Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
SecuriteInfo.com.Linux.Siggen.9999.6640.19420.elf

Overview

General Information

Sample name:SecuriteInfo.com.Linux.Siggen.9999.6640.19420.elf
Analysis ID:1522341
MD5:7107b1cd2e054b027ba94c7acb00df60
SHA1:895a33bdf643e6c1e4760c23645415c7b09fb9cd
SHA256:3a935d41b1e975b201e7a0a59287f52eee4722fb2eaecd741568679cbfd7970e
Tags:elf
Infos:

Detection

Mirai
Score:72
Range:0 - 100
Whitelisted:false

Signatures

Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Yara detected Mirai
Machine Learning detection for sample
Sample is packed with UPX
Detected TCP or UDP traffic on non-standard ports
ELF contains segments with high entropy indicating compressed/encrypted content
Enumerates processes within the "proc" file system
Sample contains only a LOAD segment without any section mappings
Sample tries to kill a process (SIGKILL)
Yara signature match

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1522341
Start date and time:2024-09-30 00:20:11 +02:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 44s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:SecuriteInfo.com.Linux.Siggen.9999.6640.19420.elf
Detection:MAL
Classification:mal72.troj.evad.linELF@0/0@0/0
  • VT rate limit hit for: SecuriteInfo.com.Linux.Siggen.9999.6640.19420.elf
Command:/tmp/SecuriteInfo.com.Linux.Siggen.9999.6640.19420.elf
PID:5430
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
lzrd cock fest"/proc/"/exe
Standard Error:
  • system is lnxubuntu20
  • sh (PID: 5450, Parent: 1588, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-rfkill
  • gsd-rfkill (PID: 5450, Parent: 1588, MD5: 88a16a3c0aba1759358c06215ecfb5cc) Arguments: /usr/libexec/gsd-rfkill
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
MiraiMirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese. Nowadays it targets a wide range of networked embedded devices such as IP cameras, home routers (many vendors involved), and other IoT devices. Since the source code was published on "Hack Forums" many variants of the Mirai family appeared, infecting mostly home networks all around the world.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/elf.mirai
SourceRuleDescriptionAuthorStrings
5430.1.0000000008048000.0000000008057000.r-x.sdmpJoeSecurity_Mirai_8Yara detected MiraiJoe Security
    5430.1.0000000008048000.0000000008057000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
    • 0xce00:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xce14:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xce28:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xce3c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xce50:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xce64:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xce78:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xce8c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xcea0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xceb4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xcec8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xcedc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xcef0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xcf04:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xcf18:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xcf2c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xcf40:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xcf54:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xcf68:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xcf7c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xcf90:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    5430.1.0000000008048000.0000000008057000.r-x.sdmpLinux_Trojan_Gafgyt_ea92cca8unknownunknown
    • 0xd358:$a: 53 65 6C 66 20 52 65 70 20 46 75 63 6B 69 6E 67 20 4E 65 54 69 53 20 61 6E 64
    5430.1.0000000008048000.0000000008057000.r-x.sdmpLinux_Trojan_Mirai_b14f4c5dunknownunknown
    • 0x60f0:$a: 53 31 DB 8B 4C 24 0C 8B 54 24 08 83 F9 01 76 15 66 8B 02 83 E9 02 25 FF FF 00 00 83 C2 02 01 C3 83 F9 01 77 EB 49 75 05 0F BE 02 01 C3
    5430.1.0000000008048000.0000000008057000.r-x.sdmpLinux_Trojan_Mirai_88de437funknownunknown
    • 0x7a52:$a: 24 08 8B 4C 24 04 85 D2 74 0D 31 C0 89 F6 C6 04 08 00 40 39 D0
    Click to see the 7 entries
    No Suricata rule has matched

    Click to jump to signature section

    Show All Signature Results

    AV Detection

    barindex
    Source: SecuriteInfo.com.Linux.Siggen.9999.6640.19420.elfReversingLabs: Detection: 57%
    Source: SecuriteInfo.com.Linux.Siggen.9999.6640.19420.elfJoe Sandbox ML: detected
    Source: global trafficTCP traffic: 192.168.2.13:53454 -> 93.123.85.221:3778
    Source: unknownTCP traffic detected without corresponding DNS query: 93.123.85.221
    Source: unknownTCP traffic detected without corresponding DNS query: 93.123.85.221
    Source: unknownTCP traffic detected without corresponding DNS query: 93.123.85.221
    Source: unknownTCP traffic detected without corresponding DNS query: 93.123.85.221
    Source: unknownTCP traffic detected without corresponding DNS query: 93.123.85.221
    Source: unknownTCP traffic detected without corresponding DNS query: 93.123.85.221
    Source: unknownTCP traffic detected without corresponding DNS query: 93.123.85.221
    Source: unknownTCP traffic detected without corresponding DNS query: 93.123.85.221
    Source: unknownTCP traffic detected without corresponding DNS query: 93.123.85.221
    Source: unknownTCP traffic detected without corresponding DNS query: 93.123.85.221
    Source: unknownTCP traffic detected without corresponding DNS query: 93.123.85.221
    Source: unknownTCP traffic detected without corresponding DNS query: 93.123.85.221
    Source: unknownTCP traffic detected without corresponding DNS query: 93.123.85.221
    Source: unknownTCP traffic detected without corresponding DNS query: 93.123.85.221
    Source: unknownTCP traffic detected without corresponding DNS query: 93.123.85.221
    Source: unknownTCP traffic detected without corresponding DNS query: 93.123.85.221
    Source: unknownTCP traffic detected without corresponding DNS query: 93.123.85.221
    Source: unknownTCP traffic detected without corresponding DNS query: 93.123.85.221
    Source: unknownTCP traffic detected without corresponding DNS query: 93.123.85.221
    Source: unknownTCP traffic detected without corresponding DNS query: 93.123.85.221
    Source: unknownTCP traffic detected without corresponding DNS query: 93.123.85.221
    Source: unknownTCP traffic detected without corresponding DNS query: 93.123.85.221
    Source: unknownTCP traffic detected without corresponding DNS query: 93.123.85.221
    Source: unknownTCP traffic detected without corresponding DNS query: 93.123.85.221
    Source: unknownTCP traffic detected without corresponding DNS query: 93.123.85.221
    Source: unknownTCP traffic detected without corresponding DNS query: 93.123.85.221
    Source: unknownTCP traffic detected without corresponding DNS query: 93.123.85.221
    Source: unknownTCP traffic detected without corresponding DNS query: 93.123.85.221
    Source: unknownTCP traffic detected without corresponding DNS query: 93.123.85.221
    Source: unknownTCP traffic detected without corresponding DNS query: 93.123.85.221
    Source: unknownTCP traffic detected without corresponding DNS query: 93.123.85.221
    Source: unknownTCP traffic detected without corresponding DNS query: 93.123.85.221
    Source: unknownTCP traffic detected without corresponding DNS query: 93.123.85.221
    Source: unknownTCP traffic detected without corresponding DNS query: 93.123.85.221
    Source: unknownTCP traffic detected without corresponding DNS query: 93.123.85.221
    Source: unknownTCP traffic detected without corresponding DNS query: 93.123.85.221
    Source: unknownTCP traffic detected without corresponding DNS query: 93.123.85.221
    Source: unknownTCP traffic detected without corresponding DNS query: 93.123.85.221
    Source: unknownTCP traffic detected without corresponding DNS query: 93.123.85.221
    Source: unknownTCP traffic detected without corresponding DNS query: 93.123.85.221
    Source: unknownTCP traffic detected without corresponding DNS query: 93.123.85.221
    Source: unknownTCP traffic detected without corresponding DNS query: 93.123.85.221
    Source: unknownTCP traffic detected without corresponding DNS query: 93.123.85.221
    Source: unknownTCP traffic detected without corresponding DNS query: 93.123.85.221
    Source: unknownTCP traffic detected without corresponding DNS query: 93.123.85.221
    Source: unknownTCP traffic detected without corresponding DNS query: 93.123.85.221
    Source: unknownTCP traffic detected without corresponding DNS query: 93.123.85.221
    Source: unknownTCP traffic detected without corresponding DNS query: 93.123.85.221
    Source: unknownTCP traffic detected without corresponding DNS query: 93.123.85.221
    Source: unknownTCP traffic detected without corresponding DNS query: 93.123.85.221
    Source: SecuriteInfo.com.Linux.Siggen.9999.6640.19420.elfString found in binary or memory: http://upx.sf.net

    System Summary

    barindex
    Source: 5430.1.0000000008048000.0000000008057000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
    Source: 5430.1.0000000008048000.0000000008057000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown
    Source: 5430.1.0000000008048000.0000000008057000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_b14f4c5d Author: unknown
    Source: 5430.1.0000000008048000.0000000008057000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_88de437f Author: unknown
    Source: 5430.1.0000000008048000.0000000008057000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_ae9d0fa6 Author: unknown
    Source: 5430.1.0000000008048000.0000000008057000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_389ee3e9 Author: unknown
    Source: 5430.1.0000000008048000.0000000008057000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_cc93863b Author: unknown
    Source: 5430.1.0000000008048000.0000000008057000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_8aa7b5d3 Author: unknown
    Source: Process Memory Space: SecuriteInfo.com.Linux.Siggen.9999.6640.19420.elf PID: 5430, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
    Source: Process Memory Space: SecuriteInfo.com.Linux.Siggen.9999.6640.19420.elf PID: 5430, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown
    Source: LOAD without section mappingsProgram segment: 0xc01000
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.6640.19420.elf (PID: 5431)SIGKILL sent: pid: 914, result: successfulJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.6640.19420.elf (PID: 5431)SIGKILL sent: pid: 917, result: successfulJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.6640.19420.elf (PID: 5431)SIGKILL sent: pid: 936, result: successfulJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.6640.19420.elf (PID: 5431)SIGKILL sent: pid: 1238, result: successfulJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.6640.19420.elf (PID: 5431)SIGKILL sent: pid: 1320, result: successfulJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.6640.19420.elf (PID: 5431)SIGKILL sent: pid: 1884, result: successfulJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.6640.19420.elf (PID: 5431)SIGKILL sent: pid: 5450, result: successfulJump to behavior
    Source: 5430.1.0000000008048000.0000000008057000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
    Source: 5430.1.0000000008048000.0000000008057000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16
    Source: 5430.1.0000000008048000.0000000008057000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_b14f4c5d os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = a70d052918dd2fbc66db241da6438015130f0fb6929229bfe573546fe98da817, id = b14f4c5d-054f-46e6-9fa8-3588f1ef68b7, last_modified = 2021-09-16
    Source: 5430.1.0000000008048000.0000000008057000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_88de437f reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = c19eb595c2b444a809bef8500c20342c9f46694d3018e268833f9b884133a1ea, id = 88de437f-9c98-4e1d-96c0-7b433c99886a, last_modified = 2021-09-16
    Source: 5430.1.0000000008048000.0000000008057000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_ae9d0fa6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = ca2bf2771844bec95563800d19a35dd230413f8eff0bd44c8ab0b4c596f81bfc, id = ae9d0fa6-be06-4656-9b13-8edfc0ee9e71, last_modified = 2021-09-16
    Source: 5430.1.0000000008048000.0000000008057000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_389ee3e9 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 59f2359dc1f41d385d639d157b4cd9fc73d76d8abb7cc09d47632bb4c9a39e6e, id = 389ee3e9-70c1-4c93-a999-292cf6ff1652, last_modified = 2022-01-26
    Source: 5430.1.0000000008048000.0000000008057000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_cc93863b reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = f3ecd30f0b511a8e92cfa642409d559e7612c3f57a1659ca46c77aca809a00ac, id = cc93863b-1050-40ba-9d02-5ec9ce6a3a28, last_modified = 2022-01-26
    Source: 5430.1.0000000008048000.0000000008057000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_8aa7b5d3 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 02a2c18c362df4b1fceb33f3b605586514ba9a00c7afedf71c04fa54d8146444, id = 8aa7b5d3-e1eb-4b55-b36a-0d3a242c06e9, last_modified = 2022-01-26
    Source: Process Memory Space: SecuriteInfo.com.Linux.Siggen.9999.6640.19420.elf PID: 5430, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
    Source: Process Memory Space: SecuriteInfo.com.Linux.Siggen.9999.6640.19420.elf PID: 5430, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16
    Source: classification engineClassification label: mal72.troj.evad.linELF@0/0@0/0

    Data Obfuscation

    barindex
    Source: initial sampleString containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $
    Source: initial sampleString containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $
    Source: initial sampleString containing UPX found: $Id: UPX 3.94 Copyright (C) 1996-2017 the UPX Team. All Rights Reserved. $
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.6640.19420.elf (PID: 5431)File opened: /proc/3761/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.6640.19420.elf (PID: 5431)File opened: /proc/230/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.6640.19420.elf (PID: 5431)File opened: /proc/110/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.6640.19420.elf (PID: 5431)File opened: /proc/231/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.6640.19420.elf (PID: 5431)File opened: /proc/111/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.6640.19420.elf (PID: 5431)File opened: /proc/232/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.6640.19420.elf (PID: 5431)File opened: /proc/112/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.6640.19420.elf (PID: 5431)File opened: /proc/233/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.6640.19420.elf (PID: 5431)File opened: /proc/113/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.6640.19420.elf (PID: 5431)File opened: /proc/234/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.6640.19420.elf (PID: 5431)File opened: /proc/114/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.6640.19420.elf (PID: 5431)File opened: /proc/235/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.6640.19420.elf (PID: 5431)File opened: /proc/115/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.6640.19420.elf (PID: 5431)File opened: /proc/236/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.6640.19420.elf (PID: 5431)File opened: /proc/116/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.6640.19420.elf (PID: 5431)File opened: /proc/237/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.6640.19420.elf (PID: 5431)File opened: /proc/117/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.6640.19420.elf (PID: 5431)File opened: /proc/238/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.6640.19420.elf (PID: 5431)File opened: /proc/118/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.6640.19420.elf (PID: 5431)File opened: /proc/239/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.6640.19420.elf (PID: 5431)File opened: /proc/119/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.6640.19420.elf (PID: 5431)File opened: /proc/3632/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.6640.19420.elf (PID: 5431)File opened: /proc/914/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.6640.19420.elf (PID: 5431)File opened: /proc/10/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.6640.19420.elf (PID: 5431)File opened: /proc/917/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.6640.19420.elf (PID: 5431)File opened: /proc/11/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.6640.19420.elf (PID: 5431)File opened: /proc/12/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.6640.19420.elf (PID: 5431)File opened: /proc/5273/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.6640.19420.elf (PID: 5431)File opened: /proc/13/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.6640.19420.elf (PID: 5431)File opened: /proc/14/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.6640.19420.elf (PID: 5431)File opened: /proc/15/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.6640.19420.elf (PID: 5431)File opened: /proc/16/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.6640.19420.elf (PID: 5431)File opened: /proc/17/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.6640.19420.elf (PID: 5431)File opened: /proc/18/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.6640.19420.elf (PID: 5431)File opened: /proc/19/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.6640.19420.elf (PID: 5431)File opened: /proc/240/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.6640.19420.elf (PID: 5431)File opened: /proc/3095/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.6640.19420.elf (PID: 5431)File opened: /proc/120/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.6640.19420.elf (PID: 5431)File opened: /proc/241/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.6640.19420.elf (PID: 5431)File opened: /proc/0/statJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.6640.19420.elf (PID: 5431)File opened: /proc/121/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.6640.19420.elf (PID: 5431)File opened: /proc/242/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.6640.19420.elf (PID: 5431)File opened: /proc/1/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.6640.19420.elf (PID: 5431)File opened: /proc/122/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.6640.19420.elf (PID: 5431)File opened: /proc/243/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.6640.19420.elf (PID: 5431)File opened: /proc/2/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.6640.19420.elf (PID: 5431)File opened: /proc/123/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.6640.19420.elf (PID: 5431)File opened: /proc/244/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.6640.19420.elf (PID: 5431)File opened: /proc/3/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.6640.19420.elf (PID: 5431)File opened: /proc/124/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.6640.19420.elf (PID: 5431)File opened: /proc/245/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.6640.19420.elf (PID: 5431)File opened: /proc/1588/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.6640.19420.elf (PID: 5431)File opened: /proc/125/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.6640.19420.elf (PID: 5431)File opened: /proc/4/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.6640.19420.elf (PID: 5431)File opened: /proc/246/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.6640.19420.elf (PID: 5431)File opened: /proc/126/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.6640.19420.elf (PID: 5431)File opened: /proc/5/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.6640.19420.elf (PID: 5431)File opened: /proc/247/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.6640.19420.elf (PID: 5431)File opened: /proc/127/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.6640.19420.elf (PID: 5431)File opened: /proc/6/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.6640.19420.elf (PID: 5431)File opened: /proc/248/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.6640.19420.elf (PID: 5431)File opened: /proc/128/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.6640.19420.elf (PID: 5431)File opened: /proc/7/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.6640.19420.elf (PID: 5431)File opened: /proc/249/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.6640.19420.elf (PID: 5431)File opened: /proc/129/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.6640.19420.elf (PID: 5431)File opened: /proc/8/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.6640.19420.elf (PID: 5431)File opened: /proc/800/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.6640.19420.elf (PID: 5431)File opened: /proc/9/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.6640.19420.elf (PID: 5431)File opened: /proc/1906/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.6640.19420.elf (PID: 5431)File opened: /proc/802/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.6640.19420.elf (PID: 5431)File opened: /proc/803/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.6640.19420.elf (PID: 5431)File opened: /proc/20/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.6640.19420.elf (PID: 5431)File opened: /proc/21/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.6640.19420.elf (PID: 5431)File opened: /proc/22/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.6640.19420.elf (PID: 5431)File opened: /proc/23/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.6640.19420.elf (PID: 5431)File opened: /proc/24/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.6640.19420.elf (PID: 5431)File opened: /proc/25/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.6640.19420.elf (PID: 5431)File opened: /proc/26/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.6640.19420.elf (PID: 5431)File opened: /proc/27/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.6640.19420.elf (PID: 5431)File opened: /proc/28/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.6640.19420.elf (PID: 5431)File opened: /proc/29/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.6640.19420.elf (PID: 5431)File opened: /proc/3420/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.6640.19420.elf (PID: 5431)File opened: /proc/1482/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.6640.19420.elf (PID: 5431)File opened: /proc/490/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.6640.19420.elf (PID: 5431)File opened: /proc/1480/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.6640.19420.elf (PID: 5431)File opened: /proc/250/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.6640.19420.elf (PID: 5431)File opened: /proc/371/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.6640.19420.elf (PID: 5431)File opened: /proc/130/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.6640.19420.elf (PID: 5431)File opened: /proc/251/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.6640.19420.elf (PID: 5431)File opened: /proc/131/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.6640.19420.elf (PID: 5431)File opened: /proc/252/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.6640.19420.elf (PID: 5431)File opened: /proc/132/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.6640.19420.elf (PID: 5431)File opened: /proc/253/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.6640.19420.elf (PID: 5431)File opened: /proc/254/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.6640.19420.elf (PID: 5431)File opened: /proc/1238/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.6640.19420.elf (PID: 5431)File opened: /proc/134/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.6640.19420.elf (PID: 5431)File opened: /proc/255/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.6640.19420.elf (PID: 5431)File opened: /proc/256/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.6640.19420.elf (PID: 5431)File opened: /proc/257/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.6640.19420.elf (PID: 5431)File opened: /proc/378/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.6640.19420.elf (PID: 5431)File opened: /proc/3413/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.6640.19420.elf (PID: 5431)File opened: /proc/258/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.6640.19420.elf (PID: 5431)File opened: /proc/259/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.6640.19420.elf (PID: 5431)File opened: /proc/1475/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.6640.19420.elf (PID: 5431)File opened: /proc/936/cmdlineJump to behavior
    Source: SecuriteInfo.com.Linux.Siggen.9999.6640.19420.elfSubmission file: segment LOAD with 7.8909 entropy (max. 8.0)

    Stealing of Sensitive Information

    barindex
    Source: Yara matchFile source: 5430.1.0000000008048000.0000000008057000.r-x.sdmp, type: MEMORY
    Source: Yara matchFile source: Process Memory Space: SecuriteInfo.com.Linux.Siggen.9999.6640.19420.elf PID: 5430, type: MEMORYSTR

    Remote Access Functionality

    barindex
    Source: Yara matchFile source: 5430.1.0000000008048000.0000000008057000.r-x.sdmp, type: MEMORY
    Source: Yara matchFile source: Process Memory Space: SecuriteInfo.com.Linux.Siggen.9999.6640.19420.elf PID: 5430, type: MEMORYSTR
    ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
    Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception11
    Obfuscated Files or Information
    1
    OS Credential Dumping
    System Service DiscoveryRemote ServicesData from Local System1
    Non-Standard Port
    Exfiltration Over Other Network MediumAbuse Accessibility Features
    No configs have been found
    Hide Legend

    Legend:

    • Process
    • Signature
    • Created File
    • DNS/IP Info
    • Is Dropped
    • Number of created Files
    • Is malicious
    • Internet
    SourceDetectionScannerLabelLink
    SecuriteInfo.com.Linux.Siggen.9999.6640.19420.elf58%ReversingLabsLinux.Backdoor.Mirai
    SecuriteInfo.com.Linux.Siggen.9999.6640.19420.elf100%Joe Sandbox ML
    No Antivirus matches
    No Antivirus matches
    SourceDetectionScannerLabelLink
    http://upx.sf.net0%URL Reputationsafe
    No contacted domains info
    NameSourceMaliciousAntivirus DetectionReputation
    http://upx.sf.netSecuriteInfo.com.Linux.Siggen.9999.6640.19420.elftrue
    • URL Reputation: safe
    unknown
    • No. of IPs < 25%
    • 25% < No. of IPs < 50%
    • 50% < No. of IPs < 75%
    • 75% < No. of IPs
    IPDomainCountryFlagASNASN NameMalicious
    93.123.85.221
    unknownBulgaria
    43561NET1-ASBGfalse
    No context
    No context
    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
    NET1-ASBGKeyFormed.exeGet hashmaliciousUnknownBrowse
    • 83.222.191.195
    https://www.google.com/url?q=https%3A%2F%2Fgoo.gl%2Fotzvm%236%261afkvsGet hashmaliciousUnknownBrowse
    • 93.123.118.245
    SecuriteInfo.com.Win32.Sector.30.19697.26848.exeGet hashmaliciousSalityBrowse
    • 83.222.184.130
    SecuriteInfo.com.Linux.Siggen.9999.6145.9800.elfGet hashmaliciousMiraiBrowse
    • 93.123.85.119
    SecuriteInfo.com.Linux.Siggen.9999.20750.2018.elfGet hashmaliciousUnknownBrowse
    • 93.123.85.119
    SecuriteInfo.com.Linux.Siggen.9999.32241.1909.elfGet hashmaliciousUnknownBrowse
    • 93.123.85.119
    SecuriteInfo.com.Linux.Siggen.9999.8925.23450.elfGet hashmaliciousUnknownBrowse
    • 93.123.85.119
    SecuriteInfo.com.Linux.Siggen.9999.15981.30880.elfGet hashmaliciousMiraiBrowse
    • 93.123.85.119
    SecuriteInfo.com.Linux.Siggen.9999.23942.12921.elfGet hashmaliciousUnknownBrowse
    • 93.123.85.119
    SecuriteInfo.com.Linux.Siggen.9999.9288.24208.elfGet hashmaliciousMiraiBrowse
    • 93.123.85.141
    No context
    No context
    No created / dropped files found
    File type:ELF 32-bit LSB executable, Intel 80386, version 1 (GNU/Linux), statically linked, no section header
    Entropy (8bit):7.886542394690035
    TrID:
    • ELF Executable and Linkable format (Linux) (4029/14) 50.16%
    • ELF Executable and Linkable format (generic) (4004/1) 49.84%
    File name:SecuriteInfo.com.Linux.Siggen.9999.6640.19420.elf
    File size:30'220 bytes
    MD5:7107b1cd2e054b027ba94c7acb00df60
    SHA1:895a33bdf643e6c1e4760c23645415c7b09fb9cd
    SHA256:3a935d41b1e975b201e7a0a59287f52eee4722fb2eaecd741568679cbfd7970e
    SHA512:cf7be31ce95975bc468ab3b11e903a281b4338f3ac2bc1cfb8cf4be7d0334f7e2a9b35835f1b6870197a4125f136546af93680309adf58eb2573da7299d7c8d2
    SSDEEP:768:xX7WVHAoGJk6IcweEaOQyp1sq2MOVwAwJJJggouY:97WVHvek6PwnNUq2MwwAwvJa
    TLSH:57D2F170D6DC190BFA6553BF032E8495219E0F440F6AA6E7C38F495B06E137A662C4CC
    File Content Preview:.ELF.................... }..4...........4. ...(......................u...u.............. ... ... ...................Q.td...............................4UPX!........P...P.......^........?d..ELF.......d.......4....4. (.......k.-.#................p..... ..A.

    ELF header

    Class:ELF32
    Data:2's complement, little endian
    Version:1 (current)
    Machine:Intel 80386
    Version Number:0x1
    Type:EXEC (Executable file)
    OS/ABI:UNIX - Linux
    ABI Version:0
    Entry Point Address:0xc07d20
    Flags:0x0
    ELF Header Size:52
    Program Header Offset:52
    Program Header Size:32
    Number of Program Headers:3
    Section Header Offset:0
    Section Header Size:40
    Number of Section Headers:0
    Header String Table Index:0
    TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
    LOAD0x00xc010000xc010000x75030x75037.89090x5R E0x1000
    LOAD0xb200x8059b200x8059b200x00x00.00000x6RW 0x1000
    GNU_STACK0x00x00x00x00x00.00000x6RW 0x4
    TimestampSource PortDest PortSource IPDest IP
    Sep 30, 2024 00:20:54.059125900 CEST534543778192.168.2.1393.123.85.221
    Sep 30, 2024 00:20:54.066731930 CEST37785345493.123.85.221192.168.2.13
    Sep 30, 2024 00:20:54.066817045 CEST534543778192.168.2.1393.123.85.221
    Sep 30, 2024 00:20:54.066860914 CEST534543778192.168.2.1393.123.85.221
    Sep 30, 2024 00:20:54.074534893 CEST37785345493.123.85.221192.168.2.13
    Sep 30, 2024 00:20:54.074580908 CEST534543778192.168.2.1393.123.85.221
    Sep 30, 2024 00:20:54.081662893 CEST37785345493.123.85.221192.168.2.13
    Sep 30, 2024 00:21:15.456954956 CEST37785345493.123.85.221192.168.2.13
    Sep 30, 2024 00:21:15.457057953 CEST534543778192.168.2.1393.123.85.221
    Sep 30, 2024 00:21:15.464509010 CEST37785345493.123.85.221192.168.2.13
    Sep 30, 2024 00:21:16.458183050 CEST534563778192.168.2.1393.123.85.221
    Sep 30, 2024 00:21:16.465291023 CEST37785345693.123.85.221192.168.2.13
    Sep 30, 2024 00:21:16.465358019 CEST534563778192.168.2.1393.123.85.221
    Sep 30, 2024 00:21:16.465399981 CEST534563778192.168.2.1393.123.85.221
    Sep 30, 2024 00:21:16.473463058 CEST37785345693.123.85.221192.168.2.13
    Sep 30, 2024 00:21:16.473506927 CEST534563778192.168.2.1393.123.85.221
    Sep 30, 2024 00:21:16.481029987 CEST37785345693.123.85.221192.168.2.13
    Sep 30, 2024 00:21:26.475052118 CEST534563778192.168.2.1393.123.85.221
    Sep 30, 2024 00:21:26.481596947 CEST37785345693.123.85.221192.168.2.13
    Sep 30, 2024 00:21:37.843883038 CEST37785345693.123.85.221192.168.2.13
    Sep 30, 2024 00:21:37.843955994 CEST534563778192.168.2.1393.123.85.221
    Sep 30, 2024 00:21:37.850689888 CEST37785345693.123.85.221192.168.2.13
    Sep 30, 2024 00:21:38.844794989 CEST534583778192.168.2.1393.123.85.221
    Sep 30, 2024 00:21:38.852435112 CEST37785345893.123.85.221192.168.2.13
    Sep 30, 2024 00:21:38.852490902 CEST534583778192.168.2.1393.123.85.221
    Sep 30, 2024 00:21:38.852518082 CEST534583778192.168.2.1393.123.85.221
    Sep 30, 2024 00:21:38.860213995 CEST37785345893.123.85.221192.168.2.13
    Sep 30, 2024 00:21:38.860263109 CEST534583778192.168.2.1393.123.85.221
    Sep 30, 2024 00:21:38.867558956 CEST37785345893.123.85.221192.168.2.13
    Sep 30, 2024 00:21:58.867052078 CEST534583778192.168.2.1393.123.85.221
    Sep 30, 2024 00:21:58.873903990 CEST37785345893.123.85.221192.168.2.13
    Sep 30, 2024 00:22:00.272628069 CEST37785345893.123.85.221192.168.2.13
    Sep 30, 2024 00:22:00.272718906 CEST534583778192.168.2.1393.123.85.221
    Sep 30, 2024 00:22:00.279927015 CEST37785345893.123.85.221192.168.2.13
    Sep 30, 2024 00:22:01.273855925 CEST534603778192.168.2.1393.123.85.221
    Sep 30, 2024 00:22:01.278717995 CEST37785346093.123.85.221192.168.2.13
    Sep 30, 2024 00:22:01.278814077 CEST534603778192.168.2.1393.123.85.221
    Sep 30, 2024 00:22:01.278871059 CEST534603778192.168.2.1393.123.85.221
    Sep 30, 2024 00:22:01.283634901 CEST37785346093.123.85.221192.168.2.13
    Sep 30, 2024 00:22:01.283678055 CEST534603778192.168.2.1393.123.85.221
    Sep 30, 2024 00:22:01.288431883 CEST37785346093.123.85.221192.168.2.13
    Sep 30, 2024 00:22:22.655718088 CEST37785346093.123.85.221192.168.2.13
    Sep 30, 2024 00:22:22.655814886 CEST534603778192.168.2.1393.123.85.221
    Sep 30, 2024 00:22:22.662467957 CEST37785346093.123.85.221192.168.2.13
    Sep 30, 2024 00:22:23.656559944 CEST534623778192.168.2.1393.123.85.221
    Sep 30, 2024 00:22:23.708065033 CEST37785346293.123.85.221192.168.2.13
    Sep 30, 2024 00:22:23.708132029 CEST534623778192.168.2.1393.123.85.221
    Sep 30, 2024 00:22:23.708156109 CEST534623778192.168.2.1393.123.85.221
    Sep 30, 2024 00:22:23.718635082 CEST37785346293.123.85.221192.168.2.13
    Sep 30, 2024 00:22:23.718682051 CEST534623778192.168.2.1393.123.85.221
    Sep 30, 2024 00:22:23.726629972 CEST37785346293.123.85.221192.168.2.13
    Sep 30, 2024 00:22:33.715004921 CEST534623778192.168.2.1393.123.85.221
    Sep 30, 2024 00:22:33.719923973 CEST37785346293.123.85.221192.168.2.13
    Sep 30, 2024 00:22:45.064356089 CEST37785346293.123.85.221192.168.2.13
    Sep 30, 2024 00:22:45.064456940 CEST534623778192.168.2.1393.123.85.221
    Sep 30, 2024 00:22:45.071191072 CEST37785346293.123.85.221192.168.2.13
    Sep 30, 2024 00:22:46.065321922 CEST534643778192.168.2.1393.123.85.221
    Sep 30, 2024 00:22:46.071752071 CEST37785346493.123.85.221192.168.2.13
    Sep 30, 2024 00:22:46.071822882 CEST534643778192.168.2.1393.123.85.221
    Sep 30, 2024 00:22:46.071852922 CEST534643778192.168.2.1393.123.85.221
    Sep 30, 2024 00:22:46.078413963 CEST37785346493.123.85.221192.168.2.13
    Sep 30, 2024 00:22:46.078457117 CEST534643778192.168.2.1393.123.85.221
    Sep 30, 2024 00:22:46.084988117 CEST37785346493.123.85.221192.168.2.13
    Sep 30, 2024 00:23:06.086991072 CEST534643778192.168.2.1393.123.85.221
    Sep 30, 2024 00:23:06.093550920 CEST37785346493.123.85.221192.168.2.13
    Sep 30, 2024 00:23:07.453773975 CEST37785346493.123.85.221192.168.2.13
    Sep 30, 2024 00:23:07.453861952 CEST534643778192.168.2.1393.123.85.221
    Sep 30, 2024 00:23:07.460421085 CEST37785346493.123.85.221192.168.2.13
    Sep 30, 2024 00:23:08.454765081 CEST534663778192.168.2.1393.123.85.221
    Sep 30, 2024 00:23:08.459868908 CEST37785346693.123.85.221192.168.2.13
    Sep 30, 2024 00:23:08.459943056 CEST534663778192.168.2.1393.123.85.221
    Sep 30, 2024 00:23:08.459981918 CEST534663778192.168.2.1393.123.85.221
    Sep 30, 2024 00:23:08.464797020 CEST37785346693.123.85.221192.168.2.13
    Sep 30, 2024 00:23:08.464839935 CEST534663778192.168.2.1393.123.85.221
    Sep 30, 2024 00:23:08.469708920 CEST37785346693.123.85.221192.168.2.13
    Sep 30, 2024 00:23:29.863878965 CEST37785346693.123.85.221192.168.2.13
    Sep 30, 2024 00:23:29.864000082 CEST534663778192.168.2.1393.123.85.221
    Sep 30, 2024 00:23:29.870290041 CEST37785346693.123.85.221192.168.2.13
    Sep 30, 2024 00:23:30.865073919 CEST534683778192.168.2.1393.123.85.221
    Sep 30, 2024 00:23:30.871682882 CEST37785346893.123.85.221192.168.2.13
    Sep 30, 2024 00:23:30.871782064 CEST534683778192.168.2.1393.123.85.221
    Sep 30, 2024 00:23:30.871835947 CEST534683778192.168.2.1393.123.85.221
    Sep 30, 2024 00:23:30.878452063 CEST37785346893.123.85.221192.168.2.13
    Sep 30, 2024 00:23:30.878565073 CEST534683778192.168.2.1393.123.85.221
    Sep 30, 2024 00:23:30.884170055 CEST37785346893.123.85.221192.168.2.13
    Sep 30, 2024 00:23:40.879008055 CEST534683778192.168.2.1393.123.85.221
    Sep 30, 2024 00:23:40.884428024 CEST37785346893.123.85.221192.168.2.13
    Sep 30, 2024 00:23:52.253580093 CEST37785346893.123.85.221192.168.2.13
    Sep 30, 2024 00:23:52.253659964 CEST534683778192.168.2.1393.123.85.221
    Sep 30, 2024 00:23:52.260044098 CEST37785346893.123.85.221192.168.2.13
    Sep 30, 2024 00:23:53.254683971 CEST534703778192.168.2.1393.123.85.221
    Sep 30, 2024 00:23:53.259589911 CEST37785347093.123.85.221192.168.2.13
    Sep 30, 2024 00:23:53.259649038 CEST534703778192.168.2.1393.123.85.221
    Sep 30, 2024 00:23:53.259685040 CEST534703778192.168.2.1393.123.85.221
    Sep 30, 2024 00:23:53.264509916 CEST37785347093.123.85.221192.168.2.13
    Sep 30, 2024 00:23:53.264555931 CEST534703778192.168.2.1393.123.85.221
    Sep 30, 2024 00:23:53.269315958 CEST37785347093.123.85.221192.168.2.13
    Sep 30, 2024 00:24:13.275023937 CEST534703778192.168.2.1393.123.85.221
    Sep 30, 2024 00:24:13.281611919 CEST37785347093.123.85.221192.168.2.13
    Sep 30, 2024 00:24:14.626642942 CEST37785347093.123.85.221192.168.2.13
    Sep 30, 2024 00:24:14.626741886 CEST534703778192.168.2.1393.123.85.221
    Sep 30, 2024 00:24:14.633460999 CEST37785347093.123.85.221192.168.2.13
    Sep 30, 2024 00:24:15.628248930 CEST534723778192.168.2.1393.123.85.221
    Sep 30, 2024 00:24:15.640650988 CEST37785347293.123.85.221192.168.2.13
    Sep 30, 2024 00:24:15.640718937 CEST534723778192.168.2.1393.123.85.221
    Sep 30, 2024 00:24:15.640841007 CEST534723778192.168.2.1393.123.85.221
    Sep 30, 2024 00:24:15.647418022 CEST37785347293.123.85.221192.168.2.13
    Sep 30, 2024 00:24:15.649389982 CEST534723778192.168.2.1393.123.85.221
    Sep 30, 2024 00:24:15.655911922 CEST37785347293.123.85.221192.168.2.13

    System Behavior

    Start time (UTC):22:20:53
    Start date (UTC):29/09/2024
    Path:/tmp/SecuriteInfo.com.Linux.Siggen.9999.6640.19420.elf
    Arguments:/tmp/SecuriteInfo.com.Linux.Siggen.9999.6640.19420.elf
    File size:30220 bytes
    MD5 hash:7107b1cd2e054b027ba94c7acb00df60

    Start time (UTC):22:20:53
    Start date (UTC):29/09/2024
    Path:/tmp/SecuriteInfo.com.Linux.Siggen.9999.6640.19420.elf
    Arguments:-
    File size:30220 bytes
    MD5 hash:7107b1cd2e054b027ba94c7acb00df60

    Start time (UTC):22:20:53
    Start date (UTC):29/09/2024
    Path:/tmp/SecuriteInfo.com.Linux.Siggen.9999.6640.19420.elf
    Arguments:-
    File size:30220 bytes
    MD5 hash:7107b1cd2e054b027ba94c7acb00df60

    Start time (UTC):22:20:53
    Start date (UTC):29/09/2024
    Path:/usr/libexec/gnome-session-binary
    Arguments:-
    File size:334664 bytes
    MD5 hash:d9b90be4f7db60cb3c2d3da6a1d31bfb

    Start time (UTC):22:20:53
    Start date (UTC):29/09/2024
    Path:/bin/sh
    Arguments:/bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-rfkill
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):22:20:53
    Start date (UTC):29/09/2024
    Path:/usr/libexec/gsd-rfkill
    Arguments:/usr/libexec/gsd-rfkill
    File size:51808 bytes
    MD5 hash:88a16a3c0aba1759358c06215ecfb5cc