Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
x86.elf

Overview

General Information

Sample name:x86.elf
Analysis ID:1583919
MD5:75c592fdbef6e2a717e94a7243747a55
SHA1:b75ac97b39dc661c5fdddff8b81b894af292b46e
SHA256:5e32cd9ca17361b8deea9202641ff4db44bbc56324ba81b880a457b62f892cac
Tags:elfuser-abuse_ch
Infos:

Detection

Score:64
Range:0 - 100
Whitelisted:false

Signatures

Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Machine Learning detection for sample
Sample tries to kill multiple processes (SIGKILL)
Detected TCP or UDP traffic on non-standard ports
Enumerates processes within the "proc" file system
Found strings indicative of a multi-platform dropper
Sample contains strings indicative of BusyBox which embeds multiple Unix commands in a single executable
Sample has stripped symbol table
Sample tries to kill a process (SIGKILL)
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Tries to resolve domain names, but no domain seems valid (expired dropper behavior)
Yara signature match

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1583919
Start date and time:2025-01-03 21:12:05 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 3m 20s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:x86.elf
Detection:MAL
Classification:mal64.spre.linELF@0/0@5/0
  • VT rate limit hit for: x86.elf
Command:/tmp/x86.elf
PID:6217
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
dear
Standard Error:
  • system is lnxubuntu20
  • x86.elf (PID: 6217, Parent: 6135, MD5: 75c592fdbef6e2a717e94a7243747a55) Arguments: /tmp/x86.elf
    • x86.elf New Fork (PID: 6218, Parent: 6217)
      • x86.elf New Fork (PID: 6219, Parent: 6218)
      • x86.elf New Fork (PID: 6220, Parent: 6218)
  • cleanup
SourceRuleDescriptionAuthorStrings
x86.elfLinux_Trojan_Mirai_b14f4c5dunknownunknown
  • 0xa50:$a: 53 31 DB 8B 4C 24 0C 8B 54 24 08 83 F9 01 76 15 66 8B 02 83 E9 02 25 FF FF 00 00 83 C2 02 01 C3 83 F9 01 77 EB 49 75 05 0F BE 02 01 C3
x86.elfLinux_Trojan_Mirai_88de437funknownunknown
  • 0x31c2:$a: 24 08 8B 4C 24 04 85 D2 74 0D 31 C0 89 F6 C6 04 08 00 40 39 D0
x86.elfLinux_Trojan_Mirai_389ee3e9unknownunknown
  • 0x8e83:$a: 89 45 00 EB 2C 8B 4B 04 8B 13 8B 7B 18 8B 01 01 02 8B 02 83
x86.elfLinux_Trojan_Mirai_cc93863bunknownunknown
  • 0x7941:$a: C3 57 8B 44 24 0C 8B 4C 24 10 8B 7C 24 08 F3 AA 8B 44 24 08
x86.elfLinux_Trojan_Mirai_8aa7b5d3unknownunknown
  • 0x3192:$a: 8B 4C 24 14 8B 74 24 0C 8B 5C 24 10 85 C9 74 0D 31 D2 8A 04 1A 88
SourceRuleDescriptionAuthorStrings
6217.1.0000000008048000.0000000008053000.r-x.sdmpLinux_Trojan_Mirai_b14f4c5dunknownunknown
  • 0xa50:$a: 53 31 DB 8B 4C 24 0C 8B 54 24 08 83 F9 01 76 15 66 8B 02 83 E9 02 25 FF FF 00 00 83 C2 02 01 C3 83 F9 01 77 EB 49 75 05 0F BE 02 01 C3
6217.1.0000000008048000.0000000008053000.r-x.sdmpLinux_Trojan_Mirai_88de437funknownunknown
  • 0x31c2:$a: 24 08 8B 4C 24 04 85 D2 74 0D 31 C0 89 F6 C6 04 08 00 40 39 D0
6217.1.0000000008048000.0000000008053000.r-x.sdmpLinux_Trojan_Mirai_389ee3e9unknownunknown
  • 0x8e83:$a: 89 45 00 EB 2C 8B 4B 04 8B 13 8B 7B 18 8B 01 01 02 8B 02 83
6217.1.0000000008048000.0000000008053000.r-x.sdmpLinux_Trojan_Mirai_cc93863bunknownunknown
  • 0x7941:$a: C3 57 8B 44 24 0C 8B 4C 24 10 8B 7C 24 08 F3 AA 8B 44 24 08
6217.1.0000000008048000.0000000008053000.r-x.sdmpLinux_Trojan_Mirai_8aa7b5d3unknownunknown
  • 0x3192:$a: 8B 4C 24 14 8B 74 24 0C 8B 5C 24 10 85 C9 74 0D 31 D2 8A 04 1A 88
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: x86.elfReversingLabs: Detection: 39%
Source: x86.elfJoe Sandbox ML: detected
Source: x86.elfString: /proc/self/exeself/proc//bin/bash/bin/sh/bin/dashwgettftpncnetcatnmaptcpdumpsocatcurlbusyboxpythonrebootechoinitcroniptablessshdtelnetdtftpdrshdrexecdxinetdpftp/bin/login
Source: global trafficTCP traffic: 192.168.2.23:54244 -> 210.99.167.219:13566
Source: global trafficTCP traffic: 192.168.2.23:43474 -> 210.99.235.231:13566
Source: global trafficTCP traffic: 192.168.2.23:47256 -> 210.99.234.181:13566
Source: global trafficTCP traffic: 192.168.2.23:60640 -> 210.99.91.209:13566
Source: global trafficTCP traffic: 192.168.2.23:51134 -> 210.99.82.151:13566
Source: global trafficTCP traffic: 192.168.2.23:41816 -> 210.99.185.68:13566
Source: global trafficTCP traffic: 192.168.2.23:55718 -> 210.99.251.37:13566
Source: global trafficTCP traffic: 192.168.2.23:51864 -> 210.99.170.52:13566
Source: global trafficTCP traffic: 192.168.2.23:60674 -> 210.99.19.133:13566
Source: global trafficTCP traffic: 192.168.2.23:45724 -> 210.99.45.211:13566
Source: global trafficTCP traffic: 192.168.2.23:42216 -> 210.99.34.26:13566
Source: global trafficTCP traffic: 192.168.2.23:36058 -> 210.99.179.142:13566
Source: global trafficTCP traffic: 192.168.2.23:44464 -> 210.99.252.114:13566
Source: global trafficTCP traffic: 192.168.2.23:41840 -> 210.99.156.146:13566
Source: global trafficTCP traffic: 192.168.2.23:37820 -> 210.99.95.52:13566
Source: global trafficTCP traffic: 192.168.2.23:37870 -> 210.99.208.6:13566
Source: global trafficTCP traffic: 192.168.2.23:51028 -> 210.99.15.188:13566
Source: global trafficTCP traffic: 192.168.2.23:39162 -> 210.99.238.249:13566
Source: global trafficTCP traffic: 192.168.2.23:38430 -> 210.99.113.64:13566
Source: global trafficTCP traffic: 192.168.2.23:54866 -> 210.99.144.204:13566
Source: global trafficTCP traffic: 192.168.2.23:59272 -> 210.99.18.73:13566
Source: global trafficTCP traffic: 192.168.2.23:42580 -> 83.222.191.90:13566
Source: global trafficTCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
Source: global trafficTCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
Source: global trafficTCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
Source: unknownDNS traffic detected: query: secure-network-rebirthltd.ru replaycode: Name error (3)
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.191.90
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.191.90
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.191.90
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.191.90
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.191.90
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.191.90
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.191.90
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.191.90
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.191.90
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.191.90
Source: global trafficDNS traffic detected: DNS query: secure-network-rebirthltd.ru
Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443

System Summary

barindex
Source: x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_b14f4c5d Author: unknown
Source: x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_88de437f Author: unknown
Source: x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_389ee3e9 Author: unknown
Source: x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_cc93863b Author: unknown
Source: x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_8aa7b5d3 Author: unknown
Source: 6217.1.0000000008048000.0000000008053000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_b14f4c5d Author: unknown
Source: 6217.1.0000000008048000.0000000008053000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_88de437f Author: unknown
Source: 6217.1.0000000008048000.0000000008053000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_389ee3e9 Author: unknown
Source: 6217.1.0000000008048000.0000000008053000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_cc93863b Author: unknown
Source: 6217.1.0000000008048000.0000000008053000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_8aa7b5d3 Author: unknown
Source: /tmp/x86.elf (PID: 6219)SIGKILL sent: pid: 6232, result: successfulJump to behavior
Source: /tmp/x86.elf (PID: 6219)SIGKILL sent: pid: 6233, result: successfulJump to behavior
Source: /tmp/x86.elf (PID: 6219)SIGKILL sent: pid: 6234, result: successfulJump to behavior
Source: /tmp/x86.elf (PID: 6219)SIGKILL sent: pid: 6235, result: successfulJump to behavior
Source: /tmp/x86.elf (PID: 6219)SIGKILL sent: pid: 6236, result: successfulJump to behavior
Source: /tmp/x86.elf (PID: 6219)SIGKILL sent: pid: 6237, result: successfulJump to behavior
Source: /tmp/x86.elf (PID: 6219)SIGKILL sent: pid: 6238, result: successfulJump to behavior
Source: /tmp/x86.elf (PID: 6219)SIGKILL sent: pid: 6239, result: successfulJump to behavior
Source: /tmp/x86.elf (PID: 6219)SIGKILL sent: pid: 6240, result: successfulJump to behavior
Source: /tmp/x86.elf (PID: 6219)SIGKILL sent: pid: 6241, result: successfulJump to behavior
Source: /tmp/x86.elf (PID: 6219)SIGKILL sent: pid: 6242, result: successfulJump to behavior
Source: /tmp/x86.elf (PID: 6219)SIGKILL sent: pid: 6243, result: successfulJump to behavior
Source: /tmp/x86.elf (PID: 6219)SIGKILL sent: pid: 6244, result: successfulJump to behavior
Source: /tmp/x86.elf (PID: 6219)SIGKILL sent: pid: 6245, result: successfulJump to behavior
Source: /tmp/x86.elf (PID: 6219)SIGKILL sent: pid: 6246, result: successfulJump to behavior
Source: /tmp/x86.elf (PID: 6219)SIGKILL sent: pid: 6247, result: successfulJump to behavior
Source: /tmp/x86.elf (PID: 6219)SIGKILL sent: pid: 6248, result: successfulJump to behavior
Source: /tmp/x86.elf (PID: 6219)SIGKILL sent: pid: 6249, result: successfulJump to behavior
Source: /tmp/x86.elf (PID: 6219)SIGKILL sent: pid: 6250, result: successfulJump to behavior
Source: /tmp/x86.elf (PID: 6219)SIGKILL sent: pid: 6251, result: successfulJump to behavior
Source: /tmp/x86.elf (PID: 6219)SIGKILL sent: pid: 6288, result: successfulJump to behavior
Source: /tmp/x86.elf (PID: 6219)SIGKILL sent: pid: 6302, result: successfulJump to behavior
Source: /tmp/x86.elf (PID: 6219)SIGKILL sent: pid: 6307, result: successfulJump to behavior
Source: Initial sampleString containing 'busybox' found: busybox
Source: Initial sampleString containing 'busybox' found: /proc/self/exeself/proc//bin/bash/bin/sh/bin/dashwgettftpncnetcatnmaptcpdumpsocatcurlbusyboxpythonrebootechoinitcroniptablessshdtelnetdtftpdrshdrexecdxinetdpftp/bin/login
Source: ELF static info symbol of initial sample.symtab present: no
Source: /tmp/x86.elf (PID: 6219)SIGKILL sent: pid: 6232, result: successfulJump to behavior
Source: /tmp/x86.elf (PID: 6219)SIGKILL sent: pid: 6233, result: successfulJump to behavior
Source: /tmp/x86.elf (PID: 6219)SIGKILL sent: pid: 6234, result: successfulJump to behavior
Source: /tmp/x86.elf (PID: 6219)SIGKILL sent: pid: 6235, result: successfulJump to behavior
Source: /tmp/x86.elf (PID: 6219)SIGKILL sent: pid: 6236, result: successfulJump to behavior
Source: /tmp/x86.elf (PID: 6219)SIGKILL sent: pid: 6237, result: successfulJump to behavior
Source: /tmp/x86.elf (PID: 6219)SIGKILL sent: pid: 6238, result: successfulJump to behavior
Source: /tmp/x86.elf (PID: 6219)SIGKILL sent: pid: 6239, result: successfulJump to behavior
Source: /tmp/x86.elf (PID: 6219)SIGKILL sent: pid: 6240, result: successfulJump to behavior
Source: /tmp/x86.elf (PID: 6219)SIGKILL sent: pid: 6241, result: successfulJump to behavior
Source: /tmp/x86.elf (PID: 6219)SIGKILL sent: pid: 6242, result: successfulJump to behavior
Source: /tmp/x86.elf (PID: 6219)SIGKILL sent: pid: 6243, result: successfulJump to behavior
Source: /tmp/x86.elf (PID: 6219)SIGKILL sent: pid: 6244, result: successfulJump to behavior
Source: /tmp/x86.elf (PID: 6219)SIGKILL sent: pid: 6245, result: successfulJump to behavior
Source: /tmp/x86.elf (PID: 6219)SIGKILL sent: pid: 6246, result: successfulJump to behavior
Source: /tmp/x86.elf (PID: 6219)SIGKILL sent: pid: 6247, result: successfulJump to behavior
Source: /tmp/x86.elf (PID: 6219)SIGKILL sent: pid: 6248, result: successfulJump to behavior
Source: /tmp/x86.elf (PID: 6219)SIGKILL sent: pid: 6249, result: successfulJump to behavior
Source: /tmp/x86.elf (PID: 6219)SIGKILL sent: pid: 6250, result: successfulJump to behavior
Source: /tmp/x86.elf (PID: 6219)SIGKILL sent: pid: 6251, result: successfulJump to behavior
Source: /tmp/x86.elf (PID: 6219)SIGKILL sent: pid: 6288, result: successfulJump to behavior
Source: /tmp/x86.elf (PID: 6219)SIGKILL sent: pid: 6302, result: successfulJump to behavior
Source: /tmp/x86.elf (PID: 6219)SIGKILL sent: pid: 6307, result: successfulJump to behavior
Source: x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_b14f4c5d os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = a70d052918dd2fbc66db241da6438015130f0fb6929229bfe573546fe98da817, id = b14f4c5d-054f-46e6-9fa8-3588f1ef68b7, last_modified = 2021-09-16
Source: x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_88de437f reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = c19eb595c2b444a809bef8500c20342c9f46694d3018e268833f9b884133a1ea, id = 88de437f-9c98-4e1d-96c0-7b433c99886a, last_modified = 2021-09-16
Source: x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_389ee3e9 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 59f2359dc1f41d385d639d157b4cd9fc73d76d8abb7cc09d47632bb4c9a39e6e, id = 389ee3e9-70c1-4c93-a999-292cf6ff1652, last_modified = 2022-01-26
Source: x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_cc93863b reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = f3ecd30f0b511a8e92cfa642409d559e7612c3f57a1659ca46c77aca809a00ac, id = cc93863b-1050-40ba-9d02-5ec9ce6a3a28, last_modified = 2022-01-26
Source: x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_8aa7b5d3 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 02a2c18c362df4b1fceb33f3b605586514ba9a00c7afedf71c04fa54d8146444, id = 8aa7b5d3-e1eb-4b55-b36a-0d3a242c06e9, last_modified = 2022-01-26
Source: 6217.1.0000000008048000.0000000008053000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_b14f4c5d os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = a70d052918dd2fbc66db241da6438015130f0fb6929229bfe573546fe98da817, id = b14f4c5d-054f-46e6-9fa8-3588f1ef68b7, last_modified = 2021-09-16
Source: 6217.1.0000000008048000.0000000008053000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_88de437f reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = c19eb595c2b444a809bef8500c20342c9f46694d3018e268833f9b884133a1ea, id = 88de437f-9c98-4e1d-96c0-7b433c99886a, last_modified = 2021-09-16
Source: 6217.1.0000000008048000.0000000008053000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_389ee3e9 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 59f2359dc1f41d385d639d157b4cd9fc73d76d8abb7cc09d47632bb4c9a39e6e, id = 389ee3e9-70c1-4c93-a999-292cf6ff1652, last_modified = 2022-01-26
Source: 6217.1.0000000008048000.0000000008053000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_cc93863b reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = f3ecd30f0b511a8e92cfa642409d559e7612c3f57a1659ca46c77aca809a00ac, id = cc93863b-1050-40ba-9d02-5ec9ce6a3a28, last_modified = 2022-01-26
Source: 6217.1.0000000008048000.0000000008053000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_8aa7b5d3 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 02a2c18c362df4b1fceb33f3b605586514ba9a00c7afedf71c04fa54d8146444, id = 8aa7b5d3-e1eb-4b55-b36a-0d3a242c06e9, last_modified = 2022-01-26
Source: classification engineClassification label: mal64.spre.linELF@0/0@5/0
Source: /tmp/x86.elf (PID: 6219)File opened: /proc/6241/mapsJump to behavior
Source: /tmp/x86.elf (PID: 6219)File opened: /proc/6241/cmdlineJump to behavior
Source: /tmp/x86.elf (PID: 6219)File opened: /proc/6240/mapsJump to behavior
Source: /tmp/x86.elf (PID: 6219)File opened: /proc/6240/cmdlineJump to behavior
Source: /tmp/x86.elf (PID: 6219)File opened: /proc/6251/mapsJump to behavior
Source: /tmp/x86.elf (PID: 6219)File opened: /proc/6251/cmdlineJump to behavior
Source: /tmp/x86.elf (PID: 6219)File opened: /proc/6232/mapsJump to behavior
Source: /tmp/x86.elf (PID: 6219)File opened: /proc/6232/cmdlineJump to behavior
Source: /tmp/x86.elf (PID: 6219)File opened: /proc/6243/mapsJump to behavior
Source: /tmp/x86.elf (PID: 6219)File opened: /proc/6243/cmdlineJump to behavior
Source: /tmp/x86.elf (PID: 6219)File opened: /proc/6242/mapsJump to behavior
Source: /tmp/x86.elf (PID: 6219)File opened: /proc/6242/cmdlineJump to behavior
Source: /tmp/x86.elf (PID: 6219)File opened: /proc/6234/mapsJump to behavior
Source: /tmp/x86.elf (PID: 6219)File opened: /proc/6234/cmdlineJump to behavior
Source: /tmp/x86.elf (PID: 6219)File opened: /proc/6245/mapsJump to behavior
Source: /tmp/x86.elf (PID: 6219)File opened: /proc/6245/cmdlineJump to behavior
Source: /tmp/x86.elf (PID: 6219)File opened: /proc/6233/mapsJump to behavior
Source: /tmp/x86.elf (PID: 6219)File opened: /proc/6233/cmdlineJump to behavior
Source: /tmp/x86.elf (PID: 6219)File opened: /proc/6244/mapsJump to behavior
Source: /tmp/x86.elf (PID: 6219)File opened: /proc/6244/cmdlineJump to behavior
Source: /tmp/x86.elf (PID: 6219)File opened: /proc/6288/mapsJump to behavior
Source: /tmp/x86.elf (PID: 6219)File opened: /proc/6288/cmdlineJump to behavior
Source: /tmp/x86.elf (PID: 6219)File opened: /proc/6236/mapsJump to behavior
Source: /tmp/x86.elf (PID: 6219)File opened: /proc/6236/cmdlineJump to behavior
Source: /tmp/x86.elf (PID: 6219)File opened: /proc/6247/mapsJump to behavior
Source: /tmp/x86.elf (PID: 6219)File opened: /proc/6247/cmdlineJump to behavior
Source: /tmp/x86.elf (PID: 6219)File opened: /proc/6302/mapsJump to behavior
Source: /tmp/x86.elf (PID: 6219)File opened: /proc/6302/cmdlineJump to behavior
Source: /tmp/x86.elf (PID: 6219)File opened: /proc/6235/mapsJump to behavior
Source: /tmp/x86.elf (PID: 6219)File opened: /proc/6235/cmdlineJump to behavior
Source: /tmp/x86.elf (PID: 6219)File opened: /proc/6246/mapsJump to behavior
Source: /tmp/x86.elf (PID: 6219)File opened: /proc/6246/cmdlineJump to behavior
Source: /tmp/x86.elf (PID: 6219)File opened: /proc/6250/mapsJump to behavior
Source: /tmp/x86.elf (PID: 6219)File opened: /proc/6250/cmdlineJump to behavior
Source: /tmp/x86.elf (PID: 6219)File opened: /proc/6238/mapsJump to behavior
Source: /tmp/x86.elf (PID: 6219)File opened: /proc/6238/cmdlineJump to behavior
Source: /tmp/x86.elf (PID: 6219)File opened: /proc/6249/mapsJump to behavior
Source: /tmp/x86.elf (PID: 6219)File opened: /proc/6249/cmdlineJump to behavior
Source: /tmp/x86.elf (PID: 6219)File opened: /proc/6237/mapsJump to behavior
Source: /tmp/x86.elf (PID: 6219)File opened: /proc/6237/cmdlineJump to behavior
Source: /tmp/x86.elf (PID: 6219)File opened: /proc/6248/mapsJump to behavior
Source: /tmp/x86.elf (PID: 6219)File opened: /proc/6248/cmdlineJump to behavior
Source: /tmp/x86.elf (PID: 6219)File opened: /proc/6239/mapsJump to behavior
Source: /tmp/x86.elf (PID: 6219)File opened: /proc/6239/cmdlineJump to behavior
Source: /tmp/x86.elf (PID: 6219)File opened: /proc/6307/mapsJump to behavior
Source: /tmp/x86.elf (PID: 6219)File opened: /proc/6307/cmdlineJump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity Information1
Scripting
Valid AccountsWindows Management Instrumentation1
Scripting
Path InterceptionDirect Volume Access1
OS Credential Dumping
System Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network Medium1
Service Stop
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Non-Standard Port
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
Non-Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture2
Application Layer Protocol
Traffic DuplicationData Destruction
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1583919 Sample: x86.elf Startdate: 03/01/2025 Architecture: LINUX Score: 64 17 secure-network-rebirthltd.ru 2->17 19 210.99.170.52, 13566, 51864 SEOULMETRO-ASSeoulMetropolitanGovernmentKR Korea Republic of 2->19 21 24 other IPs or domains 2->21 23 Malicious sample detected (through community Yara rule) 2->23 25 Multi AV Scanner detection for submitted file 2->25 27 Machine Learning detection for sample 2->27 8 x86.elf 2->8         started        signatures3 process4 process5 10 x86.elf 8->10         started        process6 12 x86.elf 10->12         started        15 x86.elf 10->15         started        signatures7 29 Sample tries to kill multiple processes (SIGKILL) 12->29

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
x86.elf39%ReversingLabsLinux.Backdoor.Mirai
x86.elf100%Joe Sandbox ML
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
secure-network-rebirthltd.ru
unknown
unknowntrue
    unknown
    • No. of IPs < 25%
    • 25% < No. of IPs < 50%
    • 50% < No. of IPs < 75%
    • 75% < No. of IPs
    IPDomainCountryFlagASNASN NameMalicious
    210.99.82.151
    unknownKorea Republic of
    4766KIXS-AS-KRKoreaTelecomKRfalse
    210.99.185.68
    unknownKorea Republic of
    4766KIXS-AS-KRKoreaTelecomKRfalse
    210.99.18.73
    unknownKorea Republic of
    4766KIXS-AS-KRKoreaTelecomKRfalse
    210.99.251.37
    unknownKorea Republic of
    17841NCIA-AS-KRNATIONALINFORMATIONRESOURCESSERVICEKRfalse
    210.99.238.249
    unknownKorea Republic of
    4766KIXS-AS-KRKoreaTelecomKRfalse
    210.99.15.188
    unknownKorea Republic of
    4766KIXS-AS-KRKoreaTelecomKRfalse
    210.99.170.52
    unknownKorea Republic of
    9647SEOULMETRO-ASSeoulMetropolitanGovernmentKRfalse
    91.189.91.43
    unknownUnited Kingdom
    41231CANONICAL-ASGBfalse
    91.189.91.42
    unknownUnited Kingdom
    41231CANONICAL-ASGBfalse
    210.99.167.219
    unknownKorea Republic of
    4766KIXS-AS-KRKoreaTelecomKRfalse
    210.99.91.209
    unknownKorea Republic of
    45400NICNETKoreaTelecomKRfalse
    83.222.191.90
    unknownBulgaria
    43561NET1-ASBGfalse
    109.202.202.202
    unknownSwitzerland
    13030INIT7CHfalse
    210.99.156.146
    unknownKorea Republic of
    9696EDAS-ASOscarEnterpriseKRfalse
    210.99.45.211
    unknownKorea Republic of
    4766KIXS-AS-KRKoreaTelecomKRfalse
    210.99.144.204
    unknownKorea Republic of
    4766KIXS-AS-KRKoreaTelecomKRfalse
    210.99.234.181
    unknownKorea Republic of
    4766KIXS-AS-KRKoreaTelecomKRfalse
    210.99.95.52
    unknownKorea Republic of
    4766KIXS-AS-KRKoreaTelecomKRfalse
    210.99.34.26
    unknownKorea Republic of
    4766KIXS-AS-KRKoreaTelecomKRfalse
    210.99.208.6
    unknownKorea Republic of
    4766KIXS-AS-KRKoreaTelecomKRfalse
    210.99.113.64
    unknownKorea Republic of
    4766KIXS-AS-KRKoreaTelecomKRfalse
    210.99.19.133
    unknownKorea Republic of
    4766KIXS-AS-KRKoreaTelecomKRfalse
    210.99.252.114
    unknownKorea Republic of
    17841NCIA-AS-KRNATIONALINFORMATIONRESOURCESSERVICEKRfalse
    210.99.235.231
    unknownKorea Republic of
    4766KIXS-AS-KRKoreaTelecomKRfalse
    210.99.179.142
    unknownKorea Republic of
    4766KIXS-AS-KRKoreaTelecomKRfalse
    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
    83.222.191.90arm7.elfGet hashmaliciousMiraiBrowse
      arm4.elfGet hashmaliciousUnknownBrowse
        m68k.elfGet hashmaliciousUnknownBrowse
          mips.elfGet hashmaliciousUnknownBrowse
            mpsl.elfGet hashmaliciousUnknownBrowse
              mpsl.elfGet hashmaliciousUnknownBrowse
                m68k.elfGet hashmaliciousMiraiBrowse
                  ppc.elfGet hashmaliciousMiraiBrowse
                    arm4.elfGet hashmaliciousMiraiBrowse
                      spc.elfGet hashmaliciousUnknownBrowse
                        109.202.202.202kpLwzBouH4.elfGet hashmaliciousUnknownBrowse
                        • ch.archive.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_92.0%2bbuild3-0ubuntu0.20.04.1_amd64.deb
                        91.189.91.43arm4.elfGet hashmaliciousUnknownBrowse
                          arm6.elfGet hashmaliciousUnknownBrowse
                            mpsl.elfGet hashmaliciousUnknownBrowse
                              ub8ehJSePAfc9FYqZIT6.i686.elfGet hashmaliciousUnknownBrowse
                                ub8ehJSePAfc9FYqZIT6.x86_64.elfGet hashmaliciousUnknownBrowse
                                  ub8ehJSePAfc9FYqZIT6.x86.elfGet hashmaliciousUnknownBrowse
                                    UDMp3dZ7nc.elfGet hashmaliciousXorDDoSBrowse
                                      nova2.elfGet hashmaliciousUnknownBrowse
                                        154.216.18.23-boatnet.arm7-2025-01-03T11_41_00.elfGet hashmaliciousMiraiBrowse
                                          g.elfGet hashmaliciousUnknownBrowse
                                            91.189.91.42arm4.elfGet hashmaliciousUnknownBrowse
                                              arm6.elfGet hashmaliciousUnknownBrowse
                                                mpsl.elfGet hashmaliciousUnknownBrowse
                                                  ub8ehJSePAfc9FYqZIT6.i686.elfGet hashmaliciousUnknownBrowse
                                                    ub8ehJSePAfc9FYqZIT6.sh4.elfGet hashmaliciousUnknownBrowse
                                                      ub8ehJSePAfc9FYqZIT6.x86_64.elfGet hashmaliciousUnknownBrowse
                                                        ub8ehJSePAfc9FYqZIT6.x86.elfGet hashmaliciousUnknownBrowse
                                                          UDMp3dZ7nc.elfGet hashmaliciousXorDDoSBrowse
                                                            nova2.elfGet hashmaliciousUnknownBrowse
                                                              154.216.18.23-boatnet.arm7-2025-01-03T11_41_00.elfGet hashmaliciousMiraiBrowse
                                                                No context
                                                                MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                NCIA-AS-KRNATIONALINFORMATIONRESOURCESSERVICEKRarm7.elfGet hashmaliciousMiraiBrowse
                                                                • 210.99.50.140
                                                                arm4.elfGet hashmaliciousUnknownBrowse
                                                                • 210.99.58.159
                                                                mips.elfGet hashmaliciousUnknownBrowse
                                                                • 210.99.58.148
                                                                mpsl.elfGet hashmaliciousUnknownBrowse
                                                                • 210.99.251.181
                                                                loligang.x86.elfGet hashmaliciousMiraiBrowse
                                                                • 152.99.11.225
                                                                mipsel.nn.elfGet hashmaliciousMirai, OkiruBrowse
                                                                • 27.101.40.27
                                                                x86_32.nn.elfGet hashmaliciousMirai, OkiruBrowse
                                                                • 152.99.241.255
                                                                arm7.nn-20241218-0633.elfGet hashmaliciousMirai, OkiruBrowse
                                                                • 203.241.53.42
                                                                rebirth.m68k.elfGet hashmaliciousMirai, OkiruBrowse
                                                                • 116.67.4.240
                                                                la.bot.arm6.elfGet hashmaliciousMiraiBrowse
                                                                • 116.67.4.223
                                                                KIXS-AS-KRKoreaTelecomKRarmv6l.elfGet hashmaliciousMiraiBrowse
                                                                • 183.120.140.88
                                                                arm7.elfGet hashmaliciousMiraiBrowse
                                                                • 210.99.13.2
                                                                arm4.elfGet hashmaliciousUnknownBrowse
                                                                • 210.99.96.5
                                                                m68k.elfGet hashmaliciousUnknownBrowse
                                                                • 210.99.235.155
                                                                mips.elfGet hashmaliciousUnknownBrowse
                                                                • 210.99.93.155
                                                                mpsl.elfGet hashmaliciousUnknownBrowse
                                                                • 210.99.224.65
                                                                armv5l.elfGet hashmaliciousMiraiBrowse
                                                                • 220.92.130.121
                                                                armv7l.elfGet hashmaliciousMiraiBrowse
                                                                • 221.161.77.61
                                                                armv4l.elfGet hashmaliciousMiraiBrowse
                                                                • 218.151.13.97
                                                                4.elfGet hashmaliciousUnknownBrowse
                                                                • 125.158.221.60
                                                                KIXS-AS-KRKoreaTelecomKRarmv6l.elfGet hashmaliciousMiraiBrowse
                                                                • 183.120.140.88
                                                                arm7.elfGet hashmaliciousMiraiBrowse
                                                                • 210.99.13.2
                                                                arm4.elfGet hashmaliciousUnknownBrowse
                                                                • 210.99.96.5
                                                                m68k.elfGet hashmaliciousUnknownBrowse
                                                                • 210.99.235.155
                                                                mips.elfGet hashmaliciousUnknownBrowse
                                                                • 210.99.93.155
                                                                mpsl.elfGet hashmaliciousUnknownBrowse
                                                                • 210.99.224.65
                                                                armv5l.elfGet hashmaliciousMiraiBrowse
                                                                • 220.92.130.121
                                                                armv7l.elfGet hashmaliciousMiraiBrowse
                                                                • 221.161.77.61
                                                                armv4l.elfGet hashmaliciousMiraiBrowse
                                                                • 218.151.13.97
                                                                4.elfGet hashmaliciousUnknownBrowse
                                                                • 125.158.221.60
                                                                KIXS-AS-KRKoreaTelecomKRarmv6l.elfGet hashmaliciousMiraiBrowse
                                                                • 183.120.140.88
                                                                arm7.elfGet hashmaliciousMiraiBrowse
                                                                • 210.99.13.2
                                                                arm4.elfGet hashmaliciousUnknownBrowse
                                                                • 210.99.96.5
                                                                m68k.elfGet hashmaliciousUnknownBrowse
                                                                • 210.99.235.155
                                                                mips.elfGet hashmaliciousUnknownBrowse
                                                                • 210.99.93.155
                                                                mpsl.elfGet hashmaliciousUnknownBrowse
                                                                • 210.99.224.65
                                                                armv5l.elfGet hashmaliciousMiraiBrowse
                                                                • 220.92.130.121
                                                                armv7l.elfGet hashmaliciousMiraiBrowse
                                                                • 221.161.77.61
                                                                armv4l.elfGet hashmaliciousMiraiBrowse
                                                                • 218.151.13.97
                                                                4.elfGet hashmaliciousUnknownBrowse
                                                                • 125.158.221.60
                                                                No context
                                                                No context
                                                                No created / dropped files found
                                                                File type:ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, stripped
                                                                Entropy (8bit):6.270284862385435
                                                                TrID:
                                                                • ELF Executable and Linkable format (Linux) (4029/14) 50.16%
                                                                • ELF Executable and Linkable format (generic) (4004/1) 49.84%
                                                                File name:x86.elf
                                                                File size:45'904 bytes
                                                                MD5:75c592fdbef6e2a717e94a7243747a55
                                                                SHA1:b75ac97b39dc661c5fdddff8b81b894af292b46e
                                                                SHA256:5e32cd9ca17361b8deea9202641ff4db44bbc56324ba81b880a457b62f892cac
                                                                SHA512:29d4ed63b50497e1d8eded924d0eb6128a44f656ffdabecab02ee5c707350331b96acf8d9e9832863689976f46507272036f41642b55bda383f8d36e85bbb320
                                                                SSDEEP:768:DaCgnDEPlIgqMtjBMxub1P1UAIMCTz377ooz2W2RXrA4vH:DaCtlIZSjBMK1dUAIlr7rz2WcbA4vH
                                                                TLSH:BB233AC8D943E4F0EC0616B124B7E7338773F97A102CF997D79DDA32A842A45A61B19C
                                                                File Content Preview:.ELF....................d...4...........4. ...(..............................................0...0......`...........Q.td............................U..S.......w....h........[]...$.............U......=.1...t..5....$0.....$0......u........t....h.)..........

                                                                ELF header

                                                                Class:ELF32
                                                                Data:2's complement, little endian
                                                                Version:1 (current)
                                                                Machine:Intel 80386
                                                                Version Number:0x1
                                                                Type:EXEC (Executable file)
                                                                OS/ABI:UNIX - System V
                                                                ABI Version:0
                                                                Entry Point Address:0x8048164
                                                                Flags:0x0
                                                                ELF Header Size:52
                                                                Program Header Offset:52
                                                                Program Header Size:32
                                                                Number of Program Headers:3
                                                                Section Header Offset:45504
                                                                Section Header Size:40
                                                                Number of Section Headers:10
                                                                Header String Table Index:9
                                                                NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                                                NULL0x00x00x00x00x0000
                                                                .initPROGBITS0x80480940x940x1c0x00x6AX001
                                                                .textPROGBITS0x80480b00xb00x9da60x00x6AX0016
                                                                .finiPROGBITS0x8051e560x9e560x170x00x6AX001
                                                                .rodataPROGBITS0x8051e800x9e800xb600x00x2A0032
                                                                .ctorsPROGBITS0x80530000xb0000x80x00x3WA004
                                                                .dtorsPROGBITS0x80530080xb0080x80x00x3WA004
                                                                .dataPROGBITS0x80530200xb0200x1600x00x3WA0032
                                                                .bssNOBITS0x80531800xb1800x4e00x00x3WA0032
                                                                .shstrtabSTRTAB0x00xb1800x3e0x00x0001
                                                                TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                                LOAD0x00x80480000x80480000xa9e00xa9e06.42570x5R E0x1000.init .text .fini .rodata
                                                                LOAD0xb0000x80530000x80530000x1800x6604.47580x6RW 0x1000.ctors .dtors .data .bss
                                                                GNU_STACK0x00x00x00x00x00.00000x6RW 0x4
                                                                TimestampSource PortDest PortSource IPDest IP
                                                                Jan 3, 2025 21:12:44.041968107 CET5424413566192.168.2.23210.99.167.219
                                                                Jan 3, 2025 21:12:44.041974068 CET4347413566192.168.2.23210.99.235.231
                                                                Jan 3, 2025 21:12:44.042025089 CET4725613566192.168.2.23210.99.234.181
                                                                Jan 3, 2025 21:12:44.042031050 CET6064013566192.168.2.23210.99.91.209
                                                                Jan 3, 2025 21:12:44.042030096 CET5113413566192.168.2.23210.99.82.151
                                                                Jan 3, 2025 21:12:44.042037010 CET4181613566192.168.2.23210.99.185.68
                                                                Jan 3, 2025 21:12:44.042061090 CET5571813566192.168.2.23210.99.251.37
                                                                Jan 3, 2025 21:12:44.042072058 CET5186413566192.168.2.23210.99.170.52
                                                                Jan 3, 2025 21:12:44.042077065 CET6067413566192.168.2.23210.99.19.133
                                                                Jan 3, 2025 21:12:44.042078972 CET4572413566192.168.2.23210.99.45.211
                                                                Jan 3, 2025 21:12:44.042098045 CET4221613566192.168.2.23210.99.34.26
                                                                Jan 3, 2025 21:12:44.042104959 CET3605813566192.168.2.23210.99.179.142
                                                                Jan 3, 2025 21:12:44.042110920 CET4446413566192.168.2.23210.99.252.114
                                                                Jan 3, 2025 21:12:44.042115927 CET4184013566192.168.2.23210.99.156.146
                                                                Jan 3, 2025 21:12:44.042138100 CET3782013566192.168.2.23210.99.95.52
                                                                Jan 3, 2025 21:12:44.042140007 CET3787013566192.168.2.23210.99.208.6
                                                                Jan 3, 2025 21:12:44.042146921 CET5102813566192.168.2.23210.99.15.188
                                                                Jan 3, 2025 21:12:44.042146921 CET3916213566192.168.2.23210.99.238.249
                                                                Jan 3, 2025 21:12:44.042160988 CET3843013566192.168.2.23210.99.113.64
                                                                Jan 3, 2025 21:12:44.042170048 CET5486613566192.168.2.23210.99.144.204
                                                                Jan 3, 2025 21:12:44.042181969 CET5927213566192.168.2.23210.99.18.73
                                                                Jan 3, 2025 21:12:44.047087908 CET1356654244210.99.167.219192.168.2.23
                                                                Jan 3, 2025 21:12:44.047105074 CET1356643474210.99.235.231192.168.2.23
                                                                Jan 3, 2025 21:12:44.047152042 CET5424413566192.168.2.23210.99.167.219
                                                                Jan 3, 2025 21:12:44.047156096 CET4347413566192.168.2.23210.99.235.231
                                                                Jan 3, 2025 21:12:44.047161102 CET1356660640210.99.91.209192.168.2.23
                                                                Jan 3, 2025 21:12:44.047173977 CET1356641816210.99.185.68192.168.2.23
                                                                Jan 3, 2025 21:12:44.047188044 CET1356647256210.99.234.181192.168.2.23
                                                                Jan 3, 2025 21:12:44.047199965 CET1356655718210.99.251.37192.168.2.23
                                                                Jan 3, 2025 21:12:44.047203064 CET6064013566192.168.2.23210.99.91.209
                                                                Jan 3, 2025 21:12:44.047208071 CET4181613566192.168.2.23210.99.185.68
                                                                Jan 3, 2025 21:12:44.047213078 CET1356651134210.99.82.151192.168.2.23
                                                                Jan 3, 2025 21:12:44.047224045 CET4725613566192.168.2.23210.99.234.181
                                                                Jan 3, 2025 21:12:44.047224045 CET5571813566192.168.2.23210.99.251.37
                                                                Jan 3, 2025 21:12:44.047233105 CET1356651864210.99.170.52192.168.2.23
                                                                Jan 3, 2025 21:12:44.047245026 CET5113413566192.168.2.23210.99.82.151
                                                                Jan 3, 2025 21:12:44.047246933 CET1356645724210.99.45.211192.168.2.23
                                                                Jan 3, 2025 21:12:44.047259092 CET1356660674210.99.19.133192.168.2.23
                                                                Jan 3, 2025 21:12:44.047270060 CET5186413566192.168.2.23210.99.170.52
                                                                Jan 3, 2025 21:12:44.047271013 CET1356642216210.99.34.26192.168.2.23
                                                                Jan 3, 2025 21:12:44.047272921 CET4572413566192.168.2.23210.99.45.211
                                                                Jan 3, 2025 21:12:44.047283888 CET1356641840210.99.156.146192.168.2.23
                                                                Jan 3, 2025 21:12:44.047286034 CET6067413566192.168.2.23210.99.19.133
                                                                Jan 3, 2025 21:12:44.047298908 CET1356636058210.99.179.142192.168.2.23
                                                                Jan 3, 2025 21:12:44.047307014 CET4221613566192.168.2.23210.99.34.26
                                                                Jan 3, 2025 21:12:44.047317028 CET4184013566192.168.2.23210.99.156.146
                                                                Jan 3, 2025 21:12:44.047321081 CET1356644464210.99.252.114192.168.2.23
                                                                Jan 3, 2025 21:12:44.047328949 CET3605813566192.168.2.23210.99.179.142
                                                                Jan 3, 2025 21:12:44.047333956 CET1356637820210.99.95.52192.168.2.23
                                                                Jan 3, 2025 21:12:44.047348022 CET1356637870210.99.208.6192.168.2.23
                                                                Jan 3, 2025 21:12:44.047359943 CET4446413566192.168.2.23210.99.252.114
                                                                Jan 3, 2025 21:12:44.047359943 CET1356651028210.99.15.188192.168.2.23
                                                                Jan 3, 2025 21:12:44.047359943 CET3782013566192.168.2.23210.99.95.52
                                                                Jan 3, 2025 21:12:44.047375917 CET3787013566192.168.2.23210.99.208.6
                                                                Jan 3, 2025 21:12:44.047391891 CET5102813566192.168.2.23210.99.15.188
                                                                Jan 3, 2025 21:12:44.051873922 CET1356639162210.99.238.249192.168.2.23
                                                                Jan 3, 2025 21:12:44.051887989 CET1356638430210.99.113.64192.168.2.23
                                                                Jan 3, 2025 21:12:44.051901102 CET1356654866210.99.144.204192.168.2.23
                                                                Jan 3, 2025 21:12:44.051913023 CET1356659272210.99.18.73192.168.2.23
                                                                Jan 3, 2025 21:12:44.051943064 CET3843013566192.168.2.23210.99.113.64
                                                                Jan 3, 2025 21:12:44.051943064 CET5486613566192.168.2.23210.99.144.204
                                                                Jan 3, 2025 21:12:44.051944017 CET3916213566192.168.2.23210.99.238.249
                                                                Jan 3, 2025 21:12:44.051985025 CET5927213566192.168.2.23210.99.18.73
                                                                Jan 3, 2025 21:12:44.083518028 CET4258013566192.168.2.2383.222.191.90
                                                                Jan 3, 2025 21:12:44.088265896 CET135664258083.222.191.90192.168.2.23
                                                                Jan 3, 2025 21:12:44.088331938 CET4258013566192.168.2.2383.222.191.90
                                                                Jan 3, 2025 21:12:44.088345051 CET4258013566192.168.2.2383.222.191.90
                                                                Jan 3, 2025 21:12:44.093127012 CET135664258083.222.191.90192.168.2.23
                                                                Jan 3, 2025 21:12:44.093178988 CET4258013566192.168.2.2383.222.191.90
                                                                Jan 3, 2025 21:12:44.098010063 CET135664258083.222.191.90192.168.2.23
                                                                Jan 3, 2025 21:12:45.174951077 CET43928443192.168.2.2391.189.91.42
                                                                Jan 3, 2025 21:12:50.550189972 CET42836443192.168.2.2391.189.91.43
                                                                Jan 3, 2025 21:12:52.086136103 CET4251680192.168.2.23109.202.202.202
                                                                Jan 3, 2025 21:12:54.097074032 CET4258013566192.168.2.2383.222.191.90
                                                                Jan 3, 2025 21:12:54.101949930 CET135664258083.222.191.90192.168.2.23
                                                                Jan 3, 2025 21:12:54.329761982 CET135664258083.222.191.90192.168.2.23
                                                                Jan 3, 2025 21:12:54.330068111 CET4258013566192.168.2.2383.222.191.90
                                                                Jan 3, 2025 21:12:54.784728050 CET135664258083.222.191.90192.168.2.23
                                                                Jan 3, 2025 21:12:54.784786940 CET4258013566192.168.2.2383.222.191.90
                                                                Jan 3, 2025 21:13:05.652133942 CET43928443192.168.2.2391.189.91.42
                                                                Jan 3, 2025 21:13:17.938505888 CET42836443192.168.2.2391.189.91.43
                                                                Jan 3, 2025 21:13:22.033998013 CET4251680192.168.2.23109.202.202.202
                                                                Jan 3, 2025 21:13:46.606553078 CET43928443192.168.2.2391.189.91.42
                                                                Jan 3, 2025 21:13:54.825417995 CET4258013566192.168.2.2383.222.191.90
                                                                Jan 3, 2025 21:13:54.830310106 CET135664258083.222.191.90192.168.2.23
                                                                Jan 3, 2025 21:13:55.027185917 CET135664258083.222.191.90192.168.2.23
                                                                Jan 3, 2025 21:13:55.027292967 CET4258013566192.168.2.2383.222.191.90
                                                                Jan 3, 2025 21:13:55.783409119 CET135664258083.222.191.90192.168.2.23
                                                                Jan 3, 2025 21:13:55.783488989 CET4258013566192.168.2.2383.222.191.90
                                                                TimestampSource PortDest PortSource IPDest IP
                                                                Jan 3, 2025 21:12:44.045002937 CET6004353192.168.2.238.8.8.8
                                                                Jan 3, 2025 21:12:44.054442883 CET53600438.8.8.8192.168.2.23
                                                                Jan 3, 2025 21:12:44.054528952 CET4405553192.168.2.238.8.8.8
                                                                Jan 3, 2025 21:12:44.061681032 CET53440558.8.8.8192.168.2.23
                                                                Jan 3, 2025 21:12:44.061748981 CET5501753192.168.2.238.8.8.8
                                                                Jan 3, 2025 21:12:44.069053888 CET53550178.8.8.8192.168.2.23
                                                                Jan 3, 2025 21:12:44.069118023 CET5694453192.168.2.238.8.8.8
                                                                Jan 3, 2025 21:12:44.076283932 CET53569448.8.8.8192.168.2.23
                                                                Jan 3, 2025 21:12:44.076486111 CET5901653192.168.2.238.8.8.8
                                                                Jan 3, 2025 21:12:44.083425999 CET53590168.8.8.8192.168.2.23
                                                                TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                                                Jan 3, 2025 21:12:44.045002937 CET192.168.2.238.8.8.80x9274Standard query (0)secure-network-rebirthltd.ruA (IP address)IN (0x0001)false
                                                                Jan 3, 2025 21:12:44.054528952 CET192.168.2.238.8.8.80x9274Standard query (0)secure-network-rebirthltd.ruA (IP address)IN (0x0001)false
                                                                Jan 3, 2025 21:12:44.061748981 CET192.168.2.238.8.8.80x9274Standard query (0)secure-network-rebirthltd.ruA (IP address)IN (0x0001)false
                                                                Jan 3, 2025 21:12:44.069118023 CET192.168.2.238.8.8.80x9274Standard query (0)secure-network-rebirthltd.ruA (IP address)IN (0x0001)false
                                                                Jan 3, 2025 21:12:44.076486111 CET192.168.2.238.8.8.80x9274Standard query (0)secure-network-rebirthltd.ruA (IP address)IN (0x0001)false
                                                                TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                                                Jan 3, 2025 21:12:44.054442883 CET8.8.8.8192.168.2.230x9274Name error (3)secure-network-rebirthltd.runonenoneA (IP address)IN (0x0001)false
                                                                Jan 3, 2025 21:12:44.061681032 CET8.8.8.8192.168.2.230x9274Name error (3)secure-network-rebirthltd.runonenoneA (IP address)IN (0x0001)false
                                                                Jan 3, 2025 21:12:44.069053888 CET8.8.8.8192.168.2.230x9274Name error (3)secure-network-rebirthltd.runonenoneA (IP address)IN (0x0001)false
                                                                Jan 3, 2025 21:12:44.076283932 CET8.8.8.8192.168.2.230x9274Name error (3)secure-network-rebirthltd.runonenoneA (IP address)IN (0x0001)false
                                                                Jan 3, 2025 21:12:44.083425999 CET8.8.8.8192.168.2.230x9274Name error (3)secure-network-rebirthltd.runonenoneA (IP address)IN (0x0001)false

                                                                System Behavior

                                                                Start time (UTC):20:12:43
                                                                Start date (UTC):03/01/2025
                                                                Path:/tmp/x86.elf
                                                                Arguments:/tmp/x86.elf
                                                                File size:45904 bytes
                                                                MD5 hash:75c592fdbef6e2a717e94a7243747a55

                                                                Start time (UTC):20:12:43
                                                                Start date (UTC):03/01/2025
                                                                Path:/tmp/x86.elf
                                                                Arguments:-
                                                                File size:45904 bytes
                                                                MD5 hash:75c592fdbef6e2a717e94a7243747a55

                                                                Start time (UTC):20:12:43
                                                                Start date (UTC):03/01/2025
                                                                Path:/tmp/x86.elf
                                                                Arguments:-
                                                                File size:45904 bytes
                                                                MD5 hash:75c592fdbef6e2a717e94a7243747a55

                                                                Start time (UTC):20:12:43
                                                                Start date (UTC):03/01/2025
                                                                Path:/tmp/x86.elf
                                                                Arguments:-
                                                                File size:45904 bytes
                                                                MD5 hash:75c592fdbef6e2a717e94a7243747a55