Loading ...

Play interactive tourEdit tour

Linux Analysis Report MPnFvIsvJp

Overview

General Information

Sample Name:MPnFvIsvJp
Analysis ID:507413
MD5:2af6167aa24d06f1795c507272d02916
SHA1:24092366777f504a441a27f3555ca64e00719528
SHA256:4c6ea0ba603fe0b1d8a97485afcf756d6e2a2630dfe18ee33353a17588924741
Tags:32elfmiraipowerpc
Infos:

Most interesting Screenshot:

Detection

Mirai
Score:72
Range:0 - 100
Whitelisted:false

Signatures

Snort IDS alert for network traffic (e.g. based on Emerging Threat rules)
Yara detected Mirai
Multi AV Scanner detection for submitted file
Uses known network protocols on non-standard ports
Sample tries to kill many processes (SIGKILL)
Sample has stripped symbol table
Uses the "uname" system call to query kernel version information (possible evasion)
Enumerates processes within the "proc" file system
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Detected TCP or UDP traffic on non-standard ports
Executes the "rm" command used to delete files or directories
Sample listens on a socket
Sample tries to kill a process (SIGKILL)

Classification

Analysis Advice

All HTTP servers contacted by the sample do not answer. Likely the sample is an old dropper which does no longer work
Static ELF header machine description suggests that the sample might not execute correctly on this machine

General Information

Joe Sandbox Version:33.0.0 White Diamond
Analysis ID:507413
Start date:22.10.2021
Start time:08:23:59
Joe Sandbox Product:CloudBasic
Overall analysis duration:0h 6m 43s
Hypervisor based Inspection enabled:false
Report type:light
Sample file name:MPnFvIsvJp
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Detection:MAL
Classification:mal72.spre.troj.lin@0/3@0/0
Warnings:
Show All
  • Report size exceeded maximum capacity and may have missing network information.
  • TCP Packets have been reduced to 100

Process Tree

  • system is lnxubuntu20
  • dash New Fork (PID: 5213, Parent: 4342)
  • cat (PID: 5213, Parent: 4342, MD5: 7e9d213e404ad3bb82e4ebb2e1f2c1b3) Arguments: cat /tmp/tmp.nd5wZIclrj
  • dash New Fork (PID: 5214, Parent: 4342)
  • head (PID: 5214, Parent: 4342, MD5: fd96a67145172477dd57131396fc9608) Arguments: head -n 10
  • dash New Fork (PID: 5215, Parent: 4342)
  • tr (PID: 5215, Parent: 4342, MD5: fbd1402dd9f72d8ebfff00ce7c3a7bb5) Arguments: tr -d \\000-\\011\\013\\014\\016-\\037
  • dash New Fork (PID: 5216, Parent: 4342)
  • cut (PID: 5216, Parent: 4342, MD5: d8ed0ea8f22c0de0f8692d4d9f1759d3) Arguments: cut -c -80
  • dash New Fork (PID: 5217, Parent: 4342)
  • cat (PID: 5217, Parent: 4342, MD5: 7e9d213e404ad3bb82e4ebb2e1f2c1b3) Arguments: cat /tmp/tmp.nd5wZIclrj
  • dash New Fork (PID: 5218, Parent: 4342)
  • head (PID: 5218, Parent: 4342, MD5: fd96a67145172477dd57131396fc9608) Arguments: head -n 10
  • dash New Fork (PID: 5219, Parent: 4342)
  • tr (PID: 5219, Parent: 4342, MD5: fbd1402dd9f72d8ebfff00ce7c3a7bb5) Arguments: tr -d \\000-\\011\\013\\014\\016-\\037
  • dash New Fork (PID: 5220, Parent: 4342)
  • cut (PID: 5220, Parent: 4342, MD5: d8ed0ea8f22c0de0f8692d4d9f1759d3) Arguments: cut -c -80
  • dash New Fork (PID: 5221, Parent: 4342)
  • rm (PID: 5221, Parent: 4342, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.nd5wZIclrj /tmp/tmp.zShyQQ7qTu /tmp/tmp.3SdD1ZBLJc
  • MPnFvIsvJp (PID: 5267, Parent: 5124, MD5: ae65271c943d3451b7f026d1fadccea6) Arguments: /tmp/MPnFvIsvJp
  • systemd New Fork (PID: 5307, Parent: 1)
  • sshd (PID: 5307, Parent: 1, MD5: dbca7a6bbf7bf57fedac243d4b2cb340) Arguments: /usr/sbin/sshd -t
  • systemd New Fork (PID: 5308, Parent: 1)
  • sshd (PID: 5308, Parent: 1, MD5: dbca7a6bbf7bf57fedac243d4b2cb340) Arguments: /usr/sbin/sshd -D
  • cleanup

Yara Overview

PCAP (Network Traffic)

SourceRuleDescriptionAuthorStrings
dump.pcapJoeSecurity_Mirai_12Yara detected MiraiJoe Security

    Jbx Signature Overview

    Click to jump to signature section

    Show All Signature Results

    AV Detection:

    barindex
    Multi AV Scanner detection for submitted fileShow sources
    Source: MPnFvIsvJpVirustotal: Detection: 50%Perma Link
    Source: MPnFvIsvJpReversingLabs: Detection: 58%

    Networking:

    barindex
    Snort IDS alert for network traffic (e.g. based on Emerging Threat rules)Show sources
    Source: TrafficSnort IDS: 716 INFO TELNET access 66.118.196.129:23 -> 192.168.2.23:36798
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 1.70.80.93:23 -> 192.168.2.23:60370
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 179.56.172.132:23 -> 192.168.2.23:49592
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 179.56.172.132:23 -> 192.168.2.23:49592
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 121.150.34.138:23 -> 192.168.2.23:52212
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 121.150.34.138:23 -> 192.168.2.23:52212
    Source: TrafficSnort IDS: 716 INFO TELNET access 66.118.196.129:23 -> 192.168.2.23:36930
    Source: TrafficSnort IDS: 716 INFO TELNET access 220.189.69.158:23 -> 192.168.2.23:40952
    Source: TrafficSnort IDS: 716 INFO TELNET access 220.189.69.158:23 -> 192.168.2.23:41016
    Source: TrafficSnort IDS: 716 INFO TELNET access 220.189.69.158:23 -> 192.168.2.23:41030
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 121.150.34.138:23 -> 192.168.2.23:52276
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 121.150.34.138:23 -> 192.168.2.23:52276
    Source: TrafficSnort IDS: 716 INFO TELNET access 220.189.69.158:23 -> 192.168.2.23:41038
    Source: TrafficSnort IDS: 716 INFO TELNET access 220.189.69.158:23 -> 192.168.2.23:41042
    Source: TrafficSnort IDS: 716 INFO TELNET access 220.189.69.158:23 -> 192.168.2.23:41062
    Source: TrafficSnort IDS: 716 INFO TELNET access 220.189.69.158:23 -> 192.168.2.23:41082
    Source: TrafficSnort IDS: 716 INFO TELNET access 220.189.69.158:23 -> 192.168.2.23:41094
    Source: TrafficSnort IDS: 716 INFO TELNET access 220.189.69.158:23 -> 192.168.2.23:41112
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 121.150.34.138:23 -> 192.168.2.23:52378
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 121.150.34.138:23 -> 192.168.2.23:52378
    Source: TrafficSnort IDS: 716 INFO TELNET access 220.189.69.158:23 -> 192.168.2.23:41132
    Source: TrafficSnort IDS: 2023448 ET TROJAN Possible Linux.Mirai Login Attempt (ubnt) 192.168.2.23:41132 -> 220.189.69.158:23
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 179.56.172.132:23 -> 192.168.2.23:49808
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 179.56.172.132:23 -> 192.168.2.23:49808
    Source: TrafficSnort IDS: 716 INFO TELNET access 211.115.228.149:23 -> 192.168.2.23:50968
    Source: TrafficSnort IDS: 716 INFO TELNET access 66.118.196.129:23 -> 192.168.2.23:37140
    Source: TrafficSnort IDS: 716 INFO TELNET access 89.135.36.164:23 -> 192.168.2.23:55640
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 121.150.34.138:23 -> 192.168.2.23:52440
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 121.150.34.138:23 -> 192.168.2.23:52440
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 89.135.36.164:23 -> 192.168.2.23:55640
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 89.135.36.164:23 -> 192.168.2.23:55640
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 113.26.230.147:23 -> 192.168.2.23:39150
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 70.35.225.138:23 -> 192.168.2.23:57216
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 70.35.225.138:23 -> 192.168.2.23:57216
    Source: TrafficSnort IDS: 716 INFO TELNET access 89.135.36.164:23 -> 192.168.2.23:55702
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 121.150.34.138:23 -> 192.168.2.23:52512
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 121.150.34.138:23 -> 192.168.2.23:52512
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 89.135.36.164:23 -> 192.168.2.23:55702
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 89.135.36.164:23 -> 192.168.2.23:55702
    Source: TrafficSnort IDS: 716 INFO TELNET access 89.135.36.164:23 -> 192.168.2.23:55736
    Source: TrafficSnort IDS: 716 INFO TELNET access 211.115.228.149:23 -> 192.168.2.23:51104
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 89.135.36.164:23 -> 192.168.2.23:55736
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 89.135.36.164:23 -> 192.168.2.23:55736
    Source: TrafficSnort IDS: 716 INFO TELNET access 66.118.196.129:23 -> 192.168.2.23:37274
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 121.150.34.138:23 -> 192.168.2.23:52560
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 121.150.34.138:23 -> 192.168.2.23:52560
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 179.56.172.132:23 -> 192.168.2.23:49962
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 179.56.172.132:23 -> 192.168.2.23:49962
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 216.123.69.13:23 -> 192.168.2.23:39930
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 216.123.69.13:23 -> 192.168.2.23:39930
    Source: TrafficSnort IDS: 716 INFO TELNET access 89.135.36.164:23 -> 192.168.2.23:55782
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 89.135.36.164:23 -> 192.168.2.23:55782
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 89.135.36.164:23 -> 192.168.2.23:55782
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 121.150.34.138:23 -> 192.168.2.23:52616
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 121.150.34.138:23 -> 192.168.2.23:52616
    Uses known network protocols on non-standard portsShow sources
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37764
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37768
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37770
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37772
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37774
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37776
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37780
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37782
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37794
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37796
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37784
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37798
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37804
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37806
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37808
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39468
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37816
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39474
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37814
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39476
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37822
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39480
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39486
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37828
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39488
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37834
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39492
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39496
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39498
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39502
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 54454
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 54458
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 54468
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 54470
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 54476
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 54478
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 54488
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 54494
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 54496
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 54500
    Source: global trafficTCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
    Source: global trafficTCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
    Source: global trafficTCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
    Source: global trafficTCP traffic: 192.168.2.23:44200 -> 176.126.175.188:1312
    Source: /tmp/MPnFvIsvJp (PID: 5270)Socket: 0.0.0.0::22
    Source: /tmp/MPnFvIsvJp (PID: 5270)Socket: 0.0.0.0::23
    Source: /tmp/MPnFvIsvJp (PID: 5270)Socket: 0.0.0.0::53413
    Source: /tmp/MPnFvIsvJp (PID: 5270)Socket: 0.0.0.0::80
    Source: /tmp/MPnFvIsvJp (PID: 5270)Socket: 0.0.0.0::52869
    Source: /tmp/MPnFvIsvJp (PID: 5270)Socket: 0.0.0.0::37215
    Source: /tmp/MPnFvIsvJp (PID: 5276)Socket: 0.0.0.0::0
    Source: /tmp/MPnFvIsvJp (PID: 5276)Socket: 0.0.0.0::23
    Source: /tmp/MPnFvIsvJp (PID: 5276)Socket: 0.0.0.0::53413
    Source: /tmp/MPnFvIsvJp (PID: 5276)Socket: 0.0.0.0::80
    Source: /tmp/MPnFvIsvJp (PID: 5276)Socket: 0.0.0.0::52869
    Source: /tmp/MPnFvIsvJp (PID: 5276)Socket: 0.0.0.0::37215
    Source: /usr/sbin/sshd (PID: 5308)Socket: [::]::22
    Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443
    Source: unknownTCP traffic detected without corresponding DNS query: 176.126.175.188
    Source: unknownTCP traffic detected without corresponding DNS query: 141.236.143.83
    Source: unknownTCP traffic detected without corresponding DNS query: 92.42.25.252
    Source: unknownTCP traffic detected without corresponding DNS query: 254.81.82.214
    Source: unknownTCP traffic detected without corresponding DNS query: 114.119.111.231
    Source: unknownTCP traffic detected without corresponding DNS query: 80.122.42.242
    Source: unknownTCP traffic detected without corresponding DNS query: 101.82.42.191
    Source: unknownTCP traffic detected without corresponding DNS query: 2.85.105.98
    Source: unknownTCP traffic detected without corresponding DNS query: 53.225.130.44
    Source: unknownTCP traffic detected without corresponding DNS query: 35.216.80.163
    Source: unknownTCP traffic detected without corresponding DNS query: 250.204.96.3
    Source: unknownTCP traffic detected without corresponding DNS query: 178.155.158.132
    Source: unknownTCP traffic detected without corresponding DNS query: 37.226.184.57
    Source: unknownTCP traffic detected without corresponding DNS query: 4.101.100.125
    Source: unknownTCP traffic detected without corresponding DNS query: 59.2.58.91
    Source: unknownTCP traffic detected without corresponding DNS query: 111.68.240.159
    Source: unknownTCP traffic detected without corresponding DNS query: 145.127.203.168
    Source: unknownTCP traffic detected without corresponding DNS query: 93.111.178.142
    Source: unknownTCP traffic detected without corresponding DNS query: 109.227.12.105
    Source: unknownTCP traffic detected without corresponding DNS query: 166.155.133.136
    Source: unknownTCP traffic detected without corresponding DNS query: 45.253.45.196
    Source: unknownTCP traffic detected without corresponding DNS query: 114.127.150.38
    Source: unknownTCP traffic detected without corresponding DNS query: 142.134.60.96
    Source: unknownTCP traffic detected without corresponding DNS query: 90.183.57.44
    Source: unknownTCP traffic detected without corresponding DNS query: 254.63.233.189
    Source: unknownTCP traffic detected without corresponding DNS query: 125.45.23.97
    Source: unknownTCP traffic detected without corresponding DNS query: 252.237.198.223
    Source: unknownTCP traffic detected without corresponding DNS query: 61.95.222.35
    Source: unknownTCP traffic detected without corresponding DNS query: 120.14.42.228
    Source: unknownTCP traffic detected without corresponding DNS query: 84.58.140.225
    Source: unknownTCP traffic detected without corresponding DNS query: 81.108.193.140
    Source: unknownTCP traffic detected without corresponding DNS query: 9.127.16.250
    Source: unknownTCP traffic detected without corresponding DNS query: 246.101.183.47
    Source: unknownTCP traffic detected without corresponding DNS query: 165.115.26.237
    Source: unknownTCP traffic detected without corresponding DNS query: 152.146.155.12
    Source: unknownTCP traffic detected without corresponding DNS query: 145.117.154.94
    Source: unknownTCP traffic detected without corresponding DNS query: 48.5.50.187
    Source: unknownTCP traffic detected without corresponding DNS query: 243.134.35.78
    Source: unknownTCP traffic detected without corresponding DNS query: 27.154.165.37
    Source: unknownTCP traffic detected without corresponding DNS query: 23.226.106.55
    Source: unknownTCP traffic detected without corresponding DNS query: 166.27.220.118
    Source: unknownTCP traffic detected without corresponding DNS query: 182.169.48.199
    Source: unknownTCP traffic detected without corresponding DNS query: 207.126.60.86
    Source: unknownTCP traffic detected without corresponding DNS query: 84.168.179.71
    Source: unknownTCP traffic detected without corresponding DNS query: 53.149.80.83
    Source: unknownTCP traffic detected without corresponding DNS query: 20.182.141.7
    Source: unknownTCP traffic detected without corresponding DNS query: 87.233.107.0
    Source: unknownTCP traffic detected without corresponding DNS query: 95.130.139.211
    Source: unknownTCP traffic detected without corresponding DNS query: 161.154.243.114
    Source: unknownTCP traffic detected without corresponding DNS query: 74.133.199.57
    Source: motd-news.18.drString found in binary or memory: https://ubuntu.com/blog/microk8s-memory-optimisation

    System Summary:

    barindex
    Sample tries to kill many processes (SIGKILL)Show sources
    Source: /tmp/MPnFvIsvJp (PID: 5276)SIGKILL sent: pid: 936, result: successful
    Source: /tmp/MPnFvIsvJp (PID: 5276)SIGKILL sent: pid: 5270, result: successful
    Source: /tmp/MPnFvIsvJp (PID: 5276)SIGKILL sent: pid: 720, result: successful
    Source: /tmp/MPnFvIsvJp (PID: 5276)SIGKILL sent: pid: 759, result: successful
    Source: /tmp/MPnFvIsvJp (PID: 5276)SIGKILL sent: pid: 788, result: successful
    Source: /tmp/MPnFvIsvJp (PID: 5276)SIGKILL sent: pid: 800, result: successful
    Source: /tmp/MPnFvIsvJp (PID: 5276)SIGKILL sent: pid: 847, result: successful
    Source: /tmp/MPnFvIsvJp (PID: 5276)SIGKILL sent: pid: 884, result: successful
    Source: /tmp/MPnFvIsvJp (PID: 5276)SIGKILL sent: pid: 1334, result: successful
    Source: /tmp/MPnFvIsvJp (PID: 5276)SIGKILL sent: pid: 1335, result: successful
    Source: /tmp/MPnFvIsvJp (PID: 5276)SIGKILL sent: pid: 1860, result: successful
    Source: /tmp/MPnFvIsvJp (PID: 5276)SIGKILL sent: pid: 1872, result: successful
    Source: /tmp/MPnFvIsvJp (PID: 5276)SIGKILL sent: pid: 2096, result: successful
    Source: /tmp/MPnFvIsvJp (PID: 5276)SIGKILL sent: pid: 2097, result: successful
    Source: /tmp/MPnFvIsvJp (PID: 5276)SIGKILL sent: pid: 2102, result: successful
    Source: /tmp/MPnFvIsvJp (PID: 5276)SIGKILL sent: pid: 2180, result: successful
    Source: /tmp/MPnFvIsvJp (PID: 5276)SIGKILL sent: pid: 2191, result: successful
    Source: /tmp/MPnFvIsvJp (PID: 5276)SIGKILL sent: pid: 2208, result: successful
    Source: ELF static info symbol of initial sample.symtab present: no
    Source: /tmp/MPnFvIsvJp (PID: 5276)SIGKILL sent: pid: 936, result: successful
    Source: /tmp/MPnFvIsvJp (PID: 5276)SIGKILL sent: pid: 5270, result: successful
    Source: /tmp/MPnFvIsvJp (PID: 5276)SIGKILL sent: pid: 720, result: successful
    Source: /tmp/MPnFvIsvJp (PID: 5276)SIGKILL sent: pid: 759, result: successful
    Source: /tmp/MPnFvIsvJp (PID: 5276)SIGKILL sent: pid: 788, result: successful
    Source: /tmp/MPnFvIsvJp (PID: 5276)SIGKILL sent: pid: 800, result: successful
    Source: /tmp/MPnFvIsvJp (PID: 5276)SIGKILL sent: pid: 847, result: successful
    Source: /tmp/MPnFvIsvJp (PID: 5276)SIGKILL sent: pid: 884, result: successful
    Source: /tmp/MPnFvIsvJp (PID: 5276)SIGKILL sent: pid: 1334, result: successful
    Source: /tmp/MPnFvIsvJp (PID: 5276)SIGKILL sent: pid: 1335, result: successful
    Source: /tmp/MPnFvIsvJp (PID: 5276)SIGKILL sent: pid: 1860, result: successful
    Source: /tmp/MPnFvIsvJp (PID: 5276)SIGKILL sent: pid: 1872, result: successful
    Source: /tmp/MPnFvIsvJp (PID: 5276)SIGKILL sent: pid: 2096, result: successful
    Source: /tmp/MPnFvIsvJp (PID: 5276)SIGKILL sent: pid: 2097, result: successful
    Source: /tmp/MPnFvIsvJp (PID: 5276)SIGKILL sent: pid: 2102, result: successful
    Source: /tmp/MPnFvIsvJp (PID: 5276)SIGKILL sent: pid: 2180, result: successful
    Source: /tmp/MPnFvIsvJp (PID: 5276)SIGKILL sent: pid: 2191, result: successful
    Source: /tmp/MPnFvIsvJp (PID: 5276)SIGKILL sent: pid: 2208, result: successful
    Source: classification engineClassification label: mal72.spre.troj.lin@0/3@0/0
    Source: MPnFvIsvJpJoe Sandbox Cloud Basic: Detection: clean Score: 0Perma Link
    Source: /tmp/MPnFvIsvJp (PID: 5276)File opened: /proc/2033/fd
    Source: /tmp/MPnFvIsvJp (PID: 5276)File opened: /proc/2033/exe
    Source: /tmp/MPnFvIsvJp (PID: 5276)File opened: /proc/1582/fd
    Source: /tmp/MPnFvIsvJp (PID: 5276)File opened: /proc/1582/exe
    Source: /tmp/MPnFvIsvJp (PID: 5276)File opened: /proc/2275/fd
    Source: /tmp/MPnFvIsvJp (PID: 5276)File opened: /proc/1612/fd
    Source: /tmp/MPnFvIsvJp (PID: 5276)File opened: /proc/1612/exe
    Source: /tmp/MPnFvIsvJp (PID: 5276)File opened: /proc/1579/fd
    Source: /tmp/MPnFvIsvJp (PID: 5276)File opened: /proc/1579/exe
    Source: /tmp/MPnFvIsvJp (PID: 5276)File opened: /proc/1699/fd
    Source: /tmp/MPnFvIsvJp (PID: 5276)File opened: /proc/1699/exe
    Source: /tmp/MPnFvIsvJp (PID: 5276)File opened: /proc/1335/fd
    Source: /tmp/MPnFvIsvJp (PID: 5276)File opened: /proc/1335/exe
    Source: /tmp/MPnFvIsvJp (PID: 5276)File opened: /proc/1698/fd
    Source: /tmp/MPnFvIsvJp (PID: 5276)File opened: /proc/1698/exe
    Source: /tmp/MPnFvIsvJp (PID: 5276)File opened: /proc/2028/fd
    Source: /tmp/MPnFvIsvJp (PID: 5276)File opened: /proc/2028/exe
    Source: /tmp/MPnFvIsvJp (PID: 5276)File opened: /proc/1334/fd
    Source: /tmp/MPnFvIsvJp (PID: 5276)File opened: /proc/1334/exe
    Source: /tmp/MPnFvIsvJp (PID: 5276)File opened: /proc/1576/fd
    Source: /tmp/MPnFvIsvJp (PID: 5276)File opened: /proc/1576/exe
    Source: /tmp/MPnFvIsvJp (PID: 5276)File opened: /proc/2302/fd
    Source: /tmp/MPnFvIsvJp (PID: 5276)File opened: /proc/3236/fd
    Source: /tmp/MPnFvIsvJp (PID: 5276)File opened: /proc/2025/fd
    Source: /tmp/MPnFvIsvJp (PID: 5276)File opened: /proc/2025/exe
    Source: /tmp/MPnFvIsvJp (PID: 5276)File opened: /proc/2146/fd
    Source: /tmp/MPnFvIsvJp (PID: 5276)File opened: /proc/2146/exe
    Source: /tmp/MPnFvIsvJp (PID: 5276)File opened: /proc/910/exe
    Source: /tmp/MPnFvIsvJp (PID: 5276)File opened: /proc/912/fd
    Source: /tmp/MPnFvIsvJp (PID: 5276)File opened: /proc/912/fd
    Source: /tmp/MPnFvIsvJp (PID: 5276)File opened: /proc/912/exe
    Source: /tmp/MPnFvIsvJp (PID: 5276)File opened: /proc/759/fd
    Source: /tmp/MPnFvIsvJp (PID: 5276)File opened: /proc/759/fd
    Source: /tmp/MPnFvIsvJp (PID: 5276)File opened: /proc/759/exe
    Source: /tmp/MPnFvIsvJp (PID: 5276)File opened: /proc/517/exe
    Source: /tmp/MPnFvIsvJp (PID: 5276)File opened: /proc/2307/fd
    Source: /tmp/MPnFvIsvJp (PID: 5276)File opened: /proc/918/fd
    Source: /tmp/MPnFvIsvJp (PID: 5276)File opened: /proc/918/fd
    Source: /tmp/MPnFvIsvJp (PID: 5276)File opened: /proc/918/exe
    Source: /tmp/MPnFvIsvJp (PID: 5276)File opened: /proc/1594/fd
    Source: /tmp/MPnFvIsvJp (PID: 5276)File opened: /proc/1594/exe
    Source: /tmp/MPnFvIsvJp (PID: 5276)File opened: /proc/2285/fd
    Source: /tmp/MPnFvIsvJp (PID: 5276)File opened: /proc/2281/fd
    Source: /tmp/MPnFvIsvJp (PID: 5276)File opened: /proc/5270/fd
    Source: /tmp/MPnFvIsvJp (PID: 5276)File opened: /proc/1349/fd
    Source: /tmp/MPnFvIsvJp (PID: 5276)File opened: /proc/1349/exe
    Source: /tmp/MPnFvIsvJp (PID: 5276)File opened: /proc/1/fd
    Source: /tmp/MPnFvIsvJp (PID: 5276)File opened: /proc/1/fd
    Source: /tmp/MPnFvIsvJp (PID: 5276)File opened: /proc/1623/fd
    Source: /tmp/MPnFvIsvJp (PID: 5276)File opened: /proc/1623/exe
    Source: /tmp/MPnFvIsvJp (PID: 5276)File opened: /proc/761/fd
    Source: /tmp/MPnFvIsvJp (PID: 5276)File opened: /proc/761/fd
    Source: /tmp/MPnFvIsvJp (PID: 5276)File opened: /proc/761/exe
    Source: /tmp/MPnFvIsvJp (PID: 5276)File opened: /proc/1622/fd
    Source: /tmp/MPnFvIsvJp (PID: 5276)File opened: /proc/1622/exe
    Source: /tmp/MPnFvIsvJp (PID: 5276)File opened: /proc/884/fd
    Source: /tmp/MPnFvIsvJp (PID: 5276)File opened: /proc/884/fd
    Source: /tmp/MPnFvIsvJp (PID: 5276)File opened: /proc/884/exe
    Source: /tmp/MPnFvIsvJp (PID: 5276)File opened: /proc/1983/fd
    Source: /tmp/MPnFvIsvJp (PID: 5276)File opened: /proc/1983/exe
    Source: /tmp/MPnFvIsvJp (PID: 5276)File opened: /proc/2038/fd
    Source: /tmp/MPnFvIsvJp (PID: 5276)File opened: /proc/2038/exe
    Source: /tmp/MPnFvIsvJp (PID: 5276)File opened: /proc/1586/fd
    Source: /tmp/MPnFvIsvJp (PID: 5276)File opened: /proc/1586/exe
    Source: /tmp/MPnFvIsvJp (PID: 5276)File opened: /proc/1465/fd
    Source: /tmp/MPnFvIsvJp (PID: 5276)File opened: /proc/1465/exe
    Source: /tmp/MPnFvIsvJp (PID: 5276)File opened: /proc/1344/fd
    Source: /tmp/MPnFvIsvJp (PID: 5276)File opened: /proc/1344/exe
    Source: /tmp/MPnFvIsvJp (PID: 5276)File opened: /proc/1860/fd
    Source: /tmp/MPnFvIsvJp (PID: 5276)File opened: /proc/1860/exe
    Source: /tmp/MPnFvIsvJp (PID: 5276)File opened: /proc/1463/fd
    Source: /tmp/MPnFvIsvJp (PID: 5276)File opened: /proc/1463/exe
    Source: /tmp/MPnFvIsvJp (PID: 5276)File opened: /proc/2156/fd
    Source: /tmp/MPnFvIsvJp (PID: 5276)File opened: /proc/2156/exe
    Source: /tmp/MPnFvIsvJp (PID: 5276)File opened: /proc/800/fd
    Source: /tmp/MPnFvIsvJp (PID: 5276)File opened: /proc/800/fd
    Source: /tmp/MPnFvIsvJp (PID: 5276)File opened: /proc/800/exe
    Source: /tmp/MPnFvIsvJp (PID: 5276)File opened: /proc/801/fd
    Source: /tmp/MPnFvIsvJp (PID: 5276)File opened: /proc/801/fd
    Source: /tmp/MPnFvIsvJp (PID: 5276)File opened: /proc/801/exe
    Source: /tmp/MPnFvIsvJp (PID: 5276)File opened: /proc/1629/fd
    Source: /tmp/MPnFvIsvJp (PID: 5276)File opened: /proc/1629/exe
    Source: /tmp/MPnFvIsvJp (PID: 5276)File opened: /proc/1627/fd
    Source: /tmp/MPnFvIsvJp (PID: 5276)File opened: /proc/1627/exe
    Source: /tmp/MPnFvIsvJp (PID: 5276)File opened: /proc/1900/fd
    Source: /tmp/MPnFvIsvJp (PID: 5276)File opened: /proc/1900/exe
    Source: /tmp/MPnFvIsvJp (PID: 5276)File opened: /proc/491/fd
    Source: /tmp/MPnFvIsvJp (PID: 5276)File opened: /proc/491/fd
    Source: /tmp/MPnFvIsvJp (PID: 5276)File opened: /proc/491/exe
    Source: /tmp/MPnFvIsvJp (PID: 5276)File opened: /proc/2294/fd
    Source: /tmp/MPnFvIsvJp (PID: 5276)File opened: /proc/2050/fd
    Source: /tmp/MPnFvIsvJp (PID: 5276)File opened: /proc/2050/exe
    Source: /tmp/MPnFvIsvJp (PID: 5276)File opened: /proc/1877/fd
    Source: /tmp/MPnFvIsvJp (PID: 5276)File opened: /proc/1877/exe
    Source: /tmp/MPnFvIsvJp (PID: 5276)File opened: /proc/772/fd
    Source: /tmp/MPnFvIsvJp (PID: 5276)File opened: /proc/772/fd
    Source: /tmp/MPnFvIsvJp (PID: 5276)File opened: /proc/772/exe
    Source: /tmp/MPnFvIsvJp (PID: 5276)File opened: /proc/1633/fd
    Source: /tmp/MPnFvIsvJp (PID: 5276)File opened: /proc/1633/exe
    Source: /tmp/MPnFvIsvJp (PID: 5276)File opened: /proc/1599/fd
    Source: /tmp/MPnFvIsvJp (PID: 5276)File opened: /proc/1599/exe
    Source: /tmp/MPnFvIsvJp (PID: 5276)File opened: /proc/1632/fd
    Source: /tmp/MPnFvIsvJp (PID: 5276)File opened: /proc/1632/exe
    Source: /tmp/MPnFvIsvJp (PID: 5276)File opened: /proc/1477/fd
    Source: /tmp/MPnFvIsvJp (PID: 5276)File opened: /proc/1477/exe
    Source: /usr/bin/dash (PID: 5221)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.nd5wZIclrj /tmp/tmp.zShyQQ7qTu /tmp/tmp.3SdD1ZBLJc

    Hooking and other Techniques for Hiding and Protection:

    barindex
    Uses known network protocols on non-standard portsShow sources
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37764
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37768
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37770
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37772
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37774
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37776
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37780
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37782
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37794
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37796
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37784
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37798
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37804
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37806
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37808
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39468
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37816
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39474
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37814
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39476
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37822
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39480
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39486
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37828
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39488
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37834
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39492
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39496
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39498
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39502
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 54454
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 54458
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 54468
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 54470
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 54476
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 54478
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 54488
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 54494
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 54496
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 54500
    Source: /tmp/MPnFvIsvJp (PID: 5267)Queries kernel information via 'uname':
    Source: MPnFvIsvJp, 5267.1.000000000d0936a4.000000009ef99e4c.rw-.sdmpBinary or memory string: !/etc/qemu-binfmt/ppc11!hotpluggableq
    Source: MPnFvIsvJp, 5270.1.000000000d0936a4.000000009ef99e4c.rw-.sdmpBinary or memory string: !/etc/qemu-binfmt/ppc1
    Source: MPnFvIsvJp, 5267.1.000000000d0936a4.000000009ef99e4c.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/ppc
    Source: MPnFvIsvJp, 5267.1.00000000c3376e66.00000000dbbd983f.rw-.sdmpBinary or memory string: /usr/bin/qemu-ppc
    Source: MPnFvIsvJp, 5267.1.00000000c3376e66.00000000dbbd983f.rw-.sdmpBinary or memory string: CJx86_64/usr/bin/qemu-ppc/tmp/MPnFvIsvJpSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/MPnFvIsvJp

    Stealing of Sensitive Information:

    barindex
    Yara detected MiraiShow sources
    Source: Yara matchFile source: dump.pcap, type: PCAP

    Remote Access Functionality:

    barindex
    Yara detected MiraiShow sources
    Source: Yara matchFile source: dump.pcap, type: PCAP

    Mitre Att&ck Matrix

    Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
    Valid AccountsWindows Management InstrumentationPath InterceptionPath InterceptionFile Deletion1OS Credential Dumping1Security Software Discovery11Remote ServicesData from Local SystemExfiltration Over Other Network MediumEncrypted Channel1Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
    Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over BluetoothNon-Standard Port11Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
    Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated ExfiltrationApplication Layer Protocol1Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data

    Malware Configuration

    No configs have been found

    Behavior Graph

    Hide Legend

    Legend:

    • Process
    • Signature
    • Created File
    • DNS/IP Info
    • Is Dropped
    • Number of created Files
    • Is malicious
    • Internet
    behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 507413 Sample: MPnFvIsvJp Startdate: 22/10/2021 Architecture: LINUX Score: 72 29 104.119.90.60 XO-AS15US United States 2->29 31 196.61.253.222 Web-Telecom-ServicesZA South Africa 2->31 33 98 other IPs or domains 2->33 35 Snort IDS alert for network traffic (e.g. based on Emerging Threat rules) 2->35 37 Multi AV Scanner detection for submitted file 2->37 39 Yara detected Mirai 2->39 41 Uses known network protocols on non-standard ports 2->41 8 dash rm MPnFvIsvJp 2->8         started        10 dash head 2->10         started        12 dash tr 2->12         started        14 8 other processes 2->14 signatures3 process4 process5 16 MPnFvIsvJp 8->16         started        18 MPnFvIsvJp 8->18         started        20 MPnFvIsvJp 8->20         started        process6 22 MPnFvIsvJp 16->22         started        25 MPnFvIsvJp 16->25         started        27 MPnFvIsvJp 16->27         started        signatures7 43 Sample tries to kill many processes (SIGKILL) 22->43

    Screenshots

    Thumbnails

    This section contains all screenshots as thumbnails, including those not shown in the slideshow.

    windows-stand

    Antivirus, Machine Learning and Genetic Malware Detection

    Initial Sample

    SourceDetectionScannerLabelLink
    MPnFvIsvJp50%VirustotalBrowse
    MPnFvIsvJp58%ReversingLabsLinux.Trojan.Mirai

    Dropped Files

    No Antivirus matches

    Domains

    No Antivirus matches

    URLs

    No Antivirus matches

    Domains and IPs

    Contacted Domains

    No contacted domains info

    URLs from Memory and Binaries

    NameSourceMaliciousAntivirus DetectionReputation
    https://ubuntu.com/blog/microk8s-memory-optimisationmotd-news.18.drfalse
      high

      Contacted IPs

      • No. of IPs < 25%
      • 25% < No. of IPs < 50%
      • 50% < No. of IPs < 75%
      • 75% < No. of IPs

      Public

      IPDomainCountryFlagASNASN NameMalicious
      53.112.165.99
      unknownGermany
      31399DAIMLER-ASITIGNGlobalNetworkDEfalse
      162.249.159.72
      unknownUnited States
      12177ETS-TELEPHONE-COMPANYUSfalse
      38.189.106.217
      unknownUnited States
      174COGENT-174USfalse
      146.117.193.114
      unknownunknown
      17477MCT-SYDNEYMacquarieTelecomAUfalse
      197.45.56.18
      unknownEgypt
      8452TE-ASTE-ASEGfalse
      79.112.91.127
      unknownRomania
      8708RCS-RDS73-75DrStaicoviciROfalse
      159.230.61.6
      unknownUnited States
      4922SHENTELUSfalse
      104.119.90.60
      unknownUnited States
      2828XO-AS15USfalse
      73.210.5.139
      unknownUnited States
      7922COMCAST-7922USfalse
      185.13.32.132
      unknownRussian Federation
      46844ST-BGPUSfalse
      95.195.139.140
      unknownSweden
      3301TELIANET-SWEDENTeliaCompanySEfalse
      109.142.99.132
      unknownBelgium
      5432PROXIMUS-ISP-ASBEfalse
      84.141.10.139
      unknownGermany
      3320DTAGInternetserviceprovideroperationsDEfalse
      2.144.217.201
      unknownIran (ISLAMIC Republic Of)
      44244IRANCELL-ASIRfalse
      254.124.160.89
      unknownReserved
      unknownunknownfalse
      157.72.111.104
      unknownJapan131932JEIS-NETJREastInformationSystemsCompanyJPfalse
      166.2.57.61
      unknownUnited States
      4152USDA-1USfalse
      196.98.136.157
      unknownKenya
      33771SAFARICOM-LIMITEDKEfalse
      105.214.52.124
      unknownSouth Africa
      16637MTNNS-ASZAfalse
      76.177.163.230
      unknownUnited States
      10796TWC-10796-MIDWESTUSfalse
      18.69.142.225
      unknownUnited States
      3MIT-GATEWAYSUSfalse
      47.253.16.98
      unknownUnited States
      45102CNNIC-ALIBABA-US-NET-APAlibabaUSTechnologyCoLtdCfalse
      222.209.131.174
      unknownChina
      4134CHINANET-BACKBONENo31Jin-rongStreetCNfalse
      118.144.105.142
      unknownChina
      4808CHINA169-BJChinaUnicomBeijingProvinceNetworkCNfalse
      73.26.71.206
      unknownUnited States
      7922COMCAST-7922USfalse
      216.44.168.130
      unknownUnited States
      22691ISPNET-1USfalse
      207.34.254.92
      unknownCanada
      852ASN852CAfalse
      109.236.158.185
      unknownGermany
      62023NYNEXDEfalse
      4.26.92.139
      unknownUnited States
      3356LEVEL3USfalse
      78.143.58.117
      unknownGermany
      34309LINK11Link11GmbHDEfalse
      158.255.70.161
      unknownFrance
      39104OXEVAFRfalse
      249.229.94.227
      unknownReserved
      unknownunknownfalse
      118.28.147.193
      unknownChina
      45090CNNIC-TENCENT-NET-APShenzhenTencentComputerSystemsCompafalse
      121.127.142.57
      unknownKorea Republic of
      9756CHEONANVITSSEN-AS-KRTbroadChungbuBroadcastingCoKRfalse
      82.231.167.86
      unknownFrance
      12322PROXADFRfalse
      90.252.197.202
      unknownUnited Kingdom
      5378VodafoneGBfalse
      207.176.202.218
      unknownUnited States
      3491BTN-ASNUSfalse
      18.30.10.250
      unknownUnited States
      3MIT-GATEWAYSUSfalse
      223.8.151.73
      unknownChina
      4134CHINANET-BACKBONENo31Jin-rongStreetCNfalse
      192.20.120.58
      unknownUnited States
      14153EDGECAST-IRUSfalse
      200.167.253.216
      unknownBrazil
      4230CLAROSABRfalse
      86.68.72.129
      unknownFrance
      15557LDCOMNETFRfalse
      213.146.201.32
      unknownPortugal
      5626ONIInternetServiceProviderPTfalse
      83.45.140.221
      unknownSpain
      3352TELEFONICA_DE_ESPANAESfalse
      152.26.195.240
      unknownUnited States
      81NCRENUSfalse
      221.0.56.164
      unknownChina
      4837CHINA169-BACKBONECHINAUNICOMChina169BackboneCNfalse
      133.55.183.163
      unknownJapan2907SINET-ASResearchOrganizationofInformationandSystemsNfalse
      2.17.213.1
      unknownEuropean Union
      16625AKAMAI-ASUSfalse
      248.29.159.14
      unknownReserved
      unknownunknownfalse
      41.152.76.213
      unknownEgypt
      36992ETISALAT-MISREGfalse
      201.19.52.194
      unknownBrazil
      7738TelemarNorteLesteSABRfalse
      240.42.170.232
      unknownReserved
      unknownunknownfalse
      139.156.150.80
      unknownNetherlands
      2497IIJInternetInitiativeJapanIncJPfalse
      118.64.199.38
      unknownChina
      4713OCNNTTCommunicationsCorporationJPfalse
      121.145.80.39
      unknownKorea Republic of
      4766KIXS-AS-KRKoreaTelecomKRfalse
      98.59.61.81
      unknownUnited States
      7922COMCAST-7922USfalse
      196.61.253.222
      unknownSouth Africa
      328029Web-Telecom-ServicesZAfalse
      205.153.15.252
      unknownUnited States
      209CENTURYLINK-US-LEGACY-QWESTUSfalse
      223.10.93.212
      unknownChina
      4134CHINANET-BACKBONENo31Jin-rongStreetCNfalse
      223.93.79.103
      unknownChina
      56041CMNET-ZHEJIANG-APChinaMobilecommunicationscorporationCfalse
      175.12.84.190
      unknownChina
      4134CHINANET-BACKBONENo31Jin-rongStreetCNfalse
      183.25.200.23
      unknownChina
      4134CHINANET-BACKBONENo31Jin-rongStreetCNfalse
      93.137.66.222
      unknownCroatia (LOCAL Name: Hrvatska)
      5391T-HTCroatianTelecomIncHRfalse
      189.40.178.46
      unknownBrazil
      26615TIMSABRfalse
      180.140.66.56
      unknownChina
      4134CHINANET-BACKBONENo31Jin-rongStreetCNfalse
      203.176.141.81
      unknownCambodia
      38235MEKONGNET-ADC-AS-APANGKORDATACOMMUNICATIONKHfalse
      45.146.92.203
      unknownGermany
      60781LEASEWEB-NL-AMS-01NetherlandsNLfalse
      19.197.93.3
      unknownUnited States
      3MIT-GATEWAYSUSfalse
      212.191.184.166
      unknownPoland
      16283LODMAN-AS2MetropolitanAreaNetworkLODMANPLfalse
      60.23.101.154
      unknownChina
      4837CHINA169-BACKBONECHINAUNICOMChina169BackboneCNfalse
      73.49.124.155
      unknownUnited States
      7922COMCAST-7922USfalse
      142.212.99.59
      unknownCanada
      13576SDNW-13576USfalse
      79.106.115.210
      unknownAlbania
      42313ALBTELECOM-ASALfalse
      32.251.50.182
      unknownUnited States
      2686ATGS-MMD-ASUSfalse
      253.83.161.80
      unknownReserved
      unknownunknownfalse
      17.208.85.231
      unknownUnited States
      714APPLE-ENGINEERINGUSfalse
      174.105.227.80
      unknownUnited States
      10796TWC-10796-MIDWESTUSfalse
      250.12.81.189
      unknownReserved
      unknownunknownfalse
      247.235.238.231
      unknownReserved
      unknownunknownfalse
      78.254.217.14
      unknownFrance
      12322PROXADFRfalse
      216.239.120.101
      unknownUnited States
      6623CBSI-1USfalse
      243.115.4.52
      unknownReserved
      unknownunknownfalse
      89.146.240.88
      unknownGermany
      8495INTERNET_AGFrankfurt-Munich-Stuttgart-Amsterdam-LondonDEfalse
      221.170.37.56
      unknownJapan2518BIGLOBEBIGLOBEIncJPfalse
      73.191.86.218
      unknownUnited States
      7922COMCAST-7922USfalse
      94.11.229.252
      unknownUnited Kingdom
      5607BSKYB-BROADBAND-ASGBfalse
      1.201.22.138
      unknownKorea Republic of
      38099KAKAO-AS-KRKakaoCorpKRfalse
      31.156.41.151
      unknownItaly
      30722VODAFONE-IT-ASNITfalse
      211.43.179.175
      unknownKorea Republic of
      7561SAMSUNGELEC-AS-KRSamsungElectronicsCoKRfalse
      120.202.209.113
      unknownChina
      9808CMNET-GDGuangdongMobileCommunicationCoLtdCNfalse
      186.106.106.120
      unknownChile
      7418TELEFONICACHILESACLfalse
      161.116.72.74
      unknownSpain
      13041CESCA-ACESfalse
      195.225.21.96
      unknownNorway
      25148BASEFARM-ASNOslo-NorwayNOfalse
      84.85.119.56
      unknownNetherlands
      1136KPNKPNNationalEUfalse
      184.169.138.101
      unknownUnited States
      16509AMAZON-02USfalse
      81.235.47.61
      unknownSweden
      3301TELIANET-SWEDENTeliaCompanySEfalse
      59.247.33.40
      unknownChina
      2516KDDIKDDICORPORATIONJPfalse
      62.76.192.45
      unknownRussian Federation
      200135FLEXSOFT-ASRUfalse
      178.179.16.172
      unknownRussian Federation
      25159SONICDUO-ASRUfalse
      23.26.94.58
      unknownUnited States
      11798ACEDATACENTERS-AS-1USfalse


      Runtime Messages

      Command:/tmp/MPnFvIsvJp
      Exit Code:0
      Exit Code Info:
      Killed:False
      Standard Output:
      Connected To CNC
      Standard Error:

      Joe Sandbox View / Context

      IPs

      MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
      95.195.139.140ZIB8Eu6SUWGet hashmaliciousBrowse
        118.144.105.142bqrHRKVNodGet hashmaliciousBrowse

          Domains

          No context

          ASN

          MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
          DAIMLER-ASITIGNGlobalNetworkDEUYnpKcFZ2sGet hashmaliciousBrowse
          • 53.55.173.225
          lQKil1R7D9Get hashmaliciousBrowse
          • 53.191.190.232
          oH6qNmnFRPGet hashmaliciousBrowse
          • 53.222.36.80
          Tf9ATzpdKRGet hashmaliciousBrowse
          • 53.15.248.186
          b3astmode.armGet hashmaliciousBrowse
          • 53.94.68.130
          b3astmode.arm7Get hashmaliciousBrowse
          • 53.229.195.214
          gjoqKYwnGGGet hashmaliciousBrowse
          • 53.60.141.114
          hNsTaM2BAuGet hashmaliciousBrowse
          • 53.209.76.80
          iSdOB1UKQvGet hashmaliciousBrowse
          • 53.6.170.177
          Kot3UfQMDmGet hashmaliciousBrowse
          • 53.117.49.110
          kMn6L4fH2TGet hashmaliciousBrowse
          • 53.231.244.12
          x86Get hashmaliciousBrowse
          • 53.82.162.71
          arm7Get hashmaliciousBrowse
          • 53.139.143.37
          arm7Get hashmaliciousBrowse
          • 53.125.154.192
          GRPVtMlbK5Get hashmaliciousBrowse
          • 53.251.116.245
          armGet hashmaliciousBrowse
          • 53.15.57.128
          S3LjnqUKlmGet hashmaliciousBrowse
          • 53.190.194.162
          7vmT7Q2se0Get hashmaliciousBrowse
          • 53.9.145.121
          ouMR5UDBpjGet hashmaliciousBrowse
          • 53.178.98.137
          sora.armGet hashmaliciousBrowse
          • 53.240.30.150
          COGENT-174UST4xP1S9FhzGet hashmaliciousBrowse
          • 38.219.169.128
          cosvgegE1SGet hashmaliciousBrowse
          • 204.240.223.118
          gKCq4VLpjLGet hashmaliciousBrowse
          • 38.57.190.29
          mkRkjGXjDJGet hashmaliciousBrowse
          • 149.121.17.196
          zYMp3detVOGet hashmaliciousBrowse
          • 204.7.106.123
          pLpqV3XZ76Get hashmaliciousBrowse
          • 2.58.5.255
          ggtS1fKIqXGet hashmaliciousBrowse
          • 198.242.181.102
          Tf9ATzpdKRGet hashmaliciousBrowse
          • 38.83.11.68
          b3astmode.arm7Get hashmaliciousBrowse
          • 38.10.205.211
          b3astmode.x86Get hashmaliciousBrowse
          • 206.84.234.163
          sora.x86Get hashmaliciousBrowse
          • 23.237.9.127
          sora.arm7Get hashmaliciousBrowse
          • 206.7.224.111
          p6j5MzMpDWGet hashmaliciousBrowse
          • 38.5.199.135
          tqQd9hibj0Get hashmaliciousBrowse
          • 38.142.152.59
          gjoqKYwnGGGet hashmaliciousBrowse
          • 38.174.109.106
          hNsTaM2BAuGet hashmaliciousBrowse
          • 38.219.109.6
          Shipping_docs190dk0lwt837.exeGet hashmaliciousBrowse
          • 154.23.172.72
          x86Get hashmaliciousBrowse
          • 38.220.172.141
          armGet hashmaliciousBrowse
          • 38.250.166.201
          JuofJwjQMTGet hashmaliciousBrowse
          • 38.218.17.35
          ETS-TELEPHONE-COMPANYUSOro00CeYE0Get hashmaliciousBrowse
          • 162.249.159.63
          1.shGet hashmaliciousBrowse
          • 162.217.40.164

          JA3 Fingerprints

          No context

          Dropped Files

          No context

          Created / dropped Files

          /proc/5308/oom_score_adj
          Process:/usr/sbin/sshd
          File Type:ASCII text
          Category:dropped
          Size (bytes):6
          Entropy (8bit):1.7924812503605778
          Encrypted:false
          SSDEEP:3:ptn:Dn
          MD5:CBF282CC55ED0792C33D10003D1F760A
          SHA1:007DD8BD75468E6B7ABA4285E9B267202C7EAEED
          SHA-256:FCDBAB99FCC0F4409E5F9D7D6FC497780288B4C441698126BB62832412774D22
          SHA-512:4643A8675D213C7DA35CC0C2BFB3B6F20324F9C48AEA7BA79F470615698C9A0CEFDA45CAA1957FC29110EE746BC8458AB8AB1E43EB513912A5E1E8858812CC00
          Malicious:false
          Reputation:high, very likely benign file
          Preview: -1000.
          /run/sshd.pid
          Process:/usr/sbin/sshd
          File Type:ASCII text
          Category:dropped
          Size (bytes):5
          Entropy (8bit):2.321928094887362
          Encrypted:false
          SSDEEP:3:DVdv:Jdv
          MD5:AF34BBE5A632AEFB5A6EDF64F8F26DA6
          SHA1:783857FEDC655D8822AED8FA0F1ABAA11B513FD9
          SHA-256:33B0D743AB15ABC049A46B5D5C68352F01F66D07AF7734E1F3AD459B4652C1C0
          SHA-512:0C13D42C8F6B55E2A344E7C90C80A62A3C70C377BF42586D4B527941D74C67ED735917F9E6905D354F18571FE00ECB2B8D0BF60CF8ABE0A6A7F23E79916EA40B
          Malicious:false
          Reputation:low
          Preview: 5308.
          /var/cache/motd-news
          Process:/usr/bin/cut
          File Type:ASCII text
          Category:dropped
          Size (bytes):191
          Entropy (8bit):4.515771857099866
          Encrypted:false
          SSDEEP:3:P2lnI+5MsqqzNLz+FRNScHUBfRau95++sZzR5woLB1Fh0VTGTl/X5kURn:OZ8uNLzDc0pR75+9Zz/woFmIT52URn
          MD5:DD514F892B5F93ED615D366E58AC58AF
          SHA1:BA75EDB3C2232CC260BC187F604DC8F25AA72C11
          SHA-256:F40D0DCE6E83DF74109FEF5E68E51CC255727783EEAE04C3E34677E23F7552CF
          SHA-512:9150BDE63F6C4850C5340D8877892B4D9BBF9EBDC98CDCF557A93FA304C1222CEE446418F5BE2ACCDBF38393778AFA5D4F3EDCB37A47BF57D3A4B2DEAD42A2D0
          Malicious:false
          Reputation:moderate, very likely benign file
          Preview: * Super-optimized for small spaces - read how we shrank the memory. footprint of MicroK8s to make it the smallest full K8s around... https://ubuntu.com/blog/microk8s-memory-optimisation.

          Static File Info

          General

          File type:ELF 32-bit MSB executable, PowerPC or cisco 4500, version 1 (SYSV), statically linked, stripped
          Entropy (8bit):6.25159913283433
          TrID:
          • ELF Executable and Linkable format (generic) (4004/1) 100.00%
          File name:MPnFvIsvJp
          File size:51604
          MD5:2af6167aa24d06f1795c507272d02916
          SHA1:24092366777f504a441a27f3555ca64e00719528
          SHA256:4c6ea0ba603fe0b1d8a97485afcf756d6e2a2630dfe18ee33353a17588924741
          SHA512:96c0db3f2db0c58cc109b4d3b99f087326091287f41041f420cf9039765a816a9a09115aa3e00413e64428cc6b2db177c03e7e2418b51adc64a71d65ec9694dc
          SSDEEP:768:opgPdUwOe1Po/7wni3RiAPSnPfDPKA2JjcRlgaizjrvVwipnpBX9QeA3:D1FOe1Po/kcExB9Mai6wvXeN3
          File Content Preview:.ELF...........................4.........4. ...(.......................................................t............dt.Q.............................!..|......$H...H......$8!. |...N.. .!..|.......?.............../...@..\?........+../...A..$8...})......N..

          Static ELF Info

          ELF header

          Class:ELF32
          Data:2's complement, big endian
          Version:1 (current)
          Machine:PowerPC
          Version Number:0x1
          Type:EXEC (Executable file)
          OS/ABI:UNIX - System V
          ABI Version:0
          Entry Point Address:0x100001f0
          Flags:0x0
          ELF Header Size:52
          Program Header Offset:52
          Program Header Size:32
          Number of Program Headers:3
          Section Header Offset:51124
          Section Header Size:40
          Number of Section Headers:12
          Header String Table Index:11

          Sections

          NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
          NULL0x00x00x00x00x0000
          .initPROGBITS0x100000940x940x240x00x6AX004
          .textPROGBITS0x100000b80xb80xbef40x00x6AX004
          .finiPROGBITS0x1000bfac0xbfac0x200x00x6AX004
          .rodataPROGBITS0x1000bfcc0xbfcc0x6240x00x2A004
          .ctorsPROGBITS0x1001c5f40xc5f40x80x00x3WA004
          .dtorsPROGBITS0x1001c5fc0xc5fc0x80x00x3WA004
          .dataPROGBITS0x1001c6080xc6080x1400x00x3WA008
          .sdataPROGBITS0x1001c7480xc7480x200x00x3WA004
          .sbssNOBITS0x1001c7680xc7680x740x00x3WA004
          .bssNOBITS0x1001c7dc0xc7680x20c0x00x3WA004
          .shstrtabSTRTAB0x00xc7680x4b0x00x0001

          Program Segments

          TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
          LOAD0x00x100000000x100000000xc5f00xc5f04.02840x5R E0x10000.init .text .fini .rodata
          LOAD0xc5f40x1001c5f40x1001c5f40x1740x3f40.37540x6RW 0x10000.ctors .dtors .data .sdata .sbss .bss
          GNU_STACK0x00x00x00x00x00.00000x6RW 0x4

          Network Behavior

          Network Port Distribution

          TCP Packets

          TimestampSource PortDest PortSource IPDest IP
          Oct 22, 2021 08:24:58.508336067 CEST442001312192.168.2.23176.126.175.188
          Oct 22, 2021 08:24:58.511778116 CEST2607723192.168.2.23141.236.143.83
          Oct 22, 2021 08:24:58.511840105 CEST2607723192.168.2.2392.42.25.252
          Oct 22, 2021 08:24:58.511845112 CEST2607723192.168.2.23254.81.82.214
          Oct 22, 2021 08:24:58.511847973 CEST2607723192.168.2.23114.119.111.231
          Oct 22, 2021 08:24:58.511873960 CEST2607723192.168.2.2380.122.42.242
          Oct 22, 2021 08:24:58.511884928 CEST2607723192.168.2.23101.82.42.191
          Oct 22, 2021 08:24:58.511924028 CEST2607723192.168.2.232.85.105.98
          Oct 22, 2021 08:24:58.514966011 CEST2607723192.168.2.2353.225.130.44
          Oct 22, 2021 08:24:58.514971018 CEST2607723192.168.2.2335.216.80.163
          Oct 22, 2021 08:24:58.515041113 CEST2607723192.168.2.23250.204.96.3
          Oct 22, 2021 08:24:58.515068054 CEST2607723192.168.2.23178.155.158.132
          Oct 22, 2021 08:24:58.515098095 CEST2607723192.168.2.2337.226.184.57
          Oct 22, 2021 08:24:58.515188932 CEST2607723192.168.2.234.101.100.125
          Oct 22, 2021 08:24:58.515202045 CEST2607723192.168.2.2359.2.58.91
          Oct 22, 2021 08:24:58.515206099 CEST2607723192.168.2.23111.68.240.159
          Oct 22, 2021 08:24:58.515213013 CEST2607723192.168.2.23145.127.203.168
          Oct 22, 2021 08:24:58.515214920 CEST2607723192.168.2.2393.111.178.142
          Oct 22, 2021 08:24:58.515218973 CEST2607723192.168.2.23109.227.12.105
          Oct 22, 2021 08:24:58.515221119 CEST2607723192.168.2.23166.155.133.136
          Oct 22, 2021 08:24:58.515222073 CEST2607723192.168.2.2345.253.45.196
          Oct 22, 2021 08:24:58.515228987 CEST2607723192.168.2.23114.127.150.38
          Oct 22, 2021 08:24:58.515233040 CEST2607723192.168.2.23142.134.60.96
          Oct 22, 2021 08:24:58.515235901 CEST2607723192.168.2.2390.183.57.44
          Oct 22, 2021 08:24:58.515243053 CEST2607723192.168.2.23165.210.212.161
          Oct 22, 2021 08:24:58.515249014 CEST2607723192.168.2.23254.63.233.189
          Oct 22, 2021 08:24:58.515249014 CEST2607723192.168.2.23125.45.23.97
          Oct 22, 2021 08:24:58.515254021 CEST2607723192.168.2.23252.237.198.223
          Oct 22, 2021 08:24:58.515259027 CEST2607723192.168.2.2361.95.222.35
          Oct 22, 2021 08:24:58.515259981 CEST2607723192.168.2.23120.14.42.228
          Oct 22, 2021 08:24:58.515261889 CEST2607723192.168.2.2384.58.140.225
          Oct 22, 2021 08:24:58.515263081 CEST2607723192.168.2.2381.108.193.140
          Oct 22, 2021 08:24:58.515269995 CEST2607723192.168.2.239.127.16.250
          Oct 22, 2021 08:24:58.515275002 CEST2607723192.168.2.23246.101.183.47
          Oct 22, 2021 08:24:58.515281916 CEST2607723192.168.2.23165.115.26.237
          Oct 22, 2021 08:24:58.515319109 CEST2607723192.168.2.23152.146.155.12
          Oct 22, 2021 08:24:58.515331030 CEST2607723192.168.2.23145.117.154.94
          Oct 22, 2021 08:24:58.515332937 CEST2607723192.168.2.23221.139.10.233
          Oct 22, 2021 08:24:58.515341043 CEST2607723192.168.2.2348.5.50.187
          Oct 22, 2021 08:24:58.515346050 CEST2607723192.168.2.23243.134.35.78
          Oct 22, 2021 08:24:58.515403986 CEST2607723192.168.2.2327.154.165.37
          Oct 22, 2021 08:24:58.515405893 CEST2607723192.168.2.2323.226.106.55
          Oct 22, 2021 08:24:58.515413046 CEST2607723192.168.2.23166.27.220.118
          Oct 22, 2021 08:24:58.515429020 CEST2607723192.168.2.23182.169.48.199
          Oct 22, 2021 08:24:58.515444040 CEST2607723192.168.2.23207.126.60.86
          Oct 22, 2021 08:24:58.515445948 CEST2607723192.168.2.2384.168.179.71
          Oct 22, 2021 08:24:58.515451908 CEST2607723192.168.2.2353.149.80.83
          Oct 22, 2021 08:24:58.515453100 CEST2607723192.168.2.2320.182.141.7
          Oct 22, 2021 08:24:58.515484095 CEST2607723192.168.2.2387.233.107.0
          Oct 22, 2021 08:24:58.515490055 CEST2607723192.168.2.2395.130.139.211
          Oct 22, 2021 08:24:58.515507936 CEST2607723192.168.2.23161.154.243.114
          Oct 22, 2021 08:24:58.515542984 CEST2607723192.168.2.2374.133.199.57
          Oct 22, 2021 08:24:58.515552998 CEST2607723192.168.2.23102.147.184.149
          Oct 22, 2021 08:24:58.515567064 CEST2607723192.168.2.23110.126.128.6
          Oct 22, 2021 08:24:58.515574932 CEST2607723192.168.2.23202.182.2.64
          Oct 22, 2021 08:24:58.515578985 CEST2607723192.168.2.23253.251.64.66
          Oct 22, 2021 08:24:58.515580893 CEST2607723192.168.2.2360.0.240.0
          Oct 22, 2021 08:24:58.515582085 CEST2607723192.168.2.2357.32.57.173
          Oct 22, 2021 08:24:58.515590906 CEST2607723192.168.2.2368.212.144.230
          Oct 22, 2021 08:24:58.515639067 CEST2607723192.168.2.2363.134.108.162
          Oct 22, 2021 08:24:58.515686035 CEST2607723192.168.2.23208.22.240.253
          Oct 22, 2021 08:24:58.515736103 CEST2607723192.168.2.23107.63.37.245
          Oct 22, 2021 08:24:58.515739918 CEST2607723192.168.2.23252.33.41.3
          Oct 22, 2021 08:24:58.515752077 CEST2607723192.168.2.2342.30.132.28
          Oct 22, 2021 08:24:58.515758991 CEST2607723192.168.2.23112.59.224.191
          Oct 22, 2021 08:24:58.515760899 CEST2607723192.168.2.23156.110.35.118
          Oct 22, 2021 08:24:58.515821934 CEST2607723192.168.2.23169.228.3.46
          Oct 22, 2021 08:24:58.517318010 CEST2607723192.168.2.23180.4.97.13
          Oct 22, 2021 08:24:58.517319918 CEST2607723192.168.2.2341.88.176.109
          Oct 22, 2021 08:24:58.517337084 CEST2607723192.168.2.23200.156.148.55
          Oct 22, 2021 08:24:58.517337084 CEST2607723192.168.2.23241.37.88.63
          Oct 22, 2021 08:24:58.517343044 CEST2607723192.168.2.23209.245.129.33
          Oct 22, 2021 08:24:58.517350912 CEST2607723192.168.2.23198.104.229.161
          Oct 22, 2021 08:24:58.517357111 CEST2607723192.168.2.2324.93.232.8
          Oct 22, 2021 08:24:58.517365932 CEST2607723192.168.2.2365.74.105.187
          Oct 22, 2021 08:24:58.517390013 CEST2607723192.168.2.2345.172.83.109
          Oct 22, 2021 08:24:58.517401934 CEST2607723192.168.2.2380.16.9.180
          Oct 22, 2021 08:24:58.517414093 CEST2607723192.168.2.2367.81.10.255
          Oct 22, 2021 08:24:58.517421007 CEST2607723192.168.2.2323.238.110.210
          Oct 22, 2021 08:24:58.517431021 CEST2607723192.168.2.232.114.211.24
          Oct 22, 2021 08:24:58.517432928 CEST2607723192.168.2.2392.244.88.114
          Oct 22, 2021 08:24:58.517435074 CEST2607723192.168.2.23154.165.254.179
          Oct 22, 2021 08:24:58.517436981 CEST2607723192.168.2.23102.91.68.49
          Oct 22, 2021 08:24:58.517437935 CEST2607723192.168.2.2398.101.39.112
          Oct 22, 2021 08:24:58.517496109 CEST2607723192.168.2.23217.254.156.206
          Oct 22, 2021 08:24:58.517501116 CEST2607723192.168.2.23205.177.212.78
          Oct 22, 2021 08:24:58.517508030 CEST2607723192.168.2.23201.123.193.162
          Oct 22, 2021 08:24:58.517510891 CEST2607723192.168.2.2353.134.81.62
          Oct 22, 2021 08:24:58.517520905 CEST2607723192.168.2.23113.226.100.169
          Oct 22, 2021 08:24:58.517525911 CEST2607723192.168.2.2382.186.17.221
          Oct 22, 2021 08:24:58.517527103 CEST2607723192.168.2.2393.119.5.238
          Oct 22, 2021 08:24:58.517535925 CEST2607723192.168.2.2354.17.236.221
          Oct 22, 2021 08:24:58.517556906 CEST2607723192.168.2.2399.38.146.253
          Oct 22, 2021 08:24:58.517633915 CEST2607723192.168.2.23101.157.12.73
          Oct 22, 2021 08:24:58.517647982 CEST2607723192.168.2.23121.156.210.245
          Oct 22, 2021 08:24:58.517652035 CEST2607723192.168.2.2369.96.225.50
          Oct 22, 2021 08:24:58.517652035 CEST2607723192.168.2.23162.245.15.163
          Oct 22, 2021 08:24:58.517663002 CEST2607723192.168.2.23120.191.201.111
          Oct 22, 2021 08:24:58.517680883 CEST2607723192.168.2.2320.76.113.197
          Oct 22, 2021 08:24:58.517693043 CEST2607723192.168.2.2345.208.146.73

          System Behavior

          General

          Start time:08:24:45
          Start date:22/10/2021
          Path:/usr/bin/dash
          Arguments:n/a
          File size:129816 bytes
          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

          General

          Start time:08:24:45
          Start date:22/10/2021
          Path:/usr/bin/cat
          Arguments:cat /tmp/tmp.nd5wZIclrj
          File size:43416 bytes
          MD5 hash:7e9d213e404ad3bb82e4ebb2e1f2c1b3

          General

          Start time:08:24:45
          Start date:22/10/2021
          Path:/usr/bin/dash
          Arguments:n/a
          File size:129816 bytes
          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

          General

          Start time:08:24:45
          Start date:22/10/2021
          Path:/usr/bin/head
          Arguments:head -n 10
          File size:47480 bytes
          MD5 hash:fd96a67145172477dd57131396fc9608

          General

          Start time:08:24:45
          Start date:22/10/2021
          Path:/usr/bin/dash
          Arguments:n/a
          File size:129816 bytes
          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

          General

          Start time:08:24:45
          Start date:22/10/2021
          Path:/usr/bin/tr
          Arguments:tr -d \\000-\\011\\013\\014\\016-\\037
          File size:51544 bytes
          MD5 hash:fbd1402dd9f72d8ebfff00ce7c3a7bb5

          General

          Start time:08:24:45
          Start date:22/10/2021
          Path:/usr/bin/dash
          Arguments:n/a
          File size:129816 bytes
          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

          General

          Start time:08:24:45
          Start date:22/10/2021
          Path:/usr/bin/cut
          Arguments:cut -c -80
          File size:47480 bytes
          MD5 hash:d8ed0ea8f22c0de0f8692d4d9f1759d3

          General

          Start time:08:24:46
          Start date:22/10/2021
          Path:/usr/bin/dash
          Arguments:n/a
          File size:129816 bytes
          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

          General

          Start time:08:24:46
          Start date:22/10/2021
          Path:/usr/bin/cat
          Arguments:cat /tmp/tmp.nd5wZIclrj
          File size:43416 bytes
          MD5 hash:7e9d213e404ad3bb82e4ebb2e1f2c1b3

          General

          Start time:08:24:46
          Start date:22/10/2021
          Path:/usr/bin/dash
          Arguments:n/a
          File size:129816 bytes
          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

          General

          Start time:08:24:46
          Start date:22/10/2021
          Path:/usr/bin/head
          Arguments:head -n 10
          File size:47480 bytes
          MD5 hash:fd96a67145172477dd57131396fc9608

          General

          Start time:08:24:46
          Start date:22/10/2021
          Path:/usr/bin/dash
          Arguments:n/a
          File size:129816 bytes
          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

          General

          Start time:08:24:46
          Start date:22/10/2021
          Path:/usr/bin/tr
          Arguments:tr -d \\000-\\011\\013\\014\\016-\\037
          File size:51544 bytes
          MD5 hash:fbd1402dd9f72d8ebfff00ce7c3a7bb5

          General

          Start time:08:24:46
          Start date:22/10/2021
          Path:/usr/bin/dash
          Arguments:n/a
          File size:129816 bytes
          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

          General

          Start time:08:24:46
          Start date:22/10/2021
          Path:/usr/bin/cut
          Arguments:cut -c -80
          File size:47480 bytes
          MD5 hash:d8ed0ea8f22c0de0f8692d4d9f1759d3

          General

          Start time:08:24:46
          Start date:22/10/2021
          Path:/usr/bin/dash
          Arguments:n/a
          File size:129816 bytes
          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

          General

          Start time:08:24:46
          Start date:22/10/2021
          Path:/usr/bin/rm
          Arguments:rm -f /tmp/tmp.nd5wZIclrj /tmp/tmp.zShyQQ7qTu /tmp/tmp.3SdD1ZBLJc
          File size:72056 bytes
          MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b

          General

          Start time:08:24:56
          Start date:22/10/2021
          Path:/tmp/MPnFvIsvJp
          Arguments:/tmp/MPnFvIsvJp
          File size:5388968 bytes
          MD5 hash:ae65271c943d3451b7f026d1fadccea6

          General

          Start time:08:24:57
          Start date:22/10/2021
          Path:/tmp/MPnFvIsvJp
          Arguments:n/a
          File size:5388968 bytes
          MD5 hash:ae65271c943d3451b7f026d1fadccea6

          General

          Start time:08:24:57
          Start date:22/10/2021
          Path:/tmp/MPnFvIsvJp
          Arguments:n/a
          File size:5388968 bytes
          MD5 hash:ae65271c943d3451b7f026d1fadccea6

          General

          Start time:08:24:57
          Start date:22/10/2021
          Path:/tmp/MPnFvIsvJp
          Arguments:n/a
          File size:5388968 bytes
          MD5 hash:ae65271c943d3451b7f026d1fadccea6

          General

          Start time:08:24:57
          Start date:22/10/2021
          Path:/tmp/MPnFvIsvJp
          Arguments:n/a
          File size:5388968 bytes
          MD5 hash:ae65271c943d3451b7f026d1fadccea6

          General

          Start time:08:24:57
          Start date:22/10/2021
          Path:/tmp/MPnFvIsvJp
          Arguments:n/a
          File size:5388968 bytes
          MD5 hash:ae65271c943d3451b7f026d1fadccea6

          General

          Start time:08:24:57
          Start date:22/10/2021
          Path:/tmp/MPnFvIsvJp
          Arguments:n/a
          File size:5388968 bytes
          MD5 hash:ae65271c943d3451b7f026d1fadccea6

          General

          Start time:08:25:11
          Start date:22/10/2021
          Path:/usr/lib/systemd/systemd
          Arguments:n/a
          File size:1620224 bytes
          MD5 hash:9b2bec7092a40488108543f9334aab75

          General

          Start time:08:25:11
          Start date:22/10/2021
          Path:/usr/sbin/sshd
          Arguments:/usr/sbin/sshd -t
          File size:876328 bytes
          MD5 hash:dbca7a6bbf7bf57fedac243d4b2cb340

          General

          Start time:08:25:11
          Start date:22/10/2021
          Path:/usr/lib/systemd/systemd
          Arguments:n/a
          File size:1620224 bytes
          MD5 hash:9b2bec7092a40488108543f9334aab75

          General

          Start time:08:25:11
          Start date:22/10/2021
          Path:/usr/sbin/sshd
          Arguments:/usr/sbin/sshd -D
          File size:876328 bytes
          MD5 hash:dbca7a6bbf7bf57fedac243d4b2cb340