MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2f1854f309c913068700c0c3efec3a84ea48e62393df38bab9c8233053e2b19b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Tsunami


Vendor detections: 10


Intelligence 10 IOCs YARA 15 File information Comments

SHA256 hash: 2f1854f309c913068700c0c3efec3a84ea48e62393df38bab9c8233053e2b19b
SHA3-384 hash: 2d7f164aa2fa25f86751b35ea1e9c94e7d75b88dcb4ab42a9e6c75d15478693c868b33615fa4b144aa15766cf467b9b4
SHA1 hash: 624e0d9c94309de8d038b2e21cf07685d2020fdb
MD5 hash: c91421f0d68095890b50a034dbf9d060
humanhash: finch-echo-oven-wolfram
File name:bin
Download: download sample
Signature Tsunami
File size:7'344'128 bytes
First seen:2024-03-12 17:29:27 UTC
Last seen:2024-03-13 16:04:35 UTC
File type: elf
MIME type:application/x-executable
ssdeep 49152:FdvgYnvuqgrb/TGvO90dL3BmAFd4A64nsfJYgJi1QjpzkpDKzBzQgQHDSZ/+/A5X:YqpgxDFnEqZJvlNiPt9y7LxXk5prrT
TLSH T109769D47F89190A5C1AEE230C666D293BB707C845B3423D32B50FBB92B76BD46E79314
telfhash t10d62bb3449bc70f2b6a6d961f373b4b4953758b567f838b11022ac95ffd0e811ca682b
TrID 50.1% (.) ELF Executable and Linkable format (Linux) (4022/12)
49.8% (.O) ELF Executable and Linkable format (generic) (4000/1)
Reporter Anonymous
Tags:elf Tsunami

Intelligence


File Origin
# of uploads :
2
# of downloads :
199
Origin country :
US US
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Receives data from a server
Collects information on the CPU
Collects information on the OS
Sends data to a server
Locks files
Launching a process
Changes access rights for a written file
Creating a file in the %temp% directory
Creating a file
Changes owner for a written file
Changes the time when the file was created, accessed, or modified
Deletes a file
DNS request
Creating a process from a recently created file
Sets a written file as executable
Manages services
Opens a port
Collects information on the RAM
Connection attempt
Loading a system driver
Writes files to system directory
Creates or modifies files in /cron to set up autorun
Creates or modifies symbolic links in /init.d to set up autorun
Creates or modifies files in /init.d to set up autorun
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
anti-debug expand lolbin packed packed upx
Malware family:
ngrok-server
Verdict:
Suspicious
Result
Threat name:
PwnRig Miner
Detection:
malicious
Classification:
troj.evad.mine
Score:
100 / 100
Signature
Deletes all firewall rules
Detected Stratum mining protocol
Drops files in suspicious directories
Drops invisible ELF files
Executes the "crontab" command typically for achieving persistence
Executes the "iptables" command to insert, remove and/or manipulate rules
Machine Learning detection for dropped file
Machine Learning detection for sample
Malicious sample detected (through community Yara rule)
Modifies the '.bashrc' or '.bash_profile' file typically for persisting actions
Protects files from modification
Sample deletes itself
Sample is packed with UPX
Sample reads /proc/mounts (often used for finding a writable filesystem)
Sample tries to persist itself using cron
Sample tries to persist itself using System V runlevels
Searches for CPU information (likely indicative for DDoS capability)
Tries to load the MSR kernel module used for reading/writing to CPUs model specific register
Uses IRC for communication with a C&C
Uses known network protocols on non-standard ports
Writes identical ELF files to multiple locations
Writes to CPU model specific registers (MSR) (e.g. miners improve performance by disabling HW prefetcher)
Yara detected PwnRig Miner
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1407729 Sample: bin.elf Startdate: 12/03/2024 Architecture: LINUX Score: 100 147 51.255.171.23, 54538, 80 OVHFR France 2->147 149 run.on-demand.pw 165.232.106.186, 42714, 80 ALLEGHENYHEALTHNETWORKUS United States 2->149 151 7 other IPs or domains 2->151 155 Malicious sample detected (through community Yara rule) 2->155 157 Yara detected PwnRig Miner 2->157 159 Uses IRC for communication with a C&C 2->159 161 5 other signatures 2->161 11 bin.elf 2->11         started        15 systemd bash 2->15         started        17 systemd snapd-env-generator 2->17         started        19 8 other processes 2->19 signatures3 process4 file5 137 /var/spool/cron/.lib-knlib4, ASCII 11->137 dropped 139 /tmp/service-agent, ELF 11->139 dropped 141 /opt/.klibsystem5, ELF 11->141 dropped 143 8 other malicious files 11->143 dropped 205 Writes identical ELF files to multiple locations 11->205 207 Drops invisible ELF files 11->207 209 Drops files in suspicious directories 11->209 211 Sample tries to persist itself using cron 11->211 21 bin.elf bash ufw 11->21         started        23 bin.elf service-agent 11->23         started        26 bin.elf bash 11->26         started        35 25 other processes 11->35 28 bash -bash 15->28         started        30 bash cp 15->30         started        33 bash rm 15->33         started        signatures6 process7 file8 37 ufw ufw-init 21->37         started        39 ufw iptables 21->39         started        165 Sample reads /proc/mounts (often used for finding a writable filesystem) 23->165 41 service-agent sh 23->41         started        45 service-agent sh 23->45         started        47 service-agent sh 23->47         started        51 2 other processes 26->51 49 -bash sh 28->49         started        53 4 other processes 28->53 145 /usr/bin/-bash, ELF 30->145 dropped 167 Writes identical ELF files to multiple locations 30->167 169 Drops files in suspicious directories 30->169 171 Sample deletes itself 33->171 173 Deletes all firewall rules 35->173 175 Protects files from modification 35->175 177 Executes the "iptables" command to insert, remove and/or manipulate rules 35->177 179 Executes the "crontab" command typically for achieving persistence 35->179 55 4 other processes 35->55 signatures9 process10 file11 65 163 other processes 37->65 115 /root/.bash_profile, ASCII 41->115 dropped 181 Modifies the '.bashrc' or '.bash_profile' file typically for persisting actions 41->181 57 sh tee 41->57         started        61 sh sed 41->61         started        67 41 other processes 41->67 63 sh 45->63         started        69 5 other processes 45->69 71 8 other processes 47->71 73 6 other processes 49->73 117 /var/spool/cron/crontabs/tmp.3DlKFR, ASCII 51->117 dropped 183 Sample tries to persist itself using cron 51->183 185 Executes the "crontab" command typically for achieving persistence 51->185 187 Writes to CPU model specific registers (MSR) (e.g. miners improve performance by disabling HW prefetcher) 53->187 75 18 other processes 53->75 signatures12 process13 file14 119 /etc/cron.weekly/pwnrig, ASCII 57->119 dropped 131 4 other malicious files 57->131 dropped 189 Sample tries to persist itself using cron 57->189 121 /etc/cron.weekly/sedzVFEsM, Bourne-Again 61->121 dropped 123 /etc/cron.monthly/sedHTB3AM, Bourne-Again 61->123 dropped 133 3 other malicious files 61->133 dropped 77 sh 63->77         started        86 6 other processes 63->86 191 Deletes all firewall rules 65->191 193 Executes the "iptables" command to insert, remove and/or manipulate rules 65->193 79 ip6tables modprobe 65->79         started        125 /usr/bin/sysdr, ELF 67->125 dropped 127 /usr/bin/initdr, ELF 67->127 dropped 129 /usr/bin/crondr, ELF 67->129 dropped 135 4 other malicious files 67->135 dropped 195 Writes identical ELF files to multiple locations 67->195 197 Protects files from modification 67->197 199 Drops files in suspicious directories 67->199 201 Sample tries to persist itself using System V runlevels 67->201 88 4 other processes 67->88 90 7 other processes 69->90 203 Searches for CPU information (likely indicative for DDoS capability) 73->203 81 sh 73->81         started        92 13 other processes 73->92 83 sh modprobe 75->83         started        94 5 other processes 75->94 signatures15 process16 signatures17 96 sh grep 77->96         started        99 sh cut 77->99         started        101 sh sed 77->101         started        103 sh sed 77->103         started        105 sh grep 81->105         started        109 3 other processes 81->109 163 Tries to load the MSR kernel module used for reading/writing to CPUs model specific register 83->163 111 12 other processes 86->111 107 sh hostname 90->107         started        113 13 other processes 92->113 process18 signatures19 153 Searches for CPU information (likely indicative for DDoS capability) 96->153
Threat name:
Linux.Backdoor.Tsunami
Status:
Malicious
First seen:
2024-03-12 17:30:07 UTC
File Type:
ELF64 Little (Exe)
AV detection:
11 of 24 (45.83%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:kaiten antivm botnet infostealer linux persistence rootkit upx
Behaviour
GoLang User-Agent
Enumerates kernel/hardware configuration
Reads runtime system information
Writes file to shm directory
Writes file to tmp directory
Attempts to change immutable files
Checks CPU configuration
Checks hardware identifiers (DMI)
Creates/modifies Cron job
Enumerates running processes
Modifies init.d
Modifies systemd
Reads CPU attributes
Reads hardware information
Writes file to system bin folder
Executes dropped EXE
Flushes firewall rules
Loads a kernel module
Reads EFI boot settings
UPX packed file
Detects Kaiten/Tsunami Payload
Kaiten/Tsunami
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:BLOWFISH_Constants
Author:phoul (@phoul)
Description:Look for Blowfish constants
Rule name:enterpriseapps2
Author:Tim Brown @timb_machine
Description:Enterprise apps
Rule name:enterpriseunix2
Author:Tim Brown @timb_machine
Description:Enterprise UNIX
Rule name:F01_s1ckrule
Author:s1ckb017
Rule name:GoBinTest
Rule name:golang
Rule name:golang_binary_string
Description:Golang strings present
Rule name:golang_duffcopy_amd64
Rule name:identity_golang
Author:Eric Yocam
Description:find Golang malware
Rule name:MD5_Constants
Author:phoul (@phoul)
Description:Look for MD5 constants
Rule name:RIPEMD160_Constants
Author:phoul (@phoul)
Description:Look for RIPEMD-160 constants
Rule name:setsockopt
Author:Tim Brown @timb_machine
Description:Hunts for setsockopt() red flags
Rule name:SHA1_Constants
Author:phoul (@phoul)
Description:Look for SHA1 constants
Rule name:SHA512_Constants
Author:phoul (@phoul)
Description:Look for SHA384/SHA512 constants
Rule name:unixredflags3
Author:Tim Brown @timb_machine
Description:Hunts for UNIX red flags

File information


The table below shows additional information about this malware sample such as delivery method and external references.

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_PIEMissing Position-Independent Executable (PIE) Protectionhigh

Comments