Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
unix.x86_64.elf

Overview

General Information

Sample name:unix.x86_64.elf
Analysis ID:1584451
MD5:e04fbc05bbe06d477992514738a188e9
SHA1:693225c2b100081058701f6467bfb9b261d61c94
SHA256:2681c41cd4ef1c8308a73706e9d25665d58e9b0a3bc246cc1a647add80efb44f
Tags:elfuser-abuse_ch
Infos:

Detection

Mirai
Score:92
Range:0 - 100
Whitelisted:false

Signatures

Antivirus / Scanner detection for submitted sample
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Yara detected Mirai
Machine Learning detection for sample
Sample deletes itself
Uses dynamic DNS services
Creates hidden files and/or directories
Detected TCP or UDP traffic on non-standard ports
Sample has stripped symbol table
Yara signature match

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1584451
Start date and time:2025-01-05 15:12:11 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 19s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:unix.x86_64.elf
Detection:MAL
Classification:mal92.troj.evad.linELF@0/0@6/0
Command:/tmp/unix.x86_64.elf
PID:5435
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:

Standard Error:
  • system is lnxubuntu20
  • unix.x86_64.elf (PID: 5435, Parent: 5362, MD5: e04fbc05bbe06d477992514738a188e9) Arguments: /tmp/unix.x86_64.elf
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
MiraiMirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese. Nowadays it targets a wide range of networked embedded devices such as IP cameras, home routers (many vendors involved), and other IoT devices. Since the source code was published on "Hack Forums" many variants of the Mirai family appeared, infecting mostly home networks all around the world.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/elf.mirai
SourceRuleDescriptionAuthorStrings
unix.x86_64.elfJoeSecurity_Mirai_3Yara detected MiraiJoe Security
    unix.x86_64.elfJoeSecurity_Mirai_8Yara detected MiraiJoe Security
      unix.x86_64.elfLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
      • 0x165c0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x165d4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x165e8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x165fc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x16610:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x16624:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x16638:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x1664c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x16660:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x16674:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x16688:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x1669c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x166b0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x166c4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x166d8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x166ec:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x16700:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x16714:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x16728:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x1673c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x16750:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      unix.x86_64.elfLinux_Trojan_Gafgyt_9e9530a7unknownunknown
      • 0xb2ec:$a: F6 48 63 FF B8 36 00 00 00 0F 05 48 3D 00 F0 FF FF 48 89 C3
      unix.x86_64.elfLinux_Trojan_Gafgyt_807911a2unknownunknown
      • 0xbb63:$a: FE 48 39 F3 0F 94 C2 48 83 F9 FF 0F 94 C0 84 D0 74 16 4B 8D
      Click to see the 11 entries
      SourceRuleDescriptionAuthorStrings
      5435.1.0000000000400000.000000000041a000.r-x.sdmpJoeSecurity_Mirai_3Yara detected MiraiJoe Security
        5435.1.0000000000400000.000000000041a000.r-x.sdmpJoeSecurity_Mirai_8Yara detected MiraiJoe Security
          5435.1.0000000000400000.000000000041a000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
          • 0x165c0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x165d4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x165e8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x165fc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x16610:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x16624:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x16638:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x1664c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x16660:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x16674:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x16688:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x1669c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x166b0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x166c4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x166d8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x166ec:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x16700:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x16714:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x16728:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x1673c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x16750:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          5435.1.0000000000400000.000000000041a000.r-x.sdmpLinux_Trojan_Gafgyt_9e9530a7unknownunknown
          • 0xb2ec:$a: F6 48 63 FF B8 36 00 00 00 0F 05 48 3D 00 F0 FF FF 48 89 C3
          5435.1.0000000000400000.000000000041a000.r-x.sdmpLinux_Trojan_Gafgyt_807911a2unknownunknown
          • 0xbb63:$a: FE 48 39 F3 0F 94 C2 48 83 F9 FF 0F 94 C0 84 D0 74 16 4B 8D
          Click to see the 15 entries
          No Suricata rule has matched

          Click to jump to signature section

          Show All Signature Results

          AV Detection

          barindex
          Source: unix.x86_64.elfAvira: detected
          Source: unix.x86_64.elfVirustotal: Detection: 50%Perma Link
          Source: unix.x86_64.elfReversingLabs: Detection: 55%
          Source: unix.x86_64.elfJoe Sandbox ML: detected

          Networking

          barindex
          Source: unknownDNS query: name: unixbot.ddns.net
          Source: global trafficTCP traffic: 192.168.2.13:44318 -> 123.253.61.116:3778
          Source: global trafficDNS traffic detected: DNS query: unixbot.ddns.net

          System Summary

          barindex
          Source: unix.x86_64.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
          Source: unix.x86_64.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_9e9530a7 Author: unknown
          Source: unix.x86_64.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_807911a2 Author: unknown
          Source: unix.x86_64.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown
          Source: unix.x86_64.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_d4227dbf Author: unknown
          Source: unix.x86_64.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_d996d335 Author: unknown
          Source: unix.x86_64.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_d0c57a2e Author: unknown
          Source: unix.x86_64.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_620087b9 Author: unknown
          Source: unix.x86_64.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_0cd591cd Author: unknown
          Source: unix.x86_64.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_33b4111a Author: unknown
          Source: unix.x86_64.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_a33a8363 Author: unknown
          Source: unix.x86_64.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_1e0c5ce0 Author: unknown
          Source: unix.x86_64.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_6a77af0f Author: unknown
          Source: unix.x86_64.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_e0cf29e2 Author: unknown
          Source: 5435.1.0000000000400000.000000000041a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
          Source: 5435.1.0000000000400000.000000000041a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_9e9530a7 Author: unknown
          Source: 5435.1.0000000000400000.000000000041a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_807911a2 Author: unknown
          Source: 5435.1.0000000000400000.000000000041a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown
          Source: 5435.1.0000000000400000.000000000041a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d4227dbf Author: unknown
          Source: 5435.1.0000000000400000.000000000041a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d996d335 Author: unknown
          Source: 5435.1.0000000000400000.000000000041a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d0c57a2e Author: unknown
          Source: 5435.1.0000000000400000.000000000041a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_620087b9 Author: unknown
          Source: 5435.1.0000000000400000.000000000041a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_0cd591cd Author: unknown
          Source: 5435.1.0000000000400000.000000000041a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_33b4111a Author: unknown
          Source: 5435.1.0000000000400000.000000000041a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a33a8363 Author: unknown
          Source: 5435.1.0000000000400000.000000000041a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_1e0c5ce0 Author: unknown
          Source: 5435.1.0000000000400000.000000000041a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_6a77af0f Author: unknown
          Source: 5435.1.0000000000400000.000000000041a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_e0cf29e2 Author: unknown
          Source: Process Memory Space: unix.x86_64.elf PID: 5435, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
          Source: Process Memory Space: unix.x86_64.elf PID: 5435, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown
          Source: ELF static info symbol of initial sample.symtab present: no
          Source: unix.x86_64.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
          Source: unix.x86_64.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_9e9530a7 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = d6ad6512051e87c8c35dc168d82edd071b122d026dce21d39b9782b3d6a01e50, id = 9e9530a7-ad4d-4a44-b764-437b7621052f, last_modified = 2021-09-16
          Source: unix.x86_64.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_807911a2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = f409037091b7372f5a42bbe437316bd11c655e7a5fe1fcf83d1981cb5c4a389f, id = 807911a2-f6ec-4e65-924f-61cb065dafc6, last_modified = 2021-09-16
          Source: unix.x86_64.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16
          Source: unix.x86_64.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_d4227dbf reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 58c4b1d4d167876b64cfa10f609911a80284180e4db093917fea16fae8ccd4e3, id = d4227dbf-6ab4-4637-a6ba-0e604acaafb4, last_modified = 2021-09-16
          Source: unix.x86_64.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_d996d335 reference_sample = b511eacd4b44744c8cf82d1b4a9bc6f1022fe6be7c5d17356b171f727ddc6eda, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = e9ccb8412f32187c309b0e9afcc3a6da21ad2f1ffa251c27f9f720ccb284e3ac, id = d996d335-e049-4052-bf36-6cd07c911a8b, last_modified = 2021-09-16
          Source: unix.x86_64.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_d0c57a2e os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 3ee7d3a33575ed3aa7431489a8fb18bf30cfd5d6c776066ab2a27f93303124b6, id = d0c57a2e-c10c-436c-be13-50a269326cf2, last_modified = 2021-09-16
          Source: unix.x86_64.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_620087b9 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 06cd7e6eb62352ec2ccb9ed48e58c0583c02fefd137cd048d053ab30b5330307, id = 620087b9-c87d-4752-89e8-ca1c16486b28, last_modified = 2021-09-16
          Source: unix.x86_64.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_0cd591cd os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 96c4ff70729ddb981adafd8c8277649a88a87e380d2f321dff53f0741675fb1b, id = 0cd591cd-c348-4c3a-a895-2063cf892cda, last_modified = 2021-09-16
          Source: unix.x86_64.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_33b4111a reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 9c3b63b9a0f54006bae12abcefdb518904a85f78be573f0780f0a265b12d2d6e, id = 33b4111a-e59e-48db-9d74-34ca44fcd9f5, last_modified = 2021-09-16
          Source: unix.x86_64.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_a33a8363 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 74f964eaadbf8f30d40cdec40b603c5141135d2e658e7ce217d0d6c62e18dd08, id = a33a8363-5511-4fe1-a0d8-75156b9ccfc7, last_modified = 2021-09-16
          Source: unix.x86_64.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_1e0c5ce0 reference_sample = 5b1f95840caebf9721bf318126be27085ec08cf7881ec64a884211a934351c2d, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 8e45538b59f9c9b8bc49661069044900c8199e487714c715c1b1f970fd528e3b, id = 1e0c5ce0-3b76-4da4-8bed-2e5036b6ce79, last_modified = 2021-09-16
          Source: unix.x86_64.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_6a77af0f os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 4e436f509e7e732e3d0326bcbdde555bba0653213ddf31b43cfdfbe16abb0016, id = 6a77af0f-31fa-4793-82aa-10b065ba1ec0, last_modified = 2021-09-16
          Source: unix.x86_64.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_e0cf29e2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 3f124c3c9f124264dfbbcca1e4b4d7cfcf3274170d4bf8966b6559045873948f, id = e0cf29e2-88d7-4aa4-b60a-c24626f2b246, last_modified = 2021-09-16
          Source: 5435.1.0000000000400000.000000000041a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
          Source: 5435.1.0000000000400000.000000000041a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_9e9530a7 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = d6ad6512051e87c8c35dc168d82edd071b122d026dce21d39b9782b3d6a01e50, id = 9e9530a7-ad4d-4a44-b764-437b7621052f, last_modified = 2021-09-16
          Source: 5435.1.0000000000400000.000000000041a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_807911a2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = f409037091b7372f5a42bbe437316bd11c655e7a5fe1fcf83d1981cb5c4a389f, id = 807911a2-f6ec-4e65-924f-61cb065dafc6, last_modified = 2021-09-16
          Source: 5435.1.0000000000400000.000000000041a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16
          Source: 5435.1.0000000000400000.000000000041a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d4227dbf reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 58c4b1d4d167876b64cfa10f609911a80284180e4db093917fea16fae8ccd4e3, id = d4227dbf-6ab4-4637-a6ba-0e604acaafb4, last_modified = 2021-09-16
          Source: 5435.1.0000000000400000.000000000041a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d996d335 reference_sample = b511eacd4b44744c8cf82d1b4a9bc6f1022fe6be7c5d17356b171f727ddc6eda, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = e9ccb8412f32187c309b0e9afcc3a6da21ad2f1ffa251c27f9f720ccb284e3ac, id = d996d335-e049-4052-bf36-6cd07c911a8b, last_modified = 2021-09-16
          Source: 5435.1.0000000000400000.000000000041a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d0c57a2e os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 3ee7d3a33575ed3aa7431489a8fb18bf30cfd5d6c776066ab2a27f93303124b6, id = d0c57a2e-c10c-436c-be13-50a269326cf2, last_modified = 2021-09-16
          Source: 5435.1.0000000000400000.000000000041a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_620087b9 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 06cd7e6eb62352ec2ccb9ed48e58c0583c02fefd137cd048d053ab30b5330307, id = 620087b9-c87d-4752-89e8-ca1c16486b28, last_modified = 2021-09-16
          Source: 5435.1.0000000000400000.000000000041a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_0cd591cd os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 96c4ff70729ddb981adafd8c8277649a88a87e380d2f321dff53f0741675fb1b, id = 0cd591cd-c348-4c3a-a895-2063cf892cda, last_modified = 2021-09-16
          Source: 5435.1.0000000000400000.000000000041a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_33b4111a reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 9c3b63b9a0f54006bae12abcefdb518904a85f78be573f0780f0a265b12d2d6e, id = 33b4111a-e59e-48db-9d74-34ca44fcd9f5, last_modified = 2021-09-16
          Source: 5435.1.0000000000400000.000000000041a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a33a8363 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 74f964eaadbf8f30d40cdec40b603c5141135d2e658e7ce217d0d6c62e18dd08, id = a33a8363-5511-4fe1-a0d8-75156b9ccfc7, last_modified = 2021-09-16
          Source: 5435.1.0000000000400000.000000000041a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_1e0c5ce0 reference_sample = 5b1f95840caebf9721bf318126be27085ec08cf7881ec64a884211a934351c2d, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 8e45538b59f9c9b8bc49661069044900c8199e487714c715c1b1f970fd528e3b, id = 1e0c5ce0-3b76-4da4-8bed-2e5036b6ce79, last_modified = 2021-09-16
          Source: 5435.1.0000000000400000.000000000041a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_6a77af0f os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 4e436f509e7e732e3d0326bcbdde555bba0653213ddf31b43cfdfbe16abb0016, id = 6a77af0f-31fa-4793-82aa-10b065ba1ec0, last_modified = 2021-09-16
          Source: 5435.1.0000000000400000.000000000041a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_e0cf29e2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 3f124c3c9f124264dfbbcca1e4b4d7cfcf3274170d4bf8966b6559045873948f, id = e0cf29e2-88d7-4aa4-b60a-c24626f2b246, last_modified = 2021-09-16
          Source: Process Memory Space: unix.x86_64.elf PID: 5435, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
          Source: Process Memory Space: unix.x86_64.elf PID: 5435, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16
          Source: classification engineClassification label: mal92.troj.evad.linELF@0/0@6/0
          Source: /tmp/unix.x86_64.elf (PID: 5436)Directory: /tmp/.Jump to behavior
          Source: /tmp/unix.x86_64.elf (PID: 5436)Directory: /tmp/..Jump to behavior

          Hooking and other Techniques for Hiding and Protection

          barindex
          Source: /tmp/unix.x86_64.elf (PID: 5435)File: /tmp/unix.x86_64.elfJump to behavior

          Stealing of Sensitive Information

          barindex
          Source: Yara matchFile source: unix.x86_64.elf, type: SAMPLE
          Source: Yara matchFile source: 5435.1.0000000000400000.000000000041a000.r-x.sdmp, type: MEMORY
          Source: Yara matchFile source: Process Memory Space: unix.x86_64.elf PID: 5435, type: MEMORYSTR

          Remote Access Functionality

          barindex
          Source: Yara matchFile source: unix.x86_64.elf, type: SAMPLE
          Source: Yara matchFile source: 5435.1.0000000000400000.000000000041a000.r-x.sdmp, type: MEMORY
          Source: Yara matchFile source: Process Memory Space: unix.x86_64.elf PID: 5435, type: MEMORYSTR
          ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
          Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception1
          Hidden Files and Directories
          OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
          Non-Standard Port
          Exfiltration Over Other Network MediumAbuse Accessibility Features
          CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
          File Deletion
          LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
          Non-Application Layer Protocol
          Exfiltration Over BluetoothNetwork Denial of Service
          Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive11
          Application Layer Protocol
          Automated ExfiltrationData Encrypted for Impact
          No configs have been found
          Hide Legend

          Legend:

          • Process
          • Signature
          • Created File
          • DNS/IP Info
          • Is Dropped
          • Number of created Files
          • Is malicious
          • Internet
          SourceDetectionScannerLabelLink
          unix.x86_64.elf51%VirustotalBrowse
          unix.x86_64.elf55%ReversingLabsLinux.Trojan.Mirai
          unix.x86_64.elf100%AviraEXP/ELF.Mirai.Z.A
          unix.x86_64.elf100%Joe Sandbox ML
          No Antivirus matches
          No Antivirus matches
          No Antivirus matches
          NameIPActiveMaliciousAntivirus DetectionReputation
          unixbot.ddns.net
          123.253.61.116
          truefalse
            high
            • No. of IPs < 25%
            • 25% < No. of IPs < 50%
            • 50% < No. of IPs < 75%
            • 75% < No. of IPs
            IPDomainCountryFlagASNASN NameMalicious
            123.253.61.116
            unixbot.ddns.netThailand
            136523COLODEE-AS-APCOLODEEDIGITALNETWORKCOLTDTHfalse
            MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
            123.253.61.116main.arm7.elfGet hashmaliciousMiraiBrowse
              main.x86_64.elfGet hashmaliciousMiraiBrowse
                main.sh4.elfGet hashmaliciousMiraiBrowse
                  fuckunix.arm7.elfGet hashmaliciousMiraiBrowse
                    main.mpsl.elfGet hashmaliciousMiraiBrowse
                      fuckunix.x86.elfGet hashmaliciousMiraiBrowse
                        main.x86.elfGet hashmaliciousMiraiBrowse
                          main.arm.elfGet hashmaliciousMiraiBrowse
                            main.mips.elfGet hashmaliciousMiraiBrowse
                              fuckunix.arm.elfGet hashmaliciousMiraiBrowse
                                MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                unixbot.ddns.netmain.arm7.elfGet hashmaliciousMiraiBrowse
                                • 123.253.61.116
                                main.x86_64.elfGet hashmaliciousMiraiBrowse
                                • 123.253.61.116
                                main.sh4.elfGet hashmaliciousMiraiBrowse
                                • 123.253.61.116
                                main.mpsl.elfGet hashmaliciousMiraiBrowse
                                • 123.253.61.116
                                main.x86.elfGet hashmaliciousMiraiBrowse
                                • 123.253.61.116
                                main.arm.elfGet hashmaliciousMiraiBrowse
                                • 123.253.61.116
                                main.mips.elfGet hashmaliciousMiraiBrowse
                                • 123.253.61.116
                                main.ppc.elfGet hashmaliciousMiraiBrowse
                                • 123.253.61.116
                                main.m68k.elfGet hashmaliciousMiraiBrowse
                                • 123.253.61.116
                                main.arm5.elfGet hashmaliciousMiraiBrowse
                                • 123.253.61.116
                                MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                COLODEE-AS-APCOLODEEDIGITALNETWORKCOLTDTHmain.arm7.elfGet hashmaliciousMiraiBrowse
                                • 123.253.61.116
                                main.x86_64.elfGet hashmaliciousMiraiBrowse
                                • 123.253.61.116
                                main.sh4.elfGet hashmaliciousMiraiBrowse
                                • 123.253.61.116
                                fuckunix.arm7.elfGet hashmaliciousMiraiBrowse
                                • 123.253.61.116
                                main.mpsl.elfGet hashmaliciousMiraiBrowse
                                • 123.253.61.116
                                fuckunix.x86.elfGet hashmaliciousMiraiBrowse
                                • 123.253.61.116
                                main.x86.elfGet hashmaliciousMiraiBrowse
                                • 123.253.61.116
                                main.arm.elfGet hashmaliciousMiraiBrowse
                                • 123.253.61.116
                                main.mips.elfGet hashmaliciousMiraiBrowse
                                • 123.253.61.116
                                fuckunix.arm.elfGet hashmaliciousMiraiBrowse
                                • 123.253.61.116
                                No context
                                No context
                                No created / dropped files found
                                File type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), statically linked, stripped
                                Entropy (8bit):5.214991818286515
                                TrID:
                                • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                                File name:unix.x86_64.elf
                                File size:146'120 bytes
                                MD5:e04fbc05bbe06d477992514738a188e9
                                SHA1:693225c2b100081058701f6467bfb9b261d61c94
                                SHA256:2681c41cd4ef1c8308a73706e9d25665d58e9b0a3bc246cc1a647add80efb44f
                                SHA512:44794e3c14b01c88a4fd3baa16282ac4b3f745795ff42523e1cf6dc6592c991e77c20563573b3da61290ae906180ee1fd99f74a1e4bf0512fff11d8855fb49fd
                                SSDEEP:3072:xtxS0FsNDQOrRbKMY1eC0YUMOXal7YyjaU3rDwEcxN20aB9x:xtxS0FsNDQkRbKfzJkyfQNHaB9
                                TLSH:B1E36D17B4C184FDC4DAC2744BAAB53BDD32F1A91238B15B27D4AB221E9EE305F1DA05
                                File Content Preview:.ELF..............>.......@.....@.......H8..........@.8...@.......................@.......@...............................................Q.......Q.............................Q.td....................................................H...._.....\..H........

                                ELF header

                                Class:ELF64
                                Data:2's complement, little endian
                                Version:1 (current)
                                Machine:Advanced Micro Devices X86-64
                                Version Number:0x1
                                Type:EXEC (Executable file)
                                OS/ABI:UNIX - System V
                                ABI Version:0
                                Entry Point Address:0x400194
                                Flags:0x0
                                ELF Header Size:64
                                Program Header Offset:64
                                Program Header Size:56
                                Number of Program Headers:3
                                Section Header Offset:145480
                                Section Header Size:64
                                Number of Section Headers:10
                                Header String Table Index:9
                                NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                NULL0x00x00x00x00x0000
                                .initPROGBITS0x4000e80xe80x130x00x6AX001
                                .textPROGBITS0x4001000x1000x15cb60x00x6AX0016
                                .finiPROGBITS0x415db60x15db60xe0x00x6AX001
                                .rodataPROGBITS0x415de00x15de00x3ae10x00x2A0032
                                .ctorsPROGBITS0x51a0000x1a0000x180x00x3WA008
                                .dtorsPROGBITS0x51a0180x1a0180x100x00x3WA008
                                .dataPROGBITS0x51a0400x1a0400x97c80x00x3WA0032
                                .bssNOBITS0x5238200x238080x82800x00x3WA0032
                                .shstrtabSTRTAB0x00x238080x3e0x00x0001
                                TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                LOAD0x00x4000000x4000000x198c10x198c16.44700x5R E0x100000.init .text .fini .rodata
                                LOAD0x1a0000x51a0000x51a0000x98080x11aa00.47390x6RW 0x100000.ctors .dtors .data .bss
                                GNU_STACK0x00x00x00x00x00.00000x6RW 0x8
                                TimestampSource PortDest PortSource IPDest IP
                                Jan 5, 2025 15:13:01.728128910 CET443183778192.168.2.13123.253.61.116
                                Jan 5, 2025 15:13:01.733006954 CET377844318123.253.61.116192.168.2.13
                                Jan 5, 2025 15:13:01.733071089 CET443183778192.168.2.13123.253.61.116
                                Jan 5, 2025 15:13:01.733915091 CET443183778192.168.2.13123.253.61.116
                                Jan 5, 2025 15:13:01.738719940 CET377844318123.253.61.116192.168.2.13
                                Jan 5, 2025 15:13:01.738764048 CET443183778192.168.2.13123.253.61.116
                                Jan 5, 2025 15:13:01.743547916 CET377844318123.253.61.116192.168.2.13
                                Jan 5, 2025 15:13:11.744004011 CET443183778192.168.2.13123.253.61.116
                                Jan 5, 2025 15:13:11.748883963 CET377844318123.253.61.116192.168.2.13
                                Jan 5, 2025 15:13:23.114317894 CET377844318123.253.61.116192.168.2.13
                                Jan 5, 2025 15:13:23.114433050 CET443183778192.168.2.13123.253.61.116
                                Jan 5, 2025 15:13:23.119283915 CET377844318123.253.61.116192.168.2.13
                                Jan 5, 2025 15:13:24.124897003 CET443203778192.168.2.13123.253.61.116
                                Jan 5, 2025 15:13:24.130096912 CET377844320123.253.61.116192.168.2.13
                                Jan 5, 2025 15:13:24.130155087 CET443203778192.168.2.13123.253.61.116
                                Jan 5, 2025 15:13:24.130933046 CET443203778192.168.2.13123.253.61.116
                                Jan 5, 2025 15:13:24.135762930 CET377844320123.253.61.116192.168.2.13
                                Jan 5, 2025 15:13:24.135811090 CET443203778192.168.2.13123.253.61.116
                                Jan 5, 2025 15:13:24.140551090 CET377844320123.253.61.116192.168.2.13
                                Jan 5, 2025 15:13:45.505325079 CET377844320123.253.61.116192.168.2.13
                                Jan 5, 2025 15:13:45.505472898 CET443203778192.168.2.13123.253.61.116
                                Jan 5, 2025 15:13:45.510199070 CET377844320123.253.61.116192.168.2.13
                                Jan 5, 2025 15:13:46.516367912 CET443223778192.168.2.13123.253.61.116
                                Jan 5, 2025 15:13:46.521111012 CET377844322123.253.61.116192.168.2.13
                                Jan 5, 2025 15:13:46.521161079 CET443223778192.168.2.13123.253.61.116
                                Jan 5, 2025 15:13:46.521836042 CET443223778192.168.2.13123.253.61.116
                                Jan 5, 2025 15:13:46.526663065 CET377844322123.253.61.116192.168.2.13
                                Jan 5, 2025 15:13:46.526714087 CET443223778192.168.2.13123.253.61.116
                                Jan 5, 2025 15:13:46.531475067 CET377844322123.253.61.116192.168.2.13
                                Jan 5, 2025 15:14:07.880769968 CET377844322123.253.61.116192.168.2.13
                                Jan 5, 2025 15:14:07.881150007 CET443223778192.168.2.13123.253.61.116
                                Jan 5, 2025 15:14:07.885931015 CET377844322123.253.61.116192.168.2.13
                                Jan 5, 2025 15:14:08.919816971 CET443243778192.168.2.13123.253.61.116
                                Jan 5, 2025 15:14:08.924612045 CET377844324123.253.61.116192.168.2.13
                                Jan 5, 2025 15:14:08.924714088 CET443243778192.168.2.13123.253.61.116
                                Jan 5, 2025 15:14:08.925741911 CET443243778192.168.2.13123.253.61.116
                                Jan 5, 2025 15:14:08.930524111 CET377844324123.253.61.116192.168.2.13
                                Jan 5, 2025 15:14:08.930584908 CET443243778192.168.2.13123.253.61.116
                                Jan 5, 2025 15:14:08.935450077 CET377844324123.253.61.116192.168.2.13
                                Jan 5, 2025 15:14:18.935825109 CET443243778192.168.2.13123.253.61.116
                                Jan 5, 2025 15:14:18.942194939 CET377844324123.253.61.116192.168.2.13
                                Jan 5, 2025 15:14:30.272892952 CET377844324123.253.61.116192.168.2.13
                                Jan 5, 2025 15:14:30.273024082 CET443243778192.168.2.13123.253.61.116
                                Jan 5, 2025 15:14:30.280950069 CET377844324123.253.61.116192.168.2.13
                                Jan 5, 2025 15:14:31.282198906 CET443263778192.168.2.13123.253.61.116
                                Jan 5, 2025 15:14:31.288736105 CET377844326123.253.61.116192.168.2.13
                                Jan 5, 2025 15:14:31.288789988 CET443263778192.168.2.13123.253.61.116
                                Jan 5, 2025 15:14:31.289388895 CET443263778192.168.2.13123.253.61.116
                                Jan 5, 2025 15:14:31.295540094 CET377844326123.253.61.116192.168.2.13
                                Jan 5, 2025 15:14:31.295582056 CET443263778192.168.2.13123.253.61.116
                                Jan 5, 2025 15:14:31.300425053 CET377844326123.253.61.116192.168.2.13
                                Jan 5, 2025 15:14:52.648032904 CET377844326123.253.61.116192.168.2.13
                                Jan 5, 2025 15:14:52.648511887 CET443263778192.168.2.13123.253.61.116
                                Jan 5, 2025 15:14:52.653314114 CET377844326123.253.61.116192.168.2.13
                                Jan 5, 2025 15:14:53.692671061 CET443283778192.168.2.13123.253.61.116
                                Jan 5, 2025 15:14:53.697571993 CET377844328123.253.61.116192.168.2.13
                                Jan 5, 2025 15:14:53.697664976 CET443283778192.168.2.13123.253.61.116
                                Jan 5, 2025 15:14:53.698620081 CET443283778192.168.2.13123.253.61.116
                                Jan 5, 2025 15:14:53.703358889 CET377844328123.253.61.116192.168.2.13
                                Jan 5, 2025 15:14:53.703419924 CET443283778192.168.2.13123.253.61.116
                                Jan 5, 2025 15:14:53.708214998 CET377844328123.253.61.116192.168.2.13
                                TimestampSource PortDest PortSource IPDest IP
                                Jan 5, 2025 15:13:01.689471006 CET5772553192.168.2.138.8.8.8
                                Jan 5, 2025 15:13:01.727624893 CET53577258.8.8.8192.168.2.13
                                Jan 5, 2025 15:13:24.116724968 CET5880253192.168.2.138.8.8.8
                                Jan 5, 2025 15:13:24.124465942 CET53588028.8.8.8192.168.2.13
                                Jan 5, 2025 15:13:46.507356882 CET5798753192.168.2.138.8.8.8
                                Jan 5, 2025 15:13:46.515969038 CET53579878.8.8.8192.168.2.13
                                Jan 5, 2025 15:14:08.883507013 CET6090053192.168.2.138.8.8.8
                                Jan 5, 2025 15:14:08.919234991 CET53609008.8.8.8192.168.2.13
                                Jan 5, 2025 15:14:31.274837971 CET4378153192.168.2.138.8.8.8
                                Jan 5, 2025 15:14:31.281860113 CET53437818.8.8.8192.168.2.13
                                Jan 5, 2025 15:14:53.651338100 CET4171253192.168.2.138.8.8.8
                                Jan 5, 2025 15:14:53.691704988 CET53417128.8.8.8192.168.2.13
                                TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                Jan 5, 2025 15:13:01.689471006 CET192.168.2.138.8.8.80x0Standard query (0)unixbot.ddns.netA (IP address)IN (0x0001)false
                                Jan 5, 2025 15:13:24.116724968 CET192.168.2.138.8.8.80x0Standard query (0)unixbot.ddns.netA (IP address)IN (0x0001)false
                                Jan 5, 2025 15:13:46.507356882 CET192.168.2.138.8.8.80x0Standard query (0)unixbot.ddns.netA (IP address)IN (0x0001)false
                                Jan 5, 2025 15:14:08.883507013 CET192.168.2.138.8.8.80x0Standard query (0)unixbot.ddns.netA (IP address)IN (0x0001)false
                                Jan 5, 2025 15:14:31.274837971 CET192.168.2.138.8.8.80x0Standard query (0)unixbot.ddns.netA (IP address)IN (0x0001)false
                                Jan 5, 2025 15:14:53.651338100 CET192.168.2.138.8.8.80x0Standard query (0)unixbot.ddns.netA (IP address)IN (0x0001)false
                                TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                Jan 5, 2025 15:13:01.727624893 CET8.8.8.8192.168.2.130x0No error (0)unixbot.ddns.net123.253.61.116A (IP address)IN (0x0001)false
                                Jan 5, 2025 15:13:24.124465942 CET8.8.8.8192.168.2.130x0No error (0)unixbot.ddns.net123.253.61.116A (IP address)IN (0x0001)false
                                Jan 5, 2025 15:13:46.515969038 CET8.8.8.8192.168.2.130x0No error (0)unixbot.ddns.net123.253.61.116A (IP address)IN (0x0001)false
                                Jan 5, 2025 15:14:08.919234991 CET8.8.8.8192.168.2.130x0No error (0)unixbot.ddns.net123.253.61.116A (IP address)IN (0x0001)false
                                Jan 5, 2025 15:14:31.281860113 CET8.8.8.8192.168.2.130x0No error (0)unixbot.ddns.net123.253.61.116A (IP address)IN (0x0001)false
                                Jan 5, 2025 15:14:53.691704988 CET8.8.8.8192.168.2.130x0No error (0)unixbot.ddns.net123.253.61.116A (IP address)IN (0x0001)false

                                System Behavior

                                Start time (UTC):14:12:54
                                Start date (UTC):05/01/2025
                                Path:/tmp/unix.x86_64.elf
                                Arguments:/tmp/unix.x86_64.elf
                                File size:146120 bytes
                                MD5 hash:e04fbc05bbe06d477992514738a188e9

                                Start time (UTC):14:12:54
                                Start date (UTC):05/01/2025
                                Path:/tmp/unix.x86_64.elf
                                Arguments:-
                                File size:146120 bytes
                                MD5 hash:e04fbc05bbe06d477992514738a188e9