Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
ub8ehJSePAfc9FYqZIT6.ppc.elf

Overview

General Information

Sample name:ub8ehJSePAfc9FYqZIT6.ppc.elf
Analysis ID:1581066
MD5:7d78600253837f3c2ed8ebe7a3476952
SHA1:9ca379e07406bcd3bc3c4ed606430017907e85c1
SHA256:f0039251c6ec39533feecd7b6585499ddb60094d845936d08f1a42cae327d70e
Tags:elfuser-abuse_ch
Infos:

Detection

Score:68
Range:0 - 100
Whitelisted:false

Signatures

Antivirus / Scanner detection for submitted sample
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Sample is packed with UPX
Detected TCP or UDP traffic on non-standard ports
ELF contains segments with high entropy indicating compressed/encrypted content
Enumerates processes within the "proc" file system
Sample contains only a LOAD segment without any section mappings
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Uses the "uname" system call to query kernel version information (possible evasion)
Yara signature match

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1581066
Start date and time:2024-12-26 22:06:06 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 5m 4s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:ub8ehJSePAfc9FYqZIT6.ppc.elf
Detection:MAL
Classification:mal68.evad.linELF@0/0@0/0
  • VT rate limit hit for: ub8ehJSePAfc9FYqZIT6.ppc.elf
Command:/tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf
PID:6267
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
lzrd cock fest"/proc/"/exe
Standard Error:
  • system is lnxubuntu20
  • cleanup
SourceRuleDescriptionAuthorStrings
6281.1.00007f917c014000.00007f917c017000.rwx.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0x350:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x364:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x378:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x38c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3a0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3b4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3c8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3dc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3f0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x404:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x418:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x42c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x440:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x454:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x468:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x47c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x490:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x4a4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x4b8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x4cc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x4e0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
6271.1.00007f917c014000.00007f917c017000.rwx.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0x350:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x364:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x378:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x38c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3a0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3b4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3c8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3dc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3f0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x404:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x418:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x42c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x440:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x454:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x468:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x47c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x490:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x4a4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x4b8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x4cc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x4e0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
6267.1.00007f917c014000.00007f917c017000.rwx.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0x350:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x364:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x378:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x38c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3a0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3b4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3c8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3dc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3f0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x404:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x418:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x42c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x440:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x454:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x468:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x47c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x490:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x4a4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x4b8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x4cc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x4e0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
6269.1.00007f917c014000.00007f917c017000.rwx.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0x350:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x364:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x378:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x38c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3a0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3b4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3c8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3dc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3f0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x404:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x418:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x42c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x440:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x454:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x468:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x47c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x490:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x4a4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x4b8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x4cc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x4e0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
Process Memory Space: ub8ehJSePAfc9FYqZIT6.ppc.elf PID: 6267Linux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0x4979:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x498d:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x49a1:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x49b5:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x49c9:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x49dd:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x49f1:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x4a05:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x4a19:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x4a2d:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x4a41:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x4a55:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x4a69:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x4a7d:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x4a91:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x4aa5:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x4ab9:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x4acd:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x4ae1:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x4af5:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x4b09:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
Click to see the 3 entries
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: ub8ehJSePAfc9FYqZIT6.ppc.elfAvira: detected
Source: ub8ehJSePAfc9FYqZIT6.ppc.elfReversingLabs: Detection: 42%
Source: global trafficTCP traffic: 192.168.2.23:55270 -> 92.118.56.167:3778
Source: global trafficTCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
Source: global trafficTCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
Source: global trafficTCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: ub8ehJSePAfc9FYqZIT6.ppc.elfString found in binary or memory: http://upx.sf.net
Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443

System Summary

barindex
Source: 6281.1.00007f917c014000.00007f917c017000.rwx.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: 6271.1.00007f917c014000.00007f917c017000.rwx.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: 6267.1.00007f917c014000.00007f917c017000.rwx.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: 6269.1.00007f917c014000.00007f917c017000.rwx.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: Process Memory Space: ub8ehJSePAfc9FYqZIT6.ppc.elf PID: 6267, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: Process Memory Space: ub8ehJSePAfc9FYqZIT6.ppc.elf PID: 6269, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: Process Memory Space: ub8ehJSePAfc9FYqZIT6.ppc.elf PID: 6271, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: Process Memory Space: ub8ehJSePAfc9FYqZIT6.ppc.elf PID: 6281, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: LOAD without section mappingsProgram segment: 0x100000
Source: 6281.1.00007f917c014000.00007f917c017000.rwx.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: 6271.1.00007f917c014000.00007f917c017000.rwx.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: 6267.1.00007f917c014000.00007f917c017000.rwx.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: 6269.1.00007f917c014000.00007f917c017000.rwx.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: Process Memory Space: ub8ehJSePAfc9FYqZIT6.ppc.elf PID: 6267, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: Process Memory Space: ub8ehJSePAfc9FYqZIT6.ppc.elf PID: 6269, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: Process Memory Space: ub8ehJSePAfc9FYqZIT6.ppc.elf PID: 6271, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: Process Memory Space: ub8ehJSePAfc9FYqZIT6.ppc.elf PID: 6281, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: classification engineClassification label: mal68.evad.linELF@0/0@0/0

Data Obfuscation

barindex
Source: initial sampleString containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $
Source: initial sampleString containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $
Source: initial sampleString containing UPX found: $Id: UPX 3.94 Copyright (C) 1996-2017 the UPX Team. All Rights Reserved. $
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6267)File opened: /proc/1582/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6267)File opened: /proc/3088/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6267)File opened: /proc/230/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6267)File opened: /proc/110/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6267)File opened: /proc/231/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6267)File opened: /proc/111/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6267)File opened: /proc/232/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6267)File opened: /proc/1579/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6267)File opened: /proc/112/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6267)File opened: /proc/233/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6267)File opened: /proc/1699/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6267)File opened: /proc/113/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6267)File opened: /proc/234/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6267)File opened: /proc/1335/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6267)File opened: /proc/1698/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6267)File opened: /proc/114/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6267)File opened: /proc/235/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6267)File opened: /proc/1334/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6267)File opened: /proc/1576/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6267)File opened: /proc/2302/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6267)File opened: /proc/115/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6267)File opened: /proc/236/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6267)File opened: /proc/116/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6267)File opened: /proc/237/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6267)File opened: /proc/117/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6267)File opened: /proc/118/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6267)File opened: /proc/910/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6267)File opened: /proc/119/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6267)File opened: /proc/912/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6267)File opened: /proc/10/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6267)File opened: /proc/2307/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6267)File opened: /proc/11/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6267)File opened: /proc/918/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6267)File opened: /proc/6241/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6267)File opened: /proc/12/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6267)File opened: /proc/13/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6267)File opened: /proc/14/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6267)File opened: /proc/15/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6267)File opened: /proc/16/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6267)File opened: /proc/17/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6267)File opened: /proc/18/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6267)File opened: /proc/1594/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6267)File opened: /proc/120/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6267)File opened: /proc/121/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6267)File opened: /proc/1349/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6267)File opened: /proc/1/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6267)File opened: /proc/122/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6267)File opened: /proc/243/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6267)File opened: /proc/123/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6267)File opened: /proc/2/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6267)File opened: /proc/124/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6267)File opened: /proc/3/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6267)File opened: /proc/4/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6267)File opened: /proc/125/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6267)File opened: /proc/126/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6267)File opened: /proc/1344/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6267)File opened: /proc/1465/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6267)File opened: /proc/1586/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6267)File opened: /proc/127/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6267)File opened: /proc/6/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6267)File opened: /proc/248/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6267)File opened: /proc/128/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6267)File opened: /proc/249/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6267)File opened: /proc/1463/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6267)File opened: /proc/800/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6267)File opened: /proc/9/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6267)File opened: /proc/801/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6267)File opened: /proc/20/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6267)File opened: /proc/21/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6267)File opened: /proc/1900/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6267)File opened: /proc/22/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6267)File opened: /proc/23/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6267)File opened: /proc/6251/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6267)File opened: /proc/24/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6267)File opened: /proc/25/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6267)File opened: /proc/26/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6267)File opened: /proc/27/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6267)File opened: /proc/28/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6267)File opened: /proc/29/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6267)File opened: /proc/491/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6267)File opened: /proc/250/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6267)File opened: /proc/130/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6267)File opened: /proc/251/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6267)File opened: /proc/6250/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6267)File opened: /proc/252/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6267)File opened: /proc/132/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6267)File opened: /proc/253/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6267)File opened: /proc/254/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6267)File opened: /proc/255/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6267)File opened: /proc/256/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6267)File opened: /proc/1599/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6267)File opened: /proc/257/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6267)File opened: /proc/1477/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6267)File opened: /proc/379/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6267)File opened: /proc/258/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6267)File opened: /proc/1476/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6267)File opened: /proc/259/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6267)File opened: /proc/1475/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6267)File opened: /proc/936/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6267)File opened: /proc/30/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6267)File opened: /proc/2208/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6267)File opened: /proc/35/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6267)File opened: /proc/6267/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6267)File opened: /proc/1809/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6267)File opened: /proc/1494/statusJump to behavior
Source: ub8ehJSePAfc9FYqZIT6.ppc.elfSubmission file: segment LOAD with 7.9629 entropy (max. 8.0)
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6267)Queries kernel information via 'uname': Jump to behavior
Source: ub8ehJSePAfc9FYqZIT6.ppc.elf, 6269.1.000056341c3df000.000056341c48f000.rw-.sdmpBinary or memory string: !/etc/qemu-binfmt/ppc11!hotpluggableq
Source: ub8ehJSePAfc9FYqZIT6.ppc.elf, 6267.1.00007ffe38509000.00007ffe3852a000.rw-.sdmp, ub8ehJSePAfc9FYqZIT6.ppc.elf, 6269.1.00007ffe38509000.00007ffe3852a000.rw-.sdmp, ub8ehJSePAfc9FYqZIT6.ppc.elf, 6271.1.00007ffe38509000.00007ffe3852a000.rw-.sdmp, ub8ehJSePAfc9FYqZIT6.ppc.elf, 6281.1.00007ffe38509000.00007ffe3852a000.rw-.sdmpBinary or memory string: iPx86_64/usr/bin/qemu-ppc/tmp/ub8ehJSePAfc9FYqZIT6.ppc.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf
Source: ub8ehJSePAfc9FYqZIT6.ppc.elf, 6267.1.000056341c3df000.000056341c4b0000.rw-.sdmp, ub8ehJSePAfc9FYqZIT6.ppc.elf, 6271.1.000056341c3df000.000056341c48f000.rw-.sdmp, ub8ehJSePAfc9FYqZIT6.ppc.elf, 6281.1.000056341c3df000.000056341c4b0000.rw-.sdmpBinary or memory string: !/etc/qemu-binfmt/ppc1
Source: ub8ehJSePAfc9FYqZIT6.ppc.elf, 6267.1.000056341c3df000.000056341c4b0000.rw-.sdmp, ub8ehJSePAfc9FYqZIT6.ppc.elf, 6269.1.000056341c3df000.000056341c48f000.rw-.sdmp, ub8ehJSePAfc9FYqZIT6.ppc.elf, 6271.1.000056341c3df000.000056341c48f000.rw-.sdmp, ub8ehJSePAfc9FYqZIT6.ppc.elf, 6281.1.000056341c3df000.000056341c4b0000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/ppc
Source: ub8ehJSePAfc9FYqZIT6.ppc.elf, 6267.1.00007ffe38509000.00007ffe3852a000.rw-.sdmp, ub8ehJSePAfc9FYqZIT6.ppc.elf, 6269.1.00007ffe38509000.00007ffe3852a000.rw-.sdmp, ub8ehJSePAfc9FYqZIT6.ppc.elf, 6271.1.00007ffe38509000.00007ffe3852a000.rw-.sdmp, ub8ehJSePAfc9FYqZIT6.ppc.elf, 6281.1.00007ffe38509000.00007ffe3852a000.rw-.sdmpBinary or memory string: /usr/bin/qemu-ppc
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception11
Obfuscated Files or Information
1
OS Credential Dumping
11
Security Software Discovery
Remote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Non-Standard Port
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
SourceDetectionScannerLabelLink
ub8ehJSePAfc9FYqZIT6.ppc.elf42%ReversingLabsLinux.Trojan.Mirai
ub8ehJSePAfc9FYqZIT6.ppc.elf100%AviraEXP/ELF.Agent.F.118
No Antivirus matches
No Antivirus matches
No Antivirus matches
No contacted domains info
NameSourceMaliciousAntivirus DetectionReputation
http://upx.sf.netub8ehJSePAfc9FYqZIT6.ppc.elffalse
    high
    • No. of IPs < 25%
    • 25% < No. of IPs < 50%
    • 50% < No. of IPs < 75%
    • 75% < No. of IPs
    IPDomainCountryFlagASNASN NameMalicious
    109.202.202.202
    unknownSwitzerland
    13030INIT7CHfalse
    92.118.56.167
    unknownGermany
    9009M247GBfalse
    91.189.91.43
    unknownUnited Kingdom
    41231CANONICAL-ASGBfalse
    91.189.91.42
    unknownUnited Kingdom
    41231CANONICAL-ASGBfalse
    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
    109.202.202.202kpLwzBouH4.elfGet hashmaliciousUnknownBrowse
    • ch.archive.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_92.0%2bbuild3-0ubuntu0.20.04.1_amd64.deb
    92.118.56.167ub8ehJSePAfc9FYqZIT6.arm.elfGet hashmaliciousMiraiBrowse
      ub8ehJSePAfc9FYqZIT6.m68k.elfGet hashmaliciousMiraiBrowse
        ub8ehJSePAfc9FYqZIT6.sh4.elfGet hashmaliciousUnknownBrowse
          ub8ehJSePAfc9FYqZIT6.i686.elfGet hashmaliciousUnknownBrowse
            ub8ehJSePAfc9FYqZIT6.x86.elfGet hashmaliciousUnknownBrowse
              91.189.91.43ub8ehJSePAfc9FYqZIT6.arm.elfGet hashmaliciousMiraiBrowse
                win.elfGet hashmaliciousUnknownBrowse
                  .i.elfGet hashmaliciousUnknownBrowse
                    boatnet.mpsl.elfGet hashmaliciousMiraiBrowse
                      boatnet.arc.elfGet hashmaliciousMiraiBrowse
                        boatnet.sh4.elfGet hashmaliciousMiraiBrowse
                          most-m68k.elfGet hashmaliciousUnknownBrowse
                            sshd.elfGet hashmaliciousUnknownBrowse
                              bin.sh.elfGet hashmaliciousUnknownBrowse
                                byte.arm.elfGet hashmaliciousMirai, OkiruBrowse
                                  91.189.91.42ub8ehJSePAfc9FYqZIT6.arm.elfGet hashmaliciousMiraiBrowse
                                    win.elfGet hashmaliciousUnknownBrowse
                                      .i.elfGet hashmaliciousUnknownBrowse
                                        boatnet.mpsl.elfGet hashmaliciousMiraiBrowse
                                          boatnet.arc.elfGet hashmaliciousMiraiBrowse
                                            boatnet.sh4.elfGet hashmaliciousMiraiBrowse
                                              most-m68k.elfGet hashmaliciousUnknownBrowse
                                                sshd.elfGet hashmaliciousUnknownBrowse
                                                  bin.sh.elfGet hashmaliciousUnknownBrowse
                                                    byte.arm.elfGet hashmaliciousMirai, OkiruBrowse
                                                      No context
                                                      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                      CANONICAL-ASGBub8ehJSePAfc9FYqZIT6.arm.elfGet hashmaliciousMiraiBrowse
                                                      • 91.189.91.42
                                                      ub8ehJSePAfc9FYqZIT6.m68k.elfGet hashmaliciousMiraiBrowse
                                                      • 185.125.190.26
                                                      win.elfGet hashmaliciousUnknownBrowse
                                                      • 91.189.91.42
                                                      .i.elfGet hashmaliciousUnknownBrowse
                                                      • 91.189.91.42
                                                      boatnet.ppc.elfGet hashmaliciousMiraiBrowse
                                                      • 185.125.190.26
                                                      boatnet.mpsl.elfGet hashmaliciousMiraiBrowse
                                                      • 91.189.91.42
                                                      boatnet.arm7.elfGet hashmaliciousMiraiBrowse
                                                      • 185.125.190.26
                                                      boatnet.arc.elfGet hashmaliciousMiraiBrowse
                                                      • 91.189.91.42
                                                      boatnet.sh4.elfGet hashmaliciousMiraiBrowse
                                                      • 91.189.91.42
                                                      most-m68k.elfGet hashmaliciousUnknownBrowse
                                                      • 91.189.91.42
                                                      CANONICAL-ASGBub8ehJSePAfc9FYqZIT6.arm.elfGet hashmaliciousMiraiBrowse
                                                      • 91.189.91.42
                                                      ub8ehJSePAfc9FYqZIT6.m68k.elfGet hashmaliciousMiraiBrowse
                                                      • 185.125.190.26
                                                      win.elfGet hashmaliciousUnknownBrowse
                                                      • 91.189.91.42
                                                      .i.elfGet hashmaliciousUnknownBrowse
                                                      • 91.189.91.42
                                                      boatnet.ppc.elfGet hashmaliciousMiraiBrowse
                                                      • 185.125.190.26
                                                      boatnet.mpsl.elfGet hashmaliciousMiraiBrowse
                                                      • 91.189.91.42
                                                      boatnet.arm7.elfGet hashmaliciousMiraiBrowse
                                                      • 185.125.190.26
                                                      boatnet.arc.elfGet hashmaliciousMiraiBrowse
                                                      • 91.189.91.42
                                                      boatnet.sh4.elfGet hashmaliciousMiraiBrowse
                                                      • 91.189.91.42
                                                      most-m68k.elfGet hashmaliciousUnknownBrowse
                                                      • 91.189.91.42
                                                      INIT7CHub8ehJSePAfc9FYqZIT6.arm.elfGet hashmaliciousMiraiBrowse
                                                      • 109.202.202.202
                                                      win.elfGet hashmaliciousUnknownBrowse
                                                      • 109.202.202.202
                                                      .i.elfGet hashmaliciousUnknownBrowse
                                                      • 109.202.202.202
                                                      boatnet.mpsl.elfGet hashmaliciousMiraiBrowse
                                                      • 109.202.202.202
                                                      boatnet.arc.elfGet hashmaliciousMiraiBrowse
                                                      • 109.202.202.202
                                                      boatnet.sh4.elfGet hashmaliciousMiraiBrowse
                                                      • 109.202.202.202
                                                      most-m68k.elfGet hashmaliciousUnknownBrowse
                                                      • 109.202.202.202
                                                      sshd.elfGet hashmaliciousUnknownBrowse
                                                      • 109.202.202.202
                                                      bin.sh.elfGet hashmaliciousUnknownBrowse
                                                      • 109.202.202.202
                                                      byte.arm.elfGet hashmaliciousMirai, OkiruBrowse
                                                      • 109.202.202.202
                                                      M247GBub8ehJSePAfc9FYqZIT6.arm.elfGet hashmaliciousMiraiBrowse
                                                      • 92.118.56.167
                                                      ub8ehJSePAfc9FYqZIT6.m68k.elfGet hashmaliciousMiraiBrowse
                                                      • 92.118.56.167
                                                      ub8ehJSePAfc9FYqZIT6.sh4.elfGet hashmaliciousUnknownBrowse
                                                      • 92.118.56.167
                                                      ub8ehJSePAfc9FYqZIT6.i686.elfGet hashmaliciousUnknownBrowse
                                                      • 92.118.56.167
                                                      ub8ehJSePAfc9FYqZIT6.x86.elfGet hashmaliciousUnknownBrowse
                                                      • 92.118.56.167
                                                      http://au.kirmalk.com/watch.php?vid=7750fd3c8Get hashmaliciousUnknownBrowse
                                                      • 38.132.109.126
                                                      nklppc.elfGet hashmaliciousUnknownBrowse
                                                      • 193.160.72.174
                                                      https://en.newsnowbangla.com/archives/69912Get hashmaliciousHTMLPhisher, TechSupportScamBrowse
                                                      • 45.10.162.162
                                                      arm.elfGet hashmaliciousUnknownBrowse
                                                      • 92.249.48.36
                                                      powerpc.nn.elfGet hashmaliciousMirai, OkiruBrowse
                                                      • 38.204.189.65
                                                      No context
                                                      No context
                                                      No created / dropped files found
                                                      File type:ELF 32-bit MSB executable, PowerPC or cisco 4500, version 1 (GNU/Linux), statically linked, no section header
                                                      Entropy (8bit):7.960861554335051
                                                      TrID:
                                                      • ELF Executable and Linkable format (Linux) (4029/14) 50.16%
                                                      • ELF Executable and Linkable format (generic) (4004/1) 49.84%
                                                      File name:ub8ehJSePAfc9FYqZIT6.ppc.elf
                                                      File size:40'316 bytes
                                                      MD5:7d78600253837f3c2ed8ebe7a3476952
                                                      SHA1:9ca379e07406bcd3bc3c4ed606430017907e85c1
                                                      SHA256:f0039251c6ec39533feecd7b6585499ddb60094d845936d08f1a42cae327d70e
                                                      SHA512:1c6c0b4387753dc8eca230f8c9a78361f6f6cab57f12fc433e5d3f58ffd3f731999e58ac8e7fbf8f1fb3c34ae78d27a313b76ecc82743067fc94be66a1843987
                                                      SSDEEP:768:qiIycbQHUBnVYoMcb/BLY+d34eE6H2PUQzSh18rNsH4uVcqgw09U:fI7bQ0BVeA5YYnH25zBI4u+qgw09U
                                                      TLSH:1603F075F0EA1EAAEAFECB710589F7813FD6B7CF36D58550A1E2D31071498121192DC2
                                                      File Content Preview:.ELF...........................4.........4. ...(.......................p...p..............k...k...k.................dt.Q................................UPX!..........b...b........V.......?.E.h4...@b........=.a....`..Y...j{.c.HL}.....H..z.q.H.....8ea......

                                                      ELF header

                                                      Class:ELF32
                                                      Data:2's complement, big endian
                                                      Version:1 (current)
                                                      Machine:PowerPC
                                                      Version Number:0x1
                                                      Type:EXEC (Executable file)
                                                      OS/ABI:UNIX - Linux
                                                      ABI Version:0
                                                      Entry Point Address:0x108a88
                                                      Flags:0x0
                                                      ELF Header Size:52
                                                      Program Header Offset:52
                                                      Program Header Size:32
                                                      Number of Program Headers:3
                                                      Section Header Offset:0
                                                      Section Header Size:40
                                                      Number of Section Headers:0
                                                      Header String Table Index:0
                                                      TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                      LOAD0x00x1000000x1000000x9c700x9c707.96290x5R E0x10000
                                                      LOAD0x6b900x10026b900x10026b900x00x00.00000x6RW 0x10000
                                                      GNU_STACK0x00x00x00x00x00.00000x6RW 0x4
                                                      TimestampSource PortDest PortSource IPDest IP
                                                      Dec 26, 2024 22:07:05.925977945 CET552703778192.168.2.2392.118.56.167
                                                      Dec 26, 2024 22:07:06.045655966 CET37785527092.118.56.167192.168.2.23
                                                      Dec 26, 2024 22:07:06.045834064 CET552703778192.168.2.2392.118.56.167
                                                      Dec 26, 2024 22:07:06.078998089 CET552703778192.168.2.2392.118.56.167
                                                      Dec 26, 2024 22:07:06.198648930 CET37785527092.118.56.167192.168.2.23
                                                      Dec 26, 2024 22:07:06.198741913 CET552703778192.168.2.2392.118.56.167
                                                      Dec 26, 2024 22:07:06.319844007 CET37785527092.118.56.167192.168.2.23
                                                      Dec 26, 2024 22:07:07.279520035 CET37785527092.118.56.167192.168.2.23
                                                      Dec 26, 2024 22:07:07.280078888 CET552703778192.168.2.2392.118.56.167
                                                      Dec 26, 2024 22:07:07.280078888 CET552703778192.168.2.2392.118.56.167
                                                      Dec 26, 2024 22:07:07.281363964 CET552723778192.168.2.2392.118.56.167
                                                      Dec 26, 2024 22:07:07.400903940 CET37785527292.118.56.167192.168.2.23
                                                      Dec 26, 2024 22:07:07.401272058 CET552723778192.168.2.2392.118.56.167
                                                      Dec 26, 2024 22:07:07.403016090 CET552723778192.168.2.2392.118.56.167
                                                      Dec 26, 2024 22:07:07.522861958 CET37785527292.118.56.167192.168.2.23
                                                      Dec 26, 2024 22:07:07.522967100 CET552723778192.168.2.2392.118.56.167
                                                      Dec 26, 2024 22:07:07.642715931 CET37785527292.118.56.167192.168.2.23
                                                      Dec 26, 2024 22:07:07.795845032 CET43928443192.168.2.2391.189.91.42
                                                      Dec 26, 2024 22:07:08.307885885 CET4251680192.168.2.23109.202.202.202
                                                      Dec 26, 2024 22:07:08.661302090 CET37785527292.118.56.167192.168.2.23
                                                      Dec 26, 2024 22:07:08.661554098 CET552723778192.168.2.2392.118.56.167
                                                      Dec 26, 2024 22:07:08.661555052 CET552723778192.168.2.2392.118.56.167
                                                      Dec 26, 2024 22:07:08.662136078 CET552743778192.168.2.2392.118.56.167
                                                      Dec 26, 2024 22:07:08.781582117 CET37785527492.118.56.167192.168.2.23
                                                      Dec 26, 2024 22:07:08.781688929 CET552743778192.168.2.2392.118.56.167
                                                      Dec 26, 2024 22:07:08.782552958 CET552743778192.168.2.2392.118.56.167
                                                      Dec 26, 2024 22:07:08.902031898 CET37785527492.118.56.167192.168.2.23
                                                      Dec 26, 2024 22:07:08.902158022 CET552743778192.168.2.2392.118.56.167
                                                      Dec 26, 2024 22:07:09.021682978 CET37785527492.118.56.167192.168.2.23
                                                      Dec 26, 2024 22:07:10.019380093 CET37785527492.118.56.167192.168.2.23
                                                      Dec 26, 2024 22:07:10.019499063 CET552743778192.168.2.2392.118.56.167
                                                      Dec 26, 2024 22:07:10.019668102 CET552743778192.168.2.2392.118.56.167
                                                      Dec 26, 2024 22:07:10.020116091 CET552763778192.168.2.2392.118.56.167
                                                      Dec 26, 2024 22:07:10.139772892 CET37785527692.118.56.167192.168.2.23
                                                      Dec 26, 2024 22:07:10.139957905 CET552763778192.168.2.2392.118.56.167
                                                      Dec 26, 2024 22:07:10.141022921 CET552763778192.168.2.2392.118.56.167
                                                      Dec 26, 2024 22:07:10.261223078 CET37785527692.118.56.167192.168.2.23
                                                      Dec 26, 2024 22:07:10.261332989 CET552763778192.168.2.2392.118.56.167
                                                      Dec 26, 2024 22:07:10.380867004 CET37785527692.118.56.167192.168.2.23
                                                      Dec 26, 2024 22:07:11.370300055 CET37785527692.118.56.167192.168.2.23
                                                      Dec 26, 2024 22:07:11.370557070 CET552763778192.168.2.2392.118.56.167
                                                      Dec 26, 2024 22:07:11.370711088 CET552763778192.168.2.2392.118.56.167
                                                      Dec 26, 2024 22:07:11.371223927 CET552783778192.168.2.2392.118.56.167
                                                      Dec 26, 2024 22:07:11.490801096 CET37785527892.118.56.167192.168.2.23
                                                      Dec 26, 2024 22:07:11.490922928 CET552783778192.168.2.2392.118.56.167
                                                      Dec 26, 2024 22:07:11.491774082 CET552783778192.168.2.2392.118.56.167
                                                      Dec 26, 2024 22:07:11.611267090 CET37785527892.118.56.167192.168.2.23
                                                      Dec 26, 2024 22:07:11.611346006 CET552783778192.168.2.2392.118.56.167
                                                      Dec 26, 2024 22:07:11.730927944 CET37785527892.118.56.167192.168.2.23
                                                      Dec 26, 2024 22:07:11.759710073 CET552803778192.168.2.2392.118.56.167
                                                      Dec 26, 2024 22:07:11.879271984 CET37785528092.118.56.167192.168.2.23
                                                      Dec 26, 2024 22:07:11.879383087 CET552803778192.168.2.2392.118.56.167
                                                      Dec 26, 2024 22:07:11.889787912 CET552803778192.168.2.2392.118.56.167
                                                      Dec 26, 2024 22:07:12.009437084 CET37785528092.118.56.167192.168.2.23
                                                      Dec 26, 2024 22:07:12.009571075 CET552803778192.168.2.2392.118.56.167
                                                      Dec 26, 2024 22:07:12.129102945 CET37785528092.118.56.167192.168.2.23
                                                      Dec 26, 2024 22:07:12.725454092 CET37785527892.118.56.167192.168.2.23
                                                      Dec 26, 2024 22:07:12.725852013 CET552783778192.168.2.2392.118.56.167
                                                      Dec 26, 2024 22:07:12.725852013 CET552783778192.168.2.2392.118.56.167
                                                      Dec 26, 2024 22:07:12.726517916 CET552823778192.168.2.2392.118.56.167
                                                      Dec 26, 2024 22:07:12.846007109 CET37785528292.118.56.167192.168.2.23
                                                      Dec 26, 2024 22:07:12.846126080 CET552823778192.168.2.2392.118.56.167
                                                      Dec 26, 2024 22:07:12.847287893 CET552823778192.168.2.2392.118.56.167
                                                      Dec 26, 2024 22:07:12.966954947 CET37785528292.118.56.167192.168.2.23
                                                      Dec 26, 2024 22:07:12.967159033 CET552823778192.168.2.2392.118.56.167
                                                      Dec 26, 2024 22:07:13.086711884 CET37785528292.118.56.167192.168.2.23
                                                      Dec 26, 2024 22:07:13.119033098 CET37785528092.118.56.167192.168.2.23
                                                      Dec 26, 2024 22:07:13.119357109 CET552803778192.168.2.2392.118.56.167
                                                      Dec 26, 2024 22:07:13.119558096 CET552803778192.168.2.2392.118.56.167
                                                      Dec 26, 2024 22:07:13.120206118 CET552843778192.168.2.2392.118.56.167
                                                      Dec 26, 2024 22:07:13.239620924 CET37785528492.118.56.167192.168.2.23
                                                      Dec 26, 2024 22:07:13.239862919 CET552843778192.168.2.2392.118.56.167
                                                      Dec 26, 2024 22:07:13.240763903 CET552843778192.168.2.2392.118.56.167
                                                      Dec 26, 2024 22:07:13.360155106 CET37785528492.118.56.167192.168.2.23
                                                      Dec 26, 2024 22:07:13.360349894 CET552843778192.168.2.2392.118.56.167
                                                      Dec 26, 2024 22:07:13.427189112 CET42836443192.168.2.2391.189.91.43
                                                      Dec 26, 2024 22:07:13.479868889 CET37785528492.118.56.167192.168.2.23
                                                      Dec 26, 2024 22:07:14.079648018 CET37785528292.118.56.167192.168.2.23
                                                      Dec 26, 2024 22:07:14.080013990 CET552823778192.168.2.2392.118.56.167
                                                      Dec 26, 2024 22:07:14.080013990 CET552823778192.168.2.2392.118.56.167
                                                      Dec 26, 2024 22:07:14.080442905 CET552863778192.168.2.2392.118.56.167
                                                      Dec 26, 2024 22:07:14.200294971 CET37785528692.118.56.167192.168.2.23
                                                      Dec 26, 2024 22:07:14.200419903 CET552863778192.168.2.2392.118.56.167
                                                      Dec 26, 2024 22:07:14.201351881 CET552863778192.168.2.2392.118.56.167
                                                      Dec 26, 2024 22:07:14.320804119 CET37785528692.118.56.167192.168.2.23
                                                      Dec 26, 2024 22:07:14.320995092 CET552863778192.168.2.2392.118.56.167
                                                      Dec 26, 2024 22:07:14.440670967 CET37785528692.118.56.167192.168.2.23
                                                      Dec 26, 2024 22:07:14.469484091 CET37785528492.118.56.167192.168.2.23
                                                      Dec 26, 2024 22:07:14.469603062 CET552843778192.168.2.2392.118.56.167
                                                      Dec 26, 2024 22:07:14.469630003 CET552843778192.168.2.2392.118.56.167
                                                      Dec 26, 2024 22:07:14.470086098 CET552883778192.168.2.2392.118.56.167
                                                      Dec 26, 2024 22:07:14.589519024 CET37785528892.118.56.167192.168.2.23
                                                      Dec 26, 2024 22:07:14.589735031 CET552883778192.168.2.2392.118.56.167
                                                      Dec 26, 2024 22:07:14.590826035 CET552883778192.168.2.2392.118.56.167
                                                      Dec 26, 2024 22:07:14.710772038 CET37785528892.118.56.167192.168.2.23
                                                      Dec 26, 2024 22:07:14.710959911 CET552883778192.168.2.2392.118.56.167
                                                      Dec 26, 2024 22:07:14.830652952 CET37785528892.118.56.167192.168.2.23
                                                      Dec 26, 2024 22:07:15.430617094 CET37785528692.118.56.167192.168.2.23
                                                      Dec 26, 2024 22:07:15.430919886 CET552863778192.168.2.2392.118.56.167
                                                      Dec 26, 2024 22:07:15.431092978 CET552863778192.168.2.2392.118.56.167
                                                      Dec 26, 2024 22:07:15.431858063 CET552903778192.168.2.2392.118.56.167
                                                      Dec 26, 2024 22:07:15.551322937 CET37785529092.118.56.167192.168.2.23
                                                      Dec 26, 2024 22:07:15.551592112 CET552903778192.168.2.2392.118.56.167
                                                      Dec 26, 2024 22:07:15.552563906 CET552903778192.168.2.2392.118.56.167
                                                      Dec 26, 2024 22:07:15.922764063 CET552903778192.168.2.2392.118.56.167
                                                      Dec 26, 2024 22:07:16.172379017 CET37785528892.118.56.167192.168.2.23
                                                      Dec 26, 2024 22:07:16.172432899 CET37785528892.118.56.167192.168.2.23
                                                      Dec 26, 2024 22:07:16.172493935 CET552883778192.168.2.2392.118.56.167
                                                      Dec 26, 2024 22:07:16.172493935 CET552883778192.168.2.2392.118.56.167
                                                      Dec 26, 2024 22:07:16.172545910 CET552883778192.168.2.2392.118.56.167
                                                      Dec 26, 2024 22:07:16.172585011 CET37785529092.118.56.167192.168.2.23
                                                      Dec 26, 2024 22:07:16.172599077 CET37785529092.118.56.167192.168.2.23
                                                      Dec 26, 2024 22:07:16.173069954 CET552923778192.168.2.2392.118.56.167
                                                      Dec 26, 2024 22:07:16.194694042 CET37785528892.118.56.167192.168.2.23
                                                      Dec 26, 2024 22:07:16.194761038 CET552883778192.168.2.2392.118.56.167
                                                      Dec 26, 2024 22:07:16.292500973 CET37785529292.118.56.167192.168.2.23
                                                      Dec 26, 2024 22:07:16.292573929 CET552923778192.168.2.2392.118.56.167
                                                      Dec 26, 2024 22:07:16.293484926 CET552923778192.168.2.2392.118.56.167
                                                      Dec 26, 2024 22:07:16.413100004 CET37785529292.118.56.167192.168.2.23
                                                      Dec 26, 2024 22:07:16.413225889 CET552923778192.168.2.2392.118.56.167
                                                      Dec 26, 2024 22:07:16.532963991 CET37785529292.118.56.167192.168.2.23
                                                      Dec 26, 2024 22:07:17.282227039 CET37785529092.118.56.167192.168.2.23
                                                      Dec 26, 2024 22:07:17.282429934 CET552903778192.168.2.2392.118.56.167
                                                      Dec 26, 2024 22:07:17.282442093 CET552903778192.168.2.2392.118.56.167
                                                      Dec 26, 2024 22:07:17.283001900 CET552943778192.168.2.2392.118.56.167
                                                      Dec 26, 2024 22:07:17.402489901 CET37785529492.118.56.167192.168.2.23
                                                      Dec 26, 2024 22:07:17.402710915 CET552943778192.168.2.2392.118.56.167
                                                      Dec 26, 2024 22:07:17.404004097 CET552943778192.168.2.2392.118.56.167
                                                      Dec 26, 2024 22:07:17.523428917 CET37785529492.118.56.167192.168.2.23
                                                      Dec 26, 2024 22:07:17.523550987 CET552943778192.168.2.2392.118.56.167
                                                      Dec 26, 2024 22:07:17.524746895 CET37785529292.118.56.167192.168.2.23
                                                      Dec 26, 2024 22:07:17.524799109 CET552923778192.168.2.2392.118.56.167
                                                      Dec 26, 2024 22:07:17.524879932 CET552923778192.168.2.2392.118.56.167
                                                      Dec 26, 2024 22:07:17.525321960 CET552963778192.168.2.2392.118.56.167
                                                      Dec 26, 2024 22:07:17.643116951 CET37785529492.118.56.167192.168.2.23
                                                      Dec 26, 2024 22:07:17.644865036 CET37785529692.118.56.167192.168.2.23
                                                      Dec 26, 2024 22:07:17.645032883 CET552963778192.168.2.2392.118.56.167
                                                      Dec 26, 2024 22:07:17.646061897 CET552963778192.168.2.2392.118.56.167
                                                      Dec 26, 2024 22:07:17.765523911 CET37785529692.118.56.167192.168.2.23
                                                      Dec 26, 2024 22:07:17.765718937 CET552963778192.168.2.2392.118.56.167
                                                      Dec 26, 2024 22:07:17.885237932 CET37785529692.118.56.167192.168.2.23
                                                      Dec 26, 2024 22:07:18.646069050 CET37785529492.118.56.167192.168.2.23
                                                      Dec 26, 2024 22:07:18.646274090 CET552943778192.168.2.2392.118.56.167
                                                      Dec 26, 2024 22:07:18.646387100 CET552943778192.168.2.2392.118.56.167
                                                      Dec 26, 2024 22:07:18.646990061 CET552983778192.168.2.2392.118.56.167
                                                      Dec 26, 2024 22:07:18.766472101 CET37785529892.118.56.167192.168.2.23
                                                      Dec 26, 2024 22:07:18.766587019 CET552983778192.168.2.2392.118.56.167
                                                      Dec 26, 2024 22:07:18.767929077 CET552983778192.168.2.2392.118.56.167
                                                      Dec 26, 2024 22:07:18.874284029 CET37785529692.118.56.167192.168.2.23
                                                      Dec 26, 2024 22:07:18.874382019 CET552963778192.168.2.2392.118.56.167
                                                      Dec 26, 2024 22:07:18.874414921 CET552963778192.168.2.2392.118.56.167
                                                      Dec 26, 2024 22:07:18.874933004 CET553003778192.168.2.2392.118.56.167
                                                      Dec 26, 2024 22:07:18.887701988 CET37785529892.118.56.167192.168.2.23
                                                      Dec 26, 2024 22:07:18.887758970 CET552983778192.168.2.2392.118.56.167
                                                      Dec 26, 2024 22:07:18.994543076 CET37785530092.118.56.167192.168.2.23
                                                      Dec 26, 2024 22:07:18.994622946 CET553003778192.168.2.2392.118.56.167
                                                      Dec 26, 2024 22:07:18.995615959 CET553003778192.168.2.2392.118.56.167
                                                      Dec 26, 2024 22:07:19.007282972 CET37785529892.118.56.167192.168.2.23
                                                      Dec 26, 2024 22:07:19.115071058 CET37785530092.118.56.167192.168.2.23
                                                      Dec 26, 2024 22:07:19.115257025 CET553003778192.168.2.2392.118.56.167
                                                      Dec 26, 2024 22:07:19.234817982 CET37785530092.118.56.167192.168.2.23
                                                      Dec 26, 2024 22:07:19.998848915 CET37785529892.118.56.167192.168.2.23
                                                      Dec 26, 2024 22:07:19.999160051 CET552983778192.168.2.2392.118.56.167
                                                      Dec 26, 2024 22:07:19.999160051 CET552983778192.168.2.2392.118.56.167
                                                      Dec 26, 2024 22:07:19.999989033 CET553023778192.168.2.2392.118.56.167
                                                      Dec 26, 2024 22:07:20.119443893 CET37785530292.118.56.167192.168.2.23
                                                      Dec 26, 2024 22:07:20.119834900 CET553023778192.168.2.2392.118.56.167
                                                      Dec 26, 2024 22:07:20.224140882 CET37785530092.118.56.167192.168.2.23
                                                      Dec 26, 2024 22:07:20.224405050 CET553003778192.168.2.2392.118.56.167
                                                      Dec 26, 2024 22:07:20.224503994 CET553003778192.168.2.2392.118.56.167
                                                      Dec 26, 2024 22:07:20.225161076 CET553043778192.168.2.2392.118.56.167
                                                      Dec 26, 2024 22:07:20.345416069 CET37785530492.118.56.167192.168.2.23
                                                      Dec 26, 2024 22:07:20.345545053 CET553043778192.168.2.2392.118.56.167
                                                      Dec 26, 2024 22:07:20.346890926 CET553043778192.168.2.2392.118.56.167
                                                      Dec 26, 2024 22:07:20.466495991 CET37785530492.118.56.167192.168.2.23
                                                      Dec 26, 2024 22:07:20.466653109 CET553043778192.168.2.2392.118.56.167
                                                      Dec 26, 2024 22:07:20.586251974 CET37785530492.118.56.167192.168.2.23
                                                      Dec 26, 2024 22:07:21.010021925 CET553023778192.168.2.2392.118.56.167
                                                      Dec 26, 2024 22:07:21.129784107 CET37785530292.118.56.167192.168.2.23
                                                      Dec 26, 2024 22:07:21.129887104 CET553023778192.168.2.2392.118.56.167
                                                      Dec 26, 2024 22:07:21.130975008 CET553023778192.168.2.2392.118.56.167
                                                      Dec 26, 2024 22:07:21.250622988 CET37785530292.118.56.167192.168.2.23
                                                      Dec 26, 2024 22:07:21.250720024 CET553023778192.168.2.2392.118.56.167
                                                      Dec 26, 2024 22:07:21.370335102 CET37785530292.118.56.167192.168.2.23
                                                      Dec 26, 2024 22:07:21.573050976 CET37785530492.118.56.167192.168.2.23
                                                      Dec 26, 2024 22:07:21.573136091 CET553043778192.168.2.2392.118.56.167
                                                      Dec 26, 2024 22:07:21.573174953 CET553043778192.168.2.2392.118.56.167
                                                      Dec 26, 2024 22:07:21.573848963 CET553063778192.168.2.2392.118.56.167
                                                      Dec 26, 2024 22:07:21.693447113 CET37785530692.118.56.167192.168.2.23
                                                      Dec 26, 2024 22:07:21.693519115 CET553063778192.168.2.2392.118.56.167
                                                      Dec 26, 2024 22:07:21.694334030 CET553063778192.168.2.2392.118.56.167
                                                      Dec 26, 2024 22:07:21.813843012 CET37785530692.118.56.167192.168.2.23
                                                      Dec 26, 2024 22:07:21.814143896 CET553063778192.168.2.2392.118.56.167
                                                      Dec 26, 2024 22:07:21.933710098 CET37785530692.118.56.167192.168.2.23
                                                      Dec 26, 2024 22:07:22.922516108 CET37785530692.118.56.167192.168.2.23
                                                      Dec 26, 2024 22:07:22.922847986 CET553063778192.168.2.2392.118.56.167
                                                      Dec 26, 2024 22:07:22.922920942 CET553063778192.168.2.2392.118.56.167
                                                      Dec 26, 2024 22:07:22.923671007 CET553083778192.168.2.2392.118.56.167
                                                      Dec 26, 2024 22:07:23.043206930 CET37785530892.118.56.167192.168.2.23
                                                      Dec 26, 2024 22:07:23.043472052 CET553083778192.168.2.2392.118.56.167
                                                      Dec 26, 2024 22:07:23.044617891 CET553083778192.168.2.2392.118.56.167
                                                      Dec 26, 2024 22:07:23.164166927 CET37785530892.118.56.167192.168.2.23
                                                      Dec 26, 2024 22:07:23.164480925 CET553083778192.168.2.2392.118.56.167
                                                      Dec 26, 2024 22:07:23.284071922 CET37785530892.118.56.167192.168.2.23
                                                      Dec 26, 2024 22:07:24.272552967 CET37785530892.118.56.167192.168.2.23
                                                      Dec 26, 2024 22:07:24.272756100 CET553083778192.168.2.2392.118.56.167
                                                      Dec 26, 2024 22:07:24.272865057 CET553083778192.168.2.2392.118.56.167
                                                      Dec 26, 2024 22:07:24.273703098 CET553103778192.168.2.2392.118.56.167
                                                      Dec 26, 2024 22:07:24.393281937 CET37785531092.118.56.167192.168.2.23
                                                      Dec 26, 2024 22:07:24.393394947 CET553103778192.168.2.2392.118.56.167
                                                      Dec 26, 2024 22:07:24.394676924 CET553103778192.168.2.2392.118.56.167
                                                      Dec 26, 2024 22:07:24.514400005 CET37785531092.118.56.167192.168.2.23
                                                      Dec 26, 2024 22:07:24.514655113 CET553103778192.168.2.2392.118.56.167
                                                      Dec 26, 2024 22:07:24.634174109 CET37785531092.118.56.167192.168.2.23
                                                      Dec 26, 2024 22:07:28.017070055 CET43928443192.168.2.2391.189.91.42
                                                      Dec 26, 2024 22:07:31.140033007 CET553023778192.168.2.2392.118.56.167
                                                      Dec 26, 2024 22:07:31.259936094 CET37785530292.118.56.167192.168.2.23
                                                      Dec 26, 2024 22:07:31.503269911 CET37785530292.118.56.167192.168.2.23
                                                      Dec 26, 2024 22:07:31.503447056 CET553023778192.168.2.2392.118.56.167
                                                      Dec 26, 2024 22:07:34.400918961 CET553103778192.168.2.2392.118.56.167
                                                      Dec 26, 2024 22:07:34.520855904 CET37785531092.118.56.167192.168.2.23
                                                      Dec 26, 2024 22:07:34.759670973 CET37785531092.118.56.167192.168.2.23
                                                      Dec 26, 2024 22:07:34.760008097 CET553103778192.168.2.2392.118.56.167
                                                      Dec 26, 2024 22:07:38.255747080 CET4251680192.168.2.23109.202.202.202
                                                      Dec 26, 2024 22:07:40.303369045 CET42836443192.168.2.2391.189.91.43
                                                      Dec 26, 2024 22:08:08.971623898 CET43928443192.168.2.2391.189.91.42
                                                      Dec 26, 2024 22:08:31.556094885 CET553023778192.168.2.2392.118.56.167
                                                      Dec 26, 2024 22:08:31.675930023 CET37785530292.118.56.167192.168.2.23
                                                      Dec 26, 2024 22:08:31.913470030 CET37785530292.118.56.167192.168.2.23
                                                      Dec 26, 2024 22:08:31.913671970 CET553023778192.168.2.2392.118.56.167
                                                      Dec 26, 2024 22:08:34.812544107 CET553103778192.168.2.2392.118.56.167
                                                      Dec 26, 2024 22:08:34.932410955 CET37785531092.118.56.167192.168.2.23
                                                      Dec 26, 2024 22:08:35.171257019 CET37785531092.118.56.167192.168.2.23
                                                      Dec 26, 2024 22:08:35.171546936 CET553103778192.168.2.2392.118.56.167

                                                      System Behavior

                                                      Start time (UTC):21:07:04
                                                      Start date (UTC):26/12/2024
                                                      Path:/tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf
                                                      Arguments:/tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf
                                                      File size:5388968 bytes
                                                      MD5 hash:ae65271c943d3451b7f026d1fadccea6

                                                      Start time (UTC):21:07:04
                                                      Start date (UTC):26/12/2024
                                                      Path:/tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf
                                                      Arguments:-
                                                      File size:5388968 bytes
                                                      MD5 hash:ae65271c943d3451b7f026d1fadccea6

                                                      Start time (UTC):21:07:04
                                                      Start date (UTC):26/12/2024
                                                      Path:/tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf
                                                      Arguments:-
                                                      File size:5388968 bytes
                                                      MD5 hash:ae65271c943d3451b7f026d1fadccea6

                                                      Start time (UTC):21:07:04
                                                      Start date (UTC):26/12/2024
                                                      Path:/tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf
                                                      Arguments:-
                                                      File size:5388968 bytes
                                                      MD5 hash:ae65271c943d3451b7f026d1fadccea6

                                                      Start time (UTC):21:07:10
                                                      Start date (UTC):26/12/2024
                                                      Path:/tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf
                                                      Arguments:-
                                                      File size:5388968 bytes
                                                      MD5 hash:ae65271c943d3451b7f026d1fadccea6

                                                      Start time (UTC):21:07:10
                                                      Start date (UTC):26/12/2024
                                                      Path:/tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf
                                                      Arguments:-
                                                      File size:5388968 bytes
                                                      MD5 hash:ae65271c943d3451b7f026d1fadccea6