Edit tour
Linux
Analysis Report
x86.elf
Overview
General Information
Sample name: | x86.elf |
Analysis ID: | 1554844 |
MD5: | c9cc4534c5122223e5282a852219f2d5 |
SHA1: | c4e23822052a18c0a8a2b215d919c616244b2c55 |
SHA256: | f4e06fd9e513da8ad3bb9a21d7944881ea1827fd2dd503fc13d27a8594fb899c |
Tags: | elfuser-abuse_ch |
Infos: |
Detection
Score: | 60 |
Range: | 0 - 100 |
Whitelisted: | false |
Signatures
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Machine Learning detection for sample
Detected TCP or UDP traffic on non-standard ports
Enumerates processes within the "proc" file system
Found strings indicative of a multi-platform dropper
Sample has stripped symbol table
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Yara signature match
Classification
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1554844 |
Start date and time: | 2024-11-13 01:19:07 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 4m 54s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultlinuxfilecookbook.jbs |
Analysis system description: | Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11) |
Analysis Mode: | default |
Sample name: | x86.elf |
Detection: | MAL |
Classification: | mal60.linELF@0/0@0/0 |
Command: | /tmp/x86.elf |
PID: | 6269 |
Exit Code: | 0 |
Exit Code Info: | |
Killed: | False |
Standard Output: | Onboard the boat |
Standard Error: |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
Linux_Trojan_Mirai_b14f4c5d | unknown | unknown |
| |
Linux_Trojan_Mirai_88de437f | unknown | unknown |
| |
Linux_Trojan_Mirai_ae9d0fa6 | unknown | unknown |
| |
Linux_Trojan_Mirai_389ee3e9 | unknown | unknown |
| |
Linux_Trojan_Mirai_cc93863b | unknown | unknown |
| |
Click to see the 1 entries |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
Linux_Trojan_Mirai_b14f4c5d | unknown | unknown |
| |
Linux_Trojan_Mirai_88de437f | unknown | unknown |
| |
Linux_Trojan_Mirai_ae9d0fa6 | unknown | unknown |
| |
Linux_Trojan_Mirai_389ee3e9 | unknown | unknown |
| |
Linux_Trojan_Mirai_cc93863b | unknown | unknown |
| |
Click to see the 1 entries |
⊘No Suricata rule has matched
Click to jump to signature section
Show All Signature Results
AV Detection |
---|
Source: | ReversingLabs: |
Source: | Joe Sandbox ML: |
Source: | String: |
Source: | TCP traffic: |
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
System Summary |
---|
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | .symtab present: |
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Classification label: |
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | 1 Scripting | Valid Accounts | Windows Management Instrumentation | 1 Scripting | Path Interception | Direct Volume Access | 1 OS Credential Dumping | System Service Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | Rootkit | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 1 Non-Standard Port | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 1 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
⊘No configs have been found
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
45% | ReversingLabs | Linux.Trojan.Mirai | ||
100% | Joe Sandbox ML |
⊘No Antivirus matches
⊘No Antivirus matches
⊘No Antivirus matches
⊘No contacted domains info
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
109.202.202.202 | unknown | Switzerland | 13030 | INIT7CH | false | |
154.213.187.125 | unknown | Seychelles | 22769 | DDOSING-BGP-NETWORKUS | false | |
91.189.91.43 | unknown | United Kingdom | 41231 | CANONICAL-ASGB | false | |
91.189.91.42 | unknown | United Kingdom | 41231 | CANONICAL-ASGB | false |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
109.202.202.202 | Get hash | malicious | Unknown | Browse |
| |
154.213.187.125 | Get hash | malicious | Unknown | Browse | ||
91.189.91.43 | Get hash | malicious | Unknown | Browse | ||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Mirai | Browse | |||
91.189.91.42 | Get hash | malicious | Unknown | Browse | ||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Mirai | Browse |
⊘No context
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
CANONICAL-ASGB | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
CANONICAL-ASGB | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
INIT7CH | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
DDOSING-BGP-NETWORKUS | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
⊘No context
⊘No context
⊘No created / dropped files found
File type: | |
Entropy (8bit): | 6.517162073073792 |
TrID: |
|
File name: | x86.elf |
File size: | 47'628 bytes |
MD5: | c9cc4534c5122223e5282a852219f2d5 |
SHA1: | c4e23822052a18c0a8a2b215d919c616244b2c55 |
SHA256: | f4e06fd9e513da8ad3bb9a21d7944881ea1827fd2dd503fc13d27a8594fb899c |
SHA512: | 8bda409561694c399a71b3c0d7be2e5099cfb8aab1a1a2db57905570d609bb807b87286370d0f33eeaa4dd39f5afe8b918ce98588ba9915f8b451e73de6c3d8e |
SSDEEP: | 768:eZhXwvAoa+eVC6LAqIEKdNPF2IqnDRDiCW3irxWKun+8H1fLb658fJSiIDK:chXwvta+eCPfPMIcU3CWKunlH9Lb6IJJ |
TLSH: | FE236CC5E983E8F5ED57017611B3F7378AB6F53A1029DA93C3589936E892A00E71A34C |
File Content Preview: | .ELF....................d...4...|.......4. ...(..............................................E...E..|...@i..........Q.td............................U..S.......7....h....C...[]...$.............U......=@H...t..5.....E......E......u........t....h.5.......... |
ELF header | |
---|---|
Class: | |
Data: | |
Version: | |
Machine: | |
Version Number: | |
Type: | |
OS/ABI: | |
ABI Version: | 0 |
Entry Point Address: | |
Flags: | |
ELF Header Size: | 52 |
Program Header Offset: | 52 |
Program Header Size: | 32 |
Number of Program Headers: | 3 |
Section Header Offset: | 47228 |
Section Header Size: | 40 |
Number of Section Headers: | 10 |
Header String Table Index: | 9 |
Name | Type | Address | Offset | Size | EntSize | Flags | Flags Description | Link | Info | Align |
---|---|---|---|---|---|---|---|---|---|---|
NULL | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0 | 0 | 0 | ||
.init | PROGBITS | 0x8048094 | 0x94 | 0x1c | 0x0 | 0x6 | AX | 0 | 0 | 1 |
.text | PROGBITS | 0x80480b0 | 0xb0 | 0xa066 | 0x0 | 0x6 | AX | 0 | 0 | 16 |
.fini | PROGBITS | 0x8052116 | 0xa116 | 0x17 | 0x0 | 0x6 | AX | 0 | 0 | 1 |
.rodata | PROGBITS | 0x8052140 | 0xa140 | 0x147c | 0x0 | 0x2 | A | 0 | 0 | 32 |
.ctors | PROGBITS | 0x80545c0 | 0xb5c0 | 0x8 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.dtors | PROGBITS | 0x80545c8 | 0xb5c8 | 0x8 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.data | PROGBITS | 0x80545e0 | 0xb5e0 | 0x25c | 0x0 | 0x3 | WA | 0 | 0 | 32 |
.bss | NOBITS | 0x8054840 | 0xb83c | 0x66c0 | 0x0 | 0x3 | WA | 0 | 0 | 32 |
.shstrtab | STRTAB | 0x0 | 0xb83c | 0x3e | 0x0 | 0x0 | 0 | 0 | 1 |
Type | Offset | Virtual Address | Physical Address | File Size | Memory Size | Entropy | Flags | Flags Description | Align | Prog Interpreter | Section Mappings |
---|---|---|---|---|---|---|---|---|---|---|---|
LOAD | 0x0 | 0x8048000 | 0x8048000 | 0xb5bc | 0xb5bc | 6.5604 | 0x5 | R E | 0x1000 | .init .text .fini .rodata | |
LOAD | 0xb5c0 | 0x80545c0 | 0x80545c0 | 0x27c | 0x6940 | 3.4475 | 0x6 | RW | 0x1000 | .ctors .dtors .data .bss | |
GNU_STACK | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0.0000 | 0x6 | RW | 0x4 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Nov 13, 2024 01:20:18.276002884 CET | 53478 | 51321 | 192.168.2.23 | 154.213.187.125 |
Nov 13, 2024 01:20:18.280824900 CET | 51321 | 53478 | 154.213.187.125 | 192.168.2.23 |
Nov 13, 2024 01:20:18.280890942 CET | 53478 | 51321 | 192.168.2.23 | 154.213.187.125 |
Nov 13, 2024 01:20:18.280910015 CET | 53478 | 51321 | 192.168.2.23 | 154.213.187.125 |
Nov 13, 2024 01:20:18.285700083 CET | 51321 | 53478 | 154.213.187.125 | 192.168.2.23 |
Nov 13, 2024 01:20:18.285734892 CET | 53478 | 51321 | 192.168.2.23 | 154.213.187.125 |
Nov 13, 2024 01:20:18.290596962 CET | 51321 | 53478 | 154.213.187.125 | 192.168.2.23 |
Nov 13, 2024 01:20:18.430733919 CET | 43928 | 443 | 192.168.2.23 | 91.189.91.42 |
Nov 13, 2024 01:20:19.302330017 CET | 51321 | 53478 | 154.213.187.125 | 192.168.2.23 |
Nov 13, 2024 01:20:19.302458048 CET | 53478 | 51321 | 192.168.2.23 | 154.213.187.125 |
Nov 13, 2024 01:20:19.307226896 CET | 51321 | 53478 | 154.213.187.125 | 192.168.2.23 |
Nov 13, 2024 01:20:20.303203106 CET | 53480 | 51321 | 192.168.2.23 | 154.213.187.125 |
Nov 13, 2024 01:20:20.307981014 CET | 51321 | 53480 | 154.213.187.125 | 192.168.2.23 |
Nov 13, 2024 01:20:20.308054924 CET | 53480 | 51321 | 192.168.2.23 | 154.213.187.125 |
Nov 13, 2024 01:20:20.308070898 CET | 53480 | 51321 | 192.168.2.23 | 154.213.187.125 |
Nov 13, 2024 01:20:20.312892914 CET | 51321 | 53480 | 154.213.187.125 | 192.168.2.23 |
Nov 13, 2024 01:20:20.312962055 CET | 53480 | 51321 | 192.168.2.23 | 154.213.187.125 |
Nov 13, 2024 01:20:20.317729950 CET | 51321 | 53480 | 154.213.187.125 | 192.168.2.23 |
Nov 13, 2024 01:20:21.313519001 CET | 51321 | 53480 | 154.213.187.125 | 192.168.2.23 |
Nov 13, 2024 01:20:21.313638926 CET | 53480 | 51321 | 192.168.2.23 | 154.213.187.125 |
Nov 13, 2024 01:20:21.318440914 CET | 51321 | 53480 | 154.213.187.125 | 192.168.2.23 |
Nov 13, 2024 01:20:22.314369917 CET | 53482 | 51321 | 192.168.2.23 | 154.213.187.125 |
Nov 13, 2024 01:20:22.319246054 CET | 51321 | 53482 | 154.213.187.125 | 192.168.2.23 |
Nov 13, 2024 01:20:22.319331884 CET | 53482 | 51321 | 192.168.2.23 | 154.213.187.125 |
Nov 13, 2024 01:20:22.319354057 CET | 53482 | 51321 | 192.168.2.23 | 154.213.187.125 |
Nov 13, 2024 01:20:22.324186087 CET | 51321 | 53482 | 154.213.187.125 | 192.168.2.23 |
Nov 13, 2024 01:20:22.324258089 CET | 53482 | 51321 | 192.168.2.23 | 154.213.187.125 |
Nov 13, 2024 01:20:22.329020977 CET | 51321 | 53482 | 154.213.187.125 | 192.168.2.23 |
Nov 13, 2024 01:20:23.305993080 CET | 51321 | 53482 | 154.213.187.125 | 192.168.2.23 |
Nov 13, 2024 01:20:23.306102991 CET | 53482 | 51321 | 192.168.2.23 | 154.213.187.125 |
Nov 13, 2024 01:20:23.311419010 CET | 51321 | 53482 | 154.213.187.125 | 192.168.2.23 |
Nov 13, 2024 01:20:24.061983109 CET | 42836 | 443 | 192.168.2.23 | 91.189.91.43 |
Nov 13, 2024 01:20:24.306812048 CET | 53484 | 51321 | 192.168.2.23 | 154.213.187.125 |
Nov 13, 2024 01:20:24.311821938 CET | 51321 | 53484 | 154.213.187.125 | 192.168.2.23 |
Nov 13, 2024 01:20:24.311911106 CET | 53484 | 51321 | 192.168.2.23 | 154.213.187.125 |
Nov 13, 2024 01:20:24.311911106 CET | 53484 | 51321 | 192.168.2.23 | 154.213.187.125 |
Nov 13, 2024 01:20:24.316956997 CET | 51321 | 53484 | 154.213.187.125 | 192.168.2.23 |
Nov 13, 2024 01:20:24.317007065 CET | 53484 | 51321 | 192.168.2.23 | 154.213.187.125 |
Nov 13, 2024 01:20:24.321849108 CET | 51321 | 53484 | 154.213.187.125 | 192.168.2.23 |
Nov 13, 2024 01:20:25.299989939 CET | 51321 | 53484 | 154.213.187.125 | 192.168.2.23 |
Nov 13, 2024 01:20:25.300076008 CET | 53484 | 51321 | 192.168.2.23 | 154.213.187.125 |
Nov 13, 2024 01:20:25.304898977 CET | 51321 | 53484 | 154.213.187.125 | 192.168.2.23 |
Nov 13, 2024 01:20:26.300724030 CET | 53486 | 51321 | 192.168.2.23 | 154.213.187.125 |
Nov 13, 2024 01:20:26.305896997 CET | 51321 | 53486 | 154.213.187.125 | 192.168.2.23 |
Nov 13, 2024 01:20:26.305973053 CET | 53486 | 51321 | 192.168.2.23 | 154.213.187.125 |
Nov 13, 2024 01:20:26.306015968 CET | 53486 | 51321 | 192.168.2.23 | 154.213.187.125 |
Nov 13, 2024 01:20:26.311117887 CET | 51321 | 53486 | 154.213.187.125 | 192.168.2.23 |
Nov 13, 2024 01:20:26.311161041 CET | 53486 | 51321 | 192.168.2.23 | 154.213.187.125 |
Nov 13, 2024 01:20:26.316076040 CET | 51321 | 53486 | 154.213.187.125 | 192.168.2.23 |
Nov 13, 2024 01:20:27.308650017 CET | 51321 | 53486 | 154.213.187.125 | 192.168.2.23 |
Nov 13, 2024 01:20:27.308738947 CET | 53486 | 51321 | 192.168.2.23 | 154.213.187.125 |
Nov 13, 2024 01:20:27.313592911 CET | 51321 | 53486 | 154.213.187.125 | 192.168.2.23 |
Nov 13, 2024 01:20:28.309418917 CET | 53488 | 51321 | 192.168.2.23 | 154.213.187.125 |
Nov 13, 2024 01:20:28.314238071 CET | 51321 | 53488 | 154.213.187.125 | 192.168.2.23 |
Nov 13, 2024 01:20:28.314300060 CET | 53488 | 51321 | 192.168.2.23 | 154.213.187.125 |
Nov 13, 2024 01:20:28.314318895 CET | 53488 | 51321 | 192.168.2.23 | 154.213.187.125 |
Nov 13, 2024 01:20:28.319158077 CET | 51321 | 53488 | 154.213.187.125 | 192.168.2.23 |
Nov 13, 2024 01:20:28.319205999 CET | 53488 | 51321 | 192.168.2.23 | 154.213.187.125 |
Nov 13, 2024 01:20:28.324048042 CET | 51321 | 53488 | 154.213.187.125 | 192.168.2.23 |
Nov 13, 2024 01:20:29.317521095 CET | 51321 | 53488 | 154.213.187.125 | 192.168.2.23 |
Nov 13, 2024 01:20:29.317603111 CET | 53488 | 51321 | 192.168.2.23 | 154.213.187.125 |
Nov 13, 2024 01:20:29.322448969 CET | 51321 | 53488 | 154.213.187.125 | 192.168.2.23 |
Nov 13, 2024 01:20:30.318176985 CET | 53490 | 51321 | 192.168.2.23 | 154.213.187.125 |
Nov 13, 2024 01:20:30.323072910 CET | 51321 | 53490 | 154.213.187.125 | 192.168.2.23 |
Nov 13, 2024 01:20:30.323128939 CET | 53490 | 51321 | 192.168.2.23 | 154.213.187.125 |
Nov 13, 2024 01:20:30.323153973 CET | 53490 | 51321 | 192.168.2.23 | 154.213.187.125 |
Nov 13, 2024 01:20:30.327979088 CET | 51321 | 53490 | 154.213.187.125 | 192.168.2.23 |
Nov 13, 2024 01:20:30.328022957 CET | 53490 | 51321 | 192.168.2.23 | 154.213.187.125 |
Nov 13, 2024 01:20:30.332842112 CET | 51321 | 53490 | 154.213.187.125 | 192.168.2.23 |
Nov 13, 2024 01:20:31.700351000 CET | 51321 | 53490 | 154.213.187.125 | 192.168.2.23 |
Nov 13, 2024 01:20:31.700436115 CET | 53490 | 51321 | 192.168.2.23 | 154.213.187.125 |
Nov 13, 2024 01:20:31.705915928 CET | 51321 | 53490 | 154.213.187.125 | 192.168.2.23 |
Nov 13, 2024 01:20:32.701103926 CET | 53492 | 51321 | 192.168.2.23 | 154.213.187.125 |
Nov 13, 2024 01:20:32.706026077 CET | 51321 | 53492 | 154.213.187.125 | 192.168.2.23 |
Nov 13, 2024 01:20:32.706090927 CET | 53492 | 51321 | 192.168.2.23 | 154.213.187.125 |
Nov 13, 2024 01:20:32.706113100 CET | 53492 | 51321 | 192.168.2.23 | 154.213.187.125 |
Nov 13, 2024 01:20:32.711025000 CET | 51321 | 53492 | 154.213.187.125 | 192.168.2.23 |
Nov 13, 2024 01:20:32.711070061 CET | 53492 | 51321 | 192.168.2.23 | 154.213.187.125 |
Nov 13, 2024 01:20:32.715970993 CET | 51321 | 53492 | 154.213.187.125 | 192.168.2.23 |
Nov 13, 2024 01:20:33.705992937 CET | 51321 | 53492 | 154.213.187.125 | 192.168.2.23 |
Nov 13, 2024 01:20:33.706084013 CET | 53492 | 51321 | 192.168.2.23 | 154.213.187.125 |
Nov 13, 2024 01:20:33.710927010 CET | 51321 | 53492 | 154.213.187.125 | 192.168.2.23 |
Nov 13, 2024 01:20:34.706784964 CET | 53494 | 51321 | 192.168.2.23 | 154.213.187.125 |
Nov 13, 2024 01:20:34.711735010 CET | 51321 | 53494 | 154.213.187.125 | 192.168.2.23 |
Nov 13, 2024 01:20:34.711785078 CET | 53494 | 51321 | 192.168.2.23 | 154.213.187.125 |
Nov 13, 2024 01:20:34.711807013 CET | 53494 | 51321 | 192.168.2.23 | 154.213.187.125 |
Nov 13, 2024 01:20:34.716629028 CET | 51321 | 53494 | 154.213.187.125 | 192.168.2.23 |
Nov 13, 2024 01:20:34.716670990 CET | 53494 | 51321 | 192.168.2.23 | 154.213.187.125 |
Nov 13, 2024 01:20:34.721501112 CET | 51321 | 53494 | 154.213.187.125 | 192.168.2.23 |
Nov 13, 2024 01:20:35.710763931 CET | 51321 | 53494 | 154.213.187.125 | 192.168.2.23 |
Nov 13, 2024 01:20:35.710834980 CET | 53494 | 51321 | 192.168.2.23 | 154.213.187.125 |
Nov 13, 2024 01:20:35.715631962 CET | 51321 | 53494 | 154.213.187.125 | 192.168.2.23 |
Nov 13, 2024 01:20:36.711460114 CET | 53496 | 51321 | 192.168.2.23 | 154.213.187.125 |
Nov 13, 2024 01:20:36.716363907 CET | 51321 | 53496 | 154.213.187.125 | 192.168.2.23 |
Nov 13, 2024 01:20:36.716420889 CET | 53496 | 51321 | 192.168.2.23 | 154.213.187.125 |
Nov 13, 2024 01:20:36.716468096 CET | 53496 | 51321 | 192.168.2.23 | 154.213.187.125 |
Nov 13, 2024 01:20:36.721244097 CET | 51321 | 53496 | 154.213.187.125 | 192.168.2.23 |
Nov 13, 2024 01:20:36.721287966 CET | 53496 | 51321 | 192.168.2.23 | 154.213.187.125 |
Nov 13, 2024 01:20:36.726064920 CET | 51321 | 53496 | 154.213.187.125 | 192.168.2.23 |
Nov 13, 2024 01:20:37.707444906 CET | 51321 | 53496 | 154.213.187.125 | 192.168.2.23 |
Nov 13, 2024 01:20:37.707541943 CET | 53496 | 51321 | 192.168.2.23 | 154.213.187.125 |
Nov 13, 2024 01:20:37.712414980 CET | 51321 | 53496 | 154.213.187.125 | 192.168.2.23 |
Nov 13, 2024 01:20:38.708147049 CET | 53498 | 51321 | 192.168.2.23 | 154.213.187.125 |
Nov 13, 2024 01:20:38.713052034 CET | 51321 | 53498 | 154.213.187.125 | 192.168.2.23 |
Nov 13, 2024 01:20:38.713099957 CET | 53498 | 51321 | 192.168.2.23 | 154.213.187.125 |
Nov 13, 2024 01:20:38.713125944 CET | 53498 | 51321 | 192.168.2.23 | 154.213.187.125 |
Nov 13, 2024 01:20:38.717890024 CET | 51321 | 53498 | 154.213.187.125 | 192.168.2.23 |
Nov 13, 2024 01:20:38.717936993 CET | 53498 | 51321 | 192.168.2.23 | 154.213.187.125 |
Nov 13, 2024 01:20:38.723033905 CET | 51321 | 53498 | 154.213.187.125 | 192.168.2.23 |
Nov 13, 2024 01:20:39.419900894 CET | 42516 | 80 | 192.168.2.23 | 109.202.202.202 |
Nov 13, 2024 01:20:39.419903994 CET | 43928 | 443 | 192.168.2.23 | 91.189.91.42 |
Nov 13, 2024 01:20:39.716240883 CET | 51321 | 53498 | 154.213.187.125 | 192.168.2.23 |
Nov 13, 2024 01:20:39.716324091 CET | 53498 | 51321 | 192.168.2.23 | 154.213.187.125 |
Nov 13, 2024 01:20:39.721123934 CET | 51321 | 53498 | 154.213.187.125 | 192.168.2.23 |
Nov 13, 2024 01:20:40.716842890 CET | 53500 | 51321 | 192.168.2.23 | 154.213.187.125 |
Nov 13, 2024 01:20:40.721769094 CET | 51321 | 53500 | 154.213.187.125 | 192.168.2.23 |
Nov 13, 2024 01:20:40.721857071 CET | 53500 | 51321 | 192.168.2.23 | 154.213.187.125 |
Nov 13, 2024 01:20:40.721883059 CET | 53500 | 51321 | 192.168.2.23 | 154.213.187.125 |
Nov 13, 2024 01:20:40.726774931 CET | 51321 | 53500 | 154.213.187.125 | 192.168.2.23 |
Nov 13, 2024 01:20:40.726819038 CET | 53500 | 51321 | 192.168.2.23 | 154.213.187.125 |
Nov 13, 2024 01:20:40.731648922 CET | 51321 | 53500 | 154.213.187.125 | 192.168.2.23 |
Nov 13, 2024 01:20:41.735789061 CET | 51321 | 53500 | 154.213.187.125 | 192.168.2.23 |
Nov 13, 2024 01:20:41.735882044 CET | 53500 | 51321 | 192.168.2.23 | 154.213.187.125 |
Nov 13, 2024 01:20:41.740909100 CET | 51321 | 53500 | 154.213.187.125 | 192.168.2.23 |
Nov 13, 2024 01:20:42.736495018 CET | 53502 | 51321 | 192.168.2.23 | 154.213.187.125 |
Nov 13, 2024 01:20:42.741457939 CET | 51321 | 53502 | 154.213.187.125 | 192.168.2.23 |
Nov 13, 2024 01:20:42.741509914 CET | 53502 | 51321 | 192.168.2.23 | 154.213.187.125 |
Nov 13, 2024 01:20:42.741554022 CET | 53502 | 51321 | 192.168.2.23 | 154.213.187.125 |
Nov 13, 2024 01:20:42.746495008 CET | 51321 | 53502 | 154.213.187.125 | 192.168.2.23 |
Nov 13, 2024 01:20:42.746529102 CET | 53502 | 51321 | 192.168.2.23 | 154.213.187.125 |
Nov 13, 2024 01:20:42.751398087 CET | 51321 | 53502 | 154.213.187.125 | 192.168.2.23 |
Nov 13, 2024 01:20:43.736246109 CET | 51321 | 53502 | 154.213.187.125 | 192.168.2.23 |
Nov 13, 2024 01:20:43.736330986 CET | 53502 | 51321 | 192.168.2.23 | 154.213.187.125 |
Nov 13, 2024 01:20:43.741173029 CET | 51321 | 53502 | 154.213.187.125 | 192.168.2.23 |
Nov 13, 2024 01:20:44.737137079 CET | 53504 | 51321 | 192.168.2.23 | 154.213.187.125 |
Nov 13, 2024 01:20:44.743036985 CET | 51321 | 53504 | 154.213.187.125 | 192.168.2.23 |
Nov 13, 2024 01:20:44.743112087 CET | 53504 | 51321 | 192.168.2.23 | 154.213.187.125 |
Nov 13, 2024 01:20:44.743128061 CET | 53504 | 51321 | 192.168.2.23 | 154.213.187.125 |
Nov 13, 2024 01:20:44.747869015 CET | 51321 | 53504 | 154.213.187.125 | 192.168.2.23 |
Nov 13, 2024 01:20:44.747925043 CET | 53504 | 51321 | 192.168.2.23 | 154.213.187.125 |
Nov 13, 2024 01:20:44.752712965 CET | 51321 | 53504 | 154.213.187.125 | 192.168.2.23 |
Nov 13, 2024 01:20:49.658505917 CET | 42836 | 443 | 192.168.2.23 | 91.189.91.43 |
Nov 13, 2024 01:20:54.749855995 CET | 53504 | 51321 | 192.168.2.23 | 154.213.187.125 |
Nov 13, 2024 01:20:54.756032944 CET | 51321 | 53504 | 154.213.187.125 | 192.168.2.23 |
Nov 13, 2024 01:20:55.004614115 CET | 51321 | 53504 | 154.213.187.125 | 192.168.2.23 |
Nov 13, 2024 01:20:55.004678965 CET | 53504 | 51321 | 192.168.2.23 | 154.213.187.125 |
Nov 13, 2024 01:21:20.374397039 CET | 43928 | 443 | 192.168.2.23 | 91.189.91.42 |
Nov 13, 2024 01:21:40.851700068 CET | 42836 | 443 | 192.168.2.23 | 91.189.91.43 |
Nov 13, 2024 01:21:55.043749094 CET | 53504 | 51321 | 192.168.2.23 | 154.213.187.125 |
Nov 13, 2024 01:21:55.048619032 CET | 51321 | 53504 | 154.213.187.125 | 192.168.2.23 |
Nov 13, 2024 01:21:55.297388077 CET | 51321 | 53504 | 154.213.187.125 | 192.168.2.23 |
Nov 13, 2024 01:21:55.297508001 CET | 53504 | 51321 | 192.168.2.23 | 154.213.187.125 |
System Behavior
Start time (UTC): | 00:20:17 |
Start date (UTC): | 13/11/2024 |
Path: | /tmp/x86.elf |
Arguments: | /tmp/x86.elf |
File size: | 47628 bytes |
MD5 hash: | c9cc4534c5122223e5282a852219f2d5 |
Start time (UTC): | 00:20:17 |
Start date (UTC): | 13/11/2024 |
Path: | /tmp/x86.elf |
Arguments: | - |
File size: | 47628 bytes |
MD5 hash: | c9cc4534c5122223e5282a852219f2d5 |
Start time (UTC): | 00:20:17 |
Start date (UTC): | 13/11/2024 |
Path: | /tmp/x86.elf |
Arguments: | - |
File size: | 47628 bytes |
MD5 hash: | c9cc4534c5122223e5282a852219f2d5 |
Start time (UTC): | 00:20:17 |
Start date (UTC): | 13/11/2024 |
Path: | /tmp/x86.elf |
Arguments: | - |
File size: | 47628 bytes |
MD5 hash: | c9cc4534c5122223e5282a852219f2d5 |