Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
lpm941yTS7

Overview

General Information

Sample Name:lpm941yTS7
Analysis ID:680637
MD5:3c35a776bd33e73772576d33cf8db7a9
SHA1:2e8bfc20102b201eaf14227ac5abffea4ba73c7c
SHA256:e68f58e09f39ec1c8b2f2bf4b90f626b0b0d4906194f37a37a677f3a3c4f3434
Tags:32elfmipsmirai
Infos:

Detection

Mirai
Score:80
Range:0 - 100
Whitelisted:false

Signatures

Malicious sample detected (through community Yara rule)
Yara detected Mirai
Multi AV Scanner detection for submitted file
Sample is packed with UPX
Uses known network protocols on non-standard ports
Sample contains only a LOAD segment without any section mappings
Yara signature match
Uses the "uname" system call to query kernel version information (possible evasion)
Enumerates processes within the "proc" file system
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Detected TCP or UDP traffic on non-standard ports
Sample listens on a socket
Sample tries to kill a process (SIGKILL)
ELF contains segments with high entropy indicating compressed/encrypted content

Classification

Analysis Advice

Static ELF header machine description suggests that the sample might not execute correctly on this machine.
All HTTP servers contacted by the sample do not answer. The sample is likely an old dropper which does no longer work.
Static ELF header machine description suggests that the sample might only run correctly on MIPS or ARM architectures.
Joe Sandbox Version:35.0.0 Citrine
Analysis ID:680637
Start date and time: 08/08/202222:55:092022-08-08 22:55:09 +02:00
Joe Sandbox Product:CloudBasic
Overall analysis duration:0h 6m 55s
Hypervisor based Inspection enabled:false
Report type:light
Sample file name:lpm941yTS7
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Detection:MAL
Classification:mal80.troj.evad.lin@0/0@0/0
  • Report size exceeded maximum capacity and may have missing network information.
  • TCP Packets have been reduced to 100
Command:/tmp/lpm941yTS7
PID:6226
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
Connected To CNC
Standard Error:
  • system is lnxubuntu20
  • cleanup
SourceRuleDescriptionAuthorStrings
dump.pcapJoeSecurity_Mirai_12Yara detected MiraiJoe Security
    SourceRuleDescriptionAuthorStrings
    6329.1.00007f56f8400000.00007f56f8414000.r-x.sdmpJoeSecurity_Mirai_8Yara detected MiraiJoe Security
      6329.1.00007f56f8400000.00007f56f8414000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
      • 0x12d50:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x12d64:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x12d78:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x12d8c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x12da0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x12db4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x12dc8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x12ddc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x12df0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x12e04:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x12e18:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x12e2c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x12e40:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x12e54:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x12e68:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x12e7c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x12e90:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x12ea4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x12eb8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x12ecc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x12ee0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      6329.1.00007f56f8400000.00007f56f8414000.r-x.sdmpLinux_Trojan_Gafgyt_ea92cca8unknownunknown
      • 0x132a8:$a: 53 65 6C 66 20 52 65 70 20 46 75 63 6B 69 6E 67 20 4E 65 54 69 53 20 61 6E 64
      6228.1.00007f56f8400000.00007f56f8414000.r-x.sdmpJoeSecurity_Mirai_8Yara detected MiraiJoe Security
        6228.1.00007f56f8400000.00007f56f8414000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
        • 0x12d50:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x12d64:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x12d78:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x12d8c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x12da0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x12db4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x12dc8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x12ddc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x12df0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x12e04:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x12e18:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x12e2c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x12e40:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x12e54:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x12e68:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x12e7c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x12e90:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x12ea4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x12eb8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x12ecc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x12ee0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        Click to see the 30 entries
        No Snort rule has matched

        Click to jump to signature section

        Show All Signature Results

        AV Detection

        barindex
        Source: lpm941yTS7Virustotal: Detection: 30%Perma Link

        Networking

        barindex
        Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57720
        Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57736
        Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57746
        Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57758
        Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57774
        Source: global trafficTCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
        Source: global trafficTCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
        Source: global trafficTCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
        Source: global trafficTCP traffic: 192.168.2.23:35686 -> 208.67.106.33:1312
        Source: /tmp/lpm941yTS7 (PID: 6228)Socket: 0.0.0.0::0
        Source: /tmp/lpm941yTS7 (PID: 6228)Socket: 0.0.0.0::53413
        Source: /tmp/lpm941yTS7 (PID: 6228)Socket: 0.0.0.0::80
        Source: /tmp/lpm941yTS7 (PID: 6228)Socket: 0.0.0.0::52869
        Source: /tmp/lpm941yTS7 (PID: 6228)Socket: 0.0.0.0::37215
        Source: /tmp/lpm941yTS7 (PID: 6234)Socket: 0.0.0.0::0
        Source: /tmp/lpm941yTS7 (PID: 6234)Socket: 0.0.0.0::23
        Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443
        Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
        Source: unknownTCP traffic detected without corresponding DNS query: 208.67.106.33
        Source: unknownTCP traffic detected without corresponding DNS query: 208.67.106.33
        Source: unknownTCP traffic detected without corresponding DNS query: 208.67.106.33
        Source: unknownTCP traffic detected without corresponding DNS query: 190.132.191.225
        Source: unknownTCP traffic detected without corresponding DNS query: 105.206.81.225
        Source: unknownTCP traffic detected without corresponding DNS query: 59.131.106.236
        Source: unknownTCP traffic detected without corresponding DNS query: 120.17.200.140
        Source: unknownTCP traffic detected without corresponding DNS query: 107.43.55.13
        Source: unknownTCP traffic detected without corresponding DNS query: 146.218.36.127
        Source: unknownTCP traffic detected without corresponding DNS query: 182.32.164.121
        Source: unknownTCP traffic detected without corresponding DNS query: 191.73.229.109
        Source: unknownTCP traffic detected without corresponding DNS query: 171.82.255.115
        Source: unknownTCP traffic detected without corresponding DNS query: 186.126.13.19
        Source: unknownTCP traffic detected without corresponding DNS query: 64.18.157.129
        Source: unknownTCP traffic detected without corresponding DNS query: 193.178.53.130
        Source: unknownTCP traffic detected without corresponding DNS query: 41.74.121.189
        Source: unknownTCP traffic detected without corresponding DNS query: 92.76.124.129
        Source: unknownTCP traffic detected without corresponding DNS query: 59.251.207.45
        Source: unknownTCP traffic detected without corresponding DNS query: 177.112.72.195
        Source: unknownTCP traffic detected without corresponding DNS query: 174.200.206.218
        Source: unknownTCP traffic detected without corresponding DNS query: 172.67.128.144
        Source: unknownTCP traffic detected without corresponding DNS query: 68.154.44.159
        Source: unknownTCP traffic detected without corresponding DNS query: 112.164.104.255
        Source: unknownTCP traffic detected without corresponding DNS query: 32.64.207.128
        Source: unknownTCP traffic detected without corresponding DNS query: 125.185.40.96
        Source: unknownTCP traffic detected without corresponding DNS query: 121.136.179.41
        Source: unknownTCP traffic detected without corresponding DNS query: 183.223.48.119
        Source: unknownTCP traffic detected without corresponding DNS query: 59.47.18.233
        Source: unknownTCP traffic detected without corresponding DNS query: 68.30.7.249
        Source: unknownTCP traffic detected without corresponding DNS query: 202.31.236.205
        Source: unknownTCP traffic detected without corresponding DNS query: 72.15.69.180
        Source: unknownTCP traffic detected without corresponding DNS query: 222.0.122.91
        Source: unknownTCP traffic detected without corresponding DNS query: 103.2.74.0
        Source: unknownTCP traffic detected without corresponding DNS query: 44.78.5.86
        Source: unknownTCP traffic detected without corresponding DNS query: 145.195.146.193
        Source: unknownTCP traffic detected without corresponding DNS query: 118.133.189.102
        Source: unknownTCP traffic detected without corresponding DNS query: 37.134.15.67
        Source: unknownTCP traffic detected without corresponding DNS query: 92.237.140.188
        Source: unknownTCP traffic detected without corresponding DNS query: 109.192.112.130
        Source: unknownTCP traffic detected without corresponding DNS query: 198.139.69.177
        Source: unknownTCP traffic detected without corresponding DNS query: 209.237.221.172
        Source: unknownTCP traffic detected without corresponding DNS query: 201.96.51.248
        Source: unknownTCP traffic detected without corresponding DNS query: 1.103.126.187
        Source: unknownTCP traffic detected without corresponding DNS query: 76.216.183.44
        Source: unknownTCP traffic detected without corresponding DNS query: 250.62.192.150
        Source: unknownTCP traffic detected without corresponding DNS query: 166.149.207.233
        Source: unknownTCP traffic detected without corresponding DNS query: 17.111.27.56
        Source: unknownTCP traffic detected without corresponding DNS query: 142.74.134.97
        Source: unknownTCP traffic detected without corresponding DNS query: 135.36.125.104
        Source: lpm941yTS7String found in binary or memory: http://upx.sf.net

        System Summary

        barindex
        Source: 6329.1.00007f56f8400000.00007f56f8414000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
        Source: 6329.1.00007f56f8400000.00007f56f8414000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown
        Source: 6228.1.00007f56f8400000.00007f56f8414000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
        Source: 6228.1.00007f56f8400000.00007f56f8414000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown
        Source: 6328.1.00007f56f8400000.00007f56f8414000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
        Source: 6328.1.00007f56f8400000.00007f56f8414000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown
        Source: 6226.1.00007f56f8400000.00007f56f8414000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
        Source: 6226.1.00007f56f8400000.00007f56f8414000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown
        Source: 6337.1.00007f56f8400000.00007f56f8414000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
        Source: 6337.1.00007f56f8400000.00007f56f8414000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown
        Source: 6229.1.00007f56f8400000.00007f56f8414000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
        Source: 6229.1.00007f56f8400000.00007f56f8414000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown
        Source: 6235.1.00007f56f8400000.00007f56f8414000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
        Source: 6235.1.00007f56f8400000.00007f56f8414000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown
        Source: 6345.1.00007f56f8400000.00007f56f8414000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
        Source: 6345.1.00007f56f8400000.00007f56f8414000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown
        Source: Process Memory Space: lpm941yTS7 PID: 6226, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
        Source: Process Memory Space: lpm941yTS7 PID: 6226, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown
        Source: Process Memory Space: lpm941yTS7 PID: 6228, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
        Source: Process Memory Space: lpm941yTS7 PID: 6228, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown
        Source: Process Memory Space: lpm941yTS7 PID: 6229, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
        Source: Process Memory Space: lpm941yTS7 PID: 6229, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown
        Source: Process Memory Space: lpm941yTS7 PID: 6328, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
        Source: Process Memory Space: lpm941yTS7 PID: 6328, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown
        Source: Process Memory Space: lpm941yTS7 PID: 6329, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
        Source: Process Memory Space: lpm941yTS7 PID: 6329, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown
        Source: Process Memory Space: lpm941yTS7 PID: 6337, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
        Source: LOAD without section mappingsProgram segment: 0x100000
        Source: 6329.1.00007f56f8400000.00007f56f8414000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
        Source: 6329.1.00007f56f8400000.00007f56f8414000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16
        Source: 6228.1.00007f56f8400000.00007f56f8414000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
        Source: 6228.1.00007f56f8400000.00007f56f8414000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16
        Source: 6328.1.00007f56f8400000.00007f56f8414000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
        Source: 6328.1.00007f56f8400000.00007f56f8414000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16
        Source: 6226.1.00007f56f8400000.00007f56f8414000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
        Source: 6226.1.00007f56f8400000.00007f56f8414000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16
        Source: 6337.1.00007f56f8400000.00007f56f8414000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
        Source: 6337.1.00007f56f8400000.00007f56f8414000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16
        Source: 6229.1.00007f56f8400000.00007f56f8414000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
        Source: 6229.1.00007f56f8400000.00007f56f8414000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16
        Source: 6235.1.00007f56f8400000.00007f56f8414000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
        Source: 6235.1.00007f56f8400000.00007f56f8414000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16
        Source: 6345.1.00007f56f8400000.00007f56f8414000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
        Source: 6345.1.00007f56f8400000.00007f56f8414000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16
        Source: Process Memory Space: lpm941yTS7 PID: 6226, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
        Source: Process Memory Space: lpm941yTS7 PID: 6226, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16
        Source: Process Memory Space: lpm941yTS7 PID: 6228, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
        Source: Process Memory Space: lpm941yTS7 PID: 6228, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16
        Source: Process Memory Space: lpm941yTS7 PID: 6229, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
        Source: Process Memory Space: lpm941yTS7 PID: 6229, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16
        Source: Process Memory Space: lpm941yTS7 PID: 6328, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
        Source: Process Memory Space: lpm941yTS7 PID: 6328, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16
        Source: Process Memory Space: lpm941yTS7 PID: 6329, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
        Source: Process Memory Space: lpm941yTS7 PID: 6329, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16
        Source: Process Memory Space: lpm941yTS7 PID: 6337, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
        Source: /tmp/lpm941yTS7 (PID: 6228)SIGKILL sent: pid: 936, result: successful
        Source: /tmp/lpm941yTS7 (PID: 6234)SIGKILL sent: pid: 936, result: successful
        Source: classification engineClassification label: mal80.troj.evad.lin@0/0@0/0

        Data Obfuscation

        barindex
        Source: initial sampleString containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $
        Source: initial sampleString containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $
        Source: initial sampleString containing UPX found: $Id: UPX 3.94 Copyright (C) 1996-2017 the UPX Team. All Rights Reserved. $
        Source: /tmp/lpm941yTS7 (PID: 6234)File opened: /proc/491/fd
        Source: /tmp/lpm941yTS7 (PID: 6234)File opened: /proc/793/fd
        Source: /tmp/lpm941yTS7 (PID: 6234)File opened: /proc/772/fd
        Source: /tmp/lpm941yTS7 (PID: 6234)File opened: /proc/796/fd
        Source: /tmp/lpm941yTS7 (PID: 6234)File opened: /proc/774/fd
        Source: /tmp/lpm941yTS7 (PID: 6234)File opened: /proc/797/fd
        Source: /tmp/lpm941yTS7 (PID: 6234)File opened: /proc/777/fd
        Source: /tmp/lpm941yTS7 (PID: 6234)File opened: /proc/799/fd
        Source: /tmp/lpm941yTS7 (PID: 6234)File opened: /proc/658/fd
        Source: /tmp/lpm941yTS7 (PID: 6234)File opened: /proc/912/fd
        Source: /tmp/lpm941yTS7 (PID: 6234)File opened: /proc/759/fd
        Source: /tmp/lpm941yTS7 (PID: 6234)File opened: /proc/936/fd
        Source: /tmp/lpm941yTS7 (PID: 6234)File opened: /proc/918/fd
        Source: /tmp/lpm941yTS7 (PID: 6234)File opened: /proc/1/fd
        Source: /tmp/lpm941yTS7 (PID: 6234)File opened: /proc/761/fd
        Source: /tmp/lpm941yTS7 (PID: 6234)File opened: /proc/785/fd
        Source: /tmp/lpm941yTS7 (PID: 6234)File opened: /proc/884/fd
        Source: /tmp/lpm941yTS7 (PID: 6234)File opened: /proc/720/fd
        Source: /tmp/lpm941yTS7 (PID: 6234)File opened: /proc/721/fd
        Source: /tmp/lpm941yTS7 (PID: 6234)File opened: /proc/788/fd
        Source: /tmp/lpm941yTS7 (PID: 6234)File opened: /proc/789/fd
        Source: /tmp/lpm941yTS7 (PID: 6234)File opened: /proc/800/fd
        Source: /tmp/lpm941yTS7 (PID: 6234)File opened: /proc/801/fd
        Source: /tmp/lpm941yTS7 (PID: 6234)File opened: /proc/847/fd
        Source: /tmp/lpm941yTS7 (PID: 6234)File opened: /proc/904/fd
        Source: /tmp/lpm941yTS7 (PID: 6228)File opened: /proc/491/fd
        Source: /tmp/lpm941yTS7 (PID: 6228)File opened: /proc/793/fd
        Source: /tmp/lpm941yTS7 (PID: 6228)File opened: /proc/772/fd
        Source: /tmp/lpm941yTS7 (PID: 6228)File opened: /proc/796/fd
        Source: /tmp/lpm941yTS7 (PID: 6228)File opened: /proc/774/fd
        Source: /tmp/lpm941yTS7 (PID: 6228)File opened: /proc/797/fd
        Source: /tmp/lpm941yTS7 (PID: 6228)File opened: /proc/777/fd
        Source: /tmp/lpm941yTS7 (PID: 6228)File opened: /proc/799/fd
        Source: /tmp/lpm941yTS7 (PID: 6228)File opened: /proc/658/fd
        Source: /tmp/lpm941yTS7 (PID: 6228)File opened: /proc/912/fd
        Source: /tmp/lpm941yTS7 (PID: 6228)File opened: /proc/759/fd
        Source: /tmp/lpm941yTS7 (PID: 6228)File opened: /proc/936/fd
        Source: /tmp/lpm941yTS7 (PID: 6228)File opened: /proc/918/fd
        Source: /tmp/lpm941yTS7 (PID: 6228)File opened: /proc/1/fd
        Source: /tmp/lpm941yTS7 (PID: 6228)File opened: /proc/761/fd
        Source: /tmp/lpm941yTS7 (PID: 6228)File opened: /proc/785/fd
        Source: /tmp/lpm941yTS7 (PID: 6228)File opened: /proc/884/fd
        Source: /tmp/lpm941yTS7 (PID: 6228)File opened: /proc/720/fd
        Source: /tmp/lpm941yTS7 (PID: 6228)File opened: /proc/721/fd
        Source: /tmp/lpm941yTS7 (PID: 6228)File opened: /proc/788/fd
        Source: /tmp/lpm941yTS7 (PID: 6228)File opened: /proc/789/fd
        Source: /tmp/lpm941yTS7 (PID: 6228)File opened: /proc/800/fd
        Source: /tmp/lpm941yTS7 (PID: 6228)File opened: /proc/801/fd
        Source: /tmp/lpm941yTS7 (PID: 6228)File opened: /proc/847/fd
        Source: /tmp/lpm941yTS7 (PID: 6228)File opened: /proc/904/fd

        Hooking and other Techniques for Hiding and Protection

        barindex
        Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57720
        Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57736
        Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57746
        Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57758
        Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57774
        Source: lpm941yTS7Submission file: segment LOAD with 7.8921 entropy (max. 8.0)
        Source: /tmp/lpm941yTS7 (PID: 6226)Queries kernel information via 'uname':
        Source: lpm941yTS7, 6226.1.00007fffed760000.00007fffed781000.rw-.sdmp, lpm941yTS7, 6228.1.00007fffed760000.00007fffed781000.rw-.sdmp, lpm941yTS7, 6329.1.00007fffed760000.00007fffed781000.rw-.sdmp, lpm941yTS7, 6345.1.00007fffed760000.00007fffed781000.rw-.sdmp, lpm941yTS7, 6337.1.00007fffed760000.00007fffed781000.rw-.sdmp, lpm941yTS7, 6229.1.00007fffed760000.00007fffed781000.rw-.sdmp, lpm941yTS7, 6328.1.00007fffed760000.00007fffed781000.rw-.sdmp, lpm941yTS7, 6235.1.00007fffed760000.00007fffed781000.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-mips/tmp/lpm941yTS7SUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/lpm941yTS7
        Source: lpm941yTS7, 6226.1.000055dea86e6000.000055dea876d000.rw-.sdmp, lpm941yTS7, 6228.1.000055dea86e6000.000055dea876d000.rw-.sdmp, lpm941yTS7, 6329.1.000055dea86e6000.000055dea876d000.rw-.sdmp, lpm941yTS7, 6345.1.000055dea86e6000.000055dea876d000.rw-.sdmp, lpm941yTS7, 6337.1.000055dea86e6000.000055dea876d000.rw-.sdmp, lpm941yTS7, 6229.1.000055dea86e6000.000055dea876d000.rw-.sdmp, lpm941yTS7, 6328.1.000055dea86e6000.000055dea876d000.rw-.sdmp, lpm941yTS7, 6235.1.000055dea86e6000.000055dea876d000.rw-.sdmpBinary or memory string: U!/etc/qemu-binfmt/mips
        Source: lpm941yTS7, 6226.1.000055dea86e6000.000055dea876d000.rw-.sdmp, lpm941yTS7, 6228.1.000055dea86e6000.000055dea876d000.rw-.sdmp, lpm941yTS7, 6329.1.000055dea86e6000.000055dea876d000.rw-.sdmp, lpm941yTS7, 6345.1.000055dea86e6000.000055dea876d000.rw-.sdmp, lpm941yTS7, 6337.1.000055dea86e6000.000055dea876d000.rw-.sdmp, lpm941yTS7, 6229.1.000055dea86e6000.000055dea876d000.rw-.sdmp, lpm941yTS7, 6328.1.000055dea86e6000.000055dea876d000.rw-.sdmp, lpm941yTS7, 6235.1.000055dea86e6000.000055dea876d000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/mips
        Source: lpm941yTS7, 6226.1.00007fffed760000.00007fffed781000.rw-.sdmp, lpm941yTS7, 6228.1.00007fffed760000.00007fffed781000.rw-.sdmp, lpm941yTS7, 6329.1.00007fffed760000.00007fffed781000.rw-.sdmp, lpm941yTS7, 6345.1.00007fffed760000.00007fffed781000.rw-.sdmp, lpm941yTS7, 6337.1.00007fffed760000.00007fffed781000.rw-.sdmp, lpm941yTS7, 6229.1.00007fffed760000.00007fffed781000.rw-.sdmp, lpm941yTS7, 6328.1.00007fffed760000.00007fffed781000.rw-.sdmp, lpm941yTS7, 6235.1.00007fffed760000.00007fffed781000.rw-.sdmpBinary or memory string: /usr/bin/qemu-mips

        Stealing of Sensitive Information

        barindex
        Source: Yara matchFile source: 6329.1.00007f56f8400000.00007f56f8414000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6228.1.00007f56f8400000.00007f56f8414000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6328.1.00007f56f8400000.00007f56f8414000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6226.1.00007f56f8400000.00007f56f8414000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6337.1.00007f56f8400000.00007f56f8414000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6229.1.00007f56f8400000.00007f56f8414000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6235.1.00007f56f8400000.00007f56f8414000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6345.1.00007f56f8400000.00007f56f8414000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: dump.pcap, type: PCAP

        Remote Access Functionality

        barindex
        Source: Yara matchFile source: 6329.1.00007f56f8400000.00007f56f8414000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6228.1.00007f56f8400000.00007f56f8414000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6328.1.00007f56f8400000.00007f56f8414000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6226.1.00007f56f8400000.00007f56f8414000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6337.1.00007f56f8400000.00007f56f8414000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6229.1.00007f56f8400000.00007f56f8414000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6235.1.00007f56f8400000.00007f56f8414000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6345.1.00007f56f8400000.00007f56f8414000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: dump.pcap, type: PCAP
        Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
        Valid AccountsWindows Management InstrumentationPath InterceptionPath Interception11
        Obfuscated Files or Information
        1
        OS Credential Dumping
        11
        Security Software Discovery
        Remote ServicesData from Local SystemExfiltration Over Other Network Medium1
        Encrypted Channel
        Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
        Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over Bluetooth11
        Non-Standard Port
        Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
        Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated Exfiltration1
        Application Layer Protocol
        Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
        No configs have been found
        Hide Legend

        Legend:

        • Process
        • Signature
        • Created File
        • DNS/IP Info
        • Is Dropped
        • Number of created Files
        • Is malicious
        • Internet
        behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 680637 Sample: lpm941yTS7 Startdate: 08/08/2022 Architecture: LINUX Score: 80 42 40.138.179.142 WINDSTREAMUS United States 2->42 44 159.1.39.156 WA-STATE-GOVUS United States 2->44 46 98 other IPs or domains 2->46 48 Malicious sample detected (through community Yara rule) 2->48 50 Multi AV Scanner detection for submitted file 2->50 52 Yara detected Mirai 2->52 54 2 other signatures 2->54 10 lpm941yTS7 2->10         started        signatures3 process4 process5 12 lpm941yTS7 10->12         started        14 lpm941yTS7 10->14         started        16 lpm941yTS7 10->16         started        process6 18 lpm941yTS7 12->18         started        20 lpm941yTS7 12->20         started        22 lpm941yTS7 14->22         started        24 lpm941yTS7 14->24         started        26 lpm941yTS7 14->26         started        process7 28 lpm941yTS7 18->28         started        30 lpm941yTS7 18->30         started        32 lpm941yTS7 18->32         started        34 lpm941yTS7 22->34         started        36 lpm941yTS7 22->36         started        process8 38 lpm941yTS7 28->38         started        40 lpm941yTS7 28->40         started       
        SourceDetectionScannerLabelLink
        lpm941yTS731%VirustotalBrowse
        No Antivirus matches
        No Antivirus matches
        No Antivirus matches
        No contacted domains info
        NameSourceMaliciousAntivirus DetectionReputation
        http://upx.sf.netlpm941yTS7false
          high
          • No. of IPs < 25%
          • 25% < No. of IPs < 50%
          • 50% < No. of IPs < 75%
          • 75% < No. of IPs
          IPDomainCountryFlagASNASN NameMalicious
          161.136.104.16
          unknownUnited States
          17311ECMC-BGPUSfalse
          65.1.40.142
          unknownUnited States
          16509AMAZON-02USfalse
          189.39.203.79
          unknownBrazil
          262669KONNETINFORMATICAEIRELI-EPPBRfalse
          206.168.101.180
          unknownUnited States
          21777MASSIVE-NETWORKSUSfalse
          200.54.58.160
          unknownChile
          16629CTCCORPSATELEFONICAEMPRESASCLfalse
          95.122.127.127
          unknownSpain
          3352TELEFONICA_DE_ESPANAESfalse
          247.76.132.121
          unknownReserved
          unknownunknownfalse
          245.13.115.95
          unknownReserved
          unknownunknownfalse
          222.212.148.244
          unknownChina
          4134CHINANET-BACKBONENo31Jin-rongStreetCNfalse
          81.119.247.66
          unknownItaly
          20746ASN-IDCTNOOMINCITfalse
          159.1.39.156
          unknownUnited States
          4193WA-STATE-GOVUSfalse
          244.152.15.37
          unknownReserved
          unknownunknownfalse
          180.201.226.243
          unknownChina
          4538ERX-CERNET-BKBChinaEducationandResearchNetworkCenterfalse
          75.152.119.197
          unknownCanada
          852ASN852CAfalse
          60.120.70.64
          unknownJapan17676GIGAINFRASoftbankBBCorpJPfalse
          83.197.144.194
          unknownFrance
          3215FranceTelecom-OrangeFRfalse
          218.2.241.218
          unknownChina
          4134CHINANET-BACKBONENo31Jin-rongStreetCNfalse
          190.229.106.190
          unknownArgentina
          7303TelecomArgentinaSAARfalse
          90.204.93.152
          unknownUnited Kingdom
          5607BSKYB-BROADBAND-ASGBfalse
          89.166.0.137
          unknownFinland
          16086DNAFIfalse
          152.186.220.34
          unknownUnited States
          701UUNETUSfalse
          24.218.235.19
          unknownUnited States
          7922COMCAST-7922USfalse
          1.215.11.168
          unknownKorea Republic of
          3786LGDACOMLGDACOMCorporationKRfalse
          198.54.236.99
          unknownUnited States
          19878MEDIMPACTUSfalse
          203.18.46.218
          unknownAustralia
          58980M5NETWORKS-AS-APM5NetworksAustraliaPTYLTDAUfalse
          44.161.29.189
          unknownUnited States
          7377UCSDUSfalse
          152.107.33.135
          unknownSouth Africa
          36994Vodacom-VBZAfalse
          189.101.229.36
          unknownBrazil
          28573CLAROSABRfalse
          209.135.157.127
          unknownUnited States
          6428CDMUSfalse
          60.41.1.157
          unknownJapan4713OCNNTTCommunicationsCorporationJPfalse
          181.40.129.219
          unknownParaguay
          23201TelecelSAPYfalse
          100.30.104.187
          unknownUnited States
          14618AMAZON-AESUSfalse
          12.157.74.215
          unknownUnited States
          54940BFS-49-54940USfalse
          92.123.156.134
          unknownEuropean Union
          16625AKAMAI-ASUSfalse
          125.76.82.37
          unknownChina
          4134CHINANET-BACKBONENo31Jin-rongStreetCNfalse
          154.28.148.131
          unknownUnited States
          174COGENT-174USfalse
          195.170.35.113
          unknownRussian Federation
          8395EAST-ASRUfalse
          135.248.251.92
          unknownUnited States
          10455LUCENT-CIOUSfalse
          40.138.179.142
          unknownUnited States
          7029WINDSTREAMUSfalse
          188.18.193.157
          unknownRussian Federation
          12389ROSTELECOM-ASRUfalse
          133.159.9.73
          unknownJapan2497IIJInternetInitiativeJapanIncJPfalse
          24.219.2.202
          unknownUnited States
          8092AMHUSfalse
          204.28.35.22
          unknownUnited States
          13325STOMIUSfalse
          109.142.52.113
          unknownBelgium
          5432PROXIMUS-ISP-ASBEfalse
          16.247.101.210
          unknownUnited States
          unknownunknownfalse
          179.150.209.225
          unknownBrazil
          26599TELEFONICABRASILSABRfalse
          62.19.114.206
          unknownItaly
          16232ASN-TIMServiceProviderITfalse
          165.112.152.191
          unknownUnited States
          3527NIH-NETUSfalse
          57.219.161.214
          unknownBelgium
          2686ATGS-MMD-ASUSfalse
          4.40.43.230
          unknownUnited States
          3356LEVEL3USfalse
          174.35.223.130
          unknownCanada
          22995BARR-XPLR-ASNCAfalse
          255.140.153.133
          unknownReserved
          unknownunknownfalse
          20.23.44.40
          unknownUnited States
          8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
          100.61.17.144
          unknownUnited States
          701UUNETUSfalse
          111.99.71.66
          unknownJapan2516KDDIKDDICORPORATIONJPfalse
          66.98.44.150
          unknownDominican Republic
          6400CompaniaDominicanadeTelefonosSADOfalse
          183.251.91.55
          unknownChina
          9808CMNET-GDGuangdongMobileCommunicationCoLtdCNfalse
          57.208.205.191
          unknownBelgium
          2686ATGS-MMD-ASUSfalse
          67.86.198.169
          unknownUnited States
          6128CABLE-NET-1USfalse
          170.73.237.218
          unknownUnited States
          16761FEDMOG-ASN-01USfalse
          186.137.104.2
          unknownArgentina
          10318TelecomArgentinaSAARfalse
          195.6.117.95
          unknownFrance
          3215FranceTelecom-OrangeFRfalse
          156.247.76.131
          unknownSeychelles
          54600PEGTECHINCUSfalse
          247.52.25.65
          unknownReserved
          unknownunknownfalse
          123.171.223.85
          unknownChina
          4809CHINATELECOM-CORE-WAN-CN2ChinaTelecomNextGenerationCarrfalse
          202.58.175.68
          unknownIndonesia
          24526BINUSBinaNusantaraUniversityIDfalse
          188.216.156.208
          unknownItaly
          30722VODAFONE-IT-ASNITfalse
          119.111.53.73
          unknownPhilippines
          9299IPG-AS-APPhilippineLongDistanceTelephoneCompanyPHfalse
          27.77.16.88
          unknownViet Nam
          7552VIETEL-AS-APViettelGroupVNfalse
          17.88.236.23
          unknownUnited States
          714APPLE-ENGINEERINGUSfalse
          63.132.44.153
          unknownUnited States
          3561CENTURYLINK-LEGACY-SAVVISUSfalse
          112.198.173.248
          unknownPhilippines
          132199GLOBE-MOBILE-5TH-GEN-ASGlobeTelecomIncPHfalse
          122.31.101.190
          unknownJapan4713OCNNTTCommunicationsCorporationJPfalse
          40.119.109.110
          unknownUnited States
          8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
          102.216.78.32
          unknownunknown
          36926CKL1-ASNKEfalse
          58.19.60.76
          unknownChina
          4837CHINA169-BACKBONECHINAUNICOMChina169BackboneCNfalse
          102.99.177.195
          unknownMorocco
          36925ASMediMAfalse
          32.39.52.250
          unknownUnited States
          2686ATGS-MMD-ASUSfalse
          114.154.139.151
          unknownJapan4713OCNNTTCommunicationsCorporationJPfalse
          89.141.144.182
          unknownSpain
          12430VODAFONE_ESESfalse
          73.101.23.224
          unknownUnited States
          7922COMCAST-7922USfalse
          54.140.144.79
          unknownUnited States
          14618AMAZON-AESUSfalse
          243.163.200.109
          unknownReserved
          unknownunknownfalse
          141.88.195.47
          unknownGermany
          48778IHK-NETDEfalse
          119.126.143.148
          unknownChina
          4134CHINANET-BACKBONENo31Jin-rongStreetCNfalse
          14.184.247.123
          unknownViet Nam
          45899VNPT-AS-VNVNPTCorpVNfalse
          76.176.102.102
          unknownUnited States
          20001TWC-20001-PACWESTUSfalse
          36.40.5.35
          unknownChina
          4134CHINANET-BACKBONENo31Jin-rongStreetCNfalse
          57.129.81.255
          unknownBelgium
          2686ATGS-MMD-ASUSfalse
          68.80.0.77
          unknownUnited States
          7922COMCAST-7922USfalse
          242.224.73.37
          unknownReserved
          unknownunknownfalse
          57.253.127.143
          unknownBelgium
          2686ATGS-MMD-ASUSfalse
          120.186.107.130
          unknownIndonesia
          4761INDOSAT-INP-APINDOSATInternetNetworkProviderIDfalse
          219.44.234.205
          unknownJapan17676GIGAINFRASoftbankBBCorpJPfalse
          99.187.244.142
          unknownUnited States
          7018ATT-INTERNET4USfalse
          241.4.106.88
          unknownReserved
          unknownunknownfalse
          40.39.119.169
          unknownUnited States
          4249LILLY-ASUSfalse
          40.240.246.178
          unknownUnited States
          4249LILLY-ASUSfalse
          98.226.129.162
          unknownUnited States
          7922COMCAST-7922USfalse
          185.248.70.79
          unknownNetherlands
          202374PREWESTNLfalse
          No context
          No context
          No context
          No context
          No context
          No created / dropped files found
          File type:ELF 32-bit MSB executable, MIPS, MIPS-I version 1 (SYSV), statically linked, stripped
          Entropy (8bit):7.888569870363595
          TrID:
          • ELF Executable and Linkable format (Linux) (4029/14) 50.16%
          • ELF Executable and Linkable format (generic) (4004/1) 49.84%
          File name:lpm941yTS7
          File size:28916
          MD5:3c35a776bd33e73772576d33cf8db7a9
          SHA1:2e8bfc20102b201eaf14227ac5abffea4ba73c7c
          SHA256:e68f58e09f39ec1c8b2f2bf4b90f626b0b0d4906194f37a37a677f3a3c4f3434
          SHA512:c44212a50db58007fcc8014db88bd400e4a8d8e5ecd3c8cebe1305bae9628019c3556b46a5efb6ffdd49d34f38d2406715419a67552a0bc04758aebae97e7e47
          SSDEEP:768:l4ylAtv6pqLZeZAk0rVUCrJgGlzDpbuR1Jo:eMBGZeykghVJui
          TLSH:A4D2C07C272E86AAEF6A41740FF10B0B29750F61F871A81B6616EC421B571B43C9BED1
          File Content Preview:.ELF......................\x...4.........4. ...(......................o...o...............Mp.EMp.EMp....................UPX!.d........M@..M@.......U.......?.E.h4...@b..) ..]....E..N....r.-...G.F..S.r).......)=........).G..A.l.Vg..s._[#w...=...WW..........

          ELF header

          Class:ELF32
          Data:2's complement, big endian
          Version:1 (current)
          Machine:MIPS R3000
          Version Number:0x1
          Type:EXEC (Executable file)
          OS/ABI:UNIX - System V
          ABI Version:0
          Entry Point Address:0x105c78
          Flags:0x1007
          ELF Header Size:52
          Program Header Offset:52
          Program Header Size:32
          Number of Program Headers:2
          Section Header Offset:0
          Section Header Size:40
          Number of Section Headers:0
          Header String Table Index:0
          TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
          LOAD0x00x1000000x1000000x6fbc0x6fbc7.89210x5R E0x10000
          LOAD0x4d700x454d700x454d700x00x00.00000x6RW 0x10000
          TimestampSource PortDest PortSource IPDest IP
          Aug 8, 2022 22:55:57.279284000 CEST4251680192.168.2.23109.202.202.202
          Aug 8, 2022 22:55:58.842984915 CEST356861312192.168.2.23208.67.106.33
          Aug 8, 2022 22:55:58.870109081 CEST131235686208.67.106.33192.168.2.23
          Aug 8, 2022 22:55:58.870176077 CEST356861312192.168.2.23208.67.106.33
          Aug 8, 2022 22:55:58.870803118 CEST356861312192.168.2.23208.67.106.33
          Aug 8, 2022 22:55:58.875574112 CEST1384123192.168.2.23190.132.191.225
          Aug 8, 2022 22:55:58.875618935 CEST1384123192.168.2.23105.206.81.225
          Aug 8, 2022 22:55:58.875665903 CEST1384123192.168.2.2359.131.106.236
          Aug 8, 2022 22:55:58.875672102 CEST1384123192.168.2.23120.17.200.140
          Aug 8, 2022 22:55:58.875766039 CEST1384123192.168.2.23107.43.55.13
          Aug 8, 2022 22:55:58.875793934 CEST1384123192.168.2.23146.218.36.127
          Aug 8, 2022 22:55:58.875843048 CEST1384123192.168.2.23182.32.164.121
          Aug 8, 2022 22:55:58.875847101 CEST1384123192.168.2.23191.73.229.109
          Aug 8, 2022 22:55:58.875870943 CEST1384123192.168.2.23171.82.255.115
          Aug 8, 2022 22:55:58.875897884 CEST1384123192.168.2.23186.126.13.19
          Aug 8, 2022 22:55:58.875917912 CEST1384123192.168.2.2364.18.157.129
          Aug 8, 2022 22:55:58.875929117 CEST1384123192.168.2.23193.178.53.130
          Aug 8, 2022 22:55:58.875936985 CEST1384123192.168.2.2341.74.121.189
          Aug 8, 2022 22:55:58.875962019 CEST1384123192.168.2.2392.76.124.129
          Aug 8, 2022 22:55:58.875968933 CEST1384123192.168.2.2359.251.207.45
          Aug 8, 2022 22:55:58.875984907 CEST1384123192.168.2.2323.10.143.10
          Aug 8, 2022 22:55:58.875991106 CEST1384123192.168.2.23177.112.72.195
          Aug 8, 2022 22:55:58.876032114 CEST1384123192.168.2.23174.200.206.218
          Aug 8, 2022 22:55:58.876516104 CEST1384123192.168.2.23159.149.10.84
          Aug 8, 2022 22:55:58.876562119 CEST1384123192.168.2.23172.67.128.144
          Aug 8, 2022 22:55:58.876571894 CEST1384123192.168.2.2368.154.44.159
          Aug 8, 2022 22:55:58.876576900 CEST1384123192.168.2.23112.164.104.255
          Aug 8, 2022 22:55:58.876615047 CEST1384123192.168.2.2332.64.207.128
          Aug 8, 2022 22:55:58.876646996 CEST1384123192.168.2.23125.185.40.96
          Aug 8, 2022 22:55:58.876647949 CEST1384123192.168.2.23121.136.179.41
          Aug 8, 2022 22:55:58.876655102 CEST1384123192.168.2.23183.223.48.119
          Aug 8, 2022 22:55:58.876668930 CEST1384123192.168.2.2359.47.18.233
          Aug 8, 2022 22:55:58.876682043 CEST1384123192.168.2.2368.30.7.249
          Aug 8, 2022 22:55:58.876701117 CEST1384123192.168.2.23202.31.236.205
          Aug 8, 2022 22:55:58.876705885 CEST1384123192.168.2.2372.15.69.180
          Aug 8, 2022 22:55:58.876718044 CEST1384123192.168.2.23222.0.122.91
          Aug 8, 2022 22:55:58.876750946 CEST1384123192.168.2.23103.2.74.0
          Aug 8, 2022 22:55:58.876771927 CEST1384123192.168.2.2344.78.5.86
          Aug 8, 2022 22:55:58.876811028 CEST1384123192.168.2.23145.195.146.193
          Aug 8, 2022 22:55:58.876828909 CEST1384123192.168.2.23118.133.189.102
          Aug 8, 2022 22:55:58.876830101 CEST1384123192.168.2.2337.134.15.67
          Aug 8, 2022 22:55:58.876831055 CEST1384123192.168.2.2392.237.140.188
          Aug 8, 2022 22:55:58.876835108 CEST1384123192.168.2.23109.192.112.130
          Aug 8, 2022 22:55:58.876893044 CEST1384123192.168.2.23198.139.69.177
          Aug 8, 2022 22:55:58.876915932 CEST1384123192.168.2.23209.237.221.172
          Aug 8, 2022 22:55:58.876959085 CEST1384123192.168.2.23201.96.51.248
          Aug 8, 2022 22:55:58.876960993 CEST1384123192.168.2.231.103.126.187
          Aug 8, 2022 22:55:58.876974106 CEST1384123192.168.2.2376.216.183.44
          Aug 8, 2022 22:55:58.876981974 CEST1384123192.168.2.23250.62.192.150
          Aug 8, 2022 22:55:58.876986980 CEST1384123192.168.2.23210.133.132.193
          Aug 8, 2022 22:55:58.876987934 CEST1384123192.168.2.23166.149.207.233
          Aug 8, 2022 22:55:58.877002001 CEST1384123192.168.2.2317.111.27.56
          Aug 8, 2022 22:55:58.877013922 CEST1384123192.168.2.23142.74.134.97
          Aug 8, 2022 22:55:58.877042055 CEST1384123192.168.2.23135.36.125.104
          Aug 8, 2022 22:55:58.877078056 CEST1384123192.168.2.23212.228.46.143
          Aug 8, 2022 22:55:58.877090931 CEST1384123192.168.2.2319.49.243.72
          Aug 8, 2022 22:55:58.877126932 CEST1384123192.168.2.23168.79.22.11
          Aug 8, 2022 22:55:58.877149105 CEST1384123192.168.2.23156.164.72.113
          Aug 8, 2022 22:55:58.877196074 CEST1384123192.168.2.23136.49.65.146
          Aug 8, 2022 22:55:58.877224922 CEST1384123192.168.2.23176.78.89.21
          Aug 8, 2022 22:55:58.877249002 CEST1384123192.168.2.23152.77.175.63
          Aug 8, 2022 22:55:58.877259016 CEST1384123192.168.2.23203.155.101.202
          Aug 8, 2022 22:55:58.877293110 CEST1384123192.168.2.2366.27.94.228
          Aug 8, 2022 22:55:58.877311945 CEST1384123192.168.2.23211.122.235.164
          Aug 8, 2022 22:55:58.877325058 CEST1384123192.168.2.23161.11.203.211
          Aug 8, 2022 22:55:58.877338886 CEST1384123192.168.2.2361.74.25.222
          Aug 8, 2022 22:55:58.877357960 CEST1384123192.168.2.23108.227.164.78
          Aug 8, 2022 22:55:58.877376080 CEST1384123192.168.2.2388.109.87.167
          Aug 8, 2022 22:55:58.877377033 CEST1384123192.168.2.23176.60.69.192
          Aug 8, 2022 22:55:58.877383947 CEST1384123192.168.2.23120.92.212.251
          Aug 8, 2022 22:55:58.877392054 CEST1384123192.168.2.23146.201.77.235
          Aug 8, 2022 22:55:58.877393961 CEST1384123192.168.2.23251.3.74.63
          Aug 8, 2022 22:55:58.877396107 CEST1384123192.168.2.23175.150.13.51
          Aug 8, 2022 22:55:58.877404928 CEST1384123192.168.2.23217.143.222.90
          Aug 8, 2022 22:55:58.877414942 CEST1384123192.168.2.23190.220.112.152
          Aug 8, 2022 22:55:58.877424002 CEST1384123192.168.2.2339.236.57.59
          Aug 8, 2022 22:55:58.877424002 CEST1384123192.168.2.2381.36.11.180
          Aug 8, 2022 22:55:58.877455950 CEST1384123192.168.2.2346.44.15.74
          Aug 8, 2022 22:55:58.877475023 CEST1384123192.168.2.2375.91.0.255
          Aug 8, 2022 22:55:58.877475977 CEST1384123192.168.2.2324.147.206.111
          Aug 8, 2022 22:55:58.877517939 CEST1384123192.168.2.23217.252.227.207
          Aug 8, 2022 22:55:58.877521038 CEST1384123192.168.2.23178.232.72.37
          Aug 8, 2022 22:55:58.877541065 CEST1384123192.168.2.2376.89.69.132
          Aug 8, 2022 22:55:58.877552032 CEST1384123192.168.2.23206.122.84.190
          Aug 8, 2022 22:55:58.877557993 CEST1384123192.168.2.23159.69.101.189
          Aug 8, 2022 22:55:58.877567053 CEST1384123192.168.2.23125.190.223.99
          Aug 8, 2022 22:55:58.877625942 CEST1384123192.168.2.23193.83.98.148
          Aug 8, 2022 22:55:58.877641916 CEST1384123192.168.2.23180.104.139.124
          Aug 8, 2022 22:55:58.877644062 CEST1384123192.168.2.2387.214.27.17
          Aug 8, 2022 22:55:58.877649069 CEST1384123192.168.2.23113.84.151.28
          Aug 8, 2022 22:55:58.877655029 CEST1384123192.168.2.23191.152.148.66
          Aug 8, 2022 22:55:58.877659082 CEST1384123192.168.2.2317.112.23.45
          Aug 8, 2022 22:55:58.877696991 CEST1384123192.168.2.2386.197.21.28
          Aug 8, 2022 22:55:58.877697945 CEST1384123192.168.2.23170.22.81.229
          Aug 8, 2022 22:55:58.877716064 CEST1384123192.168.2.23245.190.205.186
          Aug 8, 2022 22:55:58.877716064 CEST1384123192.168.2.2312.212.93.39
          Aug 8, 2022 22:55:58.877736092 CEST1384123192.168.2.23200.18.81.255
          Aug 8, 2022 22:55:58.877752066 CEST1384123192.168.2.2393.192.165.223
          Aug 8, 2022 22:55:58.877753973 CEST1384123192.168.2.2338.5.235.251
          Aug 8, 2022 22:55:58.877784014 CEST1384123192.168.2.2334.162.195.87

          System Behavior

          Start time:22:55:57
          Start date:08/08/2022
          Path:/tmp/lpm941yTS7
          Arguments:/tmp/lpm941yTS7
          File size:5777432 bytes
          MD5 hash:0083f1f0e77be34ad27f849842bbb00c
          Start time:22:55:58
          Start date:08/08/2022
          Path:/tmp/lpm941yTS7
          Arguments:n/a
          File size:5777432 bytes
          MD5 hash:0083f1f0e77be34ad27f849842bbb00c
          Start time:22:58:51
          Start date:08/08/2022
          Path:/tmp/lpm941yTS7
          Arguments:n/a
          File size:5777432 bytes
          MD5 hash:0083f1f0e77be34ad27f849842bbb00c
          Start time:22:58:51
          Start date:08/08/2022
          Path:/tmp/lpm941yTS7
          Arguments:n/a
          File size:5777432 bytes
          MD5 hash:0083f1f0e77be34ad27f849842bbb00c
          Start time:22:58:51
          Start date:08/08/2022
          Path:/tmp/lpm941yTS7
          Arguments:n/a
          File size:5777432 bytes
          MD5 hash:0083f1f0e77be34ad27f849842bbb00c
          Start time:22:58:56
          Start date:08/08/2022
          Path:/tmp/lpm941yTS7
          Arguments:n/a
          File size:5777432 bytes
          MD5 hash:0083f1f0e77be34ad27f849842bbb00c
          Start time:22:58:56
          Start date:08/08/2022
          Path:/tmp/lpm941yTS7
          Arguments:n/a
          File size:5777432 bytes
          MD5 hash:0083f1f0e77be34ad27f849842bbb00c
          Start time:22:58:51
          Start date:08/08/2022
          Path:/tmp/lpm941yTS7
          Arguments:n/a
          File size:5777432 bytes
          MD5 hash:0083f1f0e77be34ad27f849842bbb00c
          Start time:22:58:51
          Start date:08/08/2022
          Path:/tmp/lpm941yTS7
          Arguments:n/a
          File size:5777432 bytes
          MD5 hash:0083f1f0e77be34ad27f849842bbb00c
          Start time:22:55:58
          Start date:08/08/2022
          Path:/tmp/lpm941yTS7
          Arguments:n/a
          File size:5777432 bytes
          MD5 hash:0083f1f0e77be34ad27f849842bbb00c
          Start time:22:55:58
          Start date:08/08/2022
          Path:/tmp/lpm941yTS7
          Arguments:n/a
          File size:5777432 bytes
          MD5 hash:0083f1f0e77be34ad27f849842bbb00c
          Start time:22:55:58
          Start date:08/08/2022
          Path:/tmp/lpm941yTS7
          Arguments:n/a
          File size:5777432 bytes
          MD5 hash:0083f1f0e77be34ad27f849842bbb00c
          Start time:22:58:51
          Start date:08/08/2022
          Path:/tmp/lpm941yTS7
          Arguments:n/a
          File size:5777432 bytes
          MD5 hash:0083f1f0e77be34ad27f849842bbb00c
          Start time:22:58:51
          Start date:08/08/2022
          Path:/tmp/lpm941yTS7
          Arguments:n/a
          File size:5777432 bytes
          MD5 hash:0083f1f0e77be34ad27f849842bbb00c
          Start time:22:55:58
          Start date:08/08/2022
          Path:/tmp/lpm941yTS7
          Arguments:n/a
          File size:5777432 bytes
          MD5 hash:0083f1f0e77be34ad27f849842bbb00c
          Start time:22:55:58
          Start date:08/08/2022
          Path:/tmp/lpm941yTS7
          Arguments:n/a
          File size:5777432 bytes
          MD5 hash:0083f1f0e77be34ad27f849842bbb00c