Edit tour

Linux Analysis Report
ub8ehJSePAfc9FYqZIT6.ppc.elf

Overview

General Information

Sample name:ub8ehJSePAfc9FYqZIT6.ppc.elf
Analysis ID:1649631
MD5:6ce96062fd4f4559c3d64fa4e640610e
SHA1:97d9020bef4fafc874da871204781b117b359919
SHA256:7c5ece8b04893af5937cba1b096ad703ffde47ff771891ca393356e33112fa8b
Tags:elfuser-abuse_ch
Infos:

Detection

Score:68
Range:0 - 100

Signatures

Antivirus / Scanner detection for submitted sample
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Sample is packed with UPX
Detected TCP or UDP traffic on non-standard ports
ELF contains segments with high entropy indicating compressed/encrypted content
Enumerates processes within the "proc" file system
Sample contains only a LOAD segment without any section mappings
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Uses the "uname" system call to query kernel version information (possible evasion)
Yara signature match

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
Joe Sandbox version:42.0.0 Malachite
Analysis ID:1649631
Start date and time:2025-03-27 00:26:58 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 5m 12s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:ub8ehJSePAfc9FYqZIT6.ppc.elf
Detection:MAL
Classification:mal68.evad.linELF@0/0@0/0
Command:/tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf
PID:6280
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
lzrd cock fest"/proc/"/exe
Standard Error:
  • system is lnxubuntu20
  • cleanup
SourceRuleDescriptionAuthorStrings
6284.1.00007ff288014000.00007ff288017000.rwx.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0x350:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x364:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x378:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x38c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3a0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3b4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3c8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3dc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3f0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x404:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x418:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x42c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x440:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x454:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x468:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x47c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x490:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x4a4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x4b8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x4cc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x4e0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
6290.1.00007ff288014000.00007ff288017000.rwx.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0x350:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x364:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x378:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x38c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3a0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3b4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3c8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3dc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3f0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x404:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x418:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x42c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x440:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x454:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x468:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x47c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x490:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x4a4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x4b8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x4cc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x4e0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
6282.1.00007ff288014000.00007ff288017000.rwx.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0x350:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x364:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x378:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x38c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3a0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3b4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3c8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3dc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3f0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x404:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x418:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x42c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x440:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x454:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x468:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x47c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x490:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x4a4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x4b8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x4cc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x4e0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
6280.1.00007ff288014000.00007ff288017000.rwx.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0x350:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x364:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x378:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x38c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3a0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3b4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3c8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3dc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3f0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x404:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x418:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x42c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x440:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x454:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x468:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x47c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x490:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x4a4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x4b8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x4cc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x4e0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
Process Memory Space: ub8ehJSePAfc9FYqZIT6.ppc.elf PID: 6280Linux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0x5c93:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x5ca7:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x5cbb:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x5ccf:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x5ce3:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x5cf7:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x5d0b:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x5d1f:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x5d33:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x5d47:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x5d5b:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x5d6f:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x5d83:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x5d97:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x5dab:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x5dbf:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x5dd3:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x5de7:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x5dfb:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x5e0f:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x5e23:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
Click to see the 3 entries
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: ub8ehJSePAfc9FYqZIT6.ppc.elfAvira: detected
Source: ub8ehJSePAfc9FYqZIT6.ppc.elfVirustotal: Detection: 42%Perma Link
Source: ub8ehJSePAfc9FYqZIT6.ppc.elfReversingLabs: Detection: 52%
Source: global trafficTCP traffic: 192.168.2.23:45366 -> 61.7.209.116:3778
Source: global trafficTCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
Source: global trafficTCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
Source: global trafficTCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
Source: unknownTCP traffic detected without corresponding DNS query: 61.7.209.116
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 61.7.209.116
Source: unknownTCP traffic detected without corresponding DNS query: 61.7.209.116
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 61.7.209.116
Source: unknownTCP traffic detected without corresponding DNS query: 61.7.209.116
Source: unknownTCP traffic detected without corresponding DNS query: 61.7.209.116
Source: unknownTCP traffic detected without corresponding DNS query: 61.7.209.116
Source: unknownTCP traffic detected without corresponding DNS query: 61.7.209.116
Source: unknownTCP traffic detected without corresponding DNS query: 61.7.209.116
Source: unknownTCP traffic detected without corresponding DNS query: 61.7.209.116
Source: unknownTCP traffic detected without corresponding DNS query: 61.7.209.116
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 61.7.209.116
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 61.7.209.116
Source: unknownTCP traffic detected without corresponding DNS query: 61.7.209.116
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 61.7.209.116
Source: unknownTCP traffic detected without corresponding DNS query: 61.7.209.116
Source: unknownTCP traffic detected without corresponding DNS query: 61.7.209.116
Source: unknownTCP traffic detected without corresponding DNS query: 61.7.209.116
Source: unknownTCP traffic detected without corresponding DNS query: 61.7.209.116
Source: unknownTCP traffic detected without corresponding DNS query: 61.7.209.116
Source: unknownTCP traffic detected without corresponding DNS query: 61.7.209.116
Source: unknownTCP traffic detected without corresponding DNS query: 61.7.209.116
Source: unknownTCP traffic detected without corresponding DNS query: 61.7.209.116
Source: unknownTCP traffic detected without corresponding DNS query: 61.7.209.116
Source: unknownTCP traffic detected without corresponding DNS query: 61.7.209.116
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 61.7.209.116
Source: unknownTCP traffic detected without corresponding DNS query: 61.7.209.116
Source: unknownTCP traffic detected without corresponding DNS query: 61.7.209.116
Source: unknownTCP traffic detected without corresponding DNS query: 61.7.209.116
Source: unknownTCP traffic detected without corresponding DNS query: 61.7.209.116
Source: unknownTCP traffic detected without corresponding DNS query: 61.7.209.116
Source: unknownTCP traffic detected without corresponding DNS query: 61.7.209.116
Source: unknownTCP traffic detected without corresponding DNS query: 61.7.209.116
Source: unknownTCP traffic detected without corresponding DNS query: 61.7.209.116
Source: unknownTCP traffic detected without corresponding DNS query: 61.7.209.116
Source: unknownTCP traffic detected without corresponding DNS query: 61.7.209.116
Source: unknownTCP traffic detected without corresponding DNS query: 61.7.209.116
Source: unknownTCP traffic detected without corresponding DNS query: 61.7.209.116
Source: unknownTCP traffic detected without corresponding DNS query: 61.7.209.116
Source: unknownTCP traffic detected without corresponding DNS query: 61.7.209.116
Source: unknownTCP traffic detected without corresponding DNS query: 61.7.209.116
Source: unknownTCP traffic detected without corresponding DNS query: 61.7.209.116
Source: unknownTCP traffic detected without corresponding DNS query: 61.7.209.116
Source: unknownTCP traffic detected without corresponding DNS query: 61.7.209.116
Source: ub8ehJSePAfc9FYqZIT6.ppc.elfString found in binary or memory: http://upx.sf.net
Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443

System Summary

barindex
Source: 6284.1.00007ff288014000.00007ff288017000.rwx.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: 6290.1.00007ff288014000.00007ff288017000.rwx.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: 6282.1.00007ff288014000.00007ff288017000.rwx.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: 6280.1.00007ff288014000.00007ff288017000.rwx.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: Process Memory Space: ub8ehJSePAfc9FYqZIT6.ppc.elf PID: 6280, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: Process Memory Space: ub8ehJSePAfc9FYqZIT6.ppc.elf PID: 6282, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: Process Memory Space: ub8ehJSePAfc9FYqZIT6.ppc.elf PID: 6284, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: Process Memory Space: ub8ehJSePAfc9FYqZIT6.ppc.elf PID: 6290, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: LOAD without section mappingsProgram segment: 0x100000
Source: 6284.1.00007ff288014000.00007ff288017000.rwx.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: 6290.1.00007ff288014000.00007ff288017000.rwx.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: 6282.1.00007ff288014000.00007ff288017000.rwx.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: 6280.1.00007ff288014000.00007ff288017000.rwx.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: Process Memory Space: ub8ehJSePAfc9FYqZIT6.ppc.elf PID: 6280, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: Process Memory Space: ub8ehJSePAfc9FYqZIT6.ppc.elf PID: 6282, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: Process Memory Space: ub8ehJSePAfc9FYqZIT6.ppc.elf PID: 6284, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: Process Memory Space: ub8ehJSePAfc9FYqZIT6.ppc.elf PID: 6290, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: classification engineClassification label: mal68.evad.linELF@0/0@0/0

Data Obfuscation

barindex
Source: initial sampleString containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $
Source: initial sampleString containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $
Source: initial sampleString containing UPX found: $Id: UPX 3.94 Copyright (C) 1996-2017 the UPX Team. All Rights Reserved. $
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6280)File opened: /proc/6112/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6280)File opened: /proc/6235/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6280)File opened: /proc/1582/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6280)File opened: /proc/3088/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6280)File opened: /proc/230/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6280)File opened: /proc/110/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6280)File opened: /proc/231/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6280)File opened: /proc/111/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6280)File opened: /proc/232/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6280)File opened: /proc/1579/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6280)File opened: /proc/112/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6280)File opened: /proc/233/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6280)File opened: /proc/1699/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6280)File opened: /proc/113/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6280)File opened: /proc/234/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6280)File opened: /proc/1335/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6280)File opened: /proc/1698/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6280)File opened: /proc/114/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6280)File opened: /proc/235/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6280)File opened: /proc/1334/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6280)File opened: /proc/1576/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6280)File opened: /proc/2302/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6280)File opened: /proc/115/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6280)File opened: /proc/236/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6280)File opened: /proc/116/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6280)File opened: /proc/237/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6280)File opened: /proc/117/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6280)File opened: /proc/118/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6280)File opened: /proc/910/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6280)File opened: /proc/119/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6280)File opened: /proc/912/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6280)File opened: /proc/10/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6280)File opened: /proc/2307/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6280)File opened: /proc/11/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6280)File opened: /proc/918/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6280)File opened: /proc/12/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6280)File opened: /proc/13/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6280)File opened: /proc/14/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6280)File opened: /proc/15/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6280)File opened: /proc/16/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6280)File opened: /proc/17/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6280)File opened: /proc/18/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6280)File opened: /proc/1594/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6280)File opened: /proc/120/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6280)File opened: /proc/121/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6280)File opened: /proc/1349/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6280)File opened: /proc/1/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6280)File opened: /proc/122/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6280)File opened: /proc/243/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6280)File opened: /proc/123/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6280)File opened: /proc/2/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6280)File opened: /proc/124/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6280)File opened: /proc/3/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6280)File opened: /proc/4/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6280)File opened: /proc/125/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6280)File opened: /proc/126/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6280)File opened: /proc/1344/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6280)File opened: /proc/1465/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6280)File opened: /proc/1586/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6280)File opened: /proc/127/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6280)File opened: /proc/6/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6280)File opened: /proc/248/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6280)File opened: /proc/128/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6280)File opened: /proc/249/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6280)File opened: /proc/1463/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6280)File opened: /proc/800/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6280)File opened: /proc/9/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6280)File opened: /proc/801/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6280)File opened: /proc/20/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6280)File opened: /proc/21/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6280)File opened: /proc/1900/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6280)File opened: /proc/22/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6280)File opened: /proc/23/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6280)File opened: /proc/24/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6280)File opened: /proc/25/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6280)File opened: /proc/26/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6280)File opened: /proc/27/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6280)File opened: /proc/28/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6280)File opened: /proc/29/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6280)File opened: /proc/491/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6280)File opened: /proc/250/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6280)File opened: /proc/130/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6280)File opened: /proc/251/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6280)File opened: /proc/252/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6280)File opened: /proc/132/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6280)File opened: /proc/253/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6280)File opened: /proc/254/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6280)File opened: /proc/255/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6280)File opened: /proc/256/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6280)File opened: /proc/1599/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6280)File opened: /proc/257/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6280)File opened: /proc/1477/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6280)File opened: /proc/379/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6280)File opened: /proc/258/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6280)File opened: /proc/1476/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6280)File opened: /proc/259/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6280)File opened: /proc/1475/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6280)File opened: /proc/936/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6280)File opened: /proc/30/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6280)File opened: /proc/2208/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6280)File opened: /proc/35/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6280)File opened: /proc/6265/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6280)File opened: /proc/6264/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6280)File opened: /proc/1809/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6280)File opened: /proc/1494/statusJump to behavior
Source: ub8ehJSePAfc9FYqZIT6.ppc.elfSubmission file: segment LOAD with 7.9644 entropy (max. 8.0)
Source: /tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf (PID: 6280)Queries kernel information via 'uname': Jump to behavior
Source: ub8ehJSePAfc9FYqZIT6.ppc.elf, 6282.1.000055c58d36b000.000055c58d41b000.rw-.sdmpBinary or memory string: !/etc/qemu-binfmt/ppc11!hotpluggableq
Source: ub8ehJSePAfc9FYqZIT6.ppc.elf, 6280.1.000055c58d36b000.000055c58d43c000.rw-.sdmp, ub8ehJSePAfc9FYqZIT6.ppc.elf, 6284.1.000055c58d36b000.000055c58d41b000.rw-.sdmp, ub8ehJSePAfc9FYqZIT6.ppc.elf, 6290.1.000055c58d36b000.000055c58d43c000.rw-.sdmpBinary or memory string: !/etc/qemu-binfmt/ppc1
Source: ub8ehJSePAfc9FYqZIT6.ppc.elf, 6280.1.000055c58d36b000.000055c58d43c000.rw-.sdmp, ub8ehJSePAfc9FYqZIT6.ppc.elf, 6282.1.000055c58d36b000.000055c58d41b000.rw-.sdmp, ub8ehJSePAfc9FYqZIT6.ppc.elf, 6284.1.000055c58d36b000.000055c58d41b000.rw-.sdmp, ub8ehJSePAfc9FYqZIT6.ppc.elf, 6290.1.000055c58d36b000.000055c58d43c000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/ppc
Source: ub8ehJSePAfc9FYqZIT6.ppc.elf, 6280.1.00007fff5c833000.00007fff5c854000.rw-.sdmp, ub8ehJSePAfc9FYqZIT6.ppc.elf, 6282.1.00007fff5c833000.00007fff5c854000.rw-.sdmp, ub8ehJSePAfc9FYqZIT6.ppc.elf, 6284.1.00007fff5c833000.00007fff5c854000.rw-.sdmp, ub8ehJSePAfc9FYqZIT6.ppc.elf, 6290.1.00007fff5c833000.00007fff5c854000.rw-.sdmpBinary or memory string: /usr/bin/qemu-ppc
Source: ub8ehJSePAfc9FYqZIT6.ppc.elf, 6280.1.00007fff5c833000.00007fff5c854000.rw-.sdmp, ub8ehJSePAfc9FYqZIT6.ppc.elf, 6282.1.00007fff5c833000.00007fff5c854000.rw-.sdmp, ub8ehJSePAfc9FYqZIT6.ppc.elf, 6284.1.00007fff5c833000.00007fff5c854000.rw-.sdmp, ub8ehJSePAfc9FYqZIT6.ppc.elf, 6290.1.00007fff5c833000.00007fff5c854000.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-ppc/tmp/ub8ehJSePAfc9FYqZIT6.ppc.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception11
Obfuscated Files or Information
1
OS Credential Dumping
11
Security Software Discovery
Remote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Non-Standard Port
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1649631 Sample: ub8ehJSePAfc9FYqZIT6.ppc.elf Startdate: 27/03/2025 Architecture: LINUX Score: 68 20 109.202.202.202, 80 INIT7CH Switzerland 2->20 22 61.7.209.116, 3778, 45366, 45368 CAT-APTheCommunicationAuthoityofThailandCATTH Thailand 2->22 24 2 other IPs or domains 2->24 26 Malicious sample detected (through community Yara rule) 2->26 28 Antivirus / Scanner detection for submitted sample 2->28 30 Multi AV Scanner detection for submitted file 2->30 32 Sample is packed with UPX 2->32 8 ub8ehJSePAfc9FYqZIT6.ppc.elf 2->8         started        signatures3 process4 process5 10 ub8ehJSePAfc9FYqZIT6.ppc.elf 8->10         started        12 ub8ehJSePAfc9FYqZIT6.ppc.elf 8->12         started        14 ub8ehJSePAfc9FYqZIT6.ppc.elf 8->14         started        process6 16 ub8ehJSePAfc9FYqZIT6.ppc.elf 10->16         started        18 ub8ehJSePAfc9FYqZIT6.ppc.elf 10->18         started       
SourceDetectionScannerLabelLink
ub8ehJSePAfc9FYqZIT6.ppc.elf43%VirustotalBrowse
ub8ehJSePAfc9FYqZIT6.ppc.elf53%ReversingLabsLinux.Trojan.Mirai
ub8ehJSePAfc9FYqZIT6.ppc.elf100%AviraEXP/ELF.Agent.F.118
No Antivirus matches
No Antivirus matches
No Antivirus matches

Download Network PCAP: filteredfull

No contacted domains info
NameSourceMaliciousAntivirus DetectionReputation
http://upx.sf.netub8ehJSePAfc9FYqZIT6.ppc.elffalse
    high
    • No. of IPs < 25%
    • 25% < No. of IPs < 50%
    • 50% < No. of IPs < 75%
    • 75% < No. of IPs
    IPDomainCountryFlagASNASN NameMalicious
    109.202.202.202
    unknownSwitzerland
    13030INIT7CHfalse
    61.7.209.116
    unknownThailand
    9931CAT-APTheCommunicationAuthoityofThailandCATTHfalse
    91.189.91.43
    unknownUnited Kingdom
    41231CANONICAL-ASGBfalse
    91.189.91.42
    unknownUnited Kingdom
    41231CANONICAL-ASGBfalse
    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
    109.202.202.202kpLwzBouH4.elfGet hashmaliciousUnknownBrowse
    • ch.archive.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_92.0%2bbuild3-0ubuntu0.20.04.1_amd64.deb
    61.7.209.116ub8ehJSePAfc9FYqZIT6.arm6.elfGet hashmaliciousUnknownBrowse
      ub8ehJSePAfc9FYqZIT6.i686.elfGet hashmaliciousUnknownBrowse
        ub8ehJSePAfc9FYqZIT6.mpsl.elfGet hashmaliciousUnknownBrowse
          ub8ehJSePAfc9FYqZIT6.mips.elfGet hashmaliciousUnknownBrowse
            ub8ehJSePAfc9FYqZIT6.x86.elfGet hashmaliciousUnknownBrowse
              cbot.exeGet hashmaliciousUnknownBrowse
                raw_cbot.exeGet hashmaliciousUnknownBrowse
                  cbot.exeGet hashmaliciousUnknownBrowse
                    raw_cbot.exeGet hashmaliciousUnknownBrowse
                      91.189.91.43ub8ehJSePAfc9FYqZIT6.i686.elfGet hashmaliciousUnknownBrowse
                        efea6.elfGet hashmaliciousMiraiBrowse
                          na.elfGet hashmaliciousPrometeiBrowse
                            na.elfGet hashmaliciousPrometeiBrowse
                              na.elfGet hashmaliciousPrometeiBrowse
                                arm5.elfGet hashmaliciousUnknownBrowse
                                  arm5.elfGet hashmaliciousUnknownBrowse
                                    rjfe686.elfGet hashmaliciousUnknownBrowse
                                      mpsl.elfGet hashmaliciousUnknownBrowse
                                        .i.elfGet hashmaliciousUnknownBrowse
                                          91.189.91.42ub8ehJSePAfc9FYqZIT6.i686.elfGet hashmaliciousUnknownBrowse
                                            efea6.elfGet hashmaliciousMiraiBrowse
                                              na.elfGet hashmaliciousPrometeiBrowse
                                                na.elfGet hashmaliciousPrometeiBrowse
                                                  na.elfGet hashmaliciousPrometeiBrowse
                                                    arm5.elfGet hashmaliciousUnknownBrowse
                                                      na.elfGet hashmaliciousPrometeiBrowse
                                                        arm5.elfGet hashmaliciousUnknownBrowse
                                                          rjfe686.elfGet hashmaliciousUnknownBrowse
                                                            mpsl.elfGet hashmaliciousUnknownBrowse
                                                              No context
                                                              MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                              CANONICAL-ASGBub8ehJSePAfc9FYqZIT6.i686.elfGet hashmaliciousUnknownBrowse
                                                              • 91.189.91.42
                                                              efea6.elfGet hashmaliciousMiraiBrowse
                                                              • 91.189.91.42
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 91.189.91.42
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 91.189.91.42
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 91.189.91.42
                                                              arm5.elfGet hashmaliciousUnknownBrowse
                                                              • 91.189.91.42
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 91.189.91.42
                                                              arm5.elfGet hashmaliciousUnknownBrowse
                                                              • 91.189.91.42
                                                              rjfe686.elfGet hashmaliciousUnknownBrowse
                                                              • 91.189.91.42
                                                              mpsl.elfGet hashmaliciousUnknownBrowse
                                                              • 91.189.91.42
                                                              CANONICAL-ASGBub8ehJSePAfc9FYqZIT6.i686.elfGet hashmaliciousUnknownBrowse
                                                              • 91.189.91.42
                                                              efea6.elfGet hashmaliciousMiraiBrowse
                                                              • 91.189.91.42
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 91.189.91.42
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 91.189.91.42
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 91.189.91.42
                                                              arm5.elfGet hashmaliciousUnknownBrowse
                                                              • 91.189.91.42
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 91.189.91.42
                                                              arm5.elfGet hashmaliciousUnknownBrowse
                                                              • 91.189.91.42
                                                              rjfe686.elfGet hashmaliciousUnknownBrowse
                                                              • 91.189.91.42
                                                              mpsl.elfGet hashmaliciousUnknownBrowse
                                                              • 91.189.91.42
                                                              CAT-APTheCommunicationAuthoityofThailandCATTHub8ehJSePAfc9FYqZIT6.m68k.elfGet hashmaliciousMiraiBrowse
                                                              • 61.7.209.116
                                                              ub8ehJSePAfc9FYqZIT6.arm6.elfGet hashmaliciousUnknownBrowse
                                                              • 61.7.209.116
                                                              ub8ehJSePAfc9FYqZIT6.i686.elfGet hashmaliciousUnknownBrowse
                                                              • 61.7.209.116
                                                              ub8ehJSePAfc9FYqZIT6.mpsl.elfGet hashmaliciousUnknownBrowse
                                                              • 61.7.209.116
                                                              ub8ehJSePAfc9FYqZIT6.mips.elfGet hashmaliciousUnknownBrowse
                                                              • 61.7.209.116
                                                              ub8ehJSePAfc9FYqZIT6.x86.elfGet hashmaliciousUnknownBrowse
                                                              • 61.7.209.116
                                                              cbot.exeGet hashmaliciousUnknownBrowse
                                                              • 61.7.209.116
                                                              raw_cbot.exeGet hashmaliciousUnknownBrowse
                                                              • 61.7.209.116
                                                              cbot.exeGet hashmaliciousUnknownBrowse
                                                              • 61.7.209.116
                                                              raw_cbot.exeGet hashmaliciousUnknownBrowse
                                                              • 61.7.209.116
                                                              INIT7CHub8ehJSePAfc9FYqZIT6.i686.elfGet hashmaliciousUnknownBrowse
                                                              • 109.202.202.202
                                                              efea6.elfGet hashmaliciousMiraiBrowse
                                                              • 109.202.202.202
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 109.202.202.202
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 109.202.202.202
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 109.202.202.202
                                                              arm5.elfGet hashmaliciousUnknownBrowse
                                                              • 109.202.202.202
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 109.202.202.202
                                                              arm5.elfGet hashmaliciousUnknownBrowse
                                                              • 109.202.202.202
                                                              rjfe686.elfGet hashmaliciousUnknownBrowse
                                                              • 109.202.202.202
                                                              mpsl.elfGet hashmaliciousUnknownBrowse
                                                              • 109.202.202.202
                                                              No context
                                                              No context
                                                              No created / dropped files found
                                                              File type:ELF 32-bit MSB executable, PowerPC or cisco 4500, version 1 (GNU/Linux), statically linked, no section header
                                                              Entropy (8bit):7.9624032940225495
                                                              TrID:
                                                              • ELF Executable and Linkable format (Linux) (4029/14) 50.16%
                                                              • ELF Executable and Linkable format (generic) (4004/1) 49.84%
                                                              File name:ub8ehJSePAfc9FYqZIT6.ppc.elf
                                                              File size:40'324 bytes
                                                              MD5:6ce96062fd4f4559c3d64fa4e640610e
                                                              SHA1:97d9020bef4fafc874da871204781b117b359919
                                                              SHA256:7c5ece8b04893af5937cba1b096ad703ffde47ff771891ca393356e33112fa8b
                                                              SHA512:5aec1351698d12a49107616d5faca41eb0e44d116254ea01fe7ad0d1ba608308000f5b8975009b0b284ff498dac016188cb6ec7420ed5cf2dfd3972781df89cb
                                                              SSDEEP:768:yrqQ4JXTPxcCj3do/vTKRVDkO1HmQcvbG+TqarjEP8oBtVY+4uVcqgw09G:uqQbCj3do/+fDrJ1cyUqOgkqO+4u+qgq
                                                              TLSH:AD03E167C8495ED6E9FFD5611705CAE1F7E01E8DAFA18CAE1C56CB03332E869520CA50
                                                              File Content Preview:.ELF...........................4.........4. ...(.......................x...x..............k...k...k.................dt.Q................................UPX!..........b...b........V.......?.E.h4...@b........=.a....`..Y...j{.c.HL}.....H..z.q.H.....8ea......

                                                              ELF header

                                                              Class:ELF32
                                                              Data:2's complement, big endian
                                                              Version:1 (current)
                                                              Machine:PowerPC
                                                              Version Number:0x1
                                                              Type:EXEC (Executable file)
                                                              OS/ABI:UNIX - Linux
                                                              ABI Version:0
                                                              Entry Point Address:0x108a90
                                                              Flags:0x0
                                                              ELF Header Size:52
                                                              Program Header Offset:52
                                                              Program Header Size:32
                                                              Number of Program Headers:3
                                                              Section Header Offset:0
                                                              Section Header Size:40
                                                              Number of Section Headers:0
                                                              Header String Table Index:0
                                                              TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                              LOAD0x00x1000000x1000000x9c780x9c787.96440x5R E0x10000
                                                              LOAD0x6b900x10026b900x10026b900x00x00.00000x6RW 0x10000
                                                              GNU_STACK0x00x00x00x00x00.00000x6RW 0x4

                                                              Download Network PCAP: filteredfull

                                                              • Total Packets: 58
                                                              • 3778 undefined
                                                              • 443 (HTTPS)
                                                              • 80 (HTTP)
                                                              TimestampSource PortDest PortSource IPDest IP
                                                              Mar 27, 2025 00:28:05.830338001 CET453663778192.168.2.2361.7.209.116
                                                              Mar 27, 2025 00:28:06.189729929 CET37784536661.7.209.116192.168.2.23
                                                              Mar 27, 2025 00:28:06.645761967 CET43928443192.168.2.2391.189.91.42
                                                              Mar 27, 2025 00:28:11.190963030 CET453683778192.168.2.2361.7.209.116
                                                              Mar 27, 2025 00:28:11.547492981 CET37784536861.7.209.116192.168.2.23
                                                              Mar 27, 2025 00:28:11.649240971 CET453703778192.168.2.2361.7.209.116
                                                              Mar 27, 2025 00:28:12.006283998 CET37784537061.7.209.116192.168.2.23
                                                              Mar 27, 2025 00:28:12.024816990 CET42836443192.168.2.2391.189.91.43
                                                              Mar 27, 2025 00:28:14.548799992 CET453723778192.168.2.2361.7.209.116
                                                              Mar 27, 2025 00:28:14.901206970 CET37784537261.7.209.116192.168.2.23
                                                              Mar 27, 2025 00:28:17.007982016 CET453743778192.168.2.2361.7.209.116
                                                              Mar 27, 2025 00:28:17.375792027 CET37784537461.7.209.116192.168.2.23
                                                              Mar 27, 2025 00:28:17.902457952 CET453763778192.168.2.2361.7.209.116
                                                              Mar 27, 2025 00:28:18.257386923 CET37784537661.7.209.116192.168.2.23
                                                              Mar 27, 2025 00:28:19.260653973 CET453783778192.168.2.2361.7.209.116
                                                              Mar 27, 2025 00:28:19.613171101 CET37784537861.7.209.116192.168.2.23
                                                              Mar 27, 2025 00:28:20.378365040 CET453803778192.168.2.2361.7.209.116
                                                              Mar 27, 2025 00:28:20.739512920 CET37784538061.7.209.116192.168.2.23
                                                              Mar 27, 2025 00:28:23.615498066 CET453823778192.168.2.2361.7.209.116
                                                              Mar 27, 2025 00:28:23.742067099 CET453843778192.168.2.2361.7.209.116
                                                              Mar 27, 2025 00:28:23.975090981 CET37784538261.7.209.116192.168.2.23
                                                              Mar 27, 2025 00:28:24.101330996 CET37784538461.7.209.116192.168.2.23
                                                              Mar 27, 2025 00:28:25.104547024 CET453863778192.168.2.2361.7.209.116
                                                              Mar 27, 2025 00:28:25.467133045 CET37784538661.7.209.116192.168.2.23
                                                              Mar 27, 2025 00:28:27.890969038 CET43928443192.168.2.2391.189.91.42
                                                              Mar 27, 2025 00:28:29.470110893 CET453883778192.168.2.2361.7.209.116
                                                              Mar 27, 2025 00:28:29.825172901 CET37784538861.7.209.116192.168.2.23
                                                              Mar 27, 2025 00:28:29.938488007 CET4251680192.168.2.23109.202.202.202
                                                              Mar 27, 2025 00:28:33.976931095 CET453903778192.168.2.2361.7.209.116
                                                              Mar 27, 2025 00:28:34.329421997 CET37784539061.7.209.116192.168.2.23
                                                              Mar 27, 2025 00:28:37.333870888 CET453923778192.168.2.2361.7.209.116
                                                              Mar 27, 2025 00:28:37.695091963 CET37784539261.7.209.116192.168.2.23
                                                              Mar 27, 2025 00:28:38.129266024 CET42836443192.168.2.2391.189.91.43
                                                              Mar 27, 2025 00:28:39.697841883 CET453943778192.168.2.2361.7.209.116
                                                              Mar 27, 2025 00:28:39.827162981 CET453963778192.168.2.2361.7.209.116
                                                              Mar 27, 2025 00:28:40.065849066 CET37784539461.7.209.116192.168.2.23
                                                              Mar 27, 2025 00:28:40.182099104 CET37784539661.7.209.116192.168.2.23
                                                              Mar 27, 2025 00:28:41.068151951 CET453983778192.168.2.2361.7.209.116
                                                              Mar 27, 2025 00:28:41.422920942 CET37784539861.7.209.116192.168.2.23
                                                              Mar 27, 2025 00:28:43.186563015 CET454003778192.168.2.2361.7.209.116
                                                              Mar 27, 2025 00:28:43.551724911 CET37784540061.7.209.116192.168.2.23
                                                              Mar 27, 2025 00:28:45.554801941 CET454023778192.168.2.2361.7.209.116
                                                              Mar 27, 2025 00:28:45.913779020 CET37784540261.7.209.116192.168.2.23
                                                              Mar 27, 2025 00:28:46.425523043 CET454043778192.168.2.2361.7.209.116
                                                              Mar 27, 2025 00:28:46.783054113 CET37784540461.7.209.116192.168.2.23
                                                              Mar 27, 2025 00:28:46.917313099 CET454063778192.168.2.2361.7.209.116
                                                              Mar 27, 2025 00:28:47.275342941 CET37784540661.7.209.116192.168.2.23
                                                              Mar 27, 2025 00:28:52.278034925 CET454083778192.168.2.2361.7.209.116
                                                              Mar 27, 2025 00:28:52.642394066 CET37784540861.7.209.116192.168.2.23
                                                              Mar 27, 2025 00:28:55.784957886 CET454103778192.168.2.2361.7.209.116
                                                              Mar 27, 2025 00:28:56.142853022 CET37784541061.7.209.116192.168.2.23
                                                              Mar 27, 2025 00:29:01.644365072 CET454123778192.168.2.2361.7.209.116
                                                              Mar 27, 2025 00:29:01.997787952 CET37784541261.7.209.116192.168.2.23
                                                              Mar 27, 2025 00:29:05.145149946 CET454143778192.168.2.2361.7.209.116
                                                              Mar 27, 2025 00:29:05.498487949 CET37784541461.7.209.116192.168.2.23
                                                              Mar 27, 2025 00:29:08.845354080 CET43928443192.168.2.2391.189.91.42
                                                              Mar 27, 2025 00:29:10.998867035 CET454163778192.168.2.2361.7.209.116
                                                              Mar 27, 2025 00:29:11.500178099 CET454183778192.168.2.2361.7.209.116
                                                              Mar 27, 2025 00:29:11.853173971 CET37784541861.7.209.116192.168.2.23
                                                              Mar 27, 2025 00:29:12.012614965 CET454163778192.168.2.2361.7.209.116
                                                              Mar 27, 2025 00:29:12.370237112 CET37784541661.7.209.116192.168.2.23
                                                              Mar 27, 2025 00:29:14.856024981 CET454203778192.168.2.2361.7.209.116
                                                              Mar 27, 2025 00:29:15.216161013 CET37784542061.7.209.116192.168.2.23
                                                              Mar 27, 2025 00:29:18.374790907 CET454223778192.168.2.2361.7.209.116
                                                              Mar 27, 2025 00:29:18.734288931 CET37784542261.7.209.116192.168.2.23
                                                              Mar 27, 2025 00:29:19.220067024 CET454243778192.168.2.2361.7.209.116
                                                              Mar 27, 2025 00:29:19.580293894 CET37784542461.7.209.116192.168.2.23
                                                              Mar 27, 2025 00:29:21.737395048 CET454263778192.168.2.2361.7.209.116
                                                              Mar 27, 2025 00:29:22.095906019 CET37784542661.7.209.116192.168.2.23
                                                              Mar 27, 2025 00:29:26.100933075 CET454283778192.168.2.2361.7.209.116
                                                              Mar 27, 2025 00:29:26.465574980 CET37784542861.7.209.116192.168.2.23
                                                              Mar 27, 2025 00:29:27.582043886 CET454303778192.168.2.2361.7.209.116
                                                              Mar 27, 2025 00:29:27.943094015 CET37784543061.7.209.116192.168.2.23
                                                              Mar 27, 2025 00:29:28.946029902 CET454323778192.168.2.2361.7.209.116
                                                              Mar 27, 2025 00:29:29.310458899 CET37784543261.7.209.116192.168.2.23
                                                              Mar 27, 2025 00:29:34.473731041 CET454343778192.168.2.2361.7.209.116
                                                              Mar 27, 2025 00:29:34.835809946 CET37784543461.7.209.116192.168.2.23
                                                              Mar 27, 2025 00:29:35.311651945 CET454363778192.168.2.2361.7.209.116
                                                              Mar 27, 2025 00:29:35.678728104 CET37784543661.7.209.116192.168.2.23
                                                              Mar 27, 2025 00:29:35.838934898 CET454383778192.168.2.2361.7.209.116
                                                              Mar 27, 2025 00:29:36.194468975 CET37784543861.7.209.116192.168.2.23
                                                              Mar 27, 2025 00:29:41.680402994 CET454403778192.168.2.2361.7.209.116
                                                              Mar 27, 2025 00:29:42.037141085 CET37784544061.7.209.116192.168.2.23
                                                              Mar 27, 2025 00:29:42.196242094 CET454423778192.168.2.2361.7.209.116
                                                              Mar 27, 2025 00:29:42.556719065 CET37784544261.7.209.116192.168.2.23
                                                              Mar 27, 2025 00:29:48.559484959 CET454443778192.168.2.2361.7.209.116
                                                              Mar 27, 2025 00:29:48.916659117 CET37784544461.7.209.116192.168.2.23
                                                              Mar 27, 2025 00:29:49.038815022 CET454463778192.168.2.2361.7.209.116
                                                              Mar 27, 2025 00:29:49.401602983 CET37784544661.7.209.116192.168.2.23
                                                              Mar 27, 2025 00:29:52.405096054 CET454483778192.168.2.2361.7.209.116
                                                              Mar 27, 2025 00:29:52.759824991 CET37784544861.7.209.116192.168.2.23
                                                              Mar 27, 2025 00:29:55.918962002 CET454503778192.168.2.2361.7.209.116
                                                              Mar 27, 2025 00:29:56.277964115 CET37784545061.7.209.116192.168.2.23
                                                              Mar 27, 2025 00:29:56.763102055 CET454523778192.168.2.2361.7.209.116
                                                              Mar 27, 2025 00:29:57.117134094 CET37784545261.7.209.116192.168.2.23
                                                              Mar 27, 2025 00:29:59.281563997 CET454543778192.168.2.2361.7.209.116
                                                              Mar 27, 2025 00:29:59.638432026 CET37784545461.7.209.116192.168.2.23
                                                              Mar 27, 2025 00:30:03.641144991 CET454563778192.168.2.2361.7.209.116
                                                              Mar 27, 2025 00:30:04.004199028 CET37784545661.7.209.116192.168.2.23
                                                              Mar 27, 2025 00:30:04.119170904 CET454583778192.168.2.2361.7.209.116
                                                              Mar 27, 2025 00:30:04.475235939 CET37784545861.7.209.116192.168.2.23
                                                              Mar 27, 2025 00:30:05.478863955 CET454603778192.168.2.2361.7.209.116
                                                              Mar 27, 2025 00:30:05.834959030 CET37784546061.7.209.116192.168.2.23
                                                              Mar 27, 2025 00:30:11.007013083 CET454623778192.168.2.2361.7.209.116
                                                              Mar 27, 2025 00:30:11.370537996 CET37784546261.7.209.116192.168.2.23
                                                              Mar 27, 2025 00:30:12.373322964 CET454643778192.168.2.2361.7.209.116
                                                              Mar 27, 2025 00:30:12.728116035 CET37784546461.7.209.116192.168.2.23
                                                              Mar 27, 2025 00:30:12.837227106 CET454663778192.168.2.2361.7.209.116
                                                              Mar 27, 2025 00:30:13.201538086 CET37784546661.7.209.116192.168.2.23

                                                              System Behavior

                                                              Start time (UTC):23:28:04
                                                              Start date (UTC):26/03/2025
                                                              Path:/tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf
                                                              Arguments:/tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf
                                                              File size:5388968 bytes
                                                              MD5 hash:ae65271c943d3451b7f026d1fadccea6

                                                              Start time (UTC):23:28:04
                                                              Start date (UTC):26/03/2025
                                                              Path:/tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf
                                                              Arguments:-
                                                              File size:5388968 bytes
                                                              MD5 hash:ae65271c943d3451b7f026d1fadccea6

                                                              Start time (UTC):23:28:04
                                                              Start date (UTC):26/03/2025
                                                              Path:/tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf
                                                              Arguments:-
                                                              File size:5388968 bytes
                                                              MD5 hash:ae65271c943d3451b7f026d1fadccea6

                                                              Start time (UTC):23:28:04
                                                              Start date (UTC):26/03/2025
                                                              Path:/tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf
                                                              Arguments:-
                                                              File size:5388968 bytes
                                                              MD5 hash:ae65271c943d3451b7f026d1fadccea6

                                                              Start time (UTC):23:28:10
                                                              Start date (UTC):26/03/2025
                                                              Path:/tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf
                                                              Arguments:-
                                                              File size:5388968 bytes
                                                              MD5 hash:ae65271c943d3451b7f026d1fadccea6

                                                              Start time (UTC):23:28:10
                                                              Start date (UTC):26/03/2025
                                                              Path:/tmp/ub8ehJSePAfc9FYqZIT6.ppc.elf
                                                              Arguments:-
                                                              File size:5388968 bytes
                                                              MD5 hash:ae65271c943d3451b7f026d1fadccea6