Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
gY2rWwaH7T.elf

Overview

General Information

Sample name:gY2rWwaH7T.elf
renamed because original name is a hash value
Original sample name:578553b85a60b77c1c112fae1e83c3a51b5e8e4c71d40ea3ec2dabef52b55e5a.elf
Analysis ID:1665624
MD5:c45fc85cbdb939eea34bfb83548668b9
SHA1:8decbb11c7ac5ceb15b27c3eadc834f6e94139c8
SHA256:578553b85a60b77c1c112fae1e83c3a51b5e8e4c71d40ea3ec2dabef52b55e5a
Tags:elfuser-mentality
Infos:

Detection

Score:48
Range:0 - 100

Signatures

Antivirus / Scanner detection for submitted sample
Detected TCP or UDP traffic on non-standard ports
Sample has stripped symbol table
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

Joe Sandbox version:42.0.0 Malachite
Analysis ID:1665624
Start date and time:2025-04-15 17:47:26 +02:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 45s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:gY2rWwaH7T.elf
renamed because original name is a hash value
Original Sample Name:578553b85a60b77c1c112fae1e83c3a51b5e8e4c71d40ea3ec2dabef52b55e5a.elf
Detection:MAL
Classification:mal48.linELF@0/0@0/0
Command:/tmp/gY2rWwaH7T.elf
PID:6253
Exit Code:139
Exit Code Info:SIGSEGV (11) Segmentation fault invalid memory reference
Killed:False
Standard Output:
ELF@`4V4 (@@O0O0PEPEPT$dtQ<'<!'<'! '9 <'!'9F ' <'!' "V`@P Y $B P P Y $B4@$4 $O0$"V` '(<'!'\\$O0@$Vd lP@$P ' ' !<'d!!'$$'x4 0 0 F$@!bF$c%`(!! "!<'!'($ 0&2&12!"@ !X0" !*`"S$t !(!$ &12($ '0L (!@L$ $<'p!000F$@!b$c%`(!! $
<'!000F$@!b$c%`(!!8 <'x!'D@<840,($ X0!!0`_f $P@!@M!'$$X0" ! !*$u#&RT&1L` !D@<840,($ $ 'HL (!@L$ $u&R&R!X !D@<840,($ 'H P@!@| X @ ! !L (!@6 !X @ !| \ @! $ !L (!@&1L ! (!@ !L $| x bFPDCu(!$Cu$$ @ !0!$b!&$!E$$c0!B Q!Cy8! 0!!x D @@(!@0!8!!!d!D$C+`@8!<'!'tplhd`\XTP ,!!@!$@$@@$`$b'(L@ !$ $(& @<,B@&%L $(& 8`@ ! $ @@!!D@+&6/@(<&4Br!#!H0!b!#!&6L(! $(H c$Vcb0$'&c0&s !` $ @@!<@ 4$b"'d+@2`$ $& @@ ! (! 4$cb#"!4&$b&L $('d+ @& @ @<D@8 !0!@8! D@ !@&1@&@@ ! 7@@ tplhd`\XTP'x D@<8 !0!@8! D@ @D <'`!'($ `$ $PL@!D$(#" $`b!$q$B $@!D$(#" $`b!$q$B $@!D("$ `b!$q$B $@!D$(#" $`b!$q$B $0@!D$(#" $`b!$q$B $@!D$(#" $`b!$q$B $@!D$(#" $`b!$q$B $@!D$(#" $`b!$q$B $T@!D$
(#" $`b!$q$B $<@!D$(#" $`b!$q$B $l@!D$(#" $b!$qB&pt` !(!$ &sp($ '0,@0!$,0!`$$00!0C!$D!'0B<41"GR1J1eb1l1t1@Ah#C#J!
N^01Gf#(#(! !d#C#M!01Gf#(#(! !d#C#I!01Gf#(#(! !d#C#H!01Gf#(#(! !d#C#89g#(#E%0BH!(*@$0@!$(@!`$$0C!%1D
!D!e!F!b!,0BE!,'0B@!@!<'T!| d#b!bb<'!' 0| d#Xb! !,bNF6NF>6(!!b&b !"&!b&b !$&*@ '(<'!' 0| d#Xb! !,bNF6NF>6(!!b&b !"&!b&b !$&*@ '(<'!'840,($ 0|b#Xs! ! !`,NF6NF>6(!!b&b !"&!b&b !$&*@C#S!D$| ' !X @!`,NF6NF>6(!!b&b !"&!b&b !$&*@@!@!840,($ '@<'!',($ $$$G`@ ! @!<[|4B{V$ $$$G@ ! @!<4B;$ $$$J@ ! @!<d$4B* $$$G@ ! @!<L4B_w$ $$$G@ ! @!<4BX$ $$$G@ ! @!<0$4B@D< $2$2$G@ ! @!<14B8
H$2LP $=$=$G@ ! @!<74BMsT$=X\ $$$H(@ ! @!<6$4B5480 $$$H8@ ! @!<4B$ $$$HL@ ! @!<Pl4B $
$
$H\@ ! @!<]a4B$$
(, $$$Hl@ ! @!<.4BFx$| $1$1$H@ ! @!< 4BSl$1pt $$$H@ ! @!</4B$ $$$I@ ! @!<QS4B[ $$$I@ ! @!<$4Bb $$$I@ ! @!<4B` $$$I@ ! @!<J4B $$$I@ ! @!<N4B`$ $$$Jp@ ! @!<Q4B$ $$$J@ ! @!<v4BQ$ $ $,$,$J@ ! @!<'d4B'($,,0 $9$9$J@ ! @!<@4B3d$9hl $@ !$J$ @!<C$4BRbxpt,($ '0<'@!'0<0804000,0(0$0 00`0@ $$` $"` $#(! $$T @ !@8@! ` !@+@ !$B0B,B
@$@ ! $
@!\ 't$ ! (!$$ (!@(! ! !0 '@(! " ! !0 $$"(! @!0 ! @(!$t ! (! !(! $V"! @ !@(! @!VX @ !0@@$t ! (!$$ (!@(! !0 !@(! " !0 !$#(! @!@(! 0 !T !@S@!' !@!t$ !(!@$b$B0B,B
@$v $$ (!@(! !0 !@(! " !0 !$#(! @!@(! 0 !0 !" ! $K00 !(! " ! !t$ (! !(! $"!0^ ! ` 0@0 @!0@ !(! @8! !L^$ t ` !( $$( $"( $#0<0804000,0(0$0 00'0@8B@L ! $t !<'!'LHD@<840t'$!! !(! ` $%(! $%@ ! (!$%( @!$bX',' !$`0! @8!@A !0! 8!$C !0!H!$ $$
$&!B@G*`GAH?*;H!(@F!D$ (!$"!$ dC$`$BF!%!0@ !(B@(! !X ` !0 !@LHD@<840'P$$(!F!%!0@ !(B@ !<'@!'@t'*$n!(! ` !xF
EPCTDUES %0!8'-$ !0T 4P@(!p $$*<<4v4U$BXQ@ ! $$ 0!@ !<`(!$Q+B Q1$@!! ' xD$ $$@( ! ! !p $!'Pd0! ! !d4F $$<'!'<840,($ !!!!+$$$` ! 4(!@Q0# !$@ @!@$$ !<840,($ '@V"!2+W^$<'!'8!<40,($ !!!0R!$ , $0S&Tt!$b#',$$ 0BQ&
!$@
&0!!!C
$d&!F$!T ! `(! !L(!30! $@(@!!<840,($ '@$<' !'$ ' $
@,@!# D
xp!d D
,p!d !$ '(<'(!'($ !$ '@4@!t$@*(! D
q!e ! D
q!e $ ! @(!($ '0<'!<'4cm(#!<<`l44<< !(!44c8!~!@'d'd<d4<<(!' 4B4'4^!'0 !$'C<48!@$BU<!4c~!c@$BC<$4c~!cBC!DD$ %DD<4 !<48!Bg!dD$ %<4B^!BF(*dD<4c~!f(@<$@$@X !$, $ @ !$ <4AF,4,$@$X0F#B0!1B9@g!f#C#@$cKpC!F `, !pX P!+@P D
p!c$b,B@ <4cCB @ !D#$bC<Vh`><g#$b<$$ 0!@!$@$ <$4B^!$G4$ ! !d$ 0! !d4F $ !H $(`<<4(!<48!!B !$b%<4B^!BW(*<4c~!wX !8$
`W4l@R<b@L@K4!%!e$c<4(!!B !G$b%<4B^!BG(*<4c~!g&1"*@"&,l !$$BxC+@$ &1"*@&,<4(!<4<8!4B^!E$0! 8!@b@l@@@<<44c'E8!'e~!!!dBD0B@W&sbb*@&,l!$@<4c~!cBC!C00c`<48!<$4B0 ^!G4 $ `X !b@g',<4 !q<&"0B48!c!#', ! $$$$& $& $ !$$ $&1 !0! 8! $@!$bXDc&sd
&, !bb*@~$
<48!BG!CD0c`$$K(b@<4 !BD!C$0c,`0<',4c~!g !4 $0`<jnmqCrCEuEDD$ ! $x$(,C$ $bi<}!($q<4c~!cBC!CD0c`e<48! $]< $ ',@'@!,@!!,&1%*@&$ 0!@@! 4,R ` ! 4e4 !BD!CD0c`4t! !(! 4! !@!! Q"P" !S0#(! $@@O@!$B:$ O$"r!"S""@""@<4c~!c4b8!0!(! !"
$b&""+@0!@$b#,b@E$cK4C!D !b$b(7P$ !(! $@@@!($)B' ! %!b%"
C&!B!@w<(b@@C`<4 !$"<4 !+@,$ $<48! @!0B&$' !$'$ $$"0<'T4B^!B'<$ $@$Cp$x<Ddj$$c,X !` !XDB',4c~!!B!`4B4BH @P'i4`$@ @!@@!$"<b4C8! ! $
$D $ES$#b{$gwC,$
', $ e4B5xb<4c<~!',4d(!e$ ,$L$$ 'M$IJ K$$ 'Q<4c~!f !$ $b@jX !d<4c~!,d', $<4B^!F !&G $(k@""@|$c$<4c~!c4b!2t%&<b!P @ !@
RP$&% 0!X !$<4c~!c4b!H @&L&D&$ $
@ $<4c~!c4b!DH @ @ !$"$"C<48!4(!'( $(` q$X ! 0` !XD<4B^!E $$LD # !<4c~!c4e(!'( $(U@:$lb@4$` $,l@@b$:C!!$l&$ ! b*@&1,$@l@$@!!lD& $ !b*@&1,l@ l$@X !<4dH$4$5 $5`b@!$<cC!DH$56f $5&1b"*@$<4& !&4(! !$<'h!'lhd`\XTPLHp t'@ ! ! $0!8$ (!$ $$
$x | @" !$x 0!p(b@@@ @
@t0 ,B@p(b@`$!tF!P0 ! !t@0! (!$p$BD*`$$ !@
!lhd`\XTPLH'p @!| $` b$ '$$X@(! $$X$Kl $( $X !X $X $$< &D !( $$x$ &P$$ $,cvwn qruf i@ !#jdD`mn$qp $dP0! ! !d4F $pD $d0! !4Fd ! $tp h BfBiBf Bi 88$4$'4' ',D<@$,`C(D!$&sb*@:#!T $Th"!D<4W '(Th"!D<@4W 0!DT@!BX"!D &sC#!pb*@h tp $,D@$BV<dBf!b$(E%b@D0$0! 8!@m<DBf!b0B@'( $$C|$c(bxXD 8L $$Ld # !tE &@p(b@`t0 $CW$ &DP2tb$rDT$C@X"!D 0! $TQ-L8 (!@ 88$$=| pPt b'4' ',D<@<'}!'8`0!$! 0 ! (!$8! 0B !(!$4 l @!<4aG ! (!8G#B8!9Ah!g!C#G!G $0B !(!$$ h0B $4 !(! d ! (!$4 | ! (!0!$ x ! (!$$ @!0B !(!$8! Xtx G$ ! (! ! (!$$ p ! (!$$ @! ! (!$$ @! ! (!$$ HD !(!$ $@$bBS*@&d$PH$b
D*@,D $d@!$$ $$P@!$$$ !(!$ ' P*|x0c`t00c!2\@T$ 2$E$CB '$B0c0B00!40" `$PS*\DB`z `$ $ ! d!p<4cC$<@<D%4cC$<D%hl&4&d<8&&&:$@$/ p` x eE
f!b @b#~!d<$eX8b$
&<4cC$<@<D%4cC$<D%&l4"h0$d@#$@#$ "T~"$B'}"DHH*$B'$'(','.L !p$b @4 x eE
f!b"`P\pT"B $ (` !$ ,&d $&d $&d
$X@$HbD*@*@$&(! $P !$
@ !P"
$ @
B
@ !(!& !@ #% !$$&B (!$@ ! $d*@H @C#^(!b!q,B &3&2&@O&4: !@ # !bp!$bA0 :" ]B O D": 0B$C'"5CP$L$BLD*@@$b ` !,D _@! $LX !', @(!P<'s!'p|xtplh`0 !$$(,0 ! 0 !`$ < ! (!$4 @! ! (!$4 0V0B !(!0!$ X0B !(!$$ T' 0B$8! !(! P ! (!$$ L ! (!$$ @! ! (!$$ @! ! (!$$ HD !(!$ $@!$b@BS*@A&d$H$bDbHb*@`H,D $d0BTT,@$X4b! 0BXL@ @0SPe<<8B4C!",B @
#0 #b!0$$ $@ !@D$6$X<&'$$$ (@HD (! $L``(!8@$B$c8@&1T&&RL``!`` ! $B 0CD $|xtplh'HD!b*`H$B\*$P<!`5!H$b@.cDbU.c`@i.c$` !`&$!$ `(! !%`0! $@&1&R$$&*@i$ ! !%`0!$@ &&1&R$.c$` !`&$!$ `(! !%`0! $@&1&R$.c$` !`&$!$ `(! !%`0! $@&1&R$,\D &0D,`$$!$ `(! !%`0! $@&1&R$ $!, @(!@!L<'k!'8!0x! 0$B 0!$ !(! ! (!$$ @! ! (!$4 @!' 0B$8! !(! h ! (!$$ @! ! (!$$ @! ! (!$$ @! ! (!$$ \X !(!$ $T$b$BS*@&d$d\$Xbf *\$cX$B# !p'@P!!$$p$cFD@Ef$B @HH$b#'Ht(! ` !l'D'$'4','(`''D|@$BU!@$BWd$b`*@T$ !l@\pX,H(b@$HtH $!P!&$y$#"C!pC+@f$!B !$b%(*!&&1$&8!0!0 , !X !PL$6-@)BC!C2$0c`4B$0B@$ !P@(!$$@ @!V@X &RT&LSp, @(!dX !3 xhD
$46@C#C!,c `58$$ 0!@ !S"$$|$4$ $0d$0! ! !d4F $$H $$X$ !&]"$KN! bB!8 $`$|($ ! $@$@vtH $@$X ! $, $
`$c`e$0!$8!0 ,X !p,X Hc$bE$d<B&RHt $@X !`$`/2*H@l$HH$#'Ht ! $e'D$, ! `(!-@!\X\ *$B%\Xb*<'bd!'P`0 !!$! 0 ! (!$8! x0B !(!$4 d @!<4aG ! (!8G#B8!9Ah!g!C#G!G $0B !(!$$ `0B $4 !(! \ ! (!$4 t ! (!0!$ p ! (!$$ @!0B !(!$8! Plx G$ ! (! ! (!$$ h ! (!$$ @! ! (!$$ @! ! (!$$ @< !(!$ $8$bBS*@&d$H@$b
<*@,< $d@!$$ $$P@!$$$ !(!$ ' Px*tp0cXl00c2T@L$ 2$E$C4 '$B0c0B00!40,("T(B X$PC*D`q `$ $x ! xd!p<`4D$<@<C%4D$<C%d4\&&,`&$@$/ hC` x eE
f!b $b!@ #<4cC$ !<@C%<4D$<D%d"`0,"#\`$$@$$ "$C"L@'#@<@*$BD| b !h$b}4XTPL`"BP$@b<*|@*@$&d(! $P !$
@ !P"
$ @
B
f@ !`(!& ` !@ #b% !$$&4 (!$@ ! $d*@L @C#xW(!d!q,B &2@&3, !@ # !bh!$b0 4" 0B$CX'"yC ",TPs L`ob kBH$bD$*@D8$bC ` !<,< ^@! $DX !', @(!LH<'X!'d`\XTPLHD@ !00l8$8! !(! $ ! (!$4 4 ! (!$8! @! ! (!$8! @! ! (!$4 0 ! (!$4 @! ! (!$$ @! ! (!$$ @! ! (!$$ @! '$ !(!$ 8!@@!$@
b@x@24,$bBS*@&d$($$ $$P@!$$$ !(!$ ' P'8t !(! $8<4B $<@< %4B $$< %0804220e$$A9:<@$@>,$2(!NPL ''L$'(82 bfjP !$
$F$"
!@(! @D&#B$($,* ! (! $@ 8$cd*@X 4x `C
@b#lb0! !"#,B @ !@ #l !b!0 " B <4caC D#B !!)e!d!C#D!C#($b$$*@$ $bg ` !` $$X !d`\XTPLHD@'h, @(!(<'R!'tplhd`\XTP`0 !!$! 0 ! (!$8! @!0B !(!$4 D L<4aG ! (!8G#B8!9Ah!g!C#G!G $0B !(!$8! <0B $4 !(! 8 ! (!$$i H ! (!$$ @! ! (!$$ @! ! (!$$ @!($bBS*@!&d$0` $&$& '$$$$@! $P@!$$$ !(!$ ' P3LH0c0@4a <4S!`$ $ !w!p<@S$C%<4cC$<C%D&$$B <@8$@$ xC@ x eE
f!b 4@C#U!C$$$c$#& > @(! $p*@ ,e 3 !@sL4OTP !$
$"
F$ !@(! @ !@E #$B !$$ ! (! $@ $d*@1 @C#U(!w!q,B 4@&2 !@ # !b@!s0 4" " B0$C,$*@,($C @ ! $,X !tplhd`\XTP'x, @(!0<'K!'`|x`0 !!$$! 0 ! (!$8! @!0B !(!$4 \ l<4aG ! (!8G#B8!9Ah!g!C#G!G $0B !(!$8! T0B $4 !(! P ! (!$4 h ! (!0!$ d ! (!$$ 0T0Bx g !(!$ D`'$$8! !(! ! (!$$ @ ! (!$$ @! ! (!$$ @! ! (!$$ 40 !(!$ $,$bBS*@&d$<4$b
0* .,0 $d0T.@!$$$$`! $Ps@!$$$ !(!$ ' Pa@@$@q0TDlhd0c039XLHm &&0B0s!K(! <4cC$<<@C%4D$<b%T\(XP`$@$ `` exdD
e!b S @D#V!D$qLH7*BD` `$ $ !~!p@ 8!&0!&&(! $404Y*$c8tp o!`$ "@ x eE
f!b"X4PLpuHyD 4S
.0st.@(!$&D$ !P& !$"
"
F !@(!& @ E!@ # !B"&$ (! ! $@ $cw*@B !@ #^! !Q@(e#&!b,B @&2p $ !@ # !`b!s0 l" H" B s"<$"8$B8Y*@,$b? ` !8,p `(!n0T $8X !|x', @(!^<@<'B!'!0@b!$c 0$! !(!$8! # $0B !(!$4 x' <4aG ! (!8G#B8!9Ah!g!C#G!G $0B !(!$$ p0B !(!$4 l0B !(!$8! h0B !(!$$ d0B !(!$
$ `0B !(!$8! \0B !(!$8! X ! (!$
8! 0V0! $ !(! 0U ! (!$$ @!0B !(!$8! T'$$8! !(! ! (!$$ L ! (!$$ @! ! (!$$ @! ! (!$$ @< !(!$ $8$bBS*@&d$H@$b<*@*@!$$$ $$Q@!$$ !(!$ ' QL`!$T00Bt`P2d0`\X0B0c0&'<2'L'($|t(! $ !@%$@$$ 0!@!$ud$0! ! !d4F $$Cf$cph,c ,0`l.H',$ !X !@! @! &Cb+`2t$((! $ !$ $@$XC* !@b`hC<l<b$f$f@X !X !$$ 0!@!$!' cb!0!*L,< $d@!, @(!H'<@<@b*$D&@g !@!
&0&&&s& SV&1 t4bn&PcP !$
!(!2F@8!
$$$<#">@$ !(! $@`$"TT!`" @$<b*@*@&($&(&(! $&s&& S&1 H$bD$*@D8$b ` ! " $$ $D, `(!@!db$hh"<4cC$<<@C%4D$<C%"x&("$pt$l#&0@&2($@"x$"b"$#<4d$<Pb% P@n<4cC$<D%4cC$<D%4cC$<D%4cC$<D%4cC$<D%4cC$C%L@ !L 0!|$c $B$ |& b&s(! $<'5!'00$ <b4cMC`$$0f#f!C# `$ $$8! $0B$4 0B <4aG $8G#B8!9Ah!g!C#C!G $ $$ $ $0B$4 $0B$8! $0B$$ $0B$
$ $0B$8! | $0B$8! x $0B$
8! t $0!$ 0P $$$ @!'$$0B$8! p $$$ l $$$ h $$$ d $$$ X $T$ $lP$@s@!p2' $8!<|xt0B0c000'<'L'(l@$`$X ! <4aG $8G#B8!9Ah!g!C#C!G $0B$$$ R@!$$$ @ !(! $Rv !$ 4 $ '($=@$4@$$ 0!R`@!d$0! @ ! !d4F $ !@$ #,!b,B @b04.H !', $X !@!$K$ !((!$ $@ !XR\,C(@0``.< P#(B@X !$$ 0!R@! $BF*` \ !@!!C!Q4c&3p$XTbg*@$!@!(B@$&d(! $ @db#f!!$$dV,&R2PP&( !$"
&"
2 !`(!&G ` b@C#&! ! (! $@`bR!b $BD*`A C!Q4!&3 "l<b$g$gy@aX !p !@ # !b!40 ., `(!x@!`$\$B\F*@,P$d ` !$<Y<h$$d*@`X$bT*@+@Z$X$ $\X !' C!EdFChbDC ! g!p<4cC$<@C%V$<C%`Q&x$d D!CDC$<#4E<P $F %&$ %""<4G$<C%4D$<F%4G$<C%4D$<4cF%C$<4cG%C$C%"l!(!0! &( $BF*`
$@,$ (!R`,T $dU@!l$&( (! $BF*` g<'(,!'0`0 !!$$! 0 ! (!$8! @!0B !(!$4 \ <4aG ! (!8G#B8!9Ah!g!C#G!G $0B !(!$8! T0B $4 !(! P ! (!$4 ! (!$4 | ! (!$8! x ! (!$$ t ! (!$
8! p ! (!$8! l ! (!$8! h ! (!$
8! d ! (!0!$ ` ! (!$$ @!0Bxg !(!$ D@'$$8! !(! ! (!$$ < ! (!$$ @! ! (!$$ @! ! (!$$ 0, !(!$ $($bBS*@&d$80$b
,*@*,, $d@!*@$<`$@@!D$$ $$P@!$$$ !(!$ ' P|00B0cXLH tp0D0elh0F0gd`0H0i<&(%@-4<D@L0r4S!<L<"<PS$C%4D$<C%4D$<C%4D$<C%4D$<C%4D$<C%4D$C%"H$ "<@N&(@(! 0! $P*`R `$ $ !~!p<<@S$C%4D$<C%\XTP@&$@$ @` x eE
f!b @b#v!b4xC| u"0,0*$B4 w0!@$s @ x eE
f!b"X4PLp}HxPD`20
*,S`*@$&D(! $2P&( !$"
&"
2 !@(!& @ @ F%d#v!B$ef (!&( ! $@ C$Ft!*C@L !@ #^! !Q@(e#&!b,B @x&2p $ !@ # !b@!sk0 d" H" BxP{ tB a"8$4$B4D*@($b- ` !&, @(!`@! $4(! $X !', @(!8$<<'!'8`0 !$! 0 ! (!$8! 0B !(!$4 P |<4aG ! (!8G#B8!9Ah!g!C#G!G $0B !(!$$ H0B $4 !(! D ! (!$4 x ! (!$4 t ! (!$8! p ! (!$8! l ! (!$8! h ! (!$
8! d ! (!$8! ` ! (!$$ \ ! (!$
8! XTxG$ ! (! ! (!0!$ 4 ! (!$$ @! ! (!$$ @! ! (!$$ @! ! (!$$ @! ! (!$$ @!($*@&$0$bBS*@&d, @(!@!$$ $$P@!$$$ !(!$ ' P*|x0c0L@th0c0!<@8$ &rd`0EX0f\0HT800i0D&c<<%@-4<D@L0t4V&u!` ! $ ! d!p<@&V$C%<4cC$<C%PLHD$@$ 4b@ x eE
f!b @<@C#4C!C"<V$C%D$<C%4D$<C%4D$<C%4D$<C%4D$C%<4cC$D%"<p"$$#( )0B$Bx$
*/$$$,. -0$$8$:;4`9! !&1qb< $P*`a &V(&U,&T !C!Q&2! !&pb< @b#d!d$b,B @|$4 b@ x E
f!b"L4P@pp<tpPzlp~8?P !$
!"
@(!28! @ @ d#F%d!B$ef (! !0! $@ $c~*@ 0$b,$*@U,($br ` !k Bp !@ # !4b!$w0 p" <B BpP lpB }B f" $,X !', (!0<',!H"0!lI$ (!$$$,GgD!$$,$b!d!C#I!!<'|!' $!XQ@ ! @@@ ! t !(! $, '(<'!'@<840,(0F!2elR$Cb]&C, !$bE$c,$`!!@!@<840,('H@!&H,8!"A$!%,#$b !0$$ $$ 0!@ !P"$$' 4$ 0d !$ 0!4Fd$ !$X !"35 4$H"4
&% $@!@!" "E !<'
!'($ ' !X ! "& "&\ @! &BI<[@i%(&C&8%C&'8&@%BB'&qV4BS % &0%*@bV0&(&&VEV($ '0<'!'840,($ VVD&g&C&C0&VV0VVV@V!!!! gVV"D&&C&C@&IV&V1VFV'V@hV gVV"D&&C&C@&IV&V1VFV'V@hV gVV"D&&C&C@&IV&V1VFV'V@ohV gVV"D&&C&C@&IV&V1VFV'V@YhV gVV"D&&C&C@&IV&V1VFV'V@ChV gVV"D&&C&C@&IV&V1VFV'V@-hV gVV"D&&C&C0&IV(V0VHV'V@?fV VV"D&&C&C@&VV1VVV@QV+@!Be%D%(&E&1@0&@&$B-B %(%$ &(&@D&e&V#VFVhV840,($ !'@+@!Be%D%h&F& 1@@&0&$B-B %(% &(&@D&e&VVVV<'<!',($ !<4BVfV<#4cV<4B6e WbV<!4SM$tK$."@V &10H@J1)T1J #B3 !!B)@e!d!@#1@!0&#BS0!1B!@d!f!#H#1)4H!8G#BS8!9B!@d!g!CP#1JTP!(E#B(!)B!@d!e!C#0BT!$EFC&D &E(&F0& &,($ '0 &1S D#B !!B)@e!d!C#R& &<'!'<840,($ !!<4SM$tK$."@VV"D&c&C&C8&VV0VVV@V+@!Be%D%(&E&1@0&P&+
"B
BE%d%&c&"
*@ &(&DVeVFVjV1G8
B1
L1)
V&1#Bb!B!@D!C!8#08!(#B3(!)B@C!E!@#1@!0&#BS0!1B@C!F!"H#1)4H! D#B !!B@C!D!BP#1JTP!$EB&C&D &E(& &<840,($ '@VV"D&&C&C8&VV0VVV@@V+@!Be%D%(&E&1@0&8&+"BBE%d%"&&"*@ &(&DVeVFVgV&1#Bb!B!@D!C!#R& 6& [@P! @8!<'!'D@<840,($ !!R0`!$gVV"D&&C&C@&VV1VVV@ZhV+@!e%B&D%(1@0&E&@&$B %-B(%$ &D&(&V@e&CVVV$BR2R(R(R*@$&"&1D@<840,($ 'H&"&1R @@!"<'!'$ VV>B8%2@&"&&B@&8&X&BVC%"&@V !b&@C%B&@b`&3BF%&1b&!!VVVVVVVV0#$c`c
$ P!'(@! @X!<'T!'!@@@ ! @ ! ' ' <'!'000!$$ 0!@!$b'\!!'t(! ! $ 0B$0^a\]`_ !'h$B@@!'i8!$.0$&$B(!@$i`$@!8!# !$$b`b`$ $@@! &lB',$h2e&b'<'$|x$'\ 0B$$5,.0@<
`C
C !0x@d` !$ 0!$dF0$` ! $lh$`(!` !0! $@U@!l^$d$0! ` !` !d4F $' ~!$ (!r%0!8!($ 'h` !(!$@l$@b0B@e U+0@] ! \]""!(%0%$Dbcb% ``##@?(!@!$2@,C`<!4@E!(!$2@,C$!b %&
$@0! !$:@,E<!4@E!0!$:@,EC !`$B@!`|4 $$+$t 40 <4cC !D#~`R<$b<PP$b<4Bb:x8BxX ` !`X !p4B<$<4cW4BF*<%<4c4B=<=<A4cz4Bj<3M<4c4B<]<4c4BoH <.4cC(! # #D#!b04B~$cG$E$d$b$cb%dZ@0!%$C%B !$e|B$b%eFdB%`*8! !$
$
$
$IJK
%*@$
H$
<4B~4BPP<LL{4B@ !!@ !0!$(*@$ $|p@3 *d e*@!d$8$ d@t( $@ !@D!t$cDp b%$C !|( $@(!@
e!$Bd`\<'h!' 0 0@!@!P $D
"@p!p@@ ! @ !! '(<'!'d`\XTP!$$ 0!$PIB $4,$ ('(<D*, (! $P%$
HD(*, (! $P'@T ! $<!$4BB8< :@D'8$ $@$C$XD !!d`\XTP'h!!d`\XTP'h$D$4$' $'LPD`(!$ $@0P. @$Lb 0!!XD !'T$ $@p(!'`e+@` !
$ b%d!$d+@!b%f$@CC<!4BBb&<'!'L!PHD@<8<l4ew<54c4P(+ <<<J}44Bp4c$(, 0@c @\$ @U( @N, @G !@@' $+'@!$Q!&!$#'% !#! !`$ $&R@ !@&1 @E*@`!! !!!PLHD@<8'X@!`!@!*@P!$H!@!$?K@!%)!I!Bd%%)%)%"@!8!!D!$d!!b8!$Cb$!@!$0..0!$@!b@$cd#@!b@$ce0#$!$c$$b$!!0!$ $$
$$-5<$+<<4BX!E
@!8!PH$,b
@e*$,B@$$7#e*@(+@$C*$C@!$@$,B@$W`#$$!`<$<4B<'!'($ !!!!@(!!!@$BC%(!` ! $$C,%$*0!$@(!$
b"!(!0!$
$
H$cfbG`$cf$(#%!($ '0$!$!!($ '0<'P!'($ !!
!!&1@&@@ ! Q@` !($ '0($ '0<'!'840,($ !D@k!!b@$cp# c'D!CG!$?bD !$BC@$$!@@!b@$cp#$R ! &e@@! @ !(!@@!@&F$
&I !!$b$$c$!@&$B@2# !C$?$$B@!!840,($ '@!!<'!' l$ 'X@ @b!'( @@ C!'($B<'!'840$ $@$ $@!$"O$ <$4cI%CC # Bd! #D#,b@*<4B H'$5$ !(! (!4 ! 'X ! CV(d$c CV840!'@$cKC!D !@V840!'@(!840!'@| @(!840!'@<4B <T4BEP <y4B <PP4BPP <4B8 <4B <C4B <'!'`!d\XTPLHD@|x&B*!$# hp00'@$!`!!!d`\XTPLHD@'h$ $$P8d@ !$ 0!8d4F $$$8(!$ ' PQ&Cp !$$c@d$B#<4B<b$<d%4Bb$2P<@b%&#" $"$@"#pP"h&7& "4 ! $@"
(!!D!$Ed$$$&'$$&(8 (! $@8X @!`!X8 $}`!<'(!'840,(! !' $:@m@!@CBDE$0c,b
@g$66$0B,C
`q$0B,B@>$$0B,B@f$d%$C b(DF$0c,b
@$..$0B,C
`$0B,B@B$$0B,B@$$%! !C%F%*"(% %@`!!&1@&@@ ! Q@ ` !840,('@0B,B@$$0B,B@$0B6$0B,C
`6%$CbDE$0c,b
@.$0B,B@$$0B,B@$0B6$0B,C
`#6%*C`bDE$0c,b
@"$0B,B@$$0B,B@$$66$0B,C
`$0B,B@$$0B,B@$66$0B,C
`
$0B,B@$$0B,B@$%$CZbDE$0c,b
@
$0B,B@s$$0B,B@$$66$0B,C
`
$0B,B@]$$0B,B@$%*C`-b DE$0c,b
@
$0B,B@N$$0B,B@v$$66$0B,C
`$0B,B@8$$0B,B@_$%!0B,B@0$$0B,B@X$$0B66-0B6d6F0B6n60B660B660B..%!$$$7$$Z0B6C6$~0B6g6$0B660B..<'(!'x|xtplhd`` $,(! $,@ ! (!$,( @!$'XX'X!@$Bb!!$$$
(! ! $!V&&RU !"T@x !!$
$
(!g$
B#f$$BB# c$:Xb !$C$:bU$$$!` $-(! $-@(!*"
@<! !$?$
!F !&R21&!Bb$&R&R( $-&T$$ b
!!$D$ $C&1 !8 X !X$BzX( $-t!r!X !X@!|xtplhd`' XD
!B<'!'p|xtplh`! $'` $(` $)` $*(! $'T @ !d@Vd @I'Y@!'Y`$c'!'9`$c!`$cC$UC$.b$' (!@ !B@a@@!!b@$cd8#$'X!@(!$$c$f$G@!@F!!b@$cu8#$;!(! !!$$c$f$!$((! h!@ !B@"!b@$cd(#$`!$$b$$c@ ! (!@!$" !(! $ @@!X ! !!$
$
(!g$f$$B#'!@`&!b@$cu #$!$b$b&s$c(! !@b%`@$) (!@ !B@!b@$cd(#$!$$b$$c@ ! (!@!$" !(! $ @Z@!X ! !!$
$
(!g$f$$Bb #!@!9$0br$x(!$0D$0c,b
@$!0$0B,C
`0B$0B,B@$$0BD%0B$C$* (!@ !B@!b@$cd#$b{$`$c$$e`qX !d @td ( $'( $(( $)( $*!|xtplh':b$Xb$';`$!Y E$0B0B,B@$$0Bv!0B,B@$p$0B,B@w$0Bg!@ ! (!@!$(! ! $$C$1bX !3X !{<'h!'TPLHD@<840\@
!TPLHD@<840'X` $4$4' @!T$B !@@!! ` !@0! !@H&
$b $@!0 !@P! '`$E(! $@ !(!@B P0 ! ! ! (! @0!D $$,h<4W' B@ ! ` ! @0! !@&t ` !$3 '(@r!(T @e@! ` !$Q0@W !C
$b !@(!$ &$ !C& !0P!@@! &`$ P(!@ !'@B P0 ! ! ! (! @0!D $$,h<B@ ! 4W ' ` !$Q0@ !t ` !&*@&( $4(@ @ !\~t!<'!$$@ ! <'!'$ $'4,c4`0 $@! P$$ '(<'0!'$ '440$|@! P$!$ '(<'!'$@! P$!' <'`!'$@! P$!' <'!'$@! P$' <'!'$@! P$' <'@!'$@! P$' <'!'($ !! !$=C\ @!(B@$!! !@&@!(!@ !$k@! P@ `@! @(!@
@!@! @ @ ! !! !($ '0<'p!' $ '@$ `!'(<' !'Pp!' !'Y$L !C$ $B+ !@ !@ (!`! $$C (!!'<'P!B@<@!`!<' !'$@! P$' <'!'$@! P$' <'`!'$@! P$' <'!'$ '440$@! P$!$ '(<'!'$@! P$!' <'0!'$ 0!4@0'4!`0!$@! P$!$ '(<'!$0! $<'!'! '8'$`' @! P$! '(<'!'$@! P$' <'!'$@! P$' <'P!'! '8'$.' @! P$! '(<'!'$@! P$' <'p!'$,B@$ $$
C$$c@!@ ! $P!' <'!'$@! P$' <'p!'$@! P$' <'!'$@! P$' <'!'$@! P$' <'P!'840,(!"$'$ !\0!R` ! $$%C`! < !$0` ! 2$@ @ !( !@ !840,(!'@<' !'@$< 4A@!N!@ ! '@ !,$ $A ! !(P @!30 $0@@!P@@@l,C`B$B`E $@B@ @ !( ! !$C&D (!@!'<'!'0,($\0!! '< !#"8b+@$%& @!" "#C!C!""@' $!0,('8<'!<'`!'( 'b! D#C!C!<4c(C$'0( !0B(%D(%@#10# !08#8!0!$00#$8!$#$F$!`C!(!!b@$c$ce#0b@<4G<4FbG!F$@$cb@$d#@#$B@#$B@#$B<'p!' '@$ `!'(<' !'$I@! P$' <'!'$J@! P$' <'`!'$L@! P$' <'!'! '8'$M' @! P$! '(<'!'$O@! P$' <' !'! '8<'$P' @! P$! '(<'!'$R@! P$' <'@!'! '8<'$T' @! P$! '(<'!'! '8'$U' @! P$! '(<'@!'$W@! P$' <'!'( 0!h` ' ! $C$' <'p!'0(! $!' <'0!'<8$!(@
$ $$$C'@$caD!h' (!@$4 (!,Bd !' '@$<8!'@$BD!C$C$+$Bd!d$ %!d$1B00!$'b$!<'!'($ ,$@a<$ '\ @!GPp+@p!$B#C$<, !@0!$$$$b$ & #\, $" < 0! (! '\ @!&! !$C!($ '0<'!' !
! $C`! !@!00!@ !@(! ! '(<'!'$ S!< &(! 0!R@!BB+@<, & !"\, \$ '(`b@CC\ #$ #\,$ '(<'`!',($
!@ !$ !,($ '0$C$."@$$Q+@-&"< 2#0! (!\ @!P!-b &$@@!$!`(!&F @ !` !@ !`!B+@`!< (! Q0#\ q`!,($ '0$$BC0$,@$!g+@$,+@#fbbh@0!H0!bg#$Bc`!'$gg#$H+@ $0$+@$,+@#ebeb8!bc`8!!<'!'$ @!H!@H!&E+5#$C+@.h! '%"%"&(!'9( B! ###$B
0! (!'9( C! !! 8! 0!'9( (!!
%8! 0!'9( (! !$ '(<'@!'0,(\'! !< 8Y ! ! $D $@$ D !<'P!'8x$ '@$caE!h' ! $@i'< (!$ 0!@b$ ! $@I$ '@$caD!h' $@L$d(! ' A' $<'0!Q @!$6$$b'd ! (! @!`(!<$0!P @!0<`(!$ 0! !d(!'d(! @!@<4cdb*C!!$'<'!' <C48!d'(!04b#C#F!8#C#G! '(<'!'@@C#y &@C!$DY HY ' ' !<'!' ,!$ !$C
$$L (!PH '(<'$!'bW$@$bW$$C@ @ ' ' <'!'P!0!$CH!$CB!!0'(! $x!b@$e!@' D !(! $&, 'L L`$$CtQ @!| @!tq|bb !$Q/$< ! <$ ! 66 ! $@@DC#PDD!C@C!Y &+@``! @@!C#@C!Y &+@@ @@@@ @ !F! @(!T @ !<'0!' !P$' <'!'d`\X!!!$$' '0(! 0!'8h@ ! $ @!&$'@@$< "P8"#!d`\X'h<'!'$b@! P$' <'!' ! !$@! P<'@!'H'!(!$@! P$` !@ (! !'<'!'$ !@@!!0F
$ ! (!!+&@& !$ '(<'!'@!D<840,($ $#'!!H`(!${@! R$$B!;$`!$/$$$BC0$&@!+@8!H 0!4& $$C#"&#""! $!r!+&$&@8!4 #!D@<840,($ !'H<'!'$@! P$!' <'!'$@! P$!' <'P!'$@! P$' <'!'$@! P$' <'!'$!( (!'0!@''$,' @!@ ! $P@!!($ '0<'!'$F@! P$' <'!' !D@ ! @D @!Q ! @!A!$! '(<'!'$@! P$' <'!' !0!(! ! $"#"""" "$$"((,#<"8<8"XX"`#d`d"@@"HH"PP"DD"LL"TT '(<'p!' !0!(! ! $"""""" "$(,"04"PT"TX"8<"@D"HL"<@"DH"LP '((.!@&13H#1) 0#(! !08#8!0!$ $ 08#8!0!$$8!$$8#00#(! !08#8!$$0!<'!'#F+!@! !,(!@P!1B0#@!$%JB`$c0@O80-"@! !@
@!$cLC!B\!@'H!$$0%C$$)%C$$"%C$$%C$$%C$$
%C$%C$ $%Cibibibi%b$c$Hi`$@$$ 0Lh#$X!%b@8!`$b$b
H!@!%%k %G%%k%G%%G%%k%GC%C%C%C%%k`$$C%$$BP#(#0`0!%JB$$$!' <'!7X!p$
)$.@I!B0B@*@!$)@$$@C!@i!cF8!0b@)B@$$0b @HX%%J)B@$$!<'!',(< $Q'$ P!@$cah ! $@(!<$ 0!bW@@$bW@\ &Q $< &Q$W@b$0W@(!' $$ '$E!D$cad$' 0!b$W@
W@$b$DW@ $
<'0!C,C<'!'(! 0! !$E(+ !b! $$C!' <'!'X !(!\@ ! ' <'@!' $$BPY#$P$ &1 '(<'!'<'! '9 ' O`{d~h{l)|ymh}l)`g)y{fn{lzz+:#d%:/$$#)d%8-Jqjyvqkljykp6tqzj}d{pmj{pw~pwttaoww|6tqzj}dqm}kkqup}j}6tqzj}+`ar+sepgl`kcUTG\XBRnUTG1m&'4m70#,&-/B^UR@O^UR@ION^UR@IONO^UR<u+0$w:16w:-+!:7 $w:16w+0$/9,;0<7?$3+/9(<h$<9=576XLgfi|m(,=$888(af(PEZ(|g( <0[Na_ojIiNn?=C{Z[MMz<aLkpzm~Nr^e`onj>Y}l{{=:BC0kKZ0je]pFJXF:^eyL\}kBD;mijaRk=PZQ^Ocj`>J@=0Q|c!(|g(jm(jdikcda{|ml(nzge(|`a{(ifl(n}|}zm(jg|fm|{(nzge(}{&(Kgf|ik|2(`gz{mHza{m}x&fm|(a|`(\pAL(ifl(AX(Zifom'I[F&Zuh$&55."5G{|}f&ea|icm&kge&|t{|}f&~gq{&fdt{|}f9&d&oggodm&kget{|}f:&d&oggodm&kget{|}f;&d&oggodm&kget{|}f<&d&oggodm&kget{|}f&~gax{|}f|&kget{|}f&{axfm|&fm|e/>)e8/9%&<d)%$,Jp|tbtcgtc#u#o`m#{mxodhck#LLcBBBBBBBBBBBBBBBBBm/jjwjsTx`tjs<uvs\st
[c
iafXg\ii

VJ
=):*FT#('#),/dev/nullo<oLnnnooo( `EP @<7UVX|y~EQXAIAM0AM0EA@AA
0AAEjEWA`EPEWEW A/EQA*A
A@ApA`@eA#EV@A@1@A
0@A@/@'AEVAAF@EVEW0ApA9@(@|AA6ABAE@EVA'P@EVA9 A*@0AP@EVXEWP@y@lAhA5EV@hEVEW@@!A@@olEQEV@|@`AEk@HAG@A
A5@AC@,@AAAA=`EVA4@@A`@EV@EP0Ej|@JhAA A/@T@@A08EVA8A3AEVTEP$@ A
@X@@`EP,ApAp@DA%pAAEW`A>@AA@,@,@@.@
(A?A;AEVA@@A`AEVAE@A@EVEP(A A/A# A:A EVA@@A9A0EWA@pEQp@*EPX@@@,APA/AAEVAEVA+EjlA!0@A/A @Ei@EVA@@A)@EP@A:@A
A-EP8A(@<@^A;PEVEW@@ EVEVA6 A/A`A.PA@AP@SA`A
@HA3AApEQ@ApEg`A.shstrtab.init.text.fini.rodata.ctors.dtors.data.got.sbss.bss@@ EAGG\AG`G`%EPP,EPP3EP P 9EQQt>EVTVTDEV`VTVTI
Standard Error:qemu: uncaught target signal 11 (Segmentation fault) - core dumped
  • system is lnxubuntu20
  • gY2rWwaH7T.elf (PID: 6253, Parent: 6166, MD5: 0083f1f0e77be34ad27f849842bbb00c) Arguments: /tmp/gY2rWwaH7T.elf
  • cleanup
No yara matches
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: gY2rWwaH7T.elfAvira: detected
Source: global trafficTCP traffic: 192.168.2.23:39864 -> 82.24.200.45:7581
Source: global trafficTCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
Source: global trafficTCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
Source: global trafficTCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 82.24.200.45
Source: unknownTCP traffic detected without corresponding DNS query: 82.24.200.45
Source: unknownTCP traffic detected without corresponding DNS query: 82.24.200.45
Source: unknownTCP traffic detected without corresponding DNS query: 82.24.200.45
Source: unknownTCP traffic detected without corresponding DNS query: 82.24.200.45
Source: unknownTCP traffic detected without corresponding DNS query: 82.24.200.45
Source: unknownTCP traffic detected without corresponding DNS query: 82.24.200.45
Source: unknownTCP traffic detected without corresponding DNS query: 82.24.200.45
Source: unknownTCP traffic detected without corresponding DNS query: 82.24.200.45
Source: unknownTCP traffic detected without corresponding DNS query: 82.24.200.45
Source: unknownTCP traffic detected without corresponding DNS query: 82.24.200.45
Source: unknownTCP traffic detected without corresponding DNS query: 82.24.200.45
Source: unknownTCP traffic detected without corresponding DNS query: 82.24.200.45
Source: unknownTCP traffic detected without corresponding DNS query: 82.24.200.45
Source: unknownTCP traffic detected without corresponding DNS query: 82.24.200.45
Source: unknownTCP traffic detected without corresponding DNS query: 82.24.200.45
Source: unknownTCP traffic detected without corresponding DNS query: 82.24.200.45
Source: unknownTCP traffic detected without corresponding DNS query: 82.24.200.45
Source: unknownTCP traffic detected without corresponding DNS query: 82.24.200.45
Source: unknownTCP traffic detected without corresponding DNS query: 82.24.200.45
Source: unknownTCP traffic detected without corresponding DNS query: 82.24.200.45
Source: unknownTCP traffic detected without corresponding DNS query: 82.24.200.45
Source: unknownTCP traffic detected without corresponding DNS query: 82.24.200.45
Source: unknownTCP traffic detected without corresponding DNS query: 82.24.200.45
Source: unknownTCP traffic detected without corresponding DNS query: 82.24.200.45
Source: unknownTCP traffic detected without corresponding DNS query: 82.24.200.45
Source: unknownTCP traffic detected without corresponding DNS query: 82.24.200.45
Source: unknownTCP traffic detected without corresponding DNS query: 82.24.200.45
Source: unknownTCP traffic detected without corresponding DNS query: 82.24.200.45
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443
Source: ELF static info symbol of initial sample.symtab present: no
Source: classification engineClassification label: mal48.linELF@0/0@0/0
Source: /tmp/gY2rWwaH7T.elf (PID: 6253)Queries kernel information via 'uname': Jump to behavior
Source: gY2rWwaH7T.elf, 6253.1.000056449ad06000.000056449ad8d000.rw-.sdmpBinary or memory string: DV!/etc/qemu-binfmt/mips
Source: gY2rWwaH7T.elf, 6253.1.00007ffc09a3f000.00007ffc09a60000.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-mips/tmp/gY2rWwaH7T.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/gY2rWwaH7T.elf
Source: gY2rWwaH7T.elf, 6253.1.000056449ad06000.000056449ad8d000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/mips
Source: gY2rWwaH7T.elf, 6253.1.00007ffc09a3f000.00007ffc09a60000.rw-.sdmpBinary or memory string: /usr/bin/qemu-mips
Source: gY2rWwaH7T.elf, 6253.1.00007ffc09a3f000.00007ffc09a60000.rw-.sdmpBinary or memory string: qemu: uncaught target signal 11 (Segmentation fault) - core dumped
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath InterceptionDirect Volume AccessOS Credential Dumping11
Security Software Discovery
Remote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Non-Standard Port
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
SourceDetectionScannerLabelLink
gY2rWwaH7T.elf6%ReversingLabsLinux.Downloader.Mirai
gY2rWwaH7T.elf100%AviraLINUX/GM.MiraiDow.GR
No Antivirus matches
No Antivirus matches
No Antivirus matches
No contacted domains info
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs
IPDomainCountryFlagASNASN NameMalicious
82.24.200.45
unknownUnited Kingdom
5089NTLGBfalse
109.202.202.202
unknownSwitzerland
13030INIT7CHfalse
91.189.91.43
unknownUnited Kingdom
41231CANONICAL-ASGBfalse
91.189.91.42
unknownUnited Kingdom
41231CANONICAL-ASGBfalse
MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
109.202.202.202kpLwzBouH4.elfGet hashmaliciousUnknownBrowse
  • ch.archive.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_92.0%2bbuild3-0ubuntu0.20.04.1_amd64.deb
91.189.91.43boatnet.ppc.elfGet hashmaliciousMiraiBrowse
    boatnet.arm6.elfGet hashmaliciousMiraiBrowse
      boatnet.arm5.elfGet hashmaliciousMiraiBrowse
        boatnet.ppc.elfGet hashmaliciousMiraiBrowse
          boatnet.arm.elfGet hashmaliciousMiraiBrowse
            boatnet.arm.elfGet hashmaliciousMiraiBrowse
              na.elfGet hashmaliciousPrometeiBrowse
                sshd.elfGet hashmaliciousUnknownBrowse
                  na.elfGet hashmaliciousPrometeiBrowse
                    boatnet.arm7.elfGet hashmaliciousMiraiBrowse
                      91.189.91.42boatnet.ppc.elfGet hashmaliciousMiraiBrowse
                        boatnet.arm6.elfGet hashmaliciousMiraiBrowse
                          boatnet.arm5.elfGet hashmaliciousMiraiBrowse
                            boatnet.ppc.elfGet hashmaliciousMiraiBrowse
                              boatnet.arm.elfGet hashmaliciousMiraiBrowse
                                boatnet.arm.elfGet hashmaliciousMiraiBrowse
                                  na.elfGet hashmaliciousPrometeiBrowse
                                    sshd.elfGet hashmaliciousUnknownBrowse
                                      na.elfGet hashmaliciousPrometeiBrowse
                                        boatnet.arm7.elfGet hashmaliciousMiraiBrowse
                                          No context
                                          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                          CANONICAL-ASGBboatnet.ppc.elfGet hashmaliciousMiraiBrowse
                                          • 91.189.91.42
                                          boatnet.arm6.elfGet hashmaliciousMiraiBrowse
                                          • 91.189.91.42
                                          boatnet.arm5.elfGet hashmaliciousMiraiBrowse
                                          • 91.189.91.42
                                          boatnet.ppc.elfGet hashmaliciousMiraiBrowse
                                          • 91.189.91.42
                                          boatnet.arm.elfGet hashmaliciousMiraiBrowse
                                          • 91.189.91.42
                                          boatnet.arm.elfGet hashmaliciousMiraiBrowse
                                          • 91.189.91.42
                                          na.elfGet hashmaliciousPrometeiBrowse
                                          • 91.189.91.42
                                          sshd.elfGet hashmaliciousUnknownBrowse
                                          • 91.189.91.42
                                          na.elfGet hashmaliciousPrometeiBrowse
                                          • 91.189.91.42
                                          na.elfGet hashmaliciousPrometeiBrowse
                                          • 185.125.190.26
                                          CANONICAL-ASGBboatnet.ppc.elfGet hashmaliciousMiraiBrowse
                                          • 91.189.91.42
                                          boatnet.arm6.elfGet hashmaliciousMiraiBrowse
                                          • 91.189.91.42
                                          boatnet.arm5.elfGet hashmaliciousMiraiBrowse
                                          • 91.189.91.42
                                          boatnet.ppc.elfGet hashmaliciousMiraiBrowse
                                          • 91.189.91.42
                                          boatnet.arm.elfGet hashmaliciousMiraiBrowse
                                          • 91.189.91.42
                                          boatnet.arm.elfGet hashmaliciousMiraiBrowse
                                          • 91.189.91.42
                                          na.elfGet hashmaliciousPrometeiBrowse
                                          • 91.189.91.42
                                          sshd.elfGet hashmaliciousUnknownBrowse
                                          • 91.189.91.42
                                          na.elfGet hashmaliciousPrometeiBrowse
                                          • 91.189.91.42
                                          na.elfGet hashmaliciousPrometeiBrowse
                                          • 185.125.190.26
                                          INIT7CHboatnet.ppc.elfGet hashmaliciousMiraiBrowse
                                          • 109.202.202.202
                                          boatnet.arm6.elfGet hashmaliciousMiraiBrowse
                                          • 109.202.202.202
                                          boatnet.arm5.elfGet hashmaliciousMiraiBrowse
                                          • 109.202.202.202
                                          boatnet.ppc.elfGet hashmaliciousMiraiBrowse
                                          • 109.202.202.202
                                          boatnet.arm.elfGet hashmaliciousMiraiBrowse
                                          • 109.202.202.202
                                          boatnet.arm.elfGet hashmaliciousMiraiBrowse
                                          • 109.202.202.202
                                          na.elfGet hashmaliciousPrometeiBrowse
                                          • 109.202.202.202
                                          sshd.elfGet hashmaliciousUnknownBrowse
                                          • 109.202.202.202
                                          na.elfGet hashmaliciousPrometeiBrowse
                                          • 109.202.202.202
                                          boatnet.arm7.elfGet hashmaliciousMiraiBrowse
                                          • 109.202.202.202
                                          NTLGBxd.mpsl.elfGet hashmaliciousMiraiBrowse
                                          • 62.31.100.39
                                          xd.sh4.elfGet hashmaliciousMiraiBrowse
                                          • 82.0.40.143
                                          xd.spc.elfGet hashmaliciousMiraiBrowse
                                          • 213.107.147.109
                                          splx86.elfGet hashmaliciousUnknownBrowse
                                          • 86.26.95.127
                                          nklsh4.elfGet hashmaliciousUnknownBrowse
                                          • 82.8.228.144
                                          jklppc.elfGet hashmaliciousUnknownBrowse
                                          • 82.2.230.60
                                          nklmips.elfGet hashmaliciousUnknownBrowse
                                          • 81.101.48.245
                                          rep.arm7.elfGet hashmaliciousMiraiBrowse
                                          • 92.239.105.68
                                          rep.x86_64.elfGet hashmaliciousMiraiBrowse
                                          • 163.164.234.228
                                          splarm5.elfGet hashmaliciousUnknownBrowse
                                          • 82.18.222.195
                                          No context
                                          No context
                                          No created / dropped files found
                                          File type:ELF 32-bit MSB executable, MIPS, MIPS-I version 1 (SYSV), statically linked, stripped
                                          Entropy (8bit):4.1577278826978805
                                          TrID:
                                          • ELF Executable and Linkable format (Linux) (4029/14) 50.16%
                                          • ELF Executable and Linkable format (generic) (4004/1) 49.84%
                                          File name:gY2rWwaH7T.elf
                                          File size:1'503 bytes
                                          MD5:c45fc85cbdb939eea34bfb83548668b9
                                          SHA1:8decbb11c7ac5ceb15b27c3eadc834f6e94139c8
                                          SHA256:578553b85a60b77c1c112fae1e83c3a51b5e8e4c71d40ea3ec2dabef52b55e5a
                                          SHA512:b52d793825c56a8720802a1ade7323d430dd56540948c2fafc2941290f1f4e5b90ed34335d8ba7b97dbab71367e7fb1a8855d183b1b702a0329c4e911730c430
                                          SSDEEP:24:3m/EXC9R8omsxz8omyDVnjmgTcBcdJassRUbMUTAfPBoVLsHVNJYkx8WM8UU:2/alSOARSgTIcdESI2iVNJJaJm
                                          TLSH:EF31F0472FB25ED5FAAAC03846730B06739956B046D0CB0AC1DDE5001E513CE9CBD7E9
                                          File Content Preview:.ELF.....................@.|...4... .....4. ...(.............@...@...........................D...D.....<...P........dt.Q..........................................0!..8!....$....h........0%......8!0G..$..........@.C.!......*..C.!.`..$B.........%<...'......

                                          ELF header

                                          Class:ELF32
                                          Data:2's complement, big endian
                                          Version:1 (current)
                                          Machine:MIPS R3000
                                          Version Number:0x1
                                          Type:EXEC (Executable file)
                                          OS/ABI:UNIX - System V
                                          ABI Version:0
                                          Entry Point Address:0x40027c
                                          Flags:0x1007
                                          ELF Header Size:52
                                          Program Header Offset:52
                                          Program Header Size:32
                                          Number of Program Headers:3
                                          Section Header Offset:1056
                                          Section Header Size:40
                                          Number of Section Headers:7
                                          Header String Table Index:6
                                          NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                          NULL0x00x00x00x00x0000
                                          .textPROGBITS0x4000a00xa00x3000x00x6AX0016
                                          .rodataPROGBITS0x4003a00x3a00x100x10x32AMS004
                                          .gotPROGBITS0x4403b00x3b00x3c0x40x10000003WAp0016
                                          .bssNOBITS0x4403f00x3ec0x100x00x3WA0016
                                          .mdebug.abi32PROGBITS0x480x3ec0x00x00x0001
                                          .shstrtabSTRTAB0x00x3ec0x310x00x0001
                                          TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                          LOAD0x00x4000000x4000000x3b00x3b04.71220x5R E0x10000.text .rodata
                                          LOAD0x3b00x4403b00x4403b00x3c0x502.18350x6RW 0x10000.got .bss
                                          GNU_STACK0x00x00x00x00x00.00000x7RWE0x4
                                          TimestampSource PortDest PortSource IPDest IP
                                          Apr 15, 2025 17:48:20.848334074 CEST43928443192.168.2.2391.189.91.42
                                          Apr 15, 2025 17:48:21.830926895 CEST398647581192.168.2.2382.24.200.45
                                          Apr 15, 2025 17:48:21.984283924 CEST75813986482.24.200.45192.168.2.23
                                          Apr 15, 2025 17:48:21.984519958 CEST398647581192.168.2.2382.24.200.45
                                          Apr 15, 2025 17:48:21.986105919 CEST398647581192.168.2.2382.24.200.45
                                          Apr 15, 2025 17:48:22.139322042 CEST75813986482.24.200.45192.168.2.23
                                          Apr 15, 2025 17:48:22.139404058 CEST75813986482.24.200.45192.168.2.23
                                          Apr 15, 2025 17:48:22.139465094 CEST75813986482.24.200.45192.168.2.23
                                          Apr 15, 2025 17:48:22.139503002 CEST75813986482.24.200.45192.168.2.23
                                          Apr 15, 2025 17:48:22.139522076 CEST398647581192.168.2.2382.24.200.45
                                          Apr 15, 2025 17:48:22.139522076 CEST398647581192.168.2.2382.24.200.45
                                          Apr 15, 2025 17:48:22.139544010 CEST75813986482.24.200.45192.168.2.23
                                          Apr 15, 2025 17:48:22.139583111 CEST75813986482.24.200.45192.168.2.23
                                          Apr 15, 2025 17:48:22.139597893 CEST398647581192.168.2.2382.24.200.45
                                          Apr 15, 2025 17:48:22.139597893 CEST398647581192.168.2.2382.24.200.45
                                          Apr 15, 2025 17:48:22.139619112 CEST75813986482.24.200.45192.168.2.23
                                          Apr 15, 2025 17:48:22.139630079 CEST398647581192.168.2.2382.24.200.45
                                          Apr 15, 2025 17:48:22.139656067 CEST75813986482.24.200.45192.168.2.23
                                          Apr 15, 2025 17:48:22.139667034 CEST398647581192.168.2.2382.24.200.45
                                          Apr 15, 2025 17:48:22.139692068 CEST75813986482.24.200.45192.168.2.23
                                          Apr 15, 2025 17:48:22.139713049 CEST398647581192.168.2.2382.24.200.45
                                          Apr 15, 2025 17:48:22.139727116 CEST75813986482.24.200.45192.168.2.23
                                          Apr 15, 2025 17:48:22.139739990 CEST398647581192.168.2.2382.24.200.45
                                          Apr 15, 2025 17:48:22.139763117 CEST75813986482.24.200.45192.168.2.23
                                          Apr 15, 2025 17:48:22.139889002 CEST398647581192.168.2.2382.24.200.45
                                          Apr 15, 2025 17:48:22.139935017 CEST398647581192.168.2.2382.24.200.45
                                          Apr 15, 2025 17:48:22.293061972 CEST75813986482.24.200.45192.168.2.23
                                          Apr 15, 2025 17:48:22.293098927 CEST75813986482.24.200.45192.168.2.23
                                          Apr 15, 2025 17:48:22.293112993 CEST75813986482.24.200.45192.168.2.23
                                          Apr 15, 2025 17:48:22.293128967 CEST75813986482.24.200.45192.168.2.23
                                          Apr 15, 2025 17:48:22.293143988 CEST75813986482.24.200.45192.168.2.23
                                          Apr 15, 2025 17:48:22.293159008 CEST75813986482.24.200.45192.168.2.23
                                          Apr 15, 2025 17:48:22.293174982 CEST75813986482.24.200.45192.168.2.23
                                          Apr 15, 2025 17:48:22.293190002 CEST75813986482.24.200.45192.168.2.23
                                          Apr 15, 2025 17:48:22.293190002 CEST398647581192.168.2.2382.24.200.45
                                          Apr 15, 2025 17:48:22.293190002 CEST398647581192.168.2.2382.24.200.45
                                          Apr 15, 2025 17:48:22.293205976 CEST75813986482.24.200.45192.168.2.23
                                          Apr 15, 2025 17:48:22.293221951 CEST398647581192.168.2.2382.24.200.45
                                          Apr 15, 2025 17:48:22.293221951 CEST398647581192.168.2.2382.24.200.45
                                          Apr 15, 2025 17:48:22.293221951 CEST398647581192.168.2.2382.24.200.45
                                          Apr 15, 2025 17:48:22.293221951 CEST398647581192.168.2.2382.24.200.45
                                          Apr 15, 2025 17:48:22.293225050 CEST75813986482.24.200.45192.168.2.23
                                          Apr 15, 2025 17:48:22.295053005 CEST398647581192.168.2.2382.24.200.45
                                          Apr 15, 2025 17:48:22.446419001 CEST75813986482.24.200.45192.168.2.23
                                          Apr 15, 2025 17:48:22.446460009 CEST75813986482.24.200.45192.168.2.23
                                          Apr 15, 2025 17:48:22.446470022 CEST75813986482.24.200.45192.168.2.23
                                          Apr 15, 2025 17:48:22.446479082 CEST75813986482.24.200.45192.168.2.23
                                          Apr 15, 2025 17:48:22.446490049 CEST75813986482.24.200.45192.168.2.23
                                          Apr 15, 2025 17:48:22.446825981 CEST398647581192.168.2.2382.24.200.45
                                          Apr 15, 2025 17:48:22.448168039 CEST75813986482.24.200.45192.168.2.23
                                          Apr 15, 2025 17:48:22.448194981 CEST75813986482.24.200.45192.168.2.23
                                          Apr 15, 2025 17:48:22.448213100 CEST75813986482.24.200.45192.168.2.23
                                          Apr 15, 2025 17:48:22.448230028 CEST75813986482.24.200.45192.168.2.23
                                          Apr 15, 2025 17:48:22.448246002 CEST75813986482.24.200.45192.168.2.23
                                          Apr 15, 2025 17:48:22.448270082 CEST75813986482.24.200.45192.168.2.23
                                          Apr 15, 2025 17:48:22.448687077 CEST398647581192.168.2.2382.24.200.45
                                          Apr 15, 2025 17:48:22.600055933 CEST75813986482.24.200.45192.168.2.23
                                          Apr 15, 2025 17:48:22.600096941 CEST75813986482.24.200.45192.168.2.23
                                          Apr 15, 2025 17:48:22.600330114 CEST398647581192.168.2.2382.24.200.45
                                          Apr 15, 2025 17:48:22.601692915 CEST75813986482.24.200.45192.168.2.23
                                          Apr 15, 2025 17:48:22.601717949 CEST75813986482.24.200.45192.168.2.23
                                          Apr 15, 2025 17:48:22.601733923 CEST75813986482.24.200.45192.168.2.23
                                          Apr 15, 2025 17:48:22.601751089 CEST75813986482.24.200.45192.168.2.23
                                          Apr 15, 2025 17:48:22.601814985 CEST75813986482.24.200.45192.168.2.23
                                          Apr 15, 2025 17:48:22.601830006 CEST75813986482.24.200.45192.168.2.23
                                          Apr 15, 2025 17:48:22.601845980 CEST75813986482.24.200.45192.168.2.23
                                          Apr 15, 2025 17:48:22.601862907 CEST75813986482.24.200.45192.168.2.23
                                          Apr 15, 2025 17:48:22.601919889 CEST75813986482.24.200.45192.168.2.23
                                          Apr 15, 2025 17:48:22.602323055 CEST398647581192.168.2.2382.24.200.45
                                          Apr 15, 2025 17:48:22.753653049 CEST75813986482.24.200.45192.168.2.23
                                          Apr 15, 2025 17:48:22.753693104 CEST75813986482.24.200.45192.168.2.23
                                          Apr 15, 2025 17:48:22.754019022 CEST398647581192.168.2.2382.24.200.45
                                          Apr 15, 2025 17:48:22.755306959 CEST75813986482.24.200.45192.168.2.23
                                          Apr 15, 2025 17:48:22.755335093 CEST75813986482.24.200.45192.168.2.23
                                          Apr 15, 2025 17:48:22.755351067 CEST75813986482.24.200.45192.168.2.23
                                          Apr 15, 2025 17:48:22.755367041 CEST75813986482.24.200.45192.168.2.23
                                          Apr 15, 2025 17:48:22.755383968 CEST75813986482.24.200.45192.168.2.23
                                          Apr 15, 2025 17:48:22.755399942 CEST75813986482.24.200.45192.168.2.23
                                          Apr 15, 2025 17:48:22.755417109 CEST75813986482.24.200.45192.168.2.23
                                          Apr 15, 2025 17:48:22.755433083 CEST75813986482.24.200.45192.168.2.23
                                          Apr 15, 2025 17:48:22.755567074 CEST75813986482.24.200.45192.168.2.23
                                          Apr 15, 2025 17:48:22.755584955 CEST75813986482.24.200.45192.168.2.23
                                          Apr 15, 2025 17:48:22.756180048 CEST398647581192.168.2.2382.24.200.45
                                          Apr 15, 2025 17:48:22.907291889 CEST75813986482.24.200.45192.168.2.23
                                          Apr 15, 2025 17:48:22.907330990 CEST75813986482.24.200.45192.168.2.23
                                          Apr 15, 2025 17:48:22.907474041 CEST398647581192.168.2.2382.24.200.45
                                          Apr 15, 2025 17:48:22.909265995 CEST75813986482.24.200.45192.168.2.23
                                          Apr 15, 2025 17:48:22.909332991 CEST75813986482.24.200.45192.168.2.23
                                          Apr 15, 2025 17:48:22.909349918 CEST75813986482.24.200.45192.168.2.23
                                          Apr 15, 2025 17:48:22.909365892 CEST75813986482.24.200.45192.168.2.23
                                          Apr 15, 2025 17:48:22.909399033 CEST75813986482.24.200.45192.168.2.23
                                          Apr 15, 2025 17:48:22.909415007 CEST75813986482.24.200.45192.168.2.23
                                          Apr 15, 2025 17:48:22.909430981 CEST75813986482.24.200.45192.168.2.23
                                          Apr 15, 2025 17:48:22.909446001 CEST75813986482.24.200.45192.168.2.23
                                          Apr 15, 2025 17:48:22.909543991 CEST75813986482.24.200.45192.168.2.23
                                          Apr 15, 2025 17:48:22.909564018 CEST75813986482.24.200.45192.168.2.23
                                          Apr 15, 2025 17:48:22.911026955 CEST398647581192.168.2.2382.24.200.45
                                          Apr 15, 2025 17:48:23.279140949 CEST398647581192.168.2.2382.24.200.45
                                          Apr 15, 2025 17:48:23.432260990 CEST75813986482.24.200.45192.168.2.23
                                          Apr 15, 2025 17:48:26.479490042 CEST42836443192.168.2.2391.189.91.43
                                          Apr 15, 2025 17:48:27.503540993 CEST4251680192.168.2.23109.202.202.202
                                          Apr 15, 2025 17:48:41.837348938 CEST43928443192.168.2.2391.189.91.42
                                          Apr 15, 2025 17:48:52.075941086 CEST42836443192.168.2.2391.189.91.43
                                          Apr 15, 2025 17:48:58.219018936 CEST4251680192.168.2.23109.202.202.202
                                          Apr 15, 2025 17:49:22.791726112 CEST43928443192.168.2.2391.189.91.42
                                          Apr 15, 2025 17:49:43.268836021 CEST42836443192.168.2.2391.189.91.43

                                          System Behavior

                                          Start time (UTC):15:48:21
                                          Start date (UTC):15/04/2025
                                          Path:/tmp/gY2rWwaH7T.elf
                                          Arguments:/tmp/gY2rWwaH7T.elf
                                          File size:5777432 bytes
                                          MD5 hash:0083f1f0e77be34ad27f849842bbb00c