Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
zerm68k.elf

Overview

General Information

Sample name:zerm68k.elf
Analysis ID:1543158
MD5:1d68b438282771f4a9fd88497e1aa35b
SHA1:58d1cca61d5ef67d4bbc46fdff9d6bd3663e5a75
SHA256:8dbf0e8164c609ed504c645633c26e96e8a8d4a643e0dff42834020a280a3c7a
Tags:elfMiraiuser-abuse_ch
Infos:

Detection

Score:56
Range:0 - 100
Whitelisted:false

Signatures

Multi AV Scanner detection for submitted file
Connects to many ports of the same IP (likely port scanning)
Sends malformed DNS queries
Detected TCP or UDP traffic on non-standard ports
Sample has stripped symbol table
Sample listens on a socket
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1543158
Start date and time:2024-10-27 10:00:46 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 54s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:zerm68k.elf
Detection:MAL
Classification:mal56.troj.linELF@0/0@11/0
  • VT rate limit hit for: zerm68k.elf
Command:/tmp/zerm68k.elf
PID:5652
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
The Peoples Bank of China.
Standard Error:
  • system is lnxubuntu20
  • zerm68k.elf (PID: 5652, Parent: 5578, MD5: cd177594338c77b895ae27c33f8f86cc) Arguments: /tmp/zerm68k.elf
  • cleanup
No yara matches
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: zerm68k.elfReversingLabs: Detection: 47%

Networking

barindex
Source: global trafficTCP traffic: 185.150.24.67 ports 38241,1,2,3,4,8
Source: global trafficTCP traffic: 45.156.86.24 ports 38241,1,2,3,4,8
Source: global trafficDNS traffic detected: malformed DNS query: netfags.geek. [malformed]
Source: global trafficDNS traffic detected: malformed DNS query: burnthe.libre. [malformed]
Source: global trafficDNS traffic detected: malformed DNS query: yellowchink.pirate. [malformed]
Source: global trafficTCP traffic: 192.168.2.15:55542 -> 45.156.86.24:38241
Source: global trafficTCP traffic: 192.168.2.15:35542 -> 185.150.24.67:38241
Source: /tmp/zerm68k.elf (PID: 5652)Socket: 127.0.0.1:39148Jump to behavior
Source: unknownUDP traffic detected without corresponding DNS query: 168.235.111.72
Source: unknownUDP traffic detected without corresponding DNS query: 194.36.144.87
Source: unknownUDP traffic detected without corresponding DNS query: 194.36.144.87
Source: unknownUDP traffic detected without corresponding DNS query: 194.36.144.87
Source: unknownUDP traffic detected without corresponding DNS query: 194.36.144.87
Source: unknownUDP traffic detected without corresponding DNS query: 51.158.108.203
Source: unknownUDP traffic detected without corresponding DNS query: 194.36.144.87
Source: unknownUDP traffic detected without corresponding DNS query: 194.36.144.87
Source: unknownUDP traffic detected without corresponding DNS query: 81.169.136.222
Source: unknownUDP traffic detected without corresponding DNS query: 168.235.111.72
Source: unknownUDP traffic detected without corresponding DNS query: 185.181.61.24
Source: global trafficDNS traffic detected: DNS query: netfags.geek
Source: global trafficDNS traffic detected: DNS query: burnthe.libre
Source: global trafficDNS traffic detected: DNS query: netfags.geek. [malformed]
Source: global trafficDNS traffic detected: DNS query: chinklabs.dyn
Source: global trafficDNS traffic detected: DNS query: yellowchink.pirate
Source: global trafficDNS traffic detected: DNS query: burnthe.libre. [malformed]
Source: global trafficDNS traffic detected: DNS query: yellowchink.pirate. [malformed]
Source: ELF static info symbol of initial sample.symtab present: no
Source: classification engineClassification label: mal56.troj.linELF@0/0@11/0
Source: /tmp/zerm68k.elf (PID: 5652)Queries kernel information via 'uname': Jump to behavior
Source: zerm68k.elf, 5652.1.000055d11cff8000.000055d11d07c000.rw-.sdmpBinary or memory string: U!/etc/qemu-binfmt/m68k
Source: zerm68k.elf, 5652.1.00007ffd1521f000.00007ffd15240000.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-m68k/tmp/zerm68k.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/zerm68k.elf
Source: zerm68k.elf, 5652.1.00007ffd1521f000.00007ffd15240000.rw-.sdmpBinary or memory string: /usr/bin/qemu-m68k
Source: zerm68k.elf, 5652.1.000055d11cff8000.000055d11d07c000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/m68k
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath InterceptionDirect Volume AccessOS Credential Dumping11
Security Software Discovery
Remote ServicesData from Local System1
Non-Standard Port
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1543158 Sample: zerm68k.elf Startdate: 27/10/2024 Architecture: LINUX Score: 56 14 yellowchink.pirate. [malformed] 2->14 16 netfags.geek. [malformed] 2->16 18 5 other IPs or domains 2->18 20 Multi AV Scanner detection for submitted file 2->20 22 Connects to many ports of the same IP (likely port scanning) 2->22 8 zerm68k.elf 2->8         started        signatures3 24 Sends malformed DNS queries 16->24 process4 process5 10 zerm68k.elf 8->10         started        process6 12 zerm68k.elf 10->12         started       
SourceDetectionScannerLabelLink
zerm68k.elf47%ReversingLabsLinux.Backdoor.Mirai
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
netfags.geek
45.156.86.24
truetrue
    unknown
    yellowchink.pirate
    45.156.86.24
    truetrue
      unknown
      chinklabs.dyn
      185.150.24.67
      truetrue
        unknown
        burnthe.libre
        45.156.86.24
        truetrue
          unknown
          netfags.geek. [malformed]
          unknown
          unknowntrue
            unknown
            burnthe.libre. [malformed]
            unknown
            unknowntrue
              unknown
              yellowchink.pirate. [malformed]
              unknown
              unknowntrue
                unknown
                • No. of IPs < 25%
                • 25% < No. of IPs < 50%
                • 50% < No. of IPs < 75%
                • 75% < No. of IPs
                IPDomainCountryFlagASNASN NameMalicious
                185.150.24.67
                chinklabs.dynNetherlands
                44592SKYLINKNLtrue
                45.156.86.24
                netfags.geekGermany
                44592SKYLINKNLtrue
                MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                185.150.24.67zerspc.elfGet hashmaliciousUnknownBrowse
                  zerarm5.elfGet hashmaliciousUnknownBrowse
                    zermips.elfGet hashmaliciousUnknownBrowse
                      zersh4.elfGet hashmaliciousUnknownBrowse
                        zerppc.elfGet hashmaliciousUnknownBrowse
                          file.exeGet hashmaliciousUnknownBrowse
                            https://search-dl3.com/staticpr/12.zipGet hashmaliciousUnknownBrowse
                              45.156.86.24zerspc.elfGet hashmaliciousUnknownBrowse
                                nabm68k.elfGet hashmaliciousUnknownBrowse
                                  zerarm.elfGet hashmaliciousUnknownBrowse
                                    zerarm5.elfGet hashmaliciousUnknownBrowse
                                      nabspc.elfGet hashmaliciousUnknownBrowse
                                        zerx86.elfGet hashmaliciousUnknownBrowse
                                          nabppc.elfGet hashmaliciousUnknownBrowse
                                            nabmips.elfGet hashmaliciousUnknownBrowse
                                              zermips.elfGet hashmaliciousUnknownBrowse
                                                nabarm.elfGet hashmaliciousUnknownBrowse
                                                  MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                  yellowchink.piratenabm68k.elfGet hashmaliciousUnknownBrowse
                                                  • 45.156.86.24
                                                  nklx86.elfGet hashmaliciousUnknownBrowse
                                                  • 45.156.86.24
                                                  zerarm5.elfGet hashmaliciousUnknownBrowse
                                                  • 45.156.86.24
                                                  nabspc.elfGet hashmaliciousUnknownBrowse
                                                  • 45.156.86.24
                                                  zerx86.elfGet hashmaliciousUnknownBrowse
                                                  • 45.156.86.24
                                                  chinklabs.dynnklx86.elfGet hashmaliciousUnknownBrowse
                                                  • 185.150.24.67
                                                  zerarm5.elfGet hashmaliciousUnknownBrowse
                                                  • 185.150.24.67
                                                  MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                  SKYLINKNLzerspc.elfGet hashmaliciousUnknownBrowse
                                                  • 45.156.86.24
                                                  nabm68k.elfGet hashmaliciousUnknownBrowse
                                                  • 45.156.86.24
                                                  zerarm.elfGet hashmaliciousUnknownBrowse
                                                  • 45.156.86.24
                                                  zerarm5.elfGet hashmaliciousUnknownBrowse
                                                  • 45.156.86.24
                                                  nabspc.elfGet hashmaliciousUnknownBrowse
                                                  • 45.156.86.24
                                                  zerx86.elfGet hashmaliciousUnknownBrowse
                                                  • 45.156.86.24
                                                  nabppc.elfGet hashmaliciousUnknownBrowse
                                                  • 45.156.86.24
                                                  nabmips.elfGet hashmaliciousUnknownBrowse
                                                  • 45.156.86.24
                                                  zermips.elfGet hashmaliciousUnknownBrowse
                                                  • 45.156.86.24
                                                  nabarm.elfGet hashmaliciousUnknownBrowse
                                                  • 45.156.86.24
                                                  SKYLINKNLzerspc.elfGet hashmaliciousUnknownBrowse
                                                  • 45.156.86.24
                                                  nabm68k.elfGet hashmaliciousUnknownBrowse
                                                  • 45.156.86.24
                                                  zerarm.elfGet hashmaliciousUnknownBrowse
                                                  • 45.156.86.24
                                                  zerarm5.elfGet hashmaliciousUnknownBrowse
                                                  • 45.156.86.24
                                                  nabspc.elfGet hashmaliciousUnknownBrowse
                                                  • 45.156.86.24
                                                  zerx86.elfGet hashmaliciousUnknownBrowse
                                                  • 45.156.86.24
                                                  nabppc.elfGet hashmaliciousUnknownBrowse
                                                  • 45.156.86.24
                                                  nabmips.elfGet hashmaliciousUnknownBrowse
                                                  • 45.156.86.24
                                                  zermips.elfGet hashmaliciousUnknownBrowse
                                                  • 45.156.86.24
                                                  nabarm.elfGet hashmaliciousUnknownBrowse
                                                  • 45.156.86.24
                                                  No context
                                                  No context
                                                  No created / dropped files found
                                                  File type:ELF 32-bit MSB executable, Motorola m68k, 68020, version 1 (SYSV), statically linked, stripped
                                                  Entropy (8bit):6.209448832967863
                                                  TrID:
                                                  • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                                                  File name:zerm68k.elf
                                                  File size:48'628 bytes
                                                  MD5:1d68b438282771f4a9fd88497e1aa35b
                                                  SHA1:58d1cca61d5ef67d4bbc46fdff9d6bd3663e5a75
                                                  SHA256:8dbf0e8164c609ed504c645633c26e96e8a8d4a643e0dff42834020a280a3c7a
                                                  SHA512:54a45cd236224dd1eca50a41f0566389e94c8cac75eaa0f3925007cb9acacdad1419ea8b531c4d71114f32025c3ad2f2f9cd7601917ecf8ac53c10d6bd8b5e42
                                                  SSDEEP:768:fPegq++79Zv4DyKHs//NLaO7oA20/QuSbFbRDlF8nANzq:HNq7nv4DyOs3NLj7o8/Qu2bRDP8nkq
                                                  TLSH:17233C99B801AD3CFD4BF7BE84130A0CF560375951A20B2B67ABFE936C726944D16D83
                                                  File Content Preview:.ELF.......................D...4...<.....4. ...(.......................v...v...... ........|...|...|...|.......... .dt.Q............................NV..a....da.....N^NuNV..J9....f>"y.... QJ.g.X.#.....N."y.... QJ.f.A.....J.g.Hy...xN.X.........N^NuNV..N^NuN

                                                  ELF header

                                                  Class:ELF32
                                                  Data:2's complement, big endian
                                                  Version:1 (current)
                                                  Machine:MC68000
                                                  Version Number:0x1
                                                  Type:EXEC (Executable file)
                                                  OS/ABI:UNIX - System V
                                                  ABI Version:0
                                                  Entry Point Address:0x80000144
                                                  Flags:0x0
                                                  ELF Header Size:52
                                                  Program Header Offset:52
                                                  Program Header Size:32
                                                  Number of Program Headers:3
                                                  Section Header Offset:48188
                                                  Section Header Size:40
                                                  Number of Section Headers:11
                                                  Header String Table Index:10
                                                  NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                                  NULL0x00x00x00x00x0000
                                                  .initPROGBITS0x800000940x940x140x00x6AX002
                                                  .textPROGBITS0x800000a80xa80xb1c20x00x6AX004
                                                  .finiPROGBITS0x8000b26a0xb26a0xe0x00x6AX002
                                                  .rodataPROGBITS0x8000b2780xb2780x7fe0x00x2A002
                                                  .ctorsPROGBITS0x8000da7c0xba7c0x80x00x3WA004
                                                  .dtorsPROGBITS0x8000da840xba840x80x00x3WA004
                                                  .jcrPROGBITS0x8000da8c0xba8c0x40x00x3WA004
                                                  .dataPROGBITS0x8000da900xba900x1680x00x3WA004
                                                  .bssNOBITS0x8000dbf80xbbf80x1740x00x3WA004
                                                  .shstrtabSTRTAB0x00xbbf80x430x00x0001
                                                  TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                  LOAD0x00x800000000x800000000xba760xba766.25810x5R E0x2000.init .text .fini .rodata
                                                  LOAD0xba7c0x8000da7c0x8000da7c0x17c0x2f00.88330x6RW 0x2000.ctors .dtors .jcr .data .bss
                                                  GNU_STACK0x00x00x00x00x00.00000x6RW 0x4
                                                  TimestampSource PortDest PortSource IPDest IP
                                                  Oct 27, 2024 10:01:50.430027962 CET5554238241192.168.2.1545.156.86.24
                                                  Oct 27, 2024 10:01:50.435419083 CET382415554245.156.86.24192.168.2.15
                                                  Oct 27, 2024 10:01:50.435501099 CET5554238241192.168.2.1545.156.86.24
                                                  Oct 27, 2024 10:01:50.436463118 CET5554238241192.168.2.1545.156.86.24
                                                  Oct 27, 2024 10:01:50.441968918 CET382415554245.156.86.24192.168.2.15
                                                  Oct 27, 2024 10:01:50.442037106 CET5554238241192.168.2.1545.156.86.24
                                                  Oct 27, 2024 10:01:50.447423935 CET382415554245.156.86.24192.168.2.15
                                                  Oct 27, 2024 10:02:00.446639061 CET5554238241192.168.2.1545.156.86.24
                                                  Oct 27, 2024 10:02:00.452399969 CET382415554245.156.86.24192.168.2.15
                                                  Oct 27, 2024 10:02:00.804382086 CET382415554245.156.86.24192.168.2.15
                                                  Oct 27, 2024 10:02:00.805039883 CET5554238241192.168.2.1545.156.86.24
                                                  Oct 27, 2024 10:02:00.810653925 CET382415554245.156.86.24192.168.2.15
                                                  Oct 27, 2024 10:02:01.820624113 CET5554438241192.168.2.1545.156.86.24
                                                  Oct 27, 2024 10:02:01.826018095 CET382415554445.156.86.24192.168.2.15
                                                  Oct 27, 2024 10:02:01.826082945 CET5554438241192.168.2.1545.156.86.24
                                                  Oct 27, 2024 10:02:01.826989889 CET5554438241192.168.2.1545.156.86.24
                                                  Oct 27, 2024 10:02:01.832509995 CET382415554445.156.86.24192.168.2.15
                                                  Oct 27, 2024 10:02:01.832571030 CET5554438241192.168.2.1545.156.86.24
                                                  Oct 27, 2024 10:02:01.838109016 CET382415554445.156.86.24192.168.2.15
                                                  Oct 27, 2024 10:02:12.666147947 CET382415554445.156.86.24192.168.2.15
                                                  Oct 27, 2024 10:02:12.666747093 CET5554438241192.168.2.1545.156.86.24
                                                  Oct 27, 2024 10:02:12.672476053 CET382415554445.156.86.24192.168.2.15
                                                  Oct 27, 2024 10:02:13.682650089 CET5554638241192.168.2.1545.156.86.24
                                                  Oct 27, 2024 10:02:13.688425064 CET382415554645.156.86.24192.168.2.15
                                                  Oct 27, 2024 10:02:13.688652039 CET5554638241192.168.2.1545.156.86.24
                                                  Oct 27, 2024 10:02:13.690320969 CET5554638241192.168.2.1545.156.86.24
                                                  Oct 27, 2024 10:02:13.695822001 CET382415554645.156.86.24192.168.2.15
                                                  Oct 27, 2024 10:02:13.695920944 CET5554638241192.168.2.1545.156.86.24
                                                  Oct 27, 2024 10:02:13.701383114 CET382415554645.156.86.24192.168.2.15
                                                  Oct 27, 2024 10:02:24.696712017 CET382415554645.156.86.24192.168.2.15
                                                  Oct 27, 2024 10:02:24.697010040 CET5554638241192.168.2.1545.156.86.24
                                                  Oct 27, 2024 10:02:24.703288078 CET382415554645.156.86.24192.168.2.15
                                                  Oct 27, 2024 10:02:25.710952997 CET5554838241192.168.2.1545.156.86.24
                                                  Oct 27, 2024 10:02:25.716689110 CET382415554845.156.86.24192.168.2.15
                                                  Oct 27, 2024 10:02:25.716749907 CET5554838241192.168.2.1545.156.86.24
                                                  Oct 27, 2024 10:02:25.717529058 CET5554838241192.168.2.1545.156.86.24
                                                  Oct 27, 2024 10:02:25.723298073 CET382415554845.156.86.24192.168.2.15
                                                  Oct 27, 2024 10:02:25.723402023 CET5554838241192.168.2.1545.156.86.24
                                                  Oct 27, 2024 10:02:25.729010105 CET382415554845.156.86.24192.168.2.15
                                                  Oct 27, 2024 10:02:36.541434050 CET382415554845.156.86.24192.168.2.15
                                                  Oct 27, 2024 10:02:36.541600943 CET5554838241192.168.2.1545.156.86.24
                                                  Oct 27, 2024 10:02:36.547050953 CET382415554845.156.86.24192.168.2.15
                                                  Oct 27, 2024 10:02:37.559803009 CET3554238241192.168.2.15185.150.24.67
                                                  Oct 27, 2024 10:02:37.565248013 CET3824135542185.150.24.67192.168.2.15
                                                  Oct 27, 2024 10:02:37.565327883 CET3554238241192.168.2.15185.150.24.67
                                                  Oct 27, 2024 10:02:37.566802025 CET3554238241192.168.2.15185.150.24.67
                                                  Oct 27, 2024 10:02:37.572309971 CET3824135542185.150.24.67192.168.2.15
                                                  Oct 27, 2024 10:02:37.572400093 CET3554238241192.168.2.15185.150.24.67
                                                  Oct 27, 2024 10:02:37.577867031 CET3824135542185.150.24.67192.168.2.15
                                                  Oct 27, 2024 10:02:39.188162088 CET3824135542185.150.24.67192.168.2.15
                                                  Oct 27, 2024 10:02:39.188460112 CET3554238241192.168.2.15185.150.24.67
                                                  Oct 27, 2024 10:02:39.193993092 CET3824135542185.150.24.67192.168.2.15
                                                  Oct 27, 2024 10:02:40.211536884 CET5555238241192.168.2.1545.156.86.24
                                                  Oct 27, 2024 10:02:40.217070103 CET382415555245.156.86.24192.168.2.15
                                                  Oct 27, 2024 10:02:40.217312098 CET5555238241192.168.2.1545.156.86.24
                                                  Oct 27, 2024 10:02:40.219254971 CET5555238241192.168.2.1545.156.86.24
                                                  Oct 27, 2024 10:02:40.224864960 CET382415555245.156.86.24192.168.2.15
                                                  Oct 27, 2024 10:02:40.224946022 CET5555238241192.168.2.1545.156.86.24
                                                  Oct 27, 2024 10:02:40.230417013 CET382415555245.156.86.24192.168.2.15
                                                  Oct 27, 2024 10:02:51.054430008 CET382415555245.156.86.24192.168.2.15
                                                  Oct 27, 2024 10:02:51.054933071 CET5555238241192.168.2.1545.156.86.24
                                                  Oct 27, 2024 10:02:51.060731888 CET382415555245.156.86.24192.168.2.15
                                                  Oct 27, 2024 10:02:52.353832006 CET5555438241192.168.2.1545.156.86.24
                                                  Oct 27, 2024 10:02:52.359532118 CET382415555445.156.86.24192.168.2.15
                                                  Oct 27, 2024 10:02:52.359817982 CET5555438241192.168.2.1545.156.86.24
                                                  Oct 27, 2024 10:02:52.361481905 CET5555438241192.168.2.1545.156.86.24
                                                  Oct 27, 2024 10:02:52.367000103 CET382415555445.156.86.24192.168.2.15
                                                  Oct 27, 2024 10:02:52.367073059 CET5555438241192.168.2.1545.156.86.24
                                                  Oct 27, 2024 10:02:52.372484922 CET382415555445.156.86.24192.168.2.15
                                                  Oct 27, 2024 10:03:03.202358961 CET382415555445.156.86.24192.168.2.15
                                                  Oct 27, 2024 10:03:03.202940941 CET5555438241192.168.2.1545.156.86.24
                                                  Oct 27, 2024 10:03:03.208420992 CET382415555445.156.86.24192.168.2.15
                                                  Oct 27, 2024 10:03:04.341274023 CET5555638241192.168.2.1545.156.86.24
                                                  Oct 27, 2024 10:03:04.346713066 CET382415555645.156.86.24192.168.2.15
                                                  Oct 27, 2024 10:03:04.347070932 CET5555638241192.168.2.1545.156.86.24
                                                  Oct 27, 2024 10:03:04.348742008 CET5555638241192.168.2.1545.156.86.24
                                                  Oct 27, 2024 10:03:04.354083061 CET382415555645.156.86.24192.168.2.15
                                                  Oct 27, 2024 10:03:04.354316950 CET5555638241192.168.2.1545.156.86.24
                                                  Oct 27, 2024 10:03:04.359772921 CET382415555645.156.86.24192.168.2.15
                                                  Oct 27, 2024 10:03:14.358592033 CET5555638241192.168.2.1545.156.86.24
                                                  Oct 27, 2024 10:03:14.364101887 CET382415555645.156.86.24192.168.2.15
                                                  Oct 27, 2024 10:03:14.719866991 CET382415555645.156.86.24192.168.2.15
                                                  Oct 27, 2024 10:03:14.720160007 CET5555638241192.168.2.1545.156.86.24
                                                  Oct 27, 2024 10:03:14.725665092 CET382415555645.156.86.24192.168.2.15
                                                  Oct 27, 2024 10:03:15.754432917 CET5555838241192.168.2.1545.156.86.24
                                                  Oct 27, 2024 10:03:15.760741949 CET382415555845.156.86.24192.168.2.15
                                                  Oct 27, 2024 10:03:15.761080980 CET5555838241192.168.2.1545.156.86.24
                                                  Oct 27, 2024 10:03:15.762645006 CET5555838241192.168.2.1545.156.86.24
                                                  Oct 27, 2024 10:03:15.768539906 CET382415555845.156.86.24192.168.2.15
                                                  Oct 27, 2024 10:03:15.768733978 CET5555838241192.168.2.1545.156.86.24
                                                  Oct 27, 2024 10:03:15.774143934 CET382415555845.156.86.24192.168.2.15
                                                  Oct 27, 2024 10:03:26.603466034 CET382415555845.156.86.24192.168.2.15
                                                  Oct 27, 2024 10:03:26.604065895 CET5555838241192.168.2.1545.156.86.24
                                                  Oct 27, 2024 10:03:26.609558105 CET382415555845.156.86.24192.168.2.15
                                                  Oct 27, 2024 10:03:27.705235958 CET5556038241192.168.2.1545.156.86.24
                                                  Oct 27, 2024 10:03:27.710787058 CET382415556045.156.86.24192.168.2.15
                                                  Oct 27, 2024 10:03:27.711205959 CET5556038241192.168.2.1545.156.86.24
                                                  Oct 27, 2024 10:03:27.713009119 CET5556038241192.168.2.1545.156.86.24
                                                  Oct 27, 2024 10:03:27.718513966 CET382415556045.156.86.24192.168.2.15
                                                  Oct 27, 2024 10:03:27.718832016 CET5556038241192.168.2.1545.156.86.24
                                                  Oct 27, 2024 10:03:27.724155903 CET382415556045.156.86.24192.168.2.15
                                                  Oct 27, 2024 10:03:38.843534946 CET382415556045.156.86.24192.168.2.15
                                                  Oct 27, 2024 10:03:38.843805075 CET5556038241192.168.2.1545.156.86.24
                                                  Oct 27, 2024 10:03:38.843812943 CET382415556045.156.86.24192.168.2.15
                                                  Oct 27, 2024 10:03:38.843868971 CET5556038241192.168.2.1545.156.86.24
                                                  Oct 27, 2024 10:03:38.859962940 CET382415556045.156.86.24192.168.2.15
                                                  Oct 27, 2024 10:03:39.884008884 CET5556238241192.168.2.1545.156.86.24
                                                  Oct 27, 2024 10:03:39.889687061 CET382415556245.156.86.24192.168.2.15
                                                  Oct 27, 2024 10:03:39.889955044 CET5556238241192.168.2.1545.156.86.24
                                                  Oct 27, 2024 10:03:39.891926050 CET5556238241192.168.2.1545.156.86.24
                                                  Oct 27, 2024 10:03:39.897865057 CET382415556245.156.86.24192.168.2.15
                                                  Oct 27, 2024 10:03:39.898189068 CET5556238241192.168.2.1545.156.86.24
                                                  Oct 27, 2024 10:03:39.904277086 CET382415556245.156.86.24192.168.2.15
                                                  TimestampSource PortDest PortSource IPDest IP
                                                  Oct 27, 2024 10:01:50.335982084 CET3685453192.168.2.15168.235.111.72
                                                  Oct 27, 2024 10:01:50.428841114 CET5336854168.235.111.72192.168.2.15
                                                  Oct 27, 2024 10:02:01.807929039 CET3948453192.168.2.15194.36.144.87
                                                  Oct 27, 2024 10:02:01.819906950 CET5339484194.36.144.87192.168.2.15
                                                  Oct 27, 2024 10:02:13.670342922 CET5666353192.168.2.15194.36.144.87
                                                  Oct 27, 2024 10:02:13.681118011 CET5356663194.36.144.87192.168.2.15
                                                  Oct 27, 2024 10:02:25.699623108 CET4744253192.168.2.15194.36.144.87
                                                  Oct 27, 2024 10:02:25.710355997 CET5347442194.36.144.87192.168.2.15
                                                  Oct 27, 2024 10:02:37.547168970 CET5724153192.168.2.15194.36.144.87
                                                  Oct 27, 2024 10:02:37.558649063 CET5357241194.36.144.87192.168.2.15
                                                  Oct 27, 2024 10:02:40.193806887 CET5848153192.168.2.1551.158.108.203
                                                  Oct 27, 2024 10:02:40.209717035 CET535848151.158.108.203192.168.2.15
                                                  Oct 27, 2024 10:02:52.059477091 CET3933553192.168.2.15194.36.144.87
                                                  Oct 27, 2024 10:02:52.352718115 CET5339335194.36.144.87192.168.2.15
                                                  Oct 27, 2024 10:03:04.208713055 CET3385953192.168.2.15194.36.144.87
                                                  Oct 27, 2024 10:03:04.339762926 CET5333859194.36.144.87192.168.2.15
                                                  Oct 27, 2024 10:03:15.725230932 CET6029653192.168.2.1581.169.136.222
                                                  Oct 27, 2024 10:03:15.753168106 CET536029681.169.136.222192.168.2.15
                                                  Oct 27, 2024 10:03:27.609436989 CET5771653192.168.2.15168.235.111.72
                                                  Oct 27, 2024 10:03:27.702718973 CET5357716168.235.111.72192.168.2.15
                                                  Oct 27, 2024 10:03:39.848315954 CET4199453192.168.2.15185.181.61.24
                                                  Oct 27, 2024 10:03:39.882134914 CET5341994185.181.61.24192.168.2.15
                                                  TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                                  Oct 27, 2024 10:01:50.335982084 CET192.168.2.15168.235.111.720xd44Standard query (0)netfags.geekA (IP address)IN (0x0001)false
                                                  Oct 27, 2024 10:02:01.807929039 CET192.168.2.15194.36.144.870xdff4Standard query (0)burnthe.libreA (IP address)IN (0x0001)false
                                                  Oct 27, 2024 10:02:13.670342922 CET192.168.2.15194.36.144.870xf6d1Standard query (0)netfags.geek. [malformed]256405false
                                                  Oct 27, 2024 10:02:25.699623108 CET192.168.2.15194.36.144.870xfd22Standard query (0)netfags.geek. [malformed]256417false
                                                  Oct 27, 2024 10:02:37.547168970 CET192.168.2.15194.36.144.870xaf21Standard query (0)chinklabs.dynA (IP address)IN (0x0001)false
                                                  Oct 27, 2024 10:02:40.193806887 CET192.168.2.1551.158.108.2030x1f0eStandard query (0)yellowchink.pirateA (IP address)IN (0x0001)false
                                                  Oct 27, 2024 10:02:52.059477091 CET192.168.2.15194.36.144.870xbbe7Standard query (0)yellowchink.pirateA (IP address)IN (0x0001)false
                                                  Oct 27, 2024 10:03:04.208713055 CET192.168.2.15194.36.144.870xc18dStandard query (0)burnthe.libre. [malformed]256456false
                                                  Oct 27, 2024 10:03:15.725230932 CET192.168.2.1581.169.136.2220x7f0dStandard query (0)netfags.geek. [malformed]256467false
                                                  Oct 27, 2024 10:03:27.609436989 CET192.168.2.15168.235.111.720x82cStandard query (0)yellowchink.pirate. [malformed]256479false
                                                  Oct 27, 2024 10:03:39.848315954 CET192.168.2.15185.181.61.240xcb9cStandard query (0)yellowchink.pirate. [malformed]256491false
                                                  TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                                  Oct 27, 2024 10:01:50.428841114 CET168.235.111.72192.168.2.150xd44No error (0)netfags.geek45.156.86.24A (IP address)IN (0x0001)false
                                                  Oct 27, 2024 10:02:01.819906950 CET194.36.144.87192.168.2.150xdff4No error (0)burnthe.libre45.156.86.24A (IP address)IN (0x0001)false
                                                  Oct 27, 2024 10:02:13.681118011 CET194.36.144.87192.168.2.150xf6d1Format error (1)netfags.geek. [malformed]nonenone256405false
                                                  Oct 27, 2024 10:02:25.710355997 CET194.36.144.87192.168.2.150xfd22Format error (1)netfags.geek. [malformed]nonenone256417false
                                                  Oct 27, 2024 10:02:37.558649063 CET194.36.144.87192.168.2.150xaf21No error (0)chinklabs.dyn185.150.24.67A (IP address)IN (0x0001)false
                                                  Oct 27, 2024 10:02:40.209717035 CET51.158.108.203192.168.2.150x1f0eNo error (0)yellowchink.pirate45.156.86.24A (IP address)IN (0x0001)false
                                                  Oct 27, 2024 10:02:52.352718115 CET194.36.144.87192.168.2.150xbbe7No error (0)yellowchink.pirate45.156.86.24A (IP address)IN (0x0001)false
                                                  Oct 27, 2024 10:03:04.339762926 CET194.36.144.87192.168.2.150xc18dFormat error (1)burnthe.libre. [malformed]nonenone256456false

                                                  System Behavior

                                                  Start time (UTC):09:01:49
                                                  Start date (UTC):27/10/2024
                                                  Path:/tmp/zerm68k.elf
                                                  Arguments:/tmp/zerm68k.elf
                                                  File size:4463432 bytes
                                                  MD5 hash:cd177594338c77b895ae27c33f8f86cc

                                                  Start time (UTC):09:01:49
                                                  Start date (UTC):27/10/2024
                                                  Path:/tmp/zerm68k.elf
                                                  Arguments:-
                                                  File size:4463432 bytes
                                                  MD5 hash:cd177594338c77b895ae27c33f8f86cc

                                                  Start time (UTC):09:01:49
                                                  Start date (UTC):27/10/2024
                                                  Path:/tmp/zerm68k.elf
                                                  Arguments:-
                                                  File size:4463432 bytes
                                                  MD5 hash:cd177594338c77b895ae27c33f8f86cc