Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf

Overview

General Information

Sample name:SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf
Analysis ID:1502375
MD5:d209dadd662918c0360d992f693a4c88
SHA1:ff29a4cb9d0d2a4ad7e15f7523bdc5d5d681f990
SHA256:f461632cc61eaa9bcf7deb5dba0ca986c5ea65fb366fae6d329cee5458abd07d
Tags:elf
Infos:

Detection

Mirai
Score:68
Range:0 - 100
Whitelisted:false

Signatures

Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Yara detected Mirai
Sample is packed with UPX
Detected TCP or UDP traffic on non-standard ports
ELF contains segments with high entropy indicating compressed/encrypted content
Enumerates processes within the "proc" file system
Sample contains only a LOAD segment without any section mappings
Uses the "uname" system call to query kernel version information (possible evasion)
Yara signature match

Classification

Joe Sandbox version:40.0.0 Tourmaline
Analysis ID:1502375
Start date and time:2024-09-01 01:54:30 +02:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 5m 12s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf
Detection:MAL
Classification:mal68.troj.evad.linELF@0/0@2/0
Command:/tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf
PID:5480
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
lzrd cock fest"/proc/"/exe
Standard Error:
  • system is lnxubuntu20
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
MiraiMirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese. Nowadays it targets a wide range of networked embedded devices such as IP cameras, home routers (many vendors involved), and other IoT devices. Since the source code was published on "Hack Forums" many variants of the Mirai family appeared, infecting mostly home networks all around the world.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/elf.mirai
SourceRuleDescriptionAuthorStrings
5485.1.00007efbf4400000.00007efbf442d000.r-x.sdmpJoeSecurity_Mirai_8Yara detected MiraiJoe Security
    5485.1.00007efbf4400000.00007efbf442d000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
    • 0x2ab30:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x2ab44:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x2ab58:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x2ab6c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x2ab80:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x2ab94:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x2aba8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x2abbc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x2abd0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x2abe4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x2abf8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x2ac0c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x2ac20:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x2ac34:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x2ac48:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x2ac5c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x2ac70:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x2ac84:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x2ac98:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x2acac:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x2acc0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    5485.1.00007efbf4400000.00007efbf442d000.r-x.sdmpLinux_Trojan_Gafgyt_ea92cca8unknownunknown
    • 0x2b088:$a: 53 65 6C 66 20 52 65 70 20 46 75 63 6B 69 6E 67 20 4E 65 54 69 53 20 61 6E 64
    5480.1.00007efbf4400000.00007efbf442d000.r-x.sdmpJoeSecurity_Mirai_8Yara detected MiraiJoe Security
      5480.1.00007efbf4400000.00007efbf442d000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
      • 0x2ab30:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x2ab44:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x2ab58:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x2ab6c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x2ab80:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x2ab94:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x2aba8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x2abbc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x2abd0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x2abe4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x2abf8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x2ac0c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x2ac20:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x2ac34:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x2ac48:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x2ac5c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x2ac70:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x2ac84:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x2ac98:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x2acac:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x2acc0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      Click to see the 5 entries
      No Suricata rule has matched

      Click to jump to signature section

      Show All Signature Results

      AV Detection

      barindex
      Source: SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elfReversingLabs: Detection: 31%
      Source: SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elfVirustotal: Detection: 22%Perma Link
      Source: global trafficTCP traffic: 192.168.2.13:40424 -> 94.156.71.225:3778
      Source: unknownTCP traffic detected without corresponding DNS query: 94.156.71.225
      Source: unknownTCP traffic detected without corresponding DNS query: 94.156.71.225
      Source: unknownTCP traffic detected without corresponding DNS query: 94.156.71.225
      Source: unknownTCP traffic detected without corresponding DNS query: 94.156.71.225
      Source: unknownTCP traffic detected without corresponding DNS query: 94.156.71.225
      Source: unknownTCP traffic detected without corresponding DNS query: 94.156.71.225
      Source: unknownTCP traffic detected without corresponding DNS query: 94.156.71.225
      Source: unknownTCP traffic detected without corresponding DNS query: 94.156.71.225
      Source: unknownTCP traffic detected without corresponding DNS query: 94.156.71.225
      Source: unknownTCP traffic detected without corresponding DNS query: 94.156.71.225
      Source: unknownTCP traffic detected without corresponding DNS query: 94.156.71.225
      Source: unknownTCP traffic detected without corresponding DNS query: 94.156.71.225
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: global trafficDNS traffic detected: DNS query: daisy.ubuntu.com
      Source: SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elfString found in binary or memory: http://upx.sf.net

      System Summary

      barindex
      Source: 5485.1.00007efbf4400000.00007efbf442d000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
      Source: 5485.1.00007efbf4400000.00007efbf442d000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown
      Source: 5480.1.00007efbf4400000.00007efbf442d000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
      Source: 5480.1.00007efbf4400000.00007efbf442d000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown
      Source: Process Memory Space: SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf PID: 5480, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
      Source: Process Memory Space: SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf PID: 5480, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown
      Source: Process Memory Space: SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf PID: 5485, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
      Source: LOAD without section mappingsProgram segment: 0x100000
      Source: 5485.1.00007efbf4400000.00007efbf442d000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
      Source: 5485.1.00007efbf4400000.00007efbf442d000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16
      Source: 5480.1.00007efbf4400000.00007efbf442d000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
      Source: 5480.1.00007efbf4400000.00007efbf442d000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16
      Source: Process Memory Space: SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf PID: 5480, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
      Source: Process Memory Space: SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf PID: 5480, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16
      Source: Process Memory Space: SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf PID: 5485, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
      Source: classification engineClassification label: mal68.troj.evad.linELF@0/0@2/0

      Data Obfuscation

      barindex
      Source: initial sampleString containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $
      Source: initial sampleString containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $
      Source: initial sampleString containing UPX found: $Id: UPX 3.94 Copyright (C) 1996-2017 the UPX Team. All Rights Reserved. $
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf (PID: 5483)File opened: /proc/230/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf (PID: 5483)File opened: /proc/110/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf (PID: 5483)File opened: /proc/231/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf (PID: 5483)File opened: /proc/3638/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf (PID: 5483)File opened: /proc/111/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf (PID: 5483)File opened: /proc/232/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf (PID: 5483)File opened: /proc/112/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf (PID: 5483)File opened: /proc/233/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf (PID: 5483)File opened: /proc/113/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf (PID: 5483)File opened: /proc/234/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf (PID: 5483)File opened: /proc/114/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf (PID: 5483)File opened: /proc/235/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf (PID: 5483)File opened: /proc/115/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf (PID: 5483)File opened: /proc/236/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf (PID: 5483)File opened: /proc/116/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf (PID: 5483)File opened: /proc/237/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf (PID: 5483)File opened: /proc/117/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf (PID: 5483)File opened: /proc/238/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf (PID: 5483)File opened: /proc/118/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf (PID: 5483)File opened: /proc/239/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf (PID: 5483)File opened: /proc/119/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf (PID: 5483)File opened: /proc/3752/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf (PID: 5483)File opened: /proc/914/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf (PID: 5483)File opened: /proc/10/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf (PID: 5483)File opened: /proc/917/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf (PID: 5483)File opened: /proc/11/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf (PID: 5483)File opened: /proc/12/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf (PID: 5483)File opened: /proc/13/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf (PID: 5483)File opened: /proc/14/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf (PID: 5483)File opened: /proc/15/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf (PID: 5483)File opened: /proc/16/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf (PID: 5483)File opened: /proc/17/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf (PID: 5483)File opened: /proc/18/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf (PID: 5483)File opened: /proc/19/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf (PID: 5483)File opened: /proc/240/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf (PID: 5483)File opened: /proc/3095/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf (PID: 5483)File opened: /proc/120/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf (PID: 5483)File opened: /proc/241/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf (PID: 5483)File opened: /proc/121/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf (PID: 5483)File opened: /proc/242/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf (PID: 5483)File opened: /proc/1/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf (PID: 5483)File opened: /proc/122/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf (PID: 5483)File opened: /proc/243/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf (PID: 5483)File opened: /proc/2/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf (PID: 5483)File opened: /proc/123/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf (PID: 5483)File opened: /proc/244/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf (PID: 5483)File opened: /proc/3/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf (PID: 5483)File opened: /proc/124/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf (PID: 5483)File opened: /proc/245/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf (PID: 5483)File opened: /proc/1588/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf (PID: 5483)File opened: /proc/125/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf (PID: 5483)File opened: /proc/4/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf (PID: 5483)File opened: /proc/246/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf (PID: 5483)File opened: /proc/126/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf (PID: 5483)File opened: /proc/5/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf (PID: 5483)File opened: /proc/247/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf (PID: 5483)File opened: /proc/127/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf (PID: 5483)File opened: /proc/6/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf (PID: 5483)File opened: /proc/248/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf (PID: 5483)File opened: /proc/128/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf (PID: 5483)File opened: /proc/7/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf (PID: 5483)File opened: /proc/249/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf (PID: 5483)File opened: /proc/129/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf (PID: 5483)File opened: /proc/8/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf (PID: 5483)File opened: /proc/800/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf (PID: 5483)File opened: /proc/9/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf (PID: 5483)File opened: /proc/1906/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf (PID: 5483)File opened: /proc/802/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf (PID: 5483)File opened: /proc/803/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf (PID: 5483)File opened: /proc/20/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf (PID: 5483)File opened: /proc/21/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf (PID: 5483)File opened: /proc/22/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf (PID: 5483)File opened: /proc/23/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf (PID: 5483)File opened: /proc/24/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf (PID: 5483)File opened: /proc/25/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf (PID: 5483)File opened: /proc/26/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf (PID: 5483)File opened: /proc/27/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf (PID: 5483)File opened: /proc/28/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf (PID: 5483)File opened: /proc/29/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf (PID: 5483)File opened: /proc/3420/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf (PID: 5483)File opened: /proc/1482/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf (PID: 5483)File opened: /proc/490/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf (PID: 5483)File opened: /proc/1480/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf (PID: 5483)File opened: /proc/250/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf (PID: 5483)File opened: /proc/371/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf (PID: 5483)File opened: /proc/130/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf (PID: 5483)File opened: /proc/251/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf (PID: 5483)File opened: /proc/131/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf (PID: 5483)File opened: /proc/252/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf (PID: 5483)File opened: /proc/132/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf (PID: 5483)File opened: /proc/253/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf (PID: 5483)File opened: /proc/254/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf (PID: 5483)File opened: /proc/1238/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf (PID: 5483)File opened: /proc/134/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf (PID: 5483)File opened: /proc/255/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf (PID: 5483)File opened: /proc/256/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf (PID: 5483)File opened: /proc/257/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf (PID: 5483)File opened: /proc/378/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf (PID: 5483)File opened: /proc/3413/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf (PID: 5483)File opened: /proc/258/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf (PID: 5483)File opened: /proc/259/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf (PID: 5483)File opened: /proc/1475/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf (PID: 5483)File opened: /proc/936/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf (PID: 5483)File opened: /proc/30/statusJump to behavior
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf (PID: 5483)File opened: /proc/816/statusJump to behavior
      Source: SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elfSubmission file: segment LOAD with 7.9413 entropy (max. 8.0)
      Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf (PID: 5480)Queries kernel information via 'uname': Jump to behavior
      Source: SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf, 5480.1.000055e13c978000.000055e13ca20000.rw-.sdmp, SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf, 5485.1.000055e13c978000.000055e13ca20000.rw-.sdmpBinary or memory string: U!/etc/qemu-binfmt/mips
      Source: SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf, 5480.1.000055e13c978000.000055e13ca20000.rw-.sdmp, SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf, 5485.1.000055e13c978000.000055e13ca20000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/mips
      Source: SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf, 5480.1.00007fff18fc5000.00007fff18fe6000.rw-.sdmp, SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf, 5485.1.00007fff18fc5000.00007fff18fe6000.rw-.sdmpBinary or memory string: /usr/bin/qemu-mips
      Source: SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf, 5480.1.00007fff18fc5000.00007fff18fe6000.rw-.sdmp, SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf, 5485.1.00007fff18fc5000.00007fff18fe6000.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-mips/tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf

      Stealing of Sensitive Information

      barindex
      Source: Yara matchFile source: 5485.1.00007efbf4400000.00007efbf442d000.r-x.sdmp, type: MEMORY
      Source: Yara matchFile source: 5480.1.00007efbf4400000.00007efbf442d000.r-x.sdmp, type: MEMORY
      Source: Yara matchFile source: Process Memory Space: SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf PID: 5480, type: MEMORYSTR

      Remote Access Functionality

      barindex
      Source: Yara matchFile source: 5485.1.00007efbf4400000.00007efbf442d000.r-x.sdmp, type: MEMORY
      Source: Yara matchFile source: 5480.1.00007efbf4400000.00007efbf442d000.r-x.sdmp, type: MEMORY
      Source: Yara matchFile source: Process Memory Space: SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf PID: 5480, type: MEMORYSTR
      ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
      Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception11
      Obfuscated Files or Information
      1
      OS Credential Dumping
      11
      Security Software Discovery
      Remote ServicesData from Local System1
      Non-Standard Port
      Exfiltration Over Other Network MediumAbuse Accessibility Features
      CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
      Non-Application Layer Protocol
      Exfiltration Over BluetoothNetwork Denial of Service
      Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
      Application Layer Protocol
      Automated ExfiltrationData Encrypted for Impact
      No configs have been found
      Hide Legend

      Legend:

      • Process
      • Signature
      • Created File
      • DNS/IP Info
      • Is Dropped
      • Number of created Files
      • Is malicious
      • Internet
      SourceDetectionScannerLabelLink
      SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf32%ReversingLabsLinux.Trojan.Multiverze
      SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf23%VirustotalBrowse
      No Antivirus matches
      SourceDetectionScannerLabelLink
      daisy.ubuntu.com0%VirustotalBrowse
      SourceDetectionScannerLabelLink
      http://upx.sf.net0%URL Reputationsafe
      http://upx.sf.net0%URL Reputationsafe
      NameIPActiveMaliciousAntivirus DetectionReputation
      daisy.ubuntu.com
      162.213.35.25
      truefalseunknown
      NameSourceMaliciousAntivirus DetectionReputation
      http://upx.sf.netSecuriteInfo.com.Linux.Siggen.9999.5622.5080.elftrue
      • URL Reputation: safe
      • URL Reputation: safe
      unknown
      • No. of IPs < 25%
      • 25% < No. of IPs < 50%
      • 50% < No. of IPs < 75%
      • 75% < No. of IPs
      IPDomainCountryFlagASNASN NameMalicious
      94.156.71.225
      unknownBulgaria
      31420TERASYST-ASBGfalse
      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
      94.156.71.225SecuriteInfo.com.Linux.Siggen.9999.20705.30523.elfGet hashmaliciousMiraiBrowse
        SecuriteInfo.com.Linux.Siggen.9999.18582.17843.elfGet hashmaliciousMiraiBrowse
          SecuriteInfo.com.Linux.Siggen.9999.127.12108.elfGet hashmaliciousMiraiBrowse
            SecuriteInfo.com.Linux.Siggen.9999.9304.22091.elfGet hashmaliciousMiraiBrowse
              SecuriteInfo.com.Linux.Siggen.9999.22319.26890.elfGet hashmaliciousMiraiBrowse
                MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                daisy.ubuntu.comSecuriteInfo.com.Linux.Siggen.9999.18582.17843.elfGet hashmaliciousMiraiBrowse
                • 162.213.35.25
                SecuriteInfo.com.Linux.Siggen.9999.127.12108.elfGet hashmaliciousMiraiBrowse
                • 162.213.35.25
                SecuriteInfo.com.Linux.Siggen.9999.9304.22091.elfGet hashmaliciousMiraiBrowse
                • 162.213.35.25
                bot.arm6.elfGet hashmaliciousMirai, OkiruBrowse
                • 162.213.35.25
                SecuriteInfo.com.Linux.Siggen.9999.20093.10545.elfGet hashmaliciousMiraiBrowse
                • 162.213.35.24
                SecuriteInfo.com.ELF.Flooder-TB.29079.9826.elfGet hashmaliciousUnknownBrowse
                • 162.213.35.25
                sora.arm7.elfGet hashmaliciousMiraiBrowse
                • 162.213.35.25
                sora.m68k.elfGet hashmaliciousMiraiBrowse
                • 162.213.35.25
                sora.ppc.elfGet hashmaliciousUnknownBrowse
                • 162.213.35.25
                sora.sh4.elfGet hashmaliciousMiraiBrowse
                • 162.213.35.25
                MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                TERASYST-ASBGSecuriteInfo.com.Linux.Siggen.9999.20705.30523.elfGet hashmaliciousMiraiBrowse
                • 94.156.71.225
                SecuriteInfo.com.Linux.Siggen.9999.18582.17843.elfGet hashmaliciousMiraiBrowse
                • 94.156.71.225
                SecuriteInfo.com.Linux.Siggen.9999.127.12108.elfGet hashmaliciousMiraiBrowse
                • 94.156.71.225
                SecuriteInfo.com.Linux.Siggen.9999.9304.22091.elfGet hashmaliciousMiraiBrowse
                • 94.156.71.225
                SecuriteInfo.com.Linux.Siggen.9999.22319.26890.elfGet hashmaliciousMiraiBrowse
                • 94.156.71.225
                SecuriteInfo.com.ELF.Agent-CMS.31992.20858.elfGet hashmaliciousUnknownBrowse
                • 94.156.69.214
                6I8BO0tIYE.exeGet hashmaliciousSmokeLoaderBrowse
                • 94.156.69.247
                Customer-orderlist-Bestellung0940670009988208.exeGet hashmaliciousRedLineBrowse
                • 94.156.65.203
                best.x86.elfGet hashmaliciousUnknownBrowse
                • 94.156.69.188
                1724226243b9348f3b411af582580bd6a603a5ce20b028cbcc95a10a9590dca310f3191fd6655.dat-decoded.exeGet hashmaliciousRemcosBrowse
                • 94.156.65.159
                No context
                No context
                No created / dropped files found
                File type:ELF 32-bit MSB executable, MIPS, MIPS-I version 1 (SYSV), statically linked, no section header
                Entropy (8bit):7.938710915902252
                TrID:
                • ELF Executable and Linkable format (Linux) (4029/14) 50.16%
                • ELF Executable and Linkable format (generic) (4004/1) 49.84%
                File name:SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf
                File size:42'556 bytes
                MD5:d209dadd662918c0360d992f693a4c88
                SHA1:ff29a4cb9d0d2a4ad7e15f7523bdc5d5d681f990
                SHA256:f461632cc61eaa9bcf7deb5dba0ca986c5ea65fb366fae6d329cee5458abd07d
                SHA512:809bb6cea3b997755c9464d90f6b3e18b2a007c2b55dcb85ef475e72f632f6c0ea435c9fb7567741ff5233204e958d234ca7ec8e69bfdffff1a8c1dab7c55aba
                SSDEEP:768:5IFulBJl1WCiiw2kE2LIZ6r18twq8DB21UxhLvKQrZ+FiVIQJgGlzDpbuR1JJ:5IYtfiLI8x8twqEB2yxhr0FaVJuD
                TLSH:D913F13BD64041E7FC44E4BA71E197416E23076ABD12FC4D8E3DDA279DC48B26087698
                File Content Preview:.ELF...........................4.........4. ...(.............................................C...C...................../UPX!.d.....................V.......?.E.h4...@b..) ..]....E..4....='./@..b;..xz(.....B...R...w..j......J.....l.... ./.`...<.............

                ELF header

                Class:ELF32
                Data:2's complement, big endian
                Version:1 (current)
                Machine:MIPS R3000
                Version Number:0x1
                Type:EXEC (Executable file)
                OS/ABI:UNIX - System V
                ABI Version:0
                Entry Point Address:0x1091c0
                Flags:0x1007
                ELF Header Size:52
                Program Header Offset:52
                Program Header Size:32
                Number of Program Headers:2
                Section Header Offset:0
                Section Header Size:40
                Number of Section Headers:0
                Header String Table Index:0
                TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                LOAD0x00x1000000x1000000xa5040xa5047.94130x5R E0x10000
                LOAD0xdeb40x43deb40x43deb40x00x00.00000x6RW 0x10000
                TimestampSource PortDest PortSource IPDest IP
                Sep 1, 2024 01:55:34.893794060 CEST404243778192.168.2.1394.156.71.225
                Sep 1, 2024 01:55:34.898580074 CEST37784042494.156.71.225192.168.2.13
                Sep 1, 2024 01:55:34.898628950 CEST404243778192.168.2.1394.156.71.225
                Sep 1, 2024 01:55:34.931185961 CEST404243778192.168.2.1394.156.71.225
                Sep 1, 2024 01:55:34.935997009 CEST37784042494.156.71.225192.168.2.13
                Sep 1, 2024 01:55:34.936037064 CEST404243778192.168.2.1394.156.71.225
                Sep 1, 2024 01:55:34.940799952 CEST37784042494.156.71.225192.168.2.13
                Sep 1, 2024 01:55:44.940155983 CEST404243778192.168.2.1394.156.71.225
                Sep 1, 2024 01:55:44.945112944 CEST37784042494.156.71.225192.168.2.13
                Sep 1, 2024 01:55:45.110620022 CEST37784042494.156.71.225192.168.2.13
                Sep 1, 2024 01:55:45.110685110 CEST404243778192.168.2.1394.156.71.225
                Sep 1, 2024 01:56:45.164345026 CEST404243778192.168.2.1394.156.71.225
                Sep 1, 2024 01:56:45.169311047 CEST37784042494.156.71.225192.168.2.13
                Sep 1, 2024 01:56:45.334980011 CEST37784042494.156.71.225192.168.2.13
                Sep 1, 2024 01:56:45.335191011 CEST404243778192.168.2.1394.156.71.225
                Sep 1, 2024 01:57:45.394429922 CEST404243778192.168.2.1394.156.71.225
                Sep 1, 2024 01:57:45.399333000 CEST37784042494.156.71.225192.168.2.13
                Sep 1, 2024 01:57:45.565408945 CEST37784042494.156.71.225192.168.2.13
                Sep 1, 2024 01:57:45.565489054 CEST404243778192.168.2.1394.156.71.225
                Sep 1, 2024 01:58:45.625937939 CEST404243778192.168.2.1394.156.71.225
                Sep 1, 2024 01:58:45.779093981 CEST37784042494.156.71.225192.168.2.13
                Sep 1, 2024 01:58:45.944539070 CEST37784042494.156.71.225192.168.2.13
                Sep 1, 2024 01:58:45.944665909 CEST404243778192.168.2.1394.156.71.225
                TimestampSource PortDest PortSource IPDest IP
                Sep 1, 2024 01:58:21.623126030 CEST3357053192.168.2.131.1.1.1
                Sep 1, 2024 01:58:21.623183012 CEST3478053192.168.2.131.1.1.1
                Sep 1, 2024 01:58:21.629740953 CEST53347801.1.1.1192.168.2.13
                Sep 1, 2024 01:58:21.630026102 CEST53335701.1.1.1192.168.2.13
                TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                Sep 1, 2024 01:58:21.623126030 CEST192.168.2.131.1.1.10x53e8Standard query (0)daisy.ubuntu.comA (IP address)IN (0x0001)false
                Sep 1, 2024 01:58:21.623183012 CEST192.168.2.131.1.1.10x8a88Standard query (0)daisy.ubuntu.com28IN (0x0001)false
                TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                Sep 1, 2024 01:58:21.630026102 CEST1.1.1.1192.168.2.130x53e8No error (0)daisy.ubuntu.com162.213.35.25A (IP address)IN (0x0001)false
                Sep 1, 2024 01:58:21.630026102 CEST1.1.1.1192.168.2.130x53e8No error (0)daisy.ubuntu.com162.213.35.24A (IP address)IN (0x0001)false

                System Behavior

                Start time (UTC):23:55:33
                Start date (UTC):31/08/2024
                Path:/tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf
                Arguments:/tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf
                File size:5777432 bytes
                MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                Start time (UTC):23:55:33
                Start date (UTC):31/08/2024
                Path:/tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf
                Arguments:-
                File size:5777432 bytes
                MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                Start time (UTC):23:55:33
                Start date (UTC):31/08/2024
                Path:/tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf
                Arguments:-
                File size:5777432 bytes
                MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                Start time (UTC):23:55:39
                Start date (UTC):31/08/2024
                Path:/tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf
                Arguments:-
                File size:5777432 bytes
                MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                Start time (UTC):23:55:45
                Start date (UTC):31/08/2024
                Path:/tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf
                Arguments:-
                File size:5777432 bytes
                MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                Start time (UTC):23:55:50
                Start date (UTC):31/08/2024
                Path:/tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf
                Arguments:-
                File size:5777432 bytes
                MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                Start time (UTC):23:55:56
                Start date (UTC):31/08/2024
                Path:/tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf
                Arguments:-
                File size:5777432 bytes
                MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                Start time (UTC):23:56:01
                Start date (UTC):31/08/2024
                Path:/tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf
                Arguments:-
                File size:5777432 bytes
                MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                Start time (UTC):23:56:07
                Start date (UTC):31/08/2024
                Path:/tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf
                Arguments:-
                File size:5777432 bytes
                MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                Start time (UTC):23:56:12
                Start date (UTC):31/08/2024
                Path:/tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf
                Arguments:-
                File size:5777432 bytes
                MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                Start time (UTC):23:56:17
                Start date (UTC):31/08/2024
                Path:/tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf
                Arguments:-
                File size:5777432 bytes
                MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                Start time (UTC):23:56:22
                Start date (UTC):31/08/2024
                Path:/tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf
                Arguments:-
                File size:5777432 bytes
                MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                Start time (UTC):23:56:27
                Start date (UTC):31/08/2024
                Path:/tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf
                Arguments:-
                File size:5777432 bytes
                MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                Start time (UTC):23:56:32
                Start date (UTC):31/08/2024
                Path:/tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf
                Arguments:-
                File size:5777432 bytes
                MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                Start time (UTC):23:56:37
                Start date (UTC):31/08/2024
                Path:/tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf
                Arguments:-
                File size:5777432 bytes
                MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                Start time (UTC):23:56:42
                Start date (UTC):31/08/2024
                Path:/tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf
                Arguments:-
                File size:5777432 bytes
                MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                Start time (UTC):23:56:47
                Start date (UTC):31/08/2024
                Path:/tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf
                Arguments:-
                File size:5777432 bytes
                MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                Start time (UTC):23:56:52
                Start date (UTC):31/08/2024
                Path:/tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf
                Arguments:-
                File size:5777432 bytes
                MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                Start time (UTC):23:56:57
                Start date (UTC):31/08/2024
                Path:/tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf
                Arguments:-
                File size:5777432 bytes
                MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                Start time (UTC):23:57:02
                Start date (UTC):31/08/2024
                Path:/tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf
                Arguments:-
                File size:5777432 bytes
                MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                Start time (UTC):23:57:07
                Start date (UTC):31/08/2024
                Path:/tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf
                Arguments:-
                File size:5777432 bytes
                MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                Start time (UTC):23:57:12
                Start date (UTC):31/08/2024
                Path:/tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf
                Arguments:-
                File size:5777432 bytes
                MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                Start time (UTC):23:57:17
                Start date (UTC):31/08/2024
                Path:/tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf
                Arguments:-
                File size:5777432 bytes
                MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                Start time (UTC):23:57:22
                Start date (UTC):31/08/2024
                Path:/tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf
                Arguments:-
                File size:5777432 bytes
                MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                Start time (UTC):23:57:27
                Start date (UTC):31/08/2024
                Path:/tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf
                Arguments:-
                File size:5777432 bytes
                MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                Start time (UTC):23:57:32
                Start date (UTC):31/08/2024
                Path:/tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf
                Arguments:-
                File size:5777432 bytes
                MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                Start time (UTC):23:57:37
                Start date (UTC):31/08/2024
                Path:/tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf
                Arguments:-
                File size:5777432 bytes
                MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                Start time (UTC):23:57:42
                Start date (UTC):31/08/2024
                Path:/tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf
                Arguments:-
                File size:5777432 bytes
                MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                Start time (UTC):23:57:47
                Start date (UTC):31/08/2024
                Path:/tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf
                Arguments:-
                File size:5777432 bytes
                MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                Start time (UTC):23:57:52
                Start date (UTC):31/08/2024
                Path:/tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf
                Arguments:-
                File size:5777432 bytes
                MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                Start time (UTC):23:57:57
                Start date (UTC):31/08/2024
                Path:/tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf
                Arguments:-
                File size:5777432 bytes
                MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                Start time (UTC):23:58:02
                Start date (UTC):31/08/2024
                Path:/tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf
                Arguments:-
                File size:5777432 bytes
                MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                Start time (UTC):23:58:07
                Start date (UTC):31/08/2024
                Path:/tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf
                Arguments:-
                File size:5777432 bytes
                MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                Start time (UTC):23:58:12
                Start date (UTC):31/08/2024
                Path:/tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf
                Arguments:-
                File size:5777432 bytes
                MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                Start time (UTC):23:58:17
                Start date (UTC):31/08/2024
                Path:/tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf
                Arguments:-
                File size:5777432 bytes
                MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                Start time (UTC):23:58:23
                Start date (UTC):31/08/2024
                Path:/tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf
                Arguments:-
                File size:5777432 bytes
                MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                Start time (UTC):23:58:28
                Start date (UTC):31/08/2024
                Path:/tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf
                Arguments:-
                File size:5777432 bytes
                MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                Start time (UTC):23:58:33
                Start date (UTC):31/08/2024
                Path:/tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf
                Arguments:-
                File size:5777432 bytes
                MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                Start time (UTC):23:58:38
                Start date (UTC):31/08/2024
                Path:/tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf
                Arguments:-
                File size:5777432 bytes
                MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                Start time (UTC):23:58:43
                Start date (UTC):31/08/2024
                Path:/tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf
                Arguments:-
                File size:5777432 bytes
                MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                Start time (UTC):23:58:48
                Start date (UTC):31/08/2024
                Path:/tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf
                Arguments:-
                File size:5777432 bytes
                MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                Start time (UTC):23:58:53
                Start date (UTC):31/08/2024
                Path:/tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf
                Arguments:-
                File size:5777432 bytes
                MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                Start time (UTC):23:58:58
                Start date (UTC):31/08/2024
                Path:/tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf
                Arguments:-
                File size:5777432 bytes
                MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                Start time (UTC):23:59:03
                Start date (UTC):31/08/2024
                Path:/tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf
                Arguments:-
                File size:5777432 bytes
                MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                Start time (UTC):23:59:08
                Start date (UTC):31/08/2024
                Path:/tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf
                Arguments:-
                File size:5777432 bytes
                MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                Start time (UTC):23:55:33
                Start date (UTC):31/08/2024
                Path:/tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf
                Arguments:-
                File size:5777432 bytes
                MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                Start time (UTC):23:55:33
                Start date (UTC):31/08/2024
                Path:/tmp/SecuriteInfo.com.Linux.Siggen.9999.5622.5080.elf
                Arguments:-
                File size:5777432 bytes
                MD5 hash:0083f1f0e77be34ad27f849842bbb00c