Loading ...

Play interactive tourEdit tour

Linux Analysis Report csB31kWt10

Overview

General Information

Sample Name:csB31kWt10
Analysis ID:511554
MD5:df1ed6e73703ce09673aa4525975d129
SHA1:4b3444321f460d0ea48f4e96eb0ea45b27b885a6
SHA256:1d41b0a9c3b189c68bf219335a60f8156857fc6cef890e165e9ad2c48b15103a
Tags:32elfmipsmirai
Infos:

Most interesting Screenshot:

Detection

Score:48
Range:0 - 100
Whitelisted:false

Signatures

Multi AV Scanner detection for submitted file
Sample has stripped symbol table
Uses the "uname" system call to query kernel version information (possible evasion)
Enumerates processes within the "proc" file system
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Detected TCP or UDP traffic on non-standard ports
Sample tries to kill a process (SIGKILL)

Classification

Analysis Advice

Static ELF header machine description suggests that the sample might only run correctly on MIPS or ARM architectures
All HTTP servers contacted by the sample do not answer. Likely the sample is an old dropper which does no longer work
Static ELF header machine description suggests that the sample might not execute correctly on this machine

General Information

Joe Sandbox Version:34.0.0 Boulder Opal
Analysis ID:511554
Start date:29.10.2021
Start time:09:39:11
Joe Sandbox Product:CloudBasic
Overall analysis duration:0h 3m 55s
Hypervisor based Inspection enabled:false
Report type:light
Sample file name:csB31kWt10
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Detection:MAL
Classification:mal48.lin@0/4@0/0

Process Tree

  • system is lnxubuntu20
  • csB31kWt10 (PID: 5241, Parent: 5119, MD5: 0d6f61f82cf2f781c6eb0661071d42d9) Arguments: /tmp/csB31kWt10
  • cleanup

Yara Overview

No yara matches

Jbx Signature Overview

Click to jump to signature section

Show All Signature Results

AV Detection:

barindex
Multi AV Scanner detection for submitted fileShow sources
Source: csB31kWt10Virustotal: Detection: 22%Perma Link
Source: csB31kWt10ReversingLabs: Detection: 25%
Source: global trafficTCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
Source: global trafficTCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
Source: global trafficTCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
Source: global trafficTCP traffic: 192.168.2.23:56596 -> 45.95.169.120:455
Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443
Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 121.66.166.226
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
Source: ELF static info symbol of initial sample.symtab present: no
Source: /tmp/csB31kWt10 (PID: 5246)SIGKILL sent: pid: 2256, result: successful
Source: /tmp/csB31kWt10 (PID: 5246)SIGKILL sent: pid: 2258, result: no such process
Source: /tmp/csB31kWt10 (PID: 5246)SIGKILL sent: pid: 5206, result: successful
Source: /tmp/csB31kWt10 (PID: 5246)SIGKILL sent: pid: 5210, result: successful
Source: /tmp/csB31kWt10 (PID: 5246)SIGKILL sent: pid: 5319, result: successful
Source: /tmp/csB31kWt10 (PID: 5246)SIGKILL sent: pid: 5325, result: successful
Source: classification engineClassification label: mal48.lin@0/4@0/0
Source: csB31kWt10Joe Sandbox Cloud Basic: Detection: clean Score: 0Perma Link
Source: /tmp/csB31kWt10 (PID: 5246)File opened: /proc/5147/cmdline
Source: /tmp/csB31kWt10 (PID: 5246)File opened: /proc/5147/cmdline
Source: /tmp/csB31kWt10 (PID: 5246)File opened: /proc/5147/status
Source: /tmp/csB31kWt10 (PID: 5246)File opened: /proc/5147/status
Source: /tmp/csB31kWt10 (PID: 5246)File opened: /proc/1582/cmdline
Source: /tmp/csB31kWt10 (PID: 5246)File opened: /proc/1582/cmdline
Source: /tmp/csB31kWt10 (PID: 5246)File opened: /proc/1582/status
Source: /tmp/csB31kWt10 (PID: 5246)File opened: /proc/1582/status
Source: /tmp/csB31kWt10 (PID: 5246)File opened: /proc/3088/cmdline
Source: /tmp/csB31kWt10 (PID: 5246)File opened: /proc/3088/cmdline
Source: /tmp/csB31kWt10 (PID: 5246)File opened: /proc/3088/status
Source: /tmp/csB31kWt10 (PID: 5246)File opened: /proc/3088/status
Source: /tmp/csB31kWt10 (PID: 5246)File opened: /proc/230/cmdline
Source: /tmp/csB31kWt10 (PID: 5246)File opened: /proc/230/cmdline
Source: /tmp/csB31kWt10 (PID: 5246)File opened: /proc/230/status
Source: /tmp/csB31kWt10 (PID: 5246)File opened: /proc/230/status
Source: /tmp/csB31kWt10 (PID: 5246)File opened: /proc/110/cmdline
Source: /tmp/csB31kWt10 (PID: 5246)File opened: /proc/110/cmdline
Source: /tmp/csB31kWt10 (PID: 5246)File opened: /proc/110/status
Source: /tmp/csB31kWt10 (PID: 5246)File opened: /proc/110/status
Source: /tmp/csB31kWt10 (PID: 5246)File opened: /proc/231/cmdline
Source: /tmp/csB31kWt10 (PID: 5246)File opened: /proc/231/cmdline
Source: /tmp/csB31kWt10 (PID: 5246)File opened: /proc/231/status
Source: /tmp/csB31kWt10 (PID: 5246)File opened: /proc/231/status
Source: /tmp/csB31kWt10 (PID: 5246)File opened: /proc/111/cmdline
Source: /tmp/csB31kWt10 (PID: 5246)File opened: /proc/111/cmdline
Source: /tmp/csB31kWt10 (PID: 5246)File opened: /proc/111/status
Source: /tmp/csB31kWt10 (PID: 5246)File opened: /proc/111/status
Source: /tmp/csB31kWt10 (PID: 5246)File opened: /proc/232/cmdline
Source: /tmp/csB31kWt10 (PID: 5246)File opened: /proc/232/cmdline
Source: /tmp/csB31kWt10 (PID: 5246)File opened: /proc/232/status
Source: /tmp/csB31kWt10 (PID: 5246)File opened: /proc/232/status
Source: /tmp/csB31kWt10 (PID: 5246)File opened: /proc/1579/cmdline
Source: /tmp/csB31kWt10 (PID: 5246)File opened: /proc/1579/cmdline
Source: /tmp/csB31kWt10 (PID: 5246)File opened: /proc/1579/status
Source: /tmp/csB31kWt10 (PID: 5246)File opened: /proc/1579/status
Source: /tmp/csB31kWt10 (PID: 5246)File opened: /proc/112/cmdline
Source: /tmp/csB31kWt10 (PID: 5246)File opened: /proc/112/cmdline
Source: /tmp/csB31kWt10 (PID: 5246)File opened: /proc/112/status
Source: /tmp/csB31kWt10 (PID: 5246)File opened: /proc/112/status
Source: /tmp/csB31kWt10 (PID: 5246)File opened: /proc/233/cmdline
Source: /tmp/csB31kWt10 (PID: 5246)File opened: /proc/233/cmdline
Source: /tmp/csB31kWt10 (PID: 5246)File opened: /proc/233/status
Source: /tmp/csB31kWt10 (PID: 5246)File opened: /proc/233/status
Source: /tmp/csB31kWt10 (PID: 5246)File opened: /proc/1699/cmdline
Source: /tmp/csB31kWt10 (PID: 5246)File opened: /proc/1699/cmdline
Source: /tmp/csB31kWt10 (PID: 5246)File opened: /proc/1699/status
Source: /tmp/csB31kWt10 (PID: 5246)File opened: /proc/1699/status
Source: /tmp/csB31kWt10 (PID: 5246)File opened: /proc/113/cmdline
Source: /tmp/csB31kWt10 (PID: 5246)File opened: /proc/113/cmdline
Source: /tmp/csB31kWt10 (PID: 5246)File opened: /proc/113/status
Source: /tmp/csB31kWt10 (PID: 5246)File opened: /proc/113/status
Source: /tmp/csB31kWt10 (PID: 5246)File opened: /proc/234/cmdline
Source: /tmp/csB31kWt10 (PID: 5246)File opened: /proc/234/cmdline
Source: /tmp/csB31kWt10 (PID: 5246)File opened: /proc/234/status
Source: /tmp/csB31kWt10 (PID: 5246)File opened: /proc/234/status
Source: /tmp/csB31kWt10 (PID: 5246)File opened: /proc/1335/cmdline
Source: /tmp/csB31kWt10 (PID: 5246)File opened: /proc/1335/cmdline
Source: /tmp/csB31kWt10 (PID: 5246)File opened: /proc/1335/status
Source: /tmp/csB31kWt10 (PID: 5246)File opened: /proc/1335/status
Source: /tmp/csB31kWt10 (PID: 5246)File opened: /proc/1698/cmdline
Source: /tmp/csB31kWt10 (PID: 5246)File opened: /proc/1698/cmdline
Source: /tmp/csB31kWt10 (PID: 5246)File opened: /proc/1698/status
Source: /tmp/csB31kWt10 (PID: 5246)File opened: /proc/1698/status
Source: /tmp/csB31kWt10 (PID: 5246)File opened: /proc/114/cmdline
Source: /tmp/csB31kWt10 (PID: 5246)File opened: /proc/114/cmdline
Source: /tmp/csB31kWt10 (PID: 5246)File opened: /proc/114/status
Source: /tmp/csB31kWt10 (PID: 5246)File opened: /proc/114/status
Source: /tmp/csB31kWt10 (PID: 5246)File opened: /proc/235/cmdline
Source: /tmp/csB31kWt10 (PID: 5246)File opened: /proc/235/cmdline
Source: /tmp/csB31kWt10 (PID: 5246)File opened: /proc/235/status
Source: /tmp/csB31kWt10 (PID: 5246)File opened: /proc/235/status
Source: /tmp/csB31kWt10 (PID: 5246)File opened: /proc/1334/cmdline
Source: /tmp/csB31kWt10 (PID: 5246)File opened: /proc/1334/cmdline
Source: /tmp/csB31kWt10 (PID: 5246)File opened: /proc/1334/status
Source: /tmp/csB31kWt10 (PID: 5246)File opened: /proc/1334/status
Source: /tmp/csB31kWt10 (PID: 5246)File opened: /proc/1576/cmdline
Source: /tmp/csB31kWt10 (PID: 5246)File opened: /proc/1576/cmdline
Source: /tmp/csB31kWt10 (PID: 5246)File opened: /proc/1576/status
Source: /tmp/csB31kWt10 (PID: 5246)File opened: /proc/1576/status
Source: /tmp/csB31kWt10 (PID: 5246)File opened: /proc/2302/cmdline
Source: /tmp/csB31kWt10 (PID: 5246)File opened: /proc/2302/cmdline
Source: /tmp/csB31kWt10 (PID: 5246)File opened: /proc/2302/status
Source: /tmp/csB31kWt10 (PID: 5246)File opened: /proc/2302/status
Source: /tmp/csB31kWt10 (PID: 5246)File opened: /proc/115/cmdline
Source: /tmp/csB31kWt10 (PID: 5246)File opened: /proc/115/cmdline
Source: /tmp/csB31kWt10 (PID: 5246)File opened: /proc/115/status
Source: /tmp/csB31kWt10 (PID: 5246)File opened: /proc/115/status
Source: /tmp/csB31kWt10 (PID: 5246)File opened: /proc/236/cmdline
Source: /tmp/csB31kWt10 (PID: 5246)File opened: /proc/236/cmdline
Source: /tmp/csB31kWt10 (PID: 5246)File opened: /proc/236/status
Source: /tmp/csB31kWt10 (PID: 5246)File opened: /proc/236/status
Source: /tmp/csB31kWt10 (PID: 5246)File opened: /proc/116/cmdline
Source: /tmp/csB31kWt10 (PID: 5246)File opened: /proc/116/cmdline
Source: /tmp/csB31kWt10 (PID: 5246)File opened: /proc/116/status
Source: /tmp/csB31kWt10 (PID: 5246)File opened: /proc/116/status
Source: /tmp/csB31kWt10 (PID: 5246)File opened: /proc/237/cmdline
Source: /tmp/csB31kWt10 (PID: 5246)File opened: /proc/237/cmdline
Source: /tmp/csB31kWt10 (PID: 5246)File opened: /proc/237/status
Source: /tmp/csB31kWt10 (PID: 5246)File opened: /proc/237/status
Source: /tmp/csB31kWt10 (PID: 5246)File opened: /proc/117/cmdline
Source: /tmp/csB31kWt10 (PID: 5246)File opened: /proc/117/cmdline
Source: /tmp/csB31kWt10 (PID: 5246)File opened: /proc/117/status
Source: /tmp/csB31kWt10 (PID: 5246)File opened: /proc/117/status
Source: /tmp/csB31kWt10 (PID: 5246)File opened: /proc/118/cmdline
Source: /tmp/csB31kWt10 (PID: 5246)File opened: /proc/118/cmdline
Source: /tmp/csB31kWt10 (PID: 5246)File opened: /proc/118/status
Source: /tmp/csB31kWt10 (PID: 5246)File opened: /proc/118/status
Source: /tmp/csB31kWt10 (PID: 5241)Queries kernel information via 'uname':
Source: csB31kWt10, 5241.1.00000000a991e760.0000000054a0b362.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/mipsel
Source: csB31kWt10, 5241.1.0000000058f3b3c4.00000000a5779272.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-mipsel/tmp/csB31kWt10SUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/csB31kWt10
Source: csB31kWt10, 5241.1.00000000a991e760.0000000054a0b362.rw-.sdmpBinary or memory string: U!/etc/qemu-binfmt/mipsel
Source: csB31kWt10, 5241.1.0000000058f3b3c4.00000000a5779272.rw-.sdmpBinary or memory string: /usr/bin/qemu-mipsel

Mitre Att&ck Matrix

Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid AccountsWindows Management InstrumentationPath InterceptionPath InterceptionDirect Volume AccessOS Credential Dumping1Security Software Discovery11Remote ServicesData from Local SystemExfiltration Over Other Network MediumEncrypted Channel1Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over BluetoothNon-Standard Port1Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated ExfiltrationApplication Layer Protocol1Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data

Malware Configuration

No configs have been found

Behavior Graph

Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 511554 Sample: csB31kWt10 Startdate: 29/10/2021 Architecture: LINUX Score: 48 14 121.66.166.226, 23, 45686 LGDACOMLGDACOMCorporationKR Korea Republic of 2->14 16 109.202.202.202, 80 INIT7CH Switzerland 2->16 18 3 other IPs or domains 2->18 20 Multi AV Scanner detection for submitted file 2->20 8 csB31kWt10 2->8         started        signatures3 process4 process5 10 csB31kWt10 8->10         started        process6 12 csB31kWt10 10->12         started       

Screenshots

Thumbnails

This section contains all screenshots as thumbnails, including those not shown in the slideshow.

windows-stand

Antivirus, Machine Learning and Genetic Malware Detection

Initial Sample

SourceDetectionScannerLabelLink
csB31kWt1023%VirustotalBrowse
csB31kWt1025%ReversingLabsLinux.Trojan.Mirai

Dropped Files

No Antivirus matches

Domains

No Antivirus matches

URLs

No Antivirus matches

Domains and IPs

Contacted Domains

No contacted domains info

Contacted IPs

  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs

Public

IPDomainCountryFlagASNASN NameMalicious
121.66.166.226
unknownKorea Republic of
3786LGDACOMLGDACOMCorporationKRfalse
45.95.169.120
unknownCroatia (LOCAL Name: Hrvatska)
42864GIGANET-HUGigaNetInternetServiceProviderCoHUfalse
109.202.202.202
unknownSwitzerland
13030INIT7CHfalse
91.189.91.43
unknownUnited Kingdom
41231CANONICAL-ASGBfalse
91.189.91.42
unknownUnited Kingdom
41231CANONICAL-ASGBfalse


Runtime Messages

Command:/tmp/csB31kWt10
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:

Standard Error:

Joe Sandbox View / Context

IPs

MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
45.95.169.120QWg2NTuodYGet hashmaliciousBrowse
    SL92Sz9pl2Get hashmaliciousBrowse
      YpKL484IG5Get hashmaliciousBrowse
        Y4W4j5QIqDGet hashmaliciousBrowse
          1TnmkstVG8Get hashmaliciousBrowse
            iksM5QEg2jGet hashmaliciousBrowse
              109.202.202.202QWg2NTuodYGet hashmaliciousBrowse
                6VLeGqFkPSGet hashmaliciousBrowse
                  DL5blLw1lyGet hashmaliciousBrowse
                    SL92Sz9pl2Get hashmaliciousBrowse
                      YpKL484IG5Get hashmaliciousBrowse
                        Y4W4j5QIqDGet hashmaliciousBrowse
                          1TnmkstVG8Get hashmaliciousBrowse
                            iksM5QEg2jGet hashmaliciousBrowse
                              lGJEkz80oeGet hashmaliciousBrowse
                                roV7kGaVr1Get hashmaliciousBrowse
                                  SecuriteInfo.com.Linux.Siggen.4218.298.3210Get hashmaliciousBrowse
                                    uPOWBxniTAGet hashmaliciousBrowse
                                      qy5unieRgRGet hashmaliciousBrowse
                                        sAzPpn6mKZGet hashmaliciousBrowse
                                          AxadDC89j9Get hashmaliciousBrowse
                                            ZErnXU2XR1Get hashmaliciousBrowse
                                              sTHJvS5LPJGet hashmaliciousBrowse
                                                THzHjYQ4z6Get hashmaliciousBrowse
                                                  jC0B6sMh1dGet hashmaliciousBrowse
                                                    JoLmvC65B7Get hashmaliciousBrowse
                                                      91.189.91.43QWg2NTuodYGet hashmaliciousBrowse
                                                        6VLeGqFkPSGet hashmaliciousBrowse
                                                          DL5blLw1lyGet hashmaliciousBrowse
                                                            SL92Sz9pl2Get hashmaliciousBrowse
                                                              YpKL484IG5Get hashmaliciousBrowse
                                                                Y4W4j5QIqDGet hashmaliciousBrowse
                                                                  1TnmkstVG8Get hashmaliciousBrowse
                                                                    iksM5QEg2jGet hashmaliciousBrowse
                                                                      lGJEkz80oeGet hashmaliciousBrowse
                                                                        roV7kGaVr1Get hashmaliciousBrowse
                                                                          SecuriteInfo.com.Linux.Siggen.4218.298.3210Get hashmaliciousBrowse
                                                                            uPOWBxniTAGet hashmaliciousBrowse
                                                                              qy5unieRgRGet hashmaliciousBrowse
                                                                                sAzPpn6mKZGet hashmaliciousBrowse
                                                                                  AxadDC89j9Get hashmaliciousBrowse
                                                                                    ZErnXU2XR1Get hashmaliciousBrowse
                                                                                      sTHJvS5LPJGet hashmaliciousBrowse
                                                                                        THzHjYQ4z6Get hashmaliciousBrowse
                                                                                          jC0B6sMh1dGet hashmaliciousBrowse
                                                                                            JoLmvC65B7Get hashmaliciousBrowse

                                                                                              Domains

                                                                                              No context

                                                                                              ASN

                                                                                              MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                                                                                              GIGANET-HUGigaNetInternetServiceProviderCoHUQWg2NTuodYGet hashmaliciousBrowse
                                                                                              • 45.95.169.120
                                                                                              SL92Sz9pl2Get hashmaliciousBrowse
                                                                                              • 45.95.169.120
                                                                                              YpKL484IG5Get hashmaliciousBrowse
                                                                                              • 45.95.169.120
                                                                                              Y4W4j5QIqDGet hashmaliciousBrowse
                                                                                              • 45.95.169.120
                                                                                              1TnmkstVG8Get hashmaliciousBrowse
                                                                                              • 45.95.169.120
                                                                                              iksM5QEg2jGet hashmaliciousBrowse
                                                                                              • 45.95.169.120
                                                                                              RicwIfIHLKGet hashmaliciousBrowse
                                                                                              • 45.95.169.115
                                                                                              aIY7AxjUMcGet hashmaliciousBrowse
                                                                                              • 45.95.169.115
                                                                                              DtJmFQxtNCGet hashmaliciousBrowse
                                                                                              • 45.95.169.115
                                                                                              Wm4CzOCmNYGet hashmaliciousBrowse
                                                                                              • 45.95.169.115
                                                                                              vunWUzXJvCGet hashmaliciousBrowse
                                                                                              • 45.95.169.115
                                                                                              52xhBHy9WzGet hashmaliciousBrowse
                                                                                              • 45.95.169.115
                                                                                              YGvwG0iCDEGet hashmaliciousBrowse
                                                                                              • 45.95.169.115
                                                                                              dbd5O0RUTqGet hashmaliciousBrowse
                                                                                              • 45.95.169.115
                                                                                              fHVDVj0pzOGet hashmaliciousBrowse
                                                                                              • 45.95.169.115
                                                                                              eZPk7Fg5w7Get hashmaliciousBrowse
                                                                                              • 45.95.169.115
                                                                                              ph5PjoFBpjGet hashmaliciousBrowse
                                                                                              • 45.95.169.115
                                                                                              xugAk5haatGet hashmaliciousBrowse
                                                                                              • 45.95.169.115
                                                                                              0jEbWQtzs0Get hashmaliciousBrowse
                                                                                              • 45.95.169.115
                                                                                              8g3tc5SWwBGet hashmaliciousBrowse
                                                                                              • 92.52.211.220
                                                                                              LGDACOMLGDACOMCorporationKRJUZVpUSH0WGet hashmaliciousBrowse
                                                                                              • 210.219.31.15
                                                                                              2pPPNW1XSoGet hashmaliciousBrowse
                                                                                              • 118.128.83.148
                                                                                              SL92Sz9pl2Get hashmaliciousBrowse
                                                                                              • 1.217.238.242
                                                                                              oCN3rc0FzJ.exeGet hashmaliciousBrowse
                                                                                              • 115.88.24.202
                                                                                              BsNj9o1U0P.exeGet hashmaliciousBrowse
                                                                                              • 106.241.4.103
                                                                                              sMoq8eQy9U.exeGet hashmaliciousBrowse
                                                                                              • 211.119.84.112
                                                                                              pSY2vVxk86.exeGet hashmaliciousBrowse
                                                                                              • 210.92.250.133
                                                                                              KXSHtkFjm1.exeGet hashmaliciousBrowse
                                                                                              • 115.91.217.231
                                                                                              e4eukUb6d1.exeGet hashmaliciousBrowse
                                                                                              • 115.88.24.202
                                                                                              rdvL5Vuyg7.exeGet hashmaliciousBrowse
                                                                                              • 211.40.39.251
                                                                                              9JVjZ8tdvF.exeGet hashmaliciousBrowse
                                                                                              • 210.92.250.133
                                                                                              RgHOcm1miq.exeGet hashmaliciousBrowse
                                                                                              • 61.36.14.230
                                                                                              ECOC8S2pt7.exeGet hashmaliciousBrowse
                                                                                              • 210.182.29.70
                                                                                              DyTbafeDoq.exeGet hashmaliciousBrowse
                                                                                              • 211.119.84.112
                                                                                              yZ7D7o1Z7pGet hashmaliciousBrowse
                                                                                              • 61.32.157.192
                                                                                              VdcjZYprbtGet hashmaliciousBrowse
                                                                                              • 106.251.165.239
                                                                                              pLoEhdXNms.exeGet hashmaliciousBrowse
                                                                                              • 61.36.14.230
                                                                                              AQ7reGjgnP.exeGet hashmaliciousBrowse
                                                                                              • 211.53.202.252
                                                                                              344bx4XUBN.exeGet hashmaliciousBrowse
                                                                                              • 211.168.197.211
                                                                                              Km5KAxQLLV.exeGet hashmaliciousBrowse
                                                                                              • 115.88.24.202

                                                                                              JA3 Fingerprints

                                                                                              No context

                                                                                              Dropped Files

                                                                                              No context

                                                                                              Created / dropped Files

                                                                                              /tmp/qemu-open.TuD6GS (deleted)
                                                                                              Process:/tmp/csB31kWt10
                                                                                              File Type:ASCII text, with no line terminators
                                                                                              Category:dropped
                                                                                              Size (bytes):16
                                                                                              Entropy (8bit):3.625
                                                                                              Encrypted:false
                                                                                              SSDEEP:3:TgBCyy:TgYf
                                                                                              MD5:4A922E471FA53B8DAA0FEE8547E3E06A
                                                                                              SHA1:77B255512D26AE39E42695F3E340304FC34DCBA5
                                                                                              SHA-256:B269152470ED063CECFB68A18C34EB1D7986D5217862054DD313F3E7C93DF8AC
                                                                                              SHA-512:7B2A9BF1B59032D221D4C8FA4EFE69F6C01C1DE7B7A91C4FAF1DC26ACCE292953B38CCB6E5F582AACC9DBD8E7EA71FC37A249FC639CB79ADC2AE7CA9B5BB4DC0
                                                                                              Malicious:false
                                                                                              Reputation:low
                                                                                              Preview: /tmp/csB31kWt10.
                                                                                              /tmp/qemu-open.bKPayR (deleted)
                                                                                              Process:/tmp/csB31kWt10
                                                                                              File Type:ASCII text, with no line terminators
                                                                                              Category:dropped
                                                                                              Size (bytes):16
                                                                                              Entropy (8bit):3.625
                                                                                              Encrypted:false
                                                                                              SSDEEP:3:TgBCyy:TgYf
                                                                                              MD5:4A922E471FA53B8DAA0FEE8547E3E06A
                                                                                              SHA1:77B255512D26AE39E42695F3E340304FC34DCBA5
                                                                                              SHA-256:B269152470ED063CECFB68A18C34EB1D7986D5217862054DD313F3E7C93DF8AC
                                                                                              SHA-512:7B2A9BF1B59032D221D4C8FA4EFE69F6C01C1DE7B7A91C4FAF1DC26ACCE292953B38CCB6E5F582AACC9DBD8E7EA71FC37A249FC639CB79ADC2AE7CA9B5BB4DC0
                                                                                              Malicious:false
                                                                                              Reputation:low
                                                                                              Preview: /tmp/csB31kWt10.
                                                                                              /tmp/qemu-open.iXUKLT (deleted)
                                                                                              Process:/tmp/csB31kWt10
                                                                                              File Type:ASCII text, with no line terminators
                                                                                              Category:dropped
                                                                                              Size (bytes):16
                                                                                              Entropy (8bit):3.625
                                                                                              Encrypted:false
                                                                                              SSDEEP:3:TgBCyy:TgYf
                                                                                              MD5:4A922E471FA53B8DAA0FEE8547E3E06A
                                                                                              SHA1:77B255512D26AE39E42695F3E340304FC34DCBA5
                                                                                              SHA-256:B269152470ED063CECFB68A18C34EB1D7986D5217862054DD313F3E7C93DF8AC
                                                                                              SHA-512:7B2A9BF1B59032D221D4C8FA4EFE69F6C01C1DE7B7A91C4FAF1DC26ACCE292953B38CCB6E5F582AACC9DBD8E7EA71FC37A249FC639CB79ADC2AE7CA9B5BB4DC0
                                                                                              Malicious:false
                                                                                              Reputation:low
                                                                                              Preview: /tmp/csB31kWt10.
                                                                                              /tmp/qemu-open.mDwNfR (deleted)
                                                                                              Process:/tmp/csB31kWt10
                                                                                              File Type:ASCII text, with no line terminators
                                                                                              Category:dropped
                                                                                              Size (bytes):16
                                                                                              Entropy (8bit):3.625
                                                                                              Encrypted:false
                                                                                              SSDEEP:3:TgBCyy:TgYf
                                                                                              MD5:4A922E471FA53B8DAA0FEE8547E3E06A
                                                                                              SHA1:77B255512D26AE39E42695F3E340304FC34DCBA5
                                                                                              SHA-256:B269152470ED063CECFB68A18C34EB1D7986D5217862054DD313F3E7C93DF8AC
                                                                                              SHA-512:7B2A9BF1B59032D221D4C8FA4EFE69F6C01C1DE7B7A91C4FAF1DC26ACCE292953B38CCB6E5F582AACC9DBD8E7EA71FC37A249FC639CB79ADC2AE7CA9B5BB4DC0
                                                                                              Malicious:false
                                                                                              Reputation:low
                                                                                              Preview: /tmp/csB31kWt10.

                                                                                              Static File Info

                                                                                              General

                                                                                              File type:ELF 32-bit LSB executable, MIPS, MIPS-I version 1 (SYSV), statically linked, stripped
                                                                                              Entropy (8bit):5.526002031107092
                                                                                              TrID:
                                                                                              • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                                                                                              File name:csB31kWt10
                                                                                              File size:48624
                                                                                              MD5:df1ed6e73703ce09673aa4525975d129
                                                                                              SHA1:4b3444321f460d0ea48f4e96eb0ea45b27b885a6
                                                                                              SHA256:1d41b0a9c3b189c68bf219335a60f8156857fc6cef890e165e9ad2c48b15103a
                                                                                              SHA512:6776e5c9d462128f3ae4f07c019f4d5b195890116f7158359adb4e7a24642985db262eb3e4ab832fd721030635b96343f6bf3848b3775bcf772fd6e44d2f67e0
                                                                                              SSDEEP:768:n24VmMBIOoR7sYhz9ezjFFZ4GZJZTXiT+dQeEogrig0cH:PYhz98jnZ4yzy3rl5
                                                                                              File Content Preview:.ELF....................`.@.4...........4. ...(...............@...@...........................D...D.....`)..........Q.td...............................<|7.'!......'.......................<X7.'!... .........9'.. ........................<(7.'!.............9

                                                                                              Static ELF Info

                                                                                              ELF header

                                                                                              Class:ELF32
                                                                                              Data:2's complement, little endian
                                                                                              Version:1 (current)
                                                                                              Machine:MIPS R3000
                                                                                              Version Number:0x1
                                                                                              Type:EXEC (Executable file)
                                                                                              OS/ABI:UNIX - System V
                                                                                              ABI Version:0
                                                                                              Entry Point Address:0x400260
                                                                                              Flags:0x1007
                                                                                              ELF Header Size:52
                                                                                              Program Header Offset:52
                                                                                              Program Header Size:32
                                                                                              Number of Program Headers:3
                                                                                              Section Header Offset:48104
                                                                                              Section Header Size:40
                                                                                              Number of Section Headers:13
                                                                                              Header String Table Index:12

                                                                                              Sections

                                                                                              NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                                                                              NULL0x00x00x00x00x0000
                                                                                              .initPROGBITS0x4000940x940x8c0x00x6AX004
                                                                                              .textPROGBITS0x4001200x1200x9bd00x00x6AX0016
                                                                                              .finiPROGBITS0x409cf00x9cf00x5c0x00x6AX004
                                                                                              .rodataPROGBITS0x409d500x9d500x6a00x00x2A0016
                                                                                              .ctorsPROGBITS0x44a3f40xa3f40x80x00x3WA004
                                                                                              .dtorsPROGBITS0x44a3fc0xa3fc0x80x00x3WA004
                                                                                              .dataPROGBITS0x44a4100xa4100x14100x00x3WA0016
                                                                                              .gotPROGBITS0x44b8200xb8200x3700x40x10000003WA0016
                                                                                              .sbssNOBITS0x44bb900xbb900x300x00x10000003WA004
                                                                                              .bssNOBITS0x44bbc00xbb900x11940x00x3WA0016
                                                                                              .mdebug.abi32PROGBITS0x61e0xbb900x00x00x0001
                                                                                              .shstrtabSTRTAB0x00xbb900x570x00x0001

                                                                                              Program Segments

                                                                                              TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                                                              LOAD0x00x4000000x4000000xa3f00xa3f03.15280x5R E0x10000.init .text .fini .rodata
                                                                                              LOAD0xa3f40x44a3f40x44a3f40x179c0x29602.11030x6RW 0x10000.ctors .dtors .data .got .sbss .bss
                                                                                              GNU_STACK0x00x00x00x00x00.00000x7RWE0x4

                                                                                              Network Behavior

                                                                                              Network Port Distribution

                                                                                              TCP Packets

                                                                                              TimestampSource PortDest PortSource IPDest IP
                                                                                              Oct 29, 2021 09:39:55.775208950 CEST56596455192.168.2.2345.95.169.120
                                                                                              Oct 29, 2021 09:39:56.787815094 CEST56596455192.168.2.2345.95.169.120
                                                                                              Oct 29, 2021 09:39:56.821877956 CEST4555659645.95.169.120192.168.2.23
                                                                                              Oct 29, 2021 09:39:56.883721113 CEST42836443192.168.2.2391.189.91.43
                                                                                              Oct 29, 2021 09:39:57.395620108 CEST4251680192.168.2.23109.202.202.202
                                                                                              Oct 29, 2021 09:40:01.821957111 CEST56598455192.168.2.2345.95.169.120
                                                                                              Oct 29, 2021 09:40:02.834111929 CEST56598455192.168.2.2345.95.169.120
                                                                                              Oct 29, 2021 09:40:04.849616051 CEST56598455192.168.2.2345.95.169.120
                                                                                              Oct 29, 2021 09:40:08.916371107 CEST56598455192.168.2.2345.95.169.120
                                                                                              Oct 29, 2021 09:40:12.495445013 CEST43928443192.168.2.2391.189.91.42
                                                                                              Oct 29, 2021 09:40:17.102184057 CEST56598455192.168.2.2345.95.169.120
                                                                                              Oct 29, 2021 09:40:22.732641935 CEST42836443192.168.2.2391.189.91.43
                                                                                              Oct 29, 2021 09:40:24.528080940 CEST2345686121.66.166.226192.168.2.23
                                                                                              Oct 29, 2021 09:40:24.528234959 CEST4568623192.168.2.23121.66.166.226
                                                                                              Oct 29, 2021 09:40:26.827641010 CEST4251680192.168.2.23109.202.202.202
                                                                                              Oct 29, 2021 09:40:33.225825071 CEST56598455192.168.2.2345.95.169.120
                                                                                              Oct 29, 2021 09:40:53.444281101 CEST43928443192.168.2.2391.189.91.42
                                                                                              Oct 29, 2021 09:41:05.728996038 CEST56598455192.168.2.2345.95.169.120
                                                                                              Oct 29, 2021 09:41:05.762437105 CEST4555659845.95.169.120192.168.2.23
                                                                                              Oct 29, 2021 09:41:10.761538029 CEST56600455192.168.2.2345.95.169.120
                                                                                              Oct 29, 2021 09:41:11.775424004 CEST56600455192.168.2.2345.95.169.120
                                                                                              Oct 29, 2021 09:41:11.808981895 CEST4555660045.95.169.120192.168.2.23
                                                                                              Oct 29, 2021 09:41:13.918786049 CEST42836443192.168.2.2391.189.91.43
                                                                                              Oct 29, 2021 09:41:16.808116913 CEST56602455192.168.2.2345.95.169.120
                                                                                              Oct 29, 2021 09:41:16.841016054 CEST4555660245.95.169.120192.168.2.23
                                                                                              Oct 29, 2021 09:41:21.840012074 CEST56606455192.168.2.2345.95.169.120
                                                                                              Oct 29, 2021 09:41:21.873492002 CEST4555660645.95.169.120192.168.2.23
                                                                                              Oct 29, 2021 09:41:26.872570038 CEST56608455192.168.2.2345.95.169.120
                                                                                              Oct 29, 2021 09:41:27.898883104 CEST56608455192.168.2.2345.95.169.120
                                                                                              Oct 29, 2021 09:41:27.932296991 CEST4555660845.95.169.120192.168.2.23

                                                                                              System Behavior

                                                                                              General

                                                                                              Start time:09:39:54
                                                                                              Start date:29/10/2021
                                                                                              Path:/tmp/csB31kWt10
                                                                                              Arguments:/tmp/csB31kWt10
                                                                                              File size:5773336 bytes
                                                                                              MD5 hash:0d6f61f82cf2f781c6eb0661071d42d9

                                                                                              General

                                                                                              Start time:09:39:55
                                                                                              Start date:29/10/2021
                                                                                              Path:/tmp/csB31kWt10
                                                                                              Arguments:n/a
                                                                                              File size:5773336 bytes
                                                                                              MD5 hash:0d6f61f82cf2f781c6eb0661071d42d9

                                                                                              General

                                                                                              Start time:09:39:55
                                                                                              Start date:29/10/2021
                                                                                              Path:/tmp/csB31kWt10
                                                                                              Arguments:n/a
                                                                                              File size:5773336 bytes
                                                                                              MD5 hash:0d6f61f82cf2f781c6eb0661071d42d9