Edit tour
Linux
Analysis Report
na.elf
Overview
General Information
Detection
Mirai
Score: | 80 |
Range: | 0 - 100 |
Whitelisted: | false |
Signatures
Antivirus / Scanner detection for submitted sample
Detected Mirai
Multi AV Scanner detection for submitted file
Suricata IDS alerts for network traffic
Sample reads /proc/mounts (often used for finding a writable filesystem)
Sample tries to kill multiple processes (SIGKILL)
Detected TCP or UDP traffic on non-standard ports
Sample contains strings indicative of BusyBox which embeds multiple Unix commands in a single executable
Sample has stripped symbol table
Sample listens on a socket
Sample tries to kill a process (SIGKILL)
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Uses the "uname" system call to query kernel version information (possible evasion)
Classification
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1528724 |
Start date and time: | 2024-10-08 09:55:04 +02:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 5m 0s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultlinuxfilecookbook.jbs |
Analysis system description: | Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11) |
Analysis Mode: | default |
Sample name: | na.elf |
Detection: | MAL |
Classification: | mal80.spre.troj.linELF@0/0@7/0 |
Command: | /tmp/na.elf |
PID: | 6220 |
Exit Code: | 0 |
Exit Code Info: | |
Killed: | False |
Standard Output: | listening to tun0 |
Standard Error: |
- system is lnxubuntu20
- udisksd New Fork (PID: 6265, Parent: 799)
- gnome-session-binary New Fork (PID: 6292, Parent: 1477)
- systemd New Fork (PID: 6293, Parent: 1)
- gnome-session-binary New Fork (PID: 6352, Parent: 1477)
- gnome-session-binary New Fork (PID: 6355, Parent: 1477)
- gnome-session-binary New Fork (PID: 6358, Parent: 1477)
- gvfsd-fuse New Fork (PID: 6359, Parent: 2038)
- gnome-session-binary New Fork (PID: 6360, Parent: 1477)
- xfce4-panel New Fork (PID: 6361, Parent: 2063)
- gnome-session-binary New Fork (PID: 6363, Parent: 1477)
- xfce4-panel New Fork (PID: 6364, Parent: 2063)
- gnome-session-binary New Fork (PID: 6366, Parent: 1477)
- xfce4-panel New Fork (PID: 6367, Parent: 2063)
- udisksd New Fork (PID: 6368, Parent: 799)
- systemd New Fork (PID: 6374, Parent: 1)
- xfce4-panel New Fork (PID: 6415, Parent: 2063)
- gnome-session-binary New Fork (PID: 6422, Parent: 1477)
- xfce4-panel New Fork (PID: 6423, Parent: 2063)
- gnome-session-binary New Fork (PID: 6424, Parent: 1477)
- systemd New Fork (PID: 6426, Parent: 1)
- xfce4-panel New Fork (PID: 6458, Parent: 2063)
- gnome-session-binary New Fork (PID: 6465, Parent: 1477)
- udisksd New Fork (PID: 6467, Parent: 799)
- gnome-session-binary New Fork (PID: 6468, Parent: 1477)
- gnome-session-binary New Fork (PID: 6469, Parent: 1477)
- systemd New Fork (PID: 6472, Parent: 1)
- systemd New Fork (PID: 6512, Parent: 1)
- cleanup
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
Mirai | Mirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese. Nowadays it targets a wide range of networked embedded devices such as IP cameras, home routers (many vendors involved), and other IoT devices. Since the source code was published on "Hack Forums" many variants of the Mirai family appeared, infecting mostly home networks all around the world. | No Attribution |
⊘No yara matches
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-10-08T09:55:44.489649+0200 | 2030490 | 1 | Malware Command and Control Activity Detected | 192.168.2.23 | 46602 | 93.123.39.116 | 51511 | TCP |
2024-10-08T09:56:46.243721+0200 | 2030490 | 1 | Malware Command and Control Activity Detected | 192.168.2.23 | 46604 | 93.123.39.116 | 51511 | TCP |
2024-10-08T09:57:09.626300+0200 | 2030490 | 1 | Malware Command and Control Activity Detected | 192.168.2.23 | 46606 | 93.123.39.116 | 51511 | TCP |
2024-10-08T09:57:41.652289+0200 | 2030490 | 1 | Malware Command and Control Activity Detected | 192.168.2.23 | 46608 | 93.123.39.116 | 51511 | TCP |
2024-10-08T09:58:08.056399+0200 | 2030490 | 1 | Malware Command and Control Activity Detected | 192.168.2.23 | 46610 | 93.123.39.116 | 51511 | TCP |
2024-10-08T09:58:36.473711+0200 | 2030490 | 1 | Malware Command and Control Activity Detected | 192.168.2.23 | 46612 | 93.123.39.116 | 51511 | TCP |
2024-10-08T09:59:01.850884+0200 | 2030490 | 1 | Malware Command and Control Activity Detected | 192.168.2.23 | 46614 | 93.123.39.116 | 51511 | TCP |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-10-08T09:55:45.163449+0200 | 2030489 | 1 | Malware Command and Control Activity Detected | 93.123.39.116 | 51511 | 192.168.2.23 | 46602 | TCP |
2024-10-08T09:56:03.186025+0200 | 2030489 | 1 | Malware Command and Control Activity Detected | 93.123.39.116 | 51511 | 192.168.2.23 | 46602 | TCP |
2024-10-08T09:56:23.207555+0200 | 2030489 | 1 | Malware Command and Control Activity Detected | 93.123.39.116 | 51511 | 192.168.2.23 | 46602 | TCP |
Click to jump to signature section
Show All Signature Results
AV Detection |
---|
Source: | Avira: |
Source: | ReversingLabs: | |||
Source: | Virustotal: | Perma Link |
Networking |
---|
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: |
Source: | TCP traffic: |
Source: | Socket: | Jump to behavior |
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: |
Source: | DNS traffic detected: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
System Summary |
---|
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior |
Source: | String containing 'busybox' found: | ||
Source: | String containing 'busybox' found: |
Source: | .symtab present: |
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior |
Source: | Classification label: |
Persistence and Installation Behavior |
---|
Source: | File: | Jump to behavior |
Source: | Queries kernel information via 'uname': | Jump to behavior | ||
Source: | Queries kernel information via 'uname': | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Remote Access Functionality |
---|
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | Path Interception | Path Interception | Direct Volume Access | OS Credential Dumping | 11 Security Software Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | 1 Service Stop |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | Rootkit | LSASS Memory | 1 File and Directory Discovery | Remote Desktop Protocol | Data from Removable Media | 1 Non-Standard Port | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 1 Non-Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | 2 Application Layer Protocol | Traffic Duplication | Data Destruction |
⊘No configs have been found
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
55% | ReversingLabs | Linux.Backdoor.Mirai | ||
67% | Virustotal | Browse | ||
100% | Avira | LINUX/Mirai.bonb |
⊘No Antivirus matches
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
15% | Virustotal | Browse |
⊘No Antivirus matches
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
fdh32fsdfhs.shop | 93.123.39.116 | true | true |
| unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
93.123.39.116 | fdh32fsdfhs.shop | Bulgaria | 43561 | NET1-ASBG | true | |
109.202.202.202 | unknown | Switzerland | 13030 | INIT7CH | false | |
91.189.91.43 | unknown | United Kingdom | 41231 | CANONICAL-ASGB | false | |
91.189.91.42 | unknown | United Kingdom | 41231 | CANONICAL-ASGB | false |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
109.202.202.202 | Get hash | malicious | Unknown | Browse |
| |
91.189.91.43 | Get hash | malicious | Unknown | Browse | ||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Mirai, Gafgyt | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
91.189.91.42 | Get hash | malicious | Unknown | Browse | ||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Mirai, Gafgyt | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
fdh32fsdfhs.shop | Get hash | malicious | Mirai | Browse |
| |
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
CANONICAL-ASGB | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai, Gafgyt | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
CANONICAL-ASGB | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai, Gafgyt | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
NET1-ASBG | Get hash | malicious | Mirai | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | XWorm | Browse |
| ||
Get hash | malicious | Phisher | Browse |
| ||
Get hash | malicious | Okiru | Browse |
| ||
Get hash | malicious | Mirai, Okiru | Browse |
| ||
Get hash | malicious | Okiru | Browse |
| ||
Get hash | malicious | Okiru | Browse |
| ||
Get hash | malicious | Okiru | Browse |
| ||
Get hash | malicious | Okiru | Browse |
| ||
INIT7CH | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai, Gafgyt | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
⊘No context
⊘No context
⊘No created / dropped files found
File type: | |
Entropy (8bit): | 5.515007807447613 |
TrID: |
|
File name: | na.elf |
File size: | 68'512 bytes |
MD5: | c3f8d3cb4762fd27d6626a7d6c33d2e7 |
SHA1: | 2a7d3a7e349e478ef071d46635a3c736aa0bc332 |
SHA256: | 596613b25032e7529bb64dd157734647cb0ed09a199890625419edf87c6f1ac9 |
SHA512: | 4c2f7caefd58c3a36eecec36e4a4cf85b60f1a1e71995dedef405224ce7a6b2fdcfd0440b145837bfd75d75aeb0001d6547fe0a28d72a67fab4fa784d77b3c74 |
SSDEEP: | 1536:ZEsl9JVBEBsM5JiJx32ln0jly5qT7eOBNlYu:ZzfJYBd5Ji332ln0jly5qTHNlb |
TLSH: | 2D63B65D6E329FEDFBAC863047B34A20A798339527E1D684D29CC6002F7028D645FBA4 |
File Content Preview: | .ELF.....................@.`...4.........4. ...(.............@...@...........................E...E.....@..-X........dt.Q............................<...'......!'.......................<...'......!... ....'9... ......................<...'......!........'9. |
ELF header | |
---|---|
Class: | |
Data: | |
Version: | |
Machine: | |
Version Number: | |
Type: | |
OS/ABI: | |
ABI Version: | 0 |
Entry Point Address: | |
Flags: | |
ELF Header Size: | 52 |
Program Header Offset: | 52 |
Program Header Size: | 32 |
Number of Program Headers: | 3 |
Section Header Offset: | 67992 |
Section Header Size: | 40 |
Number of Section Headers: | 13 |
Header String Table Index: | 12 |
Name | Type | Address | Offset | Size | EntSize | Flags | Flags Description | Link | Info | Align |
---|---|---|---|---|---|---|---|---|---|---|
NULL | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0 | 0 | 0 | ||
.init | PROGBITS | 0x400094 | 0x94 | 0x8c | 0x0 | 0x6 | AX | 0 | 0 | 4 |
.text | PROGBITS | 0x400120 | 0x120 | 0xe390 | 0x0 | 0x6 | AX | 0 | 0 | 16 |
.fini | PROGBITS | 0x40e4b0 | 0xe4b0 | 0x5c | 0x0 | 0x6 | AX | 0 | 0 | 4 |
.rodata | PROGBITS | 0x40e510 | 0xe510 | 0x1a70 | 0x0 | 0x2 | A | 0 | 0 | 16 |
.ctors | PROGBITS | 0x450000 | 0x10000 | 0x8 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.dtors | PROGBITS | 0x450008 | 0x10008 | 0x8 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.data.rel.ro | PROGBITS | 0x450014 | 0x10014 | 0x84 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.data | PROGBITS | 0x4500a0 | 0x100a0 | 0x3e0 | 0x0 | 0x3 | WA | 0 | 0 | 16 |
.got | PROGBITS | 0x450480 | 0x10480 | 0x4c0 | 0x4 | 0x10000003 | WAp | 0 | 0 | 16 |
.sbss | NOBITS | 0x450940 | 0x10940 | 0x24 | 0x0 | 0x10000003 | WAp | 0 | 0 | 4 |
.bss | NOBITS | 0x450970 | 0x10940 | 0x23e8 | 0x0 | 0x3 | WA | 0 | 0 | 16 |
.shstrtab | STRTAB | 0x0 | 0x10940 | 0x56 | 0x0 | 0x0 | 0 | 0 | 1 |
Type | Offset | Virtual Address | Physical Address | File Size | Memory Size | Entropy | Flags | Flags Description | Align | Prog Interpreter | Section Mappings |
---|---|---|---|---|---|---|---|---|---|---|---|
LOAD | 0x0 | 0x400000 | 0x400000 | 0xff80 | 0xff80 | 5.5640 | 0x5 | R E | 0x10000 | .init .text .fini .rodata | |
LOAD | 0x10000 | 0x450000 | 0x450000 | 0x940 | 0x2d58 | 3.7376 | 0x6 | RW | 0x10000 | .ctors .dtors .data.rel.ro .data .got .sbss .bss | |
GNU_STACK | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0.0000 | 0x7 | RWE | 0x4 |
Timestamp | SID | Signature | Severity | Source IP | Source Port | Dest IP | Dest Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-10-08T09:55:44.489649+0200 | 2030490 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) | 1 | 192.168.2.23 | 46602 | 93.123.39.116 | 51511 | TCP |
2024-10-08T09:55:45.163449+0200 | 2030489 | ET MALWARE ELF/MooBot Mirai DDoS Variant Server Response | 1 | 93.123.39.116 | 51511 | 192.168.2.23 | 46602 | TCP |
2024-10-08T09:56:03.186025+0200 | 2030489 | ET MALWARE ELF/MooBot Mirai DDoS Variant Server Response | 1 | 93.123.39.116 | 51511 | 192.168.2.23 | 46602 | TCP |
2024-10-08T09:56:23.207555+0200 | 2030489 | ET MALWARE ELF/MooBot Mirai DDoS Variant Server Response | 1 | 93.123.39.116 | 51511 | 192.168.2.23 | 46602 | TCP |
2024-10-08T09:56:46.243721+0200 | 2030490 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) | 1 | 192.168.2.23 | 46604 | 93.123.39.116 | 51511 | TCP |
2024-10-08T09:57:09.626300+0200 | 2030490 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) | 1 | 192.168.2.23 | 46606 | 93.123.39.116 | 51511 | TCP |
2024-10-08T09:57:41.652289+0200 | 2030490 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) | 1 | 192.168.2.23 | 46608 | 93.123.39.116 | 51511 | TCP |
2024-10-08T09:58:08.056399+0200 | 2030490 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) | 1 | 192.168.2.23 | 46610 | 93.123.39.116 | 51511 | TCP |
2024-10-08T09:58:36.473711+0200 | 2030490 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) | 1 | 192.168.2.23 | 46612 | 93.123.39.116 | 51511 | TCP |
2024-10-08T09:59:01.850884+0200 | 2030490 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) | 1 | 192.168.2.23 | 46614 | 93.123.39.116 | 51511 | TCP |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Oct 8, 2024 09:55:43.696624041 CEST | 43928 | 443 | 192.168.2.23 | 91.189.91.42 |
Oct 8, 2024 09:55:44.448931932 CEST | 46602 | 51511 | 192.168.2.23 | 93.123.39.116 |
Oct 8, 2024 09:55:44.454212904 CEST | 51511 | 46602 | 93.123.39.116 | 192.168.2.23 |
Oct 8, 2024 09:55:44.454278946 CEST | 46602 | 51511 | 192.168.2.23 | 93.123.39.116 |
Oct 8, 2024 09:55:44.489649057 CEST | 46602 | 51511 | 192.168.2.23 | 93.123.39.116 |
Oct 8, 2024 09:55:44.494581938 CEST | 51511 | 46602 | 93.123.39.116 | 192.168.2.23 |
Oct 8, 2024 09:55:45.163449049 CEST | 51511 | 46602 | 93.123.39.116 | 192.168.2.23 |
Oct 8, 2024 09:55:45.163513899 CEST | 46602 | 51511 | 192.168.2.23 | 93.123.39.116 |
Oct 8, 2024 09:55:49.327867985 CEST | 42836 | 443 | 192.168.2.23 | 91.189.91.43 |
Oct 8, 2024 09:55:50.351713896 CEST | 42516 | 80 | 192.168.2.23 | 109.202.202.202 |
Oct 8, 2024 09:55:55.167105913 CEST | 46602 | 51511 | 192.168.2.23 | 93.123.39.116 |
Oct 8, 2024 09:55:55.172347069 CEST | 51511 | 46602 | 93.123.39.116 | 192.168.2.23 |
Oct 8, 2024 09:56:03.186024904 CEST | 51511 | 46602 | 93.123.39.116 | 192.168.2.23 |
Oct 8, 2024 09:56:03.186193943 CEST | 46602 | 51511 | 192.168.2.23 | 93.123.39.116 |
Oct 8, 2024 09:56:05.453630924 CEST | 43928 | 443 | 192.168.2.23 | 91.189.91.42 |
Oct 8, 2024 09:56:15.692198038 CEST | 42836 | 443 | 192.168.2.23 | 91.189.91.43 |
Oct 8, 2024 09:56:19.787681103 CEST | 42516 | 80 | 192.168.2.23 | 109.202.202.202 |
Oct 8, 2024 09:56:23.207555056 CEST | 51511 | 46602 | 93.123.39.116 | 192.168.2.23 |
Oct 8, 2024 09:56:23.207648039 CEST | 46602 | 51511 | 192.168.2.23 | 93.123.39.116 |
Oct 8, 2024 09:56:40.216161966 CEST | 51511 | 46602 | 93.123.39.116 | 192.168.2.23 |
Oct 8, 2024 09:56:40.216619015 CEST | 46602 | 51511 | 192.168.2.23 | 93.123.39.116 |
Oct 8, 2024 09:56:40.221472979 CEST | 51511 | 46602 | 93.123.39.116 | 192.168.2.23 |
Oct 8, 2024 09:56:46.236943960 CEST | 46604 | 51511 | 192.168.2.23 | 93.123.39.116 |
Oct 8, 2024 09:56:46.242120981 CEST | 51511 | 46604 | 93.123.39.116 | 192.168.2.23 |
Oct 8, 2024 09:56:46.242199898 CEST | 46604 | 51511 | 192.168.2.23 | 93.123.39.116 |
Oct 8, 2024 09:56:46.243721008 CEST | 46604 | 51511 | 192.168.2.23 | 93.123.39.116 |
Oct 8, 2024 09:56:46.248495102 CEST | 51511 | 46604 | 93.123.39.116 | 192.168.2.23 |
Oct 8, 2024 09:56:46.407928944 CEST | 43928 | 443 | 192.168.2.23 | 91.189.91.42 |
Oct 8, 2024 09:57:07.611759901 CEST | 51511 | 46604 | 93.123.39.116 | 192.168.2.23 |
Oct 8, 2024 09:57:07.611989021 CEST | 46604 | 51511 | 192.168.2.23 | 93.123.39.116 |
Oct 8, 2024 09:57:07.616909981 CEST | 51511 | 46604 | 93.123.39.116 | 192.168.2.23 |
Oct 8, 2024 09:57:09.620719910 CEST | 46606 | 51511 | 192.168.2.23 | 93.123.39.116 |
Oct 8, 2024 09:57:09.625694990 CEST | 51511 | 46606 | 93.123.39.116 | 192.168.2.23 |
Oct 8, 2024 09:57:09.625750065 CEST | 46606 | 51511 | 192.168.2.23 | 93.123.39.116 |
Oct 8, 2024 09:57:09.626300097 CEST | 46606 | 51511 | 192.168.2.23 | 93.123.39.116 |
Oct 8, 2024 09:57:09.631211042 CEST | 51511 | 46606 | 93.123.39.116 | 192.168.2.23 |
Oct 8, 2024 09:57:19.635126114 CEST | 46606 | 51511 | 192.168.2.23 | 93.123.39.116 |
Oct 8, 2024 09:57:19.640511036 CEST | 51511 | 46606 | 93.123.39.116 | 192.168.2.23 |
Oct 8, 2024 09:57:31.635833025 CEST | 51511 | 46606 | 93.123.39.116 | 192.168.2.23 |
Oct 8, 2024 09:57:31.635909081 CEST | 51511 | 46606 | 93.123.39.116 | 192.168.2.23 |
Oct 8, 2024 09:57:31.635982037 CEST | 46606 | 51511 | 192.168.2.23 | 93.123.39.116 |
Oct 8, 2024 09:57:31.636149883 CEST | 46606 | 51511 | 192.168.2.23 | 93.123.39.116 |
Oct 8, 2024 09:57:31.636198044 CEST | 51511 | 46606 | 93.123.39.116 | 192.168.2.23 |
Oct 8, 2024 09:57:31.636269093 CEST | 46606 | 51511 | 192.168.2.23 | 93.123.39.116 |
Oct 8, 2024 09:57:31.845863104 CEST | 46606 | 51511 | 192.168.2.23 | 93.123.39.116 |
Oct 8, 2024 09:57:31.884478092 CEST | 51511 | 46606 | 93.123.39.116 | 192.168.2.23 |
Oct 8, 2024 09:57:31.884684086 CEST | 46606 | 51511 | 192.168.2.23 | 93.123.39.116 |
Oct 8, 2024 09:57:32.057641983 CEST | 46606 | 51511 | 192.168.2.23 | 93.123.39.116 |
Oct 8, 2024 09:57:32.118391037 CEST | 51511 | 46606 | 93.123.39.116 | 192.168.2.23 |
Oct 8, 2024 09:57:32.120978117 CEST | 51511 | 46606 | 93.123.39.116 | 192.168.2.23 |
Oct 8, 2024 09:57:32.121105909 CEST | 46606 | 51511 | 192.168.2.23 | 93.123.39.116 |
Oct 8, 2024 09:57:32.121356010 CEST | 51511 | 46606 | 93.123.39.116 | 192.168.2.23 |
Oct 8, 2024 09:57:32.121414900 CEST | 46606 | 51511 | 192.168.2.23 | 93.123.39.116 |
Oct 8, 2024 09:57:41.645719051 CEST | 46608 | 51511 | 192.168.2.23 | 93.123.39.116 |
Oct 8, 2024 09:57:41.650985003 CEST | 51511 | 46608 | 93.123.39.116 | 192.168.2.23 |
Oct 8, 2024 09:57:41.651228905 CEST | 46608 | 51511 | 192.168.2.23 | 93.123.39.116 |
Oct 8, 2024 09:57:41.652288914 CEST | 46608 | 51511 | 192.168.2.23 | 93.123.39.116 |
Oct 8, 2024 09:57:41.657279968 CEST | 51511 | 46608 | 93.123.39.116 | 192.168.2.23 |
Oct 8, 2024 09:58:03.038808107 CEST | 51511 | 46608 | 93.123.39.116 | 192.168.2.23 |
Oct 8, 2024 09:58:03.039314985 CEST | 46608 | 51511 | 192.168.2.23 | 93.123.39.116 |
Oct 8, 2024 09:58:03.044521093 CEST | 51511 | 46608 | 93.123.39.116 | 192.168.2.23 |
Oct 8, 2024 09:58:08.049561977 CEST | 46610 | 51511 | 192.168.2.23 | 93.123.39.116 |
Oct 8, 2024 09:58:08.055727959 CEST | 51511 | 46610 | 93.123.39.116 | 192.168.2.23 |
Oct 8, 2024 09:58:08.055775881 CEST | 46610 | 51511 | 192.168.2.23 | 93.123.39.116 |
Oct 8, 2024 09:58:08.056399107 CEST | 46610 | 51511 | 192.168.2.23 | 93.123.39.116 |
Oct 8, 2024 09:58:08.062200069 CEST | 51511 | 46610 | 93.123.39.116 | 192.168.2.23 |
Oct 8, 2024 09:58:29.455112934 CEST | 51511 | 46610 | 93.123.39.116 | 192.168.2.23 |
Oct 8, 2024 09:58:29.455545902 CEST | 46610 | 51511 | 192.168.2.23 | 93.123.39.116 |
Oct 8, 2024 09:58:29.460983038 CEST | 51511 | 46610 | 93.123.39.116 | 192.168.2.23 |
Oct 8, 2024 09:58:36.467864037 CEST | 46612 | 51511 | 192.168.2.23 | 93.123.39.116 |
Oct 8, 2024 09:58:36.472738981 CEST | 51511 | 46612 | 93.123.39.116 | 192.168.2.23 |
Oct 8, 2024 09:58:36.472791910 CEST | 46612 | 51511 | 192.168.2.23 | 93.123.39.116 |
Oct 8, 2024 09:58:36.473711014 CEST | 46612 | 51511 | 192.168.2.23 | 93.123.39.116 |
Oct 8, 2024 09:58:36.478473902 CEST | 51511 | 46612 | 93.123.39.116 | 192.168.2.23 |
Oct 8, 2024 09:58:46.482532024 CEST | 46612 | 51511 | 192.168.2.23 | 93.123.39.116 |
Oct 8, 2024 09:58:46.487943888 CEST | 51511 | 46612 | 93.123.39.116 | 192.168.2.23 |
Oct 8, 2024 09:58:57.831271887 CEST | 51511 | 46612 | 93.123.39.116 | 192.168.2.23 |
Oct 8, 2024 09:58:57.831528902 CEST | 46612 | 51511 | 192.168.2.23 | 93.123.39.116 |
Oct 8, 2024 09:58:57.836987019 CEST | 51511 | 46612 | 93.123.39.116 | 192.168.2.23 |
Oct 8, 2024 09:59:01.842700958 CEST | 46614 | 51511 | 192.168.2.23 | 93.123.39.116 |
Oct 8, 2024 09:59:01.848732948 CEST | 51511 | 46614 | 93.123.39.116 | 192.168.2.23 |
Oct 8, 2024 09:59:01.849109888 CEST | 46614 | 51511 | 192.168.2.23 | 93.123.39.116 |
Oct 8, 2024 09:59:01.850883961 CEST | 46614 | 51511 | 192.168.2.23 | 93.123.39.116 |
Oct 8, 2024 09:59:01.855943918 CEST | 51511 | 46614 | 93.123.39.116 | 192.168.2.23 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Oct 8, 2024 09:55:44.409923077 CEST | 60475 | 53 | 192.168.2.23 | 8.8.8.8 |
Oct 8, 2024 09:55:44.439930916 CEST | 53 | 60475 | 8.8.8.8 | 192.168.2.23 |
Oct 8, 2024 09:56:46.220021963 CEST | 40773 | 53 | 192.168.2.23 | 8.8.8.8 |
Oct 8, 2024 09:56:46.236118078 CEST | 53 | 40773 | 8.8.8.8 | 192.168.2.23 |
Oct 8, 2024 09:57:09.613114119 CEST | 51812 | 53 | 192.168.2.23 | 8.8.8.8 |
Oct 8, 2024 09:57:09.620398998 CEST | 53 | 51812 | 8.8.8.8 | 192.168.2.23 |
Oct 8, 2024 09:57:41.637854099 CEST | 40003 | 53 | 192.168.2.23 | 8.8.8.8 |
Oct 8, 2024 09:57:41.645188093 CEST | 53 | 40003 | 8.8.8.8 | 192.168.2.23 |
Oct 8, 2024 09:58:08.040855885 CEST | 58951 | 53 | 192.168.2.23 | 8.8.8.8 |
Oct 8, 2024 09:58:08.049109936 CEST | 53 | 58951 | 8.8.8.8 | 192.168.2.23 |
Oct 8, 2024 09:58:36.460153103 CEST | 38378 | 53 | 192.168.2.23 | 8.8.8.8 |
Oct 8, 2024 09:58:36.467252970 CEST | 53 | 38378 | 8.8.8.8 | 192.168.2.23 |
Oct 8, 2024 09:59:01.834928036 CEST | 47425 | 53 | 192.168.2.23 | 8.8.8.8 |
Oct 8, 2024 09:59:01.841305017 CEST | 53 | 47425 | 8.8.8.8 | 192.168.2.23 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Oct 8, 2024 09:55:44.409923077 CEST | 192.168.2.23 | 8.8.8.8 | 0xea0b | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 8, 2024 09:56:46.220021963 CEST | 192.168.2.23 | 8.8.8.8 | 0xe17c | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 8, 2024 09:57:09.613114119 CEST | 192.168.2.23 | 8.8.8.8 | 0x5a14 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 8, 2024 09:57:41.637854099 CEST | 192.168.2.23 | 8.8.8.8 | 0xc98e | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 8, 2024 09:58:08.040855885 CEST | 192.168.2.23 | 8.8.8.8 | 0x3ec5 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 8, 2024 09:58:36.460153103 CEST | 192.168.2.23 | 8.8.8.8 | 0x268c | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 8, 2024 09:59:01.834928036 CEST | 192.168.2.23 | 8.8.8.8 | 0x1d48 | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Oct 8, 2024 09:55:44.439930916 CEST | 8.8.8.8 | 192.168.2.23 | 0xea0b | No error (0) | 93.123.39.116 | A (IP address) | IN (0x0001) | false | ||
Oct 8, 2024 09:56:46.236118078 CEST | 8.8.8.8 | 192.168.2.23 | 0xe17c | No error (0) | 93.123.39.116 | A (IP address) | IN (0x0001) | false | ||
Oct 8, 2024 09:57:09.620398998 CEST | 8.8.8.8 | 192.168.2.23 | 0x5a14 | No error (0) | 93.123.39.116 | A (IP address) | IN (0x0001) | false | ||
Oct 8, 2024 09:57:41.645188093 CEST | 8.8.8.8 | 192.168.2.23 | 0xc98e | No error (0) | 93.123.39.116 | A (IP address) | IN (0x0001) | false | ||
Oct 8, 2024 09:58:08.049109936 CEST | 8.8.8.8 | 192.168.2.23 | 0x3ec5 | No error (0) | 93.123.39.116 | A (IP address) | IN (0x0001) | false | ||
Oct 8, 2024 09:58:36.467252970 CEST | 8.8.8.8 | 192.168.2.23 | 0x268c | No error (0) | 93.123.39.116 | A (IP address) | IN (0x0001) | false | ||
Oct 8, 2024 09:59:01.841305017 CEST | 8.8.8.8 | 192.168.2.23 | 0x1d48 | No error (0) | 93.123.39.116 | A (IP address) | IN (0x0001) | false |
System Behavior
Start time (UTC): | 07:55:42 |
Start date (UTC): | 08/10/2024 |
Path: | /tmp/na.elf |
Arguments: | /tmp/na.elf |
File size: | 5777432 bytes |
MD5 hash: | 0083f1f0e77be34ad27f849842bbb00c |
Start time (UTC): | 07:55:42 |
Start date (UTC): | 08/10/2024 |
Path: | /tmp/na.elf |
Arguments: | - |
File size: | 5777432 bytes |
MD5 hash: | 0083f1f0e77be34ad27f849842bbb00c |
Start time (UTC): | 07:55:43 |
Start date (UTC): | 08/10/2024 |
Path: | /tmp/na.elf |
Arguments: | - |
File size: | 5777432 bytes |
MD5 hash: | 0083f1f0e77be34ad27f849842bbb00c |
Start time (UTC): | 07:55:43 |
Start date (UTC): | 08/10/2024 |
Path: | /usr/lib/udisks2/udisksd |
Arguments: | - |
File size: | 483056 bytes |
MD5 hash: | 1d7ae439cc3d82fa6b127671ce037a24 |
Start time (UTC): | 07:55:43 |
Start date (UTC): | 08/10/2024 |
Path: | /usr/sbin/dumpe2fs |
Arguments: | dumpe2fs -h /dev/dm-0 |
File size: | 31112 bytes |
MD5 hash: | 5c66f7d8f7681a40562cf049ad4b72b4 |
Start time (UTC): | 07:55:43 |
Start date (UTC): | 08/10/2024 |
Path: | /usr/libexec/gnome-session-binary |
Arguments: | - |
File size: | 334664 bytes |
MD5 hash: | d9b90be4f7db60cb3c2d3da6a1d31bfb |
Start time (UTC): | 07:55:43 |
Start date (UTC): | 08/10/2024 |
Path: | /bin/sh |
Arguments: | /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-sharing |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 07:55:43 |
Start date (UTC): | 08/10/2024 |
Path: | /usr/libexec/gsd-sharing |
Arguments: | /usr/libexec/gsd-sharing |
File size: | 35424 bytes |
MD5 hash: | e29d9025d98590fbb69f89fdbd4438b3 |
Start time (UTC): | 07:55:43 |
Start date (UTC): | 08/10/2024 |
Path: | /usr/lib/systemd/systemd |
Arguments: | - |
File size: | 1620224 bytes |
MD5 hash: | 9b2bec7092a40488108543f9334aab75 |
Start time (UTC): | 07:55:43 |
Start date (UTC): | 08/10/2024 |
Path: | /usr/lib/upower/upowerd |
Arguments: | /usr/lib/upower/upowerd |
File size: | 260328 bytes |
MD5 hash: | 1253eea2fe5fe4017069664284e326cd |
Start time (UTC): | 07:55:43 |
Start date (UTC): | 08/10/2024 |
Path: | /usr/libexec/gnome-session-binary |
Arguments: | - |
File size: | 334664 bytes |
MD5 hash: | d9b90be4f7db60cb3c2d3da6a1d31bfb |
Start time (UTC): | 07:55:43 |
Start date (UTC): | 08/10/2024 |
Path: | /bin/sh |
Arguments: | /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-wacom |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 07:55:43 |
Start date (UTC): | 08/10/2024 |
Path: | /usr/libexec/gsd-wacom |
Arguments: | /usr/libexec/gsd-wacom |
File size: | 39520 bytes |
MD5 hash: | 13778dd1a23a4e94ddc17ac9caa4fcc1 |
Start time (UTC): | 07:55:43 |
Start date (UTC): | 08/10/2024 |
Path: | /usr/libexec/gnome-session-binary |
Arguments: | - |
File size: | 334664 bytes |
MD5 hash: | d9b90be4f7db60cb3c2d3da6a1d31bfb |
Start time (UTC): | 07:55:43 |
Start date (UTC): | 08/10/2024 |
Path: | /bin/sh |
Arguments: | /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-color |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 07:55:44 |
Start date (UTC): | 08/10/2024 |
Path: | /usr/libexec/gsd-color |
Arguments: | /usr/libexec/gsd-color |
File size: | 92832 bytes |
MD5 hash: | ac2861ad93ce047283e8e87cefef9a19 |
Start time (UTC): | 07:55:43 |
Start date (UTC): | 08/10/2024 |
Path: | /usr/libexec/gnome-session-binary |
Arguments: | - |
File size: | 334664 bytes |
MD5 hash: | d9b90be4f7db60cb3c2d3da6a1d31bfb |
Start time (UTC): | 07:55:43 |
Start date (UTC): | 08/10/2024 |
Path: | /bin/sh |
Arguments: | /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-keyboard |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 07:55:44 |
Start date (UTC): | 08/10/2024 |
Path: | /usr/libexec/gsd-keyboard |
Arguments: | /usr/libexec/gsd-keyboard |
File size: | 39760 bytes |
MD5 hash: | 8e288fd17c80bb0a1148b964b2ac2279 |
Start time (UTC): | 07:55:43 |
Start date (UTC): | 08/10/2024 |
Path: | /usr/libexec/gvfsd-fuse |
Arguments: | - |
File size: | 47632 bytes |
MD5 hash: | d18fbf1cbf8eb57b17fac48b7b4be933 |
Start time (UTC): | 07:55:43 |
Start date (UTC): | 08/10/2024 |
Path: | /bin/fusermount |
Arguments: | fusermount -u -q -z -- /run/user/1000/gvfs |
File size: | 39144 bytes |
MD5 hash: | 576a1b135c82bdcbc97a91acea900566 |
Start time (UTC): | 07:55:44 |
Start date (UTC): | 08/10/2024 |
Path: | /usr/libexec/gnome-session-binary |
Arguments: | - |
File size: | 334664 bytes |
MD5 hash: | d9b90be4f7db60cb3c2d3da6a1d31bfb |
Start time (UTC): | 07:55:44 |
Start date (UTC): | 08/10/2024 |
Path: | /bin/sh |
Arguments: | /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-print-notifications |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 07:55:44 |
Start date (UTC): | 08/10/2024 |
Path: | /usr/libexec/gsd-print-notifications |
Arguments: | /usr/libexec/gsd-print-notifications |
File size: | 51840 bytes |
MD5 hash: | 71539698aa691718cee775d6b9450ae2 |
Start time (UTC): | 07:55:44 |
Start date (UTC): | 08/10/2024 |
Path: | /usr/bin/xfce4-panel |
Arguments: | - |
File size: | 375768 bytes |
MD5 hash: | a15b657c7d54ac1385f1f15004ea6784 |
Start time (UTC): | 07:55:44 |
Start date (UTC): | 08/10/2024 |
Path: | /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 |
Arguments: | /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libsystray.so 6 12582920 systray "Notification Area" "Area where notification icons appear" |
File size: | 35136 bytes |
MD5 hash: | ac0b8a906f359a8ae102244738682e76 |
Start time (UTC): | 07:55:44 |
Start date (UTC): | 08/10/2024 |
Path: | /usr/libexec/gnome-session-binary |
Arguments: | - |
File size: | 334664 bytes |
MD5 hash: | d9b90be4f7db60cb3c2d3da6a1d31bfb |
Start time (UTC): | 07:55:44 |
Start date (UTC): | 08/10/2024 |
Path: | /bin/sh |
Arguments: | /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-rfkill |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 07:55:44 |
Start date (UTC): | 08/10/2024 |
Path: | /usr/libexec/gsd-rfkill |
Arguments: | /usr/libexec/gsd-rfkill |
File size: | 51808 bytes |
MD5 hash: | 88a16a3c0aba1759358c06215ecfb5cc |
Start time (UTC): | 07:55:44 |
Start date (UTC): | 08/10/2024 |
Path: | /usr/bin/xfce4-panel |
Arguments: | - |
File size: | 375768 bytes |
MD5 hash: | a15b657c7d54ac1385f1f15004ea6784 |
Start time (UTC): | 07:55:44 |
Start date (UTC): | 08/10/2024 |
Path: | /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 |
Arguments: | /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libstatusnotifier.so 7 12582921 statusnotifier "Status Notifier Plugin" "Provides a panel area for status notifier items (application indicators)" |
File size: | 35136 bytes |
MD5 hash: | ac0b8a906f359a8ae102244738682e76 |
Start time (UTC): | 07:55:44 |
Start date (UTC): | 08/10/2024 |
Path: | /usr/libexec/gnome-session-binary |
Arguments: | - |
File size: | 334664 bytes |
MD5 hash: | d9b90be4f7db60cb3c2d3da6a1d31bfb |
Start time (UTC): | 07:55:44 |
Start date (UTC): | 08/10/2024 |
Path: | /bin/sh |
Arguments: | /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-smartcard |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 07:55:45 |
Start date (UTC): | 08/10/2024 |
Path: | /usr/libexec/gsd-smartcard |
Arguments: | /usr/libexec/gsd-smartcard |
File size: | 109152 bytes |
MD5 hash: | ea1fbd7f62e4cd0331eae2ef754ee605 |
Start time (UTC): | 07:55:44 |
Start date (UTC): | 08/10/2024 |
Path: | /usr/bin/xfce4-panel |
Arguments: | - |
File size: | 375768 bytes |
MD5 hash: | a15b657c7d54ac1385f1f15004ea6784 |
Start time (UTC): | 07:55:44 |
Start date (UTC): | 08/10/2024 |
Path: | /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 |
Arguments: | /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libpulseaudio-plugin.so 8 12582922 pulseaudio "PulseAudio Plugin" "Adjust the audio volume of the PulseAudio sound system" |
File size: | 35136 bytes |
MD5 hash: | ac0b8a906f359a8ae102244738682e76 |
Start time (UTC): | 07:55:44 |
Start date (UTC): | 08/10/2024 |
Path: | /usr/lib/udisks2/udisksd |
Arguments: | - |
File size: | 483056 bytes |
MD5 hash: | 1d7ae439cc3d82fa6b127671ce037a24 |
Start time (UTC): | 07:55:44 |
Start date (UTC): | 08/10/2024 |
Path: | /usr/sbin/dumpe2fs |
Arguments: | dumpe2fs -h /dev/dm-0 |
File size: | 31112 bytes |
MD5 hash: | 5c66f7d8f7681a40562cf049ad4b72b4 |
Start time (UTC): | 07:55:45 |
Start date (UTC): | 08/10/2024 |
Path: | /usr/lib/systemd/systemd |
Arguments: | - |
File size: | 1620224 bytes |
MD5 hash: | 9b2bec7092a40488108543f9334aab75 |
Start time (UTC): | 07:55:45 |
Start date (UTC): | 08/10/2024 |
Path: | /usr/lib/upower/upowerd |
Arguments: | /usr/lib/upower/upowerd |
File size: | 260328 bytes |
MD5 hash: | 1253eea2fe5fe4017069664284e326cd |
Start time (UTC): | 07:55:45 |
Start date (UTC): | 08/10/2024 |
Path: | /usr/bin/xfce4-panel |
Arguments: | - |
File size: | 375768 bytes |
MD5 hash: | a15b657c7d54ac1385f1f15004ea6784 |
Start time (UTC): | 07:55:45 |
Start date (UTC): | 08/10/2024 |
Path: | /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 |
Arguments: | /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libxfce4powermanager.so 9 12582923 power-manager-plugin "Power Manager Plugin" "Display the battery levels of your devices and control the brightness of your display" |
File size: | 35136 bytes |
MD5 hash: | ac0b8a906f359a8ae102244738682e76 |
Start time (UTC): | 07:55:45 |
Start date (UTC): | 08/10/2024 |
Path: | /usr/libexec/gnome-session-binary |
Arguments: | - |
File size: | 334664 bytes |
MD5 hash: | d9b90be4f7db60cb3c2d3da6a1d31bfb |
Start time (UTC): | 07:55:45 |
Start date (UTC): | 08/10/2024 |
Path: | /bin/sh |
Arguments: | /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-media-keys |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 07:55:45 |
Start date (UTC): | 08/10/2024 |
Path: | /usr/libexec/gsd-media-keys |
Arguments: | /usr/libexec/gsd-media-keys |
File size: | 232936 bytes |
MD5 hash: | a425448c135afb4b8bfd79cc0b6b74da |
Start time (UTC): | 07:55:45 |
Start date (UTC): | 08/10/2024 |
Path: | /usr/bin/xfce4-panel |
Arguments: | - |
File size: | 375768 bytes |
MD5 hash: | a15b657c7d54ac1385f1f15004ea6784 |
Start time (UTC): | 07:55:45 |
Start date (UTC): | 08/10/2024 |
Path: | /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 |
Arguments: | /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libnotification-plugin.so 10 12582924 notification-plugin "Notification Plugin" "Notification plugin for the Xfce panel" |
File size: | 35136 bytes |
MD5 hash: | ac0b8a906f359a8ae102244738682e76 |
Start time (UTC): | 07:55:45 |
Start date (UTC): | 08/10/2024 |
Path: | /usr/libexec/gnome-session-binary |
Arguments: | - |
File size: | 334664 bytes |
MD5 hash: | d9b90be4f7db60cb3c2d3da6a1d31bfb |
Start time (UTC): | 07:55:45 |
Start date (UTC): | 08/10/2024 |
Path: | /bin/sh |
Arguments: | /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-screensaver-proxy |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 07:55:45 |
Start date (UTC): | 08/10/2024 |
Path: | /usr/libexec/gsd-screensaver-proxy |
Arguments: | /usr/libexec/gsd-screensaver-proxy |
File size: | 27232 bytes |
MD5 hash: | 77e309450c87dceee43f1a9e50cc0d02 |
Start time (UTC): | 07:55:45 |
Start date (UTC): | 08/10/2024 |
Path: | /usr/lib/systemd/systemd |
Arguments: | - |
File size: | 1620224 bytes |
MD5 hash: | 9b2bec7092a40488108543f9334aab75 |
Start time (UTC): | 07:55:45 |
Start date (UTC): | 08/10/2024 |
Path: | /usr/lib/upower/upowerd |
Arguments: | /usr/lib/upower/upowerd |
File size: | 260328 bytes |
MD5 hash: | 1253eea2fe5fe4017069664284e326cd |
Start time (UTC): | 07:55:45 |
Start date (UTC): | 08/10/2024 |
Path: | /usr/bin/xfce4-panel |
Arguments: | - |
File size: | 375768 bytes |
MD5 hash: | a15b657c7d54ac1385f1f15004ea6784 |
Start time (UTC): | 07:55:45 |
Start date (UTC): | 08/10/2024 |
Path: | /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 |
Arguments: | /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libactions.so 14 12582925 actions "Action Buttons" "Log out, lock or other system actions" |
File size: | 35136 bytes |
MD5 hash: | ac0b8a906f359a8ae102244738682e76 |
Start time (UTC): | 07:55:45 |
Start date (UTC): | 08/10/2024 |
Path: | /usr/libexec/gnome-session-binary |
Arguments: | - |
File size: | 334664 bytes |
MD5 hash: | d9b90be4f7db60cb3c2d3da6a1d31bfb |
Start time (UTC): | 07:55:45 |
Start date (UTC): | 08/10/2024 |
Path: | /bin/sh |
Arguments: | /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-a11y-settings |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 07:55:45 |
Start date (UTC): | 08/10/2024 |
Path: | /usr/libexec/gsd-a11y-settings |
Arguments: | /usr/libexec/gsd-a11y-settings |
File size: | 23056 bytes |
MD5 hash: | 18e243d2cf30ecee7ea89d1462725c5c |
Start time (UTC): | 07:55:45 |
Start date (UTC): | 08/10/2024 |
Path: | /usr/lib/udisks2/udisksd |
Arguments: | - |
File size: | 483056 bytes |
MD5 hash: | 1d7ae439cc3d82fa6b127671ce037a24 |
Start time (UTC): | 07:55:45 |
Start date (UTC): | 08/10/2024 |
Path: | /usr/sbin/dumpe2fs |
Arguments: | dumpe2fs -h /dev/dm-0 |
File size: | 31112 bytes |
MD5 hash: | 5c66f7d8f7681a40562cf049ad4b72b4 |
Start time (UTC): | 07:55:45 |
Start date (UTC): | 08/10/2024 |
Path: | /usr/libexec/gnome-session-binary |
Arguments: | - |
File size: | 334664 bytes |
MD5 hash: | d9b90be4f7db60cb3c2d3da6a1d31bfb |
Start time (UTC): | 07:55:45 |
Start date (UTC): | 08/10/2024 |
Path: | /bin/sh |
Arguments: | /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-housekeeping |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 07:55:45 |
Start date (UTC): | 08/10/2024 |
Path: | /usr/libexec/gsd-housekeeping |
Arguments: | /usr/libexec/gsd-housekeeping |
File size: | 51840 bytes |
MD5 hash: | b55f3394a84976ddb92a2915e5d76914 |
Start time (UTC): | 07:55:45 |
Start date (UTC): | 08/10/2024 |
Path: | /usr/libexec/gnome-session-binary |
Arguments: | - |
File size: | 334664 bytes |
MD5 hash: | d9b90be4f7db60cb3c2d3da6a1d31bfb |
Start time (UTC): | 07:55:45 |
Start date (UTC): | 08/10/2024 |
Path: | /bin/sh |
Arguments: | /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-power |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 07:55:45 |
Start date (UTC): | 08/10/2024 |
Path: | /usr/libexec/gsd-power |
Arguments: | /usr/libexec/gsd-power |
File size: | 88672 bytes |
MD5 hash: | 28b8e1b43c3e7f1db6741ea1ecd978b7 |
Start time (UTC): | 07:55:45 |
Start date (UTC): | 08/10/2024 |
Path: | /usr/lib/systemd/systemd |
Arguments: | - |
File size: | 1620224 bytes |
MD5 hash: | 9b2bec7092a40488108543f9334aab75 |
Start time (UTC): | 07:55:45 |
Start date (UTC): | 08/10/2024 |
Path: | /usr/lib/upower/upowerd |
Arguments: | /usr/lib/upower/upowerd |
File size: | 260328 bytes |
MD5 hash: | 1253eea2fe5fe4017069664284e326cd |
Start time (UTC): | 07:55:46 |
Start date (UTC): | 08/10/2024 |
Path: | /usr/lib/systemd/systemd |
Arguments: | - |
File size: | 1620224 bytes |
MD5 hash: | 9b2bec7092a40488108543f9334aab75 |
Start time (UTC): | 07:55:46 |
Start date (UTC): | 08/10/2024 |
Path: | /usr/lib/upower/upowerd |
Arguments: | /usr/lib/upower/upowerd |
File size: | 260328 bytes |
MD5 hash: | 1253eea2fe5fe4017069664284e326cd |