Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
unix.ppc.elf

Overview

General Information

Sample name:unix.ppc.elf
Analysis ID:1584469
MD5:c5969e84a54f82ba88ec2a3e9e7a8d52
SHA1:92af8b1462a0b58075319b43e622966a1570d7ee
SHA256:473b1cdbb12e360f56397702cc9d3d6c1bb993b372f28dd34accbadaf6742eab
Tags:elfuser-abuse_ch
Infos:

Detection

Mirai
Score:88
Range:0 - 100
Whitelisted:false

Signatures

Antivirus / Scanner detection for submitted sample
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Yara detected Mirai
Sample deletes itself
Uses dynamic DNS services
Creates hidden files and/or directories
Detected TCP or UDP traffic on non-standard ports
Sample has stripped symbol table
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Uses the "uname" system call to query kernel version information (possible evasion)
Yara signature match

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1584469
Start date and time:2025-01-05 15:32:10 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 44s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:unix.ppc.elf
Detection:MAL
Classification:mal88.troj.evad.linELF@0/0@6/0
Command:/tmp/unix.ppc.elf
PID:6259
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:

Standard Error:
  • system is lnxubuntu20
  • unix.ppc.elf (PID: 6259, Parent: 6183, MD5: ae65271c943d3451b7f026d1fadccea6) Arguments: /tmp/unix.ppc.elf
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
MiraiMirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese. Nowadays it targets a wide range of networked embedded devices such as IP cameras, home routers (many vendors involved), and other IoT devices. Since the source code was published on "Hack Forums" many variants of the Mirai family appeared, infecting mostly home networks all around the world.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/elf.mirai
SourceRuleDescriptionAuthorStrings
unix.ppc.elfJoeSecurity_Mirai_3Yara detected MiraiJoe Security
    unix.ppc.elfJoeSecurity_Mirai_8Yara detected MiraiJoe Security
      unix.ppc.elfLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
      • 0x19540:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x19554:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x19568:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x1957c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x19590:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x195a4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x195b8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x195cc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x195e0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x195f4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x19608:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x1961c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x19630:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x19644:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x19658:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x1966c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x19680:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x19694:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x196a8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x196bc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x196d0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      unix.ppc.elfLinux_Trojan_Gafgyt_ea92cca8unknownunknown
      • 0x19400:$a: 53 65 6C 66 20 52 65 70 20 46 75 63 6B 69 6E 67 20 4E 65 54 69 53 20 61 6E 64
      SourceRuleDescriptionAuthorStrings
      6259.1.00007f8ae8001000.00007f8ae801e000.r-x.sdmpJoeSecurity_Mirai_3Yara detected MiraiJoe Security
        6259.1.00007f8ae8001000.00007f8ae801e000.r-x.sdmpJoeSecurity_Mirai_8Yara detected MiraiJoe Security
          6259.1.00007f8ae8001000.00007f8ae801e000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
          • 0x19540:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x19554:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x19568:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x1957c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x19590:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x195a4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x195b8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x195cc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x195e0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x195f4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x19608:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x1961c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x19630:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x19644:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x19658:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x1966c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x19680:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x19694:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x196a8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x196bc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x196d0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          6259.1.00007f8ae8001000.00007f8ae801e000.r-x.sdmpLinux_Trojan_Gafgyt_ea92cca8unknownunknown
          • 0x19400:$a: 53 65 6C 66 20 52 65 70 20 46 75 63 6B 69 6E 67 20 4E 65 54 69 53 20 61 6E 64
          Process Memory Space: unix.ppc.elf PID: 6259JoeSecurity_Mirai_3Yara detected MiraiJoe Security
            Click to see the 3 entries
            No Suricata rule has matched

            Click to jump to signature section

            Show All Signature Results

            AV Detection

            barindex
            Source: unix.ppc.elfAvira: detected
            Source: unix.ppc.elfVirustotal: Detection: 60%Perma Link
            Source: unix.ppc.elfReversingLabs: Detection: 60%

            Networking

            barindex
            Source: unknownDNS query: name: unixbot.ddns.net
            Source: global trafficTCP traffic: 192.168.2.23:47304 -> 123.253.61.116:3778
            Source: global trafficTCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
            Source: global trafficTCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
            Source: global trafficTCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
            Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
            Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
            Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
            Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
            Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
            Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
            Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
            Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
            Source: global trafficDNS traffic detected: DNS query: unixbot.ddns.net
            Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443

            System Summary

            barindex
            Source: unix.ppc.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
            Source: unix.ppc.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown
            Source: 6259.1.00007f8ae8001000.00007f8ae801e000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
            Source: 6259.1.00007f8ae8001000.00007f8ae801e000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown
            Source: Process Memory Space: unix.ppc.elf PID: 6259, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
            Source: Process Memory Space: unix.ppc.elf PID: 6259, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown
            Source: ELF static info symbol of initial sample.symtab present: no
            Source: unix.ppc.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
            Source: unix.ppc.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16
            Source: 6259.1.00007f8ae8001000.00007f8ae801e000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
            Source: 6259.1.00007f8ae8001000.00007f8ae801e000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16
            Source: Process Memory Space: unix.ppc.elf PID: 6259, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
            Source: Process Memory Space: unix.ppc.elf PID: 6259, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16
            Source: classification engineClassification label: mal88.troj.evad.linELF@0/0@6/0
            Source: /tmp/unix.ppc.elf (PID: 6261)Directory: /tmp/.Jump to behavior
            Source: /tmp/unix.ppc.elf (PID: 6261)Directory: /tmp/..Jump to behavior

            Hooking and other Techniques for Hiding and Protection

            barindex
            Source: /tmp/unix.ppc.elf (PID: 6259)File: /tmp/unix.ppc.elfJump to behavior
            Source: /tmp/unix.ppc.elf (PID: 6259)Queries kernel information via 'uname': Jump to behavior
            Source: unix.ppc.elf, 6259.1.000055f623953000.000055f623a03000.rw-.sdmpBinary or memory string: !/etc/qemu-binfmt/ppc11!hotpluggableq
            Source: unix.ppc.elf, 6259.1.000055f623953000.000055f623a03000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/ppc
            Source: unix.ppc.elf, 6259.1.00007fff38870000.00007fff38891000.rw-.sdmpBinary or memory string: /usr/bin/qemu-ppc
            Source: unix.ppc.elf, 6259.1.00007fff38870000.00007fff38891000.rw-.sdmpBinary or memory string: Bcx86_64/usr/bin/qemu-ppc/tmp/unix.ppc.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/unix.ppc.elf

            Stealing of Sensitive Information

            barindex
            Source: Yara matchFile source: unix.ppc.elf, type: SAMPLE
            Source: Yara matchFile source: 6259.1.00007f8ae8001000.00007f8ae801e000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: Process Memory Space: unix.ppc.elf PID: 6259, type: MEMORYSTR

            Remote Access Functionality

            barindex
            Source: Yara matchFile source: unix.ppc.elf, type: SAMPLE
            Source: Yara matchFile source: 6259.1.00007f8ae8001000.00007f8ae801e000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: Process Memory Space: unix.ppc.elf PID: 6259, type: MEMORYSTR
            ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
            Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception1
            Hidden Files and Directories
            OS Credential Dumping11
            Security Software Discovery
            Remote ServicesData from Local System1
            Encrypted Channel
            Exfiltration Over Other Network MediumAbuse Accessibility Features
            CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
            File Deletion
            LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
            Non-Standard Port
            Exfiltration Over BluetoothNetwork Denial of Service
            Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
            Non-Application Layer Protocol
            Automated ExfiltrationData Encrypted for Impact
            Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture12
            Application Layer Protocol
            Traffic DuplicationData Destruction
            No configs have been found
            Hide Legend

            Legend:

            • Process
            • Signature
            • Created File
            • DNS/IP Info
            • Is Dropped
            • Number of created Files
            • Is malicious
            • Internet
            SourceDetectionScannerLabelLink
            unix.ppc.elf60%VirustotalBrowse
            unix.ppc.elf61%ReversingLabsLinux.Trojan.Mirai
            unix.ppc.elf100%AviraEXP/ELF.Mirai.Z.A
            No Antivirus matches
            No Antivirus matches
            No Antivirus matches
            NameIPActiveMaliciousAntivirus DetectionReputation
            unixbot.ddns.net
            123.253.61.116
            truefalse
              high
              • No. of IPs < 25%
              • 25% < No. of IPs < 50%
              • 50% < No. of IPs < 75%
              • 75% < No. of IPs
              IPDomainCountryFlagASNASN NameMalicious
              109.202.202.202
              unknownSwitzerland
              13030INIT7CHfalse
              91.189.91.43
              unknownUnited Kingdom
              41231CANONICAL-ASGBfalse
              91.189.91.42
              unknownUnited Kingdom
              41231CANONICAL-ASGBfalse
              123.253.61.116
              unixbot.ddns.netThailand
              136523COLODEE-AS-APCOLODEEDIGITALNETWORKCOLTDTHfalse
              MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
              109.202.202.202kpLwzBouH4.elfGet hashmaliciousUnknownBrowse
              • ch.archive.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_92.0%2bbuild3-0ubuntu0.20.04.1_amd64.deb
              91.189.91.43momo.ppc.elfGet hashmaliciousMiraiBrowse
                momo.x86.elfGet hashmaliciousMiraiBrowse
                  unix.x86.elfGet hashmaliciousMiraiBrowse
                    main.sh4.elfGet hashmaliciousMiraiBrowse
                      fuckunix.arm7.elfGet hashmaliciousMiraiBrowse
                        Space.spc.elfGet hashmaliciousMiraiBrowse
                          main.mpsl.elfGet hashmaliciousMiraiBrowse
                            z0r0.arc.elfGet hashmaliciousMiraiBrowse
                              main.x86.elfGet hashmaliciousMiraiBrowse
                                fenty.arm4.elfGet hashmaliciousMiraiBrowse
                                  91.189.91.42momo.ppc.elfGet hashmaliciousMiraiBrowse
                                    momo.x86.elfGet hashmaliciousMiraiBrowse
                                      unix.x86.elfGet hashmaliciousMiraiBrowse
                                        unix.arm5.elfGet hashmaliciousMiraiBrowse
                                          main.sh4.elfGet hashmaliciousMiraiBrowse
                                            fuckunix.arm7.elfGet hashmaliciousMiraiBrowse
                                              Space.spc.elfGet hashmaliciousMiraiBrowse
                                                main.mpsl.elfGet hashmaliciousMiraiBrowse
                                                  z0r0.arc.elfGet hashmaliciousMiraiBrowse
                                                    main.x86.elfGet hashmaliciousMiraiBrowse
                                                      123.253.61.116unix.m68k.elfGet hashmaliciousMiraiBrowse
                                                        fuckunix.x86_64.elfGet hashmaliciousMiraiBrowse
                                                          unix.arm.elfGet hashmaliciousMiraiBrowse
                                                            unix.x86.elfGet hashmaliciousMiraiBrowse
                                                              unix.sh4.elfGet hashmaliciousMiraiBrowse
                                                                unix.arm5.elfGet hashmaliciousMiraiBrowse
                                                                  unix.mips.elfGet hashmaliciousMiraiBrowse
                                                                    unix.mpsl.elfGet hashmaliciousMiraiBrowse
                                                                      unix.x86_64.elfGet hashmaliciousMiraiBrowse
                                                                        main.arm7.elfGet hashmaliciousMiraiBrowse
                                                                          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                          unixbot.ddns.netunix.m68k.elfGet hashmaliciousMiraiBrowse
                                                                          • 123.253.61.116
                                                                          unix.arm.elfGet hashmaliciousMiraiBrowse
                                                                          • 123.253.61.116
                                                                          unix.x86.elfGet hashmaliciousMiraiBrowse
                                                                          • 123.253.61.116
                                                                          unix.sh4.elfGet hashmaliciousMiraiBrowse
                                                                          • 123.253.61.116
                                                                          unix.arm5.elfGet hashmaliciousMiraiBrowse
                                                                          • 123.253.61.116
                                                                          unix.mips.elfGet hashmaliciousMiraiBrowse
                                                                          • 123.253.61.116
                                                                          unix.mpsl.elfGet hashmaliciousMiraiBrowse
                                                                          • 123.253.61.116
                                                                          unix.x86_64.elfGet hashmaliciousMiraiBrowse
                                                                          • 123.253.61.116
                                                                          main.arm7.elfGet hashmaliciousMiraiBrowse
                                                                          • 123.253.61.116
                                                                          main.x86_64.elfGet hashmaliciousMiraiBrowse
                                                                          • 123.253.61.116
                                                                          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                          CANONICAL-ASGBmomo.spc.elfGet hashmaliciousMiraiBrowse
                                                                          • 185.125.190.26
                                                                          fuckunix.x86_64.elfGet hashmaliciousMiraiBrowse
                                                                          • 185.125.190.26
                                                                          momo.ppc.elfGet hashmaliciousMiraiBrowse
                                                                          • 91.189.91.42
                                                                          momo.sh4.elfGet hashmaliciousMiraiBrowse
                                                                          • 185.125.190.26
                                                                          momo.x86.elfGet hashmaliciousMiraiBrowse
                                                                          • 91.189.91.42
                                                                          unix.x86.elfGet hashmaliciousMiraiBrowse
                                                                          • 91.189.91.42
                                                                          unix.arm5.elfGet hashmaliciousMiraiBrowse
                                                                          • 91.189.91.42
                                                                          main.sh4.elfGet hashmaliciousMiraiBrowse
                                                                          • 91.189.91.42
                                                                          fuckunix.arm7.elfGet hashmaliciousMiraiBrowse
                                                                          • 91.189.91.42
                                                                          Space.spc.elfGet hashmaliciousMiraiBrowse
                                                                          • 91.189.91.42
                                                                          CANONICAL-ASGBmomo.spc.elfGet hashmaliciousMiraiBrowse
                                                                          • 185.125.190.26
                                                                          fuckunix.x86_64.elfGet hashmaliciousMiraiBrowse
                                                                          • 185.125.190.26
                                                                          momo.ppc.elfGet hashmaliciousMiraiBrowse
                                                                          • 91.189.91.42
                                                                          momo.sh4.elfGet hashmaliciousMiraiBrowse
                                                                          • 185.125.190.26
                                                                          momo.x86.elfGet hashmaliciousMiraiBrowse
                                                                          • 91.189.91.42
                                                                          unix.x86.elfGet hashmaliciousMiraiBrowse
                                                                          • 91.189.91.42
                                                                          unix.arm5.elfGet hashmaliciousMiraiBrowse
                                                                          • 91.189.91.42
                                                                          main.sh4.elfGet hashmaliciousMiraiBrowse
                                                                          • 91.189.91.42
                                                                          fuckunix.arm7.elfGet hashmaliciousMiraiBrowse
                                                                          • 91.189.91.42
                                                                          Space.spc.elfGet hashmaliciousMiraiBrowse
                                                                          • 91.189.91.42
                                                                          INIT7CHmomo.ppc.elfGet hashmaliciousMiraiBrowse
                                                                          • 109.202.202.202
                                                                          momo.x86.elfGet hashmaliciousMiraiBrowse
                                                                          • 109.202.202.202
                                                                          unix.x86.elfGet hashmaliciousMiraiBrowse
                                                                          • 109.202.202.202
                                                                          unix.arm5.elfGet hashmaliciousMiraiBrowse
                                                                          • 109.202.202.202
                                                                          main.sh4.elfGet hashmaliciousMiraiBrowse
                                                                          • 109.202.202.202
                                                                          fuckunix.arm7.elfGet hashmaliciousMiraiBrowse
                                                                          • 109.202.202.202
                                                                          Space.spc.elfGet hashmaliciousMiraiBrowse
                                                                          • 109.202.202.202
                                                                          main.mpsl.elfGet hashmaliciousMiraiBrowse
                                                                          • 109.202.202.202
                                                                          z0r0.arc.elfGet hashmaliciousMiraiBrowse
                                                                          • 109.202.202.202
                                                                          main.x86.elfGet hashmaliciousMiraiBrowse
                                                                          • 109.202.202.202
                                                                          COLODEE-AS-APCOLODEEDIGITALNETWORKCOLTDTHunix.m68k.elfGet hashmaliciousMiraiBrowse
                                                                          • 123.253.61.116
                                                                          fuckunix.x86_64.elfGet hashmaliciousMiraiBrowse
                                                                          • 123.253.61.116
                                                                          unix.arm.elfGet hashmaliciousMiraiBrowse
                                                                          • 123.253.61.116
                                                                          unix.x86.elfGet hashmaliciousMiraiBrowse
                                                                          • 123.253.61.116
                                                                          unix.sh4.elfGet hashmaliciousMiraiBrowse
                                                                          • 123.253.61.116
                                                                          unix.arm5.elfGet hashmaliciousMiraiBrowse
                                                                          • 123.253.61.116
                                                                          unix.mips.elfGet hashmaliciousMiraiBrowse
                                                                          • 123.253.61.116
                                                                          unix.mpsl.elfGet hashmaliciousMiraiBrowse
                                                                          • 123.253.61.116
                                                                          unix.x86_64.elfGet hashmaliciousMiraiBrowse
                                                                          • 123.253.61.116
                                                                          main.arm7.elfGet hashmaliciousMiraiBrowse
                                                                          • 123.253.61.116
                                                                          No context
                                                                          No context
                                                                          No created / dropped files found
                                                                          File type:ELF 32-bit MSB executable, PowerPC or cisco 4500, version 1 (SYSV), statically linked, stripped
                                                                          Entropy (8bit):5.6825380342719685
                                                                          TrID:
                                                                          • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                                                                          File name:unix.ppc.elf
                                                                          File size:135'988 bytes
                                                                          MD5:c5969e84a54f82ba88ec2a3e9e7a8d52
                                                                          SHA1:92af8b1462a0b58075319b43e622966a1570d7ee
                                                                          SHA256:473b1cdbb12e360f56397702cc9d3d6c1bb993b372f28dd34accbadaf6742eab
                                                                          SHA512:adb3269f4e2e1d5cf869783a0818ab2919f5d5462e83481f14817e7613c21863a656eb2b5f9ccf6f97b88c9f82464bb60fdef126f8196fd48b9f07cfda121e34
                                                                          SSDEEP:1536:cg47ftbBUO/kfFacSJ9/EhxFj30x32XvA8feoVGdTdiTWqzZojlYOpJLu+104wY:fY2s98hxC398fbU3H/AY
                                                                          TLSH:36D32905B30C0B47D1632EF03E3F57E097AF9AC121E8FA40655FAA8A9171D325589EDD
                                                                          File Content Preview:.ELF...........................4...T.....4. ...(......................................................N.............dt.Q.............................!..|......$H...H......$8!. |...N.. .!..|.......?.............../...@..\?......$.+../...A..$8...}).....$N..

                                                                          ELF header

                                                                          Class:ELF32
                                                                          Data:2's complement, big endian
                                                                          Version:1 (current)
                                                                          Machine:PowerPC
                                                                          Version Number:0x1
                                                                          Type:EXEC (Executable file)
                                                                          OS/ABI:UNIX - System V
                                                                          ABI Version:0
                                                                          Entry Point Address:0x100001f0
                                                                          Flags:0x0
                                                                          ELF Header Size:52
                                                                          Program Header Offset:52
                                                                          Program Header Size:32
                                                                          Number of Program Headers:3
                                                                          Section Header Offset:135508
                                                                          Section Header Size:40
                                                                          Number of Section Headers:12
                                                                          Header String Table Index:11
                                                                          NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                                                          NULL0x00x00x00x00x0000
                                                                          .initPROGBITS0x100000940x940x240x00x6AX004
                                                                          .textPROGBITS0x100000b80xb80x18c300x00x6AX004
                                                                          .finiPROGBITS0x10018ce80x18ce80x200x00x6AX004
                                                                          .rodataPROGBITS0x10018d080x18d080x35f00x00x2A008
                                                                          .ctorsPROGBITS0x1002c2fc0x1c2fc0xc0x00x3WA004
                                                                          .dtorsPROGBITS0x1002c3080x1c3080x80x00x3WA004
                                                                          .dataPROGBITS0x1002c3200x1c3200x4d600x00x3WA0032
                                                                          .sdataPROGBITS0x100310800x210800x880x00x3WA004
                                                                          .sbssNOBITS0x100311080x211080x1080x00x3WA004
                                                                          .bssNOBITS0x100312100x211080x55740x00x3WA008
                                                                          .shstrtabSTRTAB0x00x211080x4b0x00x0001
                                                                          TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                                          LOAD0x00x100000000x100000000x1c2f80x1c2f86.23870x5R E0x10000.init .text .fini .rodata
                                                                          LOAD0x1c2fc0x1002c2fc0x1002c2fc0x4e0c0xa4880.95110x6RW 0x10000.ctors .dtors .data .sdata .sbss .bss
                                                                          GNU_STACK0x00x00x00x00x00.00000x6RW 0x4
                                                                          TimestampSource PortDest PortSource IPDest IP
                                                                          Jan 5, 2025 15:33:06.608899117 CET43928443192.168.2.2391.189.91.42
                                                                          Jan 5, 2025 15:33:11.980151892 CET4251680192.168.2.23109.202.202.202
                                                                          Jan 5, 2025 15:33:11.980173111 CET42836443192.168.2.2391.189.91.43
                                                                          Jan 5, 2025 15:33:12.603725910 CET473043778192.168.2.23123.253.61.116
                                                                          Jan 5, 2025 15:33:12.608536959 CET377847304123.253.61.116192.168.2.23
                                                                          Jan 5, 2025 15:33:12.608753920 CET473043778192.168.2.23123.253.61.116
                                                                          Jan 5, 2025 15:33:12.609529018 CET473043778192.168.2.23123.253.61.116
                                                                          Jan 5, 2025 15:33:12.614291906 CET377847304123.253.61.116192.168.2.23
                                                                          Jan 5, 2025 15:33:12.614357948 CET473043778192.168.2.23123.253.61.116
                                                                          Jan 5, 2025 15:33:12.619175911 CET377847304123.253.61.116192.168.2.23
                                                                          Jan 5, 2025 15:33:22.618561029 CET473043778192.168.2.23123.253.61.116
                                                                          Jan 5, 2025 15:33:22.623485088 CET377847304123.253.61.116192.168.2.23
                                                                          Jan 5, 2025 15:33:27.594153881 CET43928443192.168.2.2391.189.91.42
                                                                          Jan 5, 2025 15:33:34.068977118 CET377847304123.253.61.116192.168.2.23
                                                                          Jan 5, 2025 15:33:34.069741011 CET473043778192.168.2.23123.253.61.116
                                                                          Jan 5, 2025 15:33:34.074640036 CET377847304123.253.61.116192.168.2.23
                                                                          Jan 5, 2025 15:33:35.080001116 CET473063778192.168.2.23123.253.61.116
                                                                          Jan 5, 2025 15:33:35.084764957 CET377847306123.253.61.116192.168.2.23
                                                                          Jan 5, 2025 15:33:35.084882975 CET473063778192.168.2.23123.253.61.116
                                                                          Jan 5, 2025 15:33:35.085830927 CET473063778192.168.2.23123.253.61.116
                                                                          Jan 5, 2025 15:33:35.090576887 CET377847306123.253.61.116192.168.2.23
                                                                          Jan 5, 2025 15:33:35.090643883 CET473063778192.168.2.23123.253.61.116
                                                                          Jan 5, 2025 15:33:35.095448971 CET377847306123.253.61.116192.168.2.23
                                                                          Jan 5, 2025 15:33:37.832856894 CET42836443192.168.2.2391.189.91.43
                                                                          Jan 5, 2025 15:33:41.928366899 CET4251680192.168.2.23109.202.202.202
                                                                          Jan 5, 2025 15:33:56.438429117 CET377847306123.253.61.116192.168.2.23
                                                                          Jan 5, 2025 15:33:56.438678026 CET473063778192.168.2.23123.253.61.116
                                                                          Jan 5, 2025 15:33:56.443443060 CET377847306123.253.61.116192.168.2.23
                                                                          Jan 5, 2025 15:33:57.481743097 CET473083778192.168.2.23123.253.61.116
                                                                          Jan 5, 2025 15:33:57.486594915 CET377847308123.253.61.116192.168.2.23
                                                                          Jan 5, 2025 15:33:57.486655951 CET473083778192.168.2.23123.253.61.116
                                                                          Jan 5, 2025 15:33:57.487673044 CET473083778192.168.2.23123.253.61.116
                                                                          Jan 5, 2025 15:33:57.492449999 CET377847308123.253.61.116192.168.2.23
                                                                          Jan 5, 2025 15:33:57.492523909 CET473083778192.168.2.23123.253.61.116
                                                                          Jan 5, 2025 15:33:57.497294903 CET377847308123.253.61.116192.168.2.23
                                                                          Jan 5, 2025 15:34:08.548649073 CET43928443192.168.2.2391.189.91.42
                                                                          Jan 5, 2025 15:34:18.865653038 CET377847308123.253.61.116192.168.2.23
                                                                          Jan 5, 2025 15:34:18.866103888 CET473083778192.168.2.23123.253.61.116
                                                                          Jan 5, 2025 15:34:18.870883942 CET377847308123.253.61.116192.168.2.23
                                                                          Jan 5, 2025 15:34:19.908343077 CET473103778192.168.2.23123.253.61.116
                                                                          Jan 5, 2025 15:34:19.913121939 CET377847310123.253.61.116192.168.2.23
                                                                          Jan 5, 2025 15:34:19.913183928 CET473103778192.168.2.23123.253.61.116
                                                                          Jan 5, 2025 15:34:19.914092064 CET473103778192.168.2.23123.253.61.116
                                                                          Jan 5, 2025 15:34:19.918915987 CET377847310123.253.61.116192.168.2.23
                                                                          Jan 5, 2025 15:34:19.919002056 CET473103778192.168.2.23123.253.61.116
                                                                          Jan 5, 2025 15:34:19.923743963 CET377847310123.253.61.116192.168.2.23
                                                                          Jan 5, 2025 15:34:29.025897980 CET42836443192.168.2.2391.189.91.43
                                                                          Jan 5, 2025 15:34:29.921804905 CET473103778192.168.2.23123.253.61.116
                                                                          Jan 5, 2025 15:34:29.926629066 CET377847310123.253.61.116192.168.2.23
                                                                          Jan 5, 2025 15:34:41.267631054 CET377847310123.253.61.116192.168.2.23
                                                                          Jan 5, 2025 15:34:41.267865896 CET473103778192.168.2.23123.253.61.116
                                                                          Jan 5, 2025 15:34:41.272651911 CET377847310123.253.61.116192.168.2.23
                                                                          Jan 5, 2025 15:34:42.277344942 CET473123778192.168.2.23123.253.61.116
                                                                          Jan 5, 2025 15:34:42.282144070 CET377847312123.253.61.116192.168.2.23
                                                                          Jan 5, 2025 15:34:42.282223940 CET473123778192.168.2.23123.253.61.116
                                                                          Jan 5, 2025 15:34:42.283180952 CET473123778192.168.2.23123.253.61.116
                                                                          Jan 5, 2025 15:34:42.288000107 CET377847312123.253.61.116192.168.2.23
                                                                          Jan 5, 2025 15:34:42.288059950 CET473123778192.168.2.23123.253.61.116
                                                                          Jan 5, 2025 15:34:42.292901993 CET377847312123.253.61.116192.168.2.23
                                                                          Jan 5, 2025 15:35:03.658786058 CET377847312123.253.61.116192.168.2.23
                                                                          Jan 5, 2025 15:35:03.659137011 CET473123778192.168.2.23123.253.61.116
                                                                          Jan 5, 2025 15:35:03.663933039 CET377847312123.253.61.116192.168.2.23
                                                                          Jan 5, 2025 15:35:04.700840950 CET473143778192.168.2.23123.253.61.116
                                                                          Jan 5, 2025 15:35:04.705636978 CET377847314123.253.61.116192.168.2.23
                                                                          Jan 5, 2025 15:35:04.705686092 CET473143778192.168.2.23123.253.61.116
                                                                          Jan 5, 2025 15:35:04.706736088 CET473143778192.168.2.23123.253.61.116
                                                                          Jan 5, 2025 15:35:04.711489916 CET377847314123.253.61.116192.168.2.23
                                                                          Jan 5, 2025 15:35:04.711530924 CET473143778192.168.2.23123.253.61.116
                                                                          Jan 5, 2025 15:35:04.716315031 CET377847314123.253.61.116192.168.2.23
                                                                          TimestampSource PortDest PortSource IPDest IP
                                                                          Jan 5, 2025 15:33:12.562613010 CET5529253192.168.2.238.8.8.8
                                                                          Jan 5, 2025 15:33:12.602941990 CET53552928.8.8.8192.168.2.23
                                                                          Jan 5, 2025 15:33:35.072734118 CET4195353192.168.2.238.8.8.8
                                                                          Jan 5, 2025 15:33:35.079397917 CET53419538.8.8.8192.168.2.23
                                                                          Jan 5, 2025 15:33:57.440963984 CET5246153192.168.2.238.8.8.8
                                                                          Jan 5, 2025 15:33:57.480978012 CET53524618.8.8.8192.168.2.23
                                                                          Jan 5, 2025 15:34:19.867988110 CET5340853192.168.2.238.8.8.8
                                                                          Jan 5, 2025 15:34:19.907536983 CET53534088.8.8.8192.168.2.23
                                                                          Jan 5, 2025 15:34:42.270277977 CET3990353192.168.2.238.8.8.8
                                                                          Jan 5, 2025 15:34:42.276928902 CET53399038.8.8.8192.168.2.23
                                                                          Jan 5, 2025 15:35:04.661709070 CET4195053192.168.2.238.8.8.8
                                                                          Jan 5, 2025 15:35:04.699924946 CET53419508.8.8.8192.168.2.23
                                                                          TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                                                          Jan 5, 2025 15:33:12.562613010 CET192.168.2.238.8.8.80x0Standard query (0)unixbot.ddns.netA (IP address)IN (0x0001)false
                                                                          Jan 5, 2025 15:33:35.072734118 CET192.168.2.238.8.8.80x0Standard query (0)unixbot.ddns.netA (IP address)IN (0x0001)false
                                                                          Jan 5, 2025 15:33:57.440963984 CET192.168.2.238.8.8.80x0Standard query (0)unixbot.ddns.netA (IP address)IN (0x0001)false
                                                                          Jan 5, 2025 15:34:19.867988110 CET192.168.2.238.8.8.80x0Standard query (0)unixbot.ddns.netA (IP address)IN (0x0001)false
                                                                          Jan 5, 2025 15:34:42.270277977 CET192.168.2.238.8.8.80x0Standard query (0)unixbot.ddns.netA (IP address)IN (0x0001)false
                                                                          Jan 5, 2025 15:35:04.661709070 CET192.168.2.238.8.8.80x0Standard query (0)unixbot.ddns.netA (IP address)IN (0x0001)false
                                                                          TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                                                          Jan 5, 2025 15:33:12.602941990 CET8.8.8.8192.168.2.230x0No error (0)unixbot.ddns.net123.253.61.116A (IP address)IN (0x0001)false
                                                                          Jan 5, 2025 15:33:35.079397917 CET8.8.8.8192.168.2.230x0No error (0)unixbot.ddns.net123.253.61.116A (IP address)IN (0x0001)false
                                                                          Jan 5, 2025 15:33:57.480978012 CET8.8.8.8192.168.2.230x0No error (0)unixbot.ddns.net123.253.61.116A (IP address)IN (0x0001)false
                                                                          Jan 5, 2025 15:34:19.907536983 CET8.8.8.8192.168.2.230x0No error (0)unixbot.ddns.net123.253.61.116A (IP address)IN (0x0001)false
                                                                          Jan 5, 2025 15:34:42.276928902 CET8.8.8.8192.168.2.230x0No error (0)unixbot.ddns.net123.253.61.116A (IP address)IN (0x0001)false
                                                                          Jan 5, 2025 15:35:04.699924946 CET8.8.8.8192.168.2.230x0No error (0)unixbot.ddns.net123.253.61.116A (IP address)IN (0x0001)false

                                                                          System Behavior

                                                                          Start time (UTC):14:33:03
                                                                          Start date (UTC):05/01/2025
                                                                          Path:/tmp/unix.ppc.elf
                                                                          Arguments:/tmp/unix.ppc.elf
                                                                          File size:5388968 bytes
                                                                          MD5 hash:ae65271c943d3451b7f026d1fadccea6

                                                                          Start time (UTC):14:33:03
                                                                          Start date (UTC):05/01/2025
                                                                          Path:/tmp/unix.ppc.elf
                                                                          Arguments:-
                                                                          File size:5388968 bytes
                                                                          MD5 hash:ae65271c943d3451b7f026d1fadccea6