Edit tour

Linux Analysis Report
gigab.m68.elf

Overview

General Information

Sample name:gigab.m68.elf
Analysis ID:1646301
MD5:01ad5e4dfd65abf7ff8ea5dcb6b85c1f
SHA1:1fe6c0767238ebb60424a52df545661b8db5e704
SHA256:d5290c6e1d1376765f1395697b2a1b65d79a33bd64ac4c4cf902a2407665431a
Tags:elfuser-abuse_ch
Infos:

Detection

Score:52
Range:0 - 100

Signatures

Multi AV Scanner detection for submitted file
Opens /proc/net/* files useful for finding connected devices and routers
Detected TCP or UDP traffic on non-standard ports
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
Joe Sandbox version:42.0.0 Malachite
Analysis ID:1646301
Start date and time:2025-03-23 20:42:10 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 5m 13s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:gigab.m68.elf
Detection:MAL
Classification:mal52.spre.linELF@0/1@0/0
Command:/tmp/gigab.m68.elf
PID:6221
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:

Standard Error:
  • system is lnxubuntu20
  • gigab.m68.elf (PID: 6221, Parent: 6142, MD5: cd177594338c77b895ae27c33f8f86cc) Arguments: /tmp/gigab.m68.elf
  • cleanup
No yara matches
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: gigab.m68.elfReversingLabs: Detection: 27%

Spreading

barindex
Source: /tmp/gigab.m68.elf (PID: 6221)Opens: /proc/net/routeJump to behavior
Source: global trafficTCP traffic: 192.168.2.23:47546 -> 37.44.238.66:666
Source: global trafficTCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
Source: global trafficTCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
Source: global trafficTCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.66
Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.66
Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.66
Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.66
Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.66
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.66
Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.66
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.66
Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.66
Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.66
Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.66
Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443
Source: classification engineClassification label: mal52.spre.linELF@0/1@0/0
Source: /tmp/gigab.m68.elf (PID: 6221)Queries kernel information via 'uname': Jump to behavior
Source: gigab.m68.elf, 6221.1.00007ffdb270a000.00007ffdb272b000.rw-.sdmp, gigab.m68.elf, 6223.1.00007ffdb270a000.00007ffdb272b000.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-m68k/tmp/gigab.m68.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/gigab.m68.elf
Source: gigab.m68.elf, 6221.1.0000562832afc000.0000562832b60000.rw-.sdmp, gigab.m68.elf, 6223.1.0000562832afc000.0000562832b60000.rw-.sdmpBinary or memory string: 2(V!/etc/qemu-binfmt/m68k
Source: gigab.m68.elf, 6221.1.00007ffdb270a000.00007ffdb272b000.rw-.sdmp, gigab.m68.elf, 6223.1.00007ffdb270a000.00007ffdb272b000.rw-.sdmpBinary or memory string: /usr/bin/qemu-m68k
Source: gigab.m68.elf, 6221.1.00007ffdb270a000.00007ffdb272b000.rw-.sdmpBinary or memory string: /tmp/qemu-open.SqJnpB
Source: gigab.m68.elf, 6221.1.0000562832afc000.0000562832b60000.rw-.sdmp, gigab.m68.elf, 6223.1.0000562832afc000.0000562832b60000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/m68k
Source: gigab.m68.elf, 6221.1.00007ffdb270a000.00007ffdb272b000.rw-.sdmpBinary or memory string: .(V/tmp/qemu-open.SqJnpB\
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath InterceptionDirect Volume AccessOS Credential Dumping11
Security Software Discovery
Remote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS Memory1
Remote System Discovery
Remote Desktop ProtocolData from Removable Media1
Non-Standard Port
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1646301 Sample: gigab.m68.elf Startdate: 23/03/2025 Architecture: LINUX Score: 52 15 109.202.202.202, 80 INIT7CH Switzerland 2->15 17 37.44.238.66, 47546, 666 HARMONYHOSTING-ASFR France 2->17 19 2 other IPs or domains 2->19 21 Multi AV Scanner detection for submitted file 2->21 8 gigab.m68.elf 2->8         started        signatures3 process4 signatures5 23 Opens /proc/net/* files useful for finding connected devices and routers 8->23 11 gigab.m68.elf 8->11         started        process6 process7 13 gigab.m68.elf 11->13         started       
SourceDetectionScannerLabelLink
gigab.m68.elf28%ReversingLabsLinux.Backdoor.Mirai
No Antivirus matches
No Antivirus matches
No Antivirus matches

Download Network PCAP: filteredfull

No contacted domains info
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs
IPDomainCountryFlagASNASN NameMalicious
109.202.202.202
unknownSwitzerland
13030INIT7CHfalse
37.44.238.66
unknownFrance
49434HARMONYHOSTING-ASFRfalse
91.189.91.43
unknownUnited Kingdom
41231CANONICAL-ASGBfalse
91.189.91.42
unknownUnited Kingdom
41231CANONICAL-ASGBfalse
MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
109.202.202.202kpLwzBouH4.elfGet hashmaliciousUnknownBrowse
  • ch.archive.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_92.0%2bbuild3-0ubuntu0.20.04.1_amd64.deb
37.44.238.66gigab.ppc.elfGet hashmaliciousUnknownBrowse
    gigab.arm6.elfGet hashmaliciousUnknownBrowse
      gigab.arm5.elfGet hashmaliciousUnknownBrowse
        gigab.arm4.elfGet hashmaliciousUnknownBrowse
          gigab.sh4.elfGet hashmaliciousUnknownBrowse
            gigab.m68.elfGet hashmaliciousUnknownBrowse
              gigab.arm5.elfGet hashmaliciousUnknownBrowse
                gigab.mips.elfGet hashmaliciousUnknownBrowse
                  gigab.mips.elfGet hashmaliciousGafgytBrowse
                    gigab.spc.elfGet hashmaliciousGafgytBrowse
                      91.189.91.43gigab.ppc.elfGet hashmaliciousUnknownBrowse
                        gigab.arm6.elfGet hashmaliciousUnknownBrowse
                          na.elfGet hashmaliciousPrometeiBrowse
                            gigab.arm5.elfGet hashmaliciousUnknownBrowse
                              na.elfGet hashmaliciousPrometeiBrowse
                                na.elfGet hashmaliciousPrometeiBrowse
                                  gigab.i686.elfGet hashmaliciousUnknownBrowse
                                    gigab.arm4.elfGet hashmaliciousUnknownBrowse
                                      na.elfGet hashmaliciousPrometeiBrowse
                                        na.elfGet hashmaliciousPrometeiBrowse
                                          91.189.91.42gigab.ppc.elfGet hashmaliciousUnknownBrowse
                                            gigab.arm6.elfGet hashmaliciousUnknownBrowse
                                              na.elfGet hashmaliciousPrometeiBrowse
                                                gigab.arm5.elfGet hashmaliciousUnknownBrowse
                                                  na.elfGet hashmaliciousPrometeiBrowse
                                                    na.elfGet hashmaliciousPrometeiBrowse
                                                      gigab.i686.elfGet hashmaliciousUnknownBrowse
                                                        gigab.arm4.elfGet hashmaliciousUnknownBrowse
                                                          na.elfGet hashmaliciousPrometeiBrowse
                                                            na.elfGet hashmaliciousPrometeiBrowse
                                                              No context
                                                              MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                              HARMONYHOSTING-ASFRgigab.ppc.elfGet hashmaliciousUnknownBrowse
                                                              • 37.44.238.66
                                                              gigab.arm6.elfGet hashmaliciousUnknownBrowse
                                                              • 37.44.238.66
                                                              gigab.arm5.elfGet hashmaliciousUnknownBrowse
                                                              • 37.44.238.66
                                                              gigab.arm4.elfGet hashmaliciousUnknownBrowse
                                                              • 37.44.238.66
                                                              gigab.sh4.elfGet hashmaliciousUnknownBrowse
                                                              • 37.44.238.66
                                                              gigab.m68.elfGet hashmaliciousUnknownBrowse
                                                              • 37.44.238.66
                                                              spim.elfGet hashmaliciousMiraiBrowse
                                                              • 37.44.238.92
                                                              686i.elfGet hashmaliciousMiraiBrowse
                                                              • 37.44.238.88
                                                              gigab.arm5.elfGet hashmaliciousUnknownBrowse
                                                              • 37.44.238.66
                                                              gigab.mips.elfGet hashmaliciousUnknownBrowse
                                                              • 37.44.238.66
                                                              CANONICAL-ASGBgigab.ppc.elfGet hashmaliciousUnknownBrowse
                                                              • 91.189.91.42
                                                              gigab.arm6.elfGet hashmaliciousUnknownBrowse
                                                              • 91.189.91.42
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 91.189.91.42
                                                              gigab.arm5.elfGet hashmaliciousUnknownBrowse
                                                              • 91.189.91.42
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 91.189.91.42
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 91.189.91.42
                                                              gigab.i686.elfGet hashmaliciousUnknownBrowse
                                                              • 91.189.91.42
                                                              gigab.arm4.elfGet hashmaliciousUnknownBrowse
                                                              • 91.189.91.42
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 91.189.91.42
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 91.189.91.42
                                                              CANONICAL-ASGBgigab.ppc.elfGet hashmaliciousUnknownBrowse
                                                              • 91.189.91.42
                                                              gigab.arm6.elfGet hashmaliciousUnknownBrowse
                                                              • 91.189.91.42
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 91.189.91.42
                                                              gigab.arm5.elfGet hashmaliciousUnknownBrowse
                                                              • 91.189.91.42
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 91.189.91.42
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 91.189.91.42
                                                              gigab.i686.elfGet hashmaliciousUnknownBrowse
                                                              • 91.189.91.42
                                                              gigab.arm4.elfGet hashmaliciousUnknownBrowse
                                                              • 91.189.91.42
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 91.189.91.42
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 91.189.91.42
                                                              INIT7CHgigab.ppc.elfGet hashmaliciousUnknownBrowse
                                                              • 109.202.202.202
                                                              gigab.arm6.elfGet hashmaliciousUnknownBrowse
                                                              • 109.202.202.202
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 109.202.202.202
                                                              gigab.arm5.elfGet hashmaliciousUnknownBrowse
                                                              • 109.202.202.202
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 109.202.202.202
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 109.202.202.202
                                                              gigab.i686.elfGet hashmaliciousUnknownBrowse
                                                              • 109.202.202.202
                                                              gigab.arm4.elfGet hashmaliciousUnknownBrowse
                                                              • 109.202.202.202
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 109.202.202.202
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 109.202.202.202
                                                              No context
                                                              No context
                                                              Process:/tmp/gigab.m68.elf
                                                              File Type:ASCII text
                                                              Category:dropped
                                                              Size (bytes):230
                                                              Entropy (8bit):3.709552666863289
                                                              Encrypted:false
                                                              SSDEEP:6:iekrEcvwAsE5KlwSd4pzKaV6Lpms/a/1VCxGF:ur+m5MwSdIKaV6L1adVRF
                                                              MD5:2E667F43AE18CD1FE3C108641708A82C
                                                              SHA1:12B90DE2DA0FBCFE66F3D6130905E56C8D6A68D3
                                                              SHA-256:6F721492E7A337C5B498A8F55F5EB7AC745AFF716D0B5B08EFF2C1B6B250F983
                                                              SHA-512:D2A0EE2509154EC1098994F38BE172F98F4150399C534A04D5C675D7C05630802225019F19344CC9070C576BC465A4FEB382AC7712DE6BF25E9244B54A9DB830
                                                              Malicious:false
                                                              Reputation:high, very likely benign file
                                                              Preview:Iface.Destination.Gateway .Flags.RefCnt.Use.Metric.Mask..MTU.Window.IRTT .ens160.00000000.c0a80201.0003.0.0.0.00000000.0.0.0.ens160.c0a80200.00000000.0001.0.0.0.ffffff00.0.0.0.
                                                              File type:ELF 32-bit MSB executable, Motorola m68k, 68020, version 1 (SYSV), statically linked, missing section headers at 89940
                                                              Entropy (8bit):5.973488693838132
                                                              TrID:
                                                              • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                                                              File name:gigab.m68.elf
                                                              File size:86'615 bytes
                                                              MD5:01ad5e4dfd65abf7ff8ea5dcb6b85c1f
                                                              SHA1:1fe6c0767238ebb60424a52df545661b8db5e704
                                                              SHA256:d5290c6e1d1376765f1395697b2a1b65d79a33bd64ac4c4cf902a2407665431a
                                                              SHA512:5fbc2ac4c53acc8a99c0fd49449d758a69e46a16e239e5975d000aabfe67ea71af2573a8d5658af2193d3d80ac59d397a049e6fdcf206e88161754221172777e
                                                              SSDEEP:1536:9t+8nq4xvCQeqacWucW0JcWcBYV3NziLyPbFymFeu8icaqUUfp8v3He3:/qWvCQeqacWucW0JcWcBk3NuMxhRDrMB
                                                              TLSH:AE831AD7FC01EAB6F40AE7370C5348197270F7B10A521A736357366BED3A198186BE86
                                                              File Content Preview:.ELF.......................D...4..]t.....4. ...(......................N...N....... .......N...n...n.......i....... .dt.Q............................NV..a....da...4.N^NuNV..J9..p.f>"y..n$ QJ.g.X.#...n$N."y..n$ QJ.f.A.....J.g.Hy..n.N.X.......p.N^NuNV..N^NuN

                                                              Download Network PCAP: filteredfull

                                                              • Total Packets: 18
                                                              • 666 undefined
                                                              • 443 (HTTPS)
                                                              • 80 (HTTP)
                                                              TimestampSource PortDest PortSource IPDest IP
                                                              Mar 23, 2025 20:42:54.161809921 CET43928443192.168.2.2391.189.91.42
                                                              Mar 23, 2025 20:42:55.988910913 CET47546666192.168.2.2337.44.238.66
                                                              Mar 23, 2025 20:42:56.192498922 CET6664754637.44.238.66192.168.2.23
                                                              Mar 23, 2025 20:42:56.192591906 CET47546666192.168.2.2337.44.238.66
                                                              Mar 23, 2025 20:42:57.009582996 CET47546666192.168.2.2337.44.238.66
                                                              Mar 23, 2025 20:42:57.212961912 CET6664754637.44.238.66192.168.2.23
                                                              Mar 23, 2025 20:42:57.213378906 CET47546666192.168.2.2337.44.238.66
                                                              Mar 23, 2025 20:42:57.215313911 CET47546666192.168.2.2337.44.238.66
                                                              Mar 23, 2025 20:42:57.420939922 CET6664754637.44.238.66192.168.2.23
                                                              Mar 23, 2025 20:42:59.793164968 CET42836443192.168.2.2391.189.91.43
                                                              Mar 23, 2025 20:43:00.561047077 CET4251680192.168.2.23109.202.202.202
                                                              Mar 23, 2025 20:43:14.127383947 CET43928443192.168.2.2391.189.91.42
                                                              Mar 23, 2025 20:43:26.413685083 CET42836443192.168.2.2391.189.91.43
                                                              Mar 23, 2025 20:43:30.509067059 CET4251680192.168.2.23109.202.202.202
                                                              Mar 23, 2025 20:43:54.608104944 CET6664754637.44.238.66192.168.2.23
                                                              Mar 23, 2025 20:43:54.609096050 CET47546666192.168.2.2337.44.238.66
                                                              Mar 23, 2025 20:43:54.818406105 CET6664754637.44.238.66192.168.2.23
                                                              Mar 23, 2025 20:43:54.818861008 CET47546666192.168.2.2337.44.238.66
                                                              Mar 23, 2025 20:43:55.081572056 CET43928443192.168.2.2391.189.91.42
                                                              Mar 23, 2025 20:44:54.614403009 CET6664754637.44.238.66192.168.2.23
                                                              Mar 23, 2025 20:44:54.614742041 CET47546666192.168.2.2337.44.238.66
                                                              Mar 23, 2025 20:44:54.819224119 CET6664754637.44.238.66192.168.2.23
                                                              Mar 23, 2025 20:44:54.819582939 CET47546666192.168.2.2337.44.238.66
                                                              Mar 23, 2025 20:45:54.628336906 CET6664754637.44.238.66192.168.2.23
                                                              Mar 23, 2025 20:45:54.628660917 CET47546666192.168.2.2337.44.238.66
                                                              Mar 23, 2025 20:45:54.832496881 CET6664754637.44.238.66192.168.2.23
                                                              Mar 23, 2025 20:45:54.832791090 CET47546666192.168.2.2337.44.238.66

                                                              System Behavior

                                                              Start time (UTC):19:42:54
                                                              Start date (UTC):23/03/2025
                                                              Path:/tmp/gigab.m68.elf
                                                              Arguments:/tmp/gigab.m68.elf
                                                              File size:4463432 bytes
                                                              MD5 hash:cd177594338c77b895ae27c33f8f86cc

                                                              Start time (UTC):19:42:54
                                                              Start date (UTC):23/03/2025
                                                              Path:/tmp/gigab.m68.elf
                                                              Arguments:-
                                                              File size:4463432 bytes
                                                              MD5 hash:cd177594338c77b895ae27c33f8f86cc

                                                              Start time (UTC):19:42:54
                                                              Start date (UTC):23/03/2025
                                                              Path:/tmp/gigab.m68.elf
                                                              Arguments:-
                                                              File size:4463432 bytes
                                                              MD5 hash:cd177594338c77b895ae27c33f8f86cc