Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
131350528.pdf

Overview

General Information

Sample name:131350528.pdf
Analysis ID:1562126
MD5:0f9fd8e0a5053509bddd66b2947a2576
SHA1:c611ab1e22a0877c776e74cfd2bb0936a23bca1a
SHA256:cede25c03d9edaaf64adeb65e023bdce37b502883948600b80ce6e009f0c2d92
Infos:

Detection

Score:2
Range:0 - 100
Whitelisted:false

Signatures

Creates hidden files and/or directories
Document contains embedded VBA macros
Document misses a certain OLE stream usually present in this Microsoft Office document type
Executes the "rm" command used to delete files or directories
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1562126
Start date and time:2024-11-25 08:36:03 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 5m 5s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:131350528.pdf
Detection:CLEAN
Classification:clean2.linPDF@0/2@0/0
  • VT rate limit hit for: 131350528.pdf
Command:sudo -u saturnino xdg-open "/tmp/131350528.pdf"
PID:6250
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:

Standard Error:
  • system is lnxubuntu20
  • exo-open (PID: 6266, Parent: 6251, MD5: 60a307a6a6325e2034eb5cc56bff1abd) Arguments: exo-open /tmp/131350528.pdf
    • exo-open New Fork (PID: 6268, Parent: 6266)
    • dbus-launch (PID: 6268, Parent: 6266, MD5: 0b22a45154a51c6121bb1d208d8ab203) Arguments: dbus-launch --autolaunch=ee49dfd4fa47433baee88884e2d7de7c --binary-syntax --close-stderr
    • exo-open New Fork (PID: 6270, Parent: 6266)
      • exo-open New Fork (PID: 6271, Parent: 6270)
      • sh (PID: 6271, Parent: 1860, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh evince /tmp/131350528.pdf
      • evince (PID: 6271, Parent: 1860, MD5: 3b2e161f515da97cbd986ec82e935859) Arguments: evince /tmp/131350528.pdf
        • evince New Fork (PID: 6274, Parent: 6271)
        • dbus-launch (PID: 6274, Parent: 6271, MD5: 0b22a45154a51c6121bb1d208d8ab203) Arguments: dbus-launch --autolaunch=ee49dfd4fa47433baee88884e2d7de7c --binary-syntax --close-stderr
  • dash New Fork (PID: 6227, Parent: 4332)
  • rm (PID: 6227, Parent: 4332, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.XDXaw8psax /tmp/tmp.RIRhJt6zeB /tmp/tmp.qSXKvcdNkz
  • dash New Fork (PID: 6228, Parent: 4332)
  • rm (PID: 6228, Parent: 4332, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.XDXaw8psax /tmp/tmp.RIRhJt6zeB /tmp/tmp.qSXKvcdNkz
  • cleanup
No yara matches
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: unknownTCP traffic detected without corresponding DNS query: 54.171.230.55
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: recently-used.xbel.JJN4X2.45.drString found in binary or memory: http://freedesktop.org
Source: recently-used.xbel.JJN4X2.45.drString found in binary or memory: http://www.freedesktop.org/standards/desktop-bookmarks
Source: recently-used.xbel.JJN4X2.45.drString found in binary or memory: http://www.freedesktop.org/standards/shared-mime-info
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 33606
Source: unknownNetwork traffic detected: HTTP traffic on port 33606 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443
Source: recently-used.xbel.JJN4X2.45.drOLE indicator, VBA macros: true
Source: recently-used.xbel.JJN4X2.45.drOLE stream indicators for Word, Excel, PowerPoint, and Visio: all false
Source: classification engineClassification label: clean2.linPDF@0/2@0/0
Source: /usr/bin/exo-open (PID: 6266)Directory: /home/saturnino/.Xdefaults-galassiaJump to behavior
Source: /usr/bin/exo-open (PID: 6266)Directory: /home/saturnino/.cacheJump to behavior
Source: /usr/bin/evince (PID: 6271)Directory: /home/saturnino/.Xdefaults-galassiaJump to behavior
Source: /usr/bin/evince (PID: 6271)Directory: /usr/share/fonts/.uuidJump to behavior
Source: /usr/bin/evince (PID: 6271)Directory: /usr/local/share/fonts/.uuidJump to behavior
Source: /usr/bin/evince (PID: 6271)Directory: /home/saturnino/.local/share/fonts/.uuidJump to behavior
Source: /usr/bin/evince (PID: 6271)Directory: /home/saturnino/.fonts/.uuidJump to behavior
Source: /usr/bin/evince (PID: 6271)Directory: /usr/share/fonts/X11/.uuidJump to behavior
Source: /usr/bin/evince (PID: 6271)Directory: /usr/share/fonts/cMap/.uuidJump to behavior
Source: /usr/bin/evince (PID: 6271)Directory: /usr/share/fonts/cmap/.uuidJump to behavior
Source: /usr/bin/evince (PID: 6271)Directory: /usr/share/fonts/opentype/.uuidJump to behavior
Source: /usr/bin/evince (PID: 6271)Directory: /usr/share/fonts/truetype/.uuidJump to behavior
Source: /usr/bin/evince (PID: 6271)Directory: /usr/share/fonts/type1/.uuidJump to behavior
Source: /usr/bin/evince (PID: 6271)Directory: /usr/share/fonts/X11/Type1/.uuidJump to behavior
Source: /usr/bin/evince (PID: 6271)Directory: /usr/share/fonts/X11/encodings/.uuidJump to behavior
Source: /usr/bin/evince (PID: 6271)Directory: /usr/share/fonts/X11/misc/.uuidJump to behavior
Source: /usr/bin/evince (PID: 6271)Directory: /usr/share/fonts/X11/util/.uuidJump to behavior
Source: /usr/bin/evince (PID: 6271)Directory: /usr/share/fonts/cmap/adobe-cns1/.uuidJump to behavior
Source: /usr/bin/evince (PID: 6271)Directory: /usr/share/fonts/cmap/adobe-gb1/.uuidJump to behavior
Source: /usr/bin/evince (PID: 6271)Directory: /usr/share/fonts/cmap/adobe-japan1/.uuidJump to behavior
Source: /usr/bin/evince (PID: 6271)Directory: /usr/share/fonts/cmap/adobe-japan2/.uuidJump to behavior
Source: /usr/bin/evince (PID: 6271)Directory: /usr/share/fonts/cmap/adobe-korea1/.uuidJump to behavior
Source: /usr/bin/evince (PID: 6271)Directory: /usr/share/fonts/opentype/malayalam/.uuidJump to behavior
Source: /usr/bin/evince (PID: 6271)Directory: /usr/share/fonts/opentype/mathjax/.uuidJump to behavior
Source: /usr/bin/evince (PID: 6271)Directory: /usr/share/fonts/opentype/noto/.uuidJump to behavior
Source: /usr/bin/evince (PID: 6271)Directory: /usr/share/fonts/opentype/urw-base35/.uuidJump to behavior
Source: /usr/bin/evince (PID: 6271)Directory: /usr/share/fonts/truetype/Gargi/.uuidJump to behavior
Source: /usr/bin/evince (PID: 6271)Directory: /usr/share/fonts/truetype/Gubbi/.uuidJump to behavior
Source: /usr/bin/evince (PID: 6271)Directory: /usr/share/fonts/truetype/Nakula/.uuidJump to behavior
Source: /usr/bin/evince (PID: 6271)Directory: /usr/share/fonts/truetype/Navilu/.uuidJump to behavior
Source: /usr/bin/evince (PID: 6271)Directory: /usr/share/fonts/truetype/Sahadeva/.uuidJump to behavior
Source: /usr/bin/evince (PID: 6271)Directory: /usr/share/fonts/truetype/Sarai/.uuidJump to behavior
Source: /usr/bin/evince (PID: 6271)Directory: /usr/share/fonts/truetype/abyssinica/.uuidJump to behavior
Source: /usr/bin/evince (PID: 6271)Directory: /usr/share/fonts/truetype/ancient-scripts/.uuidJump to behavior
Source: /usr/bin/evince (PID: 6271)Directory: /usr/share/fonts/truetype/dejavu/.uuidJump to behavior
Source: /usr/bin/evince (PID: 6271)Directory: /usr/share/fonts/truetype/droid/.uuidJump to behavior
Source: /usr/bin/evince (PID: 6271)Directory: /usr/share/fonts/truetype/fonts-beng-extra/.uuidJump to behavior
Source: /usr/bin/evince (PID: 6271)Directory: /usr/share/fonts/truetype/fonts-deva-extra/.uuidJump to behavior
Source: /usr/bin/evince (PID: 6271)Directory: /usr/share/fonts/truetype/fonts-gujr-extra/.uuidJump to behavior
Source: /usr/bin/evince (PID: 6271)Directory: /usr/share/fonts/truetype/fonts-guru-extra/.uuidJump to behavior
Source: /usr/bin/evince (PID: 6271)Directory: /usr/share/fonts/truetype/fonts-kalapi/.uuidJump to behavior
Source: /usr/bin/evince (PID: 6271)Directory: /usr/share/fonts/truetype/fonts-orya-extra/.uuidJump to behavior
Source: /usr/bin/evince (PID: 6271)Directory: /usr/share/fonts/truetype/fonts-telu-extra/.uuidJump to behavior
Source: /usr/bin/evince (PID: 6271)Directory: /usr/share/fonts/truetype/fonts-yrsa-rasa/.uuidJump to behavior
Source: /usr/bin/evince (PID: 6271)Directory: /usr/share/fonts/truetype/freefont/.uuidJump to behavior
Source: /usr/bin/evince (PID: 6271)Directory: /usr/share/fonts/truetype/kacst/.uuidJump to behavior
Source: /usr/bin/evince (PID: 6271)Directory: /usr/share/fonts/truetype/kacst-one/.uuidJump to behavior
Source: /usr/bin/evince (PID: 6271)Directory: /usr/share/fonts/truetype/lao/.uuidJump to behavior
Source: /usr/bin/evince (PID: 6271)Directory: /usr/share/fonts/truetype/lato/.uuidJump to behavior
Source: /usr/bin/evince (PID: 6271)Directory: /usr/share/fonts/truetype/liberation/.uuidJump to behavior
Source: /usr/bin/evince (PID: 6271)Directory: /usr/share/fonts/truetype/liberation2/.uuidJump to behavior
Source: /usr/bin/evince (PID: 6271)Directory: /usr/share/fonts/truetype/lohit-assamese/.uuidJump to behavior
Source: /usr/bin/evince (PID: 6271)Directory: /usr/share/fonts/truetype/lohit-bengali/.uuidJump to behavior
Source: /usr/bin/evince (PID: 6271)Directory: /usr/share/fonts/truetype/lohit-devanagari/.uuidJump to behavior
Source: /usr/bin/evince (PID: 6271)Directory: /usr/share/fonts/truetype/lohit-gujarati/.uuidJump to behavior
Source: /usr/bin/evince (PID: 6271)Directory: /usr/share/fonts/truetype/lohit-kannada/.uuidJump to behavior
Source: /usr/bin/evince (PID: 6271)Directory: /usr/share/fonts/truetype/lohit-malayalam/.uuidJump to behavior
Source: /usr/bin/evince (PID: 6271)Directory: /usr/share/fonts/truetype/lohit-oriya/.uuidJump to behavior
Source: /usr/bin/evince (PID: 6271)Directory: /usr/share/fonts/truetype/lohit-punjabi/.uuidJump to behavior
Source: /usr/bin/evince (PID: 6271)Directory: /usr/share/fonts/truetype/lohit-tamil/.uuidJump to behavior
Source: /usr/bin/evince (PID: 6271)Directory: /usr/share/fonts/truetype/lohit-tamil-classical/.uuidJump to behavior
Source: /usr/bin/evince (PID: 6271)Directory: /usr/share/fonts/truetype/lohit-telugu/.uuidJump to behavior
Source: /usr/bin/evince (PID: 6271)Directory: /usr/share/fonts/truetype/malayalam/.uuidJump to behavior
Source: /usr/bin/evince (PID: 6271)Directory: /usr/share/fonts/truetype/noto/.uuidJump to behavior
Source: /usr/bin/evince (PID: 6271)Directory: /usr/share/fonts/truetype/openoffice/.uuidJump to behavior
Source: /usr/bin/evince (PID: 6271)Directory: /usr/share/fonts/truetype/padauk/.uuidJump to behavior
Source: /usr/bin/evince (PID: 6271)Directory: /usr/share/fonts/truetype/pagul/.uuidJump to behavior
Source: /usr/bin/evince (PID: 6271)Directory: /usr/share/fonts/truetype/samyak/.uuidJump to behavior
Source: /usr/bin/evince (PID: 6271)Directory: /usr/share/fonts/truetype/samyak-fonts/.uuidJump to behavior
Source: /usr/bin/evince (PID: 6271)Directory: /usr/share/fonts/truetype/sinhala/.uuidJump to behavior
Source: /usr/bin/evince (PID: 6271)Directory: /usr/share/fonts/truetype/tibetan-machine/.uuidJump to behavior
Source: /usr/bin/evince (PID: 6271)Directory: /usr/share/fonts/truetype/tlwg/.uuidJump to behavior
Source: /usr/bin/evince (PID: 6271)Directory: /usr/share/fonts/truetype/ttf-khmeros-core/.uuidJump to behavior
Source: /usr/bin/evince (PID: 6271)Directory: /usr/share/fonts/truetype/ubuntu/.uuidJump to behavior
Source: /usr/bin/evince (PID: 6271)Directory: /usr/share/fonts/type1/urw-base35/.uuidJump to behavior
Source: /usr/bin/evince (PID: 6271)Directory: /usr/share/fonts/X11/encodings/large/.uuidJump to behavior
Source: /usr/bin/evince (PID: 6271)Directory: /home/saturnino/.cacheJump to behavior
Source: /usr/bin/dash (PID: 6227)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.XDXaw8psax /tmp/tmp.RIRhJt6zeB /tmp/tmp.qSXKvcdNkzJump to behavior
Source: /usr/bin/dash (PID: 6228)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.XDXaw8psax /tmp/tmp.RIRhJt6zeB /tmp/tmp.qSXKvcdNkzJump to behavior
Source: /usr/bin/exo-open (PID: 6266)Queries kernel information via 'uname': Jump to behavior
Source: /usr/bin/dbus-launch (PID: 6268)Queries kernel information via 'uname': Jump to behavior
Source: /usr/bin/evince (PID: 6271)Queries kernel information via 'uname': Jump to behavior
Source: /usr/bin/dbus-launch (PID: 6274)Queries kernel information via 'uname': Jump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity Information1
Scripting
Valid AccountsWindows Management Instrumentation1
Scripting
Path Interception1
Hidden Files and Directories
OS Credential Dumping1
Security Software Discovery
Remote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
File Deletion
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1562126 Sample: 131350528.pdf Startdate: 25/11/2024 Architecture: LINUX Score: 2 22 109.202.202.202, 80 INIT7CH Switzerland 2->22 24 91.189.91.42, 443 CANONICAL-ASGB United Kingdom 2->24 26 2 other IPs or domains 2->26 8 exo-open 2->8         started        10 dash rm 2->10         started        12 dash rm 2->12         started        process3 process4 14 exo-open 8->14         started        16 exo-open dbus-launch 8->16         started        process5 18 exo-open sh evince 14->18         started        process6 20 evince dbus-launch 18->20         started       

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
131350528.pdf0%ReversingLabs
No Antivirus matches
No Antivirus matches
No Antivirus matches
No contacted domains info
NameSourceMaliciousAntivirus DetectionReputation
http://www.freedesktop.org/standards/desktop-bookmarksrecently-used.xbel.JJN4X2.45.drfalse
    high
    http://www.freedesktop.org/standards/shared-mime-inforecently-used.xbel.JJN4X2.45.drfalse
      high
      http://freedesktop.orgrecently-used.xbel.JJN4X2.45.drfalse
        high
        • No. of IPs < 25%
        • 25% < No. of IPs < 50%
        • 50% < No. of IPs < 75%
        • 75% < No. of IPs
        IPDomainCountryFlagASNASN NameMalicious
        54.171.230.55
        unknownUnited States
        16509AMAZON-02USfalse
        109.202.202.202
        unknownSwitzerland
        13030INIT7CHfalse
        91.189.91.43
        unknownUnited Kingdom
        41231CANONICAL-ASGBfalse
        91.189.91.42
        unknownUnited Kingdom
        41231CANONICAL-ASGBfalse
        MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
        54.171.230.55pXdN91.armv5l.elfGet hashmaliciousMirai, GafgytBrowse
          pXdN91.mips.elfGet hashmaliciousMirai, GafgytBrowse
            bin.sh.elfGet hashmaliciousMiraiBrowse
              bot.mips.elfGet hashmaliciousMirai, Gafgyt, OkiruBrowse
                wheiuwa4.elfGet hashmaliciousUnknownBrowse
                  wheiuwa4.elfGet hashmaliciousUnknownBrowse
                    x86.elfGet hashmaliciousUnknownBrowse
                      hidakibest.arm4.elfGet hashmaliciousGafgyt, MiraiBrowse
                        arm.elfGet hashmaliciousUnknownBrowse
                          main_ppc.elfGet hashmaliciousMiraiBrowse
                            109.202.202.202kpLwzBouH4.elfGet hashmaliciousUnknownBrowse
                            • ch.archive.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_92.0%2bbuild3-0ubuntu0.20.04.1_amd64.deb
                            91.189.91.43pXdN91.armv5l.elfGet hashmaliciousMirai, GafgytBrowse
                              pXdN91.mips.elfGet hashmaliciousMirai, GafgytBrowse
                                Mozi.a.elfGet hashmaliciousUnknownBrowse
                                  bin.sh.elfGet hashmaliciousMiraiBrowse
                                    vqsjh4.elfGet hashmaliciousMiraiBrowse
                                      vkjqpc.elfGet hashmaliciousUnknownBrowse
                                        dwhdbg.elfGet hashmaliciousUnknownBrowse
                                          sshd.elfGet hashmaliciousUnknownBrowse
                                            bin.sh.elfGet hashmaliciousMiraiBrowse
                                              x86_64.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                91.189.91.42pXdN91.armv5l.elfGet hashmaliciousMirai, GafgytBrowse
                                                  pXdN91.mips.elfGet hashmaliciousMirai, GafgytBrowse
                                                    Mozi.a.elfGet hashmaliciousUnknownBrowse
                                                      bin.sh.elfGet hashmaliciousMiraiBrowse
                                                        vqsjh4.elfGet hashmaliciousMiraiBrowse
                                                          vkjqpc.elfGet hashmaliciousUnknownBrowse
                                                            dwhdbg.elfGet hashmaliciousUnknownBrowse
                                                              sshd.elfGet hashmaliciousUnknownBrowse
                                                                bin.sh.elfGet hashmaliciousMiraiBrowse
                                                                  x86_64.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                                    No context
                                                                    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                    CANONICAL-ASGBpXdN91.armv4l.elfGet hashmaliciousMirai, GafgytBrowse
                                                                    • 185.125.190.26
                                                                    pXdN91.armv5l.elfGet hashmaliciousMirai, GafgytBrowse
                                                                    • 91.189.91.42
                                                                    pXdN91.mips.elfGet hashmaliciousMirai, GafgytBrowse
                                                                    • 91.189.91.42
                                                                    Mozi.a.elfGet hashmaliciousUnknownBrowse
                                                                    • 91.189.91.42
                                                                    bin.sh.elfGet hashmaliciousMiraiBrowse
                                                                    • 91.189.91.42
                                                                    vqsjh4.elfGet hashmaliciousMiraiBrowse
                                                                    • 91.189.91.42
                                                                    vkjqpc.elfGet hashmaliciousUnknownBrowse
                                                                    • 91.189.91.42
                                                                    dwhdbg.elfGet hashmaliciousUnknownBrowse
                                                                    • 91.189.91.42
                                                                    sshd.elfGet hashmaliciousUnknownBrowse
                                                                    • 91.189.91.42
                                                                    bin.sh.elfGet hashmaliciousMiraiBrowse
                                                                    • 91.189.91.42
                                                                    CANONICAL-ASGBpXdN91.armv4l.elfGet hashmaliciousMirai, GafgytBrowse
                                                                    • 185.125.190.26
                                                                    pXdN91.armv5l.elfGet hashmaliciousMirai, GafgytBrowse
                                                                    • 91.189.91.42
                                                                    pXdN91.mips.elfGet hashmaliciousMirai, GafgytBrowse
                                                                    • 91.189.91.42
                                                                    Mozi.a.elfGet hashmaliciousUnknownBrowse
                                                                    • 91.189.91.42
                                                                    bin.sh.elfGet hashmaliciousMiraiBrowse
                                                                    • 91.189.91.42
                                                                    vqsjh4.elfGet hashmaliciousMiraiBrowse
                                                                    • 91.189.91.42
                                                                    vkjqpc.elfGet hashmaliciousUnknownBrowse
                                                                    • 91.189.91.42
                                                                    dwhdbg.elfGet hashmaliciousUnknownBrowse
                                                                    • 91.189.91.42
                                                                    sshd.elfGet hashmaliciousUnknownBrowse
                                                                    • 91.189.91.42
                                                                    bin.sh.elfGet hashmaliciousMiraiBrowse
                                                                    • 91.189.91.42
                                                                    AMAZON-02USpXdN91.armv5l.elfGet hashmaliciousMirai, GafgytBrowse
                                                                    • 54.171.230.55
                                                                    pXdN91.mips.elfGet hashmaliciousMirai, GafgytBrowse
                                                                    • 54.171.230.55
                                                                    file (1).txt.batGet hashmaliciousUnknownBrowse
                                                                    • 18.181.154.24
                                                                    startup.txt.batGet hashmaliciousUnknownBrowse
                                                                    • 18.181.154.24
                                                                    run.txt.batGet hashmaliciousUnknownBrowse
                                                                    • 18.181.154.24
                                                                    9758xBqgE1azKnB.exeGet hashmaliciousXWormBrowse
                                                                    • 18.181.154.24
                                                                    file.exeGet hashmaliciousAmadey, LummaC Stealer, Stealc, VidarBrowse
                                                                    • 18.239.168.24
                                                                    file.exeGet hashmaliciousCredential FlusherBrowse
                                                                    • 108.158.75.108
                                                                    file.exeGet hashmaliciousAmadey, Stealc, VidarBrowse
                                                                    • 3.167.152.14
                                                                    https://clever-photos-686127.framer.app/Get hashmaliciousUnknownBrowse
                                                                    • 108.158.75.21
                                                                    INIT7CHpXdN91.armv5l.elfGet hashmaliciousMirai, GafgytBrowse
                                                                    • 109.202.202.202
                                                                    pXdN91.mips.elfGet hashmaliciousMirai, GafgytBrowse
                                                                    • 109.202.202.202
                                                                    Mozi.a.elfGet hashmaliciousUnknownBrowse
                                                                    • 109.202.202.202
                                                                    bin.sh.elfGet hashmaliciousMiraiBrowse
                                                                    • 109.202.202.202
                                                                    vqsjh4.elfGet hashmaliciousMiraiBrowse
                                                                    • 109.202.202.202
                                                                    vkjqpc.elfGet hashmaliciousUnknownBrowse
                                                                    • 109.202.202.202
                                                                    dwhdbg.elfGet hashmaliciousUnknownBrowse
                                                                    • 109.202.202.202
                                                                    sshd.elfGet hashmaliciousUnknownBrowse
                                                                    • 109.202.202.202
                                                                    bin.sh.elfGet hashmaliciousMiraiBrowse
                                                                    • 109.202.202.202
                                                                    x86_64.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                                    • 109.202.202.202
                                                                    No context
                                                                    No context
                                                                    Process:/usr/bin/evince
                                                                    File Type:very short file (no magic)
                                                                    Category:dropped
                                                                    Size (bytes):1
                                                                    Entropy (8bit):0.0
                                                                    Encrypted:false
                                                                    SSDEEP:3::
                                                                    MD5:93B885ADFE0DA089CDF634904FD59F71
                                                                    SHA1:5BA93C9DB0CFF93F52B521D7420E43F6EDA2784F
                                                                    SHA-256:6E340B9CFFB37A989CA544E6BB780A2C78901D3FB33738768511A30617AFA01D
                                                                    SHA-512:B8244D028981D693AF7B456AF8EFA4CAD63D282E19FF14942C246E50D9351D22704A802A71C3580B6370DE4CEB293C324A8423342557D4E5C38438F0E36910EE
                                                                    Malicious:false
                                                                    Reputation:high, very likely benign file
                                                                    Preview:.
                                                                    Process:/usr/bin/evince
                                                                    File Type:XML 1.0 document, ASCII text
                                                                    Category:dropped
                                                                    Size (bytes):702
                                                                    Entropy (8bit):5.11120528597766
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdE2J9kLS3ROBQkLSjE7vfCFTbjpmJtnLRVHZlEweKwxh9XyB/bxwR+we7x+0l:2dEm3RJVjAaV4JtVV5Kh9CB/gEdZb
                                                                    MD5:853FBB65F3C6D0FF1234FB4987EF9BD3
                                                                    SHA1:08BB1351438A87EAF214F55E144FD62659557E08
                                                                    SHA-256:A5F92B95D44D994021CDBE2920C21FD2D1E7FD259F75ECCE7AE3715DE1C8E4A7
                                                                    SHA-512:AF55BD7A320BE02153B61A0DC49F1558A892DD5CFD8216C6F1B27377BD7703117396587E8845EE321CA2D0A4491868EEB2AC0B5FB43858E20BDAA70477CA21EA
                                                                    Malicious:false
                                                                    Reputation:low
                                                                    Preview:<?xml version="1.0" encoding="UTF-8"?>.<xbel version="1.0". xmlns:bookmark="http://www.freedesktop.org/standards/desktop-bookmarks". xmlns:mime="http://www.freedesktop.org/standards/shared-mime-info".>. <bookmark href="file:///tmp/131350528.pdf" added="2024-11-25T07:36:54Z" modified="2024-11-25T07:36:54Z" visited="1969-12-31T23:59:59Z">. <info>. <metadata owner="http://freedesktop.org">. <mime:mime-type type="application/pdf"/>. <bookmark:applications>. <bookmark:application name="Document Viewer" exec="&apos;evince %u&apos;" modified="2024-11-25T07:36:54Z" count="1"/>. </bookmark:applications>. </metadata>. </info>. </bookmark>.</xbel>
                                                                    File type:PDF document, version 1.7 (zip deflate encoded)
                                                                    Entropy (8bit):7.966571972716478
                                                                    TrID:
                                                                    • Adobe Portable Document Format (5005/1) 100.00%
                                                                    File name:131350528.pdf
                                                                    File size:392'735 bytes
                                                                    MD5:0f9fd8e0a5053509bddd66b2947a2576
                                                                    SHA1:c611ab1e22a0877c776e74cfd2bb0936a23bca1a
                                                                    SHA256:cede25c03d9edaaf64adeb65e023bdce37b502883948600b80ce6e009f0c2d92
                                                                    SHA512:6fc2076c3c42562677bae4be4fe78f37bd87b934d909af843bc68c66dbb410c008a792e7eea8c1110a68b974ee49bbebd8ca44307afe7dc41c7670a0e2aeb554
                                                                    SSDEEP:6144:TD7ik1xrAYTHXQDYfNb9Y3CKqat+SLUU9hJ8vx9c/QhhcL+QBcddHzUlBpNJpM:T/L/TEDPSKqat9LTqM4hCmd2TJpM
                                                                    TLSH:6484235F0256CC67C09F5C7456BDB24BBAD384B21887A1663B0C894BD70CFA3789EA17
                                                                    File Content Preview:%PDF-1.7.%......25 0 obj.<</Linearized 1/L 392736/O 27/E 153207/N 2/T 392383/H [ 516 239]>>.endobj. ..49 0 obj.<</DecodeParms<</Columns 5/Predictor 12>>/Filter/FlateDecode/ID[<8BA3753F03F9355DF7D0AF23264481D9><D0CF8C85E5D52B44A5C08F0955CE2CC

                                                                    General

                                                                    Header:%PDF-1.7
                                                                    Total Entropy:7.966572
                                                                    Total Bytes:392735
                                                                    Stream Entropy:7.972481
                                                                    Stream Bytes:385823
                                                                    Entropy outside Streams:5.335201
                                                                    Bytes outside Streams:6912
                                                                    Number of EOF found:2
                                                                    Bytes after EOF:
                                                                    NameCount
                                                                    obj44
                                                                    endobj44
                                                                    stream40
                                                                    endstream40
                                                                    xref0
                                                                    trailer0
                                                                    startxref2
                                                                    /Page2
                                                                    /Encrypt0
                                                                    /ObjStm6
                                                                    /URI0
                                                                    /JS0
                                                                    /JavaScript0
                                                                    /AA0
                                                                    /OpenAction0
                                                                    /AcroForm0
                                                                    /JBIG2Decode0
                                                                    /RichMedia0
                                                                    /Launch0
                                                                    /EmbeddedFile0

                                                                    Image Streams

                                                                    IDDHASHMD5Preview
                                                                    39000000000000000088faecb1ced8d491f8e4c8e931f4c02e
                                                                    3207070c8d3a440d0b4987d174d53427f04e0170e61d4784a
                                                                    4627170c8d3a440d4ed6b7f445a5a494fee411ea3bff3311c
                                                                    6a9a8c4e868e1e4488f294d884d24c67d14a566d2d348d737
                                                                    7a9acc4ec78e3e440490e770140a223e29248af362f1a358c
                                                                    TimestampSource PortDest PortSource IPDest IP
                                                                    Nov 25, 2024 08:36:47.117336035 CET4433360654.171.230.55192.168.2.23
                                                                    Nov 25, 2024 08:36:47.117654085 CET33606443192.168.2.2354.171.230.55
                                                                    Nov 25, 2024 08:36:47.237145901 CET4433360654.171.230.55192.168.2.23
                                                                    Nov 25, 2024 08:36:47.833228111 CET43928443192.168.2.2391.189.91.42
                                                                    Nov 25, 2024 08:36:53.460444927 CET42836443192.168.2.2391.189.91.43
                                                                    Nov 25, 2024 08:36:54.740293026 CET4251680192.168.2.23109.202.202.202
                                                                    Nov 25, 2024 08:37:08.306536913 CET43928443192.168.2.2391.189.91.42
                                                                    Nov 25, 2024 08:37:20.592958927 CET42836443192.168.2.2391.189.91.43
                                                                    Nov 25, 2024 08:37:24.688365936 CET4251680192.168.2.23109.202.202.202
                                                                    Nov 25, 2024 08:37:49.260907888 CET43928443192.168.2.2391.189.91.42

                                                                    System Behavior

                                                                    Start time (UTC):07:36:48
                                                                    Start date (UTC):25/11/2024
                                                                    Path:/usr/bin/exo-open
                                                                    Arguments:exo-open /tmp/131350528.pdf
                                                                    File size:27264 bytes
                                                                    MD5 hash:60a307a6a6325e2034eb5cc56bff1abd

                                                                    Start time (UTC):07:36:49
                                                                    Start date (UTC):25/11/2024
                                                                    Path:/usr/bin/exo-open
                                                                    Arguments:-
                                                                    File size:27264 bytes
                                                                    MD5 hash:60a307a6a6325e2034eb5cc56bff1abd

                                                                    Start time (UTC):07:36:49
                                                                    Start date (UTC):25/11/2024
                                                                    Path:/usr/bin/dbus-launch
                                                                    Arguments:dbus-launch --autolaunch=ee49dfd4fa47433baee88884e2d7de7c --binary-syntax --close-stderr
                                                                    File size:34960 bytes
                                                                    MD5 hash:0b22a45154a51c6121bb1d208d8ab203

                                                                    Start time (UTC):07:36:49
                                                                    Start date (UTC):25/11/2024
                                                                    Path:/usr/bin/exo-open
                                                                    Arguments:-
                                                                    File size:27264 bytes
                                                                    MD5 hash:60a307a6a6325e2034eb5cc56bff1abd

                                                                    Start time (UTC):07:36:49
                                                                    Start date (UTC):25/11/2024
                                                                    Path:/usr/bin/exo-open
                                                                    Arguments:-
                                                                    File size:27264 bytes
                                                                    MD5 hash:60a307a6a6325e2034eb5cc56bff1abd

                                                                    Start time (UTC):07:36:49
                                                                    Start date (UTC):25/11/2024
                                                                    Path:/bin/sh
                                                                    Arguments:/bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh evince /tmp/131350528.pdf
                                                                    File size:129816 bytes
                                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                    Start time (UTC):07:36:49
                                                                    Start date (UTC):25/11/2024
                                                                    Path:/usr/bin/evince
                                                                    Arguments:evince /tmp/131350528.pdf
                                                                    File size:482984 bytes
                                                                    MD5 hash:3b2e161f515da97cbd986ec82e935859

                                                                    Start time (UTC):07:36:50
                                                                    Start date (UTC):25/11/2024
                                                                    Path:/usr/bin/evince
                                                                    Arguments:-
                                                                    File size:482984 bytes
                                                                    MD5 hash:3b2e161f515da97cbd986ec82e935859

                                                                    Start time (UTC):07:36:50
                                                                    Start date (UTC):25/11/2024
                                                                    Path:/usr/bin/dbus-launch
                                                                    Arguments:dbus-launch --autolaunch=ee49dfd4fa47433baee88884e2d7de7c --binary-syntax --close-stderr
                                                                    File size:34960 bytes
                                                                    MD5 hash:0b22a45154a51c6121bb1d208d8ab203

                                                                    Start time (UTC):07:36:46
                                                                    Start date (UTC):25/11/2024
                                                                    Path:/usr/bin/dash
                                                                    Arguments:-
                                                                    File size:129816 bytes
                                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                    Start time (UTC):07:36:46
                                                                    Start date (UTC):25/11/2024
                                                                    Path:/usr/bin/rm
                                                                    Arguments:rm -f /tmp/tmp.XDXaw8psax /tmp/tmp.RIRhJt6zeB /tmp/tmp.qSXKvcdNkz
                                                                    File size:72056 bytes
                                                                    MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b

                                                                    Start time (UTC):07:36:46
                                                                    Start date (UTC):25/11/2024
                                                                    Path:/usr/bin/dash
                                                                    Arguments:-
                                                                    File size:129816 bytes
                                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                    Start time (UTC):07:36:46
                                                                    Start date (UTC):25/11/2024
                                                                    Path:/usr/bin/rm
                                                                    Arguments:rm -f /tmp/tmp.XDXaw8psax /tmp/tmp.RIRhJt6zeB /tmp/tmp.qSXKvcdNkz
                                                                    File size:72056 bytes
                                                                    MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b