Linux
Analysis Report
drea4.elf
Overview
General Information
Sample name: | drea4.elf |
Analysis ID: | 1654410 |
MD5: | 4d62d320f777c6787d9357459e36470e |
SHA1: | c5c6f7e10c8230ca27cee9357c7ac542a63d46f7 |
SHA256: | 03069f187732fe9890a92d7b25e44d804176a1f6c7b5a6537a8de7d166111d5f |
Tags: | elfuser-abuse_ch |
Infos: |
Detection
Score: | 60 |
Range: | 0 - 100 |
Signatures
Classification
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1654410 |
Start date and time: | 2025-04-02 10:51:14 +02:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 4m 50s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultlinuxfilecookbook.jbs |
Analysis system description: | Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11) |
Analysis Mode: | default |
Sample name: | drea4.elf |
Detection: | MAL |
Classification: | mal60.troj.evad.linELF@0/6@11/0 |
Command: | /tmp/drea4.elf |
PID: | 6224 |
Exit Code: | 0 |
Exit Code Info: | |
Killed: | False |
Standard Output: | kovey/cursinq was here, go away! |
Standard Error: |
- • AV Detection
- • Spreading
- • Networking
- • System Summary
- • Data Obfuscation
- • Persistence and Installation Behavior
- • Hooking and other Techniques for Hiding and Protection
- • Malware Analysis System Evasion
Click to jump to signature section
AV Detection |
---|
Source: | Virustotal: | Perma Link | ||
Source: | ReversingLabs: |
Source: | String: |
Networking |
---|
Source: | DNS traffic detected: |
Source: | TCP traffic: |
Source: | Socket: | Jump to behavior |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | .symtab present: |
Source: | SIGKILL sent: | Jump to behavior |
Source: | Classification label: |
Data Obfuscation |
---|
Source: | Deleted: | Jump to behavior |
Source: | File: | Jump to behavior | ||
Source: | File: | Jump to behavior |
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior |
Source: | Rm executable: | Jump to behavior | ||
Source: | Rm executable: | Jump to behavior |
Source: | Reads from proc file: | Jump to behavior |
Hooking and other Techniques for Hiding and Protection |
---|
Source: | File: | Jump to behavior |
Source: | Queries kernel information via 'uname': | Jump to behavior | ||
Source: | Queries kernel information via 'uname': | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | 1 Scripting | Valid Accounts | Windows Management Instrumentation | 1 Scripting | Path Interception | 1 Hidden Files and Directories | 1 OS Credential Dumping | 11 Security Software Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | 11 File Deletion | LSASS Memory | 1 System Information Discovery | Remote Desktop Protocol | Data from Removable Media | 1 Non-Standard Port | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 1 Non-Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | 2 Application Layer Protocol | Traffic Duplication | Data Destruction |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
42% | Virustotal | Browse | ||
42% | ReversingLabs | Linux.Backdoor.Mirai |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
raw.awaken-network.net | 141.98.10.142 | true | false | high | |
raw.awaken-network.net. [malformed] | unknown | unknown | false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
34.249.145.219 | unknown | United States | 16509 | AMAZON-02US | false | |
141.98.10.142 | raw.awaken-network.net | Lithuania | 209605 | HOSTBALTICLT | false | |
109.202.202.202 | unknown | Switzerland | 13030 | INIT7CH | false | |
91.189.91.43 | unknown | United Kingdom | 41231 | CANONICAL-ASGB | false | |
91.189.91.42 | unknown | United Kingdom | 41231 | CANONICAL-ASGB | false |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
34.249.145.219 | Get hash | malicious | Unknown | Browse | ||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Gafgyt, Mirai | Browse | |||
Get hash | malicious | Gafgyt, Mirai | Browse | |||
Get hash | malicious | Prometei | Browse | |||
Get hash | malicious | Prometei | Browse | |||
141.98.10.142 | Get hash | malicious | Unknown | Browse | ||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
109.202.202.202 | Get hash | malicious | Unknown | Browse |
| |
91.189.91.43 | Get hash | malicious | Unknown | Browse | ||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Gafgyt, Mirai | Browse | |||
Get hash | malicious | Gafgyt, Mirai | Browse |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
raw.awaken-network.net | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
CANONICAL-ASGB | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Gafgyt, Mirai | Browse |
| ||
HOSTBALTICLT | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
INIT7CH | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Gafgyt, Mirai | Browse |
| ||
Get hash | malicious | Gafgyt, Mirai | Browse |
| ||
AMAZON-02US | Get hash | malicious | HTMLPhisher, Invisible JS, Tycoon2FA | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | FormBook | Browse |
|
Process: | /lib/systemd/systemd-journald |
File Type: | |
Category: | dropped |
Size (bytes): | 223 |
Entropy (8bit): | 5.559171184636957 |
Encrypted: | false |
SSDEEP: | 3:SbFVVmFyinKMsPOYsn9ms954Hh6SnLAqC+h6KV+h6CQzuxmpNTRAScSZNpy0Mxs+:SbFuFyLVIg1BG+f+MvRAxmbMqji4s |
MD5: | 03D762A87EC03501C7CCD975719A38AA |
SHA1: | E72309E8A57D4620F6BCD02D9AB74DDB707363D1 |
SHA-256: | 5D1087526084CB926527310A67FE246A60C0113587A24657112F0E69A221FDEE |
SHA-512: | 051E2B11B31703512343E161C22AD65595808BCB989AF0221EB665DB2BEA741EEE28955155C4054D3FBD7B4E204CE3EBCC6ACF9D6AD46C3E4AC736A5C8008558 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | /lib/systemd/systemd-journald |
File Type: | |
Category: | dropped |
Size (bytes): | 223 |
Entropy (8bit): | 5.502538043457177 |
Encrypted: | false |
SSDEEP: | 3:SbFVVmFyinKMsPOYsn9ms954Hh6SnLAqC+h6KV+h6CQzuxmsah3QkQhHK3W80ws+:SbFuFyLVIg1BG+f+MsaNEI3W80ji4s |
MD5: | 17E41BC7B19B3FEA6CA14659AB5B1F6A |
SHA1: | 33B3887A63F366896BEBDB03DAC46369085BFFC0 |
SHA-256: | 708FD51A9D1D48D1323977BD6CBEA42BFA83AE0B84CE43E18769282535BEA561 |
SHA-512: | 4CC4878E97E6A96F574C8A681DCCC2092284B6F837E3F3EFB5367C9021D11D4946F21D6D5C5237D6C893589A30657191F78A32B7D15AFD88DD988115492F6FD3 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | /tmp/drea4.elf |
File Type: | |
Category: | dropped |
Size (bytes): | 16 |
Entropy (8bit): | 3.625 |
Encrypted: | false |
SSDEEP: | 3:TghA4Lill:TgWGill |
MD5: | 316C395856E59A4DF4F6C436462FCB1C |
SHA1: | DB9792C3BB80EE91F2AB07966803B86B0EDF927C |
SHA-256: | 80E6B23A0957CAA636A21CB14E4F233A1E9A6C94AE112FE5CDE34695084A97B8 |
SHA-512: | 1AAB1B252C7BE4DE8FB008C2AC05A095A1EEA12D6E2568363841A395DCE6EAB574F2315095F7FB7BBB350BB6F2C76C97D69BCBC5A3BAFCDDB7257C652FC73314 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | /tmp/drea4.elf |
File Type: | |
Category: | dropped |
Size (bytes): | 25 |
Entropy (8bit): | 4.0536606896881855 |
Encrypted: | false |
SSDEEP: | 3:TghA4LiloHJN:TgWGilaJN |
MD5: | 483D6A09B2CA216506A99F8710FAB5BF |
SHA1: | B0AEB578E506E3F7369C95EE5DAACB58F79C5541 |
SHA-256: | E4A0665D33137B88F25EE53F14032589A277B97D643F210CF387EB748E5E39B9 |
SHA-512: | 6366E089E41B4A0CECD9B63B35A6ED1BDB4E96CEFBE795B93DE306720086CB7E7DDBFF25D50FFE75BC415C48056F7D552FF18E6597845BC473C728EA9423E13B |
Malicious: | false |
Reputation: | moderate, very likely benign file |
Preview: |
Process: | /lib/systemd/systemd-journald |
File Type: | |
Category: | dropped |
Size (bytes): | 240 |
Entropy (8bit): | 1.3755317395372328 |
Encrypted: | false |
SSDEEP: | 3:F31HlyhsdfaXKhsdf+/l:F3C656A |
MD5: | D4C3799F6BC4EBEFE5F63B8D46ED7039 |
SHA1: | E0536A2FC602C7013013CB73DED18084EB763420 |
SHA-256: | 2304B486FF30FDE30631A2F38F3A7D1B1D3C3046475055F82956F2D13FC23FB5 |
SHA-512: | 50E343145F5ABEA12927856500F8E52427F419342CF9CDFCB4FEA2DC65E57FB083A8AAABE45CC121F252E11E7B72D1B5807D42614D311F81FE358E8899AC77C7 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | /lib/systemd/systemd-journald |
File Type: | |
Category: | dropped |
Size (bytes): | 240 |
Entropy (8bit): | 1.4392978820660198 |
Encrypted: | false |
SSDEEP: | 3:F31HlACb/FLTXllYCb/FLTnl:F3wm/Fgm/F |
MD5: | 72B8D19242770B2D3253E32032C9335F |
SHA1: | DAF6CB64E5F286571CE79D706156F08EA254EF6E |
SHA-256: | 061B9DA1B9D7855656BB4FB9BE2AA7946A14577C80D5F8033D3E9A3B499A6FEB |
SHA-512: | FB017A776C3FB6EB1714C9E309B583BFE7357BDC078C3AC6803BC0C223547186F2992B0A3288EFD4107E9C422FD31BC87458DF17AD40456414EA72DD279CD063 |
Malicious: | false |
Reputation: | low |
Preview: |
File type: | |
Entropy (8bit): | 5.501352345620335 |
TrID: |
|
File name: | drea4.elf |
File size: | 156'672 bytes |
MD5: | 4d62d320f777c6787d9357459e36470e |
SHA1: | c5c6f7e10c8230ca27cee9357c7ac542a63d46f7 |
SHA256: | 03069f187732fe9890a92d7b25e44d804176a1f6c7b5a6537a8de7d166111d5f |
SHA512: | 37bb157cff88d488ef0efbcb504cba0b10527994c851eb3cfa895ea6b275274d1fd03e41e8d96d7f9f8721e080ed5f79d3dbe075e6dc1a3582c2ca5f8726677c |
SSDEEP: | 3072:MnP+TWJxFa1xFM54MLDJ4/wXcjn8TYKJ:Mn161xe54MXJ44X+n8ce |
TLSH: | C5E31846B8915F67C6C712BBFB5E428D372617A9D3EE72038D255F20378A85B0E37242 |
File Content Preview: | .ELF...a..........(.........4...pb......4. ...(.....................8...8...............<...<...<....J..............Q.td..................................-...L."....u..........0@-.\P...0....S.0...P@...0... ....R......0...0...........0... ....R..... 0....S |
ELF header | |
---|---|
Class: | |
Data: | |
Version: | |
Machine: | |
Version Number: | |
Type: | |
OS/ABI: | |
ABI Version: | 0 |
Entry Point Address: | |
Flags: | |
ELF Header Size: | 52 |
Program Header Offset: | 52 |
Program Header Size: | 32 |
Number of Program Headers: | 3 |
Section Header Offset: | 156272 |
Section Header Size: | 40 |
Number of Section Headers: | 10 |
Header String Table Index: | 9 |
Name | Type | Address | Offset | Size | EntSize | Flags | Flags Description | Link | Info | Align |
---|---|---|---|---|---|---|---|---|---|---|
NULL | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0 | 0 | 0 | ||
.init | PROGBITS | 0x8094 | 0x94 | 0x18 | 0x0 | 0x6 | AX | 0 | 0 | 4 |
.text | PROGBITS | 0x80b0 | 0xb0 | 0x1d67c | 0x0 | 0x6 | AX | 0 | 0 | 16 |
.fini | PROGBITS | 0x2572c | 0x1d72c | 0x14 | 0x0 | 0x6 | AX | 0 | 0 | 4 |
.rodata | PROGBITS | 0x25740 | 0x1d740 | 0x3ff8 | 0x0 | 0x2 | A | 0 | 0 | 4 |
.ctors | PROGBITS | 0x3173c | 0x2173c | 0xc | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.dtors | PROGBITS | 0x31748 | 0x21748 | 0x8 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.data | PROGBITS | 0x31760 | 0x21760 | 0x4ad0 | 0x0 | 0x3 | WA | 0 | 0 | 32 |
.bss | NOBITS | 0x36230 | 0x26230 | 0xc5dc | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.shstrtab | STRTAB | 0x0 | 0x26230 | 0x3e | 0x0 | 0x0 | 0 | 0 | 1 |
Type | Offset | Virtual Address | Physical Address | File Size | Memory Size | Entropy | Flags | Flags Description | Align | Prog Interpreter | Section Mappings |
---|---|---|---|---|---|---|---|---|---|---|---|
LOAD | 0x0 | 0x8000 | 0x8000 | 0x21738 | 0x21738 | 5.9408 | 0x5 | R E | 0x8000 | .init .text .fini .rodata | |
LOAD | 0x2173c | 0x3173c | 0x3173c | 0x4af4 | 0x110d0 | 0.5956 | 0x6 | RW | 0x8000 | .ctors .dtors .data .bss | |
GNU_STACK | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0.0000 | 0x7 | RWE | 0x4 |
Download Network PCAP: filtered – full
- Total Packets: 59
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Apr 2, 2025 10:52:00.199384928 CEST | 43928 | 443 | 192.168.2.23 | 91.189.91.42 |
Apr 2, 2025 10:52:02.112963915 CEST | 41904 | 2211 | 192.168.2.23 | 141.98.10.142 |
Apr 2, 2025 10:52:02.304315090 CEST | 2211 | 41904 | 141.98.10.142 | 192.168.2.23 |
Apr 2, 2025 10:52:02.304657936 CEST | 41904 | 2211 | 192.168.2.23 | 141.98.10.142 |
Apr 2, 2025 10:52:02.313589096 CEST | 41904 | 2211 | 192.168.2.23 | 141.98.10.142 |
Apr 2, 2025 10:52:02.430469990 CEST | 50626 | 7733 | 192.168.2.23 | 141.98.10.142 |
Apr 2, 2025 10:52:02.500473022 CEST | 2211 | 41904 | 141.98.10.142 | 192.168.2.23 |
Apr 2, 2025 10:52:02.500530005 CEST | 41904 | 2211 | 192.168.2.23 | 141.98.10.142 |
Apr 2, 2025 10:52:02.687324047 CEST | 2211 | 41904 | 141.98.10.142 | 192.168.2.23 |
Apr 2, 2025 10:52:02.767976046 CEST | 2211 | 41904 | 141.98.10.142 | 192.168.2.23 |
Apr 2, 2025 10:52:02.768068075 CEST | 41904 | 2211 | 192.168.2.23 | 141.98.10.142 |
Apr 2, 2025 10:52:02.768330097 CEST | 41904 | 2211 | 192.168.2.23 | 141.98.10.142 |
Apr 2, 2025 10:52:03.430859089 CEST | 50626 | 7733 | 192.168.2.23 | 141.98.10.142 |
Apr 2, 2025 10:52:03.842129946 CEST | 41908 | 2211 | 192.168.2.23 | 141.98.10.142 |
Apr 2, 2025 10:52:04.030930042 CEST | 2211 | 41908 | 141.98.10.142 | 192.168.2.23 |
Apr 2, 2025 10:52:04.031021118 CEST | 41908 | 2211 | 192.168.2.23 | 141.98.10.142 |
Apr 2, 2025 10:52:04.038228035 CEST | 41908 | 2211 | 192.168.2.23 | 141.98.10.142 |
Apr 2, 2025 10:52:04.226982117 CEST | 2211 | 41908 | 141.98.10.142 | 192.168.2.23 |
Apr 2, 2025 10:52:04.227063894 CEST | 41908 | 2211 | 192.168.2.23 | 141.98.10.142 |
Apr 2, 2025 10:52:04.416953087 CEST | 2211 | 41908 | 141.98.10.142 | 192.168.2.23 |
Apr 2, 2025 10:52:05.446573973 CEST | 50626 | 7733 | 192.168.2.23 | 141.98.10.142 |
Apr 2, 2025 10:52:05.830547094 CEST | 42836 | 443 | 192.168.2.23 | 91.189.91.43 |
Apr 2, 2025 10:52:07.110349894 CEST | 42516 | 80 | 192.168.2.23 | 109.202.202.202 |
Apr 2, 2025 10:52:08.768819094 CEST | 50630 | 7733 | 192.168.2.23 | 141.98.10.142 |
Apr 2, 2025 10:52:09.670044899 CEST | 50626 | 7733 | 192.168.2.23 | 141.98.10.142 |
Apr 2, 2025 10:52:09.798007011 CEST | 50630 | 7733 | 192.168.2.23 | 141.98.10.142 |
Apr 2, 2025 10:52:11.813795090 CEST | 50630 | 7733 | 192.168.2.23 | 141.98.10.142 |
Apr 2, 2025 10:52:16.069189072 CEST | 50630 | 7733 | 192.168.2.23 | 141.98.10.142 |
Apr 2, 2025 10:52:17.860953093 CEST | 50626 | 7733 | 192.168.2.23 | 141.98.10.142 |
Apr 2, 2025 10:52:19.417978048 CEST | 2211 | 41908 | 141.98.10.142 | 192.168.2.23 |
Apr 2, 2025 10:52:19.418025970 CEST | 41908 | 2211 | 192.168.2.23 | 141.98.10.142 |
Apr 2, 2025 10:52:20.934740067 CEST | 43928 | 443 | 192.168.2.23 | 91.189.91.42 |
Apr 2, 2025 10:52:22.128079891 CEST | 39256 | 443 | 192.168.2.23 | 34.249.145.219 |
Apr 2, 2025 10:52:22.128125906 CEST | 443 | 39256 | 34.249.145.219 | 192.168.2.23 |
Apr 2, 2025 10:52:22.128284931 CEST | 39256 | 443 | 192.168.2.23 | 34.249.145.219 |
Apr 2, 2025 10:52:22.128618956 CEST | 39256 | 443 | 192.168.2.23 | 34.249.145.219 |
Apr 2, 2025 10:52:22.128632069 CEST | 443 | 39256 | 34.249.145.219 | 192.168.2.23 |
Apr 2, 2025 10:52:24.260032892 CEST | 50630 | 7733 | 192.168.2.23 | 141.98.10.142 |
Apr 2, 2025 10:52:33.218986034 CEST | 42836 | 443 | 192.168.2.23 | 91.189.91.43 |
Apr 2, 2025 10:52:33.986783028 CEST | 50626 | 7733 | 192.168.2.23 | 141.98.10.142 |
Apr 2, 2025 10:52:34.606674910 CEST | 2211 | 41908 | 141.98.10.142 | 192.168.2.23 |
Apr 2, 2025 10:52:34.606873035 CEST | 41908 | 2211 | 192.168.2.23 | 141.98.10.142 |
Apr 2, 2025 10:52:37.314325094 CEST | 42516 | 80 | 192.168.2.23 | 109.202.202.202 |
Apr 2, 2025 10:52:40.385808945 CEST | 50630 | 7733 | 192.168.2.23 | 141.98.10.142 |
Apr 2, 2025 10:52:49.798472881 CEST | 2211 | 41908 | 141.98.10.142 | 192.168.2.23 |
Apr 2, 2025 10:52:49.798666954 CEST | 41908 | 2211 | 192.168.2.23 | 141.98.10.142 |
Apr 2, 2025 10:53:01.886857986 CEST | 43928 | 443 | 192.168.2.23 | 91.189.91.42 |
Apr 2, 2025 10:53:04.989852905 CEST | 2211 | 41908 | 141.98.10.142 | 192.168.2.23 |
Apr 2, 2025 10:53:04.990056992 CEST | 41908 | 2211 | 192.168.2.23 | 141.98.10.142 |
Apr 2, 2025 10:53:08.030128956 CEST | 50626 | 7733 | 192.168.2.23 | 141.98.10.142 |
Apr 2, 2025 10:53:14.100404024 CEST | 41908 | 2211 | 192.168.2.23 | 141.98.10.142 |
Apr 2, 2025 10:53:14.173135042 CEST | 50630 | 7733 | 192.168.2.23 | 141.98.10.142 |
Apr 2, 2025 10:53:14.290177107 CEST | 2211 | 41908 | 141.98.10.142 | 192.168.2.23 |
Apr 2, 2025 10:53:22.120456934 CEST | 39256 | 443 | 192.168.2.23 | 34.249.145.219 |
Apr 2, 2025 10:53:22.164278030 CEST | 443 | 39256 | 34.249.145.219 | 192.168.2.23 |
Apr 2, 2025 10:53:24.109515905 CEST | 41908 | 2211 | 192.168.2.23 | 141.98.10.142 |
Apr 2, 2025 10:53:24.297010899 CEST | 2211 | 41908 | 141.98.10.142 | 192.168.2.23 |
Apr 2, 2025 10:53:39.538316011 CEST | 2211 | 41908 | 141.98.10.142 | 192.168.2.23 |
Apr 2, 2025 10:53:39.538624048 CEST | 41908 | 2211 | 192.168.2.23 | 141.98.10.142 |
Apr 2, 2025 10:53:54.733643055 CEST | 2211 | 41908 | 141.98.10.142 | 192.168.2.23 |
Apr 2, 2025 10:53:54.733812094 CEST | 41908 | 2211 | 192.168.2.23 | 141.98.10.142 |
Apr 2, 2025 10:54:05.029033899 CEST | 443 | 39256 | 34.249.145.219 | 192.168.2.23 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Apr 2, 2025 10:52:01.533310890 CEST | 58265 | 53 | 192.168.2.23 | 8.8.8.8 |
Apr 2, 2025 10:52:01.634239912 CEST | 53 | 58265 | 8.8.8.8 | 192.168.2.23 |
Apr 2, 2025 10:52:01.637172937 CEST | 49353 | 53 | 192.168.2.23 | 8.8.8.8 |
Apr 2, 2025 10:52:01.727866888 CEST | 53 | 49353 | 8.8.8.8 | 192.168.2.23 |
Apr 2, 2025 10:52:01.729773045 CEST | 45918 | 53 | 192.168.2.23 | 8.8.8.8 |
Apr 2, 2025 10:52:01.820282936 CEST | 53 | 45918 | 8.8.8.8 | 192.168.2.23 |
Apr 2, 2025 10:52:01.827397108 CEST | 39357 | 53 | 192.168.2.23 | 8.8.8.8 |
Apr 2, 2025 10:52:01.916692972 CEST | 53 | 39357 | 8.8.8.8 | 192.168.2.23 |
Apr 2, 2025 10:52:01.920273066 CEST | 42551 | 53 | 192.168.2.23 | 8.8.8.8 |
Apr 2, 2025 10:52:02.011425972 CEST | 53 | 42551 | 8.8.8.8 | 192.168.2.23 |
Apr 2, 2025 10:52:02.016830921 CEST | 40834 | 53 | 192.168.2.23 | 8.8.8.8 |
Apr 2, 2025 10:52:02.109967947 CEST | 53 | 40834 | 8.8.8.8 | 192.168.2.23 |
Apr 2, 2025 10:52:02.773752928 CEST | 51552 | 53 | 192.168.2.23 | 8.8.8.8 |
Apr 2, 2025 10:52:02.864310980 CEST | 53 | 51552 | 8.8.8.8 | 192.168.2.23 |
Apr 2, 2025 10:52:02.867923975 CEST | 47532 | 53 | 192.168.2.23 | 8.8.8.8 |
Apr 2, 2025 10:52:02.960020065 CEST | 53 | 47532 | 8.8.8.8 | 192.168.2.23 |
Apr 2, 2025 10:52:02.998302937 CEST | 49142 | 53 | 192.168.2.23 | 8.8.8.8 |
Apr 2, 2025 10:52:03.091809988 CEST | 53 | 49142 | 8.8.8.8 | 192.168.2.23 |
Apr 2, 2025 10:52:03.094693899 CEST | 37735 | 53 | 192.168.2.23 | 8.8.8.8 |
Apr 2, 2025 10:52:03.196069002 CEST | 53 | 37735 | 8.8.8.8 | 192.168.2.23 |
Apr 2, 2025 10:52:03.198803902 CEST | 54672 | 53 | 192.168.2.23 | 8.8.8.8 |
Apr 2, 2025 10:52:03.292052984 CEST | 53 | 54672 | 8.8.8.8 | 192.168.2.23 |
Apr 2, 2025 10:52:03.295768976 CEST | 42781 | 53 | 192.168.2.23 | 8.8.8.8 |
Apr 2, 2025 10:52:03.421648979 CEST | 53 | 42781 | 8.8.8.8 | 192.168.2.23 |
Apr 2, 2025 10:52:03.432794094 CEST | 48935 | 53 | 192.168.2.23 | 8.8.8.8 |
Apr 2, 2025 10:52:03.554784060 CEST | 53 | 48935 | 8.8.8.8 | 192.168.2.23 |
Apr 2, 2025 10:52:03.557770014 CEST | 60875 | 53 | 192.168.2.23 | 8.8.8.8 |
Apr 2, 2025 10:52:03.649007082 CEST | 53 | 60875 | 8.8.8.8 | 192.168.2.23 |
Apr 2, 2025 10:52:03.652127028 CEST | 47445 | 53 | 192.168.2.23 | 8.8.8.8 |
Apr 2, 2025 10:52:03.745502949 CEST | 53 | 47445 | 8.8.8.8 | 192.168.2.23 |
Apr 2, 2025 10:52:03.748383045 CEST | 50127 | 53 | 192.168.2.23 | 8.8.8.8 |
Apr 2, 2025 10:52:03.839579105 CEST | 53 | 50127 | 8.8.8.8 | 192.168.2.23 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Apr 2, 2025 10:52:01.533310890 CEST | 192.168.2.23 | 8.8.8.8 | 0xe336 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Apr 2, 2025 10:52:01.637172937 CEST | 192.168.2.23 | 8.8.8.8 | 0x50ec | Standard query (0) | 256 | 433 | false | |
Apr 2, 2025 10:52:01.729773045 CEST | 192.168.2.23 | 8.8.8.8 | 0x50ec | Standard query (0) | 256 | 433 | false | |
Apr 2, 2025 10:52:01.827397108 CEST | 192.168.2.23 | 8.8.8.8 | 0x50ec | Standard query (0) | 256 | 433 | false | |
Apr 2, 2025 10:52:01.920273066 CEST | 192.168.2.23 | 8.8.8.8 | 0x50ec | Standard query (0) | 256 | 434 | false | |
Apr 2, 2025 10:52:02.016830921 CEST | 192.168.2.23 | 8.8.8.8 | 0x50ec | Standard query (0) | 256 | 434 | false | |
Apr 2, 2025 10:52:03.295768976 CEST | 192.168.2.23 | 8.8.8.8 | 0x90a5 | Standard query (0) | 256 | 435 | false | |
Apr 2, 2025 10:52:03.432794094 CEST | 192.168.2.23 | 8.8.8.8 | 0x90a5 | Standard query (0) | 256 | 435 | false | |
Apr 2, 2025 10:52:03.557770014 CEST | 192.168.2.23 | 8.8.8.8 | 0x90a5 | Standard query (0) | 256 | 435 | false | |
Apr 2, 2025 10:52:03.652127028 CEST | 192.168.2.23 | 8.8.8.8 | 0x90a5 | Standard query (0) | 256 | 435 | false | |
Apr 2, 2025 10:52:03.748383045 CEST | 192.168.2.23 | 8.8.8.8 | 0x90a5 | Standard query (0) | 256 | 435 | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Apr 2, 2025 10:52:01.634239912 CEST | 8.8.8.8 | 192.168.2.23 | 0xe336 | No error (0) | 141.98.10.142 | A (IP address) | IN (0x0001) | false |
System Behavior
Start time (UTC): | 08:52:00 |
Start date (UTC): | 02/04/2025 |
Path: | /tmp/drea4.elf |
Arguments: | /tmp/drea4.elf |
File size: | 4956856 bytes |
MD5 hash: | 5ebfcae4fe2471fcc5695c2394773ff1 |
Start time (UTC): | 08:52:00 |
Start date (UTC): | 02/04/2025 |
Path: | /tmp/drea4.elf |
Arguments: | - |
File size: | 4956856 bytes |
MD5 hash: | 5ebfcae4fe2471fcc5695c2394773ff1 |
Start time (UTC): | 08:52:00 |
Start date (UTC): | 02/04/2025 |
Path: | /tmp/drea4.elf |
Arguments: | - |
File size: | 4956856 bytes |
MD5 hash: | 5ebfcae4fe2471fcc5695c2394773ff1 |
Start time (UTC): | 08:52:00 |
Start date (UTC): | 02/04/2025 |
Path: | /tmp/drea4.elf |
Arguments: | - |
File size: | 4956856 bytes |
MD5 hash: | 5ebfcae4fe2471fcc5695c2394773ff1 |
Start time (UTC): | 08:52:01 |
Start date (UTC): | 02/04/2025 |
Path: | /usr/lib/systemd/systemd |
Arguments: | - |
File size: | 1620224 bytes |
MD5 hash: | 9b2bec7092a40488108543f9334aab75 |
Start time (UTC): | 08:52:01 |
Start date (UTC): | 02/04/2025 |
Path: | /usr/bin/journalctl |
Arguments: | /usr/bin/journalctl --smart-relinquish-var |
File size: | 80120 bytes |
MD5 hash: | bf3a987344f3bacafc44efd882abda8b |
Start time (UTC): | 08:52:02 |
Start date (UTC): | 02/04/2025 |
Path: | /usr/lib/systemd/systemd |
Arguments: | - |
File size: | 1620224 bytes |
MD5 hash: | 9b2bec7092a40488108543f9334aab75 |
Start time (UTC): | 08:52:02 |
Start date (UTC): | 02/04/2025 |
Path: | /lib/systemd/systemd-journald |
Arguments: | /lib/systemd/systemd-journald |
File size: | 162032 bytes |
MD5 hash: | 474667ece6cecb5e04c6eb897a1d0d9e |
Start time (UTC): | 08:52:08 |
Start date (UTC): | 02/04/2025 |
Path: | /usr/lib/systemd/systemd |
Arguments: | - |
File size: | 1620224 bytes |
MD5 hash: | 9b2bec7092a40488108543f9334aab75 |
Start time (UTC): | 08:52:08 |
Start date (UTC): | 02/04/2025 |
Path: | /usr/bin/journalctl |
Arguments: | /usr/bin/journalctl --flush |
File size: | 80120 bytes |
MD5 hash: | bf3a987344f3bacafc44efd882abda8b |
Start time (UTC): | 08:53:21 |
Start date (UTC): | 02/04/2025 |
Path: | /usr/bin/dash |
Arguments: | - |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 08:53:21 |
Start date (UTC): | 02/04/2025 |
Path: | /usr/bin/rm |
Arguments: | rm -f /tmp/tmp.2rpWcSBNXl /tmp/tmp.VLIxd1RKtm /tmp/tmp.uMZZxL5Pf3 |
File size: | 72056 bytes |
MD5 hash: | aa2b5496fdbfd88e38791ab81f90b95b |
Start time (UTC): | 08:53:21 |
Start date (UTC): | 02/04/2025 |
Path: | /usr/bin/dash |
Arguments: | - |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 08:53:21 |
Start date (UTC): | 02/04/2025 |
Path: | /usr/bin/rm |
Arguments: | rm -f /tmp/tmp.2rpWcSBNXl /tmp/tmp.VLIxd1RKtm /tmp/tmp.uMZZxL5Pf3 |
File size: | 72056 bytes |
MD5 hash: | aa2b5496fdbfd88e38791ab81f90b95b |