Linux Analysis Report
kkkmips.elf

Overview

General Information

Sample name: kkkmips.elf
Analysis ID: 1542907
MD5: 2f062e17fbb7780a5f276ab5ed52decc
SHA1: 0e83f57c4ce01b4ae4b77e2b13f34d2a84936505
SHA256: d773993b0901239af1ffdd4b0e32b672a60a1485fc904aaa93b66997a4c02816
Tags: elfkkkMiraiuser-NDA0E
Infos:

Detection

Score: 56
Range: 0 - 100
Whitelisted: false

Signatures

Antivirus / Scanner detection for submitted sample
Multi AV Scanner detection for submitted file
Detected TCP or UDP traffic on non-standard ports
Sample has stripped symbol table
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

AV Detection

barindex
Source: kkkmips.elf Avira: detected
Source: kkkmips.elf ReversingLabs: Detection: 71%
Source: global traffic TCP traffic: 192.168.2.15:40154 -> 5.59.249.232:1337
Source: unknown TCP traffic detected without corresponding DNS query: 5.59.249.232
Source: unknown TCP traffic detected without corresponding DNS query: 5.59.249.232
Source: unknown TCP traffic detected without corresponding DNS query: 158.102.219.167
Source: unknown TCP traffic detected without corresponding DNS query: 172.134.103.242
Source: unknown TCP traffic detected without corresponding DNS query: 125.13.85.167
Source: unknown TCP traffic detected without corresponding DNS query: 222.86.83.79
Source: unknown TCP traffic detected without corresponding DNS query: 104.158.60.48
Source: unknown TCP traffic detected without corresponding DNS query: 198.197.253.236
Source: unknown TCP traffic detected without corresponding DNS query: 78.86.78.52
Source: unknown TCP traffic detected without corresponding DNS query: 99.215.200.181
Source: unknown TCP traffic detected without corresponding DNS query: 106.69.178.185
Source: unknown TCP traffic detected without corresponding DNS query: 115.161.104.162
Source: unknown TCP traffic detected without corresponding DNS query: 106.47.23.97
Source: unknown TCP traffic detected without corresponding DNS query: 219.4.59.135
Source: unknown TCP traffic detected without corresponding DNS query: 174.139.227.61
Source: unknown TCP traffic detected without corresponding DNS query: 34.238.51.12
Source: unknown TCP traffic detected without corresponding DNS query: 59.158.82.69
Source: unknown TCP traffic detected without corresponding DNS query: 76.221.107.24
Source: unknown TCP traffic detected without corresponding DNS query: 254.12.40.195
Source: unknown TCP traffic detected without corresponding DNS query: 149.217.102.94
Source: unknown TCP traffic detected without corresponding DNS query: 34.83.195.61
Source: unknown TCP traffic detected without corresponding DNS query: 156.209.105.206
Source: unknown TCP traffic detected without corresponding DNS query: 84.130.242.217
Source: unknown TCP traffic detected without corresponding DNS query: 251.203.95.167
Source: unknown TCP traffic detected without corresponding DNS query: 174.222.198.54
Source: unknown TCP traffic detected without corresponding DNS query: 151.93.133.140
Source: unknown TCP traffic detected without corresponding DNS query: 200.13.225.62
Source: unknown TCP traffic detected without corresponding DNS query: 20.164.9.162
Source: unknown TCP traffic detected without corresponding DNS query: 68.43.215.206
Source: unknown TCP traffic detected without corresponding DNS query: 206.170.231.120
Source: unknown TCP traffic detected without corresponding DNS query: 12.100.204.54
Source: unknown TCP traffic detected without corresponding DNS query: 4.60.191.246
Source: unknown TCP traffic detected without corresponding DNS query: 169.243.126.16
Source: unknown TCP traffic detected without corresponding DNS query: 112.239.153.108
Source: unknown TCP traffic detected without corresponding DNS query: 46.29.115.207
Source: unknown TCP traffic detected without corresponding DNS query: 108.218.49.208
Source: unknown TCP traffic detected without corresponding DNS query: 86.223.22.234
Source: unknown TCP traffic detected without corresponding DNS query: 168.63.111.118
Source: unknown TCP traffic detected without corresponding DNS query: 186.1.143.255
Source: unknown TCP traffic detected without corresponding DNS query: 62.107.119.128
Source: unknown TCP traffic detected without corresponding DNS query: 196.19.118.175
Source: unknown TCP traffic detected without corresponding DNS query: 19.55.138.243
Source: unknown TCP traffic detected without corresponding DNS query: 85.233.145.94
Source: unknown TCP traffic detected without corresponding DNS query: 113.131.119.200
Source: unknown TCP traffic detected without corresponding DNS query: 185.239.191.105
Source: unknown TCP traffic detected without corresponding DNS query: 124.113.61.92
Source: unknown TCP traffic detected without corresponding DNS query: 142.38.96.65
Source: unknown TCP traffic detected without corresponding DNS query: 121.158.199.202
Source: unknown TCP traffic detected without corresponding DNS query: 177.169.199.12
Source: unknown TCP traffic detected without corresponding DNS query: 99.99.58.178
Source: ELF static info symbol of initial sample .symtab present: no
Source: classification engine Classification label: mal56.linELF@0/0@0/0
Source: /tmp/kkkmips.elf (PID: 5531) Queries kernel information via 'uname': Jump to behavior
Source: kkkmips.elf, 5531.1.0000558a580fc000.0000558a58183000.rw-.sdmp, kkkmips.elf, 5533.1.0000558a580fc000.0000558a58183000.rw-.sdmp, kkkmips.elf, 5538.1.0000558a580fc000.0000558a58183000.rw-.sdmp Binary or memory string: U!/etc/qemu-binfmt/mips
Source: kkkmips.elf, 5531.1.0000558a580fc000.0000558a58183000.rw-.sdmp, kkkmips.elf, 5533.1.0000558a580fc000.0000558a58183000.rw-.sdmp, kkkmips.elf, 5538.1.0000558a580fc000.0000558a58183000.rw-.sdmp Binary or memory string: /etc/qemu-binfmt/mips
Source: kkkmips.elf, 5531.1.00007fff2cae2000.00007fff2cb03000.rw-.sdmp, kkkmips.elf, 5533.1.00007fff2cae2000.00007fff2cb03000.rw-.sdmp, kkkmips.elf, 5538.1.00007fff2cae2000.00007fff2cb03000.rw-.sdmp Binary or memory string: /usr/bin/qemu-mips
Source: kkkmips.elf, 5531.1.00007fff2cae2000.00007fff2cb03000.rw-.sdmp, kkkmips.elf, 5533.1.00007fff2cae2000.00007fff2cb03000.rw-.sdmp, kkkmips.elf, 5538.1.00007fff2cae2000.00007fff2cb03000.rw-.sdmp Binary or memory string: Xx86_64/usr/bin/qemu-mips/tmp/kkkmips.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/kkkmips.elf
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs