Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
x86.elf

Overview

General Information

Sample name:x86.elf
Analysis ID:1582132
MD5:cceafa49d179b6e7b676b2f37b5443fb
SHA1:580646fc0865d98af685e4811420d9178acf047b
SHA256:3ea72cb22a6f75a513d5fdf81bd054ac24639023b37b0229ecbbb6343bfcf366
Tags:elfuser-abuse_ch
Infos:

Detection

Score:68
Range:0 - 100
Whitelisted:false

Signatures

Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Suricata IDS alerts for network traffic
Machine Learning detection for sample
Detected TCP or UDP traffic on non-standard ports
Sample has stripped symbol table
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Yara signature match

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1582132
Start date and time:2024-12-30 02:42:45 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 57s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:x86.elf
Detection:MAL
Classification:mal68.linELF@0/0@2/0
Command:/tmp/x86.elf
PID:5507
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
$UICIDEBOY$
Standard Error:
  • system is lnxubuntu20
  • x86.elf (PID: 5507, Parent: 5428, MD5: cceafa49d179b6e7b676b2f37b5443fb) Arguments: /tmp/x86.elf
    • x86.elf New Fork (PID: 5508, Parent: 5507)
  • cleanup
SourceRuleDescriptionAuthorStrings
x86.elfLinux_Trojan_Gafgyt_e6d75e6funknownunknown
  • 0x3aba:$a: 00 00 00 CD 80 C3 8B 54 24 04 8B 4C 24 08 87 D3 B8 5B 00 00 00
x86.elfLinux_Trojan_Mirai_122ff2e6unknownunknown
  • 0x188b:$a: 24 EB 15 89 F0 83 C8 01 EB 03 8B 5B 08 3B 43 04 72 F8 8B 4B 0C 89
x86.elfLinux_Trojan_Mirai_fa48b592unknownunknown
  • 0x53c1:$a: 31 C0 BA 01 00 00 00 B9 01 00 00 00 03 04 24 89 D7 31 D2 F7 F7 0F
x86.elfLinux_Trojan_Mirai_8aa7b5d3unknownunknown
  • 0xc52:$a: 8B 4C 24 14 8B 74 24 0C 8B 5C 24 10 85 C9 74 0D 31 D2 8A 04 1A 88
SourceRuleDescriptionAuthorStrings
5507.1.0000000008048000.000000000804f000.r-x.sdmpLinux_Trojan_Gafgyt_e6d75e6funknownunknown
  • 0x3aba:$a: 00 00 00 CD 80 C3 8B 54 24 04 8B 4C 24 08 87 D3 B8 5B 00 00 00
5507.1.0000000008048000.000000000804f000.r-x.sdmpLinux_Trojan_Mirai_122ff2e6unknownunknown
  • 0x188b:$a: 24 EB 15 89 F0 83 C8 01 EB 03 8B 5B 08 3B 43 04 72 F8 8B 4B 0C 89
5507.1.0000000008048000.000000000804f000.r-x.sdmpLinux_Trojan_Mirai_fa48b592unknownunknown
  • 0x53c1:$a: 31 C0 BA 01 00 00 00 B9 01 00 00 00 03 04 24 89 D7 31 D2 F7 F7 0F
5507.1.0000000008048000.000000000804f000.r-x.sdmpLinux_Trojan_Mirai_8aa7b5d3unknownunknown
  • 0xc52:$a: 8B 4C 24 14 8B 74 24 0C 8B 5C 24 10 85 C9 74 0D 31 D2 8A 04 1A 88
TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
2024-12-30T02:43:35.694258+010028498161A Network Trojan was detected192.168.2.145076085.239.34.1346666TCP

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: x86.elfVirustotal: Detection: 21%Perma Link
Source: x86.elfReversingLabs: Detection: 26%
Source: x86.elfJoe Sandbox ML: detected

Networking

barindex
Source: Network trafficSuricata IDS: 2849816 - Severity 1 - ETPRO MALWARE ELF/Multiverze CnC Checkin : 192.168.2.14:50760 -> 85.239.34.134:6666
Source: global trafficTCP traffic: 192.168.2.14:50760 -> 85.239.34.134:6666
Source: global trafficTCP traffic: 192.168.2.14:46540 -> 185.125.190.26:443
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 185.125.190.26
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 185.125.190.26
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: global trafficDNS traffic detected: DNS query: daisy.ubuntu.com
Source: unknownNetwork traffic detected: HTTP traffic on port 46540 -> 443

System Summary

barindex
Source: x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_e6d75e6f Author: unknown
Source: x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_122ff2e6 Author: unknown
Source: x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_fa48b592 Author: unknown
Source: x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_8aa7b5d3 Author: unknown
Source: 5507.1.0000000008048000.000000000804f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_e6d75e6f Author: unknown
Source: 5507.1.0000000008048000.000000000804f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_122ff2e6 Author: unknown
Source: 5507.1.0000000008048000.000000000804f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_fa48b592 Author: unknown
Source: 5507.1.0000000008048000.000000000804f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_8aa7b5d3 Author: unknown
Source: ELF static info symbol of initial sample.symtab present: no
Source: x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_e6d75e6f reference_sample = 48b15093f33c18778724c48c34199a420be4beb0d794e36034097806e1521eb8, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = e99805e8917d6526031270b6da5c2f3cc1c8235fed1d47134835a107d0df497c, id = e6d75e6f-aa04-4767-8730-6909958044a7, last_modified = 2021-09-16
Source: x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_122ff2e6 reference_sample = c7dd999a033fa3edc1936785b87cd69ce2f5cac5a084ddfaf527a1094e718bc4, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 3c9ffd7537e30a21eefa6c174f801264b92a85a1bc73e34e6dc9e29f84658348, id = 122ff2e6-56e6-4aa8-a3ec-c19d31eb1f80, last_modified = 2021-09-16
Source: x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_fa48b592 reference_sample = c9e33befeec133720b3ba40bb3cd7f636aad80f72f324c5fe65ac7af271c49ee, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 8838d2752b310dbf7d12f6cf023244aaff4fdf5b55cf1e3b71843210df0fcf88, id = fa48b592-8d80-45af-a3e4-232695b8f5dd, last_modified = 2021-09-16
Source: x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_8aa7b5d3 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 02a2c18c362df4b1fceb33f3b605586514ba9a00c7afedf71c04fa54d8146444, id = 8aa7b5d3-e1eb-4b55-b36a-0d3a242c06e9, last_modified = 2022-01-26
Source: 5507.1.0000000008048000.000000000804f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_e6d75e6f reference_sample = 48b15093f33c18778724c48c34199a420be4beb0d794e36034097806e1521eb8, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = e99805e8917d6526031270b6da5c2f3cc1c8235fed1d47134835a107d0df497c, id = e6d75e6f-aa04-4767-8730-6909958044a7, last_modified = 2021-09-16
Source: 5507.1.0000000008048000.000000000804f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_122ff2e6 reference_sample = c7dd999a033fa3edc1936785b87cd69ce2f5cac5a084ddfaf527a1094e718bc4, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 3c9ffd7537e30a21eefa6c174f801264b92a85a1bc73e34e6dc9e29f84658348, id = 122ff2e6-56e6-4aa8-a3ec-c19d31eb1f80, last_modified = 2021-09-16
Source: 5507.1.0000000008048000.000000000804f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_fa48b592 reference_sample = c9e33befeec133720b3ba40bb3cd7f636aad80f72f324c5fe65ac7af271c49ee, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 8838d2752b310dbf7d12f6cf023244aaff4fdf5b55cf1e3b71843210df0fcf88, id = fa48b592-8d80-45af-a3e4-232695b8f5dd, last_modified = 2021-09-16
Source: 5507.1.0000000008048000.000000000804f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_8aa7b5d3 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 02a2c18c362df4b1fceb33f3b605586514ba9a00c7afedf71c04fa54d8146444, id = 8aa7b5d3-e1eb-4b55-b36a-0d3a242c06e9, last_modified = 2022-01-26
Source: classification engineClassification label: mal68.linELF@0/0@2/0
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath InterceptionDirect Volume AccessOS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Non-Standard Port
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
Non-Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture2
Application Layer Protocol
Traffic DuplicationData Destruction
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
x86.elf22%VirustotalBrowse
x86.elf26%ReversingLabsLinux.Backdoor.Gafgyt
x86.elf100%Joe Sandbox ML
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
daisy.ubuntu.com
162.213.35.24
truefalse
    high
    • No. of IPs < 25%
    • 25% < No. of IPs < 50%
    • 50% < No. of IPs < 75%
    • 75% < No. of IPs
    IPDomainCountryFlagASNASN NameMalicious
    85.239.34.134
    unknownRussian Federation
    134121RAINBOW-HKRainbownetworklimitedHKtrue
    185.125.190.26
    unknownUnited Kingdom
    41231CANONICAL-ASGBfalse
    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
    85.239.34.134spc.elfGet hashmaliciousUnknownBrowse
      212.64.215.71-arm-2024-12-25T12_31_55.elfGet hashmaliciousUnknownBrowse
        ppc.elfGet hashmaliciousMiraiBrowse
          sh4.elfGet hashmaliciousMiraiBrowse
            mips.elfGet hashmaliciousMiraiBrowse
              spc.elfGet hashmaliciousMiraiBrowse
                arm6.elfGet hashmaliciousMiraiBrowse
                  arm.elfGet hashmaliciousMiraiBrowse
                    m68k.elfGet hashmaliciousMiraiBrowse
                      arm7.elfGet hashmaliciousMiraiBrowse
                        185.125.190.26dlr.arm6.elfGet hashmaliciousUnknownBrowse
                          Aqua.arm6.elfGet hashmaliciousUnknownBrowse
                            Aqua.arm4.elfGet hashmaliciousUnknownBrowse
                              Aqua.ppc.elfGet hashmaliciousUnknownBrowse
                                arm5.elfGet hashmaliciousUnknownBrowse
                                  x86_64.elfGet hashmaliciousUnknownBrowse
                                    bot.x86.elfGet hashmaliciousMirai, OkiruBrowse
                                      armv6l.elfGet hashmaliciousMiraiBrowse
                                        x86_64.elfGet hashmaliciousGafgyt, MiraiBrowse
                                          bot.arm.elfGet hashmaliciousMirai, Gafgyt, OkiruBrowse
                                            MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                            daisy.ubuntu.comspc.elfGet hashmaliciousUnknownBrowse
                                            • 162.213.35.24
                                            rebirth.arm4.elfGet hashmaliciousGafgytBrowse
                                            • 162.213.35.24
                                            dlr.arm5.elfGet hashmaliciousUnknownBrowse
                                            • 162.213.35.24
                                            rebirth.arm5.elfGet hashmaliciousGafgytBrowse
                                            • 162.213.35.24
                                            rebirth.i686.elfGet hashmaliciousGafgytBrowse
                                            • 162.213.35.25
                                            loligang.m68k.elfGet hashmaliciousMiraiBrowse
                                            • 162.213.35.24
                                            dlr.arm.elfGet hashmaliciousUnknownBrowse
                                            • 162.213.35.25
                                            loligang.arm5.elfGet hashmaliciousMiraiBrowse
                                            • 162.213.35.24
                                            loligang.arm6.elfGet hashmaliciousMiraiBrowse
                                            • 162.213.35.24
                                            mips.elfGet hashmaliciousMirai, MoobotBrowse
                                            • 162.213.35.25
                                            MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                            RAINBOW-HKRainbownetworklimitedHKspc.elfGet hashmaliciousUnknownBrowse
                                            • 85.239.34.134
                                            1C6ljtnwXP.exeGet hashmaliciousLummaCBrowse
                                            • 85.239.54.77
                                            212.64.215.71-arm-2024-12-25T12_31_55.elfGet hashmaliciousUnknownBrowse
                                            • 85.239.34.134
                                            armv5l.elfGet hashmaliciousUnknownBrowse
                                            • 185.152.92.158
                                            statmentt.exeGet hashmaliciousScreenConnect ToolBrowse
                                            • 85.239.34.190
                                            ppc.elfGet hashmaliciousMiraiBrowse
                                            • 85.239.34.134
                                            sh4.elfGet hashmaliciousMiraiBrowse
                                            • 85.239.34.134
                                            mips.elfGet hashmaliciousMiraiBrowse
                                            • 85.239.34.134
                                            spc.elfGet hashmaliciousMiraiBrowse
                                            • 85.239.34.134
                                            arm6.elfGet hashmaliciousMiraiBrowse
                                            • 85.239.34.134
                                            CANONICAL-ASGBudpmpsl.elfGet hashmaliciousUnknownBrowse
                                            • 91.189.91.42
                                            .Sarm.elfGet hashmaliciousUnknownBrowse
                                            • 91.189.91.42
                                            dc.elfGet hashmaliciousGafgyt, MiraiBrowse
                                            • 91.189.91.42
                                            rebirth.i686.elfGet hashmaliciousGafgytBrowse
                                            • 91.189.91.42
                                            dlr.arm6.elfGet hashmaliciousUnknownBrowse
                                            • 185.125.190.26
                                            .Sx86.elfGet hashmaliciousUnknownBrowse
                                            • 91.189.91.42
                                            bin.sh.elfGet hashmaliciousMiraiBrowse
                                            • 91.189.91.42
                                            dlr.mips.elfGet hashmaliciousMiraiBrowse
                                            • 91.189.91.42
                                            main_arm.elfGet hashmaliciousMiraiBrowse
                                            • 91.189.91.42
                                            DemonGen-linux-amd64.elfGet hashmaliciousUnknownBrowse
                                            • 91.189.91.42
                                            No context
                                            No context
                                            No created / dropped files found
                                            File type:ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, stripped
                                            Entropy (8bit):6.314619132395707
                                            TrID:
                                            • ELF Executable and Linkable format (Linux) (4029/14) 50.16%
                                            • ELF Executable and Linkable format (generic) (4004/1) 49.84%
                                            File name:x86.elf
                                            File size:27'772 bytes
                                            MD5:cceafa49d179b6e7b676b2f37b5443fb
                                            SHA1:580646fc0865d98af685e4811420d9178acf047b
                                            SHA256:3ea72cb22a6f75a513d5fdf81bd054ac24639023b37b0229ecbbb6343bfcf366
                                            SHA512:37d629dae886a148297da6d9f2b042bb8f818e2049793d029a21c99f55a970f2927e937191fc0e7e63df5c620845ace610391ea00c6bba720dc6a899aeb9e8fc
                                            SSDEEP:768:IrGgKUkQ7nrf37LZdGmfuYx96p0V8J2lMAg/Jw:IrHKUkQ7nzrLZdzhM0VMf/
                                            TLSH:50C23B05F5C2E7BBEC5610FDA3A1ABB97731D11721C89A03D3A76525AC4212C898FF6C
                                            File Content Preview:.ELF........................4...Lj......4. ...(......................a...a...............a...............7...............g..........................Q.td............................U..S......./w...h.....W..[]...$.............U......=.....t..5..............

                                            ELF header

                                            Class:ELF32
                                            Data:2's complement, little endian
                                            Version:1 (current)
                                            Machine:Intel 80386
                                            Version Number:0x1
                                            Type:EXEC (Executable file)
                                            OS/ABI:UNIX - System V
                                            ABI Version:0
                                            Entry Point Address:0x8048184
                                            Flags:0x0
                                            ELF Header Size:52
                                            Program Header Offset:52
                                            Program Header Size:32
                                            Number of Program Headers:4
                                            Section Header Offset:27212
                                            Section Header Size:40
                                            Number of Section Headers:14
                                            Header String Table Index:13
                                            NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                            NULL0x00x00x00x00x0000
                                            .initPROGBITS0x80480b40xb40x1c0x00x6AX001
                                            .textPROGBITS0x80480d00xd00x58170x00x6AX0016
                                            .finiPROGBITS0x804d8e70x58e70x170x00x6AX001
                                            .rodataPROGBITS0x804d9000x59000x80c0x00x2A0032
                                            .eh_framePROGBITS0x804f10c0x610c0x6cc0x00x3WA004
                                            .tbssNOBITS0x804f7d80x67d80x80x00x403WAT004
                                            .ctorsPROGBITS0x804f7d80x67d80x80x00x3WA004
                                            .dtorsPROGBITS0x804f7e00x67e00x80x00x3WA004
                                            .jcrPROGBITS0x804f7e80x67e80x40x00x3WA004
                                            .got.pltPROGBITS0x804f7ec0x67ec0xc0x40x3WA004
                                            .dataPROGBITS0x804f7f80x67f80x1f80x00x3WA004
                                            .bssNOBITS0x804f9f00x69f00x2ec00x00x3WA004
                                            .shstrtabSTRTAB0x00x69f00x5c0x00x0001
                                            TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                            LOAD0x00x80480000x80480000x610c0x610c6.40050x5R E0x1000.init .text .fini .rodata
                                            LOAD0x610c0x804f10c0x804f10c0x8e40x37a44.69810x6RW 0x1000.eh_frame .tbss .ctors .dtors .jcr .got.plt .data .bss
                                            TLS0x67d80x804f7d80x804f7d80x00x80.00000x4R 0x4.tbss
                                            GNU_STACK0x00x00x00x00x00.00000x6RW 0x4
                                            TimestampSIDSignatureSeveritySource IPSource PortDest IPDest PortProtocol
                                            2024-12-30T02:43:35.694258+01002849816ETPRO MALWARE ELF/Multiverze CnC Checkin1192.168.2.145076085.239.34.1346666TCP
                                            TimestampSource PortDest PortSource IPDest IP
                                            Dec 30, 2024 02:43:35.689259052 CET507606666192.168.2.1485.239.34.134
                                            Dec 30, 2024 02:43:35.694190979 CET66665076085.239.34.134192.168.2.14
                                            Dec 30, 2024 02:43:35.694247007 CET507606666192.168.2.1485.239.34.134
                                            Dec 30, 2024 02:43:35.694257975 CET507606666192.168.2.1485.239.34.134
                                            Dec 30, 2024 02:43:35.699074030 CET66665076085.239.34.134192.168.2.14
                                            Dec 30, 2024 02:43:41.163837910 CET66665076085.239.34.134192.168.2.14
                                            Dec 30, 2024 02:43:41.164192915 CET507606666192.168.2.1485.239.34.134
                                            Dec 30, 2024 02:43:42.849889994 CET66665076085.239.34.134192.168.2.14
                                            Dec 30, 2024 02:43:42.850188971 CET507606666192.168.2.1485.239.34.134
                                            Dec 30, 2024 02:43:42.850344896 CET507606666192.168.2.1485.239.34.134
                                            Dec 30, 2024 02:43:42.855106115 CET66665076085.239.34.134192.168.2.14
                                            Dec 30, 2024 02:43:46.177987099 CET66665076085.239.34.134192.168.2.14
                                            Dec 30, 2024 02:43:46.178137064 CET507606666192.168.2.1485.239.34.134
                                            Dec 30, 2024 02:43:46.178303957 CET507606666192.168.2.1485.239.34.134
                                            Dec 30, 2024 02:43:46.183120012 CET66665076085.239.34.134192.168.2.14
                                            Dec 30, 2024 02:43:46.411967993 CET46540443192.168.2.14185.125.190.26
                                            Dec 30, 2024 02:43:51.262515068 CET66665076085.239.34.134192.168.2.14
                                            Dec 30, 2024 02:43:51.262720108 CET507606666192.168.2.1485.239.34.134
                                            Dec 30, 2024 02:43:51.262757063 CET507606666192.168.2.1485.239.34.134
                                            Dec 30, 2024 02:43:51.267648935 CET66665076085.239.34.134192.168.2.14
                                            Dec 30, 2024 02:43:56.268301010 CET66665076085.239.34.134192.168.2.14
                                            Dec 30, 2024 02:43:56.268739939 CET507606666192.168.2.1485.239.34.134
                                            Dec 30, 2024 02:43:56.273613930 CET66665076085.239.34.134192.168.2.14
                                            Dec 30, 2024 02:43:57.861267090 CET66665076085.239.34.134192.168.2.14
                                            Dec 30, 2024 02:43:57.861690044 CET507606666192.168.2.1485.239.34.134
                                            Dec 30, 2024 02:43:57.866565943 CET66665076085.239.34.134192.168.2.14
                                            Dec 30, 2024 02:44:01.281816959 CET66665076085.239.34.134192.168.2.14
                                            Dec 30, 2024 02:44:01.282200098 CET507606666192.168.2.1485.239.34.134
                                            Dec 30, 2024 02:44:01.287060976 CET66665076085.239.34.134192.168.2.14
                                            Dec 30, 2024 02:44:06.358697891 CET66665076085.239.34.134192.168.2.14
                                            Dec 30, 2024 02:44:06.359266996 CET507606666192.168.2.1485.239.34.134
                                            Dec 30, 2024 02:44:06.364150047 CET66665076085.239.34.134192.168.2.14
                                            Dec 30, 2024 02:44:11.364696026 CET66665076085.239.34.134192.168.2.14
                                            Dec 30, 2024 02:44:11.364988089 CET507606666192.168.2.1485.239.34.134
                                            Dec 30, 2024 02:44:11.369810104 CET66665076085.239.34.134192.168.2.14
                                            Dec 30, 2024 02:44:12.876176119 CET66665076085.239.34.134192.168.2.14
                                            Dec 30, 2024 02:44:12.876460075 CET507606666192.168.2.1485.239.34.134
                                            Dec 30, 2024 02:44:12.881341934 CET66665076085.239.34.134192.168.2.14
                                            Dec 30, 2024 02:44:16.371911049 CET66665076085.239.34.134192.168.2.14
                                            Dec 30, 2024 02:44:16.372155905 CET507606666192.168.2.1485.239.34.134
                                            Dec 30, 2024 02:44:16.376976013 CET66665076085.239.34.134192.168.2.14
                                            Dec 30, 2024 02:44:17.386782885 CET46540443192.168.2.14185.125.190.26
                                            Dec 30, 2024 02:44:21.377587080 CET66665076085.239.34.134192.168.2.14
                                            Dec 30, 2024 02:44:21.377886057 CET507606666192.168.2.1485.239.34.134
                                            Dec 30, 2024 02:44:21.382746935 CET66665076085.239.34.134192.168.2.14
                                            Dec 30, 2024 02:44:26.389306068 CET66665076085.239.34.134192.168.2.14
                                            Dec 30, 2024 02:44:26.389616013 CET507606666192.168.2.1485.239.34.134
                                            Dec 30, 2024 02:44:26.395867109 CET66665076085.239.34.134192.168.2.14
                                            Dec 30, 2024 02:44:27.885617971 CET66665076085.239.34.134192.168.2.14
                                            Dec 30, 2024 02:44:27.886111975 CET507606666192.168.2.1485.239.34.134
                                            Dec 30, 2024 02:44:27.891001940 CET66665076085.239.34.134192.168.2.14
                                            Dec 30, 2024 02:44:31.433027983 CET66665076085.239.34.134192.168.2.14
                                            Dec 30, 2024 02:44:31.433233023 CET507606666192.168.2.1485.239.34.134
                                            Dec 30, 2024 02:44:31.438069105 CET66665076085.239.34.134192.168.2.14
                                            Dec 30, 2024 02:44:36.443527937 CET66665076085.239.34.134192.168.2.14
                                            Dec 30, 2024 02:44:36.443732977 CET507606666192.168.2.1485.239.34.134
                                            Dec 30, 2024 02:44:36.448559999 CET66665076085.239.34.134192.168.2.14
                                            Dec 30, 2024 02:44:41.458755016 CET66665076085.239.34.134192.168.2.14
                                            Dec 30, 2024 02:44:41.459059000 CET507606666192.168.2.1485.239.34.134
                                            Dec 30, 2024 02:44:41.463849068 CET66665076085.239.34.134192.168.2.14
                                            Dec 30, 2024 02:44:42.923707008 CET66665076085.239.34.134192.168.2.14
                                            Dec 30, 2024 02:44:42.924032927 CET507606666192.168.2.1485.239.34.134
                                            Dec 30, 2024 02:44:42.928874969 CET66665076085.239.34.134192.168.2.14
                                            Dec 30, 2024 02:44:46.474900007 CET66665076085.239.34.134192.168.2.14
                                            Dec 30, 2024 02:44:46.475064993 CET507606666192.168.2.1485.239.34.134
                                            Dec 30, 2024 02:44:46.479932070 CET66665076085.239.34.134192.168.2.14
                                            Dec 30, 2024 02:44:51.488744020 CET66665076085.239.34.134192.168.2.14
                                            Dec 30, 2024 02:44:51.489059925 CET507606666192.168.2.1485.239.34.134
                                            Dec 30, 2024 02:44:51.493961096 CET66665076085.239.34.134192.168.2.14
                                            Dec 30, 2024 02:44:56.528156996 CET66665076085.239.34.134192.168.2.14
                                            Dec 30, 2024 02:44:56.528388023 CET507606666192.168.2.1485.239.34.134
                                            Dec 30, 2024 02:44:56.533201933 CET66665076085.239.34.134192.168.2.14
                                            Dec 30, 2024 02:45:01.545874119 CET66665076085.239.34.134192.168.2.14
                                            Dec 30, 2024 02:45:01.546088934 CET507606666192.168.2.1485.239.34.134
                                            Dec 30, 2024 02:45:01.550854921 CET66665076085.239.34.134192.168.2.14
                                            Dec 30, 2024 02:45:06.563252926 CET66665076085.239.34.134192.168.2.14
                                            Dec 30, 2024 02:45:06.563438892 CET507606666192.168.2.1485.239.34.134
                                            Dec 30, 2024 02:45:06.568299055 CET66665076085.239.34.134192.168.2.14
                                            Dec 30, 2024 02:45:11.575915098 CET66665076085.239.34.134192.168.2.14
                                            Dec 30, 2024 02:45:11.576127052 CET507606666192.168.2.1485.239.34.134
                                            Dec 30, 2024 02:45:11.580934048 CET66665076085.239.34.134192.168.2.14
                                            Dec 30, 2024 02:45:12.978571892 CET66665076085.239.34.134192.168.2.14
                                            Dec 30, 2024 02:45:12.979036093 CET507606666192.168.2.1485.239.34.134
                                            Dec 30, 2024 02:45:12.983881950 CET66665076085.239.34.134192.168.2.14
                                            Dec 30, 2024 02:45:16.587294102 CET66665076085.239.34.134192.168.2.14
                                            Dec 30, 2024 02:45:16.587790012 CET507606666192.168.2.1485.239.34.134
                                            Dec 30, 2024 02:45:16.592711926 CET66665076085.239.34.134192.168.2.14
                                            Dec 30, 2024 02:45:21.629476070 CET66665076085.239.34.134192.168.2.14
                                            Dec 30, 2024 02:45:21.629688025 CET507606666192.168.2.1485.239.34.134
                                            Dec 30, 2024 02:45:21.634535074 CET66665076085.239.34.134192.168.2.14
                                            Dec 30, 2024 02:45:26.640686989 CET66665076085.239.34.134192.168.2.14
                                            Dec 30, 2024 02:45:26.640784025 CET507606666192.168.2.1485.239.34.134
                                            Dec 30, 2024 02:45:26.645648956 CET66665076085.239.34.134192.168.2.14
                                            Dec 30, 2024 02:45:27.988001108 CET66665076085.239.34.134192.168.2.14
                                            Dec 30, 2024 02:45:27.988159895 CET507606666192.168.2.1485.239.34.134
                                            Dec 30, 2024 02:45:27.993010044 CET66665076085.239.34.134192.168.2.14
                                            Dec 30, 2024 02:45:31.648138046 CET66665076085.239.34.134192.168.2.14
                                            Dec 30, 2024 02:45:31.648494959 CET507606666192.168.2.1485.239.34.134
                                            Dec 30, 2024 02:45:31.653371096 CET66665076085.239.34.134192.168.2.14
                                            Dec 30, 2024 02:45:36.656138897 CET66665076085.239.34.134192.168.2.14
                                            Dec 30, 2024 02:45:36.656301022 CET507606666192.168.2.1485.239.34.134
                                            Dec 30, 2024 02:45:36.661194086 CET66665076085.239.34.134192.168.2.14
                                            Dec 30, 2024 02:45:41.662975073 CET66665076085.239.34.134192.168.2.14
                                            Dec 30, 2024 02:45:41.663152933 CET507606666192.168.2.1485.239.34.134
                                            Dec 30, 2024 02:45:41.668138027 CET66665076085.239.34.134192.168.2.14
                                            Dec 30, 2024 02:45:43.058500051 CET66665076085.239.34.134192.168.2.14
                                            Dec 30, 2024 02:45:43.058759928 CET507606666192.168.2.1485.239.34.134
                                            Dec 30, 2024 02:45:43.063673973 CET66665076085.239.34.134192.168.2.14
                                            Dec 30, 2024 02:45:46.673209906 CET66665076085.239.34.134192.168.2.14
                                            Dec 30, 2024 02:45:46.673454046 CET507606666192.168.2.1485.239.34.134
                                            Dec 30, 2024 02:45:46.678306103 CET66665076085.239.34.134192.168.2.14
                                            Dec 30, 2024 02:45:51.684350967 CET66665076085.239.34.134192.168.2.14
                                            Dec 30, 2024 02:45:51.684618950 CET507606666192.168.2.1485.239.34.134
                                            Dec 30, 2024 02:45:51.689471960 CET66665076085.239.34.134192.168.2.14
                                            Dec 30, 2024 02:45:56.729758024 CET66665076085.239.34.134192.168.2.14
                                            Dec 30, 2024 02:45:56.729922056 CET507606666192.168.2.1485.239.34.134
                                            Dec 30, 2024 02:45:56.734733105 CET66665076085.239.34.134192.168.2.14
                                            Dec 30, 2024 02:45:58.065973043 CET66665076085.239.34.134192.168.2.14
                                            Dec 30, 2024 02:45:58.066194057 CET507606666192.168.2.1485.239.34.134
                                            Dec 30, 2024 02:45:58.071043968 CET66665076085.239.34.134192.168.2.14
                                            Dec 30, 2024 02:46:01.736485004 CET66665076085.239.34.134192.168.2.14
                                            Dec 30, 2024 02:46:01.736726046 CET507606666192.168.2.1485.239.34.134
                                            Dec 30, 2024 02:46:01.741615057 CET66665076085.239.34.134192.168.2.14
                                            Dec 30, 2024 02:46:06.743066072 CET66665076085.239.34.134192.168.2.14
                                            Dec 30, 2024 02:46:06.743232012 CET507606666192.168.2.1485.239.34.134
                                            Dec 30, 2024 02:46:06.748130083 CET66665076085.239.34.134192.168.2.14
                                            Dec 30, 2024 02:46:11.759037971 CET66665076085.239.34.134192.168.2.14
                                            Dec 30, 2024 02:46:11.759388924 CET507606666192.168.2.1485.239.34.134
                                            Dec 30, 2024 02:46:11.764219046 CET66665076085.239.34.134192.168.2.14
                                            Dec 30, 2024 02:46:13.086365938 CET66665076085.239.34.134192.168.2.14
                                            Dec 30, 2024 02:46:13.086600065 CET507606666192.168.2.1485.239.34.134
                                            Dec 30, 2024 02:46:13.091471910 CET66665076085.239.34.134192.168.2.14
                                            Dec 30, 2024 02:46:16.767848969 CET66665076085.239.34.134192.168.2.14
                                            Dec 30, 2024 02:46:16.768224001 CET507606666192.168.2.1485.239.34.134
                                            Dec 30, 2024 02:46:16.773052931 CET66665076085.239.34.134192.168.2.14
                                            Dec 30, 2024 02:46:21.778309107 CET66665076085.239.34.134192.168.2.14
                                            Dec 30, 2024 02:46:21.779457092 CET507606666192.168.2.1485.239.34.134
                                            Dec 30, 2024 02:46:21.784316063 CET66665076085.239.34.134192.168.2.14
                                            Dec 30, 2024 02:46:26.783926964 CET66665076085.239.34.134192.168.2.14
                                            Dec 30, 2024 02:46:26.784168959 CET507606666192.168.2.1485.239.34.134
                                            Dec 30, 2024 02:46:26.790177107 CET66665076085.239.34.134192.168.2.14
                                            Dec 30, 2024 02:46:28.161767006 CET66665076085.239.34.134192.168.2.14
                                            Dec 30, 2024 02:46:28.162034988 CET507606666192.168.2.1485.239.34.134
                                            Dec 30, 2024 02:46:28.166915894 CET66665076085.239.34.134192.168.2.14
                                            Dec 30, 2024 02:46:31.789566994 CET66665076085.239.34.134192.168.2.14
                                            Dec 30, 2024 02:46:31.789777040 CET507606666192.168.2.1485.239.34.134
                                            Dec 30, 2024 02:46:31.794564009 CET66665076085.239.34.134192.168.2.14
                                            Dec 30, 2024 02:46:36.857460022 CET66665076085.239.34.134192.168.2.14
                                            Dec 30, 2024 02:46:36.857749939 CET507606666192.168.2.1485.239.34.134
                                            Dec 30, 2024 02:46:36.862555981 CET66665076085.239.34.134192.168.2.14
                                            Dec 30, 2024 02:46:41.877542019 CET66665076085.239.34.134192.168.2.14
                                            Dec 30, 2024 02:46:41.877831936 CET507606666192.168.2.1485.239.34.134
                                            Dec 30, 2024 02:46:41.882635117 CET66665076085.239.34.134192.168.2.14
                                            Dec 30, 2024 02:46:46.891761065 CET66665076085.239.34.134192.168.2.14
                                            Dec 30, 2024 02:46:46.892091990 CET507606666192.168.2.1485.239.34.134
                                            Dec 30, 2024 02:46:46.896955013 CET66665076085.239.34.134192.168.2.14
                                            Dec 30, 2024 02:46:51.950526953 CET66665076085.239.34.134192.168.2.14
                                            Dec 30, 2024 02:46:51.950882912 CET507606666192.168.2.1485.239.34.134
                                            Dec 30, 2024 02:46:51.955734015 CET66665076085.239.34.134192.168.2.14
                                            Dec 30, 2024 02:46:56.963975906 CET66665076085.239.34.134192.168.2.14
                                            Dec 30, 2024 02:46:56.964284897 CET507606666192.168.2.1485.239.34.134
                                            Dec 30, 2024 02:46:56.969096899 CET66665076085.239.34.134192.168.2.14
                                            Dec 30, 2024 02:46:58.189188957 CET66665076085.239.34.134192.168.2.14
                                            Dec 30, 2024 02:46:58.189389944 CET507606666192.168.2.1485.239.34.134
                                            Dec 30, 2024 02:46:58.194163084 CET66665076085.239.34.134192.168.2.14
                                            Dec 30, 2024 02:47:01.976002932 CET66665076085.239.34.134192.168.2.14
                                            Dec 30, 2024 02:47:01.976183891 CET507606666192.168.2.1485.239.34.134
                                            Dec 30, 2024 02:47:01.981023073 CET66665076085.239.34.134192.168.2.14
                                            Dec 30, 2024 02:47:06.982867956 CET66665076085.239.34.134192.168.2.14
                                            Dec 30, 2024 02:47:06.983118057 CET507606666192.168.2.1485.239.34.134
                                            Dec 30, 2024 02:47:06.987927914 CET66665076085.239.34.134192.168.2.14
                                            TimestampSource PortDest PortSource IPDest IP
                                            Dec 30, 2024 02:46:21.441056013 CET4525953192.168.2.148.8.8.8
                                            Dec 30, 2024 02:46:21.441121101 CET3398253192.168.2.148.8.8.8
                                            Dec 30, 2024 02:46:21.447293043 CET53452598.8.8.8192.168.2.14
                                            Dec 30, 2024 02:46:21.447371960 CET53339828.8.8.8192.168.2.14
                                            TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                            Dec 30, 2024 02:46:21.441056013 CET192.168.2.148.8.8.80xae86Standard query (0)daisy.ubuntu.comA (IP address)IN (0x0001)false
                                            Dec 30, 2024 02:46:21.441121101 CET192.168.2.148.8.8.80x608Standard query (0)daisy.ubuntu.com28IN (0x0001)false
                                            TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                            Dec 30, 2024 02:46:21.447293043 CET8.8.8.8192.168.2.140xae86No error (0)daisy.ubuntu.com162.213.35.24A (IP address)IN (0x0001)false
                                            Dec 30, 2024 02:46:21.447293043 CET8.8.8.8192.168.2.140xae86No error (0)daisy.ubuntu.com162.213.35.25A (IP address)IN (0x0001)false

                                            System Behavior

                                            Start time (UTC):01:43:35
                                            Start date (UTC):30/12/2024
                                            Path:/tmp/x86.elf
                                            Arguments:/tmp/x86.elf
                                            File size:27772 bytes
                                            MD5 hash:cceafa49d179b6e7b676b2f37b5443fb

                                            Start time (UTC):01:43:35
                                            Start date (UTC):30/12/2024
                                            Path:/tmp/x86.elf
                                            Arguments:-
                                            File size:27772 bytes
                                            MD5 hash:cceafa49d179b6e7b676b2f37b5443fb