Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
fuckunix.x86_64.elf

Overview

General Information

Sample name:fuckunix.x86_64.elf
Analysis ID:1584474
MD5:ec0334b40fe1c306ab2e7a37788c44b8
SHA1:5a55507248eb51f46ef2dfc296a9246607510434
SHA256:a58781523a35d9033d99bbe68ba203864d5154d5ce1382892a5d034fe46db208
Tags:elfuser-abuse_ch
Infos:

Detection

Mirai
Score:76
Range:0 - 100
Whitelisted:false

Signatures

Antivirus / Scanner detection for submitted sample
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Yara detected Mirai
Machine Learning detection for sample
Sample has stripped symbol table
Sample listens on a socket
Tries to resolve domain names, but no domain seems valid (expired dropper behavior)
Yara signature match

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1584474
Start date and time:2025-01-05 15:28:27 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 27s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:fuckunix.x86_64.elf
Detection:MAL
Classification:mal76.troj.linELF@0/0@30/0
Command:/tmp/fuckunix.x86_64.elf
PID:5500
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
listening tun0
Standard Error:
  • system is lnxubuntu20
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
MiraiMirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese. Nowadays it targets a wide range of networked embedded devices such as IP cameras, home routers (many vendors involved), and other IoT devices. Since the source code was published on "Hack Forums" many variants of the Mirai family appeared, infecting mostly home networks all around the world.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/elf.mirai
SourceRuleDescriptionAuthorStrings
fuckunix.x86_64.elfJoeSecurity_Mirai_3Yara detected MiraiJoe Security
    fuckunix.x86_64.elfLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
    • 0x86e8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x86fc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x8710:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x8724:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x8738:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x874c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x8760:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x8774:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x8788:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x879c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x87b0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x87c4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x87d8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x87ec:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x8800:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x8814:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x8828:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x883c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x8850:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x8864:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x8878:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    fuckunix.x86_64.elfLinux_Trojan_Gafgyt_9e9530a7unknownunknown
    • 0x5c44:$a: F6 48 63 FF B8 36 00 00 00 0F 05 48 3D 00 F0 FF FF 48 89 C3
    fuckunix.x86_64.elfLinux_Trojan_Gafgyt_807911a2unknownunknown
    • 0x6433:$a: FE 48 39 F3 0F 94 C2 48 83 F9 FF 0F 94 C0 84 D0 74 16 4B 8D
    fuckunix.x86_64.elfLinux_Trojan_Gafgyt_d4227dbfunknownunknown
    • 0x5372:$a: FF 48 81 EC D0 00 00 00 48 8D 84 24 E0 00 00 00 48 89 54 24 30 C7 04 24 18 00
    Click to see the 6 entries
    SourceRuleDescriptionAuthorStrings
    5500.1.0000000000400000.000000000040b000.r-x.sdmpJoeSecurity_Mirai_3Yara detected MiraiJoe Security
      5500.1.0000000000400000.000000000040b000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
      • 0x86e8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x86fc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x8710:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x8724:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x8738:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x874c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x8760:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x8774:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x8788:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x879c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x87b0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x87c4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x87d8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x87ec:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x8800:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x8814:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x8828:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x883c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x8850:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x8864:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x8878:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      5500.1.0000000000400000.000000000040b000.r-x.sdmpLinux_Trojan_Gafgyt_9e9530a7unknownunknown
      • 0x5c44:$a: F6 48 63 FF B8 36 00 00 00 0F 05 48 3D 00 F0 FF FF 48 89 C3
      5500.1.0000000000400000.000000000040b000.r-x.sdmpLinux_Trojan_Gafgyt_807911a2unknownunknown
      • 0x6433:$a: FE 48 39 F3 0F 94 C2 48 83 F9 FF 0F 94 C0 84 D0 74 16 4B 8D
      5500.1.0000000000400000.000000000040b000.r-x.sdmpLinux_Trojan_Gafgyt_d4227dbfunknownunknown
      • 0x5372:$a: FF 48 81 EC D0 00 00 00 48 8D 84 24 E0 00 00 00 48 89 54 24 30 C7 04 24 18 00
      Click to see the 8 entries
      No Suricata rule has matched

      Click to jump to signature section

      Show All Signature Results

      AV Detection

      barindex
      Source: fuckunix.x86_64.elfAvira: detected
      Source: fuckunix.x86_64.elfVirustotal: Detection: 57%Perma Link
      Source: fuckunix.x86_64.elfReversingLabs: Detection: 60%
      Source: fuckunix.x86_64.elfJoe Sandbox ML: detected
      Source: /tmp/fuckunix.x86_64.elf (PID: 5500)Socket: 127.0.0.1:48132Jump to behavior
      Source: unknownDNS traffic detected: query: ybetncx"hhb"bix replaycode: Name error (3)
      Source: unknownTCP traffic detected without corresponding DNS query: 123.253.61.116
      Source: unknownTCP traffic detected without corresponding DNS query: 123.253.61.116
      Source: unknownTCP traffic detected without corresponding DNS query: 123.253.61.116
      Source: unknownTCP traffic detected without corresponding DNS query: 123.253.61.116
      Source: unknownTCP traffic detected without corresponding DNS query: 123.253.61.116
      Source: unknownTCP traffic detected without corresponding DNS query: 185.125.190.26
      Source: unknownTCP traffic detected without corresponding DNS query: 123.253.61.116
      Source: unknownTCP traffic detected without corresponding DNS query: 123.253.61.116
      Source: unknownTCP traffic detected without corresponding DNS query: 123.253.61.116
      Source: unknownTCP traffic detected without corresponding DNS query: 123.253.61.116
      Source: unknownTCP traffic detected without corresponding DNS query: 123.253.61.116
      Source: unknownTCP traffic detected without corresponding DNS query: 185.125.190.26
      Source: unknownTCP traffic detected without corresponding DNS query: 123.253.61.116
      Source: unknownTCP traffic detected without corresponding DNS query: 123.253.61.116
      Source: unknownTCP traffic detected without corresponding DNS query: 123.253.61.116
      Source: unknownTCP traffic detected without corresponding DNS query: 123.253.61.116
      Source: unknownTCP traffic detected without corresponding DNS query: 123.253.61.116
      Source: unknownTCP traffic detected without corresponding DNS query: 123.253.61.116
      Source: unknownTCP traffic detected without corresponding DNS query: 123.253.61.116
      Source: unknownTCP traffic detected without corresponding DNS query: 123.253.61.116
      Source: unknownTCP traffic detected without corresponding DNS query: 123.253.61.116
      Source: unknownTCP traffic detected without corresponding DNS query: 123.253.61.116
      Source: unknownTCP traffic detected without corresponding DNS query: 123.253.61.116
      Source: unknownTCP traffic detected without corresponding DNS query: 123.253.61.116
      Source: unknownTCP traffic detected without corresponding DNS query: 123.253.61.116
      Source: unknownTCP traffic detected without corresponding DNS query: 123.253.61.116
      Source: unknownTCP traffic detected without corresponding DNS query: 123.253.61.116
      Source: unknownTCP traffic detected without corresponding DNS query: 123.253.61.116
      Source: unknownTCP traffic detected without corresponding DNS query: 123.253.61.116
      Source: unknownTCP traffic detected without corresponding DNS query: 123.253.61.116
      Source: unknownTCP traffic detected without corresponding DNS query: 123.253.61.116
      Source: unknownTCP traffic detected without corresponding DNS query: 123.253.61.116
      Source: unknownTCP traffic detected without corresponding DNS query: 123.253.61.116
      Source: global trafficDNS traffic detected: DNS query: ybetncx"hhb"bix
      Source: unknownNetwork traffic detected: HTTP traffic on port 46540 -> 443

      System Summary

      barindex
      Source: fuckunix.x86_64.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
      Source: fuckunix.x86_64.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_9e9530a7 Author: unknown
      Source: fuckunix.x86_64.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_807911a2 Author: unknown
      Source: fuckunix.x86_64.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_d4227dbf Author: unknown
      Source: fuckunix.x86_64.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_620087b9 Author: unknown
      Source: fuckunix.x86_64.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_33b4111a Author: unknown
      Source: fuckunix.x86_64.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_520deeb8 Author: unknown
      Source: fuckunix.x86_64.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_6a77af0f Author: unknown
      Source: fuckunix.x86_64.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_01e4a728 Author: unknown
      Source: fuckunix.x86_64.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_e0cf29e2 Author: unknown
      Source: 5500.1.0000000000400000.000000000040b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
      Source: 5500.1.0000000000400000.000000000040b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_9e9530a7 Author: unknown
      Source: 5500.1.0000000000400000.000000000040b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_807911a2 Author: unknown
      Source: 5500.1.0000000000400000.000000000040b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d4227dbf Author: unknown
      Source: 5500.1.0000000000400000.000000000040b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_620087b9 Author: unknown
      Source: 5500.1.0000000000400000.000000000040b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_33b4111a Author: unknown
      Source: 5500.1.0000000000400000.000000000040b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_520deeb8 Author: unknown
      Source: 5500.1.0000000000400000.000000000040b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_6a77af0f Author: unknown
      Source: 5500.1.0000000000400000.000000000040b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_01e4a728 Author: unknown
      Source: 5500.1.0000000000400000.000000000040b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_e0cf29e2 Author: unknown
      Source: Process Memory Space: fuckunix.x86_64.elf PID: 5500, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
      Source: ELF static info symbol of initial sample.symtab present: no
      Source: fuckunix.x86_64.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
      Source: fuckunix.x86_64.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_9e9530a7 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = d6ad6512051e87c8c35dc168d82edd071b122d026dce21d39b9782b3d6a01e50, id = 9e9530a7-ad4d-4a44-b764-437b7621052f, last_modified = 2021-09-16
      Source: fuckunix.x86_64.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_807911a2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = f409037091b7372f5a42bbe437316bd11c655e7a5fe1fcf83d1981cb5c4a389f, id = 807911a2-f6ec-4e65-924f-61cb065dafc6, last_modified = 2021-09-16
      Source: fuckunix.x86_64.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_d4227dbf reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 58c4b1d4d167876b64cfa10f609911a80284180e4db093917fea16fae8ccd4e3, id = d4227dbf-6ab4-4637-a6ba-0e604acaafb4, last_modified = 2021-09-16
      Source: fuckunix.x86_64.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_620087b9 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 06cd7e6eb62352ec2ccb9ed48e58c0583c02fefd137cd048d053ab30b5330307, id = 620087b9-c87d-4752-89e8-ca1c16486b28, last_modified = 2021-09-16
      Source: fuckunix.x86_64.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_33b4111a reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 9c3b63b9a0f54006bae12abcefdb518904a85f78be573f0780f0a265b12d2d6e, id = 33b4111a-e59e-48db-9d74-34ca44fcd9f5, last_modified = 2021-09-16
      Source: fuckunix.x86_64.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_520deeb8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = f4dfd1d76e07ff875eedfe0ef4f861bee1e4d8e66d68385f602f29cc35e30cca, id = 520deeb8-cbc0-4225-8d23-adba5e040471, last_modified = 2021-09-16
      Source: fuckunix.x86_64.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_6a77af0f os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 4e436f509e7e732e3d0326bcbdde555bba0653213ddf31b43cfdfbe16abb0016, id = 6a77af0f-31fa-4793-82aa-10b065ba1ec0, last_modified = 2021-09-16
      Source: fuckunix.x86_64.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_01e4a728 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = d90477364982bdc6cd22079c245d866454475749f762620273091f2fab73c196, id = 01e4a728-7c1c-479b-aed0-cb76d64dbb02, last_modified = 2021-09-16
      Source: fuckunix.x86_64.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_e0cf29e2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 3f124c3c9f124264dfbbcca1e4b4d7cfcf3274170d4bf8966b6559045873948f, id = e0cf29e2-88d7-4aa4-b60a-c24626f2b246, last_modified = 2021-09-16
      Source: 5500.1.0000000000400000.000000000040b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
      Source: 5500.1.0000000000400000.000000000040b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_9e9530a7 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = d6ad6512051e87c8c35dc168d82edd071b122d026dce21d39b9782b3d6a01e50, id = 9e9530a7-ad4d-4a44-b764-437b7621052f, last_modified = 2021-09-16
      Source: 5500.1.0000000000400000.000000000040b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_807911a2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = f409037091b7372f5a42bbe437316bd11c655e7a5fe1fcf83d1981cb5c4a389f, id = 807911a2-f6ec-4e65-924f-61cb065dafc6, last_modified = 2021-09-16
      Source: 5500.1.0000000000400000.000000000040b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d4227dbf reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 58c4b1d4d167876b64cfa10f609911a80284180e4db093917fea16fae8ccd4e3, id = d4227dbf-6ab4-4637-a6ba-0e604acaafb4, last_modified = 2021-09-16
      Source: 5500.1.0000000000400000.000000000040b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_620087b9 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 06cd7e6eb62352ec2ccb9ed48e58c0583c02fefd137cd048d053ab30b5330307, id = 620087b9-c87d-4752-89e8-ca1c16486b28, last_modified = 2021-09-16
      Source: 5500.1.0000000000400000.000000000040b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_33b4111a reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 9c3b63b9a0f54006bae12abcefdb518904a85f78be573f0780f0a265b12d2d6e, id = 33b4111a-e59e-48db-9d74-34ca44fcd9f5, last_modified = 2021-09-16
      Source: 5500.1.0000000000400000.000000000040b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_520deeb8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = f4dfd1d76e07ff875eedfe0ef4f861bee1e4d8e66d68385f602f29cc35e30cca, id = 520deeb8-cbc0-4225-8d23-adba5e040471, last_modified = 2021-09-16
      Source: 5500.1.0000000000400000.000000000040b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_6a77af0f os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 4e436f509e7e732e3d0326bcbdde555bba0653213ddf31b43cfdfbe16abb0016, id = 6a77af0f-31fa-4793-82aa-10b065ba1ec0, last_modified = 2021-09-16
      Source: 5500.1.0000000000400000.000000000040b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_01e4a728 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = d90477364982bdc6cd22079c245d866454475749f762620273091f2fab73c196, id = 01e4a728-7c1c-479b-aed0-cb76d64dbb02, last_modified = 2021-09-16
      Source: 5500.1.0000000000400000.000000000040b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_e0cf29e2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 3f124c3c9f124264dfbbcca1e4b4d7cfcf3274170d4bf8966b6559045873948f, id = e0cf29e2-88d7-4aa4-b60a-c24626f2b246, last_modified = 2021-09-16
      Source: Process Memory Space: fuckunix.x86_64.elf PID: 5500, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
      Source: classification engineClassification label: mal76.troj.linELF@0/0@30/0

      Stealing of Sensitive Information

      barindex
      Source: Yara matchFile source: fuckunix.x86_64.elf, type: SAMPLE
      Source: Yara matchFile source: 5500.1.0000000000400000.000000000040b000.r-x.sdmp, type: MEMORY
      Source: Yara matchFile source: Process Memory Space: fuckunix.x86_64.elf PID: 5500, type: MEMORYSTR

      Remote Access Functionality

      barindex
      Source: Yara matchFile source: fuckunix.x86_64.elf, type: SAMPLE
      Source: Yara matchFile source: 5500.1.0000000000400000.000000000040b000.r-x.sdmp, type: MEMORY
      Source: Yara matchFile source: Process Memory Space: fuckunix.x86_64.elf PID: 5500, type: MEMORYSTR
      ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
      Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath InterceptionDirect Volume AccessOS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
      Encrypted Channel
      Exfiltration Over Other Network MediumAbuse Accessibility Features
      CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
      Non-Application Layer Protocol
      Exfiltration Over BluetoothNetwork Denial of Service
      Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive2
      Application Layer Protocol
      Automated ExfiltrationData Encrypted for Impact
      No configs have been found
      SourceDetectionScannerLabelLink
      fuckunix.x86_64.elf58%VirustotalBrowse
      fuckunix.x86_64.elf61%ReversingLabsLinux.Trojan.Mirai
      fuckunix.x86_64.elf100%AviraEXP/ELF.Gafgyt.D
      fuckunix.x86_64.elf100%Joe Sandbox ML
      No Antivirus matches
      No Antivirus matches
      No Antivirus matches
      No contacted domains info
      • No. of IPs < 25%
      • 25% < No. of IPs < 50%
      • 50% < No. of IPs < 75%
      • 75% < No. of IPs
      IPDomainCountryFlagASNASN NameMalicious
      185.125.190.26
      unknownUnited Kingdom
      41231CANONICAL-ASGBfalse
      123.253.61.116
      unknownThailand
      136523COLODEE-AS-APCOLODEEDIGITALNETWORKCOLTDTHfalse
      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
      185.125.190.26momo.sh4.elfGet hashmaliciousMiraiBrowse
        fuckunix.x86.elfGet hashmaliciousMiraiBrowse
          z0r0.mips.elfGet hashmaliciousUnknownBrowse
            z0r0.mpsl.elfGet hashmaliciousUnknownBrowse
              fenty.arm4.elfGet hashmaliciousMiraiBrowse
                a.elfGet hashmaliciousGafgytBrowse
                  176.119.150.11-i-2025-01-04T15_20_35.elfGet hashmaliciousGafgyt, MiraiBrowse
                    Space.ppc.elfGet hashmaliciousMiraiBrowse
                      la.bot.mipsel.elfGet hashmaliciousMiraiBrowse
                        185.232.205.45-boatnet.mips-2025-01-03T23_59_45.elfGet hashmaliciousMiraiBrowse
                          123.253.61.116unix.arm.elfGet hashmaliciousMiraiBrowse
                            unix.x86.elfGet hashmaliciousMiraiBrowse
                              unix.sh4.elfGet hashmaliciousMiraiBrowse
                                unix.arm5.elfGet hashmaliciousMiraiBrowse
                                  unix.mips.elfGet hashmaliciousMiraiBrowse
                                    unix.mpsl.elfGet hashmaliciousMiraiBrowse
                                      unix.x86_64.elfGet hashmaliciousMiraiBrowse
                                        main.arm7.elfGet hashmaliciousMiraiBrowse
                                          main.x86_64.elfGet hashmaliciousMiraiBrowse
                                            main.sh4.elfGet hashmaliciousMiraiBrowse
                                              No context
                                              MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                              CANONICAL-ASGBmomo.sh4.elfGet hashmaliciousMiraiBrowse
                                              • 185.125.190.26
                                              momo.x86.elfGet hashmaliciousMiraiBrowse
                                              • 91.189.91.42
                                              unix.x86.elfGet hashmaliciousMiraiBrowse
                                              • 91.189.91.42
                                              unix.arm5.elfGet hashmaliciousMiraiBrowse
                                              • 91.189.91.42
                                              main.sh4.elfGet hashmaliciousMiraiBrowse
                                              • 91.189.91.42
                                              fuckunix.arm7.elfGet hashmaliciousMiraiBrowse
                                              • 91.189.91.42
                                              Space.spc.elfGet hashmaliciousMiraiBrowse
                                              • 91.189.91.42
                                              main.mpsl.elfGet hashmaliciousMiraiBrowse
                                              • 91.189.91.42
                                              fuckunix.x86.elfGet hashmaliciousMiraiBrowse
                                              • 185.125.190.26
                                              z0r0.arc.elfGet hashmaliciousMiraiBrowse
                                              • 91.189.91.42
                                              COLODEE-AS-APCOLODEEDIGITALNETWORKCOLTDTHunix.arm.elfGet hashmaliciousMiraiBrowse
                                              • 123.253.61.116
                                              unix.x86.elfGet hashmaliciousMiraiBrowse
                                              • 123.253.61.116
                                              unix.sh4.elfGet hashmaliciousMiraiBrowse
                                              • 123.253.61.116
                                              unix.arm5.elfGet hashmaliciousMiraiBrowse
                                              • 123.253.61.116
                                              unix.mips.elfGet hashmaliciousMiraiBrowse
                                              • 123.253.61.116
                                              unix.mpsl.elfGet hashmaliciousMiraiBrowse
                                              • 123.253.61.116
                                              unix.x86_64.elfGet hashmaliciousMiraiBrowse
                                              • 123.253.61.116
                                              main.arm7.elfGet hashmaliciousMiraiBrowse
                                              • 123.253.61.116
                                              main.x86_64.elfGet hashmaliciousMiraiBrowse
                                              • 123.253.61.116
                                              main.sh4.elfGet hashmaliciousMiraiBrowse
                                              • 123.253.61.116
                                              No context
                                              No context
                                              No created / dropped files found
                                              File type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), statically linked, stripped
                                              Entropy (8bit):6.257581978658178
                                              TrID:
                                              • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                                              File name:fuckunix.x86_64.elf
                                              File size:42'720 bytes
                                              MD5:ec0334b40fe1c306ab2e7a37788c44b8
                                              SHA1:5a55507248eb51f46ef2dfc296a9246607510434
                                              SHA256:a58781523a35d9033d99bbe68ba203864d5154d5ce1382892a5d034fe46db208
                                              SHA512:d316038aebd891b4126d4ef4cf1f37f1d3e179c135be947bcfdb74c6434c4fe946788a30684da164208cd3163e1c3e5727011e3094f2d913be295f2d61464257
                                              SSDEEP:768:MIkksBtHmcHjwhqMpbiAI2doAp6XNpQNBcwdjQ9o/89aPsvKQLDL:QksBtHmcHchqYbmApm4NBcwdn89aU3Ln
                                              TLSH:7E131927F64681FDC45AC17842BBBA36D82274FE1239B19737E0FB326997D221E19C44
                                              File Content Preview:.ELF..............>.......@.....@.......`...........@.8...@.......................@.......@...............................................P.......P.....8.......`...............Q.td....................................................H...._........H........

                                              ELF header

                                              Class:ELF64
                                              Data:2's complement, little endian
                                              Version:1 (current)
                                              Machine:Advanced Micro Devices X86-64
                                              Version Number:0x1
                                              Type:EXEC (Executable file)
                                              OS/ABI:UNIX - System V
                                              ABI Version:0
                                              Entry Point Address:0x400194
                                              Flags:0x0
                                              ELF Header Size:64
                                              Program Header Offset:64
                                              Program Header Size:56
                                              Number of Program Headers:3
                                              Section Header Offset:42080
                                              Section Header Size:64
                                              Number of Section Headers:10
                                              Header String Table Index:9
                                              NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                              NULL0x00x00x00x00x0000
                                              .initPROGBITS0x4000e80xe80x130x00x6AX001
                                              .textPROGBITS0x4001000x1000x81060x00x6AX0016
                                              .finiPROGBITS0x4082060x82060xe0x00x6AX001
                                              .rodataPROGBITS0x4082200x82200x1fc00x00x2A0032
                                              .ctorsPROGBITS0x50a1e80xa1e80x100x00x3WA008
                                              .dtorsPROGBITS0x50a1f80xa1f80x100x00x3WA008
                                              .dataPROGBITS0x50a2200xa2200x2000x00x3WA0032
                                              .bssNOBITS0x50a4200xa4200xb280x00x3WA0032
                                              .shstrtabSTRTAB0x00xa4200x3e0x00x0001
                                              TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                              LOAD0x00x4000000x4000000xa1e00xa1e06.33170x5R E0x100000.init .text .fini .rodata
                                              LOAD0xa1e80x50a1e80x50a1e80x2380xd602.92620x6RW 0x100000.ctors .dtors .data .bss
                                              GNU_STACK0x00x00x00x00x00.00000x6RW 0x8
                                              TimestampSource PortDest PortSource IPDest IP
                                              Jan 5, 2025 15:29:19.390809059 CET5822880192.168.2.14123.253.61.116
                                              Jan 5, 2025 15:29:19.395576000 CET8058228123.253.61.116192.168.2.14
                                              Jan 5, 2025 15:29:19.395665884 CET5822880192.168.2.14123.253.61.116
                                              Jan 5, 2025 15:29:19.396313906 CET5822880192.168.2.14123.253.61.116
                                              Jan 5, 2025 15:29:19.401103020 CET8058228123.253.61.116192.168.2.14
                                              Jan 5, 2025 15:29:19.401145935 CET5822880192.168.2.14123.253.61.116
                                              Jan 5, 2025 15:29:19.405927896 CET8058228123.253.61.116192.168.2.14
                                              Jan 5, 2025 15:29:29.406260967 CET5822880192.168.2.14123.253.61.116
                                              Jan 5, 2025 15:29:29.411005974 CET8058228123.253.61.116192.168.2.14
                                              Jan 5, 2025 15:29:30.163722992 CET46540443192.168.2.14185.125.190.26
                                              Jan 5, 2025 15:29:40.776345968 CET8058228123.253.61.116192.168.2.14
                                              Jan 5, 2025 15:29:40.776561975 CET5822880192.168.2.14123.253.61.116
                                              Jan 5, 2025 15:29:40.781459093 CET8058228123.253.61.116192.168.2.14
                                              Jan 5, 2025 15:29:41.818629980 CET5823080192.168.2.14123.253.61.116
                                              Jan 5, 2025 15:29:41.823451996 CET8058230123.253.61.116192.168.2.14
                                              Jan 5, 2025 15:29:41.823520899 CET5823080192.168.2.14123.253.61.116
                                              Jan 5, 2025 15:29:41.824259996 CET5823080192.168.2.14123.253.61.116
                                              Jan 5, 2025 15:29:41.829137087 CET8058230123.253.61.116192.168.2.14
                                              Jan 5, 2025 15:29:41.829189062 CET5823080192.168.2.14123.253.61.116
                                              Jan 5, 2025 15:29:41.834017992 CET8058230123.253.61.116192.168.2.14
                                              Jan 5, 2025 15:30:01.650921106 CET46540443192.168.2.14185.125.190.26
                                              Jan 5, 2025 15:30:03.200436115 CET8058230123.253.61.116192.168.2.14
                                              Jan 5, 2025 15:30:03.200932980 CET5823080192.168.2.14123.253.61.116
                                              Jan 5, 2025 15:30:03.205770016 CET8058230123.253.61.116192.168.2.14
                                              Jan 5, 2025 15:30:04.246728897 CET5823280192.168.2.14123.253.61.116
                                              Jan 5, 2025 15:30:04.252245903 CET8058232123.253.61.116192.168.2.14
                                              Jan 5, 2025 15:30:04.252294064 CET5823280192.168.2.14123.253.61.116
                                              Jan 5, 2025 15:30:04.252907038 CET5823280192.168.2.14123.253.61.116
                                              Jan 5, 2025 15:30:04.258307934 CET8058232123.253.61.116192.168.2.14
                                              Jan 5, 2025 15:30:04.258351088 CET5823280192.168.2.14123.253.61.116
                                              Jan 5, 2025 15:30:04.263164997 CET8058232123.253.61.116192.168.2.14
                                              Jan 5, 2025 15:30:25.621191025 CET8058232123.253.61.116192.168.2.14
                                              Jan 5, 2025 15:30:25.621387959 CET5823280192.168.2.14123.253.61.116
                                              Jan 5, 2025 15:30:25.626207113 CET8058232123.253.61.116192.168.2.14
                                              Jan 5, 2025 15:30:26.664465904 CET5823480192.168.2.14123.253.61.116
                                              Jan 5, 2025 15:30:26.669264078 CET8058234123.253.61.116192.168.2.14
                                              Jan 5, 2025 15:30:26.669348955 CET5823480192.168.2.14123.253.61.116
                                              Jan 5, 2025 15:30:26.670403004 CET5823480192.168.2.14123.253.61.116
                                              Jan 5, 2025 15:30:26.675188065 CET8058234123.253.61.116192.168.2.14
                                              Jan 5, 2025 15:30:26.675251007 CET5823480192.168.2.14123.253.61.116
                                              Jan 5, 2025 15:30:26.682039022 CET8058234123.253.61.116192.168.2.14
                                              Jan 5, 2025 15:30:36.680057049 CET5823480192.168.2.14123.253.61.116
                                              Jan 5, 2025 15:30:36.684931993 CET8058234123.253.61.116192.168.2.14
                                              Jan 5, 2025 15:30:48.027967930 CET8058234123.253.61.116192.168.2.14
                                              Jan 5, 2025 15:30:48.028623104 CET5823480192.168.2.14123.253.61.116
                                              Jan 5, 2025 15:30:48.033452988 CET8058234123.253.61.116192.168.2.14
                                              Jan 5, 2025 15:30:49.095001936 CET5823680192.168.2.14123.253.61.116
                                              Jan 5, 2025 15:30:49.099874020 CET8058236123.253.61.116192.168.2.14
                                              Jan 5, 2025 15:30:49.099946976 CET5823680192.168.2.14123.253.61.116
                                              Jan 5, 2025 15:30:49.100963116 CET5823680192.168.2.14123.253.61.116
                                              Jan 5, 2025 15:30:49.105690956 CET8058236123.253.61.116192.168.2.14
                                              Jan 5, 2025 15:30:49.105751991 CET5823680192.168.2.14123.253.61.116
                                              Jan 5, 2025 15:30:49.110532999 CET8058236123.253.61.116192.168.2.14
                                              Jan 5, 2025 15:31:10.450472116 CET8058236123.253.61.116192.168.2.14
                                              Jan 5, 2025 15:31:10.450694084 CET5823680192.168.2.14123.253.61.116
                                              Jan 5, 2025 15:31:10.455533981 CET8058236123.253.61.116192.168.2.14
                                              Jan 5, 2025 15:31:11.493412018 CET5823880192.168.2.14123.253.61.116
                                              Jan 5, 2025 15:31:11.498285055 CET8058238123.253.61.116192.168.2.14
                                              Jan 5, 2025 15:31:11.498402119 CET5823880192.168.2.14123.253.61.116
                                              Jan 5, 2025 15:31:11.499464989 CET5823880192.168.2.14123.253.61.116
                                              Jan 5, 2025 15:31:11.504192114 CET8058238123.253.61.116192.168.2.14
                                              Jan 5, 2025 15:31:11.504235983 CET5823880192.168.2.14123.253.61.116
                                              Jan 5, 2025 15:31:11.508985996 CET8058238123.253.61.116192.168.2.14
                                              TimestampSource PortDest PortSource IPDest IP
                                              Jan 5, 2025 15:29:19.349864960 CET4664153192.168.2.148.8.8.8
                                              Jan 5, 2025 15:29:19.359736919 CET53466418.8.8.8192.168.2.14
                                              Jan 5, 2025 15:29:19.360477924 CET6036153192.168.2.148.8.8.8
                                              Jan 5, 2025 15:29:19.367445946 CET53603618.8.8.8192.168.2.14
                                              Jan 5, 2025 15:29:19.368077040 CET4737553192.168.2.148.8.8.8
                                              Jan 5, 2025 15:29:19.375193119 CET53473758.8.8.8192.168.2.14
                                              Jan 5, 2025 15:29:19.375794888 CET3867853192.168.2.148.8.8.8
                                              Jan 5, 2025 15:29:19.382747889 CET53386788.8.8.8192.168.2.14
                                              Jan 5, 2025 15:29:19.383382082 CET5589853192.168.2.148.8.8.8
                                              Jan 5, 2025 15:29:19.390449047 CET53558988.8.8.8192.168.2.14
                                              Jan 5, 2025 15:29:41.778803110 CET5362253192.168.2.148.8.8.8
                                              Jan 5, 2025 15:29:41.786590099 CET53536228.8.8.8192.168.2.14
                                              Jan 5, 2025 15:29:41.787492990 CET4034053192.168.2.148.8.8.8
                                              Jan 5, 2025 15:29:41.794408083 CET53403408.8.8.8192.168.2.14
                                              Jan 5, 2025 15:29:41.795381069 CET4027853192.168.2.148.8.8.8
                                              Jan 5, 2025 15:29:41.802412987 CET53402788.8.8.8192.168.2.14
                                              Jan 5, 2025 15:29:41.803159952 CET4583253192.168.2.148.8.8.8
                                              Jan 5, 2025 15:29:41.810369968 CET53458328.8.8.8192.168.2.14
                                              Jan 5, 2025 15:29:41.811192989 CET4082353192.168.2.148.8.8.8
                                              Jan 5, 2025 15:29:41.818280935 CET53408238.8.8.8192.168.2.14
                                              Jan 5, 2025 15:30:04.202987909 CET3695653192.168.2.148.8.8.8
                                              Jan 5, 2025 15:30:04.209868908 CET53369568.8.8.8192.168.2.14
                                              Jan 5, 2025 15:30:04.210510969 CET4477853192.168.2.148.8.8.8
                                              Jan 5, 2025 15:30:04.217403889 CET53447788.8.8.8192.168.2.14
                                              Jan 5, 2025 15:30:04.218105078 CET3526353192.168.2.148.8.8.8
                                              Jan 5, 2025 15:30:04.224875927 CET53352638.8.8.8192.168.2.14
                                              Jan 5, 2025 15:30:04.225491047 CET3419453192.168.2.148.8.8.8
                                              Jan 5, 2025 15:30:04.237958908 CET53341948.8.8.8192.168.2.14
                                              Jan 5, 2025 15:30:04.238766909 CET4009453192.168.2.148.8.8.8
                                              Jan 5, 2025 15:30:04.246407032 CET53400948.8.8.8192.168.2.14
                                              Jan 5, 2025 15:30:26.624408007 CET4363853192.168.2.148.8.8.8
                                              Jan 5, 2025 15:30:26.631556988 CET53436388.8.8.8192.168.2.14
                                              Jan 5, 2025 15:30:26.632720947 CET4863253192.168.2.148.8.8.8
                                              Jan 5, 2025 15:30:26.640192986 CET53486328.8.8.8192.168.2.14
                                              Jan 5, 2025 15:30:26.641284943 CET4019653192.168.2.148.8.8.8
                                              Jan 5, 2025 15:30:26.647960901 CET53401968.8.8.8192.168.2.14
                                              Jan 5, 2025 15:30:26.649044037 CET3588053192.168.2.148.8.8.8
                                              Jan 5, 2025 15:30:26.655894041 CET53358808.8.8.8192.168.2.14
                                              Jan 5, 2025 15:30:26.656970024 CET5925353192.168.2.148.8.8.8
                                              Jan 5, 2025 15:30:26.663928986 CET53592538.8.8.8192.168.2.14
                                              Jan 5, 2025 15:30:49.030467987 CET4033153192.168.2.148.8.8.8
                                              Jan 5, 2025 15:30:49.037477016 CET53403318.8.8.8192.168.2.14
                                              Jan 5, 2025 15:30:49.038166046 CET5198753192.168.2.148.8.8.8
                                              Jan 5, 2025 15:30:49.069880962 CET53519878.8.8.8192.168.2.14
                                              Jan 5, 2025 15:30:49.071258068 CET3720653192.168.2.148.8.8.8
                                              Jan 5, 2025 15:30:49.078341007 CET53372068.8.8.8192.168.2.14
                                              Jan 5, 2025 15:30:49.079387903 CET5287153192.168.2.148.8.8.8
                                              Jan 5, 2025 15:30:49.086371899 CET53528718.8.8.8192.168.2.14
                                              Jan 5, 2025 15:30:49.087465048 CET5541753192.168.2.148.8.8.8
                                              Jan 5, 2025 15:30:49.094443083 CET53554178.8.8.8192.168.2.14
                                              Jan 5, 2025 15:31:11.453496933 CET4799953192.168.2.148.8.8.8
                                              Jan 5, 2025 15:31:11.460422039 CET53479998.8.8.8192.168.2.14
                                              Jan 5, 2025 15:31:11.461091995 CET4381553192.168.2.148.8.8.8
                                              Jan 5, 2025 15:31:11.468776941 CET53438158.8.8.8192.168.2.14
                                              Jan 5, 2025 15:31:11.469799995 CET5310053192.168.2.148.8.8.8
                                              Jan 5, 2025 15:31:11.476748943 CET53531008.8.8.8192.168.2.14
                                              Jan 5, 2025 15:31:11.477744102 CET5690753192.168.2.148.8.8.8
                                              Jan 5, 2025 15:31:11.484730959 CET53569078.8.8.8192.168.2.14
                                              Jan 5, 2025 15:31:11.485807896 CET3319553192.168.2.148.8.8.8
                                              Jan 5, 2025 15:31:11.492882967 CET53331958.8.8.8192.168.2.14
                                              TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                              Jan 5, 2025 15:29:19.349864960 CET192.168.2.148.8.8.80x44aeStandard query (0)ybetncx"hhb"bixA (IP address)IN (0x0001)false
                                              Jan 5, 2025 15:29:19.360477924 CET192.168.2.148.8.8.80x44aeStandard query (0)ybetncx"hhb"bixA (IP address)IN (0x0001)false
                                              Jan 5, 2025 15:29:19.368077040 CET192.168.2.148.8.8.80x44aeStandard query (0)ybetncx"hhb"bixA (IP address)IN (0x0001)false
                                              Jan 5, 2025 15:29:19.375794888 CET192.168.2.148.8.8.80x44aeStandard query (0)ybetncx"hhb"bixA (IP address)IN (0x0001)false
                                              Jan 5, 2025 15:29:19.383382082 CET192.168.2.148.8.8.80x44aeStandard query (0)ybetncx"hhb"bixA (IP address)IN (0x0001)false
                                              Jan 5, 2025 15:29:41.778803110 CET192.168.2.148.8.8.80x87f5Standard query (0)ybetncx"hhb"bixA (IP address)IN (0x0001)false
                                              Jan 5, 2025 15:29:41.787492990 CET192.168.2.148.8.8.80x87f5Standard query (0)ybetncx"hhb"bixA (IP address)IN (0x0001)false
                                              Jan 5, 2025 15:29:41.795381069 CET192.168.2.148.8.8.80x87f5Standard query (0)ybetncx"hhb"bixA (IP address)IN (0x0001)false
                                              Jan 5, 2025 15:29:41.803159952 CET192.168.2.148.8.8.80x87f5Standard query (0)ybetncx"hhb"bixA (IP address)IN (0x0001)false
                                              Jan 5, 2025 15:29:41.811192989 CET192.168.2.148.8.8.80x87f5Standard query (0)ybetncx"hhb"bixA (IP address)IN (0x0001)false
                                              Jan 5, 2025 15:30:04.202987909 CET192.168.2.148.8.8.80x2196Standard query (0)ybetncx"hhb"bixA (IP address)IN (0x0001)false
                                              Jan 5, 2025 15:30:04.210510969 CET192.168.2.148.8.8.80x2196Standard query (0)ybetncx"hhb"bixA (IP address)IN (0x0001)false
                                              Jan 5, 2025 15:30:04.218105078 CET192.168.2.148.8.8.80x2196Standard query (0)ybetncx"hhb"bixA (IP address)IN (0x0001)false
                                              Jan 5, 2025 15:30:04.225491047 CET192.168.2.148.8.8.80x2196Standard query (0)ybetncx"hhb"bixA (IP address)IN (0x0001)false
                                              Jan 5, 2025 15:30:04.238766909 CET192.168.2.148.8.8.80x2196Standard query (0)ybetncx"hhb"bixA (IP address)IN (0x0001)false
                                              Jan 5, 2025 15:30:26.624408007 CET192.168.2.148.8.8.80x80a8Standard query (0)ybetncx"hhb"bixA (IP address)IN (0x0001)false
                                              Jan 5, 2025 15:30:26.632720947 CET192.168.2.148.8.8.80x80a8Standard query (0)ybetncx"hhb"bixA (IP address)IN (0x0001)false
                                              Jan 5, 2025 15:30:26.641284943 CET192.168.2.148.8.8.80x80a8Standard query (0)ybetncx"hhb"bixA (IP address)IN (0x0001)false
                                              Jan 5, 2025 15:30:26.649044037 CET192.168.2.148.8.8.80x80a8Standard query (0)ybetncx"hhb"bixA (IP address)IN (0x0001)false
                                              Jan 5, 2025 15:30:26.656970024 CET192.168.2.148.8.8.80x80a8Standard query (0)ybetncx"hhb"bixA (IP address)IN (0x0001)false
                                              Jan 5, 2025 15:30:49.030467987 CET192.168.2.148.8.8.80x46d5Standard query (0)ybetncx"hhb"bixA (IP address)IN (0x0001)false
                                              Jan 5, 2025 15:30:49.038166046 CET192.168.2.148.8.8.80x46d5Standard query (0)ybetncx"hhb"bixA (IP address)IN (0x0001)false
                                              Jan 5, 2025 15:30:49.071258068 CET192.168.2.148.8.8.80x46d5Standard query (0)ybetncx"hhb"bixA (IP address)IN (0x0001)false
                                              Jan 5, 2025 15:30:49.079387903 CET192.168.2.148.8.8.80x46d5Standard query (0)ybetncx"hhb"bixA (IP address)IN (0x0001)false
                                              Jan 5, 2025 15:30:49.087465048 CET192.168.2.148.8.8.80x46d5Standard query (0)ybetncx"hhb"bixA (IP address)IN (0x0001)false
                                              Jan 5, 2025 15:31:11.453496933 CET192.168.2.148.8.8.80x4d83Standard query (0)ybetncx"hhb"bixA (IP address)IN (0x0001)false
                                              Jan 5, 2025 15:31:11.461091995 CET192.168.2.148.8.8.80x4d83Standard query (0)ybetncx"hhb"bixA (IP address)IN (0x0001)false
                                              Jan 5, 2025 15:31:11.469799995 CET192.168.2.148.8.8.80x4d83Standard query (0)ybetncx"hhb"bixA (IP address)IN (0x0001)false
                                              Jan 5, 2025 15:31:11.477744102 CET192.168.2.148.8.8.80x4d83Standard query (0)ybetncx"hhb"bixA (IP address)IN (0x0001)false
                                              Jan 5, 2025 15:31:11.485807896 CET192.168.2.148.8.8.80x4d83Standard query (0)ybetncx"hhb"bixA (IP address)IN (0x0001)false
                                              TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                              Jan 5, 2025 15:29:19.359736919 CET8.8.8.8192.168.2.140x44aeName error (3)ybetncx"hhb"bixnonenoneA (IP address)IN (0x0001)false
                                              Jan 5, 2025 15:29:19.367445946 CET8.8.8.8192.168.2.140x44aeName error (3)ybetncx"hhb"bixnonenoneA (IP address)IN (0x0001)false
                                              Jan 5, 2025 15:29:19.375193119 CET8.8.8.8192.168.2.140x44aeName error (3)ybetncx"hhb"bixnonenoneA (IP address)IN (0x0001)false
                                              Jan 5, 2025 15:29:19.382747889 CET8.8.8.8192.168.2.140x44aeName error (3)ybetncx"hhb"bixnonenoneA (IP address)IN (0x0001)false
                                              Jan 5, 2025 15:29:19.390449047 CET8.8.8.8192.168.2.140x44aeName error (3)ybetncx"hhb"bixnonenoneA (IP address)IN (0x0001)false
                                              Jan 5, 2025 15:29:41.786590099 CET8.8.8.8192.168.2.140x87f5Name error (3)ybetncx"hhb"bixnonenoneA (IP address)IN (0x0001)false
                                              Jan 5, 2025 15:29:41.794408083 CET8.8.8.8192.168.2.140x87f5Name error (3)ybetncx"hhb"bixnonenoneA (IP address)IN (0x0001)false
                                              Jan 5, 2025 15:29:41.802412987 CET8.8.8.8192.168.2.140x87f5Name error (3)ybetncx"hhb"bixnonenoneA (IP address)IN (0x0001)false
                                              Jan 5, 2025 15:29:41.810369968 CET8.8.8.8192.168.2.140x87f5Name error (3)ybetncx"hhb"bixnonenoneA (IP address)IN (0x0001)false
                                              Jan 5, 2025 15:29:41.818280935 CET8.8.8.8192.168.2.140x87f5Name error (3)ybetncx"hhb"bixnonenoneA (IP address)IN (0x0001)false
                                              Jan 5, 2025 15:30:04.209868908 CET8.8.8.8192.168.2.140x2196Name error (3)ybetncx"hhb"bixnonenoneA (IP address)IN (0x0001)false
                                              Jan 5, 2025 15:30:04.217403889 CET8.8.8.8192.168.2.140x2196Name error (3)ybetncx"hhb"bixnonenoneA (IP address)IN (0x0001)false
                                              Jan 5, 2025 15:30:04.224875927 CET8.8.8.8192.168.2.140x2196Name error (3)ybetncx"hhb"bixnonenoneA (IP address)IN (0x0001)false
                                              Jan 5, 2025 15:30:04.237958908 CET8.8.8.8192.168.2.140x2196Name error (3)ybetncx"hhb"bixnonenoneA (IP address)IN (0x0001)false
                                              Jan 5, 2025 15:30:04.246407032 CET8.8.8.8192.168.2.140x2196Name error (3)ybetncx"hhb"bixnonenoneA (IP address)IN (0x0001)false
                                              Jan 5, 2025 15:30:26.631556988 CET8.8.8.8192.168.2.140x80a8Name error (3)ybetncx"hhb"bixnonenoneA (IP address)IN (0x0001)false
                                              Jan 5, 2025 15:30:26.640192986 CET8.8.8.8192.168.2.140x80a8Name error (3)ybetncx"hhb"bixnonenoneA (IP address)IN (0x0001)false
                                              Jan 5, 2025 15:30:26.647960901 CET8.8.8.8192.168.2.140x80a8Name error (3)ybetncx"hhb"bixnonenoneA (IP address)IN (0x0001)false
                                              Jan 5, 2025 15:30:26.655894041 CET8.8.8.8192.168.2.140x80a8Name error (3)ybetncx"hhb"bixnonenoneA (IP address)IN (0x0001)false
                                              Jan 5, 2025 15:30:26.663928986 CET8.8.8.8192.168.2.140x80a8Name error (3)ybetncx"hhb"bixnonenoneA (IP address)IN (0x0001)false
                                              Jan 5, 2025 15:30:49.037477016 CET8.8.8.8192.168.2.140x46d5Name error (3)ybetncx"hhb"bixnonenoneA (IP address)IN (0x0001)false
                                              Jan 5, 2025 15:30:49.069880962 CET8.8.8.8192.168.2.140x46d5Name error (3)ybetncx"hhb"bixnonenoneA (IP address)IN (0x0001)false
                                              Jan 5, 2025 15:30:49.078341007 CET8.8.8.8192.168.2.140x46d5Name error (3)ybetncx"hhb"bixnonenoneA (IP address)IN (0x0001)false
                                              Jan 5, 2025 15:30:49.086371899 CET8.8.8.8192.168.2.140x46d5Name error (3)ybetncx"hhb"bixnonenoneA (IP address)IN (0x0001)false
                                              Jan 5, 2025 15:30:49.094443083 CET8.8.8.8192.168.2.140x46d5Name error (3)ybetncx"hhb"bixnonenoneA (IP address)IN (0x0001)false
                                              Jan 5, 2025 15:31:11.460422039 CET8.8.8.8192.168.2.140x4d83Name error (3)ybetncx"hhb"bixnonenoneA (IP address)IN (0x0001)false
                                              Jan 5, 2025 15:31:11.468776941 CET8.8.8.8192.168.2.140x4d83Name error (3)ybetncx"hhb"bixnonenoneA (IP address)IN (0x0001)false
                                              Jan 5, 2025 15:31:11.476748943 CET8.8.8.8192.168.2.140x4d83Name error (3)ybetncx"hhb"bixnonenoneA (IP address)IN (0x0001)false
                                              Jan 5, 2025 15:31:11.484730959 CET8.8.8.8192.168.2.140x4d83Name error (3)ybetncx"hhb"bixnonenoneA (IP address)IN (0x0001)false
                                              Jan 5, 2025 15:31:11.492882967 CET8.8.8.8192.168.2.140x4d83Name error (3)ybetncx"hhb"bixnonenoneA (IP address)IN (0x0001)false
                                              Session IDSource IPSource PortDestination IPDestination Port
                                              0192.168.2.1458228123.253.61.11680
                                              TimestampBytes transferredDirectionData
                                              Jan 5, 2025 15:29:19.396313906 CET16OUTData Raw: 00 00 00 01
                                              Data Ascii:
                                              Jan 5, 2025 15:29:19.401145935 CET13OUTData Raw: 00
                                              Data Ascii:
                                              Jan 5, 2025 15:29:29.406260967 CET14OUTData Raw: 00 00
                                              Data Ascii:


                                              Session IDSource IPSource PortDestination IPDestination Port
                                              1192.168.2.1458230123.253.61.11680
                                              TimestampBytes transferredDirectionData
                                              Jan 5, 2025 15:29:41.824259996 CET16OUTData Raw: 00 00 00 01
                                              Data Ascii:
                                              Jan 5, 2025 15:29:41.829189062 CET13OUTData Raw: 00
                                              Data Ascii:


                                              Session IDSource IPSource PortDestination IPDestination Port
                                              2192.168.2.1458232123.253.61.11680
                                              TimestampBytes transferredDirectionData
                                              Jan 5, 2025 15:30:04.252907038 CET16OUTData Raw: 00 00 00 01
                                              Data Ascii:
                                              Jan 5, 2025 15:30:04.258351088 CET13OUTData Raw: 00
                                              Data Ascii:


                                              Session IDSource IPSource PortDestination IPDestination Port
                                              3192.168.2.1458234123.253.61.11680
                                              TimestampBytes transferredDirectionData
                                              Jan 5, 2025 15:30:26.670403004 CET16OUTData Raw: 00 00 00 01
                                              Data Ascii:
                                              Jan 5, 2025 15:30:26.675251007 CET13OUTData Raw: 00
                                              Data Ascii:
                                              Jan 5, 2025 15:30:36.680057049 CET14OUTData Raw: 00 00
                                              Data Ascii:


                                              Session IDSource IPSource PortDestination IPDestination Port
                                              4192.168.2.1458236123.253.61.11680
                                              TimestampBytes transferredDirectionData
                                              Jan 5, 2025 15:30:49.100963116 CET16OUTData Raw: 00 00 00 01
                                              Data Ascii:
                                              Jan 5, 2025 15:30:49.105751991 CET13OUTData Raw: 00
                                              Data Ascii:


                                              Session IDSource IPSource PortDestination IPDestination Port
                                              5192.168.2.1458238123.253.61.11680
                                              TimestampBytes transferredDirectionData
                                              Jan 5, 2025 15:31:11.499464989 CET16OUTData Raw: 00 00 00 01
                                              Data Ascii:
                                              Jan 5, 2025 15:31:11.504235983 CET13OUTData Raw: 00
                                              Data Ascii:


                                              System Behavior

                                              Start time (UTC):14:29:18
                                              Start date (UTC):05/01/2025
                                              Path:/tmp/fuckunix.x86_64.elf
                                              Arguments:/tmp/fuckunix.x86_64.elf
                                              File size:42720 bytes
                                              MD5 hash:ec0334b40fe1c306ab2e7a37788c44b8

                                              Start time (UTC):14:29:18
                                              Start date (UTC):05/01/2025
                                              Path:/tmp/fuckunix.x86_64.elf
                                              Arguments:-
                                              File size:42720 bytes
                                              MD5 hash:ec0334b40fe1c306ab2e7a37788c44b8