Source: na.elf |
ReversingLabs: Detection: 18% |
Source: Network traffic |
Suricata IDS: 2850023 - Severity 1 - ETPRO JA3 Hash - Possible Ligolo Server/Golang Binary Response : 121.41.18.122:3232 -> 192.168.2.23:54174 |
Source: global traffic |
TCP traffic: 192.168.2.23:54174 -> 121.41.18.122:3232 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 91.189.91.42 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 121.41.18.122 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 121.41.18.122 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 121.41.18.122 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 121.41.18.122 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 121.41.18.122 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 121.41.18.122 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 121.41.18.122 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 121.41.18.122 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 121.41.18.122 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 121.41.18.122 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 121.41.18.122 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 121.41.18.122 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 121.41.18.122 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 121.41.18.122 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 121.41.18.122 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 121.41.18.122 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 121.41.18.122 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 121.41.18.122 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 121.41.18.122 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 121.41.18.122 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 121.41.18.122 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 121.41.18.122 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 121.41.18.122 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 121.41.18.122 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 121.41.18.122 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 121.41.18.122 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 121.41.18.122 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 121.41.18.122 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 121.41.18.122 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 121.41.18.122 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 121.41.18.122 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 121.41.18.122 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 121.41.18.122 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 121.41.18.122 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 121.41.18.122 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 121.41.18.122 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 121.41.18.122 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 121.41.18.122 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 121.41.18.122 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 121.41.18.122 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 121.41.18.122 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 121.41.18.122 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 121.41.18.122 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 121.41.18.122 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 121.41.18.122 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 121.41.18.122 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 121.41.18.122 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 121.41.18.122 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 121.41.18.122 |
Source: na.elf |
String found in binary or memory: http://upx.sf.net |
Source: unknown |
Network traffic detected: HTTP traffic on port 43928 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 39256 |
Source: unknown |
Network traffic detected: HTTP traffic on port 39256 -> 443 |
Source: LOAD without section mappings |
Program segment: 0x400000 |
Source: classification engine |
Classification label: mal64.evad.linELF@0/0@0/0 |
Source: initial sample |
String containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $ |
Source: initial sample |
String containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $ |
Source: initial sample |
String containing UPX found: $Id: UPX 3.96 Copyright (C) 1996-2020 the UPX Team. All Rights Reserved. $ |
Source: /usr/bin/dash (PID: 6295) |
Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.hsFND1riiL /tmp/tmp.h3IQgAEO96 /tmp/tmp.5cGkCVw7uC |
Jump to behavior |
Source: /usr/bin/dash (PID: 6296) |
Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.hsFND1riiL /tmp/tmp.h3IQgAEO96 /tmp/tmp.5cGkCVw7uC |
Jump to behavior |
Source: submitted sample |
Stderr: 2024/10/06 15:59:10 Forking2024/10/06 15:59:11 Connecting to 121.41.18.122:32322024/10/06 15:59:14 Successfully connnected
121.41.18.122:32322024/10/06 15:59:14 [client] INFO ??:1 BoFsrOtr() : Handling channel: jump2024/10/06 15:59:17 [121.41.18.122:3232]
INFO ??:1 () : New SSH connection, version SSH-2.0-paramiko_3.0.02024/10/06 15:59:18 [121.41.18.122:3232] INFO ??:1 BoFsrOtr()
: Handling channel: session2024/10/06 15:59:19 [121.41.18.122:3232] INFO ??:1 BoFsrOtr() : Handling channel: session2024/10/06
15:59:20 [121.41.18.122:3232] INFO ??:1 IFu6thF7() : Session got request: "exec"2024/10/06 15:59:20 [121.41.18.122:3232] INFO
??:3 IFu6thF7() : Session disconnected2024/10/06 15:59:20 [121.41.18.122:3232] INFO ??:6 IFu6thF7() : Session disconnected2024/10/06
15:59:20 [client] ERROR ??:1 () : Channel call back error: connection terminated: exit code = 0 |
Source: na.elf |
Submission file: segment LOAD with 7.8849 entropy (max. 8.0) |
Source: /proc/self/exe (PID: 6282) |
Queries kernel information via 'uname': |
Jump to behavior |