Source: global traffic |
TCP traffic: 5.230.228.42 ports 34567,3,4,5,6,7 |
Source: global traffic |
TCP traffic: 5.230.228.44 ports 4443,0,1,2,5,27015,995,7 |
Source: global traffic |
TCP traffic: 5.230.228.62 ports 34567,3,993,4,5,6,3389,7 |
Source: /tmp/SecuriteInfo.com.ELF.Mirai-COW.6055.9040.elf (PID: 5433) |
Opens: /sys/class/net/ |
Jump to behavior |
Source: /tmp/SecuriteInfo.com.ELF.Mirai-COW.6055.9040.elf (PID: 5433) |
Opens: /sys/class/net/lo/address |
Jump to behavior |
Source: /tmp/SecuriteInfo.com.ELF.Mirai-COW.6055.9040.elf (PID: 5433) |
Opens: /sys/class/net/ens160/address |
Jump to behavior |
Source: /tmp/SecuriteInfo.com.ELF.Mirai-COW.6055.9040.elf (PID: 5433) |
Opens: /sys/class/net/ens160/flags |
Jump to behavior |
Source: /tmp/SecuriteInfo.com.ELF.Mirai-COW.6055.9040.elf (PID: 5433) |
Opens: /sys/class/net/ens160/carrier |
Jump to behavior |
Source: ip traffic |
Subnet 5.230.228.0/24: 5.230.228.46, 5.230.228.42, 5.230.228.23, 5.230.228.45, 5.230.228.44, 5.230.228.62 |
Source: global traffic |
TCP traffic: 192.168.2.13:38288 -> 185.248.144.209:25565 |
Source: global traffic |
TCP traffic: 192.168.2.13:48038 -> 194.156.98.15:7777 |
Source: global traffic |
TCP traffic: 192.168.2.13:33492 -> 94.131.118.154:25565 |
Source: global traffic |
TCP traffic: 192.168.2.13:49060 -> 5.230.228.46:3478 |
Source: global traffic |
TCP traffic: 192.168.2.13:57152 -> 5.230.228.62:34567 |
Source: global traffic |
TCP traffic: 192.168.2.13:58606 -> 5.230.122.80:3389 |
Source: global traffic |
TCP traffic: 192.168.2.13:48480 -> 5.230.228.42:34567 |
Source: global traffic |
TCP traffic: 192.168.2.13:48798 -> 5.230.228.23:35000 |
Source: global traffic |
TCP traffic: 192.168.2.13:60062 -> 5.230.228.44:27015 |
Source: global traffic |
TCP traffic: 192.168.2.13:51152 -> 5.230.229.84:10001 |
Source: global traffic |
TCP traffic: 192.168.2.13:37862 -> 5.230.228.45:18004 |
Source: global traffic |
TCP traffic: 192.168.2.13:58962 -> 5.230.118.247:10001 |
Source: global traffic |
TCP traffic: 192.168.2.13:46966 -> 5.230.171.8:6666 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 185.248.144.209 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 185.248.144.209 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 185.248.144.209 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 185.248.144.209 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 194.156.98.15 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 194.156.98.15 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 194.156.98.15 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 194.156.98.15 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 94.131.118.154 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 94.131.118.154 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 94.131.118.154 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 94.131.118.154 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 5.230.171.9 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 5.230.171.9 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 5.230.171.9 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 5.230.171.9 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 5.230.171.9 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 5.230.171.9 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 5.230.171.9 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 5.230.171.9 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 5.230.171.9 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 5.230.171.9 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 5.230.171.9 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 5.230.228.46 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 5.230.228.46 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 5.230.228.46 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 5.230.228.46 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 5.230.228.62 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 5.230.228.62 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 5.230.228.62 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 5.230.228.62 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 5.230.122.80 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 5.230.122.80 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 5.230.122.80 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 5.230.122.80 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 5.230.122.80 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 5.230.228.62 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 5.230.228.62 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 5.230.228.62 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 5.230.228.62 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 5.230.228.62 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 5.230.228.42 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 5.230.228.42 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 5.230.228.42 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 5.230.228.42 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 5.230.228.42 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 5.230.228.23 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 5.230.228.23 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 5.230.228.23 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 5.230.228.23 |
Source: global traffic |
DNS traffic detected: DNS query: iranistrash.libre |
Source: ELF static info symbol of initial sample |
.symtab present: no |
Source: classification engine |
Classification label: mal60.spre.troj.spyw.evad.linELF@0/0@1/0 |
Source: /usr/bin/dash (PID: 5416) |
Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.iU1SEy0i9P /tmp/tmp.G57otRedo4 /tmp/tmp.sO0jyoNh1s |
Jump to behavior |
Source: /usr/bin/dash (PID: 5417) |
Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.iU1SEy0i9P /tmp/tmp.G57otRedo4 /tmp/tmp.sO0jyoNh1s |
Jump to behavior |
Source: /tmp/SecuriteInfo.com.ELF.Mirai-COW.6055.9040.elf (PID: 5429) |
File: /tmp/SecuriteInfo.com.ELF.Mirai-COW.6055.9040.elf |
Jump to behavior |
Source: /tmp/SecuriteInfo.com.ELF.Mirai-COW.6055.9040.elf (PID: 5429) |
Queries kernel information via 'uname': |
Jump to behavior |
Source: /tmp/SecuriteInfo.com.ELF.Mirai-COW.6055.9040.elf (PID: 5433) |
Queries kernel information via 'uname': |
Jump to behavior |
Source: SecuriteInfo.com.ELF.Mirai-COW.6055.9040.elf, 5429.1.000055ebf0853000.000055ebf0981000.rw-.sdmp |
Binary or memory string: U!/etc/qemu-binfmt/arm |
Source: SecuriteInfo.com.ELF.Mirai-COW.6055.9040.elf, 5429.1.000055ebf0853000.000055ebf0981000.rw-.sdmp |
Binary or memory string: /etc/qemu-binfmt/arm |
Source: SecuriteInfo.com.ELF.Mirai-COW.6055.9040.elf, 5429.1.00007fffa67a0000.00007fffa67c1000.rw-.sdmp |
Binary or memory string: /usr/bin/qemu-arm |
Source: SecuriteInfo.com.ELF.Mirai-COW.6055.9040.elf, 5429.1.00007fffa67a0000.00007fffa67c1000.rw-.sdmp |
Binary or memory string: Hx86_64/usr/bin/qemu-arm/tmp/SecuriteInfo.com.ELF.Mirai-COW.6055.9040.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/SecuriteInfo.com.ELF.Mirai-COW.6055.9040.elf |
Source: Traffic |
DNS traffic detected: queries for: iranistrash.libre |