Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
na.elf

Overview

General Information

Sample name:na.elf
Analysis ID:1528724
MD5:c3f8d3cb4762fd27d6626a7d6c33d2e7
SHA1:2a7d3a7e349e478ef071d46635a3c736aa0bc332
SHA256:596613b25032e7529bb64dd157734647cb0ed09a199890625419edf87c6f1ac9
Tags:elfuser-abuse_ch
Infos:

Detection

Mirai
Score:80
Range:0 - 100
Whitelisted:false

Signatures

Antivirus / Scanner detection for submitted sample
Detected Mirai
Multi AV Scanner detection for submitted file
Suricata IDS alerts for network traffic
Sample reads /proc/mounts (often used for finding a writable filesystem)
Sample tries to kill multiple processes (SIGKILL)
Detected TCP or UDP traffic on non-standard ports
Sample contains strings indicative of BusyBox which embeds multiple Unix commands in a single executable
Sample has stripped symbol table
Sample listens on a socket
Sample tries to kill a process (SIGKILL)
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1528724
Start date and time:2024-10-08 09:55:04 +02:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 5m 0s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:na.elf
Detection:MAL
Classification:mal80.spre.troj.linELF@0/0@7/0
Command:/tmp/na.elf
PID:6220
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
listening to tun0
Standard Error:
  • system is lnxubuntu20
  • na.elf (PID: 6220, Parent: 6139, MD5: 0083f1f0e77be34ad27f849842bbb00c) Arguments: /tmp/na.elf
    • na.elf New Fork (PID: 6222, Parent: 6220)
    • na.elf New Fork (PID: 6224, Parent: 6220)
  • udisksd New Fork (PID: 6265, Parent: 799)
  • dumpe2fs (PID: 6265, Parent: 799, MD5: 5c66f7d8f7681a40562cf049ad4b72b4) Arguments: dumpe2fs -h /dev/dm-0
  • sh (PID: 6292, Parent: 1477, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-sharing
  • gsd-sharing (PID: 6292, Parent: 1477, MD5: e29d9025d98590fbb69f89fdbd4438b3) Arguments: /usr/libexec/gsd-sharing
  • systemd New Fork (PID: 6293, Parent: 1)
  • upowerd (PID: 6293, Parent: 1, MD5: 1253eea2fe5fe4017069664284e326cd) Arguments: /usr/lib/upower/upowerd
  • sh (PID: 6352, Parent: 1477, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-wacom
  • gsd-wacom (PID: 6352, Parent: 1477, MD5: 13778dd1a23a4e94ddc17ac9caa4fcc1) Arguments: /usr/libexec/gsd-wacom
  • sh (PID: 6355, Parent: 1477, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-color
  • gsd-color (PID: 6355, Parent: 1477, MD5: ac2861ad93ce047283e8e87cefef9a19) Arguments: /usr/libexec/gsd-color
  • sh (PID: 6358, Parent: 1477, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-keyboard
  • gsd-keyboard (PID: 6358, Parent: 1477, MD5: 8e288fd17c80bb0a1148b964b2ac2279) Arguments: /usr/libexec/gsd-keyboard
  • fusermount (PID: 6359, Parent: 2038, MD5: 576a1b135c82bdcbc97a91acea900566) Arguments: fusermount -u -q -z -- /run/user/1000/gvfs
  • sh (PID: 6360, Parent: 1477, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-print-notifications
  • gsd-print-notifications (PID: 6360, Parent: 1477, MD5: 71539698aa691718cee775d6b9450ae2) Arguments: /usr/libexec/gsd-print-notifications
  • wrapper-2.0 (PID: 6361, Parent: 2063, MD5: ac0b8a906f359a8ae102244738682e76) Arguments: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libsystray.so 6 12582920 systray "Notification Area" "Area where notification icons appear"
  • sh (PID: 6363, Parent: 1477, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-rfkill
  • gsd-rfkill (PID: 6363, Parent: 1477, MD5: 88a16a3c0aba1759358c06215ecfb5cc) Arguments: /usr/libexec/gsd-rfkill
  • wrapper-2.0 (PID: 6364, Parent: 2063, MD5: ac0b8a906f359a8ae102244738682e76) Arguments: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libstatusnotifier.so 7 12582921 statusnotifier "Status Notifier Plugin" "Provides a panel area for status notifier items (application indicators)"
  • sh (PID: 6366, Parent: 1477, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-smartcard
  • gsd-smartcard (PID: 6366, Parent: 1477, MD5: ea1fbd7f62e4cd0331eae2ef754ee605) Arguments: /usr/libexec/gsd-smartcard
  • wrapper-2.0 (PID: 6367, Parent: 2063, MD5: ac0b8a906f359a8ae102244738682e76) Arguments: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libpulseaudio-plugin.so 8 12582922 pulseaudio "PulseAudio Plugin" "Adjust the audio volume of the PulseAudio sound system"
  • udisksd New Fork (PID: 6368, Parent: 799)
  • dumpe2fs (PID: 6368, Parent: 799, MD5: 5c66f7d8f7681a40562cf049ad4b72b4) Arguments: dumpe2fs -h /dev/dm-0
  • systemd New Fork (PID: 6374, Parent: 1)
  • upowerd (PID: 6374, Parent: 1, MD5: 1253eea2fe5fe4017069664284e326cd) Arguments: /usr/lib/upower/upowerd
  • wrapper-2.0 (PID: 6415, Parent: 2063, MD5: ac0b8a906f359a8ae102244738682e76) Arguments: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libxfce4powermanager.so 9 12582923 power-manager-plugin "Power Manager Plugin" "Display the battery levels of your devices and control the brightness of your display"
  • sh (PID: 6422, Parent: 1477, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-media-keys
  • gsd-media-keys (PID: 6422, Parent: 1477, MD5: a425448c135afb4b8bfd79cc0b6b74da) Arguments: /usr/libexec/gsd-media-keys
  • wrapper-2.0 (PID: 6423, Parent: 2063, MD5: ac0b8a906f359a8ae102244738682e76) Arguments: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libnotification-plugin.so 10 12582924 notification-plugin "Notification Plugin" "Notification plugin for the Xfce panel"
  • sh (PID: 6424, Parent: 1477, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-screensaver-proxy
  • gsd-screensaver-proxy (PID: 6424, Parent: 1477, MD5: 77e309450c87dceee43f1a9e50cc0d02) Arguments: /usr/libexec/gsd-screensaver-proxy
  • systemd New Fork (PID: 6426, Parent: 1)
  • upowerd (PID: 6426, Parent: 1, MD5: 1253eea2fe5fe4017069664284e326cd) Arguments: /usr/lib/upower/upowerd
  • wrapper-2.0 (PID: 6458, Parent: 2063, MD5: ac0b8a906f359a8ae102244738682e76) Arguments: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libactions.so 14 12582925 actions "Action Buttons" "Log out, lock or other system actions"
  • sh (PID: 6465, Parent: 1477, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-a11y-settings
  • gsd-a11y-settings (PID: 6465, Parent: 1477, MD5: 18e243d2cf30ecee7ea89d1462725c5c) Arguments: /usr/libexec/gsd-a11y-settings
  • udisksd New Fork (PID: 6467, Parent: 799)
  • dumpe2fs (PID: 6467, Parent: 799, MD5: 5c66f7d8f7681a40562cf049ad4b72b4) Arguments: dumpe2fs -h /dev/dm-0
  • sh (PID: 6468, Parent: 1477, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-housekeeping
  • gsd-housekeeping (PID: 6468, Parent: 1477, MD5: b55f3394a84976ddb92a2915e5d76914) Arguments: /usr/libexec/gsd-housekeeping
  • sh (PID: 6469, Parent: 1477, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-power
  • gsd-power (PID: 6469, Parent: 1477, MD5: 28b8e1b43c3e7f1db6741ea1ecd978b7) Arguments: /usr/libexec/gsd-power
  • systemd New Fork (PID: 6472, Parent: 1)
  • upowerd (PID: 6472, Parent: 1, MD5: 1253eea2fe5fe4017069664284e326cd) Arguments: /usr/lib/upower/upowerd
  • systemd New Fork (PID: 6512, Parent: 1)
  • upowerd (PID: 6512, Parent: 1, MD5: 1253eea2fe5fe4017069664284e326cd) Arguments: /usr/lib/upower/upowerd
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
MiraiMirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese. Nowadays it targets a wide range of networked embedded devices such as IP cameras, home routers (many vendors involved), and other IoT devices. Since the source code was published on "Hack Forums" many variants of the Mirai family appeared, infecting mostly home networks all around the world.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/elf.mirai
No yara matches
TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
2024-10-08T09:55:44.489649+020020304901Malware Command and Control Activity Detected192.168.2.234660293.123.39.11651511TCP
2024-10-08T09:56:46.243721+020020304901Malware Command and Control Activity Detected192.168.2.234660493.123.39.11651511TCP
2024-10-08T09:57:09.626300+020020304901Malware Command and Control Activity Detected192.168.2.234660693.123.39.11651511TCP
2024-10-08T09:57:41.652289+020020304901Malware Command and Control Activity Detected192.168.2.234660893.123.39.11651511TCP
2024-10-08T09:58:08.056399+020020304901Malware Command and Control Activity Detected192.168.2.234661093.123.39.11651511TCP
2024-10-08T09:58:36.473711+020020304901Malware Command and Control Activity Detected192.168.2.234661293.123.39.11651511TCP
2024-10-08T09:59:01.850884+020020304901Malware Command and Control Activity Detected192.168.2.234661493.123.39.11651511TCP
TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
2024-10-08T09:55:45.163449+020020304891Malware Command and Control Activity Detected93.123.39.11651511192.168.2.2346602TCP
2024-10-08T09:56:03.186025+020020304891Malware Command and Control Activity Detected93.123.39.11651511192.168.2.2346602TCP
2024-10-08T09:56:23.207555+020020304891Malware Command and Control Activity Detected93.123.39.11651511192.168.2.2346602TCP

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: na.elfAvira: detected
Source: na.elfReversingLabs: Detection: 55%
Source: na.elfVirustotal: Detection: 67%Perma Link

Networking

barindex
Source: Network trafficSuricata IDS: 2030490 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) : 192.168.2.23:46604 -> 93.123.39.116:51511
Source: Network trafficSuricata IDS: 2030490 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) : 192.168.2.23:46608 -> 93.123.39.116:51511
Source: Network trafficSuricata IDS: 2030490 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) : 192.168.2.23:46602 -> 93.123.39.116:51511
Source: Network trafficSuricata IDS: 2030489 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant Server Response : 93.123.39.116:51511 -> 192.168.2.23:46602
Source: Network trafficSuricata IDS: 2030490 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) : 192.168.2.23:46610 -> 93.123.39.116:51511
Source: Network trafficSuricata IDS: 2030490 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) : 192.168.2.23:46612 -> 93.123.39.116:51511
Source: Network trafficSuricata IDS: 2030490 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) : 192.168.2.23:46606 -> 93.123.39.116:51511
Source: Network trafficSuricata IDS: 2030490 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) : 192.168.2.23:46614 -> 93.123.39.116:51511
Source: global trafficTCP traffic: 192.168.2.23:46602 -> 93.123.39.116:51511
Source: /tmp/na.elf (PID: 6220)Socket: 127.0.0.1:6628Jump to behavior
Source: global trafficTCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
Source: global trafficTCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
Source: global trafficTCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: global trafficDNS traffic detected: DNS query: fdh32fsdfhs.shop
Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443

System Summary

barindex
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 789, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 796, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 799, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 1349, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 1389, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 1463, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 1465, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 1477, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 1489, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 1579, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 1582, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 1586, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 1594, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 1599, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 1622, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 1623, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 1627, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 1629, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 1632, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 1633, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 1638, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 1639, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 1642, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 1648, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 1654, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 1656, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 1661, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 1664, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 1668, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 1698, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 1699, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 1809, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 1888, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 1890, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 2009, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 2018, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 2033, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 2038, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 2077, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 2078, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 2079, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 2080, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 2083, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 2084, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 2114, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 2128, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 2129, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 2146, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 2156, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 2180, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 2195, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 2208, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 2226, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 2235, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 2242, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 2275, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 2281, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 2285, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 2289, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 2294, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 2307, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 2637, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 3236, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 6292, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 6293, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 6352, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 6355, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 6358, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 6360, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 6361, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 6364, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 6367, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 6373, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 6374, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 6363, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 6366, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 6415, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 6423, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 6425, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 6422, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 6424, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 6426, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 6458, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 6465, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 6468, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 6469, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 6472, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 6512, result: successfulJump to behavior
Source: Initial sampleString containing 'busybox' found: /bin/busybox
Source: Initial sampleString containing 'busybox' found: //proc/self/exe/bin/busybox/proc/%d/etc/systmp.d/proc//exe%s/lib/systemd/usr/lib/systemd/systemd/usr/libexec/openssh/sftp-server/usr/lib/openssh/sftp-server/sys/system/dvr/main/usr/mnt/mtd/org/userfs/home/process/net_process/var/tmp/sonia/usr/sbin/usr/bin/mnt/gm/bin/var/Sofia/usr/sbin/sshd/usr/sbin/ntpd/usr/sbin/cupsd/usr/lib/apt/methods/http/usr/sbin/crond/usr/sbin/rsyslogd/usr/sbin/inetd/usr/sbin/dnsmasq/usr/bin/DVRServer/usr/bin/DVRShell/usr/bin/DVRControl/usr/bin/DVRRemoteAgent/usr/bin/DVRNetService/root/binw
Source: ELF static info symbol of initial sample.symtab present: no
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 789, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 796, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 799, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 1349, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 1389, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 1463, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 1465, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 1477, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 1489, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 1579, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 1582, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 1586, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 1594, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 1599, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 1622, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 1623, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 1627, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 1629, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 1632, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 1633, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 1638, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 1639, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 1642, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 1648, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 1654, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 1656, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 1661, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 1664, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 1668, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 1698, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 1699, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 1809, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 1888, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 1890, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 2009, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 2018, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 2033, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 2038, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 2077, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 2078, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 2079, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 2080, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 2083, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 2084, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 2114, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 2128, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 2129, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 2146, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 2156, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 2180, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 2195, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 2208, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 2226, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 2235, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 2242, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 2275, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 2281, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 2285, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 2289, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 2294, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 2307, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 2637, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 3236, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 6292, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 6293, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 6352, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 6355, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 6358, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 6360, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 6361, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 6364, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 6367, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 6373, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 6374, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 6363, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 6366, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 6415, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 6423, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 6425, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 6422, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 6424, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 6426, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 6458, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 6465, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 6468, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 6469, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 6472, result: successfulJump to behavior
Source: /tmp/na.elf (PID: 6222)SIGKILL sent: pid: 6512, result: successfulJump to behavior
Source: classification engineClassification label: mal80.spre.troj.linELF@0/0@7/0

Persistence and Installation Behavior

barindex
Source: /bin/fusermount (PID: 6359)File: /proc/6359/mountsJump to behavior
Source: /tmp/na.elf (PID: 6220)Queries kernel information via 'uname': Jump to behavior
Source: /tmp/na.elf (PID: 6224)Queries kernel information via 'uname': Jump to behavior
Source: na.elf, 6220.1.00007fffd569c000.00007fffd56bd000.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-mips/tmp/na.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/na.elf
Source: na.elf, 6220.1.000055f1e20aa000.000055f1e2131000.rw-.sdmpBinary or memory string: U!/etc/qemu-binfmt/mips
Source: na.elf, 6220.1.000055f1e20aa000.000055f1e2131000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/mips
Source: na.elf, 6220.1.00007fffd569c000.00007fffd56bd000.rw-.sdmpBinary or memory string: /usr/bin/qemu-mips

Remote Access Functionality

barindex
Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)
Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)
Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)
Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant Server Response
Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)
Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant Server Response
Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant Server Response
Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)
Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)
Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath InterceptionDirect Volume AccessOS Credential Dumping11
Security Software Discovery
Remote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network Medium1
Service Stop
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS Memory1
File and Directory Discovery
Remote Desktop ProtocolData from Removable Media1
Non-Standard Port
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
Non-Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture2
Application Layer Protocol
Traffic DuplicationData Destruction
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
na.elf55%ReversingLabsLinux.Backdoor.Mirai
na.elf67%VirustotalBrowse
na.elf100%AviraLINUX/Mirai.bonb
No Antivirus matches
SourceDetectionScannerLabelLink
fdh32fsdfhs.shop15%VirustotalBrowse
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
fdh32fsdfhs.shop
93.123.39.116
truetrueunknown
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs
IPDomainCountryFlagASNASN NameMalicious
93.123.39.116
fdh32fsdfhs.shopBulgaria
43561NET1-ASBGtrue
109.202.202.202
unknownSwitzerland
13030INIT7CHfalse
91.189.91.43
unknownUnited Kingdom
41231CANONICAL-ASGBfalse
91.189.91.42
unknownUnited Kingdom
41231CANONICAL-ASGBfalse
MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
109.202.202.202kpLwzBouH4.elfGet hashmaliciousUnknownBrowse
  • ch.archive.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_92.0%2bbuild3-0ubuntu0.20.04.1_amd64.deb
91.189.91.43na.elfGet hashmaliciousUnknownBrowse
    na.elfGet hashmaliciousUnknownBrowse
      na.elfGet hashmaliciousMiraiBrowse
        na.elfGet hashmaliciousMiraiBrowse
          na.elfGet hashmaliciousUnknownBrowse
            r3M3VGE5AG.elfGet hashmaliciousUnknownBrowse
              l8XbwyLvrK.elfGet hashmaliciousMirai, GafgytBrowse
                arm7.elfGet hashmaliciousMiraiBrowse
                  SecuriteInfo.com.ELF.Mirai-CVD.31968.3467.elfGet hashmaliciousUnknownBrowse
                    SecuriteInfo.com.ELF.Mirai-CVD.12952.14309.elfGet hashmaliciousUnknownBrowse
                      91.189.91.42na.elfGet hashmaliciousUnknownBrowse
                        na.elfGet hashmaliciousUnknownBrowse
                          na.elfGet hashmaliciousMiraiBrowse
                            na.elfGet hashmaliciousMiraiBrowse
                              na.elfGet hashmaliciousUnknownBrowse
                                r3M3VGE5AG.elfGet hashmaliciousUnknownBrowse
                                  l8XbwyLvrK.elfGet hashmaliciousMirai, GafgytBrowse
                                    arm7.elfGet hashmaliciousMiraiBrowse
                                      SecuriteInfo.com.ELF.Mirai-CVD.31968.3467.elfGet hashmaliciousUnknownBrowse
                                        SecuriteInfo.com.ELF.Mirai-CVD.12952.14309.elfGet hashmaliciousUnknownBrowse
                                          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                          fdh32fsdfhs.shopi586.elfGet hashmaliciousMiraiBrowse
                                          • 185.196.9.5
                                          i686.elfGet hashmaliciousMiraiBrowse
                                          • 185.196.9.5
                                          i686nk.elfGet hashmaliciousMiraiBrowse
                                          • 185.196.9.5
                                          mips.elfGet hashmaliciousMiraiBrowse
                                          • 185.196.9.5
                                          mipsel.elfGet hashmaliciousMiraiBrowse
                                          • 185.196.9.5
                                          mipselnk.elfGet hashmaliciousMiraiBrowse
                                          • 185.196.9.5
                                          mipsnk.elfGet hashmaliciousMiraiBrowse
                                          • 185.196.9.5
                                          x86_64.elfGet hashmaliciousMiraiBrowse
                                          • 185.196.9.5
                                          arm6.elfGet hashmaliciousMiraiBrowse
                                          • 185.196.9.5
                                          arm.elfGet hashmaliciousMiraiBrowse
                                          • 185.196.9.5
                                          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                          CANONICAL-ASGBna.elfGet hashmaliciousUnknownBrowse
                                          • 91.189.91.42
                                          na.elfGet hashmaliciousUnknownBrowse
                                          • 91.189.91.42
                                          na.elfGet hashmaliciousMiraiBrowse
                                          • 185.125.190.26
                                          na.elfGet hashmaliciousMiraiBrowse
                                          • 91.189.91.42
                                          na.elfGet hashmaliciousMiraiBrowse
                                          • 91.189.91.42
                                          na.elfGet hashmaliciousUnknownBrowse
                                          • 91.189.91.42
                                          r3M3VGE5AG.elfGet hashmaliciousUnknownBrowse
                                          • 91.189.91.42
                                          l8XbwyLvrK.elfGet hashmaliciousMirai, GafgytBrowse
                                          • 91.189.91.42
                                          arm7.elfGet hashmaliciousMiraiBrowse
                                          • 91.189.91.42
                                          x86.elfGet hashmaliciousUnknownBrowse
                                          • 185.125.190.26
                                          CANONICAL-ASGBna.elfGet hashmaliciousUnknownBrowse
                                          • 91.189.91.42
                                          na.elfGet hashmaliciousUnknownBrowse
                                          • 91.189.91.42
                                          na.elfGet hashmaliciousMiraiBrowse
                                          • 185.125.190.26
                                          na.elfGet hashmaliciousMiraiBrowse
                                          • 91.189.91.42
                                          na.elfGet hashmaliciousMiraiBrowse
                                          • 91.189.91.42
                                          na.elfGet hashmaliciousUnknownBrowse
                                          • 91.189.91.42
                                          r3M3VGE5AG.elfGet hashmaliciousUnknownBrowse
                                          • 91.189.91.42
                                          l8XbwyLvrK.elfGet hashmaliciousMirai, GafgytBrowse
                                          • 91.189.91.42
                                          arm7.elfGet hashmaliciousMiraiBrowse
                                          • 91.189.91.42
                                          x86.elfGet hashmaliciousUnknownBrowse
                                          • 185.125.190.26
                                          NET1-ASBGarm7.elfGet hashmaliciousMiraiBrowse
                                          • 93.123.39.105
                                          x86.elfGet hashmaliciousUnknownBrowse
                                          • 93.123.39.105
                                          k4STQvJ6rV.vbsGet hashmaliciousXWormBrowse
                                          • 93.123.39.76
                                          https://swissquotech.com/swissquote-2024.zipGet hashmaliciousPhisherBrowse
                                          • 87.121.45.6
                                          mipsel.nn.elfGet hashmaliciousOkiruBrowse
                                          • 93.123.85.166
                                          arm7.nn.elfGet hashmaliciousMirai, OkiruBrowse
                                          • 93.123.85.166
                                          x86_32.nn.elfGet hashmaliciousOkiruBrowse
                                          • 93.123.85.166
                                          x86_64.nn.elfGet hashmaliciousOkiruBrowse
                                          • 93.123.85.166
                                          mips.nn.elfGet hashmaliciousOkiruBrowse
                                          • 93.123.85.166
                                          arm5.nn.elfGet hashmaliciousOkiruBrowse
                                          • 93.123.85.166
                                          INIT7CHna.elfGet hashmaliciousUnknownBrowse
                                          • 109.202.202.202
                                          na.elfGet hashmaliciousUnknownBrowse
                                          • 109.202.202.202
                                          na.elfGet hashmaliciousMiraiBrowse
                                          • 109.202.202.202
                                          na.elfGet hashmaliciousMiraiBrowse
                                          • 109.202.202.202
                                          na.elfGet hashmaliciousUnknownBrowse
                                          • 109.202.202.202
                                          r3M3VGE5AG.elfGet hashmaliciousUnknownBrowse
                                          • 109.202.202.202
                                          l8XbwyLvrK.elfGet hashmaliciousMirai, GafgytBrowse
                                          • 109.202.202.202
                                          arm7.elfGet hashmaliciousMiraiBrowse
                                          • 109.202.202.202
                                          SecuriteInfo.com.ELF.Mirai-CVD.31968.3467.elfGet hashmaliciousUnknownBrowse
                                          • 109.202.202.202
                                          SecuriteInfo.com.ELF.Mirai-CVD.12952.14309.elfGet hashmaliciousUnknownBrowse
                                          • 109.202.202.202
                                          No context
                                          No context
                                          No created / dropped files found
                                          File type:ELF 32-bit MSB executable, MIPS, MIPS-I version 1 (SYSV), statically linked, stripped
                                          Entropy (8bit):5.515007807447613
                                          TrID:
                                          • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                                          File name:na.elf
                                          File size:68'512 bytes
                                          MD5:c3f8d3cb4762fd27d6626a7d6c33d2e7
                                          SHA1:2a7d3a7e349e478ef071d46635a3c736aa0bc332
                                          SHA256:596613b25032e7529bb64dd157734647cb0ed09a199890625419edf87c6f1ac9
                                          SHA512:4c2f7caefd58c3a36eecec36e4a4cf85b60f1a1e71995dedef405224ce7a6b2fdcfd0440b145837bfd75d75aeb0001d6547fe0a28d72a67fab4fa784d77b3c74
                                          SSDEEP:1536:ZEsl9JVBEBsM5JiJx32ln0jly5qT7eOBNlYu:ZzfJYBd5Ji332ln0jly5qTHNlb
                                          TLSH:2D63B65D6E329FEDFBAC863047B34A20A798339527E1D684D29CC6002F7028D645FBA4
                                          File Content Preview:.ELF.....................@.`...4.........4. ...(.............@...@...........................E...E.....@..-X........dt.Q............................<...'......!'.......................<...'......!... ....'9... ......................<...'......!........'9.

                                          ELF header

                                          Class:ELF32
                                          Data:2's complement, big endian
                                          Version:1 (current)
                                          Machine:MIPS R3000
                                          Version Number:0x1
                                          Type:EXEC (Executable file)
                                          OS/ABI:UNIX - System V
                                          ABI Version:0
                                          Entry Point Address:0x400260
                                          Flags:0x1007
                                          ELF Header Size:52
                                          Program Header Offset:52
                                          Program Header Size:32
                                          Number of Program Headers:3
                                          Section Header Offset:67992
                                          Section Header Size:40
                                          Number of Section Headers:13
                                          Header String Table Index:12
                                          NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                          NULL0x00x00x00x00x0000
                                          .initPROGBITS0x4000940x940x8c0x00x6AX004
                                          .textPROGBITS0x4001200x1200xe3900x00x6AX0016
                                          .finiPROGBITS0x40e4b00xe4b00x5c0x00x6AX004
                                          .rodataPROGBITS0x40e5100xe5100x1a700x00x2A0016
                                          .ctorsPROGBITS0x4500000x100000x80x00x3WA004
                                          .dtorsPROGBITS0x4500080x100080x80x00x3WA004
                                          .data.rel.roPROGBITS0x4500140x100140x840x00x3WA004
                                          .dataPROGBITS0x4500a00x100a00x3e00x00x3WA0016
                                          .gotPROGBITS0x4504800x104800x4c00x40x10000003WAp0016
                                          .sbssNOBITS0x4509400x109400x240x00x10000003WAp004
                                          .bssNOBITS0x4509700x109400x23e80x00x3WA0016
                                          .shstrtabSTRTAB0x00x109400x560x00x0001
                                          TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                          LOAD0x00x4000000x4000000xff800xff805.56400x5R E0x10000.init .text .fini .rodata
                                          LOAD0x100000x4500000x4500000x9400x2d583.73760x6RW 0x10000.ctors .dtors .data.rel.ro .data .got .sbss .bss
                                          GNU_STACK0x00x00x00x00x00.00000x7RWE0x4
                                          TimestampSIDSignatureSeveritySource IPSource PortDest IPDest PortProtocol
                                          2024-10-08T09:55:44.489649+02002030490ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)1192.168.2.234660293.123.39.11651511TCP
                                          2024-10-08T09:55:45.163449+02002030489ET MALWARE ELF/MooBot Mirai DDoS Variant Server Response193.123.39.11651511192.168.2.2346602TCP
                                          2024-10-08T09:56:03.186025+02002030489ET MALWARE ELF/MooBot Mirai DDoS Variant Server Response193.123.39.11651511192.168.2.2346602TCP
                                          2024-10-08T09:56:23.207555+02002030489ET MALWARE ELF/MooBot Mirai DDoS Variant Server Response193.123.39.11651511192.168.2.2346602TCP
                                          2024-10-08T09:56:46.243721+02002030490ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)1192.168.2.234660493.123.39.11651511TCP
                                          2024-10-08T09:57:09.626300+02002030490ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)1192.168.2.234660693.123.39.11651511TCP
                                          2024-10-08T09:57:41.652289+02002030490ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)1192.168.2.234660893.123.39.11651511TCP
                                          2024-10-08T09:58:08.056399+02002030490ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)1192.168.2.234661093.123.39.11651511TCP
                                          2024-10-08T09:58:36.473711+02002030490ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)1192.168.2.234661293.123.39.11651511TCP
                                          2024-10-08T09:59:01.850884+02002030490ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)1192.168.2.234661493.123.39.11651511TCP
                                          TimestampSource PortDest PortSource IPDest IP
                                          Oct 8, 2024 09:55:43.696624041 CEST43928443192.168.2.2391.189.91.42
                                          Oct 8, 2024 09:55:44.448931932 CEST4660251511192.168.2.2393.123.39.116
                                          Oct 8, 2024 09:55:44.454212904 CEST515114660293.123.39.116192.168.2.23
                                          Oct 8, 2024 09:55:44.454278946 CEST4660251511192.168.2.2393.123.39.116
                                          Oct 8, 2024 09:55:44.489649057 CEST4660251511192.168.2.2393.123.39.116
                                          Oct 8, 2024 09:55:44.494581938 CEST515114660293.123.39.116192.168.2.23
                                          Oct 8, 2024 09:55:45.163449049 CEST515114660293.123.39.116192.168.2.23
                                          Oct 8, 2024 09:55:45.163513899 CEST4660251511192.168.2.2393.123.39.116
                                          Oct 8, 2024 09:55:49.327867985 CEST42836443192.168.2.2391.189.91.43
                                          Oct 8, 2024 09:55:50.351713896 CEST4251680192.168.2.23109.202.202.202
                                          Oct 8, 2024 09:55:55.167105913 CEST4660251511192.168.2.2393.123.39.116
                                          Oct 8, 2024 09:55:55.172347069 CEST515114660293.123.39.116192.168.2.23
                                          Oct 8, 2024 09:56:03.186024904 CEST515114660293.123.39.116192.168.2.23
                                          Oct 8, 2024 09:56:03.186193943 CEST4660251511192.168.2.2393.123.39.116
                                          Oct 8, 2024 09:56:05.453630924 CEST43928443192.168.2.2391.189.91.42
                                          Oct 8, 2024 09:56:15.692198038 CEST42836443192.168.2.2391.189.91.43
                                          Oct 8, 2024 09:56:19.787681103 CEST4251680192.168.2.23109.202.202.202
                                          Oct 8, 2024 09:56:23.207555056 CEST515114660293.123.39.116192.168.2.23
                                          Oct 8, 2024 09:56:23.207648039 CEST4660251511192.168.2.2393.123.39.116
                                          Oct 8, 2024 09:56:40.216161966 CEST515114660293.123.39.116192.168.2.23
                                          Oct 8, 2024 09:56:40.216619015 CEST4660251511192.168.2.2393.123.39.116
                                          Oct 8, 2024 09:56:40.221472979 CEST515114660293.123.39.116192.168.2.23
                                          Oct 8, 2024 09:56:46.236943960 CEST4660451511192.168.2.2393.123.39.116
                                          Oct 8, 2024 09:56:46.242120981 CEST515114660493.123.39.116192.168.2.23
                                          Oct 8, 2024 09:56:46.242199898 CEST4660451511192.168.2.2393.123.39.116
                                          Oct 8, 2024 09:56:46.243721008 CEST4660451511192.168.2.2393.123.39.116
                                          Oct 8, 2024 09:56:46.248495102 CEST515114660493.123.39.116192.168.2.23
                                          Oct 8, 2024 09:56:46.407928944 CEST43928443192.168.2.2391.189.91.42
                                          Oct 8, 2024 09:57:07.611759901 CEST515114660493.123.39.116192.168.2.23
                                          Oct 8, 2024 09:57:07.611989021 CEST4660451511192.168.2.2393.123.39.116
                                          Oct 8, 2024 09:57:07.616909981 CEST515114660493.123.39.116192.168.2.23
                                          Oct 8, 2024 09:57:09.620719910 CEST4660651511192.168.2.2393.123.39.116
                                          Oct 8, 2024 09:57:09.625694990 CEST515114660693.123.39.116192.168.2.23
                                          Oct 8, 2024 09:57:09.625750065 CEST4660651511192.168.2.2393.123.39.116
                                          Oct 8, 2024 09:57:09.626300097 CEST4660651511192.168.2.2393.123.39.116
                                          Oct 8, 2024 09:57:09.631211042 CEST515114660693.123.39.116192.168.2.23
                                          Oct 8, 2024 09:57:19.635126114 CEST4660651511192.168.2.2393.123.39.116
                                          Oct 8, 2024 09:57:19.640511036 CEST515114660693.123.39.116192.168.2.23
                                          Oct 8, 2024 09:57:31.635833025 CEST515114660693.123.39.116192.168.2.23
                                          Oct 8, 2024 09:57:31.635909081 CEST515114660693.123.39.116192.168.2.23
                                          Oct 8, 2024 09:57:31.635982037 CEST4660651511192.168.2.2393.123.39.116
                                          Oct 8, 2024 09:57:31.636149883 CEST4660651511192.168.2.2393.123.39.116
                                          Oct 8, 2024 09:57:31.636198044 CEST515114660693.123.39.116192.168.2.23
                                          Oct 8, 2024 09:57:31.636269093 CEST4660651511192.168.2.2393.123.39.116
                                          Oct 8, 2024 09:57:31.845863104 CEST4660651511192.168.2.2393.123.39.116
                                          Oct 8, 2024 09:57:31.884478092 CEST515114660693.123.39.116192.168.2.23
                                          Oct 8, 2024 09:57:31.884684086 CEST4660651511192.168.2.2393.123.39.116
                                          Oct 8, 2024 09:57:32.057641983 CEST4660651511192.168.2.2393.123.39.116
                                          Oct 8, 2024 09:57:32.118391037 CEST515114660693.123.39.116192.168.2.23
                                          Oct 8, 2024 09:57:32.120978117 CEST515114660693.123.39.116192.168.2.23
                                          Oct 8, 2024 09:57:32.121105909 CEST4660651511192.168.2.2393.123.39.116
                                          Oct 8, 2024 09:57:32.121356010 CEST515114660693.123.39.116192.168.2.23
                                          Oct 8, 2024 09:57:32.121414900 CEST4660651511192.168.2.2393.123.39.116
                                          Oct 8, 2024 09:57:41.645719051 CEST4660851511192.168.2.2393.123.39.116
                                          Oct 8, 2024 09:57:41.650985003 CEST515114660893.123.39.116192.168.2.23
                                          Oct 8, 2024 09:57:41.651228905 CEST4660851511192.168.2.2393.123.39.116
                                          Oct 8, 2024 09:57:41.652288914 CEST4660851511192.168.2.2393.123.39.116
                                          Oct 8, 2024 09:57:41.657279968 CEST515114660893.123.39.116192.168.2.23
                                          Oct 8, 2024 09:58:03.038808107 CEST515114660893.123.39.116192.168.2.23
                                          Oct 8, 2024 09:58:03.039314985 CEST4660851511192.168.2.2393.123.39.116
                                          Oct 8, 2024 09:58:03.044521093 CEST515114660893.123.39.116192.168.2.23
                                          Oct 8, 2024 09:58:08.049561977 CEST4661051511192.168.2.2393.123.39.116
                                          Oct 8, 2024 09:58:08.055727959 CEST515114661093.123.39.116192.168.2.23
                                          Oct 8, 2024 09:58:08.055775881 CEST4661051511192.168.2.2393.123.39.116
                                          Oct 8, 2024 09:58:08.056399107 CEST4661051511192.168.2.2393.123.39.116
                                          Oct 8, 2024 09:58:08.062200069 CEST515114661093.123.39.116192.168.2.23
                                          Oct 8, 2024 09:58:29.455112934 CEST515114661093.123.39.116192.168.2.23
                                          Oct 8, 2024 09:58:29.455545902 CEST4661051511192.168.2.2393.123.39.116
                                          Oct 8, 2024 09:58:29.460983038 CEST515114661093.123.39.116192.168.2.23
                                          Oct 8, 2024 09:58:36.467864037 CEST4661251511192.168.2.2393.123.39.116
                                          Oct 8, 2024 09:58:36.472738981 CEST515114661293.123.39.116192.168.2.23
                                          Oct 8, 2024 09:58:36.472791910 CEST4661251511192.168.2.2393.123.39.116
                                          Oct 8, 2024 09:58:36.473711014 CEST4661251511192.168.2.2393.123.39.116
                                          Oct 8, 2024 09:58:36.478473902 CEST515114661293.123.39.116192.168.2.23
                                          Oct 8, 2024 09:58:46.482532024 CEST4661251511192.168.2.2393.123.39.116
                                          Oct 8, 2024 09:58:46.487943888 CEST515114661293.123.39.116192.168.2.23
                                          Oct 8, 2024 09:58:57.831271887 CEST515114661293.123.39.116192.168.2.23
                                          Oct 8, 2024 09:58:57.831528902 CEST4661251511192.168.2.2393.123.39.116
                                          Oct 8, 2024 09:58:57.836987019 CEST515114661293.123.39.116192.168.2.23
                                          Oct 8, 2024 09:59:01.842700958 CEST4661451511192.168.2.2393.123.39.116
                                          Oct 8, 2024 09:59:01.848732948 CEST515114661493.123.39.116192.168.2.23
                                          Oct 8, 2024 09:59:01.849109888 CEST4661451511192.168.2.2393.123.39.116
                                          Oct 8, 2024 09:59:01.850883961 CEST4661451511192.168.2.2393.123.39.116
                                          Oct 8, 2024 09:59:01.855943918 CEST515114661493.123.39.116192.168.2.23
                                          TimestampSource PortDest PortSource IPDest IP
                                          Oct 8, 2024 09:55:44.409923077 CEST6047553192.168.2.238.8.8.8
                                          Oct 8, 2024 09:55:44.439930916 CEST53604758.8.8.8192.168.2.23
                                          Oct 8, 2024 09:56:46.220021963 CEST4077353192.168.2.238.8.8.8
                                          Oct 8, 2024 09:56:46.236118078 CEST53407738.8.8.8192.168.2.23
                                          Oct 8, 2024 09:57:09.613114119 CEST5181253192.168.2.238.8.8.8
                                          Oct 8, 2024 09:57:09.620398998 CEST53518128.8.8.8192.168.2.23
                                          Oct 8, 2024 09:57:41.637854099 CEST4000353192.168.2.238.8.8.8
                                          Oct 8, 2024 09:57:41.645188093 CEST53400038.8.8.8192.168.2.23
                                          Oct 8, 2024 09:58:08.040855885 CEST5895153192.168.2.238.8.8.8
                                          Oct 8, 2024 09:58:08.049109936 CEST53589518.8.8.8192.168.2.23
                                          Oct 8, 2024 09:58:36.460153103 CEST3837853192.168.2.238.8.8.8
                                          Oct 8, 2024 09:58:36.467252970 CEST53383788.8.8.8192.168.2.23
                                          Oct 8, 2024 09:59:01.834928036 CEST4742553192.168.2.238.8.8.8
                                          Oct 8, 2024 09:59:01.841305017 CEST53474258.8.8.8192.168.2.23
                                          TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                          Oct 8, 2024 09:55:44.409923077 CEST192.168.2.238.8.8.80xea0bStandard query (0)fdh32fsdfhs.shopA (IP address)IN (0x0001)false
                                          Oct 8, 2024 09:56:46.220021963 CEST192.168.2.238.8.8.80xe17cStandard query (0)fdh32fsdfhs.shopA (IP address)IN (0x0001)false
                                          Oct 8, 2024 09:57:09.613114119 CEST192.168.2.238.8.8.80x5a14Standard query (0)fdh32fsdfhs.shopA (IP address)IN (0x0001)false
                                          Oct 8, 2024 09:57:41.637854099 CEST192.168.2.238.8.8.80xc98eStandard query (0)fdh32fsdfhs.shopA (IP address)IN (0x0001)false
                                          Oct 8, 2024 09:58:08.040855885 CEST192.168.2.238.8.8.80x3ec5Standard query (0)fdh32fsdfhs.shopA (IP address)IN (0x0001)false
                                          Oct 8, 2024 09:58:36.460153103 CEST192.168.2.238.8.8.80x268cStandard query (0)fdh32fsdfhs.shopA (IP address)IN (0x0001)false
                                          Oct 8, 2024 09:59:01.834928036 CEST192.168.2.238.8.8.80x1d48Standard query (0)fdh32fsdfhs.shopA (IP address)IN (0x0001)false
                                          TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                          Oct 8, 2024 09:55:44.439930916 CEST8.8.8.8192.168.2.230xea0bNo error (0)fdh32fsdfhs.shop93.123.39.116A (IP address)IN (0x0001)false
                                          Oct 8, 2024 09:56:46.236118078 CEST8.8.8.8192.168.2.230xe17cNo error (0)fdh32fsdfhs.shop93.123.39.116A (IP address)IN (0x0001)false
                                          Oct 8, 2024 09:57:09.620398998 CEST8.8.8.8192.168.2.230x5a14No error (0)fdh32fsdfhs.shop93.123.39.116A (IP address)IN (0x0001)false
                                          Oct 8, 2024 09:57:41.645188093 CEST8.8.8.8192.168.2.230xc98eNo error (0)fdh32fsdfhs.shop93.123.39.116A (IP address)IN (0x0001)false
                                          Oct 8, 2024 09:58:08.049109936 CEST8.8.8.8192.168.2.230x3ec5No error (0)fdh32fsdfhs.shop93.123.39.116A (IP address)IN (0x0001)false
                                          Oct 8, 2024 09:58:36.467252970 CEST8.8.8.8192.168.2.230x268cNo error (0)fdh32fsdfhs.shop93.123.39.116A (IP address)IN (0x0001)false
                                          Oct 8, 2024 09:59:01.841305017 CEST8.8.8.8192.168.2.230x1d48No error (0)fdh32fsdfhs.shop93.123.39.116A (IP address)IN (0x0001)false

                                          System Behavior

                                          Start time (UTC):07:55:42
                                          Start date (UTC):08/10/2024
                                          Path:/tmp/na.elf
                                          Arguments:/tmp/na.elf
                                          File size:5777432 bytes
                                          MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                                          Start time (UTC):07:55:42
                                          Start date (UTC):08/10/2024
                                          Path:/tmp/na.elf
                                          Arguments:-
                                          File size:5777432 bytes
                                          MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                                          Start time (UTC):07:55:43
                                          Start date (UTC):08/10/2024
                                          Path:/tmp/na.elf
                                          Arguments:-
                                          File size:5777432 bytes
                                          MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                                          Start time (UTC):07:55:43
                                          Start date (UTC):08/10/2024
                                          Path:/usr/lib/udisks2/udisksd
                                          Arguments:-
                                          File size:483056 bytes
                                          MD5 hash:1d7ae439cc3d82fa6b127671ce037a24

                                          Start time (UTC):07:55:43
                                          Start date (UTC):08/10/2024
                                          Path:/usr/sbin/dumpe2fs
                                          Arguments:dumpe2fs -h /dev/dm-0
                                          File size:31112 bytes
                                          MD5 hash:5c66f7d8f7681a40562cf049ad4b72b4

                                          Start time (UTC):07:55:43
                                          Start date (UTC):08/10/2024
                                          Path:/usr/libexec/gnome-session-binary
                                          Arguments:-
                                          File size:334664 bytes
                                          MD5 hash:d9b90be4f7db60cb3c2d3da6a1d31bfb

                                          Start time (UTC):07:55:43
                                          Start date (UTC):08/10/2024
                                          Path:/bin/sh
                                          Arguments:/bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-sharing
                                          File size:129816 bytes
                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                          Start time (UTC):07:55:43
                                          Start date (UTC):08/10/2024
                                          Path:/usr/libexec/gsd-sharing
                                          Arguments:/usr/libexec/gsd-sharing
                                          File size:35424 bytes
                                          MD5 hash:e29d9025d98590fbb69f89fdbd4438b3

                                          Start time (UTC):07:55:43
                                          Start date (UTC):08/10/2024
                                          Path:/usr/lib/systemd/systemd
                                          Arguments:-
                                          File size:1620224 bytes
                                          MD5 hash:9b2bec7092a40488108543f9334aab75

                                          Start time (UTC):07:55:43
                                          Start date (UTC):08/10/2024
                                          Path:/usr/lib/upower/upowerd
                                          Arguments:/usr/lib/upower/upowerd
                                          File size:260328 bytes
                                          MD5 hash:1253eea2fe5fe4017069664284e326cd

                                          Start time (UTC):07:55:43
                                          Start date (UTC):08/10/2024
                                          Path:/usr/libexec/gnome-session-binary
                                          Arguments:-
                                          File size:334664 bytes
                                          MD5 hash:d9b90be4f7db60cb3c2d3da6a1d31bfb

                                          Start time (UTC):07:55:43
                                          Start date (UTC):08/10/2024
                                          Path:/bin/sh
                                          Arguments:/bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-wacom
                                          File size:129816 bytes
                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                          Start time (UTC):07:55:43
                                          Start date (UTC):08/10/2024
                                          Path:/usr/libexec/gsd-wacom
                                          Arguments:/usr/libexec/gsd-wacom
                                          File size:39520 bytes
                                          MD5 hash:13778dd1a23a4e94ddc17ac9caa4fcc1

                                          Start time (UTC):07:55:43
                                          Start date (UTC):08/10/2024
                                          Path:/usr/libexec/gnome-session-binary
                                          Arguments:-
                                          File size:334664 bytes
                                          MD5 hash:d9b90be4f7db60cb3c2d3da6a1d31bfb

                                          Start time (UTC):07:55:43
                                          Start date (UTC):08/10/2024
                                          Path:/bin/sh
                                          Arguments:/bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-color
                                          File size:129816 bytes
                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                          Start time (UTC):07:55:44
                                          Start date (UTC):08/10/2024
                                          Path:/usr/libexec/gsd-color
                                          Arguments:/usr/libexec/gsd-color
                                          File size:92832 bytes
                                          MD5 hash:ac2861ad93ce047283e8e87cefef9a19

                                          Start time (UTC):07:55:43
                                          Start date (UTC):08/10/2024
                                          Path:/usr/libexec/gnome-session-binary
                                          Arguments:-
                                          File size:334664 bytes
                                          MD5 hash:d9b90be4f7db60cb3c2d3da6a1d31bfb

                                          Start time (UTC):07:55:43
                                          Start date (UTC):08/10/2024
                                          Path:/bin/sh
                                          Arguments:/bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-keyboard
                                          File size:129816 bytes
                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                          Start time (UTC):07:55:44
                                          Start date (UTC):08/10/2024
                                          Path:/usr/libexec/gsd-keyboard
                                          Arguments:/usr/libexec/gsd-keyboard
                                          File size:39760 bytes
                                          MD5 hash:8e288fd17c80bb0a1148b964b2ac2279

                                          Start time (UTC):07:55:43
                                          Start date (UTC):08/10/2024
                                          Path:/usr/libexec/gvfsd-fuse
                                          Arguments:-
                                          File size:47632 bytes
                                          MD5 hash:d18fbf1cbf8eb57b17fac48b7b4be933

                                          Start time (UTC):07:55:43
                                          Start date (UTC):08/10/2024
                                          Path:/bin/fusermount
                                          Arguments:fusermount -u -q -z -- /run/user/1000/gvfs
                                          File size:39144 bytes
                                          MD5 hash:576a1b135c82bdcbc97a91acea900566

                                          Start time (UTC):07:55:44
                                          Start date (UTC):08/10/2024
                                          Path:/usr/libexec/gnome-session-binary
                                          Arguments:-
                                          File size:334664 bytes
                                          MD5 hash:d9b90be4f7db60cb3c2d3da6a1d31bfb

                                          Start time (UTC):07:55:44
                                          Start date (UTC):08/10/2024
                                          Path:/bin/sh
                                          Arguments:/bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-print-notifications
                                          File size:129816 bytes
                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                          Start time (UTC):07:55:44
                                          Start date (UTC):08/10/2024
                                          Path:/usr/libexec/gsd-print-notifications
                                          Arguments:/usr/libexec/gsd-print-notifications
                                          File size:51840 bytes
                                          MD5 hash:71539698aa691718cee775d6b9450ae2

                                          Start time (UTC):07:55:44
                                          Start date (UTC):08/10/2024
                                          Path:/usr/bin/xfce4-panel
                                          Arguments:-
                                          File size:375768 bytes
                                          MD5 hash:a15b657c7d54ac1385f1f15004ea6784

                                          Start time (UTC):07:55:44
                                          Start date (UTC):08/10/2024
                                          Path:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
                                          Arguments:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libsystray.so 6 12582920 systray "Notification Area" "Area where notification icons appear"
                                          File size:35136 bytes
                                          MD5 hash:ac0b8a906f359a8ae102244738682e76

                                          Start time (UTC):07:55:44
                                          Start date (UTC):08/10/2024
                                          Path:/usr/libexec/gnome-session-binary
                                          Arguments:-
                                          File size:334664 bytes
                                          MD5 hash:d9b90be4f7db60cb3c2d3da6a1d31bfb

                                          Start time (UTC):07:55:44
                                          Start date (UTC):08/10/2024
                                          Path:/bin/sh
                                          Arguments:/bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-rfkill
                                          File size:129816 bytes
                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                          Start time (UTC):07:55:44
                                          Start date (UTC):08/10/2024
                                          Path:/usr/libexec/gsd-rfkill
                                          Arguments:/usr/libexec/gsd-rfkill
                                          File size:51808 bytes
                                          MD5 hash:88a16a3c0aba1759358c06215ecfb5cc

                                          Start time (UTC):07:55:44
                                          Start date (UTC):08/10/2024
                                          Path:/usr/bin/xfce4-panel
                                          Arguments:-
                                          File size:375768 bytes
                                          MD5 hash:a15b657c7d54ac1385f1f15004ea6784

                                          Start time (UTC):07:55:44
                                          Start date (UTC):08/10/2024
                                          Path:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
                                          Arguments:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libstatusnotifier.so 7 12582921 statusnotifier "Status Notifier Plugin" "Provides a panel area for status notifier items (application indicators)"
                                          File size:35136 bytes
                                          MD5 hash:ac0b8a906f359a8ae102244738682e76

                                          Start time (UTC):07:55:44
                                          Start date (UTC):08/10/2024
                                          Path:/usr/libexec/gnome-session-binary
                                          Arguments:-
                                          File size:334664 bytes
                                          MD5 hash:d9b90be4f7db60cb3c2d3da6a1d31bfb

                                          Start time (UTC):07:55:44
                                          Start date (UTC):08/10/2024
                                          Path:/bin/sh
                                          Arguments:/bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-smartcard
                                          File size:129816 bytes
                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                          Start time (UTC):07:55:45
                                          Start date (UTC):08/10/2024
                                          Path:/usr/libexec/gsd-smartcard
                                          Arguments:/usr/libexec/gsd-smartcard
                                          File size:109152 bytes
                                          MD5 hash:ea1fbd7f62e4cd0331eae2ef754ee605

                                          Start time (UTC):07:55:44
                                          Start date (UTC):08/10/2024
                                          Path:/usr/bin/xfce4-panel
                                          Arguments:-
                                          File size:375768 bytes
                                          MD5 hash:a15b657c7d54ac1385f1f15004ea6784

                                          Start time (UTC):07:55:44
                                          Start date (UTC):08/10/2024
                                          Path:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
                                          Arguments:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libpulseaudio-plugin.so 8 12582922 pulseaudio "PulseAudio Plugin" "Adjust the audio volume of the PulseAudio sound system"
                                          File size:35136 bytes
                                          MD5 hash:ac0b8a906f359a8ae102244738682e76
                                          Start time (UTC):07:55:44
                                          Start date (UTC):08/10/2024
                                          Path:/usr/lib/udisks2/udisksd
                                          Arguments:-
                                          File size:483056 bytes
                                          MD5 hash:1d7ae439cc3d82fa6b127671ce037a24

                                          Start time (UTC):07:55:44
                                          Start date (UTC):08/10/2024
                                          Path:/usr/sbin/dumpe2fs
                                          Arguments:dumpe2fs -h /dev/dm-0
                                          File size:31112 bytes
                                          MD5 hash:5c66f7d8f7681a40562cf049ad4b72b4

                                          Start time (UTC):07:55:45
                                          Start date (UTC):08/10/2024
                                          Path:/usr/lib/systemd/systemd
                                          Arguments:-
                                          File size:1620224 bytes
                                          MD5 hash:9b2bec7092a40488108543f9334aab75

                                          Start time (UTC):07:55:45
                                          Start date (UTC):08/10/2024
                                          Path:/usr/lib/upower/upowerd
                                          Arguments:/usr/lib/upower/upowerd
                                          File size:260328 bytes
                                          MD5 hash:1253eea2fe5fe4017069664284e326cd

                                          Start time (UTC):07:55:45
                                          Start date (UTC):08/10/2024
                                          Path:/usr/bin/xfce4-panel
                                          Arguments:-
                                          File size:375768 bytes
                                          MD5 hash:a15b657c7d54ac1385f1f15004ea6784

                                          Start time (UTC):07:55:45
                                          Start date (UTC):08/10/2024
                                          Path:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
                                          Arguments:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libxfce4powermanager.so 9 12582923 power-manager-plugin "Power Manager Plugin" "Display the battery levels of your devices and control the brightness of your display"
                                          File size:35136 bytes
                                          MD5 hash:ac0b8a906f359a8ae102244738682e76

                                          Start time (UTC):07:55:45
                                          Start date (UTC):08/10/2024
                                          Path:/usr/libexec/gnome-session-binary
                                          Arguments:-
                                          File size:334664 bytes
                                          MD5 hash:d9b90be4f7db60cb3c2d3da6a1d31bfb

                                          Start time (UTC):07:55:45
                                          Start date (UTC):08/10/2024
                                          Path:/bin/sh
                                          Arguments:/bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-media-keys
                                          File size:129816 bytes
                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                          Start time (UTC):07:55:45
                                          Start date (UTC):08/10/2024
                                          Path:/usr/libexec/gsd-media-keys
                                          Arguments:/usr/libexec/gsd-media-keys
                                          File size:232936 bytes
                                          MD5 hash:a425448c135afb4b8bfd79cc0b6b74da

                                          Start time (UTC):07:55:45
                                          Start date (UTC):08/10/2024
                                          Path:/usr/bin/xfce4-panel
                                          Arguments:-
                                          File size:375768 bytes
                                          MD5 hash:a15b657c7d54ac1385f1f15004ea6784

                                          Start time (UTC):07:55:45
                                          Start date (UTC):08/10/2024
                                          Path:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
                                          Arguments:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libnotification-plugin.so 10 12582924 notification-plugin "Notification Plugin" "Notification plugin for the Xfce panel"
                                          File size:35136 bytes
                                          MD5 hash:ac0b8a906f359a8ae102244738682e76

                                          Start time (UTC):07:55:45
                                          Start date (UTC):08/10/2024
                                          Path:/usr/libexec/gnome-session-binary
                                          Arguments:-
                                          File size:334664 bytes
                                          MD5 hash:d9b90be4f7db60cb3c2d3da6a1d31bfb

                                          Start time (UTC):07:55:45
                                          Start date (UTC):08/10/2024
                                          Path:/bin/sh
                                          Arguments:/bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-screensaver-proxy
                                          File size:129816 bytes
                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                          Start time (UTC):07:55:45
                                          Start date (UTC):08/10/2024
                                          Path:/usr/libexec/gsd-screensaver-proxy
                                          Arguments:/usr/libexec/gsd-screensaver-proxy
                                          File size:27232 bytes
                                          MD5 hash:77e309450c87dceee43f1a9e50cc0d02

                                          Start time (UTC):07:55:45
                                          Start date (UTC):08/10/2024
                                          Path:/usr/lib/systemd/systemd
                                          Arguments:-
                                          File size:1620224 bytes
                                          MD5 hash:9b2bec7092a40488108543f9334aab75

                                          Start time (UTC):07:55:45
                                          Start date (UTC):08/10/2024
                                          Path:/usr/lib/upower/upowerd
                                          Arguments:/usr/lib/upower/upowerd
                                          File size:260328 bytes
                                          MD5 hash:1253eea2fe5fe4017069664284e326cd

                                          Start time (UTC):07:55:45
                                          Start date (UTC):08/10/2024
                                          Path:/usr/bin/xfce4-panel
                                          Arguments:-
                                          File size:375768 bytes
                                          MD5 hash:a15b657c7d54ac1385f1f15004ea6784

                                          Start time (UTC):07:55:45
                                          Start date (UTC):08/10/2024
                                          Path:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
                                          Arguments:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libactions.so 14 12582925 actions "Action Buttons" "Log out, lock or other system actions"
                                          File size:35136 bytes
                                          MD5 hash:ac0b8a906f359a8ae102244738682e76

                                          Start time (UTC):07:55:45
                                          Start date (UTC):08/10/2024
                                          Path:/usr/libexec/gnome-session-binary
                                          Arguments:-
                                          File size:334664 bytes
                                          MD5 hash:d9b90be4f7db60cb3c2d3da6a1d31bfb

                                          Start time (UTC):07:55:45
                                          Start date (UTC):08/10/2024
                                          Path:/bin/sh
                                          Arguments:/bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-a11y-settings
                                          File size:129816 bytes
                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                          Start time (UTC):07:55:45
                                          Start date (UTC):08/10/2024
                                          Path:/usr/libexec/gsd-a11y-settings
                                          Arguments:/usr/libexec/gsd-a11y-settings
                                          File size:23056 bytes
                                          MD5 hash:18e243d2cf30ecee7ea89d1462725c5c

                                          Start time (UTC):07:55:45
                                          Start date (UTC):08/10/2024
                                          Path:/usr/lib/udisks2/udisksd
                                          Arguments:-
                                          File size:483056 bytes
                                          MD5 hash:1d7ae439cc3d82fa6b127671ce037a24

                                          Start time (UTC):07:55:45
                                          Start date (UTC):08/10/2024
                                          Path:/usr/sbin/dumpe2fs
                                          Arguments:dumpe2fs -h /dev/dm-0
                                          File size:31112 bytes
                                          MD5 hash:5c66f7d8f7681a40562cf049ad4b72b4

                                          Start time (UTC):07:55:45
                                          Start date (UTC):08/10/2024
                                          Path:/usr/libexec/gnome-session-binary
                                          Arguments:-
                                          File size:334664 bytes
                                          MD5 hash:d9b90be4f7db60cb3c2d3da6a1d31bfb

                                          Start time (UTC):07:55:45
                                          Start date (UTC):08/10/2024
                                          Path:/bin/sh
                                          Arguments:/bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-housekeeping
                                          File size:129816 bytes
                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                          Start time (UTC):07:55:45
                                          Start date (UTC):08/10/2024
                                          Path:/usr/libexec/gsd-housekeeping
                                          Arguments:/usr/libexec/gsd-housekeeping
                                          File size:51840 bytes
                                          MD5 hash:b55f3394a84976ddb92a2915e5d76914

                                          Start time (UTC):07:55:45
                                          Start date (UTC):08/10/2024
                                          Path:/usr/libexec/gnome-session-binary
                                          Arguments:-
                                          File size:334664 bytes
                                          MD5 hash:d9b90be4f7db60cb3c2d3da6a1d31bfb

                                          Start time (UTC):07:55:45
                                          Start date (UTC):08/10/2024
                                          Path:/bin/sh
                                          Arguments:/bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-power
                                          File size:129816 bytes
                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                          Start time (UTC):07:55:45
                                          Start date (UTC):08/10/2024
                                          Path:/usr/libexec/gsd-power
                                          Arguments:/usr/libexec/gsd-power
                                          File size:88672 bytes
                                          MD5 hash:28b8e1b43c3e7f1db6741ea1ecd978b7

                                          Start time (UTC):07:55:45
                                          Start date (UTC):08/10/2024
                                          Path:/usr/lib/systemd/systemd
                                          Arguments:-
                                          File size:1620224 bytes
                                          MD5 hash:9b2bec7092a40488108543f9334aab75

                                          Start time (UTC):07:55:45
                                          Start date (UTC):08/10/2024
                                          Path:/usr/lib/upower/upowerd
                                          Arguments:/usr/lib/upower/upowerd
                                          File size:260328 bytes
                                          MD5 hash:1253eea2fe5fe4017069664284e326cd

                                          Start time (UTC):07:55:46
                                          Start date (UTC):08/10/2024
                                          Path:/usr/lib/systemd/systemd
                                          Arguments:-
                                          File size:1620224 bytes
                                          MD5 hash:9b2bec7092a40488108543f9334aab75

                                          Start time (UTC):07:55:46
                                          Start date (UTC):08/10/2024
                                          Path:/usr/lib/upower/upowerd
                                          Arguments:/usr/lib/upower/upowerd
                                          File size:260328 bytes
                                          MD5 hash:1253eea2fe5fe4017069664284e326cd