Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
ub8ehJSePAfc9FYqZIT6.mips.elf

Overview

General Information

Sample name:ub8ehJSePAfc9FYqZIT6.mips.elf
Analysis ID:1581068
MD5:64fa0599b70a18403044c5ead883bb4a
SHA1:a36e9a7e4989cacce45ab21473fc96f450d1585a
SHA256:036a4c6d7e77446c407820f59b351b834aa4cb0c7d3075aed5830474bc355f90
Tags:elfuser-abuse_ch
Infos:

Detection

Score:60
Range:0 - 100
Whitelisted:false

Signatures

Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Sample is packed with UPX
Detected TCP or UDP traffic on non-standard ports
ELF contains segments with high entropy indicating compressed/encrypted content
Enumerates processes within the "proc" file system
Sample contains only a LOAD segment without any section mappings
Uses the "uname" system call to query kernel version information (possible evasion)
Yara signature match

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1581068
Start date and time:2024-12-26 22:06:10 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 50s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:ub8ehJSePAfc9FYqZIT6.mips.elf
Detection:MAL
Classification:mal60.evad.linELF@0/0@0/0
  • VT rate limit hit for: ub8ehJSePAfc9FYqZIT6.mips.elf
Command:/tmp/ub8ehJSePAfc9FYqZIT6.mips.elf
PID:5445
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
lzrd cock fest"/proc/"/exe
Standard Error:
  • system is lnxubuntu20
  • cleanup
SourceRuleDescriptionAuthorStrings
5448.1.00007ff2c8400000.00007ff2c842c000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0x28f4c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28f60:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28f74:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28f88:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28f9c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28fb0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28fc4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28fd8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28fec:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29000:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29014:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29028:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x2903c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29050:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29064:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29078:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x2908c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x290a0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x290b4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x290c8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x290dc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
5445.1.00007ff2c8400000.00007ff2c842c000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0x28f4c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28f60:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28f74:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28f88:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28f9c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28fb0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28fc4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28fd8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28fec:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29000:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29014:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29028:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x2903c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29050:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29064:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29078:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x2908c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x290a0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x290b4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x290c8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x290dc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
5456.1.00007ff2c8400000.00007ff2c842c000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0x28f4c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28f60:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28f74:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28f88:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28f9c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28fb0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28fc4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28fd8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28fec:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29000:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29014:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29028:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x2903c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29050:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29064:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29078:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x2908c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x290a0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x290b4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x290c8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x290dc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
5450.1.00007ff2c8400000.00007ff2c842c000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0x28f4c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28f60:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28f74:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28f88:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28f9c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28fb0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28fc4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28fd8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28fec:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29000:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29014:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29028:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x2903c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29050:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29064:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29078:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x2908c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x290a0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x290b4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x290c8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x290dc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
Process Memory Space: ub8ehJSePAfc9FYqZIT6.mips.elf PID: 5445Linux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0x3da6:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3dba:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3dce:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3de2:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3df6:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3e0a:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3e1e:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3e32:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3e46:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3e5a:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3e6e:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3e82:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3e96:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3eaa:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3ebe:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3ed2:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3ee6:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3efa:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3f0e:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3f22:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3f36:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
Click to see the 3 entries
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: ub8ehJSePAfc9FYqZIT6.mips.elfReversingLabs: Detection: 36%
Source: global trafficTCP traffic: 192.168.2.13:33606 -> 92.118.56.167:3778
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: ub8ehJSePAfc9FYqZIT6.mips.elfString found in binary or memory: http://upx.sf.net

System Summary

barindex
Source: 5448.1.00007ff2c8400000.00007ff2c842c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: 5445.1.00007ff2c8400000.00007ff2c842c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: 5456.1.00007ff2c8400000.00007ff2c842c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: 5450.1.00007ff2c8400000.00007ff2c842c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: Process Memory Space: ub8ehJSePAfc9FYqZIT6.mips.elf PID: 5445, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: Process Memory Space: ub8ehJSePAfc9FYqZIT6.mips.elf PID: 5448, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: Process Memory Space: ub8ehJSePAfc9FYqZIT6.mips.elf PID: 5450, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: Process Memory Space: ub8ehJSePAfc9FYqZIT6.mips.elf PID: 5456, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: LOAD without section mappingsProgram segment: 0x100000
Source: 5448.1.00007ff2c8400000.00007ff2c842c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: 5445.1.00007ff2c8400000.00007ff2c842c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: 5456.1.00007ff2c8400000.00007ff2c842c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: 5450.1.00007ff2c8400000.00007ff2c842c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: Process Memory Space: ub8ehJSePAfc9FYqZIT6.mips.elf PID: 5445, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: Process Memory Space: ub8ehJSePAfc9FYqZIT6.mips.elf PID: 5448, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: Process Memory Space: ub8ehJSePAfc9FYqZIT6.mips.elf PID: 5450, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: Process Memory Space: ub8ehJSePAfc9FYqZIT6.mips.elf PID: 5456, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: classification engineClassification label: mal60.evad.linELF@0/0@0/0

Data Obfuscation

barindex
Source: initial sampleString containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $
Source: initial sampleString containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $
Source: initial sampleString containing UPX found: $Id: UPX 3.94 Copyright (C) 1996-2017 the UPX Team. All Rights Reserved. $
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mips.elf (PID: 5445)File opened: /proc/5389/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mips.elf (PID: 5445)File opened: /proc/230/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mips.elf (PID: 5445)File opened: /proc/110/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mips.elf (PID: 5445)File opened: /proc/231/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mips.elf (PID: 5445)File opened: /proc/111/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mips.elf (PID: 5445)File opened: /proc/232/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mips.elf (PID: 5445)File opened: /proc/112/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mips.elf (PID: 5445)File opened: /proc/233/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mips.elf (PID: 5445)File opened: /proc/113/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mips.elf (PID: 5445)File opened: /proc/234/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mips.elf (PID: 5445)File opened: /proc/114/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mips.elf (PID: 5445)File opened: /proc/235/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mips.elf (PID: 5445)File opened: /proc/115/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mips.elf (PID: 5445)File opened: /proc/236/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mips.elf (PID: 5445)File opened: /proc/116/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mips.elf (PID: 5445)File opened: /proc/237/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mips.elf (PID: 5445)File opened: /proc/117/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mips.elf (PID: 5445)File opened: /proc/238/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mips.elf (PID: 5445)File opened: /proc/118/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mips.elf (PID: 5445)File opened: /proc/239/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mips.elf (PID: 5445)File opened: /proc/119/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mips.elf (PID: 5445)File opened: /proc/914/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mips.elf (PID: 5445)File opened: /proc/3634/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mips.elf (PID: 5445)File opened: /proc/10/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mips.elf (PID: 5445)File opened: /proc/917/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mips.elf (PID: 5445)File opened: /proc/11/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mips.elf (PID: 5445)File opened: /proc/12/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mips.elf (PID: 5445)File opened: /proc/13/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mips.elf (PID: 5445)File opened: /proc/14/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mips.elf (PID: 5445)File opened: /proc/15/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mips.elf (PID: 5445)File opened: /proc/16/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mips.elf (PID: 5445)File opened: /proc/17/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mips.elf (PID: 5445)File opened: /proc/18/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mips.elf (PID: 5445)File opened: /proc/19/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mips.elf (PID: 5445)File opened: /proc/240/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mips.elf (PID: 5445)File opened: /proc/3095/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mips.elf (PID: 5445)File opened: /proc/120/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mips.elf (PID: 5445)File opened: /proc/241/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mips.elf (PID: 5445)File opened: /proc/121/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mips.elf (PID: 5445)File opened: /proc/242/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mips.elf (PID: 5445)File opened: /proc/1/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mips.elf (PID: 5445)File opened: /proc/122/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mips.elf (PID: 5445)File opened: /proc/243/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mips.elf (PID: 5445)File opened: /proc/2/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mips.elf (PID: 5445)File opened: /proc/123/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mips.elf (PID: 5445)File opened: /proc/244/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mips.elf (PID: 5445)File opened: /proc/3/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mips.elf (PID: 5445)File opened: /proc/124/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mips.elf (PID: 5445)File opened: /proc/245/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mips.elf (PID: 5445)File opened: /proc/1588/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mips.elf (PID: 5445)File opened: /proc/125/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mips.elf (PID: 5445)File opened: /proc/4/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mips.elf (PID: 5445)File opened: /proc/246/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mips.elf (PID: 5445)File opened: /proc/126/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mips.elf (PID: 5445)File opened: /proc/5/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mips.elf (PID: 5445)File opened: /proc/247/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mips.elf (PID: 5445)File opened: /proc/127/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mips.elf (PID: 5445)File opened: /proc/6/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mips.elf (PID: 5445)File opened: /proc/248/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mips.elf (PID: 5445)File opened: /proc/128/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mips.elf (PID: 5445)File opened: /proc/7/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mips.elf (PID: 5445)File opened: /proc/249/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mips.elf (PID: 5445)File opened: /proc/129/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mips.elf (PID: 5445)File opened: /proc/8/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mips.elf (PID: 5445)File opened: /proc/800/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mips.elf (PID: 5445)File opened: /proc/9/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mips.elf (PID: 5445)File opened: /proc/1906/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mips.elf (PID: 5445)File opened: /proc/802/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mips.elf (PID: 5445)File opened: /proc/803/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mips.elf (PID: 5445)File opened: /proc/20/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mips.elf (PID: 5445)File opened: /proc/21/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mips.elf (PID: 5445)File opened: /proc/22/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mips.elf (PID: 5445)File opened: /proc/23/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mips.elf (PID: 5445)File opened: /proc/24/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mips.elf (PID: 5445)File opened: /proc/25/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mips.elf (PID: 5445)File opened: /proc/5286/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mips.elf (PID: 5445)File opened: /proc/26/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mips.elf (PID: 5445)File opened: /proc/27/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mips.elf (PID: 5445)File opened: /proc/28/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mips.elf (PID: 5445)File opened: /proc/29/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mips.elf (PID: 5445)File opened: /proc/3420/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mips.elf (PID: 5445)File opened: /proc/1482/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mips.elf (PID: 5445)File opened: /proc/490/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mips.elf (PID: 5445)File opened: /proc/1480/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mips.elf (PID: 5445)File opened: /proc/250/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mips.elf (PID: 5445)File opened: /proc/371/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mips.elf (PID: 5445)File opened: /proc/130/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mips.elf (PID: 5445)File opened: /proc/251/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mips.elf (PID: 5445)File opened: /proc/131/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mips.elf (PID: 5445)File opened: /proc/252/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mips.elf (PID: 5445)File opened: /proc/132/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mips.elf (PID: 5445)File opened: /proc/253/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mips.elf (PID: 5445)File opened: /proc/254/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mips.elf (PID: 5445)File opened: /proc/1238/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mips.elf (PID: 5445)File opened: /proc/134/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mips.elf (PID: 5445)File opened: /proc/255/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mips.elf (PID: 5445)File opened: /proc/256/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mips.elf (PID: 5445)File opened: /proc/257/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mips.elf (PID: 5445)File opened: /proc/378/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mips.elf (PID: 5445)File opened: /proc/3413/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mips.elf (PID: 5445)File opened: /proc/258/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mips.elf (PID: 5445)File opened: /proc/259/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mips.elf (PID: 5445)File opened: /proc/1475/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mips.elf (PID: 5445)File opened: /proc/936/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mips.elf (PID: 5445)File opened: /proc/30/statusJump to behavior
Source: ub8ehJSePAfc9FYqZIT6.mips.elfSubmission file: segment LOAD with 7.9457 entropy (max. 8.0)
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mips.elf (PID: 5445)Queries kernel information via 'uname': Jump to behavior
Source: ub8ehJSePAfc9FYqZIT6.mips.elf, 5445.1.00007ffd26faa000.00007ffd26fcb000.rw-.sdmp, ub8ehJSePAfc9FYqZIT6.mips.elf, 5448.1.00007ffd26faa000.00007ffd26fcb000.rw-.sdmp, ub8ehJSePAfc9FYqZIT6.mips.elf, 5450.1.00007ffd26faa000.00007ffd26fcb000.rw-.sdmp, ub8ehJSePAfc9FYqZIT6.mips.elf, 5456.1.00007ffd26faa000.00007ffd26fcb000.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-mips/tmp/ub8ehJSePAfc9FYqZIT6.mips.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/ub8ehJSePAfc9FYqZIT6.mips.elf
Source: ub8ehJSePAfc9FYqZIT6.mips.elf, 5445.1.0000559cb564d000.0000559cb56f5000.rw-.sdmp, ub8ehJSePAfc9FYqZIT6.mips.elf, 5448.1.0000559cb564d000.0000559cb56f5000.rw-.sdmp, ub8ehJSePAfc9FYqZIT6.mips.elf, 5450.1.0000559cb564d000.0000559cb56f5000.rw-.sdmp, ub8ehJSePAfc9FYqZIT6.mips.elf, 5456.1.0000559cb564d000.0000559cb56f5000.rw-.sdmpBinary or memory string: U!/etc/qemu-binfmt/mips
Source: ub8ehJSePAfc9FYqZIT6.mips.elf, 5445.1.0000559cb564d000.0000559cb56f5000.rw-.sdmp, ub8ehJSePAfc9FYqZIT6.mips.elf, 5448.1.0000559cb564d000.0000559cb56f5000.rw-.sdmp, ub8ehJSePAfc9FYqZIT6.mips.elf, 5450.1.0000559cb564d000.0000559cb56f5000.rw-.sdmp, ub8ehJSePAfc9FYqZIT6.mips.elf, 5456.1.0000559cb564d000.0000559cb56f5000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/mips
Source: ub8ehJSePAfc9FYqZIT6.mips.elf, 5445.1.00007ffd26faa000.00007ffd26fcb000.rw-.sdmp, ub8ehJSePAfc9FYqZIT6.mips.elf, 5448.1.00007ffd26faa000.00007ffd26fcb000.rw-.sdmp, ub8ehJSePAfc9FYqZIT6.mips.elf, 5450.1.00007ffd26faa000.00007ffd26fcb000.rw-.sdmp, ub8ehJSePAfc9FYqZIT6.mips.elf, 5456.1.00007ffd26faa000.00007ffd26fcb000.rw-.sdmpBinary or memory string: /usr/bin/qemu-mips
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception11
Obfuscated Files or Information
1
OS Credential Dumping
11
Security Software Discovery
Remote ServicesData from Local System1
Non-Standard Port
Exfiltration Over Other Network MediumAbuse Accessibility Features
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1581068 Sample: ub8ehJSePAfc9FYqZIT6.mips.elf Startdate: 26/12/2024 Architecture: LINUX Score: 60 20 92.118.56.167, 33606, 33608, 33610 M247GB Germany 2->20 22 Malicious sample detected (through community Yara rule) 2->22 24 Multi AV Scanner detection for submitted file 2->24 26 Sample is packed with UPX 2->26 8 ub8ehJSePAfc9FYqZIT6.mips.elf 2->8         started        signatures3 process4 process5 10 ub8ehJSePAfc9FYqZIT6.mips.elf 8->10         started        12 ub8ehJSePAfc9FYqZIT6.mips.elf 8->12         started        14 ub8ehJSePAfc9FYqZIT6.mips.elf 8->14         started        process6 16 ub8ehJSePAfc9FYqZIT6.mips.elf 10->16         started        18 ub8ehJSePAfc9FYqZIT6.mips.elf 10->18         started       
SourceDetectionScannerLabelLink
ub8ehJSePAfc9FYqZIT6.mips.elf37%ReversingLabsLinux.Trojan.Gafgyt
No Antivirus matches
No Antivirus matches
No Antivirus matches
No contacted domains info
NameSourceMaliciousAntivirus DetectionReputation
http://upx.sf.netub8ehJSePAfc9FYqZIT6.mips.elffalse
    high
    • No. of IPs < 25%
    • 25% < No. of IPs < 50%
    • 50% < No. of IPs < 75%
    • 75% < No. of IPs
    IPDomainCountryFlagASNASN NameMalicious
    92.118.56.167
    unknownGermany
    9009M247GBfalse
    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
    92.118.56.167ub8ehJSePAfc9FYqZIT6.arm.elfGet hashmaliciousMiraiBrowse
      ub8ehJSePAfc9FYqZIT6.m68k.elfGet hashmaliciousMiraiBrowse
        ub8ehJSePAfc9FYqZIT6.sh4.elfGet hashmaliciousUnknownBrowse
          ub8ehJSePAfc9FYqZIT6.i686.elfGet hashmaliciousUnknownBrowse
            ub8ehJSePAfc9FYqZIT6.x86.elfGet hashmaliciousUnknownBrowse
              No context
              MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
              M247GBub8ehJSePAfc9FYqZIT6.arm.elfGet hashmaliciousMiraiBrowse
              • 92.118.56.167
              ub8ehJSePAfc9FYqZIT6.m68k.elfGet hashmaliciousMiraiBrowse
              • 92.118.56.167
              ub8ehJSePAfc9FYqZIT6.sh4.elfGet hashmaliciousUnknownBrowse
              • 92.118.56.167
              ub8ehJSePAfc9FYqZIT6.i686.elfGet hashmaliciousUnknownBrowse
              • 92.118.56.167
              ub8ehJSePAfc9FYqZIT6.x86.elfGet hashmaliciousUnknownBrowse
              • 92.118.56.167
              http://au.kirmalk.com/watch.php?vid=7750fd3c8Get hashmaliciousUnknownBrowse
              • 38.132.109.126
              nklppc.elfGet hashmaliciousUnknownBrowse
              • 193.160.72.174
              https://en.newsnowbangla.com/archives/69912Get hashmaliciousHTMLPhisher, TechSupportScamBrowse
              • 45.10.162.162
              arm.elfGet hashmaliciousUnknownBrowse
              • 92.249.48.36
              powerpc.nn.elfGet hashmaliciousMirai, OkiruBrowse
              • 38.204.189.65
              No context
              No context
              No created / dropped files found
              File type:ELF 32-bit MSB executable, MIPS, MIPS-I version 1 (SYSV), statically linked, no section header
              Entropy (8bit):7.943500284939222
              TrID:
              • ELF Executable and Linkable format (Linux) (4029/14) 50.16%
              • ELF Executable and Linkable format (generic) (4004/1) 49.84%
              File name:ub8ehJSePAfc9FYqZIT6.mips.elf
              File size:44'148 bytes
              MD5:64fa0599b70a18403044c5ead883bb4a
              SHA1:a36e9a7e4989cacce45ab21473fc96f450d1585a
              SHA256:036a4c6d7e77446c407820f59b351b834aa4cb0c7d3075aed5830474bc355f90
              SHA512:5b8738b611cf774d494dec0703e19c5fc54a246eb27e08c6f7a1a1be72aeccd5ee8bdb6916c0676a3bc6625954a91a6f02441ecc2903d7d5a5db072d2f323b85
              SSDEEP:768:57ph1LjFGpx652lJXasyEk6JGbr6MWiNIx8FwEEosJgGlzDpbuR1JXK:5zA65yk6JGbrbNwQ6okVJug
              TLSH:F113E16D550488EEE4858C7547E80B507F320BB0F463D843E50DB497EAAA9F93E235AD
              File Content Preview:.ELF...........................4.........4. ...(.......................D...D.................C...C......................UPX!.h.....................V.......?.E.h4...@b..) ..]....E..`..........@4#.Y..~.9....b...Q".|.H.%Q.z....6u.."....cLw.........b.........

              ELF header

              Class:ELF32
              Data:2's complement, big endian
              Version:1 (current)
              Machine:MIPS R3000
              Version Number:0x1
              Type:EXEC (Executable file)
              OS/ABI:UNIX - System V
              ABI Version:0
              Entry Point Address:0x109800
              Flags:0x1007
              ELF Header Size:52
              Program Header Offset:52
              Program Header Size:32
              Number of Program Headers:2
              Section Header Offset:0
              Section Header Size:40
              Number of Section Headers:0
              Header String Table Index:0
              TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
              LOAD0x00x1000000x1000000xab440xab447.94570x5R E0x10000
              LOAD0xcffc0x43cffc0x43cffc0x00x00.00000x6RW 0x10000
              TimestampSource PortDest PortSource IPDest IP
              Dec 26, 2024 22:07:11.626250029 CET336063778192.168.2.1392.118.56.167
              Dec 26, 2024 22:07:11.745815992 CET37783360692.118.56.167192.168.2.13
              Dec 26, 2024 22:07:11.745887995 CET336063778192.168.2.1392.118.56.167
              Dec 26, 2024 22:07:11.781708956 CET336063778192.168.2.1392.118.56.167
              Dec 26, 2024 22:07:11.901293039 CET37783360692.118.56.167192.168.2.13
              Dec 26, 2024 22:07:11.901340008 CET336063778192.168.2.1392.118.56.167
              Dec 26, 2024 22:07:12.020904064 CET37783360692.118.56.167192.168.2.13
              Dec 26, 2024 22:07:12.980007887 CET37783360692.118.56.167192.168.2.13
              Dec 26, 2024 22:07:12.980618000 CET336063778192.168.2.1392.118.56.167
              Dec 26, 2024 22:07:12.980618000 CET336063778192.168.2.1392.118.56.167
              Dec 26, 2024 22:07:12.981193066 CET336083778192.168.2.1392.118.56.167
              Dec 26, 2024 22:07:13.100682020 CET37783360892.118.56.167192.168.2.13
              Dec 26, 2024 22:07:13.100764990 CET336083778192.168.2.1392.118.56.167
              Dec 26, 2024 22:07:13.102355957 CET336083778192.168.2.1392.118.56.167
              Dec 26, 2024 22:07:13.221831083 CET37783360892.118.56.167192.168.2.13
              Dec 26, 2024 22:07:13.221920967 CET336083778192.168.2.1392.118.56.167
              Dec 26, 2024 22:07:13.341774940 CET37783360892.118.56.167192.168.2.13
              Dec 26, 2024 22:07:14.329773903 CET37783360892.118.56.167192.168.2.13
              Dec 26, 2024 22:07:14.329988003 CET336083778192.168.2.1392.118.56.167
              Dec 26, 2024 22:07:14.330045938 CET336083778192.168.2.1392.118.56.167
              Dec 26, 2024 22:07:14.330595016 CET336103778192.168.2.1392.118.56.167
              Dec 26, 2024 22:07:14.450041056 CET37783361092.118.56.167192.168.2.13
              Dec 26, 2024 22:07:14.450193882 CET336103778192.168.2.1392.118.56.167
              Dec 26, 2024 22:07:14.451030970 CET336103778192.168.2.1392.118.56.167
              Dec 26, 2024 22:07:14.570504904 CET37783361092.118.56.167192.168.2.13
              Dec 26, 2024 22:07:14.570662022 CET336103778192.168.2.1392.118.56.167
              Dec 26, 2024 22:07:14.690130949 CET37783361092.118.56.167192.168.2.13
              Dec 26, 2024 22:07:16.172131062 CET37783361092.118.56.167192.168.2.13
              Dec 26, 2024 22:07:16.172316074 CET336103778192.168.2.1392.118.56.167
              Dec 26, 2024 22:07:16.172346115 CET336103778192.168.2.1392.118.56.167
              Dec 26, 2024 22:07:16.172395945 CET37783361092.118.56.167192.168.2.13
              Dec 26, 2024 22:07:16.172422886 CET37783361092.118.56.167192.168.2.13
              Dec 26, 2024 22:07:16.172466040 CET336103778192.168.2.1392.118.56.167
              Dec 26, 2024 22:07:16.172466040 CET336103778192.168.2.1392.118.56.167
              Dec 26, 2024 22:07:16.172925949 CET336123778192.168.2.1392.118.56.167
              Dec 26, 2024 22:07:16.292340994 CET37783361292.118.56.167192.168.2.13
              Dec 26, 2024 22:07:16.292417049 CET336123778192.168.2.1392.118.56.167
              Dec 26, 2024 22:07:17.204334021 CET336123778192.168.2.1392.118.56.167
              Dec 26, 2024 22:07:17.323895931 CET37783361292.118.56.167192.168.2.13
              Dec 26, 2024 22:07:17.323997974 CET336123778192.168.2.1392.118.56.167
              Dec 26, 2024 22:07:17.325158119 CET336123778192.168.2.1392.118.56.167
              Dec 26, 2024 22:07:17.382666111 CET336143778192.168.2.1392.118.56.167
              Dec 26, 2024 22:07:17.444967031 CET37783361292.118.56.167192.168.2.13
              Dec 26, 2024 22:07:17.445013046 CET336123778192.168.2.1392.118.56.167
              Dec 26, 2024 22:07:17.502259970 CET37783361492.118.56.167192.168.2.13
              Dec 26, 2024 22:07:17.502334118 CET336143778192.168.2.1392.118.56.167
              Dec 26, 2024 22:07:17.521253109 CET336143778192.168.2.1392.118.56.167
              Dec 26, 2024 22:07:17.564548969 CET37783361292.118.56.167192.168.2.13
              Dec 26, 2024 22:07:17.640769005 CET37783361492.118.56.167192.168.2.13
              Dec 26, 2024 22:07:17.640842915 CET336143778192.168.2.1392.118.56.167
              Dec 26, 2024 22:07:17.760312080 CET37783361492.118.56.167192.168.2.13
              Dec 26, 2024 22:07:18.572926998 CET37783361292.118.56.167192.168.2.13
              Dec 26, 2024 22:07:18.573271036 CET336123778192.168.2.1392.118.56.167
              Dec 26, 2024 22:07:18.573364019 CET336123778192.168.2.1392.118.56.167
              Dec 26, 2024 22:07:18.574027061 CET336163778192.168.2.1392.118.56.167
              Dec 26, 2024 22:07:18.693532944 CET37783361692.118.56.167192.168.2.13
              Dec 26, 2024 22:07:18.693707943 CET336163778192.168.2.1392.118.56.167
              Dec 26, 2024 22:07:18.694762945 CET336163778192.168.2.1392.118.56.167
              Dec 26, 2024 22:07:18.732407093 CET37783361492.118.56.167192.168.2.13
              Dec 26, 2024 22:07:18.732476950 CET336143778192.168.2.1392.118.56.167
              Dec 26, 2024 22:07:18.732893944 CET336143778192.168.2.1392.118.56.167
              Dec 26, 2024 22:07:18.733444929 CET336183778192.168.2.1392.118.56.167
              Dec 26, 2024 22:07:18.814357042 CET37783361692.118.56.167192.168.2.13
              Dec 26, 2024 22:07:18.814414978 CET336163778192.168.2.1392.118.56.167
              Dec 26, 2024 22:07:18.853091002 CET37783361892.118.56.167192.168.2.13
              Dec 26, 2024 22:07:18.853275061 CET336183778192.168.2.1392.118.56.167
              Dec 26, 2024 22:07:18.854424953 CET336183778192.168.2.1392.118.56.167
              Dec 26, 2024 22:07:18.934029102 CET37783361692.118.56.167192.168.2.13
              Dec 26, 2024 22:07:18.973912954 CET37783361892.118.56.167192.168.2.13
              Dec 26, 2024 22:07:18.974193096 CET336183778192.168.2.1392.118.56.167
              Dec 26, 2024 22:07:19.093755960 CET37783361892.118.56.167192.168.2.13
              Dec 26, 2024 22:07:19.923718929 CET37783361692.118.56.167192.168.2.13
              Dec 26, 2024 22:07:19.923831940 CET336163778192.168.2.1392.118.56.167
              Dec 26, 2024 22:07:19.923885107 CET336163778192.168.2.1392.118.56.167
              Dec 26, 2024 22:07:19.924439907 CET336203778192.168.2.1392.118.56.167
              Dec 26, 2024 22:07:20.043986082 CET37783362092.118.56.167192.168.2.13
              Dec 26, 2024 22:07:20.044147015 CET336203778192.168.2.1392.118.56.167
              Dec 26, 2024 22:07:20.045166016 CET336203778192.168.2.1392.118.56.167
              Dec 26, 2024 22:07:20.082882881 CET37783361892.118.56.167192.168.2.13
              Dec 26, 2024 22:07:20.082966089 CET336183778192.168.2.1392.118.56.167
              Dec 26, 2024 22:07:20.083003044 CET336183778192.168.2.1392.118.56.167
              Dec 26, 2024 22:07:20.083420992 CET336223778192.168.2.1392.118.56.167
              Dec 26, 2024 22:07:20.164679050 CET37783362092.118.56.167192.168.2.13
              Dec 26, 2024 22:07:20.164860964 CET336203778192.168.2.1392.118.56.167
              Dec 26, 2024 22:07:20.202826023 CET37783362292.118.56.167192.168.2.13
              Dec 26, 2024 22:07:20.202958107 CET336223778192.168.2.1392.118.56.167
              Dec 26, 2024 22:07:20.204015017 CET336223778192.168.2.1392.118.56.167
              Dec 26, 2024 22:07:20.284569025 CET37783362092.118.56.167192.168.2.13
              Dec 26, 2024 22:07:20.323548079 CET37783362292.118.56.167192.168.2.13
              Dec 26, 2024 22:07:20.323685884 CET336223778192.168.2.1392.118.56.167
              Dec 26, 2024 22:07:20.443428993 CET37783362292.118.56.167192.168.2.13
              Dec 26, 2024 22:07:21.274275064 CET37783362092.118.56.167192.168.2.13
              Dec 26, 2024 22:07:21.274502993 CET336203778192.168.2.1392.118.56.167
              Dec 26, 2024 22:07:21.274560928 CET336203778192.168.2.1392.118.56.167
              Dec 26, 2024 22:07:21.275204897 CET336243778192.168.2.1392.118.56.167
              Dec 26, 2024 22:07:21.394768953 CET37783362492.118.56.167192.168.2.13
              Dec 26, 2024 22:07:21.395066023 CET336243778192.168.2.1392.118.56.167
              Dec 26, 2024 22:07:21.429158926 CET37783362292.118.56.167192.168.2.13
              Dec 26, 2024 22:07:21.429409027 CET336223778192.168.2.1392.118.56.167
              Dec 26, 2024 22:07:21.429578066 CET336223778192.168.2.1392.118.56.167
              Dec 26, 2024 22:07:21.430248022 CET336263778192.168.2.1392.118.56.167
              Dec 26, 2024 22:07:21.549877882 CET37783362692.118.56.167192.168.2.13
              Dec 26, 2024 22:07:21.550010920 CET336263778192.168.2.1392.118.56.167
              Dec 26, 2024 22:07:21.551075935 CET336263778192.168.2.1392.118.56.167
              Dec 26, 2024 22:07:21.671416998 CET37783362692.118.56.167192.168.2.13
              Dec 26, 2024 22:07:21.671488047 CET336263778192.168.2.1392.118.56.167
              Dec 26, 2024 22:07:21.791075945 CET37783362692.118.56.167192.168.2.13
              Dec 26, 2024 22:07:22.292311907 CET336243778192.168.2.1392.118.56.167
              Dec 26, 2024 22:07:22.411967993 CET37783362492.118.56.167192.168.2.13
              Dec 26, 2024 22:07:22.412164927 CET336243778192.168.2.1392.118.56.167
              Dec 26, 2024 22:07:22.413178921 CET336243778192.168.2.1392.118.56.167
              Dec 26, 2024 22:07:22.532871008 CET37783362492.118.56.167192.168.2.13
              Dec 26, 2024 22:07:22.533057928 CET336243778192.168.2.1392.118.56.167
              Dec 26, 2024 22:07:22.652710915 CET37783362492.118.56.167192.168.2.13
              Dec 26, 2024 22:07:22.785238028 CET37783362692.118.56.167192.168.2.13
              Dec 26, 2024 22:07:22.785365105 CET336263778192.168.2.1392.118.56.167
              Dec 26, 2024 22:07:22.785444975 CET336263778192.168.2.1392.118.56.167
              Dec 26, 2024 22:07:22.786058903 CET336283778192.168.2.1392.118.56.167
              Dec 26, 2024 22:07:22.905936003 CET37783362892.118.56.167192.168.2.13
              Dec 26, 2024 22:07:22.906069040 CET336283778192.168.2.1392.118.56.167
              Dec 26, 2024 22:07:22.907027960 CET336283778192.168.2.1392.118.56.167
              Dec 26, 2024 22:07:23.026742935 CET37783362892.118.56.167192.168.2.13
              Dec 26, 2024 22:07:23.026840925 CET336283778192.168.2.1392.118.56.167
              Dec 26, 2024 22:07:23.146655083 CET37783362892.118.56.167192.168.2.13
              Dec 26, 2024 22:07:23.641881943 CET37783362492.118.56.167192.168.2.13
              Dec 26, 2024 22:07:23.642014027 CET336243778192.168.2.1392.118.56.167
              Dec 26, 2024 22:07:23.642081976 CET336243778192.168.2.1392.118.56.167
              Dec 26, 2024 22:07:23.642621040 CET336303778192.168.2.1392.118.56.167
              Dec 26, 2024 22:07:23.762377024 CET37783363092.118.56.167192.168.2.13
              Dec 26, 2024 22:07:23.762469053 CET336303778192.168.2.1392.118.56.167
              Dec 26, 2024 22:07:23.763195992 CET336303778192.168.2.1392.118.56.167
              Dec 26, 2024 22:07:23.882673025 CET37783363092.118.56.167192.168.2.13
              Dec 26, 2024 22:07:23.883018017 CET336303778192.168.2.1392.118.56.167
              Dec 26, 2024 22:07:24.002652884 CET37783363092.118.56.167192.168.2.13
              Dec 26, 2024 22:07:24.139302015 CET37783362892.118.56.167192.168.2.13
              Dec 26, 2024 22:07:24.139457941 CET336283778192.168.2.1392.118.56.167
              Dec 26, 2024 22:07:24.139477015 CET336283778192.168.2.1392.118.56.167
              Dec 26, 2024 22:07:24.140129089 CET336323778192.168.2.1392.118.56.167
              Dec 26, 2024 22:07:24.259742022 CET37783363292.118.56.167192.168.2.13
              Dec 26, 2024 22:07:24.259890079 CET336323778192.168.2.1392.118.56.167
              Dec 26, 2024 22:07:24.261166096 CET336323778192.168.2.1392.118.56.167
              Dec 26, 2024 22:07:24.380909920 CET37783363292.118.56.167192.168.2.13
              Dec 26, 2024 22:07:24.381047964 CET336323778192.168.2.1392.118.56.167
              Dec 26, 2024 22:07:24.500858068 CET37783363292.118.56.167192.168.2.13
              Dec 26, 2024 22:07:24.991729975 CET37783363092.118.56.167192.168.2.13
              Dec 26, 2024 22:07:24.992158890 CET336303778192.168.2.1392.118.56.167
              Dec 26, 2024 22:07:24.992223978 CET336303778192.168.2.1392.118.56.167
              Dec 26, 2024 22:07:24.992976904 CET336343778192.168.2.1392.118.56.167
              Dec 26, 2024 22:07:25.112658024 CET37783363492.118.56.167192.168.2.13
              Dec 26, 2024 22:07:25.112834930 CET336343778192.168.2.1392.118.56.167
              Dec 26, 2024 22:07:25.114003897 CET336343778192.168.2.1392.118.56.167
              Dec 26, 2024 22:07:25.233601093 CET37783363492.118.56.167192.168.2.13
              Dec 26, 2024 22:07:25.233748913 CET336343778192.168.2.1392.118.56.167
              Dec 26, 2024 22:07:25.354409933 CET37783363492.118.56.167192.168.2.13
              Dec 26, 2024 22:07:25.490247011 CET37783363292.118.56.167192.168.2.13
              Dec 26, 2024 22:07:25.490657091 CET336323778192.168.2.1392.118.56.167
              Dec 26, 2024 22:07:25.490657091 CET336323778192.168.2.1392.118.56.167
              Dec 26, 2024 22:07:25.491275072 CET336363778192.168.2.1392.118.56.167
              Dec 26, 2024 22:07:25.611049891 CET37783363692.118.56.167192.168.2.13
              Dec 26, 2024 22:07:25.611232042 CET336363778192.168.2.1392.118.56.167
              Dec 26, 2024 22:07:25.612413883 CET336363778192.168.2.1392.118.56.167
              Dec 26, 2024 22:07:25.732014894 CET37783363692.118.56.167192.168.2.13
              Dec 26, 2024 22:07:25.732247114 CET336363778192.168.2.1392.118.56.167
              Dec 26, 2024 22:07:25.851999998 CET37783363692.118.56.167192.168.2.13
              Dec 26, 2024 22:07:26.472670078 CET37783363492.118.56.167192.168.2.13
              Dec 26, 2024 22:07:26.472882986 CET336343778192.168.2.1392.118.56.167
              Dec 26, 2024 22:07:26.473006010 CET336343778192.168.2.1392.118.56.167
              Dec 26, 2024 22:07:26.473737001 CET336383778192.168.2.1392.118.56.167
              Dec 26, 2024 22:07:26.593373060 CET37783363892.118.56.167192.168.2.13
              Dec 26, 2024 22:07:26.593488932 CET336383778192.168.2.1392.118.56.167
              Dec 26, 2024 22:07:26.594810009 CET336383778192.168.2.1392.118.56.167
              Dec 26, 2024 22:07:26.714560032 CET37783363892.118.56.167192.168.2.13
              Dec 26, 2024 22:07:26.714776993 CET336383778192.168.2.1392.118.56.167
              Dec 26, 2024 22:07:26.834438086 CET37783363892.118.56.167192.168.2.13
              Dec 26, 2024 22:07:35.622874022 CET336363778192.168.2.1392.118.56.167
              Dec 26, 2024 22:07:35.742816925 CET37783363692.118.56.167192.168.2.13
              Dec 26, 2024 22:07:35.981456041 CET37783363692.118.56.167192.168.2.13
              Dec 26, 2024 22:07:35.981574059 CET336363778192.168.2.1392.118.56.167
              Dec 26, 2024 22:07:36.596518040 CET336383778192.168.2.1392.118.56.167
              Dec 26, 2024 22:07:36.716145992 CET37783363892.118.56.167192.168.2.13
              Dec 26, 2024 22:07:36.956094027 CET37783363892.118.56.167192.168.2.13
              Dec 26, 2024 22:07:36.956367970 CET336383778192.168.2.1392.118.56.167
              Dec 26, 2024 22:08:36.025927067 CET336363778192.168.2.1392.118.56.167
              Dec 26, 2024 22:08:36.147207975 CET37783363692.118.56.167192.168.2.13
              Dec 26, 2024 22:08:36.388101101 CET37783363692.118.56.167192.168.2.13
              Dec 26, 2024 22:08:36.388420105 CET336363778192.168.2.1392.118.56.167
              Dec 26, 2024 22:08:37.011234045 CET336383778192.168.2.1392.118.56.167
              Dec 26, 2024 22:08:37.131055117 CET37783363892.118.56.167192.168.2.13
              Dec 26, 2024 22:08:37.370872021 CET37783363892.118.56.167192.168.2.13
              Dec 26, 2024 22:08:37.371157885 CET336383778192.168.2.1392.118.56.167

              System Behavior

              Start time (UTC):21:07:10
              Start date (UTC):26/12/2024
              Path:/tmp/ub8ehJSePAfc9FYqZIT6.mips.elf
              Arguments:/tmp/ub8ehJSePAfc9FYqZIT6.mips.elf
              File size:5777432 bytes
              MD5 hash:0083f1f0e77be34ad27f849842bbb00c

              Start time (UTC):21:07:10
              Start date (UTC):26/12/2024
              Path:/tmp/ub8ehJSePAfc9FYqZIT6.mips.elf
              Arguments:-
              File size:5777432 bytes
              MD5 hash:0083f1f0e77be34ad27f849842bbb00c

              Start time (UTC):21:07:10
              Start date (UTC):26/12/2024
              Path:/tmp/ub8ehJSePAfc9FYqZIT6.mips.elf
              Arguments:-
              File size:5777432 bytes
              MD5 hash:0083f1f0e77be34ad27f849842bbb00c

              Start time (UTC):21:07:10
              Start date (UTC):26/12/2024
              Path:/tmp/ub8ehJSePAfc9FYqZIT6.mips.elf
              Arguments:-
              File size:5777432 bytes
              MD5 hash:0083f1f0e77be34ad27f849842bbb00c

              Start time (UTC):21:07:16
              Start date (UTC):26/12/2024
              Path:/tmp/ub8ehJSePAfc9FYqZIT6.mips.elf
              Arguments:-
              File size:5777432 bytes
              MD5 hash:0083f1f0e77be34ad27f849842bbb00c

              Start time (UTC):21:07:16
              Start date (UTC):26/12/2024
              Path:/tmp/ub8ehJSePAfc9FYqZIT6.mips.elf
              Arguments:-
              File size:5777432 bytes
              MD5 hash:0083f1f0e77be34ad27f849842bbb00c