Loading ...

Play interactive tourEdit tour

Linux Analysis Report rijsTqU0If

Overview

General Information

Sample Name:rijsTqU0If
Analysis ID:511555
MD5:8c305137c8b025af33ac608a9b5465b9
SHA1:4dc66a698ddbfbb1bf77a67af5c85b997b99a17e
SHA256:93ca4f85d13c01834ae5b36d93cca17bd924dcbb9b238c7a3e2d51646d0c636a
Tags:32elfmipsmirai
Infos:

Most interesting Screenshot:

Detection

Score:48
Range:0 - 100
Whitelisted:false

Signatures

Multi AV Scanner detection for submitted file
Sample has stripped symbol table
Uses the "uname" system call to query kernel version information (possible evasion)
Enumerates processes within the "proc" file system
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Detected TCP or UDP traffic on non-standard ports
Sample tries to kill a process (SIGKILL)

Classification

Analysis Advice

Static ELF header machine description suggests that the sample might only run correctly on MIPS or ARM architectures
All HTTP servers contacted by the sample do not answer. Likely the sample is an old dropper which does no longer work
Static ELF header machine description suggests that the sample might not execute correctly on this machine

General Information

Joe Sandbox Version:34.0.0 Boulder Opal
Analysis ID:511555
Start date:29.10.2021
Start time:09:42:04
Joe Sandbox Product:CloudBasic
Overall analysis duration:0h 3m 53s
Hypervisor based Inspection enabled:false
Report type:full
Sample file name:rijsTqU0If
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Detection:MAL
Classification:mal48.lin@0/4@0/0

Process Tree

  • system is lnxubuntu20
  • rijsTqU0If (PID: 5257, Parent: 5135, MD5: 0083f1f0e77be34ad27f849842bbb00c) Arguments: /tmp/rijsTqU0If
  • cleanup

Yara Overview

No yara matches

Jbx Signature Overview

Click to jump to signature section

Show All Signature Results

AV Detection:

barindex
Multi AV Scanner detection for submitted fileShow sources
Source: rijsTqU0IfVirustotal: Detection: 21%Perma Link
Source: rijsTqU0IfReversingLabs: Detection: 15%
Source: global trafficTCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
Source: global trafficTCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
Source: global trafficTCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
Source: global trafficTCP traffic: 192.168.2.23:56596 -> 45.95.169.120:455
Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443
Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 14.245.169.210
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: ELF static info symbol of initial sample.symtab present: no
Source: /tmp/rijsTqU0If (PID: 5261)SIGKILL sent: pid: 2256, result: successfulJump to behavior
Source: /tmp/rijsTqU0If (PID: 5261)SIGKILL sent: pid: 2258, result: no such processJump to behavior
Source: /tmp/rijsTqU0If (PID: 5261)SIGKILL sent: pid: 5216, result: successfulJump to behavior
Source: /tmp/rijsTqU0If (PID: 5261)SIGKILL sent: pid: 5217, result: successfulJump to behavior
Source: /tmp/rijsTqU0If (PID: 5261)SIGKILL sent: pid: 5332, result: successfulJump to behavior
Source: /tmp/rijsTqU0If (PID: 5261)SIGKILL sent: pid: 5339, result: successfulJump to behavior
Source: classification engineClassification label: mal48.lin@0/4@0/0
Source: rijsTqU0IfJoe Sandbox Cloud Basic: Detection: clean Score: 0Perma Link
Source: /tmp/rijsTqU0If (PID: 5261)File opened: /proc/5261/statusJump to behavior
Source: /tmp/rijsTqU0If (PID: 5261)File opened: /proc/5261/statusJump to behavior
Source: /tmp/rijsTqU0If (PID: 5261)File opened: /proc/1582/cmdlineJump to behavior
Source: /tmp/rijsTqU0If (PID: 5261)File opened: /proc/1582/cmdlineJump to behavior
Source: /tmp/rijsTqU0If (PID: 5261)File opened: /proc/1582/statusJump to behavior
Source: /tmp/rijsTqU0If (PID: 5261)File opened: /proc/1582/statusJump to behavior
Source: /tmp/rijsTqU0If (PID: 5261)File opened: /proc/3088/cmdlineJump to behavior
Source: /tmp/rijsTqU0If (PID: 5261)File opened: /proc/3088/cmdlineJump to behavior
Source: /tmp/rijsTqU0If (PID: 5261)File opened: /proc/3088/statusJump to behavior
Source: /tmp/rijsTqU0If (PID: 5261)File opened: /proc/3088/statusJump to behavior
Source: /tmp/rijsTqU0If (PID: 5261)File opened: /proc/230/cmdlineJump to behavior
Source: /tmp/rijsTqU0If (PID: 5261)File opened: /proc/230/cmdlineJump to behavior
Source: /tmp/rijsTqU0If (PID: 5261)File opened: /proc/230/statusJump to behavior
Source: /tmp/rijsTqU0If (PID: 5261)File opened: /proc/230/statusJump to behavior
Source: /tmp/rijsTqU0If (PID: 5261)File opened: /proc/110/cmdlineJump to behavior
Source: /tmp/rijsTqU0If (PID: 5261)File opened: /proc/110/cmdlineJump to behavior
Source: /tmp/rijsTqU0If (PID: 5261)File opened: /proc/110/statusJump to behavior
Source: /tmp/rijsTqU0If (PID: 5261)File opened: /proc/110/statusJump to behavior
Source: /tmp/rijsTqU0If (PID: 5261)File opened: /proc/231/cmdlineJump to behavior
Source: /tmp/rijsTqU0If (PID: 5261)File opened: /proc/231/cmdlineJump to behavior
Source: /tmp/rijsTqU0If (PID: 5261)File opened: /proc/231/statusJump to behavior
Source: /tmp/rijsTqU0If (PID: 5261)File opened: /proc/231/statusJump to behavior
Source: /tmp/rijsTqU0If (PID: 5261)File opened: /proc/111/cmdlineJump to behavior
Source: /tmp/rijsTqU0If (PID: 5261)File opened: /proc/111/cmdlineJump to behavior
Source: /tmp/rijsTqU0If (PID: 5261)File opened: /proc/111/statusJump to behavior
Source: /tmp/rijsTqU0If (PID: 5261)File opened: /proc/111/statusJump to behavior
Source: /tmp/rijsTqU0If (PID: 5261)File opened: /proc/232/cmdlineJump to behavior
Source: /tmp/rijsTqU0If (PID: 5261)File opened: /proc/232/cmdlineJump to behavior
Source: /tmp/rijsTqU0If (PID: 5261)File opened: /proc/232/statusJump to behavior
Source: /tmp/rijsTqU0If (PID: 5261)File opened: /proc/232/statusJump to behavior
Source: /tmp/rijsTqU0If (PID: 5261)File opened: /proc/1579/cmdlineJump to behavior
Source: /tmp/rijsTqU0If (PID: 5261)File opened: /proc/1579/cmdlineJump to behavior
Source: /tmp/rijsTqU0If (PID: 5261)File opened: /proc/1579/statusJump to behavior
Source: /tmp/rijsTqU0If (PID: 5261)File opened: /proc/1579/statusJump to behavior
Source: /tmp/rijsTqU0If (PID: 5261)File opened: /proc/112/cmdlineJump to behavior
Source: /tmp/rijsTqU0If (PID: 5261)File opened: /proc/112/cmdlineJump to behavior
Source: /tmp/rijsTqU0If (PID: 5261)File opened: /proc/112/statusJump to behavior
Source: /tmp/rijsTqU0If (PID: 5261)File opened: /proc/112/statusJump to behavior
Source: /tmp/rijsTqU0If (PID: 5261)File opened: /proc/233/cmdlineJump to behavior
Source: /tmp/rijsTqU0If (PID: 5261)File opened: /proc/233/cmdlineJump to behavior
Source: /tmp/rijsTqU0If (PID: 5261)File opened: /proc/233/statusJump to behavior
Source: /tmp/rijsTqU0If (PID: 5261)File opened: /proc/233/statusJump to behavior
Source: /tmp/rijsTqU0If (PID: 5261)File opened: /proc/1699/cmdlineJump to behavior
Source: /tmp/rijsTqU0If (PID: 5261)File opened: /proc/1699/cmdlineJump to behavior
Source: /tmp/rijsTqU0If (PID: 5261)File opened: /proc/1699/statusJump to behavior
Source: /tmp/rijsTqU0If (PID: 5261)File opened: /proc/1699/statusJump to behavior
Source: /tmp/rijsTqU0If (PID: 5261)File opened: /proc/113/cmdlineJump to behavior
Source: /tmp/rijsTqU0If (PID: 5261)File opened: /proc/113/cmdlineJump to behavior
Source: /tmp/rijsTqU0If (PID: 5261)File opened: /proc/113/statusJump to behavior
Source: /tmp/rijsTqU0If (PID: 5261)File opened: /proc/113/statusJump to behavior
Source: /tmp/rijsTqU0If (PID: 5261)File opened: /proc/234/cmdlineJump to behavior
Source: /tmp/rijsTqU0If (PID: 5261)File opened: /proc/234/cmdlineJump to behavior
Source: /tmp/rijsTqU0If (PID: 5261)File opened: /proc/234/statusJump to behavior
Source: /tmp/rijsTqU0If (PID: 5261)File opened: /proc/234/statusJump to behavior
Source: /tmp/rijsTqU0If (PID: 5261)File opened: /proc/1335/cmdlineJump to behavior
Source: /tmp/rijsTqU0If (PID: 5261)File opened: /proc/1335/cmdlineJump to behavior
Source: /tmp/rijsTqU0If (PID: 5261)File opened: /proc/1335/statusJump to behavior
Source: /tmp/rijsTqU0If (PID: 5261)File opened: /proc/1335/statusJump to behavior
Source: /tmp/rijsTqU0If (PID: 5261)File opened: /proc/1698/cmdlineJump to behavior
Source: /tmp/rijsTqU0If (PID: 5261)File opened: /proc/1698/cmdlineJump to behavior
Source: /tmp/rijsTqU0If (PID: 5261)File opened: /proc/1698/statusJump to behavior
Source: /tmp/rijsTqU0If (PID: 5261)File opened: /proc/1698/statusJump to behavior
Source: /tmp/rijsTqU0If (PID: 5261)File opened: /proc/114/cmdlineJump to behavior
Source: /tmp/rijsTqU0If (PID: 5261)File opened: /proc/114/cmdlineJump to behavior
Source: /tmp/rijsTqU0If (PID: 5261)File opened: /proc/114/statusJump to behavior
Source: /tmp/rijsTqU0If (PID: 5261)File opened: /proc/114/statusJump to behavior
Source: /tmp/rijsTqU0If (PID: 5261)File opened: /proc/235/cmdlineJump to behavior
Source: /tmp/rijsTqU0If (PID: 5261)File opened: /proc/235/cmdlineJump to behavior
Source: /tmp/rijsTqU0If (PID: 5261)File opened: /proc/235/statusJump to behavior
Source: /tmp/rijsTqU0If (PID: 5261)File opened: /proc/235/statusJump to behavior
Source: /tmp/rijsTqU0If (PID: 5261)File opened: /proc/1334/cmdlineJump to behavior
Source: /tmp/rijsTqU0If (PID: 5261)File opened: /proc/1334/cmdlineJump to behavior
Source: /tmp/rijsTqU0If (PID: 5261)File opened: /proc/1334/statusJump to behavior
Source: /tmp/rijsTqU0If (PID: 5261)File opened: /proc/1334/statusJump to behavior
Source: /tmp/rijsTqU0If (PID: 5261)File opened: /proc/1576/cmdlineJump to behavior
Source: /tmp/rijsTqU0If (PID: 5261)File opened: /proc/1576/cmdlineJump to behavior
Source: /tmp/rijsTqU0If (PID: 5261)File opened: /proc/1576/statusJump to behavior
Source: /tmp/rijsTqU0If (PID: 5261)File opened: /proc/1576/statusJump to behavior
Source: /tmp/rijsTqU0If (PID: 5261)File opened: /proc/2302/cmdlineJump to behavior
Source: /tmp/rijsTqU0If (PID: 5261)File opened: /proc/2302/cmdlineJump to behavior
Source: /tmp/rijsTqU0If (PID: 5261)File opened: /proc/2302/statusJump to behavior
Source: /tmp/rijsTqU0If (PID: 5261)File opened: /proc/2302/statusJump to behavior
Source: /tmp/rijsTqU0If (PID: 5261)File opened: /proc/115/cmdlineJump to behavior
Source: /tmp/rijsTqU0If (PID: 5261)File opened: /proc/115/cmdlineJump to behavior
Source: /tmp/rijsTqU0If (PID: 5261)File opened: /proc/115/statusJump to behavior
Source: /tmp/rijsTqU0If (PID: 5261)File opened: /proc/115/statusJump to behavior
Source: /tmp/rijsTqU0If (PID: 5261)File opened: /proc/236/cmdlineJump to behavior
Source: /tmp/rijsTqU0If (PID: 5261)File opened: /proc/236/cmdlineJump to behavior
Source: /tmp/rijsTqU0If (PID: 5261)File opened: /proc/236/statusJump to behavior
Source: /tmp/rijsTqU0If (PID: 5261)File opened: /proc/236/statusJump to behavior
Source: /tmp/rijsTqU0If (PID: 5261)File opened: /proc/116/cmdlineJump to behavior
Source: /tmp/rijsTqU0If (PID: 5261)File opened: /proc/116/cmdlineJump to behavior
Source: /tmp/rijsTqU0If (PID: 5261)File opened: /proc/116/statusJump to behavior
Source: /tmp/rijsTqU0If (PID: 5261)File opened: /proc/116/statusJump to behavior
Source: /tmp/rijsTqU0If (PID: 5261)File opened: /proc/237/cmdlineJump to behavior
Source: /tmp/rijsTqU0If (PID: 5261)File opened: /proc/237/cmdlineJump to behavior
Source: /tmp/rijsTqU0If (PID: 5261)File opened: /proc/237/statusJump to behavior
Source: /tmp/rijsTqU0If (PID: 5261)File opened: /proc/237/statusJump to behavior
Source: /tmp/rijsTqU0If (PID: 5261)File opened: /proc/117/cmdlineJump to behavior
Source: /tmp/rijsTqU0If (PID: 5261)File opened: /proc/117/cmdlineJump to behavior
Source: /tmp/rijsTqU0If (PID: 5261)File opened: /proc/117/statusJump to behavior
Source: /tmp/rijsTqU0If (PID: 5261)File opened: /proc/117/statusJump to behavior
Source: /tmp/rijsTqU0If (PID: 5261)File opened: /proc/118/cmdlineJump to behavior
Source: /tmp/rijsTqU0If (PID: 5261)File opened: /proc/118/cmdlineJump to behavior
Source: /tmp/rijsTqU0If (PID: 5261)File opened: /proc/118/statusJump to behavior
Source: /tmp/rijsTqU0If (PID: 5261)File opened: /proc/118/statusJump to behavior
Source: /tmp/rijsTqU0If (PID: 5257)Queries kernel information via 'uname': Jump to behavior
Source: rijsTqU0If, 5257.1.000000002e1e1e19.000000007037b6cf.rw-.sdmpBinary or memory string: 'x86_64/usr/bin/qemu-mips/tmp/rijsTqU0IfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/rijsTqU0If
Source: rijsTqU0If, 5257.1.00000000ea33cb04.0000000086a4c822.rw-.sdmpBinary or memory string: U!/etc/qemu-binfmt/mips
Source: rijsTqU0If, 5257.1.00000000ea33cb04.0000000086a4c822.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/mips
Source: rijsTqU0If, 5257.1.000000002e1e1e19.000000007037b6cf.rw-.sdmpBinary or memory string: /usr/bin/qemu-mips

Mitre Att&ck Matrix

Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid AccountsWindows Management InstrumentationPath InterceptionPath InterceptionDirect Volume AccessOS Credential Dumping1Security Software Discovery11Remote ServicesData from Local SystemExfiltration Over Other Network MediumEncrypted Channel1Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over BluetoothNon-Standard Port1Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated ExfiltrationApplication Layer Protocol1Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data

Malware Configuration

No configs have been found

Behavior Graph

Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 511555 Sample: rijsTqU0If Startdate: 29/10/2021 Architecture: LINUX Score: 48 14 14.245.169.210, 23, 51120 VNPT-AS-VNVNPTCorpVN Viet Nam 2->14 16 109.202.202.202, 80 INIT7CH Switzerland 2->16 18 3 other IPs or domains 2->18 20 Multi AV Scanner detection for submitted file 2->20 8 rijsTqU0If 2->8         started        signatures3 process4 process5 10 rijsTqU0If 8->10         started        process6 12 rijsTqU0If 10->12         started       

Screenshots

Thumbnails

This section contains all screenshots as thumbnails, including those not shown in the slideshow.

windows-stand

Antivirus, Machine Learning and Genetic Malware Detection

Initial Sample

SourceDetectionScannerLabelLink
rijsTqU0If21%VirustotalBrowse
rijsTqU0If16%ReversingLabsLinux.Trojan.Mirai

Dropped Files

No Antivirus matches

Domains

No Antivirus matches

URLs

No Antivirus matches

Domains and IPs

Contacted Domains

No contacted domains info

Contacted IPs

  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs

Public

IPDomainCountryFlagASNASN NameMalicious
14.245.169.210
unknownViet Nam
45899VNPT-AS-VNVNPTCorpVNfalse
45.95.169.120
unknownCroatia (LOCAL Name: Hrvatska)
42864GIGANET-HUGigaNetInternetServiceProviderCoHUfalse
109.202.202.202
unknownSwitzerland
13030INIT7CHfalse
91.189.91.43
unknownUnited Kingdom
41231CANONICAL-ASGBfalse
91.189.91.42
unknownUnited Kingdom
41231CANONICAL-ASGBfalse


Runtime Messages

Command:/tmp/rijsTqU0If
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:

Standard Error:

Joe Sandbox View / Context

IPs

MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
45.95.169.120csB31kWt10Get hashmaliciousBrowse
    QWg2NTuodYGet hashmaliciousBrowse
      SL92Sz9pl2Get hashmaliciousBrowse
        YpKL484IG5Get hashmaliciousBrowse
          Y4W4j5QIqDGet hashmaliciousBrowse
            1TnmkstVG8Get hashmaliciousBrowse
              iksM5QEg2jGet hashmaliciousBrowse
                109.202.202.202csB31kWt10Get hashmaliciousBrowse
                  QWg2NTuodYGet hashmaliciousBrowse
                    6VLeGqFkPSGet hashmaliciousBrowse
                      DL5blLw1lyGet hashmaliciousBrowse
                        SL92Sz9pl2Get hashmaliciousBrowse
                          YpKL484IG5Get hashmaliciousBrowse
                            Y4W4j5QIqDGet hashmaliciousBrowse
                              1TnmkstVG8Get hashmaliciousBrowse
                                iksM5QEg2jGet hashmaliciousBrowse
                                  lGJEkz80oeGet hashmaliciousBrowse
                                    roV7kGaVr1Get hashmaliciousBrowse
                                      SecuriteInfo.com.Linux.Siggen.4218.298.3210Get hashmaliciousBrowse
                                        uPOWBxniTAGet hashmaliciousBrowse
                                          qy5unieRgRGet hashmaliciousBrowse
                                            sAzPpn6mKZGet hashmaliciousBrowse
                                              AxadDC89j9Get hashmaliciousBrowse
                                                ZErnXU2XR1Get hashmaliciousBrowse
                                                  sTHJvS5LPJGet hashmaliciousBrowse
                                                    THzHjYQ4z6Get hashmaliciousBrowse
                                                      jC0B6sMh1dGet hashmaliciousBrowse
                                                        91.189.91.43csB31kWt10Get hashmaliciousBrowse
                                                          QWg2NTuodYGet hashmaliciousBrowse
                                                            6VLeGqFkPSGet hashmaliciousBrowse
                                                              DL5blLw1lyGet hashmaliciousBrowse
                                                                SL92Sz9pl2Get hashmaliciousBrowse
                                                                  YpKL484IG5Get hashmaliciousBrowse
                                                                    Y4W4j5QIqDGet hashmaliciousBrowse
                                                                      1TnmkstVG8Get hashmaliciousBrowse
                                                                        iksM5QEg2jGet hashmaliciousBrowse
                                                                          lGJEkz80oeGet hashmaliciousBrowse
                                                                            roV7kGaVr1Get hashmaliciousBrowse
                                                                              SecuriteInfo.com.Linux.Siggen.4218.298.3210Get hashmaliciousBrowse
                                                                                uPOWBxniTAGet hashmaliciousBrowse
                                                                                  qy5unieRgRGet hashmaliciousBrowse
                                                                                    sAzPpn6mKZGet hashmaliciousBrowse
                                                                                      AxadDC89j9Get hashmaliciousBrowse
                                                                                        ZErnXU2XR1Get hashmaliciousBrowse
                                                                                          sTHJvS5LPJGet hashmaliciousBrowse
                                                                                            THzHjYQ4z6Get hashmaliciousBrowse
                                                                                              jC0B6sMh1dGet hashmaliciousBrowse
                                                                                                91.189.91.42csB31kWt10Get hashmaliciousBrowse
                                                                                                  QWg2NTuodYGet hashmaliciousBrowse
                                                                                                    6VLeGqFkPSGet hashmaliciousBrowse
                                                                                                      DL5blLw1lyGet hashmaliciousBrowse
                                                                                                        SL92Sz9pl2Get hashmaliciousBrowse
                                                                                                          YpKL484IG5Get hashmaliciousBrowse
                                                                                                            Y4W4j5QIqDGet hashmaliciousBrowse
                                                                                                              1TnmkstVG8Get hashmaliciousBrowse
                                                                                                                iksM5QEg2jGet hashmaliciousBrowse
                                                                                                                  lGJEkz80oeGet hashmaliciousBrowse
                                                                                                                    roV7kGaVr1Get hashmaliciousBrowse
                                                                                                                      SecuriteInfo.com.Linux.Siggen.4218.298.3210Get hashmaliciousBrowse
                                                                                                                        uPOWBxniTAGet hashmaliciousBrowse
                                                                                                                          qy5unieRgRGet hashmaliciousBrowse
                                                                                                                            sAzPpn6mKZGet hashmaliciousBrowse
                                                                                                                              AxadDC89j9Get hashmaliciousBrowse
                                                                                                                                ZErnXU2XR1Get hashmaliciousBrowse
                                                                                                                                  sTHJvS5LPJGet hashmaliciousBrowse
                                                                                                                                    THzHjYQ4z6Get hashmaliciousBrowse
                                                                                                                                      jC0B6sMh1dGet hashmaliciousBrowse

                                                                                                                                        Domains

                                                                                                                                        No context

                                                                                                                                        ASN

                                                                                                                                        MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                                                                                                                                        GIGANET-HUGigaNetInternetServiceProviderCoHUcsB31kWt10Get hashmaliciousBrowse
                                                                                                                                        • 45.95.169.120
                                                                                                                                        QWg2NTuodYGet hashmaliciousBrowse
                                                                                                                                        • 45.95.169.120
                                                                                                                                        SL92Sz9pl2Get hashmaliciousBrowse
                                                                                                                                        • 45.95.169.120
                                                                                                                                        YpKL484IG5Get hashmaliciousBrowse
                                                                                                                                        • 45.95.169.120
                                                                                                                                        Y4W4j5QIqDGet hashmaliciousBrowse
                                                                                                                                        • 45.95.169.120
                                                                                                                                        1TnmkstVG8Get hashmaliciousBrowse
                                                                                                                                        • 45.95.169.120
                                                                                                                                        iksM5QEg2jGet hashmaliciousBrowse
                                                                                                                                        • 45.95.169.120
                                                                                                                                        RicwIfIHLKGet hashmaliciousBrowse
                                                                                                                                        • 45.95.169.115
                                                                                                                                        aIY7AxjUMcGet hashmaliciousBrowse
                                                                                                                                        • 45.95.169.115
                                                                                                                                        DtJmFQxtNCGet hashmaliciousBrowse
                                                                                                                                        • 45.95.169.115
                                                                                                                                        Wm4CzOCmNYGet hashmaliciousBrowse
                                                                                                                                        • 45.95.169.115
                                                                                                                                        vunWUzXJvCGet hashmaliciousBrowse
                                                                                                                                        • 45.95.169.115
                                                                                                                                        52xhBHy9WzGet hashmaliciousBrowse
                                                                                                                                        • 45.95.169.115
                                                                                                                                        YGvwG0iCDEGet hashmaliciousBrowse
                                                                                                                                        • 45.95.169.115
                                                                                                                                        dbd5O0RUTqGet hashmaliciousBrowse
                                                                                                                                        • 45.95.169.115
                                                                                                                                        fHVDVj0pzOGet hashmaliciousBrowse
                                                                                                                                        • 45.95.169.115
                                                                                                                                        eZPk7Fg5w7Get hashmaliciousBrowse
                                                                                                                                        • 45.95.169.115
                                                                                                                                        ph5PjoFBpjGet hashmaliciousBrowse
                                                                                                                                        • 45.95.169.115
                                                                                                                                        xugAk5haatGet hashmaliciousBrowse
                                                                                                                                        • 45.95.169.115
                                                                                                                                        0jEbWQtzs0Get hashmaliciousBrowse
                                                                                                                                        • 45.95.169.115
                                                                                                                                        INIT7CHcsB31kWt10Get hashmaliciousBrowse
                                                                                                                                        • 109.202.202.202
                                                                                                                                        QWg2NTuodYGet hashmaliciousBrowse
                                                                                                                                        • 109.202.202.202
                                                                                                                                        6VLeGqFkPSGet hashmaliciousBrowse
                                                                                                                                        • 109.202.202.202
                                                                                                                                        DL5blLw1lyGet hashmaliciousBrowse
                                                                                                                                        • 109.202.202.202
                                                                                                                                        SL92Sz9pl2Get hashmaliciousBrowse
                                                                                                                                        • 109.202.202.202
                                                                                                                                        YpKL484IG5Get hashmaliciousBrowse
                                                                                                                                        • 109.202.202.202
                                                                                                                                        Y4W4j5QIqDGet hashmaliciousBrowse
                                                                                                                                        • 109.202.202.202
                                                                                                                                        1TnmkstVG8Get hashmaliciousBrowse
                                                                                                                                        • 109.202.202.202
                                                                                                                                        iksM5QEg2jGet hashmaliciousBrowse
                                                                                                                                        • 109.202.202.202
                                                                                                                                        lGJEkz80oeGet hashmaliciousBrowse
                                                                                                                                        • 109.202.202.202
                                                                                                                                        roV7kGaVr1Get hashmaliciousBrowse
                                                                                                                                        • 109.202.202.202
                                                                                                                                        SecuriteInfo.com.Linux.Siggen.4218.298.3210Get hashmaliciousBrowse
                                                                                                                                        • 109.202.202.202
                                                                                                                                        uPOWBxniTAGet hashmaliciousBrowse
                                                                                                                                        • 109.202.202.202
                                                                                                                                        qy5unieRgRGet hashmaliciousBrowse
                                                                                                                                        • 109.202.202.202
                                                                                                                                        sAzPpn6mKZGet hashmaliciousBrowse
                                                                                                                                        • 109.202.202.202
                                                                                                                                        AxadDC89j9Get hashmaliciousBrowse
                                                                                                                                        • 109.202.202.202
                                                                                                                                        ZErnXU2XR1Get hashmaliciousBrowse
                                                                                                                                        • 109.202.202.202
                                                                                                                                        sTHJvS5LPJGet hashmaliciousBrowse
                                                                                                                                        • 109.202.202.202
                                                                                                                                        THzHjYQ4z6Get hashmaliciousBrowse
                                                                                                                                        • 109.202.202.202
                                                                                                                                        jC0B6sMh1dGet hashmaliciousBrowse
                                                                                                                                        • 109.202.202.202
                                                                                                                                        VNPT-AS-VNVNPTCorpVNvEBWe85OY5Get hashmaliciousBrowse
                                                                                                                                        • 14.253.102.15
                                                                                                                                        5mLAGfiGBfGet hashmaliciousBrowse
                                                                                                                                        • 123.22.248.38
                                                                                                                                        VdcjZYprbtGet hashmaliciousBrowse
                                                                                                                                        • 14.161.68.251
                                                                                                                                        x86_64Get hashmaliciousBrowse
                                                                                                                                        • 14.253.102.17
                                                                                                                                        3QM8LROaOkGet hashmaliciousBrowse
                                                                                                                                        • 14.243.17.127
                                                                                                                                        mdyu2wtnR8Get hashmaliciousBrowse
                                                                                                                                        • 113.174.188.232
                                                                                                                                        4VC4C0PxQbGet hashmaliciousBrowse
                                                                                                                                        • 123.29.125.18
                                                                                                                                        KfvEoN0wIwGet hashmaliciousBrowse
                                                                                                                                        • 123.16.27.140
                                                                                                                                        K1fia4oWepGet hashmaliciousBrowse
                                                                                                                                        • 123.22.224.13
                                                                                                                                        juxSAmZoqxGet hashmaliciousBrowse
                                                                                                                                        • 123.18.32.68
                                                                                                                                        db0fa4b8db0333367e9bda3ab68b8042.x86Get hashmaliciousBrowse
                                                                                                                                        • 123.22.248.34
                                                                                                                                        6NzbU4oW61Get hashmaliciousBrowse
                                                                                                                                        • 123.26.120.231
                                                                                                                                        IcwrPqGkXPGet hashmaliciousBrowse
                                                                                                                                        • 113.180.223.7
                                                                                                                                        sora.armGet hashmaliciousBrowse
                                                                                                                                        • 14.178.101.117
                                                                                                                                        UYnpKcFZ2sGet hashmaliciousBrowse
                                                                                                                                        • 14.232.212.176
                                                                                                                                        zYMp3detVOGet hashmaliciousBrowse
                                                                                                                                        • 113.175.69.143
                                                                                                                                        Tf9ATzpdKRGet hashmaliciousBrowse
                                                                                                                                        • 14.237.37.63
                                                                                                                                        b3astmode.x86Get hashmaliciousBrowse
                                                                                                                                        • 14.184.247.127
                                                                                                                                        JYWllP5wHPGet hashmaliciousBrowse
                                                                                                                                        • 222.252.74.200
                                                                                                                                        sora.arm7Get hashmaliciousBrowse
                                                                                                                                        • 14.180.176.215

                                                                                                                                        JA3 Fingerprints

                                                                                                                                        No context

                                                                                                                                        Dropped Files

                                                                                                                                        No context

                                                                                                                                        Created / dropped Files

                                                                                                                                        /tmp/qemu-open.FkwII2 (deleted)
                                                                                                                                        Process:/tmp/rijsTqU0If
                                                                                                                                        File Type:ASCII text, with no line terminators
                                                                                                                                        Category:dropped
                                                                                                                                        Size (bytes):16
                                                                                                                                        Entropy (8bit):3.875
                                                                                                                                        Encrypted:false
                                                                                                                                        SSDEEP:3:TgfUX:TgfUX
                                                                                                                                        MD5:F74579562F35CBFB0F4F4CDB336291CC
                                                                                                                                        SHA1:832C3E5265179CEE8D7209B6AA96F037415D564A
                                                                                                                                        SHA-256:D6A6D223938608296B875F461E30143D0860BBDD07D17AF915F5D4EEB51D4A51
                                                                                                                                        SHA-512:337EA0D2387093EC5498EB2E43F437CEB1D73E7CD1C274924485BC96BBFA539C5FAAAB0124D786A8691BDC8A05D26220C37686CF7A8E6BB0D441BC4B9B5BAA04
                                                                                                                                        Malicious:false
                                                                                                                                        Reputation:low
                                                                                                                                        Preview: /tmp/rijsTqU0If.
                                                                                                                                        /tmp/qemu-open.l72D7Z (deleted)
                                                                                                                                        Process:/tmp/rijsTqU0If
                                                                                                                                        File Type:ASCII text, with no line terminators
                                                                                                                                        Category:dropped
                                                                                                                                        Size (bytes):16
                                                                                                                                        Entropy (8bit):3.875
                                                                                                                                        Encrypted:false
                                                                                                                                        SSDEEP:3:TgfUX:TgfUX
                                                                                                                                        MD5:F74579562F35CBFB0F4F4CDB336291CC
                                                                                                                                        SHA1:832C3E5265179CEE8D7209B6AA96F037415D564A
                                                                                                                                        SHA-256:D6A6D223938608296B875F461E30143D0860BBDD07D17AF915F5D4EEB51D4A51
                                                                                                                                        SHA-512:337EA0D2387093EC5498EB2E43F437CEB1D73E7CD1C274924485BC96BBFA539C5FAAAB0124D786A8691BDC8A05D26220C37686CF7A8E6BB0D441BC4B9B5BAA04
                                                                                                                                        Malicious:false
                                                                                                                                        Reputation:low
                                                                                                                                        Preview: /tmp/rijsTqU0If.
                                                                                                                                        /tmp/qemu-open.mWC470 (deleted)
                                                                                                                                        Process:/tmp/rijsTqU0If
                                                                                                                                        File Type:ASCII text, with no line terminators
                                                                                                                                        Category:dropped
                                                                                                                                        Size (bytes):16
                                                                                                                                        Entropy (8bit):3.875
                                                                                                                                        Encrypted:false
                                                                                                                                        SSDEEP:3:TgfUX:TgfUX
                                                                                                                                        MD5:F74579562F35CBFB0F4F4CDB336291CC
                                                                                                                                        SHA1:832C3E5265179CEE8D7209B6AA96F037415D564A
                                                                                                                                        SHA-256:D6A6D223938608296B875F461E30143D0860BBDD07D17AF915F5D4EEB51D4A51
                                                                                                                                        SHA-512:337EA0D2387093EC5498EB2E43F437CEB1D73E7CD1C274924485BC96BBFA539C5FAAAB0124D786A8691BDC8A05D26220C37686CF7A8E6BB0D441BC4B9B5BAA04
                                                                                                                                        Malicious:false
                                                                                                                                        Reputation:low
                                                                                                                                        Preview: /tmp/rijsTqU0If.
                                                                                                                                        /tmp/qemu-open.zQV7X2 (deleted)
                                                                                                                                        Process:/tmp/rijsTqU0If
                                                                                                                                        File Type:ASCII text, with no line terminators
                                                                                                                                        Category:dropped
                                                                                                                                        Size (bytes):16
                                                                                                                                        Entropy (8bit):3.875
                                                                                                                                        Encrypted:false
                                                                                                                                        SSDEEP:3:TgfUX:TgfUX
                                                                                                                                        MD5:F74579562F35CBFB0F4F4CDB336291CC
                                                                                                                                        SHA1:832C3E5265179CEE8D7209B6AA96F037415D564A
                                                                                                                                        SHA-256:D6A6D223938608296B875F461E30143D0860BBDD07D17AF915F5D4EEB51D4A51
                                                                                                                                        SHA-512:337EA0D2387093EC5498EB2E43F437CEB1D73E7CD1C274924485BC96BBFA539C5FAAAB0124D786A8691BDC8A05D26220C37686CF7A8E6BB0D441BC4B9B5BAA04
                                                                                                                                        Malicious:false
                                                                                                                                        Reputation:low
                                                                                                                                        Preview: /tmp/rijsTqU0If.

                                                                                                                                        Static File Info

                                                                                                                                        General

                                                                                                                                        File type:ELF 32-bit MSB executable, MIPS, MIPS-I version 1 (SYSV), statically linked, stripped
                                                                                                                                        Entropy (8bit):5.519592349845016
                                                                                                                                        TrID:
                                                                                                                                        • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                                                                                                                                        File name:rijsTqU0If
                                                                                                                                        File size:48272
                                                                                                                                        MD5:8c305137c8b025af33ac608a9b5465b9
                                                                                                                                        SHA1:4dc66a698ddbfbb1bf77a67af5c85b997b99a17e
                                                                                                                                        SHA256:93ca4f85d13c01834ae5b36d93cca17bd924dcbb9b238c7a3e2d51646d0c636a
                                                                                                                                        SHA512:d7f2b6b6cc51d996d08e29006955b5283861010ae910e17168c5532f8bd56bf0b07eab51f4198ff39c82fecb7c534785c9513ef08812e868c89c8103e52d3ce4
                                                                                                                                        SSDEEP:768:JSLLLLLLLLOIqHAH1kJJ5hpnagnRqZPqtbKSWQiyn3Sb6G8dhDJ:W0TV3RqI8nyCb6lJJ
                                                                                                                                        File Content Preview:.ELF.....................@.`...4.........4. ...(.............@...@...........................D...D........)`........dt.Q............................<...'.6....!'.......................<...'.5....!... ....'9... ......................<...'.5....!........'9.

                                                                                                                                        Static ELF Info

                                                                                                                                        ELF header

                                                                                                                                        Class:ELF32
                                                                                                                                        Data:2's complement, big endian
                                                                                                                                        Version:1 (current)
                                                                                                                                        Machine:MIPS R3000
                                                                                                                                        Version Number:0x1
                                                                                                                                        Type:EXEC (Executable file)
                                                                                                                                        OS/ABI:UNIX - System V
                                                                                                                                        ABI Version:0
                                                                                                                                        Entry Point Address:0x400260
                                                                                                                                        Flags:0x1007
                                                                                                                                        ELF Header Size:52
                                                                                                                                        Program Header Offset:52
                                                                                                                                        Program Header Size:32
                                                                                                                                        Number of Program Headers:3
                                                                                                                                        Section Header Offset:47752
                                                                                                                                        Section Header Size:40
                                                                                                                                        Number of Section Headers:13
                                                                                                                                        Header String Table Index:12

                                                                                                                                        Sections

                                                                                                                                        NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                                                                                                                        NULL0x00x00x00x00x0000
                                                                                                                                        .initPROGBITS0x4000940x940x8c0x00x6AX004
                                                                                                                                        .textPROGBITS0x4001200x1200x9a700x00x6AX0016
                                                                                                                                        .finiPROGBITS0x409b900x9b900x5c0x00x6AX004
                                                                                                                                        .rodataPROGBITS0x409bf00x9bf00x6a00x00x2A0016
                                                                                                                                        .ctorsPROGBITS0x44a2940xa2940x80x00x3WA004
                                                                                                                                        .dtorsPROGBITS0x44a29c0xa29c0x80x00x3WA004
                                                                                                                                        .dataPROGBITS0x44a2b00xa2b00x14100x00x3WA0016
                                                                                                                                        .gotPROGBITS0x44b6c00xb6c00x3700x40x10000003WA0016
                                                                                                                                        .sbssNOBITS0x44ba300xba300x300x00x10000003WA004
                                                                                                                                        .bssNOBITS0x44ba600xba300x11940x00x3WA0016
                                                                                                                                        .mdebug.abi32PROGBITS0x61e0xba300x00x00x0001
                                                                                                                                        .shstrtabSTRTAB0x00xba300x570x00x0001

                                                                                                                                        Program Segments

                                                                                                                                        TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                                                                                                        LOAD0x00x4000000x4000000xa2900xa2903.13290x5R E0x10000.init .text .fini .rodata
                                                                                                                                        LOAD0xa2940x44a2940x44a2940x179c0x29602.12260x6RW 0x10000.ctors .dtors .data .got .sbss .bss
                                                                                                                                        GNU_STACK0x00x00x00x00x00.00000x7RWE0x4

                                                                                                                                        Network Behavior

                                                                                                                                        Network Port Distribution

                                                                                                                                        TCP Packets

                                                                                                                                        TimestampSource PortDest PortSource IPDest IP
                                                                                                                                        Oct 29, 2021 09:42:48.434736013 CEST56596455192.168.2.2345.95.169.120
                                                                                                                                        Oct 29, 2021 09:42:48.468739033 CEST4555659645.95.169.120192.168.2.23
                                                                                                                                        Oct 29, 2021 09:42:50.924155951 CEST4251680192.168.2.23109.202.202.202
                                                                                                                                        Oct 29, 2021 09:42:50.924197912 CEST42836443192.168.2.2391.189.91.43
                                                                                                                                        Oct 29, 2021 09:42:53.469223976 CEST56598455192.168.2.2345.95.169.120
                                                                                                                                        Oct 29, 2021 09:42:54.475702047 CEST56598455192.168.2.2345.95.169.120
                                                                                                                                        Oct 29, 2021 09:42:54.509037018 CEST4555659845.95.169.120192.168.2.23
                                                                                                                                        Oct 29, 2021 09:42:59.508882999 CEST56600455192.168.2.2345.95.169.120
                                                                                                                                        Oct 29, 2021 09:42:59.543243885 CEST4555660045.95.169.120192.168.2.23
                                                                                                                                        Oct 29, 2021 09:43:04.542954922 CEST56602455192.168.2.2345.95.169.120
                                                                                                                                        Oct 29, 2021 09:43:05.258423090 CEST43928443192.168.2.2391.189.91.42
                                                                                                                                        Oct 29, 2021 09:43:05.546467066 CEST56602455192.168.2.2345.95.169.120
                                                                                                                                        Oct 29, 2021 09:43:05.579452991 CEST4555660245.95.169.120192.168.2.23
                                                                                                                                        Oct 29, 2021 09:43:10.579250097 CEST56604455192.168.2.2345.95.169.120
                                                                                                                                        Oct 29, 2021 09:43:11.593632936 CEST56604455192.168.2.2345.95.169.120
                                                                                                                                        Oct 29, 2021 09:43:13.609396935 CEST56604455192.168.2.2345.95.169.120
                                                                                                                                        Oct 29, 2021 09:43:13.643373013 CEST4555660445.95.169.120192.168.2.23
                                                                                                                                        Oct 29, 2021 09:43:17.544953108 CEST42836443192.168.2.2391.189.91.43
                                                                                                                                        Oct 29, 2021 09:43:18.643186092 CEST56606455192.168.2.2345.95.169.120
                                                                                                                                        Oct 29, 2021 09:43:18.677001953 CEST4555660645.95.169.120192.168.2.23
                                                                                                                                        Oct 29, 2021 09:43:21.640388966 CEST4251680192.168.2.23109.202.202.202
                                                                                                                                        Oct 29, 2021 09:43:30.817409039 CEST235112014.245.169.210192.168.2.23
                                                                                                                                        Oct 29, 2021 09:43:30.817544937 CEST5112023192.168.2.2314.245.169.210
                                                                                                                                        Oct 29, 2021 09:43:46.213304996 CEST43928443192.168.2.2391.189.91.42

                                                                                                                                        System Behavior

                                                                                                                                        General

                                                                                                                                        Start time:09:42:47
                                                                                                                                        Start date:29/10/2021
                                                                                                                                        Path:/tmp/rijsTqU0If
                                                                                                                                        Arguments:/tmp/rijsTqU0If
                                                                                                                                        File size:5777432 bytes
                                                                                                                                        MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                                                                                                                                        General

                                                                                                                                        Start time:09:42:47
                                                                                                                                        Start date:29/10/2021
                                                                                                                                        Path:/tmp/rijsTqU0If
                                                                                                                                        Arguments:n/a
                                                                                                                                        File size:5777432 bytes
                                                                                                                                        MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                                                                                                                                        General

                                                                                                                                        Start time:09:42:47
                                                                                                                                        Start date:29/10/2021
                                                                                                                                        Path:/tmp/rijsTqU0If
                                                                                                                                        Arguments:n/a
                                                                                                                                        File size:5777432 bytes
                                                                                                                                        MD5 hash:0083f1f0e77be34ad27f849842bbb00c