Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf

Overview

General Information

Sample name:SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf
Analysis ID:1502374
MD5:aa169fa830cdf00b8611b0977dc2f162
SHA1:c0722ee6b87b245b7e6c9203c367ae052ddebff1
SHA256:78cfdc711effbe746fdd0e197963294b5c70fad50b28ab3e8a6adece80ced177
Tags:elf
Infos:

Detection

Mirai
Score:68
Range:0 - 100
Whitelisted:false

Signatures

Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Yara detected Mirai
Sample is packed with UPX
Detected TCP or UDP traffic on non-standard ports
ELF contains segments with high entropy indicating compressed/encrypted content
Enumerates processes within the "proc" file system
Executes the "rm" command used to delete files or directories
Sample contains only a LOAD segment without any section mappings
Uses the "uname" system call to query kernel version information (possible evasion)
Yara signature match

Classification

Joe Sandbox version:40.0.0 Tourmaline
Analysis ID:1502374
Start date and time:2024-09-01 01:53:57 +02:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 5m 28s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf
Detection:MAL
Classification:mal68.troj.evad.linELF@0/0@0/0
Command:/tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf
PID:6265
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
lzrd cock fest"/proc/"/exe
Standard Error:
  • system is lnxubuntu20
  • dash New Fork (PID: 6288, Parent: 4331)
  • rm (PID: 6288, Parent: 4331, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.F90B2oY7y7 /tmp/tmp.lRsNrXAb1n /tmp/tmp.LviB0ul97I
  • dash New Fork (PID: 6289, Parent: 4331)
  • rm (PID: 6289, Parent: 4331, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.F90B2oY7y7 /tmp/tmp.lRsNrXAb1n /tmp/tmp.LviB0ul97I
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
MiraiMirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese. Nowadays it targets a wide range of networked embedded devices such as IP cameras, home routers (many vendors involved), and other IoT devices. Since the source code was published on "Hack Forums" many variants of the Mirai family appeared, infecting mostly home networks all around the world.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/elf.mirai
SourceRuleDescriptionAuthorStrings
6265.1.00007f2720017000.00007f272002d000.r-x.sdmpJoeSecurity_Mirai_8Yara detected MiraiJoe Security
    6265.1.00007f2720017000.00007f272002d000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
    • 0x13580:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x13594:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x135a8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x135bc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x135d0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x135e4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x135f8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x1360c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x13620:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x13634:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x13648:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x1365c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x13670:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x13684:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x13698:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x136ac:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x136c0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x136d4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x136e8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x136fc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x13710:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    6265.1.00007f2720017000.00007f272002d000.r-x.sdmpLinux_Trojan_Gafgyt_ea92cca8unknownunknown
    • 0x13ad8:$a: 53 65 6C 66 20 52 65 70 20 46 75 63 6B 69 6E 67 20 4E 65 54 69 53 20 61 6E 64
    6269.1.00007f2720017000.00007f272002d000.r-x.sdmpJoeSecurity_Mirai_8Yara detected MiraiJoe Security
      6269.1.00007f2720017000.00007f272002d000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
      • 0x13580:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x13594:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x135a8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x135bc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x135d0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x135e4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x135f8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x1360c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x13620:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x13634:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x13648:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x1365c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x13670:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x13684:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x13698:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x136ac:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x136c0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x136d4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x136e8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x136fc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x13710:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      Click to see the 7 entries
      No Suricata rule has matched

      Click to jump to signature section

      Show All Signature Results

      AV Detection

      barindex
      Source: SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elfReversingLabs: Detection: 34%
      Source: SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elfVirustotal: Detection: 22%Perma Link
      Source: global trafficTCP traffic: 192.168.2.23:45134 -> 94.156.71.225:3778
      Source: unknownTCP traffic detected without corresponding DNS query: 94.156.71.225
      Source: unknownTCP traffic detected without corresponding DNS query: 94.156.71.225
      Source: unknownTCP traffic detected without corresponding DNS query: 94.156.71.225
      Source: unknownTCP traffic detected without corresponding DNS query: 94.156.71.225
      Source: unknownTCP traffic detected without corresponding DNS query: 94.156.71.225
      Source: unknownTCP traffic detected without corresponding DNS query: 94.156.71.225
      Source: unknownTCP traffic detected without corresponding DNS query: 94.156.71.225
      Source: unknownTCP traffic detected without corresponding DNS query: 94.156.71.225
      Source: unknownTCP traffic detected without corresponding DNS query: 94.156.71.225
      Source: unknownTCP traffic detected without corresponding DNS query: 94.156.71.225
      Source: unknownTCP traffic detected without corresponding DNS query: 94.156.71.225
      Source: unknownTCP traffic detected without corresponding DNS query: 94.156.71.225
      Source: unknownTCP traffic detected without corresponding DNS query: 94.156.71.225
      Source: unknownTCP traffic detected without corresponding DNS query: 94.156.71.225
      Source: unknownTCP traffic detected without corresponding DNS query: 94.156.71.225
      Source: unknownTCP traffic detected without corresponding DNS query: 94.156.71.225
      Source: unknownTCP traffic detected without corresponding DNS query: 94.156.71.225
      Source: unknownTCP traffic detected without corresponding DNS query: 94.156.71.225
      Source: unknownTCP traffic detected without corresponding DNS query: 94.156.71.225
      Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
      Source: unknownTCP traffic detected without corresponding DNS query: 94.156.71.225
      Source: unknownTCP traffic detected without corresponding DNS query: 94.156.71.225
      Source: unknownTCP traffic detected without corresponding DNS query: 94.156.71.225
      Source: unknownTCP traffic detected without corresponding DNS query: 94.156.71.225
      Source: unknownTCP traffic detected without corresponding DNS query: 94.156.71.225
      Source: unknownTCP traffic detected without corresponding DNS query: 94.156.71.225
      Source: unknownTCP traffic detected without corresponding DNS query: 94.156.71.225
      Source: unknownTCP traffic detected without corresponding DNS query: 94.156.71.225
      Source: unknownTCP traffic detected without corresponding DNS query: 34.249.145.219
      Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
      Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
      Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
      Source: unknownTCP traffic detected without corresponding DNS query: 94.156.71.225
      Source: unknownTCP traffic detected without corresponding DNS query: 94.156.71.225
      Source: unknownTCP traffic detected without corresponding DNS query: 94.156.71.225
      Source: unknownTCP traffic detected without corresponding DNS query: 94.156.71.225
      Source: unknownTCP traffic detected without corresponding DNS query: 94.156.71.225
      Source: unknownTCP traffic detected without corresponding DNS query: 94.156.71.225
      Source: SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elfString found in binary or memory: http://upx.sf.net
      Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39256
      Source: unknownNetwork traffic detected: HTTP traffic on port 39256 -> 443

      System Summary

      barindex
      Source: 6265.1.00007f2720017000.00007f272002d000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
      Source: 6265.1.00007f2720017000.00007f272002d000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown
      Source: 6269.1.00007f2720017000.00007f272002d000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
      Source: 6269.1.00007f2720017000.00007f272002d000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown
      Source: Process Memory Space: SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf PID: 6265, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
      Source: Process Memory Space: SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf PID: 6265, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown
      Source: Process Memory Space: SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf PID: 6269, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
      Source: Process Memory Space: SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf PID: 6269, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown
      Source: LOAD without section mappingsProgram segment: 0x8000
      Source: 6265.1.00007f2720017000.00007f272002d000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
      Source: 6265.1.00007f2720017000.00007f272002d000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16
      Source: 6269.1.00007f2720017000.00007f272002d000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
      Source: 6269.1.00007f2720017000.00007f272002d000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16
      Source: Process Memory Space: SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf PID: 6265, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
      Source: Process Memory Space: SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf PID: 6265, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16
      Source: Process Memory Space: SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf PID: 6269, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
      Source: Process Memory Space: SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf PID: 6269, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16
      Source: classification engineClassification label: mal68.troj.evad.linELF@0/0@0/0

      Data Obfuscation

      barindex
      Source: initial sampleString containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $
      Source: initial sampleString containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $
      Source: initial sampleString containing UPX found: $Id: UPX 3.94 Copyright (C) 1996-2017 the UPX Team. All Rights Reserved. $
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf (PID: 6267)File opened: /proc/1582/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf (PID: 6267)File opened: /proc/3088/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf (PID: 6267)File opened: /proc/230/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf (PID: 6267)File opened: /proc/110/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf (PID: 6267)File opened: /proc/231/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf (PID: 6267)File opened: /proc/111/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf (PID: 6267)File opened: /proc/232/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf (PID: 6267)File opened: /proc/1579/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf (PID: 6267)File opened: /proc/112/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf (PID: 6267)File opened: /proc/233/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf (PID: 6267)File opened: /proc/1699/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf (PID: 6267)File opened: /proc/113/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf (PID: 6267)File opened: /proc/234/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf (PID: 6267)File opened: /proc/1335/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf (PID: 6267)File opened: /proc/1698/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf (PID: 6267)File opened: /proc/114/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf (PID: 6267)File opened: /proc/235/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf (PID: 6267)File opened: /proc/1334/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf (PID: 6267)File opened: /proc/1576/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf (PID: 6267)File opened: /proc/2302/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf (PID: 6267)File opened: /proc/115/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf (PID: 6267)File opened: /proc/236/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf (PID: 6267)File opened: /proc/116/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf (PID: 6267)File opened: /proc/237/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf (PID: 6267)File opened: /proc/117/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf (PID: 6267)File opened: /proc/118/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf (PID: 6267)File opened: /proc/910/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf (PID: 6267)File opened: /proc/119/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf (PID: 6267)File opened: /proc/912/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf (PID: 6267)File opened: /proc/10/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf (PID: 6267)File opened: /proc/2307/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf (PID: 6267)File opened: /proc/11/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf (PID: 6267)File opened: /proc/918/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf (PID: 6267)File opened: /proc/12/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf (PID: 6267)File opened: /proc/6240/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf (PID: 6267)File opened: /proc/13/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf (PID: 6267)File opened: /proc/14/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf (PID: 6267)File opened: /proc/15/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf (PID: 6267)File opened: /proc/16/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf (PID: 6267)File opened: /proc/17/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf (PID: 6267)File opened: /proc/18/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf (PID: 6267)File opened: /proc/1594/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf (PID: 6267)File opened: /proc/120/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf (PID: 6267)File opened: /proc/121/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf (PID: 6267)File opened: /proc/1349/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf (PID: 6267)File opened: /proc/1/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf (PID: 6267)File opened: /proc/122/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf (PID: 6267)File opened: /proc/243/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf (PID: 6267)File opened: /proc/123/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf (PID: 6267)File opened: /proc/2/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf (PID: 6267)File opened: /proc/124/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf (PID: 6267)File opened: /proc/3/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf (PID: 6267)File opened: /proc/4/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf (PID: 6267)File opened: /proc/125/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf (PID: 6267)File opened: /proc/126/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf (PID: 6267)File opened: /proc/1344/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf (PID: 6267)File opened: /proc/1465/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf (PID: 6267)File opened: /proc/1586/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf (PID: 6267)File opened: /proc/127/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf (PID: 6267)File opened: /proc/6/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf (PID: 6267)File opened: /proc/248/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf (PID: 6267)File opened: /proc/128/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf (PID: 6267)File opened: /proc/249/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf (PID: 6267)File opened: /proc/1463/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf (PID: 6267)File opened: /proc/800/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf (PID: 6267)File opened: /proc/9/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf (PID: 6267)File opened: /proc/801/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf (PID: 6267)File opened: /proc/20/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf (PID: 6267)File opened: /proc/21/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf (PID: 6267)File opened: /proc/1900/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf (PID: 6267)File opened: /proc/22/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf (PID: 6267)File opened: /proc/23/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf (PID: 6267)File opened: /proc/24/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf (PID: 6267)File opened: /proc/25/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf (PID: 6267)File opened: /proc/26/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf (PID: 6267)File opened: /proc/27/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf (PID: 6267)File opened: /proc/28/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf (PID: 6267)File opened: /proc/29/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf (PID: 6267)File opened: /proc/491/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf (PID: 6267)File opened: /proc/250/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf (PID: 6267)File opened: /proc/130/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf (PID: 6267)File opened: /proc/251/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf (PID: 6267)File opened: /proc/252/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf (PID: 6267)File opened: /proc/132/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf (PID: 6267)File opened: /proc/253/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf (PID: 6267)File opened: /proc/254/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf (PID: 6267)File opened: /proc/255/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf (PID: 6267)File opened: /proc/256/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf (PID: 6267)File opened: /proc/1599/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf (PID: 6267)File opened: /proc/257/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf (PID: 6267)File opened: /proc/1477/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf (PID: 6267)File opened: /proc/379/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf (PID: 6267)File opened: /proc/258/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf (PID: 6267)File opened: /proc/1476/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf (PID: 6267)File opened: /proc/259/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf (PID: 6267)File opened: /proc/1475/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf (PID: 6267)File opened: /proc/6249/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf (PID: 6267)File opened: /proc/6248/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf (PID: 6267)File opened: /proc/936/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf (PID: 6267)File opened: /proc/30/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf (PID: 6267)File opened: /proc/2208/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf (PID: 6267)File opened: /proc/35/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf (PID: 6267)File opened: /proc/6267/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf (PID: 6267)File opened: /proc/1809/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf (PID: 6267)File opened: /proc/1494/statusJump to behavior
      Source: /usr/bin/dash (PID: 6288)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.F90B2oY7y7 /tmp/tmp.lRsNrXAb1n /tmp/tmp.LviB0ul97IJump to behavior
      Source: /usr/bin/dash (PID: 6289)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.F90B2oY7y7 /tmp/tmp.lRsNrXAb1n /tmp/tmp.LviB0ul97IJump to behavior
      Source: SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elfSubmission file: segment LOAD with 7.967 entropy (max. 8.0)
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf (PID: 6265)Queries kernel information via 'uname': Jump to behavior
      Source: SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf, 6265.1.0000557a92809000.0000557a92a17000.rw-.sdmp, SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf, 6269.1.0000557a92809000.0000557a92a17000.rw-.sdmpBinary or memory string: zU!/etc/qemu-binfmt/arm
      Source: SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf, 6265.1.00007fff384d3000.00007fff384f4000.rw-.sdmp, SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf, 6269.1.00007fff384d3000.00007fff384f4000.rw-.sdmpBinary or memory string: 8x86_64/usr/bin/qemu-arm/tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf
      Source: SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf, 6265.1.0000557a92809000.0000557a92a17000.rw-.sdmp, SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf, 6269.1.0000557a92809000.0000557a92a17000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/arm
      Source: SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf, 6265.1.00007fff384d3000.00007fff384f4000.rw-.sdmp, SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf, 6269.1.00007fff384d3000.00007fff384f4000.rw-.sdmpBinary or memory string: /usr/bin/qemu-arm

      Stealing of Sensitive Information

      barindex
      Source: Yara matchFile source: 6265.1.00007f2720017000.00007f272002d000.r-x.sdmp, type: MEMORY
      Source: Yara matchFile source: 6269.1.00007f2720017000.00007f272002d000.r-x.sdmp, type: MEMORY
      Source: Yara matchFile source: Process Memory Space: SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf PID: 6265, type: MEMORYSTR
      Source: Yara matchFile source: Process Memory Space: SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf PID: 6269, type: MEMORYSTR

      Remote Access Functionality

      barindex
      Source: Yara matchFile source: 6265.1.00007f2720017000.00007f272002d000.r-x.sdmp, type: MEMORY
      Source: Yara matchFile source: 6269.1.00007f2720017000.00007f272002d000.r-x.sdmp, type: MEMORY
      Source: Yara matchFile source: Process Memory Space: SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf PID: 6265, type: MEMORYSTR
      Source: Yara matchFile source: Process Memory Space: SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf PID: 6269, type: MEMORYSTR
      ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
      Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception11
      Obfuscated Files or Information
      1
      OS Credential Dumping
      11
      Security Software Discovery
      Remote ServicesData from Local System1
      Encrypted Channel
      Exfiltration Over Other Network MediumAbuse Accessibility Features
      CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
      File Deletion
      LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
      Non-Standard Port
      Exfiltration Over BluetoothNetwork Denial of Service
      Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
      Application Layer Protocol
      Automated ExfiltrationData Encrypted for Impact
      No configs have been found
      Hide Legend

      Legend:

      • Process
      • Signature
      • Created File
      • DNS/IP Info
      • Is Dropped
      • Number of created Files
      • Is malicious
      • Internet
      behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1502374 Sample: SecuriteInfo.com.Linux.Sigg... Startdate: 01/09/2024 Architecture: LINUX Score: 68 28 94.156.71.225, 3778, 45134, 45136 TERASYST-ASBG Bulgaria 2->28 30 109.202.202.202, 80 INIT7CH Switzerland 2->30 32 2 other IPs or domains 2->32 34 Malicious sample detected (through community Yara rule) 2->34 36 Multi AV Scanner detection for submitted file 2->36 38 Yara detected Mirai 2->38 40 Sample is packed with UPX 2->40 8 SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf 2->8         started        10 dash rm 2->10         started        12 dash rm 2->12         started        signatures3 process4 process5 14 SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf 8->14         started        16 SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf 8->16         started        18 SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf 8->18         started        process6 20 SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf 14->20         started        22 SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf 14->22         started        24 SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf 14->24         started        26 40 other processes 14->26
      SourceDetectionScannerLabelLink
      SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf34%ReversingLabsLinux.Trojan.Multiverze
      SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf23%VirustotalBrowse
      No Antivirus matches
      No Antivirus matches
      SourceDetectionScannerLabelLink
      http://upx.sf.net0%URL Reputationsafe
      http://upx.sf.net0%URL Reputationsafe
      No contacted domains info
      NameSourceMaliciousAntivirus DetectionReputation
      http://upx.sf.netSecuriteInfo.com.Linux.Siggen.9999.20705.30523.elftrue
      • URL Reputation: safe
      • URL Reputation: safe
      unknown
      • No. of IPs < 25%
      • 25% < No. of IPs < 50%
      • 50% < No. of IPs < 75%
      • 75% < No. of IPs
      IPDomainCountryFlagASNASN NameMalicious
      94.156.71.225
      unknownBulgaria
      31420TERASYST-ASBGfalse
      34.249.145.219
      unknownUnited States
      16509AMAZON-02USfalse
      109.202.202.202
      unknownSwitzerland
      13030INIT7CHfalse
      91.189.91.42
      unknownUnited Kingdom
      41231CANONICAL-ASGBfalse
      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
      94.156.71.225SecuriteInfo.com.Linux.Siggen.9999.18582.17843.elfGet hashmaliciousMiraiBrowse
        SecuriteInfo.com.Linux.Siggen.9999.127.12108.elfGet hashmaliciousMiraiBrowse
          SecuriteInfo.com.Linux.Siggen.9999.9304.22091.elfGet hashmaliciousMiraiBrowse
            SecuriteInfo.com.Linux.Siggen.9999.22319.26890.elfGet hashmaliciousMiraiBrowse
              34.249.145.219SecuriteInfo.com.Trojan.Linux.GenericKD.42965685.3102.14954.elfGet hashmaliciousUnknownBrowse
                hidakibest.mpsl.elfGet hashmaliciousGafgyt, MiraiBrowse
                  arm61.elfGet hashmaliciousGafgyt, MiraiBrowse
                    m68k.elfGet hashmaliciousGafgyt, MiraiBrowse
                      firmware.sparc.elfGet hashmaliciousUnknownBrowse
                        tppc.elfGet hashmaliciousUnknownBrowse
                          MDFZw2U0Ighb3bI9K2SX7ce4TvmxPbklXP.elfGet hashmaliciousUnknownBrowse
                            earm6.elfGet hashmaliciousUnknownBrowse
                              hoho.arc.elfGet hashmaliciousUnknownBrowse
                                arm4.elfGet hashmaliciousUnknownBrowse
                                  109.202.202.202kpLwzBouH4.elfGet hashmaliciousUnknownBrowse
                                  • ch.archive.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_92.0%2bbuild3-0ubuntu0.20.04.1_amd64.deb
                                  91.189.91.42SecuriteInfo.com.Linux.Siggen.9999.27011.25101.elfGet hashmaliciousMiraiBrowse
                                    bot.mpsl.elfGet hashmaliciousGafgyt, Mirai, OkiruBrowse
                                      bot.mips.elfGet hashmaliciousGafgyt, Mirai, OkiruBrowse
                                        bot.m68k.elfGet hashmaliciousGafgyt, Mirai, OkiruBrowse
                                          SecuriteInfo.com.Linux.Siggen.9999.22319.26890.elfGet hashmaliciousMiraiBrowse
                                            arm5.elfGet hashmaliciousUnknownBrowse
                                              SecuriteInfo.com.ELF.Mirai-CTV.23934.12709.elfGet hashmaliciousUnknownBrowse
                                                aisuru.arm7.elfGet hashmaliciousUnknownBrowse
                                                  botnt.arm7.elfGet hashmaliciousUnknownBrowse
                                                    SecuriteInfo.com.ELF.Agent-CMS.31992.20858.elfGet hashmaliciousUnknownBrowse
                                                      No context
                                                      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                      CANONICAL-ASGBSecuriteInfo.com.Linux.Siggen.9999.18582.17843.elfGet hashmaliciousMiraiBrowse
                                                      • 185.125.190.26
                                                      SecuriteInfo.com.Linux.Siggen.9999.9304.22091.elfGet hashmaliciousMiraiBrowse
                                                      • 185.125.190.26
                                                      SecuriteInfo.com.Linux.Siggen.9999.27011.25101.elfGet hashmaliciousMiraiBrowse
                                                      • 91.189.91.42
                                                      bot.mpsl.elfGet hashmaliciousGafgyt, Mirai, OkiruBrowse
                                                      • 91.189.91.42
                                                      bot.sh4.elfGet hashmaliciousGafgyt, Mirai, OkiruBrowse
                                                      • 185.125.190.26
                                                      bot.mips.elfGet hashmaliciousGafgyt, Mirai, OkiruBrowse
                                                      • 91.189.91.42
                                                      bot.m68k.elfGet hashmaliciousGafgyt, Mirai, OkiruBrowse
                                                      • 91.189.91.42
                                                      SecuriteInfo.com.Linux.Siggen.9999.22319.26890.elfGet hashmaliciousMiraiBrowse
                                                      • 91.189.91.42
                                                      arm5.elfGet hashmaliciousUnknownBrowse
                                                      • 91.189.91.42
                                                      SecuriteInfo.com.ELF.Mirai-CTV.23934.12709.elfGet hashmaliciousUnknownBrowse
                                                      • 91.189.91.42
                                                      TERASYST-ASBGSecuriteInfo.com.Linux.Siggen.9999.18582.17843.elfGet hashmaliciousMiraiBrowse
                                                      • 94.156.71.225
                                                      SecuriteInfo.com.Linux.Siggen.9999.127.12108.elfGet hashmaliciousMiraiBrowse
                                                      • 94.156.71.225
                                                      SecuriteInfo.com.Linux.Siggen.9999.9304.22091.elfGet hashmaliciousMiraiBrowse
                                                      • 94.156.71.225
                                                      SecuriteInfo.com.Linux.Siggen.9999.22319.26890.elfGet hashmaliciousMiraiBrowse
                                                      • 94.156.71.225
                                                      SecuriteInfo.com.ELF.Agent-CMS.31992.20858.elfGet hashmaliciousUnknownBrowse
                                                      • 94.156.69.214
                                                      6I8BO0tIYE.exeGet hashmaliciousSmokeLoaderBrowse
                                                      • 94.156.69.247
                                                      Customer-orderlist-Bestellung0940670009988208.exeGet hashmaliciousRedLineBrowse
                                                      • 94.156.65.203
                                                      best.x86.elfGet hashmaliciousUnknownBrowse
                                                      • 94.156.69.188
                                                      1724226243b9348f3b411af582580bd6a603a5ce20b028cbcc95a10a9590dca310f3191fd6655.dat-decoded.exeGet hashmaliciousRemcosBrowse
                                                      • 94.156.65.159
                                                      PurchaseOrder849393.vbsGet hashmaliciousRemcosBrowse
                                                      • 94.156.65.159
                                                      INIT7CHSecuriteInfo.com.Linux.Siggen.9999.27011.25101.elfGet hashmaliciousMiraiBrowse
                                                      • 109.202.202.202
                                                      bot.mpsl.elfGet hashmaliciousGafgyt, Mirai, OkiruBrowse
                                                      • 109.202.202.202
                                                      bot.mips.elfGet hashmaliciousGafgyt, Mirai, OkiruBrowse
                                                      • 109.202.202.202
                                                      bot.m68k.elfGet hashmaliciousGafgyt, Mirai, OkiruBrowse
                                                      • 109.202.202.202
                                                      SecuriteInfo.com.Linux.Siggen.9999.22319.26890.elfGet hashmaliciousMiraiBrowse
                                                      • 109.202.202.202
                                                      arm5.elfGet hashmaliciousUnknownBrowse
                                                      • 109.202.202.202
                                                      SecuriteInfo.com.ELF.Mirai-CTV.23934.12709.elfGet hashmaliciousUnknownBrowse
                                                      • 109.202.202.202
                                                      aisuru.arm7.elfGet hashmaliciousUnknownBrowse
                                                      • 109.202.202.202
                                                      botnt.arm7.elfGet hashmaliciousUnknownBrowse
                                                      • 109.202.202.202
                                                      SecuriteInfo.com.ELF.Agent-CMS.31992.20858.elfGet hashmaliciousUnknownBrowse
                                                      • 109.202.202.202
                                                      AMAZON-02UShttps://uppholldlgins.mystrikingly.com/Get hashmaliciousUnknownBrowse
                                                      • 52.84.150.39
                                                      http://juno-100505.weeblysite.com/Get hashmaliciousUnknownBrowse
                                                      • 54.201.194.161
                                                      http://telstra-105864.weeblysite.com/Get hashmaliciousHTMLPhisherBrowse
                                                      • 54.201.194.161
                                                      https://multicoinsystemnode.firebaseapp.com/Get hashmaliciousUnknownBrowse
                                                      • 108.156.60.80
                                                      https://66d29bf389fa9da58249d6b4--joyful-cupcake-4f3db5.netlify.app/Get hashmaliciousUnknownBrowse
                                                      • 52.58.254.253
                                                      http://att-108937.weeblysite.com/Get hashmaliciousUnknownBrowse
                                                      • 54.201.194.161
                                                      http://telstra-100127.weeblysite.com/Get hashmaliciousUnknownBrowse
                                                      • 54.201.194.161
                                                      http://telstra-104325.weeblysite.com/Get hashmaliciousHTMLPhisherBrowse
                                                      • 52.40.251.69
                                                      http://www.audentifydigital.com/Get hashmaliciousUnknownBrowse
                                                      • 52.222.201.15
                                                      https://66d2795a9886f088ed2f8c66--loquacious-pixie-9e563f.netlify.app/Get hashmaliciousUnknownBrowse
                                                      • 35.156.224.161
                                                      No context
                                                      No context
                                                      No created / dropped files found
                                                      File type:ELF 32-bit LSB executable, ARM, version 1 (ARM), statically linked, no section header
                                                      Entropy (8bit):7.9646664927376785
                                                      TrID:
                                                      • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                                                      File name:SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf
                                                      File size:37'464 bytes
                                                      MD5:aa169fa830cdf00b8611b0977dc2f162
                                                      SHA1:c0722ee6b87b245b7e6c9203c367ae052ddebff1
                                                      SHA256:78cfdc711effbe746fdd0e197963294b5c70fad50b28ab3e8a6adece80ced177
                                                      SHA512:dd8ff759a638da0adc3931a11964f01e86a323875b9cc70f5bbab96607dbe6153db2f4e8f020ae8e0cc3b26448a128ce8e272755a51b9b3e99da59378668f61d
                                                      SSDEEP:768:UtjunoxdhVlNVZ+OXK6ixemZPE332y4SBr1CGUDbbxHZ/3OA9fas3Uoz2h5:gPVlNVgOEIYcH2y4eZCGm5B39BXz2b
                                                      TLSH:18F2E15A71D7BE68C4A04C70AE794303269A2F6C81F93B6F31644BAFD287D46FB30591
                                                      File Content Preview:.ELF...a..........(.........4...........4. ...(.....................G...G...........................................Q.td............................s.y.UPX!........L[..L[......S..........?.E.h;.}...^..........f.7.......l.v#..l.Y.d.R....T..l....q.;..-Nn..<

                                                      ELF header

                                                      Class:ELF32
                                                      Data:2's complement, little endian
                                                      Version:1 (current)
                                                      Machine:ARM
                                                      Version Number:0x1
                                                      Type:EXEC (Executable file)
                                                      OS/ABI:ARM - ABI
                                                      ABI Version:0
                                                      Entry Point Address:0xff98
                                                      Flags:0x202
                                                      ELF Header Size:52
                                                      Program Header Offset:52
                                                      Program Header Size:32
                                                      Number of Program Headers:3
                                                      Section Header Offset:0
                                                      Section Header Size:40
                                                      Number of Section Headers:0
                                                      Header String Table Index:0
                                                      TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                      LOAD0x00x80000x80000x91470x91477.96700x5R E0x8000
                                                      LOAD0x7f800x27f800x27f800x00x00.00000x6RW 0x8000
                                                      GNU_STACK0x00x00x00x00x00.00000x7RWE0x4
                                                      TimestampSource PortDest PortSource IPDest IP
                                                      Sep 1, 2024 01:55:06.884608984 CEST451343778192.168.2.2394.156.71.225
                                                      Sep 1, 2024 01:55:06.889607906 CEST37784513494.156.71.225192.168.2.23
                                                      Sep 1, 2024 01:55:06.889659882 CEST451343778192.168.2.2394.156.71.225
                                                      Sep 1, 2024 01:55:06.906774998 CEST451343778192.168.2.2394.156.71.225
                                                      Sep 1, 2024 01:55:06.911566973 CEST37784513494.156.71.225192.168.2.23
                                                      Sep 1, 2024 01:55:06.911606073 CEST451343778192.168.2.2394.156.71.225
                                                      Sep 1, 2024 01:55:06.916373968 CEST37784513494.156.71.225192.168.2.23
                                                      Sep 1, 2024 01:55:08.096553087 CEST37784513494.156.71.225192.168.2.23
                                                      Sep 1, 2024 01:55:08.096568108 CEST37784513494.156.71.225192.168.2.23
                                                      Sep 1, 2024 01:55:08.096573114 CEST37784513494.156.71.225192.168.2.23
                                                      Sep 1, 2024 01:55:08.096617937 CEST37784513494.156.71.225192.168.2.23
                                                      Sep 1, 2024 01:55:08.096772909 CEST451343778192.168.2.2394.156.71.225
                                                      Sep 1, 2024 01:55:08.096774101 CEST451343778192.168.2.2394.156.71.225
                                                      Sep 1, 2024 01:55:08.096774101 CEST451343778192.168.2.2394.156.71.225
                                                      Sep 1, 2024 01:55:08.096774101 CEST451343778192.168.2.2394.156.71.225
                                                      Sep 1, 2024 01:55:08.096904039 CEST451343778192.168.2.2394.156.71.225
                                                      Sep 1, 2024 01:55:08.097417116 CEST451363778192.168.2.2394.156.71.225
                                                      Sep 1, 2024 01:55:08.102159023 CEST37784513694.156.71.225192.168.2.23
                                                      Sep 1, 2024 01:55:08.102240086 CEST451363778192.168.2.2394.156.71.225
                                                      Sep 1, 2024 01:55:08.103117943 CEST451363778192.168.2.2394.156.71.225
                                                      Sep 1, 2024 01:55:08.107852936 CEST37784513694.156.71.225192.168.2.23
                                                      Sep 1, 2024 01:55:08.107908964 CEST451363778192.168.2.2394.156.71.225
                                                      Sep 1, 2024 01:55:08.112679958 CEST37784513694.156.71.225192.168.2.23
                                                      Sep 1, 2024 01:55:08.696407080 CEST37784513694.156.71.225192.168.2.23
                                                      Sep 1, 2024 01:55:08.696630001 CEST451363778192.168.2.2394.156.71.225
                                                      Sep 1, 2024 01:55:08.696630001 CEST451363778192.168.2.2394.156.71.225
                                                      Sep 1, 2024 01:55:08.697148085 CEST451383778192.168.2.2394.156.71.225
                                                      Sep 1, 2024 01:55:08.703490019 CEST37784513894.156.71.225192.168.2.23
                                                      Sep 1, 2024 01:55:08.703546047 CEST451383778192.168.2.2394.156.71.225
                                                      Sep 1, 2024 01:55:08.704240084 CEST451383778192.168.2.2394.156.71.225
                                                      Sep 1, 2024 01:55:08.710761070 CEST37784513894.156.71.225192.168.2.23
                                                      Sep 1, 2024 01:55:08.710800886 CEST451383778192.168.2.2394.156.71.225
                                                      Sep 1, 2024 01:55:08.717227936 CEST37784513894.156.71.225192.168.2.23
                                                      Sep 1, 2024 01:55:09.426282883 CEST43928443192.168.2.2391.189.91.42
                                                      Sep 1, 2024 01:55:10.312026978 CEST37784513894.156.71.225192.168.2.23
                                                      Sep 1, 2024 01:55:10.312153101 CEST451383778192.168.2.2394.156.71.225
                                                      Sep 1, 2024 01:55:10.312175989 CEST451383778192.168.2.2394.156.71.225
                                                      Sep 1, 2024 01:55:10.312733889 CEST451403778192.168.2.2394.156.71.225
                                                      Sep 1, 2024 01:55:10.318733931 CEST37784514094.156.71.225192.168.2.23
                                                      Sep 1, 2024 01:55:10.318783998 CEST451403778192.168.2.2394.156.71.225
                                                      Sep 1, 2024 01:55:10.319511890 CEST451403778192.168.2.2394.156.71.225
                                                      Sep 1, 2024 01:55:10.325227022 CEST37784514094.156.71.225192.168.2.23
                                                      Sep 1, 2024 01:55:10.325269938 CEST451403778192.168.2.2394.156.71.225
                                                      Sep 1, 2024 01:55:10.330168009 CEST37784514094.156.71.225192.168.2.23
                                                      Sep 1, 2024 01:55:20.327632904 CEST451403778192.168.2.2394.156.71.225
                                                      Sep 1, 2024 01:55:20.332570076 CEST37784514094.156.71.225192.168.2.23
                                                      Sep 1, 2024 01:55:20.498927116 CEST37784514094.156.71.225192.168.2.23
                                                      Sep 1, 2024 01:55:20.499042034 CEST451403778192.168.2.2394.156.71.225
                                                      Sep 1, 2024 01:55:24.885976076 CEST4433925634.249.145.219192.168.2.23
                                                      Sep 1, 2024 01:55:24.886241913 CEST39256443192.168.2.2334.249.145.219
                                                      Sep 1, 2024 01:55:24.891912937 CEST4433925634.249.145.219192.168.2.23
                                                      Sep 1, 2024 01:55:29.135365963 CEST4251680192.168.2.23109.202.202.202
                                                      Sep 1, 2024 01:55:31.183121920 CEST43928443192.168.2.2391.189.91.42
                                                      Sep 1, 2024 01:56:12.137506962 CEST43928443192.168.2.2391.189.91.42
                                                      Sep 1, 2024 01:56:20.551367998 CEST451403778192.168.2.2394.156.71.225
                                                      Sep 1, 2024 01:56:20.556265116 CEST37784514094.156.71.225192.168.2.23
                                                      Sep 1, 2024 01:56:20.722624063 CEST37784514094.156.71.225192.168.2.23
                                                      Sep 1, 2024 01:56:20.722676039 CEST451403778192.168.2.2394.156.71.225
                                                      Sep 1, 2024 01:57:20.769979000 CEST451403778192.168.2.2394.156.71.225
                                                      Sep 1, 2024 01:57:20.774924994 CEST37784514094.156.71.225192.168.2.23
                                                      Sep 1, 2024 01:57:21.232775927 CEST37784514094.156.71.225192.168.2.23
                                                      Sep 1, 2024 01:57:21.232888937 CEST451403778192.168.2.2394.156.71.225
                                                      Sep 1, 2024 01:58:21.283598900 CEST451403778192.168.2.2394.156.71.225
                                                      Sep 1, 2024 01:58:21.288489103 CEST37784514094.156.71.225192.168.2.23
                                                      Sep 1, 2024 01:58:21.503745079 CEST37784514094.156.71.225192.168.2.23
                                                      Sep 1, 2024 01:58:21.503917933 CEST451403778192.168.2.2394.156.71.225

                                                      System Behavior

                                                      Start time (UTC):23:55:05
                                                      Start date (UTC):31/08/2024
                                                      Path:/tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf
                                                      Arguments:/tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf
                                                      File size:4956856 bytes
                                                      MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                      Start time (UTC):23:55:05
                                                      Start date (UTC):31/08/2024
                                                      Path:/tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf
                                                      Arguments:-
                                                      File size:4956856 bytes
                                                      MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                      Start time (UTC):23:55:05
                                                      Start date (UTC):31/08/2024
                                                      Path:/tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf
                                                      Arguments:-
                                                      File size:4956856 bytes
                                                      MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                      Start time (UTC):23:55:11
                                                      Start date (UTC):31/08/2024
                                                      Path:/tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf
                                                      Arguments:-
                                                      File size:4956856 bytes
                                                      MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                      Start time (UTC):23:55:16
                                                      Start date (UTC):31/08/2024
                                                      Path:/tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf
                                                      Arguments:-
                                                      File size:4956856 bytes
                                                      MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                      Start time (UTC):23:55:22
                                                      Start date (UTC):31/08/2024
                                                      Path:/tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf
                                                      Arguments:-
                                                      File size:4956856 bytes
                                                      MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                      Start time (UTC):23:55:27
                                                      Start date (UTC):31/08/2024
                                                      Path:/tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf
                                                      Arguments:-
                                                      File size:4956856 bytes
                                                      MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                      Start time (UTC):23:55:33
                                                      Start date (UTC):31/08/2024
                                                      Path:/tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf
                                                      Arguments:-
                                                      File size:4956856 bytes
                                                      MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                      Start time (UTC):23:55:38
                                                      Start date (UTC):31/08/2024
                                                      Path:/tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf
                                                      Arguments:-
                                                      File size:4956856 bytes
                                                      MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                      Start time (UTC):23:55:43
                                                      Start date (UTC):31/08/2024
                                                      Path:/tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf
                                                      Arguments:-
                                                      File size:4956856 bytes
                                                      MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                      Start time (UTC):23:55:48
                                                      Start date (UTC):31/08/2024
                                                      Path:/tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf
                                                      Arguments:-
                                                      File size:4956856 bytes
                                                      MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                      Start time (UTC):23:55:53
                                                      Start date (UTC):31/08/2024
                                                      Path:/tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf
                                                      Arguments:-
                                                      File size:4956856 bytes
                                                      MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                      Start time (UTC):23:55:58
                                                      Start date (UTC):31/08/2024
                                                      Path:/tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf
                                                      Arguments:-
                                                      File size:4956856 bytes
                                                      MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                      Start time (UTC):23:56:03
                                                      Start date (UTC):31/08/2024
                                                      Path:/tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf
                                                      Arguments:-
                                                      File size:4956856 bytes
                                                      MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                      Start time (UTC):23:56:08
                                                      Start date (UTC):31/08/2024
                                                      Path:/tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf
                                                      Arguments:-
                                                      File size:4956856 bytes
                                                      MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                      Start time (UTC):23:56:13
                                                      Start date (UTC):31/08/2024
                                                      Path:/tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf
                                                      Arguments:-
                                                      File size:4956856 bytes
                                                      MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                      Start time (UTC):23:56:18
                                                      Start date (UTC):31/08/2024
                                                      Path:/tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf
                                                      Arguments:-
                                                      File size:4956856 bytes
                                                      MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                      Start time (UTC):23:56:24
                                                      Start date (UTC):31/08/2024
                                                      Path:/tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf
                                                      Arguments:-
                                                      File size:4956856 bytes
                                                      MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                      Start time (UTC):23:56:29
                                                      Start date (UTC):31/08/2024
                                                      Path:/tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf
                                                      Arguments:-
                                                      File size:4956856 bytes
                                                      MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                      Start time (UTC):23:56:34
                                                      Start date (UTC):31/08/2024
                                                      Path:/tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf
                                                      Arguments:-
                                                      File size:4956856 bytes
                                                      MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                      Start time (UTC):23:56:39
                                                      Start date (UTC):31/08/2024
                                                      Path:/tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf
                                                      Arguments:-
                                                      File size:4956856 bytes
                                                      MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                      Start time (UTC):23:56:44
                                                      Start date (UTC):31/08/2024
                                                      Path:/tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf
                                                      Arguments:-
                                                      File size:4956856 bytes
                                                      MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                      Start time (UTC):23:56:49
                                                      Start date (UTC):31/08/2024
                                                      Path:/tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf
                                                      Arguments:-
                                                      File size:4956856 bytes
                                                      MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                      Start time (UTC):23:56:54
                                                      Start date (UTC):31/08/2024
                                                      Path:/tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf
                                                      Arguments:-
                                                      File size:4956856 bytes
                                                      MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                      Start time (UTC):23:56:59
                                                      Start date (UTC):31/08/2024
                                                      Path:/tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf
                                                      Arguments:-
                                                      File size:4956856 bytes
                                                      MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                      Start time (UTC):23:57:04
                                                      Start date (UTC):31/08/2024
                                                      Path:/tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf
                                                      Arguments:-
                                                      File size:4956856 bytes
                                                      MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                      Start time (UTC):23:57:09
                                                      Start date (UTC):31/08/2024
                                                      Path:/tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf
                                                      Arguments:-
                                                      File size:4956856 bytes
                                                      MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                      Start time (UTC):23:57:14
                                                      Start date (UTC):31/08/2024
                                                      Path:/tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf
                                                      Arguments:-
                                                      File size:4956856 bytes
                                                      MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                      Start time (UTC):23:57:19
                                                      Start date (UTC):31/08/2024
                                                      Path:/tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf
                                                      Arguments:-
                                                      File size:4956856 bytes
                                                      MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                      Start time (UTC):23:57:24
                                                      Start date (UTC):31/08/2024
                                                      Path:/tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf
                                                      Arguments:-
                                                      File size:4956856 bytes
                                                      MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                      Start time (UTC):23:57:29
                                                      Start date (UTC):31/08/2024
                                                      Path:/tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf
                                                      Arguments:-
                                                      File size:4956856 bytes
                                                      MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                      Start time (UTC):23:57:34
                                                      Start date (UTC):31/08/2024
                                                      Path:/tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf
                                                      Arguments:-
                                                      File size:4956856 bytes
                                                      MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                      Start time (UTC):23:57:39
                                                      Start date (UTC):31/08/2024
                                                      Path:/tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf
                                                      Arguments:-
                                                      File size:4956856 bytes
                                                      MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                      Start time (UTC):23:57:44
                                                      Start date (UTC):31/08/2024
                                                      Path:/tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf
                                                      Arguments:-
                                                      File size:4956856 bytes
                                                      MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                      Start time (UTC):23:57:49
                                                      Start date (UTC):31/08/2024
                                                      Path:/tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf
                                                      Arguments:-
                                                      File size:4956856 bytes
                                                      MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                      Start time (UTC):23:57:54
                                                      Start date (UTC):31/08/2024
                                                      Path:/tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf
                                                      Arguments:-
                                                      File size:4956856 bytes
                                                      MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                      Start time (UTC):23:57:59
                                                      Start date (UTC):31/08/2024
                                                      Path:/tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf
                                                      Arguments:-
                                                      File size:4956856 bytes
                                                      MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                      Start time (UTC):23:58:04
                                                      Start date (UTC):31/08/2024
                                                      Path:/tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf
                                                      Arguments:-
                                                      File size:4956856 bytes
                                                      MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                      Start time (UTC):23:58:09
                                                      Start date (UTC):31/08/2024
                                                      Path:/tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf
                                                      Arguments:-
                                                      File size:4956856 bytes
                                                      MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                      Start time (UTC):23:58:14
                                                      Start date (UTC):31/08/2024
                                                      Path:/tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf
                                                      Arguments:-
                                                      File size:4956856 bytes
                                                      MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                      Start time (UTC):23:58:19
                                                      Start date (UTC):31/08/2024
                                                      Path:/tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf
                                                      Arguments:-
                                                      File size:4956856 bytes
                                                      MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                      Start time (UTC):23:58:24
                                                      Start date (UTC):31/08/2024
                                                      Path:/tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf
                                                      Arguments:-
                                                      File size:4956856 bytes
                                                      MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                      Start time (UTC):23:58:30
                                                      Start date (UTC):31/08/2024
                                                      Path:/tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf
                                                      Arguments:-
                                                      File size:4956856 bytes
                                                      MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                      Start time (UTC):23:58:35
                                                      Start date (UTC):31/08/2024
                                                      Path:/tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf
                                                      Arguments:-
                                                      File size:4956856 bytes
                                                      MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                      Start time (UTC):23:58:40
                                                      Start date (UTC):31/08/2024
                                                      Path:/tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf
                                                      Arguments:-
                                                      File size:4956856 bytes
                                                      MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                      Start time (UTC):23:55:05
                                                      Start date (UTC):31/08/2024
                                                      Path:/tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf
                                                      Arguments:-
                                                      File size:4956856 bytes
                                                      MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                      Start time (UTC):23:55:05
                                                      Start date (UTC):31/08/2024
                                                      Path:/tmp/SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elf
                                                      Arguments:-
                                                      File size:4956856 bytes
                                                      MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                      Start time (UTC):23:55:23
                                                      Start date (UTC):31/08/2024
                                                      Path:/usr/bin/dash
                                                      Arguments:-
                                                      File size:129816 bytes
                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                      Start time (UTC):23:55:23
                                                      Start date (UTC):31/08/2024
                                                      Path:/usr/bin/rm
                                                      Arguments:rm -f /tmp/tmp.F90B2oY7y7 /tmp/tmp.lRsNrXAb1n /tmp/tmp.LviB0ul97I
                                                      File size:72056 bytes
                                                      MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b

                                                      Start time (UTC):23:55:23
                                                      Start date (UTC):31/08/2024
                                                      Path:/usr/bin/dash
                                                      Arguments:-
                                                      File size:129816 bytes
                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                      Start time (UTC):23:55:23
                                                      Start date (UTC):31/08/2024
                                                      Path:/usr/bin/rm
                                                      Arguments:rm -f /tmp/tmp.F90B2oY7y7 /tmp/tmp.lRsNrXAb1n /tmp/tmp.LviB0ul97I
                                                      File size:72056 bytes
                                                      MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b