Edit tour
Linux
Analysis Report
x86_64.elf
Overview
General Information
Sample name: | x86_64.elf |
Analysis ID: | 1583933 |
MD5: | ed891007b83f07e55a4dfb6e92b1a1cc |
SHA1: | e25fd8410dda41b3f4005b0e1dc66f9ee1951358 |
SHA256: | b75eab90673b94fd015bc817741fe37bfaee97166f5430e327c578bd57622349 |
Tags: | elfuser-abuse_ch |
Infos: |
Detection
Score: | 64 |
Range: | 0 - 100 |
Whitelisted: | false |
Signatures
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Machine Learning detection for sample
Sample tries to kill multiple processes (SIGKILL)
Detected TCP or UDP traffic on non-standard ports
Enumerates processes within the "proc" file system
Found strings indicative of a multi-platform dropper
Sample contains strings indicative of BusyBox which embeds multiple Unix commands in a single executable
Sample has stripped symbol table
Sample listens on a socket
Sample tries to kill a process (SIGKILL)
Tries to resolve domain names, but no domain seems valid (expired dropper behavior)
Yara signature match
Classification
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1583933 |
Start date and time: | 2025-01-03 21:42:06 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 5m 51s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultlinuxfilecookbook.jbs |
Analysis system description: | Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11) |
Analysis Mode: | default |
Sample name: | x86_64.elf |
Detection: | MAL |
Classification: | mal64.spre.linELF@0/0@5/0 |
- Connection to analysis system has been lost, crash info: Unknown
- VT rate limit hit for: x86_64.elf
Command: | /tmp/x86_64.elf |
PID: | 5454 |
Exit Code: | 0 |
Exit Code Info: | |
Killed: | False |
Standard Output: | dear |
Standard Error: |
- system is lnxubuntu20
- x86_64.elf New Fork (PID: 5455, Parent: 5454)
- x86_64.elf New Fork (PID: 5456, Parent: 5455)
- x86_64.elf New Fork (PID: 5457, Parent: 5455)
- cleanup
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
Linux_Trojan_Gafgyt_9e9530a7 | unknown | unknown |
| |
Linux_Trojan_Gafgyt_807911a2 | unknown | unknown |
| |
Linux_Trojan_Gafgyt_d4227dbf | unknown | unknown |
| |
Linux_Trojan_Gafgyt_620087b9 | unknown | unknown |
| |
Linux_Trojan_Gafgyt_33b4111a | unknown | unknown |
| |
Click to see the 3 entries |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
Linux_Trojan_Gafgyt_9e9530a7 | unknown | unknown |
| |
Linux_Trojan_Gafgyt_807911a2 | unknown | unknown |
| |
Linux_Trojan_Gafgyt_d4227dbf | unknown | unknown |
| |
Linux_Trojan_Gafgyt_620087b9 | unknown | unknown |
| |
Linux_Trojan_Gafgyt_33b4111a | unknown | unknown |
| |
Click to see the 3 entries |
⊘No Suricata rule has matched
Click to jump to signature section
Show All Signature Results
AV Detection |
---|
Source: | ReversingLabs: |
Source: | Joe Sandbox ML: |
Source: | String: |
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: |
Source: | Socket: | Jump to behavior |
Source: | DNS traffic detected: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: |
Source: | DNS traffic detected: |
System Summary |
---|
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior |
Source: | String containing 'busybox' found: | ||
Source: | String containing 'busybox' found: |
Source: | .symtab present: |
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior |
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Classification label: |
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | 1 Scripting | Valid Accounts | Windows Management Instrumentation | 1 Scripting | Path Interception | Direct Volume Access | 1 OS Credential Dumping | System Service Discovery | Remote Services | Data from Local System | 1 Non-Standard Port | Exfiltration Over Other Network Medium | 1 Service Stop |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | Rootkit | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 1 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 1 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
⊘No configs have been found
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
29% | ReversingLabs | Linux.Backdoor.Mirai | ||
100% | Joe Sandbox ML |
⊘No Antivirus matches
⊘No Antivirus matches
⊘No Antivirus matches
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
secure-network-rebirthltd.ru | unknown | unknown | true | unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
210.99.62.0 | unknown | Korea Republic of | 17841 | NCIA-AS-KRNATIONALINFORMATIONRESOURCESSERVICEKR | false | |
210.99.64.36 | unknown | Korea Republic of | 4766 | KIXS-AS-KRKoreaTelecomKR | false | |
210.99.33.147 | unknown | Korea Republic of | 4766 | KIXS-AS-KRKoreaTelecomKR | false | |
210.99.159.53 | unknown | Korea Republic of | 45400 | NICNETKoreaTelecomKR | false | |
210.99.39.92 | unknown | Korea Republic of | 4766 | KIXS-AS-KRKoreaTelecomKR | false | |
210.99.100.134 | unknown | Korea Republic of | 4766 | KIXS-AS-KRKoreaTelecomKR | false | |
210.99.46.108 | unknown | Korea Republic of | 4766 | KIXS-AS-KRKoreaTelecomKR | false | |
210.99.42.127 | unknown | Korea Republic of | 4766 | KIXS-AS-KRKoreaTelecomKR | false | |
210.99.4.109 | unknown | Korea Republic of | 4766 | KIXS-AS-KRKoreaTelecomKR | false | |
210.99.66.152 | unknown | Korea Republic of | 4766 | KIXS-AS-KRKoreaTelecomKR | false | |
210.99.83.136 | unknown | Korea Republic of | 4766 | KIXS-AS-KRKoreaTelecomKR | false | |
210.99.222.226 | unknown | Korea Republic of | 4766 | KIXS-AS-KRKoreaTelecomKR | false | |
210.99.203.215 | unknown | Korea Republic of | 9696 | EDAS-ASOscarEnterpriseKR | false | |
210.99.24.3 | unknown | Korea Republic of | 17841 | NCIA-AS-KRNATIONALINFORMATIONRESOURCESSERVICEKR | false | |
210.99.98.72 | unknown | Korea Republic of | 4766 | KIXS-AS-KRKoreaTelecomKR | false | |
210.99.86.154 | unknown | Korea Republic of | 4766 | KIXS-AS-KRKoreaTelecomKR | false | |
210.99.81.8 | unknown | Korea Republic of | 17600 | ENVICO-AS-KRKOREARESOURCESRECOVERYANDREUTILIZATIONCORP | false | |
210.99.228.38 | unknown | Korea Republic of | 4766 | KIXS-AS-KRKoreaTelecomKR | false | |
210.99.145.114 | unknown | Korea Republic of | 4766 | KIXS-AS-KRKoreaTelecomKR | false | |
210.99.27.168 | unknown | Korea Republic of | 17841 | NCIA-AS-KRNATIONALINFORMATIONRESOURCESSERVICEKR | false | |
210.99.234.158 | unknown | Korea Republic of | 4766 | KIXS-AS-KRKoreaTelecomKR | false | |
210.99.178.86 | unknown | Korea Republic of | 4766 | KIXS-AS-KRKoreaTelecomKR | false | |
210.99.133.95 | unknown | Korea Republic of | 4766 | KIXS-AS-KRKoreaTelecomKR | false | |
83.222.191.90 | unknown | Bulgaria | 43561 | NET1-ASBG | false | |
210.99.105.26 | unknown | Korea Republic of | 4766 | KIXS-AS-KRKoreaTelecomKR | false | |
210.99.159.41 | unknown | Korea Republic of | 45400 | NICNETKoreaTelecomKR | false | |
210.99.94.184 | unknown | Korea Republic of | 4766 | KIXS-AS-KRKoreaTelecomKR | false | |
210.99.173.147 | unknown | Korea Republic of | 45400 | NICNETKoreaTelecomKR | false | |
210.99.23.191 | unknown | Korea Republic of | 4766 | KIXS-AS-KRKoreaTelecomKR | false | |
210.99.52.99 | unknown | Korea Republic of | 17841 | NCIA-AS-KRNATIONALINFORMATIONRESOURCESSERVICEKR | false | |
210.99.56.147 | unknown | Korea Republic of | 17841 | NCIA-AS-KRNATIONALINFORMATIONRESOURCESSERVICEKR | false | |
210.99.32.179 | unknown | Korea Republic of | 4766 | KIXS-AS-KRKoreaTelecomKR | false | |
210.99.117.64 | unknown | Korea Republic of | 4766 | KIXS-AS-KRKoreaTelecomKR | false | |
210.99.150.5 | unknown | Korea Republic of | 4766 | KIXS-AS-KRKoreaTelecomKR | false | |
210.99.112.151 | unknown | Korea Republic of | 4766 | KIXS-AS-KRKoreaTelecomKR | false | |
210.99.132.5 | unknown | Korea Republic of | 4766 | KIXS-AS-KRKoreaTelecomKR | false | |
210.99.114.242 | unknown | Korea Republic of | 4766 | KIXS-AS-KRKoreaTelecomKR | false |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
83.222.191.90 | Get hash | malicious | Unknown | Browse | ||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Mirai | Browse |
⊘No context
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
NCIA-AS-KRNATIONALINFORMATIONRESOURCESSERVICEKR | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai, Okiru | Browse |
| ||
Get hash | malicious | Mirai, Okiru | Browse |
| ||
Get hash | malicious | Mirai, Okiru | Browse |
| ||
NICNETKoreaTelecomKR | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai, Moobot, Okiru | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
KIXS-AS-KRKoreaTelecomKR | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
KIXS-AS-KRKoreaTelecomKR | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
|
⊘No context
⊘No context
⊘No created / dropped files found
File type: | |
Entropy (8bit): | 5.991012329464663 |
TrID: |
|
File name: | x86_64.elf |
File size: | 50'464 bytes |
MD5: | ed891007b83f07e55a4dfb6e92b1a1cc |
SHA1: | e25fd8410dda41b3f4005b0e1dc66f9ee1951358 |
SHA256: | b75eab90673b94fd015bc817741fe37bfaee97166f5430e327c578bd57622349 |
SHA512: | 93009a3a0212f713370ad8fd9e636b6eabf5b260abcee7977da70354099ca89fbf52398f7d2442d8c6a4d42b63487f0b74629ea3352f4136c955573c8e6a55bf |
SSDEEP: | 1536:tFd1tcGNKHpG156FBNtvPf5HG0gPpN9T77777777777777777L7777777L777O7y:V1tvKJGTeNPf5HcpN9T777777777777/ |
TLSH: | AD332907F942C0FDC459C6B00E67B53AC57735BEC239B2A677D4FB26A885F111E29848 |
File Content Preview: | .ELF..............>.......@.....@...................@.8...@.......................@.......@...............................................P.......P.....`.......................Q.td....................................................H...._....*...H........ |
ELF header | |
---|---|
Class: | |
Data: | |
Version: | |
Machine: | |
Version Number: | |
Type: | |
OS/ABI: | |
ABI Version: | 0 |
Entry Point Address: | |
Flags: | |
ELF Header Size: | 64 |
Program Header Offset: | 64 |
Program Header Size: | 56 |
Number of Program Headers: | 3 |
Section Header Offset: | 49824 |
Section Header Size: | 64 |
Number of Section Headers: | 10 |
Header String Table Index: | 9 |
Name | Type | Address | Offset | Size | EntSize | Flags | Flags Description | Link | Info | Align |
---|---|---|---|---|---|---|---|---|---|---|
NULL | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0 | 0 | 0 | ||
.init | PROGBITS | 0x4000e8 | 0xe8 | 0x13 | 0x0 | 0x6 | AX | 0 | 0 | 1 |
.text | PROGBITS | 0x400100 | 0x100 | 0xaa56 | 0x0 | 0x6 | AX | 0 | 0 | 16 |
.fini | PROGBITS | 0x40ab56 | 0xab56 | 0xe | 0x0 | 0x6 | AX | 0 | 0 | 1 |
.rodata | PROGBITS | 0x40ab80 | 0xab80 | 0xe00 | 0x0 | 0x2 | A | 0 | 0 | 32 |
.ctors | PROGBITS | 0x50c000 | 0xc000 | 0x10 | 0x0 | 0x3 | WA | 0 | 0 | 8 |
.dtors | PROGBITS | 0x50c010 | 0xc010 | 0x10 | 0x0 | 0x3 | WA | 0 | 0 | 8 |
.data | PROGBITS | 0x50c040 | 0xc040 | 0x220 | 0x0 | 0x3 | WA | 0 | 0 | 32 |
.bss | NOBITS | 0x50c260 | 0xc260 | 0x8a8 | 0x0 | 0x3 | WA | 0 | 0 | 32 |
.shstrtab | STRTAB | 0x0 | 0xc260 | 0x3e | 0x0 | 0x0 | 0 | 0 | 1 |
Type | Offset | Virtual Address | Physical Address | File Size | Memory Size | Entropy | Flags | Flags Description | Align | Prog Interpreter | Section Mappings |
---|---|---|---|---|---|---|---|---|---|---|---|
LOAD | 0x0 | 0x400000 | 0x400000 | 0xb980 | 0xb980 | 6.1809 | 0x5 | R E | 0x100000 | .init .text .fini .rodata | |
LOAD | 0xc000 | 0x50c000 | 0x50c000 | 0x260 | 0xb08 | 3.1542 | 0x6 | RW | 0x100000 | .ctors .dtors .data .bss | |
GNU_STACK | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0.0000 | 0x6 | RW | 0x8 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jan 3, 2025 21:42:51.250031948 CET | 44246 | 13566 | 192.168.2.13 | 210.99.132.5 |
Jan 3, 2025 21:42:51.252392054 CET | 41314 | 13566 | 192.168.2.13 | 210.99.159.41 |
Jan 3, 2025 21:42:51.253844976 CET | 52158 | 13566 | 192.168.2.13 | 210.99.228.38 |
Jan 3, 2025 21:42:51.255100012 CET | 13566 | 44246 | 210.99.132.5 | 192.168.2.13 |
Jan 3, 2025 21:42:51.255152941 CET | 44246 | 13566 | 192.168.2.13 | 210.99.132.5 |
Jan 3, 2025 21:42:51.256417990 CET | 55814 | 13566 | 192.168.2.13 | 210.99.81.8 |
Jan 3, 2025 21:42:51.257322073 CET | 13566 | 41314 | 210.99.159.41 | 192.168.2.13 |
Jan 3, 2025 21:42:51.257391930 CET | 41314 | 13566 | 192.168.2.13 | 210.99.159.41 |
Jan 3, 2025 21:42:51.257919073 CET | 36224 | 13566 | 192.168.2.13 | 210.99.159.53 |
Jan 3, 2025 21:42:51.258661985 CET | 13566 | 52158 | 210.99.228.38 | 192.168.2.13 |
Jan 3, 2025 21:42:51.258708954 CET | 52158 | 13566 | 192.168.2.13 | 210.99.228.38 |
Jan 3, 2025 21:42:51.259016991 CET | 47182 | 13566 | 192.168.2.13 | 210.99.52.99 |
Jan 3, 2025 21:42:51.260198116 CET | 42452 | 13566 | 192.168.2.13 | 210.99.112.151 |
Jan 3, 2025 21:42:51.261226892 CET | 46204 | 13566 | 192.168.2.13 | 210.99.100.134 |
Jan 3, 2025 21:42:51.261315107 CET | 13566 | 55814 | 210.99.81.8 | 192.168.2.13 |
Jan 3, 2025 21:42:51.261358023 CET | 55814 | 13566 | 192.168.2.13 | 210.99.81.8 |
Jan 3, 2025 21:42:51.262435913 CET | 44586 | 13566 | 192.168.2.13 | 210.99.66.152 |
Jan 3, 2025 21:42:51.262679100 CET | 13566 | 36224 | 210.99.159.53 | 192.168.2.13 |
Jan 3, 2025 21:42:51.262721062 CET | 36224 | 13566 | 192.168.2.13 | 210.99.159.53 |
Jan 3, 2025 21:42:51.263478041 CET | 41822 | 13566 | 192.168.2.13 | 210.99.145.114 |
Jan 3, 2025 21:42:51.263803005 CET | 13566 | 47182 | 210.99.52.99 | 192.168.2.13 |
Jan 3, 2025 21:42:51.263856888 CET | 47182 | 13566 | 192.168.2.13 | 210.99.52.99 |
Jan 3, 2025 21:42:51.264687061 CET | 37202 | 13566 | 192.168.2.13 | 210.99.203.215 |
Jan 3, 2025 21:42:51.265008926 CET | 13566 | 42452 | 210.99.112.151 | 192.168.2.13 |
Jan 3, 2025 21:42:51.265067101 CET | 42452 | 13566 | 192.168.2.13 | 210.99.112.151 |
Jan 3, 2025 21:42:51.265753031 CET | 52022 | 13566 | 192.168.2.13 | 210.99.39.92 |
Jan 3, 2025 21:42:51.266048908 CET | 13566 | 46204 | 210.99.100.134 | 192.168.2.13 |
Jan 3, 2025 21:42:51.266078949 CET | 46204 | 13566 | 192.168.2.13 | 210.99.100.134 |
Jan 3, 2025 21:42:51.267030001 CET | 38238 | 13566 | 192.168.2.13 | 210.99.105.26 |
Jan 3, 2025 21:42:51.267473936 CET | 13566 | 44586 | 210.99.66.152 | 192.168.2.13 |
Jan 3, 2025 21:42:51.267514944 CET | 44586 | 13566 | 192.168.2.13 | 210.99.66.152 |
Jan 3, 2025 21:42:51.268117905 CET | 33094 | 13566 | 192.168.2.13 | 210.99.117.64 |
Jan 3, 2025 21:42:51.268623114 CET | 13566 | 41822 | 210.99.145.114 | 192.168.2.13 |
Jan 3, 2025 21:42:51.268661976 CET | 41822 | 13566 | 192.168.2.13 | 210.99.145.114 |
Jan 3, 2025 21:42:51.269309998 CET | 40982 | 13566 | 192.168.2.13 | 210.99.4.109 |
Jan 3, 2025 21:42:51.269781113 CET | 13566 | 37202 | 210.99.203.215 | 192.168.2.13 |
Jan 3, 2025 21:42:51.269823074 CET | 37202 | 13566 | 192.168.2.13 | 210.99.203.215 |
Jan 3, 2025 21:42:51.270323992 CET | 34336 | 13566 | 192.168.2.13 | 210.99.83.136 |
Jan 3, 2025 21:42:51.270863056 CET | 13566 | 52022 | 210.99.39.92 | 192.168.2.13 |
Jan 3, 2025 21:42:51.270905018 CET | 52022 | 13566 | 192.168.2.13 | 210.99.39.92 |
Jan 3, 2025 21:42:51.271491051 CET | 59526 | 13566 | 192.168.2.13 | 210.99.114.242 |
Jan 3, 2025 21:42:51.272269964 CET | 13566 | 38238 | 210.99.105.26 | 192.168.2.13 |
Jan 3, 2025 21:42:51.272309065 CET | 38238 | 13566 | 192.168.2.13 | 210.99.105.26 |
Jan 3, 2025 21:42:51.272495031 CET | 52712 | 13566 | 192.168.2.13 | 210.99.178.86 |
Jan 3, 2025 21:42:51.273430109 CET | 13566 | 33094 | 210.99.117.64 | 192.168.2.13 |
Jan 3, 2025 21:42:51.273475885 CET | 33094 | 13566 | 192.168.2.13 | 210.99.117.64 |
Jan 3, 2025 21:42:51.273658991 CET | 44556 | 13566 | 192.168.2.13 | 210.99.24.3 |
Jan 3, 2025 21:42:51.274601936 CET | 13566 | 40982 | 210.99.4.109 | 192.168.2.13 |
Jan 3, 2025 21:42:51.274646044 CET | 40982 | 13566 | 192.168.2.13 | 210.99.4.109 |
Jan 3, 2025 21:42:51.274671078 CET | 36304 | 13566 | 192.168.2.13 | 210.99.94.184 |
Jan 3, 2025 21:42:51.275666952 CET | 13566 | 34336 | 210.99.83.136 | 192.168.2.13 |
Jan 3, 2025 21:42:51.275708914 CET | 34336 | 13566 | 192.168.2.13 | 210.99.83.136 |
Jan 3, 2025 21:42:51.275916100 CET | 45932 | 13566 | 192.168.2.13 | 210.99.56.147 |
Jan 3, 2025 21:42:51.276941061 CET | 53820 | 13566 | 192.168.2.13 | 210.99.27.168 |
Jan 3, 2025 21:42:51.277064085 CET | 13566 | 59526 | 210.99.114.242 | 192.168.2.13 |
Jan 3, 2025 21:42:51.277106047 CET | 59526 | 13566 | 192.168.2.13 | 210.99.114.242 |
Jan 3, 2025 21:42:51.278158903 CET | 43710 | 13566 | 192.168.2.13 | 210.99.42.127 |
Jan 3, 2025 21:42:51.278201103 CET | 13566 | 52712 | 210.99.178.86 | 192.168.2.13 |
Jan 3, 2025 21:42:51.278233051 CET | 52712 | 13566 | 192.168.2.13 | 210.99.178.86 |
Jan 3, 2025 21:42:51.279175043 CET | 48658 | 13566 | 192.168.2.13 | 210.99.46.108 |
Jan 3, 2025 21:42:51.279383898 CET | 13566 | 44556 | 210.99.24.3 | 192.168.2.13 |
Jan 3, 2025 21:42:51.279424906 CET | 44556 | 13566 | 192.168.2.13 | 210.99.24.3 |
Jan 3, 2025 21:42:51.280406952 CET | 47132 | 13566 | 192.168.2.13 | 210.99.23.191 |
Jan 3, 2025 21:42:51.280466080 CET | 13566 | 36304 | 210.99.94.184 | 192.168.2.13 |
Jan 3, 2025 21:42:51.280503988 CET | 36304 | 13566 | 192.168.2.13 | 210.99.94.184 |
Jan 3, 2025 21:42:51.281434059 CET | 34536 | 13566 | 192.168.2.13 | 210.99.222.226 |
Jan 3, 2025 21:42:51.281899929 CET | 13566 | 45932 | 210.99.56.147 | 192.168.2.13 |
Jan 3, 2025 21:42:51.281930923 CET | 13566 | 53820 | 210.99.27.168 | 192.168.2.13 |
Jan 3, 2025 21:42:51.281939030 CET | 45932 | 13566 | 192.168.2.13 | 210.99.56.147 |
Jan 3, 2025 21:42:51.281980991 CET | 53820 | 13566 | 192.168.2.13 | 210.99.27.168 |
Jan 3, 2025 21:42:51.282694101 CET | 48714 | 13566 | 192.168.2.13 | 210.99.150.5 |
Jan 3, 2025 21:42:51.283006907 CET | 13566 | 43710 | 210.99.42.127 | 192.168.2.13 |
Jan 3, 2025 21:42:51.283036947 CET | 43710 | 13566 | 192.168.2.13 | 210.99.42.127 |
Jan 3, 2025 21:42:51.283651114 CET | 41860 | 13566 | 192.168.2.13 | 210.99.62.0 |
Jan 3, 2025 21:42:51.284159899 CET | 13566 | 48658 | 210.99.46.108 | 192.168.2.13 |
Jan 3, 2025 21:42:51.284185886 CET | 48658 | 13566 | 192.168.2.13 | 210.99.46.108 |
Jan 3, 2025 21:42:51.284842014 CET | 38568 | 13566 | 192.168.2.13 | 210.99.32.179 |
Jan 3, 2025 21:42:51.285245895 CET | 13566 | 47132 | 210.99.23.191 | 192.168.2.13 |
Jan 3, 2025 21:42:51.285299063 CET | 47132 | 13566 | 192.168.2.13 | 210.99.23.191 |
Jan 3, 2025 21:42:51.285352945 CET | 46442 | 13566 | 192.168.2.13 | 210.99.64.36 |
Jan 3, 2025 21:42:51.285897017 CET | 45502 | 13566 | 192.168.2.13 | 210.99.33.147 |
Jan 3, 2025 21:42:51.286425114 CET | 37618 | 13566 | 192.168.2.13 | 210.99.173.147 |
Jan 3, 2025 21:42:51.286648035 CET | 13566 | 34536 | 210.99.222.226 | 192.168.2.13 |
Jan 3, 2025 21:42:51.286689043 CET | 34536 | 13566 | 192.168.2.13 | 210.99.222.226 |
Jan 3, 2025 21:42:51.286967039 CET | 57892 | 13566 | 192.168.2.13 | 210.99.133.95 |
Jan 3, 2025 21:42:51.287492990 CET | 35772 | 13566 | 192.168.2.13 | 210.99.234.158 |
Jan 3, 2025 21:42:51.287839890 CET | 13566 | 48714 | 210.99.150.5 | 192.168.2.13 |
Jan 3, 2025 21:42:51.287900925 CET | 48714 | 13566 | 192.168.2.13 | 210.99.150.5 |
Jan 3, 2025 21:42:51.288049936 CET | 50220 | 13566 | 192.168.2.13 | 210.99.98.72 |
Jan 3, 2025 21:42:51.288589001 CET | 40886 | 13566 | 192.168.2.13 | 210.99.86.154 |
Jan 3, 2025 21:42:51.288921118 CET | 13566 | 41860 | 210.99.62.0 | 192.168.2.13 |
Jan 3, 2025 21:42:51.288965940 CET | 41860 | 13566 | 192.168.2.13 | 210.99.62.0 |
Jan 3, 2025 21:42:51.290034056 CET | 13566 | 38568 | 210.99.32.179 | 192.168.2.13 |
Jan 3, 2025 21:42:51.290152073 CET | 38568 | 13566 | 192.168.2.13 | 210.99.32.179 |
Jan 3, 2025 21:42:51.291439056 CET | 13566 | 46442 | 210.99.64.36 | 192.168.2.13 |
Jan 3, 2025 21:42:51.291480064 CET | 46442 | 13566 | 192.168.2.13 | 210.99.64.36 |
Jan 3, 2025 21:42:51.291488886 CET | 13566 | 45502 | 210.99.33.147 | 192.168.2.13 |
Jan 3, 2025 21:42:51.291517973 CET | 13566 | 37618 | 210.99.173.147 | 192.168.2.13 |
Jan 3, 2025 21:42:51.291528940 CET | 45502 | 13566 | 192.168.2.13 | 210.99.33.147 |
Jan 3, 2025 21:42:51.291608095 CET | 37618 | 13566 | 192.168.2.13 | 210.99.173.147 |
Jan 3, 2025 21:42:51.292643070 CET | 13566 | 57892 | 210.99.133.95 | 192.168.2.13 |
Jan 3, 2025 21:42:51.292670965 CET | 13566 | 35772 | 210.99.234.158 | 192.168.2.13 |
Jan 3, 2025 21:42:51.292684078 CET | 57892 | 13566 | 192.168.2.13 | 210.99.133.95 |
Jan 3, 2025 21:42:51.292710066 CET | 35772 | 13566 | 192.168.2.13 | 210.99.234.158 |
Jan 3, 2025 21:42:51.293764114 CET | 13566 | 50220 | 210.99.98.72 | 192.168.2.13 |
Jan 3, 2025 21:42:51.293793917 CET | 13566 | 40886 | 210.99.86.154 | 192.168.2.13 |
Jan 3, 2025 21:42:51.293819904 CET | 50220 | 13566 | 192.168.2.13 | 210.99.98.72 |
Jan 3, 2025 21:42:51.293839931 CET | 40886 | 13566 | 192.168.2.13 | 210.99.86.154 |
Jan 3, 2025 21:42:51.329142094 CET | 42740 | 13566 | 192.168.2.13 | 83.222.191.90 |
Jan 3, 2025 21:42:51.333977938 CET | 13566 | 42740 | 83.222.191.90 | 192.168.2.13 |
Jan 3, 2025 21:42:51.334024906 CET | 42740 | 13566 | 192.168.2.13 | 83.222.191.90 |
Jan 3, 2025 21:42:51.334630013 CET | 42740 | 13566 | 192.168.2.13 | 83.222.191.90 |
Jan 3, 2025 21:42:51.339435101 CET | 13566 | 42740 | 83.222.191.90 | 192.168.2.13 |
Jan 3, 2025 21:42:51.339477062 CET | 42740 | 13566 | 192.168.2.13 | 83.222.191.90 |
Jan 3, 2025 21:42:51.344295025 CET | 13566 | 42740 | 83.222.191.90 | 192.168.2.13 |
Jan 3, 2025 21:43:01.343430042 CET | 42740 | 13566 | 192.168.2.13 | 83.222.191.90 |
Jan 3, 2025 21:43:01.348228931 CET | 13566 | 42740 | 83.222.191.90 | 192.168.2.13 |
Jan 3, 2025 21:43:01.544647932 CET | 13566 | 42740 | 83.222.191.90 | 192.168.2.13 |
Jan 3, 2025 21:43:01.544935942 CET | 42740 | 13566 | 192.168.2.13 | 83.222.191.90 |
Jan 3, 2025 21:43:01.906466007 CET | 13566 | 42740 | 83.222.191.90 | 192.168.2.13 |
Jan 3, 2025 21:43:01.906531096 CET | 42740 | 13566 | 192.168.2.13 | 83.222.191.90 |
Jan 3, 2025 21:44:01.966679096 CET | 42740 | 13566 | 192.168.2.13 | 83.222.191.90 |
Jan 3, 2025 21:44:01.972881079 CET | 13566 | 42740 | 83.222.191.90 | 192.168.2.13 |
Jan 3, 2025 21:44:02.169419050 CET | 13566 | 42740 | 83.222.191.90 | 192.168.2.13 |
Jan 3, 2025 21:44:02.169467926 CET | 42740 | 13566 | 192.168.2.13 | 83.222.191.90 |
Jan 3, 2025 21:44:02.906445026 CET | 13566 | 42740 | 83.222.191.90 | 192.168.2.13 |
Jan 3, 2025 21:44:02.906500101 CET | 42740 | 13566 | 192.168.2.13 | 83.222.191.90 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jan 3, 2025 21:42:51.290544987 CET | 35635 | 53 | 192.168.2.13 | 8.8.8.8 |
Jan 3, 2025 21:42:51.297544956 CET | 53 | 35635 | 8.8.8.8 | 192.168.2.13 |
Jan 3, 2025 21:42:51.298351049 CET | 42476 | 53 | 192.168.2.13 | 8.8.8.8 |
Jan 3, 2025 21:42:51.305658102 CET | 53 | 42476 | 8.8.8.8 | 192.168.2.13 |
Jan 3, 2025 21:42:51.306281090 CET | 37917 | 53 | 192.168.2.13 | 8.8.8.8 |
Jan 3, 2025 21:42:51.313218117 CET | 53 | 37917 | 8.8.8.8 | 192.168.2.13 |
Jan 3, 2025 21:42:51.313810110 CET | 47351 | 53 | 192.168.2.13 | 8.8.8.8 |
Jan 3, 2025 21:42:51.321136951 CET | 53 | 47351 | 8.8.8.8 | 192.168.2.13 |
Jan 3, 2025 21:42:51.321736097 CET | 44454 | 53 | 192.168.2.13 | 8.8.8.8 |
Jan 3, 2025 21:42:51.328855038 CET | 53 | 44454 | 8.8.8.8 | 192.168.2.13 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Jan 3, 2025 21:42:51.290544987 CET | 192.168.2.13 | 8.8.8.8 | 0xec0 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 3, 2025 21:42:51.298351049 CET | 192.168.2.13 | 8.8.8.8 | 0xec0 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 3, 2025 21:42:51.306281090 CET | 192.168.2.13 | 8.8.8.8 | 0xec0 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 3, 2025 21:42:51.313810110 CET | 192.168.2.13 | 8.8.8.8 | 0xec0 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 3, 2025 21:42:51.321736097 CET | 192.168.2.13 | 8.8.8.8 | 0xec0 | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Jan 3, 2025 21:42:51.297544956 CET | 8.8.8.8 | 192.168.2.13 | 0xec0 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Jan 3, 2025 21:42:51.305658102 CET | 8.8.8.8 | 192.168.2.13 | 0xec0 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Jan 3, 2025 21:42:51.313218117 CET | 8.8.8.8 | 192.168.2.13 | 0xec0 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Jan 3, 2025 21:42:51.321136951 CET | 8.8.8.8 | 192.168.2.13 | 0xec0 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Jan 3, 2025 21:42:51.328855038 CET | 8.8.8.8 | 192.168.2.13 | 0xec0 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false |
System Behavior
Start time (UTC): | 20:42:50 |
Start date (UTC): | 03/01/2025 |
Path: | /tmp/x86_64.elf |
Arguments: | /tmp/x86_64.elf |
File size: | 50464 bytes |
MD5 hash: | ed891007b83f07e55a4dfb6e92b1a1cc |
Start time (UTC): | 20:42:50 |
Start date (UTC): | 03/01/2025 |
Path: | /tmp/x86_64.elf |
Arguments: | - |
File size: | 50464 bytes |
MD5 hash: | ed891007b83f07e55a4dfb6e92b1a1cc |
Start time (UTC): | 20:42:50 |
Start date (UTC): | 03/01/2025 |
Path: | /tmp/x86_64.elf |
Arguments: | - |
File size: | 50464 bytes |
MD5 hash: | ed891007b83f07e55a4dfb6e92b1a1cc |
Start time (UTC): | 20:42:50 |
Start date (UTC): | 03/01/2025 |
Path: | /tmp/x86_64.elf |
Arguments: | - |
File size: | 50464 bytes |
MD5 hash: | ed891007b83f07e55a4dfb6e92b1a1cc |