Loading ...

Play interactive tourEdit tour

Linux Analysis Report YpKL484IG5

Overview

General Information

Sample Name:YpKL484IG5
Analysis ID:511523
MD5:e9e2ace904c9f2049ee2d16403868e50
SHA1:dcd1a8cef227c63725ed272a8b9e83f8306104d8
SHA256:0ace9c1e48517f73c6385f9ebdf3f67a9e7a37bddca6503e1d8f5f6ad7dc91a6
Tags:32elfrenesas
Infos:

Most interesting Screenshot:

Detection

Score:48
Range:0 - 100
Whitelisted:false

Signatures

Multi AV Scanner detection for submitted file
Sample has stripped symbol table
Uses the "uname" system call to query kernel version information (possible evasion)
Enumerates processes within the "proc" file system
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Detected TCP or UDP traffic on non-standard ports
Sample tries to kill a process (SIGKILL)

Classification

Analysis Advice

All HTTP servers contacted by the sample do not answer. Likely the sample is an old dropper which does no longer work
Static ELF header machine description suggests that the sample might not execute correctly on this machine

General Information

Joe Sandbox Version:34.0.0 Boulder Opal
Analysis ID:511523
Start date:29.10.2021
Start time:09:02:12
Joe Sandbox Product:CloudBasic
Overall analysis duration:0h 4m 1s
Hypervisor based Inspection enabled:false
Report type:light
Sample file name:YpKL484IG5
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Detection:MAL
Classification:mal48.lin@0/4@0/0

Process Tree

  • system is lnxubuntu20
  • YpKL484IG5 (PID: 5237, Parent: 5119, MD5: 8943e5f8f8c280467b4472c15ae93ba9) Arguments: /tmp/YpKL484IG5
  • cleanup

Yara Overview

No yara matches

Jbx Signature Overview

Click to jump to signature section

Show All Signature Results

AV Detection:

barindex
Multi AV Scanner detection for submitted fileShow sources
Source: YpKL484IG5Virustotal: Detection: 21%Perma Link
Source: YpKL484IG5ReversingLabs: Detection: 15%
Source: global trafficTCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
Source: global trafficTCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
Source: global trafficTCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
Source: global trafficTCP traffic: 192.168.2.23:56596 -> 45.95.169.120:455
Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443
Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
Source: unknownTCP traffic detected without corresponding DNS query: 182.52.32.82
Source: unknownTCP traffic detected without corresponding DNS query: 182.52.32.82
Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
Source: unknownTCP traffic detected without corresponding DNS query: 209.90.166.193
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
Source: ELF static info symbol of initial sample.symtab present: no
Source: /tmp/YpKL484IG5 (PID: 5241)SIGKILL sent: pid: 2256, result: successful
Source: /tmp/YpKL484IG5 (PID: 5241)SIGKILL sent: pid: 2258, result: successful
Source: /tmp/YpKL484IG5 (PID: 5241)SIGKILL sent: pid: 5200, result: successful
Source: /tmp/YpKL484IG5 (PID: 5241)SIGKILL sent: pid: 5201, result: successful
Source: /tmp/YpKL484IG5 (PID: 5241)SIGKILL sent: pid: 5314, result: successful
Source: /tmp/YpKL484IG5 (PID: 5241)SIGKILL sent: pid: 5314, result: no such process
Source: /tmp/YpKL484IG5 (PID: 5241)SIGKILL sent: pid: 5320, result: successful
Source: classification engineClassification label: mal48.lin@0/4@0/0
Source: YpKL484IG5Joe Sandbox Cloud Basic: Detection: clean Score: 0Perma Link
Source: /tmp/YpKL484IG5 (PID: 5241)File opened: /proc/5145/cmdline
Source: /tmp/YpKL484IG5 (PID: 5241)File opened: /proc/5145/cmdline
Source: /tmp/YpKL484IG5 (PID: 5241)File opened: /proc/5145/status
Source: /tmp/YpKL484IG5 (PID: 5241)File opened: /proc/5145/status
Source: /tmp/YpKL484IG5 (PID: 5241)File opened: /proc/1582/cmdline
Source: /tmp/YpKL484IG5 (PID: 5241)File opened: /proc/1582/cmdline
Source: /tmp/YpKL484IG5 (PID: 5241)File opened: /proc/1582/status
Source: /tmp/YpKL484IG5 (PID: 5241)File opened: /proc/1582/status
Source: /tmp/YpKL484IG5 (PID: 5241)File opened: /proc/3088/cmdline
Source: /tmp/YpKL484IG5 (PID: 5241)File opened: /proc/3088/cmdline
Source: /tmp/YpKL484IG5 (PID: 5241)File opened: /proc/3088/status
Source: /tmp/YpKL484IG5 (PID: 5241)File opened: /proc/3088/status
Source: /tmp/YpKL484IG5 (PID: 5241)File opened: /proc/230/cmdline
Source: /tmp/YpKL484IG5 (PID: 5241)File opened: /proc/230/cmdline
Source: /tmp/YpKL484IG5 (PID: 5241)File opened: /proc/230/status
Source: /tmp/YpKL484IG5 (PID: 5241)File opened: /proc/230/status
Source: /tmp/YpKL484IG5 (PID: 5241)File opened: /proc/110/cmdline
Source: /tmp/YpKL484IG5 (PID: 5241)File opened: /proc/110/cmdline
Source: /tmp/YpKL484IG5 (PID: 5241)File opened: /proc/110/status
Source: /tmp/YpKL484IG5 (PID: 5241)File opened: /proc/110/status
Source: /tmp/YpKL484IG5 (PID: 5241)File opened: /proc/231/cmdline
Source: /tmp/YpKL484IG5 (PID: 5241)File opened: /proc/231/cmdline
Source: /tmp/YpKL484IG5 (PID: 5241)File opened: /proc/231/status
Source: /tmp/YpKL484IG5 (PID: 5241)File opened: /proc/231/status
Source: /tmp/YpKL484IG5 (PID: 5241)File opened: /proc/111/cmdline
Source: /tmp/YpKL484IG5 (PID: 5241)File opened: /proc/111/cmdline
Source: /tmp/YpKL484IG5 (PID: 5241)File opened: /proc/111/status
Source: /tmp/YpKL484IG5 (PID: 5241)File opened: /proc/111/status
Source: /tmp/YpKL484IG5 (PID: 5241)File opened: /proc/232/cmdline
Source: /tmp/YpKL484IG5 (PID: 5241)File opened: /proc/232/cmdline
Source: /tmp/YpKL484IG5 (PID: 5241)File opened: /proc/232/status
Source: /tmp/YpKL484IG5 (PID: 5241)File opened: /proc/232/status
Source: /tmp/YpKL484IG5 (PID: 5241)File opened: /proc/1579/cmdline
Source: /tmp/YpKL484IG5 (PID: 5241)File opened: /proc/1579/cmdline
Source: /tmp/YpKL484IG5 (PID: 5241)File opened: /proc/1579/status
Source: /tmp/YpKL484IG5 (PID: 5241)File opened: /proc/1579/status
Source: /tmp/YpKL484IG5 (PID: 5241)File opened: /proc/112/cmdline
Source: /tmp/YpKL484IG5 (PID: 5241)File opened: /proc/112/cmdline
Source: /tmp/YpKL484IG5 (PID: 5241)File opened: /proc/112/status
Source: /tmp/YpKL484IG5 (PID: 5241)File opened: /proc/112/status
Source: /tmp/YpKL484IG5 (PID: 5241)File opened: /proc/233/cmdline
Source: /tmp/YpKL484IG5 (PID: 5241)File opened: /proc/233/cmdline
Source: /tmp/YpKL484IG5 (PID: 5241)File opened: /proc/233/status
Source: /tmp/YpKL484IG5 (PID: 5241)File opened: /proc/233/status
Source: /tmp/YpKL484IG5 (PID: 5241)File opened: /proc/1699/cmdline
Source: /tmp/YpKL484IG5 (PID: 5241)File opened: /proc/1699/cmdline
Source: /tmp/YpKL484IG5 (PID: 5241)File opened: /proc/1699/status
Source: /tmp/YpKL484IG5 (PID: 5241)File opened: /proc/1699/status
Source: /tmp/YpKL484IG5 (PID: 5241)File opened: /proc/113/cmdline
Source: /tmp/YpKL484IG5 (PID: 5241)File opened: /proc/113/cmdline
Source: /tmp/YpKL484IG5 (PID: 5241)File opened: /proc/113/status
Source: /tmp/YpKL484IG5 (PID: 5241)File opened: /proc/113/status
Source: /tmp/YpKL484IG5 (PID: 5241)File opened: /proc/234/cmdline
Source: /tmp/YpKL484IG5 (PID: 5241)File opened: /proc/234/cmdline
Source: /tmp/YpKL484IG5 (PID: 5241)File opened: /proc/234/status
Source: /tmp/YpKL484IG5 (PID: 5241)File opened: /proc/234/status
Source: /tmp/YpKL484IG5 (PID: 5241)File opened: /proc/1335/cmdline
Source: /tmp/YpKL484IG5 (PID: 5241)File opened: /proc/1335/cmdline
Source: /tmp/YpKL484IG5 (PID: 5241)File opened: /proc/1335/status
Source: /tmp/YpKL484IG5 (PID: 5241)File opened: /proc/1335/status
Source: /tmp/YpKL484IG5 (PID: 5241)File opened: /proc/1698/cmdline
Source: /tmp/YpKL484IG5 (PID: 5241)File opened: /proc/1698/cmdline
Source: /tmp/YpKL484IG5 (PID: 5241)File opened: /proc/1698/status
Source: /tmp/YpKL484IG5 (PID: 5241)File opened: /proc/1698/status
Source: /tmp/YpKL484IG5 (PID: 5241)File opened: /proc/114/cmdline
Source: /tmp/YpKL484IG5 (PID: 5241)File opened: /proc/114/cmdline
Source: /tmp/YpKL484IG5 (PID: 5241)File opened: /proc/114/status
Source: /tmp/YpKL484IG5 (PID: 5241)File opened: /proc/114/status
Source: /tmp/YpKL484IG5 (PID: 5241)File opened: /proc/235/cmdline
Source: /tmp/YpKL484IG5 (PID: 5241)File opened: /proc/235/cmdline
Source: /tmp/YpKL484IG5 (PID: 5241)File opened: /proc/235/status
Source: /tmp/YpKL484IG5 (PID: 5241)File opened: /proc/235/status
Source: /tmp/YpKL484IG5 (PID: 5241)File opened: /proc/1334/cmdline
Source: /tmp/YpKL484IG5 (PID: 5241)File opened: /proc/1334/cmdline
Source: /tmp/YpKL484IG5 (PID: 5241)File opened: /proc/1334/status
Source: /tmp/YpKL484IG5 (PID: 5241)File opened: /proc/1334/status
Source: /tmp/YpKL484IG5 (PID: 5241)File opened: /proc/1576/cmdline
Source: /tmp/YpKL484IG5 (PID: 5241)File opened: /proc/1576/cmdline
Source: /tmp/YpKL484IG5 (PID: 5241)File opened: /proc/1576/status
Source: /tmp/YpKL484IG5 (PID: 5241)File opened: /proc/1576/status
Source: /tmp/YpKL484IG5 (PID: 5241)File opened: /proc/2302/cmdline
Source: /tmp/YpKL484IG5 (PID: 5241)File opened: /proc/2302/cmdline
Source: /tmp/YpKL484IG5 (PID: 5241)File opened: /proc/2302/status
Source: /tmp/YpKL484IG5 (PID: 5241)File opened: /proc/2302/status
Source: /tmp/YpKL484IG5 (PID: 5241)File opened: /proc/115/cmdline
Source: /tmp/YpKL484IG5 (PID: 5241)File opened: /proc/115/cmdline
Source: /tmp/YpKL484IG5 (PID: 5241)File opened: /proc/115/status
Source: /tmp/YpKL484IG5 (PID: 5241)File opened: /proc/115/status
Source: /tmp/YpKL484IG5 (PID: 5241)File opened: /proc/236/cmdline
Source: /tmp/YpKL484IG5 (PID: 5241)File opened: /proc/236/cmdline
Source: /tmp/YpKL484IG5 (PID: 5241)File opened: /proc/236/status
Source: /tmp/YpKL484IG5 (PID: 5241)File opened: /proc/236/status
Source: /tmp/YpKL484IG5 (PID: 5241)File opened: /proc/116/cmdline
Source: /tmp/YpKL484IG5 (PID: 5241)File opened: /proc/116/cmdline
Source: /tmp/YpKL484IG5 (PID: 5241)File opened: /proc/116/status
Source: /tmp/YpKL484IG5 (PID: 5241)File opened: /proc/116/status
Source: /tmp/YpKL484IG5 (PID: 5241)File opened: /proc/237/cmdline
Source: /tmp/YpKL484IG5 (PID: 5241)File opened: /proc/237/cmdline
Source: /tmp/YpKL484IG5 (PID: 5241)File opened: /proc/237/status
Source: /tmp/YpKL484IG5 (PID: 5241)File opened: /proc/237/status
Source: /tmp/YpKL484IG5 (PID: 5241)File opened: /proc/117/cmdline
Source: /tmp/YpKL484IG5 (PID: 5241)File opened: /proc/117/cmdline
Source: /tmp/YpKL484IG5 (PID: 5241)File opened: /proc/117/status
Source: /tmp/YpKL484IG5 (PID: 5241)File opened: /proc/117/status
Source: /tmp/YpKL484IG5 (PID: 5241)File opened: /proc/118/cmdline
Source: /tmp/YpKL484IG5 (PID: 5241)File opened: /proc/118/cmdline
Source: /tmp/YpKL484IG5 (PID: 5241)File opened: /proc/118/status
Source: /tmp/YpKL484IG5 (PID: 5241)File opened: /proc/118/status
Source: /tmp/YpKL484IG5 (PID: 5237)Queries kernel information via 'uname':
Source: YpKL484IG5, 5237.1.000000009c09c6c1.00000000030754b0.rw-.sdmpBinary or memory string: /usr/bin/qemu-sh4
Source: YpKL484IG5, 5237.1.00000000016977e0.00000000df726e07.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/sh4
Source: YpKL484IG5, 5237.1.00000000016977e0.00000000df726e07.rw-.sdmpBinary or memory string: [U5!/etc/qemu-binfmt/sh4
Source: YpKL484IG5, 5237.1.000000009c09c6c1.00000000030754b0.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-sh4/tmp/YpKL484IG5SUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/YpKL484IG5

Mitre Att&ck Matrix

Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid AccountsWindows Management InstrumentationPath InterceptionPath InterceptionDirect Volume AccessOS Credential Dumping1Security Software Discovery11Remote ServicesData from Local SystemExfiltration Over Other Network MediumEncrypted Channel1Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over BluetoothNon-Standard Port1Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated ExfiltrationApplication Layer Protocol1Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data

Malware Configuration

No configs have been found

Behavior Graph

Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 511523 Sample: YpKL484IG5 Startdate: 29/10/2021 Architecture: LINUX Score: 48 14 182.52.32.82, 23, 37178 TOT-NETTOTPublicCompanyLimitedTH Thailand 2->14 16 209.90.166.193, 23, 52586 PRIMUS-AS6407CA Canada 2->16 18 4 other IPs or domains 2->18 20 Multi AV Scanner detection for submitted file 2->20 8 YpKL484IG5 2->8         started        signatures3 process4 process5 10 YpKL484IG5 8->10         started        process6 12 YpKL484IG5 10->12         started       

Screenshots

Thumbnails

This section contains all screenshots as thumbnails, including those not shown in the slideshow.

windows-stand

Antivirus, Machine Learning and Genetic Malware Detection

Initial Sample

SourceDetectionScannerLabelLink
YpKL484IG521%VirustotalBrowse
YpKL484IG516%ReversingLabsLinux.Trojan.Mirai

Dropped Files

No Antivirus matches

Domains

No Antivirus matches

URLs

No Antivirus matches

Domains and IPs

Contacted Domains

No contacted domains info

Contacted IPs

  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs

Public

IPDomainCountryFlagASNASN NameMalicious
45.95.169.120
unknownCroatia (LOCAL Name: Hrvatska)
42864GIGANET-HUGigaNetInternetServiceProviderCoHUfalse
209.90.166.193
unknownCanada
6407PRIMUS-AS6407CAfalse
109.202.202.202
unknownSwitzerland
13030INIT7CHfalse
182.52.32.82
unknownThailand
23969TOT-NETTOTPublicCompanyLimitedTHfalse
91.189.91.43
unknownUnited Kingdom
41231CANONICAL-ASGBfalse
91.189.91.42
unknownUnited Kingdom
41231CANONICAL-ASGBfalse


Runtime Messages

Command:/tmp/YpKL484IG5
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:

Standard Error:

Joe Sandbox View / Context

IPs

MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
45.95.169.120Y4W4j5QIqDGet hashmaliciousBrowse
    1TnmkstVG8Get hashmaliciousBrowse
      iksM5QEg2jGet hashmaliciousBrowse
        109.202.202.202Y4W4j5QIqDGet hashmaliciousBrowse
          1TnmkstVG8Get hashmaliciousBrowse
            iksM5QEg2jGet hashmaliciousBrowse
              lGJEkz80oeGet hashmaliciousBrowse
                roV7kGaVr1Get hashmaliciousBrowse
                  SecuriteInfo.com.Linux.Siggen.4218.298.3210Get hashmaliciousBrowse
                    uPOWBxniTAGet hashmaliciousBrowse
                      qy5unieRgRGet hashmaliciousBrowse
                        sAzPpn6mKZGet hashmaliciousBrowse
                          AxadDC89j9Get hashmaliciousBrowse
                            ZErnXU2XR1Get hashmaliciousBrowse
                              sTHJvS5LPJGet hashmaliciousBrowse
                                THzHjYQ4z6Get hashmaliciousBrowse
                                  jC0B6sMh1dGet hashmaliciousBrowse
                                    JoLmvC65B7Get hashmaliciousBrowse
                                      AOaKSm1cijGet hashmaliciousBrowse
                                        Mozi.aGet hashmaliciousBrowse
                                          ggbMKQDdG2Get hashmaliciousBrowse
                                            SecuriteInfo.com.Linux.Siggen.4218.31606.9155Get hashmaliciousBrowse
                                              AbriuSDkeLGet hashmaliciousBrowse
                                                91.189.91.43Y4W4j5QIqDGet hashmaliciousBrowse
                                                  1TnmkstVG8Get hashmaliciousBrowse
                                                    iksM5QEg2jGet hashmaliciousBrowse
                                                      lGJEkz80oeGet hashmaliciousBrowse
                                                        roV7kGaVr1Get hashmaliciousBrowse
                                                          SecuriteInfo.com.Linux.Siggen.4218.298.3210Get hashmaliciousBrowse
                                                            uPOWBxniTAGet hashmaliciousBrowse
                                                              qy5unieRgRGet hashmaliciousBrowse
                                                                sAzPpn6mKZGet hashmaliciousBrowse
                                                                  AxadDC89j9Get hashmaliciousBrowse
                                                                    ZErnXU2XR1Get hashmaliciousBrowse
                                                                      sTHJvS5LPJGet hashmaliciousBrowse
                                                                        THzHjYQ4z6Get hashmaliciousBrowse
                                                                          jC0B6sMh1dGet hashmaliciousBrowse
                                                                            JoLmvC65B7Get hashmaliciousBrowse
                                                                              AOaKSm1cijGet hashmaliciousBrowse
                                                                                Mozi.aGet hashmaliciousBrowse
                                                                                  ggbMKQDdG2Get hashmaliciousBrowse
                                                                                    SecuriteInfo.com.Linux.Siggen.4218.31606.9155Get hashmaliciousBrowse
                                                                                      AbriuSDkeLGet hashmaliciousBrowse

                                                                                        Domains

                                                                                        No context

                                                                                        ASN

                                                                                        MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                                                                                        PRIMUS-AS6407CAo4wjsQMo7qGet hashmaliciousBrowse
                                                                                        • 204.52.2.37
                                                                                        RkH17dHLZtGet hashmaliciousBrowse
                                                                                        • 204.52.2.46
                                                                                        L1ecmEWyAwGet hashmaliciousBrowse
                                                                                        • 173.206.218.16
                                                                                        notabotnet.armGet hashmaliciousBrowse
                                                                                        • 173.206.218.20
                                                                                        kqaEUydKGFGet hashmaliciousBrowse
                                                                                        • 204.48.48.94
                                                                                        bTRSDGefHcGet hashmaliciousBrowse
                                                                                        • 216.181.238.32
                                                                                        sora.armGet hashmaliciousBrowse
                                                                                        • 173.206.243.26
                                                                                        ho4yrUrdk1Get hashmaliciousBrowse
                                                                                        • 216.254.194.50
                                                                                        dark.armGet hashmaliciousBrowse
                                                                                        • 204.52.2.67
                                                                                        sora.armGet hashmaliciousBrowse
                                                                                        • 207.116.25.36
                                                                                        KzWXGmiJxSGet hashmaliciousBrowse
                                                                                        • 207.116.49.59
                                                                                        hzD4UBTK5HGet hashmaliciousBrowse
                                                                                        • 108.63.164.212
                                                                                        BqfM9JwIC5Get hashmaliciousBrowse
                                                                                        • 204.52.83.211
                                                                                        R0zLx1X0D0Get hashmaliciousBrowse
                                                                                        • 204.48.2.5
                                                                                        TwlnaihoCKGet hashmaliciousBrowse
                                                                                        • 207.116.49.15
                                                                                        sA0dlWB3alGet hashmaliciousBrowse
                                                                                        • 64.56.254.247
                                                                                        3f7zmNN0nQGet hashmaliciousBrowse
                                                                                        • 209.227.129.123
                                                                                        KoknEiNL8UGet hashmaliciousBrowse
                                                                                        • 216.254.182.70
                                                                                        3etkq3iOPQGet hashmaliciousBrowse
                                                                                        • 173.206.218.72
                                                                                        peach.arm7Get hashmaliciousBrowse
                                                                                        • 216.254.194.81
                                                                                        GIGANET-HUGigaNetInternetServiceProviderCoHUY4W4j5QIqDGet hashmaliciousBrowse
                                                                                        • 45.95.169.120
                                                                                        1TnmkstVG8Get hashmaliciousBrowse
                                                                                        • 45.95.169.120
                                                                                        iksM5QEg2jGet hashmaliciousBrowse
                                                                                        • 45.95.169.120
                                                                                        RicwIfIHLKGet hashmaliciousBrowse
                                                                                        • 45.95.169.115
                                                                                        aIY7AxjUMcGet hashmaliciousBrowse
                                                                                        • 45.95.169.115
                                                                                        DtJmFQxtNCGet hashmaliciousBrowse
                                                                                        • 45.95.169.115
                                                                                        Wm4CzOCmNYGet hashmaliciousBrowse
                                                                                        • 45.95.169.115
                                                                                        vunWUzXJvCGet hashmaliciousBrowse
                                                                                        • 45.95.169.115
                                                                                        52xhBHy9WzGet hashmaliciousBrowse
                                                                                        • 45.95.169.115
                                                                                        YGvwG0iCDEGet hashmaliciousBrowse
                                                                                        • 45.95.169.115
                                                                                        dbd5O0RUTqGet hashmaliciousBrowse
                                                                                        • 45.95.169.115
                                                                                        fHVDVj0pzOGet hashmaliciousBrowse
                                                                                        • 45.95.169.115
                                                                                        eZPk7Fg5w7Get hashmaliciousBrowse
                                                                                        • 45.95.169.115
                                                                                        ph5PjoFBpjGet hashmaliciousBrowse
                                                                                        • 45.95.169.115
                                                                                        xugAk5haatGet hashmaliciousBrowse
                                                                                        • 45.95.169.115
                                                                                        0jEbWQtzs0Get hashmaliciousBrowse
                                                                                        • 45.95.169.115
                                                                                        8g3tc5SWwBGet hashmaliciousBrowse
                                                                                        • 92.52.211.220
                                                                                        7okgnZjK06Get hashmaliciousBrowse
                                                                                        • 45.95.169.115
                                                                                        D9efs9TYvNGet hashmaliciousBrowse
                                                                                        • 45.95.169.115
                                                                                        LlE7nUUjmAGet hashmaliciousBrowse
                                                                                        • 45.95.169.115
                                                                                        INIT7CHY4W4j5QIqDGet hashmaliciousBrowse
                                                                                        • 109.202.202.202
                                                                                        1TnmkstVG8Get hashmaliciousBrowse
                                                                                        • 109.202.202.202
                                                                                        iksM5QEg2jGet hashmaliciousBrowse
                                                                                        • 109.202.202.202
                                                                                        lGJEkz80oeGet hashmaliciousBrowse
                                                                                        • 109.202.202.202
                                                                                        roV7kGaVr1Get hashmaliciousBrowse
                                                                                        • 109.202.202.202
                                                                                        SecuriteInfo.com.Linux.Siggen.4218.298.3210Get hashmaliciousBrowse
                                                                                        • 109.202.202.202
                                                                                        uPOWBxniTAGet hashmaliciousBrowse
                                                                                        • 109.202.202.202
                                                                                        qy5unieRgRGet hashmaliciousBrowse
                                                                                        • 109.202.202.202
                                                                                        sAzPpn6mKZGet hashmaliciousBrowse
                                                                                        • 109.202.202.202
                                                                                        AxadDC89j9Get hashmaliciousBrowse
                                                                                        • 109.202.202.202
                                                                                        ZErnXU2XR1Get hashmaliciousBrowse
                                                                                        • 109.202.202.202
                                                                                        sTHJvS5LPJGet hashmaliciousBrowse
                                                                                        • 109.202.202.202
                                                                                        THzHjYQ4z6Get hashmaliciousBrowse
                                                                                        • 109.202.202.202
                                                                                        jC0B6sMh1dGet hashmaliciousBrowse
                                                                                        • 109.202.202.202
                                                                                        JoLmvC65B7Get hashmaliciousBrowse
                                                                                        • 109.202.202.202
                                                                                        AOaKSm1cijGet hashmaliciousBrowse
                                                                                        • 109.202.202.202
                                                                                        Mozi.aGet hashmaliciousBrowse
                                                                                        • 109.202.202.202
                                                                                        ggbMKQDdG2Get hashmaliciousBrowse
                                                                                        • 109.202.202.202
                                                                                        SecuriteInfo.com.Linux.Siggen.4218.31606.9155Get hashmaliciousBrowse
                                                                                        • 109.202.202.202
                                                                                        AbriuSDkeLGet hashmaliciousBrowse
                                                                                        • 109.202.202.202

                                                                                        JA3 Fingerprints

                                                                                        No context

                                                                                        Dropped Files

                                                                                        No context

                                                                                        Created / dropped Files

                                                                                        /tmp/qemu-open.1prlPu (deleted)
                                                                                        Process:/tmp/YpKL484IG5
                                                                                        File Type:ASCII text, with no line terminators
                                                                                        Category:dropped
                                                                                        Size (bytes):16
                                                                                        Entropy (8bit):3.625
                                                                                        Encrypted:false
                                                                                        SSDEEP:3:TgIJ:Tgo
                                                                                        MD5:6BEB25EF1CFC2913704E086EDFA828E7
                                                                                        SHA1:6A4BEAF98F707CBEE3FB5537560BB6982E564F02
                                                                                        SHA-256:4E3BE4C49C92511634294722FA7FB5B93A90F751E18A8CB94DA0C67BEAC7E51A
                                                                                        SHA-512:81F690A68C4E2B246176B7868FFF7C1468AB7640B4829910940B3B219347090AA57EC945656D5FB41FA7901D9831202000A8AD290C979F0634AE723FF9583F9B
                                                                                        Malicious:false
                                                                                        Reputation:low
                                                                                        Preview: /tmp/YpKL484IG5.
                                                                                        /tmp/qemu-open.F9rJYt (deleted)
                                                                                        Process:/tmp/YpKL484IG5
                                                                                        File Type:ASCII text, with no line terminators
                                                                                        Category:dropped
                                                                                        Size (bytes):16
                                                                                        Entropy (8bit):3.625
                                                                                        Encrypted:false
                                                                                        SSDEEP:3:TgIJ:Tgo
                                                                                        MD5:6BEB25EF1CFC2913704E086EDFA828E7
                                                                                        SHA1:6A4BEAF98F707CBEE3FB5537560BB6982E564F02
                                                                                        SHA-256:4E3BE4C49C92511634294722FA7FB5B93A90F751E18A8CB94DA0C67BEAC7E51A
                                                                                        SHA-512:81F690A68C4E2B246176B7868FFF7C1468AB7640B4829910940B3B219347090AA57EC945656D5FB41FA7901D9831202000A8AD290C979F0634AE723FF9583F9B
                                                                                        Malicious:false
                                                                                        Reputation:low
                                                                                        Preview: /tmp/YpKL484IG5.
                                                                                        /tmp/qemu-open.g4pvNs (deleted)
                                                                                        Process:/tmp/YpKL484IG5
                                                                                        File Type:ASCII text, with no line terminators
                                                                                        Category:dropped
                                                                                        Size (bytes):16
                                                                                        Entropy (8bit):3.625
                                                                                        Encrypted:false
                                                                                        SSDEEP:3:TgIJ:Tgo
                                                                                        MD5:6BEB25EF1CFC2913704E086EDFA828E7
                                                                                        SHA1:6A4BEAF98F707CBEE3FB5537560BB6982E564F02
                                                                                        SHA-256:4E3BE4C49C92511634294722FA7FB5B93A90F751E18A8CB94DA0C67BEAC7E51A
                                                                                        SHA-512:81F690A68C4E2B246176B7868FFF7C1468AB7640B4829910940B3B219347090AA57EC945656D5FB41FA7901D9831202000A8AD290C979F0634AE723FF9583F9B
                                                                                        Malicious:false
                                                                                        Reputation:low
                                                                                        Preview: /tmp/YpKL484IG5.
                                                                                        /tmp/qemu-open.v6w7Qw (deleted)
                                                                                        Process:/tmp/YpKL484IG5
                                                                                        File Type:ASCII text, with no line terminators
                                                                                        Category:dropped
                                                                                        Size (bytes):16
                                                                                        Entropy (8bit):3.625
                                                                                        Encrypted:false
                                                                                        SSDEEP:3:TgIJ:Tgo
                                                                                        MD5:6BEB25EF1CFC2913704E086EDFA828E7
                                                                                        SHA1:6A4BEAF98F707CBEE3FB5537560BB6982E564F02
                                                                                        SHA-256:4E3BE4C49C92511634294722FA7FB5B93A90F751E18A8CB94DA0C67BEAC7E51A
                                                                                        SHA-512:81F690A68C4E2B246176B7868FFF7C1468AB7640B4829910940B3B219347090AA57EC945656D5FB41FA7901D9831202000A8AD290C979F0634AE723FF9583F9B
                                                                                        Malicious:false
                                                                                        Reputation:low
                                                                                        Preview: /tmp/YpKL484IG5.

                                                                                        Static File Info

                                                                                        General

                                                                                        File type:ELF 32-bit LSB executable, Renesas SH, version 1 (SYSV), statically linked, stripped
                                                                                        Entropy (8bit):6.667136040804854
                                                                                        TrID:
                                                                                        • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                                                                                        File name:YpKL484IG5
                                                                                        File size:32140
                                                                                        MD5:e9e2ace904c9f2049ee2d16403868e50
                                                                                        SHA1:dcd1a8cef227c63725ed272a8b9e83f8306104d8
                                                                                        SHA256:0ace9c1e48517f73c6385f9ebdf3f67a9e7a37bddca6503e1d8f5f6ad7dc91a6
                                                                                        SHA512:f4bf61bbc2cd88641adddceb7544e53b2f9abae6e62f03bc2898cc1e2f714135e340ad2abde01beadc71064320c494dbfb5159c18675f0a448c22a795f380177
                                                                                        SSDEEP:384:D+kUtKh11Cj3vHN2btttaukXT0oPaqO7LPaokol9rH/WUqBUMt9CH7Kzgsb:D+kUtKtCj3vHCEDGqpol9rfX+Ce
                                                                                        File Content Preview:.ELF..............*.......@.4....{......4. ...(...............@...@..g...g...............g...gA..gA.....X%..........Q.td............................././"O.n........#.*@........#.*@.`...o&O.n...l..............................././.../.a"O.!...n...a.b("...q.

                                                                                        Static ELF Info

                                                                                        ELF header

                                                                                        Class:ELF32
                                                                                        Data:2's complement, little endian
                                                                                        Version:1 (current)
                                                                                        Machine:<unknown>
                                                                                        Version Number:0x1
                                                                                        Type:EXEC (Executable file)
                                                                                        OS/ABI:UNIX - System V
                                                                                        ABI Version:0
                                                                                        Entry Point Address:0x4001a0
                                                                                        Flags:0x9
                                                                                        ELF Header Size:52
                                                                                        Program Header Offset:52
                                                                                        Program Header Size:32
                                                                                        Number of Program Headers:3
                                                                                        Section Header Offset:31740
                                                                                        Section Header Size:40
                                                                                        Number of Section Headers:10
                                                                                        Header String Table Index:9

                                                                                        Sections

                                                                                        NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                                                                        NULL0x00x00x00x00x0000
                                                                                        .initPROGBITS0x4000940x940x300x00x6AX004
                                                                                        .textPROGBITS0x4000e00xe00x60c00x00x6AX0032
                                                                                        .finiPROGBITS0x4061a00x61a00x240x00x6AX004
                                                                                        .rodataPROGBITS0x4061c40x61c40x6100x00x2A004
                                                                                        .ctorsPROGBITS0x4167d80x67d80x80x00x3WA004
                                                                                        .dtorsPROGBITS0x4167e00x67e00x80x00x3WA004
                                                                                        .dataPROGBITS0x4167ec0x67ec0x13d00x00x3WA004
                                                                                        .bssNOBITS0x417bbc0x7bbc0x11740x00x3WA004
                                                                                        .shstrtabSTRTAB0x00x7bbc0x3e0x00x0001

                                                                                        Program Segments

                                                                                        TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                                                        LOAD0x00x4000000x4000000x67d40x67d44.77840x5R E0x10000.init .text .fini .rodata
                                                                                        LOAD0x67d80x4167d80x4167d80x13e40x25581.76790x6RW 0x10000.ctors .dtors .data .bss
                                                                                        GNU_STACK0x00x00x00x00x00.00000x7RWE0x4

                                                                                        Network Behavior

                                                                                        Network Port Distribution

                                                                                        TCP Packets

                                                                                        TimestampSource PortDest PortSource IPDest IP
                                                                                        Oct 29, 2021 09:03:01.031599998 CEST56596455192.168.2.2345.95.169.120
                                                                                        Oct 29, 2021 09:03:02.054563999 CEST56596455192.168.2.2345.95.169.120
                                                                                        Oct 29, 2021 09:03:04.070488930 CEST56596455192.168.2.2345.95.169.120
                                                                                        Oct 29, 2021 09:03:08.294153929 CEST56596455192.168.2.2345.95.169.120
                                                                                        Oct 29, 2021 09:03:08.328254938 CEST4555659645.95.169.120192.168.2.23
                                                                                        Oct 29, 2021 09:03:08.531069994 CEST2337178182.52.32.82192.168.2.23
                                                                                        Oct 29, 2021 09:03:08.531335115 CEST3717823192.168.2.23182.52.32.82
                                                                                        Oct 29, 2021 09:03:08.534249067 CEST2337178182.52.32.82192.168.2.23
                                                                                        Oct 29, 2021 09:03:08.534403086 CEST3717823192.168.2.23182.52.32.82
                                                                                        Oct 29, 2021 09:03:13.330996990 CEST56598455192.168.2.2345.95.169.120
                                                                                        Oct 29, 2021 09:03:13.925837994 CEST43928443192.168.2.2391.189.91.42
                                                                                        Oct 29, 2021 09:03:14.341797113 CEST56598455192.168.2.2345.95.169.120
                                                                                        Oct 29, 2021 09:03:16.357666016 CEST56598455192.168.2.2345.95.169.120
                                                                                        Oct 29, 2021 09:03:20.581516981 CEST56598455192.168.2.2345.95.169.120
                                                                                        Oct 29, 2021 09:03:23.722290039 CEST2352586209.90.166.193192.168.2.23
                                                                                        Oct 29, 2021 09:03:23.723402977 CEST5258623192.168.2.23209.90.166.193
                                                                                        Oct 29, 2021 09:03:26.213084936 CEST42836443192.168.2.2391.189.91.43
                                                                                        Oct 29, 2021 09:03:28.772907019 CEST56598455192.168.2.2345.95.169.120
                                                                                        Oct 29, 2021 09:03:30.308788061 CEST4251680192.168.2.23109.202.202.202
                                                                                        Oct 29, 2021 09:03:44.899954081 CEST56598455192.168.2.2345.95.169.120
                                                                                        Oct 29, 2021 09:03:54.883512974 CEST43928443192.168.2.2391.189.91.42
                                                                                        Oct 29, 2021 09:04:17.409924030 CEST56598455192.168.2.2345.95.169.120
                                                                                        Oct 29, 2021 09:04:17.452140093 CEST4555659845.95.169.120192.168.2.23
                                                                                        Oct 29, 2021 09:04:22.453083992 CEST56602455192.168.2.2345.95.169.120
                                                                                        Oct 29, 2021 09:04:22.498486042 CEST4555660245.95.169.120192.168.2.23
                                                                                        Oct 29, 2021 09:04:27.498642921 CEST56604455192.168.2.2345.95.169.120
                                                                                        Oct 29, 2021 09:04:27.540374994 CEST4555660445.95.169.120192.168.2.23
                                                                                        Oct 29, 2021 09:04:32.540743113 CEST56606455192.168.2.2345.95.169.120
                                                                                        Oct 29, 2021 09:04:33.568922997 CEST56606455192.168.2.2345.95.169.120
                                                                                        Oct 29, 2021 09:04:35.584825993 CEST56606455192.168.2.2345.95.169.120
                                                                                        Oct 29, 2021 09:04:35.628063917 CEST4555660645.95.169.120192.168.2.23
                                                                                        Oct 29, 2021 09:04:40.628163099 CEST56608455192.168.2.2345.95.169.120
                                                                                        Oct 29, 2021 09:04:40.676052094 CEST4555660845.95.169.120192.168.2.23

                                                                                        System Behavior

                                                                                        General

                                                                                        Start time:09:02:59
                                                                                        Start date:29/10/2021
                                                                                        Path:/tmp/YpKL484IG5
                                                                                        Arguments:/tmp/YpKL484IG5
                                                                                        File size:4139976 bytes
                                                                                        MD5 hash:8943e5f8f8c280467b4472c15ae93ba9

                                                                                        General

                                                                                        Start time:09:03:00
                                                                                        Start date:29/10/2021
                                                                                        Path:/tmp/YpKL484IG5
                                                                                        Arguments:n/a
                                                                                        File size:4139976 bytes
                                                                                        MD5 hash:8943e5f8f8c280467b4472c15ae93ba9

                                                                                        General

                                                                                        Start time:09:03:00
                                                                                        Start date:29/10/2021
                                                                                        Path:/tmp/YpKL484IG5
                                                                                        Arguments:n/a
                                                                                        File size:4139976 bytes
                                                                                        MD5 hash:8943e5f8f8c280467b4472c15ae93ba9