Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
VIVACIOUS_SNOWFLAKE.elf

Overview

General Information

Sample name:VIVACIOUS_SNOWFLAKE.elf
Analysis ID:1566973
MD5:7c6af882f13545df23b5667432a09585
SHA1:14185f9c8993a45ac670c772831b291dccd067ac
SHA256:a80f7c3976a5235c6d8f1e86d8540452a30851ec27d34e56017f372732faaea6
Tags:elfuser-abuse_ch
Infos:

Detection

Sliver
Score:84
Range:0 - 100
Whitelisted:false

Signatures

Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Suricata IDS alerts for network traffic
Yara detected Sliver Implants
Machine Learning detection for sample
Performs DNS TXT record lookups
Queries the IP of a very long domain name
Connects to many different domains
Sample has stripped symbol table
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Uses the "uname" system call to query kernel version information (possible evasion)
Yara signature match

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1566973
Start date and time:2024-12-02 21:43:06 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 7m 22s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:VIVACIOUS_SNOWFLAKE.elf
Detection:MAL
Classification:mal84.troj.evad.linELF@0/0@38/0
  • VT rate limit hit for: VIVACIOUS_SNOWFLAKE.elf
Command:/tmp/VIVACIOUS_SNOWFLAKE.elf
PID:6272
Exit Code:
Exit Code Info:
Killed:True
Standard Output:

Standard Error:
  • system is lnxubuntu20
  • VIVACIOUS_SNOWFLAKE.elf (PID: 6272, Parent: 6195, MD5: 7c6af882f13545df23b5667432a09585) Arguments: /tmp/VIVACIOUS_SNOWFLAKE.elf
  • cleanup
SourceRuleDescriptionAuthorStrings
VIVACIOUS_SNOWFLAKE.elfMulti_Trojan_Bishopsliver_42298c4aunknownunknown
  • 0xb8cc33:$a1: ).RequestResend
  • 0xb8ab26:$a2: ).GetPrivInfo
VIVACIOUS_SNOWFLAKE.elfINDICATOR_TOOL_SliverDetects Sliver implant cross-platform adversary emulation/red teamditekSHen
  • 0x9028da:$s3: .WGTCPForwarder
  • 0x903e1b:$s3: .WGTCPForwarder
  • 0x906eb8:$s3: .WGTCPForwarder
  • 0x907def:$s3: .WGTCPForwarder
  • 0x90aebf:$s3: .WGTCPForwarder
  • 0x90c5b9:$s3: .WGTCPForwarder
  • 0x8fdbb3:$s6: .BackdoorReq
  • 0x90284a:$s7: .ProcessDumpReq
  • 0x90682b:$s8: .InvokeSpawnDllReq
  • 0x8fa916:$s9: .SpawnDll
  • 0x8fdcc4:$s9: .SpawnDll
SourceRuleDescriptionAuthorStrings
6272.1.000000c000000000.000000c000800000.rw-.sdmpJoeSecurity_SliverYara detected Sliver ImplantsJoe Security
    Process Memory Space: VIVACIOUS_SNOWFLAKE.elf PID: 6272JoeSecurity_SliverYara detected Sliver ImplantsJoe Security
      TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
      2024-12-02T21:44:28.482039+010028527451Malware Command and Control Activity Detected192.168.2.23466351.1.1.153UDP
      TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
      2024-12-02T21:44:11.418401+010028527411Malware Command and Control Activity Detected192.168.2.23546601.1.1.153UDP

      Click to jump to signature section

      Show All Signature Results

      AV Detection

      barindex
      Source: VIVACIOUS_SNOWFLAKE.elfReversingLabs: Detection: 52%
      Source: VIVACIOUS_SNOWFLAKE.elfJoe Sandbox ML: detected

      Networking

      barindex
      Source: Network trafficSuricata IDS: 2852741 - Severity 1 - ETPRO MALWARE Sliver DNS SessionInit Request : 192.168.2.23:54660 -> 1.1.1.1:53
      Source: Network trafficSuricata IDS: 2852745 - Severity 1 - ETPRO MALWARE Sliver DNS Base58 Poll Request : 192.168.2.23:46635 -> 1.1.1.1:53
      Source: unknownDNS traffic detected: query: Mw61bELXmC4yq4v2wXRjyJZwrVShKVjMiPmRCUV3ZEM6xxknuxU5BMpxnRFUbHu.FxPfSfyAKA3TXem6R5UPUnsdmvuLmvAWp9W6xPmXMSGemeAqz5RgbjhxBayhy1S.hs3uUMSZ9D8Be2U6GoiriwEWiAcBLSbwRPRREa5jKFzXvcTpTpgjQcnTFH9yXoX.DgnvB7vTsEwLa7NxEuS2mHDM8pbNV9DJV.0x0000b.fashionspeedy.com
      Source: unknownDNS traffic detected: query: 4CnUTQv52TZRaVn7dcv1gWgz11eyMXBSCf2vqawQhCK8V9upciceSZjSu568FKr.A9CUXP2PtUcQEcWAgGchy6dNGuoEhppe7AAZPRbWtd16QjArhrmGfLktKnBKWx5.SoQ8K4JcSs4dGn5A2cfYqiiUNEqiNxArAaw1QwLH5aSfgNqdGB.0x0000b.fashionspeedy.com
      Source: unknownDNS traffic detected: query: Mzd7mTh3RK7BTVwGwEFocG9vuCmyuqmS2sAySv8cEY2cQt51vEb3aDCnFQN5DW9.a2X1ifaCd9sJux3PHrS6EtACFowPb71T4bC3WynCuemUssBFJiwH4dQCrJxcN47.Gp2iTWHpKXE86W1gcBT16rjX7NNTmWBrCpNwNzbsEtXH3fGRaqF4YR5ShTV7bGi.bF5vUaaMXd3rupjn76z1ejpH6xkYhjn9q.0x0000b.fashionspeedy.com
      Source: unknownDNS traffic detected: query: Mzd7mTh3ReJRcSJAWVj2is2y88xRQCYRKRkfsJ73ZkfJajCoeM66KZfF2Qgu8AU.BJsUBFNBnRJGFM2Ak2mfGXp8DfokjLWHZdMbg9A4jWwFsgn7yg1fN2AvgYuY5nZ.feNHGbbevAgLYVWyAqZWc4nXuqxg8GXVK1RiSTRyTG93r1zFSBfTG9wXKUxkp57.So4Z8hyhHhdzW76kNYMnSPX3pukst4NJo.0x0000b.fashionspeedy.com
      Source: unknownDNS traffic detected: query: xGW6nFo6YzQH6j3RdiMggsgMfNZVaJQiuN8Ezd6sTizxTbf4jwvbgZaSrpMfwrQ.qsk8EHRz1gHmps.0x0000b.fashionspeedy.com
      Source: unknownDNS traffic detected: query: LpgfPusGunQMRGTjscuyVWkyZQt9KgdNAoiNdvpb3dsR5PGMKNXMzLr7XZQim6n.xstcgjEMoywwup3a69WxjzVmRGSsqEFcu3tCRTyEgfovAZDSP96NeJQtuhHaHZL.qKhL1XuGbMERpA6J2W2U1dxsY.0x0000b.fashionspeedy.com
      Source: unknownDNS traffic detected: query: LpgfPush4meiqhK4ZoWGmmZQVSq3avqPPSiPWg3phVsoQeFcKdzXCZwqfn5s3ia.TNuM65Lu4sQEB9i99zqd8Kh5rSiLwjUZoFDxLyFTqbF3sRhPAZyHFaNFp3eDNtU.5nh7K8CfsTDPVR1LqcWnzCCwY.0x0000b.fashionspeedy.com
      Source: unknownDNS traffic detected: query: LpgfPushDk65Fi5P54hjJGgwpqgzmbMR6xH7d12gFFXXwhpZP822UDTNHkLppPf.5uy3yqtwWy8zHcXEMyHYPmHCrKCeXf2mTp51xUeFL5qJHVn12WNb5pX73nQX24S.quYoab3RyKqgYM8zryQjnVaqb.0x0000b.fashionspeedy.com
      Source: unknownDNS traffic detected: query: LpgfPushNiuTfJ2t3vRqwWYcVTgCSYV9T44ZsuCPVw5RAdJTDobr8jBhZY7cmf7.xCcnkSTKQbTADbwSPyZ534GE3AY57RqQ41TbEArxhWwQmQDoPqFC6YA7xsgnHoj.hrYHEtqB5ZvDfJUUhe8FzFGpc.0x0000b.fashionspeedy.com
      Source: unknownDNS traffic detected: query: LpgfPushXhJq6JmSdsPa2RAARGBmVPtBiiB3bF8NPRGiyQ7vEuEQ5PT1XJCrc1P.Sipm7yrd4nHtqSt8tfs4Hot6oEHWgGJ4UzYDgJagPF9ydKyV8tgFZPNBeECfVqb.yrk9adeQv8PYUeF8xSKdX9sAp.0x0000b.fashionspeedy.com
      Source: unknownDNS traffic detected: query: LpgfPushGGAcVkhEPTuckGVnGTN7g4GrHiz5Zx2jTcXbb1cBoNJr1qxAU4N3RRS.FPsvmmY7ZGoeeZFm5iPAge3ev8pHgZNgPzsDiDiKMCEPp5as94UEh1SrtnVxZYw.ypXnpzQhhg7YePCPZ45AH9kT1.0x0000b.fashionspeedy.com
      Source: unknownDNS traffic detected: query: LpgfPushqfQZumEVH6g2f8MMmbrKdJgsD2yQ3j1KJeqfKbGYnXEcBZajfpw2HTt.h4tPzgPuP88M69yZjkcwvcTEGAVaHJ7d4fVzjU8ev8psq6CEEJ19aoVFFxwVymF.q8iy5tmkra4RSBCpqM5ciX5u2.0x0000b.fashionspeedy.com
      Source: unknownDNS traffic detected: query: LpgfPushzEewKnT5E86Gd7tiknL7pyH3VNyVT8a1SYaNLNp6MsdxKugY3j9Haf6.DKjreLjsWFryXFYMW4gj6bQe9fsghA2gooKEpYSpRnWMAjc9rMCbxqxtkKCUPar.LFmyX69PfhPLGq8QEH7cKNxfP.0x0000b.fashionspeedy.com
      Source: unknownNetwork traffic detected: DNS query count 38
      Source: global trafficTCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
      Source: global trafficTCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
      Source: global trafficTCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
      Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
      Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
      Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
      Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
      Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
      Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: global trafficDNS traffic detected: DNS query: baakbt7jt8ca.0x0000b.fashionspeedy.com
      Source: global trafficDNS traffic detected: DNS query: 11vzd182342743ckeg3rzw6c.0x0000b.fashionspeedy.com
      Source: global trafficDNS traffic detected: DNS query: 11vzd182342dt9h897kxynkb.0x0000b.fashionspeedy.com
      Source: global trafficDNS traffic detected: DNS query: 11vzd182342f6z7uxjym04yh.0x0000b.fashionspeedy.com
      Source: global trafficDNS traffic detected: DNS query: 11vzd182342e7ucw5vjdyeqe.0x0000b.fashionspeedy.com
      Source: global trafficDNS traffic detected: DNS query: U8TLqVrTo6CVBz2wRTTS.0x0000b.fashionspeedy.com
      Source: global trafficDNS traffic detected: DNS query: U8TLqVrTnw9Qd26hM5Vv.0x0000b.fashionspeedy.com
      Source: global trafficDNS traffic detected: DNS query: U8TLqVrTnPtu6t9FixBj.0x0000b.fashionspeedy.com
      Source: global trafficDNS traffic detected: DNS query: U8TLqVrTnxasfkg9urnE.0x0000b.fashionspeedy.com
      Source: global trafficDNS traffic detected: DNS query: Mw61bELXmC4yq4v2wXRjyJZwrVShKVjMiPmRCUV3ZEM6xxknuxU5BMpxnRFUbHu.FxPfSfyAKA3TXem6R5UPUnsdmvuLmvAWp9W6xPmXMSGemeAqz5RgbjhxBayhy1S.hs3uUMSZ9D8Be2U6GoiriwEWiAcBLSbwRPRREa5jKFzXvcTpTpgjQcnTFH9yXoX.DgnvB7vTsEwLa7NxEuS2mHDM8pbNV9DJV.0x0000b.fashionspeedy.com
      Source: global trafficDNS traffic detected: DNS query: 4CnUTQv52TZRaVn7dcv1gWgz11eyMXBSCf2vqawQhCK8V9upciceSZjSu568FKr.A9CUXP2PtUcQEcWAgGchy6dNGuoEhppe7AAZPRbWtd16QjArhrmGfLktKnBKWx5.SoQ8K4JcSs4dGn5A2cfYqiiUNEqiNxArAaw1QwLH5aSfgNqdGB.0x0000b.fashionspeedy.com
      Source: global trafficDNS traffic detected: DNS query: Mzd7mTh3RK7BTVwGwEFocG9vuCmyuqmS2sAySv8cEY2cQt51vEb3aDCnFQN5DW9.a2X1ifaCd9sJux3PHrS6EtACFowPb71T4bC3WynCuemUssBFJiwH4dQCrJxcN47.Gp2iTWHpKXE86W1gcBT16rjX7NNTmWBrCpNwNzbsEtXH3fGRaqF4YR5ShTV7bGi.bF5vUaaMXd3rupjn76z1ejpH6xkYhjn9q.0x0000b.fashionspeedy.com
      Source: global trafficDNS traffic detected: DNS query: Mzd7mTh3ReJRcSJAWVj2is2y88xRQCYRKRkfsJ73ZkfJajCoeM66KZfF2Qgu8AU.BJsUBFNBnRJGFM2Ak2mfGXp8DfokjLWHZdMbg9A4jWwFsgn7yg1fN2AvgYuY5nZ.feNHGbbevAgLYVWyAqZWc4nXuqxg8GXVK1RiSTRyTG93r1zFSBfTG9wXKUxkp57.So4Z8hyhHhdzW76kNYMnSPX3pukst4NJo.0x0000b.fashionspeedy.com
      Source: global trafficDNS traffic detected: DNS query: xGW6nFo6YzQH6j3RdiMggsgMfNZVaJQiuN8Ezd6sTizxTbf4jwvbgZaSrpMfwrQ.qsk8EHRz1gHmps.0x0000b.fashionspeedy.com
      Source: global trafficDNS traffic detected: DNS query: LpgfPusGunQMRGTjscuyVWkyZQt9KgdNAoiNdvpb3dsR5PGMKNXMzLr7XZQim6n.xstcgjEMoywwup3a69WxjzVmRGSsqEFcu3tCRTyEgfovAZDSP96NeJQtuhHaHZL.qKhL1XuGbMERpA6J2W2U1dxsY.0x0000b.fashionspeedy.com
      Source: global trafficDNS traffic detected: DNS query: 6NguhvqpquxEq2i2E6pzWPE.0x0000b.fashionspeedy.com
      Source: global trafficDNS traffic detected: DNS query: backbhz9k431a78.0x0000b.fashionspeedy.com
      Source: global trafficDNS traffic detected: DNS query: LpgfPush4meiqhK4ZoWGmmZQVSq3avqPPSiPWg3phVsoQeFcKdzXCZwqfn5s3ia.TNuM65Lu4sQEB9i99zqd8Kh5rSiLwjUZoFDxLyFTqbF3sRhPAZyHFaNFp3eDNtU.5nh7K8CfsTDPVR1LqcWnzCCwY.0x0000b.fashionspeedy.com
      Source: global trafficDNS traffic detected: DNS query: 6NguhvqpquxEpZdDN5BnEqe.0x0000b.fashionspeedy.com
      Source: global trafficDNS traffic detected: DNS query: backbhz9k451a78.0x0000b.fashionspeedy.com
      Source: global trafficDNS traffic detected: DNS query: LpgfPushDk65Fi5P54hjJGgwpqgzmbMR6xH7d12gFFXXwhpZP822UDTNHkLppPf.5uy3yqtwWy8zHcXEMyHYPmHCrKCeXf2mTp51xUeFL5qJHVn12WNb5pX73nQX24S.quYoab3RyKqgYM8zryQjnVaqb.0x0000b.fashionspeedy.com
      Source: global trafficDNS traffic detected: DNS query: 6Nguhvqpquxf2RLvWN5wrb8.0x0000b.fashionspeedy.com
      Source: global trafficDNS traffic detected: DNS query: backbhz9k471a78.0x0000b.fashionspeedy.com
      Source: global trafficDNS traffic detected: DNS query: LpgfPushNiuTfJ2t3vRqwWYcVTgCSYV9T44ZsuCPVw5RAdJTDobr8jBhZY7cmf7.xCcnkSTKQbTADbwSPyZ534GE3AY57RqQ41TbEArxhWwQmQDoPqFC6YA7xsgnHoj.hrYHEtqB5ZvDfJUUhe8FzFGpc.0x0000b.fashionspeedy.com
      Source: global trafficDNS traffic detected: DNS query: 6NguhvqpquxEokX9xRofGjP.0x0000b.fashionspeedy.com
      Source: global trafficDNS traffic detected: DNS query: backbhz9k491a78.0x0000b.fashionspeedy.com
      Source: global trafficDNS traffic detected: DNS query: LpgfPushXhJq6JmSdsPa2RAARGBmVPtBiiB3bF8NPRGiyQ7vEuEQ5PT1XJCrc1P.Sipm7yrd4nHtqSt8tfs4Hot6oEHWgGJ4UzYDgJagPF9ydKyV8tgFZPNBeECfVqb.yrk9adeQv8PYUeF8xSKdX9sAp.0x0000b.fashionspeedy.com
      Source: global trafficDNS traffic detected: DNS query: 6Nguhvqpquxf4Zhsc3g6Wzf.0x0000b.fashionspeedy.com
      Source: global trafficDNS traffic detected: DNS query: backbhz9k4p1a78.0x0000b.fashionspeedy.com
      Source: global trafficDNS traffic detected: DNS query: LpgfPushGGAcVkhEPTuckGVnGTN7g4GrHiz5Zx2jTcXbb1cBoNJr1qxAU4N3RRS.FPsvmmY7ZGoeeZFm5iPAge3ev8pHgZNgPzsDiDiKMCEPp5as94UEh1SrtnVxZYw.ypXnpzQhhg7YePCPZ45AH9kT1.0x0000b.fashionspeedy.com
      Source: global trafficDNS traffic detected: DNS query: 6NguhvqpquxEhuSbi65st27.0x0000b.fashionspeedy.com
      Source: global trafficDNS traffic detected: DNS query: backbhz9k4u1a78.0x0000b.fashionspeedy.com
      Source: global trafficDNS traffic detected: DNS query: LpgfPushqfQZumEVH6g2f8MMmbrKdJgsD2yQ3j1KJeqfKbGYnXEcBZajfpw2HTt.h4tPzgPuP88M69yZjkcwvcTEGAVaHJ7d4fVzjU8ev8psq6CEEJ19aoVFFxwVymF.q8iy5tmkra4RSBCpqM5ciX5u2.0x0000b.fashionspeedy.com
      Source: global trafficDNS traffic detected: DNS query: 6NguhvqpquxESJybPHjHn25.0x0000b.fashionspeedy.com
      Source: global trafficDNS traffic detected: DNS query: backbhz9k4y1a78.0x0000b.fashionspeedy.com
      Source: global trafficDNS traffic detected: DNS query: LpgfPushzEewKnT5E86Gd7tiknL7pyH3VNyVT8a1SYaNLNp6MsdxKugY3j9Haf6.DKjreLjsWFryXFYMW4gj6bQe9fsghA2gooKEpYSpRnWMAjc9rMCbxqxtkKCUPar.LFmyX69PfhPLGq8QEH7cKNxfP.0x0000b.fashionspeedy.com
      Source: global trafficDNS traffic detected: DNS query: 6NguhvqpquxEGpxzq9kvu7r.0x0000b.fashionspeedy.com
      Source: global trafficDNS traffic detected: DNS query: backbhz9kf11a78.0x0000b.fashionspeedy.com
      Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443

      System Summary

      barindex
      Source: VIVACIOUS_SNOWFLAKE.elf, type: SAMPLEMatched rule: Multi_Trojan_Bishopsliver_42298c4a Author: unknown
      Source: VIVACIOUS_SNOWFLAKE.elf, type: SAMPLEMatched rule: Detects Sliver implant cross-platform adversary emulation/red team Author: ditekSHen
      Source: ELF static info symbol of initial sample.symtab present: no
      Source: VIVACIOUS_SNOWFLAKE.elf, type: SAMPLEMatched rule: Multi_Trojan_Bishopsliver_42298c4a reference_sample = 3b45aae401ac64c055982b5f3782a3c4c892bdb9f9a5531657d50c27497c8007, os = multi, severity = x86, creation_date = 2021-10-20, scan_context = file, memory, license = Elastic License v2, threat_name = Multi.Trojan.Bishopsliver, fingerprint = 0734b090ea10abedef4d9ed48d45c834dd5cf8e424886a5be98e484f69c5e12a, id = 42298c4a-fcea-4c5a-b213-32db00e4eb5a, last_modified = 2022-01-14
      Source: VIVACIOUS_SNOWFLAKE.elf, type: SAMPLEMatched rule: INDICATOR_TOOL_Sliver author = ditekSHen, description = Detects Sliver implant cross-platform adversary emulation/red team
      Source: classification engineClassification label: mal84.troj.evad.linELF@0/0@38/0
      Source: ELF file sectionSubmission: VIVACIOUS_SNOWFLAKE.elf
      Source: /tmp/VIVACIOUS_SNOWFLAKE.elf (PID: 6272)Queries kernel information via 'uname': Jump to behavior

      HIPS / PFW / Operating System Protection Evasion

      barindex
      Source: TrafficDNS traffic detected: queries for: Mw61bELXmC4yq4v2wXRjyJZwrVShKVjMiPmRCUV3ZEM6xxknuxU5BMpxnRFUbHu.FxPfSfyAKA3TXem6R5UPUnsdmvuLmvAWp9W6xPmXMSGemeAqz5RgbjhxBayhy1S.hs3uUMSZ9D8Be2U6GoiriwEWiAcBLSbwRPRREa5jKFzXvcTpTpgjQcnTFH9yXoX.DgnvB7vTsEwLa7NxEuS2mHDM8pbNV9DJV.0x0000b.fashionspeedy.com
      Source: TrafficDNS traffic detected: queries for: 4CnUTQv52TZRaVn7dcv1gWgz11eyMXBSCf2vqawQhCK8V9upciceSZjSu568FKr.A9CUXP2PtUcQEcWAgGchy6dNGuoEhppe7AAZPRbWtd16QjArhrmGfLktKnBKWx5.SoQ8K4JcSs4dGn5A2cfYqiiUNEqiNxArAaw1QwLH5aSfgNqdGB.0x0000b.fashionspeedy.com
      Source: TrafficDNS traffic detected: queries for: 6NguhvqpquxEq2i2E6pzWPE.0x0000b.fashionspeedy.com
      Source: TrafficDNS traffic detected: queries for: backbhz9k431a78.0x0000b.fashionspeedy.com
      Source: TrafficDNS traffic detected: queries for: 6NguhvqpquxEpZdDN5BnEqe.0x0000b.fashionspeedy.com
      Source: TrafficDNS traffic detected: queries for: backbhz9k451a78.0x0000b.fashionspeedy.com
      Source: TrafficDNS traffic detected: queries for: 6Nguhvqpquxf2RLvWN5wrb8.0x0000b.fashionspeedy.com
      Source: TrafficDNS traffic detected: queries for: backbhz9k471a78.0x0000b.fashionspeedy.com
      Source: TrafficDNS traffic detected: queries for: 6NguhvqpquxEokX9xRofGjP.0x0000b.fashionspeedy.com
      Source: TrafficDNS traffic detected: queries for: backbhz9k491a78.0x0000b.fashionspeedy.com
      Source: TrafficDNS traffic detected: queries for: 6Nguhvqpquxf4Zhsc3g6Wzf.0x0000b.fashionspeedy.com
      Source: TrafficDNS traffic detected: queries for: backbhz9k4p1a78.0x0000b.fashionspeedy.com
      Source: TrafficDNS traffic detected: queries for: 6NguhvqpquxEhuSbi65st27.0x0000b.fashionspeedy.com
      Source: TrafficDNS traffic detected: queries for: backbhz9k4u1a78.0x0000b.fashionspeedy.com
      Source: TrafficDNS traffic detected: queries for: 6NguhvqpquxESJybPHjHn25.0x0000b.fashionspeedy.com
      Source: TrafficDNS traffic detected: queries for: backbhz9k4y1a78.0x0000b.fashionspeedy.com
      Source: TrafficDNS traffic detected: queries for: 6NguhvqpquxEGpxzq9kvu7r.0x0000b.fashionspeedy.com
      Source: TrafficDNS traffic detected: queries for: backbhz9kf11a78.0x0000b.fashionspeedy.com

      Stealing of Sensitive Information

      barindex
      Source: Yara matchFile source: 6272.1.000000c000000000.000000c000800000.rw-.sdmp, type: MEMORY
      Source: Yara matchFile source: Process Memory Space: VIVACIOUS_SNOWFLAKE.elf PID: 6272, type: MEMORYSTR

      Remote Access Functionality

      barindex
      Source: Yara matchFile source: 6272.1.000000c000000000.000000c000800000.rw-.sdmp, type: MEMORY
      Source: Yara matchFile source: Process Memory Space: VIVACIOUS_SNOWFLAKE.elf PID: 6272, type: MEMORYSTR
      ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
      Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath InterceptionDirect Volume AccessOS Credential Dumping1
      Security Software Discovery
      Remote ServicesData from Local System1
      Encrypted Channel
      Exfiltration Over Other Network MediumAbuse Accessibility Features
      CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
      Non-Application Layer Protocol
      Exfiltration Over BluetoothNetwork Denial of Service
      Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive12
      Application Layer Protocol
      Automated ExfiltrationData Encrypted for Impact
      No configs have been found

      This section contains all screenshots as thumbnails, including those not shown in the slideshow.


      windows-stand
      SourceDetectionScannerLabelLink
      VIVACIOUS_SNOWFLAKE.elf53%ReversingLabsLinux.Trojan.Sliver
      VIVACIOUS_SNOWFLAKE.elf100%Joe Sandbox ML
      No Antivirus matches
      No Antivirus matches
      No Antivirus matches
      NameIPActiveMaliciousAntivirus DetectionReputation
      U8TLqVrTnxasfkg9urnE.0x0000b.fashionspeedy.com
      66.232.194.253
      truefalse
        unknown
        LpgfPushGGAcVkhEPTuckGVnGTN7g4GrHiz5Zx2jTcXbb1cBoNJr1qxAU4N3RRS.FPsvmmY7ZGoeeZFm5iPAge3ev8pHgZNgPzsDiDiKMCEPp5as94UEh1SrtnVxZYw.ypXnpzQhhg7YePCPZ45AH9kT1.0x0000b.fashionspeedy.com
        1.84.239.125
        truetrue
          unknown
          LpgfPusGunQMRGTjscuyVWkyZQt9KgdNAoiNdvpb3dsR5PGMKNXMzLr7XZQim6n.xstcgjEMoywwup3a69WxjzVmRGSsqEFcu3tCRTyEgfovAZDSP96NeJQtuhHaHZL.qKhL1XuGbMERpA6J2W2U1dxsY.0x0000b.fashionspeedy.com
          206.4.237.138
          truetrue
            unknown
            xGW6nFo6YzQH6j3RdiMggsgMfNZVaJQiuN8Ezd6sTizxTbf4jwvbgZaSrpMfwrQ.qsk8EHRz1gHmps.0x0000b.fashionspeedy.com
            209.130.158.56
            truetrue
              unknown
              U8TLqVrTnPtu6t9FixBj.0x0000b.fashionspeedy.com
              188.94.122.38
              truefalse
                unknown
                baakbt7jt8ca.0x0000b.fashionspeedy.com
                55.185.130.14
                truefalse
                  unknown
                  11vzd182342743ckeg3rzw6c.0x0000b.fashionspeedy.com
                  137.154.240.38
                  truefalse
                    unknown
                    Mzd7mTh3RK7BTVwGwEFocG9vuCmyuqmS2sAySv8cEY2cQt51vEb3aDCnFQN5DW9.a2X1ifaCd9sJux3PHrS6EtACFowPb71T4bC3WynCuemUssBFJiwH4dQCrJxcN47.Gp2iTWHpKXE86W1gcBT16rjX7NNTmWBrCpNwNzbsEtXH3fGRaqF4YR5ShTV7bGi.bF5vUaaMXd3rupjn76z1ejpH6xkYhjn9q.0x0000b.fashionspeedy.com
                    172.136.140.167
                    truetrue
                      unknown
                      LpgfPushXhJq6JmSdsPa2RAARGBmVPtBiiB3bF8NPRGiyQ7vEuEQ5PT1XJCrc1P.Sipm7yrd4nHtqSt8tfs4Hot6oEHWgGJ4UzYDgJagPF9ydKyV8tgFZPNBeECfVqb.yrk9adeQv8PYUeF8xSKdX9sAp.0x0000b.fashionspeedy.com
                      142.219.25.241
                      truetrue
                        unknown
                        U8TLqVrTnw9Qd26hM5Vv.0x0000b.fashionspeedy.com
                        15.14.166.112
                        truefalse
                          unknown
                          11vzd182342dt9h897kxynkb.0x0000b.fashionspeedy.com
                          246.41.15.231
                          truefalse
                            unknown
                            Mzd7mTh3ReJRcSJAWVj2is2y88xRQCYRKRkfsJ73ZkfJajCoeM66KZfF2Qgu8AU.BJsUBFNBnRJGFM2Ak2mfGXp8DfokjLWHZdMbg9A4jWwFsgn7yg1fN2AvgYuY5nZ.feNHGbbevAgLYVWyAqZWc4nXuqxg8GXVK1RiSTRyTG93r1zFSBfTG9wXKUxkp57.So4Z8hyhHhdzW76kNYMnSPX3pukst4NJo.0x0000b.fashionspeedy.com
                            123.42.4.50
                            truetrue
                              unknown
                              LpgfPushqfQZumEVH6g2f8MMmbrKdJgsD2yQ3j1KJeqfKbGYnXEcBZajfpw2HTt.h4tPzgPuP88M69yZjkcwvcTEGAVaHJ7d4fVzjU8ev8psq6CEEJ19aoVFFxwVymF.q8iy5tmkra4RSBCpqM5ciX5u2.0x0000b.fashionspeedy.com
                              19.68.163.193
                              truetrue
                                unknown
                                LpgfPushNiuTfJ2t3vRqwWYcVTgCSYV9T44ZsuCPVw5RAdJTDobr8jBhZY7cmf7.xCcnkSTKQbTADbwSPyZ534GE3AY57RqQ41TbEArxhWwQmQDoPqFC6YA7xsgnHoj.hrYHEtqB5ZvDfJUUhe8FzFGpc.0x0000b.fashionspeedy.com
                                194.59.188.10
                                truetrue
                                  unknown
                                  11vzd182342f6z7uxjym04yh.0x0000b.fashionspeedy.com
                                  178.215.145.199
                                  truefalse
                                    unknown
                                    11vzd182342e7ucw5vjdyeqe.0x0000b.fashionspeedy.com
                                    1.247.215.215
                                    truefalse
                                      unknown
                                      U8TLqVrTo6CVBz2wRTTS.0x0000b.fashionspeedy.com
                                      181.99.74.228
                                      truefalse
                                        unknown
                                        LpgfPush4meiqhK4ZoWGmmZQVSq3avqPPSiPWg3phVsoQeFcKdzXCZwqfn5s3ia.TNuM65Lu4sQEB9i99zqd8Kh5rSiLwjUZoFDxLyFTqbF3sRhPAZyHFaNFp3eDNtU.5nh7K8CfsTDPVR1LqcWnzCCwY.0x0000b.fashionspeedy.com
                                        156.49.83.116
                                        truetrue
                                          unknown
                                          LpgfPushDk65Fi5P54hjJGgwpqgzmbMR6xH7d12gFFXXwhpZP822UDTNHkLppPf.5uy3yqtwWy8zHcXEMyHYPmHCrKCeXf2mTp51xUeFL5qJHVn12WNb5pX73nQX24S.quYoab3RyKqgYM8zryQjnVaqb.0x0000b.fashionspeedy.com
                                          82.88.235.84
                                          truetrue
                                            unknown
                                            LpgfPushzEewKnT5E86Gd7tiknL7pyH3VNyVT8a1SYaNLNp6MsdxKugY3j9Haf6.DKjreLjsWFryXFYMW4gj6bQe9fsghA2gooKEpYSpRnWMAjc9rMCbxqxtkKCUPar.LFmyX69PfhPLGq8QEH7cKNxfP.0x0000b.fashionspeedy.com
                                            245.2.250.60
                                            truetrue
                                              unknown
                                              6NguhvqpquxEhuSbi65st27.0x0000b.fashionspeedy.com
                                              unknown
                                              unknowntrue
                                                unknown
                                                backbhz9k451a78.0x0000b.fashionspeedy.com
                                                unknown
                                                unknowntrue
                                                  unknown
                                                  6NguhvqpquxEq2i2E6pzWPE.0x0000b.fashionspeedy.com
                                                  unknown
                                                  unknowntrue
                                                    unknown
                                                    backbhz9k4u1a78.0x0000b.fashionspeedy.com
                                                    unknown
                                                    unknowntrue
                                                      unknown
                                                      6Nguhvqpquxf4Zhsc3g6Wzf.0x0000b.fashionspeedy.com
                                                      unknown
                                                      unknowntrue
                                                        unknown
                                                        backbhz9kf11a78.0x0000b.fashionspeedy.com
                                                        unknown
                                                        unknowntrue
                                                          unknown
                                                          6NguhvqpquxEGpxzq9kvu7r.0x0000b.fashionspeedy.com
                                                          unknown
                                                          unknowntrue
                                                            unknown
                                                            backbhz9k491a78.0x0000b.fashionspeedy.com
                                                            unknown
                                                            unknowntrue
                                                              unknown
                                                              6NguhvqpquxESJybPHjHn25.0x0000b.fashionspeedy.com
                                                              unknown
                                                              unknowntrue
                                                                unknown
                                                                backbhz9k471a78.0x0000b.fashionspeedy.com
                                                                unknown
                                                                unknowntrue
                                                                  unknown
                                                                  6NguhvqpquxEpZdDN5BnEqe.0x0000b.fashionspeedy.com
                                                                  unknown
                                                                  unknowntrue
                                                                    unknown
                                                                    4CnUTQv52TZRaVn7dcv1gWgz11eyMXBSCf2vqawQhCK8V9upciceSZjSu568FKr.A9CUXP2PtUcQEcWAgGchy6dNGuoEhppe7AAZPRbWtd16QjArhrmGfLktKnBKWx5.SoQ8K4JcSs4dGn5A2cfYqiiUNEqiNxArAaw1QwLH5aSfgNqdGB.0x0000b.fashionspeedy.com
                                                                    unknown
                                                                    unknowntrue
                                                                      unknown
                                                                      backbhz9k4p1a78.0x0000b.fashionspeedy.com
                                                                      unknown
                                                                      unknowntrue
                                                                        unknown
                                                                        backbhz9k4y1a78.0x0000b.fashionspeedy.com
                                                                        unknown
                                                                        unknowntrue
                                                                          unknown
                                                                          Mw61bELXmC4yq4v2wXRjyJZwrVShKVjMiPmRCUV3ZEM6xxknuxU5BMpxnRFUbHu.FxPfSfyAKA3TXem6R5UPUnsdmvuLmvAWp9W6xPmXMSGemeAqz5RgbjhxBayhy1S.hs3uUMSZ9D8Be2U6GoiriwEWiAcBLSbwRPRREa5jKFzXvcTpTpgjQcnTFH9yXoX.DgnvB7vTsEwLa7NxEuS2mHDM8pbNV9DJV.0x0000b.fashionspeedy.com
                                                                          unknown
                                                                          unknowntrue
                                                                            unknown
                                                                            backbhz9k431a78.0x0000b.fashionspeedy.com
                                                                            unknown
                                                                            unknowntrue
                                                                              unknown
                                                                              6Nguhvqpquxf2RLvWN5wrb8.0x0000b.fashionspeedy.com
                                                                              unknown
                                                                              unknowntrue
                                                                                unknown
                                                                                6NguhvqpquxEokX9xRofGjP.0x0000b.fashionspeedy.com
                                                                                unknown
                                                                                unknowntrue
                                                                                  unknown
                                                                                  • No. of IPs < 25%
                                                                                  • 25% < No. of IPs < 50%
                                                                                  • 50% < No. of IPs < 75%
                                                                                  • 75% < No. of IPs
                                                                                  IPDomainCountryFlagASNASN NameMalicious
                                                                                  109.202.202.202
                                                                                  unknownSwitzerland
                                                                                  13030INIT7CHfalse
                                                                                  91.189.91.43
                                                                                  unknownUnited Kingdom
                                                                                  41231CANONICAL-ASGBfalse
                                                                                  91.189.91.42
                                                                                  unknownUnited Kingdom
                                                                                  41231CANONICAL-ASGBfalse
                                                                                  MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                                  109.202.202.202kpLwzBouH4.elfGet hashmaliciousUnknownBrowse
                                                                                  • ch.archive.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_92.0%2bbuild3-0ubuntu0.20.04.1_amd64.deb
                                                                                  91.189.91.43agent.elfGet hashmaliciousUnknownBrowse
                                                                                    ppc.elfGet hashmaliciousMiraiBrowse
                                                                                      .i.elfGet hashmaliciousUnknownBrowse
                                                                                        ub8ehJSePAfc9FYqZIT6.arm5.elfGet hashmaliciousUnknownBrowse
                                                                                          ub8ehJSePAfc9FYqZIT6.arm6.elfGet hashmaliciousUnknownBrowse
                                                                                            ub8ehJSePAfc9FYqZIT6.arm.elfGet hashmaliciousMiraiBrowse
                                                                                              ub8ehJSePAfc9FYqZIT6.i686.elfGet hashmaliciousUnknownBrowse
                                                                                                tftp.elfGet hashmaliciousUnknownBrowse
                                                                                                  i686.elfGet hashmaliciousUnknownBrowse
                                                                                                    ub8ehJSePAfc9FYqZIT6.x86_64.elfGet hashmaliciousUnknownBrowse
                                                                                                      91.189.91.42agent.elfGet hashmaliciousUnknownBrowse
                                                                                                        ppc.elfGet hashmaliciousMiraiBrowse
                                                                                                          .i.elfGet hashmaliciousUnknownBrowse
                                                                                                            ub8ehJSePAfc9FYqZIT6.arm5.elfGet hashmaliciousUnknownBrowse
                                                                                                              ub8ehJSePAfc9FYqZIT6.arm6.elfGet hashmaliciousUnknownBrowse
                                                                                                                ub8ehJSePAfc9FYqZIT6.arm.elfGet hashmaliciousMiraiBrowse
                                                                                                                  ub8ehJSePAfc9FYqZIT6.i686.elfGet hashmaliciousUnknownBrowse
                                                                                                                    Demon.sh4.elfGet hashmaliciousMirai, GafgytBrowse
                                                                                                                      tftp.elfGet hashmaliciousUnknownBrowse
                                                                                                                        i686.elfGet hashmaliciousUnknownBrowse
                                                                                                                          No context
                                                                                                                          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                                                                          CANONICAL-ASGBagent.elfGet hashmaliciousUnknownBrowse
                                                                                                                          • 91.189.91.42
                                                                                                                          ppc.elfGet hashmaliciousMiraiBrowse
                                                                                                                          • 91.189.91.42
                                                                                                                          .i.elfGet hashmaliciousUnknownBrowse
                                                                                                                          • 91.189.91.42
                                                                                                                          ub8ehJSePAfc9FYqZIT6.arm5.elfGet hashmaliciousUnknownBrowse
                                                                                                                          • 91.189.91.42
                                                                                                                          ub8ehJSePAfc9FYqZIT6.arm6.elfGet hashmaliciousUnknownBrowse
                                                                                                                          • 91.189.91.42
                                                                                                                          ub8ehJSePAfc9FYqZIT6.arm.elfGet hashmaliciousMiraiBrowse
                                                                                                                          • 91.189.91.42
                                                                                                                          ub8ehJSePAfc9FYqZIT6.mips.elfGet hashmaliciousUnknownBrowse
                                                                                                                          • 185.125.190.26
                                                                                                                          ub8ehJSePAfc9FYqZIT6.i686.elfGet hashmaliciousUnknownBrowse
                                                                                                                          • 91.189.91.42
                                                                                                                          Demon.i586.elfGet hashmaliciousMirai, GafgytBrowse
                                                                                                                          • 185.125.190.26
                                                                                                                          Demon.sh4.elfGet hashmaliciousMirai, GafgytBrowse
                                                                                                                          • 91.189.91.42
                                                                                                                          CANONICAL-ASGBagent.elfGet hashmaliciousUnknownBrowse
                                                                                                                          • 91.189.91.42
                                                                                                                          ppc.elfGet hashmaliciousMiraiBrowse
                                                                                                                          • 91.189.91.42
                                                                                                                          .i.elfGet hashmaliciousUnknownBrowse
                                                                                                                          • 91.189.91.42
                                                                                                                          ub8ehJSePAfc9FYqZIT6.arm5.elfGet hashmaliciousUnknownBrowse
                                                                                                                          • 91.189.91.42
                                                                                                                          ub8ehJSePAfc9FYqZIT6.arm6.elfGet hashmaliciousUnknownBrowse
                                                                                                                          • 91.189.91.42
                                                                                                                          ub8ehJSePAfc9FYqZIT6.arm.elfGet hashmaliciousMiraiBrowse
                                                                                                                          • 91.189.91.42
                                                                                                                          ub8ehJSePAfc9FYqZIT6.mips.elfGet hashmaliciousUnknownBrowse
                                                                                                                          • 185.125.190.26
                                                                                                                          ub8ehJSePAfc9FYqZIT6.i686.elfGet hashmaliciousUnknownBrowse
                                                                                                                          • 91.189.91.42
                                                                                                                          Demon.i586.elfGet hashmaliciousMirai, GafgytBrowse
                                                                                                                          • 185.125.190.26
                                                                                                                          Demon.sh4.elfGet hashmaliciousMirai, GafgytBrowse
                                                                                                                          • 91.189.91.42
                                                                                                                          INIT7CHagent.elfGet hashmaliciousUnknownBrowse
                                                                                                                          • 109.202.202.202
                                                                                                                          ppc.elfGet hashmaliciousMiraiBrowse
                                                                                                                          • 109.202.202.202
                                                                                                                          .i.elfGet hashmaliciousUnknownBrowse
                                                                                                                          • 109.202.202.202
                                                                                                                          ub8ehJSePAfc9FYqZIT6.arm5.elfGet hashmaliciousUnknownBrowse
                                                                                                                          • 109.202.202.202
                                                                                                                          ub8ehJSePAfc9FYqZIT6.arm6.elfGet hashmaliciousUnknownBrowse
                                                                                                                          • 109.202.202.202
                                                                                                                          ub8ehJSePAfc9FYqZIT6.arm.elfGet hashmaliciousMiraiBrowse
                                                                                                                          • 109.202.202.202
                                                                                                                          ub8ehJSePAfc9FYqZIT6.i686.elfGet hashmaliciousUnknownBrowse
                                                                                                                          • 109.202.202.202
                                                                                                                          Demon.sh4.elfGet hashmaliciousMirai, GafgytBrowse
                                                                                                                          • 109.202.202.202
                                                                                                                          tftp.elfGet hashmaliciousUnknownBrowse
                                                                                                                          • 109.202.202.202
                                                                                                                          i686.elfGet hashmaliciousUnknownBrowse
                                                                                                                          • 109.202.202.202
                                                                                                                          No context
                                                                                                                          No context
                                                                                                                          No created / dropped files found
                                                                                                                          File type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), statically linked, stripped
                                                                                                                          Entropy (8bit):6.094863602972719
                                                                                                                          TrID:
                                                                                                                          • ELF Executable and Linkable format (Linux) (4029/14) 50.16%
                                                                                                                          • ELF Executable and Linkable format (generic) (4004/1) 49.84%
                                                                                                                          File name:VIVACIOUS_SNOWFLAKE.elf
                                                                                                                          File size:15'392'768 bytes
                                                                                                                          MD5:7c6af882f13545df23b5667432a09585
                                                                                                                          SHA1:14185f9c8993a45ac670c772831b291dccd067ac
                                                                                                                          SHA256:a80f7c3976a5235c6d8f1e86d8540452a30851ec27d34e56017f372732faaea6
                                                                                                                          SHA512:13a01f607732e18f6f4ec1080b7820eeb459ad9de36a6eebc2979172042e282a8414cd21c00454fcf4647b1e1e5a73bbfeb22c6dc9d1d69a34c65b72b6c631b1
                                                                                                                          SSDEEP:98304:cM8QB9a8tlOjctjo8Yu6e+xBlZJDbRf0II0FNBmYG+E3C2M3BuSu:cM8QB08Yde+tRf0ILFNBmYG73lM39u
                                                                                                                          TLSH:CEF62A03F8D514D5C4EAD1B489214272BA71785C0B7923CB2BA1F7B82B32BF49E7A754
                                                                                                                          File Content Preview:.ELF..............>.......E.....@...................@.8...@.............@.......@.@.....@.@.....P.......P.................................@.......@......^.......^.......................`.......`.......`.......OX......OX...............................&....

                                                                                                                          ELF header

                                                                                                                          Class:ELF64
                                                                                                                          Data:2's complement, little endian
                                                                                                                          Version:1 (current)
                                                                                                                          Machine:Advanced Micro Devices X86-64
                                                                                                                          Version Number:0x1
                                                                                                                          Type:EXEC (Executable file)
                                                                                                                          OS/ABI:UNIX - System V
                                                                                                                          ABI Version:0
                                                                                                                          Entry Point Address:0x45d0e0
                                                                                                                          Flags:0x0
                                                                                                                          ELF Header Size:64
                                                                                                                          Program Header Offset:64
                                                                                                                          Program Header Size:56
                                                                                                                          Number of Program Headers:6
                                                                                                                          Section Header Offset:400
                                                                                                                          Section Header Size:64
                                                                                                                          Number of Section Headers:13
                                                                                                                          Header String Table Index:3
                                                                                                                          NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                                                                                                          NULL0x00x00x00x00x0000
                                                                                                                          .textPROGBITS0x4010000x10000x8e4e9d0x00x6AX0032
                                                                                                                          .rodataPROGBITS0xce60000x8e60000x2719430x00x2A0032
                                                                                                                          .shstrtabSTRTAB0x00xb579600x870x00x0001
                                                                                                                          .typelinkPROGBITS0xf57a000xb57a000x48c40x00x2A0032
                                                                                                                          .itablinkPROGBITS0xf5c2e00xb5c2e00x18900x00x2A0032
                                                                                                                          .gosymtabPROGBITS0xf5db700xb5db700x00x00x2A001
                                                                                                                          .gopclntabPROGBITS0xf5db800xb5db800x30d4000x00x2A0032
                                                                                                                          .go.buildinfoPROGBITS0x126b0000xe6b0000x300x00x3WA0016
                                                                                                                          .noptrdataPROGBITS0x126b0400xe6b0400x322400x00x3WA0032
                                                                                                                          .dataPROGBITS0x129d2800xe9d2800x106380x00x3WA0032
                                                                                                                          .bssNOBITS0x12ad8c00xead8c00x335000x00x3WA0032
                                                                                                                          .noptrbssNOBITS0x12e0dc00xee0dc00x132b00x00x3WA0032
                                                                                                                          TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                                                                                          PHDR0x400x4000400x4000400x1500x1501.63920x4R 0x1000
                                                                                                                          LOAD0x00x4000000x4000000x8e5e9d0x8e5e9d6.19670x5R E0x1000.text
                                                                                                                          LOAD0x8e60000xce60000xce60000x584f800x584f805.20630x4R 0x1000.rodata .typelink .itablink .gosymtab .gopclntab
                                                                                                                          LOAD0xe6b0000x126b0000x126b0000x428c00x890704.67780x6RW 0x1000.go.buildinfo .noptrdata .data .bss .noptrbss
                                                                                                                          GNU_STACK0x00x00x00x00x00.00000x6RW 0x8
                                                                                                                          LOOS+50415800x00x00x00x00x00.00000x2a00 0x8
                                                                                                                          TimestampSIDSignatureSeveritySource IPSource PortDest IPDest PortProtocol
                                                                                                                          2024-12-02T21:44:11.418401+01002852741ETPRO MALWARE Sliver DNS SessionInit Request1192.168.2.23546601.1.1.153UDP
                                                                                                                          2024-12-02T21:44:28.482039+01002852745ETPRO MALWARE Sliver DNS Base58 Poll Request1192.168.2.23466351.1.1.153UDP
                                                                                                                          TimestampSource PortDest PortSource IPDest IP
                                                                                                                          Dec 2, 2024 21:44:13.724657059 CET43928443192.168.2.2391.189.91.42
                                                                                                                          Dec 2, 2024 21:44:19.355817080 CET42836443192.168.2.2391.189.91.43
                                                                                                                          Dec 2, 2024 21:44:34.201714039 CET43928443192.168.2.2391.189.91.42
                                                                                                                          Dec 2, 2024 21:44:38.297264099 CET4251680192.168.2.23109.202.202.202
                                                                                                                          Dec 2, 2024 21:44:46.488123894 CET42836443192.168.2.2391.189.91.43
                                                                                                                          Dec 2, 2024 21:45:15.156197071 CET43928443192.168.2.2391.189.91.42
                                                                                                                          TimestampSource PortDest PortSource IPDest IP
                                                                                                                          Dec 2, 2024 21:44:11.418401003 CET5466053192.168.2.231.1.1.1
                                                                                                                          Dec 2, 2024 21:44:11.772806883 CET53546601.1.1.1192.168.2.23
                                                                                                                          Dec 2, 2024 21:44:11.779062033 CET5344753192.168.2.231.1.1.1
                                                                                                                          Dec 2, 2024 21:44:12.125320911 CET53534471.1.1.1192.168.2.23
                                                                                                                          Dec 2, 2024 21:44:12.129070997 CET5664853192.168.2.231.1.1.1
                                                                                                                          Dec 2, 2024 21:44:12.481369019 CET53566481.1.1.1192.168.2.23
                                                                                                                          Dec 2, 2024 21:44:12.486340046 CET4670153192.168.2.231.1.1.1
                                                                                                                          Dec 2, 2024 21:44:12.840188980 CET53467011.1.1.1192.168.2.23
                                                                                                                          Dec 2, 2024 21:44:12.845212936 CET5263453192.168.2.231.1.1.1
                                                                                                                          Dec 2, 2024 21:44:13.195004940 CET53526341.1.1.1192.168.2.23
                                                                                                                          Dec 2, 2024 21:44:13.198190928 CET4121953192.168.2.231.1.1.1
                                                                                                                          Dec 2, 2024 21:44:13.548901081 CET53412191.1.1.1192.168.2.23
                                                                                                                          Dec 2, 2024 21:44:13.552633047 CET6083053192.168.2.231.1.1.1
                                                                                                                          Dec 2, 2024 21:44:13.904458046 CET53608301.1.1.1192.168.2.23
                                                                                                                          Dec 2, 2024 21:44:13.907392979 CET4996153192.168.2.231.1.1.1
                                                                                                                          Dec 2, 2024 21:44:14.260323048 CET53499611.1.1.1192.168.2.23
                                                                                                                          Dec 2, 2024 21:44:14.264158964 CET4487253192.168.2.231.1.1.1
                                                                                                                          Dec 2, 2024 21:44:14.616060972 CET53448721.1.1.1192.168.2.23
                                                                                                                          Dec 2, 2024 21:44:14.621933937 CET3580253192.168.2.231.1.1.1
                                                                                                                          Dec 2, 2024 21:44:15.204693079 CET53358021.1.1.1192.168.2.23
                                                                                                                          Dec 2, 2024 21:44:15.209120035 CET5867753192.168.2.231.1.1.1
                                                                                                                          Dec 2, 2024 21:44:15.767826080 CET53586771.1.1.1192.168.2.23
                                                                                                                          Dec 2, 2024 21:44:15.779898882 CET5277753192.168.2.231.1.1.1
                                                                                                                          Dec 2, 2024 21:44:15.782012939 CET5544153192.168.2.231.1.1.1
                                                                                                                          Dec 2, 2024 21:44:16.335663080 CET53554411.1.1.1192.168.2.23
                                                                                                                          Dec 2, 2024 21:44:16.336169004 CET53527771.1.1.1192.168.2.23
                                                                                                                          Dec 2, 2024 21:44:16.340684891 CET5079953192.168.2.231.1.1.1
                                                                                                                          Dec 2, 2024 21:44:16.897880077 CET53507991.1.1.1192.168.2.23
                                                                                                                          Dec 2, 2024 21:44:17.904680967 CET3640353192.168.2.231.1.1.1
                                                                                                                          Dec 2, 2024 21:44:18.460571051 CET53364031.1.1.1192.168.2.23
                                                                                                                          Dec 2, 2024 21:44:18.466922998 CET4758953192.168.2.231.1.1.1
                                                                                                                          Dec 2, 2024 21:44:18.816339016 CET53475891.1.1.1192.168.2.23
                                                                                                                          Dec 2, 2024 21:44:18.822359085 CET4989653192.168.2.231.1.1.1
                                                                                                                          Dec 2, 2024 21:44:19.176155090 CET53498961.1.1.1192.168.2.23
                                                                                                                          Dec 2, 2024 21:44:22.905930996 CET5869953192.168.2.231.1.1.1
                                                                                                                          Dec 2, 2024 21:44:23.467206001 CET53586991.1.1.1192.168.2.23
                                                                                                                          Dec 2, 2024 21:44:23.472304106 CET5905253192.168.2.231.1.1.1
                                                                                                                          Dec 2, 2024 21:44:23.825366020 CET53590521.1.1.1192.168.2.23
                                                                                                                          Dec 2, 2024 21:44:23.832119942 CET4694953192.168.2.231.1.1.1
                                                                                                                          Dec 2, 2024 21:44:24.180372000 CET53469491.1.1.1192.168.2.23
                                                                                                                          Dec 2, 2024 21:44:27.914053917 CET5810453192.168.2.231.1.1.1
                                                                                                                          Dec 2, 2024 21:44:28.474632025 CET53581041.1.1.1192.168.2.23
                                                                                                                          Dec 2, 2024 21:44:28.482038975 CET4663553192.168.2.231.1.1.1
                                                                                                                          Dec 2, 2024 21:44:28.830612898 CET53466351.1.1.1192.168.2.23
                                                                                                                          Dec 2, 2024 21:44:28.836647034 CET6090653192.168.2.231.1.1.1
                                                                                                                          Dec 2, 2024 21:44:29.191901922 CET53609061.1.1.1192.168.2.23
                                                                                                                          Dec 2, 2024 21:44:32.907613993 CET3745953192.168.2.231.1.1.1
                                                                                                                          Dec 2, 2024 21:44:33.466341972 CET53374591.1.1.1192.168.2.23
                                                                                                                          Dec 2, 2024 21:44:33.476612091 CET4009953192.168.2.231.1.1.1
                                                                                                                          Dec 2, 2024 21:44:33.830091953 CET53400991.1.1.1192.168.2.23
                                                                                                                          Dec 2, 2024 21:44:33.838598013 CET4743453192.168.2.231.1.1.1
                                                                                                                          Dec 2, 2024 21:44:34.192389965 CET53474341.1.1.1192.168.2.23
                                                                                                                          Dec 2, 2024 21:44:37.910440922 CET4199853192.168.2.231.1.1.1
                                                                                                                          Dec 2, 2024 21:44:38.470710039 CET53419981.1.1.1192.168.2.23
                                                                                                                          Dec 2, 2024 21:44:38.478661060 CET4151053192.168.2.231.1.1.1
                                                                                                                          Dec 2, 2024 21:44:38.835522890 CET53415101.1.1.1192.168.2.23
                                                                                                                          Dec 2, 2024 21:44:38.842047930 CET5875953192.168.2.231.1.1.1
                                                                                                                          Dec 2, 2024 21:44:39.194166899 CET53587591.1.1.1192.168.2.23
                                                                                                                          Dec 2, 2024 21:44:42.906208038 CET5563753192.168.2.231.1.1.1
                                                                                                                          Dec 2, 2024 21:44:43.466104984 CET53556371.1.1.1192.168.2.23
                                                                                                                          Dec 2, 2024 21:44:43.473568916 CET4490853192.168.2.231.1.1.1
                                                                                                                          Dec 2, 2024 21:44:43.821137905 CET53449081.1.1.1192.168.2.23
                                                                                                                          Dec 2, 2024 21:44:43.825912952 CET5099753192.168.2.231.1.1.1
                                                                                                                          Dec 2, 2024 21:44:44.177736998 CET53509971.1.1.1192.168.2.23
                                                                                                                          Dec 2, 2024 21:44:47.911681890 CET5271253192.168.2.231.1.1.1
                                                                                                                          Dec 2, 2024 21:44:48.463571072 CET53527121.1.1.1192.168.2.23
                                                                                                                          Dec 2, 2024 21:44:48.472692966 CET4103553192.168.2.231.1.1.1
                                                                                                                          Dec 2, 2024 21:44:48.819602966 CET53410351.1.1.1192.168.2.23
                                                                                                                          Dec 2, 2024 21:44:48.826531887 CET3567153192.168.2.231.1.1.1
                                                                                                                          Dec 2, 2024 21:44:49.179352999 CET53356711.1.1.1192.168.2.23
                                                                                                                          Dec 2, 2024 21:44:52.910753012 CET5987653192.168.2.231.1.1.1
                                                                                                                          Dec 2, 2024 21:44:53.470062971 CET53598761.1.1.1192.168.2.23
                                                                                                                          Dec 2, 2024 21:44:53.477086067 CET4544053192.168.2.231.1.1.1
                                                                                                                          Dec 2, 2024 21:44:53.824803114 CET53454401.1.1.1192.168.2.23
                                                                                                                          Dec 2, 2024 21:44:53.831603050 CET3368453192.168.2.231.1.1.1
                                                                                                                          Dec 2, 2024 21:44:54.178807020 CET53336841.1.1.1192.168.2.23
                                                                                                                          TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                                                                                                          Dec 2, 2024 21:44:11.418401003 CET192.168.2.231.1.1.10x3814Standard query (0)baakbt7jt8ca.0x0000b.fashionspeedy.comA (IP address)IN (0x0001)false
                                                                                                                          Dec 2, 2024 21:44:11.779062033 CET192.168.2.231.1.1.10xf657Standard query (0)11vzd182342743ckeg3rzw6c.0x0000b.fashionspeedy.comA (IP address)IN (0x0001)false
                                                                                                                          Dec 2, 2024 21:44:12.129070997 CET192.168.2.231.1.1.10xc4eeStandard query (0)11vzd182342dt9h897kxynkb.0x0000b.fashionspeedy.comA (IP address)IN (0x0001)false
                                                                                                                          Dec 2, 2024 21:44:12.486340046 CET192.168.2.231.1.1.10x2898Standard query (0)11vzd182342f6z7uxjym04yh.0x0000b.fashionspeedy.comA (IP address)IN (0x0001)false
                                                                                                                          Dec 2, 2024 21:44:12.845212936 CET192.168.2.231.1.1.10xbed2Standard query (0)11vzd182342e7ucw5vjdyeqe.0x0000b.fashionspeedy.comA (IP address)IN (0x0001)false
                                                                                                                          Dec 2, 2024 21:44:13.198190928 CET192.168.2.231.1.1.10xab7fStandard query (0)U8TLqVrTo6CVBz2wRTTS.0x0000b.fashionspeedy.comA (IP address)IN (0x0001)false
                                                                                                                          Dec 2, 2024 21:44:13.552633047 CET192.168.2.231.1.1.10xa877Standard query (0)U8TLqVrTnw9Qd26hM5Vv.0x0000b.fashionspeedy.comA (IP address)IN (0x0001)false
                                                                                                                          Dec 2, 2024 21:44:13.907392979 CET192.168.2.231.1.1.10x9dbdStandard query (0)U8TLqVrTnPtu6t9FixBj.0x0000b.fashionspeedy.comA (IP address)IN (0x0001)false
                                                                                                                          Dec 2, 2024 21:44:14.264158964 CET192.168.2.231.1.1.10x812dStandard query (0)U8TLqVrTnxasfkg9urnE.0x0000b.fashionspeedy.comA (IP address)IN (0x0001)false
                                                                                                                          Dec 2, 2024 21:44:14.621933937 CET192.168.2.231.1.1.10x3122Standard query (0)Mw61bELXmC4yq4v2wXRjyJZwrVShKVjMiPmRCUV3ZEM6xxknuxU5BMpxnRFUbHu.FxPfSfyAKA3TXem6R5UPUnsdmvuLmvAWp9W6xPmXMSGemeAqz5RgbjhxBayhy1S.hs3uUMSZ9D8Be2U6GoiriwEWiAcBLSbwRPRREa5jKFzXvcTpTpgjQcnTFH9yXoX.DgnvB7vTsEwLa7NxEuS2mHDM8pbNV9DJV.0x0000b.fashionspeedy.com16IN (0x0001)false
                                                                                                                          Dec 2, 2024 21:44:15.209120035 CET192.168.2.231.1.1.10x8eStandard query (0)4CnUTQv52TZRaVn7dcv1gWgz11eyMXBSCf2vqawQhCK8V9upciceSZjSu568FKr.A9CUXP2PtUcQEcWAgGchy6dNGuoEhppe7AAZPRbWtd16QjArhrmGfLktKnBKWx5.SoQ8K4JcSs4dGn5A2cfYqiiUNEqiNxArAaw1QwLH5aSfgNqdGB.0x0000b.fashionspeedy.com16IN (0x0001)false
                                                                                                                          Dec 2, 2024 21:44:15.779898882 CET192.168.2.231.1.1.10xb905Standard query (0)Mzd7mTh3RK7BTVwGwEFocG9vuCmyuqmS2sAySv8cEY2cQt51vEb3aDCnFQN5DW9.a2X1ifaCd9sJux3PHrS6EtACFowPb71T4bC3WynCuemUssBFJiwH4dQCrJxcN47.Gp2iTWHpKXE86W1gcBT16rjX7NNTmWBrCpNwNzbsEtXH3fGRaqF4YR5ShTV7bGi.bF5vUaaMXd3rupjn76z1ejpH6xkYhjn9q.0x0000b.fashionspeedy.comA (IP address)IN (0x0001)false
                                                                                                                          Dec 2, 2024 21:44:15.782012939 CET192.168.2.231.1.1.10x2c17Standard query (0)Mzd7mTh3ReJRcSJAWVj2is2y88xRQCYRKRkfsJ73ZkfJajCoeM66KZfF2Qgu8AU.BJsUBFNBnRJGFM2Ak2mfGXp8DfokjLWHZdMbg9A4jWwFsgn7yg1fN2AvgYuY5nZ.feNHGbbevAgLYVWyAqZWc4nXuqxg8GXVK1RiSTRyTG93r1zFSBfTG9wXKUxkp57.So4Z8hyhHhdzW76kNYMnSPX3pukst4NJo.0x0000b.fashionspeedy.comA (IP address)IN (0x0001)false
                                                                                                                          Dec 2, 2024 21:44:16.340684891 CET192.168.2.231.1.1.10xcac9Standard query (0)xGW6nFo6YzQH6j3RdiMggsgMfNZVaJQiuN8Ezd6sTizxTbf4jwvbgZaSrpMfwrQ.qsk8EHRz1gHmps.0x0000b.fashionspeedy.comA (IP address)IN (0x0001)false
                                                                                                                          Dec 2, 2024 21:44:17.904680967 CET192.168.2.231.1.1.10x64dStandard query (0)LpgfPusGunQMRGTjscuyVWkyZQt9KgdNAoiNdvpb3dsR5PGMKNXMzLr7XZQim6n.xstcgjEMoywwup3a69WxjzVmRGSsqEFcu3tCRTyEgfovAZDSP96NeJQtuhHaHZL.qKhL1XuGbMERpA6J2W2U1dxsY.0x0000b.fashionspeedy.comA (IP address)IN (0x0001)false
                                                                                                                          Dec 2, 2024 21:44:18.466922998 CET192.168.2.231.1.1.10xab1fStandard query (0)6NguhvqpquxEq2i2E6pzWPE.0x0000b.fashionspeedy.com16IN (0x0001)false
                                                                                                                          Dec 2, 2024 21:44:18.822359085 CET192.168.2.231.1.1.10x1182Standard query (0)backbhz9k431a78.0x0000b.fashionspeedy.com16IN (0x0001)false
                                                                                                                          Dec 2, 2024 21:44:22.905930996 CET192.168.2.231.1.1.10xedffStandard query (0)LpgfPush4meiqhK4ZoWGmmZQVSq3avqPPSiPWg3phVsoQeFcKdzXCZwqfn5s3ia.TNuM65Lu4sQEB9i99zqd8Kh5rSiLwjUZoFDxLyFTqbF3sRhPAZyHFaNFp3eDNtU.5nh7K8CfsTDPVR1LqcWnzCCwY.0x0000b.fashionspeedy.comA (IP address)IN (0x0001)false
                                                                                                                          Dec 2, 2024 21:44:23.472304106 CET192.168.2.231.1.1.10x8904Standard query (0)6NguhvqpquxEpZdDN5BnEqe.0x0000b.fashionspeedy.com16IN (0x0001)false
                                                                                                                          Dec 2, 2024 21:44:23.832119942 CET192.168.2.231.1.1.10x11a0Standard query (0)backbhz9k451a78.0x0000b.fashionspeedy.com16IN (0x0001)false
                                                                                                                          Dec 2, 2024 21:44:27.914053917 CET192.168.2.231.1.1.10xeae4Standard query (0)LpgfPushDk65Fi5P54hjJGgwpqgzmbMR6xH7d12gFFXXwhpZP822UDTNHkLppPf.5uy3yqtwWy8zHcXEMyHYPmHCrKCeXf2mTp51xUeFL5qJHVn12WNb5pX73nQX24S.quYoab3RyKqgYM8zryQjnVaqb.0x0000b.fashionspeedy.comA (IP address)IN (0x0001)false
                                                                                                                          Dec 2, 2024 21:44:28.482038975 CET192.168.2.231.1.1.10x8b68Standard query (0)6Nguhvqpquxf2RLvWN5wrb8.0x0000b.fashionspeedy.com16IN (0x0001)false
                                                                                                                          Dec 2, 2024 21:44:28.836647034 CET192.168.2.231.1.1.10xa4f2Standard query (0)backbhz9k471a78.0x0000b.fashionspeedy.com16IN (0x0001)false
                                                                                                                          Dec 2, 2024 21:44:32.907613993 CET192.168.2.231.1.1.10xb79dStandard query (0)LpgfPushNiuTfJ2t3vRqwWYcVTgCSYV9T44ZsuCPVw5RAdJTDobr8jBhZY7cmf7.xCcnkSTKQbTADbwSPyZ534GE3AY57RqQ41TbEArxhWwQmQDoPqFC6YA7xsgnHoj.hrYHEtqB5ZvDfJUUhe8FzFGpc.0x0000b.fashionspeedy.comA (IP address)IN (0x0001)false
                                                                                                                          Dec 2, 2024 21:44:33.476612091 CET192.168.2.231.1.1.10xc631Standard query (0)6NguhvqpquxEokX9xRofGjP.0x0000b.fashionspeedy.com16IN (0x0001)false
                                                                                                                          Dec 2, 2024 21:44:33.838598013 CET192.168.2.231.1.1.10x307dStandard query (0)backbhz9k491a78.0x0000b.fashionspeedy.com16IN (0x0001)false
                                                                                                                          Dec 2, 2024 21:44:37.910440922 CET192.168.2.231.1.1.10x7257Standard query (0)LpgfPushXhJq6JmSdsPa2RAARGBmVPtBiiB3bF8NPRGiyQ7vEuEQ5PT1XJCrc1P.Sipm7yrd4nHtqSt8tfs4Hot6oEHWgGJ4UzYDgJagPF9ydKyV8tgFZPNBeECfVqb.yrk9adeQv8PYUeF8xSKdX9sAp.0x0000b.fashionspeedy.comA (IP address)IN (0x0001)false
                                                                                                                          Dec 2, 2024 21:44:38.478661060 CET192.168.2.231.1.1.10x2940Standard query (0)6Nguhvqpquxf4Zhsc3g6Wzf.0x0000b.fashionspeedy.com16IN (0x0001)false
                                                                                                                          Dec 2, 2024 21:44:38.842047930 CET192.168.2.231.1.1.10xbdd6Standard query (0)backbhz9k4p1a78.0x0000b.fashionspeedy.com16IN (0x0001)false
                                                                                                                          Dec 2, 2024 21:44:42.906208038 CET192.168.2.231.1.1.10x2b41Standard query (0)LpgfPushGGAcVkhEPTuckGVnGTN7g4GrHiz5Zx2jTcXbb1cBoNJr1qxAU4N3RRS.FPsvmmY7ZGoeeZFm5iPAge3ev8pHgZNgPzsDiDiKMCEPp5as94UEh1SrtnVxZYw.ypXnpzQhhg7YePCPZ45AH9kT1.0x0000b.fashionspeedy.comA (IP address)IN (0x0001)false
                                                                                                                          Dec 2, 2024 21:44:43.473568916 CET192.168.2.231.1.1.10xb14aStandard query (0)6NguhvqpquxEhuSbi65st27.0x0000b.fashionspeedy.com16IN (0x0001)false
                                                                                                                          Dec 2, 2024 21:44:43.825912952 CET192.168.2.231.1.1.10x24e2Standard query (0)backbhz9k4u1a78.0x0000b.fashionspeedy.com16IN (0x0001)false
                                                                                                                          Dec 2, 2024 21:44:47.911681890 CET192.168.2.231.1.1.10x65e1Standard query (0)LpgfPushqfQZumEVH6g2f8MMmbrKdJgsD2yQ3j1KJeqfKbGYnXEcBZajfpw2HTt.h4tPzgPuP88M69yZjkcwvcTEGAVaHJ7d4fVzjU8ev8psq6CEEJ19aoVFFxwVymF.q8iy5tmkra4RSBCpqM5ciX5u2.0x0000b.fashionspeedy.comA (IP address)IN (0x0001)false
                                                                                                                          Dec 2, 2024 21:44:48.472692966 CET192.168.2.231.1.1.10xcdd7Standard query (0)6NguhvqpquxESJybPHjHn25.0x0000b.fashionspeedy.com16IN (0x0001)false
                                                                                                                          Dec 2, 2024 21:44:48.826531887 CET192.168.2.231.1.1.10x4b16Standard query (0)backbhz9k4y1a78.0x0000b.fashionspeedy.com16IN (0x0001)false
                                                                                                                          Dec 2, 2024 21:44:52.910753012 CET192.168.2.231.1.1.10x1927Standard query (0)LpgfPushzEewKnT5E86Gd7tiknL7pyH3VNyVT8a1SYaNLNp6MsdxKugY3j9Haf6.DKjreLjsWFryXFYMW4gj6bQe9fsghA2gooKEpYSpRnWMAjc9rMCbxqxtkKCUPar.LFmyX69PfhPLGq8QEH7cKNxfP.0x0000b.fashionspeedy.comA (IP address)IN (0x0001)false
                                                                                                                          Dec 2, 2024 21:44:53.477086067 CET192.168.2.231.1.1.10x4b6aStandard query (0)6NguhvqpquxEGpxzq9kvu7r.0x0000b.fashionspeedy.com16IN (0x0001)false
                                                                                                                          Dec 2, 2024 21:44:53.831603050 CET192.168.2.231.1.1.10xc77cStandard query (0)backbhz9kf11a78.0x0000b.fashionspeedy.com16IN (0x0001)false
                                                                                                                          TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                                                                                                          Dec 2, 2024 21:44:11.772806883 CET1.1.1.1192.168.2.230x3814No error (0)baakbt7jt8ca.0x0000b.fashionspeedy.com55.185.130.14A (IP address)IN (0x0001)false
                                                                                                                          Dec 2, 2024 21:44:12.125320911 CET1.1.1.1192.168.2.230xf657No error (0)11vzd182342743ckeg3rzw6c.0x0000b.fashionspeedy.com137.154.240.38A (IP address)IN (0x0001)false
                                                                                                                          Dec 2, 2024 21:44:12.481369019 CET1.1.1.1192.168.2.230xc4eeNo error (0)11vzd182342dt9h897kxynkb.0x0000b.fashionspeedy.com246.41.15.231A (IP address)IN (0x0001)false
                                                                                                                          Dec 2, 2024 21:44:12.840188980 CET1.1.1.1192.168.2.230x2898No error (0)11vzd182342f6z7uxjym04yh.0x0000b.fashionspeedy.com178.215.145.199A (IP address)IN (0x0001)false
                                                                                                                          Dec 2, 2024 21:44:13.195004940 CET1.1.1.1192.168.2.230xbed2No error (0)11vzd182342e7ucw5vjdyeqe.0x0000b.fashionspeedy.com1.247.215.215A (IP address)IN (0x0001)false
                                                                                                                          Dec 2, 2024 21:44:13.548901081 CET1.1.1.1192.168.2.230xab7fNo error (0)U8TLqVrTo6CVBz2wRTTS.0x0000b.fashionspeedy.com181.99.74.228A (IP address)IN (0x0001)false
                                                                                                                          Dec 2, 2024 21:44:13.904458046 CET1.1.1.1192.168.2.230xa877No error (0)U8TLqVrTnw9Qd26hM5Vv.0x0000b.fashionspeedy.com15.14.166.112A (IP address)IN (0x0001)false
                                                                                                                          Dec 2, 2024 21:44:14.260323048 CET1.1.1.1192.168.2.230x9dbdNo error (0)U8TLqVrTnPtu6t9FixBj.0x0000b.fashionspeedy.com188.94.122.38A (IP address)IN (0x0001)false
                                                                                                                          Dec 2, 2024 21:44:14.616060972 CET1.1.1.1192.168.2.230x812dNo error (0)U8TLqVrTnxasfkg9urnE.0x0000b.fashionspeedy.com66.232.194.253A (IP address)IN (0x0001)false
                                                                                                                          Dec 2, 2024 21:44:15.204693079 CET1.1.1.1192.168.2.230x3122No error (0)Mw61bELXmC4yq4v2wXRjyJZwrVShKVjMiPmRCUV3ZEM6xxknuxU5BMpxnRFUbHu.FxPfSfyAKA3TXem6R5UPUnsdmvuLmvAWp9W6xPmXMSGemeAqz5RgbjhxBayhy1S.hs3uUMSZ9D8Be2U6GoiriwEWiAcBLSbwRPRREa5jKFzXvcTpTpgjQcnTFH9yXoX.DgnvB7vTsEwLa7NxEuS2mHDM8pbNV9DJV.0x0000b.fashionspeedy.comTXT (Text strings)IN (0x0001)false
                                                                                                                          Dec 2, 2024 21:44:15.767826080 CET1.1.1.1192.168.2.230x8eNo error (0)4CnUTQv52TZRaVn7dcv1gWgz11eyMXBSCf2vqawQhCK8V9upciceSZjSu568FKr.A9CUXP2PtUcQEcWAgGchy6dNGuoEhppe7AAZPRbWtd16QjArhrmGfLktKnBKWx5.SoQ8K4JcSs4dGn5A2cfYqiiUNEqiNxArAaw1QwLH5aSfgNqdGB.0x0000b.fashionspeedy.comTXT (Text strings)IN (0x0001)false
                                                                                                                          Dec 2, 2024 21:44:16.335663080 CET1.1.1.1192.168.2.230x2c17No error (0)Mzd7mTh3ReJRcSJAWVj2is2y88xRQCYRKRkfsJ73ZkfJajCoeM66KZfF2Qgu8AU.BJsUBFNBnRJGFM2Ak2mfGXp8DfokjLWHZdMbg9A4jWwFsgn7yg1fN2AvgYuY5nZ.feNHGbbevAgLYVWyAqZWc4nXuqxg8GXVK1RiSTRyTG93r1zFSBfTG9wXKUxkp57.So4Z8hyhHhdzW76kNYMnSPX3pukst4NJo.0x0000b.fashionspeedy.com123.42.4.50A (IP address)IN (0x0001)false
                                                                                                                          Dec 2, 2024 21:44:16.336169004 CET1.1.1.1192.168.2.230xb905No error (0)Mzd7mTh3RK7BTVwGwEFocG9vuCmyuqmS2sAySv8cEY2cQt51vEb3aDCnFQN5DW9.a2X1ifaCd9sJux3PHrS6EtACFowPb71T4bC3WynCuemUssBFJiwH4dQCrJxcN47.Gp2iTWHpKXE86W1gcBT16rjX7NNTmWBrCpNwNzbsEtXH3fGRaqF4YR5ShTV7bGi.bF5vUaaMXd3rupjn76z1ejpH6xkYhjn9q.0x0000b.fashionspeedy.com172.136.140.167A (IP address)IN (0x0001)false
                                                                                                                          Dec 2, 2024 21:44:16.897880077 CET1.1.1.1192.168.2.230xcac9No error (0)xGW6nFo6YzQH6j3RdiMggsgMfNZVaJQiuN8Ezd6sTizxTbf4jwvbgZaSrpMfwrQ.qsk8EHRz1gHmps.0x0000b.fashionspeedy.com209.130.158.56A (IP address)IN (0x0001)false
                                                                                                                          Dec 2, 2024 21:44:18.460571051 CET1.1.1.1192.168.2.230x64dNo error (0)LpgfPusGunQMRGTjscuyVWkyZQt9KgdNAoiNdvpb3dsR5PGMKNXMzLr7XZQim6n.xstcgjEMoywwup3a69WxjzVmRGSsqEFcu3tCRTyEgfovAZDSP96NeJQtuhHaHZL.qKhL1XuGbMERpA6J2W2U1dxsY.0x0000b.fashionspeedy.com206.4.237.138A (IP address)IN (0x0001)false
                                                                                                                          Dec 2, 2024 21:44:18.816339016 CET1.1.1.1192.168.2.230xab1fNo error (0)6NguhvqpquxEq2i2E6pzWPE.0x0000b.fashionspeedy.comTXT (Text strings)IN (0x0001)false
                                                                                                                          Dec 2, 2024 21:44:19.176155090 CET1.1.1.1192.168.2.230x1182No error (0)backbhz9k431a78.0x0000b.fashionspeedy.comTXT (Text strings)IN (0x0001)false
                                                                                                                          Dec 2, 2024 21:44:23.467206001 CET1.1.1.1192.168.2.230xedffNo error (0)LpgfPush4meiqhK4ZoWGmmZQVSq3avqPPSiPWg3phVsoQeFcKdzXCZwqfn5s3ia.TNuM65Lu4sQEB9i99zqd8Kh5rSiLwjUZoFDxLyFTqbF3sRhPAZyHFaNFp3eDNtU.5nh7K8CfsTDPVR1LqcWnzCCwY.0x0000b.fashionspeedy.com156.49.83.116A (IP address)IN (0x0001)false
                                                                                                                          Dec 2, 2024 21:44:23.825366020 CET1.1.1.1192.168.2.230x8904No error (0)6NguhvqpquxEpZdDN5BnEqe.0x0000b.fashionspeedy.comTXT (Text strings)IN (0x0001)false
                                                                                                                          Dec 2, 2024 21:44:24.180372000 CET1.1.1.1192.168.2.230x11a0No error (0)backbhz9k451a78.0x0000b.fashionspeedy.comTXT (Text strings)IN (0x0001)false
                                                                                                                          Dec 2, 2024 21:44:28.474632025 CET1.1.1.1192.168.2.230xeae4No error (0)LpgfPushDk65Fi5P54hjJGgwpqgzmbMR6xH7d12gFFXXwhpZP822UDTNHkLppPf.5uy3yqtwWy8zHcXEMyHYPmHCrKCeXf2mTp51xUeFL5qJHVn12WNb5pX73nQX24S.quYoab3RyKqgYM8zryQjnVaqb.0x0000b.fashionspeedy.com82.88.235.84A (IP address)IN (0x0001)false
                                                                                                                          Dec 2, 2024 21:44:28.830612898 CET1.1.1.1192.168.2.230x8b68No error (0)6Nguhvqpquxf2RLvWN5wrb8.0x0000b.fashionspeedy.comTXT (Text strings)IN (0x0001)false
                                                                                                                          Dec 2, 2024 21:44:29.191901922 CET1.1.1.1192.168.2.230xa4f2No error (0)backbhz9k471a78.0x0000b.fashionspeedy.comTXT (Text strings)IN (0x0001)false
                                                                                                                          Dec 2, 2024 21:44:33.466341972 CET1.1.1.1192.168.2.230xb79dNo error (0)LpgfPushNiuTfJ2t3vRqwWYcVTgCSYV9T44ZsuCPVw5RAdJTDobr8jBhZY7cmf7.xCcnkSTKQbTADbwSPyZ534GE3AY57RqQ41TbEArxhWwQmQDoPqFC6YA7xsgnHoj.hrYHEtqB5ZvDfJUUhe8FzFGpc.0x0000b.fashionspeedy.com194.59.188.10A (IP address)IN (0x0001)false
                                                                                                                          Dec 2, 2024 21:44:33.830091953 CET1.1.1.1192.168.2.230xc631No error (0)6NguhvqpquxEokX9xRofGjP.0x0000b.fashionspeedy.comTXT (Text strings)IN (0x0001)false
                                                                                                                          Dec 2, 2024 21:44:34.192389965 CET1.1.1.1192.168.2.230x307dNo error (0)backbhz9k491a78.0x0000b.fashionspeedy.comTXT (Text strings)IN (0x0001)false
                                                                                                                          Dec 2, 2024 21:44:38.470710039 CET1.1.1.1192.168.2.230x7257No error (0)LpgfPushXhJq6JmSdsPa2RAARGBmVPtBiiB3bF8NPRGiyQ7vEuEQ5PT1XJCrc1P.Sipm7yrd4nHtqSt8tfs4Hot6oEHWgGJ4UzYDgJagPF9ydKyV8tgFZPNBeECfVqb.yrk9adeQv8PYUeF8xSKdX9sAp.0x0000b.fashionspeedy.com142.219.25.241A (IP address)IN (0x0001)false
                                                                                                                          Dec 2, 2024 21:44:38.835522890 CET1.1.1.1192.168.2.230x2940No error (0)6Nguhvqpquxf4Zhsc3g6Wzf.0x0000b.fashionspeedy.comTXT (Text strings)IN (0x0001)false
                                                                                                                          Dec 2, 2024 21:44:39.194166899 CET1.1.1.1192.168.2.230xbdd6No error (0)backbhz9k4p1a78.0x0000b.fashionspeedy.comTXT (Text strings)IN (0x0001)false
                                                                                                                          Dec 2, 2024 21:44:43.466104984 CET1.1.1.1192.168.2.230x2b41No error (0)LpgfPushGGAcVkhEPTuckGVnGTN7g4GrHiz5Zx2jTcXbb1cBoNJr1qxAU4N3RRS.FPsvmmY7ZGoeeZFm5iPAge3ev8pHgZNgPzsDiDiKMCEPp5as94UEh1SrtnVxZYw.ypXnpzQhhg7YePCPZ45AH9kT1.0x0000b.fashionspeedy.com1.84.239.125A (IP address)IN (0x0001)false
                                                                                                                          Dec 2, 2024 21:44:43.821137905 CET1.1.1.1192.168.2.230xb14aNo error (0)6NguhvqpquxEhuSbi65st27.0x0000b.fashionspeedy.comTXT (Text strings)IN (0x0001)false
                                                                                                                          Dec 2, 2024 21:44:44.177736998 CET1.1.1.1192.168.2.230x24e2No error (0)backbhz9k4u1a78.0x0000b.fashionspeedy.comTXT (Text strings)IN (0x0001)false
                                                                                                                          Dec 2, 2024 21:44:48.463571072 CET1.1.1.1192.168.2.230x65e1No error (0)LpgfPushqfQZumEVH6g2f8MMmbrKdJgsD2yQ3j1KJeqfKbGYnXEcBZajfpw2HTt.h4tPzgPuP88M69yZjkcwvcTEGAVaHJ7d4fVzjU8ev8psq6CEEJ19aoVFFxwVymF.q8iy5tmkra4RSBCpqM5ciX5u2.0x0000b.fashionspeedy.com19.68.163.193A (IP address)IN (0x0001)false
                                                                                                                          Dec 2, 2024 21:44:48.819602966 CET1.1.1.1192.168.2.230xcdd7No error (0)6NguhvqpquxESJybPHjHn25.0x0000b.fashionspeedy.comTXT (Text strings)IN (0x0001)false
                                                                                                                          Dec 2, 2024 21:44:49.179352999 CET1.1.1.1192.168.2.230x4b16No error (0)backbhz9k4y1a78.0x0000b.fashionspeedy.comTXT (Text strings)IN (0x0001)false
                                                                                                                          Dec 2, 2024 21:44:53.470062971 CET1.1.1.1192.168.2.230x1927No error (0)LpgfPushzEewKnT5E86Gd7tiknL7pyH3VNyVT8a1SYaNLNp6MsdxKugY3j9Haf6.DKjreLjsWFryXFYMW4gj6bQe9fsghA2gooKEpYSpRnWMAjc9rMCbxqxtkKCUPar.LFmyX69PfhPLGq8QEH7cKNxfP.0x0000b.fashionspeedy.com245.2.250.60A (IP address)IN (0x0001)false
                                                                                                                          Dec 2, 2024 21:44:53.824803114 CET1.1.1.1192.168.2.230x4b6aNo error (0)6NguhvqpquxEGpxzq9kvu7r.0x0000b.fashionspeedy.comTXT (Text strings)IN (0x0001)false
                                                                                                                          Dec 2, 2024 21:44:54.178807020 CET1.1.1.1192.168.2.230xc77cNo error (0)backbhz9kf11a78.0x0000b.fashionspeedy.comTXT (Text strings)IN (0x0001)false

                                                                                                                          System Behavior

                                                                                                                          Start time (UTC):20:44:10
                                                                                                                          Start date (UTC):02/12/2024
                                                                                                                          Path:/tmp/VIVACIOUS_SNOWFLAKE.elf
                                                                                                                          Arguments:/tmp/VIVACIOUS_SNOWFLAKE.elf
                                                                                                                          File size:15392768 bytes
                                                                                                                          MD5 hash:7c6af882f13545df23b5667432a09585