Edit tour

Linux Analysis Report
x86.elf

Overview

General Information

Sample name:x86.elf
Analysis ID:1646585
MD5:84f6600098a7ffd79c0d1d2b3561022c
SHA1:816e28410202debd9bb33a5ee5adca4ffceb210f
SHA256:feeff674c195b3afcc964d71281ddb2c8f366e30ce12137c7b00b79b2a5ac966
Tags:elfuser-abuse_ch
Infos:

Detection

Score:60
Range:0 - 100

Signatures

Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Sample is packed with UPX
ELF contains segments with high entropy indicating compressed/encrypted content
Enumerates processes within the "proc" file system
Sample contains only a LOAD segment without any section mappings
Tries to resolve domain names, but no domain seems valid (expired dropper behavior)
Yara signature match

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
Joe Sandbox version:42.0.0 Malachite
Analysis ID:1646585
Start date and time:2025-03-24 06:18:35 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 39s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:x86.elf
Detection:MAL
Classification:mal60.evad.linELF@0/0@50/0
  • VT rate limit hit for: 198.98.51.68
Command:/tmp/x86.elf
PID:5572
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
skidmark botnet
Standard Error:
  • system is lnxubuntu20
  • x86.elf (PID: 5572, Parent: 5497, MD5: 84f6600098a7ffd79c0d1d2b3561022c) Arguments: /tmp/x86.elf
    • x86.elf New Fork (PID: 5573, Parent: 5572)
      • x86.elf New Fork (PID: 5574, Parent: 5573)
      • x86.elf New Fork (PID: 5575, Parent: 5573)
      • x86.elf New Fork (PID: 5576, Parent: 5573)
  • cleanup
SourceRuleDescriptionAuthorStrings
5576.1.0000000008048000.0000000008054000.r-x.sdmpLinux_Trojan_Mirai_fa3ad9d0unknownunknown
  • 0xd4f:$a: CB 08 C1 CB 10 66 C1 CB 08 31 C9 8A 4F 14 D3 E8 01 D8 66 C1
5576.1.0000000008048000.0000000008054000.r-x.sdmpLinux_Trojan_Mirai_b14f4c5dunknownunknown
  • 0x2b50:$a: 53 31 DB 8B 4C 24 0C 8B 54 24 08 83 F9 01 76 15 66 8B 02 83 E9 02 25 FF FF 00 00 83 C2 02 01 C3 83 F9 01 77 EB 49 75 05 0F BE 02 01 C3
5576.1.0000000008048000.0000000008054000.r-x.sdmpLinux_Trojan_Mirai_5f7b67b8unknownunknown
  • 0x8df6:$a: 89 38 83 CF FF 89 F8 5A 59 5F C3 57 56 83 EC 04 8B 7C 24 10 8B 4C
5576.1.0000000008048000.0000000008054000.r-x.sdmpLinux_Trojan_Mirai_88de437funknownunknown
  • 0x45f2:$a: 24 08 8B 4C 24 04 85 D2 74 0D 31 C0 89 F6 C6 04 08 00 40 39 D0
5576.1.0000000008048000.0000000008054000.r-x.sdmpLinux_Trojan_Mirai_389ee3e9unknownunknown
  • 0x7ff6:$a: 89 45 00 EB 2C 8B 4B 04 8B 13 8B 7B 18 8B 01 01 02 8B 02 83
Click to see the 9 entries
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: x86.elfReversingLabs: Detection: 19%
Source: unknownDNS traffic detected: query: 198.98.51.68 replaycode: Name error (3)
Source: unknownTCP traffic detected without corresponding DNS query: 175.30.53.20
Source: unknownTCP traffic detected without corresponding DNS query: 175.30.53.20
Source: unknownTCP traffic detected without corresponding DNS query: 175.30.53.20
Source: unknownTCP traffic detected without corresponding DNS query: 175.30.53.20
Source: unknownTCP traffic detected without corresponding DNS query: 175.30.53.20
Source: unknownTCP traffic detected without corresponding DNS query: 175.30.53.20
Source: unknownTCP traffic detected without corresponding DNS query: 175.30.53.20
Source: unknownTCP traffic detected without corresponding DNS query: 175.30.53.20
Source: unknownTCP traffic detected without corresponding DNS query: 175.30.53.20
Source: unknownTCP traffic detected without corresponding DNS query: 175.30.53.20
Source: unknownTCP traffic detected without corresponding DNS query: 175.30.53.20
Source: unknownTCP traffic detected without corresponding DNS query: 175.30.53.20
Source: unknownTCP traffic detected without corresponding DNS query: 175.30.53.20
Source: unknownTCP traffic detected without corresponding DNS query: 175.30.53.20
Source: unknownTCP traffic detected without corresponding DNS query: 175.30.53.20
Source: unknownTCP traffic detected without corresponding DNS query: 175.30.53.20
Source: unknownTCP traffic detected without corresponding DNS query: 175.30.53.20
Source: unknownTCP traffic detected without corresponding DNS query: 175.30.53.20
Source: unknownTCP traffic detected without corresponding DNS query: 175.30.53.20
Source: unknownTCP traffic detected without corresponding DNS query: 175.30.53.20
Source: unknownTCP traffic detected without corresponding DNS query: 175.30.53.20
Source: unknownTCP traffic detected without corresponding DNS query: 175.30.53.20
Source: unknownTCP traffic detected without corresponding DNS query: 175.30.53.20
Source: unknownTCP traffic detected without corresponding DNS query: 175.30.53.20
Source: unknownTCP traffic detected without corresponding DNS query: 175.30.53.20
Source: unknownTCP traffic detected without corresponding DNS query: 175.30.53.20
Source: unknownTCP traffic detected without corresponding DNS query: 175.30.53.20
Source: unknownTCP traffic detected without corresponding DNS query: 175.30.53.20
Source: unknownTCP traffic detected without corresponding DNS query: 175.30.53.20
Source: unknownTCP traffic detected without corresponding DNS query: 175.30.53.20
Source: unknownTCP traffic detected without corresponding DNS query: 175.30.53.20
Source: unknownTCP traffic detected without corresponding DNS query: 175.30.53.20
Source: unknownTCP traffic detected without corresponding DNS query: 175.30.53.20
Source: unknownTCP traffic detected without corresponding DNS query: 175.30.53.20
Source: unknownTCP traffic detected without corresponding DNS query: 175.30.53.20
Source: unknownTCP traffic detected without corresponding DNS query: 175.30.53.20
Source: unknownTCP traffic detected without corresponding DNS query: 175.30.53.20
Source: unknownUDP traffic detected without corresponding DNS query: 51.158.108.203
Source: unknownUDP traffic detected without corresponding DNS query: 51.158.108.203
Source: unknownUDP traffic detected without corresponding DNS query: 51.158.108.203
Source: unknownUDP traffic detected without corresponding DNS query: 51.158.108.203
Source: unknownUDP traffic detected without corresponding DNS query: 51.158.108.203
Source: unknownUDP traffic detected without corresponding DNS query: 81.169.136.222
Source: unknownUDP traffic detected without corresponding DNS query: 81.169.136.222
Source: unknownUDP traffic detected without corresponding DNS query: 81.169.136.222
Source: unknownUDP traffic detected without corresponding DNS query: 81.169.136.222
Source: unknownUDP traffic detected without corresponding DNS query: 81.169.136.222
Source: unknownUDP traffic detected without corresponding DNS query: 51.77.149.139
Source: unknownUDP traffic detected without corresponding DNS query: 51.77.149.139
Source: unknownUDP traffic detected without corresponding DNS query: 51.77.149.139
Source: global trafficDNS traffic detected: DNS query: 198.98.51.68
Source: x86.elfString found in binary or memory: http://upx.sf.net

System Summary

barindex
Source: 5576.1.0000000008048000.0000000008054000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_fa3ad9d0 Author: unknown
Source: 5576.1.0000000008048000.0000000008054000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_b14f4c5d Author: unknown
Source: 5576.1.0000000008048000.0000000008054000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_5f7b67b8 Author: unknown
Source: 5576.1.0000000008048000.0000000008054000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_88de437f Author: unknown
Source: 5576.1.0000000008048000.0000000008054000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_389ee3e9 Author: unknown
Source: 5576.1.0000000008048000.0000000008054000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_cc93863b Author: unknown
Source: 5576.1.0000000008048000.0000000008054000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_8aa7b5d3 Author: unknown
Source: 5572.1.0000000008048000.0000000008054000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_fa3ad9d0 Author: unknown
Source: 5572.1.0000000008048000.0000000008054000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_b14f4c5d Author: unknown
Source: 5572.1.0000000008048000.0000000008054000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_5f7b67b8 Author: unknown
Source: 5572.1.0000000008048000.0000000008054000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_88de437f Author: unknown
Source: 5572.1.0000000008048000.0000000008054000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_389ee3e9 Author: unknown
Source: 5572.1.0000000008048000.0000000008054000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_cc93863b Author: unknown
Source: 5572.1.0000000008048000.0000000008054000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_8aa7b5d3 Author: unknown
Source: LOAD without section mappingsProgram segment: 0xc01000
Source: 5576.1.0000000008048000.0000000008054000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_fa3ad9d0 reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = fe93a3552b72b107f95cc5a7e59da64fe84d31df833bf36c81d8f31d8d79d7ca, id = fa3ad9d0-7c55-4621-90fc-6b154c44a67b, last_modified = 2021-09-16
Source: 5576.1.0000000008048000.0000000008054000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_b14f4c5d os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = a70d052918dd2fbc66db241da6438015130f0fb6929229bfe573546fe98da817, id = b14f4c5d-054f-46e6-9fa8-3588f1ef68b7, last_modified = 2021-09-16
Source: 5576.1.0000000008048000.0000000008054000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_5f7b67b8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 6cb5fb0b7c132e9c11ac72da43278025b60810ea3733c9c6d6ca966163185940, id = 5f7b67b8-3d7b-48a4-8f03-b6f2c92be92e, last_modified = 2021-09-16
Source: 5576.1.0000000008048000.0000000008054000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_88de437f reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = c19eb595c2b444a809bef8500c20342c9f46694d3018e268833f9b884133a1ea, id = 88de437f-9c98-4e1d-96c0-7b433c99886a, last_modified = 2021-09-16
Source: 5576.1.0000000008048000.0000000008054000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_389ee3e9 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 59f2359dc1f41d385d639d157b4cd9fc73d76d8abb7cc09d47632bb4c9a39e6e, id = 389ee3e9-70c1-4c93-a999-292cf6ff1652, last_modified = 2022-01-26
Source: 5576.1.0000000008048000.0000000008054000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_cc93863b reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = f3ecd30f0b511a8e92cfa642409d559e7612c3f57a1659ca46c77aca809a00ac, id = cc93863b-1050-40ba-9d02-5ec9ce6a3a28, last_modified = 2022-01-26
Source: 5576.1.0000000008048000.0000000008054000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_8aa7b5d3 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 02a2c18c362df4b1fceb33f3b605586514ba9a00c7afedf71c04fa54d8146444, id = 8aa7b5d3-e1eb-4b55-b36a-0d3a242c06e9, last_modified = 2022-01-26
Source: 5572.1.0000000008048000.0000000008054000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_fa3ad9d0 reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = fe93a3552b72b107f95cc5a7e59da64fe84d31df833bf36c81d8f31d8d79d7ca, id = fa3ad9d0-7c55-4621-90fc-6b154c44a67b, last_modified = 2021-09-16
Source: 5572.1.0000000008048000.0000000008054000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_b14f4c5d os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = a70d052918dd2fbc66db241da6438015130f0fb6929229bfe573546fe98da817, id = b14f4c5d-054f-46e6-9fa8-3588f1ef68b7, last_modified = 2021-09-16
Source: 5572.1.0000000008048000.0000000008054000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_5f7b67b8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 6cb5fb0b7c132e9c11ac72da43278025b60810ea3733c9c6d6ca966163185940, id = 5f7b67b8-3d7b-48a4-8f03-b6f2c92be92e, last_modified = 2021-09-16
Source: 5572.1.0000000008048000.0000000008054000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_88de437f reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = c19eb595c2b444a809bef8500c20342c9f46694d3018e268833f9b884133a1ea, id = 88de437f-9c98-4e1d-96c0-7b433c99886a, last_modified = 2021-09-16
Source: 5572.1.0000000008048000.0000000008054000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_389ee3e9 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 59f2359dc1f41d385d639d157b4cd9fc73d76d8abb7cc09d47632bb4c9a39e6e, id = 389ee3e9-70c1-4c93-a999-292cf6ff1652, last_modified = 2022-01-26
Source: 5572.1.0000000008048000.0000000008054000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_cc93863b reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = f3ecd30f0b511a8e92cfa642409d559e7612c3f57a1659ca46c77aca809a00ac, id = cc93863b-1050-40ba-9d02-5ec9ce6a3a28, last_modified = 2022-01-26
Source: 5572.1.0000000008048000.0000000008054000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_8aa7b5d3 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 02a2c18c362df4b1fceb33f3b605586514ba9a00c7afedf71c04fa54d8146444, id = 8aa7b5d3-e1eb-4b55-b36a-0d3a242c06e9, last_modified = 2022-01-26
Source: classification engineClassification label: mal60.evad.linELF@0/0@50/0

Data Obfuscation

barindex
Source: initial sampleString containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $
Source: initial sampleString containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $
Source: initial sampleString containing UPX found: $Id: UPX 3.94 Copyright (C) 1996-2017 the UPX Team. All Rights Reserved. $
Source: /tmp/x86.elf (PID: 5575)File opened: /proc/110/cmdlineJump to behavior
Source: /tmp/x86.elf (PID: 5575)File opened: /proc/231/cmdlineJump to behavior
Source: /tmp/x86.elf (PID: 5575)File opened: /proc/111/cmdlineJump to behavior
Source: /tmp/x86.elf (PID: 5575)File opened: /proc/112/cmdlineJump to behavior
Source: /tmp/x86.elf (PID: 5575)File opened: /proc/233/cmdlineJump to behavior
Source: /tmp/x86.elf (PID: 5575)File opened: /proc/113/cmdlineJump to behavior
Source: /tmp/x86.elf (PID: 5575)File opened: /proc/114/cmdlineJump to behavior
Source: /tmp/x86.elf (PID: 5575)File opened: /proc/235/cmdlineJump to behavior
Source: /tmp/x86.elf (PID: 5575)File opened: /proc/115/cmdlineJump to behavior
Source: /tmp/x86.elf (PID: 5575)File opened: /proc/1333/cmdlineJump to behavior
Source: /tmp/x86.elf (PID: 5575)File opened: /proc/116/cmdlineJump to behavior
Source: /tmp/x86.elf (PID: 5575)File opened: /proc/1695/cmdlineJump to behavior
Source: /tmp/x86.elf (PID: 5575)File opened: /proc/117/cmdlineJump to behavior
Source: /tmp/x86.elf (PID: 5575)File opened: /proc/118/cmdlineJump to behavior
Source: /tmp/x86.elf (PID: 5575)File opened: /proc/119/cmdlineJump to behavior
Source: /tmp/x86.elf (PID: 5575)File opened: /proc/911/cmdlineJump to behavior
Source: /tmp/x86.elf (PID: 5575)File opened: /proc/914/cmdlineJump to behavior
Source: /tmp/x86.elf (PID: 5575)File opened: /proc/10/cmdlineJump to behavior
Source: /tmp/x86.elf (PID: 5575)File opened: /proc/917/cmdlineJump to behavior
Source: /tmp/x86.elf (PID: 5575)File opened: /proc/11/cmdlineJump to behavior
Source: /tmp/x86.elf (PID: 5575)File opened: /proc/12/cmdlineJump to behavior
Source: /tmp/x86.elf (PID: 5575)File opened: /proc/13/cmdlineJump to behavior
Source: /tmp/x86.elf (PID: 5575)File opened: /proc/14/cmdlineJump to behavior
Source: /tmp/x86.elf (PID: 5575)File opened: /proc/15/cmdlineJump to behavior
Source: /tmp/x86.elf (PID: 5575)File opened: /proc/16/cmdlineJump to behavior
Source: /tmp/x86.elf (PID: 5575)File opened: /proc/17/cmdlineJump to behavior
Source: /tmp/x86.elf (PID: 5575)File opened: /proc/18/cmdlineJump to behavior
Source: /tmp/x86.elf (PID: 5575)File opened: /proc/19/cmdlineJump to behavior
Source: /tmp/x86.elf (PID: 5575)File opened: /proc/1591/cmdlineJump to behavior
Source: /tmp/x86.elf (PID: 5575)File opened: /proc/120/cmdlineJump to behavior
Source: /tmp/x86.elf (PID: 5575)File opened: /proc/121/cmdlineJump to behavior
Source: /tmp/x86.elf (PID: 5575)File opened: /proc/1/cmdlineJump to behavior
Source: /tmp/x86.elf (PID: 5575)File opened: /proc/122/cmdlineJump to behavior
Source: /tmp/x86.elf (PID: 5575)File opened: /proc/243/cmdlineJump to behavior
Source: /tmp/x86.elf (PID: 5575)File opened: /proc/2/cmdlineJump to behavior
Source: /tmp/x86.elf (PID: 5575)File opened: /proc/123/cmdlineJump to behavior
Source: /tmp/x86.elf (PID: 5575)File opened: /proc/3/cmdlineJump to behavior
Source: /tmp/x86.elf (PID: 5575)File opened: /proc/124/cmdlineJump to behavior
Source: /tmp/x86.elf (PID: 5575)File opened: /proc/1588/cmdlineJump to behavior
Source: /tmp/x86.elf (PID: 5575)File opened: /proc/125/cmdlineJump to behavior
Source: /tmp/x86.elf (PID: 5575)File opened: /proc/4/cmdlineJump to behavior
Source: /tmp/x86.elf (PID: 5575)File opened: /proc/246/cmdlineJump to behavior
Source: /tmp/x86.elf (PID: 5575)File opened: /proc/126/cmdlineJump to behavior
Source: /tmp/x86.elf (PID: 5575)File opened: /proc/5/cmdlineJump to behavior
Source: /tmp/x86.elf (PID: 5575)File opened: /proc/127/cmdlineJump to behavior
Source: /tmp/x86.elf (PID: 5575)File opened: /proc/6/cmdlineJump to behavior
Source: /tmp/x86.elf (PID: 5575)File opened: /proc/1585/cmdlineJump to behavior
Source: /tmp/x86.elf (PID: 5575)File opened: /proc/128/cmdlineJump to behavior
Source: /tmp/x86.elf (PID: 5575)File opened: /proc/7/cmdlineJump to behavior
Source: /tmp/x86.elf (PID: 5575)File opened: /proc/129/cmdlineJump to behavior
Source: /tmp/x86.elf (PID: 5575)File opened: /proc/8/cmdlineJump to behavior
Source: /tmp/x86.elf (PID: 5575)File opened: /proc/800/cmdlineJump to behavior
Source: /tmp/x86.elf (PID: 5575)File opened: /proc/9/cmdlineJump to behavior
Source: /tmp/x86.elf (PID: 5575)File opened: /proc/802/cmdlineJump to behavior
Source: /tmp/x86.elf (PID: 5575)File opened: /proc/803/cmdlineJump to behavior
Source: /tmp/x86.elf (PID: 5575)File opened: /proc/804/cmdlineJump to behavior
Source: /tmp/x86.elf (PID: 5575)File opened: /proc/20/cmdlineJump to behavior
Source: /tmp/x86.elf (PID: 5575)File opened: /proc/21/cmdlineJump to behavior
Source: /tmp/x86.elf (PID: 5575)File opened: /proc/3407/cmdlineJump to behavior
Source: /tmp/x86.elf (PID: 5575)File opened: /proc/22/cmdlineJump to behavior
Source: /tmp/x86.elf (PID: 5575)File opened: /proc/23/cmdlineJump to behavior
Source: /tmp/x86.elf (PID: 5575)File opened: /proc/24/cmdlineJump to behavior
Source: /tmp/x86.elf (PID: 5575)File opened: /proc/25/cmdlineJump to behavior
Source: /tmp/x86.elf (PID: 5575)File opened: /proc/26/cmdlineJump to behavior
Source: /tmp/x86.elf (PID: 5575)File opened: /proc/27/cmdlineJump to behavior
Source: /tmp/x86.elf (PID: 5575)File opened: /proc/28/cmdlineJump to behavior
Source: /tmp/x86.elf (PID: 5575)File opened: /proc/29/cmdlineJump to behavior
Source: /tmp/x86.elf (PID: 5575)File opened: /proc/1484/cmdlineJump to behavior
Source: /tmp/x86.elf (PID: 5575)File opened: /proc/490/cmdlineJump to behavior
Source: /tmp/x86.elf (PID: 5575)File opened: /proc/250/cmdlineJump to behavior
Source: /tmp/x86.elf (PID: 5575)File opened: /proc/130/cmdlineJump to behavior
Source: /tmp/x86.elf (PID: 5575)File opened: /proc/251/cmdlineJump to behavior
Source: /tmp/x86.elf (PID: 5575)File opened: /proc/131/cmdlineJump to behavior
Source: /tmp/x86.elf (PID: 5575)File opened: /proc/132/cmdlineJump to behavior
Source: /tmp/x86.elf (PID: 5575)File opened: /proc/133/cmdlineJump to behavior
Source: /tmp/x86.elf (PID: 5575)File opened: /proc/1479/cmdlineJump to behavior
Source: /tmp/x86.elf (PID: 5575)File opened: /proc/378/cmdlineJump to behavior
Source: /tmp/x86.elf (PID: 5575)File opened: /proc/258/cmdlineJump to behavior
Source: /tmp/x86.elf (PID: 5575)File opened: /proc/259/cmdlineJump to behavior
Source: /tmp/x86.elf (PID: 5575)File opened: /proc/931/cmdlineJump to behavior
Source: /tmp/x86.elf (PID: 5575)File opened: /proc/1595/cmdlineJump to behavior
Source: /tmp/x86.elf (PID: 5575)File opened: /proc/812/cmdlineJump to behavior
Source: /tmp/x86.elf (PID: 5575)File opened: /proc/933/cmdlineJump to behavior
Source: /tmp/x86.elf (PID: 5575)File opened: /proc/3895/cmdlineJump to behavior
Source: /tmp/x86.elf (PID: 5575)File opened: /proc/30/cmdlineJump to behavior
Source: /tmp/x86.elf (PID: 5575)File opened: /proc/3419/cmdlineJump to behavior
Source: /tmp/x86.elf (PID: 5575)File opened: /proc/35/cmdlineJump to behavior
Source: /tmp/x86.elf (PID: 5575)File opened: /proc/3310/cmdlineJump to behavior
Source: /tmp/x86.elf (PID: 5575)File opened: /proc/260/cmdlineJump to behavior
Source: /tmp/x86.elf (PID: 5575)File opened: /proc/261/cmdlineJump to behavior
Source: /tmp/x86.elf (PID: 5575)File opened: /proc/262/cmdlineJump to behavior
Source: /tmp/x86.elf (PID: 5575)File opened: /proc/142/cmdlineJump to behavior
Source: /tmp/x86.elf (PID: 5575)File opened: /proc/263/cmdlineJump to behavior
Source: /tmp/x86.elf (PID: 5575)File opened: /proc/264/cmdlineJump to behavior
Source: /tmp/x86.elf (PID: 5575)File opened: /proc/265/cmdlineJump to behavior
Source: /tmp/x86.elf (PID: 5575)File opened: /proc/145/cmdlineJump to behavior
Source: /tmp/x86.elf (PID: 5575)File opened: /proc/266/cmdlineJump to behavior
Source: /tmp/x86.elf (PID: 5575)File opened: /proc/267/cmdlineJump to behavior
Source: /tmp/x86.elf (PID: 5575)File opened: /proc/268/cmdlineJump to behavior
Source: /tmp/x86.elf (PID: 5575)File opened: /proc/3303/cmdlineJump to behavior
Source: /tmp/x86.elf (PID: 5575)File opened: /proc/269/cmdlineJump to behavior
Source: /tmp/x86.elf (PID: 5575)File opened: /proc/1486/cmdlineJump to behavior
Source: /tmp/x86.elf (PID: 5575)File opened: /proc/1806/cmdlineJump to behavior
Source: /tmp/x86.elf (PID: 5575)File opened: /proc/3440/cmdlineJump to behavior
Source: /tmp/x86.elf (PID: 5575)File opened: /proc/270/cmdlineJump to behavior
Source: x86.elfSubmission file: segment LOAD with 7.8804 entropy (max. 8.0)
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception11
Obfuscated Files or Information
1
OS Credential Dumping
System Service DiscoveryRemote ServicesData from Local System1
Non-Application Layer Protocol
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1646585 Sample: x86.elf Startdate: 24/03/2025 Architecture: LINUX Score: 60 18 198.98.51.68 2->18 20 175.30.53.20, 23 CHINANET-BACKBONENo31Jin-rongStreetCN China 2->20 22 Malicious sample detected (through community Yara rule) 2->22 24 Multi AV Scanner detection for submitted file 2->24 26 Sample is packed with UPX 2->26 8 x86.elf 2->8         started        signatures3 process4 process5 10 x86.elf 8->10         started        process6 12 x86.elf 10->12         started        14 x86.elf 10->14         started        16 x86.elf 10->16         started       
SourceDetectionScannerLabelLink
x86.elf19%ReversingLabsLinux.Trojan.Mirai
No Antivirus matches
No Antivirus matches
No Antivirus matches

Download Network PCAP: filteredfull

NameIPActiveMaliciousAntivirus DetectionReputation
198.98.51.68
unknown
unknowntrue
    unknown
    NameSourceMaliciousAntivirus DetectionReputation
    http://upx.sf.netx86.elffalse
      high
      • No. of IPs < 25%
      • 25% < No. of IPs < 50%
      • 50% < No. of IPs < 75%
      • 75% < No. of IPs
      IPDomainCountryFlagASNASN NameMalicious
      175.30.53.20
      unknownChina
      4134CHINANET-BACKBONENo31Jin-rongStreetCNfalse
      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
      175.30.53.20x86_64.elfGet hashmaliciousUnknownBrowse
        arm.elfGet hashmaliciousUnknownBrowse
          mpsl.elfGet hashmaliciousUnknownBrowse
            gjsoX84ZOy.elfGet hashmaliciousMiraiBrowse
              skwXrj6q72.elfGet hashmaliciousUnknownBrowse
                VqY324s7TO.elfGet hashmaliciousUnknownBrowse
                  1v1A4KluJp.elfGet hashmaliciousUnknownBrowse
                    fI2JqkDmZj.elfGet hashmaliciousUnknownBrowse
                      No context
                      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                      CHINANET-BACKBONENo31Jin-rongStreetCNx86_64.elfGet hashmaliciousUnknownBrowse
                      • 175.30.53.20
                      arm.elfGet hashmaliciousUnknownBrowse
                      • 175.30.53.20
                      mpsl.elfGet hashmaliciousUnknownBrowse
                      • 175.30.53.20
                      resgod.arm.elfGet hashmaliciousMiraiBrowse
                      • 223.8.175.23
                      resgod.arm5.elfGet hashmaliciousMiraiBrowse
                      • 223.8.175.35
                      resgod.sh4.elfGet hashmaliciousMiraiBrowse
                      • 223.8.175.39
                      resgod.mips.elfGet hashmaliciousMiraiBrowse
                      • 223.8.175.35
                      resgod.arm7.elfGet hashmaliciousMiraiBrowse
                      • 223.8.175.38
                      resgod.ppc.elfGet hashmaliciousMiraiBrowse
                      • 223.8.175.37
                      resgod.spc.elfGet hashmaliciousMiraiBrowse
                      • 223.8.175.23
                      No context
                      No context
                      No created / dropped files found
                      File type:ELF 32-bit LSB executable, Intel 80386, version 1 (GNU/Linux), statically linked, no section header
                      Entropy (8bit):7.876189945139115
                      TrID:
                      • ELF Executable and Linkable format (Linux) (4029/14) 50.16%
                      • ELF Executable and Linkable format (generic) (4004/1) 49.84%
                      File name:x86.elf
                      File size:27'180 bytes
                      MD5:84f6600098a7ffd79c0d1d2b3561022c
                      SHA1:816e28410202debd9bb33a5ee5adca4ffceb210f
                      SHA256:feeff674c195b3afcc964d71281ddb2c8f366e30ce12137c7b00b79b2a5ac966
                      SHA512:a3eeea30b58f250d721bd089f4a9c2def1532cecaa5f70922006d23c22361db08b89fb2a7df6144960920d74c92c5ec9788baf8a1526a89ce9d821c0db688632
                      SSDEEP:768:op2yUILNsxUpj3BX5vP8hAlihyle8PzH3Odu:op2F72x8hTyVHP
                      TLSH:57C2E129850EBF5FC9546E72134A5DBE4DF4BCA017EFD1D12C58084B276A0AC6CB0E47
                      File Content Preview:.ELF....................0q..4...........4. ...(.....................+i..+i..............`...`y..`y..................Q.td...............................tUPX!....................^........?d..ELF.......d.......4....4. (.......k.-.#.|.......=......A......>.r.

                      ELF header

                      Class:ELF32
                      Data:2's complement, little endian
                      Version:1 (current)
                      Machine:Intel 80386
                      Version Number:0x1
                      Type:EXEC (Executable file)
                      OS/ABI:UNIX - Linux
                      ABI Version:0
                      Entry Point Address:0xc07130
                      Flags:0x0
                      ELF Header Size:52
                      Program Header Offset:52
                      Program Header Size:32
                      Number of Program Headers:3
                      Section Header Offset:0
                      Section Header Size:40
                      Number of Section Headers:0
                      Header String Table Index:0
                      TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                      LOAD0x00xc010000xc010000x692b0x692b7.88040x5R E0x1000
                      LOAD0x9600x80579600x80579600x00x00.00000x6RW 0x1000
                      GNU_STACK0x00x00x00x00x00.00000x6RW 0x4

                      Download Network PCAP: filteredfull

                      • Total Packets: 87
                      • 53 (DNS)
                      • 23 (Telnet)
                      TimestampSource PortDest PortSource IPDest IP
                      Mar 24, 2025 06:19:38.187649012 CET5411623192.168.2.15175.30.53.20
                      Mar 24, 2025 06:19:39.188914061 CET5411623192.168.2.15175.30.53.20
                      Mar 24, 2025 06:19:41.204860926 CET5411623192.168.2.15175.30.53.20
                      Mar 24, 2025 06:19:45.364763021 CET5411623192.168.2.15175.30.53.20
                      Mar 24, 2025 06:19:49.234806061 CET5411823192.168.2.15175.30.53.20
                      Mar 24, 2025 06:19:50.260632992 CET5411823192.168.2.15175.30.53.20
                      Mar 24, 2025 06:19:52.276552916 CET5411823192.168.2.15175.30.53.20
                      Mar 24, 2025 06:19:56.372495890 CET5411823192.168.2.15175.30.53.20
                      Mar 24, 2025 06:20:00.093164921 CET5412023192.168.2.15175.30.53.20
                      Mar 24, 2025 06:20:01.108325005 CET5412023192.168.2.15175.30.53.20
                      Mar 24, 2025 06:20:03.124252081 CET5412023192.168.2.15175.30.53.20
                      Mar 24, 2025 06:20:07.380151033 CET5412023192.168.2.15175.30.53.20
                      Mar 24, 2025 06:20:11.016341925 CET5412223192.168.2.15175.30.53.20
                      Mar 24, 2025 06:20:12.020013094 CET5412223192.168.2.15175.30.53.20
                      Mar 24, 2025 06:20:14.036147118 CET5412223192.168.2.15175.30.53.20
                      Mar 24, 2025 06:20:18.131886959 CET5412223192.168.2.15175.30.53.20
                      Mar 24, 2025 06:20:46.051156044 CET5412423192.168.2.15175.30.53.20
                      Mar 24, 2025 06:20:47.059075117 CET5412423192.168.2.15175.30.53.20
                      Mar 24, 2025 06:20:49.075059891 CET5412423192.168.2.15175.30.53.20
                      Mar 24, 2025 06:20:53.202946901 CET5412423192.168.2.15175.30.53.20
                      Mar 24, 2025 06:20:57.100472927 CET5412623192.168.2.15175.30.53.20
                      Mar 24, 2025 06:20:58.130801916 CET5412623192.168.2.15175.30.53.20
                      Mar 24, 2025 06:21:00.146745920 CET5412623192.168.2.15175.30.53.20
                      Mar 24, 2025 06:21:04.210830927 CET5412623192.168.2.15175.30.53.20
                      Mar 24, 2025 06:21:07.956974983 CET5412823192.168.2.15175.30.53.20
                      Mar 24, 2025 06:21:08.978738070 CET5412823192.168.2.15175.30.53.20
                      Mar 24, 2025 06:21:10.994647026 CET5412823192.168.2.15175.30.53.20
                      Mar 24, 2025 06:21:15.218619108 CET5412823192.168.2.15175.30.53.20
                      Mar 24, 2025 06:21:18.945929050 CET5413023192.168.2.15175.30.53.20
                      Mar 24, 2025 06:21:19.954261065 CET5413023192.168.2.15175.30.53.20
                      Mar 24, 2025 06:21:21.970176935 CET5413023192.168.2.15175.30.53.20
                      Mar 24, 2025 06:21:26.226116896 CET5413023192.168.2.15175.30.53.20
                      Mar 24, 2025 06:21:29.800331116 CET5413223192.168.2.15175.30.53.20
                      Mar 24, 2025 06:21:30.801976919 CET5413223192.168.2.15175.30.53.20
                      Mar 24, 2025 06:21:32.817940950 CET5413223192.168.2.15175.30.53.20
                      Mar 24, 2025 06:21:36.977840900 CET5413223192.168.2.15175.30.53.20
                      Mar 24, 2025 06:21:40.306853056 CET5413423192.168.2.15175.30.53.20
                      TimestampSource PortDest PortSource IPDest IP
                      Mar 24, 2025 06:19:37.218995094 CET4167353192.168.2.1551.158.108.203
                      Mar 24, 2025 06:19:37.486259937 CET534167351.158.108.203192.168.2.15
                      Mar 24, 2025 06:19:37.486418009 CET3306053192.168.2.1551.158.108.203
                      Mar 24, 2025 06:19:37.661875010 CET533306051.158.108.203192.168.2.15
                      Mar 24, 2025 06:19:37.662022114 CET5940353192.168.2.1551.158.108.203
                      Mar 24, 2025 06:19:37.837088108 CET535940351.158.108.203192.168.2.15
                      Mar 24, 2025 06:19:37.837243080 CET5261553192.168.2.1551.158.108.203
                      Mar 24, 2025 06:19:38.011631012 CET535261551.158.108.203192.168.2.15
                      Mar 24, 2025 06:19:38.011782885 CET3278053192.168.2.1551.158.108.203
                      Mar 24, 2025 06:19:38.187515974 CET533278051.158.108.203192.168.2.15
                      Mar 24, 2025 06:19:48.197577953 CET3674653192.168.2.1581.169.136.222
                      Mar 24, 2025 06:19:48.405495882 CET533674681.169.136.222192.168.2.15
                      Mar 24, 2025 06:19:48.405766964 CET4338653192.168.2.1581.169.136.222
                      Mar 24, 2025 06:19:48.612797976 CET534338681.169.136.222192.168.2.15
                      Mar 24, 2025 06:19:48.613101959 CET4936053192.168.2.1581.169.136.222
                      Mar 24, 2025 06:19:48.822654963 CET534936081.169.136.222192.168.2.15
                      Mar 24, 2025 06:19:48.822844982 CET3509953192.168.2.1581.169.136.222
                      Mar 24, 2025 06:19:49.051115036 CET533509981.169.136.222192.168.2.15
                      Mar 24, 2025 06:19:49.051347017 CET4347153192.168.2.1581.169.136.222
                      Mar 24, 2025 06:19:49.234555960 CET534347181.169.136.222192.168.2.15
                      Mar 24, 2025 06:19:59.244755030 CET5138453192.168.2.15195.10.195.195
                      Mar 24, 2025 06:19:59.416222095 CET5351384195.10.195.195192.168.2.15
                      Mar 24, 2025 06:19:59.416548967 CET3927253192.168.2.15195.10.195.195
                      Mar 24, 2025 06:19:59.585874081 CET5339272195.10.195.195192.168.2.15
                      Mar 24, 2025 06:19:59.586050034 CET4486253192.168.2.15195.10.195.195
                      Mar 24, 2025 06:19:59.754744053 CET5344862195.10.195.195192.168.2.15
                      Mar 24, 2025 06:19:59.754923105 CET4682353192.168.2.15195.10.195.195
                      Mar 24, 2025 06:19:59.923748970 CET5346823195.10.195.195192.168.2.15
                      Mar 24, 2025 06:19:59.924046040 CET5740853192.168.2.15195.10.195.195
                      Mar 24, 2025 06:20:00.092971087 CET5357408195.10.195.195192.168.2.15
                      Mar 24, 2025 06:20:10.094707966 CET5907453192.168.2.1551.77.149.139
                      Mar 24, 2025 06:20:10.282424927 CET535907451.77.149.139192.168.2.15
                      Mar 24, 2025 06:20:10.282582998 CET4895053192.168.2.1551.77.149.139
                      Mar 24, 2025 06:20:10.463174105 CET534895051.77.149.139192.168.2.15
                      Mar 24, 2025 06:20:10.463318110 CET5530353192.168.2.1551.77.149.139
                      Mar 24, 2025 06:20:10.641274929 CET535530351.77.149.139192.168.2.15
                      Mar 24, 2025 06:20:10.641397953 CET3558453192.168.2.1551.77.149.139
                      Mar 24, 2025 06:20:10.835606098 CET533558451.77.149.139192.168.2.15
                      Mar 24, 2025 06:20:10.835927963 CET4477753192.168.2.1551.77.149.139
                      Mar 24, 2025 06:20:11.016204119 CET534477751.77.149.139192.168.2.15
                      Mar 24, 2025 06:20:21.026221037 CET5166353192.168.2.15178.254.22.166
                      Mar 24, 2025 06:20:26.031197071 CET4089653192.168.2.15178.254.22.166
                      Mar 24, 2025 06:20:31.036161900 CET5283153192.168.2.15178.254.22.166
                      Mar 24, 2025 06:20:36.041162968 CET5196753192.168.2.15178.254.22.166
                      Mar 24, 2025 06:20:41.046246052 CET3421853192.168.2.15178.254.22.166
                      Mar 24, 2025 06:20:56.060086012 CET3723953192.168.2.15185.181.61.24
                      Mar 24, 2025 06:20:56.256870985 CET5337239185.181.61.24192.168.2.15
                      Mar 24, 2025 06:20:56.257083893 CET4436553192.168.2.15185.181.61.24
                      Mar 24, 2025 06:20:56.480242014 CET5344365185.181.61.24192.168.2.15
                      Mar 24, 2025 06:20:56.480650902 CET4354653192.168.2.15185.181.61.24
                      Mar 24, 2025 06:20:56.677431107 CET5343546185.181.61.24192.168.2.15
                      Mar 24, 2025 06:20:56.677625895 CET5042753192.168.2.15185.181.61.24
                      Mar 24, 2025 06:20:56.902800083 CET5350427185.181.61.24192.168.2.15
                      Mar 24, 2025 06:20:56.903136015 CET3365553192.168.2.15185.181.61.24
                      Mar 24, 2025 06:20:57.100229025 CET5333655185.181.61.24192.168.2.15
                      Mar 24, 2025 06:21:07.106796980 CET4790353192.168.2.15195.10.195.195
                      Mar 24, 2025 06:21:07.275691032 CET5347903195.10.195.195192.168.2.15
                      Mar 24, 2025 06:21:07.276168108 CET4056753192.168.2.15195.10.195.195
                      Mar 24, 2025 06:21:07.446822882 CET5340567195.10.195.195192.168.2.15
                      Mar 24, 2025 06:21:07.447288036 CET4955453192.168.2.15195.10.195.195
                      Mar 24, 2025 06:21:07.617966890 CET5349554195.10.195.195192.168.2.15
                      Mar 24, 2025 06:21:07.618469954 CET5588653192.168.2.15195.10.195.195
                      Mar 24, 2025 06:21:07.786973000 CET5355886195.10.195.195192.168.2.15
                      Mar 24, 2025 06:21:07.787405014 CET5327453192.168.2.15195.10.195.195
                      Mar 24, 2025 06:21:07.956460953 CET5353274195.10.195.195192.168.2.15
                      Mar 24, 2025 06:21:17.966409922 CET3423053192.168.2.1551.158.108.203
                      Mar 24, 2025 06:21:18.240370989 CET533423051.158.108.203192.168.2.15
                      Mar 24, 2025 06:21:18.240684032 CET3366753192.168.2.1551.158.108.203
                      Mar 24, 2025 06:21:18.414995909 CET533366751.158.108.203192.168.2.15
                      Mar 24, 2025 06:21:18.415203094 CET4245153192.168.2.1551.158.108.203
                      Mar 24, 2025 06:21:18.591900110 CET534245151.158.108.203192.168.2.15
                      Mar 24, 2025 06:21:18.592206955 CET4897453192.168.2.1551.158.108.203
                      Mar 24, 2025 06:21:18.769524097 CET534897451.158.108.203192.168.2.15
                      Mar 24, 2025 06:21:18.769793034 CET4537453192.168.2.1551.158.108.203
                      Mar 24, 2025 06:21:18.945784092 CET534537451.158.108.203192.168.2.15
                      Mar 24, 2025 06:21:28.954082966 CET5168853192.168.2.15195.10.195.195
                      Mar 24, 2025 06:21:29.124423027 CET5351688195.10.195.195192.168.2.15
                      Mar 24, 2025 06:21:29.124667883 CET4125253192.168.2.15195.10.195.195
                      Mar 24, 2025 06:21:29.293060064 CET5341252195.10.195.195192.168.2.15
                      Mar 24, 2025 06:21:29.293313980 CET3942653192.168.2.15195.10.195.195
                      Mar 24, 2025 06:21:29.461601973 CET5339426195.10.195.195192.168.2.15
                      Mar 24, 2025 06:21:29.462126017 CET3509853192.168.2.15195.10.195.195
                      Mar 24, 2025 06:21:29.630666971 CET5335098195.10.195.195192.168.2.15
                      Mar 24, 2025 06:21:29.630928993 CET4615953192.168.2.15195.10.195.195
                      Mar 24, 2025 06:21:29.800165892 CET5346159195.10.195.195192.168.2.15
                      Mar 24, 2025 06:21:39.809820890 CET5450353192.168.2.15134.195.4.2
                      Mar 24, 2025 06:21:39.907480001 CET5354503134.195.4.2192.168.2.15
                      Mar 24, 2025 06:21:39.907972097 CET5750753192.168.2.15134.195.4.2
                      Mar 24, 2025 06:21:40.007348061 CET5357507134.195.4.2192.168.2.15
                      Mar 24, 2025 06:21:40.007606030 CET5156653192.168.2.15134.195.4.2
                      Mar 24, 2025 06:21:40.104954958 CET5351566134.195.4.2192.168.2.15
                      Mar 24, 2025 06:21:40.105248928 CET5012153192.168.2.15134.195.4.2
                      Mar 24, 2025 06:21:40.204768896 CET5350121134.195.4.2192.168.2.15
                      Mar 24, 2025 06:21:40.205084085 CET4404753192.168.2.15134.195.4.2
                      Mar 24, 2025 06:21:40.306413889 CET5344047134.195.4.2192.168.2.15
                      TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                      Mar 24, 2025 06:19:37.218995094 CET192.168.2.1551.158.108.2030x5971Standard query (0)198.98.51.68A (IP address)IN (0x0001)false
                      Mar 24, 2025 06:19:37.486418009 CET192.168.2.1551.158.108.2030x5971Standard query (0)198.98.51.68A (IP address)IN (0x0001)false
                      Mar 24, 2025 06:19:37.662022114 CET192.168.2.1551.158.108.2030x5971Standard query (0)198.98.51.68A (IP address)IN (0x0001)false
                      Mar 24, 2025 06:19:37.837243080 CET192.168.2.1551.158.108.2030x5971Standard query (0)198.98.51.68A (IP address)IN (0x0001)false
                      Mar 24, 2025 06:19:38.011782885 CET192.168.2.1551.158.108.2030x5971Standard query (0)198.98.51.68A (IP address)IN (0x0001)false
                      Mar 24, 2025 06:19:48.197577953 CET192.168.2.1581.169.136.2220xa5eStandard query (0)198.98.51.68A (IP address)IN (0x0001)false
                      Mar 24, 2025 06:19:48.405766964 CET192.168.2.1581.169.136.2220xa5eStandard query (0)198.98.51.68A (IP address)IN (0x0001)false
                      Mar 24, 2025 06:19:48.613101959 CET192.168.2.1581.169.136.2220xa5eStandard query (0)198.98.51.68A (IP address)IN (0x0001)false
                      Mar 24, 2025 06:19:48.822844982 CET192.168.2.1581.169.136.2220xa5eStandard query (0)198.98.51.68A (IP address)IN (0x0001)false
                      Mar 24, 2025 06:19:49.051347017 CET192.168.2.1581.169.136.2220xa5eStandard query (0)198.98.51.68A (IP address)IN (0x0001)false
                      Mar 24, 2025 06:19:59.244755030 CET192.168.2.15195.10.195.1950x1c81Standard query (0)198.98.51.68A (IP address)IN (0x0001)false
                      Mar 24, 2025 06:19:59.416548967 CET192.168.2.15195.10.195.1950x1c81Standard query (0)198.98.51.68A (IP address)IN (0x0001)false
                      Mar 24, 2025 06:19:59.586050034 CET192.168.2.15195.10.195.1950x1c81Standard query (0)198.98.51.68A (IP address)IN (0x0001)false
                      Mar 24, 2025 06:19:59.754923105 CET192.168.2.15195.10.195.1950x1c81Standard query (0)198.98.51.68A (IP address)IN (0x0001)false
                      Mar 24, 2025 06:19:59.924046040 CET192.168.2.15195.10.195.1950x1c81Standard query (0)198.98.51.68A (IP address)IN (0x0001)false
                      Mar 24, 2025 06:20:10.094707966 CET192.168.2.1551.77.149.1390x32e7Standard query (0)198.98.51.68A (IP address)IN (0x0001)false
                      Mar 24, 2025 06:20:10.282582998 CET192.168.2.1551.77.149.1390x32e7Standard query (0)198.98.51.68A (IP address)IN (0x0001)false
                      Mar 24, 2025 06:20:10.463318110 CET192.168.2.1551.77.149.1390x32e7Standard query (0)198.98.51.68A (IP address)IN (0x0001)false
                      Mar 24, 2025 06:20:10.641397953 CET192.168.2.1551.77.149.1390x32e7Standard query (0)198.98.51.68A (IP address)IN (0x0001)false
                      Mar 24, 2025 06:20:10.835927963 CET192.168.2.1551.77.149.1390x32e7Standard query (0)198.98.51.68A (IP address)IN (0x0001)false
                      Mar 24, 2025 06:20:21.026221037 CET192.168.2.15178.254.22.1660x8127Standard query (0)198.98.51.68A (IP address)IN (0x0001)false
                      Mar 24, 2025 06:20:26.031197071 CET192.168.2.15178.254.22.1660x8127Standard query (0)198.98.51.68A (IP address)IN (0x0001)false
                      Mar 24, 2025 06:20:31.036161900 CET192.168.2.15178.254.22.1660x8127Standard query (0)198.98.51.68A (IP address)IN (0x0001)false
                      Mar 24, 2025 06:20:36.041162968 CET192.168.2.15178.254.22.1660x8127Standard query (0)198.98.51.68A (IP address)IN (0x0001)false
                      Mar 24, 2025 06:20:41.046246052 CET192.168.2.15178.254.22.1660x8127Standard query (0)198.98.51.68A (IP address)IN (0x0001)false
                      Mar 24, 2025 06:20:56.060086012 CET192.168.2.15185.181.61.240xfb2Standard query (0)198.98.51.68A (IP address)IN (0x0001)false
                      Mar 24, 2025 06:20:56.257083893 CET192.168.2.15185.181.61.240xfb2Standard query (0)198.98.51.68A (IP address)IN (0x0001)false
                      Mar 24, 2025 06:20:56.480650902 CET192.168.2.15185.181.61.240xfb2Standard query (0)198.98.51.68A (IP address)IN (0x0001)false
                      Mar 24, 2025 06:20:56.677625895 CET192.168.2.15185.181.61.240xfb2Standard query (0)198.98.51.68A (IP address)IN (0x0001)false
                      Mar 24, 2025 06:20:56.903136015 CET192.168.2.15185.181.61.240xfb2Standard query (0)198.98.51.68A (IP address)IN (0x0001)false
                      Mar 24, 2025 06:21:07.106796980 CET192.168.2.15195.10.195.1950xfc94Standard query (0)198.98.51.68A (IP address)IN (0x0001)false
                      Mar 24, 2025 06:21:07.276168108 CET192.168.2.15195.10.195.1950xfc94Standard query (0)198.98.51.68A (IP address)IN (0x0001)false
                      Mar 24, 2025 06:21:07.447288036 CET192.168.2.15195.10.195.1950xfc94Standard query (0)198.98.51.68A (IP address)IN (0x0001)false
                      Mar 24, 2025 06:21:07.618469954 CET192.168.2.15195.10.195.1950xfc94Standard query (0)198.98.51.68A (IP address)IN (0x0001)false
                      Mar 24, 2025 06:21:07.787405014 CET192.168.2.15195.10.195.1950xfc94Standard query (0)198.98.51.68A (IP address)IN (0x0001)false
                      Mar 24, 2025 06:21:17.966409922 CET192.168.2.1551.158.108.2030xbff4Standard query (0)198.98.51.68A (IP address)IN (0x0001)false
                      Mar 24, 2025 06:21:18.240684032 CET192.168.2.1551.158.108.2030xbff4Standard query (0)198.98.51.68A (IP address)IN (0x0001)false
                      Mar 24, 2025 06:21:18.415203094 CET192.168.2.1551.158.108.2030xbff4Standard query (0)198.98.51.68A (IP address)IN (0x0001)false
                      Mar 24, 2025 06:21:18.592206955 CET192.168.2.1551.158.108.2030xbff4Standard query (0)198.98.51.68A (IP address)IN (0x0001)false
                      Mar 24, 2025 06:21:18.769793034 CET192.168.2.1551.158.108.2030xbff4Standard query (0)198.98.51.68A (IP address)IN (0x0001)false
                      Mar 24, 2025 06:21:28.954082966 CET192.168.2.15195.10.195.1950xedbbStandard query (0)198.98.51.68A (IP address)IN (0x0001)false
                      Mar 24, 2025 06:21:29.124667883 CET192.168.2.15195.10.195.1950xedbbStandard query (0)198.98.51.68A (IP address)IN (0x0001)false
                      Mar 24, 2025 06:21:29.293313980 CET192.168.2.15195.10.195.1950xedbbStandard query (0)198.98.51.68A (IP address)IN (0x0001)false
                      Mar 24, 2025 06:21:29.462126017 CET192.168.2.15195.10.195.1950xedbbStandard query (0)198.98.51.68A (IP address)IN (0x0001)false
                      Mar 24, 2025 06:21:29.630928993 CET192.168.2.15195.10.195.1950xedbbStandard query (0)198.98.51.68A (IP address)IN (0x0001)false
                      Mar 24, 2025 06:21:39.809820890 CET192.168.2.15134.195.4.20x42b9Standard query (0)198.98.51.68A (IP address)IN (0x0001)false
                      Mar 24, 2025 06:21:39.907972097 CET192.168.2.15134.195.4.20x42b9Standard query (0)198.98.51.68A (IP address)IN (0x0001)false
                      Mar 24, 2025 06:21:40.007606030 CET192.168.2.15134.195.4.20x42b9Standard query (0)198.98.51.68A (IP address)IN (0x0001)false
                      Mar 24, 2025 06:21:40.105248928 CET192.168.2.15134.195.4.20x42b9Standard query (0)198.98.51.68A (IP address)IN (0x0001)false
                      Mar 24, 2025 06:21:40.205084085 CET192.168.2.15134.195.4.20x42b9Standard query (0)198.98.51.68A (IP address)IN (0x0001)false
                      TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                      Mar 24, 2025 06:19:37.486259937 CET51.158.108.203192.168.2.150x5971Name error (3)198.98.51.68nonenoneA (IP address)IN (0x0001)false
                      Mar 24, 2025 06:19:37.661875010 CET51.158.108.203192.168.2.150x5971Name error (3)198.98.51.68nonenoneA (IP address)IN (0x0001)false
                      Mar 24, 2025 06:19:37.837088108 CET51.158.108.203192.168.2.150x5971Name error (3)198.98.51.68nonenoneA (IP address)IN (0x0001)false
                      Mar 24, 2025 06:19:38.011631012 CET51.158.108.203192.168.2.150x5971Name error (3)198.98.51.68nonenoneA (IP address)IN (0x0001)false
                      Mar 24, 2025 06:19:38.187515974 CET51.158.108.203192.168.2.150x5971Name error (3)198.98.51.68nonenoneA (IP address)IN (0x0001)false
                      Mar 24, 2025 06:19:48.405495882 CET81.169.136.222192.168.2.150xa5eName error (3)198.98.51.68nonenoneA (IP address)IN (0x0001)false
                      Mar 24, 2025 06:19:48.612797976 CET81.169.136.222192.168.2.150xa5eName error (3)198.98.51.68nonenoneA (IP address)IN (0x0001)false
                      Mar 24, 2025 06:19:48.822654963 CET81.169.136.222192.168.2.150xa5eName error (3)198.98.51.68nonenoneA (IP address)IN (0x0001)false
                      Mar 24, 2025 06:19:49.051115036 CET81.169.136.222192.168.2.150xa5eName error (3)198.98.51.68nonenoneA (IP address)IN (0x0001)false
                      Mar 24, 2025 06:19:49.234555960 CET81.169.136.222192.168.2.150xa5eName error (3)198.98.51.68nonenoneA (IP address)IN (0x0001)false
                      Mar 24, 2025 06:19:59.416222095 CET195.10.195.195192.168.2.150x1c81Name error (3)198.98.51.68nonenoneA (IP address)IN (0x0001)false
                      Mar 24, 2025 06:19:59.585874081 CET195.10.195.195192.168.2.150x1c81Name error (3)198.98.51.68nonenoneA (IP address)IN (0x0001)false
                      Mar 24, 2025 06:19:59.754744053 CET195.10.195.195192.168.2.150x1c81Name error (3)198.98.51.68nonenoneA (IP address)IN (0x0001)false
                      Mar 24, 2025 06:19:59.923748970 CET195.10.195.195192.168.2.150x1c81Name error (3)198.98.51.68nonenoneA (IP address)IN (0x0001)false
                      Mar 24, 2025 06:20:00.092971087 CET195.10.195.195192.168.2.150x1c81Name error (3)198.98.51.68nonenoneA (IP address)IN (0x0001)false
                      Mar 24, 2025 06:20:10.282424927 CET51.77.149.139192.168.2.150x32e7Name error (3)198.98.51.68nonenoneA (IP address)IN (0x0001)false
                      Mar 24, 2025 06:20:10.463174105 CET51.77.149.139192.168.2.150x32e7Name error (3)198.98.51.68nonenoneA (IP address)IN (0x0001)false
                      Mar 24, 2025 06:20:10.641274929 CET51.77.149.139192.168.2.150x32e7Name error (3)198.98.51.68nonenoneA (IP address)IN (0x0001)false
                      Mar 24, 2025 06:20:10.835606098 CET51.77.149.139192.168.2.150x32e7Name error (3)198.98.51.68nonenoneA (IP address)IN (0x0001)false
                      Mar 24, 2025 06:20:11.016204119 CET51.77.149.139192.168.2.150x32e7Name error (3)198.98.51.68nonenoneA (IP address)IN (0x0001)false
                      Mar 24, 2025 06:20:56.256870985 CET185.181.61.24192.168.2.150xfb2Name error (3)198.98.51.68nonenoneA (IP address)IN (0x0001)false
                      Mar 24, 2025 06:20:56.480242014 CET185.181.61.24192.168.2.150xfb2Name error (3)198.98.51.68nonenoneA (IP address)IN (0x0001)false
                      Mar 24, 2025 06:20:56.677431107 CET185.181.61.24192.168.2.150xfb2Name error (3)198.98.51.68nonenoneA (IP address)IN (0x0001)false
                      Mar 24, 2025 06:20:56.902800083 CET185.181.61.24192.168.2.150xfb2Name error (3)198.98.51.68nonenoneA (IP address)IN (0x0001)false
                      Mar 24, 2025 06:20:57.100229025 CET185.181.61.24192.168.2.150xfb2Name error (3)198.98.51.68nonenoneA (IP address)IN (0x0001)false
                      Mar 24, 2025 06:21:07.275691032 CET195.10.195.195192.168.2.150xfc94Name error (3)198.98.51.68nonenoneA (IP address)IN (0x0001)false
                      Mar 24, 2025 06:21:07.446822882 CET195.10.195.195192.168.2.150xfc94Name error (3)198.98.51.68nonenoneA (IP address)IN (0x0001)false
                      Mar 24, 2025 06:21:07.617966890 CET195.10.195.195192.168.2.150xfc94Name error (3)198.98.51.68nonenoneA (IP address)IN (0x0001)false
                      Mar 24, 2025 06:21:07.786973000 CET195.10.195.195192.168.2.150xfc94Name error (3)198.98.51.68nonenoneA (IP address)IN (0x0001)false
                      Mar 24, 2025 06:21:07.956460953 CET195.10.195.195192.168.2.150xfc94Name error (3)198.98.51.68nonenoneA (IP address)IN (0x0001)false
                      Mar 24, 2025 06:21:18.240370989 CET51.158.108.203192.168.2.150xbff4Name error (3)198.98.51.68nonenoneA (IP address)IN (0x0001)false
                      Mar 24, 2025 06:21:18.414995909 CET51.158.108.203192.168.2.150xbff4Name error (3)198.98.51.68nonenoneA (IP address)IN (0x0001)false
                      Mar 24, 2025 06:21:18.591900110 CET51.158.108.203192.168.2.150xbff4Name error (3)198.98.51.68nonenoneA (IP address)IN (0x0001)false
                      Mar 24, 2025 06:21:18.769524097 CET51.158.108.203192.168.2.150xbff4Name error (3)198.98.51.68nonenoneA (IP address)IN (0x0001)false
                      Mar 24, 2025 06:21:18.945784092 CET51.158.108.203192.168.2.150xbff4Name error (3)198.98.51.68nonenoneA (IP address)IN (0x0001)false
                      Mar 24, 2025 06:21:29.124423027 CET195.10.195.195192.168.2.150xedbbName error (3)198.98.51.68nonenoneA (IP address)IN (0x0001)false
                      Mar 24, 2025 06:21:29.293060064 CET195.10.195.195192.168.2.150xedbbName error (3)198.98.51.68nonenoneA (IP address)IN (0x0001)false
                      Mar 24, 2025 06:21:29.461601973 CET195.10.195.195192.168.2.150xedbbName error (3)198.98.51.68nonenoneA (IP address)IN (0x0001)false
                      Mar 24, 2025 06:21:29.630666971 CET195.10.195.195192.168.2.150xedbbName error (3)198.98.51.68nonenoneA (IP address)IN (0x0001)false
                      Mar 24, 2025 06:21:29.800165892 CET195.10.195.195192.168.2.150xedbbName error (3)198.98.51.68nonenoneA (IP address)IN (0x0001)false
                      Mar 24, 2025 06:21:39.907480001 CET134.195.4.2192.168.2.150x42b9Name error (3)198.98.51.68nonenoneA (IP address)IN (0x0001)false
                      Mar 24, 2025 06:21:40.007348061 CET134.195.4.2192.168.2.150x42b9Name error (3)198.98.51.68nonenoneA (IP address)IN (0x0001)false
                      Mar 24, 2025 06:21:40.104954958 CET134.195.4.2192.168.2.150x42b9Name error (3)198.98.51.68nonenoneA (IP address)IN (0x0001)false
                      Mar 24, 2025 06:21:40.204768896 CET134.195.4.2192.168.2.150x42b9Name error (3)198.98.51.68nonenoneA (IP address)IN (0x0001)false
                      Mar 24, 2025 06:21:40.306413889 CET134.195.4.2192.168.2.150x42b9Name error (3)198.98.51.68nonenoneA (IP address)IN (0x0001)false

                      System Behavior

                      Start time (UTC):05:19:36
                      Start date (UTC):24/03/2025
                      Path:/tmp/x86.elf
                      Arguments:/tmp/x86.elf
                      File size:27180 bytes
                      MD5 hash:84f6600098a7ffd79c0d1d2b3561022c

                      Start time (UTC):05:19:36
                      Start date (UTC):24/03/2025
                      Path:/tmp/x86.elf
                      Arguments:-
                      File size:27180 bytes
                      MD5 hash:84f6600098a7ffd79c0d1d2b3561022c

                      Start time (UTC):05:19:36
                      Start date (UTC):24/03/2025
                      Path:/tmp/x86.elf
                      Arguments:-
                      File size:27180 bytes
                      MD5 hash:84f6600098a7ffd79c0d1d2b3561022c

                      Start time (UTC):05:19:36
                      Start date (UTC):24/03/2025
                      Path:/tmp/x86.elf
                      Arguments:-
                      File size:27180 bytes
                      MD5 hash:84f6600098a7ffd79c0d1d2b3561022c

                      Start time (UTC):05:19:36
                      Start date (UTC):24/03/2025
                      Path:/tmp/x86.elf
                      Arguments:-
                      File size:27180 bytes
                      MD5 hash:84f6600098a7ffd79c0d1d2b3561022c