Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
na.elf

Overview

General Information

Sample name:na.elf
Analysis ID:1536980
MD5:0238b625efdffe4d312ffc6afd840cf8
SHA1:d88261c035ba355c7f8267fa3d68a62b3012079f
SHA256:1f4d4fb0a1ca4abcfcaa37863fa404b78b8eac3e6ed66f6646c94053eb6da894
Tags:elfuser-abuse_ch
Infos:

Detection

Mirai
Score:64
Range:0 - 100
Whitelisted:false

Signatures

Antivirus / Scanner detection for submitted sample
Malicious sample detected (through community Yara rule)
Yara detected Mirai
Detected TCP or UDP traffic on non-standard ports
Enumerates processes within the "proc" file system
Sample contains strings indicative of BusyBox which embeds multiple Unix commands in a single executable
Sample has stripped symbol table
Uses the "uname" system call to query kernel version information (possible evasion)
Yara signature match

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1536980
Start date and time:2024-10-18 13:27:13 +02:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 29s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:na.elf
Detection:MAL
Classification:mal64.troj.linELF@0/0@0/0
  • VT rate limit hit for: na.elf
Command:/tmp/na.elf
PID:5519
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
lzrd cock fest"/proc/"/exe
Standard Error:
  • system is lnxubuntu20
  • na.elf (PID: 5519, Parent: 5444, MD5: cd177594338c77b895ae27c33f8f86cc) Arguments: /tmp/na.elf
    • na.elf New Fork (PID: 5521, Parent: 5519)
      • na.elf New Fork (PID: 5523, Parent: 5521)
      • na.elf New Fork (PID: 5525, Parent: 5521)
    • na.elf New Fork (PID: 5540, Parent: 5519)
    • na.elf New Fork (PID: 5541, Parent: 5519)
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
MiraiMirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese. Nowadays it targets a wide range of networked embedded devices such as IP cameras, home routers (many vendors involved), and other IoT devices. Since the source code was published on "Hack Forums" many variants of the Mirai family appeared, infecting mostly home networks all around the world.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/elf.mirai
SourceRuleDescriptionAuthorStrings
na.elfJoeSecurity_Mirai_8Yara detected MiraiJoe Security
    na.elfLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
    • 0x151af:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x151c3:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x151d7:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x151eb:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x151ff:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x15213:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x15227:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x1523b:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x1524f:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x15263:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x15277:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x1528b:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x1529f:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x152b3:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x152c7:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x152db:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x152ef:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x15303:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x15317:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x1532b:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x1533f:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    SourceRuleDescriptionAuthorStrings
    5523.1.00007f7750001000.00007f7750019000.r-x.sdmpJoeSecurity_Mirai_8Yara detected MiraiJoe Security
      5523.1.00007f7750001000.00007f7750019000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
      • 0x151af:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x151c3:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x151d7:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x151eb:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x151ff:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x15213:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x15227:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x1523b:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x1524f:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x15263:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x15277:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x1528b:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x1529f:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x152b3:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x152c7:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x152db:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x152ef:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x15303:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x15317:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x1532b:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x1533f:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      5519.1.00007f7750001000.00007f7750019000.r-x.sdmpJoeSecurity_Mirai_8Yara detected MiraiJoe Security
        5519.1.00007f7750001000.00007f7750019000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
        • 0x151af:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x151c3:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x151d7:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x151eb:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x151ff:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x15213:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x15227:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x1523b:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x1524f:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x15263:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x15277:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x1528b:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x1529f:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x152b3:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x152c7:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x152db:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x152ef:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x15303:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x15317:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x1532b:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x1533f:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        5521.1.00007f7750001000.00007f7750019000.r-x.sdmpJoeSecurity_Mirai_8Yara detected MiraiJoe Security
          Click to see the 11 entries
          No Suricata rule has matched

          Click to jump to signature section

          Show All Signature Results

          AV Detection

          barindex
          Source: na.elfAvira: detected
          Source: global trafficTCP traffic: 192.168.2.15:58160 -> 45.86.155.23:3778
          Source: unknownTCP traffic detected without corresponding DNS query: 45.86.155.23
          Source: unknownTCP traffic detected without corresponding DNS query: 45.86.155.23
          Source: unknownTCP traffic detected without corresponding DNS query: 45.86.155.23
          Source: unknownTCP traffic detected without corresponding DNS query: 45.86.155.23
          Source: unknownTCP traffic detected without corresponding DNS query: 45.86.155.23
          Source: unknownTCP traffic detected without corresponding DNS query: 45.86.155.23
          Source: unknownTCP traffic detected without corresponding DNS query: 45.86.155.23
          Source: unknownTCP traffic detected without corresponding DNS query: 45.86.155.23
          Source: unknownTCP traffic detected without corresponding DNS query: 45.86.155.23
          Source: unknownTCP traffic detected without corresponding DNS query: 45.86.155.23
          Source: unknownTCP traffic detected without corresponding DNS query: 45.86.155.23
          Source: unknownTCP traffic detected without corresponding DNS query: 45.86.155.23
          Source: unknownTCP traffic detected without corresponding DNS query: 45.86.155.23
          Source: unknownTCP traffic detected without corresponding DNS query: 45.86.155.23
          Source: unknownTCP traffic detected without corresponding DNS query: 45.86.155.23
          Source: unknownTCP traffic detected without corresponding DNS query: 45.86.155.23
          Source: unknownTCP traffic detected without corresponding DNS query: 45.86.155.23
          Source: unknownTCP traffic detected without corresponding DNS query: 45.86.155.23
          Source: unknownTCP traffic detected without corresponding DNS query: 45.86.155.23
          Source: unknownTCP traffic detected without corresponding DNS query: 45.86.155.23
          Source: unknownTCP traffic detected without corresponding DNS query: 45.86.155.23
          Source: unknownTCP traffic detected without corresponding DNS query: 45.86.155.23
          Source: unknownTCP traffic detected without corresponding DNS query: 45.86.155.23
          Source: unknownTCP traffic detected without corresponding DNS query: 45.86.155.23
          Source: unknownTCP traffic detected without corresponding DNS query: 45.86.155.23
          Source: unknownTCP traffic detected without corresponding DNS query: 45.86.155.23
          Source: unknownTCP traffic detected without corresponding DNS query: 45.86.155.23
          Source: unknownTCP traffic detected without corresponding DNS query: 45.86.155.23
          Source: unknownTCP traffic detected without corresponding DNS query: 45.86.155.23
          Source: unknownTCP traffic detected without corresponding DNS query: 45.86.155.23
          Source: unknownTCP traffic detected without corresponding DNS query: 45.86.155.23
          Source: unknownTCP traffic detected without corresponding DNS query: 45.86.155.23
          Source: unknownTCP traffic detected without corresponding DNS query: 45.86.155.23
          Source: unknownTCP traffic detected without corresponding DNS query: 45.86.155.23
          Source: unknownTCP traffic detected without corresponding DNS query: 45.86.155.23
          Source: unknownTCP traffic detected without corresponding DNS query: 45.86.155.23
          Source: unknownTCP traffic detected without corresponding DNS query: 45.86.155.23
          Source: unknownTCP traffic detected without corresponding DNS query: 45.86.155.23
          Source: unknownTCP traffic detected without corresponding DNS query: 45.86.155.23
          Source: unknownTCP traffic detected without corresponding DNS query: 45.86.155.23
          Source: unknownTCP traffic detected without corresponding DNS query: 45.86.155.23
          Source: unknownTCP traffic detected without corresponding DNS query: 45.86.155.23
          Source: unknownTCP traffic detected without corresponding DNS query: 45.86.155.23
          Source: unknownTCP traffic detected without corresponding DNS query: 45.86.155.23
          Source: unknownTCP traffic detected without corresponding DNS query: 45.86.155.23
          Source: unknownTCP traffic detected without corresponding DNS query: 45.86.155.23
          Source: unknownTCP traffic detected without corresponding DNS query: 45.86.155.23
          Source: unknownTCP traffic detected without corresponding DNS query: 45.86.155.23
          Source: unknownTCP traffic detected without corresponding DNS query: 45.86.155.23
          Source: unknownTCP traffic detected without corresponding DNS query: 45.86.155.23

          System Summary

          barindex
          Source: na.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
          Source: 5523.1.00007f7750001000.00007f7750019000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
          Source: 5519.1.00007f7750001000.00007f7750019000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
          Source: 5521.1.00007f7750001000.00007f7750019000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
          Source: 5540.1.00007f7750001000.00007f7750019000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
          Source: Process Memory Space: na.elf PID: 5519, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
          Source: Process Memory Space: na.elf PID: 5521, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
          Source: Process Memory Space: na.elf PID: 5523, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
          Source: Process Memory Space: na.elf PID: 5540, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
          Source: Initial sampleString containing 'busybox' found: /bin/busybox
          Source: Initial sampleString containing 'busybox' found: /proc/net/tcp.x86.x86_64.arm.arm5.arm6.arm7.mips.mipsel.sh4.ppc/proc/proc/%d/exe/proc/%s/statusName:%s/bin/busybox/bin/systemd/usr/bintest/tmp/condi/tmp/zxcr9999/tmp/condinetwork/var/condibot/var/zxcr9999/var/CondiBot/var/condinet/bin/watchdog45.86.155.23
          Source: ELF static info symbol of initial sample.symtab present: no
          Source: na.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
          Source: 5523.1.00007f7750001000.00007f7750019000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
          Source: 5519.1.00007f7750001000.00007f7750019000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
          Source: 5521.1.00007f7750001000.00007f7750019000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
          Source: 5540.1.00007f7750001000.00007f7750019000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
          Source: Process Memory Space: na.elf PID: 5519, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
          Source: Process Memory Space: na.elf PID: 5521, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
          Source: Process Memory Space: na.elf PID: 5523, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
          Source: Process Memory Space: na.elf PID: 5540, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
          Source: classification engineClassification label: mal64.troj.linELF@0/0@0/0
          Source: /tmp/na.elf (PID: 5519)File opened: /proc/110/statusJump to behavior
          Source: /tmp/na.elf (PID: 5519)File opened: /proc/231/statusJump to behavior
          Source: /tmp/na.elf (PID: 5519)File opened: /proc/111/statusJump to behavior
          Source: /tmp/na.elf (PID: 5519)File opened: /proc/112/statusJump to behavior
          Source: /tmp/na.elf (PID: 5519)File opened: /proc/233/statusJump to behavior
          Source: /tmp/na.elf (PID: 5519)File opened: /proc/113/statusJump to behavior
          Source: /tmp/na.elf (PID: 5519)File opened: /proc/114/statusJump to behavior
          Source: /tmp/na.elf (PID: 5519)File opened: /proc/235/statusJump to behavior
          Source: /tmp/na.elf (PID: 5519)File opened: /proc/115/statusJump to behavior
          Source: /tmp/na.elf (PID: 5519)File opened: /proc/1333/statusJump to behavior
          Source: /tmp/na.elf (PID: 5519)File opened: /proc/116/statusJump to behavior
          Source: /tmp/na.elf (PID: 5519)File opened: /proc/1695/statusJump to behavior
          Source: /tmp/na.elf (PID: 5519)File opened: /proc/117/statusJump to behavior
          Source: /tmp/na.elf (PID: 5519)File opened: /proc/118/statusJump to behavior
          Source: /tmp/na.elf (PID: 5519)File opened: /proc/119/statusJump to behavior
          Source: /tmp/na.elf (PID: 5519)File opened: /proc/911/statusJump to behavior
          Source: /tmp/na.elf (PID: 5519)File opened: /proc/3874/statusJump to behavior
          Source: /tmp/na.elf (PID: 5519)File opened: /proc/914/statusJump to behavior
          Source: /tmp/na.elf (PID: 5519)File opened: /proc/10/statusJump to behavior
          Source: /tmp/na.elf (PID: 5519)File opened: /proc/917/statusJump to behavior
          Source: /tmp/na.elf (PID: 5519)File opened: /proc/11/statusJump to behavior
          Source: /tmp/na.elf (PID: 5519)File opened: /proc/12/statusJump to behavior
          Source: /tmp/na.elf (PID: 5519)File opened: /proc/13/statusJump to behavior
          Source: /tmp/na.elf (PID: 5519)File opened: /proc/14/statusJump to behavior
          Source: /tmp/na.elf (PID: 5519)File opened: /proc/15/statusJump to behavior
          Source: /tmp/na.elf (PID: 5519)File opened: /proc/16/statusJump to behavior
          Source: /tmp/na.elf (PID: 5519)File opened: /proc/17/statusJump to behavior
          Source: /tmp/na.elf (PID: 5519)File opened: /proc/18/statusJump to behavior
          Source: /tmp/na.elf (PID: 5519)File opened: /proc/19/statusJump to behavior
          Source: /tmp/na.elf (PID: 5519)File opened: /proc/1591/statusJump to behavior
          Source: /tmp/na.elf (PID: 5519)File opened: /proc/120/statusJump to behavior
          Source: /tmp/na.elf (PID: 5519)File opened: /proc/121/statusJump to behavior
          Source: /tmp/na.elf (PID: 5519)File opened: /proc/1/statusJump to behavior
          Source: /tmp/na.elf (PID: 5519)File opened: /proc/122/statusJump to behavior
          Source: /tmp/na.elf (PID: 5519)File opened: /proc/243/statusJump to behavior
          Source: /tmp/na.elf (PID: 5519)File opened: /proc/2/statusJump to behavior
          Source: /tmp/na.elf (PID: 5519)File opened: /proc/123/statusJump to behavior
          Source: /tmp/na.elf (PID: 5519)File opened: /proc/3/statusJump to behavior
          Source: /tmp/na.elf (PID: 5519)File opened: /proc/124/statusJump to behavior
          Source: /tmp/na.elf (PID: 5519)File opened: /proc/1588/statusJump to behavior
          Source: /tmp/na.elf (PID: 5519)File opened: /proc/125/statusJump to behavior
          Source: /tmp/na.elf (PID: 5519)File opened: /proc/4/statusJump to behavior
          Source: /tmp/na.elf (PID: 5519)File opened: /proc/246/statusJump to behavior
          Source: /tmp/na.elf (PID: 5519)File opened: /proc/126/statusJump to behavior
          Source: /tmp/na.elf (PID: 5519)File opened: /proc/5/statusJump to behavior
          Source: /tmp/na.elf (PID: 5519)File opened: /proc/127/statusJump to behavior
          Source: /tmp/na.elf (PID: 5519)File opened: /proc/6/statusJump to behavior
          Source: /tmp/na.elf (PID: 5519)File opened: /proc/1585/statusJump to behavior
          Source: /tmp/na.elf (PID: 5519)File opened: /proc/128/statusJump to behavior
          Source: /tmp/na.elf (PID: 5519)File opened: /proc/7/statusJump to behavior
          Source: /tmp/na.elf (PID: 5519)File opened: /proc/129/statusJump to behavior
          Source: /tmp/na.elf (PID: 5519)File opened: /proc/8/statusJump to behavior
          Source: /tmp/na.elf (PID: 5519)File opened: /proc/800/statusJump to behavior
          Source: /tmp/na.elf (PID: 5519)File opened: /proc/9/statusJump to behavior
          Source: /tmp/na.elf (PID: 5519)File opened: /proc/802/statusJump to behavior
          Source: /tmp/na.elf (PID: 5519)File opened: /proc/803/statusJump to behavior
          Source: /tmp/na.elf (PID: 5519)File opened: /proc/804/statusJump to behavior
          Source: /tmp/na.elf (PID: 5519)File opened: /proc/20/statusJump to behavior
          Source: /tmp/na.elf (PID: 5519)File opened: /proc/21/statusJump to behavior
          Source: /tmp/na.elf (PID: 5519)File opened: /proc/3407/statusJump to behavior
          Source: /tmp/na.elf (PID: 5519)File opened: /proc/22/statusJump to behavior
          Source: /tmp/na.elf (PID: 5519)File opened: /proc/23/statusJump to behavior
          Source: /tmp/na.elf (PID: 5519)File opened: /proc/24/statusJump to behavior
          Source: /tmp/na.elf (PID: 5519)File opened: /proc/25/statusJump to behavior
          Source: /tmp/na.elf (PID: 5519)File opened: /proc/26/statusJump to behavior
          Source: /tmp/na.elf (PID: 5519)File opened: /proc/27/statusJump to behavior
          Source: /tmp/na.elf (PID: 5519)File opened: /proc/28/statusJump to behavior
          Source: /tmp/na.elf (PID: 5519)File opened: /proc/29/statusJump to behavior
          Source: /tmp/na.elf (PID: 5519)File opened: /proc/1484/statusJump to behavior
          Source: /tmp/na.elf (PID: 5519)File opened: /proc/490/statusJump to behavior
          Source: /tmp/na.elf (PID: 5519)File opened: /proc/250/statusJump to behavior
          Source: /tmp/na.elf (PID: 5519)File opened: /proc/130/statusJump to behavior
          Source: /tmp/na.elf (PID: 5519)File opened: /proc/251/statusJump to behavior
          Source: /tmp/na.elf (PID: 5519)File opened: /proc/131/statusJump to behavior
          Source: /tmp/na.elf (PID: 5519)File opened: /proc/132/statusJump to behavior
          Source: /tmp/na.elf (PID: 5519)File opened: /proc/133/statusJump to behavior
          Source: /tmp/na.elf (PID: 5519)File opened: /proc/1479/statusJump to behavior
          Source: /tmp/na.elf (PID: 5519)File opened: /proc/378/statusJump to behavior
          Source: /tmp/na.elf (PID: 5519)File opened: /proc/258/statusJump to behavior
          Source: /tmp/na.elf (PID: 5519)File opened: /proc/259/statusJump to behavior
          Source: /tmp/na.elf (PID: 5519)File opened: /proc/931/statusJump to behavior
          Source: /tmp/na.elf (PID: 5519)File opened: /proc/1595/statusJump to behavior
          Source: /tmp/na.elf (PID: 5519)File opened: /proc/812/statusJump to behavior
          Source: /tmp/na.elf (PID: 5519)File opened: /proc/933/statusJump to behavior
          Source: /tmp/na.elf (PID: 5519)File opened: /proc/30/statusJump to behavior
          Source: /tmp/na.elf (PID: 5519)File opened: /proc/3419/statusJump to behavior
          Source: /tmp/na.elf (PID: 5519)File opened: /proc/35/statusJump to behavior
          Source: /tmp/na.elf (PID: 5519)File opened: /proc/3310/statusJump to behavior
          Source: /tmp/na.elf (PID: 5519)File opened: /proc/260/statusJump to behavior
          Source: /tmp/na.elf (PID: 5519)File opened: /proc/261/statusJump to behavior
          Source: /tmp/na.elf (PID: 5519)File opened: /proc/262/statusJump to behavior
          Source: /tmp/na.elf (PID: 5519)File opened: /proc/142/statusJump to behavior
          Source: /tmp/na.elf (PID: 5519)File opened: /proc/263/statusJump to behavior
          Source: /tmp/na.elf (PID: 5519)File opened: /proc/264/statusJump to behavior
          Source: /tmp/na.elf (PID: 5519)File opened: /proc/265/statusJump to behavior
          Source: /tmp/na.elf (PID: 5519)File opened: /proc/145/statusJump to behavior
          Source: /tmp/na.elf (PID: 5519)File opened: /proc/266/statusJump to behavior
          Source: /tmp/na.elf (PID: 5519)File opened: /proc/267/statusJump to behavior
          Source: /tmp/na.elf (PID: 5519)File opened: /proc/268/statusJump to behavior
          Source: /tmp/na.elf (PID: 5519)File opened: /proc/3303/statusJump to behavior
          Source: /tmp/na.elf (PID: 5519)File opened: /proc/269/statusJump to behavior
          Source: /tmp/na.elf (PID: 5519)File opened: /proc/1486/statusJump to behavior
          Source: /tmp/na.elf (PID: 5519)File opened: /proc/1806/statusJump to behavior
          Source: /tmp/na.elf (PID: 5519)File opened: /proc/3440/statusJump to behavior
          Source: /tmp/na.elf (PID: 5519)File opened: /proc/270/statusJump to behavior
          Source: /tmp/na.elf (PID: 5519)Queries kernel information via 'uname': Jump to behavior
          Source: na.elf, 5519.1.00007ffefafd4000.00007ffefaff5000.rw-.sdmp, na.elf, 5521.1.00007ffefafd4000.00007ffefaff5000.rw-.sdmp, na.elf, 5523.1.00007ffefafd4000.00007ffefaff5000.rw-.sdmp, na.elf, 5540.1.00007ffefafd4000.00007ffefaff5000.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-m68k/tmp/na.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/na.elf
          Source: na.elf, 5519.1.000055d8bd139000.000055d8bd1c1000.rw-.sdmp, na.elf, 5521.1.000055d8bd139000.000055d8bd19d000.rw-.sdmp, na.elf, 5523.1.000055d8bd139000.000055d8bd19d000.rw-.sdmp, na.elf, 5540.1.000055d8bd139000.000055d8bd1c1000.rw-.sdmpBinary or memory string: U!/etc/qemu-binfmt/m68k
          Source: na.elf, 5519.1.00007ffefafd4000.00007ffefaff5000.rw-.sdmp, na.elf, 5521.1.00007ffefafd4000.00007ffefaff5000.rw-.sdmp, na.elf, 5523.1.00007ffefafd4000.00007ffefaff5000.rw-.sdmp, na.elf, 5540.1.00007ffefafd4000.00007ffefaff5000.rw-.sdmpBinary or memory string: /usr/bin/qemu-m68k
          Source: na.elf, 5519.1.000055d8bd139000.000055d8bd1c1000.rw-.sdmp, na.elf, 5521.1.000055d8bd139000.000055d8bd19d000.rw-.sdmp, na.elf, 5523.1.000055d8bd139000.000055d8bd19d000.rw-.sdmp, na.elf, 5540.1.000055d8bd139000.000055d8bd1c1000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/m68k

          Stealing of Sensitive Information

          barindex
          Source: Yara matchFile source: na.elf, type: SAMPLE
          Source: Yara matchFile source: 5523.1.00007f7750001000.00007f7750019000.r-x.sdmp, type: MEMORY
          Source: Yara matchFile source: 5519.1.00007f7750001000.00007f7750019000.r-x.sdmp, type: MEMORY
          Source: Yara matchFile source: 5521.1.00007f7750001000.00007f7750019000.r-x.sdmp, type: MEMORY
          Source: Yara matchFile source: 5540.1.00007f7750001000.00007f7750019000.r-x.sdmp, type: MEMORY
          Source: Yara matchFile source: Process Memory Space: na.elf PID: 5519, type: MEMORYSTR
          Source: Yara matchFile source: Process Memory Space: na.elf PID: 5521, type: MEMORYSTR
          Source: Yara matchFile source: Process Memory Space: na.elf PID: 5523, type: MEMORYSTR
          Source: Yara matchFile source: Process Memory Space: na.elf PID: 5540, type: MEMORYSTR

          Remote Access Functionality

          barindex
          Source: Yara matchFile source: na.elf, type: SAMPLE
          Source: Yara matchFile source: 5523.1.00007f7750001000.00007f7750019000.r-x.sdmp, type: MEMORY
          Source: Yara matchFile source: 5519.1.00007f7750001000.00007f7750019000.r-x.sdmp, type: MEMORY
          Source: Yara matchFile source: 5521.1.00007f7750001000.00007f7750019000.r-x.sdmp, type: MEMORY
          Source: Yara matchFile source: 5540.1.00007f7750001000.00007f7750019000.r-x.sdmp, type: MEMORY
          Source: Yara matchFile source: Process Memory Space: na.elf PID: 5519, type: MEMORYSTR
          Source: Yara matchFile source: Process Memory Space: na.elf PID: 5521, type: MEMORYSTR
          Source: Yara matchFile source: Process Memory Space: na.elf PID: 5523, type: MEMORYSTR
          Source: Yara matchFile source: Process Memory Space: na.elf PID: 5540, type: MEMORYSTR
          ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
          Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath InterceptionDirect Volume Access1
          OS Credential Dumping
          11
          Security Software Discovery
          Remote ServicesData from Local System1
          Non-Standard Port
          Exfiltration Over Other Network MediumAbuse Accessibility Features
          No configs have been found
          Hide Legend

          Legend:

          • Process
          • Signature
          • Created File
          • DNS/IP Info
          • Is Dropped
          • Number of created Files
          • Is malicious
          • Internet
          behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1536980 Sample: na.elf Startdate: 18/10/2024 Architecture: LINUX Score: 64 20 45.86.155.23, 3778, 58160, 58162 EVERYONE-BANDWIDTH-INCDE Germany 2->20 22 Malicious sample detected (through community Yara rule) 2->22 24 Antivirus / Scanner detection for submitted sample 2->24 26 Yara detected Mirai 2->26 8 na.elf 2->8         started        signatures3 process4 process5 10 na.elf 8->10         started        12 na.elf 8->12         started        14 na.elf 8->14         started        process6 16 na.elf 10->16         started        18 na.elf 10->18         started       

          This section contains all screenshots as thumbnails, including those not shown in the slideshow.


          windows-stand
          SourceDetectionScannerLabelLink
          na.elf100%AviraLINUX/Mirai.bonb
          No Antivirus matches
          No Antivirus matches
          No Antivirus matches
          No contacted domains info
          • No. of IPs < 25%
          • 25% < No. of IPs < 50%
          • 50% < No. of IPs < 75%
          • 75% < No. of IPs
          IPDomainCountryFlagASNASN NameMalicious
          45.86.155.23
          unknownGermany
          202322EVERYONE-BANDWIDTH-INCDEfalse
          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
          45.86.155.23na.elfGet hashmaliciousUnknownBrowse
            na.elfGet hashmaliciousUnknownBrowse
              No context
              MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
              EVERYONE-BANDWIDTH-INCDEna.elfGet hashmaliciousUnknownBrowse
              • 45.86.155.23
              na.elfGet hashmaliciousUnknownBrowse
              • 45.86.155.23
              http://qgasyntax.com/2753402WB7192675vw697764118Il17367cC38SJr190893GZGet hashmaliciousPhisherBrowse
              • 45.13.225.215
              K5P6Oe31Kq.elfGet hashmaliciousMiraiBrowse
              • 45.133.73.210
              No context
              No context
              No created / dropped files found
              File type:ELF 32-bit MSB executable, Motorola m68k, 68020, version 1 (SYSV), statically linked, stripped
              Entropy (8bit):6.27386271018054
              TrID:
              • ELF Executable and Linkable format (generic) (4004/1) 100.00%
              File name:na.elf
              File size:97'552 bytes
              MD5:0238b625efdffe4d312ffc6afd840cf8
              SHA1:d88261c035ba355c7f8267fa3d68a62b3012079f
              SHA256:1f4d4fb0a1ca4abcfcaa37863fa404b78b8eac3e6ed66f6646c94053eb6da894
              SHA512:6eca6159eeb54dec4fd996f4f39752691b55f52c334e5c5749bf72ec1417eb390d3a4422a489088a4ec28dd53b981642875a247ece597ae15e15760f4d38fd15
              SSDEEP:1536:RsSFA59NqetNpGXnwzX8/EqXabQeuacWjcW0JcWcBl4rZpipI4WlV/N4zfVZolAm:GS6NqekOXqqbQeuacWjcW0JcWcBSrZpx
              TLSH:279319C7F810ED7EF80BD67748534D0E7671F2A00A930A227767BA67EC761A5142BD82
              File Content Preview:.ELF.......................D...4..{......4. ...(......................x...x....... .......x............x..*....... .dt.Q............................NV..a....da...P N^NuNV..J9...@f>"y.... QJ.g.X.#.....N."y.... QJ.f.A.....J.g.Hy....N.X........@N^NuNV..N^NuN

              ELF header

              Class:ELF32
              Data:2's complement, big endian
              Version:1 (current)
              Machine:MC68000
              Version Number:0x1
              Type:EXEC (Executable file)
              OS/ABI:UNIX - System V
              ABI Version:0
              Entry Point Address:0x80000144
              Flags:0x0
              ELF Header Size:52
              Program Header Offset:52
              Program Header Size:32
              Number of Program Headers:3
              Section Header Offset:97152
              Section Header Size:40
              Number of Section Headers:10
              Header String Table Index:9
              NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
              NULL0x00x00x00x00x0000
              .initPROGBITS0x800000940x940x140x00x6AX002
              .textPROGBITS0x800000a80xa80x1504a0x00x6AX004
              .finiPROGBITS0x800150f20x150f20xe0x00x6AX002
              .rodataPROGBITS0x800151000x151000x27c10x00x2A002
              .ctorsPROGBITS0x800198c80x178c80x80x00x3WA004
              .dtorsPROGBITS0x800198d00x178d00x80x00x3WA004
              .dataPROGBITS0x800198dc0x178dc0x2640x00x3WA004
              .bssNOBITS0x80019b400x17b400x28180x00x3WA004
              .shstrtabSTRTAB0x00x17b400x3e0x00x0001
              TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
              LOAD0x00x800000000x800000000x178c10x178c16.28940x5R E0x2000.init .text .fini .rodata
              LOAD0x178c80x800198c80x800198c80x2780x2a903.65170x6RW 0x2000.ctors .dtors .data .bss
              GNU_STACK0x00x00x00x00x00.00000x6RW 0x4
              TimestampSource PortDest PortSource IPDest IP
              Oct 18, 2024 13:27:55.911839008 CEST581603778192.168.2.1545.86.155.23
              Oct 18, 2024 13:27:55.917535067 CEST37785816045.86.155.23192.168.2.15
              Oct 18, 2024 13:27:55.917591095 CEST581603778192.168.2.1545.86.155.23
              Oct 18, 2024 13:27:55.935849905 CEST581603778192.168.2.1545.86.155.23
              Oct 18, 2024 13:27:55.940831900 CEST37785816045.86.155.23192.168.2.15
              Oct 18, 2024 13:27:55.940884113 CEST581603778192.168.2.1545.86.155.23
              Oct 18, 2024 13:27:55.945719957 CEST37785816045.86.155.23192.168.2.15
              Oct 18, 2024 13:27:56.784873009 CEST37785816045.86.155.23192.168.2.15
              Oct 18, 2024 13:27:56.785053968 CEST581603778192.168.2.1545.86.155.23
              Oct 18, 2024 13:27:56.785141945 CEST581603778192.168.2.1545.86.155.23
              Oct 18, 2024 13:27:56.785716057 CEST581623778192.168.2.1545.86.155.23
              Oct 18, 2024 13:27:56.791461945 CEST37785816245.86.155.23192.168.2.15
              Oct 18, 2024 13:27:56.791594982 CEST581623778192.168.2.1545.86.155.23
              Oct 18, 2024 13:27:56.792581081 CEST581623778192.168.2.1545.86.155.23
              Oct 18, 2024 13:27:56.797470093 CEST37785816245.86.155.23192.168.2.15
              Oct 18, 2024 13:27:56.797525883 CEST581623778192.168.2.1545.86.155.23
              Oct 18, 2024 13:27:56.802397013 CEST37785816245.86.155.23192.168.2.15
              Oct 18, 2024 13:27:57.627167940 CEST37785816245.86.155.23192.168.2.15
              Oct 18, 2024 13:27:57.627363920 CEST581623778192.168.2.1545.86.155.23
              Oct 18, 2024 13:27:57.627363920 CEST581623778192.168.2.1545.86.155.23
              Oct 18, 2024 13:27:57.627811909 CEST581643778192.168.2.1545.86.155.23
              Oct 18, 2024 13:27:57.632688999 CEST37785816445.86.155.23192.168.2.15
              Oct 18, 2024 13:27:57.632755041 CEST581643778192.168.2.1545.86.155.23
              Oct 18, 2024 13:27:57.633781910 CEST581643778192.168.2.1545.86.155.23
              Oct 18, 2024 13:27:57.638632059 CEST37785816445.86.155.23192.168.2.15
              Oct 18, 2024 13:27:57.638689995 CEST581643778192.168.2.1545.86.155.23
              Oct 18, 2024 13:27:57.643609047 CEST37785816445.86.155.23192.168.2.15
              Oct 18, 2024 13:27:58.454508066 CEST37785816445.86.155.23192.168.2.15
              Oct 18, 2024 13:27:58.454619884 CEST581643778192.168.2.1545.86.155.23
              Oct 18, 2024 13:27:58.454695940 CEST581643778192.168.2.1545.86.155.23
              Oct 18, 2024 13:27:58.455250025 CEST581663778192.168.2.1545.86.155.23
              Oct 18, 2024 13:27:58.460081100 CEST37785816645.86.155.23192.168.2.15
              Oct 18, 2024 13:27:58.460145950 CEST581663778192.168.2.1545.86.155.23
              Oct 18, 2024 13:27:58.460939884 CEST581663778192.168.2.1545.86.155.23
              Oct 18, 2024 13:27:58.465858936 CEST37785816645.86.155.23192.168.2.15
              Oct 18, 2024 13:27:58.465904951 CEST581663778192.168.2.1545.86.155.23
              Oct 18, 2024 13:27:58.470779896 CEST37785816645.86.155.23192.168.2.15
              Oct 18, 2024 13:27:59.299453974 CEST37785816645.86.155.23192.168.2.15
              Oct 18, 2024 13:27:59.299562931 CEST581663778192.168.2.1545.86.155.23
              Oct 18, 2024 13:27:59.299609900 CEST581663778192.168.2.1545.86.155.23
              Oct 18, 2024 13:27:59.300487995 CEST581683778192.168.2.1545.86.155.23
              Oct 18, 2024 13:27:59.305318117 CEST37785816845.86.155.23192.168.2.15
              Oct 18, 2024 13:27:59.305397034 CEST581683778192.168.2.1545.86.155.23
              Oct 18, 2024 13:27:59.306143999 CEST581683778192.168.2.1545.86.155.23
              Oct 18, 2024 13:27:59.311038017 CEST37785816845.86.155.23192.168.2.15
              Oct 18, 2024 13:27:59.311093092 CEST581683778192.168.2.1545.86.155.23
              Oct 18, 2024 13:27:59.315896988 CEST37785816845.86.155.23192.168.2.15
              Oct 18, 2024 13:28:00.147074938 CEST37785816845.86.155.23192.168.2.15
              Oct 18, 2024 13:28:00.147113085 CEST37785816845.86.155.23192.168.2.15
              Oct 18, 2024 13:28:00.147279024 CEST581683778192.168.2.1545.86.155.23
              Oct 18, 2024 13:28:00.147279024 CEST581683778192.168.2.1545.86.155.23
              Oct 18, 2024 13:28:00.147279024 CEST581683778192.168.2.1545.86.155.23
              Oct 18, 2024 13:28:00.147883892 CEST581703778192.168.2.1545.86.155.23
              Oct 18, 2024 13:28:00.152928114 CEST37785817045.86.155.23192.168.2.15
              Oct 18, 2024 13:28:00.153002977 CEST581703778192.168.2.1545.86.155.23
              Oct 18, 2024 13:28:00.153757095 CEST581703778192.168.2.1545.86.155.23
              Oct 18, 2024 13:28:00.158734083 CEST37785817045.86.155.23192.168.2.15
              Oct 18, 2024 13:28:00.158788919 CEST581703778192.168.2.1545.86.155.23
              Oct 18, 2024 13:28:00.163819075 CEST37785817045.86.155.23192.168.2.15
              Oct 18, 2024 13:28:00.992657900 CEST37785817045.86.155.23192.168.2.15
              Oct 18, 2024 13:28:00.992706060 CEST37785817045.86.155.23192.168.2.15
              Oct 18, 2024 13:28:00.993016005 CEST581703778192.168.2.1545.86.155.23
              Oct 18, 2024 13:28:00.993016005 CEST581703778192.168.2.1545.86.155.23
              Oct 18, 2024 13:28:00.993016005 CEST581703778192.168.2.1545.86.155.23
              Oct 18, 2024 13:28:00.993509054 CEST581723778192.168.2.1545.86.155.23
              Oct 18, 2024 13:28:00.998626947 CEST37785817245.86.155.23192.168.2.15
              Oct 18, 2024 13:28:00.998692036 CEST581723778192.168.2.1545.86.155.23
              Oct 18, 2024 13:28:00.999512911 CEST581723778192.168.2.1545.86.155.23
              Oct 18, 2024 13:28:01.005759001 CEST37785817245.86.155.23192.168.2.15
              Oct 18, 2024 13:28:01.005815983 CEST581723778192.168.2.1545.86.155.23
              Oct 18, 2024 13:28:01.011923075 CEST37785817245.86.155.23192.168.2.15
              Oct 18, 2024 13:28:01.539935112 CEST581743778192.168.2.1545.86.155.23
              Oct 18, 2024 13:28:01.544967890 CEST37785817445.86.155.23192.168.2.15
              Oct 18, 2024 13:28:01.545022964 CEST581743778192.168.2.1545.86.155.23
              Oct 18, 2024 13:28:01.601846933 CEST581743778192.168.2.1545.86.155.23
              Oct 18, 2024 13:28:01.606723070 CEST37785817445.86.155.23192.168.2.15
              Oct 18, 2024 13:28:01.606770992 CEST581743778192.168.2.1545.86.155.23
              Oct 18, 2024 13:28:01.611758947 CEST37785817445.86.155.23192.168.2.15
              Oct 18, 2024 13:28:01.826214075 CEST37785817245.86.155.23192.168.2.15
              Oct 18, 2024 13:28:01.826256037 CEST37785817245.86.155.23192.168.2.15
              Oct 18, 2024 13:28:01.826288939 CEST581723778192.168.2.1545.86.155.23
              Oct 18, 2024 13:28:01.826333046 CEST581723778192.168.2.1545.86.155.23
              Oct 18, 2024 13:28:01.826344967 CEST581723778192.168.2.1545.86.155.23
              Oct 18, 2024 13:28:01.826869965 CEST581763778192.168.2.1545.86.155.23
              Oct 18, 2024 13:28:01.831775904 CEST37785817645.86.155.23192.168.2.15
              Oct 18, 2024 13:28:01.831845045 CEST581763778192.168.2.1545.86.155.23
              Oct 18, 2024 13:28:01.832704067 CEST581763778192.168.2.1545.86.155.23
              Oct 18, 2024 13:28:01.837686062 CEST37785817645.86.155.23192.168.2.15
              Oct 18, 2024 13:28:01.837737083 CEST581763778192.168.2.1545.86.155.23
              Oct 18, 2024 13:28:01.842621088 CEST37785817645.86.155.23192.168.2.15
              Oct 18, 2024 13:28:02.392359972 CEST37785817445.86.155.23192.168.2.15
              Oct 18, 2024 13:28:02.392513990 CEST581743778192.168.2.1545.86.155.23
              Oct 18, 2024 13:28:02.392653942 CEST581743778192.168.2.1545.86.155.23
              Oct 18, 2024 13:28:02.393241882 CEST581783778192.168.2.1545.86.155.23
              Oct 18, 2024 13:28:02.398117065 CEST37785817845.86.155.23192.168.2.15
              Oct 18, 2024 13:28:02.398181915 CEST581783778192.168.2.1545.86.155.23
              Oct 18, 2024 13:28:02.399000883 CEST581783778192.168.2.1545.86.155.23
              Oct 18, 2024 13:28:02.403831005 CEST37785817845.86.155.23192.168.2.15
              Oct 18, 2024 13:28:02.403897047 CEST581783778192.168.2.1545.86.155.23
              Oct 18, 2024 13:28:02.408947945 CEST37785817845.86.155.23192.168.2.15
              Oct 18, 2024 13:28:02.677953959 CEST37785817645.86.155.23192.168.2.15
              Oct 18, 2024 13:28:02.678061008 CEST581763778192.168.2.1545.86.155.23
              Oct 18, 2024 13:28:02.678103924 CEST581763778192.168.2.1545.86.155.23
              Oct 18, 2024 13:28:02.678797960 CEST581803778192.168.2.1545.86.155.23
              Oct 18, 2024 13:28:02.683692932 CEST37785818045.86.155.23192.168.2.15
              Oct 18, 2024 13:28:02.683763027 CEST581803778192.168.2.1545.86.155.23
              Oct 18, 2024 13:28:02.685050011 CEST581803778192.168.2.1545.86.155.23
              Oct 18, 2024 13:28:02.689914942 CEST37785818045.86.155.23192.168.2.15
              Oct 18, 2024 13:28:02.689965010 CEST581803778192.168.2.1545.86.155.23
              Oct 18, 2024 13:28:02.694878101 CEST37785818045.86.155.23192.168.2.15
              Oct 18, 2024 13:28:03.247823000 CEST37785817845.86.155.23192.168.2.15
              Oct 18, 2024 13:28:03.247853994 CEST37785817845.86.155.23192.168.2.15
              Oct 18, 2024 13:28:03.247936010 CEST581783778192.168.2.1545.86.155.23
              Oct 18, 2024 13:28:03.247936964 CEST581783778192.168.2.1545.86.155.23
              Oct 18, 2024 13:28:03.248018026 CEST581783778192.168.2.1545.86.155.23
              Oct 18, 2024 13:28:03.248553991 CEST581823778192.168.2.1545.86.155.23
              Oct 18, 2024 13:28:03.253451109 CEST37785818245.86.155.23192.168.2.15
              Oct 18, 2024 13:28:03.253513098 CEST581823778192.168.2.1545.86.155.23
              Oct 18, 2024 13:28:03.254342079 CEST581823778192.168.2.1545.86.155.23
              Oct 18, 2024 13:28:03.259373903 CEST37785818245.86.155.23192.168.2.15
              Oct 18, 2024 13:28:03.259426117 CEST581823778192.168.2.1545.86.155.23
              Oct 18, 2024 13:28:03.264370918 CEST37785818245.86.155.23192.168.2.15
              Oct 18, 2024 13:28:03.509926081 CEST37785818045.86.155.23192.168.2.15
              Oct 18, 2024 13:28:03.510019064 CEST581803778192.168.2.1545.86.155.23
              Oct 18, 2024 13:28:03.510066032 CEST581803778192.168.2.1545.86.155.23
              Oct 18, 2024 13:28:03.510637999 CEST581843778192.168.2.1545.86.155.23
              Oct 18, 2024 13:28:03.515533924 CEST37785818445.86.155.23192.168.2.15
              Oct 18, 2024 13:28:03.515590906 CEST581843778192.168.2.1545.86.155.23
              Oct 18, 2024 13:28:03.516486883 CEST581843778192.168.2.1545.86.155.23
              Oct 18, 2024 13:28:03.521485090 CEST37785818445.86.155.23192.168.2.15
              Oct 18, 2024 13:28:03.521531105 CEST581843778192.168.2.1545.86.155.23
              Oct 18, 2024 13:28:03.526395082 CEST37785818445.86.155.23192.168.2.15
              Oct 18, 2024 13:28:04.080039024 CEST37785818245.86.155.23192.168.2.15
              Oct 18, 2024 13:28:04.080096006 CEST37785818245.86.155.23192.168.2.15
              Oct 18, 2024 13:28:04.080123901 CEST581823778192.168.2.1545.86.155.23
              Oct 18, 2024 13:28:04.080147028 CEST581823778192.168.2.1545.86.155.23
              Oct 18, 2024 13:28:04.080168009 CEST581823778192.168.2.1545.86.155.23
              Oct 18, 2024 13:28:04.080579996 CEST581863778192.168.2.1545.86.155.23
              Oct 18, 2024 13:28:04.085398912 CEST37785818645.86.155.23192.168.2.15
              Oct 18, 2024 13:28:04.085453987 CEST581863778192.168.2.1545.86.155.23
              Oct 18, 2024 13:28:04.086055040 CEST581863778192.168.2.1545.86.155.23
              Oct 18, 2024 13:28:04.090991974 CEST37785818645.86.155.23192.168.2.15
              Oct 18, 2024 13:28:04.091039896 CEST581863778192.168.2.1545.86.155.23
              Oct 18, 2024 13:28:04.095935106 CEST37785818645.86.155.23192.168.2.15
              Oct 18, 2024 13:28:04.355173111 CEST37785818445.86.155.23192.168.2.15
              Oct 18, 2024 13:28:04.355276108 CEST581843778192.168.2.1545.86.155.23
              Oct 18, 2024 13:28:04.355276108 CEST581843778192.168.2.1545.86.155.23
              Oct 18, 2024 13:28:04.355681896 CEST581883778192.168.2.1545.86.155.23
              Oct 18, 2024 13:28:04.360994101 CEST37785818845.86.155.23192.168.2.15
              Oct 18, 2024 13:28:04.361051083 CEST581883778192.168.2.1545.86.155.23
              Oct 18, 2024 13:28:04.361866951 CEST581883778192.168.2.1545.86.155.23
              Oct 18, 2024 13:28:04.366842031 CEST37785818845.86.155.23192.168.2.15
              Oct 18, 2024 13:28:04.366908073 CEST581883778192.168.2.1545.86.155.23
              Oct 18, 2024 13:28:04.371934891 CEST37785818845.86.155.23192.168.2.15
              Oct 18, 2024 13:28:05.197027922 CEST37785818845.86.155.23192.168.2.15
              Oct 18, 2024 13:28:05.197160959 CEST581883778192.168.2.1545.86.155.23
              Oct 18, 2024 13:28:05.197273016 CEST581883778192.168.2.1545.86.155.23
              Oct 18, 2024 13:28:05.197735071 CEST581903778192.168.2.1545.86.155.23
              Oct 18, 2024 13:28:05.203282118 CEST37785819045.86.155.23192.168.2.15
              Oct 18, 2024 13:28:05.203380108 CEST581903778192.168.2.1545.86.155.23
              Oct 18, 2024 13:28:05.204166889 CEST581903778192.168.2.1545.86.155.23
              Oct 18, 2024 13:28:05.209198952 CEST37785819045.86.155.23192.168.2.15
              Oct 18, 2024 13:28:05.209239960 CEST581903778192.168.2.1545.86.155.23
              Oct 18, 2024 13:28:05.214183092 CEST37785819045.86.155.23192.168.2.15
              Oct 18, 2024 13:28:14.096350908 CEST581863778192.168.2.1545.86.155.23
              Oct 18, 2024 13:28:14.101367950 CEST37785818645.86.155.23192.168.2.15
              Oct 18, 2024 13:28:14.338303089 CEST37785818645.86.155.23192.168.2.15
              Oct 18, 2024 13:28:14.338475943 CEST581863778192.168.2.1545.86.155.23
              Oct 18, 2024 13:28:15.209634066 CEST581903778192.168.2.1545.86.155.23
              Oct 18, 2024 13:28:15.214822054 CEST37785819045.86.155.23192.168.2.15
              Oct 18, 2024 13:28:15.455979109 CEST37785819045.86.155.23192.168.2.15
              Oct 18, 2024 13:28:15.456087112 CEST581903778192.168.2.1545.86.155.23
              Oct 18, 2024 13:29:14.398072004 CEST581863778192.168.2.1545.86.155.23
              Oct 18, 2024 13:29:14.405742884 CEST37785818645.86.155.23192.168.2.15
              Oct 18, 2024 13:29:14.642874002 CEST37785818645.86.155.23192.168.2.15
              Oct 18, 2024 13:29:14.642983913 CEST581863778192.168.2.1545.86.155.23
              Oct 18, 2024 13:29:15.500757933 CEST581903778192.168.2.1545.86.155.23
              Oct 18, 2024 13:29:15.505861044 CEST37785819045.86.155.23192.168.2.15
              Oct 18, 2024 13:29:15.743264914 CEST37785819045.86.155.23192.168.2.15
              Oct 18, 2024 13:29:15.743608952 CEST581903778192.168.2.1545.86.155.23

              System Behavior

              Start time (UTC):11:27:54
              Start date (UTC):18/10/2024
              Path:/tmp/na.elf
              Arguments:/tmp/na.elf
              File size:4463432 bytes
              MD5 hash:cd177594338c77b895ae27c33f8f86cc

              Start time (UTC):11:27:54
              Start date (UTC):18/10/2024
              Path:/tmp/na.elf
              Arguments:-
              File size:4463432 bytes
              MD5 hash:cd177594338c77b895ae27c33f8f86cc

              Start time (UTC):11:27:54
              Start date (UTC):18/10/2024
              Path:/tmp/na.elf
              Arguments:-
              File size:4463432 bytes
              MD5 hash:cd177594338c77b895ae27c33f8f86cc

              Start time (UTC):11:27:54
              Start date (UTC):18/10/2024
              Path:/tmp/na.elf
              Arguments:-
              File size:4463432 bytes
              MD5 hash:cd177594338c77b895ae27c33f8f86cc

              Start time (UTC):11:28:00
              Start date (UTC):18/10/2024
              Path:/tmp/na.elf
              Arguments:-
              File size:4463432 bytes
              MD5 hash:cd177594338c77b895ae27c33f8f86cc

              Start time (UTC):11:28:00
              Start date (UTC):18/10/2024
              Path:/tmp/na.elf
              Arguments:-
              File size:4463432 bytes
              MD5 hash:cd177594338c77b895ae27c33f8f86cc