Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
zmap.x86.elf

Overview

General Information

Sample name:zmap.x86.elf
Analysis ID:1580388
MD5:7779c9056b747f05d9d0b5033f58080f
SHA1:adbd9c8299eb02f34460587ade84e13c8afaf732
SHA256:4bc210de5a0d0660b3f36c21486b94fbc2d447c4306824b4e6b95349023d7510
Tags:elfuser-abuse_ch
Infos:

Detection

Okiru
Score:72
Range:0 - 100
Whitelisted:false

Signatures

Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Yara detected Okiru
Machine Learning detection for sample
Sample deletes itself
Detected TCP or UDP traffic on non-standard ports
Sample has stripped symbol table
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Yara signature match

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1580388
Start date and time:2024-12-24 12:57:06 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 25s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:zmap.x86.elf
Detection:MAL
Classification:mal72.troj.evad.linELF@0/0@8/0
  • VT rate limit hit for: zmap.x86.elf
Command:/tmp/zmap.x86.elf
PID:6231
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
VagneRHere
Standard Error:
  • system is lnxubuntu20
  • zmap.x86.elf (PID: 6231, Parent: 6156, MD5: 7779c9056b747f05d9d0b5033f58080f) Arguments: /tmp/zmap.x86.elf
  • cleanup
SourceRuleDescriptionAuthorStrings
zmap.x86.elfJoeSecurity_OkiruYara detected OkiruJoe Security
    zmap.x86.elfLinux_Trojan_Mirai_b14f4c5dunknownunknown
    • 0xb20:$a: 53 31 DB 8B 4C 24 0C 8B 54 24 08 83 F9 01 76 15 66 8B 02 83 E9 02 25 FF FF 00 00 83 C2 02 01 C3 83 F9 01 77 EB 49 75 05 0F BE 02 01 C3
    zmap.x86.elfLinux_Trojan_Mirai_88de437funknownunknown
    • 0x84e2:$a: 24 08 8B 4C 24 04 85 D2 74 0D 31 C0 89 F6 C6 04 08 00 40 39 D0
    zmap.x86.elfLinux_Trojan_Mirai_389ee3e9unknownunknown
    • 0xb670:$a: 89 45 00 EB 2C 8B 4B 04 8B 13 8B 7B 18 8B 01 01 02 8B 02 83
    zmap.x86.elfLinux_Trojan_Mirai_cc93863bunknownunknown
    • 0x9f91:$a: C3 57 8B 44 24 0C 8B 4C 24 10 8B 7C 24 08 F3 AA 8B 44 24 08
    Click to see the 1 entries
    SourceRuleDescriptionAuthorStrings
    6233.1.0000000008048000.0000000008057000.r-x.sdmpJoeSecurity_OkiruYara detected OkiruJoe Security
      6233.1.0000000008048000.0000000008057000.r-x.sdmpLinux_Trojan_Mirai_b14f4c5dunknownunknown
      • 0xb20:$a: 53 31 DB 8B 4C 24 0C 8B 54 24 08 83 F9 01 76 15 66 8B 02 83 E9 02 25 FF FF 00 00 83 C2 02 01 C3 83 F9 01 77 EB 49 75 05 0F BE 02 01 C3
      6233.1.0000000008048000.0000000008057000.r-x.sdmpLinux_Trojan_Mirai_88de437funknownunknown
      • 0x84e2:$a: 24 08 8B 4C 24 04 85 D2 74 0D 31 C0 89 F6 C6 04 08 00 40 39 D0
      6233.1.0000000008048000.0000000008057000.r-x.sdmpLinux_Trojan_Mirai_389ee3e9unknownunknown
      • 0xb670:$a: 89 45 00 EB 2C 8B 4B 04 8B 13 8B 7B 18 8B 01 01 02 8B 02 83
      6233.1.0000000008048000.0000000008057000.r-x.sdmpLinux_Trojan_Mirai_cc93863bunknownunknown
      • 0x9f91:$a: C3 57 8B 44 24 0C 8B 4C 24 10 8B 7C 24 08 F3 AA 8B 44 24 08
      Click to see the 9 entries
      No Suricata rule has matched

      Click to jump to signature section

      Show All Signature Results

      AV Detection

      barindex
      Source: zmap.x86.elfReversingLabs: Detection: 60%
      Source: zmap.x86.elfJoe Sandbox ML: detected
      Source: global trafficTCP traffic: 192.168.2.23:39538 -> 185.196.8.105:59962
      Source: global trafficTCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
      Source: global trafficTCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
      Source: global trafficTCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
      Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
      Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
      Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
      Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
      Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
      Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
      Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
      Source: global trafficDNS traffic detected: DNS query: srvy.vlrt-gap.com
      Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443

      System Summary

      barindex
      Source: zmap.x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_b14f4c5d Author: unknown
      Source: zmap.x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_88de437f Author: unknown
      Source: zmap.x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_389ee3e9 Author: unknown
      Source: zmap.x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_cc93863b Author: unknown
      Source: zmap.x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_8aa7b5d3 Author: unknown
      Source: 6233.1.0000000008048000.0000000008057000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_b14f4c5d Author: unknown
      Source: 6233.1.0000000008048000.0000000008057000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_88de437f Author: unknown
      Source: 6233.1.0000000008048000.0000000008057000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_389ee3e9 Author: unknown
      Source: 6233.1.0000000008048000.0000000008057000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_cc93863b Author: unknown
      Source: 6233.1.0000000008048000.0000000008057000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_8aa7b5d3 Author: unknown
      Source: 6231.1.0000000008048000.0000000008057000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_b14f4c5d Author: unknown
      Source: 6231.1.0000000008048000.0000000008057000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_88de437f Author: unknown
      Source: 6231.1.0000000008048000.0000000008057000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_389ee3e9 Author: unknown
      Source: 6231.1.0000000008048000.0000000008057000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_cc93863b Author: unknown
      Source: 6231.1.0000000008048000.0000000008057000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_8aa7b5d3 Author: unknown
      Source: ELF static info symbol of initial sample.symtab present: no
      Source: zmap.x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_b14f4c5d os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = a70d052918dd2fbc66db241da6438015130f0fb6929229bfe573546fe98da817, id = b14f4c5d-054f-46e6-9fa8-3588f1ef68b7, last_modified = 2021-09-16
      Source: zmap.x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_88de437f reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = c19eb595c2b444a809bef8500c20342c9f46694d3018e268833f9b884133a1ea, id = 88de437f-9c98-4e1d-96c0-7b433c99886a, last_modified = 2021-09-16
      Source: zmap.x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_389ee3e9 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 59f2359dc1f41d385d639d157b4cd9fc73d76d8abb7cc09d47632bb4c9a39e6e, id = 389ee3e9-70c1-4c93-a999-292cf6ff1652, last_modified = 2022-01-26
      Source: zmap.x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_cc93863b reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = f3ecd30f0b511a8e92cfa642409d559e7612c3f57a1659ca46c77aca809a00ac, id = cc93863b-1050-40ba-9d02-5ec9ce6a3a28, last_modified = 2022-01-26
      Source: zmap.x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_8aa7b5d3 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 02a2c18c362df4b1fceb33f3b605586514ba9a00c7afedf71c04fa54d8146444, id = 8aa7b5d3-e1eb-4b55-b36a-0d3a242c06e9, last_modified = 2022-01-26
      Source: 6233.1.0000000008048000.0000000008057000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_b14f4c5d os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = a70d052918dd2fbc66db241da6438015130f0fb6929229bfe573546fe98da817, id = b14f4c5d-054f-46e6-9fa8-3588f1ef68b7, last_modified = 2021-09-16
      Source: 6233.1.0000000008048000.0000000008057000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_88de437f reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = c19eb595c2b444a809bef8500c20342c9f46694d3018e268833f9b884133a1ea, id = 88de437f-9c98-4e1d-96c0-7b433c99886a, last_modified = 2021-09-16
      Source: 6233.1.0000000008048000.0000000008057000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_389ee3e9 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 59f2359dc1f41d385d639d157b4cd9fc73d76d8abb7cc09d47632bb4c9a39e6e, id = 389ee3e9-70c1-4c93-a999-292cf6ff1652, last_modified = 2022-01-26
      Source: 6233.1.0000000008048000.0000000008057000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_cc93863b reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = f3ecd30f0b511a8e92cfa642409d559e7612c3f57a1659ca46c77aca809a00ac, id = cc93863b-1050-40ba-9d02-5ec9ce6a3a28, last_modified = 2022-01-26
      Source: 6233.1.0000000008048000.0000000008057000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_8aa7b5d3 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 02a2c18c362df4b1fceb33f3b605586514ba9a00c7afedf71c04fa54d8146444, id = 8aa7b5d3-e1eb-4b55-b36a-0d3a242c06e9, last_modified = 2022-01-26
      Source: 6231.1.0000000008048000.0000000008057000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_b14f4c5d os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = a70d052918dd2fbc66db241da6438015130f0fb6929229bfe573546fe98da817, id = b14f4c5d-054f-46e6-9fa8-3588f1ef68b7, last_modified = 2021-09-16
      Source: 6231.1.0000000008048000.0000000008057000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_88de437f reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = c19eb595c2b444a809bef8500c20342c9f46694d3018e268833f9b884133a1ea, id = 88de437f-9c98-4e1d-96c0-7b433c99886a, last_modified = 2021-09-16
      Source: 6231.1.0000000008048000.0000000008057000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_389ee3e9 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 59f2359dc1f41d385d639d157b4cd9fc73d76d8abb7cc09d47632bb4c9a39e6e, id = 389ee3e9-70c1-4c93-a999-292cf6ff1652, last_modified = 2022-01-26
      Source: 6231.1.0000000008048000.0000000008057000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_cc93863b reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = f3ecd30f0b511a8e92cfa642409d559e7612c3f57a1659ca46c77aca809a00ac, id = cc93863b-1050-40ba-9d02-5ec9ce6a3a28, last_modified = 2022-01-26
      Source: 6231.1.0000000008048000.0000000008057000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_8aa7b5d3 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 02a2c18c362df4b1fceb33f3b605586514ba9a00c7afedf71c04fa54d8146444, id = 8aa7b5d3-e1eb-4b55-b36a-0d3a242c06e9, last_modified = 2022-01-26
      Source: classification engineClassification label: mal72.troj.evad.linELF@0/0@8/0

      Hooking and other Techniques for Hiding and Protection

      barindex
      Source: /tmp/zmap.x86.elf (PID: 6231)File: /tmp/zmap.x86.elfJump to behavior

      Stealing of Sensitive Information

      barindex
      Source: Yara matchFile source: zmap.x86.elf, type: SAMPLE
      Source: Yara matchFile source: 6233.1.0000000008048000.0000000008057000.r-x.sdmp, type: MEMORY
      Source: Yara matchFile source: 6231.1.0000000008048000.0000000008057000.r-x.sdmp, type: MEMORY
      Source: Yara matchFile source: Process Memory Space: zmap.x86.elf PID: 6231, type: MEMORYSTR
      Source: Yara matchFile source: Process Memory Space: zmap.x86.elf PID: 6233, type: MEMORYSTR

      Remote Access Functionality

      barindex
      Source: Yara matchFile source: zmap.x86.elf, type: SAMPLE
      Source: Yara matchFile source: 6233.1.0000000008048000.0000000008057000.r-x.sdmp, type: MEMORY
      Source: Yara matchFile source: 6231.1.0000000008048000.0000000008057000.r-x.sdmp, type: MEMORY
      Source: Yara matchFile source: Process Memory Space: zmap.x86.elf PID: 6231, type: MEMORYSTR
      Source: Yara matchFile source: Process Memory Space: zmap.x86.elf PID: 6233, type: MEMORYSTR
      ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
      Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception1
      File Deletion
      OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
      Encrypted Channel
      Exfiltration Over Other Network MediumAbuse Accessibility Features
      CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
      Non-Standard Port
      Exfiltration Over BluetoothNetwork Denial of Service
      Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
      Non-Application Layer Protocol
      Automated ExfiltrationData Encrypted for Impact
      Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture2
      Application Layer Protocol
      Traffic DuplicationData Destruction
      No configs have been found
      Hide Legend

      Legend:

      • Process
      • Signature
      • Created File
      • DNS/IP Info
      • Is Dropped
      • Number of created Files
      • Is malicious
      • Internet
      SourceDetectionScannerLabelLink
      zmap.x86.elf61%ReversingLabsLinux.Trojan.LnxMirai
      zmap.x86.elf100%Joe Sandbox ML
      No Antivirus matches
      No Antivirus matches
      No Antivirus matches
      NameIPActiveMaliciousAntivirus DetectionReputation
      srvy.vlrt-gap.com
      185.196.8.105
      truefalse
        unknown
        • No. of IPs < 25%
        • 25% < No. of IPs < 50%
        • 50% < No. of IPs < 75%
        • 75% < No. of IPs
        IPDomainCountryFlagASNASN NameMalicious
        185.196.8.105
        srvy.vlrt-gap.comSwitzerland
        34888SIMPLECARRER2ITfalse
        109.202.202.202
        unknownSwitzerland
        13030INIT7CHfalse
        91.189.91.43
        unknownUnited Kingdom
        41231CANONICAL-ASGBfalse
        91.189.91.42
        unknownUnited Kingdom
        41231CANONICAL-ASGBfalse
        MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
        185.196.8.105zmap.arm.elfGet hashmaliciousMirai, OkiruBrowse
          109.202.202.202kpLwzBouH4.elfGet hashmaliciousUnknownBrowse
          • ch.archive.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_92.0%2bbuild3-0ubuntu0.20.04.1_amd64.deb
          91.189.91.43zmap.arm.elfGet hashmaliciousMirai, OkiruBrowse
            most-m68k.elfGet hashmaliciousUnknownBrowse
              arm7.elfGet hashmaliciousUnknownBrowse
                x86_64.nn.elfGet hashmaliciousOkiruBrowse
                  nshppc.elfGet hashmaliciousUnknownBrowse
                    nshsh4.elfGet hashmaliciousUnknownBrowse
                      Mozi.m.elfGet hashmaliciousUnknownBrowse
                        nshmips.elfGet hashmaliciousUnknownBrowse
                          Mozi.m.elfGet hashmaliciousUnknownBrowse
                            arm.elfGet hashmaliciousUnknownBrowse
                              91.189.91.42zmap.arm.elfGet hashmaliciousMirai, OkiruBrowse
                                most-m68k.elfGet hashmaliciousUnknownBrowse
                                  arm7.elfGet hashmaliciousUnknownBrowse
                                    x86_64.nn.elfGet hashmaliciousOkiruBrowse
                                      nshppc.elfGet hashmaliciousUnknownBrowse
                                        nshsh4.elfGet hashmaliciousUnknownBrowse
                                          Mozi.m.elfGet hashmaliciousUnknownBrowse
                                            nshmips.elfGet hashmaliciousUnknownBrowse
                                              Mozi.m.elfGet hashmaliciousUnknownBrowse
                                                arm.elfGet hashmaliciousUnknownBrowse
                                                  MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                  srvy.vlrt-gap.comzmap.arm.elfGet hashmaliciousMirai, OkiruBrowse
                                                  • 185.196.8.105
                                                  MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                  CANONICAL-ASGBzmap.arm.elfGet hashmaliciousMirai, OkiruBrowse
                                                  • 91.189.91.42
                                                  most-m68k.elfGet hashmaliciousUnknownBrowse
                                                  • 91.189.91.42
                                                  arm7.elfGet hashmaliciousUnknownBrowse
                                                  • 91.189.91.42
                                                  x86_64.nn.elfGet hashmaliciousOkiruBrowse
                                                  • 91.189.91.42
                                                  nshppc.elfGet hashmaliciousUnknownBrowse
                                                  • 91.189.91.42
                                                  nshsh4.elfGet hashmaliciousUnknownBrowse
                                                  • 91.189.91.42
                                                  Mozi.m.elfGet hashmaliciousUnknownBrowse
                                                  • 91.189.91.42
                                                  nshmips.elfGet hashmaliciousUnknownBrowse
                                                  • 91.189.91.42
                                                  Mozi.m.elfGet hashmaliciousUnknownBrowse
                                                  • 91.189.91.42
                                                  arm.elfGet hashmaliciousUnknownBrowse
                                                  • 91.189.91.42
                                                  CANONICAL-ASGBzmap.arm.elfGet hashmaliciousMirai, OkiruBrowse
                                                  • 91.189.91.42
                                                  most-m68k.elfGet hashmaliciousUnknownBrowse
                                                  • 91.189.91.42
                                                  arm7.elfGet hashmaliciousUnknownBrowse
                                                  • 91.189.91.42
                                                  x86_64.nn.elfGet hashmaliciousOkiruBrowse
                                                  • 91.189.91.42
                                                  nshppc.elfGet hashmaliciousUnknownBrowse
                                                  • 91.189.91.42
                                                  nshsh4.elfGet hashmaliciousUnknownBrowse
                                                  • 91.189.91.42
                                                  Mozi.m.elfGet hashmaliciousUnknownBrowse
                                                  • 91.189.91.42
                                                  nshmips.elfGet hashmaliciousUnknownBrowse
                                                  • 91.189.91.42
                                                  Mozi.m.elfGet hashmaliciousUnknownBrowse
                                                  • 91.189.91.42
                                                  arm.elfGet hashmaliciousUnknownBrowse
                                                  • 91.189.91.42
                                                  SIMPLECARRER2ITzmap.arm.elfGet hashmaliciousMirai, OkiruBrowse
                                                  • 185.196.8.105
                                                  DQmU06kq9I.exeGet hashmaliciousLiteHTTP BotBrowse
                                                  • 185.208.159.109
                                                  file.exeGet hashmaliciousLummaC, Amadey, Credential Flusher, LiteHTTP Bot, LummaC Stealer, Stealc, XmrigBrowse
                                                  • 185.208.159.109
                                                  file.exeGet hashmaliciousScreenConnect Tool, Amadey, RHADAMANTHYS, XWorm, XmrigBrowse
                                                  • 185.196.8.237
                                                  file.exeGet hashmaliciousAsyncRAT, VenomRATBrowse
                                                  • 185.208.158.187
                                                  Ziraat Bankasi Swift Mesaji.dqy.dllGet hashmaliciousAsyncRAT, VenomRATBrowse
                                                  • 185.208.158.187
                                                  file.exeGet hashmaliciousAsyncRAT, VenomRATBrowse
                                                  • 185.208.158.187
                                                  file.exeGet hashmaliciousAsyncRAT, VenomRATBrowse
                                                  • 185.208.158.187
                                                  lLNOwu1HG4.jsGet hashmaliciousRHADAMANTHYSBrowse
                                                  • 185.196.8.68
                                                  file.exeGet hashmaliciousPureLog Stealer, XWormBrowse
                                                  • 185.196.8.239
                                                  INIT7CHzmap.arm.elfGet hashmaliciousMirai, OkiruBrowse
                                                  • 109.202.202.202
                                                  most-m68k.elfGet hashmaliciousUnknownBrowse
                                                  • 109.202.202.202
                                                  arm7.elfGet hashmaliciousUnknownBrowse
                                                  • 109.202.202.202
                                                  x86_64.nn.elfGet hashmaliciousOkiruBrowse
                                                  • 109.202.202.202
                                                  nshppc.elfGet hashmaliciousUnknownBrowse
                                                  • 109.202.202.202
                                                  nshsh4.elfGet hashmaliciousUnknownBrowse
                                                  • 109.202.202.202
                                                  Mozi.m.elfGet hashmaliciousUnknownBrowse
                                                  • 109.202.202.202
                                                  nshmips.elfGet hashmaliciousUnknownBrowse
                                                  • 109.202.202.202
                                                  Mozi.m.elfGet hashmaliciousUnknownBrowse
                                                  • 109.202.202.202
                                                  arm.elfGet hashmaliciousUnknownBrowse
                                                  • 109.202.202.202
                                                  No context
                                                  No context
                                                  No created / dropped files found
                                                  File type:ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, stripped
                                                  Entropy (8bit):6.522678808965998
                                                  TrID:
                                                  • ELF Executable and Linkable format (Linux) (4029/14) 50.16%
                                                  • ELF Executable and Linkable format (generic) (4004/1) 49.84%
                                                  File name:zmap.x86.elf
                                                  File size:62'640 bytes
                                                  MD5:7779c9056b747f05d9d0b5033f58080f
                                                  SHA1:adbd9c8299eb02f34460587ade84e13c8afaf732
                                                  SHA256:4bc210de5a0d0660b3f36c21486b94fbc2d447c4306824b4e6b95349023d7510
                                                  SHA512:5ef8d9bc2187a8ffecdb2a346f35da9d1a93de779ee8d4c8e65a4c144ae97649de3d55e2515efc437f1c6a6b4afd8cd92879287c806fb1f2681fca01637d30df
                                                  SSDEEP:1536:1BGfyT5OGMMt4cesUTeFIv5TzHhq6g80CIjOepn2+:1caT5OGMMtmaATzBq6p07KanL
                                                  TLSH:8B534BC4E583DCFAEC5605705173EB368B77F13B1268DA87C7A89923F852B01E54629C
                                                  File Content Preview:.ELF....................d...4... .......4. ...(..............................................p...p.......*..........Q.td............................U..S.......w....h........[]...$.............U......=.r...t..5....$p.....$p......u........t....h.o..........

                                                  ELF header

                                                  Class:ELF32
                                                  Data:2's complement, little endian
                                                  Version:1 (current)
                                                  Machine:Intel 80386
                                                  Version Number:0x1
                                                  Type:EXEC (Executable file)
                                                  OS/ABI:UNIX - System V
                                                  ABI Version:0
                                                  Entry Point Address:0x8048164
                                                  Flags:0x0
                                                  ELF Header Size:52
                                                  Program Header Offset:52
                                                  Program Header Size:32
                                                  Number of Program Headers:3
                                                  Section Header Offset:62240
                                                  Section Header Size:40
                                                  Number of Section Headers:10
                                                  Header String Table Index:9
                                                  NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                                  NULL0x00x00x00x00x0000
                                                  .initPROGBITS0x80480940x940x1c0x00x6AX001
                                                  .textPROGBITS0x80480b00xb00xd1060x00x6AX0016
                                                  .finiPROGBITS0x80551b60xd1b60x170x00x6AX001
                                                  .rodataPROGBITS0x80551e00xd1e00x1e1c0x00x2A0032
                                                  .ctorsPROGBITS0x80570000xf0000x80x00x3WA004
                                                  .dtorsPROGBITS0x80570080xf0080x80x00x3WA004
                                                  .dataPROGBITS0x80570200xf0200x2c00x00x3WA0032
                                                  .bssNOBITS0x80572e00xf2e00x27c00x00x3WA0032
                                                  .shstrtabSTRTAB0x00xf2e00x3e0x00x0001
                                                  TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                  LOAD0x00x80480000x80480000xeffc0xeffc6.55670x5R E0x1000.init .text .fini .rodata
                                                  LOAD0xf0000x80570000x80570000x2e00x2aa03.73850x6RW 0x1000.ctors .dtors .data .bss
                                                  GNU_STACK0x00x00x00x00x00.00000x6RW 0x4
                                                  TimestampSource PortDest PortSource IPDest IP
                                                  Dec 24, 2024 12:57:50.111363888 CET3953859962192.168.2.23185.196.8.105
                                                  Dec 24, 2024 12:57:50.231511116 CET5996239538185.196.8.105192.168.2.23
                                                  Dec 24, 2024 12:57:50.231638908 CET3953859962192.168.2.23185.196.8.105
                                                  Dec 24, 2024 12:57:50.231683016 CET3953859962192.168.2.23185.196.8.105
                                                  Dec 24, 2024 12:57:50.351861000 CET5996239538185.196.8.105192.168.2.23
                                                  Dec 24, 2024 12:57:50.352008104 CET3953859962192.168.2.23185.196.8.105
                                                  Dec 24, 2024 12:57:50.471910954 CET5996239538185.196.8.105192.168.2.23
                                                  Dec 24, 2024 12:57:51.536281109 CET5996239538185.196.8.105192.168.2.23
                                                  Dec 24, 2024 12:57:51.536407948 CET3953859962192.168.2.23185.196.8.105
                                                  Dec 24, 2024 12:57:51.536462069 CET3953859962192.168.2.23185.196.8.105
                                                  Dec 24, 2024 12:57:51.669589043 CET43928443192.168.2.2391.189.91.42
                                                  Dec 24, 2024 12:57:51.898699999 CET3954059962192.168.2.23185.196.8.105
                                                  Dec 24, 2024 12:57:52.019120932 CET5996239540185.196.8.105192.168.2.23
                                                  Dec 24, 2024 12:57:52.019252062 CET3954059962192.168.2.23185.196.8.105
                                                  Dec 24, 2024 12:57:52.019361973 CET3954059962192.168.2.23185.196.8.105
                                                  Dec 24, 2024 12:57:52.139269114 CET5996239540185.196.8.105192.168.2.23
                                                  Dec 24, 2024 12:57:52.139389038 CET3954059962192.168.2.23185.196.8.105
                                                  Dec 24, 2024 12:57:52.259354115 CET5996239540185.196.8.105192.168.2.23
                                                  Dec 24, 2024 12:57:53.320395947 CET5996239540185.196.8.105192.168.2.23
                                                  Dec 24, 2024 12:57:53.320553064 CET3954059962192.168.2.23185.196.8.105
                                                  Dec 24, 2024 12:57:53.320652962 CET3954059962192.168.2.23185.196.8.105
                                                  Dec 24, 2024 12:57:53.454709053 CET3954259962192.168.2.23185.196.8.105
                                                  Dec 24, 2024 12:57:53.574529886 CET5996239542185.196.8.105192.168.2.23
                                                  Dec 24, 2024 12:57:53.574657917 CET3954259962192.168.2.23185.196.8.105
                                                  Dec 24, 2024 12:57:53.574875116 CET3954259962192.168.2.23185.196.8.105
                                                  Dec 24, 2024 12:57:53.694449902 CET5996239542185.196.8.105192.168.2.23
                                                  Dec 24, 2024 12:57:53.694762945 CET3954259962192.168.2.23185.196.8.105
                                                  Dec 24, 2024 12:57:53.814714909 CET5996239542185.196.8.105192.168.2.23
                                                  Dec 24, 2024 12:57:54.891304970 CET5996239542185.196.8.105192.168.2.23
                                                  Dec 24, 2024 12:57:54.891483068 CET3954259962192.168.2.23185.196.8.105
                                                  Dec 24, 2024 12:57:54.891483068 CET3954259962192.168.2.23185.196.8.105
                                                  Dec 24, 2024 12:57:55.026535988 CET3954459962192.168.2.23185.196.8.105
                                                  Dec 24, 2024 12:57:55.146461964 CET5996239544185.196.8.105192.168.2.23
                                                  Dec 24, 2024 12:57:55.146585941 CET3954459962192.168.2.23185.196.8.105
                                                  Dec 24, 2024 12:57:55.146769047 CET3954459962192.168.2.23185.196.8.105
                                                  Dec 24, 2024 12:57:55.266803980 CET5996239544185.196.8.105192.168.2.23
                                                  Dec 24, 2024 12:57:55.266900063 CET3954459962192.168.2.23185.196.8.105
                                                  Dec 24, 2024 12:57:55.386579037 CET5996239544185.196.8.105192.168.2.23
                                                  Dec 24, 2024 12:57:56.446378946 CET5996239544185.196.8.105192.168.2.23
                                                  Dec 24, 2024 12:57:56.446507931 CET3954459962192.168.2.23185.196.8.105
                                                  Dec 24, 2024 12:57:56.446620941 CET3954459962192.168.2.23185.196.8.105
                                                  Dec 24, 2024 12:57:56.811347008 CET3954659962192.168.2.23185.196.8.105
                                                  Dec 24, 2024 12:57:56.931364059 CET5996239546185.196.8.105192.168.2.23
                                                  Dec 24, 2024 12:57:56.931454897 CET3954659962192.168.2.23185.196.8.105
                                                  Dec 24, 2024 12:57:57.044681072 CET42836443192.168.2.2391.189.91.43
                                                  Dec 24, 2024 12:57:57.812599897 CET3954659962192.168.2.23185.196.8.105
                                                  Dec 24, 2024 12:57:57.932564974 CET5996239546185.196.8.105192.168.2.23
                                                  Dec 24, 2024 12:57:57.932656050 CET3954659962192.168.2.23185.196.8.105
                                                  Dec 24, 2024 12:57:57.932760000 CET3954659962192.168.2.23185.196.8.105
                                                  Dec 24, 2024 12:57:58.052753925 CET5996239546185.196.8.105192.168.2.23
                                                  Dec 24, 2024 12:57:58.052817106 CET3954659962192.168.2.23185.196.8.105
                                                  Dec 24, 2024 12:57:58.172667980 CET5996239546185.196.8.105192.168.2.23
                                                  Dec 24, 2024 12:57:58.580454111 CET4251680192.168.2.23109.202.202.202
                                                  Dec 24, 2024 12:57:59.329308987 CET5996239546185.196.8.105192.168.2.23
                                                  Dec 24, 2024 12:57:59.329629898 CET3954659962192.168.2.23185.196.8.105
                                                  Dec 24, 2024 12:57:59.329796076 CET3954659962192.168.2.23185.196.8.105
                                                  Dec 24, 2024 12:57:59.570888042 CET3954859962192.168.2.23185.196.8.105
                                                  Dec 24, 2024 12:57:59.690690041 CET5996239548185.196.8.105192.168.2.23
                                                  Dec 24, 2024 12:57:59.691104889 CET3954859962192.168.2.23185.196.8.105
                                                  Dec 24, 2024 12:57:59.691104889 CET3954859962192.168.2.23185.196.8.105
                                                  Dec 24, 2024 12:57:59.810982943 CET5996239548185.196.8.105192.168.2.23
                                                  Dec 24, 2024 12:57:59.811219931 CET3954859962192.168.2.23185.196.8.105
                                                  Dec 24, 2024 12:57:59.930942059 CET5996239548185.196.8.105192.168.2.23
                                                  Dec 24, 2024 12:58:00.988061905 CET5996239548185.196.8.105192.168.2.23
                                                  Dec 24, 2024 12:58:00.988581896 CET3954859962192.168.2.23185.196.8.105
                                                  Dec 24, 2024 12:58:00.988581896 CET3954859962192.168.2.23185.196.8.105
                                                  Dec 24, 2024 12:58:01.348762989 CET3955059962192.168.2.23185.196.8.105
                                                  Dec 24, 2024 12:58:01.468592882 CET5996239550185.196.8.105192.168.2.23
                                                  Dec 24, 2024 12:58:01.468909979 CET3955059962192.168.2.23185.196.8.105
                                                  Dec 24, 2024 12:58:01.468909979 CET3955059962192.168.2.23185.196.8.105
                                                  Dec 24, 2024 12:58:01.588609934 CET5996239550185.196.8.105192.168.2.23
                                                  Dec 24, 2024 12:58:01.589107037 CET3955059962192.168.2.23185.196.8.105
                                                  Dec 24, 2024 12:58:01.708782911 CET5996239550185.196.8.105192.168.2.23
                                                  Dec 24, 2024 12:58:02.777934074 CET5996239550185.196.8.105192.168.2.23
                                                  Dec 24, 2024 12:58:02.778343916 CET3955059962192.168.2.23185.196.8.105
                                                  Dec 24, 2024 12:58:02.778343916 CET3955059962192.168.2.23185.196.8.105
                                                  Dec 24, 2024 12:58:02.913286924 CET3955259962192.168.2.23185.196.8.105
                                                  Dec 24, 2024 12:58:03.033057928 CET5996239552185.196.8.105192.168.2.23
                                                  Dec 24, 2024 12:58:03.033365011 CET3955259962192.168.2.23185.196.8.105
                                                  Dec 24, 2024 12:58:03.033365011 CET3955259962192.168.2.23185.196.8.105
                                                  Dec 24, 2024 12:58:03.153085947 CET5996239552185.196.8.105192.168.2.23
                                                  Dec 24, 2024 12:58:03.153461933 CET3955259962192.168.2.23185.196.8.105
                                                  Dec 24, 2024 12:58:03.273231983 CET5996239552185.196.8.105192.168.2.23
                                                  Dec 24, 2024 12:58:12.146610975 CET43928443192.168.2.2391.189.91.42
                                                  Dec 24, 2024 12:58:13.042067051 CET3955259962192.168.2.23185.196.8.105
                                                  Dec 24, 2024 12:58:13.161823988 CET5996239552185.196.8.105192.168.2.23
                                                  Dec 24, 2024 12:58:13.472413063 CET5996239552185.196.8.105192.168.2.23
                                                  Dec 24, 2024 12:58:13.472630978 CET3955259962192.168.2.23185.196.8.105
                                                  Dec 24, 2024 12:58:24.432854891 CET42836443192.168.2.2391.189.91.43
                                                  Dec 24, 2024 12:58:28.528491020 CET4251680192.168.2.23109.202.202.202
                                                  Dec 24, 2024 12:58:53.100944996 CET43928443192.168.2.2391.189.91.42
                                                  Dec 24, 2024 12:59:13.474371910 CET3955259962192.168.2.23185.196.8.105
                                                  Dec 24, 2024 12:59:13.593913078 CET5996239552185.196.8.105192.168.2.23
                                                  Dec 24, 2024 12:59:13.897252083 CET5996239552185.196.8.105192.168.2.23
                                                  Dec 24, 2024 12:59:13.897370100 CET3955259962192.168.2.23185.196.8.105
                                                  TimestampSource PortDest PortSource IPDest IP
                                                  Dec 24, 2024 12:57:49.976443052 CET4821553192.168.2.238.8.8.8
                                                  Dec 24, 2024 12:57:50.111149073 CET53482158.8.8.8192.168.2.23
                                                  Dec 24, 2024 12:57:51.536511898 CET3397953192.168.2.238.8.8.8
                                                  Dec 24, 2024 12:57:51.898417950 CET53339798.8.8.8192.168.2.23
                                                  Dec 24, 2024 12:57:53.320653915 CET5820853192.168.2.238.8.8.8
                                                  Dec 24, 2024 12:57:53.454487085 CET53582088.8.8.8192.168.2.23
                                                  Dec 24, 2024 12:57:54.891565084 CET4291453192.168.2.238.8.8.8
                                                  Dec 24, 2024 12:57:55.026247025 CET53429148.8.8.8192.168.2.23
                                                  Dec 24, 2024 12:57:56.446701050 CET4909953192.168.2.238.8.8.8
                                                  Dec 24, 2024 12:57:56.811089039 CET53490998.8.8.8192.168.2.23
                                                  Dec 24, 2024 12:57:59.329916954 CET4296653192.168.2.238.8.8.8
                                                  Dec 24, 2024 12:57:59.570343971 CET53429668.8.8.8192.168.2.23
                                                  Dec 24, 2024 12:58:00.988492012 CET4707453192.168.2.238.8.8.8
                                                  Dec 24, 2024 12:58:01.348258972 CET53470748.8.8.8192.168.2.23
                                                  Dec 24, 2024 12:58:02.778228998 CET5328753192.168.2.238.8.8.8
                                                  Dec 24, 2024 12:58:02.913003922 CET53532878.8.8.8192.168.2.23
                                                  TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                                  Dec 24, 2024 12:57:49.976443052 CET192.168.2.238.8.8.80x16b2Standard query (0)srvy.vlrt-gap.comA (IP address)IN (0x0001)false
                                                  Dec 24, 2024 12:57:51.536511898 CET192.168.2.238.8.8.80xb823Standard query (0)srvy.vlrt-gap.comA (IP address)IN (0x0001)false
                                                  Dec 24, 2024 12:57:53.320653915 CET192.168.2.238.8.8.80xdcf8Standard query (0)srvy.vlrt-gap.comA (IP address)IN (0x0001)false
                                                  Dec 24, 2024 12:57:54.891565084 CET192.168.2.238.8.8.80xf005Standard query (0)srvy.vlrt-gap.comA (IP address)IN (0x0001)false
                                                  Dec 24, 2024 12:57:56.446701050 CET192.168.2.238.8.8.80x5a00Standard query (0)srvy.vlrt-gap.comA (IP address)IN (0x0001)false
                                                  Dec 24, 2024 12:57:59.329916954 CET192.168.2.238.8.8.80x9e5bStandard query (0)srvy.vlrt-gap.comA (IP address)IN (0x0001)false
                                                  Dec 24, 2024 12:58:00.988492012 CET192.168.2.238.8.8.80xac44Standard query (0)srvy.vlrt-gap.comA (IP address)IN (0x0001)false
                                                  Dec 24, 2024 12:58:02.778228998 CET192.168.2.238.8.8.80xf5fdStandard query (0)srvy.vlrt-gap.comA (IP address)IN (0x0001)false
                                                  TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                                  Dec 24, 2024 12:57:50.111149073 CET8.8.8.8192.168.2.230x16b2No error (0)srvy.vlrt-gap.com185.196.8.105A (IP address)IN (0x0001)false
                                                  Dec 24, 2024 12:57:51.898417950 CET8.8.8.8192.168.2.230xb823No error (0)srvy.vlrt-gap.com185.196.8.105A (IP address)IN (0x0001)false
                                                  Dec 24, 2024 12:57:53.454487085 CET8.8.8.8192.168.2.230xdcf8No error (0)srvy.vlrt-gap.com185.196.8.105A (IP address)IN (0x0001)false
                                                  Dec 24, 2024 12:57:55.026247025 CET8.8.8.8192.168.2.230xf005No error (0)srvy.vlrt-gap.com185.196.8.105A (IP address)IN (0x0001)false
                                                  Dec 24, 2024 12:57:56.811089039 CET8.8.8.8192.168.2.230x5a00No error (0)srvy.vlrt-gap.com185.196.8.105A (IP address)IN (0x0001)false
                                                  Dec 24, 2024 12:57:59.570343971 CET8.8.8.8192.168.2.230x9e5bNo error (0)srvy.vlrt-gap.com185.196.8.105A (IP address)IN (0x0001)false
                                                  Dec 24, 2024 12:58:01.348258972 CET8.8.8.8192.168.2.230xac44No error (0)srvy.vlrt-gap.com185.196.8.105A (IP address)IN (0x0001)false
                                                  Dec 24, 2024 12:58:02.913003922 CET8.8.8.8192.168.2.230xf5fdNo error (0)srvy.vlrt-gap.com185.196.8.105A (IP address)IN (0x0001)false

                                                  System Behavior

                                                  Start time (UTC):11:57:49
                                                  Start date (UTC):24/12/2024
                                                  Path:/tmp/zmap.x86.elf
                                                  Arguments:/tmp/zmap.x86.elf
                                                  File size:62640 bytes
                                                  MD5 hash:7779c9056b747f05d9d0b5033f58080f

                                                  Start time (UTC):11:57:49
                                                  Start date (UTC):24/12/2024
                                                  Path:/tmp/zmap.x86.elf
                                                  Arguments:-
                                                  File size:62640 bytes
                                                  MD5 hash:7779c9056b747f05d9d0b5033f58080f

                                                  Start time (UTC):11:57:49
                                                  Start date (UTC):24/12/2024
                                                  Path:/tmp/zmap.x86.elf
                                                  Arguments:-
                                                  File size:62640 bytes
                                                  MD5 hash:7779c9056b747f05d9d0b5033f58080f