Loading ...

Play interactive tourEdit tour

Linux Analysis Report iksM5QEg2j

Overview

General Information

Sample Name:iksM5QEg2j
Analysis ID:511504
MD5:d5f7312f62ca02ad0873bdd213dd71be
SHA1:d157216923829b73f69c4db6cf6d6bf80edd4962
SHA256:752b21a8ab77df1640dade907ad8268990665e0b00a3909b1bf19a23ef8c0770
Tags:32elfintel
Infos:

Most interesting Screenshot:

Detection

Score:52
Range:0 - 100
Whitelisted:false

Signatures

Multi AV Scanner detection for submitted file
Machine Learning detection for sample
Enumerates processes within the "proc" file system
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Detected TCP or UDP traffic on non-standard ports
Sample tries to kill a process (SIGKILL)
Sample has stripped symbol table

Classification

Analysis Advice

All HTTP servers contacted by the sample do not answer. Likely the sample is an old dropper which does no longer work

General Information

Joe Sandbox Version:34.0.0 Boulder Opal
Analysis ID:511504
Start date:29.10.2021
Start time:08:33:41
Joe Sandbox Product:CloudBasic
Overall analysis duration:0h 3m 55s
Hypervisor based Inspection enabled:false
Report type:light
Sample file name:iksM5QEg2j
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Detection:MAL
Classification:mal52.lin@0/0@0/0

Process Tree

  • system is lnxubuntu20
  • iksM5QEg2j (PID: 5236, Parent: 5112, MD5: d5f7312f62ca02ad0873bdd213dd71be) Arguments: /tmp/iksM5QEg2j
  • cleanup

Yara Overview

No yara matches

Jbx Signature Overview

Click to jump to signature section

Show All Signature Results

AV Detection:

barindex
Multi AV Scanner detection for submitted fileShow sources
Source: iksM5QEg2jVirustotal: Detection: 27%Perma Link
Machine Learning detection for sampleShow sources
Source: iksM5QEg2jJoe Sandbox ML: detected
Source: global trafficTCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
Source: global trafficTCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
Source: global trafficTCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
Source: global trafficTCP traffic: 192.168.2.23:56596 -> 45.95.169.120:455
Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443
Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: /tmp/iksM5QEg2j (PID: 5238)SIGKILL sent: pid: 2256, result: successful
Source: /tmp/iksM5QEg2j (PID: 5238)SIGKILL sent: pid: 2258, result: no such process
Source: /tmp/iksM5QEg2j (PID: 5238)SIGKILL sent: pid: 5193, result: successful
Source: /tmp/iksM5QEg2j (PID: 5238)SIGKILL sent: pid: 5194, result: successful
Source: /tmp/iksM5QEg2j (PID: 5238)SIGKILL sent: pid: 5310, result: successful
Source: /tmp/iksM5QEg2j (PID: 5238)SIGKILL sent: pid: 5314, result: successful
Source: ELF static info symbol of initial sample.symtab present: no
Source: classification engineClassification label: mal52.lin@0/0@0/0
Source: iksM5QEg2jJoe Sandbox Cloud Basic: Detection: clean Score: 0Perma Link
Source: /tmp/iksM5QEg2j (PID: 5238)File opened: /proc/5140/cmdline
Source: /tmp/iksM5QEg2j (PID: 5238)File opened: /proc/5140/cmdline
Source: /tmp/iksM5QEg2j (PID: 5238)File opened: /proc/5140/status
Source: /tmp/iksM5QEg2j (PID: 5238)File opened: /proc/5140/status
Source: /tmp/iksM5QEg2j (PID: 5238)File opened: /proc/1582/cmdline
Source: /tmp/iksM5QEg2j (PID: 5238)File opened: /proc/1582/cmdline
Source: /tmp/iksM5QEg2j (PID: 5238)File opened: /proc/1582/status
Source: /tmp/iksM5QEg2j (PID: 5238)File opened: /proc/1582/status
Source: /tmp/iksM5QEg2j (PID: 5238)File opened: /proc/3088/cmdline
Source: /tmp/iksM5QEg2j (PID: 5238)File opened: /proc/3088/cmdline
Source: /tmp/iksM5QEg2j (PID: 5238)File opened: /proc/3088/status
Source: /tmp/iksM5QEg2j (PID: 5238)File opened: /proc/3088/status
Source: /tmp/iksM5QEg2j (PID: 5238)File opened: /proc/230/cmdline
Source: /tmp/iksM5QEg2j (PID: 5238)File opened: /proc/230/cmdline
Source: /tmp/iksM5QEg2j (PID: 5238)File opened: /proc/230/status
Source: /tmp/iksM5QEg2j (PID: 5238)File opened: /proc/230/status
Source: /tmp/iksM5QEg2j (PID: 5238)File opened: /proc/110/cmdline
Source: /tmp/iksM5QEg2j (PID: 5238)File opened: /proc/110/cmdline
Source: /tmp/iksM5QEg2j (PID: 5238)File opened: /proc/110/status
Source: /tmp/iksM5QEg2j (PID: 5238)File opened: /proc/110/status
Source: /tmp/iksM5QEg2j (PID: 5238)File opened: /proc/231/cmdline
Source: /tmp/iksM5QEg2j (PID: 5238)File opened: /proc/231/cmdline
Source: /tmp/iksM5QEg2j (PID: 5238)File opened: /proc/231/status
Source: /tmp/iksM5QEg2j (PID: 5238)File opened: /proc/231/status
Source: /tmp/iksM5QEg2j (PID: 5238)File opened: /proc/111/cmdline
Source: /tmp/iksM5QEg2j (PID: 5238)File opened: /proc/111/cmdline
Source: /tmp/iksM5QEg2j (PID: 5238)File opened: /proc/111/status
Source: /tmp/iksM5QEg2j (PID: 5238)File opened: /proc/111/status
Source: /tmp/iksM5QEg2j (PID: 5238)File opened: /proc/232/cmdline
Source: /tmp/iksM5QEg2j (PID: 5238)File opened: /proc/232/cmdline
Source: /tmp/iksM5QEg2j (PID: 5238)File opened: /proc/232/status
Source: /tmp/iksM5QEg2j (PID: 5238)File opened: /proc/232/status
Source: /tmp/iksM5QEg2j (PID: 5238)File opened: /proc/1579/cmdline
Source: /tmp/iksM5QEg2j (PID: 5238)File opened: /proc/1579/cmdline
Source: /tmp/iksM5QEg2j (PID: 5238)File opened: /proc/1579/status
Source: /tmp/iksM5QEg2j (PID: 5238)File opened: /proc/1579/status
Source: /tmp/iksM5QEg2j (PID: 5238)File opened: /proc/112/cmdline
Source: /tmp/iksM5QEg2j (PID: 5238)File opened: /proc/112/cmdline
Source: /tmp/iksM5QEg2j (PID: 5238)File opened: /proc/112/status
Source: /tmp/iksM5QEg2j (PID: 5238)File opened: /proc/112/status
Source: /tmp/iksM5QEg2j (PID: 5238)File opened: /proc/233/cmdline
Source: /tmp/iksM5QEg2j (PID: 5238)File opened: /proc/233/cmdline
Source: /tmp/iksM5QEg2j (PID: 5238)File opened: /proc/233/status
Source: /tmp/iksM5QEg2j (PID: 5238)File opened: /proc/233/status
Source: /tmp/iksM5QEg2j (PID: 5238)File opened: /proc/1699/cmdline
Source: /tmp/iksM5QEg2j (PID: 5238)File opened: /proc/1699/cmdline
Source: /tmp/iksM5QEg2j (PID: 5238)File opened: /proc/1699/status
Source: /tmp/iksM5QEg2j (PID: 5238)File opened: /proc/1699/status
Source: /tmp/iksM5QEg2j (PID: 5238)File opened: /proc/113/cmdline
Source: /tmp/iksM5QEg2j (PID: 5238)File opened: /proc/113/cmdline
Source: /tmp/iksM5QEg2j (PID: 5238)File opened: /proc/113/status
Source: /tmp/iksM5QEg2j (PID: 5238)File opened: /proc/113/status
Source: /tmp/iksM5QEg2j (PID: 5238)File opened: /proc/234/cmdline
Source: /tmp/iksM5QEg2j (PID: 5238)File opened: /proc/234/cmdline
Source: /tmp/iksM5QEg2j (PID: 5238)File opened: /proc/234/status
Source: /tmp/iksM5QEg2j (PID: 5238)File opened: /proc/234/status
Source: /tmp/iksM5QEg2j (PID: 5238)File opened: /proc/1335/cmdline
Source: /tmp/iksM5QEg2j (PID: 5238)File opened: /proc/1335/cmdline
Source: /tmp/iksM5QEg2j (PID: 5238)File opened: /proc/1335/status
Source: /tmp/iksM5QEg2j (PID: 5238)File opened: /proc/1335/status
Source: /tmp/iksM5QEg2j (PID: 5238)File opened: /proc/1698/cmdline
Source: /tmp/iksM5QEg2j (PID: 5238)File opened: /proc/1698/cmdline
Source: /tmp/iksM5QEg2j (PID: 5238)File opened: /proc/1698/status
Source: /tmp/iksM5QEg2j (PID: 5238)File opened: /proc/1698/status
Source: /tmp/iksM5QEg2j (PID: 5238)File opened: /proc/114/cmdline
Source: /tmp/iksM5QEg2j (PID: 5238)File opened: /proc/114/cmdline
Source: /tmp/iksM5QEg2j (PID: 5238)File opened: /proc/114/status
Source: /tmp/iksM5QEg2j (PID: 5238)File opened: /proc/114/status
Source: /tmp/iksM5QEg2j (PID: 5238)File opened: /proc/235/cmdline
Source: /tmp/iksM5QEg2j (PID: 5238)File opened: /proc/235/cmdline
Source: /tmp/iksM5QEg2j (PID: 5238)File opened: /proc/235/status
Source: /tmp/iksM5QEg2j (PID: 5238)File opened: /proc/235/status
Source: /tmp/iksM5QEg2j (PID: 5238)File opened: /proc/1334/cmdline
Source: /tmp/iksM5QEg2j (PID: 5238)File opened: /proc/1334/cmdline
Source: /tmp/iksM5QEg2j (PID: 5238)File opened: /proc/1334/status
Source: /tmp/iksM5QEg2j (PID: 5238)File opened: /proc/1334/status
Source: /tmp/iksM5QEg2j (PID: 5238)File opened: /proc/1576/cmdline
Source: /tmp/iksM5QEg2j (PID: 5238)File opened: /proc/1576/cmdline
Source: /tmp/iksM5QEg2j (PID: 5238)File opened: /proc/1576/status
Source: /tmp/iksM5QEg2j (PID: 5238)File opened: /proc/1576/status
Source: /tmp/iksM5QEg2j (PID: 5238)File opened: /proc/2302/cmdline
Source: /tmp/iksM5QEg2j (PID: 5238)File opened: /proc/2302/cmdline
Source: /tmp/iksM5QEg2j (PID: 5238)File opened: /proc/2302/status
Source: /tmp/iksM5QEg2j (PID: 5238)File opened: /proc/2302/status
Source: /tmp/iksM5QEg2j (PID: 5238)File opened: /proc/115/cmdline
Source: /tmp/iksM5QEg2j (PID: 5238)File opened: /proc/115/cmdline
Source: /tmp/iksM5QEg2j (PID: 5238)File opened: /proc/115/status
Source: /tmp/iksM5QEg2j (PID: 5238)File opened: /proc/115/status
Source: /tmp/iksM5QEg2j (PID: 5238)File opened: /proc/236/cmdline
Source: /tmp/iksM5QEg2j (PID: 5238)File opened: /proc/236/cmdline
Source: /tmp/iksM5QEg2j (PID: 5238)File opened: /proc/236/status
Source: /tmp/iksM5QEg2j (PID: 5238)File opened: /proc/236/status
Source: /tmp/iksM5QEg2j (PID: 5238)File opened: /proc/116/cmdline
Source: /tmp/iksM5QEg2j (PID: 5238)File opened: /proc/116/cmdline
Source: /tmp/iksM5QEg2j (PID: 5238)File opened: /proc/116/status
Source: /tmp/iksM5QEg2j (PID: 5238)File opened: /proc/116/status
Source: /tmp/iksM5QEg2j (PID: 5238)File opened: /proc/237/cmdline
Source: /tmp/iksM5QEg2j (PID: 5238)File opened: /proc/237/cmdline
Source: /tmp/iksM5QEg2j (PID: 5238)File opened: /proc/237/status
Source: /tmp/iksM5QEg2j (PID: 5238)File opened: /proc/237/status
Source: /tmp/iksM5QEg2j (PID: 5238)File opened: /proc/117/cmdline
Source: /tmp/iksM5QEg2j (PID: 5238)File opened: /proc/117/cmdline
Source: /tmp/iksM5QEg2j (PID: 5238)File opened: /proc/117/status
Source: /tmp/iksM5QEg2j (PID: 5238)File opened: /proc/117/status
Source: /tmp/iksM5QEg2j (PID: 5238)File opened: /proc/118/cmdline
Source: /tmp/iksM5QEg2j (PID: 5238)File opened: /proc/118/cmdline
Source: /tmp/iksM5QEg2j (PID: 5238)File opened: /proc/118/status
Source: /tmp/iksM5QEg2j (PID: 5238)File opened: /proc/118/status

Mitre Att&ck Matrix

Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid AccountsWindows Management InstrumentationPath InterceptionPath InterceptionDirect Volume AccessOS Credential Dumping1System Service DiscoveryRemote ServicesData from Local SystemExfiltration Over Other Network MediumEncrypted Channel1Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over BluetoothNon-Standard Port1Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated ExfiltrationApplication Layer Protocol1Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data

Malware Configuration

No configs have been found

Behavior Graph

Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet

Screenshots

Thumbnails

This section contains all screenshots as thumbnails, including those not shown in the slideshow.

windows-stand

Antivirus, Machine Learning and Genetic Malware Detection

Initial Sample

SourceDetectionScannerLabelLink
iksM5QEg2j27%VirustotalBrowse
iksM5QEg2j100%Joe Sandbox ML

Dropped Files

No Antivirus matches

Domains

No Antivirus matches

URLs

No Antivirus matches

Domains and IPs

Contacted Domains

No contacted domains info

Contacted IPs

  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs

Public

IPDomainCountryFlagASNASN NameMalicious
45.95.169.120
unknownCroatia (LOCAL Name: Hrvatska)
42864GIGANET-HUGigaNetInternetServiceProviderCoHUfalse
109.202.202.202
unknownSwitzerland
13030INIT7CHfalse
91.189.91.43
unknownUnited Kingdom
41231CANONICAL-ASGBfalse
91.189.91.42
unknownUnited Kingdom
41231CANONICAL-ASGBfalse


Runtime Messages

Command:/tmp/iksM5QEg2j
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:

Standard Error:

Joe Sandbox View / Context

IPs

MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
109.202.202.202lGJEkz80oeGet hashmaliciousBrowse
    roV7kGaVr1Get hashmaliciousBrowse
      SecuriteInfo.com.Linux.Siggen.4218.298.3210Get hashmaliciousBrowse
        uPOWBxniTAGet hashmaliciousBrowse
          qy5unieRgRGet hashmaliciousBrowse
            sAzPpn6mKZGet hashmaliciousBrowse
              AxadDC89j9Get hashmaliciousBrowse
                ZErnXU2XR1Get hashmaliciousBrowse
                  sTHJvS5LPJGet hashmaliciousBrowse
                    THzHjYQ4z6Get hashmaliciousBrowse
                      jC0B6sMh1dGet hashmaliciousBrowse
                        JoLmvC65B7Get hashmaliciousBrowse
                          AOaKSm1cijGet hashmaliciousBrowse
                            Mozi.aGet hashmaliciousBrowse
                              ggbMKQDdG2Get hashmaliciousBrowse
                                SecuriteInfo.com.Linux.Siggen.4218.31606.9155Get hashmaliciousBrowse
                                  AbriuSDkeLGet hashmaliciousBrowse
                                    xjmPNreY8IGet hashmaliciousBrowse
                                      u7kjf23xQcGet hashmaliciousBrowse
                                        nrT4coM180Get hashmaliciousBrowse
                                          91.189.91.43lGJEkz80oeGet hashmaliciousBrowse
                                            roV7kGaVr1Get hashmaliciousBrowse
                                              SecuriteInfo.com.Linux.Siggen.4218.298.3210Get hashmaliciousBrowse
                                                uPOWBxniTAGet hashmaliciousBrowse
                                                  qy5unieRgRGet hashmaliciousBrowse
                                                    sAzPpn6mKZGet hashmaliciousBrowse
                                                      AxadDC89j9Get hashmaliciousBrowse
                                                        ZErnXU2XR1Get hashmaliciousBrowse
                                                          sTHJvS5LPJGet hashmaliciousBrowse
                                                            THzHjYQ4z6Get hashmaliciousBrowse
                                                              jC0B6sMh1dGet hashmaliciousBrowse
                                                                JoLmvC65B7Get hashmaliciousBrowse
                                                                  AOaKSm1cijGet hashmaliciousBrowse
                                                                    Mozi.aGet hashmaliciousBrowse
                                                                      ggbMKQDdG2Get hashmaliciousBrowse
                                                                        SecuriteInfo.com.Linux.Siggen.4218.31606.9155Get hashmaliciousBrowse
                                                                          AbriuSDkeLGet hashmaliciousBrowse
                                                                            xjmPNreY8IGet hashmaliciousBrowse
                                                                              u7kjf23xQcGet hashmaliciousBrowse
                                                                                nrT4coM180Get hashmaliciousBrowse
                                                                                  91.189.91.42lGJEkz80oeGet hashmaliciousBrowse
                                                                                    roV7kGaVr1Get hashmaliciousBrowse
                                                                                      SecuriteInfo.com.Linux.Siggen.4218.298.3210Get hashmaliciousBrowse
                                                                                        uPOWBxniTAGet hashmaliciousBrowse
                                                                                          qy5unieRgRGet hashmaliciousBrowse
                                                                                            sAzPpn6mKZGet hashmaliciousBrowse
                                                                                              AxadDC89j9Get hashmaliciousBrowse
                                                                                                ZErnXU2XR1Get hashmaliciousBrowse
                                                                                                  sTHJvS5LPJGet hashmaliciousBrowse
                                                                                                    THzHjYQ4z6Get hashmaliciousBrowse
                                                                                                      jC0B6sMh1dGet hashmaliciousBrowse
                                                                                                        JoLmvC65B7Get hashmaliciousBrowse
                                                                                                          AOaKSm1cijGet hashmaliciousBrowse
                                                                                                            Mozi.aGet hashmaliciousBrowse
                                                                                                              ggbMKQDdG2Get hashmaliciousBrowse
                                                                                                                SecuriteInfo.com.Linux.Siggen.4218.31606.9155Get hashmaliciousBrowse
                                                                                                                  AbriuSDkeLGet hashmaliciousBrowse
                                                                                                                    xjmPNreY8IGet hashmaliciousBrowse
                                                                                                                      u7kjf23xQcGet hashmaliciousBrowse
                                                                                                                        nrT4coM180Get hashmaliciousBrowse

                                                                                                                          Domains

                                                                                                                          No context

                                                                                                                          ASN

                                                                                                                          MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                                                                                                                          CANONICAL-ASGBlGJEkz80oeGet hashmaliciousBrowse
                                                                                                                          • 91.189.91.42
                                                                                                                          roV7kGaVr1Get hashmaliciousBrowse
                                                                                                                          • 91.189.91.42
                                                                                                                          SecuriteInfo.com.Linux.Siggen.4218.298.3210Get hashmaliciousBrowse
                                                                                                                          • 91.189.91.42
                                                                                                                          uPOWBxniTAGet hashmaliciousBrowse
                                                                                                                          • 91.189.91.42
                                                                                                                          qy5unieRgRGet hashmaliciousBrowse
                                                                                                                          • 91.189.91.42
                                                                                                                          sAzPpn6mKZGet hashmaliciousBrowse
                                                                                                                          • 91.189.91.42
                                                                                                                          AxadDC89j9Get hashmaliciousBrowse
                                                                                                                          • 91.189.91.42
                                                                                                                          ZErnXU2XR1Get hashmaliciousBrowse
                                                                                                                          • 91.189.91.42
                                                                                                                          sTHJvS5LPJGet hashmaliciousBrowse
                                                                                                                          • 91.189.91.42
                                                                                                                          THzHjYQ4z6Get hashmaliciousBrowse
                                                                                                                          • 91.189.91.42
                                                                                                                          jC0B6sMh1dGet hashmaliciousBrowse
                                                                                                                          • 91.189.91.42
                                                                                                                          JoLmvC65B7Get hashmaliciousBrowse
                                                                                                                          • 91.189.91.42
                                                                                                                          AOaKSm1cijGet hashmaliciousBrowse
                                                                                                                          • 91.189.91.42
                                                                                                                          Mozi.aGet hashmaliciousBrowse
                                                                                                                          • 91.189.91.42
                                                                                                                          ggbMKQDdG2Get hashmaliciousBrowse
                                                                                                                          • 91.189.91.42
                                                                                                                          SecuriteInfo.com.Linux.Siggen.4218.31606.9155Get hashmaliciousBrowse
                                                                                                                          • 91.189.91.42
                                                                                                                          AbriuSDkeLGet hashmaliciousBrowse
                                                                                                                          • 91.189.91.42
                                                                                                                          xjmPNreY8IGet hashmaliciousBrowse
                                                                                                                          • 91.189.91.42
                                                                                                                          u7kjf23xQcGet hashmaliciousBrowse
                                                                                                                          • 91.189.91.42
                                                                                                                          nrT4coM180Get hashmaliciousBrowse
                                                                                                                          • 91.189.91.42
                                                                                                                          GIGANET-HUGigaNetInternetServiceProviderCoHURicwIfIHLKGet hashmaliciousBrowse
                                                                                                                          • 45.95.169.115
                                                                                                                          aIY7AxjUMcGet hashmaliciousBrowse
                                                                                                                          • 45.95.169.115
                                                                                                                          DtJmFQxtNCGet hashmaliciousBrowse
                                                                                                                          • 45.95.169.115
                                                                                                                          Wm4CzOCmNYGet hashmaliciousBrowse
                                                                                                                          • 45.95.169.115
                                                                                                                          vunWUzXJvCGet hashmaliciousBrowse
                                                                                                                          • 45.95.169.115
                                                                                                                          52xhBHy9WzGet hashmaliciousBrowse
                                                                                                                          • 45.95.169.115
                                                                                                                          YGvwG0iCDEGet hashmaliciousBrowse
                                                                                                                          • 45.95.169.115
                                                                                                                          dbd5O0RUTqGet hashmaliciousBrowse
                                                                                                                          • 45.95.169.115
                                                                                                                          fHVDVj0pzOGet hashmaliciousBrowse
                                                                                                                          • 45.95.169.115
                                                                                                                          eZPk7Fg5w7Get hashmaliciousBrowse
                                                                                                                          • 45.95.169.115
                                                                                                                          ph5PjoFBpjGet hashmaliciousBrowse
                                                                                                                          • 45.95.169.115
                                                                                                                          xugAk5haatGet hashmaliciousBrowse
                                                                                                                          • 45.95.169.115
                                                                                                                          0jEbWQtzs0Get hashmaliciousBrowse
                                                                                                                          • 45.95.169.115
                                                                                                                          8g3tc5SWwBGet hashmaliciousBrowse
                                                                                                                          • 92.52.211.220
                                                                                                                          7okgnZjK06Get hashmaliciousBrowse
                                                                                                                          • 45.95.169.115
                                                                                                                          D9efs9TYvNGet hashmaliciousBrowse
                                                                                                                          • 45.95.169.115
                                                                                                                          LlE7nUUjmAGet hashmaliciousBrowse
                                                                                                                          • 45.95.169.115
                                                                                                                          3HwsuWd7atGet hashmaliciousBrowse
                                                                                                                          • 45.95.169.115
                                                                                                                          XOg0GKdALNGet hashmaliciousBrowse
                                                                                                                          • 45.95.169.115
                                                                                                                          2VSJDSxulvGet hashmaliciousBrowse
                                                                                                                          • 45.95.169.115
                                                                                                                          INIT7CHlGJEkz80oeGet hashmaliciousBrowse
                                                                                                                          • 109.202.202.202
                                                                                                                          roV7kGaVr1Get hashmaliciousBrowse
                                                                                                                          • 109.202.202.202
                                                                                                                          SecuriteInfo.com.Linux.Siggen.4218.298.3210Get hashmaliciousBrowse
                                                                                                                          • 109.202.202.202
                                                                                                                          uPOWBxniTAGet hashmaliciousBrowse
                                                                                                                          • 109.202.202.202
                                                                                                                          qy5unieRgRGet hashmaliciousBrowse
                                                                                                                          • 109.202.202.202
                                                                                                                          sAzPpn6mKZGet hashmaliciousBrowse
                                                                                                                          • 109.202.202.202
                                                                                                                          AxadDC89j9Get hashmaliciousBrowse
                                                                                                                          • 109.202.202.202
                                                                                                                          ZErnXU2XR1Get hashmaliciousBrowse
                                                                                                                          • 109.202.202.202
                                                                                                                          sTHJvS5LPJGet hashmaliciousBrowse
                                                                                                                          • 109.202.202.202
                                                                                                                          THzHjYQ4z6Get hashmaliciousBrowse
                                                                                                                          • 109.202.202.202
                                                                                                                          jC0B6sMh1dGet hashmaliciousBrowse
                                                                                                                          • 109.202.202.202
                                                                                                                          JoLmvC65B7Get hashmaliciousBrowse
                                                                                                                          • 109.202.202.202
                                                                                                                          AOaKSm1cijGet hashmaliciousBrowse
                                                                                                                          • 109.202.202.202
                                                                                                                          Mozi.aGet hashmaliciousBrowse
                                                                                                                          • 109.202.202.202
                                                                                                                          ggbMKQDdG2Get hashmaliciousBrowse
                                                                                                                          • 109.202.202.202
                                                                                                                          SecuriteInfo.com.Linux.Siggen.4218.31606.9155Get hashmaliciousBrowse
                                                                                                                          • 109.202.202.202
                                                                                                                          AbriuSDkeLGet hashmaliciousBrowse
                                                                                                                          • 109.202.202.202
                                                                                                                          xjmPNreY8IGet hashmaliciousBrowse
                                                                                                                          • 109.202.202.202
                                                                                                                          u7kjf23xQcGet hashmaliciousBrowse
                                                                                                                          • 109.202.202.202
                                                                                                                          nrT4coM180Get hashmaliciousBrowse
                                                                                                                          • 109.202.202.202

                                                                                                                          JA3 Fingerprints

                                                                                                                          No context

                                                                                                                          Dropped Files

                                                                                                                          No context

                                                                                                                          Created / dropped Files

                                                                                                                          No created / dropped files found

                                                                                                                          Static File Info

                                                                                                                          General

                                                                                                                          File type:ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, stripped
                                                                                                                          Entropy (8bit):6.216846948570903
                                                                                                                          TrID:
                                                                                                                          • ELF Executable and Linkable format (Linux) (4029/14) 50.16%
                                                                                                                          • ELF Executable and Linkable format (generic) (4004/1) 49.84%
                                                                                                                          File name:iksM5QEg2j
                                                                                                                          File size:34032
                                                                                                                          MD5:d5f7312f62ca02ad0873bdd213dd71be
                                                                                                                          SHA1:d157216923829b73f69c4db6cf6d6bf80edd4962
                                                                                                                          SHA256:752b21a8ab77df1640dade907ad8268990665e0b00a3909b1bf19a23ef8c0770
                                                                                                                          SHA512:b047436a6b9a89b3126e5d95ff6ace8d42985780620d0a7ee2b65e53590de0db5a06f33f2a0cc7fc5d6fd8ce929e16b56134509a1fec59bc1bd46da714673ed0
                                                                                                                          SSDEEP:384:fXxT87+xyCCy/hGAzz9H/wm1h9+Ezq7H8OOhPWMq:/xT87+M0Xfwm0EzqD8OkOl
                                                                                                                          File Content Preview:.ELF....................d...4...`.......4. ...(......................h...h...............p.......... ....(..........Q.td............................U..S.......wo...h....#`..[]...$.............U......= ....t..5....$......$.......u........t....h............

                                                                                                                          Static ELF Info

                                                                                                                          ELF header

                                                                                                                          Class:ELF32
                                                                                                                          Data:2's complement, little endian
                                                                                                                          Version:1 (current)
                                                                                                                          Machine:Intel 80386
                                                                                                                          Version Number:0x1
                                                                                                                          Type:EXEC (Executable file)
                                                                                                                          OS/ABI:UNIX - System V
                                                                                                                          ABI Version:0
                                                                                                                          Entry Point Address:0x8048164
                                                                                                                          Flags:0x0
                                                                                                                          ELF Header Size:52
                                                                                                                          Program Header Offset:52
                                                                                                                          Program Header Size:32
                                                                                                                          Number of Program Headers:3
                                                                                                                          Section Header Offset:33632
                                                                                                                          Section Header Size:40
                                                                                                                          Number of Section Headers:10
                                                                                                                          Header String Table Index:9

                                                                                                                          Sections

                                                                                                                          NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                                                                                                          NULL0x00x00x00x00x0000
                                                                                                                          .initPROGBITS0x80480940x940x1c0x00x6AX001
                                                                                                                          .textPROGBITS0x80480b00xb00x60460x00x6AX0016
                                                                                                                          .finiPROGBITS0x804e0f60x60f60x170x00x6AX001
                                                                                                                          .rodataPROGBITS0x804e1200x61200x7600x00x2A0032
                                                                                                                          .ctorsPROGBITS0x804f0000x70000x80x00x3WA004
                                                                                                                          .dtorsPROGBITS0x804f0080x70080x80x00x3WA004
                                                                                                                          .dataPROGBITS0x804f0200x70200x13000x00x3WA0032
                                                                                                                          .bssNOBITS0x80503200x83200x15800x00x3WA0032
                                                                                                                          .shstrtabSTRTAB0x00x83200x3e0x00x0001

                                                                                                                          Program Segments

                                                                                                                          TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                                                                                          LOAD0x00x80480000x80480000x68800x68803.84500x5R E0x1000.init .text .fini .rodata
                                                                                                                          LOAD0x70000x804f0000x804f0000x13200x28a01.70470x6RW 0x1000.ctors .dtors .data .bss
                                                                                                                          GNU_STACK0x00x00x00x00x00.00000x6RW 0x4

                                                                                                                          Network Behavior

                                                                                                                          Network Port Distribution

                                                                                                                          TCP Packets

                                                                                                                          TimestampSource PortDest PortSource IPDest IP
                                                                                                                          Oct 29, 2021 08:34:27.722455978 CEST56596455192.168.2.2345.95.169.120
                                                                                                                          Oct 29, 2021 08:34:28.012080908 CEST42836443192.168.2.2391.189.91.43
                                                                                                                          Oct 29, 2021 08:34:28.268069983 CEST4251680192.168.2.23109.202.202.202
                                                                                                                          Oct 29, 2021 08:34:28.748022079 CEST56596455192.168.2.2345.95.169.120
                                                                                                                          Oct 29, 2021 08:34:30.763940096 CEST56596455192.168.2.2345.95.169.120
                                                                                                                          Oct 29, 2021 08:34:34.927752972 CEST56596455192.168.2.2345.95.169.120
                                                                                                                          Oct 29, 2021 08:34:43.115407944 CEST56596455192.168.2.2345.95.169.120
                                                                                                                          Oct 29, 2021 08:34:43.627465010 CEST43928443192.168.2.2391.189.91.42
                                                                                                                          Oct 29, 2021 08:34:53.866913080 CEST42836443192.168.2.2391.189.91.43
                                                                                                                          Oct 29, 2021 08:34:57.962716103 CEST4251680192.168.2.23109.202.202.202
                                                                                                                          Oct 29, 2021 08:34:59.242724895 CEST56596455192.168.2.2345.95.169.120
                                                                                                                          Oct 29, 2021 08:35:24.585443020 CEST43928443192.168.2.2391.189.91.42
                                                                                                                          Oct 29, 2021 08:35:32.777060986 CEST56596455192.168.2.2345.95.169.120
                                                                                                                          Oct 29, 2021 08:35:45.064485073 CEST42836443192.168.2.2391.189.91.43

                                                                                                                          System Behavior

                                                                                                                          General

                                                                                                                          Start time:08:34:26
                                                                                                                          Start date:29/10/2021
                                                                                                                          Path:/tmp/iksM5QEg2j
                                                                                                                          Arguments:/tmp/iksM5QEg2j
                                                                                                                          File size:34032 bytes
                                                                                                                          MD5 hash:d5f7312f62ca02ad0873bdd213dd71be

                                                                                                                          General

                                                                                                                          Start time:08:34:26
                                                                                                                          Start date:29/10/2021
                                                                                                                          Path:/tmp/iksM5QEg2j
                                                                                                                          Arguments:n/a
                                                                                                                          File size:34032 bytes
                                                                                                                          MD5 hash:d5f7312f62ca02ad0873bdd213dd71be

                                                                                                                          General

                                                                                                                          Start time:08:34:26
                                                                                                                          Start date:29/10/2021
                                                                                                                          Path:/tmp/iksM5QEg2j
                                                                                                                          Arguments:n/a
                                                                                                                          File size:34032 bytes
                                                                                                                          MD5 hash:d5f7312f62ca02ad0873bdd213dd71be