Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
zmap.arm.elf

Overview

General Information

Sample name:zmap.arm.elf
Analysis ID:1544691
MD5:823958d1dbb59368ec9cb465345ede82
SHA1:4246851d3b9f1b59c45e2069fc1e204fa2937fc6
SHA256:ce3fcb923990e59f2bcee0f811a868fa7a0abf2a461b54974977d1db6e940aee
Tags:elfMiraiuser-abuse_ch
Infos:

Detection

Mirai, Okiru
Score:84
Range:0 - 100
Whitelisted:false

Signatures

Antivirus / Scanner detection for submitted sample
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Yara detected Mirai
Yara detected Okiru
Sample deletes itself
Detected TCP or UDP traffic on non-standard ports
Sample has stripped symbol table
Sample listens on a socket
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Uses the "uname" system call to query kernel version information (possible evasion)
Yara signature match

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1544691
Start date and time:2024-10-29 17:27:25 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 38s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:zmap.arm.elf
Detection:MAL
Classification:mal84.troj.evad.linELF@0/0@23/0
  • VT rate limit hit for: zmap.arm.elf
Command:/tmp/zmap.arm.elf
PID:5513
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
VagneRHere
Standard Error:
  • system is lnxubuntu20
  • zmap.arm.elf (PID: 5513, Parent: 5429, MD5: 5ebfcae4fe2471fcc5695c2394773ff1) Arguments: /tmp/zmap.arm.elf
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
MiraiMirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese. Nowadays it targets a wide range of networked embedded devices such as IP cameras, home routers (many vendors involved), and other IoT devices. Since the source code was published on "Hack Forums" many variants of the Mirai family appeared, infecting mostly home networks all around the world.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/elf.mirai
SourceRuleDescriptionAuthorStrings
zmap.arm.elfJoeSecurity_OkiruYara detected OkiruJoe Security
    zmap.arm.elfJoeSecurity_Mirai_8Yara detected MiraiJoe Security
      zmap.arm.elfLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
      • 0x10248:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x1025c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x10270:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x10284:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x10298:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x102ac:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x102c0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x102d4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x102e8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x102fc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x10310:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x10324:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x10338:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x1034c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x10360:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x10374:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x10388:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x1039c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x103b0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x103c4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x103d8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      SourceRuleDescriptionAuthorStrings
      5517.1.00007ffa80017000.00007ffa8002a000.r-x.sdmpJoeSecurity_OkiruYara detected OkiruJoe Security
        5517.1.00007ffa80017000.00007ffa8002a000.r-x.sdmpJoeSecurity_Mirai_8Yara detected MiraiJoe Security
          5517.1.00007ffa80017000.00007ffa8002a000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
          • 0x10248:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x1025c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x10270:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x10284:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x10298:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x102ac:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x102c0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x102d4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x102e8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x102fc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x10310:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x10324:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x10338:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x1034c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x10360:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x10374:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x10388:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x1039c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x103b0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x103c4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x103d8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          5513.1.00007ffa80017000.00007ffa8002a000.r-x.sdmpJoeSecurity_OkiruYara detected OkiruJoe Security
            5513.1.00007ffa80017000.00007ffa8002a000.r-x.sdmpJoeSecurity_Mirai_8Yara detected MiraiJoe Security
              Click to see the 7 entries
              No Suricata rule has matched

              Click to jump to signature section

              Show All Signature Results

              AV Detection

              barindex
              Source: zmap.arm.elfAvira: detected
              Source: zmap.arm.elfReversingLabs: Detection: 63%
              Source: global trafficTCP traffic: 192.168.2.14:54784 -> 154.216.20.164:59962
              Source: /tmp/zmap.arm.elf (PID: 5513)Socket: 127.0.0.1:39148Jump to behavior
              Source: global trafficTCP traffic: 192.168.2.14:46540 -> 185.125.190.26:443
              Source: unknownTCP traffic detected without corresponding DNS query: 185.125.190.26
              Source: unknownTCP traffic detected without corresponding DNS query: 185.125.190.26
              Source: global trafficDNS traffic detected: DNS query: cnc.dico-inside.com
              Source: unknownNetwork traffic detected: HTTP traffic on port 46540 -> 443

              System Summary

              barindex
              Source: zmap.arm.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
              Source: 5517.1.00007ffa80017000.00007ffa8002a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
              Source: 5513.1.00007ffa80017000.00007ffa8002a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
              Source: Process Memory Space: zmap.arm.elf PID: 5513, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
              Source: Process Memory Space: zmap.arm.elf PID: 5517, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
              Source: ELF static info symbol of initial sample.symtab present: no
              Source: zmap.arm.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
              Source: 5517.1.00007ffa80017000.00007ffa8002a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
              Source: 5513.1.00007ffa80017000.00007ffa8002a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
              Source: Process Memory Space: zmap.arm.elf PID: 5513, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
              Source: Process Memory Space: zmap.arm.elf PID: 5517, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
              Source: classification engineClassification label: mal84.troj.evad.linELF@0/0@23/0

              Hooking and other Techniques for Hiding and Protection

              barindex
              Source: /tmp/zmap.arm.elf (PID: 5513)File: /tmp/zmap.arm.elfJump to behavior
              Source: /tmp/zmap.arm.elf (PID: 5513)Queries kernel information via 'uname': Jump to behavior
              Source: zmap.arm.elf, 5513.1.00007ffdb7d57000.00007ffdb7d78000.rw-.sdmp, zmap.arm.elf, 5517.1.00007ffdb7d57000.00007ffdb7d78000.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-arm/tmp/zmap.arm.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/zmap.arm.elf
              Source: zmap.arm.elf, 5513.1.0000558bd0919000.0000558bd0a47000.rw-.sdmp, zmap.arm.elf, 5517.1.0000558bd0919000.0000558bd0a47000.rw-.sdmpBinary or memory string: U!/etc/qemu-binfmt/arm
              Source: zmap.arm.elf, 5513.1.0000558bd0919000.0000558bd0a47000.rw-.sdmp, zmap.arm.elf, 5517.1.0000558bd0919000.0000558bd0a47000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/arm
              Source: zmap.arm.elf, 5513.1.00007ffdb7d57000.00007ffdb7d78000.rw-.sdmp, zmap.arm.elf, 5517.1.00007ffdb7d57000.00007ffdb7d78000.rw-.sdmpBinary or memory string: /usr/bin/qemu-arm

              Stealing of Sensitive Information

              barindex
              Source: Yara matchFile source: zmap.arm.elf, type: SAMPLE
              Source: Yara matchFile source: 5517.1.00007ffa80017000.00007ffa8002a000.r-x.sdmp, type: MEMORY
              Source: Yara matchFile source: 5513.1.00007ffa80017000.00007ffa8002a000.r-x.sdmp, type: MEMORY
              Source: Yara matchFile source: Process Memory Space: zmap.arm.elf PID: 5513, type: MEMORYSTR
              Source: Yara matchFile source: Process Memory Space: zmap.arm.elf PID: 5517, type: MEMORYSTR
              Source: Yara matchFile source: zmap.arm.elf, type: SAMPLE
              Source: Yara matchFile source: 5517.1.00007ffa80017000.00007ffa8002a000.r-x.sdmp, type: MEMORY
              Source: Yara matchFile source: 5513.1.00007ffa80017000.00007ffa8002a000.r-x.sdmp, type: MEMORY
              Source: Yara matchFile source: Process Memory Space: zmap.arm.elf PID: 5513, type: MEMORYSTR
              Source: Yara matchFile source: Process Memory Space: zmap.arm.elf PID: 5517, type: MEMORYSTR

              Remote Access Functionality

              barindex
              Source: Yara matchFile source: zmap.arm.elf, type: SAMPLE
              Source: Yara matchFile source: 5517.1.00007ffa80017000.00007ffa8002a000.r-x.sdmp, type: MEMORY
              Source: Yara matchFile source: 5513.1.00007ffa80017000.00007ffa8002a000.r-x.sdmp, type: MEMORY
              Source: Yara matchFile source: Process Memory Space: zmap.arm.elf PID: 5513, type: MEMORYSTR
              Source: Yara matchFile source: Process Memory Space: zmap.arm.elf PID: 5517, type: MEMORYSTR
              Source: Yara matchFile source: zmap.arm.elf, type: SAMPLE
              Source: Yara matchFile source: 5517.1.00007ffa80017000.00007ffa8002a000.r-x.sdmp, type: MEMORY
              Source: Yara matchFile source: 5513.1.00007ffa80017000.00007ffa8002a000.r-x.sdmp, type: MEMORY
              Source: Yara matchFile source: Process Memory Space: zmap.arm.elf PID: 5513, type: MEMORYSTR
              Source: Yara matchFile source: Process Memory Space: zmap.arm.elf PID: 5517, type: MEMORYSTR
              ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
              Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception1
              File Deletion
              OS Credential Dumping11
              Security Software Discovery
              Remote ServicesData from Local System1
              Encrypted Channel
              Exfiltration Over Other Network MediumAbuse Accessibility Features
              CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
              Non-Standard Port
              Exfiltration Over BluetoothNetwork Denial of Service
              Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
              Non-Application Layer Protocol
              Automated ExfiltrationData Encrypted for Impact
              Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture2
              Application Layer Protocol
              Traffic DuplicationData Destruction
              No configs have been found
              Hide Legend

              Legend:

              • Process
              • Signature
              • Created File
              • DNS/IP Info
              • Is Dropped
              • Number of created Files
              • Is malicious
              • Internet
              SourceDetectionScannerLabelLink
              zmap.arm.elf63%ReversingLabsLinux.Trojan.Mirai
              zmap.arm.elf100%AviraEXP/ELF.Mirai.Z.A
              No Antivirus matches
              No Antivirus matches
              No Antivirus matches
              NameIPActiveMaliciousAntivirus DetectionReputation
              cnc.dico-inside.com
              154.216.20.164
              truefalse
                unknown
                • No. of IPs < 25%
                • 25% < No. of IPs < 50%
                • 50% < No. of IPs < 75%
                • 75% < No. of IPs
                IPDomainCountryFlagASNASN NameMalicious
                185.125.190.26
                unknownUnited Kingdom
                41231CANONICAL-ASGBfalse
                154.216.20.164
                cnc.dico-inside.comSeychelles
                135357SKHT-ASShenzhenKatherineHengTechnologyInformationCofalse
                MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                185.125.190.26ppc.elfGet hashmaliciousMiraiBrowse
                  wriww68k.elfGet hashmaliciousGafgyt, Mirai, OkiruBrowse
                    x86.elfGet hashmaliciousUnknownBrowse
                      zmap.x86_64.elfGet hashmaliciousOkiruBrowse
                        spc.elfGet hashmaliciousMiraiBrowse
                          na.elfGet hashmaliciousGafgyt, MiraiBrowse
                            na.elfGet hashmaliciousGafgyt, MiraiBrowse
                              na.elfGet hashmaliciousGafgyt, MiraiBrowse
                                boatnet.arm7.elfGet hashmaliciousMiraiBrowse
                                  m68k.elfGet hashmaliciousUnknownBrowse
                                    154.216.20.164zmap.arm7.elfGet hashmaliciousMirai, OkiruBrowse
                                      zmap.mips.elfGet hashmaliciousMirai, OkiruBrowse
                                        zmap.m68k.elfGet hashmaliciousMirai, OkiruBrowse
                                          zmap.mpsl.elfGet hashmaliciousMirai, OkiruBrowse
                                            zmap.ppc.elfGet hashmaliciousMirai, OkiruBrowse
                                              zmap.sh4.elfGet hashmaliciousMirai, OkiruBrowse
                                                zmap.spc.elfGet hashmaliciousMirai, OkiruBrowse
                                                  zmap.x86.elfGet hashmaliciousOkiruBrowse
                                                    debug.dbg.elfGet hashmaliciousMirai, OkiruBrowse
                                                      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                      cnc.dico-inside.comzmap.arm7.elfGet hashmaliciousMirai, OkiruBrowse
                                                      • 154.216.20.164
                                                      zmap.mips.elfGet hashmaliciousMirai, OkiruBrowse
                                                      • 154.216.20.164
                                                      zmap.m68k.elfGet hashmaliciousMirai, OkiruBrowse
                                                      • 154.216.20.164
                                                      zmap.mpsl.elfGet hashmaliciousMirai, OkiruBrowse
                                                      • 154.216.20.164
                                                      zmap.ppc.elfGet hashmaliciousMirai, OkiruBrowse
                                                      • 154.216.20.164
                                                      zmap.sh4.elfGet hashmaliciousMirai, OkiruBrowse
                                                      • 154.216.20.164
                                                      zmap.spc.elfGet hashmaliciousMirai, OkiruBrowse
                                                      • 154.216.20.164
                                                      zmap.x86.elfGet hashmaliciousOkiruBrowse
                                                      • 154.216.20.164
                                                      debug.dbg.elfGet hashmaliciousMirai, OkiruBrowse
                                                      • 154.216.20.164
                                                      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                      SKHT-ASShenzhenKatherineHengTechnologyInformationCoarm5.elfGet hashmaliciousUnknownBrowse
                                                      • 154.216.20.58
                                                      jew.spc.elfGet hashmaliciousMiraiBrowse
                                                      • 156.254.70.156
                                                      x86_64.elfGet hashmaliciousMiraiBrowse
                                                      • 156.241.11.59
                                                      mips.elfGet hashmaliciousUnknownBrowse
                                                      • 154.216.20.58
                                                      parm.elfGet hashmaliciousMiraiBrowse
                                                      • 156.230.19.184
                                                      tel.x86.elfGet hashmaliciousMiraiBrowse
                                                      • 156.230.19.193
                                                      zmap.arm7.elfGet hashmaliciousMirai, OkiruBrowse
                                                      • 154.216.20.164
                                                      zmap.mips.elfGet hashmaliciousMirai, OkiruBrowse
                                                      • 154.216.20.164
                                                      zmap.m68k.elfGet hashmaliciousMirai, OkiruBrowse
                                                      • 154.216.20.164
                                                      garm.elfGet hashmaliciousMiraiBrowse
                                                      • 156.241.11.91
                                                      CANONICAL-ASGBmips.elfGet hashmaliciousUnknownBrowse
                                                      • 91.189.91.42
                                                      ppc.elfGet hashmaliciousMiraiBrowse
                                                      • 185.125.190.26
                                                      parm6.elfGet hashmaliciousMiraiBrowse
                                                      • 91.189.91.42
                                                      zmap.mpsl.elfGet hashmaliciousMirai, OkiruBrowse
                                                      • 91.189.91.42
                                                      xmpsl.elfGet hashmaliciousUnknownBrowse
                                                      • 91.189.91.42
                                                      tarm.elfGet hashmaliciousUnknownBrowse
                                                      • 91.189.91.42
                                                      wriww68k.elfGet hashmaliciousGafgyt, Mirai, OkiruBrowse
                                                      • 185.125.190.26
                                                      zmap.sh4.elfGet hashmaliciousMirai, OkiruBrowse
                                                      • 91.189.91.42
                                                      x86.elfGet hashmaliciousUnknownBrowse
                                                      • 185.125.190.26
                                                      zmap.x86_64.elfGet hashmaliciousOkiruBrowse
                                                      • 185.125.190.26
                                                      No context
                                                      No context
                                                      No created / dropped files found
                                                      File type:ELF 32-bit LSB executable, ARM, version 1 (ARM), statically linked, stripped
                                                      Entropy (8bit):6.196744399151135
                                                      TrID:
                                                      • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                                                      File name:zmap.arm.elf
                                                      File size:75'840 bytes
                                                      MD5:823958d1dbb59368ec9cb465345ede82
                                                      SHA1:4246851d3b9f1b59c45e2069fc1e204fa2937fc6
                                                      SHA256:ce3fcb923990e59f2bcee0f811a868fa7a0abf2a461b54974977d1db6e940aee
                                                      SHA512:2598ed24790e8e29fe7e54c8b06c65bc58a55348a0eb20359d6b25eeee0d5565b5746915c6f07f6149f8c0fa8ffac3a060bb7b794d36dbfeaeb40f8aebe4803d
                                                      SSDEEP:1536:+jdTb69MAWg92P72qa9H4S5wPX6WZeqLeBZebFvTsA:+jd14H4QWZetb0Ts
                                                      TLSH:0C733A45B9815A13C6E5127BFAAE01CD372523E8E3DE7207DE216F21379682F0D67A81
                                                      File Content Preview:.ELF...a..........(.........4....&......4. ...(......................"..."..............."..."...".......'..........Q.td..................................-...L."...R@..........0@-.\P...0....S.0...P@...0... ....R......0...0...........0... ....R..... 0....S

                                                      ELF header

                                                      Class:ELF32
                                                      Data:2's complement, little endian
                                                      Version:1 (current)
                                                      Machine:ARM
                                                      Version Number:0x1
                                                      Type:EXEC (Executable file)
                                                      OS/ABI:ARM - ABI
                                                      ABI Version:0
                                                      Entry Point Address:0x8190
                                                      Flags:0x202
                                                      ELF Header Size:52
                                                      Program Header Offset:52
                                                      Program Header Size:32
                                                      Number of Program Headers:3
                                                      Section Header Offset:75440
                                                      Section Header Size:40
                                                      Number of Section Headers:10
                                                      Header String Table Index:9
                                                      NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                                      NULL0x00x00x00x00x0000
                                                      .initPROGBITS0x80940x940x180x00x6AX004
                                                      .textPROGBITS0x80b00xb00x101800x00x6AX0016
                                                      .finiPROGBITS0x182300x102300x140x00x6AX004
                                                      .rodataPROGBITS0x182440x102440x20840x00x2A004
                                                      .ctorsPROGBITS0x222cc0x122cc0x80x00x3WA004
                                                      .dtorsPROGBITS0x222d40x122d40x80x00x3WA004
                                                      .dataPROGBITS0x222e00x122e00x3900x00x3WA004
                                                      .bssNOBITS0x226700x126700x24300x00x3WA004
                                                      .shstrtabSTRTAB0x00x126700x3e0x00x0001
                                                      TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                      LOAD0x00x80000x80000x122c80x122c86.22510x5R E0x8000.init .text .fini .rodata
                                                      LOAD0x122cc0x222cc0x222cc0x3a40x27d43.06850x6RW 0x8000.ctors .dtors .data .bss
                                                      GNU_STACK0x00x00x00x00x00.00000x7RWE0x4
                                                      TimestampSource PortDest PortSource IPDest IP
                                                      Oct 29, 2024 17:28:18.811501980 CET5478459962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:18.817039967 CET5996254784154.216.20.164192.168.2.14
                                                      Oct 29, 2024 17:28:18.817121983 CET5478459962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:18.829580069 CET5478459962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:18.835028887 CET5996254784154.216.20.164192.168.2.14
                                                      Oct 29, 2024 17:28:18.835086107 CET5478459962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:18.840500116 CET5996254784154.216.20.164192.168.2.14
                                                      Oct 29, 2024 17:28:19.697688103 CET5996254784154.216.20.164192.168.2.14
                                                      Oct 29, 2024 17:28:19.698081017 CET5478459962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:19.698081017 CET5478459962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:19.762167931 CET5478659962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:19.767673969 CET5996254786154.216.20.164192.168.2.14
                                                      Oct 29, 2024 17:28:19.767985106 CET5478659962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:19.769148111 CET5478659962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:19.775088072 CET5996254786154.216.20.164192.168.2.14
                                                      Oct 29, 2024 17:28:19.775192022 CET5478659962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:19.781131983 CET5996254786154.216.20.164192.168.2.14
                                                      Oct 29, 2024 17:28:20.637486935 CET5996254786154.216.20.164192.168.2.14
                                                      Oct 29, 2024 17:28:20.637722015 CET5478659962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:20.637722015 CET5478659962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:20.637763023 CET5996254786154.216.20.164192.168.2.14
                                                      Oct 29, 2024 17:28:20.637825012 CET5478659962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:20.706221104 CET5478859962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:20.717914104 CET5996254788154.216.20.164192.168.2.14
                                                      Oct 29, 2024 17:28:20.718008041 CET5478859962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:20.718980074 CET5478859962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:20.729301929 CET5996254788154.216.20.164192.168.2.14
                                                      Oct 29, 2024 17:28:20.729398966 CET5478859962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:20.735080957 CET5996254788154.216.20.164192.168.2.14
                                                      Oct 29, 2024 17:28:21.596369982 CET5996254788154.216.20.164192.168.2.14
                                                      Oct 29, 2024 17:28:21.596493959 CET5478859962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:21.596570969 CET5478859962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:21.607337952 CET5479059962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:21.613018036 CET5996254790154.216.20.164192.168.2.14
                                                      Oct 29, 2024 17:28:21.613084078 CET5479059962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:21.613715887 CET5479059962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:21.619091034 CET5996254790154.216.20.164192.168.2.14
                                                      Oct 29, 2024 17:28:21.619142056 CET5479059962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:21.624445915 CET5996254790154.216.20.164192.168.2.14
                                                      Oct 29, 2024 17:28:22.493290901 CET5996254790154.216.20.164192.168.2.14
                                                      Oct 29, 2024 17:28:22.493436098 CET5479059962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:22.493473053 CET5479059962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:22.502439976 CET5479259962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:22.507863045 CET5996254792154.216.20.164192.168.2.14
                                                      Oct 29, 2024 17:28:22.507960081 CET5479259962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:22.508557081 CET5479259962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:22.514362097 CET5996254792154.216.20.164192.168.2.14
                                                      Oct 29, 2024 17:28:22.514431953 CET5479259962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:22.519889116 CET5996254792154.216.20.164192.168.2.14
                                                      Oct 29, 2024 17:28:23.368053913 CET5996254792154.216.20.164192.168.2.14
                                                      Oct 29, 2024 17:28:23.368226051 CET5479259962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:23.368295908 CET5479259962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:23.378143072 CET5479459962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:23.383833885 CET5996254794154.216.20.164192.168.2.14
                                                      Oct 29, 2024 17:28:23.383904934 CET5479459962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:23.384510994 CET5479459962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:23.389853001 CET5996254794154.216.20.164192.168.2.14
                                                      Oct 29, 2024 17:28:23.389914989 CET5479459962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:23.395294905 CET5996254794154.216.20.164192.168.2.14
                                                      Oct 29, 2024 17:28:24.258979082 CET5996254794154.216.20.164192.168.2.14
                                                      Oct 29, 2024 17:28:24.259166956 CET5479459962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:24.259252071 CET5479459962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:24.270593882 CET5479659962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:24.275985956 CET5996254796154.216.20.164192.168.2.14
                                                      Oct 29, 2024 17:28:24.276078939 CET5479659962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:24.276890993 CET5479659962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:24.282227993 CET5996254796154.216.20.164192.168.2.14
                                                      Oct 29, 2024 17:28:24.282291889 CET5479659962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:24.289388895 CET5996254796154.216.20.164192.168.2.14
                                                      Oct 29, 2024 17:28:25.249794960 CET5996254796154.216.20.164192.168.2.14
                                                      Oct 29, 2024 17:28:25.250049114 CET5479659962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:25.250049114 CET5479659962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:25.260272026 CET5479859962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:25.265697002 CET5996254798154.216.20.164192.168.2.14
                                                      Oct 29, 2024 17:28:25.265753031 CET5479859962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:25.266478062 CET5479859962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:25.271835089 CET5996254798154.216.20.164192.168.2.14
                                                      Oct 29, 2024 17:28:25.271950960 CET5479859962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:25.277267933 CET5996254798154.216.20.164192.168.2.14
                                                      Oct 29, 2024 17:28:26.151930094 CET5996254798154.216.20.164192.168.2.14
                                                      Oct 29, 2024 17:28:26.152076006 CET5479859962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:26.152122974 CET5479859962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:26.161017895 CET5480059962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:26.166467905 CET5996254800154.216.20.164192.168.2.14
                                                      Oct 29, 2024 17:28:26.166548967 CET5480059962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:26.167212963 CET5480059962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:26.172665119 CET5996254800154.216.20.164192.168.2.14
                                                      Oct 29, 2024 17:28:26.172722101 CET5480059962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:26.178212881 CET5996254800154.216.20.164192.168.2.14
                                                      Oct 29, 2024 17:28:27.044857979 CET5996254800154.216.20.164192.168.2.14
                                                      Oct 29, 2024 17:28:27.045023918 CET5480059962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:27.045125008 CET5480059962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:27.054202080 CET5480259962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:27.059993029 CET5996254802154.216.20.164192.168.2.14
                                                      Oct 29, 2024 17:28:27.060096979 CET5480259962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:27.060868025 CET5480259962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:27.066155910 CET5996254802154.216.20.164192.168.2.14
                                                      Oct 29, 2024 17:28:27.066226006 CET5480259962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:27.071638107 CET5996254802154.216.20.164192.168.2.14
                                                      Oct 29, 2024 17:28:27.936135054 CET5996254802154.216.20.164192.168.2.14
                                                      Oct 29, 2024 17:28:27.936300993 CET5480259962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:27.936372042 CET5480259962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:27.945751905 CET5480459962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:27.952150106 CET5996254804154.216.20.164192.168.2.14
                                                      Oct 29, 2024 17:28:27.952203035 CET5480459962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:27.952790976 CET5480459962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:27.958295107 CET5996254804154.216.20.164192.168.2.14
                                                      Oct 29, 2024 17:28:27.958347082 CET5480459962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:27.963974953 CET5996254804154.216.20.164192.168.2.14
                                                      Oct 29, 2024 17:28:28.826984882 CET5996254804154.216.20.164192.168.2.14
                                                      Oct 29, 2024 17:28:28.827223063 CET5480459962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:28.827281952 CET5480459962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:28.837117910 CET5480659962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:28.842717886 CET5996254806154.216.20.164192.168.2.14
                                                      Oct 29, 2024 17:28:28.842899084 CET5480659962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:28.843854904 CET5480659962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:28.849821091 CET5996254806154.216.20.164192.168.2.14
                                                      Oct 29, 2024 17:28:28.849881887 CET5480659962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:28.855529070 CET5996254806154.216.20.164192.168.2.14
                                                      Oct 29, 2024 17:28:29.193483114 CET46540443192.168.2.14185.125.190.26
                                                      Oct 29, 2024 17:28:29.789130926 CET5996254806154.216.20.164192.168.2.14
                                                      Oct 29, 2024 17:28:29.789150000 CET5996254806154.216.20.164192.168.2.14
                                                      Oct 29, 2024 17:28:29.789299011 CET5480659962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:29.789299011 CET5480659962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:29.789401054 CET5480659962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:29.791342974 CET5996254806154.216.20.164192.168.2.14
                                                      Oct 29, 2024 17:28:29.791435957 CET5480659962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:29.799155951 CET5480859962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:29.804610968 CET5996254808154.216.20.164192.168.2.14
                                                      Oct 29, 2024 17:28:29.804655075 CET5480859962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:29.805615902 CET5480859962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:29.810964108 CET5996254808154.216.20.164192.168.2.14
                                                      Oct 29, 2024 17:28:29.811003923 CET5480859962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:29.816421986 CET5996254808154.216.20.164192.168.2.14
                                                      Oct 29, 2024 17:28:30.673145056 CET5996254808154.216.20.164192.168.2.14
                                                      Oct 29, 2024 17:28:30.673276901 CET5480859962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:30.673337936 CET5480859962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:30.682888031 CET5481059962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:30.688927889 CET5996254810154.216.20.164192.168.2.14
                                                      Oct 29, 2024 17:28:30.689008951 CET5481059962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:30.689594030 CET5481059962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:30.695354939 CET5996254810154.216.20.164192.168.2.14
                                                      Oct 29, 2024 17:28:30.695413113 CET5481059962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:30.700854063 CET5996254810154.216.20.164192.168.2.14
                                                      Oct 29, 2024 17:28:31.560652971 CET5996254810154.216.20.164192.168.2.14
                                                      Oct 29, 2024 17:28:31.560746908 CET5996254810154.216.20.164192.168.2.14
                                                      Oct 29, 2024 17:28:31.560800076 CET5996254810154.216.20.164192.168.2.14
                                                      Oct 29, 2024 17:28:31.560817003 CET5481059962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:31.560853958 CET5481059962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:31.560853958 CET5481059962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:31.560854912 CET5481059962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:31.570405006 CET5481259962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:31.575860023 CET5996254812154.216.20.164192.168.2.14
                                                      Oct 29, 2024 17:28:31.575917006 CET5481259962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:31.576400042 CET5481259962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:31.582285881 CET5996254812154.216.20.164192.168.2.14
                                                      Oct 29, 2024 17:28:31.582355976 CET5481259962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:31.588619947 CET5996254812154.216.20.164192.168.2.14
                                                      Oct 29, 2024 17:28:32.510178089 CET5996254812154.216.20.164192.168.2.14
                                                      Oct 29, 2024 17:28:32.510341883 CET5481259962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:32.510468960 CET5481259962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:32.521461964 CET5481459962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:32.527395964 CET5996254814154.216.20.164192.168.2.14
                                                      Oct 29, 2024 17:28:32.527508020 CET5481459962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:32.528130054 CET5481459962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:32.533795118 CET5996254814154.216.20.164192.168.2.14
                                                      Oct 29, 2024 17:28:32.533879042 CET5481459962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:32.539916039 CET5996254814154.216.20.164192.168.2.14
                                                      Oct 29, 2024 17:28:33.406833887 CET5996254814154.216.20.164192.168.2.14
                                                      Oct 29, 2024 17:28:33.407072067 CET5481459962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:33.407100916 CET5481459962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:33.417510033 CET5481659962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:33.423363924 CET5996254816154.216.20.164192.168.2.14
                                                      Oct 29, 2024 17:28:33.423497915 CET5481659962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:33.424174070 CET5481659962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:33.429606915 CET5996254816154.216.20.164192.168.2.14
                                                      Oct 29, 2024 17:28:33.429714918 CET5481659962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:33.435101032 CET5996254816154.216.20.164192.168.2.14
                                                      Oct 29, 2024 17:28:34.289659977 CET5996254816154.216.20.164192.168.2.14
                                                      Oct 29, 2024 17:28:34.289855957 CET5996254816154.216.20.164192.168.2.14
                                                      Oct 29, 2024 17:28:34.289936066 CET5481659962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:34.289936066 CET5481659962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:34.290020943 CET5481659962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:34.299987078 CET5481859962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:34.305423021 CET5996254818154.216.20.164192.168.2.14
                                                      Oct 29, 2024 17:28:34.305541992 CET5481859962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:34.306534052 CET5481859962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:34.312422991 CET5996254818154.216.20.164192.168.2.14
                                                      Oct 29, 2024 17:28:34.312489033 CET5481859962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:34.318043947 CET5996254818154.216.20.164192.168.2.14
                                                      Oct 29, 2024 17:28:35.247839928 CET5996254818154.216.20.164192.168.2.14
                                                      Oct 29, 2024 17:28:35.247854948 CET5996254818154.216.20.164192.168.2.14
                                                      Oct 29, 2024 17:28:35.247879028 CET5996254818154.216.20.164192.168.2.14
                                                      Oct 29, 2024 17:28:35.248053074 CET5481859962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:35.248099089 CET5481859962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:35.248099089 CET5481859962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:35.248184919 CET5481859962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:35.257735014 CET5482059962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:35.263159990 CET5996254820154.216.20.164192.168.2.14
                                                      Oct 29, 2024 17:28:35.263278008 CET5482059962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:35.264113903 CET5482059962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:35.269527912 CET5996254820154.216.20.164192.168.2.14
                                                      Oct 29, 2024 17:28:35.269618034 CET5482059962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:35.275011063 CET5996254820154.216.20.164192.168.2.14
                                                      Oct 29, 2024 17:28:36.138708115 CET5996254820154.216.20.164192.168.2.14
                                                      Oct 29, 2024 17:28:36.138935089 CET5482059962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:36.139020920 CET5482059962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:36.202075958 CET5482259962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:36.207623005 CET5996254822154.216.20.164192.168.2.14
                                                      Oct 29, 2024 17:28:36.207756996 CET5482259962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:36.209088087 CET5482259962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:36.214495897 CET5996254822154.216.20.164192.168.2.14
                                                      Oct 29, 2024 17:28:36.214581013 CET5482259962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:36.220546007 CET5996254822154.216.20.164192.168.2.14
                                                      Oct 29, 2024 17:28:37.107027054 CET5996254822154.216.20.164192.168.2.14
                                                      Oct 29, 2024 17:28:37.107405901 CET5482259962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:37.107505083 CET5482259962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:37.147306919 CET5482459962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:37.153311968 CET5996254824154.216.20.164192.168.2.14
                                                      Oct 29, 2024 17:28:37.153405905 CET5482459962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:37.154572964 CET5482459962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:37.160775900 CET5996254824154.216.20.164192.168.2.14
                                                      Oct 29, 2024 17:28:37.160851955 CET5482459962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:37.166528940 CET5996254824154.216.20.164192.168.2.14
                                                      Oct 29, 2024 17:28:38.035844088 CET5996254824154.216.20.164192.168.2.14
                                                      Oct 29, 2024 17:28:38.035972118 CET5996254824154.216.20.164192.168.2.14
                                                      Oct 29, 2024 17:28:38.036024094 CET5482459962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:38.036084890 CET5482459962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:38.036084890 CET5482459962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:38.045553923 CET5482659962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:38.050908089 CET5996254826154.216.20.164192.168.2.14
                                                      Oct 29, 2024 17:28:38.050975084 CET5482659962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:38.051677942 CET5482659962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:38.057018995 CET5996254826154.216.20.164192.168.2.14
                                                      Oct 29, 2024 17:28:38.057085991 CET5482659962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:38.062743902 CET5996254826154.216.20.164192.168.2.14
                                                      Oct 29, 2024 17:28:38.914911032 CET5996254826154.216.20.164192.168.2.14
                                                      Oct 29, 2024 17:28:38.915110111 CET5482659962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:38.915131092 CET5996254826154.216.20.164192.168.2.14
                                                      Oct 29, 2024 17:28:38.915174007 CET5482659962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:38.915256977 CET5482659962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:38.925916910 CET5482859962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:38.931269884 CET5996254828154.216.20.164192.168.2.14
                                                      Oct 29, 2024 17:28:38.931441069 CET5482859962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:38.932107925 CET5482859962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:38.937550068 CET5996254828154.216.20.164192.168.2.14
                                                      Oct 29, 2024 17:28:38.937644958 CET5482859962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:38.943263054 CET5996254828154.216.20.164192.168.2.14
                                                      Oct 29, 2024 17:28:48.941031933 CET5482859962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:28:48.946774960 CET5996254828154.216.20.164192.168.2.14
                                                      Oct 29, 2024 17:28:49.249403954 CET5996254828154.216.20.164192.168.2.14
                                                      Oct 29, 2024 17:28:49.249562979 CET5482859962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:29:00.168284893 CET46540443192.168.2.14185.125.190.26
                                                      Oct 29, 2024 17:29:49.300436020 CET5482859962192.168.2.14154.216.20.164
                                                      Oct 29, 2024 17:29:49.306524038 CET5996254828154.216.20.164192.168.2.14
                                                      Oct 29, 2024 17:29:49.564480066 CET5996254828154.216.20.164192.168.2.14
                                                      Oct 29, 2024 17:29:49.564672947 CET5482859962192.168.2.14154.216.20.164
                                                      TimestampSource PortDest PortSource IPDest IP
                                                      Oct 29, 2024 17:28:18.799911976 CET6078253192.168.2.148.8.8.8
                                                      Oct 29, 2024 17:28:18.808861017 CET53607828.8.8.8192.168.2.14
                                                      Oct 29, 2024 17:28:19.699105024 CET5926153192.168.2.148.8.8.8
                                                      Oct 29, 2024 17:28:19.761317015 CET53592618.8.8.8192.168.2.14
                                                      Oct 29, 2024 17:28:20.638957024 CET3407253192.168.2.148.8.8.8
                                                      Oct 29, 2024 17:28:20.705172062 CET53340728.8.8.8192.168.2.14
                                                      Oct 29, 2024 17:28:21.597441912 CET4163853192.168.2.148.8.8.8
                                                      Oct 29, 2024 17:28:21.606856108 CET53416388.8.8.8192.168.2.14
                                                      Oct 29, 2024 17:28:22.494370937 CET5332253192.168.2.148.8.8.8
                                                      Oct 29, 2024 17:28:22.502017975 CET53533228.8.8.8192.168.2.14
                                                      Oct 29, 2024 17:28:23.369204044 CET3987153192.168.2.148.8.8.8
                                                      Oct 29, 2024 17:28:23.377727032 CET53398718.8.8.8192.168.2.14
                                                      Oct 29, 2024 17:28:24.260304928 CET5773653192.168.2.148.8.8.8
                                                      Oct 29, 2024 17:28:24.270010948 CET53577368.8.8.8192.168.2.14
                                                      Oct 29, 2024 17:28:25.251064062 CET5033553192.168.2.148.8.8.8
                                                      Oct 29, 2024 17:28:25.259705067 CET53503358.8.8.8192.168.2.14
                                                      Oct 29, 2024 17:28:26.152923107 CET4556353192.168.2.148.8.8.8
                                                      Oct 29, 2024 17:28:26.160413027 CET53455638.8.8.8192.168.2.14
                                                      Oct 29, 2024 17:28:27.046096087 CET3942753192.168.2.148.8.8.8
                                                      Oct 29, 2024 17:28:27.053471088 CET53394278.8.8.8192.168.2.14
                                                      Oct 29, 2024 17:28:27.937407017 CET5176453192.168.2.148.8.8.8
                                                      Oct 29, 2024 17:28:27.945363998 CET53517648.8.8.8192.168.2.14
                                                      Oct 29, 2024 17:28:28.828593969 CET5781153192.168.2.148.8.8.8
                                                      Oct 29, 2024 17:28:28.836597919 CET53578118.8.8.8192.168.2.14
                                                      Oct 29, 2024 17:28:29.790643930 CET3496853192.168.2.148.8.8.8
                                                      Oct 29, 2024 17:28:29.798654079 CET53349688.8.8.8192.168.2.14
                                                      Oct 29, 2024 17:28:30.674640894 CET4449953192.168.2.148.8.8.8
                                                      Oct 29, 2024 17:28:30.682296991 CET53444998.8.8.8192.168.2.14
                                                      Oct 29, 2024 17:28:31.561579943 CET3667353192.168.2.148.8.8.8
                                                      Oct 29, 2024 17:28:31.570061922 CET53366738.8.8.8192.168.2.14
                                                      Oct 29, 2024 17:28:32.511645079 CET6007053192.168.2.148.8.8.8
                                                      Oct 29, 2024 17:28:32.520726919 CET53600708.8.8.8192.168.2.14
                                                      Oct 29, 2024 17:28:33.407999992 CET3582953192.168.2.148.8.8.8
                                                      Oct 29, 2024 17:28:33.416810036 CET53358298.8.8.8192.168.2.14
                                                      Oct 29, 2024 17:28:34.291380882 CET3584053192.168.2.148.8.8.8
                                                      Oct 29, 2024 17:28:34.299446106 CET53358408.8.8.8192.168.2.14
                                                      Oct 29, 2024 17:28:35.249511957 CET4530953192.168.2.148.8.8.8
                                                      Oct 29, 2024 17:28:35.257191896 CET53453098.8.8.8192.168.2.14
                                                      Oct 29, 2024 17:28:36.140469074 CET5071953192.168.2.148.8.8.8
                                                      Oct 29, 2024 17:28:36.200712919 CET53507198.8.8.8192.168.2.14
                                                      Oct 29, 2024 17:28:37.112157106 CET5467153192.168.2.148.8.8.8
                                                      Oct 29, 2024 17:28:37.146044970 CET53546718.8.8.8192.168.2.14
                                                      Oct 29, 2024 17:28:38.037092924 CET5857053192.168.2.148.8.8.8
                                                      Oct 29, 2024 17:28:38.045118093 CET53585708.8.8.8192.168.2.14
                                                      Oct 29, 2024 17:28:38.916825056 CET4475753192.168.2.148.8.8.8
                                                      Oct 29, 2024 17:28:38.925324917 CET53447578.8.8.8192.168.2.14
                                                      TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                                      Oct 29, 2024 17:28:18.799911976 CET192.168.2.148.8.8.80xd9b4Standard query (0)cnc.dico-inside.comA (IP address)IN (0x0001)false
                                                      Oct 29, 2024 17:28:19.699105024 CET192.168.2.148.8.8.80xea53Standard query (0)cnc.dico-inside.comA (IP address)IN (0x0001)false
                                                      Oct 29, 2024 17:28:20.638957024 CET192.168.2.148.8.8.80x193bStandard query (0)cnc.dico-inside.comA (IP address)IN (0x0001)false
                                                      Oct 29, 2024 17:28:21.597441912 CET192.168.2.148.8.8.80xae02Standard query (0)cnc.dico-inside.comA (IP address)IN (0x0001)false
                                                      Oct 29, 2024 17:28:22.494370937 CET192.168.2.148.8.8.80x5659Standard query (0)cnc.dico-inside.comA (IP address)IN (0x0001)false
                                                      Oct 29, 2024 17:28:23.369204044 CET192.168.2.148.8.8.80xf7cStandard query (0)cnc.dico-inside.comA (IP address)IN (0x0001)false
                                                      Oct 29, 2024 17:28:24.260304928 CET192.168.2.148.8.8.80xce37Standard query (0)cnc.dico-inside.comA (IP address)IN (0x0001)false
                                                      Oct 29, 2024 17:28:25.251064062 CET192.168.2.148.8.8.80x61a1Standard query (0)cnc.dico-inside.comA (IP address)IN (0x0001)false
                                                      Oct 29, 2024 17:28:26.152923107 CET192.168.2.148.8.8.80xd6edStandard query (0)cnc.dico-inside.comA (IP address)IN (0x0001)false
                                                      Oct 29, 2024 17:28:27.046096087 CET192.168.2.148.8.8.80xd6abStandard query (0)cnc.dico-inside.comA (IP address)IN (0x0001)false
                                                      Oct 29, 2024 17:28:27.937407017 CET192.168.2.148.8.8.80x6c8fStandard query (0)cnc.dico-inside.comA (IP address)IN (0x0001)false
                                                      Oct 29, 2024 17:28:28.828593969 CET192.168.2.148.8.8.80x9d42Standard query (0)cnc.dico-inside.comA (IP address)IN (0x0001)false
                                                      Oct 29, 2024 17:28:29.790643930 CET192.168.2.148.8.8.80x9309Standard query (0)cnc.dico-inside.comA (IP address)IN (0x0001)false
                                                      Oct 29, 2024 17:28:30.674640894 CET192.168.2.148.8.8.80x7551Standard query (0)cnc.dico-inside.comA (IP address)IN (0x0001)false
                                                      Oct 29, 2024 17:28:31.561579943 CET192.168.2.148.8.8.80x5031Standard query (0)cnc.dico-inside.comA (IP address)IN (0x0001)false
                                                      Oct 29, 2024 17:28:32.511645079 CET192.168.2.148.8.8.80x9a74Standard query (0)cnc.dico-inside.comA (IP address)IN (0x0001)false
                                                      Oct 29, 2024 17:28:33.407999992 CET192.168.2.148.8.8.80x4edStandard query (0)cnc.dico-inside.comA (IP address)IN (0x0001)false
                                                      Oct 29, 2024 17:28:34.291380882 CET192.168.2.148.8.8.80xff0eStandard query (0)cnc.dico-inside.comA (IP address)IN (0x0001)false
                                                      Oct 29, 2024 17:28:35.249511957 CET192.168.2.148.8.8.80x6266Standard query (0)cnc.dico-inside.comA (IP address)IN (0x0001)false
                                                      Oct 29, 2024 17:28:36.140469074 CET192.168.2.148.8.8.80x3149Standard query (0)cnc.dico-inside.comA (IP address)IN (0x0001)false
                                                      Oct 29, 2024 17:28:37.112157106 CET192.168.2.148.8.8.80x318fStandard query (0)cnc.dico-inside.comA (IP address)IN (0x0001)false
                                                      Oct 29, 2024 17:28:38.037092924 CET192.168.2.148.8.8.80x5d30Standard query (0)cnc.dico-inside.comA (IP address)IN (0x0001)false
                                                      Oct 29, 2024 17:28:38.916825056 CET192.168.2.148.8.8.80xbcc9Standard query (0)cnc.dico-inside.comA (IP address)IN (0x0001)false
                                                      TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                                      Oct 29, 2024 17:28:18.808861017 CET8.8.8.8192.168.2.140xd9b4No error (0)cnc.dico-inside.com154.216.20.164A (IP address)IN (0x0001)false
                                                      Oct 29, 2024 17:28:19.761317015 CET8.8.8.8192.168.2.140xea53No error (0)cnc.dico-inside.com154.216.20.164A (IP address)IN (0x0001)false
                                                      Oct 29, 2024 17:28:20.705172062 CET8.8.8.8192.168.2.140x193bNo error (0)cnc.dico-inside.com154.216.20.164A (IP address)IN (0x0001)false
                                                      Oct 29, 2024 17:28:21.606856108 CET8.8.8.8192.168.2.140xae02No error (0)cnc.dico-inside.com154.216.20.164A (IP address)IN (0x0001)false
                                                      Oct 29, 2024 17:28:22.502017975 CET8.8.8.8192.168.2.140x5659No error (0)cnc.dico-inside.com154.216.20.164A (IP address)IN (0x0001)false
                                                      Oct 29, 2024 17:28:23.377727032 CET8.8.8.8192.168.2.140xf7cNo error (0)cnc.dico-inside.com154.216.20.164A (IP address)IN (0x0001)false
                                                      Oct 29, 2024 17:28:24.270010948 CET8.8.8.8192.168.2.140xce37No error (0)cnc.dico-inside.com154.216.20.164A (IP address)IN (0x0001)false
                                                      Oct 29, 2024 17:28:25.259705067 CET8.8.8.8192.168.2.140x61a1No error (0)cnc.dico-inside.com154.216.20.164A (IP address)IN (0x0001)false
                                                      Oct 29, 2024 17:28:26.160413027 CET8.8.8.8192.168.2.140xd6edNo error (0)cnc.dico-inside.com154.216.20.164A (IP address)IN (0x0001)false
                                                      Oct 29, 2024 17:28:27.053471088 CET8.8.8.8192.168.2.140xd6abNo error (0)cnc.dico-inside.com154.216.20.164A (IP address)IN (0x0001)false
                                                      Oct 29, 2024 17:28:27.945363998 CET8.8.8.8192.168.2.140x6c8fNo error (0)cnc.dico-inside.com154.216.20.164A (IP address)IN (0x0001)false
                                                      Oct 29, 2024 17:28:28.836597919 CET8.8.8.8192.168.2.140x9d42No error (0)cnc.dico-inside.com154.216.20.164A (IP address)IN (0x0001)false
                                                      Oct 29, 2024 17:28:29.798654079 CET8.8.8.8192.168.2.140x9309No error (0)cnc.dico-inside.com154.216.20.164A (IP address)IN (0x0001)false
                                                      Oct 29, 2024 17:28:30.682296991 CET8.8.8.8192.168.2.140x7551No error (0)cnc.dico-inside.com154.216.20.164A (IP address)IN (0x0001)false
                                                      Oct 29, 2024 17:28:31.570061922 CET8.8.8.8192.168.2.140x5031No error (0)cnc.dico-inside.com154.216.20.164A (IP address)IN (0x0001)false
                                                      Oct 29, 2024 17:28:32.520726919 CET8.8.8.8192.168.2.140x9a74No error (0)cnc.dico-inside.com154.216.20.164A (IP address)IN (0x0001)false
                                                      Oct 29, 2024 17:28:33.416810036 CET8.8.8.8192.168.2.140x4edNo error (0)cnc.dico-inside.com154.216.20.164A (IP address)IN (0x0001)false
                                                      Oct 29, 2024 17:28:34.299446106 CET8.8.8.8192.168.2.140xff0eNo error (0)cnc.dico-inside.com154.216.20.164A (IP address)IN (0x0001)false
                                                      Oct 29, 2024 17:28:35.257191896 CET8.8.8.8192.168.2.140x6266No error (0)cnc.dico-inside.com154.216.20.164A (IP address)IN (0x0001)false
                                                      Oct 29, 2024 17:28:36.200712919 CET8.8.8.8192.168.2.140x3149No error (0)cnc.dico-inside.com154.216.20.164A (IP address)IN (0x0001)false
                                                      Oct 29, 2024 17:28:37.146044970 CET8.8.8.8192.168.2.140x318fNo error (0)cnc.dico-inside.com154.216.20.164A (IP address)IN (0x0001)false
                                                      Oct 29, 2024 17:28:38.045118093 CET8.8.8.8192.168.2.140x5d30No error (0)cnc.dico-inside.com154.216.20.164A (IP address)IN (0x0001)false
                                                      Oct 29, 2024 17:28:38.925324917 CET8.8.8.8192.168.2.140xbcc9No error (0)cnc.dico-inside.com154.216.20.164A (IP address)IN (0x0001)false

                                                      System Behavior

                                                      Start time (UTC):16:28:18
                                                      Start date (UTC):29/10/2024
                                                      Path:/tmp/zmap.arm.elf
                                                      Arguments:/tmp/zmap.arm.elf
                                                      File size:4956856 bytes
                                                      MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                      Start time (UTC):16:28:18
                                                      Start date (UTC):29/10/2024
                                                      Path:/tmp/zmap.arm.elf
                                                      Arguments:-
                                                      File size:4956856 bytes
                                                      MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                      Start time (UTC):16:28:18
                                                      Start date (UTC):29/10/2024
                                                      Path:/tmp/zmap.arm.elf
                                                      Arguments:-
                                                      File size:4956856 bytes
                                                      MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1