Linux
Analysis Report
g4.elf
Overview
General Information
Detection
Score: | 64 |
Range: | 0 - 100 |
Whitelisted: | false |
Signatures
Classification
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1589621 |
Start date and time: | 2025-01-13 00:11:08 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 5m 15s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultlinuxfilecookbook.jbs |
Analysis system description: | Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11) |
Analysis Mode: | default |
Sample name: | g4.elf |
Detection: | MAL |
Classification: | mal64.spre.troj.evad.linELF@0/6@0/0 |
- VT rate limit hit for: /etc/init.d/hello
- VT rate limit hit for: http://103.136.41.100/g4
Command: | /tmp/g4.elf |
PID: | 5444 |
Exit Code: | 0 |
Exit Code Info: | |
Killed: | False |
Standard Output: | gosh that chinese family at the other table sure ate a lot |
Standard Error: |
- system is lnxubuntu20
- g4.elf New Fork (PID: 5455, Parent: 5444)
- sh New Fork (PID: 5457, Parent: 5455)
- g4.elf New Fork (PID: 5463, Parent: 5444)
- sh New Fork (PID: 5469, Parent: 5463)
- g4.elf New Fork (PID: 5470, Parent: 5444)
- sh New Fork (PID: 5472, Parent: 5470)
- g4.elf New Fork (PID: 5473, Parent: 5444)
- sh New Fork (PID: 5475, Parent: 5473)
- xfce4-panel New Fork (PID: 5448, Parent: 3147)
- xfce4-panel New Fork (PID: 5449, Parent: 3147)
- xfce4-panel New Fork (PID: 5450, Parent: 3147)
- xfce4-panel New Fork (PID: 5451, Parent: 3147)
- xfce4-panel New Fork (PID: 5452, Parent: 3147)
- xfce4-panel New Fork (PID: 5453, Parent: 3147)
- systemd New Fork (PID: 5459, Parent: 5458)
- cleanup
Click to jump to signature section
AV Detection |
---|
Source: | ReversingLabs: | |||
Source: | Virustotal: | Perma Link |
Source: | TCP traffic: |
Source: | TCP traffic: |
Source: | Socket: | Jump to behavior |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
System Summary |
---|
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior |
Source: | .symtab present: |
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior |
Source: | Classification label: |
Persistence and Installation Behavior |
---|
Source: | Crontab executable: | Jump to behavior |
Source: | File: | Jump to behavior |
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior |
Source: | Shell command executed: | Jump to behavior | ||
Source: | Shell command executed: | Jump to behavior | ||
Source: | Shell command executed: | Jump to behavior | ||
Source: | Shell command executed: | Jump to behavior |
Source: | Systemctl executable: | Jump to behavior | ||
Source: | Systemctl executable: | Jump to behavior |
Source: | Reads from proc file: | Jump to behavior |
Source: | Writes shell script file to disk with an unusual file extension: | Jump to dropped file |
Hooking and other Techniques for Hiding and Protection |
---|
Source: | File: | Jump to dropped file |
Source: | Queries kernel information via 'uname': | Jump to behavior | ||
Source: | Queries kernel information via 'uname': | Jump to behavior | ||
Source: | Queries kernel information via 'uname': | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | 1 Scripting | Valid Accounts | 1 Scheduled Task/Job | 1 Systemd Service | 1 Systemd Service | 1 Masquerading | 1 OS Credential Dumping | 11 Security Software Discovery | Remote Services | Data from Local System | 1 Non-Standard Port | Exfiltration Over Other Network Medium | 1 Service Stop |
Credentials | Domains | Default Accounts | Scheduled Task/Job | 1 Scheduled Task/Job | 1 Scheduled Task/Job | Rootkit | LSASS Memory | 1 System Information Discovery | Remote Desktop Protocol | Data from Removable Media | Junk Data | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | 1 Scripting | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | Steganography | Automated Exfiltration | Data Encrypted for Impact |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
39% | ReversingLabs | Linux.Backdoor.Mirai | ||
38% | Virustotal | Browse |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
100% | Avira URL Cloud | malware |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high | |||
false |
| unknown | ||
false | high | |||
false | high | |||
false | high | |||
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
77.90.22.16 | unknown | Germany | 12586 | ASGHOSTNETDE | false | |
1.1.1.1 | unknown | Australia | 13335 | CLOUDFLARENETUS | false |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
77.90.22.16 | Get hash | malicious | Unknown | Browse | ||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
1.1.1.1 | Get hash | malicious | Xmrig | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | FormBook, NSISDropper | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
CLOUDFLARENETUS | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | LummaC | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | LummaC | Browse |
| ||
ASGHOSTNETDE | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Njrat | Browse |
| ||
Get hash | malicious | RedLine | Browse |
| ||
Get hash | malicious | Njrat | Browse |
|
Process: | /tmp/g4.elf |
File Type: | |
Category: | dropped |
Size (bytes): | 617 |
Entropy (8bit): | 4.73699121422326 |
Encrypted: | false |
SSDEEP: | 12:i5BpMp5kTMp5Gu+a6zEq26Y2sMG259srxylKNVUdURucTyl:ifpMr8MrPd6QqwMGAsrxy8bp4 |
MD5: | C0BDFE9F238AD713156495EA2A224748 |
SHA1: | 140CCB9B07A53A03B0DA57C8A588C088EC1C0E4F |
SHA-256: | 3E84B34A9468D7CB0C1DD0B4025F21F43B1271727DD1BBF006994908D72B61CA |
SHA-512: | B0B7E96E44FB4C3D95737A476273AFC6F01D8C4AE28798AE98C63970C75F2F1E534A21F6705B99E1B145CDFE444982F5E8FFA88D6BD0E6D060A761807F640DA2 |
Malicious: | true |
Joe Sandbox View: |
|
Reputation: | low |
Preview: |
Process: | /tmp/g4.elf |
File Type: | |
Category: | dropped |
Size (bytes): | 313 |
Entropy (8bit): | 5.28368958442553 |
Encrypted: | false |
SSDEEP: | 6:z8KbX9RZAMGCk4vEuIACLm+fOAtMFF5C26VGBg+CIEXwsCBLQmWA4Rv:zb9RZADJiIE+m4Eq26Y2sLLHWrv |
MD5: | E8FA660699DB2AC4047D8DFCC165B2B5 |
SHA1: | C2C17589EF087A334E2989D39443A62156BF78BA |
SHA-256: | A0893A909155A2EE8D132B3B3A40E3FBA42589AC842490141B7D9E8964FC9B6B |
SHA-512: | C258B9CDD646447DD11D21DD928E355B0FF0CDF3C2BE965A519D95E287428C6428095551FAF2B77E3E9970AA6A163D12AC6C6AF74B7FD3A8EA90ED0130A64B26 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | /usr/lib/systemd/system-environment-generators/snapd-env-generator |
File Type: | |
Category: | dropped |
Size (bytes): | 76 |
Entropy (8bit): | 3.7627880354948586 |
Encrypted: | false |
SSDEEP: | 3:+M4VMPQnMLmPQ9JEcwwbn:+M4m4MixcZb |
MD5: | D86A1F5765F37989EB0EC3837AD13ECC |
SHA1: | D749672A734D9DEAFD61DCA501C6929EC431B83E |
SHA-256: | 85889AB8222C947C58BE565723AE603CC1A0BD2153B6B11E156826A21E6CCD45 |
SHA-512: | 338C4B776FDCC2D05E869AE1F9DB64E6E7ECC4C621AB45E51DD07C73306BACBAD7882BE8D3ACF472CAEB30D4E5367F8793D3E006694184A68F74AC943A4B7C07 |
Malicious: | false |
Reputation: | moderate, very likely benign file |
Preview: |
Process: | /tmp/g4.elf |
File Type: | |
Category: | dropped |
Size (bytes): | 134 |
Entropy (8bit): | 4.800827342303799 |
Encrypted: | false |
SSDEEP: | 3:SH3YFKKtoRFeMPHRC2I+KRIYoSGuVGBg2ZCIUU0XzT9Fw2sePn:SH3otMFF5C26VGBg+CIEX9W5Cn |
MD5: | 0A91D2A42E3A40230F13F8AE1ACE835B |
SHA1: | 84600ADBE8E19D753BDF02E878413990F9D47168 |
SHA-256: | 1B5CF37D84868105A7D316172D6D5FAC3C7896AFD590BFB547C2908AD6E11B28 |
SHA-512: | 2A6A6C514219F49BEB0EA57AEDE2BBBF7EA6ADF277861184AD1A5D4DA934DCC4A74C556B67C62E0B010C69C217510B318B241E411B6456A0CDD2293AAB13BA6C |
Malicious: | true |
Reputation: | low |
Preview: |
Process: | /tmp/g4.elf |
File Type: | |
Category: | dropped |
Size (bytes): | 259 |
Entropy (8bit): | 3.482343383791146 |
Encrypted: | false |
SSDEEP: | 3:FV5IX9FQWUQfvxzVoHXSY/VUWV/FFFQWUQfvxm3/l/VVdf/FVLADsVHI1v/VVdft:OgcB7Y/VUS/FYc8/VjmsVot/VOArB/VF |
MD5: | A4081B8878882933359D0D776002F530 |
SHA1: | DCF81EC7D8C3FEEE9E341BFD6E59DAAB398F450B |
SHA-256: | 91E3CBA51E45CBDCFEA7B3C6E6C2EBD496135169123FA83512FC18086601C3BE |
SHA-512: | 18C82C68DE2846DE158D1224E37C14104954B7327EDDEFAEC4395AE6D89A5ECC810D06186C078780F84288FDEC0D98E9EC20423AB630E60EA39922D25789084E |
Malicious: | false |
Preview: |
Process: | /usr/bin/crontab |
File Type: | |
Category: | dropped |
Size (bytes): | 324 |
Entropy (8bit): | 5.241534489502274 |
Encrypted: | false |
SSDEEP: | 6:SUrpqoqQjEOP1K8XAEuLuwJOBFQ3pMfeiGMQ5UYLtCFt3HYotMFF5C26VGBg+CIK:8Qj7QEuLut83pMmUeHLUHYAEq26Y2sK |
MD5: | 55F5CD1A9CAB34E760F62D96880034DC |
SHA1: | AAC043A6DA2972D2787310B971F451B344C5DF26 |
SHA-256: | BA6DA3F04BB4516A380F3215363A95511D87FD030BCBF257B735B517988EB069 |
SHA-512: | B44642BDEA9C5E7D95FABFCC7DCEE15DB39D551929C15AC306B305A7ABF4A1A4CCEAF25612D641F370FF2546850A2C62DDE817B742B4D3FF3B948FDC3C1E0D5E |
Malicious: | true |
Preview: |
File type: | |
Entropy (8bit): | 6.101053593735504 |
TrID: |
|
File name: | g4.elf |
File size: | 79'764 bytes |
MD5: | 1443976ddacfe32b22fe05a76420689c |
SHA1: | 6493f3149343976174ad2c1b3389526ec2255276 |
SHA256: | 3a6669e953a2133f8de9dd431e2aadbe65fd64e8a6ee9508a9e62a303a7ecbc9 |
SHA512: | c9aa17bcd0b7f03f8c59636dbc018553ec4bb867e88c5fb1273b703ccc9514421fa18d55280720b64f783bdbf8add325dd0484ce38e174184f949285a7c9a693 |
SSDEEP: | 1536:fbSnyk49wU591IDhe/+l40O+7MEiAcMbzz8n1gIZgTeg:jJ5OKKcMbzz8SJT |
TLSH: | AA73F756F9819B42C5D402BB7A1E569E33076BA8E3DE3313DD241B24778B62F0F27906 |
File Content Preview: | .ELF..............(.....T...4....5......4. ...(.....................l-..l-...............0...0...0..................Q.td..................................-...L..................@-.,@...0....S..... 0....S.........../..0...0...@..../..5.......0....-.@0....S |
ELF header | |
---|---|
Class: | |
Data: | |
Version: | |
Machine: | |
Version Number: | |
Type: | |
OS/ABI: | |
ABI Version: | 0 |
Entry Point Address: | |
Flags: | |
ELF Header Size: | 52 |
Program Header Offset: | 52 |
Program Header Size: | 32 |
Number of Program Headers: | 3 |
Section Header Offset: | 79244 |
Section Header Size: | 40 |
Number of Section Headers: | 13 |
Header String Table Index: | 12 |
Name | Type | Address | Offset | Size | EntSize | Flags | Flags Description | Link | Info | Align |
---|---|---|---|---|---|---|---|---|---|---|
NULL | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0 | 0 | 0 | ||
.init | PROGBITS | 0x8094 | 0x94 | 0x10 | 0x0 | 0x6 | AX | 0 | 0 | 4 |
.text | PROGBITS | 0x80b0 | 0xb0 | 0x11370 | 0x0 | 0x6 | AX | 0 | 0 | 16 |
.fini | PROGBITS | 0x19420 | 0x11420 | 0x10 | 0x0 | 0x6 | AX | 0 | 0 | 4 |
.rodata | PROGBITS | 0x19430 | 0x11430 | 0x193c | 0x0 | 0x2 | A | 0 | 0 | 4 |
.eh_frame | PROGBITS | 0x23000 | 0x13000 | 0x4 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.init_array | INIT_ARRAY | 0x23004 | 0x13004 | 0x4 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.fini_array | FINI_ARRAY | 0x23008 | 0x13008 | 0x4 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.got | PROGBITS | 0x23010 | 0x13010 | 0x74 | 0x4 | 0x3 | WA | 0 | 0 | 4 |
.data | PROGBITS | 0x23084 | 0x13084 | 0x490 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.bss | NOBITS | 0x23514 | 0x13514 | 0x2978 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.ARM.attributes | ARM_ATTRIBUTES | 0x0 | 0x13514 | 0x10 | 0x0 | 0x0 | 0 | 0 | 1 | |
.shstrtab | STRTAB | 0x0 | 0x13524 | 0x67 | 0x0 | 0x0 | 0 | 0 | 1 |
Type | Offset | Virtual Address | Physical Address | File Size | Memory Size | Entropy | Flags | Flags Description | Align | Prog Interpreter | Section Mappings |
---|---|---|---|---|---|---|---|---|---|---|---|
LOAD | 0x0 | 0x8000 | 0x8000 | 0x12d6c | 0x12d6c | 6.1248 | 0x5 | R E | 0x8000 | .init .text .fini .rodata | |
LOAD | 0x13000 | 0x23000 | 0x23000 | 0x514 | 0x2e8c | 6.0196 | 0x6 | RW | 0x8000 | .eh_frame .init_array .fini_array .got .data .bss | |
GNU_STACK | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0.0000 | 0x7 | RWE | 0x4 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jan 13, 2025 00:12:19.862370968 CET | 35841 | 53 | 192.168.2.13 | 1.1.1.1 |
Jan 13, 2025 00:12:19.867151976 CET | 53 | 35841 | 1.1.1.1 | 192.168.2.13 |
Jan 13, 2025 00:12:19.867240906 CET | 35841 | 53 | 192.168.2.13 | 1.1.1.1 |
Jan 13, 2025 00:12:19.867283106 CET | 35841 | 53 | 192.168.2.13 | 1.1.1.1 |
Jan 13, 2025 00:12:19.872390032 CET | 53 | 35841 | 1.1.1.1 | 192.168.2.13 |
Jan 13, 2025 00:12:19.872441053 CET | 35841 | 53 | 192.168.2.13 | 1.1.1.1 |
Jan 13, 2025 00:12:22.020209074 CET | 52098 | 5625 | 192.168.2.13 | 77.90.22.16 |
Jan 13, 2025 00:12:22.025134087 CET | 5625 | 52098 | 77.90.22.16 | 192.168.2.13 |
Jan 13, 2025 00:12:22.025279999 CET | 52098 | 5625 | 192.168.2.13 | 77.90.22.16 |
Jan 13, 2025 00:12:22.035104036 CET | 52098 | 5625 | 192.168.2.13 | 77.90.22.16 |
Jan 13, 2025 00:12:22.039874077 CET | 5625 | 52098 | 77.90.22.16 | 192.168.2.13 |
Jan 13, 2025 00:12:53.479043007 CET | 52098 | 5625 | 192.168.2.13 | 77.90.22.16 |
Jan 13, 2025 00:12:53.483906984 CET | 5625 | 52098 | 77.90.22.16 | 192.168.2.13 |
Jan 13, 2025 00:13:24.198863029 CET | 52098 | 5625 | 192.168.2.13 | 77.90.22.16 |
Jan 13, 2025 00:13:24.203707933 CET | 5625 | 52098 | 77.90.22.16 | 192.168.2.13 |
Jan 13, 2025 00:13:33.123050928 CET | 52098 | 5625 | 192.168.2.13 | 77.90.22.16 |
Jan 13, 2025 00:13:33.129317999 CET | 5625 | 52098 | 77.90.22.16 | 192.168.2.13 |
Jan 13, 2025 00:13:33.308451891 CET | 5625 | 52098 | 77.90.22.16 | 192.168.2.13 |
Jan 13, 2025 00:13:33.308535099 CET | 52098 | 5625 | 192.168.2.13 | 77.90.22.16 |
Jan 13, 2025 00:14:05.158926964 CET | 52098 | 5625 | 192.168.2.13 | 77.90.22.16 |
Jan 13, 2025 00:14:05.163923025 CET | 5625 | 52098 | 77.90.22.16 | 192.168.2.13 |
System Behavior
Start time (UTC): | 23:12:12 |
Start date (UTC): | 12/01/2025 |
Path: | /tmp/g4.elf |
Arguments: | /tmp/g4.elf |
File size: | 4956856 bytes |
MD5 hash: | 5ebfcae4fe2471fcc5695c2394773ff1 |
Start time (UTC): | 23:12:18 |
Start date (UTC): | 12/01/2025 |
Path: | /tmp/g4.elf |
Arguments: | - |
File size: | 4956856 bytes |
MD5 hash: | 5ebfcae4fe2471fcc5695c2394773ff1 |
Start time (UTC): | 23:12:18 |
Start date (UTC): | 12/01/2025 |
Path: | /bin/sh |
Arguments: | sh -c "systemctl daemon-reload > /dev/null 2>&1" |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 23:12:18 |
Start date (UTC): | 12/01/2025 |
Path: | /bin/sh |
Arguments: | - |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 23:12:18 |
Start date (UTC): | 12/01/2025 |
Path: | /usr/bin/systemctl |
Arguments: | systemctl daemon-reload |
File size: | 996584 bytes |
MD5 hash: | 4deddfb6741481f68aeac522cc26ff4b |
Start time (UTC): | 23:12:19 |
Start date (UTC): | 12/01/2025 |
Path: | /tmp/g4.elf |
Arguments: | - |
File size: | 4956856 bytes |
MD5 hash: | 5ebfcae4fe2471fcc5695c2394773ff1 |
Start time (UTC): | 23:12:19 |
Start date (UTC): | 12/01/2025 |
Path: | /bin/sh |
Arguments: | sh -c "systemctl start hello.service > /dev/null 2>&1" |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 23:12:19 |
Start date (UTC): | 12/01/2025 |
Path: | /bin/sh |
Arguments: | - |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 23:12:19 |
Start date (UTC): | 12/01/2025 |
Path: | /usr/bin/systemctl |
Arguments: | systemctl start hello.service |
File size: | 996584 bytes |
MD5 hash: | 4deddfb6741481f68aeac522cc26ff4b |
Start time (UTC): | 23:12:19 |
Start date (UTC): | 12/01/2025 |
Path: | /tmp/g4.elf |
Arguments: | - |
File size: | 4956856 bytes |
MD5 hash: | 5ebfcae4fe2471fcc5695c2394773ff1 |
Start time (UTC): | 23:12:19 |
Start date (UTC): | 12/01/2025 |
Path: | /bin/sh |
Arguments: | sh -c "crontab /tmp/crontab.tmp > /dev/null 2>&1" |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 23:12:19 |
Start date (UTC): | 12/01/2025 |
Path: | /bin/sh |
Arguments: | - |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 23:12:19 |
Start date (UTC): | 12/01/2025 |
Path: | /usr/bin/crontab |
Arguments: | crontab /tmp/crontab.tmp |
File size: | 43720 bytes |
MD5 hash: | 66e521d421ac9b407699061bf21806f5 |
Start time (UTC): | 23:12:19 |
Start date (UTC): | 12/01/2025 |
Path: | /tmp/g4.elf |
Arguments: | - |
File size: | 4956856 bytes |
MD5 hash: | 5ebfcae4fe2471fcc5695c2394773ff1 |
Start time (UTC): | 23:12:19 |
Start date (UTC): | 12/01/2025 |
Path: | /bin/sh |
Arguments: | sh -c "/etc/init.d/hello > /dev/null 2>&1" |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 23:12:19 |
Start date (UTC): | 12/01/2025 |
Path: | /bin/sh |
Arguments: | - |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 23:12:20 |
Start date (UTC): | 12/01/2025 |
Path: | /tmp/g4.elf |
Arguments: | - |
File size: | 4956856 bytes |
MD5 hash: | 5ebfcae4fe2471fcc5695c2394773ff1 |
Start time (UTC): | 23:12:20 |
Start date (UTC): | 12/01/2025 |
Path: | /tmp/g4.elf |
Arguments: | - |
File size: | 4956856 bytes |
MD5 hash: | 5ebfcae4fe2471fcc5695c2394773ff1 |
Start time (UTC): | 23:12:20 |
Start date (UTC): | 12/01/2025 |
Path: | /tmp/g4.elf |
Arguments: | - |
File size: | 4956856 bytes |
MD5 hash: | 5ebfcae4fe2471fcc5695c2394773ff1 |
Start time (UTC): | 23:12:20 |
Start date (UTC): | 12/01/2025 |
Path: | /tmp/g4.elf |
Arguments: | - |
File size: | 4956856 bytes |
MD5 hash: | 5ebfcae4fe2471fcc5695c2394773ff1 |
Start time (UTC): | 23:12:20 |
Start date (UTC): | 12/01/2025 |
Path: | /tmp/g4.elf |
Arguments: | - |
File size: | 4956856 bytes |
MD5 hash: | 5ebfcae4fe2471fcc5695c2394773ff1 |
Start time (UTC): | 23:12:14 |
Start date (UTC): | 12/01/2025 |
Path: | /usr/bin/xfce4-panel |
Arguments: | - |
File size: | 375768 bytes |
MD5 hash: | a15b657c7d54ac1385f1f15004ea6784 |
Start time (UTC): | 23:12:14 |
Start date (UTC): | 12/01/2025 |
Path: | /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 |
Arguments: | /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libsystray.so 6 12582920 systray "Notification Area" "Area where notification icons appear" |
File size: | 35136 bytes |
MD5 hash: | ac0b8a906f359a8ae102244738682e76 |
Start time (UTC): | 23:12:14 |
Start date (UTC): | 12/01/2025 |
Path: | /usr/bin/xfce4-panel |
Arguments: | - |
File size: | 375768 bytes |
MD5 hash: | a15b657c7d54ac1385f1f15004ea6784 |
Start time (UTC): | 23:12:14 |
Start date (UTC): | 12/01/2025 |
Path: | /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 |
Arguments: | /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libstatusnotifier.so 7 12582921 statusnotifier "Status Notifier Plugin" "Provides a panel area for status notifier items (application indicators)" |
File size: | 35136 bytes |
MD5 hash: | ac0b8a906f359a8ae102244738682e76 |
Start time (UTC): | 23:12:14 |
Start date (UTC): | 12/01/2025 |
Path: | /usr/bin/xfce4-panel |
Arguments: | - |
File size: | 375768 bytes |
MD5 hash: | a15b657c7d54ac1385f1f15004ea6784 |
Start time (UTC): | 23:12:14 |
Start date (UTC): | 12/01/2025 |
Path: | /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 |
Arguments: | /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libpulseaudio-plugin.so 8 12582922 pulseaudio "PulseAudio Plugin" "Adjust the audio volume of the PulseAudio sound system" |
File size: | 35136 bytes |
MD5 hash: | ac0b8a906f359a8ae102244738682e76 |
Start time (UTC): | 23:12:14 |
Start date (UTC): | 12/01/2025 |
Path: | /usr/bin/xfce4-panel |
Arguments: | - |
File size: | 375768 bytes |
MD5 hash: | a15b657c7d54ac1385f1f15004ea6784 |
Start time (UTC): | 23:12:14 |
Start date (UTC): | 12/01/2025 |
Path: | /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 |
Arguments: | /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libxfce4powermanager.so 9 12582923 power-manager-plugin "Power Manager Plugin" "Display the battery levels of your devices and control the brightness of your display" |
File size: | 35136 bytes |
MD5 hash: | ac0b8a906f359a8ae102244738682e76 |
Start time (UTC): | 23:12:14 |
Start date (UTC): | 12/01/2025 |
Path: | /usr/bin/xfce4-panel |
Arguments: | - |
File size: | 375768 bytes |
MD5 hash: | a15b657c7d54ac1385f1f15004ea6784 |
Start time (UTC): | 23:12:14 |
Start date (UTC): | 12/01/2025 |
Path: | /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 |
Arguments: | /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libnotification-plugin.so 10 12582924 notification-plugin "Notification Plugin" "Notification plugin for the Xfce panel" |
File size: | 35136 bytes |
MD5 hash: | ac0b8a906f359a8ae102244738682e76 |
Start time (UTC): | 23:12:15 |
Start date (UTC): | 12/01/2025 |
Path: | /usr/bin/xfce4-panel |
Arguments: | - |
File size: | 375768 bytes |
MD5 hash: | a15b657c7d54ac1385f1f15004ea6784 |
Start time (UTC): | 23:12:15 |
Start date (UTC): | 12/01/2025 |
Path: | /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 |
Arguments: | /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libactions.so 14 12582925 actions "Action Buttons" "Log out, lock or other system actions" |
File size: | 35136 bytes |
MD5 hash: | ac0b8a906f359a8ae102244738682e76 |
Start time (UTC): | 23:12:18 |
Start date (UTC): | 12/01/2025 |
Path: | /usr/lib/systemd/systemd |
Arguments: | - |
File size: | 1620224 bytes |
MD5 hash: | 9b2bec7092a40488108543f9334aab75 |
Start time (UTC): | 23:12:18 |
Start date (UTC): | 12/01/2025 |
Path: | /usr/lib/systemd/system-environment-generators/snapd-env-generator |
Arguments: | /usr/lib/systemd/system-environment-generators/snapd-env-generator |
File size: | 22760 bytes |
MD5 hash: | 3633b075f40283ec938a2a6a89671b0e |