Loading ...

Play interactive tourEdit tour

Linux Analysis Report dPNmxIxa36

Overview

General Information

Sample Name:dPNmxIxa36
Analysis ID:529876
MD5:565a0642865835b01ddbdb90f7d4ea69
SHA1:78dc6791664f17078ff4e34c4b677006fd1f1299
SHA256:8e0c4e5bcca73638856d033c7600c17eb562fe38b147bd886d6f996f27838151
Tags:32elfmips
Infos:

Detection

Score:48
Range:0 - 100
Whitelisted:false

Signatures

Multi AV Scanner detection for submitted file
Sample contains only a LOAD segment without any section mappings
Uses the "uname" system call to query kernel version information (possible evasion)
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Detected TCP or UDP traffic on non-standard ports

Classification

Analysis Advice

Static ELF header machine description suggests that the sample might only run correctly on MIPS or ARM architectures
All HTTP servers contacted by the sample do not answer. Likely the sample is an old dropper which does no longer work
Non-zero exit code suggests an error during the execution. Lookup the error code for hints.
Static ELF header machine description suggests that the sample might not execute correctly on this machine

General Information

Joe Sandbox Version:34.0.0 Boulder Opal
Analysis ID:529876
Start date:28.11.2021
Start time:15:08:54
Joe Sandbox Product:CloudBasic
Overall analysis duration:0h 4m 49s
Hypervisor based Inspection enabled:false
Report type:full
Sample file name:dPNmxIxa36
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Detection:MAL
Classification:mal48.lin@0/0@0/0

Process Tree

  • system is lnxubuntu20
  • dPNmxIxa36 (PID: 5221, Parent: 5118, MD5: 0083f1f0e77be34ad27f849842bbb00c) Arguments: /tmp/dPNmxIxa36
  • cleanup

Yara Overview

No yara matches

Jbx Signature Overview

Click to jump to signature section

Show All Signature Results

AV Detection:

barindex
Multi AV Scanner detection for submitted fileShow sources
Source: dPNmxIxa36Virustotal: Detection: 11%Perma Link
Source: dPNmxIxa36ReversingLabs: Detection: 24%
Source: global trafficTCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
Source: global trafficTCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
Source: global trafficTCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
Source: global trafficTCP traffic: 192.168.2.23:35642 -> 45.95.169.133:717
Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.133
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: LOAD without section mappingsProgram segment: 0x400000
Source: classification engineClassification label: mal48.lin@0/0@0/0
Source: /tmp/dPNmxIxa36 (PID: 5221)Queries kernel information via 'uname': Jump to behavior
Source: dPNmxIxa36, 5221.1.000000007fc53086.000000009d1a5eb3.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-mips/tmp/dPNmxIxa36SUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/dPNmxIxa36
Source: dPNmxIxa36, 5221.1.00000000af1018e2.000000001f530990.rw-.sdmpBinary or memory string: U!/etc/qemu-binfmt/mips
Source: dPNmxIxa36, 5221.1.00000000af1018e2.000000001f530990.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/mips
Source: dPNmxIxa36, 5221.1.000000007fc53086.000000009d1a5eb3.rw-.sdmpBinary or memory string: /usr/bin/qemu-mips
Source: dPNmxIxa36, 5221.1.000000007fc53086.000000009d1a5eb3.rw-.sdmpBinary or memory string: qemu: uncaught target signal 5 (Trace/breakpoint trap) - core dumped

Mitre Att&ck Matrix

Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid AccountsWindows Management InstrumentationPath InterceptionPath InterceptionDirect Volume AccessOS Credential DumpingSecurity Software Discovery11Remote ServicesData from Local SystemExfiltration Over Other Network MediumEncrypted Channel1Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over BluetoothNon-Standard Port1Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated ExfiltrationApplication Layer Protocol1Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data

Malware Configuration

No configs have been found

Behavior Graph

Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet

Antivirus, Machine Learning and Genetic Malware Detection

Initial Sample

SourceDetectionScannerLabelLink
dPNmxIxa3611%VirustotalBrowse
dPNmxIxa3624%ReversingLabsLinux.Trojan.Gafgyt

Dropped Files

No Antivirus matches

Domains

No Antivirus matches

URLs

No Antivirus matches

Domains and IPs

Contacted Domains

No contacted domains info

Contacted IPs

  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs

Public

IPDomainCountryFlagASNASN NameMalicious
45.95.169.133
unknownCroatia (LOCAL Name: Hrvatska)
42864GIGANET-HUGigaNetInternetServiceProviderCoHUfalse
109.202.202.202
unknownSwitzerland
13030INIT7CHfalse
91.189.91.43
unknownUnited Kingdom
41231CANONICAL-ASGBfalse
91.189.91.42
unknownUnited Kingdom
41231CANONICAL-ASGBfalse


Runtime Messages

Command:/tmp/dPNmxIxa36
Exit Code:133
Exit Code Info:
Killed:False
Standard Output:

Standard Error:qemu: uncaught target signal 5 (Trace/breakpoint trap) - core dumped

Joe Sandbox View / Context

IPs

MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
45.95.169.133AAVv6nd497Get hashmaliciousBrowse
    e9BE1FK860Get hashmaliciousBrowse
      Gd18OVeWM9Get hashmaliciousBrowse
        109.202.202.202AAVv6nd497Get hashmaliciousBrowse
          e9BE1FK860Get hashmaliciousBrowse
            wriRgGnavYGet hashmaliciousBrowse
              Hs7hqIukmHGet hashmaliciousBrowse
                Gd18OVeWM9Get hashmaliciousBrowse
                  v8qiTISjUUGet hashmaliciousBrowse
                    Bu8Mj7TcLLGet hashmaliciousBrowse
                      SPWv1xQJN2Get hashmaliciousBrowse
                        C7FpC2RDAjGet hashmaliciousBrowse
                          ptDMShZLZhGet hashmaliciousBrowse
                            NH4nR1N8wkGet hashmaliciousBrowse
                              p5DTKpaxTEGet hashmaliciousBrowse
                                Vc90gP8W1bGet hashmaliciousBrowse
                                  9l4aoLWfPsGet hashmaliciousBrowse
                                    1rfzPU44e6Get hashmaliciousBrowse
                                      z0r0.armGet hashmaliciousBrowse
                                        z0r0.arm7Get hashmaliciousBrowse
                                          SecuriteInfo.com.Linux.Mirai.53.8326.23579Get hashmaliciousBrowse
                                            SecuriteInfo.com.Linux.Mirai.791.16681.31108Get hashmaliciousBrowse
                                              sora.x86Get hashmaliciousBrowse
                                                91.189.91.43AAVv6nd497Get hashmaliciousBrowse
                                                  e9BE1FK860Get hashmaliciousBrowse
                                                    wriRgGnavYGet hashmaliciousBrowse
                                                      Hs7hqIukmHGet hashmaliciousBrowse
                                                        Gd18OVeWM9Get hashmaliciousBrowse
                                                          v8qiTISjUUGet hashmaliciousBrowse
                                                            Bu8Mj7TcLLGet hashmaliciousBrowse
                                                              SPWv1xQJN2Get hashmaliciousBrowse
                                                                C7FpC2RDAjGet hashmaliciousBrowse
                                                                  ptDMShZLZhGet hashmaliciousBrowse
                                                                    NH4nR1N8wkGet hashmaliciousBrowse
                                                                      p5DTKpaxTEGet hashmaliciousBrowse
                                                                        Vc90gP8W1bGet hashmaliciousBrowse
                                                                          9l4aoLWfPsGet hashmaliciousBrowse
                                                                            1rfzPU44e6Get hashmaliciousBrowse
                                                                              z0r0.armGet hashmaliciousBrowse
                                                                                z0r0.arm7Get hashmaliciousBrowse
                                                                                  SecuriteInfo.com.Linux.Mirai.53.8326.23579Get hashmaliciousBrowse
                                                                                    SecuriteInfo.com.Linux.Mirai.791.16681.31108Get hashmaliciousBrowse
                                                                                      sora.x86Get hashmaliciousBrowse

                                                                                        Domains

                                                                                        No context

                                                                                        ASN

                                                                                        MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                                                                                        CANONICAL-ASGBAAVv6nd497Get hashmaliciousBrowse
                                                                                        • 91.189.91.42
                                                                                        e9BE1FK860Get hashmaliciousBrowse
                                                                                        • 91.189.91.42
                                                                                        wriRgGnavYGet hashmaliciousBrowse
                                                                                        • 91.189.91.42
                                                                                        Hs7hqIukmHGet hashmaliciousBrowse
                                                                                        • 91.189.91.42
                                                                                        Gd18OVeWM9Get hashmaliciousBrowse
                                                                                        • 91.189.91.42
                                                                                        v8qiTISjUUGet hashmaliciousBrowse
                                                                                        • 91.189.91.42
                                                                                        Bu8Mj7TcLLGet hashmaliciousBrowse
                                                                                        • 91.189.91.42
                                                                                        SPWv1xQJN2Get hashmaliciousBrowse
                                                                                        • 91.189.91.42
                                                                                        C7FpC2RDAjGet hashmaliciousBrowse
                                                                                        • 91.189.91.42
                                                                                        ptDMShZLZhGet hashmaliciousBrowse
                                                                                        • 91.189.91.42
                                                                                        NH4nR1N8wkGet hashmaliciousBrowse
                                                                                        • 91.189.91.42
                                                                                        p5DTKpaxTEGet hashmaliciousBrowse
                                                                                        • 91.189.91.42
                                                                                        Vc90gP8W1bGet hashmaliciousBrowse
                                                                                        • 91.189.91.42
                                                                                        9l4aoLWfPsGet hashmaliciousBrowse
                                                                                        • 91.189.91.42
                                                                                        1rfzPU44e6Get hashmaliciousBrowse
                                                                                        • 91.189.91.42
                                                                                        z0r0.armGet hashmaliciousBrowse
                                                                                        • 91.189.91.42
                                                                                        z0r0.arm7Get hashmaliciousBrowse
                                                                                        • 91.189.91.42
                                                                                        SecuriteInfo.com.Linux.Mirai.53.8326.23579Get hashmaliciousBrowse
                                                                                        • 91.189.91.42
                                                                                        SecuriteInfo.com.Linux.Mirai.791.16681.31108Get hashmaliciousBrowse
                                                                                        • 91.189.91.42
                                                                                        sora.x86Get hashmaliciousBrowse
                                                                                        • 91.189.91.42
                                                                                        GIGANET-HUGigaNetInternetServiceProviderCoHUAAVv6nd497Get hashmaliciousBrowse
                                                                                        • 45.95.169.133
                                                                                        e9BE1FK860Get hashmaliciousBrowse
                                                                                        • 45.95.169.133
                                                                                        Gd18OVeWM9Get hashmaliciousBrowse
                                                                                        • 45.95.169.133
                                                                                        P2MNIRJ4gJGet hashmaliciousBrowse
                                                                                        • 45.95.169.115
                                                                                        sE1xgTiVhlGet hashmaliciousBrowse
                                                                                        • 45.95.169.115
                                                                                        IVpX0wAyepGet hashmaliciousBrowse
                                                                                        • 45.95.169.115
                                                                                        jmDafm8AndGet hashmaliciousBrowse
                                                                                        • 45.95.169.115
                                                                                        6Pw7ywG1RxGet hashmaliciousBrowse
                                                                                        • 45.95.169.115
                                                                                        U8HSORd9SzGet hashmaliciousBrowse
                                                                                        • 45.95.169.115
                                                                                        xz9rffd17JGet hashmaliciousBrowse
                                                                                        • 45.95.169.115
                                                                                        K3j3e3MgZWGet hashmaliciousBrowse
                                                                                        • 45.95.169.115
                                                                                        Eu5R5GFRQvGet hashmaliciousBrowse
                                                                                        • 45.95.169.115
                                                                                        NvwKITeL1YGet hashmaliciousBrowse
                                                                                        • 45.95.169.115
                                                                                        89qfrZ4qCRGet hashmaliciousBrowse
                                                                                        • 45.95.169.115
                                                                                        Lmgm44M8oXGet hashmaliciousBrowse
                                                                                        • 45.95.169.115
                                                                                        57KgFrJHk5Get hashmaliciousBrowse
                                                                                        • 45.95.169.115
                                                                                        sora.x86Get hashmaliciousBrowse
                                                                                        • 92.52.211.233
                                                                                        o6aMoZKsIKGet hashmaliciousBrowse
                                                                                        • 92.52.211.202
                                                                                        qlmOM0y98BGet hashmaliciousBrowse
                                                                                        • 45.95.169.120
                                                                                        3tgXa7CGc1Get hashmaliciousBrowse
                                                                                        • 45.95.169.120
                                                                                        INIT7CHAAVv6nd497Get hashmaliciousBrowse
                                                                                        • 109.202.202.202
                                                                                        e9BE1FK860Get hashmaliciousBrowse
                                                                                        • 109.202.202.202
                                                                                        wriRgGnavYGet hashmaliciousBrowse
                                                                                        • 109.202.202.202
                                                                                        Hs7hqIukmHGet hashmaliciousBrowse
                                                                                        • 109.202.202.202
                                                                                        Gd18OVeWM9Get hashmaliciousBrowse
                                                                                        • 109.202.202.202
                                                                                        v8qiTISjUUGet hashmaliciousBrowse
                                                                                        • 109.202.202.202
                                                                                        Bu8Mj7TcLLGet hashmaliciousBrowse
                                                                                        • 109.202.202.202
                                                                                        SPWv1xQJN2Get hashmaliciousBrowse
                                                                                        • 109.202.202.202
                                                                                        C7FpC2RDAjGet hashmaliciousBrowse
                                                                                        • 109.202.202.202
                                                                                        ptDMShZLZhGet hashmaliciousBrowse
                                                                                        • 109.202.202.202
                                                                                        NH4nR1N8wkGet hashmaliciousBrowse
                                                                                        • 109.202.202.202
                                                                                        p5DTKpaxTEGet hashmaliciousBrowse
                                                                                        • 109.202.202.202
                                                                                        Vc90gP8W1bGet hashmaliciousBrowse
                                                                                        • 109.202.202.202
                                                                                        9l4aoLWfPsGet hashmaliciousBrowse
                                                                                        • 109.202.202.202
                                                                                        1rfzPU44e6Get hashmaliciousBrowse
                                                                                        • 109.202.202.202
                                                                                        z0r0.armGet hashmaliciousBrowse
                                                                                        • 109.202.202.202
                                                                                        z0r0.arm7Get hashmaliciousBrowse
                                                                                        • 109.202.202.202
                                                                                        SecuriteInfo.com.Linux.Mirai.53.8326.23579Get hashmaliciousBrowse
                                                                                        • 109.202.202.202
                                                                                        SecuriteInfo.com.Linux.Mirai.791.16681.31108Get hashmaliciousBrowse
                                                                                        • 109.202.202.202
                                                                                        sora.x86Get hashmaliciousBrowse
                                                                                        • 109.202.202.202

                                                                                        JA3 Fingerprints

                                                                                        No context

                                                                                        Dropped Files

                                                                                        No context

                                                                                        Created / dropped Files

                                                                                        No created / dropped files found

                                                                                        Static File Info

                                                                                        General

                                                                                        File type:ELF 32-bit MSB executable, MIPS, MIPS-I version 1 (SYSV), statically linked, stripped
                                                                                        Entropy (8bit):7.923990757832376
                                                                                        TrID:
                                                                                        • ELF Executable and Linkable format (Linux) (4029/14) 50.16%
                                                                                        • ELF Executable and Linkable format (generic) (4004/1) 49.84%
                                                                                        File name:dPNmxIxa36
                                                                                        File size:37272
                                                                                        MD5:565a0642865835b01ddbdb90f7d4ea69
                                                                                        SHA1:78dc6791664f17078ff4e34c4b677006fd1f1299
                                                                                        SHA256:8e0c4e5bcca73638856d033c7600c17eb562fe38b147bd886d6f996f27838151
                                                                                        SHA512:05872ce0b718db2c3f356565ac9d020a76af8545d3d16f6f6fa64e3b8379e9fc925f693bb8544453c9347c0830a9a6bdbd1c8a8b41d16690b31b293113096f92
                                                                                        SSDEEP:768:wHkmWBWfJ1WnzqzmH81AnYgq2XLzDvGnRAJgGlzDpxYs7:wHz1OGmH81AYgLv+RAVrYM
                                                                                        File Content Preview:.ELF.....................@|....4.........4. ...(.............@...@.....^...^.................A...A........-..........t.LYTS........................U.......?.E.h4...@b..) ..]....E......;.\.Z=.k`N.,...........X.G.t5..C#...H....Q].....}~.N.......w...........

                                                                                        Static ELF Info

                                                                                        ELF header

                                                                                        Class:ELF32
                                                                                        Data:2's complement, big endian
                                                                                        Version:1 (current)
                                                                                        Machine:MIPS R3000
                                                                                        Version Number:0x1
                                                                                        Type:EXEC (Executable file)
                                                                                        OS/ABI:UNIX - System V
                                                                                        ABI Version:0
                                                                                        Entry Point Address:0x407ce0
                                                                                        Flags:0x1007
                                                                                        ELF Header Size:52
                                                                                        Program Header Offset:52
                                                                                        Program Header Size:32
                                                                                        Number of Program Headers:2
                                                                                        Section Header Offset:0
                                                                                        Section Header Size:40
                                                                                        Number of Section Headers:0
                                                                                        Header String Table Index:0

                                                                                        Program Segments

                                                                                        TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                                                        LOAD0x00x4000000x4000000x905e0x905e4.12640x5R E0x10000
                                                                                        LOAD0x00x4100000x4100000x00x52dc40.00000x6RW 0x10000

                                                                                        Network Behavior

                                                                                        Network Port Distribution

                                                                                        TCP Packets

                                                                                        TimestampSource PortDest PortSource IPDest IP
                                                                                        Nov 28, 2021 15:09:38.723259926 CET42836443192.168.2.2391.189.91.43
                                                                                        Nov 28, 2021 15:09:39.491245985 CET4251680192.168.2.23109.202.202.202
                                                                                        Nov 28, 2021 15:09:45.666516066 CET7173564245.95.169.133192.168.2.23
                                                                                        Nov 28, 2021 15:09:45.666853905 CET35642717192.168.2.2345.95.169.133
                                                                                        Nov 28, 2021 15:09:53.827162027 CET43928443192.168.2.2391.189.91.42
                                                                                        Nov 28, 2021 15:10:06.114986897 CET42836443192.168.2.2391.189.91.43
                                                                                        Nov 28, 2021 15:10:10.210712910 CET4251680192.168.2.23109.202.202.202
                                                                                        Nov 28, 2021 15:10:34.786412954 CET43928443192.168.2.2391.189.91.42

                                                                                        System Behavior

                                                                                        General

                                                                                        Start time:15:09:35
                                                                                        Start date:28/11/2021
                                                                                        Path:/tmp/dPNmxIxa36
                                                                                        Arguments:/tmp/dPNmxIxa36
                                                                                        File size:5777432 bytes
                                                                                        MD5 hash:0083f1f0e77be34ad27f849842bbb00c