Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
wsskM49eA3.elf

Overview

General Information

Sample name:wsskM49eA3.elf
renamed because original name is a hash value
Original sample name:59ccf2f294605b86339ca5d4015c0016.elf
Analysis ID:1429578
MD5:59ccf2f294605b86339ca5d4015c0016
SHA1:0be2e5dddcc1f3e4b28a723e816c1a48abe74970
SHA256:96adadcb024a8a4e1a6d26d5d61b596ac07fcfff9217eea1b5d8bc61ac137e48
Tags:32elfintelmirai
Infos:

Detection

Score:64
Range:0 - 100
Whitelisted:false

Signatures

Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Connects to many ports of the same IP (likely port scanning)
Machine Learning detection for sample
Detected TCP or UDP traffic on non-standard ports
Enumerates processes within the "proc" file system
Found strings indicative of a multi-platform dropper
Sample contains strings indicative of BusyBox which embeds multiple Unix commands in a single executable
Sample has stripped symbol table
Sample tries to kill a process (SIGKILL)
Yara signature match

Classification

Joe Sandbox version:40.0.0 Tourmaline
Analysis ID:1429578
Start date and time:2024-04-22 12:15:14 +02:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 5m 18s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:wsskM49eA3.elf
renamed because original name is a hash value
Original Sample Name:59ccf2f294605b86339ca5d4015c0016.elf
Detection:MAL
Classification:mal64.troj.linELF@0/0@2/0
Command:/tmp/wsskM49eA3.elf
PID:5603
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
done.
Standard Error:
  • system is lnxubuntu20
  • cleanup
SourceRuleDescriptionAuthorStrings
wsskM49eA3.elfLinux_Trojan_Mirai_b14f4c5dunknownunknown
  • 0x4810:$a: 53 31 DB 8B 4C 24 0C 8B 54 24 08 83 F9 01 76 15 66 8B 02 83 E9 02 25 FF FF 00 00 83 C2 02 01 C3 83 F9 01 77 EB 49 75 05 0F BE 02 01 C3
wsskM49eA3.elfLinux_Trojan_Mirai_0bce98a2unknownunknown
  • 0x1041b:$a: 4B 52 41 00 46 47 44 43 57 4E 56 00 48 57 43 4C 56 47 41 4A
wsskM49eA3.elfLinux_Trojan_Mirai_95e0056cunknownunknown
  • 0x1044b:$a: 50 46 00 13 10 11 16 17 00 57 51 47 50 00 52 43 51 51 00 43
wsskM49eA3.elfLinux_Trojan_Mirai_389ee3e9unknownunknown
  • 0xc11c:$a: 89 45 00 EB 2C 8B 4B 04 8B 13 8B 7B 18 8B 01 01 02 8B 02 83
wsskM49eA3.elfLinux_Trojan_Mirai_cc93863bunknownunknown
  • 0xa856:$a: C3 57 8B 44 24 0C 8B 4C 24 10 8B 7C 24 08 F3 AA 8B 44 24 08
Click to see the 1 entries
SourceRuleDescriptionAuthorStrings
5606.1.0000000008048000.000000000805a000.r-x.sdmpLinux_Trojan_Mirai_b14f4c5dunknownunknown
  • 0x4810:$a: 53 31 DB 8B 4C 24 0C 8B 54 24 08 83 F9 01 76 15 66 8B 02 83 E9 02 25 FF FF 00 00 83 C2 02 01 C3 83 F9 01 77 EB 49 75 05 0F BE 02 01 C3
5606.1.0000000008048000.000000000805a000.r-x.sdmpLinux_Trojan_Mirai_0bce98a2unknownunknown
  • 0x1041b:$a: 4B 52 41 00 46 47 44 43 57 4E 56 00 48 57 43 4C 56 47 41 4A
5606.1.0000000008048000.000000000805a000.r-x.sdmpLinux_Trojan_Mirai_95e0056cunknownunknown
  • 0x1044b:$a: 50 46 00 13 10 11 16 17 00 57 51 47 50 00 52 43 51 51 00 43
5606.1.0000000008048000.000000000805a000.r-x.sdmpLinux_Trojan_Mirai_389ee3e9unknownunknown
  • 0xc11c:$a: 89 45 00 EB 2C 8B 4B 04 8B 13 8B 7B 18 8B 01 01 02 8B 02 83
5606.1.0000000008048000.000000000805a000.r-x.sdmpLinux_Trojan_Mirai_cc93863bunknownunknown
  • 0xa856:$a: C3 57 8B 44 24 0C 8B 4C 24 10 8B 7C 24 08 F3 AA 8B 44 24 08
Click to see the 31 entries
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: wsskM49eA3.elfVirustotal: Detection: 35%Perma Link
Source: wsskM49eA3.elfReversingLabs: Detection: 42%
Source: wsskM49eA3.elfJoe Sandbox ML: detected
Source: wsskM49eA3.elfString: 2surf2/proc/self/exebash /proc/%s/exe/wget/tftp/curlsocket/bin/busybox/usr/lib/systemd/systemd/opt/app/monitorusr/mnt/sys/boot/run/media/srv/etc/dev/telnetsshsshdbashhttpdtelnetddropbearencodersystem/z/secom//usr/sbin//usr/lib//var/tmp/wlanconthyd.archyd.x86_64hyd.x86hyd.i686hyd.mpslhyd.mipshyd.armhyd.arm4hyd.arm5hyd.arm6hyd.arm7hyd.ppchyd.spchyd.m68khyd.sh4hyd.xtensahyd.nios2hyd.aarch64hyd.microblazeel/usr/libexec/openssh/sftp-server/proc/proc/%d/cmdlinenetstat/proc/%s/cmdline.//proc//proc/%d/mapssystemd /var/run/mnt/root/var/tmp/boot/.(deleted)/home/proc/net/tcp%*s %08X127.0.0.1Killing process %d

Networking

barindex
Source: global trafficTCP traffic: 91.228.147.116 ports 0,3,5,6,7,56730
Source: global trafficTCP traffic: 192.168.2.15:36252 -> 91.228.147.116:56730
Source: unknownTCP traffic detected without corresponding DNS query: 97.251.9.249
Source: unknownTCP traffic detected without corresponding DNS query: 103.135.76.58
Source: unknownTCP traffic detected without corresponding DNS query: 159.217.245.248
Source: unknownTCP traffic detected without corresponding DNS query: 179.117.82.71
Source: unknownTCP traffic detected without corresponding DNS query: 159.220.251.45
Source: unknownTCP traffic detected without corresponding DNS query: 162.191.236.117
Source: unknownTCP traffic detected without corresponding DNS query: 107.205.226.241
Source: unknownTCP traffic detected without corresponding DNS query: 166.221.27.101
Source: unknownTCP traffic detected without corresponding DNS query: 183.173.5.20
Source: unknownTCP traffic detected without corresponding DNS query: 73.84.183.160
Source: unknownTCP traffic detected without corresponding DNS query: 61.162.171.15
Source: unknownTCP traffic detected without corresponding DNS query: 126.63.63.238
Source: unknownTCP traffic detected without corresponding DNS query: 222.14.143.131
Source: unknownTCP traffic detected without corresponding DNS query: 178.50.246.233
Source: unknownTCP traffic detected without corresponding DNS query: 17.124.138.124
Source: unknownTCP traffic detected without corresponding DNS query: 178.226.2.38
Source: unknownTCP traffic detected without corresponding DNS query: 60.223.118.87
Source: unknownTCP traffic detected without corresponding DNS query: 109.89.63.123
Source: unknownTCP traffic detected without corresponding DNS query: 34.122.151.145
Source: unknownTCP traffic detected without corresponding DNS query: 167.121.200.224
Source: unknownTCP traffic detected without corresponding DNS query: 52.212.0.193
Source: unknownTCP traffic detected without corresponding DNS query: 141.93.205.36
Source: unknownTCP traffic detected without corresponding DNS query: 170.20.88.207
Source: unknownTCP traffic detected without corresponding DNS query: 184.39.22.82
Source: unknownTCP traffic detected without corresponding DNS query: 161.224.18.189
Source: unknownTCP traffic detected without corresponding DNS query: 183.45.75.132
Source: unknownTCP traffic detected without corresponding DNS query: 70.237.113.142
Source: unknownTCP traffic detected without corresponding DNS query: 85.161.194.88
Source: unknownTCP traffic detected without corresponding DNS query: 186.234.142.202
Source: unknownTCP traffic detected without corresponding DNS query: 147.230.111.243
Source: unknownTCP traffic detected without corresponding DNS query: 217.199.83.165
Source: unknownTCP traffic detected without corresponding DNS query: 159.138.131.51
Source: unknownTCP traffic detected without corresponding DNS query: 183.247.58.60
Source: unknownTCP traffic detected without corresponding DNS query: 93.77.43.78
Source: unknownTCP traffic detected without corresponding DNS query: 95.118.106.84
Source: unknownTCP traffic detected without corresponding DNS query: 120.30.90.211
Source: unknownTCP traffic detected without corresponding DNS query: 66.235.160.232
Source: unknownTCP traffic detected without corresponding DNS query: 142.177.79.17
Source: unknownTCP traffic detected without corresponding DNS query: 108.137.148.239
Source: unknownTCP traffic detected without corresponding DNS query: 182.43.70.114
Source: unknownTCP traffic detected without corresponding DNS query: 221.82.155.108
Source: unknownTCP traffic detected without corresponding DNS query: 60.123.132.147
Source: unknownTCP traffic detected without corresponding DNS query: 139.150.227.124
Source: unknownTCP traffic detected without corresponding DNS query: 79.252.4.99
Source: unknownTCP traffic detected without corresponding DNS query: 84.11.52.65
Source: unknownTCP traffic detected without corresponding DNS query: 111.65.61.217
Source: unknownTCP traffic detected without corresponding DNS query: 63.232.218.248
Source: unknownTCP traffic detected without corresponding DNS query: 160.228.106.42
Source: unknownTCP traffic detected without corresponding DNS query: 132.157.234.252
Source: unknownTCP traffic detected without corresponding DNS query: 139.239.81.62
Source: unknownDNS traffic detected: queries for: daisy.ubuntu.com

System Summary

barindex
Source: wsskM49eA3.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_b14f4c5d Author: unknown
Source: wsskM49eA3.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_0bce98a2 Author: unknown
Source: wsskM49eA3.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_95e0056c Author: unknown
Source: wsskM49eA3.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_389ee3e9 Author: unknown
Source: wsskM49eA3.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_cc93863b Author: unknown
Source: wsskM49eA3.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_8aa7b5d3 Author: unknown
Source: 5606.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_b14f4c5d Author: unknown
Source: 5606.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_0bce98a2 Author: unknown
Source: 5606.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_95e0056c Author: unknown
Source: 5606.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_389ee3e9 Author: unknown
Source: 5606.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_cc93863b Author: unknown
Source: 5606.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_8aa7b5d3 Author: unknown
Source: 5607.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_b14f4c5d Author: unknown
Source: 5607.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_0bce98a2 Author: unknown
Source: 5607.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_95e0056c Author: unknown
Source: 5607.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_389ee3e9 Author: unknown
Source: 5607.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_cc93863b Author: unknown
Source: 5607.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_8aa7b5d3 Author: unknown
Source: 5608.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_b14f4c5d Author: unknown
Source: 5608.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_0bce98a2 Author: unknown
Source: 5608.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_95e0056c Author: unknown
Source: 5608.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_389ee3e9 Author: unknown
Source: 5608.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_cc93863b Author: unknown
Source: 5608.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_8aa7b5d3 Author: unknown
Source: 5604.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_b14f4c5d Author: unknown
Source: 5604.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_0bce98a2 Author: unknown
Source: 5604.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_95e0056c Author: unknown
Source: 5604.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_389ee3e9 Author: unknown
Source: 5604.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_cc93863b Author: unknown
Source: 5604.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_8aa7b5d3 Author: unknown
Source: 5603.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_b14f4c5d Author: unknown
Source: 5603.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_0bce98a2 Author: unknown
Source: 5603.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_95e0056c Author: unknown
Source: 5603.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_389ee3e9 Author: unknown
Source: 5603.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_cc93863b Author: unknown
Source: 5603.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_8aa7b5d3 Author: unknown
Source: 5609.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_b14f4c5d Author: unknown
Source: 5609.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_0bce98a2 Author: unknown
Source: 5609.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_95e0056c Author: unknown
Source: 5609.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_389ee3e9 Author: unknown
Source: 5609.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_cc93863b Author: unknown
Source: 5609.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_8aa7b5d3 Author: unknown
Source: Initial sampleString containing 'busybox' found: /bin/busybox
Source: Initial sampleString containing 'busybox' found: 2surf2/proc/self/exebash /proc/%s/exe/wget/tftp/curlsocket/bin/busybox/usr/lib/systemd/systemd/opt/app/monitorusr/mnt/sys/boot/run/media/srv/etc/dev/telnetsshsshdbashhttpdtelnetddropbearencodersystem/z/secom//usr/sbin//usr/lib//var/tmp/wlanconthyd.archyd.x86_64hyd.x86hyd.i686hyd.mpslhyd.mipshyd.armhyd.arm4hyd.arm5hyd.arm6hyd.arm7hyd.ppchyd.spchyd.m68khyd.sh4hyd.xtensahyd.nios2hyd.aarch64hyd.microblazeel/usr/libexec/openssh/sftp-server/proc/proc/%d/cmdlinenetstat/proc/%s/cmdline.//proc//proc/%d/mapssystemd /var/run/mnt/root/var/tmp/boot/.(deleted)/home/proc/net/tcp%*s %08X127.0.0.1Killing process %d
Source: ELF static info symbol of initial sample.symtab present: no
Source: /tmp/wsskM49eA3.elf (PID: 5605)SIGKILL sent: pid: 5604, result: successfulJump to behavior
Source: /tmp/wsskM49eA3.elf (PID: 5605)SIGKILL sent: pid: 5606, result: successfulJump to behavior
Source: /tmp/wsskM49eA3.elf (PID: 5605)SIGKILL sent: pid: 5607, result: successfulJump to behavior
Source: /tmp/wsskM49eA3.elf (PID: 5605)SIGKILL sent: pid: 5608, result: successfulJump to behavior
Source: /tmp/wsskM49eA3.elf (PID: 5605)SIGKILL sent: pid: 5609, result: successfulJump to behavior
Source: wsskM49eA3.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_b14f4c5d os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = a70d052918dd2fbc66db241da6438015130f0fb6929229bfe573546fe98da817, id = b14f4c5d-054f-46e6-9fa8-3588f1ef68b7, last_modified = 2021-09-16
Source: wsskM49eA3.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_0bce98a2 reference_sample = 1b20df8df7f84ad29d81ccbe276f49a6488c2214077b13da858656c027531c80, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 993d0d2e24152d0fb72cc5d5add395bed26671c3935f73386341398b91cb0e6e, id = 0bce98a2-113e-41e1-95c9-9e1852b26142, last_modified = 2021-09-16
Source: wsskM49eA3.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_95e0056c reference_sample = 45f67d4c18abc1bad9a9cc6305983abf3234cd955d2177f1a72c146ced50a380, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = a2550fdd2625f85050cfe53159858207a79e8337412872aaa7b4627b13cb6c94, id = 95e0056c-bc07-42cf-89ab-6c0cde3ccc8a, last_modified = 2021-09-16
Source: wsskM49eA3.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_389ee3e9 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 59f2359dc1f41d385d639d157b4cd9fc73d76d8abb7cc09d47632bb4c9a39e6e, id = 389ee3e9-70c1-4c93-a999-292cf6ff1652, last_modified = 2022-01-26
Source: wsskM49eA3.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_cc93863b reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = f3ecd30f0b511a8e92cfa642409d559e7612c3f57a1659ca46c77aca809a00ac, id = cc93863b-1050-40ba-9d02-5ec9ce6a3a28, last_modified = 2022-01-26
Source: wsskM49eA3.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_8aa7b5d3 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 02a2c18c362df4b1fceb33f3b605586514ba9a00c7afedf71c04fa54d8146444, id = 8aa7b5d3-e1eb-4b55-b36a-0d3a242c06e9, last_modified = 2022-01-26
Source: 5606.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_b14f4c5d os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = a70d052918dd2fbc66db241da6438015130f0fb6929229bfe573546fe98da817, id = b14f4c5d-054f-46e6-9fa8-3588f1ef68b7, last_modified = 2021-09-16
Source: 5606.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_0bce98a2 reference_sample = 1b20df8df7f84ad29d81ccbe276f49a6488c2214077b13da858656c027531c80, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 993d0d2e24152d0fb72cc5d5add395bed26671c3935f73386341398b91cb0e6e, id = 0bce98a2-113e-41e1-95c9-9e1852b26142, last_modified = 2021-09-16
Source: 5606.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_95e0056c reference_sample = 45f67d4c18abc1bad9a9cc6305983abf3234cd955d2177f1a72c146ced50a380, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = a2550fdd2625f85050cfe53159858207a79e8337412872aaa7b4627b13cb6c94, id = 95e0056c-bc07-42cf-89ab-6c0cde3ccc8a, last_modified = 2021-09-16
Source: 5606.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_389ee3e9 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 59f2359dc1f41d385d639d157b4cd9fc73d76d8abb7cc09d47632bb4c9a39e6e, id = 389ee3e9-70c1-4c93-a999-292cf6ff1652, last_modified = 2022-01-26
Source: 5606.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_cc93863b reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = f3ecd30f0b511a8e92cfa642409d559e7612c3f57a1659ca46c77aca809a00ac, id = cc93863b-1050-40ba-9d02-5ec9ce6a3a28, last_modified = 2022-01-26
Source: 5606.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_8aa7b5d3 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 02a2c18c362df4b1fceb33f3b605586514ba9a00c7afedf71c04fa54d8146444, id = 8aa7b5d3-e1eb-4b55-b36a-0d3a242c06e9, last_modified = 2022-01-26
Source: 5607.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_b14f4c5d os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = a70d052918dd2fbc66db241da6438015130f0fb6929229bfe573546fe98da817, id = b14f4c5d-054f-46e6-9fa8-3588f1ef68b7, last_modified = 2021-09-16
Source: 5607.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_0bce98a2 reference_sample = 1b20df8df7f84ad29d81ccbe276f49a6488c2214077b13da858656c027531c80, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 993d0d2e24152d0fb72cc5d5add395bed26671c3935f73386341398b91cb0e6e, id = 0bce98a2-113e-41e1-95c9-9e1852b26142, last_modified = 2021-09-16
Source: 5607.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_95e0056c reference_sample = 45f67d4c18abc1bad9a9cc6305983abf3234cd955d2177f1a72c146ced50a380, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = a2550fdd2625f85050cfe53159858207a79e8337412872aaa7b4627b13cb6c94, id = 95e0056c-bc07-42cf-89ab-6c0cde3ccc8a, last_modified = 2021-09-16
Source: 5607.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_389ee3e9 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 59f2359dc1f41d385d639d157b4cd9fc73d76d8abb7cc09d47632bb4c9a39e6e, id = 389ee3e9-70c1-4c93-a999-292cf6ff1652, last_modified = 2022-01-26
Source: 5607.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_cc93863b reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = f3ecd30f0b511a8e92cfa642409d559e7612c3f57a1659ca46c77aca809a00ac, id = cc93863b-1050-40ba-9d02-5ec9ce6a3a28, last_modified = 2022-01-26
Source: 5607.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_8aa7b5d3 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 02a2c18c362df4b1fceb33f3b605586514ba9a00c7afedf71c04fa54d8146444, id = 8aa7b5d3-e1eb-4b55-b36a-0d3a242c06e9, last_modified = 2022-01-26
Source: 5608.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_b14f4c5d os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = a70d052918dd2fbc66db241da6438015130f0fb6929229bfe573546fe98da817, id = b14f4c5d-054f-46e6-9fa8-3588f1ef68b7, last_modified = 2021-09-16
Source: 5608.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_0bce98a2 reference_sample = 1b20df8df7f84ad29d81ccbe276f49a6488c2214077b13da858656c027531c80, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 993d0d2e24152d0fb72cc5d5add395bed26671c3935f73386341398b91cb0e6e, id = 0bce98a2-113e-41e1-95c9-9e1852b26142, last_modified = 2021-09-16
Source: 5608.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_95e0056c reference_sample = 45f67d4c18abc1bad9a9cc6305983abf3234cd955d2177f1a72c146ced50a380, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = a2550fdd2625f85050cfe53159858207a79e8337412872aaa7b4627b13cb6c94, id = 95e0056c-bc07-42cf-89ab-6c0cde3ccc8a, last_modified = 2021-09-16
Source: 5608.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_389ee3e9 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 59f2359dc1f41d385d639d157b4cd9fc73d76d8abb7cc09d47632bb4c9a39e6e, id = 389ee3e9-70c1-4c93-a999-292cf6ff1652, last_modified = 2022-01-26
Source: 5608.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_cc93863b reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = f3ecd30f0b511a8e92cfa642409d559e7612c3f57a1659ca46c77aca809a00ac, id = cc93863b-1050-40ba-9d02-5ec9ce6a3a28, last_modified = 2022-01-26
Source: 5608.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_8aa7b5d3 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 02a2c18c362df4b1fceb33f3b605586514ba9a00c7afedf71c04fa54d8146444, id = 8aa7b5d3-e1eb-4b55-b36a-0d3a242c06e9, last_modified = 2022-01-26
Source: 5604.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_b14f4c5d os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = a70d052918dd2fbc66db241da6438015130f0fb6929229bfe573546fe98da817, id = b14f4c5d-054f-46e6-9fa8-3588f1ef68b7, last_modified = 2021-09-16
Source: 5604.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_0bce98a2 reference_sample = 1b20df8df7f84ad29d81ccbe276f49a6488c2214077b13da858656c027531c80, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 993d0d2e24152d0fb72cc5d5add395bed26671c3935f73386341398b91cb0e6e, id = 0bce98a2-113e-41e1-95c9-9e1852b26142, last_modified = 2021-09-16
Source: 5604.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_95e0056c reference_sample = 45f67d4c18abc1bad9a9cc6305983abf3234cd955d2177f1a72c146ced50a380, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = a2550fdd2625f85050cfe53159858207a79e8337412872aaa7b4627b13cb6c94, id = 95e0056c-bc07-42cf-89ab-6c0cde3ccc8a, last_modified = 2021-09-16
Source: 5604.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_389ee3e9 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 59f2359dc1f41d385d639d157b4cd9fc73d76d8abb7cc09d47632bb4c9a39e6e, id = 389ee3e9-70c1-4c93-a999-292cf6ff1652, last_modified = 2022-01-26
Source: 5604.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_cc93863b reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = f3ecd30f0b511a8e92cfa642409d559e7612c3f57a1659ca46c77aca809a00ac, id = cc93863b-1050-40ba-9d02-5ec9ce6a3a28, last_modified = 2022-01-26
Source: 5604.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_8aa7b5d3 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 02a2c18c362df4b1fceb33f3b605586514ba9a00c7afedf71c04fa54d8146444, id = 8aa7b5d3-e1eb-4b55-b36a-0d3a242c06e9, last_modified = 2022-01-26
Source: 5603.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_b14f4c5d os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = a70d052918dd2fbc66db241da6438015130f0fb6929229bfe573546fe98da817, id = b14f4c5d-054f-46e6-9fa8-3588f1ef68b7, last_modified = 2021-09-16
Source: 5603.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_0bce98a2 reference_sample = 1b20df8df7f84ad29d81ccbe276f49a6488c2214077b13da858656c027531c80, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 993d0d2e24152d0fb72cc5d5add395bed26671c3935f73386341398b91cb0e6e, id = 0bce98a2-113e-41e1-95c9-9e1852b26142, last_modified = 2021-09-16
Source: 5603.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_95e0056c reference_sample = 45f67d4c18abc1bad9a9cc6305983abf3234cd955d2177f1a72c146ced50a380, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = a2550fdd2625f85050cfe53159858207a79e8337412872aaa7b4627b13cb6c94, id = 95e0056c-bc07-42cf-89ab-6c0cde3ccc8a, last_modified = 2021-09-16
Source: 5603.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_389ee3e9 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 59f2359dc1f41d385d639d157b4cd9fc73d76d8abb7cc09d47632bb4c9a39e6e, id = 389ee3e9-70c1-4c93-a999-292cf6ff1652, last_modified = 2022-01-26
Source: 5603.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_cc93863b reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = f3ecd30f0b511a8e92cfa642409d559e7612c3f57a1659ca46c77aca809a00ac, id = cc93863b-1050-40ba-9d02-5ec9ce6a3a28, last_modified = 2022-01-26
Source: 5603.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_8aa7b5d3 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 02a2c18c362df4b1fceb33f3b605586514ba9a00c7afedf71c04fa54d8146444, id = 8aa7b5d3-e1eb-4b55-b36a-0d3a242c06e9, last_modified = 2022-01-26
Source: 5609.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_b14f4c5d os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = a70d052918dd2fbc66db241da6438015130f0fb6929229bfe573546fe98da817, id = b14f4c5d-054f-46e6-9fa8-3588f1ef68b7, last_modified = 2021-09-16
Source: 5609.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_0bce98a2 reference_sample = 1b20df8df7f84ad29d81ccbe276f49a6488c2214077b13da858656c027531c80, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 993d0d2e24152d0fb72cc5d5add395bed26671c3935f73386341398b91cb0e6e, id = 0bce98a2-113e-41e1-95c9-9e1852b26142, last_modified = 2021-09-16
Source: 5609.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_95e0056c reference_sample = 45f67d4c18abc1bad9a9cc6305983abf3234cd955d2177f1a72c146ced50a380, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = a2550fdd2625f85050cfe53159858207a79e8337412872aaa7b4627b13cb6c94, id = 95e0056c-bc07-42cf-89ab-6c0cde3ccc8a, last_modified = 2021-09-16
Source: 5609.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_389ee3e9 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 59f2359dc1f41d385d639d157b4cd9fc73d76d8abb7cc09d47632bb4c9a39e6e, id = 389ee3e9-70c1-4c93-a999-292cf6ff1652, last_modified = 2022-01-26
Source: 5609.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_cc93863b reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = f3ecd30f0b511a8e92cfa642409d559e7612c3f57a1659ca46c77aca809a00ac, id = cc93863b-1050-40ba-9d02-5ec9ce6a3a28, last_modified = 2022-01-26
Source: 5609.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_8aa7b5d3 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 02a2c18c362df4b1fceb33f3b605586514ba9a00c7afedf71c04fa54d8146444, id = 8aa7b5d3-e1eb-4b55-b36a-0d3a242c06e9, last_modified = 2022-01-26
Source: classification engineClassification label: mal64.troj.linELF@0/0@2/0
Source: /tmp/wsskM49eA3.elf (PID: 5605)File opened: /proc/110/mapsJump to behavior
Source: /tmp/wsskM49eA3.elf (PID: 5605)File opened: /proc/110/cmdlineJump to behavior
Source: /tmp/wsskM49eA3.elf (PID: 5605)File opened: /proc/231/mapsJump to behavior
Source: /tmp/wsskM49eA3.elf (PID: 5605)File opened: /proc/231/cmdlineJump to behavior
Source: /tmp/wsskM49eA3.elf (PID: 5605)File opened: /proc/111/mapsJump to behavior
Source: /tmp/wsskM49eA3.elf (PID: 5605)File opened: /proc/111/cmdlineJump to behavior
Source: /tmp/wsskM49eA3.elf (PID: 5605)File opened: /proc/112/mapsJump to behavior
Source: /tmp/wsskM49eA3.elf (PID: 5605)File opened: /proc/112/cmdlineJump to behavior
Source: /tmp/wsskM49eA3.elf (PID: 5605)File opened: /proc/233/mapsJump to behavior
Source: /tmp/wsskM49eA3.elf (PID: 5605)File opened: /proc/233/cmdlineJump to behavior
Source: /tmp/wsskM49eA3.elf (PID: 5605)File opened: /proc/113/mapsJump to behavior
Source: /tmp/wsskM49eA3.elf (PID: 5605)File opened: /proc/113/cmdlineJump to behavior
Source: /tmp/wsskM49eA3.elf (PID: 5605)File opened: /proc/114/mapsJump to behavior
Source: /tmp/wsskM49eA3.elf (PID: 5605)File opened: /proc/114/cmdlineJump to behavior
Source: /tmp/wsskM49eA3.elf (PID: 5605)File opened: /proc/235/mapsJump to behavior
Source: /tmp/wsskM49eA3.elf (PID: 5605)File opened: /proc/235/cmdlineJump to behavior
Source: /tmp/wsskM49eA3.elf (PID: 5605)File opened: /proc/115/mapsJump to behavior
Source: /tmp/wsskM49eA3.elf (PID: 5605)File opened: /proc/115/cmdlineJump to behavior
Source: /tmp/wsskM49eA3.elf (PID: 5605)File opened: /proc/1333/mapsJump to behavior
Source: /tmp/wsskM49eA3.elf (PID: 5605)File opened: /proc/1333/cmdlineJump to behavior
Source: /tmp/wsskM49eA3.elf (PID: 5605)File opened: /proc/116/mapsJump to behavior
Source: /tmp/wsskM49eA3.elf (PID: 5605)File opened: /proc/116/cmdlineJump to behavior
Source: /tmp/wsskM49eA3.elf (PID: 5605)File opened: /proc/1695/mapsJump to behavior
Source: /tmp/wsskM49eA3.elf (PID: 5605)File opened: /proc/1695/cmdlineJump to behavior
Source: /tmp/wsskM49eA3.elf (PID: 5605)File opened: /proc/117/mapsJump to behavior
Source: /tmp/wsskM49eA3.elf (PID: 5605)File opened: /proc/117/cmdlineJump to behavior
Source: /tmp/wsskM49eA3.elf (PID: 5605)File opened: /proc/118/mapsJump to behavior
Source: /tmp/wsskM49eA3.elf (PID: 5605)File opened: /proc/118/cmdlineJump to behavior
Source: /tmp/wsskM49eA3.elf (PID: 5605)File opened: /proc/119/mapsJump to behavior
Source: /tmp/wsskM49eA3.elf (PID: 5605)File opened: /proc/119/cmdlineJump to behavior
Source: /tmp/wsskM49eA3.elf (PID: 5605)File opened: /proc/911/mapsJump to behavior
Source: /tmp/wsskM49eA3.elf (PID: 5605)File opened: /proc/911/cmdlineJump to behavior
Source: /tmp/wsskM49eA3.elf (PID: 5605)File opened: /proc/914/mapsJump to behavior
Source: /tmp/wsskM49eA3.elf (PID: 5605)File opened: /proc/914/cmdlineJump to behavior
Source: /tmp/wsskM49eA3.elf (PID: 5605)File opened: /proc/10/mapsJump to behavior
Source: /tmp/wsskM49eA3.elf (PID: 5605)File opened: /proc/10/cmdlineJump to behavior
Source: /tmp/wsskM49eA3.elf (PID: 5605)File opened: /proc/917/mapsJump to behavior
Source: /tmp/wsskM49eA3.elf (PID: 5605)File opened: /proc/917/cmdlineJump to behavior
Source: /tmp/wsskM49eA3.elf (PID: 5605)File opened: /proc/11/mapsJump to behavior
Source: /tmp/wsskM49eA3.elf (PID: 5605)File opened: /proc/11/cmdlineJump to behavior
Source: /tmp/wsskM49eA3.elf (PID: 5605)File opened: /proc/12/mapsJump to behavior
Source: /tmp/wsskM49eA3.elf (PID: 5605)File opened: /proc/12/cmdlineJump to behavior
Source: /tmp/wsskM49eA3.elf (PID: 5605)File opened: /proc/13/mapsJump to behavior
Source: /tmp/wsskM49eA3.elf (PID: 5605)File opened: /proc/13/cmdlineJump to behavior
Source: /tmp/wsskM49eA3.elf (PID: 5605)File opened: /proc/14/mapsJump to behavior
Source: /tmp/wsskM49eA3.elf (PID: 5605)File opened: /proc/14/cmdlineJump to behavior
Source: /tmp/wsskM49eA3.elf (PID: 5605)File opened: /proc/15/mapsJump to behavior
Source: /tmp/wsskM49eA3.elf (PID: 5605)File opened: /proc/15/cmdlineJump to behavior
Source: /tmp/wsskM49eA3.elf (PID: 5605)File opened: /proc/16/mapsJump to behavior
Source: /tmp/wsskM49eA3.elf (PID: 5605)File opened: /proc/16/cmdlineJump to behavior
Source: /tmp/wsskM49eA3.elf (PID: 5605)File opened: /proc/17/mapsJump to behavior
Source: /tmp/wsskM49eA3.elf (PID: 5605)File opened: /proc/17/cmdlineJump to behavior
Source: /tmp/wsskM49eA3.elf (PID: 5605)File opened: /proc/18/mapsJump to behavior
Source: /tmp/wsskM49eA3.elf (PID: 5605)File opened: /proc/18/cmdlineJump to behavior
Source: /tmp/wsskM49eA3.elf (PID: 5605)File opened: /proc/19/mapsJump to behavior
Source: /tmp/wsskM49eA3.elf (PID: 5605)File opened: /proc/19/cmdlineJump to behavior
Source: /tmp/wsskM49eA3.elf (PID: 5605)File opened: /proc/1591/mapsJump to behavior
Source: /tmp/wsskM49eA3.elf (PID: 5605)File opened: /proc/1591/cmdlineJump to behavior
Source: /tmp/wsskM49eA3.elf (PID: 5605)File opened: /proc/120/mapsJump to behavior
Source: /tmp/wsskM49eA3.elf (PID: 5605)File opened: /proc/120/cmdlineJump to behavior
Source: /tmp/wsskM49eA3.elf (PID: 5605)File opened: /proc/121/mapsJump to behavior
Source: /tmp/wsskM49eA3.elf (PID: 5605)File opened: /proc/121/cmdlineJump to behavior
Source: /tmp/wsskM49eA3.elf (PID: 5605)File opened: /proc/1/mapsJump to behavior
Source: /tmp/wsskM49eA3.elf (PID: 5605)File opened: /proc/1/cmdlineJump to behavior
Source: /tmp/wsskM49eA3.elf (PID: 5605)File opened: /proc/122/mapsJump to behavior
Source: /tmp/wsskM49eA3.elf (PID: 5605)File opened: /proc/122/cmdlineJump to behavior
Source: /tmp/wsskM49eA3.elf (PID: 5605)File opened: /proc/243/mapsJump to behavior
Source: /tmp/wsskM49eA3.elf (PID: 5605)File opened: /proc/243/cmdlineJump to behavior
Source: /tmp/wsskM49eA3.elf (PID: 5605)File opened: /proc/2/mapsJump to behavior
Source: /tmp/wsskM49eA3.elf (PID: 5605)File opened: /proc/2/cmdlineJump to behavior
Source: /tmp/wsskM49eA3.elf (PID: 5605)File opened: /proc/123/mapsJump to behavior
Source: /tmp/wsskM49eA3.elf (PID: 5605)File opened: /proc/123/cmdlineJump to behavior
Source: /tmp/wsskM49eA3.elf (PID: 5605)File opened: /proc/3/mapsJump to behavior
Source: /tmp/wsskM49eA3.elf (PID: 5605)File opened: /proc/3/cmdlineJump to behavior
Source: /tmp/wsskM49eA3.elf (PID: 5605)File opened: /proc/124/mapsJump to behavior
Source: /tmp/wsskM49eA3.elf (PID: 5605)File opened: /proc/124/cmdlineJump to behavior
Source: /tmp/wsskM49eA3.elf (PID: 5605)File opened: /proc/1588/mapsJump to behavior
Source: /tmp/wsskM49eA3.elf (PID: 5605)File opened: /proc/1588/cmdlineJump to behavior
Source: /tmp/wsskM49eA3.elf (PID: 5605)File opened: /proc/125/mapsJump to behavior
Source: /tmp/wsskM49eA3.elf (PID: 5605)File opened: /proc/125/cmdlineJump to behavior
Source: /tmp/wsskM49eA3.elf (PID: 5605)File opened: /proc/4/mapsJump to behavior
Source: /tmp/wsskM49eA3.elf (PID: 5605)File opened: /proc/4/cmdlineJump to behavior
Source: /tmp/wsskM49eA3.elf (PID: 5605)File opened: /proc/246/mapsJump to behavior
Source: /tmp/wsskM49eA3.elf (PID: 5605)File opened: /proc/246/cmdlineJump to behavior
Source: /tmp/wsskM49eA3.elf (PID: 5605)File opened: /proc/126/mapsJump to behavior
Source: /tmp/wsskM49eA3.elf (PID: 5605)File opened: /proc/126/cmdlineJump to behavior
Source: /tmp/wsskM49eA3.elf (PID: 5605)File opened: /proc/5/mapsJump to behavior
Source: /tmp/wsskM49eA3.elf (PID: 5605)File opened: /proc/5/cmdlineJump to behavior
Source: /tmp/wsskM49eA3.elf (PID: 5605)File opened: /proc/127/mapsJump to behavior
Source: /tmp/wsskM49eA3.elf (PID: 5605)File opened: /proc/127/cmdlineJump to behavior
Source: /tmp/wsskM49eA3.elf (PID: 5605)File opened: /proc/6/mapsJump to behavior
Source: /tmp/wsskM49eA3.elf (PID: 5605)File opened: /proc/6/cmdlineJump to behavior
Source: /tmp/wsskM49eA3.elf (PID: 5605)File opened: /proc/1585/mapsJump to behavior
Source: /tmp/wsskM49eA3.elf (PID: 5605)File opened: /proc/1585/cmdlineJump to behavior
Source: /tmp/wsskM49eA3.elf (PID: 5605)File opened: /proc/128/mapsJump to behavior
Source: /tmp/wsskM49eA3.elf (PID: 5605)File opened: /proc/128/cmdlineJump to behavior
Source: /tmp/wsskM49eA3.elf (PID: 5605)File opened: /proc/7/mapsJump to behavior
Source: /tmp/wsskM49eA3.elf (PID: 5605)File opened: /proc/7/cmdlineJump to behavior
Source: /tmp/wsskM49eA3.elf (PID: 5605)File opened: /proc/129/mapsJump to behavior
Source: /tmp/wsskM49eA3.elf (PID: 5605)File opened: /proc/129/cmdlineJump to behavior
Source: /tmp/wsskM49eA3.elf (PID: 5605)File opened: /proc/8/mapsJump to behavior
Source: /tmp/wsskM49eA3.elf (PID: 5605)File opened: /proc/8/cmdlineJump to behavior
Source: /tmp/wsskM49eA3.elf (PID: 5605)File opened: /proc/800/mapsJump to behavior
Source: /tmp/wsskM49eA3.elf (PID: 5605)File opened: /proc/800/cmdlineJump to behavior
Source: /tmp/wsskM49eA3.elf (PID: 5605)File opened: /proc/9/mapsJump to behavior
Source: /tmp/wsskM49eA3.elf (PID: 5605)File opened: /proc/9/cmdlineJump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity Information1
Scripting
Valid AccountsWindows Management Instrumentation1
Scripting
Path InterceptionDirect Volume Access1
OS Credential Dumping
System Service DiscoveryRemote ServicesData from Local System1
Non-Standard Port
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1429578 Sample: wsskM49eA3.elf Startdate: 22/04/2024 Architecture: LINUX Score: 64 22 91.228.147.116, 36252, 56730 MIROHOSTWebhostingdatacenteranddomainnamesregistrati Ukraine 2->22 24 217.155.142.63, 23 ZEN-ASZenInternet-UKGB United Kingdom 2->24 26 99 other IPs or domains 2->26 28 Malicious sample detected (through community Yara rule) 2->28 30 Multi AV Scanner detection for submitted file 2->30 32 Machine Learning detection for sample 2->32 34 Connects to many ports of the same IP (likely port scanning) 2->34 8 wsskM49eA3.elf 2->8         started        signatures3 process4 process5 10 wsskM49eA3.elf 8->10         started        12 wsskM49eA3.elf 8->12         started        14 wsskM49eA3.elf 8->14         started        16 wsskM49eA3.elf 8->16         started        process6 18 wsskM49eA3.elf 10->18         started        20 wsskM49eA3.elf 10->20         started       

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
wsskM49eA3.elf35%VirustotalBrowse
wsskM49eA3.elf42%ReversingLabsLinux.Trojan.Mirai
wsskM49eA3.elf100%Joe Sandbox ML
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
daisy.ubuntu.com
162.213.35.25
truefalse
    high
    • No. of IPs < 25%
    • 25% < No. of IPs < 50%
    • 50% < No. of IPs < 75%
    • 75% < No. of IPs
    IPDomainCountryFlagASNASN NameMalicious
    42.156.254.168
    unknownChina
    37963CNNIC-ALIBABA-CN-NET-APHangzhouAlibabaAdvertisingCoLtdfalse
    81.49.108.252
    unknownFrance
    3215FranceTelecom-OrangeFRfalse
    108.156.143.196
    unknownUnited States
    16509AMAZON-02USfalse
    186.234.142.202
    unknownBrazil
    7162UniversoOnlineSABRfalse
    178.109.130.69
    unknownUnited Kingdom
    12576EELtdGBfalse
    131.242.51.136
    unknownAustralia
    9650CITEC-AU-APQLDGovernmentBusinessITAUfalse
    109.98.66.195
    unknownRomania
    9050RTDBucharestRomaniaROfalse
    139.91.2.111
    unknownGreece
    8522FORTH-ASGRfalse
    160.146.176.129
    unknownUnited States
    5953DNIC-ASBLK-05800-06055USfalse
    48.54.243.157
    unknownUnited States
    2686ATGS-MMD-ASUSfalse
    93.86.41.53
    unknownSerbia
    8400TELEKOM-ASRSfalse
    32.205.243.218
    unknownUnited States
    2686ATGS-MMD-ASUSfalse
    142.177.79.17
    unknownCanada
    855CANET-ASN-4CAfalse
    27.187.152.126
    unknownChina
    4134CHINANET-BACKBONENo31Jin-rongStreetCNfalse
    113.129.36.183
    unknownChina
    4134CHINANET-BACKBONENo31Jin-rongStreetCNfalse
    219.153.98.147
    unknownChina
    134420CHINATELECOM-CHONGQING-IDCChongqingTelecomCNfalse
    80.236.252.137
    unknownBelgium
    5432PROXIMUS-ISP-ASBEfalse
    139.239.81.62
    unknownUnited States
    1462DNIC-ASBLK-01462-01463USfalse
    72.176.112.170
    unknownUnited States
    11427TWC-11427-TEXASUSfalse
    39.218.57.253
    unknownIndonesia
    23693TELKOMSEL-ASN-IDPTTelekomunikasiSelularIDfalse
    217.155.142.63
    unknownUnited Kingdom
    13037ZEN-ASZenInternet-UKGBfalse
    141.33.226.28
    unknownGermany
    680DFNVereinzurFoerderungeinesDeutschenForschungsnetzesefalse
    141.6.47.136
    unknownGermany
    15495BASF-IT-SERVICESDEfalse
    124.105.19.108
    unknownPhilippines
    9299IPG-AS-APPhilippineLongDistanceTelephoneCompanyPHfalse
    20.192.103.239
    unknownUnited States
    8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
    39.26.17.88
    unknownKorea Republic of
    4766KIXS-AS-KRKoreaTelecomKRfalse
    59.227.21.250
    unknownChina
    2516KDDIKDDICORPORATIONJPfalse
    221.82.155.108
    unknownJapan17676GIGAINFRASoftbankBBCorpJPfalse
    36.245.218.102
    unknownJapan37903EMOBILEYmobileCorporationJPfalse
    80.120.237.129
    unknownAustria
    8447TELEKOM-ATA1TelekomAustriaAGATfalse
    130.199.62.88
    unknownUnited States
    43BNL-ASUSfalse
    63.57.185.160
    unknownUnited States
    701UUNETUSfalse
    164.244.193.242
    unknownUnited States
    3303SWISSCOMSwisscomSwitzerlandLtdCHfalse
    81.135.64.218
    unknownUnited Kingdom
    2856BT-UK-ASBTnetUKRegionalnetworkGBfalse
    114.63.212.66
    unknownChina
    9812CNNIC-CN-COLNETOrientalCableNetworkCoLtdCNfalse
    140.134.200.162
    unknownTaiwan; Republic of China (ROC)
    1659ERX-TANET-ASN1TaiwanAcademicNetworkTANetInformationCfalse
    161.31.161.4
    unknownUnited States
    40581AREON-ASUSfalse
    1.104.79.246
    unknownKorea Republic of
    4766KIXS-AS-KRKoreaTelecomKRfalse
    51.204.64.235
    unknownUnited States
    2686ATGS-MMD-ASUSfalse
    2.18.165.112
    unknownEuropean Union
    16625AKAMAI-ASUSfalse
    24.215.239.188
    unknownUnited States
    12271TWC-12271-NYCUSfalse
    132.157.234.252
    unknownPeru
    21575ENTELPERUSAPEfalse
    57.109.192.81
    unknownBelgium
    51964ORANGE-BUSINESS-SERVICES-IPSN-ASNFRfalse
    131.150.52.165
    unknownUnited States
    7843TWC-7843-BBUSfalse
    202.125.69.20
    unknownBangladesh
    17471CYBERNET-BD-ASGrameenCybernetLtdBangladeshASforlocafalse
    186.112.246.251
    unknownColombia
    3816COLOMBIATELECOMUNICACIONESSAESPCOfalse
    192.106.110.86
    unknownItaly
    1267ASN-WINDTREIUNETEUfalse
    196.119.39.156
    unknownMorocco
    36925ASMediMAfalse
    83.135.94.213
    unknownGermany
    8881VERSATELDEfalse
    168.9.90.3
    unknownUnited States
    18838DCSSGAUSfalse
    193.160.133.72
    unknownNorway
    202120COMSAVE-ASNLfalse
    185.6.69.47
    unknownGermany
    44700HAENDLEKORTE-ASDEfalse
    210.90.15.43
    unknownKorea Republic of
    17841NCIA-AS-KRNATIONALINFORMATIONRESOURCESSERVICEKRfalse
    86.157.114.162
    unknownUnited Kingdom
    2856BT-UK-ASBTnetUKRegionalnetworkGBfalse
    222.24.48.4
    unknownChina
    4538ERX-CERNET-BKBChinaEducationandResearchNetworkCenterfalse
    222.14.143.131
    unknownJapan2516KDDIKDDICORPORATIONJPfalse
    102.7.212.114
    unknownunknown
    36926CKL1-ASNKEfalse
    193.180.134.170
    unknownSweden
    25176AC-NETSEfalse
    69.68.135.62
    unknownUnited States
    4282CENTURYLINK-TSDS-FLFTMYUSfalse
    47.169.39.191
    unknownUnited States
    5650FRONTIER-FRTRUSfalse
    104.45.127.220
    unknownUnited States
    8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
    8.30.32.42
    unknownUnited States
    323088X8-ASUSfalse
    25.119.72.90
    unknownUnited Kingdom
    7922COMCAST-7922USfalse
    45.224.97.84
    unknownEcuador
    264668NEDETELSAECfalse
    118.116.207.128
    unknownChina
    139220CHINANET-SICHUAN-CHUANXI-IDCSichuanChuanxnIDCCNfalse
    91.228.147.116
    unknownUkraine
    28907MIROHOSTWebhostingdatacenteranddomainnamesregistratitrue
    17.203.144.208
    unknownUnited States
    714APPLE-ENGINEERINGUSfalse
    195.133.89.28
    unknownRussian Federation
    41082URALTRANSCOM-ASUAfalse
    142.29.206.162
    unknownCanada
    3633PROVINCE-OF-BRITISH-COLUMBIACAfalse
    41.179.49.187
    unknownEgypt
    24863LINKdotNET-ASEGfalse
    195.52.206.232
    unknownGermany
    12312ECOTELDEfalse
    135.60.228.60
    unknownUnited States
    18676AVAYAUSfalse
    43.142.103.144
    unknownJapan4249LILLY-ASUSfalse
    223.237.30.44
    unknownIndia
    45609BHARTI-MOBILITY-AS-APBhartiAirtelLtdASforGPRSServicefalse
    182.55.164.152
    unknownSingapore
    55430STARHUB-NGNBNStarhubLtdSGfalse
    104.164.219.14
    unknownUnited States
    18779EGIHOSTINGUSfalse
    52.38.55.159
    unknownUnited States
    16509AMAZON-02USfalse
    149.115.106.189
    unknownUnited States
    13693NTS-ONLINEUSfalse
    212.101.125.9
    unknownTurkey
    199484BETAINTERNATIONALTRfalse
    70.237.113.142
    unknownUnited States
    7018ATT-INTERNET4USfalse
    185.216.201.241
    unknownGermany
    46261QUICKPACKETUSfalse
    171.247.84.13
    unknownViet Nam
    7552VIETEL-AS-APViettelGroupVNfalse
    52.174.40.233
    unknownUnited States
    8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
    155.201.186.85
    unknownUnited States
    20426PWC-ASUSfalse
    102.161.163.158
    unknownMauritius
    30999EMTEL-AS-APMUfalse
    34.72.179.158
    unknownUnited States
    15169GOOGLEUSfalse
    57.40.209.60
    unknownBelgium
    2686ATGS-MMD-ASUSfalse
    122.223.42.54
    unknownJapan2519VECTANTARTERIANetworksCorporationJPfalse
    154.25.118.144
    unknownUnited States
    174COGENT-174USfalse
    73.84.183.160
    unknownUnited States
    7922COMCAST-7922USfalse
    89.80.244.147
    unknownFrance
    5410BOUYGTEL-ISPFRfalse
    218.148.126.50
    unknownKorea Republic of
    4766KIXS-AS-KRKoreaTelecomKRfalse
    139.190.162.212
    unknownUnited Kingdom
    38547WITRIBE-AS-APWITRIBEPAKISTANLIMITEDPKfalse
    75.173.17.50
    unknownUnited States
    209CENTURYLINK-US-LEGACY-QWESTUSfalse
    91.125.185.26
    unknownUnited Kingdom
    6871PLUSNETUKInternetServiceProviderGBfalse
    169.93.81.200
    unknownUnited States
    37611AfrihostZAfalse
    162.37.90.189
    unknownUnited States
    35893ACPCAfalse
    120.34.124.233
    unknownChina
    4134CHINANET-BACKBONENo31Jin-rongStreetCNfalse
    79.141.197.160
    unknownFrance
    836220rueDenisPapinFRfalse
    196.144.133.60
    unknownEgypt
    36935Vodafone-EGfalse
    No context
    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
    daisy.ubuntu.comjPLqxoxi1w.elfGet hashmaliciousMiraiBrowse
    • 162.213.35.24
    dI3tFWyJ6d.elfGet hashmaliciousMiraiBrowse
    • 162.213.35.24
    OO1vDl4L4r.elfGet hashmaliciousUnknownBrowse
    • 162.213.35.25
    tB42BIvqlr.elfGet hashmaliciousUnknownBrowse
    • 162.213.35.24
    kFpCQq6szE.elfGet hashmaliciousUnknownBrowse
    • 162.213.35.25
    Caa2tySjUN.elfGet hashmaliciousGafgytBrowse
    • 162.213.35.25
    tajma.mpsl-20240422-0539.elfGet hashmaliciousMirai, OkiruBrowse
    • 162.213.35.24
    tajma.x86_64-20240422-0536.elfGet hashmaliciousMirai, OkiruBrowse
    • 162.213.35.24
    tajma.mips-20240422-0536.elfGet hashmaliciousMirai, OkiruBrowse
    • 162.213.35.24
    tajma.arm-20240422-0536.elfGet hashmaliciousMirai, OkiruBrowse
    • 162.213.35.24
    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
    CNNIC-ALIBABA-CN-NET-APHangzhouAlibabaAdvertisingCoLtdjPLqxoxi1w.elfGet hashmaliciousMiraiBrowse
    • 139.240.157.240
    aQvU3QHA3N.elfGet hashmaliciousUnknownBrowse
    • 101.134.43.250
    42EYULJ8y1.elfGet hashmaliciousMiraiBrowse
    • 121.41.202.249
    tajma.x86-20240422-0535.elfGet hashmaliciousMirai, OkiruBrowse
    • 39.102.175.240
    SecuriteInfo.com.FileRepMalware.6915.17186.exeGet hashmaliciousUnknownBrowse
    • 106.14.81.150
    SecuriteInfo.com.FileRepMalware.6915.17186.exeGet hashmaliciousUnknownBrowse
    • 106.14.81.150
    Y98pGn3FUt.elfGet hashmaliciousMiraiBrowse
    • 101.135.57.228
    WCcNzb83Y3.exeGet hashmaliciousCobaltStrikeBrowse
    • 47.120.39.182
    mCS7AR9pKm.elfGet hashmaliciousMirai, OkiruBrowse
    • 8.156.94.142
    http://www.sushi-idea.comGet hashmaliciousUnknownBrowse
    • 59.82.121.97
    UniversoOnlineSABRhttp://www.indeks.pt/Get hashmaliciousUnknownBrowse
    • 200.147.4.47
    E0sl4ONdra.elfGet hashmaliciousMiraiBrowse
    • 200.98.219.211
    la.bot.arm7.elfGet hashmaliciousMiraiBrowse
    • 200.98.180.36
    xQwEu422am.elfGet hashmaliciousMiraiBrowse
    • 200.98.179.20
    huhu.mpsl.elfGet hashmaliciousMirai, OkiruBrowse
    • 200.98.220.157
    SecuriteInfo.com.Win32.Evo-gen.23836.28931.exeGet hashmaliciousUnknownBrowse
    • 200.147.35.207
    SecuriteInfo.com.Win32.Evo-gen.23836.28931.exeGet hashmaliciousUnknownBrowse
    • 200.147.35.207
    3rOSHAZ6SC.elfGet hashmaliciousMiraiBrowse
    • 200.221.105.223
    ngZVdu9k3p.elfGet hashmaliciousMiraiBrowse
    • 200.147.241.218
    1208819601.exeGet hashmaliciousUnknownBrowse
    • 200.98.94.238
    FranceTelecom-OrangeFRtajma.arm7-20240422-0539.elfGet hashmaliciousMirai, OkiruBrowse
    • 83.194.238.219
    EgLiYySziA.elfGet hashmaliciousMirai, OkiruBrowse
    • 92.149.191.112
    b3astmode.x86.elfGet hashmaliciousUnknownBrowse
    • 109.218.10.129
    sZyq3DvYmc.elfGet hashmaliciousMiraiBrowse
    • 129.182.162.130
    tajma.arm7-20240421-1029.elfGet hashmaliciousMirai, OkiruBrowse
    • 90.119.151.28
    YKTNuK117e.exeGet hashmaliciousNjratBrowse
    • 83.196.78.85
    JdnjRc1VGX.elfGet hashmaliciousMiraiBrowse
    • 86.199.95.91
    H6ccnU1094.elfGet hashmaliciousMirai, OkiruBrowse
    • 83.115.239.3
    9IseFevRH6.elfGet hashmaliciousMiraiBrowse
    • 109.211.102.134
    BzmhHwFpCV.elfGet hashmaliciousMiraiBrowse
    • 90.13.203.111
    AMAZON-02USjPLqxoxi1w.elfGet hashmaliciousMiraiBrowse
    • 52.222.196.118
    dI3tFWyJ6d.elfGet hashmaliciousMiraiBrowse
    • 108.150.4.174
    aQvU3QHA3N.elfGet hashmaliciousUnknownBrowse
    • 18.236.14.150
    SecuriteInfo.com.Win64.Evo-gen.21575.16188.exeGet hashmaliciousPython Stealer, Monster StealerBrowse
    • 18.230.76.116
    http://www.blindgifthate.sa.com/ykihrabu/jbfcdwmhs3663abhjj/TI9CoAbsa45o4OGHN76mykzGVOmjjmAqisj5bnGXtxk/QsrceDcgb2PLDfYqvtVO8PWEvzs-rzaZd0h8Kd799UCOgPZmzKrZcJ8a7B4swzsjaoRhIr2uYEImfmwVp4h4VAGet hashmaliciousUnknownBrowse
    • 13.226.225.8
    https://www.sigtn.com/utils/emt.cfm?client_id=9195153&campaign_id=73466&link=aHR0cHM6Ly9saW5rLm1haWwuYmVlaGlpdi5jb20vbHMvY2xpY2s/dXBuPXUwMDEucklvcWRaR1R1SGJzNzQ0S21jWTQzbm9GN25FNXlXdTZFcUlEQ1JQVW5LVlRsVDF5N0p0RTVORGVVSmxOU254Uk82V2lWVzB6akF4aVNnRXQ4S0dzZUdDb3N4OE9CV0tIQ1VyMmlaRXQ0LTJCM2EtMkZuWXhLOHNYNW1IZ0ZPZFd1VHpnUmNyMHdMYk52c0NadXktMkZiSXRoVDI4bi0yRjdCUy0yQmVINGxDRVExVTQxQU5xSS0zRFhBa0FfdWpTUjJaZ1VvcFZ3R0Y1eWNMcm5nS0Y1andZVnZoMHVzbGExV2Z5ZUs2QXJvYzFDOXFaY3NKZHlBVHNhVnFnZmxkNjlSOE1FQ3J6dHdtVUw5QkliUXRiM1VjUEwxanplbGNyNG1jZGFhdlZNZFE0ejA0ZHFqRC0yRkR4RVlVV1lLM3BjNTBsREpndVd5Z0NZMEZ2LTJGdG9kUkpjSzNjRlYwcDdMYS0yQlh1NjRveEtqVkpFUkV3WGJSekN0dTlZazJBSmgwQVVNeUxiOTVXWlBiTmxOQjlmTXRhbm41aDY2eDByMm5nR2k5QmJkLTJCdWd1Ync2Z092blJheXlKLTJGYXB3eHBSSHpxZHZER21pREhpR09kemxvQVRJQWkxMWR5ZWhpazY3NDRzQ2E3dzl0MWZqU2JvTWpXd1dvdXlVaDJPd0VyLTJCOHJDZTB1VjF6clJDTi0yQjh6Z2R4Y1JibkZ1a3JtNGVJbU5WQUJnSFMtMkZ1S2RrUDdrZkUxUm9PWlVGdWU3bzZkLTJGY3FpMUx2VXVpbW9VbmxzMjRseXRVQzNQdUpiOVlDZ0Zoc29LRlZOMUxvZXloOFFGTERUaEN4VjE5UC0yRmxCWTRpZURUI2NzaGVwcGFyZEBtb29nLmNvbQ==Get hashmaliciousUnknownBrowse
    • 3.163.115.58
    P84GQvkQhC.elfGet hashmaliciousUnknownBrowse
    • 34.243.160.129
    HfcQmQis2J.elfGet hashmaliciousUnknownBrowse
    • 34.243.160.129
    vXahA76yEa.elfGet hashmaliciousUnknownBrowse
    • 34.249.145.219
    42EYULJ8y1.elfGet hashmaliciousMiraiBrowse
    • 130.177.187.239
    No context
    No context
    No created / dropped files found
    File type:ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, stripped
    Entropy (8bit):6.460571467241214
    TrID:
    • ELF Executable and Linkable format (Linux) (4029/14) 50.16%
    • ELF Executable and Linkable format (generic) (4004/1) 49.84%
    File name:wsskM49eA3.elf
    File size:75'664 bytes
    MD5:59ccf2f294605b86339ca5d4015c0016
    SHA1:0be2e5dddcc1f3e4b28a723e816c1a48abe74970
    SHA256:96adadcb024a8a4e1a6d26d5d61b596ac07fcfff9217eea1b5d8bc61ac137e48
    SHA512:a92d3c6935a007fae9c1d04e45834981c4679f9c55ef5fcb3a9ca5d388ad7ac20e0f74fe14563eca6cf03eb3e293ea31c1fa6c5152257c02aa848bc6dfa8fcec
    SSDEEP:1536:lSo+gSRUuVcYOn+h6WRu+V7XPEd3Y6mhD0cEqbCk9m17w1Sls8:lSo+gSRnmNurTIPmhDtEquWmPs8
    TLSH:72735BC0D683D8F6E8460AB1617BAB374637F9351129EA87D769EA32FC52700E60735C
    File Content Preview:.ELF....................d...4....&......4. ...(.......................................... ...............+..........Q.td............................U..S.......w....h....C...[]...$.............U......=.....t..5....$......$.......u........t....h............

    ELF header

    Class:ELF32
    Data:2's complement, little endian
    Version:1 (current)
    Machine:Intel 80386
    Version Number:0x1
    Type:EXEC (Executable file)
    OS/ABI:UNIX - System V
    ABI Version:0
    Entry Point Address:0x8048164
    Flags:0x0
    ELF Header Size:52
    Program Header Offset:52
    Program Header Size:32
    Number of Program Headers:3
    Section Header Offset:75264
    Section Header Size:40
    Number of Section Headers:10
    Header String Table Index:9
    NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
    NULL0x00x00x00x00x0000
    .initPROGBITS0x80480940x940x1c0x00x6AX001
    .textPROGBITS0x80480b00xb00xf2660x00x6AX0016
    .finiPROGBITS0x80573160xf3160x170x00x6AX001
    .rodataPROGBITS0x80573400xf3400x28a00x00x2A0032
    .ctorsPROGBITS0x805a0000x120000x80x00x3WA004
    .dtorsPROGBITS0x805a0080x120080x80x00x3WA004
    .dataPROGBITS0x805a0200x120200x5a00x00x3WA0032
    .bssNOBITS0x805a5c00x125c00x25c00x00x3WA0032
    .shstrtabSTRTAB0x00x125c00x3e0x00x0001
    TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
    LOAD0x00x80480000x80480000x11be00x11be06.54300x5R E0x1000.init .text .fini .rodata
    LOAD0x120000x805a0000x805a0000x5c00x2b804.36360x6RW 0x1000.ctors .dtors .data .bss
    GNU_STACK0x00x00x00x00x00.00000x6RW 0x4
    TimestampSource PortDest PortSource IPDest IP
    Apr 22, 2024 12:16:02.100656986 CEST5704123192.168.2.1597.251.9.249
    Apr 22, 2024 12:16:02.100661993 CEST5704123192.168.2.15103.135.76.58
    Apr 22, 2024 12:16:02.100704908 CEST5704123192.168.2.15159.217.245.248
    Apr 22, 2024 12:16:02.100704908 CEST5704123192.168.2.15179.117.82.71
    Apr 22, 2024 12:16:02.100754023 CEST5704123192.168.2.15159.220.251.45
    Apr 22, 2024 12:16:02.100754976 CEST5704123192.168.2.15162.191.236.117
    Apr 22, 2024 12:16:02.100754976 CEST5704123192.168.2.15107.205.226.241
    Apr 22, 2024 12:16:02.100754023 CEST5704123192.168.2.15166.221.27.101
    Apr 22, 2024 12:16:02.100754976 CEST5704123192.168.2.15183.173.5.20
    Apr 22, 2024 12:16:02.100754976 CEST5704123192.168.2.1573.84.183.160
    Apr 22, 2024 12:16:02.100773096 CEST5704123192.168.2.1561.162.171.15
    Apr 22, 2024 12:16:02.100783110 CEST5704123192.168.2.15126.63.63.238
    Apr 22, 2024 12:16:02.100773096 CEST5704123192.168.2.15222.14.143.131
    Apr 22, 2024 12:16:02.100794077 CEST5704123192.168.2.15178.50.246.233
    Apr 22, 2024 12:16:02.100795031 CEST5704123192.168.2.1517.124.138.124
    Apr 22, 2024 12:16:02.100795031 CEST5704123192.168.2.15178.226.2.38
    Apr 22, 2024 12:16:02.100795031 CEST5704123192.168.2.1560.223.118.87
    Apr 22, 2024 12:16:02.100795031 CEST5704123192.168.2.15109.89.63.123
    Apr 22, 2024 12:16:02.100809097 CEST5704123192.168.2.1534.122.151.145
    Apr 22, 2024 12:16:02.100824118 CEST5704123192.168.2.15167.121.200.224
    Apr 22, 2024 12:16:02.100847006 CEST5704123192.168.2.1552.212.0.193
    Apr 22, 2024 12:16:02.100850105 CEST5704123192.168.2.15141.93.205.36
    Apr 22, 2024 12:16:02.100850105 CEST5704123192.168.2.15170.20.88.207
    Apr 22, 2024 12:16:02.100850105 CEST5704123192.168.2.15184.39.22.82
    Apr 22, 2024 12:16:02.100853920 CEST5704123192.168.2.15161.224.18.189
    Apr 22, 2024 12:16:02.100853920 CEST5704123192.168.2.15183.45.75.132
    Apr 22, 2024 12:16:02.100872040 CEST5704123192.168.2.1570.237.113.142
    Apr 22, 2024 12:16:02.100872040 CEST5704123192.168.2.1585.161.194.88
    Apr 22, 2024 12:16:02.100882053 CEST5704123192.168.2.15186.234.142.202
    Apr 22, 2024 12:16:02.100882053 CEST5704123192.168.2.15147.230.111.243
    Apr 22, 2024 12:16:02.100882053 CEST5704123192.168.2.15217.199.83.165
    Apr 22, 2024 12:16:02.100918055 CEST5704123192.168.2.15159.138.131.51
    Apr 22, 2024 12:16:02.100930929 CEST5704123192.168.2.15183.247.58.60
    Apr 22, 2024 12:16:02.100943089 CEST5704123192.168.2.1593.77.43.78
    Apr 22, 2024 12:16:02.100946903 CEST5704123192.168.2.1595.118.106.84
    Apr 22, 2024 12:16:02.100946903 CEST5704123192.168.2.15120.30.90.211
    Apr 22, 2024 12:16:02.100955963 CEST5704123192.168.2.1566.235.160.232
    Apr 22, 2024 12:16:02.100965977 CEST5704123192.168.2.15142.177.79.17
    Apr 22, 2024 12:16:02.100966930 CEST5704123192.168.2.15108.137.148.239
    Apr 22, 2024 12:16:02.100974083 CEST5704123192.168.2.15182.43.70.114
    Apr 22, 2024 12:16:02.100982904 CEST5704123192.168.2.15221.82.155.108
    Apr 22, 2024 12:16:02.101003885 CEST5704123192.168.2.1560.123.132.147
    Apr 22, 2024 12:16:02.101002932 CEST5704123192.168.2.15139.150.227.124
    Apr 22, 2024 12:16:02.101005077 CEST5704123192.168.2.1579.252.4.99
    Apr 22, 2024 12:16:02.101013899 CEST5704123192.168.2.1584.11.52.65
    Apr 22, 2024 12:16:02.101013899 CEST5704123192.168.2.15111.65.61.217
    Apr 22, 2024 12:16:02.101013899 CEST5704123192.168.2.1563.232.218.248
    Apr 22, 2024 12:16:02.101013899 CEST5704123192.168.2.15160.228.106.42
    Apr 22, 2024 12:16:02.101022005 CEST5704123192.168.2.15132.157.234.252
    Apr 22, 2024 12:16:02.101030111 CEST5704123192.168.2.15139.239.81.62
    Apr 22, 2024 12:16:02.101037979 CEST5704123192.168.2.15175.37.253.10
    Apr 22, 2024 12:16:02.101042032 CEST5704123192.168.2.15197.90.46.12
    Apr 22, 2024 12:16:02.101042032 CEST5704123192.168.2.1531.83.132.210
    Apr 22, 2024 12:16:02.101069927 CEST5704123192.168.2.1541.26.32.7
    Apr 22, 2024 12:16:02.101070881 CEST5704123192.168.2.1577.116.143.25
    Apr 22, 2024 12:16:02.101073027 CEST5704123192.168.2.1550.145.7.239
    Apr 22, 2024 12:16:02.101075888 CEST5704123192.168.2.15217.95.175.253
    Apr 22, 2024 12:16:02.101098061 CEST5704123192.168.2.1554.110.45.131
    Apr 22, 2024 12:16:02.101100922 CEST5704123192.168.2.15105.81.79.98
    Apr 22, 2024 12:16:02.101104975 CEST5704123192.168.2.1580.238.129.79
    Apr 22, 2024 12:16:02.101119041 CEST5704123192.168.2.1586.157.114.162
    Apr 22, 2024 12:16:02.101119041 CEST5704123192.168.2.15202.219.6.154
    Apr 22, 2024 12:16:02.101155043 CEST5704123192.168.2.15139.91.2.111
    Apr 22, 2024 12:16:02.101161003 CEST5704123192.168.2.15120.34.124.233
    Apr 22, 2024 12:16:02.101161003 CEST5704123192.168.2.1523.78.145.74
    Apr 22, 2024 12:16:02.101162910 CEST5704123192.168.2.1579.141.197.160
    Apr 22, 2024 12:16:02.101165056 CEST5704123192.168.2.15130.43.7.243
    Apr 22, 2024 12:16:02.101167917 CEST5704123192.168.2.15154.163.209.195
    Apr 22, 2024 12:16:02.101176977 CEST5704123192.168.2.15141.66.229.217
    Apr 22, 2024 12:16:02.101226091 CEST5704123192.168.2.1571.170.29.196
    Apr 22, 2024 12:16:02.101226091 CEST5704123192.168.2.15162.37.90.189
    Apr 22, 2024 12:16:02.101227999 CEST5704123192.168.2.15104.164.219.14
    Apr 22, 2024 12:16:02.101227999 CEST5704123192.168.2.15146.166.193.17
    Apr 22, 2024 12:16:02.101232052 CEST5704123192.168.2.15139.159.241.95
    Apr 22, 2024 12:16:02.101232052 CEST5704123192.168.2.15217.155.142.63
    Apr 22, 2024 12:16:02.101233959 CEST5704123192.168.2.1545.54.117.104
    Apr 22, 2024 12:16:02.101243019 CEST5704123192.168.2.1571.188.62.41
    Apr 22, 2024 12:16:02.101263046 CEST5704123192.168.2.15120.130.199.26
    Apr 22, 2024 12:16:02.101286888 CEST5704123192.168.2.15216.235.165.63
    Apr 22, 2024 12:16:02.101288080 CEST5704123192.168.2.1539.193.66.106
    Apr 22, 2024 12:16:02.101294994 CEST5704123192.168.2.15119.178.119.226
    Apr 22, 2024 12:16:02.101298094 CEST5704123192.168.2.15218.148.126.50
    Apr 22, 2024 12:16:02.101298094 CEST5704123192.168.2.15118.126.108.13
    Apr 22, 2024 12:16:02.101311922 CEST5704123192.168.2.15130.199.62.88
    Apr 22, 2024 12:16:02.101334095 CEST5704123192.168.2.15168.157.3.178
    Apr 22, 2024 12:16:02.101334095 CEST5704123192.168.2.15175.40.44.129
    Apr 22, 2024 12:16:02.101334095 CEST5704123192.168.2.15155.49.231.171
    Apr 22, 2024 12:16:02.101334095 CEST5704123192.168.2.15165.81.116.59
    Apr 22, 2024 12:16:02.101340055 CEST5704123192.168.2.15178.109.130.69
    Apr 22, 2024 12:16:02.101355076 CEST5704123192.168.2.1563.33.138.204
    Apr 22, 2024 12:16:02.101381063 CEST5704123192.168.2.1576.58.240.116
    Apr 22, 2024 12:16:02.101381063 CEST5704123192.168.2.15130.239.60.132
    Apr 22, 2024 12:16:02.101392031 CEST5704123192.168.2.15102.7.212.114
    Apr 22, 2024 12:16:02.101392031 CEST5704123192.168.2.15221.96.215.249
    Apr 22, 2024 12:16:02.101406097 CEST5704123192.168.2.1527.69.190.11
    Apr 22, 2024 12:16:02.101411104 CEST5704123192.168.2.1557.40.209.60
    Apr 22, 2024 12:16:02.101412058 CEST5704123192.168.2.1553.231.49.201
    Apr 22, 2024 12:16:02.101412058 CEST5704123192.168.2.15206.196.4.72
    Apr 22, 2024 12:16:02.101413965 CEST5704123192.168.2.15187.107.253.185
    Apr 22, 2024 12:16:02.101421118 CEST5704123192.168.2.1535.226.167.244
    Apr 22, 2024 12:16:02.101428032 CEST5704123192.168.2.15211.139.202.185
    Apr 22, 2024 12:16:02.101439953 CEST5704123192.168.2.1534.230.75.227
    Apr 22, 2024 12:16:02.101459026 CEST5704123192.168.2.15167.139.240.70
    Apr 22, 2024 12:16:02.101459026 CEST5704123192.168.2.1594.45.105.110
    Apr 22, 2024 12:16:02.101466894 CEST5704123192.168.2.15131.150.52.165
    Apr 22, 2024 12:16:02.101469040 CEST5704123192.168.2.15164.116.41.92
    Apr 22, 2024 12:16:02.101491928 CEST5704123192.168.2.1524.215.239.188
    Apr 22, 2024 12:16:02.101504087 CEST5704123192.168.2.15192.106.110.86
    Apr 22, 2024 12:16:02.101516962 CEST5704123192.168.2.1552.38.55.159
    Apr 22, 2024 12:16:02.101521969 CEST5704123192.168.2.1587.65.141.89
    Apr 22, 2024 12:16:02.101521969 CEST5704123192.168.2.15105.29.56.204
    Apr 22, 2024 12:16:02.101526976 CEST5704123192.168.2.1525.119.72.90
    Apr 22, 2024 12:16:02.101526976 CEST5704123192.168.2.15157.182.115.29
    Apr 22, 2024 12:16:02.101527929 CEST5704123192.168.2.15100.162.125.128
    Apr 22, 2024 12:16:02.101538897 CEST5704123192.168.2.15198.192.237.101
    Apr 22, 2024 12:16:02.101546049 CEST5704123192.168.2.1573.45.7.241
    Apr 22, 2024 12:16:02.101557970 CEST5704123192.168.2.15196.75.55.163
    Apr 22, 2024 12:16:02.101566076 CEST5704123192.168.2.15122.223.42.54
    Apr 22, 2024 12:16:02.101572037 CEST5704123192.168.2.1536.246.240.48
    Apr 22, 2024 12:16:02.101592064 CEST5704123192.168.2.1594.199.231.129
    Apr 22, 2024 12:16:02.101592064 CEST5704123192.168.2.1541.31.240.215
    Apr 22, 2024 12:16:02.101592064 CEST5704123192.168.2.1580.120.237.129
    Apr 22, 2024 12:16:02.101592064 CEST5704123192.168.2.1513.96.28.208
    Apr 22, 2024 12:16:02.101598024 CEST5704123192.168.2.1574.244.136.183
    Apr 22, 2024 12:16:02.101598978 CEST5704123192.168.2.15135.60.228.60
    Apr 22, 2024 12:16:02.101610899 CEST5704123192.168.2.1589.127.164.113
    Apr 22, 2024 12:16:02.101610899 CEST5704123192.168.2.15198.34.119.98
    Apr 22, 2024 12:16:02.101623058 CEST5704123192.168.2.15138.245.57.96
    Apr 22, 2024 12:16:02.101623058 CEST5704123192.168.2.1561.89.157.161
    Apr 22, 2024 12:16:02.101639986 CEST5704123192.168.2.15176.196.74.216
    Apr 22, 2024 12:16:02.101644039 CEST5704123192.168.2.1566.187.9.170
    Apr 22, 2024 12:16:02.101655006 CEST5704123192.168.2.15149.115.106.189
    Apr 22, 2024 12:16:02.101660013 CEST5704123192.168.2.15168.13.149.105
    Apr 22, 2024 12:16:02.101679087 CEST5704123192.168.2.1561.51.45.225
    Apr 22, 2024 12:16:02.101680994 CEST5704123192.168.2.15161.77.16.127
    Apr 22, 2024 12:16:02.101684093 CEST5704123192.168.2.15187.84.10.55
    Apr 22, 2024 12:16:02.101684093 CEST5704123192.168.2.15220.214.85.97
    Apr 22, 2024 12:16:02.101696968 CEST5704123192.168.2.1573.118.124.247
    Apr 22, 2024 12:16:02.101713896 CEST5704123192.168.2.1545.224.97.84
    Apr 22, 2024 12:16:02.101722956 CEST5704123192.168.2.15149.110.67.252
    Apr 22, 2024 12:16:02.101727009 CEST5704123192.168.2.15104.179.232.169
    Apr 22, 2024 12:16:02.101736069 CEST5704123192.168.2.15219.153.98.147
    Apr 22, 2024 12:16:02.101736069 CEST5704123192.168.2.15135.32.82.196
    Apr 22, 2024 12:16:02.101752996 CEST5704123192.168.2.15210.90.106.122
    Apr 22, 2024 12:16:02.101773977 CEST5704123192.168.2.1571.133.53.162
    Apr 22, 2024 12:16:02.101773977 CEST5704123192.168.2.15114.91.77.63
    Apr 22, 2024 12:16:02.101804018 CEST5704123192.168.2.15166.223.179.171
    Apr 22, 2024 12:16:02.101804018 CEST5704123192.168.2.15185.216.201.241
    Apr 22, 2024 12:16:02.101804018 CEST5704123192.168.2.15180.194.148.178
    Apr 22, 2024 12:16:02.101807117 CEST5704123192.168.2.15120.189.206.122
    Apr 22, 2024 12:16:02.101807117 CEST5704123192.168.2.15122.56.197.176
    Apr 22, 2024 12:16:02.101819038 CEST5704123192.168.2.1536.245.218.102
    Apr 22, 2024 12:16:02.101819038 CEST5704123192.168.2.15219.180.95.37
    Apr 22, 2024 12:16:02.101820946 CEST5704123192.168.2.15123.75.104.156
    Apr 22, 2024 12:16:02.101820946 CEST5704123192.168.2.1584.116.130.151
    Apr 22, 2024 12:16:02.101824045 CEST5704123192.168.2.15118.116.207.128
    Apr 22, 2024 12:16:02.101824045 CEST5704123192.168.2.15134.142.154.79
    Apr 22, 2024 12:16:02.101838112 CEST5704123192.168.2.1540.61.248.196
    Apr 22, 2024 12:16:02.101838112 CEST5704123192.168.2.15174.55.142.215
    Apr 22, 2024 12:16:02.101871967 CEST5704123192.168.2.15104.45.127.220
    Apr 22, 2024 12:16:02.101885080 CEST5704123192.168.2.1548.54.243.157
    Apr 22, 2024 12:16:02.101885080 CEST5704123192.168.2.151.193.49.101
    Apr 22, 2024 12:16:02.101886034 CEST5704123192.168.2.1574.10.38.35
    Apr 22, 2024 12:16:02.101901054 CEST5704123192.168.2.15200.111.6.175
    Apr 22, 2024 12:16:02.101907969 CEST5704123192.168.2.1534.210.50.7
    Apr 22, 2024 12:16:02.101908922 CEST5704123192.168.2.15166.172.228.208
    Apr 22, 2024 12:16:02.101927042 CEST5704123192.168.2.15135.74.135.86
    Apr 22, 2024 12:16:02.101929903 CEST5704123192.168.2.1540.99.238.245
    Apr 22, 2024 12:16:02.101938963 CEST5704123192.168.2.15119.192.104.252
    Apr 22, 2024 12:16:02.101943016 CEST5704123192.168.2.15108.106.156.32
    Apr 22, 2024 12:16:02.101954937 CEST5704123192.168.2.1573.123.45.233
    Apr 22, 2024 12:16:02.101954937 CEST5704123192.168.2.15170.119.119.45
    Apr 22, 2024 12:16:02.101960897 CEST5704123192.168.2.15168.213.110.231
    Apr 22, 2024 12:16:02.101962090 CEST5704123192.168.2.1551.204.64.235
    Apr 22, 2024 12:16:02.101960897 CEST5704123192.168.2.15106.103.2.146
    Apr 22, 2024 12:16:02.101978064 CEST5704123192.168.2.15132.113.243.20
    Apr 22, 2024 12:16:02.101983070 CEST5704123192.168.2.1548.152.39.71
    Apr 22, 2024 12:16:02.101988077 CEST5704123192.168.2.15175.103.110.223
    Apr 22, 2024 12:16:02.101989031 CEST5704123192.168.2.15184.205.151.187
    Apr 22, 2024 12:16:02.101989031 CEST5704123192.168.2.15163.195.173.66
    Apr 22, 2024 12:16:02.101999998 CEST5704123192.168.2.1570.52.241.66
    Apr 22, 2024 12:16:02.102009058 CEST5704123192.168.2.15204.16.206.231
    Apr 22, 2024 12:16:02.102009058 CEST5704123192.168.2.1585.19.9.125
    Apr 22, 2024 12:16:02.102029085 CEST5704123192.168.2.1579.224.64.124
    Apr 22, 2024 12:16:02.102029085 CEST5704123192.168.2.1569.201.66.165
    Apr 22, 2024 12:16:02.102041006 CEST5704123192.168.2.1548.45.149.111
    Apr 22, 2024 12:16:02.102051973 CEST5704123192.168.2.151.129.10.4
    Apr 22, 2024 12:16:02.102061033 CEST5704123192.168.2.15163.110.202.189
    Apr 22, 2024 12:16:02.102073908 CEST5704123192.168.2.1536.81.39.250
    Apr 22, 2024 12:16:02.102080107 CEST5704123192.168.2.15203.137.50.87
    Apr 22, 2024 12:16:02.102080107 CEST5704123192.168.2.15200.192.226.160
    Apr 22, 2024 12:16:02.102097988 CEST5704123192.168.2.15160.146.176.129
    Apr 22, 2024 12:16:02.102117062 CEST5704123192.168.2.152.254.36.109
    Apr 22, 2024 12:16:02.102117062 CEST5704123192.168.2.15154.173.144.10
    Apr 22, 2024 12:16:02.102118969 CEST5704123192.168.2.1527.115.124.42
    Apr 22, 2024 12:16:02.102130890 CEST5704123192.168.2.15223.237.30.44
    Apr 22, 2024 12:16:02.102133989 CEST5704123192.168.2.1543.113.156.150
    Apr 22, 2024 12:16:02.102142096 CEST5704123192.168.2.15145.227.158.179
    Apr 22, 2024 12:16:02.102149010 CEST5704123192.168.2.1571.64.24.40
    Apr 22, 2024 12:16:02.102175951 CEST5704123192.168.2.15196.133.72.205
    Apr 22, 2024 12:16:02.102176905 CEST5704123192.168.2.15154.25.118.144
    Apr 22, 2024 12:16:02.102179050 CEST5704123192.168.2.15185.229.129.215
    Apr 22, 2024 12:16:02.102185011 CEST5704123192.168.2.1597.218.227.85
    Apr 22, 2024 12:16:02.102200985 CEST5704123192.168.2.15115.92.236.26
    Apr 22, 2024 12:16:02.102201939 CEST5704123192.168.2.158.30.32.42
    Apr 22, 2024 12:16:02.102214098 CEST5704123192.168.2.15195.52.206.232
    Apr 22, 2024 12:16:02.102220058 CEST5704123192.168.2.1520.208.35.246
    Apr 22, 2024 12:16:02.102221012 CEST5704123192.168.2.1582.167.76.130
    Apr 22, 2024 12:16:02.102232933 CEST5704123192.168.2.1567.97.2.190
    Apr 22, 2024 12:16:02.102255106 CEST5704123192.168.2.15109.75.237.133
    Apr 22, 2024 12:16:02.102257013 CEST5704123192.168.2.152.18.165.112
    Apr 22, 2024 12:16:02.102263927 CEST5704123192.168.2.1565.91.9.204
    Apr 22, 2024 12:16:02.102266073 CEST5704123192.168.2.15117.64.187.132
    Apr 22, 2024 12:16:02.102288961 CEST5704123192.168.2.15112.190.33.152
    Apr 22, 2024 12:16:02.102289915 CEST5704123192.168.2.15100.206.208.180
    Apr 22, 2024 12:16:02.102291107 CEST5704123192.168.2.1524.96.94.181
    Apr 22, 2024 12:16:02.102292061 CEST5704123192.168.2.1540.26.69.211
    Apr 22, 2024 12:16:02.102317095 CEST5704123192.168.2.1593.86.41.53
    Apr 22, 2024 12:16:02.102317095 CEST5704123192.168.2.1543.142.103.144
    Apr 22, 2024 12:16:02.102322102 CEST5704123192.168.2.15110.104.171.15
    Apr 22, 2024 12:16:02.102322102 CEST5704123192.168.2.1514.76.25.32
    Apr 22, 2024 12:16:02.102322102 CEST5704123192.168.2.1581.230.134.194
    Apr 22, 2024 12:16:02.102324963 CEST5704123192.168.2.15147.96.46.147
    Apr 22, 2024 12:16:02.102338076 CEST5704123192.168.2.1536.168.72.45
    Apr 22, 2024 12:16:02.102343082 CEST5704123192.168.2.15162.95.40.218
    Apr 22, 2024 12:16:02.102343082 CEST5704123192.168.2.15207.135.57.155
    Apr 22, 2024 12:16:02.102361917 CEST5704123192.168.2.15148.175.167.189
    Apr 22, 2024 12:16:02.102363110 CEST5704123192.168.2.15200.117.245.6
    Apr 22, 2024 12:16:02.102372885 CEST5704123192.168.2.15114.55.41.27
    Apr 22, 2024 12:16:02.102397919 CEST5704123192.168.2.15199.112.107.251
    Apr 22, 2024 12:16:02.102400064 CEST5704123192.168.2.15114.63.212.66
    Apr 22, 2024 12:16:02.102400064 CEST5704123192.168.2.1552.174.40.233
    Apr 22, 2024 12:16:02.102420092 CEST5704123192.168.2.1581.135.64.218
    Apr 22, 2024 12:16:02.102421045 CEST5704123192.168.2.15117.82.23.188
    Apr 22, 2024 12:16:02.102421045 CEST5704123192.168.2.15198.90.58.79
    Apr 22, 2024 12:16:02.102421999 CEST5704123192.168.2.15148.76.161.28
    Apr 22, 2024 12:16:02.102442026 CEST5704123192.168.2.1541.208.58.138
    Apr 22, 2024 12:16:02.102442026 CEST5704123192.168.2.15185.90.0.164
    Apr 22, 2024 12:16:02.102443933 CEST5704123192.168.2.15124.165.14.19
    Apr 22, 2024 12:16:02.102463961 CEST5704123192.168.2.154.55.82.119
    Apr 22, 2024 12:16:02.102485895 CEST5704123192.168.2.15141.33.226.28
    Apr 22, 2024 12:16:02.102495909 CEST5704123192.168.2.1591.125.185.26
    Apr 22, 2024 12:16:02.102511883 CEST5704123192.168.2.1559.83.39.52
    Apr 22, 2024 12:16:02.102514029 CEST5704123192.168.2.15160.160.40.103
    Apr 22, 2024 12:16:02.102514029 CEST5704123192.168.2.15121.247.193.158
    Apr 22, 2024 12:16:02.102521896 CEST5704123192.168.2.15101.254.50.42
    Apr 22, 2024 12:16:02.102521896 CEST5704123192.168.2.1563.57.185.160
    Apr 22, 2024 12:16:02.102524042 CEST5704123192.168.2.15120.248.17.191
    Apr 22, 2024 12:16:02.102524996 CEST5704123192.168.2.15216.150.8.151
    Apr 22, 2024 12:16:02.102539062 CEST5704123192.168.2.1594.105.141.31
    Apr 22, 2024 12:16:02.102546930 CEST5704123192.168.2.15142.197.242.49
    Apr 22, 2024 12:16:02.102567911 CEST5704123192.168.2.15126.248.183.192
    Apr 22, 2024 12:16:02.102569103 CEST5704123192.168.2.15164.244.193.242
    Apr 22, 2024 12:16:02.102581024 CEST5704123192.168.2.1539.12.230.95
    Apr 22, 2024 12:16:02.102595091 CEST5704123192.168.2.1532.182.95.199
    Apr 22, 2024 12:16:02.102595091 CEST5704123192.168.2.15120.23.197.120
    Apr 22, 2024 12:16:02.109785080 CEST3625256730192.168.2.1591.228.147.116
    Apr 22, 2024 12:16:02.219918966 CEST235704166.187.9.170192.168.2.15
    Apr 22, 2024 12:16:02.294472933 CEST2357041104.164.219.14192.168.2.15
    Apr 22, 2024 12:16:02.335402966 CEST235704177.116.143.25192.168.2.15
    Apr 22, 2024 12:16:02.335412025 CEST235704177.116.143.25192.168.2.15
    Apr 22, 2024 12:16:02.335594893 CEST5704123192.168.2.1577.116.143.25
    Apr 22, 2024 12:16:02.337296963 CEST235704194.45.105.110192.168.2.15
    Apr 22, 2024 12:16:02.343285084 CEST567303625291.228.147.116192.168.2.15
    Apr 22, 2024 12:16:02.343360901 CEST3625256730192.168.2.1591.228.147.116
    Apr 22, 2024 12:16:02.381958961 CEST2357041218.148.126.50192.168.2.15
    Apr 22, 2024 12:16:02.443008900 CEST2357041119.178.119.226192.168.2.15
    Apr 22, 2024 12:16:02.480827093 CEST2357041219.153.98.147192.168.2.15
    Apr 22, 2024 12:16:02.580312014 CEST2357041162.191.236.117192.168.2.15
    Apr 22, 2024 12:16:02.657449007 CEST2357041160.160.40.103192.168.2.15
    Apr 22, 2024 12:16:03.103621006 CEST5704123192.168.2.15104.238.45.83
    Apr 22, 2024 12:16:03.103631973 CEST5704123192.168.2.15115.56.172.141
    Apr 22, 2024 12:16:03.103638887 CEST5704123192.168.2.15112.152.2.92
    Apr 22, 2024 12:16:03.103638887 CEST5704123192.168.2.15141.136.17.187
    Apr 22, 2024 12:16:03.103647947 CEST5704123192.168.2.1586.161.164.77
    Apr 22, 2024 12:16:03.103646040 CEST5704123192.168.2.1517.237.121.189
    Apr 22, 2024 12:16:03.103647947 CEST5704123192.168.2.15103.38.186.87
    Apr 22, 2024 12:16:03.103646040 CEST5704123192.168.2.1536.239.58.227
    Apr 22, 2024 12:16:03.103653908 CEST5704123192.168.2.15138.114.216.212
    Apr 22, 2024 12:16:03.103653908 CEST5704123192.168.2.1596.31.250.182
    Apr 22, 2024 12:16:03.103653908 CEST5704123192.168.2.15149.248.157.83
    Apr 22, 2024 12:16:03.103674889 CEST5704123192.168.2.15219.147.247.119
    Apr 22, 2024 12:16:03.103674889 CEST5704123192.168.2.15201.44.11.53
    Apr 22, 2024 12:16:03.103682995 CEST5704123192.168.2.15203.103.214.252
    Apr 22, 2024 12:16:03.103684902 CEST5704123192.168.2.15196.66.210.193
    Apr 22, 2024 12:16:03.103684902 CEST5704123192.168.2.1536.36.150.117
    Apr 22, 2024 12:16:03.103684902 CEST5704123192.168.2.15193.191.75.216
    Apr 22, 2024 12:16:03.103687048 CEST5704123192.168.2.15206.75.206.252
    Apr 22, 2024 12:16:03.103692055 CEST5704123192.168.2.15145.251.140.229
    Apr 22, 2024 12:16:03.103692055 CEST5704123192.168.2.15168.37.172.206
    Apr 22, 2024 12:16:03.103692055 CEST5704123192.168.2.1532.205.243.218
    Apr 22, 2024 12:16:03.103692055 CEST5704123192.168.2.15218.249.228.248
    Apr 22, 2024 12:16:03.103703022 CEST5704123192.168.2.15124.70.83.31
    Apr 22, 2024 12:16:03.103710890 CEST5704123192.168.2.1536.41.196.241
    Apr 22, 2024 12:16:03.103710890 CEST5704123192.168.2.15139.190.162.212
    Apr 22, 2024 12:16:03.103724003 CEST5704123192.168.2.15209.197.105.101
    Apr 22, 2024 12:16:03.103724003 CEST5704123192.168.2.1599.128.87.141
    Apr 22, 2024 12:16:03.103729010 CEST5704123192.168.2.15133.224.248.204
    Apr 22, 2024 12:16:03.103729010 CEST5704123192.168.2.15148.208.160.191
    Apr 22, 2024 12:16:03.103729010 CEST5704123192.168.2.15142.85.133.218
    Apr 22, 2024 12:16:03.103733063 CEST5704123192.168.2.1594.86.23.49
    Apr 22, 2024 12:16:03.103765965 CEST5704123192.168.2.1536.157.27.80
    Apr 22, 2024 12:16:03.103765965 CEST5704123192.168.2.15202.125.69.20
    Apr 22, 2024 12:16:03.103765965 CEST5704123192.168.2.15176.169.92.237
    Apr 22, 2024 12:16:03.103769064 CEST5704123192.168.2.15217.118.128.185
    Apr 22, 2024 12:16:03.103769064 CEST5704123192.168.2.1527.176.66.144
    Apr 22, 2024 12:16:03.103769064 CEST5704123192.168.2.1591.81.20.101
    Apr 22, 2024 12:16:03.103777885 CEST5704123192.168.2.15168.9.90.3
    Apr 22, 2024 12:16:03.103779078 CEST5704123192.168.2.15157.41.211.217
    Apr 22, 2024 12:16:03.103779078 CEST5704123192.168.2.15195.133.89.28
    Apr 22, 2024 12:16:03.103780031 CEST5704123192.168.2.15148.209.40.33
    Apr 22, 2024 12:16:03.103779078 CEST5704123192.168.2.15174.202.161.127
    Apr 22, 2024 12:16:03.103780031 CEST5704123192.168.2.15212.101.125.9
    Apr 22, 2024 12:16:03.103780031 CEST5704123192.168.2.15172.138.170.62
    Apr 22, 2024 12:16:03.103780031 CEST5704123192.168.2.15187.42.101.62
    Apr 22, 2024 12:16:03.103780031 CEST5704123192.168.2.1576.50.59.142
    Apr 22, 2024 12:16:03.103780031 CEST5704123192.168.2.1520.192.103.239
    Apr 22, 2024 12:16:03.103785992 CEST5704123192.168.2.15120.15.210.162
    Apr 22, 2024 12:16:03.103785992 CEST5704123192.168.2.15120.167.13.70
    Apr 22, 2024 12:16:03.103787899 CEST5704123192.168.2.1574.3.120.75
    Apr 22, 2024 12:16:03.103796959 CEST5704123192.168.2.15189.245.50.7
    Apr 22, 2024 12:16:03.103796959 CEST5704123192.168.2.15213.158.87.245
    Apr 22, 2024 12:16:03.103796959 CEST5704123192.168.2.1569.68.135.62
    Apr 22, 2024 12:16:03.103799105 CEST5704123192.168.2.1523.229.176.54
    Apr 22, 2024 12:16:03.103800058 CEST5704123192.168.2.1542.156.254.168
    Apr 22, 2024 12:16:03.103801012 CEST5704123192.168.2.15190.205.241.67
    Apr 22, 2024 12:16:03.103801012 CEST5704123192.168.2.15223.221.125.221
    Apr 22, 2024 12:16:03.103806019 CEST5704123192.168.2.1541.179.49.187
    Apr 22, 2024 12:16:03.103815079 CEST5704123192.168.2.15137.44.156.210
    Apr 22, 2024 12:16:03.103815079 CEST5704123192.168.2.15115.41.120.136
    Apr 22, 2024 12:16:03.103815079 CEST5704123192.168.2.15222.28.187.163
    Apr 22, 2024 12:16:03.103817940 CEST5704123192.168.2.15104.201.191.210
    Apr 22, 2024 12:16:03.103826046 CEST5704123192.168.2.1571.126.226.125
    Apr 22, 2024 12:16:03.103826046 CEST5704123192.168.2.15114.178.195.249
    Apr 22, 2024 12:16:03.103826046 CEST5704123192.168.2.15203.250.219.211
    Apr 22, 2024 12:16:03.103826046 CEST5704123192.168.2.1595.224.190.14
    Apr 22, 2024 12:16:03.103826046 CEST5704123192.168.2.1557.109.192.81
    Apr 22, 2024 12:16:03.103826046 CEST5704123192.168.2.1547.169.39.191
    Apr 22, 2024 12:16:03.103827953 CEST5704123192.168.2.15196.119.39.156
    Apr 22, 2024 12:16:03.103827953 CEST5704123192.168.2.15197.186.182.208
    Apr 22, 2024 12:16:03.103827953 CEST5704123192.168.2.1541.29.173.24
    Apr 22, 2024 12:16:03.103827953 CEST5704123192.168.2.15156.106.26.148
    Apr 22, 2024 12:16:03.103832960 CEST5704123192.168.2.1583.191.248.143
    Apr 22, 2024 12:16:03.103832960 CEST5704123192.168.2.15125.168.149.13
    Apr 22, 2024 12:16:03.103833914 CEST5704123192.168.2.1547.93.137.201
    Apr 22, 2024 12:16:03.103835106 CEST5704123192.168.2.15210.225.84.47
    Apr 22, 2024 12:16:03.103836060 CEST5704123192.168.2.15189.246.117.76
    Apr 22, 2024 12:16:03.103863955 CEST5704123192.168.2.15111.123.61.125
    Apr 22, 2024 12:16:03.103864908 CEST5704123192.168.2.15197.188.90.245
    Apr 22, 2024 12:16:03.103873014 CEST5704123192.168.2.1592.79.79.251
    Apr 22, 2024 12:16:03.103873014 CEST5704123192.168.2.1520.20.53.101
    Apr 22, 2024 12:16:03.103873014 CEST5704123192.168.2.1558.142.88.242
    Apr 22, 2024 12:16:03.103873014 CEST5704123192.168.2.15104.7.105.98
    Apr 22, 2024 12:16:03.103878975 CEST5704123192.168.2.15186.112.246.251
    Apr 22, 2024 12:16:03.103879929 CEST5704123192.168.2.1589.80.244.147
    Apr 22, 2024 12:16:03.103882074 CEST5704123192.168.2.1580.236.252.137
    Apr 22, 2024 12:16:03.103882074 CEST5704123192.168.2.15113.129.36.183
    Apr 22, 2024 12:16:03.103883028 CEST5704123192.168.2.15174.13.7.207
    Apr 22, 2024 12:16:03.103883028 CEST5704123192.168.2.15193.160.133.72
    Apr 22, 2024 12:16:03.103894949 CEST5704123192.168.2.15168.105.65.77
    Apr 22, 2024 12:16:03.103895903 CEST5704123192.168.2.15155.201.186.85
    Apr 22, 2024 12:16:03.103894949 CEST5704123192.168.2.15106.123.228.3
    Apr 22, 2024 12:16:03.103903055 CEST5704123192.168.2.15131.242.51.136
    Apr 22, 2024 12:16:03.103903055 CEST5704123192.168.2.15206.110.34.173
    Apr 22, 2024 12:16:03.103910923 CEST5704123192.168.2.15161.31.161.4
    Apr 22, 2024 12:16:03.103910923 CEST5704123192.168.2.1535.247.144.126
    Apr 22, 2024 12:16:03.103912115 CEST5704123192.168.2.15222.123.211.169
    Apr 22, 2024 12:16:03.103912115 CEST5704123192.168.2.15173.82.74.240
    Apr 22, 2024 12:16:03.103939056 CEST5704123192.168.2.15171.101.107.229
    Apr 22, 2024 12:16:03.103940010 CEST5704123192.168.2.15132.8.64.111
    Apr 22, 2024 12:16:03.103943110 CEST5704123192.168.2.15139.95.60.144
    Apr 22, 2024 12:16:03.103943110 CEST5704123192.168.2.15109.164.7.235
    Apr 22, 2024 12:16:03.103943110 CEST5704123192.168.2.15171.196.51.164
    Apr 22, 2024 12:16:03.103950024 CEST5704123192.168.2.1551.175.210.52
    Apr 22, 2024 12:16:03.103950024 CEST5704123192.168.2.1543.241.176.216
    Apr 22, 2024 12:16:03.103950024 CEST5704123192.168.2.1577.40.29.77
    Apr 22, 2024 12:16:03.103950977 CEST5704123192.168.2.159.37.190.7
    Apr 22, 2024 12:16:03.103957891 CEST5704123192.168.2.1571.167.48.158
    Apr 22, 2024 12:16:03.103957891 CEST5704123192.168.2.15172.197.51.101
    Apr 22, 2024 12:16:03.103965998 CEST5704123192.168.2.15108.156.143.196
    Apr 22, 2024 12:16:03.103965998 CEST5704123192.168.2.1527.187.152.126
    Apr 22, 2024 12:16:03.103965998 CEST5704123192.168.2.15157.8.122.110
    Apr 22, 2024 12:16:03.103965998 CEST5704123192.168.2.15109.98.66.195
    Apr 22, 2024 12:16:03.103971958 CEST5704123192.168.2.15189.135.65.148
    Apr 22, 2024 12:16:03.103981972 CEST5704123192.168.2.15185.6.69.47
    Apr 22, 2024 12:16:03.103985071 CEST5704123192.168.2.15158.35.3.95
    Apr 22, 2024 12:16:03.103991985 CEST5704123192.168.2.15217.17.18.79
    Apr 22, 2024 12:16:03.103991985 CEST5704123192.168.2.1539.26.17.88
    Apr 22, 2024 12:16:03.104002953 CEST5704123192.168.2.15140.134.200.162
    Apr 22, 2024 12:16:03.104002953 CEST5704123192.168.2.1560.121.82.244
    Apr 22, 2024 12:16:03.104013920 CEST5704123192.168.2.1540.111.143.189
    Apr 22, 2024 12:16:03.104013920 CEST5704123192.168.2.15171.171.4.111
    Apr 22, 2024 12:16:03.104013920 CEST5704123192.168.2.1517.192.66.171
    Apr 22, 2024 12:16:03.104016066 CEST5704123192.168.2.15161.174.160.177
    Apr 22, 2024 12:16:03.104053974 CEST5704123192.168.2.152.187.248.172
    Apr 22, 2024 12:16:03.104054928 CEST5704123192.168.2.15128.69.187.179
    Apr 22, 2024 12:16:03.104053974 CEST5704123192.168.2.1569.238.219.195
    Apr 22, 2024 12:16:03.104053974 CEST5704123192.168.2.15171.247.84.13
    Apr 22, 2024 12:16:03.104062080 CEST5704123192.168.2.15184.177.76.248
    Apr 22, 2024 12:16:03.104062080 CEST5704123192.168.2.15104.162.153.191
    Apr 22, 2024 12:16:03.104069948 CEST5704123192.168.2.1585.88.229.240
    Apr 22, 2024 12:16:03.104077101 CEST5704123192.168.2.15109.198.146.241
    Apr 22, 2024 12:16:03.104077101 CEST5704123192.168.2.15222.161.31.9
    Apr 22, 2024 12:16:03.104084015 CEST5704123192.168.2.1581.49.108.252
    Apr 22, 2024 12:16:03.104089022 CEST5704123192.168.2.1581.108.238.180
    Apr 22, 2024 12:16:03.104104996 CEST5704123192.168.2.15175.152.20.50
    Apr 22, 2024 12:16:03.104104996 CEST5704123192.168.2.15170.31.12.56
    Apr 22, 2024 12:16:03.104113102 CEST5704123192.168.2.15210.90.15.43
    Apr 22, 2024 12:16:03.104115963 CEST5704123192.168.2.1568.87.228.104
    Apr 22, 2024 12:16:03.104116917 CEST5704123192.168.2.1570.201.30.66
    Apr 22, 2024 12:16:03.104116917 CEST5704123192.168.2.15148.137.189.78
    Apr 22, 2024 12:16:03.104120970 CEST5704123192.168.2.15137.218.48.225
    Apr 22, 2024 12:16:03.104120970 CEST5704123192.168.2.15154.167.24.205
    Apr 22, 2024 12:16:03.104120970 CEST5704123192.168.2.15120.115.199.93
    Apr 22, 2024 12:16:03.104124069 CEST5704123192.168.2.15190.74.55.207
    Apr 22, 2024 12:16:03.104130030 CEST5704123192.168.2.15141.181.23.66
    Apr 22, 2024 12:16:03.104131937 CEST5704123192.168.2.15184.197.22.221
    Apr 22, 2024 12:16:03.104132891 CEST5704123192.168.2.15109.75.225.212
    Apr 22, 2024 12:16:03.104146004 CEST5704123192.168.2.15128.173.12.195
    Apr 22, 2024 12:16:03.104146957 CEST5704123192.168.2.15141.6.47.136
    Apr 22, 2024 12:16:03.104177952 CEST5704123192.168.2.15213.235.242.176
    Apr 22, 2024 12:16:03.104177952 CEST5704123192.168.2.15171.243.112.180
    Apr 22, 2024 12:16:03.104178905 CEST5704123192.168.2.15120.104.33.220
    Apr 22, 2024 12:16:03.104177952 CEST5704123192.168.2.15142.63.198.132
    Apr 22, 2024 12:16:03.104177952 CEST5704123192.168.2.15170.248.148.133
    Apr 22, 2024 12:16:03.104188919 CEST5704123192.168.2.15162.76.26.38
    Apr 22, 2024 12:16:03.104193926 CEST5704123192.168.2.1539.208.135.97
    Apr 22, 2024 12:16:03.104193926 CEST5704123192.168.2.1577.101.23.49
    Apr 22, 2024 12:16:03.104193926 CEST5704123192.168.2.15147.13.55.251
    Apr 22, 2024 12:16:03.104195118 CEST5704123192.168.2.15192.117.185.163
    Apr 22, 2024 12:16:03.104204893 CEST5704123192.168.2.15163.49.133.103
    Apr 22, 2024 12:16:03.104204893 CEST5704123192.168.2.15168.7.167.18
    Apr 22, 2024 12:16:03.104207993 CEST5704123192.168.2.1565.195.30.245
    Apr 22, 2024 12:16:03.104207993 CEST5704123192.168.2.1586.212.132.127
    Apr 22, 2024 12:16:03.104207993 CEST5704123192.168.2.15169.93.81.200
    Apr 22, 2024 12:16:03.104207993 CEST5704123192.168.2.15124.169.132.56
    Apr 22, 2024 12:16:03.104207993 CEST5704123192.168.2.15223.236.188.35
    Apr 22, 2024 12:16:03.104208946 CEST5704123192.168.2.15157.209.227.109
    Apr 22, 2024 12:16:03.104207993 CEST5704123192.168.2.15193.180.134.170
    Apr 22, 2024 12:16:03.104208946 CEST5704123192.168.2.15132.174.198.222
    Apr 22, 2024 12:16:03.104207993 CEST5704123192.168.2.1594.29.78.122
    Apr 22, 2024 12:16:03.104208946 CEST5704123192.168.2.15195.248.124.180
    Apr 22, 2024 12:16:03.104207993 CEST5704123192.168.2.15163.187.236.53
    Apr 22, 2024 12:16:03.104207993 CEST5704123192.168.2.1583.135.94.213
    Apr 22, 2024 12:16:03.104222059 CEST5704123192.168.2.15176.52.50.166
    Apr 22, 2024 12:16:03.104222059 CEST5704123192.168.2.15203.219.235.129
    Apr 22, 2024 12:16:03.104222059 CEST5704123192.168.2.15201.244.236.46
    Apr 22, 2024 12:16:03.104223013 CEST5704123192.168.2.1559.162.57.164
    Apr 22, 2024 12:16:03.104222059 CEST5704123192.168.2.15192.88.210.73
    Apr 22, 2024 12:16:03.104226112 CEST5704123192.168.2.1589.57.108.11
    Apr 22, 2024 12:16:03.104226112 CEST5704123192.168.2.15142.29.206.162
    Apr 22, 2024 12:16:03.104228020 CEST5704123192.168.2.1564.133.241.168
    Apr 22, 2024 12:16:03.104228020 CEST5704123192.168.2.15118.58.220.200
    Apr 22, 2024 12:16:03.104228020 CEST5704123192.168.2.1531.99.201.84
    Apr 22, 2024 12:16:03.104228020 CEST5704123192.168.2.15223.158.125.219
    Apr 22, 2024 12:16:03.104229927 CEST5704123192.168.2.1538.208.191.131
    Apr 22, 2024 12:16:03.104229927 CEST5704123192.168.2.15124.105.19.108
    Apr 22, 2024 12:16:03.104240894 CEST5704123192.168.2.1517.203.144.208
    Apr 22, 2024 12:16:03.104255915 CEST5704123192.168.2.1544.245.166.155
    Apr 22, 2024 12:16:03.104255915 CEST5704123192.168.2.1513.40.65.101
    Apr 22, 2024 12:16:03.104260921 CEST5704123192.168.2.15112.178.174.15
    Apr 22, 2024 12:16:03.104264975 CEST5704123192.168.2.1518.214.103.73
    Apr 22, 2024 12:16:03.104274035 CEST5704123192.168.2.1532.134.192.181
    Apr 22, 2024 12:16:03.104274035 CEST5704123192.168.2.15114.107.1.44
    Apr 22, 2024 12:16:03.104274035 CEST5704123192.168.2.15218.224.225.52
    Apr 22, 2024 12:16:03.104274035 CEST5704123192.168.2.15222.24.48.4
    Apr 22, 2024 12:16:03.104274035 CEST5704123192.168.2.1534.72.179.158
    Apr 22, 2024 12:16:03.104274035 CEST5704123192.168.2.15118.83.127.149
    Apr 22, 2024 12:16:03.104276896 CEST5704123192.168.2.158.173.88.211
    Apr 22, 2024 12:16:03.104274035 CEST5704123192.168.2.1575.54.187.78
    Apr 22, 2024 12:16:03.104276896 CEST5704123192.168.2.15125.151.88.169
    Apr 22, 2024 12:16:03.104274035 CEST5704123192.168.2.1593.131.103.12
    Apr 22, 2024 12:16:03.104276896 CEST5704123192.168.2.15145.2.186.70
    Apr 22, 2024 12:16:03.104276896 CEST5704123192.168.2.15145.10.241.158
    Apr 22, 2024 12:16:03.104279995 CEST5704123192.168.2.1553.97.157.133
    Apr 22, 2024 12:16:03.104279995 CEST5704123192.168.2.15145.197.56.171
    Apr 22, 2024 12:16:03.104279995 CEST5704123192.168.2.15140.233.94.56
    Apr 22, 2024 12:16:03.104279995 CEST5704123192.168.2.1599.217.192.5
    Apr 22, 2024 12:16:03.104279995 CEST5704123192.168.2.1546.236.212.247
    Apr 22, 2024 12:16:03.104279995 CEST5704123192.168.2.1559.227.21.250
    Apr 22, 2024 12:16:03.104279995 CEST5704123192.168.2.1512.194.93.154
    Apr 22, 2024 12:16:03.104279995 CEST5704123192.168.2.1513.134.244.116
    Apr 22, 2024 12:16:03.104289055 CEST5704123192.168.2.15160.49.188.128
    Apr 22, 2024 12:16:03.104293108 CEST5704123192.168.2.15115.91.201.228
    Apr 22, 2024 12:16:03.104295969 CEST5704123192.168.2.1572.176.112.170
    Apr 22, 2024 12:16:03.104295969 CEST5704123192.168.2.1517.212.162.181
    Apr 22, 2024 12:16:03.104301929 CEST5704123192.168.2.15116.152.149.5
    Apr 22, 2024 12:16:03.104310989 CEST5704123192.168.2.15132.108.177.6
    Apr 22, 2024 12:16:03.104311943 CEST5704123192.168.2.15180.152.167.73
    Apr 22, 2024 12:16:03.104321003 CEST5704123192.168.2.15209.38.199.215
    Apr 22, 2024 12:16:03.104331017 CEST5704123192.168.2.1575.173.17.50
    Apr 22, 2024 12:16:03.104331017 CEST5704123192.168.2.1568.91.127.9
    Apr 22, 2024 12:16:03.104331017 CEST5704123192.168.2.15164.182.254.205
    Apr 22, 2024 12:16:03.104331017 CEST5704123192.168.2.15100.8.41.133
    Apr 22, 2024 12:16:03.104334116 CEST5704123192.168.2.1547.82.186.237
    Apr 22, 2024 12:16:03.104334116 CEST5704123192.168.2.15180.15.109.249
    Apr 22, 2024 12:16:03.104338884 CEST5704123192.168.2.15143.50.94.154
    Apr 22, 2024 12:16:03.104338884 CEST5704123192.168.2.15102.161.163.158
    Apr 22, 2024 12:16:03.104338884 CEST5704123192.168.2.1597.7.175.189
    Apr 22, 2024 12:16:03.104338884 CEST5704123192.168.2.15196.225.226.187
    Apr 22, 2024 12:16:03.104346037 CEST5704123192.168.2.15206.187.151.148
    Apr 22, 2024 12:16:03.104347944 CEST5704123192.168.2.1562.9.191.201
    Apr 22, 2024 12:16:03.104373932 CEST5704123192.168.2.15197.27.150.208
    Apr 22, 2024 12:16:03.104373932 CEST5704123192.168.2.1540.111.65.196
    Apr 22, 2024 12:16:03.104376078 CEST5704123192.168.2.15184.46.152.175
    Apr 22, 2024 12:16:03.104376078 CEST5704123192.168.2.15190.106.197.192
    Apr 22, 2024 12:16:03.104377031 CEST5704123192.168.2.15139.176.73.151
    Apr 22, 2024 12:16:03.104377031 CEST5704123192.168.2.1578.155.128.95
    Apr 22, 2024 12:16:03.104376078 CEST5704123192.168.2.15168.16.110.72
    Apr 22, 2024 12:16:03.104394913 CEST5704123192.168.2.15108.142.124.193
    Apr 22, 2024 12:16:03.104396105 CEST5704123192.168.2.1584.140.7.173
    Apr 22, 2024 12:16:03.104396105 CEST5704123192.168.2.15181.113.13.92
    Apr 22, 2024 12:16:03.104396105 CEST5704123192.168.2.15216.83.84.228
    Apr 22, 2024 12:16:03.104397058 CEST5704123192.168.2.15182.55.164.152
    Apr 22, 2024 12:16:03.104396105 CEST5704123192.168.2.1591.140.188.174
    Apr 22, 2024 12:16:03.104397058 CEST5704123192.168.2.15112.225.132.232
    Apr 22, 2024 12:16:03.104396105 CEST5704123192.168.2.151.104.79.246
    Apr 22, 2024 12:16:03.104397058 CEST5704123192.168.2.15104.100.206.46
    Apr 22, 2024 12:16:03.104403973 CEST5704123192.168.2.15144.156.210.214
    Apr 22, 2024 12:16:03.104403973 CEST5704123192.168.2.159.252.23.200
    Apr 22, 2024 12:16:03.104406118 CEST5704123192.168.2.1575.151.246.48
    Apr 22, 2024 12:16:03.104406118 CEST5704123192.168.2.1539.218.57.253
    Apr 22, 2024 12:16:03.104406118 CEST5704123192.168.2.1559.44.29.84
    Apr 22, 2024 12:16:03.104445934 CEST5704123192.168.2.15196.144.133.60
    Apr 22, 2024 12:16:03.104445934 CEST5704123192.168.2.15109.18.197.137
    Apr 22, 2024 12:16:03.104445934 CEST5704123192.168.2.15219.93.252.82
    Apr 22, 2024 12:16:03.375744104 CEST3625256730192.168.2.1591.228.147.116
    Apr 22, 2024 12:16:03.388201952 CEST2357041125.151.88.169192.168.2.15
    Apr 22, 2024 12:16:03.393306971 CEST2357041112.178.174.15192.168.2.15
    Apr 22, 2024 12:16:03.395001888 CEST2357041196.66.210.193192.168.2.15
    Apr 22, 2024 12:16:03.609365940 CEST567303625291.228.147.116192.168.2.15
    Apr 22, 2024 12:16:03.609438896 CEST3625256730192.168.2.1591.228.147.116
    TimestampSource PortDest PortSource IPDest IP
    Apr 22, 2024 12:18:46.130846977 CEST5836353192.168.2.151.1.1.1
    Apr 22, 2024 12:18:46.130939960 CEST3284053192.168.2.151.1.1.1
    Apr 22, 2024 12:18:46.235168934 CEST53328401.1.1.1192.168.2.15
    Apr 22, 2024 12:18:46.235207081 CEST53583631.1.1.1192.168.2.15
    TimestampSource IPDest IPChecksumCodeType
    Apr 22, 2024 12:16:02.238519907 CEST67.21.225.9192.168.2.157b1e(Time to live exceeded in transit)Time Exceeded
    Apr 22, 2024 12:16:02.245626926 CEST154.54.88.42192.168.2.15b7f1(Time to live exceeded in transit)Time Exceeded
    Apr 22, 2024 12:16:02.247211933 CEST69.201.66.165192.168.2.154833(Unknown)Destination Unreachable
    Apr 22, 2024 12:16:02.301033020 CEST194.51.85.164192.168.2.15d4ff(Net unreachable)Destination Unreachable
    Apr 22, 2024 12:16:02.322993040 CEST217.95.175.253192.168.2.1594ac(Unknown)Destination Unreachable
    Apr 22, 2024 12:16:02.330267906 CEST95.118.106.84192.168.2.15543f(Unknown)Destination Unreachable
    Apr 22, 2024 12:16:02.336646080 CEST188.1.231.30192.168.2.152f10(Net unreachable)Destination Unreachable
    Apr 22, 2024 12:16:03.338985920 CEST83.135.94.213192.168.2.156bad(Unknown)Destination Unreachable
    Apr 22, 2024 12:16:03.362838030 CEST195.133.89.28192.168.2.15dc69(Unknown)Destination Unreachable
    Apr 22, 2024 12:16:03.392623901 CEST203.72.191.114192.168.2.15ffa2(Net unreachable)Destination Unreachable
    Apr 22, 2024 12:16:03.484013081 CEST103.26.244.1192.168.2.15c752(Time to live exceeded in transit)Time Exceeded
    Apr 22, 2024 12:16:04.361844063 CEST221.145.4.170192.168.2.15a08d(Host unreachable)Destination Unreachable
    TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
    Apr 22, 2024 12:18:46.130846977 CEST192.168.2.151.1.1.10xfa49Standard query (0)daisy.ubuntu.comA (IP address)IN (0x0001)false
    Apr 22, 2024 12:18:46.130939960 CEST192.168.2.151.1.1.10xd336Standard query (0)daisy.ubuntu.com28IN (0x0001)false
    TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
    Apr 22, 2024 12:18:46.235207081 CEST1.1.1.1192.168.2.150xfa49No error (0)daisy.ubuntu.com162.213.35.25A (IP address)IN (0x0001)false
    Apr 22, 2024 12:18:46.235207081 CEST1.1.1.1192.168.2.150xfa49No error (0)daisy.ubuntu.com162.213.35.24A (IP address)IN (0x0001)false

    System Behavior

    Start time (UTC):10:16:01
    Start date (UTC):22/04/2024
    Path:/tmp/wsskM49eA3.elf
    Arguments:/tmp/wsskM49eA3.elf
    File size:75664 bytes
    MD5 hash:59ccf2f294605b86339ca5d4015c0016

    Start time (UTC):10:16:01
    Start date (UTC):22/04/2024
    Path:/tmp/wsskM49eA3.elf
    Arguments:-
    File size:75664 bytes
    MD5 hash:59ccf2f294605b86339ca5d4015c0016

    Start time (UTC):10:16:01
    Start date (UTC):22/04/2024
    Path:/tmp/wsskM49eA3.elf
    Arguments:-
    File size:75664 bytes
    MD5 hash:59ccf2f294605b86339ca5d4015c0016

    Start time (UTC):10:16:01
    Start date (UTC):22/04/2024
    Path:/tmp/wsskM49eA3.elf
    Arguments:-
    File size:75664 bytes
    MD5 hash:59ccf2f294605b86339ca5d4015c0016

    Start time (UTC):10:16:01
    Start date (UTC):22/04/2024
    Path:/tmp/wsskM49eA3.elf
    Arguments:-
    File size:75664 bytes
    MD5 hash:59ccf2f294605b86339ca5d4015c0016

    Start time (UTC):10:16:01
    Start date (UTC):22/04/2024
    Path:/tmp/wsskM49eA3.elf
    Arguments:-
    File size:75664 bytes
    MD5 hash:59ccf2f294605b86339ca5d4015c0016
    Start time (UTC):10:16:01
    Start date (UTC):22/04/2024
    Path:/tmp/wsskM49eA3.elf
    Arguments:-
    File size:75664 bytes
    MD5 hash:59ccf2f294605b86339ca5d4015c0016