Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
mpsl.elf

Overview

General Information

Sample name:mpsl.elf
Analysis ID:1538769
MD5:eaf4f92882209af2ac633f3755b92284
SHA1:fe20895c65e750dd1fc0dd45445720ba952576a4
SHA256:ec5afbd33022308ae46716f3226b32620982da469fb81120939aeee2b386e857
Tags:elfuser-abuse_ch
Infos:

Detection

Mirai, Moobot
Score:100
Range:0 - 100
Whitelisted:false

Signatures

Antivirus / Scanner detection for submitted sample
Detected Mirai
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Suricata IDS alerts for network traffic
Yara detected Mirai
Yara detected Moobot
Connects to many ports of the same IP (likely port scanning)
Sample deletes itself
Detected TCP or UDP traffic on non-standard ports
Enumerates processes within the "proc" file system
Sample has stripped symbol table
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Uses the "uname" system call to query kernel version information (possible evasion)
Yara signature match

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1538769
Start date and time:2024-10-21 18:46:07 +02:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 39s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:mpsl.elf
Detection:MAL
Classification:mal100.troj.evad.linELF@0/0@24/0
  • VT rate limit hit for: mpsl.elf
Command:/tmp/mpsl.elf
PID:6243
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
done.
Standard Error:
  • system is lnxubuntu20
  • mpsl.elf (PID: 6243, Parent: 6165, MD5: 0d6f61f82cf2f781c6eb0661071d42d9) Arguments: /tmp/mpsl.elf
    • mpsl.elf New Fork (PID: 6245, Parent: 6243)
      • mpsl.elf New Fork (PID: 6247, Parent: 6245)
      • mpsl.elf New Fork (PID: 6249, Parent: 6245)
        • mpsl.elf New Fork (PID: 6251, Parent: 6249)
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
MiraiMirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese. Nowadays it targets a wide range of networked embedded devices such as IP cameras, home routers (many vendors involved), and other IoT devices. Since the source code was published on "Hack Forums" many variants of the Mirai family appeared, infecting mostly home networks all around the world.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/elf.mirai
NameDescriptionAttributionBlogpost URLsLink
MooBotNo Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/elf.moobot
SourceRuleDescriptionAuthorStrings
mpsl.elfJoeSecurity_MoobotYara detected MoobotJoe Security
    mpsl.elfJoeSecurity_Mirai_8Yara detected MiraiJoe Security
      mpsl.elfLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
      • 0xf4ac:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xf4c0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xf4d4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xf4e8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xf4fc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xf510:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xf524:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xf538:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xf54c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xf560:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xf574:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xf588:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xf59c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xf5b0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xf5c4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xf5d8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xf5ec:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xf600:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xf614:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xf628:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xf63c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      SourceRuleDescriptionAuthorStrings
      6243.1.00007ff9b4400000.00007ff9b4411000.r-x.sdmpJoeSecurity_MoobotYara detected MoobotJoe Security
        6243.1.00007ff9b4400000.00007ff9b4411000.r-x.sdmpJoeSecurity_Mirai_8Yara detected MiraiJoe Security
          6243.1.00007ff9b4400000.00007ff9b4411000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
          • 0xf4ac:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xf4c0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xf4d4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xf4e8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xf4fc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xf510:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xf524:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xf538:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xf54c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xf560:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xf574:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xf588:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xf59c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xf5b0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xf5c4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xf5d8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xf5ec:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xf600:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xf614:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xf628:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xf63c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          Process Memory Space: mpsl.elf PID: 6243JoeSecurity_MoobotYara detected MoobotJoe Security
            Process Memory Space: mpsl.elf PID: 6243JoeSecurity_Mirai_8Yara detected MiraiJoe Security
              Click to see the 1 entries
              TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
              2024-10-21T18:46:56.685755+020020304911Malware Command and Control Activity Detected192.168.2.2360532107.189.4.20158431TCP
              2024-10-21T18:47:02.114474+020020304911Malware Command and Control Activity Detected192.168.2.2360534107.189.4.20158431TCP
              2024-10-21T18:47:03.570774+020020304911Malware Command and Control Activity Detected192.168.2.2360536107.189.4.20158431TCP
              2024-10-21T18:47:08.044068+020020304911Malware Command and Control Activity Detected192.168.2.2360538107.189.4.20158431TCP
              2024-10-21T18:47:13.596698+020020304911Malware Command and Control Activity Detected192.168.2.2360540107.189.4.20158431TCP
              2024-10-21T18:47:21.028675+020020304911Malware Command and Control Activity Detected192.168.2.2360542107.189.4.20158431TCP
              2024-10-21T18:47:24.459662+020020304911Malware Command and Control Activity Detected192.168.2.2360544107.189.4.20158431TCP
              2024-10-21T18:47:28.892181+020020304911Malware Command and Control Activity Detected192.168.2.2360546107.189.4.20158431TCP
              2024-10-21T18:47:37.348328+020020304911Malware Command and Control Activity Detected192.168.2.2360548107.189.4.20158431TCP
              2024-10-21T18:47:47.784153+020020304911Malware Command and Control Activity Detected192.168.2.2360550107.189.4.20158431TCP
              2024-10-21T18:47:54.217105+020020304911Malware Command and Control Activity Detected192.168.2.2360552107.189.4.20158431TCP
              2024-10-21T18:47:56.788475+020020304911Malware Command and Control Activity Detected192.168.2.2360554107.189.4.20158431TCP
              2024-10-21T18:47:59.220557+020020304911Malware Command and Control Activity Detected192.168.2.2360556107.189.4.20158431TCP
              2024-10-21T18:48:04.652976+020020304911Malware Command and Control Activity Detected192.168.2.2360558107.189.4.20158431TCP
              2024-10-21T18:48:09.110620+020020304911Malware Command and Control Activity Detected192.168.2.2360560107.189.4.20158431TCP
              2024-10-21T18:48:11.540482+020020304911Malware Command and Control Activity Detected192.168.2.2360562107.189.4.20158431TCP
              2024-10-21T18:48:21.972963+020020304911Malware Command and Control Activity Detected192.168.2.2360564107.189.4.20158431TCP
              2024-10-21T18:48:27.403718+020020304911Malware Command and Control Activity Detected192.168.2.2360566107.189.4.20158431TCP
              2024-10-21T18:48:31.842157+020020304911Malware Command and Control Activity Detected192.168.2.2360568107.189.4.20158431TCP
              2024-10-21T18:48:37.390600+020020304911Malware Command and Control Activity Detected192.168.2.2360570107.189.4.20158431TCP
              2024-10-21T18:48:39.824204+020020304911Malware Command and Control Activity Detected192.168.2.2360572107.189.4.20158431TCP
              2024-10-21T18:48:45.269697+020020304911Malware Command and Control Activity Detected192.168.2.2360574107.189.4.20158431TCP
              2024-10-21T18:48:51.699905+020020304911Malware Command and Control Activity Detected192.168.2.2360576107.189.4.20158431TCP
              2024-10-21T18:49:00.134037+020020304911Malware Command and Control Activity Detected192.168.2.2360578107.189.4.20158431TCP

              Click to jump to signature section

              Show All Signature Results

              AV Detection

              barindex
              Source: mpsl.elfAvira: detected
              Source: mpsl.elfReversingLabs: Detection: 63%

              Networking

              barindex
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.23:60560 -> 107.189.4.201:58431
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.23:60544 -> 107.189.4.201:58431
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.23:60534 -> 107.189.4.201:58431
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.23:60542 -> 107.189.4.201:58431
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.23:60550 -> 107.189.4.201:58431
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.23:60574 -> 107.189.4.201:58431
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.23:60568 -> 107.189.4.201:58431
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.23:60548 -> 107.189.4.201:58431
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.23:60566 -> 107.189.4.201:58431
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.23:60570 -> 107.189.4.201:58431
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.23:60564 -> 107.189.4.201:58431
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.23:60536 -> 107.189.4.201:58431
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.23:60554 -> 107.189.4.201:58431
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.23:60558 -> 107.189.4.201:58431
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.23:60532 -> 107.189.4.201:58431
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.23:60538 -> 107.189.4.201:58431
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.23:60578 -> 107.189.4.201:58431
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.23:60576 -> 107.189.4.201:58431
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.23:60552 -> 107.189.4.201:58431
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.23:60572 -> 107.189.4.201:58431
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.23:60546 -> 107.189.4.201:58431
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.23:60556 -> 107.189.4.201:58431
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.23:60562 -> 107.189.4.201:58431
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.23:60540 -> 107.189.4.201:58431
              Source: global trafficTCP traffic: 107.189.4.201 ports 58431,1,3,4,5,8
              Source: global trafficTCP traffic: 192.168.2.23:60532 -> 107.189.4.201:58431
              Source: global trafficTCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
              Source: global trafficTCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
              Source: global trafficTCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
              Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
              Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
              Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
              Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
              Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
              Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
              Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
              Source: global trafficDNS traffic detected: DNS query: update.byeux.com
              Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443

              System Summary

              barindex
              Source: mpsl.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
              Source: 6243.1.00007ff9b4400000.00007ff9b4411000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
              Source: Process Memory Space: mpsl.elf PID: 6243, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
              Source: ELF static info symbol of initial sample.symtab present: no
              Source: mpsl.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
              Source: 6243.1.00007ff9b4400000.00007ff9b4411000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
              Source: Process Memory Space: mpsl.elf PID: 6243, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
              Source: classification engineClassification label: mal100.troj.evad.linELF@0/0@24/0
              Source: /tmp/mpsl.elf (PID: 6247)File opened: /proc/1582/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6247)File opened: /proc/3088/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6247)File opened: /proc/230/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6247)File opened: /proc/110/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6247)File opened: /proc/231/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6247)File opened: /proc/111/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6247)File opened: /proc/232/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6247)File opened: /proc/1579/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6247)File opened: /proc/112/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6247)File opened: /proc/233/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6247)File opened: /proc/1699/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6247)File opened: /proc/113/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6247)File opened: /proc/234/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6247)File opened: /proc/1335/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6247)File opened: /proc/1698/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6247)File opened: /proc/114/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6247)File opened: /proc/235/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6247)File opened: /proc/1334/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6247)File opened: /proc/1576/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6247)File opened: /proc/2302/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6247)File opened: /proc/115/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6247)File opened: /proc/236/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6247)File opened: /proc/116/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6247)File opened: /proc/237/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6247)File opened: /proc/117/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6247)File opened: /proc/118/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6247)File opened: /proc/910/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6247)File opened: /proc/6227/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6247)File opened: /proc/119/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6247)File opened: /proc/912/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6247)File opened: /proc/6228/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6247)File opened: /proc/10/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6247)File opened: /proc/2307/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6247)File opened: /proc/11/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6247)File opened: /proc/918/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6247)File opened: /proc/12/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6247)File opened: /proc/13/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6247)File opened: /proc/14/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6247)File opened: /proc/15/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6247)File opened: /proc/16/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6247)File opened: /proc/17/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6247)File opened: /proc/18/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6247)File opened: /proc/1594/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6247)File opened: /proc/120/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6247)File opened: /proc/121/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6247)File opened: /proc/1349/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6247)File opened: /proc/1/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6247)File opened: /proc/122/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6247)File opened: /proc/243/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6247)File opened: /proc/123/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6247)File opened: /proc/2/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6247)File opened: /proc/124/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6247)File opened: /proc/3/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6247)File opened: /proc/4/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6247)File opened: /proc/125/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6247)File opened: /proc/126/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6247)File opened: /proc/1344/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6247)File opened: /proc/1465/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6247)File opened: /proc/1586/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6247)File opened: /proc/127/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6247)File opened: /proc/6/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6247)File opened: /proc/248/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6247)File opened: /proc/128/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6247)File opened: /proc/249/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6247)File opened: /proc/1463/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6247)File opened: /proc/800/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6247)File opened: /proc/9/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6247)File opened: /proc/801/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6247)File opened: /proc/20/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6247)File opened: /proc/21/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6247)File opened: /proc/1900/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6247)File opened: /proc/22/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6247)File opened: /proc/23/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6247)File opened: /proc/6251/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6247)File opened: /proc/24/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6247)File opened: /proc/25/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6247)File opened: /proc/26/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6247)File opened: /proc/27/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6247)File opened: /proc/6134/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6247)File opened: /proc/28/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6247)File opened: /proc/29/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6247)File opened: /proc/491/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6247)File opened: /proc/250/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6247)File opened: /proc/130/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6247)File opened: /proc/251/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6247)File opened: /proc/252/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6247)File opened: /proc/132/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6247)File opened: /proc/253/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6247)File opened: /proc/254/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6247)File opened: /proc/255/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6247)File opened: /proc/4509/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6247)File opened: /proc/256/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6247)File opened: /proc/1599/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6247)File opened: /proc/257/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6247)File opened: /proc/1477/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6247)File opened: /proc/379/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6247)File opened: /proc/258/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6247)File opened: /proc/1476/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6247)File opened: /proc/259/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6247)File opened: /proc/1475/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6247)File opened: /proc/6249/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6247)File opened: /proc/936/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6247)File opened: /proc/30/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6247)File opened: /proc/2208/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6247)File opened: /proc/35/cmdlineJump to behavior

              Hooking and other Techniques for Hiding and Protection

              barindex
              Source: /tmp/mpsl.elf (PID: 6243)File: /tmp/mpsl.elfJump to behavior
              Source: /tmp/mpsl.elf (PID: 6243)Queries kernel information via 'uname': Jump to behavior
              Source: mpsl.elf, 6243.1.000055d08330d000.000055d083394000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/mipsel
              Source: mpsl.elf, 6243.1.00007ffd3cbde000.00007ffd3cbff000.rw-.sdmpBinary or memory string: N#x86_64/usr/bin/qemu-mipsel/tmp/mpsl.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/mpsl.elf
              Source: mpsl.elf, 6243.1.000055d08330d000.000055d083394000.rw-.sdmpBinary or memory string: U!/etc/qemu-binfmt/mipsel
              Source: mpsl.elf, 6243.1.00007ffd3cbde000.00007ffd3cbff000.rw-.sdmpBinary or memory string: /usr/bin/qemu-mipsel

              Stealing of Sensitive Information

              barindex
              Source: Yara matchFile source: mpsl.elf, type: SAMPLE
              Source: Yara matchFile source: 6243.1.00007ff9b4400000.00007ff9b4411000.r-x.sdmp, type: MEMORY
              Source: Yara matchFile source: Process Memory Space: mpsl.elf PID: 6243, type: MEMORYSTR
              Source: Yara matchFile source: mpsl.elf, type: SAMPLE
              Source: Yara matchFile source: 6243.1.00007ff9b4400000.00007ff9b4411000.r-x.sdmp, type: MEMORY
              Source: Yara matchFile source: Process Memory Space: mpsl.elf PID: 6243, type: MEMORYSTR

              Remote Access Functionality

              barindex
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: Yara matchFile source: mpsl.elf, type: SAMPLE
              Source: Yara matchFile source: 6243.1.00007ff9b4400000.00007ff9b4411000.r-x.sdmp, type: MEMORY
              Source: Yara matchFile source: Process Memory Space: mpsl.elf PID: 6243, type: MEMORYSTR
              Source: Yara matchFile source: mpsl.elf, type: SAMPLE
              Source: Yara matchFile source: 6243.1.00007ff9b4400000.00007ff9b4411000.r-x.sdmp, type: MEMORY
              Source: Yara matchFile source: Process Memory Space: mpsl.elf PID: 6243, type: MEMORYSTR
              ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
              Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception1
              File Deletion
              1
              OS Credential Dumping
              11
              Security Software Discovery
              Remote ServicesData from Local System1
              Encrypted Channel
              Exfiltration Over Other Network MediumAbuse Accessibility Features
              CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
              Non-Standard Port
              Exfiltration Over BluetoothNetwork Denial of Service
              Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
              Non-Application Layer Protocol
              Automated ExfiltrationData Encrypted for Impact
              Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture2
              Application Layer Protocol
              Traffic DuplicationData Destruction
              No configs have been found
              Hide Legend

              Legend:

              • Process
              • Signature
              • Created File
              • DNS/IP Info
              • Is Dropped
              • Number of created Files
              • Is malicious
              • Internet
              behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1538769 Sample: mpsl.elf Startdate: 21/10/2024 Architecture: LINUX Score: 100 20 update.byeux.com 107.189.4.201, 58431, 60532, 60534 PONYNETUS United States 2->20 22 109.202.202.202, 80 INIT7CH Switzerland 2->22 24 2 other IPs or domains 2->24 26 Suricata IDS alerts for network traffic 2->26 28 Malicious sample detected (through community Yara rule) 2->28 30 Antivirus / Scanner detection for submitted sample 2->30 32 5 other signatures 2->32 9 mpsl.elf 2->9         started        signatures3 process4 signatures5 34 Sample deletes itself 9->34 12 mpsl.elf 9->12         started        process6 process7 14 mpsl.elf 12->14         started        16 mpsl.elf 12->16         started        process8 18 mpsl.elf 14->18         started       
              SourceDetectionScannerLabelLink
              mpsl.elf63%ReversingLabsLinux.Backdoor.Mirai
              mpsl.elf100%AviraEXP/ELF.Mirai.Z.A
              No Antivirus matches
              No Antivirus matches
              No Antivirus matches
              NameIPActiveMaliciousAntivirus DetectionReputation
              update.byeux.com
              107.189.4.201
              truetrue
                unknown
                • No. of IPs < 25%
                • 25% < No. of IPs < 50%
                • 50% < No. of IPs < 75%
                • 75% < No. of IPs
                IPDomainCountryFlagASNASN NameMalicious
                107.189.4.201
                update.byeux.comUnited States
                53667PONYNETUStrue
                109.202.202.202
                unknownSwitzerland
                13030INIT7CHfalse
                91.189.91.43
                unknownUnited Kingdom
                41231CANONICAL-ASGBfalse
                91.189.91.42
                unknownUnited Kingdom
                41231CANONICAL-ASGBfalse
                MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                107.189.4.201JVL2bXW1ch.elfGet hashmaliciousMirai, MoobotBrowse
                  arm7.elfGet hashmaliciousMirai, MoobotBrowse
                    mips.elfGet hashmaliciousMirai, MoobotBrowse
                      109.202.202.202kpLwzBouH4.elfGet hashmaliciousUnknownBrowse
                      • ch.archive.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_92.0%2bbuild3-0ubuntu0.20.04.1_amd64.deb
                      91.189.91.43mirai.arm5.elfGet hashmaliciousUnknownBrowse
                        tftp.elfGet hashmaliciousUnknownBrowse
                          4.elfGet hashmaliciousUnknownBrowse
                            sparc.elfGet hashmaliciousGafgyt, MiraiBrowse
                              m68k.elfGet hashmaliciousGafgyt, MiraiBrowse
                                meow.arm.elfGet hashmaliciousUnknownBrowse
                                  bot.mpsl.elfGet hashmaliciousMirai, Gafgyt, OkiruBrowse
                                    mirai.mips.elfGet hashmaliciousUnknownBrowse
                                      bot.ppc.elfGet hashmaliciousMirai, Gafgyt, OkiruBrowse
                                        bot.arm5.elfGet hashmaliciousMirai, Gafgyt, OkiruBrowse
                                          91.189.91.42mirai.arm5.elfGet hashmaliciousUnknownBrowse
                                            tftp.elfGet hashmaliciousUnknownBrowse
                                              4.elfGet hashmaliciousUnknownBrowse
                                                sparc.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                  m68k.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                    meow.arm.elfGet hashmaliciousUnknownBrowse
                                                      bot.x86_64.elfGet hashmaliciousMirai, Gafgyt, OkiruBrowse
                                                        x86.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                          bot.mpsl.elfGet hashmaliciousMirai, Gafgyt, OkiruBrowse
                                                            mirai.mips.elfGet hashmaliciousUnknownBrowse
                                                              MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                              update.byeux.comJVL2bXW1ch.elfGet hashmaliciousMirai, MoobotBrowse
                                                              • 107.189.4.201
                                                              arm7.elfGet hashmaliciousMirai, MoobotBrowse
                                                              • 107.189.4.201
                                                              mips.elfGet hashmaliciousMirai, MoobotBrowse
                                                              • 107.189.4.201
                                                              MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                              CANONICAL-ASGBmirai.arm5.elfGet hashmaliciousUnknownBrowse
                                                              • 91.189.91.42
                                                              tftp.elfGet hashmaliciousUnknownBrowse
                                                              • 91.189.91.42
                                                              4.elfGet hashmaliciousUnknownBrowse
                                                              • 91.189.91.42
                                                              sparc.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                              • 91.189.91.42
                                                              m68k.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                              • 91.189.91.42
                                                              meow.arm.elfGet hashmaliciousUnknownBrowse
                                                              • 91.189.91.42
                                                              bot.x86_64.elfGet hashmaliciousMirai, Gafgyt, OkiruBrowse
                                                              • 91.189.91.42
                                                              x86.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                              • 91.189.91.42
                                                              bot.mpsl.elfGet hashmaliciousMirai, Gafgyt, OkiruBrowse
                                                              • 91.189.91.42
                                                              mirai.mips.elfGet hashmaliciousUnknownBrowse
                                                              • 91.189.91.42
                                                              CANONICAL-ASGBmirai.arm5.elfGet hashmaliciousUnknownBrowse
                                                              • 91.189.91.42
                                                              tftp.elfGet hashmaliciousUnknownBrowse
                                                              • 91.189.91.42
                                                              4.elfGet hashmaliciousUnknownBrowse
                                                              • 91.189.91.42
                                                              sparc.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                              • 91.189.91.42
                                                              m68k.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                              • 91.189.91.42
                                                              meow.arm.elfGet hashmaliciousUnknownBrowse
                                                              • 91.189.91.42
                                                              bot.x86_64.elfGet hashmaliciousMirai, Gafgyt, OkiruBrowse
                                                              • 91.189.91.42
                                                              x86.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                              • 91.189.91.42
                                                              bot.mpsl.elfGet hashmaliciousMirai, Gafgyt, OkiruBrowse
                                                              • 91.189.91.42
                                                              mirai.mips.elfGet hashmaliciousUnknownBrowse
                                                              • 91.189.91.42
                                                              INIT7CHmirai.arm5.elfGet hashmaliciousUnknownBrowse
                                                              • 109.202.202.202
                                                              tftp.elfGet hashmaliciousUnknownBrowse
                                                              • 109.202.202.202
                                                              4.elfGet hashmaliciousUnknownBrowse
                                                              • 109.202.202.202
                                                              sparc.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                              • 109.202.202.202
                                                              m68k.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                              • 109.202.202.202
                                                              meow.arm.elfGet hashmaliciousUnknownBrowse
                                                              • 109.202.202.202
                                                              bot.x86_64.elfGet hashmaliciousMirai, Gafgyt, OkiruBrowse
                                                              • 109.202.202.202
                                                              x86.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                              • 109.202.202.202
                                                              bot.mpsl.elfGet hashmaliciousMirai, Gafgyt, OkiruBrowse
                                                              • 109.202.202.202
                                                              mirai.mips.elfGet hashmaliciousUnknownBrowse
                                                              • 109.202.202.202
                                                              PONYNETUSdss.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                              • 209.141.42.202
                                                              co.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                              • 209.141.42.202
                                                              586.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                              • 209.141.42.202
                                                              __min__c.elfGet hashmaliciousUnknownBrowse
                                                              • 205.185.117.101
                                                              co.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                              • 205.185.122.67
                                                              x86.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                              • 205.185.122.67
                                                              https://shoutout.wix.com/so/abP9tNDlV/c?w=3l7661HU1QXfrlxhsiEng39pDUk08HpBaevjMtJB-KM.eyJ1IjoiaHR0cHM6Ly92ZXJpZnlmaWxlcy5naXRodWIuaW8vbWFuLyIsInIiOiI1N2VlOTAzYy01NWI5LTQzMWEtMzQ0Yi1lM2Y2MTY0YTdiNDIiLCJtIjoibWFpbCIsImMiOiIzNjA5ODM5OC0zMzdiLTQyZjUtYTE5MC1iMmU1MTdiZmVkNmMifQGet hashmaliciousHTMLPhisherBrowse
                                                              • 162.244.94.12
                                                              QgmKRZO1Yp.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                              • 205.185.122.67
                                                              zOSCVTuLxE.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                              • 205.185.122.67
                                                              8t8VJiEGar.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                              • 205.185.122.67
                                                              No context
                                                              No context
                                                              No created / dropped files found
                                                              File type:ELF 32-bit LSB executable, MIPS, MIPS-I version 1 (SYSV), statically linked, stripped
                                                              Entropy (8bit):5.490969198434503
                                                              TrID:
                                                              • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                                                              File name:mpsl.elf
                                                              File size:72'288 bytes
                                                              MD5:eaf4f92882209af2ac633f3755b92284
                                                              SHA1:fe20895c65e750dd1fc0dd45445720ba952576a4
                                                              SHA256:ec5afbd33022308ae46716f3226b32620982da469fb81120939aeee2b386e857
                                                              SHA512:563db38902b0c2226900c2e4d2080ceabcaaa882b11cb201735fe8f57f0406c2d3571129d7ed194461bea50e56b5fca3d9c592b1d554deb9dee9242acf2f33ac
                                                              SSDEEP:768:Leh4txgcRLNurDjdg8eBroeaESQJ2w6uXatZXEPXitU5EiegY0xh1wntIF:Leh0KPUro1EfNEZXEZEinY0mnt
                                                              TLSH:EA63D716FB650FB7DC6BCD3306A81B013ACC558A22E97B363534D828F65B24B59E3C64
                                                              File Content Preview:.ELF....................`.@.4...X.......4. ...(...............@...@...........................E...E..... *..........Q.td...............................<...'!......'.......................<...'!... .........9'.. ........................<...'!.............9

                                                              ELF header

                                                              Class:ELF32
                                                              Data:2's complement, little endian
                                                              Version:1 (current)
                                                              Machine:MIPS R3000
                                                              Version Number:0x1
                                                              Type:EXEC (Executable file)
                                                              OS/ABI:UNIX - System V
                                                              ABI Version:0
                                                              Entry Point Address:0x400260
                                                              Flags:0x1007
                                                              ELF Header Size:52
                                                              Program Header Offset:52
                                                              Program Header Size:32
                                                              Number of Program Headers:3
                                                              Section Header Offset:71768
                                                              Section Header Size:40
                                                              Number of Section Headers:13
                                                              Header String Table Index:12
                                                              NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                                              NULL0x00x00x00x00x0000
                                                              .initPROGBITS0x4000940x940x8c0x00x6AX004
                                                              .textPROGBITS0x4001200x1200xf2500x00x6AX0016
                                                              .finiPROGBITS0x40f3700xf3700x5c0x00x6AX004
                                                              .rodataPROGBITS0x40f3d00xf3d00x1ae00x00x2A0016
                                                              .ctorsPROGBITS0x4510000x110000x80x00x3WA004
                                                              .dtorsPROGBITS0x4510080x110080x80x00x3WA004
                                                              .dataPROGBITS0x4510200x110200x3a00x00x3WA0016
                                                              .gotPROGBITS0x4513c00x113c00x4400x40x10000003WAp0016
                                                              .sbssNOBITS0x4518000x118000x1c0x00x10000003WAp004
                                                              .bssNOBITS0x4518200x118000x22000x00x3WA0016
                                                              .mdebug.abi32PROGBITS0x9120x118000x00x00x0001
                                                              .shstrtabSTRTAB0x00x118000x570x00x0001
                                                              TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                              LOAD0x00x4000000x4000000x10eb00x10eb05.54640x5R E0x10000.init .text .fini .rodata
                                                              LOAD0x110000x4510000x4510000x8000x2a203.67350x6RW 0x10000.ctors .dtors .data .got .sbss .bss
                                                              GNU_STACK0x00x00x00x00x00.00000x7RWE0x4
                                                              TimestampSIDSignatureSeveritySource IPSource PortDest IPDest PortProtocol
                                                              2024-10-21T18:46:56.685755+02002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.2360532107.189.4.20158431TCP
                                                              2024-10-21T18:47:02.114474+02002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.2360534107.189.4.20158431TCP
                                                              2024-10-21T18:47:03.570774+02002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.2360536107.189.4.20158431TCP
                                                              2024-10-21T18:47:08.044068+02002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.2360538107.189.4.20158431TCP
                                                              2024-10-21T18:47:13.596698+02002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.2360540107.189.4.20158431TCP
                                                              2024-10-21T18:47:21.028675+02002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.2360542107.189.4.20158431TCP
                                                              2024-10-21T18:47:24.459662+02002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.2360544107.189.4.20158431TCP
                                                              2024-10-21T18:47:28.892181+02002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.2360546107.189.4.20158431TCP
                                                              2024-10-21T18:47:37.348328+02002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.2360548107.189.4.20158431TCP
                                                              2024-10-21T18:47:47.784153+02002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.2360550107.189.4.20158431TCP
                                                              2024-10-21T18:47:54.217105+02002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.2360552107.189.4.20158431TCP
                                                              2024-10-21T18:47:56.788475+02002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.2360554107.189.4.20158431TCP
                                                              2024-10-21T18:47:59.220557+02002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.2360556107.189.4.20158431TCP
                                                              2024-10-21T18:48:04.652976+02002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.2360558107.189.4.20158431TCP
                                                              2024-10-21T18:48:09.110620+02002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.2360560107.189.4.20158431TCP
                                                              2024-10-21T18:48:11.540482+02002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.2360562107.189.4.20158431TCP
                                                              2024-10-21T18:48:21.972963+02002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.2360564107.189.4.20158431TCP
                                                              2024-10-21T18:48:27.403718+02002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.2360566107.189.4.20158431TCP
                                                              2024-10-21T18:48:31.842157+02002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.2360568107.189.4.20158431TCP
                                                              2024-10-21T18:48:37.390600+02002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.2360570107.189.4.20158431TCP
                                                              2024-10-21T18:48:39.824204+02002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.2360572107.189.4.20158431TCP
                                                              2024-10-21T18:48:45.269697+02002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.2360574107.189.4.20158431TCP
                                                              2024-10-21T18:48:51.699905+02002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.2360576107.189.4.20158431TCP
                                                              2024-10-21T18:49:00.134037+02002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.2360578107.189.4.20158431TCP
                                                              TimestampSource PortDest PortSource IPDest IP
                                                              Oct 21, 2024 18:46:56.676738024 CEST6053258431192.168.2.23107.189.4.201
                                                              Oct 21, 2024 18:46:56.682744980 CEST5843160532107.189.4.201192.168.2.23
                                                              Oct 21, 2024 18:46:56.682826042 CEST6053258431192.168.2.23107.189.4.201
                                                              Oct 21, 2024 18:46:56.685755014 CEST6053258431192.168.2.23107.189.4.201
                                                              Oct 21, 2024 18:46:56.691221952 CEST5843160532107.189.4.201192.168.2.23
                                                              Oct 21, 2024 18:46:57.097203016 CEST5843160532107.189.4.201192.168.2.23
                                                              Oct 21, 2024 18:46:57.097598076 CEST6053258431192.168.2.23107.189.4.201
                                                              Oct 21, 2024 18:46:57.103079081 CEST5843160532107.189.4.201192.168.2.23
                                                              Oct 21, 2024 18:46:59.629048109 CEST42836443192.168.2.2391.189.91.43
                                                              Oct 21, 2024 18:47:00.653006077 CEST4251680192.168.2.23109.202.202.202
                                                              Oct 21, 2024 18:47:02.108202934 CEST6053458431192.168.2.23107.189.4.201
                                                              Oct 21, 2024 18:47:02.113604069 CEST5843160534107.189.4.201192.168.2.23
                                                              Oct 21, 2024 18:47:02.113681078 CEST6053458431192.168.2.23107.189.4.201
                                                              Oct 21, 2024 18:47:02.114474058 CEST6053458431192.168.2.23107.189.4.201
                                                              Oct 21, 2024 18:47:02.119853020 CEST5843160534107.189.4.201192.168.2.23
                                                              Oct 21, 2024 18:47:02.553823948 CEST5843160534107.189.4.201192.168.2.23
                                                              Oct 21, 2024 18:47:02.554045916 CEST6053458431192.168.2.23107.189.4.201
                                                              Oct 21, 2024 18:47:02.559773922 CEST5843160534107.189.4.201192.168.2.23
                                                              Oct 21, 2024 18:47:03.564557076 CEST6053658431192.168.2.23107.189.4.201
                                                              Oct 21, 2024 18:47:03.569972992 CEST5843160536107.189.4.201192.168.2.23
                                                              Oct 21, 2024 18:47:03.570049047 CEST6053658431192.168.2.23107.189.4.201
                                                              Oct 21, 2024 18:47:03.570774078 CEST6053658431192.168.2.23107.189.4.201
                                                              Oct 21, 2024 18:47:03.576155901 CEST5843160536107.189.4.201192.168.2.23
                                                              Oct 21, 2024 18:47:03.989176035 CEST5843160536107.189.4.201192.168.2.23
                                                              Oct 21, 2024 18:47:03.989382982 CEST6053658431192.168.2.23107.189.4.201
                                                              Oct 21, 2024 18:47:03.994859934 CEST5843160536107.189.4.201192.168.2.23
                                                              Oct 21, 2024 18:47:08.015471935 CEST6053858431192.168.2.23107.189.4.201
                                                              Oct 21, 2024 18:47:08.020862103 CEST5843160538107.189.4.201192.168.2.23
                                                              Oct 21, 2024 18:47:08.020936966 CEST6053858431192.168.2.23107.189.4.201
                                                              Oct 21, 2024 18:47:08.044068098 CEST6053858431192.168.2.23107.189.4.201
                                                              Oct 21, 2024 18:47:08.049499989 CEST5843160538107.189.4.201192.168.2.23
                                                              Oct 21, 2024 18:47:08.579482079 CEST5843160538107.189.4.201192.168.2.23
                                                              Oct 21, 2024 18:47:08.579777956 CEST6053858431192.168.2.23107.189.4.201
                                                              Oct 21, 2024 18:47:08.579818964 CEST6053858431192.168.2.23107.189.4.201
                                                              Oct 21, 2024 18:47:08.585491896 CEST5843160538107.189.4.201192.168.2.23
                                                              Oct 21, 2024 18:47:13.590354919 CEST6054058431192.168.2.23107.189.4.201
                                                              Oct 21, 2024 18:47:13.595761061 CEST5843160540107.189.4.201192.168.2.23
                                                              Oct 21, 2024 18:47:13.595877886 CEST6054058431192.168.2.23107.189.4.201
                                                              Oct 21, 2024 18:47:13.596698046 CEST6054058431192.168.2.23107.189.4.201
                                                              Oct 21, 2024 18:47:13.602065086 CEST5843160540107.189.4.201192.168.2.23
                                                              Oct 21, 2024 18:47:14.012062073 CEST5843160540107.189.4.201192.168.2.23
                                                              Oct 21, 2024 18:47:14.012574911 CEST6054058431192.168.2.23107.189.4.201
                                                              Oct 21, 2024 18:47:14.018018007 CEST5843160540107.189.4.201192.168.2.23
                                                              Oct 21, 2024 18:47:14.986913919 CEST43928443192.168.2.2391.189.91.42
                                                              Oct 21, 2024 18:47:21.022263050 CEST6054258431192.168.2.23107.189.4.201
                                                              Oct 21, 2024 18:47:21.027764082 CEST5843160542107.189.4.201192.168.2.23
                                                              Oct 21, 2024 18:47:21.027883053 CEST6054258431192.168.2.23107.189.4.201
                                                              Oct 21, 2024 18:47:21.028675079 CEST6054258431192.168.2.23107.189.4.201
                                                              Oct 21, 2024 18:47:21.034054995 CEST5843160542107.189.4.201192.168.2.23
                                                              Oct 21, 2024 18:47:21.442603111 CEST5843160542107.189.4.201192.168.2.23
                                                              Oct 21, 2024 18:47:21.442802906 CEST6054258431192.168.2.23107.189.4.201
                                                              Oct 21, 2024 18:47:21.449992895 CEST5843160542107.189.4.201192.168.2.23
                                                              Oct 21, 2024 18:47:24.453512907 CEST6054458431192.168.2.23107.189.4.201
                                                              Oct 21, 2024 18:47:24.458952904 CEST5843160544107.189.4.201192.168.2.23
                                                              Oct 21, 2024 18:47:24.459028959 CEST6054458431192.168.2.23107.189.4.201
                                                              Oct 21, 2024 18:47:24.459661961 CEST6054458431192.168.2.23107.189.4.201
                                                              Oct 21, 2024 18:47:24.465082884 CEST5843160544107.189.4.201192.168.2.23
                                                              Oct 21, 2024 18:47:24.875291109 CEST5843160544107.189.4.201192.168.2.23
                                                              Oct 21, 2024 18:47:24.875585079 CEST6054458431192.168.2.23107.189.4.201
                                                              Oct 21, 2024 18:47:24.881091118 CEST5843160544107.189.4.201192.168.2.23
                                                              Oct 21, 2024 18:47:25.225562096 CEST42836443192.168.2.2391.189.91.43
                                                              Oct 21, 2024 18:47:28.885857105 CEST6054658431192.168.2.23107.189.4.201
                                                              Oct 21, 2024 18:47:28.891310930 CEST5843160546107.189.4.201192.168.2.23
                                                              Oct 21, 2024 18:47:28.891407013 CEST6054658431192.168.2.23107.189.4.201
                                                              Oct 21, 2024 18:47:28.892180920 CEST6054658431192.168.2.23107.189.4.201
                                                              Oct 21, 2024 18:47:28.897572994 CEST5843160546107.189.4.201192.168.2.23
                                                              Oct 21, 2024 18:47:29.325067997 CEST5843160546107.189.4.201192.168.2.23
                                                              Oct 21, 2024 18:47:29.325505018 CEST6054658431192.168.2.23107.189.4.201
                                                              Oct 21, 2024 18:47:29.331027985 CEST5843160546107.189.4.201192.168.2.23
                                                              Oct 21, 2024 18:47:31.368643045 CEST4251680192.168.2.23109.202.202.202
                                                              Oct 21, 2024 18:47:37.340001106 CEST6054858431192.168.2.23107.189.4.201
                                                              Oct 21, 2024 18:47:37.345506907 CEST5843160548107.189.4.201192.168.2.23
                                                              Oct 21, 2024 18:47:37.345612049 CEST6054858431192.168.2.23107.189.4.201
                                                              Oct 21, 2024 18:47:37.348328114 CEST6054858431192.168.2.23107.189.4.201
                                                              Oct 21, 2024 18:47:37.353737116 CEST5843160548107.189.4.201192.168.2.23
                                                              Oct 21, 2024 18:47:37.762137890 CEST5843160548107.189.4.201192.168.2.23
                                                              Oct 21, 2024 18:47:37.762329102 CEST6054858431192.168.2.23107.189.4.201
                                                              Oct 21, 2024 18:47:37.768950939 CEST5843160548107.189.4.201192.168.2.23
                                                              Oct 21, 2024 18:47:47.775950909 CEST6055058431192.168.2.23107.189.4.201
                                                              Oct 21, 2024 18:47:47.781549931 CEST5843160550107.189.4.201192.168.2.23
                                                              Oct 21, 2024 18:47:47.781639099 CEST6055058431192.168.2.23107.189.4.201
                                                              Oct 21, 2024 18:47:47.784152985 CEST6055058431192.168.2.23107.189.4.201
                                                              Oct 21, 2024 18:47:47.789891958 CEST5843160550107.189.4.201192.168.2.23
                                                              Oct 21, 2024 18:47:48.199471951 CEST5843160550107.189.4.201192.168.2.23
                                                              Oct 21, 2024 18:47:48.199784994 CEST6055058431192.168.2.23107.189.4.201
                                                              Oct 21, 2024 18:47:48.205236912 CEST5843160550107.189.4.201192.168.2.23
                                                              Oct 21, 2024 18:47:54.210556984 CEST6055258431192.168.2.23107.189.4.201
                                                              Oct 21, 2024 18:47:54.216222048 CEST5843160552107.189.4.201192.168.2.23
                                                              Oct 21, 2024 18:47:54.216283083 CEST6055258431192.168.2.23107.189.4.201
                                                              Oct 21, 2024 18:47:54.217104912 CEST6055258431192.168.2.23107.189.4.201
                                                              Oct 21, 2024 18:47:54.222413063 CEST5843160552107.189.4.201192.168.2.23
                                                              Oct 21, 2024 18:47:54.770087957 CEST5843160552107.189.4.201192.168.2.23
                                                              Oct 21, 2024 18:47:54.770473003 CEST6055258431192.168.2.23107.189.4.201
                                                              Oct 21, 2024 18:47:54.780241013 CEST5843160552107.189.4.201192.168.2.23
                                                              Oct 21, 2024 18:47:55.941169024 CEST43928443192.168.2.2391.189.91.42
                                                              Oct 21, 2024 18:47:56.781819105 CEST6055458431192.168.2.23107.189.4.201
                                                              Oct 21, 2024 18:47:56.787240982 CEST5843160554107.189.4.201192.168.2.23
                                                              Oct 21, 2024 18:47:56.787327051 CEST6055458431192.168.2.23107.189.4.201
                                                              Oct 21, 2024 18:47:56.788475037 CEST6055458431192.168.2.23107.189.4.201
                                                              Oct 21, 2024 18:47:56.793756962 CEST5843160554107.189.4.201192.168.2.23
                                                              Oct 21, 2024 18:47:57.202419043 CEST5843160554107.189.4.201192.168.2.23
                                                              Oct 21, 2024 18:47:57.202645063 CEST6055458431192.168.2.23107.189.4.201
                                                              Oct 21, 2024 18:47:57.208197117 CEST5843160554107.189.4.201192.168.2.23
                                                              Oct 21, 2024 18:47:59.213988066 CEST6055658431192.168.2.23107.189.4.201
                                                              Oct 21, 2024 18:47:59.219369888 CEST5843160556107.189.4.201192.168.2.23
                                                              Oct 21, 2024 18:47:59.219440937 CEST6055658431192.168.2.23107.189.4.201
                                                              Oct 21, 2024 18:47:59.220556974 CEST6055658431192.168.2.23107.189.4.201
                                                              Oct 21, 2024 18:47:59.225851059 CEST5843160556107.189.4.201192.168.2.23
                                                              Oct 21, 2024 18:47:59.633209944 CEST5843160556107.189.4.201192.168.2.23
                                                              Oct 21, 2024 18:47:59.633367062 CEST6055658431192.168.2.23107.189.4.201
                                                              Oct 21, 2024 18:47:59.638691902 CEST5843160556107.189.4.201192.168.2.23
                                                              Oct 21, 2024 18:48:04.645349979 CEST6055858431192.168.2.23107.189.4.201
                                                              Oct 21, 2024 18:48:04.652015924 CEST5843160558107.189.4.201192.168.2.23
                                                              Oct 21, 2024 18:48:04.652092934 CEST6055858431192.168.2.23107.189.4.201
                                                              Oct 21, 2024 18:48:04.652976036 CEST6055858431192.168.2.23107.189.4.201
                                                              Oct 21, 2024 18:48:04.658704996 CEST5843160558107.189.4.201192.168.2.23
                                                              Oct 21, 2024 18:48:05.089251995 CEST5843160558107.189.4.201192.168.2.23
                                                              Oct 21, 2024 18:48:05.089484930 CEST6055858431192.168.2.23107.189.4.201
                                                              Oct 21, 2024 18:48:05.095956087 CEST5843160558107.189.4.201192.168.2.23
                                                              Oct 21, 2024 18:48:09.102019072 CEST6056058431192.168.2.23107.189.4.201
                                                              Oct 21, 2024 18:48:09.109606981 CEST5843160560107.189.4.201192.168.2.23
                                                              Oct 21, 2024 18:48:09.109659910 CEST6056058431192.168.2.23107.189.4.201
                                                              Oct 21, 2024 18:48:09.110620022 CEST6056058431192.168.2.23107.189.4.201
                                                              Oct 21, 2024 18:48:09.115938902 CEST5843160560107.189.4.201192.168.2.23
                                                              Oct 21, 2024 18:48:09.522998095 CEST5843160560107.189.4.201192.168.2.23
                                                              Oct 21, 2024 18:48:09.523299932 CEST6056058431192.168.2.23107.189.4.201
                                                              Oct 21, 2024 18:48:09.523299932 CEST6056058431192.168.2.23107.189.4.201
                                                              Oct 21, 2024 18:48:09.528875113 CEST5843160560107.189.4.201192.168.2.23
                                                              Oct 21, 2024 18:48:11.534019947 CEST6056258431192.168.2.23107.189.4.201
                                                              Oct 21, 2024 18:48:11.539391994 CEST5843160562107.189.4.201192.168.2.23
                                                              Oct 21, 2024 18:48:11.539478064 CEST6056258431192.168.2.23107.189.4.201
                                                              Oct 21, 2024 18:48:11.540482044 CEST6056258431192.168.2.23107.189.4.201
                                                              Oct 21, 2024 18:48:11.545846939 CEST5843160562107.189.4.201192.168.2.23
                                                              Oct 21, 2024 18:48:11.953789949 CEST5843160562107.189.4.201192.168.2.23
                                                              Oct 21, 2024 18:48:11.956685066 CEST6056258431192.168.2.23107.189.4.201
                                                              Oct 21, 2024 18:48:11.956685066 CEST6056258431192.168.2.23107.189.4.201
                                                              Oct 21, 2024 18:48:11.962415934 CEST5843160562107.189.4.201192.168.2.23
                                                              Oct 21, 2024 18:48:16.418406010 CEST42836443192.168.2.2391.189.91.43
                                                              Oct 21, 2024 18:48:21.966458082 CEST6056458431192.168.2.23107.189.4.201
                                                              Oct 21, 2024 18:48:21.971805096 CEST5843160564107.189.4.201192.168.2.23
                                                              Oct 21, 2024 18:48:21.971975088 CEST6056458431192.168.2.23107.189.4.201
                                                              Oct 21, 2024 18:48:21.972963095 CEST6056458431192.168.2.23107.189.4.201
                                                              Oct 21, 2024 18:48:21.978486061 CEST5843160564107.189.4.201192.168.2.23
                                                              Oct 21, 2024 18:48:22.385345936 CEST5843160564107.189.4.201192.168.2.23
                                                              Oct 21, 2024 18:48:22.385679007 CEST6056458431192.168.2.23107.189.4.201
                                                              Oct 21, 2024 18:48:22.391058922 CEST5843160564107.189.4.201192.168.2.23
                                                              Oct 21, 2024 18:48:27.396887064 CEST6056658431192.168.2.23107.189.4.201
                                                              Oct 21, 2024 18:48:27.402400970 CEST5843160566107.189.4.201192.168.2.23
                                                              Oct 21, 2024 18:48:27.402502060 CEST6056658431192.168.2.23107.189.4.201
                                                              Oct 21, 2024 18:48:27.403717995 CEST6056658431192.168.2.23107.189.4.201
                                                              Oct 21, 2024 18:48:27.409158945 CEST5843160566107.189.4.201192.168.2.23
                                                              Oct 21, 2024 18:48:27.823889017 CEST5843160566107.189.4.201192.168.2.23
                                                              Oct 21, 2024 18:48:27.824323893 CEST6056658431192.168.2.23107.189.4.201
                                                              Oct 21, 2024 18:48:27.829790115 CEST5843160566107.189.4.201192.168.2.23
                                                              Oct 21, 2024 18:48:31.835683107 CEST6056858431192.168.2.23107.189.4.201
                                                              Oct 21, 2024 18:48:31.841135025 CEST5843160568107.189.4.201192.168.2.23
                                                              Oct 21, 2024 18:48:31.841212988 CEST6056858431192.168.2.23107.189.4.201
                                                              Oct 21, 2024 18:48:31.842156887 CEST6056858431192.168.2.23107.189.4.201
                                                              Oct 21, 2024 18:48:31.847598076 CEST5843160568107.189.4.201192.168.2.23
                                                              Oct 21, 2024 18:48:32.256174088 CEST5843160568107.189.4.201192.168.2.23
                                                              Oct 21, 2024 18:48:32.256639957 CEST6056858431192.168.2.23107.189.4.201
                                                              Oct 21, 2024 18:48:32.262217999 CEST5843160568107.189.4.201192.168.2.23
                                                              Oct 21, 2024 18:48:37.384186983 CEST6057058431192.168.2.23107.189.4.201
                                                              Oct 21, 2024 18:48:37.389626980 CEST5843160570107.189.4.201192.168.2.23
                                                              Oct 21, 2024 18:48:37.389717102 CEST6057058431192.168.2.23107.189.4.201
                                                              Oct 21, 2024 18:48:37.390599966 CEST6057058431192.168.2.23107.189.4.201
                                                              Oct 21, 2024 18:48:37.395992994 CEST5843160570107.189.4.201192.168.2.23
                                                              Oct 21, 2024 18:48:37.803685904 CEST5843160570107.189.4.201192.168.2.23
                                                              Oct 21, 2024 18:48:37.804162979 CEST6057058431192.168.2.23107.189.4.201
                                                              Oct 21, 2024 18:48:37.809624910 CEST5843160570107.189.4.201192.168.2.23
                                                              Oct 21, 2024 18:48:39.816957951 CEST6057258431192.168.2.23107.189.4.201
                                                              Oct 21, 2024 18:48:39.822633028 CEST5843160572107.189.4.201192.168.2.23
                                                              Oct 21, 2024 18:48:39.822734118 CEST6057258431192.168.2.23107.189.4.201
                                                              Oct 21, 2024 18:48:39.824203968 CEST6057258431192.168.2.23107.189.4.201
                                                              Oct 21, 2024 18:48:39.829682112 CEST5843160572107.189.4.201192.168.2.23
                                                              Oct 21, 2024 18:48:40.252480984 CEST5843160572107.189.4.201192.168.2.23
                                                              Oct 21, 2024 18:48:40.252922058 CEST6057258431192.168.2.23107.189.4.201
                                                              Oct 21, 2024 18:48:40.258316994 CEST5843160572107.189.4.201192.168.2.23
                                                              Oct 21, 2024 18:48:45.263468981 CEST6057458431192.168.2.23107.189.4.201
                                                              Oct 21, 2024 18:48:45.268805027 CEST5843160574107.189.4.201192.168.2.23
                                                              Oct 21, 2024 18:48:45.268883944 CEST6057458431192.168.2.23107.189.4.201
                                                              Oct 21, 2024 18:48:45.269696951 CEST6057458431192.168.2.23107.189.4.201
                                                              Oct 21, 2024 18:48:45.274945021 CEST5843160574107.189.4.201192.168.2.23
                                                              Oct 21, 2024 18:48:45.682894945 CEST5843160574107.189.4.201192.168.2.23
                                                              Oct 21, 2024 18:48:45.683357954 CEST6057458431192.168.2.23107.189.4.201
                                                              Oct 21, 2024 18:48:45.688721895 CEST5843160574107.189.4.201192.168.2.23
                                                              Oct 21, 2024 18:48:51.693605900 CEST6057658431192.168.2.23107.189.4.201
                                                              Oct 21, 2024 18:48:51.699029922 CEST5843160576107.189.4.201192.168.2.23
                                                              Oct 21, 2024 18:48:51.699093103 CEST6057658431192.168.2.23107.189.4.201
                                                              Oct 21, 2024 18:48:51.699904919 CEST6057658431192.168.2.23107.189.4.201
                                                              Oct 21, 2024 18:48:51.705425978 CEST5843160576107.189.4.201192.168.2.23
                                                              Oct 21, 2024 18:48:52.115467072 CEST5843160576107.189.4.201192.168.2.23
                                                              Oct 21, 2024 18:48:52.115628004 CEST6057658431192.168.2.23107.189.4.201
                                                              Oct 21, 2024 18:48:52.121115923 CEST5843160576107.189.4.201192.168.2.23
                                                              Oct 21, 2024 18:49:00.127127886 CEST6057858431192.168.2.23107.189.4.201
                                                              Oct 21, 2024 18:49:00.132596970 CEST5843160578107.189.4.201192.168.2.23
                                                              Oct 21, 2024 18:49:00.132661104 CEST6057858431192.168.2.23107.189.4.201
                                                              Oct 21, 2024 18:49:00.134037018 CEST6057858431192.168.2.23107.189.4.201
                                                              Oct 21, 2024 18:49:00.139400959 CEST5843160578107.189.4.201192.168.2.23
                                                              Oct 21, 2024 18:49:00.546240091 CEST5843160578107.189.4.201192.168.2.23
                                                              Oct 21, 2024 18:49:00.546617031 CEST6057858431192.168.2.23107.189.4.201
                                                              Oct 21, 2024 18:49:00.553819895 CEST5843160578107.189.4.201192.168.2.23
                                                              TimestampSource PortDest PortSource IPDest IP
                                                              Oct 21, 2024 18:46:56.665713072 CEST4582653192.168.2.238.8.8.8
                                                              Oct 21, 2024 18:46:56.675388098 CEST53458268.8.8.8192.168.2.23
                                                              Oct 21, 2024 18:47:02.099356890 CEST3790453192.168.2.238.8.8.8
                                                              Oct 21, 2024 18:47:02.107680082 CEST53379048.8.8.8192.168.2.23
                                                              Oct 21, 2024 18:47:03.556425095 CEST3293953192.168.2.238.8.8.8
                                                              Oct 21, 2024 18:47:03.563976049 CEST53329398.8.8.8192.168.2.23
                                                              Oct 21, 2024 18:47:08.000377893 CEST5613253192.168.2.238.8.8.8
                                                              Oct 21, 2024 18:47:08.008980989 CEST53561328.8.8.8192.168.2.23
                                                              Oct 21, 2024 18:47:13.581804037 CEST5767053192.168.2.238.8.8.8
                                                              Oct 21, 2024 18:47:13.589972019 CEST53576708.8.8.8192.168.2.23
                                                              Oct 21, 2024 18:47:21.014208078 CEST4414653192.168.2.238.8.8.8
                                                              Oct 21, 2024 18:47:21.021806955 CEST53441468.8.8.8192.168.2.23
                                                              Oct 21, 2024 18:47:24.445038080 CEST3784753192.168.2.238.8.8.8
                                                              Oct 21, 2024 18:47:24.453138113 CEST53378478.8.8.8192.168.2.23
                                                              Oct 21, 2024 18:47:28.877041101 CEST3553753192.168.2.238.8.8.8
                                                              Oct 21, 2024 18:47:28.885396957 CEST53355378.8.8.8192.168.2.23
                                                              Oct 21, 2024 18:47:37.329623938 CEST4148253192.168.2.238.8.8.8
                                                              Oct 21, 2024 18:47:37.337913990 CEST53414828.8.8.8192.168.2.23
                                                              Oct 21, 2024 18:47:47.765227079 CEST3533953192.168.2.238.8.8.8
                                                              Oct 21, 2024 18:47:47.774179935 CEST53353398.8.8.8192.168.2.23
                                                              Oct 21, 2024 18:47:54.201797009 CEST6023253192.168.2.238.8.8.8
                                                              Oct 21, 2024 18:47:54.210047007 CEST53602328.8.8.8192.168.2.23
                                                              Oct 21, 2024 18:47:56.773128986 CEST3328753192.168.2.238.8.8.8
                                                              Oct 21, 2024 18:47:56.781193972 CEST53332878.8.8.8192.168.2.23
                                                              Oct 21, 2024 18:47:59.205399036 CEST5867053192.168.2.238.8.8.8
                                                              Oct 21, 2024 18:47:59.213465929 CEST53586708.8.8.8192.168.2.23
                                                              Oct 21, 2024 18:48:04.635566950 CEST4459753192.168.2.238.8.8.8
                                                              Oct 21, 2024 18:48:04.644793034 CEST53445978.8.8.8192.168.2.23
                                                              Oct 21, 2024 18:48:09.092149973 CEST3299753192.168.2.238.8.8.8
                                                              Oct 21, 2024 18:48:09.101484060 CEST53329978.8.8.8192.168.2.23
                                                              Oct 21, 2024 18:48:11.525926113 CEST4321353192.168.2.238.8.8.8
                                                              Oct 21, 2024 18:48:11.533380032 CEST53432138.8.8.8192.168.2.23
                                                              Oct 21, 2024 18:48:21.957993984 CEST4193853192.168.2.238.8.8.8
                                                              Oct 21, 2024 18:48:21.965934992 CEST53419388.8.8.8192.168.2.23
                                                              Oct 21, 2024 18:48:27.388463974 CEST3643253192.168.2.238.8.8.8
                                                              Oct 21, 2024 18:48:27.396083117 CEST53364328.8.8.8192.168.2.23
                                                              Oct 21, 2024 18:48:31.827047110 CEST4183053192.168.2.238.8.8.8
                                                              Oct 21, 2024 18:48:31.835066080 CEST53418308.8.8.8192.168.2.23
                                                              Oct 21, 2024 18:48:37.259110928 CEST5361053192.168.2.238.8.8.8
                                                              Oct 21, 2024 18:48:37.382463932 CEST53536108.8.8.8192.168.2.23
                                                              Oct 21, 2024 18:48:39.807550907 CEST4315453192.168.2.238.8.8.8
                                                              Oct 21, 2024 18:48:39.816059113 CEST53431548.8.8.8192.168.2.23
                                                              Oct 21, 2024 18:48:45.255021095 CEST4130353192.168.2.238.8.8.8
                                                              Oct 21, 2024 18:48:45.262969017 CEST53413038.8.8.8192.168.2.23
                                                              Oct 21, 2024 18:48:51.685933113 CEST5415453192.168.2.238.8.8.8
                                                              Oct 21, 2024 18:48:51.693088055 CEST53541548.8.8.8192.168.2.23
                                                              Oct 21, 2024 18:49:00.118402958 CEST5701853192.168.2.238.8.8.8
                                                              Oct 21, 2024 18:49:00.126121044 CEST53570188.8.8.8192.168.2.23
                                                              TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                                              Oct 21, 2024 18:46:56.665713072 CEST192.168.2.238.8.8.80x42e2Standard query (0)update.byeux.comA (IP address)IN (0x0001)false
                                                              Oct 21, 2024 18:47:02.099356890 CEST192.168.2.238.8.8.80x55e8Standard query (0)update.byeux.comA (IP address)IN (0x0001)false
                                                              Oct 21, 2024 18:47:03.556425095 CEST192.168.2.238.8.8.80x95b8Standard query (0)update.byeux.comA (IP address)IN (0x0001)false
                                                              Oct 21, 2024 18:47:08.000377893 CEST192.168.2.238.8.8.80x3f1fStandard query (0)update.byeux.comA (IP address)IN (0x0001)false
                                                              Oct 21, 2024 18:47:13.581804037 CEST192.168.2.238.8.8.80x3360Standard query (0)update.byeux.comA (IP address)IN (0x0001)false
                                                              Oct 21, 2024 18:47:21.014208078 CEST192.168.2.238.8.8.80xabd3Standard query (0)update.byeux.comA (IP address)IN (0x0001)false
                                                              Oct 21, 2024 18:47:24.445038080 CEST192.168.2.238.8.8.80xf6c0Standard query (0)update.byeux.comA (IP address)IN (0x0001)false
                                                              Oct 21, 2024 18:47:28.877041101 CEST192.168.2.238.8.8.80x573cStandard query (0)update.byeux.comA (IP address)IN (0x0001)false
                                                              Oct 21, 2024 18:47:37.329623938 CEST192.168.2.238.8.8.80xde19Standard query (0)update.byeux.comA (IP address)IN (0x0001)false
                                                              Oct 21, 2024 18:47:47.765227079 CEST192.168.2.238.8.8.80x7359Standard query (0)update.byeux.comA (IP address)IN (0x0001)false
                                                              Oct 21, 2024 18:47:54.201797009 CEST192.168.2.238.8.8.80x4692Standard query (0)update.byeux.comA (IP address)IN (0x0001)false
                                                              Oct 21, 2024 18:47:56.773128986 CEST192.168.2.238.8.8.80x4861Standard query (0)update.byeux.comA (IP address)IN (0x0001)false
                                                              Oct 21, 2024 18:47:59.205399036 CEST192.168.2.238.8.8.80x3974Standard query (0)update.byeux.comA (IP address)IN (0x0001)false
                                                              Oct 21, 2024 18:48:04.635566950 CEST192.168.2.238.8.8.80x6df5Standard query (0)update.byeux.comA (IP address)IN (0x0001)false
                                                              Oct 21, 2024 18:48:09.092149973 CEST192.168.2.238.8.8.80x381Standard query (0)update.byeux.comA (IP address)IN (0x0001)false
                                                              Oct 21, 2024 18:48:11.525926113 CEST192.168.2.238.8.8.80xe80dStandard query (0)update.byeux.comA (IP address)IN (0x0001)false
                                                              Oct 21, 2024 18:48:21.957993984 CEST192.168.2.238.8.8.80x7210Standard query (0)update.byeux.comA (IP address)IN (0x0001)false
                                                              Oct 21, 2024 18:48:27.388463974 CEST192.168.2.238.8.8.80xa18dStandard query (0)update.byeux.comA (IP address)IN (0x0001)false
                                                              Oct 21, 2024 18:48:31.827047110 CEST192.168.2.238.8.8.80xf423Standard query (0)update.byeux.comA (IP address)IN (0x0001)false
                                                              Oct 21, 2024 18:48:37.259110928 CEST192.168.2.238.8.8.80xe9e4Standard query (0)update.byeux.comA (IP address)IN (0x0001)false
                                                              Oct 21, 2024 18:48:39.807550907 CEST192.168.2.238.8.8.80xf9cdStandard query (0)update.byeux.comA (IP address)IN (0x0001)false
                                                              Oct 21, 2024 18:48:45.255021095 CEST192.168.2.238.8.8.80x94fcStandard query (0)update.byeux.comA (IP address)IN (0x0001)false
                                                              Oct 21, 2024 18:48:51.685933113 CEST192.168.2.238.8.8.80x869dStandard query (0)update.byeux.comA (IP address)IN (0x0001)false
                                                              Oct 21, 2024 18:49:00.118402958 CEST192.168.2.238.8.8.80x4d06Standard query (0)update.byeux.comA (IP address)IN (0x0001)false
                                                              TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                                              Oct 21, 2024 18:46:56.675388098 CEST8.8.8.8192.168.2.230x42e2No error (0)update.byeux.com107.189.4.201A (IP address)IN (0x0001)false
                                                              Oct 21, 2024 18:47:02.107680082 CEST8.8.8.8192.168.2.230x55e8No error (0)update.byeux.com107.189.4.201A (IP address)IN (0x0001)false
                                                              Oct 21, 2024 18:47:03.563976049 CEST8.8.8.8192.168.2.230x95b8No error (0)update.byeux.com107.189.4.201A (IP address)IN (0x0001)false
                                                              Oct 21, 2024 18:47:08.008980989 CEST8.8.8.8192.168.2.230x3f1fNo error (0)update.byeux.com107.189.4.201A (IP address)IN (0x0001)false
                                                              Oct 21, 2024 18:47:13.589972019 CEST8.8.8.8192.168.2.230x3360No error (0)update.byeux.com107.189.4.201A (IP address)IN (0x0001)false
                                                              Oct 21, 2024 18:47:21.021806955 CEST8.8.8.8192.168.2.230xabd3No error (0)update.byeux.com107.189.4.201A (IP address)IN (0x0001)false
                                                              Oct 21, 2024 18:47:24.453138113 CEST8.8.8.8192.168.2.230xf6c0No error (0)update.byeux.com107.189.4.201A (IP address)IN (0x0001)false
                                                              Oct 21, 2024 18:47:28.885396957 CEST8.8.8.8192.168.2.230x573cNo error (0)update.byeux.com107.189.4.201A (IP address)IN (0x0001)false
                                                              Oct 21, 2024 18:47:37.337913990 CEST8.8.8.8192.168.2.230xde19No error (0)update.byeux.com107.189.4.201A (IP address)IN (0x0001)false
                                                              Oct 21, 2024 18:47:47.774179935 CEST8.8.8.8192.168.2.230x7359No error (0)update.byeux.com107.189.4.201A (IP address)IN (0x0001)false
                                                              Oct 21, 2024 18:47:54.210047007 CEST8.8.8.8192.168.2.230x4692No error (0)update.byeux.com107.189.4.201A (IP address)IN (0x0001)false
                                                              Oct 21, 2024 18:47:56.781193972 CEST8.8.8.8192.168.2.230x4861No error (0)update.byeux.com107.189.4.201A (IP address)IN (0x0001)false
                                                              Oct 21, 2024 18:47:59.213465929 CEST8.8.8.8192.168.2.230x3974No error (0)update.byeux.com107.189.4.201A (IP address)IN (0x0001)false
                                                              Oct 21, 2024 18:48:04.644793034 CEST8.8.8.8192.168.2.230x6df5No error (0)update.byeux.com107.189.4.201A (IP address)IN (0x0001)false
                                                              Oct 21, 2024 18:48:09.101484060 CEST8.8.8.8192.168.2.230x381No error (0)update.byeux.com107.189.4.201A (IP address)IN (0x0001)false
                                                              Oct 21, 2024 18:48:11.533380032 CEST8.8.8.8192.168.2.230xe80dNo error (0)update.byeux.com107.189.4.201A (IP address)IN (0x0001)false
                                                              Oct 21, 2024 18:48:21.965934992 CEST8.8.8.8192.168.2.230x7210No error (0)update.byeux.com107.189.4.201A (IP address)IN (0x0001)false
                                                              Oct 21, 2024 18:48:27.396083117 CEST8.8.8.8192.168.2.230xa18dNo error (0)update.byeux.com107.189.4.201A (IP address)IN (0x0001)false
                                                              Oct 21, 2024 18:48:31.835066080 CEST8.8.8.8192.168.2.230xf423No error (0)update.byeux.com107.189.4.201A (IP address)IN (0x0001)false
                                                              Oct 21, 2024 18:48:37.382463932 CEST8.8.8.8192.168.2.230xe9e4No error (0)update.byeux.com107.189.4.201A (IP address)IN (0x0001)false
                                                              Oct 21, 2024 18:48:39.816059113 CEST8.8.8.8192.168.2.230xf9cdNo error (0)update.byeux.com107.189.4.201A (IP address)IN (0x0001)false
                                                              Oct 21, 2024 18:48:45.262969017 CEST8.8.8.8192.168.2.230x94fcNo error (0)update.byeux.com107.189.4.201A (IP address)IN (0x0001)false
                                                              Oct 21, 2024 18:48:51.693088055 CEST8.8.8.8192.168.2.230x869dNo error (0)update.byeux.com107.189.4.201A (IP address)IN (0x0001)false
                                                              Oct 21, 2024 18:49:00.126121044 CEST8.8.8.8192.168.2.230x4d06No error (0)update.byeux.com107.189.4.201A (IP address)IN (0x0001)false

                                                              System Behavior

                                                              Start time (UTC):16:46:55
                                                              Start date (UTC):21/10/2024
                                                              Path:/tmp/mpsl.elf
                                                              Arguments:/tmp/mpsl.elf
                                                              File size:5773336 bytes
                                                              MD5 hash:0d6f61f82cf2f781c6eb0661071d42d9

                                                              Start time (UTC):16:46:55
                                                              Start date (UTC):21/10/2024
                                                              Path:/tmp/mpsl.elf
                                                              Arguments:-
                                                              File size:5773336 bytes
                                                              MD5 hash:0d6f61f82cf2f781c6eb0661071d42d9

                                                              Start time (UTC):16:46:55
                                                              Start date (UTC):21/10/2024
                                                              Path:/tmp/mpsl.elf
                                                              Arguments:-
                                                              File size:5773336 bytes
                                                              MD5 hash:0d6f61f82cf2f781c6eb0661071d42d9

                                                              Start time (UTC):16:46:55
                                                              Start date (UTC):21/10/2024
                                                              Path:/tmp/mpsl.elf
                                                              Arguments:-
                                                              File size:5773336 bytes
                                                              MD5 hash:0d6f61f82cf2f781c6eb0661071d42d9

                                                              Start time (UTC):16:46:55
                                                              Start date (UTC):21/10/2024
                                                              Path:/tmp/mpsl.elf
                                                              Arguments:-
                                                              File size:5773336 bytes
                                                              MD5 hash:0d6f61f82cf2f781c6eb0661071d42d9