Loading ...

Play interactive tourEdit tour

Linux Analysis Report 78mne21kC0

Overview

General Information

Sample Name:78mne21kC0
Analysis ID:491790
MD5:12cf087e49d1f9abc65f3b9f6d62470c
SHA1:464abb479aa8d908d534ba39691b427e21b65566
SHA256:9b4db7f46e24f6f9748d2b82a2497fe237fce6b1f4922c6a4eaffd286a2d3466
Tags:32elfmiraimotorola
Infos:

Detection

Score:52
Range:0 - 100
Whitelisted:false

Signatures

Multi AV Scanner detection for submitted file
Opens /proc/net/* files useful for finding connected devices and routers
Uses the "uname" system call to query kernel version information (possible evasion)
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Detected TCP or UDP traffic on non-standard ports
Sample has stripped symbol table

Classification

Analysis Advice

All HTTP servers contacted by the sample do not answer. Likely the sample is an old dropper which does no longer work
Static ELF header machine description suggests that the sample might not execute correctly on this machine

General Information

Joe Sandbox Version:33.0.0 White Diamond
Analysis ID:491790
Start date:27.09.2021
Start time:22:40:19
Joe Sandbox Product:CloudBasic
Overall analysis duration:0h 6m 23s
Hypervisor based Inspection enabled:false
Report type:light
Sample file name:78mne21kC0
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Detection:MAL
Classification:mal52.spre.lin@0/1@0/0

Process Tree

  • system is lnxubuntu20
  • 78mne21kC0 (PID: 5226, Parent: 5114, MD5: cd177594338c77b895ae27c33f8f86cc) Arguments: /tmp/78mne21kC0
  • cleanup

Yara Overview

No yara matches

Jbx Signature Overview

Click to jump to signature section

Show All Signature Results

AV Detection:

barindex
Multi AV Scanner detection for submitted fileShow sources
Source: 78mne21kC0Virustotal: Detection: 47%Perma Link
Source: 78mne21kC0ReversingLabs: Detection: 46%

Spreading:

barindex
Opens /proc/net/* files useful for finding connected devices and routersShow sources
Source: /tmp/78mne21kC0 (PID: 5226)Opens: /proc/net/route
Source: global trafficTCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
Source: global trafficTCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
Source: global trafficTCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
Source: global trafficTCP traffic: 192.168.2.23:44652 -> 167.114.109.203:6525
Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443
Source: unknownTCP traffic detected without corresponding DNS query: 167.114.109.203
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 167.114.109.203
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 167.114.109.203
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 167.114.109.203
Source: unknownTCP traffic detected without corresponding DNS query: 167.114.109.203
Source: unknownTCP traffic detected without corresponding DNS query: 167.114.109.203
Source: unknownTCP traffic detected without corresponding DNS query: 167.114.109.203
Source: unknownTCP traffic detected without corresponding DNS query: 167.114.109.203
Source: unknownTCP traffic detected without corresponding DNS query: 167.114.109.203
Source: unknownTCP traffic detected without corresponding DNS query: 167.114.109.203
Source: unknownTCP traffic detected without corresponding DNS query: 167.114.109.203
Source: ELF static info symbol of initial sample.symtab present: no
Source: classification engineClassification label: mal52.spre.lin@0/1@0/0
Source: /tmp/78mne21kC0 (PID: 5226)Queries kernel information via 'uname':
Source: 78mne21kC0, 5226.1.000000001e77fee7.0000000066c953cb.rw-.sdmpBinary or memory string: U!/etc/qemu-binfmt/m68k
Source: 78mne21kC0, 5226.1.000000002f8e5260.0000000019954b0f.rw-.sdmpBinary or memory string: U/tmp/qemu-open.cFPgFo\4
Source: 78mne21kC0, 5226.1.000000002f8e5260.0000000019954b0f.rw-.sdmpBinary or memory string: /tmp/qemu-open.cFPgFo
Source: 78mne21kC0, 5226.1.000000002f8e5260.0000000019954b0f.rw-.sdmpBinary or memory string: /usr/bin/qemu-m68k
Source: 78mne21kC0, 5226.1.000000001e77fee7.0000000066c953cb.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/m68k
Source: 78mne21kC0, 5226.1.000000002f8e5260.0000000019954b0f.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-m68k/tmp/78mne21kC0SUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/78mne21kC0

Mitre Att&ck Matrix

Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid AccountsWindows Management InstrumentationPath InterceptionPath InterceptionDirect Volume AccessOS Credential DumpingSecurity Software Discovery11Remote ServicesData from Local SystemExfiltration Over Other Network MediumEncrypted Channel1Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryRemote System Discovery1Remote Desktop ProtocolData from Removable MediaExfiltration Over BluetoothNon-Standard Port1Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated ExfiltrationApplication Layer Protocol1Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data

Malware Configuration

No configs have been found

Behavior Graph

Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 491790 Sample: 78mne21kC0 Startdate: 27/09/2021 Architecture: LINUX Score: 52 17 167.114.109.203, 44652, 44654, 44656 OVHFR Canada 2->17 19 109.202.202.202, 80 INIT7CH Switzerland 2->19 21 2 other IPs or domains 2->21 23 Multi AV Scanner detection for submitted file 2->23 8 78mne21kC0 2->8         started        signatures3 process4 signatures5 25 Opens /proc/net/* files useful for finding connected devices and routers 8->25 11 78mne21kC0 8->11         started        13 78mne21kC0 8->13         started        process6 process7 15 78mne21kC0 11->15         started       

Antivirus, Machine Learning and Genetic Malware Detection

Initial Sample

SourceDetectionScannerLabelLink
78mne21kC048%VirustotalBrowse
78mne21kC047%ReversingLabsLinux.Backdoor.Bashlite

Dropped Files

No Antivirus matches

Domains

No Antivirus matches

URLs

No Antivirus matches

Domains and IPs

Contacted Domains

No contacted domains info

Contacted IPs

  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs

Public

IPDomainCountryFlagASNASN NameMalicious
167.114.109.203
unknownCanada
16276OVHFRfalse
109.202.202.202
unknownSwitzerland
13030INIT7CHfalse
91.189.91.43
unknownUnited Kingdom
41231CANONICAL-ASGBfalse
91.189.91.42
unknownUnited Kingdom
41231CANONICAL-ASGBfalse


Runtime Messages

Command:/tmp/78mne21kC0
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
gosh that chinese family at the other table sure ate alot
Standard Error:

Joe Sandbox View / Context

IPs

MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
167.114.109.203exIOc2VzNAGet hashmaliciousBrowse
    QJWCkLL0hWGet hashmaliciousBrowse
      sA7VIyESByGet hashmaliciousBrowse
        bmcmz7CH5kGet hashmaliciousBrowse
          CTKpl4EfIwGet hashmaliciousBrowse
            imqksAx51TGet hashmaliciousBrowse
              8eyaMuD9DYGet hashmaliciousBrowse
                tnMrX1z0d5Get hashmaliciousBrowse
                  X86_64Get hashmaliciousBrowse
                    109.202.202.202exIOc2VzNAGet hashmaliciousBrowse
                      QJWCkLL0hWGet hashmaliciousBrowse
                        sA7VIyESByGet hashmaliciousBrowse
                          bmcmz7CH5kGet hashmaliciousBrowse
                            CTKpl4EfIwGet hashmaliciousBrowse
                              imqksAx51TGet hashmaliciousBrowse
                                8eyaMuD9DYGet hashmaliciousBrowse
                                  tnMrX1z0d5Get hashmaliciousBrowse
                                    H3NaLv48NKGet hashmaliciousBrowse
                                      i07CkTx8C4Get hashmaliciousBrowse
                                        p22l26A3WuGet hashmaliciousBrowse
                                          fVNp9NC9l9Get hashmaliciousBrowse
                                            wlJuLkUpqEGet hashmaliciousBrowse
                                              cAoLg1WlGiGet hashmaliciousBrowse
                                                77sa4X7MY2Get hashmaliciousBrowse
                                                  X86_64Get hashmaliciousBrowse
                                                    rrVvnZMcFsGet hashmaliciousBrowse
                                                      pAu4km62R9Get hashmaliciousBrowse
                                                        kUFNxyzq7hGet hashmaliciousBrowse
                                                          QMVi2eFA3OGet hashmaliciousBrowse
                                                            91.189.91.43exIOc2VzNAGet hashmaliciousBrowse
                                                              QJWCkLL0hWGet hashmaliciousBrowse
                                                                sA7VIyESByGet hashmaliciousBrowse
                                                                  bmcmz7CH5kGet hashmaliciousBrowse
                                                                    CTKpl4EfIwGet hashmaliciousBrowse
                                                                      imqksAx51TGet hashmaliciousBrowse
                                                                        8eyaMuD9DYGet hashmaliciousBrowse
                                                                          tnMrX1z0d5Get hashmaliciousBrowse
                                                                            H3NaLv48NKGet hashmaliciousBrowse
                                                                              i07CkTx8C4Get hashmaliciousBrowse
                                                                                p22l26A3WuGet hashmaliciousBrowse
                                                                                  fVNp9NC9l9Get hashmaliciousBrowse
                                                                                    wlJuLkUpqEGet hashmaliciousBrowse
                                                                                      cAoLg1WlGiGet hashmaliciousBrowse
                                                                                        77sa4X7MY2Get hashmaliciousBrowse
                                                                                          X86_64Get hashmaliciousBrowse
                                                                                            rrVvnZMcFsGet hashmaliciousBrowse
                                                                                              pAu4km62R9Get hashmaliciousBrowse
                                                                                                kUFNxyzq7hGet hashmaliciousBrowse
                                                                                                  QMVi2eFA3OGet hashmaliciousBrowse

                                                                                                    Domains

                                                                                                    No context

                                                                                                    ASN

                                                                                                    MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                                                                                                    CANONICAL-ASGBexIOc2VzNAGet hashmaliciousBrowse
                                                                                                    • 91.189.91.42
                                                                                                    QJWCkLL0hWGet hashmaliciousBrowse
                                                                                                    • 91.189.91.42
                                                                                                    sA7VIyESByGet hashmaliciousBrowse
                                                                                                    • 91.189.91.42
                                                                                                    bmcmz7CH5kGet hashmaliciousBrowse
                                                                                                    • 91.189.91.42
                                                                                                    CTKpl4EfIwGet hashmaliciousBrowse
                                                                                                    • 91.189.91.42
                                                                                                    imqksAx51TGet hashmaliciousBrowse
                                                                                                    • 91.189.91.42
                                                                                                    8eyaMuD9DYGet hashmaliciousBrowse
                                                                                                    • 91.189.91.42
                                                                                                    tnMrX1z0d5Get hashmaliciousBrowse
                                                                                                    • 91.189.91.42
                                                                                                    H3NaLv48NKGet hashmaliciousBrowse
                                                                                                    • 91.189.91.42
                                                                                                    i07CkTx8C4Get hashmaliciousBrowse
                                                                                                    • 91.189.91.42
                                                                                                    p22l26A3WuGet hashmaliciousBrowse
                                                                                                    • 91.189.91.42
                                                                                                    fVNp9NC9l9Get hashmaliciousBrowse
                                                                                                    • 91.189.91.42
                                                                                                    wlJuLkUpqEGet hashmaliciousBrowse
                                                                                                    • 91.189.91.42
                                                                                                    cAoLg1WlGiGet hashmaliciousBrowse
                                                                                                    • 91.189.91.42
                                                                                                    77sa4X7MY2Get hashmaliciousBrowse
                                                                                                    • 91.189.91.42
                                                                                                    X86_64Get hashmaliciousBrowse
                                                                                                    • 91.189.91.42
                                                                                                    rrVvnZMcFsGet hashmaliciousBrowse
                                                                                                    • 91.189.91.42
                                                                                                    pAu4km62R9Get hashmaliciousBrowse
                                                                                                    • 91.189.91.42
                                                                                                    kUFNxyzq7hGet hashmaliciousBrowse
                                                                                                    • 91.189.91.42
                                                                                                    QMVi2eFA3OGet hashmaliciousBrowse
                                                                                                    • 91.189.91.42
                                                                                                    OVHFRexIOc2VzNAGet hashmaliciousBrowse
                                                                                                    • 167.114.109.203
                                                                                                    QJWCkLL0hWGet hashmaliciousBrowse
                                                                                                    • 167.114.109.203
                                                                                                    sA7VIyESByGet hashmaliciousBrowse
                                                                                                    • 167.114.109.203
                                                                                                    bmcmz7CH5kGet hashmaliciousBrowse
                                                                                                    • 167.114.109.203
                                                                                                    CTKpl4EfIwGet hashmaliciousBrowse
                                                                                                    • 167.114.109.203
                                                                                                    imqksAx51TGet hashmaliciousBrowse
                                                                                                    • 167.114.109.203
                                                                                                    8eyaMuD9DYGet hashmaliciousBrowse
                                                                                                    • 167.114.109.203
                                                                                                    tnMrX1z0d5Get hashmaliciousBrowse
                                                                                                    • 167.114.109.203
                                                                                                    X86_64Get hashmaliciousBrowse
                                                                                                    • 167.114.109.203
                                                                                                    2mdb3OG6FM.exeGet hashmaliciousBrowse
                                                                                                    • 51.255.34.79
                                                                                                    GRUPO MARI#U00d1O OBRAS Y SERVICIOS, SL Oferta 2709212890.exeGet hashmaliciousBrowse
                                                                                                    • 37.59.226.120
                                                                                                    ZFb3RmLJzoGet hashmaliciousBrowse
                                                                                                    • 51.70.255.217
                                                                                                    Sht1aYGDIXGet hashmaliciousBrowse
                                                                                                    • 51.178.244.189
                                                                                                    nDHL_Shipment_Notification_1231413385_Notification_1231413385_september2021.exeGet hashmaliciousBrowse
                                                                                                    • 178.32.63.50
                                                                                                    DHL_Shipment_Notification_1231413385_Notification_1231413385_september2021.exeGet hashmaliciousBrowse
                                                                                                    • 178.32.63.50
                                                                                                    Lrs8NGx6VM.exeGet hashmaliciousBrowse
                                                                                                    • 164.132.171.176
                                                                                                    Claim-838392655-09242021.xlsGet hashmaliciousBrowse
                                                                                                    • 51.89.115.111
                                                                                                    2PzMc3x4WP.exeGet hashmaliciousBrowse
                                                                                                    • 87.98.153.120
                                                                                                    e5jVcbuCo5.exeGet hashmaliciousBrowse
                                                                                                    • 176.31.32.199
                                                                                                    i7qUJCnMz0.exeGet hashmaliciousBrowse
                                                                                                    • 176.31.32.199
                                                                                                    INIT7CHexIOc2VzNAGet hashmaliciousBrowse
                                                                                                    • 109.202.202.202
                                                                                                    QJWCkLL0hWGet hashmaliciousBrowse
                                                                                                    • 109.202.202.202
                                                                                                    sA7VIyESByGet hashmaliciousBrowse
                                                                                                    • 109.202.202.202
                                                                                                    bmcmz7CH5kGet hashmaliciousBrowse
                                                                                                    • 109.202.202.202
                                                                                                    CTKpl4EfIwGet hashmaliciousBrowse
                                                                                                    • 109.202.202.202
                                                                                                    imqksAx51TGet hashmaliciousBrowse
                                                                                                    • 109.202.202.202
                                                                                                    8eyaMuD9DYGet hashmaliciousBrowse
                                                                                                    • 109.202.202.202
                                                                                                    tnMrX1z0d5Get hashmaliciousBrowse
                                                                                                    • 109.202.202.202
                                                                                                    H3NaLv48NKGet hashmaliciousBrowse
                                                                                                    • 109.202.202.202
                                                                                                    i07CkTx8C4Get hashmaliciousBrowse
                                                                                                    • 109.202.202.202
                                                                                                    p22l26A3WuGet hashmaliciousBrowse
                                                                                                    • 109.202.202.202
                                                                                                    fVNp9NC9l9Get hashmaliciousBrowse
                                                                                                    • 109.202.202.202
                                                                                                    wlJuLkUpqEGet hashmaliciousBrowse
                                                                                                    • 109.202.202.202
                                                                                                    cAoLg1WlGiGet hashmaliciousBrowse
                                                                                                    • 109.202.202.202
                                                                                                    77sa4X7MY2Get hashmaliciousBrowse
                                                                                                    • 109.202.202.202
                                                                                                    X86_64Get hashmaliciousBrowse
                                                                                                    • 109.202.202.202
                                                                                                    rrVvnZMcFsGet hashmaliciousBrowse
                                                                                                    • 109.202.202.202
                                                                                                    pAu4km62R9Get hashmaliciousBrowse
                                                                                                    • 109.202.202.202
                                                                                                    kUFNxyzq7hGet hashmaliciousBrowse
                                                                                                    • 109.202.202.202
                                                                                                    QMVi2eFA3OGet hashmaliciousBrowse
                                                                                                    • 109.202.202.202

                                                                                                    JA3 Fingerprints

                                                                                                    No context

                                                                                                    Dropped Files

                                                                                                    No context

                                                                                                    Created / dropped Files

                                                                                                    /tmp/qemu-open.cFPgFo (deleted)
                                                                                                    Process:/tmp/78mne21kC0
                                                                                                    File Type:ASCII text
                                                                                                    Category:dropped
                                                                                                    Size (bytes):230
                                                                                                    Entropy (8bit):3.709552666863289
                                                                                                    Encrypted:false
                                                                                                    SSDEEP:6:iekrEcvwAsE5KlwSd4pzKaV6Lpms/a/1VCxGF:ur+m5MwSdIKaV6L1adVRF
                                                                                                    MD5:2E667F43AE18CD1FE3C108641708A82C
                                                                                                    SHA1:12B90DE2DA0FBCFE66F3D6130905E56C8D6A68D3
                                                                                                    SHA-256:6F721492E7A337C5B498A8F55F5EB7AC745AFF716D0B5B08EFF2C1B6B250F983
                                                                                                    SHA-512:D2A0EE2509154EC1098994F38BE172F98F4150399C534A04D5C675D7C05630802225019F19344CC9070C576BC465A4FEB382AC7712DE6BF25E9244B54A9DB830
                                                                                                    Malicious:false
                                                                                                    Reputation:moderate, very likely benign file
                                                                                                    Preview: Iface.Destination.Gateway .Flags.RefCnt.Use.Metric.Mask..MTU.Window.IRTT .ens160.00000000.c0a80201.0003.0.0.0.00000000.0.0.0.ens160.c0a80200.00000000.0001.0.0.0.ffffff00.0.0.0.

                                                                                                    Static File Info

                                                                                                    General

                                                                                                    File type:ELF 32-bit MSB executable, Motorola m68k, 68020, version 1 (SYSV), statically linked, stripped
                                                                                                    Entropy (8bit):6.069222226696124
                                                                                                    TrID:
                                                                                                    • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                                                                                                    File name:78mne21kC0
                                                                                                    File size:89492
                                                                                                    MD5:12cf087e49d1f9abc65f3b9f6d62470c
                                                                                                    SHA1:464abb479aa8d908d534ba39691b427e21b65566
                                                                                                    SHA256:9b4db7f46e24f6f9748d2b82a2497fe237fce6b1f4922c6a4eaffd286a2d3466
                                                                                                    SHA512:156e7dcb2e6bf92cb46e7e1d0dffba83044a930a7a60edc074967528016a0a955ec70d5e016c33c6d72ff5b2d9ae38563fedfe42ed9db06d37d9cf2150ade3b2
                                                                                                    SSDEEP:1536:AcpLOIVa0aIh8FuX2W4Wsyf0/zH1B3fc+iDwy8RAlC:AcpyqaId+WFMXxiDwy8RAlC
                                                                                                    File Content Preview:.ELF.......................D...4..[......4. ...(......................K...K....... .......K...k...k.......g....... .dt.Q............................NV..a....da...".N^NuNV..J9..odf>"y..k. QJ.g.X.#...k.N."y..k. QJ.f.A.....J.g.Hy..K.N.X.......odN^NuNV..N^NuN

                                                                                                    Static ELF Info

                                                                                                    ELF header

                                                                                                    Class:ELF32
                                                                                                    Data:2's complement, big endian
                                                                                                    Version:1 (current)
                                                                                                    Machine:MC68000
                                                                                                    Version Number:0x1
                                                                                                    Type:EXEC (Executable file)
                                                                                                    OS/ABI:UNIX - System V
                                                                                                    ABI Version:0
                                                                                                    Entry Point Address:0x80000144
                                                                                                    Flags:0x0
                                                                                                    ELF Header Size:52
                                                                                                    Program Header Offset:52
                                                                                                    Program Header Size:32
                                                                                                    Number of Program Headers:3
                                                                                                    Section Header Offset:88972
                                                                                                    Section Header Size:40
                                                                                                    Number of Section Headers:13
                                                                                                    Header String Table Index:12

                                                                                                    Sections

                                                                                                    NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                                                                                    NULL0x00x00x00x00x0000
                                                                                                    .initPROGBITS0x800000940x940x140x00x6AX002
                                                                                                    .textPROGBITS0x800000a80xa80x122b80x00x6AX004
                                                                                                    .finiPROGBITS0x800123600x123600xe0x00x6AX002
                                                                                                    .rodataPROGBITS0x8001236e0x1236e0x283a0x00x2A002
                                                                                                    .eh_framePROGBITS0x80014ba80x14ba80x40x00x2A004
                                                                                                    .ctorsPROGBITS0x80016bac0x14bac0x80x00x3WA004
                                                                                                    .dtorsPROGBITS0x80016bb40x14bb40x80x00x3WA004
                                                                                                    .jcrPROGBITS0x80016bbc0x14bbc0x40x00x3WA004
                                                                                                    .dataPROGBITS0x80016bc00x14bc00x3a40x00x3WA004
                                                                                                    .bssNOBITS0x80016f640x14f640x64200x00x3WA004
                                                                                                    .commentPROGBITS0x00x14f640xbd00x00x0001
                                                                                                    .shstrtabSTRTAB0x00x15b340x560x00x0001

                                                                                                    Program Segments

                                                                                                    TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                                                                    LOAD0x00x800000000x800000000x14bac0x14bac4.03650x5R E0x2000.init .text .fini .rodata .eh_frame
                                                                                                    LOAD0x14bac0x80016bac0x80016bac0x3b80x67d81.66930x6RW 0x2000.ctors .dtors .jcr .data .bss
                                                                                                    GNU_STACK0x00x00x00x00x00.00000x6RW 0x4

                                                                                                    Network Behavior

                                                                                                    Network Port Distribution

                                                                                                    TCP Packets

                                                                                                    TimestampSource PortDest PortSource IPDest IP
                                                                                                    Sep 27, 2021 22:41:02.044011116 CEST446526525192.168.2.23167.114.109.203
                                                                                                    Sep 27, 2021 22:41:02.163188934 CEST652544652167.114.109.203192.168.2.23
                                                                                                    Sep 27, 2021 22:41:04.237195015 CEST42836443192.168.2.2391.189.91.43
                                                                                                    Sep 27, 2021 22:41:05.005088091 CEST4251680192.168.2.23109.202.202.202
                                                                                                    Sep 27, 2021 22:41:19.084280014 CEST43928443192.168.2.2391.189.91.42
                                                                                                    Sep 27, 2021 22:41:22.164369106 CEST446546525192.168.2.23167.114.109.203
                                                                                                    Sep 27, 2021 22:41:22.294698000 CEST652544654167.114.109.203192.168.2.23
                                                                                                    Sep 27, 2021 22:41:31.371589899 CEST42836443192.168.2.2391.189.91.43
                                                                                                    Sep 27, 2021 22:41:35.467391014 CEST4251680192.168.2.23109.202.202.202
                                                                                                    Sep 27, 2021 22:41:42.295109987 CEST446566525192.168.2.23167.114.109.203
                                                                                                    Sep 27, 2021 22:41:42.423990965 CEST652544656167.114.109.203192.168.2.23
                                                                                                    Sep 27, 2021 22:42:00.041908979 CEST43928443192.168.2.2391.189.91.42
                                                                                                    Sep 27, 2021 22:42:02.424287081 CEST446586525192.168.2.23167.114.109.203
                                                                                                    Sep 27, 2021 22:42:02.539799929 CEST652544658167.114.109.203192.168.2.23
                                                                                                    Sep 27, 2021 22:42:22.540050983 CEST446606525192.168.2.23167.114.109.203
                                                                                                    Sep 27, 2021 22:42:22.656213045 CEST652544660167.114.109.203192.168.2.23
                                                                                                    Sep 27, 2021 22:42:42.657004118 CEST446626525192.168.2.23167.114.109.203
                                                                                                    Sep 27, 2021 22:42:42.776714087 CEST652544662167.114.109.203192.168.2.23
                                                                                                    Sep 27, 2021 22:43:02.776978970 CEST446646525192.168.2.23167.114.109.203
                                                                                                    Sep 27, 2021 22:43:02.891592979 CEST652544664167.114.109.203192.168.2.23
                                                                                                    Sep 27, 2021 22:43:22.891875982 CEST446666525192.168.2.23167.114.109.203
                                                                                                    Sep 27, 2021 22:43:23.010710955 CEST652544666167.114.109.203192.168.2.23
                                                                                                    Sep 27, 2021 22:43:43.010927916 CEST446686525192.168.2.23167.114.109.203
                                                                                                    Sep 27, 2021 22:43:43.126482964 CEST652544668167.114.109.203192.168.2.23
                                                                                                    Sep 27, 2021 22:44:03.126398087 CEST446706525192.168.2.23167.114.109.203
                                                                                                    Sep 27, 2021 22:44:03.245327950 CEST652544670167.114.109.203192.168.2.23
                                                                                                    Sep 27, 2021 22:44:23.245476961 CEST446726525192.168.2.23167.114.109.203
                                                                                                    Sep 27, 2021 22:44:23.364697933 CEST652544672167.114.109.203192.168.2.23

                                                                                                    System Behavior

                                                                                                    General

                                                                                                    Start time:22:41:00
                                                                                                    Start date:27/09/2021
                                                                                                    Path:/tmp/78mne21kC0
                                                                                                    Arguments:/tmp/78mne21kC0
                                                                                                    File size:4463432 bytes
                                                                                                    MD5 hash:cd177594338c77b895ae27c33f8f86cc

                                                                                                    General

                                                                                                    Start time:22:41:00
                                                                                                    Start date:27/09/2021
                                                                                                    Path:/tmp/78mne21kC0
                                                                                                    Arguments:n/a
                                                                                                    File size:4463432 bytes
                                                                                                    MD5 hash:cd177594338c77b895ae27c33f8f86cc

                                                                                                    General

                                                                                                    Start time:22:41:00
                                                                                                    Start date:27/09/2021
                                                                                                    Path:/tmp/78mne21kC0
                                                                                                    Arguments:n/a
                                                                                                    File size:4463432 bytes
                                                                                                    MD5 hash:cd177594338c77b895ae27c33f8f86cc

                                                                                                    General

                                                                                                    Start time:22:41:00
                                                                                                    Start date:27/09/2021
                                                                                                    Path:/tmp/78mne21kC0
                                                                                                    Arguments:n/a
                                                                                                    File size:4463432 bytes
                                                                                                    MD5 hash:cd177594338c77b895ae27c33f8f86cc