Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
zerppc.elf

Overview

General Information

Sample name:zerppc.elf
Analysis ID:1543098
MD5:dca795506df8d44ff8a9d45e85caf92b
SHA1:1212e0e371e3ea71cc517f7ff644c9ff4362560e
SHA256:6d86b401f77c1ffcc9d29d1b157f44b08611b84c4ea238b32d76c48eae4f62da
Tags:elfuser-abuse_ch
Infos:

Detection

Score:56
Range:0 - 100
Whitelisted:false

Signatures

Multi AV Scanner detection for submitted file
Connects to many ports of the same IP (likely port scanning)
Sends malformed DNS queries
Detected TCP or UDP traffic on non-standard ports
Sample has stripped symbol table
Sample listens on a socket
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1543098
Start date and time:2024-10-27 08:57:13 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 34s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:zerppc.elf
Detection:MAL
Classification:mal56.troj.linELF@0/0@18/0
  • VT rate limit hit for: yellowchink.pirate
Command:/tmp/zerppc.elf
PID:5462
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
The Peoples Bank of China.
Standard Error:
  • system is lnxubuntu20
  • zerppc.elf (PID: 5462, Parent: 5370, MD5: ae65271c943d3451b7f026d1fadccea6) Arguments: /tmp/zerppc.elf
  • cleanup
No yara matches
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: zerppc.elfReversingLabs: Detection: 39%
Source: zerppc.elfVirustotal: Detection: 43%Perma Link

Networking

barindex
Source: global trafficTCP traffic: 185.150.24.67 ports 38241,1,2,3,4,8
Source: global trafficTCP traffic: 45.156.86.24 ports 38241,1,2,3,4,8
Source: global trafficDNS traffic detected: malformed DNS query: netfags.geek. [malformed]
Source: global trafficDNS traffic detected: malformed DNS query: burnthe.libre. [malformed]
Source: global trafficDNS traffic detected: malformed DNS query: yellowchink.pirate. [malformed]
Source: global trafficDNS traffic detected: malformed DNS query: chinklabs.dyn. [malformed]
Source: global trafficTCP traffic: 192.168.2.13:33436 -> 185.150.24.67:38241
Source: global trafficTCP traffic: 192.168.2.13:49400 -> 45.156.86.24:38241
Source: /tmp/zerppc.elf (PID: 5462)Socket: 127.0.0.1:39148Jump to behavior
Source: unknownUDP traffic detected without corresponding DNS query: 51.158.108.203
Source: unknownUDP traffic detected without corresponding DNS query: 202.61.197.122
Source: unknownUDP traffic detected without corresponding DNS query: 152.53.15.127
Source: unknownUDP traffic detected without corresponding DNS query: 51.158.108.203
Source: unknownUDP traffic detected without corresponding DNS query: 81.169.136.222
Source: unknownUDP traffic detected without corresponding DNS query: 194.36.144.87
Source: unknownUDP traffic detected without corresponding DNS query: 185.181.61.24
Source: unknownUDP traffic detected without corresponding DNS query: 81.169.136.222
Source: unknownUDP traffic detected without corresponding DNS query: 194.36.144.87
Source: unknownUDP traffic detected without corresponding DNS query: 152.53.15.127
Source: unknownUDP traffic detected without corresponding DNS query: 185.181.61.24
Source: unknownUDP traffic detected without corresponding DNS query: 202.61.197.122
Source: unknownUDP traffic detected without corresponding DNS query: 81.169.136.222
Source: unknownUDP traffic detected without corresponding DNS query: 51.158.108.203
Source: unknownUDP traffic detected without corresponding DNS query: 202.61.197.122
Source: unknownUDP traffic detected without corresponding DNS query: 51.158.108.203
Source: unknownUDP traffic detected without corresponding DNS query: 202.61.197.122
Source: unknownUDP traffic detected without corresponding DNS query: 51.158.108.203
Source: global trafficDNS traffic detected: DNS query: chinklabs.dyn
Source: global trafficDNS traffic detected: DNS query: netfags.geek. [malformed]
Source: global trafficDNS traffic detected: DNS query: yellowchink.pirate
Source: global trafficDNS traffic detected: DNS query: burnthe.libre. [malformed]
Source: global trafficDNS traffic detected: DNS query: burnthe.libre
Source: global trafficDNS traffic detected: DNS query: yellowchink.pirate. [malformed]
Source: global trafficDNS traffic detected: DNS query: chinklabs.dyn. [malformed]
Source: ELF static info symbol of initial sample.symtab present: no
Source: classification engineClassification label: mal56.troj.linELF@0/0@18/0
Source: /tmp/zerppc.elf (PID: 5462)Queries kernel information via 'uname': Jump to behavior
Source: zerppc.elf, 5462.1.000055557d443000.000055557d4f3000.rw-.sdmpBinary or memory string: !/etc/qemu-binfmt/ppc1
Source: zerppc.elf, 5462.1.000055557d443000.000055557d4f3000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/ppc
Source: zerppc.elf, 5462.1.00007ffd0768a000.00007ffd076ab000.rw-.sdmpBinary or memory string: /usr/bin/qemu-ppc
Source: zerppc.elf, 5462.1.00007ffd0768a000.00007ffd076ab000.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-ppc/tmp/zerppc.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/zerppc.elf
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath InterceptionDirect Volume AccessOS Credential Dumping11
Security Software Discovery
Remote ServicesData from Local System1
Non-Standard Port
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1543098 Sample: zerppc.elf Startdate: 27/10/2024 Architecture: LINUX Score: 56 14 yellowchink.pirate. [malformed] 2->14 16 netfags.geek. [malformed] 2->16 18 5 other IPs or domains 2->18 20 Multi AV Scanner detection for submitted file 2->20 22 Connects to many ports of the same IP (likely port scanning) 2->22 8 zerppc.elf 2->8         started        signatures3 24 Sends malformed DNS queries 16->24 process4 process5 10 zerppc.elf 8->10         started        process6 12 zerppc.elf 10->12         started       

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
zerppc.elf39%ReversingLabsLinux.Trojan.Mirai
zerppc.elf43%VirustotalBrowse
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
yellowchink.pirate
45.156.86.24
truetrue
    unknown
    chinklabs.dyn
    185.150.24.67
    truetrue
      unknown
      burnthe.libre
      45.156.86.24
      truetrue
        unknown
        chinklabs.dyn. [malformed]
        unknown
        unknowntrue
          unknown
          netfags.geek. [malformed]
          unknown
          unknowntrue
            unknown
            burnthe.libre. [malformed]
            unknown
            unknowntrue
              unknown
              yellowchink.pirate. [malformed]
              unknown
              unknowntrue
                unknown
                • No. of IPs < 25%
                • 25% < No. of IPs < 50%
                • 50% < No. of IPs < 75%
                • 75% < No. of IPs
                IPDomainCountryFlagASNASN NameMalicious
                185.150.24.67
                chinklabs.dynNetherlands
                44592SKYLINKNLtrue
                45.156.86.24
                yellowchink.pirateGermany
                44592SKYLINKNLtrue
                MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                185.150.24.67file.exeGet hashmaliciousUnknownBrowse
                  https://search-dl3.com/staticpr/12.zipGet hashmaliciousUnknownBrowse
                    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                    burnthe.librejydeTkHxMv.elfGet hashmaliciousUnknownBrowse
                    • 77.105.135.60
                    OCSM1XFiPg.elfGet hashmaliciousUnknownBrowse
                    • 5.181.80.61
                    yellowchink.pirateEGQr0VDazQ.elfGet hashmaliciousUnknownBrowse
                    • 5.181.80.189
                    q9WhhN00yY.elfGet hashmaliciousUnknownBrowse
                    • 77.105.135.60
                    ztGOiA742S.elfGet hashmaliciousUnknownBrowse
                    • 77.105.135.60
                    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                    SKYLINKNLSecuriteInfo.com.Win64.TrojanX-gen.14578.3729.exeGet hashmaliciousUnknownBrowse
                    • 45.141.37.12
                    http://185.150.26.210/bot.x86_64Get hashmaliciousUnknownBrowse
                    • 185.150.26.210
                    bot.x86.elfGet hashmaliciousMirai, OkiruBrowse
                    • 185.150.26.210
                    SecuriteInfo.com.Linux.Siggen.9999.2215.16365.elfGet hashmaliciousMirai, OkiruBrowse
                    • 185.150.26.210
                    SecuriteInfo.com.Linux.Siggen.9999.23508.27121.elfGet hashmaliciousMirai, OkiruBrowse
                    • 185.150.26.210
                    IUuKCHla6X.elfGet hashmaliciousMirai, OkiruBrowse
                    • 185.150.26.210
                    4GZzy6vjRR.elfGet hashmaliciousMirai, OkiruBrowse
                    • 185.150.26.210
                    QXdKX2YT7x.elfGet hashmaliciousMirai, OkiruBrowse
                    • 185.150.26.210
                    FyLw329X1Q.elfGet hashmaliciousMirai, OkiruBrowse
                    • 185.150.26.210
                    84v276RQAQ.elfGet hashmaliciousMirai, OkiruBrowse
                    • 185.150.26.210
                    SKYLINKNLSecuriteInfo.com.Win64.TrojanX-gen.14578.3729.exeGet hashmaliciousUnknownBrowse
                    • 45.141.37.12
                    http://185.150.26.210/bot.x86_64Get hashmaliciousUnknownBrowse
                    • 185.150.26.210
                    bot.x86.elfGet hashmaliciousMirai, OkiruBrowse
                    • 185.150.26.210
                    SecuriteInfo.com.Linux.Siggen.9999.2215.16365.elfGet hashmaliciousMirai, OkiruBrowse
                    • 185.150.26.210
                    SecuriteInfo.com.Linux.Siggen.9999.23508.27121.elfGet hashmaliciousMirai, OkiruBrowse
                    • 185.150.26.210
                    IUuKCHla6X.elfGet hashmaliciousMirai, OkiruBrowse
                    • 185.150.26.210
                    4GZzy6vjRR.elfGet hashmaliciousMirai, OkiruBrowse
                    • 185.150.26.210
                    QXdKX2YT7x.elfGet hashmaliciousMirai, OkiruBrowse
                    • 185.150.26.210
                    FyLw329X1Q.elfGet hashmaliciousMirai, OkiruBrowse
                    • 185.150.26.210
                    84v276RQAQ.elfGet hashmaliciousMirai, OkiruBrowse
                    • 185.150.26.210
                    No context
                    No context
                    No created / dropped files found
                    File type:ELF 32-bit MSB executable, PowerPC or cisco 4500, version 1 (SYSV), statically linked, stripped
                    Entropy (8bit):6.217742381176895
                    TrID:
                    • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                    File name:zerppc.elf
                    File size:46'296 bytes
                    MD5:dca795506df8d44ff8a9d45e85caf92b
                    SHA1:1212e0e371e3ea71cc517f7ff644c9ff4362560e
                    SHA256:6d86b401f77c1ffcc9d29d1b157f44b08611b84c4ea238b32d76c48eae4f62da
                    SHA512:48173f7875e5dbf9333f0555bfc9839ee3703dbfb236e66ba353ef8b81850eeb38f32dca98a4c580ed4247b5c1602e45086b9a53c2331856f7b43b6dfaab0926
                    SSDEEP:768:UrpFtoekRioB66QTNC0SRhWELuIGSfZPsNDSYYc7qNnH:2FWTEX6QWRhWDShP0DSYB7unH
                    TLSH:19234B43721C0A27C5A25774253F17F093FFADA025E4B688A40F9B5A8971F372486F9E
                    File Content Preview:.ELF...........................4.........4. ...(....................................................................dt.Q.............................!..|......$H...H..m...$8!. |...N.. .!..|.......?.............../...@..\?........+../...A..$8...})......N..

                    ELF header

                    Class:ELF32
                    Data:2's complement, big endian
                    Version:1 (current)
                    Machine:PowerPC
                    Version Number:0x1
                    Type:EXEC (Executable file)
                    OS/ABI:UNIX - System V
                    ABI Version:0
                    Entry Point Address:0x100001f0
                    Flags:0x0
                    ELF Header Size:52
                    Program Header Offset:52
                    Program Header Size:32
                    Number of Program Headers:3
                    Section Header Offset:45776
                    Section Header Size:40
                    Number of Section Headers:13
                    Header String Table Index:12
                    NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                    NULL0x00x00x00x00x0000
                    .initPROGBITS0x100000940x940x240x00x6AX004
                    .textPROGBITS0x100000b80xb80xa6c40x00x6AX004
                    .finiPROGBITS0x1000a77c0xa77c0x200x00x6AX004
                    .rodataPROGBITS0x1000a79c0xa79c0x95c0x00x2A004
                    .ctorsPROGBITS0x1001b0fc0xb0fc0x80x00x3WA004
                    .dtorsPROGBITS0x1001b1040xb1040x80x00x3WA004
                    .jcrPROGBITS0x1001b10c0xb10c0x40x00x3WA004
                    .dataPROGBITS0x1001b1100xb1100x1480x00x3WA008
                    .sdataPROGBITS0x1001b2580xb2580x280x00x3WA004
                    .sbssNOBITS0x1001b2800xb2800x5c0x00x3WA004
                    .bssNOBITS0x1001b2dc0xb2800x10c0x00x3WA004
                    .shstrtabSTRTAB0x00xb2800x500x00x0001
                    TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                    LOAD0x00x100000000x100000000xb0f80xb0f86.27490x5R E0x10000.init .text .fini .rodata
                    LOAD0xb0fc0x1001b0fc0x1001b0fc0x1840x2ec0.89880x6RW 0x10000.ctors .dtors .jcr .data .sdata .sbss .bss
                    GNU_STACK0x00x00x00x00x00.00000x6RW 0x4
                    TimestampSource PortDest PortSource IPDest IP
                    Oct 27, 2024 08:58:03.487375021 CET3343638241192.168.2.13185.150.24.67
                    Oct 27, 2024 08:58:03.492981911 CET3824133436185.150.24.67192.168.2.13
                    Oct 27, 2024 08:58:03.493212938 CET3343638241192.168.2.13185.150.24.67
                    Oct 27, 2024 08:58:03.506023884 CET3343638241192.168.2.13185.150.24.67
                    Oct 27, 2024 08:58:03.511667967 CET3824133436185.150.24.67192.168.2.13
                    Oct 27, 2024 08:58:03.511856079 CET3343638241192.168.2.13185.150.24.67
                    Oct 27, 2024 08:58:03.517400980 CET3824133436185.150.24.67192.168.2.13
                    Oct 27, 2024 08:58:04.275667906 CET3824133436185.150.24.67192.168.2.13
                    Oct 27, 2024 08:58:04.276146889 CET3343638241192.168.2.13185.150.24.67
                    Oct 27, 2024 08:58:04.282031059 CET3824133436185.150.24.67192.168.2.13
                    Oct 27, 2024 08:58:05.289815903 CET3343838241192.168.2.13185.150.24.67
                    Oct 27, 2024 08:58:05.295377970 CET3824133438185.150.24.67192.168.2.13
                    Oct 27, 2024 08:58:05.295444012 CET3343838241192.168.2.13185.150.24.67
                    Oct 27, 2024 08:58:05.296185017 CET3343838241192.168.2.13185.150.24.67
                    Oct 27, 2024 08:58:05.301441908 CET3824133438185.150.24.67192.168.2.13
                    Oct 27, 2024 08:58:05.301491976 CET3343838241192.168.2.13185.150.24.67
                    Oct 27, 2024 08:58:05.306849957 CET3824133438185.150.24.67192.168.2.13
                    Oct 27, 2024 08:58:05.895735979 CET3824133438185.150.24.67192.168.2.13
                    Oct 27, 2024 08:58:05.896171093 CET3343838241192.168.2.13185.150.24.67
                    Oct 27, 2024 08:58:05.901988029 CET3824133438185.150.24.67192.168.2.13
                    Oct 27, 2024 08:58:06.910146952 CET3344038241192.168.2.13185.150.24.67
                    Oct 27, 2024 08:58:06.916084051 CET3824133440185.150.24.67192.168.2.13
                    Oct 27, 2024 08:58:06.916176081 CET3344038241192.168.2.13185.150.24.67
                    Oct 27, 2024 08:58:06.917084932 CET3344038241192.168.2.13185.150.24.67
                    Oct 27, 2024 08:58:06.922831059 CET3824133440185.150.24.67192.168.2.13
                    Oct 27, 2024 08:58:06.922992945 CET3344038241192.168.2.13185.150.24.67
                    Oct 27, 2024 08:58:06.928656101 CET3824133440185.150.24.67192.168.2.13
                    Oct 27, 2024 08:58:07.504314899 CET3824133440185.150.24.67192.168.2.13
                    Oct 27, 2024 08:58:07.504689932 CET3344038241192.168.2.13185.150.24.67
                    Oct 27, 2024 08:58:07.510468960 CET3824133440185.150.24.67192.168.2.13
                    Oct 27, 2024 08:58:08.523277998 CET4940038241192.168.2.1345.156.86.24
                    Oct 27, 2024 08:58:08.528814077 CET382414940045.156.86.24192.168.2.13
                    Oct 27, 2024 08:58:08.528871059 CET4940038241192.168.2.1345.156.86.24
                    Oct 27, 2024 08:58:08.530217886 CET4940038241192.168.2.1345.156.86.24
                    Oct 27, 2024 08:58:08.535504103 CET382414940045.156.86.24192.168.2.13
                    Oct 27, 2024 08:58:08.535559893 CET4940038241192.168.2.1345.156.86.24
                    Oct 27, 2024 08:58:08.540958881 CET382414940045.156.86.24192.168.2.13
                    Oct 27, 2024 08:58:18.540407896 CET4940038241192.168.2.1345.156.86.24
                    Oct 27, 2024 08:58:18.545696020 CET382414940045.156.86.24192.168.2.13
                    Oct 27, 2024 08:58:18.908116102 CET382414940045.156.86.24192.168.2.13
                    Oct 27, 2024 08:58:18.908360958 CET4940038241192.168.2.1345.156.86.24
                    Oct 27, 2024 08:58:18.913805962 CET382414940045.156.86.24192.168.2.13
                    Oct 27, 2024 08:58:19.940155983 CET4940238241192.168.2.1345.156.86.24
                    Oct 27, 2024 08:58:19.945480108 CET382414940245.156.86.24192.168.2.13
                    Oct 27, 2024 08:58:19.945599079 CET4940238241192.168.2.1345.156.86.24
                    Oct 27, 2024 08:58:19.946753025 CET4940238241192.168.2.1345.156.86.24
                    Oct 27, 2024 08:58:19.951170921 CET382414940245.156.86.24192.168.2.13
                    Oct 27, 2024 08:58:19.951288939 CET4940238241192.168.2.1345.156.86.24
                    Oct 27, 2024 08:58:19.952076912 CET382414940245.156.86.24192.168.2.13
                    Oct 27, 2024 08:58:19.956867933 CET382414940245.156.86.24192.168.2.13
                    Oct 27, 2024 08:58:20.966356039 CET4940438241192.168.2.1345.156.86.24
                    Oct 27, 2024 08:58:20.972070932 CET382414940445.156.86.24192.168.2.13
                    Oct 27, 2024 08:58:20.972330093 CET4940438241192.168.2.1345.156.86.24
                    Oct 27, 2024 08:58:20.973454952 CET4940438241192.168.2.1345.156.86.24
                    Oct 27, 2024 08:58:20.978754997 CET382414940445.156.86.24192.168.2.13
                    Oct 27, 2024 08:58:20.978816986 CET4940438241192.168.2.1345.156.86.24
                    Oct 27, 2024 08:58:20.984126091 CET382414940445.156.86.24192.168.2.13
                    Oct 27, 2024 08:58:31.791130066 CET382414940445.156.86.24192.168.2.13
                    Oct 27, 2024 08:58:31.791388035 CET4940438241192.168.2.1345.156.86.24
                    Oct 27, 2024 08:58:31.796966076 CET382414940445.156.86.24192.168.2.13
                    Oct 27, 2024 08:58:32.828563929 CET3344838241192.168.2.13185.150.24.67
                    Oct 27, 2024 08:58:32.835189104 CET3824133448185.150.24.67192.168.2.13
                    Oct 27, 2024 08:58:32.835275888 CET3344838241192.168.2.13185.150.24.67
                    Oct 27, 2024 08:58:32.836328983 CET3344838241192.168.2.13185.150.24.67
                    Oct 27, 2024 08:58:32.842963934 CET3824133448185.150.24.67192.168.2.13
                    Oct 27, 2024 08:58:32.843024015 CET3344838241192.168.2.13185.150.24.67
                    Oct 27, 2024 08:58:32.848917961 CET3824133448185.150.24.67192.168.2.13
                    Oct 27, 2024 08:58:33.432430029 CET3824133448185.150.24.67192.168.2.13
                    Oct 27, 2024 08:58:33.432663918 CET3344838241192.168.2.13185.150.24.67
                    Oct 27, 2024 08:58:33.437984943 CET3824133448185.150.24.67192.168.2.13
                    Oct 27, 2024 08:58:34.464654922 CET3345038241192.168.2.13185.150.24.67
                    Oct 27, 2024 08:58:34.469948053 CET3824133450185.150.24.67192.168.2.13
                    Oct 27, 2024 08:58:34.469990015 CET3345038241192.168.2.13185.150.24.67
                    Oct 27, 2024 08:58:34.470756054 CET3345038241192.168.2.13185.150.24.67
                    Oct 27, 2024 08:58:34.476011038 CET3824133450185.150.24.67192.168.2.13
                    Oct 27, 2024 08:58:34.476066113 CET3345038241192.168.2.13185.150.24.67
                    Oct 27, 2024 08:58:34.481430054 CET3824133450185.150.24.67192.168.2.13
                    Oct 27, 2024 08:58:35.058887959 CET3824133450185.150.24.67192.168.2.13
                    Oct 27, 2024 08:58:35.059062958 CET3345038241192.168.2.13185.150.24.67
                    Oct 27, 2024 08:58:35.064425945 CET3824133450185.150.24.67192.168.2.13
                    Oct 27, 2024 08:58:36.073278904 CET4941038241192.168.2.1345.156.86.24
                    Oct 27, 2024 08:58:36.079051971 CET382414941045.156.86.24192.168.2.13
                    Oct 27, 2024 08:58:36.079124928 CET4941038241192.168.2.1345.156.86.24
                    Oct 27, 2024 08:58:36.080343008 CET4941038241192.168.2.1345.156.86.24
                    Oct 27, 2024 08:58:36.084661961 CET382414941045.156.86.24192.168.2.13
                    Oct 27, 2024 08:58:36.084726095 CET4941038241192.168.2.1345.156.86.24
                    Oct 27, 2024 08:58:36.085566998 CET382414941045.156.86.24192.168.2.13
                    Oct 27, 2024 08:58:36.092138052 CET382414941045.156.86.24192.168.2.13
                    Oct 27, 2024 08:58:37.099772930 CET4941238241192.168.2.1345.156.86.24
                    Oct 27, 2024 08:58:37.105921030 CET382414941245.156.86.24192.168.2.13
                    Oct 27, 2024 08:58:37.105993986 CET4941238241192.168.2.1345.156.86.24
                    Oct 27, 2024 08:58:37.106914997 CET4941238241192.168.2.1345.156.86.24
                    Oct 27, 2024 08:58:37.112454891 CET382414941245.156.86.24192.168.2.13
                    Oct 27, 2024 08:58:37.112560987 CET4941238241192.168.2.1345.156.86.24
                    Oct 27, 2024 08:58:37.112724066 CET382414941245.156.86.24192.168.2.13
                    Oct 27, 2024 08:58:37.119359016 CET382414941245.156.86.24192.168.2.13
                    Oct 27, 2024 08:58:38.149538040 CET4941438241192.168.2.1345.156.86.24
                    Oct 27, 2024 08:58:38.154901981 CET382414941445.156.86.24192.168.2.13
                    Oct 27, 2024 08:58:38.154972076 CET4941438241192.168.2.1345.156.86.24
                    Oct 27, 2024 08:58:38.156421900 CET4941438241192.168.2.1345.156.86.24
                    Oct 27, 2024 08:58:38.161798000 CET382414941445.156.86.24192.168.2.13
                    Oct 27, 2024 08:58:38.161856890 CET4941438241192.168.2.1345.156.86.24
                    Oct 27, 2024 08:58:38.167203903 CET382414941445.156.86.24192.168.2.13
                    Oct 27, 2024 08:58:48.988919020 CET382414941445.156.86.24192.168.2.13
                    Oct 27, 2024 08:58:48.989198923 CET4941438241192.168.2.1345.156.86.24
                    Oct 27, 2024 08:58:48.994652033 CET382414941445.156.86.24192.168.2.13
                    Oct 27, 2024 08:58:50.003118038 CET4941638241192.168.2.1345.156.86.24
                    Oct 27, 2024 08:58:50.008450031 CET382414941645.156.86.24192.168.2.13
                    Oct 27, 2024 08:58:50.008584976 CET4941638241192.168.2.1345.156.86.24
                    Oct 27, 2024 08:58:50.009548903 CET4941638241192.168.2.1345.156.86.24
                    Oct 27, 2024 08:58:50.014970064 CET382414941645.156.86.24192.168.2.13
                    Oct 27, 2024 08:58:50.015111923 CET4941638241192.168.2.1345.156.86.24
                    Oct 27, 2024 08:58:50.020457029 CET382414941645.156.86.24192.168.2.13
                    Oct 27, 2024 08:59:00.846548080 CET382414941645.156.86.24192.168.2.13
                    Oct 27, 2024 08:59:00.846698046 CET4941638241192.168.2.1345.156.86.24
                    Oct 27, 2024 08:59:00.853811979 CET382414941645.156.86.24192.168.2.13
                    Oct 27, 2024 08:59:01.879578114 CET4941838241192.168.2.1345.156.86.24
                    Oct 27, 2024 08:59:01.884915113 CET382414941845.156.86.24192.168.2.13
                    Oct 27, 2024 08:59:01.885001898 CET4941838241192.168.2.1345.156.86.24
                    Oct 27, 2024 08:59:01.886126041 CET4941838241192.168.2.1345.156.86.24
                    Oct 27, 2024 08:59:01.891594887 CET382414941845.156.86.24192.168.2.13
                    Oct 27, 2024 08:59:01.891663074 CET4941838241192.168.2.1345.156.86.24
                    Oct 27, 2024 08:59:01.897073030 CET382414941845.156.86.24192.168.2.13
                    Oct 27, 2024 08:59:12.713751078 CET382414941845.156.86.24192.168.2.13
                    Oct 27, 2024 08:59:12.714024067 CET4941838241192.168.2.1345.156.86.24
                    Oct 27, 2024 08:59:12.719320059 CET382414941845.156.86.24192.168.2.13
                    Oct 27, 2024 08:59:13.734813929 CET4942038241192.168.2.1345.156.86.24
                    Oct 27, 2024 08:59:13.740230083 CET382414942045.156.86.24192.168.2.13
                    Oct 27, 2024 08:59:13.740300894 CET4942038241192.168.2.1345.156.86.24
                    Oct 27, 2024 08:59:13.741133928 CET4942038241192.168.2.1345.156.86.24
                    Oct 27, 2024 08:59:13.746817112 CET382414942045.156.86.24192.168.2.13
                    Oct 27, 2024 08:59:13.746922016 CET4942038241192.168.2.1345.156.86.24
                    Oct 27, 2024 08:59:13.752222061 CET382414942045.156.86.24192.168.2.13
                    Oct 27, 2024 08:59:24.648431063 CET382414942045.156.86.24192.168.2.13
                    Oct 27, 2024 08:59:24.648576021 CET4942038241192.168.2.1345.156.86.24
                    Oct 27, 2024 08:59:24.654088020 CET382414942045.156.86.24192.168.2.13
                    Oct 27, 2024 08:59:25.663589954 CET4942238241192.168.2.1345.156.86.24
                    Oct 27, 2024 08:59:25.668962955 CET382414942245.156.86.24192.168.2.13
                    Oct 27, 2024 08:59:25.669054031 CET4942238241192.168.2.1345.156.86.24
                    Oct 27, 2024 08:59:25.670047998 CET4942238241192.168.2.1345.156.86.24
                    Oct 27, 2024 08:59:25.675384998 CET382414942245.156.86.24192.168.2.13
                    Oct 27, 2024 08:59:25.675442934 CET4942238241192.168.2.1345.156.86.24
                    Oct 27, 2024 08:59:25.680809975 CET382414942245.156.86.24192.168.2.13
                    Oct 27, 2024 08:59:35.680258036 CET4942238241192.168.2.1345.156.86.24
                    Oct 27, 2024 08:59:35.685676098 CET382414942245.156.86.24192.168.2.13
                    Oct 27, 2024 08:59:36.048253059 CET382414942245.156.86.24192.168.2.13
                    Oct 27, 2024 08:59:36.048736095 CET4942238241192.168.2.1345.156.86.24
                    Oct 27, 2024 08:59:36.054058075 CET382414942245.156.86.24192.168.2.13
                    Oct 27, 2024 08:59:37.070190907 CET4942438241192.168.2.1345.156.86.24
                    Oct 27, 2024 08:59:37.075700998 CET382414942445.156.86.24192.168.2.13
                    Oct 27, 2024 08:59:37.075794935 CET4942438241192.168.2.1345.156.86.24
                    Oct 27, 2024 08:59:37.077317953 CET4942438241192.168.2.1345.156.86.24
                    Oct 27, 2024 08:59:37.082617998 CET382414942445.156.86.24192.168.2.13
                    Oct 27, 2024 08:59:37.082686901 CET4942438241192.168.2.1345.156.86.24
                    Oct 27, 2024 08:59:37.088217974 CET382414942445.156.86.24192.168.2.13
                    Oct 27, 2024 08:59:47.890459061 CET382414942445.156.86.24192.168.2.13
                    Oct 27, 2024 08:59:47.890786886 CET4942438241192.168.2.1345.156.86.24
                    Oct 27, 2024 08:59:47.896379948 CET382414942445.156.86.24192.168.2.13
                    Oct 27, 2024 08:59:48.908127069 CET4942638241192.168.2.1345.156.86.24
                    Oct 27, 2024 08:59:48.913664103 CET382414942645.156.86.24192.168.2.13
                    Oct 27, 2024 08:59:48.913789034 CET4942638241192.168.2.1345.156.86.24
                    Oct 27, 2024 08:59:48.915234089 CET4942638241192.168.2.1345.156.86.24
                    Oct 27, 2024 08:59:48.920620918 CET382414942645.156.86.24192.168.2.13
                    Oct 27, 2024 08:59:48.920829058 CET4942638241192.168.2.1345.156.86.24
                    Oct 27, 2024 08:59:48.926218033 CET382414942645.156.86.24192.168.2.13
                    Oct 27, 2024 08:59:59.747068882 CET382414942645.156.86.24192.168.2.13
                    Oct 27, 2024 08:59:59.747354031 CET4942638241192.168.2.1345.156.86.24
                    Oct 27, 2024 08:59:59.752747059 CET382414942645.156.86.24192.168.2.13
                    Oct 27, 2024 09:00:00.767774105 CET4942838241192.168.2.1345.156.86.24
                    Oct 27, 2024 09:00:00.773186922 CET382414942845.156.86.24192.168.2.13
                    Oct 27, 2024 09:00:00.773297071 CET4942838241192.168.2.1345.156.86.24
                    Oct 27, 2024 09:00:00.774115086 CET4942838241192.168.2.1345.156.86.24
                    Oct 27, 2024 09:00:00.779386997 CET382414942845.156.86.24192.168.2.13
                    Oct 27, 2024 09:00:00.779434919 CET4942838241192.168.2.1345.156.86.24
                    Oct 27, 2024 09:00:00.784787893 CET382414942845.156.86.24192.168.2.13
                    TimestampSource PortDest PortSource IPDest IP
                    Oct 27, 2024 08:58:03.465802908 CET3451853192.168.2.1351.158.108.203
                    Oct 27, 2024 08:58:03.482372999 CET533451851.158.108.203192.168.2.13
                    Oct 27, 2024 08:58:05.278806925 CET5967653192.168.2.13202.61.197.122
                    Oct 27, 2024 08:58:05.289331913 CET5359676202.61.197.122192.168.2.13
                    Oct 27, 2024 08:58:06.898382902 CET5108153192.168.2.13152.53.15.127
                    Oct 27, 2024 08:58:06.909492016 CET5351081152.53.15.127192.168.2.13
                    Oct 27, 2024 08:58:08.506511927 CET4401053192.168.2.1351.158.108.203
                    Oct 27, 2024 08:58:08.522433043 CET534401051.158.108.203192.168.2.13
                    Oct 27, 2024 08:58:19.911047935 CET6040253192.168.2.1381.169.136.222
                    Oct 27, 2024 08:58:19.939189911 CET536040281.169.136.222192.168.2.13
                    Oct 27, 2024 08:58:20.954787970 CET4546353192.168.2.13194.36.144.87
                    Oct 27, 2024 08:58:20.965321064 CET5345463194.36.144.87192.168.2.13
                    Oct 27, 2024 08:58:32.794020891 CET4945653192.168.2.13185.181.61.24
                    Oct 27, 2024 08:58:32.827630043 CET5349456185.181.61.24192.168.2.13
                    Oct 27, 2024 08:58:34.435870886 CET4387953192.168.2.1381.169.136.222
                    Oct 27, 2024 08:58:34.464160919 CET534387981.169.136.222192.168.2.13
                    Oct 27, 2024 08:58:36.061888933 CET3870253192.168.2.13194.36.144.87
                    Oct 27, 2024 08:58:36.072698116 CET5338702194.36.144.87192.168.2.13
                    Oct 27, 2024 08:58:37.087366104 CET3983753192.168.2.13152.53.15.127
                    Oct 27, 2024 08:58:37.099116087 CET5339837152.53.15.127192.168.2.13
                    Oct 27, 2024 08:58:38.115178108 CET5937953192.168.2.13185.181.61.24
                    Oct 27, 2024 08:58:38.148529053 CET5359379185.181.61.24192.168.2.13
                    Oct 27, 2024 08:58:49.991590023 CET3940953192.168.2.13202.61.197.122
                    Oct 27, 2024 08:58:50.002639055 CET5339409202.61.197.122192.168.2.13
                    Oct 27, 2024 08:59:01.849875927 CET5908153192.168.2.1381.169.136.222
                    Oct 27, 2024 08:59:01.878751993 CET535908181.169.136.222192.168.2.13
                    Oct 27, 2024 08:59:13.717858076 CET5106353192.168.2.1351.158.108.203
                    Oct 27, 2024 08:59:13.734034061 CET535106351.158.108.203192.168.2.13
                    Oct 27, 2024 08:59:25.652400970 CET4061153192.168.2.13202.61.197.122
                    Oct 27, 2024 08:59:25.663000107 CET5340611202.61.197.122192.168.2.13
                    Oct 27, 2024 08:59:37.052851915 CET5696053192.168.2.1351.158.108.203
                    Oct 27, 2024 08:59:37.069034100 CET535696051.158.108.203192.168.2.13
                    Oct 27, 2024 08:59:48.896055937 CET4174353192.168.2.13202.61.197.122
                    Oct 27, 2024 08:59:48.906852961 CET5341743202.61.197.122192.168.2.13
                    Oct 27, 2024 09:00:00.750327110 CET5621353192.168.2.1351.158.108.203
                    Oct 27, 2024 09:00:00.767127991 CET535621351.158.108.203192.168.2.13
                    TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                    Oct 27, 2024 08:58:03.465802908 CET192.168.2.1351.158.108.2030xa175Standard query (0)chinklabs.dynA (IP address)IN (0x0001)false
                    Oct 27, 2024 08:58:05.278806925 CET192.168.2.13202.61.197.1220x76d0Standard query (0)netfags.geek. [malformed]256397false
                    Oct 27, 2024 08:58:06.898382902 CET192.168.2.13152.53.15.1270x2f6fStandard query (0)netfags.geek. [malformed]256398false
                    Oct 27, 2024 08:58:08.506511927 CET192.168.2.1351.158.108.2030xee81Standard query (0)yellowchink.pirateA (IP address)IN (0x0001)false
                    Oct 27, 2024 08:58:19.911047935 CET192.168.2.1381.169.136.2220x32a0Standard query (0)burnthe.libre. [malformed]256411false
                    Oct 27, 2024 08:58:20.954787970 CET192.168.2.13194.36.144.870xd221Standard query (0)netfags.geek. [malformed]256412false
                    Oct 27, 2024 08:58:32.794020891 CET192.168.2.13185.181.61.240xe8e0Standard query (0)chinklabs.dynA (IP address)IN (0x0001)false
                    Oct 27, 2024 08:58:34.435870886 CET192.168.2.1381.169.136.2220xc402Standard query (0)netfags.geek. [malformed]256426false
                    Oct 27, 2024 08:58:36.061888933 CET192.168.2.13194.36.144.870x8286Standard query (0)burnthe.libreA (IP address)IN (0x0001)false
                    Oct 27, 2024 08:58:37.087366104 CET192.168.2.13152.53.15.1270xd359Standard query (0)yellowchink.pirate. [malformed]256429false
                    Oct 27, 2024 08:58:38.115178108 CET192.168.2.13185.181.61.240x4045Standard query (0)chinklabs.dyn. [malformed]256430false
                    Oct 27, 2024 08:58:49.991590023 CET192.168.2.13202.61.197.1220x91e0Standard query (0)netfags.geek. [malformed]256442false
                    Oct 27, 2024 08:59:01.849875927 CET192.168.2.1381.169.136.2220xbb0dStandard query (0)yellowchink.pirate. [malformed]256453false
                    Oct 27, 2024 08:59:13.717858076 CET192.168.2.1351.158.108.2030xf354Standard query (0)burnthe.libre. [malformed]256465false
                    Oct 27, 2024 08:59:25.652400970 CET192.168.2.13202.61.197.1220x802aStandard query (0)chinklabs.dyn. [malformed]256477false
                    Oct 27, 2024 08:59:37.052851915 CET192.168.2.1351.158.108.2030x217eStandard query (0)chinklabs.dyn. [malformed]256489false
                    Oct 27, 2024 08:59:48.896055937 CET192.168.2.13202.61.197.1220xb8ecStandard query (0)burnthe.libre. [malformed]256500false
                    Oct 27, 2024 09:00:00.750327110 CET192.168.2.1351.158.108.2030x95eeStandard query (0)netfags.geek. [malformed]256256false
                    TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                    Oct 27, 2024 08:58:03.482372999 CET51.158.108.203192.168.2.130xa175No error (0)chinklabs.dyn185.150.24.67A (IP address)IN (0x0001)false
                    Oct 27, 2024 08:58:06.909492016 CET152.53.15.127192.168.2.130x2f6fFormat error (1)netfags.geek. [malformed]nonenone256398false
                    Oct 27, 2024 08:58:08.522433043 CET51.158.108.203192.168.2.130xee81No error (0)yellowchink.pirate45.156.86.24A (IP address)IN (0x0001)false
                    Oct 27, 2024 08:58:20.965321064 CET194.36.144.87192.168.2.130xd221Format error (1)netfags.geek. [malformed]nonenone256412false
                    Oct 27, 2024 08:58:32.827630043 CET185.181.61.24192.168.2.130xe8e0No error (0)chinklabs.dyn185.150.24.67A (IP address)IN (0x0001)false
                    Oct 27, 2024 08:58:36.072698116 CET194.36.144.87192.168.2.130x8286No error (0)burnthe.libre45.156.86.24A (IP address)IN (0x0001)false
                    Oct 27, 2024 08:58:37.099116087 CET152.53.15.127192.168.2.130xd359Format error (1)yellowchink.pirate. [malformed]nonenone256429false
                    Oct 27, 2024 08:59:13.734034061 CET51.158.108.203192.168.2.130xf354Format error (1)burnthe.libre. [malformed]nonenone256465false
                    Oct 27, 2024 08:59:37.069034100 CET51.158.108.203192.168.2.130x217eFormat error (1)chinklabs.dyn. [malformed]nonenone256489false
                    Oct 27, 2024 09:00:00.767127991 CET51.158.108.203192.168.2.130x95eeFormat error (1)netfags.geek. [malformed]nonenone256256false

                    System Behavior

                    Start time (UTC):07:58:02
                    Start date (UTC):27/10/2024
                    Path:/tmp/zerppc.elf
                    Arguments:/tmp/zerppc.elf
                    File size:5388968 bytes
                    MD5 hash:ae65271c943d3451b7f026d1fadccea6

                    Start time (UTC):07:58:02
                    Start date (UTC):27/10/2024
                    Path:/tmp/zerppc.elf
                    Arguments:-
                    File size:5388968 bytes
                    MD5 hash:ae65271c943d3451b7f026d1fadccea6

                    Start time (UTC):07:58:02
                    Start date (UTC):27/10/2024
                    Path:/tmp/zerppc.elf
                    Arguments:-
                    File size:5388968 bytes
                    MD5 hash:ae65271c943d3451b7f026d1fadccea6