Edit tour

Linux Analysis Report
dbg.x86.elf

Overview

General Information

Sample name:dbg.x86.elf
Analysis ID:1594540
MD5:2280f52b2b40424d0a9fec0670ee06c5
SHA1:9e2f7d98dd4fe048bffb843b1bd76aa1e37aad4d
SHA256:9790ae1ce87543c28c70365f2cdef970f5d426aee8cc24756f20a771123f9274
Tags:elfuser-abuse_ch
Infos:

Detection

Score:60
Range:0 - 100
Whitelisted:false

Signatures

Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Machine Learning detection for sample
Detected TCP or UDP traffic on non-standard ports
Sample has stripped symbol table
Suricata IDS alerts with low severity for network traffic
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Yara signature match

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
Joe Sandbox version:42.0.0 Malachite
Analysis ID:1594540
Start date and time:2025-01-19 06:02:04 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 6m 58s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:dbg.x86.elf
Detection:MAL
Classification:mal60.linELF@0/0@1/0
Command:/tmp/dbg.x86.elf
PID:6233
Exit Code:
Exit Code Info:
Killed:True
Standard Output:
suka
Standard Error:
  • system is lnxubuntu20
  • dbg.x86.elf (PID: 6233, Parent: 6159, MD5: 2280f52b2b40424d0a9fec0670ee06c5) Arguments: /tmp/dbg.x86.elf
  • cleanup
SourceRuleDescriptionAuthorStrings
dbg.x86.elfLinux_Trojan_Mirai_b14f4c5dunknownunknown
  • 0x4a40:$a: 53 31 DB 8B 4C 24 0C 8B 54 24 08 83 F9 01 76 15 66 8B 02 83 E9 02 25 FF FF 00 00 83 C2 02 01 C3 83 F9 01 77 EB 49 75 05 0F BE 02 01 C3
dbg.x86.elfLinux_Trojan_Mirai_449937aaunknownunknown
  • 0xb8fa:$a: 00 00 5B 72 65 73 6F 6C 76 5D 20 46 6F 75 6E 64 20 49 50 20
dbg.x86.elfLinux_Trojan_Mirai_88de437funknownunknown
  • 0x6652:$a: 24 08 8B 4C 24 04 85 D2 74 0D 31 C0 89 F6 C6 04 08 00 40 39 D0
dbg.x86.elfLinux_Trojan_Mirai_389ee3e9unknownunknown
  • 0x96fe:$a: 89 45 00 EB 2C 8B 4B 04 8B 13 8B 7B 18 8B 01 01 02 8B 02 83
dbg.x86.elfLinux_Trojan_Mirai_cc93863bunknownunknown
  • 0x8059:$a: C3 57 8B 44 24 0C 8B 4C 24 10 8B 7C 24 08 F3 AA 8B 44 24 08
Click to see the 1 entries
SourceRuleDescriptionAuthorStrings
6233.1.0000000008048000.0000000008055000.r-x.sdmpLinux_Trojan_Mirai_b14f4c5dunknownunknown
  • 0x4a40:$a: 53 31 DB 8B 4C 24 0C 8B 54 24 08 83 F9 01 76 15 66 8B 02 83 E9 02 25 FF FF 00 00 83 C2 02 01 C3 83 F9 01 77 EB 49 75 05 0F BE 02 01 C3
6233.1.0000000008048000.0000000008055000.r-x.sdmpLinux_Trojan_Mirai_449937aaunknownunknown
  • 0xb8fa:$a: 00 00 5B 72 65 73 6F 6C 76 5D 20 46 6F 75 6E 64 20 49 50 20
6233.1.0000000008048000.0000000008055000.r-x.sdmpLinux_Trojan_Mirai_88de437funknownunknown
  • 0x6652:$a: 24 08 8B 4C 24 04 85 D2 74 0D 31 C0 89 F6 C6 04 08 00 40 39 D0
6233.1.0000000008048000.0000000008055000.r-x.sdmpLinux_Trojan_Mirai_389ee3e9unknownunknown
  • 0x96fe:$a: 89 45 00 EB 2C 8B 4B 04 8B 13 8B 7B 18 8B 01 01 02 8B 02 83
6233.1.0000000008048000.0000000008055000.r-x.sdmpLinux_Trojan_Mirai_cc93863bunknownunknown
  • 0x8059:$a: C3 57 8B 44 24 0C 8B 4C 24 10 8B 7C 24 08 F3 AA 8B 44 24 08
Click to see the 1 entries
TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
2025-01-19T06:02:56.644016+010025000342Misc Attack83.222.191.9013566192.168.2.2342660TCP

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: dbg.x86.elfReversingLabs: Detection: 28%
Source: dbg.x86.elfJoe Sandbox ML: detected
Source: global trafficTCP traffic: 192.168.2.23:40460 -> 83.222.206.100:13566
Source: global trafficTCP traffic: 192.168.2.23:40844 -> 83.222.167.34:13566
Source: global trafficTCP traffic: 192.168.2.23:52604 -> 83.222.132.243:13566
Source: global trafficTCP traffic: 192.168.2.23:52986 -> 83.222.199.28:13566
Source: global trafficTCP traffic: 192.168.2.23:41996 -> 83.222.110.84:13566
Source: global trafficTCP traffic: 192.168.2.23:41762 -> 83.222.31.67:13566
Source: global trafficTCP traffic: 192.168.2.23:54718 -> 83.222.242.183:13566
Source: global trafficTCP traffic: 192.168.2.23:34044 -> 83.222.213.24:13566
Source: global trafficTCP traffic: 192.168.2.23:33198 -> 83.222.93.228:13566
Source: global trafficTCP traffic: 192.168.2.23:45950 -> 83.222.39.108:13566
Source: global trafficTCP traffic: 192.168.2.23:33162 -> 83.222.24.252:13566
Source: global trafficTCP traffic: 192.168.2.23:55886 -> 83.222.111.126:13566
Source: global trafficTCP traffic: 192.168.2.23:48440 -> 83.222.4.90:13566
Source: global trafficTCP traffic: 192.168.2.23:34670 -> 83.222.190.70:13566
Source: global trafficTCP traffic: 192.168.2.23:47366 -> 83.222.235.251:13566
Source: global trafficTCP traffic: 192.168.2.23:52754 -> 83.222.96.67:13566
Source: global trafficTCP traffic: 192.168.2.23:49112 -> 83.222.8.82:13566
Source: global trafficTCP traffic: 192.168.2.23:39544 -> 83.222.251.119:13566
Source: global trafficTCP traffic: 192.168.2.23:41964 -> 83.222.166.26:13566
Source: global trafficTCP traffic: 192.168.2.23:54714 -> 83.222.186.43:13566
Source: global trafficTCP traffic: 192.168.2.23:47274 -> 83.222.13.130:13566
Source: global trafficTCP traffic: 192.168.2.23:46790 -> 83.222.71.125:13566
Source: global trafficTCP traffic: 192.168.2.23:46312 -> 83.222.156.230:13566
Source: global trafficTCP traffic: 192.168.2.23:37324 -> 83.222.0.75:13566
Source: global trafficTCP traffic: 192.168.2.23:57670 -> 83.222.100.52:13566
Source: global trafficTCP traffic: 192.168.2.23:39900 -> 83.222.185.34:13566
Source: global trafficTCP traffic: 192.168.2.23:41632 -> 83.222.122.164:13566
Source: global trafficTCP traffic: 192.168.2.23:41118 -> 83.222.16.53:13566
Source: global trafficTCP traffic: 192.168.2.23:42648 -> 83.222.158.172:13566
Source: global trafficTCP traffic: 192.168.2.23:56192 -> 83.222.215.213:13566
Source: global trafficTCP traffic: 192.168.2.23:52406 -> 83.222.29.162:13566
Source: global trafficTCP traffic: 192.168.2.23:33630 -> 83.222.27.254:13566
Source: global trafficTCP traffic: 192.168.2.23:47482 -> 83.222.239.36:13566
Source: global trafficTCP traffic: 192.168.2.23:43916 -> 83.222.80.234:13566
Source: global trafficTCP traffic: 192.168.2.23:41996 -> 83.222.155.246:13566
Source: global trafficTCP traffic: 192.168.2.23:57484 -> 83.222.5.85:13566
Source: global trafficTCP traffic: 192.168.2.23:46504 -> 83.222.33.18:13566
Source: global trafficTCP traffic: 192.168.2.23:60560 -> 83.222.215.105:13566
Source: global trafficTCP traffic: 192.168.2.23:56270 -> 83.222.143.215:13566
Source: global trafficTCP traffic: 192.168.2.23:41292 -> 83.222.180.102:13566
Source: global trafficTCP traffic: 192.168.2.23:34098 -> 83.222.172.24:13566
Source: global trafficTCP traffic: 192.168.2.23:44754 -> 83.222.154.101:13566
Source: global trafficTCP traffic: 192.168.2.23:43502 -> 83.222.58.21:13566
Source: global trafficTCP traffic: 192.168.2.23:55292 -> 83.222.9.88:13566
Source: global trafficTCP traffic: 192.168.2.23:49932 -> 83.222.183.25:13566
Source: global trafficTCP traffic: 192.168.2.23:36440 -> 83.222.141.85:13566
Source: global trafficTCP traffic: 192.168.2.23:43412 -> 83.222.197.169:13566
Source: global trafficTCP traffic: 192.168.2.23:52702 -> 83.222.83.181:13566
Source: global trafficTCP traffic: 192.168.2.23:49346 -> 83.222.205.163:13566
Source: global trafficTCP traffic: 192.168.2.23:35368 -> 83.222.159.104:13566
Source: global trafficTCP traffic: 192.168.2.23:55526 -> 83.222.153.164:13566
Source: global trafficTCP traffic: 192.168.2.23:55242 -> 83.222.189.187:13566
Source: global trafficTCP traffic: 192.168.2.23:55586 -> 83.222.183.149:13566
Source: global trafficTCP traffic: 192.168.2.23:38634 -> 83.222.36.70:13566
Source: global trafficTCP traffic: 192.168.2.23:59024 -> 83.222.108.216:13566
Source: global trafficTCP traffic: 192.168.2.23:46068 -> 83.222.173.25:13566
Source: global trafficTCP traffic: 192.168.2.23:42660 -> 83.222.191.90:13566
Source: Network trafficSuricata IDS: 2500034 - Severity 2 - ET COMPROMISED Known Compromised or Hostile Host Traffic group 18 : 83.222.191.90:13566 -> 192.168.2.23:42660
Source: global trafficTCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
Source: global trafficTCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
Source: global trafficTCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.206.100
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.167.34
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.132.243
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.199.28
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.31.67
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.242.183
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.213.24
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.93.228
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.39.108
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.24.252
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.111.126
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.4.90
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.190.70
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.235.251
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.96.67
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.8.82
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.251.119
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.166.26
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.186.43
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.13.130
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.71.125
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.156.230
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.0.75
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.100.52
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.185.34
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.122.164
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.16.53
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.158.172
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.215.213
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.29.162
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.27.254
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.239.36
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.80.234
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.155.246
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.5.85
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.33.18
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.215.105
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.143.215
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.180.102
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.172.24
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.154.101
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.58.21
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.9.88
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.183.25
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.141.85
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.197.169
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.83.181
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.205.163
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.159.104
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.153.164
Source: global trafficDNS traffic detected: DNS query: secure-network-rebirthltd.ru
Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443

System Summary

barindex
Source: dbg.x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_b14f4c5d Author: unknown
Source: dbg.x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_449937aa Author: unknown
Source: dbg.x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_88de437f Author: unknown
Source: dbg.x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_389ee3e9 Author: unknown
Source: dbg.x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_cc93863b Author: unknown
Source: dbg.x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_8aa7b5d3 Author: unknown
Source: 6233.1.0000000008048000.0000000008055000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_b14f4c5d Author: unknown
Source: 6233.1.0000000008048000.0000000008055000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_449937aa Author: unknown
Source: 6233.1.0000000008048000.0000000008055000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_88de437f Author: unknown
Source: 6233.1.0000000008048000.0000000008055000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_389ee3e9 Author: unknown
Source: 6233.1.0000000008048000.0000000008055000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_cc93863b Author: unknown
Source: 6233.1.0000000008048000.0000000008055000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_8aa7b5d3 Author: unknown
Source: ELF static info symbol of initial sample.symtab present: no
Source: dbg.x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_b14f4c5d os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = a70d052918dd2fbc66db241da6438015130f0fb6929229bfe573546fe98da817, id = b14f4c5d-054f-46e6-9fa8-3588f1ef68b7, last_modified = 2021-09-16
Source: dbg.x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_449937aa reference_sample = 6f27766534445cffb097c7c52db1fca53b2210c1b10b75594f77c34dc8b994fe, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = cf2c6b86830099f039b41aeaafbffedfb8294a1124c499e99a11f48a06cd1dfd, id = 449937aa-682a-4906-89ab-80d7127e461e, last_modified = 2021-09-16
Source: dbg.x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_88de437f reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = c19eb595c2b444a809bef8500c20342c9f46694d3018e268833f9b884133a1ea, id = 88de437f-9c98-4e1d-96c0-7b433c99886a, last_modified = 2021-09-16
Source: dbg.x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_389ee3e9 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 59f2359dc1f41d385d639d157b4cd9fc73d76d8abb7cc09d47632bb4c9a39e6e, id = 389ee3e9-70c1-4c93-a999-292cf6ff1652, last_modified = 2022-01-26
Source: dbg.x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_cc93863b reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = f3ecd30f0b511a8e92cfa642409d559e7612c3f57a1659ca46c77aca809a00ac, id = cc93863b-1050-40ba-9d02-5ec9ce6a3a28, last_modified = 2022-01-26
Source: dbg.x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_8aa7b5d3 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 02a2c18c362df4b1fceb33f3b605586514ba9a00c7afedf71c04fa54d8146444, id = 8aa7b5d3-e1eb-4b55-b36a-0d3a242c06e9, last_modified = 2022-01-26
Source: 6233.1.0000000008048000.0000000008055000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_b14f4c5d os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = a70d052918dd2fbc66db241da6438015130f0fb6929229bfe573546fe98da817, id = b14f4c5d-054f-46e6-9fa8-3588f1ef68b7, last_modified = 2021-09-16
Source: 6233.1.0000000008048000.0000000008055000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_449937aa reference_sample = 6f27766534445cffb097c7c52db1fca53b2210c1b10b75594f77c34dc8b994fe, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = cf2c6b86830099f039b41aeaafbffedfb8294a1124c499e99a11f48a06cd1dfd, id = 449937aa-682a-4906-89ab-80d7127e461e, last_modified = 2021-09-16
Source: 6233.1.0000000008048000.0000000008055000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_88de437f reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = c19eb595c2b444a809bef8500c20342c9f46694d3018e268833f9b884133a1ea, id = 88de437f-9c98-4e1d-96c0-7b433c99886a, last_modified = 2021-09-16
Source: 6233.1.0000000008048000.0000000008055000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_389ee3e9 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 59f2359dc1f41d385d639d157b4cd9fc73d76d8abb7cc09d47632bb4c9a39e6e, id = 389ee3e9-70c1-4c93-a999-292cf6ff1652, last_modified = 2022-01-26
Source: 6233.1.0000000008048000.0000000008055000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_cc93863b reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = f3ecd30f0b511a8e92cfa642409d559e7612c3f57a1659ca46c77aca809a00ac, id = cc93863b-1050-40ba-9d02-5ec9ce6a3a28, last_modified = 2022-01-26
Source: 6233.1.0000000008048000.0000000008055000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_8aa7b5d3 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 02a2c18c362df4b1fceb33f3b605586514ba9a00c7afedf71c04fa54d8146444, id = 8aa7b5d3-e1eb-4b55-b36a-0d3a242c06e9, last_modified = 2022-01-26
Source: classification engineClassification label: mal60.linELF@0/0@1/0
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath InterceptionDirect Volume AccessOS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Non-Standard Port
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
Non-Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture2
Application Layer Protocol
Traffic DuplicationData Destruction
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1594540 Sample: dbg.x86.elf Startdate: 19/01/2025 Architecture: LINUX Score: 60 8 83.222.197.169, 13566, 43412 SYNTERRA-ASRU Russian Federation 2->8 10 83.222.199.28, 13566, 52986 SYNTERRA-ASRU Russian Federation 2->10 12 58 other IPs or domains 2->12 14 Malicious sample detected (through community Yara rule) 2->14 16 Multi AV Scanner detection for submitted file 2->16 18 Machine Learning detection for sample 2->18 6 dbg.x86.elf 2->6         started        signatures3 process4

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
dbg.x86.elf29%ReversingLabsLinux.Backdoor.Gafgyt
dbg.x86.elf100%Joe Sandbox ML
No Antivirus matches
No Antivirus matches
No Antivirus matches

Download Network PCAP: filteredfull

NameIPActiveMaliciousAntivirus DetectionReputation
secure-network-rebirthltd.ru
83.222.191.90
truefalse
    high
    • No. of IPs < 25%
    • 25% < No. of IPs < 50%
    • 50% < No. of IPs < 75%
    • 75% < No. of IPs
    IPDomainCountryFlagASNASN NameMalicious
    83.222.206.100
    unknownRussian Federation
    6854SYNTERRA-ASRUfalse
    83.222.172.24
    unknownBulgaria
    49040KIG-UNISAT-TVBGfalse
    83.222.100.52
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    83.222.167.34
    unknownBulgaria
    49040KIG-UNISAT-TVBGfalse
    83.222.141.85
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.24.252
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.155.246
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.158.172
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.80.234
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.166.26
    unknownBulgaria
    12615GCN-ASGCNAD-SofiaBulgariaBGfalse
    83.222.33.18
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.122.164
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    83.222.215.105
    unknownRussian Federation
    25159SONICDUO-ASRUfalse
    83.222.251.119
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.199.28
    unknownRussian Federation
    6854SYNTERRA-ASRUfalse
    91.189.91.43
    unknownUnited Kingdom
    41231CANONICAL-ASGBfalse
    91.189.91.42
    unknownUnited Kingdom
    41231CANONICAL-ASGBfalse
    83.222.173.25
    unknownBulgaria
    12615GCN-ASGCNAD-SofiaBulgariaBGfalse
    83.222.8.82
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.153.164
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.96.67
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    83.222.183.25
    unknownBulgaria
    12615GCN-ASGCNAD-SofiaBulgariaBGfalse
    83.222.186.43
    unknownBulgaria
    43561NET1-ASBGfalse
    83.222.93.228
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.185.34
    unknownBulgaria
    43561NET1-ASBGfalse
    83.222.39.108
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.156.230
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.197.169
    unknownRussian Federation
    6854SYNTERRA-ASRUfalse
    83.222.159.104
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.71.125
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.239.36
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.9.88
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.213.24
    unknownRussian Federation
    25159SONICDUO-ASRUfalse
    83.222.215.213
    unknownRussian Federation
    25159SONICDUO-ASRUfalse
    83.222.0.75
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.111.126
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    83.222.5.85
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.189.187
    unknownBulgaria
    43561NET1-ASBGfalse
    83.222.36.70
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.180.102
    unknownBulgaria
    205872EXTRANET-ASBGfalse
    83.222.190.70
    unknownBulgaria
    43561NET1-ASBGfalse
    83.222.58.21
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.205.163
    unknownRussian Federation
    6854SYNTERRA-ASRUfalse
    83.222.27.254
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.242.183
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.16.53
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.183.149
    unknownBulgaria
    12615GCN-ASGCNAD-SofiaBulgariaBGfalse
    83.222.235.251
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.13.130
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.191.90
    secure-network-rebirthltd.ruBulgaria
    43561NET1-ASBGfalse
    83.222.29.162
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.132.243
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    109.202.202.202
    unknownSwitzerland
    13030INIT7CHfalse
    83.222.83.181
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.31.67
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.154.101
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.110.84
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    83.222.108.216
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    83.222.4.90
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.143.215
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
    83.222.96.67Kloki.i686.elfGet hashmaliciousUnknownBrowse
      loki.x86.elfGet hashmaliciousUnknownBrowse
        91.189.91.43mips.elfGet hashmaliciousUnknownBrowse
          spc.elfGet hashmaliciousUnknownBrowse
            x86.elfGet hashmaliciousUnknownBrowse
              arm7.elfGet hashmaliciousUnknownBrowse
                45.11.229.95-boatnet.arc-2025-01-19T02_22_30.elfGet hashmaliciousMiraiBrowse
                  na.elfGet hashmaliciousPrometeiBrowse
                    Kloki.mpsl.elfGet hashmaliciousUnknownBrowse
                      sh4.elfGet hashmaliciousUnknownBrowse
                        na.elfGet hashmaliciousPrometeiBrowse
                          Kloki.arm6.elfGet hashmaliciousUnknownBrowse
                            91.189.91.42mips.elfGet hashmaliciousUnknownBrowse
                              spc.elfGet hashmaliciousUnknownBrowse
                                x86.elfGet hashmaliciousUnknownBrowse
                                  arm7.elfGet hashmaliciousUnknownBrowse
                                    45.11.229.95-boatnet.x86-2025-01-19T02_22_29.elfGet hashmaliciousMiraiBrowse
                                      45.11.229.95-boatnet.arc-2025-01-19T02_22_30.elfGet hashmaliciousMiraiBrowse
                                        na.elfGet hashmaliciousPrometeiBrowse
                                          Kloki.mpsl.elfGet hashmaliciousUnknownBrowse
                                            sh4.elfGet hashmaliciousUnknownBrowse
                                              na.elfGet hashmaliciousPrometeiBrowse
                                                MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                secure-network-rebirthltd.ruKloki.mpsl.elfGet hashmaliciousUnknownBrowse
                                                • 83.222.191.90
                                                loki.arm5.elfGet hashmaliciousUnknownBrowse
                                                • 83.222.191.90
                                                loki.i686.elfGet hashmaliciousUnknownBrowse
                                                • 83.222.191.90
                                                loki.arm4.elfGet hashmaliciousUnknownBrowse
                                                • 83.222.191.90
                                                loki.ppc.elfGet hashmaliciousUnknownBrowse
                                                • 83.222.191.90
                                                Kloki.arm4.elfGet hashmaliciousUnknownBrowse
                                                • 83.222.191.90
                                                Kloki.m68k.elfGet hashmaliciousUnknownBrowse
                                                • 83.222.191.90
                                                Kloki.i686.elfGet hashmaliciousUnknownBrowse
                                                • 83.222.191.90
                                                loki.x86.elfGet hashmaliciousUnknownBrowse
                                                • 83.222.191.90
                                                Kloki.mips.elfGet hashmaliciousUnknownBrowse
                                                • 83.222.191.90
                                                MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                MNOGOBYTE-ASMoscowRussiaRUKloki.mpsl.elfGet hashmaliciousUnknownBrowse
                                                • 83.222.102.164
                                                loki.arm5.elfGet hashmaliciousUnknownBrowse
                                                • 83.222.123.142
                                                loki.i686.elfGet hashmaliciousUnknownBrowse
                                                • 83.222.99.79
                                                loki.arm4.elfGet hashmaliciousUnknownBrowse
                                                • 83.222.123.192
                                                loki.ppc.elfGet hashmaliciousUnknownBrowse
                                                • 83.222.106.184
                                                Kloki.arm4.elfGet hashmaliciousUnknownBrowse
                                                • 83.222.114.40
                                                Kloki.m68k.elfGet hashmaliciousUnknownBrowse
                                                • 83.222.100.166
                                                Kloki.i686.elfGet hashmaliciousUnknownBrowse
                                                • 83.222.114.84
                                                loki.x86.elfGet hashmaliciousUnknownBrowse
                                                • 83.222.117.151
                                                Kloki.mips.elfGet hashmaliciousUnknownBrowse
                                                • 83.222.105.103
                                                SYNTERRA-ASRUKloki.mpsl.elfGet hashmaliciousUnknownBrowse
                                                • 83.222.211.141
                                                loki.arm5.elfGet hashmaliciousUnknownBrowse
                                                • 83.222.192.164
                                                loki.i686.elfGet hashmaliciousUnknownBrowse
                                                • 83.222.203.223
                                                loki.arm4.elfGet hashmaliciousUnknownBrowse
                                                • 83.222.192.64
                                                loki.ppc.elfGet hashmaliciousUnknownBrowse
                                                • 83.222.195.117
                                                Kloki.arm4.elfGet hashmaliciousUnknownBrowse
                                                • 83.222.207.75
                                                Kloki.m68k.elfGet hashmaliciousUnknownBrowse
                                                • 83.222.192.22
                                                Kloki.i686.elfGet hashmaliciousUnknownBrowse
                                                • 83.222.204.106
                                                loki.x86.elfGet hashmaliciousUnknownBrowse
                                                • 83.222.204.106
                                                Kloki.mips.elfGet hashmaliciousUnknownBrowse
                                                • 83.222.210.211
                                                KIG-UNISAT-TVBGloki.i686.elfGet hashmaliciousUnknownBrowse
                                                • 83.222.170.80
                                                loki.arm4.elfGet hashmaliciousUnknownBrowse
                                                • 83.222.172.206
                                                Kloki.m68k.elfGet hashmaliciousUnknownBrowse
                                                • 83.222.167.50
                                                Kloki.i686.elfGet hashmaliciousUnknownBrowse
                                                • 83.222.160.160
                                                loki.x86.elfGet hashmaliciousUnknownBrowse
                                                • 83.222.160.160
                                                Kloki.mips.elfGet hashmaliciousUnknownBrowse
                                                • 83.222.170.174
                                                loki.mips.elfGet hashmaliciousUnknownBrowse
                                                • 83.222.172.220
                                                Kloki.sh4.elfGet hashmaliciousUnknownBrowse
                                                • 83.222.170.87
                                                loki.arm7.elfGet hashmaliciousMiraiBrowse
                                                • 83.222.160.209
                                                Kloki.ppc.elfGet hashmaliciousUnknownBrowse
                                                • 83.222.160.195
                                                No context
                                                No context
                                                No created / dropped files found
                                                File type:ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, stripped
                                                Entropy (8bit):6.449727581119564
                                                TrID:
                                                • ELF Executable and Linkable format (Linux) (4029/14) 50.16%
                                                • ELF Executable and Linkable format (generic) (4004/1) 49.84%
                                                File name:dbg.x86.elf
                                                File size:54'416 bytes
                                                MD5:2280f52b2b40424d0a9fec0670ee06c5
                                                SHA1:9e2f7d98dd4fe048bffb843b1bd76aa1e37aad4d
                                                SHA256:9790ae1ce87543c28c70365f2cdef970f5d426aee8cc24756f20a771123f9274
                                                SHA512:5274f1f18e4d841d4486225fe72df5f0138b66ad5d3eaef2629dc76037f9c8a1f835ba391595546fd61c01e31204a1f8e1fbb0e9e8cbc5136f4d022ea6ff27f8
                                                SSDEEP:1536:Dil8aOO2vwFTvapPSp5el5HzMVFnB7V6E8xdSm1f:DiWTO2vKvFp5evT2FB7kEMSSf
                                                TLSH:E1336CC19743D4F6EC5B09715037F3739AB2E03E0268DA93C3A9D632F853A51E61A28C
                                                File Content Preview:.ELF....................d...4...........4. ...(..............................................P...P.......'..........Q.td............................U..S.......w....h........[]...$.............U......=.R...t..5....$P.....$P......u........t....h.L..........

                                                ELF header

                                                Class:ELF32
                                                Data:2's complement, little endian
                                                Version:1 (current)
                                                Machine:Intel 80386
                                                Version Number:0x1
                                                Type:EXEC (Executable file)
                                                OS/ABI:UNIX - System V
                                                ABI Version:0
                                                Entry Point Address:0x8048164
                                                Flags:0x0
                                                ELF Header Size:52
                                                Program Header Offset:52
                                                Program Header Size:32
                                                Number of Program Headers:3
                                                Section Header Offset:54016
                                                Section Header Size:40
                                                Number of Section Headers:10
                                                Header String Table Index:9
                                                NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                                NULL0x00x00x00x00x0000
                                                .initPROGBITS0x80480940x940x1c0x00x6AX001
                                                .textPROGBITS0x80480b00xb00xb1060x00x6AX0016
                                                .finiPROGBITS0x80531b60xb1b60x170x00x6AX001
                                                .rodataPROGBITS0x80531e00xb1e00x1adc0x00x2A0032
                                                .ctorsPROGBITS0x80550000xd0000x80x00x3WA004
                                                .dtorsPROGBITS0x80550080xd0080x80x00x3WA004
                                                .dataPROGBITS0x80550200xd0200x2a00x00x3WA0032
                                                .bssNOBITS0x80552c00xd2c00x24c00x00x3WA0032
                                                .shstrtabSTRTAB0x00xd2c00x3e0x00x0001
                                                TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                LOAD0x00x80480000x80480000xccbc0xccbc6.54820x5R E0x1000.init .text .fini .rodata
                                                LOAD0xd0000x80550000x80550000x2c00x27803.50880x6RW 0x1000.ctors .dtors .data .bss
                                                GNU_STACK0x00x00x00x00x00.00000x6RW 0x4

                                                Download Network PCAP: filteredfull

                                                TimestampSIDSignatureSeveritySource IPSource PortDest IPDest PortProtocol
                                                2025-01-19T06:02:56.644016+01002500034ET COMPROMISED Known Compromised or Hostile Host Traffic group 18283.222.191.9013566192.168.2.2342660TCP
                                                • Total Packets: 128
                                                • 13566 undefined
                                                • 443 (HTTPS)
                                                • 80 (HTTP)
                                                • 53 (DNS)
                                                TimestampSource PortDest PortSource IPDest IP
                                                Jan 19, 2025 06:02:56.628407001 CET4046013566192.168.2.2383.222.206.100
                                                Jan 19, 2025 06:02:56.628428936 CET4084413566192.168.2.2383.222.167.34
                                                Jan 19, 2025 06:02:56.628467083 CET5260413566192.168.2.2383.222.132.243
                                                Jan 19, 2025 06:02:56.628470898 CET5298613566192.168.2.2383.222.199.28
                                                Jan 19, 2025 06:02:56.628468990 CET4199613566192.168.2.2383.222.110.84
                                                Jan 19, 2025 06:02:56.628468990 CET4176213566192.168.2.2383.222.31.67
                                                Jan 19, 2025 06:02:56.628519058 CET5471813566192.168.2.2383.222.242.183
                                                Jan 19, 2025 06:02:56.628523111 CET3404413566192.168.2.2383.222.213.24
                                                Jan 19, 2025 06:02:56.628525972 CET3319813566192.168.2.2383.222.93.228
                                                Jan 19, 2025 06:02:56.628571033 CET4595013566192.168.2.2383.222.39.108
                                                Jan 19, 2025 06:02:56.628571033 CET3316213566192.168.2.2383.222.24.252
                                                Jan 19, 2025 06:02:56.628567934 CET5588613566192.168.2.2383.222.111.126
                                                Jan 19, 2025 06:02:56.628585100 CET4844013566192.168.2.2383.222.4.90
                                                Jan 19, 2025 06:02:56.628585100 CET3467013566192.168.2.2383.222.190.70
                                                Jan 19, 2025 06:02:56.628585100 CET4736613566192.168.2.2383.222.235.251
                                                Jan 19, 2025 06:02:56.628603935 CET5275413566192.168.2.2383.222.96.67
                                                Jan 19, 2025 06:02:56.628612995 CET4911213566192.168.2.2383.222.8.82
                                                Jan 19, 2025 06:02:56.628637075 CET3954413566192.168.2.2383.222.251.119
                                                Jan 19, 2025 06:02:56.628637075 CET4196413566192.168.2.2383.222.166.26
                                                Jan 19, 2025 06:02:56.628654957 CET5471413566192.168.2.2383.222.186.43
                                                Jan 19, 2025 06:02:56.628673077 CET4727413566192.168.2.2383.222.13.130
                                                Jan 19, 2025 06:02:56.628679037 CET4679013566192.168.2.2383.222.71.125
                                                Jan 19, 2025 06:02:56.628683090 CET4631213566192.168.2.2383.222.156.230
                                                Jan 19, 2025 06:02:56.628694057 CET3732413566192.168.2.2383.222.0.75
                                                Jan 19, 2025 06:02:56.628726959 CET5767013566192.168.2.2383.222.100.52
                                                Jan 19, 2025 06:02:56.628731966 CET3990013566192.168.2.2383.222.185.34
                                                Jan 19, 2025 06:02:56.628745079 CET4163213566192.168.2.2383.222.122.164
                                                Jan 19, 2025 06:02:56.628777981 CET4111813566192.168.2.2383.222.16.53
                                                Jan 19, 2025 06:02:56.628802061 CET4264813566192.168.2.2383.222.158.172
                                                Jan 19, 2025 06:02:56.628802061 CET5619213566192.168.2.2383.222.215.213
                                                Jan 19, 2025 06:02:56.628802061 CET5240613566192.168.2.2383.222.29.162
                                                Jan 19, 2025 06:02:56.628806114 CET3363013566192.168.2.2383.222.27.254
                                                Jan 19, 2025 06:02:56.628829002 CET4748213566192.168.2.2383.222.239.36
                                                Jan 19, 2025 06:02:56.628833055 CET4391613566192.168.2.2383.222.80.234
                                                Jan 19, 2025 06:02:56.628839970 CET4199613566192.168.2.2383.222.155.246
                                                Jan 19, 2025 06:02:56.628866911 CET5748413566192.168.2.2383.222.5.85
                                                Jan 19, 2025 06:02:56.628874063 CET4650413566192.168.2.2383.222.33.18
                                                Jan 19, 2025 06:02:56.628882885 CET6056013566192.168.2.2383.222.215.105
                                                Jan 19, 2025 06:02:56.628896952 CET5627013566192.168.2.2383.222.143.215
                                                Jan 19, 2025 06:02:56.628920078 CET4129213566192.168.2.2383.222.180.102
                                                Jan 19, 2025 06:02:56.628925085 CET3409813566192.168.2.2383.222.172.24
                                                Jan 19, 2025 06:02:56.628931046 CET4475413566192.168.2.2383.222.154.101
                                                Jan 19, 2025 06:02:56.628958941 CET4350213566192.168.2.2383.222.58.21
                                                Jan 19, 2025 06:02:56.628959894 CET5529213566192.168.2.2383.222.9.88
                                                Jan 19, 2025 06:02:56.628984928 CET4993213566192.168.2.2383.222.183.25
                                                Jan 19, 2025 06:02:56.628985882 CET3644013566192.168.2.2383.222.141.85
                                                Jan 19, 2025 06:02:56.628998041 CET4341213566192.168.2.2383.222.197.169
                                                Jan 19, 2025 06:02:56.629014969 CET5270213566192.168.2.2383.222.83.181
                                                Jan 19, 2025 06:02:56.629030943 CET4934613566192.168.2.2383.222.205.163
                                                Jan 19, 2025 06:02:56.629046917 CET3536813566192.168.2.2383.222.159.104
                                                Jan 19, 2025 06:02:56.629055023 CET5552613566192.168.2.2383.222.153.164
                                                Jan 19, 2025 06:02:56.629077911 CET5524213566192.168.2.2383.222.189.187
                                                Jan 19, 2025 06:02:56.629081964 CET5558613566192.168.2.2383.222.183.149
                                                Jan 19, 2025 06:02:56.629111052 CET3863413566192.168.2.2383.222.36.70
                                                Jan 19, 2025 06:02:56.629117012 CET5902413566192.168.2.2383.222.108.216
                                                Jan 19, 2025 06:02:56.629125118 CET4606813566192.168.2.2383.222.173.25
                                                Jan 19, 2025 06:02:56.633671045 CET135665298683.222.199.28192.168.2.23
                                                Jan 19, 2025 06:02:56.633688927 CET135664046083.222.206.100192.168.2.23
                                                Jan 19, 2025 06:02:56.633703947 CET135665260483.222.132.243192.168.2.23
                                                Jan 19, 2025 06:02:56.633725882 CET135664084483.222.167.34192.168.2.23
                                                Jan 19, 2025 06:02:56.633735895 CET5298613566192.168.2.2383.222.199.28
                                                Jan 19, 2025 06:02:56.633740902 CET135663319883.222.93.228192.168.2.23
                                                Jan 19, 2025 06:02:56.633761883 CET135664199683.222.110.84192.168.2.23
                                                Jan 19, 2025 06:02:56.633765936 CET4084413566192.168.2.2383.222.167.34
                                                Jan 19, 2025 06:02:56.633776903 CET135664176283.222.31.67192.168.2.23
                                                Jan 19, 2025 06:02:56.633790970 CET135665471883.222.242.183192.168.2.23
                                                Jan 19, 2025 06:02:56.633805037 CET135663404483.222.213.24192.168.2.23
                                                Jan 19, 2025 06:02:56.633805990 CET4199613566192.168.2.2383.222.110.84
                                                Jan 19, 2025 06:02:56.633817911 CET135664595083.222.39.108192.168.2.23
                                                Jan 19, 2025 06:02:56.633831978 CET3404413566192.168.2.2383.222.213.24
                                                Jan 19, 2025 06:02:56.633867979 CET3319813566192.168.2.2383.222.93.228
                                                Jan 19, 2025 06:02:56.633888006 CET4176213566192.168.2.2383.222.31.67
                                                Jan 19, 2025 06:02:56.633883953 CET4046013566192.168.2.2383.222.206.100
                                                Jan 19, 2025 06:02:56.633884907 CET5471813566192.168.2.2383.222.242.183
                                                Jan 19, 2025 06:02:56.633953094 CET5260413566192.168.2.2383.222.132.243
                                                Jan 19, 2025 06:02:56.633953094 CET4595013566192.168.2.2383.222.39.108
                                                Jan 19, 2025 06:02:56.634160995 CET135663316283.222.24.252192.168.2.23
                                                Jan 19, 2025 06:02:56.634176016 CET135665588683.222.111.126192.168.2.23
                                                Jan 19, 2025 06:02:56.634191036 CET135664844083.222.4.90192.168.2.23
                                                Jan 19, 2025 06:02:56.634200096 CET3316213566192.168.2.2383.222.24.252
                                                Jan 19, 2025 06:02:56.634203911 CET135663467083.222.190.70192.168.2.23
                                                Jan 19, 2025 06:02:56.634211063 CET135664911283.222.8.82192.168.2.23
                                                Jan 19, 2025 06:02:56.634217024 CET135664736683.222.235.251192.168.2.23
                                                Jan 19, 2025 06:02:56.634222984 CET5588613566192.168.2.2383.222.111.126
                                                Jan 19, 2025 06:02:56.634231091 CET135665275483.222.96.67192.168.2.23
                                                Jan 19, 2025 06:02:56.634252071 CET4911213566192.168.2.2383.222.8.82
                                                Jan 19, 2025 06:02:56.634253025 CET3467013566192.168.2.2383.222.190.70
                                                Jan 19, 2025 06:02:56.634258032 CET135663954483.222.251.119192.168.2.23
                                                Jan 19, 2025 06:02:56.634253025 CET4844013566192.168.2.2383.222.4.90
                                                Jan 19, 2025 06:02:56.634253025 CET4736613566192.168.2.2383.222.235.251
                                                Jan 19, 2025 06:02:56.634274960 CET5275413566192.168.2.2383.222.96.67
                                                Jan 19, 2025 06:02:56.634278059 CET135664196483.222.166.26192.168.2.23
                                                Jan 19, 2025 06:02:56.634291887 CET135665471483.222.186.43192.168.2.23
                                                Jan 19, 2025 06:02:56.634305954 CET135664727483.222.13.130192.168.2.23
                                                Jan 19, 2025 06:02:56.634315014 CET3954413566192.168.2.2383.222.251.119
                                                Jan 19, 2025 06:02:56.634315014 CET4196413566192.168.2.2383.222.166.26
                                                Jan 19, 2025 06:02:56.634320974 CET135664679083.222.71.125192.168.2.23
                                                Jan 19, 2025 06:02:56.634335995 CET135663732483.222.0.75192.168.2.23
                                                Jan 19, 2025 06:02:56.634336948 CET5471413566192.168.2.2383.222.186.43
                                                Jan 19, 2025 06:02:56.634341002 CET4727413566192.168.2.2383.222.13.130
                                                Jan 19, 2025 06:02:56.634351015 CET135664631283.222.156.230192.168.2.23
                                                Jan 19, 2025 06:02:56.634356022 CET4679013566192.168.2.2383.222.71.125
                                                Jan 19, 2025 06:02:56.634365082 CET135665767083.222.100.52192.168.2.23
                                                Jan 19, 2025 06:02:56.634371042 CET3732413566192.168.2.2383.222.0.75
                                                Jan 19, 2025 06:02:56.634381056 CET135663990083.222.185.34192.168.2.23
                                                Jan 19, 2025 06:02:56.634390116 CET4631213566192.168.2.2383.222.156.230
                                                Jan 19, 2025 06:02:56.634401083 CET135664163283.222.122.164192.168.2.23
                                                Jan 19, 2025 06:02:56.634411097 CET5767013566192.168.2.2383.222.100.52
                                                Jan 19, 2025 06:02:56.634418964 CET3990013566192.168.2.2383.222.185.34
                                                Jan 19, 2025 06:02:56.634424925 CET135664111883.222.16.53192.168.2.23
                                                Jan 19, 2025 06:02:56.634438038 CET135663363083.222.27.254192.168.2.23
                                                Jan 19, 2025 06:02:56.634443045 CET4163213566192.168.2.2383.222.122.164
                                                Jan 19, 2025 06:02:56.634453058 CET135664264883.222.158.172192.168.2.23
                                                Jan 19, 2025 06:02:56.634466887 CET4111813566192.168.2.2383.222.16.53
                                                Jan 19, 2025 06:02:56.634474039 CET3363013566192.168.2.2383.222.27.254
                                                Jan 19, 2025 06:02:56.634480953 CET135665619283.222.215.213192.168.2.23
                                                Jan 19, 2025 06:02:56.634495020 CET135665240683.222.29.162192.168.2.23
                                                Jan 19, 2025 06:02:56.634507895 CET135664391683.222.80.234192.168.2.23
                                                Jan 19, 2025 06:02:56.634507895 CET4264813566192.168.2.2383.222.158.172
                                                Jan 19, 2025 06:02:56.634522915 CET5619213566192.168.2.2383.222.215.213
                                                Jan 19, 2025 06:02:56.634522915 CET5240613566192.168.2.2383.222.29.162
                                                Jan 19, 2025 06:02:56.634535074 CET135664748283.222.239.36192.168.2.23
                                                Jan 19, 2025 06:02:56.634548903 CET135664199683.222.155.246192.168.2.23
                                                Jan 19, 2025 06:02:56.634558916 CET4391613566192.168.2.2383.222.80.234
                                                Jan 19, 2025 06:02:56.634565115 CET135664650483.222.33.18192.168.2.23
                                                Jan 19, 2025 06:02:56.634568930 CET4748213566192.168.2.2383.222.239.36
                                                Jan 19, 2025 06:02:56.634577036 CET4199613566192.168.2.2383.222.155.246
                                                Jan 19, 2025 06:02:56.634594917 CET135665748483.222.5.85192.168.2.23
                                                Jan 19, 2025 06:02:56.634602070 CET4650413566192.168.2.2383.222.33.18
                                                Jan 19, 2025 06:02:56.634608984 CET135666056083.222.215.105192.168.2.23
                                                Jan 19, 2025 06:02:56.634624004 CET135665627083.222.143.215192.168.2.23
                                                Jan 19, 2025 06:02:56.634635925 CET5748413566192.168.2.2383.222.5.85
                                                Jan 19, 2025 06:02:56.634639025 CET135664129283.222.180.102192.168.2.23
                                                Jan 19, 2025 06:02:56.634646893 CET6056013566192.168.2.2383.222.215.105
                                                Jan 19, 2025 06:02:56.634653091 CET135664475483.222.154.101192.168.2.23
                                                Jan 19, 2025 06:02:56.634658098 CET5627013566192.168.2.2383.222.143.215
                                                Jan 19, 2025 06:02:56.634665966 CET135663409883.222.172.24192.168.2.23
                                                Jan 19, 2025 06:02:56.634676933 CET4129213566192.168.2.2383.222.180.102
                                                Jan 19, 2025 06:02:56.634680033 CET135665529283.222.9.88192.168.2.23
                                                Jan 19, 2025 06:02:56.634685040 CET4475413566192.168.2.2383.222.154.101
                                                Jan 19, 2025 06:02:56.634695053 CET135664350283.222.58.21192.168.2.23
                                                Jan 19, 2025 06:02:56.634701967 CET3409813566192.168.2.2383.222.172.24
                                                Jan 19, 2025 06:02:56.634710073 CET135663644083.222.141.85192.168.2.23
                                                Jan 19, 2025 06:02:56.634713888 CET5529213566192.168.2.2383.222.9.88
                                                Jan 19, 2025 06:02:56.634723902 CET135664993283.222.183.25192.168.2.23
                                                Jan 19, 2025 06:02:56.634737015 CET4350213566192.168.2.2383.222.58.21
                                                Jan 19, 2025 06:02:56.634738922 CET135664341283.222.197.169192.168.2.23
                                                Jan 19, 2025 06:02:56.634742022 CET3644013566192.168.2.2383.222.141.85
                                                Jan 19, 2025 06:02:56.634752035 CET135665270283.222.83.181192.168.2.23
                                                Jan 19, 2025 06:02:56.634759903 CET4993213566192.168.2.2383.222.183.25
                                                Jan 19, 2025 06:02:56.634767056 CET135664934683.222.205.163192.168.2.23
                                                Jan 19, 2025 06:02:56.634771109 CET4341213566192.168.2.2383.222.197.169
                                                Jan 19, 2025 06:02:56.634779930 CET135663536883.222.159.104192.168.2.23
                                                Jan 19, 2025 06:02:56.634790897 CET5270213566192.168.2.2383.222.83.181
                                                Jan 19, 2025 06:02:56.634793997 CET135665552683.222.153.164192.168.2.23
                                                Jan 19, 2025 06:02:56.634807110 CET135665558683.222.183.149192.168.2.23
                                                Jan 19, 2025 06:02:56.634819031 CET4934613566192.168.2.2383.222.205.163
                                                Jan 19, 2025 06:02:56.634819031 CET3536813566192.168.2.2383.222.159.104
                                                Jan 19, 2025 06:02:56.634834051 CET135665524283.222.189.187192.168.2.23
                                                Jan 19, 2025 06:02:56.634835005 CET5552613566192.168.2.2383.222.153.164
                                                Jan 19, 2025 06:02:56.634835005 CET5558613566192.168.2.2383.222.183.149
                                                Jan 19, 2025 06:02:56.634849072 CET135665902483.222.108.216192.168.2.23
                                                Jan 19, 2025 06:02:56.634865046 CET135663863483.222.36.70192.168.2.23
                                                Jan 19, 2025 06:02:56.634875059 CET5524213566192.168.2.2383.222.189.187
                                                Jan 19, 2025 06:02:56.634880066 CET5902413566192.168.2.2383.222.108.216
                                                Jan 19, 2025 06:02:56.634891033 CET135664606883.222.173.25192.168.2.23
                                                Jan 19, 2025 06:02:56.634907961 CET3863413566192.168.2.2383.222.36.70
                                                Jan 19, 2025 06:02:56.634922981 CET4606813566192.168.2.2383.222.173.25
                                                Jan 19, 2025 06:02:56.639130116 CET4266013566192.168.2.2383.222.191.90
                                                Jan 19, 2025 06:02:56.644016027 CET135664266083.222.191.90192.168.2.23
                                                Jan 19, 2025 06:02:56.644078970 CET4266013566192.168.2.2383.222.191.90
                                                Jan 19, 2025 06:02:56.644112110 CET4266013566192.168.2.2383.222.191.90
                                                Jan 19, 2025 06:02:56.648942947 CET135664266083.222.191.90192.168.2.23
                                                Jan 19, 2025 06:02:56.648994923 CET4266013566192.168.2.2383.222.191.90
                                                Jan 19, 2025 06:02:56.653811932 CET135664266083.222.191.90192.168.2.23
                                                Jan 19, 2025 06:02:59.467628956 CET42836443192.168.2.2391.189.91.43
                                                Jan 19, 2025 06:03:00.235387087 CET4251680192.168.2.23109.202.202.202
                                                Jan 19, 2025 06:03:06.650204897 CET4266013566192.168.2.2383.222.191.90
                                                Jan 19, 2025 06:03:06.655555010 CET135664266083.222.191.90192.168.2.23
                                                Jan 19, 2025 06:03:06.858498096 CET135664266083.222.191.90192.168.2.23
                                                Jan 19, 2025 06:03:06.858799934 CET4266013566192.168.2.2383.222.191.90
                                                Jan 19, 2025 06:03:07.239099026 CET135664266083.222.191.90192.168.2.23
                                                Jan 19, 2025 06:03:07.239358902 CET4266013566192.168.2.2383.222.191.90
                                                Jan 19, 2025 06:03:15.593333006 CET43928443192.168.2.2391.189.91.42
                                                Jan 19, 2025 06:03:25.831928968 CET42836443192.168.2.2391.189.91.43
                                                Jan 19, 2025 06:03:29.927190065 CET4251680192.168.2.23109.202.202.202
                                                Jan 19, 2025 06:03:41.615077019 CET4266013566192.168.2.2383.222.191.90
                                                Jan 19, 2025 06:03:41.622569084 CET135664266083.222.191.90192.168.2.23
                                                Jan 19, 2025 06:03:41.622663021 CET4266013566192.168.2.2383.222.191.90
                                                Jan 19, 2025 06:03:56.547600031 CET43928443192.168.2.2391.189.91.42
                                                TimestampSource PortDest PortSource IPDest IP
                                                Jan 19, 2025 06:02:56.629162073 CET3773053192.168.2.238.8.8.8
                                                Jan 19, 2025 06:02:56.639035940 CET53377308.8.8.8192.168.2.23
                                                TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                                Jan 19, 2025 06:02:56.629162073 CET192.168.2.238.8.8.80xaccStandard query (0)secure-network-rebirthltd.ruA (IP address)IN (0x0001)false
                                                TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                                Jan 19, 2025 06:02:56.639035940 CET8.8.8.8192.168.2.230xaccNo error (0)secure-network-rebirthltd.ru83.222.191.90A (IP address)IN (0x0001)false

                                                System Behavior

                                                Start time (UTC):05:02:55
                                                Start date (UTC):19/01/2025
                                                Path:/tmp/dbg.x86.elf
                                                Arguments:/tmp/dbg.x86.elf
                                                File size:54416 bytes
                                                MD5 hash:2280f52b2b40424d0a9fec0670ee06c5