Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
qICLEK5VRO

Overview

General Information

Sample Name:qICLEK5VRO
Analysis ID:627364
MD5:e94958fb5d8da1a7d544c06d4632c846
SHA1:f66479adc6f036533919b6155a7e310cf4f07928
SHA256:0ec1ae5752fd6770b25b0e51d83503cf758b5b84a1939dcca1eef4d9ad50b4a2
Tags:32elfmirairenesas
Infos:

Detection

Score:52
Range:0 - 100
Whitelisted:false

Signatures

Multi AV Scanner detection for submitted file
Sample deletes itself
Sample has stripped symbol table
Uses the "uname" system call to query kernel version information (possible evasion)
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Detected TCP or UDP traffic on non-standard ports

Classification

Analysis Advice

Static ELF header machine description suggests that the sample might not execute correctly on this machine.
All HTTP servers contacted by the sample do not answer. The sample is likely an old dropper which does no longer work.
Non-zero exit code suggests an error during the execution. Lookup the error code for hints.
Joe Sandbox Version:34.0.0 Boulder Opal
Analysis ID:627364
Start date and time: 16/05/202213:58:122022-05-16 13:58:12 +02:00
Joe Sandbox Product:CloudBasic
Overall analysis duration:0h 5m 7s
Hypervisor based Inspection enabled:false
Report type:full
Sample file name:qICLEK5VRO
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Detection:MAL
Classification:mal52.evad.lin@0/0@0/0
  • VT rate limit hit for: qICLEK5VRO
Command:/tmp/qICLEK5VRO
PID:6246
Exit Code:1
Exit Code Info:
Killed:False
Standard Output:
[[91mAbyssal[0m] established connection.
Monitoring device.
Standard Error:
  • system is lnxubuntu20
  • qICLEK5VRO (PID: 6246, Parent: 6155, MD5: 8943e5f8f8c280467b4472c15ae93ba9) Arguments: /tmp/qICLEK5VRO
  • cleanup
No yara matches
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: qICLEK5VROReversingLabs: Detection: 39%
Source: global trafficTCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
Source: global trafficTCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
Source: global trafficTCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
Source: global trafficTCP traffic: 192.168.2.23:43480 -> 103.136.41.110:6525
Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 103.136.41.110
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: ELF static info symbol of initial sample.symtab present: no
Source: classification engineClassification label: mal52.evad.lin@0/0@0/0

Hooking and other Techniques for Hiding and Protection

barindex
Source: /tmp/qICLEK5VRO (PID: 6246)File: /tmp/qICLEK5VROJump to behavior
Source: /tmp/qICLEK5VRO (PID: 6246)Queries kernel information via 'uname': Jump to behavior
Source: qICLEK5VRO, 6246.1.00000000bbab0635.00000000cdb971d4.rw-.sdmpBinary or memory string: /usr/bin/qemu-sh4
Source: qICLEK5VRO, 6246.1.000000003fae4da2.0000000033fabfd2.rw-.sdmpBinary or memory string: U5!/etc/qemu-binfmt/sh4
Source: qICLEK5VRO, 6246.1.000000003fae4da2.0000000033fabfd2.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/sh4
Source: qICLEK5VRO, 6246.1.00000000bbab0635.00000000cdb971d4.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-sh4/tmp/qICLEK5VROSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/qICLEK5VRO
Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid AccountsWindows Management InstrumentationPath InterceptionPath Interception1
File Deletion
OS Credential Dumping11
Security Software Discovery
Remote ServicesData from Local SystemExfiltration Over Other Network Medium1
Encrypted Channel
Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over Bluetooth1
Non-Standard Port
Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated Exfiltration1
Application Layer Protocol
Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
SourceDetectionScannerLabelLink
qICLEK5VRO39%ReversingLabsLinux.Trojan.Mirai
No Antivirus matches
No Antivirus matches
No Antivirus matches
No contacted domains info
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs
IPDomainCountryFlagASNASN NameMalicious
103.136.41.110
unknownIndia
139884AGPL-AS-APApeironGlobalPvtLtdINfalse
109.202.202.202
unknownSwitzerland
13030INIT7CHfalse
91.189.91.43
unknownUnited Kingdom
41231CANONICAL-ASGBfalse
91.189.91.42
unknownUnited Kingdom
41231CANONICAL-ASGBfalse
MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
103.136.41.110qaE0C9rclbGet hashmaliciousBrowse
    PpcvaRE8wFGet hashmaliciousBrowse
      aPll2HI0vqGet hashmaliciousBrowse
        QQ7EA6NtnRGet hashmaliciousBrowse
          GXUKKZ7QnfGet hashmaliciousBrowse
            tJ9TlGLj1KGet hashmaliciousBrowse
              ixOTaOEDIWGet hashmaliciousBrowse
                OCrSf4L4AHGet hashmaliciousBrowse
                  HvIio1rY75Get hashmaliciousBrowse
                    nQ9DQ8dyp9Get hashmaliciousBrowse
                      fJoJrFsRDUGet hashmaliciousBrowse
                        1U7K4ZoysUGet hashmaliciousBrowse
                          2OudwAz06pGet hashmaliciousBrowse
                            LmbPIbBJtGGet hashmaliciousBrowse
                              muwVjbx43uGet hashmaliciousBrowse
                                6mgPR0Wyq7Get hashmaliciousBrowse
                                  pLYNr2qjHVGet hashmaliciousBrowse
                                    bwUj1FMbJ6Get hashmaliciousBrowse
                                      wZwjwmeeGWGet hashmaliciousBrowse
                                        6zl1VArwOvGet hashmaliciousBrowse
                                          109.202.202.202qaE0C9rclbGet hashmaliciousBrowse
                                            fxlJlYCE4IGet hashmaliciousBrowse
                                              rW2vFLB6JyGet hashmaliciousBrowse
                                                UnHAnaAW.arm5Get hashmaliciousBrowse
                                                  n9eApCavgKGet hashmaliciousBrowse
                                                    rrmc88FRmfGet hashmaliciousBrowse
                                                      X66tU1iptIGet hashmaliciousBrowse
                                                        lWfQlkujqzGet hashmaliciousBrowse
                                                          X8hY1BGn3dGet hashmaliciousBrowse
                                                            r5Ns1m235yGet hashmaliciousBrowse
                                                              T6Sv400TfWGet hashmaliciousBrowse
                                                                tUOen8R3jCGet hashmaliciousBrowse
                                                                  X2jhhXiaJfGet hashmaliciousBrowse
                                                                    SaIN1z8B7XGet hashmaliciousBrowse
                                                                      TSL33T.arm5Get hashmaliciousBrowse
                                                                        ZG9zarm7Get hashmaliciousBrowse
                                                                          ZG9zarmGet hashmaliciousBrowse
                                                                            wMZjd2tXuZGet hashmaliciousBrowse
                                                                              Anti.arm5Get hashmaliciousBrowse
                                                                                lgvIcn4KKzGet hashmaliciousBrowse
                                                                                  No context
                                                                                  MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                                                                                  AGPL-AS-APApeironGlobalPvtLtdINqaE0C9rclbGet hashmaliciousBrowse
                                                                                  • 103.136.41.110
                                                                                  EG4I1PrzgqGet hashmaliciousBrowse
                                                                                  • 103.136.40.176
                                                                                  j0Ee2pkXcHGet hashmaliciousBrowse
                                                                                  • 103.136.40.176
                                                                                  1Ggdi0m8hfGet hashmaliciousBrowse
                                                                                  • 103.136.40.176
                                                                                  PpcvaRE8wFGet hashmaliciousBrowse
                                                                                  • 103.136.41.110
                                                                                  aPll2HI0vqGet hashmaliciousBrowse
                                                                                  • 103.136.41.110
                                                                                  QQ7EA6NtnRGet hashmaliciousBrowse
                                                                                  • 103.136.41.110
                                                                                  Iitoq5GM0G.exeGet hashmaliciousBrowse
                                                                                  • 103.136.40.167
                                                                                  GXUKKZ7QnfGet hashmaliciousBrowse
                                                                                  • 103.136.41.110
                                                                                  tJ9TlGLj1KGet hashmaliciousBrowse
                                                                                  • 103.136.41.110
                                                                                  ixOTaOEDIWGet hashmaliciousBrowse
                                                                                  • 103.136.41.110
                                                                                  OCrSf4L4AHGet hashmaliciousBrowse
                                                                                  • 103.136.41.110
                                                                                  HvIio1rY75Get hashmaliciousBrowse
                                                                                  • 103.136.41.110
                                                                                  nQ9DQ8dyp9Get hashmaliciousBrowse
                                                                                  • 103.136.41.110
                                                                                  fJoJrFsRDUGet hashmaliciousBrowse
                                                                                  • 103.136.41.110
                                                                                  1U7K4ZoysUGet hashmaliciousBrowse
                                                                                  • 103.136.41.110
                                                                                  2OudwAz06pGet hashmaliciousBrowse
                                                                                  • 103.136.41.110
                                                                                  LmbPIbBJtGGet hashmaliciousBrowse
                                                                                  • 103.136.41.110
                                                                                  muwVjbx43uGet hashmaliciousBrowse
                                                                                  • 103.136.41.110
                                                                                  6mgPR0Wyq7Get hashmaliciousBrowse
                                                                                  • 103.136.41.110
                                                                                  INIT7CHqaE0C9rclbGet hashmaliciousBrowse
                                                                                  • 109.202.202.202
                                                                                  fxlJlYCE4IGet hashmaliciousBrowse
                                                                                  • 109.202.202.202
                                                                                  rW2vFLB6JyGet hashmaliciousBrowse
                                                                                  • 109.202.202.202
                                                                                  UnHAnaAW.arm5Get hashmaliciousBrowse
                                                                                  • 109.202.202.202
                                                                                  n9eApCavgKGet hashmaliciousBrowse
                                                                                  • 109.202.202.202
                                                                                  rrmc88FRmfGet hashmaliciousBrowse
                                                                                  • 109.202.202.202
                                                                                  X66tU1iptIGet hashmaliciousBrowse
                                                                                  • 109.202.202.202
                                                                                  lWfQlkujqzGet hashmaliciousBrowse
                                                                                  • 109.202.202.202
                                                                                  X8hY1BGn3dGet hashmaliciousBrowse
                                                                                  • 109.202.202.202
                                                                                  r5Ns1m235yGet hashmaliciousBrowse
                                                                                  • 109.202.202.202
                                                                                  T6Sv400TfWGet hashmaliciousBrowse
                                                                                  • 109.202.202.202
                                                                                  tUOen8R3jCGet hashmaliciousBrowse
                                                                                  • 109.202.202.202
                                                                                  X2jhhXiaJfGet hashmaliciousBrowse
                                                                                  • 109.202.202.202
                                                                                  SaIN1z8B7XGet hashmaliciousBrowse
                                                                                  • 109.202.202.202
                                                                                  TSL33T.arm5Get hashmaliciousBrowse
                                                                                  • 109.202.202.202
                                                                                  ZG9zarm7Get hashmaliciousBrowse
                                                                                  • 109.202.202.202
                                                                                  ZG9zarmGet hashmaliciousBrowse
                                                                                  • 109.202.202.202
                                                                                  wMZjd2tXuZGet hashmaliciousBrowse
                                                                                  • 109.202.202.202
                                                                                  Anti.arm5Get hashmaliciousBrowse
                                                                                  • 109.202.202.202
                                                                                  lgvIcn4KKzGet hashmaliciousBrowse
                                                                                  • 109.202.202.202
                                                                                  No context
                                                                                  No context
                                                                                  No created / dropped files found
                                                                                  File type:ELF 32-bit LSB executable, Renesas SH, version 1 (SYSV), statically linked, stripped
                                                                                  Entropy (8bit):6.843964110789535
                                                                                  TrID:
                                                                                  • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                                                                                  File name:qICLEK5VRO
                                                                                  File size:81308
                                                                                  MD5:e94958fb5d8da1a7d544c06d4632c846
                                                                                  SHA1:f66479adc6f036533919b6155a7e310cf4f07928
                                                                                  SHA256:0ec1ae5752fd6770b25b0e51d83503cf758b5b84a1939dcca1eef4d9ad50b4a2
                                                                                  SHA512:aaf1eb528111e34512a32c5fa99e5812069a1a3167c16b0dff82ba49e24921fc254cf1305f35bdd129b0ed4d000def35ab68f2ebb4d580309be539f635196648
                                                                                  SSDEEP:1536:KVyy0IgITcOFkcwo82Kq6pkILtHhwxeK82WDyG9ECl9n8j96:OynQLD/6pkIxHhwxR8d9EOcE
                                                                                  TLSH:B583AF72C16C6F2CD2044AB47961EF368753A40083AB6FF79999C7666443DACF6087F8
                                                                                  File Content Preview:.ELF..............*.......@.4....<......4. ...(...............@...@..5...5...............5...5B..5B.....<*..........Q.td............................././"O.n........#.*@........#.*@.....o&O.n...l..............................././.../.a"O.!...n...a.b("...q.

                                                                                  ELF header

                                                                                  Class:ELF32
                                                                                  Data:2's complement, little endian
                                                                                  Version:1 (current)
                                                                                  Machine:<unknown>
                                                                                  Version Number:0x1
                                                                                  Type:EXEC (Executable file)
                                                                                  OS/ABI:UNIX - System V
                                                                                  ABI Version:0
                                                                                  Entry Point Address:0x4001a0
                                                                                  Flags:0x9
                                                                                  ELF Header Size:52
                                                                                  Program Header Offset:52
                                                                                  Program Header Size:32
                                                                                  Number of Program Headers:3
                                                                                  Section Header Offset:80908
                                                                                  Section Header Size:40
                                                                                  Number of Section Headers:10
                                                                                  Header String Table Index:9
                                                                                  NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                                                                  NULL0x00x00x00x00x0000
                                                                                  .initPROGBITS0x4000940x940x300x00x6AX004
                                                                                  .textPROGBITS0x4000e00xe00x114000x00x6AX0032
                                                                                  .finiPROGBITS0x4114e00x114e00x240x00x6AX004
                                                                                  .rodataPROGBITS0x4115040x115040x20040x00x2A004
                                                                                  .ctorsPROGBITS0x42350c0x1350c0x80x00x3WA004
                                                                                  .dtorsPROGBITS0x4235140x135140x80x00x3WA004
                                                                                  .dataPROGBITS0x4235200x135200x6ac0x00x3WA004
                                                                                  .bssNOBITS0x423bcc0x13bcc0x237c0x00x3WA004
                                                                                  .shstrtabSTRTAB0x00x13bcc0x3e0x00x0001
                                                                                  TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                                                  LOAD0x00x4000000x4000000x135080x135084.80800x5R E0x10000.init .text .fini .rodata
                                                                                  LOAD0x1350c0x42350c0x42350c0x6c00x2a3c2.67530x6RW 0x10000.ctors .dtors .data .bss
                                                                                  GNU_STACK0x00x00x00x00x00.00000x7RWE0x4
                                                                                  TimestampSource PortDest PortSource IPDest IP
                                                                                  May 16, 2022 13:59:18.430448055 CEST43928443192.168.2.2391.189.91.42
                                                                                  May 16, 2022 13:59:28.670478106 CEST42836443192.168.2.2391.189.91.43
                                                                                  May 16, 2022 13:59:34.814235926 CEST4251680192.168.2.23109.202.202.202
                                                                                  May 16, 2022 13:59:59.390058041 CEST43928443192.168.2.2391.189.91.42
                                                                                  May 16, 2022 14:00:17.113245964 CEST652543480103.136.41.110192.168.2.23
                                                                                  May 16, 2022 14:00:17.113445044 CEST434806525192.168.2.23103.136.41.110
                                                                                  May 16, 2022 14:00:19.869844913 CEST42836443192.168.2.2391.189.91.43

                                                                                  System Behavior

                                                                                  Start time:13:59:06
                                                                                  Start date:16/05/2022
                                                                                  Path:/tmp/qICLEK5VRO
                                                                                  Arguments:/tmp/qICLEK5VRO
                                                                                  File size:4139976 bytes
                                                                                  MD5 hash:8943e5f8f8c280467b4472c15ae93ba9