
                          .i.elfGet hashmaliciousUnknownBrowse
                            mips.elfGet hashmaliciousGafgyt, MiraiBrowse
                              Mozi.m.elfGet hashmaliciousMiraiBrowse
                                mipsel.elfGet hashmaliciousGafgyt, MiraiBrowse
                                  ub8ehJSePAfc9FYqZIT6.x86.elfGet hashmaliciousUnknownBrowse
                                    ngwa5.elfGet hashmaliciousMiraiBrowse
                                      fnkea7.elfGet hashmaliciousMiraiBrowse
                                        xd.arm5.elfGet hashmaliciousMiraiBrowse
                                          wkb86.elfGet hashmaliciousMiraiBrowse
                                            91.189.91.42keksec.x86.elfGet hashmaliciousGafgyt, MiraiBrowse
                                              .i.elfGet hashmaliciousUnknownBrowse
                                                mips.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                  Mozi.m.elfGet hashmaliciousMiraiBrowse
                                                    mipsel.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                      ub8ehJSePAfc9FYqZIT6.x86.elfGet hashmaliciousUnknownBrowse
                                                        ngwa5.elfGet hashmaliciousMiraiBrowse
                                                          fnkea7.elfGet hashmaliciousMiraiBrowse
                                                            xd.arm5.elfGet hashmaliciousMiraiBrowse
                                                              telnet.arm7.elfGet hashmaliciousUnknownBrowse
                                                                No context
                                                                MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                CANONICAL-ASGBkeksec.x86.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                                • 91.189.91.42
                                                                .i.elfGet hashmaliciousUnknownBrowse
                                                                • 91.189.91.42
                                                                mips.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                                • 91.189.91.42
                                                                Mozi.m.elfGet hashmaliciousMiraiBrowse
                                                                • 91.189.91.42
                                                                mipsel.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                                • 91.189.91.42
                                                                ub8ehJSePAfc9FYqZIT6.x86.elfGet hashmaliciousUnknownBrowse
                                                                • 91.189.91.42
                                                                ngwa5.elfGet hashmaliciousMiraiBrowse
                                                                • 91.189.91.42
                                                                fnkea7.elfGet hashmaliciousMiraiBrowse
                                                                • 91.189.91.42
                                                                xd.arm5.elfGet hashmaliciousMiraiBrowse
                                                                • 91.189.91.42
                                                                telnet.arm7.elfGet hashmaliciousUnknownBrowse
                                                                • 91.189.91.42
                                                                CANONICAL-ASGBkeksec.x86.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                                • 91.189.91.42
                                                                .i.elfGet hashmaliciousUnknownBrowse
                                                                • 91.189.91.42
                                                                mips.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                                • 91.189.91.42
                                                                Mozi.m.elfGet hashmaliciousMiraiBrowse
                                                                • 91.189.91.42
                                                                mipsel.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                                • 91.189.91.42
                                                                ub8ehJSePAfc9FYqZIT6.x86.elfGet hashmaliciousUnknownBrowse
                                                                • 91.189.91.42
                                                                ngwa5.elfGet hashmaliciousMiraiBrowse
                                                                • 91.189.91.42
                                                                fnkea7.elfGet hashmaliciousMiraiBrowse
                                                                • 91.189.91.42
                                                                xd.arm5.elfGet hashmaliciousMiraiBrowse
                                                                • 91.189.91.42
                                                                telnet.arm7.elfGet hashmaliciousUnknownBrowse
                                                                • 91.189.91.42
                                                                AMAZON-02USMozi.m.elfGet hashmaliciousMiraiBrowse
                                                                • 54.171.230.55
                                                                Google Authenticator You're trying to sign in from a new location.msgGet hashmaliciousUnknownBrowse
                                                                • 52.31.78.174
                                                                xd.arm7.elfGet hashmaliciousMiraiBrowse
                                                                • 13.253.145.149
                                                                xd.x86.elfGet hashmaliciousMiraiBrowse
                                                                • 13.217.90.231
                                                                xd.ppc.elfGet hashmaliciousMiraiBrowse
                                                                • 13.236.144.167
                                                                telnet.arm7.elfGet hashmaliciousUnknownBrowse
                                                                • 34.249.145.219
                                                                xd.sh4.elfGet hashmaliciousMiraiBrowse
                                                                • 54.103.155.156
                                                                xd.mpsl.elfGet hashmaliciousMiraiBrowse
                                                                • 13.229.67.134
                                                                telnet.ppc.elfGet hashmaliciousUnknownBrowse
                                                                • 13.214.69.250
                                                                telnet.arm.elfGet hashmaliciousUnknownBrowse
                                                                • 52.30.223.93
                                                                INIT7CHkeksec.x86.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                                • 109.202.202.202
                                                                .i.elfGet hashmaliciousUnknownBrowse
                                                                • 109.202.202.202
                                                                mips.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                                • 109.202.202.202
                                                                Mozi.m.elfGet hashmaliciousMiraiBrowse
                                                                • 109.202.202.202
                                                                mipsel.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                                • 109.202.202.202
                                                                ub8ehJSePAfc9FYqZIT6.x86.elfGet hashmaliciousUnknownBrowse
                                                                • 109.202.202.202
                                                                ngwa5.elfGet hashmaliciousMiraiBrowse
                                                                • 109.202.202.202
                                                                fnkea7.elfGet hashmaliciousMiraiBrowse
                                                                • 109.202.202.202
                                                                xd.arm5.elfGet hashmaliciousMiraiBrowse
                                                                • 109.202.202.202
                                                                telnet.arm7.elfGet hashmaliciousUnknownBrowse
                                                                • 109.202.202.202
                                                                No context
                                                                No context
                                                                No created / dropped files found
                                                                File type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), statically linked, missing section headers at 195120
                                                                Entropy (8bit):4.780297199074252
                                                                TrID:
                                                                • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                                                                File name:most-x86_64.elf
                                                                File size:164'808 bytes
                                                                MD5:16b764a6f05d307a39d5700276a5b045
                                                                SHA1:b20e01c604baf8048104976b1be425b51c66e5b2
                                                                SHA256:0084e80f57fffae677137645ec0a3a728f345b6b93397b4877eb48e5cdfa009d
                                                                SHA512:ac6213a7aa865a3c01360c29beb44e426982a8975a858fbb440ef7f6d433d2a87705c730496ad04c5c16b267f6047063786a332e26611dfd593541cb35a5fc3b
                                                                SSDEEP:3072:eL9D+tG8Fg8g8Z0J6Vf68dRRhmifGPfJVaG:O9DX8q8r5lGZoG
                                                                TLSH:C1F34B07B5C290FDC4CAC1744B9FB537ED32B4AD1238B16B27D4AA229E49E311F2DA51
                                                                File Content Preview:.ELF..............>.......@.....@...................@.8...@.......................@.......@.....................................X.......X.R.......Q.....X.......................Q.td....................................................H...._....Jt..H........
                                                                TimestampSource PortDest PortSource IPDest IP
                                                                Dec 26, 2024 10:02:50.597446918 CET43928443192.168.2.2391.189.91.42
                                                                Dec 26, 2024 10:02:55.972807884 CET42836443192.168.2.2391.189.91.43
                                                                Dec 26, 2024 10:02:57.508503914 CET4251680192.168.2.23109.202.202.202
                                                                Dec 26, 2024 10:03:09.533828020 CET4433360654.171.230.55192.168.2.23
                                                                Dec 26, 2024 10:03:09.533849001 CET4433360654.171.230.55192.168.2.23
                                                                Dec 26, 2024 10:03:09.533864975 CET4433360654.171.230.55192.168.2.23
                                                                Dec 26, 2024 10:03:09.533972025 CET33606443192.168.2.2354.171.230.55
                                                                Dec 26, 2024 10:03:09.534012079 CET33606443192.168.2.2354.171.230.55
                                                                Dec 26, 2024 10:03:09.534012079 CET33606443192.168.2.2354.171.230.55
                                                                Dec 26, 2024 10:03:09.534938097 CET33606443192.168.2.2354.171.230.55
                                                                Dec 26, 2024 10:03:09.654439926 CET4433360654.171.230.55192.168.2.23
                                                                Dec 26, 2024 10:03:10.818656921 CET43928443192.168.2.2391.189.91.42
                                                                Dec 26, 2024 10:03:11.298434973 CET4433360654.171.230.55192.168.2.23
                                                                Dec 26, 2024 10:03:11.298738003 CET33606443192.168.2.2354.171.230.55
                                                                Dec 26, 2024 10:03:11.299118996 CET33606443192.168.2.2354.171.230.55
                                                                Dec 26, 2024 10:03:11.418654919 CET4433360654.171.230.55192.168.2.23
                                                                Dec 26, 2024 10:03:11.694083929 CET4433360654.171.230.55192.168.2.23
                                                                Dec 26, 2024 10:03:11.694288015 CET33606443192.168.2.2354.171.230.55
                                                                Dec 26, 2024 10:03:11.695651054 CET33606443192.168.2.2354.171.230.55
                                                                Dec 26, 2024 10:03:11.880577087 CET4433360654.171.230.55192.168.2.23
                                                                Dec 26, 2024 10:03:11.880670071 CET33606443192.168.2.2354.171.230.55
                                                                Dec 26, 2024 10:03:23.104975939 CET42836443192.168.2.2391.189.91.43
                                                                Dec 26, 2024 10:03:27.200423002 CET4251680192.168.2.23109.202.202.202
                                                                Dec 26, 2024 10:03:51.773032904 CET43928443192.168.2.2391.189.91.42
                                                                TimestampSource IPSource PortDest IPDest PortSubjectIssuerNot BeforeNot AfterJA3 SSL Client FingerprintJA3 SSL Client Digest
                                                                Dec 26, 2024 10:03:09.533864975 CET54.171.230.55443192.168.2.2333606CN=motd.ubuntu.com CN=R11, O=Let's Encrypt, C=USCN=R11, O=Let's Encrypt, C=US CN=ISRG Root X1, O=Internet Security Research Group, C=USMon Oct 21 10:21:37 CEST 2024 Wed Mar 13 01:00:00 CET 2024Sun Jan 19 09:21:36 CET 2025 Sat Mar 13 00:59:59 CET 2027
                                                                CN=R11, O=Let's Encrypt, C=USCN=ISRG Root X1, O=Internet Security Research Group, C=USWed Mar 13 01:00:00 CET 2024Sat Mar 13 00:59:59 CET 2027

                                                                System Behavior

                                                                Start time (UTC):09:03:11
                                                                Start date (UTC):26/12/2024
                                                                Path:/usr/bin/dash
                                                                Arguments:-
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):09:03:11
                                                                Start date (UTC):26/12/2024
                                                                Path:/usr/bin/rm
                                                                Arguments:rm -f /tmp/tmp.FlsIgEvZ3C /tmp/tmp.nJUaRX1JcV /tmp/tmp.4pvzDqUXO5
                                                                File size:72056 bytes
                                                                MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b

                                                                Start time (UTC):09:03:11
                                                                Start date (UTC):26/12/2024
                                                                Path:/usr/bin/dash
                                                                Arguments:-
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):09:03:11
                                                                Start date (UTC):26/12/2024
                                                                Path:/usr/bin/cat
                                                                Arguments:cat /tmp/tmp.FlsIgEvZ3C
                                                                File size:43416 bytes
                                                                MD5 hash:7e9d213e404ad3bb82e4ebb2e1f2c1b3

                                                                Start time (UTC):09:03:11
                                                                Start date (UTC):26/12/2024
                                                                Path:/usr/bin/dash
                                                                Arguments:-
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):09:03:11
                                                                Start date (UTC):26/12/2024
                                                                Path:/usr/bin/head
                                                                Arguments:head -n 10
                                                                File size:47480 bytes
                                                                MD5 hash:fd96a67145172477dd57131396fc9608

                                                                Start time (UTC):09:03:11
                                                                Start date (UTC):26/12/2024
                                                                Path:/usr/bin/dash
                                                                Arguments:-
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):09:03:11
                                                                Start date (UTC):26/12/2024
                                                                Path:/usr/bin/tr
                                                                Arguments:tr -d \\000-\\011\\013\\014\\016-\\037
                                                                File size:51544 bytes
                                                                MD5 hash:fbd1402dd9f72d8ebfff00ce7c3a7bb5

                                                                Start time (UTC):09:03:11
                                                                Start date (UTC):26/12/2024
                                                                Path:/usr/bin/dash
                                                                Arguments:-
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):09:03:11
                                                                Start date (UTC):26/12/2024
                                                                Path:/usr/bin/cut
                                                                Arguments:cut -c -80
                                                                File size:47480 bytes
                                                                MD5 hash:d8ed0ea8f22c0de0f8692d4d9f1759d3

                                                                Start time (UTC):09:03:11
                                                                Start date (UTC):26/12/2024
                                                                Path:/usr/bin/dash
                                                                Arguments:-
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):09:03:11
                                                                Start date (UTC):26/12/2024
                                                                Path:/usr/bin/cat
                                                                Arguments:cat /tmp/tmp.FlsIgEvZ3C
                                                                File size:43416 bytes
                                                                MD5 hash:7e9d213e404ad3bb82e4ebb2e1f2c1b3

                                                                Start time (UTC):09:03:11
                                                                Start date (UTC):26/12/2024
                                                                Path:/usr/bin/dash
                                                                Arguments:-
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):09:03:11
                                                                Start date (UTC):26/12/2024
                                                                Path:/usr/bin/head
                                                                Arguments:head -n 10
                                                                File size:47480 bytes
                                                                MD5 hash:fd96a67145172477dd57131396fc9608

                                                                Start time (UTC):09:03:11
                                                                Start date (UTC):26/12/2024
                                                                Path:/usr/bin/dash
                                                                Arguments:-
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):09:03:11
                                                                Start date (UTC):26/12/2024
                                                                Path:/usr/bin/tr
                                                                Arguments:tr -d \\000-\\011\\013\\014\\016-\\037
                                                                File size:51544 bytes
                                                                MD5 hash:fbd1402dd9f72d8ebfff00ce7c3a7bb5

                                                                Start time (UTC):09:03:11
                                                                Start date (UTC):26/12/2024
                                                                Path:/usr/bin/dash
                                                                Arguments:-
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):09:03:11
                                                                Start date (UTC):26/12/2024
                                                                Path:/usr/bin/cut
                                                                Arguments:cut -c -80
                                                                File size:47480 bytes
                                                                MD5 hash:d8ed0ea8f22c0de0f8692d4d9f1759d3

                                                                Start time (UTC):09:03:11
                                                                Start date (UTC):26/12/2024
                                                                Path:/usr/bin/dash
                                                                Arguments:-
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):09:03:11
                                                                Start date (UTC):26/12/2024
                                                                Path:/usr/bin/rm
                                                                Arguments:rm -f /tmp/tmp.FlsIgEvZ3C /tmp/tmp.nJUaRX1JcV /tmp/tmp.4pvzDqUXO5
                                                                File size:72056 bytes
                                                                MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b