Click to jump to signature section
Source: T0UouPkHIQ.elf | ReversingLabs: Detection: 43% |
Source: T0UouPkHIQ.elf | Virustotal: Detection: 49% | Perma Link |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 33314 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 33320 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 33332 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 33340 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 33354 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 33360 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 33384 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 33408 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 33424 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 33432 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 33458 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 33478 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 33486 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 33494 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 33500 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 33508 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 33518 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 33522 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 33528 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 33548 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 33582 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 33606 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 33612 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 33618 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 33624 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 33630 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 33636 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 33646 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 58968 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 58974 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 58978 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 58982 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 58988 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 58994 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 59000 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 59006 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 59012 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 59016 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 59024 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 59028 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 59034 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 59044 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 59058 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 59064 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 59076 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 59086 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 59092 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 59098 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 59122 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 59146 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 59172 |
Source: global traffic | TCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443 |
Source: global traffic | TCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80 |
Source: global traffic | TCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443 |
Source: global traffic | TCP traffic: 192.168.2.23:51468 -> 45.95.169.181:6666 |
Source: /tmp/T0UouPkHIQ.elf (PID: 6391) | Socket: 127.0.0.1::8888 | Jump to behavior |
Source: /tmp/T0UouPkHIQ.elf (PID: 6399) | Socket: 0.0.0.0::23 | Jump to behavior |
Source: unknown | Network traffic detected: HTTP traffic on port 43928 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 42836 -> 443 |
Source: unknown | TCP traffic detected without corresponding DNS query: 61.31.174.2 |
Source: unknown | TCP traffic detected without corresponding DNS query: 171.156.80.98 |
Source: unknown | TCP traffic detected without corresponding DNS query: 217.178.43.36 |
Source: unknown | TCP traffic detected without corresponding DNS query: 218.13.236.16 |
Source: unknown | TCP traffic detected without corresponding DNS query: 1.54.103.113 |
Source: unknown | TCP traffic detected without corresponding DNS query: 109.218.43.86 |
Source: unknown | TCP traffic detected without corresponding DNS query: 183.71.68.147 |
Source: unknown | TCP traffic detected without corresponding DNS query: 34.149.242.204 |
Source: unknown | TCP traffic detected without corresponding DNS query: 196.18.86.132 |
Source: unknown | TCP traffic detected without corresponding DNS query: 157.90.76.132 |
Source: unknown | TCP traffic detected without corresponding DNS query: 14.163.119.38 |
Source: unknown | TCP traffic detected without corresponding DNS query: 197.228.249.191 |
Source: unknown | TCP traffic detected without corresponding DNS query: 99.53.171.127 |
Source: unknown | TCP traffic detected without corresponding DNS query: 82.121.74.65 |
Source: unknown | TCP traffic detected without corresponding DNS query: 184.141.165.119 |
Source: unknown | TCP traffic detected without corresponding DNS query: 61.0.86.39 |
Source: unknown | TCP traffic detected without corresponding DNS query: 131.53.158.185 |
Source: unknown | TCP traffic detected without corresponding DNS query: 157.163.16.60 |
Source: unknown | TCP traffic detected without corresponding DNS query: 99.131.220.99 |
Source: unknown | TCP traffic detected without corresponding DNS query: 125.96.138.25 |
Source: unknown | TCP traffic detected without corresponding DNS query: 143.50.89.43 |
Source: unknown | TCP traffic detected without corresponding DNS query: 67.121.147.31 |
Source: unknown | TCP traffic detected without corresponding DNS query: 69.67.42.10 |
Source: unknown | TCP traffic detected without corresponding DNS query: 67.173.198.103 |
Source: unknown | TCP traffic detected without corresponding DNS query: 45.132.95.235 |
Source: unknown | TCP traffic detected without corresponding DNS query: 221.201.236.185 |
Source: unknown | TCP traffic detected without corresponding DNS query: 132.46.241.222 |
Source: unknown | TCP traffic detected without corresponding DNS query: 144.83.84.95 |
Source: unknown | TCP traffic detected without corresponding DNS query: 107.220.19.105 |
Source: unknown | TCP traffic detected without corresponding DNS query: 143.111.22.41 |
Source: unknown | TCP traffic detected without corresponding DNS query: 8.160.226.177 |
Source: unknown | TCP traffic detected without corresponding DNS query: 162.199.226.2 |
Source: unknown | TCP traffic detected without corresponding DNS query: 156.253.114.253 |
Source: unknown | TCP traffic detected without corresponding DNS query: 27.208.41.101 |
Source: unknown | TCP traffic detected without corresponding DNS query: 23.26.186.63 |
Source: unknown | TCP traffic detected without corresponding DNS query: 16.175.190.171 |
Source: unknown | TCP traffic detected without corresponding DNS query: 223.200.249.91 |
Source: unknown | TCP traffic detected without corresponding DNS query: 207.223.205.101 |
Source: unknown | TCP traffic detected without corresponding DNS query: 76.162.114.154 |
Source: unknown | TCP traffic detected without corresponding DNS query: 34.6.63.3 |
Source: unknown | TCP traffic detected without corresponding DNS query: 139.173.13.246 |
Source: unknown | TCP traffic detected without corresponding DNS query: 197.63.7.103 |
Source: unknown | TCP traffic detected without corresponding DNS query: 94.180.255.159 |
Source: unknown | TCP traffic detected without corresponding DNS query: 31.223.200.228 |
Source: unknown | TCP traffic detected without corresponding DNS query: 180.234.38.8 |
Source: unknown | TCP traffic detected without corresponding DNS query: 41.130.206.62 |
Source: unknown | TCP traffic detected without corresponding DNS query: 83.166.159.129 |
Source: unknown | TCP traffic detected without corresponding DNS query: 111.241.11.29 |
Source: unknown | TCP traffic detected without corresponding DNS query: 8.209.224.119 |
Source: unknown | TCP traffic detected without corresponding DNS query: 169.183.199.111 |
Source: T0UouPkHIQ.elf | String found in binary or memory: http://45.95.169.181/bins/mips; |
Source: T0UouPkHIQ.elf | String found in binary or memory: http://fast.no/support/crawler.asp) |
Source: T0UouPkHIQ.elf | String found in binary or memory: http://feedback.redkolibri.com/ |
Source: T0UouPkHIQ.elf | String found in binary or memory: http://www.baidu.com/search/spider.htm) |
Source: T0UouPkHIQ.elf | String found in binary or memory: http://www.baidu.com/search/spider.html) |
Source: T0UouPkHIQ.elf | String found in binary or memory: http://www.billybobbot.com/crawler/) |
Source: ELF static info symbol of initial sample | .symtab present: no |
Source: classification engine | Classification label: mal68.troj.linELF@0/53@0/0 |
Source: /usr/sbin/logrotate (PID: 6372) | Shell command executed: sh -c "\n\t\tinvoke-rc.d --quiet cups restart > /dev/null\n" logrotate_script "/var/log/cups/*log " | Jump to behavior |
Source: /usr/sbin/logrotate (PID: 6381) | Shell command executed: sh -c /usr/lib/rsyslog/rsyslog-rotate logrotate_script /var/log/syslog | Jump to behavior |
Source: /usr/sbin/invoke-rc.d (PID: 6376) | Systemctl executable: /usr/bin/systemctl -> systemctl --quiet is-enabled cups.service | Jump to behavior |
Source: /usr/sbin/invoke-rc.d (PID: 6379) | Systemctl executable: /usr/bin/systemctl -> systemctl --quiet is-active cups.service | Jump to behavior |
Source: /usr/lib/rsyslog/rsyslog-rotate (PID: 6383) | Systemctl executable: /usr/bin/systemctl -> systemctl kill -s HUP rsyslog.service | Jump to behavior |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 33314 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 33320 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 33332 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 33340 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 33354 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 33360 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 33384 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 33408 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 33424 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 33432 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 33458 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 33478 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 33486 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 33494 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 33500 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 33508 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 33518 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 33522 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 33528 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 33548 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 33582 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 33606 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 33612 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 33618 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 33624 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 33630 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 33636 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 33646 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 58968 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 58974 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 58978 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 58982 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 58988 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 58994 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 59000 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 59006 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 59012 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 59016 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 59024 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 59028 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 59034 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 59044 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 59058 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 59064 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 59076 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 59086 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 59092 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 59098 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 59122 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 59146 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 59172 |
Source: /usr/sbin/logrotate (PID: 6201) | Truncated file: /var/log/btmp.2 | Jump to behavior |
Source: /usr/sbin/logrotate (PID: 6201) | Truncated file: /var/log/cups/access_log.1 | Jump to behavior |
Source: /usr/sbin/logrotate (PID: 6201) | Truncated file: /var/log/syslog.1 | Jump to behavior |
Source: /usr/bin/find (PID: 6247) | Queries kernel information via 'uname': | Jump to behavior |
Source: /tmp/T0UouPkHIQ.elf (PID: 6391) | Queries kernel information via 'uname': | Jump to behavior |
Source: 6375.22.dr | Binary or memory string: -9915837702310A--gzvmware kernel module |
Source: 6375.22.dr | Binary or memory string: -1116261022170A--gzQEMU User Emulator |
Source: 6375.22.dr | Binary or memory string: qemu-or1k |
Source: 6375.22.dr | Binary or memory string: qemu-riscv64 |
Source: 6375.22.dr | Binary or memory string: {cqemu |
Source: 6375.22.dr | Binary or memory string: qemu-arm |
Source: 6375.22.dr | Binary or memory string: (qemu |
Source: 6375.22.dr | Binary or memory string: qemu-tilegx |
Source: 6375.22.dr | Binary or memory string: qemu-hppa |
Source: 6375.22.dr | Binary or memory string: q{rqemu% |
Source: 6375.22.dr | Binary or memory string: )qemu |
Source: 6375.22.dr | Binary or memory string: vmware-toolbox-cmd |
Source: 6375.22.dr | Binary or memory string: qemu-ppc |
Source: 6375.22.dr | Binary or memory string: Tqemu9 |
Source: T0UouPkHIQ.elf, 6391.1.0000564f868ea000.0000564f8696f000.rw-.sdmp, T0UouPkHIQ.elf, 6397.1.0000564f868ea000.0000564f8696f000.rw-.sdmp, T0UouPkHIQ.elf, 6399.1.0000564f868ea000.0000564f8696f000.rw-.sdmp, T0UouPkHIQ.elf, 6409.1.0000564f868ea000.0000564f8696f000.rw-.sdmp, T0UouPkHIQ.elf, 6401.1.0000564f868ea000.0000564f8696f000.rw-.sdmp | Binary or memory string: /etc/qemu-binfmt/m68k |
Source: 6375.22.dr | Binary or memory string: qemu-aarch64_be |
Source: 6375.22.dr | Binary or memory string: 0qemu9 |
Source: 6375.22.dr | Binary or memory string: qemu-sparc64 |
Source: T0UouPkHIQ.elf, 6391.1.00007ffd063fd000.00007ffd0641e000.rw-.sdmp, T0UouPkHIQ.elf, 6397.1.00007ffd063fd000.00007ffd0641e000.rw-.sdmp, T0UouPkHIQ.elf, 6399.1.00007ffd063fd000.00007ffd0641e000.rw-.sdmp, T0UouPkHIQ.elf, 6409.1.00007ffd063fd000.00007ffd0641e000.rw-.sdmp, T0UouPkHIQ.elf, 6401.1.00007ffd063fd000.00007ffd0641e000.rw-.sdmp | Binary or memory string: x86_64/usr/bin/qemu-m68k/tmp/T0UouPkHIQ.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/T0UouPkHIQ.elf |
Source: 6375.22.dr | Binary or memory string: qemu-mips64 |
Source: 6375.22.dr | Binary or memory string: vV:qemu9 |
Source: 6375.22.dr | Binary or memory string: qemu-ppc64le |
Source: 6375.22.dr | Binary or memory string: <glib::param::uint64Glib::Param::UInt643pm315820097650A--gzWrapper for uint64 parameters in GLibx86_64-linux-gnu-ld.gold-1116112426130B--gzThe GNU ELF linkerprinter-profile-1115804162510A--gzProfile using X-Rite ColorMunki and Argyll CMSgrub-fstest-1116214898500A--gzdebug tool for GRUB filesystem driversxdg-user-dir-1115483406210A--gzFind an XDG user dirkmodsign-1115569251480A--gzKernel module signing toolsensible-editor-1115739932820A--gzsensible editing, paging, and web browsingminesMines6615854478170Cgnome-mines-gzinputattach-1115708189280A--gzattach a serial line to an input-layer devicegapplication-1116155671180A--gzD-Bus application launcherip-tunnel-8815816145190A--gztunnel configurationkoi8rxterm-1116140167530A--gzX terminal emulator for KOI8-R environmentsfoo2hiperc-wrapper-1115804162510A-tgzConvert Postscript into a HIPERC printer streamcryptsetup-reencrypt-8816002888050A--gztool for offline LUKS device re-encryptionsyndaemon-1115861716810A--gza program that monitors keyboard activity and disables the touchpad when the keyboard is being used.gslj-1115980290200B--gzFormat and print text for LaserJet printer using ghostscriptfile2brl-1115757179490A--gzTranslate an xml or a text file into an embosser-ready braille filexfdesktop-settings-1115793419820A--gzDesktop settings for Xfceua-1115856013570B--gzManage Ubuntu Advantage services from Canonicallatin4-7715812813670B--gzISO 8859-4 character set encoded in octal, decimal, and hexadecimalsane-genesys-5516003468200A--gzSANE backend for GL646, GL841, GL843, GL847 and GL124 based USB flatbed scannerspdftohtml-1115853266670A--gzprogram to convert PDF files into HTML, XML and PNG imagesbluetooth-sendto-1116015653360A--gzGTK application for transferring files over Bluetoothqemu-ppc64-1116261022170B--gzQEMU User Emulatorcache_metadata_size-8815811608350A--gzEstimate the size of the metadata device needed for a given configuration.net::dbus::exporterNet::DBus::Exporter3pm315773746310A--gzExport object methods and signals to the bussane-pint-5516003468200A--gzSANE backend for scanners that use the PINT device driverbpf-helpers7-7715812813670A--gzlist of eBPF helper functionsfull-4415812813670A--gzalways full devicelogin-1115906478670A--gzbegin session on the systemcups-snmp-8815877390340A--gzcups snmp backend (deprecated)ordchr-3am315728089600A--gzconvert characters to strings and vice versasosreport-1116092694050A--gzCollect and package diagnostic and support datatop-111582782727 |