Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
x86.elf

Overview

General Information

Sample name:x86.elf
Analysis ID:1528579
MD5:06e3ae9bd59b025cb7181795f58aae35
SHA1:e000ac312d41d31186236d2725928c4b4c9388ed
SHA256:351977f033a333c54b7ec6f1ce1effa9619f3840a0326167c89350a4643912e8
Tags:user-elfdigest
Infos:

Detection

Score:72
Range:0 - 100
Whitelisted:false

Signatures

Antivirus / Scanner detection for submitted sample
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Connects to many ports of the same IP (likely port scanning)
Machine Learning detection for sample
Detected TCP or UDP traffic on non-standard ports
Sample has stripped symbol table
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Yara signature match

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1528579
Start date and time:2024-10-08 03:05:07 +02:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 14s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:x86.elf
Detection:MAL
Classification:mal72.troj.linELF@0/0@10/0
Command:/tmp/x86.elf
PID:5433
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
zenci
Standard Error:
  • system is lnxubuntu20
  • x86.elf (PID: 5433, Parent: 5357, MD5: 06e3ae9bd59b025cb7181795f58aae35) Arguments: /tmp/x86.elf
    • x86.elf New Fork (PID: 5434, Parent: 5433)
      • x86.elf New Fork (PID: 5443, Parent: 5434)
  • udisksd New Fork (PID: 5444, Parent: 802)
  • dumpe2fs (PID: 5444, Parent: 802, MD5: 5c66f7d8f7681a40562cf049ad4b72b4) Arguments: dumpe2fs -h /dev/dm-0
  • cleanup
SourceRuleDescriptionAuthorStrings
x86.elfLinux_Trojan_Mirai_b14f4c5dunknownunknown
  • 0x7c0:$a: 53 31 DB 8B 4C 24 0C 8B 54 24 08 83 F9 01 76 15 66 8B 02 83 E9 02 25 FF FF 00 00 83 C2 02 01 C3 83 F9 01 77 EB 49 75 05 0F BE 02 01 C3
x86.elfLinux_Trojan_Mirai_88de437funknownunknown
  • 0x69f2:$a: 24 08 8B 4C 24 04 85 D2 74 0D 31 C0 89 F6 C6 04 08 00 40 39 D0
x86.elfLinux_Trojan_Mirai_389ee3e9unknownunknown
  • 0x9a5d:$a: 89 45 00 EB 2C 8B 4B 04 8B 13 8B 7B 18 8B 01 01 02 8B 02 83
x86.elfLinux_Trojan_Mirai_cc93863bunknownunknown
  • 0x83b4:$a: C3 57 8B 44 24 0C 8B 4C 24 10 8B 7C 24 08 F3 AA 8B 44 24 08
x86.elfLinux_Trojan_Mirai_8aa7b5d3unknownunknown
  • 0x69c2:$a: 8B 4C 24 14 8B 74 24 0C 8B 5C 24 10 85 C9 74 0D 31 D2 8A 04 1A 88
SourceRuleDescriptionAuthorStrings
5443.1.0000000008048000.0000000008055000.r-x.sdmpLinux_Trojan_Mirai_b14f4c5dunknownunknown
  • 0x7c0:$a: 53 31 DB 8B 4C 24 0C 8B 54 24 08 83 F9 01 76 15 66 8B 02 83 E9 02 25 FF FF 00 00 83 C2 02 01 C3 83 F9 01 77 EB 49 75 05 0F BE 02 01 C3
5443.1.0000000008048000.0000000008055000.r-x.sdmpLinux_Trojan_Mirai_88de437funknownunknown
  • 0x69f2:$a: 24 08 8B 4C 24 04 85 D2 74 0D 31 C0 89 F6 C6 04 08 00 40 39 D0
5443.1.0000000008048000.0000000008055000.r-x.sdmpLinux_Trojan_Mirai_389ee3e9unknownunknown
  • 0x9a5d:$a: 89 45 00 EB 2C 8B 4B 04 8B 13 8B 7B 18 8B 01 01 02 8B 02 83
5443.1.0000000008048000.0000000008055000.r-x.sdmpLinux_Trojan_Mirai_cc93863bunknownunknown
  • 0x83b4:$a: C3 57 8B 44 24 0C 8B 4C 24 10 8B 7C 24 08 F3 AA 8B 44 24 08
5443.1.0000000008048000.0000000008055000.r-x.sdmpLinux_Trojan_Mirai_8aa7b5d3unknownunknown
  • 0x69c2:$a: 8B 4C 24 14 8B 74 24 0C 8B 5C 24 10 85 C9 74 0D 31 D2 8A 04 1A 88
Click to see the 5 entries
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: x86.elfAvira: detected
Source: x86.elfReversingLabs: Detection: 57%
Source: x86.elfVirustotal: Detection: 59%Perma Link
Source: x86.elfJoe Sandbox ML: detected

Networking

barindex
Source: global trafficTCP traffic: 93.123.39.105 ports 38241,1,2,3,4,8
Source: global trafficTCP traffic: 192.168.2.13:34974 -> 93.123.39.105:38241
Source: global trafficTCP traffic: 192.168.2.13:48202 -> 185.125.190.26:443
Source: unknownTCP traffic detected without corresponding DNS query: 185.125.190.26
Source: unknownTCP traffic detected without corresponding DNS query: 185.125.190.26
Source: unknownUDP traffic detected without corresponding DNS query: 51.158.108.203
Source: unknownUDP traffic detected without corresponding DNS query: 80.152.203.134
Source: unknownUDP traffic detected without corresponding DNS query: 81.169.136.222
Source: unknownUDP traffic detected without corresponding DNS query: 51.158.108.203
Source: unknownUDP traffic detected without corresponding DNS query: 194.36.144.87
Source: unknownUDP traffic detected without corresponding DNS query: 217.160.70.42
Source: unknownUDP traffic detected without corresponding DNS query: 70.34.254.19
Source: unknownUDP traffic detected without corresponding DNS query: 139.84.165.176
Source: unknownUDP traffic detected without corresponding DNS query: 185.181.61.24
Source: unknownUDP traffic detected without corresponding DNS query: 80.152.203.134
Source: global trafficDNS traffic detected: DNS query: enemybotnet.com
Source: unknownNetwork traffic detected: HTTP traffic on port 48202 -> 443

System Summary

barindex
Source: x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_b14f4c5d Author: unknown
Source: x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_88de437f Author: unknown
Source: x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_389ee3e9 Author: unknown
Source: x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_cc93863b Author: unknown
Source: x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_8aa7b5d3 Author: unknown
Source: 5443.1.0000000008048000.0000000008055000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_b14f4c5d Author: unknown
Source: 5443.1.0000000008048000.0000000008055000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_88de437f Author: unknown
Source: 5443.1.0000000008048000.0000000008055000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_389ee3e9 Author: unknown
Source: 5443.1.0000000008048000.0000000008055000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_cc93863b Author: unknown
Source: 5443.1.0000000008048000.0000000008055000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_8aa7b5d3 Author: unknown
Source: 5433.1.0000000008048000.0000000008055000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_b14f4c5d Author: unknown
Source: 5433.1.0000000008048000.0000000008055000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_88de437f Author: unknown
Source: 5433.1.0000000008048000.0000000008055000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_389ee3e9 Author: unknown
Source: 5433.1.0000000008048000.0000000008055000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_cc93863b Author: unknown
Source: 5433.1.0000000008048000.0000000008055000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_8aa7b5d3 Author: unknown
Source: ELF static info symbol of initial sample.symtab present: no
Source: x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_b14f4c5d os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = a70d052918dd2fbc66db241da6438015130f0fb6929229bfe573546fe98da817, id = b14f4c5d-054f-46e6-9fa8-3588f1ef68b7, last_modified = 2021-09-16
Source: x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_88de437f reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = c19eb595c2b444a809bef8500c20342c9f46694d3018e268833f9b884133a1ea, id = 88de437f-9c98-4e1d-96c0-7b433c99886a, last_modified = 2021-09-16
Source: x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_389ee3e9 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 59f2359dc1f41d385d639d157b4cd9fc73d76d8abb7cc09d47632bb4c9a39e6e, id = 389ee3e9-70c1-4c93-a999-292cf6ff1652, last_modified = 2022-01-26
Source: x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_cc93863b reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = f3ecd30f0b511a8e92cfa642409d559e7612c3f57a1659ca46c77aca809a00ac, id = cc93863b-1050-40ba-9d02-5ec9ce6a3a28, last_modified = 2022-01-26
Source: x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_8aa7b5d3 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 02a2c18c362df4b1fceb33f3b605586514ba9a00c7afedf71c04fa54d8146444, id = 8aa7b5d3-e1eb-4b55-b36a-0d3a242c06e9, last_modified = 2022-01-26
Source: 5443.1.0000000008048000.0000000008055000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_b14f4c5d os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = a70d052918dd2fbc66db241da6438015130f0fb6929229bfe573546fe98da817, id = b14f4c5d-054f-46e6-9fa8-3588f1ef68b7, last_modified = 2021-09-16
Source: 5443.1.0000000008048000.0000000008055000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_88de437f reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = c19eb595c2b444a809bef8500c20342c9f46694d3018e268833f9b884133a1ea, id = 88de437f-9c98-4e1d-96c0-7b433c99886a, last_modified = 2021-09-16
Source: 5443.1.0000000008048000.0000000008055000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_389ee3e9 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 59f2359dc1f41d385d639d157b4cd9fc73d76d8abb7cc09d47632bb4c9a39e6e, id = 389ee3e9-70c1-4c93-a999-292cf6ff1652, last_modified = 2022-01-26
Source: 5443.1.0000000008048000.0000000008055000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_cc93863b reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = f3ecd30f0b511a8e92cfa642409d559e7612c3f57a1659ca46c77aca809a00ac, id = cc93863b-1050-40ba-9d02-5ec9ce6a3a28, last_modified = 2022-01-26
Source: 5443.1.0000000008048000.0000000008055000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_8aa7b5d3 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 02a2c18c362df4b1fceb33f3b605586514ba9a00c7afedf71c04fa54d8146444, id = 8aa7b5d3-e1eb-4b55-b36a-0d3a242c06e9, last_modified = 2022-01-26
Source: 5433.1.0000000008048000.0000000008055000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_b14f4c5d os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = a70d052918dd2fbc66db241da6438015130f0fb6929229bfe573546fe98da817, id = b14f4c5d-054f-46e6-9fa8-3588f1ef68b7, last_modified = 2021-09-16
Source: 5433.1.0000000008048000.0000000008055000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_88de437f reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = c19eb595c2b444a809bef8500c20342c9f46694d3018e268833f9b884133a1ea, id = 88de437f-9c98-4e1d-96c0-7b433c99886a, last_modified = 2021-09-16
Source: 5433.1.0000000008048000.0000000008055000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_389ee3e9 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 59f2359dc1f41d385d639d157b4cd9fc73d76d8abb7cc09d47632bb4c9a39e6e, id = 389ee3e9-70c1-4c93-a999-292cf6ff1652, last_modified = 2022-01-26
Source: 5433.1.0000000008048000.0000000008055000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_cc93863b reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = f3ecd30f0b511a8e92cfa642409d559e7612c3f57a1659ca46c77aca809a00ac, id = cc93863b-1050-40ba-9d02-5ec9ce6a3a28, last_modified = 2022-01-26
Source: 5433.1.0000000008048000.0000000008055000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_8aa7b5d3 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 02a2c18c362df4b1fceb33f3b605586514ba9a00c7afedf71c04fa54d8146444, id = 8aa7b5d3-e1eb-4b55-b36a-0d3a242c06e9, last_modified = 2022-01-26
Source: classification engineClassification label: mal72.troj.linELF@0/0@10/0
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath InterceptionDirect Volume AccessOS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Non-Standard Port
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
Non-Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture2
Application Layer Protocol
Traffic DuplicationData Destruction
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1528579 Sample: x86.elf Startdate: 08/10/2024 Architecture: LINUX Score: 72 16 enemybotnet.com 93.123.39.105, 34974, 34976, 34978 NET1-ASBG Bulgaria 2->16 18 185.125.190.26, 443 CANONICAL-ASGB United Kingdom 2->18 20 Malicious sample detected (through community Yara rule) 2->20 22 Antivirus / Scanner detection for submitted sample 2->22 24 Multi AV Scanner detection for submitted file 2->24 26 2 other signatures 2->26 8 x86.elf 2->8         started        10 udisksd dumpe2fs 2->10         started        signatures3 process4 process5 12 x86.elf 8->12         started        process6 14 x86.elf 12->14         started       

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
x86.elf58%ReversingLabsLinux.Trojan.Mirai
x86.elf59%VirustotalBrowse
x86.elf100%AviraLINUX/AVI.Mirai.jbpzl
x86.elf100%Joe Sandbox ML
No Antivirus matches
SourceDetectionScannerLabelLink
enemybotnet.com14%VirustotalBrowse
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
enemybotnet.com
93.123.39.105
truetrueunknown
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs
IPDomainCountryFlagASNASN NameMalicious
93.123.39.105
enemybotnet.comBulgaria
43561NET1-ASBGtrue
185.125.190.26
unknownUnited Kingdom
41231CANONICAL-ASGBfalse
MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
185.125.190.26boatnet.x86.elfGet hashmaliciousMiraiBrowse
    na.elfGet hashmaliciousUnknownBrowse
      na.elfGet hashmaliciousMirai, Gafgyt, OkiruBrowse
        na.elfGet hashmaliciousUnknownBrowse
          na.elfGet hashmaliciousMirai, Gafgyt, OkiruBrowse
            2xl3rbZjPq.elfGet hashmaliciousMiraiBrowse
              Rdih5xVXy1.elfGet hashmaliciousMiraiBrowse
                na.elfGet hashmaliciousSliverBrowse
                  aqDJaFteog.elfGet hashmaliciousMiraiBrowse
                    3Gd0qX1f74.elfGet hashmaliciousMiraiBrowse
                      No context
                      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                      NET1-ASBGk4STQvJ6rV.vbsGet hashmaliciousXWormBrowse
                      • 93.123.39.76
                      https://swissquotech.com/swissquote-2024.zipGet hashmaliciousPhisherBrowse
                      • 87.121.45.6
                      mipsel.nn.elfGet hashmaliciousOkiruBrowse
                      • 93.123.85.166
                      arm7.nn.elfGet hashmaliciousMirai, OkiruBrowse
                      • 93.123.85.166
                      x86_32.nn.elfGet hashmaliciousOkiruBrowse
                      • 93.123.85.166
                      x86_64.nn.elfGet hashmaliciousOkiruBrowse
                      • 93.123.85.166
                      mips.nn.elfGet hashmaliciousOkiruBrowse
                      • 93.123.85.166
                      arm5.nn.elfGet hashmaliciousOkiruBrowse
                      • 93.123.85.166
                      arm.nn.elfGet hashmaliciousOkiruBrowse
                      • 93.123.85.166
                      SecuriteInfo.com.Linux.Siggen.9999.9437.5075.elfGet hashmaliciousMiraiBrowse
                      • 93.123.85.221
                      CANONICAL-ASGBSecuriteInfo.com.ELF.Mirai-CVD.31968.3467.elfGet hashmaliciousUnknownBrowse
                      • 91.189.91.42
                      SecuriteInfo.com.ELF.Mirai-CVD.12952.14309.elfGet hashmaliciousUnknownBrowse
                      • 91.189.91.42
                      SecuriteInfo.com.ELF.Mirai-COW.15022.10577.elfGet hashmaliciousUnknownBrowse
                      • 91.189.91.42
                      Mk4eUPwWIY.elfGet hashmaliciousMiraiBrowse
                      • 91.189.91.42
                      AzRiLxCGXJ.elfGet hashmaliciousMiraiBrowse
                      • 91.189.91.42
                      Cr8Dw4Ybgh.elfGet hashmaliciousMiraiBrowse
                      • 91.189.91.42
                      slSUX7klEH.elfGet hashmaliciousMiraiBrowse
                      • 91.189.91.42
                      boatnet.arm.elfGet hashmaliciousMiraiBrowse
                      • 91.189.91.42
                      boatnet.x86.elfGet hashmaliciousMiraiBrowse
                      • 185.125.190.26
                      dMCIAXJOD1.elfGet hashmaliciousUnknownBrowse
                      • 91.189.91.42
                      No context
                      No context
                      No created / dropped files found
                      File type:ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, stripped
                      Entropy (8bit):6.445466527555396
                      TrID:
                      • ELF Executable and Linkable format (Linux) (4029/14) 50.16%
                      • ELF Executable and Linkable format (generic) (4004/1) 49.84%
                      File name:x86.elf
                      File size:54'352 bytes
                      MD5:06e3ae9bd59b025cb7181795f58aae35
                      SHA1:e000ac312d41d31186236d2725928c4b4c9388ed
                      SHA256:351977f033a333c54b7ec6f1ce1effa9619f3840a0326167c89350a4643912e8
                      SHA512:867d6fd1168c757397be71de59ff309092bae91427a16c53ebf9377ca8d4dbd2d08d3ba91a93b2239521f494e8a16165cdb5bb21efc1c15e6f524ddeff4e97b6
                      SSDEEP:1536:koFZyQDHb4T1WhmlDnEwLw5rL23W5B4OJBjb7Sx:DyQD74T1W6IwLE/p5B9J1b+
                      TLSH:CE3339C4E64BE8F5FC56067421B7E3728A73F93A0029D997C369A432AC52A05E6573CC
                      File Content Preview:.ELF....................d...4...........4. ...(..............................................P...P.......7..........Q.td............................U..S.......w....h........[]...$.............U......=.R...t..5....$P.....$P......u........t....h.M..........

                      ELF header

                      Class:ELF32
                      Data:2's complement, little endian
                      Version:1 (current)
                      Machine:Intel 80386
                      Version Number:0x1
                      Type:EXEC (Executable file)
                      OS/ABI:UNIX - System V
                      ABI Version:0
                      Entry Point Address:0x8048164
                      Flags:0x0
                      ELF Header Size:52
                      Program Header Offset:52
                      Program Header Size:32
                      Number of Program Headers:3
                      Section Header Offset:53952
                      Section Header Size:40
                      Number of Section Headers:10
                      Header String Table Index:9
                      NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                      NULL0x00x00x00x00x0000
                      .initPROGBITS0x80480940x940x1c0x00x6AX001
                      .textPROGBITS0x80480b00xb00xb5f60x00x6AX0016
                      .finiPROGBITS0x80536a60xb6a60x170x00x6AX001
                      .rodataPROGBITS0x80536c00xb6c00x16fc0x00x2A0032
                      .ctorsPROGBITS0x80550000xd0000x80x00x3WA004
                      .dtorsPROGBITS0x80550080xd0080x80x00x3WA004
                      .dataPROGBITS0x80550200xd0200x2600x00x3WA0032
                      .bssNOBITS0x80552800xd2800x35600x00x3WA0032
                      .shstrtabSTRTAB0x00xd2800x3e0x00x0001
                      TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                      LOAD0x00x80480000x80480000xcdbc0xcdbc6.52360x5R E0x1000.init .text .fini .rodata
                      LOAD0xd0000x80550000x80550000x2800x37e03.33850x6RW 0x1000.ctors .dtors .data .bss
                      GNU_STACK0x00x00x00x00x00.00000x6RW 0x4
                      TimestampSource PortDest PortSource IPDest IP
                      Oct 8, 2024 03:05:49.088587046 CEST3497438241192.168.2.1393.123.39.105
                      Oct 8, 2024 03:05:49.093559980 CEST382413497493.123.39.105192.168.2.13
                      Oct 8, 2024 03:05:49.093697071 CEST3497438241192.168.2.1393.123.39.105
                      Oct 8, 2024 03:05:49.093848944 CEST3497438241192.168.2.1393.123.39.105
                      Oct 8, 2024 03:05:49.098648071 CEST382413497493.123.39.105192.168.2.13
                      Oct 8, 2024 03:05:49.098715067 CEST3497438241192.168.2.1393.123.39.105
                      Oct 8, 2024 03:05:49.103558064 CEST382413497493.123.39.105192.168.2.13
                      Oct 8, 2024 03:05:49.688637018 CEST382413497493.123.39.105192.168.2.13
                      Oct 8, 2024 03:05:49.689806938 CEST3497438241192.168.2.1393.123.39.105
                      Oct 8, 2024 03:05:49.689806938 CEST3497438241192.168.2.1393.123.39.105
                      Oct 8, 2024 03:05:51.910320997 CEST3497638241192.168.2.1393.123.39.105
                      Oct 8, 2024 03:05:51.917134047 CEST382413497693.123.39.105192.168.2.13
                      Oct 8, 2024 03:05:51.917212009 CEST3497638241192.168.2.1393.123.39.105
                      Oct 8, 2024 03:05:51.917229891 CEST3497638241192.168.2.1393.123.39.105
                      Oct 8, 2024 03:05:51.924397945 CEST382413497693.123.39.105192.168.2.13
                      Oct 8, 2024 03:05:51.924447060 CEST3497638241192.168.2.1393.123.39.105
                      Oct 8, 2024 03:05:51.929564953 CEST382413497693.123.39.105192.168.2.13
                      Oct 8, 2024 03:05:52.546123981 CEST382413497693.123.39.105192.168.2.13
                      Oct 8, 2024 03:05:52.546354055 CEST3497638241192.168.2.1393.123.39.105
                      Oct 8, 2024 03:05:52.546382904 CEST3497638241192.168.2.1393.123.39.105
                      Oct 8, 2024 03:05:54.753374100 CEST3497838241192.168.2.1393.123.39.105
                      Oct 8, 2024 03:05:54.758296013 CEST382413497893.123.39.105192.168.2.13
                      Oct 8, 2024 03:05:54.758399010 CEST3497838241192.168.2.1393.123.39.105
                      Oct 8, 2024 03:05:54.758419991 CEST3497838241192.168.2.1393.123.39.105
                      Oct 8, 2024 03:05:54.763315916 CEST382413497893.123.39.105192.168.2.13
                      Oct 8, 2024 03:05:54.763381958 CEST3497838241192.168.2.1393.123.39.105
                      Oct 8, 2024 03:05:54.768265009 CEST382413497893.123.39.105192.168.2.13
                      Oct 8, 2024 03:05:55.357073069 CEST382413497893.123.39.105192.168.2.13
                      Oct 8, 2024 03:05:55.357434988 CEST3497838241192.168.2.1393.123.39.105
                      Oct 8, 2024 03:05:55.357434988 CEST3497838241192.168.2.1393.123.39.105
                      Oct 8, 2024 03:05:57.384001970 CEST3498038241192.168.2.1393.123.39.105
                      Oct 8, 2024 03:05:57.392838955 CEST382413498093.123.39.105192.168.2.13
                      Oct 8, 2024 03:05:57.392932892 CEST3498038241192.168.2.1393.123.39.105
                      Oct 8, 2024 03:05:57.392998934 CEST3498038241192.168.2.1393.123.39.105
                      Oct 8, 2024 03:05:57.402319908 CEST382413498093.123.39.105192.168.2.13
                      Oct 8, 2024 03:05:57.402386904 CEST3498038241192.168.2.1393.123.39.105
                      Oct 8, 2024 03:05:57.409818888 CEST382413498093.123.39.105192.168.2.13
                      Oct 8, 2024 03:05:57.995060921 CEST382413498093.123.39.105192.168.2.13
                      Oct 8, 2024 03:05:57.995373011 CEST3498038241192.168.2.1393.123.39.105
                      Oct 8, 2024 03:05:57.995373011 CEST3498038241192.168.2.1393.123.39.105
                      Oct 8, 2024 03:05:59.974400043 CEST48202443192.168.2.13185.125.190.26
                      Oct 8, 2024 03:06:00.009942055 CEST3498238241192.168.2.1393.123.39.105
                      Oct 8, 2024 03:06:00.014784098 CEST382413498293.123.39.105192.168.2.13
                      Oct 8, 2024 03:06:00.014842033 CEST3498238241192.168.2.1393.123.39.105
                      Oct 8, 2024 03:06:00.014978886 CEST3498238241192.168.2.1393.123.39.105
                      Oct 8, 2024 03:06:00.019956112 CEST382413498293.123.39.105192.168.2.13
                      Oct 8, 2024 03:06:00.020102978 CEST3498238241192.168.2.1393.123.39.105
                      Oct 8, 2024 03:06:00.025010109 CEST382413498293.123.39.105192.168.2.13
                      Oct 8, 2024 03:06:00.615123034 CEST382413498293.123.39.105192.168.2.13
                      Oct 8, 2024 03:06:00.615243912 CEST3498238241192.168.2.1393.123.39.105
                      Oct 8, 2024 03:06:00.615339041 CEST3498238241192.168.2.1393.123.39.105
                      Oct 8, 2024 03:06:02.836009026 CEST3498438241192.168.2.1393.123.39.105
                      Oct 8, 2024 03:06:02.840946913 CEST382413498493.123.39.105192.168.2.13
                      Oct 8, 2024 03:06:02.841048002 CEST3498438241192.168.2.1393.123.39.105
                      Oct 8, 2024 03:06:02.841063976 CEST3498438241192.168.2.1393.123.39.105
                      Oct 8, 2024 03:06:02.846013069 CEST382413498493.123.39.105192.168.2.13
                      Oct 8, 2024 03:06:02.846085072 CEST3498438241192.168.2.1393.123.39.105
                      Oct 8, 2024 03:06:02.850950003 CEST382413498493.123.39.105192.168.2.13
                      Oct 8, 2024 03:06:03.448095083 CEST382413498493.123.39.105192.168.2.13
                      Oct 8, 2024 03:06:03.448220015 CEST3498438241192.168.2.1393.123.39.105
                      Oct 8, 2024 03:06:03.448242903 CEST3498438241192.168.2.1393.123.39.105
                      Oct 8, 2024 03:06:15.679271936 CEST3498638241192.168.2.1393.123.39.105
                      Oct 8, 2024 03:06:15.686873913 CEST382413498693.123.39.105192.168.2.13
                      Oct 8, 2024 03:06:15.687004089 CEST3498638241192.168.2.1393.123.39.105
                      Oct 8, 2024 03:06:15.687047958 CEST3498638241192.168.2.1393.123.39.105
                      Oct 8, 2024 03:06:15.695159912 CEST382413498693.123.39.105192.168.2.13
                      Oct 8, 2024 03:06:15.695240021 CEST3498638241192.168.2.1393.123.39.105
                      Oct 8, 2024 03:06:15.703066111 CEST382413498693.123.39.105192.168.2.13
                      Oct 8, 2024 03:06:16.293148994 CEST382413498693.123.39.105192.168.2.13
                      Oct 8, 2024 03:06:16.293441057 CEST3498638241192.168.2.1393.123.39.105
                      Oct 8, 2024 03:06:16.293442011 CEST3498638241192.168.2.1393.123.39.105
                      Oct 8, 2024 03:06:18.498868942 CEST3498838241192.168.2.1393.123.39.105
                      Oct 8, 2024 03:06:18.503714085 CEST382413498893.123.39.105192.168.2.13
                      Oct 8, 2024 03:06:18.503794909 CEST3498838241192.168.2.1393.123.39.105
                      Oct 8, 2024 03:06:18.503866911 CEST3498838241192.168.2.1393.123.39.105
                      Oct 8, 2024 03:06:18.508600950 CEST382413498893.123.39.105192.168.2.13
                      Oct 8, 2024 03:06:18.508657932 CEST3498838241192.168.2.1393.123.39.105
                      Oct 8, 2024 03:06:18.513423920 CEST382413498893.123.39.105192.168.2.13
                      Oct 8, 2024 03:06:28.514107943 CEST3498838241192.168.2.1393.123.39.105
                      Oct 8, 2024 03:06:28.518925905 CEST382413498893.123.39.105192.168.2.13
                      Oct 8, 2024 03:06:28.685590029 CEST382413498893.123.39.105192.168.2.13
                      Oct 8, 2024 03:06:28.685738087 CEST3498838241192.168.2.1393.123.39.105
                      Oct 8, 2024 03:06:31.462349892 CEST48202443192.168.2.13185.125.190.26
                      Oct 8, 2024 03:07:28.734805107 CEST3498838241192.168.2.1393.123.39.105
                      Oct 8, 2024 03:07:28.740108013 CEST382413498893.123.39.105192.168.2.13
                      Oct 8, 2024 03:07:28.907763958 CEST382413498893.123.39.105192.168.2.13
                      Oct 8, 2024 03:07:28.908122063 CEST3498838241192.168.2.1393.123.39.105
                      TimestampSource PortDest PortSource IPDest IP
                      Oct 8, 2024 03:05:49.072932959 CEST3577953192.168.2.1351.158.108.203
                      Oct 8, 2024 03:05:49.088387012 CEST533577951.158.108.203192.168.2.13
                      Oct 8, 2024 03:05:51.692514896 CEST5048153192.168.2.1380.152.203.134
                      Oct 8, 2024 03:05:51.910128117 CEST535048180.152.203.134192.168.2.13
                      Oct 8, 2024 03:05:54.550093889 CEST5107053192.168.2.1381.169.136.222
                      Oct 8, 2024 03:05:54.752870083 CEST535107081.169.136.222192.168.2.13
                      Oct 8, 2024 03:05:57.362029076 CEST4661253192.168.2.1351.158.108.203
                      Oct 8, 2024 03:05:57.383697987 CEST534661251.158.108.203192.168.2.13
                      Oct 8, 2024 03:05:59.999314070 CEST5029353192.168.2.13194.36.144.87
                      Oct 8, 2024 03:06:00.009316921 CEST5350293194.36.144.87192.168.2.13
                      Oct 8, 2024 03:06:02.620208979 CEST3309453192.168.2.13217.160.70.42
                      Oct 8, 2024 03:06:02.835741043 CEST5333094217.160.70.42192.168.2.13
                      Oct 8, 2024 03:06:05.453380108 CEST4733253192.168.2.1370.34.254.19
                      Oct 8, 2024 03:06:10.458461046 CEST4011653192.168.2.13139.84.165.176
                      Oct 8, 2024 03:06:15.463547945 CEST4784653192.168.2.13185.181.61.24
                      Oct 8, 2024 03:06:15.679043055 CEST5347846185.181.61.24192.168.2.13
                      Oct 8, 2024 03:06:18.298240900 CEST5860953192.168.2.1380.152.203.134
                      Oct 8, 2024 03:06:18.498577118 CEST535860980.152.203.134192.168.2.13
                      TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                      Oct 8, 2024 03:05:49.072932959 CEST192.168.2.1351.158.108.2030xcf36Standard query (0)enemybotnet.comA (IP address)IN (0x0001)false
                      Oct 8, 2024 03:05:51.692514896 CEST192.168.2.1380.152.203.1340x7c3eStandard query (0)enemybotnet.comA (IP address)IN (0x0001)false
                      Oct 8, 2024 03:05:54.550093889 CEST192.168.2.1381.169.136.2220xd22eStandard query (0)enemybotnet.comA (IP address)IN (0x0001)false
                      Oct 8, 2024 03:05:57.362029076 CEST192.168.2.1351.158.108.2030x14c8Standard query (0)enemybotnet.comA (IP address)IN (0x0001)false
                      Oct 8, 2024 03:05:59.999314070 CEST192.168.2.13194.36.144.870xd523Standard query (0)enemybotnet.comA (IP address)IN (0x0001)false
                      Oct 8, 2024 03:06:02.620208979 CEST192.168.2.13217.160.70.420xf19fStandard query (0)enemybotnet.comA (IP address)IN (0x0001)false
                      Oct 8, 2024 03:06:05.453380108 CEST192.168.2.1370.34.254.190xf9f7Standard query (0)enemybotnet.comA (IP address)IN (0x0001)false
                      Oct 8, 2024 03:06:10.458461046 CEST192.168.2.13139.84.165.1760xc235Standard query (0)enemybotnet.comA (IP address)IN (0x0001)false
                      Oct 8, 2024 03:06:15.463547945 CEST192.168.2.13185.181.61.240xa4d5Standard query (0)enemybotnet.comA (IP address)IN (0x0001)false
                      Oct 8, 2024 03:06:18.298240900 CEST192.168.2.1380.152.203.1340x7e8bStandard query (0)enemybotnet.comA (IP address)IN (0x0001)false
                      TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                      Oct 8, 2024 03:05:49.088387012 CEST51.158.108.203192.168.2.130xcf36No error (0)enemybotnet.com93.123.39.105A (IP address)IN (0x0001)false
                      Oct 8, 2024 03:05:51.910128117 CEST80.152.203.134192.168.2.130x7c3eNo error (0)enemybotnet.com93.123.39.105A (IP address)IN (0x0001)false
                      Oct 8, 2024 03:05:54.752870083 CEST81.169.136.222192.168.2.130xd22eNo error (0)enemybotnet.com93.123.39.105A (IP address)IN (0x0001)false
                      Oct 8, 2024 03:05:57.383697987 CEST51.158.108.203192.168.2.130x14c8No error (0)enemybotnet.com93.123.39.105A (IP address)IN (0x0001)false
                      Oct 8, 2024 03:06:00.009316921 CEST194.36.144.87192.168.2.130xd523No error (0)enemybotnet.com93.123.39.105A (IP address)IN (0x0001)false
                      Oct 8, 2024 03:06:02.835741043 CEST217.160.70.42192.168.2.130xf19fNo error (0)enemybotnet.com93.123.39.105A (IP address)IN (0x0001)false
                      Oct 8, 2024 03:06:15.679043055 CEST185.181.61.24192.168.2.130xa4d5No error (0)enemybotnet.com93.123.39.105A (IP address)IN (0x0001)false
                      Oct 8, 2024 03:06:18.498577118 CEST80.152.203.134192.168.2.130x7e8bNo error (0)enemybotnet.com93.123.39.105A (IP address)IN (0x0001)false

                      System Behavior

                      Start time (UTC):01:05:47
                      Start date (UTC):08/10/2024
                      Path:/tmp/x86.elf
                      Arguments:/tmp/x86.elf
                      File size:54352 bytes
                      MD5 hash:06e3ae9bd59b025cb7181795f58aae35

                      Start time (UTC):01:05:47
                      Start date (UTC):08/10/2024
                      Path:/tmp/x86.elf
                      Arguments:-
                      File size:54352 bytes
                      MD5 hash:06e3ae9bd59b025cb7181795f58aae35

                      Start time (UTC):01:05:47
                      Start date (UTC):08/10/2024
                      Path:/tmp/x86.elf
                      Arguments:-
                      File size:54352 bytes
                      MD5 hash:06e3ae9bd59b025cb7181795f58aae35

                      Start time (UTC):01:05:47
                      Start date (UTC):08/10/2024
                      Path:/usr/lib/udisks2/udisksd
                      Arguments:-
                      File size:483056 bytes
                      MD5 hash:1d7ae439cc3d82fa6b127671ce037a24

                      Start time (UTC):01:05:47
                      Start date (UTC):08/10/2024
                      Path:/usr/sbin/dumpe2fs
                      Arguments:dumpe2fs -h /dev/dm-0
                      File size:31112 bytes
                      MD5 hash:5c66f7d8f7681a40562cf049ad4b72b4