Edit tour

Linux Analysis Report
i686.elf

Overview

General Information

Sample name:i686.elf
Analysis ID:1646212
MD5:7be047aad03862b336186f2b4f378b74
SHA1:7b417da16cc0db4c62d552332f64e82a525ba0c9
SHA256:bdd96f70b8ad52353baa09e1dabfd694eb503b67e011b5d2051252d0a7113b94
Tags:elfuser-abuse_ch
Infos:

Detection

Mirai
Score:76
Range:0 - 100

Signatures

Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Yara detected Mirai
Connects to many ports of the same IP (likely port scanning)
Sample deletes itself
Sample is packed with UPX
Detected TCP or UDP traffic on non-standard ports
ELF contains segments with high entropy indicating compressed/encrypted content
Executes the "rm" command used to delete files or directories
Sample contains only a LOAD segment without any section mappings
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Yara signature match

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
Joe Sandbox version:42.0.0 Malachite
Analysis ID:1646212
Start date and time:2025-03-23 17:07:10 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 36s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:i686.elf
Detection:MAL
Classification:mal76.troj.evad.linELF@0/0@0/0
Command:/tmp/i686.elf
PID:6261
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
Obliterate You
Standard Error:
  • system is lnxubuntu20
  • dash New Fork (PID: 6223, Parent: 4332)
  • rm (PID: 6223, Parent: 4332, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.e0UCmpr0U3 /tmp/tmp.OgOVs4TfJ9 /tmp/tmp.7g0nkV7u2K
  • dash New Fork (PID: 6224, Parent: 4332)
  • cat (PID: 6224, Parent: 4332, MD5: 7e9d213e404ad3bb82e4ebb2e1f2c1b3) Arguments: cat /tmp/tmp.e0UCmpr0U3
  • dash New Fork (PID: 6225, Parent: 4332)
  • head (PID: 6225, Parent: 4332, MD5: fd96a67145172477dd57131396fc9608) Arguments: head -n 10
  • dash New Fork (PID: 6226, Parent: 4332)
  • tr (PID: 6226, Parent: 4332, MD5: fbd1402dd9f72d8ebfff00ce7c3a7bb5) Arguments: tr -d \\000-\\011\\013\\014\\016-\\037
  • dash New Fork (PID: 6227, Parent: 4332)
  • cut (PID: 6227, Parent: 4332, MD5: d8ed0ea8f22c0de0f8692d4d9f1759d3) Arguments: cut -c -80
  • dash New Fork (PID: 6228, Parent: 4332)
  • cat (PID: 6228, Parent: 4332, MD5: 7e9d213e404ad3bb82e4ebb2e1f2c1b3) Arguments: cat /tmp/tmp.e0UCmpr0U3
  • dash New Fork (PID: 6229, Parent: 4332)
  • head (PID: 6229, Parent: 4332, MD5: fd96a67145172477dd57131396fc9608) Arguments: head -n 10
  • dash New Fork (PID: 6230, Parent: 4332)
  • tr (PID: 6230, Parent: 4332, MD5: fbd1402dd9f72d8ebfff00ce7c3a7bb5) Arguments: tr -d \\000-\\011\\013\\014\\016-\\037
  • dash New Fork (PID: 6231, Parent: 4332)
  • cut (PID: 6231, Parent: 4332, MD5: d8ed0ea8f22c0de0f8692d4d9f1759d3) Arguments: cut -c -80
  • dash New Fork (PID: 6232, Parent: 4332)
  • rm (PID: 6232, Parent: 4332, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.e0UCmpr0U3 /tmp/tmp.OgOVs4TfJ9 /tmp/tmp.7g0nkV7u2K
  • i686.elf (PID: 6261, Parent: 6149, MD5: 7be047aad03862b336186f2b4f378b74) Arguments: /tmp/i686.elf
    • i686.elf New Fork (PID: 6262, Parent: 6261)
      • i686.elf New Fork (PID: 6263, Parent: 6262)
        • i686.elf New Fork (PID: 6264, Parent: 6263)
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
MiraiMirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese. Nowadays it targets a wide range of networked embedded devices such as IP cameras, home routers (many vendors involved), and other IoT devices. Since the source code was published on "Hack Forums" many variants of the Mirai family appeared, infecting mostly home networks all around the world.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/elf.mirai
SourceRuleDescriptionAuthorStrings
6261.1.0000000008048000.0000000008055000.r-x.sdmpJoeSecurity_Mirai_9Yara detected MiraiJoe Security
    6261.1.0000000008048000.0000000008055000.r-x.sdmpLinux_Trojan_Mirai_268aac0bunknownunknown
    • 0x4e9f:$a: 24 18 0F B7 44 24 20 8B 54 24 1C 83 F9 01 8B 7E 0C 89 04 24 8B
    6261.1.0000000008048000.0000000008055000.r-x.sdmpLinux_Trojan_Mirai_0cb1699cunknownunknown
    • 0x4e52:$a: DB 8B 4C 24 0C 8B 54 24 08 83 F9 01 76 10 0F B7 02 83 E9 02 83
    6261.1.0000000008048000.0000000008055000.r-x.sdmpLinux_Trojan_Mirai_70ef58f1unknownunknown
    • 0x642d:$a: 89 D0 8B 19 01 D8 0F B6 5C 24 10 30 18 89 D0 8B 19 01 D8 0F B6 5C
    • 0x64ad:$a: 89 D0 8B 19 01 D8 0F B6 5C 24 10 30 18 89 D0 8B 19 01 D8 0F B6 5C
    6261.1.0000000008048000.0000000008055000.r-x.sdmpLinux_Trojan_Mirai_3a85a418unknownunknown
    • 0x4917:$a: 01 D8 66 C1 C8 08 C1 C8 10 66 C1 C8 08 66 83 7C 24 2C FF 89
    Click to see the 3 entries
    No Suricata rule has matched

    Click to jump to signature section

    Show All Signature Results

    AV Detection

    barindex
    Source: i686.elfReversingLabs: Detection: 50%
    Source: i686.elfVirustotal: Detection: 21%Perma Link

    Networking

    barindex
    Source: global trafficTCP traffic: 198.98.51.68 ports 1,2,3,4,5,23451
    Source: global trafficTCP traffic: 192.168.2.23:60332 -> 198.98.51.68:23451
    Source: global trafficTCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
    Source: global trafficTCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
    Source: global trafficTCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
    Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
    Source: unknownTCP traffic detected without corresponding DNS query: 198.98.51.68
    Source: unknownTCP traffic detected without corresponding DNS query: 198.98.51.68
    Source: unknownTCP traffic detected without corresponding DNS query: 198.98.51.68
    Source: unknownTCP traffic detected without corresponding DNS query: 198.98.51.68
    Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
    Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
    Source: unknownTCP traffic detected without corresponding DNS query: 198.98.51.68
    Source: unknownTCP traffic detected without corresponding DNS query: 198.98.51.68
    Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
    Source: unknownTCP traffic detected without corresponding DNS query: 198.98.51.68
    Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
    Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
    Source: unknownTCP traffic detected without corresponding DNS query: 198.98.51.68
    Source: unknownTCP traffic detected without corresponding DNS query: 198.98.51.68
    Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
    Source: unknownTCP traffic detected without corresponding DNS query: 198.98.51.68
    Source: unknownTCP traffic detected without corresponding DNS query: 198.98.51.68
    Source: unknownTCP traffic detected without corresponding DNS query: 198.98.51.68
    Source: unknownTCP traffic detected without corresponding DNS query: 198.98.51.68
    Source: unknownTCP traffic detected without corresponding DNS query: 198.98.51.68
    Source: i686.elfString found in binary or memory: http://upx.sf.net
    Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443

    System Summary

    barindex
    Source: 6261.1.0000000008048000.0000000008055000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_268aac0b Author: unknown
    Source: 6261.1.0000000008048000.0000000008055000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_0cb1699c Author: unknown
    Source: 6261.1.0000000008048000.0000000008055000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_70ef58f1 Author: unknown
    Source: 6261.1.0000000008048000.0000000008055000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_3a85a418 Author: unknown
    Source: 6261.1.0000000008048000.0000000008055000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_2e3f67a9 Author: unknown
    Source: 6261.1.0000000008048000.0000000008055000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_88de437f Author: unknown
    Source: 6261.1.0000000008048000.0000000008055000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_cc93863b Author: unknown
    Source: LOAD without section mappingsProgram segment: 0xc01000
    Source: 6261.1.0000000008048000.0000000008055000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_268aac0b reference_sample = 49c94d184d7e387c3efe34ae6f021e011c3046ae631c9733ab0a230d5fe28ead, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 9c581721bf82af7dc6482a2c41af5fb3404e01c82545c7b2b29230f707014781, id = 268aac0b-c5c7-4035-8381-4e182de91e32, last_modified = 2021-09-16
    Source: 6261.1.0000000008048000.0000000008055000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_0cb1699c reference_sample = fc8741f67f39e7409ab2c6c62d4f9acdd168d3e53cf6976dd87501833771cacb, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 6e44c68bba8c9fb53ac85080b9ad765579f027cabfea5055a0bb3a85b8671089, id = 0cb1699c-9a08-4885-aa7f-0f1ee2543cac, last_modified = 2021-09-16
    Source: 6261.1.0000000008048000.0000000008055000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_70ef58f1 reference_sample = fc8741f67f39e7409ab2c6c62d4f9acdd168d3e53cf6976dd87501833771cacb, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = c46eac9185e5f396456004d1e0c42b54a9318e0450f797c55703122cfb8fea89, id = 70ef58f1-ac74-4e33-ae03-e68d1d5a4379, last_modified = 2021-09-16
    Source: 6261.1.0000000008048000.0000000008055000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_3a85a418 reference_sample = 86a43b39b157f47ab12e9dc1013b4eec0e1792092d4cef2772a21a9bf4fc518a, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 554aff5770bfe8fdeae94f5f5a0fd7f7786340a95633433d8e686af1c25b8cec, id = 3a85a418-2bd9-445a-86cb-657ca7edf566, last_modified = 2021-09-16
    Source: 6261.1.0000000008048000.0000000008055000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_2e3f67a9 reference_sample = fc8741f67f39e7409ab2c6c62d4f9acdd168d3e53cf6976dd87501833771cacb, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 6a06815f3d2e5f1a7a67f4264953dbb2e9d14e5f3486b178da845eab5b922d4f, id = 2e3f67a9-6fd5-4457-a626-3a9015bdb401, last_modified = 2021-09-16
    Source: 6261.1.0000000008048000.0000000008055000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_88de437f reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = c19eb595c2b444a809bef8500c20342c9f46694d3018e268833f9b884133a1ea, id = 88de437f-9c98-4e1d-96c0-7b433c99886a, last_modified = 2021-09-16
    Source: 6261.1.0000000008048000.0000000008055000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_cc93863b reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = f3ecd30f0b511a8e92cfa642409d559e7612c3f57a1659ca46c77aca809a00ac, id = cc93863b-1050-40ba-9d02-5ec9ce6a3a28, last_modified = 2022-01-26
    Source: classification engineClassification label: mal76.troj.evad.linELF@0/0@0/0

    Data Obfuscation

    barindex
    Source: initial sampleString containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $
    Source: initial sampleString containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $
    Source: initial sampleString containing UPX found: $Id: UPX 3.94 Copyright (C) 1996-2017 the UPX Team. All Rights Reserved. $
    Source: /usr/bin/dash (PID: 6223)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.e0UCmpr0U3 /tmp/tmp.OgOVs4TfJ9 /tmp/tmp.7g0nkV7u2KJump to behavior
    Source: /usr/bin/dash (PID: 6232)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.e0UCmpr0U3 /tmp/tmp.OgOVs4TfJ9 /tmp/tmp.7g0nkV7u2KJump to behavior

    Hooking and other Techniques for Hiding and Protection

    barindex
    Source: /tmp/i686.elf (PID: 6261)File: /tmp/i686.elfJump to behavior
    Source: i686.elfSubmission file: segment LOAD with 7.8891 entropy (max. 8.0)

    Stealing of Sensitive Information

    barindex
    Source: Yara matchFile source: 6261.1.0000000008048000.0000000008055000.r-x.sdmp, type: MEMORY

    Remote Access Functionality

    barindex
    Source: Yara matchFile source: 6261.1.0000000008048000.0000000008055000.r-x.sdmp, type: MEMORY
    ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
    Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception11
    Obfuscated Files or Information
    OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
    Encrypted Channel
    Exfiltration Over Other Network MediumAbuse Accessibility Features
    CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts11
    File Deletion
    LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
    Non-Standard Port
    Exfiltration Over BluetoothNetwork Denial of Service
    Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
    Application Layer Protocol
    Automated ExfiltrationData Encrypted for Impact
    No configs have been found
    Hide Legend

    Legend:

    • Process
    • Signature
    • Created File
    • DNS/IP Info
    • Is Dropped
    • Number of created Files
    • Is malicious
    • Internet
    behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1646212 Sample: i686.elf Startdate: 23/03/2025 Architecture: LINUX Score: 76 24 198.98.51.68, 23451, 60332 PONYNETUS United States 2->24 26 109.202.202.202, 80 INIT7CH Switzerland 2->26 28 2 other IPs or domains 2->28 30 Malicious sample detected (through community Yara rule) 2->30 32 Multi AV Scanner detection for submitted file 2->32 34 Yara detected Mirai 2->34 36 2 other signatures 2->36 9 dash rm i686.elf 2->9         started        12 dash rm 2->12         started        14 dash cut 2->14         started        16 7 other processes 2->16 signatures3 process4 signatures5 38 Sample deletes itself 9->38 18 i686.elf 9->18         started        process6 process7 20 i686.elf 18->20         started        process8 22 i686.elf 20->22         started       
    SourceDetectionScannerLabelLink
    i686.elf50%ReversingLabsLinux.Backdoor.Mirai
    i686.elf22%VirustotalBrowse
    No Antivirus matches
    No Antivirus matches
    No Antivirus matches

    Download Network PCAP: filteredfull

    No contacted domains info
    NameSourceMaliciousAntivirus DetectionReputation
    http://upx.sf.neti686.elffalse
      high
      • No. of IPs < 25%
      • 25% < No. of IPs < 50%
      • 50% < No. of IPs < 75%
      • 75% < No. of IPs
      IPDomainCountryFlagASNASN NameMalicious
      198.98.51.68
      unknownUnited States
      53667PONYNETUStrue
      109.202.202.202
      unknownSwitzerland
      13030INIT7CHfalse
      91.189.91.43
      unknownUnited Kingdom
      41231CANONICAL-ASGBfalse
      91.189.91.42
      unknownUnited Kingdom
      41231CANONICAL-ASGBfalse
      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
      198.98.51.68arm.elfGet hashmaliciousMiraiBrowse
        x86.elfGet hashmaliciousMiraiBrowse
          mpsl.elfGet hashmaliciousMiraiBrowse
            mips.elfGet hashmaliciousMiraiBrowse
              i486.elfGet hashmaliciousUnknownBrowse
                arm7.elfGet hashmaliciousMiraiBrowse
                  x86_64.elfGet hashmaliciousMiraiBrowse
                    109.202.202.202kpLwzBouH4.elfGet hashmaliciousUnknownBrowse
                    • ch.archive.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_92.0%2bbuild3-0ubuntu0.20.04.1_amd64.deb
                    91.189.91.43i.elfGet hashmaliciousUnknownBrowse
                      na.elfGet hashmaliciousPrometeiBrowse
                        na.elfGet hashmaliciousPrometeiBrowse
                          na.elfGet hashmaliciousPrometeiBrowse
                            morte.arm7.elfGet hashmaliciousOkiruBrowse
                              morte.sh4.elfGet hashmaliciousGafgyt, OkiruBrowse
                                morte.arm5.elfGet hashmaliciousOkiruBrowse
                                  na.elfGet hashmaliciousPrometeiBrowse
                                    na.elfGet hashmaliciousPrometeiBrowse
                                      miner.elfGet hashmaliciousUnknownBrowse
                                        91.189.91.42i.elfGet hashmaliciousUnknownBrowse
                                          na.elfGet hashmaliciousPrometeiBrowse
                                            na.elfGet hashmaliciousPrometeiBrowse
                                              na.elfGet hashmaliciousPrometeiBrowse
                                                morte.arm7.elfGet hashmaliciousOkiruBrowse
                                                  morte.sh4.elfGet hashmaliciousGafgyt, OkiruBrowse
                                                    morte.arm5.elfGet hashmaliciousOkiruBrowse
                                                      na.elfGet hashmaliciousPrometeiBrowse
                                                        na.elfGet hashmaliciousPrometeiBrowse
                                                          miner.elfGet hashmaliciousUnknownBrowse
                                                            No context
                                                            MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                            CANONICAL-ASGBi.elfGet hashmaliciousUnknownBrowse
                                                            • 91.189.91.42
                                                            na.elfGet hashmaliciousPrometeiBrowse
                                                            • 91.189.91.42
                                                            na.elfGet hashmaliciousPrometeiBrowse
                                                            • 185.125.190.26
                                                            na.elfGet hashmaliciousPrometeiBrowse
                                                            • 91.189.91.42
                                                            na.elfGet hashmaliciousPrometeiBrowse
                                                            • 91.189.91.42
                                                            morte.arm7.elfGet hashmaliciousOkiruBrowse
                                                            • 91.189.91.42
                                                            morte.sh4.elfGet hashmaliciousGafgyt, OkiruBrowse
                                                            • 91.189.91.42
                                                            morte.arm5.elfGet hashmaliciousOkiruBrowse
                                                            • 91.189.91.42
                                                            na.elfGet hashmaliciousPrometeiBrowse
                                                            • 91.189.91.42
                                                            na.elfGet hashmaliciousPrometeiBrowse
                                                            • 91.189.91.42
                                                            CANONICAL-ASGBi.elfGet hashmaliciousUnknownBrowse
                                                            • 91.189.91.42
                                                            na.elfGet hashmaliciousPrometeiBrowse
                                                            • 91.189.91.42
                                                            na.elfGet hashmaliciousPrometeiBrowse
                                                            • 185.125.190.26
                                                            na.elfGet hashmaliciousPrometeiBrowse
                                                            • 91.189.91.42
                                                            na.elfGet hashmaliciousPrometeiBrowse
                                                            • 91.189.91.42
                                                            morte.arm7.elfGet hashmaliciousOkiruBrowse
                                                            • 91.189.91.42
                                                            morte.sh4.elfGet hashmaliciousGafgyt, OkiruBrowse
                                                            • 91.189.91.42
                                                            morte.arm5.elfGet hashmaliciousOkiruBrowse
                                                            • 91.189.91.42
                                                            na.elfGet hashmaliciousPrometeiBrowse
                                                            • 91.189.91.42
                                                            na.elfGet hashmaliciousPrometeiBrowse
                                                            • 91.189.91.42
                                                            INIT7CHi.elfGet hashmaliciousUnknownBrowse
                                                            • 109.202.202.202
                                                            na.elfGet hashmaliciousPrometeiBrowse
                                                            • 109.202.202.202
                                                            na.elfGet hashmaliciousPrometeiBrowse
                                                            • 109.202.202.202
                                                            na.elfGet hashmaliciousPrometeiBrowse
                                                            • 109.202.202.202
                                                            morte.arm7.elfGet hashmaliciousOkiruBrowse
                                                            • 109.202.202.202
                                                            morte.sh4.elfGet hashmaliciousGafgyt, OkiruBrowse
                                                            • 109.202.202.202
                                                            morte.arm5.elfGet hashmaliciousOkiruBrowse
                                                            • 109.202.202.202
                                                            na.elfGet hashmaliciousPrometeiBrowse
                                                            • 109.202.202.202
                                                            na.elfGet hashmaliciousPrometeiBrowse
                                                            • 109.202.202.202
                                                            miner.elfGet hashmaliciousUnknownBrowse
                                                            • 109.202.202.202
                                                            PONYNETUSarm.elfGet hashmaliciousMiraiBrowse
                                                            • 198.98.51.68
                                                            x86.elfGet hashmaliciousMiraiBrowse
                                                            • 198.98.51.68
                                                            mpsl.elfGet hashmaliciousMiraiBrowse
                                                            • 198.98.51.68
                                                            mips.elfGet hashmaliciousMiraiBrowse
                                                            • 198.98.51.68
                                                            i486.elfGet hashmaliciousUnknownBrowse
                                                            • 198.98.51.68
                                                            arm7.elfGet hashmaliciousMiraiBrowse
                                                            • 198.98.51.68
                                                            x86_64.elfGet hashmaliciousMiraiBrowse
                                                            • 198.98.51.68
                                                            boatnet.ppc.elfGet hashmaliciousMiraiBrowse
                                                            • 209.141.40.172
                                                            boatnet.m68k.elfGet hashmaliciousMiraiBrowse
                                                            • 209.141.40.172
                                                            boatnet.arm7.elfGet hashmaliciousMiraiBrowse
                                                            • 209.141.40.172
                                                            No context
                                                            No context
                                                            No created / dropped files found
                                                            File type:ELF 32-bit LSB executable, Intel 80386, version 1 (GNU/Linux), statically linked, no section header
                                                            Entropy (8bit):7.884656488383752
                                                            TrID:
                                                            • ELF Executable and Linkable format (Linux) (4029/14) 50.16%
                                                            • ELF Executable and Linkable format (generic) (4004/1) 49.84%
                                                            File name:i686.elf
                                                            File size:27'580 bytes
                                                            MD5:7be047aad03862b336186f2b4f378b74
                                                            SHA1:7b417da16cc0db4c62d552332f64e82a525ba0c9
                                                            SHA256:bdd96f70b8ad52353baa09e1dabfd694eb503b67e011b5d2051252d0a7113b94
                                                            SHA512:eae770123cfc84eda9f6525577aa8fae3ccb9b314181b394377d98a1d0e122c0f6c4cf2059fc97bcc4cdd52d951ffe004922f8ee92a42732866e20487ba92e2f
                                                            SSDEEP:384:M8QYzk79o52YiuEYaBEdmHgnJDp59+e4yDY3goZhgVSyCIrrYUIs4JGCtjlNUIvP:lY7a27xbAJDtZDY3g8hgMyChQ4JztjVX
                                                            TLSH:42C2E158EEDEC48FE668837DD19BA80414B744B8AF537E08DDDC22537C2B271661CA0E
                                                            File Content Preview:.ELF.....................r..4...........4. ...(......................j...j..............@...@}..@}..................Q.td................................UPX!........L...L.......^........?d..ELF.......h.......4....4. (.......k.-.#.\..............P..|..@..A.

                                                            ELF header

                                                            Class:ELF32
                                                            Data:2's complement, little endian
                                                            Version:1 (current)
                                                            Machine:Intel 80386
                                                            Version Number:0x1
                                                            Type:EXEC (Executable file)
                                                            OS/ABI:UNIX - Linux
                                                            ABI Version:0
                                                            Entry Point Address:0xc072d0
                                                            Flags:0x0
                                                            ELF Header Size:52
                                                            Program Header Offset:52
                                                            Program Header Size:32
                                                            Number of Program Headers:3
                                                            Section Header Offset:0
                                                            Section Header Size:40
                                                            Number of Section Headers:0
                                                            Header String Table Index:0
                                                            TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                            LOAD0x00xc010000xc010000x6ab30x6ab37.88910x5R E0x1000
                                                            LOAD0xd400x8057d400x8057d400x00x00.00000x6RW 0x1000
                                                            GNU_STACK0x00x00x00x00x00.00000x6RW 0x4

                                                            Download Network PCAP: filteredfull

                                                            • Total Packets: 21
                                                            • 23451 undefined
                                                            • 443 (HTTPS)
                                                            • 80 (HTTP)
                                                            TimestampSource PortDest PortSource IPDest IP
                                                            Mar 23, 2025 17:07:58.211338043 CET43928443192.168.2.2391.189.91.42
                                                            Mar 23, 2025 17:07:58.424474001 CET6033223451192.168.2.23198.98.51.68
                                                            Mar 23, 2025 17:07:58.516454935 CET2345160332198.98.51.68192.168.2.23
                                                            Mar 23, 2025 17:07:58.516521931 CET6033223451192.168.2.23198.98.51.68
                                                            Mar 23, 2025 17:07:58.516580105 CET6033223451192.168.2.23198.98.51.68
                                                            Mar 23, 2025 17:07:58.607275009 CET2345160332198.98.51.68192.168.2.23
                                                            Mar 23, 2025 17:07:58.607338905 CET6033223451192.168.2.23198.98.51.68
                                                            Mar 23, 2025 17:07:58.700005054 CET2345160332198.98.51.68192.168.2.23
                                                            Mar 23, 2025 17:08:03.842538118 CET42836443192.168.2.2391.189.91.43
                                                            Mar 23, 2025 17:08:04.614433050 CET4251680192.168.2.23109.202.202.202
                                                            Mar 23, 2025 17:08:08.521873951 CET6033223451192.168.2.23198.98.51.68
                                                            Mar 23, 2025 17:08:08.612206936 CET2345160332198.98.51.68192.168.2.23
                                                            Mar 23, 2025 17:08:08.612221956 CET2345160332198.98.51.68192.168.2.23
                                                            Mar 23, 2025 17:08:08.612261057 CET6033223451192.168.2.23198.98.51.68
                                                            Mar 23, 2025 17:08:18.432495117 CET43928443192.168.2.2391.189.91.42
                                                            Mar 23, 2025 17:08:23.728408098 CET2345160332198.98.51.68192.168.2.23
                                                            Mar 23, 2025 17:08:23.728472948 CET6033223451192.168.2.23198.98.51.68
                                                            Mar 23, 2025 17:08:30.718770981 CET42836443192.168.2.2391.189.91.43
                                                            Mar 23, 2025 17:08:34.814248085 CET4251680192.168.2.23109.202.202.202
                                                            Mar 23, 2025 17:08:38.818635941 CET2345160332198.98.51.68192.168.2.23
                                                            Mar 23, 2025 17:08:38.818721056 CET6033223451192.168.2.23198.98.51.68
                                                            Mar 23, 2025 17:08:53.911066055 CET2345160332198.98.51.68192.168.2.23
                                                            Mar 23, 2025 17:08:53.911200047 CET6033223451192.168.2.23198.98.51.68
                                                            Mar 23, 2025 17:08:59.386809111 CET43928443192.168.2.2391.189.91.42
                                                            Mar 23, 2025 17:09:08.653565884 CET6033223451192.168.2.23198.98.51.68
                                                            Mar 23, 2025 17:09:08.743952036 CET2345160332198.98.51.68192.168.2.23
                                                            Mar 23, 2025 17:09:08.744091034 CET6033223451192.168.2.23198.98.51.68
                                                            Mar 23, 2025 17:09:23.888227940 CET2345160332198.98.51.68192.168.2.23
                                                            Mar 23, 2025 17:09:23.888324976 CET6033223451192.168.2.23198.98.51.68
                                                            Mar 23, 2025 17:09:38.978636980 CET2345160332198.98.51.68192.168.2.23
                                                            Mar 23, 2025 17:09:38.978719950 CET6033223451192.168.2.23198.98.51.68
                                                            Mar 23, 2025 17:09:54.068367958 CET2345160332198.98.51.68192.168.2.23
                                                            Mar 23, 2025 17:09:54.068561077 CET6033223451192.168.2.23198.98.51.68

                                                            System Behavior

                                                            Start time (UTC):16:07:54
                                                            Start date (UTC):23/03/2025
                                                            Path:/usr/bin/dash
                                                            Arguments:-
                                                            File size:129816 bytes
                                                            MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                            Start time (UTC):16:07:54
                                                            Start date (UTC):23/03/2025
                                                            Path:/usr/bin/rm
                                                            Arguments:rm -f /tmp/tmp.e0UCmpr0U3 /tmp/tmp.OgOVs4TfJ9 /tmp/tmp.7g0nkV7u2K
                                                            File size:72056 bytes
                                                            MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b

                                                            Start time (UTC):16:07:54
                                                            Start date (UTC):23/03/2025
                                                            Path:/usr/bin/dash
                                                            Arguments:-
                                                            File size:129816 bytes
                                                            MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                            Start time (UTC):16:07:54
                                                            Start date (UTC):23/03/2025
                                                            Path:/usr/bin/cat
                                                            Arguments:cat /tmp/tmp.e0UCmpr0U3
                                                            File size:43416 bytes
                                                            MD5 hash:7e9d213e404ad3bb82e4ebb2e1f2c1b3

                                                            Start time (UTC):16:07:54
                                                            Start date (UTC):23/03/2025
                                                            Path:/usr/bin/dash
                                                            Arguments:-
                                                            File size:129816 bytes
                                                            MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                            Start time (UTC):16:07:54
                                                            Start date (UTC):23/03/2025
                                                            Path:/usr/bin/head
                                                            Arguments:head -n 10
                                                            File size:47480 bytes
                                                            MD5 hash:fd96a67145172477dd57131396fc9608

                                                            Start time (UTC):16:07:54
                                                            Start date (UTC):23/03/2025
                                                            Path:/usr/bin/dash
                                                            Arguments:-
                                                            File size:129816 bytes
                                                            MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                            Start time (UTC):16:07:54
                                                            Start date (UTC):23/03/2025
                                                            Path:/usr/bin/tr
                                                            Arguments:tr -d \\000-\\011\\013\\014\\016-\\037
                                                            File size:51544 bytes
                                                            MD5 hash:fbd1402dd9f72d8ebfff00ce7c3a7bb5

                                                            Start time (UTC):16:07:54
                                                            Start date (UTC):23/03/2025
                                                            Path:/usr/bin/dash
                                                            Arguments:-
                                                            File size:129816 bytes
                                                            MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                            Start time (UTC):16:07:54
                                                            Start date (UTC):23/03/2025
                                                            Path:/usr/bin/cut
                                                            Arguments:cut -c -80
                                                            File size:47480 bytes
                                                            MD5 hash:d8ed0ea8f22c0de0f8692d4d9f1759d3

                                                            Start time (UTC):16:07:54
                                                            Start date (UTC):23/03/2025
                                                            Path:/usr/bin/dash
                                                            Arguments:-
                                                            File size:129816 bytes
                                                            MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                            Start time (UTC):16:07:54
                                                            Start date (UTC):23/03/2025
                                                            Path:/usr/bin/cat
                                                            Arguments:cat /tmp/tmp.e0UCmpr0U3
                                                            File size:43416 bytes
                                                            MD5 hash:7e9d213e404ad3bb82e4ebb2e1f2c1b3

                                                            Start time (UTC):16:07:54
                                                            Start date (UTC):23/03/2025
                                                            Path:/usr/bin/dash
                                                            Arguments:-
                                                            File size:129816 bytes
                                                            MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                            Start time (UTC):16:07:54
                                                            Start date (UTC):23/03/2025
                                                            Path:/usr/bin/head
                                                            Arguments:head -n 10
                                                            File size:47480 bytes
                                                            MD5 hash:fd96a67145172477dd57131396fc9608

                                                            Start time (UTC):16:07:54
                                                            Start date (UTC):23/03/2025
                                                            Path:/usr/bin/dash
                                                            Arguments:-
                                                            File size:129816 bytes
                                                            MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                            Start time (UTC):16:07:54
                                                            Start date (UTC):23/03/2025
                                                            Path:/usr/bin/tr
                                                            Arguments:tr -d \\000-\\011\\013\\014\\016-\\037
                                                            File size:51544 bytes
                                                            MD5 hash:fbd1402dd9f72d8ebfff00ce7c3a7bb5

                                                            Start time (UTC):16:07:54
                                                            Start date (UTC):23/03/2025
                                                            Path:/usr/bin/dash
                                                            Arguments:-
                                                            File size:129816 bytes
                                                            MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                            Start time (UTC):16:07:54
                                                            Start date (UTC):23/03/2025
                                                            Path:/usr/bin/cut
                                                            Arguments:cut -c -80
                                                            File size:47480 bytes
                                                            MD5 hash:d8ed0ea8f22c0de0f8692d4d9f1759d3

                                                            Start time (UTC):16:07:54
                                                            Start date (UTC):23/03/2025
                                                            Path:/usr/bin/dash
                                                            Arguments:-
                                                            File size:129816 bytes
                                                            MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                            Start time (UTC):16:07:54
                                                            Start date (UTC):23/03/2025
                                                            Path:/usr/bin/rm
                                                            Arguments:rm -f /tmp/tmp.e0UCmpr0U3 /tmp/tmp.OgOVs4TfJ9 /tmp/tmp.7g0nkV7u2K
                                                            File size:72056 bytes
                                                            MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b

                                                            Start time (UTC):16:07:57
                                                            Start date (UTC):23/03/2025
                                                            Path:/tmp/i686.elf
                                                            Arguments:/tmp/i686.elf
                                                            File size:27580 bytes
                                                            MD5 hash:7be047aad03862b336186f2b4f378b74

                                                            Start time (UTC):16:07:57
                                                            Start date (UTC):23/03/2025
                                                            Path:/tmp/i686.elf
                                                            Arguments:-
                                                            File size:27580 bytes
                                                            MD5 hash:7be047aad03862b336186f2b4f378b74

                                                            Start time (UTC):16:07:57
                                                            Start date (UTC):23/03/2025
                                                            Path:/tmp/i686.elf
                                                            Arguments:-
                                                            File size:27580 bytes
                                                            MD5 hash:7be047aad03862b336186f2b4f378b74

                                                            Start time (UTC):16:07:57
                                                            Start date (UTC):23/03/2025
                                                            Path:/tmp/i686.elf
                                                            Arguments:-
                                                            File size:27580 bytes
                                                            MD5 hash:7be047aad03862b336186f2b4f378b74