Loading ...

Play interactive tourEdit tour

Linux Analysis Report 3tgXa7CGc1

Overview

General Information

Sample Name:3tgXa7CGc1
Analysis ID:511557
MD5:3ca11c21956b7c6a03ef4f48698c209e
SHA1:d26f991c4df35a746a324129f588601fc105fd18
SHA256:ddfb21fd0f3589e3ecf1421d65941a8ff85e0e324e2b2149ce67e26727c5c97f
Tags:32elfmips
Infos:

Detection

Score:48
Range:0 - 100
Whitelisted:false

Signatures

Multi AV Scanner detection for submitted file
Sample has stripped symbol table
Uses the "uname" system call to query kernel version information (possible evasion)
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Detected TCP or UDP traffic on non-standard ports

Classification

Analysis Advice

Static ELF header machine description suggests that the sample might only run correctly on MIPS or ARM architectures
All HTTP servers contacted by the sample do not answer. Likely the sample is an old dropper which does no longer work
Static ELF header machine description suggests that the sample might not execute correctly on this machine

General Information

Joe Sandbox Version:34.0.0 Boulder Opal
Analysis ID:511557
Start date:29.10.2021
Start time:09:44:55
Joe Sandbox Product:CloudBasic
Overall analysis duration:0h 4m 48s
Hypervisor based Inspection enabled:false
Report type:full
Sample file name:3tgXa7CGc1
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Detection:MAL
Classification:mal48.lin@0/0@0/0

Process Tree

  • system is lnxubuntu20
  • 3tgXa7CGc1 (PID: 5236, Parent: 5113, MD5: 0083f1f0e77be34ad27f849842bbb00c) Arguments: /tmp/3tgXa7CGc1
  • cleanup

Yara Overview

No yara matches

Jbx Signature Overview

Click to jump to signature section

Show All Signature Results

AV Detection:

barindex
Multi AV Scanner detection for submitted fileShow sources
Source: 3tgXa7CGc1Virustotal: Detection: 24%Perma Link
Source: 3tgXa7CGc1ReversingLabs: Detection: 26%
Source: global trafficTCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
Source: global trafficTCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
Source: global trafficTCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
Source: global trafficTCP traffic: 192.168.2.23:56596 -> 45.95.169.120:455
Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443
Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
Source: ELF static info symbol of initial sample.symtab present: no
Source: classification engineClassification label: mal48.lin@0/0@0/0
Source: 3tgXa7CGc1Joe Sandbox Cloud Basic: Detection: clean Score: 0Perma Link
Source: /tmp/3tgXa7CGc1 (PID: 5236)Queries kernel information via 'uname': Jump to behavior
Source: 3tgXa7CGc1, 5236.1.00000000bc16e1e6.000000004454ad71.rw-.sdmpBinary or memory string: U!/etc/qemu-binfmt/mips
Source: 3tgXa7CGc1, 5236.1.00000000bc16e1e6.000000004454ad71.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/mips
Source: 3tgXa7CGc1, 5236.1.000000008fb90f6d.00000000cab4e971.rw-.sdmpBinary or memory string: 4lx86_64/usr/bin/qemu-mips/tmp/3tgXa7CGc1SUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/3tgXa7CGc1
Source: 3tgXa7CGc1, 5236.1.000000008fb90f6d.00000000cab4e971.rw-.sdmpBinary or memory string: /usr/bin/qemu-mips

Mitre Att&ck Matrix

Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid AccountsWindows Management InstrumentationPath InterceptionPath InterceptionDirect Volume AccessOS Credential DumpingSecurity Software Discovery11Remote ServicesData from Local SystemExfiltration Over Other Network MediumEncrypted Channel1Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over BluetoothNon-Standard Port1Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated ExfiltrationApplication Layer Protocol1Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data

Malware Configuration

No configs have been found

Behavior Graph

Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet

Antivirus, Machine Learning and Genetic Malware Detection

Initial Sample

SourceDetectionScannerLabelLink
3tgXa7CGc125%VirustotalBrowse
3tgXa7CGc127%ReversingLabsLinux.Trojan.Mirai

Dropped Files

No Antivirus matches

Domains

No Antivirus matches

URLs

No Antivirus matches

Domains and IPs

Contacted Domains

No contacted domains info

Contacted IPs

  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs

Public

IPDomainCountryFlagASNASN NameMalicious
45.95.169.120
unknownCroatia (LOCAL Name: Hrvatska)
42864GIGANET-HUGigaNetInternetServiceProviderCoHUfalse
109.202.202.202
unknownSwitzerland
13030INIT7CHfalse
91.189.91.43
unknownUnited Kingdom
41231CANONICAL-ASGBfalse
91.189.91.42
unknownUnited Kingdom
41231CANONICAL-ASGBfalse


Runtime Messages

Command:/tmp/3tgXa7CGc1
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:

Standard Error:

Joe Sandbox View / Context

IPs

MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
45.95.169.120rijsTqU0IfGet hashmaliciousBrowse
    csB31kWt10Get hashmaliciousBrowse
      QWg2NTuodYGet hashmaliciousBrowse
        SL92Sz9pl2Get hashmaliciousBrowse
          YpKL484IG5Get hashmaliciousBrowse
            Y4W4j5QIqDGet hashmaliciousBrowse
              1TnmkstVG8Get hashmaliciousBrowse
                iksM5QEg2jGet hashmaliciousBrowse
                  109.202.202.202rijsTqU0IfGet hashmaliciousBrowse
                    csB31kWt10Get hashmaliciousBrowse
                      QWg2NTuodYGet hashmaliciousBrowse
                        6VLeGqFkPSGet hashmaliciousBrowse
                          DL5blLw1lyGet hashmaliciousBrowse
                            SL92Sz9pl2Get hashmaliciousBrowse
                              YpKL484IG5Get hashmaliciousBrowse
                                Y4W4j5QIqDGet hashmaliciousBrowse
                                  1TnmkstVG8Get hashmaliciousBrowse
                                    iksM5QEg2jGet hashmaliciousBrowse
                                      lGJEkz80oeGet hashmaliciousBrowse
                                        roV7kGaVr1Get hashmaliciousBrowse
                                          SecuriteInfo.com.Linux.Siggen.4218.298.3210Get hashmaliciousBrowse
                                            uPOWBxniTAGet hashmaliciousBrowse
                                              qy5unieRgRGet hashmaliciousBrowse
                                                sAzPpn6mKZGet hashmaliciousBrowse
                                                  AxadDC89j9Get hashmaliciousBrowse
                                                    ZErnXU2XR1Get hashmaliciousBrowse
                                                      sTHJvS5LPJGet hashmaliciousBrowse
                                                        THzHjYQ4z6Get hashmaliciousBrowse
                                                          91.189.91.43rijsTqU0IfGet hashmaliciousBrowse
                                                            csB31kWt10Get hashmaliciousBrowse
                                                              QWg2NTuodYGet hashmaliciousBrowse
                                                                6VLeGqFkPSGet hashmaliciousBrowse
                                                                  DL5blLw1lyGet hashmaliciousBrowse
                                                                    SL92Sz9pl2Get hashmaliciousBrowse
                                                                      YpKL484IG5Get hashmaliciousBrowse
                                                                        Y4W4j5QIqDGet hashmaliciousBrowse
                                                                          1TnmkstVG8Get hashmaliciousBrowse
                                                                            iksM5QEg2jGet hashmaliciousBrowse
                                                                              lGJEkz80oeGet hashmaliciousBrowse
                                                                                roV7kGaVr1Get hashmaliciousBrowse
                                                                                  SecuriteInfo.com.Linux.Siggen.4218.298.3210Get hashmaliciousBrowse
                                                                                    uPOWBxniTAGet hashmaliciousBrowse
                                                                                      qy5unieRgRGet hashmaliciousBrowse
                                                                                        sAzPpn6mKZGet hashmaliciousBrowse
                                                                                          AxadDC89j9Get hashmaliciousBrowse
                                                                                            ZErnXU2XR1Get hashmaliciousBrowse
                                                                                              sTHJvS5LPJGet hashmaliciousBrowse
                                                                                                THzHjYQ4z6Get hashmaliciousBrowse
                                                                                                  91.189.91.42rijsTqU0IfGet hashmaliciousBrowse
                                                                                                    csB31kWt10Get hashmaliciousBrowse
                                                                                                      QWg2NTuodYGet hashmaliciousBrowse
                                                                                                        6VLeGqFkPSGet hashmaliciousBrowse
                                                                                                          DL5blLw1lyGet hashmaliciousBrowse
                                                                                                            SL92Sz9pl2Get hashmaliciousBrowse
                                                                                                              YpKL484IG5Get hashmaliciousBrowse
                                                                                                                Y4W4j5QIqDGet hashmaliciousBrowse
                                                                                                                  1TnmkstVG8Get hashmaliciousBrowse
                                                                                                                    iksM5QEg2jGet hashmaliciousBrowse
                                                                                                                      lGJEkz80oeGet hashmaliciousBrowse
                                                                                                                        roV7kGaVr1Get hashmaliciousBrowse
                                                                                                                          SecuriteInfo.com.Linux.Siggen.4218.298.3210Get hashmaliciousBrowse
                                                                                                                            uPOWBxniTAGet hashmaliciousBrowse
                                                                                                                              qy5unieRgRGet hashmaliciousBrowse
                                                                                                                                sAzPpn6mKZGet hashmaliciousBrowse
                                                                                                                                  AxadDC89j9Get hashmaliciousBrowse
                                                                                                                                    ZErnXU2XR1Get hashmaliciousBrowse
                                                                                                                                      sTHJvS5LPJGet hashmaliciousBrowse
                                                                                                                                        THzHjYQ4z6Get hashmaliciousBrowse

                                                                                                                                          Domains

                                                                                                                                          No context

                                                                                                                                          ASN

                                                                                                                                          MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                                                                                                                                          CANONICAL-ASGBrijsTqU0IfGet hashmaliciousBrowse
                                                                                                                                          • 91.189.91.42
                                                                                                                                          csB31kWt10Get hashmaliciousBrowse
                                                                                                                                          • 91.189.91.42
                                                                                                                                          QWg2NTuodYGet hashmaliciousBrowse
                                                                                                                                          • 91.189.91.42
                                                                                                                                          6VLeGqFkPSGet hashmaliciousBrowse
                                                                                                                                          • 91.189.91.42
                                                                                                                                          DL5blLw1lyGet hashmaliciousBrowse
                                                                                                                                          • 91.189.91.42
                                                                                                                                          SL92Sz9pl2Get hashmaliciousBrowse
                                                                                                                                          • 91.189.91.42
                                                                                                                                          YpKL484IG5Get hashmaliciousBrowse
                                                                                                                                          • 91.189.91.42
                                                                                                                                          Y4W4j5QIqDGet hashmaliciousBrowse
                                                                                                                                          • 91.189.91.42
                                                                                                                                          1TnmkstVG8Get hashmaliciousBrowse
                                                                                                                                          • 91.189.91.42
                                                                                                                                          iksM5QEg2jGet hashmaliciousBrowse
                                                                                                                                          • 91.189.91.42
                                                                                                                                          lGJEkz80oeGet hashmaliciousBrowse
                                                                                                                                          • 91.189.91.42
                                                                                                                                          roV7kGaVr1Get hashmaliciousBrowse
                                                                                                                                          • 91.189.91.42
                                                                                                                                          SecuriteInfo.com.Linux.Siggen.4218.298.3210Get hashmaliciousBrowse
                                                                                                                                          • 91.189.91.42
                                                                                                                                          uPOWBxniTAGet hashmaliciousBrowse
                                                                                                                                          • 91.189.91.42
                                                                                                                                          qy5unieRgRGet hashmaliciousBrowse
                                                                                                                                          • 91.189.91.42
                                                                                                                                          sAzPpn6mKZGet hashmaliciousBrowse
                                                                                                                                          • 91.189.91.42
                                                                                                                                          AxadDC89j9Get hashmaliciousBrowse
                                                                                                                                          • 91.189.91.42
                                                                                                                                          ZErnXU2XR1Get hashmaliciousBrowse
                                                                                                                                          • 91.189.91.42
                                                                                                                                          sTHJvS5LPJGet hashmaliciousBrowse
                                                                                                                                          • 91.189.91.42
                                                                                                                                          THzHjYQ4z6Get hashmaliciousBrowse
                                                                                                                                          • 91.189.91.42
                                                                                                                                          CANONICAL-ASGBrijsTqU0IfGet hashmaliciousBrowse
                                                                                                                                          • 91.189.91.42
                                                                                                                                          csB31kWt10Get hashmaliciousBrowse
                                                                                                                                          • 91.189.91.42
                                                                                                                                          QWg2NTuodYGet hashmaliciousBrowse
                                                                                                                                          • 91.189.91.42
                                                                                                                                          6VLeGqFkPSGet hashmaliciousBrowse
                                                                                                                                          • 91.189.91.42
                                                                                                                                          DL5blLw1lyGet hashmaliciousBrowse
                                                                                                                                          • 91.189.91.42
                                                                                                                                          SL92Sz9pl2Get hashmaliciousBrowse
                                                                                                                                          • 91.189.91.42
                                                                                                                                          YpKL484IG5Get hashmaliciousBrowse
                                                                                                                                          • 91.189.91.42
                                                                                                                                          Y4W4j5QIqDGet hashmaliciousBrowse
                                                                                                                                          • 91.189.91.42
                                                                                                                                          1TnmkstVG8Get hashmaliciousBrowse
                                                                                                                                          • 91.189.91.42
                                                                                                                                          iksM5QEg2jGet hashmaliciousBrowse
                                                                                                                                          • 91.189.91.42
                                                                                                                                          lGJEkz80oeGet hashmaliciousBrowse
                                                                                                                                          • 91.189.91.42
                                                                                                                                          roV7kGaVr1Get hashmaliciousBrowse
                                                                                                                                          • 91.189.91.42
                                                                                                                                          SecuriteInfo.com.Linux.Siggen.4218.298.3210Get hashmaliciousBrowse
                                                                                                                                          • 91.189.91.42
                                                                                                                                          uPOWBxniTAGet hashmaliciousBrowse
                                                                                                                                          • 91.189.91.42
                                                                                                                                          qy5unieRgRGet hashmaliciousBrowse
                                                                                                                                          • 91.189.91.42
                                                                                                                                          sAzPpn6mKZGet hashmaliciousBrowse
                                                                                                                                          • 91.189.91.42
                                                                                                                                          AxadDC89j9Get hashmaliciousBrowse
                                                                                                                                          • 91.189.91.42
                                                                                                                                          ZErnXU2XR1Get hashmaliciousBrowse
                                                                                                                                          • 91.189.91.42
                                                                                                                                          sTHJvS5LPJGet hashmaliciousBrowse
                                                                                                                                          • 91.189.91.42
                                                                                                                                          THzHjYQ4z6Get hashmaliciousBrowse
                                                                                                                                          • 91.189.91.42
                                                                                                                                          GIGANET-HUGigaNetInternetServiceProviderCoHUrijsTqU0IfGet hashmaliciousBrowse
                                                                                                                                          • 45.95.169.120
                                                                                                                                          csB31kWt10Get hashmaliciousBrowse
                                                                                                                                          • 45.95.169.120
                                                                                                                                          QWg2NTuodYGet hashmaliciousBrowse
                                                                                                                                          • 45.95.169.120
                                                                                                                                          SL92Sz9pl2Get hashmaliciousBrowse
                                                                                                                                          • 45.95.169.120
                                                                                                                                          YpKL484IG5Get hashmaliciousBrowse
                                                                                                                                          • 45.95.169.120
                                                                                                                                          Y4W4j5QIqDGet hashmaliciousBrowse
                                                                                                                                          • 45.95.169.120
                                                                                                                                          1TnmkstVG8Get hashmaliciousBrowse
                                                                                                                                          • 45.95.169.120
                                                                                                                                          iksM5QEg2jGet hashmaliciousBrowse
                                                                                                                                          • 45.95.169.120
                                                                                                                                          RicwIfIHLKGet hashmaliciousBrowse
                                                                                                                                          • 45.95.169.115
                                                                                                                                          aIY7AxjUMcGet hashmaliciousBrowse
                                                                                                                                          • 45.95.169.115
                                                                                                                                          DtJmFQxtNCGet hashmaliciousBrowse
                                                                                                                                          • 45.95.169.115
                                                                                                                                          Wm4CzOCmNYGet hashmaliciousBrowse
                                                                                                                                          • 45.95.169.115
                                                                                                                                          vunWUzXJvCGet hashmaliciousBrowse
                                                                                                                                          • 45.95.169.115
                                                                                                                                          52xhBHy9WzGet hashmaliciousBrowse
                                                                                                                                          • 45.95.169.115
                                                                                                                                          YGvwG0iCDEGet hashmaliciousBrowse
                                                                                                                                          • 45.95.169.115
                                                                                                                                          dbd5O0RUTqGet hashmaliciousBrowse
                                                                                                                                          • 45.95.169.115
                                                                                                                                          fHVDVj0pzOGet hashmaliciousBrowse
                                                                                                                                          • 45.95.169.115
                                                                                                                                          eZPk7Fg5w7Get hashmaliciousBrowse
                                                                                                                                          • 45.95.169.115
                                                                                                                                          ph5PjoFBpjGet hashmaliciousBrowse
                                                                                                                                          • 45.95.169.115
                                                                                                                                          xugAk5haatGet hashmaliciousBrowse
                                                                                                                                          • 45.95.169.115
                                                                                                                                          INIT7CHrijsTqU0IfGet hashmaliciousBrowse
                                                                                                                                          • 109.202.202.202
                                                                                                                                          csB31kWt10Get hashmaliciousBrowse
                                                                                                                                          • 109.202.202.202
                                                                                                                                          QWg2NTuodYGet hashmaliciousBrowse
                                                                                                                                          • 109.202.202.202
                                                                                                                                          6VLeGqFkPSGet hashmaliciousBrowse
                                                                                                                                          • 109.202.202.202
                                                                                                                                          DL5blLw1lyGet hashmaliciousBrowse
                                                                                                                                          • 109.202.202.202
                                                                                                                                          SL92Sz9pl2Get hashmaliciousBrowse
                                                                                                                                          • 109.202.202.202
                                                                                                                                          YpKL484IG5Get hashmaliciousBrowse
                                                                                                                                          • 109.202.202.202
                                                                                                                                          Y4W4j5QIqDGet hashmaliciousBrowse
                                                                                                                                          • 109.202.202.202
                                                                                                                                          1TnmkstVG8Get hashmaliciousBrowse
                                                                                                                                          • 109.202.202.202
                                                                                                                                          iksM5QEg2jGet hashmaliciousBrowse
                                                                                                                                          • 109.202.202.202
                                                                                                                                          lGJEkz80oeGet hashmaliciousBrowse
                                                                                                                                          • 109.202.202.202
                                                                                                                                          roV7kGaVr1Get hashmaliciousBrowse
                                                                                                                                          • 109.202.202.202
                                                                                                                                          SecuriteInfo.com.Linux.Siggen.4218.298.3210Get hashmaliciousBrowse
                                                                                                                                          • 109.202.202.202
                                                                                                                                          uPOWBxniTAGet hashmaliciousBrowse
                                                                                                                                          • 109.202.202.202
                                                                                                                                          qy5unieRgRGet hashmaliciousBrowse
                                                                                                                                          • 109.202.202.202
                                                                                                                                          sAzPpn6mKZGet hashmaliciousBrowse
                                                                                                                                          • 109.202.202.202
                                                                                                                                          AxadDC89j9Get hashmaliciousBrowse
                                                                                                                                          • 109.202.202.202
                                                                                                                                          ZErnXU2XR1Get hashmaliciousBrowse
                                                                                                                                          • 109.202.202.202
                                                                                                                                          sTHJvS5LPJGet hashmaliciousBrowse
                                                                                                                                          • 109.202.202.202
                                                                                                                                          THzHjYQ4z6Get hashmaliciousBrowse
                                                                                                                                          • 109.202.202.202

                                                                                                                                          JA3 Fingerprints

                                                                                                                                          No context

                                                                                                                                          Dropped Files

                                                                                                                                          No context

                                                                                                                                          Created / dropped Files

                                                                                                                                          No created / dropped files found

                                                                                                                                          Static File Info

                                                                                                                                          General

                                                                                                                                          File type:ELF 32-bit MSB executable, MIPS, MIPS-I version 1 (SYSV), statically linked, stripped
                                                                                                                                          Entropy (8bit):5.51303684741125
                                                                                                                                          TrID:
                                                                                                                                          • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                                                                                                                                          File name:3tgXa7CGc1
                                                                                                                                          File size:40824
                                                                                                                                          MD5:3ca11c21956b7c6a03ef4f48698c209e
                                                                                                                                          SHA1:d26f991c4df35a746a324129f588601fc105fd18
                                                                                                                                          SHA256:ddfb21fd0f3589e3ecf1421d65941a8ff85e0e324e2b2149ce67e26727c5c97f
                                                                                                                                          SHA512:e49f2110dc9ec4867ac9962aea7eb1e8d814d45a143341873bacdd40588a3db975bbdc7f545cd546c1bc4477bffd721322fc2ccbb370154c698b081241433a2e
                                                                                                                                          SSDEEP:768:nsILLLLLLLLiBnHd/lWMBYacrctZ2dqCUwr6ruD:Wbcdzr3
                                                                                                                                          File Content Preview:.ELF.....................@.`...4...p.....4. ...(.............@...@...........................D...D.....D..%8........dt.Q............................<...'..L...!'.......................<...'..(...!... ....'9... ......................<...'......!... ....'9~

                                                                                                                                          Static ELF Info

                                                                                                                                          ELF header

                                                                                                                                          Class:ELF32
                                                                                                                                          Data:2's complement, big endian
                                                                                                                                          Version:1 (current)
                                                                                                                                          Machine:MIPS R3000
                                                                                                                                          Version Number:0x1
                                                                                                                                          Type:EXEC (Executable file)
                                                                                                                                          OS/ABI:UNIX - System V
                                                                                                                                          ABI Version:0
                                                                                                                                          Entry Point Address:0x400260
                                                                                                                                          Flags:0x1007
                                                                                                                                          ELF Header Size:52
                                                                                                                                          Program Header Offset:52
                                                                                                                                          Program Header Size:32
                                                                                                                                          Number of Program Headers:3
                                                                                                                                          Section Header Offset:40304
                                                                                                                                          Section Header Size:40
                                                                                                                                          Number of Section Headers:13
                                                                                                                                          Header String Table Index:12

                                                                                                                                          Sections

                                                                                                                                          NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                                                                                                                          NULL0x00x00x00x00x0000
                                                                                                                                          .initPROGBITS0x4000940x940x8c0x00x6AX004
                                                                                                                                          .textPROGBITS0x4001200x1200x7e100x00x6AX0016
                                                                                                                                          .finiPROGBITS0x407f300x7f300x5c0x00x6AX004
                                                                                                                                          .rodataPROGBITS0x407f900x7f900x6400x00x2A0016
                                                                                                                                          .ctorsPROGBITS0x4485d40x85d40x80x00x3WA004
                                                                                                                                          .dtorsPROGBITS0x4485dc0x85dc0x80x00x3WA004
                                                                                                                                          .dataPROGBITS0x4485f00x85f00x14000x00x3WA0016
                                                                                                                                          .gotPROGBITS0x4499f00x99f00x3280x40x10000003WA0016
                                                                                                                                          .sbssNOBITS0x449d180x9d180x180x00x10000003WA004
                                                                                                                                          .bssNOBITS0x449d300x9d180xddc0x00x3WA0016
                                                                                                                                          .mdebug.abi32PROGBITS0x5b20x9d180x00x00x0001
                                                                                                                                          .shstrtabSTRTAB0x00x9d180x570x00x0001

                                                                                                                                          Program Segments

                                                                                                                                          TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                                                                                                          LOAD0x00x4000000x4000000x85d00x85d03.14100x5R E0x10000.init .text .fini .rodata
                                                                                                                                          LOAD0x85d40x4485d40x4485d40x17440x25382.10590x6RW 0x10000.ctors .dtors .data .got .sbss .bss
                                                                                                                                          GNU_STACK0x00x00x00x00x00.00000x7RWE0x4

                                                                                                                                          Network Behavior

                                                                                                                                          Network Port Distribution

                                                                                                                                          TCP Packets

                                                                                                                                          TimestampSource PortDest PortSource IPDest IP
                                                                                                                                          Oct 29, 2021 09:45:39.109786987 CEST56596455192.168.2.2345.95.169.120
                                                                                                                                          Oct 29, 2021 09:45:39.143711090 CEST4555659645.95.169.120192.168.2.23
                                                                                                                                          Oct 29, 2021 09:45:41.589173079 CEST42836443192.168.2.2391.189.91.43
                                                                                                                                          Oct 29, 2021 09:45:42.357373953 CEST4251680192.168.2.23109.202.202.202
                                                                                                                                          Oct 29, 2021 09:45:44.144357920 CEST56598455192.168.2.2345.95.169.120
                                                                                                                                          Oct 29, 2021 09:45:45.172996044 CEST56598455192.168.2.2345.95.169.120
                                                                                                                                          Oct 29, 2021 09:45:47.188868999 CEST56598455192.168.2.2345.95.169.120
                                                                                                                                          Oct 29, 2021 09:45:51.316535950 CEST56598455192.168.2.2345.95.169.120
                                                                                                                                          Oct 29, 2021 09:45:56.948025942 CEST43928443192.168.2.2391.189.91.42
                                                                                                                                          Oct 29, 2021 09:45:59.507862091 CEST56598455192.168.2.2345.95.169.120
                                                                                                                                          Oct 29, 2021 09:46:07.187310934 CEST42836443192.168.2.2391.189.91.43
                                                                                                                                          Oct 29, 2021 09:46:13.330899000 CEST4251680192.168.2.23109.202.202.202
                                                                                                                                          Oct 29, 2021 09:46:15.634732008 CEST56598455192.168.2.2345.95.169.120
                                                                                                                                          Oct 29, 2021 09:46:37.905170918 CEST43928443192.168.2.2391.189.91.42
                                                                                                                                          Oct 29, 2021 09:46:48.144355059 CEST56598455192.168.2.2345.95.169.120
                                                                                                                                          Oct 29, 2021 09:46:48.178010941 CEST4555659845.95.169.120192.168.2.23
                                                                                                                                          Oct 29, 2021 09:46:53.178486109 CEST56600455192.168.2.2345.95.169.120
                                                                                                                                          Oct 29, 2021 09:46:53.212130070 CEST4555660045.95.169.120192.168.2.23
                                                                                                                                          Oct 29, 2021 09:46:58.212428093 CEST56602455192.168.2.2345.95.169.120
                                                                                                                                          Oct 29, 2021 09:46:58.383584023 CEST42836443192.168.2.2391.189.91.43
                                                                                                                                          Oct 29, 2021 09:46:59.215594053 CEST56602455192.168.2.2345.95.169.120
                                                                                                                                          Oct 29, 2021 09:47:01.231421947 CEST56602455192.168.2.2345.95.169.120
                                                                                                                                          Oct 29, 2021 09:47:01.264568090 CEST4555660245.95.169.120192.168.2.23
                                                                                                                                          Oct 29, 2021 09:47:06.264934063 CEST56606455192.168.2.2345.95.169.120
                                                                                                                                          Oct 29, 2021 09:47:06.299184084 CEST4555660645.95.169.120192.168.2.23
                                                                                                                                          Oct 29, 2021 09:47:11.299403906 CEST56608455192.168.2.2345.95.169.120
                                                                                                                                          Oct 29, 2021 09:47:12.302715063 CEST56608455192.168.2.2345.95.169.120
                                                                                                                                          Oct 29, 2021 09:47:12.345128059 CEST4555660845.95.169.120192.168.2.23

                                                                                                                                          System Behavior

                                                                                                                                          General

                                                                                                                                          Start time:09:45:38
                                                                                                                                          Start date:29/10/2021
                                                                                                                                          Path:/tmp/3tgXa7CGc1
                                                                                                                                          Arguments:/tmp/3tgXa7CGc1
                                                                                                                                          File size:5777432 bytes
                                                                                                                                          MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                                                                                                                                          General

                                                                                                                                          Start time:09:45:38
                                                                                                                                          Start date:29/10/2021
                                                                                                                                          Path:/tmp/3tgXa7CGc1
                                                                                                                                          Arguments:n/a
                                                                                                                                          File size:5777432 bytes
                                                                                                                                          MD5 hash:0083f1f0e77be34ad27f849842bbb00c