Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
x86

Overview

General Information

Sample Name:x86
Analysis ID:635907
MD5:bef642eeed970f7c3ee944a513ea4c88
SHA1:baaa1dc20118f95134cb1ca1fa0c32ad49ed8eeb
SHA256:10f35885f96f694fbf6239de4f4e400367cdb0201bd6b4a6fa85b3cc609de22e
Infos:

Detection

Mirai
Score:64
Range:0 - 100
Whitelisted:false

Signatures

Multi AV Scanner detection for submitted file
Yara detected Mirai
Machine Learning detection for sample
Uses known network protocols on non-standard ports
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Detected TCP or UDP traffic on non-standard ports
Sample has stripped symbol table

Classification

Analysis Advice

All HTTP servers contacted by the sample do not answer. The sample is likely an old dropper which does no longer work.
Joe Sandbox Version:34.0.0 Boulder Opal
Analysis ID:635907
Start date and time: 30/05/202206:58:452022-05-30 06:58:45 +02:00
Joe Sandbox Product:CloudBasic
Overall analysis duration:0h 6m 10s
Hypervisor based Inspection enabled:false
Report type:light
Sample file name:x86
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Detection:MAL
Classification:mal64.troj.lin@0/0@0/0
  • Report size exceeded maximum capacity and may have missing network information.
  • TCP Packets have been reduced to 100
Command:/tmp/x86
PID:6221
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
''
Standard Error:
  • system is lnxubuntu20
  • x86 (PID: 6221, Parent: 6129, MD5: bef642eeed970f7c3ee944a513ea4c88) Arguments: /tmp/x86
    • x86 New Fork (PID: 6222, Parent: 6221)
    • x86 New Fork (PID: 6223, Parent: 6221)
      • x86 New Fork (PID: 6225, Parent: 6223)
        • x86 New Fork (PID: 6233, Parent: 6225)
          • x86 New Fork (PID: 6234, Parent: 6233)
      • x86 New Fork (PID: 6226, Parent: 6223)
        • x86 New Fork (PID: 6227, Parent: 6226)
  • cleanup
SourceRuleDescriptionAuthorStrings
dump.pcapJoeSecurity_Mirai_12Yara detected MiraiJoe Security
    No Snort rule has matched

    Click to jump to signature section

    Show All Signature Results

    AV Detection

    barindex
    Source: x86Virustotal: Detection: 45%Perma Link
    Source: x86Joe Sandbox ML: detected

    Networking

    barindex
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 36102
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 36150
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 36194
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 36228
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 36276
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 36316
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 55232
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 36348
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 36390
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 55258
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 55436
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 36450
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 36738
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 36796
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 36846
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 55504
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 36882
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 55816
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 36928
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 55840
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 36958
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 55874
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37056
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37134
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37200
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37254
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 55976
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 56270
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 56296
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 56314
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 56330
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37288
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 56354
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37490
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 56452
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 56532
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 56622
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 56694
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 56750
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 56798
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 56854
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37586
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 38010
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 38052
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 38194
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 38350
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 38454
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 56884
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 38542
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57504
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57562
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57628
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57674
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57700
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57740
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57700
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57802
    Source: global trafficTCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
    Source: global trafficTCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
    Source: global trafficTCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
    Source: global trafficTCP traffic: 192.168.2.23:35432 -> 190.123.44.199:39497
    Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443
    Source: unknownTCP traffic detected without corresponding DNS query: 119.48.37.48
    Source: unknownTCP traffic detected without corresponding DNS query: 112.199.58.34
    Source: unknownTCP traffic detected without corresponding DNS query: 112.199.58.34
    Source: unknownTCP traffic detected without corresponding DNS query: 119.48.37.48
    Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
    Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
    Source: unknownTCP traffic detected without corresponding DNS query: 119.48.37.48
    Source: unknownTCP traffic detected without corresponding DNS query: 8.96.87.23
    Source: unknownTCP traffic detected without corresponding DNS query: 101.211.21.120
    Source: unknownTCP traffic detected without corresponding DNS query: 119.21.212.120
    Source: unknownTCP traffic detected without corresponding DNS query: 31.254.177.252
    Source: unknownTCP traffic detected without corresponding DNS query: 162.189.50.109
    Source: unknownTCP traffic detected without corresponding DNS query: 92.155.50.169
    Source: unknownTCP traffic detected without corresponding DNS query: 1.114.66.222
    Source: unknownTCP traffic detected without corresponding DNS query: 83.164.66.106
    Source: unknownTCP traffic detected without corresponding DNS query: 80.45.115.63
    Source: unknownTCP traffic detected without corresponding DNS query: 19.139.69.139
    Source: unknownTCP traffic detected without corresponding DNS query: 136.163.173.249
    Source: unknownTCP traffic detected without corresponding DNS query: 100.17.171.186
    Source: unknownTCP traffic detected without corresponding DNS query: 2.253.132.212
    Source: unknownTCP traffic detected without corresponding DNS query: 102.143.203.201
    Source: unknownTCP traffic detected without corresponding DNS query: 18.19.199.39
    Source: unknownTCP traffic detected without corresponding DNS query: 117.78.143.153
    Source: unknownTCP traffic detected without corresponding DNS query: 131.130.219.36
    Source: unknownTCP traffic detected without corresponding DNS query: 87.129.46.43
    Source: unknownTCP traffic detected without corresponding DNS query: 72.201.168.50
    Source: unknownTCP traffic detected without corresponding DNS query: 91.78.49.31
    Source: unknownTCP traffic detected without corresponding DNS query: 118.61.172.171
    Source: unknownTCP traffic detected without corresponding DNS query: 117.236.64.119
    Source: unknownTCP traffic detected without corresponding DNS query: 218.55.177.68
    Source: unknownTCP traffic detected without corresponding DNS query: 102.24.47.215
    Source: unknownTCP traffic detected without corresponding DNS query: 70.37.108.135
    Source: unknownTCP traffic detected without corresponding DNS query: 117.182.136.248
    Source: unknownTCP traffic detected without corresponding DNS query: 87.32.147.70
    Source: unknownTCP traffic detected without corresponding DNS query: 155.15.109.18
    Source: unknownTCP traffic detected without corresponding DNS query: 190.247.152.244
    Source: unknownTCP traffic detected without corresponding DNS query: 125.239.28.124
    Source: unknownTCP traffic detected without corresponding DNS query: 131.48.123.198
    Source: unknownTCP traffic detected without corresponding DNS query: 161.184.56.240
    Source: unknownTCP traffic detected without corresponding DNS query: 108.162.204.92
    Source: unknownTCP traffic detected without corresponding DNS query: 147.166.16.121
    Source: unknownTCP traffic detected without corresponding DNS query: 196.134.215.117
    Source: unknownTCP traffic detected without corresponding DNS query: 42.27.39.90
    Source: unknownTCP traffic detected without corresponding DNS query: 58.57.176.45
    Source: unknownTCP traffic detected without corresponding DNS query: 168.229.44.89
    Source: unknownTCP traffic detected without corresponding DNS query: 80.116.246.85
    Source: unknownTCP traffic detected without corresponding DNS query: 23.202.87.42
    Source: unknownTCP traffic detected without corresponding DNS query: 135.84.138.222
    Source: unknownTCP traffic detected without corresponding DNS query: 221.54.169.180
    Source: unknownTCP traffic detected without corresponding DNS query: 153.35.145.184
    Source: ELF static info symbol of initial sample.symtab present: no
    Source: classification engineClassification label: mal64.troj.lin@0/0@0/0

    Hooking and other Techniques for Hiding and Protection

    barindex
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 36102
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 36150
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 36194
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 36228
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 36276
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 36316
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 55232
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 36348
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 36390
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 55258
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 55436
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 36450
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 36738
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 36796
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 36846
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 55504
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 36882
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 55816
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 36928
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 55840
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 36958
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 55874
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37056
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37134
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37200
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37254
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 55976
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 56270
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 56296
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 56314
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 56330
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37288
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 56354
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37490
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 56452
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 56532
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 56622
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 56694
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 56750
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 56798
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 56854
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37586
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 38010
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 38052
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 38194
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 38350
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 38454
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 56884
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 38542
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57504
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57562
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57628
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57674
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57700
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57740
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57700
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57802

    Stealing of Sensitive Information

    barindex
    Source: Yara matchFile source: dump.pcap, type: PCAP

    Remote Access Functionality

    barindex
    Source: Yara matchFile source: dump.pcap, type: PCAP
    Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
    Valid AccountsWindows Management InstrumentationPath InterceptionPath InterceptionDirect Volume AccessOS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local SystemExfiltration Over Other Network Medium1
    Encrypted Channel
    Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
    Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over Bluetooth11
    Non-Standard Port
    Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
    Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated Exfiltration1
    Application Layer Protocol
    Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
    No configs have been found
    Hide Legend

    Legend:

    • Process
    • Signature
    • Created File
    • DNS/IP Info
    • Is Dropped
    • Number of created Files
    • Is malicious
    • Internet
    behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 635907 Sample: x86 Startdate: 30/05/2022 Architecture: LINUX Score: 64 26 206.219.82.9 ZAYO-6461US United States 2->26 28 174.130.97.135 WINDSTREAMUS United States 2->28 30 98 other IPs or domains 2->30 32 Multi AV Scanner detection for submitted file 2->32 34 Yara detected Mirai 2->34 36 Machine Learning detection for sample 2->36 38 Uses known network protocols on non-standard ports 2->38 10 x86 2->10         started        signatures3 process4 process5 12 x86 10->12         started        14 x86 10->14         started        process6 16 x86 12->16         started        18 x86 12->18         started        process7 20 x86 16->20         started        22 x86 18->22         started        process8 24 x86 20->24         started       
    SourceDetectionScannerLabelLink
    x8646%VirustotalBrowse
    x86100%Joe Sandbox ML
    No Antivirus matches
    No Antivirus matches
    No Antivirus matches
    No contacted domains info
    • No. of IPs < 25%
    • 25% < No. of IPs < 50%
    • 50% < No. of IPs < 75%
    • 75% < No. of IPs
    IPDomainCountryFlagASNASN NameMalicious
    71.82.186.46
    unknownUnited States
    20115CHARTER-20115USfalse
    8.188.166.156
    unknownSingapore
    37963CNNIC-ALIBABA-CN-NET-APHangzhouAlibabaAdvertisingCoLtdfalse
    222.18.102.174
    unknownChina
    4538ERX-CERNET-BKBChinaEducationandResearchNetworkCenterfalse
    163.69.133.211
    unknownFrance
    17816CHINA169-GZChinaUnicomIPnetworkChina169Guangdongprovifalse
    161.199.170.152
    unknownUnited States
    27311AS27311USfalse
    97.195.248.46
    unknownUnited States
    6167CELLCO-PARTUSfalse
    167.127.239.68
    unknownUnited States
    11520ALLSTATE-INSURANCE-COUSfalse
    115.107.38.68
    unknownChina
    17488HATHWAY-NET-APHathwayIPOverCableInternetINfalse
    173.66.71.180
    unknownUnited States
    701UUNETUSfalse
    24.45.250.77
    unknownUnited States
    6128CABLE-NET-1USfalse
    92.184.111.45
    unknownFrance
    3215FranceTelecom-OrangeFRfalse
    61.106.99.55
    unknownKorea Republic of
    17839DREAMPLUS-AS-KRLGHelloVisionCorpKRfalse
    98.112.164.94
    unknownUnited States
    7018ATT-INTERNET4USfalse
    223.217.50.228
    unknownJapan4713OCNNTTCommunicationsCorporationJPfalse
    112.183.28.110
    unknownKorea Republic of
    4766KIXS-AS-KRKoreaTelecomKRfalse
    183.23.36.205
    unknownChina
    4134CHINANET-BACKBONENo31Jin-rongStreetCNfalse
    161.145.179.44
    unknownUnited States
    263740CorporacionLaceibanetsocietyHNfalse
    171.188.4.179
    unknownUnited States
    9874STARHUB-MOBILEStarHubLtdSGfalse
    66.126.55.147
    unknownUnited States
    22352APPLIED-TECHNOLOGYUSfalse
    206.219.82.9
    unknownUnited States
    6461ZAYO-6461USfalse
    1.68.163.174
    unknownChina
    4134CHINANET-BACKBONENo31Jin-rongStreetCNfalse
    141.89.138.125
    unknownGermany
    680DFNVereinzurFoerderungeinesDeutschenForschungsnetzesefalse
    139.182.115.224
    unknownUnited States
    2152CSUNET-NWUSfalse
    63.100.146.131
    unknownUnited States
    701UUNETUSfalse
    116.40.101.173
    unknownKorea Republic of
    17858POWERVIS-AS-KRLGPOWERCOMMKRfalse
    166.111.47.118
    unknownChina
    4538ERX-CERNET-BKBChinaEducationandResearchNetworkCenterfalse
    73.99.131.134
    unknownUnited States
    7922COMCAST-7922USfalse
    71.75.173.83
    unknownUnited States
    11426TWC-11426-CAROLINASUSfalse
    20.231.62.15
    unknownUnited States
    8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
    220.79.231.181
    unknownKorea Republic of
    4766KIXS-AS-KRKoreaTelecomKRfalse
    130.146.219.140
    unknownNetherlands
    6908DATAHOPDatahop-SixDegreesGBfalse
    18.252.179.134
    unknownUnited States
    16509AMAZON-02USfalse
    174.130.97.135
    unknownUnited States
    7029WINDSTREAMUSfalse
    168.5.246.18
    unknownUnited States
    8RICE-ASUSfalse
    103.223.165.48
    unknownChina
    135445IDNIC-AIRPAY-AS-IDPTAirpayInternationalIndonesiaIDfalse
    63.202.183.61
    unknownUnited States
    7018ATT-INTERNET4USfalse
    196.170.140.141
    unknownTogo
    24691TOGOTEL-ASTogoTelecomTogoTGfalse
    181.45.1.154
    unknownArgentina
    27747TelecentroSAARfalse
    206.9.140.116
    unknownUnited States
    5006VOYANTUSfalse
    109.174.181.139
    unknownUnited Kingdom
    4589EASYNETEasynetGlobalServicesEUfalse
    182.134.160.88
    unknownChina
    4134CHINANET-BACKBONENo31Jin-rongStreetCNfalse
    95.183.142.116
    unknownTurkey
    8517ULAKNETTRfalse
    9.100.126.155
    unknownUnited States
    3356LEVEL3USfalse
    34.96.75.202
    unknownUnited States
    15169GOOGLEUSfalse
    169.80.122.10
    unknownUnited States
    37611AfrihostZAfalse
    212.229.189.169
    unknownUnited Kingdom
    6659NEXINTO-DEfalse
    193.122.239.176
    unknownUnited States
    31898ORACLE-BMC-31898USfalse
    199.98.250.141
    unknownUnited States
    174COGENT-174USfalse
    152.247.120.26
    unknownBrazil
    26599TELEFONICABRASILSABRfalse
    98.175.159.226
    unknownUnited States
    22773ASN-CXA-ALL-CCI-22773-RDCUSfalse
    149.64.54.62
    unknownUnited States
    188SAIC-ASUSfalse
    185.91.208.162
    unknownAzerbaijan
    198193ASN-TCABLEESfalse
    54.109.99.197
    unknownUnited States
    16509AMAZON-02USfalse
    91.211.55.231
    unknownRussian Federation
    48494MKNET-ASCZfalse
    9.195.199.9
    unknownUnited States
    3356LEVEL3USfalse
    114.108.48.50
    unknownKorea Republic of
    23563VITSSEN-SUWON-AS-KRTbroadSuwonBroadcastingCorporationKfalse
    218.72.121.235
    unknownChina
    4134CHINANET-BACKBONENo31Jin-rongStreetCNfalse
    18.133.194.252
    unknownUnited States
    16509AMAZON-02USfalse
    157.21.250.131
    unknownUnited States
    53446EVMSUSfalse
    38.118.59.140
    unknownUnited States
    174COGENT-174USfalse
    184.98.240.213
    unknownUnited States
    209CENTURYLINK-US-LEGACY-QWESTUSfalse
    176.86.239.65
    unknownSpain
    3352TELEFONICA_DE_ESPANAESfalse
    203.101.40.148
    unknownIndia
    24560AIRTELBROADBAND-AS-APBhartiAirtelLtdTelemediaServicesfalse
    216.137.217.153
    unknownUnited States
    11090MTAONLINE-ASUSfalse
    89.67.99.51
    unknownPoland
    6830LIBERTYGLOBALLibertyGlobalformerlyUPCBroadbandHoldingfalse
    183.152.181.199
    unknownChina
    4134CHINANET-BACKBONENo31Jin-rongStreetCNfalse
    39.3.14.235
    unknownJapan4725ODNSoftBankMobileCorpJPfalse
    185.203.160.88
    unknownIran (ISLAMIC Republic Of)
    205837SADADPSP-ASSadadProcessingModernServicesCompanyPJSfalse
    90.34.68.223
    unknownFrance
    3215FranceTelecom-OrangeFRfalse
    187.213.164.208
    unknownMexico
    8151UninetSAdeCVMXfalse
    200.172.238.44
    unknownBrazil
    4230CLAROSABRfalse
    61.73.112.244
    unknownKorea Republic of
    4766KIXS-AS-KRKoreaTelecomKRfalse
    81.148.253.114
    unknownUnited Kingdom
    2856BT-UK-ASBTnetUKRegionalnetworkGBfalse
    45.173.39.97
    unknownBrazil
    268790DEBORAALINEALMEIDA-MEBRfalse
    131.215.33.187
    unknownUnited States
    31CITUSfalse
    112.183.28.147
    unknownKorea Republic of
    4766KIXS-AS-KRKoreaTelecomKRfalse
    99.55.160.90
    unknownUnited States
    7018ATT-INTERNET4USfalse
    108.30.94.26
    unknownUnited States
    701UUNETUSfalse
    136.94.212.177
    unknownUnited States
    60311ONEFMCHfalse
    115.6.239.91
    unknownKorea Republic of
    4766KIXS-AS-KRKoreaTelecomKRfalse
    42.170.152.249
    unknownChina
    4249LILLY-ASUSfalse
    77.19.124.127
    unknownNorway
    2119TELENOR-NEXTELTelenorNorgeASNOfalse
    209.210.62.8
    unknownUnited States
    396033BFDX515USfalse
    149.210.46.1
    unknownGreece
    29247COSMOTE-GRCosmoteMobileTelecommunicationsSAGRfalse
    85.103.175.203
    unknownTurkey
    9121TTNETTRfalse
    125.137.19.174
    unknownKorea Republic of
    4766KIXS-AS-KRKoreaTelecomKRfalse
    213.23.15.125
    unknownGermany
    3209VODANETInternationalIP-BackboneofVodafoneDEfalse
    191.154.239.239
    unknownColombia
    26611COMCELSACOfalse
    153.248.18.11
    unknownJapan4713OCNNTTCommunicationsCorporationJPfalse
    179.185.213.56
    unknownBrazil
    18881TELEFONICABRASILSABRfalse
    84.223.116.24
    unknownItaly
    8612TISCALI-ITfalse
    94.9.108.60
    unknownUnited Kingdom
    5607BSKYB-BROADBAND-ASGBfalse
    203.190.179.96
    unknownSingapore
    7552VIETEL-AS-APViettelGroupVNfalse
    158.113.125.249
    unknownUnited States
    49278NORDEFNOfalse
    42.30.66.52
    unknownKorea Republic of
    9644SKTELECOM-NET-ASSKTelecomKRfalse
    128.83.226.100
    unknownUnited States
    18UTEXASUSfalse
    218.209.89.102
    unknownKorea Republic of
    23563VITSSEN-SUWON-AS-KRTbroadSuwonBroadcastingCorporationKfalse
    98.67.105.92
    unknownUnited States
    11351TWC-11351-NORTHEASTUSfalse
    161.26.142.204
    unknownUnited States
    1916AssociacaoRedeNacionaldeEnsinoePesquisaBRfalse
    131.141.109.74
    unknownCanada
    74SSC-299-Z-74CAfalse
    No context
    No context
    No context
    No context
    No context
    No created / dropped files found
    File type:ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, stripped
    Entropy (8bit):6.483956231146537
    TrID:
    • ELF Executable and Linkable format (Linux) (4029/14) 50.16%
    • ELF Executable and Linkable format (generic) (4004/1) 49.84%
    File name:x86
    File size:55332
    MD5:bef642eeed970f7c3ee944a513ea4c88
    SHA1:baaa1dc20118f95134cb1ca1fa0c32ad49ed8eeb
    SHA256:10f35885f96f694fbf6239de4f4e400367cdb0201bd6b4a6fa85b3cc609de22e
    SHA512:11e9b343e7c658355d22ea542808b0f1bcb191cc4537296d4ea3ceac1a564b0c1fa283f831054a029451207a5cfae41939231aab73ac9f737036aea887f3b8f1
    SSDEEP:768:cRe7+KeFIsC1pDU/4p+gP0JrTS/+Q+Y7RamvmxDOKUKICkmT1:WI+KidsP0JK/+Qh7RasmxiKFsm
    TLSH:60433A85D6DBF9F2E85104BC30A9AB72DF33F53AA871D9DBE39D24229C06201D20635D
    File Content Preview:.ELF....................d...4...........4. ...(..............................................c...c.......k..........Q.td............................U..S............h....C...[]...$.............U......=`f...t..5.....c......c......u........t....h.S..........

    ELF header

    Class:ELF32
    Data:2's complement, little endian
    Version:1 (current)
    Machine:Intel 80386
    Version Number:0x1
    Type:EXEC (Executable file)
    OS/ABI:UNIX - System V
    ABI Version:0
    Entry Point Address:0x8048164
    Flags:0x0
    ELF Header Size:52
    Program Header Offset:52
    Program Header Size:32
    Number of Program Headers:3
    Section Header Offset:54932
    Section Header Size:40
    Number of Section Headers:10
    Header String Table Index:9
    NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
    NULL0x00x00x00x00x0000
    .initPROGBITS0x80480940x940x1c0x00x6AX001
    .textPROGBITS0x80480b00xb00xc3660x00x6AX0016
    .finiPROGBITS0x80544160xc4160x170x00x6AX001
    .rodataPROGBITS0x80544400xc4400xf400x00x2A0032
    .ctorsPROGBITS0x80563840xd3840x80x00x3WA004
    .dtorsPROGBITS0x805638c0xd38c0x80x00x3WA004
    .dataPROGBITS0x80563c00xd3c00x2940x00x3WA0032
    .bssNOBITS0x80566600xd6540x69040x00x3WA0032
    .shstrtabSTRTAB0x00xd6540x3e0x00x0001
    TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
    LOAD0x00x80480000x80480000xd3800xd3803.61310x5R E0x1000.init .text .fini .rodata
    LOAD0xd3840x80563840x80563840x2d00x6be02.08110x6RW 0x1000.ctors .dtors .data .bss
    GNU_STACK0x00x00x00x00x00.00000x6RW 0x4
    TimestampSource PortDest PortSource IPDest IP
    May 30, 2022 06:59:33.350195885 CEST2350008119.48.37.48192.168.2.23
    May 30, 2022 06:59:33.350447893 CEST5000823192.168.2.23119.48.37.48
    May 30, 2022 06:59:33.684422970 CEST2341260112.199.58.34192.168.2.23
    May 30, 2022 06:59:33.684451103 CEST2341260112.199.58.34192.168.2.23
    May 30, 2022 06:59:33.684602976 CEST4126023192.168.2.23112.199.58.34
    May 30, 2022 06:59:33.684638977 CEST4126023192.168.2.23112.199.58.34
    May 30, 2022 06:59:33.902144909 CEST2350008119.48.37.48192.168.2.23
    May 30, 2022 06:59:33.902334929 CEST5000823192.168.2.23119.48.37.48
    May 30, 2022 06:59:34.534204006 CEST42836443192.168.2.2391.189.91.43
    May 30, 2022 06:59:34.790235043 CEST4251680192.168.2.23109.202.202.202
    May 30, 2022 06:59:34.998879910 CEST2350008119.48.37.48192.168.2.23
    May 30, 2022 06:59:34.999098063 CEST5000823192.168.2.23119.48.37.48
    May 30, 2022 06:59:35.408418894 CEST3637323192.168.2.238.96.87.23
    May 30, 2022 06:59:35.408418894 CEST3637323192.168.2.23101.211.21.120
    May 30, 2022 06:59:35.408428907 CEST3637323192.168.2.23179.10.18.120
    May 30, 2022 06:59:35.408435106 CEST3637323192.168.2.23119.21.212.120
    May 30, 2022 06:59:35.408468008 CEST3637323192.168.2.2331.254.177.252
    May 30, 2022 06:59:35.408472061 CEST3637323192.168.2.23162.189.50.109
    May 30, 2022 06:59:35.408493042 CEST3637323192.168.2.2392.155.50.169
    May 30, 2022 06:59:35.408500910 CEST3637323192.168.2.231.114.66.222
    May 30, 2022 06:59:35.408500910 CEST3637323192.168.2.2383.164.66.106
    May 30, 2022 06:59:35.408505917 CEST3637323192.168.2.2380.45.115.63
    May 30, 2022 06:59:35.408514023 CEST3637323192.168.2.2319.139.69.139
    May 30, 2022 06:59:35.408525944 CEST3637323192.168.2.23136.163.173.249
    May 30, 2022 06:59:35.408535004 CEST3637323192.168.2.23100.17.171.186
    May 30, 2022 06:59:35.408538103 CEST3637323192.168.2.232.253.132.212
    May 30, 2022 06:59:35.408546925 CEST3637323192.168.2.23102.143.203.201
    May 30, 2022 06:59:35.408565044 CEST3637323192.168.2.2318.19.199.39
    May 30, 2022 06:59:35.408590078 CEST3637323192.168.2.23117.78.143.153
    May 30, 2022 06:59:35.408595085 CEST3637323192.168.2.23131.130.219.36
    May 30, 2022 06:59:35.408596992 CEST3637323192.168.2.2387.129.46.43
    May 30, 2022 06:59:35.408620119 CEST3637323192.168.2.2372.201.168.50
    May 30, 2022 06:59:35.408674955 CEST3637323192.168.2.2391.78.49.31
    May 30, 2022 06:59:35.408679962 CEST3637323192.168.2.23118.61.172.171
    May 30, 2022 06:59:35.408679962 CEST3637323192.168.2.23117.236.64.119
    May 30, 2022 06:59:35.408684015 CEST3637323192.168.2.23218.55.177.68
    May 30, 2022 06:59:35.408694983 CEST3637323192.168.2.23102.24.47.215
    May 30, 2022 06:59:35.408695936 CEST3637323192.168.2.2370.37.108.135
    May 30, 2022 06:59:35.408696890 CEST3637323192.168.2.23117.182.136.248
    May 30, 2022 06:59:35.408701897 CEST3637323192.168.2.2387.32.147.70
    May 30, 2022 06:59:35.408703089 CEST3637323192.168.2.23155.15.109.18
    May 30, 2022 06:59:35.408710003 CEST3637323192.168.2.23190.247.152.244
    May 30, 2022 06:59:35.408715963 CEST3637323192.168.2.23125.239.28.124
    May 30, 2022 06:59:35.408716917 CEST3637323192.168.2.23131.48.123.198
    May 30, 2022 06:59:35.408727884 CEST3637323192.168.2.23161.184.56.240
    May 30, 2022 06:59:35.408729076 CEST3637323192.168.2.23108.162.204.92
    May 30, 2022 06:59:35.408734083 CEST3637323192.168.2.23147.166.16.121
    May 30, 2022 06:59:35.408807039 CEST3637323192.168.2.23196.134.215.117
    May 30, 2022 06:59:35.408816099 CEST3637323192.168.2.2342.27.39.90
    May 30, 2022 06:59:35.408827066 CEST3637323192.168.2.2358.57.176.45
    May 30, 2022 06:59:35.408855915 CEST3637323192.168.2.23168.229.44.89
    May 30, 2022 06:59:35.408860922 CEST3637323192.168.2.2380.116.246.85
    May 30, 2022 06:59:35.408869982 CEST3637323192.168.2.2323.202.87.42
    May 30, 2022 06:59:35.408874035 CEST3637323192.168.2.23135.84.138.222
    May 30, 2022 06:59:35.408883095 CEST3637323192.168.2.23221.54.169.180
    May 30, 2022 06:59:35.408905029 CEST3637323192.168.2.23153.35.145.184
    May 30, 2022 06:59:35.408905029 CEST3637323192.168.2.2393.252.199.123
    May 30, 2022 06:59:35.408922911 CEST3637323192.168.2.23110.18.183.220
    May 30, 2022 06:59:35.408925056 CEST3637323192.168.2.23200.13.58.219
    May 30, 2022 06:59:35.408934116 CEST3637323192.168.2.23207.86.126.100
    May 30, 2022 06:59:35.408947945 CEST3637323192.168.2.2367.250.83.151
    May 30, 2022 06:59:35.408960104 CEST3637323192.168.2.2395.138.69.241
    May 30, 2022 06:59:35.408970118 CEST3637323192.168.2.2367.202.193.96
    May 30, 2022 06:59:35.408979893 CEST3637323192.168.2.2347.41.174.1
    May 30, 2022 06:59:35.408991098 CEST3637323192.168.2.231.254.17.66
    May 30, 2022 06:59:35.409001112 CEST3637323192.168.2.2318.168.160.204
    May 30, 2022 06:59:35.409008980 CEST3637323192.168.2.2320.88.249.72
    May 30, 2022 06:59:35.409023046 CEST3637323192.168.2.232.161.172.133
    May 30, 2022 06:59:35.409033060 CEST3637323192.168.2.23192.221.23.40
    May 30, 2022 06:59:35.409044981 CEST3637323192.168.2.23151.116.52.175
    May 30, 2022 06:59:35.409054995 CEST3637323192.168.2.23119.111.118.243
    May 30, 2022 06:59:35.409065962 CEST3637323192.168.2.2365.36.16.51
    May 30, 2022 06:59:35.409080029 CEST3637323192.168.2.23128.140.250.128
    May 30, 2022 06:59:35.409084082 CEST3637323192.168.2.23122.105.233.110
    May 30, 2022 06:59:35.409097910 CEST3637323192.168.2.23132.205.154.72
    May 30, 2022 06:59:35.409107924 CEST3637323192.168.2.23118.181.150.139
    May 30, 2022 06:59:35.409116030 CEST3637323192.168.2.23148.193.212.143
    May 30, 2022 06:59:35.409125090 CEST3637323192.168.2.23168.97.66.76
    May 30, 2022 06:59:35.409142971 CEST3637323192.168.2.2371.136.9.107
    May 30, 2022 06:59:35.409151077 CEST3637323192.168.2.23212.97.246.207
    May 30, 2022 06:59:35.409158945 CEST3637323192.168.2.2391.6.240.218
    May 30, 2022 06:59:35.409178019 CEST3637323192.168.2.23131.72.158.124
    May 30, 2022 06:59:35.409188032 CEST3637323192.168.2.2358.169.66.188
    May 30, 2022 06:59:35.409198999 CEST3637323192.168.2.23183.211.69.53
    May 30, 2022 06:59:35.409212112 CEST3637323192.168.2.23109.191.69.175
    May 30, 2022 06:59:35.409240007 CEST3637323192.168.2.23122.189.245.178
    May 30, 2022 06:59:35.409248114 CEST3637323192.168.2.23209.147.2.206
    May 30, 2022 06:59:35.409248114 CEST3637323192.168.2.23171.78.211.12
    May 30, 2022 06:59:35.409267902 CEST3637323192.168.2.23202.122.130.17
    May 30, 2022 06:59:35.409584045 CEST3637323192.168.2.2337.237.124.2
    May 30, 2022 06:59:35.409590006 CEST3637323192.168.2.23114.50.255.22
    May 30, 2022 06:59:35.409612894 CEST3637323192.168.2.2360.103.177.248
    May 30, 2022 06:59:35.409615040 CEST3637323192.168.2.2377.13.181.73
    May 30, 2022 06:59:35.409627914 CEST3637323192.168.2.23136.246.188.42
    May 30, 2022 06:59:35.409636021 CEST3637323192.168.2.23181.43.175.189
    May 30, 2022 06:59:35.409655094 CEST3637323192.168.2.23144.0.247.73
    May 30, 2022 06:59:35.409662962 CEST3637323192.168.2.2331.240.157.160
    May 30, 2022 06:59:35.409678936 CEST3637323192.168.2.23200.142.192.117
    May 30, 2022 06:59:35.409681082 CEST3637323192.168.2.2317.55.108.2
    May 30, 2022 06:59:35.409701109 CEST3637323192.168.2.23221.24.144.224

    System Behavior

    Start time:06:59:34
    Start date:30/05/2022
    Path:/tmp/x86
    Arguments:/tmp/x86
    File size:55332 bytes
    MD5 hash:bef642eeed970f7c3ee944a513ea4c88
    Start time:06:59:34
    Start date:30/05/2022
    Path:/tmp/x86
    Arguments:n/a
    File size:55332 bytes
    MD5 hash:bef642eeed970f7c3ee944a513ea4c88
    Start time:06:59:34
    Start date:30/05/2022
    Path:/tmp/x86
    Arguments:n/a
    File size:55332 bytes
    MD5 hash:bef642eeed970f7c3ee944a513ea4c88
    Start time:06:59:34
    Start date:30/05/2022
    Path:/tmp/x86
    Arguments:n/a
    File size:55332 bytes
    MD5 hash:bef642eeed970f7c3ee944a513ea4c88
    Start time:06:59:41
    Start date:30/05/2022
    Path:/tmp/x86
    Arguments:n/a
    File size:55332 bytes
    MD5 hash:bef642eeed970f7c3ee944a513ea4c88
    Start time:06:59:41
    Start date:30/05/2022
    Path:/tmp/x86
    Arguments:n/a
    File size:55332 bytes
    MD5 hash:bef642eeed970f7c3ee944a513ea4c88
    Start time:06:59:34
    Start date:30/05/2022
    Path:/tmp/x86
    Arguments:n/a
    File size:55332 bytes
    MD5 hash:bef642eeed970f7c3ee944a513ea4c88
    Start time:06:59:34
    Start date:30/05/2022
    Path:/tmp/x86
    Arguments:n/a
    File size:55332 bytes
    MD5 hash:bef642eeed970f7c3ee944a513ea4c88