Loading ...

Play interactive tourEdit tour

Linux Analysis Report IcwrPqGkXP

Overview

General Information

Sample Name:IcwrPqGkXP
Analysis ID:507447
MD5:18fe913ce8856fc1ea6ebc0412e09da7
SHA1:ff1494dd42dcda452120a9af38a1f5550bd29c55
SHA256:dea614c4a0a319bb53e0d5d9b77d360e23d79e43e4c7a5179c9c3f6b66c26e74
Tags:32elfmipsmirai
Infos:

Most interesting Screenshot:

Detection

Mirai
Score:72
Range:0 - 100
Whitelisted:false

Signatures

Snort IDS alert for network traffic (e.g. based on Emerging Threat rules)
Yara detected Mirai
Multi AV Scanner detection for submitted file
Uses known network protocols on non-standard ports
Sample tries to kill many processes (SIGKILL)
Sample has stripped symbol table
Uses the "uname" system call to query kernel version information (possible evasion)
Enumerates processes within the "proc" file system
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Detected TCP or UDP traffic on non-standard ports
Sample listens on a socket
Sample tries to kill a process (SIGKILL)

Classification

Analysis Advice

Static ELF header machine description suggests that the sample might only run correctly on MIPS or ARM architectures
All HTTP servers contacted by the sample do not answer. Likely the sample is an old dropper which does no longer work
Static ELF header machine description suggests that the sample might not execute correctly on this machine

General Information

Joe Sandbox Version:33.0.0 White Diamond
Analysis ID:507447
Start date:22.10.2021
Start time:09:08:35
Joe Sandbox Product:CloudBasic
Overall analysis duration:0h 6m 39s
Hypervisor based Inspection enabled:false
Report type:light
Sample file name:IcwrPqGkXP
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Detection:MAL
Classification:mal72.spre.troj.lin@0/6@0/0
Warnings:
Show All
  • Report size exceeded maximum capacity and may have missing network information.
  • TCP Packets have been reduced to 100

Process Tree

  • system is lnxubuntu20
  • IcwrPqGkXP (PID: 5250, Parent: 5121, MD5: 0083f1f0e77be34ad27f849842bbb00c) Arguments: /tmp/IcwrPqGkXP
  • systemd New Fork (PID: 5287, Parent: 1)
  • sshd (PID: 5287, Parent: 1, MD5: dbca7a6bbf7bf57fedac243d4b2cb340) Arguments: /usr/sbin/sshd -t
  • systemd New Fork (PID: 5290, Parent: 1)
  • sshd (PID: 5290, Parent: 1, MD5: dbca7a6bbf7bf57fedac243d4b2cb340) Arguments: /usr/sbin/sshd -D
  • systemd New Fork (PID: 5404, Parent: 1)
  • sshd (PID: 5404, Parent: 1, MD5: dbca7a6bbf7bf57fedac243d4b2cb340) Arguments: /usr/sbin/sshd -t
  • systemd New Fork (PID: 5405, Parent: 1)
  • sshd (PID: 5405, Parent: 1, MD5: dbca7a6bbf7bf57fedac243d4b2cb340) Arguments: /usr/sbin/sshd -D
  • systemd New Fork (PID: 5406, Parent: 1)
  • sshd (PID: 5406, Parent: 1, MD5: dbca7a6bbf7bf57fedac243d4b2cb340) Arguments: /usr/sbin/sshd -t
  • systemd New Fork (PID: 5407, Parent: 1)
  • sshd (PID: 5407, Parent: 1, MD5: dbca7a6bbf7bf57fedac243d4b2cb340) Arguments: /usr/sbin/sshd -D
  • cleanup

Yara Overview

PCAP (Network Traffic)

SourceRuleDescriptionAuthorStrings
dump.pcapJoeSecurity_Mirai_12Yara detected MiraiJoe Security

    Jbx Signature Overview

    Click to jump to signature section

    Show All Signature Results

    AV Detection:

    barindex
    Multi AV Scanner detection for submitted fileShow sources
    Source: IcwrPqGkXPVirustotal: Detection: 50%Perma Link
    Source: IcwrPqGkXPReversingLabs: Detection: 54%

    Networking:

    barindex
    Snort IDS alert for network traffic (e.g. based on Emerging Threat rules)Show sources
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 96.238.96.121:23 -> 192.168.2.23:42082
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 96.238.96.121:23 -> 192.168.2.23:42082
    Source: TrafficSnort IDS: 716 INFO TELNET access 112.220.29.174:23 -> 192.168.2.23:48464
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 45.177.144.56:23 -> 192.168.2.23:36450
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 45.177.144.56:23 -> 192.168.2.23:36450
    Source: TrafficSnort IDS: 716 INFO TELNET access 123.231.185.250:23 -> 192.168.2.23:56124
    Source: TrafficSnort IDS: 716 INFO TELNET access 112.220.29.174:23 -> 192.168.2.23:48672
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 96.238.96.121:23 -> 192.168.2.23:42336
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 96.238.96.121:23 -> 192.168.2.23:42336
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 45.177.144.56:23 -> 192.168.2.23:36516
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 45.177.144.56:23 -> 192.168.2.23:36516
    Source: TrafficSnort IDS: 716 INFO TELNET access 123.231.185.250:23 -> 192.168.2.23:56172
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 46.171.37.170:23 -> 192.168.2.23:54750
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 45.177.144.56:23 -> 192.168.2.23:36576
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 45.177.144.56:23 -> 192.168.2.23:36576
    Source: TrafficSnort IDS: 716 INFO TELNET access 123.231.185.250:23 -> 192.168.2.23:56204
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 46.171.37.170:23 -> 192.168.2.23:54778
    Source: TrafficSnort IDS: 716 INFO TELNET access 203.140.151.163:23 -> 192.168.2.23:45858
    Source: TrafficSnort IDS: 716 INFO TELNET access 203.140.151.163:23 -> 192.168.2.23:45882
    Source: TrafficSnort IDS: 716 INFO TELNET access 120.194.66.6:23 -> 192.168.2.23:42560
    Source: TrafficSnort IDS: 716 INFO TELNET access 120.194.66.6:23 -> 192.168.2.23:42570
    Source: TrafficSnort IDS: 2023448 ET TROJAN Possible Linux.Mirai Login Attempt (ubnt) 192.168.2.23:42570 -> 120.194.66.6:23
    Source: TrafficSnort IDS: 716 INFO TELNET access 123.231.185.250:23 -> 192.168.2.23:56270
    Source: TrafficSnort IDS: 716 INFO TELNET access 203.140.151.163:23 -> 192.168.2.23:45906
    Source: TrafficSnort IDS: 716 INFO TELNET access 120.194.66.6:23 -> 192.168.2.23:42582
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 46.171.37.170:23 -> 192.168.2.23:54854
    Source: TrafficSnort IDS: 2023448 ET TROJAN Possible Linux.Mirai Login Attempt (ubnt) 192.168.2.23:42582 -> 120.194.66.6:23
    Source: TrafficSnort IDS: 716 INFO TELNET access 112.220.29.174:23 -> 192.168.2.23:48816
    Source: TrafficSnort IDS: 716 INFO TELNET access 120.194.66.6:23 -> 192.168.2.23:42594
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 45.177.144.56:23 -> 192.168.2.23:36640
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 45.177.144.56:23 -> 192.168.2.23:36640
    Source: TrafficSnort IDS: 716 INFO TELNET access 203.140.151.163:23 -> 192.168.2.23:45932
    Source: TrafficSnort IDS: 716 INFO TELNET access 120.194.66.6:23 -> 192.168.2.23:42604
    Source: TrafficSnort IDS: 716 INFO TELNET access 120.194.66.6:23 -> 192.168.2.23:42626
    Source: TrafficSnort IDS: 716 INFO TELNET access 120.194.66.6:23 -> 192.168.2.23:42638
    Source: TrafficSnort IDS: 716 INFO TELNET access 162.251.124.166:23 -> 192.168.2.23:57340
    Source: TrafficSnort IDS: 716 INFO TELNET access 120.194.66.6:23 -> 192.168.2.23:42644
    Source: TrafficSnort IDS: 716 INFO TELNET access 203.140.151.163:23 -> 192.168.2.23:45980
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 46.171.37.170:23 -> 192.168.2.23:54912
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 96.238.96.121:23 -> 192.168.2.23:42534
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 96.238.96.121:23 -> 192.168.2.23:42534
    Source: TrafficSnort IDS: 716 INFO TELNET access 120.194.66.6:23 -> 192.168.2.23:42668
    Source: TrafficSnort IDS: 716 INFO TELNET access 120.194.66.6:23 -> 192.168.2.23:42682
    Source: TrafficSnort IDS: 2023433 ET TROJAN Possible Linux.Mirai Login Attempt (7ujMko0admin) 192.168.2.23:56922 -> 115.74.246.212:23
    Source: TrafficSnort IDS: 716 INFO TELNET access 123.231.185.250:23 -> 192.168.2.23:56386
    Source: TrafficSnort IDS: 716 INFO TELNET access 203.140.151.163:23 -> 192.168.2.23:46032
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 46.171.37.170:23 -> 192.168.2.23:55004
    Source: TrafficSnort IDS: 716 INFO TELNET access 162.251.124.166:23 -> 192.168.2.23:57438
    Source: TrafficSnort IDS: 716 INFO TELNET access 203.140.151.163:23 -> 192.168.2.23:46074
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 45.177.144.56:23 -> 192.168.2.23:36786
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 45.177.144.56:23 -> 192.168.2.23:36786
    Source: TrafficSnort IDS: 716 INFO TELNET access 203.140.151.163:23 -> 192.168.2.23:46102
    Source: TrafficSnort IDS: 716 INFO TELNET access 123.231.185.250:23 -> 192.168.2.23:56474
    Source: TrafficSnort IDS: 716 INFO TELNET access 162.251.124.166:23 -> 192.168.2.23:57480
    Source: TrafficSnort IDS: 716 INFO TELNET access 203.140.151.163:23 -> 192.168.2.23:46122
    Source: TrafficSnort IDS: 716 INFO TELNET access 162.251.124.166:23 -> 192.168.2.23:57498
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 46.171.37.170:23 -> 192.168.2.23:55068
    Source: TrafficSnort IDS: 716 INFO TELNET access 203.140.151.163:23 -> 192.168.2.23:46138
    Source: TrafficSnort IDS: 2023434 ET TROJAN Possible Linux.Mirai Login Attempt (7ujMko0vizxv) 192.168.2.23:57052 -> 115.74.246.212:23
    Source: TrafficSnort IDS: 716 INFO TELNET access 123.231.185.250:23 -> 192.168.2.23:56516
    Source: TrafficSnort IDS: 2023433 ET TROJAN Possible Linux.Mirai Login Attempt (7ujMko0admin) 192.168.2.23:57058 -> 115.74.246.212:23
    Source: TrafficSnort IDS: 716 INFO TELNET access 112.220.29.174:23 -> 192.168.2.23:49060
    Source: TrafficSnort IDS: 716 INFO TELNET access 162.251.124.166:23 -> 192.168.2.23:57528
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 45.177.144.56:23 -> 192.168.2.23:36874
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 45.177.144.56:23 -> 192.168.2.23:36874
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 46.171.37.170:23 -> 192.168.2.23:55152
    Source: TrafficSnort IDS: 716 INFO TELNET access 162.251.124.166:23 -> 192.168.2.23:57602
    Source: TrafficSnort IDS: 716 INFO TELNET access 123.231.185.250:23 -> 192.168.2.23:56608
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 96.238.96.121:23 -> 192.168.2.23:42804
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 96.238.96.121:23 -> 192.168.2.23:42804
    Source: TrafficSnort IDS: 716 INFO TELNET access 220.85.117.10:23 -> 192.168.2.23:45420
    Source: TrafficSnort IDS: 716 INFO TELNET access 162.251.124.166:23 -> 192.168.2.23:57634
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 45.177.144.56:23 -> 192.168.2.23:36996
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 45.177.144.56:23 -> 192.168.2.23:36996
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 46.171.37.170:23 -> 192.168.2.23:55212
    Source: TrafficSnort IDS: 716 INFO TELNET access 162.251.124.166:23 -> 192.168.2.23:57666
    Source: TrafficSnort IDS: 716 INFO TELNET access 123.231.185.250:23 -> 192.168.2.23:56672
    Source: TrafficSnort IDS: 716 INFO TELNET access 113.15.180.40:23 -> 192.168.2.23:52606
    Source: TrafficSnort IDS: 716 INFO TELNET access 162.251.124.166:23 -> 192.168.2.23:57778
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 46.171.37.170:23 -> 192.168.2.23:55348
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 113.15.180.40:23 -> 192.168.2.23:52606
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 45.177.144.56:23 -> 192.168.2.23:37156
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 45.177.144.56:23 -> 192.168.2.23:37156
    Source: TrafficSnort IDS: 716 INFO TELNET access 123.231.185.250:23 -> 192.168.2.23:56804
    Source: TrafficSnort IDS: 716 INFO TELNET access 112.220.29.174:23 -> 192.168.2.23:49344
    Source: TrafficSnort IDS: 716 INFO TELNET access 113.15.180.40:23 -> 192.168.2.23:52694
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 113.15.180.40:23 -> 192.168.2.23:52694
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 46.171.37.170:23 -> 192.168.2.23:55398
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 221.10.172.131:23 -> 192.168.2.23:42474
    Source: TrafficSnort IDS: 716 INFO TELNET access 113.15.180.40:23 -> 192.168.2.23:52726
    Source: TrafficSnort IDS: 716 INFO TELNET access 27.210.215.115:23 -> 192.168.2.23:37176
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 45.177.144.56:23 -> 192.168.2.23:37224
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 45.177.144.56:23 -> 192.168.2.23:37224
    Source: TrafficSnort IDS: 716 INFO TELNET access 220.85.117.10:23 -> 192.168.2.23:45678
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 113.15.180.40:23 -> 192.168.2.23:52726
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 27.210.215.115:23 -> 192.168.2.23:37176
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 27.210.215.115:23 -> 192.168.2.23:37176
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 96.238.96.121:23 -> 192.168.2.23:43088
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 96.238.96.121:23 -> 192.168.2.23:43088
    Source: TrafficSnort IDS: 716 INFO TELNET access 113.15.180.40:23 -> 192.168.2.23:52796
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 221.10.172.131:23 -> 192.168.2.23:42554
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 113.15.180.40:23 -> 192.168.2.23:52796
    Source: TrafficSnort IDS: 716 INFO TELNET access 27.210.215.115:23 -> 192.168.2.23:37242
    Source: TrafficSnort IDS: 716 INFO TELNET access 113.15.180.40:23 -> 192.168.2.23:52818
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 45.177.144.56:23 -> 192.168.2.23:37312
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 45.177.144.56:23 -> 192.168.2.23:37312
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 27.210.215.115:23 -> 192.168.2.23:37242
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 27.210.215.115:23 -> 192.168.2.23:37242
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 113.15.180.40:23 -> 192.168.2.23:52818
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 221.10.172.131:23 -> 192.168.2.23:42576
    Source: TrafficSnort IDS: 716 INFO TELNET access 162.251.124.166:23 -> 192.168.2.23:57948
    Source: TrafficSnort IDS: 716 INFO TELNET access 113.15.180.40:23 -> 192.168.2.23:52840
    Source: TrafficSnort IDS: 716 INFO TELNET access 112.220.29.174:23 -> 192.168.2.23:49502
    Uses known network protocols on non-standard portsShow sources
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43252
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43256
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43260
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43262
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43272
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43268
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43274
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43278
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43282
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43286
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43290
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43316
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43292
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43322
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43342
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43344
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43362
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43366
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43374
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43360
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37882
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37884
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37888
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37890
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37892
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37896
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37898
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37900
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37908
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37914
    Source: global trafficTCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
    Source: global trafficTCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
    Source: global trafficTCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
    Source: global trafficTCP traffic: 192.168.2.23:44200 -> 176.126.175.188:1312
    Source: /tmp/IcwrPqGkXP (PID: 5253)Socket: 0.0.0.0::0
    Source: /tmp/IcwrPqGkXP (PID: 5253)Socket: 0.0.0.0::23
    Source: /tmp/IcwrPqGkXP (PID: 5253)Socket: 0.0.0.0::53413
    Source: /tmp/IcwrPqGkXP (PID: 5253)Socket: 0.0.0.0::80
    Source: /tmp/IcwrPqGkXP (PID: 5253)Socket: 0.0.0.0::52869
    Source: /tmp/IcwrPqGkXP (PID: 5253)Socket: 0.0.0.0::37215
    Source: /tmp/IcwrPqGkXP (PID: 5259)Socket: 0.0.0.0::22
    Source: /tmp/IcwrPqGkXP (PID: 5259)Socket: 0.0.0.0::23
    Source: /tmp/IcwrPqGkXP (PID: 5259)Socket: 0.0.0.0::53413
    Source: /tmp/IcwrPqGkXP (PID: 5259)Socket: 0.0.0.0::80
    Source: /tmp/IcwrPqGkXP (PID: 5259)Socket: 0.0.0.0::52869
    Source: /tmp/IcwrPqGkXP (PID: 5259)Socket: 0.0.0.0::37215
    Source: /usr/sbin/sshd (PID: 5290)Socket: [::]::22
    Source: /usr/sbin/sshd (PID: 5405)Socket: 0.0.0.0::22
    Source: /usr/sbin/sshd (PID: 5405)Socket: [::]::22
    Source: /usr/sbin/sshd (PID: 5407)Socket: 0.0.0.0::22
    Source: /usr/sbin/sshd (PID: 5407)Socket: [::]::22
    Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443
    Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
    Source: unknownTCP traffic detected without corresponding DNS query: 176.126.175.188
    Source: unknownTCP traffic detected without corresponding DNS query: 75.91.152.247
    Source: unknownTCP traffic detected without corresponding DNS query: 184.237.126.242
    Source: unknownTCP traffic detected without corresponding DNS query: 40.172.207.84
    Source: unknownTCP traffic detected without corresponding DNS query: 183.218.255.83
    Source: unknownTCP traffic detected without corresponding DNS query: 111.242.180.118
    Source: unknownTCP traffic detected without corresponding DNS query: 171.59.92.231
    Source: unknownTCP traffic detected without corresponding DNS query: 203.25.197.232
    Source: unknownTCP traffic detected without corresponding DNS query: 118.2.251.79
    Source: unknownTCP traffic detected without corresponding DNS query: 118.68.125.140
    Source: unknownTCP traffic detected without corresponding DNS query: 38.74.198.225
    Source: unknownTCP traffic detected without corresponding DNS query: 253.114.31.118
    Source: unknownTCP traffic detected without corresponding DNS query: 108.211.59.236
    Source: unknownTCP traffic detected without corresponding DNS query: 180.15.42.13
    Source: unknownTCP traffic detected without corresponding DNS query: 169.50.228.79
    Source: unknownTCP traffic detected without corresponding DNS query: 166.73.1.187
    Source: unknownTCP traffic detected without corresponding DNS query: 155.111.169.178
    Source: unknownTCP traffic detected without corresponding DNS query: 69.40.101.27
    Source: unknownTCP traffic detected without corresponding DNS query: 194.3.176.129
    Source: unknownTCP traffic detected without corresponding DNS query: 179.22.6.207
    Source: unknownTCP traffic detected without corresponding DNS query: 212.177.222.62
    Source: unknownTCP traffic detected without corresponding DNS query: 89.209.189.20
    Source: unknownTCP traffic detected without corresponding DNS query: 71.68.153.155
    Source: unknownTCP traffic detected without corresponding DNS query: 179.190.66.93
    Source: unknownTCP traffic detected without corresponding DNS query: 191.62.73.5
    Source: unknownTCP traffic detected without corresponding DNS query: 80.40.242.1
    Source: unknownTCP traffic detected without corresponding DNS query: 252.19.250.113
    Source: unknownTCP traffic detected without corresponding DNS query: 79.158.185.6
    Source: unknownTCP traffic detected without corresponding DNS query: 86.152.55.178
    Source: unknownTCP traffic detected without corresponding DNS query: 250.76.71.171
    Source: unknownTCP traffic detected without corresponding DNS query: 145.187.24.155
    Source: unknownTCP traffic detected without corresponding DNS query: 4.31.189.126
    Source: unknownTCP traffic detected without corresponding DNS query: 95.9.175.225
    Source: unknownTCP traffic detected without corresponding DNS query: 8.138.189.91
    Source: unknownTCP traffic detected without corresponding DNS query: 217.216.63.38
    Source: unknownTCP traffic detected without corresponding DNS query: 178.1.203.237
    Source: unknownTCP traffic detected without corresponding DNS query: 77.69.105.75
    Source: unknownTCP traffic detected without corresponding DNS query: 146.188.2.100
    Source: unknownTCP traffic detected without corresponding DNS query: 245.105.21.99
    Source: unknownTCP traffic detected without corresponding DNS query: 147.125.98.210
    Source: unknownTCP traffic detected without corresponding DNS query: 130.32.135.51
    Source: unknownTCP traffic detected without corresponding DNS query: 197.87.52.245
    Source: unknownTCP traffic detected without corresponding DNS query: 171.15.242.108
    Source: unknownTCP traffic detected without corresponding DNS query: 133.158.120.223
    Source: unknownTCP traffic detected without corresponding DNS query: 133.197.139.22
    Source: unknownTCP traffic detected without corresponding DNS query: 119.230.119.116
    Source: unknownTCP traffic detected without corresponding DNS query: 141.12.150.118
    Source: unknownTCP traffic detected without corresponding DNS query: 176.117.57.57
    Source: unknownTCP traffic detected without corresponding DNS query: 151.105.216.116

    System Summary:

    barindex
    Sample tries to kill many processes (SIGKILL)Show sources
    Source: /tmp/IcwrPqGkXP (PID: 5253)SIGKILL sent: pid: 5259, result: successful
    Source: /tmp/IcwrPqGkXP (PID: 5253)SIGKILL sent: pid: 720, result: successful
    Source: /tmp/IcwrPqGkXP (PID: 5253)SIGKILL sent: pid: 759, result: successful
    Source: /tmp/IcwrPqGkXP (PID: 5253)SIGKILL sent: pid: 788, result: successful
    Source: /tmp/IcwrPqGkXP (PID: 5253)SIGKILL sent: pid: 800, result: successful
    Source: /tmp/IcwrPqGkXP (PID: 5253)SIGKILL sent: pid: 847, result: successful
    Source: /tmp/IcwrPqGkXP (PID: 5253)SIGKILL sent: pid: 884, result: successful
    Source: /tmp/IcwrPqGkXP (PID: 5253)SIGKILL sent: pid: 1334, result: successful
    Source: /tmp/IcwrPqGkXP (PID: 5253)SIGKILL sent: pid: 1335, result: successful
    Source: /tmp/IcwrPqGkXP (PID: 5253)SIGKILL sent: pid: 1872, result: successful
    Source: /tmp/IcwrPqGkXP (PID: 5253)SIGKILL sent: pid: 2096, result: successful
    Source: /tmp/IcwrPqGkXP (PID: 5253)SIGKILL sent: pid: 2097, result: successful
    Source: /tmp/IcwrPqGkXP (PID: 5253)SIGKILL sent: pid: 2102, result: successful
    Source: /tmp/IcwrPqGkXP (PID: 5253)SIGKILL sent: pid: 2180, result: successful
    Source: /tmp/IcwrPqGkXP (PID: 5253)SIGKILL sent: pid: 2191, result: successful
    Source: /tmp/IcwrPqGkXP (PID: 5253)SIGKILL sent: pid: 2208, result: successful
    Source: /tmp/IcwrPqGkXP (PID: 5253)SIGKILL sent: pid: 2275, result: successful
    Source: /tmp/IcwrPqGkXP (PID: 5253)SIGKILL sent: pid: 2281, result: successful
    Source: /tmp/IcwrPqGkXP (PID: 5253)SIGKILL sent: pid: 2285, result: successful
    Source: /tmp/IcwrPqGkXP (PID: 5253)SIGKILL sent: pid: 2289, result: successful
    Source: /tmp/IcwrPqGkXP (PID: 5253)SIGKILL sent: pid: 2294, result: successful
    Source: /tmp/IcwrPqGkXP (PID: 5253)SIGKILL sent: pid: 5255, result: successful
    Source: /tmp/IcwrPqGkXP (PID: 5253)SIGKILL sent: pid: 5263, result: successful
    Source: /tmp/IcwrPqGkXP (PID: 5253)SIGKILL sent: pid: 5290, result: successful
    Source: /tmp/IcwrPqGkXP (PID: 5253)SIGKILL sent: pid: 5405, result: successful
    Source: /tmp/IcwrPqGkXP (PID: 5253)SIGKILL sent: pid: 5253, result: unknown
    Source: /tmp/IcwrPqGkXP (PID: 5259)SIGKILL sent: pid: 936, result: successful
    Source: ELF static info symbol of initial sample.symtab present: no
    Source: /tmp/IcwrPqGkXP (PID: 5253)SIGKILL sent: pid: 5259, result: successful
    Source: /tmp/IcwrPqGkXP (PID: 5253)SIGKILL sent: pid: 720, result: successful
    Source: /tmp/IcwrPqGkXP (PID: 5253)SIGKILL sent: pid: 759, result: successful
    Source: /tmp/IcwrPqGkXP (PID: 5253)SIGKILL sent: pid: 788, result: successful
    Source: /tmp/IcwrPqGkXP (PID: 5253)SIGKILL sent: pid: 800, result: successful
    Source: /tmp/IcwrPqGkXP (PID: 5253)SIGKILL sent: pid: 847, result: successful
    Source: /tmp/IcwrPqGkXP (PID: 5253)SIGKILL sent: pid: 884, result: successful
    Source: /tmp/IcwrPqGkXP (PID: 5253)SIGKILL sent: pid: 1334, result: successful
    Source: /tmp/IcwrPqGkXP (PID: 5253)SIGKILL sent: pid: 1335, result: successful
    Source: /tmp/IcwrPqGkXP (PID: 5253)SIGKILL sent: pid: 1872, result: successful
    Source: /tmp/IcwrPqGkXP (PID: 5253)SIGKILL sent: pid: 2096, result: successful
    Source: /tmp/IcwrPqGkXP (PID: 5253)SIGKILL sent: pid: 2097, result: successful
    Source: /tmp/IcwrPqGkXP (PID: 5253)SIGKILL sent: pid: 2102, result: successful
    Source: /tmp/IcwrPqGkXP (PID: 5253)SIGKILL sent: pid: 2180, result: successful
    Source: /tmp/IcwrPqGkXP (PID: 5253)SIGKILL sent: pid: 2191, result: successful
    Source: /tmp/IcwrPqGkXP (PID: 5253)SIGKILL sent: pid: 2208, result: successful
    Source: /tmp/IcwrPqGkXP (PID: 5253)SIGKILL sent: pid: 2275, result: successful
    Source: /tmp/IcwrPqGkXP (PID: 5253)SIGKILL sent: pid: 2281, result: successful
    Source: /tmp/IcwrPqGkXP (PID: 5253)SIGKILL sent: pid: 2285, result: successful
    Source: /tmp/IcwrPqGkXP (PID: 5253)SIGKILL sent: pid: 2289, result: successful
    Source: /tmp/IcwrPqGkXP (PID: 5253)SIGKILL sent: pid: 2294, result: successful
    Source: /tmp/IcwrPqGkXP (PID: 5253)SIGKILL sent: pid: 5255, result: successful
    Source: /tmp/IcwrPqGkXP (PID: 5253)SIGKILL sent: pid: 5263, result: successful
    Source: /tmp/IcwrPqGkXP (PID: 5253)SIGKILL sent: pid: 5290, result: successful
    Source: /tmp/IcwrPqGkXP (PID: 5253)SIGKILL sent: pid: 5405, result: successful
    Source: /tmp/IcwrPqGkXP (PID: 5253)SIGKILL sent: pid: 5253, result: unknown
    Source: /tmp/IcwrPqGkXP (PID: 5259)SIGKILL sent: pid: 936, result: successful
    Source: classification engineClassification label: mal72.spre.troj.lin@0/6@0/0
    Source: IcwrPqGkXPJoe Sandbox Cloud Basic: Detection: clean Score: 0Perma Link
    Source: /tmp/IcwrPqGkXP (PID: 5253)File opened: /proc/5263/fd
    Source: /tmp/IcwrPqGkXP (PID: 5253)File opened: /proc/5263/exe
    Source: /tmp/IcwrPqGkXP (PID: 5253)File opened: /proc/5265/exe
    Source: /tmp/IcwrPqGkXP (PID: 5253)File opened: /proc/4452/exe
    Source: /tmp/IcwrPqGkXP (PID: 5253)File opened: /proc/2033/fd
    Source: /tmp/IcwrPqGkXP (PID: 5253)File opened: /proc/2033/fd
    Source: /tmp/IcwrPqGkXP (PID: 5253)File opened: /proc/2033/exe
    Source: /tmp/IcwrPqGkXP (PID: 5253)File opened: /proc/2033/fd
    Source: /tmp/IcwrPqGkXP (PID: 5253)File opened: /proc/2033/fd
    Source: /tmp/IcwrPqGkXP (PID: 5253)File opened: /proc/1582/fd
    Source: /tmp/IcwrPqGkXP (PID: 5253)File opened: /proc/1582/fd
    Source: /tmp/IcwrPqGkXP (PID: 5253)File opened: /proc/1582/exe
    Source: /tmp/IcwrPqGkXP (PID: 5253)File opened: /proc/1582/fd
    Source: /tmp/IcwrPqGkXP (PID: 5253)File opened: /proc/1582/fd
    Source: /tmp/IcwrPqGkXP (PID: 5253)File opened: /proc/2275/fd
    Source: /tmp/IcwrPqGkXP (PID: 5253)File opened: /proc/2275/fd
    Source: /tmp/IcwrPqGkXP (PID: 5253)File opened: /proc/2275/exe
    Source: /tmp/IcwrPqGkXP (PID: 5253)File opened: /proc/3088/exe
    Source: /tmp/IcwrPqGkXP (PID: 5253)File opened: /proc/5260/exe
    Source: /tmp/IcwrPqGkXP (PID: 5253)File opened: /proc/1612/fd
    Source: /tmp/IcwrPqGkXP (PID: 5253)File opened: /proc/1612/fd
    Source: /tmp/IcwrPqGkXP (PID: 5253)File opened: /proc/1612/exe
    Source: /tmp/IcwrPqGkXP (PID: 5253)File opened: /proc/1612/fd
    Source: /tmp/IcwrPqGkXP (PID: 5253)File opened: /proc/1612/fd
    Source: /tmp/IcwrPqGkXP (PID: 5253)File opened: /proc/1579/fd
    Source: /tmp/IcwrPqGkXP (PID: 5253)File opened: /proc/1579/fd
    Source: /tmp/IcwrPqGkXP (PID: 5253)File opened: /proc/1579/exe
    Source: /tmp/IcwrPqGkXP (PID: 5253)File opened: /proc/1579/fd
    Source: /tmp/IcwrPqGkXP (PID: 5253)File opened: /proc/1579/fd
    Source: /tmp/IcwrPqGkXP (PID: 5253)File opened: /proc/1699/fd
    Source: /tmp/IcwrPqGkXP (PID: 5253)File opened: /proc/1699/fd
    Source: /tmp/IcwrPqGkXP (PID: 5253)File opened: /proc/1699/exe
    Source: /tmp/IcwrPqGkXP (PID: 5253)File opened: /proc/1699/fd
    Source: /tmp/IcwrPqGkXP (PID: 5253)File opened: /proc/1699/fd
    Source: /tmp/IcwrPqGkXP (PID: 5253)File opened: /proc/1335/fd
    Source: /tmp/IcwrPqGkXP (PID: 5253)File opened: /proc/1335/fd
    Source: /tmp/IcwrPqGkXP (PID: 5253)File opened: /proc/1335/exe
    Source: /tmp/IcwrPqGkXP (PID: 5253)File opened: /proc/1698/fd
    Source: /tmp/IcwrPqGkXP (PID: 5253)File opened: /proc/1698/fd
    Source: /tmp/IcwrPqGkXP (PID: 5253)File opened: /proc/1698/exe
    Source: /tmp/IcwrPqGkXP (PID: 5253)File opened: /proc/1698/fd
    Source: /tmp/IcwrPqGkXP (PID: 5253)File opened: /proc/1698/fd
    Source: /tmp/IcwrPqGkXP (PID: 5253)File opened: /proc/2028/fd
    Source: /tmp/IcwrPqGkXP (PID: 5253)File opened: /proc/2028/fd
    Source: /tmp/IcwrPqGkXP (PID: 5253)File opened: /proc/2028/exe
    Source: /tmp/IcwrPqGkXP (PID: 5253)File opened: /proc/2028/fd
    Source: /tmp/IcwrPqGkXP (PID: 5253)File opened: /proc/2028/fd
    Source: /tmp/IcwrPqGkXP (PID: 5253)File opened: /proc/1334/fd
    Source: /tmp/IcwrPqGkXP (PID: 5253)File opened: /proc/1334/fd
    Source: /tmp/IcwrPqGkXP (PID: 5253)File opened: /proc/1334/exe
    Source: /tmp/IcwrPqGkXP (PID: 5253)File opened: /proc/1334/fd
    Source: /tmp/IcwrPqGkXP (PID: 5253)File opened: /proc/1334/fd
    Source: /tmp/IcwrPqGkXP (PID: 5253)File opened: /proc/1576/fd
    Source: /tmp/IcwrPqGkXP (PID: 5253)File opened: /proc/1576/fd
    Source: /tmp/IcwrPqGkXP (PID: 5253)File opened: /proc/1576/exe
    Source: /tmp/IcwrPqGkXP (PID: 5253)File opened: /proc/1576/fd
    Source: /tmp/IcwrPqGkXP (PID: 5253)File opened: /proc/1576/fd
    Source: /tmp/IcwrPqGkXP (PID: 5253)File opened: /proc/2302/fd
    Source: /tmp/IcwrPqGkXP (PID: 5253)File opened: /proc/2302/fd
    Source: /tmp/IcwrPqGkXP (PID: 5253)File opened: /proc/2302/exe
    Source: /tmp/IcwrPqGkXP (PID: 5253)File opened: /proc/2302/fd
    Source: /tmp/IcwrPqGkXP (PID: 5253)File opened: /proc/2302/fd
    Source: /tmp/IcwrPqGkXP (PID: 5253)File opened: /proc/3236/fd
    Source: /tmp/IcwrPqGkXP (PID: 5253)File opened: /proc/3236/fd
    Source: /tmp/IcwrPqGkXP (PID: 5253)File opened: /proc/3236/exe
    Source: /tmp/IcwrPqGkXP (PID: 5253)File opened: /proc/3236/fd
    Source: /tmp/IcwrPqGkXP (PID: 5253)File opened: /proc/3236/fd
    Source: /tmp/IcwrPqGkXP (PID: 5253)File opened: /proc/2025/fd
    Source: /tmp/IcwrPqGkXP (PID: 5253)File opened: /proc/2025/fd
    Source: /tmp/IcwrPqGkXP (PID: 5253)File opened: /proc/2025/exe
    Source: /tmp/IcwrPqGkXP (PID: 5253)File opened: /proc/2025/fd
    Source: /tmp/IcwrPqGkXP (PID: 5253)File opened: /proc/2025/fd
    Source: /tmp/IcwrPqGkXP (PID: 5253)File opened: /proc/2146/fd
    Source: /tmp/IcwrPqGkXP (PID: 5253)File opened: /proc/2146/fd
    Source: /tmp/IcwrPqGkXP (PID: 5253)File opened: /proc/2146/exe
    Source: /tmp/IcwrPqGkXP (PID: 5253)File opened: /proc/2146/fd
    Source: /tmp/IcwrPqGkXP (PID: 5253)File opened: /proc/2146/fd
    Source: /tmp/IcwrPqGkXP (PID: 5253)File opened: /proc/910/exe
    Source: /tmp/IcwrPqGkXP (PID: 5253)File opened: /proc/5259/fd
    Source: /tmp/IcwrPqGkXP (PID: 5253)File opened: /proc/5259/fd
    Source: /tmp/IcwrPqGkXP (PID: 5253)File opened: /proc/912/fd
    Source: /tmp/IcwrPqGkXP (PID: 5253)File opened: /proc/912/fd
    Source: /tmp/IcwrPqGkXP (PID: 5253)File opened: /proc/912/exe
    Source: /tmp/IcwrPqGkXP (PID: 5253)File opened: /proc/912/fd
    Source: /tmp/IcwrPqGkXP (PID: 5253)File opened: /proc/912/fd
    Source: /tmp/IcwrPqGkXP (PID: 5253)File opened: /proc/759/fd
    Source: /tmp/IcwrPqGkXP (PID: 5253)File opened: /proc/759/fd
    Source: /tmp/IcwrPqGkXP (PID: 5253)File opened: /proc/759/exe
    Source: /tmp/IcwrPqGkXP (PID: 5253)File opened: /proc/759/fd
    Source: /tmp/IcwrPqGkXP (PID: 5253)File opened: /proc/759/fd
    Source: /tmp/IcwrPqGkXP (PID: 5253)File opened: /proc/517/exe
    Source: /tmp/IcwrPqGkXP (PID: 5253)File opened: /proc/2307/fd
    Source: /tmp/IcwrPqGkXP (PID: 5253)File opened: /proc/2307/fd
    Source: /tmp/IcwrPqGkXP (PID: 5253)File opened: /proc/2307/exe
    Source: /tmp/IcwrPqGkXP (PID: 5253)File opened: /proc/2307/fd
    Source: /tmp/IcwrPqGkXP (PID: 5253)File opened: /proc/2307/fd
    Source: /tmp/IcwrPqGkXP (PID: 5253)File opened: /proc/918/fd
    Source: /tmp/IcwrPqGkXP (PID: 5253)File opened: /proc/918/fd
    Source: /tmp/IcwrPqGkXP (PID: 5253)File opened: /proc/918/exe
    Source: /tmp/IcwrPqGkXP (PID: 5253)File opened: /proc/918/fd
    Source: /tmp/IcwrPqGkXP (PID: 5253)File opened: /proc/918/fd
    Source: /tmp/IcwrPqGkXP (PID: 5253)File opened: /proc/5151/exe
    Source: /tmp/IcwrPqGkXP (PID: 5253)File opened: /proc/5274/fd
    Source: /tmp/IcwrPqGkXP (PID: 5253)File opened: /proc/5275/fd
    Source: /tmp/IcwrPqGkXP (PID: 5253)File opened: /proc/5276/fd

    Hooking and other Techniques for Hiding and Protection:

    barindex
    Uses known network protocols on non-standard portsShow sources
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43252
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43256
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43260
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43262
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43272
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43268
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43274
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43278
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43282
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43286
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43290
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43316
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43292
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43322
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43342
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43344
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43362
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43366
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43374
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43360
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37882
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37884
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37888
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37890
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37892
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37896
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37898
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37900
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37908
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37914
    Source: /tmp/IcwrPqGkXP (PID: 5250)Queries kernel information via 'uname':
    Source: IcwrPqGkXP, 5250.1.0000000020017d06.000000003f0ad8fa.rw-.sdmpBinary or memory string: U!/etc/qemu-binfmt/mips
    Source: IcwrPqGkXP, 5250.1.0000000020017d06.000000003f0ad8fa.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/mips
    Source: IcwrPqGkXP, 5253.1.000000003f0ad8fa.000000001a2aa0c5.rw-.sdmpBinary or memory string: /usr/bin/vmtoolsd
    Source: IcwrPqGkXP, 5250.1.000000008c28e82d.0000000037a278d6.rw-.sdmpBinary or memory string: /usr/bin/qemu-mips
    Source: IcwrPqGkXP, 5253.1.000000003f0ad8fa.000000001a2aa0c5.rw-.sdmpBinary or memory string: U!/proc/2146/fd/11mips/pr1/usr/bin/vmtoolsdips/
    Source: IcwrPqGkXP, 5250.1.000000008c28e82d.0000000037a278d6.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-mips/tmp/IcwrPqGkXPSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/IcwrPqGkXP
    Source: IcwrPqGkXP, 5253.1.000000003f0ad8fa.000000001a2aa0c5.rw-.sdmpBinary or memory string: Uu-binfmt/mips/r10!/proc/1627/fd/14!/proc/797/fd/351/proc/1886/fd/48mips/r10!/proc/1627/fd/13!/proc/797/fd/361/proc/2096/fd/3/mips/r10!/proc/1627/fd/12!/proc/797/fd/371/proc/1886/fd/49mips/r10!/proc/1627/fd/10!/proc/797/fd/391/usr/bin/qemu-mipsps/r10!/proc/1627/fd/90!/proc/799/exe1/proc/1886/fd/50mips/r10!/proc/1627/fd/80!/proc/799/fd1/proc/2096/fd/2/mips/r10!/proc/1627/fd/70!/proc/799/fd/.1/proc/1886/fd/51mips/r10!/proc/1627/fd/60!/proc/799/fd/..10

    Stealing of Sensitive Information:

    barindex
    Yara detected MiraiShow sources
    Source: Yara matchFile source: dump.pcap, type: PCAP

    Remote Access Functionality:

    barindex
    Yara detected MiraiShow sources
    Source: Yara matchFile source: dump.pcap, type: PCAP

    Mitre Att&ck Matrix

    Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
    Valid AccountsWindows Management InstrumentationPath InterceptionPath InterceptionDirect Volume AccessOS Credential Dumping1Security Software Discovery11Remote ServicesData from Local SystemExfiltration Over Other Network MediumEncrypted Channel1Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
    Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over BluetoothNon-Standard Port11Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
    Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated ExfiltrationApplication Layer Protocol1Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data

    Malware Configuration

    No configs have been found

    Behavior Graph

    Hide Legend

    Legend:

    • Process
    • Signature
    • Created File
    • DNS/IP Info
    • Is Dropped
    • Number of created Files
    • Is malicious
    • Internet
    behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 507447 Sample: IcwrPqGkXP Startdate: 22/10/2021 Architecture: LINUX Score: 72 30 216.80.250.213 WINDSTREAMUS United States 2->30 32 130.250.57.142 VXCHNGE-TX01US United States 2->32 34 98 other IPs or domains 2->34 38 Snort IDS alert for network traffic (e.g. based on Emerging Threat rules) 2->38 40 Multi AV Scanner detection for submitted file 2->40 42 Yara detected Mirai 2->42 44 Uses known network protocols on non-standard ports 2->44 8 IcwrPqGkXP 2->8         started        10 systemd sshd 2->10         started        12 systemd sshd 2->12         started        14 4 other processes 2->14 signatures3 process4 process5 16 IcwrPqGkXP 8->16         started        18 IcwrPqGkXP 8->18         started        21 IcwrPqGkXP 8->21         started        signatures6 23 IcwrPqGkXP 16->23         started        26 IcwrPqGkXP 16->26         started        28 IcwrPqGkXP 16->28         started        36 Sample tries to kill many processes (SIGKILL) 18->36 process7 signatures8 46 Sample tries to kill many processes (SIGKILL) 23->46

    Screenshots

    Thumbnails

    This section contains all screenshots as thumbnails, including those not shown in the slideshow.

    windows-stand

    Antivirus, Machine Learning and Genetic Malware Detection

    Initial Sample

    SourceDetectionScannerLabelLink
    IcwrPqGkXP50%VirustotalBrowse
    IcwrPqGkXP55%ReversingLabsLinux.Trojan.Mirai

    Dropped Files

    No Antivirus matches

    Domains

    No Antivirus matches

    URLs

    No Antivirus matches

    Domains and IPs

    Contacted Domains

    No contacted domains info

    Contacted IPs

    • No. of IPs < 25%
    • 25% < No. of IPs < 50%
    • 50% < No. of IPs < 75%
    • 75% < No. of IPs

    Public

    IPDomainCountryFlagASNASN NameMalicious
    151.142.57.149
    unknownUnited States
    10967HOMEDEPOTNETUSfalse
    186.246.4.65
    unknownBrazil
    7738TelemarNorteLesteSABRfalse
    136.244.180.180
    unknownUnited States
    3606CONNCOLL-ASUSfalse
    114.246.134.99
    unknownChina
    4808CHINA169-BJChinaUnicomBeijingProvinceNetworkCNfalse
    87.99.160.241
    unknownSweden
    12501NORRNODITSSEfalse
    220.10.138.154
    unknownJapan17676GIGAINFRASoftbankBBCorpJPfalse
    111.98.122.40
    unknownJapan2516KDDIKDDICORPORATIONJPfalse
    168.245.234.50
    unknownUnited States
    393706NELSONCABLEUSfalse
    191.169.131.225
    unknownBrazil
    26615TIMSABRfalse
    201.21.20.15
    unknownBrazil
    28573CLAROSABRfalse
    115.191.0.168
    unknownChina
    7497CSTNET-AS-APComputerNetworkInformationCenterCNfalse
    182.67.0.254
    unknownIndia
    45609BHARTI-MOBILITY-AS-APBhartiAirtelLtdASforGPRSServicefalse
    184.254.1.5
    unknownUnited States
    10507SPCSUSfalse
    149.12.44.6
    unknownUnited States
    48945IFNL-ASGBfalse
    240.193.66.243
    unknownReserved
    unknownunknownfalse
    216.221.62.137
    unknownCanada
    6280SYNAPSECAfalse
    130.250.57.142
    unknownUnited States
    394901VXCHNGE-TX01USfalse
    92.210.255.138
    unknownGermany
    3209VODANETInternationalIP-BackboneofVodafoneDEfalse
    175.244.101.81
    unknownKorea Republic of
    4766KIXS-AS-KRKoreaTelecomKRfalse
    109.226.128.16
    unknownGermany
    21032TELTA-ASDEfalse
    133.120.23.87
    unknownJapan2522PPP-EXPJapanNetworkInformationCenterJPfalse
    148.70.47.116
    unknownChina
    45090CNNIC-TENCENT-NET-APShenzhenTencentComputerSystemsCompafalse
    42.203.248.247
    unknownChina
    4134CHINANET-BACKBONENo31Jin-rongStreetCNfalse
    60.158.0.171
    unknownJapan17676GIGAINFRASoftbankBBCorpJPfalse
    151.112.119.144
    unknownUnited States
    32480LLUMCUSfalse
    110.111.113.82
    unknownChina
    38341CNNIC-HCENET-APHEXIEInformationtechnologyCoLtdCNfalse
    113.180.223.7
    unknownViet Nam
    45899VNPT-AS-VNVNPTCorpVNfalse
    61.185.194.127
    unknownChina
    4134CHINANET-BACKBONENo31Jin-rongStreetCNfalse
    67.206.151.115
    unknownUnited States
    26857TRUSTCOMM-ASUSfalse
    158.126.37.100
    unknownSweden
    31756COLORADOSPRINGS-GOVUSfalse
    213.146.201.54
    unknownPortugal
    5626ONIInternetServiceProviderPTfalse
    59.19.24.218
    unknownKorea Republic of
    4766KIXS-AS-KRKoreaTelecomKRfalse
    155.2.116.79
    unknownUnited States
    2386INS-ASUSfalse
    85.45.125.184
    unknownItaly
    3269ASN-IBSNAZITfalse
    5.160.167.152
    unknownIran (ISLAMIC Republic Of)
    42337RESPINA-ASIRfalse
    31.121.69.183
    unknownUnited Kingdom
    2856BT-UK-ASBTnetUKRegionalnetworkGBfalse
    159.7.220.25
    unknownSweden
    1906NORTHROP-GRUMMANUSfalse
    83.44.49.14
    unknownSpain
    3352TELEFONICA_DE_ESPANAESfalse
    84.247.123.155
    unknownRomania
    60509TELEPERFORMANCE-ASROfalse
    216.80.250.213
    unknownUnited States
    7029WINDSTREAMUSfalse
    61.111.143.75
    unknownKorea Republic of
    4670HYUNDAI-KRShinbiroKRfalse
    93.169.65.140
    unknownSaudi Arabia
    39891ALJAWWALSTC-ASSAfalse
    195.223.249.170
    unknownItaly
    3269ASN-IBSNAZITfalse
    8.135.206.253
    unknownSingapore
    37963CNNIC-ALIBABA-CN-NET-APHangzhouAlibabaAdvertisingCoLtdfalse
    192.244.191.206
    unknownJapan11363FUJITSU-USAUSfalse
    138.236.115.201
    unknownUnited States
    17234GACUSfalse
    94.42.249.41
    unknownPoland
    5588GTSCEGTSCentralEuropeAntelGermanyCZfalse
    199.3.5.110
    unknownUnited States
    1239SPRINTLINKUSfalse
    149.115.226.181
    unknownUnited States
    174COGENT-174USfalse
    96.66.178.36
    unknownUnited States
    7922COMCAST-7922USfalse
    195.66.5.176
    unknownGermany
    9063SAARGATE-ASVSENETGmbHDEfalse
    121.201.230.87
    unknownChina
    17623CNCGROUP-SZChinaUnicomShenzennetworkCNfalse
    188.13.148.235
    unknownItaly
    3269ASN-IBSNAZITfalse
    246.179.47.128
    unknownReserved
    unknownunknownfalse
    246.9.73.167
    unknownReserved
    unknownunknownfalse
    164.113.178.223
    unknownUnited States
    2495KANRENUSfalse
    44.26.197.42
    unknownUnited States
    63069SURELINEUSfalse
    197.2.84.140
    unknownTunisia
    37705TOPNETTNfalse
    78.50.41.178
    unknownGermany
    6805TDDE-ASN1DEfalse
    38.217.98.240
    unknownUnited States
    174COGENT-174USfalse
    115.247.124.243
    unknownIndia
    55836RELIANCEJIO-INRelianceJioInfocommLimitedINfalse
    184.11.40.157
    unknownUnited States
    7011FRONTIER-AND-CITIZENSUSfalse
    16.142.65.134
    unknownUnited States
    unknownunknownfalse
    204.8.204.13
    unknownAngola
    328165Banco-de-Investimento-RuralAOfalse
    223.221.104.203
    unknownChina
    4134CHINANET-BACKBONENo31Jin-rongStreetCNfalse
    45.145.30.173
    unknownTurkey
    197328INETLTDTRfalse
    82.141.139.16
    unknownHungary
    12301INVITECHHUfalse
    219.21.25.139
    unknownJapan17676GIGAINFRASoftbankBBCorpJPfalse
    185.70.34.116
    unknownUnited Kingdom
    201353NSUKGBfalse
    35.84.199.85
    unknownUnited States
    237MERIT-AS-14USfalse
    48.233.101.228
    unknownUnited States
    2686ATGS-MMD-ASUSfalse
    175.219.69.250
    unknownKorea Republic of
    4766KIXS-AS-KRKoreaTelecomKRfalse
    76.145.199.51
    unknownUnited States
    7922COMCAST-7922USfalse
    123.73.29.199
    unknownChina
    9394CTTNETChinaTieTongTelecommunicationsCorporationCNfalse
    221.163.247.179
    unknownKorea Republic of
    4766KIXS-AS-KRKoreaTelecomKRfalse
    183.3.52.187
    unknownChina
    4134CHINANET-BACKBONENo31Jin-rongStreetCNfalse
    17.109.252.29
    unknownUnited States
    714APPLE-ENGINEERINGUSfalse
    99.48.195.62
    unknownUnited States
    7018ATT-INTERNET4USfalse
    102.112.147.46
    unknownMauritius
    23889MauritiusTelecomMUfalse
    222.43.48.173
    unknownChina
    45069CNNIC-CTTSDNET-APchinatietongShandongnetCNfalse
    117.186.4.82
    unknownChina
    24400CMNET-V4SHANGHAI-AS-APShanghaiMobileCommunicationsCoLtfalse
    96.1.87.79
    unknownCanada
    852ASN852CAfalse
    157.10.154.106
    unknownunknown
    4837CHINA169-BACKBONECHINAUNICOMChina169BackboneCNfalse
    247.78.135.221
    unknownReserved
    unknownunknownfalse
    71.161.252.154
    unknownUnited States
    701UUNETUSfalse
    72.113.124.144
    unknownUnited States
    22394CELLCOUSfalse
    115.30.102.59
    unknownTaiwan; Republic of China (ROC)
    133747TRIUMPH-AS-APTRIUMPHDYNASTYLimitedHKfalse
    121.231.7.49
    unknownChina
    4134CHINANET-BACKBONENo31Jin-rongStreetCNfalse
    254.5.211.44
    unknownReserved
    unknownunknownfalse
    97.250.16.26
    unknownUnited States
    6167CELLCO-PARTUSfalse
    85.136.14.63
    unknownSpain
    12357COMUNITELSPAINESfalse
    211.91.48.146
    unknownChina
    4837CHINA169-BACKBONECHINAUNICOMChina169BackboneCNfalse
    48.171.221.80
    unknownUnited States
    2686ATGS-MMD-ASUSfalse
    9.172.67.125
    unknownUnited States
    3356LEVEL3USfalse
    255.56.145.124
    unknownReserved
    unknownunknownfalse
    203.27.10.136
    unknownChina
    2764AAPTAAPTLimitedAUfalse
    106.34.174.230
    unknownChina
    4134CHINANET-BACKBONENo31Jin-rongStreetCNfalse
    210.226.36.155
    unknownJapan4713OCNNTTCommunicationsCorporationJPfalse
    32.1.117.241
    unknownUnited States
    2686ATGS-MMD-ASUSfalse
    212.249.81.39
    unknownSwitzerland
    702UUNETUSfalse


    Runtime Messages

    Command:/tmp/IcwrPqGkXP
    Exit Code:0
    Exit Code Info:
    Killed:False
    Standard Output:
    Connected To CNC
    Standard Error:

    Joe Sandbox View / Context

    IPs

    No context

    Domains

    No context

    ASN

    MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
    TelemarNorteLesteSABRMPnFvIsvJpGet hashmaliciousBrowse
    • 201.19.52.194
    g22kPe2LIcGet hashmaliciousBrowse
    • 186.246.215.95
    cosvgegE1SGet hashmaliciousBrowse
    • 191.2.105.255
    gKCq4VLpjLGet hashmaliciousBrowse
    • 191.45.41.196
    uK570ZEpyQGet hashmaliciousBrowse
    • 191.214.237.61
    F3br85KuNXGet hashmaliciousBrowse
    • 201.18.7.193
    jviIYCvWBcGet hashmaliciousBrowse
    • 191.42.56.200
    pLpqV3XZ76Get hashmaliciousBrowse
    • 189.105.44.62
    ggtS1fKIqXGet hashmaliciousBrowse
    • 191.0.212.55
    sora.armGet hashmaliciousBrowse
    • 187.43.203.27
    buiodawbdawbuiopdw.x86Get hashmaliciousBrowse
    • 187.43.170.12
    Kot3UfQMDmGet hashmaliciousBrowse
    • 191.214.114.207
    arm7Get hashmaliciousBrowse
    • 201.58.44.232
    arm7Get hashmaliciousBrowse
    • 191.2.153.111
    JuofJwjQMTGet hashmaliciousBrowse
    • 189.104.65.237
    x86Get hashmaliciousBrowse
    • 189.105.20.47
    Z1JWqe0tZnGet hashmaliciousBrowse
    • 179.67.232.124
    raCyB7pYpdGet hashmaliciousBrowse
    • 152.237.114.166
    il32XbklZmGet hashmaliciousBrowse
    • 201.32.125.192
    7SerHvEAjEGet hashmaliciousBrowse
    • 179.68.219.97
    HOMEDEPOTNETUSil32XbklZmGet hashmaliciousBrowse
    • 151.140.99.116
    8A5Aub0x7rGet hashmaliciousBrowse
    • 151.140.70.186
    h8RVQktJXrGet hashmaliciousBrowse
    • 165.131.82.191
    KG7X7nyxQ4Get hashmaliciousBrowse
    • 165.130.201.189
    b3astmode.arm7Get hashmaliciousBrowse
    • 151.140.99.100
    3DAMhv0DFIGet hashmaliciousBrowse
    • 151.140.52.118
    jFQ6SEAt26Get hashmaliciousBrowse
    • 165.130.6.234
    2YrqtABAvtGet hashmaliciousBrowse
    • 165.131.138.205
    i64RJ7IpMWGet hashmaliciousBrowse
    • 207.11.39.140
    b3astmode.arm7Get hashmaliciousBrowse
    • 151.142.57.178
    l9Ix5r5wGZGet hashmaliciousBrowse
    • 165.130.248.172
    e5q6xjMRESGet hashmaliciousBrowse
    • 151.140.146.198
    DLGXmh48NDGet hashmaliciousBrowse
    • 151.142.57.102
    bwuBy0kegzGet hashmaliciousBrowse
    • 151.140.128.106
    x86_unpackedGet hashmaliciousBrowse
    • 151.142.57.160
    fil1Get hashmaliciousBrowse
    • 151.142.57.173

    JA3 Fingerprints

    No context

    Dropped Files

    No context

    Created / dropped Files

    /proc/5290/oom_score_adj
    Process:/usr/sbin/sshd
    File Type:ASCII text
    Category:dropped
    Size (bytes):6
    Entropy (8bit):1.7924812503605778
    Encrypted:false
    SSDEEP:3:ptn:Dn
    MD5:CBF282CC55ED0792C33D10003D1F760A
    SHA1:007DD8BD75468E6B7ABA4285E9B267202C7EAEED
    SHA-256:FCDBAB99FCC0F4409E5F9D7D6FC497780288B4C441698126BB62832412774D22
    SHA-512:4643A8675D213C7DA35CC0C2BFB3B6F20324F9C48AEA7BA79F470615698C9A0CEFDA45CAA1957FC29110EE746BC8458AB8AB1E43EB513912A5E1E8858812CC00
    Malicious:false
    Reputation:high, very likely benign file
    Preview: -1000.
    /proc/5405/oom_score_adj
    Process:/usr/sbin/sshd
    File Type:ASCII text
    Category:dropped
    Size (bytes):6
    Entropy (8bit):1.7924812503605778
    Encrypted:false
    SSDEEP:3:ptn:Dn
    MD5:CBF282CC55ED0792C33D10003D1F760A
    SHA1:007DD8BD75468E6B7ABA4285E9B267202C7EAEED
    SHA-256:FCDBAB99FCC0F4409E5F9D7D6FC497780288B4C441698126BB62832412774D22
    SHA-512:4643A8675D213C7DA35CC0C2BFB3B6F20324F9C48AEA7BA79F470615698C9A0CEFDA45CAA1957FC29110EE746BC8458AB8AB1E43EB513912A5E1E8858812CC00
    Malicious:false
    Reputation:high, very likely benign file
    Preview: -1000.
    /proc/5407/oom_score_adj
    Process:/usr/sbin/sshd
    File Type:ASCII text
    Category:dropped
    Size (bytes):6
    Entropy (8bit):1.7924812503605778
    Encrypted:false
    SSDEEP:3:ptn:Dn
    MD5:CBF282CC55ED0792C33D10003D1F760A
    SHA1:007DD8BD75468E6B7ABA4285E9B267202C7EAEED
    SHA-256:FCDBAB99FCC0F4409E5F9D7D6FC497780288B4C441698126BB62832412774D22
    SHA-512:4643A8675D213C7DA35CC0C2BFB3B6F20324F9C48AEA7BA79F470615698C9A0CEFDA45CAA1957FC29110EE746BC8458AB8AB1E43EB513912A5E1E8858812CC00
    Malicious:false
    Reputation:high, very likely benign file
    Preview: -1000.
    /run/sshd.pid
    Process:/usr/sbin/sshd
    File Type:ASCII text
    Category:dropped
    Size (bytes):5
    Entropy (8bit):2.321928094887362
    Encrypted:false
    SSDEEP:3:E4v:Ei
    MD5:C1CD8B3D865DA678B4D32DDFFA91B683
    SHA1:DBD80617342B88805FEC6EFEC7A720E751598798
    SHA-256:11D1C64BB9D6C776EF791C61A88BB582C6AD4C816754E5BF48C9327DDBF39BDF
    SHA-512:3B0D361F3DD594CFA593C98E571C58A3D86FB9A1F1E8F8C78F505BE5231C312E63AB5DD724BF3D8DEDE78DF740C5D0BAB5DB0DA1916EAAAB6A4BCA289A56B313
    Malicious:false
    Reputation:low
    Preview: 5407.

    Static File Info

    General

    File type:ELF 32-bit MSB executable, MIPS, MIPS-I version 1 (SYSV), statically linked, stripped
    Entropy (8bit):5.296758508714272
    TrID:
    • ELF Executable and Linkable format (generic) (4004/1) 100.00%
    File name:IcwrPqGkXP
    File size:71764
    MD5:18fe913ce8856fc1ea6ebc0412e09da7
    SHA1:ff1494dd42dcda452120a9af38a1f5550bd29c55
    SHA256:dea614c4a0a319bb53e0d5d9b77d360e23d79e43e4c7a5179c9c3f6b66c26e74
    SHA512:487221c1701546a05d979979ff75ceaf3600c504da5b6581ea90e627a81b07869442431a4d1b157cb9620c60d92d9d3ddee7d8de37249b7b402bc419eb4da617
    SSDEEP:1536:WkvDSnAd6mYoPdd8TVs1o0vB1tA0iLuYw2+O/82:WkLSA3vGko0pTAmYw2+OE2
    File Content Preview:.ELF.....................@.`...4...L.....4. ...(.............@...@...........................E...E..................dt.Q............................<...'......!'.......................<...'......!... ....'9... ......................<...'......!........'9.

    Static ELF Info

    ELF header

    Class:ELF32
    Data:2's complement, big endian
    Version:1 (current)
    Machine:MIPS R3000
    Version Number:0x1
    Type:EXEC (Executable file)
    OS/ABI:UNIX - System V
    ABI Version:0
    Entry Point Address:0x400260
    Flags:0x1007
    ELF Header Size:52
    Program Header Offset:52
    Program Header Size:32
    Number of Program Headers:3
    Section Header Offset:71244
    Section Header Size:40
    Number of Section Headers:13
    Header String Table Index:12

    Sections

    NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
    NULL0x00x00x00x00x0000
    .initPROGBITS0x4000940x940x8c0x00x6AX004
    .textPROGBITS0x4001200x1200xffe00x00x6AX0016
    .finiPROGBITS0x4101000x101000x5c0x00x6AX004
    .rodataPROGBITS0x4101600x101600x6600x00x2A0016
    .ctorsPROGBITS0x4510000x110000x80x00x3WA004
    .dtorsPROGBITS0x4510080x110080x80x00x3WA004
    .dataPROGBITS0x4510200x110200x1900x00x3WA0016
    .gotPROGBITS0x4511b00x111b00x4440x40x10000003WA0016
    .sbssNOBITS0x4515f40x115f40x240x00x10000003WA004
    .bssNOBITS0x4516200x115f40x2a00x00x3WA0016
    .mdebug.abi32PROGBITS0x72c0x115f40x00x00x0001
    .shstrtabSTRTAB0x00x115f40x570x00x0001

    Program Segments

    TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
    LOAD0x00x4000000x4000000x107c00x107c03.34920x5R E0x10000.init .text .fini .rodata
    LOAD0x110000x4510000x4510000x5f40x8c01.81170x6RW 0x10000.ctors .dtors .data .got .sbss .bss
    GNU_STACK0x00x00x00x00x00.00000x7RWE0x4

    Network Behavior

    Network Port Distribution

    TCP Packets

    TimestampSource PortDest PortSource IPDest IP
    Oct 22, 2021 09:09:20.965967894 CEST4251680192.168.2.23109.202.202.202
    Oct 22, 2021 09:09:21.455444098 CEST442001312192.168.2.23176.126.175.188
    Oct 22, 2021 09:09:21.466552973 CEST6239123192.168.2.2375.91.152.247
    Oct 22, 2021 09:09:21.466599941 CEST6239123192.168.2.23184.237.126.242
    Oct 22, 2021 09:09:21.466609955 CEST6239123192.168.2.23196.95.110.240
    Oct 22, 2021 09:09:21.466614962 CEST6239123192.168.2.2340.172.207.84
    Oct 22, 2021 09:09:21.466618061 CEST6239123192.168.2.23183.218.255.83
    Oct 22, 2021 09:09:21.466669083 CEST6239123192.168.2.23250.210.164.244
    Oct 22, 2021 09:09:21.466672897 CEST6239123192.168.2.23111.242.180.118
    Oct 22, 2021 09:09:21.466684103 CEST6239123192.168.2.23171.59.92.231
    Oct 22, 2021 09:09:21.466691017 CEST6239123192.168.2.23203.25.197.232
    Oct 22, 2021 09:09:21.466696978 CEST6239123192.168.2.23118.2.251.79
    Oct 22, 2021 09:09:21.466716051 CEST6239123192.168.2.23118.68.125.140
    Oct 22, 2021 09:09:21.466723919 CEST6239123192.168.2.2338.74.198.225
    Oct 22, 2021 09:09:21.466736078 CEST6239123192.168.2.23253.114.31.118
    Oct 22, 2021 09:09:21.466759920 CEST6239123192.168.2.23108.211.59.236
    Oct 22, 2021 09:09:21.466783047 CEST6239123192.168.2.23180.15.42.13
    Oct 22, 2021 09:09:21.466814041 CEST6239123192.168.2.23169.50.228.79
    Oct 22, 2021 09:09:21.466826916 CEST6239123192.168.2.23166.73.1.187
    Oct 22, 2021 09:09:21.466850996 CEST6239123192.168.2.23155.111.169.178
    Oct 22, 2021 09:09:21.466953039 CEST6239123192.168.2.2369.40.101.27
    Oct 22, 2021 09:09:21.466957092 CEST6239123192.168.2.23194.3.176.129
    Oct 22, 2021 09:09:21.466974974 CEST6239123192.168.2.23179.22.6.207
    Oct 22, 2021 09:09:21.466976881 CEST6239123192.168.2.23212.177.222.62
    Oct 22, 2021 09:09:21.467022896 CEST6239123192.168.2.2389.209.189.20
    Oct 22, 2021 09:09:21.467067003 CEST6239123192.168.2.2371.68.153.155
    Oct 22, 2021 09:09:21.467067003 CEST6239123192.168.2.23179.190.66.93
    Oct 22, 2021 09:09:21.467075109 CEST6239123192.168.2.23191.62.73.5
    Oct 22, 2021 09:09:21.467076063 CEST6239123192.168.2.23255.10.15.206
    Oct 22, 2021 09:09:21.467144012 CEST6239123192.168.2.2380.40.242.1
    Oct 22, 2021 09:09:21.467149019 CEST6239123192.168.2.23252.19.250.113
    Oct 22, 2021 09:09:21.467154026 CEST6239123192.168.2.2379.158.185.6
    Oct 22, 2021 09:09:21.467159986 CEST6239123192.168.2.2386.152.55.178
    Oct 22, 2021 09:09:21.467195988 CEST6239123192.168.2.23250.76.71.171
    Oct 22, 2021 09:09:21.467201948 CEST6239123192.168.2.23145.187.24.155
    Oct 22, 2021 09:09:21.467207909 CEST6239123192.168.2.234.31.189.126
    Oct 22, 2021 09:09:21.467210054 CEST6239123192.168.2.2395.9.175.225
    Oct 22, 2021 09:09:21.467214108 CEST6239123192.168.2.238.138.189.91
    Oct 22, 2021 09:09:21.467226028 CEST6239123192.168.2.23217.216.63.38
    Oct 22, 2021 09:09:21.467236996 CEST6239123192.168.2.23178.1.203.237
    Oct 22, 2021 09:09:21.467245102 CEST6239123192.168.2.2377.69.105.75
    Oct 22, 2021 09:09:21.467269897 CEST6239123192.168.2.23146.188.2.100
    Oct 22, 2021 09:09:21.467273951 CEST6239123192.168.2.23245.105.21.99
    Oct 22, 2021 09:09:21.467348099 CEST6239123192.168.2.23147.125.98.210
    Oct 22, 2021 09:09:21.467361927 CEST6239123192.168.2.23130.32.135.51
    Oct 22, 2021 09:09:21.467363119 CEST6239123192.168.2.23197.87.52.245
    Oct 22, 2021 09:09:21.467391014 CEST6239123192.168.2.23171.15.242.108
    Oct 22, 2021 09:09:21.467403889 CEST6239123192.168.2.23220.110.254.214
    Oct 22, 2021 09:09:21.467405081 CEST6239123192.168.2.23133.158.120.223
    Oct 22, 2021 09:09:21.467426062 CEST6239123192.168.2.23133.197.139.22
    Oct 22, 2021 09:09:21.467427015 CEST6239123192.168.2.23119.230.119.116
    Oct 22, 2021 09:09:21.467428923 CEST6239123192.168.2.23141.12.150.118
    Oct 22, 2021 09:09:21.467449903 CEST6239123192.168.2.23176.117.57.57
    Oct 22, 2021 09:09:21.467478037 CEST6239123192.168.2.23151.105.216.116
    Oct 22, 2021 09:09:21.467489004 CEST6239123192.168.2.23125.128.148.184
    Oct 22, 2021 09:09:21.467495918 CEST6239123192.168.2.23203.12.234.212
    Oct 22, 2021 09:09:21.467509031 CEST6239123192.168.2.23205.129.13.21
    Oct 22, 2021 09:09:21.467516899 CEST6239123192.168.2.23148.30.241.151
    Oct 22, 2021 09:09:21.467525005 CEST6239123192.168.2.23217.31.98.122
    Oct 22, 2021 09:09:21.467530966 CEST6239123192.168.2.2338.162.60.184
    Oct 22, 2021 09:09:21.467534065 CEST6239123192.168.2.2393.147.9.212
    Oct 22, 2021 09:09:21.467540026 CEST6239123192.168.2.2347.143.80.114
    Oct 22, 2021 09:09:21.467550039 CEST6239123192.168.2.23184.26.253.181
    Oct 22, 2021 09:09:21.467556953 CEST6239123192.168.2.23122.206.46.181
    Oct 22, 2021 09:09:21.467566013 CEST6239123192.168.2.234.38.148.189
    Oct 22, 2021 09:09:21.467590094 CEST6239123192.168.2.23248.132.18.249
    Oct 22, 2021 09:09:21.467600107 CEST6239123192.168.2.23194.8.42.200
    Oct 22, 2021 09:09:21.467638969 CEST6239123192.168.2.2391.40.204.126
    Oct 22, 2021 09:09:21.467641115 CEST6239123192.168.2.23187.246.203.208
    Oct 22, 2021 09:09:21.467674971 CEST6239123192.168.2.23165.198.68.235
    Oct 22, 2021 09:09:21.467772007 CEST6239123192.168.2.2313.158.85.12
    Oct 22, 2021 09:09:21.467799902 CEST6239123192.168.2.23190.2.58.243
    Oct 22, 2021 09:09:21.467828035 CEST6239123192.168.2.23172.113.205.5
    Oct 22, 2021 09:09:21.467840910 CEST6239123192.168.2.23142.67.39.229
    Oct 22, 2021 09:09:21.467844963 CEST6239123192.168.2.238.99.167.98
    Oct 22, 2021 09:09:21.467854023 CEST6239123192.168.2.23113.96.40.208
    Oct 22, 2021 09:09:21.467869997 CEST6239123192.168.2.23149.217.202.149
    Oct 22, 2021 09:09:21.467881918 CEST6239123192.168.2.23177.123.203.137
    Oct 22, 2021 09:09:21.467892885 CEST6239123192.168.2.2338.80.109.228
    Oct 22, 2021 09:09:21.467892885 CEST6239123192.168.2.2392.44.51.89
    Oct 22, 2021 09:09:21.467894077 CEST6239123192.168.2.23108.134.134.177
    Oct 22, 2021 09:09:21.467930079 CEST6239123192.168.2.23198.22.75.172
    Oct 22, 2021 09:09:21.467956066 CEST6239123192.168.2.23199.60.6.54
    Oct 22, 2021 09:09:21.467962980 CEST6239123192.168.2.23109.217.132.49
    Oct 22, 2021 09:09:21.467988014 CEST6239123192.168.2.23216.200.67.125
    Oct 22, 2021 09:09:21.467994928 CEST6239123192.168.2.23124.133.234.199
    Oct 22, 2021 09:09:21.468002081 CEST6239123192.168.2.23196.102.105.255
    Oct 22, 2021 09:09:21.468014002 CEST6239123192.168.2.23197.164.199.47
    Oct 22, 2021 09:09:21.468027115 CEST6239123192.168.2.2391.208.101.239
    Oct 22, 2021 09:09:21.468034029 CEST6239123192.168.2.23200.214.173.33
    Oct 22, 2021 09:09:21.468041897 CEST6239123192.168.2.23197.131.149.222
    Oct 22, 2021 09:09:21.468054056 CEST6239123192.168.2.23118.190.74.223
    Oct 22, 2021 09:09:21.468060017 CEST6239123192.168.2.2313.144.114.70
    Oct 22, 2021 09:09:21.468099117 CEST6239123192.168.2.23207.167.236.253
    Oct 22, 2021 09:09:21.468115091 CEST6239123192.168.2.23209.6.34.185
    Oct 22, 2021 09:09:21.468122005 CEST6239123192.168.2.2389.183.10.81
    Oct 22, 2021 09:09:21.468127966 CEST6239123192.168.2.23191.0.222.90
    Oct 22, 2021 09:09:21.468152046 CEST6239123192.168.2.23117.120.132.63
    Oct 22, 2021 09:09:21.468164921 CEST6239123192.168.2.23175.229.93.122
    Oct 22, 2021 09:09:21.468199015 CEST6239123192.168.2.2366.72.145.251

    System Behavior

    General

    Start time:09:09:20
    Start date:22/10/2021
    Path:/tmp/IcwrPqGkXP
    Arguments:/tmp/IcwrPqGkXP
    File size:5777432 bytes
    MD5 hash:0083f1f0e77be34ad27f849842bbb00c

    General

    Start time:09:09:20
    Start date:22/10/2021
    Path:/tmp/IcwrPqGkXP
    Arguments:n/a
    File size:5777432 bytes
    MD5 hash:0083f1f0e77be34ad27f849842bbb00c

    General

    Start time:09:09:20
    Start date:22/10/2021
    Path:/tmp/IcwrPqGkXP
    Arguments:n/a
    File size:5777432 bytes
    MD5 hash:0083f1f0e77be34ad27f849842bbb00c

    General

    Start time:09:09:20
    Start date:22/10/2021
    Path:/tmp/IcwrPqGkXP
    Arguments:n/a
    File size:5777432 bytes
    MD5 hash:0083f1f0e77be34ad27f849842bbb00c

    General

    Start time:09:09:20
    Start date:22/10/2021
    Path:/tmp/IcwrPqGkXP
    Arguments:n/a
    File size:5777432 bytes
    MD5 hash:0083f1f0e77be34ad27f849842bbb00c

    General

    Start time:09:09:20
    Start date:22/10/2021
    Path:/tmp/IcwrPqGkXP
    Arguments:n/a
    File size:5777432 bytes
    MD5 hash:0083f1f0e77be34ad27f849842bbb00c

    General

    Start time:09:09:20
    Start date:22/10/2021
    Path:/tmp/IcwrPqGkXP
    Arguments:n/a
    File size:5777432 bytes
    MD5 hash:0083f1f0e77be34ad27f849842bbb00c

    General

    Start time:09:09:33
    Start date:22/10/2021
    Path:/usr/lib/systemd/systemd
    Arguments:n/a
    File size:1620224 bytes
    MD5 hash:9b2bec7092a40488108543f9334aab75

    General

    Start time:09:09:33
    Start date:22/10/2021
    Path:/usr/sbin/sshd
    Arguments:/usr/sbin/sshd -t
    File size:876328 bytes
    MD5 hash:dbca7a6bbf7bf57fedac243d4b2cb340

    General

    Start time:09:09:34
    Start date:22/10/2021
    Path:/usr/lib/systemd/systemd
    Arguments:n/a
    File size:1620224 bytes
    MD5 hash:9b2bec7092a40488108543f9334aab75

    General

    Start time:09:09:34
    Start date:22/10/2021
    Path:/usr/sbin/sshd
    Arguments:/usr/sbin/sshd -D
    File size:876328 bytes
    MD5 hash:dbca7a6bbf7bf57fedac243d4b2cb340

    General

    Start time:09:12:19
    Start date:22/10/2021
    Path:/usr/lib/systemd/systemd
    Arguments:n/a
    File size:1620224 bytes
    MD5 hash:9b2bec7092a40488108543f9334aab75

    General

    Start time:09:12:19
    Start date:22/10/2021
    Path:/usr/sbin/sshd
    Arguments:/usr/sbin/sshd -t
    File size:876328 bytes
    MD5 hash:dbca7a6bbf7bf57fedac243d4b2cb340

    General

    Start time:09:12:19
    Start date:22/10/2021
    Path:/usr/lib/systemd/systemd
    Arguments:n/a
    File size:1620224 bytes
    MD5 hash:9b2bec7092a40488108543f9334aab75

    General

    Start time:09:12:19
    Start date:22/10/2021
    Path:/usr/sbin/sshd
    Arguments:/usr/sbin/sshd -D
    File size:876328 bytes
    MD5 hash:dbca7a6bbf7bf57fedac243d4b2cb340

    General

    Start time:09:12:21
    Start date:22/10/2021
    Path:/usr/lib/systemd/systemd
    Arguments:n/a
    File size:1620224 bytes
    MD5 hash:9b2bec7092a40488108543f9334aab75

    General

    Start time:09:12:21
    Start date:22/10/2021
    Path:/usr/sbin/sshd
    Arguments:/usr/sbin/sshd -t
    File size:876328 bytes
    MD5 hash:dbca7a6bbf7bf57fedac243d4b2cb340

    General

    Start time:09:12:21
    Start date:22/10/2021
    Path:/usr/lib/systemd/systemd
    Arguments:n/a
    File size:1620224 bytes
    MD5 hash:9b2bec7092a40488108543f9334aab75

    General

    Start time:09:12:21
    Start date:22/10/2021
    Path:/usr/sbin/sshd
    Arguments:/usr/sbin/sshd -D
    File size:876328 bytes
    MD5 hash:dbca7a6bbf7bf57fedac243d4b2cb340