Loading ...

Play interactive tourEdit tour

Linux Analysis Report sora.x86

Overview

General Information

Sample Name:sora.x86
Analysis ID:513641
MD5:ec0785f99de2a1ea900d48a9bb26bf1c
SHA1:bdabfc4ef8c6e050ba2a88927ac9429bd71813c9
SHA256:30ad105f506c59e85005c99f64fcfc577c2a51caf131bc9f57e5172a404654d3
Tags:Mirai
Infos:

Most interesting Screenshot:

Detection

Mirai
Score:76
Range:0 - 100
Whitelisted:false

Signatures

Snort IDS alert for network traffic (e.g. based on Emerging Threat rules)
Yara detected Mirai
Multi AV Scanner detection for submitted file
Sample is packed with UPX
Uses known network protocols on non-standard ports
Sample tries to kill many processes (SIGKILL)
Sample contains only a LOAD segment without any section mappings
Enumerates processes within the "proc" file system
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Detected TCP or UDP traffic on non-standard ports
Sample listens on a socket
Sample tries to kill a process (SIGKILL)

Classification

Analysis Advice

All HTTP servers contacted by the sample do not answer. Likely the sample is an old dropper which does no longer work

General Information

Joe Sandbox Version:34.0.0 Boulder Opal
Analysis ID:513641
Start date:02.11.2021
Start time:12:12:50
Joe Sandbox Product:CloudBasic
Overall analysis duration:0h 6m 49s
Hypervisor based Inspection enabled:false
Report type:light
Sample file name:sora.x86
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Detection:MAL
Classification:mal76.spre.troj.evad.linX86@0/6@0/0
Warnings:
Show All
  • Report size exceeded maximum capacity and may have missing network information.
  • TCP Packets have been reduced to 100

Process Tree

  • system is lnxubuntu20
  • sora.x86 (PID: 5233, Parent: 5111, MD5: ec0785f99de2a1ea900d48a9bb26bf1c) Arguments: /tmp/sora.x86
    • sora.x86 New Fork (PID: 5234, Parent: 5233)
      • sora.x86 New Fork (PID: 5389, Parent: 5234)
      • sora.x86 New Fork (PID: 5390, Parent: 5234)
        • sora.x86 New Fork (PID: 5391, Parent: 5390)
          • sora.x86 New Fork (PID: 5401, Parent: 5391)
          • sora.x86 New Fork (PID: 5402, Parent: 5391)
        • sora.x86 New Fork (PID: 5392, Parent: 5390)
        • sora.x86 New Fork (PID: 5393, Parent: 5390)
    • sora.x86 New Fork (PID: 5235, Parent: 5233)
    • sora.x86 New Fork (PID: 5236, Parent: 5233)
      • sora.x86 New Fork (PID: 5237, Parent: 5236)
        • sora.x86 New Fork (PID: 5381, Parent: 5237)
        • sora.x86 New Fork (PID: 5382, Parent: 5237)
      • sora.x86 New Fork (PID: 5238, Parent: 5236)
      • sora.x86 New Fork (PID: 5239, Parent: 5236)
  • systemd New Fork (PID: 5266, Parent: 1)
  • sshd (PID: 5266, Parent: 1, MD5: dbca7a6bbf7bf57fedac243d4b2cb340) Arguments: /usr/sbin/sshd -t
  • systemd New Fork (PID: 5267, Parent: 1)
  • sshd (PID: 5267, Parent: 1, MD5: dbca7a6bbf7bf57fedac243d4b2cb340) Arguments: /usr/sbin/sshd -D
  • systemd New Fork (PID: 5375, Parent: 1)
  • sshd (PID: 5375, Parent: 1, MD5: dbca7a6bbf7bf57fedac243d4b2cb340) Arguments: /usr/sbin/sshd -t
  • systemd New Fork (PID: 5376, Parent: 1)
  • sshd (PID: 5376, Parent: 1, MD5: dbca7a6bbf7bf57fedac243d4b2cb340) Arguments: /usr/sbin/sshd -D
  • systemd New Fork (PID: 5379, Parent: 1)
  • sshd (PID: 5379, Parent: 1, MD5: dbca7a6bbf7bf57fedac243d4b2cb340) Arguments: /usr/sbin/sshd -t
  • systemd New Fork (PID: 5380, Parent: 1)
  • sshd (PID: 5380, Parent: 1, MD5: dbca7a6bbf7bf57fedac243d4b2cb340) Arguments: /usr/sbin/sshd -D
  • cleanup

Yara Overview

PCAP (Network Traffic)

SourceRuleDescriptionAuthorStrings
dump.pcapJoeSecurity_Mirai_12Yara detected MiraiJoe Security

    Jbx Signature Overview

    Click to jump to signature section

    Show All Signature Results

    AV Detection:

    barindex
    Multi AV Scanner detection for submitted fileShow sources
    Source: sora.x86Virustotal: Detection: 37%Perma Link
    Source: sora.x86ReversingLabs: Detection: 46%

    Networking:

    barindex
    Snort IDS alert for network traffic (e.g. based on Emerging Threat rules)Show sources
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 212.125.30.65:23 -> 192.168.2.23:44938
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 212.125.30.65:23 -> 192.168.2.23:44938
    Source: TrafficSnort IDS: 716 INFO TELNET access 61.6.202.2:23 -> 192.168.2.23:44300
    Source: TrafficSnort IDS: 716 INFO TELNET access 218.188.97.1:23 -> 192.168.2.23:51970
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 212.125.30.65:23 -> 192.168.2.23:44962
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 212.125.30.65:23 -> 192.168.2.23:44962
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 61.6.202.2:23 -> 192.168.2.23:44300
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 61.6.202.2:23 -> 192.168.2.23:44300
    Source: TrafficSnort IDS: 716 INFO TELNET access 61.6.202.2:23 -> 192.168.2.23:44324
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 201.48.115.182:23 -> 192.168.2.23:44878
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 61.6.202.2:23 -> 192.168.2.23:44324
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 61.6.202.2:23 -> 192.168.2.23:44324
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 212.125.30.65:23 -> 192.168.2.23:45014
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 212.125.30.65:23 -> 192.168.2.23:45014
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 201.48.115.182:23 -> 192.168.2.23:44900
    Source: TrafficSnort IDS: 716 INFO TELNET access 61.6.202.2:23 -> 192.168.2.23:44388
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 212.125.30.65:23 -> 192.168.2.23:45066
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 212.125.30.65:23 -> 192.168.2.23:45066
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 61.6.202.2:23 -> 192.168.2.23:44388
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 61.6.202.2:23 -> 192.168.2.23:44388
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 201.48.115.182:23 -> 192.168.2.23:44962
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 201.48.115.182:23 -> 192.168.2.23:44972
    Source: TrafficSnort IDS: 716 INFO TELNET access 61.6.202.2:23 -> 192.168.2.23:44436
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 212.125.30.65:23 -> 192.168.2.23:45110
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 212.125.30.65:23 -> 192.168.2.23:45110
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 61.6.202.2:23 -> 192.168.2.23:44436
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 61.6.202.2:23 -> 192.168.2.23:44436
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 201.48.115.182:23 -> 192.168.2.23:45012
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 203.69.198.65:23 -> 192.168.2.23:40434
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 203.69.198.65:23 -> 192.168.2.23:40434
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 212.125.30.65:23 -> 192.168.2.23:45154
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 212.125.30.65:23 -> 192.168.2.23:45154
    Source: TrafficSnort IDS: 716 INFO TELNET access 61.6.202.2:23 -> 192.168.2.23:44504
    Source: TrafficSnort IDS: 2023449 ET TROJAN Possible Linux.Mirai Login Attempt (vizxv) 192.168.2.23:56484 -> 115.79.214.35:23
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 61.6.202.2:23 -> 192.168.2.23:44504
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 61.6.202.2:23 -> 192.168.2.23:44504
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 201.48.115.182:23 -> 192.168.2.23:45076
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 212.125.30.65:23 -> 192.168.2.23:45214
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 212.125.30.65:23 -> 192.168.2.23:45214
    Source: TrafficSnort IDS: 716 INFO TELNET access 61.6.202.2:23 -> 192.168.2.23:44552
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 61.6.202.2:23 -> 192.168.2.23:44552
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 61.6.202.2:23 -> 192.168.2.23:44552
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 212.125.30.65:23 -> 192.168.2.23:45236
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 212.125.30.65:23 -> 192.168.2.23:45236
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 201.48.115.182:23 -> 192.168.2.23:45098
    Source: TrafficSnort IDS: 716 INFO TELNET access 61.6.202.2:23 -> 192.168.2.23:44570
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 212.125.30.65:23 -> 192.168.2.23:45248
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 212.125.30.65:23 -> 192.168.2.23:45248
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 61.6.202.2:23 -> 192.168.2.23:44570
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 61.6.202.2:23 -> 192.168.2.23:44570
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 201.48.115.182:23 -> 192.168.2.23:45140
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 203.69.198.65:23 -> 192.168.2.23:40576
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 203.69.198.65:23 -> 192.168.2.23:40576
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 212.125.30.65:23 -> 192.168.2.23:45314
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 212.125.30.65:23 -> 192.168.2.23:45314
    Source: TrafficSnort IDS: 716 INFO TELNET access 61.6.202.2:23 -> 192.168.2.23:44644
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 201.48.115.182:23 -> 192.168.2.23:45194
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 61.6.202.2:23 -> 192.168.2.23:44644
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 61.6.202.2:23 -> 192.168.2.23:44644
    Source: TrafficSnort IDS: 716 INFO TELNET access 96.72.253.42:23 -> 192.168.2.23:60738
    Source: TrafficSnort IDS: 404 ICMP Destination Unreachable Protocol Unreachable 188.149.129.13: -> 192.168.2.23:
    Source: TrafficSnort IDS: 716 INFO TELNET access 190.15.104.241:23 -> 192.168.2.23:41706
    Source: TrafficSnort IDS: 716 INFO TELNET access 96.72.253.42:23 -> 192.168.2.23:60754
    Source: TrafficSnort IDS: 716 INFO TELNET access 61.6.202.2:23 -> 192.168.2.23:44702
    Source: TrafficSnort IDS: 2023448 ET TROJAN Possible Linux.Mirai Login Attempt (ubnt) 192.168.2.23:44702 -> 61.6.202.2:23
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 201.48.115.182:23 -> 192.168.2.23:45246
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 61.6.202.2:23 -> 192.168.2.23:44702
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 61.6.202.2:23 -> 192.168.2.23:44702
    Source: TrafficSnort IDS: 716 INFO TELNET access 61.6.202.2:23 -> 192.168.2.23:44736
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 61.6.202.2:23 -> 192.168.2.23:44736
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 61.6.202.2:23 -> 192.168.2.23:44736
    Source: TrafficSnort IDS: 716 INFO TELNET access 45.90.2.90:23 -> 192.168.2.23:41522
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 203.69.198.65:23 -> 192.168.2.23:40732
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 203.69.198.65:23 -> 192.168.2.23:40732
    Source: TrafficSnort IDS: 716 INFO TELNET access 77.40.12.104:23 -> 192.168.2.23:37576
    Source: TrafficSnort IDS: 716 INFO TELNET access 96.72.253.42:23 -> 192.168.2.23:60826
    Source: TrafficSnort IDS: 716 INFO TELNET access 77.40.12.104:23 -> 192.168.2.23:37590
    Source: TrafficSnort IDS: 716 INFO TELNET access 190.15.104.241:23 -> 192.168.2.23:41842
    Source: TrafficSnort IDS: 716 INFO TELNET access 77.40.12.104:23 -> 192.168.2.23:37632
    Source: TrafficSnort IDS: 716 INFO TELNET access 96.72.253.42:23 -> 192.168.2.23:60882
    Source: TrafficSnort IDS: 716 INFO TELNET access 77.40.12.104:23 -> 192.168.2.23:37644
    Source: TrafficSnort IDS: 716 INFO TELNET access 210.179.251.177:23 -> 192.168.2.23:48122
    Source: TrafficSnort IDS: 716 INFO TELNET access 77.40.12.104:23 -> 192.168.2.23:37682
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 210.179.251.177:23 -> 192.168.2.23:48122
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 210.179.251.177:23 -> 192.168.2.23:48122
    Source: TrafficSnort IDS: 716 INFO TELNET access 77.40.12.104:23 -> 192.168.2.23:37754
    Source: TrafficSnort IDS: 716 INFO TELNET access 77.40.12.104:23 -> 192.168.2.23:37778
    Source: TrafficSnort IDS: 716 INFO TELNET access 210.179.251.177:23 -> 192.168.2.23:48238
    Source: TrafficSnort IDS: 2023449 ET TROJAN Possible Linux.Mirai Login Attempt (vizxv) 192.168.2.23:54254 -> 115.75.98.226:23
    Source: TrafficSnort IDS: 716 INFO TELNET access 45.90.2.90:23 -> 192.168.2.23:41762
    Source: TrafficSnort IDS: 716 INFO TELNET access 77.40.12.104:23 -> 192.168.2.23:37796
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 210.179.251.177:23 -> 192.168.2.23:48238
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 210.179.251.177:23 -> 192.168.2.23:48238
    Source: TrafficSnort IDS: 716 INFO TELNET access 96.72.253.42:23 -> 192.168.2.23:32864
    Source: TrafficSnort IDS: 2023443 ET TROJAN Possible Linux.Mirai Login Attempt (klv123) 192.168.2.23:54296 -> 115.75.98.226:23
    Source: TrafficSnort IDS: 716 INFO TELNET access 77.40.12.104:23 -> 192.168.2.23:37828
    Source: TrafficSnort IDS: 716 INFO TELNET access 77.40.12.104:23 -> 192.168.2.23:37868
    Source: TrafficSnort IDS: 716 INFO TELNET access 103.173.6.15:23 -> 192.168.2.23:38582
    Source: TrafficSnort IDS: 716 INFO TELNET access 210.179.251.177:23 -> 192.168.2.23:48360
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 203.69.198.65:23 -> 192.168.2.23:41052
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 203.69.198.65:23 -> 192.168.2.23:41052
    Source: TrafficSnort IDS: 716 INFO TELNET access 190.15.104.241:23 -> 192.168.2.23:42132
    Source: TrafficSnort IDS: 716 INFO TELNET access 96.72.253.42:23 -> 192.168.2.23:32926
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 103.173.6.15:23 -> 192.168.2.23:38582
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 210.179.251.177:23 -> 192.168.2.23:48360
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 210.179.251.177:23 -> 192.168.2.23:48360
    Source: TrafficSnort IDS: 716 INFO TELNET access 103.173.6.15:23 -> 192.168.2.23:38676
    Source: TrafficSnort IDS: 716 INFO TELNET access 185.135.198.105:23 -> 192.168.2.23:34132
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 103.173.6.15:23 -> 192.168.2.23:38676
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 77.45.127.194:23 -> 192.168.2.23:40282
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 209.204.38.131:23 -> 192.168.2.23:55792
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 209.204.38.131:23 -> 192.168.2.23:55792
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 14.163.149.204:23 -> 192.168.2.23:40580
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 14.163.149.204:23 -> 192.168.2.23:40580
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 187.111.16.218:23 -> 192.168.2.23:34532
    Source: TrafficSnort IDS: 716 INFO TELNET access 210.179.251.177:23 -> 192.168.2.23:48548
    Source: TrafficSnort IDS: 716 INFO TELNET access 103.173.6.15:23 -> 192.168.2.23:38778
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 209.204.38.131:23 -> 192.168.2.23:55856
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 209.204.38.131:23 -> 192.168.2.23:55856
    Uses known network protocols on non-standard portsShow sources
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 45482
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 45488
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 45494
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 45498
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 45504
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 45508
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 45518
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 45526
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 45530
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 45536
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43404
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43406
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43408
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43410
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43412
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43414
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43418
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43422
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43424
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43426
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 55094
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 55102
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 55106
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 55114
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 55118
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 55122
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 55146
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 55148
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 55150
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 55156
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 41668
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 41672
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 41678
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 41680
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 41684
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 41692
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 41696
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 41698
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 41702
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 41706
    Source: global trafficTCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
    Source: global trafficTCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
    Source: global trafficTCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
    Source: global trafficTCP traffic: 192.168.2.23:34478 -> 163.172.46.83:1312
    Source: /usr/sbin/sshd (PID: 5267)Socket: 0.0.0.0::22
    Source: /usr/sbin/sshd (PID: 5267)Socket: [::]::22
    Source: /usr/sbin/sshd (PID: 5376)Socket: 0.0.0.0::22
    Source: /usr/sbin/sshd (PID: 5376)Socket: [::]::22
    Source: /usr/sbin/sshd (PID: 5380)Socket: 0.0.0.0::22
    Source: /usr/sbin/sshd (PID: 5380)Socket: [::]::22
    Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443
    Source: unknownTCP traffic detected without corresponding DNS query: 123.20.222.138
    Source: unknownTCP traffic detected without corresponding DNS query: 123.20.222.138
    Source: unknownTCP traffic detected without corresponding DNS query: 163.172.46.83
    Source: unknownTCP traffic detected without corresponding DNS query: 70.49.139.233
    Source: unknownTCP traffic detected without corresponding DNS query: 196.166.26.104
    Source: unknownTCP traffic detected without corresponding DNS query: 122.65.3.23
    Source: unknownTCP traffic detected without corresponding DNS query: 77.120.124.218
    Source: unknownTCP traffic detected without corresponding DNS query: 109.18.116.104
    Source: unknownTCP traffic detected without corresponding DNS query: 178.90.74.234
    Source: unknownTCP traffic detected without corresponding DNS query: 255.211.112.251
    Source: unknownTCP traffic detected without corresponding DNS query: 196.108.178.104
    Source: unknownTCP traffic detected without corresponding DNS query: 70.27.86.7
    Source: unknownTCP traffic detected without corresponding DNS query: 166.200.189.165
    Source: unknownTCP traffic detected without corresponding DNS query: 34.45.213.74
    Source: unknownTCP traffic detected without corresponding DNS query: 190.104.213.78
    Source: unknownTCP traffic detected without corresponding DNS query: 186.192.119.191
    Source: unknownTCP traffic detected without corresponding DNS query: 216.65.150.238
    Source: unknownTCP traffic detected without corresponding DNS query: 66.20.55.108
    Source: unknownTCP traffic detected without corresponding DNS query: 173.54.23.112
    Source: unknownTCP traffic detected without corresponding DNS query: 217.183.53.18
    Source: unknownTCP traffic detected without corresponding DNS query: 109.237.181.38
    Source: unknownTCP traffic detected without corresponding DNS query: 120.45.89.132
    Source: unknownTCP traffic detected without corresponding DNS query: 74.89.62.223
    Source: unknownTCP traffic detected without corresponding DNS query: 42.85.124.163
    Source: unknownTCP traffic detected without corresponding DNS query: 61.178.239.116
    Source: unknownTCP traffic detected without corresponding DNS query: 119.138.78.19
    Source: unknownTCP traffic detected without corresponding DNS query: 188.251.191.78
    Source: unknownTCP traffic detected without corresponding DNS query: 90.181.154.80
    Source: unknownTCP traffic detected without corresponding DNS query: 85.248.240.253
    Source: unknownTCP traffic detected without corresponding DNS query: 47.64.65.248
    Source: unknownTCP traffic detected without corresponding DNS query: 186.203.134.244
    Source: unknownTCP traffic detected without corresponding DNS query: 18.71.145.7
    Source: unknownTCP traffic detected without corresponding DNS query: 198.90.101.205
    Source: unknownTCP traffic detected without corresponding DNS query: 39.13.189.102
    Source: unknownTCP traffic detected without corresponding DNS query: 81.156.104.106
    Source: unknownTCP traffic detected without corresponding DNS query: 72.251.170.133
    Source: unknownTCP traffic detected without corresponding DNS query: 97.220.49.43
    Source: unknownTCP traffic detected without corresponding DNS query: 97.30.4.220
    Source: unknownTCP traffic detected without corresponding DNS query: 139.165.213.203
    Source: unknownTCP traffic detected without corresponding DNS query: 143.254.233.95
    Source: unknownTCP traffic detected without corresponding DNS query: 43.63.71.126
    Source: unknownTCP traffic detected without corresponding DNS query: 118.48.121.185
    Source: unknownTCP traffic detected without corresponding DNS query: 19.246.213.214
    Source: unknownTCP traffic detected without corresponding DNS query: 252.164.253.193
    Source: unknownTCP traffic detected without corresponding DNS query: 196.180.24.33
    Source: unknownTCP traffic detected without corresponding DNS query: 196.127.24.93
    Source: unknownTCP traffic detected without corresponding DNS query: 242.78.232.15
    Source: unknownTCP traffic detected without corresponding DNS query: 241.30.175.224
    Source: unknownTCP traffic detected without corresponding DNS query: 9.13.238.161
    Source: unknownTCP traffic detected without corresponding DNS query: 88.230.124.172
    Source: sora.x86String found in binary or memory: http://upx.sf.net

    System Summary:

    barindex
    Sample tries to kill many processes (SIGKILL)Show sources
    Source: /tmp/sora.x86 (PID: 5234)SIGKILL sent: pid: 720, result: successful
    Source: /tmp/sora.x86 (PID: 5234)SIGKILL sent: pid: 759, result: successful
    Source: /tmp/sora.x86 (PID: 5234)SIGKILL sent: pid: 788, result: successful
    Source: /tmp/sora.x86 (PID: 5234)SIGKILL sent: pid: 800, result: successful
    Source: /tmp/sora.x86 (PID: 5234)SIGKILL sent: pid: 847, result: successful
    Source: /tmp/sora.x86 (PID: 5234)SIGKILL sent: pid: 884, result: successful
    Source: /tmp/sora.x86 (PID: 5234)SIGKILL sent: pid: 1334, result: successful
    Source: /tmp/sora.x86 (PID: 5234)SIGKILL sent: pid: 1335, result: successful
    Source: /tmp/sora.x86 (PID: 5234)SIGKILL sent: pid: 1872, result: successful
    Source: /tmp/sora.x86 (PID: 5234)SIGKILL sent: pid: 2096, result: successful
    Source: /tmp/sora.x86 (PID: 5234)SIGKILL sent: pid: 2097, result: successful
    Source: /tmp/sora.x86 (PID: 5234)SIGKILL sent: pid: 2102, result: successful
    Source: /tmp/sora.x86 (PID: 5234)SIGKILL sent: pid: 2180, result: successful
    Source: /tmp/sora.x86 (PID: 5234)SIGKILL sent: pid: 2191, result: successful
    Source: /tmp/sora.x86 (PID: 5234)SIGKILL sent: pid: 2208, result: successful
    Source: /tmp/sora.x86 (PID: 5234)SIGKILL sent: pid: 2275, result: successful
    Source: /tmp/sora.x86 (PID: 5234)SIGKILL sent: pid: 2281, result: successful
    Source: /tmp/sora.x86 (PID: 5234)SIGKILL sent: pid: 2285, result: successful
    Source: /tmp/sora.x86 (PID: 5234)SIGKILL sent: pid: 2289, result: successful
    Source: /tmp/sora.x86 (PID: 5234)SIGKILL sent: pid: 2294, result: successful
    Source: /tmp/sora.x86 (PID: 5234)SIGKILL sent: pid: 5267, result: successful
    Source: /tmp/sora.x86 (PID: 5234)SIGKILL sent: pid: 5376, result: successful
    Source: /tmp/sora.x86 (PID: 5237)SIGKILL sent: pid: 936, result: successful
    Source: LOAD without section mappingsProgram segment: 0xc01000
    Source: /tmp/sora.x86 (PID: 5234)SIGKILL sent: pid: 720, result: successful
    Source: /tmp/sora.x86 (PID: 5234)SIGKILL sent: pid: 759, result: successful
    Source: /tmp/sora.x86 (PID: 5234)SIGKILL sent: pid: 788, result: successful
    Source: /tmp/sora.x86 (PID: 5234)SIGKILL sent: pid: 800, result: successful
    Source: /tmp/sora.x86 (PID: 5234)SIGKILL sent: pid: 847, result: successful
    Source: /tmp/sora.x86 (PID: 5234)SIGKILL sent: pid: 884, result: successful
    Source: /tmp/sora.x86 (PID: 5234)SIGKILL sent: pid: 1334, result: successful
    Source: /tmp/sora.x86 (PID: 5234)SIGKILL sent: pid: 1335, result: successful
    Source: /tmp/sora.x86 (PID: 5234)SIGKILL sent: pid: 1872, result: successful
    Source: /tmp/sora.x86 (PID: 5234)SIGKILL sent: pid: 2096, result: successful
    Source: /tmp/sora.x86 (PID: 5234)SIGKILL sent: pid: 2097, result: successful
    Source: /tmp/sora.x86 (PID: 5234)SIGKILL sent: pid: 2102, result: successful
    Source: /tmp/sora.x86 (PID: 5234)SIGKILL sent: pid: 2180, result: successful
    Source: /tmp/sora.x86 (PID: 5234)SIGKILL sent: pid: 2191, result: successful
    Source: /tmp/sora.x86 (PID: 5234)SIGKILL sent: pid: 2208, result: successful
    Source: /tmp/sora.x86 (PID: 5234)SIGKILL sent: pid: 2275, result: successful
    Source: /tmp/sora.x86 (PID: 5234)SIGKILL sent: pid: 2281, result: successful
    Source: /tmp/sora.x86 (PID: 5234)SIGKILL sent: pid: 2285, result: successful
    Source: /tmp/sora.x86 (PID: 5234)SIGKILL sent: pid: 2289, result: successful
    Source: /tmp/sora.x86 (PID: 5234)SIGKILL sent: pid: 2294, result: successful
    Source: /tmp/sora.x86 (PID: 5234)SIGKILL sent: pid: 5267, result: successful
    Source: /tmp/sora.x86 (PID: 5234)SIGKILL sent: pid: 5376, result: successful
    Source: /tmp/sora.x86 (PID: 5237)SIGKILL sent: pid: 936, result: successful
    Source: classification engineClassification label: mal76.spre.troj.evad.linX86@0/6@0/0
    Source: sora.x86Joe Sandbox Cloud Basic: Detection: clean Score: 0Perma Link

    Data Obfuscation:

    barindex
    Sample is packed with UPXShow sources
    Source: initial sampleString containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $
    Source: initial sampleString containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $
    Source: initial sampleString containing UPX found: $Id: UPX 3.94 Copyright (C) 1996-2017 the UPX Team. All Rights Reserved. $
    Source: /tmp/sora.x86 (PID: 5234)File opened: /proc/5267/exe
    Source: /tmp/sora.x86 (PID: 5234)File opened: /proc/1582/exe
    Source: /tmp/sora.x86 (PID: 5234)File opened: /proc/1582/fd
    Source: /tmp/sora.x86 (PID: 5234)File opened: /proc/2033/exe
    Source: /tmp/sora.x86 (PID: 5234)File opened: /proc/2033/fd
    Source: /tmp/sora.x86 (PID: 5234)File opened: /proc/2275/exe
    Source: /tmp/sora.x86 (PID: 5234)File opened: /proc/3088/exe
    Source: /tmp/sora.x86 (PID: 5234)File opened: /proc/1612/exe
    Source: /tmp/sora.x86 (PID: 5234)File opened: /proc/1612/fd
    Source: /tmp/sora.x86 (PID: 5234)File opened: /proc/1579/exe
    Source: /tmp/sora.x86 (PID: 5234)File opened: /proc/1579/fd
    Source: /tmp/sora.x86 (PID: 5234)File opened: /proc/1699/exe
    Source: /tmp/sora.x86 (PID: 5234)File opened: /proc/1699/fd
    Source: /tmp/sora.x86 (PID: 5234)File opened: /proc/1335/exe
    Source: /tmp/sora.x86 (PID: 5234)File opened: /proc/1698/exe
    Source: /tmp/sora.x86 (PID: 5234)File opened: /proc/1698/fd
    Source: /tmp/sora.x86 (PID: 5234)File opened: /proc/2028/exe
    Source: /tmp/sora.x86 (PID: 5234)File opened: /proc/2028/fd
    Source: /tmp/sora.x86 (PID: 5234)File opened: /proc/1334/exe
    Source: /tmp/sora.x86 (PID: 5234)File opened: /proc/1334/fd
    Source: /tmp/sora.x86 (PID: 5234)File opened: /proc/1576/exe
    Source: /tmp/sora.x86 (PID: 5234)File opened: /proc/1576/fd
    Source: /tmp/sora.x86 (PID: 5234)File opened: /proc/2302/exe
    Source: /tmp/sora.x86 (PID: 5234)File opened: /proc/2302/fd
    Source: /tmp/sora.x86 (PID: 5234)File opened: /proc/3236/exe
    Source: /tmp/sora.x86 (PID: 5234)File opened: /proc/3236/fd
    Source: /tmp/sora.x86 (PID: 5234)File opened: /proc/2025/exe
    Source: /tmp/sora.x86 (PID: 5234)File opened: /proc/2025/fd
    Source: /tmp/sora.x86 (PID: 5234)File opened: /proc/2146/exe
    Source: /tmp/sora.x86 (PID: 5234)File opened: /proc/2146/fd
    Source: /tmp/sora.x86 (PID: 5234)File opened: /proc/910/exe
    Source: /tmp/sora.x86 (PID: 5234)File opened: /proc/912/exe
    Source: /tmp/sora.x86 (PID: 5234)File opened: /proc/912/fd
    Source: /tmp/sora.x86 (PID: 5234)File opened: /proc/5139/exe
    Source: /tmp/sora.x86 (PID: 5234)File opened: /proc/517/exe
    Source: /tmp/sora.x86 (PID: 5234)File opened: /proc/759/exe
    Source: /tmp/sora.x86 (PID: 5234)File opened: /proc/759/fd
    Source: /tmp/sora.x86 (PID: 5234)File opened: /proc/2307/exe
    Source: /tmp/sora.x86 (PID: 5234)File opened: /proc/2307/fd
    Source: /tmp/sora.x86 (PID: 5234)File opened: /proc/918/exe
    Source: /tmp/sora.x86 (PID: 5234)File opened: /proc/918/fd
    Source: /tmp/sora.x86 (PID: 5234)File opened: /proc/5032/exe
    Source: /tmp/sora.x86 (PID: 5234)File opened: /proc/5153/exe
    Source: /tmp/sora.x86 (PID: 5234)File opened: /proc/4461/exe
    Source: /tmp/sora.x86 (PID: 5234)File opened: /proc/1594/exe
    Source: /tmp/sora.x86 (PID: 5234)File opened: /proc/1594/fd
    Source: /tmp/sora.x86 (PID: 5234)File opened: /proc/2285/exe
    Source: /tmp/sora.x86 (PID: 5234)File opened: /proc/2281/exe
    Source: /tmp/sora.x86 (PID: 5234)File opened: /proc/1349/exe
    Source: /tmp/sora.x86 (PID: 5234)File opened: /proc/1349/fd
    Source: /tmp/sora.x86 (PID: 5234)File opened: /proc/1623/exe
    Source: /tmp/sora.x86 (PID: 5234)File opened: /proc/1623/fd
    Source: /tmp/sora.x86 (PID: 5234)File opened: /proc/1/fd
    Source: /tmp/sora.x86 (PID: 5234)File opened: /proc/761/exe
    Source: /tmp/sora.x86 (PID: 5234)File opened: /proc/761/fd
    Source: /tmp/sora.x86 (PID: 5234)File opened: /proc/1622/exe
    Source: /tmp/sora.x86 (PID: 5234)File opened: /proc/1622/fd
    Source: /tmp/sora.x86 (PID: 5234)File opened: /proc/884/exe
    Source: /tmp/sora.x86 (PID: 5234)File opened: /proc/1983/exe
    Source: /tmp/sora.x86 (PID: 5234)File opened: /proc/1983/fd
    Source: /tmp/sora.x86 (PID: 5234)File opened: /proc/2038/exe
    Source: /tmp/sora.x86 (PID: 5234)File opened: /proc/2038/fd
    Source: /tmp/sora.x86 (PID: 5234)File opened: /proc/1344/exe
    Source: /tmp/sora.x86 (PID: 5234)File opened: /proc/1344/fd
    Source: /tmp/sora.x86 (PID: 5234)File opened: /proc/1465/exe
    Source: /tmp/sora.x86 (PID: 5234)File opened: /proc/1465/fd
    Source: /tmp/sora.x86 (PID: 5234)File opened: /proc/1586/exe
    Source: /tmp/sora.x86 (PID: 5234)File opened: /proc/1586/fd
    Source: /tmp/sora.x86 (PID: 5234)File opened: /proc/1860/fd
    Source: /tmp/sora.x86 (PID: 5234)File opened: /proc/1463/exe
    Source: /tmp/sora.x86 (PID: 5234)File opened: /proc/1463/fd
    Source: /tmp/sora.x86 (PID: 5234)File opened: /proc/2156/exe
    Source: /tmp/sora.x86 (PID: 5234)File opened: /proc/2156/fd
    Source: /tmp/sora.x86 (PID: 5234)File opened: /proc/800/exe
    Source: /tmp/sora.x86 (PID: 5234)File opened: /proc/800/fd
    Source: /tmp/sora.x86 (PID: 5234)File opened: /proc/4455/exe
    Source: /tmp/sora.x86 (PID: 5234)File opened: /proc/5148/exe
    Source: /tmp/sora.x86 (PID: 5234)File opened: /proc/801/exe
    Source: /tmp/sora.x86 (PID: 5234)File opened: /proc/801/fd
    Source: /tmp/sora.x86 (PID: 5234)File opened: /proc/4456/exe
    Source: /tmp/sora.x86 (PID: 5234)File opened: /proc/4457/exe
    Source: /tmp/sora.x86 (PID: 5234)File opened: /proc/1629/exe
    Source: /tmp/sora.x86 (PID: 5234)File opened: /proc/1629/fd
    Source: /tmp/sora.x86 (PID: 5234)File opened: /proc/4458/exe
    Source: /tmp/sora.x86 (PID: 5234)File opened: /proc/1627/exe
    Source: /tmp/sora.x86 (PID: 5234)File opened: /proc/1627/fd
    Source: /tmp/sora.x86 (PID: 5234)File opened: /proc/1900/exe
    Source: /tmp/sora.x86 (PID: 5234)File opened: /proc/1900/fd
    Source: /tmp/sora.x86 (PID: 5234)File opened: /proc/5200/exe
    Source: /tmp/sora.x86 (PID: 5234)File opened: /proc/5200/fd
    Source: /tmp/sora.x86 (PID: 5234)File opened: /proc/3021/exe
    Source: /tmp/sora.x86 (PID: 5234)File opened: /proc/491/exe
    Source: /tmp/sora.x86 (PID: 5234)File opened: /proc/491/fd
    Source: /tmp/sora.x86 (PID: 5234)File opened: /proc/2294/exe
    Source: /tmp/sora.x86 (PID: 5234)File opened: /proc/2050/exe
    Source: /tmp/sora.x86 (PID: 5234)File opened: /proc/2050/fd
    Source: /tmp/sora.x86 (PID: 5234)File opened: /proc/1877/exe
    Source: /tmp/sora.x86 (PID: 5234)File opened: /proc/1877/fd
    Source: /tmp/sora.x86 (PID: 5234)File opened: /proc/772/exe
    Source: /tmp/sora.x86 (PID: 5234)File opened: /proc/772/fd
    Source: /tmp/sora.x86 (PID: 5234)File opened: /proc/1633/exe
    Source: /tmp/sora.x86 (PID: 5234)File opened: /proc/1633/fd
    Source: /tmp/sora.x86 (PID: 5234)File opened: /proc/1599/exe
    Source: /tmp/sora.x86 (PID: 5234)File opened: /proc/1599/fd
    Source: /tmp/sora.x86 (PID: 5234)File opened: /proc/1632/exe
    Source: /tmp/sora.x86 (PID: 5234)File opened: /proc/1632/fd

    Hooking and other Techniques for Hiding and Protection:

    barindex
    Uses known network protocols on non-standard portsShow sources
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 45482
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 45488
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 45494
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 45498
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 45504
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 45508
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 45518
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 45526
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 45530
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 45536
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43404
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43406
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43408
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43410
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43412
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43414
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43418
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43422
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43424
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43426
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 55094
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 55102
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 55106
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 55114
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 55118
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 55122
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 55146
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 55148
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 55150
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 55156
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 41668
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 41672
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 41678
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 41680
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 41684
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 41692
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 41696
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 41698
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 41702
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 41706

    Stealing of Sensitive Information:

    barindex
    Yara detected MiraiShow sources
    Source: Yara matchFile source: dump.pcap, type: PCAP

    Remote Access Functionality:

    barindex
    Yara detected MiraiShow sources
    Source: Yara matchFile source: dump.pcap, type: PCAP

    Mitre Att&ck Matrix

    Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
    Valid AccountsWindows Management InstrumentationPath InterceptionPath InterceptionObfuscated Files or Information1OS Credential Dumping1System Service DiscoveryRemote ServicesData from Local SystemExfiltration Over Other Network MediumEncrypted Channel1Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
    Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over BluetoothNon-Standard Port11Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
    Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated ExfiltrationApplication Layer Protocol1Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data

    Malware Configuration

    No configs have been found

    Behavior Graph

    Hide Legend

    Legend:

    • Process
    • Signature
    • Created File
    • DNS/IP Info
    • Is Dropped
    • Number of created Files
    • Is malicious
    • Internet
    behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 513641 Sample: sora.x86 Startdate: 02/11/2021 Architecture: LINUX Score: 76 50 152.113.180.158 WA-STATE-GOVUS United States 2->50 52 37.177.86.214 VODAFONE-IT-ASNIT Italy 2->52 54 98 other IPs or domains 2->54 58 Snort IDS alert for network traffic (e.g. based on Emerging Threat rules) 2->58 60 Multi AV Scanner detection for submitted file 2->60 62 Yara detected Mirai 2->62 64 2 other signatures 2->64 10 sora.x86 2->10         started        12 systemd sshd 2->12         started        14 systemd sshd 2->14         started        16 4 other processes 2->16 signatures3 process4 process5 18 sora.x86 10->18         started        21 sora.x86 10->21         started        23 sora.x86 10->23         started        signatures6 56 Sample tries to kill many processes (SIGKILL) 18->56 25 sora.x86 18->25         started        27 sora.x86 18->27         started        29 sora.x86 21->29         started        32 sora.x86 21->32         started        34 sora.x86 21->34         started        process7 signatures8 36 sora.x86 25->36         started        38 sora.x86 25->38         started        40 sora.x86 25->40         started        66 Sample tries to kill many processes (SIGKILL) 29->66 42 sora.x86 29->42         started        44 sora.x86 29->44         started        process9 process10 46 sora.x86 36->46         started        48 sora.x86 36->48         started       

    Screenshots

    Thumbnails

    This section contains all screenshots as thumbnails, including those not shown in the slideshow.

    windows-stand

    Antivirus, Machine Learning and Genetic Malware Detection

    Initial Sample

    SourceDetectionScannerLabelLink
    sora.x8638%VirustotalBrowse
    sora.x8647%ReversingLabsLinux.Trojan.Mirai

    Dropped Files

    No Antivirus matches

    Domains

    No Antivirus matches

    URLs

    No Antivirus matches

    Domains and IPs

    Contacted Domains

    No contacted domains info

    URLs from Memory and Binaries

    NameSourceMaliciousAntivirus DetectionReputation
    http://upx.sf.netsora.x86false
      high

      Contacted IPs

      • No. of IPs < 25%
      • 25% < No. of IPs < 50%
      • 50% < No. of IPs < 75%
      • 75% < No. of IPs

      Public

      IPDomainCountryFlagASNASN NameMalicious
      165.14.150.75
      unknownJapan18271EVONETSojitzSystemsCorporationJPfalse
      2.98.202.30
      unknownUnited Kingdom
      13285OPALTELECOM-ASTalkTalkCommunicationsLimitedGBfalse
      1.241.64.41
      unknownKorea Republic of
      38408GOEAY-AS-KRGYEONGGIPROVINCIALANYANGOFFICEOFEDUCATIONfalse
      126.27.223.237
      unknownJapan17676GIGAINFRASoftbankBBCorpJPfalse
      167.244.146.157
      unknownUnited States
      13325STOMIUSfalse
      148.49.170.205
      unknownUnited States
      721DNIC-ASBLK-00721-00726USfalse
      37.177.86.214
      unknownItaly
      30722VODAFONE-IT-ASNITfalse
      59.166.102.220
      unknownJapan9824JTCL-JP-ASJupiterTelecommunicationCoLtdJPfalse
      44.7.130.188
      unknownUnited States
      7377UCSDUSfalse
      113.54.159.201
      unknownChina
      24355CNGI-CD-IX-AS-APCERNET2IXatUniversityofElectronicSciefalse
      146.15.235.153
      unknownUnited States
      1467DNIC-ASBLK-01467-01468USfalse
      166.203.133.216
      unknownUnited States
      20057ATT-MOBILITY-LLC-AS20057USfalse
      251.188.124.239
      unknownReserved
      unknownunknownfalse
      210.85.191.211
      unknownTaiwan; Republic of China (ROC)
      7482APOL-ASAsiaPacificOn-lineServiceIncTWfalse
      204.62.73.110
      unknownUnited States
      22773ASN-CXA-ALL-CCI-22773-RDCUSfalse
      114.239.158.155
      unknownChina
      4134CHINANET-BACKBONENo31Jin-rongStreetCNfalse
      41.14.214.51
      unknownSouth Africa
      29975VODACOM-ZAfalse
      113.124.222.249
      unknownChina
      4134CHINANET-BACKBONENo31Jin-rongStreetCNfalse
      210.110.95.218
      unknownKorea Republic of
      4766KIXS-AS-KRKoreaTelecomKRfalse
      162.30.206.148
      unknownUnited States
      46483RGHSUSfalse
      177.70.141.190
      unknownBrazil
      266555ISPNETTELECOMUNICACOESLTDA-EPPBRfalse
      219.240.106.33
      unknownKorea Republic of
      9318SKB-ASSKBroadbandCoLtdKRfalse
      172.215.195.50
      unknownUnited States
      18747IFX18747USfalse
      201.240.238.10
      unknownPeru
      6147TelefonicadelPeruSAAPEfalse
      31.67.116.133
      unknownUnited Kingdom
      12576EELtdGBfalse
      71.111.121.46
      unknownUnited States
      701UUNETUSfalse
      88.248.29.110
      unknownTurkey
      9121TTNETTRfalse
      38.93.85.255
      unknownUnited States
      174COGENT-174USfalse
      41.115.200.72
      unknownSouth Africa
      16637MTNNS-ASZAfalse
      4.54.18.94
      unknownUnited States
      3356LEVEL3USfalse
      16.85.71.175
      unknownUnited States
      unknownunknownfalse
      74.33.14.3
      unknownUnited States
      7011FRONTIER-AND-CITIZENSUSfalse
      218.21.160.20
      unknownChina
      4837CHINA169-BACKBONECHINAUNICOMChina169BackboneCNfalse
      147.175.253.12
      unknownSlovakia (SLOVAK Republic)
      2607SANETSlovakAcademicNetworkSKfalse
      159.114.114.114
      unknownUnited Kingdom
      32982DOE-HQUSfalse
      18.68.25.132
      unknownUnited States
      3MIT-GATEWAYSUSfalse
      133.80.8.221
      unknownJapan55904KOGAKUIN-ASKOGAKUINUniversityJPfalse
      118.14.181.61
      unknownJapan4713OCNNTTCommunicationsCorporationJPfalse
      119.59.136.138
      unknownChina
      17816CHINA169-GZChinaUnicomIPnetworkChina169Guangdongprovifalse
      24.150.2.237
      unknownCanada
      7992COGECOWAVECAfalse
      103.190.121.18
      unknownunknown
      7575AARNET-AS-APAustralianAcademicandResearchNetworkAARNefalse
      126.109.127.55
      unknownJapan17676GIGAINFRASoftbankBBCorpJPfalse
      66.210.247.106
      unknownUnited States
      22773ASN-CXA-ALL-CCI-22773-RDCUSfalse
      152.113.180.158
      unknownUnited States
      4193WA-STATE-GOVUSfalse
      121.81.167.8
      unknownJapan17511OPTAGEOPTAGEIncJPfalse
      12.10.152.124
      unknownUnited States
      7018ATT-INTERNET4USfalse
      217.4.22.110
      unknownGermany
      3320DTAGInternetserviceprovideroperationsDEfalse
      44.100.131.207
      unknownUnited States
      7377UCSDUSfalse
      14.98.128.139
      unknownIndia
      45820TTSL-MEISISPTataTeleservicesISPASINfalse
      20.95.97.146
      unknownUnited States
      8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
      1.109.50.131
      unknownKorea Republic of
      4766KIXS-AS-KRKoreaTelecomKRfalse
      68.15.246.54
      unknownUnited States
      22773ASN-CXA-ALL-CCI-22773-RDCUSfalse
      59.121.20.32
      unknownTaiwan; Republic of China (ROC)
      3462HINETDataCommunicationBusinessGroupTWfalse
      34.26.63.252
      unknownUnited States
      2686ATGS-MMD-ASUSfalse
      92.203.254.252
      unknownJapan2527SO-NETSo-netEntertainmentCorporationJPfalse
      97.110.251.226
      unknownCanada
      812ROGERS-COMMUNICATIONSCAfalse
      203.175.188.145
      unknownKorea Republic of
      9693KFTCCA-ASKFTCKRfalse
      65.29.134.160
      unknownUnited States
      10796TWC-10796-MIDWESTUSfalse
      1.253.209.220
      unknownKorea Republic of
      9318SKB-ASSKBroadbandCoLtdKRfalse
      72.187.61.178
      unknownUnited States
      33363BHN-33363USfalse
      221.232.6.12
      unknownChina
      4134CHINANET-BACKBONENo31Jin-rongStreetCNfalse
      200.103.220.0
      unknownBrazil
      8167BrasilTelecomSA-FilialDistritoFederalBRfalse
      86.14.157.185
      unknownUnited Kingdom
      5089NTLGBfalse
      248.243.251.91
      unknownReserved
      unknownunknownfalse
      213.29.127.118
      unknownCzech Republic
      5588GTSCEGTSCentralEuropeAntelGermanyCZfalse
      247.120.54.225
      unknownReserved
      unknownunknownfalse
      101.163.182.162
      unknownAustralia
      1221ASN-TELSTRATelstraCorporationLtdAUfalse
      191.234.39.21
      unknownBrazil
      8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
      152.160.245.116
      unknownUnited States
      54163AHOSTINGUSfalse
      220.158.204.12
      unknownBangladesh
      134712PIPEXNETWORK-BDPipexNetworkBDfalse
      192.198.234.232
      unknownUnited States
      53468FWLUSfalse
      73.94.134.111
      unknownUnited States
      7922COMCAST-7922USfalse
      251.234.221.195
      unknownReserved
      unknownunknownfalse
      102.174.105.188
      unknownTunisia
      37693TUNISIANATNfalse
      252.43.179.218
      unknownReserved
      unknownunknownfalse
      13.233.103.202
      unknownUnited States
      16509AMAZON-02USfalse
      46.142.137.7
      unknownGermany
      8881VERSATELDEfalse
      90.134.166.190
      unknownSweden
      1257TELE2EUfalse
      110.167.231.74
      unknownChina
      4134CHINANET-BACKBONENo31Jin-rongStreetCNfalse
      92.26.2.148
      unknownUnited Kingdom
      13285OPALTELECOM-ASTalkTalkCommunicationsLimitedGBfalse
      179.227.126.169
      unknownBrazil
      26599TELEFONICABRASILSABRfalse
      103.57.64.14
      unknownunknown
      134179RWN-AS-APRealWorldNetworksPtyLtdAUfalse
      94.16.9.82
      unknownGermany
      42360SSP-EUROPEpoweredbyANXDEfalse
      27.160.78.186
      unknownKorea Republic of
      9644SKTELECOM-NET-ASSKTelecomKRfalse
      200.226.149.233
      unknownBrazil
      51964ORANGE-BUSINESS-SERVICES-IPSN-ASNFRfalse
      16.97.163.5
      unknownUnited States
      unknownunknownfalse
      42.198.166.181
      unknownChina
      7497CSTNET-AS-APComputerNetworkInformationCenterCNfalse
      71.112.18.152
      unknownUnited States
      701UUNETUSfalse
      112.219.5.116
      unknownKorea Republic of
      3786LGDACOMLGDACOMCorporationKRfalse
      59.28.140.225
      unknownKorea Republic of
      4766KIXS-AS-KRKoreaTelecomKRfalse
      158.198.246.29
      unknownJapan17511OPTAGEOPTAGEIncJPfalse
      254.122.33.192
      unknownReserved
      unknownunknownfalse
      87.180.143.9
      unknownGermany
      3320DTAGInternetserviceprovideroperationsDEfalse
      45.49.77.34
      unknownUnited States
      20001TWC-20001-PACWESTUSfalse
      153.49.4.136
      unknownUnited States
      1226CTA-42-AS1226USfalse
      98.39.201.51
      unknownUnited States
      7922COMCAST-7922USfalse
      110.203.9.8
      unknownChina
      9394CTTNETChinaTieTongTelecommunicationsCorporationCNfalse
      146.20.63.85
      unknownUnited States
      27357RACKSPACEUSfalse
      96.59.177.46
      unknownUnited States
      33363BHN-33363USfalse
      70.84.162.139
      unknownUnited States
      36351SOFTLAYERUSfalse


      Runtime Messages

      Command:/tmp/sora.x86
      Exit Code:0
      Exit Code Info:
      Killed:False
      Standard Output:
      Connected To CNC
      Standard Error:

      Joe Sandbox View / Context

      IPs

      No context

      Domains

      No context

      ASN

      MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
      EVONETSojitzSystemsCorporationJPsora.arm7Get hashmaliciousBrowse
      • 165.14.149.81
      4syAQhYxm8Get hashmaliciousBrowse
      • 165.14.198.42
      sora.arm7Get hashmaliciousBrowse
      • 165.14.73.241
      sora.arm7Get hashmaliciousBrowse
      • 165.14.198.31
      qJvDfzBXbsGet hashmaliciousBrowse
      • 165.14.137.77
      wnwO8B1WuyGet hashmaliciousBrowse
      • 165.14.198.25
      AJK7j832D2Get hashmaliciousBrowse
      • 165.14.150.39
      GMgREghUdsGet hashmaliciousBrowse
      • 165.14.160.111
      tMA66IeqHuGet hashmaliciousBrowse
      • 165.14.168.212
      Vs7Vm7J1TRGet hashmaliciousBrowse
      • 165.14.198.59
      ppc_unpackedGet hashmaliciousBrowse
      • 165.14.174.79
      OPALTELECOM-ASTalkTalkCommunicationsLimitedGBwt5i2fAcF0Get hashmaliciousBrowse
      • 78.145.16.154
      8PRjJeUifBGet hashmaliciousBrowse
      • 92.18.133.105
      Ko84iLip1uGet hashmaliciousBrowse
      • 92.3.236.146
      S8G5z3pdHwGet hashmaliciousBrowse
      • 92.24.64.128
      mP1pg0ryFAGet hashmaliciousBrowse
      • 2.100.134.151
      032k4JmR0UGet hashmaliciousBrowse
      • 92.13.106.251
      x86Get hashmaliciousBrowse
      • 2.97.101.112
      T0uznhDXKwGet hashmaliciousBrowse
      • 92.29.90.175
      ev1JsPbdMAGet hashmaliciousBrowse
      • 92.24.16.217
      apep.armGet hashmaliciousBrowse
      • 92.7.19.93
      apep.x86Get hashmaliciousBrowse
      • 92.16.44.106
      Ceji2MdFHDGet hashmaliciousBrowse
      • 2.98.204.126
      Z7QqCH0bakGet hashmaliciousBrowse
      • 92.14.197.224
      zouBbQwUTbGet hashmaliciousBrowse
      • 92.24.15.58
      jJ6GK5qbZtGet hashmaliciousBrowse
      • 92.26.100.228
      LCgNoeCOl6Get hashmaliciousBrowse
      • 92.18.133.136
      x86_64Get hashmaliciousBrowse
      • 2.98.162.217
      apep.x86Get hashmaliciousBrowse
      • 92.24.40.60
      yOtRXukeq9Get hashmaliciousBrowse
      • 92.21.79.215
      b3astmode.x86Get hashmaliciousBrowse
      • 78.146.187.95
      GOEAY-AS-KRGYEONGGIPROVINCIALANYANGOFFICEOFEDUCATIONivImhRZqGaGet hashmaliciousBrowse
      • 1.241.39.53
      dAhGa49LqlGet hashmaliciousBrowse
      • 1.241.41.126
      qINZ8rxy9SGet hashmaliciousBrowse
      • 61.77.19.135
      22kfSzInJiGet hashmaliciousBrowse
      • 1.241.39.66
      O1qCIp2iQSGet hashmaliciousBrowse
      • 1.241.64.50
      l6zn4I2gR0Get hashmaliciousBrowse
      • 1.241.64.38
      WdyAWwF87eGet hashmaliciousBrowse
      • 1.241.64.43

      JA3 Fingerprints

      No context

      Dropped Files

      No context

      Created / dropped Files

      /proc/5267/oom_score_adj
      Process:/usr/sbin/sshd
      File Type:ASCII text
      Category:dropped
      Size (bytes):6
      Entropy (8bit):1.7924812503605778
      Encrypted:false
      SSDEEP:3:ptn:Dn
      MD5:CBF282CC55ED0792C33D10003D1F760A
      SHA1:007DD8BD75468E6B7ABA4285E9B267202C7EAEED
      SHA-256:FCDBAB99FCC0F4409E5F9D7D6FC497780288B4C441698126BB62832412774D22
      SHA-512:4643A8675D213C7DA35CC0C2BFB3B6F20324F9C48AEA7BA79F470615698C9A0CEFDA45CAA1957FC29110EE746BC8458AB8AB1E43EB513912A5E1E8858812CC00
      Malicious:false
      Reputation:high, very likely benign file
      Preview: -1000.
      /proc/5376/oom_score_adj
      Process:/usr/sbin/sshd
      File Type:ASCII text
      Category:dropped
      Size (bytes):6
      Entropy (8bit):1.7924812503605778
      Encrypted:false
      SSDEEP:3:ptn:Dn
      MD5:CBF282CC55ED0792C33D10003D1F760A
      SHA1:007DD8BD75468E6B7ABA4285E9B267202C7EAEED
      SHA-256:FCDBAB99FCC0F4409E5F9D7D6FC497780288B4C441698126BB62832412774D22
      SHA-512:4643A8675D213C7DA35CC0C2BFB3B6F20324F9C48AEA7BA79F470615698C9A0CEFDA45CAA1957FC29110EE746BC8458AB8AB1E43EB513912A5E1E8858812CC00
      Malicious:false
      Reputation:high, very likely benign file
      Preview: -1000.
      /proc/5380/oom_score_adj
      Process:/usr/sbin/sshd
      File Type:ASCII text
      Category:dropped
      Size (bytes):6
      Entropy (8bit):1.7924812503605778
      Encrypted:false
      SSDEEP:3:ptn:Dn
      MD5:CBF282CC55ED0792C33D10003D1F760A
      SHA1:007DD8BD75468E6B7ABA4285E9B267202C7EAEED
      SHA-256:FCDBAB99FCC0F4409E5F9D7D6FC497780288B4C441698126BB62832412774D22
      SHA-512:4643A8675D213C7DA35CC0C2BFB3B6F20324F9C48AEA7BA79F470615698C9A0CEFDA45CAA1957FC29110EE746BC8458AB8AB1E43EB513912A5E1E8858812CC00
      Malicious:false
      Reputation:high, very likely benign file
      Preview: -1000.
      /run/sshd.pid
      Process:/usr/sbin/sshd
      File Type:ASCII text
      Category:dropped
      Size (bytes):5
      Entropy (8bit):2.321928094887362
      Encrypted:false
      SSDEEP:3:DdVv:BVv
      MD5:2522E7CF829C2CEFC020B7B06A1C99C7
      SHA1:980DD56DC2FBFF129C6F3055C60599D46546A0B0
      SHA-256:E6CFA4E1AB3F5790C61A85FC6494DE44BB8D493753E3E3C31771A9C9AA7D1FB4
      SHA-512:DA266D5D96070400172644D2650ACF3EC3F52F48C1558C519E0A218A93B457B569B11917DD92C8B05144A79080BC53E1040576B0DC4E8D47B0AE4E0508CEA3E3
      Malicious:false
      Reputation:low
      Preview: 5380.

      Static File Info

      General

      File type:ELF 32-bit LSB executable, Intel 80386, version 1 (GNU/Linux), statically linked, stripped
      Entropy (8bit):7.8717761813776965
      TrID:
      • ELF Executable and Linkable format (Linux) (4029/14) 50.16%
      • ELF Executable and Linkable format (generic) (4004/1) 49.84%
      File name:sora.x86
      File size:24728
      MD5:ec0785f99de2a1ea900d48a9bb26bf1c
      SHA1:bdabfc4ef8c6e050ba2a88927ac9429bd71813c9
      SHA256:30ad105f506c59e85005c99f64fcfc577c2a51caf131bc9f57e5172a404654d3
      SHA512:4a3d6fba5292e86f1471b2d411954e950688522b891e6d827fd89aa621a087e953b544dd268aaacc9913807e036154568fb06115741ca71c85f8acb9d8e68cb1
      SSDEEP:384:M8DKKQOcRpmYLdn6RBOFRFt5rUFX1DiSIlCo3AnupCFNqnrrd1NEZgO8UXWozPLu:R/QOC0Yhn6ROHWFlAcwNEFCnNBxcsce
      File Content Preview:.ELF.....................g..4...........4. ...(......................_..._...................W...W..................Q.td...............................tUPX!....................Z........?d..ELF.......d.......4.,..4. (.......k.-.#.`...........?..P......d..l

      Static ELF Info

      ELF header

      Class:ELF32
      Data:2's complement, little endian
      Version:1 (current)
      Machine:Intel 80386
      Version Number:0x1
      Type:EXEC (Executable file)
      OS/ABI:UNIX - Linux
      ABI Version:0
      Entry Point Address:0xc067a0
      Flags:0x0
      ELF Header Size:52
      Program Header Offset:52
      Program Header Size:32
      Number of Program Headers:3
      Section Header Offset:0
      Section Header Size:40
      Number of Section Headers:0
      Header String Table Index:0

      Program Segments

      TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
      LOAD0x00xc010000xc010000x5f9b0x5f9b4.55560x5R E0x1000
      LOAD0x7000x80557000x80557000x00x00.00000x6RW 0x1000
      GNU_STACK0x00x00x00x00x00.00000x6RW 0x4

      Network Behavior

      Network Port Distribution

      TCP Packets

      TimestampSource PortDest PortSource IPDest IP
      Nov 2, 2021 12:13:38.527992010 CET2346374123.20.222.138192.168.2.23
      Nov 2, 2021 12:13:38.528105021 CET4637423192.168.2.23123.20.222.138
      Nov 2, 2021 12:13:38.528399944 CET2346374123.20.222.138192.168.2.23
      Nov 2, 2021 12:13:38.528467894 CET4637423192.168.2.23123.20.222.138
      Nov 2, 2021 12:13:38.743113041 CET344781312192.168.2.23163.172.46.83
      Nov 2, 2021 12:13:38.743393898 CET5180923192.168.2.2370.49.139.233
      Nov 2, 2021 12:13:38.743393898 CET5180923192.168.2.23196.166.26.104
      Nov 2, 2021 12:13:38.743428946 CET5180923192.168.2.23122.65.3.23
      Nov 2, 2021 12:13:38.743431091 CET5180923192.168.2.2377.120.124.218
      Nov 2, 2021 12:13:38.743433952 CET5180923192.168.2.23109.18.116.104
      Nov 2, 2021 12:13:38.743441105 CET5180923192.168.2.23178.90.74.234
      Nov 2, 2021 12:13:38.743442059 CET5180923192.168.2.23255.211.112.251
      Nov 2, 2021 12:13:38.743446112 CET5180923192.168.2.23196.108.178.104
      Nov 2, 2021 12:13:38.743462086 CET5180923192.168.2.2370.27.86.7
      Nov 2, 2021 12:13:38.743467093 CET5180923192.168.2.23166.200.189.165
      Nov 2, 2021 12:13:38.743474007 CET5180923192.168.2.2334.45.213.74
      Nov 2, 2021 12:13:38.743474960 CET5180923192.168.2.23190.104.213.78
      Nov 2, 2021 12:13:38.743490934 CET5180923192.168.2.23186.192.119.191
      Nov 2, 2021 12:13:38.743493080 CET5180923192.168.2.23216.65.150.238
      Nov 2, 2021 12:13:38.743499041 CET5180923192.168.2.2366.20.55.108
      Nov 2, 2021 12:13:38.743498087 CET5180923192.168.2.23173.54.23.112
      Nov 2, 2021 12:13:38.743503094 CET5180923192.168.2.23217.183.53.18
      Nov 2, 2021 12:13:38.743519068 CET5180923192.168.2.23109.237.181.38
      Nov 2, 2021 12:13:38.743519068 CET5180923192.168.2.23120.45.89.132
      Nov 2, 2021 12:13:38.743529081 CET5180923192.168.2.2374.89.62.223
      Nov 2, 2021 12:13:38.743532896 CET5180923192.168.2.2342.85.124.163
      Nov 2, 2021 12:13:38.743532896 CET5180923192.168.2.2361.178.239.116
      Nov 2, 2021 12:13:38.743550062 CET5180923192.168.2.23119.138.78.19
      Nov 2, 2021 12:13:38.743567944 CET5180923192.168.2.23188.251.191.78
      Nov 2, 2021 12:13:38.743575096 CET5180923192.168.2.2390.181.154.80
      Nov 2, 2021 12:13:38.743607998 CET5180923192.168.2.2312.44.110.127
      Nov 2, 2021 12:13:38.743618011 CET5180923192.168.2.2385.248.240.253
      Nov 2, 2021 12:13:38.743623972 CET5180923192.168.2.2347.64.65.248
      Nov 2, 2021 12:13:38.743633986 CET5180923192.168.2.23186.203.134.244
      Nov 2, 2021 12:13:38.743647099 CET5180923192.168.2.2390.204.10.215
      Nov 2, 2021 12:13:38.743650913 CET5180923192.168.2.2318.71.145.7
      Nov 2, 2021 12:13:38.743660927 CET5180923192.168.2.23198.90.101.205
      Nov 2, 2021 12:13:38.743664026 CET5180923192.168.2.2339.13.189.102
      Nov 2, 2021 12:13:38.743670940 CET5180923192.168.2.2381.156.104.106
      Nov 2, 2021 12:13:38.743678093 CET5180923192.168.2.2372.251.170.133
      Nov 2, 2021 12:13:38.743680000 CET5180923192.168.2.2397.220.49.43
      Nov 2, 2021 12:13:38.743691921 CET5180923192.168.2.2397.30.4.220
      Nov 2, 2021 12:13:38.743732929 CET5180923192.168.2.23139.165.213.203
      Nov 2, 2021 12:13:38.743741035 CET5180923192.168.2.23143.254.233.95
      Nov 2, 2021 12:13:38.743745089 CET5180923192.168.2.2343.63.71.126
      Nov 2, 2021 12:13:38.743757010 CET5180923192.168.2.23118.48.121.185
      Nov 2, 2021 12:13:38.743757963 CET5180923192.168.2.2319.246.213.214
      Nov 2, 2021 12:13:38.743762970 CET5180923192.168.2.23252.164.253.193
      Nov 2, 2021 12:13:38.743769884 CET5180923192.168.2.23196.180.24.33
      Nov 2, 2021 12:13:38.743772984 CET5180923192.168.2.23196.127.24.93
      Nov 2, 2021 12:13:38.743813038 CET5180923192.168.2.23242.78.232.15
      Nov 2, 2021 12:13:38.743817091 CET5180923192.168.2.23241.30.175.224
      Nov 2, 2021 12:13:38.743818998 CET5180923192.168.2.239.13.238.161
      Nov 2, 2021 12:13:38.743824959 CET5180923192.168.2.2388.230.124.172
      Nov 2, 2021 12:13:38.743833065 CET5180923192.168.2.23149.240.70.137
      Nov 2, 2021 12:13:38.743845940 CET5180923192.168.2.2384.191.205.231
      Nov 2, 2021 12:13:38.743855953 CET5180923192.168.2.23173.175.96.1
      Nov 2, 2021 12:13:38.743856907 CET5180923192.168.2.2397.164.130.117
      Nov 2, 2021 12:13:38.743858099 CET5180923192.168.2.23253.122.119.128
      Nov 2, 2021 12:13:38.743868113 CET5180923192.168.2.23195.249.208.210
      Nov 2, 2021 12:13:38.743875027 CET5180923192.168.2.235.115.180.43
      Nov 2, 2021 12:13:38.743877888 CET5180923192.168.2.2383.220.127.91
      Nov 2, 2021 12:13:38.743880987 CET5180923192.168.2.2327.93.135.105
      Nov 2, 2021 12:13:38.743884087 CET5180923192.168.2.234.0.182.242
      Nov 2, 2021 12:13:38.743887901 CET5180923192.168.2.23117.45.24.185
      Nov 2, 2021 12:13:38.743891001 CET5180923192.168.2.23193.75.198.21
      Nov 2, 2021 12:13:38.743892908 CET5180923192.168.2.23184.235.239.121
      Nov 2, 2021 12:13:38.743896008 CET5180923192.168.2.23213.223.255.10
      Nov 2, 2021 12:13:38.743899107 CET5180923192.168.2.23217.95.163.61
      Nov 2, 2021 12:13:38.743904114 CET5180923192.168.2.23179.221.11.23
      Nov 2, 2021 12:13:38.743910074 CET5180923192.168.2.2360.71.247.235
      Nov 2, 2021 12:13:38.743911982 CET5180923192.168.2.23166.136.190.228
      Nov 2, 2021 12:13:38.743920088 CET5180923192.168.2.23177.210.216.239
      Nov 2, 2021 12:13:38.743920088 CET5180923192.168.2.23175.67.105.84
      Nov 2, 2021 12:13:38.743921995 CET5180923192.168.2.23133.95.126.247
      Nov 2, 2021 12:13:38.743925095 CET5180923192.168.2.23124.119.197.37
      Nov 2, 2021 12:13:38.743932009 CET5180923192.168.2.23205.238.144.135
      Nov 2, 2021 12:13:38.743932962 CET5180923192.168.2.23203.178.98.79
      Nov 2, 2021 12:13:38.743935108 CET5180923192.168.2.2398.231.204.159
      Nov 2, 2021 12:13:38.743947029 CET5180923192.168.2.23253.48.227.3
      Nov 2, 2021 12:13:38.743949890 CET5180923192.168.2.23178.31.84.75
      Nov 2, 2021 12:13:38.743958950 CET5180923192.168.2.23185.235.224.66
      Nov 2, 2021 12:13:38.743972063 CET5180923192.168.2.23190.97.239.14
      Nov 2, 2021 12:13:38.743988037 CET5180923192.168.2.2357.118.130.36
      Nov 2, 2021 12:13:38.744004965 CET5180923192.168.2.23191.158.116.59
      Nov 2, 2021 12:13:38.744014978 CET5180923192.168.2.2364.4.98.203
      Nov 2, 2021 12:13:38.744019985 CET5180923192.168.2.2338.65.100.29
      Nov 2, 2021 12:13:38.744052887 CET5180923192.168.2.23200.195.171.119
      Nov 2, 2021 12:13:38.744056940 CET5180923192.168.2.23122.56.215.118
      Nov 2, 2021 12:13:38.744066954 CET5180923192.168.2.23107.44.177.76
      Nov 2, 2021 12:13:38.744067907 CET5180923192.168.2.23190.133.128.217
      Nov 2, 2021 12:13:38.744100094 CET5180923192.168.2.23187.42.11.148
      Nov 2, 2021 12:13:38.744107962 CET5180923192.168.2.23191.174.177.183
      Nov 2, 2021 12:13:38.744123936 CET5180923192.168.2.23124.130.191.207
      Nov 2, 2021 12:13:38.744124889 CET5180923192.168.2.23146.252.6.205
      Nov 2, 2021 12:13:38.744133949 CET5180923192.168.2.23169.209.185.153
      Nov 2, 2021 12:13:38.744138002 CET5180923192.168.2.23166.42.102.233
      Nov 2, 2021 12:13:38.744138002 CET5180923192.168.2.2343.156.98.201
      Nov 2, 2021 12:13:38.744148970 CET5180923192.168.2.23246.32.186.79
      Nov 2, 2021 12:13:38.744155884 CET5180923192.168.2.232.98.196.39

      System Behavior

      General

      Start time:12:13:38
      Start date:02/11/2021
      Path:/tmp/sora.x86
      Arguments:/tmp/sora.x86
      File size:24728 bytes
      MD5 hash:ec0785f99de2a1ea900d48a9bb26bf1c

      General

      Start time:12:13:38
      Start date:02/11/2021
      Path:/tmp/sora.x86
      Arguments:n/a
      File size:24728 bytes
      MD5 hash:ec0785f99de2a1ea900d48a9bb26bf1c

      General

      Start time:12:16:46
      Start date:02/11/2021
      Path:/tmp/sora.x86
      Arguments:n/a
      File size:24728 bytes
      MD5 hash:ec0785f99de2a1ea900d48a9bb26bf1c

      General

      Start time:12:16:46
      Start date:02/11/2021
      Path:/tmp/sora.x86
      Arguments:n/a
      File size:24728 bytes
      MD5 hash:ec0785f99de2a1ea900d48a9bb26bf1c

      General

      Start time:12:16:46
      Start date:02/11/2021
      Path:/tmp/sora.x86
      Arguments:n/a
      File size:24728 bytes
      MD5 hash:ec0785f99de2a1ea900d48a9bb26bf1c

      General

      Start time:12:16:51
      Start date:02/11/2021
      Path:/tmp/sora.x86
      Arguments:n/a
      File size:24728 bytes
      MD5 hash:ec0785f99de2a1ea900d48a9bb26bf1c

      General

      Start time:12:16:51
      Start date:02/11/2021
      Path:/tmp/sora.x86
      Arguments:n/a
      File size:24728 bytes
      MD5 hash:ec0785f99de2a1ea900d48a9bb26bf1c

      General

      Start time:12:16:46
      Start date:02/11/2021
      Path:/tmp/sora.x86
      Arguments:n/a
      File size:24728 bytes
      MD5 hash:ec0785f99de2a1ea900d48a9bb26bf1c

      General

      Start time:12:16:46
      Start date:02/11/2021
      Path:/tmp/sora.x86
      Arguments:n/a
      File size:24728 bytes
      MD5 hash:ec0785f99de2a1ea900d48a9bb26bf1c

      General

      Start time:12:13:38
      Start date:02/11/2021
      Path:/tmp/sora.x86
      Arguments:n/a
      File size:24728 bytes
      MD5 hash:ec0785f99de2a1ea900d48a9bb26bf1c

      General

      Start time:12:13:38
      Start date:02/11/2021
      Path:/tmp/sora.x86
      Arguments:n/a
      File size:24728 bytes
      MD5 hash:ec0785f99de2a1ea900d48a9bb26bf1c

      General

      Start time:12:13:38
      Start date:02/11/2021
      Path:/tmp/sora.x86
      Arguments:n/a
      File size:24728 bytes
      MD5 hash:ec0785f99de2a1ea900d48a9bb26bf1c

      General

      Start time:12:16:33
      Start date:02/11/2021
      Path:/tmp/sora.x86
      Arguments:n/a
      File size:24728 bytes
      MD5 hash:ec0785f99de2a1ea900d48a9bb26bf1c

      General

      Start time:12:16:33
      Start date:02/11/2021
      Path:/tmp/sora.x86
      Arguments:n/a
      File size:24728 bytes
      MD5 hash:ec0785f99de2a1ea900d48a9bb26bf1c

      General

      Start time:12:13:38
      Start date:02/11/2021
      Path:/tmp/sora.x86
      Arguments:n/a
      File size:24728 bytes
      MD5 hash:ec0785f99de2a1ea900d48a9bb26bf1c

      General

      Start time:12:13:38
      Start date:02/11/2021
      Path:/tmp/sora.x86
      Arguments:n/a
      File size:24728 bytes
      MD5 hash:ec0785f99de2a1ea900d48a9bb26bf1c

      General

      Start time:12:13:49
      Start date:02/11/2021
      Path:/usr/lib/systemd/systemd
      Arguments:n/a
      File size:1620224 bytes
      MD5 hash:9b2bec7092a40488108543f9334aab75

      General

      Start time:12:13:49
      Start date:02/11/2021
      Path:/usr/sbin/sshd
      Arguments:/usr/sbin/sshd -t
      File size:876328 bytes
      MD5 hash:dbca7a6bbf7bf57fedac243d4b2cb340

      General

      Start time:12:13:50
      Start date:02/11/2021
      Path:/usr/lib/systemd/systemd
      Arguments:n/a
      File size:1620224 bytes
      MD5 hash:9b2bec7092a40488108543f9334aab75

      General

      Start time:12:13:50
      Start date:02/11/2021
      Path:/usr/sbin/sshd
      Arguments:/usr/sbin/sshd -D
      File size:876328 bytes
      MD5 hash:dbca7a6bbf7bf57fedac243d4b2cb340

      General

      Start time:12:16:26
      Start date:02/11/2021
      Path:/usr/lib/systemd/systemd
      Arguments:n/a
      File size:1620224 bytes
      MD5 hash:9b2bec7092a40488108543f9334aab75

      General

      Start time:12:16:26
      Start date:02/11/2021
      Path:/usr/sbin/sshd
      Arguments:/usr/sbin/sshd -t
      File size:876328 bytes
      MD5 hash:dbca7a6bbf7bf57fedac243d4b2cb340

      General

      Start time:12:16:27
      Start date:02/11/2021
      Path:/usr/lib/systemd/systemd
      Arguments:n/a
      File size:1620224 bytes
      MD5 hash:9b2bec7092a40488108543f9334aab75

      General

      Start time:12:16:27
      Start date:02/11/2021
      Path:/usr/sbin/sshd
      Arguments:/usr/sbin/sshd -D
      File size:876328 bytes
      MD5 hash:dbca7a6bbf7bf57fedac243d4b2cb340

      General

      Start time:12:16:29
      Start date:02/11/2021
      Path:/usr/lib/systemd/systemd
      Arguments:n/a
      File size:1620224 bytes
      MD5 hash:9b2bec7092a40488108543f9334aab75

      General

      Start time:12:16:29
      Start date:02/11/2021
      Path:/usr/sbin/sshd
      Arguments:/usr/sbin/sshd -t
      File size:876328 bytes
      MD5 hash:dbca7a6bbf7bf57fedac243d4b2cb340

      General

      Start time:12:16:29
      Start date:02/11/2021
      Path:/usr/lib/systemd/systemd
      Arguments:n/a
      File size:1620224 bytes
      MD5 hash:9b2bec7092a40488108543f9334aab75

      General

      Start time:12:16:29
      Start date:02/11/2021
      Path:/usr/sbin/sshd
      Arguments:/usr/sbin/sshd -D
      File size:876328 bytes
      MD5 hash:dbca7a6bbf7bf57fedac243d4b2cb340