Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
6THNtWwZbK

Overview

General Information

Sample Name:6THNtWwZbK
Analysis ID:557153
MD5:838c3e33f65e84ac7f7011a9b98fb608
SHA1:73bf1e05439801a0dba57edbb464dbe80d014472
SHA256:8ca9e50e94cc9c96568ecf1f5f1a1a3d3d9382843f52d7dbca95dace8efe0e0c
Tags:32elfmiraisparc
Infos:

Detection

Score:52
Range:0 - 100
Whitelisted:false

Signatures

Multi AV Scanner detection for submitted file
Sample tries to kill multiple processes (SIGKILL)
Sample has stripped symbol table
Uses the "uname" system call to query kernel version information (possible evasion)
Enumerates processes within the "proc" file system
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Detected TCP or UDP traffic on non-standard ports
Executes the "rm" command used to delete files or directories
Sample listens on a socket
Sample tries to kill a process (SIGKILL)

Classification

Analysis Advice

All HTTP servers contacted by the sample do not answer. Likely the sample is an old dropper which does no longer work
Static ELF header machine description suggests that the sample might not execute correctly on this machine
Joe Sandbox Version:34.0.0 Boulder Opal
Analysis ID:557153
Start date:20.01.2022
Start time:19:36:57
Joe Sandbox Product:CloudBasic
Overall analysis duration:0h 5m 11s
Hypervisor based Inspection enabled:false
Report type:full
Sample file name:6THNtWwZbK
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Detection:MAL
Classification:mal52.spre.lin@0/0@0/0
Command:/tmp/6THNtWwZbK
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
DaddyL33T Infected Your Shit
Standard Error:
  • system is lnxubuntu20
  • 6THNtWwZbK (PID: 5214, Parent: 5106, MD5: 7dc1c0e23cd5e102bb12e5c29403410e) Arguments: /tmp/6THNtWwZbK
  • dash New Fork (PID: 5243, Parent: 4332)
  • rm (PID: 5243, Parent: 4332, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.3kX8YuCx8O /tmp/tmp.kPrHzHFpnR /tmp/tmp.Rta5ifU2ma
  • cleanup
No yara matches

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: 6THNtWwZbKVirustotal: Detection: 46%Perma Link
Source: 6THNtWwZbKReversingLabs: Detection: 67%
Source: global trafficTCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
Source: global trafficTCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
Source: global trafficTCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
Source: global trafficTCP traffic: 192.168.2.23:51412 -> 198.50.242.157:666
Source: /tmp/6THNtWwZbK (PID: 5216)Socket: 0.0.0.0::0Jump to behavior
Source: /tmp/6THNtWwZbK (PID: 5216)Socket: 0.0.0.0::23Jump to behavior
Source: /tmp/6THNtWwZbK (PID: 5216)Socket: 0.0.0.0::53413Jump to behavior
Source: /tmp/6THNtWwZbK (PID: 5216)Socket: 0.0.0.0::80Jump to behavior
Source: /tmp/6THNtWwZbK (PID: 5216)Socket: 0.0.0.0::52869Jump to behavior
Source: /tmp/6THNtWwZbK (PID: 5216)Socket: 0.0.0.0::37215Jump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)Socket: 0.0.0.0::0Jump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)Socket: 0.0.0.0::23Jump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)Socket: 0.0.0.0::53413Jump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)Socket: 0.0.0.0::80Jump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)Socket: 0.0.0.0::52869Jump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)Socket: 0.0.0.0::37215Jump to behavior
Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443
Source: unknownTCP traffic detected without corresponding DNS query: 198.50.242.157
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 198.50.242.157
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 198.50.242.157
Source: unknownTCP traffic detected without corresponding DNS query: 198.50.242.157
Source: unknownTCP traffic detected without corresponding DNS query: 198.50.242.157
Source: unknownTCP traffic detected without corresponding DNS query: 198.50.242.157
Source: unknownTCP traffic detected without corresponding DNS query: 198.50.242.157
Source: unknownTCP traffic detected without corresponding DNS query: 198.50.242.157
Source: unknownTCP traffic detected without corresponding DNS query: 198.50.242.157
Source: unknownTCP traffic detected without corresponding DNS query: 198.50.242.157
Source: unknownTCP traffic detected without corresponding DNS query: 198.50.242.157
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 198.50.242.157
Source: unknownTCP traffic detected without corresponding DNS query: 198.50.242.157
Source: unknownTCP traffic detected without corresponding DNS query: 198.50.242.157
Source: unknownTCP traffic detected without corresponding DNS query: 198.50.242.157
Source: unknownTCP traffic detected without corresponding DNS query: 198.50.242.157
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 198.50.242.157
Source: unknownTCP traffic detected without corresponding DNS query: 198.50.242.157
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 198.50.242.157
Source: unknownTCP traffic detected without corresponding DNS query: 198.50.242.157
Source: unknownTCP traffic detected without corresponding DNS query: 198.50.242.157
Source: unknownTCP traffic detected without corresponding DNS query: 198.50.242.157
Source: unknownTCP traffic detected without corresponding DNS query: 198.50.242.157
Source: unknownTCP traffic detected without corresponding DNS query: 198.50.242.157
Source: unknownTCP traffic detected without corresponding DNS query: 198.50.242.157
Source: unknownTCP traffic detected without corresponding DNS query: 198.50.242.157
Source: unknownTCP traffic detected without corresponding DNS query: 198.50.242.157
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 198.50.242.157
Source: unknownTCP traffic detected without corresponding DNS query: 198.50.242.157
Source: unknownTCP traffic detected without corresponding DNS query: 198.50.242.157
Source: unknownTCP traffic detected without corresponding DNS query: 198.50.242.157
Source: unknownTCP traffic detected without corresponding DNS query: 198.50.242.157
Source: unknownTCP traffic detected without corresponding DNS query: 198.50.242.157
Source: unknownTCP traffic detected without corresponding DNS query: 198.50.242.157
Source: unknownTCP traffic detected without corresponding DNS query: 198.50.242.157
Source: unknownTCP traffic detected without corresponding DNS query: 198.50.242.157
Source: unknownTCP traffic detected without corresponding DNS query: 198.50.242.157
Source: unknownTCP traffic detected without corresponding DNS query: 198.50.242.157
Source: unknownTCP traffic detected without corresponding DNS query: 198.50.242.157
Source: unknownTCP traffic detected without corresponding DNS query: 198.50.242.157
Source: unknownTCP traffic detected without corresponding DNS query: 198.50.242.157
Source: unknownTCP traffic detected without corresponding DNS query: 198.50.242.157
Source: unknownTCP traffic detected without corresponding DNS query: 198.50.242.157
Source: unknownTCP traffic detected without corresponding DNS query: 198.50.242.157

System Summary

barindex
Source: /tmp/6THNtWwZbK (PID: 5216)SIGKILL sent: pid: 936, result: successfulJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)SIGKILL sent: pid: 5232, result: successfulJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)SIGKILL sent: pid: 5235, result: successfulJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)SIGKILL sent: pid: 720, result: successfulJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)SIGKILL sent: pid: 759, result: successfulJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)SIGKILL sent: pid: 788, result: successfulJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)SIGKILL sent: pid: 800, result: successfulJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)SIGKILL sent: pid: 847, result: successfulJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)SIGKILL sent: pid: 884, result: successfulJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)SIGKILL sent: pid: 936, result: successfulJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)SIGKILL sent: pid: 1334, result: successfulJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)SIGKILL sent: pid: 1335, result: successfulJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)SIGKILL sent: pid: 1860, result: successfulJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)SIGKILL sent: pid: 1872, result: successfulJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)SIGKILL sent: pid: 2096, result: successfulJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)SIGKILL sent: pid: 2097, result: successfulJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)SIGKILL sent: pid: 2102, result: successfulJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)SIGKILL sent: pid: 2180, result: successfulJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)SIGKILL sent: pid: 2208, result: successfulJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)SIGKILL sent: pid: 2275, result: successfulJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)SIGKILL sent: pid: 2281, result: successfulJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)SIGKILL sent: pid: 2285, result: successfulJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)SIGKILL sent: pid: 2289, result: successfulJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)SIGKILL sent: pid: 2294, result: successfulJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)SIGKILL sent: pid: 4450, result: successfulJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)SIGKILL sent: pid: 5222, result: unknownJump to behavior
Source: ELF static info symbol of initial sample.symtab present: no
Source: /tmp/6THNtWwZbK (PID: 5216)SIGKILL sent: pid: 936, result: successfulJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)SIGKILL sent: pid: 5232, result: successfulJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)SIGKILL sent: pid: 5235, result: successfulJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)SIGKILL sent: pid: 720, result: successfulJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)SIGKILL sent: pid: 759, result: successfulJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)SIGKILL sent: pid: 788, result: successfulJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)SIGKILL sent: pid: 800, result: successfulJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)SIGKILL sent: pid: 847, result: successfulJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)SIGKILL sent: pid: 884, result: successfulJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)SIGKILL sent: pid: 936, result: successfulJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)SIGKILL sent: pid: 1334, result: successfulJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)SIGKILL sent: pid: 1335, result: successfulJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)SIGKILL sent: pid: 1860, result: successfulJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)SIGKILL sent: pid: 1872, result: successfulJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)SIGKILL sent: pid: 2096, result: successfulJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)SIGKILL sent: pid: 2097, result: successfulJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)SIGKILL sent: pid: 2102, result: successfulJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)SIGKILL sent: pid: 2180, result: successfulJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)SIGKILL sent: pid: 2208, result: successfulJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)SIGKILL sent: pid: 2275, result: successfulJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)SIGKILL sent: pid: 2281, result: successfulJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)SIGKILL sent: pid: 2285, result: successfulJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)SIGKILL sent: pid: 2289, result: successfulJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)SIGKILL sent: pid: 2294, result: successfulJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)SIGKILL sent: pid: 4450, result: successfulJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)SIGKILL sent: pid: 5222, result: unknownJump to behavior
Source: classification engineClassification label: mal52.spre.lin@0/0@0/0
Source: /tmp/6THNtWwZbK (PID: 5222)File opened: /proc/5140/exeJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)File opened: /proc/5261/exeJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)File opened: /proc/5262/exeJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)File opened: /proc/5263/exeJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)File opened: /proc/4450/fdJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)File opened: /proc/4450/fdJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)File opened: /proc/4450/exeJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)File opened: /proc/5144/exeJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)File opened: /proc/4332/fdJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)File opened: /proc/4332/fdJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)File opened: /proc/4332/exeJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)File opened: /proc/5026/fdJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)File opened: /proc/5026/fdJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)File opened: /proc/5026/exeJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)File opened: /proc/5026/fdJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)File opened: /proc/2033/fdJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)File opened: /proc/2033/fdJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)File opened: /proc/2033/exeJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)File opened: /proc/2033/fdJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)File opened: /proc/1582/fdJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)File opened: /proc/1582/fdJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)File opened: /proc/1582/exeJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)File opened: /proc/1582/fdJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)File opened: /proc/2275/fdJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)File opened: /proc/2275/fdJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)File opened: /proc/2275/exeJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)File opened: /proc/3088/exeJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)File opened: /proc/5260/exeJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)File opened: /proc/1612/fdJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)File opened: /proc/1612/fdJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)File opened: /proc/1612/exeJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)File opened: /proc/1612/fdJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)File opened: /proc/1579/fdJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)File opened: /proc/1579/fdJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)File opened: /proc/1579/exeJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)File opened: /proc/1579/fdJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)File opened: /proc/1699/fdJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)File opened: /proc/1699/fdJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)File opened: /proc/1699/exeJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)File opened: /proc/1699/fdJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)File opened: /proc/1335/fdJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)File opened: /proc/1335/fdJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)File opened: /proc/1335/exeJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)File opened: /proc/1335/fdJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)File opened: /proc/1698/fdJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)File opened: /proc/1698/fdJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)File opened: /proc/1698/exeJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)File opened: /proc/1698/fdJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)File opened: /proc/2028/fdJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)File opened: /proc/2028/fdJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)File opened: /proc/2028/exeJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)File opened: /proc/2028/fdJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)File opened: /proc/1334/fdJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)File opened: /proc/1334/fdJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)File opened: /proc/1334/exeJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)File opened: /proc/1334/fdJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)File opened: /proc/1576/fdJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)File opened: /proc/1576/fdJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)File opened: /proc/1576/exeJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)File opened: /proc/1576/fdJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)File opened: /proc/2302/fdJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)File opened: /proc/2302/fdJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)File opened: /proc/2302/exeJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)File opened: /proc/2302/fdJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)File opened: /proc/3236/fdJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)File opened: /proc/3236/fdJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)File opened: /proc/3236/exeJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)File opened: /proc/3236/fdJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)File opened: /proc/2025/fdJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)File opened: /proc/2025/fdJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)File opened: /proc/2025/exeJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)File opened: /proc/2025/fdJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)File opened: /proc/2146/fdJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)File opened: /proc/2146/fdJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)File opened: /proc/2146/exeJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)File opened: /proc/2146/fdJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)File opened: /proc/910/exeJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)File opened: /proc/5258/exeJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)File opened: /proc/5259/exeJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)File opened: /proc/912/fdJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)File opened: /proc/912/fdJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)File opened: /proc/912/exeJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)File opened: /proc/912/fdJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)File opened: /proc/759/fdJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)File opened: /proc/759/fdJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)File opened: /proc/759/exeJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)File opened: /proc/759/fdJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)File opened: /proc/517/exeJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)File opened: /proc/2307/fdJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)File opened: /proc/2307/fdJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)File opened: /proc/2307/exeJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)File opened: /proc/2307/fdJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)File opened: /proc/918/fdJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)File opened: /proc/918/fdJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)File opened: /proc/918/exeJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)File opened: /proc/918/fdJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)File opened: /proc/4460/exeJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)File opened: /proc/1594/fdJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)File opened: /proc/1594/fdJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)File opened: /proc/1594/exeJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)File opened: /proc/1594/fdJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)File opened: /proc/2285/fdJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)File opened: /proc/2285/fdJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)File opened: /proc/2285/exeJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)File opened: /proc/2281/fdJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)File opened: /proc/2281/fdJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5222)File opened: /proc/2281/exeJump to behavior
Source: /usr/bin/dash (PID: 5243)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.3kX8YuCx8O /tmp/tmp.kPrHzHFpnR /tmp/tmp.Rta5ifU2maJump to behavior
Source: /tmp/6THNtWwZbK (PID: 5214)Queries kernel information via 'uname': Jump to behavior
Source: 6THNtWwZbK, 5214.1.000000001146a5be.00000000a8edf8f2.rw-.sdmp, 6THNtWwZbK, 5216.1.000000001146a5be.00000000a8edf8f2.rw-.sdmp, 6THNtWwZbK, 5231.1.000000001146a5be.00000000a8edf8f2.rw-.sdmp, 6THNtWwZbK, 5232.1.000000001146a5be.00000000a8edf8f2.rw-.sdmp, 6THNtWwZbK, 5235.1.000000001146a5be.00000000a8edf8f2.rw-.sdmp, 6THNtWwZbK, 5239.1.000000001146a5be.00000000a8edf8f2.rw-.sdmp, 6THNtWwZbK, 5236.1.000000001146a5be.00000000a8edf8f2.rw-.sdmp, 6THNtWwZbK, 5217.1.000000001146a5be.00000000a8edf8f2.rw-.sdmp, 6THNtWwZbK, 5222.1.000000001146a5be.00000000a8edf8f2.rw-.sdmp, 6THNtWwZbK, 5224.1.000000001146a5be.00000000a8edf8f2.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/sparc
Source: 6THNtWwZbK, 5214.1.000000001146a5be.00000000a8edf8f2.rw-.sdmp, 6THNtWwZbK, 5216.1.000000001146a5be.00000000a8edf8f2.rw-.sdmp, 6THNtWwZbK, 5231.1.000000001146a5be.00000000a8edf8f2.rw-.sdmp, 6THNtWwZbK, 5232.1.000000001146a5be.00000000a8edf8f2.rw-.sdmp, 6THNtWwZbK, 5235.1.000000001146a5be.00000000a8edf8f2.rw-.sdmp, 6THNtWwZbK, 5239.1.000000001146a5be.00000000a8edf8f2.rw-.sdmp, 6THNtWwZbK, 5236.1.000000001146a5be.00000000a8edf8f2.rw-.sdmp, 6THNtWwZbK, 5217.1.000000001146a5be.00000000a8edf8f2.rw-.sdmp, 6THNtWwZbK, 5222.1.000000001146a5be.00000000a8edf8f2.rw-.sdmp, 6THNtWwZbK, 5224.1.000000001146a5be.00000000a8edf8f2.rw-.sdmpBinary or memory string: U!/etc/qemu-binfmt/sparc
Source: 6THNtWwZbK, 5222.1.000000001146a5be.00000000a8edf8f2.rw-.sdmpBinary or memory string: U1/usr/bin/vmtoolsdparc/10!/proc/1890/fd/48!/proc/1638/fd/5
Source: 6THNtWwZbK, 5222.1.000000001146a5be.00000000a8edf8f2.rw-.sdmpBinary or memory string: /usr/bin/vmtoolsd
Source: 6THNtWwZbK, 5222.1.00000000a8edf8f2.00000000336a54b0.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/sparc/usr/libexec/evolution-addressbook-factorye4-notifyd-agent-1
Source: 6THNtWwZbK, 5214.1.00000000cc8b9fad.000000006b184953.rw-.sdmp, 6THNtWwZbK, 5216.1.00000000cc8b9fad.000000006b184953.rw-.sdmp, 6THNtWwZbK, 5231.1.00000000cc8b9fad.000000006b184953.rw-.sdmp, 6THNtWwZbK, 5232.1.00000000cc8b9fad.000000006b184953.rw-.sdmp, 6THNtWwZbK, 5235.1.00000000cc8b9fad.000000006b184953.rw-.sdmp, 6THNtWwZbK, 5239.1.00000000cc8b9fad.000000006b184953.rw-.sdmp, 6THNtWwZbK, 5236.1.00000000cc8b9fad.000000006b184953.rw-.sdmp, 6THNtWwZbK, 5217.1.00000000cc8b9fad.000000006b184953.rw-.sdmp, 6THNtWwZbK, 5222.1.00000000cc8b9fad.000000006b184953.rw-.sdmp, 6THNtWwZbK, 5224.1.00000000cc8b9fad.000000006b184953.rw-.sdmpBinary or memory string: Mx86_64/usr/bin/qemu-sparc/tmp/6THNtWwZbKSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/6THNtWwZbK
Source: 6THNtWwZbK, 5214.1.00000000cc8b9fad.000000006b184953.rw-.sdmp, 6THNtWwZbK, 5216.1.00000000cc8b9fad.000000006b184953.rw-.sdmp, 6THNtWwZbK, 5231.1.00000000cc8b9fad.000000006b184953.rw-.sdmp, 6THNtWwZbK, 5232.1.00000000cc8b9fad.000000006b184953.rw-.sdmp, 6THNtWwZbK, 5235.1.00000000cc8b9fad.000000006b184953.rw-.sdmp, 6THNtWwZbK, 5239.1.00000000cc8b9fad.000000006b184953.rw-.sdmp, 6THNtWwZbK, 5236.1.00000000cc8b9fad.000000006b184953.rw-.sdmp, 6THNtWwZbK, 5217.1.00000000cc8b9fad.000000006b184953.rw-.sdmp, 6THNtWwZbK, 5222.1.00000000cc8b9fad.000000006b184953.rw-.sdmp, 6THNtWwZbK, 5224.1.00000000cc8b9fad.000000006b184953.rw-.sdmpBinary or memory string: /usr/bin/qemu-sparc
Source: 6THNtWwZbK, 5222.1.00000000a8edf8f2.00000000336a54b0.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/sparc/usr/libexec/evolution-addressbook-factory
Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid AccountsWindows Management InstrumentationPath InterceptionPath Interception1
File Deletion
1
OS Credential Dumping
11
Security Software Discovery
Remote ServicesData from Local SystemExfiltration Over Other Network Medium1
Encrypted Channel
Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over Bluetooth1
Non-Standard Port
Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated Exfiltration1
Application Layer Protocol
Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 557153 Sample: 6THNtWwZbK Startdate: 20/01/2022 Architecture: LINUX Score: 52 36 198.50.242.157, 666 OVHFR Canada 2->36 38 109.202.202.202, 80 INIT7CH Switzerland 2->38 40 2 other IPs or domains 2->40 42 Multi AV Scanner detection for submitted file 2->42 10 6THNtWwZbK 2->10         started        12 dash rm 2->12         started        signatures3 process4 process5 14 6THNtWwZbK 10->14         started        17 6THNtWwZbK 10->17         started        19 6THNtWwZbK 10->19         started        signatures6 46 Sample tries to kill multiple processes (SIGKILL) 14->46 21 6THNtWwZbK 14->21         started        23 6THNtWwZbK 14->23         started        25 6THNtWwZbK 17->25         started        28 6THNtWwZbK 17->28         started        process7 signatures8 30 6THNtWwZbK 21->30         started        32 6THNtWwZbK 21->32         started        44 Sample tries to kill multiple processes (SIGKILL) 25->44 process9 process10 34 6THNtWwZbK 30->34         started       

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
6THNtWwZbK47%VirustotalBrowse
6THNtWwZbK68%ReversingLabsLinux.Trojan.Mirai
No Antivirus matches
No Antivirus matches
No Antivirus matches
No contacted domains info
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs
IPDomainCountryFlagASNASN NameMalicious
109.202.202.202
unknownSwitzerland
13030INIT7CHfalse
198.50.242.157
unknownCanada
16276OVHFRfalse
91.189.91.43
unknownUnited Kingdom
41231CANONICAL-ASGBfalse
91.189.91.42
unknownUnited Kingdom
41231CANONICAL-ASGBfalse
MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
109.202.202.20238i7ZKmpjCGet hashmaliciousBrowse
    UxvR1vQLsPGet hashmaliciousBrowse
      3Cutr47cRIGet hashmaliciousBrowse
        7MNENFcDvkGet hashmaliciousBrowse
          aax17rrOufGet hashmaliciousBrowse
            7Uin93XzdRGet hashmaliciousBrowse
              dTfgrSDS2dGet hashmaliciousBrowse
                2T6lUA75BGGet hashmaliciousBrowse
                  4dC79wfUhfGet hashmaliciousBrowse
                    hr7EeRmbB4Get hashmaliciousBrowse
                      QuHG7Oh8M3Get hashmaliciousBrowse
                        wmqwOUcdTzGet hashmaliciousBrowse
                          5BQxcXhYVeGet hashmaliciousBrowse
                            jkur89wyz7Get hashmaliciousBrowse
                              psEBoALR2vGet hashmaliciousBrowse
                                D7t5JlLBNAGet hashmaliciousBrowse
                                  f3imxIObeFGet hashmaliciousBrowse
                                    server.outGet hashmaliciousBrowse
                                      gang123isgodloluaintgettingthesebinslikedammwtf.armGet hashmaliciousBrowse
                                        armv4lGet hashmaliciousBrowse
                                          198.50.242.157r7jYRiiUEnGet hashmaliciousBrowse
                                            Josho.x86Get hashmaliciousBrowse
                                              91.189.91.4338i7ZKmpjCGet hashmaliciousBrowse
                                                UxvR1vQLsPGet hashmaliciousBrowse
                                                  3Cutr47cRIGet hashmaliciousBrowse
                                                    7MNENFcDvkGet hashmaliciousBrowse
                                                      aax17rrOufGet hashmaliciousBrowse
                                                        7Uin93XzdRGet hashmaliciousBrowse
                                                          dTfgrSDS2dGet hashmaliciousBrowse
                                                            2T6lUA75BGGet hashmaliciousBrowse
                                                              4dC79wfUhfGet hashmaliciousBrowse
                                                                hr7EeRmbB4Get hashmaliciousBrowse
                                                                  QuHG7Oh8M3Get hashmaliciousBrowse
                                                                    wmqwOUcdTzGet hashmaliciousBrowse
                                                                      5BQxcXhYVeGet hashmaliciousBrowse
                                                                        jkur89wyz7Get hashmaliciousBrowse
                                                                          psEBoALR2vGet hashmaliciousBrowse
                                                                            D7t5JlLBNAGet hashmaliciousBrowse
                                                                              f3imxIObeFGet hashmaliciousBrowse
                                                                                server.outGet hashmaliciousBrowse
                                                                                  gang123isgodloluaintgettingthesebinslikedammwtf.armGet hashmaliciousBrowse
                                                                                    armv4lGet hashmaliciousBrowse
                                                                                      91.189.91.4238i7ZKmpjCGet hashmaliciousBrowse
                                                                                        UxvR1vQLsPGet hashmaliciousBrowse
                                                                                          3Cutr47cRIGet hashmaliciousBrowse
                                                                                            7MNENFcDvkGet hashmaliciousBrowse
                                                                                              aax17rrOufGet hashmaliciousBrowse
                                                                                                7Uin93XzdRGet hashmaliciousBrowse
                                                                                                  dTfgrSDS2dGet hashmaliciousBrowse
                                                                                                    2T6lUA75BGGet hashmaliciousBrowse
                                                                                                      4dC79wfUhfGet hashmaliciousBrowse
                                                                                                        hr7EeRmbB4Get hashmaliciousBrowse
                                                                                                          QuHG7Oh8M3Get hashmaliciousBrowse
                                                                                                            wmqwOUcdTzGet hashmaliciousBrowse
                                                                                                              5BQxcXhYVeGet hashmaliciousBrowse
                                                                                                                jkur89wyz7Get hashmaliciousBrowse
                                                                                                                  psEBoALR2vGet hashmaliciousBrowse
                                                                                                                    D7t5JlLBNAGet hashmaliciousBrowse
                                                                                                                      f3imxIObeFGet hashmaliciousBrowse
                                                                                                                        server.outGet hashmaliciousBrowse
                                                                                                                          gang123isgodloluaintgettingthesebinslikedammwtf.armGet hashmaliciousBrowse
                                                                                                                            armv4lGet hashmaliciousBrowse
                                                                                                                              No context
                                                                                                                              MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                                                                                                                              INIT7CH38i7ZKmpjCGet hashmaliciousBrowse
                                                                                                                              • 109.202.202.202
                                                                                                                              UxvR1vQLsPGet hashmaliciousBrowse
                                                                                                                              • 109.202.202.202
                                                                                                                              3Cutr47cRIGet hashmaliciousBrowse
                                                                                                                              • 109.202.202.202
                                                                                                                              7MNENFcDvkGet hashmaliciousBrowse
                                                                                                                              • 109.202.202.202
                                                                                                                              aax17rrOufGet hashmaliciousBrowse
                                                                                                                              • 109.202.202.202
                                                                                                                              7Uin93XzdRGet hashmaliciousBrowse
                                                                                                                              • 109.202.202.202
                                                                                                                              dTfgrSDS2dGet hashmaliciousBrowse
                                                                                                                              • 109.202.202.202
                                                                                                                              2T6lUA75BGGet hashmaliciousBrowse
                                                                                                                              • 109.202.202.202
                                                                                                                              4dC79wfUhfGet hashmaliciousBrowse
                                                                                                                              • 109.202.202.202
                                                                                                                              hr7EeRmbB4Get hashmaliciousBrowse
                                                                                                                              • 109.202.202.202
                                                                                                                              QuHG7Oh8M3Get hashmaliciousBrowse
                                                                                                                              • 109.202.202.202
                                                                                                                              wmqwOUcdTzGet hashmaliciousBrowse
                                                                                                                              • 109.202.202.202
                                                                                                                              5BQxcXhYVeGet hashmaliciousBrowse
                                                                                                                              • 109.202.202.202
                                                                                                                              jkur89wyz7Get hashmaliciousBrowse
                                                                                                                              • 109.202.202.202
                                                                                                                              psEBoALR2vGet hashmaliciousBrowse
                                                                                                                              • 109.202.202.202
                                                                                                                              D7t5JlLBNAGet hashmaliciousBrowse
                                                                                                                              • 109.202.202.202
                                                                                                                              f3imxIObeFGet hashmaliciousBrowse
                                                                                                                              • 109.202.202.202
                                                                                                                              server.outGet hashmaliciousBrowse
                                                                                                                              • 109.202.202.202
                                                                                                                              gang123isgodloluaintgettingthesebinslikedammwtf.armGet hashmaliciousBrowse
                                                                                                                              • 109.202.202.202
                                                                                                                              armv4lGet hashmaliciousBrowse
                                                                                                                              • 109.202.202.202
                                                                                                                              OVHFR74654_0572.xlsmGet hashmaliciousBrowse
                                                                                                                              • 54.38.242.185
                                                                                                                              Eo4fUr4Nrw.xlsGet hashmaliciousBrowse
                                                                                                                              • 158.69.222.101
                                                                                                                              GNVAV62Lvr.xlsGet hashmaliciousBrowse
                                                                                                                              • 158.69.222.101
                                                                                                                              CshcvHW436.dllGet hashmaliciousBrowse
                                                                                                                              • 54.38.242.185
                                                                                                                              WWAaHV4zF5.dllGet hashmaliciousBrowse
                                                                                                                              • 54.38.242.185
                                                                                                                              5F4cRaOS5o.dllGet hashmaliciousBrowse
                                                                                                                              • 54.38.242.185
                                                                                                                              a3p0uD3moG.dllGet hashmaliciousBrowse
                                                                                                                              • 54.38.242.185
                                                                                                                              nSTFP6u6vB.xlsGet hashmaliciousBrowse
                                                                                                                              • 158.69.222.101
                                                                                                                              WBeOATCNzu.xlsGet hashmaliciousBrowse
                                                                                                                              • 158.69.222.101
                                                                                                                              ViDYbamMJs.xlsGet hashmaliciousBrowse
                                                                                                                              • 158.69.222.101
                                                                                                                              FY9TEhMUn0.xlsGet hashmaliciousBrowse
                                                                                                                              • 158.69.222.101
                                                                                                                              YSJ9sxniwY.xlsGet hashmaliciousBrowse
                                                                                                                              • 158.69.222.101
                                                                                                                              kQd3DizYb2.xlsGet hashmaliciousBrowse
                                                                                                                              • 158.69.222.101
                                                                                                                              qNOBm6dUwN.xlsGet hashmaliciousBrowse
                                                                                                                              • 158.69.222.101
                                                                                                                              097357825070328333.xlsGet hashmaliciousBrowse
                                                                                                                              • 158.69.222.101
                                                                                                                              a1D4Hz4M83.xlsGet hashmaliciousBrowse
                                                                                                                              • 158.69.222.101
                                                                                                                              046013654279461.xlsGet hashmaliciousBrowse
                                                                                                                              • 158.69.222.101
                                                                                                                              stbuiv_9200401.xlsmGet hashmaliciousBrowse
                                                                                                                              • 54.38.242.185
                                                                                                                              armv4lGet hashmaliciousBrowse
                                                                                                                              • 51.81.8.35
                                                                                                                              SdrurOt1Ys.xlsGet hashmaliciousBrowse
                                                                                                                              • 158.69.222.101
                                                                                                                              No context
                                                                                                                              No context
                                                                                                                              No created / dropped files found
                                                                                                                              File type:ELF 32-bit MSB executable, SPARC, version 1 (SYSV), statically linked, stripped
                                                                                                                              Entropy (8bit):5.916050120082106
                                                                                                                              TrID:
                                                                                                                              • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                                                                                                                              File name:6THNtWwZbK
                                                                                                                              File size:51480
                                                                                                                              MD5:838c3e33f65e84ac7f7011a9b98fb608
                                                                                                                              SHA1:73bf1e05439801a0dba57edbb464dbe80d014472
                                                                                                                              SHA256:8ca9e50e94cc9c96568ecf1f5f1a1a3d3d9382843f52d7dbca95dace8efe0e0c
                                                                                                                              SHA512:688242caee15726d912256d8e0266609e785b74e1811c688956252ec340b2774976064cfd032fb4f9cbe55ba7c07c6cca85466a582deef6c2e9dccc85df0476e
                                                                                                                              SSDEEP:768:J3B2oNN/Rq92B90XPBlNnXWPArOXO+p+AvpBI:Jx2UN/RS2B90XPBXX8L0EK
                                                                                                                              File Content Preview:.ELF...........................4.........4. ...(.......................................................,...d........dt.Q................................@..(....@.,.................#.....cH..`.....!.....!4..@.....".........`......$!4..!4..@...........`....

                                                                                                                              ELF header

                                                                                                                              Class:ELF32
                                                                                                                              Data:2's complement, big endian
                                                                                                                              Version:1 (current)
                                                                                                                              Machine:Sparc
                                                                                                                              Version Number:0x1
                                                                                                                              Type:EXEC (Executable file)
                                                                                                                              OS/ABI:UNIX - System V
                                                                                                                              ABI Version:0
                                                                                                                              Entry Point Address:0x101a4
                                                                                                                              Flags:0x0
                                                                                                                              ELF Header Size:52
                                                                                                                              Program Header Offset:52
                                                                                                                              Program Header Size:32
                                                                                                                              Number of Program Headers:3
                                                                                                                              Section Header Offset:51080
                                                                                                                              Section Header Size:40
                                                                                                                              Number of Section Headers:10
                                                                                                                              Header String Table Index:9
                                                                                                                              NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                                                                                                              NULL0x00x00x00x00x0000
                                                                                                                              .initPROGBITS0x100940x940x1c0x00x6AX004
                                                                                                                              .textPROGBITS0x100b00xb00xb3140x00x6AX004
                                                                                                                              .finiPROGBITS0x1b3c40xb3c40x140x00x6AX004
                                                                                                                              .rodataPROGBITS0x1b3d80xb3d80x11400x00x2A008
                                                                                                                              .ctorsPROGBITS0x2c51c0xc51c0x80x00x3WA004
                                                                                                                              .dtorsPROGBITS0x2c5240xc5240x80x00x3WA004
                                                                                                                              .dataPROGBITS0x2c5300xc5300x2180x00x3WA008
                                                                                                                              .bssNOBITS0x2c7480xc7480x2380x00x3WA004
                                                                                                                              .shstrtabSTRTAB0x00xc7480x3e0x00x0001
                                                                                                                              TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                                                                                              LOAD0x00x100000x100000xc5180xc5183.39550x5R E0x10000.init .text .fini .rodata
                                                                                                                              LOAD0xc51c0x2c51c0x2c51c0x22c0x4641.58440x6RW 0x10000.ctors .dtors .data .bss
                                                                                                                              GNU_STACK0x00x00x00x00x00.00000x6RW 0x4
                                                                                                                              TimestampSource PortDest PortSource IPDest IP
                                                                                                                              Jan 20, 2022 19:37:41.073864937 CET51412666192.168.2.23198.50.242.157
                                                                                                                              Jan 20, 2022 19:37:41.883584976 CET42836443192.168.2.2391.189.91.43
                                                                                                                              Jan 20, 2022 19:37:42.075572014 CET51412666192.168.2.23198.50.242.157
                                                                                                                              Jan 20, 2022 19:37:42.395586967 CET4251680192.168.2.23109.202.202.202
                                                                                                                              Jan 20, 2022 19:37:44.091644049 CET51412666192.168.2.23198.50.242.157
                                                                                                                              Jan 20, 2022 19:37:48.283674955 CET51412666192.168.2.23198.50.242.157
                                                                                                                              Jan 20, 2022 19:37:49.454397917 CET51414666192.168.2.23198.50.242.157
                                                                                                                              Jan 20, 2022 19:37:49.594444036 CET51416666192.168.2.23198.50.242.157
                                                                                                                              Jan 20, 2022 19:37:50.459709883 CET51414666192.168.2.23198.50.242.157
                                                                                                                              Jan 20, 2022 19:37:50.619699955 CET51416666192.168.2.23198.50.242.157
                                                                                                                              Jan 20, 2022 19:37:51.084830046 CET51418666192.168.2.23198.50.242.157
                                                                                                                              Jan 20, 2022 19:37:52.091460943 CET51418666192.168.2.23198.50.242.157
                                                                                                                              Jan 20, 2022 19:37:54.107598066 CET51418666192.168.2.23198.50.242.157
                                                                                                                              Jan 20, 2022 19:37:56.475481987 CET43928443192.168.2.2391.189.91.42
                                                                                                                              Jan 20, 2022 19:37:58.267410994 CET51418666192.168.2.23198.50.242.157
                                                                                                                              Jan 20, 2022 19:38:01.095136881 CET51420666192.168.2.23198.50.242.157
                                                                                                                              Jan 20, 2022 19:38:02.107598066 CET51420666192.168.2.23198.50.242.157
                                                                                                                              Jan 20, 2022 19:38:04.123567104 CET51420666192.168.2.23198.50.242.157
                                                                                                                              Jan 20, 2022 19:38:08.251380920 CET51420666192.168.2.23198.50.242.157
                                                                                                                              Jan 20, 2022 19:38:08.763267994 CET42836443192.168.2.2391.189.91.43
                                                                                                                              Jan 20, 2022 19:38:11.105493069 CET51422666192.168.2.23198.50.242.157
                                                                                                                              Jan 20, 2022 19:38:12.123328924 CET51422666192.168.2.23198.50.242.157
                                                                                                                              Jan 20, 2022 19:38:12.859277010 CET4251680192.168.2.23109.202.202.202
                                                                                                                              Jan 20, 2022 19:38:14.139270067 CET51422666192.168.2.23198.50.242.157
                                                                                                                              Jan 20, 2022 19:38:18.235215902 CET51422666192.168.2.23198.50.242.157
                                                                                                                              Jan 20, 2022 19:38:21.115650892 CET51424666192.168.2.23198.50.242.157
                                                                                                                              Jan 20, 2022 19:38:22.139239073 CET51424666192.168.2.23198.50.242.157
                                                                                                                              Jan 20, 2022 19:38:24.155272007 CET51424666192.168.2.23198.50.242.157
                                                                                                                              Jan 20, 2022 19:38:28.219105005 CET51424666192.168.2.23198.50.242.157
                                                                                                                              Jan 20, 2022 19:38:31.125818014 CET51426666192.168.2.23198.50.242.157
                                                                                                                              Jan 20, 2022 19:38:32.155085087 CET51426666192.168.2.23198.50.242.157
                                                                                                                              Jan 20, 2022 19:38:34.170983076 CET51426666192.168.2.23198.50.242.157
                                                                                                                              Jan 20, 2022 19:38:37.434942007 CET43928443192.168.2.2391.189.91.42
                                                                                                                              Jan 20, 2022 19:38:38.203005075 CET51426666192.168.2.23198.50.242.157
                                                                                                                              Jan 20, 2022 19:38:41.135999918 CET51428666192.168.2.23198.50.242.157
                                                                                                                              Jan 20, 2022 19:38:42.138847113 CET51428666192.168.2.23198.50.242.157
                                                                                                                              Jan 20, 2022 19:38:44.154831886 CET51428666192.168.2.23198.50.242.157
                                                                                                                              Jan 20, 2022 19:38:48.186839104 CET51428666192.168.2.23198.50.242.157
                                                                                                                              Jan 20, 2022 19:38:51.142990112 CET51430666192.168.2.23198.50.242.157
                                                                                                                              Jan 20, 2022 19:38:52.154802084 CET51430666192.168.2.23198.50.242.157
                                                                                                                              Jan 20, 2022 19:38:54.170893908 CET51430666192.168.2.23198.50.242.157
                                                                                                                              Jan 20, 2022 19:38:58.426635981 CET51430666192.168.2.23198.50.242.157
                                                                                                                              Jan 20, 2022 19:39:01.153127909 CET51432666192.168.2.23198.50.242.157
                                                                                                                              Jan 20, 2022 19:39:02.170861006 CET51432666192.168.2.23198.50.242.157
                                                                                                                              Jan 20, 2022 19:39:04.186641932 CET51432666192.168.2.23198.50.242.157
                                                                                                                              Jan 20, 2022 19:39:08.410562992 CET51432666192.168.2.23198.50.242.157
                                                                                                                              Jan 20, 2022 19:39:11.163428068 CET51434666192.168.2.23198.50.242.157
                                                                                                                              Jan 20, 2022 19:39:12.186501980 CET51434666192.168.2.23198.50.242.157
                                                                                                                              Jan 20, 2022 19:39:14.202565908 CET51434666192.168.2.23198.50.242.157
                                                                                                                              Jan 20, 2022 19:39:18.394392014 CET51434666192.168.2.23198.50.242.157
                                                                                                                              Jan 20, 2022 19:39:21.173531055 CET51436666192.168.2.23198.50.242.157
                                                                                                                              Jan 20, 2022 19:39:22.202373028 CET51436666192.168.2.23198.50.242.157
                                                                                                                              Jan 20, 2022 19:39:24.218532085 CET51436666192.168.2.23198.50.242.157
                                                                                                                              Jan 20, 2022 19:39:28.378552914 CET51436666192.168.2.23198.50.242.157
                                                                                                                              Jan 20, 2022 19:39:31.178744078 CET51438666192.168.2.23198.50.242.157
                                                                                                                              Jan 20, 2022 19:39:32.186338902 CET51438666192.168.2.23198.50.242.157
                                                                                                                              Jan 20, 2022 19:39:34.202337027 CET51438666192.168.2.23198.50.242.157
                                                                                                                              Jan 20, 2022 19:39:38.362210035 CET51438666192.168.2.23198.50.242.157
                                                                                                                              Jan 20, 2022 19:39:41.188757896 CET51440666192.168.2.23198.50.242.157
                                                                                                                              Jan 20, 2022 19:39:42.202169895 CET51440666192.168.2.23198.50.242.157
                                                                                                                              Jan 20, 2022 19:39:44.218425989 CET51440666192.168.2.23198.50.242.157
                                                                                                                              Jan 20, 2022 19:39:48.346183062 CET51440666192.168.2.23198.50.242.157
                                                                                                                              Jan 20, 2022 19:39:51.198965073 CET51442666192.168.2.23198.50.242.157

                                                                                                                              System Behavior

                                                                                                                              Start time:19:37:40
                                                                                                                              Start date:20/01/2022
                                                                                                                              Path:/tmp/6THNtWwZbK
                                                                                                                              Arguments:/tmp/6THNtWwZbK
                                                                                                                              File size:4379400 bytes
                                                                                                                              MD5 hash:7dc1c0e23cd5e102bb12e5c29403410e

                                                                                                                              Start time:19:37:40
                                                                                                                              Start date:20/01/2022
                                                                                                                              Path:/tmp/6THNtWwZbK
                                                                                                                              Arguments:n/a
                                                                                                                              File size:4379400 bytes
                                                                                                                              MD5 hash:7dc1c0e23cd5e102bb12e5c29403410e

                                                                                                                              Start time:19:37:48
                                                                                                                              Start date:20/01/2022
                                                                                                                              Path:/tmp/6THNtWwZbK
                                                                                                                              Arguments:n/a
                                                                                                                              File size:4379400 bytes
                                                                                                                              MD5 hash:7dc1c0e23cd5e102bb12e5c29403410e

                                                                                                                              Start time:19:37:48
                                                                                                                              Start date:20/01/2022
                                                                                                                              Path:/tmp/6THNtWwZbK
                                                                                                                              Arguments:n/a
                                                                                                                              File size:4379400 bytes
                                                                                                                              MD5 hash:7dc1c0e23cd5e102bb12e5c29403410e

                                                                                                                              Start time:19:37:48
                                                                                                                              Start date:20/01/2022
                                                                                                                              Path:/tmp/6THNtWwZbK
                                                                                                                              Arguments:n/a
                                                                                                                              File size:4379400 bytes
                                                                                                                              MD5 hash:7dc1c0e23cd5e102bb12e5c29403410e

                                                                                                                              Start time:19:37:48
                                                                                                                              Start date:20/01/2022
                                                                                                                              Path:/tmp/6THNtWwZbK
                                                                                                                              Arguments:n/a
                                                                                                                              File size:4379400 bytes
                                                                                                                              MD5 hash:7dc1c0e23cd5e102bb12e5c29403410e

                                                                                                                              Start time:19:37:48
                                                                                                                              Start date:20/01/2022
                                                                                                                              Path:/tmp/6THNtWwZbK
                                                                                                                              Arguments:n/a
                                                                                                                              File size:4379400 bytes
                                                                                                                              MD5 hash:7dc1c0e23cd5e102bb12e5c29403410e

                                                                                                                              Start time:19:37:40
                                                                                                                              Start date:20/01/2022
                                                                                                                              Path:/tmp/6THNtWwZbK
                                                                                                                              Arguments:n/a
                                                                                                                              File size:4379400 bytes
                                                                                                                              MD5 hash:7dc1c0e23cd5e102bb12e5c29403410e

                                                                                                                              Start time:19:37:40
                                                                                                                              Start date:20/01/2022
                                                                                                                              Path:/tmp/6THNtWwZbK
                                                                                                                              Arguments:n/a
                                                                                                                              File size:4379400 bytes
                                                                                                                              MD5 hash:7dc1c0e23cd5e102bb12e5c29403410e

                                                                                                                              Start time:19:37:40
                                                                                                                              Start date:20/01/2022
                                                                                                                              Path:/tmp/6THNtWwZbK
                                                                                                                              Arguments:n/a
                                                                                                                              File size:4379400 bytes
                                                                                                                              MD5 hash:7dc1c0e23cd5e102bb12e5c29403410e

                                                                                                                              Start time:19:37:40
                                                                                                                              Start date:20/01/2022
                                                                                                                              Path:/tmp/6THNtWwZbK
                                                                                                                              Arguments:n/a
                                                                                                                              File size:4379400 bytes
                                                                                                                              MD5 hash:7dc1c0e23cd5e102bb12e5c29403410e

                                                                                                                              Start time:19:37:52
                                                                                                                              Start date:20/01/2022
                                                                                                                              Path:/usr/bin/dash
                                                                                                                              Arguments:n/a
                                                                                                                              File size:129816 bytes
                                                                                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                                                              Start time:19:37:52
                                                                                                                              Start date:20/01/2022
                                                                                                                              Path:/usr/bin/rm
                                                                                                                              Arguments:rm -f /tmp/tmp.3kX8YuCx8O /tmp/tmp.kPrHzHFpnR /tmp/tmp.Rta5ifU2ma
                                                                                                                              File size:72056 bytes
                                                                                                                              MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b