Loading ...

Play interactive tourEdit tour

Linux Analysis Report Rpl2Twyrts

Overview

General Information

Sample Name:Rpl2Twyrts
Analysis ID:507421
MD5:4635e3761f10a21d01fec0df9fa36e2f
SHA1:a33d4b91fc25603b0ed98b17381f6a6e017f6c32
SHA256:91ccea41a26fce7feab89f9b17c889b9f7c37f29b5b5a9390a7d3f2990f43cfa
Tags:32elfmipsmirai
Infos:

Detection

Mirai
Score:72
Range:0 - 100
Whitelisted:false

Signatures

Snort IDS alert for network traffic (e.g. based on Emerging Threat rules)
Yara detected Mirai
Multi AV Scanner detection for submitted file
Uses known network protocols on non-standard ports
Sample tries to kill many processes (SIGKILL)
Sample has stripped symbol table
Uses the "uname" system call to query kernel version information (possible evasion)
Enumerates processes within the "proc" file system
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Detected TCP or UDP traffic on non-standard ports
Sample listens on a socket
Sample tries to kill a process (SIGKILL)

Classification

Analysis Advice

Static ELF header machine description suggests that the sample might only run correctly on MIPS or ARM architectures
All HTTP servers contacted by the sample do not answer. Likely the sample is an old dropper which does no longer work
Static ELF header machine description suggests that the sample might not execute correctly on this machine

General Information

Joe Sandbox Version:33.0.0 White Diamond
Analysis ID:507421
Start date:22.10.2021
Start time:08:36:22
Joe Sandbox Product:CloudBasic
Overall analysis duration:0h 5m 36s
Hypervisor based Inspection enabled:false
Report type:light
Sample file name:Rpl2Twyrts
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Detection:MAL
Classification:mal72.spre.troj.lin@0/2@0/0
Warnings:
Show All
  • Report size exceeded maximum capacity and may have missing network information.
  • TCP Packets have been reduced to 100

Process Tree

  • system is lnxubuntu20
  • Rpl2Twyrts (PID: 5246, Parent: 5121, MD5: 0d6f61f82cf2f781c6eb0661071d42d9) Arguments: /tmp/Rpl2Twyrts
  • systemd New Fork (PID: 5287, Parent: 1)
  • sshd (PID: 5287, Parent: 1, MD5: dbca7a6bbf7bf57fedac243d4b2cb340) Arguments: /usr/sbin/sshd -t
  • systemd New Fork (PID: 5290, Parent: 1)
  • sshd (PID: 5290, Parent: 1, MD5: dbca7a6bbf7bf57fedac243d4b2cb340) Arguments: /usr/sbin/sshd -D
  • cleanup

Yara Overview

PCAP (Network Traffic)

SourceRuleDescriptionAuthorStrings
dump.pcapJoeSecurity_Mirai_12Yara detected MiraiJoe Security

    Jbx Signature Overview

    Click to jump to signature section

    Show All Signature Results

    AV Detection:

    barindex
    Multi AV Scanner detection for submitted fileShow sources
    Source: Rpl2TwyrtsVirustotal: Detection: 50%Perma Link
    Source: Rpl2TwyrtsReversingLabs: Detection: 53%

    Networking:

    barindex
    Snort IDS alert for network traffic (e.g. based on Emerging Threat rules)Show sources
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 85.105.51.241:23 -> 192.168.2.23:33338
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 85.105.51.241:23 -> 192.168.2.23:33338
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 115.218.14.34:23 -> 192.168.2.23:41338
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 121.137.0.70:23 -> 192.168.2.23:34618
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 121.137.0.70:23 -> 192.168.2.23:34618
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 115.218.14.34:23 -> 192.168.2.23:41376
    Source: TrafficSnort IDS: 404 ICMP Destination Unreachable Protocol Unreachable 92.34.49.134: -> 192.168.2.23:
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 121.137.0.70:23 -> 192.168.2.23:34686
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 121.137.0.70:23 -> 192.168.2.23:34686
    Source: TrafficSnort IDS: 716 INFO TELNET access 178.207.232.219:23 -> 192.168.2.23:43666
    Source: TrafficSnort IDS: 716 INFO TELNET access 178.207.232.219:23 -> 192.168.2.23:43694
    Source: TrafficSnort IDS: 716 INFO TELNET access 178.207.232.219:23 -> 192.168.2.23:43696
    Source: TrafficSnort IDS: 716 INFO TELNET access 178.207.232.219:23 -> 192.168.2.23:43730
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 121.137.0.70:23 -> 192.168.2.23:34742
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 121.137.0.70:23 -> 192.168.2.23:34742
    Source: TrafficSnort IDS: 716 INFO TELNET access 178.207.232.219:23 -> 192.168.2.23:43736
    Source: TrafficSnort IDS: 716 INFO TELNET access 178.207.232.219:23 -> 192.168.2.23:43746
    Source: TrafficSnort IDS: 716 INFO TELNET access 178.207.232.219:23 -> 192.168.2.23:43752
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 85.105.51.241:23 -> 192.168.2.23:33544
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 85.105.51.241:23 -> 192.168.2.23:33544
    Source: TrafficSnort IDS: 716 INFO TELNET access 178.207.232.219:23 -> 192.168.2.23:43762
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 117.141.39.60:23 -> 192.168.2.23:34908
    Source: TrafficSnort IDS: 716 INFO TELNET access 178.207.232.219:23 -> 192.168.2.23:43772
    Source: TrafficSnort IDS: 716 INFO TELNET access 178.207.232.219:23 -> 192.168.2.23:43782
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 121.137.0.70:23 -> 192.168.2.23:34832
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 121.137.0.70:23 -> 192.168.2.23:34832
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 219.85.186.111:23 -> 192.168.2.23:41952
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 219.85.186.111:23 -> 192.168.2.23:41952
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 117.141.39.60:23 -> 192.168.2.23:34954
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 121.137.0.70:23 -> 192.168.2.23:34874
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 121.137.0.70:23 -> 192.168.2.23:34874
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 219.85.186.111:23 -> 192.168.2.23:42000
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 219.85.186.111:23 -> 192.168.2.23:42000
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 117.141.39.60:23 -> 192.168.2.23:35004
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 117.141.39.60:23 -> 192.168.2.23:35022
    Source: TrafficSnort IDS: 716 INFO TELNET access 61.155.111.226:23 -> 192.168.2.23:43856
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 121.137.0.70:23 -> 192.168.2.23:34940
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 121.137.0.70:23 -> 192.168.2.23:34940
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 85.105.51.241:23 -> 192.168.2.23:33688
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 85.105.51.241:23 -> 192.168.2.23:33688
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 219.85.186.111:23 -> 192.168.2.23:42056
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 219.85.186.111:23 -> 192.168.2.23:42056
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 61.155.111.226:23 -> 192.168.2.23:43856
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 117.141.39.60:23 -> 192.168.2.23:35044
    Source: TrafficSnort IDS: 716 INFO TELNET access 61.155.111.226:23 -> 192.168.2.23:43872
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 79.134.5.70:23 -> 192.168.2.23:51930
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 79.134.5.70:23 -> 192.168.2.23:51930
    Source: TrafficSnort IDS: 716 INFO TELNET access 111.118.117.166:23 -> 192.168.2.23:59234
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 121.137.0.70:23 -> 192.168.2.23:34968
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 121.137.0.70:23 -> 192.168.2.23:34968
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 117.141.39.60:23 -> 192.168.2.23:35074
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 111.118.117.166:23 -> 192.168.2.23:59234
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 111.118.117.166:23 -> 192.168.2.23:59234
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 219.85.186.111:23 -> 192.168.2.23:42094
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 219.85.186.111:23 -> 192.168.2.23:42094
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 61.155.111.226:23 -> 192.168.2.23:43872
    Source: TrafficSnort IDS: 716 INFO TELNET access 61.155.111.226:23 -> 192.168.2.23:43920
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 79.134.5.70:23 -> 192.168.2.23:51964
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 79.134.5.70:23 -> 192.168.2.23:51964
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 121.137.0.70:23 -> 192.168.2.23:35000
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 121.137.0.70:23 -> 192.168.2.23:35000
    Source: TrafficSnort IDS: 716 INFO TELNET access 111.118.117.166:23 -> 192.168.2.23:59358
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 117.141.39.60:23 -> 192.168.2.23:35152
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 61.155.111.226:23 -> 192.168.2.23:43920
    Source: TrafficSnort IDS: 716 INFO TELNET access 121.190.249.90:23 -> 192.168.2.23:53378
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 219.85.186.111:23 -> 192.168.2.23:42210
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 219.85.186.111:23 -> 192.168.2.23:42210
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 111.118.117.166:23 -> 192.168.2.23:59358
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 111.118.117.166:23 -> 192.168.2.23:59358
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 121.190.249.90:23 -> 192.168.2.23:53378
    Source: TrafficSnort IDS: 716 INFO TELNET access 61.155.111.226:23 -> 192.168.2.23:44042
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 79.134.5.70:23 -> 192.168.2.23:52076
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 79.134.5.70:23 -> 192.168.2.23:52076
    Source: TrafficSnort IDS: 716 INFO TELNET access 121.190.249.90:23 -> 192.168.2.23:53420
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 121.137.0.70:23 -> 192.168.2.23:35136
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 121.137.0.70:23 -> 192.168.2.23:35136
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 121.190.249.90:23 -> 192.168.2.23:53420
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 61.155.111.226:23 -> 192.168.2.23:44042
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 85.105.51.241:23 -> 192.168.2.23:33888
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 85.105.51.241:23 -> 192.168.2.23:33888
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 181.114.224.143:23 -> 192.168.2.23:60320
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 181.114.224.143:23 -> 192.168.2.23:60320
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 117.141.39.60:23 -> 192.168.2.23:35240
    Source: TrafficSnort IDS: 716 INFO TELNET access 121.190.249.90:23 -> 192.168.2.23:53434
    Source: TrafficSnort IDS: 716 INFO TELNET access 111.118.117.166:23 -> 192.168.2.23:59424
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 121.190.249.90:23 -> 192.168.2.23:53434
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 219.85.186.111:23 -> 192.168.2.23:42274
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 219.85.186.111:23 -> 192.168.2.23:42274
    Source: TrafficSnort IDS: 716 INFO TELNET access 121.190.249.90:23 -> 192.168.2.23:53446
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 79.134.5.70:23 -> 192.168.2.23:52138
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 79.134.5.70:23 -> 192.168.2.23:52138
    Uses known network protocols on non-standard portsShow sources
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 47728
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 47732
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 47736
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 47744
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 47750
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 47754
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 47760
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 47764
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 47770
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 47778
    Source: global trafficTCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
    Source: global trafficTCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
    Source: global trafficTCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
    Source: global trafficTCP traffic: 192.168.2.23:44200 -> 176.126.175.188:1312
    Source: /tmp/Rpl2Twyrts (PID: 5248)Socket: 0.0.0.0::0
    Source: /tmp/Rpl2Twyrts (PID: 5248)Socket: 0.0.0.0::23
    Source: /tmp/Rpl2Twyrts (PID: 5248)Socket: 0.0.0.0::53413
    Source: /tmp/Rpl2Twyrts (PID: 5248)Socket: 0.0.0.0::80
    Source: /tmp/Rpl2Twyrts (PID: 5248)Socket: 0.0.0.0::52869
    Source: /tmp/Rpl2Twyrts (PID: 5248)Socket: 0.0.0.0::37215
    Source: /tmp/Rpl2Twyrts (PID: 5254)Socket: 0.0.0.0::0
    Source: /tmp/Rpl2Twyrts (PID: 5254)Socket: 0.0.0.0::23
    Source: /tmp/Rpl2Twyrts (PID: 5254)Socket: 0.0.0.0::53413
    Source: /tmp/Rpl2Twyrts (PID: 5254)Socket: 0.0.0.0::80
    Source: /tmp/Rpl2Twyrts (PID: 5254)Socket: 0.0.0.0::52869
    Source: /tmp/Rpl2Twyrts (PID: 5254)Socket: 0.0.0.0::37215
    Source: /usr/sbin/sshd (PID: 5290)Socket: 0.0.0.0::22
    Source: /usr/sbin/sshd (PID: 5290)Socket: [::]::22
    Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443
    Source: unknownTCP traffic detected without corresponding DNS query: 176.126.175.188
    Source: unknownTCP traffic detected without corresponding DNS query: 99.22.166.11
    Source: unknownTCP traffic detected without corresponding DNS query: 63.165.84.11
    Source: unknownTCP traffic detected without corresponding DNS query: 223.195.0.116
    Source: unknownTCP traffic detected without corresponding DNS query: 35.118.13.8
    Source: unknownTCP traffic detected without corresponding DNS query: 149.182.9.19
    Source: unknownTCP traffic detected without corresponding DNS query: 24.8.223.69
    Source: unknownTCP traffic detected without corresponding DNS query: 182.145.206.142
    Source: unknownTCP traffic detected without corresponding DNS query: 9.67.65.67
    Source: unknownTCP traffic detected without corresponding DNS query: 240.16.115.86
    Source: unknownTCP traffic detected without corresponding DNS query: 12.43.212.21
    Source: unknownTCP traffic detected without corresponding DNS query: 108.55.127.139
    Source: unknownTCP traffic detected without corresponding DNS query: 201.247.47.135
    Source: unknownTCP traffic detected without corresponding DNS query: 9.169.231.174
    Source: unknownTCP traffic detected without corresponding DNS query: 223.11.182.21
    Source: unknownTCP traffic detected without corresponding DNS query: 175.215.68.114
    Source: unknownTCP traffic detected without corresponding DNS query: 76.131.185.195
    Source: unknownTCP traffic detected without corresponding DNS query: 204.186.55.14
    Source: unknownTCP traffic detected without corresponding DNS query: 104.42.93.127
    Source: unknownTCP traffic detected without corresponding DNS query: 91.185.36.65
    Source: unknownTCP traffic detected without corresponding DNS query: 73.185.144.44
    Source: unknownTCP traffic detected without corresponding DNS query: 46.44.202.14
    Source: unknownTCP traffic detected without corresponding DNS query: 146.90.157.91
    Source: unknownTCP traffic detected without corresponding DNS query: 207.19.164.238
    Source: unknownTCP traffic detected without corresponding DNS query: 2.5.107.224
    Source: unknownTCP traffic detected without corresponding DNS query: 65.109.217.140
    Source: unknownTCP traffic detected without corresponding DNS query: 193.187.14.64
    Source: unknownTCP traffic detected without corresponding DNS query: 72.239.120.156
    Source: unknownTCP traffic detected without corresponding DNS query: 164.30.143.68
    Source: unknownTCP traffic detected without corresponding DNS query: 155.206.205.161
    Source: unknownTCP traffic detected without corresponding DNS query: 19.156.56.61
    Source: unknownTCP traffic detected without corresponding DNS query: 51.5.236.88
    Source: unknownTCP traffic detected without corresponding DNS query: 206.22.155.20
    Source: unknownTCP traffic detected without corresponding DNS query: 170.182.30.23
    Source: unknownTCP traffic detected without corresponding DNS query: 66.95.128.129
    Source: unknownTCP traffic detected without corresponding DNS query: 67.85.248.138
    Source: unknownTCP traffic detected without corresponding DNS query: 209.218.75.6
    Source: unknownTCP traffic detected without corresponding DNS query: 104.187.122.215
    Source: unknownTCP traffic detected without corresponding DNS query: 218.248.90.54
    Source: unknownTCP traffic detected without corresponding DNS query: 218.93.181.123
    Source: unknownTCP traffic detected without corresponding DNS query: 76.42.25.135
    Source: unknownTCP traffic detected without corresponding DNS query: 211.104.2.117
    Source: unknownTCP traffic detected without corresponding DNS query: 203.176.253.233
    Source: unknownTCP traffic detected without corresponding DNS query: 149.176.173.143
    Source: unknownTCP traffic detected without corresponding DNS query: 170.185.42.8
    Source: unknownTCP traffic detected without corresponding DNS query: 187.248.51.123
    Source: unknownTCP traffic detected without corresponding DNS query: 125.220.33.131
    Source: unknownTCP traffic detected without corresponding DNS query: 147.187.68.56
    Source: unknownTCP traffic detected without corresponding DNS query: 211.170.82.218
    Source: unknownTCP traffic detected without corresponding DNS query: 117.189.183.121

    System Summary:

    barindex
    Sample tries to kill many processes (SIGKILL)Show sources
    Source: /tmp/Rpl2Twyrts (PID: 5248)SIGKILL sent: pid: 936, result: successful
    Source: /tmp/Rpl2Twyrts (PID: 5254)SIGKILL sent: pid: 5248, result: successful
    Source: /tmp/Rpl2Twyrts (PID: 5254)SIGKILL sent: pid: 720, result: successful
    Source: /tmp/Rpl2Twyrts (PID: 5254)SIGKILL sent: pid: 759, result: successful
    Source: /tmp/Rpl2Twyrts (PID: 5254)SIGKILL sent: pid: 788, result: successful
    Source: /tmp/Rpl2Twyrts (PID: 5254)SIGKILL sent: pid: 800, result: successful
    Source: /tmp/Rpl2Twyrts (PID: 5254)SIGKILL sent: pid: 847, result: successful
    Source: /tmp/Rpl2Twyrts (PID: 5254)SIGKILL sent: pid: 884, result: successful
    Source: /tmp/Rpl2Twyrts (PID: 5254)SIGKILL sent: pid: 1334, result: successful
    Source: /tmp/Rpl2Twyrts (PID: 5254)SIGKILL sent: pid: 1335, result: successful
    Source: /tmp/Rpl2Twyrts (PID: 5254)SIGKILL sent: pid: 1860, result: successful
    Source: /tmp/Rpl2Twyrts (PID: 5254)SIGKILL sent: pid: 1872, result: successful
    Source: /tmp/Rpl2Twyrts (PID: 5254)SIGKILL sent: pid: 2096, result: successful
    Source: /tmp/Rpl2Twyrts (PID: 5254)SIGKILL sent: pid: 2097, result: successful
    Source: /tmp/Rpl2Twyrts (PID: 5254)SIGKILL sent: pid: 2102, result: successful
    Source: /tmp/Rpl2Twyrts (PID: 5254)SIGKILL sent: pid: 2180, result: successful
    Source: /tmp/Rpl2Twyrts (PID: 5254)SIGKILL sent: pid: 2191, result: successful
    Source: /tmp/Rpl2Twyrts (PID: 5254)SIGKILL sent: pid: 2208, result: successful
    Source: ELF static info symbol of initial sample.symtab present: no
    Source: /tmp/Rpl2Twyrts (PID: 5248)SIGKILL sent: pid: 936, result: successful
    Source: /tmp/Rpl2Twyrts (PID: 5254)SIGKILL sent: pid: 5248, result: successful
    Source: /tmp/Rpl2Twyrts (PID: 5254)SIGKILL sent: pid: 720, result: successful
    Source: /tmp/Rpl2Twyrts (PID: 5254)SIGKILL sent: pid: 759, result: successful
    Source: /tmp/Rpl2Twyrts (PID: 5254)SIGKILL sent: pid: 788, result: successful
    Source: /tmp/Rpl2Twyrts (PID: 5254)SIGKILL sent: pid: 800, result: successful
    Source: /tmp/Rpl2Twyrts (PID: 5254)SIGKILL sent: pid: 847, result: successful
    Source: /tmp/Rpl2Twyrts (PID: 5254)SIGKILL sent: pid: 884, result: successful
    Source: /tmp/Rpl2Twyrts (PID: 5254)SIGKILL sent: pid: 1334, result: successful
    Source: /tmp/Rpl2Twyrts (PID: 5254)SIGKILL sent: pid: 1335, result: successful
    Source: /tmp/Rpl2Twyrts (PID: 5254)SIGKILL sent: pid: 1860, result: successful
    Source: /tmp/Rpl2Twyrts (PID: 5254)SIGKILL sent: pid: 1872, result: successful
    Source: /tmp/Rpl2Twyrts (PID: 5254)SIGKILL sent: pid: 2096, result: successful
    Source: /tmp/Rpl2Twyrts (PID: 5254)SIGKILL sent: pid: 2097, result: successful
    Source: /tmp/Rpl2Twyrts (PID: 5254)SIGKILL sent: pid: 2102, result: successful
    Source: /tmp/Rpl2Twyrts (PID: 5254)SIGKILL sent: pid: 2180, result: successful
    Source: /tmp/Rpl2Twyrts (PID: 5254)SIGKILL sent: pid: 2191, result: successful
    Source: /tmp/Rpl2Twyrts (PID: 5254)SIGKILL sent: pid: 2208, result: successful
    Source: classification engineClassification label: mal72.spre.troj.lin@0/2@0/0
    Source: Rpl2TwyrtsJoe Sandbox Cloud Basic: Detection: clean Score: 0Perma Link
    Source: /tmp/Rpl2Twyrts (PID: 5254)File opened: /proc/5268/fd
    Source: /tmp/Rpl2Twyrts (PID: 5254)File opened: /proc/2033/fd
    Source: /tmp/Rpl2Twyrts (PID: 5254)File opened: /proc/2033/fd
    Source: /tmp/Rpl2Twyrts (PID: 5254)File opened: /proc/2033/exe
    Source: /tmp/Rpl2Twyrts (PID: 5254)File opened: /proc/1582/fd
    Source: /tmp/Rpl2Twyrts (PID: 5254)File opened: /proc/1582/fd
    Source: /tmp/Rpl2Twyrts (PID: 5254)File opened: /proc/1582/exe
    Source: /tmp/Rpl2Twyrts (PID: 5254)File opened: /proc/2275/fd
    Source: /tmp/Rpl2Twyrts (PID: 5254)File opened: /proc/2275/fd
    Source: /tmp/Rpl2Twyrts (PID: 5254)File opened: /proc/1612/fd
    Source: /tmp/Rpl2Twyrts (PID: 5254)File opened: /proc/1612/fd
    Source: /tmp/Rpl2Twyrts (PID: 5254)File opened: /proc/1612/exe
    Source: /tmp/Rpl2Twyrts (PID: 5254)File opened: /proc/1579/fd
    Source: /tmp/Rpl2Twyrts (PID: 5254)File opened: /proc/1579/fd
    Source: /tmp/Rpl2Twyrts (PID: 5254)File opened: /proc/1579/exe
    Source: /tmp/Rpl2Twyrts (PID: 5254)File opened: /proc/1699/fd
    Source: /tmp/Rpl2Twyrts (PID: 5254)File opened: /proc/1699/fd
    Source: /tmp/Rpl2Twyrts (PID: 5254)File opened: /proc/1699/exe
    Source: /tmp/Rpl2Twyrts (PID: 5254)File opened: /proc/1335/fd
    Source: /tmp/Rpl2Twyrts (PID: 5254)File opened: /proc/1335/fd
    Source: /tmp/Rpl2Twyrts (PID: 5254)File opened: /proc/1335/exe
    Source: /tmp/Rpl2Twyrts (PID: 5254)File opened: /proc/1698/fd
    Source: /tmp/Rpl2Twyrts (PID: 5254)File opened: /proc/1698/fd
    Source: /tmp/Rpl2Twyrts (PID: 5254)File opened: /proc/1698/exe
    Source: /tmp/Rpl2Twyrts (PID: 5254)File opened: /proc/2028/fd
    Source: /tmp/Rpl2Twyrts (PID: 5254)File opened: /proc/2028/fd
    Source: /tmp/Rpl2Twyrts (PID: 5254)File opened: /proc/2028/exe
    Source: /tmp/Rpl2Twyrts (PID: 5254)File opened: /proc/1334/fd
    Source: /tmp/Rpl2Twyrts (PID: 5254)File opened: /proc/1334/fd
    Source: /tmp/Rpl2Twyrts (PID: 5254)File opened: /proc/1334/exe
    Source: /tmp/Rpl2Twyrts (PID: 5254)File opened: /proc/1576/fd
    Source: /tmp/Rpl2Twyrts (PID: 5254)File opened: /proc/1576/fd
    Source: /tmp/Rpl2Twyrts (PID: 5254)File opened: /proc/1576/exe
    Source: /tmp/Rpl2Twyrts (PID: 5254)File opened: /proc/2302/fd
    Source: /tmp/Rpl2Twyrts (PID: 5254)File opened: /proc/2302/fd
    Source: /tmp/Rpl2Twyrts (PID: 5254)File opened: /proc/3236/fd
    Source: /tmp/Rpl2Twyrts (PID: 5254)File opened: /proc/3236/fd
    Source: /tmp/Rpl2Twyrts (PID: 5254)File opened: /proc/2025/fd
    Source: /tmp/Rpl2Twyrts (PID: 5254)File opened: /proc/2025/fd
    Source: /tmp/Rpl2Twyrts (PID: 5254)File opened: /proc/2025/exe
    Source: /tmp/Rpl2Twyrts (PID: 5254)File opened: /proc/2146/fd
    Source: /tmp/Rpl2Twyrts (PID: 5254)File opened: /proc/2146/fd
    Source: /tmp/Rpl2Twyrts (PID: 5254)File opened: /proc/2146/exe
    Source: /tmp/Rpl2Twyrts (PID: 5254)File opened: /proc/910/exe
    Source: /tmp/Rpl2Twyrts (PID: 5254)File opened: /proc/912/fd
    Source: /tmp/Rpl2Twyrts (PID: 5254)File opened: /proc/912/fd
    Source: /tmp/Rpl2Twyrts (PID: 5254)File opened: /proc/912/exe
    Source: /tmp/Rpl2Twyrts (PID: 5254)File opened: /proc/759/fd
    Source: /tmp/Rpl2Twyrts (PID: 5254)File opened: /proc/759/fd
    Source: /tmp/Rpl2Twyrts (PID: 5254)File opened: /proc/759/exe
    Source: /tmp/Rpl2Twyrts (PID: 5254)File opened: /proc/517/exe
    Source: /tmp/Rpl2Twyrts (PID: 5254)File opened: /proc/2307/fd
    Source: /tmp/Rpl2Twyrts (PID: 5254)File opened: /proc/2307/fd
    Source: /tmp/Rpl2Twyrts (PID: 5254)File opened: /proc/918/fd
    Source: /tmp/Rpl2Twyrts (PID: 5254)File opened: /proc/918/fd
    Source: /tmp/Rpl2Twyrts (PID: 5254)File opened: /proc/918/exe
    Source: /tmp/Rpl2Twyrts (PID: 5254)File opened: /proc/5272/fd
    Source: /tmp/Rpl2Twyrts (PID: 5254)File opened: /proc/5273/fd
    Source: /tmp/Rpl2Twyrts (PID: 5254)File opened: /proc/5274/fd
    Source: /tmp/Rpl2Twyrts (PID: 5254)File opened: /proc/5275/fd
    Source: /tmp/Rpl2Twyrts (PID: 5254)File opened: /proc/5276/fd
    Source: /tmp/Rpl2Twyrts (PID: 5254)File opened: /proc/5277/fd
    Source: /tmp/Rpl2Twyrts (PID: 5254)File opened: /proc/5278/fd
    Source: /tmp/Rpl2Twyrts (PID: 5254)File opened: /proc/5279/fd
    Source: /tmp/Rpl2Twyrts (PID: 5254)File opened: /proc/1594/fd
    Source: /tmp/Rpl2Twyrts (PID: 5254)File opened: /proc/1594/fd
    Source: /tmp/Rpl2Twyrts (PID: 5254)File opened: /proc/1594/exe
    Source: /tmp/Rpl2Twyrts (PID: 5254)File opened: /proc/2285/fd
    Source: /tmp/Rpl2Twyrts (PID: 5254)File opened: /proc/2285/fd
    Source: /tmp/Rpl2Twyrts (PID: 5254)File opened: /proc/2281/fd
    Source: /tmp/Rpl2Twyrts (PID: 5254)File opened: /proc/2281/fd
    Source: /tmp/Rpl2Twyrts (PID: 5254)File opened: /proc/5270/fd
    Source: /tmp/Rpl2Twyrts (PID: 5254)File opened: /proc/5271/fd
    Source: /tmp/Rpl2Twyrts (PID: 5254)File opened: /proc/1349/fd
    Source: /tmp/Rpl2Twyrts (PID: 5254)File opened: /proc/1349/fd
    Source: /tmp/Rpl2Twyrts (PID: 5254)File opened: /proc/1349/exe
    Source: /tmp/Rpl2Twyrts (PID: 5254)File opened: /proc/1/fd
    Source: /tmp/Rpl2Twyrts (PID: 5254)File opened: /proc/1/fd
    Source: /tmp/Rpl2Twyrts (PID: 5254)File opened: /proc/1623/fd
    Source: /tmp/Rpl2Twyrts (PID: 5254)File opened: /proc/1623/fd
    Source: /tmp/Rpl2Twyrts (PID: 5254)File opened: /proc/1623/exe
    Source: /tmp/Rpl2Twyrts (PID: 5254)File opened: /proc/761/fd
    Source: /tmp/Rpl2Twyrts (PID: 5254)File opened: /proc/761/fd
    Source: /tmp/Rpl2Twyrts (PID: 5254)File opened: /proc/761/exe
    Source: /tmp/Rpl2Twyrts (PID: 5254)File opened: /proc/1622/fd
    Source: /tmp/Rpl2Twyrts (PID: 5254)File opened: /proc/1622/fd
    Source: /tmp/Rpl2Twyrts (PID: 5254)File opened: /proc/1622/exe
    Source: /tmp/Rpl2Twyrts (PID: 5254)File opened: /proc/884/fd
    Source: /tmp/Rpl2Twyrts (PID: 5254)File opened: /proc/884/fd
    Source: /tmp/Rpl2Twyrts (PID: 5254)File opened: /proc/884/exe
    Source: /tmp/Rpl2Twyrts (PID: 5254)File opened: /proc/1983/fd
    Source: /tmp/Rpl2Twyrts (PID: 5254)File opened: /proc/1983/fd
    Source: /tmp/Rpl2Twyrts (PID: 5254)File opened: /proc/1983/exe
    Source: /tmp/Rpl2Twyrts (PID: 5254)File opened: /proc/2038/fd
    Source: /tmp/Rpl2Twyrts (PID: 5254)File opened: /proc/2038/fd
    Source: /tmp/Rpl2Twyrts (PID: 5254)File opened: /proc/2038/exe
    Source: /tmp/Rpl2Twyrts (PID: 5254)File opened: /proc/1586/fd
    Source: /tmp/Rpl2Twyrts (PID: 5254)File opened: /proc/1586/fd
    Source: /tmp/Rpl2Twyrts (PID: 5254)File opened: /proc/1586/exe
    Source: /tmp/Rpl2Twyrts (PID: 5254)File opened: /proc/1465/fd
    Source: /tmp/Rpl2Twyrts (PID: 5254)File opened: /proc/1465/fd
    Source: /tmp/Rpl2Twyrts (PID: 5254)File opened: /proc/1465/exe
    Source: /tmp/Rpl2Twyrts (PID: 5254)File opened: /proc/1344/fd
    Source: /tmp/Rpl2Twyrts (PID: 5254)File opened: /proc/1344/fd
    Source: /tmp/Rpl2Twyrts (PID: 5254)File opened: /proc/1344/exe

    Hooking and other Techniques for Hiding and Protection:

    barindex
    Uses known network protocols on non-standard portsShow sources
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 47728
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 47732
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 47736
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 47744
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 47750
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 47754
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 47760
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 47764
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 47770
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 47778
    Source: /tmp/Rpl2Twyrts (PID: 5246)Queries kernel information via 'uname':
    Source: Rpl2Twyrts, 5246.1.00000000e46a4f04.0000000018f5b09c.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/mipsel
    Source: Rpl2Twyrts, 5246.1.00000000e46a4f04.0000000018f5b09c.rw-.sdmpBinary or memory string: V!/etc/qemu-binfmt/mipsel
    Source: Rpl2Twyrts, 5246.1.000000006915b6a7.0000000099a0e5b4.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-mipsel/tmp/Rpl2TwyrtsSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/Rpl2Twyrts
    Source: Rpl2Twyrts, 5246.1.000000006915b6a7.0000000099a0e5b4.rw-.sdmpBinary or memory string: /usr/bin/qemu-mipsel

    Stealing of Sensitive Information:

    barindex
    Yara detected MiraiShow sources
    Source: Yara matchFile source: dump.pcap, type: PCAP

    Remote Access Functionality:

    barindex
    Yara detected MiraiShow sources
    Source: Yara matchFile source: dump.pcap, type: PCAP

    Mitre Att&ck Matrix

    Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
    Valid AccountsWindows Management InstrumentationPath InterceptionPath InterceptionDirect Volume AccessOS Credential Dumping1Security Software Discovery11Remote ServicesData from Local SystemExfiltration Over Other Network MediumEncrypted Channel1Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
    Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over BluetoothNon-Standard Port11Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
    Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated ExfiltrationApplication Layer Protocol1Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data

    Malware Configuration

    No configs have been found

    Behavior Graph

    Hide Legend

    Legend:

    • Process
    • Signature
    • Created File
    • DNS/IP Info
    • Is Dropped
    • Number of created Files
    • Is malicious
    • Internet
    behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 507421 Sample: Rpl2Twyrts Startdate: 22/10/2021 Architecture: LINUX Score: 72 28 98.23.53.159 WINDSTREAMUS United States 2->28 30 91.228.76.149 WELLSERVER-ASRU Russian Federation 2->30 32 98 other IPs or domains 2->32 36 Snort IDS alert for network traffic (e.g. based on Emerging Threat rules) 2->36 38 Multi AV Scanner detection for submitted file 2->38 40 Yara detected Mirai 2->40 42 Uses known network protocols on non-standard ports 2->42 8 Rpl2Twyrts 2->8         started        10 systemd sshd 2->10         started        12 systemd sshd 2->12         started        signatures3 process4 process5 14 Rpl2Twyrts 8->14         started        16 Rpl2Twyrts 8->16         started        19 Rpl2Twyrts 8->19         started        signatures6 21 Rpl2Twyrts 14->21         started        24 Rpl2Twyrts 14->24         started        26 Rpl2Twyrts 14->26         started        34 Sample tries to kill many processes (SIGKILL) 16->34 process7 signatures8 44 Sample tries to kill many processes (SIGKILL) 21->44

    Antivirus, Machine Learning and Genetic Malware Detection

    Initial Sample

    SourceDetectionScannerLabelLink
    Rpl2Twyrts50%VirustotalBrowse
    Rpl2Twyrts53%ReversingLabsLinux.Trojan.Mirai

    Dropped Files

    No Antivirus matches

    Domains

    No Antivirus matches

    URLs

    No Antivirus matches

    Domains and IPs

    Contacted Domains

    No contacted domains info

    Contacted IPs

    • No. of IPs < 25%
    • 25% < No. of IPs < 50%
    • 50% < No. of IPs < 75%
    • 75% < No. of IPs

    Public

    IPDomainCountryFlagASNASN NameMalicious
    39.203.104.226
    unknownIndonesia
    23693TELKOMSEL-ASN-IDPTTelekomunikasiSelularIDfalse
    190.89.152.5
    unknownunknown
    270374KINGTELECOMUNICACOESBRfalse
    160.248.184.59
    unknownJapan2514INFOSPHERENTTPCCommunicationsIncJPfalse
    86.237.87.136
    unknownFrance
    3215FranceTelecom-OrangeFRfalse
    159.178.169.160
    unknownUnited States
    6356NERDCNETUSfalse
    198.117.113.163
    unknownUnited States
    297AS297USfalse
    170.131.168.48
    unknownUnited States
    13954STAPLESUSfalse
    77.152.117.114
    unknownFrance
    15557LDCOMNETFRfalse
    187.196.136.136
    unknownMexico
    8151UninetSAdeCVMXfalse
    183.206.48.83
    unknownChina
    56046CMNET-JIANGSU-APChinaMobilecommunicationscorporationCNfalse
    155.93.197.94
    unknownSouth Africa
    37680COOL-IDEASZAfalse
    118.155.201.133
    unknownJapan2516KDDIKDDICORPORATIONJPfalse
    65.37.101.238
    unknownUnited States
    5650FRONTIER-FRTRUSfalse
    42.21.33.100
    unknownKorea Republic of
    9644SKTELECOM-NET-ASSKTelecomKRfalse
    45.226.163.131
    unknownBrazil
    267045EASYCONNECTTECNOLOGIAJACILTDABRfalse
    153.233.14.113
    unknownJapan4713OCNNTTCommunicationsCorporationJPfalse
    98.23.53.159
    unknownUnited States
    7029WINDSTREAMUSfalse
    64.253.255.224
    unknownUnited States
    20428GLOWPOINT-ASUSfalse
    160.199.79.178
    unknownJapan7679QTNETQTnetIncJPfalse
    93.249.80.159
    unknownGermany
    3320DTAGInternetserviceprovideroperationsDEfalse
    74.217.215.131
    unknownUnited States
    12182INTERNAP-2BLKUSfalse
    88.74.255.198
    unknownGermany
    3209VODANETInternationalIP-BackboneofVodafoneDEfalse
    58.21.123.207
    unknownChina
    4837CHINA169-BACKBONECHINAUNICOMChina169BackboneCNfalse
    70.63.62.155
    unknownUnited States
    10796TWC-10796-MIDWESTUSfalse
    200.138.172.31
    unknownBrazil
    8167BrasilTelecomSA-FilialDistritoFederalBRfalse
    161.249.2.143
    unknownUnited States
    396269BPL-ASNUSfalse
    158.34.189.234
    unknownUnited States
    721DNIC-ASBLK-00721-00726USfalse
    84.38.119.247
    unknownAustria
    43939INTERNETIA_ETTH2-ASNoc-BialystokPLfalse
    8.156.46.207
    unknownSingapore
    37963CNNIC-ALIBABA-CN-NET-APHangzhouAlibabaAdvertisingCoLtdfalse
    211.11.169.244
    unknownJapan4713OCNNTTCommunicationsCorporationJPfalse
    12.121.131.53
    unknownUnited States
    7018ATT-INTERNET4USfalse
    179.73.32.17
    unknownBrazil
    26615TIMSABRfalse
    75.203.112.61
    unknownUnited States
    22394CELLCOUSfalse
    82.174.187.190
    unknownNetherlands
    13127VERSATELASfortheTrans-EuropeanTele2IPTransportbackbofalse
    186.57.123.203
    unknownArgentina
    22927TelefonicadeArgentinaARfalse
    115.136.104.95
    unknownKorea Republic of
    17858POWERVIS-AS-KRLGPOWERCOMMKRfalse
    110.144.98.170
    unknownAustralia
    1221ASN-TELSTRATelstraCorporationLtdAUfalse
    105.118.219.175
    unknownNigeria
    36873VNL1-ASNGfalse
    19.180.211.252
    unknownUnited States
    3MIT-GATEWAYSUSfalse
    100.15.26.7
    unknownUnited States
    701UUNETUSfalse
    158.47.217.111
    unknownItaly
    12551AS-ENEL-ITfalse
    251.36.138.169
    unknownReserved
    unknownunknownfalse
    84.50.15.196
    unknownEstonia
    3249ESTPAKEEfalse
    251.246.87.35
    unknownReserved
    unknownunknownfalse
    80.194.99.5
    unknownUnited Kingdom
    5089NTLGBfalse
    162.195.248.48
    unknownUnited States
    7018ATT-INTERNET4USfalse
    190.40.159.241
    unknownPeru
    6147TelefonicadelPeruSAAPEfalse
    31.18.171.187
    unknownGermany
    31334KABELDEUTSCHLAND-ASDEfalse
    87.204.237.150
    unknownPoland
    12741AS-NETIAWarszawa02-822PLfalse
    27.12.141.82
    unknownChina
    4837CHINA169-BACKBONECHINAUNICOMChina169BackboneCNfalse
    58.250.84.179
    unknownChina
    17623CNCGROUP-SZChinaUnicomShenzennetworkCNfalse
    149.212.83.51
    unknownDenmark
    8386KOCNETTRfalse
    37.52.64.35
    unknownUkraine
    6849UKRTELNETUAfalse
    191.96.28.113
    unknownChile
    61317ASDETUKhttpwwwheficedcomGBfalse
    104.186.4.233
    unknownUnited States
    7018ATT-INTERNET4USfalse
    124.181.3.104
    unknownAustralia
    1221ASN-TELSTRATelstraCorporationLtdAUfalse
    242.153.131.112
    unknownReserved
    unknownunknownfalse
    198.101.133.16
    unknownUnited States
    19994RACKSPACEUSfalse
    125.113.41.119
    unknownChina
    4134CHINANET-BACKBONENo31Jin-rongStreetCNfalse
    112.99.82.219
    unknownChina
    4134CHINANET-BACKBONENo31Jin-rongStreetCNfalse
    103.146.47.155
    unknownunknown
    139848SHIPL-AS-APSAFEGUARDHOMEIMPROVEMENTSPTYLTDAUfalse
    182.26.120.99
    unknownIndonesia
    4795INDOSATM2-IDINDOSATM2ASNIDfalse
    120.21.19.134
    unknownAustralia
    133612VODAFONE-AS-APVodafoneAustraliaPtyLtdAUfalse
    90.78.51.144
    unknownFrance
    3215FranceTelecom-OrangeFRfalse
    108.22.114.219
    unknownUnited States
    701UUNETUSfalse
    42.222.34.226
    unknownChina
    4249LILLY-ASUSfalse
    19.146.221.131
    unknownUnited States
    3MIT-GATEWAYSUSfalse
    170.244.191.219
    unknownArgentina
    265630COMISSODANTEANIBALARfalse
    187.111.50.119
    unknownBrazil
    262711TURBOMAXTELECOMUNICACOESLTDABRfalse
    70.196.121.123
    unknownUnited States
    6167CELLCO-PARTUSfalse
    247.151.111.14
    unknownReserved
    unknownunknownfalse
    37.11.20.196
    unknownSpain
    12479UNI2-ASESfalse
    209.146.99.63
    unknownUnited States
    395753KKRUSfalse
    87.48.91.173
    unknownDenmark
    3292TDCTDCASDKfalse
    91.228.76.149
    unknownRussian Federation
    56864WELLSERVER-ASRUfalse
    146.93.13.52
    unknownUnited States
    18709BOTWUSfalse
    71.219.170.252
    unknownUnited States
    209CENTURYLINK-US-LEGACY-QWESTUSfalse
    23.235.61.72
    unknownUnited States
    64252ATSIUSfalse
    141.216.159.236
    unknownUnited States
    394769UMF-7-ASUSfalse
    111.146.116.201
    unknownChina
    9394CTTNETChinaTieTongTelecommunicationsCorporationCNfalse
    192.232.122.104
    unknownUnited States
    5647ASN-KODAKUSfalse
    95.36.120.123
    unknownNetherlands
    15670BBNED-AS1NLfalse
    103.187.81.173
    unknownunknown
    7575AARNET-AS-APAustralianAcademicandResearchNetworkAARNefalse
    97.223.137.109
    unknownUnited States
    6167CELLCO-PARTUSfalse
    133.167.242.237
    unknownJapan9371SAKURA-CSAKURAInternetIncJPfalse
    95.183.142.160
    unknownTurkey
    8517ULAKNETTRfalse
    159.28.99.182
    unknownJapan2527SO-NETSo-netEntertainmentCorporationJPfalse
    241.198.25.193
    unknownReserved
    unknownunknownfalse
    251.102.148.138
    unknownReserved
    unknownunknownfalse
    83.106.59.198
    unknownUnited Kingdom
    2529DEMON-INTERNETNowmaintainedbyCableWirelessWorldwidefalse
    138.244.67.215
    unknownGermany
    12816MWN-ASDEfalse
    43.88.162.92
    unknownJapan4249LILLY-ASUSfalse
    162.30.154.204
    unknownUnited States
    46483RGHSUSfalse
    90.95.34.132
    unknownFrance
    8953ASN-ORANGE-ROMANIAROfalse
    82.47.8.178
    unknownUnited Kingdom
    5089NTLGBfalse
    43.99.42.139
    unknownJapan4249LILLY-ASUSfalse
    180.87.26.156
    unknownIndia
    6453AS6453USfalse
    115.163.218.70
    unknownJapan2527SO-NETSo-netEntertainmentCorporationJPfalse
    244.243.93.7
    unknownReserved
    unknownunknownfalse
    19.30.92.146
    unknownUnited States
    3MIT-GATEWAYSUSfalse


    Runtime Messages

    Command:/tmp/Rpl2Twyrts
    Exit Code:0
    Exit Code Info:
    Killed:False
    Standard Output:
    Connected To CNC
    Standard Error:

    Joe Sandbox View / Context

    IPs

    MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
    70.63.62.155raCyB7pYpdGet hashmaliciousBrowse

      Domains

      No context

      ASN

      MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
      TELKOMSEL-ASN-IDPTTelekomunikasiSelularIDzYMp3detVOGet hashmaliciousBrowse
      • 182.10.78.173
      ggtS1fKIqXGet hashmaliciousBrowse
      • 39.208.68.184
      oH6qNmnFRPGet hashmaliciousBrowse
      • 182.8.245.170
      b3astmode.arm7Get hashmaliciousBrowse
      • 39.205.24.41
      PFD33mzc5lGet hashmaliciousBrowse
      • 39.210.152.58
      hNsTaM2BAuGet hashmaliciousBrowse
      • 39.211.166.212
      x86Get hashmaliciousBrowse
      • 39.210.152.36
      8jfOcvTqQAGet hashmaliciousBrowse
      • 182.9.38.56
      jQCJldg3pvGet hashmaliciousBrowse
      • 39.198.157.101
      jMJ8Uz4MhkGet hashmaliciousBrowse
      • 39.216.238.64
      ATc5uxXlTpGet hashmaliciousBrowse
      • 39.239.5.147
      IN7REq0Jv5Get hashmaliciousBrowse
      • 182.3.113.176
      pandora.x86Get hashmaliciousBrowse
      • 39.221.131.173
      pandora.armGet hashmaliciousBrowse
      • 182.2.171.171
      KEgx4lC3NiGet hashmaliciousBrowse
      • 39.221.113.150
      Qfx7rFWkI5Get hashmaliciousBrowse
      • 39.232.121.185
      OcO4KUSfwnGet hashmaliciousBrowse
      • 39.195.240.250
      DGTm0edISXGet hashmaliciousBrowse
      • 39.237.138.116
      1WL2kQmrNkGet hashmaliciousBrowse
      • 182.12.155.124
      1Mwzgsrx9CGet hashmaliciousBrowse
      • 114.126.201.55

      JA3 Fingerprints

      No context

      Dropped Files

      No context

      Created / dropped Files

      /proc/5290/oom_score_adj
      Process:/usr/sbin/sshd
      File Type:ASCII text
      Category:dropped
      Size (bytes):6
      Entropy (8bit):1.7924812503605778
      Encrypted:false
      SSDEEP:3:ptn:Dn
      MD5:CBF282CC55ED0792C33D10003D1F760A
      SHA1:007DD8BD75468E6B7ABA4285E9B267202C7EAEED
      SHA-256:FCDBAB99FCC0F4409E5F9D7D6FC497780288B4C441698126BB62832412774D22
      SHA-512:4643A8675D213C7DA35CC0C2BFB3B6F20324F9C48AEA7BA79F470615698C9A0CEFDA45CAA1957FC29110EE746BC8458AB8AB1E43EB513912A5E1E8858812CC00
      Malicious:false
      Reputation:high, very likely benign file
      Preview: -1000.
      /run/sshd.pid
      Process:/usr/sbin/sshd
      File Type:ASCII text
      Category:dropped
      Size (bytes):5
      Entropy (8bit):2.321928094887362
      Encrypted:false
      SSDEEP:3:Ckvn:Cm
      MD5:3FD0BF07C83F464293873F94C4FEBF64
      SHA1:A10B2D66A4BA43FC3B81098BD761343051789CC0
      SHA-256:CD46DE89F7C34FEBE64A548F2A948CC6B9E8AF9724A496B28331DBE09769F79E
      SHA-512:A5E78FBF75B7232D1F0F65FA9D791953E29152D2C7C520CCCC1536337216754CB9C6C8BB6B66C6BE14B81C1CF33126E94EE015BC721EB77C0F5A120E2AF99D3A
      Malicious:false
      Reputation:low
      Preview: 5290.

      Static File Info

      General

      File type:ELF 32-bit LSB executable, MIPS, MIPS-I version 1 (SYSV), statically linked, stripped
      Entropy (8bit):5.425468889262933
      TrID:
      • ELF Executable and Linkable format (generic) (4004/1) 100.00%
      File name:Rpl2Twyrts
      File size:71764
      MD5:4635e3761f10a21d01fec0df9fa36e2f
      SHA1:a33d4b91fc25603b0ed98b17381f6a6e017f6c32
      SHA256:91ccea41a26fce7feab89f9b17c889b9f7c37f29b5b5a9390a7d3f2990f43cfa
      SHA512:96722d00ad0e84259b5a93ee5a1226af820855fe20889a2782b5fad7dae45555def4877628f610e8ab375ea9581ac7d84b1cb37de7d25808063ee131f05ab0a5
      SSDEEP:768:YU6bhcgHSIJWB+cHlfD2wLX3YEwja6PN1oAg5oRKxeU3hVpxedxAxePx28szI2Zx:YU6bh1HkV2wEVjZPzgj1GCK2dFsTcJ
      File Content Preview:.ELF....................`.@.4...L.......4. ...(...............@...@...........................E...E.................Q.td...............................<...'!......'.......................<...'!... .........9'.. ........................<...'!.............9

      Static ELF Info

      ELF header

      Class:ELF32
      Data:2's complement, little endian
      Version:1 (current)
      Machine:MIPS R3000
      Version Number:0x1
      Type:EXEC (Executable file)
      OS/ABI:UNIX - System V
      ABI Version:0
      Entry Point Address:0x400260
      Flags:0x1007
      ELF Header Size:52
      Program Header Offset:52
      Program Header Size:32
      Number of Program Headers:3
      Section Header Offset:71244
      Section Header Size:40
      Number of Section Headers:13
      Header String Table Index:12

      Sections

      NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
      NULL0x00x00x00x00x0000
      .initPROGBITS0x4000940x940x8c0x00x6AX004
      .textPROGBITS0x4001200x1200x107100x00x6AX0016
      .finiPROGBITS0x4108300x108300x5c0x00x6AX004
      .rodataPROGBITS0x4108900x108900x6600x00x2A0016
      .ctorsPROGBITS0x4510000x110000x80x00x3WA004
      .dtorsPROGBITS0x4510080x110080x80x00x3WA004
      .dataPROGBITS0x4510200x110200x1900x00x3WA0016
      .gotPROGBITS0x4511b00x111b00x4440x40x10000003WA0016
      .sbssNOBITS0x4515f40x115f40x240x00x10000003WA004
      .bssNOBITS0x4516200x115f40x2a00x00x3WA0016
      .mdebug.abi32PROGBITS0x72c0x115f40x00x00x0001
      .shstrtabSTRTAB0x00x115f40x570x00x0001

      Program Segments

      TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
      LOAD0x00x4000000x4000000x10ef00x10ef03.36090x5R E0x10000.init .text .fini .rodata
      LOAD0x110000x4510000x4510000x5f40x8c01.79410x6RW 0x10000.ctors .dtors .data .got .sbss .bss
      GNU_STACK0x00x00x00x00x00.00000x7RWE0x4

      Network Behavior

      Network Port Distribution

      TCP Packets

      TimestampSource PortDest PortSource IPDest IP
      Oct 22, 2021 08:37:08.866673946 CEST442001312192.168.2.23176.126.175.188
      Oct 22, 2021 08:37:08.898858070 CEST5770723192.168.2.2399.22.166.11
      Oct 22, 2021 08:37:08.898920059 CEST5770723192.168.2.2363.165.84.11
      Oct 22, 2021 08:37:08.898957014 CEST5770723192.168.2.23223.195.0.116
      Oct 22, 2021 08:37:08.898957014 CEST5770723192.168.2.2335.118.13.8
      Oct 22, 2021 08:37:08.899002075 CEST5770723192.168.2.23149.182.9.19
      Oct 22, 2021 08:37:08.899029016 CEST5770723192.168.2.2324.8.223.69
      Oct 22, 2021 08:37:08.899036884 CEST5770723192.168.2.23182.145.206.142
      Oct 22, 2021 08:37:08.899046898 CEST5770723192.168.2.239.67.65.67
      Oct 22, 2021 08:37:08.899064064 CEST5770723192.168.2.23240.16.115.86
      Oct 22, 2021 08:37:08.899066925 CEST5770723192.168.2.2312.43.212.21
      Oct 22, 2021 08:37:08.899081945 CEST5770723192.168.2.23108.55.127.139
      Oct 22, 2021 08:37:08.899095058 CEST5770723192.168.2.23201.247.47.135
      Oct 22, 2021 08:37:08.899102926 CEST5770723192.168.2.239.169.231.174
      Oct 22, 2021 08:37:08.899102926 CEST5770723192.168.2.23223.11.182.21
      Oct 22, 2021 08:37:08.899106979 CEST5770723192.168.2.23175.215.68.114
      Oct 22, 2021 08:37:08.899137020 CEST5770723192.168.2.2376.131.185.195
      Oct 22, 2021 08:37:08.899144888 CEST5770723192.168.2.23204.186.55.14
      Oct 22, 2021 08:37:08.899197102 CEST5770723192.168.2.23104.42.93.127
      Oct 22, 2021 08:37:08.899223089 CEST5770723192.168.2.2391.185.36.65
      Oct 22, 2021 08:37:08.899245024 CEST5770723192.168.2.2373.185.144.44
      Oct 22, 2021 08:37:08.899246931 CEST5770723192.168.2.2346.44.202.14
      Oct 22, 2021 08:37:08.899293900 CEST5770723192.168.2.23146.90.157.91
      Oct 22, 2021 08:37:08.899318933 CEST5770723192.168.2.23207.19.164.238
      Oct 22, 2021 08:37:08.899334908 CEST5770723192.168.2.232.5.107.224
      Oct 22, 2021 08:37:08.899342060 CEST5770723192.168.2.2365.109.217.140
      Oct 22, 2021 08:37:08.899362087 CEST5770723192.168.2.23193.187.14.64
      Oct 22, 2021 08:37:08.899368048 CEST5770723192.168.2.2372.239.120.156
      Oct 22, 2021 08:37:08.899394035 CEST5770723192.168.2.23164.30.143.68
      Oct 22, 2021 08:37:08.899445057 CEST5770723192.168.2.23155.206.205.161
      Oct 22, 2021 08:37:08.899458885 CEST5770723192.168.2.2319.156.56.61
      Oct 22, 2021 08:37:08.899499893 CEST5770723192.168.2.2351.5.236.88
      Oct 22, 2021 08:37:08.899523973 CEST5770723192.168.2.23206.22.155.20
      Oct 22, 2021 08:37:08.899558067 CEST5770723192.168.2.23170.182.30.23
      Oct 22, 2021 08:37:08.899560928 CEST5770723192.168.2.2366.95.128.129
      Oct 22, 2021 08:37:08.899574041 CEST5770723192.168.2.2367.85.248.138
      Oct 22, 2021 08:37:08.899636984 CEST5770723192.168.2.23209.218.75.6
      Oct 22, 2021 08:37:08.899660110 CEST5770723192.168.2.2354.122.110.174
      Oct 22, 2021 08:37:08.899678946 CEST5770723192.168.2.23104.187.122.215
      Oct 22, 2021 08:37:08.899679899 CEST5770723192.168.2.23218.248.90.54
      Oct 22, 2021 08:37:08.899703026 CEST5770723192.168.2.2339.110.210.111
      Oct 22, 2021 08:37:08.899720907 CEST5770723192.168.2.23218.93.181.123
      Oct 22, 2021 08:37:08.899725914 CEST5770723192.168.2.2376.42.25.135
      Oct 22, 2021 08:37:08.899729967 CEST5770723192.168.2.23211.104.2.117
      Oct 22, 2021 08:37:08.899753094 CEST5770723192.168.2.23203.176.253.233
      Oct 22, 2021 08:37:08.899756908 CEST5770723192.168.2.23149.176.173.143
      Oct 22, 2021 08:37:08.899770021 CEST5770723192.168.2.23170.185.42.8
      Oct 22, 2021 08:37:08.899775028 CEST5770723192.168.2.23187.248.51.123
      Oct 22, 2021 08:37:08.899785995 CEST5770723192.168.2.23125.220.33.131
      Oct 22, 2021 08:37:08.899846077 CEST5770723192.168.2.23147.187.68.56
      Oct 22, 2021 08:37:08.899861097 CEST5770723192.168.2.23211.170.82.218
      Oct 22, 2021 08:37:08.899883032 CEST5770723192.168.2.23117.189.183.121
      Oct 22, 2021 08:37:08.899885893 CEST5770723192.168.2.23202.193.171.122
      Oct 22, 2021 08:37:08.899899006 CEST5770723192.168.2.2362.67.202.193
      Oct 22, 2021 08:37:08.899905920 CEST5770723192.168.2.23240.84.21.215
      Oct 22, 2021 08:37:08.899909019 CEST5770723192.168.2.23145.137.197.209
      Oct 22, 2021 08:37:08.899920940 CEST5770723192.168.2.23220.49.56.252
      Oct 22, 2021 08:37:08.899931908 CEST5770723192.168.2.2361.186.174.108
      Oct 22, 2021 08:37:08.899941921 CEST5770723192.168.2.23255.100.215.106
      Oct 22, 2021 08:37:08.899945974 CEST5770723192.168.2.23133.15.47.51
      Oct 22, 2021 08:37:08.899956942 CEST5770723192.168.2.23202.160.173.85
      Oct 22, 2021 08:37:08.900018930 CEST5770723192.168.2.23150.147.162.125
      Oct 22, 2021 08:37:08.900026083 CEST5770723192.168.2.23217.165.190.167
      Oct 22, 2021 08:37:08.900053978 CEST5770723192.168.2.2337.147.202.141
      Oct 22, 2021 08:37:08.900062084 CEST5770723192.168.2.2392.232.189.47
      Oct 22, 2021 08:37:08.900062084 CEST5770723192.168.2.2358.56.231.92
      Oct 22, 2021 08:37:08.900077105 CEST5770723192.168.2.23166.149.82.25
      Oct 22, 2021 08:37:08.900104046 CEST5770723192.168.2.23185.27.116.38
      Oct 22, 2021 08:37:08.900120020 CEST5770723192.168.2.23184.129.97.204
      Oct 22, 2021 08:37:08.900146961 CEST5770723192.168.2.23154.205.244.168
      Oct 22, 2021 08:37:08.900149107 CEST5770723192.168.2.23116.161.205.12
      Oct 22, 2021 08:37:08.900158882 CEST5770723192.168.2.23223.194.91.75
      Oct 22, 2021 08:37:08.900161982 CEST5770723192.168.2.23113.141.186.71
      Oct 22, 2021 08:37:08.900176048 CEST5770723192.168.2.23164.239.149.53
      Oct 22, 2021 08:37:08.900187969 CEST5770723192.168.2.23255.178.79.189
      Oct 22, 2021 08:37:08.900196075 CEST5770723192.168.2.23149.151.30.56
      Oct 22, 2021 08:37:08.900202036 CEST5770723192.168.2.2341.127.77.255
      Oct 22, 2021 08:37:08.900234938 CEST5770723192.168.2.23168.189.196.248
      Oct 22, 2021 08:37:08.900244951 CEST5770723192.168.2.23136.112.114.252
      Oct 22, 2021 08:37:08.900278091 CEST5770723192.168.2.23107.168.125.68
      Oct 22, 2021 08:37:08.900290012 CEST5770723192.168.2.23125.251.9.175
      Oct 22, 2021 08:37:08.900295973 CEST5770723192.168.2.23186.201.189.212
      Oct 22, 2021 08:37:08.900301933 CEST5770723192.168.2.23193.187.77.25
      Oct 22, 2021 08:37:08.900301933 CEST5770723192.168.2.23255.206.191.14
      Oct 22, 2021 08:37:08.900331974 CEST5770723192.168.2.23160.164.194.118
      Oct 22, 2021 08:37:08.900357008 CEST5770723192.168.2.2324.231.76.137
      Oct 22, 2021 08:37:08.900384903 CEST5770723192.168.2.23177.47.132.74
      Oct 22, 2021 08:37:08.900403023 CEST5770723192.168.2.23186.126.128.246
      Oct 22, 2021 08:37:08.900403976 CEST5770723192.168.2.23255.78.194.123
      Oct 22, 2021 08:37:08.900405884 CEST5770723192.168.2.2381.40.254.24
      Oct 22, 2021 08:37:08.900429964 CEST5770723192.168.2.23152.59.248.225
      Oct 22, 2021 08:37:08.900466919 CEST5770723192.168.2.23157.229.198.104
      Oct 22, 2021 08:37:08.900489092 CEST5770723192.168.2.23216.185.245.138
      Oct 22, 2021 08:37:08.900490046 CEST5770723192.168.2.23112.178.121.155
      Oct 22, 2021 08:37:08.900497913 CEST5770723192.168.2.23180.126.139.170
      Oct 22, 2021 08:37:08.900520086 CEST5770723192.168.2.2337.29.158.168
      Oct 22, 2021 08:37:08.900527954 CEST5770723192.168.2.2358.28.2.36
      Oct 22, 2021 08:37:08.900532961 CEST5770723192.168.2.23195.250.169.11
      Oct 22, 2021 08:37:08.900533915 CEST5770723192.168.2.23182.18.164.188
      Oct 22, 2021 08:37:08.900543928 CEST5770723192.168.2.23197.165.59.250

      System Behavior

      General

      Start time:08:37:07
      Start date:22/10/2021
      Path:/tmp/Rpl2Twyrts
      Arguments:/tmp/Rpl2Twyrts
      File size:5773336 bytes
      MD5 hash:0d6f61f82cf2f781c6eb0661071d42d9

      General

      Start time:08:37:07
      Start date:22/10/2021
      Path:/tmp/Rpl2Twyrts
      Arguments:n/a
      File size:5773336 bytes
      MD5 hash:0d6f61f82cf2f781c6eb0661071d42d9

      General

      Start time:08:37:07
      Start date:22/10/2021
      Path:/tmp/Rpl2Twyrts
      Arguments:n/a
      File size:5773336 bytes
      MD5 hash:0d6f61f82cf2f781c6eb0661071d42d9

      General

      Start time:08:37:07
      Start date:22/10/2021
      Path:/tmp/Rpl2Twyrts
      Arguments:n/a
      File size:5773336 bytes
      MD5 hash:0d6f61f82cf2f781c6eb0661071d42d9

      General

      Start time:08:37:08
      Start date:22/10/2021
      Path:/tmp/Rpl2Twyrts
      Arguments:n/a
      File size:5773336 bytes
      MD5 hash:0d6f61f82cf2f781c6eb0661071d42d9

      General

      Start time:08:37:08
      Start date:22/10/2021
      Path:/tmp/Rpl2Twyrts
      Arguments:n/a
      File size:5773336 bytes
      MD5 hash:0d6f61f82cf2f781c6eb0661071d42d9

      General

      Start time:08:37:08
      Start date:22/10/2021
      Path:/tmp/Rpl2Twyrts
      Arguments:n/a
      File size:5773336 bytes
      MD5 hash:0d6f61f82cf2f781c6eb0661071d42d9

      General

      Start time:08:37:21
      Start date:22/10/2021
      Path:/usr/lib/systemd/systemd
      Arguments:n/a
      File size:1620224 bytes
      MD5 hash:9b2bec7092a40488108543f9334aab75

      General

      Start time:08:37:21
      Start date:22/10/2021
      Path:/usr/sbin/sshd
      Arguments:/usr/sbin/sshd -t
      File size:876328 bytes
      MD5 hash:dbca7a6bbf7bf57fedac243d4b2cb340

      General

      Start time:08:37:21
      Start date:22/10/2021
      Path:/usr/lib/systemd/systemd
      Arguments:n/a
      File size:1620224 bytes
      MD5 hash:9b2bec7092a40488108543f9334aab75

      General

      Start time:08:37:21
      Start date:22/10/2021
      Path:/usr/sbin/sshd
      Arguments:/usr/sbin/sshd -D
      File size:876328 bytes
      MD5 hash:dbca7a6bbf7bf57fedac243d4b2cb340