Edit tour

Linux Analysis Report
FBI.mpsl.elf

Overview

General Information

Sample name:FBI.mpsl.elf
Analysis ID:1654271
MD5:5ec356608a575cf57e0b90019dc1edff
SHA1:6f7b194628b403e1b66420bec9cf853337c0d7a8
SHA256:e5240047c2b3d7fd7e1e54f5bd18554f0d22c6f6ecfe06be38e27bffd4efe6e1
Tags:elfuser-abuse_ch
Infos:

Detection

Gafgyt, Mirai
Score:80
Range:0 - 100

Signatures

Antivirus / Scanner detection for submitted sample
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Yara detected Gafgyt
Yara detected Mirai
Detected TCP or UDP traffic on non-standard ports
Sample contains strings indicative of BusyBox which embeds multiple Unix commands in a single executable
Sample contains strings that are user agent strings indicative of HTTP manipulation
Sample has stripped symbol table
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Uses the "uname" system call to query kernel version information (possible evasion)
Yara signature match

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
Joe Sandbox version:42.0.0 Malachite
Analysis ID:1654271
Start date and time:2025-04-02 08:35:05 +02:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 5m 33s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:FBI.mpsl.elf
Detection:MAL
Classification:mal80.troj.linELF@0/0@0/0
Command:/tmp/FBI.mpsl.elf
PID:6267
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:

Standard Error:qemu: uncaught target signal 8 (Floating point exception) - core dumped
qemu: uncaught target signal 8 (Floating point exception) - core dumped
qemu: uncaught target signal 8 (Floating point exception) - core dumped
qemu: uncaught target signal 8 (Floating point exception) - core dumped
  • system is lnxubuntu20
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
Bashlite, GafgytBashlite is a malware family which infects Linux systems in order to launch distributed denial-of-service attacks (DDoS). Originally it was also known under the name Bashdoor, but this term now refers to the exploit method used by the malware. It has been used to launch attacks of up to 400 Gbps.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/elf.bashlite
NameDescriptionAttributionBlogpost URLsLink
MiraiMirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese. Nowadays it targets a wide range of networked embedded devices such as IP cameras, home routers (many vendors involved), and other IoT devices. Since the source code was published on "Hack Forums" many variants of the Mirai family appeared, infecting mostly home networks all around the world.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/elf.mirai
SourceRuleDescriptionAuthorStrings
FBI.mpsl.elfJoeSecurity_GafgytYara detected GafgytJoe Security
    FBI.mpsl.elfJoeSecurity_Mirai_8Yara detected MiraiJoe Security
      FBI.mpsl.elfLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
      • 0x1cc04:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x1cc18:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x1cc2c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x1cc40:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x1cc54:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x1cc68:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x1cc7c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x1cc90:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x1cca4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x1ccb8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x1cccc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x1cce0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x1ccf4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x1cd08:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x1cd1c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x1cd30:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x1cd44:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x1cd58:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x1cd6c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x1cd80:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x1cd94:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      FBI.mpsl.elfLinux_Trojan_Gafgyt_ea92cca8unknownunknown
      • 0x1cbb4:$a: 53 65 6C 66 20 52 65 70 20 46 75 63 6B 69 6E 67 20 4E 65 54 69 53 20 61 6E 64
      SourceRuleDescriptionAuthorStrings
      6275.1.00007f1bb0400000.00007f1bb0420000.r-x.sdmpJoeSecurity_GafgytYara detected GafgytJoe Security
        6275.1.00007f1bb0400000.00007f1bb0420000.r-x.sdmpJoeSecurity_Mirai_8Yara detected MiraiJoe Security
          6275.1.00007f1bb0400000.00007f1bb0420000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
          • 0x1cc04:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x1cc18:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x1cc2c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x1cc40:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x1cc54:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x1cc68:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x1cc7c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x1cc90:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x1cca4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x1ccb8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x1cccc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x1cce0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x1ccf4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x1cd08:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x1cd1c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x1cd30:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x1cd44:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x1cd58:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x1cd6c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x1cd80:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x1cd94:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          6275.1.00007f1bb0400000.00007f1bb0420000.r-x.sdmpLinux_Trojan_Gafgyt_ea92cca8unknownunknown
          • 0x1cbb4:$a: 53 65 6C 66 20 52 65 70 20 46 75 63 6B 69 6E 67 20 4E 65 54 69 53 20 61 6E 64
          6295.1.00007f1bb0400000.00007f1bb0420000.r-x.sdmpJoeSecurity_GafgytYara detected GafgytJoe Security
            Click to see the 30 entries
            No Suricata rule has matched

            Click to jump to signature section

            Show All Signature Results

            AV Detection

            barindex
            Source: FBI.mpsl.elfAvira: detected
            Source: FBI.mpsl.elfVirustotal: Detection: 63%Perma Link
            Source: FBI.mpsl.elfReversingLabs: Detection: 61%
            Source: global trafficTCP traffic: 192.168.2.23:36258 -> 176.65.144.18:1337
            Source: global trafficTCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
            Source: global trafficTCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
            Source: global trafficTCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
            Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
            Source: unknownTCP traffic detected without corresponding DNS query: 176.65.144.18
            Source: unknownTCP traffic detected without corresponding DNS query: 176.65.144.18
            Source: unknownTCP traffic detected without corresponding DNS query: 176.65.144.18
            Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
            Source: unknownTCP traffic detected without corresponding DNS query: 176.65.144.18
            Source: unknownTCP traffic detected without corresponding DNS query: 176.65.144.18
            Source: unknownTCP traffic detected without corresponding DNS query: 176.65.144.18
            Source: unknownTCP traffic detected without corresponding DNS query: 176.65.144.18
            Source: unknownTCP traffic detected without corresponding DNS query: 176.65.144.18
            Source: unknownTCP traffic detected without corresponding DNS query: 176.65.144.18
            Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
            Source: unknownTCP traffic detected without corresponding DNS query: 176.65.144.18
            Source: unknownTCP traffic detected without corresponding DNS query: 176.65.144.18
            Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
            Source: unknownTCP traffic detected without corresponding DNS query: 176.65.144.18
            Source: unknownTCP traffic detected without corresponding DNS query: 176.65.144.18
            Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
            Source: unknownTCP traffic detected without corresponding DNS query: 176.65.144.18
            Source: unknownTCP traffic detected without corresponding DNS query: 176.65.144.18
            Source: unknownTCP traffic detected without corresponding DNS query: 176.65.144.18
            Source: unknownTCP traffic detected without corresponding DNS query: 176.65.144.18
            Source: unknownTCP traffic detected without corresponding DNS query: 176.65.144.18
            Source: unknownTCP traffic detected without corresponding DNS query: 176.65.144.18
            Source: unknownTCP traffic detected without corresponding DNS query: 176.65.144.18
            Source: unknownTCP traffic detected without corresponding DNS query: 176.65.144.18
            Source: unknownTCP traffic detected without corresponding DNS query: 176.65.144.18
            Source: unknownTCP traffic detected without corresponding DNS query: 176.65.144.18
            Source: unknownTCP traffic detected without corresponding DNS query: 176.65.144.18
            Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
            Source: unknownTCP traffic detected without corresponding DNS query: 176.65.144.18
            Source: unknownTCP traffic detected without corresponding DNS query: 176.65.144.18
            Source: unknownTCP traffic detected without corresponding DNS query: 176.65.144.18
            Source: unknownTCP traffic detected without corresponding DNS query: 176.65.144.18
            Source: unknownTCP traffic detected without corresponding DNS query: 176.65.144.18
            Source: unknownTCP traffic detected without corresponding DNS query: 176.65.144.18
            Source: unknownTCP traffic detected without corresponding DNS query: 176.65.144.18
            Source: unknownTCP traffic detected without corresponding DNS query: 176.65.144.18
            Source: unknownTCP traffic detected without corresponding DNS query: 176.65.144.18
            Source: unknownTCP traffic detected without corresponding DNS query: 176.65.144.18
            Source: unknownTCP traffic detected without corresponding DNS query: 176.65.144.18
            Source: unknownTCP traffic detected without corresponding DNS query: 176.65.144.18
            Source: unknownTCP traffic detected without corresponding DNS query: 176.65.144.18
            Source: unknownTCP traffic detected without corresponding DNS query: 176.65.144.18
            Source: unknownTCP traffic detected without corresponding DNS query: 176.65.144.18
            Source: unknownTCP traffic detected without corresponding DNS query: 176.65.144.18
            Source: unknownTCP traffic detected without corresponding DNS query: 176.65.144.18
            Source: unknownTCP traffic detected without corresponding DNS query: 176.65.144.18
            Source: unknownTCP traffic detected without corresponding DNS query: 176.65.144.18
            Source: unknownTCP traffic detected without corresponding DNS query: 176.65.144.18
            Source: FBI.mpsl.elfString found in binary or memory: http://fast.no/support/crawler.asp)
            Source: FBI.mpsl.elfString found in binary or memory: http://feedback.redkolibri.com/
            Source: FBI.mpsl.elfString found in binary or memory: http://www.baidu.com/search/spider.htm)
            Source: FBI.mpsl.elfString found in binary or memory: http://www.baidu.com/search/spider.html)
            Source: FBI.mpsl.elfString found in binary or memory: http://www.billybobbot.com/crawler/)
            Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443

            System Summary

            barindex
            Source: FBI.mpsl.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
            Source: FBI.mpsl.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown
            Source: 6275.1.00007f1bb0400000.00007f1bb0420000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
            Source: 6275.1.00007f1bb0400000.00007f1bb0420000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown
            Source: 6295.1.00007f1bb0400000.00007f1bb0420000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
            Source: 6295.1.00007f1bb0400000.00007f1bb0420000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown
            Source: 6267.1.00007f1bb0400000.00007f1bb0420000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
            Source: 6267.1.00007f1bb0400000.00007f1bb0420000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown
            Source: 6293.1.00007f1bb0400000.00007f1bb0420000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
            Source: 6293.1.00007f1bb0400000.00007f1bb0420000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown
            Source: 6277.1.00007f1bb0400000.00007f1bb0420000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
            Source: 6277.1.00007f1bb0400000.00007f1bb0420000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown
            Source: Process Memory Space: FBI.mpsl.elf PID: 6267, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
            Source: Process Memory Space: FBI.mpsl.elf PID: 6267, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown
            Source: Process Memory Space: FBI.mpsl.elf PID: 6275, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
            Source: Process Memory Space: FBI.mpsl.elf PID: 6275, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown
            Source: Process Memory Space: FBI.mpsl.elf PID: 6277, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
            Source: Process Memory Space: FBI.mpsl.elf PID: 6277, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown
            Source: Process Memory Space: FBI.mpsl.elf PID: 6293, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
            Source: Process Memory Space: FBI.mpsl.elf PID: 6293, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown
            Source: Process Memory Space: FBI.mpsl.elf PID: 6295, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
            Source: Process Memory Space: FBI.mpsl.elf PID: 6295, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown
            Source: Initial sampleString containing 'busybox' found: busybox
            Source: Initial sampleString containing 'busybox' found: BusyBox
            Source: Initial sampleString containing 'busybox' found: 20+!g}]/proc/self/maps/proc//maps/root//tmp//var/run/mnt/BinsameccountoginnterhraseordeyshellsystemenablebusyboxBusyBoxBuilt-in107.182.129.217
            Source: ELF static info symbol of initial sample.symtab present: no
            Source: FBI.mpsl.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
            Source: FBI.mpsl.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16
            Source: 6275.1.00007f1bb0400000.00007f1bb0420000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
            Source: 6275.1.00007f1bb0400000.00007f1bb0420000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16
            Source: 6295.1.00007f1bb0400000.00007f1bb0420000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
            Source: 6295.1.00007f1bb0400000.00007f1bb0420000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16
            Source: 6267.1.00007f1bb0400000.00007f1bb0420000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
            Source: 6267.1.00007f1bb0400000.00007f1bb0420000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16
            Source: 6293.1.00007f1bb0400000.00007f1bb0420000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
            Source: 6293.1.00007f1bb0400000.00007f1bb0420000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16
            Source: 6277.1.00007f1bb0400000.00007f1bb0420000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
            Source: 6277.1.00007f1bb0400000.00007f1bb0420000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16
            Source: Process Memory Space: FBI.mpsl.elf PID: 6267, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
            Source: Process Memory Space: FBI.mpsl.elf PID: 6267, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16
            Source: Process Memory Space: FBI.mpsl.elf PID: 6275, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
            Source: Process Memory Space: FBI.mpsl.elf PID: 6275, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16
            Source: Process Memory Space: FBI.mpsl.elf PID: 6277, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
            Source: Process Memory Space: FBI.mpsl.elf PID: 6277, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16
            Source: Process Memory Space: FBI.mpsl.elf PID: 6293, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
            Source: Process Memory Space: FBI.mpsl.elf PID: 6293, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16
            Source: Process Memory Space: FBI.mpsl.elf PID: 6295, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
            Source: Process Memory Space: FBI.mpsl.elf PID: 6295, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16
            Source: classification engineClassification label: mal80.troj.linELF@0/0@0/0
            Source: submitted sampleStderr: qemu: uncaught target signal 8 (Floating point exception) - core dumpedqemu: uncaught target signal 8 (Floating point exception) - core dumpedqemu: uncaught target signal 8 (Floating point exception) - core dumpedqemu: uncaught target signal 8 (Floating point exception) - core dumped: exit code = 0
            Source: /tmp/FBI.mpsl.elf (PID: 6267)Queries kernel information via 'uname': Jump to behavior
            Source: FBI.mpsl.elf, 6267.1.000055c5e1c57000.000055c5e1cde000.rw-.sdmp, FBI.mpsl.elf, 6275.1.000055c5e1c57000.000055c5e1cde000.rw-.sdmp, FBI.mpsl.elf, 6277.1.000055c5e1c57000.000055c5e1cde000.rw-.sdmp, FBI.mpsl.elf, 6293.1.000055c5e1c57000.000055c5e1cde000.rw-.sdmp, FBI.mpsl.elf, 6295.1.000055c5e1c57000.000055c5e1cde000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/mipsel
            Source: FBI.mpsl.elf, 6267.1.000055c5e1c57000.000055c5e1cde000.rw-.sdmp, FBI.mpsl.elf, 6275.1.000055c5e1c57000.000055c5e1cde000.rw-.sdmp, FBI.mpsl.elf, 6277.1.000055c5e1c57000.000055c5e1cde000.rw-.sdmp, FBI.mpsl.elf, 6293.1.000055c5e1c57000.000055c5e1cde000.rw-.sdmp, FBI.mpsl.elf, 6295.1.000055c5e1c57000.000055c5e1cde000.rw-.sdmpBinary or memory string: U!/etc/qemu-binfmt/mipsel
            Source: FBI.mpsl.elf, 6267.1.00007ffc3dc79000.00007ffc3dc9a000.rw-.sdmp, FBI.mpsl.elf, 6275.1.00007ffc3dc79000.00007ffc3dc9a000.rw-.sdmp, FBI.mpsl.elf, 6277.1.00007ffc3dc79000.00007ffc3dc9a000.rw-.sdmp, FBI.mpsl.elf, 6293.1.00007ffc3dc79000.00007ffc3dc9a000.rw-.sdmp, FBI.mpsl.elf, 6295.1.00007ffc3dc79000.00007ffc3dc9a000.rw-.sdmpBinary or memory string: fx86_64/usr/bin/qemu-mipsel/tmp/FBI.mpsl.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/FBI.mpsl.elf
            Source: FBI.mpsl.elf, 6275.1.00007ffc3dc79000.00007ffc3dc9a000.rw-.sdmp, FBI.mpsl.elf, 6277.1.00007ffc3dc79000.00007ffc3dc9a000.rw-.sdmp, FBI.mpsl.elf, 6293.1.00007ffc3dc79000.00007ffc3dc9a000.rw-.sdmp, FBI.mpsl.elf, 6295.1.00007ffc3dc79000.00007ffc3dc9a000.rw-.sdmpBinary or memory string: qemu: uncaught target signal 8 (Floating point exception) - core dumped
            Source: FBI.mpsl.elf, 6267.1.00007ffc3dc79000.00007ffc3dc9a000.rw-.sdmp, FBI.mpsl.elf, 6275.1.00007ffc3dc79000.00007ffc3dc9a000.rw-.sdmp, FBI.mpsl.elf, 6277.1.00007ffc3dc79000.00007ffc3dc9a000.rw-.sdmp, FBI.mpsl.elf, 6293.1.00007ffc3dc79000.00007ffc3dc9a000.rw-.sdmp, FBI.mpsl.elf, 6295.1.00007ffc3dc79000.00007ffc3dc9a000.rw-.sdmpBinary or memory string: /usr/bin/qemu-mipsel

            Stealing of Sensitive Information

            barindex
            Source: Yara matchFile source: FBI.mpsl.elf, type: SAMPLE
            Source: Yara matchFile source: 6275.1.00007f1bb0400000.00007f1bb0420000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6295.1.00007f1bb0400000.00007f1bb0420000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6267.1.00007f1bb0400000.00007f1bb0420000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6293.1.00007f1bb0400000.00007f1bb0420000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6277.1.00007f1bb0400000.00007f1bb0420000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: FBI.mpsl.elf, type: SAMPLE
            Source: Yara matchFile source: 6275.1.00007f1bb0400000.00007f1bb0420000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6295.1.00007f1bb0400000.00007f1bb0420000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6267.1.00007f1bb0400000.00007f1bb0420000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6293.1.00007f1bb0400000.00007f1bb0420000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6277.1.00007f1bb0400000.00007f1bb0420000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: Process Memory Space: FBI.mpsl.elf PID: 6267, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: FBI.mpsl.elf PID: 6275, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: FBI.mpsl.elf PID: 6277, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: FBI.mpsl.elf PID: 6293, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: FBI.mpsl.elf PID: 6295, type: MEMORYSTR
            Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/65.0.3325.181 Safari/537.36
            Source: Initial sampleUser agent string found: Opera/9.80 (X11; Linux i686; Ubuntu/14.10) Presto/2.12.388 Version/12.16
            Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows; U; Windows NT 6.1; rv:2.2) Gecko/20110201
            Source: Initial sampleUser agent string found: Opera/9.80 (Windows NT 5.2; U; ru) Presto/2.5.22 Version/10.51
            Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36
            Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; AS; rv:11.0) like Gecko
            Source: Initial sampleUser agent string found: Mozilla/5.0 (Android; Linux armv7l; rv:9.0) Gecko/20111216 Firefox/9.0 Fennec/9.0
            Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 5.1) AppleWebKit/536.5 (KHTML, like Gecko) Chrome/19.0.1084.56 Safari/536.5
            Source: Initial sampleUser agent string found: Opera/9.80 (Windows NT 5.1; U; en) Presto/2.10.229 Version/11.60
            Source: Initial sampleUser agent string found: Mozilla/5.0 (iPad; U; CPU OS 5_1 like Mac OS X) AppleWebKit/531.21.10 (KHTML, like Gecko) Version/4.0.4 Mobile/7B367 Safari/531.21.10 UCBrowser/3.4.3.532
            Source: Initial sampleUser agent string found: Mozilla/5.0 (Nintendo WiiU) AppleWebKit/536.30 (KHTML, like Gecko) NX/3.0.4.2.12 NintendoBrowser/4.3.1.11264.US
            Source: Initial sampleUser agent string found: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.6; rv:25.0) Gecko/20100101 Firefox/25.0
            Source: Initial sampleUser agent string found: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; pl) Opera 11.00
            Source: Initial sampleUser agent string found: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0; en) Opera 11.00
            Source: Initial sampleUser agent string found: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0; ja) Opera 11.00
            Source: Initial sampleUser agent string found: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; cn) Opera 11.00
            Source: Initial sampleUser agent string found: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; fr) Opera 11.00
            Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/50.0.2661.102 Safari/537.36
            Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:12.0) Gecko/20100101 Firefox/12.0
            Source: Initial sampleUser agent string found: Mozilla/5.0 (X11; U; Linux x86_64; de; rv:1.9.2.8) Gecko/20100723 Ubuntu/10.04 (lucid) Firefox/3.6.8
            Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 5.1; rv:13.0) Gecko/20100101 Firefox/13.0.1
            Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:11.0) Gecko/20100101 Firefox/11.0
            Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:13.0) Gecko/20100101 Firefox/13.0.1
            Source: Initial sampleUser agent string found: Opera/9.80 (Windows NT 5.1; U; en) Presto/2.10.289 Version/12.01
            Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 5.1; rv:5.0.1) Gecko/20100101 Firefox/5.0.1
            Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 6.1; rv:5.0) Gecko/20100101 Firefox/5.02
            Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 6.0) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
            Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/53.0.2785.116 Safari/537.36
            Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/53.0.2785.116 Safari/537.36
            Source: Initial sampleUser agent string found: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/53.0.2785.116 Safari/537.36
            Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/53.0.2785.116 Safari/537.36
            Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/53.0.2785.143 Safari/537.36

            Remote Access Functionality

            barindex
            Source: Yara matchFile source: FBI.mpsl.elf, type: SAMPLE
            Source: Yara matchFile source: 6275.1.00007f1bb0400000.00007f1bb0420000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6295.1.00007f1bb0400000.00007f1bb0420000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6267.1.00007f1bb0400000.00007f1bb0420000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6293.1.00007f1bb0400000.00007f1bb0420000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6277.1.00007f1bb0400000.00007f1bb0420000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: FBI.mpsl.elf, type: SAMPLE
            Source: Yara matchFile source: 6275.1.00007f1bb0400000.00007f1bb0420000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6295.1.00007f1bb0400000.00007f1bb0420000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6267.1.00007f1bb0400000.00007f1bb0420000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6293.1.00007f1bb0400000.00007f1bb0420000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6277.1.00007f1bb0400000.00007f1bb0420000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: Process Memory Space: FBI.mpsl.elf PID: 6267, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: FBI.mpsl.elf PID: 6275, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: FBI.mpsl.elf PID: 6277, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: FBI.mpsl.elf PID: 6293, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: FBI.mpsl.elf PID: 6295, type: MEMORYSTR
            ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
            Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath InterceptionDirect Volume AccessOS Credential Dumping11
            Security Software Discovery
            Remote ServicesData from Local System1
            Data Obfuscation
            Exfiltration Over Other Network MediumAbuse Accessibility Features
            CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
            Encrypted Channel
            Exfiltration Over BluetoothNetwork Denial of Service
            Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
            Non-Standard Port
            Automated ExfiltrationData Encrypted for Impact
            Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture1
            Application Layer Protocol
            Traffic DuplicationData Destruction
            No configs have been found
            Hide Legend

            Legend:

            • Process
            • Signature
            • Created File
            • DNS/IP Info
            • Is Dropped
            • Number of created Files
            • Is malicious
            • Internet
            behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1654271 Sample: FBI.mpsl.elf Startdate: 02/04/2025 Architecture: LINUX Score: 80 26 176.65.144.18, 1337, 36258, 36260 PALTEL-ASPALTELAutonomousSystemPS Germany 2->26 28 109.202.202.202, 80 INIT7CH Switzerland 2->28 30 2 other IPs or domains 2->30 32 Malicious sample detected (through community Yara rule) 2->32 34 Antivirus / Scanner detection for submitted sample 2->34 36 Multi AV Scanner detection for submitted file 2->36 38 2 other signatures 2->38 10 FBI.mpsl.elf 2->10         started        signatures3 process4 process5 12 FBI.mpsl.elf 10->12         started        14 FBI.mpsl.elf 10->14         started        process6 16 FBI.mpsl.elf 12->16         started        18 FBI.mpsl.elf 12->18         started        process7 20 FBI.mpsl.elf 16->20         started        22 FBI.mpsl.elf 18->22         started        process8 24 FBI.mpsl.elf 20->24         started       
            SourceDetectionScannerLabelLink
            FBI.mpsl.elf63%VirustotalBrowse
            FBI.mpsl.elf61%ReversingLabsLinux.Backdoor.DemonBot
            FBI.mpsl.elf100%AviraEXP/ELF.Mirai.Z
            No Antivirus matches
            No Antivirus matches
            No Antivirus matches

            Download Network PCAP: filteredfull

            No contacted domains info
            NameSourceMaliciousAntivirus DetectionReputation
            http://www.baidu.com/search/spider.html)FBI.mpsl.elffalse
              high
              http://www.billybobbot.com/crawler/)FBI.mpsl.elffalse
                high
                http://fast.no/support/crawler.asp)FBI.mpsl.elffalse
                  high
                  http://feedback.redkolibri.com/FBI.mpsl.elffalse
                    high
                    http://www.baidu.com/search/spider.htm)FBI.mpsl.elffalse
                      high
                      • No. of IPs < 25%
                      • 25% < No. of IPs < 50%
                      • 50% < No. of IPs < 75%
                      • 75% < No. of IPs
                      IPDomainCountryFlagASNASN NameMalicious
                      176.65.144.18
                      unknownGermany
                      12975PALTEL-ASPALTELAutonomousSystemPSfalse
                      109.202.202.202
                      unknownSwitzerland
                      13030INIT7CHfalse
                      91.189.91.43
                      unknownUnited Kingdom
                      41231CANONICAL-ASGBfalse
                      91.189.91.42
                      unknownUnited Kingdom
                      41231CANONICAL-ASGBfalse
                      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                      176.65.144.18FBI.arm.elfGet hashmaliciousGafgyt, MiraiBrowse
                        FBI.sh4.elfGet hashmaliciousGafgyt, MiraiBrowse
                          FBI.arm7.elfGet hashmaliciousGafgyt, MiraiBrowse
                            FBI.x86.elfGet hashmaliciousGafgyt, MiraiBrowse
                              FBI.mips.elfGet hashmaliciousGafgyt, MiraiBrowse
                                FBI.arm5.elfGet hashmaliciousGafgyt, MiraiBrowse
                                  FBI.ppc.elfGet hashmaliciousGafgyt, MiraiBrowse
                                    FBI.arm6.elfGet hashmaliciousGafgyt, MiraiBrowse
                                      109.202.202.202kpLwzBouH4.elfGet hashmaliciousUnknownBrowse
                                      • ch.archive.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_92.0%2bbuild3-0ubuntu0.20.04.1_amd64.deb
                                      91.189.91.43FBI.x86.elfGet hashmaliciousGafgyt, MiraiBrowse
                                        FBI.arm5.elfGet hashmaliciousGafgyt, MiraiBrowse
                                          na.elfGet hashmaliciousPrometeiBrowse
                                            na.elfGet hashmaliciousPrometeiBrowse
                                              na.elfGet hashmaliciousPrometeiBrowse
                                                arm5.elfGet hashmaliciousUnknownBrowse
                                                  rjfe686.elfGet hashmaliciousUnknownBrowse
                                                    aarch64.elfGet hashmaliciousMiraiBrowse
                                                      sh4.elfGet hashmaliciousUnknownBrowse
                                                        efefa7.elfGet hashmaliciousMiraiBrowse
                                                          91.189.91.42FBI.x86.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                            FBI.arm5.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                                na.elfGet hashmaliciousPrometeiBrowse
                                                                  na.elfGet hashmaliciousPrometeiBrowse
                                                                    arm5.elfGet hashmaliciousUnknownBrowse
                                                                      rjfe686.elfGet hashmaliciousUnknownBrowse
                                                                        aarch64.elfGet hashmaliciousMiraiBrowse
                                                                          sh4.elfGet hashmaliciousUnknownBrowse
                                                                            efefa7.elfGet hashmaliciousMiraiBrowse
                                                                              No context
                                                                              MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                              CANONICAL-ASGBFBI.x86.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                                              • 91.189.91.42
                                                                              FBI.arm5.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                                              • 91.189.91.42
                                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                                              • 91.189.91.42
                                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                                              • 91.189.91.42
                                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                                              • 91.189.91.42
                                                                              arm5.elfGet hashmaliciousUnknownBrowse
                                                                              • 91.189.91.42
                                                                              rjfe686.elfGet hashmaliciousUnknownBrowse
                                                                              • 91.189.91.42
                                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                                              • 185.125.190.26
                                                                              aarch64.elfGet hashmaliciousMiraiBrowse
                                                                              • 91.189.91.42
                                                                              vejfa5.elfGet hashmaliciousUnknownBrowse
                                                                              • 185.125.190.26
                                                                              PALTEL-ASPALTELAutonomousSystemPSFBI.arm.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                                              • 176.65.144.18
                                                                              FBI.sh4.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                                              • 176.65.144.18
                                                                              FBI.arm7.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                                              • 176.65.144.18
                                                                              FBI.x86.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                                              • 176.65.144.18
                                                                              FBI.mips.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                                              • 176.65.144.18
                                                                              FBI.arm5.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                                              • 176.65.144.18
                                                                              FBI.ppc.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                                              • 176.65.144.18
                                                                              FBI.arm6.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                                              • 176.65.144.18
                                                                              clip64.dllGet hashmaliciousAmadeyBrowse
                                                                              • 176.65.137.193
                                                                              clip64.dllGet hashmaliciousAmadeyBrowse
                                                                              • 176.65.137.193
                                                                              CANONICAL-ASGBFBI.x86.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                                              • 91.189.91.42
                                                                              FBI.arm5.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                                              • 91.189.91.42
                                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                                              • 91.189.91.42
                                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                                              • 91.189.91.42
                                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                                              • 91.189.91.42
                                                                              arm5.elfGet hashmaliciousUnknownBrowse
                                                                              • 91.189.91.42
                                                                              rjfe686.elfGet hashmaliciousUnknownBrowse
                                                                              • 91.189.91.42
                                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                                              • 185.125.190.26
                                                                              aarch64.elfGet hashmaliciousMiraiBrowse
                                                                              • 91.189.91.42
                                                                              vejfa5.elfGet hashmaliciousUnknownBrowse
                                                                              • 185.125.190.26
                                                                              INIT7CHFBI.x86.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                                              • 109.202.202.202
                                                                              FBI.arm5.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                                              • 109.202.202.202
                                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                                              • 109.202.202.202
                                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                                              • 109.202.202.202
                                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                                              • 109.202.202.202
                                                                              arm5.elfGet hashmaliciousUnknownBrowse
                                                                              • 109.202.202.202
                                                                              rjfe686.elfGet hashmaliciousUnknownBrowse
                                                                              • 109.202.202.202
                                                                              aarch64.elfGet hashmaliciousMiraiBrowse
                                                                              • 109.202.202.202
                                                                              sh4.elfGet hashmaliciousUnknownBrowse
                                                                              • 109.202.202.202
                                                                              efefa7.elfGet hashmaliciousMiraiBrowse
                                                                              • 109.202.202.202
                                                                              No context
                                                                              No context
                                                                              No created / dropped files found
                                                                              File type:ELF 32-bit LSB executable, MIPS, MIPS-I version 1 (SYSV), statically linked, stripped
                                                                              Entropy (8bit):5.53377314222002
                                                                              TrID:
                                                                              • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                                                                              File name:FBI.mpsl.elf
                                                                              File size:150'112 bytes
                                                                              MD5:5ec356608a575cf57e0b90019dc1edff
                                                                              SHA1:6f7b194628b403e1b66420bec9cf853337c0d7a8
                                                                              SHA256:e5240047c2b3d7fd7e1e54f5bd18554f0d22c6f6ecfe06be38e27bffd4efe6e1
                                                                              SHA512:40c77a6ca2cfb422ee13996eac9c6b06a90be800a5206de504ce24edaa1219da247b90805560cbab4d1beecc4719160e78725d9114875db3d7b04ecff36b9281
                                                                              SSDEEP:1536:l3M2bKBo+0NFgNZhEyv2zJuoaZ8jCSRCt6+5Jx0/Jwq75hsp8nKxD:tYhEVzPasCB/e575hsp8nK
                                                                              TLSH:CEE3D606BF109EB7C81FDD3301F98B0124CCB49725A53B6B3674DA69BA5A58B05E3CE4
                                                                              File Content Preview:.ELF......................@.4...hG......4. ...(........p......@...@...........................@...@.|...|.....................F...F.....tv..........Q.td................................................P.F....<...'!......'.......................<`..'!... ..

                                                                              ELF header

                                                                              Class:ELF32
                                                                              Data:2's complement, little endian
                                                                              Version:1 (current)
                                                                              Machine:MIPS R3000
                                                                              Version Number:0x1
                                                                              Type:EXEC (Executable file)
                                                                              OS/ABI:UNIX - System V
                                                                              ABI Version:0
                                                                              Entry Point Address:0x4002a0
                                                                              Flags:0x1007
                                                                              ELF Header Size:52
                                                                              Program Header Offset:52
                                                                              Program Header Size:32
                                                                              Number of Program Headers:4
                                                                              Section Header Offset:149352
                                                                              Section Header Size:40
                                                                              Number of Section Headers:19
                                                                              Header String Table Index:18
                                                                              NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                                                              NULL0x00x00x00x00x0000
                                                                              .reginfoMIPS_REGINFO0x4000b40xb40x180x180x2A004
                                                                              .initPROGBITS0x4000cc0xcc0x8c0x00x6AX004
                                                                              .textPROGBITS0x4001600x1600x1acb00x00x6AX0016
                                                                              .finiPROGBITS0x41ae100x1ae100x5c0x00x6AX004
                                                                              .rodataPROGBITS0x41ae700x1ae700x4c080x00x2A0016
                                                                              .eh_framePROGBITS0x41fa780x1fa780x40x00x2A004
                                                                              .ctorsPROGBITS0x4600000x200000x80x00x3WA004
                                                                              .dtorsPROGBITS0x4600080x200080x80x00x3WA004
                                                                              .jcrPROGBITS0x4600100x200100x40x00x3WA004
                                                                              .data.rel.roPROGBITS0x4600140x200140x4f40x00x3WA004
                                                                              .dataPROGBITS0x4605100x205100x5500x00x3WA0016
                                                                              .gotPROGBITS0x460a600x20a600x5a40x40x10000003WAp0016
                                                                              .sbssNOBITS0x4610040x210040x240x00x10000003WAp004
                                                                              .bssNOBITS0x4610300x210040x66440x00x3WA0016
                                                                              .commentPROGBITS0x00x210040xdb60x00x0001
                                                                              .mdebug.abi32PROGBITS0xdb60x21dba0x00x00x0001
                                                                              .pdrPROGBITS0x00x21dbc0x29200x00x0004
                                                                              .shstrtabSTRTAB0x00x246dc0x8a0x00x0001
                                                                              TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                                              <unknown>0xb40x4000b40x4000b40x180x180.98340x4R 0x4.reginfo
                                                                              LOAD0x00x4000000x4000000x1fa7c0x1fa7c5.68190x5R E0x10000.reginfo .init .text .fini .rodata .eh_frame
                                                                              LOAD0x200000x4600000x4600000x10040x76744.41840x6RW 0x10000.ctors .dtors .jcr .data.rel.ro .data .got .sbss .bss
                                                                              GNU_STACK0x00x00x00x00x00.00000x7RWE0x4

                                                                              Download Network PCAP: filteredfull

                                                                              • Total Packets: 89
                                                                              • 1337 undefined
                                                                              • 443 (HTTPS)
                                                                              • 80 (HTTP)
                                                                              TimestampSource PortDest PortSource IPDest IP
                                                                              Apr 2, 2025 08:36:09.165496111 CEST43928443192.168.2.2391.189.91.42
                                                                              Apr 2, 2025 08:36:09.427630901 CEST362581337192.168.2.23176.65.144.18
                                                                              Apr 2, 2025 08:36:09.629386902 CEST133736258176.65.144.18192.168.2.23
                                                                              Apr 2, 2025 08:36:11.524851084 CEST362601337192.168.2.23176.65.144.18
                                                                              Apr 2, 2025 08:36:11.728660107 CEST133736260176.65.144.18192.168.2.23
                                                                              Apr 2, 2025 08:36:14.632194042 CEST362621337192.168.2.23176.65.144.18
                                                                              Apr 2, 2025 08:36:14.792840004 CEST42836443192.168.2.2391.189.91.43
                                                                              Apr 2, 2025 08:36:14.836534977 CEST133736262176.65.144.18192.168.2.23
                                                                              Apr 2, 2025 08:36:16.783261061 CEST362641337192.168.2.23176.65.144.18
                                                                              Apr 2, 2025 08:36:16.986156940 CEST133736264176.65.144.18192.168.2.23
                                                                              Apr 2, 2025 08:36:19.839278936 CEST362661337192.168.2.23176.65.144.18
                                                                              Apr 2, 2025 08:36:20.040972948 CEST133736266176.65.144.18192.168.2.23
                                                                              Apr 2, 2025 08:36:21.987889051 CEST362681337192.168.2.23176.65.144.18
                                                                              Apr 2, 2025 08:36:22.188610077 CEST133736268176.65.144.18192.168.2.23
                                                                              Apr 2, 2025 08:36:25.042972088 CEST362701337192.168.2.23176.65.144.18
                                                                              Apr 2, 2025 08:36:25.247956991 CEST133736270176.65.144.18192.168.2.23
                                                                              Apr 2, 2025 08:36:27.191226006 CEST362721337192.168.2.23176.65.144.18
                                                                              Apr 2, 2025 08:36:27.392955065 CEST133736272176.65.144.18192.168.2.23
                                                                              Apr 2, 2025 08:36:30.250363111 CEST362741337192.168.2.23176.65.144.18
                                                                              Apr 2, 2025 08:36:30.452588081 CEST133736274176.65.144.18192.168.2.23
                                                                              Apr 2, 2025 08:36:30.918682098 CEST43928443192.168.2.2391.189.91.42
                                                                              Apr 2, 2025 08:36:32.395035028 CEST362761337192.168.2.23176.65.144.18
                                                                              Apr 2, 2025 08:36:32.595076084 CEST133736276176.65.144.18192.168.2.23
                                                                              Apr 2, 2025 08:36:35.455574036 CEST362781337192.168.2.23176.65.144.18
                                                                              Apr 2, 2025 08:36:35.658128977 CEST133736278176.65.144.18192.168.2.23
                                                                              Apr 2, 2025 08:36:37.061834097 CEST4251680192.168.2.23109.202.202.202
                                                                              Apr 2, 2025 08:36:37.597662926 CEST362801337192.168.2.23176.65.144.18
                                                                              Apr 2, 2025 08:36:37.801472902 CEST133736280176.65.144.18192.168.2.23
                                                                              Apr 2, 2025 08:36:40.661027908 CEST362821337192.168.2.23176.65.144.18
                                                                              Apr 2, 2025 08:36:40.862859011 CEST133736282176.65.144.18192.168.2.23
                                                                              Apr 2, 2025 08:36:41.157196999 CEST42836443192.168.2.2391.189.91.43
                                                                              Apr 2, 2025 08:36:42.804272890 CEST362841337192.168.2.23176.65.144.18
                                                                              Apr 2, 2025 08:36:43.005748987 CEST133736284176.65.144.18192.168.2.23
                                                                              Apr 2, 2025 08:36:45.865175962 CEST362861337192.168.2.23176.65.144.18
                                                                              Apr 2, 2025 08:36:46.073559046 CEST133736286176.65.144.18192.168.2.23
                                                                              Apr 2, 2025 08:36:48.008570910 CEST362881337192.168.2.23176.65.144.18
                                                                              Apr 2, 2025 08:36:48.209253073 CEST133736288176.65.144.18192.168.2.23
                                                                              Apr 2, 2025 08:36:51.076014042 CEST362901337192.168.2.23176.65.144.18
                                                                              Apr 2, 2025 08:36:51.277256012 CEST133736290176.65.144.18192.168.2.23
                                                                              Apr 2, 2025 08:36:53.212095022 CEST362921337192.168.2.23176.65.144.18
                                                                              Apr 2, 2025 08:36:53.418327093 CEST133736292176.65.144.18192.168.2.23
                                                                              Apr 2, 2025 08:36:56.279875040 CEST362941337192.168.2.23176.65.144.18
                                                                              Apr 2, 2025 08:36:56.481590033 CEST133736294176.65.144.18192.168.2.23
                                                                              Apr 2, 2025 08:36:58.420926094 CEST362961337192.168.2.23176.65.144.18
                                                                              Apr 2, 2025 08:36:58.629116058 CEST133736296176.65.144.18192.168.2.23
                                                                              Apr 2, 2025 08:37:01.484853983 CEST362981337192.168.2.23176.65.144.18
                                                                              Apr 2, 2025 08:37:01.691559076 CEST133736298176.65.144.18192.168.2.23
                                                                              Apr 2, 2025 08:37:03.631612062 CEST363001337192.168.2.23176.65.144.18
                                                                              Apr 2, 2025 08:37:03.832581043 CEST133736300176.65.144.18192.168.2.23
                                                                              Apr 2, 2025 08:37:06.694257975 CEST363021337192.168.2.23176.65.144.18
                                                                              Apr 2, 2025 08:37:06.894176960 CEST133736302176.65.144.18192.168.2.23
                                                                              Apr 2, 2025 08:37:08.834630013 CEST363041337192.168.2.23176.65.144.18
                                                                              Apr 2, 2025 08:37:09.036812067 CEST133736304176.65.144.18192.168.2.23
                                                                              Apr 2, 2025 08:37:11.873239994 CEST43928443192.168.2.2391.189.91.42
                                                                              Apr 2, 2025 08:37:11.896639109 CEST363061337192.168.2.23176.65.144.18
                                                                              Apr 2, 2025 08:37:12.098953962 CEST133736306176.65.144.18192.168.2.23
                                                                              Apr 2, 2025 08:37:14.038635015 CEST363081337192.168.2.23176.65.144.18
                                                                              Apr 2, 2025 08:37:14.241641998 CEST133736308176.65.144.18192.168.2.23
                                                                              Apr 2, 2025 08:37:17.102263927 CEST363101337192.168.2.23176.65.144.18
                                                                              Apr 2, 2025 08:37:17.306164980 CEST133736310176.65.144.18192.168.2.23
                                                                              Apr 2, 2025 08:37:19.244275093 CEST363121337192.168.2.23176.65.144.18
                                                                              Apr 2, 2025 08:37:19.450953007 CEST133736312176.65.144.18192.168.2.23
                                                                              Apr 2, 2025 08:37:22.308676004 CEST363141337192.168.2.23176.65.144.18
                                                                              Apr 2, 2025 08:37:22.509375095 CEST133736314176.65.144.18192.168.2.23
                                                                              Apr 2, 2025 08:37:24.454011917 CEST363161337192.168.2.23176.65.144.18
                                                                              Apr 2, 2025 08:37:24.661329985 CEST133736316176.65.144.18192.168.2.23
                                                                              Apr 2, 2025 08:37:27.512271881 CEST363181337192.168.2.23176.65.144.18
                                                                              Apr 2, 2025 08:37:27.716869116 CEST133736318176.65.144.18192.168.2.23
                                                                              Apr 2, 2025 08:37:29.664716005 CEST363201337192.168.2.23176.65.144.18
                                                                              Apr 2, 2025 08:37:29.869718075 CEST133736320176.65.144.18192.168.2.23
                                                                              Apr 2, 2025 08:37:32.720088005 CEST363221337192.168.2.23176.65.144.18
                                                                              Apr 2, 2025 08:37:32.922862053 CEST133736322176.65.144.18192.168.2.23
                                                                              Apr 2, 2025 08:37:34.873473883 CEST363241337192.168.2.23176.65.144.18
                                                                              Apr 2, 2025 08:37:35.075864077 CEST133736324176.65.144.18192.168.2.23
                                                                              Apr 2, 2025 08:37:37.928033113 CEST363261337192.168.2.23176.65.144.18
                                                                              Apr 2, 2025 08:37:38.129781961 CEST133736326176.65.144.18192.168.2.23
                                                                              Apr 2, 2025 08:37:40.079478025 CEST363281337192.168.2.23176.65.144.18
                                                                              Apr 2, 2025 08:37:40.281208038 CEST133736328176.65.144.18192.168.2.23
                                                                              Apr 2, 2025 08:37:43.134171009 CEST363301337192.168.2.23176.65.144.18
                                                                              Apr 2, 2025 08:37:43.335202932 CEST133736330176.65.144.18192.168.2.23
                                                                              Apr 2, 2025 08:37:45.286577940 CEST363321337192.168.2.23176.65.144.18
                                                                              Apr 2, 2025 08:37:45.491738081 CEST133736332176.65.144.18192.168.2.23
                                                                              Apr 2, 2025 08:37:48.340688944 CEST363341337192.168.2.23176.65.144.18
                                                                              Apr 2, 2025 08:37:48.543153048 CEST133736334176.65.144.18192.168.2.23
                                                                              Apr 2, 2025 08:37:50.496119022 CEST363361337192.168.2.23176.65.144.18
                                                                              Apr 2, 2025 08:37:50.698600054 CEST133736336176.65.144.18192.168.2.23
                                                                              Apr 2, 2025 08:37:53.547660112 CEST363381337192.168.2.23176.65.144.18
                                                                              Apr 2, 2025 08:37:53.749162912 CEST133736338176.65.144.18192.168.2.23
                                                                              Apr 2, 2025 08:37:55.702527046 CEST363401337192.168.2.23176.65.144.18
                                                                              Apr 2, 2025 08:37:55.906050920 CEST133736340176.65.144.18192.168.2.23
                                                                              Apr 2, 2025 08:37:58.751288891 CEST363421337192.168.2.23176.65.144.18
                                                                              Apr 2, 2025 08:37:58.967194080 CEST133736342176.65.144.18192.168.2.23
                                                                              Apr 2, 2025 08:38:00.908622026 CEST363441337192.168.2.23176.65.144.18
                                                                              Apr 2, 2025 08:38:01.110358953 CEST133736344176.65.144.18192.168.2.23
                                                                              Apr 2, 2025 08:38:03.969854116 CEST363461337192.168.2.23176.65.144.18
                                                                              Apr 2, 2025 08:38:04.172036886 CEST133736346176.65.144.18192.168.2.23
                                                                              Apr 2, 2025 08:38:06.113214970 CEST363481337192.168.2.23176.65.144.18
                                                                              Apr 2, 2025 08:38:06.323759079 CEST133736348176.65.144.18192.168.2.23
                                                                              Apr 2, 2025 08:38:09.174057007 CEST363501337192.168.2.23176.65.144.18
                                                                              Apr 2, 2025 08:38:09.375483036 CEST133736350176.65.144.18192.168.2.23
                                                                              Apr 2, 2025 08:38:11.325979948 CEST363521337192.168.2.23176.65.144.18
                                                                              Apr 2, 2025 08:38:11.527751923 CEST133736352176.65.144.18192.168.2.23
                                                                              Apr 2, 2025 08:38:14.378012896 CEST363541337192.168.2.23176.65.144.18
                                                                              Apr 2, 2025 08:38:14.581855059 CEST133736354176.65.144.18192.168.2.23
                                                                              Apr 2, 2025 08:38:16.529333115 CEST363561337192.168.2.23176.65.144.18
                                                                              Apr 2, 2025 08:38:16.729541063 CEST133736356176.65.144.18192.168.2.23
                                                                              Apr 2, 2025 08:38:19.584440947 CEST363581337192.168.2.23176.65.144.18
                                                                              Apr 2, 2025 08:38:19.792407036 CEST133736358176.65.144.18192.168.2.23
                                                                              Apr 2, 2025 08:38:21.731489897 CEST363601337192.168.2.23176.65.144.18
                                                                              Apr 2, 2025 08:38:21.932043076 CEST133736360176.65.144.18192.168.2.23
                                                                              Apr 2, 2025 08:38:24.796658993 CEST363621337192.168.2.23176.65.144.18
                                                                              Apr 2, 2025 08:38:24.998831034 CEST133736362176.65.144.18192.168.2.23
                                                                              Apr 2, 2025 08:38:26.934324980 CEST363641337192.168.2.23176.65.144.18
                                                                              Apr 2, 2025 08:38:27.138519049 CEST133736364176.65.144.18192.168.2.23
                                                                              Apr 2, 2025 08:38:30.000878096 CEST363661337192.168.2.23176.65.144.18
                                                                              Apr 2, 2025 08:38:30.203708887 CEST133736366176.65.144.18192.168.2.23
                                                                              Apr 2, 2025 08:38:32.140444040 CEST363681337192.168.2.23176.65.144.18
                                                                              Apr 2, 2025 08:38:32.342273951 CEST133736368176.65.144.18192.168.2.23
                                                                              Apr 2, 2025 08:38:35.205533981 CEST363701337192.168.2.23176.65.144.18
                                                                              Apr 2, 2025 08:38:35.409224987 CEST133736370176.65.144.18192.168.2.23
                                                                              Apr 2, 2025 08:38:37.344921112 CEST363721337192.168.2.23176.65.144.18
                                                                              Apr 2, 2025 08:38:37.547204971 CEST133736372176.65.144.18192.168.2.23
                                                                              Apr 2, 2025 08:38:40.411056995 CEST363741337192.168.2.23176.65.144.18
                                                                              Apr 2, 2025 08:38:40.613432884 CEST133736374176.65.144.18192.168.2.23
                                                                              Apr 2, 2025 08:38:42.549432993 CEST363761337192.168.2.23176.65.144.18
                                                                              Apr 2, 2025 08:38:42.751296043 CEST133736376176.65.144.18192.168.2.23
                                                                              Apr 2, 2025 08:38:45.615854979 CEST363781337192.168.2.23176.65.144.18
                                                                              Apr 2, 2025 08:38:45.820348024 CEST133736378176.65.144.18192.168.2.23
                                                                              Apr 2, 2025 08:38:47.753609896 CEST363801337192.168.2.23176.65.144.18
                                                                              Apr 2, 2025 08:38:47.954010010 CEST133736380176.65.144.18192.168.2.23
                                                                              Apr 2, 2025 08:38:50.822977066 CEST363821337192.168.2.23176.65.144.18
                                                                              Apr 2, 2025 08:38:51.023027897 CEST133736382176.65.144.18192.168.2.23
                                                                              Apr 2, 2025 08:38:52.957117081 CEST363841337192.168.2.23176.65.144.18
                                                                              Apr 2, 2025 08:38:53.157120943 CEST133736384176.65.144.18192.168.2.23
                                                                              Apr 2, 2025 08:38:56.025661945 CEST363861337192.168.2.23176.65.144.18
                                                                              Apr 2, 2025 08:38:56.226732969 CEST133736386176.65.144.18192.168.2.23
                                                                              Apr 2, 2025 08:38:58.160197020 CEST363881337192.168.2.23176.65.144.18
                                                                              Apr 2, 2025 08:38:58.365322113 CEST133736388176.65.144.18192.168.2.23
                                                                              Apr 2, 2025 08:39:01.229341984 CEST363901337192.168.2.23176.65.144.18
                                                                              Apr 2, 2025 08:39:01.433685064 CEST133736390176.65.144.18192.168.2.23
                                                                              Apr 2, 2025 08:39:03.368230104 CEST363921337192.168.2.23176.65.144.18
                                                                              Apr 2, 2025 08:39:03.572371006 CEST133736392176.65.144.18192.168.2.23
                                                                              Apr 2, 2025 08:39:06.435250044 CEST363941337192.168.2.23176.65.144.18
                                                                              Apr 2, 2025 08:39:06.636955023 CEST133736394176.65.144.18192.168.2.23
                                                                              Apr 2, 2025 08:39:08.574146986 CEST363961337192.168.2.23176.65.144.18
                                                                              Apr 2, 2025 08:39:08.774789095 CEST133736396176.65.144.18192.168.2.23
                                                                              Apr 2, 2025 08:39:11.639420986 CEST363981337192.168.2.23176.65.144.18
                                                                              Apr 2, 2025 08:39:11.839792013 CEST133736398176.65.144.18192.168.2.23
                                                                              Apr 2, 2025 08:39:13.777468920 CEST364001337192.168.2.23176.65.144.18
                                                                              Apr 2, 2025 08:39:13.978708029 CEST133736400176.65.144.18192.168.2.23
                                                                              Apr 2, 2025 08:39:16.841656923 CEST364021337192.168.2.23176.65.144.18
                                                                              Apr 2, 2025 08:39:17.044996023 CEST133736402176.65.144.18192.168.2.23
                                                                              Apr 2, 2025 08:39:18.981148005 CEST364041337192.168.2.23176.65.144.18
                                                                              Apr 2, 2025 08:39:19.184350014 CEST133736404176.65.144.18192.168.2.23
                                                                              Apr 2, 2025 08:39:22.047316074 CEST364061337192.168.2.23176.65.144.18
                                                                              Apr 2, 2025 08:39:22.250467062 CEST133736406176.65.144.18192.168.2.23
                                                                              Apr 2, 2025 08:39:24.186400890 CEST364081337192.168.2.23176.65.144.18
                                                                              Apr 2, 2025 08:39:24.388437986 CEST133736408176.65.144.18192.168.2.23
                                                                              Apr 2, 2025 08:39:27.253592968 CEST364101337192.168.2.23176.65.144.18
                                                                              Apr 2, 2025 08:39:27.453329086 CEST133736410176.65.144.18192.168.2.23
                                                                              Apr 2, 2025 08:39:29.391012907 CEST364121337192.168.2.23176.65.144.18
                                                                              Apr 2, 2025 08:39:29.592472076 CEST133736412176.65.144.18192.168.2.23
                                                                              Apr 2, 2025 08:39:32.455859900 CEST364141337192.168.2.23176.65.144.18
                                                                              Apr 2, 2025 08:39:32.657147884 CEST133736414176.65.144.18192.168.2.23
                                                                              Apr 2, 2025 08:39:34.594707966 CEST364161337192.168.2.23176.65.144.18
                                                                              Apr 2, 2025 08:39:34.797960043 CEST133736416176.65.144.18192.168.2.23
                                                                              Apr 2, 2025 08:39:37.660707951 CEST364181337192.168.2.23176.65.144.18
                                                                              Apr 2, 2025 08:39:37.862453938 CEST133736418176.65.144.18192.168.2.23
                                                                              Apr 2, 2025 08:39:39.799875975 CEST364201337192.168.2.23176.65.144.18
                                                                              Apr 2, 2025 08:39:40.002068043 CEST133736420176.65.144.18192.168.2.23
                                                                              Apr 2, 2025 08:39:42.865844965 CEST364221337192.168.2.23176.65.144.18
                                                                              Apr 2, 2025 08:39:43.067245007 CEST133736422176.65.144.18192.168.2.23

                                                                              System Behavior

                                                                              Start time (UTC):06:36:08
                                                                              Start date (UTC):02/04/2025
                                                                              Path:/tmp/FBI.mpsl.elf
                                                                              Arguments:/tmp/FBI.mpsl.elf
                                                                              File size:5773336 bytes
                                                                              MD5 hash:0d6f61f82cf2f781c6eb0661071d42d9

                                                                              Start time (UTC):06:36:09
                                                                              Start date (UTC):02/04/2025
                                                                              Path:/tmp/FBI.mpsl.elf
                                                                              Arguments:-
                                                                              File size:5773336 bytes
                                                                              MD5 hash:0d6f61f82cf2f781c6eb0661071d42d9

                                                                              Start time (UTC):06:36:09
                                                                              Start date (UTC):02/04/2025
                                                                              Path:/tmp/FBI.mpsl.elf
                                                                              Arguments:-
                                                                              File size:5773336 bytes
                                                                              MD5 hash:0d6f61f82cf2f781c6eb0661071d42d9

                                                                              Start time (UTC):06:36:09
                                                                              Start date (UTC):02/04/2025
                                                                              Path:/tmp/FBI.mpsl.elf
                                                                              Arguments:-
                                                                              File size:5773336 bytes
                                                                              MD5 hash:0d6f61f82cf2f781c6eb0661071d42d9

                                                                              Start time (UTC):06:36:09
                                                                              Start date (UTC):02/04/2025
                                                                              Path:/tmp/FBI.mpsl.elf
                                                                              Arguments:-
                                                                              File size:5773336 bytes
                                                                              MD5 hash:0d6f61f82cf2f781c6eb0661071d42d9

                                                                              Start time (UTC):06:36:09
                                                                              Start date (UTC):02/04/2025
                                                                              Path:/tmp/FBI.mpsl.elf
                                                                              Arguments:-
                                                                              File size:5773336 bytes
                                                                              MD5 hash:0d6f61f82cf2f781c6eb0661071d42d9

                                                                              Start time (UTC):06:36:11
                                                                              Start date (UTC):02/04/2025
                                                                              Path:/tmp/FBI.mpsl.elf
                                                                              Arguments:-
                                                                              File size:5773336 bytes
                                                                              MD5 hash:0d6f61f82cf2f781c6eb0661071d42d9

                                                                              Start time (UTC):06:36:11
                                                                              Start date (UTC):02/04/2025
                                                                              Path:/tmp/FBI.mpsl.elf
                                                                              Arguments:-
                                                                              File size:5773336 bytes
                                                                              MD5 hash:0d6f61f82cf2f781c6eb0661071d42d9