Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
x86.elf

Overview

General Information

Sample name:x86.elf
Analysis ID:1582170
MD5:e373f7402c38d2e01995322180c75630
SHA1:58e5923cc56fc7d7dd296e69a1f4e6ec027c0dab
SHA256:04c91b0036335d3a4b6c7a91f26bfbe306e50381e689c4ceff99d0d27f373f4a
Tags:elfMiraiuser-abuse_ch
Infos:

Detection

Mirai, Moobot
Score:88
Range:0 - 100
Whitelisted:false

Signatures

Antivirus / Scanner detection for submitted sample
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Yara detected Mirai
Yara detected Moobot
Machine Learning detection for sample
Sample deletes itself
Enumerates processes within the "proc" file system
Sample has stripped symbol table
Yara signature match

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1582170
Start date and time:2024-12-30 03:22:19 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 28s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:x86.elf
Detection:MAL
Classification:mal88.troj.evad.linELF@0/0@20/0
Command:/tmp/x86.elf
PID:5468
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
done.
Standard Error:
  • system is lnxubuntu20
  • x86.elf (PID: 5468, Parent: 5388, MD5: e373f7402c38d2e01995322180c75630) Arguments: /tmp/x86.elf
    • x86.elf New Fork (PID: 5470, Parent: 5468)
      • x86.elf New Fork (PID: 5471, Parent: 5470)
      • x86.elf New Fork (PID: 5472, Parent: 5470)
        • x86.elf New Fork (PID: 5473, Parent: 5472)
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
MiraiMirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese. Nowadays it targets a wide range of networked embedded devices such as IP cameras, home routers (many vendors involved), and other IoT devices. Since the source code was published on "Hack Forums" many variants of the Mirai family appeared, infecting mostly home networks all around the world.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/elf.mirai
NameDescriptionAttributionBlogpost URLsLink
MooBotNo Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/elf.moobot
SourceRuleDescriptionAuthorStrings
x86.elfJoeSecurity_MoobotYara detected MoobotJoe Security
    x86.elfJoeSecurity_Mirai_8Yara detected MiraiJoe Security
      x86.elfLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
      • 0xb628:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xb63c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xb650:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xb664:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xb678:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xb68c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xb6a0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xb6b4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xb6c8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xb6dc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xb6f0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xb704:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xb718:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xb72c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xb740:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xb754:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xb768:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xb77c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xb790:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xb7a4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xb7b8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      x86.elfLinux_Trojan_Mirai_b14f4c5dunknownunknown
      • 0x4ed0:$a: 53 31 DB 8B 4C 24 0C 8B 54 24 08 83 F9 01 76 15 66 8B 02 83 E9 02 25 FF FF 00 00 83 C2 02 01 C3 83 F9 01 77 EB 49 75 05 0F BE 02 01 C3
      x86.elfLinux_Trojan_Mirai_88de437funknownunknown
      • 0x6892:$a: 24 08 8B 4C 24 04 85 D2 74 0D 31 C0 89 F6 C6 04 08 00 40 39 D0
      Click to see the 3 entries
      SourceRuleDescriptionAuthorStrings
      5468.1.0000000008048000.0000000008055000.r-x.sdmpJoeSecurity_MoobotYara detected MoobotJoe Security
        5468.1.0000000008048000.0000000008055000.r-x.sdmpJoeSecurity_Mirai_8Yara detected MiraiJoe Security
          5468.1.0000000008048000.0000000008055000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
          • 0xb628:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xb63c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xb650:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xb664:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xb678:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xb68c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xb6a0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xb6b4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xb6c8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xb6dc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xb6f0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xb704:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xb718:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xb72c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xb740:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xb754:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xb768:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xb77c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xb790:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xb7a4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xb7b8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          5468.1.0000000008048000.0000000008055000.r-x.sdmpLinux_Trojan_Mirai_b14f4c5dunknownunknown
          • 0x4ed0:$a: 53 31 DB 8B 4C 24 0C 8B 54 24 08 83 F9 01 76 15 66 8B 02 83 E9 02 25 FF FF 00 00 83 C2 02 01 C3 83 F9 01 77 EB 49 75 05 0F BE 02 01 C3
          5468.1.0000000008048000.0000000008055000.r-x.sdmpLinux_Trojan_Mirai_88de437funknownunknown
          • 0x6892:$a: 24 08 8B 4C 24 04 85 D2 74 0D 31 C0 89 F6 C6 04 08 00 40 39 D0
          Click to see the 5 entries
          No Suricata rule has matched

          Click to jump to signature section

          Show All Signature Results

          AV Detection

          barindex
          Source: x86.elfAvira: detected
          Source: x86.elfVirustotal: Detection: 53%Perma Link
          Source: x86.elfReversingLabs: Detection: 60%
          Source: x86.elfJoe Sandbox ML: detected
          Source: global trafficDNS traffic detected: DNS query: wcjwcj.cn

          System Summary

          barindex
          Source: x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
          Source: x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_b14f4c5d Author: unknown
          Source: x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_88de437f Author: unknown
          Source: x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_389ee3e9 Author: unknown
          Source: x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_cc93863b Author: unknown
          Source: x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_8aa7b5d3 Author: unknown
          Source: 5468.1.0000000008048000.0000000008055000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
          Source: 5468.1.0000000008048000.0000000008055000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_b14f4c5d Author: unknown
          Source: 5468.1.0000000008048000.0000000008055000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_88de437f Author: unknown
          Source: 5468.1.0000000008048000.0000000008055000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_389ee3e9 Author: unknown
          Source: 5468.1.0000000008048000.0000000008055000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_cc93863b Author: unknown
          Source: 5468.1.0000000008048000.0000000008055000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_8aa7b5d3 Author: unknown
          Source: Process Memory Space: x86.elf PID: 5468, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
          Source: ELF static info symbol of initial sample.symtab present: no
          Source: x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
          Source: x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_b14f4c5d os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = a70d052918dd2fbc66db241da6438015130f0fb6929229bfe573546fe98da817, id = b14f4c5d-054f-46e6-9fa8-3588f1ef68b7, last_modified = 2021-09-16
          Source: x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_88de437f reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = c19eb595c2b444a809bef8500c20342c9f46694d3018e268833f9b884133a1ea, id = 88de437f-9c98-4e1d-96c0-7b433c99886a, last_modified = 2021-09-16
          Source: x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_389ee3e9 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 59f2359dc1f41d385d639d157b4cd9fc73d76d8abb7cc09d47632bb4c9a39e6e, id = 389ee3e9-70c1-4c93-a999-292cf6ff1652, last_modified = 2022-01-26
          Source: x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_cc93863b reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = f3ecd30f0b511a8e92cfa642409d559e7612c3f57a1659ca46c77aca809a00ac, id = cc93863b-1050-40ba-9d02-5ec9ce6a3a28, last_modified = 2022-01-26
          Source: x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_8aa7b5d3 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 02a2c18c362df4b1fceb33f3b605586514ba9a00c7afedf71c04fa54d8146444, id = 8aa7b5d3-e1eb-4b55-b36a-0d3a242c06e9, last_modified = 2022-01-26
          Source: 5468.1.0000000008048000.0000000008055000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
          Source: 5468.1.0000000008048000.0000000008055000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_b14f4c5d os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = a70d052918dd2fbc66db241da6438015130f0fb6929229bfe573546fe98da817, id = b14f4c5d-054f-46e6-9fa8-3588f1ef68b7, last_modified = 2021-09-16
          Source: 5468.1.0000000008048000.0000000008055000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_88de437f reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = c19eb595c2b444a809bef8500c20342c9f46694d3018e268833f9b884133a1ea, id = 88de437f-9c98-4e1d-96c0-7b433c99886a, last_modified = 2021-09-16
          Source: 5468.1.0000000008048000.0000000008055000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_389ee3e9 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 59f2359dc1f41d385d639d157b4cd9fc73d76d8abb7cc09d47632bb4c9a39e6e, id = 389ee3e9-70c1-4c93-a999-292cf6ff1652, last_modified = 2022-01-26
          Source: 5468.1.0000000008048000.0000000008055000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_cc93863b reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = f3ecd30f0b511a8e92cfa642409d559e7612c3f57a1659ca46c77aca809a00ac, id = cc93863b-1050-40ba-9d02-5ec9ce6a3a28, last_modified = 2022-01-26
          Source: 5468.1.0000000008048000.0000000008055000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_8aa7b5d3 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 02a2c18c362df4b1fceb33f3b605586514ba9a00c7afedf71c04fa54d8146444, id = 8aa7b5d3-e1eb-4b55-b36a-0d3a242c06e9, last_modified = 2022-01-26
          Source: Process Memory Space: x86.elf PID: 5468, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
          Source: classification engineClassification label: mal88.troj.evad.linELF@0/0@20/0
          Source: /tmp/x86.elf (PID: 5471)File opened: /proc/230/cmdlineJump to behavior
          Source: /tmp/x86.elf (PID: 5471)File opened: /proc/110/cmdlineJump to behavior
          Source: /tmp/x86.elf (PID: 5471)File opened: /proc/231/cmdlineJump to behavior
          Source: /tmp/x86.elf (PID: 5471)File opened: /proc/111/cmdlineJump to behavior
          Source: /tmp/x86.elf (PID: 5471)File opened: /proc/232/cmdlineJump to behavior
          Source: /tmp/x86.elf (PID: 5471)File opened: /proc/112/cmdlineJump to behavior
          Source: /tmp/x86.elf (PID: 5471)File opened: /proc/233/cmdlineJump to behavior
          Source: /tmp/x86.elf (PID: 5471)File opened: /proc/113/cmdlineJump to behavior
          Source: /tmp/x86.elf (PID: 5471)File opened: /proc/234/cmdlineJump to behavior
          Source: /tmp/x86.elf (PID: 5471)File opened: /proc/114/cmdlineJump to behavior
          Source: /tmp/x86.elf (PID: 5471)File opened: /proc/235/cmdlineJump to behavior
          Source: /tmp/x86.elf (PID: 5471)File opened: /proc/115/cmdlineJump to behavior
          Source: /tmp/x86.elf (PID: 5471)File opened: /proc/236/cmdlineJump to behavior
          Source: /tmp/x86.elf (PID: 5471)File opened: /proc/116/cmdlineJump to behavior
          Source: /tmp/x86.elf (PID: 5471)File opened: /proc/237/cmdlineJump to behavior
          Source: /tmp/x86.elf (PID: 5471)File opened: /proc/117/cmdlineJump to behavior
          Source: /tmp/x86.elf (PID: 5471)File opened: /proc/238/cmdlineJump to behavior
          Source: /tmp/x86.elf (PID: 5471)File opened: /proc/118/cmdlineJump to behavior
          Source: /tmp/x86.elf (PID: 5471)File opened: /proc/239/cmdlineJump to behavior
          Source: /tmp/x86.elf (PID: 5471)File opened: /proc/119/cmdlineJump to behavior
          Source: /tmp/x86.elf (PID: 5471)File opened: /proc/914/cmdlineJump to behavior
          Source: /tmp/x86.elf (PID: 5471)File opened: /proc/10/cmdlineJump to behavior
          Source: /tmp/x86.elf (PID: 5471)File opened: /proc/917/cmdlineJump to behavior
          Source: /tmp/x86.elf (PID: 5471)File opened: /proc/11/cmdlineJump to behavior
          Source: /tmp/x86.elf (PID: 5471)File opened: /proc/12/cmdlineJump to behavior
          Source: /tmp/x86.elf (PID: 5471)File opened: /proc/13/cmdlineJump to behavior
          Source: /tmp/x86.elf (PID: 5471)File opened: /proc/14/cmdlineJump to behavior
          Source: /tmp/x86.elf (PID: 5471)File opened: /proc/15/cmdlineJump to behavior
          Source: /tmp/x86.elf (PID: 5471)File opened: /proc/16/cmdlineJump to behavior
          Source: /tmp/x86.elf (PID: 5471)File opened: /proc/17/cmdlineJump to behavior
          Source: /tmp/x86.elf (PID: 5471)File opened: /proc/18/cmdlineJump to behavior
          Source: /tmp/x86.elf (PID: 5471)File opened: /proc/19/cmdlineJump to behavior
          Source: /tmp/x86.elf (PID: 5471)File opened: /proc/240/cmdlineJump to behavior
          Source: /tmp/x86.elf (PID: 5471)File opened: /proc/3095/cmdlineJump to behavior
          Source: /tmp/x86.elf (PID: 5471)File opened: /proc/120/cmdlineJump to behavior
          Source: /tmp/x86.elf (PID: 5471)File opened: /proc/241/cmdlineJump to behavior
          Source: /tmp/x86.elf (PID: 5471)File opened: /proc/121/cmdlineJump to behavior
          Source: /tmp/x86.elf (PID: 5471)File opened: /proc/242/cmdlineJump to behavior
          Source: /tmp/x86.elf (PID: 5471)File opened: /proc/1/cmdlineJump to behavior
          Source: /tmp/x86.elf (PID: 5471)File opened: /proc/122/cmdlineJump to behavior
          Source: /tmp/x86.elf (PID: 5471)File opened: /proc/243/cmdlineJump to behavior
          Source: /tmp/x86.elf (PID: 5471)File opened: /proc/2/cmdlineJump to behavior
          Source: /tmp/x86.elf (PID: 5471)File opened: /proc/123/cmdlineJump to behavior
          Source: /tmp/x86.elf (PID: 5471)File opened: /proc/244/cmdlineJump to behavior
          Source: /tmp/x86.elf (PID: 5471)File opened: /proc/3/cmdlineJump to behavior
          Source: /tmp/x86.elf (PID: 5471)File opened: /proc/124/cmdlineJump to behavior
          Source: /tmp/x86.elf (PID: 5471)File opened: /proc/245/cmdlineJump to behavior
          Source: /tmp/x86.elf (PID: 5471)File opened: /proc/1588/cmdlineJump to behavior
          Source: /tmp/x86.elf (PID: 5471)File opened: /proc/125/cmdlineJump to behavior
          Source: /tmp/x86.elf (PID: 5471)File opened: /proc/4/cmdlineJump to behavior
          Source: /tmp/x86.elf (PID: 5471)File opened: /proc/246/cmdlineJump to behavior
          Source: /tmp/x86.elf (PID: 5471)File opened: /proc/126/cmdlineJump to behavior
          Source: /tmp/x86.elf (PID: 5471)File opened: /proc/5/cmdlineJump to behavior
          Source: /tmp/x86.elf (PID: 5471)File opened: /proc/247/cmdlineJump to behavior
          Source: /tmp/x86.elf (PID: 5471)File opened: /proc/127/cmdlineJump to behavior
          Source: /tmp/x86.elf (PID: 5471)File opened: /proc/6/cmdlineJump to behavior
          Source: /tmp/x86.elf (PID: 5471)File opened: /proc/248/cmdlineJump to behavior
          Source: /tmp/x86.elf (PID: 5471)File opened: /proc/128/cmdlineJump to behavior
          Source: /tmp/x86.elf (PID: 5471)File opened: /proc/7/cmdlineJump to behavior
          Source: /tmp/x86.elf (PID: 5471)File opened: /proc/249/cmdlineJump to behavior
          Source: /tmp/x86.elf (PID: 5471)File opened: /proc/129/cmdlineJump to behavior
          Source: /tmp/x86.elf (PID: 5471)File opened: /proc/8/cmdlineJump to behavior
          Source: /tmp/x86.elf (PID: 5471)File opened: /proc/800/cmdlineJump to behavior
          Source: /tmp/x86.elf (PID: 5471)File opened: /proc/9/cmdlineJump to behavior
          Source: /tmp/x86.elf (PID: 5471)File opened: /proc/1906/cmdlineJump to behavior
          Source: /tmp/x86.elf (PID: 5471)File opened: /proc/802/cmdlineJump to behavior
          Source: /tmp/x86.elf (PID: 5471)File opened: /proc/803/cmdlineJump to behavior
          Source: /tmp/x86.elf (PID: 5471)File opened: /proc/20/cmdlineJump to behavior
          Source: /tmp/x86.elf (PID: 5471)File opened: /proc/21/cmdlineJump to behavior
          Source: /tmp/x86.elf (PID: 5471)File opened: /proc/22/cmdlineJump to behavior
          Source: /tmp/x86.elf (PID: 5471)File opened: /proc/23/cmdlineJump to behavior
          Source: /tmp/x86.elf (PID: 5471)File opened: /proc/24/cmdlineJump to behavior
          Source: /tmp/x86.elf (PID: 5471)File opened: /proc/25/cmdlineJump to behavior
          Source: /tmp/x86.elf (PID: 5471)File opened: /proc/26/cmdlineJump to behavior
          Source: /tmp/x86.elf (PID: 5471)File opened: /proc/27/cmdlineJump to behavior
          Source: /tmp/x86.elf (PID: 5471)File opened: /proc/28/cmdlineJump to behavior
          Source: /tmp/x86.elf (PID: 5471)File opened: /proc/29/cmdlineJump to behavior
          Source: /tmp/x86.elf (PID: 5471)File opened: /proc/3420/cmdlineJump to behavior
          Source: /tmp/x86.elf (PID: 5471)File opened: /proc/1482/cmdlineJump to behavior
          Source: /tmp/x86.elf (PID: 5471)File opened: /proc/490/cmdlineJump to behavior
          Source: /tmp/x86.elf (PID: 5471)File opened: /proc/1480/cmdlineJump to behavior
          Source: /tmp/x86.elf (PID: 5471)File opened: /proc/250/cmdlineJump to behavior
          Source: /tmp/x86.elf (PID: 5471)File opened: /proc/371/cmdlineJump to behavior
          Source: /tmp/x86.elf (PID: 5471)File opened: /proc/130/cmdlineJump to behavior
          Source: /tmp/x86.elf (PID: 5471)File opened: /proc/251/cmdlineJump to behavior
          Source: /tmp/x86.elf (PID: 5471)File opened: /proc/131/cmdlineJump to behavior
          Source: /tmp/x86.elf (PID: 5471)File opened: /proc/252/cmdlineJump to behavior
          Source: /tmp/x86.elf (PID: 5471)File opened: /proc/132/cmdlineJump to behavior
          Source: /tmp/x86.elf (PID: 5471)File opened: /proc/253/cmdlineJump to behavior
          Source: /tmp/x86.elf (PID: 5471)File opened: /proc/254/cmdlineJump to behavior
          Source: /tmp/x86.elf (PID: 5471)File opened: /proc/1238/cmdlineJump to behavior
          Source: /tmp/x86.elf (PID: 5471)File opened: /proc/134/cmdlineJump to behavior
          Source: /tmp/x86.elf (PID: 5471)File opened: /proc/255/cmdlineJump to behavior
          Source: /tmp/x86.elf (PID: 5471)File opened: /proc/256/cmdlineJump to behavior
          Source: /tmp/x86.elf (PID: 5471)File opened: /proc/257/cmdlineJump to behavior
          Source: /tmp/x86.elf (PID: 5471)File opened: /proc/378/cmdlineJump to behavior
          Source: /tmp/x86.elf (PID: 5471)File opened: /proc/3413/cmdlineJump to behavior
          Source: /tmp/x86.elf (PID: 5471)File opened: /proc/258/cmdlineJump to behavior
          Source: /tmp/x86.elf (PID: 5471)File opened: /proc/259/cmdlineJump to behavior
          Source: /tmp/x86.elf (PID: 5471)File opened: /proc/1475/cmdlineJump to behavior
          Source: /tmp/x86.elf (PID: 5471)File opened: /proc/936/cmdlineJump to behavior
          Source: /tmp/x86.elf (PID: 5471)File opened: /proc/30/cmdlineJump to behavior
          Source: /tmp/x86.elf (PID: 5471)File opened: /proc/816/cmdlineJump to behavior
          Source: /tmp/x86.elf (PID: 5471)File opened: /proc/35/cmdlineJump to behavior
          Source: /tmp/x86.elf (PID: 5471)File opened: /proc/3310/cmdlineJump to behavior

          Hooking and other Techniques for Hiding and Protection

          barindex
          Source: /tmp/x86.elf (PID: 5468)File: /tmp/x86.elfJump to behavior

          Stealing of Sensitive Information

          barindex
          Source: Yara matchFile source: x86.elf, type: SAMPLE
          Source: Yara matchFile source: 5468.1.0000000008048000.0000000008055000.r-x.sdmp, type: MEMORY
          Source: Yara matchFile source: Process Memory Space: x86.elf PID: 5468, type: MEMORYSTR
          Source: Yara matchFile source: x86.elf, type: SAMPLE
          Source: Yara matchFile source: 5468.1.0000000008048000.0000000008055000.r-x.sdmp, type: MEMORY

          Remote Access Functionality

          barindex
          Source: Yara matchFile source: x86.elf, type: SAMPLE
          Source: Yara matchFile source: 5468.1.0000000008048000.0000000008055000.r-x.sdmp, type: MEMORY
          Source: Yara matchFile source: Process Memory Space: x86.elf PID: 5468, type: MEMORYSTR
          Source: Yara matchFile source: x86.elf, type: SAMPLE
          Source: Yara matchFile source: 5468.1.0000000008048000.0000000008055000.r-x.sdmp, type: MEMORY
          ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
          Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception1
          File Deletion
          1
          OS Credential Dumping
          System Service DiscoveryRemote ServicesData from Local System1
          Non-Application Layer Protocol
          Exfiltration Over Other Network MediumAbuse Accessibility Features
          CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
          Application Layer Protocol
          Exfiltration Over BluetoothNetwork Denial of Service
          No configs have been found
          Hide Legend

          Legend:

          • Process
          • Signature
          • Created File
          • DNS/IP Info
          • Is Dropped
          • Number of created Files
          • Is malicious
          • Internet
          behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1582170 Sample: x86.elf Startdate: 30/12/2024 Architecture: LINUX Score: 88 20 wcjwcj.cn 2->20 22 Malicious sample detected (through community Yara rule) 2->22 24 Antivirus / Scanner detection for submitted sample 2->24 26 Multi AV Scanner detection for submitted file 2->26 28 3 other signatures 2->28 9 x86.elf 2->9         started        signatures3 process4 signatures5 30 Sample deletes itself 9->30 12 x86.elf 9->12         started        process6 process7 14 x86.elf 12->14         started        16 x86.elf 12->16         started        process8 18 x86.elf 14->18         started       

          This section contains all screenshots as thumbnails, including those not shown in the slideshow.


          windows-stand
          SourceDetectionScannerLabelLink
          x86.elf53%VirustotalBrowse
          x86.elf61%ReversingLabsLinux.Trojan.Mirai
          x86.elf100%AviraEXP/ELF.Mirai.Z.A
          x86.elf100%Joe Sandbox ML
          No Antivirus matches
          No Antivirus matches
          No Antivirus matches
          NameIPActiveMaliciousAntivirus DetectionReputation
          wcjwcj.cn
          69.165.74.109
          truefalse
            high
            No contacted IP infos
            No context
            MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
            wcjwcj.cndebug.dbg.elfGet hashmaliciousMirai, MoobotBrowse
            • 69.165.74.109
            arm.elfGet hashmaliciousMirai, MoobotBrowse
            • 69.165.74.109
            arm7.elfGet hashmaliciousMirai, MoobotBrowse
            • 69.165.74.109
            mpsl.elfGet hashmaliciousMirai, MoobotBrowse
            • 69.165.74.109
            JgR39HaU3e.elfGet hashmaliciousMirai, MoobotBrowse
            • 154.9.29.154
            n2pg2vVhEO.elfGet hashmaliciousMirai, MoobotBrowse
            • 154.9.29.154
            J6yrFHwNuC.elfGet hashmaliciousMirai, MoobotBrowse
            • 154.9.29.154
            sg123JWcuU.elfGet hashmaliciousMirai, MoobotBrowse
            • 154.9.29.154
            HePOITlRYk.elfGet hashmaliciousMirai, MoobotBrowse
            • 154.9.29.154
            4GI3jkntqw.elfGet hashmaliciousMirai, MoobotBrowse
            • 154.9.29.154
            No context
            No context
            No context
            No created / dropped files found
            File type:ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, stripped
            Entropy (8bit):6.463554549002547
            TrID:
            • ELF Executable and Linkable format (Linux) (4029/14) 50.16%
            • ELF Executable and Linkable format (generic) (4004/1) 49.84%
            File name:x86.elf
            File size:54'352 bytes
            MD5:e373f7402c38d2e01995322180c75630
            SHA1:58e5923cc56fc7d7dd296e69a1f4e6ec027c0dab
            SHA256:04c91b0036335d3a4b6c7a91f26bfbe306e50381e689c4ceff99d0d27f373f4a
            SHA512:ccbacf93f639db3c512a86aa2285ae2cf8c528a6ef0f58cd8fe56b27c33b6033a2ab4feb9821225fa27d28dd750224ff3e5db107232d96f167a40862584bc063
            SSDEEP:1536:wjypeGh6HRsFWxqF7BakRLbfdpfP91NtezmM9CYj:wjypeGh6H+sxVkRLzTn9z8zmqCYj
            TLSH:2F333AC5F343D9F6D85705B42037F7375E72F0E92119E683D3A9AA32AC52702A906A9C
            File Content Preview:.ELF....................d...4...........4. ...(.....................|...|....................P...P.......(..........Q.td............................U..S.......w....h....c...[]...$.............U......=.R...t..5....$P.....$P......u........t....h|M..........

            ELF header

            Class:ELF32
            Data:2's complement, little endian
            Version:1 (current)
            Machine:Intel 80386
            Version Number:0x1
            Type:EXEC (Executable file)
            OS/ABI:UNIX - System V
            ABI Version:0
            Entry Point Address:0x8048164
            Flags:0x0
            ELF Header Size:52
            Program Header Offset:52
            Program Header Size:32
            Number of Program Headers:3
            Section Header Offset:53952
            Section Header Size:40
            Number of Section Headers:10
            Header String Table Index:9
            NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
            NULL0x00x00x00x00x0000
            .initPROGBITS0x80480940x940x1c0x00x6AX001
            .textPROGBITS0x80480b00xb00xb0860x00x6AX0016
            .finiPROGBITS0x80531360xb1360x170x00x6AX001
            .rodataPROGBITS0x80531600xb1600x1c1c0x00x2A0032
            .ctorsPROGBITS0x80550000xd0000x80x00x3WA004
            .dtorsPROGBITS0x80550080xd0080x80x00x3WA004
            .dataPROGBITS0x80550200xd0200x2600x00x3WA0032
            .bssNOBITS0x80552800xd2800x25800x00x3WA0032
            .shstrtabSTRTAB0x00xd2800x3e0x00x0001
            TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
            LOAD0x00x80480000x80480000xcd7c0xcd7c6.54780x5R E0x1000.init .text .fini .rodata
            LOAD0xd0000x80550000x80550000x2800x28003.42380x6RW 0x1000.ctors .dtors .data .bss
            GNU_STACK0x00x00x00x00x00.00000x6RW 0x4
            TimestampSource PortDest PortSource IPDest IP
            Dec 30, 2024 03:23:18.294148922 CET5340953192.168.2.138.8.8.8
            Dec 30, 2024 03:23:18.301675081 CET53534098.8.8.8192.168.2.13
            Dec 30, 2024 03:23:24.302762032 CET4241553192.168.2.138.8.8.8
            Dec 30, 2024 03:23:24.310127020 CET53424158.8.8.8192.168.2.13
            Dec 30, 2024 03:23:30.311392069 CET5855253192.168.2.138.8.8.8
            Dec 30, 2024 03:23:30.545069933 CET53585528.8.8.8192.168.2.13
            Dec 30, 2024 03:23:39.546524048 CET4610653192.168.2.138.8.8.8
            Dec 30, 2024 03:23:39.553888083 CET53461068.8.8.8192.168.2.13
            Dec 30, 2024 03:23:43.555033922 CET3773553192.168.2.138.8.8.8
            Dec 30, 2024 03:23:43.820192099 CET53377358.8.8.8192.168.2.13
            Dec 30, 2024 03:23:48.821574926 CET4175353192.168.2.138.8.8.8
            Dec 30, 2024 03:23:48.827955961 CET53417538.8.8.8192.168.2.13
            Dec 30, 2024 03:23:54.829246998 CET4397053192.168.2.138.8.8.8
            Dec 30, 2024 03:23:54.836905003 CET53439708.8.8.8192.168.2.13
            Dec 30, 2024 03:24:03.838082075 CET5428353192.168.2.138.8.8.8
            Dec 30, 2024 03:24:03.844728947 CET53542838.8.8.8192.168.2.13
            Dec 30, 2024 03:24:04.845932007 CET4956853192.168.2.138.8.8.8
            Dec 30, 2024 03:24:04.852875948 CET53495688.8.8.8192.168.2.13
            Dec 30, 2024 03:24:05.854079962 CET5548653192.168.2.138.8.8.8
            Dec 30, 2024 03:24:05.861172915 CET53554868.8.8.8192.168.2.13
            Dec 30, 2024 03:24:11.862366915 CET4073953192.168.2.138.8.8.8
            Dec 30, 2024 03:24:11.869800091 CET53407398.8.8.8192.168.2.13
            Dec 30, 2024 03:24:14.871468067 CET5706253192.168.2.138.8.8.8
            Dec 30, 2024 03:24:14.878407001 CET53570628.8.8.8192.168.2.13
            Dec 30, 2024 03:24:26.881320953 CET5703753192.168.2.138.8.8.8
            Dec 30, 2024 03:24:26.888453960 CET53570378.8.8.8192.168.2.13
            Dec 30, 2024 03:24:29.890244961 CET3925153192.168.2.138.8.8.8
            Dec 30, 2024 03:24:29.897289038 CET53392518.8.8.8192.168.2.13
            Dec 30, 2024 03:24:34.899044991 CET5053253192.168.2.138.8.8.8
            Dec 30, 2024 03:24:35.164386034 CET53505328.8.8.8192.168.2.13
            Dec 30, 2024 03:24:44.166209936 CET3460053192.168.2.138.8.8.8
            Dec 30, 2024 03:24:44.172998905 CET53346008.8.8.8192.168.2.13
            Dec 30, 2024 03:24:54.174905062 CET3676953192.168.2.138.8.8.8
            Dec 30, 2024 03:24:54.182018042 CET53367698.8.8.8192.168.2.13
            Dec 30, 2024 03:25:02.183832884 CET5326753192.168.2.138.8.8.8
            Dec 30, 2024 03:25:02.190956116 CET53532678.8.8.8192.168.2.13
            Dec 30, 2024 03:25:10.194534063 CET3780053192.168.2.138.8.8.8
            Dec 30, 2024 03:25:10.201571941 CET53378008.8.8.8192.168.2.13
            Dec 30, 2024 03:25:20.203397989 CET5910753192.168.2.138.8.8.8
            Dec 30, 2024 03:25:20.210864067 CET53591078.8.8.8192.168.2.13
            TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
            Dec 30, 2024 03:23:18.294148922 CET192.168.2.138.8.8.80x755aStandard query (0)wcjwcj.cnA (IP address)IN (0x0001)false
            Dec 30, 2024 03:23:24.302762032 CET192.168.2.138.8.8.80xe787Standard query (0)wcjwcj.cnA (IP address)IN (0x0001)false
            Dec 30, 2024 03:23:30.311392069 CET192.168.2.138.8.8.80xeda0Standard query (0)wcjwcj.cnA (IP address)IN (0x0001)false
            Dec 30, 2024 03:23:39.546524048 CET192.168.2.138.8.8.80xf789Standard query (0)wcjwcj.cnA (IP address)IN (0x0001)false
            Dec 30, 2024 03:23:43.555033922 CET192.168.2.138.8.8.80x992cStandard query (0)wcjwcj.cnA (IP address)IN (0x0001)false
            Dec 30, 2024 03:23:48.821574926 CET192.168.2.138.8.8.80x2621Standard query (0)wcjwcj.cnA (IP address)IN (0x0001)false
            Dec 30, 2024 03:23:54.829246998 CET192.168.2.138.8.8.80xddb1Standard query (0)wcjwcj.cnA (IP address)IN (0x0001)false
            Dec 30, 2024 03:24:03.838082075 CET192.168.2.138.8.8.80x4d9bStandard query (0)wcjwcj.cnA (IP address)IN (0x0001)false
            Dec 30, 2024 03:24:04.845932007 CET192.168.2.138.8.8.80x552bStandard query (0)wcjwcj.cnA (IP address)IN (0x0001)false
            Dec 30, 2024 03:24:05.854079962 CET192.168.2.138.8.8.80x911aStandard query (0)wcjwcj.cnA (IP address)IN (0x0001)false
            Dec 30, 2024 03:24:11.862366915 CET192.168.2.138.8.8.80x5871Standard query (0)wcjwcj.cnA (IP address)IN (0x0001)false
            Dec 30, 2024 03:24:14.871468067 CET192.168.2.138.8.8.80x7a8cStandard query (0)wcjwcj.cnA (IP address)IN (0x0001)false
            Dec 30, 2024 03:24:26.881320953 CET192.168.2.138.8.8.80x5b0aStandard query (0)wcjwcj.cnA (IP address)IN (0x0001)false
            Dec 30, 2024 03:24:29.890244961 CET192.168.2.138.8.8.80xd9d1Standard query (0)wcjwcj.cnA (IP address)IN (0x0001)false
            Dec 30, 2024 03:24:34.899044991 CET192.168.2.138.8.8.80xafdfStandard query (0)wcjwcj.cnA (IP address)IN (0x0001)false
            Dec 30, 2024 03:24:44.166209936 CET192.168.2.138.8.8.80xa8fdStandard query (0)wcjwcj.cnA (IP address)IN (0x0001)false
            Dec 30, 2024 03:24:54.174905062 CET192.168.2.138.8.8.80x79d9Standard query (0)wcjwcj.cnA (IP address)IN (0x0001)false
            Dec 30, 2024 03:25:02.183832884 CET192.168.2.138.8.8.80x2e1aStandard query (0)wcjwcj.cnA (IP address)IN (0x0001)false
            Dec 30, 2024 03:25:10.194534063 CET192.168.2.138.8.8.80x981dStandard query (0)wcjwcj.cnA (IP address)IN (0x0001)false
            Dec 30, 2024 03:25:20.203397989 CET192.168.2.138.8.8.80x2054Standard query (0)wcjwcj.cnA (IP address)IN (0x0001)false
            TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
            Dec 30, 2024 03:23:18.301675081 CET8.8.8.8192.168.2.130x755aNo error (0)wcjwcj.cn69.165.74.109A (IP address)IN (0x0001)false
            Dec 30, 2024 03:23:24.310127020 CET8.8.8.8192.168.2.130xe787No error (0)wcjwcj.cn69.165.74.109A (IP address)IN (0x0001)false
            Dec 30, 2024 03:23:30.545069933 CET8.8.8.8192.168.2.130xeda0No error (0)wcjwcj.cn69.165.74.109A (IP address)IN (0x0001)false
            Dec 30, 2024 03:23:39.553888083 CET8.8.8.8192.168.2.130xf789No error (0)wcjwcj.cn69.165.74.109A (IP address)IN (0x0001)false
            Dec 30, 2024 03:23:43.820192099 CET8.8.8.8192.168.2.130x992cNo error (0)wcjwcj.cn69.165.74.109A (IP address)IN (0x0001)false
            Dec 30, 2024 03:23:48.827955961 CET8.8.8.8192.168.2.130x2621No error (0)wcjwcj.cn69.165.74.109A (IP address)IN (0x0001)false
            Dec 30, 2024 03:23:54.836905003 CET8.8.8.8192.168.2.130xddb1No error (0)wcjwcj.cn69.165.74.109A (IP address)IN (0x0001)false
            Dec 30, 2024 03:24:03.844728947 CET8.8.8.8192.168.2.130x4d9bNo error (0)wcjwcj.cn69.165.74.109A (IP address)IN (0x0001)false
            Dec 30, 2024 03:24:04.852875948 CET8.8.8.8192.168.2.130x552bNo error (0)wcjwcj.cn69.165.74.109A (IP address)IN (0x0001)false
            Dec 30, 2024 03:24:05.861172915 CET8.8.8.8192.168.2.130x911aNo error (0)wcjwcj.cn69.165.74.109A (IP address)IN (0x0001)false
            Dec 30, 2024 03:24:11.869800091 CET8.8.8.8192.168.2.130x5871No error (0)wcjwcj.cn69.165.74.109A (IP address)IN (0x0001)false
            Dec 30, 2024 03:24:14.878407001 CET8.8.8.8192.168.2.130x7a8cNo error (0)wcjwcj.cn69.165.74.109A (IP address)IN (0x0001)false
            Dec 30, 2024 03:24:26.888453960 CET8.8.8.8192.168.2.130x5b0aNo error (0)wcjwcj.cn69.165.74.109A (IP address)IN (0x0001)false
            Dec 30, 2024 03:24:29.897289038 CET8.8.8.8192.168.2.130xd9d1No error (0)wcjwcj.cn69.165.74.109A (IP address)IN (0x0001)false
            Dec 30, 2024 03:24:35.164386034 CET8.8.8.8192.168.2.130xafdfNo error (0)wcjwcj.cn69.165.74.109A (IP address)IN (0x0001)false
            Dec 30, 2024 03:24:44.172998905 CET8.8.8.8192.168.2.130xa8fdNo error (0)wcjwcj.cn69.165.74.109A (IP address)IN (0x0001)false
            Dec 30, 2024 03:24:54.182018042 CET8.8.8.8192.168.2.130x79d9No error (0)wcjwcj.cn69.165.74.109A (IP address)IN (0x0001)false
            Dec 30, 2024 03:25:02.190956116 CET8.8.8.8192.168.2.130x2e1aNo error (0)wcjwcj.cn69.165.74.109A (IP address)IN (0x0001)false
            Dec 30, 2024 03:25:10.201571941 CET8.8.8.8192.168.2.130x981dNo error (0)wcjwcj.cn69.165.74.109A (IP address)IN (0x0001)false
            Dec 30, 2024 03:25:20.210864067 CET8.8.8.8192.168.2.130x2054No error (0)wcjwcj.cn69.165.74.109A (IP address)IN (0x0001)false

            System Behavior

            Start time (UTC):02:23:17
            Start date (UTC):30/12/2024
            Path:/tmp/x86.elf
            Arguments:/tmp/x86.elf
            File size:54352 bytes
            MD5 hash:e373f7402c38d2e01995322180c75630

            Start time (UTC):02:23:17
            Start date (UTC):30/12/2024
            Path:/tmp/x86.elf
            Arguments:-
            File size:54352 bytes
            MD5 hash:e373f7402c38d2e01995322180c75630

            Start time (UTC):02:23:17
            Start date (UTC):30/12/2024
            Path:/tmp/x86.elf
            Arguments:-
            File size:54352 bytes
            MD5 hash:e373f7402c38d2e01995322180c75630

            Start time (UTC):02:23:17
            Start date (UTC):30/12/2024
            Path:/tmp/x86.elf
            Arguments:-
            File size:54352 bytes
            MD5 hash:e373f7402c38d2e01995322180c75630

            Start time (UTC):02:23:17
            Start date (UTC):30/12/2024
            Path:/tmp/x86.elf
            Arguments:-
            File size:54352 bytes
            MD5 hash:e373f7402c38d2e01995322180c75630