Linux
Analysis Report
rrrdsl.elf
Overview
General Information
Sample name: | rrrdsl.elf |
Analysis ID: | 1654338 |
MD5: | 90f1bfcf9d8c82dda42c2c8c5ed32bb0 |
SHA1: | a8061f0bb41d6fcd5ad060c9daebff654431d9b7 |
SHA256: | 145c01e665da22c4d816ead167874be9ca99ccfddd553b608c0997c9db68efd9 |
Tags: | elfuser-abuse_ch |
Infos: |
Detection
Score: | 56 |
Range: | 0 - 100 |
Signatures
Classification
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1654338 |
Start date and time: | 2025-04-02 09:52:35 +02:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 4m 45s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultlinuxfilecookbook.jbs |
Analysis system description: | Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11) |
Analysis Mode: | default |
Sample name: | rrrdsl.elf |
Detection: | MAL |
Classification: | mal56.evad.linELF@0/6@6/0 |
Command: | /tmp/rrrdsl.elf |
PID: | 6218 |
Exit Code: | 0 |
Exit Code Info: | |
Killed: | False |
Standard Output: | kovey/cursinq was here, go away! |
Standard Error: |
- system is lnxubuntu20
- rrrdsl.elf New Fork (PID: 6222, Parent: 6218)
- rrrdsl.elf New Fork (PID: 6224, Parent: 6222)
- rrrdsl.elf New Fork (PID: 6225, Parent: 6222)
- systemd New Fork (PID: 6228, Parent: 1)
- systemd New Fork (PID: 6245, Parent: 1)
- systemd New Fork (PID: 6249, Parent: 1)
- dash New Fork (PID: 6277, Parent: 4340)
- dash New Fork (PID: 6278, Parent: 4340)
- cleanup
- • AV Detection
- • Spreading
- • Networking
- • System Summary
- • Data Obfuscation
- • Persistence and Installation Behavior
- • Hooking and other Techniques for Hiding and Protection
- • Malware Analysis System Evasion
Click to jump to signature section
AV Detection |
---|
Source: | Virustotal: | Perma Link | ||
Source: | ReversingLabs: |
Source: | String: |
Source: | TCP traffic: |
Source: | Socket: | Jump to behavior |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: |
Source: | DNS traffic detected: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | .symtab present: |
Source: | SIGKILL sent: | Jump to behavior |
Source: | Classification label: |
Data Obfuscation |
---|
Source: | Deleted: | Jump to behavior |
Source: | File: | Jump to behavior | ||
Source: | File: | Jump to behavior |
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior |
Source: | Rm executable: | Jump to behavior | ||
Source: | Rm executable: | Jump to behavior |
Source: | Reads from proc file: | Jump to behavior |
Hooking and other Techniques for Hiding and Protection |
---|
Source: | File: | Jump to behavior |
Source: | Queries kernel information via 'uname': | Jump to behavior | ||
Source: | Queries kernel information via 'uname': | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | 1 Scripting | Valid Accounts | Windows Management Instrumentation | 1 Scripting | Path Interception | 1 Hidden Files and Directories | 1 OS Credential Dumping | 11 Security Software Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | 11 File Deletion | LSASS Memory | 1 System Information Discovery | Remote Desktop Protocol | Data from Removable Media | 1 Non-Standard Port | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 1 Non-Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | 2 Application Layer Protocol | Traffic Duplication | Data Destruction |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
22% | Virustotal | Browse | ||
31% | ReversingLabs | Linux.Backdoor.Mirai |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
raw.awaken-network.net | 141.98.10.142 | true | false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
54.171.230.55 | unknown | United States | 16509 | AMAZON-02US | false | |
141.98.10.142 | raw.awaken-network.net | Lithuania | 209605 | HOSTBALTICLT | false | |
109.202.202.202 | unknown | Switzerland | 13030 | INIT7CH | false | |
91.189.91.43 | unknown | United Kingdom | 41231 | CANONICAL-ASGB | false | |
91.189.91.42 | unknown | United Kingdom | 41231 | CANONICAL-ASGB | false |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
54.171.230.55 | Get hash | malicious | Prometei | Browse | ||
Get hash | malicious | Prometei | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Prometei | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Prometei | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Prometei | Browse | |||
Get hash | malicious | Unknown | Browse | |||
141.98.10.142 | Get hash | malicious | Unknown | Browse | ||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
109.202.202.202 | Get hash | malicious | Unknown | Browse |
| |
91.189.91.43 | Get hash | malicious | Mirai | Browse | ||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Gafgyt, Mirai | Browse | |||
Get hash | malicious | Gafgyt, Mirai | Browse | |||
Get hash | malicious | Gafgyt, Mirai | Browse | |||
Get hash | malicious | Prometei | Browse | |||
Get hash | malicious | Prometei | Browse | |||
Get hash | malicious | Prometei | Browse |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
raw.awaken-network.net | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
CANONICAL-ASGB | Get hash | malicious | Mirai | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Gafgyt, Mirai | Browse |
| ||
Get hash | malicious | Gafgyt, Mirai | Browse |
| ||
Get hash | malicious | Gafgyt, Mirai | Browse |
| ||
Get hash | malicious | Prometei | Browse |
| ||
Get hash | malicious | Prometei | Browse |
| ||
HOSTBALTICLT | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
AMAZON-02US | Get hash | malicious | Mirai | Browse |
| |
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | CryptOne, LummaC Stealer | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | PureLog Stealer, zgRAT | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | Gafgyt, Mirai | Browse |
| ||
Get hash | malicious | Gafgyt, Mirai | Browse |
| ||
Get hash | malicious | Prometei | Browse |
| ||
INIT7CH | Get hash | malicious | Mirai | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Gafgyt, Mirai | Browse |
| ||
Get hash | malicious | Gafgyt, Mirai | Browse |
| ||
Get hash | malicious | Gafgyt, Mirai | Browse |
| ||
Get hash | malicious | Prometei | Browse |
| ||
Get hash | malicious | Prometei | Browse |
| ||
Get hash | malicious | Prometei | Browse |
|
Process: | /lib/systemd/systemd-journald |
File Type: | |
Category: | dropped |
Size (bytes): | 223 |
Entropy (8bit): | 5.5204752631881195 |
Encrypted: | false |
SSDEEP: | 3:SbFVVmFyinKMsPOYsn9ms954Hh6SnLAqC+h6KV+h6CQzuxm+vjDD7g+sjs7Lbgw3:SbFuFyLVIg1BG+f+M+vgTji4s |
MD5: | 2BC22CED11041B3EFEEB2942EC9008E6 |
SHA1: | 8BFA469B4E37A13E38FBC1BC7E0150294D252A5A |
SHA-256: | A800DF422AE6C1199A827A1EF5B75840AC3EB829AAEA1A9DDE07B59AE2E8EF31 |
SHA-512: | E8DD38B50E40F407E904B96C1282601C25CB9985458D8E3DB99F9AAB39744466402BFFE31B4F7420514BF4FE2453A34EFD21895ECF8AF89F033142E91F8ABFFC |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | /lib/systemd/systemd-journald |
File Type: | |
Category: | dropped |
Size (bytes): | 223 |
Entropy (8bit): | 5.499049365930416 |
Encrypted: | false |
SSDEEP: | 3:SbFVVmFyinKMsPOYsn9ms954Hh6SnLAqC+h6KV+h6CQzuxmpRrRcRUdDAOrcBDYy:SbFuFyLVIg1BG+f+MTRcydbI10ji4s |
MD5: | 123C0518F07FE3EB970735C37C2218B1 |
SHA1: | 11C0E1B9C56C4439C152DC158F7A725B3FB53150 |
SHA-256: | D32F96E64455FE87256170670C458DF129AEB1514D02060103C496CABB23FC37 |
SHA-512: | 23F15BB6ACD25C4A3D4EB7F025EE7842247D0A92C5BCF8C54FE15E2D448808D1CD2E359BBCE3D8852F664B6DB9D84F7419F6F63C2F78546731D0259561BAE611 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | /tmp/rrrdsl.elf |
File Type: | |
Category: | dropped |
Size (bytes): | 17 |
Entropy (8bit): | 3.4548223999466066 |
Encrypted: | false |
SSDEEP: | 3:TgxWgn:Tgp |
MD5: | F45CC7E78FB5617F878C634E2885244A |
SHA1: | 7F497D824D12411C2F761F4C0373E2B0219A04F2 |
SHA-256: | D1ABE99F1E1720A73437D51722ECFB9E22ABDA8565F245FD6E1811BEE4AB2A42 |
SHA-512: | 0D76AFC2AFE7FA666C4DF98903E70DFC935E7B9F55CE0657FE182324320E1AAA18E7746BAEE33D1166519EAB66F050964CF84F29E758A4B192A5FADB7A43F1FC |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | /tmp/rrrdsl.elf |
File Type: | |
Category: | dropped |
Size (bytes): | 26 |
Entropy (8bit): | 3.8731406795131327 |
Encrypted: | false |
SSDEEP: | 3:TgxWO8HJN:Tg2JN |
MD5: | 94BB3F3C4E316B1BFDA0789F3F4CCF1C |
SHA1: | D30AE36DEDF23C1003471DDF03ABD529AFD78DC7 |
SHA-256: | A6E654A189D43F2ECD936B290B0E3816BA80B39599736442E886809BA05E966E |
SHA-512: | 3C3B3C7F3B4BEF3B52972823D6BDD1EF1E4E29A8A88851A681ECFCF5D26E3056ACFD1332D91E44F2E2ADFA4A9D4E863A1AB64E0087D50F646C813BE04D9FD294 |
Malicious: | false |
Reputation: | moderate, very likely benign file |
Preview: |
Process: | /lib/systemd/systemd-journald |
File Type: | |
Category: | dropped |
Size (bytes): | 240 |
Entropy (8bit): | 1.448047321524811 |
Encrypted: | false |
SSDEEP: | 3:F31HlrWduNWdut:F37CuNCu |
MD5: | EA6600E5FCF614629632FCAD14E30646 |
SHA1: | 7549DF6251528FF1E3406C8EA759B393476C14D9 |
SHA-256: | 7835AF05DF6AF6BBF442ADDC624642B89621BC1BF1A4948A701AA363C90A8340 |
SHA-512: | 5E6979525FE3C2E12D1B304249542B8BC4C2D290D54443B3E182DFDECA019D58D13CEE3227593EDD98D57097255C6FE9D076B9BBFF882CEBF817EA7585DBBF37 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | /lib/systemd/systemd-journald |
File Type: | |
Category: | dropped |
Size (bytes): | 240 |
Entropy (8bit): | 1.459526019450492 |
Encrypted: | false |
SSDEEP: | 3:F31HlLJLvxLfll/bJLvxLf/:F3dNb9N |
MD5: | 86044EC664BCA36AF4CB51726D1669E9 |
SHA1: | 41E8218B4606E2529CD8960E43D4E858F464CB0E |
SHA-256: | 31117170D99A03E77D17582B3F17A6867B48FC0DF56FC4C786F58B3CF86F8A83 |
SHA-512: | F3D48D7EC97B0DFCF353A75061CFFD8AD63F0D4A5DED7BE71AF6CA931F7740646BFACB359F90B450B5BFB7DDE95D54BE1980EF8E5CD9AC5C8FC1BBFCC9F3EB9B |
Malicious: | false |
Reputation: | low |
Preview: |
File type: | |
Entropy (8bit): | 5.065296042054076 |
TrID: |
|
File name: | rrrdsl.elf |
File size: | 210'564 bytes |
MD5: | 90f1bfcf9d8c82dda42c2c8c5ed32bb0 |
SHA1: | a8061f0bb41d6fcd5ad060c9daebff654431d9b7 |
SHA256: | 145c01e665da22c4d816ead167874be9ca99ccfddd553b608c0997c9db68efd9 |
SHA512: | 9012718526777004d82cc8409568f2f348f7d413e473fa4d23cddd25d6b3f99e40d63fa8c2d55ef01a2ffce28cb531b599d6030501458ee50948daef747c6fd7 |
SSDEEP: | 3072:ZuJqa79HZLA5aYfBRQfLcu84WR6EHGDAGTFh:ZuJv79H9AJDQDcugR3UAGB |
TLSH: | 0B24C80AAB610EFBDCAFCE3706E9070529CC651722A93B393674D528F54B54B49E3C78 |
File Content Preview: | .ELF....................`.@.4...T4......4. ...(...............@...@.@...@...............D...D.F.D.F..Z..\"..........Q.td...............................<...'!......'.......................<...'!... .........9'.. ........................<x..'!...........0.9 |
ELF header | |
---|---|
Class: | |
Data: | |
Version: | |
Machine: | |
Version Number: | |
Type: | |
OS/ABI: | |
ABI Version: | 0 |
Entry Point Address: | |
Flags: | |
ELF Header Size: | 52 |
Program Header Offset: | 52 |
Program Header Size: | 32 |
Number of Program Headers: | 3 |
Section Header Offset: | 210004 |
Section Header Size: | 40 |
Number of Section Headers: | 14 |
Header String Table Index: | 13 |
Name | Type | Address | Offset | Size | EntSize | Flags | Flags Description | Link | Info | Align |
---|---|---|---|---|---|---|---|---|---|---|
NULL | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0 | 0 | 0 | ||
.init | PROGBITS | 0x400094 | 0x94 | 0x8c | 0x0 | 0x6 | AX | 0 | 0 | 4 |
.text | PROGBITS | 0x400120 | 0x120 | 0x29780 | 0x0 | 0x6 | AX | 0 | 0 | 16 |
.fini | PROGBITS | 0x4298a0 | 0x298a0 | 0x5c | 0x0 | 0x6 | AX | 0 | 0 | 4 |
.rodata | PROGBITS | 0x429900 | 0x29900 | 0x4040 | 0x0 | 0x2 | A | 0 | 0 | 16 |
.ctors | PROGBITS | 0x46d944 | 0x2d944 | 0xc | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.dtors | PROGBITS | 0x46d950 | 0x2d950 | 0x8 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.data.rel.ro | PROGBITS | 0x46d95c | 0x2d95c | 0x4ac | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.data | PROGBITS | 0x46de20 | 0x2de20 | 0x4b50 | 0x0 | 0x3 | WA | 0 | 0 | 32 |
.got | PROGBITS | 0x472970 | 0x32970 | 0xa80 | 0x4 | 0x10000003 | WAp | 0 | 0 | 16 |
.sbss | NOBITS | 0x4733f0 | 0x333f0 | 0x50 | 0x0 | 0x10000003 | WAp | 0 | 0 | 4 |
.bss | NOBITS | 0x473440 | 0x333f0 | 0xc760 | 0x0 | 0x3 | WA | 0 | 0 | 16 |
.mdebug.abi32 | PROGBITS | 0x138c | 0x333f0 | 0x0 | 0x0 | 0x0 | 0 | 0 | 1 | |
.shstrtab | STRTAB | 0x0 | 0x333f0 | 0x64 | 0x0 | 0x0 | 0 | 0 | 1 |
Type | Offset | Virtual Address | Physical Address | File Size | Memory Size | Entropy | Flags | Flags Description | Align | Prog Interpreter | Section Mappings |
---|---|---|---|---|---|---|---|---|---|---|---|
LOAD | 0x0 | 0x400000 | 0x400000 | 0x2d940 | 0x2d940 | 5.3630 | 0x5 | R E | 0x10000 | .init .text .fini .rodata | |
LOAD | 0x2d944 | 0x46d944 | 0x46d944 | 0x5aac | 0x1225c | 1.5570 | 0x6 | RW | 0x10000 | .ctors .dtors .data.rel.ro .data .got .sbss .bss | |
GNU_STACK | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0.0000 | 0x7 | RWE | 0x4 |
Download Network PCAP: filtered – full
- Total Packets: 53
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Apr 2, 2025 09:53:17.362481117 CEST | 43928 | 443 | 192.168.2.23 | 91.189.91.42 |
Apr 2, 2025 09:53:19.149940014 CEST | 41898 | 2211 | 192.168.2.23 | 141.98.10.142 |
Apr 2, 2025 09:53:19.340264082 CEST | 2211 | 41898 | 141.98.10.142 | 192.168.2.23 |
Apr 2, 2025 09:53:19.340383053 CEST | 41898 | 2211 | 192.168.2.23 | 141.98.10.142 |
Apr 2, 2025 09:53:19.342695951 CEST | 41898 | 2211 | 192.168.2.23 | 141.98.10.142 |
Apr 2, 2025 09:53:19.439026117 CEST | 50620 | 7733 | 192.168.2.23 | 141.98.10.142 |
Apr 2, 2025 09:53:19.534621000 CEST | 2211 | 41898 | 141.98.10.142 | 192.168.2.23 |
Apr 2, 2025 09:53:19.534725904 CEST | 41898 | 2211 | 192.168.2.23 | 141.98.10.142 |
Apr 2, 2025 09:53:19.732381105 CEST | 2211 | 41898 | 141.98.10.142 | 192.168.2.23 |
Apr 2, 2025 09:53:20.465832949 CEST | 50620 | 7733 | 192.168.2.23 | 141.98.10.142 |
Apr 2, 2025 09:53:22.481731892 CEST | 50620 | 7733 | 192.168.2.23 | 141.98.10.142 |
Apr 2, 2025 09:53:22.741813898 CEST | 42836 | 443 | 192.168.2.23 | 91.189.91.43 |
Apr 2, 2025 09:53:24.273401022 CEST | 42516 | 80 | 192.168.2.23 | 109.202.202.202 |
Apr 2, 2025 09:53:24.544509888 CEST | 50622 | 7733 | 192.168.2.23 | 141.98.10.142 |
Apr 2, 2025 09:53:25.553167105 CEST | 50622 | 7733 | 192.168.2.23 | 141.98.10.142 |
Apr 2, 2025 09:53:26.577330112 CEST | 50620 | 7733 | 192.168.2.23 | 141.98.10.142 |
Apr 2, 2025 09:53:27.568929911 CEST | 50622 | 7733 | 192.168.2.23 | 141.98.10.142 |
Apr 2, 2025 09:53:30.160543919 CEST | 33608 | 443 | 192.168.2.23 | 54.171.230.55 |
Apr 2, 2025 09:53:31.696432114 CEST | 50622 | 7733 | 192.168.2.23 | 141.98.10.142 |
Apr 2, 2025 09:53:34.725841999 CEST | 2211 | 41898 | 141.98.10.142 | 192.168.2.23 |
Apr 2, 2025 09:53:34.726182938 CEST | 41898 | 2211 | 192.168.2.23 | 141.98.10.142 |
Apr 2, 2025 09:53:34.767977953 CEST | 50620 | 7733 | 192.168.2.23 | 141.98.10.142 |
Apr 2, 2025 09:53:38.351442099 CEST | 43928 | 443 | 192.168.2.23 | 91.189.91.42 |
Apr 2, 2025 09:53:39.887342930 CEST | 50622 | 7733 | 192.168.2.23 | 141.98.10.142 |
Apr 2, 2025 09:53:42.876451969 CEST | 33608 | 443 | 192.168.2.23 | 54.171.230.55 |
Apr 2, 2025 09:53:43.044898033 CEST | 443 | 33608 | 54.171.230.55 | 192.168.2.23 |
Apr 2, 2025 09:53:48.590086937 CEST | 42836 | 443 | 192.168.2.23 | 91.189.91.43 |
Apr 2, 2025 09:53:49.918375015 CEST | 2211 | 41898 | 141.98.10.142 | 192.168.2.23 |
Apr 2, 2025 09:53:49.918632030 CEST | 41898 | 2211 | 192.168.2.23 | 141.98.10.142 |
Apr 2, 2025 09:53:50.893834114 CEST | 50620 | 7733 | 192.168.2.23 | 141.98.10.142 |
Apr 2, 2025 09:53:54.733246088 CEST | 42516 | 80 | 192.168.2.23 | 109.202.202.202 |
Apr 2, 2025 09:53:56.013144016 CEST | 50622 | 7733 | 192.168.2.23 | 141.98.10.142 |
Apr 2, 2025 09:54:05.109783888 CEST | 2211 | 41898 | 141.98.10.142 | 192.168.2.23 |
Apr 2, 2025 09:54:05.109968901 CEST | 41898 | 2211 | 192.168.2.23 | 141.98.10.142 |
Apr 2, 2025 09:54:19.305813074 CEST | 43928 | 443 | 192.168.2.23 | 91.189.91.42 |
Apr 2, 2025 09:54:20.297087908 CEST | 2211 | 41898 | 141.98.10.142 | 192.168.2.23 |
Apr 2, 2025 09:54:20.297389030 CEST | 41898 | 2211 | 192.168.2.23 | 141.98.10.142 |
Apr 2, 2025 09:54:23.401902914 CEST | 50620 | 7733 | 192.168.2.23 | 141.98.10.142 |
Apr 2, 2025 09:54:29.384588957 CEST | 41898 | 2211 | 192.168.2.23 | 141.98.10.142 |
Apr 2, 2025 09:54:29.544475079 CEST | 50622 | 7733 | 192.168.2.23 | 141.98.10.142 |
Apr 2, 2025 09:54:29.580106974 CEST | 2211 | 41898 | 141.98.10.142 | 192.168.2.23 |
Apr 2, 2025 09:54:39.393450975 CEST | 41898 | 2211 | 192.168.2.23 | 141.98.10.142 |
Apr 2, 2025 09:54:39.585150003 CEST | 2211 | 41898 | 141.98.10.142 | 192.168.2.23 |
Apr 2, 2025 09:54:39.783315897 CEST | 42836 | 443 | 192.168.2.23 | 91.189.91.43 |
Apr 2, 2025 09:54:54.688594103 CEST | 2211 | 41898 | 141.98.10.142 | 192.168.2.23 |
Apr 2, 2025 09:54:54.688812017 CEST | 41898 | 2211 | 192.168.2.23 | 141.98.10.142 |
Apr 2, 2025 09:54:59.190318108 CEST | 2211 | 41898 | 141.98.10.142 | 192.168.2.23 |
Apr 2, 2025 09:55:00.404221058 CEST | 41904 | 2211 | 192.168.2.23 | 141.98.10.142 |
Apr 2, 2025 09:55:00.592072010 CEST | 2211 | 41904 | 141.98.10.142 | 192.168.2.23 |
Apr 2, 2025 09:55:00.592277050 CEST | 41904 | 2211 | 192.168.2.23 | 141.98.10.142 |
Apr 2, 2025 09:55:00.594172955 CEST | 41904 | 2211 | 192.168.2.23 | 141.98.10.142 |
Apr 2, 2025 09:55:01.188231945 CEST | 41904 | 2211 | 192.168.2.23 | 141.98.10.142 |
Apr 2, 2025 09:55:01.377872944 CEST | 2211 | 41904 | 141.98.10.142 | 192.168.2.23 |
Apr 2, 2025 09:55:01.378084898 CEST | 41904 | 2211 | 192.168.2.23 | 141.98.10.142 |
Apr 2, 2025 09:55:01.565902948 CEST | 2211 | 41904 | 141.98.10.142 | 192.168.2.23 |
Apr 2, 2025 09:55:01.565927029 CEST | 2211 | 41904 | 141.98.10.142 | 192.168.2.23 |
Apr 2, 2025 09:55:01.566556931 CEST | 41904 | 2211 | 192.168.2.23 | 141.98.10.142 |
Apr 2, 2025 09:55:01.566556931 CEST | 41904 | 2211 | 192.168.2.23 | 141.98.10.142 |
Apr 2, 2025 09:55:01.771156073 CEST | 41906 | 2211 | 192.168.2.23 | 141.98.10.142 |
Apr 2, 2025 09:55:02.204186916 CEST | 2211 | 41906 | 141.98.10.142 | 192.168.2.23 |
Apr 2, 2025 09:55:02.204708099 CEST | 41906 | 2211 | 192.168.2.23 | 141.98.10.142 |
Apr 2, 2025 09:55:02.206324100 CEST | 41906 | 2211 | 192.168.2.23 | 141.98.10.142 |
Apr 2, 2025 09:55:02.639482021 CEST | 2211 | 41906 | 141.98.10.142 | 192.168.2.23 |
Apr 2, 2025 09:55:02.639677048 CEST | 41906 | 2211 | 192.168.2.23 | 141.98.10.142 |
Apr 2, 2025 09:55:03.079309940 CEST | 2211 | 41906 | 141.98.10.142 | 192.168.2.23 |
Apr 2, 2025 09:55:18.137365103 CEST | 2211 | 41906 | 141.98.10.142 | 192.168.2.23 |
Apr 2, 2025 09:55:18.137707949 CEST | 41906 | 2211 | 192.168.2.23 | 141.98.10.142 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Apr 2, 2025 09:53:18.933832884 CEST | 39870 | 53 | 192.168.2.23 | 8.8.8.8 |
Apr 2, 2025 09:53:19.036216021 CEST | 53 | 39870 | 8.8.8.8 | 192.168.2.23 |
Apr 2, 2025 09:53:19.038579941 CEST | 35657 | 53 | 192.168.2.23 | 8.8.8.8 |
Apr 2, 2025 09:53:19.148785114 CEST | 53 | 35657 | 8.8.8.8 | 192.168.2.23 |
Apr 2, 2025 09:55:00.196742058 CEST | 52491 | 53 | 192.168.2.23 | 8.8.8.8 |
Apr 2, 2025 09:55:00.297482014 CEST | 53 | 52491 | 8.8.8.8 | 192.168.2.23 |
Apr 2, 2025 09:55:00.299828053 CEST | 54593 | 53 | 192.168.2.23 | 8.8.8.8 |
Apr 2, 2025 09:55:00.402846098 CEST | 53 | 54593 | 8.8.8.8 | 192.168.2.23 |
Apr 2, 2025 09:55:01.568468094 CEST | 56668 | 53 | 192.168.2.23 | 8.8.8.8 |
Apr 2, 2025 09:55:01.668963909 CEST | 53 | 56668 | 8.8.8.8 | 192.168.2.23 |
Apr 2, 2025 09:55:01.672559023 CEST | 39919 | 53 | 192.168.2.23 | 8.8.8.8 |
Apr 2, 2025 09:55:01.769562960 CEST | 53 | 39919 | 8.8.8.8 | 192.168.2.23 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Apr 2, 2025 09:53:18.933832884 CEST | 192.168.2.23 | 8.8.8.8 | 0x7276 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Apr 2, 2025 09:53:19.038579941 CEST | 192.168.2.23 | 8.8.8.8 | 0xc8ae | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Apr 2, 2025 09:55:00.196742058 CEST | 192.168.2.23 | 8.8.8.8 | 0x2c78 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Apr 2, 2025 09:55:00.299828053 CEST | 192.168.2.23 | 8.8.8.8 | 0x81cd | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Apr 2, 2025 09:55:01.568468094 CEST | 192.168.2.23 | 8.8.8.8 | 0x78f5 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Apr 2, 2025 09:55:01.672559023 CEST | 192.168.2.23 | 8.8.8.8 | 0xb919 | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Apr 2, 2025 09:53:19.036216021 CEST | 8.8.8.8 | 192.168.2.23 | 0x7276 | No error (0) | 141.98.10.142 | A (IP address) | IN (0x0001) | false | ||
Apr 2, 2025 09:53:19.148785114 CEST | 8.8.8.8 | 192.168.2.23 | 0xc8ae | No error (0) | 141.98.10.142 | A (IP address) | IN (0x0001) | false | ||
Apr 2, 2025 09:55:00.297482014 CEST | 8.8.8.8 | 192.168.2.23 | 0x2c78 | No error (0) | 141.98.10.142 | A (IP address) | IN (0x0001) | false | ||
Apr 2, 2025 09:55:00.402846098 CEST | 8.8.8.8 | 192.168.2.23 | 0x81cd | No error (0) | 141.98.10.142 | A (IP address) | IN (0x0001) | false | ||
Apr 2, 2025 09:55:01.668963909 CEST | 8.8.8.8 | 192.168.2.23 | 0x78f5 | No error (0) | 141.98.10.142 | A (IP address) | IN (0x0001) | false | ||
Apr 2, 2025 09:55:01.769562960 CEST | 8.8.8.8 | 192.168.2.23 | 0xb919 | No error (0) | 141.98.10.142 | A (IP address) | IN (0x0001) | false |
System Behavior
Start time (UTC): | 07:53:17 |
Start date (UTC): | 02/04/2025 |
Path: | /tmp/rrrdsl.elf |
Arguments: | /tmp/rrrdsl.elf |
File size: | 5773336 bytes |
MD5 hash: | 0d6f61f82cf2f781c6eb0661071d42d9 |
Start time (UTC): | 07:53:17 |
Start date (UTC): | 02/04/2025 |
Path: | /tmp/rrrdsl.elf |
Arguments: | - |
File size: | 5773336 bytes |
MD5 hash: | 0d6f61f82cf2f781c6eb0661071d42d9 |
Start time (UTC): | 07:53:17 |
Start date (UTC): | 02/04/2025 |
Path: | /tmp/rrrdsl.elf |
Arguments: | - |
File size: | 5773336 bytes |
MD5 hash: | 0d6f61f82cf2f781c6eb0661071d42d9 |
Start time (UTC): | 07:53:17 |
Start date (UTC): | 02/04/2025 |
Path: | /tmp/rrrdsl.elf |
Arguments: | - |
File size: | 5773336 bytes |
MD5 hash: | 0d6f61f82cf2f781c6eb0661071d42d9 |
Start time (UTC): | 07:53:18 |
Start date (UTC): | 02/04/2025 |
Path: | /usr/lib/systemd/systemd |
Arguments: | - |
File size: | 1620224 bytes |
MD5 hash: | 9b2bec7092a40488108543f9334aab75 |
Start time (UTC): | 07:53:18 |
Start date (UTC): | 02/04/2025 |
Path: | /usr/bin/journalctl |
Arguments: | /usr/bin/journalctl --smart-relinquish-var |
File size: | 80120 bytes |
MD5 hash: | bf3a987344f3bacafc44efd882abda8b |
Start time (UTC): | 07:53:18 |
Start date (UTC): | 02/04/2025 |
Path: | /usr/lib/systemd/systemd |
Arguments: | - |
File size: | 1620224 bytes |
MD5 hash: | 9b2bec7092a40488108543f9334aab75 |
Start time (UTC): | 07:53:18 |
Start date (UTC): | 02/04/2025 |
Path: | /lib/systemd/systemd-journald |
Arguments: | /lib/systemd/systemd-journald |
File size: | 162032 bytes |
MD5 hash: | 474667ece6cecb5e04c6eb897a1d0d9e |
Start time (UTC): | 07:53:23 |
Start date (UTC): | 02/04/2025 |
Path: | /usr/lib/systemd/systemd |
Arguments: | - |
File size: | 1620224 bytes |
MD5 hash: | 9b2bec7092a40488108543f9334aab75 |
Start time (UTC): | 07:53:23 |
Start date (UTC): | 02/04/2025 |
Path: | /usr/bin/journalctl |
Arguments: | /usr/bin/journalctl --flush |
File size: | 80120 bytes |
MD5 hash: | bf3a987344f3bacafc44efd882abda8b |
Start time (UTC): | 07:53:41 |
Start date (UTC): | 02/04/2025 |
Path: | /usr/bin/dash |
Arguments: | - |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 07:53:41 |
Start date (UTC): | 02/04/2025 |
Path: | /usr/bin/rm |
Arguments: | rm -f /tmp/tmp.HBlUBSH8iu /tmp/tmp.4Koznmh0eB /tmp/tmp.fptI3MUqUD |
File size: | 72056 bytes |
MD5 hash: | aa2b5496fdbfd88e38791ab81f90b95b |
Start time (UTC): | 07:53:41 |
Start date (UTC): | 02/04/2025 |
Path: | /usr/bin/dash |
Arguments: | - |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 07:53:41 |
Start date (UTC): | 02/04/2025 |
Path: | /usr/bin/rm |
Arguments: | rm -f /tmp/tmp.HBlUBSH8iu /tmp/tmp.4Koznmh0eB /tmp/tmp.fptI3MUqUD |
File size: | 72056 bytes |
MD5 hash: | aa2b5496fdbfd88e38791ab81f90b95b |