Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
SecuriteInfo.com.ELF.Mirai-CVD.5487.13505.elf

Overview

General Information

Sample name:SecuriteInfo.com.ELF.Mirai-CVD.5487.13505.elf
Analysis ID:1528446
MD5:5d959c2b7278b8c8b2c4a3f1554bb96e
SHA1:a2ff0e2fd22b31f16f2b3bcc7a3e5ac61c03f5d0
SHA256:727d897cbf2466bc6390ec82e4056aa5047597390719fd1c556fef01303d91bd
Tags:elf
Infos:

Detection

Score:60
Range:0 - 100
Whitelisted:false

Signatures

Connects to many ports of the same IP (likely port scanning)
Opens /sys/class/net/* files useful for querying network interface information
Performs DNS TXT record lookups
Sample deletes itself
Sample scans a subnet
Detected TCP or UDP traffic on non-standard ports
Executes the "rm" command used to delete files or directories
Sample has stripped symbol table
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1528446
Start date and time:2024-10-07 22:44:14 +02:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 41s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:SecuriteInfo.com.ELF.Mirai-CVD.5487.13505.elf
Detection:MAL
Classification:mal60.spre.troj.spyw.evad.linELF@0/0@1/0
  • VT rate limit hit for: SecuriteInfo.com.ELF.Mirai-CVD.5487.13505.elf
Command:/tmp/SecuriteInfo.com.ELF.Mirai-CVD.5487.13505.elf
PID:5624
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
Firmware update in progress
Standard Error:
  • system is lnxubuntu20
  • dash New Fork (PID: 5605, Parent: 3678)
  • rm (PID: 5605, Parent: 3678, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.O4CuIEpsBu /tmp/tmp.vVFwAXA4E6 /tmp/tmp.brf0F1ZgS2
  • dash New Fork (PID: 5606, Parent: 3678)
  • rm (PID: 5606, Parent: 3678, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.O4CuIEpsBu /tmp/tmp.vVFwAXA4E6 /tmp/tmp.brf0F1ZgS2
  • cleanup
No yara matches
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

Networking

barindex
Source: global trafficTCP traffic: 5.230.171.8 ports 22022,3,4,3478,3544,7,8
Source: global trafficTCP traffic: 5.230.122.80 ports 7000,34567,3,4,5,6,3389,7
Source: global trafficTCP traffic: 94.131.118.154 ports 35000,0,1,2,4,27014,7
Source: /tmp/SecuriteInfo.com.ELF.Mirai-CVD.5487.13505.elf (PID: 5628)Opens: /sys/class/net/Jump to behavior
Source: /tmp/SecuriteInfo.com.ELF.Mirai-CVD.5487.13505.elf (PID: 5628)Opens: /sys/class/net/ens160/addressJump to behavior
Source: /tmp/SecuriteInfo.com.ELF.Mirai-CVD.5487.13505.elf (PID: 5628)Opens: /sys/class/net/ens160/flagsJump to behavior
Source: /tmp/SecuriteInfo.com.ELF.Mirai-CVD.5487.13505.elf (PID: 5628)Opens: /sys/class/net/ens160/carrierJump to behavior
Source: ip trafficSubnet 5.230.228.0/24: 5.230.228.47, 5.230.228.46, 5.230.228.42, 5.230.228.44, 5.230.228.62
Source: global trafficTCP traffic: 192.168.2.15:34592 -> 185.248.144.209:7000
Source: global trafficTCP traffic: 192.168.2.15:56206 -> 5.230.171.8:3478
Source: global trafficTCP traffic: 192.168.2.15:60560 -> 5.230.228.44:10001
Source: global trafficTCP traffic: 192.168.2.15:49554 -> 5.230.171.9:7777
Source: global trafficTCP traffic: 192.168.2.15:45434 -> 194.156.98.15:993
Source: global trafficTCP traffic: 192.168.2.15:39694 -> 5.230.228.47:2022
Source: global trafficTCP traffic: 192.168.2.15:55080 -> 5.230.122.80:34567
Source: global trafficTCP traffic: 192.168.2.15:50404 -> 5.230.228.46:2022
Source: global trafficTCP traffic: 192.168.2.15:60072 -> 5.230.122.82:3389
Source: global trafficTCP traffic: 192.168.2.15:33758 -> 5.230.228.62:993
Source: global trafficTCP traffic: 192.168.2.15:37800 -> 94.131.118.154:27014
Source: global trafficTCP traffic: 192.168.2.15:41856 -> 5.230.228.42:19153
Source: global trafficTCP traffic: 192.168.2.15:50728 -> 5.230.118.247:9000
Source: unknownTCP traffic detected without corresponding DNS query: 185.248.144.209
Source: unknownTCP traffic detected without corresponding DNS query: 185.248.144.209
Source: unknownTCP traffic detected without corresponding DNS query: 185.248.144.209
Source: unknownTCP traffic detected without corresponding DNS query: 185.248.144.209
Source: unknownTCP traffic detected without corresponding DNS query: 5.230.171.8
Source: unknownTCP traffic detected without corresponding DNS query: 5.230.171.8
Source: unknownTCP traffic detected without corresponding DNS query: 5.230.171.8
Source: unknownTCP traffic detected without corresponding DNS query: 5.230.171.8
Source: unknownTCP traffic detected without corresponding DNS query: 5.230.228.44
Source: unknownTCP traffic detected without corresponding DNS query: 5.230.228.44
Source: unknownTCP traffic detected without corresponding DNS query: 5.230.228.44
Source: unknownTCP traffic detected without corresponding DNS query: 5.230.228.44
Source: unknownTCP traffic detected without corresponding DNS query: 5.230.171.9
Source: unknownTCP traffic detected without corresponding DNS query: 5.230.171.9
Source: unknownTCP traffic detected without corresponding DNS query: 5.230.171.9
Source: unknownTCP traffic detected without corresponding DNS query: 5.230.171.9
Source: unknownTCP traffic detected without corresponding DNS query: 5.230.171.9
Source: unknownTCP traffic detected without corresponding DNS query: 5.230.171.9
Source: unknownTCP traffic detected without corresponding DNS query: 5.230.171.9
Source: unknownTCP traffic detected without corresponding DNS query: 5.230.171.9
Source: unknownTCP traffic detected without corresponding DNS query: 194.156.98.15
Source: unknownTCP traffic detected without corresponding DNS query: 194.156.98.15
Source: unknownTCP traffic detected without corresponding DNS query: 194.156.98.15
Source: unknownTCP traffic detected without corresponding DNS query: 194.156.98.15
Source: unknownTCP traffic detected without corresponding DNS query: 5.230.171.8
Source: unknownTCP traffic detected without corresponding DNS query: 5.230.171.8
Source: unknownTCP traffic detected without corresponding DNS query: 5.230.171.8
Source: unknownTCP traffic detected without corresponding DNS query: 5.230.171.8
Source: unknownTCP traffic detected without corresponding DNS query: 5.230.228.47
Source: unknownTCP traffic detected without corresponding DNS query: 5.230.228.47
Source: unknownTCP traffic detected without corresponding DNS query: 5.230.228.47
Source: unknownTCP traffic detected without corresponding DNS query: 5.230.228.47
Source: unknownTCP traffic detected without corresponding DNS query: 5.230.122.80
Source: unknownTCP traffic detected without corresponding DNS query: 5.230.122.80
Source: unknownTCP traffic detected without corresponding DNS query: 5.230.122.80
Source: unknownTCP traffic detected without corresponding DNS query: 5.230.122.80
Source: unknownTCP traffic detected without corresponding DNS query: 5.230.171.8
Source: unknownTCP traffic detected without corresponding DNS query: 5.230.171.8
Source: unknownTCP traffic detected without corresponding DNS query: 5.230.171.8
Source: unknownTCP traffic detected without corresponding DNS query: 5.230.171.8
Source: unknownTCP traffic detected without corresponding DNS query: 185.248.144.209
Source: unknownTCP traffic detected without corresponding DNS query: 185.248.144.209
Source: unknownTCP traffic detected without corresponding DNS query: 185.248.144.209
Source: unknownTCP traffic detected without corresponding DNS query: 185.248.144.209
Source: unknownTCP traffic detected without corresponding DNS query: 194.156.98.15
Source: unknownTCP traffic detected without corresponding DNS query: 194.156.98.15
Source: unknownTCP traffic detected without corresponding DNS query: 194.156.98.15
Source: unknownTCP traffic detected without corresponding DNS query: 194.156.98.15
Source: unknownTCP traffic detected without corresponding DNS query: 5.230.228.46
Source: unknownTCP traffic detected without corresponding DNS query: 5.230.228.46
Source: global trafficDNS traffic detected: DNS query: iranistrash.libre
Source: unknownNetwork traffic detected: HTTP traffic on port 60874 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 60874
Source: ELF static info symbol of initial sample.symtab present: no
Source: classification engineClassification label: mal60.spre.troj.spyw.evad.linELF@0/0@1/0
Source: /usr/bin/dash (PID: 5605)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.O4CuIEpsBu /tmp/tmp.vVFwAXA4E6 /tmp/tmp.brf0F1ZgS2Jump to behavior
Source: /usr/bin/dash (PID: 5606)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.O4CuIEpsBu /tmp/tmp.vVFwAXA4E6 /tmp/tmp.brf0F1ZgS2Jump to behavior

Hooking and other Techniques for Hiding and Protection

barindex
Source: /tmp/SecuriteInfo.com.ELF.Mirai-CVD.5487.13505.elf (PID: 5624)File: /tmp/SecuriteInfo.com.ELF.Mirai-CVD.5487.13505.elfJump to behavior
Source: /tmp/SecuriteInfo.com.ELF.Mirai-CVD.5487.13505.elf (PID: 5624)Queries kernel information via 'uname': Jump to behavior
Source: /tmp/SecuriteInfo.com.ELF.Mirai-CVD.5487.13505.elf (PID: 5628)Queries kernel information via 'uname': Jump to behavior
Source: SecuriteInfo.com.ELF.Mirai-CVD.5487.13505.elf, 5624.1.000055bd1bb5c000.000055bd1bbc1000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/sparc
Source: SecuriteInfo.com.ELF.Mirai-CVD.5487.13505.elf, 5624.1.000055bd1bb5c000.000055bd1bbc1000.rw-.sdmpBinary or memory string: U!/etc/qemu-binfmt/sparc
Source: SecuriteInfo.com.ELF.Mirai-CVD.5487.13505.elf, 5624.1.00007ffd67511000.00007ffd67532000.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-sparc/tmp/SecuriteInfo.com.ELF.Mirai-CVD.5487.13505.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/SecuriteInfo.com.ELF.Mirai-CVD.5487.13505.elf
Source: SecuriteInfo.com.ELF.Mirai-CVD.5487.13505.elf, 5624.1.00007ffd67511000.00007ffd67532000.rw-.sdmpBinary or memory string: /usr/bin/qemu-sparc

HIPS / PFW / Operating System Protection Evasion

barindex
Source: TrafficDNS traffic detected: queries for: iranistrash.libre
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception11
File Deletion
OS Credential Dumping11
Security Software Discovery
Remote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS Memory1
Network Service Discovery
Remote Desktop ProtocolData from Removable Media1
Non-Standard Port
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
Non-Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture2
Application Layer Protocol
Traffic DuplicationData Destruction
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
SecuriteInfo.com.ELF.Mirai-CVD.5487.13505.elf3%ReversingLabsLinux.Trojan.Mirai
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
iranistrash.libre
unknown
unknowntrue
    unknown
    • No. of IPs < 25%
    • 25% < No. of IPs < 50%
    • 50% < No. of IPs < 75%
    • 75% < No. of IPs
    IPDomainCountryFlagASNASN NameMalicious
    5.230.171.9
    unknownGermany
    12586ASGHOSTNETDEfalse
    5.230.171.8
    unknownGermany
    12586ASGHOSTNETDEtrue
    5.230.122.82
    unknownGermany
    12586ASGHOSTNETDEfalse
    5.230.122.80
    unknownGermany
    12586ASGHOSTNETDEtrue
    5.230.228.47
    unknownGermany
    12586ASGHOSTNETDEtrue
    172.217.192.127
    unknownUnited States
    15169GOOGLEUSfalse
    5.230.228.46
    unknownGermany
    12586ASGHOSTNETDEtrue
    5.230.228.42
    unknownGermany
    12586ASGHOSTNETDEtrue
    5.230.228.44
    unknownGermany
    12586ASGHOSTNETDEtrue
    94.131.118.154
    unknownUkraine
    29632NASSIST-ASGItrue
    185.248.144.209
    unknownFrance
    31531POINT-ASUAfalse
    5.230.228.62
    unknownGermany
    12586ASGHOSTNETDEtrue
    194.156.98.15
    unknownRussian Federation
    135330ADCDATACOM-AS-APADCDATACOMHKfalse
    5.230.118.247
    unknownGermany
    12586ASGHOSTNETDEfalse
    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
    185.248.144.209dMCIAXJOD1.elfGet hashmaliciousUnknownBrowse
      5.230.228.62dMCIAXJOD1.elfGet hashmaliciousUnknownBrowse
        194.156.98.15dMCIAXJOD1.elfGet hashmaliciousUnknownBrowse
          5.230.118.247dMCIAXJOD1.elfGet hashmaliciousUnknownBrowse
            5.230.228.46dMCIAXJOD1.elfGet hashmaliciousUnknownBrowse
              No context
              MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
              ASGHOSTNETDEdMCIAXJOD1.elfGet hashmaliciousUnknownBrowse
              • 5.230.228.46
              http://offersurl.shop/4xLINj83DARK5qpxdlemiob3VGFNEIWGTNIBSAK19891KTBY295f9Get hashmaliciousPhisherBrowse
              • 193.24.209.61
              Untitled.bash_rc.elfGet hashmaliciousUnknownBrowse
              • 91.238.181.239
              sora.m68k.elfGet hashmaliciousMiraiBrowse
              • 193.187.23.249
              RzsCe9RTg9.exeGet hashmaliciousRedLineBrowse
              • 77.90.44.31
              yWGzX7xR3D.dllGet hashmaliciousUnknownBrowse
              • 5.230.73.188
              yWGzX7xR3D.dllGet hashmaliciousUnknownBrowse
              • 5.230.73.188
              aqyhDUWrLW.msiGet hashmaliciousUnknownBrowse
              • 5.230.73.188
              botx.mips.elfGet hashmaliciousMiraiBrowse
              • 5.175.194.100
              ASGHOSTNETDEdMCIAXJOD1.elfGet hashmaliciousUnknownBrowse
              • 5.230.228.46
              http://offersurl.shop/4xLINj83DARK5qpxdlemiob3VGFNEIWGTNIBSAK19891KTBY295f9Get hashmaliciousPhisherBrowse
              • 193.24.209.61
              Untitled.bash_rc.elfGet hashmaliciousUnknownBrowse
              • 91.238.181.239
              sora.m68k.elfGet hashmaliciousMiraiBrowse
              • 193.187.23.249
              RzsCe9RTg9.exeGet hashmaliciousRedLineBrowse
              • 77.90.44.31
              yWGzX7xR3D.dllGet hashmaliciousUnknownBrowse
              • 5.230.73.188
              yWGzX7xR3D.dllGet hashmaliciousUnknownBrowse
              • 5.230.73.188
              aqyhDUWrLW.msiGet hashmaliciousUnknownBrowse
              • 5.230.73.188
              botx.mips.elfGet hashmaliciousMiraiBrowse
              • 5.175.194.100
              No context
              No context
              No created / dropped files found
              File type:ELF 32-bit MSB executable, SPARC, version 1 (SYSV), statically linked, stripped
              Entropy (8bit):6.050195297376419
              TrID:
              • ELF Executable and Linkable format (generic) (4004/1) 100.00%
              File name:SecuriteInfo.com.ELF.Mirai-CVD.5487.13505.elf
              File size:83'180 bytes
              MD5:5d959c2b7278b8c8b2c4a3f1554bb96e
              SHA1:a2ff0e2fd22b31f16f2b3bcc7a3e5ac61c03f5d0
              SHA256:727d897cbf2466bc6390ec82e4056aa5047597390719fd1c556fef01303d91bd
              SHA512:de5aa96b74ef67dd27511a83e34e3455dcaa0e750eb89d51a4f958d1fc77503c533429586e0cb185d0ad1104b98627376825b41792da897a157da4242ff096eb
              SSDEEP:1536:7wFKWWnCCgFmieKTImRoqQA1LJVNcCWSt5cbhd:7GKWWnSmiePANZ8SIbX
              TLSH:F6834B21BA761E27C0D0B57921F7432AF2F5464918A8CA1F7E710E8EFF6556032137B9
              File Content Preview:.ELF...........................4..C......4. ...(......................?...?...............@...@...@.......I.........dt.Q................................@..(....@.M.................#.....b...`.....!..... ...@.....".........`......$ ... ...@...........`....

              ELF header

              Class:ELF32
              Data:2's complement, big endian
              Version:1 (current)
              Machine:Sparc
              Version Number:0x1
              Type:EXEC (Executable file)
              OS/ABI:UNIX - System V
              ABI Version:0
              Entry Point Address:0x101a4
              Flags:0x0
              ELF Header Size:52
              Program Header Offset:52
              Program Header Size:32
              Number of Program Headers:3
              Section Header Offset:82700
              Section Header Size:40
              Number of Section Headers:12
              Header String Table Index:11
              NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
              NULL0x00x00x00x00x0000
              .initPROGBITS0x100940x940x1c0x00x6AX004
              .textPROGBITS0x100b00xb00x1370c0x00x6AX004
              .finiPROGBITS0x237bc0x137bc0x140x00x6AX004
              .rodataPROGBITS0x237d00x137d00x7d80x00x2A008
              .eh_framePROGBITS0x340000x140000x40x00x3WA004
              .ctorsPROGBITS0x340040x140040x80x00x3WA004
              .dtorsPROGBITS0x3400c0x1400c0x80x00x3WA004
              .gotPROGBITS0x340180x140180xd40x40x3WA004
              .dataPROGBITS0x340f00x140f00x1cc0x00x3WA008
              .bssNOBITS0x342c00x142bc0x46f00x00x3WA008
              .shstrtabSTRTAB0x00x142bc0x4d0x00x0001
              TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
              LOAD0x00x100000x100000x13fa80x13fa86.07430x5R E0x10000.init .text .fini .rodata
              LOAD0x140000x340000x340000x2bc0x49b03.06500x6RW 0x10000.eh_frame .ctors .dtors .got .data .bss
              GNU_STACK0x00x00x00x00x00.00000x6RW 0x4
              TimestampSource PortDest PortSource IPDest IP
              Oct 7, 2024 22:45:07.188383102 CEST345927000192.168.2.15185.248.144.209
              Oct 7, 2024 22:45:07.193567038 CEST700034592185.248.144.209192.168.2.15
              Oct 7, 2024 22:45:07.193918943 CEST345927000192.168.2.15185.248.144.209
              Oct 7, 2024 22:45:07.203037977 CEST345927000192.168.2.15185.248.144.209
              Oct 7, 2024 22:45:07.207962990 CEST700034592185.248.144.209192.168.2.15
              Oct 7, 2024 22:45:08.872001886 CEST700034592185.248.144.209192.168.2.15
              Oct 7, 2024 22:45:08.872457027 CEST345927000192.168.2.15185.248.144.209
              Oct 7, 2024 22:45:08.877463102 CEST700034592185.248.144.209192.168.2.15
              Oct 7, 2024 22:45:11.874357939 CEST562063478192.168.2.155.230.171.8
              Oct 7, 2024 22:45:11.879374981 CEST3478562065.230.171.8192.168.2.15
              Oct 7, 2024 22:45:11.879461050 CEST562063478192.168.2.155.230.171.8
              Oct 7, 2024 22:45:11.879487991 CEST562063478192.168.2.155.230.171.8
              Oct 7, 2024 22:45:11.884280920 CEST3478562065.230.171.8192.168.2.15
              Oct 7, 2024 22:45:13.725682020 CEST3478562065.230.171.8192.168.2.15
              Oct 7, 2024 22:45:13.726005077 CEST562063478192.168.2.155.230.171.8
              Oct 7, 2024 22:45:13.731193066 CEST3478562065.230.171.8192.168.2.15
              Oct 7, 2024 22:45:14.729933023 CEST6056010001192.168.2.155.230.228.44
              Oct 7, 2024 22:45:14.734900951 CEST10001605605.230.228.44192.168.2.15
              Oct 7, 2024 22:45:14.735002995 CEST6056010001192.168.2.155.230.228.44
              Oct 7, 2024 22:45:14.735112906 CEST6056010001192.168.2.155.230.228.44
              Oct 7, 2024 22:45:14.740021944 CEST10001605605.230.228.44192.168.2.15
              Oct 7, 2024 22:45:16.389075041 CEST10001605605.230.228.44192.168.2.15
              Oct 7, 2024 22:45:16.389484882 CEST6056010001192.168.2.155.230.228.44
              Oct 7, 2024 22:45:16.395875931 CEST10001605605.230.228.44192.168.2.15
              Oct 7, 2024 22:45:19.392002106 CEST495547777192.168.2.155.230.171.9
              Oct 7, 2024 22:45:19.400295019 CEST7777495545.230.171.9192.168.2.15
              Oct 7, 2024 22:45:19.400413990 CEST495547777192.168.2.155.230.171.9
              Oct 7, 2024 22:45:19.400525093 CEST495547777192.168.2.155.230.171.9
              Oct 7, 2024 22:45:19.408274889 CEST7777495545.230.171.9192.168.2.15
              Oct 7, 2024 22:45:21.288559914 CEST7777495545.230.171.9192.168.2.15
              Oct 7, 2024 22:45:21.289382935 CEST495547777192.168.2.155.230.171.9
              Oct 7, 2024 22:45:21.294334888 CEST7777495545.230.171.9192.168.2.15
              Oct 7, 2024 22:45:24.291877031 CEST49308995192.168.2.155.230.171.9
              Oct 7, 2024 22:45:24.296950102 CEST995493085.230.171.9192.168.2.15
              Oct 7, 2024 22:45:24.297023058 CEST49308995192.168.2.155.230.171.9
              Oct 7, 2024 22:45:24.297080994 CEST49308995192.168.2.155.230.171.9
              Oct 7, 2024 22:45:24.302409887 CEST995493085.230.171.9192.168.2.15
              Oct 7, 2024 22:45:26.147627115 CEST995493085.230.171.9192.168.2.15
              Oct 7, 2024 22:45:26.148053885 CEST49308995192.168.2.155.230.171.9
              Oct 7, 2024 22:45:26.152861118 CEST995493085.230.171.9192.168.2.15
              Oct 7, 2024 22:45:27.150372982 CEST45434993192.168.2.15194.156.98.15
              Oct 7, 2024 22:45:27.156049967 CEST99345434194.156.98.15192.168.2.15
              Oct 7, 2024 22:45:27.156187057 CEST45434993192.168.2.15194.156.98.15
              Oct 7, 2024 22:45:27.156223059 CEST45434993192.168.2.15194.156.98.15
              Oct 7, 2024 22:45:27.161056042 CEST99345434194.156.98.15192.168.2.15
              Oct 7, 2024 22:45:29.167356968 CEST99345434194.156.98.15192.168.2.15
              Oct 7, 2024 22:45:29.167749882 CEST45434993192.168.2.15194.156.98.15
              Oct 7, 2024 22:45:29.172693014 CEST99345434194.156.98.15192.168.2.15
              Oct 7, 2024 22:45:32.169759989 CEST538963544192.168.2.155.230.171.8
              Oct 7, 2024 22:45:32.174757004 CEST3544538965.230.171.8192.168.2.15
              Oct 7, 2024 22:45:32.174850941 CEST538963544192.168.2.155.230.171.8
              Oct 7, 2024 22:45:32.174945116 CEST538963544192.168.2.155.230.171.8
              Oct 7, 2024 22:45:32.179891109 CEST3544538965.230.171.8192.168.2.15
              Oct 7, 2024 22:45:34.027929068 CEST3544538965.230.171.8192.168.2.15
              Oct 7, 2024 22:45:34.028666973 CEST538963544192.168.2.155.230.171.8
              Oct 7, 2024 22:45:34.033500910 CEST3544538965.230.171.8192.168.2.15
              Oct 7, 2024 22:45:35.030998945 CEST396942022192.168.2.155.230.228.47
              Oct 7, 2024 22:45:35.037638903 CEST2022396945.230.228.47192.168.2.15
              Oct 7, 2024 22:45:35.037735939 CEST396942022192.168.2.155.230.228.47
              Oct 7, 2024 22:45:35.037770033 CEST396942022192.168.2.155.230.228.47
              Oct 7, 2024 22:45:35.046998024 CEST2022396945.230.228.47192.168.2.15
              Oct 7, 2024 22:45:36.714616060 CEST2022396945.230.228.47192.168.2.15
              Oct 7, 2024 22:45:36.715045929 CEST396942022192.168.2.155.230.228.47
              Oct 7, 2024 22:45:36.720031023 CEST2022396945.230.228.47192.168.2.15
              Oct 7, 2024 22:45:37.717205048 CEST5508034567192.168.2.155.230.122.80
              Oct 7, 2024 22:45:37.722060919 CEST34567550805.230.122.80192.168.2.15
              Oct 7, 2024 22:45:37.722141981 CEST5508034567192.168.2.155.230.122.80
              Oct 7, 2024 22:45:37.722218037 CEST5508034567192.168.2.155.230.122.80
              Oct 7, 2024 22:45:37.727144957 CEST34567550805.230.122.80192.168.2.15
              Oct 7, 2024 22:45:39.893624067 CEST34567550805.230.122.80192.168.2.15
              Oct 7, 2024 22:45:39.893970013 CEST5508034567192.168.2.155.230.122.80
              Oct 7, 2024 22:45:39.899157047 CEST34567550805.230.122.80192.168.2.15
              Oct 7, 2024 22:45:41.896759033 CEST5631022022192.168.2.155.230.171.8
              Oct 7, 2024 22:45:41.903009892 CEST22022563105.230.171.8192.168.2.15
              Oct 7, 2024 22:45:41.903090954 CEST5631022022192.168.2.155.230.171.8
              Oct 7, 2024 22:45:41.903155088 CEST5631022022192.168.2.155.230.171.8
              Oct 7, 2024 22:45:41.908184052 CEST22022563105.230.171.8192.168.2.15
              Oct 7, 2024 22:45:43.779917002 CEST22022563105.230.171.8192.168.2.15
              Oct 7, 2024 22:45:43.780607939 CEST5631022022192.168.2.155.230.171.8
              Oct 7, 2024 22:45:43.788393974 CEST22022563105.230.171.8192.168.2.15
              Oct 7, 2024 22:45:46.782798052 CEST6022827014192.168.2.15185.248.144.209
              Oct 7, 2024 22:45:46.787926912 CEST2701460228185.248.144.209192.168.2.15
              Oct 7, 2024 22:45:46.788002014 CEST6022827014192.168.2.15185.248.144.209
              Oct 7, 2024 22:45:46.788090944 CEST6022827014192.168.2.15185.248.144.209
              Oct 7, 2024 22:45:46.792999029 CEST2701460228185.248.144.209192.168.2.15
              Oct 7, 2024 22:45:48.601628065 CEST2701460228185.248.144.209192.168.2.15
              Oct 7, 2024 22:45:48.601957083 CEST6022827014192.168.2.15185.248.144.209
              Oct 7, 2024 22:45:48.607090950 CEST2701460228185.248.144.209192.168.2.15
              Oct 7, 2024 22:45:50.603199005 CEST4367610001192.168.2.15194.156.98.15
              Oct 7, 2024 22:45:50.608184099 CEST1000143676194.156.98.15192.168.2.15
              Oct 7, 2024 22:45:50.608246088 CEST4367610001192.168.2.15194.156.98.15
              Oct 7, 2024 22:45:50.608268976 CEST4367610001192.168.2.15194.156.98.15
              Oct 7, 2024 22:45:50.613221884 CEST1000143676194.156.98.15192.168.2.15
              Oct 7, 2024 22:45:52.600181103 CEST1000143676194.156.98.15192.168.2.15
              Oct 7, 2024 22:45:52.600425005 CEST4367610001192.168.2.15194.156.98.15
              Oct 7, 2024 22:45:52.605659008 CEST1000143676194.156.98.15192.168.2.15
              Oct 7, 2024 22:45:55.602165937 CEST504042022192.168.2.155.230.228.46
              Oct 7, 2024 22:45:55.607817888 CEST2022504045.230.228.46192.168.2.15
              Oct 7, 2024 22:45:55.607912064 CEST504042022192.168.2.155.230.228.46
              Oct 7, 2024 22:45:55.607981920 CEST504042022192.168.2.155.230.228.46
              Oct 7, 2024 22:45:55.612915039 CEST2022504045.230.228.46192.168.2.15
              Oct 7, 2024 22:45:57.298851967 CEST2022504045.230.228.46192.168.2.15
              Oct 7, 2024 22:45:57.299170971 CEST504042022192.168.2.155.230.228.46
              Oct 7, 2024 22:45:57.304086924 CEST2022504045.230.228.46192.168.2.15
              Oct 7, 2024 22:45:59.301059008 CEST600723389192.168.2.155.230.122.82
              Oct 7, 2024 22:45:59.306245089 CEST3389600725.230.122.82192.168.2.15
              Oct 7, 2024 22:45:59.306339979 CEST600723389192.168.2.155.230.122.82
              Oct 7, 2024 22:45:59.306410074 CEST600723389192.168.2.155.230.122.82
              Oct 7, 2024 22:45:59.311357021 CEST3389600725.230.122.82192.168.2.15
              Oct 7, 2024 22:46:01.474301100 CEST3389600725.230.122.82192.168.2.15
              Oct 7, 2024 22:46:01.474801064 CEST600723389192.168.2.155.230.122.82
              Oct 7, 2024 22:46:01.479921103 CEST3389600725.230.122.82192.168.2.15
              Oct 7, 2024 22:46:04.476174116 CEST348882222192.168.2.155.230.228.44
              Oct 7, 2024 22:46:04.481296062 CEST2222348885.230.228.44192.168.2.15
              Oct 7, 2024 22:46:04.481429100 CEST348882222192.168.2.155.230.228.44
              Oct 7, 2024 22:46:04.481512070 CEST348882222192.168.2.155.230.228.44
              Oct 7, 2024 22:46:04.486762047 CEST2222348885.230.228.44192.168.2.15
              Oct 7, 2024 22:46:14.491472960 CEST348882222192.168.2.155.230.228.44
              Oct 7, 2024 22:46:14.496908903 CEST2222348885.230.228.44192.168.2.15
              Oct 7, 2024 22:46:14.496978045 CEST348882222192.168.2.155.230.228.44
              Oct 7, 2024 22:46:15.494837046 CEST33758993192.168.2.155.230.228.62
              Oct 7, 2024 22:46:15.499943972 CEST993337585.230.228.62192.168.2.15
              Oct 7, 2024 22:46:15.500050068 CEST33758993192.168.2.155.230.228.62
              Oct 7, 2024 22:46:15.500103951 CEST33758993192.168.2.155.230.228.62
              Oct 7, 2024 22:46:15.505861998 CEST993337585.230.228.62192.168.2.15
              Oct 7, 2024 22:46:17.189742088 CEST993337585.230.228.62192.168.2.15
              Oct 7, 2024 22:46:17.190145969 CEST33758993192.168.2.155.230.228.62
              Oct 7, 2024 22:46:17.195076942 CEST993337585.230.228.62192.168.2.15
              Oct 7, 2024 22:46:19.193985939 CEST486889001192.168.2.155.230.228.62
              Oct 7, 2024 22:46:19.199255943 CEST9001486885.230.228.62192.168.2.15
              Oct 7, 2024 22:46:19.199320078 CEST486889001192.168.2.155.230.228.62
              Oct 7, 2024 22:46:19.199374914 CEST486889001192.168.2.155.230.228.62
              Oct 7, 2024 22:46:19.204322100 CEST9001486885.230.228.62192.168.2.15
              Oct 7, 2024 22:46:20.871710062 CEST9001486885.230.228.62192.168.2.15
              Oct 7, 2024 22:46:20.871941090 CEST486889001192.168.2.155.230.228.62
              Oct 7, 2024 22:46:20.872077942 CEST486889001192.168.2.155.230.228.62
              Oct 7, 2024 22:46:20.876972914 CEST9001486885.230.228.62192.168.2.15
              Oct 7, 2024 22:46:22.874669075 CEST3780027014192.168.2.1594.131.118.154
              Oct 7, 2024 22:46:22.879882097 CEST270143780094.131.118.154192.168.2.15
              Oct 7, 2024 22:46:22.879968882 CEST3780027014192.168.2.1594.131.118.154
              Oct 7, 2024 22:46:22.880031109 CEST3780027014192.168.2.1594.131.118.154
              Oct 7, 2024 22:46:22.885389090 CEST270143780094.131.118.154192.168.2.15
              Oct 7, 2024 22:46:32.889940977 CEST3780027014192.168.2.1594.131.118.154
              Oct 7, 2024 22:46:32.896892071 CEST270143780094.131.118.154192.168.2.15
              Oct 7, 2024 22:46:32.896960974 CEST3780027014192.168.2.1594.131.118.154
              Oct 7, 2024 22:46:33.891735077 CEST526563389192.168.2.155.230.122.80
              Oct 7, 2024 22:46:33.896961927 CEST3389526565.230.122.80192.168.2.15
              Oct 7, 2024 22:46:33.897144079 CEST526563389192.168.2.155.230.122.80
              Oct 7, 2024 22:46:33.897172928 CEST526563389192.168.2.155.230.122.80
              Oct 7, 2024 22:46:33.903338909 CEST3389526565.230.122.80192.168.2.15
              Oct 7, 2024 22:46:36.080957890 CEST3389526565.230.122.80192.168.2.15
              Oct 7, 2024 22:46:36.081717968 CEST526563389192.168.2.155.230.122.80
              Oct 7, 2024 22:46:36.086596012 CEST3389526565.230.122.80192.168.2.15
              Oct 7, 2024 22:46:37.084598064 CEST4185619153192.168.2.155.230.228.42
              Oct 7, 2024 22:46:37.089818001 CEST19153418565.230.228.42192.168.2.15
              Oct 7, 2024 22:46:37.089987040 CEST4185619153192.168.2.155.230.228.42
              Oct 7, 2024 22:46:37.090032101 CEST4185619153192.168.2.155.230.228.42
              Oct 7, 2024 22:46:37.094995975 CEST19153418565.230.228.42192.168.2.15
              Oct 7, 2024 22:46:47.099941969 CEST4185619153192.168.2.155.230.228.42
              Oct 7, 2024 22:46:47.109190941 CEST19153418565.230.228.42192.168.2.15
              Oct 7, 2024 22:46:47.109281063 CEST4185619153192.168.2.155.230.228.42
              Oct 7, 2024 22:46:50.101708889 CEST4004435000192.168.2.1594.131.118.154
              Oct 7, 2024 22:46:50.109599113 CEST350004004494.131.118.154192.168.2.15
              Oct 7, 2024 22:46:50.109674931 CEST4004435000192.168.2.1594.131.118.154
              Oct 7, 2024 22:46:50.109697104 CEST4004435000192.168.2.1594.131.118.154
              Oct 7, 2024 22:46:50.114567041 CEST350004004494.131.118.154192.168.2.15
              Oct 7, 2024 22:47:00.119574070 CEST4004435000192.168.2.1594.131.118.154
              Oct 7, 2024 22:47:00.125353098 CEST350004004494.131.118.154192.168.2.15
              Oct 7, 2024 22:47:00.125423908 CEST4004435000192.168.2.1594.131.118.154
              Oct 7, 2024 22:47:01.125874996 CEST588227777192.168.2.155.230.228.46
              Oct 7, 2024 22:47:01.130959988 CEST7777588225.230.228.46192.168.2.15
              Oct 7, 2024 22:47:01.131042957 CEST588227777192.168.2.155.230.228.46
              Oct 7, 2024 22:47:01.131093025 CEST588227777192.168.2.155.230.228.46
              Oct 7, 2024 22:47:01.136037111 CEST7777588225.230.228.46192.168.2.15
              Oct 7, 2024 22:47:02.849390984 CEST7777588225.230.228.46192.168.2.15
              Oct 7, 2024 22:47:02.849769115 CEST588227777192.168.2.155.230.228.46
              Oct 7, 2024 22:47:02.854784012 CEST7777588225.230.228.46192.168.2.15
              Oct 7, 2024 22:47:03.852173090 CEST507289000192.168.2.155.230.118.247
              Oct 7, 2024 22:47:03.857291937 CEST9000507285.230.118.247192.168.2.15
              Oct 7, 2024 22:47:03.857423067 CEST507289000192.168.2.155.230.118.247
              Oct 7, 2024 22:47:03.857484102 CEST507289000192.168.2.155.230.118.247
              Oct 7, 2024 22:47:03.862431049 CEST9000507285.230.118.247192.168.2.15
              Oct 7, 2024 22:47:05.709356070 CEST9000507285.230.118.247192.168.2.15
              Oct 7, 2024 22:47:05.709680080 CEST507289000192.168.2.155.230.118.247
              Oct 7, 2024 22:47:05.714895010 CEST9000507285.230.118.247192.168.2.15
              Oct 7, 2024 22:47:08.711426020 CEST60874443192.168.2.155.230.228.46
              Oct 7, 2024 22:47:08.711487055 CEST443608745.230.228.46192.168.2.15
              Oct 7, 2024 22:47:08.711541891 CEST60874443192.168.2.155.230.228.46
              Oct 7, 2024 22:47:08.711891890 CEST60874443192.168.2.155.230.228.46
              Oct 7, 2024 22:47:08.711918116 CEST443608745.230.228.46192.168.2.15
              Oct 7, 2024 22:47:08.711973906 CEST443608745.230.228.46192.168.2.15
              Oct 7, 2024 22:47:10.715348959 CEST536267000192.168.2.155.230.122.80
              Oct 7, 2024 22:47:10.720458984 CEST7000536265.230.122.80192.168.2.15
              Oct 7, 2024 22:47:10.720742941 CEST536267000192.168.2.155.230.122.80
              Oct 7, 2024 22:47:10.720779896 CEST536267000192.168.2.155.230.122.80
              Oct 7, 2024 22:47:10.725609064 CEST7000536265.230.122.80192.168.2.15
              TimestampSource PortDest PortSource IPDest IP
              Oct 7, 2024 22:45:06.464057922 CEST557413478192.168.2.15172.217.192.127
              Oct 7, 2024 22:45:07.022897959 CEST347855741172.217.192.127192.168.2.15
              Oct 7, 2024 22:45:07.109447956 CEST5776653192.168.2.15217.160.70.42
              Oct 7, 2024 22:45:07.136672020 CEST5357766217.160.70.42192.168.2.15
              TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
              Oct 7, 2024 22:45:07.109447956 CEST192.168.2.15217.160.70.420x161cStandard query (0)iranistrash.libre16IN (0x0001)false
              TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
              Oct 7, 2024 22:45:07.136672020 CEST217.160.70.42192.168.2.150x161cNo error (0)iranistrash.libreTXT (Text strings)IN (0x0001)false

              System Behavior

              Start time (UTC):20:44:51
              Start date (UTC):07/10/2024
              Path:/usr/bin/dash
              Arguments:-
              File size:129816 bytes
              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

              Start time (UTC):20:44:51
              Start date (UTC):07/10/2024
              Path:/usr/bin/rm
              Arguments:rm -f /tmp/tmp.O4CuIEpsBu /tmp/tmp.vVFwAXA4E6 /tmp/tmp.brf0F1ZgS2
              File size:72056 bytes
              MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b

              Start time (UTC):20:44:51
              Start date (UTC):07/10/2024
              Path:/usr/bin/dash
              Arguments:-
              File size:129816 bytes
              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

              Start time (UTC):20:44:51
              Start date (UTC):07/10/2024
              Path:/usr/bin/rm
              Arguments:rm -f /tmp/tmp.O4CuIEpsBu /tmp/tmp.vVFwAXA4E6 /tmp/tmp.brf0F1ZgS2
              File size:72056 bytes
              MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b

              Start time (UTC):20:45:01
              Start date (UTC):07/10/2024
              Path:/tmp/SecuriteInfo.com.ELF.Mirai-CVD.5487.13505.elf
              Arguments:/tmp/SecuriteInfo.com.ELF.Mirai-CVD.5487.13505.elf
              File size:4379400 bytes
              MD5 hash:7dc1c0e23cd5e102bb12e5c29403410e

              Start time (UTC):20:45:05
              Start date (UTC):07/10/2024
              Path:/tmp/SecuriteInfo.com.ELF.Mirai-CVD.5487.13505.elf
              Arguments:-
              File size:4379400 bytes
              MD5 hash:7dc1c0e23cd5e102bb12e5c29403410e

              Start time (UTC):20:45:05
              Start date (UTC):07/10/2024
              Path:/tmp/SecuriteInfo.com.ELF.Mirai-CVD.5487.13505.elf
              Arguments:-
              File size:4379400 bytes
              MD5 hash:7dc1c0e23cd5e102bb12e5c29403410e