Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
wind.spc.elf

Overview

General Information

Sample name:wind.spc.elf
Analysis ID:1583161
MD5:8f00e22d7347c6ff340fe95cd872f89d
SHA1:21ddad83e72c0300ab1e373845298497e4188efb
SHA256:175467743109e720a36994b63b80f60f8b009c2f8eedea1c8c65de3225223af9
Tags:elfuser-abuse_ch
Infos:

Detection

Mirai
Score:76
Range:0 - 100
Whitelisted:false

Signatures

Antivirus / Scanner detection for submitted sample
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Yara detected Mirai
Sample tries to kill multiple processes (SIGKILL)
Detected TCP or UDP traffic on non-standard ports
Enumerates processes within the "proc" file system
Sample has stripped symbol table
Sample tries to kill a process (SIGKILL)
Uses the "uname" system call to query kernel version information (possible evasion)
Yara signature match

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1583161
Start date and time:2025-01-02 05:25:05 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 5m 26s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:wind.spc.elf
Detection:MAL
Classification:mal76.spre.troj.linELF@0/0@2/0
Command:/tmp/wind.spc.elf
PID:5834
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
lzrd cock fest"/proc/"/exe
Standard Error:
  • system is lnxubuntu20
  • wind.spc.elf (PID: 5834, Parent: 5761, MD5: 7dc1c0e23cd5e102bb12e5c29403410e) Arguments: /tmp/wind.spc.elf
  • wrapper-2.0 (PID: 5844, Parent: 3235, MD5: ac0b8a906f359a8ae102244738682e76) Arguments: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libsystray.so 6 12582920 systray "Notification Area" "Area where notification icons appear"
  • wrapper-2.0 (PID: 5845, Parent: 3235, MD5: ac0b8a906f359a8ae102244738682e76) Arguments: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libstatusnotifier.so 7 12582921 statusnotifier "Status Notifier Plugin" "Provides a panel area for status notifier items (application indicators)"
  • wrapper-2.0 (PID: 5846, Parent: 3235, MD5: ac0b8a906f359a8ae102244738682e76) Arguments: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libpulseaudio-plugin.so 8 12582922 pulseaudio "PulseAudio Plugin" "Adjust the audio volume of the PulseAudio sound system"
  • wrapper-2.0 (PID: 5847, Parent: 3235, MD5: ac0b8a906f359a8ae102244738682e76) Arguments: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libxfce4powermanager.so 9 12582923 power-manager-plugin "Power Manager Plugin" "Display the battery levels of your devices and control the brightness of your display"
  • wrapper-2.0 (PID: 5848, Parent: 3235, MD5: ac0b8a906f359a8ae102244738682e76) Arguments: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libnotification-plugin.so 10 12582924 notification-plugin "Notification Plugin" "Notification plugin for the Xfce panel"
  • wrapper-2.0 (PID: 5849, Parent: 3235, MD5: ac0b8a906f359a8ae102244738682e76) Arguments: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libactions.so 14 12582925 actions "Action Buttons" "Log out, lock or other system actions"
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
MiraiMirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese. Nowadays it targets a wide range of networked embedded devices such as IP cameras, home routers (many vendors involved), and other IoT devices. Since the source code was published on "Hack Forums" many variants of the Mirai family appeared, infecting mostly home networks all around the world.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/elf.mirai
SourceRuleDescriptionAuthorStrings
wind.spc.elfJoeSecurity_Mirai_8Yara detected MiraiJoe Security
    wind.spc.elfLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
    • 0xc958:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xc96c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xc980:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xc994:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xc9a8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xc9bc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xc9d0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xc9e4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xc9f8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xca0c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xca20:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xca34:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xca48:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xca5c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xca70:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xca84:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xca98:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xcaac:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xcac0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xcad4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xcae8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    wind.spc.elfLinux_Trojan_Gafgyt_ea92cca8unknownunknown
    • 0xceb8:$a: 53 65 6C 66 20 52 65 70 20 46 75 63 6B 69 6E 67 20 4E 65 54 69 53 20 61 6E 64
    SourceRuleDescriptionAuthorStrings
    5839.1.00007f5f14011000.00007f5f1401f000.r-x.sdmpJoeSecurity_Mirai_8Yara detected MiraiJoe Security
      5839.1.00007f5f14011000.00007f5f1401f000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
      • 0xc958:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xc96c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xc980:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xc994:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xc9a8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xc9bc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xc9d0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xc9e4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xc9f8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xca0c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xca20:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xca34:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xca48:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xca5c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xca70:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xca84:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xca98:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xcaac:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xcac0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xcad4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xcae8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      5839.1.00007f5f14011000.00007f5f1401f000.r-x.sdmpLinux_Trojan_Gafgyt_ea92cca8unknownunknown
      • 0xceb8:$a: 53 65 6C 66 20 52 65 70 20 46 75 63 6B 69 6E 67 20 4E 65 54 69 53 20 61 6E 64
      5834.1.00007f5f14011000.00007f5f1401f000.r-x.sdmpJoeSecurity_Mirai_8Yara detected MiraiJoe Security
        5834.1.00007f5f14011000.00007f5f1401f000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
        • 0xc958:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0xc96c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0xc980:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0xc994:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0xc9a8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0xc9bc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0xc9d0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0xc9e4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0xc9f8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0xca0c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0xca20:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0xca34:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0xca48:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0xca5c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0xca70:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0xca84:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0xca98:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0xcaac:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0xcac0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0xcad4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0xcae8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        Click to see the 7 entries
        No Suricata rule has matched

        Click to jump to signature section

        Show All Signature Results

        AV Detection

        barindex
        Source: wind.spc.elfAvira: detected
        Source: wind.spc.elfReversingLabs: Detection: 65%
        Source: wind.spc.elfVirustotal: Detection: 63%Perma Link
        Source: global trafficTCP traffic: 192.168.2.15:57914 -> 45.95.169.120:3778
        Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
        Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
        Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
        Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
        Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
        Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
        Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
        Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
        Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
        Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
        Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
        Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
        Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
        Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
        Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
        Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
        Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
        Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
        Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
        Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
        Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
        Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
        Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
        Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
        Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
        Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
        Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
        Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
        Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
        Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
        Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
        Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
        Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
        Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
        Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
        Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
        Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
        Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
        Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
        Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
        Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
        Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
        Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
        Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
        Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
        Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
        Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
        Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
        Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
        Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
        Source: global trafficDNS traffic detected: DNS query: daisy.ubuntu.com

        System Summary

        barindex
        Source: wind.spc.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
        Source: wind.spc.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown
        Source: 5839.1.00007f5f14011000.00007f5f1401f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
        Source: 5839.1.00007f5f14011000.00007f5f1401f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown
        Source: 5834.1.00007f5f14011000.00007f5f1401f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
        Source: 5834.1.00007f5f14011000.00007f5f1401f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown
        Source: Process Memory Space: wind.spc.elf PID: 5834, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
        Source: Process Memory Space: wind.spc.elf PID: 5834, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown
        Source: Process Memory Space: wind.spc.elf PID: 5839, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
        Source: Process Memory Space: wind.spc.elf PID: 5839, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown
        Source: /tmp/wind.spc.elf (PID: 5837)SIGKILL sent: pid: 3192, result: successfulJump to behavior
        Source: /tmp/wind.spc.elf (PID: 5837)SIGKILL sent: pid: 3249, result: successfulJump to behavior
        Source: /tmp/wind.spc.elf (PID: 5837)SIGKILL sent: pid: 3250, result: successfulJump to behavior
        Source: /tmp/wind.spc.elf (PID: 5837)SIGKILL sent: pid: 3251, result: successfulJump to behavior
        Source: /tmp/wind.spc.elf (PID: 5837)SIGKILL sent: pid: 3252, result: successfulJump to behavior
        Source: /tmp/wind.spc.elf (PID: 5837)SIGKILL sent: pid: 3253, result: successfulJump to behavior
        Source: /tmp/wind.spc.elf (PID: 5837)SIGKILL sent: pid: 3255, result: successfulJump to behavior
        Source: /tmp/wind.spc.elf (PID: 5837)SIGKILL sent: pid: 3272, result: successfulJump to behavior
        Source: /tmp/wind.spc.elf (PID: 5837)SIGKILL sent: pid: 3274, result: successfulJump to behavior
        Source: /tmp/wind.spc.elf (PID: 5837)SIGKILL sent: pid: 3298, result: successfulJump to behavior
        Source: /tmp/wind.spc.elf (PID: 5837)SIGKILL sent: pid: 5844, result: successfulJump to behavior
        Source: /tmp/wind.spc.elf (PID: 5837)SIGKILL sent: pid: 5845, result: successfulJump to behavior
        Source: /tmp/wind.spc.elf (PID: 5837)SIGKILL sent: pid: 5846, result: successfulJump to behavior
        Source: /tmp/wind.spc.elf (PID: 5837)SIGKILL sent: pid: 5847, result: successfulJump to behavior
        Source: /tmp/wind.spc.elf (PID: 5837)SIGKILL sent: pid: 5848, result: successfulJump to behavior
        Source: /tmp/wind.spc.elf (PID: 5837)SIGKILL sent: pid: 5849, result: successfulJump to behavior
        Source: ELF static info symbol of initial sample.symtab present: no
        Source: /tmp/wind.spc.elf (PID: 5837)SIGKILL sent: pid: 3192, result: successfulJump to behavior
        Source: /tmp/wind.spc.elf (PID: 5837)SIGKILL sent: pid: 3249, result: successfulJump to behavior
        Source: /tmp/wind.spc.elf (PID: 5837)SIGKILL sent: pid: 3250, result: successfulJump to behavior
        Source: /tmp/wind.spc.elf (PID: 5837)SIGKILL sent: pid: 3251, result: successfulJump to behavior
        Source: /tmp/wind.spc.elf (PID: 5837)SIGKILL sent: pid: 3252, result: successfulJump to behavior
        Source: /tmp/wind.spc.elf (PID: 5837)SIGKILL sent: pid: 3253, result: successfulJump to behavior
        Source: /tmp/wind.spc.elf (PID: 5837)SIGKILL sent: pid: 3255, result: successfulJump to behavior
        Source: /tmp/wind.spc.elf (PID: 5837)SIGKILL sent: pid: 3272, result: successfulJump to behavior
        Source: /tmp/wind.spc.elf (PID: 5837)SIGKILL sent: pid: 3274, result: successfulJump to behavior
        Source: /tmp/wind.spc.elf (PID: 5837)SIGKILL sent: pid: 3298, result: successfulJump to behavior
        Source: /tmp/wind.spc.elf (PID: 5837)SIGKILL sent: pid: 5844, result: successfulJump to behavior
        Source: /tmp/wind.spc.elf (PID: 5837)SIGKILL sent: pid: 5845, result: successfulJump to behavior
        Source: /tmp/wind.spc.elf (PID: 5837)SIGKILL sent: pid: 5846, result: successfulJump to behavior
        Source: /tmp/wind.spc.elf (PID: 5837)SIGKILL sent: pid: 5847, result: successfulJump to behavior
        Source: /tmp/wind.spc.elf (PID: 5837)SIGKILL sent: pid: 5848, result: successfulJump to behavior
        Source: /tmp/wind.spc.elf (PID: 5837)SIGKILL sent: pid: 5849, result: successfulJump to behavior
        Source: wind.spc.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
        Source: wind.spc.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16
        Source: 5839.1.00007f5f14011000.00007f5f1401f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
        Source: 5839.1.00007f5f14011000.00007f5f1401f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16
        Source: 5834.1.00007f5f14011000.00007f5f1401f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
        Source: 5834.1.00007f5f14011000.00007f5f1401f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16
        Source: Process Memory Space: wind.spc.elf PID: 5834, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
        Source: Process Memory Space: wind.spc.elf PID: 5834, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16
        Source: Process Memory Space: wind.spc.elf PID: 5839, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
        Source: Process Memory Space: wind.spc.elf PID: 5839, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16
        Source: classification engineClassification label: mal76.spre.troj.linELF@0/0@2/0
        Source: /tmp/wind.spc.elf (PID: 5837)File opened: /proc/5783/cmdlineJump to behavior
        Source: /tmp/wind.spc.elf (PID: 5837)File opened: /proc/1185/cmdlineJump to behavior
        Source: /tmp/wind.spc.elf (PID: 5837)File opened: /proc/3241/cmdlineJump to behavior
        Source: /tmp/wind.spc.elf (PID: 5837)File opened: /proc/3483/cmdlineJump to behavior
        Source: /tmp/wind.spc.elf (PID: 5837)File opened: /proc/1732/cmdlineJump to behavior
        Source: /tmp/wind.spc.elf (PID: 5837)File opened: /proc/1730/cmdlineJump to behavior
        Source: /tmp/wind.spc.elf (PID: 5837)File opened: /proc/1333/cmdlineJump to behavior
        Source: /tmp/wind.spc.elf (PID: 5837)File opened: /proc/1695/cmdlineJump to behavior
        Source: /tmp/wind.spc.elf (PID: 5837)File opened: /proc/3235/cmdlineJump to behavior
        Source: /tmp/wind.spc.elf (PID: 5837)File opened: /proc/3234/cmdlineJump to behavior
        Source: /tmp/wind.spc.elf (PID: 5837)File opened: /proc/911/cmdlineJump to behavior
        Source: /tmp/wind.spc.elf (PID: 5837)File opened: /proc/515/cmdlineJump to behavior
        Source: /tmp/wind.spc.elf (PID: 5837)File opened: /proc/914/cmdlineJump to behavior
        Source: /tmp/wind.spc.elf (PID: 5837)File opened: /proc/1617/cmdlineJump to behavior
        Source: /tmp/wind.spc.elf (PID: 5837)File opened: /proc/1615/cmdlineJump to behavior
        Source: /tmp/wind.spc.elf (PID: 5837)File opened: /proc/917/cmdlineJump to behavior
        Source: /tmp/wind.spc.elf (PID: 5837)File opened: /proc/3255/cmdlineJump to behavior
        Source: /tmp/wind.spc.elf (PID: 5837)File opened: /proc/3253/cmdlineJump to behavior
        Source: /tmp/wind.spc.elf (PID: 5837)File opened: /proc/1591/cmdlineJump to behavior
        Source: /tmp/wind.spc.elf (PID: 5837)File opened: /proc/3252/cmdlineJump to behavior
        Source: /tmp/wind.spc.elf (PID: 5837)File opened: /proc/3251/cmdlineJump to behavior
        Source: /tmp/wind.spc.elf (PID: 5837)File opened: /proc/3250/cmdlineJump to behavior
        Source: /tmp/wind.spc.elf (PID: 5837)File opened: /proc/4181/cmdlineJump to behavior
        Source: /tmp/wind.spc.elf (PID: 5837)File opened: /proc/1623/cmdlineJump to behavior
        Source: /tmp/wind.spc.elf (PID: 5837)File opened: /proc/1588/cmdlineJump to behavior
        Source: /tmp/wind.spc.elf (PID: 5837)File opened: /proc/3249/cmdlineJump to behavior
        Source: /tmp/wind.spc.elf (PID: 5837)File opened: /proc/764/cmdlineJump to behavior
        Source: /tmp/wind.spc.elf (PID: 5837)File opened: /proc/3368/cmdlineJump to behavior
        Source: /tmp/wind.spc.elf (PID: 5837)File opened: /proc/1585/cmdlineJump to behavior
        Source: /tmp/wind.spc.elf (PID: 5837)File opened: /proc/3246/cmdlineJump to behavior
        Source: /tmp/wind.spc.elf (PID: 5837)File opened: /proc/3488/cmdlineJump to behavior
        Source: /tmp/wind.spc.elf (PID: 5837)File opened: /proc/766/cmdlineJump to behavior
        Source: /tmp/wind.spc.elf (PID: 5837)File opened: /proc/800/cmdlineJump to behavior
        Source: /tmp/wind.spc.elf (PID: 5837)File opened: /proc/888/cmdlineJump to behavior
        Source: /tmp/wind.spc.elf (PID: 5837)File opened: /proc/5820/cmdlineJump to behavior
        Source: /tmp/wind.spc.elf (PID: 5837)File opened: /proc/802/cmdlineJump to behavior
        Source: /tmp/wind.spc.elf (PID: 5837)File opened: /proc/1509/cmdlineJump to behavior
        Source: /tmp/wind.spc.elf (PID: 5837)File opened: /proc/5821/cmdlineJump to behavior
        Source: /tmp/wind.spc.elf (PID: 5837)File opened: /proc/803/cmdlineJump to behavior
        Source: /tmp/wind.spc.elf (PID: 5837)File opened: /proc/804/cmdlineJump to behavior
        Source: /tmp/wind.spc.elf (PID: 5837)File opened: /proc/3800/cmdlineJump to behavior
        Source: /tmp/wind.spc.elf (PID: 5837)File opened: /proc/3801/cmdlineJump to behavior
        Source: /tmp/wind.spc.elf (PID: 5837)File opened: /proc/1867/cmdlineJump to behavior
        Source: /tmp/wind.spc.elf (PID: 5837)File opened: /proc/3407/cmdlineJump to behavior
        Source: /tmp/wind.spc.elf (PID: 5837)File opened: /proc/5840/cmdlineJump to behavior
        Source: /tmp/wind.spc.elf (PID: 5837)File opened: /proc/1484/cmdlineJump to behavior
        Source: /tmp/wind.spc.elf (PID: 5837)File opened: /proc/490/cmdlineJump to behavior
        Source: /tmp/wind.spc.elf (PID: 5837)File opened: /proc/1514/cmdlineJump to behavior
        Source: /tmp/wind.spc.elf (PID: 5837)File opened: /proc/1634/cmdlineJump to behavior
        Source: /tmp/wind.spc.elf (PID: 5837)File opened: /proc/1479/cmdlineJump to behavior
        Source: /tmp/wind.spc.elf (PID: 5837)File opened: /proc/1875/cmdlineJump to behavior
        Source: /tmp/wind.spc.elf (PID: 5837)File opened: /proc/654/cmdlineJump to behavior
        Source: /tmp/wind.spc.elf (PID: 5837)File opened: /proc/3379/cmdlineJump to behavior
        Source: /tmp/wind.spc.elf (PID: 5837)File opened: /proc/655/cmdlineJump to behavior
        Source: /tmp/wind.spc.elf (PID: 5837)File opened: /proc/656/cmdlineJump to behavior
        Source: /tmp/wind.spc.elf (PID: 5837)File opened: /proc/777/cmdlineJump to behavior
        Source: /tmp/wind.spc.elf (PID: 5837)File opened: /proc/931/cmdlineJump to behavior
        Source: /tmp/wind.spc.elf (PID: 5837)File opened: /proc/1595/cmdlineJump to behavior
        Source: /tmp/wind.spc.elf (PID: 5837)File opened: /proc/657/cmdlineJump to behavior
        Source: /tmp/wind.spc.elf (PID: 5837)File opened: /proc/812/cmdlineJump to behavior
        Source: /tmp/wind.spc.elf (PID: 5837)File opened: /proc/779/cmdlineJump to behavior
        Source: /tmp/wind.spc.elf (PID: 5837)File opened: /proc/658/cmdlineJump to behavior
        Source: /tmp/wind.spc.elf (PID: 5837)File opened: /proc/933/cmdlineJump to behavior
        Source: /tmp/wind.spc.elf (PID: 5837)File opened: /proc/5678/cmdlineJump to behavior
        Source: /tmp/wind.spc.elf (PID: 5837)File opened: /proc/418/cmdlineJump to behavior
        Source: /tmp/wind.spc.elf (PID: 5837)File opened: /proc/419/cmdlineJump to behavior
        Source: /tmp/wind.spc.elf (PID: 5837)File opened: /proc/3419/cmdlineJump to behavior
        Source: /tmp/wind.spc.elf (PID: 5837)File opened: /proc/3310/cmdlineJump to behavior
        Source: /tmp/wind.spc.elf (PID: 5837)File opened: /proc/3275/cmdlineJump to behavior
        Source: /tmp/wind.spc.elf (PID: 5837)File opened: /proc/3274/cmdlineJump to behavior
        Source: /tmp/wind.spc.elf (PID: 5837)File opened: /proc/3273/cmdlineJump to behavior
        Source: /tmp/wind.spc.elf (PID: 5837)File opened: /proc/3394/cmdlineJump to behavior
        Source: /tmp/wind.spc.elf (PID: 5837)File opened: /proc/3272/cmdlineJump to behavior
        Source: /tmp/wind.spc.elf (PID: 5837)File opened: /proc/5849/cmdlineJump to behavior
        Source: /tmp/wind.spc.elf (PID: 5837)File opened: /proc/782/cmdlineJump to behavior
        Source: /tmp/wind.spc.elf (PID: 5837)File opened: /proc/3303/cmdlineJump to behavior
        Source: /tmp/wind.spc.elf (PID: 5837)File opened: /proc/1762/cmdlineJump to behavior
        Source: /tmp/wind.spc.elf (PID: 5837)File opened: /proc/3027/cmdlineJump to behavior
        Source: /tmp/wind.spc.elf (PID: 5837)File opened: /proc/1486/cmdlineJump to behavior
        Source: /tmp/wind.spc.elf (PID: 5837)File opened: /proc/789/cmdlineJump to behavior
        Source: /tmp/wind.spc.elf (PID: 5837)File opened: /proc/1806/cmdlineJump to behavior
        Source: /tmp/wind.spc.elf (PID: 5837)File opened: /proc/5844/cmdlineJump to behavior
        Source: /tmp/wind.spc.elf (PID: 5837)File opened: /proc/5845/cmdlineJump to behavior
        Source: /tmp/wind.spc.elf (PID: 5837)File opened: /proc/3701/cmdlineJump to behavior
        Source: /tmp/wind.spc.elf (PID: 5837)File opened: /proc/5846/cmdlineJump to behavior
        Source: /tmp/wind.spc.elf (PID: 5837)File opened: /proc/5847/cmdlineJump to behavior
        Source: /tmp/wind.spc.elf (PID: 5837)File opened: /proc/5848/cmdlineJump to behavior
        Source: /tmp/wind.spc.elf (PID: 5837)File opened: /proc/1660/cmdlineJump to behavior
        Source: /tmp/wind.spc.elf (PID: 5837)File opened: /proc/3440/cmdlineJump to behavior
        Source: /tmp/wind.spc.elf (PID: 5837)File opened: /proc/793/cmdlineJump to behavior
        Source: /tmp/wind.spc.elf (PID: 5837)File opened: /proc/794/cmdlineJump to behavior
        Source: /tmp/wind.spc.elf (PID: 5837)File opened: /proc/3316/cmdlineJump to behavior
        Source: /tmp/wind.spc.elf (PID: 5837)File opened: /proc/674/cmdlineJump to behavior
        Source: /tmp/wind.spc.elf (PID: 5837)File opened: /proc/796/cmdlineJump to behavior
        Source: /tmp/wind.spc.elf (PID: 5837)File opened: /proc/675/cmdlineJump to behavior
        Source: /tmp/wind.spc.elf (PID: 5837)File opened: /proc/676/cmdlineJump to behavior
        Source: /tmp/wind.spc.elf (PID: 5837)File opened: /proc/1498/cmdlineJump to behavior
        Source: /tmp/wind.spc.elf (PID: 5837)File opened: /proc/1497/cmdlineJump to behavior
        Source: /tmp/wind.spc.elf (PID: 5837)File opened: /proc/1496/cmdlineJump to behavior
        Source: /tmp/wind.spc.elf (PID: 5837)File opened: /proc/3157/cmdlineJump to behavior
        Source: /tmp/wind.spc.elf (PID: 5837)File opened: /proc/3278/cmdlineJump to behavior
        Source: /tmp/wind.spc.elf (PID: 5837)File opened: /proc/3399/cmdlineJump to behavior
        Source: /tmp/wind.spc.elf (PID: 5837)File opened: /proc/3798/cmdlineJump to behavior
        Source: /tmp/wind.spc.elf (PID: 5837)File opened: /proc/3799/cmdlineJump to behavior
        Source: /tmp/wind.spc.elf (PID: 5837)File opened: /proc/1659/cmdlineJump to behavior
        Source: /tmp/wind.spc.elf (PID: 5834)Queries kernel information via 'uname': Jump to behavior
        Source: wind.spc.elf, 5834.1.000055fea8bce000.000055fea8c53000.rw-.sdmp, wind.spc.elf, 5839.1.000055fea8bce000.000055fea8c53000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/sparc
        Source: wind.spc.elf, 5834.1.000055fea8bce000.000055fea8c53000.rw-.sdmp, wind.spc.elf, 5839.1.000055fea8bce000.000055fea8c53000.rw-.sdmpBinary or memory string: U!/etc/qemu-binfmt/sparc
        Source: wind.spc.elf, 5834.1.00007fffad26f000.00007fffad290000.rw-.sdmp, wind.spc.elf, 5839.1.00007fffad26f000.00007fffad290000.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-sparc/tmp/wind.spc.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/wind.spc.elf
        Source: wind.spc.elf, 5834.1.00007fffad26f000.00007fffad290000.rw-.sdmp, wind.spc.elf, 5839.1.00007fffad26f000.00007fffad290000.rw-.sdmpBinary or memory string: /usr/bin/qemu-sparc

        Stealing of Sensitive Information

        barindex
        Source: Yara matchFile source: wind.spc.elf, type: SAMPLE
        Source: Yara matchFile source: 5839.1.00007f5f14011000.00007f5f1401f000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 5834.1.00007f5f14011000.00007f5f1401f000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: Process Memory Space: wind.spc.elf PID: 5834, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: wind.spc.elf PID: 5839, type: MEMORYSTR

        Remote Access Functionality

        barindex
        Source: Yara matchFile source: wind.spc.elf, type: SAMPLE
        Source: Yara matchFile source: 5839.1.00007f5f14011000.00007f5f1401f000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 5834.1.00007f5f14011000.00007f5f1401f000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: Process Memory Space: wind.spc.elf PID: 5834, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: wind.spc.elf PID: 5839, type: MEMORYSTR
        ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
        Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath InterceptionDirect Volume Access1
        OS Credential Dumping
        11
        Security Software Discovery
        Remote ServicesData from Local System1
        Non-Standard Port
        Exfiltration Over Other Network Medium1
        Service Stop
        CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
        Non-Application Layer Protocol
        Exfiltration Over BluetoothNetwork Denial of Service
        Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
        Application Layer Protocol
        Automated ExfiltrationData Encrypted for Impact
        No configs have been found
        Hide Legend

        Legend:

        • Process
        • Signature
        • Created File
        • DNS/IP Info
        • Is Dropped
        • Number of created Files
        • Is malicious
        • Internet
        behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1583161 Sample: wind.spc.elf Startdate: 02/01/2025 Architecture: LINUX Score: 76 22 45.95.169.120, 3778, 57914, 57916 GIGANET-HUGigaNetInternetServiceProviderCoHU Croatia (LOCAL Name: Hrvatska) 2->22 24 daisy.ubuntu.com 2->24 26 Malicious sample detected (through community Yara rule) 2->26 28 Antivirus / Scanner detection for submitted sample 2->28 30 Multi AV Scanner detection for submitted file 2->30 32 Yara detected Mirai 2->32 7 wind.spc.elf 2->7         started        9 xfce4-panel wrapper-2.0 2->9         started        11 xfce4-panel wrapper-2.0 2->11         started        13 4 other processes 2->13 signatures3 process4 process5 15 wind.spc.elf 7->15         started        18 wind.spc.elf 7->18         started        20 wind.spc.elf 7->20         started        signatures6 34 Sample tries to kill multiple processes (SIGKILL) 15->34

        This section contains all screenshots as thumbnails, including those not shown in the slideshow.


        windows-stand
        SourceDetectionScannerLabelLink
        wind.spc.elf66%ReversingLabsLinux.Backdoor.Mirai
        wind.spc.elf63%VirustotalBrowse
        wind.spc.elf100%AviraEXP/ELF.Gafgyt.D
        No Antivirus matches
        No Antivirus matches
        No Antivirus matches
        NameIPActiveMaliciousAntivirus DetectionReputation
        daisy.ubuntu.com
        162.213.35.25
        truefalse
          high
          • No. of IPs < 25%
          • 25% < No. of IPs < 50%
          • 50% < No. of IPs < 75%
          • 75% < No. of IPs
          IPDomainCountryFlagASNASN NameMalicious
          45.95.169.120
          unknownCroatia (LOCAL Name: Hrvatska)
          42864GIGANET-HUGigaNetInternetServiceProviderCoHUfalse
          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
          45.95.169.120wind.mpsl.elfGet hashmaliciousMiraiBrowse
            wind.arm7.elfGet hashmaliciousMiraiBrowse
              m68k.elfGet hashmaliciousMiraiBrowse
                arm.elfGet hashmaliciousMiraiBrowse
                  x86.elfGet hashmaliciousMiraiBrowse
                    45.95.169.120-mips-2025-01-02T00_17_36.elfGet hashmaliciousMiraiBrowse
                      qlmOM0y98BGet hashmaliciousUnknownBrowse
                        3tgXa7CGc1Get hashmaliciousUnknownBrowse
                          rijsTqU0IfGet hashmaliciousUnknownBrowse
                            csB31kWt10Get hashmaliciousUnknownBrowse
                              MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                              daisy.ubuntu.comwind.mpsl.elfGet hashmaliciousMiraiBrowse
                              • 162.213.35.25
                              wind.arm7.elfGet hashmaliciousMiraiBrowse
                              • 162.213.35.24
                              arm.elfGet hashmaliciousMiraiBrowse
                              • 162.213.35.24
                              i.elfGet hashmaliciousUnknownBrowse
                              • 162.213.35.25
                              loligang.arm6.elfGet hashmaliciousMiraiBrowse
                              • 162.213.35.24
                              loligang.arm5.elfGet hashmaliciousMiraiBrowse
                              • 162.213.35.24
                              B_Y_T_E_x86.elfGet hashmaliciousMirai, OkiruBrowse
                              • 162.213.35.25
                              main_x86_64.elfGet hashmaliciousGafgyt, Mirai, OkiruBrowse
                              • 162.213.35.25
                              89.250.72.36-mips-2024-12-31T13_33_10.elfGet hashmaliciousGafgytBrowse
                              • 162.213.35.24
                              boatnet.mpsl.elfGet hashmaliciousMiraiBrowse
                              • 162.213.35.24
                              MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                              GIGANET-HUGigaNetInternetServiceProviderCoHUwind.mpsl.elfGet hashmaliciousMiraiBrowse
                              • 45.95.169.120
                              wind.arm7.elfGet hashmaliciousMiraiBrowse
                              • 45.95.169.120
                              m68k.elfGet hashmaliciousMiraiBrowse
                              • 45.95.169.120
                              arm.elfGet hashmaliciousMiraiBrowse
                              • 45.95.169.120
                              x86.elfGet hashmaliciousMiraiBrowse
                              • 45.95.169.120
                              45.95.169.120-mips-2025-01-02T00_17_36.elfGet hashmaliciousMiraiBrowse
                              • 45.95.169.120
                              x86_64.nn.elfGet hashmaliciousMirai, OkiruBrowse
                              • 92.52.211.236
                              bin.i586.elfGet hashmaliciousGafgyt, MiraiBrowse
                              • 88.209.217.191
                              la.bot.m68k.elfGet hashmaliciousUnknownBrowse
                              • 5.180.123.145
                              IsopYwsaG5.elfGet hashmaliciousUnknownBrowse
                              • 45.95.169.122
                              No context
                              No context
                              No created / dropped files found
                              File type:ELF 32-bit MSB executable, SPARC, version 1 (SYSV), statically linked, stripped
                              Entropy (8bit):6.0664193078609525
                              TrID:
                              • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                              File name:wind.spc.elf
                              File size:58'376 bytes
                              MD5:8f00e22d7347c6ff340fe95cd872f89d
                              SHA1:21ddad83e72c0300ab1e373845298497e4188efb
                              SHA256:175467743109e720a36994b63b80f60f8b009c2f8eedea1c8c65de3225223af9
                              SHA512:d4da2fb2c793c265670a02f6c6537e472eebf9dcacaae11b1ed1cc5dc5355c04b142d80734460748cf7f9183a425e938a505e0e152f1c4eed5e17687e5c45367
                              SSDEEP:768:RqowmZPu9wtnfbltWgC6BSJsBcfDSTFIuQKqgESnmC/xO+KpAwU:RqtmZPuutfbltZFBSJsBcfDSTFI+BEU
                              TLSH:68432921B63A1F13D0E0A47D21FB4B59B1A15ADE26A4C64E7D720F4FFF11680A943DB8
                              File Content Preview:.ELF...........................4...x.....4. ...(.......................................................8...P........dt.Q................................@..(....@.2.................#.....b8..`.....!..... ...@.....".........`......$ ... ...@...........`....

                              ELF header

                              Class:ELF32
                              Data:2's complement, big endian
                              Version:1 (current)
                              Machine:Sparc
                              Version Number:0x1
                              Type:EXEC (Executable file)
                              OS/ABI:UNIX - System V
                              ABI Version:0
                              Entry Point Address:0x101a4
                              Flags:0x0
                              ELF Header Size:52
                              Program Header Offset:52
                              Program Header Size:32
                              Number of Program Headers:3
                              Section Header Offset:57976
                              Section Header Size:40
                              Number of Section Headers:10
                              Header String Table Index:9
                              NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                              NULL0x00x00x00x00x0000
                              .initPROGBITS0x100940x940x1c0x00x6AX004
                              .textPROGBITS0x100b00xb00xc8880x00x6AX004
                              .finiPROGBITS0x1c9380xc9380x140x00x6AX004
                              .rodataPROGBITS0x1c9500xc9500x11b00x00x2A008
                              .ctorsPROGBITS0x2e0000xe0000x80x00x3WA004
                              .dtorsPROGBITS0x2e0080xe0080x80x00x3WA004
                              .dataPROGBITS0x2e0180xe0180x2200x00x3WA008
                              .bssNOBITS0x2e2380xe2380x3180x00x3WA004
                              .shstrtabSTRTAB0x00xe2380x3e0x00x0001
                              TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                              LOAD0x00x100000x100000xdb000xdb006.17290x5R E0x10000.init .text .fini .rodata
                              LOAD0xe0000x2e0000x2e0000x2380x5502.92290x6RW 0x10000.ctors .dtors .data .bss
                              GNU_STACK0x00x00x00x00x00.00000x6RW 0x4
                              TimestampSource PortDest PortSource IPDest IP
                              Jan 2, 2025 05:26:20.950009108 CET579143778192.168.2.1545.95.169.120
                              Jan 2, 2025 05:26:20.954932928 CET37785791445.95.169.120192.168.2.15
                              Jan 2, 2025 05:26:20.954987049 CET579143778192.168.2.1545.95.169.120
                              Jan 2, 2025 05:26:20.975811958 CET579143778192.168.2.1545.95.169.120
                              Jan 2, 2025 05:26:20.980647087 CET37785791445.95.169.120192.168.2.15
                              Jan 2, 2025 05:26:20.980680943 CET579143778192.168.2.1545.95.169.120
                              Jan 2, 2025 05:26:20.985502005 CET37785791445.95.169.120192.168.2.15
                              Jan 2, 2025 05:26:21.602365971 CET37785791445.95.169.120192.168.2.15
                              Jan 2, 2025 05:26:21.602427006 CET579143778192.168.2.1545.95.169.120
                              Jan 2, 2025 05:26:21.602607965 CET579143778192.168.2.1545.95.169.120
                              Jan 2, 2025 05:26:21.636461973 CET579163778192.168.2.1545.95.169.120
                              Jan 2, 2025 05:26:21.641346931 CET37785791645.95.169.120192.168.2.15
                              Jan 2, 2025 05:26:21.641673088 CET579163778192.168.2.1545.95.169.120
                              Jan 2, 2025 05:26:21.648077011 CET579163778192.168.2.1545.95.169.120
                              Jan 2, 2025 05:26:21.652808905 CET37785791645.95.169.120192.168.2.15
                              Jan 2, 2025 05:26:21.652868986 CET579163778192.168.2.1545.95.169.120
                              Jan 2, 2025 05:26:21.657706976 CET37785791645.95.169.120192.168.2.15
                              Jan 2, 2025 05:26:22.307671070 CET37785791645.95.169.120192.168.2.15
                              Jan 2, 2025 05:26:22.307790995 CET579163778192.168.2.1545.95.169.120
                              Jan 2, 2025 05:26:22.307790995 CET579163778192.168.2.1545.95.169.120
                              Jan 2, 2025 05:26:22.308763981 CET579183778192.168.2.1545.95.169.120
                              Jan 2, 2025 05:26:22.313601017 CET37785791845.95.169.120192.168.2.15
                              Jan 2, 2025 05:26:22.313656092 CET579183778192.168.2.1545.95.169.120
                              Jan 2, 2025 05:26:22.315112114 CET579183778192.168.2.1545.95.169.120
                              Jan 2, 2025 05:26:22.319935083 CET37785791845.95.169.120192.168.2.15
                              Jan 2, 2025 05:26:22.319983006 CET579183778192.168.2.1545.95.169.120
                              Jan 2, 2025 05:26:22.324839115 CET37785791845.95.169.120192.168.2.15
                              Jan 2, 2025 05:26:22.987725973 CET37785791845.95.169.120192.168.2.15
                              Jan 2, 2025 05:26:22.987783909 CET579183778192.168.2.1545.95.169.120
                              Jan 2, 2025 05:26:22.987833977 CET579183778192.168.2.1545.95.169.120
                              Jan 2, 2025 05:26:23.033693075 CET579203778192.168.2.1545.95.169.120
                              Jan 2, 2025 05:26:23.038542032 CET37785792045.95.169.120192.168.2.15
                              Jan 2, 2025 05:26:23.038592100 CET579203778192.168.2.1545.95.169.120
                              Jan 2, 2025 05:26:23.095658064 CET579203778192.168.2.1545.95.169.120
                              Jan 2, 2025 05:26:23.100461960 CET37785792045.95.169.120192.168.2.15
                              Jan 2, 2025 05:26:23.100506067 CET579203778192.168.2.1545.95.169.120
                              Jan 2, 2025 05:26:23.105267048 CET37785792045.95.169.120192.168.2.15
                              Jan 2, 2025 05:26:23.684323072 CET37785792045.95.169.120192.168.2.15
                              Jan 2, 2025 05:26:23.684374094 CET579203778192.168.2.1545.95.169.120
                              Jan 2, 2025 05:26:23.684416056 CET579203778192.168.2.1545.95.169.120
                              Jan 2, 2025 05:26:23.685201883 CET579223778192.168.2.1545.95.169.120
                              Jan 2, 2025 05:26:23.689976931 CET37785792245.95.169.120192.168.2.15
                              Jan 2, 2025 05:26:23.690071106 CET579223778192.168.2.1545.95.169.120
                              Jan 2, 2025 05:26:23.691783905 CET579223778192.168.2.1545.95.169.120
                              Jan 2, 2025 05:26:23.705439091 CET37785792245.95.169.120192.168.2.15
                              Jan 2, 2025 05:26:23.705485106 CET579223778192.168.2.1545.95.169.120
                              Jan 2, 2025 05:26:23.710258961 CET37785792245.95.169.120192.168.2.15
                              Jan 2, 2025 05:26:24.358453035 CET37785792245.95.169.120192.168.2.15
                              Jan 2, 2025 05:26:24.358561993 CET579223778192.168.2.1545.95.169.120
                              Jan 2, 2025 05:26:24.358561993 CET579223778192.168.2.1545.95.169.120
                              Jan 2, 2025 05:26:24.359707117 CET579243778192.168.2.1545.95.169.120
                              Jan 2, 2025 05:26:24.364573956 CET37785792445.95.169.120192.168.2.15
                              Jan 2, 2025 05:26:24.364625931 CET579243778192.168.2.1545.95.169.120
                              Jan 2, 2025 05:26:24.367166996 CET579243778192.168.2.1545.95.169.120
                              Jan 2, 2025 05:26:24.371937037 CET37785792445.95.169.120192.168.2.15
                              Jan 2, 2025 05:26:24.372160912 CET579243778192.168.2.1545.95.169.120
                              Jan 2, 2025 05:26:24.376979113 CET37785792445.95.169.120192.168.2.15
                              Jan 2, 2025 05:26:25.016273975 CET37785792445.95.169.120192.168.2.15
                              Jan 2, 2025 05:26:25.016334057 CET579243778192.168.2.1545.95.169.120
                              Jan 2, 2025 05:26:25.016390085 CET579243778192.168.2.1545.95.169.120
                              Jan 2, 2025 05:26:25.017537117 CET579263778192.168.2.1545.95.169.120
                              Jan 2, 2025 05:26:25.022351980 CET37785792645.95.169.120192.168.2.15
                              Jan 2, 2025 05:26:25.022440910 CET579263778192.168.2.1545.95.169.120
                              Jan 2, 2025 05:26:25.024626017 CET579263778192.168.2.1545.95.169.120
                              Jan 2, 2025 05:26:25.029437065 CET37785792645.95.169.120192.168.2.15
                              Jan 2, 2025 05:26:25.029499054 CET579263778192.168.2.1545.95.169.120
                              Jan 2, 2025 05:26:25.034288883 CET37785792645.95.169.120192.168.2.15
                              Jan 2, 2025 05:26:25.665767908 CET37785792645.95.169.120192.168.2.15
                              Jan 2, 2025 05:26:25.665829897 CET579263778192.168.2.1545.95.169.120
                              Jan 2, 2025 05:26:25.665961027 CET579263778192.168.2.1545.95.169.120
                              Jan 2, 2025 05:26:25.667017937 CET579283778192.168.2.1545.95.169.120
                              Jan 2, 2025 05:26:25.671804905 CET37785792845.95.169.120192.168.2.15
                              Jan 2, 2025 05:26:25.672075033 CET579283778192.168.2.1545.95.169.120
                              Jan 2, 2025 05:26:25.676146030 CET579283778192.168.2.1545.95.169.120
                              Jan 2, 2025 05:26:25.680982113 CET37785792845.95.169.120192.168.2.15
                              Jan 2, 2025 05:26:25.681030035 CET579283778192.168.2.1545.95.169.120
                              Jan 2, 2025 05:26:25.685854912 CET37785792845.95.169.120192.168.2.15
                              Jan 2, 2025 05:26:26.319300890 CET37785792845.95.169.120192.168.2.15
                              Jan 2, 2025 05:26:26.319380999 CET579283778192.168.2.1545.95.169.120
                              Jan 2, 2025 05:26:26.319489956 CET579283778192.168.2.1545.95.169.120
                              Jan 2, 2025 05:26:26.321099997 CET579303778192.168.2.1545.95.169.120
                              Jan 2, 2025 05:26:26.325968981 CET37785793045.95.169.120192.168.2.15
                              Jan 2, 2025 05:26:26.326067924 CET579303778192.168.2.1545.95.169.120
                              Jan 2, 2025 05:26:26.328887939 CET579303778192.168.2.1545.95.169.120
                              Jan 2, 2025 05:26:26.333693981 CET37785793045.95.169.120192.168.2.15
                              Jan 2, 2025 05:26:26.333744049 CET579303778192.168.2.1545.95.169.120
                              Jan 2, 2025 05:26:26.338577986 CET37785793045.95.169.120192.168.2.15
                              Jan 2, 2025 05:26:26.970410109 CET37785793045.95.169.120192.168.2.15
                              Jan 2, 2025 05:26:26.973516941 CET579303778192.168.2.1545.95.169.120
                              Jan 2, 2025 05:26:26.973516941 CET579303778192.168.2.1545.95.169.120
                              Jan 2, 2025 05:26:26.989501953 CET579323778192.168.2.1545.95.169.120
                              Jan 2, 2025 05:26:26.994760036 CET37785793245.95.169.120192.168.2.15
                              Jan 2, 2025 05:26:26.994816065 CET579323778192.168.2.1545.95.169.120
                              Jan 2, 2025 05:26:27.065438986 CET579323778192.168.2.1545.95.169.120
                              Jan 2, 2025 05:26:27.070512056 CET37785793245.95.169.120192.168.2.15
                              Jan 2, 2025 05:26:27.073436022 CET579323778192.168.2.1545.95.169.120
                              Jan 2, 2025 05:26:27.078404903 CET37785793245.95.169.120192.168.2.15
                              Jan 2, 2025 05:26:27.643361092 CET37785793245.95.169.120192.168.2.15
                              Jan 2, 2025 05:26:27.643531084 CET579323778192.168.2.1545.95.169.120
                              Jan 2, 2025 05:26:27.643532038 CET579323778192.168.2.1545.95.169.120
                              Jan 2, 2025 05:26:27.644057989 CET579343778192.168.2.1545.95.169.120
                              Jan 2, 2025 05:26:27.648926973 CET37785793445.95.169.120192.168.2.15
                              Jan 2, 2025 05:26:27.648997068 CET579343778192.168.2.1545.95.169.120
                              Jan 2, 2025 05:26:27.649732113 CET579343778192.168.2.1545.95.169.120
                              Jan 2, 2025 05:26:27.654668093 CET37785793445.95.169.120192.168.2.15
                              Jan 2, 2025 05:26:27.654727936 CET579343778192.168.2.1545.95.169.120
                              Jan 2, 2025 05:26:27.659651041 CET37785793445.95.169.120192.168.2.15
                              Jan 2, 2025 05:26:28.305654049 CET37785793445.95.169.120192.168.2.15
                              Jan 2, 2025 05:26:28.305751085 CET579343778192.168.2.1545.95.169.120
                              Jan 2, 2025 05:26:28.305859089 CET579343778192.168.2.1545.95.169.120
                              Jan 2, 2025 05:26:28.306588888 CET579363778192.168.2.1545.95.169.120
                              Jan 2, 2025 05:26:28.311461926 CET37785793645.95.169.120192.168.2.15
                              Jan 2, 2025 05:26:28.311532021 CET579363778192.168.2.1545.95.169.120
                              Jan 2, 2025 05:26:28.312400103 CET579363778192.168.2.1545.95.169.120
                              Jan 2, 2025 05:26:28.317281961 CET37785793645.95.169.120192.168.2.15
                              Jan 2, 2025 05:26:28.317348003 CET579363778192.168.2.1545.95.169.120
                              Jan 2, 2025 05:26:28.322211027 CET37785793645.95.169.120192.168.2.15
                              Jan 2, 2025 05:26:28.960678101 CET37785793645.95.169.120192.168.2.15
                              Jan 2, 2025 05:26:28.960768938 CET579363778192.168.2.1545.95.169.120
                              Jan 2, 2025 05:26:28.960828066 CET579363778192.168.2.1545.95.169.120
                              Jan 2, 2025 05:26:28.961289883 CET579383778192.168.2.1545.95.169.120
                              Jan 2, 2025 05:26:28.966063976 CET37785793845.95.169.120192.168.2.15
                              Jan 2, 2025 05:26:28.966109037 CET579383778192.168.2.1545.95.169.120
                              Jan 2, 2025 05:26:28.966746092 CET579383778192.168.2.1545.95.169.120
                              Jan 2, 2025 05:26:28.971549988 CET37785793845.95.169.120192.168.2.15
                              Jan 2, 2025 05:26:28.971585989 CET579383778192.168.2.1545.95.169.120
                              Jan 2, 2025 05:26:28.976377010 CET37785793845.95.169.120192.168.2.15
                              Jan 2, 2025 05:26:29.613404989 CET37785793845.95.169.120192.168.2.15
                              Jan 2, 2025 05:26:29.613559961 CET579383778192.168.2.1545.95.169.120
                              Jan 2, 2025 05:26:29.613610029 CET579383778192.168.2.1545.95.169.120
                              Jan 2, 2025 05:26:29.614079952 CET579403778192.168.2.1545.95.169.120
                              Jan 2, 2025 05:26:29.618948936 CET37785794045.95.169.120192.168.2.15
                              Jan 2, 2025 05:26:29.618999958 CET579403778192.168.2.1545.95.169.120
                              Jan 2, 2025 05:26:29.619714022 CET579403778192.168.2.1545.95.169.120
                              Jan 2, 2025 05:26:29.624545097 CET37785794045.95.169.120192.168.2.15
                              Jan 2, 2025 05:26:29.624586105 CET579403778192.168.2.1545.95.169.120
                              Jan 2, 2025 05:26:29.629467964 CET37785794045.95.169.120192.168.2.15
                              Jan 2, 2025 05:26:30.263737917 CET37785794045.95.169.120192.168.2.15
                              Jan 2, 2025 05:26:30.263957024 CET579403778192.168.2.1545.95.169.120
                              Jan 2, 2025 05:26:30.263957024 CET579403778192.168.2.1545.95.169.120
                              Jan 2, 2025 05:26:30.264460087 CET579423778192.168.2.1545.95.169.120
                              Jan 2, 2025 05:26:30.269516945 CET37785794245.95.169.120192.168.2.15
                              Jan 2, 2025 05:26:30.269566059 CET579423778192.168.2.1545.95.169.120
                              Jan 2, 2025 05:26:30.270193100 CET579423778192.168.2.1545.95.169.120
                              Jan 2, 2025 05:26:30.274947882 CET37785794245.95.169.120192.168.2.15
                              Jan 2, 2025 05:26:30.275007010 CET579423778192.168.2.1545.95.169.120
                              Jan 2, 2025 05:26:30.279782057 CET37785794245.95.169.120192.168.2.15
                              Jan 2, 2025 05:26:30.934887886 CET37785794245.95.169.120192.168.2.15
                              Jan 2, 2025 05:26:30.934983969 CET579423778192.168.2.1545.95.169.120
                              Jan 2, 2025 05:26:30.934983969 CET579423778192.168.2.1545.95.169.120
                              Jan 2, 2025 05:26:30.935455084 CET579443778192.168.2.1545.95.169.120
                              Jan 2, 2025 05:26:30.940253019 CET37785794445.95.169.120192.168.2.15
                              Jan 2, 2025 05:26:30.940304041 CET579443778192.168.2.1545.95.169.120
                              Jan 2, 2025 05:26:30.940880060 CET579443778192.168.2.1545.95.169.120
                              Jan 2, 2025 05:26:30.945702076 CET37785794445.95.169.120192.168.2.15
                              Jan 2, 2025 05:26:30.945745945 CET579443778192.168.2.1545.95.169.120
                              Jan 2, 2025 05:26:30.950572014 CET37785794445.95.169.120192.168.2.15
                              Jan 2, 2025 05:26:31.585346937 CET37785794445.95.169.120192.168.2.15
                              Jan 2, 2025 05:26:31.585458040 CET579443778192.168.2.1545.95.169.120
                              Jan 2, 2025 05:26:31.585458040 CET579443778192.168.2.1545.95.169.120
                              Jan 2, 2025 05:26:31.585870028 CET579463778192.168.2.1545.95.169.120
                              Jan 2, 2025 05:26:31.590627909 CET37785794645.95.169.120192.168.2.15
                              Jan 2, 2025 05:26:31.590672970 CET579463778192.168.2.1545.95.169.120
                              Jan 2, 2025 05:26:31.591203928 CET579463778192.168.2.1545.95.169.120
                              Jan 2, 2025 05:26:31.595942974 CET37785794645.95.169.120192.168.2.15
                              Jan 2, 2025 05:26:31.595997095 CET579463778192.168.2.1545.95.169.120
                              Jan 2, 2025 05:26:31.600775957 CET37785794645.95.169.120192.168.2.15
                              Jan 2, 2025 05:26:32.237565041 CET37785794645.95.169.120192.168.2.15
                              Jan 2, 2025 05:26:32.237828970 CET579463778192.168.2.1545.95.169.120
                              Jan 2, 2025 05:26:32.237828970 CET579463778192.168.2.1545.95.169.120
                              Jan 2, 2025 05:26:32.238284111 CET579483778192.168.2.1545.95.169.120
                              Jan 2, 2025 05:26:32.243159056 CET37785794845.95.169.120192.168.2.15
                              Jan 2, 2025 05:26:32.243201971 CET579483778192.168.2.1545.95.169.120
                              Jan 2, 2025 05:26:32.243851900 CET579483778192.168.2.1545.95.169.120
                              Jan 2, 2025 05:26:32.248657942 CET37785794845.95.169.120192.168.2.15
                              Jan 2, 2025 05:26:32.248737097 CET579483778192.168.2.1545.95.169.120
                              Jan 2, 2025 05:26:32.253496885 CET37785794845.95.169.120192.168.2.15
                              Jan 2, 2025 05:26:32.898811102 CET37785794845.95.169.120192.168.2.15
                              Jan 2, 2025 05:26:32.898914099 CET579483778192.168.2.1545.95.169.120
                              Jan 2, 2025 05:26:32.898914099 CET579483778192.168.2.1545.95.169.120
                              Jan 2, 2025 05:26:32.899427891 CET579503778192.168.2.1545.95.169.120
                              Jan 2, 2025 05:26:32.904206038 CET37785795045.95.169.120192.168.2.15
                              Jan 2, 2025 05:26:32.904258013 CET579503778192.168.2.1545.95.169.120
                              Jan 2, 2025 05:26:32.904900074 CET579503778192.168.2.1545.95.169.120
                              Jan 2, 2025 05:26:32.909672976 CET37785795045.95.169.120192.168.2.15
                              Jan 2, 2025 05:26:32.909734011 CET579503778192.168.2.1545.95.169.120
                              Jan 2, 2025 05:26:32.914547920 CET37785795045.95.169.120192.168.2.15
                              Jan 2, 2025 05:26:33.548768044 CET37785795045.95.169.120192.168.2.15
                              Jan 2, 2025 05:26:33.548886061 CET579503778192.168.2.1545.95.169.120
                              Jan 2, 2025 05:26:33.548886061 CET579503778192.168.2.1545.95.169.120
                              Jan 2, 2025 05:26:33.549303055 CET579523778192.168.2.1545.95.169.120
                              Jan 2, 2025 05:26:33.554111004 CET37785795245.95.169.120192.168.2.15
                              Jan 2, 2025 05:26:33.554192066 CET579523778192.168.2.1545.95.169.120
                              Jan 2, 2025 05:26:33.555005074 CET579523778192.168.2.1545.95.169.120
                              Jan 2, 2025 05:26:33.559834003 CET37785795245.95.169.120192.168.2.15
                              Jan 2, 2025 05:26:33.559899092 CET579523778192.168.2.1545.95.169.120
                              Jan 2, 2025 05:26:33.564760923 CET37785795245.95.169.120192.168.2.15
                              Jan 2, 2025 05:26:34.221301079 CET37785795245.95.169.120192.168.2.15
                              Jan 2, 2025 05:26:34.221450090 CET579523778192.168.2.1545.95.169.120
                              Jan 2, 2025 05:26:34.221450090 CET579523778192.168.2.1545.95.169.120
                              Jan 2, 2025 05:26:34.221952915 CET579543778192.168.2.1545.95.169.120
                              Jan 2, 2025 05:26:34.226794004 CET37785795445.95.169.120192.168.2.15
                              Jan 2, 2025 05:26:34.226850033 CET579543778192.168.2.1545.95.169.120
                              Jan 2, 2025 05:26:34.227490902 CET579543778192.168.2.1545.95.169.120
                              Jan 2, 2025 05:26:34.232270002 CET37785795445.95.169.120192.168.2.15
                              Jan 2, 2025 05:26:34.232333899 CET579543778192.168.2.1545.95.169.120
                              Jan 2, 2025 05:26:34.237144947 CET37785795445.95.169.120192.168.2.15
                              Jan 2, 2025 05:26:34.870270967 CET37785795445.95.169.120192.168.2.15
                              Jan 2, 2025 05:26:34.870390892 CET579543778192.168.2.1545.95.169.120
                              Jan 2, 2025 05:26:34.870433092 CET579543778192.168.2.1545.95.169.120
                              Jan 2, 2025 05:26:34.870929956 CET579563778192.168.2.1545.95.169.120
                              Jan 2, 2025 05:26:34.875776052 CET37785795645.95.169.120192.168.2.15
                              Jan 2, 2025 05:26:34.875821114 CET579563778192.168.2.1545.95.169.120
                              Jan 2, 2025 05:26:34.876503944 CET579563778192.168.2.1545.95.169.120
                              Jan 2, 2025 05:26:34.881290913 CET37785795645.95.169.120192.168.2.15
                              Jan 2, 2025 05:26:34.881330013 CET579563778192.168.2.1545.95.169.120
                              Jan 2, 2025 05:26:34.886164904 CET37785795645.95.169.120192.168.2.15
                              Jan 2, 2025 05:26:44.886581898 CET579563778192.168.2.1545.95.169.120
                              Jan 2, 2025 05:26:44.891525030 CET37785795645.95.169.120192.168.2.15
                              Jan 2, 2025 05:26:45.082204103 CET37785795645.95.169.120192.168.2.15
                              Jan 2, 2025 05:26:45.082371950 CET579563778192.168.2.1545.95.169.120
                              Jan 2, 2025 05:27:45.126245975 CET579563778192.168.2.1545.95.169.120
                              Jan 2, 2025 05:27:45.131217003 CET37785795645.95.169.120192.168.2.15
                              Jan 2, 2025 05:27:45.322349072 CET37785795645.95.169.120192.168.2.15
                              Jan 2, 2025 05:27:45.322402954 CET579563778192.168.2.1545.95.169.120
                              Jan 2, 2025 05:28:45.366271019 CET579563778192.168.2.1545.95.169.120
                              Jan 2, 2025 05:28:45.371150970 CET37785795645.95.169.120192.168.2.15
                              Jan 2, 2025 05:28:45.561800003 CET37785795645.95.169.120192.168.2.15
                              Jan 2, 2025 05:28:45.561844110 CET579563778192.168.2.1545.95.169.120
                              Jan 2, 2025 05:29:45.611002922 CET579563778192.168.2.1545.95.169.120
                              Jan 2, 2025 05:29:45.616008043 CET37785795645.95.169.120192.168.2.15
                              Jan 2, 2025 05:29:45.806545019 CET37785795645.95.169.120192.168.2.15
                              Jan 2, 2025 05:29:45.806601048 CET579563778192.168.2.1545.95.169.120
                              TimestampSource PortDest PortSource IPDest IP
                              Jan 2, 2025 05:29:07.769159079 CET4789653192.168.2.151.1.1.1
                              Jan 2, 2025 05:29:07.769207001 CET3307953192.168.2.151.1.1.1
                              Jan 2, 2025 05:29:07.776133060 CET53330791.1.1.1192.168.2.15
                              Jan 2, 2025 05:29:07.776624918 CET53478961.1.1.1192.168.2.15
                              TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                              Jan 2, 2025 05:29:07.769159079 CET192.168.2.151.1.1.10xad84Standard query (0)daisy.ubuntu.comA (IP address)IN (0x0001)false
                              Jan 2, 2025 05:29:07.769207001 CET192.168.2.151.1.1.10x2635Standard query (0)daisy.ubuntu.com28IN (0x0001)false
                              TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                              Jan 2, 2025 05:29:07.776624918 CET1.1.1.1192.168.2.150xad84No error (0)daisy.ubuntu.com162.213.35.25A (IP address)IN (0x0001)false
                              Jan 2, 2025 05:29:07.776624918 CET1.1.1.1192.168.2.150xad84No error (0)daisy.ubuntu.com162.213.35.24A (IP address)IN (0x0001)false

                              System Behavior

                              Start time (UTC):04:26:19
                              Start date (UTC):02/01/2025
                              Path:/tmp/wind.spc.elf
                              Arguments:/tmp/wind.spc.elf
                              File size:4379400 bytes
                              MD5 hash:7dc1c0e23cd5e102bb12e5c29403410e

                              Start time (UTC):04:26:19
                              Start date (UTC):02/01/2025
                              Path:/tmp/wind.spc.elf
                              Arguments:-
                              File size:4379400 bytes
                              MD5 hash:7dc1c0e23cd5e102bb12e5c29403410e

                              Start time (UTC):04:26:19
                              Start date (UTC):02/01/2025
                              Path:/tmp/wind.spc.elf
                              Arguments:-
                              File size:4379400 bytes
                              MD5 hash:7dc1c0e23cd5e102bb12e5c29403410e

                              Start time (UTC):04:26:19
                              Start date (UTC):02/01/2025
                              Path:/tmp/wind.spc.elf
                              Arguments:-
                              File size:4379400 bytes
                              MD5 hash:7dc1c0e23cd5e102bb12e5c29403410e

                              Start time (UTC):04:26:20
                              Start date (UTC):02/01/2025
                              Path:/usr/bin/xfce4-panel
                              Arguments:-
                              File size:375768 bytes
                              MD5 hash:a15b657c7d54ac1385f1f15004ea6784

                              Start time (UTC):04:26:20
                              Start date (UTC):02/01/2025
                              Path:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
                              Arguments:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libsystray.so 6 12582920 systray "Notification Area" "Area where notification icons appear"
                              File size:35136 bytes
                              MD5 hash:ac0b8a906f359a8ae102244738682e76

                              Start time (UTC):04:26:20
                              Start date (UTC):02/01/2025
                              Path:/usr/bin/xfce4-panel
                              Arguments:-
                              File size:375768 bytes
                              MD5 hash:a15b657c7d54ac1385f1f15004ea6784

                              Start time (UTC):04:26:20
                              Start date (UTC):02/01/2025
                              Path:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
                              Arguments:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libstatusnotifier.so 7 12582921 statusnotifier "Status Notifier Plugin" "Provides a panel area for status notifier items (application indicators)"
                              File size:35136 bytes
                              MD5 hash:ac0b8a906f359a8ae102244738682e76

                              Start time (UTC):04:26:20
                              Start date (UTC):02/01/2025
                              Path:/usr/bin/xfce4-panel
                              Arguments:-
                              File size:375768 bytes
                              MD5 hash:a15b657c7d54ac1385f1f15004ea6784

                              Start time (UTC):04:26:20
                              Start date (UTC):02/01/2025
                              Path:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
                              Arguments:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libpulseaudio-plugin.so 8 12582922 pulseaudio "PulseAudio Plugin" "Adjust the audio volume of the PulseAudio sound system"
                              File size:35136 bytes
                              MD5 hash:ac0b8a906f359a8ae102244738682e76

                              Start time (UTC):04:26:20
                              Start date (UTC):02/01/2025
                              Path:/usr/bin/xfce4-panel
                              Arguments:-
                              File size:375768 bytes
                              MD5 hash:a15b657c7d54ac1385f1f15004ea6784

                              Start time (UTC):04:26:20
                              Start date (UTC):02/01/2025
                              Path:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
                              Arguments:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libxfce4powermanager.so 9 12582923 power-manager-plugin "Power Manager Plugin" "Display the battery levels of your devices and control the brightness of your display"
                              File size:35136 bytes
                              MD5 hash:ac0b8a906f359a8ae102244738682e76

                              Start time (UTC):04:26:20
                              Start date (UTC):02/01/2025
                              Path:/usr/bin/xfce4-panel
                              Arguments:-
                              File size:375768 bytes
                              MD5 hash:a15b657c7d54ac1385f1f15004ea6784

                              Start time (UTC):04:26:20
                              Start date (UTC):02/01/2025
                              Path:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
                              Arguments:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libnotification-plugin.so 10 12582924 notification-plugin "Notification Plugin" "Notification plugin for the Xfce panel"
                              File size:35136 bytes
                              MD5 hash:ac0b8a906f359a8ae102244738682e76

                              Start time (UTC):04:26:20
                              Start date (UTC):02/01/2025
                              Path:/usr/bin/xfce4-panel
                              Arguments:-
                              File size:375768 bytes
                              MD5 hash:a15b657c7d54ac1385f1f15004ea6784

                              Start time (UTC):04:26:20
                              Start date (UTC):02/01/2025
                              Path:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
                              Arguments:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libactions.so 14 12582925 actions "Action Buttons" "Log out, lock or other system actions"
                              File size:35136 bytes
                              MD5 hash:ac0b8a906f359a8ae102244738682e76