Edit tour

Linux Analysis Report
arm7.elf

Overview

General Information

Sample name:arm7.elf
Analysis ID:1646504
MD5:c670de311370466db2545b6580d70ff2
SHA1:6a03e099c10826c7bc5c7a39bd8601d496980c0d
SHA256:6826078f8cbd788468eadcde4030cfef90c6cc7f0096d56a75b7de0ec4b8f357
Tags:elfuser-abuse_ch
Infos:

Detection

Score:52
Range:0 - 100

Signatures

Multi AV Scanner detection for submitted file
Uses STUN server to do NAT traversial
Detected TCP or UDP traffic on non-standard ports
Enumerates processes within the "proc" file system
Executes the "rm" command used to delete files or directories
Sample has stripped symbol table
Sample listens on a socket
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
Joe Sandbox version:42.0.0 Malachite
Analysis ID:1646504
Start date and time:2025-03-24 04:32:50 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 42s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:arm7.elf
Detection:MAL
Classification:mal52.troj.linELF@0/2@1/0
Command:/tmp/arm7.elf
PID:6231
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
For God so loved the world
Standard Error:
  • system is lnxubuntu20
  • arm7.elf (PID: 6231, Parent: 6151, MD5: 5ebfcae4fe2471fcc5695c2394773ff1) Arguments: /tmp/arm7.elf
    • arm7.elf New Fork (PID: 6233, Parent: 6231)
  • dash New Fork (PID: 6310, Parent: 4331)
  • rm (PID: 6310, Parent: 4331, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.UdanZs6GZ6 /tmp/tmp.p8VtV423LG /tmp/tmp.gFwVK4QLXR
  • dash New Fork (PID: 6311, Parent: 4331)
  • rm (PID: 6311, Parent: 4331, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.UdanZs6GZ6 /tmp/tmp.p8VtV423LG /tmp/tmp.gFwVK4QLXR
  • cleanup
No yara matches
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: arm7.elfReversingLabs: Detection: 16%

Networking

barindex
Source: unknownDNS query: name: stun.l.google.com
Source: global trafficTCP traffic: 192.168.2.23:47816 -> 104.245.241.61:46164
Source: global trafficUDP traffic: 192.168.2.23:49272 -> 74.125.250.129:19302
Source: /tmp/arm7.elf (PID: 6233)Socket: 127.0.0.1:22448Jump to behavior
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 104.245.241.61
Source: unknownTCP traffic detected without corresponding DNS query: 104.245.241.61
Source: unknownTCP traffic detected without corresponding DNS query: 104.245.241.61
Source: unknownTCP traffic detected without corresponding DNS query: 104.245.241.61
Source: unknownTCP traffic detected without corresponding DNS query: 104.245.241.61
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 104.245.241.61
Source: unknownTCP traffic detected without corresponding DNS query: 34.249.145.219
Source: unknownTCP traffic detected without corresponding DNS query: 34.249.145.219
Source: unknownTCP traffic detected without corresponding DNS query: 34.249.145.219
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 104.245.241.61
Source: unknownTCP traffic detected without corresponding DNS query: 104.245.241.61
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 104.245.241.61
Source: unknownTCP traffic detected without corresponding DNS query: 104.245.241.61
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 104.245.241.61
Source: unknownTCP traffic detected without corresponding DNS query: 104.245.241.61
Source: unknownTCP traffic detected without corresponding DNS query: 34.249.145.219
Source: unknownTCP traffic detected without corresponding DNS query: 104.245.241.61
Source: unknownTCP traffic detected without corresponding DNS query: 104.245.241.61
Source: unknownTCP traffic detected without corresponding DNS query: 104.245.241.61
Source: unknownTCP traffic detected without corresponding DNS query: 104.245.241.61
Source: unknownTCP traffic detected without corresponding DNS query: 104.245.241.61
Source: global trafficDNS traffic detected: DNS query: stun.l.google.com
Source: arm7.elf, 6231.1.00007f0c98035000.00007f0c9803f000.rw-.sdmpString found in binary or memory: http://17365637265742070617373776F7264206D656D6F721/t/wget.sh
Source: arm7.elf, 6231.1.00007f0c98035000.00007f0c9803f000.rw-.sdmpString found in binary or memory: https://motd.ubuntu.com
Source: arm7.elf, 6231.1.00007f0c98035000.00007f0c9803f000.rw-.sdmpString found in binary or memory: https://motd.ubuntu.comhe
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39250
Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 39250 -> 443
Source: ELF static info symbol of initial sample.symtab present: no
Source: classification engineClassification label: mal52.troj.linELF@0/2@1/0
Source: /tmp/arm7.elf (PID: 6231)File opened: /proc/1582/cmdlineJump to behavior
Source: /tmp/arm7.elf (PID: 6231)File opened: /proc/3088/cmdlineJump to behavior
Source: /tmp/arm7.elf (PID: 6231)File opened: /proc/230/cmdlineJump to behavior
Source: /tmp/arm7.elf (PID: 6231)File opened: /proc/110/cmdlineJump to behavior
Source: /tmp/arm7.elf (PID: 6231)File opened: /proc/231/cmdlineJump to behavior
Source: /tmp/arm7.elf (PID: 6231)File opened: /proc/111/cmdlineJump to behavior
Source: /tmp/arm7.elf (PID: 6231)File opened: /proc/232/cmdlineJump to behavior
Source: /tmp/arm7.elf (PID: 6231)File opened: /proc/1579/cmdlineJump to behavior
Source: /tmp/arm7.elf (PID: 6231)File opened: /proc/112/cmdlineJump to behavior
Source: /tmp/arm7.elf (PID: 6231)File opened: /proc/233/cmdlineJump to behavior
Source: /tmp/arm7.elf (PID: 6231)File opened: /proc/1699/cmdlineJump to behavior
Source: /tmp/arm7.elf (PID: 6231)File opened: /proc/113/cmdlineJump to behavior
Source: /tmp/arm7.elf (PID: 6231)File opened: /proc/234/cmdlineJump to behavior
Source: /tmp/arm7.elf (PID: 6231)File opened: /proc/1335/cmdlineJump to behavior
Source: /tmp/arm7.elf (PID: 6231)File opened: /proc/1698/cmdlineJump to behavior
Source: /tmp/arm7.elf (PID: 6231)File opened: /proc/114/cmdlineJump to behavior
Source: /tmp/arm7.elf (PID: 6231)File opened: /proc/235/cmdlineJump to behavior
Source: /tmp/arm7.elf (PID: 6231)File opened: /proc/1334/cmdlineJump to behavior
Source: /tmp/arm7.elf (PID: 6231)File opened: /proc/1576/cmdlineJump to behavior
Source: /tmp/arm7.elf (PID: 6231)File opened: /proc/2302/cmdlineJump to behavior
Source: /tmp/arm7.elf (PID: 6231)File opened: /proc/115/cmdlineJump to behavior
Source: /tmp/arm7.elf (PID: 6231)File opened: /proc/236/cmdlineJump to behavior
Source: /tmp/arm7.elf (PID: 6231)File opened: /proc/116/cmdlineJump to behavior
Source: /tmp/arm7.elf (PID: 6231)File opened: /proc/237/cmdlineJump to behavior
Source: /tmp/arm7.elf (PID: 6231)File opened: /proc/117/cmdlineJump to behavior
Source: /tmp/arm7.elf (PID: 6231)File opened: /proc/118/cmdlineJump to behavior
Source: /tmp/arm7.elf (PID: 6231)File opened: /proc/910/cmdlineJump to behavior
Source: /tmp/arm7.elf (PID: 6231)File opened: /proc/119/cmdlineJump to behavior
Source: /tmp/arm7.elf (PID: 6231)File opened: /proc/912/cmdlineJump to behavior
Source: /tmp/arm7.elf (PID: 6231)File opened: /proc/10/cmdlineJump to behavior
Source: /tmp/arm7.elf (PID: 6231)File opened: /proc/2307/cmdlineJump to behavior
Source: /tmp/arm7.elf (PID: 6231)File opened: /proc/11/cmdlineJump to behavior
Source: /tmp/arm7.elf (PID: 6231)File opened: /proc/918/cmdlineJump to behavior
Source: /tmp/arm7.elf (PID: 6231)File opened: /proc/12/cmdlineJump to behavior
Source: /tmp/arm7.elf (PID: 6231)File opened: /proc/13/cmdlineJump to behavior
Source: /tmp/arm7.elf (PID: 6231)File opened: /proc/14/cmdlineJump to behavior
Source: /tmp/arm7.elf (PID: 6231)File opened: /proc/15/cmdlineJump to behavior
Source: /tmp/arm7.elf (PID: 6231)File opened: /proc/16/cmdlineJump to behavior
Source: /tmp/arm7.elf (PID: 6231)File opened: /proc/17/cmdlineJump to behavior
Source: /tmp/arm7.elf (PID: 6231)File opened: /proc/18/cmdlineJump to behavior
Source: /tmp/arm7.elf (PID: 6231)File opened: /proc/1594/cmdlineJump to behavior
Source: /tmp/arm7.elf (PID: 6231)File opened: /proc/120/cmdlineJump to behavior
Source: /tmp/arm7.elf (PID: 6231)File opened: /proc/121/cmdlineJump to behavior
Source: /tmp/arm7.elf (PID: 6231)File opened: /proc/1349/cmdlineJump to behavior
Source: /tmp/arm7.elf (PID: 6231)File opened: /proc/1/cmdlineJump to behavior
Source: /tmp/arm7.elf (PID: 6231)File opened: /proc/122/cmdlineJump to behavior
Source: /tmp/arm7.elf (PID: 6231)File opened: /proc/243/cmdlineJump to behavior
Source: /tmp/arm7.elf (PID: 6231)File opened: /proc/123/cmdlineJump to behavior
Source: /tmp/arm7.elf (PID: 6231)File opened: /proc/2/cmdlineJump to behavior
Source: /tmp/arm7.elf (PID: 6231)File opened: /proc/124/cmdlineJump to behavior
Source: /tmp/arm7.elf (PID: 6231)File opened: /proc/3/cmdlineJump to behavior
Source: /tmp/arm7.elf (PID: 6231)File opened: /proc/4/cmdlineJump to behavior
Source: /tmp/arm7.elf (PID: 6231)File opened: /proc/125/cmdlineJump to behavior
Source: /tmp/arm7.elf (PID: 6231)File opened: /proc/126/cmdlineJump to behavior
Source: /tmp/arm7.elf (PID: 6231)File opened: /proc/1344/cmdlineJump to behavior
Source: /tmp/arm7.elf (PID: 6231)File opened: /proc/1465/cmdlineJump to behavior
Source: /tmp/arm7.elf (PID: 6231)File opened: /proc/1586/cmdlineJump to behavior
Source: /tmp/arm7.elf (PID: 6231)File opened: /proc/127/cmdlineJump to behavior
Source: /tmp/arm7.elf (PID: 6231)File opened: /proc/6/cmdlineJump to behavior
Source: /tmp/arm7.elf (PID: 6231)File opened: /proc/248/cmdlineJump to behavior
Source: /tmp/arm7.elf (PID: 6231)File opened: /proc/128/cmdlineJump to behavior
Source: /tmp/arm7.elf (PID: 6231)File opened: /proc/249/cmdlineJump to behavior
Source: /tmp/arm7.elf (PID: 6231)File opened: /proc/1463/cmdlineJump to behavior
Source: /tmp/arm7.elf (PID: 6231)File opened: /proc/800/cmdlineJump to behavior
Source: /tmp/arm7.elf (PID: 6231)File opened: /proc/9/cmdlineJump to behavior
Source: /tmp/arm7.elf (PID: 6231)File opened: /proc/801/cmdlineJump to behavior
Source: /tmp/arm7.elf (PID: 6231)File opened: /proc/20/cmdlineJump to behavior
Source: /tmp/arm7.elf (PID: 6231)File opened: /proc/21/cmdlineJump to behavior
Source: /tmp/arm7.elf (PID: 6231)File opened: /proc/1900/cmdlineJump to behavior
Source: /tmp/arm7.elf (PID: 6231)File opened: /proc/22/cmdlineJump to behavior
Source: /tmp/arm7.elf (PID: 6231)File opened: /proc/23/cmdlineJump to behavior
Source: /tmp/arm7.elf (PID: 6231)File opened: /proc/24/cmdlineJump to behavior
Source: /tmp/arm7.elf (PID: 6231)File opened: /proc/25/cmdlineJump to behavior
Source: /tmp/arm7.elf (PID: 6231)File opened: /proc/26/cmdlineJump to behavior
Source: /tmp/arm7.elf (PID: 6231)File opened: /proc/27/cmdlineJump to behavior
Source: /tmp/arm7.elf (PID: 6231)File opened: /proc/28/cmdlineJump to behavior
Source: /tmp/arm7.elf (PID: 6231)File opened: /proc/29/cmdlineJump to behavior
Source: /tmp/arm7.elf (PID: 6231)File opened: /proc/491/cmdlineJump to behavior
Source: /tmp/arm7.elf (PID: 6231)File opened: /proc/250/cmdlineJump to behavior
Source: /tmp/arm7.elf (PID: 6231)File opened: /proc/130/cmdlineJump to behavior
Source: /tmp/arm7.elf (PID: 6231)File opened: /proc/251/cmdlineJump to behavior
Source: /tmp/arm7.elf (PID: 6231)File opened: /proc/252/cmdlineJump to behavior
Source: /tmp/arm7.elf (PID: 6231)File opened: /proc/132/cmdlineJump to behavior
Source: /tmp/arm7.elf (PID: 6231)File opened: /proc/253/cmdlineJump to behavior
Source: /tmp/arm7.elf (PID: 6231)File opened: /proc/254/cmdlineJump to behavior
Source: /tmp/arm7.elf (PID: 6231)File opened: /proc/255/cmdlineJump to behavior
Source: /tmp/arm7.elf (PID: 6231)File opened: /proc/4509/cmdlineJump to behavior
Source: /tmp/arm7.elf (PID: 6231)File opened: /proc/256/cmdlineJump to behavior
Source: /tmp/arm7.elf (PID: 6231)File opened: /proc/1599/cmdlineJump to behavior
Source: /tmp/arm7.elf (PID: 6231)File opened: /proc/257/cmdlineJump to behavior
Source: /tmp/arm7.elf (PID: 6231)File opened: /proc/1477/cmdlineJump to behavior
Source: /tmp/arm7.elf (PID: 6231)File opened: /proc/379/cmdlineJump to behavior
Source: /tmp/arm7.elf (PID: 6231)File opened: /proc/258/cmdlineJump to behavior
Source: /tmp/arm7.elf (PID: 6231)File opened: /proc/1476/cmdlineJump to behavior
Source: /tmp/arm7.elf (PID: 6231)File opened: /proc/259/cmdlineJump to behavior
Source: /tmp/arm7.elf (PID: 6231)File opened: /proc/1475/cmdlineJump to behavior
Source: /tmp/arm7.elf (PID: 6231)File opened: /proc/936/cmdlineJump to behavior
Source: /tmp/arm7.elf (PID: 6231)File opened: /proc/30/cmdlineJump to behavior
Source: /tmp/arm7.elf (PID: 6231)File opened: /proc/2208/cmdlineJump to behavior
Source: /tmp/arm7.elf (PID: 6231)File opened: /proc/35/cmdlineJump to behavior
Source: /tmp/arm7.elf (PID: 6231)File opened: /proc/1809/cmdlineJump to behavior
Source: /tmp/arm7.elf (PID: 6231)File opened: /proc/1494/cmdlineJump to behavior
Source: /tmp/arm7.elf (PID: 6231)File opened: /proc/260/cmdlineJump to behavior
Source: /tmp/arm7.elf (PID: 6231)File opened: /proc/261/cmdlineJump to behavior
Source: /tmp/arm7.elf (PID: 6231)File opened: /proc/141/cmdlineJump to behavior
Source: /usr/bin/dash (PID: 6310)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.UdanZs6GZ6 /tmp/tmp.p8VtV423LG /tmp/tmp.gFwVK4QLXRJump to behavior
Source: /usr/bin/dash (PID: 6311)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.UdanZs6GZ6 /tmp/tmp.p8VtV423LG /tmp/tmp.gFwVK4QLXRJump to behavior
Source: /tmp/arm7.elf (PID: 6231)Queries kernel information via 'uname': Jump to behavior
Source: arm7.elf, 6231.1.00007f0c98035000.00007f0c9803f000.rw-.sdmpBinary or memory string: vmwarem
Source: arm7.elf, 6231.1.00007f0c98035000.00007f0c9803f000.rw-.sdmpBinary or memory string: vmware
Source: arm7.elf, 6231.1.000055f694fcf000.000055f69511e000.rw-.sdmpBinary or memory string: U!/etc/qemu-binfmt/arm
Source: arm7.elf, 6231.1.00007f0c98035000.00007f0c9803f000.rw-.sdmpBinary or memory string: qemu-arm
Source: arm7.elf, 6231.1.00007ffed7ff3000.00007ffed8014000.rw-.sdmpBinary or memory string: /tmp/qemu-open.wcuzkl
Source: arm7.elf, 6231.1.00007f0c98035000.00007f0c9803f000.rw-.sdmpBinary or memory string: qemu-arm)Zm6vnZ5U4mf8vApyWcDwXR44ZAkzslsN)
Source: arm7.elf, 6231.1.000055f694fcf000.000055f69511e000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/arm
Source: arm7.elf, 6231.1.00007ffed7ff3000.00007ffed8014000.rw-.sdmpBinary or memory string: /usr/bin/qemu-arm
Source: arm7.elf, 6231.1.00007ffed7ff3000.00007ffed8014000.rw-.sdmpBinary or memory string: U/tmp/qemu-open.wcuzkl:
Source: arm7.elf, 6231.1.00007ffed7ff3000.00007ffed8014000.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-arm/tmp/arm7.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/arm7.elf
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception1
File Deletion
1
OS Credential Dumping
11
Security Software Discovery
Remote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Non-Standard Port
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
Non-Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture2
Application Layer Protocol
Traffic DuplicationData Destruction
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1646504 Sample: arm7.elf Startdate: 24/03/2025 Architecture: LINUX Score: 52 15 stun.l.google.com 2->15 17 109.202.202.202, 80 INIT7CH Switzerland 2->17 19 5 other IPs or domains 2->19 21 Multi AV Scanner detection for submitted file 2->21 7 arm7.elf 2->7         started        9 dash rm 2->9         started        11 dash rm 2->11         started        signatures3 23 Uses STUN server to do NAT traversial 15->23 process4 process5 13 arm7.elf 7->13         started       
SourceDetectionScannerLabelLink
arm7.elf17%ReversingLabsLinux.Backdoor.Mirai
No Antivirus matches
No Antivirus matches
No Antivirus matches

Download Network PCAP: filteredfull

NameIPActiveMaliciousAntivirus DetectionReputation
stun.l.google.com
74.125.250.129
truefalse
    high
    NameSourceMaliciousAntivirus DetectionReputation
    https://motd.ubuntu.comarm7.elf, 6231.1.00007f0c98035000.00007f0c9803f000.rw-.sdmpfalse
      high
      https://motd.ubuntu.comhearm7.elf, 6231.1.00007f0c98035000.00007f0c9803f000.rw-.sdmpfalse
        high
        http://17365637265742070617373776F7264206D656D6F721/t/wget.sharm7.elf, 6231.1.00007f0c98035000.00007f0c9803f000.rw-.sdmpfalse
          high
          • No. of IPs < 25%
          • 25% < No. of IPs < 50%
          • 50% < No. of IPs < 75%
          • 75% < No. of IPs
          IPDomainCountryFlagASNASN NameMalicious
          34.249.145.219
          unknownUnited States
          16509AMAZON-02USfalse
          104.245.241.61
          unknownUnited States
          8100ASN-QUADRANET-GLOBALUSfalse
          109.202.202.202
          unknownSwitzerland
          13030INIT7CHfalse
          74.125.250.129
          stun.l.google.comUnited States
          15169GOOGLEUSfalse
          91.189.91.43
          unknownUnited Kingdom
          41231CANONICAL-ASGBfalse
          91.189.91.42
          unknownUnited Kingdom
          41231CANONICAL-ASGBfalse
          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
          34.249.145.219aarch64.elfGet hashmaliciousMiraiBrowse
            na.elfGet hashmaliciousPrometeiBrowse
              na.elfGet hashmaliciousPrometeiBrowse
                arc.elfGet hashmaliciousMiraiBrowse
                  na.elfGet hashmaliciousPrometeiBrowse
                    na.elfGet hashmaliciousPrometeiBrowse
                      m68k.elfGet hashmaliciousMiraiBrowse
                        parm5.elfGet hashmaliciousUnknownBrowse
                          na.elfGet hashmaliciousPrometeiBrowse
                            na.elfGet hashmaliciousPrometeiBrowse
                              104.245.241.61mips.elfGet hashmaliciousUnknownBrowse
                                109.202.202.202kpLwzBouH4.elfGet hashmaliciousUnknownBrowse
                                • ch.archive.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_92.0%2bbuild3-0ubuntu0.20.04.1_amd64.deb
                                91.189.91.43morte.arm6.elfGet hashmaliciousGafgyt, OkiruBrowse
                                  aarch64.elfGet hashmaliciousMiraiBrowse
                                    morte.ppc.elfGet hashmaliciousOkiruBrowse
                                      na.elfGet hashmaliciousPrometeiBrowse
                                        gigab.ppc.elfGet hashmaliciousUnknownBrowse
                                          gigab.sh4.elfGet hashmaliciousUnknownBrowse
                                            na.elfGet hashmaliciousPrometeiBrowse
                                              na.elfGet hashmaliciousPrometeiBrowse
                                                na.elfGet hashmaliciousPrometeiBrowse
                                                  arc.elfGet hashmaliciousMiraiBrowse
                                                    91.189.91.42morte.arm6.elfGet hashmaliciousGafgyt, OkiruBrowse
                                                      aarch64.elfGet hashmaliciousMiraiBrowse
                                                        morte.ppc.elfGet hashmaliciousOkiruBrowse
                                                          na.elfGet hashmaliciousPrometeiBrowse
                                                            gigab.ppc.elfGet hashmaliciousUnknownBrowse
                                                              gigab.sh4.elfGet hashmaliciousUnknownBrowse
                                                                na.elfGet hashmaliciousPrometeiBrowse
                                                                  na.elfGet hashmaliciousPrometeiBrowse
                                                                    na.elfGet hashmaliciousPrometeiBrowse
                                                                      arc.elfGet hashmaliciousMiraiBrowse
                                                                        No context
                                                                        MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                        CANONICAL-ASGBmorte.arm6.elfGet hashmaliciousGafgyt, OkiruBrowse
                                                                        • 91.189.91.42
                                                                        aarch64.elfGet hashmaliciousMiraiBrowse
                                                                        • 91.189.91.42
                                                                        morte.ppc.elfGet hashmaliciousOkiruBrowse
                                                                        • 91.189.91.42
                                                                        na.elfGet hashmaliciousPrometeiBrowse
                                                                        • 91.189.91.42
                                                                        gigab.ppc.elfGet hashmaliciousUnknownBrowse
                                                                        • 91.189.91.42
                                                                        gigab.sh4.elfGet hashmaliciousUnknownBrowse
                                                                        • 91.189.91.42
                                                                        na.elfGet hashmaliciousPrometeiBrowse
                                                                        • 91.189.91.42
                                                                        na.elfGet hashmaliciousPrometeiBrowse
                                                                        • 91.189.91.42
                                                                        na.elfGet hashmaliciousPrometeiBrowse
                                                                        • 91.189.91.42
                                                                        arc.elfGet hashmaliciousMiraiBrowse
                                                                        • 91.189.91.42
                                                                        ASN-QUADRANET-GLOBALUSmips.elfGet hashmaliciousUnknownBrowse
                                                                        • 104.245.241.61
                                                                        ARxx7NW.exeGet hashmaliciousXmrigBrowse
                                                                        • 104.245.241.161
                                                                        .main.elfGet hashmaliciousXmrigBrowse
                                                                        • 104.245.240.20
                                                                        wjfOfXh.exe1.exeGet hashmaliciousUnknownBrowse
                                                                        • 45.95.233.53
                                                                        socks.exeGet hashmaliciousSliverBrowse
                                                                        • 45.61.169.127
                                                                        2mtls.exeGet hashmaliciousSliverBrowse
                                                                        • 45.61.169.127
                                                                        1https.exeGet hashmaliciousSliverBrowse
                                                                        • 45.61.169.127
                                                                        http://t.dripemail2.com/c/eyJhbGciOiJIUzI1NiJ9.eyJhdWQiOiJkZXRvdXIiLCJpc3MiOiJtb25vbGl0aCIsInN1YiI6ImRldG91cl9saW5rIiwiaWF0IjoxNzQyNDg1MjAxLCJuYmYiOjE3NDI0ODUyMDEsImFjY291bnRfaWQiOiI5MjExNzMxIiwiZGVsaXZlcnlfaWQiOiI2ZGY2cmIydXVwbjY4cnNhdWo0NCIsInRva2VuIjoiNmRmNnJiMnV1cG42OHJzYXVqNDQiLCJzZW5kX2F0IjoxNzQyNDgzOTQ4LCJlbWFpbF9pZCI6MTA1MDc4ODcsImVtYWlsYWJsZV90eXBlIjoiQnJvYWRjYXN0IiwiZW1haWxhYmxlX2lkIjo0MTkzMDc4LCJ1cmwiOiJodHRwOi8vZ2NyLnVwcGxleC5jby5rZT9fX3M9cWMwZ2JsdTk1emZnYmh3ZHp5OG4mdXRtX3NvdXJjZT1kcmlwJnV0bV9tZWRpdW09ZW1haWwmdXRtX2NhbXBhaWduPVdlK2dvdCthK21ha2VvdmVyLiJ9.nJ9tzd3-jhbWgSNwRLHamHKYwZXuNcZIG2E1QBFM5fgGet hashmaliciousHTMLPhisherBrowse
                                                                        • 45.61.169.110
                                                                        ATT11027.xhtmlGet hashmaliciousHTMLPhisherBrowse
                                                                        • 185.174.100.76
                                                                        http://url5681.planter.eco/ls/click?upn=u001.PX1-2BssefkOe686e7wTSUMqibxN-2FCUadbAKgpTv23cYOIQxMvH9FGLuwPON-2Ft4V08mI3EhMVAoZnU-2Br4hRroTgY6212B0nGnr8aV-2B5ZtDZ10DmDDkH6mdlmAzG8M-2BiNsGPGMX1iPzlrrdaY9R4kk4qHfVergkdfGzm-2BAmGL-2FwYqLpCth-2FU-2ByXRztop6mHKwMCk43gAzvI9DCKmBcEcJQKyQ-3D-3Da5U3_GwWzR5CPD3uhhoxi7nJtY0-2BQC5TKRtJEXtldUtgGNIU9EPMkwXhPBMhFexKYRqOhYUH1k-2FQVOT9D8S6mnbGzOTVeFZqZ2eiXdrD6GdHPzzO106h29UdS-2BIz4v5acd9FnatQanlGtMNJsbvRJRS5dF6-2BMeTnNy39wilhlMfgiqmmr792hlZiyIO30hIfNO7fmE4Qvw7CYEB9aPKMoYkpeVA-3D-3DGet hashmaliciousHTMLPhisherBrowse
                                                                        • 104.245.240.188
                                                                        INIT7CHmorte.arm6.elfGet hashmaliciousGafgyt, OkiruBrowse
                                                                        • 109.202.202.202
                                                                        aarch64.elfGet hashmaliciousMiraiBrowse
                                                                        • 109.202.202.202
                                                                        morte.ppc.elfGet hashmaliciousOkiruBrowse
                                                                        • 109.202.202.202
                                                                        na.elfGet hashmaliciousPrometeiBrowse
                                                                        • 109.202.202.202
                                                                        gigab.ppc.elfGet hashmaliciousUnknownBrowse
                                                                        • 109.202.202.202
                                                                        gigab.sh4.elfGet hashmaliciousUnknownBrowse
                                                                        • 109.202.202.202
                                                                        na.elfGet hashmaliciousPrometeiBrowse
                                                                        • 109.202.202.202
                                                                        na.elfGet hashmaliciousPrometeiBrowse
                                                                        • 109.202.202.202
                                                                        na.elfGet hashmaliciousPrometeiBrowse
                                                                        • 109.202.202.202
                                                                        arc.elfGet hashmaliciousMiraiBrowse
                                                                        • 109.202.202.202
                                                                        AMAZON-02USSecuriteInfo.com.Win64.CrypterX-gen.5834.27621.exeGet hashmaliciousVidarBrowse
                                                                        • 108.138.128.112
                                                                        aarch64.elfGet hashmaliciousMiraiBrowse
                                                                        • 34.249.145.219
                                                                        resgod.arm5.elfGet hashmaliciousMiraiBrowse
                                                                        • 54.77.209.255
                                                                        na.elfGet hashmaliciousPrometeiBrowse
                                                                        • 52.43.119.120
                                                                        na.elfGet hashmaliciousPrometeiBrowse
                                                                        • 54.247.62.1
                                                                        resgod.spc.elfGet hashmaliciousMiraiBrowse
                                                                        • 52.47.230.234
                                                                        na.elfGet hashmaliciousPrometeiBrowse
                                                                        • 52.43.119.120
                                                                        https://steigerwaldt.com/Get hashmaliciousUnknownBrowse
                                                                        • 13.226.94.10
                                                                        na.elfGet hashmaliciousPrometeiBrowse
                                                                        • 52.43.119.120
                                                                        na.elfGet hashmaliciousPrometeiBrowse
                                                                        • 52.43.119.120
                                                                        No context
                                                                        No context
                                                                        Process:/tmp/arm7.elf
                                                                        File Type:data
                                                                        Category:dropped
                                                                        Size (bytes):14
                                                                        Entropy (8bit):3.521640636343319
                                                                        Encrypted:false
                                                                        SSDEEP:3:TgiLG:TgiC
                                                                        MD5:451AC90F7FA61D0393D6A5A02158D369
                                                                        SHA1:5A7D458802462B80F94A9CDA24E2C877437A8E34
                                                                        SHA-256:E2D543300D643CEF7698E750F74E8499993E346EF765FA2061EB5DFAF8D77E48
                                                                        SHA-512:EF1D000F5B8BB5AFD4F6CB347FBE0FA0E97608B8C3839B6B44CB9828E5522396B334AE37148FCD2064A423B3DDD0C8874EF7019023A84B36E3893E50353F06FE
                                                                        Malicious:false
                                                                        Reputation:moderate, very likely benign file
                                                                        Preview:/tmp/arm7.elf.
                                                                        Process:/tmp/arm7.elf
                                                                        File Type:data
                                                                        Category:dropped
                                                                        Size (bytes):14
                                                                        Entropy (8bit):3.521640636343319
                                                                        Encrypted:false
                                                                        SSDEEP:3:TgiLG:TgiC
                                                                        MD5:451AC90F7FA61D0393D6A5A02158D369
                                                                        SHA1:5A7D458802462B80F94A9CDA24E2C877437A8E34
                                                                        SHA-256:E2D543300D643CEF7698E750F74E8499993E346EF765FA2061EB5DFAF8D77E48
                                                                        SHA-512:EF1D000F5B8BB5AFD4F6CB347FBE0FA0E97608B8C3839B6B44CB9828E5522396B334AE37148FCD2064A423B3DDD0C8874EF7019023A84B36E3893E50353F06FE
                                                                        Malicious:false
                                                                        Reputation:moderate, very likely benign file
                                                                        Preview:/tmp/arm7.elf.
                                                                        File type:ELF 32-bit LSB executable, ARM, EABI4 version 1 (SYSV), statically linked, stripped
                                                                        Entropy (8bit):6.099244986194891
                                                                        TrID:
                                                                        • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                                                                        File name:arm7.elf
                                                                        File size:88'528 bytes
                                                                        MD5:c670de311370466db2545b6580d70ff2
                                                                        SHA1:6a03e099c10826c7bc5c7a39bd8601d496980c0d
                                                                        SHA256:6826078f8cbd788468eadcde4030cfef90c6cc7f0096d56a75b7de0ec4b8f357
                                                                        SHA512:0e04f9015e0603e66e592f14b2e912a5b5fdd6076d8d099ae7629bd7463b5ca7e6463a1da1adf5a08af6a79e2885a5c6cb88e41cc184f04b2ab9cc2b6c76b4c6
                                                                        SSDEEP:1536:J7nwUOfSwvszt+nH4ghA8niiANaacZ/YAcNpAylCSiSOgSn9/OY79yrE:OLqwvszt+YMn3ANaacZ/YABfgSn9/OOy
                                                                        TLSH:A6831749FD819B15D5D516BAFE0F418A33632BACE3EE7202DD245B2027CA95B0F7B412
                                                                        File Content Preview:.ELF..............(.........4...xW......4. ...(........p.R...........................................S...S...............S...S...S..4....r...............S...S...S..................Q.td..................................-...L..................@-.,@...0....S

                                                                        ELF header

                                                                        Class:ELF32
                                                                        Data:2's complement, little endian
                                                                        Version:1 (current)
                                                                        Machine:ARM
                                                                        Version Number:0x1
                                                                        Type:EXEC (Executable file)
                                                                        OS/ABI:UNIX - System V
                                                                        ABI Version:0
                                                                        Entry Point Address:0x8194
                                                                        Flags:0x4000002
                                                                        ELF Header Size:52
                                                                        Program Header Offset:52
                                                                        Program Header Size:32
                                                                        Number of Program Headers:5
                                                                        Section Header Offset:87928
                                                                        Section Header Size:40
                                                                        Number of Section Headers:15
                                                                        Header String Table Index:14
                                                                        NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                                                        NULL0x00x00x00x00x0000
                                                                        .initPROGBITS0x80d40xd40x100x00x6AX004
                                                                        .textPROGBITS0x80f00xf00x139f40x00x6AX0016
                                                                        .finiPROGBITS0x1bae40x13ae40x100x00x6AX004
                                                                        .rodataPROGBITS0x1baf80x13af80x17a80x00x2A008
                                                                        .ARM.extabPROGBITS0x1d2a00x152a00x180x00x2A004
                                                                        .ARM.exidxARM_EXIDX0x1d2b80x152b80x1180x00x82AL204
                                                                        .eh_framePROGBITS0x253d00x153d00x40x00x3WA004
                                                                        .tbssNOBITS0x253d40x153d40x80x00x403WAT004
                                                                        .init_arrayINIT_ARRAY0x253d40x153d40x40x00x3WA004
                                                                        .fini_arrayFINI_ARRAY0x253d80x153d80x40x00x3WA004
                                                                        .gotPROGBITS0x253e00x153e00xa80x40x3WA004
                                                                        .dataPROGBITS0x254880x154880x27c0x00x3WA004
                                                                        .bssNOBITS0x257040x157040x6f600x00x3WA004
                                                                        .shstrtabSTRTAB0x00x157040x730x00x0001
                                                                        TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                                        EXIDX0x152b80x1d2b80x1d2b80x1180x1184.48990x4R 0x4.ARM.exidx
                                                                        LOAD0x00x80000x80000x153d00x153d06.11610x5R E0x8000.init .text .fini .rodata .ARM.extab .ARM.exidx
                                                                        LOAD0x153d00x253d00x253d00x3340x72944.12500x6RW 0x8000.eh_frame .tbss .init_array .fini_array .got .data .bss
                                                                        TLS0x153d40x253d40x253d40x00x80.00000x4R 0x4.tbss
                                                                        GNU_STACK0x00x00x00x00x00.00000x7RWE0x4

                                                                        Download Network PCAP: filteredfull

                                                                        • Total Packets: 30
                                                                        • 46164 undefined
                                                                        • 19302 undefined
                                                                        • 443 (HTTPS)
                                                                        • 80 (HTTP)
                                                                        • 53 (DNS)
                                                                        TimestampSource PortDest PortSource IPDest IP
                                                                        Mar 24, 2025 04:33:36.467700958 CET43928443192.168.2.2391.189.91.42
                                                                        Mar 24, 2025 04:33:37.998394966 CET4781646164192.168.2.23104.245.241.61
                                                                        Mar 24, 2025 04:33:38.389584064 CET4616447816104.245.241.61192.168.2.23
                                                                        Mar 24, 2025 04:33:38.391622066 CET4781646164192.168.2.23104.245.241.61
                                                                        Mar 24, 2025 04:33:38.783601046 CET4616447816104.245.241.61192.168.2.23
                                                                        Mar 24, 2025 04:33:38.783732891 CET4781646164192.168.2.23104.245.241.61
                                                                        Mar 24, 2025 04:33:39.174995899 CET4616447816104.245.241.61192.168.2.23
                                                                        Mar 24, 2025 04:33:39.175215960 CET4781646164192.168.2.23104.245.241.61
                                                                        Mar 24, 2025 04:33:39.609379053 CET4781646164192.168.2.23104.245.241.61
                                                                        Mar 24, 2025 04:33:40.001152039 CET4616447816104.245.241.61192.168.2.23
                                                                        Mar 24, 2025 04:33:42.099095106 CET42836443192.168.2.2391.189.91.43
                                                                        Mar 24, 2025 04:33:43.378873110 CET4251680192.168.2.23109.202.202.202
                                                                        Mar 24, 2025 04:33:51.384810925 CET4616447816104.245.241.61192.168.2.23
                                                                        Mar 24, 2025 04:33:51.385056019 CET4781646164192.168.2.23104.245.241.61
                                                                        Mar 24, 2025 04:33:57.649420023 CET39250443192.168.2.2334.249.145.219
                                                                        Mar 24, 2025 04:33:57.649476051 CET4433925034.249.145.219192.168.2.23
                                                                        Mar 24, 2025 04:33:57.649555922 CET39250443192.168.2.2334.249.145.219
                                                                        Mar 24, 2025 04:33:57.649804115 CET39250443192.168.2.2334.249.145.219
                                                                        Mar 24, 2025 04:33:57.649816990 CET4433925034.249.145.219192.168.2.23
                                                                        Mar 24, 2025 04:33:58.224739075 CET43928443192.168.2.2391.189.91.42
                                                                        Mar 24, 2025 04:34:06.393480062 CET4781646164192.168.2.23104.245.241.61
                                                                        Mar 24, 2025 04:34:06.785315037 CET4616447816104.245.241.61192.168.2.23
                                                                        Mar 24, 2025 04:34:06.785475016 CET4781646164192.168.2.23104.245.241.61
                                                                        Mar 24, 2025 04:34:07.176110029 CET4616447816104.245.241.61192.168.2.23
                                                                        Mar 24, 2025 04:34:08.463346004 CET42836443192.168.2.2391.189.91.43
                                                                        Mar 24, 2025 04:34:14.606534958 CET4251680192.168.2.23109.202.202.202
                                                                        Mar 24, 2025 04:34:24.677891970 CET4781646164192.168.2.23104.245.241.61
                                                                        Mar 24, 2025 04:34:25.069025040 CET4616447816104.245.241.61192.168.2.23
                                                                        Mar 24, 2025 04:34:25.069145918 CET4781646164192.168.2.23104.245.241.61
                                                                        Mar 24, 2025 04:34:25.459717035 CET4616447816104.245.241.61192.168.2.23
                                                                        Mar 24, 2025 04:34:39.179264069 CET43928443192.168.2.2391.189.91.42
                                                                        Mar 24, 2025 04:34:43.930494070 CET4781646164192.168.2.23104.245.241.61
                                                                        Mar 24, 2025 04:34:44.321851969 CET4616447816104.245.241.61192.168.2.23
                                                                        Mar 24, 2025 04:34:44.322006941 CET4781646164192.168.2.23104.245.241.61
                                                                        Mar 24, 2025 04:34:44.713095903 CET4616447816104.245.241.61192.168.2.23
                                                                        Mar 24, 2025 04:34:57.641513109 CET39250443192.168.2.2334.249.145.219
                                                                        Mar 24, 2025 04:34:57.684317112 CET4433925034.249.145.219192.168.2.23
                                                                        Mar 24, 2025 04:35:03.418296099 CET4616447816104.245.241.61192.168.2.23
                                                                        Mar 24, 2025 04:35:03.418425083 CET4781646164192.168.2.23104.245.241.61
                                                                        Mar 24, 2025 04:35:18.431816101 CET4781646164192.168.2.23104.245.241.61
                                                                        Mar 24, 2025 04:35:18.822283030 CET4616447816104.245.241.61192.168.2.23
                                                                        Mar 24, 2025 04:35:18.822426081 CET4781646164192.168.2.23104.245.241.61
                                                                        Mar 24, 2025 04:35:19.213903904 CET4616447816104.245.241.61192.168.2.23
                                                                        Mar 24, 2025 04:35:36.051248074 CET4781646164192.168.2.23104.245.241.61
                                                                        Mar 24, 2025 04:35:36.443147898 CET4616447816104.245.241.61192.168.2.23
                                                                        Mar 24, 2025 04:35:36.443330050 CET4781646164192.168.2.23104.245.241.61
                                                                        Mar 24, 2025 04:35:36.833987951 CET4616447816104.245.241.61192.168.2.23
                                                                        Mar 24, 2025 04:35:40.427426100 CET4433925034.249.145.219192.168.2.23
                                                                        TimestampSource PortDest PortSource IPDest IP
                                                                        Mar 24, 2025 04:33:39.412918091 CET5330753192.168.2.238.8.8.8
                                                                        Mar 24, 2025 04:33:39.510339022 CET53533078.8.8.8192.168.2.23
                                                                        Mar 24, 2025 04:33:39.511133909 CET4927219302192.168.2.2374.125.250.129
                                                                        Mar 24, 2025 04:33:39.606657982 CET193024927274.125.250.129192.168.2.23
                                                                        TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                                                        Mar 24, 2025 04:33:39.412918091 CET192.168.2.238.8.8.80xfd4eStandard query (0)stun.l.google.comA (IP address)IN (0x0001)false
                                                                        TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                                                        Mar 24, 2025 04:33:39.510339022 CET8.8.8.8192.168.2.230xfd4eNo error (0)stun.l.google.com74.125.250.129A (IP address)IN (0x0001)false

                                                                        System Behavior

                                                                        Start time (UTC):03:33:36
                                                                        Start date (UTC):24/03/2025
                                                                        Path:/tmp/arm7.elf
                                                                        Arguments:-
                                                                        File size:4956856 bytes
                                                                        MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                                        Start time (UTC):03:34:56
                                                                        Start date (UTC):24/03/2025
                                                                        Path:/usr/bin/dash
                                                                        Arguments:-
                                                                        File size:129816 bytes
                                                                        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                        Start time (UTC):03:34:56
                                                                        Start date (UTC):24/03/2025
                                                                        Path:/usr/bin/rm
                                                                        Arguments:rm -f /tmp/tmp.UdanZs6GZ6 /tmp/tmp.p8VtV423LG /tmp/tmp.gFwVK4QLXR
                                                                        File size:72056 bytes
                                                                        MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b

                                                                        Start time (UTC):03:34:56
                                                                        Start date (UTC):24/03/2025
                                                                        Path:/usr/bin/dash
                                                                        Arguments:-
                                                                        File size:129816 bytes
                                                                        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                        Start time (UTC):03:34:56
                                                                        Start date (UTC):24/03/2025
                                                                        Path:/usr/bin/rm
                                                                        Arguments:rm -f /tmp/tmp.UdanZs6GZ6 /tmp/tmp.p8VtV423LG /tmp/tmp.gFwVK4QLXR
                                                                        File size:72056 bytes
                                                                        MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b