Loading ...

Play interactive tourEdit tour

Linux Analysis Report gL6zNW1uNj

Overview

General Information

Sample Name:gL6zNW1uNj
Analysis ID:519630
MD5:deee0487e17b20a74a1757f36e92a240
SHA1:865c8c7d1b4d725220d58075839e1429820e3465
SHA256:9ad0477757b6e3b5808cb2ef7b0a53c58823ab63339d8575f454341446bf2b14
Tags:32elfmiraisparc
Infos:

Most interesting Screenshot:

Detection

Mirai
Score:72
Range:0 - 100
Whitelisted:false

Signatures

Snort IDS alert for network traffic (e.g. based on Emerging Threat rules)
Yara detected Mirai
Multi AV Scanner detection for submitted file
Uses known network protocols on non-standard ports
Sample tries to kill many processes (SIGKILL)
Sample has stripped symbol table
Uses the "uname" system call to query kernel version information (possible evasion)
Enumerates processes within the "proc" file system
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Detected TCP or UDP traffic on non-standard ports
Sample listens on a socket
Sample tries to kill a process (SIGKILL)

Classification

Analysis Advice

All HTTP servers contacted by the sample do not answer. Likely the sample is an old dropper which does no longer work
Static ELF header machine description suggests that the sample might not execute correctly on this machine

General Information

Joe Sandbox Version:34.0.0 Boulder Opal
Analysis ID:519630
Start date:10.11.2021
Start time:23:51:08
Joe Sandbox Product:CloudBasic
Overall analysis duration:0h 5m 23s
Hypervisor based Inspection enabled:false
Report type:light
Sample file name:gL6zNW1uNj
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Detection:MAL
Classification:mal72.spre.troj.lin@0/4@0/0
Warnings:
Show All
  • Report size exceeded maximum capacity and may have missing network information.
  • TCP Packets have been reduced to 100

Process Tree

  • system is lnxubuntu20
  • systemd New Fork (PID: 5270, Parent: 1)
  • sshd (PID: 5270, Parent: 1, MD5: dbca7a6bbf7bf57fedac243d4b2cb340) Arguments: /usr/sbin/sshd -t
  • systemd New Fork (PID: 5286, Parent: 1)
  • sshd (PID: 5286, Parent: 1, MD5: dbca7a6bbf7bf57fedac243d4b2cb340) Arguments: /usr/sbin/sshd -D
  • systemd New Fork (PID: 5297, Parent: 1)
  • sshd (PID: 5297, Parent: 1, MD5: dbca7a6bbf7bf57fedac243d4b2cb340) Arguments: /usr/sbin/sshd -t
  • systemd New Fork (PID: 5304, Parent: 1)
  • sshd (PID: 5304, Parent: 1, MD5: dbca7a6bbf7bf57fedac243d4b2cb340) Arguments: /usr/sbin/sshd -D
  • cleanup

Yara Overview

PCAP (Network Traffic)

SourceRuleDescriptionAuthorStrings
dump.pcapJoeSecurity_Mirai_12Yara detected MiraiJoe Security

    Jbx Signature Overview

    Click to jump to signature section

    Show All Signature Results

    AV Detection:

    barindex
    Multi AV Scanner detection for submitted fileShow sources
    Source: gL6zNW1uNjVirustotal: Detection: 49%Perma Link
    Source: gL6zNW1uNjReversingLabs: Detection: 55%

    Networking:

    barindex
    Snort IDS alert for network traffic (e.g. based on Emerging Threat rules)Show sources
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 60.28.78.146:23 -> 192.168.2.23:36426
    Source: TrafficSnort IDS: 716 INFO TELNET access 124.133.7.233:23 -> 192.168.2.23:58354
    Source: TrafficSnort IDS: 716 INFO TELNET access 124.133.7.233:23 -> 192.168.2.23:58362
    Source: TrafficSnort IDS: 716 INFO TELNET access 124.133.7.233:23 -> 192.168.2.23:58366
    Source: TrafficSnort IDS: 716 INFO TELNET access 124.133.7.233:23 -> 192.168.2.23:58390
    Source: TrafficSnort IDS: 716 INFO TELNET access 124.133.7.233:23 -> 192.168.2.23:58396
    Source: TrafficSnort IDS: 716 INFO TELNET access 124.133.7.233:23 -> 192.168.2.23:58404
    Source: TrafficSnort IDS: 716 INFO TELNET access 124.133.7.233:23 -> 192.168.2.23:58408
    Source: TrafficSnort IDS: 716 INFO TELNET access 124.133.7.233:23 -> 192.168.2.23:58414
    Source: TrafficSnort IDS: 716 INFO TELNET access 124.133.7.233:23 -> 192.168.2.23:58418
    Source: TrafficSnort IDS: 716 INFO TELNET access 124.133.7.233:23 -> 192.168.2.23:58424
    Source: TrafficSnort IDS: 716 INFO TELNET access 114.168.61.85:23 -> 192.168.2.23:37474
    Source: TrafficSnort IDS: 716 INFO TELNET access 114.168.61.85:23 -> 192.168.2.23:37482
    Source: TrafficSnort IDS: 716 INFO TELNET access 114.168.61.85:23 -> 192.168.2.23:37490
    Source: TrafficSnort IDS: 716 INFO TELNET access 114.168.61.85:23 -> 192.168.2.23:37496
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 170.39.121.45:23 -> 192.168.2.23:50994
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 170.39.121.45:23 -> 192.168.2.23:50994
    Source: TrafficSnort IDS: 716 INFO TELNET access 114.168.61.85:23 -> 192.168.2.23:37510
    Source: TrafficSnort IDS: 716 INFO TELNET access 114.168.61.85:23 -> 192.168.2.23:37530
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 104.153.142.22:23 -> 192.168.2.23:54818
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 104.153.142.22:23 -> 192.168.2.23:54818
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 104.153.142.22:23 -> 192.168.2.23:54824
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 104.153.142.22:23 -> 192.168.2.23:54824
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 104.153.142.22:23 -> 192.168.2.23:54832
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 104.153.142.22:23 -> 192.168.2.23:54832
    Source: TrafficSnort IDS: 716 INFO TELNET access 114.168.61.85:23 -> 192.168.2.23:37550
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 104.153.142.22:23 -> 192.168.2.23:54858
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 104.153.142.22:23 -> 192.168.2.23:54858
    Source: TrafficSnort IDS: 716 INFO TELNET access 114.168.61.85:23 -> 192.168.2.23:37580
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 104.153.142.22:23 -> 192.168.2.23:54894
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 104.153.142.22:23 -> 192.168.2.23:54894
    Source: TrafficSnort IDS: 716 INFO TELNET access 114.168.61.85:23 -> 192.168.2.23:37620
    Source: TrafficSnort IDS: 716 INFO TELNET access 114.168.61.85:23 -> 192.168.2.23:37662
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 170.39.121.45:23 -> 192.168.2.23:51202
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 170.39.121.45:23 -> 192.168.2.23:51202
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 104.153.142.22:23 -> 192.168.2.23:55030
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 104.153.142.22:23 -> 192.168.2.23:55030
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 104.153.142.22:23 -> 192.168.2.23:55034
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 104.153.142.22:23 -> 192.168.2.23:55034
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 104.153.142.22:23 -> 192.168.2.23:55046
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 104.153.142.22:23 -> 192.168.2.23:55046
    Source: TrafficSnort IDS: 716 INFO TELNET access 179.92.78.179:23 -> 192.168.2.23:36676
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 68.115.186.41:23 -> 192.168.2.23:43838
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 68.115.186.41:23 -> 192.168.2.23:43838
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 179.92.78.179:23 -> 192.168.2.23:36676
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 179.92.78.179:23 -> 192.168.2.23:36676
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 104.153.142.22:23 -> 192.168.2.23:55096
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 104.153.142.22:23 -> 192.168.2.23:55096
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 212.113.244.20:23 -> 192.168.2.23:49610
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 212.113.244.20:23 -> 192.168.2.23:49610
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 104.153.142.22:23 -> 192.168.2.23:55134
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 104.153.142.22:23 -> 192.168.2.23:55134
    Uses known network protocols on non-standard portsShow sources
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39940
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39944
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39948
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39958
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39970
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39976
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39978
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39982
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39984
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39986
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 54608
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 54610
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 54612
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 54614
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 54620
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 54622
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 54628
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 54630
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 54634
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 54636
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 49958
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 49960
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 49962
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 49964
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 49970
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 49972
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 49974
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 49976
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 49978
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 49980
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 56710
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 56716
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 56724
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 56730
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 56736
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 56742
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 56746
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 56748
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 56750
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 56752
    Source: global trafficTCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
    Source: global trafficTCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
    Source: global trafficTCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
    Source: global trafficTCP traffic: 192.168.2.23:44384 -> 86.126.191.187:1312
    Source: /tmp/gL6zNW1uNj (PID: 5241)Socket: 0.0.0.0::0
    Source: /tmp/gL6zNW1uNj (PID: 5241)Socket: 0.0.0.0::23
    Source: /tmp/gL6zNW1uNj (PID: 5241)Socket: 0.0.0.0::53413
    Source: /tmp/gL6zNW1uNj (PID: 5241)Socket: 0.0.0.0::80
    Source: /tmp/gL6zNW1uNj (PID: 5241)Socket: 0.0.0.0::52869
    Source: /tmp/gL6zNW1uNj (PID: 5241)Socket: 0.0.0.0::37215
    Source: /tmp/gL6zNW1uNj (PID: 5247)Socket: 0.0.0.0::0
    Source: /tmp/gL6zNW1uNj (PID: 5247)Socket: 0.0.0.0::23
    Source: /tmp/gL6zNW1uNj (PID: 5247)Socket: 0.0.0.0::53413
    Source: /tmp/gL6zNW1uNj (PID: 5247)Socket: 0.0.0.0::80
    Source: /tmp/gL6zNW1uNj (PID: 5247)Socket: 0.0.0.0::52869
    Source: /tmp/gL6zNW1uNj (PID: 5247)Socket: 0.0.0.0::37215
    Source: /usr/sbin/sshd (PID: 5286)Socket: 0.0.0.0::22
    Source: /usr/sbin/sshd (PID: 5286)Socket: [::]::22
    Source: /usr/sbin/sshd (PID: 5304)Socket: 0.0.0.0::22
    Source: /usr/sbin/sshd (PID: 5304)Socket: [::]::22
    Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443
    Source: unknownTCP traffic detected without corresponding DNS query: 86.126.191.187
    Source: unknownTCP traffic detected without corresponding DNS query: 154.206.38.139
    Source: unknownTCP traffic detected without corresponding DNS query: 101.130.129.147
    Source: unknownTCP traffic detected without corresponding DNS query: 8.204.194.128
    Source: unknownTCP traffic detected without corresponding DNS query: 47.125.240.84
    Source: unknownTCP traffic detected without corresponding DNS query: 57.8.81.223
    Source: unknownTCP traffic detected without corresponding DNS query: 23.50.220.217
    Source: unknownTCP traffic detected without corresponding DNS query: 73.46.136.207
    Source: unknownTCP traffic detected without corresponding DNS query: 192.89.191.6
    Source: unknownTCP traffic detected without corresponding DNS query: 60.64.228.232
    Source: unknownTCP traffic detected without corresponding DNS query: 75.203.207.217
    Source: unknownTCP traffic detected without corresponding DNS query: 163.88.47.71
    Source: unknownTCP traffic detected without corresponding DNS query: 42.237.32.248
    Source: unknownTCP traffic detected without corresponding DNS query: 150.221.199.109
    Source: unknownTCP traffic detected without corresponding DNS query: 19.0.217.207
    Source: unknownTCP traffic detected without corresponding DNS query: 250.16.28.79
    Source: unknownTCP traffic detected without corresponding DNS query: 107.252.94.222
    Source: unknownTCP traffic detected without corresponding DNS query: 192.50.222.74
    Source: unknownTCP traffic detected without corresponding DNS query: 107.117.147.93
    Source: unknownTCP traffic detected without corresponding DNS query: 169.138.96.213
    Source: unknownTCP traffic detected without corresponding DNS query: 18.96.158.1
    Source: unknownTCP traffic detected without corresponding DNS query: 116.67.244.33
    Source: unknownTCP traffic detected without corresponding DNS query: 57.244.27.55
    Source: unknownTCP traffic detected without corresponding DNS query: 184.217.61.34
    Source: unknownTCP traffic detected without corresponding DNS query: 252.137.132.179
    Source: unknownTCP traffic detected without corresponding DNS query: 118.232.80.207
    Source: unknownTCP traffic detected without corresponding DNS query: 18.182.98.193
    Source: unknownTCP traffic detected without corresponding DNS query: 192.9.42.7
    Source: unknownTCP traffic detected without corresponding DNS query: 205.187.71.176
    Source: unknownTCP traffic detected without corresponding DNS query: 252.97.60.34
    Source: unknownTCP traffic detected without corresponding DNS query: 178.239.202.195
    Source: unknownTCP traffic detected without corresponding DNS query: 18.169.214.44
    Source: unknownTCP traffic detected without corresponding DNS query: 54.118.2.114
    Source: unknownTCP traffic detected without corresponding DNS query: 248.61.246.8
    Source: unknownTCP traffic detected without corresponding DNS query: 141.234.1.205
    Source: unknownTCP traffic detected without corresponding DNS query: 77.48.99.254
    Source: unknownTCP traffic detected without corresponding DNS query: 174.251.29.219
    Source: unknownTCP traffic detected without corresponding DNS query: 87.1.84.37
    Source: unknownTCP traffic detected without corresponding DNS query: 125.240.72.254
    Source: unknownTCP traffic detected without corresponding DNS query: 173.0.147.247
    Source: unknownTCP traffic detected without corresponding DNS query: 116.223.177.216
    Source: unknownTCP traffic detected without corresponding DNS query: 8.222.84.87
    Source: unknownTCP traffic detected without corresponding DNS query: 194.198.169.176
    Source: unknownTCP traffic detected without corresponding DNS query: 150.84.116.130
    Source: unknownTCP traffic detected without corresponding DNS query: 162.165.39.78
    Source: unknownTCP traffic detected without corresponding DNS query: 249.204.91.17
    Source: unknownTCP traffic detected without corresponding DNS query: 191.49.123.189
    Source: unknownTCP traffic detected without corresponding DNS query: 184.250.54.229
    Source: unknownTCP traffic detected without corresponding DNS query: 133.148.41.181
    Source: unknownTCP traffic detected without corresponding DNS query: 120.97.159.124

    System Summary:

    barindex
    Sample tries to kill many processes (SIGKILL)Show sources
    Source: /tmp/gL6zNW1uNj (PID: 5241)SIGKILL sent: pid: 936, result: successful
    Source: /tmp/gL6zNW1uNj (PID: 5247)SIGKILL sent: pid: 5273, result: successful
    Source: /tmp/gL6zNW1uNj (PID: 5247)SIGKILL sent: pid: 5275, result: successful
    Source: /tmp/gL6zNW1uNj (PID: 5247)SIGKILL sent: pid: 720, result: successful
    Source: /tmp/gL6zNW1uNj (PID: 5247)SIGKILL sent: pid: 759, result: successful
    Source: /tmp/gL6zNW1uNj (PID: 5247)SIGKILL sent: pid: 788, result: successful
    Source: /tmp/gL6zNW1uNj (PID: 5247)SIGKILL sent: pid: 800, result: successful
    Source: /tmp/gL6zNW1uNj (PID: 5247)SIGKILL sent: pid: 847, result: successful
    Source: /tmp/gL6zNW1uNj (PID: 5247)SIGKILL sent: pid: 884, result: successful
    Source: /tmp/gL6zNW1uNj (PID: 5247)SIGKILL sent: pid: 1334, result: successful
    Source: /tmp/gL6zNW1uNj (PID: 5247)SIGKILL sent: pid: 1335, result: successful
    Source: /tmp/gL6zNW1uNj (PID: 5247)SIGKILL sent: pid: 1860, result: successful
    Source: /tmp/gL6zNW1uNj (PID: 5247)SIGKILL sent: pid: 1872, result: successful
    Source: /tmp/gL6zNW1uNj (PID: 5247)SIGKILL sent: pid: 2096, result: successful
    Source: /tmp/gL6zNW1uNj (PID: 5247)SIGKILL sent: pid: 2097, result: successful
    Source: /tmp/gL6zNW1uNj (PID: 5247)SIGKILL sent: pid: 2102, result: successful
    Source: /tmp/gL6zNW1uNj (PID: 5247)SIGKILL sent: pid: 2180, result: successful
    Source: /tmp/gL6zNW1uNj (PID: 5247)SIGKILL sent: pid: 2191, result: successful
    Source: /tmp/gL6zNW1uNj (PID: 5247)SIGKILL sent: pid: 2208, result: successful
    Source: /tmp/gL6zNW1uNj (PID: 5247)SIGKILL sent: pid: 2275, result: successful
    Source: /tmp/gL6zNW1uNj (PID: 5247)SIGKILL sent: pid: 2281, result: successful
    Source: /tmp/gL6zNW1uNj (PID: 5247)SIGKILL sent: pid: 2285, result: successful
    Source: /tmp/gL6zNW1uNj (PID: 5247)SIGKILL sent: pid: 2289, result: successful
    Source: /tmp/gL6zNW1uNj (PID: 5247)SIGKILL sent: pid: 2294, result: successful
    Source: /tmp/gL6zNW1uNj (PID: 5247)SIGKILL sent: pid: 5250, result: successful
    Source: /tmp/gL6zNW1uNj (PID: 5247)SIGKILL sent: pid: 5280, result: successful
    Source: /tmp/gL6zNW1uNj (PID: 5247)SIGKILL sent: pid: 5281, result: successful
    Source: /tmp/gL6zNW1uNj (PID: 5247)SIGKILL sent: pid: 5286, result: successful
    Source: ELF static info symbol of initial sample.symtab present: no
    Source: /tmp/gL6zNW1uNj (PID: 5241)SIGKILL sent: pid: 936, result: successful
    Source: /tmp/gL6zNW1uNj (PID: 5247)SIGKILL sent: pid: 5273, result: successful
    Source: /tmp/gL6zNW1uNj (PID: 5247)SIGKILL sent: pid: 5275, result: successful
    Source: /tmp/gL6zNW1uNj (PID: 5247)SIGKILL sent: pid: 720, result: successful
    Source: /tmp/gL6zNW1uNj (PID: 5247)SIGKILL sent: pid: 759, result: successful
    Source: /tmp/gL6zNW1uNj (PID: 5247)SIGKILL sent: pid: 788, result: successful
    Source: /tmp/gL6zNW1uNj (PID: 5247)SIGKILL sent: pid: 800, result: successful
    Source: /tmp/gL6zNW1uNj (PID: 5247)SIGKILL sent: pid: 847, result: successful
    Source: /tmp/gL6zNW1uNj (PID: 5247)SIGKILL sent: pid: 884, result: successful
    Source: /tmp/gL6zNW1uNj (PID: 5247)SIGKILL sent: pid: 1334, result: successful
    Source: /tmp/gL6zNW1uNj (PID: 5247)SIGKILL sent: pid: 1335, result: successful
    Source: /tmp/gL6zNW1uNj (PID: 5247)SIGKILL sent: pid: 1860, result: successful
    Source: /tmp/gL6zNW1uNj (PID: 5247)SIGKILL sent: pid: 1872, result: successful
    Source: /tmp/gL6zNW1uNj (PID: 5247)SIGKILL sent: pid: 2096, result: successful
    Source: /tmp/gL6zNW1uNj (PID: 5247)SIGKILL sent: pid: 2097, result: successful
    Source: /tmp/gL6zNW1uNj (PID: 5247)SIGKILL sent: pid: 2102, result: successful
    Source: /tmp/gL6zNW1uNj (PID: 5247)SIGKILL sent: pid: 2180, result: successful
    Source: /tmp/gL6zNW1uNj (PID: 5247)SIGKILL sent: pid: 2191, result: successful
    Source: /tmp/gL6zNW1uNj (PID: 5247)SIGKILL sent: pid: 2208, result: successful
    Source: /tmp/gL6zNW1uNj (PID: 5247)SIGKILL sent: pid: 2275, result: successful
    Source: /tmp/gL6zNW1uNj (PID: 5247)SIGKILL sent: pid: 2281, result: successful
    Source: /tmp/gL6zNW1uNj (PID: 5247)SIGKILL sent: pid: 2285, result: successful
    Source: /tmp/gL6zNW1uNj (PID: 5247)SIGKILL sent: pid: 2289, result: successful
    Source: /tmp/gL6zNW1uNj (PID: 5247)SIGKILL sent: pid: 2294, result: successful
    Source: /tmp/gL6zNW1uNj (PID: 5247)SIGKILL sent: pid: 5250, result: successful
    Source: /tmp/gL6zNW1uNj (PID: 5247)SIGKILL sent: pid: 5280, result: successful
    Source: /tmp/gL6zNW1uNj (PID: 5247)SIGKILL sent: pid: 5281, result: successful
    Source: /tmp/gL6zNW1uNj (PID: 5247)SIGKILL sent: pid: 5286, result: successful
    Source: classification engineClassification label: mal72.spre.troj.lin@0/4@0/0
    Source: gL6zNW1uNjJoe Sandbox Cloud Basic: Detection: clean Score: 0Perma Link
    Source: /tmp/gL6zNW1uNj (PID: 5241)File opened: /proc/491/fd
    Source: /tmp/gL6zNW1uNj (PID: 5241)File opened: /proc/793/fd
    Source: /tmp/gL6zNW1uNj (PID: 5241)File opened: /proc/772/fd
    Source: /tmp/gL6zNW1uNj (PID: 5241)File opened: /proc/796/fd
    Source: /tmp/gL6zNW1uNj (PID: 5241)File opened: /proc/774/fd
    Source: /tmp/gL6zNW1uNj (PID: 5241)File opened: /proc/797/fd
    Source: /tmp/gL6zNW1uNj (PID: 5241)File opened: /proc/777/fd
    Source: /tmp/gL6zNW1uNj (PID: 5241)File opened: /proc/799/fd
    Source: /tmp/gL6zNW1uNj (PID: 5241)File opened: /proc/658/fd
    Source: /tmp/gL6zNW1uNj (PID: 5241)File opened: /proc/912/fd
    Source: /tmp/gL6zNW1uNj (PID: 5241)File opened: /proc/759/fd
    Source: /tmp/gL6zNW1uNj (PID: 5241)File opened: /proc/936/fd
    Source: /tmp/gL6zNW1uNj (PID: 5241)File opened: /proc/918/fd
    Source: /tmp/gL6zNW1uNj (PID: 5241)File opened: /proc/1/fd
    Source: /tmp/gL6zNW1uNj (PID: 5241)File opened: /proc/761/fd
    Source: /tmp/gL6zNW1uNj (PID: 5241)File opened: /proc/785/fd
    Source: /tmp/gL6zNW1uNj (PID: 5241)File opened: /proc/884/fd
    Source: /tmp/gL6zNW1uNj (PID: 5241)File opened: /proc/720/fd
    Source: /tmp/gL6zNW1uNj (PID: 5241)File opened: /proc/721/fd
    Source: /tmp/gL6zNW1uNj (PID: 5241)File opened: /proc/788/fd
    Source: /tmp/gL6zNW1uNj (PID: 5241)File opened: /proc/789/fd
    Source: /tmp/gL6zNW1uNj (PID: 5241)File opened: /proc/800/fd
    Source: /tmp/gL6zNW1uNj (PID: 5241)File opened: /proc/801/fd
    Source: /tmp/gL6zNW1uNj (PID: 5241)File opened: /proc/847/fd
    Source: /tmp/gL6zNW1uNj (PID: 5241)File opened: /proc/904/fd
    Source: /tmp/gL6zNW1uNj (PID: 5247)File opened: /proc/5261/fd
    Source: /tmp/gL6zNW1uNj (PID: 5247)File opened: /proc/5261/fd
    Source: /tmp/gL6zNW1uNj (PID: 5247)File opened: /proc/5261/exe
    Source: /tmp/gL6zNW1uNj (PID: 5247)File opened: /proc/5262/fd
    Source: /tmp/gL6zNW1uNj (PID: 5247)File opened: /proc/5262/fd
    Source: /tmp/gL6zNW1uNj (PID: 5247)File opened: /proc/5262/exe
    Source: /tmp/gL6zNW1uNj (PID: 5247)File opened: /proc/5263/fd
    Source: /tmp/gL6zNW1uNj (PID: 5247)File opened: /proc/5263/fd
    Source: /tmp/gL6zNW1uNj (PID: 5247)File opened: /proc/5263/exe
    Source: /tmp/gL6zNW1uNj (PID: 5247)File opened: /proc/5264/fd
    Source: /tmp/gL6zNW1uNj (PID: 5247)File opened: /proc/5264/fd
    Source: /tmp/gL6zNW1uNj (PID: 5247)File opened: /proc/5264/exe
    Source: /tmp/gL6zNW1uNj (PID: 5247)File opened: /proc/5265/fd
    Source: /tmp/gL6zNW1uNj (PID: 5247)File opened: /proc/5265/fd
    Source: /tmp/gL6zNW1uNj (PID: 5247)File opened: /proc/5265/exe
    Source: /tmp/gL6zNW1uNj (PID: 5247)File opened: /proc/5266/fd
    Source: /tmp/gL6zNW1uNj (PID: 5247)File opened: /proc/5266/fd
    Source: /tmp/gL6zNW1uNj (PID: 5247)File opened: /proc/5266/exe
    Source: /tmp/gL6zNW1uNj (PID: 5247)File opened: /proc/5145/exe
    Source: /tmp/gL6zNW1uNj (PID: 5247)File opened: /proc/5267/fd
    Source: /tmp/gL6zNW1uNj (PID: 5247)File opened: /proc/5267/fd
    Source: /tmp/gL6zNW1uNj (PID: 5247)File opened: /proc/5267/exe
    Source: /tmp/gL6zNW1uNj (PID: 5247)File opened: /proc/5268/fd
    Source: /tmp/gL6zNW1uNj (PID: 5247)File opened: /proc/5268/fd
    Source: /tmp/gL6zNW1uNj (PID: 5247)File opened: /proc/5268/exe
    Source: /tmp/gL6zNW1uNj (PID: 5247)File opened: /proc/2033/fd
    Source: /tmp/gL6zNW1uNj (PID: 5247)File opened: /proc/2033/fd
    Source: /tmp/gL6zNW1uNj (PID: 5247)File opened: /proc/2033/exe
    Source: /tmp/gL6zNW1uNj (PID: 5247)File opened: /proc/1582/fd
    Source: /tmp/gL6zNW1uNj (PID: 5247)File opened: /proc/1582/fd
    Source: /tmp/gL6zNW1uNj (PID: 5247)File opened: /proc/1582/exe
    Source: /tmp/gL6zNW1uNj (PID: 5247)File opened: /proc/2275/fd
    Source: /tmp/gL6zNW1uNj (PID: 5247)File opened: /proc/2275/fd
    Source: /tmp/gL6zNW1uNj (PID: 5247)File opened: /proc/2275/exe
    Source: /tmp/gL6zNW1uNj (PID: 5247)File opened: /proc/3088/exe
    Source: /tmp/gL6zNW1uNj (PID: 5247)File opened: /proc/5260/fd
    Source: /tmp/gL6zNW1uNj (PID: 5247)File opened: /proc/5260/fd
    Source: /tmp/gL6zNW1uNj (PID: 5247)File opened: /proc/5260/exe
    Source: /tmp/gL6zNW1uNj (PID: 5247)File opened: /proc/1612/fd
    Source: /tmp/gL6zNW1uNj (PID: 5247)File opened: /proc/1612/fd
    Source: /tmp/gL6zNW1uNj (PID: 5247)File opened: /proc/1612/exe
    Source: /tmp/gL6zNW1uNj (PID: 5247)File opened: /proc/1579/fd
    Source: /tmp/gL6zNW1uNj (PID: 5247)File opened: /proc/1579/fd
    Source: /tmp/gL6zNW1uNj (PID: 5247)File opened: /proc/1579/exe
    Source: /tmp/gL6zNW1uNj (PID: 5247)File opened: /proc/1699/fd
    Source: /tmp/gL6zNW1uNj (PID: 5247)File opened: /proc/1699/fd
    Source: /tmp/gL6zNW1uNj (PID: 5247)File opened: /proc/1699/exe
    Source: /tmp/gL6zNW1uNj (PID: 5247)File opened: /proc/1335/fd
    Source: /tmp/gL6zNW1uNj (PID: 5247)File opened: /proc/1335/fd
    Source: /tmp/gL6zNW1uNj (PID: 5247)File opened: /proc/1335/exe
    Source: /tmp/gL6zNW1uNj (PID: 5247)File opened: /proc/1698/fd
    Source: /tmp/gL6zNW1uNj (PID: 5247)File opened: /proc/1698/fd
    Source: /tmp/gL6zNW1uNj (PID: 5247)File opened: /proc/1698/exe
    Source: /tmp/gL6zNW1uNj (PID: 5247)File opened: /proc/2028/fd
    Source: /tmp/gL6zNW1uNj (PID: 5247)File opened: /proc/2028/fd
    Source: /tmp/gL6zNW1uNj (PID: 5247)File opened: /proc/2028/exe
    Source: /tmp/gL6zNW1uNj (PID: 5247)File opened: /proc/1334/fd
    Source: /tmp/gL6zNW1uNj (PID: 5247)File opened: /proc/1334/fd
    Source: /tmp/gL6zNW1uNj (PID: 5247)File opened: /proc/1334/exe
    Source: /tmp/gL6zNW1uNj (PID: 5247)File opened: /proc/1576/fd
    Source: /tmp/gL6zNW1uNj (PID: 5247)File opened: /proc/1576/fd
    Source: /tmp/gL6zNW1uNj (PID: 5247)File opened: /proc/1576/exe
    Source: /tmp/gL6zNW1uNj (PID: 5247)File opened: /proc/2302/fd
    Source: /tmp/gL6zNW1uNj (PID: 5247)File opened: /proc/2302/fd
    Source: /tmp/gL6zNW1uNj (PID: 5247)File opened: /proc/2302/exe
    Source: /tmp/gL6zNW1uNj (PID: 5247)File opened: /proc/3236/fd
    Source: /tmp/gL6zNW1uNj (PID: 5247)File opened: /proc/3236/fd
    Source: /tmp/gL6zNW1uNj (PID: 5247)File opened: /proc/3236/exe
    Source: /tmp/gL6zNW1uNj (PID: 5247)File opened: /proc/2025/fd
    Source: /tmp/gL6zNW1uNj (PID: 5247)File opened: /proc/2025/fd
    Source: /tmp/gL6zNW1uNj (PID: 5247)File opened: /proc/2025/exe
    Source: /tmp/gL6zNW1uNj (PID: 5247)File opened: /proc/2146/fd
    Source: /tmp/gL6zNW1uNj (PID: 5247)File opened: /proc/2146/fd
    Source: /tmp/gL6zNW1uNj (PID: 5247)File opened: /proc/2146/exe
    Source: /tmp/gL6zNW1uNj (PID: 5247)File opened: /proc/5258/fd
    Source: /tmp/gL6zNW1uNj (PID: 5247)File opened: /proc/5258/fd
    Source: /tmp/gL6zNW1uNj (PID: 5247)File opened: /proc/5258/exe
    Source: /tmp/gL6zNW1uNj (PID: 5247)File opened: /proc/910/exe
    Source: /tmp/gL6zNW1uNj (PID: 5247)File opened: /proc/5259/fd
    Source: /tmp/gL6zNW1uNj (PID: 5247)File opened: /proc/5259/fd
    Source: /tmp/gL6zNW1uNj (PID: 5247)File opened: /proc/5259/exe

    Hooking and other Techniques for Hiding and Protection:

    barindex
    Uses known network protocols on non-standard portsShow sources
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39940
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39944
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39948
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39958
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39970
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39976
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39978
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39982
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39984
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39986
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 54608
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 54610
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 54612
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 54614
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 54620
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 54622
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 54628
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 54630
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 54634
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 54636
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 49958
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 49960
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 49962
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 49964
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 49970
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 49972
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 49974
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 49976
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 49978
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 49980
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 56710
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 56716
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 56724
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 56730
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 56736
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 56742
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 56746
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 56748
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 56750
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 56752
    Source: /tmp/gL6zNW1uNj (PID: 5239)Queries kernel information via 'uname':
    Source: gL6zNW1uNj, 5239.1.00000000b1d99cf5.00000000f91ff669.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/sparc
    Source: gL6zNW1uNj, 5239.1.00000000b1d99cf5.00000000f91ff669.rw-.sdmpBinary or memory string: U!/etc/qemu-binfmt/sparc
    Source: gL6zNW1uNj, 5298.1.00000000b1d99cf5.00000000f91ff669.rw-.sdmpBinary or memory string: /usr/bin/vmtoolsd
    Source: gL6zNW1uNj, 5239.1.0000000082bb98ad.00000000d33cd321.rw-.sdmpBinary or memory string: {wx86_64/usr/bin/qemu-sparc/tmp/gL6zNW1uNjSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/gL6zNW1uNj
    Source: gL6zNW1uNj, 5298.1.00000000f91ff669.000000003459bf12.rw-.sdmpBinary or memory string: U/sparc/10 /usr/bin/qemu-sparc!/proc/5268/fd/111
    Source: gL6zNW1uNj, 5239.1.0000000082bb98ad.00000000d33cd321.rw-.sdmpBinary or memory string: /usr/bin/qemu-sparc
    Source: gL6zNW1uNj, 5298.1.00000000b1d99cf5.00000000f91ff669.rw-.sdmpBinary or memory string: U1/usr/bin/vmtoolsdparc/10!/proc/1890/fd/48!/proc/1642/exeP

    Stealing of Sensitive Information:

    barindex
    Yara detected MiraiShow sources
    Source: Yara matchFile source: dump.pcap, type: PCAP

    Remote Access Functionality:

    barindex
    Yara detected MiraiShow sources
    Source: Yara matchFile source: dump.pcap, type: PCAP

    Mitre Att&ck Matrix

    Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
    Valid AccountsWindows Management InstrumentationPath InterceptionPath InterceptionDirect Volume AccessOS Credential Dumping1Security Software Discovery11Remote ServicesData from Local SystemExfiltration Over Other Network MediumEncrypted Channel1Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
    Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over BluetoothNon-Standard Port11Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
    Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated ExfiltrationApplication Layer Protocol1Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data

    Malware Configuration

    No configs have been found

    Behavior Graph

    Hide Legend

    Legend:

    • Process
    • Signature
    • Created File
    • DNS/IP Info
    • Is Dropped
    • Number of created Files
    • Is malicious
    • Internet
    behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 519630 Sample: gL6zNW1uNj Startdate: 10/11/2021 Architecture: LINUX Score: 72 50 103.140.138.184 X86NETWORK-AS-APX86NetworkSdnBhdMY Malaysia 2->50 52 216.189.140.106 WCTAUS United States 2->52 54 98 other IPs or domains 2->54 58 Snort IDS alert for network traffic (e.g. based on Emerging Threat rules) 2->58 60 Multi AV Scanner detection for submitted file 2->60 62 Yara detected Mirai 2->62 64 Uses known network protocols on non-standard ports 2->64 10 gL6zNW1uNj 2->10         started        12 systemd sshd 2->12         started        14 systemd sshd 2->14         started        16 2 other processes 2->16 signatures3 process4 process5 18 gL6zNW1uNj 10->18         started        21 gL6zNW1uNj 10->21         started        23 gL6zNW1uNj 10->23         started        signatures6 56 Sample tries to kill many processes (SIGKILL) 18->56 25 gL6zNW1uNj 18->25         started        27 gL6zNW1uNj 18->27         started        29 gL6zNW1uNj 21->29         started        32 gL6zNW1uNj 21->32         started        34 gL6zNW1uNj 21->34         started        process7 signatures8 36 gL6zNW1uNj 25->36         started        38 gL6zNW1uNj 25->38         started        40 gL6zNW1uNj 25->40         started        66 Sample tries to kill many processes (SIGKILL) 29->66 42 gL6zNW1uNj 29->42         started        44 gL6zNW1uNj 29->44         started        process9 process10 46 gL6zNW1uNj 36->46         started        48 gL6zNW1uNj 36->48         started       

    Screenshots

    Thumbnails

    This section contains all screenshots as thumbnails, including those not shown in the slideshow.

    windows-stand

    Antivirus, Machine Learning and Genetic Malware Detection

    Initial Sample

    SourceDetectionScannerLabelLink
    gL6zNW1uNj49%VirustotalBrowse
    gL6zNW1uNj56%ReversingLabsLinux.Trojan.Mirai

    Dropped Files

    No Antivirus matches

    Domains

    No Antivirus matches

    URLs

    No Antivirus matches

    Domains and IPs

    Contacted Domains

    No contacted domains info

    Contacted IPs

    • No. of IPs < 25%
    • 25% < No. of IPs < 50%
    • 50% < No. of IPs < 75%
    • 75% < No. of IPs

    Public

    IPDomainCountryFlagASNASN NameMalicious
    197.153.61.25
    unknownMorocco
    36925ASMediMAfalse
    151.86.44.187
    unknownItaly
    8217ASN-ENIITfalse
    107.18.149.250
    unknownUnited States
    14654WAYPORTUSfalse
    243.122.7.203
    unknownReserved
    unknownunknownfalse
    83.81.157.142
    unknownNetherlands
    33915TNF-ASNLfalse
    170.201.71.125
    unknownUnited States
    10995PNCBANKUSfalse
    160.242.103.111
    unknownNamibia
    33763Paratus-TelecomNAfalse
    152.88.139.42
    unknownSwitzerland
    559SWITCHPeeringrequestspeeringswitchchEUfalse
    88.73.217.49
    unknownGermany
    3209VODANETInternationalIP-BackboneofVodafoneDEfalse
    191.85.197.196
    unknownArgentina
    22927TelefonicadeArgentinaARfalse
    195.161.24.251
    unknownRussian Federation
    8342RTCOMM-ASRUfalse
    34.154.113.0
    unknownUnited States
    2686ATGS-MMD-ASUSfalse
    27.104.108.182
    unknownSingapore
    4773MOBILEONELTD-AS-APMobileOneLtdMobileInternetServicePrfalse
    204.189.141.189
    unknownUnited States
    3561CENTURYLINK-LEGACY-SAVVISUSfalse
    85.248.170.96
    unknownSlovakia (SLOVAK Republic)
    5578AS-BENESTRABratislavaSlovakRepublicSKfalse
    81.43.97.163
    unknownSpain
    3352TELEFONICA_DE_ESPANAESfalse
    9.99.10.49
    unknownUnited States
    3356LEVEL3USfalse
    193.18.64.58
    unknownGermany
    41099GLOBALREACHGBfalse
    78.143.58.128
    unknownGermany
    34309LINK11Link11GmbHDEfalse
    159.142.240.78
    unknownUnited States
    2714GSA-GOVUSfalse
    83.195.47.1
    unknownFrance
    3215FranceTelecom-OrangeFRfalse
    100.39.34.187
    unknownUnited States
    5650FRONTIER-FRTRUSfalse
    35.155.144.153
    unknownUnited States
    16509AMAZON-02USfalse
    89.82.103.245
    unknownFrance
    5410BOUYGTEL-ISPFRfalse
    206.156.198.155
    unknownUnited States
    3561CENTURYLINK-LEGACY-SAVVISUSfalse
    63.15.73.8
    unknownUnited States
    701UUNETUSfalse
    102.248.204.116
    unknownSouth Africa
    5713SAIX-NETZAfalse
    247.105.76.221
    unknownReserved
    unknownunknownfalse
    248.44.16.163
    unknownReserved
    unknownunknownfalse
    135.205.234.119
    unknownUnited States
    6431ATT-RESEARCHUSfalse
    87.1.84.37
    unknownItaly
    3269ASN-IBSNAZITfalse
    241.35.160.0
    unknownReserved
    unknownunknownfalse
    246.89.40.146
    unknownReserved
    unknownunknownfalse
    168.82.87.233
    unknownUnited States
    8103STATE-OF-FLAUSfalse
    65.33.229.36
    unknownUnited States
    33363BHN-33363USfalse
    5.247.253.74
    unknownSaudi Arabia
    34400ASN-ETTIHADETISALATSAfalse
    157.138.8.249
    unknownItaly
    137ASGARRConsortiumGARREUfalse
    216.202.137.20
    unknownUnited States
    3356LEVEL3USfalse
    80.248.16.53
    unknownIceland
    29689ORIGO-ASISfalse
    24.93.166.148
    unknownUnited States
    10796TWC-10796-MIDWESTUSfalse
    18.160.223.44
    unknownUnited States
    3MIT-GATEWAYSUSfalse
    157.222.204.52
    unknownUnited States
    4704SANNETRakutenMobileIncJPfalse
    213.60.172.111
    unknownSpain
    12334Galicia-SpainESfalse
    75.223.213.59
    unknownUnited States
    22394CELLCOUSfalse
    111.243.11.20
    unknownTaiwan; Republic of China (ROC)
    3462HINETDataCommunicationBusinessGroupTWfalse
    162.239.12.7
    unknownUnited States
    7018ATT-INTERNET4USfalse
    14.185.213.79
    unknownViet Nam
    45899VNPT-AS-VNVNPTCorpVNfalse
    211.200.115.186
    unknownKorea Republic of
    9318SKB-ASSKBroadbandCoLtdKRfalse
    177.244.147.186
    unknownMexico
    13999MegaCableSAdeCVMXfalse
    173.81.96.181
    unknownUnited States
    19108SUDDENLINK-COMMUNICATIONSUSfalse
    114.159.61.103
    unknownJapan4713OCNNTTCommunicationsCorporationJPfalse
    169.156.132.11
    unknownUnited States
    6189EPFL-ASUSfalse
    110.26.118.12
    unknownTaiwan; Republic of China (ROC)
    9674FET-TWFarEastToneTelecommunicationCoLtdTWfalse
    216.189.140.106
    unknownUnited States
    21902WCTAUSfalse
    122.109.133.175
    unknownAustralia
    4804MPX-ASMicroplexPTYLTDAUfalse
    179.161.68.206
    unknownBrazil
    26599TELEFONICABRASILSABRfalse
    95.39.201.172
    unknownSpain
    12357COMUNITELSPAINESfalse
    221.190.17.112
    unknownJapan4713OCNNTTCommunicationsCorporationJPfalse
    142.14.127.103
    unknownCanada
    51964ORANGE-BUSINESS-SERVICES-IPSN-ASNFRfalse
    241.207.254.214
    unknownReserved
    unknownunknownfalse
    169.86.62.36
    unknownUnited States
    37611AfrihostZAfalse
    207.123.43.254
    unknownUnited States
    3356LEVEL3USfalse
    122.224.85.220
    unknownChina
    58461CT-HANGZHOU-IDCNo288Fu-chunRoadCNfalse
    193.146.135.162
    unknownSpain
    766REDIRISRedIRISAutonomousSystemESfalse
    244.39.205.7
    unknownReserved
    unknownunknownfalse
    18.40.249.230
    unknownUnited States
    3MIT-GATEWAYSUSfalse
    202.93.232.234
    unknownIndonesia
    38758HYPERNET-AS-IDPTHIPERNETINDODATAIDfalse
    155.199.164.179
    unknownUnited States
    786JANETJiscServicesLimitedGBfalse
    220.195.123.67
    unknownChina
    4837CHINA169-BACKBONECHINAUNICOMChina169BackboneCNfalse
    119.159.35.25
    unknownPakistan
    45595PKTELECOM-AS-PKPakistanTelecomCompanyLimitedPKfalse
    101.208.151.88
    unknownIndia
    58519CHINATELECOM-CTCLOUDCloudComputingCorporationCNfalse
    91.18.128.136
    unknownGermany
    3320DTAGInternetserviceprovideroperationsDEfalse
    194.52.199.122
    unknownSweden
    31529DENIC-ANYCAST-ASDNSanycastASobjectforDEDNSservicefalse
    23.50.220.217
    unknownUnited States
    16625AKAMAI-ASUSfalse
    98.146.118.80
    unknownUnited States
    10838OCEANIC-INTERNET-RRUSfalse
    203.168.187.234
    unknownHong Kong
    9908HKCABLE2-HK-APHKCableTVLtdHKfalse
    176.212.43.225
    unknownRussian Federation
    57378ROSTOV-ASRUfalse
    48.38.254.123
    unknownUnited States
    2686ATGS-MMD-ASUSfalse
    53.176.103.106
    unknownGermany
    31399DAIMLER-ASITIGNGlobalNetworkDEfalse
    152.223.201.108
    unknownUnited States
    30313IRSUSfalse
    102.55.170.247
    unknownMorocco
    6713IAM-ASMAfalse
    114.123.47.5
    unknownIndonesia
    23693TELKOMSEL-ASN-IDPTTelekomunikasiSelularIDfalse
    61.55.8.196
    unknownChina
    4837CHINA169-BACKBONECHINAUNICOMChina169BackboneCNfalse
    251.25.189.68
    unknownReserved
    unknownunknownfalse
    14.120.104.110
    unknownChina
    4134CHINANET-BACKBONENo31Jin-rongStreetCNfalse
    68.147.7.93
    unknownCanada
    6327SHAWCAfalse
    97.20.172.125
    unknownUnited States
    22394CELLCOUSfalse
    41.152.76.227
    unknownEgypt
    36992ETISALAT-MISREGfalse
    48.131.158.196
    unknownUnited States
    2686ATGS-MMD-ASUSfalse
    106.26.169.88
    unknownChina
    4134CHINANET-BACKBONENo31Jin-rongStreetCNfalse
    130.252.51.239
    unknownUnited States
    14365ADOBE-NETUSfalse
    155.54.253.41
    unknownSpain
    766REDIRISRedIRISAutonomousSystemESfalse
    8.2.139.206
    unknownUnited States
    3356LEVEL3USfalse
    75.235.78.135
    unknownUnited States
    22394CELLCOUSfalse
    36.131.159.191
    unknownChina
    56044CMNET-AS-LIAONINGChinaMobilecommunicationscorporationCfalse
    100.49.35.79
    unknownUnited States
    701UUNETUSfalse
    166.14.24.193
    unknownSwitzerland
    11798ACEDATACENTERS-AS-1USfalse
    246.125.194.19
    unknownReserved
    unknownunknownfalse
    223.218.222.111
    unknownJapan4713OCNNTTCommunicationsCorporationJPfalse
    103.140.138.184
    unknownMalaysia
    133936X86NETWORK-AS-APX86NetworkSdnBhdMYfalse


    Runtime Messages

    Command:/tmp/gL6zNW1uNj
    Exit Code:0
    Exit Code Info:
    Killed:False
    Standard Output:
    Connected To CNC
    Standard Error:

    Joe Sandbox View / Context

    IPs

    No context

    Domains

    No context

    ASN

    MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
    ASN-ENIITHwcNrhNfZgGet hashmaliciousBrowse
    • 151.98.27.212
    sora.armGet hashmaliciousBrowse
    • 151.96.119.3
    WhFNix8BoEGet hashmaliciousBrowse
    • 151.98.75.125
    xd.x86Get hashmaliciousBrowse
    • 151.96.214.151
    re2.arm7Get hashmaliciousBrowse
    • 151.98.75.126
    QcXQmNSaSpGet hashmaliciousBrowse
    • 151.98.27.220
    Darknet.x86Get hashmaliciousBrowse
    • 151.98.75.124
    sora.armGet hashmaliciousBrowse
    • 151.86.219.27
    j1zDAEIWibGet hashmaliciousBrowse
    • 151.98.75.136
    c0k7KpL89rGet hashmaliciousBrowse
    • 151.96.108.147
    ASMediMA3ObdCtrussGet hashmaliciousBrowse
    • 102.103.39.117
    DVHEnaPp2dGet hashmaliciousBrowse
    • 105.188.238.148
    x86Get hashmaliciousBrowse
    • 196.127.145.158
    fZ9Y8XVXDHGet hashmaliciousBrowse
    • 45.219.30.154
    SQFoFeC1jQGet hashmaliciousBrowse
    • 197.153.85.54
    xd.x86Get hashmaliciousBrowse
    • 41.93.16.194
    sora.mpslGet hashmaliciousBrowse
    • 41.87.150.68
    MePwVTNRoAGet hashmaliciousBrowse
    • 45.219.30.100
    eFsSvDKamsGet hashmaliciousBrowse
    • 41.92.37.100
    Hilix.arm7Get hashmaliciousBrowse
    • 45.219.30.118
    Hilix.x86Get hashmaliciousBrowse
    • 45.219.30.106
    aTQ4RalkUsGet hashmaliciousBrowse
    • 41.214.134.111
    8PRjJeUifBGet hashmaliciousBrowse
    • 45.216.221.197
    t7WU0JjLARGet hashmaliciousBrowse
    • 41.92.113.34
    FGVOkw9didGet hashmaliciousBrowse
    • 197.247.118.67
    arm7-20211101-1513Get hashmaliciousBrowse
    • 196.126.207.163
    mxHkqAIYT0Get hashmaliciousBrowse
    • 41.87.150.73
    Antisocial.x86Get hashmaliciousBrowse
    • 45.219.30.151
    w66OTKGVFvGet hashmaliciousBrowse
    • 45.219.30.100
    ydZLm6GD56Get hashmaliciousBrowse
    • 45.219.30.146
    WAYPORTUS8fVDxGRR8SGet hashmaliciousBrowse
    • 216.12.242.81
    P8NtIPe7f0Get hashmaliciousBrowse
    • 206.59.196.119
    3AlyfRnHRdGet hashmaliciousBrowse
    • 100.47.222.235
    YYcy9gLbBCGet hashmaliciousBrowse
    • 107.19.227.149
    rMwxCtXmuJGet hashmaliciousBrowse
    • 107.25.250.38
    b3astmode.armGet hashmaliciousBrowse
    • 107.18.150.164
    6A9RyJXCd7Get hashmaliciousBrowse
    • 100.46.121.11
    1Y2rsDBP9sGet hashmaliciousBrowse
    • 107.28.67.253
    lYmYPlzghQGet hashmaliciousBrowse
    • 107.28.67.222
    gbk4XWulUoGet hashmaliciousBrowse
    • 184.49.234.70
    INsMwWSMehGet hashmaliciousBrowse
    • 184.49.234.47
    WnhlYWJ5C5Get hashmaliciousBrowse
    • 107.18.150.166
    1S80No4PTVGet hashmaliciousBrowse
    • 107.28.20.236
    apep.x86Get hashmaliciousBrowse
    • 107.18.224.74
    6NzbU4oW61Get hashmaliciousBrowse
    • 107.18.200.92
    sora.armGet hashmaliciousBrowse
    • 107.18.39.9
    wL8CswnbUJGet hashmaliciousBrowse
    • 107.25.249.96
    JWCIQ6dmiXGet hashmaliciousBrowse
    • 107.16.234.110
    DT5DNY63RpGet hashmaliciousBrowse
    • 107.18.102.202
    eUjl39mhBTGet hashmaliciousBrowse
    • 107.25.121.193

    JA3 Fingerprints

    No context

    Dropped Files

    No context

    Created / dropped Files

    /proc/5286/oom_score_adj
    Process:/usr/sbin/sshd
    File Type:ASCII text
    Category:dropped
    Size (bytes):6
    Entropy (8bit):1.7924812503605778
    Encrypted:false
    SSDEEP:3:ptn:Dn
    MD5:CBF282CC55ED0792C33D10003D1F760A
    SHA1:007DD8BD75468E6B7ABA4285E9B267202C7EAEED
    SHA-256:FCDBAB99FCC0F4409E5F9D7D6FC497780288B4C441698126BB62832412774D22
    SHA-512:4643A8675D213C7DA35CC0C2BFB3B6F20324F9C48AEA7BA79F470615698C9A0CEFDA45CAA1957FC29110EE746BC8458AB8AB1E43EB513912A5E1E8858812CC00
    Malicious:false
    Reputation:high, very likely benign file
    Preview: -1000.
    /proc/5304/oom_score_adj
    Process:/usr/sbin/sshd
    File Type:ASCII text
    Category:dropped
    Size (bytes):6
    Entropy (8bit):1.7924812503605778
    Encrypted:false
    SSDEEP:3:ptn:Dn
    MD5:CBF282CC55ED0792C33D10003D1F760A
    SHA1:007DD8BD75468E6B7ABA4285E9B267202C7EAEED
    SHA-256:FCDBAB99FCC0F4409E5F9D7D6FC497780288B4C441698126BB62832412774D22
    SHA-512:4643A8675D213C7DA35CC0C2BFB3B6F20324F9C48AEA7BA79F470615698C9A0CEFDA45CAA1957FC29110EE746BC8458AB8AB1E43EB513912A5E1E8858812CC00
    Malicious:false
    Reputation:high, very likely benign file
    Preview: -1000.
    /run/sshd.pid
    Process:/usr/sbin/sshd
    File Type:ASCII text
    Category:dropped
    Size (bytes):5
    Entropy (8bit):2.321928094887362
    Encrypted:false
    SSDEEP:3:DVRv:JRv
    MD5:C20A7ECD1C53AD9522EEDDA05994E0FF
    SHA1:4C58A470A925D0778306B17AF553D80D949DD3DD
    SHA-256:4FA6BD7EB31F8EFFFE3EFAE78A995D530EB82462034F575AAF8163F46920EA78
    SHA-512:AC700633B219F0FC8BAADF5CA1B007794B7B2264ACC514CF4C55CE470993EC7B851D464D04A90302B91DAEB505FEE0F6E14669F2DB36B2DD7770FC4C42727CA1
    Malicious:false
    Reputation:low
    Preview: 5304.

    Static File Info

    General

    File type:ELF 32-bit MSB executable, SPARC, version 1 (SYSV), statically linked, stripped
    Entropy (8bit):6.035636042849447
    TrID:
    • ELF Executable and Linkable format (generic) (4004/1) 100.00%
    File name:gL6zNW1uNj
    File size:60412
    MD5:deee0487e17b20a74a1757f36e92a240
    SHA1:865c8c7d1b4d725220d58075839e1429820e3465
    SHA256:9ad0477757b6e3b5808cb2ef7b0a53c58823ab63339d8575f454341446bf2b14
    SHA512:94ea25eb83484a1f32249847cedff76bb149cf4f7b7d36f60b70ca057bf57407b381be6826734fba85cd4313a2b46f5fce4baae1373c174f2df99ff83c810c4d
    SSDEEP:768:eLobAxU6q9Hfymp0xginuYvCkLB6WsTwIC1DQdszoDaS0O+DCDp:eL0AxvSHfymp0xgunvCkV6vTMDaue
    File Content Preview:.ELF...........................4...l.....4. ...(.......................................................x............dt.Q................................@..(....@.8R................#.....b0..`.....!..... ...@.....".........`......$ ... ...@...........`....

    Static ELF Info

    ELF header

    Class:ELF32
    Data:2's complement, big endian
    Version:1 (current)
    Machine:Sparc
    Version Number:0x1
    Type:EXEC (Executable file)
    OS/ABI:UNIX - System V
    ABI Version:0
    Entry Point Address:0x101a4
    Flags:0x0
    ELF Header Size:52
    Program Header Offset:52
    Program Header Size:32
    Number of Program Headers:3
    Section Header Offset:60012
    Section Header Size:40
    Number of Section Headers:10
    Header String Table Index:9

    Sections

    NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
    NULL0x00x00x00x00x0000
    .initPROGBITS0x100940x940x1c0x00x6AX004
    .textPROGBITS0x100b00xb00xe1800x00x6AX004
    .finiPROGBITS0x1e2300xe2300x140x00x6AX004
    .rodataPROGBITS0x1e2480xe2480x6680x00x2A008
    .ctorsPROGBITS0x2e8b40xe8b40x80x00x3WA004
    .dtorsPROGBITS0x2e8bc0xe8bc0x80x00x3WA004
    .dataPROGBITS0x2e8c80xe8c80x1640x00x3WA008
    .bssNOBITS0x2ea300xea2c0x2880x00x3WA008
    .shstrtabSTRTAB0x00xea2c0x3e0x00x0001

    Program Segments

    TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
    LOAD0x00x100000x100000xe8b00xe8b03.38840x5R E0x10000.init .text .fini .rodata
    LOAD0xe8b40x2e8b40x2e8b40x1780x4040.31830x6RW 0x10000.ctors .dtors .data .bss
    GNU_STACK0x00x00x00x00x00.00000x6RW 0x4

    Network Behavior

    Network Port Distribution

    TCP Packets

    TimestampSource PortDest PortSource IPDest IP
    Nov 10, 2021 23:51:51.843924999 CET443841312192.168.2.2386.126.191.187
    Nov 10, 2021 23:51:51.859568119 CET4685823192.168.2.23154.206.38.139
    Nov 10, 2021 23:51:51.859600067 CET4685823192.168.2.23101.130.129.147
    Nov 10, 2021 23:51:51.859610081 CET4685823192.168.2.238.204.194.128
    Nov 10, 2021 23:51:51.859730959 CET4685823192.168.2.2347.125.240.84
    Nov 10, 2021 23:51:51.859765053 CET4685823192.168.2.2357.8.81.223
    Nov 10, 2021 23:51:51.859764099 CET4685823192.168.2.2323.50.220.217
    Nov 10, 2021 23:51:51.859771967 CET4685823192.168.2.2373.46.136.207
    Nov 10, 2021 23:51:51.859837055 CET4685823192.168.2.23192.89.191.6
    Nov 10, 2021 23:51:51.859843016 CET4685823192.168.2.2360.64.228.232
    Nov 10, 2021 23:51:51.859885931 CET4685823192.168.2.2375.203.207.217
    Nov 10, 2021 23:51:51.859934092 CET4685823192.168.2.23163.88.47.71
    Nov 10, 2021 23:51:51.860040903 CET4685823192.168.2.2342.237.32.248
    Nov 10, 2021 23:51:51.860090971 CET4685823192.168.2.23150.221.199.109
    Nov 10, 2021 23:51:51.860116005 CET4685823192.168.2.2319.0.217.207
    Nov 10, 2021 23:51:51.860124111 CET4685823192.168.2.23250.16.28.79
    Nov 10, 2021 23:51:51.860204935 CET4685823192.168.2.23107.252.94.222
    Nov 10, 2021 23:51:51.860215902 CET4685823192.168.2.23192.50.222.74
    Nov 10, 2021 23:51:51.860243082 CET4685823192.168.2.23107.117.147.93
    Nov 10, 2021 23:51:51.860269070 CET4685823192.168.2.23169.138.96.213
    Nov 10, 2021 23:51:51.860287905 CET4685823192.168.2.2318.96.158.1
    Nov 10, 2021 23:51:51.860313892 CET4685823192.168.2.23116.67.244.33
    Nov 10, 2021 23:51:51.860333920 CET4685823192.168.2.2357.244.27.55
    Nov 10, 2021 23:51:51.860343933 CET4685823192.168.2.23184.217.61.34
    Nov 10, 2021 23:51:51.860359907 CET4685823192.168.2.23252.137.132.179
    Nov 10, 2021 23:51:51.860363007 CET4685823192.168.2.23118.232.80.207
    Nov 10, 2021 23:51:51.860367060 CET4685823192.168.2.2318.182.98.193
    Nov 10, 2021 23:51:51.860444069 CET4685823192.168.2.23192.9.42.7
    Nov 10, 2021 23:51:51.860553026 CET4685823192.168.2.23205.187.71.176
    Nov 10, 2021 23:51:51.860555887 CET4685823192.168.2.23252.97.60.34
    Nov 10, 2021 23:51:51.860599041 CET4685823192.168.2.23178.239.202.195
    Nov 10, 2021 23:51:51.860630035 CET4685823192.168.2.2318.169.214.44
    Nov 10, 2021 23:51:51.860641003 CET4685823192.168.2.2354.118.2.114
    Nov 10, 2021 23:51:51.860656023 CET4685823192.168.2.23248.61.246.8
    Nov 10, 2021 23:51:51.860662937 CET4685823192.168.2.23141.234.1.205
    Nov 10, 2021 23:51:51.860706091 CET4685823192.168.2.2377.48.99.254
    Nov 10, 2021 23:51:51.861448050 CET4685823192.168.2.23174.251.29.219
    Nov 10, 2021 23:51:51.861450911 CET4685823192.168.2.2387.1.84.37
    Nov 10, 2021 23:51:51.861465931 CET4685823192.168.2.23125.240.72.254
    Nov 10, 2021 23:51:51.861481905 CET4685823192.168.2.23173.0.147.247
    Nov 10, 2021 23:51:51.861515999 CET4685823192.168.2.23116.223.177.216
    Nov 10, 2021 23:51:51.861525059 CET4685823192.168.2.238.222.84.87
    Nov 10, 2021 23:51:51.861598969 CET4685823192.168.2.2385.110.243.120
    Nov 10, 2021 23:51:51.861598969 CET4685823192.168.2.23194.198.169.176
    Nov 10, 2021 23:51:51.861602068 CET4685823192.168.2.23150.84.116.130
    Nov 10, 2021 23:51:51.861649036 CET4685823192.168.2.23162.165.39.78
    Nov 10, 2021 23:51:51.861659050 CET4685823192.168.2.23249.204.91.17
    Nov 10, 2021 23:51:51.861676931 CET4685823192.168.2.23191.49.123.189
    Nov 10, 2021 23:51:51.861679077 CET4685823192.168.2.23184.250.54.229
    Nov 10, 2021 23:51:51.861689091 CET4685823192.168.2.23133.148.41.181
    Nov 10, 2021 23:51:51.861716986 CET4685823192.168.2.23191.102.210.3
    Nov 10, 2021 23:51:51.861745119 CET4685823192.168.2.23120.97.159.124
    Nov 10, 2021 23:51:51.861763954 CET4685823192.168.2.23136.246.50.137
    Nov 10, 2021 23:51:51.861804008 CET4685823192.168.2.23161.107.153.53
    Nov 10, 2021 23:51:51.861831903 CET4685823192.168.2.2323.120.22.234
    Nov 10, 2021 23:51:51.861843109 CET4685823192.168.2.23249.8.7.244
    Nov 10, 2021 23:51:51.861865044 CET4685823192.168.2.234.114.50.95
    Nov 10, 2021 23:51:51.861876965 CET4685823192.168.2.23250.238.23.116
    Nov 10, 2021 23:51:51.861949921 CET4685823192.168.2.2366.218.9.85
    Nov 10, 2021 23:51:51.861963034 CET4685823192.168.2.23201.36.148.253
    Nov 10, 2021 23:51:51.861973047 CET4685823192.168.2.23172.139.78.139
    Nov 10, 2021 23:51:51.862056017 CET4685823192.168.2.23146.29.209.89
    Nov 10, 2021 23:51:51.862080097 CET4685823192.168.2.23183.138.134.175
    Nov 10, 2021 23:51:51.862104893 CET4685823192.168.2.2370.72.184.27
    Nov 10, 2021 23:51:51.862132072 CET4685823192.168.2.2320.10.252.55
    Nov 10, 2021 23:51:51.862135887 CET4685823192.168.2.23167.178.18.202
    Nov 10, 2021 23:51:51.862143993 CET4685823192.168.2.23133.103.70.51
    Nov 10, 2021 23:51:51.862149954 CET4685823192.168.2.23123.5.159.197
    Nov 10, 2021 23:51:51.862164021 CET4685823192.168.2.2344.155.86.25
    Nov 10, 2021 23:51:51.862175941 CET4685823192.168.2.2316.119.213.67
    Nov 10, 2021 23:51:51.862224102 CET4685823192.168.2.2363.110.82.139
    Nov 10, 2021 23:51:51.862226009 CET4685823192.168.2.23221.47.134.53
    Nov 10, 2021 23:51:51.862282991 CET4685823192.168.2.2345.7.80.58
    Nov 10, 2021 23:51:51.862299919 CET4685823192.168.2.2387.83.165.254
    Nov 10, 2021 23:51:51.862325907 CET4685823192.168.2.2357.34.122.27
    Nov 10, 2021 23:51:51.862334013 CET4685823192.168.2.2317.41.207.222
    Nov 10, 2021 23:51:51.862346888 CET4685823192.168.2.23212.222.173.252
    Nov 10, 2021 23:51:51.862390995 CET4685823192.168.2.2394.189.3.124
    Nov 10, 2021 23:51:51.862437010 CET4685823192.168.2.23203.176.95.157
    Nov 10, 2021 23:51:51.862472057 CET4685823192.168.2.2394.196.203.172
    Nov 10, 2021 23:51:51.862482071 CET4685823192.168.2.23218.103.180.43
    Nov 10, 2021 23:51:51.862586975 CET4685823192.168.2.23159.42.39.166
    Nov 10, 2021 23:51:51.862629890 CET4685823192.168.2.23206.78.188.247
    Nov 10, 2021 23:51:51.862632990 CET4685823192.168.2.23166.114.166.97
    Nov 10, 2021 23:51:51.862652063 CET4685823192.168.2.23121.150.44.160
    Nov 10, 2021 23:51:51.862659931 CET4685823192.168.2.23207.125.245.15
    Nov 10, 2021 23:51:51.862673998 CET4685823192.168.2.23245.75.180.140
    Nov 10, 2021 23:51:51.863677025 CET4685823192.168.2.23212.221.199.76
    Nov 10, 2021 23:51:51.863678932 CET4685823192.168.2.2395.176.68.15
    Nov 10, 2021 23:51:51.863689899 CET4685823192.168.2.23200.62.2.204
    Nov 10, 2021 23:51:51.863706112 CET4685823192.168.2.238.23.132.21
    Nov 10, 2021 23:51:51.863708973 CET4685823192.168.2.23247.133.146.255
    Nov 10, 2021 23:51:51.863712072 CET4685823192.168.2.23163.79.145.69
    Nov 10, 2021 23:51:51.863722086 CET4685823192.168.2.231.40.112.189
    Nov 10, 2021 23:51:51.863724947 CET4685823192.168.2.23251.86.5.44
    Nov 10, 2021 23:51:51.863785982 CET4685823192.168.2.2399.223.216.218
    Nov 10, 2021 23:51:51.863791943 CET4685823192.168.2.2327.158.15.125
    Nov 10, 2021 23:51:51.863801003 CET4685823192.168.2.23181.57.188.3
    Nov 10, 2021 23:51:51.863806963 CET4685823192.168.2.23245.38.220.243
    Nov 10, 2021 23:51:51.863841057 CET4685823192.168.2.2369.57.21.172

    System Behavior

    General

    Start time:23:51:50
    Start date:10/11/2021
    Path:/tmp/gL6zNW1uNj
    Arguments:/tmp/gL6zNW1uNj
    File size:4379400 bytes
    MD5 hash:7dc1c0e23cd5e102bb12e5c29403410e

    General

    Start time:23:51:50
    Start date:10/11/2021
    Path:/tmp/gL6zNW1uNj
    Arguments:n/a
    File size:4379400 bytes
    MD5 hash:7dc1c0e23cd5e102bb12e5c29403410e

    General

    Start time:23:51:59
    Start date:10/11/2021
    Path:/tmp/gL6zNW1uNj
    Arguments:n/a
    File size:4379400 bytes
    MD5 hash:7dc1c0e23cd5e102bb12e5c29403410e

    General

    Start time:23:51:59
    Start date:10/11/2021
    Path:/tmp/gL6zNW1uNj
    Arguments:n/a
    File size:4379400 bytes
    MD5 hash:7dc1c0e23cd5e102bb12e5c29403410e

    General

    Start time:23:51:59
    Start date:10/11/2021
    Path:/tmp/gL6zNW1uNj
    Arguments:n/a
    File size:4379400 bytes
    MD5 hash:7dc1c0e23cd5e102bb12e5c29403410e

    General

    Start time:23:51:59
    Start date:10/11/2021
    Path:/tmp/gL6zNW1uNj
    Arguments:n/a
    File size:4379400 bytes
    MD5 hash:7dc1c0e23cd5e102bb12e5c29403410e

    General

    Start time:23:51:59
    Start date:10/11/2021
    Path:/tmp/gL6zNW1uNj
    Arguments:n/a
    File size:4379400 bytes
    MD5 hash:7dc1c0e23cd5e102bb12e5c29403410e

    General

    Start time:23:51:59
    Start date:10/11/2021
    Path:/tmp/gL6zNW1uNj
    Arguments:n/a
    File size:4379400 bytes
    MD5 hash:7dc1c0e23cd5e102bb12e5c29403410e

    General

    Start time:23:51:59
    Start date:10/11/2021
    Path:/tmp/gL6zNW1uNj
    Arguments:n/a
    File size:4379400 bytes
    MD5 hash:7dc1c0e23cd5e102bb12e5c29403410e

    General

    Start time:23:51:50
    Start date:10/11/2021
    Path:/tmp/gL6zNW1uNj
    Arguments:n/a
    File size:4379400 bytes
    MD5 hash:7dc1c0e23cd5e102bb12e5c29403410e

    General

    Start time:23:51:50
    Start date:10/11/2021
    Path:/tmp/gL6zNW1uNj
    Arguments:n/a
    File size:4379400 bytes
    MD5 hash:7dc1c0e23cd5e102bb12e5c29403410e

    General

    Start time:23:51:50
    Start date:10/11/2021
    Path:/tmp/gL6zNW1uNj
    Arguments:n/a
    File size:4379400 bytes
    MD5 hash:7dc1c0e23cd5e102bb12e5c29403410e

    General

    Start time:23:52:04
    Start date:10/11/2021
    Path:/tmp/gL6zNW1uNj
    Arguments:n/a
    File size:4379400 bytes
    MD5 hash:7dc1c0e23cd5e102bb12e5c29403410e

    General

    Start time:23:52:04
    Start date:10/11/2021
    Path:/tmp/gL6zNW1uNj
    Arguments:n/a
    File size:4379400 bytes
    MD5 hash:7dc1c0e23cd5e102bb12e5c29403410e

    General

    Start time:23:51:50
    Start date:10/11/2021
    Path:/tmp/gL6zNW1uNj
    Arguments:n/a
    File size:4379400 bytes
    MD5 hash:7dc1c0e23cd5e102bb12e5c29403410e

    General

    Start time:23:51:51
    Start date:10/11/2021
    Path:/tmp/gL6zNW1uNj
    Arguments:n/a
    File size:4379400 bytes
    MD5 hash:7dc1c0e23cd5e102bb12e5c29403410e

    General

    Start time:23:51:58
    Start date:10/11/2021
    Path:/usr/lib/systemd/systemd
    Arguments:n/a
    File size:1620224 bytes
    MD5 hash:9b2bec7092a40488108543f9334aab75

    General

    Start time:23:51:58
    Start date:10/11/2021
    Path:/usr/sbin/sshd
    Arguments:/usr/sbin/sshd -t
    File size:876328 bytes
    MD5 hash:dbca7a6bbf7bf57fedac243d4b2cb340

    General

    Start time:23:51:59
    Start date:10/11/2021
    Path:/usr/lib/systemd/systemd
    Arguments:n/a
    File size:1620224 bytes
    MD5 hash:9b2bec7092a40488108543f9334aab75

    General

    Start time:23:51:59
    Start date:10/11/2021
    Path:/usr/sbin/sshd
    Arguments:/usr/sbin/sshd -D
    File size:876328 bytes
    MD5 hash:dbca7a6bbf7bf57fedac243d4b2cb340

    General

    Start time:23:52:04
    Start date:10/11/2021
    Path:/usr/lib/systemd/systemd
    Arguments:n/a
    File size:1620224 bytes
    MD5 hash:9b2bec7092a40488108543f9334aab75

    General

    Start time:23:52:04
    Start date:10/11/2021
    Path:/usr/sbin/sshd
    Arguments:/usr/sbin/sshd -t
    File size:876328 bytes
    MD5 hash:dbca7a6bbf7bf57fedac243d4b2cb340

    General

    Start time:23:52:05
    Start date:10/11/2021
    Path:/usr/lib/systemd/systemd
    Arguments:n/a
    File size:1620224 bytes
    MD5 hash:9b2bec7092a40488108543f9334aab75

    General

    Start time:23:52:05
    Start date:10/11/2021
    Path:/usr/sbin/sshd
    Arguments:/usr/sbin/sshd -D
    File size:876328 bytes
    MD5 hash:dbca7a6bbf7bf57fedac243d4b2cb340