Linux
Analysis Report
Aqua.mips.elf
Overview
General Information
Detection
Score: | 60 |
Range: | 0 - 100 |
Signatures
Antivirus / Scanner detection for submitted sample
Multi AV Scanner detection for submitted file
Sample deletes itself
Detected TCP or UDP traffic on non-standard ports
Sample has stripped symbol table
Uses the "uname" system call to query kernel version information (possible evasion)
Classification
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1649589 |
Start date and time: | 2025-03-26 23:23:23 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 4m 36s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultlinuxfilecookbook.jbs |
Analysis system description: | Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11) |
Analysis Mode: | default |
Sample name: | Aqua.mips.elf |
Detection: | MAL |
Classification: | mal60.evad.linELF@0/4@4/0 |
Command: | /tmp/Aqua.mips.elf |
PID: | 5528 |
Exit Code: | 0 |
Exit Code Info: | |
Killed: | False |
Standard Output: | kovey/cursinq was here, go away! |
Standard Error: |
⊘No yara matches
⊘No Suricata rule has matched
- • AV Detection
- • Networking
- • System Summary
- • Hooking and other Techniques for Hiding and Protection
- • Malware Analysis System Evasion
Click to jump to signature section
Show All Signature Results
AV Detection |
---|
Source: | Avira: |
Source: | ReversingLabs: |
Source: | TCP traffic: |
Source: | DNS traffic detected: |
Source: | .symtab present: |
Source: | Classification label: |
Hooking and other Techniques for Hiding and Protection |
---|
Source: | File: | Jump to behavior |
Source: | Queries kernel information via 'uname': | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | Path Interception | Path Interception | 1 File Deletion | OS Credential Dumping | 11 Security Software Discovery | Remote Services | Data from Local System | 1 Non-Standard Port | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | Rootkit | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 1 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 1 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
⊘No configs have been found
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
44% | ReversingLabs | Linux.Trojan.Mirai | ||
100% | Avira | EXP/ELF.Agent.J.8 |
⊘No Antivirus matches
⊘No Antivirus matches
⊘No Antivirus matches
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
raw.awaken-network.net | 141.98.10.142 | true | false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
141.98.10.142 | raw.awaken-network.net | Lithuania | 209605 | HOSTBALTICLT | false |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
141.98.10.142 | Get hash | malicious | Unknown | Browse | ||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Mirai | Browse |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
raw.awaken-network.net | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
HOSTBALTICLT | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
|
⊘No context
⊘No context
Process: | /tmp/Aqua.mips.elf |
File Type: | |
Category: | dropped |
Size (bytes): | 1 |
Entropy (8bit): | 0.0 |
Encrypted: | false |
SSDEEP: | 3:I:I |
MD5: | 336D5EBC5436534E61D16E63DDFCA327 |
SHA1: | 3BC15C8AAE3E4124DD409035F32EA2FD6835EFC9 |
SHA-256: | 3973E022E93220F9212C18D0D0C543AE7C309E46640DA93A4A0314DE999F5112 |
SHA-512: | 7C0B0D99A6E4C33CDA0F6F63547F878F4DD9F486DFE5D0446CE004B1C0FF28F191FF86F5D5933D3614CCEEE6FBBDC17E658881D3A164DFA5D6F4C699B2126E3D |
Malicious: | false |
Reputation: | moderate, very likely benign file |
Preview: |
Process: | /tmp/Aqua.mips.elf |
File Type: | |
Category: | dropped |
Size (bytes): | 20 |
Entropy (8bit): | 3.8219280948873617 |
Encrypted: | false |
SSDEEP: | 3:TgHWCln:Tg2m |
MD5: | 7C1C2A855F7346BEB3412DAC92CA29EB |
SHA1: | B0DAE3E8186B8040BF99333FABEEFA88104ECBEA |
SHA-256: | 3109E2EEE33B8847B1DA4A378A40A21356F3197E8574EB963B9EFE8EE77D8A30 |
SHA-512: | 6F32B319F32B07A7C310DE48B63C81866393CCBBD5AE0AC2D49E475AFB430E779EEB2DDEA51B6AD1B536533C8D5A188AA01C61010513A9A7358BC8837F0361D5 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | /tmp/Aqua.mips.elf |
File Type: | |
Category: | dropped |
Size (bytes): | 29 |
Entropy (8bit): | 4.1852301329094015 |
Encrypted: | false |
SSDEEP: | 3:TgHWCL8HJN:Tg2BJN |
MD5: | 5DE8DFDDC7FAB7288CAFB40F58749EFE |
SHA1: | E57A6BA66AE8E362D2683846F616A6693D95A81D |
SHA-256: | E8AEB1E3E141F734EC9A546B30945CF93CBCB58DBCB931216DCE3C1F467035B2 |
SHA-512: | 37F922569AEAEEB3DF5DBB21F0C9E91C41575A5B2CCBFC188DA1562F62F6499A7699FB0BE5476D4FF43267D96983A45740FE7C931A8AE9ACE5600F5B1DFE0635 |
Malicious: | false |
Reputation: | moderate, very likely benign file |
Preview: |
Process: | /tmp/Aqua.mips.elf |
File Type: | |
Category: | dropped |
Size (bytes): | 155 |
Entropy (8bit): | 2.6507616894286024 |
Encrypted: | false |
SSDEEP: | 3:FXHYRIgHWrVBdSRVFvve/FNvN:tH8Ig2rVWRVQ/1 |
MD5: | 4357E2850F800B67FCDC4673C2455AB4 |
SHA1: | D1E9179A0E0D5BB648861F22A8DB343AF65111A9 |
SHA-256: | E71F24F92A75BBC693B9A04637DE24CFDB43034AD71C3578F3B45B329619A2E2 |
SHA-512: | F09C42DFE27B78C704A49411612A4B2CDB724C7A21F613B8C1319A685932B0440F17537E7DBA96F2D13D3F9432036D9B8CB0A01CB4C33717273A5733EFAC15A9 |
Malicious: | false |
Reputation: | low |
Preview: |
File type: | |
Entropy (8bit): | 4.954997360837761 |
TrID: |
|
File name: | Aqua.mips.elf |
File size: | 179'060 bytes |
MD5: | fa343b55a035ec979f545e97986f01d8 |
SHA1: | 526c716ea09e3d65a5272c88a4fc37a46099cb17 |
SHA256: | d4929acb602dfb610d7c016a3f2db312433dca5eefeb36c12da77e7baaf37559 |
SHA512: | 6f16eacb55feb23ea961c0b5507faab16c7c0126e4a135d30c15d2f7cc8635e12152d496a7c8ecfb3d5f60b7c89f93fd0351b8272fe1e41e17c129a1dc875a11 |
SSDEEP: | 1536:1KzIpOSt3H1jlk2rzNR9ahG6Ea04hLjYeVmHbiUbCsTdHr5o+Ui2g2PO:PpOkpJahG1aHhHwHbAmlo+Ui2g2PO |
TLSH: | A504A71E6E228F7EF668C73147B74D209B5C33D616E1DA44E2ACC2105F6068E645FFA8 |
File Content Preview: | .ELF.....................@.`...4...D.....4. ...(.............@...@....R@..R@..............`..F`..F`...X.............dt.Q............................<...'.-<...!'.......................<...'.-....!...$....'9... ......................<...'.,....!... ....'9+ |
ELF header | |
---|---|
Class: | |
Data: | |
Version: | |
Machine: | |
Version Number: | |
Type: | |
OS/ABI: | |
ABI Version: | 0 |
Entry Point Address: | |
Flags: | |
ELF Header Size: | 52 |
Program Header Offset: | 52 |
Program Header Size: | 32 |
Number of Program Headers: | 3 |
Section Header Offset: | 178500 |
Section Header Size: | 40 |
Number of Section Headers: | 14 |
Header String Table Index: | 13 |
Name | Type | Address | Offset | Size | EntSize | Flags | Flags Description | Link | Info | Align |
---|---|---|---|---|---|---|---|---|---|---|
NULL | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0 | 0 | 0 | ||
.init | PROGBITS | 0x400094 | 0x94 | 0x8c | 0x0 | 0x6 | AX | 0 | 0 | 4 |
.text | PROGBITS | 0x400120 | 0x120 | 0x22b00 | 0x0 | 0x6 | AX | 0 | 0 | 16 |
.fini | PROGBITS | 0x422c20 | 0x22c20 | 0x5c | 0x0 | 0x6 | AX | 0 | 0 | 4 |
.rodata | PROGBITS | 0x422c80 | 0x22c80 | 0x25c0 | 0x0 | 0x2 | A | 0 | 0 | 16 |
.ctors | PROGBITS | 0x466000 | 0x26000 | 0xc | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.dtors | PROGBITS | 0x46600c | 0x2600c | 0x8 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.data.rel.ro | PROGBITS | 0x466018 | 0x26018 | 0x4a0 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.data | PROGBITS | 0x4664c0 | 0x264c0 | 0x4920 | 0x0 | 0x3 | WA | 0 | 0 | 32 |
.got | PROGBITS | 0x46ade0 | 0x2ade0 | 0xb00 | 0x4 | 0x10000003 | WAp | 0 | 0 | 16 |
.sbss | NOBITS | 0x46b8e0 | 0x2b8e0 | 0x50 | 0x0 | 0x10000003 | WAp | 0 | 0 | 4 |
.bss | NOBITS | 0x46b930 | 0x2b8e0 | 0x46b0 | 0x0 | 0x3 | WA | 0 | 0 | 16 |
.mdebug.abi32 | PROGBITS | 0x139e | 0x2b8e0 | 0x0 | 0x0 | 0x0 | 0 | 0 | 1 | |
.shstrtab | STRTAB | 0x0 | 0x2b8e0 | 0x64 | 0x0 | 0x0 | 0 | 0 | 1 |
Type | Offset | Virtual Address | Physical Address | File Size | Memory Size | Entropy | Flags | Flags Description | Align | Prog Interpreter | Section Mappings |
---|---|---|---|---|---|---|---|---|---|---|---|
LOAD | 0x0 | 0x400000 | 0x400000 | 0x25240 | 0x25240 | 5.4062 | 0x5 | R E | 0x10000 | .init .text .fini .rodata | |
LOAD | 0x26000 | 0x466000 | 0x466000 | 0x58e0 | 0x9fe0 | 1.3264 | 0x6 | RW | 0x10000 | .ctors .dtors .data.rel.ro .data .got .sbss .bss | |
GNU_STACK | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0.0000 | 0x7 | RWE | 0x4 |
Download Network PCAP: filtered – full
- Total Packets: 20
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Mar 26, 2025 23:24:11.012428045 CET | 46862 | 2211 | 192.168.2.15 | 141.98.10.142 |
Mar 26, 2025 23:24:11.198084116 CET | 2211 | 46862 | 141.98.10.142 | 192.168.2.15 |
Mar 26, 2025 23:24:11.198322058 CET | 46862 | 2211 | 192.168.2.15 | 141.98.10.142 |
Mar 26, 2025 23:24:11.199667931 CET | 46862 | 2211 | 192.168.2.15 | 141.98.10.142 |
Mar 26, 2025 23:24:11.385358095 CET | 2211 | 46862 | 141.98.10.142 | 192.168.2.15 |
Mar 26, 2025 23:24:11.385576010 CET | 46862 | 2211 | 192.168.2.15 | 141.98.10.142 |
Mar 26, 2025 23:24:11.570776939 CET | 2211 | 46862 | 141.98.10.142 | 192.168.2.15 |
Mar 26, 2025 23:24:26.617046118 CET | 2211 | 46862 | 141.98.10.142 | 192.168.2.15 |
Mar 26, 2025 23:24:26.617434978 CET | 46862 | 2211 | 192.168.2.15 | 141.98.10.142 |
Mar 26, 2025 23:24:41.804734945 CET | 2211 | 46862 | 141.98.10.142 | 192.168.2.15 |
Mar 26, 2025 23:24:41.805088043 CET | 46862 | 2211 | 192.168.2.15 | 141.98.10.142 |
Mar 26, 2025 23:24:56.992937088 CET | 2211 | 46862 | 141.98.10.142 | 192.168.2.15 |
Mar 26, 2025 23:24:56.993371964 CET | 46862 | 2211 | 192.168.2.15 | 141.98.10.142 |
Mar 26, 2025 23:25:12.185400963 CET | 2211 | 46862 | 141.98.10.142 | 192.168.2.15 |
Mar 26, 2025 23:25:12.185683012 CET | 46862 | 2211 | 192.168.2.15 | 141.98.10.142 |
Mar 26, 2025 23:25:21.244390965 CET | 46862 | 2211 | 192.168.2.15 | 141.98.10.142 |
Mar 26, 2025 23:25:21.429882050 CET | 2211 | 46862 | 141.98.10.142 | 192.168.2.15 |
Mar 26, 2025 23:25:31.249958992 CET | 46862 | 2211 | 192.168.2.15 | 141.98.10.142 |
Mar 26, 2025 23:25:31.435626984 CET | 2211 | 46862 | 141.98.10.142 | 192.168.2.15 |
Mar 26, 2025 23:25:46.488864899 CET | 2211 | 46862 | 141.98.10.142 | 192.168.2.15 |
Mar 26, 2025 23:25:46.489301920 CET | 46862 | 2211 | 192.168.2.15 | 141.98.10.142 |
Mar 26, 2025 23:25:55.794845104 CET | 2211 | 46862 | 141.98.10.142 | 192.168.2.15 |
Mar 26, 2025 23:25:56.977224112 CET | 46864 | 2211 | 192.168.2.15 | 141.98.10.142 |
Mar 26, 2025 23:25:57.157947063 CET | 2211 | 46864 | 141.98.10.142 | 192.168.2.15 |
Mar 26, 2025 23:25:57.158282995 CET | 46864 | 2211 | 192.168.2.15 | 141.98.10.142 |
Mar 26, 2025 23:25:57.160295010 CET | 46864 | 2211 | 192.168.2.15 | 141.98.10.142 |
Mar 26, 2025 23:25:57.341192961 CET | 2211 | 46864 | 141.98.10.142 | 192.168.2.15 |
Mar 26, 2025 23:25:57.341605902 CET | 46864 | 2211 | 192.168.2.15 | 141.98.10.142 |
Mar 26, 2025 23:25:57.522438049 CET | 2211 | 46864 | 141.98.10.142 | 192.168.2.15 |
Mar 26, 2025 23:26:12.525871038 CET | 2211 | 46864 | 141.98.10.142 | 192.168.2.15 |
Mar 26, 2025 23:26:12.526114941 CET | 46864 | 2211 | 192.168.2.15 | 141.98.10.142 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Mar 26, 2025 23:24:10.839607954 CET | 39838 | 53 | 192.168.2.15 | 8.8.8.8 |
Mar 26, 2025 23:24:10.924566984 CET | 53 | 39838 | 8.8.8.8 | 192.168.2.15 |
Mar 26, 2025 23:24:10.926469088 CET | 48119 | 53 | 192.168.2.15 | 8.8.8.8 |
Mar 26, 2025 23:24:11.011308908 CET | 53 | 48119 | 8.8.8.8 | 192.168.2.15 |
Mar 26, 2025 23:25:56.803594112 CET | 42503 | 53 | 192.168.2.15 | 8.8.8.8 |
Mar 26, 2025 23:25:56.888410091 CET | 53 | 42503 | 8.8.8.8 | 192.168.2.15 |
Mar 26, 2025 23:25:56.890816927 CET | 37448 | 53 | 192.168.2.15 | 8.8.8.8 |
Mar 26, 2025 23:25:56.975677013 CET | 53 | 37448 | 8.8.8.8 | 192.168.2.15 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Mar 26, 2025 23:24:10.839607954 CET | 192.168.2.15 | 8.8.8.8 | 0x8f9e | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 26, 2025 23:24:10.926469088 CET | 192.168.2.15 | 8.8.8.8 | 0x299a | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 26, 2025 23:25:56.803594112 CET | 192.168.2.15 | 8.8.8.8 | 0x12b | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 26, 2025 23:25:56.890816927 CET | 192.168.2.15 | 8.8.8.8 | 0x540e | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Mar 26, 2025 23:24:10.924566984 CET | 8.8.8.8 | 192.168.2.15 | 0x8f9e | No error (0) | 141.98.10.142 | A (IP address) | IN (0x0001) | false | ||
Mar 26, 2025 23:24:11.011308908 CET | 8.8.8.8 | 192.168.2.15 | 0x299a | No error (0) | 141.98.10.142 | A (IP address) | IN (0x0001) | false | ||
Mar 26, 2025 23:25:56.888410091 CET | 8.8.8.8 | 192.168.2.15 | 0x12b | No error (0) | 141.98.10.142 | A (IP address) | IN (0x0001) | false | ||
Mar 26, 2025 23:25:56.975677013 CET | 8.8.8.8 | 192.168.2.15 | 0x540e | No error (0) | 141.98.10.142 | A (IP address) | IN (0x0001) | false |
System Behavior
Start time (UTC): | 22:24:10 |
Start date (UTC): | 26/03/2025 |
Path: | /tmp/Aqua.mips.elf |
Arguments: | /tmp/Aqua.mips.elf |
File size: | 5777432 bytes |
MD5 hash: | 0083f1f0e77be34ad27f849842bbb00c |
Start time (UTC): | 22:24:10 |
Start date (UTC): | 26/03/2025 |
Path: | /tmp/Aqua.mips.elf |
Arguments: | - |
File size: | 5777432 bytes |
MD5 hash: | 0083f1f0e77be34ad27f849842bbb00c |