Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
zersh4.elf

Overview

General Information

Sample name:zersh4.elf
Analysis ID:1543113
MD5:69c06f74f2d01a61af66c16b94dc6e69
SHA1:197b464349a2f892a8c56de727b595a0ff75d53b
SHA256:a2e0455a1f5df5ae123205bde79c67e29b711fc26687c1798786ef6eff4567bf
Tags:elfuser-abuse_ch
Infos:

Detection

Score:56
Range:0 - 100
Whitelisted:false

Signatures

Multi AV Scanner detection for submitted file
Connects to many ports of the same IP (likely port scanning)
Sends malformed DNS queries
Detected TCP or UDP traffic on non-standard ports
Sample has stripped symbol table
Sample listens on a socket
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1543113
Start date and time:2024-10-27 09:13:59 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 50s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:zersh4.elf
Detection:MAL
Classification:mal56.troj.linELF@0/0@12/0
  • VT rate limit hit for: zersh4.elf
Command:/tmp/zersh4.elf
PID:5636
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
The Peoples Bank of China.
Standard Error:
  • system is lnxubuntu20
  • zersh4.elf (PID: 5636, Parent: 5556, MD5: 8943e5f8f8c280467b4472c15ae93ba9) Arguments: /tmp/zersh4.elf
  • cleanup
No yara matches
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: zersh4.elfReversingLabs: Detection: 44%

Networking

barindex
Source: global trafficTCP traffic: 185.150.24.67 ports 38241,1,2,3,4,8
Source: global trafficTCP traffic: 45.156.86.24 ports 38241,1,2,3,4,8
Source: global trafficDNS traffic detected: malformed DNS query: netfags.geek. [malformed]
Source: global trafficDNS traffic detected: malformed DNS query: chinklabs.dyn. [malformed]
Source: global trafficDNS traffic detected: malformed DNS query: yellowchink.pirate. [malformed]
Source: global trafficDNS traffic detected: malformed DNS query: burnthe.libre. [malformed]
Source: global trafficTCP traffic: 192.168.2.14:57382 -> 45.156.86.24:38241
Source: global trafficTCP traffic: 192.168.2.14:49902 -> 185.150.24.67:38241
Source: /tmp/zersh4.elf (PID: 5636)Socket: 127.0.0.1:39148Jump to behavior
Source: unknownUDP traffic detected without corresponding DNS query: 185.181.61.24
Source: unknownUDP traffic detected without corresponding DNS query: 185.181.61.24
Source: unknownUDP traffic detected without corresponding DNS query: 185.181.61.24
Source: unknownUDP traffic detected without corresponding DNS query: 194.36.144.87
Source: unknownUDP traffic detected without corresponding DNS query: 168.235.111.72
Source: unknownUDP traffic detected without corresponding DNS query: 81.169.136.222
Source: unknownUDP traffic detected without corresponding DNS query: 202.61.197.122
Source: unknownUDP traffic detected without corresponding DNS query: 168.235.111.72
Source: unknownUDP traffic detected without corresponding DNS query: 202.61.197.122
Source: unknownUDP traffic detected without corresponding DNS query: 194.36.144.87
Source: unknownUDP traffic detected without corresponding DNS query: 51.158.108.203
Source: unknownUDP traffic detected without corresponding DNS query: 194.36.144.87
Source: global trafficDNS traffic detected: DNS query: netfags.geek
Source: global trafficDNS traffic detected: DNS query: chinklabs.dyn
Source: global trafficDNS traffic detected: DNS query: burnthe.libre
Source: global trafficDNS traffic detected: DNS query: yellowchink.pirate
Source: global trafficDNS traffic detected: DNS query: netfags.geek. [malformed]
Source: global trafficDNS traffic detected: DNS query: chinklabs.dyn. [malformed]
Source: global trafficDNS traffic detected: DNS query: yellowchink.pirate. [malformed]
Source: global trafficDNS traffic detected: DNS query: burnthe.libre. [malformed]
Source: ELF static info symbol of initial sample.symtab present: no
Source: classification engineClassification label: mal56.troj.linELF@0/0@12/0
Source: /tmp/zersh4.elf (PID: 5636)Queries kernel information via 'uname': Jump to behavior
Source: zersh4.elf, 5636.1.00007ffd96ca4000.00007ffd96cc5000.rw-.sdmpBinary or memory string: /usr/bin/qemu-sh4
Source: zersh4.elf, 5636.1.000055ed7f38d000.000055ed7f3f0000.rw-.sdmpBinary or memory string: U5!/etc/qemu-binfmt/sh4
Source: zersh4.elf, 5636.1.000055ed7f38d000.000055ed7f3f0000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/sh4
Source: zersh4.elf, 5636.1.00007ffd96ca4000.00007ffd96cc5000.rw-.sdmpBinary or memory string: tx86_64/usr/bin/qemu-sh4/tmp/zersh4.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/zersh4.elf
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath InterceptionDirect Volume AccessOS Credential Dumping11
Security Software Discovery
Remote ServicesData from Local System1
Non-Standard Port
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1543113 Sample: zersh4.elf Startdate: 27/10/2024 Architecture: LINUX Score: 56 14 yellowchink.pirate. [malformed] 2->14 16 netfags.geek. [malformed] 2->16 18 6 other IPs or domains 2->18 20 Multi AV Scanner detection for submitted file 2->20 22 Connects to many ports of the same IP (likely port scanning) 2->22 8 zersh4.elf 2->8         started        signatures3 24 Sends malformed DNS queries 16->24 process4 process5 10 zersh4.elf 8->10         started        process6 12 zersh4.elf 10->12         started       
SourceDetectionScannerLabelLink
zersh4.elf45%ReversingLabsLinux.Backdoor.Gafgyt
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
netfags.geek
45.156.86.24
truetrue
    unknown
    yellowchink.pirate
    45.156.86.24
    truetrue
      unknown
      chinklabs.dyn
      185.150.24.67
      truetrue
        unknown
        burnthe.libre
        45.156.86.24
        truetrue
          unknown
          chinklabs.dyn. [malformed]
          unknown
          unknowntrue
            unknown
            netfags.geek. [malformed]
            unknown
            unknowntrue
              unknown
              burnthe.libre. [malformed]
              unknown
              unknowntrue
                unknown
                yellowchink.pirate. [malformed]
                unknown
                unknowntrue
                  unknown
                  • No. of IPs < 25%
                  • 25% < No. of IPs < 50%
                  • 50% < No. of IPs < 75%
                  • 75% < No. of IPs
                  IPDomainCountryFlagASNASN NameMalicious
                  185.150.24.67
                  chinklabs.dynNetherlands
                  44592SKYLINKNLtrue
                  45.156.86.24
                  netfags.geekGermany
                  44592SKYLINKNLtrue
                  MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                  185.150.24.67zerppc.elfGet hashmaliciousUnknownBrowse
                    file.exeGet hashmaliciousUnknownBrowse
                      https://search-dl3.com/staticpr/12.zipGet hashmaliciousUnknownBrowse
                        45.156.86.24nabsh4.elfGet hashmaliciousUnknownBrowse
                          nabmpsl.elfGet hashmaliciousUnknownBrowse
                            zerppc.elfGet hashmaliciousUnknownBrowse
                              MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                              netfags.geekjklppc.elfGet hashmaliciousUnknownBrowse
                              • 45.156.86.24
                              splmips.elfGet hashmaliciousUnknownBrowse
                              • 45.156.86.24
                              burnthe.librearm7.elfGet hashmaliciousUnknownBrowse
                              • 45.156.86.24
                              nabmpsl.elfGet hashmaliciousUnknownBrowse
                              • 45.156.86.24
                              splx86.elfGet hashmaliciousUnknownBrowse
                              • 45.156.86.24
                              jklarm.elfGet hashmaliciousUnknownBrowse
                              • 45.156.86.24
                              mpsl.elfGet hashmaliciousUnknownBrowse
                              • 45.156.86.24
                              nklmips.elfGet hashmaliciousUnknownBrowse
                              • 45.156.86.24
                              yellowchink.piratejklx86.elfGet hashmaliciousUnknownBrowse
                              • 45.156.86.24
                              jklppc.elfGet hashmaliciousUnknownBrowse
                              • 45.156.86.24
                              nabmpsl.elfGet hashmaliciousUnknownBrowse
                              • 45.156.86.24
                              chinklabs.dynnabmpsl.elfGet hashmaliciousUnknownBrowse
                              • 185.150.24.67
                              jklarm.elfGet hashmaliciousUnknownBrowse
                              • 185.150.24.67
                              MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                              SKYLINKNLnabsh4.elfGet hashmaliciousUnknownBrowse
                              • 45.156.86.24
                              nabmpsl.elfGet hashmaliciousUnknownBrowse
                              • 45.156.86.24
                              zerppc.elfGet hashmaliciousUnknownBrowse
                              • 45.156.86.24
                              SecuriteInfo.com.Win64.TrojanX-gen.14578.3729.exeGet hashmaliciousUnknownBrowse
                              • 45.141.37.12
                              http://185.150.26.210/bot.x86_64Get hashmaliciousUnknownBrowse
                              • 185.150.26.210
                              bot.x86.elfGet hashmaliciousMirai, OkiruBrowse
                              • 185.150.26.210
                              SecuriteInfo.com.Linux.Siggen.9999.2215.16365.elfGet hashmaliciousMirai, OkiruBrowse
                              • 185.150.26.210
                              SecuriteInfo.com.Linux.Siggen.9999.23508.27121.elfGet hashmaliciousMirai, OkiruBrowse
                              • 185.150.26.210
                              IUuKCHla6X.elfGet hashmaliciousMirai, OkiruBrowse
                              • 185.150.26.210
                              4GZzy6vjRR.elfGet hashmaliciousMirai, OkiruBrowse
                              • 185.150.26.210
                              SKYLINKNLnabsh4.elfGet hashmaliciousUnknownBrowse
                              • 45.156.86.24
                              nabmpsl.elfGet hashmaliciousUnknownBrowse
                              • 45.156.86.24
                              zerppc.elfGet hashmaliciousUnknownBrowse
                              • 45.156.86.24
                              SecuriteInfo.com.Win64.TrojanX-gen.14578.3729.exeGet hashmaliciousUnknownBrowse
                              • 45.141.37.12
                              http://185.150.26.210/bot.x86_64Get hashmaliciousUnknownBrowse
                              • 185.150.26.210
                              bot.x86.elfGet hashmaliciousMirai, OkiruBrowse
                              • 185.150.26.210
                              SecuriteInfo.com.Linux.Siggen.9999.2215.16365.elfGet hashmaliciousMirai, OkiruBrowse
                              • 185.150.26.210
                              SecuriteInfo.com.Linux.Siggen.9999.23508.27121.elfGet hashmaliciousMirai, OkiruBrowse
                              • 185.150.26.210
                              IUuKCHla6X.elfGet hashmaliciousMirai, OkiruBrowse
                              • 185.150.26.210
                              4GZzy6vjRR.elfGet hashmaliciousMirai, OkiruBrowse
                              • 185.150.26.210
                              No context
                              No context
                              No created / dropped files found
                              File type:ELF 32-bit LSB executable, Renesas SH, version 1 (SYSV), statically linked, stripped
                              Entropy (8bit):6.774950137456954
                              TrID:
                              • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                              File name:zersh4.elf
                              File size:42'636 bytes
                              MD5:69c06f74f2d01a61af66c16b94dc6e69
                              SHA1:197b464349a2f892a8c56de727b595a0ff75d53b
                              SHA256:a2e0455a1f5df5ae123205bde79c67e29b711fc26687c1798786ef6eff4567bf
                              SHA512:1b66d9eca06183d0f239c9b3f88271a630983669ae1e7ec434ca9fa6aa8e0898fab79b09e9eb6a53ccfd60e03c60621206feef6ae17f3b63d78cd5863ad84227
                              SSDEEP:768:aarwtOa65mMekU9m64F4kE4A27C2Cp8oORuCbhsn:aarwtOdtBFXEL2u2E7KuClsn
                              TLSH:79137EB688AEAD94C19B4674F8705D782F43F200D2631EFB6A4588A65043DBCF61A3F5
                              File Content Preview:.ELF..............*.......@.4...........4. ...(...............@...@...........................A...A.|...............Q.td............................././"O.n........#.*@........#.*@.....o&O.n...l..............................././.../.a"O.!...n...a.b("...q.

                              ELF header

                              Class:ELF32
                              Data:2's complement, little endian
                              Version:1 (current)
                              Machine:<unknown>
                              Version Number:0x1
                              Type:EXEC (Executable file)
                              OS/ABI:UNIX - System V
                              ABI Version:0
                              Entry Point Address:0x4001a0
                              Flags:0x9
                              ELF Header Size:52
                              Program Header Offset:52
                              Program Header Size:32
                              Number of Program Headers:3
                              Section Header Offset:42196
                              Section Header Size:40
                              Number of Section Headers:11
                              Header String Table Index:10
                              NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                              NULL0x00x00x00x00x0000
                              .initPROGBITS0x4000940x940x300x00x6AX004
                              .textPROGBITS0x4000e00xe00x99200x00x6AX0032
                              .finiPROGBITS0x409a000x9a000x240x00x6AX004
                              .rodataPROGBITS0x409a240x9a240x8ec0x00x2A004
                              .ctorsPROGBITS0x41a3140xa3140x80x00x3WA004
                              .dtorsPROGBITS0x41a31c0xa31c0x80x00x3WA004
                              .jcrPROGBITS0x41a3240xa3240x40x00x3WA004
                              .dataPROGBITS0x41a3280xa3280x1680x00x3WA004
                              .bssNOBITS0x41a4900xa4900x1780x00x3WA004
                              .shstrtabSTRTAB0x00xa4900x430x00x0001
                              TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                              LOAD0x00x4000000x4000000xa3100xa3106.83490x5R E0x10000.init .text .fini .rodata
                              LOAD0xa3140x41a3140x41a3140x17c0x2f40.89610x6RW 0x10000.ctors .dtors .jcr .data .bss
                              GNU_STACK0x00x00x00x00x00.00000x7RWE0x4
                              TimestampSource PortDest PortSource IPDest IP
                              Oct 27, 2024 09:15:01.331991911 CET5738238241192.168.2.1445.156.86.24
                              Oct 27, 2024 09:15:01.338572979 CET382415738245.156.86.24192.168.2.14
                              Oct 27, 2024 09:15:01.338641882 CET5738238241192.168.2.1445.156.86.24
                              Oct 27, 2024 09:15:01.340506077 CET5738238241192.168.2.1445.156.86.24
                              Oct 27, 2024 09:15:01.347127914 CET382415738245.156.86.24192.168.2.14
                              Oct 27, 2024 09:15:01.347182035 CET5738238241192.168.2.1445.156.86.24
                              Oct 27, 2024 09:15:01.353826046 CET382415738245.156.86.24192.168.2.14
                              Oct 27, 2024 09:15:11.342679977 CET5738238241192.168.2.1445.156.86.24
                              Oct 27, 2024 09:15:11.348035097 CET382415738245.156.86.24192.168.2.14
                              Oct 27, 2024 09:15:11.711098909 CET382415738245.156.86.24192.168.2.14
                              Oct 27, 2024 09:15:11.711869955 CET5738238241192.168.2.1445.156.86.24
                              Oct 27, 2024 09:15:11.717874050 CET382415738245.156.86.24192.168.2.14
                              Oct 27, 2024 09:15:12.750804901 CET4990238241192.168.2.14185.150.24.67
                              Oct 27, 2024 09:15:12.756156921 CET3824149902185.150.24.67192.168.2.14
                              Oct 27, 2024 09:15:12.756248951 CET4990238241192.168.2.14185.150.24.67
                              Oct 27, 2024 09:15:12.757302999 CET4990238241192.168.2.14185.150.24.67
                              Oct 27, 2024 09:15:12.763278008 CET3824149902185.150.24.67192.168.2.14
                              Oct 27, 2024 09:15:12.763366938 CET4990238241192.168.2.14185.150.24.67
                              Oct 27, 2024 09:15:12.769666910 CET3824149902185.150.24.67192.168.2.14
                              Oct 27, 2024 09:15:13.497633934 CET3824149902185.150.24.67192.168.2.14
                              Oct 27, 2024 09:15:13.498105049 CET4990238241192.168.2.14185.150.24.67
                              Oct 27, 2024 09:15:13.510778904 CET3824149902185.150.24.67192.168.2.14
                              Oct 27, 2024 09:15:14.539948940 CET5738638241192.168.2.1445.156.86.24
                              Oct 27, 2024 09:15:14.545317888 CET382415738645.156.86.24192.168.2.14
                              Oct 27, 2024 09:15:14.545377016 CET5738638241192.168.2.1445.156.86.24
                              Oct 27, 2024 09:15:14.546195984 CET5738638241192.168.2.1445.156.86.24
                              Oct 27, 2024 09:15:14.551515102 CET382415738645.156.86.24192.168.2.14
                              Oct 27, 2024 09:15:14.551559925 CET5738638241192.168.2.1445.156.86.24
                              Oct 27, 2024 09:15:14.556950092 CET382415738645.156.86.24192.168.2.14
                              Oct 27, 2024 09:15:25.391902924 CET382415738645.156.86.24192.168.2.14
                              Oct 27, 2024 09:15:25.392019987 CET5738638241192.168.2.1445.156.86.24
                              Oct 27, 2024 09:15:25.397372007 CET382415738645.156.86.24192.168.2.14
                              Oct 27, 2024 09:15:26.406553984 CET5738838241192.168.2.1445.156.86.24
                              Oct 27, 2024 09:15:26.421902895 CET382415738845.156.86.24192.168.2.14
                              Oct 27, 2024 09:15:26.421988964 CET5738838241192.168.2.1445.156.86.24
                              Oct 27, 2024 09:15:26.423185110 CET5738838241192.168.2.1445.156.86.24
                              Oct 27, 2024 09:15:26.428566933 CET382415738845.156.86.24192.168.2.14
                              Oct 27, 2024 09:15:26.428621054 CET5738838241192.168.2.1445.156.86.24
                              Oct 27, 2024 09:15:26.433968067 CET382415738845.156.86.24192.168.2.14
                              Oct 27, 2024 09:15:37.263693094 CET382415738845.156.86.24192.168.2.14
                              Oct 27, 2024 09:15:37.263947010 CET5738838241192.168.2.1445.156.86.24
                              Oct 27, 2024 09:15:37.270060062 CET382415738845.156.86.24192.168.2.14
                              Oct 27, 2024 09:15:38.367033005 CET5739038241192.168.2.1445.156.86.24
                              Oct 27, 2024 09:15:38.372360945 CET382415739045.156.86.24192.168.2.14
                              Oct 27, 2024 09:15:38.372625113 CET5739038241192.168.2.1445.156.86.24
                              Oct 27, 2024 09:15:38.374423027 CET5739038241192.168.2.1445.156.86.24
                              Oct 27, 2024 09:15:38.379697084 CET382415739045.156.86.24192.168.2.14
                              Oct 27, 2024 09:15:38.379762888 CET5739038241192.168.2.1445.156.86.24
                              Oct 27, 2024 09:15:38.385195017 CET382415739045.156.86.24192.168.2.14
                              Oct 27, 2024 09:15:49.217571974 CET382415739045.156.86.24192.168.2.14
                              Oct 27, 2024 09:15:49.217722893 CET5739038241192.168.2.1445.156.86.24
                              Oct 27, 2024 09:15:49.224553108 CET382415739045.156.86.24192.168.2.14
                              Oct 27, 2024 09:15:50.251389980 CET5739238241192.168.2.1445.156.86.24
                              Oct 27, 2024 09:15:50.257087946 CET382415739245.156.86.24192.168.2.14
                              Oct 27, 2024 09:15:50.257312059 CET5739238241192.168.2.1445.156.86.24
                              Oct 27, 2024 09:15:50.258729935 CET5739238241192.168.2.1445.156.86.24
                              Oct 27, 2024 09:15:50.264185905 CET382415739245.156.86.24192.168.2.14
                              Oct 27, 2024 09:15:50.264250994 CET5739238241192.168.2.1445.156.86.24
                              Oct 27, 2024 09:15:50.269505024 CET382415739245.156.86.24192.168.2.14
                              Oct 27, 2024 09:16:01.078188896 CET382415739245.156.86.24192.168.2.14
                              Oct 27, 2024 09:16:01.078401089 CET5739238241192.168.2.1445.156.86.24
                              Oct 27, 2024 09:16:01.083723068 CET382415739245.156.86.24192.168.2.14
                              Oct 27, 2024 09:16:02.094050884 CET5739438241192.168.2.1445.156.86.24
                              Oct 27, 2024 09:16:02.100519896 CET382415739445.156.86.24192.168.2.14
                              Oct 27, 2024 09:16:02.100579023 CET5739438241192.168.2.1445.156.86.24
                              Oct 27, 2024 09:16:02.101581097 CET5739438241192.168.2.1445.156.86.24
                              Oct 27, 2024 09:16:02.108100891 CET382415739445.156.86.24192.168.2.14
                              Oct 27, 2024 09:16:02.108151913 CET5739438241192.168.2.1445.156.86.24
                              Oct 27, 2024 09:16:02.114514112 CET382415739445.156.86.24192.168.2.14
                              Oct 27, 2024 09:16:12.939101934 CET382415739445.156.86.24192.168.2.14
                              Oct 27, 2024 09:16:12.939531088 CET5739438241192.168.2.1445.156.86.24
                              Oct 27, 2024 09:16:12.944886923 CET382415739445.156.86.24192.168.2.14
                              Oct 27, 2024 09:16:14.033245087 CET5739638241192.168.2.1445.156.86.24
                              Oct 27, 2024 09:16:14.039390087 CET382415739645.156.86.24192.168.2.14
                              Oct 27, 2024 09:16:14.039465904 CET5739638241192.168.2.1445.156.86.24
                              Oct 27, 2024 09:16:14.041013956 CET5739638241192.168.2.1445.156.86.24
                              Oct 27, 2024 09:16:14.046438932 CET382415739645.156.86.24192.168.2.14
                              Oct 27, 2024 09:16:14.046529055 CET5739638241192.168.2.1445.156.86.24
                              Oct 27, 2024 09:16:14.051891088 CET382415739645.156.86.24192.168.2.14
                              Oct 27, 2024 09:16:24.050853014 CET5739638241192.168.2.1445.156.86.24
                              Oct 27, 2024 09:16:24.056719065 CET382415739645.156.86.24192.168.2.14
                              Oct 27, 2024 09:16:24.402950048 CET382415739645.156.86.24192.168.2.14
                              Oct 27, 2024 09:16:24.403280973 CET5739638241192.168.2.1445.156.86.24
                              Oct 27, 2024 09:16:24.410250902 CET382415739645.156.86.24192.168.2.14
                              Oct 27, 2024 09:16:25.421309948 CET5739838241192.168.2.1445.156.86.24
                              Oct 27, 2024 09:16:25.427423954 CET382415739845.156.86.24192.168.2.14
                              Oct 27, 2024 09:16:25.427668095 CET5739838241192.168.2.1445.156.86.24
                              Oct 27, 2024 09:16:25.429847002 CET5739838241192.168.2.1445.156.86.24
                              Oct 27, 2024 09:16:25.435412884 CET382415739845.156.86.24192.168.2.14
                              Oct 27, 2024 09:16:25.435647011 CET5739838241192.168.2.1445.156.86.24
                              Oct 27, 2024 09:16:25.441462994 CET382415739845.156.86.24192.168.2.14
                              Oct 27, 2024 09:16:36.255909920 CET382415739845.156.86.24192.168.2.14
                              Oct 27, 2024 09:16:36.256339073 CET5739838241192.168.2.1445.156.86.24
                              Oct 27, 2024 09:16:36.262180090 CET382415739845.156.86.24192.168.2.14
                              Oct 27, 2024 09:16:37.271364927 CET5740038241192.168.2.1445.156.86.24
                              Oct 27, 2024 09:16:37.277199984 CET382415740045.156.86.24192.168.2.14
                              Oct 27, 2024 09:16:37.277462006 CET5740038241192.168.2.1445.156.86.24
                              Oct 27, 2024 09:16:37.279304981 CET5740038241192.168.2.1445.156.86.24
                              Oct 27, 2024 09:16:37.286132097 CET382415740045.156.86.24192.168.2.14
                              Oct 27, 2024 09:16:37.286279917 CET5740038241192.168.2.1445.156.86.24
                              Oct 27, 2024 09:16:37.293081999 CET382415740045.156.86.24192.168.2.14
                              Oct 27, 2024 09:16:48.109167099 CET382415740045.156.86.24192.168.2.14
                              Oct 27, 2024 09:16:48.109488010 CET5740038241192.168.2.1445.156.86.24
                              Oct 27, 2024 09:16:48.114959002 CET382415740045.156.86.24192.168.2.14
                              Oct 27, 2024 09:16:49.131326914 CET5740238241192.168.2.1445.156.86.24
                              Oct 27, 2024 09:16:49.136786938 CET382415740245.156.86.24192.168.2.14
                              Oct 27, 2024 09:16:49.136888981 CET5740238241192.168.2.1445.156.86.24
                              Oct 27, 2024 09:16:49.138575077 CET5740238241192.168.2.1445.156.86.24
                              Oct 27, 2024 09:16:49.143914938 CET382415740245.156.86.24192.168.2.14
                              Oct 27, 2024 09:16:49.144057035 CET5740238241192.168.2.1445.156.86.24
                              Oct 27, 2024 09:16:49.149686098 CET382415740245.156.86.24192.168.2.14
                              Oct 27, 2024 09:16:59.962359905 CET382415740245.156.86.24192.168.2.14
                              Oct 27, 2024 09:16:59.962721109 CET5740238241192.168.2.1445.156.86.24
                              Oct 27, 2024 09:16:59.968317032 CET382415740245.156.86.24192.168.2.14
                              Oct 27, 2024 09:17:01.111398935 CET5740438241192.168.2.1445.156.86.24
                              Oct 27, 2024 09:17:01.117598057 CET382415740445.156.86.24192.168.2.14
                              Oct 27, 2024 09:17:01.117978096 CET5740438241192.168.2.1445.156.86.24
                              Oct 27, 2024 09:17:01.119867086 CET5740438241192.168.2.1445.156.86.24
                              Oct 27, 2024 09:17:01.125437021 CET382415740445.156.86.24192.168.2.14
                              Oct 27, 2024 09:17:01.125688076 CET5740438241192.168.2.1445.156.86.24
                              Oct 27, 2024 09:17:01.131369114 CET382415740445.156.86.24192.168.2.14
                              TimestampSource PortDest PortSource IPDest IP
                              Oct 27, 2024 09:15:01.293315887 CET5079753192.168.2.14185.181.61.24
                              Oct 27, 2024 09:15:01.329066038 CET5350797185.181.61.24192.168.2.14
                              Oct 27, 2024 09:15:12.716280937 CET4797853192.168.2.14185.181.61.24
                              Oct 27, 2024 09:15:12.749906063 CET5347978185.181.61.24192.168.2.14
                              Oct 27, 2024 09:15:14.500978947 CET3462353192.168.2.14185.181.61.24
                              Oct 27, 2024 09:15:14.539181948 CET5334623185.181.61.24192.168.2.14
                              Oct 27, 2024 09:15:26.394768953 CET4841753192.168.2.14194.36.144.87
                              Oct 27, 2024 09:15:26.405719995 CET5348417194.36.144.87192.168.2.14
                              Oct 27, 2024 09:15:38.268136024 CET4684953192.168.2.14168.235.111.72
                              Oct 27, 2024 09:15:38.365875959 CET5346849168.235.111.72192.168.2.14
                              Oct 27, 2024 09:15:50.221023083 CET4667953192.168.2.1481.169.136.222
                              Oct 27, 2024 09:15:50.249666929 CET534667981.169.136.222192.168.2.14
                              Oct 27, 2024 09:16:02.081418037 CET5915753192.168.2.14202.61.197.122
                              Oct 27, 2024 09:16:02.093426943 CET5359157202.61.197.122192.168.2.14
                              Oct 27, 2024 09:16:13.944147110 CET4239253192.168.2.14168.235.111.72
                              Oct 27, 2024 09:16:14.032078028 CET5342392168.235.111.72192.168.2.14
                              Oct 27, 2024 09:16:25.408291101 CET3725753192.168.2.14202.61.197.122
                              Oct 27, 2024 09:16:25.419903040 CET5337257202.61.197.122192.168.2.14
                              Oct 27, 2024 09:16:37.259928942 CET4917653192.168.2.14194.36.144.87
                              Oct 27, 2024 09:16:37.270797968 CET5349176194.36.144.87192.168.2.14
                              Oct 27, 2024 09:16:49.114097118 CET5733253192.168.2.1451.158.108.203
                              Oct 27, 2024 09:16:49.130260944 CET535733251.158.108.203192.168.2.14
                              Oct 27, 2024 09:17:00.968492031 CET4078553192.168.2.14194.36.144.87
                              Oct 27, 2024 09:17:01.109072924 CET5340785194.36.144.87192.168.2.14
                              TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                              Oct 27, 2024 09:15:01.293315887 CET192.168.2.14185.181.61.240x25dStandard query (0)netfags.geekA (IP address)IN (0x0001)false
                              Oct 27, 2024 09:15:12.716280937 CET192.168.2.14185.181.61.240x476eStandard query (0)chinklabs.dynA (IP address)IN (0x0001)false
                              Oct 27, 2024 09:15:14.500978947 CET192.168.2.14185.181.61.240x431Standard query (0)burnthe.libreA (IP address)IN (0x0001)false
                              Oct 27, 2024 09:15:26.394768953 CET192.168.2.14194.36.144.870x7756Standard query (0)burnthe.libreA (IP address)IN (0x0001)false
                              Oct 27, 2024 09:15:38.268136024 CET192.168.2.14168.235.111.720x14aaStandard query (0)yellowchink.pirateA (IP address)IN (0x0001)false
                              Oct 27, 2024 09:15:50.221023083 CET192.168.2.1481.169.136.2220x7cf5Standard query (0)yellowchink.pirateA (IP address)IN (0x0001)false
                              Oct 27, 2024 09:16:02.081418037 CET192.168.2.14202.61.197.1220xa2f5Standard query (0)netfags.geek. [malformed]256450false
                              Oct 27, 2024 09:16:13.944147110 CET192.168.2.14168.235.111.720xc6c0Standard query (0)yellowchink.pirateA (IP address)IN (0x0001)false
                              Oct 27, 2024 09:16:25.408291101 CET192.168.2.14202.61.197.1220xb88aStandard query (0)chinklabs.dyn. [malformed]256473false
                              Oct 27, 2024 09:16:37.259928942 CET192.168.2.14194.36.144.870x2c36Standard query (0)yellowchink.pirate. [malformed]256485false
                              Oct 27, 2024 09:16:49.114097118 CET192.168.2.1451.158.108.2030x52ecStandard query (0)chinklabs.dyn. [malformed]256497false
                              Oct 27, 2024 09:17:00.968492031 CET192.168.2.14194.36.144.870x99d6Standard query (0)burnthe.libre. [malformed]256509false
                              TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                              Oct 27, 2024 09:15:01.329066038 CET185.181.61.24192.168.2.140x25dNo error (0)netfags.geek45.156.86.24A (IP address)IN (0x0001)false
                              Oct 27, 2024 09:15:12.749906063 CET185.181.61.24192.168.2.140x476eNo error (0)chinklabs.dyn185.150.24.67A (IP address)IN (0x0001)false
                              Oct 27, 2024 09:15:14.539181948 CET185.181.61.24192.168.2.140x431No error (0)burnthe.libre45.156.86.24A (IP address)IN (0x0001)false
                              Oct 27, 2024 09:15:26.405719995 CET194.36.144.87192.168.2.140x7756No error (0)burnthe.libre45.156.86.24A (IP address)IN (0x0001)false
                              Oct 27, 2024 09:15:38.365875959 CET168.235.111.72192.168.2.140x14aaNo error (0)yellowchink.pirate45.156.86.24A (IP address)IN (0x0001)false
                              Oct 27, 2024 09:15:50.249666929 CET81.169.136.222192.168.2.140x7cf5No error (0)yellowchink.pirate45.156.86.24A (IP address)IN (0x0001)false
                              Oct 27, 2024 09:16:14.032078028 CET168.235.111.72192.168.2.140xc6c0No error (0)yellowchink.pirate45.156.86.24A (IP address)IN (0x0001)false
                              Oct 27, 2024 09:16:37.270797968 CET194.36.144.87192.168.2.140x2c36Format error (1)yellowchink.pirate. [malformed]nonenone256485false
                              Oct 27, 2024 09:16:49.130260944 CET51.158.108.203192.168.2.140x52ecFormat error (1)chinklabs.dyn. [malformed]nonenone256497false
                              Oct 27, 2024 09:17:01.109072924 CET194.36.144.87192.168.2.140x99d6Format error (1)burnthe.libre. [malformed]nonenone256509false

                              System Behavior

                              Start time (UTC):08:15:00
                              Start date (UTC):27/10/2024
                              Path:/tmp/zersh4.elf
                              Arguments:/tmp/zersh4.elf
                              File size:4139976 bytes
                              MD5 hash:8943e5f8f8c280467b4472c15ae93ba9

                              Start time (UTC):08:15:00
                              Start date (UTC):27/10/2024
                              Path:/tmp/zersh4.elf
                              Arguments:-
                              File size:4139976 bytes
                              MD5 hash:8943e5f8f8c280467b4472c15ae93ba9

                              Start time (UTC):08:15:00
                              Start date (UTC):27/10/2024
                              Path:/tmp/zersh4.elf
                              Arguments:-
                              File size:4139976 bytes
                              MD5 hash:8943e5f8f8c280467b4472c15ae93ba9