Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
CONSTANT_STRATEGY.elf

Overview

General Information

Sample name:CONSTANT_STRATEGY.elf
Analysis ID:1578698
MD5:abbf52dd16b588944358ad6b92dd55b0
SHA1:9a67c0b8db60c7b243c121a41745fd4f34a4372c
SHA256:12e20c8380c4f76fb99e00ad484621cfec27ce239483a55844e4b42ea8db1100
Tags:elfuser-abuse_ch
Infos:

Detection

Sliver
Score:84
Range:0 - 100
Whitelisted:false

Signatures

Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Suricata IDS alerts for network traffic
Yara detected Sliver Implants
Machine Learning detection for sample
Performs DNS TXT record lookups
Queries the IP of a very long domain name
Connects to many different domains
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Uses the "uname" system call to query kernel version information (possible evasion)
Yara signature match

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1578698
Start date and time:2024-12-20 06:37:05 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 7m 6s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:CONSTANT_STRATEGY.elf
Detection:MAL
Classification:mal84.troj.evad.linELF@0/0@38/0
  • VT rate limit hit for: LpgEQkkyxkjgvbLBCkkTxFq8kLQbBJp54js4aWdBfWiSPmMjNCRHmPpYsfgi7p1.7QVC7SwnPabjdrWDFxsPYx5QpVE8awcaNW9jCHd2sM7etTgHej9neCP4bRBx9cK.RnvVoQkovy7tntkTqif1T7Trz.0x0000b.fashionspeedy.com
Command:/tmp/CONSTANT_STRATEGY.elf
PID:6253
Exit Code:
Exit Code Info:
Killed:True
Standard Output:

Standard Error:2024/12/19 23:37:54 sliver.go:99: Hello my name is CONSTANT_STRATEGY
2024/12/19 23:37:54 limits.go:58: Limit checks completed
2024/12/19 23:37:54 sliver.go:116: Running in Beacon mode with ID: e52ab1c6-11c5-423a-8cc8-7001b83d6fef
2024/12/19 23:37:54 beacon.go:102: Starting beacon loop ...
2024/12/19 23:37:54 transports.go:41: Starting c2 url generator () ...
2024/12/19 23:37:54 transports.go:104: Return generator: (chan *url.URL)(0xc0001006c0)
2024/12/19 23:37:54 beacon.go:118: Recv from c2 generator ...
2024/12/19 23:37:54 transports.go:92: Yield c2 uri = 'dns://0x0000b.fashionspeedy.com'
2024/12/19 23:37:54 transports.go:92: Yield c2 uri = 'dns://0x0000b.fashionspeedy.com'
2024/12/19 23:37:54 beacon.go:122: Next CC = dns://0x0000b.fashionspeedy.com
2024/12/19 23:37:54 beacon.go:122: Next CC = dns://0x0000b.fashionspeedy.com
2024/12/19 23:37:54 sliver.go:125: Next beacon = &{0xa59f60 0xa5df80 0xa59e20 0xa59ea0 0xa5dfc0 0xa59dc0 dns://0x0000b.fashionspeedy.com }
2024/12/19 23:37:54 transports.go:92: Yield c2 uri = 'dns://0x0000b.fashionspeedy.com'
2024/12/19 23:37:54 dnsclient.go:152: DNS client connecting to '0x0000b.fashionspeedy.com' (timeout: 5s) ...
2024/12/19 23:37:54 dnsclient.go:299: [dns] found resolvers: [127.0.0.53]
2024/12/19 23:37:54 crypto.go:227: TOTP Code: 16320111
2024/12/19 23:37:54 dnsclient.go:724: [dns] Fetching dns session id via 'baakbvw6w8c8.0x0000b.fashionspeedy.com.' ...
2024/12/19 23:37:54 resolver-generic.go:92: [dns] 127.0.0.53:53->A record of baakbvw6w8c8.0x0000b.fashionspeedy.com. ?
2024/12/19 23:37:54 resolver-generic.go:175: [dns] rtt->127.0.0.53:53 517.691388ms (err: <nil>)
2024/12/19 23:37:54 resolver-generic.go:109: [dns] answer (a): 149.204.54.100
2024/12/19 23:37:54 dnsclient.go:745: [dns] dns session id: 3591317
2024/12/19 23:37:54 dnsclient.go:307: [dns] dns session id 3591317
2024/12/19 23:37:54 dnsclient.go:311: [dns] fingerprinting resolvers ...
2024/12/19 23:37:54 dnsclient.go:841: [dns] Fingerprinting 1 resolver(s) ...
2024/12/19 23:37:54 resolver-generic.go:92: [dns] 127.0.0.53:53->A record of 115tmprb34212ahuq9t3ttp2.0x0000b.fashionspeedy.com. ?
2024/12/19 23:37:54 resolver-generic.go:175: [dns] rtt->127.0.0.53:53 342.36195ms (err: <nil>)
2024/12/19 23:37:54 resolver-generic.go:109: [dns] answer (a): 94.75.140.75
2024/12/19 23:37:54 resolver-generic.go:92: [dns] 127.0.0.53:53->A record of 115tmprb342e2k52e2rgb1ba.0x0000b.fashionspeedy.com. ?
2024/12/19 23:37:55 resolver-generic.go:175: [dns] rtt->127.0.0.53:53 339.919524ms (err: <nil>)
2024/12/19 23:37:55 resolver-generic.go:109: [dns] answer (a): 213.124.170.103
2024/12/19 23:37:55 resolver-generic.go:92: [dns] 127.0.0.53:53->A record of 115tmprb3423ag0p028dm45r.0x0000b.fashionspeedy.com. ?
2024/12/19 23:37:55 resolver-generic.go:175: [dns] rtt->127.0.0.53:53 340.759747ms (err: <nil>)
2024/12/19 23:37:55 resolver-generic.go:109: [dns] answer (a): 60.89.183.130
2024/12/19 23:37:55 resolver-generic.go:92: [dns] 127.0.0.53:53->A record of 115tmprb342178wxd5vkv1vb.0x0000b.fashionspeedy.com. ?
2024/12/19 23:37:56 resolver-generic.go:175: [dns] rtt->127.0.0.53:53 341.523892ms (err: <nil>)
2024/12/19 23:37:56 resolver-generic.go:109: [dns] answer (a): 140.118.21.128
2024/12/19 23:37:56 resolver-generic.go:92: [dns] 127.0.0.53:53->A record of TupyuUtoigqF7iixMmz8.0x0000b.fashionspeedy.com. ?
2024/12/19 23:37:56 resolver-generic.go:175: [dns] rtt->127.0.0.53:53 339.435903ms (err: <nil>)
2024/12/19 23:37:56 resolver-generic.go:109: [dns] answer (a): 174.67.41.211
2024/12/19 23:37:56 resolver-generic.go:92: [dns] 127.0.0.53:53->A record of TupyuUtoi4hZpunhyTWd.0x0000b.fashionspeedy.com. ?
2024/12/19 23:37:56 resolver-generic.go:175: [dns] rtt->127.0.0.53:53 340.717615ms (err: <nil>)
2024/12/19 23:37:56 resolver-generic.go:109: [dns] answer (a): 23.246.61.199
2024/12/19 23:37:56 resolver-generic.go:92: [dns] 127.0.0.53:53->A record of TupyuUtohxAeqYUtAfPs.0x0000b.fashionspeedy.com. ?
2024/12/19 23:37:57 resolver-generic.go:175: [dns] rtt->127.0.0.53:53 338.864673ms (err: <nil>)
2024/12/19 23:37:57 resolver-generic.go:109: [dns] answer (a): 136.242.140.131
2024/12/19 23:37:57 resolver-generic.go:92: [dns] 127.0.0.53:53->A record of TupyuUtohiWxzTiWZHH8.0x0000b.fashionspeedy.com. ?
2024/12/19 23:37:57 resolver-generic.go:175: [dns] rtt->127.0.0.53:53 339.145819ms (err: <nil>)
2024/12/19 23:37:57 resolver-generic.go:109: [dns] answer (a): 169.172.33.210
2024/12/19 23:37:57 dnsclient.go:861: [dns] 127.0.0.53:53: avg rtt 340.34114ms, base58: true, errors 0
2024/12/19 23:37:57 dnsclient.go:660: [dns] encoded: 0, subdata space: 222 | stop: 110, len: 264
2024/12/19 23:37:57 dnsclient.go:666: [dns] shave data [0:111] of 264
2024/12/19 23:37:57 dnsclient.go:672: [dns] encoded length is 168 (max: 223)
2024/12/19 23:37:57 dnsclient.go:666: [dns] shave data [0:112] of 264
2024/12/19 23:37:57 dnsclient.go:672: [dns] encoded length is 169 (max: 223)
2024/12/19 23:37:57 dnsclient.go:666: [dns] shave data [0:113] of 264
2024/12/19 23:37:57 dnsclient.go:672: [dns] encoded length is 170 (max: 223)
2024/12/19 23:37:57 dnsclient.go:666: [dns] shave data [0:114] of 264
2024/12/19 23:37:57 dnsclient.go:672: [dns] encoded length is 172 (max: 223)
2024/12/19 23:37:57 dnsclient.go:666: [dns] shave data [0:115] of 264
2024/12/19 23:37:57 dnsclient.go:672: [dns] encoded length is 173 (max: 223)
2024/12/19 23:37:57 dnsclient.go:666: [dns] shave data [0:116] of 264
2024/12/19 23:37:57 dnsclient.go:672: [dns] encoded length is 174 (max: 223)
2024/12/19 23:37:57 dnsclient.go:666: [dns] shave data [0:117] of 264
2024/12/19 23:37:57 dnsclient.go:672: [dns] encoded length is 176 (max: 223)
2024/12/19 23:37:57 dnsclient.go:666: [dns] shave data [0:118] of 264
2024/12/19 23:37:57 dnsclient.go:672: [dns] encoded length is 177 (max: 223)
2024/12/19 23:37:57 dnsclient.go:666: [dns] shave data [0:119] of 264
2024/12/19 23:37:57 dnsclient.go:672: [dns] encoded length is 179 (max: 223)
2024/12/19 23:37:57 dnsclient.go:666: [dns] shave data [0:120] of 264
2024/12/19 23:37:57 dnsclient.go:672: [dns] encoded length is 180 (max: 223)
2024/12/19 23:37:57 dnsclient.go:666: [dns] shave data [0:121] of 264
2024/12/19 23:37:57 dnsclient.go:672: [dns] encoded length is 181 (max: 223)
2024/12/19 23:37:57 dnsclient.go:666: [dns] shave data [0:122] of 264
2024/12/19 23:37:57 dnsclient.go:672: [dns] encoded length is 183 (max: 223)
2024/12/19 23:37:57 dnsclient.go:666: [dns] shave data [0:123] of 264
2024/12/19 23:37:57 dnsclient.go:672: [dns] encoded length is 184 (max: 223)
2024/12/19 23:37:57 dnsclient.go:666: [dns] shave data [0:124] of 264
2024/12/19 23:37:57 dnsclient.go:672: [dns] encoded length is 185 (max: 223)
2024/12/19 23:37:57 dnsclient.go:666: [dns] shave data [0:125] of 264
2024/12/19 23:37:57 dnsclient.go:672: [dns] encoded length is 187 (max: 223)
2024/12/19 23:37:57 dnsclient.go:666: [dns] shave data [0:126] of 264
2024/12/19 23:37:57 dnsclient.go:672: [dns] encoded length is 188 (max: 223)
2024/12/19 23:37:57 dnsclient.go:666: [dns] shave data [0:127] of 264
2024/12/19 23:37:57 dnsclient.go:672: [dns] encoded length is 189 (max: 223)
2024/12/19 23:37:57 dnsclient.go:666: [dns] shave data [0:128] of 264
2024/12/19 23:37:57 dnsclient.go:672: [dns] encoded length is 192 (max: 223)
2024/12/19 23:37:57 dnsclient.go:666: [dns] shave data [0:129] of 264
2024/12/19 23:37:57 dnsclient.go:672: [dns] encoded length is 194 (max: 223)
2024/12/19 23:37:57 dnsclient.go:666: [dns] shave data [0:130] of 264
2024/12/19 23:37:57 dnsclient.go:672: [dns] encoded length is 195 (max: 223)
2024/12/19 23:37:57 dnsclient.go:666: [dns] shave data [0:131] of 264
2024/12/19 23:37:57 dnsclient.go:672: [dns] encoded length is 196 (max: 223)
2024/12/19 23:37:57 dnsclient.go:666: [dns] shave data [0:132] of 264
2024/12/19 23:37:57 dnsclient.go:672: [dns] encoded length is 198 (max: 223)
2024/12/19 23:37:57 dnsclient.go:666: [dns] shave data [0:133] of 264
2024/12/19 23:37:57 dnsclient.go:672: [dns] encoded length is 199 (max: 223)
2024/12/19 23:37:57 dnsclient.go:666: [dns] shave data [0:134] of 264
2024/12/19 23:37:57 dnsclient.go:672: [dns] encoded length is 200 (max: 223)
2024/12/19 23:37:57 dnsclient.go:666: [dns] shave data [0:135] of 264
2024/12/19 23:37:57 dnsclient.go:672: [dns] encoded length is 202 (max: 223)
2024/12/19 23:37:57 dnsclient.go:666: [dns] shave data [0:136] of 264
2024/12/19 23:37:57 dnsclient.go:672: [dns] encoded length is 203 (max: 223)
2024/12/19 23:37:57 dnsclient.go:666: [dns] shave data [0:137] of 264
2024/12/19 23:37:57 dnsclient.go:672: [dns] encoded length is 204 (max: 223)
2024/12/19 23:37:57 dnsclient.go:666: [dns] shave data [0:138] of 264
2024/12/19 23:37:57 dnsclient.go:672: [dns] encoded length is 206 (max: 223)
2024/12/19 23:37:57 dnsclient.go:666: [dns] shave data [0:139] of 264
2024/12/19 23:37:57 dnsclient.go:672: [dns] encoded length is 207 (max: 223)
2024/12/19 23:37:57 dnsclient.go:666: [dns] shave data [0:140] of 264
2024/12/19 23:37:57 dnsclient.go:672: [dns] encoded length is 209 (max: 223)
2024/12/19 23:37:57 dnsclient.go:666: [dns] shave data [0:141] of 264
2024/12/19 23:37:57 dnsclient.go:672: [dns] encoded length is 210 (max: 223)
2024/12/19 23:37:57 dnsclient.go:666: [dns] shave data [0:142] of 264
2024/12/19 23:37:57 dnsclient.go:672: [dns] encoded length is 211 (max: 223)
2024/12/19 23:37:57 dnsclient.go:666: [dns] shave data [0:143] of 264
2024/12/19 23:37:57 dnsclient.go:672: [dns] encoded length is 213 (max: 223)
2024/12/19 23:37:57 dnsclient.go:666: [dns] shave data [0:144] of 264
2024/12/19 23:37:57 dnsclient.go:672: [dns] encoded length is 214 (max: 223)
2024/12/19 23:37:57 dnsclient.go:666: [dns] shave data [0:145] of 264
2024/12/19 23:37:57 dnsclient.go:672: [dns] encoded length is 215 (max: 223)
2024/12/19 23:37:57 dnsclient.go:666: [dns] shave data [0:146] of 264
2024/12/19 23:37:57 dnsclient.go:672: [dns] encoded length is 217 (max: 223)
2024/12/19 23:37:57 dnsclient.go:666: [dns] shave data [0:147] of 264
2024/12/19 23:37:57 dnsclient.go:672: [dns] encoded length is 218 (max: 223)
2024/12/19 23:37:57 dnsclient.go:666: [dns] shave data [0:148] of 264
2024/12/19 23:37:57 dnsclient.go:672: [dns] encoded length is 220 (max: 223)
2024/12/19 23:37:57 dnsclient.go:666: [dns] shave data [0:149] of 264
2024/12/19 23:37:57 dnsclient.go:672: [dns] encoded length is 221 (max: 223)
2024/12/19 23:37:57 dnsclient.go:666: [dns] shave data [0:150] of 264
2024/12/19 23:37:57 dnsclient.go:672: [dns] encoded length is 222 (max: 223)
2024/12/19 23:37:57 dnsclient.go:660: [dns] encoded: 0, subdata space: 222 | stop: 263, len: 264
2024/12/19 23:37:57 dnsclient.go:666: [dns] shave data [150:264] of 264
2024/12/19 23:37:57 dnsclient.go:672: [dns] encoded length is 176 (max: 223)
2024/12/19 23:37:57 dnsclient.go:701: [dns] subdata 0 (0->150): 150 bytes
2024/12/19 23:37:57 dnsclient.go:701: [dns] subdata 1 (150->264): 114 bytes
2024/12/19 23:37:57 dnsclient.go:704: [dns] original data: 264 bytes
2024/12/19 23:37:57 dnsclient.go:705: [dns] total subdata: 264 bytes
2024/12/19 23:37:58 resolver-generic.go:175: [dns] rtt->127.0.0.53:53 532.169273ms (err: <nil>)
2024/12/19 23:37:58 resolver-generic.go:152: [dns] answer (txt): []
2024/12/19 23:37:58 resolver-generic.go:175: [dns] rtt->127.0.0.53:53 544.373533ms (err: <nil>)
2024/12/19 23:37:58 resolver-generic.go:152: [dns] answer (txt): [ZETcwIBCh2W8tR0NULSaCmmU0FIxXSjl+iY4tdP9+VwB6_LuoUTdEMtWK1bfuSHF57atVhfU7n1pisxX]
2024/12/19 23:37:58 dnsclient.go:366: [dns] key exchange was successful!
2024/12/19 23:37:58 dnsclient.go:370: [dns] starting worker(s) ...
2024/12/19 23:37:58 sliver.go:178: Registering beacon with server
2024/12/19 23:37:58 beacon.go:86: Interval: 5000000000 Jitter: 0
2024/12/19 23:37:58 dnsclient.go:239: [dns] starting worker #0
2024/12/19 23:37:58 beacon.go:94: Duration: 5s
2024/12/19 23:37:58 dnsclient.go:239: [dns] starting worker #0
2024/12/19 23:37:58 sliver.go:586: Host Uuid: ee49dfd4-fa47-433b-aee8-8884e2d7de7c
2024/12/19 23:37:58 beacon.go:86: Interval: 5000000000 Jitter: 0
2024/12/19 23:37:58 beacon.go:94: Duration: 5s
2024/12/19 23:37:58 dnsclient.go:419: [dns] write envelope ...
2024/12/19 23:37:58 dnsclient.go:660: [dns] encoded: 0, subdata space: 222 | stop: 110, len: 339
2024/12/19 23:37:58 dnsclient.go:666: [dns] shave data [0:111] of 339
2024/12/19 23:37:58 dnsclient.go:672: [dns] encoded length is 168 (max: 223)
2024/12/19 23:37:58 dnsclient.go:666: [dns] shave data [0:112] of 339
2024/12/19 23:37:58 dnsclient.go:672: [dns] encoded length is 169 (max: 223)
2024/12/19 23:37:58 dnsclient.go:666: [dns] shave data [0:113] of 339
2024/12/19 23:37:58 dnsclient.go:672: [dns] encoded length is 170 (max: 223)
2024/12/19 23:37:58 dnsclient.go:666: [dns] shave data [0:114] of 339
2024/12/19 23:37:58 dnsclient.go:672: [dns] encoded length is 172 (max: 223)
2024/12/19 23:37:58 dnsclient.go:666: [dns] shave data [0:115] of 339
2024/12/19 23:37:58 dnsclient.go:672: [dns] encoded length is 173 (max: 223)
2024/12/19 23:37:58 dnsclient.go:666: [dns] shave data [0:116] of 339
2024/12/19 23:37:58 dnsclient.go:672: [dns] encoded length is 174 (max: 223)
2024/12/19 23:37:58 dnsclient.go:666: [dns] shave data [0:117] of 339
2024/12/19 23:37:58 dnsclient.go:672: [dns] encoded length is 176 (max: 223)
2024/12/19 23:37:58 dnsclient.go:666: [dns] shave data [0:118] of 339
2024/12/19 23:37:58 dnsclient.go:672: [dns] encoded length is 177 (max: 223)
2024/12/19 23:37:58 dnsclient.go:666: [dns] shave data [0:119] of 339
2024/12/19 23:37:58 dnsclient.go:672: [dns] encoded length is 179 (max: 223)
2024/12/19 23:37:58 dnsclient.go:666: [dns] shave data [0:120] of 339
2024/12/19 23:37:58 dnsclient.go:672: [dns] encoded length is 180 (max: 223)
2024/12/19 23:37:58 dnsclient.go:666: [dns] shave data [0:121] of 339
2024/12/19 23:37:58 dnsclient.go:672: [dns] encoded length is 181 (max: 223)
2024/12/19 23:37:58 dnsclient.go:666: [dns] shave data [0:122] of 339
2024/12/19 23:37:58 dnsclient.go:672: [dns] encoded length is 183 (max: 223)
2024/12/19 23:37:58 dnsclient.go:666: [dns] shave data [0:123] of 339
2024/12/19 23:37:58 dnsclient.go:672: [dns] encoded length is 184 (max: 223)
2024/12/19 23:37:58 dnsclient.go:666: [dns] shave data [0:124] of 339
2024/12/19 23:37:58 dnsclient.go:672: [dns] encoded length is 185 (max: 223)
2024/12/19 23:37:58 dnsclient.go:666: [dns] shave data [0:125] of 339
2024/12/19 23:37:58 dnsclient.go:672: [dns] encoded length is 187 (max: 223)
2024/12/19 23:37:58 dnsclient.go:666: [dns] shave data [0:126] of 339
2024/12/19 23:37:58 dnsclient.go:672: [dns] encoded length is 188 (max: 223)
2024/12/19 23:37:58 dnsclient.go:666: [dns] shave data [0:127] of 339
2024/12/19 23:37:58 dnsclient.go:672: [dns] encoded length is 189 (max: 223)
2024/12/19 23:37:58 dnsclient.go:666: [dns] shave data [0:128] of 339
2024/12/19 23:37:58 dnsclient.go:672: [dns] encoded length is 192 (max: 223)
2024/12/19 23:37:58 dnsclient.go:666: [dns] shave data [0:129] of 339
2024/12/19 23:37:58 dnsclient.go:672: [dns] encoded length is 194 (max: 223)
2024/12/19 23:37:58 dnsclient.go:666: [dns] shave data [0:130] of 339
2024/12/19 23:37:58 dnsclient.go:672: [dns] encoded length is 195 (max: 223)
2024/12/19 23:37:58 dnsclient.go:666: [dns] shave data [0:131] of 339
2024/12/19 23:37:58 dnsclient.go:672: [dns] encoded length is 196 (max: 223)
2024/12/19 23:37:58 dnsclient.go:666: [dns] shave data [0:132] of 339
2024/12/19 23:37:58 dnsclient.go:672: [dns] encoded length is 198 (max: 223)
2024/12/19 23:37:58 dnsclient.go:666: [dns] shave data [0:133] of 339
2024/12/19 23:37:58 dnsclient.go:672: [dns] encoded length is 199 (max: 223)
2024/12/19 23:37:58 dnsclient.go:666: [dns] shave data [0:134] of 339
2024/12/19 23:37:58 dnsclient.go:672: [dns] encoded length is 200 (max: 223)
2024/12/19 23:37:58 dnsclient.go:666: [dns] shave data [0:135] of 339
2024/12/19 23:37:58 dnsclient.go:672: [dns] encoded length is 202 (max: 223)
2024/12/19 23:37:58 dnsclient.go:666: [dns] shave data [0:136] of 339
2024/12/19 23:37:58 dnsclient.go:672: [dns] encoded length is 203 (max: 223)
2024/12/19 23:37:58 dnsclient.go:666: [dns] shave data [0:137] of 339
2024/12/19 23:37:58 dnsclient.go:672: [dns] encoded length is 204 (max: 223)
2024/12/19 23:37:58 dnsclient.go:666: [dns] shave data [0:138] of 339
2024/12/19 23:37:58 dnsclient.go:672: [dns] encoded length is 206 (max: 223)
2024/12/19 23:37:58 dnsclient.go:666: [dns] shave data [0:139] of 339
2024/12/19 23:37:58 dnsclient.go:672: [dns] encoded length is 207 (max: 223)
2024/12/19 23:37:58 dnsclient.go:666: [dns] shave data [0:140] of 339
2024/12/19 23:37:58 dnsclient.go:672: [dns] encoded length is 209 (max: 223)
2024/12/19 23:37:58 dnsclient.go:666: [dns] shave data [0:141] of 339
2024/12/19 23:37:58 dnsclient.go:672: [dns] encoded length is 210 (max: 223)
2024/12/19 23:37:58 dnsclient.go:666: [dns] shave data [0:142] of 339
2024/12/19 23:37:58 dnsclient.go:672: [dns] encoded length is 211 (max: 223)
2024/12/19 23:37:58 dnsclient.go:666: [dns] shave data [0:143] of 339
2024/12/19 23:37:58 dnsclient.go:672: [dns] encoded length is 213 (max: 223)
2024/12/19 23:37:58 dnsclient.go:666: [dns] shave data [0:144] of 339
2024/12/19 23:37:58 dnsclient.go:672: [dns] encoded length is 214 (max: 223)
2024/12/19 23:37:58 dnsclient.go:666: [dns] shave data [0:145] of 339
2024/12/19 23:37:58 dnsclient.go:672: [dns] encoded length is 215 (max: 223)
2024/12/19 23:37:58 dnsclient.go:666: [dns] shave data [0:146] of 339
2024/12/19 23:37:58 dnsclient.go:672: [dns] encoded length is 217 (max: 223)
2024/12/19 23:37:58 dnsclient.go:666: [dns] shave data [0:147] of 339
2024/12/19 23:37:58 dnsclient.go:672: [dns] encoded length is 218 (max: 223)
2024/12/19 23:37:58 dnsclient.go:666: [dns] shave data [0:148] of 339
2024/12/19 23:37:58 dnsclient.go:672: [dns] encoded length is 220 (max: 223)
2024/12/19 23:37:58 dnsclient.go:666: [dns] shave data [0:149] of 339
2024/12/19 23:37:58 dnsclient.go:672: [dns] encoded length is 221 (max: 223)
2024/12/19 23:37:58 dnsclient.go:666: [dns] shave data [0:150] of 339
2024/12/19 23:37:58 dnsclient.go:672: [dns] encoded length is 222 (max: 223)
2024/12/19 23:37:58 dnsclient.go:660: [dns] encoded: 0, subdata space: 222 | stop: 296, len: 339
2024/12/19 23:37:58 dnsclient.go:666: [dns] shave data [150:297] of 339
2024/12/19 23:37:58 dnsclient.go:672: [dns] encoded length is 222 (max: 223)
2024/12/19 23:37:58 dnsclient.go:660: [dns] encoded: 0, subdata space: 222 | stop: 338, len: 339
2024/12/19 23:37:58 dnsclient.go:666: [dns] shave data [297:339] of 339
2024/12/19 23:37:58 dnsclient.go:672: [dns] encoded length is 77 (max: 223)
2024/12/19 23:37:58 dnsclient.go:701: [dns] subdata 0 (0->150): 150 bytes
2024/12/19 23:37:58 dnsclient.go:701: [dns] subdata 1 (150->297): 147 bytes
2024/12/19 23:37:58 dnsclient.go:701: [dns] subdata 2 (297->339): 42 bytes
2024/12/19 23:37:58 dnsclient.go:704: [dns] original data: 339 bytes
2024/12/19 23:37:58 dnsclient.go:705: [dns] total subdata: 339 bytes
2024/12/19 23:37:58 dnsclient.go:254: [dns] #0 work: &{1 Mzd5iuQhLXMwMXiys6YwGwufVZWE7kqUocyr1GnpAPP1G7Tk4xFe7n9r1H3KsSb.Hek1WF4o5PVHvhnye4etXGq8AdftECSx2ECjT9HUjHoX49AB2w2Xmd3JcEmnLbm.7yQD16mGRM5xUhFppydAjuvDYX6C6v3JrZwZT7a3c1iikpGgiA7TNbxTbZUYAKK.b1fzTin2pAK36Anv8Bmy6F3jv74xhFi6A.0x0000b.fashionspeedy.com. 0xc00003ca30 <nil>}
2024/12/19 23:37:58 resolver-generic.go:92: [dns] 127.0.0.53:53->A record of Mzd5iuQhLXMwMXiys6YwGwufVZWE7kqUocyr1GnpAPP1G7Tk4xFe7n9r1H3KsSb.Hek1WF4o5PVHvhnye4etXGq8AdftECSx2ECjT9HUjHoX49AB2w2Xmd3JcEmnLbm.7yQD16mGRM5xUhFppydAjuvDYX6C6v3JrZwZT7a3c1iikpGgiA7TNbxTbZUYAKK.b1fzTin2pAK36Anv8Bmy6F3jv74xhFi6A.0x0000b.fashionspeedy.com. ?
2024/12/19 23:37:58 dnsclient.go:254: [dns] #0 work: &{1 Mzd5iuQhLSzB5UWsS6NnrcprNDFArRJyq3opNgbTWfm5sDYznUkcyywDZxAsJSj.hJruBCTwjAG3DTKHFBFm9LBpv3vBrSrH6uJJNLevpcuuX8hoUyrqGfm6WDRAGUy.HuW5KfSXGdsmzFNAvF2H9u8vbtixZg1SytbzThn8ESwQbQ6XQfeKJFz553Bd29P.kGc4sJD14bbV8Ap6DCUMJTHLfqoYa3Kyt.0x0000b.fashionspeedy.com. 0xc00003ca30 <nil>}
2024/12/19 23:37:58 resolver-generic.go:92: [dns] 127.0.0.53:53->A record of Mzd5iuQhLSzB5UWsS6NnrcprNDFArRJyq3opNgbTWfm5sDYznUkcyywDZxAsJSj.hJruBCTwjAG3DTKHFBFm9LBpv3vBrSrH6uJJNLevpcuuX8hoUyrqGfm6WDRAGUy.HuW5KfSXGdsmzFNAvF2H9u8vbtixZg1SytbzThn8ESwQbQ6XQfeKJFz553Bd29P.kGc4sJD14bbV8Ap6DCUMJTHLfqoYa3Kyt.0x0000b.fashionspeedy.com. ?
2024/12/19 23:37:59 resolver-generic.go:175: [dns] rtt->127.0.0.53:53 537.376511ms (err: <nil>)
2024/12/19 23:37:59 resolver-generic.go:109: [dns] answer (a): 151.207.180.104
2024/12/19 23:37:59 dnsclient.go:254: [dns] #0 work: &{1 xGW32EahCCdzEaHCDqi5Lc8g8z3GW8m5pZw3XNVbfpmgKqVfghmXc2i2eHcPXkf.cwLb2aaDGo3TdB.0x0000b.fashionspeedy.com. 0xc00003ca30 <nil>}
2024/12/19 23:37:59 resolver-generic.go:92: [dns] 127.0.0.53:53->A record of xGW32EahCCdzEaHCDqi5Lc8g8z3GW8m5pZw3XNVbfpmgKqVfghmXc2i2eHcPXkf.cwLb2aaDGo3TdB.0x0000b.fashionspeedy.com. ?
2024/12/19 23:37:59 resolver-generic.go:175: [dns] rtt->127.0.0.53:53 545.926789ms (err: <nil>)
2024/12/19 23:37:59 resolver-generic.go:109: [dns] answer (a): 189.139.47.107
2024/12/19 23:38:00 resolver-generic.go:175: [dns] rtt->127.0.0.53:53 547.228474ms (err: <nil>)
2024/12/19 23:38:00 resolver-generic.go:109: [dns] answer (a): 188.42.251.108
2024/12/19 23:38:01 beacon.go:86: Interval: 5000000000 Jitter: 0
2024/12/19 23:38:01 beacon.go:94: Duration: 5s
2024/12/19 23:38:01 sliver.go:219: [beacon] sleep until 2024-12-19 23:38:06.061259998 -0600 CST m=+12.048832603
2024/12/19 23:38:01 sliver.go:248: [beacon] sending check in ...
2024/12/19 23:38:01 beacon.go:86: Interval: 5000000000 Jitter: 0
2024/12/19 23:38:01 beacon.go:94: Duration: 5s
2024/12/19 23:38:01 dnsclient.go:419: [dns] write envelope ...
2024/12/19 23:38:01 dnsclient.go:660: [dns] encoded: 0, subdata space: 222 | stop: 99, len: 100
2024/12/19 23:38:01 dnsclient.go:666: [dns] shave data [0:100] of 100
2024/12/19 23:38:01 dnsclient.go:672: [dns] encoded length is 151 (max: 223)
2024/12/19 23:38:01 dnsclient.go:701: [dns] subdata 0 (0->100): 100 bytes
2024/12/19 23:38:01 dnsclient.go:704: [dns] original data: 100 bytes
2024/12/19 23:38:01 dnsclient.go:705: [dns] total subdata: 100 bytes
2024/12/19 23:38:01 dnsclient.go:254: [dns] #0 work: &{1 LpgEQkkyLpxogXsGx7uaT1fna3kwAwzPo844n7vckpmjMtQee8wpJ6pYvbCtejf.spVmVAwmPfKuhz5dpgrMmWLmjVFMY72UkdGj2ETKgSxnbti5LDCvww3wzjWciup.8oN7dDQtYH63EVjsSCGuoJAga.0x0000b.fashionspeedy.com. 0xc00003cc90 <nil>}
2024/12/19 23:38:01 resolver-generic.go:92: [dns] 127.0.0.53:53->A record of LpgEQkkyLpxogXsGx7uaT1fna3kwAwzPo844n7vckpmjMtQee8wpJ6pYvbCtejf.spVmVAwmPfKuhz5dpgrMmWLmjVFMY72UkdGj2ETKgSxnbti5LDCvww3wzjWciup.8oN7dDQtYH63EVjsSCGuoJAga.0x0000b.fashionspeedy.com. ?
2024/12/19 23:38:01 resolver-generic.go:175: [dns] rtt->127.0.0.53:53 538.23565ms (err: <nil>)
2024/12/19 23:38:01 resolver-generic.go:109: [dns] answer (a): 113.123.132.238
2024/12/19 23:38:01 sliver.go:261: [beacon] recv task(s) ...
2024/12/19 23:38:01 dnsclient.go:439: [dns] read envelope ...
2024/12/19 23:38:01 dnsclient.go:452: [dns] poll msg domain: 6NguVjUtpxjZqrhSF1ooGr6.0x0000b.fashionspeedy.com.
2024/12/19 23:38:02 resolver-generic.go:175: [dns] rtt->127.0.0.53:53 348.748488ms (err: <nil>)
2024/12/19 23:38:02 resolver-generic.go:152: [dns] answer (txt): [ba-nDuFwbp1U]
2024/12/19 23:38:02 dnsclient.go:459: [dns] read msg resp data: [8 6 16 149 153 219 9 40 58]
2024/12/19 23:38:02 dnsclient.go:549: [dns] parallel read (20368533): 0 -> 58 of 58
2024/12/19 23:38:02 dnsclient.go:573: [dns] collecting read results ...
2024/12/19 23:38:02 dnsclient.go:610: [dns] waiting for workers ...
2024/12/19 23:38:02 dnsclient.go:254: [dns] #0 work: &{16 backbd6tv629a78.0x0000b.fashionspeedy.com. 0xc00003cda0 0xc0002ee4e0}
2024/12/19 23:38:02 resolver-generic.go:175: [dns] rtt->127.0.0.53:53 593.932007ms (err: <nil>)
2024/12/19 23:38:02 resolver-generic.go:152: [dns] answer (txt): [jCHtZF3oGn1A33ok2Afb+fcKeWezurY+i03_HzPS6DKfZ0xOB-ehdbZfqQLplO5sRCxrERy3A2hr4IcP]
2024/12/19 23:38:02 dnsclient.go:615: [dns] workers completed, close results channel ...
2024/12/19 23:38:02 dnsclient.go:627: [dns] collecting recvData ...
2024/12/19 23:38:02 dnsclient.go:586: [dns] read result data: [50 58 87 254 120 145 161 8 31 138 36 77 13 242 2 228 129 44 31 193 222 101 79 185 44 24 149 165 236 247 38 91 8 252 23 49 133 129 202 24 47 200 79 75 82 59 17 86 214 55 20 155 87 98 124 50 148 146 161 51]
2024/12/19 23:38:02 dnsclient.go:595: [dns] recv msg: Data:"W\xfex\x91\xa1\x08\x1f\x8a$M\r\xf2\x02\xe4\x81,\x1f\xc1\xdeeO\xb9,\x18\x95\xa5\xec\xf7&[\x08\xfc\x171\x85\x81\xca\x18/\xc8OKR;\x11V\xd67\x14\x9bWb|2\x94\x92\xa13"
2024/12/19 23:38:02 dnsclient.go:604: [dns] all data collected: [87 254 120 145 161 8 31 138 36 77 13 242 2 228 129 44 31 193 222 101 79 185 44 24 149 165 236 247 38 91 8 252 23 49 133 129 202 24 47 200 79 75 82 59 17 86 214 55 20 155 87 98 124 50 148 146 161 51]
2024/12/19 23:38:02 sliver.go:286: [beacon] received 0 task(s) from server
2024/12/19 23:38:02 sliver.go:242: [beacon] closing ...
2024/12/19 23:38:06 beacon.go:86: Interval: 5000000000 Jitter: 0
2024/12/19 23:38:06 beacon.go:94: Duration: 5s
2024/12/19 23:38:06 sliver.go:219: [beacon] sleep until 2024-12-19 23:38:11.071902477 -0600 CST m=+17.059475113
2024/12/19 23:38:06 sliver.go:248: [beacon] sending check in ...
2024/12/19 23:38:06 beacon.go:86: Interval: 5000000000 Jitter: 0
2024/12/19 23:38:06 beacon.go:94: Duration: 5s
2024/12/19 23:38:06 dnsclient.go:419: [dns] write envelope ...
2024/12/19 23:38:06 dnsclient.go:660: [dns] encoded: 0, subdata space: 222 | stop: 99, len: 100
2024/12/19 23:38:06 dnsclient.go:666: [dns] shave data [0:100] of 100
2024/12/19 23:38:06 dnsclient.go:672: [dns] encoded length is 151 (max: 223)
2024/12/19 23:38:06 dnsclient.go:701: [dns] subdata 0 (0->100): 100 bytes
2024/12/19 23:38:06 dnsclient.go:704: [dns] original data: 100 bytes
2024/12/19 23:38:06 dnsclient.go:705: [dns] total subdata: 100 bytes
2024/12/19 23:38:06 dnsclient.go:254: [dns] #0 work: &{1 LpgEQkkyVooaGYsXFdRadnJuqZQkYssynnifyVmroKb249PLerQ3W27ymdz99Rh.YXUSuEsRE4BpXVxU8dddyEGH4yXkn446H7hXfXLKmbpn7XAfsbhrbqD3mdp18cN.wHztikaoWM9n3VauRigdMw9Ey.0x0000b.fashionspeedy.com. 0xc00003cf40 <nil>}
2024/12/19 23:38:06 resolver-generic.go:92: [dns] 127.0.0.53:53->A record of LpgEQkkyVooaGYsXFdRadnJuqZQkYssynnifyVmroKb249PLerQ3W27ymdz99Rh.YXUSuEsRE4BpXVxU8dddyEGH4yXkn446H7hXfXLKmbpn7XAfsbhrbqD3mdp18cN.wHztikaoWM9n3VauRigdMw9Ey.0x0000b.fashionspeedy.com. ?
2024/12/19 23:38:06 resolver-generic.go:175: [dns] rtt->127.0.0.53:53 546.730908ms (err: <nil>)
2024/12/19 23:38:06 resolver-generic.go:109: [dns] answer (a): 63.44.145.189
2024/12/19 23:38:06 sliver.go:261: [beacon] recv task(s) ...
2024/12/19 23:38:06 dnsclient.go:439: [dns] read envelope ...
2024/12/19 23:38:06 dnsclient.go:452: [dns] poll msg domain: 6NguVjUtpxjAgPtvJ3ssurk.0x0000b.fashionspeedy.com.
2024/12/19 23:38:07 resolver-generic.go:175: [dns] rtt->127.0.0.53:53 340.439195ms (err: <nil>)
2024/12/19 23:38:07 resolver-generic.go:152: [dns] answer (txt): [ba-nDuFwcp1U]
2024/12/19 23:38:07 dnsclient.go:459: [dns] read msg resp data: [8 6 16 149 153 219 17 40 58]
2024/12/19 23:38:07 dnsclient.go:549: [dns] parallel read (37145749): 0 -> 58 of 58
2024/12/19 23:38:07 dnsclient.go:573: [dns] collecting read results ...
2024/12/19 23:38:07 dnsclient.go:610: [dns] waiting for workers ...
2024/12/19 23:38:07 dnsclient.go:254: [dns] #0 work: &{16 backbd6tv649a78.0x0000b.fashionspeedy.com. 0xc00003d050 0xc0002ee960}
2024/12/19 23:38:07 resolver-generic.go:175: [dns] rtt->127.0.0.53:53 345.216728ms (err: <nil>)
2024/12/19 23:38:07 resolver-generic.go:152: [dns] answer (txt): [jCIDqxvaGy+3LtTiAf1e-WHErlP88Ub-F2L7XM8jF45RcTDOj1aqEn6WSUilmkyEHwaQ1Qcc1alGry2e]
2024/12/19 23:38:07 dnsclient.go:615: [dns] workers completed, close results channel ...
2024/12/19 23:38:07 dnsclient.go:627: [dns] collecting recvData ...
2024/12/19 23:38:07 dnsclient.go:586: [dns] read result data: [50 58 165 77 198 128 161 222 98 181 126 11 124 136 7 99 202 102 80 236 246 219 160 152 156 59 111 246 237 140 158 65 117 19 137 113 50 0 19 153 2 124 223 162 206 60 215 102 165 176 52 131 65 4 128 3 168 81 208 199]
2024/12/19 23:38:07 dnsclient.go:595: [dns] recv msg: Data:"\xa5M\xa1\xdeb\xb5~\x0b|\x88\x07c\xcafP\xec\xf6\x98\x9c;o\xf6Au\x13\x89q2\x00\x13\x99\x02|\xce<\xd7f\xa5\xb04\x83A\x04\x80\x03\xa8Q\xd0\xc7"
2024/12/19 23:38:07 dnsclient.go:604: [dns] all data collected: [165 77 198 128 161 222 98 181 126 11 124 136 7 99 202 102 80 236 246 219 160 152 156 59 111 246 237 140 158 65 117 19 137 113 50 0 19 153 2 124 223 162 206 60 215 102 165 176 52 131 65 4 128 3 168 81 208 199]
2024/12/19 23:38:07 sliver.go:286: [beacon] received 0 task(s) from server
2024/12/19 23:38:07 sliver.go:242: [beacon] closing ...
2024/12/19 23:38:11 beacon.go:86: Interval: 5000000000 Jitter: 0
2024/12/19 23:38:11 beacon.go:94: Duration: 5s
2024/12/19 23:38:11 sliver.go:219: [beacon] sleep until 2024-12-19 23:38:16.083702761 -0600 CST m=+22.071275386
2024/12/19 23:38:11 sliver.go:248: [beacon] sending check in ...
2024/12/19 23:38:11 beacon.go:86: Interval: 5000000000 Jitter: 0
2024/12/19 23:38:11 beacon.go:94: Duration: 5s
2024/12/19 23:38:11 dnsclient.go:419: [dns] write envelope ...
2024/12/19 23:38:11 dnsclient.go:660: [dns] encoded: 0, subdata space: 222 | stop: 99, len: 100
2024/12/19 23:38:11 dnsclient.go:666: [dns] shave data [0:100] of 100
2024/12/19 23:38:11 dnsclient.go:672: [dns] encoded length is 151 (max: 223)
2024/12/19 23:38:11 dnsclient.go:701: [dns] subdata 0 (0->100): 100 bytes
2024/12/19 23:38:11 dnsclient.go:704: [dns] original data: 100 bytes
2024/12/19 23:38:11 dnsclient.go:705: [dns] total subdata: 100 bytes
2024/12/19 23:38:11 dnsclient.go:254: [dns] #0 work: &{1 LpgEQkkyEndY5ZimNJk211z3bwffTiWSkFT84VgLFwJGviHPYYgZQitY5HXBRi9.HaVQNzYSUTEyYUozY9uNKQTyjr6oSHAsiF5EQ7rCLNQ1M4ZYATjUv2KzvxKAG9j.CSgvkx37BS6WPho5W6GefGMPQ.0x0000b.fashionspeedy.com. 0xc00003d200 <nil>}
2024/12/19 23:38:11 resolver-generic.go:92: [dns] 127.0.0.53:53->A record of LpgEQkkyEndY5ZimNJk211z3bwffTiWSkFT84VgLFwJGviHPYYgZQitY5HXBRi9.HaVQNzYSUTEyYUozY9uNKQTyjr6oSHAsiF5EQ7rCLNQ1M4ZYATjUv2KzvxKAG9j.CSgvkx37BS6WPho5W6GefGMPQ.0x0000b.fashionspeedy.com. ?
2024/12/19 23:38:11 resolver-generic.go:175: [dns] rtt->127.0.0.53:53 542.141424ms (err: <nil>)
2024/12/19 23:38:11 resolver-generic.go:109: [dns] answer (a): 81.64.129.31
2024/12/19 23:38:11 sliver.go:261: [beacon] recv task(s) ...
2024/12/19 23:38:11 dnsclient.go:439: [dns] read envelope ...
2024/12/19 23:38:11 dnsclient.go:452: [dns] poll msg domain: 6NguVjUtpxjZqSFWf7X8YAJ.0x0000b.fashionspeedy.com.
2024/12/19 23:38:12 resolver-generic.go:175: [dns] rtt->127.0.0.53:53 345.769524ms (err: <nil>)
2024/12/19 23:38:12 resolver-generic.go:152: [dns] answer (txt): [ba-nDuFwdp1U]
2024/12/19 23:38:12 dnsclient.go:459: [dns] read msg resp data: [8 6 16 149 153 219 25 40 58]
2024/12/19 23:38:12 dnsclient.go:549: [dns] parallel read (53922965): 0 -> 58 of 58
2024/12/19 23:38:12 dnsclient.go:573: [dns] collecting read results ...
2024/12/19 23:38:12 dnsclient.go:610: [dns] waiting for workers ...
2024/12/19 23:38:12 dnsclient.go:254: [dns] #0 work: &{16 backbd6tv669a78.0x0000b.fashionspeedy.com. 0xc00003d310 0xc0002eed80}
2024/12/19 23:38:12 resolver-generic.go:175: [dns] rtt->127.0.0.53:53 342.932344ms (err: <nil>)
2024/12/19 23:38:12 resolver-generic.go:152: [dns] answer (txt): [jCIX76K_V4z-UC40Un-Hp3q5Hhm7b9KLdAx09HF6M7s6KXtBySzp80OYD7wV5vvG-IJJFSLiRo-PW3oT]
2024/12/19 23:38:12 dnsclient.go:615: [dns] workers completed, close results channel ...
2024/12/19 23:38:12 dnsclient.go:627: [dns] collecting recvData ...
2024/12/19 23:38:12 dnsclient.go:586: [dns] read result data: [50 58 189 188 155 21 238 71 152 234 57 1 233 6 41 74 36 197 164 163 239 11 43 45 25 247 1 202 153 201 186 245 137 179 213 225 119 119 146 216 28 126 150 246 251 21 166 168 98 170 235 159 123 75 213 22 51 242 36 120]
2024/12/19 23:38:12 dnsclient.go:595: [dns] recv msg: Data:"\xbd\xbc\x9b\x15\xeeG\x98\xea9\x01\xe9\x06)J$\xa3\xef\x0b+-\x19\xf7\x01\xf5\x89\xb3\xd5\xe1ww\x92\xd8\x1c~\x96\xf6\xfb\x15\xa6\xa8b\xaa\xeb\x9f{K\xd5\x163\xf2$x"
2024/12/19 23:38:12 dnsclient.go:604: [dns] all data collected: [189 188 155 21 238 71 152 234 57 1 233 6 41 74 36 197 164 163 239 11 43 45 25 247 1 202 153 201 186 245 137 179 213 225 119 119 146 216 28 126 150 246 251 21 166 168 98 170 235 159 123 75 213 22 51 242 36 120]
2024/12/19 23:38:12 sliver.go:286: [beacon] received 0 task(s) from server
2024/12/19 23:38:12 sliver.go:242: [beacon] closing ...
2024/12/19 23:38:16 beacon.go:86: Interval: 5000000000 Jitter: 0
2024/12/19 23:38:16 beacon.go:94: Duration: 5s
2024/12/19 23:38:16 sliver.go:219: [beacon] sleep until 2024-12-19 23:38:21.092808852 -0600 CST m=+27.080381477
2024/12/19 23:38:16 sliver.go:248: [beacon] sending check in ...
2024/12/19 23:38:16 beacon.go:86: Interval: 5000000000 Jitter: 0
2024/12/19 23:38:16 beacon.go:94: Duration: 5s
2024/12/19 23:38:16 dnsclient.go:419: [dns] write envelope ...
2024/12/19 23:38:16 dnsclient.go:660: [dns] encoded: 0, subdata space: 222 | stop: 99, len: 100
2024/12/19 23:38:16 dnsclient.go:666: [dns] shave data [0:100] of 100
2024/12/19 23:38:16 dnsclient.go:672: [dns] encoded length is 151 (max: 223)
2024/12/19 23:38:16 dnsclient.go:701: [dns] subdata 0 (0->100): 100 bytes
2024/12/19 23:38:16 dnsclient.go:704: [dns] original data: 100 bytes
2024/12/19 23:38:16 dnsclient.go:705: [dns] total subdata: 100 bytes
2024/12/19 23:38:16 dnsclient.go:254: [dns] #0 work: &{1 LpgEQkkyomTuWAYb3ghZCHQEkZoEzGBVVLjV9u1B5bGHUrmryVVtvYbQg4GFFaN.fPByvTkMs7DPLZoqBDNoZ4avFTbeGPyfW1byqPgCxyQRQfhwZzZRdYa9kL1DhxE.goYK3nfikf6CjXNZbaFuyQBrj.0x0000b.fashionspeedy.com. 0xc00003c0e0 <nil>}
2024/12/19 23:38:16 resolver-generic.go:92: [dns] 127.0.0.53:53->A record of LpgEQkkyomTuWAYb3ghZCHQEkZoEzGBVVLjV9u1B5bGHUrmryVVtvYbQg4GFFaN.fPByvTkMs7DPLZoqBDNoZ4avFTbeGPyfW1byqPgCxyQRQfhwZzZRdYa9kL1DhxE.goYK3nfikf6CjXNZbaFuyQBrj.0x0000b.fashionspeedy.com. ?
2024/12/19 23:38:16 resolver-generic.go:175: [dns] rtt->127.0.0.53:53 549.860686ms (err: <nil>)
2024/12/19 23:38:16 resolver-generic.go:109: [dns] answer (a): 141.84.66.169
2024/12/19 23:38:16 sliver.go:261: [beacon] recv task(s) ...
2024/12/19 23:38:16 dnsclient.go:439: [dns] read envelope ...
2024/12/19 23:38:16 dnsclient.go:452: [dns] poll msg domain: 6NguVjUtpxjAQxc4g9np3yT.0x0000b.fashionspeedy.com.
2024/12/19 23:38:17 resolver-generic.go:175: [dns] rtt->127.0.0.53:53 342.323653ms (err: <nil>)
2024/12/19 23:38:17 resolver-generic.go:152: [dns] answer (txt): [ba-nDuFwfp1U]
2024/12/19 23:38:17 dnsclient.go:459: [dns] read msg resp data: [8 6 16 149 153 219 33 40 58]
2024/12/19 23:38:17 dnsclient.go:549: [dns] parallel read (70700181): 0 -> 58 of 58
2024/12/19 23:38:17 dnsclient.go:573: [dns] collecting read results ...
2024/12/19 23:38:17 dnsclient.go:610: [dns] waiting for workers ...
2024/12/19 23:38:17 dnsclient.go:254: [dns] #0 work: &{16 backbd6tv689a78.0x0000b.fashionspeedy.com. 0xc00003c440 0xc0002ee2a0}
2024/12/19 23:38:17 resolver-generic.go:175: [dns] rtt->127.0.0.53:53 337.58769ms (err: <nil>)
2024/12/19 23:38:17 resolver-generic.go:152: [dns] answer (txt): [jCH7eFdT_XuuVYwtd91WvwDod_VTAOTaB+wb8IK1R3LdkW+uSYOGAITWe8eIM_x4GrzA72h-TifYmEoK]
2024/12/19 23:38:17 dnsclient.go:615: [dns] workers completed, close results channel ...
2024/12/19 23:38:17 dnsclient.go:627: [dns] collecting recvData ...
2024/12/19 23:38:17 dnsclient.go:586: [dns] read result data: [50 58 111 30 113 184 87 214 89 239 230 215 27 40 60 105 185 81 25 94 248 127 30 0 135 150 194 218 171 32 214 43 70 55 206 89 223 236 104 126 174 60 31 97 234 185 87 36 161 71 159 188 50 152 224 178 62 62 100 108]
2024/12/19 23:38:17 dnsclient.go:595: [dns] recv msg: Data:"o\x1eq\xb8W\xd6Y\xef\xe6\xd7\x1b(<i\xb9Q\x19^\xf8\x7f\x1e\x00\x87\x96\xc2 \xd6+F7\xceY\xdf\xech~\xae<\x1fa\xea\xb9W$\xa1G\x9f\xbc2\x98\xe0\xb2>>dl"
2024/12/19 23:38:17 dnsclient.go:604: [dns] all data collected: [111 30 113 184 87 214 89 239 230 215 27 40 60 105 185 81 25 94 248 127 30 0 135 150 194 218 171 32 214 43 70 55 206 89 223 236 104 126 174 60 31 97 234 185 87 36 161 71 159 188 50 152 224 178 62 62 100 108]
2024/12/19 23:38:17 sliver.go:286: [beacon] received 0 task(s) from server
2024/12/19 23:38:17 sliver.go:242: [beacon] closing ...
2024/12/19 23:38:21 beacon.go:86: Interval: 5000000000 Jitter: 0
2024/12/19 23:38:21 beacon.go:94: Duration: 5s
2024/12/19 23:38:21 sliver.go:219: [beacon] sleep until 2024-12-19 23:38:26.099867053 -0600 CST m=+32.087439660
2024/12/19 23:38:21 sliver.go:248: [beacon] sending check in ...
2024/12/19 23:38:21 beacon.go:86: Interval: 5000000000 Jitter: 0
2024/12/19 23:38:21 beacon.go:94: Duration: 5s
2024/12/19 23:38:21 dnsclient.go:419: [dns] write envelope ...
2024/12/19 23:38:21 dnsclient.go:660: [dns] encoded: 0, subdata space: 222 | stop: 99, len: 100
2024/12/19 23:38:21 dnsclient.go:666: [dns] shave data [0:100] of 100
2024/12/19 23:38:21 dnsclient.go:672: [dns] encoded length is 151 (max: 223)
2024/12/19 23:38:21 dnsclient.go:701: [dns] subdata 0 (0->100): 100 bytes
2024/12/19 23:38:21 dnsclient.go:704: [dns] original data: 100 bytes
2024/12/19 23:38:21 dnsclient.go:705: [dns] total subdata: 100 bytes
2024/12/19 23:38:21 dnsclient.go:254: [dns] #0 work: &{1 LpgEQkkyxkjgvbLBCkkTxFq8kLQbBJp54js4aWdBfWiSPmMjNCRHmPpYsfgi7p1.7QVC7SwnPabjdrWDFxsPYx5QpVE8awcaNW9jCHd2sM7etTgHej9neCP4bRBx9cK.RnvVoQkovy7tntkTqif1T7Trz.0x0000b.fashionspeedy.com. 0xc00003c5f0 <nil>}
2024/12/19 23:38:21 resolver-generic.go:92: [dns] 127.0.0.53:53->A record of LpgEQkkyxkjgvbLBCkkTxFq8kLQbBJp54js4aWdBfWiSPmMjNCRHmPpYsfgi7p1.7QVC7SwnPabjdrWDFxsPYx5QpVE8awcaNW9jCHd2sM7etTgHej9neCP4bRBx9cK.RnvVoQkovy7tntkTqif1T7Trz.0x0000b.fashionspeedy.com. ?
2024/12/19 23:38:21 resolver-generic.go:175: [dns] rtt->127.0.0.53:53 545.476763ms (err: <nil>)
2024/12/19 23:38:21 resolver-generic.go:109: [dns] answer (a): 9.186.159.28
2024/12/19 23:38:21 sliver.go:261: [beacon] recv task(s) ...
2024/12/19 23:38:21 dnsclient.go:439: [dns] read envelope ...
2024/12/19 23:38:21 dnsclient.go:452: [dns] poll msg domain: 6NguVjUtpxjZmQNcGyhyXSs.0x0000b.fashionspeedy.com.
2024/12/19 23:38:22 resolver-generic.go:175: [dns] rtt->127.0.0.53:53 338.724775ms (err: <nil>)
2024/12/19 23:38:22 resolver-generic.go:152: [dns] answer (txt): [ba-nDuFwhp1U]
2024/12/19 23:38:22 dnsclient.go:459: [dns] read msg resp data: [8 6 16 149 153 219 41 40 58]
2024/12/19 23:38:22 dnsclient.go:549: [dns] parallel read (87477397): 0 -> 58 of 58
2024/12/19 23:38:22 dnsclient.go:573: [dns] collecting read results ...
2024/12/19 23:38:22 dnsclient.go:610: [dns] waiting for workers ...
2024/12/19 23:38:22 dnsclient.go:254: [dns] #0 work: &{16 backbd6tv609a78.0x0000b.fashionspeedy.com. 0xc00003c700 0xc0002ee600}
2024/12/19 23:38:22 resolver-generic.go:175: [dns] rtt->127.0.0.53:53 340.959879ms (err: <nil>)
2024/12/19 23:38:22 resolver-generic.go:152: [dns] answer (txt): [jCJFR4mQ7QE20ofUs9QBc+l2nhxjrCbz0JYtJXv9nCiUhK3bMujZc-O0Gvu7i4MbDzLo+dwFwCk1lqnk]
2024/12/19 23:38:22 dnsclient.go:615: [dns] workers completed, close results channel ...
2024/12/19 23:38:22 dnsclient.go:627: [dns] collecting recvData ...
2024/12/19 23:38:22 dnsclient.go:586: [dns] read result data: [50 58 231 214 67 244 191 73 131 5 18 58 91 45 33 19 147 131 64 167 12 82 48 158 6 191 151 175 214 178 66 50 250 42 200 130 185 147 63 17 140 65 161 166 111 46 75 130 149 235 81 228 102 231 110 51 96 57 52 13]
2024/12/19 23:38:22 dnsclient.go:595: [dns] recv msg: Data:"\xe7\xd6C\xf4\xbfI\x83\x05\x12:[-!\x13\x93\x83@\xa7\x0cR0\x9e\x06\xbf\x97\xafB2\xfa*\xb9\x93?\x11\x8cA\xa1\xa6o.K\x82\x95\xebQ\xe4f\xe7n3`94\r"
2024/12/19 23:38:22 dnsclient.go:604: [dns] all data collected: [231 214 67 244 191 73 131 5 18 58 91 45 33 19 147 131 64 167 12 82 48 158 6 191 151 175 214 178 66 50 250 42 200 130 185 147 63 17 140 65 161 166 111 46 75 130 149 235 81 228 102 231 110 51 96 57 52 13]
2024/12/19 23:38:22 sliver.go:286: [beacon] received 0 task(s) from server
2024/12/19 23:38:22 sliver.go:242: [beacon] closing ...
2024/12/19 23:38:26 beacon.go:86: Interval: 5000000000 Jitter: 0
2024/12/19 23:38:26 beacon.go:94: Duration: 5s
2024/12/19 23:38:26 sliver.go:219: [beacon] sleep until 2024-12-19 23:38:31.110406187 -0600 CST m=+37.097978894
2024/12/19 23:38:26 sliver.go:248: [beacon] sending check in ...
2024/12/19 23:38:26 beacon.go:86: Interval: 5000000000 Jitter: 0
2024/12/19 23:38:26 beacon.go:94: Duration: 5s
2024/12/19 23:38:26 dnsclient.go:419: [dns] write envelope ...
2024/12/19 23:38:26 dnsclient.go:660: [dns] encoded: 0, subdata space: 222 | stop: 99, len: 100
2024/12/19 23:38:26 dnsclient.go:666: [dns] shave data [0:100] of 100
2024/12/19 23:38:26 dnsclient.go:672: [dns] encoded length is 151 (max: 223)
2024/12/19 23:38:26 dnsclient.go:701: [dns] subdata 0 (0->100): 100 bytes
2024/12/19 23:38:26 dnsclient.go:704: [dns] original data: 100 bytes
2024/12/19 23:38:26 dnsclient.go:705: [dns] total subdata: 100 bytes
2024/12/19 23:38:26 dnsclient.go:254: [dns] #0 work: &{1 LpgEQkkz7J8ELCapaniKZoZ2yFZhtSemCFMmFwK7BgoyUQELQQAPDyq9mgXU6fi.Rux3RE2CB3JuefKSU5bpYrY1dg6dvRnCBYDaoEwKHkW1w6dzc6TyvJA5GV4XGus.NUh8RsfJUinSsogxxeXKwSgsA.0x0000b.fashionspeedy.com. 0xc000110550 <nil>}
2024/12/19 23:38:26 resolver-generic.go:92: [dns] 127.0.0.53:53->A record of LpgEQkkz7J8ELCapaniKZoZ2yFZhtSemCFMmFwK7BgoyUQELQQAPDyq9mgXU6fi.Rux3RE2CB3JuefKSU5bpYrY1dg6dvRnCBYDaoEwKHkW1w6dzc6TyvJA5GV4XGus.NUh8RsfJUinSsogxxeXKwSgsA.0x0000b.fashionspeedy.com. ?
2024/12/19 23:38:26 resolver-generic.go:175: [dns] rtt->127.0.0.53:53 534.356434ms (err: <nil>)
2024/12/19 23:38:26 resolver-generic.go:109: [dns] answer (a): 236.100.54.38
2024/12/19 23:38:26 sliver.go:261: [beacon] recv task(s) ...
2024/12/19 23:38:26 dnsclient.go:439: [dns] read envelope ...
2024/12/19 23:38:26 dnsclient.go:452: [dns] poll msg domain: 6NguVjUtpxjA467DrF1aAq5.0x0000b.fashionspeedy.com.
2024/12/19 23:38:27 resolver-generic.go:175: [dns] rtt->127.0.0.53:53 336.311605ms (err: <nil>)
2024/12/19 23:38:27 resolver-generic.go:152: [dns] answer (txt): [ba-nDuFwjp1U]
2024/12/19 23:38:27 dnsclient.go:459: [dns] read msg resp data: [8 6 16 149 153 219 49 40 58]
2024/12/19 23:38:27 dnsclient.go:549: [dns] parallel read (104254613): 0 -> 58 of 58
2024/12/19 23:38:27 dnsclient.go:573: [dns] collecting read results ...
2024/12/19 23:38:27 dnsclient.go:610: [dns] waiting for workers ...
2024/12/19 23:38:27 dnsclient.go:254: [dns] #0 work: &{16 backbd6tv6r9a78.0x0000b.fashionspeedy.com. 0xc000110660 0xc0001289c0}
2024/12/19 23:38:27 resolver-generic.go:175: [dns] rtt->127.0.0.53:53 341.766108ms (err: <nil>)
2024/12/19 23:38:27 resolver-generic.go:152: [dns] answer (txt): [jCG_Hf-iV+dCqpZ52EH693zn_UKWb19cwF3UtDO4n8RNrVz47d-ROj7L4uxnK4FLPny+NQybqytJD-FL]
2024/12/19 23:38:27 dnsclient.go:615: [dns] workers completed, close results channel ...
2024/12/19 23:38:27 dnsclient.go:627: [dns] collecting recvData ...
2024/12/19 23:38:27 dnsclient.go:586: [dns] read result data: [50 58 21 164 134 11 239 145 163 77 47 197 14 106 73 202 39 144 87 171 60 10 12 132 110 120 186 94 92 100 67 109 112 83 183 164 188 102 53 196 203 237 145 151 16 178 73 237 205 7 121 195 71 66 77 213 235 149 137 237]
2024/12/19 23:38:27 dnsclient.go:595: [dns] recv msg: Data:"\x15\xa4\x86\x0bM/\xc5\x0ejI\xca'\x90W\xab<\n\x0c\x84nx\xba^\\dCmpS\xb7\xa4\xbcf5\xc4\xcb\x10\xb2I\xed\xcd\x07y\xc3GBM\xd5\xed"
2024/12/19 23:38:27 dnsclient.go:604: [dns] all data collected: [21 164 134 11 239 145 163 77 47 197 14 106 73 202 39 144 87 171 60 10 12 132 110 120 186 94 92 100 67 109 112 83 183 164 188 102 53 196 203 237 145 151 16 178 73 237 205 7 121 195 71 66 77 213 235 149 137 237]
2024/12/19 23:38:27 sliver.go:286: [beacon] received 0 task(s) from server
2024/12/19 23:38:27 sliver.go:242: [beacon] closing ...
2024/12/19 23:38:31 beacon.go:86: Interval: 5000000000 Jitter: 0
2024/12/19 23:38:31 beacon.go:94: Duration: 5s
2024/12/19 23:38:31 sliver.go:219: [beacon] sleep until 2024-12-19 23:38:36.118483376 -0600 CST m=+42.106055997
2024/12/19 23:38:31 sliver.go:248: [beacon] sending check in ...
2024/12/19 23:38:31 beacon.go:86: Interval: 5000000000 Jitter: 0
2024/12/19 23:38:31 beacon.go:94: Duration: 5s
2024/12/19 23:38:31 dnsclient.go:419: [dns] write envelope ...
2024/12/19 23:38:31 dnsclient.go:660: [dns] encoded: 0, subdata space: 222 | stop: 99, len: 100
2024/12/19 23:38:31 dnsclient.go:666: [dns] shave data [0:100] of 100
2024/12/19 23:38:31 dnsclient.go:672: [dns] encoded length is 151 (max: 223)
2024/12/19 23:38:31 dnsclient.go:701: [dns] subdata 0 (0->100): 100 bytes
2024/12/19 23:38:31 dnsclient.go:704: [dns] original data: 100 bytes
2024/12/19 23:38:31 dnsclient.go:705: [dns] total subdata: 100 bytes
2024/12/19 23:38:31 dnsclient.go:254: [dns] #0 work: &{1 LpgEQkkzghy2kd7MojE5wQvkWzaLPpmGEnZ5UsCsPGvB68ZrHggdy1dCb9yyEdG.VkiS2PnCHaRTTZQbZPAjPfgzHPanFfMmPjE2XPzChTfqkH4QQP87n4K1WSgyyy7.6LCexTfHivZHQzigxLtNkWnA5.0x0000b.fashionspeedy.com. 0xc000110860 <nil>}
2024/12/19 23:38:31 resolver-generic.go:92: [dns] 127.0.0.53:53->A record of LpgEQkkzghy2kd7MojE5wQvkWzaLPpmGEnZ5UsCsPGvB68ZrHggdy1dCb9yyEdG.VkiS2PnCHaRTTZQbZPAjPfgzHPanFfMmPjE2XPzChTfqkH4QQP87n4K1WSgyyy7.6LCexTfHivZHQzigxLtNkWnA5.0x0000b.fashionspeedy.com. ?
2024/12/19 23:38:31 resolver-generic.go:175: [dns] rtt->127.0.0.53:53 544.203267ms (err: <nil>)
2024/12/19 23:38:31 resolver-generic.go:109: [dns] answer (a): 16.45.183.202
2024/12/19 23:38:31 sliver.go:261: [beacon] recv task(s) ...
2024/12/19 23:38:31 dnsclient.go:439: [dns] read envelope ...
2024/12/19 23:38:31 dnsclient.go:452: [dns] poll msg domain: 6NguVjUtpxjAMRhGquqNTTi.0x0000b.fashionspeedy.com.
2024/12/19 23:38:32 resolver-generic.go:175: [dns] rtt->127.0.0.53:53 346.418242ms (err: <nil>)
2024/12/19 23:38:32 resolver-generic.go:152: [dns] answer (txt): [ba-nDuFwlp1U]
2024/12/19 23:38:32 dnsclient.go:459: [dns] read msg resp data: [8 6 16 149 153 219 57 40 58]
2024/12/19 23:38:32 dnsclient.go:549: [dns] parallel read (121031829): 0 -> 58 of 58
2024/12/19 23:38:32 dnsclient.go:573: [dns] collecting read results ...
2024/12/19 23:38:32 dnsclient.go:610: [dns] waiting for workers ...
2024/12/19 23:38:32 dnsclient.go:254: [dns] #0 work: &{16 backbd6tv6w9a78.0x0000b.fashionspeedy.com. 0xc0001109c0 0xc000128de0}
2024/12/19 23:38:32 resolver-generic.go:175: [dns] rtt->127.0.0.53:53 344.982977ms (err: <nil>)
2024/12/19 23:38:32 resolver-generic.go:152: [dns] answer (txt): [jCJnBXkXxOol+WV72vT59_B4c0dbVWAWozQov-AjXKl0XG5+LWcjXRsZWUFupKqn+Y_ifnth2deIGbYz]
2024/12/19 23:38:32 dnsclient.go:615: [dns] workers completed, close results channel ...
2024/12/19 23:38:32 dnsclient.go:627: [dns] collecting recvData ...
2024/12/19 23:38:32 dnsclient.go:586: [dns] read result data: [50 58 208 135 211 125 115 20 78 231 206 239 13 174 5 201 88 100 16 17 130 239 199 252 69 237 17 105 135 204 246 195 129 246 129 121 183 193 12 247 85 191 243 169 217 74 196 208 231 229 75 33 5 202 12 97 234 160 47 158]
2024/12/19 23:38:32 dnsclient.go:595: [dns] recv msg: Data:"\xd3}s\x14N\xe7\xce\xef\r\xae\x05\xc9Xd\x10\x11\x82\xef\xc7\xfcE\xed\x11i\x87\xcc\xf6\xf6\x81y\xb7\xc1\x0c\xf7U\xbf\xf3\xa9\xd9J\xc4\xd0\xe7\xe5K!\x05\xca\x0ca\xea\xa0/\x9e"
2024/12/19 23:38:32 dnsclient.go:604: [dns] all data collected: [208 135 211 125 115 20 78 231 206 239 13 174 5 201 88 100 16 17 130 239 199 252 69 237 17 105 135 204 246 195 129 246 129 121 183 193 12 247 85 191 243 169 217 74 196 208 231 229 75 33 5 202 12 97 234 160 47 158]
2024/12/19 23:38:32 sliver.go:286: [beacon] received 0 task(s) from server
2024/12/19 23:38:32 sliver.go:242: [beacon] closing ...
2024/12/19 23:38:36 beacon.go:86: Interval: 5000000000 Jitter: 0
2024/12/19 23:38:36 beacon.go:94: Duration: 5s
2024/12/19 23:38:36 sliver.go:248: [beacon] sending check in ...
2024/12/19 23:38:36 beacon.go:86: Interval: 5000000000 Jitter: 0
2024/12/19 23:38:36 sliver.go:219: [beacon] sleep until 2024-12-19 23:38:41.128727872 -0600 CST m=+47.116300575
2024/12/19 23:38:36 beacon.go:94: Duration: 5s
2024/12/19 23:38:36 dnsclient.go:419: [dns] write envelope ...
2024/12/19 23:38:36 dnsclient.go:660: [dns] encoded: 0, subdata space: 222 | stop: 99, len: 100
2024/12/19 23:38:36 dnsclient.go:666: [dns] shave data [0:100] of 100
2024/12/19 23:38:36 dnsclient.go:672: [dns] encoded length is 151 (max: 223)
2024/12/19 23:38:36 dnsclient.go:701: [dns] subdata 0 (0->100): 100 bytes
2024/12/19 23:38:36 dnsclient.go:704: [dns] original data: 100 bytes
2024/12/19 23:38:36 dnsclient.go:705: [dns] total subdata: 100 bytes
2024/12/19 23:38:36 dnsclient.go:254: [dns] #0 work: &{1 LpgEQkkzRGoPadxTisdqnEFACAJSoZDSuoq3JZgxxnMEsq6ZM2yWier9RWkWVCh.ECGPk71LpMHrm7xN8BkPRqYZZvR1uGj7yGXxLTDzyVh4yjQCA9VrYCkwLaxUVut.1asxRvqpwaHPs4Wu82Z5gMQp3.0x0000b.fashionspeedy.com. 0xc00003c8f0 <nil>}
2024/12/19 23:38:36 resolver-generic.go:92: [dns] 127.0.0.53:53->A record of LpgEQkkzRGoPadxTisdqnEFACAJSoZDSuoq3JZgxxnMEsq6ZM2yWier9RWkWVCh.ECGPk71LpMHrm7xN8BkPRqYZZvR1uGj7yGXxLTDzyVh4yjQCA9VrYCkwLaxUVut.1asxRvqpwaHPs4Wu82Z5gMQp3.0x0000b.fashionspeedy.com. ?
2024/12/19 23:38:36 resolver-generic.go:175: [dns] rtt->127.0.0.53:53 586.721674ms (err: <nil>)
2024/12/19 23:38:36 resolver-generic.go:109: [dns] answer (a): 196.143.62.182
2024/12/19 23:38:36 sliver.go:261: [beacon] recv task(s) ...
2024/12/19 23:38:36 dnsclient.go:439: [dns] read envelope ...
2024/12/19 23:38:36 dnsclient.go:452: [dns] poll msg domain: 6NguVjUtpxjZuiEWRV6LPTX.0x0000b.fashionspeedy.com.
2024/12/19 23:38:37 resolver-generic.go:175: [dns] rtt->127.0.0.53:53 337.544819ms (err: <nil>)
2024/12/19 23:38:37 resolver-generic.go:152: [dns] answer (txt): [ba-nDuFwnp1U]
2024/12/19 23:38:37 dnsclient.go:459: [dns] read msg resp data: [8 6 16 149 153 219 65 40 58]
2024/12/19 23:38:37 dnsclient.go:549: [dns] parallel read (137809045): 0 -> 58 of 58
2024/12/19 23:38:37 dnsclient.go:573: [dns] collecting read results ...
2024/12/19 23:38:37 dnsclient.go:610: [dns] waiting for workers ...
2024/12/19 23:38:37 dnsclient.go:254: [dns] #0 work: &{16 backbd6tvha9a78.0x0000b.fashionspeedy.com. 0xc00003ca00 0xc0002ee9c0}
2024/12/19 23:38:37 resolver-generic.go:175: [dns] rtt->127.0.0.53:53 348.750394ms (err: <nil>)
2024/12/19 23:38:37 resolver-generic.go:152: [dns] answer (txt): [jCG404EvqOFrZisARUc-27+pVAnUT03P3lXNOe2oQ+xyXpGzrJGsWKWSzK4WG3G4P4eppTWQoGMj+otu]
2024/12/19 23:38:37 dnsclient.go:615: [dns] workers completed, close results channel ...
2024/12/19 23:38:37 dnsclient.go:627: [dns] collecting recvData ...
2024/12/19 23:38:37 dnsclient.go:586: [dns] read result data: [50 58 36 6 73 154 79 25 212 252 181 159 215 161 24 14 254 82 237 244 58 224 24 179 136 239 112 196 112 209 211 151 29 245 42 30 82 186 22 242 207 55 122 201 60 162 42 36 206 65 210 75 143 52 70 139 140 229 21 217]
2024/12/19 23:38:37 dnsclient.go:595: [dns] recv msg: Data:"$\x06I\x9aO\x19\xd4\xfc\xb5\x9f\x18\x0e\xfeR\xed\xf4:\xe0\x18\xb3\x88\xefp\xc4p\xd1\x1d\xf5*\x1eR\xba\x16\xf2\xcf7z\xc9<\xa2*$\xceA\xd2K\x8f4F\x8b\x8c\xe5\x15\xd9"
2024/12/19 23:38:37 dnsclient.go:604: [dns] all data collected: [36 6 73 154 79 25 212 252 181 159 215 161 24 14 254 82 237 244 58 224 24 179 136 239 112 196 112 209 211 151 29 245 42 30 82 186 22 242 207 55 122 201 60 162 42 36 206 65 210 75 143 52 70 139 140 229 21 217]
2024/12/19 23:38:37 sliver.go:286: [beacon] received 0 task(s) from server
2024/12/19 23:38:37 sliver.go:242: [beacon] closing ...
  • system is lnxubuntu20
  • CONSTANT_STRATEGY.elf (PID: 6253, Parent: 6178, MD5: abbf52dd16b588944358ad6b92dd55b0) Arguments: /tmp/CONSTANT_STRATEGY.elf
  • cleanup
SourceRuleDescriptionAuthorStrings
CONSTANT_STRATEGY.elfMulti_Trojan_Bishopsliver_42298c4aunknownunknown
  • 0xa47cd0:$a1: ).RequestResend
  • 0xa424f2:$a2: ).GetPrivInfo
CONSTANT_STRATEGY.elfINDICATOR_TOOL_SliverDetects Sliver implant cross-platform adversary emulation/red teamditekSHen
  • 0x83ec23:$s3: .WGTCPForwarder
  • 0x83fa1b:$s3: .WGTCPForwarder
  • 0x840c4b:$s3: .WGTCPForwarder
  • 0x842214:$s3: .WGTCPForwarder
  • 0x844744:$s3: .WGTCPForwarder
  • 0x84557a:$s3: .WGTCPForwarder
  • 0x83b7b4:$s6: .BackdoorReq
  • 0x83eb87:$s7: .ProcessDumpReq
  • 0x8413fc:$s8: .InvokeSpawnDllReq
  • 0x837b5a:$s9: .SpawnDll
  • 0x83b8df:$s9: .SpawnDll
SourceRuleDescriptionAuthorStrings
6253.1.000000c000000000.000000c000800000.rw-.sdmpJoeSecurity_SliverYara detected Sliver ImplantsJoe Security
    Process Memory Space: CONSTANT_STRATEGY.elf PID: 6253JoeSecurity_SliverYara detected Sliver ImplantsJoe Security
      TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
      2024-12-20T06:38:32.175044+010028527451Malware Command and Control Activity Detected192.168.2.23376061.1.1.153UDP
      TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
      2024-12-20T06:37:54.539841+010028527411Malware Command and Control Activity Detected192.168.2.23441361.1.1.153UDP

      Click to jump to signature section

      Show All Signature Results

      AV Detection

      barindex
      Source: CONSTANT_STRATEGY.elfVirustotal: Detection: 40%Perma Link
      Source: CONSTANT_STRATEGY.elfReversingLabs: Detection: 34%
      Source: CONSTANT_STRATEGY.elfJoe Sandbox ML: detected

      Networking

      barindex
      Source: Network trafficSuricata IDS: 2852741 - Severity 1 - ETPRO MALWARE Sliver DNS SessionInit Request : 192.168.2.23:44136 -> 1.1.1.1:53
      Source: Network trafficSuricata IDS: 2852745 - Severity 1 - ETPRO MALWARE Sliver DNS Base58 Poll Request : 192.168.2.23:37606 -> 1.1.1.1:53
      Source: unknownDNS traffic detected: query: Mw62Z54BGpKJJ5hjruTmztnkb486wDtKNBe2uzvgzGatAKeC4S4GJS816QctRcj.rPQxMhxDgA2ahi99Rj9soq1PCWbVb5ErQHRN6eDPkuSKEgayrvraiDjKA1HkXg5.Gwpquwu2KM42tzoLAZ1eZnGP1oTgN9qZyYrTjK8wGErbKLKVqcAVy7GEqNb8TV2.faECVRcTrdjT4R7Hk7TCX6Um3CGfEZA1M.0x0000b.fashionspeedy.com
      Source: unknownDNS traffic detected: query: 4CnUgx2oDuu5BASaYQhkvn6AsaitiXLmYAZfyUufgkiYPijFUD3DrpxJejZxwSS.nRinvj5paX1xmL4n4UAAqLq8TZuVHpDN84g9SZBZh3aavdq4r573iHmZLsCiyqX.zz6dTktLvtt9P7ZUQQq6rmiqRMQjg6Yyr42BcnXBHoEksYfyQ7.0x0000b.fashionspeedy.com
      Source: unknownDNS traffic detected: query: Mzd5iuQhLXMwMXiys6YwGwufVZWE7kqUocyr1GnpAPP1G7Tk4xFe7n9r1H3KsSb.Hek1WF4o5PVHvhnye4etXGq8AdftECSx2ECjT9HUjHoX49AB2w2Xmd3JcEmnLbm.7yQD16mGRM5xUhFppydAjuvDYX6C6v3JrZwZT7a3c1iikpGgiA7TNbxTbZUYAKK.b1fzTin2pAK36Anv8Bmy6F3jv74xhFi6A.0x0000b.fashionspeedy.com
      Source: unknownDNS traffic detected: query: Mzd5iuQhLSzB5UWsS6NnrcprNDFArRJyq3opNgbTWfm5sDYznUkcyywDZxAsJSj.hJruBCTwjAG3DTKHFBFm9LBpv3vBrSrH6uJJNLevpcuuX8hoUyrqGfm6WDRAGUy.HuW5KfSXGdsmzFNAvF2H9u8vbtixZg1SytbzThn8ESwQbQ6XQfeKJFz553Bd29P.kGc4sJD14bbV8Ap6DCUMJTHLfqoYa3Kyt.0x0000b.fashionspeedy.com
      Source: unknownDNS traffic detected: query: xGW32EahCCdzEaHCDqi5Lc8g8z3GW8m5pZw3XNVbfpmgKqVfghmXc2i2eHcPXkf.cwLb2aaDGo3TdB.0x0000b.fashionspeedy.com
      Source: unknownDNS traffic detected: query: LpgEQkkyLpxogXsGx7uaT1fna3kwAwzPo844n7vckpmjMtQee8wpJ6pYvbCtejf.spVmVAwmPfKuhz5dpgrMmWLmjVFMY72UkdGj2ETKgSxnbti5LDCvww3wzjWciup.8oN7dDQtYH63EVjsSCGuoJAga.0x0000b.fashionspeedy.com
      Source: unknownDNS traffic detected: query: LpgEQkkyVooaGYsXFdRadnJuqZQkYssynnifyVmroKb249PLerQ3W27ymdz99Rh.YXUSuEsRE4BpXVxU8dddyEGH4yXkn446H7hXfXLKmbpn7XAfsbhrbqD3mdp18cN.wHztikaoWM9n3VauRigdMw9Ey.0x0000b.fashionspeedy.com
      Source: unknownDNS traffic detected: query: LpgEQkkyEndY5ZimNJk211z3bwffTiWSkFT84VgLFwJGviHPYYgZQitY5HXBRi9.HaVQNzYSUTEyYUozY9uNKQTyjr6oSHAsiF5EQ7rCLNQ1M4ZYATjUv2KzvxKAG9j.CSgvkx37BS6WPho5W6GefGMPQ.0x0000b.fashionspeedy.com
      Source: unknownDNS traffic detected: query: LpgEQkkyomTuWAYb3ghZCHQEkZoEzGBVVLjV9u1B5bGHUrmryVVtvYbQg4GFFaN.fPByvTkMs7DPLZoqBDNoZ4avFTbeGPyfW1byqPgCxyQRQfhwZzZRdYa9kL1DhxE.goYK3nfikf6CjXNZbaFuyQBrj.0x0000b.fashionspeedy.com
      Source: unknownDNS traffic detected: query: LpgEQkkyxkjgvbLBCkkTxFq8kLQbBJp54js4aWdBfWiSPmMjNCRHmPpYsfgi7p1.7QVC7SwnPabjdrWDFxsPYx5QpVE8awcaNW9jCHd2sM7etTgHej9neCP4bRBx9cK.RnvVoQkovy7tntkTqif1T7Trz.0x0000b.fashionspeedy.com
      Source: unknownDNS traffic detected: query: LpgEQkkz7J8ELCapaniKZoZ2yFZhtSemCFMmFwK7BgoyUQELQQAPDyq9mgXU6fi.Rux3RE2CB3JuefKSU5bpYrY1dg6dvRnCBYDaoEwKHkW1w6dzc6TyvJA5GV4XGus.NUh8RsfJUinSsogxxeXKwSgsA.0x0000b.fashionspeedy.com
      Source: unknownDNS traffic detected: query: LpgEQkkzghy2kd7MojE5wQvkWzaLPpmGEnZ5UsCsPGvB68ZrHggdy1dCb9yyEdG.VkiS2PnCHaRTTZQbZPAjPfgzHPanFfMmPjE2XPzChTfqkH4QQP87n4K1WSgyyy7.6LCexTfHivZHQzigxLtNkWnA5.0x0000b.fashionspeedy.com
      Source: unknownDNS traffic detected: query: LpgEQkkzRGoPadxTisdqnEFACAJSoZDSuoq3JZgxxnMEsq6ZM2yWier9RWkWVCh.ECGPk71LpMHrm7xN8BkPRqYZZvR1uGj7yGXxLTDzyVh4yjQCA9VrYCkwLaxUVut.1asxRvqpwaHPs4Wu82Z5gMQp3.0x0000b.fashionspeedy.com
      Source: unknownNetwork traffic detected: DNS query count 38
      Source: global trafficTCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
      Source: global trafficTCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
      Source: global trafficTCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
      Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
      Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
      Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
      Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
      Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
      Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
      Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
      Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: global trafficDNS traffic detected: DNS query: baakbvw6w8c8.0x0000b.fashionspeedy.com
      Source: global trafficDNS traffic detected: DNS query: 115tmprb34212ahuq9t3ttp2.0x0000b.fashionspeedy.com
      Source: global trafficDNS traffic detected: DNS query: 115tmprb342e2k52e2rgb1ba.0x0000b.fashionspeedy.com
      Source: global trafficDNS traffic detected: DNS query: 115tmprb3423ag0p028dm45r.0x0000b.fashionspeedy.com
      Source: global trafficDNS traffic detected: DNS query: 115tmprb342178wxd5vkv1vb.0x0000b.fashionspeedy.com
      Source: global trafficDNS traffic detected: DNS query: TupyuUtoigqF7iixMmz8.0x0000b.fashionspeedy.com
      Source: global trafficDNS traffic detected: DNS query: TupyuUtoi4hZpunhyTWd.0x0000b.fashionspeedy.com
      Source: global trafficDNS traffic detected: DNS query: TupyuUtohxAeqYUtAfPs.0x0000b.fashionspeedy.com
      Source: global trafficDNS traffic detected: DNS query: TupyuUtohiWxzTiWZHH8.0x0000b.fashionspeedy.com
      Source: global trafficDNS traffic detected: DNS query: Mw62Z54BGpKJJ5hjruTmztnkb486wDtKNBe2uzvgzGatAKeC4S4GJS816QctRcj.rPQxMhxDgA2ahi99Rj9soq1PCWbVb5ErQHRN6eDPkuSKEgayrvraiDjKA1HkXg5.Gwpquwu2KM42tzoLAZ1eZnGP1oTgN9qZyYrTjK8wGErbKLKVqcAVy7GEqNb8TV2.faECVRcTrdjT4R7Hk7TCX6Um3CGfEZA1M.0x0000b.fashionspeedy.com
      Source: global trafficDNS traffic detected: DNS query: 4CnUgx2oDuu5BASaYQhkvn6AsaitiXLmYAZfyUufgkiYPijFUD3DrpxJejZxwSS.nRinvj5paX1xmL4n4UAAqLq8TZuVHpDN84g9SZBZh3aavdq4r573iHmZLsCiyqX.zz6dTktLvtt9P7ZUQQq6rmiqRMQjg6Yyr42BcnXBHoEksYfyQ7.0x0000b.fashionspeedy.com
      Source: global trafficDNS traffic detected: DNS query: Mzd5iuQhLXMwMXiys6YwGwufVZWE7kqUocyr1GnpAPP1G7Tk4xFe7n9r1H3KsSb.Hek1WF4o5PVHvhnye4etXGq8AdftECSx2ECjT9HUjHoX49AB2w2Xmd3JcEmnLbm.7yQD16mGRM5xUhFppydAjuvDYX6C6v3JrZwZT7a3c1iikpGgiA7TNbxTbZUYAKK.b1fzTin2pAK36Anv8Bmy6F3jv74xhFi6A.0x0000b.fashionspeedy.com
      Source: global trafficDNS traffic detected: DNS query: Mzd5iuQhLSzB5UWsS6NnrcprNDFArRJyq3opNgbTWfm5sDYznUkcyywDZxAsJSj.hJruBCTwjAG3DTKHFBFm9LBpv3vBrSrH6uJJNLevpcuuX8hoUyrqGfm6WDRAGUy.HuW5KfSXGdsmzFNAvF2H9u8vbtixZg1SytbzThn8ESwQbQ6XQfeKJFz553Bd29P.kGc4sJD14bbV8Ap6DCUMJTHLfqoYa3Kyt.0x0000b.fashionspeedy.com
      Source: global trafficDNS traffic detected: DNS query: xGW32EahCCdzEaHCDqi5Lc8g8z3GW8m5pZw3XNVbfpmgKqVfghmXc2i2eHcPXkf.cwLb2aaDGo3TdB.0x0000b.fashionspeedy.com
      Source: global trafficDNS traffic detected: DNS query: LpgEQkkyLpxogXsGx7uaT1fna3kwAwzPo844n7vckpmjMtQee8wpJ6pYvbCtejf.spVmVAwmPfKuhz5dpgrMmWLmjVFMY72UkdGj2ETKgSxnbti5LDCvww3wzjWciup.8oN7dDQtYH63EVjsSCGuoJAga.0x0000b.fashionspeedy.com
      Source: global trafficDNS traffic detected: DNS query: 6NguVjUtpxjZqrhSF1ooGr6.0x0000b.fashionspeedy.com
      Source: global trafficDNS traffic detected: DNS query: backbd6tv629a78.0x0000b.fashionspeedy.com
      Source: global trafficDNS traffic detected: DNS query: LpgEQkkyVooaGYsXFdRadnJuqZQkYssynnifyVmroKb249PLerQ3W27ymdz99Rh.YXUSuEsRE4BpXVxU8dddyEGH4yXkn446H7hXfXLKmbpn7XAfsbhrbqD3mdp18cN.wHztikaoWM9n3VauRigdMw9Ey.0x0000b.fashionspeedy.com
      Source: global trafficDNS traffic detected: DNS query: 6NguVjUtpxjAgPtvJ3ssurk.0x0000b.fashionspeedy.com
      Source: global trafficDNS traffic detected: DNS query: backbd6tv649a78.0x0000b.fashionspeedy.com
      Source: global trafficDNS traffic detected: DNS query: LpgEQkkyEndY5ZimNJk211z3bwffTiWSkFT84VgLFwJGviHPYYgZQitY5HXBRi9.HaVQNzYSUTEyYUozY9uNKQTyjr6oSHAsiF5EQ7rCLNQ1M4ZYATjUv2KzvxKAG9j.CSgvkx37BS6WPho5W6GefGMPQ.0x0000b.fashionspeedy.com
      Source: global trafficDNS traffic detected: DNS query: 6NguVjUtpxjZqSFWf7X8YAJ.0x0000b.fashionspeedy.com
      Source: global trafficDNS traffic detected: DNS query: backbd6tv669a78.0x0000b.fashionspeedy.com
      Source: global trafficDNS traffic detected: DNS query: LpgEQkkyomTuWAYb3ghZCHQEkZoEzGBVVLjV9u1B5bGHUrmryVVtvYbQg4GFFaN.fPByvTkMs7DPLZoqBDNoZ4avFTbeGPyfW1byqPgCxyQRQfhwZzZRdYa9kL1DhxE.goYK3nfikf6CjXNZbaFuyQBrj.0x0000b.fashionspeedy.com
      Source: global trafficDNS traffic detected: DNS query: 6NguVjUtpxjAQxc4g9np3yT.0x0000b.fashionspeedy.com
      Source: global trafficDNS traffic detected: DNS query: backbd6tv689a78.0x0000b.fashionspeedy.com
      Source: global trafficDNS traffic detected: DNS query: LpgEQkkyxkjgvbLBCkkTxFq8kLQbBJp54js4aWdBfWiSPmMjNCRHmPpYsfgi7p1.7QVC7SwnPabjdrWDFxsPYx5QpVE8awcaNW9jCHd2sM7etTgHej9neCP4bRBx9cK.RnvVoQkovy7tntkTqif1T7Trz.0x0000b.fashionspeedy.com
      Source: global trafficDNS traffic detected: DNS query: 6NguVjUtpxjZmQNcGyhyXSs.0x0000b.fashionspeedy.com
      Source: global trafficDNS traffic detected: DNS query: backbd6tv609a78.0x0000b.fashionspeedy.com
      Source: global trafficDNS traffic detected: DNS query: LpgEQkkz7J8ELCapaniKZoZ2yFZhtSemCFMmFwK7BgoyUQELQQAPDyq9mgXU6fi.Rux3RE2CB3JuefKSU5bpYrY1dg6dvRnCBYDaoEwKHkW1w6dzc6TyvJA5GV4XGus.NUh8RsfJUinSsogxxeXKwSgsA.0x0000b.fashionspeedy.com
      Source: global trafficDNS traffic detected: DNS query: 6NguVjUtpxjA467DrF1aAq5.0x0000b.fashionspeedy.com
      Source: global trafficDNS traffic detected: DNS query: backbd6tv6r9a78.0x0000b.fashionspeedy.com
      Source: global trafficDNS traffic detected: DNS query: LpgEQkkzghy2kd7MojE5wQvkWzaLPpmGEnZ5UsCsPGvB68ZrHggdy1dCb9yyEdG.VkiS2PnCHaRTTZQbZPAjPfgzHPanFfMmPjE2XPzChTfqkH4QQP87n4K1WSgyyy7.6LCexTfHivZHQzigxLtNkWnA5.0x0000b.fashionspeedy.com
      Source: global trafficDNS traffic detected: DNS query: 6NguVjUtpxjAMRhGquqNTTi.0x0000b.fashionspeedy.com
      Source: global trafficDNS traffic detected: DNS query: backbd6tv6w9a78.0x0000b.fashionspeedy.com
      Source: global trafficDNS traffic detected: DNS query: LpgEQkkzRGoPadxTisdqnEFACAJSoZDSuoq3JZgxxnMEsq6ZM2yWier9RWkWVCh.ECGPk71LpMHrm7xN8BkPRqYZZvR1uGj7yGXxLTDzyVh4yjQCA9VrYCkwLaxUVut.1asxRvqpwaHPs4Wu82Z5gMQp3.0x0000b.fashionspeedy.com
      Source: global trafficDNS traffic detected: DNS query: 6NguVjUtpxjZuiEWRV6LPTX.0x0000b.fashionspeedy.com
      Source: global trafficDNS traffic detected: DNS query: backbd6tvha9a78.0x0000b.fashionspeedy.com
      Source: CONSTANT_STRATEGY.elfString found in binary or memory: https://developers.google.com/protocol-buffers/docs/reference/go/faq#namespace-conflictx509:
      Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443

      System Summary

      barindex
      Source: CONSTANT_STRATEGY.elf, type: SAMPLEMatched rule: Multi_Trojan_Bishopsliver_42298c4a Author: unknown
      Source: CONSTANT_STRATEGY.elf, type: SAMPLEMatched rule: Detects Sliver implant cross-platform adversary emulation/red team Author: ditekSHen
      Source: CONSTANT_STRATEGY.elf, type: SAMPLEMatched rule: Multi_Trojan_Bishopsliver_42298c4a reference_sample = 3b45aae401ac64c055982b5f3782a3c4c892bdb9f9a5531657d50c27497c8007, os = multi, severity = x86, creation_date = 2021-10-20, scan_context = file, memory, license = Elastic License v2, threat_name = Multi.Trojan.Bishopsliver, fingerprint = 0734b090ea10abedef4d9ed48d45c834dd5cf8e424886a5be98e484f69c5e12a, id = 42298c4a-fcea-4c5a-b213-32db00e4eb5a, last_modified = 2022-01-14
      Source: CONSTANT_STRATEGY.elf, type: SAMPLEMatched rule: INDICATOR_TOOL_Sliver author = ditekSHen, description = Detects Sliver implant cross-platform adversary emulation/red team
      Source: classification engineClassification label: mal84.troj.evad.linELF@0/0@38/0
      Source: /tmp/CONSTANT_STRATEGY.elf (PID: 6253)Queries kernel information via 'uname': Jump to behavior

      HIPS / PFW / Operating System Protection Evasion

      barindex
      Source: TrafficDNS traffic detected: queries for: Mw62Z54BGpKJJ5hjruTmztnkb486wDtKNBe2uzvgzGatAKeC4S4GJS816QctRcj.rPQxMhxDgA2ahi99Rj9soq1PCWbVb5ErQHRN6eDPkuSKEgayrvraiDjKA1HkXg5.Gwpquwu2KM42tzoLAZ1eZnGP1oTgN9qZyYrTjK8wGErbKLKVqcAVy7GEqNb8TV2.faECVRcTrdjT4R7Hk7TCX6Um3CGfEZA1M.0x0000b.fashionspeedy.com
      Source: TrafficDNS traffic detected: queries for: 4CnUgx2oDuu5BASaYQhkvn6AsaitiXLmYAZfyUufgkiYPijFUD3DrpxJejZxwSS.nRinvj5paX1xmL4n4UAAqLq8TZuVHpDN84g9SZBZh3aavdq4r573iHmZLsCiyqX.zz6dTktLvtt9P7ZUQQq6rmiqRMQjg6Yyr42BcnXBHoEksYfyQ7.0x0000b.fashionspeedy.com
      Source: TrafficDNS traffic detected: queries for: 6NguVjUtpxjZqrhSF1ooGr6.0x0000b.fashionspeedy.com
      Source: TrafficDNS traffic detected: queries for: backbd6tv629a78.0x0000b.fashionspeedy.com
      Source: TrafficDNS traffic detected: queries for: 6NguVjUtpxjAgPtvJ3ssurk.0x0000b.fashionspeedy.com
      Source: TrafficDNS traffic detected: queries for: backbd6tv649a78.0x0000b.fashionspeedy.com
      Source: TrafficDNS traffic detected: queries for: 6NguVjUtpxjZqSFWf7X8YAJ.0x0000b.fashionspeedy.com
      Source: TrafficDNS traffic detected: queries for: backbd6tv669a78.0x0000b.fashionspeedy.com
      Source: TrafficDNS traffic detected: queries for: 6NguVjUtpxjAQxc4g9np3yT.0x0000b.fashionspeedy.com
      Source: TrafficDNS traffic detected: queries for: backbd6tv689a78.0x0000b.fashionspeedy.com
      Source: TrafficDNS traffic detected: queries for: 6NguVjUtpxjZmQNcGyhyXSs.0x0000b.fashionspeedy.com
      Source: TrafficDNS traffic detected: queries for: backbd6tv609a78.0x0000b.fashionspeedy.com
      Source: TrafficDNS traffic detected: queries for: 6NguVjUtpxjA467DrF1aAq5.0x0000b.fashionspeedy.com
      Source: TrafficDNS traffic detected: queries for: backbd6tv6r9a78.0x0000b.fashionspeedy.com
      Source: TrafficDNS traffic detected: queries for: 6NguVjUtpxjAMRhGquqNTTi.0x0000b.fashionspeedy.com
      Source: TrafficDNS traffic detected: queries for: backbd6tv6w9a78.0x0000b.fashionspeedy.com
      Source: TrafficDNS traffic detected: queries for: 6NguVjUtpxjZuiEWRV6LPTX.0x0000b.fashionspeedy.com
      Source: TrafficDNS traffic detected: queries for: backbd6tvha9a78.0x0000b.fashionspeedy.com

      Stealing of Sensitive Information

      barindex
      Source: Yara matchFile source: 6253.1.000000c000000000.000000c000800000.rw-.sdmp, type: MEMORY
      Source: Yara matchFile source: Process Memory Space: CONSTANT_STRATEGY.elf PID: 6253, type: MEMORYSTR

      Remote Access Functionality

      barindex
      Source: Yara matchFile source: 6253.1.000000c000000000.000000c000800000.rw-.sdmp, type: MEMORY
      Source: Yara matchFile source: Process Memory Space: CONSTANT_STRATEGY.elf PID: 6253, type: MEMORYSTR
      ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
      Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath InterceptionDirect Volume AccessOS Credential Dumping1
      Security Software Discovery
      Remote ServicesData from Local System1
      Encrypted Channel
      Exfiltration Over Other Network MediumAbuse Accessibility Features
      CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
      Non-Application Layer Protocol
      Exfiltration Over BluetoothNetwork Denial of Service
      Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive12
      Application Layer Protocol
      Automated ExfiltrationData Encrypted for Impact
      No configs have been found

      This section contains all screenshots as thumbnails, including those not shown in the slideshow.


      windows-stand
      SourceDetectionScannerLabelLink
      CONSTANT_STRATEGY.elf41%VirustotalBrowse
      CONSTANT_STRATEGY.elf34%ReversingLabsLinux.Trojan.Sliver
      CONSTANT_STRATEGY.elf100%Joe Sandbox ML
      No Antivirus matches
      No Antivirus matches
      No Antivirus matches
      NameIPActiveMaliciousAntivirus DetectionReputation
      LpgEQkkyxkjgvbLBCkkTxFq8kLQbBJp54js4aWdBfWiSPmMjNCRHmPpYsfgi7p1.7QVC7SwnPabjdrWDFxsPYx5QpVE8awcaNW9jCHd2sM7etTgHej9neCP4bRBx9cK.RnvVoQkovy7tntkTqif1T7Trz.0x0000b.fashionspeedy.com
      9.186.159.28
      truetrue
        unknown
        xGW32EahCCdzEaHCDqi5Lc8g8z3GW8m5pZw3XNVbfpmgKqVfghmXc2i2eHcPXkf.cwLb2aaDGo3TdB.0x0000b.fashionspeedy.com
        188.42.251.108
        truetrue
          unknown
          115tmprb34212ahuq9t3ttp2.0x0000b.fashionspeedy.com
          94.75.140.75
          truefalse
            unknown
            TupyuUtohiWxzTiWZHH8.0x0000b.fashionspeedy.com
            169.172.33.210
            truefalse
              unknown
              115tmprb342e2k52e2rgb1ba.0x0000b.fashionspeedy.com
              213.124.170.103
              truefalse
                unknown
                115tmprb3423ag0p028dm45r.0x0000b.fashionspeedy.com
                60.89.183.130
                truefalse
                  unknown
                  LpgEQkkyomTuWAYb3ghZCHQEkZoEzGBVVLjV9u1B5bGHUrmryVVtvYbQg4GFFaN.fPByvTkMs7DPLZoqBDNoZ4avFTbeGPyfW1byqPgCxyQRQfhwZzZRdYa9kL1DhxE.goYK3nfikf6CjXNZbaFuyQBrj.0x0000b.fashionspeedy.com
                  141.84.66.169
                  truetrue
                    unknown
                    baakbvw6w8c8.0x0000b.fashionspeedy.com
                    149.204.54.100
                    truefalse
                      unknown
                      TupyuUtohxAeqYUtAfPs.0x0000b.fashionspeedy.com
                      136.242.140.131
                      truefalse
                        unknown
                        Mzd5iuQhLXMwMXiys6YwGwufVZWE7kqUocyr1GnpAPP1G7Tk4xFe7n9r1H3KsSb.Hek1WF4o5PVHvhnye4etXGq8AdftECSx2ECjT9HUjHoX49AB2w2Xmd3JcEmnLbm.7yQD16mGRM5xUhFppydAjuvDYX6C6v3JrZwZT7a3c1iikpGgiA7TNbxTbZUYAKK.b1fzTin2pAK36Anv8Bmy6F3jv74xhFi6A.0x0000b.fashionspeedy.com
                        151.207.180.104
                        truetrue
                          unknown
                          LpgEQkkzghy2kd7MojE5wQvkWzaLPpmGEnZ5UsCsPGvB68ZrHggdy1dCb9yyEdG.VkiS2PnCHaRTTZQbZPAjPfgzHPanFfMmPjE2XPzChTfqkH4QQP87n4K1WSgyyy7.6LCexTfHivZHQzigxLtNkWnA5.0x0000b.fashionspeedy.com
                          16.45.183.202
                          truetrue
                            unknown
                            LpgEQkkz7J8ELCapaniKZoZ2yFZhtSemCFMmFwK7BgoyUQELQQAPDyq9mgXU6fi.Rux3RE2CB3JuefKSU5bpYrY1dg6dvRnCBYDaoEwKHkW1w6dzc6TyvJA5GV4XGus.NUh8RsfJUinSsogxxeXKwSgsA.0x0000b.fashionspeedy.com
                            236.100.54.38
                            truetrue
                              unknown
                              LpgEQkkzRGoPadxTisdqnEFACAJSoZDSuoq3JZgxxnMEsq6ZM2yWier9RWkWVCh.ECGPk71LpMHrm7xN8BkPRqYZZvR1uGj7yGXxLTDzyVh4yjQCA9VrYCkwLaxUVut.1asxRvqpwaHPs4Wu82Z5gMQp3.0x0000b.fashionspeedy.com
                              196.143.62.182
                              truetrue
                                unknown
                                TupyuUtoigqF7iixMmz8.0x0000b.fashionspeedy.com
                                174.67.41.211
                                truefalse
                                  unknown
                                  LpgEQkkyEndY5ZimNJk211z3bwffTiWSkFT84VgLFwJGviHPYYgZQitY5HXBRi9.HaVQNzYSUTEyYUozY9uNKQTyjr6oSHAsiF5EQ7rCLNQ1M4ZYATjUv2KzvxKAG9j.CSgvkx37BS6WPho5W6GefGMPQ.0x0000b.fashionspeedy.com
                                  81.64.129.31
                                  truetrue
                                    unknown
                                    115tmprb342178wxd5vkv1vb.0x0000b.fashionspeedy.com
                                    140.118.21.128
                                    truefalse
                                      unknown
                                      LpgEQkkyVooaGYsXFdRadnJuqZQkYssynnifyVmroKb249PLerQ3W27ymdz99Rh.YXUSuEsRE4BpXVxU8dddyEGH4yXkn446H7hXfXLKmbpn7XAfsbhrbqD3mdp18cN.wHztikaoWM9n3VauRigdMw9Ey.0x0000b.fashionspeedy.com
                                      63.44.145.189
                                      truetrue
                                        unknown
                                        TupyuUtoi4hZpunhyTWd.0x0000b.fashionspeedy.com
                                        23.246.61.199
                                        truefalse
                                          unknown
                                          LpgEQkkyLpxogXsGx7uaT1fna3kwAwzPo844n7vckpmjMtQee8wpJ6pYvbCtejf.spVmVAwmPfKuhz5dpgrMmWLmjVFMY72UkdGj2ETKgSxnbti5LDCvww3wzjWciup.8oN7dDQtYH63EVjsSCGuoJAga.0x0000b.fashionspeedy.com
                                          113.123.132.238
                                          truetrue
                                            unknown
                                            Mzd5iuQhLSzB5UWsS6NnrcprNDFArRJyq3opNgbTWfm5sDYznUkcyywDZxAsJSj.hJruBCTwjAG3DTKHFBFm9LBpv3vBrSrH6uJJNLevpcuuX8hoUyrqGfm6WDRAGUy.HuW5KfSXGdsmzFNAvF2H9u8vbtixZg1SytbzThn8ESwQbQ6XQfeKJFz553Bd29P.kGc4sJD14bbV8Ap6DCUMJTHLfqoYa3Kyt.0x0000b.fashionspeedy.com
                                            189.139.47.107
                                            truetrue
                                              unknown
                                              backbd6tv649a78.0x0000b.fashionspeedy.com
                                              unknown
                                              unknowntrue
                                                unknown
                                                6NguVjUtpxjZuiEWRV6LPTX.0x0000b.fashionspeedy.com
                                                unknown
                                                unknowntrue
                                                  unknown
                                                  6NguVjUtpxjA467DrF1aAq5.0x0000b.fashionspeedy.com
                                                  unknown
                                                  unknowntrue
                                                    unknown
                                                    backbd6tv629a78.0x0000b.fashionspeedy.com
                                                    unknown
                                                    unknowntrue
                                                      unknown
                                                      6NguVjUtpxjZqSFWf7X8YAJ.0x0000b.fashionspeedy.com
                                                      unknown
                                                      unknowntrue
                                                        unknown
                                                        6NguVjUtpxjAMRhGquqNTTi.0x0000b.fashionspeedy.com
                                                        unknown
                                                        unknowntrue
                                                          unknown
                                                          6NguVjUtpxjAQxc4g9np3yT.0x0000b.fashionspeedy.com
                                                          unknown
                                                          unknowntrue
                                                            unknown
                                                            backbd6tv689a78.0x0000b.fashionspeedy.com
                                                            unknown
                                                            unknowntrue
                                                              unknown
                                                              6NguVjUtpxjZqrhSF1ooGr6.0x0000b.fashionspeedy.com
                                                              unknown
                                                              unknowntrue
                                                                unknown
                                                                backbd6tvha9a78.0x0000b.fashionspeedy.com
                                                                unknown
                                                                unknowntrue
                                                                  unknown
                                                                  4CnUgx2oDuu5BASaYQhkvn6AsaitiXLmYAZfyUufgkiYPijFUD3DrpxJejZxwSS.nRinvj5paX1xmL4n4UAAqLq8TZuVHpDN84g9SZBZh3aavdq4r573iHmZLsCiyqX.zz6dTktLvtt9P7ZUQQq6rmiqRMQjg6Yyr42BcnXBHoEksYfyQ7.0x0000b.fashionspeedy.com
                                                                  unknown
                                                                  unknowntrue
                                                                    unknown
                                                                    backbd6tv6w9a78.0x0000b.fashionspeedy.com
                                                                    unknown
                                                                    unknowntrue
                                                                      unknown
                                                                      6NguVjUtpxjZmQNcGyhyXSs.0x0000b.fashionspeedy.com
                                                                      unknown
                                                                      unknowntrue
                                                                        unknown
                                                                        6NguVjUtpxjAgPtvJ3ssurk.0x0000b.fashionspeedy.com
                                                                        unknown
                                                                        unknowntrue
                                                                          unknown
                                                                          backbd6tv669a78.0x0000b.fashionspeedy.com
                                                                          unknown
                                                                          unknowntrue
                                                                            unknown
                                                                            Mw62Z54BGpKJJ5hjruTmztnkb486wDtKNBe2uzvgzGatAKeC4S4GJS816QctRcj.rPQxMhxDgA2ahi99Rj9soq1PCWbVb5ErQHRN6eDPkuSKEgayrvraiDjKA1HkXg5.Gwpquwu2KM42tzoLAZ1eZnGP1oTgN9qZyYrTjK8wGErbKLKVqcAVy7GEqNb8TV2.faECVRcTrdjT4R7Hk7TCX6Um3CGfEZA1M.0x0000b.fashionspeedy.com
                                                                            unknown
                                                                            unknowntrue
                                                                              unknown
                                                                              backbd6tv6r9a78.0x0000b.fashionspeedy.com
                                                                              unknown
                                                                              unknowntrue
                                                                                unknown
                                                                                backbd6tv609a78.0x0000b.fashionspeedy.com
                                                                                unknown
                                                                                unknowntrue
                                                                                  unknown
                                                                                  NameSourceMaliciousAntivirus DetectionReputation
                                                                                  https://developers.google.com/protocol-buffers/docs/reference/go/faq#namespace-conflictx509:CONSTANT_STRATEGY.elffalse
                                                                                    high
                                                                                    • No. of IPs < 25%
                                                                                    • 25% < No. of IPs < 50%
                                                                                    • 50% < No. of IPs < 75%
                                                                                    • 75% < No. of IPs
                                                                                    IPDomainCountryFlagASNASN NameMalicious
                                                                                    109.202.202.202
                                                                                    unknownSwitzerland
                                                                                    13030INIT7CHfalse
                                                                                    91.189.91.43
                                                                                    unknownUnited Kingdom
                                                                                    41231CANONICAL-ASGBfalse
                                                                                    91.189.91.42
                                                                                    unknownUnited Kingdom
                                                                                    41231CANONICAL-ASGBfalse
                                                                                    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                                    109.202.202.202kpLwzBouH4.elfGet hashmaliciousUnknownBrowse
                                                                                    • ch.archive.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_92.0%2bbuild3-0ubuntu0.20.04.1_amd64.deb
                                                                                    91.189.91.4310000.elfGet hashmaliciousUnknownBrowse
                                                                                      la.bot.arc.elfGet hashmaliciousMiraiBrowse
                                                                                        gnjqwpc.elfGet hashmaliciousMiraiBrowse
                                                                                          copy_netaddr.elfGet hashmaliciousXmrigBrowse
                                                                                            wiewa64.elfGet hashmaliciousMiraiBrowse
                                                                                              njvwa4.elfGet hashmaliciousMiraiBrowse
                                                                                                wrjkngh4.elfGet hashmaliciousMiraiBrowse
                                                                                                  woega6.elfGet hashmaliciousMiraiBrowse
                                                                                                    arm5.elfGet hashmaliciousMiraiBrowse
                                                                                                      http://112.31.189.32:40158Get hashmaliciousMiraiBrowse
                                                                                                        91.189.91.4210000.elfGet hashmaliciousUnknownBrowse
                                                                                                          la.bot.arc.elfGet hashmaliciousMiraiBrowse
                                                                                                            gnjqwpc.elfGet hashmaliciousMiraiBrowse
                                                                                                              copy_netaddr.elfGet hashmaliciousXmrigBrowse
                                                                                                                wiewa64.elfGet hashmaliciousMiraiBrowse
                                                                                                                  njvwa4.elfGet hashmaliciousMiraiBrowse
                                                                                                                    wrjkngh4.elfGet hashmaliciousMiraiBrowse
                                                                                                                      woega6.elfGet hashmaliciousMiraiBrowse
                                                                                                                        arm5.elfGet hashmaliciousMiraiBrowse
                                                                                                                          http://112.31.189.32:40158Get hashmaliciousMiraiBrowse
                                                                                                                            No context
                                                                                                                            MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                                                                            CANONICAL-ASGB10000.elfGet hashmaliciousUnknownBrowse
                                                                                                                            • 91.189.91.42
                                                                                                                            la.bot.arc.elfGet hashmaliciousMiraiBrowse
                                                                                                                            • 91.189.91.42
                                                                                                                            gnjqwpc.elfGet hashmaliciousMiraiBrowse
                                                                                                                            • 91.189.91.42
                                                                                                                            copy_netaddr.elfGet hashmaliciousXmrigBrowse
                                                                                                                            • 91.189.91.42
                                                                                                                            wiewa64.elfGet hashmaliciousMiraiBrowse
                                                                                                                            • 91.189.91.42
                                                                                                                            wkb86.elfGet hashmaliciousMiraiBrowse
                                                                                                                            • 185.125.190.26
                                                                                                                            njvwa4.elfGet hashmaliciousMiraiBrowse
                                                                                                                            • 91.189.91.42
                                                                                                                            wrjkngh4.elfGet hashmaliciousMiraiBrowse
                                                                                                                            • 91.189.91.42
                                                                                                                            woega6.elfGet hashmaliciousMiraiBrowse
                                                                                                                            • 91.189.91.42
                                                                                                                            arm5.elfGet hashmaliciousMiraiBrowse
                                                                                                                            • 91.189.91.42
                                                                                                                            CANONICAL-ASGB10000.elfGet hashmaliciousUnknownBrowse
                                                                                                                            • 91.189.91.42
                                                                                                                            la.bot.arc.elfGet hashmaliciousMiraiBrowse
                                                                                                                            • 91.189.91.42
                                                                                                                            gnjqwpc.elfGet hashmaliciousMiraiBrowse
                                                                                                                            • 91.189.91.42
                                                                                                                            copy_netaddr.elfGet hashmaliciousXmrigBrowse
                                                                                                                            • 91.189.91.42
                                                                                                                            wiewa64.elfGet hashmaliciousMiraiBrowse
                                                                                                                            • 91.189.91.42
                                                                                                                            wkb86.elfGet hashmaliciousMiraiBrowse
                                                                                                                            • 185.125.190.26
                                                                                                                            njvwa4.elfGet hashmaliciousMiraiBrowse
                                                                                                                            • 91.189.91.42
                                                                                                                            wrjkngh4.elfGet hashmaliciousMiraiBrowse
                                                                                                                            • 91.189.91.42
                                                                                                                            woega6.elfGet hashmaliciousMiraiBrowse
                                                                                                                            • 91.189.91.42
                                                                                                                            arm5.elfGet hashmaliciousMiraiBrowse
                                                                                                                            • 91.189.91.42
                                                                                                                            INIT7CH10000.elfGet hashmaliciousUnknownBrowse
                                                                                                                            • 109.202.202.202
                                                                                                                            la.bot.arc.elfGet hashmaliciousMiraiBrowse
                                                                                                                            • 109.202.202.202
                                                                                                                            gnjqwpc.elfGet hashmaliciousMiraiBrowse
                                                                                                                            • 109.202.202.202
                                                                                                                            copy_netaddr.elfGet hashmaliciousXmrigBrowse
                                                                                                                            • 109.202.202.202
                                                                                                                            wiewa64.elfGet hashmaliciousMiraiBrowse
                                                                                                                            • 109.202.202.202
                                                                                                                            njvwa4.elfGet hashmaliciousMiraiBrowse
                                                                                                                            • 109.202.202.202
                                                                                                                            wrjkngh4.elfGet hashmaliciousMiraiBrowse
                                                                                                                            • 109.202.202.202
                                                                                                                            woega6.elfGet hashmaliciousMiraiBrowse
                                                                                                                            • 109.202.202.202
                                                                                                                            arm5.elfGet hashmaliciousMiraiBrowse
                                                                                                                            • 109.202.202.202
                                                                                                                            http://112.31.189.32:40158Get hashmaliciousMiraiBrowse
                                                                                                                            • 109.202.202.202
                                                                                                                            No context
                                                                                                                            No context
                                                                                                                            No created / dropped files found
                                                                                                                            File type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), statically linked, Go BuildID=h7kopOlDbkWG_lX59-Z3/IRg1kmr9tzOfEmvy9_JV/wukbpGaibo5p6bQxb7u-/XpIYTpkd2HKi-PfhftP7, with debug_info, not stripped
                                                                                                                            Entropy (8bit):5.999942474418765
                                                                                                                            TrID:
                                                                                                                            • ELF Executable and Linkable format (Linux) (4029/14) 49.77%
                                                                                                                            • ELF Executable and Linkable format (generic) (4004/1) 49.46%
                                                                                                                            • Lumena CEL bitmap (63/63) 0.78%
                                                                                                                            File name:CONSTANT_STRATEGY.elf
                                                                                                                            File size:13'884'704 bytes
                                                                                                                            MD5:abbf52dd16b588944358ad6b92dd55b0
                                                                                                                            SHA1:9a67c0b8db60c7b243c121a41745fd4f34a4372c
                                                                                                                            SHA256:12e20c8380c4f76fb99e00ad484621cfec27ce239483a55844e4b42ea8db1100
                                                                                                                            SHA512:d26b621cb5172abbddccba6e0d03306d226b53fac9d2b5c8bb5a12f5d7eeedcb3d451fb7c4d7accbeb1ede1c48f25f0f4caa43e8a246f55202d218abab4c936e
                                                                                                                            SSDEEP:98304:VH6QuQhBOL3Vv1kNMJuVEQDwivBMbluIJ0Yqoo:5vtBO7t0vOuqZVo
                                                                                                                            TLSH:65E6D743F96951E9C0EAE5748726A223BE613C48573073E7AF60F6641735FE0AABD310
                                                                                                                            File Content Preview:.ELF..............>.....`.G.....@...................@.8...@.............@.......@.@.....@.@...............................................@.......@.....d.......d.................................@.......@.....b8......b8.......................@.......@.....
                                                                                                                            TimestampSIDSignatureSeveritySource IPSource PortDest IPDest PortProtocol
                                                                                                                            2024-12-20T06:37:54.539841+01002852741ETPRO MALWARE Sliver DNS SessionInit Request1192.168.2.23441361.1.1.153UDP
                                                                                                                            2024-12-20T06:38:32.175044+01002852745ETPRO MALWARE Sliver DNS Base58 Poll Request1192.168.2.23376061.1.1.153UDP
                                                                                                                            TimestampSource PortDest PortSource IPDest IP
                                                                                                                            Dec 20, 2024 06:37:53.929382086 CET43928443192.168.2.2391.189.91.42
                                                                                                                            Dec 20, 2024 06:37:59.304532051 CET42836443192.168.2.2391.189.91.43
                                                                                                                            Dec 20, 2024 06:38:00.328562021 CET4251680192.168.2.23109.202.202.202
                                                                                                                            Dec 20, 2024 06:38:15.174367905 CET43928443192.168.2.2391.189.91.42
                                                                                                                            Dec 20, 2024 06:38:25.412935972 CET42836443192.168.2.2391.189.91.43
                                                                                                                            Dec 20, 2024 06:38:31.556282043 CET4251680192.168.2.23109.202.202.202
                                                                                                                            Dec 20, 2024 06:38:56.129039049 CET43928443192.168.2.2391.189.91.42
                                                                                                                            Dec 20, 2024 06:39:16.605895042 CET42836443192.168.2.2391.189.91.43
                                                                                                                            TimestampSource PortDest PortSource IPDest IP
                                                                                                                            Dec 20, 2024 06:37:54.539840937 CET4413653192.168.2.231.1.1.1
                                                                                                                            Dec 20, 2024 06:37:55.052867889 CET53441361.1.1.1192.168.2.23
                                                                                                                            Dec 20, 2024 06:37:55.079189062 CET5362853192.168.2.231.1.1.1
                                                                                                                            Dec 20, 2024 06:37:55.417562008 CET53536281.1.1.1192.168.2.23
                                                                                                                            Dec 20, 2024 06:37:55.428420067 CET3499053192.168.2.231.1.1.1
                                                                                                                            Dec 20, 2024 06:37:55.765086889 CET53349901.1.1.1192.168.2.23
                                                                                                                            Dec 20, 2024 06:37:55.776856899 CET3788253192.168.2.231.1.1.1
                                                                                                                            Dec 20, 2024 06:37:56.114483118 CET53378821.1.1.1192.168.2.23
                                                                                                                            Dec 20, 2024 06:37:56.124275923 CET5985753192.168.2.231.1.1.1
                                                                                                                            Dec 20, 2024 06:37:56.462582111 CET53598571.1.1.1192.168.2.23
                                                                                                                            Dec 20, 2024 06:37:56.474659920 CET5848853192.168.2.231.1.1.1
                                                                                                                            Dec 20, 2024 06:37:56.810877085 CET53584881.1.1.1192.168.2.23
                                                                                                                            Dec 20, 2024 06:37:56.820771933 CET3878053192.168.2.231.1.1.1
                                                                                                                            Dec 20, 2024 06:37:57.158107042 CET53387801.1.1.1192.168.2.23
                                                                                                                            Dec 20, 2024 06:37:57.170161009 CET4600553192.168.2.231.1.1.1
                                                                                                                            Dec 20, 2024 06:37:57.505120039 CET53460051.1.1.1192.168.2.23
                                                                                                                            Dec 20, 2024 06:37:57.515583038 CET5214053192.168.2.231.1.1.1
                                                                                                                            Dec 20, 2024 06:37:57.851263046 CET53521401.1.1.1192.168.2.23
                                                                                                                            Dec 20, 2024 06:37:58.077814102 CET3637853192.168.2.231.1.1.1
                                                                                                                            Dec 20, 2024 06:37:58.606539011 CET53363781.1.1.1192.168.2.23
                                                                                                                            Dec 20, 2024 06:37:58.614749908 CET5837053192.168.2.231.1.1.1
                                                                                                                            Dec 20, 2024 06:37:59.155884027 CET53583701.1.1.1192.168.2.23
                                                                                                                            Dec 20, 2024 06:37:59.420727015 CET3386053192.168.2.231.1.1.1
                                                                                                                            Dec 20, 2024 06:37:59.427968025 CET6036253192.168.2.231.1.1.1
                                                                                                                            Dec 20, 2024 06:37:59.952459097 CET53338601.1.1.1192.168.2.23
                                                                                                                            Dec 20, 2024 06:37:59.968069077 CET4043653192.168.2.231.1.1.1
                                                                                                                            Dec 20, 2024 06:37:59.970781088 CET53603621.1.1.1192.168.2.23
                                                                                                                            Dec 20, 2024 06:38:00.511400938 CET53404361.1.1.1192.168.2.23
                                                                                                                            Dec 20, 2024 06:38:01.568188906 CET5161453192.168.2.231.1.1.1
                                                                                                                            Dec 20, 2024 06:38:02.101908922 CET53516141.1.1.1192.168.2.23
                                                                                                                            Dec 20, 2024 06:38:02.121794939 CET4673653192.168.2.231.1.1.1
                                                                                                                            Dec 20, 2024 06:38:02.467175007 CET53467361.1.1.1192.168.2.23
                                                                                                                            Dec 20, 2024 06:38:02.492588043 CET3335853192.168.2.231.1.1.1
                                                                                                                            Dec 20, 2024 06:38:03.083648920 CET53333581.1.1.1192.168.2.23
                                                                                                                            Dec 20, 2024 06:38:06.574126959 CET5419653192.168.2.231.1.1.1
                                                                                                                            Dec 20, 2024 06:38:07.117074013 CET53541961.1.1.1192.168.2.23
                                                                                                                            Dec 20, 2024 06:38:07.133510113 CET5419653192.168.2.231.1.1.1
                                                                                                                            Dec 20, 2024 06:38:07.470978022 CET53541961.1.1.1192.168.2.23
                                                                                                                            Dec 20, 2024 06:38:07.490880966 CET4920653192.168.2.231.1.1.1
                                                                                                                            Dec 20, 2024 06:38:07.833103895 CET53492061.1.1.1192.168.2.23
                                                                                                                            Dec 20, 2024 06:38:11.583800077 CET5170353192.168.2.231.1.1.1
                                                                                                                            Dec 20, 2024 06:38:12.122204065 CET53517031.1.1.1192.168.2.23
                                                                                                                            Dec 20, 2024 06:38:12.141634941 CET3513653192.168.2.231.1.1.1
                                                                                                                            Dec 20, 2024 06:38:12.483825922 CET53351361.1.1.1192.168.2.23
                                                                                                                            Dec 20, 2024 06:38:12.508040905 CET5788653192.168.2.231.1.1.1
                                                                                                                            Dec 20, 2024 06:38:12.846941948 CET53578861.1.1.1192.168.2.23
                                                                                                                            Dec 20, 2024 06:38:16.603245020 CET3792553192.168.2.231.1.1.1
                                                                                                                            Dec 20, 2024 06:38:17.148209095 CET53379251.1.1.1192.168.2.23
                                                                                                                            Dec 20, 2024 06:38:17.171715021 CET4131253192.168.2.231.1.1.1
                                                                                                                            Dec 20, 2024 06:38:17.510284901 CET53413121.1.1.1192.168.2.23
                                                                                                                            Dec 20, 2024 06:38:17.536622047 CET5332153192.168.2.231.1.1.1
                                                                                                                            Dec 20, 2024 06:38:17.869736910 CET53533211.1.1.1192.168.2.23
                                                                                                                            Dec 20, 2024 06:38:21.595040083 CET5861253192.168.2.231.1.1.1
                                                                                                                            Dec 20, 2024 06:38:22.136349916 CET53586121.1.1.1192.168.2.23
                                                                                                                            Dec 20, 2024 06:38:22.155175924 CET5150153192.168.2.231.1.1.1
                                                                                                                            Dec 20, 2024 06:38:22.490092039 CET53515011.1.1.1192.168.2.23
                                                                                                                            Dec 20, 2024 06:38:22.513729095 CET4133953192.168.2.231.1.1.1
                                                                                                                            Dec 20, 2024 06:38:22.851721048 CET53413391.1.1.1192.168.2.23
                                                                                                                            Dec 20, 2024 06:38:26.604880095 CET3849853192.168.2.231.1.1.1
                                                                                                                            Dec 20, 2024 06:38:27.136372089 CET53384981.1.1.1192.168.2.23
                                                                                                                            Dec 20, 2024 06:38:27.150755882 CET3890253192.168.2.231.1.1.1
                                                                                                                            Dec 20, 2024 06:38:27.484457970 CET53389021.1.1.1192.168.2.23
                                                                                                                            Dec 20, 2024 06:38:27.501482964 CET5845053192.168.2.231.1.1.1
                                                                                                                            Dec 20, 2024 06:38:27.839977026 CET53584501.1.1.1192.168.2.23
                                                                                                                            Dec 20, 2024 06:38:31.620085955 CET4092153192.168.2.231.1.1.1
                                                                                                                            Dec 20, 2024 06:38:32.160079956 CET53409211.1.1.1192.168.2.23
                                                                                                                            Dec 20, 2024 06:38:32.175044060 CET3760653192.168.2.231.1.1.1
                                                                                                                            Dec 20, 2024 06:38:32.516629934 CET53376061.1.1.1192.168.2.23
                                                                                                                            Dec 20, 2024 06:38:32.542566061 CET3883953192.168.2.231.1.1.1
                                                                                                                            Dec 20, 2024 06:38:32.884562969 CET53388391.1.1.1192.168.2.23
                                                                                                                            Dec 20, 2024 06:38:36.618196964 CET4926353192.168.2.231.1.1.1
                                                                                                                            Dec 20, 2024 06:38:37.200695992 CET53492631.1.1.1192.168.2.23
                                                                                                                            Dec 20, 2024 06:38:37.223958969 CET5109553192.168.2.231.1.1.1
                                                                                                                            Dec 20, 2024 06:38:37.556955099 CET53510951.1.1.1192.168.2.23
                                                                                                                            Dec 20, 2024 06:38:37.583077908 CET3408253192.168.2.231.1.1.1
                                                                                                                            Dec 20, 2024 06:38:37.928078890 CET53340821.1.1.1192.168.2.23
                                                                                                                            TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                                                                                                            Dec 20, 2024 06:37:54.539840937 CET192.168.2.231.1.1.10xdd3dStandard query (0)baakbvw6w8c8.0x0000b.fashionspeedy.comA (IP address)IN (0x0001)false
                                                                                                                            Dec 20, 2024 06:37:55.079189062 CET192.168.2.231.1.1.10x3a1dStandard query (0)115tmprb34212ahuq9t3ttp2.0x0000b.fashionspeedy.comA (IP address)IN (0x0001)false
                                                                                                                            Dec 20, 2024 06:37:55.428420067 CET192.168.2.231.1.1.10x2c97Standard query (0)115tmprb342e2k52e2rgb1ba.0x0000b.fashionspeedy.comA (IP address)IN (0x0001)false
                                                                                                                            Dec 20, 2024 06:37:55.776856899 CET192.168.2.231.1.1.10xf5b9Standard query (0)115tmprb3423ag0p028dm45r.0x0000b.fashionspeedy.comA (IP address)IN (0x0001)false
                                                                                                                            Dec 20, 2024 06:37:56.124275923 CET192.168.2.231.1.1.10x7c94Standard query (0)115tmprb342178wxd5vkv1vb.0x0000b.fashionspeedy.comA (IP address)IN (0x0001)false
                                                                                                                            Dec 20, 2024 06:37:56.474659920 CET192.168.2.231.1.1.10xd247Standard query (0)TupyuUtoigqF7iixMmz8.0x0000b.fashionspeedy.comA (IP address)IN (0x0001)false
                                                                                                                            Dec 20, 2024 06:37:56.820771933 CET192.168.2.231.1.1.10x933bStandard query (0)TupyuUtoi4hZpunhyTWd.0x0000b.fashionspeedy.comA (IP address)IN (0x0001)false
                                                                                                                            Dec 20, 2024 06:37:57.170161009 CET192.168.2.231.1.1.10x1aa4Standard query (0)TupyuUtohxAeqYUtAfPs.0x0000b.fashionspeedy.comA (IP address)IN (0x0001)false
                                                                                                                            Dec 20, 2024 06:37:57.515583038 CET192.168.2.231.1.1.10x5ac0Standard query (0)TupyuUtohiWxzTiWZHH8.0x0000b.fashionspeedy.comA (IP address)IN (0x0001)false
                                                                                                                            Dec 20, 2024 06:37:58.077814102 CET192.168.2.231.1.1.10x791cStandard query (0)Mw62Z54BGpKJJ5hjruTmztnkb486wDtKNBe2uzvgzGatAKeC4S4GJS816QctRcj.rPQxMhxDgA2ahi99Rj9soq1PCWbVb5ErQHRN6eDPkuSKEgayrvraiDjKA1HkXg5.Gwpquwu2KM42tzoLAZ1eZnGP1oTgN9qZyYrTjK8wGErbKLKVqcAVy7GEqNb8TV2.faECVRcTrdjT4R7Hk7TCX6Um3CGfEZA1M.0x0000b.fashionspeedy.com16IN (0x0001)false
                                                                                                                            Dec 20, 2024 06:37:58.614749908 CET192.168.2.231.1.1.10x853fStandard query (0)4CnUgx2oDuu5BASaYQhkvn6AsaitiXLmYAZfyUufgkiYPijFUD3DrpxJejZxwSS.nRinvj5paX1xmL4n4UAAqLq8TZuVHpDN84g9SZBZh3aavdq4r573iHmZLsCiyqX.zz6dTktLvtt9P7ZUQQq6rmiqRMQjg6Yyr42BcnXBHoEksYfyQ7.0x0000b.fashionspeedy.com16IN (0x0001)false
                                                                                                                            Dec 20, 2024 06:37:59.420727015 CET192.168.2.231.1.1.10x7667Standard query (0)Mzd5iuQhLXMwMXiys6YwGwufVZWE7kqUocyr1GnpAPP1G7Tk4xFe7n9r1H3KsSb.Hek1WF4o5PVHvhnye4etXGq8AdftECSx2ECjT9HUjHoX49AB2w2Xmd3JcEmnLbm.7yQD16mGRM5xUhFppydAjuvDYX6C6v3JrZwZT7a3c1iikpGgiA7TNbxTbZUYAKK.b1fzTin2pAK36Anv8Bmy6F3jv74xhFi6A.0x0000b.fashionspeedy.comA (IP address)IN (0x0001)false
                                                                                                                            Dec 20, 2024 06:37:59.427968025 CET192.168.2.231.1.1.10xe7a3Standard query (0)Mzd5iuQhLSzB5UWsS6NnrcprNDFArRJyq3opNgbTWfm5sDYznUkcyywDZxAsJSj.hJruBCTwjAG3DTKHFBFm9LBpv3vBrSrH6uJJNLevpcuuX8hoUyrqGfm6WDRAGUy.HuW5KfSXGdsmzFNAvF2H9u8vbtixZg1SytbzThn8ESwQbQ6XQfeKJFz553Bd29P.kGc4sJD14bbV8Ap6DCUMJTHLfqoYa3Kyt.0x0000b.fashionspeedy.comA (IP address)IN (0x0001)false
                                                                                                                            Dec 20, 2024 06:37:59.968069077 CET192.168.2.231.1.1.10x8374Standard query (0)xGW32EahCCdzEaHCDqi5Lc8g8z3GW8m5pZw3XNVbfpmgKqVfghmXc2i2eHcPXkf.cwLb2aaDGo3TdB.0x0000b.fashionspeedy.comA (IP address)IN (0x0001)false
                                                                                                                            Dec 20, 2024 06:38:01.568188906 CET192.168.2.231.1.1.10xe402Standard query (0)LpgEQkkyLpxogXsGx7uaT1fna3kwAwzPo844n7vckpmjMtQee8wpJ6pYvbCtejf.spVmVAwmPfKuhz5dpgrMmWLmjVFMY72UkdGj2ETKgSxnbti5LDCvww3wzjWciup.8oN7dDQtYH63EVjsSCGuoJAga.0x0000b.fashionspeedy.comA (IP address)IN (0x0001)false
                                                                                                                            Dec 20, 2024 06:38:02.121794939 CET192.168.2.231.1.1.10xcbe7Standard query (0)6NguVjUtpxjZqrhSF1ooGr6.0x0000b.fashionspeedy.com16IN (0x0001)false
                                                                                                                            Dec 20, 2024 06:38:02.492588043 CET192.168.2.231.1.1.10x9fd4Standard query (0)backbd6tv629a78.0x0000b.fashionspeedy.com16IN (0x0001)false
                                                                                                                            Dec 20, 2024 06:38:06.574126959 CET192.168.2.231.1.1.10x6dcfStandard query (0)LpgEQkkyVooaGYsXFdRadnJuqZQkYssynnifyVmroKb249PLerQ3W27ymdz99Rh.YXUSuEsRE4BpXVxU8dddyEGH4yXkn446H7hXfXLKmbpn7XAfsbhrbqD3mdp18cN.wHztikaoWM9n3VauRigdMw9Ey.0x0000b.fashionspeedy.comA (IP address)IN (0x0001)false
                                                                                                                            Dec 20, 2024 06:38:07.133510113 CET192.168.2.231.1.1.10x5d54Standard query (0)6NguVjUtpxjAgPtvJ3ssurk.0x0000b.fashionspeedy.com16IN (0x0001)false
                                                                                                                            Dec 20, 2024 06:38:07.490880966 CET192.168.2.231.1.1.10xc0e5Standard query (0)backbd6tv649a78.0x0000b.fashionspeedy.com16IN (0x0001)false
                                                                                                                            Dec 20, 2024 06:38:11.583800077 CET192.168.2.231.1.1.10x5996Standard query (0)LpgEQkkyEndY5ZimNJk211z3bwffTiWSkFT84VgLFwJGviHPYYgZQitY5HXBRi9.HaVQNzYSUTEyYUozY9uNKQTyjr6oSHAsiF5EQ7rCLNQ1M4ZYATjUv2KzvxKAG9j.CSgvkx37BS6WPho5W6GefGMPQ.0x0000b.fashionspeedy.comA (IP address)IN (0x0001)false
                                                                                                                            Dec 20, 2024 06:38:12.141634941 CET192.168.2.231.1.1.10x709Standard query (0)6NguVjUtpxjZqSFWf7X8YAJ.0x0000b.fashionspeedy.com16IN (0x0001)false
                                                                                                                            Dec 20, 2024 06:38:12.508040905 CET192.168.2.231.1.1.10x6ab7Standard query (0)backbd6tv669a78.0x0000b.fashionspeedy.com16IN (0x0001)false
                                                                                                                            Dec 20, 2024 06:38:16.603245020 CET192.168.2.231.1.1.10x242eStandard query (0)LpgEQkkyomTuWAYb3ghZCHQEkZoEzGBVVLjV9u1B5bGHUrmryVVtvYbQg4GFFaN.fPByvTkMs7DPLZoqBDNoZ4avFTbeGPyfW1byqPgCxyQRQfhwZzZRdYa9kL1DhxE.goYK3nfikf6CjXNZbaFuyQBrj.0x0000b.fashionspeedy.comA (IP address)IN (0x0001)false
                                                                                                                            Dec 20, 2024 06:38:17.171715021 CET192.168.2.231.1.1.10x7655Standard query (0)6NguVjUtpxjAQxc4g9np3yT.0x0000b.fashionspeedy.com16IN (0x0001)false
                                                                                                                            Dec 20, 2024 06:38:17.536622047 CET192.168.2.231.1.1.10x9040Standard query (0)backbd6tv689a78.0x0000b.fashionspeedy.com16IN (0x0001)false
                                                                                                                            Dec 20, 2024 06:38:21.595040083 CET192.168.2.231.1.1.10xca6dStandard query (0)LpgEQkkyxkjgvbLBCkkTxFq8kLQbBJp54js4aWdBfWiSPmMjNCRHmPpYsfgi7p1.7QVC7SwnPabjdrWDFxsPYx5QpVE8awcaNW9jCHd2sM7etTgHej9neCP4bRBx9cK.RnvVoQkovy7tntkTqif1T7Trz.0x0000b.fashionspeedy.comA (IP address)IN (0x0001)false
                                                                                                                            Dec 20, 2024 06:38:22.155175924 CET192.168.2.231.1.1.10x7196Standard query (0)6NguVjUtpxjZmQNcGyhyXSs.0x0000b.fashionspeedy.com16IN (0x0001)false
                                                                                                                            Dec 20, 2024 06:38:22.513729095 CET192.168.2.231.1.1.10x6387Standard query (0)backbd6tv609a78.0x0000b.fashionspeedy.com16IN (0x0001)false
                                                                                                                            Dec 20, 2024 06:38:26.604880095 CET192.168.2.231.1.1.10x1e9eStandard query (0)LpgEQkkz7J8ELCapaniKZoZ2yFZhtSemCFMmFwK7BgoyUQELQQAPDyq9mgXU6fi.Rux3RE2CB3JuefKSU5bpYrY1dg6dvRnCBYDaoEwKHkW1w6dzc6TyvJA5GV4XGus.NUh8RsfJUinSsogxxeXKwSgsA.0x0000b.fashionspeedy.comA (IP address)IN (0x0001)false
                                                                                                                            Dec 20, 2024 06:38:27.150755882 CET192.168.2.231.1.1.10x2c8eStandard query (0)6NguVjUtpxjA467DrF1aAq5.0x0000b.fashionspeedy.com16IN (0x0001)false
                                                                                                                            Dec 20, 2024 06:38:27.501482964 CET192.168.2.231.1.1.10xe9b6Standard query (0)backbd6tv6r9a78.0x0000b.fashionspeedy.com16IN (0x0001)false
                                                                                                                            Dec 20, 2024 06:38:31.620085955 CET192.168.2.231.1.1.10x5fb4Standard query (0)LpgEQkkzghy2kd7MojE5wQvkWzaLPpmGEnZ5UsCsPGvB68ZrHggdy1dCb9yyEdG.VkiS2PnCHaRTTZQbZPAjPfgzHPanFfMmPjE2XPzChTfqkH4QQP87n4K1WSgyyy7.6LCexTfHivZHQzigxLtNkWnA5.0x0000b.fashionspeedy.comA (IP address)IN (0x0001)false
                                                                                                                            Dec 20, 2024 06:38:32.175044060 CET192.168.2.231.1.1.10xb8b9Standard query (0)6NguVjUtpxjAMRhGquqNTTi.0x0000b.fashionspeedy.com16IN (0x0001)false
                                                                                                                            Dec 20, 2024 06:38:32.542566061 CET192.168.2.231.1.1.10x1fb2Standard query (0)backbd6tv6w9a78.0x0000b.fashionspeedy.com16IN (0x0001)false
                                                                                                                            Dec 20, 2024 06:38:36.618196964 CET192.168.2.231.1.1.10x5b81Standard query (0)LpgEQkkzRGoPadxTisdqnEFACAJSoZDSuoq3JZgxxnMEsq6ZM2yWier9RWkWVCh.ECGPk71LpMHrm7xN8BkPRqYZZvR1uGj7yGXxLTDzyVh4yjQCA9VrYCkwLaxUVut.1asxRvqpwaHPs4Wu82Z5gMQp3.0x0000b.fashionspeedy.comA (IP address)IN (0x0001)false
                                                                                                                            Dec 20, 2024 06:38:37.223958969 CET192.168.2.231.1.1.10xced0Standard query (0)6NguVjUtpxjZuiEWRV6LPTX.0x0000b.fashionspeedy.com16IN (0x0001)false
                                                                                                                            Dec 20, 2024 06:38:37.583077908 CET192.168.2.231.1.1.10xcc1bStandard query (0)backbd6tvha9a78.0x0000b.fashionspeedy.com16IN (0x0001)false
                                                                                                                            TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                                                                                                            Dec 20, 2024 06:37:55.052867889 CET1.1.1.1192.168.2.230xdd3dNo error (0)baakbvw6w8c8.0x0000b.fashionspeedy.com149.204.54.100A (IP address)IN (0x0001)false
                                                                                                                            Dec 20, 2024 06:37:55.417562008 CET1.1.1.1192.168.2.230x3a1dNo error (0)115tmprb34212ahuq9t3ttp2.0x0000b.fashionspeedy.com94.75.140.75A (IP address)IN (0x0001)false
                                                                                                                            Dec 20, 2024 06:37:55.765086889 CET1.1.1.1192.168.2.230x2c97No error (0)115tmprb342e2k52e2rgb1ba.0x0000b.fashionspeedy.com213.124.170.103A (IP address)IN (0x0001)false
                                                                                                                            Dec 20, 2024 06:37:56.114483118 CET1.1.1.1192.168.2.230xf5b9No error (0)115tmprb3423ag0p028dm45r.0x0000b.fashionspeedy.com60.89.183.130A (IP address)IN (0x0001)false
                                                                                                                            Dec 20, 2024 06:37:56.462582111 CET1.1.1.1192.168.2.230x7c94No error (0)115tmprb342178wxd5vkv1vb.0x0000b.fashionspeedy.com140.118.21.128A (IP address)IN (0x0001)false
                                                                                                                            Dec 20, 2024 06:37:56.810877085 CET1.1.1.1192.168.2.230xd247No error (0)TupyuUtoigqF7iixMmz8.0x0000b.fashionspeedy.com174.67.41.211A (IP address)IN (0x0001)false
                                                                                                                            Dec 20, 2024 06:37:57.158107042 CET1.1.1.1192.168.2.230x933bNo error (0)TupyuUtoi4hZpunhyTWd.0x0000b.fashionspeedy.com23.246.61.199A (IP address)IN (0x0001)false
                                                                                                                            Dec 20, 2024 06:37:57.505120039 CET1.1.1.1192.168.2.230x1aa4No error (0)TupyuUtohxAeqYUtAfPs.0x0000b.fashionspeedy.com136.242.140.131A (IP address)IN (0x0001)false
                                                                                                                            Dec 20, 2024 06:37:57.851263046 CET1.1.1.1192.168.2.230x5ac0No error (0)TupyuUtohiWxzTiWZHH8.0x0000b.fashionspeedy.com169.172.33.210A (IP address)IN (0x0001)false
                                                                                                                            Dec 20, 2024 06:37:58.606539011 CET1.1.1.1192.168.2.230x791cNo error (0)Mw62Z54BGpKJJ5hjruTmztnkb486wDtKNBe2uzvgzGatAKeC4S4GJS816QctRcj.rPQxMhxDgA2ahi99Rj9soq1PCWbVb5ErQHRN6eDPkuSKEgayrvraiDjKA1HkXg5.Gwpquwu2KM42tzoLAZ1eZnGP1oTgN9qZyYrTjK8wGErbKLKVqcAVy7GEqNb8TV2.faECVRcTrdjT4R7Hk7TCX6Um3CGfEZA1M.0x0000b.fashionspeedy.comTXT (Text strings)IN (0x0001)false
                                                                                                                            Dec 20, 2024 06:37:59.155884027 CET1.1.1.1192.168.2.230x853fNo error (0)4CnUgx2oDuu5BASaYQhkvn6AsaitiXLmYAZfyUufgkiYPijFUD3DrpxJejZxwSS.nRinvj5paX1xmL4n4UAAqLq8TZuVHpDN84g9SZBZh3aavdq4r573iHmZLsCiyqX.zz6dTktLvtt9P7ZUQQq6rmiqRMQjg6Yyr42BcnXBHoEksYfyQ7.0x0000b.fashionspeedy.comTXT (Text strings)IN (0x0001)false
                                                                                                                            Dec 20, 2024 06:37:59.952459097 CET1.1.1.1192.168.2.230x7667No error (0)Mzd5iuQhLXMwMXiys6YwGwufVZWE7kqUocyr1GnpAPP1G7Tk4xFe7n9r1H3KsSb.Hek1WF4o5PVHvhnye4etXGq8AdftECSx2ECjT9HUjHoX49AB2w2Xmd3JcEmnLbm.7yQD16mGRM5xUhFppydAjuvDYX6C6v3JrZwZT7a3c1iikpGgiA7TNbxTbZUYAKK.b1fzTin2pAK36Anv8Bmy6F3jv74xhFi6A.0x0000b.fashionspeedy.com151.207.180.104A (IP address)IN (0x0001)false
                                                                                                                            Dec 20, 2024 06:37:59.970781088 CET1.1.1.1192.168.2.230xe7a3No error (0)Mzd5iuQhLSzB5UWsS6NnrcprNDFArRJyq3opNgbTWfm5sDYznUkcyywDZxAsJSj.hJruBCTwjAG3DTKHFBFm9LBpv3vBrSrH6uJJNLevpcuuX8hoUyrqGfm6WDRAGUy.HuW5KfSXGdsmzFNAvF2H9u8vbtixZg1SytbzThn8ESwQbQ6XQfeKJFz553Bd29P.kGc4sJD14bbV8Ap6DCUMJTHLfqoYa3Kyt.0x0000b.fashionspeedy.com189.139.47.107A (IP address)IN (0x0001)false
                                                                                                                            Dec 20, 2024 06:38:00.511400938 CET1.1.1.1192.168.2.230x8374No error (0)xGW32EahCCdzEaHCDqi5Lc8g8z3GW8m5pZw3XNVbfpmgKqVfghmXc2i2eHcPXkf.cwLb2aaDGo3TdB.0x0000b.fashionspeedy.com188.42.251.108A (IP address)IN (0x0001)false
                                                                                                                            Dec 20, 2024 06:38:02.101908922 CET1.1.1.1192.168.2.230xe402No error (0)LpgEQkkyLpxogXsGx7uaT1fna3kwAwzPo844n7vckpmjMtQee8wpJ6pYvbCtejf.spVmVAwmPfKuhz5dpgrMmWLmjVFMY72UkdGj2ETKgSxnbti5LDCvww3wzjWciup.8oN7dDQtYH63EVjsSCGuoJAga.0x0000b.fashionspeedy.com113.123.132.238A (IP address)IN (0x0001)false
                                                                                                                            Dec 20, 2024 06:38:02.467175007 CET1.1.1.1192.168.2.230xcbe7No error (0)6NguVjUtpxjZqrhSF1ooGr6.0x0000b.fashionspeedy.comTXT (Text strings)IN (0x0001)false
                                                                                                                            Dec 20, 2024 06:38:03.083648920 CET1.1.1.1192.168.2.230x9fd4No error (0)backbd6tv629a78.0x0000b.fashionspeedy.comTXT (Text strings)IN (0x0001)false
                                                                                                                            Dec 20, 2024 06:38:07.117074013 CET1.1.1.1192.168.2.230x6dcfNo error (0)LpgEQkkyVooaGYsXFdRadnJuqZQkYssynnifyVmroKb249PLerQ3W27ymdz99Rh.YXUSuEsRE4BpXVxU8dddyEGH4yXkn446H7hXfXLKmbpn7XAfsbhrbqD3mdp18cN.wHztikaoWM9n3VauRigdMw9Ey.0x0000b.fashionspeedy.com63.44.145.189A (IP address)IN (0x0001)false
                                                                                                                            Dec 20, 2024 06:38:07.470978022 CET1.1.1.1192.168.2.230x5d54No error (0)6NguVjUtpxjAgPtvJ3ssurk.0x0000b.fashionspeedy.comTXT (Text strings)IN (0x0001)false
                                                                                                                            Dec 20, 2024 06:38:07.833103895 CET1.1.1.1192.168.2.230xc0e5No error (0)backbd6tv649a78.0x0000b.fashionspeedy.comTXT (Text strings)IN (0x0001)false
                                                                                                                            Dec 20, 2024 06:38:12.122204065 CET1.1.1.1192.168.2.230x5996No error (0)LpgEQkkyEndY5ZimNJk211z3bwffTiWSkFT84VgLFwJGviHPYYgZQitY5HXBRi9.HaVQNzYSUTEyYUozY9uNKQTyjr6oSHAsiF5EQ7rCLNQ1M4ZYATjUv2KzvxKAG9j.CSgvkx37BS6WPho5W6GefGMPQ.0x0000b.fashionspeedy.com81.64.129.31A (IP address)IN (0x0001)false
                                                                                                                            Dec 20, 2024 06:38:12.483825922 CET1.1.1.1192.168.2.230x709No error (0)6NguVjUtpxjZqSFWf7X8YAJ.0x0000b.fashionspeedy.comTXT (Text strings)IN (0x0001)false
                                                                                                                            Dec 20, 2024 06:38:12.846941948 CET1.1.1.1192.168.2.230x6ab7No error (0)backbd6tv669a78.0x0000b.fashionspeedy.comTXT (Text strings)IN (0x0001)false
                                                                                                                            Dec 20, 2024 06:38:17.148209095 CET1.1.1.1192.168.2.230x242eNo error (0)LpgEQkkyomTuWAYb3ghZCHQEkZoEzGBVVLjV9u1B5bGHUrmryVVtvYbQg4GFFaN.fPByvTkMs7DPLZoqBDNoZ4avFTbeGPyfW1byqPgCxyQRQfhwZzZRdYa9kL1DhxE.goYK3nfikf6CjXNZbaFuyQBrj.0x0000b.fashionspeedy.com141.84.66.169A (IP address)IN (0x0001)false
                                                                                                                            Dec 20, 2024 06:38:17.510284901 CET1.1.1.1192.168.2.230x7655No error (0)6NguVjUtpxjAQxc4g9np3yT.0x0000b.fashionspeedy.comTXT (Text strings)IN (0x0001)false
                                                                                                                            Dec 20, 2024 06:38:17.869736910 CET1.1.1.1192.168.2.230x9040No error (0)backbd6tv689a78.0x0000b.fashionspeedy.comTXT (Text strings)IN (0x0001)false
                                                                                                                            Dec 20, 2024 06:38:22.136349916 CET1.1.1.1192.168.2.230xca6dNo error (0)LpgEQkkyxkjgvbLBCkkTxFq8kLQbBJp54js4aWdBfWiSPmMjNCRHmPpYsfgi7p1.7QVC7SwnPabjdrWDFxsPYx5QpVE8awcaNW9jCHd2sM7etTgHej9neCP4bRBx9cK.RnvVoQkovy7tntkTqif1T7Trz.0x0000b.fashionspeedy.com9.186.159.28A (IP address)IN (0x0001)false
                                                                                                                            Dec 20, 2024 06:38:22.490092039 CET1.1.1.1192.168.2.230x7196No error (0)6NguVjUtpxjZmQNcGyhyXSs.0x0000b.fashionspeedy.comTXT (Text strings)IN (0x0001)false
                                                                                                                            Dec 20, 2024 06:38:22.851721048 CET1.1.1.1192.168.2.230x6387No error (0)backbd6tv609a78.0x0000b.fashionspeedy.comTXT (Text strings)IN (0x0001)false
                                                                                                                            Dec 20, 2024 06:38:27.136372089 CET1.1.1.1192.168.2.230x1e9eNo error (0)LpgEQkkz7J8ELCapaniKZoZ2yFZhtSemCFMmFwK7BgoyUQELQQAPDyq9mgXU6fi.Rux3RE2CB3JuefKSU5bpYrY1dg6dvRnCBYDaoEwKHkW1w6dzc6TyvJA5GV4XGus.NUh8RsfJUinSsogxxeXKwSgsA.0x0000b.fashionspeedy.com236.100.54.38A (IP address)IN (0x0001)false
                                                                                                                            Dec 20, 2024 06:38:27.484457970 CET1.1.1.1192.168.2.230x2c8eNo error (0)6NguVjUtpxjA467DrF1aAq5.0x0000b.fashionspeedy.comTXT (Text strings)IN (0x0001)false
                                                                                                                            Dec 20, 2024 06:38:27.839977026 CET1.1.1.1192.168.2.230xe9b6No error (0)backbd6tv6r9a78.0x0000b.fashionspeedy.comTXT (Text strings)IN (0x0001)false
                                                                                                                            Dec 20, 2024 06:38:32.160079956 CET1.1.1.1192.168.2.230x5fb4No error (0)LpgEQkkzghy2kd7MojE5wQvkWzaLPpmGEnZ5UsCsPGvB68ZrHggdy1dCb9yyEdG.VkiS2PnCHaRTTZQbZPAjPfgzHPanFfMmPjE2XPzChTfqkH4QQP87n4K1WSgyyy7.6LCexTfHivZHQzigxLtNkWnA5.0x0000b.fashionspeedy.com16.45.183.202A (IP address)IN (0x0001)false
                                                                                                                            Dec 20, 2024 06:38:32.516629934 CET1.1.1.1192.168.2.230xb8b9No error (0)6NguVjUtpxjAMRhGquqNTTi.0x0000b.fashionspeedy.comTXT (Text strings)IN (0x0001)false
                                                                                                                            Dec 20, 2024 06:38:32.884562969 CET1.1.1.1192.168.2.230x1fb2No error (0)backbd6tv6w9a78.0x0000b.fashionspeedy.comTXT (Text strings)IN (0x0001)false
                                                                                                                            Dec 20, 2024 06:38:37.200695992 CET1.1.1.1192.168.2.230x5b81No error (0)LpgEQkkzRGoPadxTisdqnEFACAJSoZDSuoq3JZgxxnMEsq6ZM2yWier9RWkWVCh.ECGPk71LpMHrm7xN8BkPRqYZZvR1uGj7yGXxLTDzyVh4yjQCA9VrYCkwLaxUVut.1asxRvqpwaHPs4Wu82Z5gMQp3.0x0000b.fashionspeedy.com196.143.62.182A (IP address)IN (0x0001)false
                                                                                                                            Dec 20, 2024 06:38:37.556955099 CET1.1.1.1192.168.2.230xced0No error (0)6NguVjUtpxjZuiEWRV6LPTX.0x0000b.fashionspeedy.comTXT (Text strings)IN (0x0001)false
                                                                                                                            Dec 20, 2024 06:38:37.928078890 CET1.1.1.1192.168.2.230xcc1bNo error (0)backbd6tvha9a78.0x0000b.fashionspeedy.comTXT (Text strings)IN (0x0001)false

                                                                                                                            System Behavior

                                                                                                                            Start time (UTC):05:37:53
                                                                                                                            Start date (UTC):20/12/2024
                                                                                                                            Path:/tmp/CONSTANT_STRATEGY.elf
                                                                                                                            Arguments:/tmp/CONSTANT_STRATEGY.elf
                                                                                                                            File size:13884704 bytes
                                                                                                                            MD5 hash:abbf52dd16b588944358ad6b92dd55b0