Click to jump to signature section
Source: Fantazy.i486.elf | ReversingLabs: Detection: 39% |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: global traffic | DNS traffic detected: DNS query: daisy.ubuntu.com |
Source: Fantazy.i486.elf, type: SAMPLE | Matched rule: Linux_Trojan_Mirai_122ff2e6 Author: unknown |
Source: Fantazy.i486.elf, type: SAMPLE | Matched rule: Linux_Trojan_Mirai_aa39fb02 Author: unknown |
Source: Fantazy.i486.elf, type: SAMPLE | Matched rule: Linux_Trojan_Mirai_575f5bc8 Author: unknown |
Source: Fantazy.i486.elf, type: SAMPLE | Matched rule: Linux_Trojan_Mirai_6e8e9257 Author: unknown |
Source: 5490.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Mirai_122ff2e6 Author: unknown |
Source: 5490.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Mirai_aa39fb02 Author: unknown |
Source: 5490.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Mirai_575f5bc8 Author: unknown |
Source: 5490.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Mirai_6e8e9257 Author: unknown |
Source: ELF static info symbol of initial sample | .symtab present: no |
Source: Fantazy.i486.elf, type: SAMPLE | Matched rule: Linux_Trojan_Mirai_122ff2e6 reference_sample = c7dd999a033fa3edc1936785b87cd69ce2f5cac5a084ddfaf527a1094e718bc4, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 3c9ffd7537e30a21eefa6c174f801264b92a85a1bc73e34e6dc9e29f84658348, id = 122ff2e6-56e6-4aa8-a3ec-c19d31eb1f80, last_modified = 2021-09-16 |
Source: Fantazy.i486.elf, type: SAMPLE | Matched rule: Linux_Trojan_Mirai_aa39fb02 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = b136ba6496816ba9737a3eb0e633c28a337511a97505f06e52f37b38599587cb, id = aa39fb02-ca7e-4809-ab5d-00e92763f7ec, last_modified = 2021-09-16 |
Source: Fantazy.i486.elf, type: SAMPLE | Matched rule: Linux_Trojan_Mirai_575f5bc8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 58e22a2acd002b07e1b1c546e8dfe9885d5dfd2092d4044630064078038e314f, id = 575f5bc8-b848-4db4-a99c-132d4d2bc8a4, last_modified = 2021-09-16 |
Source: Fantazy.i486.elf, type: SAMPLE | Matched rule: Linux_Trojan_Mirai_6e8e9257 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 4bad14aebb0b8c7aa414f38866baaf1f4b350b2026735de24bcf2014ff4b0a6a, id = 6e8e9257-a6d5-407a-a584-4656816a3ddc, last_modified = 2021-09-16 |
Source: 5490.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Mirai_122ff2e6 reference_sample = c7dd999a033fa3edc1936785b87cd69ce2f5cac5a084ddfaf527a1094e718bc4, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 3c9ffd7537e30a21eefa6c174f801264b92a85a1bc73e34e6dc9e29f84658348, id = 122ff2e6-56e6-4aa8-a3ec-c19d31eb1f80, last_modified = 2021-09-16 |
Source: 5490.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Mirai_aa39fb02 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = b136ba6496816ba9737a3eb0e633c28a337511a97505f06e52f37b38599587cb, id = aa39fb02-ca7e-4809-ab5d-00e92763f7ec, last_modified = 2021-09-16 |
Source: 5490.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Mirai_575f5bc8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 58e22a2acd002b07e1b1c546e8dfe9885d5dfd2092d4044630064078038e314f, id = 575f5bc8-b848-4db4-a99c-132d4d2bc8a4, last_modified = 2021-09-16 |
Source: 5490.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Mirai_6e8e9257 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 4bad14aebb0b8c7aa414f38866baaf1f4b350b2026735de24bcf2014ff4b0a6a, id = 6e8e9257-a6d5-407a-a584-4656816a3ddc, last_modified = 2021-09-16 |
Source: classification engine | Classification label: mal68.linELF@0/0@2/0 |