Linux
Analysis Report
morte.arm5.elf
Overview
General Information
Detection
Xmrig
Score: | 68 |
Range: | 0 - 100 |
Signatures
Antivirus / Scanner detection for submitted sample
Multi AV Scanner detection for submitted file
Yara detected Xmrig cryptocurrency miner
Found strings related to Crypto-Mining
Found strings indicative of a multi-platform dropper
HTTP GET or POST without a user agent
Sample contains strings indicative of BusyBox which embeds multiple Unix commands in a single executable
Sample has stripped symbol table
Uses the "uname" system call to query kernel version information (possible evasion)
Classification
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1729421 |
Start date and time: | 2025-07-06 08:15:20 +02:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 10m 40s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultlinuxfilecookbook.jbs |
Analysis system description: | Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11) |
Analysis Mode: | default |
Sample name: | morte.arm5.elf |
Detection: | MAL |
Classification: | mal68.mine.linELF@0/0@4/0 |
Cookbook Comments: |
|
- Max analysis timeout: 600s exceeded, the analysis took too long
- Some HTTPS proxied raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
Command: | /tmp/morte.arm5.elf |
PID: | 5807 |
Exit Code: | 255 |
Exit Code Info: | |
Killed: | False |
Standard Output: | |
Standard Error: | /lib/ld-uClibc.so.0: No such file or directory |
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
XMRIG | No Attribution |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_Xmrig | Yara detected Xmrig cryptocurrency miner | Joe Security |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_Xmrig | Yara detected Xmrig cryptocurrency miner | Joe Security | ||
JoeSecurity_Xmrig | Yara detected Xmrig cryptocurrency miner | Joe Security |
⊘No Suricata rule has matched
Click to jump to signature section
Show All Signature Results
AV Detection |
---|
Source: | Avira: |
Source: | ReversingLabs: | |||
Source: | Virustotal: | Perma Link |
Bitcoin Miner |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | String found in binary or memory: |
Source: | String: | ||
Source: | String: |
Source: | HTTP traffic detected: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | DNS traffic detected: |
Source: | HTTP traffic detected: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | String containing 'busybox' found: | ||
Source: | String containing 'busybox' found: | ||
Source: | String containing 'busybox' found: |
Source: | .symtab present: |
Source: | Classification label: |
Source: | Queries kernel information via 'uname': | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | 1 Scripting | Valid Accounts | Windows Management Instrumentation | 1 Scripting | Path Interception | Direct Volume Access | OS Credential Dumping | 11 Security Software Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | Rootkit | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 2 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 3 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
⊘No configs have been found
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
53% | ReversingLabs | Linux.Worm.Mirai | ||
38% | Virustotal | Browse | ||
100% | Avira | LINUX/Mirai.bonb |
⊘No Antivirus matches
⊘No Antivirus matches
⊘No Antivirus matches
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
daisy.ubuntu.com | 162.213.35.24 | true | false | high |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
162.213.35.25 | unknown | United States | 41231 | CANONICAL-ASGB | false | |
169.254.169.254 | unknown | Reserved | 6966 | USDOSUS | false |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
162.213.35.25 | Get hash | malicious | Mirai, Xmrig | Browse | ||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Mirai, Xmrig | Browse | |||
Get hash | malicious | Mirai, Xmrig | Browse | |||
Get hash | malicious | Mirai, Xmrig | Browse | |||
Get hash | malicious | Mirai, Xmrig | Browse | |||
Get hash | malicious | Mirai, Xmrig | Browse | |||
Get hash | malicious | Sliver | Browse | |||
Get hash | malicious | Mirai, Xmrig | Browse | |||
Get hash | malicious | Mirai, Xmrig | Browse | |||
169.254.169.254 | Get hash | malicious | Unknown | Browse | ||
Get hash | malicious | Xmrig | Browse | |||
Get hash | malicious | Mirai, Xmrig | Browse | |||
Get hash | malicious | Mirai, Xmrig | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Mirai, Xmrig | Browse | |||
Get hash | malicious | Mirai, Xmrig | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Mirai, Xmrig | Browse | |||
Get hash | malicious | Mirai, Xmrig | Browse |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
daisy.ubuntu.com | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Xmrig | Browse |
| ||
Get hash | malicious | Mirai, Xmrig | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai, Xmrig | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai, Xmrig | Browse |
| ||
Get hash | malicious | Mirai, Xmrig | Browse |
| ||
Get hash | malicious | Mirai, Xmrig | Browse |
| ||
Get hash | malicious | Mirai, Xmrig | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
USDOSUS | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Xmrig | Browse |
| ||
Get hash | malicious | Mirai, Xmrig | Browse |
| ||
Get hash | malicious | Mirai, Xmrig | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai, Xmrig | Browse |
| ||
Get hash | malicious | Mirai, Xmrig | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai, Xmrig | Browse |
| ||
Get hash | malicious | Mirai, Xmrig | Browse |
| ||
CANONICAL-ASGB | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai, Xmrig | Browse |
| ||
Get hash | malicious | Xmrig | Browse |
| ||
Get hash | malicious | Mirai, Xmrig | Browse |
| ||
Get hash | malicious | Mirai, Xmrig | Browse |
| ||
Get hash | malicious | Mirai, Xmrig | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai, Xmrig | Browse |
|
⊘No context
⊘No context
⊘No created / dropped files found
File type: | |
Entropy (8bit): | 5.863016023076899 |
TrID: |
|
File name: | morte.arm5.elf |
File size: | 59'220 bytes |
MD5: | 9ada581d6a9bed30682b75294a05ad00 |
SHA1: | 0588d6c62930a5a3bbc3f4c14bc2e01e789e764e |
SHA256: | 5a239de9ad645884852a0fb1c911c1efa06c9378097096c7e1b8280c63504a0d |
SHA512: | 182be25d3dc3e1d8ba2f868c9234ae81d99fdac935f3b7c8e5578572f46848f7ba0fd3ae8da892ac78c11f141de01e4748120dc58be10c681d5db9835981db0d |
SSDEEP: | 768:YLKbp3iZjwDcaqd+mPW511jjkVQxiOww15FGRkn/nDyyxwdo/qnHoAMM4BNBFrzE:jhWwH6I1JRPFGRknWyxQo/qnIBzE |
TLSH: | 48430881FCD289ABC5C063B6B72E568E33A273A5D2CE3307CD181B16378951F8D67A51 |
File Content Preview: | .ELF...a..........(.........4...\.......4. ...(.........4...4...4...................................................................h...h...............l...l...l...t...............................................Q.td............................/lib/ld-uCl |
ELF header | |
---|---|
Class: | |
Data: | |
Version: | |
Machine: | |
Version Number: | |
Type: | |
OS/ABI: | |
ABI Version: | 0 |
Entry Point Address: | |
Flags: | |
ELF Header Size: | 52 |
Program Header Offset: | 52 |
Program Header Size: | 32 |
Number of Program Headers: | 6 |
Section Header Offset: | 58460 |
Section Header Size: | 40 |
Number of Section Headers: | 19 |
Header String Table Index: | 18 |
Name | Type | Address | Offset | Size | EntSize | Flags | Flags Description | Link | Info | Align |
---|---|---|---|---|---|---|---|---|---|---|
NULL | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0 | 0 | 0 | ||
.interp | PROGBITS | 0x80f4 | 0xf4 | 0x14 | 0x0 | 0x2 | A | 0 | 0 | 1 |
.hash | HASH | 0x8108 | 0x108 | 0x338 | 0x4 | 0x2 | A | 3 | 0 | 4 |
.dynsym | DYNSYM | 0x8440 | 0x440 | 0x6b0 | 0x10 | 0x2 | A | 4 | 1 | 4 |
.dynstr | STRTAB | 0x8af0 | 0xaf0 | 0x349 | 0x0 | 0x2 | A | 0 | 0 | 1 |
.rel.dyn | REL | 0x8e3c | 0xe3c | 0x10 | 0x8 | 0x2 | A | 3 | 0 | 4 |
.rel.plt | REL | 0x8e4c | 0xe4c | 0x2a8 | 0x8 | 0x2 | A | 3 | 8 | 4 |
.init | PROGBITS | 0x90f4 | 0x10f4 | 0x18 | 0x0 | 0x6 | AX | 0 | 0 | 4 |
.plt | PROGBITS | 0x910c | 0x110c | 0x410 | 0x4 | 0x6 | AX | 0 | 0 | 4 |
.text | PROGBITS | 0x951c | 0x151c | 0xaa80 | 0x0 | 0x6 | AX | 0 | 0 | 4 |
.fini | PROGBITS | 0x13f9c | 0xbf9c | 0x14 | 0x0 | 0x6 | AX | 0 | 0 | 4 |
.rodata | PROGBITS | 0x13fb0 | 0xbfb0 | 0x20b8 | 0x0 | 0x2 | A | 0 | 0 | 4 |
.ctors | PROGBITS | 0x1e06c | 0xe06c | 0x8 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.dtors | PROGBITS | 0x1e074 | 0xe074 | 0x8 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.dynamic | DYNAMIC | 0x1e080 | 0xe080 | 0xb0 | 0x8 | 0x3 | WA | 4 | 0 | 4 |
.got | PROGBITS | 0x1e130 | 0xe130 | 0x160 | 0x4 | 0x3 | WA | 0 | 0 | 4 |
.data | PROGBITS | 0x1e290 | 0xe290 | 0x150 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.bss | NOBITS | 0x1e3e0 | 0xe3e0 | 0x8228 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.shstrtab | STRTAB | 0x0 | 0xe3e0 | 0x7c | 0x0 | 0x0 | 0 | 0 | 1 |
Type | Offset | Virtual Address | Physical Address | File Size | Memory Size | Entropy | Flags | Flags Description | Align | Prog Interpreter | Section Mappings |
---|---|---|---|---|---|---|---|---|---|---|---|
PHDR | 0x34 | 0x8034 | 0x8034 | 0xc0 | 0xc0 | 2.2351 | 0x5 | R E | 0x4 | ||
INTERP | 0xf4 | 0x80f4 | 0x80f4 | 0x14 | 0x14 | 3.6842 | 0x4 | R | 0x1 | /lib/ld-uClibc.so.0 | .interp |
LOAD | 0x0 | 0x8000 | 0x8000 | 0xe068 | 0xe068 | 5.9069 | 0x5 | R E | 0x8000 | .interp .hash .dynsym .dynstr .rel.dyn .rel.plt .init .plt .text .fini .rodata | |
LOAD | 0xe06c | 0x1e06c | 0x1e06c | 0x374 | 0x859c | 2.9326 | 0x6 | RW | 0x8000 | .ctors .dtors .dynamic .got .data .bss | |
DYNAMIC | 0xe080 | 0x1e080 | 0x1e080 | 0xb0 | 0xb0 | 2.0142 | 0x6 | RW | 0x4 | .dynamic | |
GNU_STACK | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0.0000 | 0x7 | RWE | 0x4 |
Type | Meta | Value | Tag |
---|---|---|---|
DT_NEEDED | sharedlib | libc.so.0 | 0x1 |
DT_INIT | value | 0x90f4 | 0xc |
DT_FINI | value | 0x13f9c | 0xd |
DT_HASH | value | 0x8108 | 0x4 |
DT_STRTAB | value | 0x8af0 | 0x5 |
DT_SYMTAB | value | 0x8440 | 0x6 |
DT_STRSZ | bytes | 841 | 0xa |
DT_SYMENT | bytes | 16 | 0xb |
DT_DEBUG | value | 0x0 | 0x15 |
DT_PLTGOT | value | 0x1e130 | 0x3 |
DT_PLTRELSZ | bytes | 680 | 0x2 |
DT_PLTREL | pltrel | DT_REL | 0x14 |
DT_JMPREL | value | 0x8e4c | 0x17 |
DT_REL | value | 0x8e3c | 0x11 |
DT_RELSZ | bytes | 16 | 0x12 |
DT_RELENT | bytes | 8 | 0x13 |
DT_NULL | value | 0x0 | 0x0 |
Name | Version Info Name | Version Info File Name | Section Name | Value | Size | Symbol Type | Symbol Bind | Symbol Visibility | Ndx |
---|---|---|---|---|---|---|---|---|---|
.dynsym | 0x0 | 0 | NOTYPE | <unknown> | DEFAULT | SHN_UNDEF | |||
__aeabi_idiv0 | .dynsym | 0x13f5c | 4 | FUNC | <unknown> | DEFAULT | 9 | ||
__aeabi_ldiv0 | .dynsym | 0x13f5c | 4 | FUNC | <unknown> | DEFAULT | 9 | ||
__aeabi_uidiv | .dynsym | 0x13c9c | 0 | FUNC | <unknown> | DEFAULT | 9 | ||
__aeabi_uidivmod | .dynsym | 0x13d94 | 24 | FUNC | <unknown> | DEFAULT | 9 | ||
__bss_end__ | .dynsym | 0x26608 | 0 | NOTYPE | <unknown> | DEFAULT | SHN_ABS | ||
__bss_start | .dynsym | 0x1e3e0 | 0 | NOTYPE | <unknown> | DEFAULT | SHN_ABS | ||
__bss_start__ | .dynsym | 0x1e3e0 | 0 | NOTYPE | <unknown> | DEFAULT | SHN_ABS | ||
__ctype_b | .dynsym | 0x1e3e0 | 4 | OBJECT | <unknown> | DEFAULT | 19 | ||
__data_start | .dynsym | 0x1e290 | 0 | NOTYPE | <unknown> | DEFAULT | 18 | ||
__div0 | .dynsym | 0x13f5c | 4 | FUNC | <unknown> | DEFAULT | 9 | ||
__end__ | .dynsym | 0x26608 | 0 | NOTYPE | <unknown> | DEFAULT | SHN_ABS | ||
__environ | .dynsym | 0x1e3e4 | 4 | OBJECT | <unknown> | DEFAULT | 19 | ||
__errno_location | .dynsym | 0x9474 | 32 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
__modsi3 | .dynsym | 0x13e78 | 228 | FUNC | <unknown> | DEFAULT | 9 | ||
__uClibc_main | .dynsym | 0x93cc | 488 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
__udivsi3 | .dynsym | 0x13c9c | 248 | FUNC | <unknown> | DEFAULT | 9 | ||
__umodsi3 | .dynsym | 0x13dac | 204 | FUNC | <unknown> | DEFAULT | 9 | ||
_bss_end__ | .dynsym | 0x26608 | 0 | NOTYPE | <unknown> | DEFAULT | SHN_ABS | ||
_edata | .dynsym | 0x1e3e0 | 0 | NOTYPE | <unknown> | DEFAULT | SHN_ABS | ||
_end | .dynsym | 0x26608 | 0 | NOTYPE | <unknown> | DEFAULT | SHN_ABS | ||
_start | .dynsym | 0x95fc | 80 | FUNC | <unknown> | DEFAULT | 9 | ||
abort | .dynsym | 0x927c | 352 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
accept | .dynsym | 0x9294 | 44 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
access | .dynsym | 0x9468 | 44 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
atoi | .dynsym | 0x948c | 12 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
bind | .dynsym | 0x92d0 | 44 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
calloc | .dynsym | 0x92ac | 88 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
chdir | .dynsym | 0x92e8 | 44 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
chmod | .dynsym | 0x9288 | 52 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
clock | .dynsym | 0x94b0 | 52 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
close | .dynsym | 0x94ec | 44 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
closedir | .dynsym | 0x94d4 | 196 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
connect | .dynsym | 0x9150 | 44 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
dup2 | .dynsym | 0x91d4 | 44 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
environ | .dynsym | 0x1e3e4 | 4 | OBJECT | <unknown> | DEFAULT | 19 | ||
execl | .dynsym | 0x91bc | 164 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
execv | .dynsym | 0x93b4 | 40 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
exit | .dynsym | 0x9480 | 172 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
fclose | .dynsym | 0x93fc | 448 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
fcntl | .dynsym | 0x94e0 | 116 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
fgets | .dynsym | 0x9198 | 164 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
fopen | .dynsym | 0x93e4 | 12 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
fork | .dynsym | 0x939c | 44 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
fread | .dynsym | 0x93c0 | 172 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
free | .dynsym | 0x94f8 | 288 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
fseek | .dynsym | 0x9300 | 12 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
fwrite | .dynsym | 0x945c | 172 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
getpid | .dynsym | 0x918c | 44 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
getppid | .dynsym | 0x9408 | 44 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
getsockname | .dynsym | 0x9510 | 44 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
getsockopt | .dynsym | 0x9450 | 48 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
inet_addr | .dynsym | 0x92dc | 36 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
inotify_add_watch | .dynsym | 0x9444 | 44 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
inotify_init | .dynsym | 0x9258 | 44 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
inotify_rm_watch | .dynsym | 0x0 | 44 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
ioctl | .dynsym | 0x9138 | 80 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
kill | .dynsym | 0x92b8 | 44 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
listen | .dynsym | 0x9390 | 44 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
malloc | .dynsym | 0x91ec | 400 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
memcpy | .dynsym | 0x91b0 | 4 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
memmove | .dynsym | 0x9168 | 4 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
memset | .dynsym | 0x93f0 | 156 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
open | .dynsym | 0x94a4 | 92 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
opendir | .dynsym | 0x9420 | 264 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
prctl | .dynsym | 0x91a4 | 48 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
rand | .dynsym | 0x933c | 4 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
read | .dynsym | 0x9354 | 44 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
readdir | .dynsym | 0x924c | 224 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
readlink | .dynsym | 0x91c8 | 44 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
realloc | .dynsym | 0x9384 | 312 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
recv | .dynsym | 0x9144 | 44 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
recvfrom | .dynsym | 0x921c | 52 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
remove | .dynsym | 0x91f8 | 72 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
rename | .dynsym | 0x92a0 | 44 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
sched_setscheduler | .dynsym | 0x9210 | 44 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
select | .dynsym | 0x9240 | 48 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
send | .dynsym | 0x9270 | 44 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
sendto | .dynsym | 0x9378 | 52 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
setsid | .dynsym | 0x94c8 | 44 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
setsockopt | .dynsym | 0x92f4 | 48 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
sigaddset | .dynsym | 0x9264 | 48 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
sigemptyset | .dynsym | 0x915c | 24 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
signal | .dynsym | 0x9348 | 200 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
sigprocmask | .dynsym | 0x9504 | 84 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
sleep | .dynsym | 0x9204 | 420 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
snprintf | .dynsym | 0x9174 | 48 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
socket | .dynsym | 0x9234 | 44 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
sscanf | .dynsym | 0x93a8 | 48 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
strcasestr | .dynsym | 0x9324 | 168 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
strcat | .dynsym | 0x92c4 | 40 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
strchr | .dynsym | 0x94bc | 264 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
strcmp | .dynsym | 0x942c | 28 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
strcpy | .dynsym | 0x9120 | 28 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
strcspn | .dynsym | 0x9438 | 64 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
strlen | .dynsym | 0x9498 | 96 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
strncpy | .dynsym | 0x9360 | 184 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
strstr | .dynsym | 0x9330 | 248 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
strtoul | .dynsym | 0x9228 | 8 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
symlink | .dynsym | 0x93d8 | 44 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
system | .dynsym | 0x91e0 | 336 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
time | .dynsym | 0x9414 | 44 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
umask | .dynsym | 0x9318 | 56 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
unlink | .dynsym | 0x936c | 44 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
usleep | .dynsym | 0x9180 | 76 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
wait | .dynsym | 0x930c | 20 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
waitpid | .dynsym | 0x912c | 8 | FUNC | <unknown> | DEFAULT | SHN_UNDEF |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jul 6, 2025 08:20:01.420061111 CEST | 48848 | 80 | 192.168.2.15 | 169.254.169.254 |
Jul 6, 2025 08:20:02.433197021 CEST | 48848 | 80 | 192.168.2.15 | 169.254.169.254 |
Jul 6, 2025 08:20:04.448750019 CEST | 48848 | 80 | 192.168.2.15 | 169.254.169.254 |
Jul 6, 2025 08:20:20.800801039 CEST | 60636 | 443 | 192.168.2.15 | 162.213.35.25 |
Jul 6, 2025 08:20:20.800837040 CEST | 443 | 60636 | 162.213.35.25 | 192.168.2.15 |
Jul 6, 2025 08:20:20.800894976 CEST | 60636 | 443 | 192.168.2.15 | 162.213.35.25 |
Jul 6, 2025 08:20:21.566319942 CEST | 60636 | 443 | 192.168.2.15 | 162.213.35.25 |
Jul 6, 2025 08:20:21.566349983 CEST | 443 | 60636 | 162.213.35.25 | 192.168.2.15 |
Jul 6, 2025 08:20:21.685249090 CEST | 443 | 60636 | 162.213.35.25 | 192.168.2.15 |
Jul 6, 2025 08:20:21.685677052 CEST | 60636 | 443 | 192.168.2.15 | 162.213.35.25 |
Jul 6, 2025 08:20:21.685677052 CEST | 60636 | 443 | 192.168.2.15 | 162.213.35.25 |
Jul 6, 2025 08:20:21.685707092 CEST | 443 | 60636 | 162.213.35.25 | 192.168.2.15 |
Jul 6, 2025 08:20:21.687097073 CEST | 60636 | 443 | 192.168.2.15 | 162.213.35.25 |
Jul 6, 2025 08:20:21.687108994 CEST | 443 | 60636 | 162.213.35.25 | 192.168.2.15 |
Jul 6, 2025 08:20:21.687433004 CEST | 60636 | 443 | 192.168.2.15 | 162.213.35.25 |
Jul 6, 2025 08:20:21.687438011 CEST | 443 | 60636 | 162.213.35.25 | 192.168.2.15 |
Jul 6, 2025 08:20:21.687549114 CEST | 443 | 60636 | 162.213.35.25 | 192.168.2.15 |
Jul 6, 2025 08:20:21.687599897 CEST | 60636 | 443 | 192.168.2.15 | 162.213.35.25 |
Jul 6, 2025 08:20:21.689903975 CEST | 443 | 60636 | 162.213.35.25 | 192.168.2.15 |
Jul 6, 2025 08:20:21.689970970 CEST | 60636 | 443 | 192.168.2.15 | 162.213.35.25 |
Jul 6, 2025 08:20:21.690025091 CEST | 60636 | 443 | 192.168.2.15 | 162.213.35.25 |
Jul 6, 2025 08:20:21.690025091 CEST | 60636 | 443 | 192.168.2.15 | 162.213.35.25 |
Jul 6, 2025 08:20:21.690440893 CEST | 443 | 60636 | 162.213.35.25 | 192.168.2.15 |
Jul 6, 2025 08:20:21.690525055 CEST | 60636 | 443 | 192.168.2.15 | 162.213.35.25 |
Jul 6, 2025 08:20:21.690535069 CEST | 60636 | 443 | 192.168.2.15 | 162.213.35.25 |
Jul 6, 2025 08:20:21.690546989 CEST | 443 | 60636 | 162.213.35.25 | 192.168.2.15 |
Jul 6, 2025 08:20:21.690557957 CEST | 443 | 60636 | 162.213.35.25 | 192.168.2.15 |
Jul 6, 2025 08:20:21.690587044 CEST | 60636 | 443 | 192.168.2.15 | 162.213.35.25 |
Jul 6, 2025 08:20:21.690587044 CEST | 60636 | 443 | 192.168.2.15 | 162.213.35.25 |
Jul 6, 2025 08:20:21.690594912 CEST | 443 | 60636 | 162.213.35.25 | 192.168.2.15 |
Jul 6, 2025 08:20:21.690603018 CEST | 443 | 60636 | 162.213.35.25 | 192.168.2.15 |
Jul 6, 2025 08:20:21.690618992 CEST | 60636 | 443 | 192.168.2.15 | 162.213.35.25 |
Jul 6, 2025 08:20:21.690624952 CEST | 443 | 60636 | 162.213.35.25 | 192.168.2.15 |
Jul 6, 2025 08:20:21.690639019 CEST | 60636 | 443 | 192.168.2.15 | 162.213.35.25 |
Jul 6, 2025 08:20:21.690639019 CEST | 60636 | 443 | 192.168.2.15 | 162.213.35.25 |
Jul 6, 2025 08:20:21.690649033 CEST | 443 | 60636 | 162.213.35.25 | 192.168.2.15 |
Jul 6, 2025 08:20:21.690656900 CEST | 443 | 60636 | 162.213.35.25 | 192.168.2.15 |
Jul 6, 2025 08:20:21.690665960 CEST | 60636 | 443 | 192.168.2.15 | 162.213.35.25 |
Jul 6, 2025 08:20:21.690673113 CEST | 443 | 60636 | 162.213.35.25 | 192.168.2.15 |
Jul 6, 2025 08:20:21.690680027 CEST | 60636 | 443 | 192.168.2.15 | 162.213.35.25 |
Jul 6, 2025 08:20:21.690696001 CEST | 60636 | 443 | 192.168.2.15 | 162.213.35.25 |
Jul 6, 2025 08:20:21.690704107 CEST | 60636 | 443 | 192.168.2.15 | 162.213.35.25 |
Jul 6, 2025 08:20:21.691458941 CEST | 443 | 60636 | 162.213.35.25 | 192.168.2.15 |
Jul 6, 2025 08:20:22.667460918 CEST | 443 | 60636 | 162.213.35.25 | 192.168.2.15 |
Jul 6, 2025 08:20:22.667612076 CEST | 443 | 60636 | 162.213.35.25 | 192.168.2.15 |
Jul 6, 2025 08:20:22.667680979 CEST | 60636 | 443 | 192.168.2.15 | 162.213.35.25 |
Jul 6, 2025 08:20:22.667680979 CEST | 60636 | 443 | 192.168.2.15 | 162.213.35.25 |
Jul 6, 2025 08:20:22.674611092 CEST | 60636 | 443 | 192.168.2.15 | 162.213.35.25 |
Jul 6, 2025 08:20:22.674905062 CEST | 443 | 60636 | 162.213.35.25 | 192.168.2.15 |
Jul 6, 2025 08:20:22.675595045 CEST | 60636 | 443 | 192.168.2.15 | 162.213.35.25 |
Jul 6, 2025 08:20:22.675606966 CEST | 443 | 60636 | 162.213.35.25 | 192.168.2.15 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jul 6, 2025 08:19:22.972877979 CEST | 60437 | 53 | 192.168.2.15 | 1.1.1.1 |
Jul 6, 2025 08:19:22.972929001 CEST | 49342 | 53 | 192.168.2.15 | 1.1.1.1 |
Jul 6, 2025 08:19:23.058482885 CEST | 53 | 60437 | 1.1.1.1 | 192.168.2.15 |
Jul 6, 2025 08:19:23.059237957 CEST | 53 | 49342 | 1.1.1.1 | 192.168.2.15 |
Jul 6, 2025 08:20:20.709419012 CEST | 41103 | 53 | 192.168.2.15 | 1.1.1.1 |
Jul 6, 2025 08:20:20.709470987 CEST | 42345 | 53 | 192.168.2.15 | 1.1.1.1 |
Jul 6, 2025 08:20:20.797287941 CEST | 53 | 41103 | 1.1.1.1 | 192.168.2.15 |
Jul 6, 2025 08:20:20.797816038 CEST | 53 | 42345 | 1.1.1.1 | 192.168.2.15 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Jul 6, 2025 08:19:22.972877979 CEST | 192.168.2.15 | 1.1.1.1 | 0xab89 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jul 6, 2025 08:19:22.972929001 CEST | 192.168.2.15 | 1.1.1.1 | 0xd065 | Standard query (0) | 28 | IN (0x0001) | false | |
Jul 6, 2025 08:20:20.709419012 CEST | 192.168.2.15 | 1.1.1.1 | 0xb09e | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jul 6, 2025 08:20:20.709470987 CEST | 192.168.2.15 | 1.1.1.1 | 0x363f | Standard query (0) | 28 | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Jul 6, 2025 08:19:23.058482885 CEST | 1.1.1.1 | 192.168.2.15 | 0xab89 | No error (0) | 162.213.35.24 | A (IP address) | IN (0x0001) | false | ||
Jul 6, 2025 08:19:23.058482885 CEST | 1.1.1.1 | 192.168.2.15 | 0xab89 | No error (0) | 162.213.35.25 | A (IP address) | IN (0x0001) | false | ||
Jul 6, 2025 08:20:20.797287941 CEST | 1.1.1.1 | 192.168.2.15 | 0xb09e | No error (0) | 162.213.35.25 | A (IP address) | IN (0x0001) | false | ||
Jul 6, 2025 08:20:20.797287941 CEST | 1.1.1.1 | 192.168.2.15 | 0xb09e | No error (0) | 162.213.35.24 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port |
---|---|---|---|---|
0 | 192.168.2.15 | 60636 | 162.213.35.25 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-07-06 06:20:21 UTC | 307 | OUT | |
2025-07-06 06:20:21 UTC | 1460 | OUT | |
2025-07-06 06:20:21 UTC | 1460 | OUT | |
2025-07-06 06:20:21 UTC | 1460 | OUT | |
2025-07-06 06:20:21 UTC | 1460 | OUT | |
2025-07-06 06:20:21 UTC | 1460 | OUT | |
2025-07-06 06:20:21 UTC | 1460 | OUT | |
2025-07-06 06:20:21 UTC | 1460 | OUT | |
2025-07-06 06:20:21 UTC | 1460 | OUT | |
2025-07-06 06:20:21 UTC | 1460 | OUT | |
2025-07-06 06:20:21 UTC | 1460 | OUT | |
2025-07-06 06:20:22 UTC | 286 | IN |
System Behavior
Start time (UTC): | 06:16:38 |
Start date (UTC): | 06/07/2025 |
Path: | /tmp/morte.arm5.elf |
Arguments: | /tmp/morte.arm5.elf |
File size: | 4956856 bytes |
MD5 hash: | 5ebfcae4fe2471fcc5695c2394773ff1 |
Start time (UTC): | 06:19:22 |
Start date (UTC): | 06/07/2025 |
Path: | /usr/bin/python3.8 |
Arguments: | - |
File size: | 5490352 bytes |
MD5 hash: | 69f442c3e33b5f9a66b722c29ad89435 |
Start time (UTC): | 06:19:22 |
Start date (UTC): | 06/07/2025 |
Path: | /bin/dpkg |
Arguments: | dpkg --print-architecture |
File size: | 309944 bytes |
MD5 hash: | 5e18156b434fc45062eec2f28b9147be |