Edit tour

Linux Analysis Report
193.124.44.77-x86-2025-02-05T21_50_26.elf

Overview

General Information

Sample name:193.124.44.77-x86-2025-02-05T21_50_26.elf
Analysis ID:1610714
MD5:1f36f66b6964f5f125b356ea14527437
SHA1:c77ecd12efb3fa2d01dd4794410114613494134b
SHA256:5f8efb6e6e0b582872c9e124c22c9168b07ee9543215fd125352b63bd65a43a9
Tags:elfuser-threatquery
Infos:

Detection

Score:60
Range:0 - 100

Signatures

Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Machine Learning detection for sample
Detected TCP or UDP traffic on non-standard ports
Enumerates processes within the "proc" file system
Found strings indicative of a multi-platform dropper
Sample has stripped symbol table
Yara signature match

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
Joe Sandbox version:42.0.0 Malachite
Analysis ID:1610714
Start date and time:2025-02-10 00:46:17 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 18s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:193.124.44.77-x86-2025-02-05T21_50_26.elf
Detection:MAL
Classification:mal60.linELF@0/0@0/0
Command:/tmp/193.124.44.77-x86-2025-02-05T21_50_26.elf
PID:5488
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
a cat is fine too
Standard Error:
  • system is lnxubuntu20
  • cleanup
SourceRuleDescriptionAuthorStrings
193.124.44.77-x86-2025-02-05T21_50_26.elfLinux_Trojan_Mirai_b14f4c5dunknownunknown
  • 0x33b0:$a: 53 31 DB 8B 4C 24 0C 8B 54 24 08 83 F9 01 76 15 66 8B 02 83 E9 02 25 FF FF 00 00 83 C2 02 01 C3 83 F9 01 77 EB 49 75 05 0F BE 02 01 C3
193.124.44.77-x86-2025-02-05T21_50_26.elfLinux_Trojan_Mirai_88de437funknownunknown
  • 0x4c42:$a: 24 08 8B 4C 24 04 85 D2 74 0D 31 C0 89 F6 C6 04 08 00 40 39 D0
193.124.44.77-x86-2025-02-05T21_50_26.elfLinux_Trojan_Mirai_ae9d0fa6unknownunknown
  • 0x192:$a: 83 EC 04 8A 44 24 18 8B 5C 24 14 88 44 24 03 8A 44 24 10 25 FF 00
193.124.44.77-x86-2025-02-05T21_50_26.elfLinux_Trojan_Mirai_389ee3e9unknownunknown
  • 0x7dee:$a: 89 45 00 EB 2C 8B 4B 04 8B 13 8B 7B 18 8B 01 01 02 8B 02 83
193.124.44.77-x86-2025-02-05T21_50_26.elfLinux_Trojan_Mirai_cc93863bunknownunknown
  • 0x664f:$a: C3 57 8B 44 24 0C 8B 4C 24 10 8B 7C 24 08 F3 AA 8B 44 24 08
Click to see the 1 entries
SourceRuleDescriptionAuthorStrings
5488.1.0000000008048000.0000000008053000.r-x.sdmpLinux_Trojan_Mirai_b14f4c5dunknownunknown
  • 0x33b0:$a: 53 31 DB 8B 4C 24 0C 8B 54 24 08 83 F9 01 76 15 66 8B 02 83 E9 02 25 FF FF 00 00 83 C2 02 01 C3 83 F9 01 77 EB 49 75 05 0F BE 02 01 C3
5488.1.0000000008048000.0000000008053000.r-x.sdmpLinux_Trojan_Mirai_88de437funknownunknown
  • 0x4c42:$a: 24 08 8B 4C 24 04 85 D2 74 0D 31 C0 89 F6 C6 04 08 00 40 39 D0
5488.1.0000000008048000.0000000008053000.r-x.sdmpLinux_Trojan_Mirai_ae9d0fa6unknownunknown
  • 0x192:$a: 83 EC 04 8A 44 24 18 8B 5C 24 14 88 44 24 03 8A 44 24 10 25 FF 00
5488.1.0000000008048000.0000000008053000.r-x.sdmpLinux_Trojan_Mirai_389ee3e9unknownunknown
  • 0x7dee:$a: 89 45 00 EB 2C 8B 4B 04 8B 13 8B 7B 18 8B 01 01 02 8B 02 83
5488.1.0000000008048000.0000000008053000.r-x.sdmpLinux_Trojan_Mirai_cc93863bunknownunknown
  • 0x664f:$a: C3 57 8B 44 24 0C 8B 4C 24 10 8B 7C 24 08 F3 AA 8B 44 24 08
Click to see the 1 entries
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: 193.124.44.77-x86-2025-02-05T21_50_26.elfVirustotal: Detection: 14%Perma Link
Source: 193.124.44.77-x86-2025-02-05T21_50_26.elfReversingLabs: Detection: 28%
Source: 193.124.44.77-x86-2025-02-05T21_50_26.elfJoe Sandbox ML: detected
Source: 193.124.44.77-x86-2025-02-05T21_50_26.elfString: (deleted)/proc/self/exe/proc//proc/proc/%s/cmdlineerrwgetcurltftpftpget. sleep 1/sbin/procd/sbin/klogd/sbin/auditd/bin/ExHttpd[kworker/0:0]
Source: global trafficTCP traffic: 192.168.2.14:35834 -> 156.229.232.154:51325
Source: unknownTCP traffic detected without corresponding DNS query: 156.229.232.154
Source: unknownTCP traffic detected without corresponding DNS query: 156.229.232.154
Source: unknownTCP traffic detected without corresponding DNS query: 156.229.232.154
Source: unknownTCP traffic detected without corresponding DNS query: 156.229.232.154
Source: unknownTCP traffic detected without corresponding DNS query: 156.229.232.154
Source: unknownTCP traffic detected without corresponding DNS query: 156.229.232.154
Source: unknownTCP traffic detected without corresponding DNS query: 156.229.232.154
Source: unknownTCP traffic detected without corresponding DNS query: 156.229.232.154
Source: unknownTCP traffic detected without corresponding DNS query: 156.229.232.154
Source: unknownTCP traffic detected without corresponding DNS query: 156.229.232.154
Source: unknownTCP traffic detected without corresponding DNS query: 156.229.232.154
Source: unknownTCP traffic detected without corresponding DNS query: 156.229.232.154
Source: unknownTCP traffic detected without corresponding DNS query: 156.229.232.154
Source: unknownTCP traffic detected without corresponding DNS query: 156.229.232.154
Source: unknownTCP traffic detected without corresponding DNS query: 156.229.232.154
Source: unknownTCP traffic detected without corresponding DNS query: 156.229.232.154
Source: unknownTCP traffic detected without corresponding DNS query: 156.229.232.154
Source: unknownTCP traffic detected without corresponding DNS query: 156.229.232.154
Source: unknownTCP traffic detected without corresponding DNS query: 156.229.232.154
Source: unknownTCP traffic detected without corresponding DNS query: 156.229.232.154
Source: unknownTCP traffic detected without corresponding DNS query: 156.229.232.154
Source: unknownTCP traffic detected without corresponding DNS query: 156.229.232.154
Source: unknownTCP traffic detected without corresponding DNS query: 156.229.232.154
Source: unknownTCP traffic detected without corresponding DNS query: 156.229.232.154
Source: unknownTCP traffic detected without corresponding DNS query: 156.229.232.154
Source: unknownTCP traffic detected without corresponding DNS query: 156.229.232.154
Source: unknownTCP traffic detected without corresponding DNS query: 156.229.232.154
Source: unknownTCP traffic detected without corresponding DNS query: 156.229.232.154
Source: unknownTCP traffic detected without corresponding DNS query: 156.229.232.154
Source: unknownTCP traffic detected without corresponding DNS query: 156.229.232.154
Source: unknownTCP traffic detected without corresponding DNS query: 156.229.232.154
Source: unknownTCP traffic detected without corresponding DNS query: 156.229.232.154
Source: unknownTCP traffic detected without corresponding DNS query: 156.229.232.154
Source: unknownTCP traffic detected without corresponding DNS query: 156.229.232.154
Source: unknownTCP traffic detected without corresponding DNS query: 156.229.232.154
Source: unknownTCP traffic detected without corresponding DNS query: 156.229.232.154
Source: unknownTCP traffic detected without corresponding DNS query: 156.229.232.154
Source: unknownTCP traffic detected without corresponding DNS query: 156.229.232.154
Source: unknownTCP traffic detected without corresponding DNS query: 156.229.232.154
Source: unknownTCP traffic detected without corresponding DNS query: 156.229.232.154
Source: unknownTCP traffic detected without corresponding DNS query: 156.229.232.154
Source: unknownTCP traffic detected without corresponding DNS query: 156.229.232.154
Source: unknownTCP traffic detected without corresponding DNS query: 156.229.232.154
Source: unknownTCP traffic detected without corresponding DNS query: 156.229.232.154
Source: unknownTCP traffic detected without corresponding DNS query: 156.229.232.154
Source: unknownTCP traffic detected without corresponding DNS query: 156.229.232.154
Source: unknownTCP traffic detected without corresponding DNS query: 156.229.232.154
Source: unknownTCP traffic detected without corresponding DNS query: 156.229.232.154
Source: unknownTCP traffic detected without corresponding DNS query: 156.229.232.154
Source: unknownTCP traffic detected without corresponding DNS query: 156.229.232.154

System Summary

barindex
Source: 193.124.44.77-x86-2025-02-05T21_50_26.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_b14f4c5d Author: unknown
Source: 193.124.44.77-x86-2025-02-05T21_50_26.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_88de437f Author: unknown
Source: 193.124.44.77-x86-2025-02-05T21_50_26.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_ae9d0fa6 Author: unknown
Source: 193.124.44.77-x86-2025-02-05T21_50_26.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_389ee3e9 Author: unknown
Source: 193.124.44.77-x86-2025-02-05T21_50_26.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_cc93863b Author: unknown
Source: 193.124.44.77-x86-2025-02-05T21_50_26.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_8aa7b5d3 Author: unknown
Source: 5488.1.0000000008048000.0000000008053000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_b14f4c5d Author: unknown
Source: 5488.1.0000000008048000.0000000008053000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_88de437f Author: unknown
Source: 5488.1.0000000008048000.0000000008053000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_ae9d0fa6 Author: unknown
Source: 5488.1.0000000008048000.0000000008053000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_389ee3e9 Author: unknown
Source: 5488.1.0000000008048000.0000000008053000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_cc93863b Author: unknown
Source: 5488.1.0000000008048000.0000000008053000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_8aa7b5d3 Author: unknown
Source: ELF static info symbol of initial sample.symtab present: no
Source: 193.124.44.77-x86-2025-02-05T21_50_26.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_b14f4c5d os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = a70d052918dd2fbc66db241da6438015130f0fb6929229bfe573546fe98da817, id = b14f4c5d-054f-46e6-9fa8-3588f1ef68b7, last_modified = 2021-09-16
Source: 193.124.44.77-x86-2025-02-05T21_50_26.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_88de437f reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = c19eb595c2b444a809bef8500c20342c9f46694d3018e268833f9b884133a1ea, id = 88de437f-9c98-4e1d-96c0-7b433c99886a, last_modified = 2021-09-16
Source: 193.124.44.77-x86-2025-02-05T21_50_26.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_ae9d0fa6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = ca2bf2771844bec95563800d19a35dd230413f8eff0bd44c8ab0b4c596f81bfc, id = ae9d0fa6-be06-4656-9b13-8edfc0ee9e71, last_modified = 2021-09-16
Source: 193.124.44.77-x86-2025-02-05T21_50_26.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_389ee3e9 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 59f2359dc1f41d385d639d157b4cd9fc73d76d8abb7cc09d47632bb4c9a39e6e, id = 389ee3e9-70c1-4c93-a999-292cf6ff1652, last_modified = 2022-01-26
Source: 193.124.44.77-x86-2025-02-05T21_50_26.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_cc93863b reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = f3ecd30f0b511a8e92cfa642409d559e7612c3f57a1659ca46c77aca809a00ac, id = cc93863b-1050-40ba-9d02-5ec9ce6a3a28, last_modified = 2022-01-26
Source: 193.124.44.77-x86-2025-02-05T21_50_26.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_8aa7b5d3 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 02a2c18c362df4b1fceb33f3b605586514ba9a00c7afedf71c04fa54d8146444, id = 8aa7b5d3-e1eb-4b55-b36a-0d3a242c06e9, last_modified = 2022-01-26
Source: 5488.1.0000000008048000.0000000008053000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_b14f4c5d os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = a70d052918dd2fbc66db241da6438015130f0fb6929229bfe573546fe98da817, id = b14f4c5d-054f-46e6-9fa8-3588f1ef68b7, last_modified = 2021-09-16
Source: 5488.1.0000000008048000.0000000008053000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_88de437f reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = c19eb595c2b444a809bef8500c20342c9f46694d3018e268833f9b884133a1ea, id = 88de437f-9c98-4e1d-96c0-7b433c99886a, last_modified = 2021-09-16
Source: 5488.1.0000000008048000.0000000008053000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_ae9d0fa6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = ca2bf2771844bec95563800d19a35dd230413f8eff0bd44c8ab0b4c596f81bfc, id = ae9d0fa6-be06-4656-9b13-8edfc0ee9e71, last_modified = 2021-09-16
Source: 5488.1.0000000008048000.0000000008053000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_389ee3e9 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 59f2359dc1f41d385d639d157b4cd9fc73d76d8abb7cc09d47632bb4c9a39e6e, id = 389ee3e9-70c1-4c93-a999-292cf6ff1652, last_modified = 2022-01-26
Source: 5488.1.0000000008048000.0000000008053000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_cc93863b reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = f3ecd30f0b511a8e92cfa642409d559e7612c3f57a1659ca46c77aca809a00ac, id = cc93863b-1050-40ba-9d02-5ec9ce6a3a28, last_modified = 2022-01-26
Source: 5488.1.0000000008048000.0000000008053000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_8aa7b5d3 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 02a2c18c362df4b1fceb33f3b605586514ba9a00c7afedf71c04fa54d8146444, id = 8aa7b5d3-e1eb-4b55-b36a-0d3a242c06e9, last_modified = 2022-01-26
Source: classification engineClassification label: mal60.linELF@0/0@0/0
Source: /tmp/193.124.44.77-x86-2025-02-05T21_50_26.elf (PID: 5490)File opened: /proc/3760/cmdlineJump to behavior
Source: /tmp/193.124.44.77-x86-2025-02-05T21_50_26.elf (PID: 5490)File opened: /proc/3761/cmdlineJump to behavior
Source: /tmp/193.124.44.77-x86-2025-02-05T21_50_26.elf (PID: 5490)File opened: /proc/1583/cmdlineJump to behavior
Source: /tmp/193.124.44.77-x86-2025-02-05T21_50_26.elf (PID: 5490)File opened: /proc/2672/cmdlineJump to behavior
Source: /tmp/193.124.44.77-x86-2025-02-05T21_50_26.elf (PID: 5490)File opened: /proc/110/cmdlineJump to behavior
Source: /tmp/193.124.44.77-x86-2025-02-05T21_50_26.elf (PID: 5490)File opened: /proc/3759/cmdlineJump to behavior
Source: /tmp/193.124.44.77-x86-2025-02-05T21_50_26.elf (PID: 5490)File opened: /proc/111/cmdlineJump to behavior
Source: /tmp/193.124.44.77-x86-2025-02-05T21_50_26.elf (PID: 5490)File opened: /proc/112/cmdlineJump to behavior
Source: /tmp/193.124.44.77-x86-2025-02-05T21_50_26.elf (PID: 5490)File opened: /proc/234/cmdlineJump to behavior
Source: /tmp/193.124.44.77-x86-2025-02-05T21_50_26.elf (PID: 5490)File opened: /proc/113/cmdlineJump to behavior
Source: /tmp/193.124.44.77-x86-2025-02-05T21_50_26.elf (PID: 5490)File opened: /proc/1577/cmdlineJump to behavior
Source: /tmp/193.124.44.77-x86-2025-02-05T21_50_26.elf (PID: 5490)File opened: /proc/235/cmdlineJump to behavior
Source: /tmp/193.124.44.77-x86-2025-02-05T21_50_26.elf (PID: 5490)File opened: /proc/114/cmdlineJump to behavior
Source: /tmp/193.124.44.77-x86-2025-02-05T21_50_26.elf (PID: 5490)File opened: /proc/115/cmdlineJump to behavior
Source: /tmp/193.124.44.77-x86-2025-02-05T21_50_26.elf (PID: 5490)File opened: /proc/116/cmdlineJump to behavior
Source: /tmp/193.124.44.77-x86-2025-02-05T21_50_26.elf (PID: 5490)File opened: /proc/117/cmdlineJump to behavior
Source: /tmp/193.124.44.77-x86-2025-02-05T21_50_26.elf (PID: 5490)File opened: /proc/118/cmdlineJump to behavior
Source: /tmp/193.124.44.77-x86-2025-02-05T21_50_26.elf (PID: 5490)File opened: /proc/119/cmdlineJump to behavior
Source: /tmp/193.124.44.77-x86-2025-02-05T21_50_26.elf (PID: 5490)File opened: /proc/917/cmdlineJump to behavior
Source: /tmp/193.124.44.77-x86-2025-02-05T21_50_26.elf (PID: 5490)File opened: /proc/1593/cmdlineJump to behavior
Source: /tmp/193.124.44.77-x86-2025-02-05T21_50_26.elf (PID: 5490)File opened: /proc/240/cmdlineJump to behavior
Source: /tmp/193.124.44.77-x86-2025-02-05T21_50_26.elf (PID: 5490)File opened: /proc/120/cmdlineJump to behavior
Source: /tmp/193.124.44.77-x86-2025-02-05T21_50_26.elf (PID: 5490)File opened: /proc/3094/cmdlineJump to behavior
Source: /tmp/193.124.44.77-x86-2025-02-05T21_50_26.elf (PID: 5490)File opened: /proc/242/cmdlineJump to behavior
Source: /tmp/193.124.44.77-x86-2025-02-05T21_50_26.elf (PID: 5490)File opened: /proc/121/cmdlineJump to behavior
Source: /tmp/193.124.44.77-x86-2025-02-05T21_50_26.elf (PID: 5490)File opened: /proc/3406/cmdlineJump to behavior
Source: /tmp/193.124.44.77-x86-2025-02-05T21_50_26.elf (PID: 5490)File opened: /proc/243/cmdlineJump to behavior
Source: /tmp/193.124.44.77-x86-2025-02-05T21_50_26.elf (PID: 5490)File opened: /proc/122/cmdlineJump to behavior
Source: /tmp/193.124.44.77-x86-2025-02-05T21_50_26.elf (PID: 5490)File opened: /proc/244/cmdlineJump to behavior
Source: /tmp/193.124.44.77-x86-2025-02-05T21_50_26.elf (PID: 5490)File opened: /proc/123/cmdlineJump to behavior
Source: /tmp/193.124.44.77-x86-2025-02-05T21_50_26.elf (PID: 5490)File opened: /proc/1589/cmdlineJump to behavior
Source: /tmp/193.124.44.77-x86-2025-02-05T21_50_26.elf (PID: 5490)File opened: /proc/245/cmdlineJump to behavior
Source: /tmp/193.124.44.77-x86-2025-02-05T21_50_26.elf (PID: 5490)File opened: /proc/124/cmdlineJump to behavior
Source: /tmp/193.124.44.77-x86-2025-02-05T21_50_26.elf (PID: 5490)File opened: /proc/1588/cmdlineJump to behavior
Source: /tmp/193.124.44.77-x86-2025-02-05T21_50_26.elf (PID: 5490)File opened: /proc/125/cmdlineJump to behavior
Source: /tmp/193.124.44.77-x86-2025-02-05T21_50_26.elf (PID: 5490)File opened: /proc/246/cmdlineJump to behavior
Source: /tmp/193.124.44.77-x86-2025-02-05T21_50_26.elf (PID: 5490)File opened: /proc/3402/cmdlineJump to behavior
Source: /tmp/193.124.44.77-x86-2025-02-05T21_50_26.elf (PID: 5490)File opened: /proc/126/cmdlineJump to behavior
Source: /tmp/193.124.44.77-x86-2025-02-05T21_50_26.elf (PID: 5490)File opened: /proc/247/cmdlineJump to behavior
Source: /tmp/193.124.44.77-x86-2025-02-05T21_50_26.elf (PID: 5490)File opened: /proc/127/cmdlineJump to behavior
Source: /tmp/193.124.44.77-x86-2025-02-05T21_50_26.elf (PID: 5490)File opened: /proc/248/cmdlineJump to behavior
Source: /tmp/193.124.44.77-x86-2025-02-05T21_50_26.elf (PID: 5490)File opened: /proc/128/cmdlineJump to behavior
Source: /tmp/193.124.44.77-x86-2025-02-05T21_50_26.elf (PID: 5490)File opened: /proc/249/cmdlineJump to behavior
Source: /tmp/193.124.44.77-x86-2025-02-05T21_50_26.elf (PID: 5490)File opened: /proc/800/cmdlineJump to behavior
Source: /tmp/193.124.44.77-x86-2025-02-05T21_50_26.elf (PID: 5490)File opened: /proc/129/cmdlineJump to behavior
Source: /tmp/193.124.44.77-x86-2025-02-05T21_50_26.elf (PID: 5490)File opened: /proc/3762/cmdlineJump to behavior
Source: /tmp/193.124.44.77-x86-2025-02-05T21_50_26.elf (PID: 5490)File opened: /proc/801/cmdlineJump to behavior
Source: /tmp/193.124.44.77-x86-2025-02-05T21_50_26.elf (PID: 5490)File opened: /proc/803/cmdlineJump to behavior
Source: /tmp/193.124.44.77-x86-2025-02-05T21_50_26.elf (PID: 5490)File opened: /proc/806/cmdlineJump to behavior
Source: /tmp/193.124.44.77-x86-2025-02-05T21_50_26.elf (PID: 5490)File opened: /proc/807/cmdlineJump to behavior
Source: /tmp/193.124.44.77-x86-2025-02-05T21_50_26.elf (PID: 5490)File opened: /proc/928/cmdlineJump to behavior
Source: /tmp/193.124.44.77-x86-2025-02-05T21_50_26.elf (PID: 5490)File opened: /proc/3420/cmdlineJump to behavior
Source: /tmp/193.124.44.77-x86-2025-02-05T21_50_26.elf (PID: 5490)File opened: /proc/490/cmdlineJump to behavior
Source: /tmp/193.124.44.77-x86-2025-02-05T21_50_26.elf (PID: 5490)File opened: /proc/250/cmdlineJump to behavior
Source: /tmp/193.124.44.77-x86-2025-02-05T21_50_26.elf (PID: 5490)File opened: /proc/130/cmdlineJump to behavior
Source: /tmp/193.124.44.77-x86-2025-02-05T21_50_26.elf (PID: 5490)File opened: /proc/251/cmdlineJump to behavior
Source: /tmp/193.124.44.77-x86-2025-02-05T21_50_26.elf (PID: 5490)File opened: /proc/131/cmdlineJump to behavior
Source: /tmp/193.124.44.77-x86-2025-02-05T21_50_26.elf (PID: 5490)File opened: /proc/252/cmdlineJump to behavior
Source: /tmp/193.124.44.77-x86-2025-02-05T21_50_26.elf (PID: 5490)File opened: /proc/132/cmdlineJump to behavior
Source: /tmp/193.124.44.77-x86-2025-02-05T21_50_26.elf (PID: 5490)File opened: /proc/253/cmdlineJump to behavior
Source: /tmp/193.124.44.77-x86-2025-02-05T21_50_26.elf (PID: 5490)File opened: /proc/254/cmdlineJump to behavior
Source: /tmp/193.124.44.77-x86-2025-02-05T21_50_26.elf (PID: 5490)File opened: /proc/255/cmdlineJump to behavior
Source: /tmp/193.124.44.77-x86-2025-02-05T21_50_26.elf (PID: 5490)File opened: /proc/135/cmdlineJump to behavior
Source: /tmp/193.124.44.77-x86-2025-02-05T21_50_26.elf (PID: 5490)File opened: /proc/256/cmdlineJump to behavior
Source: /tmp/193.124.44.77-x86-2025-02-05T21_50_26.elf (PID: 5490)File opened: /proc/1599/cmdlineJump to behavior
Source: /tmp/193.124.44.77-x86-2025-02-05T21_50_26.elf (PID: 5490)File opened: /proc/257/cmdlineJump to behavior
Source: /tmp/193.124.44.77-x86-2025-02-05T21_50_26.elf (PID: 5490)File opened: /proc/378/cmdlineJump to behavior
Source: /tmp/193.124.44.77-x86-2025-02-05T21_50_26.elf (PID: 5490)File opened: /proc/258/cmdlineJump to behavior
Source: /tmp/193.124.44.77-x86-2025-02-05T21_50_26.elf (PID: 5490)File opened: /proc/3412/cmdlineJump to behavior
Source: /tmp/193.124.44.77-x86-2025-02-05T21_50_26.elf (PID: 5490)File opened: /proc/259/cmdlineJump to behavior
Source: /tmp/193.124.44.77-x86-2025-02-05T21_50_26.elf (PID: 5490)File opened: /proc/1371/cmdlineJump to behavior
Source: /tmp/193.124.44.77-x86-2025-02-05T21_50_26.elf (PID: 5490)File opened: /proc/260/cmdlineJump to behavior
Source: /tmp/193.124.44.77-x86-2025-02-05T21_50_26.elf (PID: 5490)File opened: /proc/261/cmdlineJump to behavior
Source: /tmp/193.124.44.77-x86-2025-02-05T21_50_26.elf (PID: 5490)File opened: /proc/262/cmdlineJump to behavior
Source: /tmp/193.124.44.77-x86-2025-02-05T21_50_26.elf (PID: 5490)File opened: /proc/263/cmdlineJump to behavior
Source: /tmp/193.124.44.77-x86-2025-02-05T21_50_26.elf (PID: 5490)File opened: /proc/142/cmdlineJump to behavior
Source: /tmp/193.124.44.77-x86-2025-02-05T21_50_26.elf (PID: 5490)File opened: /proc/264/cmdlineJump to behavior
Source: /tmp/193.124.44.77-x86-2025-02-05T21_50_26.elf (PID: 5490)File opened: /proc/265/cmdlineJump to behavior
Source: /tmp/193.124.44.77-x86-2025-02-05T21_50_26.elf (PID: 5490)File opened: /proc/145/cmdlineJump to behavior
Source: /tmp/193.124.44.77-x86-2025-02-05T21_50_26.elf (PID: 5490)File opened: /proc/266/cmdlineJump to behavior
Source: /tmp/193.124.44.77-x86-2025-02-05T21_50_26.elf (PID: 5490)File opened: /proc/1369/cmdlineJump to behavior
Source: /tmp/193.124.44.77-x86-2025-02-05T21_50_26.elf (PID: 5490)File opened: /proc/267/cmdlineJump to behavior
Source: /tmp/193.124.44.77-x86-2025-02-05T21_50_26.elf (PID: 5490)File opened: /proc/3304/cmdlineJump to behavior
Source: /tmp/193.124.44.77-x86-2025-02-05T21_50_26.elf (PID: 5490)File opened: /proc/3425/cmdlineJump to behavior
Source: /tmp/193.124.44.77-x86-2025-02-05T21_50_26.elf (PID: 5490)File opened: /proc/268/cmdlineJump to behavior
Source: /tmp/193.124.44.77-x86-2025-02-05T21_50_26.elf (PID: 5490)File opened: /proc/269/cmdlineJump to behavior
Source: /tmp/193.124.44.77-x86-2025-02-05T21_50_26.elf (PID: 5490)File opened: /proc/940/cmdlineJump to behavior
Source: /tmp/193.124.44.77-x86-2025-02-05T21_50_26.elf (PID: 5490)File opened: /proc/941/cmdlineJump to behavior
Source: /tmp/193.124.44.77-x86-2025-02-05T21_50_26.elf (PID: 5490)File opened: /proc/1364/cmdlineJump to behavior
Source: /tmp/193.124.44.77-x86-2025-02-05T21_50_26.elf (PID: 5490)File opened: /proc/1383/cmdlineJump to behavior
Source: /tmp/193.124.44.77-x86-2025-02-05T21_50_26.elf (PID: 5490)File opened: /proc/270/cmdlineJump to behavior
Source: /tmp/193.124.44.77-x86-2025-02-05T21_50_26.elf (PID: 5490)File opened: /proc/1382/cmdlineJump to behavior
Source: /tmp/193.124.44.77-x86-2025-02-05T21_50_26.elf (PID: 5490)File opened: /proc/271/cmdlineJump to behavior
Source: /tmp/193.124.44.77-x86-2025-02-05T21_50_26.elf (PID: 5490)File opened: /proc/1381/cmdlineJump to behavior
Source: /tmp/193.124.44.77-x86-2025-02-05T21_50_26.elf (PID: 5490)File opened: /proc/272/cmdlineJump to behavior
Source: /tmp/193.124.44.77-x86-2025-02-05T21_50_26.elf (PID: 5490)File opened: /proc/273/cmdlineJump to behavior
Source: /tmp/193.124.44.77-x86-2025-02-05T21_50_26.elf (PID: 5490)File opened: /proc/274/cmdlineJump to behavior
Source: /tmp/193.124.44.77-x86-2025-02-05T21_50_26.elf (PID: 5490)File opened: /proc/275/cmdlineJump to behavior
Source: /tmp/193.124.44.77-x86-2025-02-05T21_50_26.elf (PID: 5490)File opened: /proc/276/cmdlineJump to behavior
Source: /tmp/193.124.44.77-x86-2025-02-05T21_50_26.elf (PID: 5490)File opened: /proc/277/cmdlineJump to behavior
Source: /tmp/193.124.44.77-x86-2025-02-05T21_50_26.elf (PID: 5490)File opened: /proc/278/cmdlineJump to behavior
Source: /tmp/193.124.44.77-x86-2025-02-05T21_50_26.elf (PID: 5490)File opened: /proc/279/cmdlineJump to behavior
Source: /tmp/193.124.44.77-x86-2025-02-05T21_50_26.elf (PID: 5490)File opened: /proc/158/cmdlineJump to behavior
Source: /tmp/193.124.44.77-x86-2025-02-05T21_50_26.elf (PID: 5490)File opened: /proc/3319/cmdlineJump to behavior
Source: /tmp/193.124.44.77-x86-2025-02-05T21_50_26.elf (PID: 5490)File opened: /proc/280/cmdlineJump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity Information1
Scripting
Valid AccountsWindows Management Instrumentation1
Scripting
Path InterceptionDirect Volume Access1
OS Credential Dumping
System Service DiscoveryRemote ServicesData from Local System1
Non-Standard Port
Exfiltration Over Other Network MediumAbuse Accessibility Features
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1610714 Sample: 193.124.44.77-x86-2025-02-0... Startdate: 10/02/2025 Architecture: LINUX Score: 60 14 156.229.232.154, 35834, 35836, 35838 ONL-HKOCEANNETWORKLIMITEDHK Seychelles 2->14 16 Malicious sample detected (through community Yara rule) 2->16 18 Multi AV Scanner detection for submitted file 2->18 20 Machine Learning detection for sample 2->20 8 193.124.44.77-x86-2025-02-05T21_50_26.elf 2->8         started        signatures3 process4 process5 10 193.124.44.77-x86-2025-02-05T21_50_26.elf 8->10         started        process6 12 193.124.44.77-x86-2025-02-05T21_50_26.elf 10->12         started       
SourceDetectionScannerLabelLink
193.124.44.77-x86-2025-02-05T21_50_26.elf14%VirustotalBrowse
193.124.44.77-x86-2025-02-05T21_50_26.elf29%ReversingLabsLinux.Trojan.Mirai
193.124.44.77-x86-2025-02-05T21_50_26.elf100%Joe Sandbox ML
No Antivirus matches
No Antivirus matches
No Antivirus matches

Download Network PCAP: filteredfull

No contacted domains info
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs
IPDomainCountryFlagASNASN NameMalicious
156.229.232.154
unknownSeychelles
139086ONL-HKOCEANNETWORKLIMITEDHKfalse
No context
No context
MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
ONL-HKOCEANNETWORKLIMITEDHK70j7mEj30N.exeGet hashmaliciousAsyncRAT, VenomRATBrowse
  • 45.202.32.101
SecuriteInfo.com.ELF.DDOSAgent-BT.21277.30452.elfGet hashmaliciousUnknownBrowse
  • 156.229.232.67
SecuriteInfo.com.ELF.DDOSAgent-BT.26540.24716.elfGet hashmaliciousUnknownBrowse
  • 156.229.232.67
main-linux-arm-5.elfGet hashmaliciousUnknownBrowse
  • 156.229.232.67
main-linux-ppc64le.elfGet hashmaliciousUnknownBrowse
  • 156.229.232.67
arm7.elfGet hashmaliciousMiraiBrowse
  • 156.229.232.99
arm5.elfGet hashmaliciousUnknownBrowse
  • 156.229.232.99
rep.arm5.elfGet hashmaliciousUnknownBrowse
  • 156.229.232.99
rep.m68k.elfGet hashmaliciousUnknownBrowse
  • 156.229.232.99
rep.arm7.elfGet hashmaliciousMiraiBrowse
  • 156.229.232.99
No context
No context
No created / dropped files found
File type:ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, stripped
Entropy (8bit):6.483600949740501
TrID:
  • ELF Executable and Linkable format (Linux) (4029/14) 50.16%
  • ELF Executable and Linkable format (generic) (4004/1) 49.84%
File name:193.124.44.77-x86-2025-02-05T21_50_26.elf
File size:46'320 bytes
MD5:1f36f66b6964f5f125b356ea14527437
SHA1:c77ecd12efb3fa2d01dd4794410114613494134b
SHA256:5f8efb6e6e0b582872c9e124c22c9168b07ee9543215fd125352b63bd65a43a9
SHA512:1db4329f88f5053fe64c8fbff67f993ac53c5ec51e82d2906e63f6aeecadddcfb6cb04fad987a24d430be3bd049780de77cef476a1e03bdcd7dba6971105354d
SSDEEP:768:m710UcwFh1MfYW4xsXq8PInYmR+stDsp31Yad4qXyZlT7vTuq/M8+akmIXg:I1dcwCfYWw/8wrksVSFLiZlX77/SakmU
TLSH:7B236CC99A43E4F5EC1B05752177EB729632E5B90035EE83C368EA32ED53A10D72728C
File Content Preview:.ELF....................d...4...`.......4. ...(.....................<...<....................0...0.. ....h..........Q.td............................U..S.......w....h........[]...$.............U......= 3...t..5....$0.....$0......u........t....h</..........

ELF header

Class:ELF32
Data:2's complement, little endian
Version:1 (current)
Machine:Intel 80386
Version Number:0x1
Type:EXEC (Executable file)
OS/ABI:UNIX - System V
ABI Version:0
Entry Point Address:0x8048164
Flags:0x0
ELF Header Size:52
Program Header Offset:52
Program Header Size:32
Number of Program Headers:3
Section Header Offset:45920
Section Header Size:40
Number of Section Headers:10
Header String Table Index:9
NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
NULL0x00x00x00x00x0000
.initPROGBITS0x80480940x940x1c0x00x6AX001
.textPROGBITS0x80480b00xb00x99260x00x6AX0016
.finiPROGBITS0x80519d60x99d60x170x00x6AX001
.rodataPROGBITS0x8051a000x9a000x153c0x00x2A0032
.ctorsPROGBITS0x80530000xb0000x80x00x3WA004
.dtorsPROGBITS0x80530080xb0080x80x00x3WA004
.dataPROGBITS0x80530200xb0200x3000x00x3WA0032
.bssNOBITS0x80533200xb3200x64e00x00x3WA0032
.shstrtabSTRTAB0x00xb3200x3e0x00x0001
TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
LOAD0x00x80480000x80480000xaf3c0xaf3c6.53960x5R E0x1000.init .text .fini .rodata
LOAD0xb0000x80530000x80530000x3200x68004.39060x6RW 0x1000.ctors .dtors .data .bss
GNU_STACK0x00x00x00x00x00.00000x6RW 0x4

Download Network PCAP: filteredfull

TimestampSource PortDest PortSource IPDest IP
Feb 10, 2025 00:47:04.481633902 CET3583451325192.168.2.14156.229.232.154
Feb 10, 2025 00:47:04.486483097 CET5132535834156.229.232.154192.168.2.14
Feb 10, 2025 00:47:04.486534119 CET3583451325192.168.2.14156.229.232.154
Feb 10, 2025 00:47:04.486565113 CET3583451325192.168.2.14156.229.232.154
Feb 10, 2025 00:47:04.491322994 CET5132535834156.229.232.154192.168.2.14
Feb 10, 2025 00:47:04.491391897 CET3583451325192.168.2.14156.229.232.154
Feb 10, 2025 00:47:04.496165991 CET5132535834156.229.232.154192.168.2.14
Feb 10, 2025 00:47:05.151801109 CET5132535834156.229.232.154192.168.2.14
Feb 10, 2025 00:47:05.151904106 CET3583451325192.168.2.14156.229.232.154
Feb 10, 2025 00:47:05.158871889 CET5132535834156.229.232.154192.168.2.14
Feb 10, 2025 00:47:06.152885914 CET3583651325192.168.2.14156.229.232.154
Feb 10, 2025 00:47:06.157763958 CET5132535836156.229.232.154192.168.2.14
Feb 10, 2025 00:47:06.157819986 CET3583651325192.168.2.14156.229.232.154
Feb 10, 2025 00:47:06.157855034 CET3583651325192.168.2.14156.229.232.154
Feb 10, 2025 00:47:06.162633896 CET5132535836156.229.232.154192.168.2.14
Feb 10, 2025 00:47:06.162671089 CET3583651325192.168.2.14156.229.232.154
Feb 10, 2025 00:47:06.167525053 CET5132535836156.229.232.154192.168.2.14
Feb 10, 2025 00:47:06.801752090 CET5132535836156.229.232.154192.168.2.14
Feb 10, 2025 00:47:06.801819086 CET3583651325192.168.2.14156.229.232.154
Feb 10, 2025 00:47:06.809815884 CET5132535836156.229.232.154192.168.2.14
Feb 10, 2025 00:47:07.802978992 CET3583851325192.168.2.14156.229.232.154
Feb 10, 2025 00:47:07.807903051 CET5132535838156.229.232.154192.168.2.14
Feb 10, 2025 00:47:07.807976961 CET3583851325192.168.2.14156.229.232.154
Feb 10, 2025 00:47:07.808007956 CET3583851325192.168.2.14156.229.232.154
Feb 10, 2025 00:47:07.812827110 CET5132535838156.229.232.154192.168.2.14
Feb 10, 2025 00:47:07.812885046 CET3583851325192.168.2.14156.229.232.154
Feb 10, 2025 00:47:07.817683935 CET5132535838156.229.232.154192.168.2.14
Feb 10, 2025 00:47:08.444240093 CET5132535838156.229.232.154192.168.2.14
Feb 10, 2025 00:47:08.444324017 CET3583851325192.168.2.14156.229.232.154
Feb 10, 2025 00:47:08.449600935 CET5132535838156.229.232.154192.168.2.14
Feb 10, 2025 00:47:09.447259903 CET3584051325192.168.2.14156.229.232.154
Feb 10, 2025 00:47:09.454329967 CET5132535840156.229.232.154192.168.2.14
Feb 10, 2025 00:47:09.454417944 CET3584051325192.168.2.14156.229.232.154
Feb 10, 2025 00:47:09.454417944 CET3584051325192.168.2.14156.229.232.154
Feb 10, 2025 00:47:09.459209919 CET5132535840156.229.232.154192.168.2.14
Feb 10, 2025 00:47:09.459255934 CET3584051325192.168.2.14156.229.232.154
Feb 10, 2025 00:47:09.464076042 CET5132535840156.229.232.154192.168.2.14
Feb 10, 2025 00:47:10.098985910 CET5132535840156.229.232.154192.168.2.14
Feb 10, 2025 00:47:10.099112034 CET3584051325192.168.2.14156.229.232.154
Feb 10, 2025 00:47:10.104103088 CET5132535840156.229.232.154192.168.2.14
Feb 10, 2025 00:47:11.100225925 CET3584251325192.168.2.14156.229.232.154
Feb 10, 2025 00:47:11.105092049 CET5132535842156.229.232.154192.168.2.14
Feb 10, 2025 00:47:11.105189085 CET3584251325192.168.2.14156.229.232.154
Feb 10, 2025 00:47:11.105216980 CET3584251325192.168.2.14156.229.232.154
Feb 10, 2025 00:47:11.109956026 CET5132535842156.229.232.154192.168.2.14
Feb 10, 2025 00:47:11.110008001 CET3584251325192.168.2.14156.229.232.154
Feb 10, 2025 00:47:11.114846945 CET5132535842156.229.232.154192.168.2.14
Feb 10, 2025 00:47:11.750693083 CET5132535842156.229.232.154192.168.2.14
Feb 10, 2025 00:47:11.750865936 CET3584251325192.168.2.14156.229.232.154
Feb 10, 2025 00:47:11.755855083 CET5132535842156.229.232.154192.168.2.14
Feb 10, 2025 00:47:12.751991034 CET3584451325192.168.2.14156.229.232.154
Feb 10, 2025 00:47:12.756886959 CET5132535844156.229.232.154192.168.2.14
Feb 10, 2025 00:47:12.756987095 CET3584451325192.168.2.14156.229.232.154
Feb 10, 2025 00:47:12.757035971 CET3584451325192.168.2.14156.229.232.154
Feb 10, 2025 00:47:12.761825085 CET5132535844156.229.232.154192.168.2.14
Feb 10, 2025 00:47:12.761873007 CET3584451325192.168.2.14156.229.232.154
Feb 10, 2025 00:47:12.766675949 CET5132535844156.229.232.154192.168.2.14
Feb 10, 2025 00:47:13.389211893 CET5132535844156.229.232.154192.168.2.14
Feb 10, 2025 00:47:13.389312029 CET3584451325192.168.2.14156.229.232.154
Feb 10, 2025 00:47:13.394140959 CET5132535844156.229.232.154192.168.2.14
Feb 10, 2025 00:47:14.389988899 CET3584651325192.168.2.14156.229.232.154
Feb 10, 2025 00:47:14.394902945 CET5132535846156.229.232.154192.168.2.14
Feb 10, 2025 00:47:14.394968987 CET3584651325192.168.2.14156.229.232.154
Feb 10, 2025 00:47:14.394994020 CET3584651325192.168.2.14156.229.232.154
Feb 10, 2025 00:47:14.399828911 CET5132535846156.229.232.154192.168.2.14
Feb 10, 2025 00:47:14.399873972 CET3584651325192.168.2.14156.229.232.154
Feb 10, 2025 00:47:14.404638052 CET5132535846156.229.232.154192.168.2.14
Feb 10, 2025 00:47:15.022800922 CET5132535846156.229.232.154192.168.2.14
Feb 10, 2025 00:47:15.022917032 CET3584651325192.168.2.14156.229.232.154
Feb 10, 2025 00:47:15.028901100 CET5132535846156.229.232.154192.168.2.14
Feb 10, 2025 00:47:16.023822069 CET3584851325192.168.2.14156.229.232.154
Feb 10, 2025 00:47:16.028780937 CET5132535848156.229.232.154192.168.2.14
Feb 10, 2025 00:47:16.028846979 CET3584851325192.168.2.14156.229.232.154
Feb 10, 2025 00:47:16.028882027 CET3584851325192.168.2.14156.229.232.154
Feb 10, 2025 00:47:16.033701897 CET5132535848156.229.232.154192.168.2.14
Feb 10, 2025 00:47:16.033778906 CET3584851325192.168.2.14156.229.232.154
Feb 10, 2025 00:47:16.038533926 CET5132535848156.229.232.154192.168.2.14
Feb 10, 2025 00:47:16.652761936 CET5132535848156.229.232.154192.168.2.14
Feb 10, 2025 00:47:16.652995110 CET3584851325192.168.2.14156.229.232.154
Feb 10, 2025 00:47:16.657871008 CET5132535848156.229.232.154192.168.2.14
Feb 10, 2025 00:47:17.654069901 CET3585051325192.168.2.14156.229.232.154
Feb 10, 2025 00:47:17.659718037 CET5132535850156.229.232.154192.168.2.14
Feb 10, 2025 00:47:17.659802914 CET3585051325192.168.2.14156.229.232.154
Feb 10, 2025 00:47:17.659847021 CET3585051325192.168.2.14156.229.232.154
Feb 10, 2025 00:47:17.665379047 CET5132535850156.229.232.154192.168.2.14
Feb 10, 2025 00:47:17.665425062 CET3585051325192.168.2.14156.229.232.154
Feb 10, 2025 00:47:17.670973063 CET5132535850156.229.232.154192.168.2.14
Feb 10, 2025 00:47:18.293560028 CET5132535850156.229.232.154192.168.2.14
Feb 10, 2025 00:47:18.293725967 CET3585051325192.168.2.14156.229.232.154
Feb 10, 2025 00:47:18.298557997 CET5132535850156.229.232.154192.168.2.14
Feb 10, 2025 00:47:19.294640064 CET3585251325192.168.2.14156.229.232.154
Feb 10, 2025 00:47:19.300867081 CET5132535852156.229.232.154192.168.2.14
Feb 10, 2025 00:47:19.300950050 CET3585251325192.168.2.14156.229.232.154
Feb 10, 2025 00:47:19.301048040 CET3585251325192.168.2.14156.229.232.154
Feb 10, 2025 00:47:19.306942940 CET5132535852156.229.232.154192.168.2.14
Feb 10, 2025 00:47:19.307018995 CET3585251325192.168.2.14156.229.232.154
Feb 10, 2025 00:47:19.312191963 CET5132535852156.229.232.154192.168.2.14
Feb 10, 2025 00:47:20.008214951 CET5132535852156.229.232.154192.168.2.14
Feb 10, 2025 00:47:20.008382082 CET3585251325192.168.2.14156.229.232.154
Feb 10, 2025 00:47:20.013276100 CET5132535852156.229.232.154192.168.2.14
Feb 10, 2025 00:47:21.009510994 CET3585451325192.168.2.14156.229.232.154
Feb 10, 2025 00:47:21.017493010 CET5132535854156.229.232.154192.168.2.14
Feb 10, 2025 00:47:21.017612934 CET3585451325192.168.2.14156.229.232.154
Feb 10, 2025 00:47:21.017627954 CET3585451325192.168.2.14156.229.232.154
Feb 10, 2025 00:47:21.025605917 CET5132535854156.229.232.154192.168.2.14
Feb 10, 2025 00:47:21.025665045 CET3585451325192.168.2.14156.229.232.154
Feb 10, 2025 00:47:21.033590078 CET5132535854156.229.232.154192.168.2.14
Feb 10, 2025 00:47:21.651106119 CET5132535854156.229.232.154192.168.2.14
Feb 10, 2025 00:47:21.651268005 CET3585451325192.168.2.14156.229.232.154
Feb 10, 2025 00:47:21.656106949 CET5132535854156.229.232.154192.168.2.14
Feb 10, 2025 00:47:22.652138948 CET3585651325192.168.2.14156.229.232.154
Feb 10, 2025 00:47:22.659377098 CET5132535856156.229.232.154192.168.2.14
Feb 10, 2025 00:47:22.659465075 CET3585651325192.168.2.14156.229.232.154
Feb 10, 2025 00:47:22.659506083 CET3585651325192.168.2.14156.229.232.154
Feb 10, 2025 00:47:22.666305065 CET5132535856156.229.232.154192.168.2.14
Feb 10, 2025 00:47:22.666383982 CET3585651325192.168.2.14156.229.232.154
Feb 10, 2025 00:47:22.672755957 CET5132535856156.229.232.154192.168.2.14
Feb 10, 2025 00:47:23.305078983 CET5132535856156.229.232.154192.168.2.14
Feb 10, 2025 00:47:23.305268049 CET3585651325192.168.2.14156.229.232.154
Feb 10, 2025 00:47:23.312129021 CET5132535856156.229.232.154192.168.2.14
Feb 10, 2025 00:47:24.306227922 CET3585851325192.168.2.14156.229.232.154
Feb 10, 2025 00:47:24.314102888 CET5132535858156.229.232.154192.168.2.14
Feb 10, 2025 00:47:24.314166069 CET3585851325192.168.2.14156.229.232.154
Feb 10, 2025 00:47:24.314199924 CET3585851325192.168.2.14156.229.232.154
Feb 10, 2025 00:47:24.319958925 CET5132535858156.229.232.154192.168.2.14
Feb 10, 2025 00:47:24.320004940 CET3585851325192.168.2.14156.229.232.154
Feb 10, 2025 00:47:24.328772068 CET5132535858156.229.232.154192.168.2.14
Feb 10, 2025 00:47:24.951706886 CET5132535858156.229.232.154192.168.2.14
Feb 10, 2025 00:47:24.951970100 CET3585851325192.168.2.14156.229.232.154
Feb 10, 2025 00:47:24.957568884 CET5132535858156.229.232.154192.168.2.14
Feb 10, 2025 00:47:25.952799082 CET3586051325192.168.2.14156.229.232.154
Feb 10, 2025 00:47:25.957964897 CET5132535860156.229.232.154192.168.2.14
Feb 10, 2025 00:47:25.958036900 CET3586051325192.168.2.14156.229.232.154
Feb 10, 2025 00:47:25.958070993 CET3586051325192.168.2.14156.229.232.154
Feb 10, 2025 00:47:25.962857962 CET5132535860156.229.232.154192.168.2.14
Feb 10, 2025 00:47:25.962904930 CET3586051325192.168.2.14156.229.232.154
Feb 10, 2025 00:47:25.968039036 CET5132535860156.229.232.154192.168.2.14
Feb 10, 2025 00:47:26.583147049 CET5132535860156.229.232.154192.168.2.14
Feb 10, 2025 00:47:26.583262920 CET3586051325192.168.2.14156.229.232.154
Feb 10, 2025 00:47:26.589378119 CET5132535860156.229.232.154192.168.2.14
Feb 10, 2025 00:47:27.584481955 CET3586251325192.168.2.14156.229.232.154
Feb 10, 2025 00:47:27.590264082 CET5132535862156.229.232.154192.168.2.14
Feb 10, 2025 00:47:27.590322971 CET3586251325192.168.2.14156.229.232.154
Feb 10, 2025 00:47:27.590358973 CET3586251325192.168.2.14156.229.232.154
Feb 10, 2025 00:47:27.596441984 CET5132535862156.229.232.154192.168.2.14
Feb 10, 2025 00:47:27.596513033 CET3586251325192.168.2.14156.229.232.154
Feb 10, 2025 00:47:27.601340055 CET5132535862156.229.232.154192.168.2.14
Feb 10, 2025 00:47:28.215188980 CET5132535862156.229.232.154192.168.2.14
Feb 10, 2025 00:47:28.215301037 CET3586251325192.168.2.14156.229.232.154
Feb 10, 2025 00:47:28.220087051 CET5132535862156.229.232.154192.168.2.14
Feb 10, 2025 00:47:29.216463089 CET3586451325192.168.2.14156.229.232.154
Feb 10, 2025 00:47:29.221340895 CET5132535864156.229.232.154192.168.2.14
Feb 10, 2025 00:47:29.221429110 CET3586451325192.168.2.14156.229.232.154
Feb 10, 2025 00:47:29.221461058 CET3586451325192.168.2.14156.229.232.154
Feb 10, 2025 00:47:29.226174116 CET5132535864156.229.232.154192.168.2.14
Feb 10, 2025 00:47:29.226237059 CET3586451325192.168.2.14156.229.232.154
Feb 10, 2025 00:47:29.231004953 CET5132535864156.229.232.154192.168.2.14
Feb 10, 2025 00:47:29.866704941 CET5132535864156.229.232.154192.168.2.14
Feb 10, 2025 00:47:29.866856098 CET3586451325192.168.2.14156.229.232.154
Feb 10, 2025 00:47:29.871608973 CET5132535864156.229.232.154192.168.2.14
Feb 10, 2025 00:47:30.868148088 CET3586651325192.168.2.14156.229.232.154
Feb 10, 2025 00:47:30.874331951 CET5132535866156.229.232.154192.168.2.14
Feb 10, 2025 00:47:30.874468088 CET3586651325192.168.2.14156.229.232.154
Feb 10, 2025 00:47:30.874550104 CET3586651325192.168.2.14156.229.232.154
Feb 10, 2025 00:47:30.881238937 CET5132535866156.229.232.154192.168.2.14
Feb 10, 2025 00:47:30.881320953 CET3586651325192.168.2.14156.229.232.154
Feb 10, 2025 00:47:30.887917042 CET5132535866156.229.232.154192.168.2.14
Feb 10, 2025 00:47:33.013024092 CET5132535866156.229.232.154192.168.2.14
Feb 10, 2025 00:47:33.013175011 CET3586651325192.168.2.14156.229.232.154
Feb 10, 2025 00:47:33.017963886 CET5132535866156.229.232.154192.168.2.14
Feb 10, 2025 00:47:34.014703989 CET3586851325192.168.2.14156.229.232.154
Feb 10, 2025 00:47:34.019531965 CET5132535868156.229.232.154192.168.2.14
Feb 10, 2025 00:47:34.019613981 CET3586851325192.168.2.14156.229.232.154
Feb 10, 2025 00:47:34.019651890 CET3586851325192.168.2.14156.229.232.154
Feb 10, 2025 00:47:34.024409056 CET5132535868156.229.232.154192.168.2.14
Feb 10, 2025 00:47:34.024461985 CET3586851325192.168.2.14156.229.232.154
Feb 10, 2025 00:47:34.029280901 CET5132535868156.229.232.154192.168.2.14
Feb 10, 2025 00:47:34.642395020 CET5132535868156.229.232.154192.168.2.14
Feb 10, 2025 00:47:34.642710924 CET3586851325192.168.2.14156.229.232.154
Feb 10, 2025 00:47:34.647573948 CET5132535868156.229.232.154192.168.2.14
Feb 10, 2025 00:47:35.643717051 CET3587051325192.168.2.14156.229.232.154
Feb 10, 2025 00:47:35.648652077 CET5132535870156.229.232.154192.168.2.14
Feb 10, 2025 00:47:35.648735046 CET3587051325192.168.2.14156.229.232.154
Feb 10, 2025 00:47:35.648773909 CET3587051325192.168.2.14156.229.232.154
Feb 10, 2025 00:47:35.653543949 CET5132535870156.229.232.154192.168.2.14
Feb 10, 2025 00:47:35.653609991 CET3587051325192.168.2.14156.229.232.154
Feb 10, 2025 00:47:35.658404112 CET5132535870156.229.232.154192.168.2.14
Feb 10, 2025 00:47:45.651390076 CET3587051325192.168.2.14156.229.232.154
Feb 10, 2025 00:47:45.659210920 CET5132535870156.229.232.154192.168.2.14
Feb 10, 2025 00:47:45.848018885 CET5132535870156.229.232.154192.168.2.14
Feb 10, 2025 00:47:45.848129988 CET3587051325192.168.2.14156.229.232.154
Feb 10, 2025 00:48:45.892472982 CET3587051325192.168.2.14156.229.232.154
Feb 10, 2025 00:48:45.898076057 CET5132535870156.229.232.154192.168.2.14
Feb 10, 2025 00:48:46.082976103 CET5132535870156.229.232.154192.168.2.14
Feb 10, 2025 00:48:46.083091021 CET3587051325192.168.2.14156.229.232.154

System Behavior

Start time (UTC):23:47:03
Start date (UTC):09/02/2025
Path:/tmp/193.124.44.77-x86-2025-02-05T21_50_26.elf
Arguments:/tmp/193.124.44.77-x86-2025-02-05T21_50_26.elf
File size:46320 bytes
MD5 hash:1f36f66b6964f5f125b356ea14527437

Start time (UTC):23:47:03
Start date (UTC):09/02/2025
Path:/tmp/193.124.44.77-x86-2025-02-05T21_50_26.elf
Arguments:-
File size:46320 bytes
MD5 hash:1f36f66b6964f5f125b356ea14527437

Start time (UTC):23:47:03
Start date (UTC):09/02/2025
Path:/tmp/193.124.44.77-x86-2025-02-05T21_50_26.elf
Arguments:-
File size:46320 bytes
MD5 hash:1f36f66b6964f5f125b356ea14527437