Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
demon.x86.elf

Overview

General Information

Sample name:demon.x86.elf
Analysis ID:1635822
MD5:81349e42618a34ec849cf5b6853a3901
SHA1:d8369f79b3ae16b68cc608f072a122ea51f20e30
SHA256:14217a50150f55e95a07a6ef6e0375b2de9f0baf792db277beaf821188229525
Tags:elfuser-abuse_ch
Infos:

Detection

Score:64
Range:0 - 100

Signatures

Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Suricata IDS alerts for network traffic
Detected TCP or UDP traffic on non-standard ports
Sample has stripped symbol table
Sample listens on a socket
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Yara signature match

Classification

Joe Sandbox version:42.0.0 Malachite
Analysis ID:1635822
Start date and time:2025-03-12 02:22:18 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 54s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:demon.x86.elf
Detection:MAL
Classification:mal64.linELF@0/0@0/0
Command:/tmp/demon.x86.elf
PID:6212
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
Dark infection successful!!
Standard Error:
  • system is lnxubuntu20
  • demon.x86.elf (PID: 6212, Parent: 6132, MD5: 81349e42618a34ec849cf5b6853a3901) Arguments: /tmp/demon.x86.elf
  • cleanup
SourceRuleDescriptionAuthorStrings
demon.x86.elfLinux_Trojan_Gafgyt_9e9530a7unknownunknown
  • 0x2cb8:$a: F6 48 63 FF B8 36 00 00 00 0F 05 48 3D 00 F0 FF FF 48 89 C3
demon.x86.elfLinux_Trojan_Gafgyt_807911a2unknownunknown
  • 0x34a7:$a: FE 48 39 F3 0F 94 C2 48 83 F9 FF 0F 94 C0 84 D0 74 16 4B 8D
demon.x86.elfLinux_Trojan_Gafgyt_d4227dbfunknownunknown
  • 0x1f46:$a: FF 48 81 EC D0 00 00 00 48 8D 84 24 E0 00 00 00 48 89 54 24 30 C7 04 24 18 00
  • 0x2080:$a: FF 48 81 EC D0 00 00 00 48 8D 84 24 E0 00 00 00 48 89 54 24 30 C7 04 24 18 00
demon.x86.elfLinux_Trojan_Gafgyt_620087b9unknownunknown
  • 0x3067:$a: 48 89 D8 48 83 C8 01 EB 04 48 8B 76 10 48 3B 46 08 72 F6 48 8B
demon.x86.elfLinux_Trojan_Gafgyt_0cd591cdunknownunknown
  • 0x28c2:$a: 4E F8 48 8D 4E D8 49 8D 42 E0 48 83 C7 03 EB 6B 4C 8B 46 F8 48 8D
Click to see the 4 entries
SourceRuleDescriptionAuthorStrings
6212.1.0000000000400000.0000000000406000.r-x.sdmpLinux_Trojan_Gafgyt_9e9530a7unknownunknown
  • 0x2cb8:$a: F6 48 63 FF B8 36 00 00 00 0F 05 48 3D 00 F0 FF FF 48 89 C3
6212.1.0000000000400000.0000000000406000.r-x.sdmpLinux_Trojan_Gafgyt_807911a2unknownunknown
  • 0x34a7:$a: FE 48 39 F3 0F 94 C2 48 83 F9 FF 0F 94 C0 84 D0 74 16 4B 8D
6212.1.0000000000400000.0000000000406000.r-x.sdmpLinux_Trojan_Gafgyt_d4227dbfunknownunknown
  • 0x1f46:$a: FF 48 81 EC D0 00 00 00 48 8D 84 24 E0 00 00 00 48 89 54 24 30 C7 04 24 18 00
  • 0x2080:$a: FF 48 81 EC D0 00 00 00 48 8D 84 24 E0 00 00 00 48 89 54 24 30 C7 04 24 18 00
6212.1.0000000000400000.0000000000406000.r-x.sdmpLinux_Trojan_Gafgyt_620087b9unknownunknown
  • 0x3067:$a: 48 89 D8 48 83 C8 01 EB 04 48 8B 76 10 48 3B 46 08 72 F6 48 8B
6212.1.0000000000400000.0000000000406000.r-x.sdmpLinux_Trojan_Gafgyt_0cd591cdunknownunknown
  • 0x28c2:$a: 4E F8 48 8D 4E D8 49 8D 42 E0 48 83 C7 03 EB 6B 4C 8B 46 F8 48 8D
Click to see the 4 entries
TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
2025-03-12T02:22:58.484975+010028366151Malware Command and Control Activity Detected192.168.2.2344796196.251.81.24610019TCP

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: demon.x86.elfReversingLabs: Detection: 47%

Networking

barindex
Source: Network trafficSuricata IDS: 2836615 - Severity 1 - ETPRO MALWARE ELF/Miori Variant CnC Activity : 192.168.2.23:44796 -> 196.251.81.246:10019
Source: global trafficTCP traffic: 192.168.2.23:44796 -> 196.251.81.246:10019
Source: /tmp/demon.x86.elf (PID: 6212)Socket: 127.0.0.1:12121Jump to behavior
Source: global trafficTCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
Source: global trafficTCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
Source: global trafficTCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
Source: unknownTCP traffic detected without corresponding DNS query: 196.251.81.246
Source: unknownTCP traffic detected without corresponding DNS query: 196.251.81.246
Source: unknownTCP traffic detected without corresponding DNS query: 196.251.81.246
Source: unknownTCP traffic detected without corresponding DNS query: 196.251.81.246
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443

System Summary

barindex
Source: demon.x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_9e9530a7 Author: unknown
Source: demon.x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_807911a2 Author: unknown
Source: demon.x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_d4227dbf Author: unknown
Source: demon.x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_620087b9 Author: unknown
Source: demon.x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_0cd591cd Author: unknown
Source: demon.x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_33b4111a Author: unknown
Source: demon.x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_a33a8363 Author: unknown
Source: demon.x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_6a77af0f Author: unknown
Source: demon.x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_e0cf29e2 Author: unknown
Source: 6212.1.0000000000400000.0000000000406000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_9e9530a7 Author: unknown
Source: 6212.1.0000000000400000.0000000000406000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_807911a2 Author: unknown
Source: 6212.1.0000000000400000.0000000000406000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d4227dbf Author: unknown
Source: 6212.1.0000000000400000.0000000000406000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_620087b9 Author: unknown
Source: 6212.1.0000000000400000.0000000000406000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_0cd591cd Author: unknown
Source: 6212.1.0000000000400000.0000000000406000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_33b4111a Author: unknown
Source: 6212.1.0000000000400000.0000000000406000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a33a8363 Author: unknown
Source: 6212.1.0000000000400000.0000000000406000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_6a77af0f Author: unknown
Source: 6212.1.0000000000400000.0000000000406000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_e0cf29e2 Author: unknown
Source: ELF static info symbol of initial sample.symtab present: no
Source: demon.x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_9e9530a7 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = d6ad6512051e87c8c35dc168d82edd071b122d026dce21d39b9782b3d6a01e50, id = 9e9530a7-ad4d-4a44-b764-437b7621052f, last_modified = 2021-09-16
Source: demon.x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_807911a2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = f409037091b7372f5a42bbe437316bd11c655e7a5fe1fcf83d1981cb5c4a389f, id = 807911a2-f6ec-4e65-924f-61cb065dafc6, last_modified = 2021-09-16
Source: demon.x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_d4227dbf reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 58c4b1d4d167876b64cfa10f609911a80284180e4db093917fea16fae8ccd4e3, id = d4227dbf-6ab4-4637-a6ba-0e604acaafb4, last_modified = 2021-09-16
Source: demon.x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_620087b9 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 06cd7e6eb62352ec2ccb9ed48e58c0583c02fefd137cd048d053ab30b5330307, id = 620087b9-c87d-4752-89e8-ca1c16486b28, last_modified = 2021-09-16
Source: demon.x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_0cd591cd os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 96c4ff70729ddb981adafd8c8277649a88a87e380d2f321dff53f0741675fb1b, id = 0cd591cd-c348-4c3a-a895-2063cf892cda, last_modified = 2021-09-16
Source: demon.x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_33b4111a reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 9c3b63b9a0f54006bae12abcefdb518904a85f78be573f0780f0a265b12d2d6e, id = 33b4111a-e59e-48db-9d74-34ca44fcd9f5, last_modified = 2021-09-16
Source: demon.x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_a33a8363 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 74f964eaadbf8f30d40cdec40b603c5141135d2e658e7ce217d0d6c62e18dd08, id = a33a8363-5511-4fe1-a0d8-75156b9ccfc7, last_modified = 2021-09-16
Source: demon.x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_6a77af0f os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 4e436f509e7e732e3d0326bcbdde555bba0653213ddf31b43cfdfbe16abb0016, id = 6a77af0f-31fa-4793-82aa-10b065ba1ec0, last_modified = 2021-09-16
Source: demon.x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_e0cf29e2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 3f124c3c9f124264dfbbcca1e4b4d7cfcf3274170d4bf8966b6559045873948f, id = e0cf29e2-88d7-4aa4-b60a-c24626f2b246, last_modified = 2021-09-16
Source: 6212.1.0000000000400000.0000000000406000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_9e9530a7 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = d6ad6512051e87c8c35dc168d82edd071b122d026dce21d39b9782b3d6a01e50, id = 9e9530a7-ad4d-4a44-b764-437b7621052f, last_modified = 2021-09-16
Source: 6212.1.0000000000400000.0000000000406000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_807911a2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = f409037091b7372f5a42bbe437316bd11c655e7a5fe1fcf83d1981cb5c4a389f, id = 807911a2-f6ec-4e65-924f-61cb065dafc6, last_modified = 2021-09-16
Source: 6212.1.0000000000400000.0000000000406000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d4227dbf reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 58c4b1d4d167876b64cfa10f609911a80284180e4db093917fea16fae8ccd4e3, id = d4227dbf-6ab4-4637-a6ba-0e604acaafb4, last_modified = 2021-09-16
Source: 6212.1.0000000000400000.0000000000406000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_620087b9 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 06cd7e6eb62352ec2ccb9ed48e58c0583c02fefd137cd048d053ab30b5330307, id = 620087b9-c87d-4752-89e8-ca1c16486b28, last_modified = 2021-09-16
Source: 6212.1.0000000000400000.0000000000406000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_0cd591cd os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 96c4ff70729ddb981adafd8c8277649a88a87e380d2f321dff53f0741675fb1b, id = 0cd591cd-c348-4c3a-a895-2063cf892cda, last_modified = 2021-09-16
Source: 6212.1.0000000000400000.0000000000406000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_33b4111a reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 9c3b63b9a0f54006bae12abcefdb518904a85f78be573f0780f0a265b12d2d6e, id = 33b4111a-e59e-48db-9d74-34ca44fcd9f5, last_modified = 2021-09-16
Source: 6212.1.0000000000400000.0000000000406000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a33a8363 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 74f964eaadbf8f30d40cdec40b603c5141135d2e658e7ce217d0d6c62e18dd08, id = a33a8363-5511-4fe1-a0d8-75156b9ccfc7, last_modified = 2021-09-16
Source: 6212.1.0000000000400000.0000000000406000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_6a77af0f os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 4e436f509e7e732e3d0326bcbdde555bba0653213ddf31b43cfdfbe16abb0016, id = 6a77af0f-31fa-4793-82aa-10b065ba1ec0, last_modified = 2021-09-16
Source: 6212.1.0000000000400000.0000000000406000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_e0cf29e2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 3f124c3c9f124264dfbbcca1e4b4d7cfcf3274170d4bf8966b6559045873948f, id = e0cf29e2-88d7-4aa4-b60a-c24626f2b246, last_modified = 2021-09-16
Source: classification engineClassification label: mal64.linELF@0/0@0/0
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath InterceptionDirect Volume AccessOS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Non-Standard Port
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
demon.x86.elf47%ReversingLabsLinux.Trojan.Gafgyt
No Antivirus matches
No Antivirus matches
No Antivirus matches
No contacted domains info
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs
IPDomainCountryFlagASNASN NameMalicious
109.202.202.202
unknownSwitzerland
13030INIT7CHfalse
196.251.81.246
unknownSeychelles
37417SONIC-WirelessZAtrue
91.189.91.43
unknownUnited Kingdom
41231CANONICAL-ASGBfalse
91.189.91.42
unknownUnited Kingdom
41231CANONICAL-ASGBfalse
MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
109.202.202.202kpLwzBouH4.elfGet hashmaliciousUnknownBrowse
  • ch.archive.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_92.0%2bbuild3-0ubuntu0.20.04.1_amd64.deb
196.251.81.246demon.x86.elfGet hashmaliciousUnknownBrowse
    demon.mips.elfGet hashmaliciousUnknownBrowse
      demon.arm.elfGet hashmaliciousUnknownBrowse
        demon.mpsl.elfGet hashmaliciousUnknownBrowse
          demon.arm.elfGet hashmaliciousUnknownBrowse
            demon.mpsl.elfGet hashmaliciousUnknownBrowse
              demon.mips.elfGet hashmaliciousUnknownBrowse
                demon.x86.elfGet hashmaliciousUnknownBrowse
                  91.189.91.43na.elfGet hashmaliciousPrometeiBrowse
                    demon.x86.elfGet hashmaliciousUnknownBrowse
                      demon.mips.elfGet hashmaliciousUnknownBrowse
                        demon.arm7.elfGet hashmaliciousUnknownBrowse
                          morte.ppc.elfGet hashmaliciousUnknownBrowse
                            morte.arm.elfGet hashmaliciousUnknownBrowse
                              morte.mpsl.elfGet hashmaliciousUnknownBrowse
                                morte.x86.elfGet hashmaliciousUnknownBrowse
                                  morte.sh4.elfGet hashmaliciousUnknownBrowse
                                    morte.m68k.elfGet hashmaliciousUnknownBrowse
                                      91.189.91.42na.elfGet hashmaliciousPrometeiBrowse
                                        demon.x86.elfGet hashmaliciousUnknownBrowse
                                          demon.mips.elfGet hashmaliciousUnknownBrowse
                                            demon.arm7.elfGet hashmaliciousUnknownBrowse
                                              morte.ppc.elfGet hashmaliciousUnknownBrowse
                                                morte.arm.elfGet hashmaliciousUnknownBrowse
                                                  morte.mpsl.elfGet hashmaliciousUnknownBrowse
                                                    morte.x86.elfGet hashmaliciousUnknownBrowse
                                                      morte.sh4.elfGet hashmaliciousUnknownBrowse
                                                        morte.m68k.elfGet hashmaliciousUnknownBrowse
                                                          No context
                                                          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                          SONIC-WirelessZAdemon.x86.elfGet hashmaliciousUnknownBrowse
                                                          • 196.251.81.246
                                                          demon.mips.elfGet hashmaliciousUnknownBrowse
                                                          • 196.251.81.246
                                                          demon.arm.elfGet hashmaliciousUnknownBrowse
                                                          • 196.251.81.246
                                                          demon.mpsl.elfGet hashmaliciousUnknownBrowse
                                                          • 196.251.81.246
                                                          demon.arm.elfGet hashmaliciousUnknownBrowse
                                                          • 196.251.81.246
                                                          demon.mpsl.elfGet hashmaliciousUnknownBrowse
                                                          • 196.251.81.246
                                                          demon.mips.elfGet hashmaliciousUnknownBrowse
                                                          • 196.251.81.246
                                                          demon.x86.elfGet hashmaliciousUnknownBrowse
                                                          • 196.251.81.246
                                                          Global e-Banking Payment Advice 000000164.exeGet hashmaliciousAgentTeslaBrowse
                                                          • 196.251.83.222
                                                          P.Order request for quotations.exeGet hashmaliciousFormBookBrowse
                                                          • 196.251.83.222
                                                          CANONICAL-ASGBna.elfGet hashmaliciousPrometeiBrowse
                                                          • 91.189.91.42
                                                          demon.x86.elfGet hashmaliciousUnknownBrowse
                                                          • 91.189.91.42
                                                          demon.mips.elfGet hashmaliciousUnknownBrowse
                                                          • 91.189.91.42
                                                          demon.arm7.elfGet hashmaliciousUnknownBrowse
                                                          • 91.189.91.42
                                                          morte.ppc.elfGet hashmaliciousUnknownBrowse
                                                          • 91.189.91.42
                                                          morte.arm.elfGet hashmaliciousUnknownBrowse
                                                          • 91.189.91.42
                                                          morte.mips.elfGet hashmaliciousUnknownBrowse
                                                          • 185.125.190.26
                                                          morte.mpsl.elfGet hashmaliciousUnknownBrowse
                                                          • 91.189.91.42
                                                          morte.x86.elfGet hashmaliciousUnknownBrowse
                                                          • 91.189.91.42
                                                          morte.sh4.elfGet hashmaliciousUnknownBrowse
                                                          • 91.189.91.42
                                                          CANONICAL-ASGBna.elfGet hashmaliciousPrometeiBrowse
                                                          • 91.189.91.42
                                                          demon.x86.elfGet hashmaliciousUnknownBrowse
                                                          • 91.189.91.42
                                                          demon.mips.elfGet hashmaliciousUnknownBrowse
                                                          • 91.189.91.42
                                                          demon.arm7.elfGet hashmaliciousUnknownBrowse
                                                          • 91.189.91.42
                                                          morte.ppc.elfGet hashmaliciousUnknownBrowse
                                                          • 91.189.91.42
                                                          morte.arm.elfGet hashmaliciousUnknownBrowse
                                                          • 91.189.91.42
                                                          morte.mips.elfGet hashmaliciousUnknownBrowse
                                                          • 185.125.190.26
                                                          morte.mpsl.elfGet hashmaliciousUnknownBrowse
                                                          • 91.189.91.42
                                                          morte.x86.elfGet hashmaliciousUnknownBrowse
                                                          • 91.189.91.42
                                                          morte.sh4.elfGet hashmaliciousUnknownBrowse
                                                          • 91.189.91.42
                                                          INIT7CHna.elfGet hashmaliciousPrometeiBrowse
                                                          • 109.202.202.202
                                                          demon.x86.elfGet hashmaliciousUnknownBrowse
                                                          • 109.202.202.202
                                                          demon.mips.elfGet hashmaliciousUnknownBrowse
                                                          • 109.202.202.202
                                                          demon.arm7.elfGet hashmaliciousUnknownBrowse
                                                          • 109.202.202.202
                                                          morte.ppc.elfGet hashmaliciousUnknownBrowse
                                                          • 109.202.202.202
                                                          morte.arm.elfGet hashmaliciousUnknownBrowse
                                                          • 109.202.202.202
                                                          morte.mpsl.elfGet hashmaliciousUnknownBrowse
                                                          • 109.202.202.202
                                                          morte.x86.elfGet hashmaliciousUnknownBrowse
                                                          • 109.202.202.202
                                                          morte.sh4.elfGet hashmaliciousUnknownBrowse
                                                          • 109.202.202.202
                                                          morte.m68k.elfGet hashmaliciousUnknownBrowse
                                                          • 109.202.202.202
                                                          No context
                                                          No context
                                                          No created / dropped files found
                                                          File type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), statically linked, stripped
                                                          Entropy (8bit):5.571267643608892
                                                          TrID:
                                                          • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                                                          File name:demon.x86.elf
                                                          File size:25'760 bytes
                                                          MD5:81349e42618a34ec849cf5b6853a3901
                                                          SHA1:d8369f79b3ae16b68cc608f072a122ea51f20e30
                                                          SHA256:14217a50150f55e95a07a6ef6e0375b2de9f0baf792db277beaf821188229525
                                                          SHA512:40872d3e0367e15adfefc5e80194d446f86d43d49170fce8b87bf4307eb6c1f9cfdcba49f8c7b3d82be795ac1790368eec64de2d4108c27cbd0a06c51fbf716d
                                                          SSDEEP:384:aBbgBHIEw5+j/IaIZ/7Ij0fj1IFZAx+luS2eT2iXi6itAXeGLrj7QHjO6EGYW:aB4HIFc/IaIZzMZJ5j2FlaPj7gjTY
                                                          TLSH:CBC2F82367C198BEC899C37755ABB238E133763D0362F59A23E4FB2A998AD101E5D500
                                                          File Content Preview:.ELF..............>.......@.....@....... b..........@.8...@.......................@.......@.....`V......`V.......................`.......`P......`P.............................Q.td....................................................H...._.....L..H........

                                                          ELF header

                                                          Class:ELF64
                                                          Data:2's complement, little endian
                                                          Version:1 (current)
                                                          Machine:Advanced Micro Devices X86-64
                                                          Version Number:0x1
                                                          Type:EXEC (Executable file)
                                                          OS/ABI:UNIX - System V
                                                          ABI Version:0
                                                          Entry Point Address:0x400194
                                                          Flags:0x0
                                                          ELF Header Size:64
                                                          Program Header Offset:64
                                                          Program Header Size:56
                                                          Number of Program Headers:3
                                                          Section Header Offset:25120
                                                          Section Header Size:64
                                                          Number of Section Headers:10
                                                          Header String Table Index:9
                                                          NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                                          NULL0x00x00x00x00x0000
                                                          .initPROGBITS0x4000e80xe80x130x00x6AX001
                                                          .textPROGBITS0x4001000x1000x4c460x00x6AX0016
                                                          .finiPROGBITS0x404d460x4d460xe0x00x6AX001
                                                          .rodataPROGBITS0x404d600x4d600x9000x00x2A0032
                                                          .ctorsPROGBITS0x5060000x60000x100x00x3WA008
                                                          .dtorsPROGBITS0x5060100x60100x100x00x3WA008
                                                          .dataPROGBITS0x5060400x60400x1a00x00x3WA0032
                                                          .bssNOBITS0x5061e00x61e00xdd280x00x3WA0032
                                                          .shstrtabSTRTAB0x00x61e00x3e0x00x0001
                                                          TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                          LOAD0x00x4000000x4000000x56600x56606.06910x5R E0x100000.init .text .fini .rodata
                                                          LOAD0x60000x5060000x5060000x1e00xdf083.26150x6RW 0x100000.ctors .dtors .data .bss
                                                          GNU_STACK0x00x00x00x00x00.00000x6RW 0x8
                                                          TimestampSIDSignatureSeveritySource IPSource PortDest IPDest PortProtocol
                                                          2025-03-12T02:22:58.484975+01002836615ETPRO MALWARE ELF/Miori Variant CnC Activity1192.168.2.2344796196.251.81.24610019TCP
                                                          TimestampSource PortDest PortSource IPDest IP
                                                          Mar 12, 2025 02:22:58.479365110 CET4479610019192.168.2.23196.251.81.246
                                                          Mar 12, 2025 02:22:58.484153032 CET1001944796196.251.81.246192.168.2.23
                                                          Mar 12, 2025 02:22:58.484224081 CET4479610019192.168.2.23196.251.81.246
                                                          Mar 12, 2025 02:22:58.484975100 CET4479610019192.168.2.23196.251.81.246
                                                          Mar 12, 2025 02:22:58.489604950 CET1001944796196.251.81.246192.168.2.23
                                                          Mar 12, 2025 02:22:58.489650965 CET4479610019192.168.2.23196.251.81.246
                                                          Mar 12, 2025 02:22:58.494304895 CET1001944796196.251.81.246192.168.2.23
                                                          Mar 12, 2025 02:22:59.433011055 CET43928443192.168.2.2391.189.91.42
                                                          Mar 12, 2025 02:23:05.064121008 CET42836443192.168.2.2391.189.91.43
                                                          Mar 12, 2025 02:23:06.088042974 CET4251680192.168.2.23109.202.202.202
                                                          Mar 12, 2025 02:23:19.654145002 CET43928443192.168.2.2391.189.91.42
                                                          Mar 12, 2025 02:23:31.940431118 CET42836443192.168.2.2391.189.91.43
                                                          Mar 12, 2025 02:23:36.035970926 CET4251680192.168.2.23109.202.202.202
                                                          Mar 12, 2025 02:24:00.608670950 CET43928443192.168.2.2391.189.91.42

                                                          System Behavior

                                                          Start time (UTC):01:22:57
                                                          Start date (UTC):12/03/2025
                                                          Path:/tmp/demon.x86.elf
                                                          Arguments:/tmp/demon.x86.elf
                                                          File size:25760 bytes
                                                          MD5 hash:81349e42618a34ec849cf5b6853a3901

                                                          Start time (UTC):01:22:57
                                                          Start date (UTC):12/03/2025
                                                          Path:/tmp/demon.x86.elf
                                                          Arguments:-
                                                          File size:25760 bytes
                                                          MD5 hash:81349e42618a34ec849cf5b6853a3901