Edit tour

Linux Analysis Report
mips.elf

Overview

General Information

Sample name:mips.elf
Analysis ID:1647756
MD5:3b77b277e4b84e1bf3b9eae9f3aa6101
SHA1:cf3daa50c2f88e341295a840633d92a59ae1b01a
SHA256:03bf3f9cd78298d3eef06e03c0c22da0cc937f4496a36f5d121f2dde51da85e2
Tags:elfuser-abuse_ch
Infos:
Errors
  • No or unstable Internet during analysis

Detection

Score:56
Range:0 - 100

Signatures

Antivirus / Scanner detection for submitted sample
Multi AV Scanner detection for submitted file
Enumerates processes within the "proc" file system
Executes the "rm" command used to delete files or directories
Sample has stripped symbol table
Sample listens on a socket
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
Joe Sandbox version:42.0.0 Malachite
Analysis ID:1647756
Start date and time:2025-03-25 08:15:32 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 48s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:mips.elf
Detection:MAL
Classification:mal56.linELF@0/2@0/0
  • No or unstable Internet during analysis
  • Excluded IPs from analysis (whitelisted): 208.67.222.222
Command:/tmp/mips.elf
PID:6259
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
For God so loved the world
Standard Error:
  • system is lnxubuntu20
  • dash New Fork (PID: 6242, Parent: 4331)
  • rm (PID: 6242, Parent: 4331, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.ebYThKkd9q /tmp/tmp.7aYhrw2n1l /tmp/tmp.r17nGbvFAY
  • dash New Fork (PID: 6243, Parent: 4331)
  • cat (PID: 6243, Parent: 4331, MD5: 7e9d213e404ad3bb82e4ebb2e1f2c1b3) Arguments: cat /tmp/tmp.ebYThKkd9q
  • dash New Fork (PID: 6244, Parent: 4331)
  • head (PID: 6244, Parent: 4331, MD5: fd96a67145172477dd57131396fc9608) Arguments: head -n 10
  • dash New Fork (PID: 6245, Parent: 4331)
  • tr (PID: 6245, Parent: 4331, MD5: fbd1402dd9f72d8ebfff00ce7c3a7bb5) Arguments: tr -d \\000-\\011\\013\\014\\016-\\037
  • dash New Fork (PID: 6246, Parent: 4331)
  • cut (PID: 6246, Parent: 4331, MD5: d8ed0ea8f22c0de0f8692d4d9f1759d3) Arguments: cut -c -80
  • dash New Fork (PID: 6247, Parent: 4331)
  • cat (PID: 6247, Parent: 4331, MD5: 7e9d213e404ad3bb82e4ebb2e1f2c1b3) Arguments: cat /tmp/tmp.ebYThKkd9q
  • dash New Fork (PID: 6248, Parent: 4331)
  • head (PID: 6248, Parent: 4331, MD5: fd96a67145172477dd57131396fc9608) Arguments: head -n 10
  • dash New Fork (PID: 6249, Parent: 4331)
  • tr (PID: 6249, Parent: 4331, MD5: fbd1402dd9f72d8ebfff00ce7c3a7bb5) Arguments: tr -d \\000-\\011\\013\\014\\016-\\037
  • dash New Fork (PID: 6250, Parent: 4331)
  • cut (PID: 6250, Parent: 4331, MD5: d8ed0ea8f22c0de0f8692d4d9f1759d3) Arguments: cut -c -80
  • dash New Fork (PID: 6251, Parent: 4331)
  • rm (PID: 6251, Parent: 4331, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.ebYThKkd9q /tmp/tmp.7aYhrw2n1l /tmp/tmp.r17nGbvFAY
  • mips.elf (PID: 6259, Parent: 6172, MD5: 0083f1f0e77be34ad27f849842bbb00c) Arguments: /tmp/mips.elf
    • mips.elf New Fork (PID: 6261, Parent: 6259)
  • cleanup
No yara matches
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: mips.elfAvira: detected
Source: mips.elfReversingLabs: Detection: 25%
Source: /tmp/mips.elf (PID: 6261)Socket: 127.0.0.1:22448Jump to behavior
Source: global trafficTCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
Source: global trafficTCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
Source: global trafficTCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownUDP traffic detected without corresponding DNS query: 208.67.220.220
Source: unknownUDP traffic detected without corresponding DNS query: 208.67.220.220
Source: unknownUDP traffic detected without corresponding DNS query: 208.67.220.220
Source: unknownUDP traffic detected without corresponding DNS query: 208.67.220.220
Source: unknownUDP traffic detected without corresponding DNS query: 208.67.220.220
Source: unknownUDP traffic detected without corresponding DNS query: 208.67.220.220
Source: mips.elf, 6259.1.00007f361c457000.00007f361c461000.rw-.sdmpString found in binary or memory: http://0/t/wget.sh
Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443
Source: ELF static info symbol of initial sample.symtab present: no
Source: classification engineClassification label: mal56.linELF@0/2@0/0
Source: /tmp/mips.elf (PID: 6259)File opened: /proc/6236/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 6259)File opened: /proc/6235/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 6259)File opened: /proc/1582/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 6259)File opened: /proc/3088/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 6259)File opened: /proc/230/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 6259)File opened: /proc/110/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 6259)File opened: /proc/231/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 6259)File opened: /proc/111/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 6259)File opened: /proc/232/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 6259)File opened: /proc/1579/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 6259)File opened: /proc/112/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 6259)File opened: /proc/233/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 6259)File opened: /proc/1699/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 6259)File opened: /proc/113/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 6259)File opened: /proc/234/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 6259)File opened: /proc/1335/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 6259)File opened: /proc/1698/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 6259)File opened: /proc/114/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 6259)File opened: /proc/235/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 6259)File opened: /proc/1334/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 6259)File opened: /proc/1576/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 6259)File opened: /proc/2302/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 6259)File opened: /proc/115/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 6259)File opened: /proc/236/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 6259)File opened: /proc/116/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 6259)File opened: /proc/237/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 6259)File opened: /proc/117/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 6259)File opened: /proc/118/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 6259)File opened: /proc/910/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 6259)File opened: /proc/119/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 6259)File opened: /proc/912/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 6259)File opened: /proc/10/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 6259)File opened: /proc/2307/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 6259)File opened: /proc/11/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 6259)File opened: /proc/918/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 6259)File opened: /proc/12/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 6259)File opened: /proc/13/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 6259)File opened: /proc/14/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 6259)File opened: /proc/15/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 6259)File opened: /proc/16/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 6259)File opened: /proc/17/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 6259)File opened: /proc/18/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 6259)File opened: /proc/1594/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 6259)File opened: /proc/120/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 6259)File opened: /proc/121/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 6259)File opened: /proc/1349/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 6259)File opened: /proc/1/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 6259)File opened: /proc/122/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 6259)File opened: /proc/243/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 6259)File opened: /proc/123/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 6259)File opened: /proc/2/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 6259)File opened: /proc/124/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 6259)File opened: /proc/3/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 6259)File opened: /proc/4/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 6259)File opened: /proc/125/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 6259)File opened: /proc/126/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 6259)File opened: /proc/1344/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 6259)File opened: /proc/1465/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 6259)File opened: /proc/1586/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 6259)File opened: /proc/127/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 6259)File opened: /proc/6/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 6259)File opened: /proc/248/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 6259)File opened: /proc/128/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 6259)File opened: /proc/249/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 6259)File opened: /proc/1463/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 6259)File opened: /proc/800/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 6259)File opened: /proc/9/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 6259)File opened: /proc/801/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 6259)File opened: /proc/20/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 6259)File opened: /proc/21/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 6259)File opened: /proc/1900/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 6259)File opened: /proc/22/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 6259)File opened: /proc/23/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 6259)File opened: /proc/24/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 6259)File opened: /proc/25/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 6259)File opened: /proc/26/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 6259)File opened: /proc/27/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 6259)File opened: /proc/28/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 6259)File opened: /proc/29/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 6259)File opened: /proc/491/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 6259)File opened: /proc/250/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 6259)File opened: /proc/130/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 6259)File opened: /proc/251/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 6259)File opened: /proc/252/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 6259)File opened: /proc/132/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 6259)File opened: /proc/253/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 6259)File opened: /proc/254/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 6259)File opened: /proc/255/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 6259)File opened: /proc/256/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 6259)File opened: /proc/1599/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 6259)File opened: /proc/257/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 6259)File opened: /proc/1477/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 6259)File opened: /proc/379/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 6259)File opened: /proc/258/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 6259)File opened: /proc/1476/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 6259)File opened: /proc/259/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 6259)File opened: /proc/1475/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 6259)File opened: /proc/936/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 6259)File opened: /proc/30/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 6259)File opened: /proc/2208/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 6259)File opened: /proc/35/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 6259)File opened: /proc/1809/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 6259)File opened: /proc/1494/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 6259)File opened: /proc/260/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 6259)File opened: /proc/261/cmdlineJump to behavior
Source: /usr/bin/dash (PID: 6242)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.ebYThKkd9q /tmp/tmp.7aYhrw2n1l /tmp/tmp.r17nGbvFAYJump to behavior
Source: /usr/bin/dash (PID: 6251)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.ebYThKkd9q /tmp/tmp.7aYhrw2n1l /tmp/tmp.r17nGbvFAYJump to behavior
Source: /tmp/mips.elf (PID: 6259)Queries kernel information via 'uname': Jump to behavior
Source: mips.elf, 6259.1.00007ffd6cba6000.00007ffd6cbc7000.rw-.sdmpBinary or memory string: /tmp/qemu-open.AeBpHt
Source: mips.elf, 6259.1.00007f361c457000.00007f361c461000.rw-.sdmpBinary or memory string: vmwarem
Source: mips.elf, 6259.1.000056127042d000.00005612704d4000.rw-.sdmpBinary or memory string: V!/etc/qemu-binfmt/mips
Source: mips.elf, 6259.1.00007f361c457000.00007f361c461000.rw-.sdmpBinary or memory string: vmware
Source: mips.elf, 6259.1.00007f361c457000.00007f361c461000.rw-.sdmpBinary or memory string: qemu-arm2QB
Source: mips.elf, 6259.1.00007f361c457000.00007f361c461000.rw-.sdmpBinary or memory string: qemu-arm
Source: mips.elf, 6259.1.000056127042d000.00005612704d4000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/mips
Source: mips.elf, 6259.1.00007ffd6cba6000.00007ffd6cbc7000.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-mips/tmp/mips.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/mips.elf
Source: mips.elf, 6259.1.00007ffd6cba6000.00007ffd6cbc7000.rw-.sdmpBinary or memory string: %s/qemu-op
Source: mips.elf, 6259.1.00007ffd6cba6000.00007ffd6cbc7000.rw-.sdmpBinary or memory string: V/tmp/qemu-open.AeBpHt\
Source: mips.elf, 6259.1.00007ffd6cba6000.00007ffd6cbc7000.rw-.sdmpBinary or memory string: /usr/bin/qemu-mips
Source: mips.elf, 6259.1.00007ffd6cba6000.00007ffd6cbc7000.rw-.sdmpBinary or memory string: MPDIR%s/qemu-op
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception1
File Deletion
1
OS Credential Dumping
11
Security Software Discovery
Remote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1647756 Sample: mips.elf Startdate: 25/03/2025 Architecture: LINUX Score: 56 17 109.202.202.202, 80 INIT7CH Switzerland 2->17 19 91.189.91.42, 443 CANONICAL-ASGB United Kingdom 2->19 21 91.189.91.43, 443 CANONICAL-ASGB United Kingdom 2->21 23 Antivirus / Scanner detection for submitted sample 2->23 25 Multi AV Scanner detection for submitted file 2->25 7 dash rm mips.elf 2->7         started        9 dash rm 2->9         started        11 dash cut 2->11         started        13 7 other processes 2->13 signatures3 process4 process5 15 mips.elf 7->15         started       
SourceDetectionScannerLabelLink
mips.elf25%ReversingLabsLinux.Backdoor.Gafgyt
mips.elf100%AviraEXP/ELF.Agent.J.8
No Antivirus matches
No Antivirus matches
No Antivirus matches

Download Network PCAP: filteredfull

No contacted domains info
NameSourceMaliciousAntivirus DetectionReputation
http://0/t/wget.shmips.elf, 6259.1.00007f361c457000.00007f361c461000.rw-.sdmpfalse
    high
    • No. of IPs < 25%
    • 25% < No. of IPs < 50%
    • 50% < No. of IPs < 75%
    • 75% < No. of IPs
    IPDomainCountryFlagASNASN NameMalicious
    109.202.202.202
    unknownSwitzerland
    13030INIT7CHfalse
    91.189.91.43
    unknownUnited Kingdom
    41231CANONICAL-ASGBfalse
    91.189.91.42
    unknownUnited Kingdom
    41231CANONICAL-ASGBfalse
    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
    109.202.202.202kpLwzBouH4.elfGet hashmaliciousUnknownBrowse
    • ch.archive.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_92.0%2bbuild3-0ubuntu0.20.04.1_amd64.deb
    91.189.91.43na.elfGet hashmaliciousPrometeiBrowse
      na.elfGet hashmaliciousPrometeiBrowse
        na.elfGet hashmaliciousPrometeiBrowse
          na.elfGet hashmaliciousPrometeiBrowse
            na.elfGet hashmaliciousPrometeiBrowse
              main_sh4.elfGet hashmaliciousMiraiBrowse
                main_arm6.elfGet hashmaliciousMiraiBrowse
                  arm.elfGet hashmaliciousUnknownBrowse
                    main_mpsl.elfGet hashmaliciousMiraiBrowse
                      na.elfGet hashmaliciousPrometeiBrowse
                        91.189.91.42na.elfGet hashmaliciousPrometeiBrowse
                          na.elfGet hashmaliciousPrometeiBrowse
                            na.elfGet hashmaliciousPrometeiBrowse
                              na.elfGet hashmaliciousPrometeiBrowse
                                na.elfGet hashmaliciousPrometeiBrowse
                                  main_sh4.elfGet hashmaliciousMiraiBrowse
                                    main_arm6.elfGet hashmaliciousMiraiBrowse
                                      arm.elfGet hashmaliciousUnknownBrowse
                                        main_mpsl.elfGet hashmaliciousMiraiBrowse
                                          na.elfGet hashmaliciousPrometeiBrowse
                                            No context
                                            MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                            CANONICAL-ASGBna.elfGet hashmaliciousPrometeiBrowse
                                            • 91.189.91.42
                                            na.elfGet hashmaliciousPrometeiBrowse
                                            • 91.189.91.42
                                            na.elfGet hashmaliciousPrometeiBrowse
                                            • 91.189.91.42
                                            na.elfGet hashmaliciousPrometeiBrowse
                                            • 91.189.91.42
                                            na.elfGet hashmaliciousPrometeiBrowse
                                            • 91.189.91.42
                                            main_sh4.elfGet hashmaliciousMiraiBrowse
                                            • 91.189.91.42
                                            main_arm6.elfGet hashmaliciousMiraiBrowse
                                            • 91.189.91.42
                                            arm.elfGet hashmaliciousUnknownBrowse
                                            • 91.189.91.42
                                            main_mpsl.elfGet hashmaliciousMiraiBrowse
                                            • 91.189.91.42
                                            na.elfGet hashmaliciousPrometeiBrowse
                                            • 91.189.91.42
                                            CANONICAL-ASGBna.elfGet hashmaliciousPrometeiBrowse
                                            • 91.189.91.42
                                            na.elfGet hashmaliciousPrometeiBrowse
                                            • 91.189.91.42
                                            na.elfGet hashmaliciousPrometeiBrowse
                                            • 91.189.91.42
                                            na.elfGet hashmaliciousPrometeiBrowse
                                            • 91.189.91.42
                                            na.elfGet hashmaliciousPrometeiBrowse
                                            • 91.189.91.42
                                            main_sh4.elfGet hashmaliciousMiraiBrowse
                                            • 91.189.91.42
                                            main_arm6.elfGet hashmaliciousMiraiBrowse
                                            • 91.189.91.42
                                            arm.elfGet hashmaliciousUnknownBrowse
                                            • 91.189.91.42
                                            main_mpsl.elfGet hashmaliciousMiraiBrowse
                                            • 91.189.91.42
                                            na.elfGet hashmaliciousPrometeiBrowse
                                            • 91.189.91.42
                                            INIT7CHna.elfGet hashmaliciousPrometeiBrowse
                                            • 109.202.202.202
                                            na.elfGet hashmaliciousPrometeiBrowse
                                            • 109.202.202.202
                                            na.elfGet hashmaliciousPrometeiBrowse
                                            • 109.202.202.202
                                            na.elfGet hashmaliciousPrometeiBrowse
                                            • 109.202.202.202
                                            na.elfGet hashmaliciousPrometeiBrowse
                                            • 109.202.202.202
                                            main_sh4.elfGet hashmaliciousMiraiBrowse
                                            • 109.202.202.202
                                            main_arm6.elfGet hashmaliciousMiraiBrowse
                                            • 109.202.202.202
                                            arm.elfGet hashmaliciousUnknownBrowse
                                            • 109.202.202.202
                                            main_mpsl.elfGet hashmaliciousMiraiBrowse
                                            • 109.202.202.202
                                            na.elfGet hashmaliciousPrometeiBrowse
                                            • 109.202.202.202
                                            No context
                                            No context
                                            Process:/tmp/mips.elf
                                            File Type:data
                                            Category:dropped
                                            Size (bytes):14
                                            Entropy (8bit):3.378783493486176
                                            Encrypted:false
                                            SSDEEP:3:TgaLGn:TgAG
                                            MD5:640E98E7A87EC50F267F24DBC141D4DD
                                            SHA1:BC19B1CF25759386125D933665A8B429D9AE7E26
                                            SHA-256:6976993806B7CE05EA0AAA6BC975462833B19CF0D6DD4C9480F26FBAF66AF31D
                                            SHA-512:3887FBDFA33FF58EF35DDD9B1A2C9BDD611208904D8D371B2AFFE6E97F4C2EDA7A5BAA9786BDD3857AB6B31FE933CBE7290E7D9223671670A9BC739D457D4BA9
                                            Malicious:false
                                            Reputation:moderate, very likely benign file
                                            Preview:/tmp/mips.elf.
                                            Process:/tmp/mips.elf
                                            File Type:data
                                            Category:dropped
                                            Size (bytes):14
                                            Entropy (8bit):3.378783493486176
                                            Encrypted:false
                                            SSDEEP:3:TgaLGn:TgAG
                                            MD5:640E98E7A87EC50F267F24DBC141D4DD
                                            SHA1:BC19B1CF25759386125D933665A8B429D9AE7E26
                                            SHA-256:6976993806B7CE05EA0AAA6BC975462833B19CF0D6DD4C9480F26FBAF66AF31D
                                            SHA-512:3887FBDFA33FF58EF35DDD9B1A2C9BDD611208904D8D371B2AFFE6E97F4C2EDA7A5BAA9786BDD3857AB6B31FE933CBE7290E7D9223671670A9BC739D457D4BA9
                                            Malicious:false
                                            Reputation:moderate, very likely benign file
                                            Preview:/tmp/mips.elf.
                                            File type:ELF 32-bit MSB executable, MIPS, MIPS-I version 1 (SYSV), statically linked, stripped
                                            Entropy (8bit):5.394675223451693
                                            TrID:
                                            • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                                            File name:mips.elf
                                            File size:93'324 bytes
                                            MD5:3b77b277e4b84e1bf3b9eae9f3aa6101
                                            SHA1:cf3daa50c2f88e341295a840633d92a59ae1b01a
                                            SHA256:03bf3f9cd78298d3eef06e03c0c22da0cc937f4496a36f5d121f2dde51da85e2
                                            SHA512:b807c0ceb68f7373209dccdeb68c733fcb6876bec759ccb982d23330a720e7a2e43ace25eee01025079c00f52954c277ea2c3147ca1ec534bd2e327c4ec63188
                                            SSDEEP:1536:Au81rICsPAJJ6o+XTWaRP0u17NmUBjnccrMe+e0Z4wJEO:Au8tICsPAJJ6vTWaRxmU1n+e4JEO
                                            TLSH:1793C74E2E31CFADF369C33547B74E31A3A923C522E1C685D2ACD6151F6024E645FBA8
                                            File Content Preview:.ELF.....................@.`...4..j......4. ...(.............@...@....S...S...............`..E`..E`....`..lT........dt.Q............................<...'......!'.......................<...'......!... ....'9... ......................<...'..h...!........'9:

                                            ELF header

                                            Class:ELF32
                                            Data:2's complement, big endian
                                            Version:1 (current)
                                            Machine:MIPS R3000
                                            Version Number:0x1
                                            Type:EXEC (Executable file)
                                            OS/ABI:UNIX - System V
                                            ABI Version:0
                                            Entry Point Address:0x400260
                                            Flags:0x1007
                                            ELF Header Size:52
                                            Program Header Offset:52
                                            Program Header Size:32
                                            Number of Program Headers:3
                                            Section Header Offset:92844
                                            Section Header Size:40
                                            Number of Section Headers:12
                                            Header String Table Index:11
                                            NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                            NULL0x00x00x00x00x0000
                                            .initPROGBITS0x4000940x940x8c0x00x6AX004
                                            .textPROGBITS0x4001200x1200x139800x00x6AX0016
                                            .finiPROGBITS0x413aa00x13aa00x5c0x00x6AX004
                                            .rodataPROGBITS0x413b000x13b000x18b00x00x2A0016
                                            .ctorsPROGBITS0x4560000x160000x80x00x3WA004
                                            .dtorsPROGBITS0x4560080x160080x80x00x3WA004
                                            .dataPROGBITS0x4560200x160200x4400x00x3WA0016
                                            .gotPROGBITS0x4564600x164600x6000x40x10000003WAp0016
                                            .sbssNOBITS0x456a600x16a600x1c0x00x10000003WAp004
                                            .bssNOBITS0x456a800x16a600x61d40x00x3WA0016
                                            .shstrtabSTRTAB0x00x16a600x490x00x0001
                                            TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                            LOAD0x00x4000000x4000000x153b00x153b05.55640x5R E0x10000.init .text .fini .rodata
                                            LOAD0x160000x4560000x4560000xa600x6c543.69920x6RW 0x10000.ctors .dtors .data .got .sbss .bss
                                            GNU_STACK0x00x00x00x00x00.00000x7RWE0x4

                                            Download Network PCAP: filteredfull

                                            • Total Packets: 21
                                            • 443 (HTTPS)
                                            • 80 (HTTP)
                                            • 53 (DNS)
                                            TimestampSource PortDest PortSource IPDest IP
                                            Mar 25, 2025 08:16:23.624953985 CET43928443192.168.2.2391.189.91.42
                                            Mar 25, 2025 08:16:29.000336885 CET42836443192.168.2.2391.189.91.43
                                            Mar 25, 2025 08:16:30.024138927 CET4251680192.168.2.23109.202.202.202
                                            Mar 25, 2025 08:16:44.102256060 CET43928443192.168.2.2391.189.91.42
                                            Mar 25, 2025 08:16:56.388592005 CET42836443192.168.2.2391.189.91.43
                                            Mar 25, 2025 08:17:00.483963013 CET4251680192.168.2.23109.202.202.202
                                            Mar 25, 2025 08:17:25.056607962 CET43928443192.168.2.2391.189.91.42
                                            TimestampSource PortDest PortSource IPDest IP
                                            Mar 25, 2025 08:16:27.910084963 CET5295553192.168.2.238.8.8.8
                                            Mar 25, 2025 08:16:29.911978006 CET4366753192.168.2.238.8.8.8
                                            Mar 25, 2025 08:16:49.930502892 CET5734753192.168.2.238.8.4.4
                                            Mar 25, 2025 08:16:51.932399988 CET4055153192.168.2.23208.67.220.220
                                            Mar 25, 2025 08:17:09.950083017 CET4122953192.168.2.238.8.8.8
                                            Mar 25, 2025 08:17:13.953984022 CET3685653192.168.2.238.8.8.8
                                            Mar 25, 2025 08:17:31.971069098 CET3400353192.168.2.238.8.4.4
                                            Mar 25, 2025 08:17:33.972961903 CET5187553192.168.2.23208.67.220.220
                                            Mar 25, 2025 08:17:35.974931002 CET5602353192.168.2.238.8.8.8
                                            Mar 25, 2025 08:17:53.978938103 CET5404853192.168.2.23208.67.220.220
                                            Mar 25, 2025 08:17:55.980809927 CET5998553192.168.2.238.8.8.8
                                            Mar 25, 2025 08:17:57.982878923 CET5978853192.168.2.23208.67.220.220
                                            Mar 25, 2025 08:18:17.995668888 CET5875553192.168.2.23208.67.220.220
                                            Mar 25, 2025 08:18:19.997673035 CET5113253192.168.2.23208.67.220.220

                                            System Behavior

                                            Start time (UTC):07:16:15
                                            Start date (UTC):25/03/2025
                                            Path:/usr/bin/dash
                                            Arguments:-
                                            File size:129816 bytes
                                            MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                            Start time (UTC):07:16:15
                                            Start date (UTC):25/03/2025
                                            Path:/usr/bin/rm
                                            Arguments:rm -f /tmp/tmp.ebYThKkd9q /tmp/tmp.7aYhrw2n1l /tmp/tmp.r17nGbvFAY
                                            File size:72056 bytes
                                            MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b

                                            Start time (UTC):07:16:15
                                            Start date (UTC):25/03/2025
                                            Path:/usr/bin/dash
                                            Arguments:-
                                            File size:129816 bytes
                                            MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                            Start time (UTC):07:16:15
                                            Start date (UTC):25/03/2025
                                            Path:/usr/bin/cat
                                            Arguments:cat /tmp/tmp.ebYThKkd9q
                                            File size:43416 bytes
                                            MD5 hash:7e9d213e404ad3bb82e4ebb2e1f2c1b3

                                            Start time (UTC):07:16:15
                                            Start date (UTC):25/03/2025
                                            Path:/usr/bin/dash
                                            Arguments:-
                                            File size:129816 bytes
                                            MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                            Start time (UTC):07:16:15
                                            Start date (UTC):25/03/2025
                                            Path:/usr/bin/head
                                            Arguments:head -n 10
                                            File size:47480 bytes
                                            MD5 hash:fd96a67145172477dd57131396fc9608

                                            Start time (UTC):07:16:15
                                            Start date (UTC):25/03/2025
                                            Path:/usr/bin/dash
                                            Arguments:-
                                            File size:129816 bytes
                                            MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                            Start time (UTC):07:16:15
                                            Start date (UTC):25/03/2025
                                            Path:/usr/bin/tr
                                            Arguments:tr -d \\000-\\011\\013\\014\\016-\\037
                                            File size:51544 bytes
                                            MD5 hash:fbd1402dd9f72d8ebfff00ce7c3a7bb5

                                            Start time (UTC):07:16:15
                                            Start date (UTC):25/03/2025
                                            Path:/usr/bin/dash
                                            Arguments:-
                                            File size:129816 bytes
                                            MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                            Start time (UTC):07:16:15
                                            Start date (UTC):25/03/2025
                                            Path:/usr/bin/cut
                                            Arguments:cut -c -80
                                            File size:47480 bytes
                                            MD5 hash:d8ed0ea8f22c0de0f8692d4d9f1759d3

                                            Start time (UTC):07:16:16
                                            Start date (UTC):25/03/2025
                                            Path:/usr/bin/dash
                                            Arguments:-
                                            File size:129816 bytes
                                            MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                            Start time (UTC):07:16:16
                                            Start date (UTC):25/03/2025
                                            Path:/usr/bin/cat
                                            Arguments:cat /tmp/tmp.ebYThKkd9q
                                            File size:43416 bytes
                                            MD5 hash:7e9d213e404ad3bb82e4ebb2e1f2c1b3

                                            Start time (UTC):07:16:16
                                            Start date (UTC):25/03/2025
                                            Path:/usr/bin/dash
                                            Arguments:-
                                            File size:129816 bytes
                                            MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                            Start time (UTC):07:16:16
                                            Start date (UTC):25/03/2025
                                            Path:/usr/bin/head
                                            Arguments:head -n 10
                                            File size:47480 bytes
                                            MD5 hash:fd96a67145172477dd57131396fc9608

                                            Start time (UTC):07:16:16
                                            Start date (UTC):25/03/2025
                                            Path:/usr/bin/dash
                                            Arguments:-
                                            File size:129816 bytes
                                            MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                            Start time (UTC):07:16:16
                                            Start date (UTC):25/03/2025
                                            Path:/usr/bin/tr
                                            Arguments:tr -d \\000-\\011\\013\\014\\016-\\037
                                            File size:51544 bytes
                                            MD5 hash:fbd1402dd9f72d8ebfff00ce7c3a7bb5

                                            Start time (UTC):07:16:16
                                            Start date (UTC):25/03/2025
                                            Path:/usr/bin/dash
                                            Arguments:-
                                            File size:129816 bytes
                                            MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                            Start time (UTC):07:16:16
                                            Start date (UTC):25/03/2025
                                            Path:/usr/bin/cut
                                            Arguments:cut -c -80
                                            File size:47480 bytes
                                            MD5 hash:d8ed0ea8f22c0de0f8692d4d9f1759d3

                                            Start time (UTC):07:16:16
                                            Start date (UTC):25/03/2025
                                            Path:/usr/bin/dash
                                            Arguments:-
                                            File size:129816 bytes
                                            MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                            Start time (UTC):07:16:16
                                            Start date (UTC):25/03/2025
                                            Path:/usr/bin/rm
                                            Arguments:rm -f /tmp/tmp.ebYThKkd9q /tmp/tmp.7aYhrw2n1l /tmp/tmp.r17nGbvFAY
                                            File size:72056 bytes
                                            MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b

                                            Start time (UTC):07:16:25
                                            Start date (UTC):25/03/2025
                                            Path:/tmp/mips.elf
                                            Arguments:-
                                            File size:5777432 bytes
                                            MD5 hash:0083f1f0e77be34ad27f849842bbb00c