Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
SecuriteInfo.com.Linux.Siggen.9999.19167.28364.elf

Overview

General Information

Sample name:SecuriteInfo.com.Linux.Siggen.9999.19167.28364.elf
Analysis ID:1522347
MD5:d2b3ab46391ff3f030474f2cc7af22e2
SHA1:ff81bb4309250372403e590ff3d72222eed5d113
SHA256:6ca89c25380c49e38c4715c731a14472f6b4984147c904d20128e564d4c230c3
Tags:elf
Infos:

Detection

Mirai
Score:72
Range:0 - 100
Whitelisted:false

Signatures

Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Yara detected Mirai
Machine Learning detection for sample
Sample is packed with UPX
Creates hidden files and/or directories
Detected TCP or UDP traffic on non-standard ports
ELF contains segments with high entropy indicating compressed/encrypted content
Enumerates processes within the "proc" file system
Sample contains only a LOAD segment without any section mappings
Sample tries to kill a process (SIGKILL)
Uses the "uname" system call to query kernel version information (possible evasion)
Yara signature match

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1522347
Start date and time:2024-09-30 00:24:52 +02:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 54s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:SecuriteInfo.com.Linux.Siggen.9999.19167.28364.elf
Detection:MAL
Classification:mal72.troj.evad.linELF@0/0@0/0
  • VT rate limit hit for: SecuriteInfo.com.Linux.Siggen.9999.19167.28364.elf
Command:/tmp/SecuriteInfo.com.Linux.Siggen.9999.19167.28364.elf
PID:5428
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
lzrd cock fest"/proc/"/exe
Standard Error:
  • system is lnxubuntu20
  • sh (PID: 5445, Parent: 1588, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-rfkill
  • gsd-rfkill (PID: 5445, Parent: 1588, MD5: 88a16a3c0aba1759358c06215ecfb5cc) Arguments: /usr/libexec/gsd-rfkill
  • systemd New Fork (PID: 5452, Parent: 1)
  • systemd-hostnamed (PID: 5452, Parent: 1, MD5: 2cc8a5576629a2d5bd98e49a4b8bef65) Arguments: /lib/systemd/systemd-hostnamed
  • gdm3 New Fork (PID: 5587, Parent: 1400)
  • Default (PID: 5587, Parent: 1400, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /etc/gdm3/PrimeOff/Default
  • gdm3 New Fork (PID: 5590, Parent: 1400)
  • Default (PID: 5590, Parent: 1400, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /etc/gdm3/PrimeOff/Default
  • systemd New Fork (PID: 5601, Parent: 1)
  • systemd-user-runtime-dir (PID: 5601, Parent: 1, MD5: d55f4b0847f88131dbcfb07435178e54) Arguments: /lib/systemd/systemd-user-runtime-dir stop 127
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
MiraiMirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese. Nowadays it targets a wide range of networked embedded devices such as IP cameras, home routers (many vendors involved), and other IoT devices. Since the source code was published on "Hack Forums" many variants of the Mirai family appeared, infecting mostly home networks all around the world.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/elf.mirai
SourceRuleDescriptionAuthorStrings
5428.1.0000000008048000.0000000008059000.r-x.sdmpJoeSecurity_Mirai_8Yara detected MiraiJoe Security
    5428.1.0000000008048000.0000000008059000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
    • 0xe780:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xe794:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xe7a8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xe7bc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xe7d0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xe7e4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xe7f8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xe80c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xe820:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xe834:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xe848:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xe85c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xe870:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xe884:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xe898:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xe8ac:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xe8c0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xe8d4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xe8e8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xe8fc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xe910:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    5428.1.0000000008048000.0000000008059000.r-x.sdmpLinux_Trojan_Gafgyt_ea92cca8unknownunknown
    • 0xecd8:$a: 53 65 6C 66 20 52 65 70 20 46 75 63 6B 69 6E 67 20 4E 65 54 69 53 20 61 6E 64
    5428.1.0000000008048000.0000000008059000.r-x.sdmpLinux_Trojan_Mirai_268aac0bunknownunknown
    • 0x755f:$a: 24 18 0F B7 44 24 20 8B 54 24 1C 83 F9 01 8B 7E 0C 89 04 24 8B
    5428.1.0000000008048000.0000000008059000.r-x.sdmpLinux_Trojan_Mirai_0cb1699cunknownunknown
    • 0x7512:$a: DB 8B 4C 24 0C 8B 54 24 08 83 F9 01 76 10 0F B7 02 83 E9 02 83
    Click to see the 8 entries
    No Suricata rule has matched

    Click to jump to signature section

    Show All Signature Results

    AV Detection

    barindex
    Source: SecuriteInfo.com.Linux.Siggen.9999.19167.28364.elfReversingLabs: Detection: 39%
    Source: SecuriteInfo.com.Linux.Siggen.9999.19167.28364.elfJoe Sandbox ML: detected
    Source: global trafficTCP traffic: 192.168.2.13:53452 -> 93.123.85.221:3778
    Source: unknownTCP traffic detected without corresponding DNS query: 93.123.85.221
    Source: unknownTCP traffic detected without corresponding DNS query: 93.123.85.221
    Source: unknownTCP traffic detected without corresponding DNS query: 93.123.85.221
    Source: unknownTCP traffic detected without corresponding DNS query: 93.123.85.221
    Source: unknownTCP traffic detected without corresponding DNS query: 93.123.85.221
    Source: unknownTCP traffic detected without corresponding DNS query: 93.123.85.221
    Source: unknownTCP traffic detected without corresponding DNS query: 93.123.85.221
    Source: unknownTCP traffic detected without corresponding DNS query: 93.123.85.221
    Source: unknownTCP traffic detected without corresponding DNS query: 93.123.85.221
    Source: unknownTCP traffic detected without corresponding DNS query: 93.123.85.221
    Source: unknownTCP traffic detected without corresponding DNS query: 93.123.85.221
    Source: unknownTCP traffic detected without corresponding DNS query: 93.123.85.221
    Source: unknownTCP traffic detected without corresponding DNS query: 93.123.85.221
    Source: unknownTCP traffic detected without corresponding DNS query: 93.123.85.221
    Source: unknownTCP traffic detected without corresponding DNS query: 93.123.85.221
    Source: unknownTCP traffic detected without corresponding DNS query: 93.123.85.221
    Source: unknownTCP traffic detected without corresponding DNS query: 93.123.85.221
    Source: unknownTCP traffic detected without corresponding DNS query: 93.123.85.221
    Source: unknownTCP traffic detected without corresponding DNS query: 93.123.85.221
    Source: unknownTCP traffic detected without corresponding DNS query: 93.123.85.221
    Source: unknownTCP traffic detected without corresponding DNS query: 93.123.85.221
    Source: unknownTCP traffic detected without corresponding DNS query: 93.123.85.221
    Source: unknownTCP traffic detected without corresponding DNS query: 93.123.85.221
    Source: unknownTCP traffic detected without corresponding DNS query: 93.123.85.221
    Source: unknownTCP traffic detected without corresponding DNS query: 93.123.85.221
    Source: unknownTCP traffic detected without corresponding DNS query: 93.123.85.221
    Source: unknownTCP traffic detected without corresponding DNS query: 93.123.85.221
    Source: unknownTCP traffic detected without corresponding DNS query: 93.123.85.221
    Source: unknownTCP traffic detected without corresponding DNS query: 93.123.85.221
    Source: unknownTCP traffic detected without corresponding DNS query: 93.123.85.221
    Source: unknownTCP traffic detected without corresponding DNS query: 93.123.85.221
    Source: unknownTCP traffic detected without corresponding DNS query: 93.123.85.221
    Source: unknownTCP traffic detected without corresponding DNS query: 93.123.85.221
    Source: unknownTCP traffic detected without corresponding DNS query: 93.123.85.221
    Source: unknownTCP traffic detected without corresponding DNS query: 93.123.85.221
    Source: unknownTCP traffic detected without corresponding DNS query: 93.123.85.221
    Source: unknownTCP traffic detected without corresponding DNS query: 93.123.85.221
    Source: unknownTCP traffic detected without corresponding DNS query: 93.123.85.221
    Source: unknownTCP traffic detected without corresponding DNS query: 93.123.85.221
    Source: unknownTCP traffic detected without corresponding DNS query: 93.123.85.221
    Source: unknownTCP traffic detected without corresponding DNS query: 93.123.85.221
    Source: unknownTCP traffic detected without corresponding DNS query: 93.123.85.221
    Source: unknownTCP traffic detected without corresponding DNS query: 93.123.85.221
    Source: unknownTCP traffic detected without corresponding DNS query: 93.123.85.221
    Source: unknownTCP traffic detected without corresponding DNS query: 93.123.85.221
    Source: unknownTCP traffic detected without corresponding DNS query: 93.123.85.221
    Source: unknownTCP traffic detected without corresponding DNS query: 93.123.85.221
    Source: unknownTCP traffic detected without corresponding DNS query: 93.123.85.221
    Source: unknownTCP traffic detected without corresponding DNS query: 93.123.85.221
    Source: unknownTCP traffic detected without corresponding DNS query: 93.123.85.221
    Source: SecuriteInfo.com.Linux.Siggen.9999.19167.28364.elfString found in binary or memory: http://upx.sf.net

    System Summary

    barindex
    Source: 5428.1.0000000008048000.0000000008059000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
    Source: 5428.1.0000000008048000.0000000008059000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown
    Source: 5428.1.0000000008048000.0000000008059000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_268aac0b Author: unknown
    Source: 5428.1.0000000008048000.0000000008059000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_0cb1699c Author: unknown
    Source: 5428.1.0000000008048000.0000000008059000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_70ef58f1 Author: unknown
    Source: 5428.1.0000000008048000.0000000008059000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_2e3f67a9 Author: unknown
    Source: 5428.1.0000000008048000.0000000008059000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_0d73971c Author: unknown
    Source: 5428.1.0000000008048000.0000000008059000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_88de437f Author: unknown
    Source: 5428.1.0000000008048000.0000000008059000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_cc93863b Author: unknown
    Source: Process Memory Space: SecuriteInfo.com.Linux.Siggen.9999.19167.28364.elf PID: 5428, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
    Source: Process Memory Space: SecuriteInfo.com.Linux.Siggen.9999.19167.28364.elf PID: 5428, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown
    Source: LOAD without section mappingsProgram segment: 0xc01000
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.19167.28364.elf (PID: 5429)SIGKILL sent: pid: 914, result: successfulJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.19167.28364.elf (PID: 5429)SIGKILL sent: pid: 917, result: successfulJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.19167.28364.elf (PID: 5429)SIGKILL sent: pid: 936, result: successfulJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.19167.28364.elf (PID: 5429)SIGKILL sent: pid: 1238, result: successfulJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.19167.28364.elf (PID: 5429)SIGKILL sent: pid: 1320, result: successfulJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.19167.28364.elf (PID: 5429)SIGKILL sent: pid: 1884, result: successfulJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.19167.28364.elf (PID: 5429)SIGKILL sent: pid: 5445, result: successfulJump to behavior
    Source: 5428.1.0000000008048000.0000000008059000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
    Source: 5428.1.0000000008048000.0000000008059000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16
    Source: 5428.1.0000000008048000.0000000008059000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_268aac0b reference_sample = 49c94d184d7e387c3efe34ae6f021e011c3046ae631c9733ab0a230d5fe28ead, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 9c581721bf82af7dc6482a2c41af5fb3404e01c82545c7b2b29230f707014781, id = 268aac0b-c5c7-4035-8381-4e182de91e32, last_modified = 2021-09-16
    Source: 5428.1.0000000008048000.0000000008059000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_0cb1699c reference_sample = fc8741f67f39e7409ab2c6c62d4f9acdd168d3e53cf6976dd87501833771cacb, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 6e44c68bba8c9fb53ac85080b9ad765579f027cabfea5055a0bb3a85b8671089, id = 0cb1699c-9a08-4885-aa7f-0f1ee2543cac, last_modified = 2021-09-16
    Source: 5428.1.0000000008048000.0000000008059000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_70ef58f1 reference_sample = fc8741f67f39e7409ab2c6c62d4f9acdd168d3e53cf6976dd87501833771cacb, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = c46eac9185e5f396456004d1e0c42b54a9318e0450f797c55703122cfb8fea89, id = 70ef58f1-ac74-4e33-ae03-e68d1d5a4379, last_modified = 2021-09-16
    Source: 5428.1.0000000008048000.0000000008059000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_2e3f67a9 reference_sample = fc8741f67f39e7409ab2c6c62d4f9acdd168d3e53cf6976dd87501833771cacb, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 6a06815f3d2e5f1a7a67f4264953dbb2e9d14e5f3486b178da845eab5b922d4f, id = 2e3f67a9-6fd5-4457-a626-3a9015bdb401, last_modified = 2021-09-16
    Source: 5428.1.0000000008048000.0000000008059000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_0d73971c reference_sample = 49c94d184d7e387c3efe34ae6f021e011c3046ae631c9733ab0a230d5fe28ead, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 95279bc45936ca867efb30040354c8ff81de31dccda051cfd40b4fb268c228c5, id = 0d73971c-4253-4e7d-b1e1-20b031197f9e, last_modified = 2021-09-16
    Source: 5428.1.0000000008048000.0000000008059000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_88de437f reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = c19eb595c2b444a809bef8500c20342c9f46694d3018e268833f9b884133a1ea, id = 88de437f-9c98-4e1d-96c0-7b433c99886a, last_modified = 2021-09-16
    Source: 5428.1.0000000008048000.0000000008059000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_cc93863b reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = f3ecd30f0b511a8e92cfa642409d559e7612c3f57a1659ca46c77aca809a00ac, id = cc93863b-1050-40ba-9d02-5ec9ce6a3a28, last_modified = 2022-01-26
    Source: Process Memory Space: SecuriteInfo.com.Linux.Siggen.9999.19167.28364.elf PID: 5428, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
    Source: Process Memory Space: SecuriteInfo.com.Linux.Siggen.9999.19167.28364.elf PID: 5428, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16
    Source: classification engineClassification label: mal72.troj.evad.linELF@0/0@0/0

    Data Obfuscation

    barindex
    Source: initial sampleString containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $
    Source: initial sampleString containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $
    Source: initial sampleString containing UPX found: $Id: UPX 3.94 Copyright (C) 1996-2017 the UPX Team. All Rights Reserved. $
    Source: /usr/libexec/gsd-rfkill (PID: 5445)Directory: <invalid fd (9)>/..Jump to behavior
    Source: /usr/libexec/gsd-rfkill (PID: 5445)Directory: <invalid fd (8)>/..Jump to behavior
    Source: /lib/systemd/systemd-hostnamed (PID: 5452)Directory: <invalid fd (10)>/..Jump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.19167.28364.elf (PID: 5429)File opened: /proc/230/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.19167.28364.elf (PID: 5429)File opened: /proc/110/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.19167.28364.elf (PID: 5429)File opened: /proc/231/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.19167.28364.elf (PID: 5429)File opened: /proc/111/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.19167.28364.elf (PID: 5429)File opened: /proc/232/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.19167.28364.elf (PID: 5429)File opened: /proc/112/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.19167.28364.elf (PID: 5429)File opened: /proc/233/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.19167.28364.elf (PID: 5429)File opened: /proc/113/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.19167.28364.elf (PID: 5429)File opened: /proc/234/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.19167.28364.elf (PID: 5429)File opened: /proc/114/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.19167.28364.elf (PID: 5429)File opened: /proc/235/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.19167.28364.elf (PID: 5429)File opened: /proc/115/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.19167.28364.elf (PID: 5429)File opened: /proc/236/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.19167.28364.elf (PID: 5429)File opened: /proc/116/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.19167.28364.elf (PID: 5429)File opened: /proc/237/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.19167.28364.elf (PID: 5429)File opened: /proc/117/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.19167.28364.elf (PID: 5429)File opened: /proc/238/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.19167.28364.elf (PID: 5429)File opened: /proc/118/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.19167.28364.elf (PID: 5429)File opened: /proc/239/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.19167.28364.elf (PID: 5429)File opened: /proc/119/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.19167.28364.elf (PID: 5429)File opened: /proc/914/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.19167.28364.elf (PID: 5429)File opened: /proc/10/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.19167.28364.elf (PID: 5429)File opened: /proc/917/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.19167.28364.elf (PID: 5429)File opened: /proc/11/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.19167.28364.elf (PID: 5429)File opened: /proc/12/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.19167.28364.elf (PID: 5429)File opened: /proc/13/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.19167.28364.elf (PID: 5429)File opened: /proc/5274/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.19167.28364.elf (PID: 5429)File opened: /proc/14/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.19167.28364.elf (PID: 5429)File opened: /proc/15/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.19167.28364.elf (PID: 5429)File opened: /proc/16/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.19167.28364.elf (PID: 5429)File opened: /proc/17/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.19167.28364.elf (PID: 5429)File opened: /proc/18/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.19167.28364.elf (PID: 5429)File opened: /proc/19/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.19167.28364.elf (PID: 5429)File opened: /proc/240/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.19167.28364.elf (PID: 5429)File opened: /proc/3095/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.19167.28364.elf (PID: 5429)File opened: /proc/120/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.19167.28364.elf (PID: 5429)File opened: /proc/241/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.19167.28364.elf (PID: 5429)File opened: /proc/0/statJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.19167.28364.elf (PID: 5429)File opened: /proc/121/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.19167.28364.elf (PID: 5429)File opened: /proc/242/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.19167.28364.elf (PID: 5429)File opened: /proc/1/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.19167.28364.elf (PID: 5429)File opened: /proc/122/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.19167.28364.elf (PID: 5429)File opened: /proc/243/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.19167.28364.elf (PID: 5429)File opened: /proc/2/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.19167.28364.elf (PID: 5429)File opened: /proc/123/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.19167.28364.elf (PID: 5429)File opened: /proc/244/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.19167.28364.elf (PID: 5429)File opened: /proc/3/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.19167.28364.elf (PID: 5429)File opened: /proc/124/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.19167.28364.elf (PID: 5429)File opened: /proc/245/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.19167.28364.elf (PID: 5429)File opened: /proc/1588/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.19167.28364.elf (PID: 5429)File opened: /proc/125/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.19167.28364.elf (PID: 5429)File opened: /proc/4/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.19167.28364.elf (PID: 5429)File opened: /proc/246/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.19167.28364.elf (PID: 5429)File opened: /proc/126/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.19167.28364.elf (PID: 5429)File opened: /proc/5/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.19167.28364.elf (PID: 5429)File opened: /proc/247/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.19167.28364.elf (PID: 5429)File opened: /proc/127/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.19167.28364.elf (PID: 5429)File opened: /proc/6/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.19167.28364.elf (PID: 5429)File opened: /proc/248/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.19167.28364.elf (PID: 5429)File opened: /proc/128/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.19167.28364.elf (PID: 5429)File opened: /proc/7/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.19167.28364.elf (PID: 5429)File opened: /proc/249/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.19167.28364.elf (PID: 5429)File opened: /proc/129/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.19167.28364.elf (PID: 5429)File opened: /proc/8/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.19167.28364.elf (PID: 5429)File opened: /proc/800/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.19167.28364.elf (PID: 5429)File opened: /proc/9/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.19167.28364.elf (PID: 5429)File opened: /proc/1906/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.19167.28364.elf (PID: 5429)File opened: /proc/802/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.19167.28364.elf (PID: 5429)File opened: /proc/803/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.19167.28364.elf (PID: 5429)File opened: /proc/20/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.19167.28364.elf (PID: 5429)File opened: /proc/21/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.19167.28364.elf (PID: 5429)File opened: /proc/22/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.19167.28364.elf (PID: 5429)File opened: /proc/23/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.19167.28364.elf (PID: 5429)File opened: /proc/24/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.19167.28364.elf (PID: 5429)File opened: /proc/25/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.19167.28364.elf (PID: 5429)File opened: /proc/26/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.19167.28364.elf (PID: 5429)File opened: /proc/27/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.19167.28364.elf (PID: 5429)File opened: /proc/28/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.19167.28364.elf (PID: 5429)File opened: /proc/29/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.19167.28364.elf (PID: 5429)File opened: /proc/3420/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.19167.28364.elf (PID: 5429)File opened: /proc/1482/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.19167.28364.elf (PID: 5429)File opened: /proc/490/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.19167.28364.elf (PID: 5429)File opened: /proc/1480/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.19167.28364.elf (PID: 5429)File opened: /proc/250/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.19167.28364.elf (PID: 5429)File opened: /proc/371/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.19167.28364.elf (PID: 5429)File opened: /proc/130/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.19167.28364.elf (PID: 5429)File opened: /proc/251/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.19167.28364.elf (PID: 5429)File opened: /proc/131/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.19167.28364.elf (PID: 5429)File opened: /proc/252/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.19167.28364.elf (PID: 5429)File opened: /proc/132/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.19167.28364.elf (PID: 5429)File opened: /proc/253/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.19167.28364.elf (PID: 5429)File opened: /proc/254/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.19167.28364.elf (PID: 5429)File opened: /proc/1238/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.19167.28364.elf (PID: 5429)File opened: /proc/134/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.19167.28364.elf (PID: 5429)File opened: /proc/255/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.19167.28364.elf (PID: 5429)File opened: /proc/256/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.19167.28364.elf (PID: 5429)File opened: /proc/257/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.19167.28364.elf (PID: 5429)File opened: /proc/378/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.19167.28364.elf (PID: 5429)File opened: /proc/3413/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.19167.28364.elf (PID: 5429)File opened: /proc/258/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.19167.28364.elf (PID: 5429)File opened: /proc/259/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.19167.28364.elf (PID: 5429)File opened: /proc/1475/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.19167.28364.elf (PID: 5429)File opened: /proc/936/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.19167.28364.elf (PID: 5429)File opened: /proc/30/cmdlineJump to behavior
    Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.19167.28364.elf (PID: 5429)File opened: /proc/816/cmdlineJump to behavior
    Source: SecuriteInfo.com.Linux.Siggen.9999.19167.28364.elfSubmission file: segment LOAD with 7.8861 entropy (max. 8.0)
    Source: /lib/systemd/systemd-hostnamed (PID: 5452)Queries kernel information via 'uname': Jump to behavior

    Stealing of Sensitive Information

    barindex
    Source: Yara matchFile source: 5428.1.0000000008048000.0000000008059000.r-x.sdmp, type: MEMORY
    Source: Yara matchFile source: Process Memory Space: SecuriteInfo.com.Linux.Siggen.9999.19167.28364.elf PID: 5428, type: MEMORYSTR

    Remote Access Functionality

    barindex
    Source: Yara matchFile source: 5428.1.0000000008048000.0000000008059000.r-x.sdmp, type: MEMORY
    Source: Yara matchFile source: Process Memory Space: SecuriteInfo.com.Linux.Siggen.9999.19167.28364.elf PID: 5428, type: MEMORYSTR
    ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
    Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception1
    Hidden Files and Directories
    1
    OS Credential Dumping
    1
    Security Software Discovery
    Remote ServicesData from Local System1
    Non-Standard Port
    Exfiltration Over Other Network MediumAbuse Accessibility Features
    CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts11
    Obfuscated Files or Information
    LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaJunk DataExfiltration Over BluetoothNetwork Denial of Service
    No configs have been found
    Hide Legend

    Legend:

    • Process
    • Signature
    • Created File
    • DNS/IP Info
    • Is Dropped
    • Number of created Files
    • Is malicious
    • Internet
    SourceDetectionScannerLabelLink
    SecuriteInfo.com.Linux.Siggen.9999.19167.28364.elf39%ReversingLabsLinux.Backdoor.Mirai
    SecuriteInfo.com.Linux.Siggen.9999.19167.28364.elf100%Joe Sandbox ML
    No Antivirus matches
    No Antivirus matches
    SourceDetectionScannerLabelLink
    http://upx.sf.net0%URL Reputationsafe
    No contacted domains info
    NameSourceMaliciousAntivirus DetectionReputation
    http://upx.sf.netSecuriteInfo.com.Linux.Siggen.9999.19167.28364.elftrue
    • URL Reputation: safe
    unknown
    • No. of IPs < 25%
    • 25% < No. of IPs < 50%
    • 50% < No. of IPs < 75%
    • 75% < No. of IPs
    IPDomainCountryFlagASNASN NameMalicious
    93.123.85.221
    unknownBulgaria
    43561NET1-ASBGfalse
    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
    93.123.85.221SecuriteInfo.com.Linux.Siggen.9999.22134.32161.elfGet hashmaliciousMiraiBrowse
      SecuriteInfo.com.Linux.Siggen.9999.30150.23014.elfGet hashmaliciousMiraiBrowse
        SecuriteInfo.com.Linux.Siggen.9999.6640.19420.elfGet hashmaliciousMiraiBrowse
          No context
          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
          NET1-ASBGSecuriteInfo.com.Linux.Siggen.9999.22134.32161.elfGet hashmaliciousMiraiBrowse
          • 93.123.85.221
          SecuriteInfo.com.Linux.Siggen.9999.30150.23014.elfGet hashmaliciousMiraiBrowse
          • 93.123.85.221
          SecuriteInfo.com.Linux.Siggen.9999.6640.19420.elfGet hashmaliciousMiraiBrowse
          • 93.123.85.221
          KeyFormed.exeGet hashmaliciousUnknownBrowse
          • 83.222.191.195
          https://www.google.com/url?q=https%3A%2F%2Fgoo.gl%2Fotzvm%236%261afkvsGet hashmaliciousUnknownBrowse
          • 93.123.118.245
          SecuriteInfo.com.Win32.Sector.30.19697.26848.exeGet hashmaliciousSalityBrowse
          • 83.222.184.130
          SecuriteInfo.com.Linux.Siggen.9999.6145.9800.elfGet hashmaliciousMiraiBrowse
          • 93.123.85.119
          SecuriteInfo.com.Linux.Siggen.9999.20750.2018.elfGet hashmaliciousUnknownBrowse
          • 93.123.85.119
          SecuriteInfo.com.Linux.Siggen.9999.32241.1909.elfGet hashmaliciousUnknownBrowse
          • 93.123.85.119
          SecuriteInfo.com.Linux.Siggen.9999.8925.23450.elfGet hashmaliciousUnknownBrowse
          • 93.123.85.119
          No context
          No context
          No created / dropped files found
          File type:ELF 32-bit LSB executable, Intel 80386, version 1 (GNU/Linux), statically linked, no section header
          Entropy (8bit):7.882344793176877
          TrID:
          • ELF Executable and Linkable format (Linux) (4029/14) 50.16%
          • ELF Executable and Linkable format (generic) (4004/1) 49.84%
          File name:SecuriteInfo.com.Linux.Siggen.9999.19167.28364.elf
          File size:31'300 bytes
          MD5:d2b3ab46391ff3f030474f2cc7af22e2
          SHA1:ff81bb4309250372403e590ff3d72222eed5d113
          SHA256:6ca89c25380c49e38c4715c731a14472f6b4984147c904d20128e564d4c230c3
          SHA512:7e25ed78d950fa5183657c9c844f8d03f8c56d25de3de4639214a37b428bec9cbb30cfec7e860f0717f4611e524f8905e95c31787dd2591b3767ec183fa896d0
          SSDEEP:768:laKJIpUheb8ArmMapSCfGtwk+sOimldbfLPDyoxxGKX:la4IjrmHpSCfGtdOi4dbfLOoH
          TLSH:75E2F232EBC0896FC051D27614BF5BFF5AF49B63F71F4A12670808D22D8BA98641E849
          File Content Preview:.ELF....................X...4...........4. ...(.....................;y..;y.............. ... ... ...................Q.td...............................4UPX!........P...P.......`........?d..ELF.......h...m...4..... .(......m..-.#.\...................T.>...

          ELF header

          Class:ELF32
          Data:2's complement, little endian
          Version:1 (current)
          Machine:Intel 80386
          Version Number:0x1
          Type:EXEC (Executable file)
          OS/ABI:UNIX - Linux
          ABI Version:0
          Entry Point Address:0xc08158
          Flags:0x0
          ELF Header Size:52
          Program Header Offset:52
          Program Header Size:32
          Number of Program Headers:3
          Section Header Offset:0
          Section Header Size:40
          Number of Section Headers:0
          Header String Table Index:0
          TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
          LOAD0x00xc010000xc010000x793b0x793b7.88610x5R E0x1000
          LOAD0xb200x805bb200x805bb200x00x00.00000x6RW 0x1000
          GNU_STACK0x00x00x00x00x00.00000x6RW 0x4
          TimestampSource PortDest PortSource IPDest IP
          Sep 30, 2024 00:25:44.562577009 CEST534523778192.168.2.1393.123.85.221
          Sep 30, 2024 00:25:44.569293976 CEST37785345293.123.85.221192.168.2.13
          Sep 30, 2024 00:25:44.569339037 CEST534523778192.168.2.1393.123.85.221
          Sep 30, 2024 00:25:44.569572926 CEST534523778192.168.2.1393.123.85.221
          Sep 30, 2024 00:25:44.576441050 CEST37785345293.123.85.221192.168.2.13
          Sep 30, 2024 00:25:44.576491117 CEST534523778192.168.2.1393.123.85.221
          Sep 30, 2024 00:25:44.582922935 CEST37785345293.123.85.221192.168.2.13
          Sep 30, 2024 00:26:05.941004038 CEST37785345293.123.85.221192.168.2.13
          Sep 30, 2024 00:26:05.941078901 CEST534523778192.168.2.1393.123.85.221
          Sep 30, 2024 00:26:05.948236942 CEST37785345293.123.85.221192.168.2.13
          Sep 30, 2024 00:26:06.941797018 CEST534543778192.168.2.1393.123.85.221
          Sep 30, 2024 00:26:06.948640108 CEST37785345493.123.85.221192.168.2.13
          Sep 30, 2024 00:26:06.948725939 CEST534543778192.168.2.1393.123.85.221
          Sep 30, 2024 00:26:06.948725939 CEST534543778192.168.2.1393.123.85.221
          Sep 30, 2024 00:26:06.956063986 CEST37785345493.123.85.221192.168.2.13
          Sep 30, 2024 00:26:06.956861019 CEST534543778192.168.2.1393.123.85.221
          Sep 30, 2024 00:26:06.964040995 CEST37785345493.123.85.221192.168.2.13
          Sep 30, 2024 00:26:16.955163956 CEST534543778192.168.2.1393.123.85.221
          Sep 30, 2024 00:26:16.961994886 CEST37785345493.123.85.221192.168.2.13
          Sep 30, 2024 00:26:28.335844040 CEST37785345493.123.85.221192.168.2.13
          Sep 30, 2024 00:26:28.335931063 CEST534543778192.168.2.1393.123.85.221
          Sep 30, 2024 00:26:28.340683937 CEST37785345493.123.85.221192.168.2.13
          Sep 30, 2024 00:26:29.336673021 CEST534563778192.168.2.1393.123.85.221
          Sep 30, 2024 00:26:29.342642069 CEST37785345693.123.85.221192.168.2.13
          Sep 30, 2024 00:26:29.342750072 CEST534563778192.168.2.1393.123.85.221
          Sep 30, 2024 00:26:29.342750072 CEST534563778192.168.2.1393.123.85.221
          Sep 30, 2024 00:26:29.348699093 CEST37785345693.123.85.221192.168.2.13
          Sep 30, 2024 00:26:29.348762989 CEST534563778192.168.2.1393.123.85.221
          Sep 30, 2024 00:26:29.354806900 CEST37785345693.123.85.221192.168.2.13
          Sep 30, 2024 00:26:49.359076977 CEST534563778192.168.2.1393.123.85.221
          Sep 30, 2024 00:26:49.363909006 CEST37785345693.123.85.221192.168.2.13
          Sep 30, 2024 00:26:50.691324949 CEST37785345693.123.85.221192.168.2.13
          Sep 30, 2024 00:26:50.691411018 CEST534563778192.168.2.1393.123.85.221
          Sep 30, 2024 00:26:50.697375059 CEST37785345693.123.85.221192.168.2.13
          Sep 30, 2024 00:26:51.692058086 CEST534583778192.168.2.1393.123.85.221
          Sep 30, 2024 00:26:51.697695017 CEST37785345893.123.85.221192.168.2.13
          Sep 30, 2024 00:26:51.697778940 CEST534583778192.168.2.1393.123.85.221
          Sep 30, 2024 00:26:51.697818995 CEST534583778192.168.2.1393.123.85.221
          Sep 30, 2024 00:26:51.702636003 CEST37785345893.123.85.221192.168.2.13
          Sep 30, 2024 00:26:51.702682972 CEST534583778192.168.2.1393.123.85.221
          Sep 30, 2024 00:26:51.707515001 CEST37785345893.123.85.221192.168.2.13
          Sep 30, 2024 00:27:13.068284988 CEST37785345893.123.85.221192.168.2.13
          Sep 30, 2024 00:27:13.068372965 CEST534583778192.168.2.1393.123.85.221
          Sep 30, 2024 00:27:13.074450016 CEST37785345893.123.85.221192.168.2.13
          Sep 30, 2024 00:27:14.068924904 CEST534603778192.168.2.1393.123.85.221
          Sep 30, 2024 00:27:14.075542927 CEST37785346093.123.85.221192.168.2.13
          Sep 30, 2024 00:27:14.075618982 CEST534603778192.168.2.1393.123.85.221
          Sep 30, 2024 00:27:14.075648069 CEST534603778192.168.2.1393.123.85.221
          Sep 30, 2024 00:27:14.081664085 CEST37785346093.123.85.221192.168.2.13
          Sep 30, 2024 00:27:14.081736088 CEST534603778192.168.2.1393.123.85.221
          Sep 30, 2024 00:27:14.088253975 CEST37785346093.123.85.221192.168.2.13
          Sep 30, 2024 00:27:24.082984924 CEST534603778192.168.2.1393.123.85.221
          Sep 30, 2024 00:27:24.231748104 CEST37785346093.123.85.221192.168.2.13
          Sep 30, 2024 00:27:35.520359039 CEST37785346093.123.85.221192.168.2.13
          Sep 30, 2024 00:27:35.520443916 CEST534603778192.168.2.1393.123.85.221
          Sep 30, 2024 00:27:35.525387049 CEST37785346093.123.85.221192.168.2.13
          Sep 30, 2024 00:27:36.521230936 CEST534623778192.168.2.1393.123.85.221
          Sep 30, 2024 00:27:36.526156902 CEST37785346293.123.85.221192.168.2.13
          Sep 30, 2024 00:27:36.526217937 CEST534623778192.168.2.1393.123.85.221
          Sep 30, 2024 00:27:36.526251078 CEST534623778192.168.2.1393.123.85.221
          Sep 30, 2024 00:27:36.531285048 CEST37785346293.123.85.221192.168.2.13
          Sep 30, 2024 00:27:36.531330109 CEST534623778192.168.2.1393.123.85.221
          Sep 30, 2024 00:27:36.536107063 CEST37785346293.123.85.221192.168.2.13
          Sep 30, 2024 00:27:56.542771101 CEST534623778192.168.2.1393.123.85.221
          Sep 30, 2024 00:27:56.547754049 CEST37785346293.123.85.221192.168.2.13
          Sep 30, 2024 00:27:57.882030964 CEST37785346293.123.85.221192.168.2.13
          Sep 30, 2024 00:27:57.882183075 CEST534623778192.168.2.1393.123.85.221
          Sep 30, 2024 00:27:57.889905930 CEST37785346293.123.85.221192.168.2.13
          Sep 30, 2024 00:27:58.883192062 CEST534643778192.168.2.1393.123.85.221
          Sep 30, 2024 00:27:58.890032053 CEST37785346493.123.85.221192.168.2.13
          Sep 30, 2024 00:27:58.890104055 CEST534643778192.168.2.1393.123.85.221
          Sep 30, 2024 00:27:58.890168905 CEST534643778192.168.2.1393.123.85.221
          Sep 30, 2024 00:27:58.896872044 CEST37785346493.123.85.221192.168.2.13
          Sep 30, 2024 00:27:58.896929026 CEST534643778192.168.2.1393.123.85.221
          Sep 30, 2024 00:27:58.903522968 CEST37785346493.123.85.221192.168.2.13
          Sep 30, 2024 00:28:20.274796009 CEST37785346493.123.85.221192.168.2.13
          Sep 30, 2024 00:28:20.274872065 CEST534643778192.168.2.1393.123.85.221
          Sep 30, 2024 00:28:20.282594919 CEST37785346493.123.85.221192.168.2.13
          Sep 30, 2024 00:28:21.275614977 CEST534663778192.168.2.1393.123.85.221
          Sep 30, 2024 00:28:21.280386925 CEST37785346693.123.85.221192.168.2.13
          Sep 30, 2024 00:28:21.280472994 CEST534663778192.168.2.1393.123.85.221
          Sep 30, 2024 00:28:21.280497074 CEST534663778192.168.2.1393.123.85.221
          Sep 30, 2024 00:28:21.285367966 CEST37785346693.123.85.221192.168.2.13
          Sep 30, 2024 00:28:21.285433054 CEST534663778192.168.2.1393.123.85.221
          Sep 30, 2024 00:28:21.290225983 CEST37785346693.123.85.221192.168.2.13
          Sep 30, 2024 00:28:31.286865950 CEST534663778192.168.2.1393.123.85.221
          Sep 30, 2024 00:28:31.291682959 CEST37785346693.123.85.221192.168.2.13
          Sep 30, 2024 00:28:42.646090984 CEST37785346693.123.85.221192.168.2.13
          Sep 30, 2024 00:28:42.646187067 CEST534663778192.168.2.1393.123.85.221
          Sep 30, 2024 00:28:42.652559042 CEST37785346693.123.85.221192.168.2.13
          Sep 30, 2024 00:28:43.647031069 CEST534683778192.168.2.1393.123.85.221
          Sep 30, 2024 00:28:43.807035923 CEST37785346893.123.85.221192.168.2.13
          Sep 30, 2024 00:28:43.807085037 CEST534683778192.168.2.1393.123.85.221
          Sep 30, 2024 00:28:43.807127953 CEST534683778192.168.2.1393.123.85.221
          Sep 30, 2024 00:28:43.813766003 CEST37785346893.123.85.221192.168.2.13
          Sep 30, 2024 00:28:43.813822031 CEST534683778192.168.2.1393.123.85.221
          Sep 30, 2024 00:28:43.820390940 CEST37785346893.123.85.221192.168.2.13
          Sep 30, 2024 00:29:03.822549105 CEST534683778192.168.2.1393.123.85.221
          Sep 30, 2024 00:29:03.829745054 CEST37785346893.123.85.221192.168.2.13
          Sep 30, 2024 00:29:05.193761110 CEST37785346893.123.85.221192.168.2.13
          Sep 30, 2024 00:29:05.193830013 CEST534683778192.168.2.1393.123.85.221
          Sep 30, 2024 00:29:05.202384949 CEST37785346893.123.85.221192.168.2.13
          Sep 30, 2024 00:29:06.194844007 CEST534703778192.168.2.1393.123.85.221
          Sep 30, 2024 00:29:06.203681946 CEST37785347093.123.85.221192.168.2.13
          Sep 30, 2024 00:29:06.203777075 CEST534703778192.168.2.1393.123.85.221
          Sep 30, 2024 00:29:06.203805923 CEST534703778192.168.2.1393.123.85.221
          Sep 30, 2024 00:29:06.212193012 CEST37785347093.123.85.221192.168.2.13
          Sep 30, 2024 00:29:06.212261915 CEST534703778192.168.2.1393.123.85.221
          Sep 30, 2024 00:29:06.218625069 CEST37785347093.123.85.221192.168.2.13

          System Behavior

          Start time (UTC):22:25:43
          Start date (UTC):29/09/2024
          Path:/tmp/SecuriteInfo.com.Linux.Siggen.9999.19167.28364.elf
          Arguments:/tmp/SecuriteInfo.com.Linux.Siggen.9999.19167.28364.elf
          File size:31300 bytes
          MD5 hash:d2b3ab46391ff3f030474f2cc7af22e2

          Start time (UTC):22:25:43
          Start date (UTC):29/09/2024
          Path:/tmp/SecuriteInfo.com.Linux.Siggen.9999.19167.28364.elf
          Arguments:-
          File size:31300 bytes
          MD5 hash:d2b3ab46391ff3f030474f2cc7af22e2

          Start time (UTC):22:25:43
          Start date (UTC):29/09/2024
          Path:/tmp/SecuriteInfo.com.Linux.Siggen.9999.19167.28364.elf
          Arguments:-
          File size:31300 bytes
          MD5 hash:d2b3ab46391ff3f030474f2cc7af22e2

          Start time (UTC):22:25:44
          Start date (UTC):29/09/2024
          Path:/usr/libexec/gnome-session-binary
          Arguments:-
          File size:334664 bytes
          MD5 hash:d9b90be4f7db60cb3c2d3da6a1d31bfb

          Start time (UTC):22:25:44
          Start date (UTC):29/09/2024
          Path:/bin/sh
          Arguments:/bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-rfkill
          File size:129816 bytes
          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

          Start time (UTC):22:25:44
          Start date (UTC):29/09/2024
          Path:/usr/libexec/gsd-rfkill
          Arguments:/usr/libexec/gsd-rfkill
          File size:51808 bytes
          MD5 hash:88a16a3c0aba1759358c06215ecfb5cc

          Start time (UTC):22:25:45
          Start date (UTC):29/09/2024
          Path:/usr/lib/systemd/systemd
          Arguments:-
          File size:1620224 bytes
          MD5 hash:9b2bec7092a40488108543f9334aab75

          Start time (UTC):22:25:45
          Start date (UTC):29/09/2024
          Path:/lib/systemd/systemd-hostnamed
          Arguments:/lib/systemd/systemd-hostnamed
          File size:35040 bytes
          MD5 hash:2cc8a5576629a2d5bd98e49a4b8bef65

          Start time (UTC):22:25:45
          Start date (UTC):29/09/2024
          Path:/usr/sbin/gdm3
          Arguments:-
          File size:453296 bytes
          MD5 hash:2492e2d8d34f9377e3e530a61a15674f

          Start time (UTC):22:25:45
          Start date (UTC):29/09/2024
          Path:/etc/gdm3/PrimeOff/Default
          Arguments:/etc/gdm3/PrimeOff/Default
          File size:129816 bytes
          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

          Start time (UTC):22:25:45
          Start date (UTC):29/09/2024
          Path:/usr/sbin/gdm3
          Arguments:-
          File size:453296 bytes
          MD5 hash:2492e2d8d34f9377e3e530a61a15674f

          Start time (UTC):22:25:45
          Start date (UTC):29/09/2024
          Path:/etc/gdm3/PrimeOff/Default
          Arguments:/etc/gdm3/PrimeOff/Default
          File size:129816 bytes
          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

          Start time (UTC):22:25:55
          Start date (UTC):29/09/2024
          Path:/usr/lib/systemd/systemd
          Arguments:-
          File size:1620224 bytes
          MD5 hash:9b2bec7092a40488108543f9334aab75

          Start time (UTC):22:25:55
          Start date (UTC):29/09/2024
          Path:/lib/systemd/systemd-user-runtime-dir
          Arguments:/lib/systemd/systemd-user-runtime-dir stop 127
          File size:22672 bytes
          MD5 hash:d55f4b0847f88131dbcfb07435178e54