Edit tour
Linux
Analysis Report
na.elf
Overview
General Information
Detection
Mirai
Score: | 80 |
Range: | 0 - 100 |
Whitelisted: | false |
Signatures
Antivirus / Scanner detection for submitted sample
Detected Mirai
Multi AV Scanner detection for submitted file
Suricata IDS alerts for network traffic
Sample reads /proc/mounts (often used for finding a writable filesystem)
Sample tries to kill multiple processes (SIGKILL)
Detected TCP or UDP traffic on non-standard ports
Sample contains strings indicative of BusyBox which embeds multiple Unix commands in a single executable
Sample has stripped symbol table
Sample listens on a socket
Sample tries to kill a process (SIGKILL)
Uses the "uname" system call to query kernel version information (possible evasion)
Classification
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1528727 |
Start date and time: | 2024-10-08 09:58:29 +02:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 4m 58s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultlinuxfilecookbook.jbs |
Analysis system description: | Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11) |
Analysis Mode: | default |
Sample name: | na.elf |
Detection: | MAL |
Classification: | mal80.spre.troj.linELF@0/0@11/0 |
Command: | /tmp/na.elf |
PID: | 5412 |
Exit Code: | 0 |
Exit Code Info: | |
Killed: | False |
Standard Output: | listening to tun0 |
Standard Error: |
- system is lnxubuntu20
- udisksd New Fork (PID: 5426, Parent: 802)
- gnome-session-binary New Fork (PID: 5434, Parent: 1588)
- gnome-session-binary New Fork (PID: 5474, Parent: 1588)
- systemd New Fork (PID: 5480, Parent: 1)
- gnome-session-binary New Fork (PID: 5497, Parent: 1588)
- gvfsd-fuse New Fork (PID: 5508, Parent: 2935)
- gnome-session-binary New Fork (PID: 5521, Parent: 1588)
- gnome-session-binary New Fork (PID: 5551, Parent: 1588)
- xfce4-panel New Fork (PID: 5559, Parent: 3147)
- gnome-session-binary New Fork (PID: 5569, Parent: 1588)
- xfce4-panel New Fork (PID: 5570, Parent: 3147)
- gnome-session-binary New Fork (PID: 5573, Parent: 1588)
- udisksd New Fork (PID: 5576, Parent: 802)
- xfce4-panel New Fork (PID: 5577, Parent: 3147)
- gnome-session-binary New Fork (PID: 5578, Parent: 1588)
- xfce4-panel New Fork (PID: 5579, Parent: 3147)
- gnome-session-binary New Fork (PID: 5580, Parent: 1588)
- xfce4-panel New Fork (PID: 5581, Parent: 3147)
- gnome-session-binary New Fork (PID: 5582, Parent: 1588)
- systemd New Fork (PID: 5583, Parent: 1)
- xfce4-panel New Fork (PID: 5621, Parent: 3147)
- gnome-session-binary New Fork (PID: 5623, Parent: 1588)
- gnome-session-binary New Fork (PID: 5624, Parent: 1588)
- gnome-session-binary New Fork (PID: 5626, Parent: 1588)
- gnome-session-binary New Fork (PID: 5629, Parent: 1588)
- udisksd New Fork (PID: 5631, Parent: 802)
- systemd New Fork (PID: 5632, Parent: 1)
- systemd New Fork (PID: 5674, Parent: 1)
- systemd New Fork (PID: 5714, Parent: 1)
- cleanup
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
Mirai | Mirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese. Nowadays it targets a wide range of networked embedded devices such as IP cameras, home routers (many vendors involved), and other IoT devices. Since the source code was published on "Hack Forums" many variants of the Mirai family appeared, infecting mostly home networks all around the world. | No Attribution |
⊘No yara matches
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-10-08T09:59:17.242468+0200 | 2030490 | 1 | Malware Command and Control Activity Detected | 192.168.2.13 | 45886 | 93.123.39.116 | 51511 | TCP |
2024-10-08T09:59:40.047694+0200 | 2030490 | 1 | Malware Command and Control Activity Detected | 192.168.2.13 | 45888 | 93.123.39.116 | 51511 | TCP |
2024-10-08T10:00:07.509801+0200 | 2030490 | 1 | Malware Command and Control Activity Detected | 192.168.2.13 | 45890 | 93.123.39.116 | 51511 | TCP |
2024-10-08T10:00:33.934771+0200 | 2030490 | 1 | Malware Command and Control Activity Detected | 192.168.2.13 | 45892 | 93.123.39.116 | 51511 | TCP |
2024-10-08T10:01:02.480700+0200 | 2030490 | 1 | Malware Command and Control Activity Detected | 192.168.2.13 | 45894 | 93.123.39.116 | 51511 | TCP |
2024-10-08T10:01:27.868099+0200 | 2030490 | 1 | Malware Command and Control Activity Detected | 192.168.2.13 | 45896 | 93.123.39.116 | 51511 | TCP |
2024-10-08T10:01:55.258977+0200 | 2030490 | 1 | Malware Command and Control Activity Detected | 192.168.2.13 | 45898 | 93.123.39.116 | 51511 | TCP |
2024-10-08T10:02:21.868279+0200 | 2030490 | 1 | Malware Command and Control Activity Detected | 192.168.2.13 | 45900 | 93.123.39.116 | 51511 | TCP |
2024-10-08T10:02:44.259939+0200 | 2030490 | 1 | Malware Command and Control Activity Detected | 192.168.2.13 | 45902 | 93.123.39.116 | 51511 | TCP |
Click to jump to signature section
Show All Signature Results
AV Detection |
---|
Source: | Avira: |
Source: | ReversingLabs: | |||
Source: | Virustotal: | Perma Link |
Networking |
---|
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: |
Source: | TCP traffic: |
Source: | Socket: | Jump to behavior |
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
System Summary |
---|
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior |
Source: | String containing 'busybox' found: | ||
Source: | String containing 'busybox' found: |
Source: | .symtab present: |
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior |
Source: | Classification label: |
Persistence and Installation Behavior |
---|
Source: | File: | Jump to behavior |
Source: | Queries kernel information via 'uname': | Jump to behavior | ||
Source: | Queries kernel information via 'uname': | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Remote Access Functionality |
---|
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | Path Interception | Path Interception | Direct Volume Access | OS Credential Dumping | 11 Security Software Discovery | Remote Services | Data from Local System | 1 Non-Standard Port | Exfiltration Over Other Network Medium | 1 Service Stop |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | Rootkit | LSASS Memory | 1 File and Directory Discovery | Remote Desktop Protocol | Data from Removable Media | 1 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 1 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
⊘No configs have been found
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
58% | ReversingLabs | Linux.Backdoor.Mirai | ||
70% | Virustotal | Browse | ||
100% | Avira | LINUX/Mirai.bonb |
⊘No Antivirus matches
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Virustotal | Browse | ||
15% | Virustotal | Browse |
⊘No Antivirus matches
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
daisy.ubuntu.com | 162.213.35.25 | true | false |
| unknown |
fdh32fsdfhs.shop | 93.123.39.116 | true | true |
| unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
93.123.39.116 | fdh32fsdfhs.shop | Bulgaria | 43561 | NET1-ASBG | true |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
93.123.39.116 | Get hash | malicious | Mirai | Browse | ||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Mirai | Browse |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
daisy.ubuntu.com | Get hash | malicious | Mirai | Browse |
| |
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
fdh32fsdfhs.shop | Get hash | malicious | Mirai | Browse |
| |
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
NET1-ASBG | Get hash | malicious | Mirai | Browse |
| |
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | XWorm | Browse |
| ||
Get hash | malicious | Phisher | Browse |
| ||
Get hash | malicious | Okiru | Browse |
| ||
Get hash | malicious | Mirai, Okiru | Browse |
| ||
Get hash | malicious | Okiru | Browse |
|
⊘No context
⊘No context
⊘No created / dropped files found
File type: | |
Entropy (8bit): | 6.136016358047989 |
TrID: |
|
File name: | na.elf |
File size: | 54'788 bytes |
MD5: | 60b449419991b0995c289daa2f356fa5 |
SHA1: | ce99e2fb8b6de404cecbae9aaaf4a53c945dabdb |
SHA256: | afdb1f2f0776fbdff4ea794aef5637bbc5ef8fd686ada1dc59cebf98cac121f8 |
SHA512: | aed6ef23751329fde0ca9702abfc0527cf32fc3449c51268fdad5143a6c0db232334193d05932ee3b3fcac678f4bdcb8bb54379745445b465bdc9f8a25a9ce99 |
SSDEEP: | 768:VMjYjGiayREhqVlgK1FofLc0twBmrvmSFu7MErHLm30NL/DJFVezt8vBQIo:PjGYVVlgK1gWBmf7oH86LD78x8vKF |
TLSH: | 91334C95B9815613CAC15277FB1E028D3B2A139CE2DF73039E16AF21338B96B0E7B545 |
File Content Preview: | .ELF...a..........(.........4...t.......4. ...(......................................................... '..........Q.td..................................-...L."...s-..........0@-.\P...0....S.0...P@...0... ....R......0...0...........0... ....R..... 0....S |
ELF header | |
---|---|
Class: | |
Data: | |
Version: | |
Machine: | |
Version Number: | |
Type: | |
OS/ABI: | |
ABI Version: | 0 |
Entry Point Address: | |
Flags: | |
ELF Header Size: | 52 |
Program Header Offset: | 52 |
Program Header Size: | 32 |
Number of Program Headers: | 3 |
Section Header Offset: | 54388 |
Section Header Size: | 40 |
Number of Section Headers: | 10 |
Header String Table Index: | 9 |
Name | Type | Address | Offset | Size | EntSize | Flags | Flags Description | Link | Info | Align |
---|---|---|---|---|---|---|---|---|---|---|
NULL | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0 | 0 | 0 | ||
.init | PROGBITS | 0x8094 | 0x94 | 0x18 | 0x0 | 0x6 | AX | 0 | 0 | 4 |
.text | PROGBITS | 0x80b0 | 0xb0 | 0xb604 | 0x0 | 0x6 | AX | 0 | 0 | 16 |
.fini | PROGBITS | 0x136b4 | 0xb6b4 | 0x14 | 0x0 | 0x6 | AX | 0 | 0 | 4 |
.rodata | PROGBITS | 0x136c8 | 0xb6c8 | 0x19b8 | 0x0 | 0x2 | A | 0 | 0 | 4 |
.ctors | PROGBITS | 0x1d084 | 0xd084 | 0x8 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.dtors | PROGBITS | 0x1d08c | 0xd08c | 0x8 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.data | PROGBITS | 0x1d098 | 0xd098 | 0x39c | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.bss | NOBITS | 0x1d434 | 0xd434 | 0x2370 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.shstrtab | STRTAB | 0x0 | 0xd434 | 0x3e | 0x0 | 0x0 | 0 | 0 | 1 |
Type | Offset | Virtual Address | Physical Address | File Size | Memory Size | Entropy | Flags | Flags Description | Align | Prog Interpreter | Section Mappings |
---|---|---|---|---|---|---|---|---|---|---|---|
LOAD | 0x0 | 0x8000 | 0x8000 | 0xd080 | 0xd080 | 6.1797 | 0x5 | R E | 0x8000 | .init .text .fini .rodata | |
LOAD | 0xd084 | 0x1d084 | 0x1d084 | 0x3b0 | 0x2720 | 2.8272 | 0x6 | RW | 0x8000 | .ctors .dtors .data .bss | |
GNU_STACK | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0.0000 | 0x7 | RWE | 0x4 |
Timestamp | SID | Signature | Severity | Source IP | Source Port | Dest IP | Dest Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-10-08T09:59:17.242468+0200 | 2030490 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) | 1 | 192.168.2.13 | 45886 | 93.123.39.116 | 51511 | TCP |
2024-10-08T09:59:40.047694+0200 | 2030490 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) | 1 | 192.168.2.13 | 45888 | 93.123.39.116 | 51511 | TCP |
2024-10-08T10:00:07.509801+0200 | 2030490 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) | 1 | 192.168.2.13 | 45890 | 93.123.39.116 | 51511 | TCP |
2024-10-08T10:00:33.934771+0200 | 2030490 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) | 1 | 192.168.2.13 | 45892 | 93.123.39.116 | 51511 | TCP |
2024-10-08T10:01:02.480700+0200 | 2030490 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) | 1 | 192.168.2.13 | 45894 | 93.123.39.116 | 51511 | TCP |
2024-10-08T10:01:27.868099+0200 | 2030490 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) | 1 | 192.168.2.13 | 45896 | 93.123.39.116 | 51511 | TCP |
2024-10-08T10:01:55.258977+0200 | 2030490 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) | 1 | 192.168.2.13 | 45898 | 93.123.39.116 | 51511 | TCP |
2024-10-08T10:02:21.868279+0200 | 2030490 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) | 1 | 192.168.2.13 | 45900 | 93.123.39.116 | 51511 | TCP |
2024-10-08T10:02:44.259939+0200 | 2030490 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) | 1 | 192.168.2.13 | 45902 | 93.123.39.116 | 51511 | TCP |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Oct 8, 2024 09:59:17.191124916 CEST | 45886 | 51511 | 192.168.2.13 | 93.123.39.116 |
Oct 8, 2024 09:59:17.198019981 CEST | 51511 | 45886 | 93.123.39.116 | 192.168.2.13 |
Oct 8, 2024 09:59:17.198101997 CEST | 45886 | 51511 | 192.168.2.13 | 93.123.39.116 |
Oct 8, 2024 09:59:17.242468119 CEST | 45886 | 51511 | 192.168.2.13 | 93.123.39.116 |
Oct 8, 2024 09:59:17.247705936 CEST | 51511 | 45886 | 93.123.39.116 | 192.168.2.13 |
Oct 8, 2024 09:59:27.248120070 CEST | 45886 | 51511 | 192.168.2.13 | 93.123.39.116 |
Oct 8, 2024 09:59:27.253331900 CEST | 51511 | 45886 | 93.123.39.116 | 192.168.2.13 |
Oct 8, 2024 09:59:38.764843941 CEST | 51511 | 45886 | 93.123.39.116 | 192.168.2.13 |
Oct 8, 2024 09:59:38.765167952 CEST | 45886 | 51511 | 192.168.2.13 | 93.123.39.116 |
Oct 8, 2024 09:59:38.768866062 CEST | 51511 | 45886 | 93.123.39.116 | 192.168.2.13 |
Oct 8, 2024 09:59:38.768929005 CEST | 45886 | 51511 | 192.168.2.13 | 93.123.39.116 |
Oct 8, 2024 09:59:38.770900965 CEST | 51511 | 45886 | 93.123.39.116 | 192.168.2.13 |
Oct 8, 2024 09:59:40.042047024 CEST | 45888 | 51511 | 192.168.2.13 | 93.123.39.116 |
Oct 8, 2024 09:59:40.047050953 CEST | 51511 | 45888 | 93.123.39.116 | 192.168.2.13 |
Oct 8, 2024 09:59:40.047127962 CEST | 45888 | 51511 | 192.168.2.13 | 93.123.39.116 |
Oct 8, 2024 09:59:40.047693968 CEST | 45888 | 51511 | 192.168.2.13 | 93.123.39.116 |
Oct 8, 2024 09:59:40.052725077 CEST | 51511 | 45888 | 93.123.39.116 | 192.168.2.13 |
Oct 8, 2024 10:00:01.481904030 CEST | 51511 | 45888 | 93.123.39.116 | 192.168.2.13 |
Oct 8, 2024 10:00:01.483571053 CEST | 45888 | 51511 | 192.168.2.13 | 93.123.39.116 |
Oct 8, 2024 10:00:01.488816023 CEST | 51511 | 45888 | 93.123.39.116 | 192.168.2.13 |
Oct 8, 2024 10:00:07.503792048 CEST | 45890 | 51511 | 192.168.2.13 | 93.123.39.116 |
Oct 8, 2024 10:00:07.508718014 CEST | 51511 | 45890 | 93.123.39.116 | 192.168.2.13 |
Oct 8, 2024 10:00:07.508783102 CEST | 45890 | 51511 | 192.168.2.13 | 93.123.39.116 |
Oct 8, 2024 10:00:07.509800911 CEST | 45890 | 51511 | 192.168.2.13 | 93.123.39.116 |
Oct 8, 2024 10:00:07.514684916 CEST | 51511 | 45890 | 93.123.39.116 | 192.168.2.13 |
Oct 8, 2024 10:00:28.916980028 CEST | 51511 | 45890 | 93.123.39.116 | 192.168.2.13 |
Oct 8, 2024 10:00:28.917126894 CEST | 45890 | 51511 | 192.168.2.13 | 93.123.39.116 |
Oct 8, 2024 10:00:28.922040939 CEST | 51511 | 45890 | 93.123.39.116 | 192.168.2.13 |
Oct 8, 2024 10:00:33.928275108 CEST | 45892 | 51511 | 192.168.2.13 | 93.123.39.116 |
Oct 8, 2024 10:00:33.933140039 CEST | 51511 | 45892 | 93.123.39.116 | 192.168.2.13 |
Oct 8, 2024 10:00:33.933244944 CEST | 45892 | 51511 | 192.168.2.13 | 93.123.39.116 |
Oct 8, 2024 10:00:33.934771061 CEST | 45892 | 51511 | 192.168.2.13 | 93.123.39.116 |
Oct 8, 2024 10:00:33.939569950 CEST | 51511 | 45892 | 93.123.39.116 | 192.168.2.13 |
Oct 8, 2024 10:00:43.941076994 CEST | 45892 | 51511 | 192.168.2.13 | 93.123.39.116 |
Oct 8, 2024 10:00:43.946381092 CEST | 51511 | 45892 | 93.123.39.116 | 192.168.2.13 |
Oct 8, 2024 10:00:55.305641890 CEST | 51511 | 45892 | 93.123.39.116 | 192.168.2.13 |
Oct 8, 2024 10:00:55.305818081 CEST | 45892 | 51511 | 192.168.2.13 | 93.123.39.116 |
Oct 8, 2024 10:00:55.311167955 CEST | 51511 | 45892 | 93.123.39.116 | 192.168.2.13 |
Oct 8, 2024 10:01:02.474031925 CEST | 45894 | 51511 | 192.168.2.13 | 93.123.39.116 |
Oct 8, 2024 10:01:02.479904890 CEST | 51511 | 45894 | 93.123.39.116 | 192.168.2.13 |
Oct 8, 2024 10:01:02.479965925 CEST | 45894 | 51511 | 192.168.2.13 | 93.123.39.116 |
Oct 8, 2024 10:01:02.480700016 CEST | 45894 | 51511 | 192.168.2.13 | 93.123.39.116 |
Oct 8, 2024 10:01:02.486192942 CEST | 51511 | 45894 | 93.123.39.116 | 192.168.2.13 |
Oct 8, 2024 10:01:23.849026918 CEST | 51511 | 45894 | 93.123.39.116 | 192.168.2.13 |
Oct 8, 2024 10:01:23.849124908 CEST | 45894 | 51511 | 192.168.2.13 | 93.123.39.116 |
Oct 8, 2024 10:01:23.854157925 CEST | 51511 | 45894 | 93.123.39.116 | 192.168.2.13 |
Oct 8, 2024 10:01:27.861099958 CEST | 45896 | 51511 | 192.168.2.13 | 93.123.39.116 |
Oct 8, 2024 10:01:27.866569996 CEST | 51511 | 45896 | 93.123.39.116 | 192.168.2.13 |
Oct 8, 2024 10:01:27.866641045 CEST | 45896 | 51511 | 192.168.2.13 | 93.123.39.116 |
Oct 8, 2024 10:01:27.868098974 CEST | 45896 | 51511 | 192.168.2.13 | 93.123.39.116 |
Oct 8, 2024 10:01:27.873296976 CEST | 51511 | 45896 | 93.123.39.116 | 192.168.2.13 |
Oct 8, 2024 10:01:49.240523100 CEST | 51511 | 45896 | 93.123.39.116 | 192.168.2.13 |
Oct 8, 2024 10:01:49.240660906 CEST | 45896 | 51511 | 192.168.2.13 | 93.123.39.116 |
Oct 8, 2024 10:01:49.245681047 CEST | 51511 | 45896 | 93.123.39.116 | 192.168.2.13 |
Oct 8, 2024 10:01:55.251379013 CEST | 45898 | 51511 | 192.168.2.13 | 93.123.39.116 |
Oct 8, 2024 10:01:55.256964922 CEST | 51511 | 45898 | 93.123.39.116 | 192.168.2.13 |
Oct 8, 2024 10:01:55.257103920 CEST | 45898 | 51511 | 192.168.2.13 | 93.123.39.116 |
Oct 8, 2024 10:01:55.258976936 CEST | 45898 | 51511 | 192.168.2.13 | 93.123.39.116 |
Oct 8, 2024 10:01:55.264075041 CEST | 51511 | 45898 | 93.123.39.116 | 192.168.2.13 |
Oct 8, 2024 10:02:05.264226913 CEST | 45898 | 51511 | 192.168.2.13 | 93.123.39.116 |
Oct 8, 2024 10:02:05.269186974 CEST | 51511 | 45898 | 93.123.39.116 | 192.168.2.13 |
Oct 8, 2024 10:02:16.852452993 CEST | 51511 | 45898 | 93.123.39.116 | 192.168.2.13 |
Oct 8, 2024 10:02:16.852686882 CEST | 45898 | 51511 | 192.168.2.13 | 93.123.39.116 |
Oct 8, 2024 10:02:16.852946997 CEST | 51511 | 45898 | 93.123.39.116 | 192.168.2.13 |
Oct 8, 2024 10:02:16.853009939 CEST | 45898 | 51511 | 192.168.2.13 | 93.123.39.116 |
Oct 8, 2024 10:02:16.858226061 CEST | 51511 | 45898 | 93.123.39.116 | 192.168.2.13 |
Oct 8, 2024 10:02:21.862310886 CEST | 45900 | 51511 | 192.168.2.13 | 93.123.39.116 |
Oct 8, 2024 10:02:21.867572069 CEST | 51511 | 45900 | 93.123.39.116 | 192.168.2.13 |
Oct 8, 2024 10:02:21.867631912 CEST | 45900 | 51511 | 192.168.2.13 | 93.123.39.116 |
Oct 8, 2024 10:02:21.868278980 CEST | 45900 | 51511 | 192.168.2.13 | 93.123.39.116 |
Oct 8, 2024 10:02:21.873123884 CEST | 51511 | 45900 | 93.123.39.116 | 192.168.2.13 |
Oct 8, 2024 10:02:43.242814064 CEST | 51511 | 45900 | 93.123.39.116 | 192.168.2.13 |
Oct 8, 2024 10:02:43.243421078 CEST | 45900 | 51511 | 192.168.2.13 | 93.123.39.116 |
Oct 8, 2024 10:02:43.248239040 CEST | 51511 | 45900 | 93.123.39.116 | 192.168.2.13 |
Oct 8, 2024 10:02:44.254090071 CEST | 45902 | 51511 | 192.168.2.13 | 93.123.39.116 |
Oct 8, 2024 10:02:44.259149075 CEST | 51511 | 45902 | 93.123.39.116 | 192.168.2.13 |
Oct 8, 2024 10:02:44.259309053 CEST | 45902 | 51511 | 192.168.2.13 | 93.123.39.116 |
Oct 8, 2024 10:02:44.259938955 CEST | 45902 | 51511 | 192.168.2.13 | 93.123.39.116 |
Oct 8, 2024 10:02:44.265568972 CEST | 51511 | 45902 | 93.123.39.116 | 192.168.2.13 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Oct 8, 2024 09:59:17.166686058 CEST | 56416 | 53 | 192.168.2.13 | 8.8.8.8 |
Oct 8, 2024 09:59:17.174041033 CEST | 53 | 56416 | 8.8.8.8 | 192.168.2.13 |
Oct 8, 2024 09:59:39.767685890 CEST | 39065 | 53 | 192.168.2.13 | 8.8.8.8 |
Oct 8, 2024 09:59:40.041527987 CEST | 53 | 39065 | 8.8.8.8 | 192.168.2.13 |
Oct 8, 2024 10:00:07.485872030 CEST | 60559 | 53 | 192.168.2.13 | 8.8.8.8 |
Oct 8, 2024 10:00:07.503160000 CEST | 53 | 60559 | 8.8.8.8 | 192.168.2.13 |
Oct 8, 2024 10:00:33.920073032 CEST | 58454 | 53 | 192.168.2.13 | 8.8.8.8 |
Oct 8, 2024 10:00:33.927581072 CEST | 53 | 58454 | 8.8.8.8 | 192.168.2.13 |
Oct 8, 2024 10:01:02.308201075 CEST | 60679 | 53 | 192.168.2.13 | 8.8.8.8 |
Oct 8, 2024 10:01:02.473443031 CEST | 53 | 60679 | 8.8.8.8 | 192.168.2.13 |
Oct 8, 2024 10:01:27.851305962 CEST | 34857 | 53 | 192.168.2.13 | 8.8.8.8 |
Oct 8, 2024 10:01:27.860481024 CEST | 53 | 34857 | 8.8.8.8 | 192.168.2.13 |
Oct 8, 2024 10:01:55.243052959 CEST | 51596 | 53 | 192.168.2.13 | 8.8.8.8 |
Oct 8, 2024 10:01:55.250299931 CEST | 53 | 51596 | 8.8.8.8 | 192.168.2.13 |
Oct 8, 2024 10:02:02.432739973 CEST | 45524 | 53 | 192.168.2.13 | 1.1.1.1 |
Oct 8, 2024 10:02:02.432739973 CEST | 58020 | 53 | 192.168.2.13 | 1.1.1.1 |
Oct 8, 2024 10:02:02.439661026 CEST | 53 | 58020 | 1.1.1.1 | 192.168.2.13 |
Oct 8, 2024 10:02:02.440037012 CEST | 53 | 45524 | 1.1.1.1 | 192.168.2.13 |
Oct 8, 2024 10:02:21.854851007 CEST | 48979 | 53 | 192.168.2.13 | 8.8.8.8 |
Oct 8, 2024 10:02:21.861939907 CEST | 53 | 48979 | 8.8.8.8 | 192.168.2.13 |
Oct 8, 2024 10:02:44.245826006 CEST | 54573 | 53 | 192.168.2.13 | 8.8.8.8 |
Oct 8, 2024 10:02:44.253700018 CEST | 53 | 54573 | 8.8.8.8 | 192.168.2.13 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Oct 8, 2024 09:59:17.166686058 CEST | 192.168.2.13 | 8.8.8.8 | 0x567d | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 8, 2024 09:59:39.767685890 CEST | 192.168.2.13 | 8.8.8.8 | 0x1175 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 8, 2024 10:00:07.485872030 CEST | 192.168.2.13 | 8.8.8.8 | 0x9768 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 8, 2024 10:00:33.920073032 CEST | 192.168.2.13 | 8.8.8.8 | 0xcdce | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 8, 2024 10:01:02.308201075 CEST | 192.168.2.13 | 8.8.8.8 | 0x2e9 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 8, 2024 10:01:27.851305962 CEST | 192.168.2.13 | 8.8.8.8 | 0x356b | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 8, 2024 10:01:55.243052959 CEST | 192.168.2.13 | 8.8.8.8 | 0x2e31 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 8, 2024 10:02:02.432739973 CEST | 192.168.2.13 | 1.1.1.1 | 0x62d | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 8, 2024 10:02:02.432739973 CEST | 192.168.2.13 | 1.1.1.1 | 0x5a4e | Standard query (0) | 28 | IN (0x0001) | false | |
Oct 8, 2024 10:02:21.854851007 CEST | 192.168.2.13 | 8.8.8.8 | 0x8882 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 8, 2024 10:02:44.245826006 CEST | 192.168.2.13 | 8.8.8.8 | 0xeb09 | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Oct 8, 2024 09:59:17.174041033 CEST | 8.8.8.8 | 192.168.2.13 | 0x567d | No error (0) | 93.123.39.116 | A (IP address) | IN (0x0001) | false | ||
Oct 8, 2024 09:59:40.041527987 CEST | 8.8.8.8 | 192.168.2.13 | 0x1175 | No error (0) | 93.123.39.116 | A (IP address) | IN (0x0001) | false | ||
Oct 8, 2024 10:00:07.503160000 CEST | 8.8.8.8 | 192.168.2.13 | 0x9768 | No error (0) | 93.123.39.116 | A (IP address) | IN (0x0001) | false | ||
Oct 8, 2024 10:00:33.927581072 CEST | 8.8.8.8 | 192.168.2.13 | 0xcdce | No error (0) | 93.123.39.116 | A (IP address) | IN (0x0001) | false | ||
Oct 8, 2024 10:01:02.473443031 CEST | 8.8.8.8 | 192.168.2.13 | 0x2e9 | No error (0) | 93.123.39.116 | A (IP address) | IN (0x0001) | false | ||
Oct 8, 2024 10:01:27.860481024 CEST | 8.8.8.8 | 192.168.2.13 | 0x356b | No error (0) | 93.123.39.116 | A (IP address) | IN (0x0001) | false | ||
Oct 8, 2024 10:01:55.250299931 CEST | 8.8.8.8 | 192.168.2.13 | 0x2e31 | No error (0) | 93.123.39.116 | A (IP address) | IN (0x0001) | false | ||
Oct 8, 2024 10:02:02.440037012 CEST | 1.1.1.1 | 192.168.2.13 | 0x62d | No error (0) | 162.213.35.25 | A (IP address) | IN (0x0001) | false | ||
Oct 8, 2024 10:02:02.440037012 CEST | 1.1.1.1 | 192.168.2.13 | 0x62d | No error (0) | 162.213.35.24 | A (IP address) | IN (0x0001) | false | ||
Oct 8, 2024 10:02:21.861939907 CEST | 8.8.8.8 | 192.168.2.13 | 0x8882 | No error (0) | 93.123.39.116 | A (IP address) | IN (0x0001) | false | ||
Oct 8, 2024 10:02:44.253700018 CEST | 8.8.8.8 | 192.168.2.13 | 0xeb09 | No error (0) | 93.123.39.116 | A (IP address) | IN (0x0001) | false |
System Behavior
Start time (UTC): | 07:59:15 |
Start date (UTC): | 08/10/2024 |
Path: | /tmp/na.elf |
Arguments: | /tmp/na.elf |
File size: | 4956856 bytes |
MD5 hash: | 5ebfcae4fe2471fcc5695c2394773ff1 |
Start time (UTC): | 07:59:15 |
Start date (UTC): | 08/10/2024 |
Path: | /tmp/na.elf |
Arguments: | - |
File size: | 4956856 bytes |
MD5 hash: | 5ebfcae4fe2471fcc5695c2394773ff1 |
Start time (UTC): | 07:59:15 |
Start date (UTC): | 08/10/2024 |
Path: | /tmp/na.elf |
Arguments: | - |
File size: | 4956856 bytes |
MD5 hash: | 5ebfcae4fe2471fcc5695c2394773ff1 |
Start time (UTC): | 07:59:15 |
Start date (UTC): | 08/10/2024 |
Path: | /usr/lib/udisks2/udisksd |
Arguments: | - |
File size: | 483056 bytes |
MD5 hash: | 1d7ae439cc3d82fa6b127671ce037a24 |
Start time (UTC): | 07:59:15 |
Start date (UTC): | 08/10/2024 |
Path: | /usr/sbin/dumpe2fs |
Arguments: | dumpe2fs -h /dev/dm-0 |
File size: | 31112 bytes |
MD5 hash: | 5c66f7d8f7681a40562cf049ad4b72b4 |
Start time (UTC): | 07:59:15 |
Start date (UTC): | 08/10/2024 |
Path: | /usr/libexec/gnome-session-binary |
Arguments: | - |
File size: | 334664 bytes |
MD5 hash: | d9b90be4f7db60cb3c2d3da6a1d31bfb |
Start time (UTC): | 07:59:15 |
Start date (UTC): | 08/10/2024 |
Path: | /bin/sh |
Arguments: | /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-sharing |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 07:59:15 |
Start date (UTC): | 08/10/2024 |
Path: | /usr/libexec/gsd-sharing |
Arguments: | /usr/libexec/gsd-sharing |
File size: | 35424 bytes |
MD5 hash: | e29d9025d98590fbb69f89fdbd4438b3 |
Start time (UTC): | 07:59:15 |
Start date (UTC): | 08/10/2024 |
Path: | /usr/libexec/gnome-session-binary |
Arguments: | - |
File size: | 334664 bytes |
MD5 hash: | d9b90be4f7db60cb3c2d3da6a1d31bfb |
Start time (UTC): | 07:59:15 |
Start date (UTC): | 08/10/2024 |
Path: | /bin/sh |
Arguments: | /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-wacom |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 07:59:15 |
Start date (UTC): | 08/10/2024 |
Path: | /usr/libexec/gsd-wacom |
Arguments: | /usr/libexec/gsd-wacom |
File size: | 39520 bytes |
MD5 hash: | 13778dd1a23a4e94ddc17ac9caa4fcc1 |
Start time (UTC): | 07:59:16 |
Start date (UTC): | 08/10/2024 |
Path: | /usr/lib/systemd/systemd |
Arguments: | - |
File size: | 1620224 bytes |
MD5 hash: | 9b2bec7092a40488108543f9334aab75 |
Start time (UTC): | 07:59:16 |
Start date (UTC): | 08/10/2024 |
Path: | /usr/lib/upower/upowerd |
Arguments: | /usr/lib/upower/upowerd |
File size: | 260328 bytes |
MD5 hash: | 1253eea2fe5fe4017069664284e326cd |
Start time (UTC): | 07:59:15 |
Start date (UTC): | 08/10/2024 |
Path: | /usr/libexec/gnome-session-binary |
Arguments: | - |
File size: | 334664 bytes |
MD5 hash: | d9b90be4f7db60cb3c2d3da6a1d31bfb |
Start time (UTC): | 07:59:15 |
Start date (UTC): | 08/10/2024 |
Path: | /bin/sh |
Arguments: | /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-color |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 07:59:16 |
Start date (UTC): | 08/10/2024 |
Path: | /usr/libexec/gsd-color |
Arguments: | /usr/libexec/gsd-color |
File size: | 92832 bytes |
MD5 hash: | ac2861ad93ce047283e8e87cefef9a19 |
Start time (UTC): | 07:59:15 |
Start date (UTC): | 08/10/2024 |
Path: | /usr/libexec/gvfsd-fuse |
Arguments: | - |
File size: | 47632 bytes |
MD5 hash: | d18fbf1cbf8eb57b17fac48b7b4be933 |
Start time (UTC): | 07:59:15 |
Start date (UTC): | 08/10/2024 |
Path: | /bin/fusermount |
Arguments: | fusermount -u -q -z -- /run/user/1000/gvfs |
File size: | 39144 bytes |
MD5 hash: | 576a1b135c82bdcbc97a91acea900566 |
Start time (UTC): | 07:59:16 |
Start date (UTC): | 08/10/2024 |
Path: | /usr/libexec/gnome-session-binary |
Arguments: | - |
File size: | 334664 bytes |
MD5 hash: | d9b90be4f7db60cb3c2d3da6a1d31bfb |
Start time (UTC): | 07:59:16 |
Start date (UTC): | 08/10/2024 |
Path: | /bin/sh |
Arguments: | /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-keyboard |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 07:59:16 |
Start date (UTC): | 08/10/2024 |
Path: | /usr/libexec/gsd-keyboard |
Arguments: | /usr/libexec/gsd-keyboard |
File size: | 39760 bytes |
MD5 hash: | 8e288fd17c80bb0a1148b964b2ac2279 |
Start time (UTC): | 07:59:16 |
Start date (UTC): | 08/10/2024 |
Path: | /usr/libexec/gnome-session-binary |
Arguments: | - |
File size: | 334664 bytes |
MD5 hash: | d9b90be4f7db60cb3c2d3da6a1d31bfb |
Start time (UTC): | 07:59:16 |
Start date (UTC): | 08/10/2024 |
Path: | /bin/sh |
Arguments: | /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-print-notifications |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 07:59:16 |
Start date (UTC): | 08/10/2024 |
Path: | /usr/libexec/gsd-print-notifications |
Arguments: | /usr/libexec/gsd-print-notifications |
File size: | 51840 bytes |
MD5 hash: | 71539698aa691718cee775d6b9450ae2 |
Start time (UTC): | 07:59:16 |
Start date (UTC): | 08/10/2024 |
Path: | /usr/bin/xfce4-panel |
Arguments: | - |
File size: | 375768 bytes |
MD5 hash: | a15b657c7d54ac1385f1f15004ea6784 |
Start time (UTC): | 07:59:16 |
Start date (UTC): | 08/10/2024 |
Path: | /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 |
Arguments: | /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libsystray.so 6 12582920 systray "Notification Area" "Area where notification icons appear" |
File size: | 35136 bytes |
MD5 hash: | ac0b8a906f359a8ae102244738682e76 |
Start time (UTC): | 07:59:16 |
Start date (UTC): | 08/10/2024 |
Path: | /usr/libexec/gnome-session-binary |
Arguments: | - |
File size: | 334664 bytes |
MD5 hash: | d9b90be4f7db60cb3c2d3da6a1d31bfb |
Start time (UTC): | 07:59:16 |
Start date (UTC): | 08/10/2024 |
Path: | /bin/sh |
Arguments: | /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-rfkill |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 07:59:16 |
Start date (UTC): | 08/10/2024 |
Path: | /usr/libexec/gsd-rfkill |
Arguments: | /usr/libexec/gsd-rfkill |
File size: | 51808 bytes |
MD5 hash: | 88a16a3c0aba1759358c06215ecfb5cc |
Start time (UTC): | 07:59:16 |
Start date (UTC): | 08/10/2024 |
Path: | /usr/bin/xfce4-panel |
Arguments: | - |
File size: | 375768 bytes |
MD5 hash: | a15b657c7d54ac1385f1f15004ea6784 |
Start time (UTC): | 07:59:16 |
Start date (UTC): | 08/10/2024 |
Path: | /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 |
Arguments: | /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libstatusnotifier.so 7 12582921 statusnotifier "Status Notifier Plugin" "Provides a panel area for status notifier items (application indicators)" |
File size: | 35136 bytes |
MD5 hash: | ac0b8a906f359a8ae102244738682e76 |
Start time (UTC): | 07:59:16 |
Start date (UTC): | 08/10/2024 |
Path: | /usr/libexec/gnome-session-binary |
Arguments: | - |
File size: | 334664 bytes |
MD5 hash: | d9b90be4f7db60cb3c2d3da6a1d31bfb |
Start time (UTC): | 07:59:16 |
Start date (UTC): | 08/10/2024 |
Path: | /bin/sh |
Arguments: | /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-smartcard |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 07:59:16 |
Start date (UTC): | 08/10/2024 |
Path: | /usr/libexec/gsd-smartcard |
Arguments: | /usr/libexec/gsd-smartcard |
File size: | 109152 bytes |
MD5 hash: | ea1fbd7f62e4cd0331eae2ef754ee605 |
Start time (UTC): | 07:59:16 |
Start date (UTC): | 08/10/2024 |
Path: | /usr/lib/udisks2/udisksd |
Arguments: | - |
File size: | 483056 bytes |
MD5 hash: | 1d7ae439cc3d82fa6b127671ce037a24 |
Start time (UTC): | 07:59:16 |
Start date (UTC): | 08/10/2024 |
Path: | /usr/sbin/dumpe2fs |
Arguments: | dumpe2fs -h /dev/dm-0 |
File size: | 31112 bytes |
MD5 hash: | 5c66f7d8f7681a40562cf049ad4b72b4 |
Start time (UTC): | 07:59:16 |
Start date (UTC): | 08/10/2024 |
Path: | /usr/bin/xfce4-panel |
Arguments: | - |
File size: | 375768 bytes |
MD5 hash: | a15b657c7d54ac1385f1f15004ea6784 |
Start time (UTC): | 07:59:16 |
Start date (UTC): | 08/10/2024 |
Path: | /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 |
Arguments: | /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libpulseaudio-plugin.so 8 12582922 pulseaudio "PulseAudio Plugin" "Adjust the audio volume of the PulseAudio sound system" |
File size: | 35136 bytes |
MD5 hash: | ac0b8a906f359a8ae102244738682e76 |
Start time (UTC): | 07:59:16 |
Start date (UTC): | 08/10/2024 |
Path: | /usr/libexec/gnome-session-binary |
Arguments: | - |
File size: | 334664 bytes |
MD5 hash: | d9b90be4f7db60cb3c2d3da6a1d31bfb |
Start time (UTC): | 07:59:16 |
Start date (UTC): | 08/10/2024 |
Path: | /bin/sh |
Arguments: | /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-datetime |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 07:59:16 |
Start date (UTC): | 08/10/2024 |
Path: | /usr/libexec/gsd-datetime |
Arguments: | /usr/libexec/gsd-datetime |
File size: | 76736 bytes |
MD5 hash: | d80d39745740de37d6634d36e344d4bc |
Start time (UTC): | 07:59:16 |
Start date (UTC): | 08/10/2024 |
Path: | /usr/bin/xfce4-panel |
Arguments: | - |
File size: | 375768 bytes |
MD5 hash: | a15b657c7d54ac1385f1f15004ea6784 |
Start time (UTC): | 07:59:16 |
Start date (UTC): | 08/10/2024 |
Path: | /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 |
Arguments: | /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libxfce4powermanager.so 9 12582923 power-manager-plugin "Power Manager Plugin" "Display the battery levels of your devices and control the brightness of your display" |
File size: | 35136 bytes |
MD5 hash: | ac0b8a906f359a8ae102244738682e76 |
Start time (UTC): | 07:59:16 |
Start date (UTC): | 08/10/2024 |
Path: | /usr/libexec/gnome-session-binary |
Arguments: | - |
File size: | 334664 bytes |
MD5 hash: | d9b90be4f7db60cb3c2d3da6a1d31bfb |
Start time (UTC): | 07:59:16 |
Start date (UTC): | 08/10/2024 |
Path: | /bin/sh |
Arguments: | /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-media-keys |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 07:59:16 |
Start date (UTC): | 08/10/2024 |
Path: | /usr/libexec/gsd-media-keys |
Arguments: | /usr/libexec/gsd-media-keys |
File size: | 232936 bytes |
MD5 hash: | a425448c135afb4b8bfd79cc0b6b74da |
Start time (UTC): | 07:59:16 |
Start date (UTC): | 08/10/2024 |
Path: | /usr/bin/xfce4-panel |
Arguments: | - |
File size: | 375768 bytes |
MD5 hash: | a15b657c7d54ac1385f1f15004ea6784 |
Start time (UTC): | 07:59:16 |
Start date (UTC): | 08/10/2024 |
Path: | /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 |
Arguments: | /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libnotification-plugin.so 10 12582924 notification-plugin "Notification Plugin" "Notification plugin for the Xfce panel" |
File size: | 35136 bytes |
MD5 hash: | ac0b8a906f359a8ae102244738682e76 |
Start time (UTC): | 07:59:16 |
Start date (UTC): | 08/10/2024 |
Path: | /usr/libexec/gnome-session-binary |
Arguments: | - |
File size: | 334664 bytes |
MD5 hash: | d9b90be4f7db60cb3c2d3da6a1d31bfb |
Start time (UTC): | 07:59:16 |
Start date (UTC): | 08/10/2024 |
Path: | /bin/sh |
Arguments: | /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-screensaver-proxy |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 07:59:17 |
Start date (UTC): | 08/10/2024 |
Path: | /usr/libexec/gsd-screensaver-proxy |
Arguments: | /usr/libexec/gsd-screensaver-proxy |
File size: | 27232 bytes |
MD5 hash: | 77e309450c87dceee43f1a9e50cc0d02 |
Start time (UTC): | 07:59:16 |
Start date (UTC): | 08/10/2024 |
Path: | /usr/lib/systemd/systemd |
Arguments: | - |
File size: | 1620224 bytes |
MD5 hash: | 9b2bec7092a40488108543f9334aab75 |
Start time (UTC): | 07:59:16 |
Start date (UTC): | 08/10/2024 |
Path: | /usr/lib/upower/upowerd |
Arguments: | /usr/lib/upower/upowerd |
File size: | 260328 bytes |
MD5 hash: | 1253eea2fe5fe4017069664284e326cd |
Start time (UTC): | 07:59:16 |
Start date (UTC): | 08/10/2024 |
Path: | /usr/bin/xfce4-panel |
Arguments: | - |
File size: | 375768 bytes |
MD5 hash: | a15b657c7d54ac1385f1f15004ea6784 |
Start time (UTC): | 07:59:16 |
Start date (UTC): | 08/10/2024 |
Path: | /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 |
Arguments: | /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libactions.so 14 12582925 actions "Action Buttons" "Log out, lock or other system actions" |
File size: | 35136 bytes |
MD5 hash: | ac0b8a906f359a8ae102244738682e76 |
Start time (UTC): | 07:59:16 |
Start date (UTC): | 08/10/2024 |
Path: | /usr/libexec/gnome-session-binary |
Arguments: | - |
File size: | 334664 bytes |
MD5 hash: | d9b90be4f7db60cb3c2d3da6a1d31bfb |
Start time (UTC): | 07:59:16 |
Start date (UTC): | 08/10/2024 |
Path: | /bin/sh |
Arguments: | /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-a11y-settings |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 07:59:17 |
Start date (UTC): | 08/10/2024 |
Path: | /usr/libexec/gsd-a11y-settings |
Arguments: | /usr/libexec/gsd-a11y-settings |
File size: | 23056 bytes |
MD5 hash: | 18e243d2cf30ecee7ea89d1462725c5c |
Start time (UTC): | 07:59:17 |
Start date (UTC): | 08/10/2024 |
Path: | /usr/libexec/gnome-session-binary |
Arguments: | - |
File size: | 334664 bytes |
MD5 hash: | d9b90be4f7db60cb3c2d3da6a1d31bfb |
Start time (UTC): | 07:59:17 |
Start date (UTC): | 08/10/2024 |
Path: | /bin/sh |
Arguments: | /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-power |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 07:59:17 |
Start date (UTC): | 08/10/2024 |
Path: | /usr/libexec/gsd-power |
Arguments: | /usr/libexec/gsd-power |
File size: | 88672 bytes |
MD5 hash: | 28b8e1b43c3e7f1db6741ea1ecd978b7 |
Start time (UTC): | 07:59:17 |
Start date (UTC): | 08/10/2024 |
Path: | /usr/libexec/gnome-session-binary |
Arguments: | - |
File size: | 334664 bytes |
MD5 hash: | d9b90be4f7db60cb3c2d3da6a1d31bfb |
Start time (UTC): | 07:59:17 |
Start date (UTC): | 08/10/2024 |
Path: | /bin/sh |
Arguments: | /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-sound |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 07:59:17 |
Start date (UTC): | 08/10/2024 |
Path: | /usr/libexec/gsd-sound |
Arguments: | /usr/libexec/gsd-sound |
File size: | 31248 bytes |
MD5 hash: | 4c7d3fb993463337b4a0eb5c80c760ee |
Start time (UTC): | 07:59:17 |
Start date (UTC): | 08/10/2024 |
Path: | /usr/libexec/gnome-session-binary |
Arguments: | - |
File size: | 334664 bytes |
MD5 hash: | d9b90be4f7db60cb3c2d3da6a1d31bfb |
Start time (UTC): | 07:59:17 |
Start date (UTC): | 08/10/2024 |
Path: | /bin/sh |
Arguments: | /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-housekeeping |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 07:59:17 |
Start date (UTC): | 08/10/2024 |
Path: | /usr/libexec/gsd-housekeeping |
Arguments: | /usr/libexec/gsd-housekeeping |
File size: | 51840 bytes |
MD5 hash: | b55f3394a84976ddb92a2915e5d76914 |
Start time (UTC): | 07:59:17 |
Start date (UTC): | 08/10/2024 |
Path: | /usr/lib/udisks2/udisksd |
Arguments: | - |
File size: | 483056 bytes |
MD5 hash: | 1d7ae439cc3d82fa6b127671ce037a24 |
Start time (UTC): | 07:59:17 |
Start date (UTC): | 08/10/2024 |
Path: | /usr/sbin/dumpe2fs |
Arguments: | dumpe2fs -h /dev/dm-0 |
File size: | 31112 bytes |
MD5 hash: | 5c66f7d8f7681a40562cf049ad4b72b4 |
Start time (UTC): | 07:59:17 |
Start date (UTC): | 08/10/2024 |
Path: | /usr/lib/systemd/systemd |
Arguments: | - |
File size: | 1620224 bytes |
MD5 hash: | 9b2bec7092a40488108543f9334aab75 |
Start time (UTC): | 07:59:17 |
Start date (UTC): | 08/10/2024 |
Path: | /usr/lib/upower/upowerd |
Arguments: | /usr/lib/upower/upowerd |
File size: | 260328 bytes |
MD5 hash: | 1253eea2fe5fe4017069664284e326cd |
Start time (UTC): | 07:59:18 |
Start date (UTC): | 08/10/2024 |
Path: | /usr/lib/systemd/systemd |
Arguments: | - |
File size: | 1620224 bytes |
MD5 hash: | 9b2bec7092a40488108543f9334aab75 |
Start time (UTC): | 07:59:18 |
Start date (UTC): | 08/10/2024 |
Path: | /usr/lib/upower/upowerd |
Arguments: | /usr/lib/upower/upowerd |
File size: | 260328 bytes |
MD5 hash: | 1253eea2fe5fe4017069664284e326cd |
Start time (UTC): | 07:59:18 |
Start date (UTC): | 08/10/2024 |
Path: | /usr/lib/systemd/systemd |
Arguments: | - |
File size: | 1620224 bytes |
MD5 hash: | 9b2bec7092a40488108543f9334aab75 |
Start time (UTC): | 07:59:18 |
Start date (UTC): | 08/10/2024 |
Path: | /usr/lib/upower/upowerd |
Arguments: | /usr/lib/upower/upowerd |
File size: | 260328 bytes |
MD5 hash: | 1253eea2fe5fe4017069664284e326cd |