Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
unix.x86.elf

Overview

General Information

Sample name:unix.x86.elf
Analysis ID:1584460
MD5:03b9a070b47074f6deefa54821108c27
SHA1:bad19bcc748b4e275c5276cc59cf4cef66054271
SHA256:7ce28542fb439b9fb1108e9803377977702a21e9f6ba03c7d193a1b712ae89ff
Tags:elfuser-abuse_ch
Infos:

Detection

Mirai
Score:92
Range:0 - 100
Whitelisted:false

Signatures

Antivirus / Scanner detection for submitted sample
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Yara detected Mirai
Machine Learning detection for sample
Sample deletes itself
Uses dynamic DNS services
Creates hidden files and/or directories
Detected TCP or UDP traffic on non-standard ports
Sample has stripped symbol table
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Yara signature match

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1584460
Start date and time:2025-01-05 15:20:29 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 43s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:unix.x86.elf
Detection:MAL
Classification:mal92.troj.evad.linELF@0/0@6/0
Command:/tmp/unix.x86.elf
PID:6262
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:

Standard Error:
  • system is lnxubuntu20
  • unix.x86.elf (PID: 6262, Parent: 6187, MD5: 03b9a070b47074f6deefa54821108c27) Arguments: /tmp/unix.x86.elf
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
MiraiMirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese. Nowadays it targets a wide range of networked embedded devices such as IP cameras, home routers (many vendors involved), and other IoT devices. Since the source code was published on "Hack Forums" many variants of the Mirai family appeared, infecting mostly home networks all around the world.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/elf.mirai
SourceRuleDescriptionAuthorStrings
unix.x86.elfJoeSecurity_Mirai_3Yara detected MiraiJoe Security
    unix.x86.elfJoeSecurity_Mirai_8Yara detected MiraiJoe Security
      unix.x86.elfLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
      • 0xf0d0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xf0e4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xf0f8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xf10c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xf120:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xf134:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xf148:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xf15c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xf170:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xf184:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xf198:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xf1ac:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xf1c0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xf1d4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xf1e8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xf1fc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xf210:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xf224:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xf238:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xf24c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xf260:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      unix.x86.elfLinux_Trojan_Gafgyt_ea92cca8unknownunknown
      • 0xefb0:$a: 53 65 6C 66 20 52 65 70 20 46 75 63 6B 69 6E 67 20 4E 65 54 69 53 20 61 6E 64
      unix.x86.elfLinux_Trojan_Mirai_b14f4c5dunknownunknown
      • 0x3d90:$a: 53 31 DB 8B 4C 24 0C 8B 54 24 08 83 F9 01 76 15 66 8B 02 83 E9 02 25 FF FF 00 00 83 C2 02 01 C3 83 F9 01 77 EB 49 75 05 0F BE 02 01 C3
      Click to see the 5 entries
      SourceRuleDescriptionAuthorStrings
      6262.1.0000000008048000.000000000805a000.r-x.sdmpJoeSecurity_Mirai_3Yara detected MiraiJoe Security
        6262.1.0000000008048000.000000000805a000.r-x.sdmpJoeSecurity_Mirai_8Yara detected MiraiJoe Security
          6262.1.0000000008048000.000000000805a000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
          • 0xf0d0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xf0e4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xf0f8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xf10c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xf120:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xf134:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xf148:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xf15c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xf170:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xf184:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xf198:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xf1ac:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xf1c0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xf1d4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xf1e8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xf1fc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xf210:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xf224:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xf238:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xf24c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xf260:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          6262.1.0000000008048000.000000000805a000.r-x.sdmpLinux_Trojan_Gafgyt_ea92cca8unknownunknown
          • 0xefb0:$a: 53 65 6C 66 20 52 65 70 20 46 75 63 6B 69 6E 67 20 4E 65 54 69 53 20 61 6E 64
          6262.1.0000000008048000.000000000805a000.r-x.sdmpLinux_Trojan_Mirai_b14f4c5dunknownunknown
          • 0x3d90:$a: 53 31 DB 8B 4C 24 0C 8B 54 24 08 83 F9 01 76 15 66 8B 02 83 E9 02 25 FF FF 00 00 83 C2 02 01 C3 83 F9 01 77 EB 49 75 05 0F BE 02 01 C3
          Click to see the 9 entries
          No Suricata rule has matched

          Click to jump to signature section

          Show All Signature Results

          AV Detection

          barindex
          Source: unix.x86.elfAvira: detected
          Source: unix.x86.elfVirustotal: Detection: 60%Perma Link
          Source: unix.x86.elfReversingLabs: Detection: 63%
          Source: unix.x86.elfJoe Sandbox ML: detected

          Networking

          barindex
          Source: unknownDNS query: name: unixbot.ddns.net
          Source: global trafficTCP traffic: 192.168.2.23:47302 -> 123.253.61.116:3778
          Source: global trafficTCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
          Source: global trafficTCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
          Source: global trafficTCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
          Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
          Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
          Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
          Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
          Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
          Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
          Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
          Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
          Source: global trafficDNS traffic detected: DNS query: unixbot.ddns.net
          Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443

          System Summary

          barindex
          Source: unix.x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
          Source: unix.x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown
          Source: unix.x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_b14f4c5d Author: unknown
          Source: unix.x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_5f7b67b8 Author: unknown
          Source: unix.x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_88de437f Author: unknown
          Source: unix.x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_389ee3e9 Author: unknown
          Source: unix.x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_cc93863b Author: unknown
          Source: unix.x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_8aa7b5d3 Author: unknown
          Source: 6262.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
          Source: 6262.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown
          Source: 6262.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_b14f4c5d Author: unknown
          Source: 6262.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_5f7b67b8 Author: unknown
          Source: 6262.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_88de437f Author: unknown
          Source: 6262.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_389ee3e9 Author: unknown
          Source: 6262.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_cc93863b Author: unknown
          Source: 6262.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_8aa7b5d3 Author: unknown
          Source: Process Memory Space: unix.x86.elf PID: 6262, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
          Source: Process Memory Space: unix.x86.elf PID: 6262, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown
          Source: ELF static info symbol of initial sample.symtab present: no
          Source: unix.x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
          Source: unix.x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16
          Source: unix.x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_b14f4c5d os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = a70d052918dd2fbc66db241da6438015130f0fb6929229bfe573546fe98da817, id = b14f4c5d-054f-46e6-9fa8-3588f1ef68b7, last_modified = 2021-09-16
          Source: unix.x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_5f7b67b8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 6cb5fb0b7c132e9c11ac72da43278025b60810ea3733c9c6d6ca966163185940, id = 5f7b67b8-3d7b-48a4-8f03-b6f2c92be92e, last_modified = 2021-09-16
          Source: unix.x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_88de437f reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = c19eb595c2b444a809bef8500c20342c9f46694d3018e268833f9b884133a1ea, id = 88de437f-9c98-4e1d-96c0-7b433c99886a, last_modified = 2021-09-16
          Source: unix.x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_389ee3e9 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 59f2359dc1f41d385d639d157b4cd9fc73d76d8abb7cc09d47632bb4c9a39e6e, id = 389ee3e9-70c1-4c93-a999-292cf6ff1652, last_modified = 2022-01-26
          Source: unix.x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_cc93863b reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = f3ecd30f0b511a8e92cfa642409d559e7612c3f57a1659ca46c77aca809a00ac, id = cc93863b-1050-40ba-9d02-5ec9ce6a3a28, last_modified = 2022-01-26
          Source: unix.x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_8aa7b5d3 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 02a2c18c362df4b1fceb33f3b605586514ba9a00c7afedf71c04fa54d8146444, id = 8aa7b5d3-e1eb-4b55-b36a-0d3a242c06e9, last_modified = 2022-01-26
          Source: 6262.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
          Source: 6262.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16
          Source: 6262.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_b14f4c5d os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = a70d052918dd2fbc66db241da6438015130f0fb6929229bfe573546fe98da817, id = b14f4c5d-054f-46e6-9fa8-3588f1ef68b7, last_modified = 2021-09-16
          Source: 6262.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_5f7b67b8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 6cb5fb0b7c132e9c11ac72da43278025b60810ea3733c9c6d6ca966163185940, id = 5f7b67b8-3d7b-48a4-8f03-b6f2c92be92e, last_modified = 2021-09-16
          Source: 6262.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_88de437f reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = c19eb595c2b444a809bef8500c20342c9f46694d3018e268833f9b884133a1ea, id = 88de437f-9c98-4e1d-96c0-7b433c99886a, last_modified = 2021-09-16
          Source: 6262.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_389ee3e9 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 59f2359dc1f41d385d639d157b4cd9fc73d76d8abb7cc09d47632bb4c9a39e6e, id = 389ee3e9-70c1-4c93-a999-292cf6ff1652, last_modified = 2022-01-26
          Source: 6262.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_cc93863b reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = f3ecd30f0b511a8e92cfa642409d559e7612c3f57a1659ca46c77aca809a00ac, id = cc93863b-1050-40ba-9d02-5ec9ce6a3a28, last_modified = 2022-01-26
          Source: 6262.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_8aa7b5d3 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 02a2c18c362df4b1fceb33f3b605586514ba9a00c7afedf71c04fa54d8146444, id = 8aa7b5d3-e1eb-4b55-b36a-0d3a242c06e9, last_modified = 2022-01-26
          Source: Process Memory Space: unix.x86.elf PID: 6262, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
          Source: Process Memory Space: unix.x86.elf PID: 6262, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16
          Source: classification engineClassification label: mal92.troj.evad.linELF@0/0@6/0
          Source: /tmp/unix.x86.elf (PID: 6263)Directory: /tmp/.Jump to behavior
          Source: /tmp/unix.x86.elf (PID: 6263)Directory: /tmp/..Jump to behavior

          Hooking and other Techniques for Hiding and Protection

          barindex
          Source: /tmp/unix.x86.elf (PID: 6262)File: /tmp/unix.x86.elfJump to behavior

          Stealing of Sensitive Information

          barindex
          Source: Yara matchFile source: unix.x86.elf, type: SAMPLE
          Source: Yara matchFile source: 6262.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORY
          Source: Yara matchFile source: Process Memory Space: unix.x86.elf PID: 6262, type: MEMORYSTR

          Remote Access Functionality

          barindex
          Source: Yara matchFile source: unix.x86.elf, type: SAMPLE
          Source: Yara matchFile source: 6262.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORY
          Source: Yara matchFile source: Process Memory Space: unix.x86.elf PID: 6262, type: MEMORYSTR
          ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
          Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception1
          Hidden Files and Directories
          OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
          Encrypted Channel
          Exfiltration Over Other Network MediumAbuse Accessibility Features
          CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
          File Deletion
          LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
          Non-Standard Port
          Exfiltration Over BluetoothNetwork Denial of Service
          Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
          Non-Application Layer Protocol
          Automated ExfiltrationData Encrypted for Impact
          Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture12
          Application Layer Protocol
          Traffic DuplicationData Destruction
          No configs have been found
          Hide Legend

          Legend:

          • Process
          • Signature
          • Created File
          • DNS/IP Info
          • Is Dropped
          • Number of created Files
          • Is malicious
          • Internet
          SourceDetectionScannerLabelLink
          unix.x86.elf61%VirustotalBrowse
          unix.x86.elf63%ReversingLabsLinux.Trojan.Mirai
          unix.x86.elf100%AviraEXP/ELF.Mirai.Z.A
          unix.x86.elf100%Joe Sandbox ML
          No Antivirus matches
          No Antivirus matches
          No Antivirus matches
          NameIPActiveMaliciousAntivirus DetectionReputation
          unixbot.ddns.net
          123.253.61.116
          truefalse
            high
            • No. of IPs < 25%
            • 25% < No. of IPs < 50%
            • 50% < No. of IPs < 75%
            • 75% < No. of IPs
            IPDomainCountryFlagASNASN NameMalicious
            109.202.202.202
            unknownSwitzerland
            13030INIT7CHfalse
            91.189.91.43
            unknownUnited Kingdom
            41231CANONICAL-ASGBfalse
            91.189.91.42
            unknownUnited Kingdom
            41231CANONICAL-ASGBfalse
            123.253.61.116
            unixbot.ddns.netThailand
            136523COLODEE-AS-APCOLODEEDIGITALNETWORKCOLTDTHfalse
            MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
            109.202.202.202kpLwzBouH4.elfGet hashmaliciousUnknownBrowse
            • ch.archive.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_92.0%2bbuild3-0ubuntu0.20.04.1_amd64.deb
            91.189.91.43main.sh4.elfGet hashmaliciousMiraiBrowse
              fuckunix.arm7.elfGet hashmaliciousMiraiBrowse
                Space.spc.elfGet hashmaliciousMiraiBrowse
                  main.mpsl.elfGet hashmaliciousMiraiBrowse
                    z0r0.arc.elfGet hashmaliciousMiraiBrowse
                      main.x86.elfGet hashmaliciousMiraiBrowse
                        fenty.arm4.elfGet hashmaliciousMiraiBrowse
                          Space.arm7.elfGet hashmaliciousMiraiBrowse
                            Space.arm.elfGet hashmaliciousMiraiBrowse
                              main.arm6.elfGet hashmaliciousMiraiBrowse
                                91.189.91.42unix.arm5.elfGet hashmaliciousMiraiBrowse
                                  main.sh4.elfGet hashmaliciousMiraiBrowse
                                    fuckunix.arm7.elfGet hashmaliciousMiraiBrowse
                                      Space.spc.elfGet hashmaliciousMiraiBrowse
                                        main.mpsl.elfGet hashmaliciousMiraiBrowse
                                          z0r0.arc.elfGet hashmaliciousMiraiBrowse
                                            main.x86.elfGet hashmaliciousMiraiBrowse
                                              fenty.arm4.elfGet hashmaliciousMiraiBrowse
                                                Space.arm7.elfGet hashmaliciousMiraiBrowse
                                                  Space.arm.elfGet hashmaliciousMiraiBrowse
                                                    123.253.61.116unix.sh4.elfGet hashmaliciousMiraiBrowse
                                                      unix.arm5.elfGet hashmaliciousMiraiBrowse
                                                        unix.mips.elfGet hashmaliciousMiraiBrowse
                                                          unix.mpsl.elfGet hashmaliciousMiraiBrowse
                                                            unix.x86_64.elfGet hashmaliciousMiraiBrowse
                                                              main.arm7.elfGet hashmaliciousMiraiBrowse
                                                                main.x86_64.elfGet hashmaliciousMiraiBrowse
                                                                  main.sh4.elfGet hashmaliciousMiraiBrowse
                                                                    fuckunix.arm7.elfGet hashmaliciousMiraiBrowse
                                                                      main.mpsl.elfGet hashmaliciousMiraiBrowse
                                                                        MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                        unixbot.ddns.netunix.arm5.elfGet hashmaliciousMiraiBrowse
                                                                        • 123.253.61.116
                                                                        unix.mips.elfGet hashmaliciousMiraiBrowse
                                                                        • 123.253.61.116
                                                                        unix.mpsl.elfGet hashmaliciousMiraiBrowse
                                                                        • 123.253.61.116
                                                                        unix.x86_64.elfGet hashmaliciousMiraiBrowse
                                                                        • 123.253.61.116
                                                                        main.arm7.elfGet hashmaliciousMiraiBrowse
                                                                        • 123.253.61.116
                                                                        main.x86_64.elfGet hashmaliciousMiraiBrowse
                                                                        • 123.253.61.116
                                                                        main.sh4.elfGet hashmaliciousMiraiBrowse
                                                                        • 123.253.61.116
                                                                        main.mpsl.elfGet hashmaliciousMiraiBrowse
                                                                        • 123.253.61.116
                                                                        main.x86.elfGet hashmaliciousMiraiBrowse
                                                                        • 123.253.61.116
                                                                        main.arm.elfGet hashmaliciousMiraiBrowse
                                                                        • 123.253.61.116
                                                                        MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                        CANONICAL-ASGBunix.arm5.elfGet hashmaliciousMiraiBrowse
                                                                        • 91.189.91.42
                                                                        main.sh4.elfGet hashmaliciousMiraiBrowse
                                                                        • 91.189.91.42
                                                                        fuckunix.arm7.elfGet hashmaliciousMiraiBrowse
                                                                        • 91.189.91.42
                                                                        Space.spc.elfGet hashmaliciousMiraiBrowse
                                                                        • 91.189.91.42
                                                                        main.mpsl.elfGet hashmaliciousMiraiBrowse
                                                                        • 91.189.91.42
                                                                        fuckunix.x86.elfGet hashmaliciousMiraiBrowse
                                                                        • 185.125.190.26
                                                                        z0r0.arc.elfGet hashmaliciousMiraiBrowse
                                                                        • 91.189.91.42
                                                                        z0r0.mips.elfGet hashmaliciousUnknownBrowse
                                                                        • 185.125.190.26
                                                                        z0r0.mpsl.elfGet hashmaliciousUnknownBrowse
                                                                        • 185.125.190.26
                                                                        main.x86.elfGet hashmaliciousMiraiBrowse
                                                                        • 91.189.91.42
                                                                        CANONICAL-ASGBunix.arm5.elfGet hashmaliciousMiraiBrowse
                                                                        • 91.189.91.42
                                                                        main.sh4.elfGet hashmaliciousMiraiBrowse
                                                                        • 91.189.91.42
                                                                        fuckunix.arm7.elfGet hashmaliciousMiraiBrowse
                                                                        • 91.189.91.42
                                                                        Space.spc.elfGet hashmaliciousMiraiBrowse
                                                                        • 91.189.91.42
                                                                        main.mpsl.elfGet hashmaliciousMiraiBrowse
                                                                        • 91.189.91.42
                                                                        fuckunix.x86.elfGet hashmaliciousMiraiBrowse
                                                                        • 185.125.190.26
                                                                        z0r0.arc.elfGet hashmaliciousMiraiBrowse
                                                                        • 91.189.91.42
                                                                        z0r0.mips.elfGet hashmaliciousUnknownBrowse
                                                                        • 185.125.190.26
                                                                        z0r0.mpsl.elfGet hashmaliciousUnknownBrowse
                                                                        • 185.125.190.26
                                                                        main.x86.elfGet hashmaliciousMiraiBrowse
                                                                        • 91.189.91.42
                                                                        INIT7CHunix.arm5.elfGet hashmaliciousMiraiBrowse
                                                                        • 109.202.202.202
                                                                        main.sh4.elfGet hashmaliciousMiraiBrowse
                                                                        • 109.202.202.202
                                                                        fuckunix.arm7.elfGet hashmaliciousMiraiBrowse
                                                                        • 109.202.202.202
                                                                        Space.spc.elfGet hashmaliciousMiraiBrowse
                                                                        • 109.202.202.202
                                                                        main.mpsl.elfGet hashmaliciousMiraiBrowse
                                                                        • 109.202.202.202
                                                                        z0r0.arc.elfGet hashmaliciousMiraiBrowse
                                                                        • 109.202.202.202
                                                                        main.x86.elfGet hashmaliciousMiraiBrowse
                                                                        • 109.202.202.202
                                                                        fenty.arm4.elfGet hashmaliciousMiraiBrowse
                                                                        • 109.202.202.202
                                                                        Space.arm7.elfGet hashmaliciousMiraiBrowse
                                                                        • 109.202.202.202
                                                                        Space.arm.elfGet hashmaliciousMiraiBrowse
                                                                        • 109.202.202.202
                                                                        COLODEE-AS-APCOLODEEDIGITALNETWORKCOLTDTHunix.sh4.elfGet hashmaliciousMiraiBrowse
                                                                        • 123.253.61.116
                                                                        unix.arm5.elfGet hashmaliciousMiraiBrowse
                                                                        • 123.253.61.116
                                                                        unix.mips.elfGet hashmaliciousMiraiBrowse
                                                                        • 123.253.61.116
                                                                        unix.mpsl.elfGet hashmaliciousMiraiBrowse
                                                                        • 123.253.61.116
                                                                        unix.x86_64.elfGet hashmaliciousMiraiBrowse
                                                                        • 123.253.61.116
                                                                        main.arm7.elfGet hashmaliciousMiraiBrowse
                                                                        • 123.253.61.116
                                                                        main.x86_64.elfGet hashmaliciousMiraiBrowse
                                                                        • 123.253.61.116
                                                                        main.sh4.elfGet hashmaliciousMiraiBrowse
                                                                        • 123.253.61.116
                                                                        fuckunix.arm7.elfGet hashmaliciousMiraiBrowse
                                                                        • 123.253.61.116
                                                                        main.mpsl.elfGet hashmaliciousMiraiBrowse
                                                                        • 123.253.61.116
                                                                        No context
                                                                        No context
                                                                        No created / dropped files found
                                                                        File type:ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, stripped
                                                                        Entropy (8bit):5.716131691837891
                                                                        TrID:
                                                                        • ELF Executable and Linkable format (Linux) (4029/14) 50.16%
                                                                        • ELF Executable and Linkable format (generic) (4004/1) 49.84%
                                                                        File name:unix.x86.elf
                                                                        File size:93'740 bytes
                                                                        MD5:03b9a070b47074f6deefa54821108c27
                                                                        SHA1:bad19bcc748b4e275c5276cc59cf4cef66054271
                                                                        SHA256:7ce28542fb439b9fb1108e9803377977702a21e9f6ba03c7d193a1b712ae89ff
                                                                        SHA512:9a9887739f1cdfd3f733c8fd774dfa36d7056129879ee89735d20e5eef31f80053d248e5f42f5ceb70a4866c17804eddd3e802b814133880fb764961e237d66a
                                                                        SSDEEP:1536:bFflLogqUc1PVQ/EmKpI8mTNzaf4laan5ScYwtOSdgLNTG:b1lLopUcpVwEmKKzTq4c8QcYaNmNTG
                                                                        TLSH:81936BC4F683D4F1E84705B26037E7376B32E0FA505DEA43C3689A32ECA1551EA16B9C
                                                                        File Content Preview:.ELF....................d...4....l......4. ...(.....................|...|................ ..........\L..............Q.td............................U..S.......{....h........[]...$.............U......=`....t..5....D......D.......u........t....h|...........

                                                                        ELF header

                                                                        Class:ELF32
                                                                        Data:2's complement, little endian
                                                                        Version:1 (current)
                                                                        Machine:Intel 80386
                                                                        Version Number:0x1
                                                                        Type:EXEC (Executable file)
                                                                        OS/ABI:UNIX - System V
                                                                        ABI Version:0
                                                                        Entry Point Address:0x8048164
                                                                        Flags:0x0
                                                                        ELF Header Size:52
                                                                        Program Header Offset:52
                                                                        Program Header Size:32
                                                                        Number of Program Headers:3
                                                                        Section Header Offset:93340
                                                                        Section Header Size:40
                                                                        Number of Section Headers:10
                                                                        Header String Table Index:9
                                                                        NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                                                        NULL0x00x00x00x00x0000
                                                                        .initPROGBITS0x80480940x940x1c0x00x6AX001
                                                                        .textPROGBITS0x80480b00xb00xe7c60x00x6AX0016
                                                                        .finiPROGBITS0x80568760xe8760x170x00x6AX001
                                                                        .rodataPROGBITS0x80568a00xe8a00x30dc0x00x2A0032
                                                                        .ctorsPROGBITS0x805a0000x120000xc0x00x3WA004
                                                                        .dtorsPROGBITS0x805a00c0x1200c0x80x00x3WA004
                                                                        .dataPROGBITS0x805a0400x120400x4c1c0x00x3WA0032
                                                                        .bssNOBITS0x805ec600x16c5c0x5a4c0x00x3WA0032
                                                                        .shstrtabSTRTAB0x00x16c5c0x3e0x00x0001
                                                                        TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                                        LOAD0x00x80480000x80480000x1197c0x1197c6.63870x5R E0x1000.init .text .fini .rodata
                                                                        LOAD0x120000x805a0000x805a0000x4c5c0xa6ac0.91230x6RW 0x1000.ctors .dtors .data .bss
                                                                        GNU_STACK0x00x00x00x00x00.00000x6RW 0x4
                                                                        TimestampSource PortDest PortSource IPDest IP
                                                                        Jan 5, 2025 15:21:30.323554039 CET43928443192.168.2.2391.189.91.42
                                                                        Jan 5, 2025 15:21:31.346554995 CET4251680192.168.2.23109.202.202.202
                                                                        Jan 5, 2025 15:21:34.145106077 CET473023778192.168.2.23123.253.61.116
                                                                        Jan 5, 2025 15:21:34.149861097 CET377847302123.253.61.116192.168.2.23
                                                                        Jan 5, 2025 15:21:34.150058985 CET473023778192.168.2.23123.253.61.116
                                                                        Jan 5, 2025 15:21:34.150058985 CET473023778192.168.2.23123.253.61.116
                                                                        Jan 5, 2025 15:21:34.154884100 CET377847302123.253.61.116192.168.2.23
                                                                        Jan 5, 2025 15:21:34.154967070 CET473023778192.168.2.23123.253.61.116
                                                                        Jan 5, 2025 15:21:34.159791946 CET377847302123.253.61.116192.168.2.23
                                                                        Jan 5, 2025 15:21:35.697979927 CET42836443192.168.2.2391.189.91.43
                                                                        Jan 5, 2025 15:21:44.156820059 CET473023778192.168.2.23123.253.61.116
                                                                        Jan 5, 2025 15:21:44.161731005 CET377847302123.253.61.116192.168.2.23
                                                                        Jan 5, 2025 15:21:51.055843115 CET43928443192.168.2.2391.189.91.42
                                                                        Jan 5, 2025 15:21:55.534075975 CET377847302123.253.61.116192.168.2.23
                                                                        Jan 5, 2025 15:21:55.534322977 CET473023778192.168.2.23123.253.61.116
                                                                        Jan 5, 2025 15:21:55.540503979 CET377847302123.253.61.116192.168.2.23
                                                                        Jan 5, 2025 15:21:56.575717926 CET473043778192.168.2.23123.253.61.116
                                                                        Jan 5, 2025 15:21:56.580518961 CET377847304123.253.61.116192.168.2.23
                                                                        Jan 5, 2025 15:21:56.580629110 CET473043778192.168.2.23123.253.61.116
                                                                        Jan 5, 2025 15:21:56.580677032 CET473043778192.168.2.23123.253.61.116
                                                                        Jan 5, 2025 15:21:56.585424900 CET377847304123.253.61.116192.168.2.23
                                                                        Jan 5, 2025 15:21:56.585495949 CET473043778192.168.2.23123.253.61.116
                                                                        Jan 5, 2025 15:21:56.590312958 CET377847304123.253.61.116192.168.2.23
                                                                        Jan 5, 2025 15:22:01.294416904 CET4251680192.168.2.23109.202.202.202
                                                                        Jan 5, 2025 15:22:01.294430017 CET42836443192.168.2.2391.189.91.43
                                                                        Jan 5, 2025 15:22:17.955877066 CET377847304123.253.61.116192.168.2.23
                                                                        Jan 5, 2025 15:22:17.956419945 CET473043778192.168.2.23123.253.61.116
                                                                        Jan 5, 2025 15:22:17.961334944 CET377847304123.253.61.116192.168.2.23
                                                                        Jan 5, 2025 15:22:18.965147972 CET473063778192.168.2.23123.253.61.116
                                                                        Jan 5, 2025 15:22:18.969954967 CET377847306123.253.61.116192.168.2.23
                                                                        Jan 5, 2025 15:22:18.970113993 CET473063778192.168.2.23123.253.61.116
                                                                        Jan 5, 2025 15:22:18.970148087 CET473063778192.168.2.23123.253.61.116
                                                                        Jan 5, 2025 15:22:18.974961042 CET377847306123.253.61.116192.168.2.23
                                                                        Jan 5, 2025 15:22:18.975024939 CET473063778192.168.2.23123.253.61.116
                                                                        Jan 5, 2025 15:22:18.979854107 CET377847306123.253.61.116192.168.2.23
                                                                        Jan 5, 2025 15:22:32.010205984 CET43928443192.168.2.2391.189.91.42
                                                                        Jan 5, 2025 15:22:40.327878952 CET377847306123.253.61.116192.168.2.23
                                                                        Jan 5, 2025 15:22:40.328150988 CET473063778192.168.2.23123.253.61.116
                                                                        Jan 5, 2025 15:22:40.333559990 CET377847306123.253.61.116192.168.2.23
                                                                        Jan 5, 2025 15:22:41.369700909 CET473083778192.168.2.23123.253.61.116
                                                                        Jan 5, 2025 15:22:41.374526024 CET377847308123.253.61.116192.168.2.23
                                                                        Jan 5, 2025 15:22:41.374764919 CET473083778192.168.2.23123.253.61.116
                                                                        Jan 5, 2025 15:22:41.374775887 CET473083778192.168.2.23123.253.61.116
                                                                        Jan 5, 2025 15:22:41.379540920 CET377847308123.253.61.116192.168.2.23
                                                                        Jan 5, 2025 15:22:41.379610062 CET473083778192.168.2.23123.253.61.116
                                                                        Jan 5, 2025 15:22:41.384403944 CET377847308123.253.61.116192.168.2.23
                                                                        Jan 5, 2025 15:22:51.379601002 CET473083778192.168.2.23123.253.61.116
                                                                        Jan 5, 2025 15:22:51.384474993 CET377847308123.253.61.116192.168.2.23
                                                                        Jan 5, 2025 15:22:52.487380028 CET42836443192.168.2.2391.189.91.43
                                                                        Jan 5, 2025 15:23:02.750339985 CET377847308123.253.61.116192.168.2.23
                                                                        Jan 5, 2025 15:23:02.750807047 CET473083778192.168.2.23123.253.61.116
                                                                        Jan 5, 2025 15:23:02.755601883 CET377847308123.253.61.116192.168.2.23
                                                                        Jan 5, 2025 15:23:03.792347908 CET473103778192.168.2.23123.253.61.116
                                                                        Jan 5, 2025 15:23:03.798393965 CET377847310123.253.61.116192.168.2.23
                                                                        Jan 5, 2025 15:23:03.798624039 CET473103778192.168.2.23123.253.61.116
                                                                        Jan 5, 2025 15:23:03.798624039 CET473103778192.168.2.23123.253.61.116
                                                                        Jan 5, 2025 15:23:03.804518938 CET377847310123.253.61.116192.168.2.23
                                                                        Jan 5, 2025 15:23:03.804589033 CET473103778192.168.2.23123.253.61.116
                                                                        Jan 5, 2025 15:23:03.810946941 CET377847310123.253.61.116192.168.2.23
                                                                        Jan 5, 2025 15:23:25.190018892 CET377847310123.253.61.116192.168.2.23
                                                                        Jan 5, 2025 15:23:25.190227985 CET473103778192.168.2.23123.253.61.116
                                                                        Jan 5, 2025 15:23:25.195003986 CET377847310123.253.61.116192.168.2.23
                                                                        Jan 5, 2025 15:23:26.231214046 CET473123778192.168.2.23123.253.61.116
                                                                        Jan 5, 2025 15:23:26.236027956 CET377847312123.253.61.116192.168.2.23
                                                                        Jan 5, 2025 15:23:26.236093044 CET473123778192.168.2.23123.253.61.116
                                                                        Jan 5, 2025 15:23:26.236113071 CET473123778192.168.2.23123.253.61.116
                                                                        Jan 5, 2025 15:23:26.240905046 CET377847312123.253.61.116192.168.2.23
                                                                        Jan 5, 2025 15:23:26.240942955 CET473123778192.168.2.23123.253.61.116
                                                                        Jan 5, 2025 15:23:26.245707035 CET377847312123.253.61.116192.168.2.23
                                                                        TimestampSource PortDest PortSource IPDest IP
                                                                        Jan 5, 2025 15:21:34.108767986 CET4283353192.168.2.238.8.8.8
                                                                        Jan 5, 2025 15:21:34.144901037 CET53428338.8.8.8192.168.2.23
                                                                        Jan 5, 2025 15:21:56.535959959 CET4984953192.168.2.238.8.8.8
                                                                        Jan 5, 2025 15:21:56.575561047 CET53498498.8.8.8192.168.2.23
                                                                        Jan 5, 2025 15:22:18.958000898 CET3906453192.168.2.238.8.8.8
                                                                        Jan 5, 2025 15:22:18.965020895 CET53390648.8.8.8192.168.2.23
                                                                        Jan 5, 2025 15:22:41.329133987 CET5409553192.168.2.238.8.8.8
                                                                        Jan 5, 2025 15:22:41.369626999 CET53540958.8.8.8192.168.2.23
                                                                        Jan 5, 2025 15:23:03.752213001 CET5199853192.168.2.238.8.8.8
                                                                        Jan 5, 2025 15:23:03.792202950 CET53519988.8.8.8192.168.2.23
                                                                        Jan 5, 2025 15:23:26.191631079 CET5583053192.168.2.238.8.8.8
                                                                        Jan 5, 2025 15:23:26.231129885 CET53558308.8.8.8192.168.2.23
                                                                        TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                                                        Jan 5, 2025 15:21:34.108767986 CET192.168.2.238.8.8.80x0Standard query (0)unixbot.ddns.netA (IP address)IN (0x0001)false
                                                                        Jan 5, 2025 15:21:56.535959959 CET192.168.2.238.8.8.80x0Standard query (0)unixbot.ddns.netA (IP address)IN (0x0001)false
                                                                        Jan 5, 2025 15:22:18.958000898 CET192.168.2.238.8.8.80x0Standard query (0)unixbot.ddns.netA (IP address)IN (0x0001)false
                                                                        Jan 5, 2025 15:22:41.329133987 CET192.168.2.238.8.8.80x0Standard query (0)unixbot.ddns.netA (IP address)IN (0x0001)false
                                                                        Jan 5, 2025 15:23:03.752213001 CET192.168.2.238.8.8.80x0Standard query (0)unixbot.ddns.netA (IP address)IN (0x0001)false
                                                                        Jan 5, 2025 15:23:26.191631079 CET192.168.2.238.8.8.80x0Standard query (0)unixbot.ddns.netA (IP address)IN (0x0001)false
                                                                        TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                                                        Jan 5, 2025 15:21:34.144901037 CET8.8.8.8192.168.2.230x0No error (0)unixbot.ddns.net123.253.61.116A (IP address)IN (0x0001)false
                                                                        Jan 5, 2025 15:21:56.575561047 CET8.8.8.8192.168.2.230x0No error (0)unixbot.ddns.net123.253.61.116A (IP address)IN (0x0001)false
                                                                        Jan 5, 2025 15:22:18.965020895 CET8.8.8.8192.168.2.230x0No error (0)unixbot.ddns.net123.253.61.116A (IP address)IN (0x0001)false
                                                                        Jan 5, 2025 15:22:41.369626999 CET8.8.8.8192.168.2.230x0No error (0)unixbot.ddns.net123.253.61.116A (IP address)IN (0x0001)false
                                                                        Jan 5, 2025 15:23:03.792202950 CET8.8.8.8192.168.2.230x0No error (0)unixbot.ddns.net123.253.61.116A (IP address)IN (0x0001)false
                                                                        Jan 5, 2025 15:23:26.231129885 CET8.8.8.8192.168.2.230x0No error (0)unixbot.ddns.net123.253.61.116A (IP address)IN (0x0001)false

                                                                        System Behavior

                                                                        Start time (UTC):14:21:27
                                                                        Start date (UTC):05/01/2025
                                                                        Path:/tmp/unix.x86.elf
                                                                        Arguments:/tmp/unix.x86.elf
                                                                        File size:93740 bytes
                                                                        MD5 hash:03b9a070b47074f6deefa54821108c27

                                                                        Start time (UTC):14:21:27
                                                                        Start date (UTC):05/01/2025
                                                                        Path:/tmp/unix.x86.elf
                                                                        Arguments:-
                                                                        File size:93740 bytes
                                                                        MD5 hash:03b9a070b47074f6deefa54821108c27