Source: global traffic |
TCP traffic: 5.230.122.82 ports 2022,3,993,7,37777,1935 |
Source: global traffic |
TCP traffic: 5.230.122.80 ports 35000,34567,3,4,554,27014,5,6,7 |
Source: global traffic |
TCP traffic: 5.230.229.83 ports 5222,2,3,4,7,3724 |
Source: global traffic |
TCP traffic: 5.230.228.62 ports 2,3,993,4,7,10001,3724 |
Source: global traffic |
TCP traffic: 194.156.98.15 ports 34567,3,443,4,5,6,7 |
Source: /tmp/SecuriteInfo.com.ELF.Mirai-CVD.30330.5069.elf (PID: 5448) |
Opens: /sys/class/net/ |
Jump to behavior |
Source: /tmp/SecuriteInfo.com.ELF.Mirai-CVD.30330.5069.elf (PID: 5448) |
Opens: /sys/class/net/lo/address |
Jump to behavior |
Source: /tmp/SecuriteInfo.com.ELF.Mirai-CVD.30330.5069.elf (PID: 5448) |
Opens: /sys/class/net/ens160/address |
Jump to behavior |
Source: /tmp/SecuriteInfo.com.ELF.Mirai-CVD.30330.5069.elf (PID: 5448) |
Opens: /sys/class/net/ens160/flags |
Jump to behavior |
Source: /tmp/SecuriteInfo.com.ELF.Mirai-CVD.30330.5069.elf (PID: 5448) |
Opens: /sys/class/net/ens160/carrier |
Jump to behavior |
Source: ip traffic |
Subnet 5.230.228.0/24: 5.230.228.47, 5.230.228.42, 5.230.228.23, 5.230.228.44, 5.230.228.62 |
Source: global traffic |
TCP traffic: 192.168.2.13:57436 -> 5.230.122.80:34567 |
Source: global traffic |
TCP traffic: 192.168.2.13:33740 -> 5.230.228.62:3724 |
Source: global traffic |
TCP traffic: 192.168.2.13:33782 -> 5.230.118.247:9000 |
Source: global traffic |
TCP traffic: 192.168.2.13:55364 -> 5.230.171.9:5000 |
Source: global traffic |
TCP traffic: 192.168.2.13:49748 -> 5.230.122.81:554 |
Source: global traffic |
TCP traffic: 192.168.2.13:38452 -> 5.230.228.44:10554 |
Source: global traffic |
TCP traffic: 192.168.2.13:40298 -> 5.230.122.82:37777 |
Source: global traffic |
TCP traffic: 192.168.2.13:59748 -> 185.248.144.209:993 |
Source: global traffic |
TCP traffic: 192.168.2.13:54706 -> 194.156.98.15:34567 |
Source: global traffic |
TCP traffic: 192.168.2.13:36506 -> 5.230.228.47:5000 |
Source: global traffic |
TCP traffic: 192.168.2.13:37776 -> 5.230.229.83:3724 |
Source: global traffic |
TCP traffic: 192.168.2.13:42252 -> 5.230.228.23:7000 |
Source: global traffic |
TCP traffic: 192.168.2.13:56458 -> 5.230.228.42:9000 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 5.230.122.80 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 5.230.122.80 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 5.230.122.80 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 5.230.122.80 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 5.230.122.80 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 5.230.228.62 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 5.230.228.62 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 5.230.228.62 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 5.230.228.62 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 5.230.118.247 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 5.230.118.247 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 5.230.118.247 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 5.230.118.247 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 5.230.122.80 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 5.230.122.80 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 5.230.122.80 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 5.230.122.80 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 5.230.122.80 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 5.230.122.80 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 5.230.122.80 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 5.230.122.80 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 5.230.171.9 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 5.230.171.9 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 5.230.171.9 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 5.230.171.9 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 5.230.228.62 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 5.230.228.62 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 5.230.228.62 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 5.230.228.62 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 5.230.122.81 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 5.230.122.81 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 5.230.122.81 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 5.230.122.81 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 5.230.228.44 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 5.230.228.44 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 5.230.228.44 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 5.230.122.81 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 5.230.228.44 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 5.230.118.247 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 5.230.118.247 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 5.230.118.247 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 5.230.118.247 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 5.230.122.82 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 5.230.122.82 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 5.230.122.82 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 5.230.122.82 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 185.248.144.209 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 185.248.144.209 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 185.248.144.209 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 185.248.144.209 |
Source: global traffic |
DNS traffic detected: DNS query: iranistrash.libre |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 56326 |
Source: unknown |
Network traffic detected: HTTP traffic on port 56326 -> 443 |
Source: ELF static info symbol of initial sample |
.symtab present: no |
Source: classification engine |
Classification label: mal60.spre.troj.spyw.evad.linELF@0/0@1/0 |
Source: /tmp/SecuriteInfo.com.ELF.Mirai-CVD.30330.5069.elf (PID: 5446) |
File: /tmp/SecuriteInfo.com.ELF.Mirai-CVD.30330.5069.elf |
Jump to behavior |
Source: /tmp/SecuriteInfo.com.ELF.Mirai-CVD.30330.5069.elf (PID: 5446) |
Queries kernel information via 'uname': |
Jump to behavior |
Source: /tmp/SecuriteInfo.com.ELF.Mirai-CVD.30330.5069.elf (PID: 5448) |
Queries kernel information via 'uname': |
Jump to behavior |
Source: SecuriteInfo.com.ELF.Mirai-CVD.30330.5069.elf, 5446.1.00007fffd46ac000.00007fffd46cd000.rw-.sdmp |
Binary or memory string: x86_64/usr/bin/qemu-ppc/tmp/SecuriteInfo.com.ELF.Mirai-CVD.30330.5069.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/SecuriteInfo.com.ELF.Mirai-CVD.30330.5069.elf |
Source: SecuriteInfo.com.ELF.Mirai-CVD.30330.5069.elf, 5446.1.000055e6c7d7f000.000055e6c7e2f000.rw-.sdmp |
Binary or memory string: !/etc/qemu-binfmt/ppc1 |
Source: SecuriteInfo.com.ELF.Mirai-CVD.30330.5069.elf, 5446.1.000055e6c7d7f000.000055e6c7e2f000.rw-.sdmp |
Binary or memory string: /etc/qemu-binfmt/ppc |
Source: SecuriteInfo.com.ELF.Mirai-CVD.30330.5069.elf, 5446.1.00007fffd46ac000.00007fffd46cd000.rw-.sdmp |
Binary or memory string: /usr/bin/qemu-ppc |
Source: Traffic |
DNS traffic detected: queries for: iranistrash.libre |