Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
res.x86.elf

Overview

General Information

Sample name:res.x86.elf
Analysis ID:1584965
MD5:c91683d171810c80cb77bd613e1b0851
SHA1:f6c6fd5ee602004f85ffb253f2330064a0750399
SHA256:139031e41e5b504fcf8967873b9404e51055bb999653bc41708fd277b16c1973
Tags:elfuser-abuse_ch
Infos:

Detection

Score:60
Range:0 - 100
Whitelisted:false

Signatures

Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Machine Learning detection for sample
Detected TCP or UDP traffic on non-standard ports
Sample has stripped symbol table
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Yara signature match

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1584965
Start date and time:2025-01-06 21:02:04 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 22s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:res.x86.elf
Detection:MAL
Classification:mal60.linELF@0/0@0/0
  • VT rate limit hit for: res.x86.elf
Command:/tmp/res.x86.elf
PID:6234
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
Who loves the sun
Standard Error:
  • system is lnxubuntu20
  • res.x86.elf (PID: 6234, Parent: 6152, MD5: c91683d171810c80cb77bd613e1b0851) Arguments: /tmp/res.x86.elf
  • cleanup
SourceRuleDescriptionAuthorStrings
res.x86.elfLinux_Trojan_Mirai_b14f4c5dunknownunknown
  • 0x51e0:$a: 53 31 DB 8B 4C 24 0C 8B 54 24 08 83 F9 01 76 15 66 8B 02 83 E9 02 25 FF FF 00 00 83 C2 02 01 C3 83 F9 01 77 EB 49 75 05 0F BE 02 01 C3
res.x86.elfLinux_Trojan_Mirai_88de437funknownunknown
  • 0x6942:$a: 24 08 8B 4C 24 04 85 D2 74 0D 31 C0 89 F6 C6 04 08 00 40 39 D0
res.x86.elfLinux_Trojan_Mirai_ae9d0fa6unknownunknown
  • 0x192:$a: 83 EC 04 8A 44 24 18 8B 5C 24 14 88 44 24 03 8A 44 24 10 25 FF 00
res.x86.elfLinux_Trojan_Mirai_389ee3e9unknownunknown
  • 0x83b9:$a: 89 45 00 EB 2C 8B 4B 04 8B 13 8B 7B 18 8B 01 01 02 8B 02 83
res.x86.elfLinux_Trojan_Mirai_cc93863bunknownunknown
  • 0x6ee8:$a: C3 57 8B 44 24 0C 8B 4C 24 10 8B 7C 24 08 F3 AA 8B 44 24 08
Click to see the 1 entries
SourceRuleDescriptionAuthorStrings
6234.1.0000000008048000.0000000008052000.r-x.sdmpLinux_Trojan_Mirai_b14f4c5dunknownunknown
  • 0x51e0:$a: 53 31 DB 8B 4C 24 0C 8B 54 24 08 83 F9 01 76 15 66 8B 02 83 E9 02 25 FF FF 00 00 83 C2 02 01 C3 83 F9 01 77 EB 49 75 05 0F BE 02 01 C3
6234.1.0000000008048000.0000000008052000.r-x.sdmpLinux_Trojan_Mirai_88de437funknownunknown
  • 0x6942:$a: 24 08 8B 4C 24 04 85 D2 74 0D 31 C0 89 F6 C6 04 08 00 40 39 D0
6234.1.0000000008048000.0000000008052000.r-x.sdmpLinux_Trojan_Mirai_ae9d0fa6unknownunknown
  • 0x192:$a: 83 EC 04 8A 44 24 18 8B 5C 24 14 88 44 24 03 8A 44 24 10 25 FF 00
6234.1.0000000008048000.0000000008052000.r-x.sdmpLinux_Trojan_Mirai_389ee3e9unknownunknown
  • 0x83b9:$a: 89 45 00 EB 2C 8B 4B 04 8B 13 8B 7B 18 8B 01 01 02 8B 02 83
6234.1.0000000008048000.0000000008052000.r-x.sdmpLinux_Trojan_Mirai_cc93863bunknownunknown
  • 0x6ee8:$a: C3 57 8B 44 24 0C 8B 4C 24 10 8B 7C 24 08 F3 AA 8B 44 24 08
Click to see the 7 entries
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: res.x86.elfReversingLabs: Detection: 60%
Source: res.x86.elfJoe Sandbox ML: detected
Source: global trafficTCP traffic: 192.168.2.23:53110 -> 79.124.60.186:37212
Source: global trafficTCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
Source: global trafficTCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
Source: global trafficTCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
Source: unknownTCP traffic detected without corresponding DNS query: 79.124.60.186
Source: unknownTCP traffic detected without corresponding DNS query: 79.124.60.186
Source: unknownTCP traffic detected without corresponding DNS query: 79.124.60.186
Source: unknownTCP traffic detected without corresponding DNS query: 79.124.60.186
Source: unknownTCP traffic detected without corresponding DNS query: 79.124.60.186
Source: unknownTCP traffic detected without corresponding DNS query: 79.124.60.186
Source: unknownTCP traffic detected without corresponding DNS query: 79.124.60.186
Source: unknownTCP traffic detected without corresponding DNS query: 79.124.60.186
Source: unknownTCP traffic detected without corresponding DNS query: 79.124.60.186
Source: unknownTCP traffic detected without corresponding DNS query: 79.124.60.186
Source: unknownTCP traffic detected without corresponding DNS query: 79.124.60.186
Source: unknownTCP traffic detected without corresponding DNS query: 79.124.60.186
Source: unknownTCP traffic detected without corresponding DNS query: 79.124.60.186
Source: unknownTCP traffic detected without corresponding DNS query: 79.124.60.186
Source: unknownTCP traffic detected without corresponding DNS query: 79.124.60.186
Source: unknownTCP traffic detected without corresponding DNS query: 79.124.60.186
Source: unknownTCP traffic detected without corresponding DNS query: 79.124.60.186
Source: unknownTCP traffic detected without corresponding DNS query: 79.124.60.186
Source: unknownTCP traffic detected without corresponding DNS query: 79.124.60.186
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 79.124.60.186
Source: unknownTCP traffic detected without corresponding DNS query: 79.124.60.186
Source: unknownTCP traffic detected without corresponding DNS query: 79.124.60.186
Source: unknownTCP traffic detected without corresponding DNS query: 79.124.60.186
Source: unknownTCP traffic detected without corresponding DNS query: 79.124.60.186
Source: unknownTCP traffic detected without corresponding DNS query: 79.124.60.186
Source: unknownTCP traffic detected without corresponding DNS query: 79.124.60.186
Source: unknownTCP traffic detected without corresponding DNS query: 79.124.60.186
Source: unknownTCP traffic detected without corresponding DNS query: 79.124.60.186
Source: unknownTCP traffic detected without corresponding DNS query: 79.124.60.186
Source: unknownTCP traffic detected without corresponding DNS query: 79.124.60.186
Source: unknownTCP traffic detected without corresponding DNS query: 79.124.60.186
Source: unknownTCP traffic detected without corresponding DNS query: 79.124.60.186
Source: unknownTCP traffic detected without corresponding DNS query: 79.124.60.186
Source: unknownTCP traffic detected without corresponding DNS query: 79.124.60.186
Source: unknownTCP traffic detected without corresponding DNS query: 79.124.60.186
Source: unknownTCP traffic detected without corresponding DNS query: 79.124.60.186
Source: unknownTCP traffic detected without corresponding DNS query: 79.124.60.186
Source: unknownTCP traffic detected without corresponding DNS query: 79.124.60.186
Source: unknownTCP traffic detected without corresponding DNS query: 79.124.60.186
Source: unknownTCP traffic detected without corresponding DNS query: 79.124.60.186
Source: unknownTCP traffic detected without corresponding DNS query: 79.124.60.186
Source: unknownTCP traffic detected without corresponding DNS query: 79.124.60.186
Source: unknownTCP traffic detected without corresponding DNS query: 79.124.60.186
Source: unknownTCP traffic detected without corresponding DNS query: 79.124.60.186
Source: unknownTCP traffic detected without corresponding DNS query: 79.124.60.186
Source: unknownTCP traffic detected without corresponding DNS query: 79.124.60.186
Source: unknownTCP traffic detected without corresponding DNS query: 79.124.60.186
Source: unknownTCP traffic detected without corresponding DNS query: 79.124.60.186
Source: unknownTCP traffic detected without corresponding DNS query: 79.124.60.186
Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443

System Summary

barindex
Source: res.x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_b14f4c5d Author: unknown
Source: res.x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_88de437f Author: unknown
Source: res.x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_ae9d0fa6 Author: unknown
Source: res.x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_389ee3e9 Author: unknown
Source: res.x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_cc93863b Author: unknown
Source: res.x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_8aa7b5d3 Author: unknown
Source: 6234.1.0000000008048000.0000000008052000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_b14f4c5d Author: unknown
Source: 6234.1.0000000008048000.0000000008052000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_88de437f Author: unknown
Source: 6234.1.0000000008048000.0000000008052000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_ae9d0fa6 Author: unknown
Source: 6234.1.0000000008048000.0000000008052000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_389ee3e9 Author: unknown
Source: 6234.1.0000000008048000.0000000008052000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_cc93863b Author: unknown
Source: 6234.1.0000000008048000.0000000008052000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_8aa7b5d3 Author: unknown
Source: 6236.1.0000000008048000.0000000008052000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_b14f4c5d Author: unknown
Source: 6236.1.0000000008048000.0000000008052000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_88de437f Author: unknown
Source: 6236.1.0000000008048000.0000000008052000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_ae9d0fa6 Author: unknown
Source: 6236.1.0000000008048000.0000000008052000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_389ee3e9 Author: unknown
Source: 6236.1.0000000008048000.0000000008052000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_cc93863b Author: unknown
Source: 6236.1.0000000008048000.0000000008052000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_8aa7b5d3 Author: unknown
Source: ELF static info symbol of initial sample.symtab present: no
Source: res.x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_b14f4c5d os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = a70d052918dd2fbc66db241da6438015130f0fb6929229bfe573546fe98da817, id = b14f4c5d-054f-46e6-9fa8-3588f1ef68b7, last_modified = 2021-09-16
Source: res.x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_88de437f reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = c19eb595c2b444a809bef8500c20342c9f46694d3018e268833f9b884133a1ea, id = 88de437f-9c98-4e1d-96c0-7b433c99886a, last_modified = 2021-09-16
Source: res.x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_ae9d0fa6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = ca2bf2771844bec95563800d19a35dd230413f8eff0bd44c8ab0b4c596f81bfc, id = ae9d0fa6-be06-4656-9b13-8edfc0ee9e71, last_modified = 2021-09-16
Source: res.x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_389ee3e9 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 59f2359dc1f41d385d639d157b4cd9fc73d76d8abb7cc09d47632bb4c9a39e6e, id = 389ee3e9-70c1-4c93-a999-292cf6ff1652, last_modified = 2022-01-26
Source: res.x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_cc93863b reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = f3ecd30f0b511a8e92cfa642409d559e7612c3f57a1659ca46c77aca809a00ac, id = cc93863b-1050-40ba-9d02-5ec9ce6a3a28, last_modified = 2022-01-26
Source: res.x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_8aa7b5d3 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 02a2c18c362df4b1fceb33f3b605586514ba9a00c7afedf71c04fa54d8146444, id = 8aa7b5d3-e1eb-4b55-b36a-0d3a242c06e9, last_modified = 2022-01-26
Source: 6234.1.0000000008048000.0000000008052000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_b14f4c5d os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = a70d052918dd2fbc66db241da6438015130f0fb6929229bfe573546fe98da817, id = b14f4c5d-054f-46e6-9fa8-3588f1ef68b7, last_modified = 2021-09-16
Source: 6234.1.0000000008048000.0000000008052000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_88de437f reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = c19eb595c2b444a809bef8500c20342c9f46694d3018e268833f9b884133a1ea, id = 88de437f-9c98-4e1d-96c0-7b433c99886a, last_modified = 2021-09-16
Source: 6234.1.0000000008048000.0000000008052000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_ae9d0fa6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = ca2bf2771844bec95563800d19a35dd230413f8eff0bd44c8ab0b4c596f81bfc, id = ae9d0fa6-be06-4656-9b13-8edfc0ee9e71, last_modified = 2021-09-16
Source: 6234.1.0000000008048000.0000000008052000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_389ee3e9 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 59f2359dc1f41d385d639d157b4cd9fc73d76d8abb7cc09d47632bb4c9a39e6e, id = 389ee3e9-70c1-4c93-a999-292cf6ff1652, last_modified = 2022-01-26
Source: 6234.1.0000000008048000.0000000008052000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_cc93863b reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = f3ecd30f0b511a8e92cfa642409d559e7612c3f57a1659ca46c77aca809a00ac, id = cc93863b-1050-40ba-9d02-5ec9ce6a3a28, last_modified = 2022-01-26
Source: 6234.1.0000000008048000.0000000008052000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_8aa7b5d3 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 02a2c18c362df4b1fceb33f3b605586514ba9a00c7afedf71c04fa54d8146444, id = 8aa7b5d3-e1eb-4b55-b36a-0d3a242c06e9, last_modified = 2022-01-26
Source: 6236.1.0000000008048000.0000000008052000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_b14f4c5d os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = a70d052918dd2fbc66db241da6438015130f0fb6929229bfe573546fe98da817, id = b14f4c5d-054f-46e6-9fa8-3588f1ef68b7, last_modified = 2021-09-16
Source: 6236.1.0000000008048000.0000000008052000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_88de437f reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = c19eb595c2b444a809bef8500c20342c9f46694d3018e268833f9b884133a1ea, id = 88de437f-9c98-4e1d-96c0-7b433c99886a, last_modified = 2021-09-16
Source: 6236.1.0000000008048000.0000000008052000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_ae9d0fa6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = ca2bf2771844bec95563800d19a35dd230413f8eff0bd44c8ab0b4c596f81bfc, id = ae9d0fa6-be06-4656-9b13-8edfc0ee9e71, last_modified = 2021-09-16
Source: 6236.1.0000000008048000.0000000008052000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_389ee3e9 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 59f2359dc1f41d385d639d157b4cd9fc73d76d8abb7cc09d47632bb4c9a39e6e, id = 389ee3e9-70c1-4c93-a999-292cf6ff1652, last_modified = 2022-01-26
Source: 6236.1.0000000008048000.0000000008052000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_cc93863b reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = f3ecd30f0b511a8e92cfa642409d559e7612c3f57a1659ca46c77aca809a00ac, id = cc93863b-1050-40ba-9d02-5ec9ce6a3a28, last_modified = 2022-01-26
Source: 6236.1.0000000008048000.0000000008052000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_8aa7b5d3 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 02a2c18c362df4b1fceb33f3b605586514ba9a00c7afedf71c04fa54d8146444, id = 8aa7b5d3-e1eb-4b55-b36a-0d3a242c06e9, last_modified = 2022-01-26
Source: classification engineClassification label: mal60.linELF@0/0@0/0
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath InterceptionDirect Volume AccessOS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Non-Standard Port
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
SourceDetectionScannerLabelLink
res.x86.elf61%ReversingLabsLinux.Trojan.Mirai
res.x86.elf100%Joe Sandbox ML
No Antivirus matches
No Antivirus matches
No Antivirus matches
No contacted domains info
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs
IPDomainCountryFlagASNASN NameMalicious
79.124.60.186
unknownBulgaria
50360TAMATIYA-ASBGfalse
109.202.202.202
unknownSwitzerland
13030INIT7CHfalse
91.189.91.43
unknownUnited Kingdom
41231CANONICAL-ASGBfalse
91.189.91.42
unknownUnited Kingdom
41231CANONICAL-ASGBfalse
MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
79.124.60.186res.x86.elfGet hashmaliciousUnknownBrowse
    109.202.202.202kpLwzBouH4.elfGet hashmaliciousUnknownBrowse
    • ch.archive.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_92.0%2bbuild3-0ubuntu0.20.04.1_amd64.deb
    91.189.91.43main_arm5.elfGet hashmaliciousMiraiBrowse
      main_mips.elfGet hashmaliciousMiraiBrowse
        main_ppc.elfGet hashmaliciousMiraiBrowse
          debug.dbg.elfGet hashmaliciousMiraiBrowse
            spc.elfGet hashmaliciousMiraiBrowse
              covid.arm.elfGet hashmaliciousUnknownBrowse
                covid.arm5.elfGet hashmaliciousUnknownBrowse
                  covid.x86.elfGet hashmaliciousMiraiBrowse
                    hidakibest.sparc.elfGet hashmaliciousGafgyt, MiraiBrowse
                      hidakibest.x86.elfGet hashmaliciousMirai, GafgytBrowse
                        91.189.91.42main_arm5.elfGet hashmaliciousMiraiBrowse
                          main_mips.elfGet hashmaliciousMiraiBrowse
                            main_ppc.elfGet hashmaliciousMiraiBrowse
                              debug.dbg.elfGet hashmaliciousMiraiBrowse
                                ppc.elfGet hashmaliciousUnknownBrowse
                                  spc.elfGet hashmaliciousMiraiBrowse
                                    covid.arm.elfGet hashmaliciousUnknownBrowse
                                      covid.arm5.elfGet hashmaliciousUnknownBrowse
                                        covid.x86.elfGet hashmaliciousMiraiBrowse
                                          hidakibest.sparc.elfGet hashmaliciousGafgyt, MiraiBrowse
                                            No context
                                            MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                            CANONICAL-ASGBmain_arm5.elfGet hashmaliciousMiraiBrowse
                                            • 91.189.91.42
                                            main_mips.elfGet hashmaliciousMiraiBrowse
                                            • 91.189.91.42
                                            main_mpsl.elfGet hashmaliciousMiraiBrowse
                                            • 185.125.190.26
                                            main_ppc.elfGet hashmaliciousMiraiBrowse
                                            • 91.189.91.42
                                            debug.dbg.elfGet hashmaliciousMiraiBrowse
                                            • 91.189.91.42
                                            ppc.elfGet hashmaliciousUnknownBrowse
                                            • 91.189.91.42
                                            spc.elfGet hashmaliciousMiraiBrowse
                                            • 91.189.91.42
                                            covid.arm.elfGet hashmaliciousUnknownBrowse
                                            • 91.189.91.42
                                            covid.arm5.elfGet hashmaliciousUnknownBrowse
                                            • 91.189.91.42
                                            covid.x86.elfGet hashmaliciousMiraiBrowse
                                            • 91.189.91.42
                                            CANONICAL-ASGBmain_arm5.elfGet hashmaliciousMiraiBrowse
                                            • 91.189.91.42
                                            main_mips.elfGet hashmaliciousMiraiBrowse
                                            • 91.189.91.42
                                            main_mpsl.elfGet hashmaliciousMiraiBrowse
                                            • 185.125.190.26
                                            main_ppc.elfGet hashmaliciousMiraiBrowse
                                            • 91.189.91.42
                                            debug.dbg.elfGet hashmaliciousMiraiBrowse
                                            • 91.189.91.42
                                            ppc.elfGet hashmaliciousUnknownBrowse
                                            • 91.189.91.42
                                            spc.elfGet hashmaliciousMiraiBrowse
                                            • 91.189.91.42
                                            covid.arm.elfGet hashmaliciousUnknownBrowse
                                            • 91.189.91.42
                                            covid.arm5.elfGet hashmaliciousUnknownBrowse
                                            • 91.189.91.42
                                            covid.x86.elfGet hashmaliciousMiraiBrowse
                                            • 91.189.91.42
                                            TAMATIYA-ASBGres.x86.elfGet hashmaliciousUnknownBrowse
                                            • 79.124.60.186
                                            http://xn--gmq700hb9ir4byxw.shop/bnBkL2ViZml0c2JwY0F7Zm1mdy9idWp0cHMkbHYvcGQvem1xanVtYnNmZC9xbmJ3MDA7dHF1dWkGet hashmaliciousReCaptcha PhishBrowse
                                            • 79.124.60.165
                                            https://login.officeteam.didgim.com/factpath/resources/patch/047620476204762098/?tpj=PlKRhyZP6wwT3cO_YX5-vBD5GuXYTvvU?SehS24G3uU3qw64njI8IZH7gQJoi5rbp7C2uDZbPGel89LOXSbLkxzcBkcMiAnricyOgDlVZzgK16brTMbOGyuYoLIN4U0HH714JGet hashmaliciousReCaptcha PhishBrowse
                                            • 79.124.60.165
                                            https://farmboyclothing.com/?7rgaki=P29icXQwPVBsaXd4dzVCcloyZWA1QmRWWUk0Oi5bbD8jdXlmdS5vZmVlamkjPnR0Ym1kIW9icXQ9P21udWkwPQs/emVwYzA9Cz96ZXBjPQs/ZWJmaTA9Cz9mbXp1dDA9ISEhIQt+ISEhISEhISELMCshTlBFIWZpdSFvaiF0dXRqeWYhbW1qdXQhdXZjIXRzZnR2IXB1IWZtY2p0anchdXBvIXQodWohdGZzdnRvRiErMCE8b2ZlZWppITt6dWptamNqdGp3ISEhISEhISEhISEhCzArIWVvdnBzaGxkYmMhZnVqaXghYiFwdW9qIWVvZm1jIXV5ZnUhdGZsYk4hKzAhPGZ1aml4ITtzcG1wZCEhISEhISEhISEhIQt8IXV5ZnUub2ZlZWppLyEhISEhISEhCz9mbXp1dD0hISEhCz9mbXVqdTA9Zm5wST9mbXVqdT0hISEhCz8jbnBkL3RmamhwbXBvaWRmdXR2c3ZkZnRBYm96ZnNjMGx2L3BkL3ptcWp1bWJzZmQvbWpibjAwO3RxdXVpPm1zdjwzIz51b2Z1b3BkISNpdGZzZ2ZzIz53anZyZi5xdXVpIWJ1Zm49ISEhIQs/IzkuR1VWIz51ZnRzYmlkIWJ1Zm49ISEhIQs/ZWJmaT0LP21udWk9P29icXQwPXFRVUt2NTg0ZDRiPm5Eaz05T29jOFlCWi5mVlJVRUpNUjlHMk1XXmtiZHZVPyN1eWZ1Lm9mZWVqaSM+dHRibWQhb2JxdD0Get hashmaliciousReCaptcha PhishBrowse
                                            • 79.124.60.165
                                            iFD9jPLjXC.exeGet hashmaliciousSystemBCBrowse
                                            • 79.124.58.130
                                            iFD9jPLjXC.exeGet hashmaliciousSystemBCBrowse
                                            • 79.124.58.130
                                            report.pdf.lnkGet hashmaliciousUnknownBrowse
                                            • 79.124.58.130
                                            2HSalvXIJE.exeGet hashmaliciousCobaltStrike, MetasploitBrowse
                                            • 79.124.58.130
                                            https://bastionesan.gay/teleforser51/Get hashmaliciousUnknownBrowse
                                            • 79.124.49.200
                                            http://condenast-hub-okta-emea-7d5ea512.aibels.com/Get hashmaliciousUnknownBrowse
                                            • 78.128.114.103
                                            INIT7CHmain_arm5.elfGet hashmaliciousMiraiBrowse
                                            • 109.202.202.202
                                            main_mips.elfGet hashmaliciousMiraiBrowse
                                            • 109.202.202.202
                                            main_ppc.elfGet hashmaliciousMiraiBrowse
                                            • 109.202.202.202
                                            debug.dbg.elfGet hashmaliciousMiraiBrowse
                                            • 109.202.202.202
                                            ppc.elfGet hashmaliciousUnknownBrowse
                                            • 109.202.202.202
                                            spc.elfGet hashmaliciousMiraiBrowse
                                            • 109.202.202.202
                                            covid.arm.elfGet hashmaliciousUnknownBrowse
                                            • 109.202.202.202
                                            covid.arm5.elfGet hashmaliciousUnknownBrowse
                                            • 109.202.202.202
                                            covid.x86.elfGet hashmaliciousMiraiBrowse
                                            • 109.202.202.202
                                            hidakibest.sparc.elfGet hashmaliciousGafgyt, MiraiBrowse
                                            • 109.202.202.202
                                            No context
                                            No context
                                            No created / dropped files found
                                            File type:ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, stripped
                                            Entropy (8bit):6.225109015631311
                                            TrID:
                                            • ELF Executable and Linkable format (Linux) (4029/14) 50.16%
                                            • ELF Executable and Linkable format (generic) (4004/1) 49.84%
                                            File name:res.x86.elf
                                            File size:41'744 bytes
                                            MD5:c91683d171810c80cb77bd613e1b0851
                                            SHA1:f6c6fd5ee602004f85ffb253f2330064a0750399
                                            SHA256:139031e41e5b504fcf8967873b9404e51055bb999653bc41708fd277b16c1973
                                            SHA512:7311797123541486e19f4780341b013d47b2706c80ed958ab1e3acf7e93c6992834d64661685c6b790930d7a10945a206520365baa5c40e9fd1f040ae1c1a2fe
                                            SSDEEP:768:hmk8bOLk5zrPOvqR9YxxkgNHoslaNUWwMr3J930FUfrXKAkj6X63O:hl8bOQ5zrPGqR9YHkgNHoOaNUWNrEFgB
                                            TLSH:2E133BC46853DEF8EC150B753132E7369F72F13AE11EE947C3E8DA23A842A01E55A15D
                                            File Content Preview:.ELF....................d...4...........4. ...(.............................................. ... ..@...............Q.td............................U..S.......w....h........[]...$.............U......=@!...t..5....$ .....$ ......u........t....h............

                                            ELF header

                                            Class:ELF32
                                            Data:2's complement, little endian
                                            Version:1 (current)
                                            Machine:Intel 80386
                                            Version Number:0x1
                                            Type:EXEC (Executable file)
                                            OS/ABI:UNIX - System V
                                            ABI Version:0
                                            Entry Point Address:0x8048164
                                            Flags:0x0
                                            ELF Header Size:52
                                            Program Header Offset:52
                                            Program Header Size:32
                                            Number of Program Headers:3
                                            Section Header Offset:41344
                                            Section Header Size:40
                                            Number of Section Headers:10
                                            Header String Table Index:9
                                            NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                            NULL0x00x00x00x00x0000
                                            .initPROGBITS0x80480940x940x1c0x00x6AX001
                                            .textPROGBITS0x80480b00xb00x8e360x00x6AX0016
                                            .finiPROGBITS0x8050ee60x8ee60x170x00x6AX001
                                            .rodataPROGBITS0x8050f000x8f000xaa00x00x2A0032
                                            .ctorsPROGBITS0x80520000xa0000x80x00x3WA004
                                            .dtorsPROGBITS0x80520080xa0080x80x00x3WA004
                                            .dataPROGBITS0x80520200xa0200x1200x00x3WA0032
                                            .bssNOBITS0x80521400xa1400x6400x00x3WA0032
                                            .shstrtabSTRTAB0x00xa1400x3e0x00x0001
                                            TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                            LOAD0x00x80480000x80480000x99a00x99a06.39400x5R E0x1000.init .text .fini .rodata
                                            LOAD0xa0000x80520000x80520000x1400x7804.56740x6RW 0x1000.ctors .dtors .data .bss
                                            GNU_STACK0x00x00x00x00x00.00000x6RW 0x4
                                            TimestampSource PortDest PortSource IPDest IP
                                            Jan 6, 2025 21:02:47.104307890 CET5311037212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:02:47.109314919 CET372125311079.124.60.186192.168.2.23
                                            Jan 6, 2025 21:02:47.109390020 CET5311037212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:02:47.109432936 CET5311037212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:02:47.114814997 CET372125311079.124.60.186192.168.2.23
                                            Jan 6, 2025 21:02:47.114860058 CET5311037212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:02:47.119611979 CET372125311079.124.60.186192.168.2.23
                                            Jan 6, 2025 21:02:48.428862095 CET372125311079.124.60.186192.168.2.23
                                            Jan 6, 2025 21:02:48.428890944 CET372125311079.124.60.186192.168.2.23
                                            Jan 6, 2025 21:02:48.428899050 CET372125311079.124.60.186192.168.2.23
                                            Jan 6, 2025 21:02:48.428961039 CET372125311079.124.60.186192.168.2.23
                                            Jan 6, 2025 21:02:48.429122925 CET5311037212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:02:48.429122925 CET5311037212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:02:48.429122925 CET5311037212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:02:48.429122925 CET5311037212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:02:48.429122925 CET5311037212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:02:48.429183960 CET5311237212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:02:48.434087992 CET372125311279.124.60.186192.168.2.23
                                            Jan 6, 2025 21:02:48.434174061 CET5311237212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:02:48.434174061 CET5311237212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:02:48.438954115 CET372125311279.124.60.186192.168.2.23
                                            Jan 6, 2025 21:02:48.439026117 CET5311237212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:02:48.443828106 CET372125311279.124.60.186192.168.2.23
                                            Jan 6, 2025 21:02:49.125467062 CET372125311279.124.60.186192.168.2.23
                                            Jan 6, 2025 21:02:49.125674009 CET5311237212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:02:49.125708103 CET5311237212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:02:49.125776052 CET5311437212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:02:49.130603075 CET372125311479.124.60.186192.168.2.23
                                            Jan 6, 2025 21:02:49.130723000 CET5311437212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:02:49.130723000 CET5311437212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:02:49.135514975 CET372125311479.124.60.186192.168.2.23
                                            Jan 6, 2025 21:02:49.135642052 CET5311437212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:02:49.140461922 CET372125311479.124.60.186192.168.2.23
                                            Jan 6, 2025 21:02:49.471541882 CET43928443192.168.2.2391.189.91.42
                                            Jan 6, 2025 21:02:49.800400972 CET372125311479.124.60.186192.168.2.23
                                            Jan 6, 2025 21:02:49.800704002 CET5311437212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:02:49.800704002 CET5311437212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:02:49.800753117 CET5311637212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:02:49.805599928 CET372125311679.124.60.186192.168.2.23
                                            Jan 6, 2025 21:02:49.805660009 CET5311637212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:02:49.805687904 CET5311637212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:02:49.810571909 CET372125311679.124.60.186192.168.2.23
                                            Jan 6, 2025 21:02:49.810621977 CET5311637212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:02:49.815397978 CET372125311679.124.60.186192.168.2.23
                                            Jan 6, 2025 21:02:50.478595972 CET372125311679.124.60.186192.168.2.23
                                            Jan 6, 2025 21:02:50.478835106 CET5311637212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:02:50.478835106 CET5311637212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:02:50.478892088 CET5311837212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:02:50.483655930 CET372125311879.124.60.186192.168.2.23
                                            Jan 6, 2025 21:02:50.483712912 CET5311837212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:02:50.483726978 CET5311837212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:02:50.488466978 CET372125311879.124.60.186192.168.2.23
                                            Jan 6, 2025 21:02:50.488512039 CET5311837212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:02:50.493247986 CET372125311879.124.60.186192.168.2.23
                                            Jan 6, 2025 21:02:51.162653923 CET372125311879.124.60.186192.168.2.23
                                            Jan 6, 2025 21:02:51.162786961 CET5311837212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:02:51.162786961 CET5311837212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:02:51.162825108 CET5312037212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:02:51.167594910 CET372125312079.124.60.186192.168.2.23
                                            Jan 6, 2025 21:02:51.167644978 CET5312037212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:02:51.167664051 CET5312037212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:02:51.172473907 CET372125312079.124.60.186192.168.2.23
                                            Jan 6, 2025 21:02:51.172542095 CET5312037212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:02:51.177320004 CET372125312079.124.60.186192.168.2.23
                                            Jan 6, 2025 21:02:51.858453035 CET372125312079.124.60.186192.168.2.23
                                            Jan 6, 2025 21:02:51.858560085 CET5312037212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:02:51.858594894 CET5312037212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:02:51.858620882 CET5312237212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:02:51.863416910 CET372125312279.124.60.186192.168.2.23
                                            Jan 6, 2025 21:02:51.863466024 CET5312237212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:02:51.863482952 CET5312237212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:02:51.868271112 CET372125312279.124.60.186192.168.2.23
                                            Jan 6, 2025 21:02:51.868330002 CET5312237212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:02:51.873089075 CET372125312279.124.60.186192.168.2.23
                                            Jan 6, 2025 21:02:52.539201021 CET372125312279.124.60.186192.168.2.23
                                            Jan 6, 2025 21:02:52.539330959 CET5312237212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:02:52.539369106 CET5312237212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:02:52.539372921 CET5312437212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:02:52.544306993 CET372125312479.124.60.186192.168.2.23
                                            Jan 6, 2025 21:02:52.544354916 CET5312437212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:02:52.544370890 CET5312437212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:02:52.549374104 CET372125312479.124.60.186192.168.2.23
                                            Jan 6, 2025 21:02:52.549417973 CET5312437212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:02:52.554291010 CET372125312479.124.60.186192.168.2.23
                                            Jan 6, 2025 21:02:53.214648962 CET372125312479.124.60.186192.168.2.23
                                            Jan 6, 2025 21:02:53.214788914 CET5312437212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:02:53.214788914 CET5312437212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:02:53.214822054 CET5312637212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:02:53.219634056 CET372125312679.124.60.186192.168.2.23
                                            Jan 6, 2025 21:02:53.219687939 CET5312637212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:02:53.219715118 CET5312637212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:02:53.224462986 CET372125312679.124.60.186192.168.2.23
                                            Jan 6, 2025 21:02:53.224538088 CET5312637212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:02:53.229289055 CET372125312679.124.60.186192.168.2.23
                                            Jan 6, 2025 21:02:53.899912119 CET372125312679.124.60.186192.168.2.23
                                            Jan 6, 2025 21:02:53.900311947 CET5312637212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:02:53.900314093 CET5312837212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:02:53.900311947 CET5312637212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:02:53.905191898 CET372125312879.124.60.186192.168.2.23
                                            Jan 6, 2025 21:02:53.905262947 CET5312837212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:02:53.905278921 CET5312837212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:02:53.910114050 CET372125312879.124.60.186192.168.2.23
                                            Jan 6, 2025 21:02:53.910176992 CET5312837212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:02:53.914963007 CET372125312879.124.60.186192.168.2.23
                                            Jan 6, 2025 21:02:54.602313042 CET372125312879.124.60.186192.168.2.23
                                            Jan 6, 2025 21:02:54.602478981 CET5312837212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:02:54.602518082 CET5312837212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:02:54.602536917 CET5313037212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:02:54.607320070 CET372125313079.124.60.186192.168.2.23
                                            Jan 6, 2025 21:02:54.607367039 CET5313037212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:02:54.607393026 CET5313037212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:02:54.612169981 CET372125313079.124.60.186192.168.2.23
                                            Jan 6, 2025 21:02:54.612248898 CET5313037212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:02:54.617006063 CET372125313079.124.60.186192.168.2.23
                                            Jan 6, 2025 21:02:55.102818966 CET42836443192.168.2.2391.189.91.43
                                            Jan 6, 2025 21:02:55.299532890 CET372125313079.124.60.186192.168.2.23
                                            Jan 6, 2025 21:02:55.299961090 CET5313037212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:02:55.300064087 CET5313037212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:02:55.300189972 CET5313237212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:02:55.304971933 CET372125313279.124.60.186192.168.2.23
                                            Jan 6, 2025 21:02:55.305049896 CET5313237212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:02:55.305113077 CET5313237212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:02:55.309914112 CET372125313279.124.60.186192.168.2.23
                                            Jan 6, 2025 21:02:55.310030937 CET5313237212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:02:55.314784050 CET372125313279.124.60.186192.168.2.23
                                            Jan 6, 2025 21:02:55.981805086 CET372125313279.124.60.186192.168.2.23
                                            Jan 6, 2025 21:02:55.981983900 CET5313237212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:02:55.981985092 CET5313237212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:02:55.982049942 CET5313437212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:02:55.986898899 CET372125313479.124.60.186192.168.2.23
                                            Jan 6, 2025 21:02:55.986974955 CET5313437212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:02:55.987005949 CET5313437212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:02:55.991734982 CET372125313479.124.60.186192.168.2.23
                                            Jan 6, 2025 21:02:55.991796970 CET5313437212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:02:55.996547937 CET372125313479.124.60.186192.168.2.23
                                            Jan 6, 2025 21:02:56.638586998 CET4251680192.168.2.23109.202.202.202
                                            Jan 6, 2025 21:02:56.669454098 CET372125313479.124.60.186192.168.2.23
                                            Jan 6, 2025 21:02:56.669611931 CET5313437212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:02:56.669644117 CET5313437212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:02:56.669706106 CET5313637212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:02:56.674618959 CET372125313679.124.60.186192.168.2.23
                                            Jan 6, 2025 21:02:56.674707890 CET5313637212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:02:56.674736023 CET5313637212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:02:56.679521084 CET372125313679.124.60.186192.168.2.23
                                            Jan 6, 2025 21:02:56.679569006 CET5313637212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:02:56.684340000 CET372125313679.124.60.186192.168.2.23
                                            Jan 6, 2025 21:02:57.363392115 CET372125313679.124.60.186192.168.2.23
                                            Jan 6, 2025 21:02:57.363703966 CET5313637212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:02:57.363704920 CET5313637212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:02:57.363704920 CET5313837212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:02:57.368509054 CET372125313879.124.60.186192.168.2.23
                                            Jan 6, 2025 21:02:57.368578911 CET5313837212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:02:57.368808031 CET5313837212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:02:57.373564005 CET372125313879.124.60.186192.168.2.23
                                            Jan 6, 2025 21:02:57.373617887 CET5313837212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:02:57.378429890 CET372125313879.124.60.186192.168.2.23
                                            Jan 6, 2025 21:02:58.053385973 CET372125313879.124.60.186192.168.2.23
                                            Jan 6, 2025 21:02:58.053565025 CET5313837212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:02:58.053642988 CET5313837212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:02:58.053744078 CET5314037212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:02:58.058573961 CET372125314079.124.60.186192.168.2.23
                                            Jan 6, 2025 21:02:58.058639050 CET5314037212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:02:58.058701992 CET5314037212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:02:58.063517094 CET372125314079.124.60.186192.168.2.23
                                            Jan 6, 2025 21:02:58.063581944 CET5314037212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:02:58.068363905 CET372125314079.124.60.186192.168.2.23
                                            Jan 6, 2025 21:02:58.748390913 CET372125314079.124.60.186192.168.2.23
                                            Jan 6, 2025 21:02:58.748727083 CET5314037212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:02:58.748769045 CET5314037212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:02:58.748867035 CET5314237212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:02:58.753635883 CET372125314279.124.60.186192.168.2.23
                                            Jan 6, 2025 21:02:58.753736973 CET5314237212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:02:58.753803968 CET5314237212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:02:58.758758068 CET372125314279.124.60.186192.168.2.23
                                            Jan 6, 2025 21:02:58.758845091 CET5314237212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:02:58.763864994 CET372125314279.124.60.186192.168.2.23
                                            Jan 6, 2025 21:02:59.436515093 CET372125314279.124.60.186192.168.2.23
                                            Jan 6, 2025 21:02:59.436671972 CET5314237212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:02:59.436804056 CET5314237212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:02:59.436932087 CET5314437212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:02:59.441720963 CET372125314479.124.60.186192.168.2.23
                                            Jan 6, 2025 21:02:59.441791058 CET5314437212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:02:59.441868067 CET5314437212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:02:59.446592093 CET372125314479.124.60.186192.168.2.23
                                            Jan 6, 2025 21:02:59.446644068 CET5314437212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:02:59.451405048 CET372125314479.124.60.186192.168.2.23
                                            Jan 6, 2025 21:03:00.143935919 CET372125314479.124.60.186192.168.2.23
                                            Jan 6, 2025 21:03:00.144249916 CET5314437212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:03:00.144321918 CET5314437212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:03:00.144432068 CET5314637212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:03:00.149281979 CET372125314679.124.60.186192.168.2.23
                                            Jan 6, 2025 21:03:00.149395943 CET5314637212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:03:00.149461985 CET5314637212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:03:00.154257059 CET372125314679.124.60.186192.168.2.23
                                            Jan 6, 2025 21:03:00.154333115 CET5314637212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:03:00.159235954 CET372125314679.124.60.186192.168.2.23
                                            Jan 6, 2025 21:03:00.839911938 CET372125314679.124.60.186192.168.2.23
                                            Jan 6, 2025 21:03:00.840101957 CET5314637212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:03:00.840181112 CET5314637212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:03:00.840296030 CET5314837212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:03:00.845113039 CET372125314879.124.60.186192.168.2.23
                                            Jan 6, 2025 21:03:00.845212936 CET5314837212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:03:00.845266104 CET5314837212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:03:00.850069046 CET372125314879.124.60.186192.168.2.23
                                            Jan 6, 2025 21:03:00.850127935 CET5314837212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:03:00.854912043 CET372125314879.124.60.186192.168.2.23
                                            Jan 6, 2025 21:03:01.534203053 CET372125314879.124.60.186192.168.2.23
                                            Jan 6, 2025 21:03:01.534522057 CET5314837212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:03:01.534522057 CET5314837212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:03:01.534600019 CET5315037212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:03:01.540287971 CET372125315079.124.60.186192.168.2.23
                                            Jan 6, 2025 21:03:01.540414095 CET5315037212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:03:01.540468931 CET5315037212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:03:01.547219992 CET372125315079.124.60.186192.168.2.23
                                            Jan 6, 2025 21:03:01.547295094 CET5315037212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:03:01.552087069 CET372125315079.124.60.186192.168.2.23
                                            Jan 6, 2025 21:03:02.212456942 CET372125315079.124.60.186192.168.2.23
                                            Jan 6, 2025 21:03:02.212656021 CET5315037212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:03:02.212724924 CET5315037212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:03:02.212826014 CET5315237212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:03:02.217632055 CET372125315279.124.60.186192.168.2.23
                                            Jan 6, 2025 21:03:02.217727900 CET5315237212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:03:02.217818022 CET5315237212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:03:02.222567081 CET372125315279.124.60.186192.168.2.23
                                            Jan 6, 2025 21:03:02.222615004 CET5315237212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:03:02.227363110 CET372125315279.124.60.186192.168.2.23
                                            Jan 6, 2025 21:03:02.887945890 CET372125315279.124.60.186192.168.2.23
                                            Jan 6, 2025 21:03:02.888137102 CET5315237212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:03:02.888231039 CET5315237212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:03:02.888336897 CET5315437212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:03:02.893112898 CET372125315479.124.60.186192.168.2.23
                                            Jan 6, 2025 21:03:02.893188000 CET5315437212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:03:02.893266916 CET5315437212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:03:02.898026943 CET372125315479.124.60.186192.168.2.23
                                            Jan 6, 2025 21:03:02.898106098 CET5315437212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:03:02.902913094 CET372125315479.124.60.186192.168.2.23
                                            Jan 6, 2025 21:03:03.583972931 CET372125315479.124.60.186192.168.2.23
                                            Jan 6, 2025 21:03:03.584192991 CET5315437212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:03:03.584193945 CET5315437212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:03:03.584203959 CET5315637212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:03:03.589420080 CET372125315679.124.60.186192.168.2.23
                                            Jan 6, 2025 21:03:03.589476109 CET5315637212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:03:03.589502096 CET5315637212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:03:03.594341993 CET372125315679.124.60.186192.168.2.23
                                            Jan 6, 2025 21:03:03.594392061 CET5315637212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:03:03.599145889 CET372125315679.124.60.186192.168.2.23
                                            Jan 6, 2025 21:03:04.259716034 CET372125315679.124.60.186192.168.2.23
                                            Jan 6, 2025 21:03:04.259864092 CET5315637212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:03:04.259911060 CET5315637212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:03:04.259941101 CET5315837212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:03:04.264723063 CET372125315879.124.60.186192.168.2.23
                                            Jan 6, 2025 21:03:04.264787912 CET5315837212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:03:04.264803886 CET5315837212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:03:04.269717932 CET372125315879.124.60.186192.168.2.23
                                            Jan 6, 2025 21:03:04.269759893 CET5315837212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:03:04.274615049 CET372125315879.124.60.186192.168.2.23
                                            Jan 6, 2025 21:03:04.962559938 CET372125315879.124.60.186192.168.2.23
                                            Jan 6, 2025 21:03:04.962723017 CET5315837212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:03:04.962774992 CET5315837212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:03:04.962781906 CET5316037212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:03:04.967606068 CET372125316079.124.60.186192.168.2.23
                                            Jan 6, 2025 21:03:04.967664003 CET5316037212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:03:04.967689037 CET5316037212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:03:04.972439051 CET372125316079.124.60.186192.168.2.23
                                            Jan 6, 2025 21:03:04.972480059 CET5316037212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:03:04.977276087 CET372125316079.124.60.186192.168.2.23
                                            Jan 6, 2025 21:03:10.460777998 CET43928443192.168.2.2391.189.91.42
                                            Jan 6, 2025 21:03:14.976692915 CET5316037212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:03:14.981589079 CET372125316079.124.60.186192.168.2.23
                                            Jan 6, 2025 21:03:15.184381008 CET372125316079.124.60.186192.168.2.23
                                            Jan 6, 2025 21:03:15.184562922 CET5316037212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:03:20.699434996 CET42836443192.168.2.2391.189.91.43
                                            Jan 6, 2025 21:03:26.842581987 CET4251680192.168.2.23109.202.202.202
                                            Jan 6, 2025 21:03:51.415395975 CET43928443192.168.2.2391.189.91.42
                                            Jan 6, 2025 21:04:11.892565966 CET42836443192.168.2.2391.189.91.43
                                            Jan 6, 2025 21:04:15.231396914 CET5316037212192.168.2.2379.124.60.186
                                            Jan 6, 2025 21:04:15.236251116 CET372125316079.124.60.186192.168.2.23
                                            Jan 6, 2025 21:04:15.440023899 CET372125316079.124.60.186192.168.2.23
                                            Jan 6, 2025 21:04:15.440160036 CET5316037212192.168.2.2379.124.60.186

                                            System Behavior

                                            Start time (UTC):20:02:46
                                            Start date (UTC):06/01/2025
                                            Path:/tmp/res.x86.elf
                                            Arguments:/tmp/res.x86.elf
                                            File size:41744 bytes
                                            MD5 hash:c91683d171810c80cb77bd613e1b0851

                                            Start time (UTC):20:02:46
                                            Start date (UTC):06/01/2025
                                            Path:/tmp/res.x86.elf
                                            Arguments:-
                                            File size:41744 bytes
                                            MD5 hash:c91683d171810c80cb77bd613e1b0851

                                            Start time (UTC):20:02:46
                                            Start date (UTC):06/01/2025
                                            Path:/tmp/res.x86.elf
                                            Arguments:-
                                            File size:41744 bytes
                                            MD5 hash:c91683d171810c80cb77bd613e1b0851