Analysis
-
max time kernel
149s -
max time network
150s -
platform
ubuntu-22.04_amd64 -
resource
ubuntu2204-amd64-20240611-en -
resource tags
arch:amd64arch:i386image:ubuntu2204-amd64-20240611-enkernel:5.15.0-105-genericlocale:en-usos:ubuntu-22.04-amd64system -
submitted
05-07-2024 01:32
General
-
Target
8ae443a654bc16b4d8a852bb72522a2ba347759ab21e6140c7b3532921d48053.elf
-
Size
39KB
-
MD5
92a2b83619fc41e25e83001bba55d561
-
SHA1
0648b9d8027f93c5ac98a67f22ac967c83512910
-
SHA256
8ae443a654bc16b4d8a852bb72522a2ba347759ab21e6140c7b3532921d48053
-
SHA512
aad7b7fcb5a655443f7e09414ebc9793d6c49d6b23c7a2a003361c377e0433b33ecda47bc256947428bc02ee397207395dae0920a2ee98cd172418cccb9285be
-
SSDEEP
768:kytOyBufBP7Gh2Lua+2bMlc6UKSOhnbcuyD7UVQRjEb/Z6TRtc9+:ntVMf+BnKcnouy8VyaBKRC9+
Malware Config
Extracted
mirai
LZRD
Signatures
-
Contacts a large (20530) amount of remote hosts 1 TTPs
This may indicate a network scan to discover remotely running services.
-
Creates a large amount of network flows 1 TTPs
This may indicate a network scan to discover remotely running services.
-
Modifies Watchdog functionality 1 TTPs 2 IoCs
Malware like Mirai modifies the Watchdog to prevent it restarting an infected system.
Processes:
8ae443a654bc16b4d8a852bb72522a2ba347759ab21e6140c7b3532921d48053.elfdescription ioc process File opened for modification /dev/watchdog 8ae443a654bc16b4d8a852bb72522a2ba347759ab21e6140c7b3532921d48053.elf File opened for modification /dev/misc/watchdog 8ae443a654bc16b4d8a852bb72522a2ba347759ab21e6140c7b3532921d48053.elf -
Enumerates active TCP sockets 1 TTPs 1 IoCs
Gets active TCP sockets from /proc virtual filesystem.
Processes:
8ae443a654bc16b4d8a852bb72522a2ba347759ab21e6140c7b3532921d48053.elfdescription ioc process File opened for reading /proc/net/tcp 8ae443a654bc16b4d8a852bb72522a2ba347759ab21e6140c7b3532921d48053.elf -
Enumerates running processes
Discovers information about currently running processes on the system
-
Reads system network configuration 1 TTPs 1 IoCs
Uses contents of /proc filesystem to enumerate network settings.
Processes:
8ae443a654bc16b4d8a852bb72522a2ba347759ab21e6140c7b3532921d48053.elfdescription ioc process File opened for reading /proc/net/tcp 8ae443a654bc16b4d8a852bb72522a2ba347759ab21e6140c7b3532921d48053.elf -
Reads runtime system information 64 IoCs
Reads data from /proc virtual filesystem.
Processes:
8ae443a654bc16b4d8a852bb72522a2ba347759ab21e6140c7b3532921d48053.elfdescription ioc process File opened for reading /proc/633/fd 8ae443a654bc16b4d8a852bb72522a2ba347759ab21e6140c7b3532921d48053.elf File opened for reading /proc/630/exe 8ae443a654bc16b4d8a852bb72522a2ba347759ab21e6140c7b3532921d48053.elf File opened for reading /proc/1359/exe 8ae443a654bc16b4d8a852bb72522a2ba347759ab21e6140c7b3532921d48053.elf File opened for reading /proc/522/fd 8ae443a654bc16b4d8a852bb72522a2ba347759ab21e6140c7b3532921d48053.elf File opened for reading /proc/1573/exe 8ae443a654bc16b4d8a852bb72522a2ba347759ab21e6140c7b3532921d48053.elf File opened for reading /proc/696/exe 8ae443a654bc16b4d8a852bb72522a2ba347759ab21e6140c7b3532921d48053.elf File opened for reading /proc/1096/fd 8ae443a654bc16b4d8a852bb72522a2ba347759ab21e6140c7b3532921d48053.elf File opened for reading /proc/1579/fd 8ae443a654bc16b4d8a852bb72522a2ba347759ab21e6140c7b3532921d48053.elf File opened for reading /proc/1155/exe 8ae443a654bc16b4d8a852bb72522a2ba347759ab21e6140c7b3532921d48053.elf File opened for reading /proc/1164/fd 8ae443a654bc16b4d8a852bb72522a2ba347759ab21e6140c7b3532921d48053.elf File opened for reading /proc/1172/exe 8ae443a654bc16b4d8a852bb72522a2ba347759ab21e6140c7b3532921d48053.elf File opened for reading /proc/1560/exe 8ae443a654bc16b4d8a852bb72522a2ba347759ab21e6140c7b3532921d48053.elf File opened for reading /proc/1583/fd 8ae443a654bc16b4d8a852bb72522a2ba347759ab21e6140c7b3532921d48053.elf File opened for reading /proc/1162/exe 8ae443a654bc16b4d8a852bb72522a2ba347759ab21e6140c7b3532921d48053.elf File opened for reading /proc/1369/fd 8ae443a654bc16b4d8a852bb72522a2ba347759ab21e6140c7b3532921d48053.elf File opened for reading /proc/1191/exe 8ae443a654bc16b4d8a852bb72522a2ba347759ab21e6140c7b3532921d48053.elf File opened for reading /proc/1159/exe 8ae443a654bc16b4d8a852bb72522a2ba347759ab21e6140c7b3532921d48053.elf File opened for reading /proc/1111/exe 8ae443a654bc16b4d8a852bb72522a2ba347759ab21e6140c7b3532921d48053.elf File opened for reading /proc/1139/exe 8ae443a654bc16b4d8a852bb72522a2ba347759ab21e6140c7b3532921d48053.elf File opened for reading /proc/1191/fd 8ae443a654bc16b4d8a852bb72522a2ba347759ab21e6140c7b3532921d48053.elf File opened for reading /proc/649/fd 8ae443a654bc16b4d8a852bb72522a2ba347759ab21e6140c7b3532921d48053.elf File opened for reading /proc/426/exe 8ae443a654bc16b4d8a852bb72522a2ba347759ab21e6140c7b3532921d48053.elf File opened for reading /proc/760/exe 8ae443a654bc16b4d8a852bb72522a2ba347759ab21e6140c7b3532921d48053.elf File opened for reading /proc/1045/exe 8ae443a654bc16b4d8a852bb72522a2ba347759ab21e6140c7b3532921d48053.elf File opened for reading /proc/1157/exe 8ae443a654bc16b4d8a852bb72522a2ba347759ab21e6140c7b3532921d48053.elf File opened for reading /proc/377/fd 8ae443a654bc16b4d8a852bb72522a2ba347759ab21e6140c7b3532921d48053.elf File opened for reading /proc/1324/fd 8ae443a654bc16b4d8a852bb72522a2ba347759ab21e6140c7b3532921d48053.elf File opened for reading /proc/713/fd 8ae443a654bc16b4d8a852bb72522a2ba347759ab21e6140c7b3532921d48053.elf File opened for reading /proc/869/fd 8ae443a654bc16b4d8a852bb72522a2ba347759ab21e6140c7b3532921d48053.elf File opened for reading /proc/1064/fd 8ae443a654bc16b4d8a852bb72522a2ba347759ab21e6140c7b3532921d48053.elf File opened for reading /proc/1160/exe 8ae443a654bc16b4d8a852bb72522a2ba347759ab21e6140c7b3532921d48053.elf File opened for reading /proc/839/fd 8ae443a654bc16b4d8a852bb72522a2ba347759ab21e6140c7b3532921d48053.elf File opened for reading /proc/1494/fd 8ae443a654bc16b4d8a852bb72522a2ba347759ab21e6140c7b3532921d48053.elf File opened for reading /proc/719/fd 8ae443a654bc16b4d8a852bb72522a2ba347759ab21e6140c7b3532921d48053.elf File opened for reading /proc/1111/fd 8ae443a654bc16b4d8a852bb72522a2ba347759ab21e6140c7b3532921d48053.elf File opened for reading /proc/413/exe 8ae443a654bc16b4d8a852bb72522a2ba347759ab21e6140c7b3532921d48053.elf File opened for reading /proc/649/exe 8ae443a654bc16b4d8a852bb72522a2ba347759ab21e6140c7b3532921d48053.elf File opened for reading /proc/1051/exe 8ae443a654bc16b4d8a852bb72522a2ba347759ab21e6140c7b3532921d48053.elf File opened for reading /proc/1067/fd 8ae443a654bc16b4d8a852bb72522a2ba347759ab21e6140c7b3532921d48053.elf File opened for reading /proc/408/exe 8ae443a654bc16b4d8a852bb72522a2ba347759ab21e6140c7b3532921d48053.elf File opened for reading /proc/611/fd 8ae443a654bc16b4d8a852bb72522a2ba347759ab21e6140c7b3532921d48053.elf File opened for reading /proc/1315/fd 8ae443a654bc16b4d8a852bb72522a2ba347759ab21e6140c7b3532921d48053.elf File opened for reading /proc/751/exe 8ae443a654bc16b4d8a852bb72522a2ba347759ab21e6140c7b3532921d48053.elf File opened for reading /proc/869/exe 8ae443a654bc16b4d8a852bb72522a2ba347759ab21e6140c7b3532921d48053.elf File opened for reading /proc/1085/exe 8ae443a654bc16b4d8a852bb72522a2ba347759ab21e6140c7b3532921d48053.elf File opened for reading /proc/585/fd 8ae443a654bc16b4d8a852bb72522a2ba347759ab21e6140c7b3532921d48053.elf File opened for reading /proc/630/fd 8ae443a654bc16b4d8a852bb72522a2ba347759ab21e6140c7b3532921d48053.elf File opened for reading /proc/1319/exe 8ae443a654bc16b4d8a852bb72522a2ba347759ab21e6140c7b3532921d48053.elf File opened for reading /proc/1324/exe 8ae443a654bc16b4d8a852bb72522a2ba347759ab21e6140c7b3532921d48053.elf File opened for reading /proc/1329/exe 8ae443a654bc16b4d8a852bb72522a2ba347759ab21e6140c7b3532921d48053.elf File opened for reading /proc/1076/fd 8ae443a654bc16b4d8a852bb72522a2ba347759ab21e6140c7b3532921d48053.elf File opened for reading /proc/1076/exe 8ae443a654bc16b4d8a852bb72522a2ba347759ab21e6140c7b3532921d48053.elf File opened for reading /proc/1385/fd 8ae443a654bc16b4d8a852bb72522a2ba347759ab21e6140c7b3532921d48053.elf File opened for reading /proc/1172/fd 8ae443a654bc16b4d8a852bb72522a2ba347759ab21e6140c7b3532921d48053.elf File opened for reading /proc/1064/exe 8ae443a654bc16b4d8a852bb72522a2ba347759ab21e6140c7b3532921d48053.elf File opened for reading /proc/964/fd 8ae443a654bc16b4d8a852bb72522a2ba347759ab21e6140c7b3532921d48053.elf File opened for reading /proc/1434/fd 8ae443a654bc16b4d8a852bb72522a2ba347759ab21e6140c7b3532921d48053.elf File opened for reading /proc/633/exe 8ae443a654bc16b4d8a852bb72522a2ba347759ab21e6140c7b3532921d48053.elf File opened for reading /proc/1234/exe 8ae443a654bc16b4d8a852bb72522a2ba347759ab21e6140c7b3532921d48053.elf File opened for reading /proc/708/fd 8ae443a654bc16b4d8a852bb72522a2ba347759ab21e6140c7b3532921d48053.elf File opened for reading /proc/992/fd 8ae443a654bc16b4d8a852bb72522a2ba347759ab21e6140c7b3532921d48053.elf File opened for reading /proc/1192/fd 8ae443a654bc16b4d8a852bb72522a2ba347759ab21e6140c7b3532921d48053.elf File opened for reading /proc/588/exe 8ae443a654bc16b4d8a852bb72522a2ba347759ab21e6140c7b3532921d48053.elf File opened for reading /proc/1337/exe 8ae443a654bc16b4d8a852bb72522a2ba347759ab21e6140c7b3532921d48053.elf
Processes
Network
MITRE ATT&CK Matrix ATT&CK v13
Replay Monitor
Loading Replay Monitor...
Downloads
-
memory/1572-1-0x0000000008048000-0x000000000805db60-memory.dmp