Loading ...

Play interactive tourEdit tour

Linux Analysis Report Josho.x86

Overview

General Information

Sample Name:Josho.x86
Analysis ID:556517
MD5:d3bcd7d304ca56b6f685073ae65fd399
SHA1:ce33c18115e73f32e83c693cf51b8b2aa201e886
SHA256:50f798eb3aadfd6966a479b74dff730bc03901ca78792f77e570ee5393f45c51
Tags:CVE-2021-44228elflog4jMirai
Infos:

Detection

Score:60
Range:0 - 100
Whitelisted:false

Signatures

Antivirus / Scanner detection for submitted sample
Multi AV Scanner detection for submitted file
Machine Learning detection for sample
Enumerates processes within the "proc" file system
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Detected TCP or UDP traffic on non-standard ports
Sample tries to kill a process (SIGKILL)
Sample has stripped symbol table

Classification

Analysis Advice

All HTTP servers contacted by the sample do not answer. Likely the sample is an old dropper which does no longer work

General Information

Joe Sandbox Version:34.0.0 Boulder Opal
Analysis ID:556517
Start date:20.01.2022
Start time:08:06:57
Joe Sandbox Product:CloudBasic
Overall analysis duration:0h 6m 30s
Hypervisor based Inspection enabled:false
Report type:full
Sample file name:Josho.x86
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Detection:MAL
Classification:mal60.linX86@0/0@0/0
Warnings:
Show All
  • VT rate limit hit for: Josho.x86

Process Tree

  • system is lnxubuntu20
  • Josho.x86 (PID: 5225, Parent: 5115, MD5: d3bcd7d304ca56b6f685073ae65fd399) Arguments: /tmp/Josho.x86
  • cleanup

Yara Overview

No yara matches

Jbx Signature Overview

Click to jump to signature section

Show All Signature Results

AV Detection:

barindex
Antivirus / Scanner detection for submitted sampleShow sources
Source: Josho.x86Avira: detected
Multi AV Scanner detection for submitted fileShow sources
Source: Josho.x86Metadefender: Detection: 44%Perma Link
Source: Josho.x86ReversingLabs: Detection: 69%
Machine Learning detection for sampleShow sources
Source: Josho.x86Joe Sandbox ML: detected
Source: global trafficTCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
Source: global trafficTCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
Source: global trafficTCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
Source: global trafficTCP traffic: 192.168.2.23:51412 -> 198.50.242.157:666
Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443
Source: unknownTCP traffic detected without corresponding DNS query: 198.50.242.157
Source: unknownTCP traffic detected without corresponding DNS query: 198.50.242.157
Source: unknownTCP traffic detected without corresponding DNS query: 198.50.242.157
Source: unknownTCP traffic detected without corresponding DNS query: 198.50.242.157
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 198.50.242.157
Source: unknownTCP traffic detected without corresponding DNS query: 198.50.242.157
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 198.50.242.157
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 198.50.242.157
Source: unknownTCP traffic detected without corresponding DNS query: 198.50.242.157
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 198.50.242.157
Source: unknownTCP traffic detected without corresponding DNS query: 198.50.242.157
Source: unknownTCP traffic detected without corresponding DNS query: 198.50.242.157
Source: unknownTCP traffic detected without corresponding DNS query: 198.50.242.157
Source: unknownTCP traffic detected without corresponding DNS query: 198.50.242.157
Source: unknownTCP traffic detected without corresponding DNS query: 198.50.242.157
Source: unknownTCP traffic detected without corresponding DNS query: 198.50.242.157
Source: unknownTCP traffic detected without corresponding DNS query: 198.50.242.157
Source: unknownTCP traffic detected without corresponding DNS query: 198.50.242.157
Source: unknownTCP traffic detected without corresponding DNS query: 198.50.242.157
Source: unknownTCP traffic detected without corresponding DNS query: 198.50.242.157
Source: unknownTCP traffic detected without corresponding DNS query: 198.50.242.157
Source: unknownTCP traffic detected without corresponding DNS query: 198.50.242.157
Source: unknownTCP traffic detected without corresponding DNS query: 198.50.242.157
Source: unknownTCP traffic detected without corresponding DNS query: 198.50.242.157
Source: unknownTCP traffic detected without corresponding DNS query: 198.50.242.157
Source: unknownTCP traffic detected without corresponding DNS query: 198.50.242.157
Source: unknownTCP traffic detected without corresponding DNS query: 198.50.242.157
Source: unknownTCP traffic detected without corresponding DNS query: 198.50.242.157
Source: unknownTCP traffic detected without corresponding DNS query: 198.50.242.157
Source: unknownTCP traffic detected without corresponding DNS query: 198.50.242.157
Source: unknownTCP traffic detected without corresponding DNS query: 198.50.242.157
Source: unknownTCP traffic detected without corresponding DNS query: 198.50.242.157
Source: unknownTCP traffic detected without corresponding DNS query: 198.50.242.157
Source: unknownTCP traffic detected without corresponding DNS query: 198.50.242.157
Source: unknownTCP traffic detected without corresponding DNS query: 198.50.242.157
Source: unknownTCP traffic detected without corresponding DNS query: 198.50.242.157
Source: unknownTCP traffic detected without corresponding DNS query: 198.50.242.157
Source: unknownTCP traffic detected without corresponding DNS query: 198.50.242.157
Source: unknownTCP traffic detected without corresponding DNS query: 198.50.242.157
Source: unknownTCP traffic detected without corresponding DNS query: 198.50.242.157
Source: unknownTCP traffic detected without corresponding DNS query: 198.50.242.157
Source: unknownTCP traffic detected without corresponding DNS query: 198.50.242.157
Source: unknownTCP traffic detected without corresponding DNS query: 198.50.242.157
Source: /tmp/Josho.x86 (PID: 5226)SIGKILL sent: pid: 936, result: successfulJump to behavior
Source: /tmp/Josho.x86 (PID: 5229)SIGKILL sent: pid: 936, result: successfulJump to behavior
Source: ELF static info symbol of initial sample.symtab present: no
Source: classification engineClassification label: mal60.linX86@0/0@0/0
Source: /tmp/Josho.x86 (PID: 5226)File opened: /proc/491/fdJump to behavior
Source: /tmp/Josho.x86 (PID: 5226)File opened: /proc/793/fdJump to behavior
Source: /tmp/Josho.x86 (PID: 5226)File opened: /proc/772/fdJump to behavior
Source: /tmp/Josho.x86 (PID: 5226)File opened: /proc/796/fdJump to behavior
Source: /tmp/Josho.x86 (PID: 5226)File opened: /proc/774/fdJump to behavior
Source: /tmp/Josho.x86 (PID: 5226)File opened: /proc/797/fdJump to behavior
Source: /tmp/Josho.x86 (PID: 5226)File opened: /proc/777/fdJump to behavior
Source: /tmp/Josho.x86 (PID: 5226)File opened: /proc/799/fdJump to behavior
Source: /tmp/Josho.x86 (PID: 5226)File opened: /proc/658/fdJump to behavior
Source: /tmp/Josho.x86 (PID: 5226)File opened: /proc/912/fdJump to behavior
Source: /tmp/Josho.x86 (PID: 5226)File opened: /proc/759/fdJump to behavior
Source: /tmp/Josho.x86 (PID: 5226)File opened: /proc/936/fdJump to behavior
Source: /tmp/Josho.x86 (PID: 5226)File opened: /proc/918/fdJump to behavior
Source: /tmp/Josho.x86 (PID: 5226)File opened: /proc/1/fdJump to behavior
Source: /tmp/Josho.x86 (PID: 5226)File opened: /proc/761/fdJump to behavior
Source: /tmp/Josho.x86 (PID: 5226)File opened: /proc/785/fdJump to behavior
Source: /tmp/Josho.x86 (PID: 5226)File opened: /proc/884/fdJump to behavior
Source: /tmp/Josho.x86 (PID: 5226)File opened: /proc/720/fdJump to behavior
Source: /tmp/Josho.x86 (PID: 5226)File opened: /proc/721/fdJump to behavior
Source: /tmp/Josho.x86 (PID: 5226)File opened: /proc/788/fdJump to behavior
Source: /tmp/Josho.x86 (PID: 5226)File opened: /proc/789/fdJump to behavior
Source: /tmp/Josho.x86 (PID: 5226)File opened: /proc/800/fdJump to behavior
Source: /tmp/Josho.x86 (PID: 5226)File opened: /proc/5226/exeJump to behavior
Source: /tmp/Josho.x86 (PID: 5226)File opened: /proc/801/fdJump to behavior
Source: /tmp/Josho.x86 (PID: 5226)File opened: /proc/847/fdJump to behavior
Source: /tmp/Josho.x86 (PID: 5226)File opened: /proc/904/fdJump to behavior
Source: /tmp/Josho.x86 (PID: 5229)File opened: /proc/491/fdJump to behavior
Source: /tmp/Josho.x86 (PID: 5229)File opened: /proc/793/fdJump to behavior
Source: /tmp/Josho.x86 (PID: 5229)File opened: /proc/772/fdJump to behavior
Source: /tmp/Josho.x86 (PID: 5229)File opened: /proc/796/fdJump to behavior
Source: /tmp/Josho.x86 (PID: 5229)File opened: /proc/774/fdJump to behavior
Source: /tmp/Josho.x86 (PID: 5229)File opened: /proc/797/fdJump to behavior
Source: /tmp/Josho.x86 (PID: 5229)File opened: /proc/777/fdJump to behavior
Source: /tmp/Josho.x86 (PID: 5229)File opened: /proc/799/fdJump to behavior
Source: /tmp/Josho.x86 (PID: 5229)File opened: /proc/658/fdJump to behavior
Source: /tmp/Josho.x86 (PID: 5229)File opened: /proc/912/fdJump to behavior
Source: /tmp/Josho.x86 (PID: 5229)File opened: /proc/759/fdJump to behavior
Source: /tmp/Josho.x86 (PID: 5229)File opened: /proc/936/fdJump to behavior
Source: /tmp/Josho.x86 (PID: 5229)File opened: /proc/918/fdJump to behavior
Source: /tmp/Josho.x86 (PID: 5229)File opened: /proc/1/fdJump to behavior
Source: /tmp/Josho.x86 (PID: 5229)File opened: /proc/761/fdJump to behavior
Source: /tmp/Josho.x86 (PID: 5229)File opened: /proc/785/fdJump to behavior
Source: /tmp/Josho.x86 (PID: 5229)File opened: /proc/884/fdJump to behavior
Source: /tmp/Josho.x86 (PID: 5229)File opened: /proc/720/fdJump to behavior
Source: /tmp/Josho.x86 (PID: 5229)File opened: /proc/721/fdJump to behavior
Source: /tmp/Josho.x86 (PID: 5229)File opened: /proc/788/fdJump to behavior
Source: /tmp/Josho.x86 (PID: 5229)File opened: /proc/789/fdJump to behavior
Source: /tmp/Josho.x86 (PID: 5229)File opened: /proc/800/fdJump to behavior
Source: /tmp/Josho.x86 (PID: 5229)File opened: /proc/801/fdJump to behavior
Source: /tmp/Josho.x86 (PID: 5229)File opened: /proc/847/fdJump to behavior
Source: /tmp/Josho.x86 (PID: 5229)File opened: /proc/5229/exeJump to behavior
Source: /tmp/Josho.x86 (PID: 5229)File opened: /proc/904/fdJump to behavior

Mitre Att&ck Matrix

Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid AccountsWindows Management InstrumentationPath InterceptionPath InterceptionDirect Volume AccessOS Credential Dumping1System Service DiscoveryRemote ServicesData from Local SystemExfiltration Over Other Network MediumEncrypted Channel1Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over BluetoothNon-Standard Port1Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated ExfiltrationApplication Layer Protocol1Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data

Malware Configuration

No configs have been found

Behavior Graph

Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 556517 Sample: Josho.x86 Startdate: 20/01/2022 Architecture: LINUX Score: 60 34 198.50.242.157, 51412, 51414, 51416 OVHFR Canada 2->34 36 109.202.202.202, 80 INIT7CH Switzerland 2->36 38 2 other IPs or domains 2->38 40 Antivirus / Scanner detection for submitted sample 2->40 42 Multi AV Scanner detection for submitted file 2->42 44 Machine Learning detection for sample 2->44 10 Josho.x86 2->10         started        signatures3 process4 process5 12 Josho.x86 10->12         started        14 Josho.x86 10->14         started        16 Josho.x86 10->16         started        process6 18 Josho.x86 12->18         started        20 Josho.x86 12->20         started        22 Josho.x86 14->22         started        24 Josho.x86 14->24         started        process7 26 Josho.x86 18->26         started        28 Josho.x86 18->28         started        30 Josho.x86 22->30         started        process8 32 Josho.x86 26->32         started       

Antivirus, Machine Learning and Genetic Malware Detection

Initial Sample

SourceDetectionScannerLabelLink
Josho.x8644%MetadefenderBrowse
Josho.x8670%ReversingLabsLinux.Trojan.Mirai
Josho.x86100%AviraLINUX/Mirai.ooygz
Josho.x86100%Joe Sandbox ML

Dropped Files

No Antivirus matches

Domains

No Antivirus matches

URLs

No Antivirus matches

Domains and IPs

Contacted Domains

No contacted domains info

Contacted IPs

  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs

Public

IPDomainCountryFlagASNASN NameMalicious
109.202.202.202
unknownSwitzerland
13030INIT7CHfalse
198.50.242.157
unknownCanada
16276OVHFRfalse
91.189.91.43
unknownUnited Kingdom
41231CANONICAL-ASGBfalse
91.189.91.42
unknownUnited Kingdom
41231CANONICAL-ASGBfalse


Runtime Messages

Command:/tmp/Josho.x86
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
DaddyL33T Infected Your Shit
Standard Error:

Joe Sandbox View / Context

IPs

MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
109.202.202.202sRZz4JQ66KGet hashmaliciousBrowse
    tYjozYxSZqGet hashmaliciousBrowse
      a-r.m-4.ISISGet hashmaliciousBrowse
        a-r.m-5.ISISGet hashmaliciousBrowse
          a-r.m-6.ISISGet hashmaliciousBrowse
            SecuriteInfo.com.ELF.Mirai.XS.15896.15279Get hashmaliciousBrowse
              a-r.m-7.ISISGet hashmaliciousBrowse
                i-5.8-6.ISISGet hashmaliciousBrowse
                  m-i.p-s.ISISGet hashmaliciousBrowse
                    m-p.s-l.ISISGet hashmaliciousBrowse
                      s-h.4-.ISISGet hashmaliciousBrowse
                        x-3.2-.ISISGet hashmaliciousBrowse
                          UnHAnaAW.arm5Get hashmaliciousBrowse
                            UnHAnaAW.arm6Get hashmaliciousBrowse
                              x-8.6-.ISISGet hashmaliciousBrowse
                                tokyo.armGet hashmaliciousBrowse
                                  tokyo.arm5Get hashmaliciousBrowse
                                    tokyo.arm6Get hashmaliciousBrowse
                                      tokyo.arm7Get hashmaliciousBrowse
                                        tokyo.m68kGet hashmaliciousBrowse
                                          91.189.91.43sRZz4JQ66KGet hashmaliciousBrowse
                                            tYjozYxSZqGet hashmaliciousBrowse
                                              a-r.m-4.ISISGet hashmaliciousBrowse
                                                a-r.m-5.ISISGet hashmaliciousBrowse
                                                  a-r.m-6.ISISGet hashmaliciousBrowse
                                                    SecuriteInfo.com.ELF.Mirai.XS.15896.15279Get hashmaliciousBrowse
                                                      a-r.m-7.ISISGet hashmaliciousBrowse
                                                        i-5.8-6.ISISGet hashmaliciousBrowse
                                                          m-i.p-s.ISISGet hashmaliciousBrowse
                                                            m-p.s-l.ISISGet hashmaliciousBrowse
                                                              s-h.4-.ISISGet hashmaliciousBrowse
                                                                x-3.2-.ISISGet hashmaliciousBrowse
                                                                  UnHAnaAW.arm5Get hashmaliciousBrowse
                                                                    UnHAnaAW.arm6Get hashmaliciousBrowse
                                                                      x-8.6-.ISISGet hashmaliciousBrowse
                                                                        tokyo.armGet hashmaliciousBrowse
                                                                          tokyo.arm5Get hashmaliciousBrowse
                                                                            tokyo.arm6Get hashmaliciousBrowse
                                                                              tokyo.arm7Get hashmaliciousBrowse
                                                                                tokyo.m68kGet hashmaliciousBrowse

                                                                                  Domains

                                                                                  No context

                                                                                  ASN

                                                                                  MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                                                                                  INIT7CHsRZz4JQ66KGet hashmaliciousBrowse
                                                                                  • 109.202.202.202
                                                                                  tYjozYxSZqGet hashmaliciousBrowse
                                                                                  • 109.202.202.202
                                                                                  a-r.m-4.ISISGet hashmaliciousBrowse
                                                                                  • 109.202.202.202
                                                                                  a-r.m-5.ISISGet hashmaliciousBrowse
                                                                                  • 109.202.202.202
                                                                                  a-r.m-6.ISISGet hashmaliciousBrowse
                                                                                  • 109.202.202.202
                                                                                  SecuriteInfo.com.ELF.Mirai.XS.15896.15279Get hashmaliciousBrowse
                                                                                  • 109.202.202.202
                                                                                  a-r.m-7.ISISGet hashmaliciousBrowse
                                                                                  • 109.202.202.202
                                                                                  i-5.8-6.ISISGet hashmaliciousBrowse
                                                                                  • 109.202.202.202
                                                                                  m-i.p-s.ISISGet hashmaliciousBrowse
                                                                                  • 109.202.202.202
                                                                                  m-p.s-l.ISISGet hashmaliciousBrowse
                                                                                  • 109.202.202.202
                                                                                  s-h.4-.ISISGet hashmaliciousBrowse
                                                                                  • 109.202.202.202
                                                                                  x-3.2-.ISISGet hashmaliciousBrowse
                                                                                  • 109.202.202.202
                                                                                  UnHAnaAW.arm5Get hashmaliciousBrowse
                                                                                  • 109.202.202.202
                                                                                  UnHAnaAW.arm6Get hashmaliciousBrowse
                                                                                  • 109.202.202.202
                                                                                  x-8.6-.ISISGet hashmaliciousBrowse
                                                                                  • 109.202.202.202
                                                                                  tokyo.armGet hashmaliciousBrowse
                                                                                  • 109.202.202.202
                                                                                  tokyo.arm5Get hashmaliciousBrowse
                                                                                  • 109.202.202.202
                                                                                  tokyo.arm6Get hashmaliciousBrowse
                                                                                  • 109.202.202.202
                                                                                  tokyo.arm7Get hashmaliciousBrowse
                                                                                  • 109.202.202.202
                                                                                  tokyo.m68kGet hashmaliciousBrowse
                                                                                  • 109.202.202.202
                                                                                  OVHFR2k7GDMVeXP.dllGet hashmaliciousBrowse
                                                                                  • 54.38.242.185
                                                                                  fcZINN0PI1.dllGet hashmaliciousBrowse
                                                                                  • 54.38.242.185
                                                                                  B0OiokCj3u.dllGet hashmaliciousBrowse
                                                                                  • 54.38.242.185
                                                                                  6LTeMOAy5Z.dllGet hashmaliciousBrowse
                                                                                  • 54.38.242.185
                                                                                  qyRCSMzFKy.dllGet hashmaliciousBrowse
                                                                                  • 54.38.242.185
                                                                                  NBC-INV-099834.exeGet hashmaliciousBrowse
                                                                                  • 37.187.180.144
                                                                                  V5dn32NKTC.exeGet hashmaliciousBrowse
                                                                                  • 51.254.27.112
                                                                                  uW6c5twHB3.dllGet hashmaliciousBrowse
                                                                                  • 54.38.242.185
                                                                                  NNjq08PWTp.dllGet hashmaliciousBrowse
                                                                                  • 54.38.242.185
                                                                                  75Up9knhHV.dllGet hashmaliciousBrowse
                                                                                  • 54.38.242.185
                                                                                  J0KMiDX4BF.dllGet hashmaliciousBrowse
                                                                                  • 54.38.242.185
                                                                                  DyN2QqaMfu.dllGet hashmaliciousBrowse
                                                                                  • 54.38.242.185
                                                                                  v0d4L8cRB4.dllGet hashmaliciousBrowse
                                                                                  • 54.38.242.185
                                                                                  mJEcAGljX5.dllGet hashmaliciousBrowse
                                                                                  • 54.38.242.185
                                                                                  QEdDci1dHJ.dllGet hashmaliciousBrowse
                                                                                  • 54.38.242.185
                                                                                  vHz2Or74EH.dllGet hashmaliciousBrowse
                                                                                  • 54.38.242.185
                                                                                  TCukZcOa.dllGet hashmaliciousBrowse
                                                                                  • 54.38.242.185
                                                                                  n1zBrIn67t.exeGet hashmaliciousBrowse
                                                                                  • 145.239.208.100
                                                                                  0E144C258913A35001FD23C3413005C90E7BC35BE3BAF.exeGet hashmaliciousBrowse
                                                                                  • 51.91.13.105
                                                                                  UnHAnaAW.x86Get hashmaliciousBrowse
                                                                                  • 51.79.183.222

                                                                                  JA3 Fingerprints

                                                                                  No context

                                                                                  Dropped Files

                                                                                  No context

                                                                                  Created / dropped Files

                                                                                  No created / dropped files found

                                                                                  Static File Info

                                                                                  General

                                                                                  File type:ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, stripped
                                                                                  Entropy (8bit):6.335327947468057
                                                                                  TrID:
                                                                                  • ELF Executable and Linkable format (Linux) (4029/14) 50.16%
                                                                                  • ELF Executable and Linkable format (generic) (4004/1) 49.84%
                                                                                  File name:Josho.x86
                                                                                  File size:41744
                                                                                  MD5:d3bcd7d304ca56b6f685073ae65fd399
                                                                                  SHA1:ce33c18115e73f32e83c693cf51b8b2aa201e886
                                                                                  SHA256:50f798eb3aadfd6966a479b74dff730bc03901ca78792f77e570ee5393f45c51
                                                                                  SHA512:9275e05e918712eb0b82b7776f61eb8bb32eb8fe316f85f2fe8082fd5fa36a4199b0e78358eb031fedea0354f6bc15dc809154e9632d983b1884a15b50fd1612
                                                                                  SSDEEP:768:Ms1yfBjf74x6DhdZMddQmJTy5GgOegYEu0ploF4M4Kj9nK:py5jf74x6DB8mmJTyXgY4ploFX4KjB
                                                                                  File Content Preview:.ELF....................d...4...........4. ...(.............................................. ... ..@...............Q.td............................U..S.......w....h........[]...$.............U......=@!...t..5....$ .....$ ......u........t....h............

                                                                                  Static ELF Info

                                                                                  ELF header

                                                                                  Class:ELF32
                                                                                  Data:2's complement, little endian
                                                                                  Version:1 (current)
                                                                                  Machine:Intel 80386
                                                                                  Version Number:0x1
                                                                                  Type:EXEC (Executable file)
                                                                                  OS/ABI:UNIX - System V
                                                                                  ABI Version:0
                                                                                  Entry Point Address:0x8048164
                                                                                  Flags:0x0
                                                                                  ELF Header Size:52
                                                                                  Program Header Offset:52
                                                                                  Program Header Size:32
                                                                                  Number of Program Headers:3
                                                                                  Section Header Offset:41344
                                                                                  Section Header Size:40
                                                                                  Number of Section Headers:10
                                                                                  Header String Table Index:9

                                                                                  Sections

                                                                                  NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                                                                  NULL0x00x00x00x00x0000
                                                                                  .initPROGBITS0x80480940x940x1c0x00x6AX001
                                                                                  .textPROGBITS0x80480b00xb00x90d60x00x6AX0016
                                                                                  .finiPROGBITS0x80511860x91860x170x00x6AX001
                                                                                  .rodataPROGBITS0x80511a00x91a00xd200x00x2A0032
                                                                                  .ctorsPROGBITS0x80520000xa0000x80x00x3WA004
                                                                                  .dtorsPROGBITS0x80520080xa0080x80x00x3WA004
                                                                                  .dataPROGBITS0x80520200xa0200x1200x00x3WA0032
                                                                                  .bssNOBITS0x80521400xa1400x5a00x00x3WA0032
                                                                                  .shstrtabSTRTAB0x00xa1400x3e0x00x0001

                                                                                  Program Segments

                                                                                  TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                                                  LOAD0x00x80480000x80480000x9ec00x9ec03.91330x5R E0x1000.init .text .fini .rodata
                                                                                  LOAD0xa0000x80520000x80520000x1400x6e02.58990x6RW 0x1000.ctors .dtors .data .bss
                                                                                  GNU_STACK0x00x00x00x00x00.00000x6RW 0x4

                                                                                  Network Behavior

                                                                                  Network Port Distribution

                                                                                  TCP Packets

                                                                                  TimestampSource PortDest PortSource IPDest IP
                                                                                  Jan 20, 2022 08:07:41.675822973 CET51412666192.168.2.23198.50.242.157
                                                                                  Jan 20, 2022 08:07:41.779963017 CET66651412198.50.242.157192.168.2.23
                                                                                  Jan 20, 2022 08:07:41.780375004 CET51412666192.168.2.23198.50.242.157
                                                                                  Jan 20, 2022 08:07:41.780596972 CET51412666192.168.2.23198.50.242.157
                                                                                  Jan 20, 2022 08:07:41.887068033 CET66651412198.50.242.157192.168.2.23
                                                                                  Jan 20, 2022 08:07:41.887223959 CET51412666192.168.2.23198.50.242.157
                                                                                  Jan 20, 2022 08:07:41.991704941 CET66651412198.50.242.157192.168.2.23
                                                                                  Jan 20, 2022 08:07:43.145689011 CET42836443192.168.2.2391.189.91.43
                                                                                  Jan 20, 2022 08:07:43.657704115 CET4251680192.168.2.23109.202.202.202
                                                                                  Jan 20, 2022 08:07:51.787544966 CET51412666192.168.2.23198.50.242.157
                                                                                  Jan 20, 2022 08:07:51.892164946 CET66651412198.50.242.157192.168.2.23
                                                                                  Jan 20, 2022 08:07:51.892191887 CET66651412198.50.242.157192.168.2.23
                                                                                  Jan 20, 2022 08:07:51.892621040 CET51412666192.168.2.23198.50.242.157
                                                                                  Jan 20, 2022 08:07:59.017446041 CET43928443192.168.2.2391.189.91.42
                                                                                  Jan 20, 2022 08:08:07.011147976 CET66651412198.50.242.157192.168.2.23
                                                                                  Jan 20, 2022 08:08:07.011360884 CET51412666192.168.2.23198.50.242.157
                                                                                  Jan 20, 2022 08:08:09.257164955 CET42836443192.168.2.2391.189.91.43
                                                                                  Jan 20, 2022 08:08:13.353055000 CET4251680192.168.2.23109.202.202.202
                                                                                  Jan 20, 2022 08:08:22.115899086 CET66651412198.50.242.157192.168.2.23
                                                                                  Jan 20, 2022 08:08:22.116080999 CET51412666192.168.2.23198.50.242.157
                                                                                  Jan 20, 2022 08:08:37.219902039 CET66651412198.50.242.157192.168.2.23
                                                                                  Jan 20, 2022 08:08:37.220077991 CET51412666192.168.2.23198.50.242.157
                                                                                  Jan 20, 2022 08:08:39.976471901 CET43928443192.168.2.2391.189.91.42
                                                                                  Jan 20, 2022 08:08:51.944278955 CET51412666192.168.2.23198.50.242.157
                                                                                  Jan 20, 2022 08:08:52.048358917 CET66651412198.50.242.157192.168.2.23
                                                                                  Jan 20, 2022 08:08:52.048568964 CET51412666192.168.2.23198.50.242.157
                                                                                  Jan 20, 2022 08:09:07.205286980 CET66651412198.50.242.157192.168.2.23
                                                                                  Jan 20, 2022 08:09:07.205463886 CET51412666192.168.2.23198.50.242.157
                                                                                  Jan 20, 2022 08:09:22.309322119 CET66651412198.50.242.157192.168.2.23
                                                                                  Jan 20, 2022 08:09:22.309453011 CET51412666192.168.2.23198.50.242.157
                                                                                  Jan 20, 2022 08:09:37.412936926 CET66651412198.50.242.157192.168.2.23
                                                                                  Jan 20, 2022 08:09:37.413119078 CET51412666192.168.2.23198.50.242.157
                                                                                  Jan 20, 2022 08:09:52.107552052 CET51412666192.168.2.23198.50.242.157
                                                                                  Jan 20, 2022 08:09:52.211673021 CET66651412198.50.242.157192.168.2.23
                                                                                  Jan 20, 2022 08:09:52.211889029 CET51412666192.168.2.23198.50.242.157
                                                                                  Jan 20, 2022 08:10:07.362843037 CET66651412198.50.242.157192.168.2.23
                                                                                  Jan 20, 2022 08:10:07.362996101 CET51412666192.168.2.23198.50.242.157
                                                                                  Jan 20, 2022 08:10:22.466775894 CET66651412198.50.242.157192.168.2.23
                                                                                  Jan 20, 2022 08:10:22.466929913 CET51412666192.168.2.23198.50.242.157
                                                                                  Jan 20, 2022 08:10:33.264053106 CET51414666192.168.2.23198.50.242.157
                                                                                  Jan 20, 2022 08:10:33.283261061 CET51416666192.168.2.23198.50.242.157
                                                                                  Jan 20, 2022 08:10:33.368388891 CET66651414198.50.242.157192.168.2.23
                                                                                  Jan 20, 2022 08:10:33.368653059 CET51414666192.168.2.23198.50.242.157
                                                                                  Jan 20, 2022 08:10:33.368788004 CET51414666192.168.2.23198.50.242.157
                                                                                  Jan 20, 2022 08:10:33.389607906 CET66651416198.50.242.157192.168.2.23
                                                                                  Jan 20, 2022 08:10:33.389834881 CET51416666192.168.2.23198.50.242.157
                                                                                  Jan 20, 2022 08:10:33.389883041 CET51416666192.168.2.23198.50.242.157
                                                                                  Jan 20, 2022 08:10:33.473062038 CET66651414198.50.242.157192.168.2.23
                                                                                  Jan 20, 2022 08:10:33.473299026 CET51414666192.168.2.23198.50.242.157
                                                                                  Jan 20, 2022 08:10:33.497775078 CET66651416198.50.242.157192.168.2.23
                                                                                  Jan 20, 2022 08:10:33.498054028 CET51416666192.168.2.23198.50.242.157
                                                                                  Jan 20, 2022 08:10:33.577613115 CET66651414198.50.242.157192.168.2.23
                                                                                  Jan 20, 2022 08:10:33.606034040 CET66651416198.50.242.157192.168.2.23
                                                                                  Jan 20, 2022 08:10:37.570797920 CET66651412198.50.242.157192.168.2.23
                                                                                  Jan 20, 2022 08:10:37.571027994 CET51412666192.168.2.23198.50.242.157
                                                                                  Jan 20, 2022 08:10:38.283601046 CET51418666192.168.2.23198.50.242.157
                                                                                  Jan 20, 2022 08:10:38.384314060 CET66651418198.50.242.157192.168.2.23
                                                                                  Jan 20, 2022 08:10:38.384529114 CET51418666192.168.2.23198.50.242.157
                                                                                  Jan 20, 2022 08:10:38.384680033 CET51418666192.168.2.23198.50.242.157
                                                                                  Jan 20, 2022 08:10:38.485346079 CET66651418198.50.242.157192.168.2.23
                                                                                  Jan 20, 2022 08:10:38.485580921 CET51418666192.168.2.23198.50.242.157
                                                                                  Jan 20, 2022 08:10:38.586090088 CET66651418198.50.242.157192.168.2.23
                                                                                  Jan 20, 2022 08:10:43.378797054 CET51414666192.168.2.23198.50.242.157
                                                                                  Jan 20, 2022 08:10:43.399951935 CET51416666192.168.2.23198.50.242.157
                                                                                  Jan 20, 2022 08:10:43.484353065 CET66651414198.50.242.157192.168.2.23
                                                                                  Jan 20, 2022 08:10:43.484376907 CET66651414198.50.242.157192.168.2.23
                                                                                  Jan 20, 2022 08:10:43.484528065 CET51414666192.168.2.23198.50.242.157
                                                                                  Jan 20, 2022 08:10:43.505764008 CET66651416198.50.242.157192.168.2.23
                                                                                  Jan 20, 2022 08:10:43.505789995 CET66651416198.50.242.157192.168.2.23
                                                                                  Jan 20, 2022 08:10:43.506056070 CET51416666192.168.2.23198.50.242.157
                                                                                  Jan 20, 2022 08:10:48.394866943 CET51418666192.168.2.23198.50.242.157
                                                                                  Jan 20, 2022 08:10:48.495402098 CET66651418198.50.242.157192.168.2.23
                                                                                  Jan 20, 2022 08:10:48.495426893 CET66651418198.50.242.157192.168.2.23
                                                                                  Jan 20, 2022 08:10:48.496222019 CET51418666192.168.2.23198.50.242.157
                                                                                  Jan 20, 2022 08:10:52.270315886 CET51412666192.168.2.23198.50.242.157
                                                                                  Jan 20, 2022 08:10:52.374490976 CET66651412198.50.242.157192.168.2.23
                                                                                  Jan 20, 2022 08:10:52.374644995 CET51412666192.168.2.23198.50.242.157
                                                                                  Jan 20, 2022 08:10:58.626935005 CET66651414198.50.242.157192.168.2.23
                                                                                  Jan 20, 2022 08:10:58.626970053 CET66651416198.50.242.157192.168.2.23
                                                                                  Jan 20, 2022 08:10:58.627173901 CET51414666192.168.2.23198.50.242.157
                                                                                  Jan 20, 2022 08:10:58.627413988 CET51416666192.168.2.23198.50.242.157
                                                                                  Jan 20, 2022 08:11:03.618947983 CET66651418198.50.242.157192.168.2.23
                                                                                  Jan 20, 2022 08:11:03.619106054 CET51418666192.168.2.23198.50.242.157
                                                                                  Jan 20, 2022 08:11:07.524807930 CET66651412198.50.242.157192.168.2.23
                                                                                  Jan 20, 2022 08:11:07.525100946 CET51412666192.168.2.23198.50.242.157

                                                                                  System Behavior

                                                                                  General

                                                                                  Start time:08:07:41
                                                                                  Start date:20/01/2022
                                                                                  Path:/tmp/Josho.x86
                                                                                  Arguments:/tmp/Josho.x86
                                                                                  File size:41744 bytes
                                                                                  MD5 hash:d3bcd7d304ca56b6f685073ae65fd399

                                                                                  General

                                                                                  Start time:08:07:41
                                                                                  Start date:20/01/2022
                                                                                  Path:/tmp/Josho.x86
                                                                                  Arguments:n/a
                                                                                  File size:41744 bytes
                                                                                  MD5 hash:d3bcd7d304ca56b6f685073ae65fd399

                                                                                  General

                                                                                  Start time:08:10:32
                                                                                  Start date:20/01/2022
                                                                                  Path:/tmp/Josho.x86
                                                                                  Arguments:n/a
                                                                                  File size:41744 bytes
                                                                                  MD5 hash:d3bcd7d304ca56b6f685073ae65fd399

                                                                                  General

                                                                                  Start time:08:10:32
                                                                                  Start date:20/01/2022
                                                                                  Path:/tmp/Josho.x86
                                                                                  Arguments:n/a
                                                                                  File size:41744 bytes
                                                                                  MD5 hash:d3bcd7d304ca56b6f685073ae65fd399

                                                                                  General

                                                                                  Start time:08:10:32
                                                                                  Start date:20/01/2022
                                                                                  Path:/tmp/Josho.x86
                                                                                  Arguments:n/a
                                                                                  File size:41744 bytes
                                                                                  MD5 hash:d3bcd7d304ca56b6f685073ae65fd399

                                                                                  General

                                                                                  Start time:08:10:37
                                                                                  Start date:20/01/2022
                                                                                  Path:/tmp/Josho.x86
                                                                                  Arguments:n/a
                                                                                  File size:41744 bytes
                                                                                  MD5 hash:d3bcd7d304ca56b6f685073ae65fd399

                                                                                  General

                                                                                  Start time:08:10:32
                                                                                  Start date:20/01/2022
                                                                                  Path:/tmp/Josho.x86
                                                                                  Arguments:n/a
                                                                                  File size:41744 bytes
                                                                                  MD5 hash:d3bcd7d304ca56b6f685073ae65fd399

                                                                                  General

                                                                                  Start time:08:07:41
                                                                                  Start date:20/01/2022
                                                                                  Path:/tmp/Josho.x86
                                                                                  Arguments:n/a
                                                                                  File size:41744 bytes
                                                                                  MD5 hash:d3bcd7d304ca56b6f685073ae65fd399

                                                                                  General

                                                                                  Start time:08:07:41
                                                                                  Start date:20/01/2022
                                                                                  Path:/tmp/Josho.x86
                                                                                  Arguments:n/a
                                                                                  File size:41744 bytes
                                                                                  MD5 hash:d3bcd7d304ca56b6f685073ae65fd399

                                                                                  General

                                                                                  Start time:08:07:41
                                                                                  Start date:20/01/2022
                                                                                  Path:/tmp/Josho.x86
                                                                                  Arguments:n/a
                                                                                  File size:41744 bytes
                                                                                  MD5 hash:d3bcd7d304ca56b6f685073ae65fd399

                                                                                  General

                                                                                  Start time:08:10:32
                                                                                  Start date:20/01/2022
                                                                                  Path:/tmp/Josho.x86
                                                                                  Arguments:n/a
                                                                                  File size:41744 bytes
                                                                                  MD5 hash:d3bcd7d304ca56b6f685073ae65fd399

                                                                                  General

                                                                                  Start time:08:07:41
                                                                                  Start date:20/01/2022
                                                                                  Path:/tmp/Josho.x86
                                                                                  Arguments:n/a
                                                                                  File size:41744 bytes
                                                                                  MD5 hash:d3bcd7d304ca56b6f685073ae65fd399