Edit tour
Linux
Analysis Report
bot.x86.elf
Overview
General Information
Sample name: | bot.x86.elf |
Analysis ID: | 1583139 |
MD5: | dd71487c78fb3cc5ab09c350a01d28f7 |
SHA1: | ab30dae9842cfe912461b1fa1a098247babe8e28 |
SHA256: | f3928fd942a8d5e9b9ffaa98e0722903f936eb895a0934ad3a24fe5a4a7495f8 |
Tags: | elfuser-abuse_ch |
Infos: |
Detection
Mirai, Okiru
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Signatures
Antivirus / Scanner detection for submitted sample
Detected Mirai
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Suricata IDS alerts for network traffic
Yara detected Mirai
Yara detected Okiru
Connects to many ports of the same IP (likely port scanning)
Machine Learning detection for sample
Detected TCP or UDP traffic on non-standard ports
Enumerates processes within the "proc" file system
Found strings indicative of a multi-platform dropper
Sample contains strings indicative of BusyBox which embeds multiple Unix commands in a single executable
Sample has stripped symbol table
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Yara signature match
Classification
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1583139 |
Start date and time: | 2025-01-02 02:51:06 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 4m 26s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultlinuxfilecookbook.jbs |
Analysis system description: | Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11) |
Analysis Mode: | default |
Sample name: | bot.x86.elf |
Detection: | MAL |
Classification: | mal100.troj.linELF@0/0@20/0 |
Command: | /tmp/bot.x86.elf |
PID: | 6241 |
Exit Code: | 0 |
Exit Code Info: | |
Killed: | False |
Standard Output: | done. |
Standard Error: |
- system is lnxubuntu20
- bot.x86.elf New Fork (PID: 6242, Parent: 6241)
- bot.x86.elf New Fork (PID: 6243, Parent: 6242)
- cleanup
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
Mirai | Mirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese. Nowadays it targets a wide range of networked embedded devices such as IP cameras, home routers (many vendors involved), and other IoT devices. Since the source code was published on "Hack Forums" many variants of the Mirai family appeared, infecting mostly home networks all around the world. | No Attribution |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_Okiru | Yara detected Okiru | Joe Security | ||
JoeSecurity_Mirai_3 | Yara detected Mirai | Joe Security | ||
JoeSecurity_Mirai_8 | Yara detected Mirai | Joe Security | ||
Linux_Trojan_Gafgyt_28a2fe0c | unknown | unknown |
| |
Linux_Trojan_Mirai_b14f4c5d | unknown | unknown |
| |
Click to see the 5 entries |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_Okiru | Yara detected Okiru | Joe Security | ||
JoeSecurity_Mirai_3 | Yara detected Mirai | Joe Security | ||
JoeSecurity_Mirai_8 | Yara detected Mirai | Joe Security | ||
Linux_Trojan_Gafgyt_28a2fe0c | unknown | unknown |
| |
Linux_Trojan_Mirai_b14f4c5d | unknown | unknown |
| |
Click to see the 9 entries |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2025-01-02T02:51:49.224916+0100 | 2030490 | 1 | Malware Command and Control Activity Detected | 192.168.2.23 | 51750 | 160.191.175.187 | 43957 | TCP |
2025-01-02T02:51:54.078810+0100 | 2030490 | 1 | Malware Command and Control Activity Detected | 192.168.2.23 | 51752 | 160.191.175.187 | 43957 | TCP |
2025-01-02T02:52:04.946028+0100 | 2030490 | 1 | Malware Command and Control Activity Detected | 192.168.2.23 | 51754 | 160.191.175.187 | 43957 | TCP |
2025-01-02T02:52:08.790763+0100 | 2030490 | 1 | Malware Command and Control Activity Detected | 192.168.2.23 | 51756 | 160.191.175.187 | 43957 | TCP |
2025-01-02T02:52:19.653054+0100 | 2030490 | 1 | Malware Command and Control Activity Detected | 192.168.2.23 | 51758 | 160.191.175.187 | 43957 | TCP |
2025-01-02T02:52:23.512886+0100 | 2030490 | 1 | Malware Command and Control Activity Detected | 192.168.2.23 | 51760 | 160.191.175.187 | 43957 | TCP |
2025-01-02T02:52:27.401265+0100 | 2030490 | 1 | Malware Command and Control Activity Detected | 192.168.2.23 | 51762 | 160.191.175.187 | 43957 | TCP |
2025-01-02T02:52:31.256623+0100 | 2030490 | 1 | Malware Command and Control Activity Detected | 192.168.2.23 | 51764 | 160.191.175.187 | 43957 | TCP |
2025-01-02T02:52:33.094730+0100 | 2030490 | 1 | Malware Command and Control Activity Detected | 192.168.2.23 | 51766 | 160.191.175.187 | 43957 | TCP |
2025-01-02T02:52:36.948372+0100 | 2030490 | 1 | Malware Command and Control Activity Detected | 192.168.2.23 | 51768 | 160.191.175.187 | 43957 | TCP |
2025-01-02T02:52:44.823225+0100 | 2030490 | 1 | Malware Command and Control Activity Detected | 192.168.2.23 | 51770 | 160.191.175.187 | 43957 | TCP |
2025-01-02T02:52:53.662268+0100 | 2030490 | 1 | Malware Command and Control Activity Detected | 192.168.2.23 | 51772 | 160.191.175.187 | 43957 | TCP |
2025-01-02T02:53:02.521685+0100 | 2030490 | 1 | Malware Command and Control Activity Detected | 192.168.2.23 | 51774 | 160.191.175.187 | 43957 | TCP |
2025-01-02T02:53:10.373177+0100 | 2030490 | 1 | Malware Command and Control Activity Detected | 192.168.2.23 | 51776 | 160.191.175.187 | 43957 | TCP |
2025-01-02T02:53:21.221830+0100 | 2030490 | 1 | Malware Command and Control Activity Detected | 192.168.2.23 | 51778 | 160.191.175.187 | 43957 | TCP |
2025-01-02T02:53:23.116860+0100 | 2030490 | 1 | Malware Command and Control Activity Detected | 192.168.2.23 | 51780 | 160.191.175.187 | 43957 | TCP |
2025-01-02T02:53:29.968975+0100 | 2030490 | 1 | Malware Command and Control Activity Detected | 192.168.2.23 | 51782 | 160.191.175.187 | 43957 | TCP |
2025-01-02T02:53:36.850192+0100 | 2030490 | 1 | Malware Command and Control Activity Detected | 192.168.2.23 | 51784 | 160.191.175.187 | 43957 | TCP |
2025-01-02T02:53:45.701356+0100 | 2030490 | 1 | Malware Command and Control Activity Detected | 192.168.2.23 | 51786 | 160.191.175.187 | 43957 | TCP |
2025-01-02T02:53:50.547752+0100 | 2030490 | 1 | Malware Command and Control Activity Detected | 192.168.2.23 | 51788 | 160.191.175.187 | 43957 | TCP |
Click to jump to signature section
Show All Signature Results
AV Detection |
---|
Source: | Avira: |
Source: | ReversingLabs: |
Source: | Joe Sandbox ML: |
Source: | String: |
Networking |
---|
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: |
Source: | TCP traffic: |
Source: | TCP traffic: |
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: |
Source: | DNS traffic detected: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
System Summary |
---|
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | String containing 'busybox' found: | ||
Source: | String containing 'busybox' found: |
Source: | .symtab present: |
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Classification label: |
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior |
Stealing of Sensitive Information |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Remote Access Functionality |
---|
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | 1 Scripting | Valid Accounts | Windows Management Instrumentation | 1 Scripting | Path Interception | Direct Volume Access | 1 OS Credential Dumping | System Service Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | Rootkit | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 1 Non-Standard Port | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 1 Non-Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | 2 Application Layer Protocol | Traffic Duplication | Data Destruction |
⊘No configs have been found
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
63% | ReversingLabs | Linux.Backdoor.Mirai | ||
100% | Avira | EXP/ELF.Mirai.Z.A | ||
100% | Joe Sandbox ML |
⊘No Antivirus matches
⊘No Antivirus matches
⊘No Antivirus matches
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
botnetdolly.zapto.org | 160.191.175.187 | true | false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
160.191.175.187 | botnetdolly.zapto.org | unknown | 2907 | SINET-ASResearchOrganizationofInformationandSystemsN | false | |
109.202.202.202 | unknown | Switzerland | 13030 | INIT7CH | false | |
91.189.91.43 | unknown | United Kingdom | 41231 | CANONICAL-ASGB | false | |
91.189.91.42 | unknown | United Kingdom | 41231 | CANONICAL-ASGB | false |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
160.191.175.187 | Get hash | malicious | Mirai, Gafgyt, Okiru | Browse | ||
Get hash | malicious | Mirai, Gafgyt, Okiru | Browse | |||
Get hash | malicious | Mirai, Gafgyt, Okiru | Browse | |||
Get hash | malicious | Mirai, Gafgyt, Okiru | Browse | |||
Get hash | malicious | Mirai, Gafgyt, Okiru | Browse | |||
Get hash | malicious | Mirai, Okiru | Browse | |||
109.202.202.202 | Get hash | malicious | Unknown | Browse |
| |
91.189.91.43 | Get hash | malicious | Mirai, Gafgyt, Okiru | Browse | ||
Get hash | malicious | Mirai, Gafgyt, Okiru | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Mirai, Gafgyt, Okiru | Browse | |||
Get hash | malicious | Mirai, Gafgyt, Okiru | Browse | |||
Get hash | malicious | Mirai, Okiru | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Mirai | Browse | |||
91.189.91.42 | Get hash | malicious | Mirai, Gafgyt, Okiru | Browse | ||
Get hash | malicious | Mirai, Gafgyt, Okiru | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Mirai, Gafgyt, Okiru | Browse | |||
Get hash | malicious | Mirai, Gafgyt, Okiru | Browse | |||
Get hash | malicious | Mirai, Okiru | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Mirai | Browse |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
botnetdolly.zapto.org | Get hash | malicious | Mirai, Gafgyt, Okiru | Browse |
| |
Get hash | malicious | Mirai, Gafgyt, Okiru | Browse |
| ||
Get hash | malicious | Mirai, Gafgyt, Okiru | Browse |
| ||
Get hash | malicious | Mirai, Gafgyt, Okiru | Browse |
| ||
Get hash | malicious | Mirai, Gafgyt, Okiru | Browse |
| ||
Get hash | malicious | Mirai, Okiru | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
CANONICAL-ASGB | Get hash | malicious | Mirai, Gafgyt, Okiru | Browse |
| |
Get hash | malicious | Mirai, Gafgyt, Okiru | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai, Gafgyt, Okiru | Browse |
| ||
Get hash | malicious | Mirai, Gafgyt, Okiru | Browse |
| ||
Get hash | malicious | Mirai, Gafgyt, Okiru | Browse |
| ||
Get hash | malicious | Mirai, Okiru | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
CANONICAL-ASGB | Get hash | malicious | Mirai, Gafgyt, Okiru | Browse |
| |
Get hash | malicious | Mirai, Gafgyt, Okiru | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai, Gafgyt, Okiru | Browse |
| ||
Get hash | malicious | Mirai, Gafgyt, Okiru | Browse |
| ||
Get hash | malicious | Mirai, Gafgyt, Okiru | Browse |
| ||
Get hash | malicious | Mirai, Okiru | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
SINET-ASResearchOrganizationofInformationandSystemsN | Get hash | malicious | Mirai, Gafgyt, Okiru | Browse |
| |
Get hash | malicious | Mirai, Gafgyt, Okiru | Browse |
| ||
Get hash | malicious | Mirai, Gafgyt, Okiru | Browse |
| ||
Get hash | malicious | Mirai, Gafgyt, Okiru | Browse |
| ||
Get hash | malicious | Mirai, Gafgyt, Okiru | Browse |
| ||
Get hash | malicious | Mirai, Okiru | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
INIT7CH | Get hash | malicious | Mirai, Gafgyt, Okiru | Browse |
| |
Get hash | malicious | Mirai, Gafgyt, Okiru | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai, Gafgyt, Okiru | Browse |
| ||
Get hash | malicious | Mirai, Gafgyt, Okiru | Browse |
| ||
Get hash | malicious | Mirai, Okiru | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
|
⊘No context
⊘No context
⊘No created / dropped files found
File type: | |
Entropy (8bit): | 5.714966505237118 |
TrID: |
|
File name: | bot.x86.elf |
File size: | 89'576 bytes |
MD5: | dd71487c78fb3cc5ab09c350a01d28f7 |
SHA1: | ab30dae9842cfe912461b1fa1a098247babe8e28 |
SHA256: | f3928fd942a8d5e9b9ffaa98e0722903f936eb895a0934ad3a24fe5a4a7495f8 |
SHA512: | ac5e285f1d20f498e7536997349f718d895239d6d4361ac2e97f362dad78abc4dda855fe20b8b306816ca47fa7b9e097ae1157540fb5fb75245563b89af9182e |
SSDEEP: | 1536:xpmWc2AcighsZ82fJxfcUHH1mSsM8y6Q+gBQ9TnkISGtAdy0xZ:xpmX2riED2frf7HVmL1Q1Q9kVTy0x |
TLSH: | DC936CC5F683D4F5E89304B1613AEB339B33F0B52019EA43D7799932ECA1511EA16B6C |
File Content Preview: | .ELF....................d...4...X\......4. ...(......................................................G..8...........Q.td............................U..S........$...h........[]...$.............U......= ....t..5...................u........t....h............ |
ELF header | |
---|---|
Class: | |
Data: | |
Version: | |
Machine: | |
Version Number: | |
Type: | |
OS/ABI: | |
ABI Version: | 0 |
Entry Point Address: | |
Flags: | |
ELF Header Size: | 52 |
Program Header Offset: | 52 |
Program Header Size: | 32 |
Number of Program Headers: | 3 |
Section Header Offset: | 89176 |
Section Header Size: | 40 |
Number of Section Headers: | 10 |
Header String Table Index: | 9 |
Name | Type | Address | Offset | Size | EntSize | Flags | Flags Description | Link | Info | Align |
---|---|---|---|---|---|---|---|---|---|---|
NULL | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0 | 0 | 0 | ||
.init | PROGBITS | 0x8048094 | 0x94 | 0x1c | 0x0 | 0x6 | AX | 0 | 0 | 1 |
.text | PROGBITS | 0x80480b0 | 0xb0 | 0xf136 | 0x0 | 0x6 | AX | 0 | 0 | 16 |
.fini | PROGBITS | 0x80571e6 | 0xf1e6 | 0x17 | 0x0 | 0x6 | AX | 0 | 0 | 1 |
.rodata | PROGBITS | 0x8057200 | 0xf200 | 0x2290 | 0x0 | 0x2 | A | 0 | 0 | 32 |
.ctors | PROGBITS | 0x805a494 | 0x11494 | 0xc | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.dtors | PROGBITS | 0x805a4a0 | 0x114a0 | 0x8 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.data | PROGBITS | 0x805a4c0 | 0x114c0 | 0x4758 | 0x0 | 0x3 | WA | 0 | 0 | 32 |
.bss | NOBITS | 0x805ec20 | 0x15c18 | 0x49ac | 0x0 | 0x3 | WA | 0 | 0 | 32 |
.shstrtab | STRTAB | 0x0 | 0x15c18 | 0x3e | 0x0 | 0x0 | 0 | 0 | 1 |
Type | Offset | Virtual Address | Physical Address | File Size | Memory Size | Entropy | Flags | Flags Description | Align | Prog Interpreter | Section Mappings |
---|---|---|---|---|---|---|---|---|---|---|---|
LOAD | 0x0 | 0x8048000 | 0x8048000 | 0x11490 | 0x11490 | 6.5886 | 0x5 | R E | 0x1000 | .init .text .fini .rodata | |
LOAD | 0x11494 | 0x805a494 | 0x805a494 | 0x4784 | 0x9138 | 0.3643 | 0x6 | RW | 0x1000 | .ctors .dtors .data .bss | |
GNU_STACK | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0.0000 | 0x6 | RW | 0x4 |
Timestamp | SID | Signature | Severity | Source IP | Source Port | Dest IP | Dest Port | Protocol |
---|---|---|---|---|---|---|---|---|
2025-01-02T02:51:49.224916+0100 | 2030490 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) | 1 | 192.168.2.23 | 51750 | 160.191.175.187 | 43957 | TCP |
2025-01-02T02:51:54.078810+0100 | 2030490 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) | 1 | 192.168.2.23 | 51752 | 160.191.175.187 | 43957 | TCP |
2025-01-02T02:52:04.946028+0100 | 2030490 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) | 1 | 192.168.2.23 | 51754 | 160.191.175.187 | 43957 | TCP |
2025-01-02T02:52:08.790763+0100 | 2030490 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) | 1 | 192.168.2.23 | 51756 | 160.191.175.187 | 43957 | TCP |
2025-01-02T02:52:19.653054+0100 | 2030490 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) | 1 | 192.168.2.23 | 51758 | 160.191.175.187 | 43957 | TCP |
2025-01-02T02:52:23.512886+0100 | 2030490 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) | 1 | 192.168.2.23 | 51760 | 160.191.175.187 | 43957 | TCP |
2025-01-02T02:52:27.401265+0100 | 2030490 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) | 1 | 192.168.2.23 | 51762 | 160.191.175.187 | 43957 | TCP |
2025-01-02T02:52:31.256623+0100 | 2030490 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) | 1 | 192.168.2.23 | 51764 | 160.191.175.187 | 43957 | TCP |
2025-01-02T02:52:33.094730+0100 | 2030490 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) | 1 | 192.168.2.23 | 51766 | 160.191.175.187 | 43957 | TCP |
2025-01-02T02:52:36.948372+0100 | 2030490 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) | 1 | 192.168.2.23 | 51768 | 160.191.175.187 | 43957 | TCP |
2025-01-02T02:52:44.823225+0100 | 2030490 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) | 1 | 192.168.2.23 | 51770 | 160.191.175.187 | 43957 | TCP |
2025-01-02T02:52:53.662268+0100 | 2030490 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) | 1 | 192.168.2.23 | 51772 | 160.191.175.187 | 43957 | TCP |
2025-01-02T02:53:02.521685+0100 | 2030490 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) | 1 | 192.168.2.23 | 51774 | 160.191.175.187 | 43957 | TCP |
2025-01-02T02:53:10.373177+0100 | 2030490 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) | 1 | 192.168.2.23 | 51776 | 160.191.175.187 | 43957 | TCP |
2025-01-02T02:53:21.221830+0100 | 2030490 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) | 1 | 192.168.2.23 | 51778 | 160.191.175.187 | 43957 | TCP |
2025-01-02T02:53:23.116860+0100 | 2030490 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) | 1 | 192.168.2.23 | 51780 | 160.191.175.187 | 43957 | TCP |
2025-01-02T02:53:29.968975+0100 | 2030490 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) | 1 | 192.168.2.23 | 51782 | 160.191.175.187 | 43957 | TCP |
2025-01-02T02:53:36.850192+0100 | 2030490 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) | 1 | 192.168.2.23 | 51784 | 160.191.175.187 | 43957 | TCP |
2025-01-02T02:53:45.701356+0100 | 2030490 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) | 1 | 192.168.2.23 | 51786 | 160.191.175.187 | 43957 | TCP |
2025-01-02T02:53:50.547752+0100 | 2030490 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) | 1 | 192.168.2.23 | 51788 | 160.191.175.187 | 43957 | TCP |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jan 2, 2025 02:51:49.220005035 CET | 51750 | 43957 | 192.168.2.23 | 160.191.175.187 |
Jan 2, 2025 02:51:49.224838972 CET | 43957 | 51750 | 160.191.175.187 | 192.168.2.23 |
Jan 2, 2025 02:51:49.224884987 CET | 51750 | 43957 | 192.168.2.23 | 160.191.175.187 |
Jan 2, 2025 02:51:49.224915981 CET | 51750 | 43957 | 192.168.2.23 | 160.191.175.187 |
Jan 2, 2025 02:51:49.229682922 CET | 43957 | 51750 | 160.191.175.187 | 192.168.2.23 |
Jan 2, 2025 02:51:50.065045118 CET | 43957 | 51750 | 160.191.175.187 | 192.168.2.23 |
Jan 2, 2025 02:51:50.065104961 CET | 51750 | 43957 | 192.168.2.23 | 160.191.175.187 |
Jan 2, 2025 02:51:50.069895029 CET | 43957 | 51750 | 160.191.175.187 | 192.168.2.23 |
Jan 2, 2025 02:51:51.478696108 CET | 43928 | 443 | 192.168.2.23 | 91.189.91.42 |
Jan 2, 2025 02:51:54.074001074 CET | 51752 | 43957 | 192.168.2.23 | 160.191.175.187 |
Jan 2, 2025 02:51:54.078746080 CET | 43957 | 51752 | 160.191.175.187 | 192.168.2.23 |
Jan 2, 2025 02:51:54.078809977 CET | 51752 | 43957 | 192.168.2.23 | 160.191.175.187 |
Jan 2, 2025 02:51:54.078809977 CET | 51752 | 43957 | 192.168.2.23 | 160.191.175.187 |
Jan 2, 2025 02:51:54.083591938 CET | 43957 | 51752 | 160.191.175.187 | 192.168.2.23 |
Jan 2, 2025 02:51:54.915374041 CET | 43957 | 51752 | 160.191.175.187 | 192.168.2.23 |
Jan 2, 2025 02:51:54.918735027 CET | 51752 | 43957 | 192.168.2.23 | 160.191.175.187 |
Jan 2, 2025 02:51:54.923533916 CET | 43957 | 51752 | 160.191.175.187 | 192.168.2.23 |
Jan 2, 2025 02:51:56.854101896 CET | 42836 | 443 | 192.168.2.23 | 91.189.91.43 |
Jan 2, 2025 02:51:58.389748096 CET | 42516 | 80 | 192.168.2.23 | 109.202.202.202 |
Jan 2, 2025 02:52:04.941149950 CET | 51754 | 43957 | 192.168.2.23 | 160.191.175.187 |
Jan 2, 2025 02:52:04.945950031 CET | 43957 | 51754 | 160.191.175.187 | 192.168.2.23 |
Jan 2, 2025 02:52:04.946002960 CET | 51754 | 43957 | 192.168.2.23 | 160.191.175.187 |
Jan 2, 2025 02:52:04.946027994 CET | 51754 | 43957 | 192.168.2.23 | 160.191.175.187 |
Jan 2, 2025 02:52:04.950820923 CET | 43957 | 51754 | 160.191.175.187 | 192.168.2.23 |
Jan 2, 2025 02:52:05.777779102 CET | 43957 | 51754 | 160.191.175.187 | 192.168.2.23 |
Jan 2, 2025 02:52:05.778067112 CET | 51754 | 43957 | 192.168.2.23 | 160.191.175.187 |
Jan 2, 2025 02:52:05.782869101 CET | 43957 | 51754 | 160.191.175.187 | 192.168.2.23 |
Jan 2, 2025 02:52:08.785846949 CET | 51756 | 43957 | 192.168.2.23 | 160.191.175.187 |
Jan 2, 2025 02:52:08.790667057 CET | 43957 | 51756 | 160.191.175.187 | 192.168.2.23 |
Jan 2, 2025 02:52:08.790714025 CET | 51756 | 43957 | 192.168.2.23 | 160.191.175.187 |
Jan 2, 2025 02:52:08.790762901 CET | 51756 | 43957 | 192.168.2.23 | 160.191.175.187 |
Jan 2, 2025 02:52:08.795567989 CET | 43957 | 51756 | 160.191.175.187 | 192.168.2.23 |
Jan 2, 2025 02:52:09.641000986 CET | 43957 | 51756 | 160.191.175.187 | 192.168.2.23 |
Jan 2, 2025 02:52:09.641103029 CET | 51756 | 43957 | 192.168.2.23 | 160.191.175.187 |
Jan 2, 2025 02:52:09.646066904 CET | 43957 | 51756 | 160.191.175.187 | 192.168.2.23 |
Jan 2, 2025 02:52:11.699856997 CET | 43928 | 443 | 192.168.2.23 | 91.189.91.42 |
Jan 2, 2025 02:52:19.648143053 CET | 51758 | 43957 | 192.168.2.23 | 160.191.175.187 |
Jan 2, 2025 02:52:19.652976036 CET | 43957 | 51758 | 160.191.175.187 | 192.168.2.23 |
Jan 2, 2025 02:52:19.653033018 CET | 51758 | 43957 | 192.168.2.23 | 160.191.175.187 |
Jan 2, 2025 02:52:19.653053999 CET | 51758 | 43957 | 192.168.2.23 | 160.191.175.187 |
Jan 2, 2025 02:52:19.657846928 CET | 43957 | 51758 | 160.191.175.187 | 192.168.2.23 |
Jan 2, 2025 02:52:20.498334885 CET | 43957 | 51758 | 160.191.175.187 | 192.168.2.23 |
Jan 2, 2025 02:52:20.498420954 CET | 51758 | 43957 | 192.168.2.23 | 160.191.175.187 |
Jan 2, 2025 02:52:20.503166914 CET | 43957 | 51758 | 160.191.175.187 | 192.168.2.23 |
Jan 2, 2025 02:52:23.507982016 CET | 51760 | 43957 | 192.168.2.23 | 160.191.175.187 |
Jan 2, 2025 02:52:23.512814999 CET | 43957 | 51760 | 160.191.175.187 | 192.168.2.23 |
Jan 2, 2025 02:52:23.512860060 CET | 51760 | 43957 | 192.168.2.23 | 160.191.175.187 |
Jan 2, 2025 02:52:23.512886047 CET | 51760 | 43957 | 192.168.2.23 | 160.191.175.187 |
Jan 2, 2025 02:52:23.517648935 CET | 43957 | 51760 | 160.191.175.187 | 192.168.2.23 |
Jan 2, 2025 02:52:23.986109018 CET | 42836 | 443 | 192.168.2.23 | 91.189.91.43 |
Jan 2, 2025 02:52:24.387521982 CET | 43957 | 51760 | 160.191.175.187 | 192.168.2.23 |
Jan 2, 2025 02:52:24.387820005 CET | 51760 | 43957 | 192.168.2.23 | 160.191.175.187 |
Jan 2, 2025 02:52:24.392651081 CET | 43957 | 51760 | 160.191.175.187 | 192.168.2.23 |
Jan 2, 2025 02:52:27.396363974 CET | 51762 | 43957 | 192.168.2.23 | 160.191.175.187 |
Jan 2, 2025 02:52:27.401104927 CET | 43957 | 51762 | 160.191.175.187 | 192.168.2.23 |
Jan 2, 2025 02:52:27.401164055 CET | 51762 | 43957 | 192.168.2.23 | 160.191.175.187 |
Jan 2, 2025 02:52:27.401264906 CET | 51762 | 43957 | 192.168.2.23 | 160.191.175.187 |
Jan 2, 2025 02:52:27.406060934 CET | 43957 | 51762 | 160.191.175.187 | 192.168.2.23 |
Jan 2, 2025 02:52:28.081530094 CET | 42516 | 80 | 192.168.2.23 | 109.202.202.202 |
Jan 2, 2025 02:52:28.243118048 CET | 43957 | 51762 | 160.191.175.187 | 192.168.2.23 |
Jan 2, 2025 02:52:28.243376017 CET | 51762 | 43957 | 192.168.2.23 | 160.191.175.187 |
Jan 2, 2025 02:52:28.248099089 CET | 43957 | 51762 | 160.191.175.187 | 192.168.2.23 |
Jan 2, 2025 02:52:31.251648903 CET | 51764 | 43957 | 192.168.2.23 | 160.191.175.187 |
Jan 2, 2025 02:52:31.256529093 CET | 43957 | 51764 | 160.191.175.187 | 192.168.2.23 |
Jan 2, 2025 02:52:31.256623030 CET | 51764 | 43957 | 192.168.2.23 | 160.191.175.187 |
Jan 2, 2025 02:52:31.256623030 CET | 51764 | 43957 | 192.168.2.23 | 160.191.175.187 |
Jan 2, 2025 02:52:31.261398077 CET | 43957 | 51764 | 160.191.175.187 | 192.168.2.23 |
Jan 2, 2025 02:52:32.080945969 CET | 43957 | 51764 | 160.191.175.187 | 192.168.2.23 |
Jan 2, 2025 02:52:32.081043959 CET | 51764 | 43957 | 192.168.2.23 | 160.191.175.187 |
Jan 2, 2025 02:52:32.085905075 CET | 43957 | 51764 | 160.191.175.187 | 192.168.2.23 |
Jan 2, 2025 02:52:33.089726925 CET | 51766 | 43957 | 192.168.2.23 | 160.191.175.187 |
Jan 2, 2025 02:52:33.094605923 CET | 43957 | 51766 | 160.191.175.187 | 192.168.2.23 |
Jan 2, 2025 02:52:33.094686031 CET | 51766 | 43957 | 192.168.2.23 | 160.191.175.187 |
Jan 2, 2025 02:52:33.094729900 CET | 51766 | 43957 | 192.168.2.23 | 160.191.175.187 |
Jan 2, 2025 02:52:33.099456072 CET | 43957 | 51766 | 160.191.175.187 | 192.168.2.23 |
Jan 2, 2025 02:52:33.933235884 CET | 43957 | 51766 | 160.191.175.187 | 192.168.2.23 |
Jan 2, 2025 02:52:33.933408022 CET | 51766 | 43957 | 192.168.2.23 | 160.191.175.187 |
Jan 2, 2025 02:52:33.938251972 CET | 43957 | 51766 | 160.191.175.187 | 192.168.2.23 |
Jan 2, 2025 02:52:36.943564892 CET | 51768 | 43957 | 192.168.2.23 | 160.191.175.187 |
Jan 2, 2025 02:52:36.948312044 CET | 43957 | 51768 | 160.191.175.187 | 192.168.2.23 |
Jan 2, 2025 02:52:36.948359966 CET | 51768 | 43957 | 192.168.2.23 | 160.191.175.187 |
Jan 2, 2025 02:52:36.948371887 CET | 51768 | 43957 | 192.168.2.23 | 160.191.175.187 |
Jan 2, 2025 02:52:36.953190088 CET | 43957 | 51768 | 160.191.175.187 | 192.168.2.23 |
Jan 2, 2025 02:52:37.779728889 CET | 43957 | 51768 | 160.191.175.187 | 192.168.2.23 |
Jan 2, 2025 02:52:37.779835939 CET | 51768 | 43957 | 192.168.2.23 | 160.191.175.187 |
Jan 2, 2025 02:52:37.784632921 CET | 43957 | 51768 | 160.191.175.187 | 192.168.2.23 |
Jan 2, 2025 02:52:44.818279982 CET | 51770 | 43957 | 192.168.2.23 | 160.191.175.187 |
Jan 2, 2025 02:52:44.823122025 CET | 43957 | 51770 | 160.191.175.187 | 192.168.2.23 |
Jan 2, 2025 02:52:44.823189020 CET | 51770 | 43957 | 192.168.2.23 | 160.191.175.187 |
Jan 2, 2025 02:52:44.823225021 CET | 51770 | 43957 | 192.168.2.23 | 160.191.175.187 |
Jan 2, 2025 02:52:44.827971935 CET | 43957 | 51770 | 160.191.175.187 | 192.168.2.23 |
Jan 2, 2025 02:52:45.648361921 CET | 43957 | 51770 | 160.191.175.187 | 192.168.2.23 |
Jan 2, 2025 02:52:45.648509979 CET | 51770 | 43957 | 192.168.2.23 | 160.191.175.187 |
Jan 2, 2025 02:52:45.653367043 CET | 43957 | 51770 | 160.191.175.187 | 192.168.2.23 |
Jan 2, 2025 02:52:52.654113054 CET | 43928 | 443 | 192.168.2.23 | 91.189.91.42 |
Jan 2, 2025 02:52:53.657371998 CET | 51772 | 43957 | 192.168.2.23 | 160.191.175.187 |
Jan 2, 2025 02:52:53.662203074 CET | 43957 | 51772 | 160.191.175.187 | 192.168.2.23 |
Jan 2, 2025 02:52:53.662250996 CET | 51772 | 43957 | 192.168.2.23 | 160.191.175.187 |
Jan 2, 2025 02:52:53.662267923 CET | 51772 | 43957 | 192.168.2.23 | 160.191.175.187 |
Jan 2, 2025 02:52:53.667074919 CET | 43957 | 51772 | 160.191.175.187 | 192.168.2.23 |
Jan 2, 2025 02:52:54.508245945 CET | 43957 | 51772 | 160.191.175.187 | 192.168.2.23 |
Jan 2, 2025 02:52:54.508548021 CET | 51772 | 43957 | 192.168.2.23 | 160.191.175.187 |
Jan 2, 2025 02:52:54.513340950 CET | 43957 | 51772 | 160.191.175.187 | 192.168.2.23 |
Jan 2, 2025 02:53:02.516602993 CET | 51774 | 43957 | 192.168.2.23 | 160.191.175.187 |
Jan 2, 2025 02:53:02.521538973 CET | 43957 | 51774 | 160.191.175.187 | 192.168.2.23 |
Jan 2, 2025 02:53:02.521631956 CET | 51774 | 43957 | 192.168.2.23 | 160.191.175.187 |
Jan 2, 2025 02:53:02.521684885 CET | 51774 | 43957 | 192.168.2.23 | 160.191.175.187 |
Jan 2, 2025 02:53:02.526470900 CET | 43957 | 51774 | 160.191.175.187 | 192.168.2.23 |
Jan 2, 2025 02:53:03.360812902 CET | 43957 | 51774 | 160.191.175.187 | 192.168.2.23 |
Jan 2, 2025 02:53:03.360925913 CET | 51774 | 43957 | 192.168.2.23 | 160.191.175.187 |
Jan 2, 2025 02:53:03.365776062 CET | 43957 | 51774 | 160.191.175.187 | 192.168.2.23 |
Jan 2, 2025 02:53:10.368294001 CET | 51776 | 43957 | 192.168.2.23 | 160.191.175.187 |
Jan 2, 2025 02:53:10.373099089 CET | 43957 | 51776 | 160.191.175.187 | 192.168.2.23 |
Jan 2, 2025 02:53:10.373164892 CET | 51776 | 43957 | 192.168.2.23 | 160.191.175.187 |
Jan 2, 2025 02:53:10.373177052 CET | 51776 | 43957 | 192.168.2.23 | 160.191.175.187 |
Jan 2, 2025 02:53:10.378046989 CET | 43957 | 51776 | 160.191.175.187 | 192.168.2.23 |
Jan 2, 2025 02:53:11.210091114 CET | 43957 | 51776 | 160.191.175.187 | 192.168.2.23 |
Jan 2, 2025 02:53:11.210211039 CET | 51776 | 43957 | 192.168.2.23 | 160.191.175.187 |
Jan 2, 2025 02:53:11.214988947 CET | 43957 | 51776 | 160.191.175.187 | 192.168.2.23 |
Jan 2, 2025 02:53:21.216835976 CET | 51778 | 43957 | 192.168.2.23 | 160.191.175.187 |
Jan 2, 2025 02:53:21.221765995 CET | 43957 | 51778 | 160.191.175.187 | 192.168.2.23 |
Jan 2, 2025 02:53:21.221817017 CET | 51778 | 43957 | 192.168.2.23 | 160.191.175.187 |
Jan 2, 2025 02:53:21.221829891 CET | 51778 | 43957 | 192.168.2.23 | 160.191.175.187 |
Jan 2, 2025 02:53:21.226666927 CET | 43957 | 51778 | 160.191.175.187 | 192.168.2.23 |
Jan 2, 2025 02:53:22.078203917 CET | 43957 | 51778 | 160.191.175.187 | 192.168.2.23 |
Jan 2, 2025 02:53:22.078337908 CET | 51778 | 43957 | 192.168.2.23 | 160.191.175.187 |
Jan 2, 2025 02:53:22.083268881 CET | 43957 | 51778 | 160.191.175.187 | 192.168.2.23 |
Jan 2, 2025 02:53:23.111851931 CET | 51780 | 43957 | 192.168.2.23 | 160.191.175.187 |
Jan 2, 2025 02:53:23.116733074 CET | 43957 | 51780 | 160.191.175.187 | 192.168.2.23 |
Jan 2, 2025 02:53:23.116821051 CET | 51780 | 43957 | 192.168.2.23 | 160.191.175.187 |
Jan 2, 2025 02:53:23.116859913 CET | 51780 | 43957 | 192.168.2.23 | 160.191.175.187 |
Jan 2, 2025 02:53:23.121699095 CET | 43957 | 51780 | 160.191.175.187 | 192.168.2.23 |
Jan 2, 2025 02:53:23.956180096 CET | 43957 | 51780 | 160.191.175.187 | 192.168.2.23 |
Jan 2, 2025 02:53:23.956315994 CET | 51780 | 43957 | 192.168.2.23 | 160.191.175.187 |
Jan 2, 2025 02:53:23.961219072 CET | 43957 | 51780 | 160.191.175.187 | 192.168.2.23 |
Jan 2, 2025 02:53:29.963987112 CET | 51782 | 43957 | 192.168.2.23 | 160.191.175.187 |
Jan 2, 2025 02:53:29.968858957 CET | 43957 | 51782 | 160.191.175.187 | 192.168.2.23 |
Jan 2, 2025 02:53:29.968934059 CET | 51782 | 43957 | 192.168.2.23 | 160.191.175.187 |
Jan 2, 2025 02:53:29.968975067 CET | 51782 | 43957 | 192.168.2.23 | 160.191.175.187 |
Jan 2, 2025 02:53:29.973790884 CET | 43957 | 51782 | 160.191.175.187 | 192.168.2.23 |
Jan 2, 2025 02:53:30.805890083 CET | 43957 | 51782 | 160.191.175.187 | 192.168.2.23 |
Jan 2, 2025 02:53:30.806154013 CET | 51782 | 43957 | 192.168.2.23 | 160.191.175.187 |
Jan 2, 2025 02:53:30.811041117 CET | 43957 | 51782 | 160.191.175.187 | 192.168.2.23 |
Jan 2, 2025 02:53:36.845248938 CET | 51784 | 43957 | 192.168.2.23 | 160.191.175.187 |
Jan 2, 2025 02:53:36.850109100 CET | 43957 | 51784 | 160.191.175.187 | 192.168.2.23 |
Jan 2, 2025 02:53:36.850169897 CET | 51784 | 43957 | 192.168.2.23 | 160.191.175.187 |
Jan 2, 2025 02:53:36.850192070 CET | 51784 | 43957 | 192.168.2.23 | 160.191.175.187 |
Jan 2, 2025 02:53:36.854933977 CET | 43957 | 51784 | 160.191.175.187 | 192.168.2.23 |
Jan 2, 2025 02:53:37.688843966 CET | 43957 | 51784 | 160.191.175.187 | 192.168.2.23 |
Jan 2, 2025 02:53:37.689069033 CET | 51784 | 43957 | 192.168.2.23 | 160.191.175.187 |
Jan 2, 2025 02:53:37.693866014 CET | 43957 | 51784 | 160.191.175.187 | 192.168.2.23 |
Jan 2, 2025 02:53:45.696435928 CET | 51786 | 43957 | 192.168.2.23 | 160.191.175.187 |
Jan 2, 2025 02:53:45.701241970 CET | 43957 | 51786 | 160.191.175.187 | 192.168.2.23 |
Jan 2, 2025 02:53:45.701344967 CET | 51786 | 43957 | 192.168.2.23 | 160.191.175.187 |
Jan 2, 2025 02:53:45.701355934 CET | 51786 | 43957 | 192.168.2.23 | 160.191.175.187 |
Jan 2, 2025 02:53:45.706147909 CET | 43957 | 51786 | 160.191.175.187 | 192.168.2.23 |
Jan 2, 2025 02:53:46.535331964 CET | 43957 | 51786 | 160.191.175.187 | 192.168.2.23 |
Jan 2, 2025 02:53:46.535531044 CET | 51786 | 43957 | 192.168.2.23 | 160.191.175.187 |
Jan 2, 2025 02:53:46.540266991 CET | 43957 | 51786 | 160.191.175.187 | 192.168.2.23 |
Jan 2, 2025 02:53:50.542784929 CET | 51788 | 43957 | 192.168.2.23 | 160.191.175.187 |
Jan 2, 2025 02:53:50.547652960 CET | 43957 | 51788 | 160.191.175.187 | 192.168.2.23 |
Jan 2, 2025 02:53:50.547739029 CET | 51788 | 43957 | 192.168.2.23 | 160.191.175.187 |
Jan 2, 2025 02:53:50.547751904 CET | 51788 | 43957 | 192.168.2.23 | 160.191.175.187 |
Jan 2, 2025 02:53:50.552520037 CET | 43957 | 51788 | 160.191.175.187 | 192.168.2.23 |
Jan 2, 2025 02:53:51.382443905 CET | 43957 | 51788 | 160.191.175.187 | 192.168.2.23 |
Jan 2, 2025 02:53:51.382539034 CET | 51788 | 43957 | 192.168.2.23 | 160.191.175.187 |
Jan 2, 2025 02:53:51.387363911 CET | 43957 | 51788 | 160.191.175.187 | 192.168.2.23 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jan 2, 2025 02:51:49.213238955 CET | 35377 | 53 | 192.168.2.23 | 8.8.8.8 |
Jan 2, 2025 02:51:49.219904900 CET | 53 | 35377 | 8.8.8.8 | 192.168.2.23 |
Jan 2, 2025 02:51:54.065805912 CET | 45741 | 53 | 192.168.2.23 | 8.8.8.8 |
Jan 2, 2025 02:51:54.073899031 CET | 53 | 45741 | 8.8.8.8 | 192.168.2.23 |
Jan 2, 2025 02:52:04.933830023 CET | 38836 | 53 | 192.168.2.23 | 8.8.8.8 |
Jan 2, 2025 02:52:04.941071987 CET | 53 | 38836 | 8.8.8.8 | 192.168.2.23 |
Jan 2, 2025 02:52:08.778594971 CET | 45634 | 53 | 192.168.2.23 | 8.8.8.8 |
Jan 2, 2025 02:52:08.785763979 CET | 53 | 45634 | 8.8.8.8 | 192.168.2.23 |
Jan 2, 2025 02:52:19.641036987 CET | 53686 | 53 | 192.168.2.23 | 8.8.8.8 |
Jan 2, 2025 02:52:19.648040056 CET | 53 | 53686 | 8.8.8.8 | 192.168.2.23 |
Jan 2, 2025 02:52:23.499186993 CET | 42276 | 53 | 192.168.2.23 | 8.8.8.8 |
Jan 2, 2025 02:52:23.507886887 CET | 53 | 42276 | 8.8.8.8 | 192.168.2.23 |
Jan 2, 2025 02:52:27.388950109 CET | 44065 | 53 | 192.168.2.23 | 8.8.8.8 |
Jan 2, 2025 02:52:27.396205902 CET | 53 | 44065 | 8.8.8.8 | 192.168.2.23 |
Jan 2, 2025 02:52:31.244400024 CET | 57158 | 53 | 192.168.2.23 | 8.8.8.8 |
Jan 2, 2025 02:52:31.251554012 CET | 53 | 57158 | 8.8.8.8 | 192.168.2.23 |
Jan 2, 2025 02:52:33.082129002 CET | 40976 | 53 | 192.168.2.23 | 8.8.8.8 |
Jan 2, 2025 02:52:33.089572906 CET | 53 | 40976 | 8.8.8.8 | 192.168.2.23 |
Jan 2, 2025 02:52:36.934222937 CET | 40666 | 53 | 192.168.2.23 | 8.8.8.8 |
Jan 2, 2025 02:52:36.943468094 CET | 53 | 40666 | 8.8.8.8 | 192.168.2.23 |
Jan 2, 2025 02:52:44.779858112 CET | 42446 | 53 | 192.168.2.23 | 8.8.8.8 |
Jan 2, 2025 02:52:44.818166018 CET | 53 | 42446 | 8.8.8.8 | 192.168.2.23 |
Jan 2, 2025 02:52:53.648458004 CET | 45909 | 53 | 192.168.2.23 | 8.8.8.8 |
Jan 2, 2025 02:52:53.657282114 CET | 53 | 45909 | 8.8.8.8 | 192.168.2.23 |
Jan 2, 2025 02:53:02.509002924 CET | 46755 | 53 | 192.168.2.23 | 8.8.8.8 |
Jan 2, 2025 02:53:02.516439915 CET | 53 | 46755 | 8.8.8.8 | 192.168.2.23 |
Jan 2, 2025 02:53:10.361032963 CET | 38707 | 53 | 192.168.2.23 | 8.8.8.8 |
Jan 2, 2025 02:53:10.368201017 CET | 53 | 38707 | 8.8.8.8 | 192.168.2.23 |
Jan 2, 2025 02:53:21.209739923 CET | 50761 | 53 | 192.168.2.23 | 8.8.8.8 |
Jan 2, 2025 02:53:21.216721058 CET | 53 | 50761 | 8.8.8.8 | 192.168.2.23 |
Jan 2, 2025 02:53:23.079066992 CET | 52843 | 53 | 192.168.2.23 | 8.8.8.8 |
Jan 2, 2025 02:53:23.111716986 CET | 53 | 52843 | 8.8.8.8 | 192.168.2.23 |
Jan 2, 2025 02:53:29.956708908 CET | 45538 | 53 | 192.168.2.23 | 8.8.8.8 |
Jan 2, 2025 02:53:29.963814974 CET | 53 | 45538 | 8.8.8.8 | 192.168.2.23 |
Jan 2, 2025 02:53:36.806510925 CET | 48352 | 53 | 192.168.2.23 | 8.8.8.8 |
Jan 2, 2025 02:53:36.845114946 CET | 53 | 48352 | 8.8.8.8 | 192.168.2.23 |
Jan 2, 2025 02:53:45.689078093 CET | 58095 | 53 | 192.168.2.23 | 8.8.8.8 |
Jan 2, 2025 02:53:45.696310043 CET | 53 | 58095 | 8.8.8.8 | 192.168.2.23 |
Jan 2, 2025 02:53:50.536082983 CET | 42175 | 53 | 192.168.2.23 | 8.8.8.8 |
Jan 2, 2025 02:53:50.542668104 CET | 53 | 42175 | 8.8.8.8 | 192.168.2.23 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Jan 2, 2025 02:51:49.213238955 CET | 192.168.2.23 | 8.8.8.8 | 0x4875 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 2, 2025 02:51:54.065805912 CET | 192.168.2.23 | 8.8.8.8 | 0x4a7c | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 2, 2025 02:52:04.933830023 CET | 192.168.2.23 | 8.8.8.8 | 0xe2d0 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 2, 2025 02:52:08.778594971 CET | 192.168.2.23 | 8.8.8.8 | 0xc49f | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 2, 2025 02:52:19.641036987 CET | 192.168.2.23 | 8.8.8.8 | 0x9fd | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 2, 2025 02:52:23.499186993 CET | 192.168.2.23 | 8.8.8.8 | 0x1c9e | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 2, 2025 02:52:27.388950109 CET | 192.168.2.23 | 8.8.8.8 | 0x26a5 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 2, 2025 02:52:31.244400024 CET | 192.168.2.23 | 8.8.8.8 | 0x675d | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 2, 2025 02:52:33.082129002 CET | 192.168.2.23 | 8.8.8.8 | 0xbf33 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 2, 2025 02:52:36.934222937 CET | 192.168.2.23 | 8.8.8.8 | 0xb05e | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 2, 2025 02:52:44.779858112 CET | 192.168.2.23 | 8.8.8.8 | 0x1ed4 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 2, 2025 02:52:53.648458004 CET | 192.168.2.23 | 8.8.8.8 | 0xd83a | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 2, 2025 02:53:02.509002924 CET | 192.168.2.23 | 8.8.8.8 | 0x1e1d | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 2, 2025 02:53:10.361032963 CET | 192.168.2.23 | 8.8.8.8 | 0x4187 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 2, 2025 02:53:21.209739923 CET | 192.168.2.23 | 8.8.8.8 | 0x609d | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 2, 2025 02:53:23.079066992 CET | 192.168.2.23 | 8.8.8.8 | 0x2283 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 2, 2025 02:53:29.956708908 CET | 192.168.2.23 | 8.8.8.8 | 0x538e | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 2, 2025 02:53:36.806510925 CET | 192.168.2.23 | 8.8.8.8 | 0x8c31 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 2, 2025 02:53:45.689078093 CET | 192.168.2.23 | 8.8.8.8 | 0x6bd0 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 2, 2025 02:53:50.536082983 CET | 192.168.2.23 | 8.8.8.8 | 0xb0c6 | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Jan 2, 2025 02:51:49.219904900 CET | 8.8.8.8 | 192.168.2.23 | 0x4875 | No error (0) | 160.191.175.187 | A (IP address) | IN (0x0001) | false | ||
Jan 2, 2025 02:51:54.073899031 CET | 8.8.8.8 | 192.168.2.23 | 0x4a7c | No error (0) | 160.191.175.187 | A (IP address) | IN (0x0001) | false | ||
Jan 2, 2025 02:52:04.941071987 CET | 8.8.8.8 | 192.168.2.23 | 0xe2d0 | No error (0) | 160.191.175.187 | A (IP address) | IN (0x0001) | false | ||
Jan 2, 2025 02:52:08.785763979 CET | 8.8.8.8 | 192.168.2.23 | 0xc49f | No error (0) | 160.191.175.187 | A (IP address) | IN (0x0001) | false | ||
Jan 2, 2025 02:52:19.648040056 CET | 8.8.8.8 | 192.168.2.23 | 0x9fd | No error (0) | 160.191.175.187 | A (IP address) | IN (0x0001) | false | ||
Jan 2, 2025 02:52:23.507886887 CET | 8.8.8.8 | 192.168.2.23 | 0x1c9e | No error (0) | 160.191.175.187 | A (IP address) | IN (0x0001) | false | ||
Jan 2, 2025 02:52:27.396205902 CET | 8.8.8.8 | 192.168.2.23 | 0x26a5 | No error (0) | 160.191.175.187 | A (IP address) | IN (0x0001) | false | ||
Jan 2, 2025 02:52:31.251554012 CET | 8.8.8.8 | 192.168.2.23 | 0x675d | No error (0) | 160.191.175.187 | A (IP address) | IN (0x0001) | false | ||
Jan 2, 2025 02:52:33.089572906 CET | 8.8.8.8 | 192.168.2.23 | 0xbf33 | No error (0) | 160.191.175.187 | A (IP address) | IN (0x0001) | false | ||
Jan 2, 2025 02:52:36.943468094 CET | 8.8.8.8 | 192.168.2.23 | 0xb05e | No error (0) | 160.191.175.187 | A (IP address) | IN (0x0001) | false | ||
Jan 2, 2025 02:52:44.818166018 CET | 8.8.8.8 | 192.168.2.23 | 0x1ed4 | No error (0) | 160.191.175.187 | A (IP address) | IN (0x0001) | false | ||
Jan 2, 2025 02:52:53.657282114 CET | 8.8.8.8 | 192.168.2.23 | 0xd83a | No error (0) | 160.191.175.187 | A (IP address) | IN (0x0001) | false | ||
Jan 2, 2025 02:53:02.516439915 CET | 8.8.8.8 | 192.168.2.23 | 0x1e1d | No error (0) | 160.191.175.187 | A (IP address) | IN (0x0001) | false | ||
Jan 2, 2025 02:53:10.368201017 CET | 8.8.8.8 | 192.168.2.23 | 0x4187 | No error (0) | 160.191.175.187 | A (IP address) | IN (0x0001) | false | ||
Jan 2, 2025 02:53:21.216721058 CET | 8.8.8.8 | 192.168.2.23 | 0x609d | No error (0) | 160.191.175.187 | A (IP address) | IN (0x0001) | false | ||
Jan 2, 2025 02:53:23.111716986 CET | 8.8.8.8 | 192.168.2.23 | 0x2283 | No error (0) | 160.191.175.187 | A (IP address) | IN (0x0001) | false | ||
Jan 2, 2025 02:53:29.963814974 CET | 8.8.8.8 | 192.168.2.23 | 0x538e | No error (0) | 160.191.175.187 | A (IP address) | IN (0x0001) | false | ||
Jan 2, 2025 02:53:36.845114946 CET | 8.8.8.8 | 192.168.2.23 | 0x8c31 | No error (0) | 160.191.175.187 | A (IP address) | IN (0x0001) | false | ||
Jan 2, 2025 02:53:45.696310043 CET | 8.8.8.8 | 192.168.2.23 | 0x6bd0 | No error (0) | 160.191.175.187 | A (IP address) | IN (0x0001) | false | ||
Jan 2, 2025 02:53:50.542668104 CET | 8.8.8.8 | 192.168.2.23 | 0xb0c6 | No error (0) | 160.191.175.187 | A (IP address) | IN (0x0001) | false |
System Behavior
Start time (UTC): | 01:51:48 |
Start date (UTC): | 02/01/2025 |
Path: | /tmp/bot.x86.elf |
Arguments: | /tmp/bot.x86.elf |
File size: | 89576 bytes |
MD5 hash: | dd71487c78fb3cc5ab09c350a01d28f7 |
Start time (UTC): | 01:51:48 |
Start date (UTC): | 02/01/2025 |
Path: | /tmp/bot.x86.elf |
Arguments: | - |
File size: | 89576 bytes |
MD5 hash: | dd71487c78fb3cc5ab09c350a01d28f7 |
Start time (UTC): | 01:51:48 |
Start date (UTC): | 02/01/2025 |
Path: | /tmp/bot.x86.elf |
Arguments: | - |
File size: | 89576 bytes |
MD5 hash: | dd71487c78fb3cc5ab09c350a01d28f7 |