Click to jump to signature section
Source: SPARC.elf | Virustotal: Detection: 30% | Perma Link |
Source: SPARC.elf | ReversingLabs: Detection: 34% |
Source: /tmp/SPARC.elf (PID: 6254) | Opens: /proc/net/route | Jump to behavior |
Source: global traffic | TCP traffic: 192.168.2.23:40706 -> 216.9.227.143:9198 |
Source: global traffic | TCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443 |
Source: global traffic | TCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443 |
Source: global traffic | TCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80 |
Source: unknown | TCP traffic detected without corresponding DNS query: 91.189.91.42 |
Source: unknown | TCP traffic detected without corresponding DNS query: 216.9.227.143 |
Source: unknown | TCP traffic detected without corresponding DNS query: 216.9.227.143 |
Source: unknown | TCP traffic detected without corresponding DNS query: 216.9.227.143 |
Source: unknown | TCP traffic detected without corresponding DNS query: 216.9.227.143 |
Source: unknown | TCP traffic detected without corresponding DNS query: 216.9.227.143 |
Source: unknown | TCP traffic detected without corresponding DNS query: 216.9.227.143 |
Source: unknown | TCP traffic detected without corresponding DNS query: 216.9.227.143 |
Source: unknown | TCP traffic detected without corresponding DNS query: 216.9.227.143 |
Source: unknown | TCP traffic detected without corresponding DNS query: 216.9.227.143 |
Source: unknown | TCP traffic detected without corresponding DNS query: 216.9.227.143 |
Source: unknown | TCP traffic detected without corresponding DNS query: 216.9.227.143 |
Source: unknown | TCP traffic detected without corresponding DNS query: 216.9.227.143 |
Source: unknown | TCP traffic detected without corresponding DNS query: 216.9.227.143 |
Source: unknown | TCP traffic detected without corresponding DNS query: 216.9.227.143 |
Source: unknown | TCP traffic detected without corresponding DNS query: 216.9.227.143 |
Source: unknown | TCP traffic detected without corresponding DNS query: 91.189.91.43 |
Source: unknown | TCP traffic detected without corresponding DNS query: 109.202.202.202 |
Source: unknown | TCP traffic detected without corresponding DNS query: 216.9.227.143 |
Source: unknown | TCP traffic detected without corresponding DNS query: 216.9.227.143 |
Source: unknown | TCP traffic detected without corresponding DNS query: 216.9.227.143 |
Source: unknown | TCP traffic detected without corresponding DNS query: 216.9.227.143 |
Source: unknown | TCP traffic detected without corresponding DNS query: 216.9.227.143 |
Source: unknown | TCP traffic detected without corresponding DNS query: 216.9.227.143 |
Source: unknown | TCP traffic detected without corresponding DNS query: 216.9.227.143 |
Source: unknown | TCP traffic detected without corresponding DNS query: 216.9.227.143 |
Source: unknown | TCP traffic detected without corresponding DNS query: 216.9.227.143 |
Source: unknown | TCP traffic detected without corresponding DNS query: 216.9.227.143 |
Source: unknown | TCP traffic detected without corresponding DNS query: 216.9.227.143 |
Source: unknown | TCP traffic detected without corresponding DNS query: 216.9.227.143 |
Source: unknown | TCP traffic detected without corresponding DNS query: 216.9.227.143 |
Source: unknown | TCP traffic detected without corresponding DNS query: 216.9.227.143 |
Source: unknown | TCP traffic detected without corresponding DNS query: 216.9.227.143 |
Source: unknown | TCP traffic detected without corresponding DNS query: 216.9.227.143 |
Source: unknown | TCP traffic detected without corresponding DNS query: 216.9.227.143 |
Source: unknown | TCP traffic detected without corresponding DNS query: 216.9.227.143 |
Source: unknown | TCP traffic detected without corresponding DNS query: 216.9.227.143 |
Source: unknown | TCP traffic detected without corresponding DNS query: 216.9.227.143 |
Source: unknown | TCP traffic detected without corresponding DNS query: 216.9.227.143 |
Source: unknown | TCP traffic detected without corresponding DNS query: 216.9.227.143 |
Source: unknown | TCP traffic detected without corresponding DNS query: 216.9.227.143 |
Source: unknown | TCP traffic detected without corresponding DNS query: 216.9.227.143 |
Source: unknown | TCP traffic detected without corresponding DNS query: 216.9.227.143 |
Source: unknown | TCP traffic detected without corresponding DNS query: 216.9.227.143 |
Source: unknown | TCP traffic detected without corresponding DNS query: 216.9.227.143 |
Source: unknown | TCP traffic detected without corresponding DNS query: 216.9.227.143 |
Source: unknown | TCP traffic detected without corresponding DNS query: 216.9.227.143 |
Source: unknown | TCP traffic detected without corresponding DNS query: 216.9.227.143 |
Source: unknown | TCP traffic detected without corresponding DNS query: 216.9.227.143 |
Source: unknown | TCP traffic detected without corresponding DNS query: 216.9.227.143 |
Source: unknown | Network traffic detected: HTTP traffic on port 43928 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 42836 -> 443 |
Source: ELF static info symbol of initial sample | .symtab present: no |
Source: classification engine | Classification label: mal52.spre.linELF@0/52@0/0 |
Source: /usr/sbin/logrotate (PID: 6329) | Directory: //. | Jump to behavior |
Source: /usr/bin/find (PID: 6364) | Directory: //. | Jump to behavior |
Source: /usr/bin/mandb (PID: 6391) | Directory: /var/cache/man/.manpath | Jump to behavior |
Source: /usr/bin/dash (PID: 6225) | Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.8YF24dOxG0 /tmp/tmp.ALq3Dnf07E /tmp/tmp.qWPgw5qXeC | Jump to behavior |
Source: /usr/bin/dash (PID: 6226) | Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.8YF24dOxG0 /tmp/tmp.ALq3Dnf07E /tmp/tmp.qWPgw5qXeC | Jump to behavior |
Source: /tmp/SPARC.elf (PID: 6254) | Queries kernel information via 'uname': | Jump to behavior |
Source: /usr/bin/find (PID: 6364) | Queries kernel information via 'uname': | Jump to behavior |
Source: 6391.27.dr | Binary or memory string: -9915837702310A--gzvmware kernel module |
Source: 6391.27.dr | Binary or memory string: -1116261022170A--gzQEMU User Emulator |
Source: 6391.27.dr | Binary or memory string: qemu-or1k |
Source: 6391.27.dr | Binary or memory string: qemu-riscv64 |
Source: 6391.27.dr | Binary or memory string: {cqemu |
Source: 6391.27.dr | Binary or memory string: qemu-arm |
Source: 6391.27.dr | Binary or memory string: (qemu |
Source: 6391.27.dr | Binary or memory string: qemu-tilegx |
Source: 6391.27.dr | Binary or memory string: qemu-hppa |
Source: 6391.27.dr | Binary or memory string: q{rqemu% |
Source: 6391.27.dr | Binary or memory string: )qemu |
Source: 6391.27.dr | Binary or memory string: vmware-toolbox-cmd |
Source: 6391.27.dr | Binary or memory string: qemu-ppc |
Source: 6391.27.dr | Binary or memory string: Tqemu9 |
Source: SPARC.elf, 6254.1.00007ffd88984000.00007ffd889a5000.rw-.sdmp, SPARC.elf, 6256.1.00007ffd88984000.00007ffd889a5000.rw-.sdmp, SPARC.elf, 6258.1.00007ffd88984000.00007ffd889a5000.rw-.sdmp | Binary or memory string: /usr/bin/qemu-sparc |
Source: 6391.27.dr | Binary or memory string: qemu-aarch64_be |
Source: 6391.27.dr | Binary or memory string: 0qemu9 |
Source: 6391.27.dr | Binary or memory string: qemu-sparc64 |
Source: 6391.27.dr | Binary or memory string: qemu-mips64 |
Source: 6391.27.dr | Binary or memory string: vV:qemu9 |
Source: 6391.27.dr | Binary or memory string: qemu-ppc64le |
Source: 6391.27.dr | Binary or memory string: <glib::param::uint64Glib::Param::UInt643pm315820097650A--gzWrapper for uint64 parameters in GLibx86_64-linux-gnu-ld.gold-1116112426130B--gzThe GNU ELF linkerprinter-profile-1115804162510A--gzProfile using X-Rite ColorMunki and Argyll CMSgrub-fstest-1116214898500A--gzdebug tool for GRUB filesystem driversxdg-user-dir-1115483406210A--gzFind an XDG user dirkmodsign-1115569251480A--gzKernel module signing toolsensible-editor-1115739932820A--gzsensible editing, paging, and web browsingminesMines6615854478170Cgnome-mines-gzinputattach-1115708189280A--gzattach a serial line to an input-layer devicegapplication-1116155671180A--gzD-Bus application launcherip-tunnel-8815816145190A--gztunnel configurationkoi8rxterm-1116140167530A--gzX terminal emulator for KOI8-R environmentsfoo2hiperc-wrapper-1115804162510A-tgzConvert Postscript into a HIPERC printer streamcryptsetup-reencrypt-8816002888050A--gztool for offline LUKS device re-encryptionsyndaemon-1115861716810A--gza program that monitors keyboard activity and disables the touchpad when the keyboard is being used.gslj-1115980290200B--gzFormat and print text for LaserJet printer using ghostscriptfile2brl-1115757179490A--gzTranslate an xml or a text file into an embosser-ready braille filexfdesktop-settings-1115793419820A--gzDesktop settings for Xfceua-1115856013570B--gzManage Ubuntu Advantage services from Canonicallatin4-7715812813670B--gzISO 8859-4 character set encoded in octal, decimal, and hexadecimalsane-genesys-5516003468200A--gzSANE backend for GL646, GL841, GL843, GL847 and GL124 based USB flatbed scannerspdftohtml-1115853266670A--gzprogram to convert PDF files into HTML, XML and PNG imagesbluetooth-sendto-1116015653360A--gzGTK application for transferring files over Bluetoothqemu-ppc64-1116261022170B--gzQEMU User Emulatorcache_metadata_size-8815811608350A--gzEstimate the size of the metadata device needed for a given configuration.net::dbus::exporterNet::DBus::Exporter3pm315773746310A--gzExport object methods and signals to the bussane-pint-5516003468200A--gzSANE backend for scanners that use the PINT device driverbpf-helpers7-7715812813670A--gzlist of eBPF helper functionsfull-4415812813670A--gzalways full devicelogin-1115906478670A--gzbegin session on the systemcups-snmp-8815877390340A--gzcups snmp backend (deprecated)ordchr-3am315728089600A--gzconvert characters to strings and vice versasosreport-1116092694050A--gzCollect and package diagnostic and support datatop-111582782727 |