Edit tour

Linux Analysis Report
sh4.elf

Overview

General Information

Sample name:sh4.elf
Analysis ID:1648515
MD5:e8ef397a6252b4bb5f9dca999a65b428
SHA1:e2e98f8e1dccaedacf57d3a976e46087c3986d57
SHA256:0138c304be84d14e19ee7c55dd9903dab13e9662be71de9b0f8bfe6cc8d14366
Tags:elfuser-abuse_ch
Infos:

Detection

Score:52
Range:0 - 100

Signatures

Multi AV Scanner detection for submitted file
Sample reads /proc/mounts (often used for finding a writable filesystem)
Enumerates processes within the "proc" file system
Executes the "rm" command used to delete files or directories
Sample has stripped symbol table
Sample listens on a socket
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
Joe Sandbox version:42.0.0 Malachite
Analysis ID:1648515
Start date and time:2025-03-25 21:48:12 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 39s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:sh4.elf
Detection:MAL
Classification:mal52.troj.linELF@0/4@0/0
Command:/tmp/sh4.elf
PID:6209
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
For God so loved the world
Standard Error:
  • system is lnxubuntu20
  • sh4.elf (PID: 6209, Parent: 6126, MD5: 8943e5f8f8c280467b4472c15ae93ba9) Arguments: /tmp/sh4.elf
    • sh4.elf New Fork (PID: 6242, Parent: 6209)
  • dash New Fork (PID: 6212, Parent: 4334)
  • rm (PID: 6212, Parent: 4334, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.umJXxnpBun /tmp/tmp.NLceEAGHg3 /tmp/tmp.6duU8a6VcW
  • dash New Fork (PID: 6213, Parent: 4334)
  • cat (PID: 6213, Parent: 4334, MD5: 7e9d213e404ad3bb82e4ebb2e1f2c1b3) Arguments: cat /tmp/tmp.umJXxnpBun
  • dash New Fork (PID: 6214, Parent: 4334)
  • head (PID: 6214, Parent: 4334, MD5: fd96a67145172477dd57131396fc9608) Arguments: head -n 10
  • dash New Fork (PID: 6215, Parent: 4334)
  • tr (PID: 6215, Parent: 4334, MD5: fbd1402dd9f72d8ebfff00ce7c3a7bb5) Arguments: tr -d \\000-\\011\\013\\014\\016-\\037
  • dash New Fork (PID: 6216, Parent: 4334)
  • cut (PID: 6216, Parent: 4334, MD5: d8ed0ea8f22c0de0f8692d4d9f1759d3) Arguments: cut -c -80
  • dash New Fork (PID: 6217, Parent: 4334)
  • cat (PID: 6217, Parent: 4334, MD5: 7e9d213e404ad3bb82e4ebb2e1f2c1b3) Arguments: cat /tmp/tmp.umJXxnpBun
  • dash New Fork (PID: 6218, Parent: 4334)
  • head (PID: 6218, Parent: 4334, MD5: fd96a67145172477dd57131396fc9608) Arguments: head -n 10
  • dash New Fork (PID: 6219, Parent: 4334)
  • tr (PID: 6219, Parent: 4334, MD5: fbd1402dd9f72d8ebfff00ce7c3a7bb5) Arguments: tr -d \\000-\\011\\013\\014\\016-\\037
  • dash New Fork (PID: 6220, Parent: 4334)
  • cut (PID: 6220, Parent: 4334, MD5: d8ed0ea8f22c0de0f8692d4d9f1759d3) Arguments: cut -c -80
  • dash New Fork (PID: 6221, Parent: 4334)
  • rm (PID: 6221, Parent: 4334, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.umJXxnpBun /tmp/tmp.NLceEAGHg3 /tmp/tmp.6duU8a6VcW
  • cleanup
No yara matches
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: sh4.elfReversingLabs: Detection: 25%
Source: unknownHTTPS traffic detected: 54.171.230.55:443 -> 192.168.2.23:33606 version: TLS 1.2
Source: /tmp/sh4.elf (PID: 6242)Socket: 127.0.0.1:22448Jump to behavior
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 54.171.230.55
Source: unknownTCP traffic detected without corresponding DNS query: 54.171.230.55
Source: unknownTCP traffic detected without corresponding DNS query: 54.171.230.55
Source: unknownTCP traffic detected without corresponding DNS query: 54.171.230.55
Source: unknownTCP traffic detected without corresponding DNS query: 54.171.230.55
Source: unknownTCP traffic detected without corresponding DNS query: 54.171.230.55
Source: unknownTCP traffic detected without corresponding DNS query: 54.171.230.55
Source: unknownTCP traffic detected without corresponding DNS query: 54.171.230.55
Source: unknownTCP traffic detected without corresponding DNS query: 54.171.230.55
Source: unknownTCP traffic detected without corresponding DNS query: 54.171.230.55
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 33606
Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 33606 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443
Source: unknownHTTPS traffic detected: 54.171.230.55:443 -> 192.168.2.23:33606 version: TLS 1.2
Source: ELF static info symbol of initial sample.symtab present: no
Source: classification engineClassification label: mal52.troj.linELF@0/4@0/0

Persistence and Installation Behavior

barindex
Source: /tmp/sh4.elf (PID: 6209)File: /proc/6209/mountsJump to behavior
Source: /tmp/sh4.elf (PID: 6209)File opened: /proc/6230/fdJump to behavior
Source: /tmp/sh4.elf (PID: 6209)File opened: /proc/6230/cmdlineJump to behavior
Source: /tmp/sh4.elf (PID: 6209)File opened: /proc/6232/fdJump to behavior
Source: /tmp/sh4.elf (PID: 6209)File opened: /proc/6232/cmdlineJump to behavior
Source: /tmp/sh4.elf (PID: 6209)File opened: /proc/6231/fdJump to behavior
Source: /tmp/sh4.elf (PID: 6209)File opened: /proc/6231/cmdlineJump to behavior
Source: /tmp/sh4.elf (PID: 6209)File opened: /proc/6234/fdJump to behavior
Source: /tmp/sh4.elf (PID: 6209)File opened: /proc/6234/cmdlineJump to behavior
Source: /tmp/sh4.elf (PID: 6209)File opened: /proc/6233/fdJump to behavior
Source: /tmp/sh4.elf (PID: 6209)File opened: /proc/6233/cmdlineJump to behavior
Source: /tmp/sh4.elf (PID: 6209)File opened: /proc/6236/fdJump to behavior
Source: /tmp/sh4.elf (PID: 6209)File opened: /proc/6236/cmdlineJump to behavior
Source: /tmp/sh4.elf (PID: 6209)File opened: /proc/6235/fdJump to behavior
Source: /tmp/sh4.elf (PID: 6209)File opened: /proc/6235/cmdlineJump to behavior
Source: /tmp/sh4.elf (PID: 6209)File opened: /proc/1582/cmdlineJump to behavior
Source: /tmp/sh4.elf (PID: 6209)File opened: /proc/1582/fdJump to behavior
Source: /tmp/sh4.elf (PID: 6209)File opened: /proc/1582/cmdlineJump to behavior
Source: /tmp/sh4.elf (PID: 6209)File opened: /proc/3088/cmdlineJump to behavior
Source: /tmp/sh4.elf (PID: 6209)File opened: /proc/230/cmdlineJump to behavior
Source: /tmp/sh4.elf (PID: 6209)File opened: /proc/110/cmdlineJump to behavior
Source: /tmp/sh4.elf (PID: 6209)File opened: /proc/231/cmdlineJump to behavior
Source: /tmp/sh4.elf (PID: 6209)File opened: /proc/111/cmdlineJump to behavior
Source: /tmp/sh4.elf (PID: 6209)File opened: /proc/232/cmdlineJump to behavior
Source: /tmp/sh4.elf (PID: 6209)File opened: /proc/1579/cmdlineJump to behavior
Source: /tmp/sh4.elf (PID: 6209)File opened: /proc/1579/fdJump to behavior
Source: /tmp/sh4.elf (PID: 6209)File opened: /proc/1579/cmdlineJump to behavior
Source: /tmp/sh4.elf (PID: 6209)File opened: /proc/112/cmdlineJump to behavior
Source: /tmp/sh4.elf (PID: 6209)File opened: /proc/233/cmdlineJump to behavior
Source: /tmp/sh4.elf (PID: 6209)File opened: /proc/1699/cmdlineJump to behavior
Source: /tmp/sh4.elf (PID: 6209)File opened: /proc/1699/fdJump to behavior
Source: /tmp/sh4.elf (PID: 6209)File opened: /proc/1699/cmdlineJump to behavior
Source: /tmp/sh4.elf (PID: 6209)File opened: /proc/113/cmdlineJump to behavior
Source: /tmp/sh4.elf (PID: 6209)File opened: /proc/234/cmdlineJump to behavior
Source: /tmp/sh4.elf (PID: 6209)File opened: /proc/1335/cmdlineJump to behavior
Source: /tmp/sh4.elf (PID: 6209)File opened: /proc/1335/fdJump to behavior
Source: /tmp/sh4.elf (PID: 6209)File opened: /proc/1335/cmdlineJump to behavior
Source: /tmp/sh4.elf (PID: 6209)File opened: /proc/1698/cmdlineJump to behavior
Source: /tmp/sh4.elf (PID: 6209)File opened: /proc/1698/fdJump to behavior
Source: /tmp/sh4.elf (PID: 6209)File opened: /proc/1698/cmdlineJump to behavior
Source: /tmp/sh4.elf (PID: 6209)File opened: /proc/114/cmdlineJump to behavior
Source: /tmp/sh4.elf (PID: 6209)File opened: /proc/235/cmdlineJump to behavior
Source: /tmp/sh4.elf (PID: 6209)File opened: /proc/1334/cmdlineJump to behavior
Source: /tmp/sh4.elf (PID: 6209)File opened: /proc/1334/fdJump to behavior
Source: /tmp/sh4.elf (PID: 6209)File opened: /proc/1334/cmdlineJump to behavior
Source: /tmp/sh4.elf (PID: 6209)File opened: /proc/1576/cmdlineJump to behavior
Source: /tmp/sh4.elf (PID: 6209)File opened: /proc/1576/fdJump to behavior
Source: /tmp/sh4.elf (PID: 6209)File opened: /proc/1576/cmdlineJump to behavior
Source: /tmp/sh4.elf (PID: 6209)File opened: /proc/2302/cmdlineJump to behavior
Source: /tmp/sh4.elf (PID: 6209)File opened: /proc/2302/fdJump to behavior
Source: /tmp/sh4.elf (PID: 6209)File opened: /proc/2302/cmdlineJump to behavior
Source: /tmp/sh4.elf (PID: 6209)File opened: /proc/115/cmdlineJump to behavior
Source: /tmp/sh4.elf (PID: 6209)File opened: /proc/236/cmdlineJump to behavior
Source: /tmp/sh4.elf (PID: 6209)File opened: /proc/116/cmdlineJump to behavior
Source: /tmp/sh4.elf (PID: 6209)File opened: /proc/237/cmdlineJump to behavior
Source: /tmp/sh4.elf (PID: 6209)File opened: /proc/117/cmdlineJump to behavior
Source: /tmp/sh4.elf (PID: 6209)File opened: /proc/118/cmdlineJump to behavior
Source: /tmp/sh4.elf (PID: 6209)File opened: /proc/910/cmdlineJump to behavior
Source: /tmp/sh4.elf (PID: 6209)File opened: /proc/6227/fdJump to behavior
Source: /tmp/sh4.elf (PID: 6209)File opened: /proc/6227/cmdlineJump to behavior
Source: /tmp/sh4.elf (PID: 6209)File opened: /proc/119/cmdlineJump to behavior
Source: /tmp/sh4.elf (PID: 6209)File opened: /proc/6226/fdJump to behavior
Source: /tmp/sh4.elf (PID: 6209)File opened: /proc/6226/cmdlineJump to behavior
Source: /tmp/sh4.elf (PID: 6209)File opened: /proc/912/cmdlineJump to behavior
Source: /tmp/sh4.elf (PID: 6209)File opened: /proc/912/fdJump to behavior
Source: /tmp/sh4.elf (PID: 6209)File opened: /proc/912/cmdlineJump to behavior
Source: /tmp/sh4.elf (PID: 6209)File opened: /proc/6229/fdJump to behavior
Source: /tmp/sh4.elf (PID: 6209)File opened: /proc/6229/cmdlineJump to behavior
Source: /tmp/sh4.elf (PID: 6209)File opened: /proc/6228/fdJump to behavior
Source: /tmp/sh4.elf (PID: 6209)File opened: /proc/6228/cmdlineJump to behavior
Source: /tmp/sh4.elf (PID: 6209)File opened: /proc/10/cmdlineJump to behavior
Source: /tmp/sh4.elf (PID: 6209)File opened: /proc/2307/cmdlineJump to behavior
Source: /tmp/sh4.elf (PID: 6209)File opened: /proc/2307/fdJump to behavior
Source: /tmp/sh4.elf (PID: 6209)File opened: /proc/2307/cmdlineJump to behavior
Source: /tmp/sh4.elf (PID: 6209)File opened: /proc/11/cmdlineJump to behavior
Source: /tmp/sh4.elf (PID: 6209)File opened: /proc/918/cmdlineJump to behavior
Source: /tmp/sh4.elf (PID: 6209)File opened: /proc/918/fdJump to behavior
Source: /tmp/sh4.elf (PID: 6209)File opened: /proc/918/cmdlineJump to behavior
Source: /tmp/sh4.elf (PID: 6209)File opened: /proc/12/cmdlineJump to behavior
Source: /tmp/sh4.elf (PID: 6209)File opened: /proc/6240/fdJump to behavior
Source: /tmp/sh4.elf (PID: 6209)File opened: /proc/6240/cmdlineJump to behavior
Source: /tmp/sh4.elf (PID: 6209)File opened: /proc/13/cmdlineJump to behavior
Source: /tmp/sh4.elf (PID: 6209)File opened: /proc/14/cmdlineJump to behavior
Source: /tmp/sh4.elf (PID: 6209)File opened: /proc/15/cmdlineJump to behavior
Source: /tmp/sh4.elf (PID: 6209)File opened: /proc/16/cmdlineJump to behavior
Source: /tmp/sh4.elf (PID: 6209)File opened: /proc/17/cmdlineJump to behavior
Source: /tmp/sh4.elf (PID: 6209)File opened: /proc/18/cmdlineJump to behavior
Source: /tmp/sh4.elf (PID: 6209)File opened: /proc/1594/cmdlineJump to behavior
Source: /tmp/sh4.elf (PID: 6209)File opened: /proc/1594/fdJump to behavior
Source: /tmp/sh4.elf (PID: 6209)File opened: /proc/1594/cmdlineJump to behavior
Source: /tmp/sh4.elf (PID: 6209)File opened: /proc/120/cmdlineJump to behavior
Source: /tmp/sh4.elf (PID: 6209)File opened: /proc/121/cmdlineJump to behavior
Source: /tmp/sh4.elf (PID: 6209)File opened: /proc/1349/cmdlineJump to behavior
Source: /tmp/sh4.elf (PID: 6209)File opened: /proc/1349/fdJump to behavior
Source: /tmp/sh4.elf (PID: 6209)File opened: /proc/1349/cmdlineJump to behavior
Source: /tmp/sh4.elf (PID: 6209)File opened: /proc/1/mapsJump to behavior
Source: /tmp/sh4.elf (PID: 6209)File opened: /proc/1/cmdlineJump to behavior
Source: /tmp/sh4.elf (PID: 6209)File opened: /proc/1/fdJump to behavior
Source: /tmp/sh4.elf (PID: 6209)File opened: /proc/1/cmdlineJump to behavior
Source: /tmp/sh4.elf (PID: 6209)File opened: /proc/122/cmdlineJump to behavior
Source: /tmp/sh4.elf (PID: 6209)File opened: /proc/243/cmdlineJump to behavior
Source: /tmp/sh4.elf (PID: 6209)File opened: /proc/123/cmdlineJump to behavior
Source: /tmp/sh4.elf (PID: 6209)File opened: /proc/2/cmdlineJump to behavior
Source: /tmp/sh4.elf (PID: 6209)File opened: /proc/124/cmdlineJump to behavior
Source: /tmp/sh4.elf (PID: 6209)File opened: /proc/3/cmdlineJump to behavior
Source: /tmp/sh4.elf (PID: 6209)File opened: /proc/4/cmdlineJump to behavior
Source: /usr/bin/dash (PID: 6212)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.umJXxnpBun /tmp/tmp.NLceEAGHg3 /tmp/tmp.6duU8a6VcWJump to behavior
Source: /usr/bin/dash (PID: 6221)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.umJXxnpBun /tmp/tmp.NLceEAGHg3 /tmp/tmp.6duU8a6VcWJump to behavior
Source: /tmp/sh4.elf (PID: 6209)Queries kernel information via 'uname': Jump to behavior
Source: sh4.elf, 6209.1.00007ffdbbe33000.00007ffdbbe54000.rw-.sdmpBinary or memory string: U/tmp/qemu-open.W6w3PH\T
Source: sh4.elf, 6209.1.00007f1298427000.00007f129842e000.rw-.sdmp, sh4.elf, 6242.1.00007f1298427000.00007f129842e000.rw-.sdmpBinary or memory string: B!!a1gAWFxuAXsFWUgBRQAA!!a1gAWFxuAXsAWUgKRXgA!!a1gAWFxuAXsAWEgJR3IA!!a10CWFxuAHsGWVcWQHAA!!a10CWFxuAHsGWVcWQHUA!!aFwAWF9uA3sGW0gLRgAA!!aFwAWFlpG2QBW0gJTwAA!!qemu-arm2QBW0gJTwAA!
Source: sh4.elf, 6242.1.00007f1298427000.00007f129842e000.rw-.sdmpBinary or memory string: vmware
Source: sh4.elf, 6209.1.00007f1298427000.00007f129842e000.rw-.sdmp, sh4.elf, 6242.1.00007f1298427000.00007f129842e000.rw-.sdmpBinary or memory string: qemu-arm
Source: sh4.elf, 6209.1.00007ffdbbe33000.00007ffdbbe54000.rw-.sdmpBinary or memory string: /tmp/qemu-open.W6w3PH
Source: sh4.elf, 6209.1.00007ffdbbe33000.00007ffdbbe54000.rw-.sdmp, sh4.elf, 6242.1.00007ffdbbe33000.00007ffdbbe54000.rw-.sdmpBinary or memory string: /usr/bin/qemu-sh4
Source: sh4.elf, 6209.1.000055d2725dc000.000055d272685000.rw-.sdmp, sh4.elf, 6242.1.000055d2725dc000.000055d272685000.rw-.sdmpBinary or memory string: U5!/etc/qemu-binfmt/sh4
Source: sh4.elf, 6209.1.000055d2725dc000.000055d272685000.rw-.sdmp, sh4.elf, 6242.1.000055d2725dc000.000055d272685000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/sh4
Source: sh4.elf, 6209.1.00007ffdbbe33000.00007ffdbbe54000.rw-.sdmp, sh4.elf, 6242.1.00007ffdbbe33000.00007ffdbbe54000.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-sh4/tmp/sh4.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/sh4.elf
Source: sh4.elf, 6242.1.00007ffdbbe33000.00007ffdbbe54000.rw-.sdmpBinary or memory string: qemu: uncaught target signal 11 (Segmentation fault) - core dumped
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception1
File Deletion
1
OS Credential Dumping
11
Security Software Discovery
Remote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS Memory1
File and Directory Discovery
Remote Desktop ProtocolData from Removable Media1
Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1648515 Sample: sh4.elf Startdate: 25/03/2025 Architecture: LINUX Score: 52 18 109.202.202.202, 80 INIT7CH Switzerland 2->18 20 91.189.91.42, 443 CANONICAL-ASGB United Kingdom 2->20 22 2 other IPs or domains 2->22 24 Multi AV Scanner detection for submitted file 2->24 7 sh4.elf 2->7         started        10 dash rm 2->10         started        12 dash head 2->12         started        14 8 other processes 2->14 signatures3 process4 signatures5 26 Sample reads /proc/mounts (often used for finding a writable filesystem) 7->26 16 sh4.elf 7->16         started        process6
SourceDetectionScannerLabelLink
sh4.elf25%ReversingLabsLinux.Backdoor.Mirai
No Antivirus matches
No Antivirus matches
No Antivirus matches

Download Network PCAP: filteredfull

No contacted domains info
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs
IPDomainCountryFlagASNASN NameMalicious
54.171.230.55
unknownUnited States
16509AMAZON-02USfalse
109.202.202.202
unknownSwitzerland
13030INIT7CHfalse
91.189.91.43
unknownUnited Kingdom
41231CANONICAL-ASGBfalse
91.189.91.42
unknownUnited Kingdom
41231CANONICAL-ASGBfalse
MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
54.171.230.55na.elfGet hashmaliciousPrometeiBrowse
    main_m68k.elfGet hashmaliciousMiraiBrowse
      boatnet.arm5.elfGet hashmaliciousMiraiBrowse
        mips.elfGet hashmaliciousMiraiBrowse
          main_sh4.elfGet hashmaliciousMiraiBrowse
            main_mpsl.elfGet hashmaliciousMiraiBrowse
              main_x86.elfGet hashmaliciousMiraiBrowse
                na.elfGet hashmaliciousPrometeiBrowse
                  na.elfGet hashmaliciousPrometeiBrowse
                    tarm7.elfGet hashmaliciousMiraiBrowse
                      109.202.202.202kpLwzBouH4.elfGet hashmaliciousUnknownBrowse
                      • ch.archive.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_92.0%2bbuild3-0ubuntu0.20.04.1_amd64.deb
                      91.189.91.43na.elfGet hashmaliciousPrometeiBrowse
                        na.elfGet hashmaliciousPrometeiBrowse
                          arm6.elfGet hashmaliciousUnknownBrowse
                            arm5.elfGet hashmaliciousUnknownBrowse
                              aarch64.elfGet hashmaliciousMiraiBrowse
                                mips.elfGet hashmaliciousMiraiBrowse
                                  mips.elfGet hashmaliciousMiraiBrowse
                                    sh4.elfGet hashmaliciousUnknownBrowse
                                      mpsl.elfGet hashmaliciousUnknownBrowse
                                        aarch64.elfGet hashmaliciousUnknownBrowse
                                          91.189.91.42na.elfGet hashmaliciousPrometeiBrowse
                                            na.elfGet hashmaliciousPrometeiBrowse
                                              arm6.elfGet hashmaliciousUnknownBrowse
                                                arm5.elfGet hashmaliciousUnknownBrowse
                                                  aarch64.elfGet hashmaliciousMiraiBrowse
                                                    mips.elfGet hashmaliciousMiraiBrowse
                                                      mips.elfGet hashmaliciousMiraiBrowse
                                                        sh4.elfGet hashmaliciousUnknownBrowse
                                                          mpsl.elfGet hashmaliciousUnknownBrowse
                                                            aarch64.elfGet hashmaliciousUnknownBrowse
                                                              No context
                                                              MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                              CANONICAL-ASGBna.elfGet hashmaliciousPrometeiBrowse
                                                              • 91.189.91.42
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 91.189.91.42
                                                              arm6.elfGet hashmaliciousUnknownBrowse
                                                              • 91.189.91.42
                                                              arm5.elfGet hashmaliciousUnknownBrowse
                                                              • 91.189.91.42
                                                              arm.elfGet hashmaliciousMiraiBrowse
                                                              • 185.125.190.26
                                                              aarch64.elfGet hashmaliciousMiraiBrowse
                                                              • 91.189.91.42
                                                              arm7.elfGet hashmaliciousMiraiBrowse
                                                              • 185.125.190.26
                                                              mpsl.elfGet hashmaliciousUnknownBrowse
                                                              • 185.125.190.26
                                                              mips.elfGet hashmaliciousMiraiBrowse
                                                              • 91.189.91.42
                                                              mips.elfGet hashmaliciousMiraiBrowse
                                                              • 91.189.91.42
                                                              CANONICAL-ASGBna.elfGet hashmaliciousPrometeiBrowse
                                                              • 91.189.91.42
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 91.189.91.42
                                                              arm6.elfGet hashmaliciousUnknownBrowse
                                                              • 91.189.91.42
                                                              arm5.elfGet hashmaliciousUnknownBrowse
                                                              • 91.189.91.42
                                                              arm.elfGet hashmaliciousMiraiBrowse
                                                              • 185.125.190.26
                                                              aarch64.elfGet hashmaliciousMiraiBrowse
                                                              • 91.189.91.42
                                                              arm7.elfGet hashmaliciousMiraiBrowse
                                                              • 185.125.190.26
                                                              mpsl.elfGet hashmaliciousUnknownBrowse
                                                              • 185.125.190.26
                                                              mips.elfGet hashmaliciousMiraiBrowse
                                                              • 91.189.91.42
                                                              mips.elfGet hashmaliciousMiraiBrowse
                                                              • 91.189.91.42
                                                              AMAZON-02USna.elfGet hashmaliciousPrometeiBrowse
                                                              • 34.249.145.219
                                                              arm6.elfGet hashmaliciousUnknownBrowse
                                                              • 34.243.160.129
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 54.170.242.139
                                                              ppc.elfGet hashmaliciousUnknownBrowse
                                                              • 34.254.182.186
                                                              main_m68k.elfGet hashmaliciousMiraiBrowse
                                                              • 54.247.62.1
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 54.247.62.1
                                                              boatnet.arm5.elfGet hashmaliciousMiraiBrowse
                                                              • 34.243.160.129
                                                              mips.elfGet hashmaliciousMiraiBrowse
                                                              • 54.171.230.55
                                                              arm7.elfGet hashmaliciousUnknownBrowse
                                                              • 54.217.10.153
                                                              mips.elfGet hashmaliciousMiraiBrowse
                                                              • 54.247.62.1
                                                              INIT7CHna.elfGet hashmaliciousPrometeiBrowse
                                                              • 109.202.202.202
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 109.202.202.202
                                                              arm6.elfGet hashmaliciousUnknownBrowse
                                                              • 109.202.202.202
                                                              arm5.elfGet hashmaliciousUnknownBrowse
                                                              • 109.202.202.202
                                                              aarch64.elfGet hashmaliciousMiraiBrowse
                                                              • 109.202.202.202
                                                              mips.elfGet hashmaliciousMiraiBrowse
                                                              • 109.202.202.202
                                                              mips.elfGet hashmaliciousMiraiBrowse
                                                              • 109.202.202.202
                                                              sh4.elfGet hashmaliciousUnknownBrowse
                                                              • 109.202.202.202
                                                              mpsl.elfGet hashmaliciousUnknownBrowse
                                                              • 109.202.202.202
                                                              aarch64.elfGet hashmaliciousUnknownBrowse
                                                              • 109.202.202.202
                                                              No context
                                                              No context
                                                              Process:/tmp/sh4.elf
                                                              File Type:ASCII text, with no line terminators
                                                              Category:dropped
                                                              Size (bytes):13
                                                              Entropy (8bit):3.5465935642949384
                                                              Encrypted:false
                                                              SSDEEP:3:TgKYn:TgKYn
                                                              MD5:AEF4020327A62D78F5A8202D453B0A74
                                                              SHA1:84FC7A7CBE0B4EF5BDB927B95EA1BD01665BE8B1
                                                              SHA-256:1878DDF74B755A998CBFD2140779771966ADF507D2B95CA86906476BFD80575B
                                                              SHA-512:0E1BF58363F746F19B92730E15E2091F05A2C87B120B004F3819735F4D60268E66711EBEB06E3B771B2DE327FCBB3DDD368241E7A6E1A1B759384F6D70A2C528
                                                              Malicious:false
                                                              Reputation:moderate, very likely benign file
                                                              Preview:/tmp/sh4.elf.
                                                              Process:/tmp/sh4.elf
                                                              File Type:ASCII text, with no line terminators
                                                              Category:dropped
                                                              Size (bytes):13
                                                              Entropy (8bit):3.5465935642949384
                                                              Encrypted:false
                                                              SSDEEP:3:TgKYn:TgKYn
                                                              MD5:AEF4020327A62D78F5A8202D453B0A74
                                                              SHA1:84FC7A7CBE0B4EF5BDB927B95EA1BD01665BE8B1
                                                              SHA-256:1878DDF74B755A998CBFD2140779771966ADF507D2B95CA86906476BFD80575B
                                                              SHA-512:0E1BF58363F746F19B92730E15E2091F05A2C87B120B004F3819735F4D60268E66711EBEB06E3B771B2DE327FCBB3DDD368241E7A6E1A1B759384F6D70A2C528
                                                              Malicious:false
                                                              Reputation:moderate, very likely benign file
                                                              Preview:/tmp/sh4.elf.
                                                              Process:/tmp/sh4.elf
                                                              File Type:ASCII text
                                                              Category:dropped
                                                              Size (bytes):360
                                                              Entropy (8bit):3.8006502646055664
                                                              Encrypted:false
                                                              SSDEEP:6:URL3IgDF1S8SVl/VUT4DF1SUj/tj/VKAvVVyAb/3hM/V+4D/VH:ILNIqcL/KaVIAbRMfF
                                                              MD5:6985186019C32F3B2FE32C66BFDF9E28
                                                              SHA1:37CBD6485921182BDB9E8769E2C727C836D8E186
                                                              SHA-256:1F17BD3F9FECA7BDF034396CBD7EC31E15243F138F6A86CAFD451D839DAFDC81
                                                              SHA-512:CBB251BA3A43F6FF5C08A5CD7B76E2CE68EDC6EA792901291AC9042BD447DC4A023023C9FF770AB6C99CA065208D89CE984FE7FEF470463E381F2C5664124B5A
                                                              Malicious:false
                                                              Reputation:low
                                                              Preview:400000-417000 r-xp 00000000 fd:00 531606 /tmp/sh4.elf.426000-427000 rw-p 00016000 fd:00 531606 /tmp/sh4.elf.427000-42e000 rw-p 00000000 00:00 0 .7f7fe000-7f7ff000 r--p 00000000 fd:00 793309 /usr/lib/x86_64-linux-gnu/libm-2.31.so.7f7ff000-7f800000 ---p 00000000 00:00 0 .7f800000-80000000 rw-p 00000000 00:00 0 [stack].
                                                              Process:/tmp/sh4.elf
                                                              File Type:ASCII text, with no line terminators
                                                              Category:dropped
                                                              Size (bytes):13
                                                              Entropy (8bit):3.5465935642949384
                                                              Encrypted:false
                                                              SSDEEP:3:TgKYn:TgKYn
                                                              MD5:AEF4020327A62D78F5A8202D453B0A74
                                                              SHA1:84FC7A7CBE0B4EF5BDB927B95EA1BD01665BE8B1
                                                              SHA-256:1878DDF74B755A998CBFD2140779771966ADF507D2B95CA86906476BFD80575B
                                                              SHA-512:0E1BF58363F746F19B92730E15E2091F05A2C87B120B004F3819735F4D60268E66711EBEB06E3B771B2DE327FCBB3DDD368241E7A6E1A1B759384F6D70A2C528
                                                              Malicious:false
                                                              Reputation:moderate, very likely benign file
                                                              Preview:/tmp/sh4.elf.
                                                              File type:ELF 32-bit LSB executable, Renesas SH, version 1 (SYSV), dynamically linked, stripped
                                                              Entropy (8bit):6.919010459621075
                                                              TrID:
                                                              • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                                                              File name:sh4.elf
                                                              File size:92'100 bytes
                                                              MD5:e8ef397a6252b4bb5f9dca999a65b428
                                                              SHA1:e2e98f8e1dccaedacf57d3a976e46087c3986d57
                                                              SHA256:0138c304be84d14e19ee7c55dd9903dab13e9662be71de9b0f8bfe6cc8d14366
                                                              SHA512:3d81c3f119aa0cdde0c22b725f71adf34ca18b50d1e5edf3d5fe952be7dafacf8ea1f136fccd93dbebf439d48b2f4e5cf78cee3f5b4f63f7d061f25b4899bb67
                                                              SSDEEP:1536:AwYQEAcgcfVmj2TBR26+wckjHzeJBvlJllmKf8xudnZrj:AFDL9Vmj2XfckDzeHJlIUdn9
                                                              TLSH:5F939E32F4202D91CC225AF4F0F4CA3947526AB180D21DB599EEE27444A7EDDF98DB6C
                                                              File Content Preview:.ELF..............*.......@.4...4f......4. ...(...............@...@.ld..ld..............He..HeB.HeB.....PI............................................././"O.n......#.*@........#.*@.H..&O.n.l..................................././.../.a"O.!...n...a.b("...q.

                                                              ELF header

                                                              Class:ELF32
                                                              Data:2's complement, little endian
                                                              Version:1 (current)
                                                              Machine:<unknown>
                                                              Version Number:0x1
                                                              Type:EXEC (Executable file)
                                                              OS/ABI:UNIX - System V
                                                              ABI Version:0
                                                              Entry Point Address:0x4001a0
                                                              Flags:0xc
                                                              ELF Header Size:52
                                                              Program Header Offset:52
                                                              Program Header Size:32
                                                              Number of Program Headers:3
                                                              Section Header Offset:91700
                                                              Section Header Size:40
                                                              Number of Section Headers:10
                                                              Header String Table Index:9
                                                              NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                                              NULL0x00x00x00x00x0000
                                                              .initPROGBITS0x4000940x940x2e0x00x6AX004
                                                              .textPROGBITS0x4000e00xe00x149000x00x6AX0032
                                                              .finiPROGBITS0x4149e00x149e00x220x00x6AX004
                                                              .rodataPROGBITS0x414a040x14a040x1a680x00x2A004
                                                              .ctorsPROGBITS0x4265480x165480x80x00x3WA004
                                                              .dtorsPROGBITS0x4265500x165500x80x00x3WA004
                                                              .dataPROGBITS0x42655c0x1655c0x980x00x3WA004
                                                              .bssNOBITS0x4265f40x165f40x48a40x00x3WA004
                                                              .shstrtabSTRTAB0x00x165f40x3e0x00x0001
                                                              TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                              LOAD0x00x4000000x4000000x1646c0x1646c6.94230x5R E0x10000.init .text .fini .rodata
                                                              LOAD0x165480x4265480x4265480xac0x49504.09050x6RW 0x10000.ctors .dtors .data .bss
                                                              DYNAMIC0x00x00x00x00x00.00000x7RWE0x4

                                                              Download Network PCAP: filteredfull

                                                              • Total Packets: 17
                                                              • 443 (HTTPS)
                                                              • 80 (HTTP)
                                                              TimestampSource PortDest PortSource IPDest IP
                                                              Mar 25, 2025 21:48:51.564311028 CET43928443192.168.2.2391.189.91.42
                                                              Mar 25, 2025 21:48:53.684290886 CET4433360654.171.230.55192.168.2.23
                                                              Mar 25, 2025 21:48:53.684319019 CET4433360654.171.230.55192.168.2.23
                                                              Mar 25, 2025 21:48:53.684336901 CET4433360654.171.230.55192.168.2.23
                                                              Mar 25, 2025 21:48:53.684411049 CET33606443192.168.2.2354.171.230.55
                                                              Mar 25, 2025 21:48:53.684411049 CET33606443192.168.2.2354.171.230.55
                                                              Mar 25, 2025 21:48:53.684411049 CET33606443192.168.2.2354.171.230.55
                                                              Mar 25, 2025 21:48:53.685430050 CET33606443192.168.2.2354.171.230.55
                                                              Mar 25, 2025 21:48:53.913666964 CET4433360654.171.230.55192.168.2.23
                                                              Mar 25, 2025 21:48:54.162583113 CET4433360654.171.230.55192.168.2.23
                                                              Mar 25, 2025 21:48:54.162874937 CET33606443192.168.2.2354.171.230.55
                                                              Mar 25, 2025 21:48:54.162899017 CET33606443192.168.2.2354.171.230.55
                                                              Mar 25, 2025 21:48:54.396646976 CET4433360654.171.230.55192.168.2.23
                                                              Mar 25, 2025 21:48:54.398900986 CET4433360654.171.230.55192.168.2.23
                                                              Mar 25, 2025 21:48:54.398946047 CET33606443192.168.2.2354.171.230.55
                                                              Mar 25, 2025 21:48:54.400444031 CET33606443192.168.2.2354.171.230.55
                                                              Mar 25, 2025 21:48:54.642689943 CET4433360654.171.230.55192.168.2.23
                                                              Mar 25, 2025 21:48:54.642790079 CET33606443192.168.2.2354.171.230.55
                                                              Mar 25, 2025 21:48:54.716937065 CET4433360654.171.230.55192.168.2.23
                                                              Mar 25, 2025 21:48:54.716996908 CET33606443192.168.2.2354.171.230.55
                                                              Mar 25, 2025 21:48:57.195310116 CET42836443192.168.2.2391.189.91.43
                                                              Mar 25, 2025 21:48:58.219232082 CET4251680192.168.2.23109.202.202.202
                                                              Mar 25, 2025 21:49:13.321188927 CET43928443192.168.2.2391.189.91.42
                                                              Mar 25, 2025 21:49:23.559839010 CET42836443192.168.2.2391.189.91.43
                                                              Mar 25, 2025 21:49:27.655224085 CET4251680192.168.2.23109.202.202.202
                                                              Mar 25, 2025 21:49:54.275670052 CET43928443192.168.2.2391.189.91.42
                                                              TimestampSource IPSource PortDest IPDest PortSubjectIssuerNot BeforeNot AfterJA3 SSL Client FingerprintJA3 SSL Client Digest
                                                              Mar 25, 2025 21:48:53.684336901 CET54.171.230.55443192.168.2.2333606CN=motd.ubuntu.com CN=R10, O=Let's Encrypt, C=USCN=R10, O=Let's Encrypt, C=US CN=ISRG Root X1, O=Internet Security Research Group, C=USSat Mar 22 09:18:05 CET 2025 Wed Mar 13 01:00:00 CET 2024Fri Jun 20 10:18:04 CEST 2025 Sat Mar 13 00:59:59 CET 2027
                                                              CN=R10, O=Let's Encrypt, C=USCN=ISRG Root X1, O=Internet Security Research Group, C=USWed Mar 13 01:00:00 CET 2024Sat Mar 13 00:59:59 CET 2027

                                                              System Behavior

                                                              Start time (UTC):20:48:53
                                                              Start date (UTC):25/03/2025
                                                              Path:/tmp/sh4.elf
                                                              Arguments:-
                                                              File size:4139976 bytes
                                                              MD5 hash:8943e5f8f8c280467b4472c15ae93ba9

                                                              Start time (UTC):20:48:53
                                                              Start date (UTC):25/03/2025
                                                              Path:/usr/bin/dash
                                                              Arguments:-
                                                              File size:129816 bytes
                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                              Start time (UTC):20:48:53
                                                              Start date (UTC):25/03/2025
                                                              Path:/usr/bin/rm
                                                              Arguments:rm -f /tmp/tmp.umJXxnpBun /tmp/tmp.NLceEAGHg3 /tmp/tmp.6duU8a6VcW
                                                              File size:72056 bytes
                                                              MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b

                                                              Start time (UTC):20:48:53
                                                              Start date (UTC):25/03/2025
                                                              Path:/usr/bin/dash
                                                              Arguments:-
                                                              File size:129816 bytes
                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                              Start time (UTC):20:48:53
                                                              Start date (UTC):25/03/2025
                                                              Path:/usr/bin/cat
                                                              Arguments:cat /tmp/tmp.umJXxnpBun
                                                              File size:43416 bytes
                                                              MD5 hash:7e9d213e404ad3bb82e4ebb2e1f2c1b3

                                                              Start time (UTC):20:48:53
                                                              Start date (UTC):25/03/2025
                                                              Path:/usr/bin/dash
                                                              Arguments:-
                                                              File size:129816 bytes
                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                              Start time (UTC):20:48:53
                                                              Start date (UTC):25/03/2025
                                                              Path:/usr/bin/head
                                                              Arguments:head -n 10
                                                              File size:47480 bytes
                                                              MD5 hash:fd96a67145172477dd57131396fc9608

                                                              Start time (UTC):20:48:53
                                                              Start date (UTC):25/03/2025
                                                              Path:/usr/bin/dash
                                                              Arguments:-
                                                              File size:129816 bytes
                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                              Start time (UTC):20:48:53
                                                              Start date (UTC):25/03/2025
                                                              Path:/usr/bin/tr
                                                              Arguments:tr -d \\000-\\011\\013\\014\\016-\\037
                                                              File size:51544 bytes
                                                              MD5 hash:fbd1402dd9f72d8ebfff00ce7c3a7bb5

                                                              Start time (UTC):20:48:53
                                                              Start date (UTC):25/03/2025
                                                              Path:/usr/bin/dash
                                                              Arguments:-
                                                              File size:129816 bytes
                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                              Start time (UTC):20:48:53
                                                              Start date (UTC):25/03/2025
                                                              Path:/usr/bin/cut
                                                              Arguments:cut -c -80
                                                              File size:47480 bytes
                                                              MD5 hash:d8ed0ea8f22c0de0f8692d4d9f1759d3

                                                              Start time (UTC):20:48:53
                                                              Start date (UTC):25/03/2025
                                                              Path:/usr/bin/dash
                                                              Arguments:-
                                                              File size:129816 bytes
                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                              Start time (UTC):20:48:53
                                                              Start date (UTC):25/03/2025
                                                              Path:/usr/bin/cat
                                                              Arguments:cat /tmp/tmp.umJXxnpBun
                                                              File size:43416 bytes
                                                              MD5 hash:7e9d213e404ad3bb82e4ebb2e1f2c1b3

                                                              Start time (UTC):20:48:53
                                                              Start date (UTC):25/03/2025
                                                              Path:/usr/bin/dash
                                                              Arguments:-
                                                              File size:129816 bytes
                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                              Start time (UTC):20:48:53
                                                              Start date (UTC):25/03/2025
                                                              Path:/usr/bin/head
                                                              Arguments:head -n 10
                                                              File size:47480 bytes
                                                              MD5 hash:fd96a67145172477dd57131396fc9608

                                                              Start time (UTC):20:48:53
                                                              Start date (UTC):25/03/2025
                                                              Path:/usr/bin/dash
                                                              Arguments:-
                                                              File size:129816 bytes
                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                              Start time (UTC):20:48:53
                                                              Start date (UTC):25/03/2025
                                                              Path:/usr/bin/tr
                                                              Arguments:tr -d \\000-\\011\\013\\014\\016-\\037
                                                              File size:51544 bytes
                                                              MD5 hash:fbd1402dd9f72d8ebfff00ce7c3a7bb5

                                                              Start time (UTC):20:48:53
                                                              Start date (UTC):25/03/2025
                                                              Path:/usr/bin/dash
                                                              Arguments:-
                                                              File size:129816 bytes
                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                              Start time (UTC):20:48:53
                                                              Start date (UTC):25/03/2025
                                                              Path:/usr/bin/cut
                                                              Arguments:cut -c -80
                                                              File size:47480 bytes
                                                              MD5 hash:d8ed0ea8f22c0de0f8692d4d9f1759d3

                                                              Start time (UTC):20:48:53
                                                              Start date (UTC):25/03/2025
                                                              Path:/usr/bin/dash
                                                              Arguments:-
                                                              File size:129816 bytes
                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                              Start time (UTC):20:48:53
                                                              Start date (UTC):25/03/2025
                                                              Path:/usr/bin/rm
                                                              Arguments:rm -f /tmp/tmp.umJXxnpBun /tmp/tmp.NLceEAGHg3 /tmp/tmp.6duU8a6VcW
                                                              File size:72056 bytes
                                                              MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b