Linux Analysis Report
x86

Overview

General Information

Sample Name: x86
Analysis ID: 635907
MD5: bef642eeed970f7c3ee944a513ea4c88
SHA1: baaa1dc20118f95134cb1ca1fa0c32ad49ed8eeb
SHA256: 10f35885f96f694fbf6239de4f4e400367cdb0201bd6b4a6fa85b3cc609de22e
Infos:

Detection

Mirai
Score: 64
Range: 0 - 100
Whitelisted: false

Signatures

Multi AV Scanner detection for submitted file
Yara detected Mirai
Machine Learning detection for sample
Uses known network protocols on non-standard ports
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Detected TCP or UDP traffic on non-standard ports
Sample has stripped symbol table

Classification

AV Detection

barindex
Source: x86 Virustotal: Detection: 45% Perma Link
Source: x86 Joe Sandbox ML: detected

Networking

barindex
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 36102
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 36150
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 36194
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 36228
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 36276
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 36316
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55232
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 36348
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 36390
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55258
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55436
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 36450
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 36738
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 36796
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 36846
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55504
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 36882
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55816
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 36928
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55840
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 36958
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55874
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 37056
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 37134
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 37200
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 37254
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55976
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 56270
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 56296
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 56314
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 56330
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 37288
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 56354
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 37490
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 56452
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 56532
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 56622
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 56694
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 56750
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 56798
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 56854
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 37586
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 38010
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 38052
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 38194
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 38350
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 38454
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 56884
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 38542
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 57504
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 57562
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 57628
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 57674
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 57700
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 57740
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 57700
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 57802
Source: global traffic TCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
Source: global traffic TCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
Source: global traffic TCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
Source: global traffic TCP traffic: 192.168.2.23:35432 -> 190.123.44.199:39497
Source: unknown Network traffic detected: HTTP traffic on port 43928 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 42836 -> 443
Source: unknown TCP traffic detected without corresponding DNS query: 119.48.37.48
Source: unknown TCP traffic detected without corresponding DNS query: 112.199.58.34
Source: unknown TCP traffic detected without corresponding DNS query: 112.199.58.34
Source: unknown TCP traffic detected without corresponding DNS query: 119.48.37.48
Source: unknown TCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknown TCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknown TCP traffic detected without corresponding DNS query: 119.48.37.48
Source: unknown TCP traffic detected without corresponding DNS query: 8.96.87.23
Source: unknown TCP traffic detected without corresponding DNS query: 101.211.21.120
Source: unknown TCP traffic detected without corresponding DNS query: 119.21.212.120
Source: unknown TCP traffic detected without corresponding DNS query: 31.254.177.252
Source: unknown TCP traffic detected without corresponding DNS query: 162.189.50.109
Source: unknown TCP traffic detected without corresponding DNS query: 92.155.50.169
Source: unknown TCP traffic detected without corresponding DNS query: 1.114.66.222
Source: unknown TCP traffic detected without corresponding DNS query: 83.164.66.106
Source: unknown TCP traffic detected without corresponding DNS query: 80.45.115.63
Source: unknown TCP traffic detected without corresponding DNS query: 19.139.69.139
Source: unknown TCP traffic detected without corresponding DNS query: 136.163.173.249
Source: unknown TCP traffic detected without corresponding DNS query: 100.17.171.186
Source: unknown TCP traffic detected without corresponding DNS query: 2.253.132.212
Source: unknown TCP traffic detected without corresponding DNS query: 102.143.203.201
Source: unknown TCP traffic detected without corresponding DNS query: 18.19.199.39
Source: unknown TCP traffic detected without corresponding DNS query: 117.78.143.153
Source: unknown TCP traffic detected without corresponding DNS query: 131.130.219.36
Source: unknown TCP traffic detected without corresponding DNS query: 87.129.46.43
Source: unknown TCP traffic detected without corresponding DNS query: 72.201.168.50
Source: unknown TCP traffic detected without corresponding DNS query: 91.78.49.31
Source: unknown TCP traffic detected without corresponding DNS query: 118.61.172.171
Source: unknown TCP traffic detected without corresponding DNS query: 117.236.64.119
Source: unknown TCP traffic detected without corresponding DNS query: 218.55.177.68
Source: unknown TCP traffic detected without corresponding DNS query: 102.24.47.215
Source: unknown TCP traffic detected without corresponding DNS query: 70.37.108.135
Source: unknown TCP traffic detected without corresponding DNS query: 117.182.136.248
Source: unknown TCP traffic detected without corresponding DNS query: 87.32.147.70
Source: unknown TCP traffic detected without corresponding DNS query: 155.15.109.18
Source: unknown TCP traffic detected without corresponding DNS query: 190.247.152.244
Source: unknown TCP traffic detected without corresponding DNS query: 125.239.28.124
Source: unknown TCP traffic detected without corresponding DNS query: 131.48.123.198
Source: unknown TCP traffic detected without corresponding DNS query: 161.184.56.240
Source: unknown TCP traffic detected without corresponding DNS query: 108.162.204.92
Source: unknown TCP traffic detected without corresponding DNS query: 147.166.16.121
Source: unknown TCP traffic detected without corresponding DNS query: 196.134.215.117
Source: unknown TCP traffic detected without corresponding DNS query: 42.27.39.90
Source: unknown TCP traffic detected without corresponding DNS query: 58.57.176.45
Source: unknown TCP traffic detected without corresponding DNS query: 168.229.44.89
Source: unknown TCP traffic detected without corresponding DNS query: 80.116.246.85
Source: unknown TCP traffic detected without corresponding DNS query: 23.202.87.42
Source: unknown TCP traffic detected without corresponding DNS query: 135.84.138.222
Source: unknown TCP traffic detected without corresponding DNS query: 221.54.169.180
Source: unknown TCP traffic detected without corresponding DNS query: 153.35.145.184
Source: ELF static info symbol of initial sample .symtab present: no
Source: classification engine Classification label: mal64.troj.lin@0/0@0/0

Hooking and other Techniques for Hiding and Protection

barindex
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 36102
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 36150
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 36194
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 36228
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 36276
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 36316
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55232
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 36348
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 36390
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55258
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55436
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 36450
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 36738
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 36796
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 36846
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55504
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 36882
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55816
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 36928
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55840
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 36958
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55874
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 37056
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 37134
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 37200
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 37254
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 55976
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 56270
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 56296
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 56314
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 56330
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 37288
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 56354
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 37490
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 56452
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 56532
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 56622
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 56694
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 56750
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 56798
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 56854
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 37586
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 38010
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 38052
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 38194
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 38350
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 38454
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 56884
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 38542
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 57504
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 57562
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 57628
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 57674
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 57700
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 57740
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 57700
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 57802

Stealing of Sensitive Information

barindex
Source: Yara match File source: dump.pcap, type: PCAP

Remote Access Functionality

barindex
Source: Yara match File source: dump.pcap, type: PCAP
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs