Edit tour
Linux
Analysis Report
x86
Overview
General Information
Sample Name: | x86 |
Analysis ID: | 635907 |
MD5: | bef642eeed970f7c3ee944a513ea4c88 |
SHA1: | baaa1dc20118f95134cb1ca1fa0c32ad49ed8eeb |
SHA256: | 10f35885f96f694fbf6239de4f4e400367cdb0201bd6b4a6fa85b3cc609de22e |
Infos: |
Detection
Mirai
Score: | 64 |
Range: | 0 - 100 |
Whitelisted: | false |
Signatures
Multi AV Scanner detection for submitted file
Yara detected Mirai
Machine Learning detection for sample
Uses known network protocols on non-standard ports
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Detected TCP or UDP traffic on non-standard ports
Sample has stripped symbol table
Classification
Analysis Advice
All HTTP servers contacted by the sample do not answer. The sample is likely an old dropper which does no longer work. |
Joe Sandbox Version: | 34.0.0 Boulder Opal |
Analysis ID: | 635907 |
Start date and time: 30/05/202206:58:45 | 2022-05-30 06:58:45 +02:00 |
Joe Sandbox Product: | CloudBasic |
Overall analysis duration: | 0h 6m 10s |
Hypervisor based Inspection enabled: | false |
Report type: | light |
Sample file name: | x86 |
Cookbook file name: | defaultlinuxfilecookbook.jbs |
Analysis system description: | Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11) |
Analysis Mode: | default |
Detection: | MAL |
Classification: | mal64.troj.lin@0/0@0/0 |
- Report size exceeded maximum capacity and may have missing network information.
- TCP Packets have been reduced to 100
Command: | /tmp/x86 |
PID: | 6221 |
Exit Code: | 0 |
Exit Code Info: | |
Killed: | False |
Standard Output: | '' |
Standard Error: |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_Mirai_12 | Yara detected Mirai | Joe Security |
⊘No Snort rule has matched
Click to jump to signature section
Show All Signature Results
AV Detection |
---|
Source: | Virustotal: | Perma Link |
Source: | Joe Sandbox ML: |
Networking |
---|
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: |
Source: | TCP traffic: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: |
Source: | .symtab present: |
Source: | Classification label: |
Hooking and other Techniques for Hiding and Protection |
---|
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Stealing of Sensitive Information |
---|
Source: | File source: |
Remote Access Functionality |
---|
Source: | File source: |
Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Exfiltration | Command and Control | Network Effects | Remote Service Effects | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Valid Accounts | Windows Management Instrumentation | Path Interception | Path Interception | Direct Volume Access | OS Credential Dumping | System Service Discovery | Remote Services | Data from Local System | Exfiltration Over Other Network Medium | 1 Encrypted Channel | Eavesdrop on Insecure Network Communication | Remotely Track Device Without Authorization | Modify System Partition |
Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | Rootkit | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | Exfiltration Over Bluetooth | 11 Non-Standard Port | Exploit SS7 to Redirect Phone Calls/SMS | Remotely Wipe Data Without Authorization | Device Lockout |
Domain Accounts | At (Linux) | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | Automated Exfiltration | 1 Application Layer Protocol | Exploit SS7 to Track Device Location | Obtain Device Cloud Backups | Delete Device Data |
⊘No configs have been found
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
46% | Virustotal | Browse | ||
100% | Joe Sandbox ML |
⊘No Antivirus matches
⊘No Antivirus matches
⊘No Antivirus matches
⊘No contacted domains info
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
71.82.186.46 | unknown | United States | 20115 | CHARTER-20115US | false | |
8.188.166.156 | unknown | Singapore | 37963 | CNNIC-ALIBABA-CN-NET-APHangzhouAlibabaAdvertisingCoLtd | false | |
222.18.102.174 | unknown | China | 4538 | ERX-CERNET-BKBChinaEducationandResearchNetworkCenter | false | |
163.69.133.211 | unknown | France | 17816 | CHINA169-GZChinaUnicomIPnetworkChina169Guangdongprovi | false | |
161.199.170.152 | unknown | United States | 27311 | AS27311US | false | |
97.195.248.46 | unknown | United States | 6167 | CELLCO-PARTUS | false | |
167.127.239.68 | unknown | United States | 11520 | ALLSTATE-INSURANCE-COUS | false | |
115.107.38.68 | unknown | China | 17488 | HATHWAY-NET-APHathwayIPOverCableInternetIN | false | |
173.66.71.180 | unknown | United States | 701 | UUNETUS | false | |
24.45.250.77 | unknown | United States | 6128 | CABLE-NET-1US | false | |
92.184.111.45 | unknown | France | 3215 | FranceTelecom-OrangeFR | false | |
61.106.99.55 | unknown | Korea Republic of | 17839 | DREAMPLUS-AS-KRLGHelloVisionCorpKR | false | |
98.112.164.94 | unknown | United States | 7018 | ATT-INTERNET4US | false | |
223.217.50.228 | unknown | Japan | 4713 | OCNNTTCommunicationsCorporationJP | false | |
112.183.28.110 | unknown | Korea Republic of | 4766 | KIXS-AS-KRKoreaTelecomKR | false | |
183.23.36.205 | unknown | China | 4134 | CHINANET-BACKBONENo31Jin-rongStreetCN | false | |
161.145.179.44 | unknown | United States | 263740 | CorporacionLaceibanetsocietyHN | false | |
171.188.4.179 | unknown | United States | 9874 | STARHUB-MOBILEStarHubLtdSG | false | |
66.126.55.147 | unknown | United States | 22352 | APPLIED-TECHNOLOGYUS | false | |
206.219.82.9 | unknown | United States | 6461 | ZAYO-6461US | false | |
1.68.163.174 | unknown | China | 4134 | CHINANET-BACKBONENo31Jin-rongStreetCN | false | |
141.89.138.125 | unknown | Germany | 680 | DFNVereinzurFoerderungeinesDeutschenForschungsnetzese | false | |
139.182.115.224 | unknown | United States | 2152 | CSUNET-NWUS | false | |
63.100.146.131 | unknown | United States | 701 | UUNETUS | false | |
116.40.101.173 | unknown | Korea Republic of | 17858 | POWERVIS-AS-KRLGPOWERCOMMKR | false | |
166.111.47.118 | unknown | China | 4538 | ERX-CERNET-BKBChinaEducationandResearchNetworkCenter | false | |
73.99.131.134 | unknown | United States | 7922 | COMCAST-7922US | false | |
71.75.173.83 | unknown | United States | 11426 | TWC-11426-CAROLINASUS | false | |
20.231.62.15 | unknown | United States | 8075 | MICROSOFT-CORP-MSN-AS-BLOCKUS | false | |
220.79.231.181 | unknown | Korea Republic of | 4766 | KIXS-AS-KRKoreaTelecomKR | false | |
130.146.219.140 | unknown | Netherlands | 6908 | DATAHOPDatahop-SixDegreesGB | false | |
18.252.179.134 | unknown | United States | 16509 | AMAZON-02US | false | |
174.130.97.135 | unknown | United States | 7029 | WINDSTREAMUS | false | |
168.5.246.18 | unknown | United States | 8 | RICE-ASUS | false | |
103.223.165.48 | unknown | China | 135445 | IDNIC-AIRPAY-AS-IDPTAirpayInternationalIndonesiaID | false | |
63.202.183.61 | unknown | United States | 7018 | ATT-INTERNET4US | false | |
196.170.140.141 | unknown | Togo | 24691 | TOGOTEL-ASTogoTelecomTogoTG | false | |
181.45.1.154 | unknown | Argentina | 27747 | TelecentroSAAR | false | |
206.9.140.116 | unknown | United States | 5006 | VOYANTUS | false | |
109.174.181.139 | unknown | United Kingdom | 4589 | EASYNETEasynetGlobalServicesEU | false | |
182.134.160.88 | unknown | China | 4134 | CHINANET-BACKBONENo31Jin-rongStreetCN | false | |
95.183.142.116 | unknown | Turkey | 8517 | ULAKNETTR | false | |
9.100.126.155 | unknown | United States | 3356 | LEVEL3US | false | |
34.96.75.202 | unknown | United States | 15169 | GOOGLEUS | false | |
169.80.122.10 | unknown | United States | 37611 | AfrihostZA | false | |
212.229.189.169 | unknown | United Kingdom | 6659 | NEXINTO-DE | false | |
193.122.239.176 | unknown | United States | 31898 | ORACLE-BMC-31898US | false | |
199.98.250.141 | unknown | United States | 174 | COGENT-174US | false | |
152.247.120.26 | unknown | Brazil | 26599 | TELEFONICABRASILSABR | false | |
98.175.159.226 | unknown | United States | 22773 | ASN-CXA-ALL-CCI-22773-RDCUS | false | |
149.64.54.62 | unknown | United States | 188 | SAIC-ASUS | false | |
185.91.208.162 | unknown | Azerbaijan | 198193 | ASN-TCABLEES | false | |
54.109.99.197 | unknown | United States | 16509 | AMAZON-02US | false | |
91.211.55.231 | unknown | Russian Federation | 48494 | MKNET-ASCZ | false | |
9.195.199.9 | unknown | United States | 3356 | LEVEL3US | false | |
114.108.48.50 | unknown | Korea Republic of | 23563 | VITSSEN-SUWON-AS-KRTbroadSuwonBroadcastingCorporationK | false | |
218.72.121.235 | unknown | China | 4134 | CHINANET-BACKBONENo31Jin-rongStreetCN | false | |
18.133.194.252 | unknown | United States | 16509 | AMAZON-02US | false | |
157.21.250.131 | unknown | United States | 53446 | EVMSUS | false | |
38.118.59.140 | unknown | United States | 174 | COGENT-174US | false | |
184.98.240.213 | unknown | United States | 209 | CENTURYLINK-US-LEGACY-QWESTUS | false | |
176.86.239.65 | unknown | Spain | 3352 | TELEFONICA_DE_ESPANAES | false | |
203.101.40.148 | unknown | India | 24560 | AIRTELBROADBAND-AS-APBhartiAirtelLtdTelemediaServices | false | |
216.137.217.153 | unknown | United States | 11090 | MTAONLINE-ASUS | false | |
89.67.99.51 | unknown | Poland | 6830 | LIBERTYGLOBALLibertyGlobalformerlyUPCBroadbandHolding | false | |
183.152.181.199 | unknown | China | 4134 | CHINANET-BACKBONENo31Jin-rongStreetCN | false | |
39.3.14.235 | unknown | Japan | 4725 | ODNSoftBankMobileCorpJP | false | |
185.203.160.88 | unknown | Iran (ISLAMIC Republic Of) | 205837 | SADADPSP-ASSadadProcessingModernServicesCompanyPJS | false | |
90.34.68.223 | unknown | France | 3215 | FranceTelecom-OrangeFR | false | |
187.213.164.208 | unknown | Mexico | 8151 | UninetSAdeCVMX | false | |
200.172.238.44 | unknown | Brazil | 4230 | CLAROSABR | false | |
61.73.112.244 | unknown | Korea Republic of | 4766 | KIXS-AS-KRKoreaTelecomKR | false | |
81.148.253.114 | unknown | United Kingdom | 2856 | BT-UK-ASBTnetUKRegionalnetworkGB | false | |
45.173.39.97 | unknown | Brazil | 268790 | DEBORAALINEALMEIDA-MEBR | false | |
131.215.33.187 | unknown | United States | 31 | CITUS | false | |
112.183.28.147 | unknown | Korea Republic of | 4766 | KIXS-AS-KRKoreaTelecomKR | false | |
99.55.160.90 | unknown | United States | 7018 | ATT-INTERNET4US | false | |
108.30.94.26 | unknown | United States | 701 | UUNETUS | false | |
136.94.212.177 | unknown | United States | 60311 | ONEFMCH | false | |
115.6.239.91 | unknown | Korea Republic of | 4766 | KIXS-AS-KRKoreaTelecomKR | false | |
42.170.152.249 | unknown | China | 4249 | LILLY-ASUS | false | |
77.19.124.127 | unknown | Norway | 2119 | TELENOR-NEXTELTelenorNorgeASNO | false | |
209.210.62.8 | unknown | United States | 396033 | BFDX515US | false | |
149.210.46.1 | unknown | Greece | 29247 | COSMOTE-GRCosmoteMobileTelecommunicationsSAGR | false | |
85.103.175.203 | unknown | Turkey | 9121 | TTNETTR | false | |
125.137.19.174 | unknown | Korea Republic of | 4766 | KIXS-AS-KRKoreaTelecomKR | false | |
213.23.15.125 | unknown | Germany | 3209 | VODANETInternationalIP-BackboneofVodafoneDE | false | |
191.154.239.239 | unknown | Colombia | 26611 | COMCELSACO | false | |
153.248.18.11 | unknown | Japan | 4713 | OCNNTTCommunicationsCorporationJP | false | |
179.185.213.56 | unknown | Brazil | 18881 | TELEFONICABRASILSABR | false | |
84.223.116.24 | unknown | Italy | 8612 | TISCALI-IT | false | |
94.9.108.60 | unknown | United Kingdom | 5607 | BSKYB-BROADBAND-ASGB | false | |
203.190.179.96 | unknown | Singapore | 7552 | VIETEL-AS-APViettelGroupVN | false | |
158.113.125.249 | unknown | United States | 49278 | NORDEFNO | false | |
42.30.66.52 | unknown | Korea Republic of | 9644 | SKTELECOM-NET-ASSKTelecomKR | false | |
128.83.226.100 | unknown | United States | 18 | UTEXASUS | false | |
218.209.89.102 | unknown | Korea Republic of | 23563 | VITSSEN-SUWON-AS-KRTbroadSuwonBroadcastingCorporationK | false | |
98.67.105.92 | unknown | United States | 11351 | TWC-11351-NORTHEASTUS | false | |
161.26.142.204 | unknown | United States | 1916 | AssociacaoRedeNacionaldeEnsinoePesquisaBR | false | |
131.141.109.74 | unknown | Canada | 74 | SSC-299-Z-74CA | false |
⊘No created / dropped files found
File type: | |
Entropy (8bit): | 6.483956231146537 |
TrID: |
|
File name: | x86 |
File size: | 55332 |
MD5: | bef642eeed970f7c3ee944a513ea4c88 |
SHA1: | baaa1dc20118f95134cb1ca1fa0c32ad49ed8eeb |
SHA256: | 10f35885f96f694fbf6239de4f4e400367cdb0201bd6b4a6fa85b3cc609de22e |
SHA512: | 11e9b343e7c658355d22ea542808b0f1bcb191cc4537296d4ea3ceac1a564b0c1fa283f831054a029451207a5cfae41939231aab73ac9f737036aea887f3b8f1 |
SSDEEP: | 768:cRe7+KeFIsC1pDU/4p+gP0JrTS/+Q+Y7RamvmxDOKUKICkmT1:WI+KidsP0JK/+Qh7RasmxiKFsm |
TLSH: | 60433A85D6DBF9F2E85104BC30A9AB72DF33F53AA871D9DBE39D24229C06201D20635D |
File Content Preview: | .ELF....................d...4...........4. ...(..............................................c...c.......k..........Q.td............................U..S............h....C...[]...$.............U......=`f...t..5.....c......c......u........t....h.S.......... |
ELF header | |
---|---|
Class: | |
Data: | |
Version: | |
Machine: | |
Version Number: | |
Type: | |
OS/ABI: | |
ABI Version: | |
Entry Point Address: | |
Flags: | |
ELF Header Size: | |
Program Header Offset: | |
Program Header Size: | |
Number of Program Headers: | |
Section Header Offset: | |
Section Header Size: | |
Number of Section Headers: | |
Header String Table Index: |
Name | Type | Address | Offset | Size | EntSize | Flags | Flags Description | Link | Info | Align |
---|---|---|---|---|---|---|---|---|---|---|
NULL | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0 | 0 | 0 | ||
.init | PROGBITS | 0x8048094 | 0x94 | 0x1c | 0x0 | 0x6 | AX | 0 | 0 | 1 |
.text | PROGBITS | 0x80480b0 | 0xb0 | 0xc366 | 0x0 | 0x6 | AX | 0 | 0 | 16 |
.fini | PROGBITS | 0x8054416 | 0xc416 | 0x17 | 0x0 | 0x6 | AX | 0 | 0 | 1 |
.rodata | PROGBITS | 0x8054440 | 0xc440 | 0xf40 | 0x0 | 0x2 | A | 0 | 0 | 32 |
.ctors | PROGBITS | 0x8056384 | 0xd384 | 0x8 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.dtors | PROGBITS | 0x805638c | 0xd38c | 0x8 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.data | PROGBITS | 0x80563c0 | 0xd3c0 | 0x294 | 0x0 | 0x3 | WA | 0 | 0 | 32 |
.bss | NOBITS | 0x8056660 | 0xd654 | 0x6904 | 0x0 | 0x3 | WA | 0 | 0 | 32 |
.shstrtab | STRTAB | 0x0 | 0xd654 | 0x3e | 0x0 | 0x0 | 0 | 0 | 1 |
Type | Offset | Virtual Address | Physical Address | File Size | Memory Size | Entropy | Flags | Flags Description | Align | Prog Interpreter | Section Mappings |
---|---|---|---|---|---|---|---|---|---|---|---|
LOAD | 0x0 | 0x8048000 | 0x8048000 | 0xd380 | 0xd380 | 3.6131 | 0x5 | R E | 0x1000 | .init .text .fini .rodata | |
LOAD | 0xd384 | 0x8056384 | 0x8056384 | 0x2d0 | 0x6be0 | 2.0811 | 0x6 | RW | 0x1000 | .ctors .dtors .data .bss | |
GNU_STACK | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0.0000 | 0x6 | RW | 0x4 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
May 30, 2022 06:59:33.350195885 CEST | 23 | 50008 | 119.48.37.48 | 192.168.2.23 |
May 30, 2022 06:59:33.350447893 CEST | 50008 | 23 | 192.168.2.23 | 119.48.37.48 |
May 30, 2022 06:59:33.684422970 CEST | 23 | 41260 | 112.199.58.34 | 192.168.2.23 |
May 30, 2022 06:59:33.684451103 CEST | 23 | 41260 | 112.199.58.34 | 192.168.2.23 |
May 30, 2022 06:59:33.684602976 CEST | 41260 | 23 | 192.168.2.23 | 112.199.58.34 |
May 30, 2022 06:59:33.684638977 CEST | 41260 | 23 | 192.168.2.23 | 112.199.58.34 |
May 30, 2022 06:59:33.902144909 CEST | 23 | 50008 | 119.48.37.48 | 192.168.2.23 |
May 30, 2022 06:59:33.902334929 CEST | 50008 | 23 | 192.168.2.23 | 119.48.37.48 |
May 30, 2022 06:59:34.534204006 CEST | 42836 | 443 | 192.168.2.23 | 91.189.91.43 |
May 30, 2022 06:59:34.790235043 CEST | 42516 | 80 | 192.168.2.23 | 109.202.202.202 |
May 30, 2022 06:59:34.998879910 CEST | 23 | 50008 | 119.48.37.48 | 192.168.2.23 |
May 30, 2022 06:59:34.999098063 CEST | 50008 | 23 | 192.168.2.23 | 119.48.37.48 |
May 30, 2022 06:59:35.408418894 CEST | 36373 | 23 | 192.168.2.23 | 8.96.87.23 |
May 30, 2022 06:59:35.408418894 CEST | 36373 | 23 | 192.168.2.23 | 101.211.21.120 |
May 30, 2022 06:59:35.408428907 CEST | 36373 | 23 | 192.168.2.23 | 179.10.18.120 |
May 30, 2022 06:59:35.408435106 CEST | 36373 | 23 | 192.168.2.23 | 119.21.212.120 |
May 30, 2022 06:59:35.408468008 CEST | 36373 | 23 | 192.168.2.23 | 31.254.177.252 |
May 30, 2022 06:59:35.408472061 CEST | 36373 | 23 | 192.168.2.23 | 162.189.50.109 |
May 30, 2022 06:59:35.408493042 CEST | 36373 | 23 | 192.168.2.23 | 92.155.50.169 |
May 30, 2022 06:59:35.408500910 CEST | 36373 | 23 | 192.168.2.23 | 1.114.66.222 |
May 30, 2022 06:59:35.408500910 CEST | 36373 | 23 | 192.168.2.23 | 83.164.66.106 |
May 30, 2022 06:59:35.408505917 CEST | 36373 | 23 | 192.168.2.23 | 80.45.115.63 |
May 30, 2022 06:59:35.408514023 CEST | 36373 | 23 | 192.168.2.23 | 19.139.69.139 |
May 30, 2022 06:59:35.408525944 CEST | 36373 | 23 | 192.168.2.23 | 136.163.173.249 |
May 30, 2022 06:59:35.408535004 CEST | 36373 | 23 | 192.168.2.23 | 100.17.171.186 |
May 30, 2022 06:59:35.408538103 CEST | 36373 | 23 | 192.168.2.23 | 2.253.132.212 |
May 30, 2022 06:59:35.408546925 CEST | 36373 | 23 | 192.168.2.23 | 102.143.203.201 |
May 30, 2022 06:59:35.408565044 CEST | 36373 | 23 | 192.168.2.23 | 18.19.199.39 |
May 30, 2022 06:59:35.408590078 CEST | 36373 | 23 | 192.168.2.23 | 117.78.143.153 |
May 30, 2022 06:59:35.408595085 CEST | 36373 | 23 | 192.168.2.23 | 131.130.219.36 |
May 30, 2022 06:59:35.408596992 CEST | 36373 | 23 | 192.168.2.23 | 87.129.46.43 |
May 30, 2022 06:59:35.408620119 CEST | 36373 | 23 | 192.168.2.23 | 72.201.168.50 |
May 30, 2022 06:59:35.408674955 CEST | 36373 | 23 | 192.168.2.23 | 91.78.49.31 |
May 30, 2022 06:59:35.408679962 CEST | 36373 | 23 | 192.168.2.23 | 118.61.172.171 |
May 30, 2022 06:59:35.408679962 CEST | 36373 | 23 | 192.168.2.23 | 117.236.64.119 |
May 30, 2022 06:59:35.408684015 CEST | 36373 | 23 | 192.168.2.23 | 218.55.177.68 |
May 30, 2022 06:59:35.408694983 CEST | 36373 | 23 | 192.168.2.23 | 102.24.47.215 |
May 30, 2022 06:59:35.408695936 CEST | 36373 | 23 | 192.168.2.23 | 70.37.108.135 |
May 30, 2022 06:59:35.408696890 CEST | 36373 | 23 | 192.168.2.23 | 117.182.136.248 |
May 30, 2022 06:59:35.408701897 CEST | 36373 | 23 | 192.168.2.23 | 87.32.147.70 |
May 30, 2022 06:59:35.408703089 CEST | 36373 | 23 | 192.168.2.23 | 155.15.109.18 |
May 30, 2022 06:59:35.408710003 CEST | 36373 | 23 | 192.168.2.23 | 190.247.152.244 |
May 30, 2022 06:59:35.408715963 CEST | 36373 | 23 | 192.168.2.23 | 125.239.28.124 |
May 30, 2022 06:59:35.408716917 CEST | 36373 | 23 | 192.168.2.23 | 131.48.123.198 |
May 30, 2022 06:59:35.408727884 CEST | 36373 | 23 | 192.168.2.23 | 161.184.56.240 |
May 30, 2022 06:59:35.408729076 CEST | 36373 | 23 | 192.168.2.23 | 108.162.204.92 |
May 30, 2022 06:59:35.408734083 CEST | 36373 | 23 | 192.168.2.23 | 147.166.16.121 |
May 30, 2022 06:59:35.408807039 CEST | 36373 | 23 | 192.168.2.23 | 196.134.215.117 |
May 30, 2022 06:59:35.408816099 CEST | 36373 | 23 | 192.168.2.23 | 42.27.39.90 |
May 30, 2022 06:59:35.408827066 CEST | 36373 | 23 | 192.168.2.23 | 58.57.176.45 |
May 30, 2022 06:59:35.408855915 CEST | 36373 | 23 | 192.168.2.23 | 168.229.44.89 |
May 30, 2022 06:59:35.408860922 CEST | 36373 | 23 | 192.168.2.23 | 80.116.246.85 |
May 30, 2022 06:59:35.408869982 CEST | 36373 | 23 | 192.168.2.23 | 23.202.87.42 |
May 30, 2022 06:59:35.408874035 CEST | 36373 | 23 | 192.168.2.23 | 135.84.138.222 |
May 30, 2022 06:59:35.408883095 CEST | 36373 | 23 | 192.168.2.23 | 221.54.169.180 |
May 30, 2022 06:59:35.408905029 CEST | 36373 | 23 | 192.168.2.23 | 153.35.145.184 |
May 30, 2022 06:59:35.408905029 CEST | 36373 | 23 | 192.168.2.23 | 93.252.199.123 |
May 30, 2022 06:59:35.408922911 CEST | 36373 | 23 | 192.168.2.23 | 110.18.183.220 |
May 30, 2022 06:59:35.408925056 CEST | 36373 | 23 | 192.168.2.23 | 200.13.58.219 |
May 30, 2022 06:59:35.408934116 CEST | 36373 | 23 | 192.168.2.23 | 207.86.126.100 |
May 30, 2022 06:59:35.408947945 CEST | 36373 | 23 | 192.168.2.23 | 67.250.83.151 |
May 30, 2022 06:59:35.408960104 CEST | 36373 | 23 | 192.168.2.23 | 95.138.69.241 |
May 30, 2022 06:59:35.408970118 CEST | 36373 | 23 | 192.168.2.23 | 67.202.193.96 |
May 30, 2022 06:59:35.408979893 CEST | 36373 | 23 | 192.168.2.23 | 47.41.174.1 |
May 30, 2022 06:59:35.408991098 CEST | 36373 | 23 | 192.168.2.23 | 1.254.17.66 |
May 30, 2022 06:59:35.409001112 CEST | 36373 | 23 | 192.168.2.23 | 18.168.160.204 |
May 30, 2022 06:59:35.409008980 CEST | 36373 | 23 | 192.168.2.23 | 20.88.249.72 |
May 30, 2022 06:59:35.409023046 CEST | 36373 | 23 | 192.168.2.23 | 2.161.172.133 |
May 30, 2022 06:59:35.409033060 CEST | 36373 | 23 | 192.168.2.23 | 192.221.23.40 |
May 30, 2022 06:59:35.409044981 CEST | 36373 | 23 | 192.168.2.23 | 151.116.52.175 |
May 30, 2022 06:59:35.409054995 CEST | 36373 | 23 | 192.168.2.23 | 119.111.118.243 |
May 30, 2022 06:59:35.409065962 CEST | 36373 | 23 | 192.168.2.23 | 65.36.16.51 |
May 30, 2022 06:59:35.409080029 CEST | 36373 | 23 | 192.168.2.23 | 128.140.250.128 |
May 30, 2022 06:59:35.409084082 CEST | 36373 | 23 | 192.168.2.23 | 122.105.233.110 |
May 30, 2022 06:59:35.409097910 CEST | 36373 | 23 | 192.168.2.23 | 132.205.154.72 |
May 30, 2022 06:59:35.409107924 CEST | 36373 | 23 | 192.168.2.23 | 118.181.150.139 |
May 30, 2022 06:59:35.409116030 CEST | 36373 | 23 | 192.168.2.23 | 148.193.212.143 |
May 30, 2022 06:59:35.409125090 CEST | 36373 | 23 | 192.168.2.23 | 168.97.66.76 |
May 30, 2022 06:59:35.409142971 CEST | 36373 | 23 | 192.168.2.23 | 71.136.9.107 |
May 30, 2022 06:59:35.409151077 CEST | 36373 | 23 | 192.168.2.23 | 212.97.246.207 |
May 30, 2022 06:59:35.409158945 CEST | 36373 | 23 | 192.168.2.23 | 91.6.240.218 |
May 30, 2022 06:59:35.409178019 CEST | 36373 | 23 | 192.168.2.23 | 131.72.158.124 |
May 30, 2022 06:59:35.409188032 CEST | 36373 | 23 | 192.168.2.23 | 58.169.66.188 |
May 30, 2022 06:59:35.409198999 CEST | 36373 | 23 | 192.168.2.23 | 183.211.69.53 |
May 30, 2022 06:59:35.409212112 CEST | 36373 | 23 | 192.168.2.23 | 109.191.69.175 |
May 30, 2022 06:59:35.409240007 CEST | 36373 | 23 | 192.168.2.23 | 122.189.245.178 |
May 30, 2022 06:59:35.409248114 CEST | 36373 | 23 | 192.168.2.23 | 209.147.2.206 |
May 30, 2022 06:59:35.409248114 CEST | 36373 | 23 | 192.168.2.23 | 171.78.211.12 |
May 30, 2022 06:59:35.409267902 CEST | 36373 | 23 | 192.168.2.23 | 202.122.130.17 |
May 30, 2022 06:59:35.409584045 CEST | 36373 | 23 | 192.168.2.23 | 37.237.124.2 |
May 30, 2022 06:59:35.409590006 CEST | 36373 | 23 | 192.168.2.23 | 114.50.255.22 |
May 30, 2022 06:59:35.409612894 CEST | 36373 | 23 | 192.168.2.23 | 60.103.177.248 |
May 30, 2022 06:59:35.409615040 CEST | 36373 | 23 | 192.168.2.23 | 77.13.181.73 |
May 30, 2022 06:59:35.409627914 CEST | 36373 | 23 | 192.168.2.23 | 136.246.188.42 |
May 30, 2022 06:59:35.409636021 CEST | 36373 | 23 | 192.168.2.23 | 181.43.175.189 |
May 30, 2022 06:59:35.409655094 CEST | 36373 | 23 | 192.168.2.23 | 144.0.247.73 |
May 30, 2022 06:59:35.409662962 CEST | 36373 | 23 | 192.168.2.23 | 31.240.157.160 |
May 30, 2022 06:59:35.409678936 CEST | 36373 | 23 | 192.168.2.23 | 200.142.192.117 |
May 30, 2022 06:59:35.409681082 CEST | 36373 | 23 | 192.168.2.23 | 17.55.108.2 |
May 30, 2022 06:59:35.409701109 CEST | 36373 | 23 | 192.168.2.23 | 221.24.144.224 |
System Behavior
Start time: | 06:59:34 |
Start date: | 30/05/2022 |
Path: | /tmp/x86 |
Arguments: | /tmp/x86 |
File size: | 55332 bytes |
MD5 hash: | bef642eeed970f7c3ee944a513ea4c88 |
Start time: | 06:59:34 |
Start date: | 30/05/2022 |
Path: | /tmp/x86 |
Arguments: | n/a |
File size: | 55332 bytes |
MD5 hash: | bef642eeed970f7c3ee944a513ea4c88 |
Start time: | 06:59:34 |
Start date: | 30/05/2022 |
Path: | /tmp/x86 |
Arguments: | n/a |
File size: | 55332 bytes |
MD5 hash: | bef642eeed970f7c3ee944a513ea4c88 |
Start time: | 06:59:34 |
Start date: | 30/05/2022 |
Path: | /tmp/x86 |
Arguments: | n/a |
File size: | 55332 bytes |
MD5 hash: | bef642eeed970f7c3ee944a513ea4c88 |
Start time: | 06:59:41 |
Start date: | 30/05/2022 |
Path: | /tmp/x86 |
Arguments: | n/a |
File size: | 55332 bytes |
MD5 hash: | bef642eeed970f7c3ee944a513ea4c88 |
Start time: | 06:59:41 |
Start date: | 30/05/2022 |
Path: | /tmp/x86 |
Arguments: | n/a |
File size: | 55332 bytes |
MD5 hash: | bef642eeed970f7c3ee944a513ea4c88 |
Start time: | 06:59:34 |
Start date: | 30/05/2022 |
Path: | /tmp/x86 |
Arguments: | n/a |
File size: | 55332 bytes |
MD5 hash: | bef642eeed970f7c3ee944a513ea4c88 |
Start time: | 06:59:34 |
Start date: | 30/05/2022 |
Path: | /tmp/x86 |
Arguments: | n/a |
File size: | 55332 bytes |
MD5 hash: | bef642eeed970f7c3ee944a513ea4c88 |