Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
mpsl.elf

Overview

General Information

Sample name:mpsl.elf
Analysis ID:1583609
MD5:a32c76d7ac1b134d807acb9d1146a833
SHA1:9ff81ef4321029bbc7b47c25375545c4f9bc8b26
SHA256:915dccaa387bdf81c0f3d87d150b7f626208ddbaf09316f06cf16574bbfd5f94
Tags:elfuser-abuse_ch
Infos:

Detection

Score:48
Range:0 - 100
Whitelisted:false

Signatures

Multi AV Scanner detection for submitted file
Detected TCP or UDP traffic on non-standard ports
Sample has stripped symbol table
Sample listens on a socket
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1583609
Start date and time:2025-01-03 07:56:06 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 56s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:mpsl.elf
Detection:MAL
Classification:mal48.linELF@0/0@0/0
Command:/tmp/mpsl.elf
PID:5833
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:

Standard Error:
  • system is lnxubuntu20
  • mpsl.elf (PID: 5833, Parent: 5759, MD5: 0d6f61f82cf2f781c6eb0661071d42d9) Arguments: /tmp/mpsl.elf
    • mpsl.elf New Fork (PID: 5835, Parent: 5833)
  • cleanup
No yara matches
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: mpsl.elfVirustotal: Detection: 12%Perma Link
Source: mpsl.elfReversingLabs: Detection: 15%
Source: global trafficTCP traffic: 192.168.2.15:36986 -> 85.239.34.134:31337
Source: /tmp/mpsl.elf (PID: 5833)Socket: 0.0.0.0:3142Jump to behavior
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: ELF static info symbol of initial sample.symtab present: no
Source: classification engineClassification label: mal48.linELF@0/0@0/0
Source: /tmp/mpsl.elf (PID: 5833)Queries kernel information via 'uname': Jump to behavior
Source: mpsl.elf, 5833.1.000055746cf9e000.000055746d025000.rw-.sdmpBinary or memory string: ltU!/etc/qemu-binfmt/mipsel
Source: mpsl.elf, 5833.1.000055746cf9e000.000055746d025000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/mipsel
Source: mpsl.elf, 5833.1.00007fff8b02f000.00007fff8b050000.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-mipsel/tmp/mpsl.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/mpsl.elf
Source: mpsl.elf, 5833.1.00007fff8b02f000.00007fff8b050000.rw-.sdmpBinary or memory string: /usr/bin/qemu-mipsel
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath InterceptionDirect Volume AccessOS Credential Dumping11
Security Software Discovery
Remote ServicesData from Local System1
Non-Standard Port
Exfiltration Over Other Network MediumAbuse Accessibility Features
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
SourceDetectionScannerLabelLink
mpsl.elf13%VirustotalBrowse
mpsl.elf16%ReversingLabsLinux.Backdoor.Gafgyt
No Antivirus matches
No Antivirus matches
No Antivirus matches
No contacted domains info
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs
IPDomainCountryFlagASNASN NameMalicious
85.239.34.134
unknownRussian Federation
134121RAINBOW-HKRainbownetworklimitedHKfalse
MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
85.239.34.134m68k.elfGet hashmaliciousUnknownBrowse
    arm6.elfGet hashmaliciousUnknownBrowse
      mips.elfGet hashmaliciousUnknownBrowse
        arm5.elfGet hashmaliciousUnknownBrowse
          spc.elfGet hashmaliciousUnknownBrowse
            sh4.elfGet hashmaliciousUnknownBrowse
              arm7.elfGet hashmaliciousUnknownBrowse
                arm.elfGet hashmaliciousUnknownBrowse
                  arm7.elfGet hashmaliciousUnknownBrowse
                    mpsl.elfGet hashmaliciousUnknownBrowse
                      No context
                      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                      RAINBOW-HKRainbownetworklimitedHKm68k.elfGet hashmaliciousUnknownBrowse
                      • 85.239.34.134
                      arm6.elfGet hashmaliciousUnknownBrowse
                      • 85.239.34.134
                      mips.elfGet hashmaliciousUnknownBrowse
                      • 85.239.34.134
                      arm5.elfGet hashmaliciousUnknownBrowse
                      • 85.239.34.134
                      spc.elfGet hashmaliciousUnknownBrowse
                      • 85.239.34.134
                      sh4.elfGet hashmaliciousUnknownBrowse
                      • 85.239.34.134
                      arm7.elfGet hashmaliciousUnknownBrowse
                      • 85.239.34.134
                      arm.elfGet hashmaliciousUnknownBrowse
                      • 85.239.34.134
                      https://klickskydd.skolverket.org/?url=https%3A%2F%2Fwww.gazeta.ru%2Fpolitics%2Fnews%2F2024%2F12%2F22%2F24684722.shtml&id=71de&rcpt=upplysningstjansten@skolverket.se&tss=1735469857&msgid=b53e7603-c5d3-11ef-8a2e-0050569b0508&html=1&h=ded85c63Get hashmaliciousHTMLPhisherBrowse
                      • 45.138.161.76
                      https://www.gazeta.ru/politics/news/2024/12/22/24684722.shtmlGet hashmaliciousHTMLPhisherBrowse
                      • 45.138.161.75
                      No context
                      No context
                      No created / dropped files found
                      File type:ELF 32-bit LSB executable, MIPS, MIPS-I version 1 (SYSV), statically linked, stripped
                      Entropy (8bit):5.264590708563799
                      TrID:
                      • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                      File name:mpsl.elf
                      File size:31'008 bytes
                      MD5:a32c76d7ac1b134d807acb9d1146a833
                      SHA1:9ff81ef4321029bbc7b47c25375545c4f9bc8b26
                      SHA256:915dccaa387bdf81c0f3d87d150b7f626208ddbaf09316f06cf16574bbfd5f94
                      SHA512:fd40a333837a300f4cd87bd59b206eb564c44efa42073906c242bcc147813fc3396f8b35ec8e848c5999003271b6fdfb5a90166389ecb1038dae7952645e43be
                      SSDEEP:384:zdtLtTRbznBxop8JI5fSTvKIZdVF+EZk/sughXiHcx8VX+oCe:zdtLFTxoUmfSWY2shXiHcx8VX+o
                      TLSH:6DD2FA06AFE21EBBDC5FCD3340E90B9625CCD61971657BA63430D81CB68F45B4AD38A8
                      File Content Preview:.ELF......................@.4...xv......4. ...(...............@...@..o...o...............p...p@..p@......3..............Dp..Dp@.Dp@.................Q.td...............................<...'!......'.......................<...'!.............9'.. ............

                      ELF header

                      Class:ELF32
                      Data:2's complement, little endian
                      Version:1 (current)
                      Machine:MIPS R3000
                      Version Number:0x1
                      Type:EXEC (Executable file)
                      OS/ABI:UNIX - System V
                      ABI Version:0
                      Entry Point Address:0x400290
                      Flags:0x1007
                      ELF Header Size:52
                      Program Header Offset:52
                      Program Header Size:32
                      Number of Program Headers:4
                      Section Header Offset:30328
                      Section Header Size:40
                      Number of Section Headers:17
                      Header String Table Index:16
                      NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                      NULL0x00x00x00x00x0000
                      .initPROGBITS0x4000b40xb40x8c0x00x6AX004
                      .textPROGBITS0x4001400x1400x6a300x00x6AX0016
                      .finiPROGBITS0x406b700x6b700x5c0x00x6AX004
                      .rodataPROGBITS0x406bd00x6bd00x3f00x00x2A0016
                      .eh_framePROGBITS0x4070000x70000x440x00x3WA004
                      .tbssNOBITS0x4070440x70440x80x00x403WAT004
                      .ctorsPROGBITS0x4070440x70440x80x00x3WA004
                      .dtorsPROGBITS0x40704c0x704c0x80x00x3WA004
                      .jcrPROGBITS0x4070540x70540x40x00x3WA004
                      .data.rel.roPROGBITS0x4070580x70580x40x00x3WA004
                      .dataPROGBITS0x4070600x70600x1480x00x3WA0016
                      .gotPROGBITS0x4071b00x71b00x44c0x40x10000003WAp0016
                      .sbssNOBITS0x4075fc0x75fc0x280x00x10000003WAp004
                      .bssNOBITS0x4076300x75fc0x2dcc0x00x3WA0016
                      .mdebug.abi32PROGBITS0x7bc0x75fc0x00x00x0001
                      .shstrtabSTRTAB0x00x75fc0x790x00x0001
                      TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                      LOAD0x00x4000000x4000000x6fc00x6fc05.37550x5R E0x1000.init .text .fini .rodata
                      LOAD0x70000x4070000x4070000x5fc0x33fc2.72750x6RW 0x1000.eh_frame .tbss .ctors .dtors .jcr .data.rel.ro .data .got .sbss .bss
                      TLS0x70440x4070440x4070440x00x80.00000x4R 0x4.tbss
                      GNU_STACK0x00x00x00x00x00.00000x7RWE0x4
                      TimestampSource PortDest PortSource IPDest IP
                      Jan 3, 2025 07:57:25.169226885 CET3698631337192.168.2.1585.239.34.134
                      Jan 3, 2025 07:57:25.174242020 CET313373698685.239.34.134192.168.2.15
                      Jan 3, 2025 07:57:25.174367905 CET3698631337192.168.2.1585.239.34.134
                      Jan 3, 2025 07:57:25.174668074 CET3698631337192.168.2.1585.239.34.134
                      Jan 3, 2025 07:57:25.179514885 CET313373698685.239.34.134192.168.2.15
                      Jan 3, 2025 07:57:25.881894112 CET313373698685.239.34.134192.168.2.15
                      Jan 3, 2025 07:57:25.882024050 CET3698631337192.168.2.1585.239.34.134
                      Jan 3, 2025 07:57:25.882265091 CET3698631337192.168.2.1585.239.34.134
                      Jan 3, 2025 07:57:25.887106895 CET313373698685.239.34.134192.168.2.15
                      Jan 3, 2025 07:57:26.126718044 CET313373698685.239.34.134192.168.2.15
                      Jan 3, 2025 07:57:26.126975060 CET3698631337192.168.2.1585.239.34.134
                      Jan 3, 2025 07:57:36.137130976 CET3698631337192.168.2.1585.239.34.134
                      Jan 3, 2025 07:57:36.142136097 CET313373698685.239.34.134192.168.2.15
                      Jan 3, 2025 07:57:36.358015060 CET313373698685.239.34.134192.168.2.15
                      Jan 3, 2025 07:57:36.358139038 CET3698631337192.168.2.1585.239.34.134
                      Jan 3, 2025 07:57:36.358731985 CET3698631337192.168.2.1585.239.34.134
                      Jan 3, 2025 07:57:36.363506079 CET313373698685.239.34.134192.168.2.15
                      Jan 3, 2025 07:57:46.368635893 CET3698631337192.168.2.1585.239.34.134
                      Jan 3, 2025 07:57:46.373609066 CET313373698685.239.34.134192.168.2.15
                      Jan 3, 2025 07:57:46.589322090 CET313373698685.239.34.134192.168.2.15
                      Jan 3, 2025 07:57:46.589432955 CET3698631337192.168.2.1585.239.34.134
                      Jan 3, 2025 07:57:56.599422932 CET3698631337192.168.2.1585.239.34.134
                      Jan 3, 2025 07:57:56.604248047 CET313373698685.239.34.134192.168.2.15
                      Jan 3, 2025 07:57:56.826235056 CET313373698685.239.34.134192.168.2.15
                      Jan 3, 2025 07:57:56.826402903 CET3698631337192.168.2.1585.239.34.134
                      Jan 3, 2025 07:58:06.836406946 CET3698631337192.168.2.1585.239.34.134
                      Jan 3, 2025 07:58:06.841197014 CET313373698685.239.34.134192.168.2.15
                      Jan 3, 2025 07:58:07.057212114 CET313373698685.239.34.134192.168.2.15
                      Jan 3, 2025 07:58:07.057327986 CET3698631337192.168.2.1585.239.34.134
                      Jan 3, 2025 07:58:17.067181110 CET3698631337192.168.2.1585.239.34.134
                      Jan 3, 2025 07:58:17.071974993 CET313373698685.239.34.134192.168.2.15
                      Jan 3, 2025 07:58:17.288018942 CET313373698685.239.34.134192.168.2.15
                      Jan 3, 2025 07:58:17.288280964 CET3698631337192.168.2.1585.239.34.134
                      Jan 3, 2025 07:58:27.298012972 CET3698631337192.168.2.1585.239.34.134
                      Jan 3, 2025 07:58:27.302838087 CET313373698685.239.34.134192.168.2.15
                      Jan 3, 2025 07:58:27.527331114 CET313373698685.239.34.134192.168.2.15
                      Jan 3, 2025 07:58:27.527492046 CET3698631337192.168.2.1585.239.34.134
                      Jan 3, 2025 07:58:37.537465096 CET3698631337192.168.2.1585.239.34.134
                      Jan 3, 2025 07:58:37.542229891 CET313373698685.239.34.134192.168.2.15
                      Jan 3, 2025 07:58:37.758138895 CET313373698685.239.34.134192.168.2.15
                      Jan 3, 2025 07:58:37.758260965 CET3698631337192.168.2.1585.239.34.134
                      Jan 3, 2025 07:58:47.768176079 CET3698631337192.168.2.1585.239.34.134
                      Jan 3, 2025 07:58:47.773020029 CET313373698685.239.34.134192.168.2.15
                      Jan 3, 2025 07:58:47.988660097 CET313373698685.239.34.134192.168.2.15
                      Jan 3, 2025 07:58:47.988814116 CET3698631337192.168.2.1585.239.34.134
                      Jan 3, 2025 07:58:57.998665094 CET3698631337192.168.2.1585.239.34.134
                      Jan 3, 2025 07:58:58.004271030 CET313373698685.239.34.134192.168.2.15
                      Jan 3, 2025 07:58:58.226217985 CET313373698685.239.34.134192.168.2.15
                      Jan 3, 2025 07:58:58.226399899 CET3698631337192.168.2.1585.239.34.134
                      Jan 3, 2025 07:59:08.236268997 CET3698631337192.168.2.1585.239.34.134
                      Jan 3, 2025 07:59:08.241122007 CET313373698685.239.34.134192.168.2.15
                      Jan 3, 2025 07:59:08.457048893 CET313373698685.239.34.134192.168.2.15
                      Jan 3, 2025 07:59:08.457353115 CET3698631337192.168.2.1585.239.34.134
                      Jan 3, 2025 07:59:18.467276096 CET3698631337192.168.2.1585.239.34.134
                      Jan 3, 2025 07:59:18.472095013 CET313373698685.239.34.134192.168.2.15
                      Jan 3, 2025 07:59:18.687833071 CET313373698685.239.34.134192.168.2.15
                      Jan 3, 2025 07:59:18.687964916 CET3698631337192.168.2.1585.239.34.134
                      Jan 3, 2025 07:59:28.698081017 CET3698631337192.168.2.1585.239.34.134
                      Jan 3, 2025 07:59:28.702996969 CET313373698685.239.34.134192.168.2.15
                      Jan 3, 2025 07:59:28.926564932 CET313373698685.239.34.134192.168.2.15
                      Jan 3, 2025 07:59:28.926930904 CET3698631337192.168.2.1585.239.34.134

                      System Behavior

                      Start time (UTC):06:57:24
                      Start date (UTC):03/01/2025
                      Path:/tmp/mpsl.elf
                      Arguments:/tmp/mpsl.elf
                      File size:5773336 bytes
                      MD5 hash:0d6f61f82cf2f781c6eb0661071d42d9

                      Start time (UTC):06:57:24
                      Start date (UTC):03/01/2025
                      Path:/tmp/mpsl.elf
                      Arguments:-
                      File size:5773336 bytes
                      MD5 hash:0d6f61f82cf2f781c6eb0661071d42d9