Edit tour

Linux Analysis Report
morte.x64.elf

Overview

General Information

Sample name:morte.x64.elf
Analysis ID:1635850
MD5:0e1a6e4b683d30c8cf86c7322dec3e2c
SHA1:b0ed1d1ef04117b75ed1f6a15528302cf84b661c
SHA256:88573b0d51fab30e51d21dd9fb23541fe371f6604317d0bc3d5a71a7e3b6ba36
Tags:elfuser-abuse_ch
Infos:

Detection

Score:60
Range:0 - 100

Signatures

Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Sample is packed with UPX
Detected TCP or UDP traffic on non-standard ports
ELF contains segments with high entropy indicating compressed/encrypted content
Sample contains only a LOAD segment without any section mappings
Sample listens on a socket
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Yara signature match

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
Joe Sandbox version:42.0.0 Malachite
Analysis ID:1635850
Start date and time:2025-03-12 02:57:17 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 31s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:morte.x64.elf
Detection:MAL
Classification:mal60.evad.linELF@0/0@0/0
Command:/tmp/morte.x64.elf
PID:6223
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
lzrd cock fest"/proc/"/exe
Standard Error:
  • system is lnxubuntu20
  • morte.x64.elf (PID: 6223, Parent: 6149, MD5: 0e1a6e4b683d30c8cf86c7322dec3e2c) Arguments: /tmp/morte.x64.elf
  • cleanup
SourceRuleDescriptionAuthorStrings
6223.1.0000000000400000.0000000000416000.r-x.sdmpLinux_Trojan_Gafgyt_9e9530a7unknownunknown
  • 0xa4d8:$a: F6 48 63 FF B8 36 00 00 00 0F 05 48 3D 00 F0 FF FF 48 89 C3
6223.1.0000000000400000.0000000000416000.r-x.sdmpLinux_Trojan_Gafgyt_807911a2unknownunknown
  • 0xad4f:$a: FE 48 39 F3 0F 94 C2 48 83 F9 FF 0F 94 C0 84 D0 74 16 4B 8D
6223.1.0000000000400000.0000000000416000.r-x.sdmpLinux_Trojan_Gafgyt_d4227dbfunknownunknown
  • 0x8456:$a: FF 48 81 EC D0 00 00 00 48 8D 84 24 E0 00 00 00 48 89 54 24 30 C7 04 24 18 00
  • 0x8648:$a: FF 48 81 EC D0 00 00 00 48 8D 84 24 E0 00 00 00 48 89 54 24 30 C7 04 24 18 00
6223.1.0000000000400000.0000000000416000.r-x.sdmpLinux_Trojan_Gafgyt_d996d335unknownunknown
  • 0xd4de:$a: D0 EB 0F 40 38 37 75 04 48 89 F8 C3 49 FF C8 48 FF C7 4D 85 C0
6223.1.0000000000400000.0000000000416000.r-x.sdmpLinux_Trojan_Gafgyt_d0c57a2eunknownunknown
  • 0x12bc6:$a: 07 0F B6 57 01 C1 E0 08 09 D0 89 06 0F BE 47 02 C1 E8 1F 89
Click to see the 21 entries
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: morte.x64.elfVirustotal: Detection: 34%Perma Link
Source: morte.x64.elfReversingLabs: Detection: 31%
Source: global trafficTCP traffic: 192.168.2.23:57468 -> 176.65.134.62:7777
Source: /tmp/morte.x64.elf (PID: 6224)Socket: 127.0.0.1:25641Jump to behavior
Source: global trafficTCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
Source: global trafficTCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
Source: global trafficTCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.134.62
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.134.62
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.134.62
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.134.62
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.134.62
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.134.62
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.134.62
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.134.62
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.134.62
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.134.62
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.134.62
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.134.62
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.134.62
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.134.62
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.134.62
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.134.62
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.134.62
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.134.62
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.134.62
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.134.62
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.134.62
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.134.62
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.134.62
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.134.62
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.134.62
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.134.62
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.134.62
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.134.62
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.134.62
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.134.62
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.134.62
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.134.62
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.134.62
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.134.62
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.134.62
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.134.62
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.134.62
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.134.62
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.134.62
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.134.62
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.134.62
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.134.62
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.134.62
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.134.62
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.134.62
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.134.62
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.134.62
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.134.62
Source: morte.x64.elfString found in binary or memory: http://upx.sf.net
Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443

System Summary

barindex
Source: 6223.1.0000000000400000.0000000000416000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_9e9530a7 Author: unknown
Source: 6223.1.0000000000400000.0000000000416000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_807911a2 Author: unknown
Source: 6223.1.0000000000400000.0000000000416000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d4227dbf Author: unknown
Source: 6223.1.0000000000400000.0000000000416000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d996d335 Author: unknown
Source: 6223.1.0000000000400000.0000000000416000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d0c57a2e Author: unknown
Source: 6223.1.0000000000400000.0000000000416000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_620087b9 Author: unknown
Source: 6223.1.0000000000400000.0000000000416000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_0cd591cd Author: unknown
Source: 6223.1.0000000000400000.0000000000416000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_33b4111a Author: unknown
Source: 6223.1.0000000000400000.0000000000416000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a33a8363 Author: unknown
Source: 6223.1.0000000000400000.0000000000416000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_520deeb8 Author: unknown
Source: 6223.1.0000000000400000.0000000000416000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_6a77af0f Author: unknown
Source: 6223.1.0000000000400000.0000000000416000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_01e4a728 Author: unknown
Source: 6223.1.0000000000400000.0000000000416000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_e0cf29e2 Author: unknown
Source: 6225.1.0000000000400000.0000000000416000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_9e9530a7 Author: unknown
Source: 6225.1.0000000000400000.0000000000416000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_807911a2 Author: unknown
Source: 6225.1.0000000000400000.0000000000416000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d4227dbf Author: unknown
Source: 6225.1.0000000000400000.0000000000416000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d996d335 Author: unknown
Source: 6225.1.0000000000400000.0000000000416000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d0c57a2e Author: unknown
Source: 6225.1.0000000000400000.0000000000416000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_620087b9 Author: unknown
Source: 6225.1.0000000000400000.0000000000416000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_0cd591cd Author: unknown
Source: 6225.1.0000000000400000.0000000000416000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_33b4111a Author: unknown
Source: 6225.1.0000000000400000.0000000000416000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a33a8363 Author: unknown
Source: 6225.1.0000000000400000.0000000000416000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_520deeb8 Author: unknown
Source: 6225.1.0000000000400000.0000000000416000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_6a77af0f Author: unknown
Source: 6225.1.0000000000400000.0000000000416000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_01e4a728 Author: unknown
Source: 6225.1.0000000000400000.0000000000416000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_e0cf29e2 Author: unknown
Source: LOAD without section mappingsProgram segment: 0x100000
Source: 6223.1.0000000000400000.0000000000416000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_9e9530a7 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = d6ad6512051e87c8c35dc168d82edd071b122d026dce21d39b9782b3d6a01e50, id = 9e9530a7-ad4d-4a44-b764-437b7621052f, last_modified = 2021-09-16
Source: 6223.1.0000000000400000.0000000000416000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_807911a2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = f409037091b7372f5a42bbe437316bd11c655e7a5fe1fcf83d1981cb5c4a389f, id = 807911a2-f6ec-4e65-924f-61cb065dafc6, last_modified = 2021-09-16
Source: 6223.1.0000000000400000.0000000000416000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d4227dbf reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 58c4b1d4d167876b64cfa10f609911a80284180e4db093917fea16fae8ccd4e3, id = d4227dbf-6ab4-4637-a6ba-0e604acaafb4, last_modified = 2021-09-16
Source: 6223.1.0000000000400000.0000000000416000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d996d335 reference_sample = b511eacd4b44744c8cf82d1b4a9bc6f1022fe6be7c5d17356b171f727ddc6eda, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = e9ccb8412f32187c309b0e9afcc3a6da21ad2f1ffa251c27f9f720ccb284e3ac, id = d996d335-e049-4052-bf36-6cd07c911a8b, last_modified = 2021-09-16
Source: 6223.1.0000000000400000.0000000000416000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d0c57a2e os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 3ee7d3a33575ed3aa7431489a8fb18bf30cfd5d6c776066ab2a27f93303124b6, id = d0c57a2e-c10c-436c-be13-50a269326cf2, last_modified = 2021-09-16
Source: 6223.1.0000000000400000.0000000000416000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_620087b9 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 06cd7e6eb62352ec2ccb9ed48e58c0583c02fefd137cd048d053ab30b5330307, id = 620087b9-c87d-4752-89e8-ca1c16486b28, last_modified = 2021-09-16
Source: 6223.1.0000000000400000.0000000000416000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_0cd591cd os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 96c4ff70729ddb981adafd8c8277649a88a87e380d2f321dff53f0741675fb1b, id = 0cd591cd-c348-4c3a-a895-2063cf892cda, last_modified = 2021-09-16
Source: 6223.1.0000000000400000.0000000000416000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_33b4111a reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 9c3b63b9a0f54006bae12abcefdb518904a85f78be573f0780f0a265b12d2d6e, id = 33b4111a-e59e-48db-9d74-34ca44fcd9f5, last_modified = 2021-09-16
Source: 6223.1.0000000000400000.0000000000416000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a33a8363 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 74f964eaadbf8f30d40cdec40b603c5141135d2e658e7ce217d0d6c62e18dd08, id = a33a8363-5511-4fe1-a0d8-75156b9ccfc7, last_modified = 2021-09-16
Source: 6223.1.0000000000400000.0000000000416000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_520deeb8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = f4dfd1d76e07ff875eedfe0ef4f861bee1e4d8e66d68385f602f29cc35e30cca, id = 520deeb8-cbc0-4225-8d23-adba5e040471, last_modified = 2021-09-16
Source: 6223.1.0000000000400000.0000000000416000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_6a77af0f os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 4e436f509e7e732e3d0326bcbdde555bba0653213ddf31b43cfdfbe16abb0016, id = 6a77af0f-31fa-4793-82aa-10b065ba1ec0, last_modified = 2021-09-16
Source: 6223.1.0000000000400000.0000000000416000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_01e4a728 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = d90477364982bdc6cd22079c245d866454475749f762620273091f2fab73c196, id = 01e4a728-7c1c-479b-aed0-cb76d64dbb02, last_modified = 2021-09-16
Source: 6223.1.0000000000400000.0000000000416000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_e0cf29e2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 3f124c3c9f124264dfbbcca1e4b4d7cfcf3274170d4bf8966b6559045873948f, id = e0cf29e2-88d7-4aa4-b60a-c24626f2b246, last_modified = 2021-09-16
Source: 6225.1.0000000000400000.0000000000416000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_9e9530a7 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = d6ad6512051e87c8c35dc168d82edd071b122d026dce21d39b9782b3d6a01e50, id = 9e9530a7-ad4d-4a44-b764-437b7621052f, last_modified = 2021-09-16
Source: 6225.1.0000000000400000.0000000000416000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_807911a2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = f409037091b7372f5a42bbe437316bd11c655e7a5fe1fcf83d1981cb5c4a389f, id = 807911a2-f6ec-4e65-924f-61cb065dafc6, last_modified = 2021-09-16
Source: 6225.1.0000000000400000.0000000000416000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d4227dbf reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 58c4b1d4d167876b64cfa10f609911a80284180e4db093917fea16fae8ccd4e3, id = d4227dbf-6ab4-4637-a6ba-0e604acaafb4, last_modified = 2021-09-16
Source: 6225.1.0000000000400000.0000000000416000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d996d335 reference_sample = b511eacd4b44744c8cf82d1b4a9bc6f1022fe6be7c5d17356b171f727ddc6eda, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = e9ccb8412f32187c309b0e9afcc3a6da21ad2f1ffa251c27f9f720ccb284e3ac, id = d996d335-e049-4052-bf36-6cd07c911a8b, last_modified = 2021-09-16
Source: 6225.1.0000000000400000.0000000000416000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d0c57a2e os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 3ee7d3a33575ed3aa7431489a8fb18bf30cfd5d6c776066ab2a27f93303124b6, id = d0c57a2e-c10c-436c-be13-50a269326cf2, last_modified = 2021-09-16
Source: 6225.1.0000000000400000.0000000000416000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_620087b9 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 06cd7e6eb62352ec2ccb9ed48e58c0583c02fefd137cd048d053ab30b5330307, id = 620087b9-c87d-4752-89e8-ca1c16486b28, last_modified = 2021-09-16
Source: 6225.1.0000000000400000.0000000000416000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_0cd591cd os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 96c4ff70729ddb981adafd8c8277649a88a87e380d2f321dff53f0741675fb1b, id = 0cd591cd-c348-4c3a-a895-2063cf892cda, last_modified = 2021-09-16
Source: 6225.1.0000000000400000.0000000000416000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_33b4111a reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 9c3b63b9a0f54006bae12abcefdb518904a85f78be573f0780f0a265b12d2d6e, id = 33b4111a-e59e-48db-9d74-34ca44fcd9f5, last_modified = 2021-09-16
Source: 6225.1.0000000000400000.0000000000416000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a33a8363 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 74f964eaadbf8f30d40cdec40b603c5141135d2e658e7ce217d0d6c62e18dd08, id = a33a8363-5511-4fe1-a0d8-75156b9ccfc7, last_modified = 2021-09-16
Source: 6225.1.0000000000400000.0000000000416000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_520deeb8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = f4dfd1d76e07ff875eedfe0ef4f861bee1e4d8e66d68385f602f29cc35e30cca, id = 520deeb8-cbc0-4225-8d23-adba5e040471, last_modified = 2021-09-16
Source: 6225.1.0000000000400000.0000000000416000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_6a77af0f os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 4e436f509e7e732e3d0326bcbdde555bba0653213ddf31b43cfdfbe16abb0016, id = 6a77af0f-31fa-4793-82aa-10b065ba1ec0, last_modified = 2021-09-16
Source: 6225.1.0000000000400000.0000000000416000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_01e4a728 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = d90477364982bdc6cd22079c245d866454475749f762620273091f2fab73c196, id = 01e4a728-7c1c-479b-aed0-cb76d64dbb02, last_modified = 2021-09-16
Source: 6225.1.0000000000400000.0000000000416000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_e0cf29e2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 3f124c3c9f124264dfbbcca1e4b4d7cfcf3274170d4bf8966b6559045873948f, id = e0cf29e2-88d7-4aa4-b60a-c24626f2b246, last_modified = 2021-09-16
Source: classification engineClassification label: mal60.evad.linELF@0/0@0/0

Data Obfuscation

barindex
Source: initial sampleString containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $
Source: initial sampleString containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $
Source: initial sampleString containing UPX found: $Id: UPX 3.94 Copyright (C) 1996-2017 the UPX Team. All Rights Reserved. $
Source: morte.x64.elfSubmission file: segment LOAD with 7.9754 entropy (max. 8.0)
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception11
Obfuscated Files or Information
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Non-Standard Port
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1635850 Sample: morte.x64.elf Startdate: 12/03/2025 Architecture: LINUX Score: 60 14 109.202.202.202, 80 INIT7CH Switzerland 2->14 16 176.65.134.62, 57468, 57470, 57472 DIOGELO-ASGB Germany 2->16 18 2 other IPs or domains 2->18 20 Malicious sample detected (through community Yara rule) 2->20 22 Multi AV Scanner detection for submitted file 2->22 24 Sample is packed with UPX 2->24 8 morte.x64.elf 2->8         started        signatures3 process4 process5 10 morte.x64.elf 8->10         started        process6 12 morte.x64.elf 10->12         started       
SourceDetectionScannerLabelLink
morte.x64.elf34%VirustotalBrowse
morte.x64.elf32%ReversingLabsLinux.Backdoor.Mirai
No Antivirus matches
No Antivirus matches
No Antivirus matches

Download Network PCAP: filteredfull

No contacted domains info
NameSourceMaliciousAntivirus DetectionReputation
http://upx.sf.netmorte.x64.elffalse
    high
    • No. of IPs < 25%
    • 25% < No. of IPs < 50%
    • 50% < No. of IPs < 75%
    • 75% < No. of IPs
    IPDomainCountryFlagASNASN NameMalicious
    176.65.134.62
    unknownGermany
    56325DIOGELO-ASGBfalse
    109.202.202.202
    unknownSwitzerland
    13030INIT7CHfalse
    91.189.91.43
    unknownUnited Kingdom
    41231CANONICAL-ASGBfalse
    91.189.91.42
    unknownUnited Kingdom
    41231CANONICAL-ASGBfalse
    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
    176.65.134.62morte.m68k.elfGet hashmaliciousUnknownBrowse
      morte.mips.elfGet hashmaliciousUnknownBrowse
        morte.arm.elfGet hashmaliciousUnknownBrowse
          morte.x86.elfGet hashmaliciousUnknownBrowse
            morte.ppc.elfGet hashmaliciousUnknownBrowse
              morte.sh4.elfGet hashmaliciousUnknownBrowse
                morte.mpsl.elfGet hashmaliciousUnknownBrowse
                  morte.ppc.elfGet hashmaliciousUnknownBrowse
                    morte.arm.elfGet hashmaliciousUnknownBrowse
                      morte.mips.elfGet hashmaliciousUnknownBrowse
                        109.202.202.202kpLwzBouH4.elfGet hashmaliciousUnknownBrowse
                        • ch.archive.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_92.0%2bbuild3-0ubuntu0.20.04.1_amd64.deb
                        91.189.91.43morte.arm.elfGet hashmaliciousUnknownBrowse
                          re.bot.mips.elfGet hashmaliciousUnknownBrowse
                            morte.arm6.elfGet hashmaliciousUnknownBrowse
                              na.elfGet hashmaliciousPrometeiBrowse
                                demon.x86.elfGet hashmaliciousUnknownBrowse
                                  na.elfGet hashmaliciousPrometeiBrowse
                                    demon.x86.elfGet hashmaliciousUnknownBrowse
                                      demon.mips.elfGet hashmaliciousUnknownBrowse
                                        demon.arm7.elfGet hashmaliciousUnknownBrowse
                                          morte.ppc.elfGet hashmaliciousUnknownBrowse
                                            91.189.91.42morte.arm.elfGet hashmaliciousUnknownBrowse
                                              re.bot.mips.elfGet hashmaliciousUnknownBrowse
                                                morte.arm6.elfGet hashmaliciousUnknownBrowse
                                                  na.elfGet hashmaliciousPrometeiBrowse
                                                    demon.x86.elfGet hashmaliciousUnknownBrowse
                                                      na.elfGet hashmaliciousPrometeiBrowse
                                                        demon.x86.elfGet hashmaliciousUnknownBrowse
                                                          demon.mips.elfGet hashmaliciousUnknownBrowse
                                                            demon.arm7.elfGet hashmaliciousUnknownBrowse
                                                              morte.ppc.elfGet hashmaliciousUnknownBrowse
                                                                No context
                                                                MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                CANONICAL-ASGBmorte.arm.elfGet hashmaliciousUnknownBrowse
                                                                • 91.189.91.42
                                                                re.bot.mips.elfGet hashmaliciousUnknownBrowse
                                                                • 91.189.91.42
                                                                morte.arm6.elfGet hashmaliciousUnknownBrowse
                                                                • 91.189.91.42
                                                                na.elfGet hashmaliciousPrometeiBrowse
                                                                • 91.189.91.42
                                                                demon.x86.elfGet hashmaliciousUnknownBrowse
                                                                • 91.189.91.42
                                                                na.elfGet hashmaliciousPrometeiBrowse
                                                                • 91.189.91.42
                                                                demon.x86.elfGet hashmaliciousUnknownBrowse
                                                                • 91.189.91.42
                                                                demon.mips.elfGet hashmaliciousUnknownBrowse
                                                                • 91.189.91.42
                                                                demon.arm7.elfGet hashmaliciousUnknownBrowse
                                                                • 91.189.91.42
                                                                morte.ppc.elfGet hashmaliciousUnknownBrowse
                                                                • 91.189.91.42
                                                                CANONICAL-ASGBmorte.arm.elfGet hashmaliciousUnknownBrowse
                                                                • 91.189.91.42
                                                                re.bot.mips.elfGet hashmaliciousUnknownBrowse
                                                                • 91.189.91.42
                                                                morte.arm6.elfGet hashmaliciousUnknownBrowse
                                                                • 91.189.91.42
                                                                na.elfGet hashmaliciousPrometeiBrowse
                                                                • 91.189.91.42
                                                                demon.x86.elfGet hashmaliciousUnknownBrowse
                                                                • 91.189.91.42
                                                                na.elfGet hashmaliciousPrometeiBrowse
                                                                • 91.189.91.42
                                                                demon.x86.elfGet hashmaliciousUnknownBrowse
                                                                • 91.189.91.42
                                                                demon.mips.elfGet hashmaliciousUnknownBrowse
                                                                • 91.189.91.42
                                                                demon.arm7.elfGet hashmaliciousUnknownBrowse
                                                                • 91.189.91.42
                                                                morte.ppc.elfGet hashmaliciousUnknownBrowse
                                                                • 91.189.91.42
                                                                INIT7CHmorte.arm.elfGet hashmaliciousUnknownBrowse
                                                                • 109.202.202.202
                                                                re.bot.mips.elfGet hashmaliciousUnknownBrowse
                                                                • 109.202.202.202
                                                                morte.arm6.elfGet hashmaliciousUnknownBrowse
                                                                • 109.202.202.202
                                                                na.elfGet hashmaliciousPrometeiBrowse
                                                                • 109.202.202.202
                                                                demon.x86.elfGet hashmaliciousUnknownBrowse
                                                                • 109.202.202.202
                                                                na.elfGet hashmaliciousPrometeiBrowse
                                                                • 109.202.202.202
                                                                demon.x86.elfGet hashmaliciousUnknownBrowse
                                                                • 109.202.202.202
                                                                demon.mips.elfGet hashmaliciousUnknownBrowse
                                                                • 109.202.202.202
                                                                demon.arm7.elfGet hashmaliciousUnknownBrowse
                                                                • 109.202.202.202
                                                                morte.ppc.elfGet hashmaliciousUnknownBrowse
                                                                • 109.202.202.202
                                                                DIOGELO-ASGBmorte.m68k.elfGet hashmaliciousUnknownBrowse
                                                                • 176.65.134.62
                                                                morte.mips.elfGet hashmaliciousUnknownBrowse
                                                                • 176.65.134.62
                                                                morte.arm.elfGet hashmaliciousUnknownBrowse
                                                                • 176.65.134.62
                                                                morte.x86.elfGet hashmaliciousUnknownBrowse
                                                                • 176.65.134.62
                                                                morte.ppc.elfGet hashmaliciousUnknownBrowse
                                                                • 176.65.134.62
                                                                morte.sh4.elfGet hashmaliciousUnknownBrowse
                                                                • 176.65.134.62
                                                                morte.mpsl.elfGet hashmaliciousUnknownBrowse
                                                                • 176.65.134.62
                                                                morte.ppc.elfGet hashmaliciousUnknownBrowse
                                                                • 176.65.134.62
                                                                morte.arm.elfGet hashmaliciousUnknownBrowse
                                                                • 176.65.134.62
                                                                morte.mips.elfGet hashmaliciousUnknownBrowse
                                                                • 176.65.134.62
                                                                No context
                                                                No context
                                                                No created / dropped files found
                                                                File type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), statically linked, no section header
                                                                Entropy (8bit):7.973799708562928
                                                                TrID:
                                                                • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                                                                File name:morte.x64.elf
                                                                File size:48'044 bytes
                                                                MD5:0e1a6e4b683d30c8cf86c7322dec3e2c
                                                                SHA1:b0ed1d1ef04117b75ed1f6a15528302cf84b661c
                                                                SHA256:88573b0d51fab30e51d21dd9fb23541fe371f6604317d0bc3d5a71a7e3b6ba36
                                                                SHA512:5c210558436090feda18debce0078894309eb6c338e9f4230bfc581fad909f5909e4a741e8c2b00d073d3b48e1a46a935213c2a8a888264457ba9763e8c2b933
                                                                SSDEEP:768:1DepiPCCC1Uuj0PbCSVuW4Pkz6HZcxMTaYElk1q5+2irO9IwyZOdV5gJQzdmAF0Q:VKUuj0zC7Hb5cxMwki5irO2P2qJ8MAuQ
                                                                TLSH:FE23F11AC17EF66CF5EE3CB6040E27D57C118A3B421606BB0C72F06DA89AC6D27B1B41
                                                                File Content Preview:.ELF..............>.....p.......@...................@.8...@.............................................................................._R......_R.............................Q.td.....................................................Gx.UPX!H..............

                                                                ELF header

                                                                Class:ELF64
                                                                Data:2's complement, little endian
                                                                Version:1 (current)
                                                                Machine:Advanced Micro Devices X86-64
                                                                Version Number:0x1
                                                                Type:EXEC (Executable file)
                                                                OS/ABI:UNIX - System V
                                                                ABI Version:0
                                                                Entry Point Address:0x10a970
                                                                Flags:0x0
                                                                ELF Header Size:64
                                                                Program Header Offset:64
                                                                Program Header Size:56
                                                                Number of Program Headers:3
                                                                Section Header Offset:0
                                                                Section Header Size:64
                                                                Number of Section Headers:0
                                                                Header String Table Index:0
                                                                TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                                LOAD0x00x1000000x1000000xbaac0xbaac7.97540x5R E0x100000
                                                                LOAD0xfa00x525fa00x525fa00x00x00.00000x6RW 0x1000
                                                                GNU_STACK0x00x00x00x00x00.00000x6RW 0x8

                                                                Download Network PCAP: filteredfull

                                                                • Total Packets: 172
                                                                • 7777 undefined
                                                                • 443 (HTTPS)
                                                                • 80 (HTTP)
                                                                TimestampSource PortDest PortSource IPDest IP
                                                                Mar 12, 2025 02:58:06.183672905 CET574687777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:06.188374996 CET777757468176.65.134.62192.168.2.23
                                                                Mar 12, 2025 02:58:06.188426971 CET574687777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:06.191580057 CET574687777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:06.196265936 CET777757468176.65.134.62192.168.2.23
                                                                Mar 12, 2025 02:58:06.196316957 CET574687777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:06.201024055 CET777757468176.65.134.62192.168.2.23
                                                                Mar 12, 2025 02:58:06.273127079 CET43928443192.168.2.2391.189.91.42
                                                                Mar 12, 2025 02:58:06.884653091 CET777757468176.65.134.62192.168.2.23
                                                                Mar 12, 2025 02:58:06.884855986 CET574687777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:06.884855986 CET574687777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:06.885312080 CET574707777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:06.889961004 CET777757470176.65.134.62192.168.2.23
                                                                Mar 12, 2025 02:58:06.890021086 CET574707777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:06.890609980 CET574707777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:06.895301104 CET777757470176.65.134.62192.168.2.23
                                                                Mar 12, 2025 02:58:06.895380020 CET574707777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:06.900008917 CET777757470176.65.134.62192.168.2.23
                                                                Mar 12, 2025 02:58:07.575364113 CET777757470176.65.134.62192.168.2.23
                                                                Mar 12, 2025 02:58:07.575489044 CET574707777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:07.575489044 CET574707777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:07.575984001 CET574727777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:07.580636978 CET777757472176.65.134.62192.168.2.23
                                                                Mar 12, 2025 02:58:07.580684900 CET574727777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:07.581288099 CET574727777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:07.585911036 CET777757472176.65.134.62192.168.2.23
                                                                Mar 12, 2025 02:58:07.585952997 CET574727777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:07.590660095 CET777757472176.65.134.62192.168.2.23
                                                                Mar 12, 2025 02:58:08.260736942 CET777757472176.65.134.62192.168.2.23
                                                                Mar 12, 2025 02:58:08.260926962 CET574727777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:08.260962009 CET574727777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:08.261428118 CET574747777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:08.266185045 CET777757474176.65.134.62192.168.2.23
                                                                Mar 12, 2025 02:58:08.266243935 CET574747777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:08.266845942 CET574747777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:08.271608114 CET777757474176.65.134.62192.168.2.23
                                                                Mar 12, 2025 02:58:08.271648884 CET574747777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:08.276367903 CET777757474176.65.134.62192.168.2.23
                                                                Mar 12, 2025 02:58:09.084064007 CET777757474176.65.134.62192.168.2.23
                                                                Mar 12, 2025 02:58:09.084233046 CET574747777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:09.084233046 CET574747777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:09.084887028 CET574767777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:09.093116999 CET777757476176.65.134.62192.168.2.23
                                                                Mar 12, 2025 02:58:09.093164921 CET574767777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:09.093875885 CET574767777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:09.098578930 CET777757476176.65.134.62192.168.2.23
                                                                Mar 12, 2025 02:58:09.098620892 CET574767777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:09.103296041 CET777757476176.65.134.62192.168.2.23
                                                                Mar 12, 2025 02:58:09.809510946 CET777757476176.65.134.62192.168.2.23
                                                                Mar 12, 2025 02:58:09.809767008 CET574767777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:09.809767008 CET574767777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:09.810267925 CET574787777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:09.814999104 CET777757478176.65.134.62192.168.2.23
                                                                Mar 12, 2025 02:58:09.815042973 CET574787777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:09.815716982 CET574787777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:09.820420027 CET777757478176.65.134.62192.168.2.23
                                                                Mar 12, 2025 02:58:09.820491076 CET574787777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:09.827544928 CET777757478176.65.134.62192.168.2.23
                                                                Mar 12, 2025 02:58:10.491353989 CET777757478176.65.134.62192.168.2.23
                                                                Mar 12, 2025 02:58:10.491455078 CET574787777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:10.491491079 CET574787777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:10.491921902 CET574807777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:10.496665001 CET777757480176.65.134.62192.168.2.23
                                                                Mar 12, 2025 02:58:10.496716022 CET574807777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:10.497262001 CET574807777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:10.501941919 CET777757480176.65.134.62192.168.2.23
                                                                Mar 12, 2025 02:58:10.501990080 CET574807777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:10.506654024 CET777757480176.65.134.62192.168.2.23
                                                                Mar 12, 2025 02:58:11.174279928 CET777757480176.65.134.62192.168.2.23
                                                                Mar 12, 2025 02:58:11.174487114 CET574807777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:11.174537897 CET574807777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:11.175009012 CET574827777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:11.179706097 CET777757482176.65.134.62192.168.2.23
                                                                Mar 12, 2025 02:58:11.179855108 CET574827777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:11.180444956 CET574827777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:11.185173035 CET777757482176.65.134.62192.168.2.23
                                                                Mar 12, 2025 02:58:11.185211897 CET574827777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:11.189802885 CET777757482176.65.134.62192.168.2.23
                                                                Mar 12, 2025 02:58:11.648441076 CET42836443192.168.2.2391.189.91.43
                                                                Mar 12, 2025 02:58:11.876185894 CET777757482176.65.134.62192.168.2.23
                                                                Mar 12, 2025 02:58:11.876403093 CET574827777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:11.876403093 CET574827777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:11.876841068 CET574847777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:11.881570101 CET777757484176.65.134.62192.168.2.23
                                                                Mar 12, 2025 02:58:11.881629944 CET574847777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:11.882210016 CET574847777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:11.886924028 CET777757484176.65.134.62192.168.2.23
                                                                Mar 12, 2025 02:58:11.886981964 CET574847777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:11.891727924 CET777757484176.65.134.62192.168.2.23
                                                                Mar 12, 2025 02:58:12.592935085 CET777757484176.65.134.62192.168.2.23
                                                                Mar 12, 2025 02:58:12.593163967 CET574847777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:12.593163967 CET574847777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:12.593554020 CET574867777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:12.598267078 CET777757486176.65.134.62192.168.2.23
                                                                Mar 12, 2025 02:58:12.598323107 CET574867777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:12.598932981 CET574867777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:12.603652954 CET777757486176.65.134.62192.168.2.23
                                                                Mar 12, 2025 02:58:12.603696108 CET574867777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:12.608377934 CET777757486176.65.134.62192.168.2.23
                                                                Mar 12, 2025 02:58:13.275702953 CET777757486176.65.134.62192.168.2.23
                                                                Mar 12, 2025 02:58:13.276045084 CET574867777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:13.276062965 CET574867777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:13.276709080 CET574887777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:13.281368971 CET777757488176.65.134.62192.168.2.23
                                                                Mar 12, 2025 02:58:13.281423092 CET574887777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:13.282170057 CET574887777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:13.286834955 CET777757488176.65.134.62192.168.2.23
                                                                Mar 12, 2025 02:58:13.286876917 CET574887777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:13.291517019 CET777757488176.65.134.62192.168.2.23
                                                                Mar 12, 2025 02:58:13.440145016 CET4251680192.168.2.23109.202.202.202
                                                                Mar 12, 2025 02:58:13.996881962 CET777757488176.65.134.62192.168.2.23
                                                                Mar 12, 2025 02:58:13.997109890 CET574887777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:13.997163057 CET574887777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:13.997731924 CET574907777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:14.002449989 CET777757490176.65.134.62192.168.2.23
                                                                Mar 12, 2025 02:58:14.002499104 CET574907777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:14.003412008 CET574907777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:14.008019924 CET777757490176.65.134.62192.168.2.23
                                                                Mar 12, 2025 02:58:14.008059025 CET574907777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:14.012758017 CET777757490176.65.134.62192.168.2.23
                                                                Mar 12, 2025 02:58:14.799514055 CET777757490176.65.134.62192.168.2.23
                                                                Mar 12, 2025 02:58:14.799612999 CET574907777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:14.799612999 CET574907777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:14.800096035 CET574927777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:14.804790020 CET777757492176.65.134.62192.168.2.23
                                                                Mar 12, 2025 02:58:14.804847002 CET574927777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:14.805427074 CET574927777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:14.810045958 CET777757492176.65.134.62192.168.2.23
                                                                Mar 12, 2025 02:58:14.810094118 CET574927777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:14.814769030 CET777757492176.65.134.62192.168.2.23
                                                                Mar 12, 2025 02:58:15.494771004 CET777757492176.65.134.62192.168.2.23
                                                                Mar 12, 2025 02:58:15.494929075 CET574927777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:15.494929075 CET574927777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:15.495574951 CET574947777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:15.500286102 CET777757494176.65.134.62192.168.2.23
                                                                Mar 12, 2025 02:58:15.500333071 CET574947777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:15.501127005 CET574947777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:15.505742073 CET777757494176.65.134.62192.168.2.23
                                                                Mar 12, 2025 02:58:15.505784035 CET574947777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:15.510720015 CET777757494176.65.134.62192.168.2.23
                                                                Mar 12, 2025 02:58:16.207827091 CET777757494176.65.134.62192.168.2.23
                                                                Mar 12, 2025 02:58:16.207937002 CET574947777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:16.207962036 CET574947777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:16.208584070 CET574967777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:16.213294983 CET777757496176.65.134.62192.168.2.23
                                                                Mar 12, 2025 02:58:16.213366985 CET574967777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:16.214191914 CET574967777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:16.218849897 CET777757496176.65.134.62192.168.2.23
                                                                Mar 12, 2025 02:58:16.218950987 CET574967777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:16.223555088 CET777757496176.65.134.62192.168.2.23
                                                                Mar 12, 2025 02:58:16.884217024 CET777757496176.65.134.62192.168.2.23
                                                                Mar 12, 2025 02:58:16.884618044 CET574967777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:16.884618044 CET574967777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:16.885098934 CET574987777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:16.889803886 CET777757498176.65.134.62192.168.2.23
                                                                Mar 12, 2025 02:58:16.889908075 CET574987777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:16.890861988 CET574987777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:16.895512104 CET777757498176.65.134.62192.168.2.23
                                                                Mar 12, 2025 02:58:16.895601034 CET574987777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:16.900288105 CET777757498176.65.134.62192.168.2.23
                                                                Mar 12, 2025 02:58:17.576694012 CET777757498176.65.134.62192.168.2.23
                                                                Mar 12, 2025 02:58:17.577097893 CET574987777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:17.577097893 CET574987777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:17.577572107 CET575007777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:17.584033012 CET777757500176.65.134.62192.168.2.23
                                                                Mar 12, 2025 02:58:17.584112883 CET575007777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:17.585131884 CET575007777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:17.591701031 CET777757500176.65.134.62192.168.2.23
                                                                Mar 12, 2025 02:58:17.591764927 CET575007777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:17.598882914 CET777757500176.65.134.62192.168.2.23
                                                                Mar 12, 2025 02:58:18.286906004 CET777757500176.65.134.62192.168.2.23
                                                                Mar 12, 2025 02:58:18.287173986 CET575007777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:18.287173986 CET575007777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:18.287559032 CET575027777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:18.292227983 CET777757502176.65.134.62192.168.2.23
                                                                Mar 12, 2025 02:58:18.292296886 CET575027777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:18.293163061 CET575027777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:18.297795057 CET777757502176.65.134.62192.168.2.23
                                                                Mar 12, 2025 02:58:18.297852993 CET575027777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:18.302556992 CET777757502176.65.134.62192.168.2.23
                                                                Mar 12, 2025 02:58:18.970654011 CET777757502176.65.134.62192.168.2.23
                                                                Mar 12, 2025 02:58:18.970976114 CET575027777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:18.970976114 CET575027777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:18.971556902 CET575047777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:18.976223946 CET777757504176.65.134.62192.168.2.23
                                                                Mar 12, 2025 02:58:18.976299047 CET575047777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:18.977276087 CET575047777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:18.981921911 CET777757504176.65.134.62192.168.2.23
                                                                Mar 12, 2025 02:58:18.981981039 CET575047777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:18.986593008 CET777757504176.65.134.62192.168.2.23
                                                                Mar 12, 2025 02:58:19.710627079 CET777757504176.65.134.62192.168.2.23
                                                                Mar 12, 2025 02:58:19.710758924 CET575047777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:19.710783005 CET575047777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:19.711466074 CET575067777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:19.716252089 CET777757506176.65.134.62192.168.2.23
                                                                Mar 12, 2025 02:58:19.716337919 CET575067777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:19.717303038 CET575067777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:19.721915960 CET777757506176.65.134.62192.168.2.23
                                                                Mar 12, 2025 02:58:19.721970081 CET575067777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:19.726600885 CET777757506176.65.134.62192.168.2.23
                                                                Mar 12, 2025 02:58:20.503150940 CET777757506176.65.134.62192.168.2.23
                                                                Mar 12, 2025 02:58:20.503319025 CET575067777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:20.503319025 CET575067777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:20.503848076 CET575087777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:20.508502960 CET777757508176.65.134.62192.168.2.23
                                                                Mar 12, 2025 02:58:20.508559942 CET575087777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:20.509526014 CET575087777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:20.514134884 CET777757508176.65.134.62192.168.2.23
                                                                Mar 12, 2025 02:58:20.514178991 CET575087777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:20.518841028 CET777757508176.65.134.62192.168.2.23
                                                                Mar 12, 2025 02:58:21.206573009 CET777757508176.65.134.62192.168.2.23
                                                                Mar 12, 2025 02:58:21.206774950 CET575087777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:21.206840992 CET575087777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:21.207483053 CET575107777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:21.212182045 CET777757510176.65.134.62192.168.2.23
                                                                Mar 12, 2025 02:58:21.212249041 CET575107777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:21.213044882 CET575107777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:21.217746019 CET777757510176.65.134.62192.168.2.23
                                                                Mar 12, 2025 02:58:21.217794895 CET575107777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:21.222419024 CET777757510176.65.134.62192.168.2.23
                                                                Mar 12, 2025 02:58:22.013807058 CET777757510176.65.134.62192.168.2.23
                                                                Mar 12, 2025 02:58:22.014034033 CET575107777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:22.014034986 CET575107777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:22.014470100 CET777757510176.65.134.62192.168.2.23
                                                                Mar 12, 2025 02:58:22.014547110 CET575107777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:22.014647007 CET575127777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:22.019268990 CET777757512176.65.134.62192.168.2.23
                                                                Mar 12, 2025 02:58:22.019347906 CET575127777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:22.020142078 CET575127777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:22.024873018 CET777757512176.65.134.62192.168.2.23
                                                                Mar 12, 2025 02:58:22.024931908 CET575127777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:22.029640913 CET777757512176.65.134.62192.168.2.23
                                                                Mar 12, 2025 02:58:22.722781897 CET777757512176.65.134.62192.168.2.23
                                                                Mar 12, 2025 02:58:22.723001957 CET575127777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:22.723040104 CET575127777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:22.723809004 CET575147777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:22.728518963 CET777757514176.65.134.62192.168.2.23
                                                                Mar 12, 2025 02:58:22.728596926 CET575147777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:22.729752064 CET575147777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:22.734440088 CET777757514176.65.134.62192.168.2.23
                                                                Mar 12, 2025 02:58:22.734500885 CET575147777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:22.739144087 CET777757514176.65.134.62192.168.2.23
                                                                Mar 12, 2025 02:58:23.426783085 CET777757514176.65.134.62192.168.2.23
                                                                Mar 12, 2025 02:58:23.426964998 CET575147777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:23.427021027 CET575147777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:23.427810907 CET575167777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:23.432554007 CET777757516176.65.134.62192.168.2.23
                                                                Mar 12, 2025 02:58:23.432636976 CET575167777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:23.434205055 CET575167777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:23.438812017 CET777757516176.65.134.62192.168.2.23
                                                                Mar 12, 2025 02:58:23.438869953 CET575167777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:23.443485022 CET777757516176.65.134.62192.168.2.23
                                                                Mar 12, 2025 02:58:24.137079954 CET777757516176.65.134.62192.168.2.23
                                                                Mar 12, 2025 02:58:24.137207031 CET575167777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:24.137290001 CET575167777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:24.138063908 CET575187777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:24.142715931 CET777757518176.65.134.62192.168.2.23
                                                                Mar 12, 2025 02:58:24.142772913 CET575187777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:24.143843889 CET575187777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:24.148464918 CET777757518176.65.134.62192.168.2.23
                                                                Mar 12, 2025 02:58:24.148510933 CET575187777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:24.153151989 CET777757518176.65.134.62192.168.2.23
                                                                Mar 12, 2025 02:58:24.815351009 CET777757518176.65.134.62192.168.2.23
                                                                Mar 12, 2025 02:58:24.815495014 CET575187777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:24.815546989 CET575187777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:24.816014051 CET575207777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:24.820677042 CET777757520176.65.134.62192.168.2.23
                                                                Mar 12, 2025 02:58:24.820729971 CET575207777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:24.821470022 CET575207777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:24.826134920 CET777757520176.65.134.62192.168.2.23
                                                                Mar 12, 2025 02:58:24.826179028 CET575207777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:24.830843925 CET777757520176.65.134.62192.168.2.23
                                                                Mar 12, 2025 02:58:28.030303001 CET43928443192.168.2.2391.189.91.42
                                                                Mar 12, 2025 02:58:34.829376936 CET575207777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:34.834018946 CET777757520176.65.134.62192.168.2.23
                                                                Mar 12, 2025 02:58:35.037364960 CET777757520176.65.134.62192.168.2.23
                                                                Mar 12, 2025 02:58:35.037467957 CET575207777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:58:38.268827915 CET42836443192.168.2.2391.189.91.43
                                                                Mar 12, 2025 02:58:44.412051916 CET4251680192.168.2.23109.202.202.202
                                                                Mar 12, 2025 02:59:08.984498978 CET43928443192.168.2.2391.189.91.42
                                                                Mar 12, 2025 02:59:35.086920023 CET575207777192.168.2.23176.65.134.62
                                                                Mar 12, 2025 02:59:35.091665983 CET777757520176.65.134.62192.168.2.23
                                                                Mar 12, 2025 02:59:35.295166969 CET777757520176.65.134.62192.168.2.23
                                                                Mar 12, 2025 02:59:35.295418024 CET575207777192.168.2.23176.65.134.62

                                                                System Behavior

                                                                Start time (UTC):01:58:05
                                                                Start date (UTC):12/03/2025
                                                                Path:/tmp/morte.x64.elf
                                                                Arguments:/tmp/morte.x64.elf
                                                                File size:48044 bytes
                                                                MD5 hash:0e1a6e4b683d30c8cf86c7322dec3e2c

                                                                Start time (UTC):01:58:05
                                                                Start date (UTC):12/03/2025
                                                                Path:/tmp/morte.x64.elf
                                                                Arguments:-
                                                                File size:48044 bytes
                                                                MD5 hash:0e1a6e4b683d30c8cf86c7322dec3e2c

                                                                Start time (UTC):01:58:05
                                                                Start date (UTC):12/03/2025
                                                                Path:/tmp/morte.x64.elf
                                                                Arguments:-
                                                                File size:48044 bytes
                                                                MD5 hash:0e1a6e4b683d30c8cf86c7322dec3e2c