Loading ...

Play interactive tourEdit tour

Linux Analysis Report sora.mips

Overview

General Information

Sample Name:sora.mips
Analysis ID:513591
MD5:f541ee6ca94d92d5c8da35fce228bb46
SHA1:46100ebb28ef32d9895277b26db0705cdb4a5729
SHA256:119853ec87c7bc15674fa8beaf375979d963c5fd763d08a32ef555041e053d04
Infos:

Most interesting Screenshot:

Detection

Mirai
Score:68
Range:0 - 100
Whitelisted:false

Signatures

Snort IDS alert for network traffic (e.g. based on Emerging Threat rules)
Yara detected Mirai
Multi AV Scanner detection for submitted file
Sample tries to kill many processes (SIGKILL)
Sample has stripped symbol table
Uses the "uname" system call to query kernel version information (possible evasion)
Enumerates processes within the "proc" file system
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Detected TCP or UDP traffic on non-standard ports
Sample listens on a socket
Sample tries to kill a process (SIGKILL)

Classification

Analysis Advice

Static ELF header machine description suggests that the sample might only run correctly on MIPS or ARM architectures
All HTTP servers contacted by the sample do not answer. Likely the sample is an old dropper which does no longer work
Static ELF header machine description suggests that the sample might not execute correctly on this machine

General Information

Joe Sandbox Version:34.0.0 Boulder Opal
Analysis ID:513591
Start date:02.11.2021
Start time:11:17:27
Joe Sandbox Product:CloudBasic
Overall analysis duration:0h 6m 50s
Hypervisor based Inspection enabled:false
Report type:light
Sample file name:sora.mips
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Detection:MAL
Classification:mal68.spre.troj.linMIPS@0/6@0/0
Warnings:
Show All
  • Report size exceeded maximum capacity and may have missing network information.
  • TCP Packets have been reduced to 100

Process Tree

  • system is lnxubuntu20
  • sora.mips (PID: 5235, Parent: 5111, MD5: 0083f1f0e77be34ad27f849842bbb00c) Arguments: /tmp/sora.mips
  • systemd New Fork (PID: 5275, Parent: 1)
  • sshd (PID: 5275, Parent: 1, MD5: dbca7a6bbf7bf57fedac243d4b2cb340) Arguments: /usr/sbin/sshd -t
  • systemd New Fork (PID: 5276, Parent: 1)
  • sshd (PID: 5276, Parent: 1, MD5: dbca7a6bbf7bf57fedac243d4b2cb340) Arguments: /usr/sbin/sshd -D
  • systemd New Fork (PID: 5386, Parent: 1)
  • sshd (PID: 5386, Parent: 1, MD5: dbca7a6bbf7bf57fedac243d4b2cb340) Arguments: /usr/sbin/sshd -t
  • systemd New Fork (PID: 5387, Parent: 1)
  • sshd (PID: 5387, Parent: 1, MD5: dbca7a6bbf7bf57fedac243d4b2cb340) Arguments: /usr/sbin/sshd -D
  • systemd New Fork (PID: 5390, Parent: 1)
  • sshd (PID: 5390, Parent: 1, MD5: dbca7a6bbf7bf57fedac243d4b2cb340) Arguments: /usr/sbin/sshd -t
  • systemd New Fork (PID: 5391, Parent: 1)
  • sshd (PID: 5391, Parent: 1, MD5: dbca7a6bbf7bf57fedac243d4b2cb340) Arguments: /usr/sbin/sshd -D
  • cleanup

Yara Overview

PCAP (Network Traffic)

SourceRuleDescriptionAuthorStrings
dump.pcapJoeSecurity_Mirai_12Yara detected MiraiJoe Security

    Jbx Signature Overview

    Click to jump to signature section

    Show All Signature Results

    AV Detection:

    barindex
    Multi AV Scanner detection for submitted fileShow sources
    Source: sora.mipsVirustotal: Detection: 52%Perma Link
    Source: sora.mipsReversingLabs: Detection: 55%

    Networking:

    barindex
    Snort IDS alert for network traffic (e.g. based on Emerging Threat rules)Show sources
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 177.0.18.97:23 -> 192.168.2.23:38638
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 121.156.14.197:23 -> 192.168.2.23:36356
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 121.156.14.197:23 -> 192.168.2.23:36356
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 177.0.18.97:23 -> 192.168.2.23:38670
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 78.109.52.50:23 -> 192.168.2.23:57802
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 78.109.52.50:23 -> 192.168.2.23:57804
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 78.109.52.50:23 -> 192.168.2.23:57808
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 78.109.52.50:23 -> 192.168.2.23:57810
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 78.109.52.50:23 -> 192.168.2.23:57814
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 177.0.18.97:23 -> 192.168.2.23:38692
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 78.109.52.50:23 -> 192.168.2.23:57820
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 78.109.52.50:23 -> 192.168.2.23:57822
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 78.109.52.50:23 -> 192.168.2.23:57826
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 78.109.52.50:23 -> 192.168.2.23:57830
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 78.109.52.50:23 -> 192.168.2.23:57840
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 177.0.18.97:23 -> 192.168.2.23:38716
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 177.0.18.97:23 -> 192.168.2.23:38724
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 121.156.14.197:23 -> 192.168.2.23:36442
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 121.156.14.197:23 -> 192.168.2.23:36442
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 124.253.26.49:23 -> 192.168.2.23:45454
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 177.0.18.97:23 -> 192.168.2.23:38754
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 66.83.255.25:23 -> 192.168.2.23:34618
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 177.0.18.97:23 -> 192.168.2.23:38764
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 78.108.27.246:23 -> 192.168.2.23:34832
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 177.0.18.97:23 -> 192.168.2.23:38820
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 177.0.18.97:23 -> 192.168.2.23:38838
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 121.156.14.197:23 -> 192.168.2.23:36554
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 121.156.14.197:23 -> 192.168.2.23:36554
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 177.0.18.97:23 -> 192.168.2.23:38870
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 208.69.187.191:23 -> 192.168.2.23:36352
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 208.69.187.191:23 -> 192.168.2.23:36352
    Source: TrafficSnort IDS: 716 INFO TELNET access 211.247.70.50:23 -> 192.168.2.23:44494
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 66.83.255.25:23 -> 192.168.2.23:34752
    Source: TrafficSnort IDS: 716 INFO TELNET access 190.193.255.54:23 -> 192.168.2.23:35734
    Source: TrafficSnort IDS: 716 INFO TELNET access 41.33.70.89:23 -> 192.168.2.23:52610
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 190.193.255.54:23 -> 192.168.2.23:35734
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 190.193.255.54:23 -> 192.168.2.23:35734
    Source: TrafficSnort IDS: 2023448 ET TROJAN Possible Linux.Mirai Login Attempt (ubnt) 192.168.2.23:44354 -> 186.7.99.184:23
    Source: TrafficSnort IDS: 716 INFO TELNET access 190.193.255.54:23 -> 192.168.2.23:35800
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 190.193.255.54:23 -> 192.168.2.23:35800
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 190.193.255.54:23 -> 192.168.2.23:35800
    Source: global trafficTCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
    Source: global trafficTCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
    Source: global trafficTCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
    Source: global trafficTCP traffic: 192.168.2.23:39692 -> 20.151.141.34:1312
    Source: /tmp/sora.mips (PID: 5237)Socket: 0.0.0.0::0
    Source: /tmp/sora.mips (PID: 5237)Socket: 0.0.0.0::23
    Source: /tmp/sora.mips (PID: 5237)Socket: 0.0.0.0::53413
    Source: /tmp/sora.mips (PID: 5237)Socket: 0.0.0.0::80
    Source: /tmp/sora.mips (PID: 5237)Socket: 0.0.0.0::52869
    Source: /tmp/sora.mips (PID: 5237)Socket: 0.0.0.0::37215
    Source: /tmp/sora.mips (PID: 5243)Socket: 0.0.0.0::22
    Source: /tmp/sora.mips (PID: 5243)Socket: 0.0.0.0::23
    Source: /tmp/sora.mips (PID: 5243)Socket: 0.0.0.0::53413
    Source: /tmp/sora.mips (PID: 5243)Socket: 0.0.0.0::80
    Source: /tmp/sora.mips (PID: 5243)Socket: 0.0.0.0::52869
    Source: /tmp/sora.mips (PID: 5243)Socket: 0.0.0.0::37215
    Source: /usr/sbin/sshd (PID: 5276)Socket: [::]::22
    Source: /usr/sbin/sshd (PID: 5387)Socket: 0.0.0.0::22
    Source: /usr/sbin/sshd (PID: 5387)Socket: [::]::22
    Source: /usr/sbin/sshd (PID: 5391)Socket: 0.0.0.0::22
    Source: /usr/sbin/sshd (PID: 5391)Socket: [::]::22
    Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443
    Source: unknownTCP traffic detected without corresponding DNS query: 20.151.141.34
    Source: unknownTCP traffic detected without corresponding DNS query: 92.125.81.222
    Source: unknownTCP traffic detected without corresponding DNS query: 206.23.56.222
    Source: unknownTCP traffic detected without corresponding DNS query: 81.250.245.60
    Source: unknownTCP traffic detected without corresponding DNS query: 178.224.11.107
    Source: unknownTCP traffic detected without corresponding DNS query: 152.177.176.172
    Source: unknownTCP traffic detected without corresponding DNS query: 107.158.11.21
    Source: unknownTCP traffic detected without corresponding DNS query: 218.56.128.93
    Source: unknownTCP traffic detected without corresponding DNS query: 36.16.231.114
    Source: unknownTCP traffic detected without corresponding DNS query: 252.125.147.157
    Source: unknownTCP traffic detected without corresponding DNS query: 177.173.219.179
    Source: unknownTCP traffic detected without corresponding DNS query: 113.230.45.131
    Source: unknownTCP traffic detected without corresponding DNS query: 27.212.249.70
    Source: unknownTCP traffic detected without corresponding DNS query: 23.26.195.206
    Source: unknownTCP traffic detected without corresponding DNS query: 167.60.218.239
    Source: unknownTCP traffic detected without corresponding DNS query: 170.103.202.249
    Source: unknownTCP traffic detected without corresponding DNS query: 42.33.237.121
    Source: unknownTCP traffic detected without corresponding DNS query: 125.216.198.116
    Source: unknownTCP traffic detected without corresponding DNS query: 106.132.143.186
    Source: unknownTCP traffic detected without corresponding DNS query: 46.66.157.206
    Source: unknownTCP traffic detected without corresponding DNS query: 241.158.158.122
    Source: unknownTCP traffic detected without corresponding DNS query: 88.230.66.254
    Source: unknownTCP traffic detected without corresponding DNS query: 20.89.229.159
    Source: unknownTCP traffic detected without corresponding DNS query: 168.255.195.10
    Source: unknownTCP traffic detected without corresponding DNS query: 135.141.217.112
    Source: unknownTCP traffic detected without corresponding DNS query: 124.86.186.137
    Source: unknownTCP traffic detected without corresponding DNS query: 92.147.222.83
    Source: unknownTCP traffic detected without corresponding DNS query: 122.238.207.126
    Source: unknownTCP traffic detected without corresponding DNS query: 200.26.216.73
    Source: unknownTCP traffic detected without corresponding DNS query: 41.20.159.169
    Source: unknownTCP traffic detected without corresponding DNS query: 144.73.8.159
    Source: unknownTCP traffic detected without corresponding DNS query: 223.54.253.28
    Source: unknownTCP traffic detected without corresponding DNS query: 243.230.107.3
    Source: unknownTCP traffic detected without corresponding DNS query: 250.44.241.30
    Source: unknownTCP traffic detected without corresponding DNS query: 150.198.177.166
    Source: unknownTCP traffic detected without corresponding DNS query: 119.123.69.154
    Source: unknownTCP traffic detected without corresponding DNS query: 121.241.205.167
    Source: unknownTCP traffic detected without corresponding DNS query: 249.135.121.55
    Source: unknownTCP traffic detected without corresponding DNS query: 44.219.36.33
    Source: unknownTCP traffic detected without corresponding DNS query: 139.22.168.95
    Source: unknownTCP traffic detected without corresponding DNS query: 166.149.131.138
    Source: unknownTCP traffic detected without corresponding DNS query: 62.195.100.65
    Source: unknownTCP traffic detected without corresponding DNS query: 133.221.246.82
    Source: unknownTCP traffic detected without corresponding DNS query: 199.11.56.87
    Source: unknownTCP traffic detected without corresponding DNS query: 95.250.78.5
    Source: unknownTCP traffic detected without corresponding DNS query: 217.139.56.209
    Source: unknownTCP traffic detected without corresponding DNS query: 23.195.178.190
    Source: unknownTCP traffic detected without corresponding DNS query: 151.88.121.184
    Source: unknownTCP traffic detected without corresponding DNS query: 95.178.152.69
    Source: unknownTCP traffic detected without corresponding DNS query: 172.186.225.86

    System Summary:

    barindex
    Sample tries to kill many processes (SIGKILL)Show sources
    Source: /tmp/sora.mips (PID: 5237)SIGKILL sent: pid: 936, result: successful
    Source: /tmp/sora.mips (PID: 5237)SIGKILL sent: pid: 5243, result: successful
    Source: /tmp/sora.mips (PID: 5237)SIGKILL sent: pid: 720, result: successful
    Source: /tmp/sora.mips (PID: 5237)SIGKILL sent: pid: 759, result: successful
    Source: /tmp/sora.mips (PID: 5237)SIGKILL sent: pid: 788, result: successful
    Source: /tmp/sora.mips (PID: 5237)SIGKILL sent: pid: 800, result: successful
    Source: /tmp/sora.mips (PID: 5237)SIGKILL sent: pid: 847, result: successful
    Source: /tmp/sora.mips (PID: 5237)SIGKILL sent: pid: 884, result: successful
    Source: /tmp/sora.mips (PID: 5237)SIGKILL sent: pid: 1334, result: successful
    Source: /tmp/sora.mips (PID: 5237)SIGKILL sent: pid: 1335, result: successful
    Source: /tmp/sora.mips (PID: 5237)SIGKILL sent: pid: 1872, result: successful
    Source: /tmp/sora.mips (PID: 5237)SIGKILL sent: pid: 2096, result: successful
    Source: /tmp/sora.mips (PID: 5237)SIGKILL sent: pid: 2097, result: successful
    Source: /tmp/sora.mips (PID: 5237)SIGKILL sent: pid: 2102, result: successful
    Source: /tmp/sora.mips (PID: 5237)SIGKILL sent: pid: 2180, result: successful
    Source: /tmp/sora.mips (PID: 5237)SIGKILL sent: pid: 2191, result: successful
    Source: /tmp/sora.mips (PID: 5237)SIGKILL sent: pid: 2208, result: successful
    Source: /tmp/sora.mips (PID: 5237)SIGKILL sent: pid: 2275, result: successful
    Source: /tmp/sora.mips (PID: 5237)SIGKILL sent: pid: 2281, result: successful
    Source: /tmp/sora.mips (PID: 5237)SIGKILL sent: pid: 2285, result: successful
    Source: /tmp/sora.mips (PID: 5237)SIGKILL sent: pid: 2289, result: successful
    Source: /tmp/sora.mips (PID: 5237)SIGKILL sent: pid: 2294, result: successful
    Source: /tmp/sora.mips (PID: 5237)SIGKILL sent: pid: 5239, result: successful
    Source: /tmp/sora.mips (PID: 5237)SIGKILL sent: pid: 5247, result: successful
    Source: /tmp/sora.mips (PID: 5237)SIGKILL sent: pid: 5276, result: successful
    Source: /tmp/sora.mips (PID: 5237)SIGKILL sent: pid: 5387, result: successful
    Source: /tmp/sora.mips (PID: 5237)SIGKILL sent: pid: 5237, result: unknown
    Source: ELF static info symbol of initial sample.symtab present: no
    Source: /tmp/sora.mips (PID: 5237)SIGKILL sent: pid: 936, result: successful
    Source: /tmp/sora.mips (PID: 5237)SIGKILL sent: pid: 5243, result: successful
    Source: /tmp/sora.mips (PID: 5237)SIGKILL sent: pid: 720, result: successful
    Source: /tmp/sora.mips (PID: 5237)SIGKILL sent: pid: 759, result: successful
    Source: /tmp/sora.mips (PID: 5237)SIGKILL sent: pid: 788, result: successful
    Source: /tmp/sora.mips (PID: 5237)SIGKILL sent: pid: 800, result: successful
    Source: /tmp/sora.mips (PID: 5237)SIGKILL sent: pid: 847, result: successful
    Source: /tmp/sora.mips (PID: 5237)SIGKILL sent: pid: 884, result: successful
    Source: /tmp/sora.mips (PID: 5237)SIGKILL sent: pid: 1334, result: successful
    Source: /tmp/sora.mips (PID: 5237)SIGKILL sent: pid: 1335, result: successful
    Source: /tmp/sora.mips (PID: 5237)SIGKILL sent: pid: 1872, result: successful
    Source: /tmp/sora.mips (PID: 5237)SIGKILL sent: pid: 2096, result: successful
    Source: /tmp/sora.mips (PID: 5237)SIGKILL sent: pid: 2097, result: successful
    Source: /tmp/sora.mips (PID: 5237)SIGKILL sent: pid: 2102, result: successful
    Source: /tmp/sora.mips (PID: 5237)SIGKILL sent: pid: 2180, result: successful
    Source: /tmp/sora.mips (PID: 5237)SIGKILL sent: pid: 2191, result: successful
    Source: /tmp/sora.mips (PID: 5237)SIGKILL sent: pid: 2208, result: successful
    Source: /tmp/sora.mips (PID: 5237)SIGKILL sent: pid: 2275, result: successful
    Source: /tmp/sora.mips (PID: 5237)SIGKILL sent: pid: 2281, result: successful
    Source: /tmp/sora.mips (PID: 5237)SIGKILL sent: pid: 2285, result: successful
    Source: /tmp/sora.mips (PID: 5237)SIGKILL sent: pid: 2289, result: successful
    Source: /tmp/sora.mips (PID: 5237)SIGKILL sent: pid: 2294, result: successful
    Source: /tmp/sora.mips (PID: 5237)SIGKILL sent: pid: 5239, result: successful
    Source: /tmp/sora.mips (PID: 5237)SIGKILL sent: pid: 5247, result: successful
    Source: /tmp/sora.mips (PID: 5237)SIGKILL sent: pid: 5276, result: successful
    Source: /tmp/sora.mips (PID: 5237)SIGKILL sent: pid: 5387, result: successful
    Source: /tmp/sora.mips (PID: 5237)SIGKILL sent: pid: 5237, result: unknown
    Source: classification engineClassification label: mal68.spre.troj.linMIPS@0/6@0/0
    Source: sora.mipsJoe Sandbox Cloud Basic: Detection: clean Score: 0Perma Link
    Source: /tmp/sora.mips (PID: 5237)File opened: /proc/5387/fd
    Source: /tmp/sora.mips (PID: 5237)File opened: /proc/2033/fd
    Source: /tmp/sora.mips (PID: 5237)File opened: /proc/2033/exe
    Source: /tmp/sora.mips (PID: 5237)File opened: /proc/2033/fd
    Source: /tmp/sora.mips (PID: 5237)File opened: /proc/2033/fd
    Source: /tmp/sora.mips (PID: 5237)File opened: /proc/1582/fd
    Source: /tmp/sora.mips (PID: 5237)File opened: /proc/1582/exe
    Source: /tmp/sora.mips (PID: 5237)File opened: /proc/1582/fd
    Source: /tmp/sora.mips (PID: 5237)File opened: /proc/1582/fd
    Source: /tmp/sora.mips (PID: 5237)File opened: /proc/2275/fd
    Source: /tmp/sora.mips (PID: 5237)File opened: /proc/2275/exe
    Source: /tmp/sora.mips (PID: 5237)File opened: /proc/3088/exe
    Source: /tmp/sora.mips (PID: 5237)File opened: /proc/1612/fd
    Source: /tmp/sora.mips (PID: 5237)File opened: /proc/1612/exe
    Source: /tmp/sora.mips (PID: 5237)File opened: /proc/1612/fd
    Source: /tmp/sora.mips (PID: 5237)File opened: /proc/1612/fd
    Source: /tmp/sora.mips (PID: 5237)File opened: /proc/1579/fd
    Source: /tmp/sora.mips (PID: 5237)File opened: /proc/1579/exe
    Source: /tmp/sora.mips (PID: 5237)File opened: /proc/1579/fd
    Source: /tmp/sora.mips (PID: 5237)File opened: /proc/1579/fd
    Source: /tmp/sora.mips (PID: 5237)File opened: /proc/1699/fd
    Source: /tmp/sora.mips (PID: 5237)File opened: /proc/1699/exe
    Source: /tmp/sora.mips (PID: 5237)File opened: /proc/1699/fd
    Source: /tmp/sora.mips (PID: 5237)File opened: /proc/1699/fd
    Source: /tmp/sora.mips (PID: 5237)File opened: /proc/1335/fd
    Source: /tmp/sora.mips (PID: 5237)File opened: /proc/1335/exe
    Source: /tmp/sora.mips (PID: 5237)File opened: /proc/1698/fd
    Source: /tmp/sora.mips (PID: 5237)File opened: /proc/1698/exe
    Source: /tmp/sora.mips (PID: 5237)File opened: /proc/1698/fd
    Source: /tmp/sora.mips (PID: 5237)File opened: /proc/1698/fd
    Source: /tmp/sora.mips (PID: 5237)File opened: /proc/2028/fd
    Source: /tmp/sora.mips (PID: 5237)File opened: /proc/2028/exe
    Source: /tmp/sora.mips (PID: 5237)File opened: /proc/2028/fd
    Source: /tmp/sora.mips (PID: 5237)File opened: /proc/2028/fd
    Source: /tmp/sora.mips (PID: 5237)File opened: /proc/1334/fd
    Source: /tmp/sora.mips (PID: 5237)File opened: /proc/1334/exe
    Source: /tmp/sora.mips (PID: 5237)File opened: /proc/1334/fd
    Source: /tmp/sora.mips (PID: 5237)File opened: /proc/1334/fd
    Source: /tmp/sora.mips (PID: 5237)File opened: /proc/1576/fd
    Source: /tmp/sora.mips (PID: 5237)File opened: /proc/1576/exe
    Source: /tmp/sora.mips (PID: 5237)File opened: /proc/1576/fd
    Source: /tmp/sora.mips (PID: 5237)File opened: /proc/1576/fd
    Source: /tmp/sora.mips (PID: 5237)File opened: /proc/2302/fd
    Source: /tmp/sora.mips (PID: 5237)File opened: /proc/2302/exe
    Source: /tmp/sora.mips (PID: 5237)File opened: /proc/2302/fd
    Source: /tmp/sora.mips (PID: 5237)File opened: /proc/2302/fd
    Source: /tmp/sora.mips (PID: 5237)File opened: /proc/3236/fd
    Source: /tmp/sora.mips (PID: 5237)File opened: /proc/3236/exe
    Source: /tmp/sora.mips (PID: 5237)File opened: /proc/3236/fd
    Source: /tmp/sora.mips (PID: 5237)File opened: /proc/3236/fd
    Source: /tmp/sora.mips (PID: 5237)File opened: /proc/2025/fd
    Source: /tmp/sora.mips (PID: 5237)File opened: /proc/2025/exe
    Source: /tmp/sora.mips (PID: 5237)File opened: /proc/2025/fd
    Source: /tmp/sora.mips (PID: 5237)File opened: /proc/2025/fd
    Source: /tmp/sora.mips (PID: 5237)File opened: /proc/2146/fd
    Source: /tmp/sora.mips (PID: 5237)File opened: /proc/2146/exe
    Source: /tmp/sora.mips (PID: 5237)File opened: /proc/2146/fd
    Source: /tmp/sora.mips (PID: 5237)File opened: /proc/2146/fd
    Source: /tmp/sora.mips (PID: 5237)File opened: /proc/910/exe
    Source: /tmp/sora.mips (PID: 5237)File opened: /proc/912/fd
    Source: /tmp/sora.mips (PID: 5237)File opened: /proc/912/fd
    Source: /tmp/sora.mips (PID: 5237)File opened: /proc/912/exe
    Source: /tmp/sora.mips (PID: 5237)File opened: /proc/912/fd
    Source: /tmp/sora.mips (PID: 5237)File opened: /proc/912/fd
    Source: /tmp/sora.mips (PID: 5237)File opened: /proc/5139/exe
    Source: /tmp/sora.mips (PID: 5237)File opened: /proc/759/fd
    Source: /tmp/sora.mips (PID: 5237)File opened: /proc/759/fd
    Source: /tmp/sora.mips (PID: 5237)File opened: /proc/759/exe
    Source: /tmp/sora.mips (PID: 5237)File opened: /proc/759/fd
    Source: /tmp/sora.mips (PID: 5237)File opened: /proc/759/fd
    Source: /tmp/sora.mips (PID: 5237)File opened: /proc/517/exe
    Source: /tmp/sora.mips (PID: 5237)File opened: /proc/2307/fd
    Source: /tmp/sora.mips (PID: 5237)File opened: /proc/2307/exe
    Source: /tmp/sora.mips (PID: 5237)File opened: /proc/2307/fd
    Source: /tmp/sora.mips (PID: 5237)File opened: /proc/2307/fd
    Source: /tmp/sora.mips (PID: 5237)File opened: /proc/918/fd
    Source: /tmp/sora.mips (PID: 5237)File opened: /proc/918/fd
    Source: /tmp/sora.mips (PID: 5237)File opened: /proc/918/exe
    Source: /tmp/sora.mips (PID: 5237)File opened: /proc/918/fd
    Source: /tmp/sora.mips (PID: 5237)File opened: /proc/918/fd
    Source: /tmp/sora.mips (PID: 5237)File opened: /proc/5033/fd
    Source: /tmp/sora.mips (PID: 5237)File opened: /proc/5276/exe
    Source: /tmp/sora.mips (PID: 5237)File opened: /proc/4465/exe
    Source: /tmp/sora.mips (PID: 5237)File opened: /proc/1594/fd
    Source: /tmp/sora.mips (PID: 5237)File opened: /proc/1594/exe
    Source: /tmp/sora.mips (PID: 5237)File opened: /proc/1594/fd
    Source: /tmp/sora.mips (PID: 5237)File opened: /proc/1594/fd
    Source: /tmp/sora.mips (PID: 5237)File opened: /proc/2285/fd
    Source: /tmp/sora.mips (PID: 5237)File opened: /proc/2285/exe
    Source: /tmp/sora.mips (PID: 5237)File opened: /proc/2281/fd
    Source: /tmp/sora.mips (PID: 5237)File opened: /proc/2281/exe
    Source: /tmp/sora.mips (PID: 5237)File opened: /proc/1349/fd
    Source: /tmp/sora.mips (PID: 5237)File opened: /proc/1349/exe
    Source: /tmp/sora.mips (PID: 5237)File opened: /proc/1349/fd
    Source: /tmp/sora.mips (PID: 5237)File opened: /proc/1349/fd
    Source: /tmp/sora.mips (PID: 5237)File opened: /proc/1/fd
    Source: /tmp/sora.mips (PID: 5237)File opened: /proc/1/fd
    Source: /tmp/sora.mips (PID: 5237)File opened: /proc/1/fd
    Source: /tmp/sora.mips (PID: 5237)File opened: /proc/1/fd
    Source: /tmp/sora.mips (PID: 5237)File opened: /proc/1623/fd
    Source: /tmp/sora.mips (PID: 5237)File opened: /proc/1623/exe
    Source: /tmp/sora.mips (PID: 5237)File opened: /proc/1623/fd
    Source: /tmp/sora.mips (PID: 5237)File opened: /proc/1623/fd
    Source: /tmp/sora.mips (PID: 5237)File opened: /proc/761/fd
    Source: /tmp/sora.mips (PID: 5237)File opened: /proc/761/fd
    Source: /tmp/sora.mips (PID: 5237)File opened: /proc/761/exe
    Source: /tmp/sora.mips (PID: 5237)File opened: /proc/761/fd
    Source: /tmp/sora.mips (PID: 5237)File opened: /proc/761/fd
    Source: /tmp/sora.mips (PID: 5235)Queries kernel information via 'uname':
    Source: sora.mips, 5237.1.00000000395f2dd2.000000003aa705ab.rw-.sdmpBinary or memory string: U1/usr/bin/vmtoolsdips/r10!/proc/2123/fd/70!/proc/1582/fd/103
    Source: sora.mips, 5235.1.00000000351202ca.00000000395f2dd2.rw-.sdmpBinary or memory string: U!/etc/qemu-binfmt/mips
    Source: sora.mips, 5235.1.00000000351202ca.00000000395f2dd2.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/mips
    Source: sora.mips, 5237.1.00000000395f2dd2.000000003aa705ab.rw-.sdmpBinary or memory string: /usr/bin/vmtoolsd
    Source: sora.mips, 5237.1.00000000395f2dd2.000000003aa705ab.rw-.sdmpBinary or memory string: Uu-binfmt/mips/0!/proc/1642/fd/2!/proc/1900/fd/7/mips/pr1/proc/2079/fd/5/mips/0!/proc/1642/fd/3!/proc/1900/fd/6/mips/pr1/usr/bin/qemu-mipsps/0!/proc/1642/fd/4!/proc/1900/fd/5/mips/pr1/proc/2079/fd/6/mips/0!/proc/1642/fd/5!/proc/1900/fd/4/mips/pr1p
    Source: sora.mips, 5235.1.0000000066980c05.000000007dcdc10d.rw-.sdmpBinary or memory string: /usr/bin/qemu-mips
    Source: sora.mips, 5235.1.0000000066980c05.000000007dcdc10d.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-mips/tmp/sora.mipsSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/sora.mips

    Stealing of Sensitive Information:

    barindex
    Yara detected MiraiShow sources
    Source: Yara matchFile source: dump.pcap, type: PCAP

    Remote Access Functionality:

    barindex
    Yara detected MiraiShow sources
    Source: Yara matchFile source: dump.pcap, type: PCAP

    Mitre Att&ck Matrix

    Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
    Valid AccountsWindows Management InstrumentationPath InterceptionPath InterceptionDirect Volume AccessOS Credential Dumping1Security Software Discovery11Remote ServicesData from Local SystemExfiltration Over Other Network MediumEncrypted Channel1Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
    Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over BluetoothNon-Standard Port1Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
    Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated ExfiltrationApplication Layer Protocol1Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data

    Malware Configuration

    No configs have been found

    Behavior Graph

    Hide Legend

    Legend:

    • Process
    • Signature
    • Created File
    • DNS/IP Info
    • Is Dropped
    • Number of created Files
    • Is malicious
    • Internet
    behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 513591 Sample: sora.mips Startdate: 02/11/2021 Architecture: LINUX Score: 68 29 70.40.0.156, 23 WOODYNET-1US United States 2->29 31 216.56.118.102 WISCNET1-ASUS United States 2->31 33 98 other IPs or domains 2->33 37 Snort IDS alert for network traffic (e.g. based on Emerging Threat rules) 2->37 39 Multi AV Scanner detection for submitted file 2->39 41 Yara detected Mirai 2->41 8 sora.mips 2->8         started        10 systemd sshd 2->10         started        12 systemd sshd 2->12         started        14 4 other processes 2->14 signatures3 process4 process5 16 sora.mips 8->16         started        19 sora.mips 8->19         started        21 sora.mips 8->21         started        signatures6 35 Sample tries to kill many processes (SIGKILL) 16->35 23 sora.mips 19->23         started        25 sora.mips 19->25         started        27 sora.mips 19->27         started        process7

    Screenshots

    Thumbnails

    This section contains all screenshots as thumbnails, including those not shown in the slideshow.

    windows-stand

    Antivirus, Machine Learning and Genetic Malware Detection

    Initial Sample

    SourceDetectionScannerLabelLink
    sora.mips52%VirustotalBrowse
    sora.mips56%ReversingLabsLinux.Trojan.Mirai

    Dropped Files

    No Antivirus matches

    Domains

    No Antivirus matches

    URLs

    No Antivirus matches

    Domains and IPs

    Contacted Domains

    No contacted domains info

    Contacted IPs

    • No. of IPs < 25%
    • 25% < No. of IPs < 50%
    • 50% < No. of IPs < 75%
    • 75% < No. of IPs

    Public

    IPDomainCountryFlagASNASN NameMalicious
    71.107.202.139
    unknownUnited States
    701UUNETUSfalse
    80.24.160.20
    unknownSpain
    3352TELEFONICA_DE_ESPANAESfalse
    70.40.0.156
    unknownUnited States
    42WOODYNET-1USfalse
    78.227.140.86
    unknownFrance
    12322PROXADFRfalse
    67.57.110.53
    unknownUnited States
    6389BELLSOUTH-NET-BLKUSfalse
    91.174.80.19
    unknownFrance
    12322PROXADFRfalse
    172.246.244.217
    unknownUnited States
    18978ENZUINC-USfalse
    245.171.55.96
    unknownReserved
    unknownunknownfalse
    63.148.160.73
    unknownUnited States
    209CENTURYLINK-US-LEGACY-QWESTUSfalse
    142.245.30.182
    unknownCanada
    19416RBC-NYUSfalse
    255.148.57.230
    unknownReserved
    unknownunknownfalse
    111.6.69.190
    unknownChina
    24445CMNET-V4HENAN-AS-APHenanMobileCommunicationsCoLtdCNfalse
    31.137.239.105
    unknownNetherlands
    15480VFNL-ASVodafoneNLAutonomousSystemNLfalse
    34.229.108.227
    unknownUnited States
    14618AMAZON-AESUSfalse
    24.64.127.6
    unknownCanada
    6327SHAWCAfalse
    76.8.118.210
    unknownCanada
    25636ONTL-2002CAfalse
    203.176.190.38
    unknownPakistan
    45195CDCPAK-PKCDCHouse99-BBlockBPKfalse
    41.193.111.37
    unknownSouth Africa
    11845Vox-TelecomZAfalse
    59.109.98.212
    unknownChina
    18245FOUNDERBNCNNICCNfalse
    121.77.143.181
    unknownChina
    9812CNNIC-CN-COLNETOrientalCableNetworkCoLtdCNfalse
    254.167.189.62
    unknownReserved
    unknownunknownfalse
    241.15.185.185
    unknownReserved
    unknownunknownfalse
    120.224.137.159
    unknownChina
    24444CMNET-V4SHANDONG-AS-APShandongMobileCommunicationCompanyfalse
    44.96.244.86
    unknownUnited States
    7377UCSDUSfalse
    114.37.39.155
    unknownTaiwan; Republic of China (ROC)
    3462HINETDataCommunicationBusinessGroupTWfalse
    37.91.93.228
    unknownGermany
    3320DTAGInternetserviceprovideroperationsDEfalse
    149.150.154.242
    unknownUnited States
    2494MUWNETMUWNETAutonomousSystemATfalse
    248.155.90.26
    unknownReserved
    unknownunknownfalse
    31.31.135.149
    unknownBelgium
    199095CITYMESH-ASBEfalse
    251.82.161.94
    unknownReserved
    unknownunknownfalse
    167.238.223.149
    unknownUnited States
    36092CENTENEUSfalse
    153.128.122.143
    unknownJapan4713OCNNTTCommunicationsCorporationJPfalse
    151.142.10.141
    unknownUnited States
    10967HOMEDEPOTNETUSfalse
    158.73.140.99
    unknownUnited States
    19050TIC-DHHS-INTERIORUSfalse
    64.28.69.73
    unknownUnited States
    3561CENTURYLINK-LEGACY-SAVVISUSfalse
    106.128.236.235
    unknownJapan2516KDDIKDDICORPORATIONJPfalse
    140.210.162.31
    unknownChina
    4808CHINA169-BJChinaUnicomBeijingProvinceNetworkCNfalse
    216.81.240.141
    unknownUnited States
    11320LIGHTEDGE-AS-02USfalse
    200.172.238.27
    unknownBrazil
    4230CLAROSABRfalse
    95.121.137.238
    unknownSpain
    3352TELEFONICA_DE_ESPANAESfalse
    17.160.100.84
    unknownUnited States
    714APPLE-ENGINEERINGUSfalse
    164.183.202.166
    unknownUnited States
    37717EL-KhawarizmiTNfalse
    240.85.62.5
    unknownReserved
    unknownunknownfalse
    104.35.143.179
    unknownUnited States
    20001TWC-20001-PACWESTUSfalse
    175.34.81.13
    unknownAustralia
    4804MPX-ASMicroplexPTYLTDAUfalse
    16.229.239.174
    unknownUnited States
    unknownunknownfalse
    86.90.140.115
    unknownNetherlands
    1136KPNKPNNationalEUfalse
    43.112.78.251
    unknownJapan4249LILLY-ASUSfalse
    255.123.99.53
    unknownReserved
    unknownunknownfalse
    195.20.246.157
    unknownGermany
    8560ONEANDONE-ASBrauerstrasse48DEfalse
    36.132.101.91
    unknownChina
    56044CMNET-AS-LIAONINGChinaMobilecommunicationscorporationCfalse
    191.254.53.60
    unknownBrazil
    27699TELEFONICABRASILSABRfalse
    45.124.201.45
    unknownAustralia
    134067UNITI-AS-APUnitiWirelessPtyLtdAUfalse
    163.40.82.221
    unknownUnited States
    226LOS-NETTOS-ASUSfalse
    96.201.7.12
    unknownUnited States
    7922COMCAST-7922USfalse
    189.181.178.68
    unknownMexico
    8151UninetSAdeCVMXfalse
    57.147.55.165
    unknownBelgium
    2686ATGS-MMD-ASUSfalse
    92.233.183.89
    unknownUnited Kingdom
    5089NTLGBfalse
    244.107.176.234
    unknownReserved
    unknownunknownfalse
    246.55.8.155
    unknownReserved
    unknownunknownfalse
    96.38.83.249
    unknownUnited States
    20115CHARTER-20115USfalse
    120.1.84.157
    unknownChina
    4837CHINA169-BACKBONECHINAUNICOMChina169BackboneCNfalse
    60.6.178.183
    unknownChina
    4837CHINA169-BACKBONECHINAUNICOMChina169BackboneCNfalse
    172.74.68.185
    unknownUnited States
    11426TWC-11426-CAROLINASUSfalse
    245.166.238.106
    unknownReserved
    unknownunknownfalse
    112.251.95.212
    unknownChina
    4837CHINA169-BACKBONECHINAUNICOMChina169BackboneCNfalse
    210.110.112.139
    unknownKorea Republic of
    3786LGDACOMLGDACOMCorporationKRfalse
    169.164.169.125
    unknownUnited States
    37611AfrihostZAfalse
    68.144.38.185
    unknownCanada
    6327SHAWCAfalse
    12.69.103.16
    unknownUnited States
    7018ATT-INTERNET4USfalse
    255.96.93.6
    unknownReserved
    unknownunknownfalse
    136.254.214.173
    unknownUnited States
    72SCHLUMBERGER-ASUSfalse
    219.69.54.175
    unknownTaiwan; Republic of China (ROC)
    9416MULTIMEDIA-AS-APHoshinMultimediaCenterIncTWfalse
    90.142.192.22
    unknownSweden
    1257TELE2EUfalse
    99.215.192.252
    unknownCanada
    812ROGERS-COMMUNICATIONSCAfalse
    167.134.52.44
    unknownVenezuela
    10405UPRR-ASN-01USfalse
    189.194.242.73
    unknownMexico
    13999MegaCableSAdeCVMXfalse
    90.35.131.168
    unknownFrance
    3215FranceTelecom-OrangeFRfalse
    205.182.104.37
    unknownUnited States
    3356LEVEL3USfalse
    250.109.197.189
    unknownReserved
    unknownunknownfalse
    157.204.30.231
    unknownUnited States
    54216GORE-NETWORKUSfalse
    167.234.69.231
    unknownUnited States
    3525ALBERTSONSUSfalse
    83.97.114.71
    unknownGermany
    209854SURFSHARKVGfalse
    142.67.215.102
    unknownCanada
    22636NOVA-SCOTIA-POWERCAfalse
    159.206.56.242
    unknownCanada
    16793DATA-TRONICSUSfalse
    80.110.234.46
    unknownAustria
    6830LIBERTYGLOBALLibertyGlobalformerlyUPCBroadbandHoldingfalse
    83.208.201.84
    unknownCzech Republic
    5610O2-CZECH-REPUBLICCZfalse
    102.236.71.235
    unknownunknown
    36926CKL1-ASNKEfalse
    65.1.40.107
    unknownUnited States
    16509AMAZON-02USfalse
    172.116.65.63
    unknownUnited States
    20001TWC-20001-PACWESTUSfalse
    151.158.166.126
    unknownunknown
    205664VATTENFALL-ABSEfalse
    216.56.118.102
    unknownUnited States
    2381WISCNET1-ASUSfalse
    67.211.159.82
    unknownUnited States
    26161TMEIC-AUSfalse
    250.85.29.212
    unknownReserved
    unknownunknownfalse
    13.176.170.242
    unknownUnited States
    7018ATT-INTERNET4USfalse
    169.147.23.233
    unknownUnited States
    11659KUMCUSfalse
    53.99.133.165
    unknownGermany
    31399DAIMLER-ASITIGNGlobalNetworkDEfalse
    174.146.255.210
    unknownUnited States
    10507SPCSUSfalse
    60.0.108.165
    unknownChina
    4837CHINA169-BACKBONECHINAUNICOMChina169BackboneCNfalse
    111.142.109.142
    unknownChina
    9394CTTNETChinaTieTongTelecommunicationsCorporationCNfalse


    Runtime Messages

    Command:/tmp/sora.mips
    Exit Code:0
    Exit Code Info:
    Killed:False
    Standard Output:
    Connected To CNC
    Standard Error:

    Joe Sandbox View / Context

    IPs

    MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
    31.31.135.149sora.armGet hashmaliciousBrowse
      95.121.137.238EtNIxD2GSDGet hashmaliciousBrowse

        Domains

        No context

        ASN

        MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
        UUNETUSarm5-20211102-0937Get hashmaliciousBrowse
        • 193.99.20.99
        wNrhZyq41NGet hashmaliciousBrowse
        • 71.245.10.212
        eFsSvDKamsGet hashmaliciousBrowse
        • 72.74.241.117
        KHSQ48GkGnGet hashmaliciousBrowse
        • 207.24.250.131
        Hilix.armGet hashmaliciousBrowse
        • 173.70.19.34
        JVHk2b1Yd5Get hashmaliciousBrowse
        • 108.54.12.29
        vRjXKh3l4nGet hashmaliciousBrowse
        • 68.133.8.110
        WhFNix8BoEGet hashmaliciousBrowse
        • 207.247.179.228
        wt5i2fAcF0Get hashmaliciousBrowse
        • 65.233.206.198
        aTQ4RalkUsGet hashmaliciousBrowse
        • 100.41.247.191
        o6aMoZKsIKGet hashmaliciousBrowse
        • 208.192.217.76
        dUW6YG1TdvGet hashmaliciousBrowse
        • 210.80.9.164
        RPov9E0iotGet hashmaliciousBrowse
        • 63.9.179.107
        8VANaS473tGet hashmaliciousBrowse
        • 108.37.65.106
        uohdbohpYbGet hashmaliciousBrowse
        • 207.24.67.100
        yVbcX1sEtSGet hashmaliciousBrowse
        • 108.3.69.246
        8PRjJeUifBGet hashmaliciousBrowse
        • 162.84.87.96
        SZAYTvvY9YGet hashmaliciousBrowse
        • 145.4.3.12
        1Y2rsDBP9sGet hashmaliciousBrowse
        • 108.3.70.173
        Ko84iLip1uGet hashmaliciousBrowse
        • 207.68.36.75
        TELEFONICA_DE_ESPANAESBsXhIyIHzCGet hashmaliciousBrowse
        • 80.36.33.66
        L831wSjET5Get hashmaliciousBrowse
        • 95.121.185.136
        JVHk2b1Yd5Get hashmaliciousBrowse
        • 95.127.124.196
        WhFNix8BoEGet hashmaliciousBrowse
        • 95.121.19.91
        yVbcX1sEtSGet hashmaliciousBrowse
        • 83.32.29.93
        8PRjJeUifBGet hashmaliciousBrowse
        • 176.80.242.237
        7DoAjWX5uZGet hashmaliciousBrowse
        • 176.80.154.240
        1Y2rsDBP9sGet hashmaliciousBrowse
        • 81.41.247.123
        Ko84iLip1uGet hashmaliciousBrowse
        • 83.40.96.83
        arH2Af5qocGet hashmaliciousBrowse
        • 83.34.180.127
        t7WU0JjLARGet hashmaliciousBrowse
        • 80.27.241.201
        P8AVd483d7Get hashmaliciousBrowse
        • 79.156.169.224
        mRQwOz6OitGet hashmaliciousBrowse
        • 81.43.163.120
        Yoshi.arm7Get hashmaliciousBrowse
        • 193.152.99.121
        Yoshi.x86Get hashmaliciousBrowse
        • 194.224.122.99
        mipselGet hashmaliciousBrowse
        • 88.16.182.168
        armGet hashmaliciousBrowse
        • 95.125.208.148
        mipsGet hashmaliciousBrowse
        • 80.37.48.128
        anWxzNav9NGet hashmaliciousBrowse
        • 83.46.177.108
        ydZLm6GD56Get hashmaliciousBrowse
        • 88.28.74.111

        JA3 Fingerprints

        No context

        Dropped Files

        No context

        Created / dropped Files

        /proc/5276/oom_score_adj
        Process:/usr/sbin/sshd
        File Type:ASCII text
        Category:dropped
        Size (bytes):6
        Entropy (8bit):1.7924812503605778
        Encrypted:false
        SSDEEP:3:ptn:Dn
        MD5:CBF282CC55ED0792C33D10003D1F760A
        SHA1:007DD8BD75468E6B7ABA4285E9B267202C7EAEED
        SHA-256:FCDBAB99FCC0F4409E5F9D7D6FC497780288B4C441698126BB62832412774D22
        SHA-512:4643A8675D213C7DA35CC0C2BFB3B6F20324F9C48AEA7BA79F470615698C9A0CEFDA45CAA1957FC29110EE746BC8458AB8AB1E43EB513912A5E1E8858812CC00
        Malicious:false
        Reputation:high, very likely benign file
        Preview: -1000.
        /proc/5387/oom_score_adj
        Process:/usr/sbin/sshd
        File Type:ASCII text
        Category:dropped
        Size (bytes):6
        Entropy (8bit):1.7924812503605778
        Encrypted:false
        SSDEEP:3:ptn:Dn
        MD5:CBF282CC55ED0792C33D10003D1F760A
        SHA1:007DD8BD75468E6B7ABA4285E9B267202C7EAEED
        SHA-256:FCDBAB99FCC0F4409E5F9D7D6FC497780288B4C441698126BB62832412774D22
        SHA-512:4643A8675D213C7DA35CC0C2BFB3B6F20324F9C48AEA7BA79F470615698C9A0CEFDA45CAA1957FC29110EE746BC8458AB8AB1E43EB513912A5E1E8858812CC00
        Malicious:false
        Reputation:high, very likely benign file
        Preview: -1000.
        /proc/5391/oom_score_adj
        Process:/usr/sbin/sshd
        File Type:ASCII text
        Category:dropped
        Size (bytes):6
        Entropy (8bit):1.7924812503605778
        Encrypted:false
        SSDEEP:3:ptn:Dn
        MD5:CBF282CC55ED0792C33D10003D1F760A
        SHA1:007DD8BD75468E6B7ABA4285E9B267202C7EAEED
        SHA-256:FCDBAB99FCC0F4409E5F9D7D6FC497780288B4C441698126BB62832412774D22
        SHA-512:4643A8675D213C7DA35CC0C2BFB3B6F20324F9C48AEA7BA79F470615698C9A0CEFDA45CAA1957FC29110EE746BC8458AB8AB1E43EB513912A5E1E8858812CC00
        Malicious:false
        Reputation:high, very likely benign file
        Preview: -1000.
        /run/sshd.pid
        Process:/usr/sbin/sshd
        File Type:ASCII text
        Category:dropped
        Size (bytes):5
        Entropy (8bit):2.321928094887362
        Encrypted:false
        SSDEEP:3:Dc2n:p
        MD5:EBC3FCE3183D08458EA683E4EA2AE38B
        SHA1:34674DDE2892AB7D2354F95DAB7D442B44E42431
        SHA-256:60015F8BF398A9443CACC8139E72C56EF7B5DCCA1518B134617D7EC546BFF5F2
        SHA-512:6C626D79B58FD4C023DBDB3018EC06C5D78E75D2D79C210138A8F8C02A18C619DB798AD163E3827A4BCCC80919827B6DD57C23B812CADFD821A9E899DAE387AB
        Malicious:false
        Reputation:low
        Preview: 5391.

        Static File Info

        General

        File type:ELF 32-bit MSB executable, MIPS, MIPS-I version 1 (SYSV), statically linked, stripped
        Entropy (8bit):5.296543702857597
        TrID:
        • ELF Executable and Linkable format (generic) (4004/1) 100.00%
        File name:sora.mips
        File size:71764
        MD5:f541ee6ca94d92d5c8da35fce228bb46
        SHA1:46100ebb28ef32d9895277b26db0705cdb4a5729
        SHA256:119853ec87c7bc15674fa8beaf375979d963c5fd763d08a32ef555041e053d04
        SHA512:8efd86b742eaf71e845f4abe47282f993fd62c4d45c4fd63b8f1ac9014a8a7c3e04242f1ecb292256ce38c36b3354ac1ceb15f86da52870fc501cb6e9921d914
        SSDEEP:1536:WkvDSnAd6mYoPdd8QVs1o0vB1tA0iLuYw2+O/8p:WkLSA3vbko0pTAmYw2+OEp
        File Content Preview:.ELF.....................@.`...4...L.....4. ...(.............@...@...........................E...E..................dt.Q............................<...'......!'.......................<...'......!... ....'9... ......................<...'......!........'9.

        Static ELF Info

        ELF header

        Class:ELF32
        Data:2's complement, big endian
        Version:1 (current)
        Machine:MIPS R3000
        Version Number:0x1
        Type:EXEC (Executable file)
        OS/ABI:UNIX - System V
        ABI Version:0
        Entry Point Address:0x400260
        Flags:0x1007
        ELF Header Size:52
        Program Header Offset:52
        Program Header Size:32
        Number of Program Headers:3
        Section Header Offset:71244
        Section Header Size:40
        Number of Section Headers:13
        Header String Table Index:12

        Sections

        NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
        NULL0x00x00x00x00x0000
        .initPROGBITS0x4000940x940x8c0x00x6AX004
        .textPROGBITS0x4001200x1200xffe00x00x6AX0016
        .finiPROGBITS0x4101000x101000x5c0x00x6AX004
        .rodataPROGBITS0x4101600x101600x6600x00x2A0016
        .ctorsPROGBITS0x4510000x110000x80x00x3WA004
        .dtorsPROGBITS0x4510080x110080x80x00x3WA004
        .dataPROGBITS0x4510200x110200x1900x00x3WA0016
        .gotPROGBITS0x4511b00x111b00x4440x40x10000003WA0016
        .sbssNOBITS0x4515f40x115f40x240x00x10000003WA004
        .bssNOBITS0x4516200x115f40x2a00x00x3WA0016
        .mdebug.abi32PROGBITS0x72c0x115f40x00x00x0001
        .shstrtabSTRTAB0x00x115f40x570x00x0001

        Program Segments

        TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
        LOAD0x00x4000000x4000000x107c00x107c03.34920x5R E0x10000.init .text .fini .rodata
        LOAD0x110000x4510000x4510000x5f40x8c01.81170x6RW 0x10000.ctors .dtors .data .got .sbss .bss
        GNU_STACK0x00x00x00x00x00.00000x7RWE0x4

        Network Behavior

        Network Port Distribution

        TCP Packets

        TimestampSource PortDest PortSource IPDest IP
        Nov 2, 2021 11:18:15.117147923 CET396921312192.168.2.2320.151.141.34
        Nov 2, 2021 11:18:15.139158010 CET5652823192.168.2.2392.125.81.222
        Nov 2, 2021 11:18:15.139244080 CET5652823192.168.2.23206.23.56.222
        Nov 2, 2021 11:18:15.139290094 CET5652823192.168.2.2381.250.245.60
        Nov 2, 2021 11:18:15.139347076 CET5652823192.168.2.23178.224.11.107
        Nov 2, 2021 11:18:15.139390945 CET5652823192.168.2.23152.177.176.172
        Nov 2, 2021 11:18:15.139472008 CET5652823192.168.2.23107.158.11.21
        Nov 2, 2021 11:18:15.139528990 CET5652823192.168.2.23218.56.128.93
        Nov 2, 2021 11:18:15.139532089 CET5652823192.168.2.2336.16.231.114
        Nov 2, 2021 11:18:15.139537096 CET5652823192.168.2.23252.125.147.157
        Nov 2, 2021 11:18:15.139542103 CET5652823192.168.2.23177.173.219.179
        Nov 2, 2021 11:18:15.139560938 CET5652823192.168.2.23113.230.45.131
        Nov 2, 2021 11:18:15.139569044 CET5652823192.168.2.2327.212.249.70
        Nov 2, 2021 11:18:15.139592886 CET5652823192.168.2.2323.26.195.206
        Nov 2, 2021 11:18:15.139631987 CET5652823192.168.2.23167.60.218.239
        Nov 2, 2021 11:18:15.139667988 CET5652823192.168.2.23170.103.202.249
        Nov 2, 2021 11:18:15.139667988 CET5652823192.168.2.2342.33.237.121
        Nov 2, 2021 11:18:15.139673948 CET5652823192.168.2.23125.216.198.116
        Nov 2, 2021 11:18:15.139699936 CET5652823192.168.2.23106.132.143.186
        Nov 2, 2021 11:18:15.139700890 CET5652823192.168.2.2346.66.157.206
        Nov 2, 2021 11:18:15.139700890 CET5652823192.168.2.23241.158.158.122
        Nov 2, 2021 11:18:15.139708996 CET5652823192.168.2.2388.230.66.254
        Nov 2, 2021 11:18:15.139715910 CET5652823192.168.2.2320.89.229.159
        Nov 2, 2021 11:18:15.139771938 CET5652823192.168.2.23168.255.195.10
        Nov 2, 2021 11:18:15.139786005 CET5652823192.168.2.23135.141.217.112
        Nov 2, 2021 11:18:15.139806032 CET5652823192.168.2.23124.86.186.137
        Nov 2, 2021 11:18:15.139806986 CET5652823192.168.2.2392.147.222.83
        Nov 2, 2021 11:18:15.139822960 CET5652823192.168.2.23122.238.207.126
        Nov 2, 2021 11:18:15.139828920 CET5652823192.168.2.23200.26.216.73
        Nov 2, 2021 11:18:15.139832973 CET5652823192.168.2.2341.20.159.169
        Nov 2, 2021 11:18:15.139853954 CET5652823192.168.2.23144.73.8.159
        Nov 2, 2021 11:18:15.139883995 CET5652823192.168.2.23223.54.253.28
        Nov 2, 2021 11:18:15.139914989 CET5652823192.168.2.23243.230.107.3
        Nov 2, 2021 11:18:15.139926910 CET5652823192.168.2.23250.44.241.30
        Nov 2, 2021 11:18:15.140034914 CET5652823192.168.2.23150.198.177.166
        Nov 2, 2021 11:18:15.140085936 CET5652823192.168.2.23119.123.69.154
        Nov 2, 2021 11:18:15.140095949 CET5652823192.168.2.23121.241.205.167
        Nov 2, 2021 11:18:15.140115976 CET5652823192.168.2.23249.135.121.55
        Nov 2, 2021 11:18:15.140115976 CET5652823192.168.2.2344.219.36.33
        Nov 2, 2021 11:18:15.140124083 CET5652823192.168.2.23139.22.168.95
        Nov 2, 2021 11:18:15.140136003 CET5652823192.168.2.23166.149.131.138
        Nov 2, 2021 11:18:15.140141964 CET5652823192.168.2.2362.195.100.65
        Nov 2, 2021 11:18:15.140144110 CET5652823192.168.2.23133.221.246.82
        Nov 2, 2021 11:18:15.140177965 CET5652823192.168.2.23199.11.56.87
        Nov 2, 2021 11:18:15.140203953 CET5652823192.168.2.2395.250.78.5
        Nov 2, 2021 11:18:15.140213013 CET5652823192.168.2.23217.139.56.209
        Nov 2, 2021 11:18:15.140230894 CET5652823192.168.2.2323.195.178.190
        Nov 2, 2021 11:18:15.140266895 CET5652823192.168.2.23151.88.121.184
        Nov 2, 2021 11:18:15.140281916 CET5652823192.168.2.2395.178.152.69
        Nov 2, 2021 11:18:15.140314102 CET5652823192.168.2.23172.186.225.86
        Nov 2, 2021 11:18:15.140326977 CET5652823192.168.2.23135.50.35.137
        Nov 2, 2021 11:18:15.140337944 CET5652823192.168.2.2373.153.175.90
        Nov 2, 2021 11:18:15.140353918 CET5652823192.168.2.23102.83.254.136
        Nov 2, 2021 11:18:15.140356064 CET5652823192.168.2.23141.23.185.1
        Nov 2, 2021 11:18:15.140356064 CET5652823192.168.2.23249.208.199.172
        Nov 2, 2021 11:18:15.140404940 CET5652823192.168.2.23207.34.245.113
        Nov 2, 2021 11:18:15.140446901 CET5652823192.168.2.235.48.121.254
        Nov 2, 2021 11:18:15.140463114 CET5652823192.168.2.23218.24.138.37
        Nov 2, 2021 11:18:15.140463114 CET5652823192.168.2.23213.48.191.96
        Nov 2, 2021 11:18:15.140477896 CET5652823192.168.2.2368.194.192.32
        Nov 2, 2021 11:18:15.140502930 CET5652823192.168.2.2371.100.252.124
        Nov 2, 2021 11:18:15.140525103 CET5652823192.168.2.23218.197.177.225
        Nov 2, 2021 11:18:15.140532017 CET5652823192.168.2.23121.234.224.111
        Nov 2, 2021 11:18:15.140539885 CET5652823192.168.2.23118.182.224.132
        Nov 2, 2021 11:18:15.140539885 CET5652823192.168.2.23180.32.84.230
        Nov 2, 2021 11:18:15.140552998 CET5652823192.168.2.23111.15.28.211
        Nov 2, 2021 11:18:15.140598059 CET5652823192.168.2.23174.1.144.192
        Nov 2, 2021 11:18:15.140624046 CET5652823192.168.2.2388.108.32.104
        Nov 2, 2021 11:18:15.140647888 CET5652823192.168.2.23108.241.190.251
        Nov 2, 2021 11:18:15.140671968 CET5652823192.168.2.2342.100.230.54
        Nov 2, 2021 11:18:15.140686989 CET5652823192.168.2.23220.246.198.94
        Nov 2, 2021 11:18:15.140695095 CET5652823192.168.2.23165.186.88.27
        Nov 2, 2021 11:18:15.140734911 CET5652823192.168.2.23208.96.111.122
        Nov 2, 2021 11:18:15.140747070 CET5652823192.168.2.23102.69.76.229
        Nov 2, 2021 11:18:15.140778065 CET5652823192.168.2.23106.197.248.64
        Nov 2, 2021 11:18:15.140784025 CET5652823192.168.2.2369.59.169.183
        Nov 2, 2021 11:18:15.140799046 CET5652823192.168.2.2392.193.47.4
        Nov 2, 2021 11:18:15.140804052 CET5652823192.168.2.23191.173.64.251
        Nov 2, 2021 11:18:15.140822887 CET5652823192.168.2.23251.51.119.115
        Nov 2, 2021 11:18:15.140860081 CET5652823192.168.2.23255.32.170.168
        Nov 2, 2021 11:18:15.140868902 CET5652823192.168.2.23241.254.48.127
        Nov 2, 2021 11:18:15.140872955 CET5652823192.168.2.2391.150.209.156
        Nov 2, 2021 11:18:15.140880108 CET5652823192.168.2.23182.249.132.115
        Nov 2, 2021 11:18:15.140889883 CET5652823192.168.2.23171.145.189.159
        Nov 2, 2021 11:18:15.140912056 CET5652823192.168.2.23156.107.144.197
        Nov 2, 2021 11:18:15.140928984 CET5652823192.168.2.23156.74.186.240
        Nov 2, 2021 11:18:15.140930891 CET5652823192.168.2.23103.188.141.76
        Nov 2, 2021 11:18:15.141031981 CET5652823192.168.2.23147.210.97.156
        Nov 2, 2021 11:18:15.141119003 CET5652823192.168.2.2388.120.138.214
        Nov 2, 2021 11:18:15.141125917 CET5652823192.168.2.2364.9.113.136
        Nov 2, 2021 11:18:15.141127110 CET5652823192.168.2.23103.110.141.150
        Nov 2, 2021 11:18:15.141165018 CET5652823192.168.2.2380.54.53.202
        Nov 2, 2021 11:18:15.141177893 CET5652823192.168.2.2331.137.156.196
        Nov 2, 2021 11:18:15.141202927 CET5652823192.168.2.23139.254.229.178
        Nov 2, 2021 11:18:15.141205072 CET5652823192.168.2.23102.19.72.172
        Nov 2, 2021 11:18:15.141222000 CET5652823192.168.2.23144.21.101.197
        Nov 2, 2021 11:18:15.141309977 CET5652823192.168.2.23213.104.64.34
        Nov 2, 2021 11:18:15.141310930 CET5652823192.168.2.23146.175.43.207
        Nov 2, 2021 11:18:15.141330004 CET5652823192.168.2.23161.203.162.108
        Nov 2, 2021 11:18:15.141331911 CET5652823192.168.2.2316.253.12.218

        System Behavior

        General

        Start time:11:18:13
        Start date:02/11/2021
        Path:/tmp/sora.mips
        Arguments:/tmp/sora.mips
        File size:5777432 bytes
        MD5 hash:0083f1f0e77be34ad27f849842bbb00c

        General

        Start time:11:18:13
        Start date:02/11/2021
        Path:/tmp/sora.mips
        Arguments:n/a
        File size:5777432 bytes
        MD5 hash:0083f1f0e77be34ad27f849842bbb00c

        General

        Start time:11:18:13
        Start date:02/11/2021
        Path:/tmp/sora.mips
        Arguments:n/a
        File size:5777432 bytes
        MD5 hash:0083f1f0e77be34ad27f849842bbb00c

        General

        Start time:11:18:13
        Start date:02/11/2021
        Path:/tmp/sora.mips
        Arguments:n/a
        File size:5777432 bytes
        MD5 hash:0083f1f0e77be34ad27f849842bbb00c

        General

        Start time:11:18:13
        Start date:02/11/2021
        Path:/tmp/sora.mips
        Arguments:n/a
        File size:5777432 bytes
        MD5 hash:0083f1f0e77be34ad27f849842bbb00c

        General

        Start time:11:18:14
        Start date:02/11/2021
        Path:/tmp/sora.mips
        Arguments:n/a
        File size:5777432 bytes
        MD5 hash:0083f1f0e77be34ad27f849842bbb00c

        General

        Start time:11:18:14
        Start date:02/11/2021
        Path:/tmp/sora.mips
        Arguments:n/a
        File size:5777432 bytes
        MD5 hash:0083f1f0e77be34ad27f849842bbb00c

        General

        Start time:11:18:26
        Start date:02/11/2021
        Path:/usr/lib/systemd/systemd
        Arguments:n/a
        File size:1620224 bytes
        MD5 hash:9b2bec7092a40488108543f9334aab75

        General

        Start time:11:18:26
        Start date:02/11/2021
        Path:/usr/sbin/sshd
        Arguments:/usr/sbin/sshd -t
        File size:876328 bytes
        MD5 hash:dbca7a6bbf7bf57fedac243d4b2cb340

        General

        Start time:11:18:27
        Start date:02/11/2021
        Path:/usr/lib/systemd/systemd
        Arguments:n/a
        File size:1620224 bytes
        MD5 hash:9b2bec7092a40488108543f9334aab75

        General

        Start time:11:18:27
        Start date:02/11/2021
        Path:/usr/sbin/sshd
        Arguments:/usr/sbin/sshd -D
        File size:876328 bytes
        MD5 hash:dbca7a6bbf7bf57fedac243d4b2cb340

        General

        Start time:11:21:08
        Start date:02/11/2021
        Path:/usr/lib/systemd/systemd
        Arguments:n/a
        File size:1620224 bytes
        MD5 hash:9b2bec7092a40488108543f9334aab75

        General

        Start time:11:21:08
        Start date:02/11/2021
        Path:/usr/sbin/sshd
        Arguments:/usr/sbin/sshd -t
        File size:876328 bytes
        MD5 hash:dbca7a6bbf7bf57fedac243d4b2cb340

        General

        Start time:11:21:09
        Start date:02/11/2021
        Path:/usr/lib/systemd/systemd
        Arguments:n/a
        File size:1620224 bytes
        MD5 hash:9b2bec7092a40488108543f9334aab75

        General

        Start time:11:21:09
        Start date:02/11/2021
        Path:/usr/sbin/sshd
        Arguments:/usr/sbin/sshd -D
        File size:876328 bytes
        MD5 hash:dbca7a6bbf7bf57fedac243d4b2cb340

        General

        Start time:11:21:11
        Start date:02/11/2021
        Path:/usr/lib/systemd/systemd
        Arguments:n/a
        File size:1620224 bytes
        MD5 hash:9b2bec7092a40488108543f9334aab75

        General

        Start time:11:21:11
        Start date:02/11/2021
        Path:/usr/sbin/sshd
        Arguments:/usr/sbin/sshd -t
        File size:876328 bytes
        MD5 hash:dbca7a6bbf7bf57fedac243d4b2cb340

        General

        Start time:11:21:11
        Start date:02/11/2021
        Path:/usr/lib/systemd/systemd
        Arguments:n/a
        File size:1620224 bytes
        MD5 hash:9b2bec7092a40488108543f9334aab75

        General

        Start time:11:21:11
        Start date:02/11/2021
        Path:/usr/sbin/sshd
        Arguments:/usr/sbin/sshd -D
        File size:876328 bytes
        MD5 hash:dbca7a6bbf7bf57fedac243d4b2cb340