Edit tour

Linux Analysis Report
gigab.mips.elf

Overview

General Information

Sample name:gigab.mips.elf
Analysis ID:1641089
MD5:97e777fa5d757a885950da9147df4f17
SHA1:c0381a921a80c210310765e810d21a52621836c9
SHA256:ef13b2634546f67d9bd696d4dc34dcee0579133d698cd400dbbd667ff7c3b5c2
Tags:elfuser-abuse_ch
Infos:

Detection

Score:52
Range:0 - 100

Signatures

Multi AV Scanner detection for submitted file
Opens /proc/net/* files useful for finding connected devices and routers
Detected TCP or UDP traffic on non-standard ports
Executes the "rm" command used to delete files or directories
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
Joe Sandbox version:42.0.0 Malachite
Analysis ID:1641089
Start date and time:2025-03-18 02:48:29 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 5m 5s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:gigab.mips.elf
Detection:MAL
Classification:mal52.spre.linELF@0/1@0/0
Command:/tmp/gigab.mips.elf
PID:6204
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:

Standard Error:
  • system is lnxubuntu20
  • dash New Fork (PID: 6192, Parent: 4331)
  • rm (PID: 6192, Parent: 4331, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.Kdmeq95weB /tmp/tmp.DjHQC98rnz /tmp/tmp.eieObn3mfy
  • dash New Fork (PID: 6193, Parent: 4331)
  • rm (PID: 6193, Parent: 4331, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.Kdmeq95weB /tmp/tmp.DjHQC98rnz /tmp/tmp.eieObn3mfy
  • cleanup
No yara matches
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: gigab.mips.elfReversingLabs: Detection: 30%

Spreading

barindex
Source: /tmp/gigab.mips.elf (PID: 6204)Opens: /proc/net/routeJump to behavior
Source: global trafficTCP traffic: 192.168.2.23:47546 -> 37.44.238.66:666
Source: global trafficTCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
Source: global trafficTCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
Source: global trafficTCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.66
Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.66
Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.66
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.66
Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.66
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.66
Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.66
Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.66
Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.66
Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443
Source: classification engineClassification label: mal52.spre.linELF@0/1@0/0
Source: /usr/bin/dash (PID: 6192)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.Kdmeq95weB /tmp/tmp.DjHQC98rnz /tmp/tmp.eieObn3mfyJump to behavior
Source: /usr/bin/dash (PID: 6193)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.Kdmeq95weB /tmp/tmp.DjHQC98rnz /tmp/tmp.eieObn3mfyJump to behavior
Source: /tmp/gigab.mips.elf (PID: 6204)Queries kernel information via 'uname': Jump to behavior
Source: gigab.mips.elf, 6204.1.000055b555e03000.000055b555e8a000.rw-.sdmp, gigab.mips.elf, 6206.1.000055b555e03000.000055b555e8a000.rw-.sdmpBinary or memory string: U!/etc/qemu-binfmt/mips
Source: gigab.mips.elf, 6204.1.000055b555e03000.000055b555e8a000.rw-.sdmp, gigab.mips.elf, 6206.1.000055b555e03000.000055b555e8a000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/mips
Source: gigab.mips.elf, 6204.1.00007ffe7cff7000.00007ffe7d018000.rw-.sdmpBinary or memory string: U/tmp/qemu-open.4MiQqj\
Source: gigab.mips.elf, 6204.1.00007ffe7cff7000.00007ffe7d018000.rw-.sdmp, gigab.mips.elf, 6206.1.00007ffe7cff7000.00007ffe7d018000.rw-.sdmpBinary or memory string: /usr/bin/qemu-mips
Source: gigab.mips.elf, 6204.1.00007ffe7cff7000.00007ffe7d018000.rw-.sdmpBinary or memory string: /tmp/qemu-open.4MiQqj
Source: gigab.mips.elf, 6204.1.00007ffe7cff7000.00007ffe7d018000.rw-.sdmp, gigab.mips.elf, 6206.1.00007ffe7cff7000.00007ffe7d018000.rw-.sdmpBinary or memory string: $Nx86_64/usr/bin/qemu-mips/tmp/gigab.mips.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/gigab.mips.elf
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception1
File Deletion
OS Credential Dumping11
Security Software Discovery
Remote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS Memory1
Remote System Discovery
Remote Desktop ProtocolData from Removable Media1
Non-Standard Port
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1641089 Sample: gigab.mips.elf Startdate: 18/03/2025 Architecture: LINUX Score: 52 17 109.202.202.202, 80 INIT7CH Switzerland 2->17 19 37.44.238.66, 47546, 666 HARMONYHOSTING-ASFR France 2->19 21 2 other IPs or domains 2->21 23 Multi AV Scanner detection for submitted file 2->23 8 dash rm gigab.mips.elf 2->8         started        11 dash rm 2->11         started        signatures3 process4 signatures5 25 Opens /proc/net/* files useful for finding connected devices and routers 8->25 13 gigab.mips.elf 8->13         started        process6 process7 15 gigab.mips.elf 13->15         started       
SourceDetectionScannerLabelLink
gigab.mips.elf31%ReversingLabsLinux.Backdoor.Gafgyt
No Antivirus matches
No Antivirus matches
No Antivirus matches

Download Network PCAP: filteredfull

No contacted domains info
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs
IPDomainCountryFlagASNASN NameMalicious
109.202.202.202
unknownSwitzerland
13030INIT7CHfalse
37.44.238.66
unknownFrance
49434HARMONYHOSTING-ASFRfalse
91.189.91.43
unknownUnited Kingdom
41231CANONICAL-ASGBfalse
91.189.91.42
unknownUnited Kingdom
41231CANONICAL-ASGBfalse
MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
109.202.202.202kpLwzBouH4.elfGet hashmaliciousUnknownBrowse
  • ch.archive.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_92.0%2bbuild3-0ubuntu0.20.04.1_amd64.deb
37.44.238.66gigab.mips.elfGet hashmaliciousGafgytBrowse
    gigab.spc.elfGet hashmaliciousGafgytBrowse
      gigab.arm5.elfGet hashmaliciousGafgytBrowse
        gigab.arm4.elfGet hashmaliciousGafgytBrowse
          gigab.x86.elfGet hashmaliciousGafgytBrowse
            gigab.ppc.elfGet hashmaliciousGafgytBrowse
              gigab.sh4.elfGet hashmaliciousGafgytBrowse
                gigab.arm4t.elfGet hashmaliciousGafgytBrowse
                  gigab.i686.elfGet hashmaliciousGafgytBrowse
                    gigab.arm6.elfGet hashmaliciousGafgytBrowse
                      91.189.91.43na.elfGet hashmaliciousPrometeiBrowse
                        na.elfGet hashmaliciousPrometeiBrowse
                          na.elfGet hashmaliciousPrometeiBrowse
                            na.elfGet hashmaliciousPrometeiBrowse
                              na.elfGet hashmaliciousPrometeiBrowse
                                na.elfGet hashmaliciousPrometeiBrowse
                                  na.elfGet hashmaliciousPrometeiBrowse
                                    na.elfGet hashmaliciousPrometeiBrowse
                                      na.elfGet hashmaliciousPrometeiBrowse
                                        na.elfGet hashmaliciousPrometeiBrowse
                                          91.189.91.42na.elfGet hashmaliciousPrometeiBrowse
                                            na.elfGet hashmaliciousPrometeiBrowse
                                              na.elfGet hashmaliciousPrometeiBrowse
                                                na.elfGet hashmaliciousPrometeiBrowse
                                                  na.elfGet hashmaliciousPrometeiBrowse
                                                    na.elfGet hashmaliciousPrometeiBrowse
                                                      na.elfGet hashmaliciousPrometeiBrowse
                                                        na.elfGet hashmaliciousPrometeiBrowse
                                                          na.elfGet hashmaliciousPrometeiBrowse
                                                            na.elfGet hashmaliciousPrometeiBrowse
                                                              No context
                                                              MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                              HARMONYHOSTING-ASFRl7vmra.elfGet hashmaliciousMiraiBrowse
                                                              • 37.44.238.92
                                                              gigab.mips.elfGet hashmaliciousGafgytBrowse
                                                              • 37.44.238.66
                                                              gigab.spc.elfGet hashmaliciousGafgytBrowse
                                                              • 37.44.238.66
                                                              gigab.arm5.elfGet hashmaliciousGafgytBrowse
                                                              • 37.44.238.66
                                                              gigab.arm4.elfGet hashmaliciousGafgytBrowse
                                                              • 37.44.238.66
                                                              gigab.x86.elfGet hashmaliciousGafgytBrowse
                                                              • 37.44.238.66
                                                              gigab.ppc.elfGet hashmaliciousGafgytBrowse
                                                              • 37.44.238.66
                                                              gigab.sh4.elfGet hashmaliciousGafgytBrowse
                                                              • 37.44.238.66
                                                              gigab.arm4t.elfGet hashmaliciousGafgytBrowse
                                                              • 37.44.238.66
                                                              gigab.i686.elfGet hashmaliciousGafgytBrowse
                                                              • 37.44.238.66
                                                              CANONICAL-ASGBna.elfGet hashmaliciousPrometeiBrowse
                                                              • 91.189.91.42
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 91.189.91.42
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 91.189.91.42
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 91.189.91.42
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 91.189.91.42
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 91.189.91.42
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 91.189.91.42
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 185.125.190.26
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 91.189.91.42
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 185.125.190.26
                                                              CANONICAL-ASGBna.elfGet hashmaliciousPrometeiBrowse
                                                              • 91.189.91.42
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 91.189.91.42
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 91.189.91.42
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 91.189.91.42
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 91.189.91.42
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 91.189.91.42
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 91.189.91.42
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 185.125.190.26
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 91.189.91.42
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 185.125.190.26
                                                              INIT7CHna.elfGet hashmaliciousPrometeiBrowse
                                                              • 109.202.202.202
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 109.202.202.202
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 109.202.202.202
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 109.202.202.202
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 109.202.202.202
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 109.202.202.202
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 109.202.202.202
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 109.202.202.202
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 109.202.202.202
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 109.202.202.202
                                                              No context
                                                              No context
                                                              Process:/tmp/gigab.mips.elf
                                                              File Type:ASCII text
                                                              Category:dropped
                                                              Size (bytes):230
                                                              Entropy (8bit):3.709552666863289
                                                              Encrypted:false
                                                              SSDEEP:6:iekrEcvwAsE5KlwSd4pzKaV6Lpms/a/1VCxGF:ur+m5MwSdIKaV6L1adVRF
                                                              MD5:2E667F43AE18CD1FE3C108641708A82C
                                                              SHA1:12B90DE2DA0FBCFE66F3D6130905E56C8D6A68D3
                                                              SHA-256:6F721492E7A337C5B498A8F55F5EB7AC745AFF716D0B5B08EFF2C1B6B250F983
                                                              SHA-512:D2A0EE2509154EC1098994F38BE172F98F4150399C534A04D5C675D7C05630802225019F19344CC9070C576BC465A4FEB382AC7712DE6BF25E9244B54A9DB830
                                                              Malicious:false
                                                              Reputation:high, very likely benign file
                                                              Preview:Iface.Destination.Gateway .Flags.RefCnt.Use.Metric.Mask..MTU.Window.IRTT .ens160.00000000.c0a80201.0003.0.0.0.00000000.0.0.0.ens160.c0a80200.00000000.0001.0.0.0.ffffff00.0.0.0.
                                                              File type:ELF 32-bit MSB executable, MIPS, MIPS-I version 1 (SYSV), statically linked, missing section headers at 121272
                                                              Entropy (8bit):5.143123785090316
                                                              TrID:
                                                              • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                                                              File name:gigab.mips.elf
                                                              File size:118'471 bytes
                                                              MD5:97e777fa5d757a885950da9147df4f17
                                                              SHA1:c0381a921a80c210310765e810d21a52621836c9
                                                              SHA256:ef13b2634546f67d9bd696d4dc34dcee0579133d698cd400dbbd667ff7c3b5c2
                                                              SHA512:885f803912524b767eed118f385ef97fe5655054d1a97b8d6e3e6183af2cd41a9556c6befbea3cf29d3825dc611c08f08ecd543fe3c868260a9278efe8a6adbb
                                                              SSDEEP:1536:iHf2lkXEauT9H4SC3DlSjn13G22rK8cecu6I/OayL+CYm4nUeSnDsk5R4/TiP/zz:1ELl21EZ0CUjDskiTiPBprL
                                                              TLSH:03C3B53E6E22AB7EE1ADD23107F25EB0D75525D227E18240F1ACDB085E7128D5C8F7A4
                                                              File Content Preview:.ELF.....................@.....4.........4. ...(....p........@...@...........................@...@.....0...0.................B...B........z(...............D.B.D.B.D................dt.Q.................................................C#P<...'."d...!'......

                                                              Download Network PCAP: filteredfull

                                                              • Total Packets: 16
                                                              • 666 undefined
                                                              • 443 (HTTPS)
                                                              • 80 (HTTP)
                                                              TimestampSource PortDest PortSource IPDest IP
                                                              Mar 18, 2025 02:49:12.236941099 CET47546666192.168.2.2337.44.238.66
                                                              Mar 18, 2025 02:49:12.241676092 CET6664754637.44.238.66192.168.2.23
                                                              Mar 18, 2025 02:49:12.241820097 CET47546666192.168.2.2337.44.238.66
                                                              Mar 18, 2025 02:49:12.243434906 CET47546666192.168.2.2337.44.238.66
                                                              Mar 18, 2025 02:49:12.248378992 CET6664754637.44.238.66192.168.2.23
                                                              Mar 18, 2025 02:49:12.472626925 CET43928443192.168.2.2391.189.91.42
                                                              Mar 18, 2025 02:49:17.847917080 CET42836443192.168.2.2391.189.91.43
                                                              Mar 18, 2025 02:49:19.383646965 CET4251680192.168.2.23109.202.202.202
                                                              Mar 18, 2025 02:49:32.949764013 CET43928443192.168.2.2391.189.91.42
                                                              Mar 18, 2025 02:49:45.236079931 CET42836443192.168.2.2391.189.91.43
                                                              Mar 18, 2025 02:49:49.331470013 CET4251680192.168.2.23109.202.202.202
                                                              Mar 18, 2025 02:50:11.370975971 CET6664754637.44.238.66192.168.2.23
                                                              Mar 18, 2025 02:50:11.371376991 CET47546666192.168.2.2337.44.238.66
                                                              Mar 18, 2025 02:50:11.519223928 CET6664754637.44.238.66192.168.2.23
                                                              Mar 18, 2025 02:50:11.519526005 CET47546666192.168.2.2337.44.238.66
                                                              Mar 18, 2025 02:50:13.904048920 CET43928443192.168.2.2391.189.91.42
                                                              Mar 18, 2025 02:51:11.385323048 CET6664754637.44.238.66192.168.2.23
                                                              Mar 18, 2025 02:51:11.385464907 CET47546666192.168.2.2337.44.238.66
                                                              Mar 18, 2025 02:51:11.520365000 CET6664754637.44.238.66192.168.2.23
                                                              Mar 18, 2025 02:51:11.520591974 CET47546666192.168.2.2337.44.238.66
                                                              Mar 18, 2025 02:52:11.446677923 CET6664754637.44.238.66192.168.2.23
                                                              Mar 18, 2025 02:52:11.446809053 CET47546666192.168.2.2337.44.238.66
                                                              Mar 18, 2025 02:52:11.584075928 CET6664754637.44.238.66192.168.2.23
                                                              Mar 18, 2025 02:52:11.584172010 CET47546666192.168.2.2337.44.238.66

                                                              System Behavior

                                                              Start time (UTC):01:49:04
                                                              Start date (UTC):18/03/2025
                                                              Path:/usr/bin/dash
                                                              Arguments:-
                                                              File size:129816 bytes
                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                              Start time (UTC):01:49:04
                                                              Start date (UTC):18/03/2025
                                                              Path:/usr/bin/rm
                                                              Arguments:rm -f /tmp/tmp.Kdmeq95weB /tmp/tmp.DjHQC98rnz /tmp/tmp.eieObn3mfy
                                                              File size:72056 bytes
                                                              MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b

                                                              Start time (UTC):01:49:04
                                                              Start date (UTC):18/03/2025
                                                              Path:/usr/bin/dash
                                                              Arguments:-
                                                              File size:129816 bytes
                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                              Start time (UTC):01:49:04
                                                              Start date (UTC):18/03/2025
                                                              Path:/usr/bin/rm
                                                              Arguments:rm -f /tmp/tmp.Kdmeq95weB /tmp/tmp.DjHQC98rnz /tmp/tmp.eieObn3mfy
                                                              File size:72056 bytes
                                                              MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b

                                                              Start time (UTC):01:49:11
                                                              Start date (UTC):18/03/2025
                                                              Path:/tmp/gigab.mips.elf
                                                              Arguments:/tmp/gigab.mips.elf
                                                              File size:5777432 bytes
                                                              MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                                                              Start time (UTC):01:49:11
                                                              Start date (UTC):18/03/2025
                                                              Path:/tmp/gigab.mips.elf
                                                              Arguments:-
                                                              File size:5777432 bytes
                                                              MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                                                              Start time (UTC):01:49:11
                                                              Start date (UTC):18/03/2025
                                                              Path:/tmp/gigab.mips.elf
                                                              Arguments:-
                                                              File size:5777432 bytes
                                                              MD5 hash:0083f1f0e77be34ad27f849842bbb00c