Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
mips.elf

Overview

General Information

Sample name:mips.elf
Analysis ID:1557785
MD5:c8a79cda97f5398387e62fa6e98666b0
SHA1:62f9ab90570d6dfeea622211a192c4bc6b84d577
SHA256:9865ef8da302ddc1e3a1da06117f8f076e9fd7ad11d87cfdfd0f0009d45457b5
Tags:elfuser-abuse_ch
Infos:

Detection

Mirai
Score:80
Range:0 - 100
Whitelisted:false

Signatures

Antivirus / Scanner detection for submitted sample
Detected Mirai
Multi AV Scanner detection for submitted file
Suricata IDS alerts for network traffic
Sample reads /proc/mounts (often used for finding a writable filesystem)
Sample tries to kill multiple processes (SIGKILL)
Detected TCP or UDP traffic on non-standard ports
Sample contains strings indicative of BusyBox which embeds multiple Unix commands in a single executable
Sample has stripped symbol table
Sample listens on a socket
Sample tries to kill a process (SIGKILL)
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1557785
Start date and time:2024-11-18 16:26:06 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 5m 1s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:mips.elf
Detection:MAL
Classification:mal80.spre.troj.linELF@0/0@1/0
  • VT rate limit hit for: mips.elf
Command:/tmp/mips.elf
PID:6219
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
listening to tun0
Standard Error:
  • system is lnxubuntu20
  • mips.elf (PID: 6219, Parent: 6132, MD5: 0083f1f0e77be34ad27f849842bbb00c) Arguments: /tmp/mips.elf
    • mips.elf New Fork (PID: 6221, Parent: 6219)
    • mips.elf New Fork (PID: 6223, Parent: 6219)
  • udisksd New Fork (PID: 6235, Parent: 799)
  • dumpe2fs (PID: 6235, Parent: 799, MD5: 5c66f7d8f7681a40562cf049ad4b72b4) Arguments: dumpe2fs -h /dev/dm-0
  • sh (PID: 6299, Parent: 1477, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-sharing
  • gsd-sharing (PID: 6299, Parent: 1477, MD5: e29d9025d98590fbb69f89fdbd4438b3) Arguments: /usr/libexec/gsd-sharing
  • systemd New Fork (PID: 6309, Parent: 1)
  • upowerd (PID: 6309, Parent: 1, MD5: 1253eea2fe5fe4017069664284e326cd) Arguments: /usr/lib/upower/upowerd
  • sh (PID: 6314, Parent: 1477, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-wacom
  • gsd-wacom (PID: 6314, Parent: 1477, MD5: 13778dd1a23a4e94ddc17ac9caa4fcc1) Arguments: /usr/libexec/gsd-wacom
  • fusermount (PID: 6354, Parent: 2038, MD5: 576a1b135c82bdcbc97a91acea900566) Arguments: fusermount -u -q -z -- /run/user/1000/gvfs
  • sh (PID: 6355, Parent: 1477, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-color
  • gsd-color (PID: 6355, Parent: 1477, MD5: ac2861ad93ce047283e8e87cefef9a19) Arguments: /usr/libexec/gsd-color
  • wrapper-2.0 (PID: 6356, Parent: 2063, MD5: ac0b8a906f359a8ae102244738682e76) Arguments: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libsystray.so 6 12582920 systray "Notification Area" "Area where notification icons appear"
  • sh (PID: 6359, Parent: 1477, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-keyboard
  • gsd-keyboard (PID: 6359, Parent: 1477, MD5: 8e288fd17c80bb0a1148b964b2ac2279) Arguments: /usr/libexec/gsd-keyboard
  • wrapper-2.0 (PID: 6361, Parent: 2063, MD5: ac0b8a906f359a8ae102244738682e76) Arguments: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libstatusnotifier.so 7 12582921 statusnotifier "Status Notifier Plugin" "Provides a panel area for status notifier items (application indicators)"
  • sh (PID: 6362, Parent: 1477, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-print-notifications
  • gsd-print-notifications (PID: 6362, Parent: 1477, MD5: 71539698aa691718cee775d6b9450ae2) Arguments: /usr/libexec/gsd-print-notifications
  • udisksd New Fork (PID: 6365, Parent: 799)
  • wrapper-2.0 (PID: 6366, Parent: 2063, MD5: ac0b8a906f359a8ae102244738682e76) Arguments: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libpulseaudio-plugin.so 8 12582922 pulseaudio "PulseAudio Plugin" "Adjust the audio volume of the PulseAudio sound system"
  • sh (PID: 6369, Parent: 1477, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-rfkill
  • gsd-rfkill (PID: 6369, Parent: 1477, MD5: 88a16a3c0aba1759358c06215ecfb5cc) Arguments: /usr/libexec/gsd-rfkill
  • udisksd New Fork (PID: 6376, Parent: 799)
  • dumpe2fs (PID: 6376, Parent: 799, MD5: 5c66f7d8f7681a40562cf049ad4b72b4) Arguments: dumpe2fs -h /dev/dm-0
  • sh (PID: 6377, Parent: 1477, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-smartcard
  • gsd-smartcard (PID: 6377, Parent: 1477, MD5: ea1fbd7f62e4cd0331eae2ef754ee605) Arguments: /usr/libexec/gsd-smartcard
  • systemd New Fork (PID: 6378, Parent: 1)
  • upowerd (PID: 6378, Parent: 1, MD5: 1253eea2fe5fe4017069664284e326cd) Arguments: /usr/lib/upower/upowerd
  • wrapper-2.0 (PID: 6385, Parent: 2063, MD5: ac0b8a906f359a8ae102244738682e76) Arguments: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libxfce4powermanager.so 9 12582923 power-manager-plugin "Power Manager Plugin" "Display the battery levels of your devices and control the brightness of your display"
  • sh (PID: 6417, Parent: 1477, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-datetime
  • gsd-datetime (PID: 6417, Parent: 1477, MD5: d80d39745740de37d6634d36e344d4bc) Arguments: /usr/libexec/gsd-datetime
  • wrapper-2.0 (PID: 6418, Parent: 2063, MD5: ac0b8a906f359a8ae102244738682e76) Arguments: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libnotification-plugin.so 10 12582924 notification-plugin "Notification Plugin" "Notification plugin for the Xfce panel"
  • sh (PID: 6419, Parent: 1477, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-media-keys
  • gsd-media-keys (PID: 6419, Parent: 1477, MD5: a425448c135afb4b8bfd79cc0b6b74da) Arguments: /usr/libexec/gsd-media-keys
  • sh (PID: 6422, Parent: 1477, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-screensaver-proxy
  • gsd-screensaver-proxy (PID: 6422, Parent: 1477, MD5: 77e309450c87dceee43f1a9e50cc0d02) Arguments: /usr/libexec/gsd-screensaver-proxy
  • wrapper-2.0 (PID: 6423, Parent: 2063, MD5: ac0b8a906f359a8ae102244738682e76) Arguments: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libactions.so 14 12582925 actions "Action Buttons" "Log out, lock or other system actions"
  • sh (PID: 6424, Parent: 1477, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-a11y-settings
  • gsd-a11y-settings (PID: 6424, Parent: 1477, MD5: 18e243d2cf30ecee7ea89d1462725c5c) Arguments: /usr/libexec/gsd-a11y-settings
  • systemd New Fork (PID: 6425, Parent: 1)
  • upowerd (PID: 6425, Parent: 1, MD5: 1253eea2fe5fe4017069664284e326cd) Arguments: /usr/lib/upower/upowerd
  • sh (PID: 6463, Parent: 1477, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-sound
  • gsd-sound (PID: 6463, Parent: 1477, MD5: 4c7d3fb993463337b4a0eb5c80c760ee) Arguments: /usr/libexec/gsd-sound
  • sh (PID: 6467, Parent: 1477, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-power
  • gsd-power (PID: 6467, Parent: 1477, MD5: 28b8e1b43c3e7f1db6741ea1ecd978b7) Arguments: /usr/libexec/gsd-power
  • systemd New Fork (PID: 6468, Parent: 1)
  • upowerd (PID: 6468, Parent: 1, MD5: 1253eea2fe5fe4017069664284e326cd) Arguments: /usr/lib/upower/upowerd
  • systemd New Fork (PID: 6508, Parent: 1)
  • upowerd (PID: 6508, Parent: 1, MD5: 1253eea2fe5fe4017069664284e326cd) Arguments: /usr/lib/upower/upowerd
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
MiraiMirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese. Nowadays it targets a wide range of networked embedded devices such as IP cameras, home routers (many vendors involved), and other IoT devices. Since the source code was published on "Hack Forums" many variants of the Mirai family appeared, infecting mostly home networks all around the world.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/elf.mirai
No yara matches
TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
2024-11-18T16:26:47.129011+010020304901Malware Command and Control Activity Detected192.168.2.234720287.120.114.3241277TCP
TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
2024-11-18T16:26:47.832758+010020304891Malware Command and Control Activity Detected87.120.114.3241277192.168.2.2347202TCP
2024-11-18T16:27:04.848429+010020304891Malware Command and Control Activity Detected87.120.114.3241277192.168.2.2347202TCP
2024-11-18T16:27:24.871409+010020304891Malware Command and Control Activity Detected87.120.114.3241277192.168.2.2347202TCP
2024-11-18T16:27:44.896116+010020304891Malware Command and Control Activity Detected87.120.114.3241277192.168.2.2347202TCP
2024-11-18T16:28:04.918400+010020304891Malware Command and Control Activity Detected87.120.114.3241277192.168.2.2347202TCP
2024-11-18T16:28:24.959404+010020304891Malware Command and Control Activity Detected87.120.114.3241277192.168.2.2347202TCP
2024-11-18T16:28:45.009233+010020304891Malware Command and Control Activity Detected87.120.114.3241277192.168.2.2347202TCP
2024-11-18T16:29:05.067140+010020304891Malware Command and Control Activity Detected87.120.114.3241277192.168.2.2347202TCP
2024-11-18T16:29:25.111875+010020304891Malware Command and Control Activity Detected87.120.114.3241277192.168.2.2347202TCP
2024-11-18T16:29:45.154436+010020304891Malware Command and Control Activity Detected87.120.114.3241277192.168.2.2347202TCP
2024-11-18T16:30:05.193982+010020304891Malware Command and Control Activity Detected87.120.114.3241277192.168.2.2347202TCP

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: mips.elfAvira: detected
Source: mips.elfReversingLabs: Detection: 52%

Networking

barindex
Source: Network trafficSuricata IDS: 2030490 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) : 192.168.2.23:47202 -> 87.120.114.32:41277
Source: Network trafficSuricata IDS: 2030489 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant Server Response : 87.120.114.32:41277 -> 192.168.2.23:47202
Source: global trafficTCP traffic: 192.168.2.23:47202 -> 87.120.114.32:41277
Source: /tmp/mips.elf (PID: 6219)Socket: 127.0.0.1:6628Jump to behavior
Source: global trafficTCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
Source: global trafficTCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
Source: global trafficTCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: global trafficDNS traffic detected: DNS query: fdh32fsdfhs.shop
Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443

System Summary

barindex
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 789, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 796, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 799, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 1349, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 1389, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 1463, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 1465, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 1477, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 1489, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 1579, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 1582, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 1586, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 1594, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 1599, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 1622, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 1623, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 1627, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 1629, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 1632, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 1633, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 1638, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 1639, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 1642, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 1648, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 1654, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 1656, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 1661, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 1664, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 1668, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 1698, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 1699, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 1809, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 1888, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 1890, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 2009, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 2018, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 2033, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 2038, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 2077, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 2078, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 2079, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 2080, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 2083, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 2084, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 2114, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 2128, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 2129, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 2146, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 2156, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 2180, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 2195, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 2208, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 2226, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 2235, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 2242, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 2275, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 2281, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 2285, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 2289, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 2294, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 2307, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 2637, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 3236, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 6299, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 6309, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 6314, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 6355, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 6356, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 6361, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 6365, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 6359, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 6362, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 6366, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 6378, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 6385, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 6418, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 6369, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 6377, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 6417, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 6419, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 6423, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 6425, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 6464, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 6422, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 6424, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 6463, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 6467, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 6468, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 6508, result: successfulJump to behavior
Source: Initial sampleString containing 'busybox' found: /bin/busybox
Source: Initial sampleString containing 'busybox' found: //proc/self/exe/bin/busybox/proc/%d/etc/systmp.d/proc//exe%s/lib/systemd/usr/lib/systemd/systemd/usr/libexec/openssh/sftp-server/usr/lib/openssh/sftp-server/sys/system/dvr/main/usr/mnt/mtd/org/userfs/home/process/net_process/var/tmp/sonia/usr/sbin/usr/bin/mnt/gm/bin/var/Sofia/usr/sbin/sshd/usr/sbin/ntpd/usr/sbin/cupsd/usr/lib/apt/methods/http/usr/sbin/crond/usr/sbin/rsyslogd/usr/sbin/inetd/usr/sbin/dnsmasq/usr/bin/DVRServer/usr/bin/DVRShell/usr/bin/DVRControl/usr/bin/DVRRemoteAgent/usr/bin/DVRNetService/root/binw
Source: ELF static info symbol of initial sample.symtab present: no
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 789, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 796, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 799, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 1349, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 1389, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 1463, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 1465, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 1477, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 1489, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 1579, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 1582, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 1586, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 1594, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 1599, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 1622, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 1623, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 1627, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 1629, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 1632, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 1633, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 1638, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 1639, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 1642, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 1648, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 1654, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 1656, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 1661, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 1664, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 1668, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 1698, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 1699, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 1809, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 1888, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 1890, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 2009, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 2018, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 2033, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 2038, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 2077, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 2078, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 2079, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 2080, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 2083, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 2084, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 2114, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 2128, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 2129, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 2146, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 2156, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 2180, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 2195, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 2208, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 2226, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 2235, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 2242, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 2275, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 2281, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 2285, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 2289, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 2294, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 2307, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 2637, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 3236, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 6299, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 6309, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 6314, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 6355, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 6356, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 6361, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 6365, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 6359, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 6362, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 6366, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 6378, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 6385, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 6418, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 6369, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 6377, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 6417, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 6419, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 6423, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 6425, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 6464, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 6422, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 6424, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 6463, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 6467, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 6468, result: successfulJump to behavior
Source: /tmp/mips.elf (PID: 6221)SIGKILL sent: pid: 6508, result: successfulJump to behavior
Source: classification engineClassification label: mal80.spre.troj.linELF@0/0@1/0

Persistence and Installation Behavior

barindex
Source: /bin/fusermount (PID: 6354)File: /proc/6354/mountsJump to behavior
Source: /tmp/mips.elf (PID: 6219)Queries kernel information via 'uname': Jump to behavior
Source: /tmp/mips.elf (PID: 6223)Queries kernel information via 'uname': Jump to behavior
Source: mips.elf, 6219.1.000055e7b106a000.000055e7b10f1000.rw-.sdmpBinary or memory string: U!/etc/qemu-binfmt/mips
Source: mips.elf, 6219.1.000055e7b106a000.000055e7b10f1000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/mips
Source: mips.elf, 6219.1.00007ffed5124000.00007ffed5145000.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-mips/tmp/mips.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/mips.elf
Source: mips.elf, 6219.1.00007ffed5124000.00007ffed5145000.rw-.sdmpBinary or memory string: /usr/bin/qemu-mips

Remote Access Functionality

barindex
Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)
Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant Server Response
Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant Server Response
Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant Server Response
Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant Server Response
Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant Server Response
Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant Server Response
Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant Server Response
Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant Server Response
Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant Server Response
Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant Server Response
Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant Server Response
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath InterceptionDirect Volume AccessOS Credential Dumping11
Security Software Discovery
Remote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network Medium1
Service Stop
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS Memory1
File and Directory Discovery
Remote Desktop ProtocolData from Removable Media1
Non-Standard Port
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
Non-Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture2
Application Layer Protocol
Traffic DuplicationData Destruction
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
mips.elf53%ReversingLabsLinux.Trojan.Mirai
mips.elf100%AviraLINUX/Mirai.bonb
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
fdh32fsdfhs.shop
87.120.114.32
truetrue
    unknown
    • No. of IPs < 25%
    • 25% < No. of IPs < 50%
    • 50% < No. of IPs < 75%
    • 75% < No. of IPs
    IPDomainCountryFlagASNASN NameMalicious
    87.120.114.32
    fdh32fsdfhs.shopBulgaria
    25206UNACS-AS-BG8000BurgasBGtrue
    109.202.202.202
    unknownSwitzerland
    13030INIT7CHfalse
    91.189.91.43
    unknownUnited Kingdom
    41231CANONICAL-ASGBfalse
    91.189.91.42
    unknownUnited Kingdom
    41231CANONICAL-ASGBfalse
    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
    109.202.202.202kpLwzBouH4.elfGet hashmaliciousUnknownBrowse
    • ch.archive.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_92.0%2bbuild3-0ubuntu0.20.04.1_amd64.deb
    91.189.91.43.i.elfGet hashmaliciousUnknownBrowse
      7YFNIkCSoS.elfGet hashmaliciousSNOWLIGHTBrowse
        iwir64.elfGet hashmaliciousMiraiBrowse
          harm5.elfGet hashmaliciousUnknownBrowse
            Mozi.m.elfGet hashmaliciousMiraiBrowse
              linux_ppc64el.elfGet hashmaliciousUnknownBrowse
                bin.sh.elfGet hashmaliciousMiraiBrowse
                  i.elfGet hashmaliciousUnknownBrowse
                    .i.elfGet hashmaliciousUnknownBrowse
                      Mozi.m.elfGet hashmaliciousUnknownBrowse
                        91.189.91.42.i.elfGet hashmaliciousUnknownBrowse
                          7YFNIkCSoS.elfGet hashmaliciousSNOWLIGHTBrowse
                            iwir64.elfGet hashmaliciousMiraiBrowse
                              harm5.elfGet hashmaliciousUnknownBrowse
                                Mozi.m.elfGet hashmaliciousMiraiBrowse
                                  linux_ppc64el.elfGet hashmaliciousUnknownBrowse
                                    bin.sh.elfGet hashmaliciousMiraiBrowse
                                      i.elfGet hashmaliciousUnknownBrowse
                                        .i.elfGet hashmaliciousUnknownBrowse
                                          Mozi.m.elfGet hashmaliciousUnknownBrowse
                                            MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                            fdh32fsdfhs.shopna.elfGet hashmaliciousMiraiBrowse
                                            • 93.123.39.116
                                            na.elfGet hashmaliciousMiraiBrowse
                                            • 93.123.39.116
                                            na.elfGet hashmaliciousMiraiBrowse
                                            • 93.123.39.116
                                            na.elfGet hashmaliciousMiraiBrowse
                                            • 93.123.39.116
                                            na.elfGet hashmaliciousMiraiBrowse
                                            • 93.123.39.116
                                            na.elfGet hashmaliciousMiraiBrowse
                                            • 93.123.39.116
                                            i586.elfGet hashmaliciousMiraiBrowse
                                            • 185.196.9.5
                                            i686.elfGet hashmaliciousMiraiBrowse
                                            • 185.196.9.5
                                            i686nk.elfGet hashmaliciousMiraiBrowse
                                            • 185.196.9.5
                                            mips.elfGet hashmaliciousMiraiBrowse
                                            • 185.196.9.5
                                            MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                            CANONICAL-ASGB.i.elfGet hashmaliciousUnknownBrowse
                                            • 91.189.91.42
                                            7YFNIkCSoS.elfGet hashmaliciousSNOWLIGHTBrowse
                                            • 91.189.91.42
                                            iwir64.elfGet hashmaliciousMiraiBrowse
                                            • 91.189.91.42
                                            harm5.elfGet hashmaliciousUnknownBrowse
                                            • 91.189.91.42
                                            Mozi.m.elfGet hashmaliciousMiraiBrowse
                                            • 91.189.91.42
                                            linux_ppc64el.elfGet hashmaliciousUnknownBrowse
                                            • 91.189.91.42
                                            bin.sh.elfGet hashmaliciousMiraiBrowse
                                            • 91.189.91.42
                                            i.elfGet hashmaliciousUnknownBrowse
                                            • 91.189.91.42
                                            .i.elfGet hashmaliciousUnknownBrowse
                                            • 91.189.91.42
                                            Mozi.m.elfGet hashmaliciousUnknownBrowse
                                            • 91.189.91.42
                                            CANONICAL-ASGB.i.elfGet hashmaliciousUnknownBrowse
                                            • 91.189.91.42
                                            7YFNIkCSoS.elfGet hashmaliciousSNOWLIGHTBrowse
                                            • 91.189.91.42
                                            iwir64.elfGet hashmaliciousMiraiBrowse
                                            • 91.189.91.42
                                            harm5.elfGet hashmaliciousUnknownBrowse
                                            • 91.189.91.42
                                            Mozi.m.elfGet hashmaliciousMiraiBrowse
                                            • 91.189.91.42
                                            linux_ppc64el.elfGet hashmaliciousUnknownBrowse
                                            • 91.189.91.42
                                            bin.sh.elfGet hashmaliciousMiraiBrowse
                                            • 91.189.91.42
                                            i.elfGet hashmaliciousUnknownBrowse
                                            • 91.189.91.42
                                            .i.elfGet hashmaliciousUnknownBrowse
                                            • 91.189.91.42
                                            Mozi.m.elfGet hashmaliciousUnknownBrowse
                                            • 91.189.91.42
                                            INIT7CH.i.elfGet hashmaliciousUnknownBrowse
                                            • 109.202.202.202
                                            7YFNIkCSoS.elfGet hashmaliciousSNOWLIGHTBrowse
                                            • 109.202.202.202
                                            iwir64.elfGet hashmaliciousMiraiBrowse
                                            • 109.202.202.202
                                            harm5.elfGet hashmaliciousUnknownBrowse
                                            • 109.202.202.202
                                            Mozi.m.elfGet hashmaliciousMiraiBrowse
                                            • 109.202.202.202
                                            linux_ppc64el.elfGet hashmaliciousUnknownBrowse
                                            • 109.202.202.202
                                            bin.sh.elfGet hashmaliciousMiraiBrowse
                                            • 109.202.202.202
                                            i.elfGet hashmaliciousUnknownBrowse
                                            • 109.202.202.202
                                            .i.elfGet hashmaliciousUnknownBrowse
                                            • 109.202.202.202
                                            Mozi.m.elfGet hashmaliciousUnknownBrowse
                                            • 109.202.202.202
                                            UNACS-AS-BG8000BurgasBGrBankRemittance_pdf.scr.exeGet hashmaliciousRemcos, GuLoaderBrowse
                                            • 87.120.114.20
                                            file.exeGet hashmaliciousXWormBrowse
                                            • 87.120.112.33
                                            Item Specifications.exeGet hashmaliciousXWormBrowse
                                            • 87.120.117.69
                                            file.exeGet hashmaliciousPureLog Stealer, XWormBrowse
                                            • 87.120.120.26
                                            View Pdf Doc_0b40e7d2137cd39647abbd9321b34da7.htmGet hashmaliciousUnknownBrowse
                                            • 87.120.115.220
                                            View Pdf Doc_a42d45ecadd4b9604949c99fe71e46fe.htmGet hashmaliciousUnknownBrowse
                                            • 87.120.115.220
                                            Customers_Technical_2D_Drawing-IMG.bat.exeGet hashmaliciousRemcosBrowse
                                            • 87.120.120.25
                                            file.exeGet hashmaliciousPureCrypter, LummaC, Amadey, LummaC Stealer, Stealc, VidarBrowse
                                            • 87.120.125.16
                                            file.exeGet hashmaliciousUnknownBrowse
                                            • 87.120.125.16
                                            file.exeGet hashmaliciousUnknownBrowse
                                            • 87.120.125.16
                                            No context
                                            No context
                                            No created / dropped files found
                                            File type:ELF 32-bit MSB executable, MIPS, MIPS-I version 1 (SYSV), statically linked, stripped
                                            Entropy (8bit):5.515014434751214
                                            TrID:
                                            • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                                            File name:mips.elf
                                            File size:68'512 bytes
                                            MD5:c8a79cda97f5398387e62fa6e98666b0
                                            SHA1:62f9ab90570d6dfeea622211a192c4bc6b84d577
                                            SHA256:9865ef8da302ddc1e3a1da06117f8f076e9fd7ad11d87cfdfd0f0009d45457b5
                                            SHA512:849df6feaaa3add23db171ad091e570eb978e8c65cfefb19adb11711d767afadc879f3a44db02ef3bcea9d86f4aaa9787501272bbceaff6e7bc6de886d0fbc68
                                            SSDEEP:1536:ZEsl9zVBEBsM5JiJx32ln0jly5qT7eOBNlYu:ZzfzYBd5Ji332ln0jly5qTHNlb
                                            TLSH:1C63B65D6E329FEDFBAC863047B34A20A798339527E1D684D29CC6002F7028D645FBA4
                                            File Content Preview:.ELF.....................@.`...4.........4. ...(.............@...@...........................E...E.....@..-X........dt.Q............................<...'......!'.......................<...'......!... ....'9... ......................<...'......!........'9.

                                            ELF header

                                            Class:ELF32
                                            Data:2's complement, big endian
                                            Version:1 (current)
                                            Machine:MIPS R3000
                                            Version Number:0x1
                                            Type:EXEC (Executable file)
                                            OS/ABI:UNIX - System V
                                            ABI Version:0
                                            Entry Point Address:0x400260
                                            Flags:0x1007
                                            ELF Header Size:52
                                            Program Header Offset:52
                                            Program Header Size:32
                                            Number of Program Headers:3
                                            Section Header Offset:67992
                                            Section Header Size:40
                                            Number of Section Headers:13
                                            Header String Table Index:12
                                            NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                            NULL0x00x00x00x00x0000
                                            .initPROGBITS0x4000940x940x8c0x00x6AX004
                                            .textPROGBITS0x4001200x1200xe3900x00x6AX0016
                                            .finiPROGBITS0x40e4b00xe4b00x5c0x00x6AX004
                                            .rodataPROGBITS0x40e5100xe5100x1a700x00x2A0016
                                            .ctorsPROGBITS0x4500000x100000x80x00x3WA004
                                            .dtorsPROGBITS0x4500080x100080x80x00x3WA004
                                            .data.rel.roPROGBITS0x4500140x100140x840x00x3WA004
                                            .dataPROGBITS0x4500a00x100a00x3e00x00x3WA0016
                                            .gotPROGBITS0x4504800x104800x4c00x40x10000003WAp0016
                                            .sbssNOBITS0x4509400x109400x240x00x10000003WAp004
                                            .bssNOBITS0x4509700x109400x23e80x00x3WA0016
                                            .shstrtabSTRTAB0x00x109400x560x00x0001
                                            TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                            LOAD0x00x4000000x4000000xff800xff805.56400x5R E0x10000.init .text .fini .rodata
                                            LOAD0x100000x4500000x4500000x9400x2d583.73760x6RW 0x10000.ctors .dtors .data.rel.ro .data .got .sbss .bss
                                            GNU_STACK0x00x00x00x00x00.00000x7RWE0x4
                                            TimestampSIDSignatureSeveritySource IPSource PortDest IPDest PortProtocol
                                            2024-11-18T16:26:47.129011+01002030490ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)1192.168.2.234720287.120.114.3241277TCP
                                            2024-11-18T16:26:47.832758+01002030489ET MALWARE ELF/MooBot Mirai DDoS Variant Server Response187.120.114.3241277192.168.2.2347202TCP
                                            2024-11-18T16:27:04.848429+01002030489ET MALWARE ELF/MooBot Mirai DDoS Variant Server Response187.120.114.3241277192.168.2.2347202TCP
                                            2024-11-18T16:27:24.871409+01002030489ET MALWARE ELF/MooBot Mirai DDoS Variant Server Response187.120.114.3241277192.168.2.2347202TCP
                                            2024-11-18T16:27:44.896116+01002030489ET MALWARE ELF/MooBot Mirai DDoS Variant Server Response187.120.114.3241277192.168.2.2347202TCP
                                            2024-11-18T16:28:04.918400+01002030489ET MALWARE ELF/MooBot Mirai DDoS Variant Server Response187.120.114.3241277192.168.2.2347202TCP
                                            2024-11-18T16:28:24.959404+01002030489ET MALWARE ELF/MooBot Mirai DDoS Variant Server Response187.120.114.3241277192.168.2.2347202TCP
                                            2024-11-18T16:28:45.009233+01002030489ET MALWARE ELF/MooBot Mirai DDoS Variant Server Response187.120.114.3241277192.168.2.2347202TCP
                                            2024-11-18T16:29:05.067140+01002030489ET MALWARE ELF/MooBot Mirai DDoS Variant Server Response187.120.114.3241277192.168.2.2347202TCP
                                            2024-11-18T16:29:25.111875+01002030489ET MALWARE ELF/MooBot Mirai DDoS Variant Server Response187.120.114.3241277192.168.2.2347202TCP
                                            2024-11-18T16:29:45.154436+01002030489ET MALWARE ELF/MooBot Mirai DDoS Variant Server Response187.120.114.3241277192.168.2.2347202TCP
                                            2024-11-18T16:30:05.193982+01002030489ET MALWARE ELF/MooBot Mirai DDoS Variant Server Response187.120.114.3241277192.168.2.2347202TCP
                                            TimestampSource PortDest PortSource IPDest IP
                                            Nov 18, 2024 16:26:46.589696884 CET43928443192.168.2.2391.189.91.42
                                            Nov 18, 2024 16:26:47.107256889 CET4720241277192.168.2.2387.120.114.32
                                            Nov 18, 2024 16:26:47.113259077 CET412774720287.120.114.32192.168.2.23
                                            Nov 18, 2024 16:26:47.113329887 CET4720241277192.168.2.2387.120.114.32
                                            Nov 18, 2024 16:26:47.129010916 CET4720241277192.168.2.2387.120.114.32
                                            Nov 18, 2024 16:26:47.133853912 CET412774720287.120.114.32192.168.2.23
                                            Nov 18, 2024 16:26:47.832757950 CET412774720287.120.114.32192.168.2.23
                                            Nov 18, 2024 16:26:47.832815886 CET4720241277192.168.2.2387.120.114.32
                                            Nov 18, 2024 16:26:52.220941067 CET42836443192.168.2.2391.189.91.43
                                            Nov 18, 2024 16:26:53.756763935 CET4251680192.168.2.23109.202.202.202
                                            Nov 18, 2024 16:26:57.840327024 CET4720241277192.168.2.2387.120.114.32
                                            Nov 18, 2024 16:26:57.845324993 CET412774720287.120.114.32192.168.2.23
                                            Nov 18, 2024 16:27:04.848428965 CET412774720287.120.114.32192.168.2.23
                                            Nov 18, 2024 16:27:04.848515034 CET4720241277192.168.2.2387.120.114.32
                                            Nov 18, 2024 16:27:07.834784985 CET43928443192.168.2.2391.189.91.42
                                            Nov 18, 2024 16:27:18.073404074 CET42836443192.168.2.2391.189.91.43
                                            Nov 18, 2024 16:27:24.216612101 CET4251680192.168.2.23109.202.202.202
                                            Nov 18, 2024 16:27:24.871408939 CET412774720287.120.114.32192.168.2.23
                                            Nov 18, 2024 16:27:24.871479988 CET4720241277192.168.2.2387.120.114.32
                                            Nov 18, 2024 16:27:44.896116018 CET412774720287.120.114.32192.168.2.23
                                            Nov 18, 2024 16:27:44.896182060 CET4720241277192.168.2.2387.120.114.32
                                            Nov 18, 2024 16:27:48.789200068 CET43928443192.168.2.2391.189.91.42
                                            Nov 18, 2024 16:28:04.910420895 CET4720241277192.168.2.2387.120.114.32
                                            Nov 18, 2024 16:28:04.915530920 CET412774720287.120.114.32192.168.2.23
                                            Nov 18, 2024 16:28:04.918400049 CET412774720287.120.114.32192.168.2.23
                                            Nov 18, 2024 16:28:04.918536901 CET4720241277192.168.2.2387.120.114.32
                                            Nov 18, 2024 16:28:09.266377926 CET42836443192.168.2.2391.189.91.43
                                            Nov 18, 2024 16:28:24.959403992 CET412774720287.120.114.32192.168.2.23
                                            Nov 18, 2024 16:28:24.959462881 CET4720241277192.168.2.2387.120.114.32
                                            Nov 18, 2024 16:28:45.009232998 CET412774720287.120.114.32192.168.2.23
                                            Nov 18, 2024 16:28:45.009299994 CET4720241277192.168.2.2387.120.114.32
                                            Nov 18, 2024 16:29:05.026766062 CET4720241277192.168.2.2387.120.114.32
                                            Nov 18, 2024 16:29:05.067140102 CET412774720287.120.114.32192.168.2.23
                                            Nov 18, 2024 16:29:05.067240000 CET4720241277192.168.2.2387.120.114.32
                                            Nov 18, 2024 16:29:25.111875057 CET412774720287.120.114.32192.168.2.23
                                            Nov 18, 2024 16:29:25.112011909 CET4720241277192.168.2.2387.120.114.32
                                            Nov 18, 2024 16:29:45.154436111 CET412774720287.120.114.32192.168.2.23
                                            Nov 18, 2024 16:29:45.154511929 CET4720241277192.168.2.2387.120.114.32
                                            Nov 18, 2024 16:30:05.169599056 CET4720241277192.168.2.2387.120.114.32
                                            Nov 18, 2024 16:30:05.193981886 CET412774720287.120.114.32192.168.2.23
                                            Nov 18, 2024 16:30:05.194037914 CET4720241277192.168.2.2387.120.114.32
                                            TimestampSource PortDest PortSource IPDest IP
                                            Nov 18, 2024 16:26:47.063709021 CET4532953192.168.2.238.8.8.8
                                            Nov 18, 2024 16:26:47.071132898 CET53453298.8.8.8192.168.2.23
                                            TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                            Nov 18, 2024 16:26:47.063709021 CET192.168.2.238.8.8.80x5f09Standard query (0)fdh32fsdfhs.shopA (IP address)IN (0x0001)false
                                            TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                            Nov 18, 2024 16:26:47.071132898 CET8.8.8.8192.168.2.230x5f09No error (0)fdh32fsdfhs.shop87.120.114.32A (IP address)IN (0x0001)false

                                            System Behavior

                                            Start time (UTC):15:26:46
                                            Start date (UTC):18/11/2024
                                            Path:/tmp/mips.elf
                                            Arguments:/tmp/mips.elf
                                            File size:5777432 bytes
                                            MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                                            Start time (UTC):15:26:46
                                            Start date (UTC):18/11/2024
                                            Path:/tmp/mips.elf
                                            Arguments:-
                                            File size:5777432 bytes
                                            MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                                            Start time (UTC):15:26:46
                                            Start date (UTC):18/11/2024
                                            Path:/tmp/mips.elf
                                            Arguments:-
                                            File size:5777432 bytes
                                            MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                                            Start time (UTC):15:26:46
                                            Start date (UTC):18/11/2024
                                            Path:/usr/lib/udisks2/udisksd
                                            Arguments:-
                                            File size:483056 bytes
                                            MD5 hash:1d7ae439cc3d82fa6b127671ce037a24

                                            Start time (UTC):15:26:46
                                            Start date (UTC):18/11/2024
                                            Path:/usr/sbin/dumpe2fs
                                            Arguments:dumpe2fs -h /dev/dm-0
                                            File size:31112 bytes
                                            MD5 hash:5c66f7d8f7681a40562cf049ad4b72b4

                                            Start time (UTC):15:26:46
                                            Start date (UTC):18/11/2024
                                            Path:/usr/libexec/gnome-session-binary
                                            Arguments:-
                                            File size:334664 bytes
                                            MD5 hash:d9b90be4f7db60cb3c2d3da6a1d31bfb

                                            Start time (UTC):15:26:46
                                            Start date (UTC):18/11/2024
                                            Path:/bin/sh
                                            Arguments:/bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-sharing
                                            File size:129816 bytes
                                            MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                            Start time (UTC):15:26:46
                                            Start date (UTC):18/11/2024
                                            Path:/usr/libexec/gsd-sharing
                                            Arguments:/usr/libexec/gsd-sharing
                                            File size:35424 bytes
                                            MD5 hash:e29d9025d98590fbb69f89fdbd4438b3

                                            Start time (UTC):15:26:46
                                            Start date (UTC):18/11/2024
                                            Path:/usr/lib/systemd/systemd
                                            Arguments:-
                                            File size:1620224 bytes
                                            MD5 hash:9b2bec7092a40488108543f9334aab75

                                            Start time (UTC):15:26:46
                                            Start date (UTC):18/11/2024
                                            Path:/usr/lib/upower/upowerd
                                            Arguments:/usr/lib/upower/upowerd
                                            File size:260328 bytes
                                            MD5 hash:1253eea2fe5fe4017069664284e326cd

                                            Start time (UTC):15:26:46
                                            Start date (UTC):18/11/2024
                                            Path:/usr/libexec/gnome-session-binary
                                            Arguments:-
                                            File size:334664 bytes
                                            MD5 hash:d9b90be4f7db60cb3c2d3da6a1d31bfb

                                            Start time (UTC):15:26:46
                                            Start date (UTC):18/11/2024
                                            Path:/bin/sh
                                            Arguments:/bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-wacom
                                            File size:129816 bytes
                                            MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                            Start time (UTC):15:26:47
                                            Start date (UTC):18/11/2024
                                            Path:/usr/libexec/gsd-wacom
                                            Arguments:/usr/libexec/gsd-wacom
                                            File size:39520 bytes
                                            MD5 hash:13778dd1a23a4e94ddc17ac9caa4fcc1

                                            Start time (UTC):15:26:46
                                            Start date (UTC):18/11/2024
                                            Path:/usr/libexec/gvfsd-fuse
                                            Arguments:-
                                            File size:47632 bytes
                                            MD5 hash:d18fbf1cbf8eb57b17fac48b7b4be933

                                            Start time (UTC):15:26:46
                                            Start date (UTC):18/11/2024
                                            Path:/bin/fusermount
                                            Arguments:fusermount -u -q -z -- /run/user/1000/gvfs
                                            File size:39144 bytes
                                            MD5 hash:576a1b135c82bdcbc97a91acea900566

                                            Start time (UTC):15:26:46
                                            Start date (UTC):18/11/2024
                                            Path:/usr/libexec/gnome-session-binary
                                            Arguments:-
                                            File size:334664 bytes
                                            MD5 hash:d9b90be4f7db60cb3c2d3da6a1d31bfb

                                            Start time (UTC):15:26:46
                                            Start date (UTC):18/11/2024
                                            Path:/bin/sh
                                            Arguments:/bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-color
                                            File size:129816 bytes
                                            MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                            Start time (UTC):15:26:47
                                            Start date (UTC):18/11/2024
                                            Path:/usr/libexec/gsd-color
                                            Arguments:/usr/libexec/gsd-color
                                            File size:92832 bytes
                                            MD5 hash:ac2861ad93ce047283e8e87cefef9a19

                                            Start time (UTC):15:26:46
                                            Start date (UTC):18/11/2024
                                            Path:/usr/bin/xfce4-panel
                                            Arguments:-
                                            File size:375768 bytes
                                            MD5 hash:a15b657c7d54ac1385f1f15004ea6784

                                            Start time (UTC):15:26:46
                                            Start date (UTC):18/11/2024
                                            Path:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
                                            Arguments:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libsystray.so 6 12582920 systray "Notification Area" "Area where notification icons appear"
                                            File size:35136 bytes
                                            MD5 hash:ac0b8a906f359a8ae102244738682e76

                                            Start time (UTC):15:26:46
                                            Start date (UTC):18/11/2024
                                            Path:/usr/libexec/gnome-session-binary
                                            Arguments:-
                                            File size:334664 bytes
                                            MD5 hash:d9b90be4f7db60cb3c2d3da6a1d31bfb

                                            Start time (UTC):15:26:46
                                            Start date (UTC):18/11/2024
                                            Path:/bin/sh
                                            Arguments:/bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-keyboard
                                            File size:129816 bytes
                                            MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                            Start time (UTC):15:26:47
                                            Start date (UTC):18/11/2024
                                            Path:/usr/libexec/gsd-keyboard
                                            Arguments:/usr/libexec/gsd-keyboard
                                            File size:39760 bytes
                                            MD5 hash:8e288fd17c80bb0a1148b964b2ac2279

                                            Start time (UTC):15:26:47
                                            Start date (UTC):18/11/2024
                                            Path:/usr/bin/xfce4-panel
                                            Arguments:-
                                            File size:375768 bytes
                                            MD5 hash:a15b657c7d54ac1385f1f15004ea6784

                                            Start time (UTC):15:26:47
                                            Start date (UTC):18/11/2024
                                            Path:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
                                            Arguments:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libstatusnotifier.so 7 12582921 statusnotifier "Status Notifier Plugin" "Provides a panel area for status notifier items (application indicators)"
                                            File size:35136 bytes
                                            MD5 hash:ac0b8a906f359a8ae102244738682e76

                                            Start time (UTC):15:26:47
                                            Start date (UTC):18/11/2024
                                            Path:/usr/libexec/gnome-session-binary
                                            Arguments:-
                                            File size:334664 bytes
                                            MD5 hash:d9b90be4f7db60cb3c2d3da6a1d31bfb

                                            Start time (UTC):15:26:47
                                            Start date (UTC):18/11/2024
                                            Path:/bin/sh
                                            Arguments:/bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-print-notifications
                                            File size:129816 bytes
                                            MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                            Start time (UTC):15:26:47
                                            Start date (UTC):18/11/2024
                                            Path:/usr/libexec/gsd-print-notifications
                                            Arguments:/usr/libexec/gsd-print-notifications
                                            File size:51840 bytes
                                            MD5 hash:71539698aa691718cee775d6b9450ae2

                                            Start time (UTC):15:26:47
                                            Start date (UTC):18/11/2024
                                            Path:/usr/lib/udisks2/udisksd
                                            Arguments:-
                                            File size:483056 bytes
                                            MD5 hash:1d7ae439cc3d82fa6b127671ce037a24

                                            Start time (UTC):15:26:47
                                            Start date (UTC):18/11/2024
                                            Path:/usr/bin/xfce4-panel
                                            Arguments:-
                                            File size:375768 bytes
                                            MD5 hash:a15b657c7d54ac1385f1f15004ea6784

                                            Start time (UTC):15:26:47
                                            Start date (UTC):18/11/2024
                                            Path:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
                                            Arguments:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libpulseaudio-plugin.so 8 12582922 pulseaudio "PulseAudio Plugin" "Adjust the audio volume of the PulseAudio sound system"
                                            File size:35136 bytes
                                            MD5 hash:ac0b8a906f359a8ae102244738682e76

                                            Start time (UTC):15:26:47
                                            Start date (UTC):18/11/2024
                                            Path:/usr/libexec/gnome-session-binary
                                            Arguments:-
                                            File size:334664 bytes
                                            MD5 hash:d9b90be4f7db60cb3c2d3da6a1d31bfb

                                            Start time (UTC):15:26:47
                                            Start date (UTC):18/11/2024
                                            Path:/bin/sh
                                            Arguments:/bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-rfkill
                                            File size:129816 bytes
                                            MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                            Start time (UTC):15:26:47
                                            Start date (UTC):18/11/2024
                                            Path:/usr/libexec/gsd-rfkill
                                            Arguments:/usr/libexec/gsd-rfkill
                                            File size:51808 bytes
                                            MD5 hash:88a16a3c0aba1759358c06215ecfb5cc

                                            Start time (UTC):15:26:47
                                            Start date (UTC):18/11/2024
                                            Path:/usr/lib/udisks2/udisksd
                                            Arguments:-
                                            File size:483056 bytes
                                            MD5 hash:1d7ae439cc3d82fa6b127671ce037a24

                                            Start time (UTC):15:26:47
                                            Start date (UTC):18/11/2024
                                            Path:/usr/sbin/dumpe2fs
                                            Arguments:dumpe2fs -h /dev/dm-0
                                            File size:31112 bytes
                                            MD5 hash:5c66f7d8f7681a40562cf049ad4b72b4

                                            Start time (UTC):15:26:47
                                            Start date (UTC):18/11/2024
                                            Path:/usr/libexec/gnome-session-binary
                                            Arguments:-
                                            File size:334664 bytes
                                            MD5 hash:d9b90be4f7db60cb3c2d3da6a1d31bfb

                                            Start time (UTC):15:26:47
                                            Start date (UTC):18/11/2024
                                            Path:/bin/sh
                                            Arguments:/bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-smartcard
                                            File size:129816 bytes
                                            MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                            Start time (UTC):15:26:48
                                            Start date (UTC):18/11/2024
                                            Path:/usr/libexec/gsd-smartcard
                                            Arguments:/usr/libexec/gsd-smartcard
                                            File size:109152 bytes
                                            MD5 hash:ea1fbd7f62e4cd0331eae2ef754ee605

                                            Start time (UTC):15:26:47
                                            Start date (UTC):18/11/2024
                                            Path:/usr/lib/systemd/systemd
                                            Arguments:-
                                            File size:1620224 bytes
                                            MD5 hash:9b2bec7092a40488108543f9334aab75

                                            Start time (UTC):15:26:47
                                            Start date (UTC):18/11/2024
                                            Path:/usr/lib/upower/upowerd
                                            Arguments:/usr/lib/upower/upowerd
                                            File size:260328 bytes
                                            MD5 hash:1253eea2fe5fe4017069664284e326cd

                                            Start time (UTC):15:26:47
                                            Start date (UTC):18/11/2024
                                            Path:/usr/bin/xfce4-panel
                                            Arguments:-
                                            File size:375768 bytes
                                            MD5 hash:a15b657c7d54ac1385f1f15004ea6784

                                            Start time (UTC):15:26:47
                                            Start date (UTC):18/11/2024
                                            Path:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
                                            Arguments:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libxfce4powermanager.so 9 12582923 power-manager-plugin "Power Manager Plugin" "Display the battery levels of your devices and control the brightness of your display"
                                            File size:35136 bytes
                                            MD5 hash:ac0b8a906f359a8ae102244738682e76

                                            Start time (UTC):15:26:47
                                            Start date (UTC):18/11/2024
                                            Path:/usr/libexec/gnome-session-binary
                                            Arguments:-
                                            File size:334664 bytes
                                            MD5 hash:d9b90be4f7db60cb3c2d3da6a1d31bfb

                                            Start time (UTC):15:26:47
                                            Start date (UTC):18/11/2024
                                            Path:/bin/sh
                                            Arguments:/bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-datetime
                                            File size:129816 bytes
                                            MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                            Start time (UTC):15:26:48
                                            Start date (UTC):18/11/2024
                                            Path:/usr/libexec/gsd-datetime
                                            Arguments:/usr/libexec/gsd-datetime
                                            File size:76736 bytes
                                            MD5 hash:d80d39745740de37d6634d36e344d4bc

                                            Start time (UTC):15:26:47
                                            Start date (UTC):18/11/2024
                                            Path:/usr/bin/xfce4-panel
                                            Arguments:-
                                            File size:375768 bytes
                                            MD5 hash:a15b657c7d54ac1385f1f15004ea6784

                                            Start time (UTC):15:26:47
                                            Start date (UTC):18/11/2024
                                            Path:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
                                            Arguments:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libnotification-plugin.so 10 12582924 notification-plugin "Notification Plugin" "Notification plugin for the Xfce panel"
                                            File size:35136 bytes
                                            MD5 hash:ac0b8a906f359a8ae102244738682e76

                                            Start time (UTC):15:26:48
                                            Start date (UTC):18/11/2024
                                            Path:/usr/libexec/gnome-session-binary
                                            Arguments:-
                                            File size:334664 bytes
                                            MD5 hash:d9b90be4f7db60cb3c2d3da6a1d31bfb

                                            Start time (UTC):15:26:48
                                            Start date (UTC):18/11/2024
                                            Path:/bin/sh
                                            Arguments:/bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-media-keys
                                            File size:129816 bytes
                                            MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                            Start time (UTC):15:26:48
                                            Start date (UTC):18/11/2024
                                            Path:/usr/libexec/gsd-media-keys
                                            Arguments:/usr/libexec/gsd-media-keys
                                            File size:232936 bytes
                                            MD5 hash:a425448c135afb4b8bfd79cc0b6b74da

                                            Start time (UTC):15:26:48
                                            Start date (UTC):18/11/2024
                                            Path:/usr/libexec/gnome-session-binary
                                            Arguments:-
                                            File size:334664 bytes
                                            MD5 hash:d9b90be4f7db60cb3c2d3da6a1d31bfb

                                            Start time (UTC):15:26:48
                                            Start date (UTC):18/11/2024
                                            Path:/bin/sh
                                            Arguments:/bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-screensaver-proxy
                                            File size:129816 bytes
                                            MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                            Start time (UTC):15:26:48
                                            Start date (UTC):18/11/2024
                                            Path:/usr/libexec/gsd-screensaver-proxy
                                            Arguments:/usr/libexec/gsd-screensaver-proxy
                                            File size:27232 bytes
                                            MD5 hash:77e309450c87dceee43f1a9e50cc0d02

                                            Start time (UTC):15:26:48
                                            Start date (UTC):18/11/2024
                                            Path:/usr/bin/xfce4-panel
                                            Arguments:-
                                            File size:375768 bytes
                                            MD5 hash:a15b657c7d54ac1385f1f15004ea6784

                                            Start time (UTC):15:26:48
                                            Start date (UTC):18/11/2024
                                            Path:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
                                            Arguments:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libactions.so 14 12582925 actions "Action Buttons" "Log out, lock or other system actions"
                                            File size:35136 bytes
                                            MD5 hash:ac0b8a906f359a8ae102244738682e76

                                            Start time (UTC):15:26:48
                                            Start date (UTC):18/11/2024
                                            Path:/usr/libexec/gnome-session-binary
                                            Arguments:-
                                            File size:334664 bytes
                                            MD5 hash:d9b90be4f7db60cb3c2d3da6a1d31bfb

                                            Start time (UTC):15:26:48
                                            Start date (UTC):18/11/2024
                                            Path:/bin/sh
                                            Arguments:/bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-a11y-settings
                                            File size:129816 bytes
                                            MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                            Start time (UTC):15:26:48
                                            Start date (UTC):18/11/2024
                                            Path:/usr/libexec/gsd-a11y-settings
                                            Arguments:/usr/libexec/gsd-a11y-settings
                                            File size:23056 bytes
                                            MD5 hash:18e243d2cf30ecee7ea89d1462725c5c

                                            Start time (UTC):15:26:48
                                            Start date (UTC):18/11/2024
                                            Path:/usr/lib/systemd/systemd
                                            Arguments:-
                                            File size:1620224 bytes
                                            MD5 hash:9b2bec7092a40488108543f9334aab75

                                            Start time (UTC):15:26:48
                                            Start date (UTC):18/11/2024
                                            Path:/usr/lib/upower/upowerd
                                            Arguments:/usr/lib/upower/upowerd
                                            File size:260328 bytes
                                            MD5 hash:1253eea2fe5fe4017069664284e326cd

                                            Start time (UTC):15:26:48
                                            Start date (UTC):18/11/2024
                                            Path:/usr/libexec/gnome-session-binary
                                            Arguments:-
                                            File size:334664 bytes
                                            MD5 hash:d9b90be4f7db60cb3c2d3da6a1d31bfb

                                            Start time (UTC):15:26:48
                                            Start date (UTC):18/11/2024
                                            Path:/bin/sh
                                            Arguments:/bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-sound
                                            File size:129816 bytes
                                            MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                            Start time (UTC):15:26:48
                                            Start date (UTC):18/11/2024
                                            Path:/usr/libexec/gsd-sound
                                            Arguments:/usr/libexec/gsd-sound
                                            File size:31248 bytes
                                            MD5 hash:4c7d3fb993463337b4a0eb5c80c760ee

                                            Start time (UTC):15:26:48
                                            Start date (UTC):18/11/2024
                                            Path:/usr/libexec/gnome-session-binary
                                            Arguments:-
                                            File size:334664 bytes
                                            MD5 hash:d9b90be4f7db60cb3c2d3da6a1d31bfb

                                            Start time (UTC):15:26:48
                                            Start date (UTC):18/11/2024
                                            Path:/bin/sh
                                            Arguments:/bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-power
                                            File size:129816 bytes
                                            MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                            Start time (UTC):15:26:49
                                            Start date (UTC):18/11/2024
                                            Path:/usr/libexec/gsd-power
                                            Arguments:/usr/libexec/gsd-power
                                            File size:88672 bytes
                                            MD5 hash:28b8e1b43c3e7f1db6741ea1ecd978b7
                                            Start time (UTC):15:26:49
                                            Start date (UTC):18/11/2024
                                            Path:/usr/lib/systemd/systemd
                                            Arguments:-
                                            File size:1620224 bytes
                                            MD5 hash:9b2bec7092a40488108543f9334aab75

                                            Start time (UTC):15:26:49
                                            Start date (UTC):18/11/2024
                                            Path:/usr/lib/upower/upowerd
                                            Arguments:/usr/lib/upower/upowerd
                                            File size:260328 bytes
                                            MD5 hash:1253eea2fe5fe4017069664284e326cd

                                            Start time (UTC):15:26:49
                                            Start date (UTC):18/11/2024
                                            Path:/usr/lib/systemd/systemd
                                            Arguments:-
                                            File size:1620224 bytes
                                            MD5 hash:9b2bec7092a40488108543f9334aab75

                                            Start time (UTC):15:26:49
                                            Start date (UTC):18/11/2024
                                            Path:/usr/lib/upower/upowerd
                                            Arguments:/usr/lib/upower/upowerd
                                            File size:260328 bytes
                                            MD5 hash:1253eea2fe5fe4017069664284e326cd