Linux
Analysis Report
morte.arm5.elf
Overview
General Information
Sample name: | morte.arm5.elf |
Analysis ID: | 1729403 |
Has dependencies: | false |
MD5: | 3f16712361cc7de3a700a9a81d2b7952 |
SHA1: | 04fb98d6e4d2d15ff889b43c48ce9267ed40ab3b |
SHA256: | 5f4bab35d194d49ac496bc02c68f6e464ec3c7914330eb4c5c751502fcdf8bf9 |
Tags: | elfMiraiupx-decuser-abuse_ch |
Infos: |
Detection
Xmrig
Score: | 68 |
Range: | 0 - 100 |
Signatures
Antivirus / Scanner detection for submitted sample
Multi AV Scanner detection for submitted file
Yara detected Xmrig cryptocurrency miner
Found strings related to Crypto-Mining
Found strings indicative of a multi-platform dropper
HTTP GET or POST without a user agent
Sample contains strings indicative of BusyBox which embeds multiple Unix commands in a single executable
Sample has stripped symbol table
Uses the "uname" system call to query kernel version information (possible evasion)
Classification
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1729403 |
Start date and time: | 2025-07-06 07:58:38 +02:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 10m 43s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultlinuxfilecookbook.jbs |
Analysis system description: | Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11) |
Analysis Mode: | default |
Sample name: | morte.arm5.elf |
Detection: | MAL |
Classification: | mal68.mine.linELF@0/0@4/0 |
Cookbook Comments: |
|
- Max analysis timeout: 600s exceeded, the analysis took too long
- Some HTTPS proxied raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
Command: | /tmp/morte.arm5.elf |
PID: | 5495 |
Exit Code: | 255 |
Exit Code Info: | |
Killed: | False |
Standard Output: | |
Standard Error: | /lib/ld-uClibc.so.0: No such file or directory |
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
XMRIG | No Attribution |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_Xmrig | Yara detected Xmrig cryptocurrency miner | Joe Security |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_Xmrig | Yara detected Xmrig cryptocurrency miner | Joe Security | ||
JoeSecurity_Xmrig | Yara detected Xmrig cryptocurrency miner | Joe Security |
⊘No Suricata rule has matched
Click to jump to signature section
Show All Signature Results
AV Detection |
---|
Source: | Avira: |
Source: | ReversingLabs: | |||
Source: | Virustotal: | Perma Link |
Bitcoin Miner |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | String found in binary or memory: |
Source: | String: | ||
Source: | String: |
Source: | HTTP traffic detected: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: |
Source: | DNS traffic detected: |
Source: | HTTP traffic detected: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | String containing 'busybox' found: | ||
Source: | String containing 'busybox' found: | ||
Source: | String containing 'busybox' found: |
Source: | .symtab present: |
Source: | Classification label: |
Source: | Queries kernel information via 'uname': | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | 1 Scripting | Valid Accounts | Windows Management Instrumentation | 1 Scripting | Path Interception | Direct Volume Access | OS Credential Dumping | 11 Security Software Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | Rootkit | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 2 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 3 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
⊘No configs have been found
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
53% | ReversingLabs | Linux.Worm.Mirai | ||
38% | Virustotal | Browse | ||
100% | Avira | LINUX/Mirai.bonb |
⊘No Antivirus matches
⊘No Antivirus matches
⊘No Antivirus matches
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
daisy.ubuntu.com | 162.213.35.24 | true | false | high |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
162.213.35.24 | daisy.ubuntu.com | United States | 41231 | CANONICAL-ASGB | false | |
169.254.169.254 | unknown | Reserved | 6966 | USDOSUS | false |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
162.213.35.24 | Get hash | malicious | Mirai, Xmrig | Browse | ||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Mirai, Xmrig | Browse | |||
Get hash | malicious | Mirai, Xmrig | Browse | |||
Get hash | malicious | Mirai, Xmrig | Browse | |||
Get hash | malicious | Xmrig | Browse | |||
Get hash | malicious | Mirai, Xmrig | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Xmrig | Browse | |||
Get hash | malicious | Xmrig | Browse | |||
169.254.169.254 | Get hash | malicious | Mirai, Xmrig | Browse | ||
Get hash | malicious | Mirai, Xmrig | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Mirai, Xmrig | Browse | |||
Get hash | malicious | Mirai, Xmrig | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Mirai, Xmrig | Browse | |||
Get hash | malicious | Mirai, Xmrig | Browse | |||
Get hash | malicious | Mirai, Xmrig | Browse | |||
Get hash | malicious | Mirai, Xmrig | Browse |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
daisy.ubuntu.com | Get hash | malicious | Mirai, Xmrig | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai, Xmrig | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai, Xmrig | Browse |
| ||
Get hash | malicious | Mirai, Xmrig | Browse |
| ||
Get hash | malicious | Mirai, Xmrig | Browse |
| ||
Get hash | malicious | Mirai, Xmrig | Browse |
| ||
Get hash | malicious | Mirai, Xmrig | Browse |
| ||
Get hash | malicious | Xmrig | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
USDOSUS | Get hash | malicious | Mirai, Xmrig | Browse |
| |
Get hash | malicious | Mirai, Xmrig | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai, Xmrig | Browse |
| ||
Get hash | malicious | Mirai, Xmrig | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai, Xmrig | Browse |
| ||
Get hash | malicious | Mirai, Xmrig | Browse |
| ||
Get hash | malicious | Mirai, Xmrig | Browse |
| ||
Get hash | malicious | Mirai, Xmrig | Browse |
| ||
CANONICAL-ASGB | Get hash | malicious | Mirai, Xmrig | Browse |
| |
Get hash | malicious | Mirai, Xmrig | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai, Xmrig | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai, Xmrig | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai, Xmrig | Browse |
| ||
Get hash | malicious | Mirai, Xmrig | Browse |
| ||
Get hash | malicious | Mirai, Xmrig | Browse |
|
⊘No context
⊘No context
⊘No created / dropped files found
File type: | |
Entropy (8bit): | 5.806229587585947 |
TrID: |
|
File name: | morte.arm5.elf |
File size: | 59'268 bytes |
MD5: | 3f16712361cc7de3a700a9a81d2b7952 |
SHA1: | 04fb98d6e4d2d15ff889b43c48ce9267ed40ab3b |
SHA256: | 5f4bab35d194d49ac496bc02c68f6e464ec3c7914330eb4c5c751502fcdf8bf9 |
SHA512: | e78e7d90422770263c37351f6a6b65b150ca229f2497684fc293bf715a132729e1921308a065fe4a633822d8c1fdf27b8fb3bf831543dd4ed16a1aef2a98d42a |
SSDEEP: | 768:xm0C9iGercqJUPx+iXq+cco4wH5jGlUnZBDUTNWzlioVIFDFMhBNwFdgn+mz:4cpYx+IXSjGlUnPUTNclgFpd |
TLSH: | CB43F886F89286AEC6D017BAA72E158E33927795D2DF3717CC484B1233C960F4D67E41 |
File Content Preview: | .ELF...a..........(.........4...........4. ...(.........4...4...4................................................................... ... ...............................<...........................................Q.td............................/lib/ld-uCl |
ELF header | |
---|---|
Class: | |
Data: | |
Version: | |
Machine: | |
Version Number: | |
Type: | |
OS/ABI: | |
ABI Version: | 0 |
Entry Point Address: | |
Flags: | |
ELF Header Size: | 52 |
Program Header Offset: | 52 |
Program Header Size: | 32 |
Number of Program Headers: | 6 |
Section Header Offset: | 58508 |
Section Header Size: | 40 |
Number of Section Headers: | 19 |
Header String Table Index: | 18 |
Name | Type | Address | Offset | Size | EntSize | Flags | Flags Description | Link | Info | Align |
---|---|---|---|---|---|---|---|---|---|---|
NULL | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0 | 0 | 0 | ||
.interp | PROGBITS | 0x80f4 | 0xf4 | 0x14 | 0x0 | 0x2 | A | 0 | 0 | 1 |
.hash | HASH | 0x8108 | 0x108 | 0x334 | 0x4 | 0x2 | A | 3 | 0 | 4 |
.dynsym | DYNSYM | 0x843c | 0x43c | 0x6a0 | 0x10 | 0x2 | A | 4 | 1 | 4 |
.dynstr | STRTAB | 0x8adc | 0xadc | 0x342 | 0x0 | 0x2 | A | 0 | 0 | 1 |
.rel.dyn | REL | 0x8e20 | 0xe20 | 0x10 | 0x8 | 0x2 | A | 3 | 0 | 4 |
.rel.plt | REL | 0x8e30 | 0xe30 | 0x2a0 | 0x8 | 0x2 | A | 3 | 8 | 4 |
.init | PROGBITS | 0x90d0 | 0x10d0 | 0x18 | 0x0 | 0x6 | AX | 0 | 0 | 4 |
.plt | PROGBITS | 0x90e8 | 0x10e8 | 0x404 | 0x4 | 0x6 | AX | 0 | 0 | 4 |
.text | PROGBITS | 0x94ec | 0x14ec | 0xa8f4 | 0x0 | 0x6 | AX | 0 | 0 | 4 |
.fini | PROGBITS | 0x13de0 | 0xbde0 | 0x14 | 0x0 | 0x6 | AX | 0 | 0 | 4 |
.rodata | PROGBITS | 0x13df4 | 0xbdf4 | 0x1f2c | 0x0 | 0x2 | A | 0 | 0 | 4 |
.ctors | PROGBITS | 0x1e000 | 0xe000 | 0x8 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.dtors | PROGBITS | 0x1e008 | 0xe008 | 0x8 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.dynamic | DYNAMIC | 0x1e014 | 0xe014 | 0xb0 | 0x8 | 0x3 | WA | 4 | 0 | 4 |
.got | PROGBITS | 0x1e0c4 | 0xe0c4 | 0x15c | 0x4 | 0x3 | WA | 0 | 0 | 4 |
.data | PROGBITS | 0x1e220 | 0xe220 | 0x1f0 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.bss | NOBITS | 0x1e410 | 0xe410 | 0x822c | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.shstrtab | STRTAB | 0x0 | 0xe410 | 0x7c | 0x0 | 0x0 | 0 | 0 | 1 |
Type | Offset | Virtual Address | Physical Address | File Size | Memory Size | Entropy | Flags | Flags Description | Align | Prog Interpreter | Section Mappings |
---|---|---|---|---|---|---|---|---|---|---|---|
PHDR | 0x34 | 0x8034 | 0x8034 | 0xc0 | 0xc0 | 2.1865 | 0x5 | R E | 0x4 | ||
INTERP | 0xf4 | 0x80f4 | 0x80f4 | 0x14 | 0x14 | 3.6842 | 0x4 | R | 0x1 | /lib/ld-uClibc.so.0 | .interp |
LOAD | 0x0 | 0x8000 | 0x8000 | 0xdd20 | 0xdd20 | 5.8959 | 0x5 | R E | 0x8000 | .interp .hash .dynsym .dynstr .rel.dyn .rel.plt .init .plt .text .fini .rodata | |
LOAD | 0xe000 | 0x1e000 | 0x1e000 | 0x410 | 0x863c | 3.2077 | 0x6 | RW | 0x8000 | .ctors .dtors .dynamic .got .data .bss | |
DYNAMIC | 0xe014 | 0x1e014 | 0x1e014 | 0xb0 | 0xb0 | 2.0029 | 0x6 | RW | 0x4 | .dynamic | |
GNU_STACK | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0.0000 | 0x7 | RWE | 0x4 |
Type | Meta | Value | Tag |
---|---|---|---|
DT_NEEDED | sharedlib | libc.so.0 | 0x1 |
DT_INIT | value | 0x90d0 | 0xc |
DT_FINI | value | 0x13de0 | 0xd |
DT_HASH | value | 0x8108 | 0x4 |
DT_STRTAB | value | 0x8adc | 0x5 |
DT_SYMTAB | value | 0x843c | 0x6 |
DT_STRSZ | bytes | 834 | 0xa |
DT_SYMENT | bytes | 16 | 0xb |
DT_DEBUG | value | 0x0 | 0x15 |
DT_PLTGOT | value | 0x1e0c4 | 0x3 |
DT_PLTRELSZ | bytes | 672 | 0x2 |
DT_PLTREL | pltrel | DT_REL | 0x14 |
DT_JMPREL | value | 0x8e30 | 0x17 |
DT_REL | value | 0x8e20 | 0x11 |
DT_RELSZ | bytes | 16 | 0x12 |
DT_RELENT | bytes | 8 | 0x13 |
DT_NULL | value | 0x0 | 0x0 |
Name | Version Info Name | Version Info File Name | Section Name | Value | Size | Symbol Type | Symbol Bind | Symbol Visibility | Ndx |
---|---|---|---|---|---|---|---|---|---|
.dynsym | 0x0 | 0 | NOTYPE | <unknown> | DEFAULT | SHN_UNDEF | |||
__aeabi_idiv0 | .dynsym | 0x13da0 | 4 | FUNC | <unknown> | DEFAULT | 9 | ||
__aeabi_ldiv0 | .dynsym | 0x13da0 | 4 | FUNC | <unknown> | DEFAULT | 9 | ||
__aeabi_uidiv | .dynsym | 0x13ae0 | 0 | FUNC | <unknown> | DEFAULT | 9 | ||
__aeabi_uidivmod | .dynsym | 0x13bd8 | 24 | FUNC | <unknown> | DEFAULT | 9 | ||
__bss_end__ | .dynsym | 0x2663c | 0 | NOTYPE | <unknown> | DEFAULT | SHN_ABS | ||
__bss_start | .dynsym | 0x1e410 | 0 | NOTYPE | <unknown> | DEFAULT | SHN_ABS | ||
__bss_start__ | .dynsym | 0x1e410 | 0 | NOTYPE | <unknown> | DEFAULT | SHN_ABS | ||
__ctype_b | .dynsym | 0x1e410 | 4 | OBJECT | <unknown> | DEFAULT | 19 | ||
__data_start | .dynsym | 0x1e220 | 0 | NOTYPE | <unknown> | DEFAULT | 18 | ||
__div0 | .dynsym | 0x13da0 | 4 | FUNC | <unknown> | DEFAULT | 9 | ||
__end__ | .dynsym | 0x2663c | 0 | NOTYPE | <unknown> | DEFAULT | SHN_ABS | ||
__environ | .dynsym | 0x1e414 | 4 | OBJECT | <unknown> | DEFAULT | 19 | ||
__errno_location | .dynsym | 0x9444 | 32 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
__modsi3 | .dynsym | 0x13cbc | 228 | FUNC | <unknown> | DEFAULT | 9 | ||
__uClibc_main | .dynsym | 0x939c | 488 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
__udivsi3 | .dynsym | 0x13ae0 | 248 | FUNC | <unknown> | DEFAULT | 9 | ||
__umodsi3 | .dynsym | 0x13bf0 | 204 | FUNC | <unknown> | DEFAULT | 9 | ||
_bss_end__ | .dynsym | 0x2663c | 0 | NOTYPE | <unknown> | DEFAULT | SHN_ABS | ||
_edata | .dynsym | 0x1e410 | 0 | NOTYPE | <unknown> | DEFAULT | SHN_ABS | ||
_end | .dynsym | 0x2663c | 0 | NOTYPE | <unknown> | DEFAULT | SHN_ABS | ||
_start | .dynsym | 0x95cc | 80 | FUNC | <unknown> | DEFAULT | 9 | ||
abort | .dynsym | 0x9258 | 352 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
accept | .dynsym | 0x9270 | 44 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
access | .dynsym | 0x9438 | 44 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
atoi | .dynsym | 0x945c | 12 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
bind | .dynsym | 0x92a0 | 44 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
calloc | .dynsym | 0x927c | 88 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
chdir | .dynsym | 0x92b8 | 44 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
chmod | .dynsym | 0x9264 | 52 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
clock | .dynsym | 0x9480 | 52 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
close | .dynsym | 0x94bc | 44 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
closedir | .dynsym | 0x94a4 | 196 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
connect | .dynsym | 0x912c | 44 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
dup2 | .dynsym | 0x91b0 | 44 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
environ | .dynsym | 0x1e414 | 4 | OBJECT | <unknown> | DEFAULT | 19 | ||
execl | .dynsym | 0x9198 | 164 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
execv | .dynsym | 0x9384 | 40 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
exit | .dynsym | 0x9450 | 172 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
fclose | .dynsym | 0x93cc | 448 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
fcntl | .dynsym | 0x94b0 | 116 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
fgets | .dynsym | 0x9174 | 164 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
fopen | .dynsym | 0x93b4 | 12 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
fork | .dynsym | 0x936c | 44 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
fread | .dynsym | 0x9390 | 172 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
free | .dynsym | 0x94c8 | 288 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
fseek | .dynsym | 0x92d0 | 12 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
fwrite | .dynsym | 0x942c | 172 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
getpid | .dynsym | 0x9168 | 44 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
getppid | .dynsym | 0x93d8 | 44 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
getsockname | .dynsym | 0x94e0 | 44 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
getsockopt | .dynsym | 0x9420 | 48 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
inet_addr | .dynsym | 0x92ac | 36 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
inotify_add_watch | .dynsym | 0x9414 | 44 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
inotify_init | .dynsym | 0x9234 | 44 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
inotify_rm_watch | .dynsym | 0x0 | 44 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
ioctl | .dynsym | 0x9114 | 80 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
kill | .dynsym | 0x9288 | 44 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
listen | .dynsym | 0x9360 | 44 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
malloc | .dynsym | 0x91c8 | 400 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
memcpy | .dynsym | 0x918c | 4 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
memmove | .dynsym | 0x9144 | 4 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
memset | .dynsym | 0x93c0 | 156 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
open | .dynsym | 0x9474 | 92 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
opendir | .dynsym | 0x93f0 | 264 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
prctl | .dynsym | 0x9180 | 48 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
rand | .dynsym | 0x930c | 4 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
read | .dynsym | 0x9324 | 44 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
readdir | .dynsym | 0x9228 | 224 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
readlink | .dynsym | 0x91a4 | 44 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
realloc | .dynsym | 0x9354 | 312 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
recv | .dynsym | 0x9120 | 44 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
recvfrom | .dynsym | 0x91f8 | 52 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
remove | .dynsym | 0x91d4 | 72 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
sched_setscheduler | .dynsym | 0x91ec | 44 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
select | .dynsym | 0x921c | 48 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
send | .dynsym | 0x924c | 44 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
sendto | .dynsym | 0x9348 | 52 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
setsid | .dynsym | 0x9498 | 44 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
setsockopt | .dynsym | 0x92c4 | 48 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
sigaddset | .dynsym | 0x9240 | 48 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
sigemptyset | .dynsym | 0x9138 | 24 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
signal | .dynsym | 0x9318 | 200 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
sigprocmask | .dynsym | 0x94d4 | 84 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
sleep | .dynsym | 0x91e0 | 420 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
snprintf | .dynsym | 0x9150 | 48 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
socket | .dynsym | 0x9210 | 44 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
sscanf | .dynsym | 0x9378 | 48 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
strcasestr | .dynsym | 0x92f4 | 168 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
strcat | .dynsym | 0x9294 | 40 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
strchr | .dynsym | 0x948c | 264 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
strcmp | .dynsym | 0x93fc | 28 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
strcpy | .dynsym | 0x90fc | 28 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
strcspn | .dynsym | 0x9408 | 64 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
strlen | .dynsym | 0x9468 | 96 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
strncpy | .dynsym | 0x9330 | 184 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
strstr | .dynsym | 0x9300 | 248 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
strtoul | .dynsym | 0x9204 | 8 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
symlink | .dynsym | 0x93a8 | 44 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
system | .dynsym | 0x91bc | 336 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
time | .dynsym | 0x93e4 | 44 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
umask | .dynsym | 0x92e8 | 56 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
unlink | .dynsym | 0x933c | 44 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
usleep | .dynsym | 0x915c | 76 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
wait | .dynsym | 0x92dc | 20 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
waitpid | .dynsym | 0x9108 | 8 | FUNC | <unknown> | DEFAULT | SHN_UNDEF |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jul 6, 2025 08:02:31.226268053 CEST | 34816 | 53 | 192.168.2.13 | 8.8.8.8 |
Jul 6, 2025 08:02:31.312103033 CEST | 53 | 34816 | 8.8.8.8 | 192.168.2.13 |
Jul 6, 2025 08:02:31.312227011 CEST | 34816 | 53 | 192.168.2.13 | 8.8.8.8 |
Jul 6, 2025 08:02:31.312227011 CEST | 34816 | 53 | 192.168.2.13 | 8.8.8.8 |
Jul 6, 2025 08:02:31.313386917 CEST | 34816 | 53 | 192.168.2.13 | 8.8.8.8 |
Jul 6, 2025 08:02:31.398030996 CEST | 53 | 34816 | 8.8.8.8 | 192.168.2.13 |
Jul 6, 2025 08:02:31.398216963 CEST | 53 | 34816 | 8.8.8.8 | 192.168.2.13 |
Jul 6, 2025 08:02:31.398395061 CEST | 34816 | 53 | 192.168.2.13 | 8.8.8.8 |
Jul 6, 2025 08:02:31.399139881 CEST | 53 | 34816 | 8.8.8.8 | 192.168.2.13 |
Jul 6, 2025 08:02:31.399172068 CEST | 34816 | 53 | 192.168.2.13 | 8.8.8.8 |
Jul 6, 2025 08:02:33.399208069 CEST | 53 | 34816 | 8.8.8.8 | 192.168.2.13 |
Jul 6, 2025 08:02:33.399359941 CEST | 34816 | 53 | 192.168.2.13 | 8.8.8.8 |
Jul 6, 2025 08:02:33.485173941 CEST | 53 | 34816 | 8.8.8.8 | 192.168.2.13 |
Jul 6, 2025 08:03:10.689059973 CEST | 49268 | 80 | 192.168.2.13 | 169.254.169.254 |
Jul 6, 2025 08:03:11.702164888 CEST | 49268 | 80 | 192.168.2.13 | 169.254.169.254 |
Jul 6, 2025 08:03:13.718267918 CEST | 49268 | 80 | 192.168.2.13 | 169.254.169.254 |
Jul 6, 2025 08:03:31.619185925 CEST | 34820 | 53 | 192.168.2.13 | 8.8.8.8 |
Jul 6, 2025 08:03:31.704751015 CEST | 53 | 34820 | 8.8.8.8 | 192.168.2.13 |
Jul 6, 2025 08:03:31.704932928 CEST | 34820 | 53 | 192.168.2.13 | 8.8.8.8 |
Jul 6, 2025 08:03:31.704932928 CEST | 34820 | 53 | 192.168.2.13 | 8.8.8.8 |
Jul 6, 2025 08:03:31.705065012 CEST | 34820 | 53 | 192.168.2.13 | 8.8.8.8 |
Jul 6, 2025 08:03:31.790683031 CEST | 53 | 34820 | 8.8.8.8 | 192.168.2.13 |
Jul 6, 2025 08:03:31.790699959 CEST | 53 | 34820 | 8.8.8.8 | 192.168.2.13 |
Jul 6, 2025 08:03:31.790712118 CEST | 53 | 34820 | 8.8.8.8 | 192.168.2.13 |
Jul 6, 2025 08:03:31.790983915 CEST | 34820 | 53 | 192.168.2.13 | 8.8.8.8 |
Jul 6, 2025 08:03:31.796967983 CEST | 53 | 34820 | 8.8.8.8 | 192.168.2.13 |
Jul 6, 2025 08:03:31.797319889 CEST | 34820 | 53 | 192.168.2.13 | 8.8.8.8 |
Jul 6, 2025 08:03:31.802675009 CEST | 38442 | 443 | 192.168.2.13 | 162.213.35.24 |
Jul 6, 2025 08:03:31.802716017 CEST | 443 | 38442 | 162.213.35.24 | 192.168.2.13 |
Jul 6, 2025 08:03:31.802761078 CEST | 38442 | 443 | 192.168.2.13 | 162.213.35.24 |
Jul 6, 2025 08:03:32.563297987 CEST | 38442 | 443 | 192.168.2.13 | 162.213.35.24 |
Jul 6, 2025 08:03:32.563322067 CEST | 443 | 38442 | 162.213.35.24 | 192.168.2.13 |
Jul 6, 2025 08:03:32.683415890 CEST | 443 | 38442 | 162.213.35.24 | 192.168.2.13 |
Jul 6, 2025 08:03:32.683517933 CEST | 38442 | 443 | 192.168.2.13 | 162.213.35.24 |
Jul 6, 2025 08:03:32.683743954 CEST | 38442 | 443 | 192.168.2.13 | 162.213.35.24 |
Jul 6, 2025 08:03:32.683753014 CEST | 443 | 38442 | 162.213.35.24 | 192.168.2.13 |
Jul 6, 2025 08:03:32.684698105 CEST | 38442 | 443 | 192.168.2.13 | 162.213.35.24 |
Jul 6, 2025 08:03:32.684708118 CEST | 443 | 38442 | 162.213.35.24 | 192.168.2.13 |
Jul 6, 2025 08:03:32.685074091 CEST | 443 | 38442 | 162.213.35.24 | 192.168.2.13 |
Jul 6, 2025 08:03:32.685110092 CEST | 38442 | 443 | 192.168.2.13 | 162.213.35.24 |
Jul 6, 2025 08:03:32.685127974 CEST | 38442 | 443 | 192.168.2.13 | 162.213.35.24 |
Jul 6, 2025 08:03:32.686929941 CEST | 443 | 38442 | 162.213.35.24 | 192.168.2.13 |
Jul 6, 2025 08:03:32.686986923 CEST | 38442 | 443 | 192.168.2.13 | 162.213.35.24 |
Jul 6, 2025 08:03:32.687041044 CEST | 38442 | 443 | 192.168.2.13 | 162.213.35.24 |
Jul 6, 2025 08:03:32.687041044 CEST | 38442 | 443 | 192.168.2.13 | 162.213.35.24 |
Jul 6, 2025 08:03:32.687436104 CEST | 443 | 38442 | 162.213.35.24 | 192.168.2.13 |
Jul 6, 2025 08:03:32.687510967 CEST | 38442 | 443 | 192.168.2.13 | 162.213.35.24 |
Jul 6, 2025 08:03:32.687526941 CEST | 38442 | 443 | 192.168.2.13 | 162.213.35.24 |
Jul 6, 2025 08:03:32.687536001 CEST | 443 | 38442 | 162.213.35.24 | 192.168.2.13 |
Jul 6, 2025 08:03:32.687545061 CEST | 443 | 38442 | 162.213.35.24 | 192.168.2.13 |
Jul 6, 2025 08:03:32.687597036 CEST | 38442 | 443 | 192.168.2.13 | 162.213.35.24 |
Jul 6, 2025 08:03:32.687597036 CEST | 38442 | 443 | 192.168.2.13 | 162.213.35.24 |
Jul 6, 2025 08:03:32.687609911 CEST | 443 | 38442 | 162.213.35.24 | 192.168.2.13 |
Jul 6, 2025 08:03:32.687617064 CEST | 443 | 38442 | 162.213.35.24 | 192.168.2.13 |
Jul 6, 2025 08:03:32.687628984 CEST | 38442 | 443 | 192.168.2.13 | 162.213.35.24 |
Jul 6, 2025 08:03:32.687628984 CEST | 38442 | 443 | 192.168.2.13 | 162.213.35.24 |
Jul 6, 2025 08:03:32.687628984 CEST | 38442 | 443 | 192.168.2.13 | 162.213.35.24 |
Jul 6, 2025 08:03:32.687638044 CEST | 443 | 38442 | 162.213.35.24 | 192.168.2.13 |
Jul 6, 2025 08:03:32.687644958 CEST | 443 | 38442 | 162.213.35.24 | 192.168.2.13 |
Jul 6, 2025 08:03:32.687649965 CEST | 443 | 38442 | 162.213.35.24 | 192.168.2.13 |
Jul 6, 2025 08:03:32.687663078 CEST | 38442 | 443 | 192.168.2.13 | 162.213.35.24 |
Jul 6, 2025 08:03:32.687668085 CEST | 443 | 38442 | 162.213.35.24 | 192.168.2.13 |
Jul 6, 2025 08:03:32.687683105 CEST | 38442 | 443 | 192.168.2.13 | 162.213.35.24 |
Jul 6, 2025 08:03:32.687683105 CEST | 38442 | 443 | 192.168.2.13 | 162.213.35.24 |
Jul 6, 2025 08:03:32.687696934 CEST | 443 | 38442 | 162.213.35.24 | 192.168.2.13 |
Jul 6, 2025 08:03:32.687712908 CEST | 38442 | 443 | 192.168.2.13 | 162.213.35.24 |
Jul 6, 2025 08:03:32.688344002 CEST | 443 | 38442 | 162.213.35.24 | 192.168.2.13 |
Jul 6, 2025 08:03:33.595182896 CEST | 443 | 38442 | 162.213.35.24 | 192.168.2.13 |
Jul 6, 2025 08:03:33.595248938 CEST | 443 | 38442 | 162.213.35.24 | 192.168.2.13 |
Jul 6, 2025 08:03:33.595309973 CEST | 443 | 38442 | 162.213.35.24 | 192.168.2.13 |
Jul 6, 2025 08:03:33.595320940 CEST | 38442 | 443 | 192.168.2.13 | 162.213.35.24 |
Jul 6, 2025 08:03:33.595320940 CEST | 38442 | 443 | 192.168.2.13 | 162.213.35.24 |
Jul 6, 2025 08:03:33.595355034 CEST | 38442 | 443 | 192.168.2.13 | 162.213.35.24 |
Jul 6, 2025 08:03:33.603133917 CEST | 38442 | 443 | 192.168.2.13 | 162.213.35.24 |
Jul 6, 2025 08:03:33.603463888 CEST | 443 | 38442 | 162.213.35.24 | 192.168.2.13 |
Jul 6, 2025 08:03:33.604315042 CEST | 38442 | 443 | 192.168.2.13 | 162.213.35.24 |
Jul 6, 2025 08:03:33.604332924 CEST | 443 | 38442 | 162.213.35.24 | 192.168.2.13 |
Jul 6, 2025 08:03:33.792623043 CEST | 53 | 34820 | 8.8.8.8 | 192.168.2.13 |
Jul 6, 2025 08:03:33.792747021 CEST | 34820 | 53 | 192.168.2.13 | 8.8.8.8 |
Jul 6, 2025 08:03:33.878887892 CEST | 53 | 34820 | 8.8.8.8 | 192.168.2.13 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Jul 6, 2025 08:02:31.312227011 CEST | 192.168.2.13 | 8.8.8.8 | 0xcae0 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jul 6, 2025 08:02:31.313386917 CEST | 192.168.2.13 | 8.8.8.8 | 0x793e | Standard query (0) | 28 | IN (0x0001) | false | |
Jul 6, 2025 08:03:31.704932928 CEST | 192.168.2.13 | 8.8.8.8 | 0xa744 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jul 6, 2025 08:03:31.705065012 CEST | 192.168.2.13 | 8.8.8.8 | 0x96fc | Standard query (0) | 28 | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Jul 6, 2025 08:02:31.398216963 CEST | 8.8.8.8 | 192.168.2.13 | 0xcae0 | No error (0) | 162.213.35.24 | A (IP address) | IN (0x0001) | false | ||
Jul 6, 2025 08:02:31.398216963 CEST | 8.8.8.8 | 192.168.2.13 | 0xcae0 | No error (0) | 162.213.35.25 | A (IP address) | IN (0x0001) | false | ||
Jul 6, 2025 08:03:31.796967983 CEST | 8.8.8.8 | 192.168.2.13 | 0xa744 | No error (0) | 162.213.35.24 | A (IP address) | IN (0x0001) | false | ||
Jul 6, 2025 08:03:31.796967983 CEST | 8.8.8.8 | 192.168.2.13 | 0xa744 | No error (0) | 162.213.35.25 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port |
---|---|---|---|---|
0 | 192.168.2.13 | 38442 | 162.213.35.24 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-07-06 06:03:32 UTC | 307 | OUT | |
2025-07-06 06:03:32 UTC | 1460 | OUT | |
2025-07-06 06:03:32 UTC | 1460 | OUT | |
2025-07-06 06:03:32 UTC | 1460 | OUT | |
2025-07-06 06:03:32 UTC | 1460 | OUT | |
2025-07-06 06:03:32 UTC | 1460 | OUT | |
2025-07-06 06:03:32 UTC | 1460 | OUT | |
2025-07-06 06:03:32 UTC | 1460 | OUT | |
2025-07-06 06:03:32 UTC | 1460 | OUT | |
2025-07-06 06:03:32 UTC | 1460 | OUT | |
2025-07-06 06:03:32 UTC | 1460 | OUT | |
2025-07-06 06:03:33 UTC | 286 | IN |
System Behavior
Start time (UTC): | 05:59:43 |
Start date (UTC): | 06/07/2025 |
Path: | /tmp/morte.arm5.elf |
Arguments: | /tmp/morte.arm5.elf |
File size: | 4956856 bytes |
MD5 hash: | 5ebfcae4fe2471fcc5695c2394773ff1 |
Start time (UTC): | 06:02:29 |
Start date (UTC): | 06/07/2025 |
Path: | /usr/bin/python3.8 |
Arguments: | - |
File size: | 5490352 bytes |
MD5 hash: | 69f442c3e33b5f9a66b722c29ad89435 |
Start time (UTC): | 06:02:29 |
Start date (UTC): | 06/07/2025 |
Path: | /bin/dpkg |
Arguments: | dpkg --print-architecture |
File size: | 309944 bytes |
MD5 hash: | 5e18156b434fc45062eec2f28b9147be |