Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
ub8ehJSePAfc9FYqZIT6.arm6.elf

Overview

General Information

Sample name:ub8ehJSePAfc9FYqZIT6.arm6.elf
Analysis ID:1581074
MD5:e93c4d4afb75bc0b947ad0ecfb31f4cd
SHA1:5ce4e75e6e053bd2f754f5d21a40d4ab8d0eebc4
SHA256:dbad09080055f65cf654a98bb734c0fc541b8a829be58dee564e681d39b11fec
Tags:elfuser-abuse_ch
Infos:

Detection

Score:60
Range:0 - 100
Whitelisted:false

Signatures

Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Sample is packed with UPX
Detected TCP or UDP traffic on non-standard ports
ELF contains segments with high entropy indicating compressed/encrypted content
Enumerates processes within the "proc" file system
Sample contains only a LOAD segment without any section mappings
Uses the "uname" system call to query kernel version information (possible evasion)
Yara signature match

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1581074
Start date and time:2024-12-26 22:14:36 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 51s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:ub8ehJSePAfc9FYqZIT6.arm6.elf
Detection:MAL
Classification:mal60.evad.linELF@0/0@0/0
  • VT rate limit hit for: ub8ehJSePAfc9FYqZIT6.arm6.elf
Command:/tmp/ub8ehJSePAfc9FYqZIT6.arm6.elf
PID:5569
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
lzrd cock fest"/proc/"/exe
Standard Error:
  • system is lnxubuntu20
  • cleanup
SourceRuleDescriptionAuthorStrings
5569.1.00007f6b1c017000.00007f6b1c02f000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0x15320:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15334:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15348:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1535c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15370:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15384:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15398:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x153ac:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x153c0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x153d4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x153e8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x153fc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15410:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15424:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15438:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1544c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15460:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15474:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15488:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1549c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x154b0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
5585.1.00007f6b1c017000.00007f6b1c02f000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0x15320:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15334:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15348:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1535c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15370:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15384:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15398:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x153ac:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x153c0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x153d4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x153e8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x153fc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15410:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15424:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15438:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1544c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15460:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15474:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15488:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1549c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x154b0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
5571.1.00007f6b1c017000.00007f6b1c02f000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0x15320:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15334:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15348:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1535c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15370:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15384:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15398:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x153ac:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x153c0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x153d4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x153e8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x153fc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15410:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15424:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15438:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1544c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15460:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15474:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15488:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1549c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x154b0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
5573.1.00007f6b1c017000.00007f6b1c02f000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0x15320:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15334:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15348:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1535c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15370:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15384:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15398:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x153ac:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x153c0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x153d4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x153e8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x153fc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15410:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15424:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15438:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1544c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15460:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15474:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15488:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1549c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x154b0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
Process Memory Space: ub8ehJSePAfc9FYqZIT6.arm6.elf PID: 5569Linux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0xc36:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xc4a:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xc5e:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xc72:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xc86:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xc9a:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xcae:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xcc2:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xcd6:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xcea:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xcfe:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xd12:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xd26:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xd3a:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xd4e:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xd62:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xd76:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xd8a:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xd9e:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xdb2:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xdc6:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
Click to see the 3 entries
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: ub8ehJSePAfc9FYqZIT6.arm6.elfReversingLabs: Detection: 36%
Source: global trafficTCP traffic: 192.168.2.14:55802 -> 92.118.56.167:3778
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
Source: ub8ehJSePAfc9FYqZIT6.arm6.elfString found in binary or memory: http://upx.sf.net

System Summary

barindex
Source: 5569.1.00007f6b1c017000.00007f6b1c02f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: 5585.1.00007f6b1c017000.00007f6b1c02f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: 5571.1.00007f6b1c017000.00007f6b1c02f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: 5573.1.00007f6b1c017000.00007f6b1c02f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: Process Memory Space: ub8ehJSePAfc9FYqZIT6.arm6.elf PID: 5569, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: Process Memory Space: ub8ehJSePAfc9FYqZIT6.arm6.elf PID: 5571, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: Process Memory Space: ub8ehJSePAfc9FYqZIT6.arm6.elf PID: 5573, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: Process Memory Space: ub8ehJSePAfc9FYqZIT6.arm6.elf PID: 5585, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: LOAD without section mappingsProgram segment: 0x8000
Source: 5569.1.00007f6b1c017000.00007f6b1c02f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: 5585.1.00007f6b1c017000.00007f6b1c02f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: 5571.1.00007f6b1c017000.00007f6b1c02f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: 5573.1.00007f6b1c017000.00007f6b1c02f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: Process Memory Space: ub8ehJSePAfc9FYqZIT6.arm6.elf PID: 5569, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: Process Memory Space: ub8ehJSePAfc9FYqZIT6.arm6.elf PID: 5571, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: Process Memory Space: ub8ehJSePAfc9FYqZIT6.arm6.elf PID: 5573, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: Process Memory Space: ub8ehJSePAfc9FYqZIT6.arm6.elf PID: 5585, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: classification engineClassification label: mal60.evad.linELF@0/0@0/0

Data Obfuscation

barindex
Source: initial sampleString containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $
Source: initial sampleString containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $
Source: initial sampleString containing UPX found: $Id: UPX 3.94 Copyright (C) 1996-2017 the UPX Team. All Rights Reserved. $
Source: /tmp/ub8ehJSePAfc9FYqZIT6.arm6.elf (PID: 5569)File opened: /proc/3760/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.arm6.elf (PID: 5569)File opened: /proc/1583/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.arm6.elf (PID: 5569)File opened: /proc/2672/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.arm6.elf (PID: 5569)File opened: /proc/110/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.arm6.elf (PID: 5569)File opened: /proc/3759/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.arm6.elf (PID: 5569)File opened: /proc/111/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.arm6.elf (PID: 5569)File opened: /proc/112/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.arm6.elf (PID: 5569)File opened: /proc/113/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.arm6.elf (PID: 5569)File opened: /proc/234/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.arm6.elf (PID: 5569)File opened: /proc/1577/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.arm6.elf (PID: 5569)File opened: /proc/114/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.arm6.elf (PID: 5569)File opened: /proc/235/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.arm6.elf (PID: 5569)File opened: /proc/115/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.arm6.elf (PID: 5569)File opened: /proc/116/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.arm6.elf (PID: 5569)File opened: /proc/117/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.arm6.elf (PID: 5569)File opened: /proc/118/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.arm6.elf (PID: 5569)File opened: /proc/119/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.arm6.elf (PID: 5569)File opened: /proc/3757/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.arm6.elf (PID: 5569)File opened: /proc/10/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.arm6.elf (PID: 5569)File opened: /proc/917/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.arm6.elf (PID: 5569)File opened: /proc/3758/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.arm6.elf (PID: 5569)File opened: /proc/11/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.arm6.elf (PID: 5569)File opened: /proc/12/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.arm6.elf (PID: 5569)File opened: /proc/13/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.arm6.elf (PID: 5569)File opened: /proc/14/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.arm6.elf (PID: 5569)File opened: /proc/15/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.arm6.elf (PID: 5569)File opened: /proc/16/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.arm6.elf (PID: 5569)File opened: /proc/17/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.arm6.elf (PID: 5569)File opened: /proc/18/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.arm6.elf (PID: 5569)File opened: /proc/19/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.arm6.elf (PID: 5569)File opened: /proc/1593/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.arm6.elf (PID: 5569)File opened: /proc/240/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.arm6.elf (PID: 5569)File opened: /proc/120/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.arm6.elf (PID: 5569)File opened: /proc/3094/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.arm6.elf (PID: 5569)File opened: /proc/121/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.arm6.elf (PID: 5569)File opened: /proc/242/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.arm6.elf (PID: 5569)File opened: /proc/3406/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.arm6.elf (PID: 5569)File opened: /proc/1/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.arm6.elf (PID: 5569)File opened: /proc/122/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.arm6.elf (PID: 5569)File opened: /proc/243/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.arm6.elf (PID: 5569)File opened: /proc/2/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.arm6.elf (PID: 5569)File opened: /proc/123/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.arm6.elf (PID: 5569)File opened: /proc/244/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.arm6.elf (PID: 5569)File opened: /proc/1589/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.arm6.elf (PID: 5569)File opened: /proc/3/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.arm6.elf (PID: 5569)File opened: /proc/124/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.arm6.elf (PID: 5569)File opened: /proc/245/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.arm6.elf (PID: 5569)File opened: /proc/1588/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.arm6.elf (PID: 5569)File opened: /proc/125/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.arm6.elf (PID: 5569)File opened: /proc/4/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.arm6.elf (PID: 5569)File opened: /proc/246/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.arm6.elf (PID: 5569)File opened: /proc/3402/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.arm6.elf (PID: 5569)File opened: /proc/126/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.arm6.elf (PID: 5569)File opened: /proc/5/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.arm6.elf (PID: 5569)File opened: /proc/247/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.arm6.elf (PID: 5569)File opened: /proc/127/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.arm6.elf (PID: 5569)File opened: /proc/6/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.arm6.elf (PID: 5569)File opened: /proc/248/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.arm6.elf (PID: 5569)File opened: /proc/128/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.arm6.elf (PID: 5569)File opened: /proc/7/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.arm6.elf (PID: 5569)File opened: /proc/249/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.arm6.elf (PID: 5569)File opened: /proc/8/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.arm6.elf (PID: 5569)File opened: /proc/129/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.arm6.elf (PID: 5569)File opened: /proc/800/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.arm6.elf (PID: 5569)File opened: /proc/9/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.arm6.elf (PID: 5569)File opened: /proc/801/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.arm6.elf (PID: 5569)File opened: /proc/803/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.arm6.elf (PID: 5569)File opened: /proc/20/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.arm6.elf (PID: 5569)File opened: /proc/806/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.arm6.elf (PID: 5569)File opened: /proc/21/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.arm6.elf (PID: 5569)File opened: /proc/807/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.arm6.elf (PID: 5569)File opened: /proc/928/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.arm6.elf (PID: 5569)File opened: /proc/22/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.arm6.elf (PID: 5569)File opened: /proc/23/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.arm6.elf (PID: 5569)File opened: /proc/24/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.arm6.elf (PID: 5569)File opened: /proc/25/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.arm6.elf (PID: 5569)File opened: /proc/26/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.arm6.elf (PID: 5569)File opened: /proc/27/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.arm6.elf (PID: 5569)File opened: /proc/28/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.arm6.elf (PID: 5569)File opened: /proc/29/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.arm6.elf (PID: 5569)File opened: /proc/3420/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.arm6.elf (PID: 5569)File opened: /proc/490/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.arm6.elf (PID: 5569)File opened: /proc/250/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.arm6.elf (PID: 5569)File opened: /proc/130/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.arm6.elf (PID: 5569)File opened: /proc/251/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.arm6.elf (PID: 5569)File opened: /proc/131/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.arm6.elf (PID: 5569)File opened: /proc/252/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.arm6.elf (PID: 5569)File opened: /proc/132/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.arm6.elf (PID: 5569)File opened: /proc/253/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.arm6.elf (PID: 5569)File opened: /proc/254/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.arm6.elf (PID: 5569)File opened: /proc/255/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.arm6.elf (PID: 5569)File opened: /proc/135/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.arm6.elf (PID: 5569)File opened: /proc/256/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.arm6.elf (PID: 5569)File opened: /proc/1599/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.arm6.elf (PID: 5569)File opened: /proc/257/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.arm6.elf (PID: 5569)File opened: /proc/378/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.arm6.elf (PID: 5569)File opened: /proc/258/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.arm6.elf (PID: 5569)File opened: /proc/3412/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.arm6.elf (PID: 5569)File opened: /proc/259/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.arm6.elf (PID: 5569)File opened: /proc/30/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.arm6.elf (PID: 5569)File opened: /proc/35/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.arm6.elf (PID: 5569)File opened: /proc/1371/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.arm6.elf (PID: 5569)File opened: /proc/260/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.arm6.elf (PID: 5569)File opened: /proc/261/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.arm6.elf (PID: 5569)File opened: /proc/262/statusJump to behavior
Source: ub8ehJSePAfc9FYqZIT6.arm6.elfSubmission file: segment LOAD with 7.9729 entropy (max. 8.0)
Source: /tmp/ub8ehJSePAfc9FYqZIT6.arm6.elf (PID: 5569)Queries kernel information via 'uname': Jump to behavior
Source: ub8ehJSePAfc9FYqZIT6.arm6.elf, 5569.1.00007fff78cdd000.00007fff78cfe000.rw-.sdmp, ub8ehJSePAfc9FYqZIT6.arm6.elf, 5571.1.00007fff78cdd000.00007fff78cfe000.rw-.sdmp, ub8ehJSePAfc9FYqZIT6.arm6.elf, 5573.1.00007fff78cdd000.00007fff78cfe000.rw-.sdmp, ub8ehJSePAfc9FYqZIT6.arm6.elf, 5585.1.00007fff78cdd000.00007fff78cfe000.rw-.sdmpBinary or memory string: ~x86_64/usr/bin/qemu-arm/tmp/ub8ehJSePAfc9FYqZIT6.arm6.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/ub8ehJSePAfc9FYqZIT6.arm6.elf
Source: ub8ehJSePAfc9FYqZIT6.arm6.elf, 5569.1.0000562aea9b4000.0000562aeaba2000.rw-.sdmp, ub8ehJSePAfc9FYqZIT6.arm6.elf, 5571.1.0000562aea9b4000.0000562aeaba2000.rw-.sdmp, ub8ehJSePAfc9FYqZIT6.arm6.elf, 5573.1.0000562aea9b4000.0000562aeaba2000.rw-.sdmp, ub8ehJSePAfc9FYqZIT6.arm6.elf, 5585.1.0000562aea9b4000.0000562aeaba2000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/arm
Source: ub8ehJSePAfc9FYqZIT6.arm6.elf, 5569.1.00007fff78cdd000.00007fff78cfe000.rw-.sdmp, ub8ehJSePAfc9FYqZIT6.arm6.elf, 5571.1.00007fff78cdd000.00007fff78cfe000.rw-.sdmp, ub8ehJSePAfc9FYqZIT6.arm6.elf, 5573.1.00007fff78cdd000.00007fff78cfe000.rw-.sdmp, ub8ehJSePAfc9FYqZIT6.arm6.elf, 5585.1.00007fff78cdd000.00007fff78cfe000.rw-.sdmpBinary or memory string: /usr/bin/qemu-arm
Source: ub8ehJSePAfc9FYqZIT6.arm6.elf, 5569.1.0000562aea9b4000.0000562aeaba2000.rw-.sdmp, ub8ehJSePAfc9FYqZIT6.arm6.elf, 5571.1.0000562aea9b4000.0000562aeaba2000.rw-.sdmp, ub8ehJSePAfc9FYqZIT6.arm6.elf, 5573.1.0000562aea9b4000.0000562aeaba2000.rw-.sdmp, ub8ehJSePAfc9FYqZIT6.arm6.elf, 5585.1.0000562aea9b4000.0000562aeaba2000.rw-.sdmpBinary or memory string: *V!/etc/qemu-binfmt/arm
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception11
Obfuscated Files or Information
1
OS Credential Dumping
11
Security Software Discovery
Remote ServicesData from Local System1
Non-Standard Port
Exfiltration Over Other Network MediumAbuse Accessibility Features
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1581074 Sample: ub8ehJSePAfc9FYqZIT6.arm6.elf Startdate: 26/12/2024 Architecture: LINUX Score: 60 20 92.118.56.167, 3778, 55802, 55804 M247GB Germany 2->20 22 Malicious sample detected (through community Yara rule) 2->22 24 Multi AV Scanner detection for submitted file 2->24 26 Sample is packed with UPX 2->26 8 ub8ehJSePAfc9FYqZIT6.arm6.elf 2->8         started        signatures3 process4 process5 10 ub8ehJSePAfc9FYqZIT6.arm6.elf 8->10         started        12 ub8ehJSePAfc9FYqZIT6.arm6.elf 8->12         started        14 ub8ehJSePAfc9FYqZIT6.arm6.elf 8->14         started        process6 16 ub8ehJSePAfc9FYqZIT6.arm6.elf 10->16         started        18 ub8ehJSePAfc9FYqZIT6.arm6.elf 10->18         started       

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
ub8ehJSePAfc9FYqZIT6.arm6.elf37%ReversingLabsLinux.Trojan.Mirai
No Antivirus matches
No Antivirus matches
No Antivirus matches
No contacted domains info
NameSourceMaliciousAntivirus DetectionReputation
http://upx.sf.netub8ehJSePAfc9FYqZIT6.arm6.elffalse
    high
    • No. of IPs < 25%
    • 25% < No. of IPs < 50%
    • 50% < No. of IPs < 75%
    • 75% < No. of IPs
    IPDomainCountryFlagASNASN NameMalicious
    92.118.56.167
    unknownGermany
    9009M247GBfalse
    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
    92.118.56.167ub8ehJSePAfc9FYqZIT6.arm7.elfGet hashmaliciousMiraiBrowse
      ub8ehJSePAfc9FYqZIT6.x86_64.elfGet hashmaliciousUnknownBrowse
        ub8ehJSePAfc9FYqZIT6.ppc.elfGet hashmaliciousUnknownBrowse
          ub8ehJSePAfc9FYqZIT6.mips.elfGet hashmaliciousUnknownBrowse
            ub8ehJSePAfc9FYqZIT6.mpsl.elfGet hashmaliciousUnknownBrowse
              ub8ehJSePAfc9FYqZIT6.arm.elfGet hashmaliciousMiraiBrowse
                ub8ehJSePAfc9FYqZIT6.m68k.elfGet hashmaliciousMiraiBrowse
                  ub8ehJSePAfc9FYqZIT6.sh4.elfGet hashmaliciousUnknownBrowse
                    ub8ehJSePAfc9FYqZIT6.i686.elfGet hashmaliciousUnknownBrowse
                      ub8ehJSePAfc9FYqZIT6.x86.elfGet hashmaliciousUnknownBrowse
                        No context
                        MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                        M247GBub8ehJSePAfc9FYqZIT6.arm7.elfGet hashmaliciousMiraiBrowse
                        • 92.118.56.167
                        ub8ehJSePAfc9FYqZIT6.x86_64.elfGet hashmaliciousUnknownBrowse
                        • 92.118.56.167
                        ub8ehJSePAfc9FYqZIT6.ppc.elfGet hashmaliciousUnknownBrowse
                        • 92.118.56.167
                        ub8ehJSePAfc9FYqZIT6.mips.elfGet hashmaliciousUnknownBrowse
                        • 92.118.56.167
                        ub8ehJSePAfc9FYqZIT6.mpsl.elfGet hashmaliciousUnknownBrowse
                        • 92.118.56.167
                        ub8ehJSePAfc9FYqZIT6.arm.elfGet hashmaliciousMiraiBrowse
                        • 92.118.56.167
                        ub8ehJSePAfc9FYqZIT6.m68k.elfGet hashmaliciousMiraiBrowse
                        • 92.118.56.167
                        ub8ehJSePAfc9FYqZIT6.sh4.elfGet hashmaliciousUnknownBrowse
                        • 92.118.56.167
                        ub8ehJSePAfc9FYqZIT6.i686.elfGet hashmaliciousUnknownBrowse
                        • 92.118.56.167
                        ub8ehJSePAfc9FYqZIT6.x86.elfGet hashmaliciousUnknownBrowse
                        • 92.118.56.167
                        No context
                        No context
                        No created / dropped files found
                        File type:ELF 32-bit LSB executable, ARM, EABI4 version 1 (GNU/Linux), statically linked, no section header
                        Entropy (8bit):7.971155039666942
                        TrID:
                        • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                        File name:ub8ehJSePAfc9FYqZIT6.arm6.elf
                        File size:44'600 bytes
                        MD5:e93c4d4afb75bc0b947ad0ecfb31f4cd
                        SHA1:5ce4e75e6e053bd2f754f5d21a40d4ab8d0eebc4
                        SHA256:dbad09080055f65cf654a98bb734c0fc541b8a829be58dee564e681d39b11fec
                        SHA512:b002ff40984a06178a1c1fda0b7d380e81ead35c3681c555bc0f4cba0276f205b79665a46942155b87bbc1a1079b912a5df7cd7dbdf6a196a22c6715fb636ff3
                        SSDEEP:768:orZyKJoofyfTtMLfclRAAO+jVbumZnLM3XgcTaWS5HOFm1fKs9q3UEL+:KbjjOAgfnLGRMOISL+
                        TLSH:0513F1B66E97D82EC4A67F3D9CA58EC70F0B35FDB4E89042A13146691EF104CA7A5483
                        File Content Preview:.ELF..............(.........4...........4. ...(.........................................H...H...H...................Q.td...............................OUPX!...................._..........?.E.h;....#..$.......L..T.|..r.F..ZS..n.8.I+.e......rQN..D....I.:#/.

                        ELF header

                        Class:ELF32
                        Data:2's complement, little endian
                        Version:1 (current)
                        Machine:ARM
                        Version Number:0x1
                        Type:EXEC (Executable file)
                        OS/ABI:UNIX - Linux
                        ABI Version:0
                        Entry Point Address:0x11b00
                        Flags:0x4000002
                        ELF Header Size:52
                        Program Header Offset:52
                        Program Header Size:32
                        Number of Program Headers:3
                        Section Header Offset:0
                        Section Header Size:40
                        Number of Section Headers:0
                        Header String Table Index:0
                        TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                        LOAD0x00x80000x80000xaced0xaced7.97290x5R E0x8000
                        LOAD0xb480x20b480x20b480x00x00.00000x6RW 0x8000
                        GNU_STACK0x00x00x00x00x00.00000x7RWE0x4
                        TimestampSource PortDest PortSource IPDest IP
                        Dec 26, 2024 22:15:37.919003963 CET558023778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:15:38.038602114 CET37785580292.118.56.167192.168.2.14
                        Dec 26, 2024 22:15:38.038815022 CET558023778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:15:38.045378923 CET558023778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:15:38.165395975 CET37785580292.118.56.167192.168.2.14
                        Dec 26, 2024 22:15:38.165463924 CET558023778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:15:38.285197973 CET37785580292.118.56.167192.168.2.14
                        Dec 26, 2024 22:15:39.291034937 CET37785580292.118.56.167192.168.2.14
                        Dec 26, 2024 22:15:39.291481972 CET558023778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:15:39.291481972 CET558023778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:15:39.292165041 CET558043778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:15:39.411719084 CET37785580492.118.56.167192.168.2.14
                        Dec 26, 2024 22:15:39.411837101 CET558043778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:15:39.412981033 CET558043778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:15:39.532608986 CET37785580492.118.56.167192.168.2.14
                        Dec 26, 2024 22:15:39.532808065 CET558043778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:15:39.652599096 CET37785580492.118.56.167192.168.2.14
                        Dec 26, 2024 22:15:40.666671991 CET37785580492.118.56.167192.168.2.14
                        Dec 26, 2024 22:15:40.666832924 CET558043778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:15:40.666902065 CET558043778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:15:40.667537928 CET558063778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:15:40.787030935 CET37785580692.118.56.167192.168.2.14
                        Dec 26, 2024 22:15:40.787267923 CET558063778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:15:40.788218975 CET558063778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:15:40.907933950 CET37785580692.118.56.167192.168.2.14
                        Dec 26, 2024 22:15:40.908118010 CET558063778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:15:41.027811050 CET37785580692.118.56.167192.168.2.14
                        Dec 26, 2024 22:15:42.022392988 CET37785580692.118.56.167192.168.2.14
                        Dec 26, 2024 22:15:42.022521019 CET558063778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:15:42.022582054 CET558063778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:15:42.023153067 CET558083778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:15:42.144212008 CET37785580892.118.56.167192.168.2.14
                        Dec 26, 2024 22:15:42.144309044 CET558083778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:15:42.145179987 CET558083778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:15:42.264636993 CET37785580892.118.56.167192.168.2.14
                        Dec 26, 2024 22:15:42.264727116 CET558083778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:15:42.384249926 CET37785580892.118.56.167192.168.2.14
                        Dec 26, 2024 22:15:43.374440908 CET37785580892.118.56.167192.168.2.14
                        Dec 26, 2024 22:15:43.374588013 CET558083778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:15:43.374680996 CET558083778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:15:43.375443935 CET558103778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:15:43.495332956 CET37785581092.118.56.167192.168.2.14
                        Dec 26, 2024 22:15:43.495471954 CET558103778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:15:43.496645927 CET558103778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:15:43.616198063 CET37785581092.118.56.167192.168.2.14
                        Dec 26, 2024 22:15:43.616261959 CET558103778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:15:43.735754967 CET37785581092.118.56.167192.168.2.14
                        Dec 26, 2024 22:15:43.862550974 CET558123778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:15:43.982064009 CET37785581292.118.56.167192.168.2.14
                        Dec 26, 2024 22:15:43.982121944 CET558123778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:15:43.998755932 CET558123778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:15:44.118630886 CET37785581292.118.56.167192.168.2.14
                        Dec 26, 2024 22:15:44.118681908 CET558123778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:15:44.238276005 CET37785581292.118.56.167192.168.2.14
                        Dec 26, 2024 22:15:44.733781099 CET37785581092.118.56.167192.168.2.14
                        Dec 26, 2024 22:15:44.734083891 CET558103778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:15:44.734211922 CET558103778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:15:44.734930038 CET558143778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:15:45.091950893 CET37785581092.118.56.167192.168.2.14
                        Dec 26, 2024 22:15:45.091976881 CET37785581492.118.56.167192.168.2.14
                        Dec 26, 2024 22:15:45.092335939 CET558143778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:15:45.092345953 CET558103778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:15:45.093864918 CET558143778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:15:45.212007999 CET37785581292.118.56.167192.168.2.14
                        Dec 26, 2024 22:15:45.212086916 CET558123778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:15:45.212791920 CET558123778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:15:45.213454962 CET37785581492.118.56.167192.168.2.14
                        Dec 26, 2024 22:15:45.213485003 CET558163778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:15:45.213535070 CET558143778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:15:45.333162069 CET37785581692.118.56.167192.168.2.14
                        Dec 26, 2024 22:15:45.333177090 CET37785581492.118.56.167192.168.2.14
                        Dec 26, 2024 22:15:45.333247900 CET558163778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:15:45.334635973 CET558163778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:15:45.454186916 CET37785581692.118.56.167192.168.2.14
                        Dec 26, 2024 22:15:45.454410076 CET558163778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:15:45.573967934 CET37785581692.118.56.167192.168.2.14
                        Dec 26, 2024 22:15:46.321325064 CET37785581492.118.56.167192.168.2.14
                        Dec 26, 2024 22:15:46.321430922 CET558143778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:15:46.321465969 CET558143778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:15:46.322035074 CET558183778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:15:46.445375919 CET37785581892.118.56.167192.168.2.14
                        Dec 26, 2024 22:15:46.445477009 CET558183778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:15:46.446984053 CET558183778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:15:46.563569069 CET37785581692.118.56.167192.168.2.14
                        Dec 26, 2024 22:15:46.563685894 CET558163778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:15:46.563740969 CET558163778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:15:46.564331055 CET558203778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:15:46.566493034 CET37785581892.118.56.167192.168.2.14
                        Dec 26, 2024 22:15:46.566559076 CET558183778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:15:46.683846951 CET37785582092.118.56.167192.168.2.14
                        Dec 26, 2024 22:15:46.683943033 CET558203778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:15:46.684959888 CET558203778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:15:46.686151028 CET37785581892.118.56.167192.168.2.14
                        Dec 26, 2024 22:15:46.804790020 CET37785582092.118.56.167192.168.2.14
                        Dec 26, 2024 22:15:46.804903984 CET558203778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:15:46.931389093 CET37785582092.118.56.167192.168.2.14
                        Dec 26, 2024 22:15:47.687479019 CET37785581892.118.56.167192.168.2.14
                        Dec 26, 2024 22:15:47.687582970 CET558183778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:15:47.687673092 CET558183778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:15:47.688057899 CET558223778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:15:47.815602064 CET37785582292.118.56.167192.168.2.14
                        Dec 26, 2024 22:15:47.815676928 CET558223778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:15:47.816498041 CET558223778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:15:47.936016083 CET37785582292.118.56.167192.168.2.14
                        Dec 26, 2024 22:15:47.936202049 CET558223778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:15:48.055798054 CET37785582292.118.56.167192.168.2.14
                        Dec 26, 2024 22:15:49.049190044 CET37785582292.118.56.167192.168.2.14
                        Dec 26, 2024 22:15:49.049401045 CET558223778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:15:49.049530983 CET558223778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:15:49.050295115 CET558243778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:15:49.169807911 CET37785582492.118.56.167192.168.2.14
                        Dec 26, 2024 22:15:49.169928074 CET558243778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:15:49.171195984 CET558243778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:15:49.290951967 CET37785582492.118.56.167192.168.2.14
                        Dec 26, 2024 22:15:49.291157961 CET558243778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:15:49.410803080 CET37785582492.118.56.167192.168.2.14
                        Dec 26, 2024 22:15:50.636135101 CET37785582492.118.56.167192.168.2.14
                        Dec 26, 2024 22:15:50.636301994 CET558243778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:15:50.636488914 CET558243778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:15:50.637042046 CET558263778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:15:50.658488989 CET37785582492.118.56.167192.168.2.14
                        Dec 26, 2024 22:15:50.658554077 CET558243778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:15:50.756598949 CET37785582692.118.56.167192.168.2.14
                        Dec 26, 2024 22:15:50.756719112 CET558263778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:15:50.757843971 CET558263778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:15:50.877392054 CET37785582692.118.56.167192.168.2.14
                        Dec 26, 2024 22:15:50.877501011 CET558263778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:15:50.997044086 CET37785582692.118.56.167192.168.2.14
                        Dec 26, 2024 22:15:51.996037006 CET37785582692.118.56.167192.168.2.14
                        Dec 26, 2024 22:15:51.996309042 CET558263778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:15:51.996309996 CET558263778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:15:51.997021914 CET558283778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:15:52.116580009 CET37785582892.118.56.167192.168.2.14
                        Dec 26, 2024 22:15:52.116859913 CET558283778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:15:52.118185997 CET558283778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:15:52.238341093 CET37785582892.118.56.167192.168.2.14
                        Dec 26, 2024 22:15:52.238535881 CET558283778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:15:52.358989000 CET37785582892.118.56.167192.168.2.14
                        Dec 26, 2024 22:15:53.347933054 CET37785582892.118.56.167192.168.2.14
                        Dec 26, 2024 22:15:53.348200083 CET558283778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:15:53.348200083 CET558283778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:15:53.348814011 CET558303778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:15:53.468398094 CET37785583092.118.56.167192.168.2.14
                        Dec 26, 2024 22:15:53.468605995 CET558303778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:15:53.469686031 CET558303778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:15:53.589299917 CET37785583092.118.56.167192.168.2.14
                        Dec 26, 2024 22:15:53.589436054 CET558303778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:15:53.870323896 CET37785583092.118.56.167192.168.2.14
                        Dec 26, 2024 22:15:54.782183886 CET37785583092.118.56.167192.168.2.14
                        Dec 26, 2024 22:15:54.782499075 CET558303778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:15:54.782499075 CET558303778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:15:54.783335924 CET558323778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:15:54.902853966 CET37785583292.118.56.167192.168.2.14
                        Dec 26, 2024 22:15:54.903014898 CET558323778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:15:54.904222012 CET558323778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:15:55.023706913 CET37785583292.118.56.167192.168.2.14
                        Dec 26, 2024 22:15:55.023812056 CET558323778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:15:55.143635988 CET37785583292.118.56.167192.168.2.14
                        Dec 26, 2024 22:15:56.177423954 CET37785583292.118.56.167192.168.2.14
                        Dec 26, 2024 22:15:56.177675962 CET558323778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:15:56.177675962 CET558323778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:15:56.178523064 CET558343778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:15:56.297976971 CET37785583492.118.56.167192.168.2.14
                        Dec 26, 2024 22:15:56.298347950 CET558343778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:15:56.299678087 CET558343778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:15:56.419353008 CET37785583492.118.56.167192.168.2.14
                        Dec 26, 2024 22:15:56.419595957 CET558343778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:15:56.539226055 CET37785583492.118.56.167192.168.2.14
                        Dec 26, 2024 22:15:56.694799900 CET558203778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:15:56.814481974 CET37785582092.118.56.167192.168.2.14
                        Dec 26, 2024 22:15:57.053169966 CET37785582092.118.56.167192.168.2.14
                        Dec 26, 2024 22:15:57.053308964 CET558203778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:15:57.532111883 CET37785583492.118.56.167192.168.2.14
                        Dec 26, 2024 22:15:57.532351971 CET558343778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:15:57.532351971 CET558343778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:15:57.532880068 CET558363778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:15:57.652379036 CET37785583692.118.56.167192.168.2.14
                        Dec 26, 2024 22:15:57.652494907 CET558363778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:15:57.654017925 CET558363778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:15:57.774019003 CET37785583692.118.56.167192.168.2.14
                        Dec 26, 2024 22:15:57.774194002 CET558363778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:15:57.893786907 CET37785583692.118.56.167192.168.2.14
                        Dec 26, 2024 22:15:59.408308983 CET37785583692.118.56.167192.168.2.14
                        Dec 26, 2024 22:15:59.408339977 CET37785583692.118.56.167192.168.2.14
                        Dec 26, 2024 22:15:59.408505917 CET558363778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:15:59.408507109 CET558363778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:15:59.408585072 CET558363778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:15:59.409387112 CET558383778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:15:59.528930902 CET37785583892.118.56.167192.168.2.14
                        Dec 26, 2024 22:15:59.529213905 CET558383778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:15:59.530706882 CET558383778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:15:59.650361061 CET37785583892.118.56.167192.168.2.14
                        Dec 26, 2024 22:15:59.650541067 CET558383778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:15:59.770198107 CET37785583892.118.56.167192.168.2.14
                        Dec 26, 2024 22:16:00.758903027 CET37785583892.118.56.167192.168.2.14
                        Dec 26, 2024 22:16:00.759221077 CET558383778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:16:00.759263992 CET558383778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:16:00.760179043 CET558403778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:16:00.879833937 CET37785584092.118.56.167192.168.2.14
                        Dec 26, 2024 22:16:00.879949093 CET558403778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:16:00.881539106 CET558403778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:16:01.001065969 CET37785584092.118.56.167192.168.2.14
                        Dec 26, 2024 22:16:01.001348019 CET558403778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:16:01.121196032 CET37785584092.118.56.167192.168.2.14
                        Dec 26, 2024 22:16:02.109122038 CET37785584092.118.56.167192.168.2.14
                        Dec 26, 2024 22:16:02.109376907 CET558403778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:16:02.109410048 CET558403778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:16:02.110178947 CET558423778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:16:02.229836941 CET37785584292.118.56.167192.168.2.14
                        Dec 26, 2024 22:16:02.230015039 CET558423778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:16:02.231256962 CET558423778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:16:02.350714922 CET37785584292.118.56.167192.168.2.14
                        Dec 26, 2024 22:16:02.350821972 CET558423778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:16:02.470300913 CET37785584292.118.56.167192.168.2.14
                        Dec 26, 2024 22:16:03.459743977 CET37785584292.118.56.167192.168.2.14
                        Dec 26, 2024 22:16:03.459908962 CET558423778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:16:03.459999084 CET558423778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:16:03.460704088 CET558443778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:16:04.044878006 CET37785584292.118.56.167192.168.2.14
                        Dec 26, 2024 22:16:04.045062065 CET558423778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:16:04.045098066 CET37785584492.118.56.167192.168.2.14
                        Dec 26, 2024 22:16:04.045196056 CET558443778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:16:04.046386957 CET558443778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:16:04.165829897 CET37785584492.118.56.167192.168.2.14
                        Dec 26, 2024 22:16:04.166126966 CET558443778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:16:04.285614967 CET37785584492.118.56.167192.168.2.14
                        Dec 26, 2024 22:16:05.273042917 CET37785584492.118.56.167192.168.2.14
                        Dec 26, 2024 22:16:05.273340940 CET558443778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:16:05.273341894 CET558443778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:16:05.274158955 CET558463778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:16:05.393950939 CET37785584692.118.56.167192.168.2.14
                        Dec 26, 2024 22:16:05.394270897 CET558463778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:16:05.395735979 CET558463778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:16:05.516830921 CET37785584692.118.56.167192.168.2.14
                        Dec 26, 2024 22:16:05.516984940 CET558463778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:16:05.636514902 CET37785584692.118.56.167192.168.2.14
                        Dec 26, 2024 22:16:06.624248028 CET37785584692.118.56.167192.168.2.14
                        Dec 26, 2024 22:16:06.624387980 CET558463778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:16:06.624454975 CET558463778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:16:06.625260115 CET558483778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:16:06.745510101 CET37785584892.118.56.167192.168.2.14
                        Dec 26, 2024 22:16:06.745793104 CET558483778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:16:06.746990919 CET558483778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:16:06.866911888 CET37785584892.118.56.167192.168.2.14
                        Dec 26, 2024 22:16:06.867012024 CET558483778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:16:06.986747980 CET37785584892.118.56.167192.168.2.14
                        Dec 26, 2024 22:16:08.357156038 CET37785584892.118.56.167192.168.2.14
                        Dec 26, 2024 22:16:08.357533932 CET558483778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:16:08.357533932 CET558483778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:16:08.358242989 CET558503778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:16:08.358267069 CET37785584892.118.56.167192.168.2.14
                        Dec 26, 2024 22:16:08.358345985 CET558483778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:16:08.477859974 CET37785585092.118.56.167192.168.2.14
                        Dec 26, 2024 22:16:08.478025913 CET558503778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:16:08.479129076 CET558503778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:16:08.599037886 CET37785585092.118.56.167192.168.2.14
                        Dec 26, 2024 22:16:08.599334002 CET558503778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:16:08.718841076 CET37785585092.118.56.167192.168.2.14
                        Dec 26, 2024 22:16:09.709589005 CET37785585092.118.56.167192.168.2.14
                        Dec 26, 2024 22:16:09.709929943 CET558503778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:16:09.709929943 CET558503778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:16:09.710803986 CET558523778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:16:09.830745935 CET37785585292.118.56.167192.168.2.14
                        Dec 26, 2024 22:16:09.830967903 CET558523778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:16:09.832685947 CET558523778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:16:09.952147007 CET37785585292.118.56.167192.168.2.14
                        Dec 26, 2024 22:16:09.952374935 CET558523778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:16:10.071810961 CET37785585292.118.56.167192.168.2.14
                        Dec 26, 2024 22:16:11.060136080 CET37785585292.118.56.167192.168.2.14
                        Dec 26, 2024 22:16:11.060281992 CET558523778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:16:11.060375929 CET558523778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:16:11.060899019 CET558543778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:16:11.180442095 CET37785585492.118.56.167192.168.2.14
                        Dec 26, 2024 22:16:11.180587053 CET558543778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:16:11.181718111 CET558543778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:16:11.561933994 CET558543778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:16:11.572798014 CET37785585492.118.56.167192.168.2.14
                        Dec 26, 2024 22:16:11.681658983 CET37785585492.118.56.167192.168.2.14
                        Dec 26, 2024 22:16:21.191745043 CET558543778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:16:21.312273026 CET37785585492.118.56.167192.168.2.14
                        Dec 26, 2024 22:16:21.640553951 CET37785585492.118.56.167192.168.2.14
                        Dec 26, 2024 22:16:21.640815020 CET558543778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:16:57.096892118 CET558203778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:16:57.216636896 CET37785582092.118.56.167192.168.2.14
                        Dec 26, 2024 22:16:57.455379009 CET37785582092.118.56.167192.168.2.14
                        Dec 26, 2024 22:16:57.455691099 CET558203778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:17:21.695739985 CET558543778192.168.2.1492.118.56.167
                        Dec 26, 2024 22:17:21.815285921 CET37785585492.118.56.167192.168.2.14
                        Dec 26, 2024 22:17:22.054208040 CET37785585492.118.56.167192.168.2.14
                        Dec 26, 2024 22:17:22.054400921 CET558543778192.168.2.1492.118.56.167

                        System Behavior

                        Start time (UTC):21:15:36
                        Start date (UTC):26/12/2024
                        Path:/tmp/ub8ehJSePAfc9FYqZIT6.arm6.elf
                        Arguments:/tmp/ub8ehJSePAfc9FYqZIT6.arm6.elf
                        File size:4956856 bytes
                        MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                        Start time (UTC):21:15:36
                        Start date (UTC):26/12/2024
                        Path:/tmp/ub8ehJSePAfc9FYqZIT6.arm6.elf
                        Arguments:-
                        File size:4956856 bytes
                        MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                        Start time (UTC):21:15:36
                        Start date (UTC):26/12/2024
                        Path:/tmp/ub8ehJSePAfc9FYqZIT6.arm6.elf
                        Arguments:-
                        File size:4956856 bytes
                        MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                        Start time (UTC):21:15:36
                        Start date (UTC):26/12/2024
                        Path:/tmp/ub8ehJSePAfc9FYqZIT6.arm6.elf
                        Arguments:-
                        File size:4956856 bytes
                        MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                        Start time (UTC):21:15:42
                        Start date (UTC):26/12/2024
                        Path:/tmp/ub8ehJSePAfc9FYqZIT6.arm6.elf
                        Arguments:-
                        File size:4956856 bytes
                        MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                        Start time (UTC):21:15:42
                        Start date (UTC):26/12/2024
                        Path:/tmp/ub8ehJSePAfc9FYqZIT6.arm6.elf
                        Arguments:-
                        File size:4956856 bytes
                        MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1