Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
mips64.elf

Overview

General Information

Sample name:mips64.elf
Analysis ID:1585969
MD5:82074fe106c6454ab6c5d46ac8ad7d60
SHA1:8028c7806560ca1cf59e5e4282a09422c9b5b649
SHA256:c85289518b537d9faebc819e928bd1b163b4f202cc29de7a680a8cfda1697c01
Tags:elfuser-abuse_ch
Infos:

Detection

Score:48
Range:0 - 100
Whitelisted:false

Signatures

Multi AV Scanner detection for submitted file
Executes the "rm" command used to delete files or directories
Sample has stripped symbol table
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1585969
Start date and time:2025-01-08 15:41:00 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 5m 1s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:mips64.elf
Detection:MAL
Classification:mal48.linELF@0/0@0/0
Command:/tmp/mips64.elf
PID:6252
Exit Code:2
Exit Code Info:
Killed:False
Standard Output:

Standard Error:fatal error: sigaction failed

runtime stack:
runtime.throw({0x379d40, 0x10})
C:/Program Files/Go/src/runtime/panic.go:1077 +0x58 fp=0x4000800b60 sp=0x4000800b38 pc=0x5a240
runtime.sysSigaction.func1()
C:/Program Files/Go/src/runtime/os_linux.go:560 +0x50 fp=0x4000800b78 sp=0x4000800b60 pc=0x96788
runtime.sysSigaction(0x41, 0x4000800bc8, 0x0)
C:/Program Files/Go/src/runtime/os_linux.go:559 +0x8c fp=0x4000800ba8 sp=0x4000800b78 pc=0x567f4
runtime.sigaction(...)
C:/Program Files/Go/src/runtime/sigaction.go:15
runtime.setsig(0x41, 0x799c8)
C:/Program Files/Go/src/runtime/os_linux.go:507 +0xb8 fp=0x4000800bf0 sp=0x4000800ba8 pc=0x566b0
runtime.initsig(0x0)
C:/Program Files/Go/src/runtime/signal_unix.go:148 +0x344 fp=0x4000800c60 sp=0x4000800bf0 pc=0x78f44
runtime.mstartm0()
C:/Program Files/Go/src/runtime/proc.go:1624 +0x7c fp=0x4000800c70 sp=0x4000800c60 pc=0x61f74
runtime.mstart1()
C:/Program Files/Go/src/runtime/proc.go:1596 +0x98 fp=0x4000800c90 sp=0x4000800c70 pc=0x61e50
runtime.mstart0()
C:/Program Files/Go/src/runtime/proc.go:1557 +0x7c fp=0x4000800cb8 sp=0x4000800c90 pc=0x61d94
runtime.mstart()
C:/Program Files/Go/src/runtime/asm_mips64x.s:88 +0x14 fp=0x4000800cc0 sp=0x4000800cb8 pc=0x9da44

goroutine 1 [runnable]:
runtime.main()
C:/Program Files/Go/src/runtime/proc.go:144 fp=0xc00002c7d8 sp=0xc00002c7d8 pc=0x5db30
runtime.goexit()
C:/Program Files/Go/src/runtime/asm_mips64x.s:648 +0x4 fp=0xc00002c7d8 sp=0xc00002c7d8 pc=0x9ff14
  • system is lnxubuntu20
  • mips64.elf (PID: 6252, Parent: 6177, MD5: 801a06b4e0ed2dca89cbfa1f900a483d) Arguments: /tmp/mips64.elf
  • dash New Fork (PID: 6254, Parent: 4331)
  • rm (PID: 6254, Parent: 4331, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.5Vx6NvMNxO /tmp/tmp.2OwtgP9FvV /tmp/tmp.zof4bB4zyV
  • dash New Fork (PID: 6255, Parent: 4331)
  • rm (PID: 6255, Parent: 4331, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.5Vx6NvMNxO /tmp/tmp.2OwtgP9FvV /tmp/tmp.zof4bB4zyV
  • cleanup
No yara matches
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: mips64.elfReversingLabs: Detection: 23%
Source: unknownTCP traffic detected without corresponding DNS query: 54.171.230.55
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: mips64.elfString found in binary or memory: http://.css
Source: mips64.elfString found in binary or memory: http://.jpg
Source: mips64.elfString found in binary or memory: http://html4/loose.dtd
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 33606
Source: unknownNetwork traffic detected: HTTP traffic on port 33606 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443
Source: ELF static info symbol of initial sample.symtab present: no
Source: classification engineClassification label: mal48.linELF@0/0@0/0
Source: ELF file sectionSubmission: mips64.elf
Source: /usr/bin/dash (PID: 6254)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.5Vx6NvMNxO /tmp/tmp.2OwtgP9FvV /tmp/tmp.zof4bB4zyVJump to behavior
Source: /usr/bin/dash (PID: 6255)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.5Vx6NvMNxO /tmp/tmp.2OwtgP9FvV /tmp/tmp.zof4bB4zyVJump to behavior
Source: /tmp/mips64.elf (PID: 6252)Queries kernel information via 'uname': Jump to behavior
Source: mips64.elf, 6252.1.00007ffe0c7ec000.00007ffe0c80d000.rw-.sdmpBinary or memory string: /usr/bin/qemu-mips64
Source: mips64.elf, 6252.1.0000563482970000.0000563482f13000.rw-.sdmpBinary or memory string: 4V!/etc/qemu-binfmt/mips641RelativeDistinguishedName
Source: mips64.elf, 6252.1.00007ffe0c7ec000.00007ffe0c80d000.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-mips64/tmp/mips64.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/mips64.elf
Source: mips64.elf, 6252.1.0000563482970000.0000563482f13000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/mips64
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception1
File Deletion
OS Credential Dumping11
Security Software Discovery
Remote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1585969 Sample: mips64.elf Startdate: 08/01/2025 Architecture: LINUX Score: 48 12 109.202.202.202, 80 INIT7CH Switzerland 2->12 14 91.189.91.42, 443 CANONICAL-ASGB United Kingdom 2->14 16 2 other IPs or domains 2->16 18 Multi AV Scanner detection for submitted file 2->18 6 dash rm 2->6         started        8 dash rm 2->8         started        10 mips64.elf 2->10         started        signatures3 process4
SourceDetectionScannerLabelLink
mips64.elf24%ReversingLabsLinux.Trojan.Kaiji
No Antivirus matches
No Antivirus matches
No Antivirus matches
No contacted domains info
NameSourceMaliciousAntivirus DetectionReputation
http://html4/loose.dtdmips64.elffalse
    high
    http://.cssmips64.elffalse
      high
      http://.jpgmips64.elffalse
        high
        • No. of IPs < 25%
        • 25% < No. of IPs < 50%
        • 50% < No. of IPs < 75%
        • 75% < No. of IPs
        IPDomainCountryFlagASNASN NameMalicious
        54.171.230.55
        unknownUnited States
        16509AMAZON-02USfalse
        109.202.202.202
        unknownSwitzerland
        13030INIT7CHfalse
        91.189.91.43
        unknownUnited Kingdom
        41231CANONICAL-ASGBfalse
        91.189.91.42
        unknownUnited Kingdom
        41231CANONICAL-ASGBfalse
        MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
        54.171.230.55la.bot.arc.elfGet hashmaliciousMiraiBrowse
          main_m68k.elfGet hashmaliciousMiraiBrowse
            sh4.elfGet hashmaliciousMiraiBrowse
              sparc.elfGet hashmaliciousUnknownBrowse
                i686.elfGet hashmaliciousUnknownBrowse
                  wind.arm6.elfGet hashmaliciousMiraiBrowse
                    wind.x86.elfGet hashmaliciousMiraiBrowse
                      la.bot.sparc.elfGet hashmaliciousMiraiBrowse
                        arm.elfGet hashmaliciousMiraiBrowse
                          nshkarm.elfGet hashmaliciousUnknownBrowse
                            109.202.202.202kpLwzBouH4.elfGet hashmaliciousUnknownBrowse
                            • ch.archive.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_92.0%2bbuild3-0ubuntu0.20.04.1_amd64.deb
                            91.189.91.43mips64el.elfGet hashmaliciousUnknownBrowse
                              main_arm.elfGet hashmaliciousMiraiBrowse
                                mips.elfGet hashmaliciousMiraiBrowse
                                  main_sh4.elfGet hashmaliciousMiraiBrowse
                                    mips.elfGet hashmaliciousMiraiBrowse
                                      ntpd.elfGet hashmaliciousUnknownBrowse
                                        tftp.elfGet hashmaliciousUnknownBrowse
                                          la.bot.mipsel.elfGet hashmaliciousMiraiBrowse
                                            la.bot.arc.elfGet hashmaliciousMiraiBrowse
                                              la.bot.m68k.elfGet hashmaliciousMiraiBrowse
                                                91.189.91.42mips64el.elfGet hashmaliciousUnknownBrowse
                                                  main_arm.elfGet hashmaliciousMiraiBrowse
                                                    mips.elfGet hashmaliciousMiraiBrowse
                                                      main_sh4.elfGet hashmaliciousMiraiBrowse
                                                        mips.elfGet hashmaliciousMiraiBrowse
                                                          ntpd.elfGet hashmaliciousUnknownBrowse
                                                            tftp.elfGet hashmaliciousUnknownBrowse
                                                              la.bot.mipsel.elfGet hashmaliciousMiraiBrowse
                                                                la.bot.arc.elfGet hashmaliciousMiraiBrowse
                                                                  la.bot.arm7.elfGet hashmaliciousMiraiBrowse
                                                                    No context
                                                                    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                    CANONICAL-ASGB386.elfGet hashmaliciousUnknownBrowse
                                                                    • 185.125.190.26
                                                                    mips64el.elfGet hashmaliciousUnknownBrowse
                                                                    • 91.189.91.42
                                                                    main_arm5.elfGet hashmaliciousMiraiBrowse
                                                                    • 185.125.190.26
                                                                    main_arm.elfGet hashmaliciousMiraiBrowse
                                                                    • 91.189.91.42
                                                                    mips.elfGet hashmaliciousMiraiBrowse
                                                                    • 91.189.91.42
                                                                    main_sh4.elfGet hashmaliciousMiraiBrowse
                                                                    • 91.189.91.42
                                                                    mips.elfGet hashmaliciousMiraiBrowse
                                                                    • 91.189.91.42
                                                                    ntpd.elfGet hashmaliciousUnknownBrowse
                                                                    • 91.189.91.42
                                                                    tftp.elfGet hashmaliciousUnknownBrowse
                                                                    • 91.189.91.42
                                                                    la.bot.mipsel.elfGet hashmaliciousMiraiBrowse
                                                                    • 91.189.91.42
                                                                    AMAZON-02USORDER REF 47896798 PSMCO.exeGet hashmaliciousFormBook, PureLog StealerBrowse
                                                                    • 13.248.169.48
                                                                    https://connect.intuit.com/portal/app/CommerceNetwork/view/scs-v1-01f29c80fd42416b93c1e1b116eb15aeb0bd36fe1ddc4e298589676767f7a30254c18947c53d4f9a9d199271c071ab8c?locale=EN_USGet hashmaliciousUnknownBrowse
                                                                    • 44.229.88.240
                                                                    malw.htaGet hashmaliciousBranchlock ObfuscatorBrowse
                                                                    • 52.216.45.10
                                                                    atomxml.ps1Get hashmaliciousPureLog Stealer, RHADAMANTHYS, zgRATBrowse
                                                                    • 185.166.143.48
                                                                    06012025_1416_bombastic.htaGet hashmaliciousBranchlock ObfuscatorBrowse
                                                                    • 52.216.220.130
                                                                    malw.htaGet hashmaliciousUnknownBrowse
                                                                    • 54.231.132.66
                                                                    http://www.hillviewlodge.hotelrent.topGet hashmaliciousUnknownBrowse
                                                                    • 18.245.31.129
                                                                    https://www.dollartip.info/unsubscribe/?d=mdlandrec.netGet hashmaliciousUnknownBrowse
                                                                    • 52.222.232.30
                                                                    https://wetransfert-devis-factgfd.mystrikingly.com/Get hashmaliciousUnknownBrowse
                                                                    • 18.245.60.5
                                                                    mail (4).emlGet hashmaliciousUnknownBrowse
                                                                    • 52.29.116.175
                                                                    INIT7CHmips64el.elfGet hashmaliciousUnknownBrowse
                                                                    • 109.202.202.202
                                                                    main_arm.elfGet hashmaliciousMiraiBrowse
                                                                    • 109.202.202.202
                                                                    mips.elfGet hashmaliciousMiraiBrowse
                                                                    • 109.202.202.202
                                                                    main_sh4.elfGet hashmaliciousMiraiBrowse
                                                                    • 109.202.202.202
                                                                    mips.elfGet hashmaliciousMiraiBrowse
                                                                    • 109.202.202.202
                                                                    ntpd.elfGet hashmaliciousUnknownBrowse
                                                                    • 109.202.202.202
                                                                    tftp.elfGet hashmaliciousUnknownBrowse
                                                                    • 109.202.202.202
                                                                    la.bot.mipsel.elfGet hashmaliciousMiraiBrowse
                                                                    • 109.202.202.202
                                                                    la.bot.arc.elfGet hashmaliciousMiraiBrowse
                                                                    • 109.202.202.202
                                                                    la.bot.arm7.elfGet hashmaliciousMiraiBrowse
                                                                    • 109.202.202.202
                                                                    No context
                                                                    No context
                                                                    No created / dropped files found
                                                                    File type:ELF 64-bit MSB executable, MIPS, MIPS-III version 1 (SYSV), statically linked, Go BuildID=p4EjpCqN-ta2Kpyol3Ti/omRcKRIuI-P5jzcWA8xV/IlrSs1HO2qvoF90sPSeM/oQuHp0mqJY4Nw_AdXpyH, stripped
                                                                    Entropy (8bit):5.411098205902281
                                                                    TrID:
                                                                    • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                                                                    File name:mips64.elf
                                                                    File size:5'832'704 bytes
                                                                    MD5:82074fe106c6454ab6c5d46ac8ad7d60
                                                                    SHA1:8028c7806560ca1cf59e5e4282a09422c9b5b649
                                                                    SHA256:c85289518b537d9faebc819e928bd1b163b4f202cc29de7a680a8cfda1697c01
                                                                    SHA512:cc27ebc2882d33d781abdd457d409417ae6c4aecf34d2fa3f08259d54f0d757e22b5db8184387e9df228f284f3def211c0924ea9bbdae89ba44c3f4fa8315561
                                                                    SSDEEP:49152:Pfk83HR7cfBf/xpkV3+xqaSmXqzrm36ivHH:PfkzE9Vzrm36ivn
                                                                    TLSH:204619527F94EE1BE29421358AF6C23433D53E0582E421339612F71D2EBB2B49D5BED8
                                                                    File Content Preview:.ELF...........................`.......@........ ....@.8...@...................@.......@.......@.......P.......P...............................................d.......d...............................................4.......4...................../.......0.

                                                                    ELF header

                                                                    Class:ELF64
                                                                    Data:2's complement, big endian
                                                                    Version:1 (current)
                                                                    Machine:MIPS R3000
                                                                    Version Number:0x1
                                                                    Type:EXEC (Executable file)
                                                                    OS/ABI:UNIX - System V
                                                                    ABI Version:0
                                                                    Entry Point Address:0xa1060
                                                                    Flags:0x20000004
                                                                    ELF Header Size:64
                                                                    Program Header Offset:64
                                                                    Program Header Size:56
                                                                    Number of Program Headers:6
                                                                    Section Header Offset:400
                                                                    Section Header Size:64
                                                                    Number of Section Headers:14
                                                                    Header String Table Index:3
                                                                    NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                                                    NULL0x00x00x00x00x0000
                                                                    .textPROGBITS0x110000x10000x2eaf340x00x6AX008
                                                                    .rodataPROGBITS0x3000000x2f00000xeb17c0x00x2A0032
                                                                    .shstrtabSTRTAB0x00x3db1800x980x00x0001
                                                                    .typelinkPROGBITS0x3eb2200x3db2200x17040x00x2A0032
                                                                    .itablinkPROGBITS0x3ec9400x3dc9400x9180x00x2A0032
                                                                    .gosymtabPROGBITS0x3ed2580x3dd2580x00x00x2A001
                                                                    .gopclntabPROGBITS0x3ed2600x3dd2600x1489500x00x2A0032
                                                                    .go.buildinfoPROGBITS0x5400000x5300000x1500x00x3WA0016
                                                                    .noptrdataPROGBITS0x5401600x5301600x476000x00x3WA0032
                                                                    .dataPROGBITS0x5877600x5777600xd3a00x00x3WA0032
                                                                    .bssNOBITS0x594b000x584b000x2e3d80x00x3WA0032
                                                                    .noptrbssNOBITS0x5c2ee00x5b2ee00x6ab00x00x3WA0032
                                                                    .note.go.buildidNOTE0x10f9c0xf9c0x640x00x2A004
                                                                    TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                                    PHDR0x400x100400x100400x1500x1501.52850x4R 0x10000
                                                                    NOTE0xf9c0x10f9c0x10f9c0x640x645.40370x4R 0x4.note.go.buildid
                                                                    LOAD0x00x100000x100000x2ebf340x2ebf345.11670x5R E0x10000.text .note.go.buildid
                                                                    LOAD0x2f00000x3000000x3000000x235bb00x235bb05.36940x4R 0x10000.rodata .typelink .itablink .gosymtab .gopclntab
                                                                    LOAD0x5300000x5400000x5400000x54b000x899905.98140x6RW 0x10000.go.buildinfo .noptrdata .data .bss .noptrbss
                                                                    GNU_STACK0x00x00x00x00x00.00000x6RW 0x8
                                                                    TimestampSource PortDest PortSource IPDest IP
                                                                    Jan 8, 2025 15:42:02.334769011 CET4433360654.171.230.55192.168.2.23
                                                                    Jan 8, 2025 15:42:02.334971905 CET33606443192.168.2.2354.171.230.55
                                                                    Jan 8, 2025 15:42:02.339766979 CET4433360654.171.230.55192.168.2.23
                                                                    Jan 8, 2025 15:42:03.205034971 CET4251680192.168.2.23109.202.202.202
                                                                    Jan 8, 2025 15:42:04.228873968 CET43928443192.168.2.2391.189.91.42
                                                                    Jan 8, 2025 15:42:09.860120058 CET42836443192.168.2.2391.189.91.43
                                                                    Jan 8, 2025 15:42:24.961899996 CET43928443192.168.2.2391.189.91.42
                                                                    Jan 8, 2025 15:42:33.152764082 CET4251680192.168.2.23109.202.202.202
                                                                    Jan 8, 2025 15:42:37.248192072 CET42836443192.168.2.2391.189.91.43
                                                                    Jan 8, 2025 15:43:05.916174889 CET43928443192.168.2.2391.189.91.42

                                                                    System Behavior

                                                                    Start time (UTC):14:42:00
                                                                    Start date (UTC):08/01/2025
                                                                    Path:/tmp/mips64.elf
                                                                    Arguments:/tmp/mips64.elf
                                                                    File size:5830456 bytes
                                                                    MD5 hash:801a06b4e0ed2dca89cbfa1f900a483d

                                                                    Start time (UTC):14:42:01
                                                                    Start date (UTC):08/01/2025
                                                                    Path:/usr/bin/dash
                                                                    Arguments:-
                                                                    File size:129816 bytes
                                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                    Start time (UTC):14:42:01
                                                                    Start date (UTC):08/01/2025
                                                                    Path:/usr/bin/rm
                                                                    Arguments:rm -f /tmp/tmp.5Vx6NvMNxO /tmp/tmp.2OwtgP9FvV /tmp/tmp.zof4bB4zyV
                                                                    File size:72056 bytes
                                                                    MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b

                                                                    Start time (UTC):14:42:01
                                                                    Start date (UTC):08/01/2025
                                                                    Path:/usr/bin/dash
                                                                    Arguments:-
                                                                    File size:129816 bytes
                                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                    Start time (UTC):14:42:01
                                                                    Start date (UTC):08/01/2025
                                                                    Path:/usr/bin/rm
                                                                    Arguments:rm -f /tmp/tmp.5Vx6NvMNxO /tmp/tmp.2OwtgP9FvV /tmp/tmp.zof4bB4zyV
                                                                    File size:72056 bytes
                                                                    MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b