Linux Analysis Report gL6zNW1uNj

Overview

General Information

Sample Name: gL6zNW1uNj
Analysis ID: 519630
MD5: deee0487e17b20a74a1757f36e92a240
SHA1: 865c8c7d1b4d725220d58075839e1429820e3465
SHA256: 9ad0477757b6e3b5808cb2ef7b0a53c58823ab63339d8575f454341446bf2b14
Tags: 32elfmiraisparc
Infos:

Most interesting Screenshot:

Detection

Mirai
Score: 72
Range: 0 - 100
Whitelisted: false

Signatures

Snort IDS alert for network traffic (e.g. based on Emerging Threat rules)
Yara detected Mirai
Multi AV Scanner detection for submitted file
Uses known network protocols on non-standard ports
Sample tries to kill many processes (SIGKILL)
Sample has stripped symbol table
Uses the "uname" system call to query kernel version information (possible evasion)
Enumerates processes within the "proc" file system
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Detected TCP or UDP traffic on non-standard ports
Sample listens on a socket
Sample tries to kill a process (SIGKILL)

Classification

AV Detection:

barindex
Multi AV Scanner detection for submitted file
Source: gL6zNW1uNj Virustotal: Detection: 49% Perma Link
Source: gL6zNW1uNj ReversingLabs: Detection: 55%

Networking:

barindex
Snort IDS alert for network traffic (e.g. based on Emerging Threat rules)
Source: Traffic Snort IDS: 492 INFO TELNET login failed 60.28.78.146:23 -> 192.168.2.23:36426
Source: Traffic Snort IDS: 716 INFO TELNET access 124.133.7.233:23 -> 192.168.2.23:58354
Source: Traffic Snort IDS: 716 INFO TELNET access 124.133.7.233:23 -> 192.168.2.23:58362
Source: Traffic Snort IDS: 716 INFO TELNET access 124.133.7.233:23 -> 192.168.2.23:58366
Source: Traffic Snort IDS: 716 INFO TELNET access 124.133.7.233:23 -> 192.168.2.23:58390
Source: Traffic Snort IDS: 716 INFO TELNET access 124.133.7.233:23 -> 192.168.2.23:58396
Source: Traffic Snort IDS: 716 INFO TELNET access 124.133.7.233:23 -> 192.168.2.23:58404
Source: Traffic Snort IDS: 716 INFO TELNET access 124.133.7.233:23 -> 192.168.2.23:58408
Source: Traffic Snort IDS: 716 INFO TELNET access 124.133.7.233:23 -> 192.168.2.23:58414
Source: Traffic Snort IDS: 716 INFO TELNET access 124.133.7.233:23 -> 192.168.2.23:58418
Source: Traffic Snort IDS: 716 INFO TELNET access 124.133.7.233:23 -> 192.168.2.23:58424
Source: Traffic Snort IDS: 716 INFO TELNET access 114.168.61.85:23 -> 192.168.2.23:37474
Source: Traffic Snort IDS: 716 INFO TELNET access 114.168.61.85:23 -> 192.168.2.23:37482
Source: Traffic Snort IDS: 716 INFO TELNET access 114.168.61.85:23 -> 192.168.2.23:37490
Source: Traffic Snort IDS: 716 INFO TELNET access 114.168.61.85:23 -> 192.168.2.23:37496
Source: Traffic Snort IDS: 1251 INFO TELNET Bad Login 170.39.121.45:23 -> 192.168.2.23:50994
Source: Traffic Snort IDS: 718 INFO TELNET login incorrect 170.39.121.45:23 -> 192.168.2.23:50994
Source: Traffic Snort IDS: 716 INFO TELNET access 114.168.61.85:23 -> 192.168.2.23:37510
Source: Traffic Snort IDS: 716 INFO TELNET access 114.168.61.85:23 -> 192.168.2.23:37530
Source: Traffic Snort IDS: 1251 INFO TELNET Bad Login 104.153.142.22:23 -> 192.168.2.23:54818
Source: Traffic Snort IDS: 718 INFO TELNET login incorrect 104.153.142.22:23 -> 192.168.2.23:54818
Source: Traffic Snort IDS: 1251 INFO TELNET Bad Login 104.153.142.22:23 -> 192.168.2.23:54824
Source: Traffic Snort IDS: 718 INFO TELNET login incorrect 104.153.142.22:23 -> 192.168.2.23:54824
Source: Traffic Snort IDS: 1251 INFO TELNET Bad Login 104.153.142.22:23 -> 192.168.2.23:54832
Source: Traffic Snort IDS: 718 INFO TELNET login incorrect 104.153.142.22:23 -> 192.168.2.23:54832
Source: Traffic Snort IDS: 716 INFO TELNET access 114.168.61.85:23 -> 192.168.2.23:37550
Source: Traffic Snort IDS: 1251 INFO TELNET Bad Login 104.153.142.22:23 -> 192.168.2.23:54858
Source: Traffic Snort IDS: 718 INFO TELNET login incorrect 104.153.142.22:23 -> 192.168.2.23:54858
Source: Traffic Snort IDS: 716 INFO TELNET access 114.168.61.85:23 -> 192.168.2.23:37580
Source: Traffic Snort IDS: 1251 INFO TELNET Bad Login 104.153.142.22:23 -> 192.168.2.23:54894
Source: Traffic Snort IDS: 718 INFO TELNET login incorrect 104.153.142.22:23 -> 192.168.2.23:54894
Source: Traffic Snort IDS: 716 INFO TELNET access 114.168.61.85:23 -> 192.168.2.23:37620
Source: Traffic Snort IDS: 716 INFO TELNET access 114.168.61.85:23 -> 192.168.2.23:37662
Source: Traffic Snort IDS: 1251 INFO TELNET Bad Login 170.39.121.45:23 -> 192.168.2.23:51202
Source: Traffic Snort IDS: 718 INFO TELNET login incorrect 170.39.121.45:23 -> 192.168.2.23:51202
Source: Traffic Snort IDS: 1251 INFO TELNET Bad Login 104.153.142.22:23 -> 192.168.2.23:55030
Source: Traffic Snort IDS: 718 INFO TELNET login incorrect 104.153.142.22:23 -> 192.168.2.23:55030
Source: Traffic Snort IDS: 1251 INFO TELNET Bad Login 104.153.142.22:23 -> 192.168.2.23:55034
Source: Traffic Snort IDS: 718 INFO TELNET login incorrect 104.153.142.22:23 -> 192.168.2.23:55034
Source: Traffic Snort IDS: 1251 INFO TELNET Bad Login 104.153.142.22:23 -> 192.168.2.23:55046
Source: Traffic Snort IDS: 718 INFO TELNET login incorrect 104.153.142.22:23 -> 192.168.2.23:55046
Source: Traffic Snort IDS: 716 INFO TELNET access 179.92.78.179:23 -> 192.168.2.23:36676
Source: Traffic Snort IDS: 1251 INFO TELNET Bad Login 68.115.186.41:23 -> 192.168.2.23:43838
Source: Traffic Snort IDS: 718 INFO TELNET login incorrect 68.115.186.41:23 -> 192.168.2.23:43838
Source: Traffic Snort IDS: 1251 INFO TELNET Bad Login 179.92.78.179:23 -> 192.168.2.23:36676
Source: Traffic Snort IDS: 718 INFO TELNET login incorrect 179.92.78.179:23 -> 192.168.2.23:36676
Source: Traffic Snort IDS: 1251 INFO TELNET Bad Login 104.153.142.22:23 -> 192.168.2.23:55096
Source: Traffic Snort IDS: 718 INFO TELNET login incorrect 104.153.142.22:23 -> 192.168.2.23:55096
Source: Traffic Snort IDS: 1251 INFO TELNET Bad Login 212.113.244.20:23 -> 192.168.2.23:49610
Source: Traffic Snort IDS: 718 INFO TELNET login incorrect 212.113.244.20:23 -> 192.168.2.23:49610
Source: Traffic Snort IDS: 1251 INFO TELNET Bad Login 104.153.142.22:23 -> 192.168.2.23:55134
Source: Traffic Snort IDS: 718 INFO TELNET login incorrect 104.153.142.22:23 -> 192.168.2.23:55134
Uses known network protocols on non-standard ports
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 39940
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 39944
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 39948
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 39958
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 39970
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 39976
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 39978
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 39982
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 39984
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 39986
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 54608
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 54610
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 54612
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 54614
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 54620
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 54622
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 54628
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 54630
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 54634
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 54636
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 49958
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 49960
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 49962
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 49964
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 49970
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 49972
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 49974
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 49976
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 49978
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 49980
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 56710
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 56716
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 56724
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 56730
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 56736
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 56742
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 56746
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 56748
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 56750
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 56752
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Source: global traffic TCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
Source: global traffic TCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
Source: global traffic TCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
Detected TCP or UDP traffic on non-standard ports
Source: global traffic TCP traffic: 192.168.2.23:44384 -> 86.126.191.187:1312
Sample listens on a socket
Source: /tmp/gL6zNW1uNj (PID: 5241) Socket: 0.0.0.0::0 Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5241) Socket: 0.0.0.0::23 Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5241) Socket: 0.0.0.0::53413 Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5241) Socket: 0.0.0.0::80 Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5241) Socket: 0.0.0.0::52869 Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5241) Socket: 0.0.0.0::37215 Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) Socket: 0.0.0.0::0 Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) Socket: 0.0.0.0::23 Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) Socket: 0.0.0.0::53413 Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) Socket: 0.0.0.0::80 Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) Socket: 0.0.0.0::52869 Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) Socket: 0.0.0.0::37215 Jump to behavior
Source: /usr/sbin/sshd (PID: 5286) Socket: 0.0.0.0::22 Jump to behavior
Source: /usr/sbin/sshd (PID: 5286) Socket: [::]::22 Jump to behavior
Source: /usr/sbin/sshd (PID: 5304) Socket: 0.0.0.0::22 Jump to behavior
Source: /usr/sbin/sshd (PID: 5304) Socket: [::]::22 Jump to behavior
Source: unknown Network traffic detected: HTTP traffic on port 43928 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 42836 -> 443
Source: unknown TCP traffic detected without corresponding DNS query: 86.126.191.187
Source: unknown TCP traffic detected without corresponding DNS query: 154.206.38.139
Source: unknown TCP traffic detected without corresponding DNS query: 101.130.129.147
Source: unknown TCP traffic detected without corresponding DNS query: 8.204.194.128
Source: unknown TCP traffic detected without corresponding DNS query: 47.125.240.84
Source: unknown TCP traffic detected without corresponding DNS query: 57.8.81.223
Source: unknown TCP traffic detected without corresponding DNS query: 23.50.220.217
Source: unknown TCP traffic detected without corresponding DNS query: 73.46.136.207
Source: unknown TCP traffic detected without corresponding DNS query: 192.89.191.6
Source: unknown TCP traffic detected without corresponding DNS query: 60.64.228.232
Source: unknown TCP traffic detected without corresponding DNS query: 75.203.207.217
Source: unknown TCP traffic detected without corresponding DNS query: 163.88.47.71
Source: unknown TCP traffic detected without corresponding DNS query: 42.237.32.248
Source: unknown TCP traffic detected without corresponding DNS query: 150.221.199.109
Source: unknown TCP traffic detected without corresponding DNS query: 19.0.217.207
Source: unknown TCP traffic detected without corresponding DNS query: 250.16.28.79
Source: unknown TCP traffic detected without corresponding DNS query: 107.252.94.222
Source: unknown TCP traffic detected without corresponding DNS query: 192.50.222.74
Source: unknown TCP traffic detected without corresponding DNS query: 107.117.147.93
Source: unknown TCP traffic detected without corresponding DNS query: 169.138.96.213
Source: unknown TCP traffic detected without corresponding DNS query: 18.96.158.1
Source: unknown TCP traffic detected without corresponding DNS query: 116.67.244.33
Source: unknown TCP traffic detected without corresponding DNS query: 57.244.27.55
Source: unknown TCP traffic detected without corresponding DNS query: 184.217.61.34
Source: unknown TCP traffic detected without corresponding DNS query: 252.137.132.179
Source: unknown TCP traffic detected without corresponding DNS query: 118.232.80.207
Source: unknown TCP traffic detected without corresponding DNS query: 18.182.98.193
Source: unknown TCP traffic detected without corresponding DNS query: 192.9.42.7
Source: unknown TCP traffic detected without corresponding DNS query: 205.187.71.176
Source: unknown TCP traffic detected without corresponding DNS query: 252.97.60.34
Source: unknown TCP traffic detected without corresponding DNS query: 178.239.202.195
Source: unknown TCP traffic detected without corresponding DNS query: 18.169.214.44
Source: unknown TCP traffic detected without corresponding DNS query: 54.118.2.114
Source: unknown TCP traffic detected without corresponding DNS query: 248.61.246.8
Source: unknown TCP traffic detected without corresponding DNS query: 141.234.1.205
Source: unknown TCP traffic detected without corresponding DNS query: 77.48.99.254
Source: unknown TCP traffic detected without corresponding DNS query: 174.251.29.219
Source: unknown TCP traffic detected without corresponding DNS query: 87.1.84.37
Source: unknown TCP traffic detected without corresponding DNS query: 125.240.72.254
Source: unknown TCP traffic detected without corresponding DNS query: 173.0.147.247
Source: unknown TCP traffic detected without corresponding DNS query: 116.223.177.216
Source: unknown TCP traffic detected without corresponding DNS query: 8.222.84.87
Source: unknown TCP traffic detected without corresponding DNS query: 194.198.169.176
Source: unknown TCP traffic detected without corresponding DNS query: 150.84.116.130
Source: unknown TCP traffic detected without corresponding DNS query: 162.165.39.78
Source: unknown TCP traffic detected without corresponding DNS query: 249.204.91.17
Source: unknown TCP traffic detected without corresponding DNS query: 191.49.123.189
Source: unknown TCP traffic detected without corresponding DNS query: 184.250.54.229
Source: unknown TCP traffic detected without corresponding DNS query: 133.148.41.181
Source: unknown TCP traffic detected without corresponding DNS query: 120.97.159.124

System Summary:

barindex
Sample tries to kill many processes (SIGKILL)
Source: /tmp/gL6zNW1uNj (PID: 5241) SIGKILL sent: pid: 936, result: successful Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) SIGKILL sent: pid: 5273, result: successful Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) SIGKILL sent: pid: 5275, result: successful Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) SIGKILL sent: pid: 720, result: successful Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) SIGKILL sent: pid: 759, result: successful Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) SIGKILL sent: pid: 788, result: successful Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) SIGKILL sent: pid: 800, result: successful Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) SIGKILL sent: pid: 847, result: successful Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) SIGKILL sent: pid: 884, result: successful Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) SIGKILL sent: pid: 1334, result: successful Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) SIGKILL sent: pid: 1335, result: successful Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) SIGKILL sent: pid: 1860, result: successful Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) SIGKILL sent: pid: 1872, result: successful Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) SIGKILL sent: pid: 2096, result: successful Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) SIGKILL sent: pid: 2097, result: successful Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) SIGKILL sent: pid: 2102, result: successful Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) SIGKILL sent: pid: 2180, result: successful Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) SIGKILL sent: pid: 2191, result: successful Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) SIGKILL sent: pid: 2208, result: successful Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) SIGKILL sent: pid: 2275, result: successful Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) SIGKILL sent: pid: 2281, result: successful Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) SIGKILL sent: pid: 2285, result: successful Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) SIGKILL sent: pid: 2289, result: successful Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) SIGKILL sent: pid: 2294, result: successful Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) SIGKILL sent: pid: 5250, result: successful Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) SIGKILL sent: pid: 5280, result: successful Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) SIGKILL sent: pid: 5281, result: successful Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) SIGKILL sent: pid: 5286, result: successful Jump to behavior
Sample has stripped symbol table
Source: ELF static info symbol of initial sample .symtab present: no
Sample tries to kill a process (SIGKILL)
Source: /tmp/gL6zNW1uNj (PID: 5241) SIGKILL sent: pid: 936, result: successful Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) SIGKILL sent: pid: 5273, result: successful Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) SIGKILL sent: pid: 5275, result: successful Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) SIGKILL sent: pid: 720, result: successful Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) SIGKILL sent: pid: 759, result: successful Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) SIGKILL sent: pid: 788, result: successful Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) SIGKILL sent: pid: 800, result: successful Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) SIGKILL sent: pid: 847, result: successful Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) SIGKILL sent: pid: 884, result: successful Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) SIGKILL sent: pid: 1334, result: successful Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) SIGKILL sent: pid: 1335, result: successful Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) SIGKILL sent: pid: 1860, result: successful Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) SIGKILL sent: pid: 1872, result: successful Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) SIGKILL sent: pid: 2096, result: successful Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) SIGKILL sent: pid: 2097, result: successful Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) SIGKILL sent: pid: 2102, result: successful Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) SIGKILL sent: pid: 2180, result: successful Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) SIGKILL sent: pid: 2191, result: successful Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) SIGKILL sent: pid: 2208, result: successful Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) SIGKILL sent: pid: 2275, result: successful Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) SIGKILL sent: pid: 2281, result: successful Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) SIGKILL sent: pid: 2285, result: successful Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) SIGKILL sent: pid: 2289, result: successful Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) SIGKILL sent: pid: 2294, result: successful Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) SIGKILL sent: pid: 5250, result: successful Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) SIGKILL sent: pid: 5280, result: successful Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) SIGKILL sent: pid: 5281, result: successful Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) SIGKILL sent: pid: 5286, result: successful Jump to behavior
Source: classification engine Classification label: mal72.spre.troj.lin@0/4@0/0
Source: gL6zNW1uNj Joe Sandbox Cloud Basic: Detection: clean Score: 0 Perma Link

Persistence and Installation Behavior:

barindex
Enumerates processes within the "proc" file system
Source: /tmp/gL6zNW1uNj (PID: 5241) File opened: /proc/491/fd Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5241) File opened: /proc/793/fd Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5241) File opened: /proc/772/fd Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5241) File opened: /proc/796/fd Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5241) File opened: /proc/774/fd Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5241) File opened: /proc/797/fd Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5241) File opened: /proc/777/fd Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5241) File opened: /proc/799/fd Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5241) File opened: /proc/658/fd Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5241) File opened: /proc/912/fd Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5241) File opened: /proc/759/fd Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5241) File opened: /proc/936/fd Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5241) File opened: /proc/918/fd Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5241) File opened: /proc/1/fd Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5241) File opened: /proc/761/fd Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5241) File opened: /proc/785/fd Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5241) File opened: /proc/884/fd Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5241) File opened: /proc/720/fd Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5241) File opened: /proc/721/fd Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5241) File opened: /proc/788/fd Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5241) File opened: /proc/789/fd Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5241) File opened: /proc/800/fd Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5241) File opened: /proc/801/fd Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5241) File opened: /proc/847/fd Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5241) File opened: /proc/904/fd Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) File opened: /proc/5261/fd Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) File opened: /proc/5261/fd Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) File opened: /proc/5261/exe Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) File opened: /proc/5262/fd Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) File opened: /proc/5262/fd Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) File opened: /proc/5262/exe Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) File opened: /proc/5263/fd Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) File opened: /proc/5263/fd Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) File opened: /proc/5263/exe Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) File opened: /proc/5264/fd Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) File opened: /proc/5264/fd Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) File opened: /proc/5264/exe Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) File opened: /proc/5265/fd Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) File opened: /proc/5265/fd Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) File opened: /proc/5265/exe Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) File opened: /proc/5266/fd Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) File opened: /proc/5266/fd Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) File opened: /proc/5266/exe Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) File opened: /proc/5145/exe Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) File opened: /proc/5267/fd Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) File opened: /proc/5267/fd Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) File opened: /proc/5267/exe Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) File opened: /proc/5268/fd Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) File opened: /proc/5268/fd Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) File opened: /proc/5268/exe Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) File opened: /proc/2033/fd Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) File opened: /proc/2033/fd Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) File opened: /proc/2033/exe Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) File opened: /proc/1582/fd Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) File opened: /proc/1582/fd Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) File opened: /proc/1582/exe Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) File opened: /proc/2275/fd Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) File opened: /proc/2275/fd Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) File opened: /proc/2275/exe Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) File opened: /proc/3088/exe Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) File opened: /proc/5260/fd Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) File opened: /proc/5260/fd Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) File opened: /proc/5260/exe Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) File opened: /proc/1612/fd Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) File opened: /proc/1612/fd Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) File opened: /proc/1612/exe Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) File opened: /proc/1579/fd Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) File opened: /proc/1579/fd Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) File opened: /proc/1579/exe Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) File opened: /proc/1699/fd Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) File opened: /proc/1699/fd Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) File opened: /proc/1699/exe Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) File opened: /proc/1335/fd Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) File opened: /proc/1335/fd Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) File opened: /proc/1335/exe Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) File opened: /proc/1698/fd Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) File opened: /proc/1698/fd Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) File opened: /proc/1698/exe Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) File opened: /proc/2028/fd Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) File opened: /proc/2028/fd Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) File opened: /proc/2028/exe Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) File opened: /proc/1334/fd Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) File opened: /proc/1334/fd Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) File opened: /proc/1334/exe Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) File opened: /proc/1576/fd Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) File opened: /proc/1576/fd Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) File opened: /proc/1576/exe Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) File opened: /proc/2302/fd Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) File opened: /proc/2302/fd Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) File opened: /proc/2302/exe Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) File opened: /proc/3236/fd Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) File opened: /proc/3236/fd Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) File opened: /proc/3236/exe Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) File opened: /proc/2025/fd Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) File opened: /proc/2025/fd Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) File opened: /proc/2025/exe Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) File opened: /proc/2146/fd Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) File opened: /proc/2146/fd Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) File opened: /proc/2146/exe Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) File opened: /proc/5258/fd Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) File opened: /proc/5258/fd Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) File opened: /proc/5258/exe Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) File opened: /proc/910/exe Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) File opened: /proc/5259/fd Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) File opened: /proc/5259/fd Jump to behavior
Source: /tmp/gL6zNW1uNj (PID: 5247) File opened: /proc/5259/exe Jump to behavior

Hooking and other Techniques for Hiding and Protection:

barindex
Uses known network protocols on non-standard ports
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 39940
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 39944
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 39948
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 39958
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 39970
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 39976
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 39978
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 39982
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 39984
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 39986
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 54608
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 54610
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 54612
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 54614
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 54620
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 54622
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 54628
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 54630
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 54634
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 54636
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 49958
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 49960
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 49962
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 49964
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 49970
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 49972
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 49974
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 49976
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 49978
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 49980
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 56710
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 56716
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 56724
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 56730
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 56736
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 56742
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 56746
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 56748
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 56750
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 56752

Malware Analysis System Evasion:

barindex
Uses the "uname" system call to query kernel version information (possible evasion)
Source: /tmp/gL6zNW1uNj (PID: 5239) Queries kernel information via 'uname': Jump to behavior
Source: gL6zNW1uNj, 5239.1.00000000b1d99cf5.00000000f91ff669.rw-.sdmp Binary or memory string: /etc/qemu-binfmt/sparc
Source: gL6zNW1uNj, 5239.1.00000000b1d99cf5.00000000f91ff669.rw-.sdmp Binary or memory string: U!/etc/qemu-binfmt/sparc
Source: gL6zNW1uNj, 5298.1.00000000b1d99cf5.00000000f91ff669.rw-.sdmp Binary or memory string: /usr/bin/vmtoolsd
Source: gL6zNW1uNj, 5239.1.0000000082bb98ad.00000000d33cd321.rw-.sdmp Binary or memory string: {wx86_64/usr/bin/qemu-sparc/tmp/gL6zNW1uNjSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/gL6zNW1uNj
Source: gL6zNW1uNj, 5298.1.00000000f91ff669.000000003459bf12.rw-.sdmp Binary or memory string: U/sparc/10 /usr/bin/qemu-sparc!/proc/5268/fd/111
Source: gL6zNW1uNj, 5239.1.0000000082bb98ad.00000000d33cd321.rw-.sdmp Binary or memory string: /usr/bin/qemu-sparc
Source: gL6zNW1uNj, 5298.1.00000000b1d99cf5.00000000f91ff669.rw-.sdmp Binary or memory string: U1/usr/bin/vmtoolsdparc/10!/proc/1890/fd/48!/proc/1642/exeP

Stealing of Sensitive Information:

barindex
Yara detected Mirai
Source: Yara match File source: dump.pcap, type: PCAP

Remote Access Functionality:

barindex
Yara detected Mirai
Source: Yara match File source: dump.pcap, type: PCAP
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs