Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
zmap.arm.elf

Overview

General Information

Sample name:zmap.arm.elf
Analysis ID:1546748
MD5:cdc46d2754ffaf581f0e011c4960332d
SHA1:53657bd523faeea5d768a830412113fb46c39321
SHA256:9f29e193d60134d76b92f383016a64f7eae0e500e561b203529564104b3fd101
Tags:elfuser-abuse_ch
Infos:

Detection

Mirai, Okiru
Score:84
Range:0 - 100
Whitelisted:false

Signatures

Antivirus / Scanner detection for submitted sample
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Yara detected Mirai
Yara detected Okiru
Sample deletes itself
Detected TCP or UDP traffic on non-standard ports
Sample has stripped symbol table
Sample listens on a socket
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Uses the "uname" system call to query kernel version information (possible evasion)
Yara signature match

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1546748
Start date and time:2024-11-01 15:18:09 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 45s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:zmap.arm.elf
Detection:MAL
Classification:mal84.troj.evad.linELF@0/0@13/0
  • VT rate limit hit for: zmap.arm.elf
Command:/tmp/zmap.arm.elf
PID:6264
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
VagneRHere
Standard Error:
  • system is lnxubuntu20
  • zmap.arm.elf (PID: 6264, Parent: 6176, MD5: 5ebfcae4fe2471fcc5695c2394773ff1) Arguments: /tmp/zmap.arm.elf
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
MiraiMirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese. Nowadays it targets a wide range of networked embedded devices such as IP cameras, home routers (many vendors involved), and other IoT devices. Since the source code was published on "Hack Forums" many variants of the Mirai family appeared, infecting mostly home networks all around the world.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/elf.mirai
SourceRuleDescriptionAuthorStrings
zmap.arm.elfJoeSecurity_OkiruYara detected OkiruJoe Security
    zmap.arm.elfJoeSecurity_Mirai_8Yara detected MiraiJoe Security
      zmap.arm.elfLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
      • 0x10258:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x1026c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x10280:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x10294:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x102a8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x102bc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x102d0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x102e4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x102f8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x1030c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x10320:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x10334:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x10348:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x1035c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x10370:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x10384:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x10398:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x103ac:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x103c0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x103d4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x103e8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      SourceRuleDescriptionAuthorStrings
      6268.1.00007ff4fc017000.00007ff4fc02a000.r-x.sdmpJoeSecurity_OkiruYara detected OkiruJoe Security
        6268.1.00007ff4fc017000.00007ff4fc02a000.r-x.sdmpJoeSecurity_Mirai_8Yara detected MiraiJoe Security
          6268.1.00007ff4fc017000.00007ff4fc02a000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
          • 0x10258:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x1026c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x10280:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x10294:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x102a8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x102bc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x102d0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x102e4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x102f8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x1030c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x10320:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x10334:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x10348:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x1035c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x10370:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x10384:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x10398:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x103ac:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x103c0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x103d4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x103e8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          6264.1.00007ff4fc017000.00007ff4fc02a000.r-x.sdmpJoeSecurity_OkiruYara detected OkiruJoe Security
            6264.1.00007ff4fc017000.00007ff4fc02a000.r-x.sdmpJoeSecurity_Mirai_8Yara detected MiraiJoe Security
              Click to see the 7 entries
              No Suricata rule has matched

              Click to jump to signature section

              Show All Signature Results

              AV Detection

              barindex
              Source: zmap.arm.elfAvira: detected
              Source: zmap.arm.elfReversingLabs: Detection: 63%
              Source: global trafficTCP traffic: 192.168.2.23:35784 -> 154.216.16.38:59962
              Source: /tmp/zmap.arm.elf (PID: 6264)Socket: 127.0.0.1:39148Jump to behavior
              Source: global trafficTCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
              Source: global trafficTCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
              Source: global trafficTCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
              Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
              Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
              Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
              Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
              Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
              Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
              Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
              Source: global trafficDNS traffic detected: DNS query: server.dico-inside.com
              Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443

              System Summary

              barindex
              Source: zmap.arm.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
              Source: 6268.1.00007ff4fc017000.00007ff4fc02a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
              Source: 6264.1.00007ff4fc017000.00007ff4fc02a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
              Source: Process Memory Space: zmap.arm.elf PID: 6264, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
              Source: Process Memory Space: zmap.arm.elf PID: 6268, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
              Source: ELF static info symbol of initial sample.symtab present: no
              Source: zmap.arm.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
              Source: 6268.1.00007ff4fc017000.00007ff4fc02a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
              Source: 6264.1.00007ff4fc017000.00007ff4fc02a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
              Source: Process Memory Space: zmap.arm.elf PID: 6264, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
              Source: Process Memory Space: zmap.arm.elf PID: 6268, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
              Source: classification engineClassification label: mal84.troj.evad.linELF@0/0@13/0

              Hooking and other Techniques for Hiding and Protection

              barindex
              Source: /tmp/zmap.arm.elf (PID: 6264)File: /tmp/zmap.arm.elfJump to behavior
              Source: /tmp/zmap.arm.elf (PID: 6264)Queries kernel information via 'uname': Jump to behavior
              Source: zmap.arm.elf, 6264.1.00007fff6b845000.00007fff6b866000.rw-.sdmp, zmap.arm.elf, 6268.1.00007fff6b845000.00007fff6b866000.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-arm/tmp/zmap.arm.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/zmap.arm.elf
              Source: zmap.arm.elf, 6264.1.000055ce039c4000.000055ce03af2000.rw-.sdmp, zmap.arm.elf, 6268.1.000055ce039c4000.000055ce03af2000.rw-.sdmpBinary or memory string: U!/etc/qemu-binfmt/arm
              Source: zmap.arm.elf, 6264.1.000055ce039c4000.000055ce03af2000.rw-.sdmp, zmap.arm.elf, 6268.1.000055ce039c4000.000055ce03af2000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/arm
              Source: zmap.arm.elf, 6264.1.00007fff6b845000.00007fff6b866000.rw-.sdmp, zmap.arm.elf, 6268.1.00007fff6b845000.00007fff6b866000.rw-.sdmpBinary or memory string: /usr/bin/qemu-arm

              Stealing of Sensitive Information

              barindex
              Source: Yara matchFile source: zmap.arm.elf, type: SAMPLE
              Source: Yara matchFile source: 6268.1.00007ff4fc017000.00007ff4fc02a000.r-x.sdmp, type: MEMORY
              Source: Yara matchFile source: 6264.1.00007ff4fc017000.00007ff4fc02a000.r-x.sdmp, type: MEMORY
              Source: Yara matchFile source: Process Memory Space: zmap.arm.elf PID: 6264, type: MEMORYSTR
              Source: Yara matchFile source: Process Memory Space: zmap.arm.elf PID: 6268, type: MEMORYSTR
              Source: Yara matchFile source: zmap.arm.elf, type: SAMPLE
              Source: Yara matchFile source: 6268.1.00007ff4fc017000.00007ff4fc02a000.r-x.sdmp, type: MEMORY
              Source: Yara matchFile source: 6264.1.00007ff4fc017000.00007ff4fc02a000.r-x.sdmp, type: MEMORY
              Source: Yara matchFile source: Process Memory Space: zmap.arm.elf PID: 6264, type: MEMORYSTR
              Source: Yara matchFile source: Process Memory Space: zmap.arm.elf PID: 6268, type: MEMORYSTR

              Remote Access Functionality

              barindex
              Source: Yara matchFile source: zmap.arm.elf, type: SAMPLE
              Source: Yara matchFile source: 6268.1.00007ff4fc017000.00007ff4fc02a000.r-x.sdmp, type: MEMORY
              Source: Yara matchFile source: 6264.1.00007ff4fc017000.00007ff4fc02a000.r-x.sdmp, type: MEMORY
              Source: Yara matchFile source: Process Memory Space: zmap.arm.elf PID: 6264, type: MEMORYSTR
              Source: Yara matchFile source: Process Memory Space: zmap.arm.elf PID: 6268, type: MEMORYSTR
              Source: Yara matchFile source: zmap.arm.elf, type: SAMPLE
              Source: Yara matchFile source: 6268.1.00007ff4fc017000.00007ff4fc02a000.r-x.sdmp, type: MEMORY
              Source: Yara matchFile source: 6264.1.00007ff4fc017000.00007ff4fc02a000.r-x.sdmp, type: MEMORY
              Source: Yara matchFile source: Process Memory Space: zmap.arm.elf PID: 6264, type: MEMORYSTR
              Source: Yara matchFile source: Process Memory Space: zmap.arm.elf PID: 6268, type: MEMORYSTR
              ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
              Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception1
              File Deletion
              OS Credential Dumping11
              Security Software Discovery
              Remote ServicesData from Local System1
              Encrypted Channel
              Exfiltration Over Other Network MediumAbuse Accessibility Features
              CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
              Non-Standard Port
              Exfiltration Over BluetoothNetwork Denial of Service
              Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
              Non-Application Layer Protocol
              Automated ExfiltrationData Encrypted for Impact
              Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture2
              Application Layer Protocol
              Traffic DuplicationData Destruction
              No configs have been found
              Hide Legend

              Legend:

              • Process
              • Signature
              • Created File
              • DNS/IP Info
              • Is Dropped
              • Number of created Files
              • Is malicious
              • Internet
              SourceDetectionScannerLabelLink
              zmap.arm.elf63%ReversingLabsLinux.Trojan.Mirai
              zmap.arm.elf100%AviraEXP/ELF.Mirai.Z.A
              No Antivirus matches
              No Antivirus matches
              No Antivirus matches
              NameIPActiveMaliciousAntivirus DetectionReputation
              server.dico-inside.com
              154.216.16.38
              truefalse
                unknown
                • No. of IPs < 25%
                • 25% < No. of IPs < 50%
                • 50% < No. of IPs < 75%
                • 75% < No. of IPs
                IPDomainCountryFlagASNASN NameMalicious
                109.202.202.202
                unknownSwitzerland
                13030INIT7CHfalse
                154.216.16.38
                server.dico-inside.comSeychelles
                135357SKHT-ASShenzhenKatherineHengTechnologyInformationCofalse
                91.189.91.43
                unknownUnited Kingdom
                41231CANONICAL-ASGBfalse
                91.189.91.42
                unknownUnited Kingdom
                41231CANONICAL-ASGBfalse
                MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                109.202.202.202kpLwzBouH4.elfGet hashmaliciousUnknownBrowse
                • ch.archive.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_92.0%2bbuild3-0ubuntu0.20.04.1_amd64.deb
                154.216.16.38zmap.spc.elfGet hashmaliciousMirai, OkiruBrowse
                  zmap.sh4.elfGet hashmaliciousMirai, OkiruBrowse
                    zmap.ppc.elfGet hashmaliciousMirai, OkiruBrowse
                      zmap.arm7.elfGet hashmaliciousMirai, OkiruBrowse
                        zmap.x86.elfGet hashmaliciousOkiruBrowse
                          91.189.91.43zmap.sh4.elfGet hashmaliciousMirai, OkiruBrowse
                            zmap.arm6.elfGet hashmaliciousMirai, OkiruBrowse
                              main_ppc.elfGet hashmaliciousMiraiBrowse
                                main_m68k.elfGet hashmaliciousMiraiBrowse
                                  dlr.mpsl.elfGet hashmaliciousOkiruBrowse
                                    .i.elfGet hashmaliciousUnknownBrowse
                                      harm5.elfGet hashmaliciousUnknownBrowse
                                        boatnet.spc.elfGet hashmaliciousMiraiBrowse
                                          boatnet.mips.elfGet hashmaliciousMiraiBrowse
                                            boatnet.arm6.elfGet hashmaliciousMiraiBrowse
                                              MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                              server.dico-inside.comzmap.spc.elfGet hashmaliciousMirai, OkiruBrowse
                                              • 154.216.16.38
                                              zmap.sh4.elfGet hashmaliciousMirai, OkiruBrowse
                                              • 154.216.16.38
                                              zmap.ppc.elfGet hashmaliciousMirai, OkiruBrowse
                                              • 154.216.16.38
                                              zmap.arm7.elfGet hashmaliciousMirai, OkiruBrowse
                                              • 154.216.16.38
                                              zmap.x86.elfGet hashmaliciousOkiruBrowse
                                              • 154.216.16.38
                                              MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                              CANONICAL-ASGBzmap.spc.elfGet hashmaliciousMirai, OkiruBrowse
                                              • 185.125.190.26
                                              zmap.sh4.elfGet hashmaliciousMirai, OkiruBrowse
                                              • 91.189.91.42
                                              zmap.arm7.elfGet hashmaliciousMirai, OkiruBrowse
                                              • 185.125.190.26
                                              zmap.arm6.elfGet hashmaliciousMirai, OkiruBrowse
                                              • 91.189.91.42
                                              main_ppc.elfGet hashmaliciousMiraiBrowse
                                              • 91.189.91.42
                                              main_m68k.elfGet hashmaliciousMiraiBrowse
                                              • 91.189.91.42
                                              zmap.x86_64.elfGet hashmaliciousOkiruBrowse
                                              • 185.125.190.26
                                              dlr.mpsl.elfGet hashmaliciousOkiruBrowse
                                              • 91.189.91.42
                                              .i.elfGet hashmaliciousUnknownBrowse
                                              • 91.189.91.42
                                              harm5.elfGet hashmaliciousUnknownBrowse
                                              • 91.189.91.42
                                              SKHT-ASShenzhenKatherineHengTechnologyInformationCozmap.spc.elfGet hashmaliciousMirai, OkiruBrowse
                                              • 154.216.16.38
                                              zmap.sh4.elfGet hashmaliciousMirai, OkiruBrowse
                                              • 154.216.16.38
                                              zmap.ppc.elfGet hashmaliciousMirai, OkiruBrowse
                                              • 154.216.16.38
                                              zmap.arm7.elfGet hashmaliciousMirai, OkiruBrowse
                                              • 154.216.16.38
                                              dlr.arm7.elfGet hashmaliciousMirai, OkiruBrowse
                                              • 154.216.16.39
                                              zmap.x86.elfGet hashmaliciousOkiruBrowse
                                              • 154.216.16.38
                                              dlr.mpsl.elfGet hashmaliciousOkiruBrowse
                                              • 154.216.16.39
                                              file.exeGet hashmaliciousLummaC, Amadey, Credential Flusher, LummaC Stealer, Stealc, XWormBrowse
                                              • 154.216.17.34
                                              file.exeGet hashmaliciousLummaC, Amadey, Credential Flusher, LummaC Stealer, Stealc, XmrigBrowse
                                              • 154.216.17.34
                                              x86.elfGet hashmaliciousMiraiBrowse
                                              • 156.241.11.55
                                              INIT7CHzmap.sh4.elfGet hashmaliciousMirai, OkiruBrowse
                                              • 109.202.202.202
                                              zmap.arm6.elfGet hashmaliciousMirai, OkiruBrowse
                                              • 109.202.202.202
                                              main_ppc.elfGet hashmaliciousMiraiBrowse
                                              • 109.202.202.202
                                              main_m68k.elfGet hashmaliciousMiraiBrowse
                                              • 109.202.202.202
                                              dlr.mpsl.elfGet hashmaliciousOkiruBrowse
                                              • 109.202.202.202
                                              .i.elfGet hashmaliciousUnknownBrowse
                                              • 109.202.202.202
                                              harm5.elfGet hashmaliciousUnknownBrowse
                                              • 109.202.202.202
                                              boatnet.spc.elfGet hashmaliciousMiraiBrowse
                                              • 109.202.202.202
                                              boatnet.mips.elfGet hashmaliciousMiraiBrowse
                                              • 109.202.202.202
                                              boatnet.arm6.elfGet hashmaliciousMiraiBrowse
                                              • 109.202.202.202
                                              No context
                                              No context
                                              No created / dropped files found
                                              File type:ELF 32-bit LSB executable, ARM, version 1 (ARM), statically linked, stripped
                                              Entropy (8bit):6.195553546452842
                                              TrID:
                                              • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                                              File name:zmap.arm.elf
                                              File size:75'856 bytes
                                              MD5:cdc46d2754ffaf581f0e011c4960332d
                                              SHA1:53657bd523faeea5d768a830412113fb46c39321
                                              SHA256:9f29e193d60134d76b92f383016a64f7eae0e500e561b203529564104b3fd101
                                              SHA512:77e58e1118b1418fb44b59b7c174d2f6d2fc0bea79d58f4e06c2e396ea367cca9343e71052b8f25517e9c191d1a4e52ba1a791e4c99444337b1d0e4dad1fcdbf
                                              SSDEEP:1536:ExfayMskaJ9CgsYFIAXmgEqScyXignvvn:ExgIIA2gEskFvn
                                              TLSH:B2733946B8815A13C6E1127BFAAE418D372523E8E3DF7217DE216F21379682F0D67E41
                                              File Content Preview:.ELF...a..........(.........4....&......4. ...(......................"..."..............."..."...".......'..........Q.td..................................-...L."...V@..........0@-.\P...0....S.0...P@...0... ....R......0...0...........0... ....R..... 0....S

                                              ELF header

                                              Class:ELF32
                                              Data:2's complement, little endian
                                              Version:1 (current)
                                              Machine:ARM
                                              Version Number:0x1
                                              Type:EXEC (Executable file)
                                              OS/ABI:ARM - ABI
                                              ABI Version:0
                                              Entry Point Address:0x8190
                                              Flags:0x202
                                              ELF Header Size:52
                                              Program Header Offset:52
                                              Program Header Size:32
                                              Number of Program Headers:3
                                              Section Header Offset:75456
                                              Section Header Size:40
                                              Number of Section Headers:10
                                              Header String Table Index:9
                                              NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                              NULL0x00x00x00x00x0000
                                              .initPROGBITS0x80940x940x180x00x6AX004
                                              .textPROGBITS0x80b00xb00x101900x00x6AX0016
                                              .finiPROGBITS0x182400x102400x140x00x6AX004
                                              .rodataPROGBITS0x182540x102540x20840x00x2A004
                                              .ctorsPROGBITS0x222dc0x122dc0x80x00x3WA004
                                              .dtorsPROGBITS0x222e40x122e40x80x00x3WA004
                                              .dataPROGBITS0x222f00x122f00x3900x00x3WA004
                                              .bssNOBITS0x226800x126800x24300x00x3WA004
                                              .shstrtabSTRTAB0x00x126800x3e0x00x0001
                                              TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                              LOAD0x00x80000x80000x122d80x122d86.22440x5R E0x8000.init .text .fini .rodata
                                              LOAD0x122dc0x222dc0x222dc0x3a40x27d43.06470x6RW 0x8000.ctors .dtors .data .bss
                                              GNU_STACK0x00x00x00x00x00.00000x7RWE0x4
                                              TimestampSource PortDest PortSource IPDest IP
                                              Nov 1, 2024 15:19:06.566318989 CET3578459962192.168.2.23154.216.16.38
                                              Nov 1, 2024 15:19:06.571737051 CET5996235784154.216.16.38192.168.2.23
                                              Nov 1, 2024 15:19:06.571800947 CET3578459962192.168.2.23154.216.16.38
                                              Nov 1, 2024 15:19:06.574706078 CET3578459962192.168.2.23154.216.16.38
                                              Nov 1, 2024 15:19:06.579629898 CET5996235784154.216.16.38192.168.2.23
                                              Nov 1, 2024 15:19:06.579689980 CET3578459962192.168.2.23154.216.16.38
                                              Nov 1, 2024 15:19:06.584709883 CET5996235784154.216.16.38192.168.2.23
                                              Nov 1, 2024 15:19:07.304742098 CET43928443192.168.2.2391.189.91.42
                                              Nov 1, 2024 15:19:07.448272943 CET5996235784154.216.16.38192.168.2.23
                                              Nov 1, 2024 15:19:07.448302984 CET5996235784154.216.16.38192.168.2.23
                                              Nov 1, 2024 15:19:07.448472977 CET3578459962192.168.2.23154.216.16.38
                                              Nov 1, 2024 15:19:07.448472977 CET3578459962192.168.2.23154.216.16.38
                                              Nov 1, 2024 15:19:07.448679924 CET3578459962192.168.2.23154.216.16.38
                                              Nov 1, 2024 15:19:07.475260019 CET3578659962192.168.2.23154.216.16.38
                                              Nov 1, 2024 15:19:07.480184078 CET5996235786154.216.16.38192.168.2.23
                                              Nov 1, 2024 15:19:07.480242014 CET3578659962192.168.2.23154.216.16.38
                                              Nov 1, 2024 15:19:07.488923073 CET3578659962192.168.2.23154.216.16.38
                                              Nov 1, 2024 15:19:07.493838072 CET5996235786154.216.16.38192.168.2.23
                                              Nov 1, 2024 15:19:07.493895054 CET3578659962192.168.2.23154.216.16.38
                                              Nov 1, 2024 15:19:07.498687983 CET5996235786154.216.16.38192.168.2.23
                                              Nov 1, 2024 15:19:08.350261927 CET5996235786154.216.16.38192.168.2.23
                                              Nov 1, 2024 15:19:08.350349903 CET5996235786154.216.16.38192.168.2.23
                                              Nov 1, 2024 15:19:08.350430012 CET3578659962192.168.2.23154.216.16.38
                                              Nov 1, 2024 15:19:08.350430012 CET3578659962192.168.2.23154.216.16.38
                                              Nov 1, 2024 15:19:08.350478888 CET3578659962192.168.2.23154.216.16.38
                                              Nov 1, 2024 15:19:08.363112926 CET3578859962192.168.2.23154.216.16.38
                                              Nov 1, 2024 15:19:08.370814085 CET5996235788154.216.16.38192.168.2.23
                                              Nov 1, 2024 15:19:08.370937109 CET3578859962192.168.2.23154.216.16.38
                                              Nov 1, 2024 15:19:08.371663094 CET3578859962192.168.2.23154.216.16.38
                                              Nov 1, 2024 15:19:08.376708031 CET5996235788154.216.16.38192.168.2.23
                                              Nov 1, 2024 15:19:08.376766920 CET3578859962192.168.2.23154.216.16.38
                                              Nov 1, 2024 15:19:08.381614923 CET5996235788154.216.16.38192.168.2.23
                                              Nov 1, 2024 15:19:09.237011909 CET5996235788154.216.16.38192.168.2.23
                                              Nov 1, 2024 15:19:09.237103939 CET5996235788154.216.16.38192.168.2.23
                                              Nov 1, 2024 15:19:09.237157106 CET3578859962192.168.2.23154.216.16.38
                                              Nov 1, 2024 15:19:09.237158060 CET3578859962192.168.2.23154.216.16.38
                                              Nov 1, 2024 15:19:09.237231970 CET3578859962192.168.2.23154.216.16.38
                                              Nov 1, 2024 15:19:09.245722055 CET3579059962192.168.2.23154.216.16.38
                                              Nov 1, 2024 15:19:09.250859022 CET5996235790154.216.16.38192.168.2.23
                                              Nov 1, 2024 15:19:09.250916004 CET3579059962192.168.2.23154.216.16.38
                                              Nov 1, 2024 15:19:09.251782894 CET3579059962192.168.2.23154.216.16.38
                                              Nov 1, 2024 15:19:09.256606102 CET5996235790154.216.16.38192.168.2.23
                                              Nov 1, 2024 15:19:09.256652117 CET3579059962192.168.2.23154.216.16.38
                                              Nov 1, 2024 15:19:09.261464119 CET5996235790154.216.16.38192.168.2.23
                                              Nov 1, 2024 15:19:10.119119883 CET5996235790154.216.16.38192.168.2.23
                                              Nov 1, 2024 15:19:10.119364977 CET3579059962192.168.2.23154.216.16.38
                                              Nov 1, 2024 15:19:10.119435072 CET3579059962192.168.2.23154.216.16.38
                                              Nov 1, 2024 15:19:10.131342888 CET3579259962192.168.2.23154.216.16.38
                                              Nov 1, 2024 15:19:10.138315916 CET5996235792154.216.16.38192.168.2.23
                                              Nov 1, 2024 15:19:10.138411999 CET3579259962192.168.2.23154.216.16.38
                                              Nov 1, 2024 15:19:10.139064074 CET3579259962192.168.2.23154.216.16.38
                                              Nov 1, 2024 15:19:10.144566059 CET5996235792154.216.16.38192.168.2.23
                                              Nov 1, 2024 15:19:10.144684076 CET3579259962192.168.2.23154.216.16.38
                                              Nov 1, 2024 15:19:10.150383949 CET5996235792154.216.16.38192.168.2.23
                                              Nov 1, 2024 15:19:11.005412102 CET5996235792154.216.16.38192.168.2.23
                                              Nov 1, 2024 15:19:11.005426884 CET5996235792154.216.16.38192.168.2.23
                                              Nov 1, 2024 15:19:11.005626917 CET3579259962192.168.2.23154.216.16.38
                                              Nov 1, 2024 15:19:11.005626917 CET3579259962192.168.2.23154.216.16.38
                                              Nov 1, 2024 15:19:11.005707026 CET3579259962192.168.2.23154.216.16.38
                                              Nov 1, 2024 15:19:11.006501913 CET5996235792154.216.16.38192.168.2.23
                                              Nov 1, 2024 15:19:11.006628036 CET3579259962192.168.2.23154.216.16.38
                                              Nov 1, 2024 15:19:11.015350103 CET3579459962192.168.2.23154.216.16.38
                                              Nov 1, 2024 15:19:11.020332098 CET5996235794154.216.16.38192.168.2.23
                                              Nov 1, 2024 15:19:11.020668983 CET3579459962192.168.2.23154.216.16.38
                                              Nov 1, 2024 15:19:11.021384001 CET3579459962192.168.2.23154.216.16.38
                                              Nov 1, 2024 15:19:11.027005911 CET5996235794154.216.16.38192.168.2.23
                                              Nov 1, 2024 15:19:11.027069092 CET3579459962192.168.2.23154.216.16.38
                                              Nov 1, 2024 15:19:11.031873941 CET5996235794154.216.16.38192.168.2.23
                                              Nov 1, 2024 15:19:11.891582966 CET5996235794154.216.16.38192.168.2.23
                                              Nov 1, 2024 15:19:11.891773939 CET3579459962192.168.2.23154.216.16.38
                                              Nov 1, 2024 15:19:11.891773939 CET3579459962192.168.2.23154.216.16.38
                                              Nov 1, 2024 15:19:11.900635004 CET3579659962192.168.2.23154.216.16.38
                                              Nov 1, 2024 15:19:11.905447006 CET5996235796154.216.16.38192.168.2.23
                                              Nov 1, 2024 15:19:11.905519009 CET3579659962192.168.2.23154.216.16.38
                                              Nov 1, 2024 15:19:11.906316042 CET3579659962192.168.2.23154.216.16.38
                                              Nov 1, 2024 15:19:11.911097050 CET5996235796154.216.16.38192.168.2.23
                                              Nov 1, 2024 15:19:11.911154032 CET3579659962192.168.2.23154.216.16.38
                                              Nov 1, 2024 15:19:11.911676884 CET4251680192.168.2.23109.202.202.202
                                              Nov 1, 2024 15:19:11.915952921 CET5996235796154.216.16.38192.168.2.23
                                              Nov 1, 2024 15:19:12.679646015 CET42836443192.168.2.2391.189.91.43
                                              Nov 1, 2024 15:19:12.781805038 CET5996235796154.216.16.38192.168.2.23
                                              Nov 1, 2024 15:19:12.781836987 CET5996235796154.216.16.38192.168.2.23
                                              Nov 1, 2024 15:19:12.781963110 CET3579659962192.168.2.23154.216.16.38
                                              Nov 1, 2024 15:19:12.781963110 CET3579659962192.168.2.23154.216.16.38
                                              Nov 1, 2024 15:19:12.781963110 CET3579659962192.168.2.23154.216.16.38
                                              Nov 1, 2024 15:19:12.791773081 CET3579859962192.168.2.23154.216.16.38
                                              Nov 1, 2024 15:19:12.798825026 CET5996235798154.216.16.38192.168.2.23
                                              Nov 1, 2024 15:19:12.798928976 CET3579859962192.168.2.23154.216.16.38
                                              Nov 1, 2024 15:19:12.799494982 CET3579859962192.168.2.23154.216.16.38
                                              Nov 1, 2024 15:19:12.804301023 CET5996235798154.216.16.38192.168.2.23
                                              Nov 1, 2024 15:19:12.804579020 CET3579859962192.168.2.23154.216.16.38
                                              Nov 1, 2024 15:19:12.810369015 CET5996235798154.216.16.38192.168.2.23
                                              Nov 1, 2024 15:19:14.066838026 CET5996235798154.216.16.38192.168.2.23
                                              Nov 1, 2024 15:19:14.067080975 CET3579859962192.168.2.23154.216.16.38
                                              Nov 1, 2024 15:19:14.067080975 CET3579859962192.168.2.23154.216.16.38
                                              Nov 1, 2024 15:19:14.076527119 CET3580059962192.168.2.23154.216.16.38
                                              Nov 1, 2024 15:19:14.081574917 CET5996235800154.216.16.38192.168.2.23
                                              Nov 1, 2024 15:19:14.081651926 CET3580059962192.168.2.23154.216.16.38
                                              Nov 1, 2024 15:19:14.082385063 CET3580059962192.168.2.23154.216.16.38
                                              Nov 1, 2024 15:19:14.087229967 CET5996235800154.216.16.38192.168.2.23
                                              Nov 1, 2024 15:19:14.087282896 CET3580059962192.168.2.23154.216.16.38
                                              Nov 1, 2024 15:19:14.092133999 CET5996235800154.216.16.38192.168.2.23
                                              Nov 1, 2024 15:19:14.953275919 CET5996235800154.216.16.38192.168.2.23
                                              Nov 1, 2024 15:19:14.953427076 CET3580059962192.168.2.23154.216.16.38
                                              Nov 1, 2024 15:19:14.953469992 CET3580059962192.168.2.23154.216.16.38
                                              Nov 1, 2024 15:19:14.962790966 CET3580259962192.168.2.23154.216.16.38
                                              Nov 1, 2024 15:19:14.968348980 CET5996235802154.216.16.38192.168.2.23
                                              Nov 1, 2024 15:19:14.968409061 CET3580259962192.168.2.23154.216.16.38
                                              Nov 1, 2024 15:19:14.969329119 CET3580259962192.168.2.23154.216.16.38
                                              Nov 1, 2024 15:19:14.974194050 CET5996235802154.216.16.38192.168.2.23
                                              Nov 1, 2024 15:19:14.974242926 CET3580259962192.168.2.23154.216.16.38
                                              Nov 1, 2024 15:19:14.979085922 CET5996235802154.216.16.38192.168.2.23
                                              Nov 1, 2024 15:19:15.839270115 CET5996235802154.216.16.38192.168.2.23
                                              Nov 1, 2024 15:19:15.839396000 CET5996235802154.216.16.38192.168.2.23
                                              Nov 1, 2024 15:19:15.839442968 CET3580259962192.168.2.23154.216.16.38
                                              Nov 1, 2024 15:19:15.839469910 CET3580259962192.168.2.23154.216.16.38
                                              Nov 1, 2024 15:19:15.839540005 CET3580259962192.168.2.23154.216.16.38
                                              Nov 1, 2024 15:19:15.848398924 CET3580459962192.168.2.23154.216.16.38
                                              Nov 1, 2024 15:19:15.853260994 CET5996235804154.216.16.38192.168.2.23
                                              Nov 1, 2024 15:19:15.853343010 CET3580459962192.168.2.23154.216.16.38
                                              Nov 1, 2024 15:19:15.854053020 CET3580459962192.168.2.23154.216.16.38
                                              Nov 1, 2024 15:19:15.858966112 CET5996235804154.216.16.38192.168.2.23
                                              Nov 1, 2024 15:19:15.859041929 CET3580459962192.168.2.23154.216.16.38
                                              Nov 1, 2024 15:19:15.863845110 CET5996235804154.216.16.38192.168.2.23
                                              Nov 1, 2024 15:19:16.732671976 CET5996235804154.216.16.38192.168.2.23
                                              Nov 1, 2024 15:19:16.732990980 CET3580459962192.168.2.23154.216.16.38
                                              Nov 1, 2024 15:19:16.733135939 CET3580459962192.168.2.23154.216.16.38
                                              Nov 1, 2024 15:19:16.742372036 CET3580659962192.168.2.23154.216.16.38
                                              Nov 1, 2024 15:19:16.747289896 CET5996235806154.216.16.38192.168.2.23
                                              Nov 1, 2024 15:19:16.747366905 CET3580659962192.168.2.23154.216.16.38
                                              Nov 1, 2024 15:19:16.748245001 CET3580659962192.168.2.23154.216.16.38
                                              Nov 1, 2024 15:19:16.753424883 CET5996235806154.216.16.38192.168.2.23
                                              Nov 1, 2024 15:19:16.753479004 CET3580659962192.168.2.23154.216.16.38
                                              Nov 1, 2024 15:19:16.758378029 CET5996235806154.216.16.38192.168.2.23
                                              Nov 1, 2024 15:19:17.808533907 CET5996235806154.216.16.38192.168.2.23
                                              Nov 1, 2024 15:19:17.808691978 CET3580659962192.168.2.23154.216.16.38
                                              Nov 1, 2024 15:19:17.808736086 CET3580659962192.168.2.23154.216.16.38
                                              Nov 1, 2024 15:19:18.068444014 CET5996235806154.216.16.38192.168.2.23
                                              Nov 1, 2024 15:19:18.068603992 CET3580659962192.168.2.23154.216.16.38
                                              Nov 1, 2024 15:19:18.069181919 CET5996235806154.216.16.38192.168.2.23
                                              Nov 1, 2024 15:19:18.069248915 CET3580659962192.168.2.23154.216.16.38
                                              Nov 1, 2024 15:19:18.097560883 CET3580859962192.168.2.23154.216.16.38
                                              Nov 1, 2024 15:19:18.102958918 CET5996235808154.216.16.38192.168.2.23
                                              Nov 1, 2024 15:19:18.103066921 CET3580859962192.168.2.23154.216.16.38
                                              Nov 1, 2024 15:19:18.106054068 CET3580859962192.168.2.23154.216.16.38
                                              Nov 1, 2024 15:19:18.111918926 CET5996235808154.216.16.38192.168.2.23
                                              Nov 1, 2024 15:19:18.112232924 CET3580859962192.168.2.23154.216.16.38
                                              Nov 1, 2024 15:19:18.117115974 CET5996235808154.216.16.38192.168.2.23
                                              Nov 1, 2024 15:19:27.525645018 CET43928443192.168.2.2391.189.91.42
                                              Nov 1, 2024 15:19:28.114965916 CET3580859962192.168.2.23154.216.16.38
                                              Nov 1, 2024 15:19:28.119828939 CET5996235808154.216.16.38192.168.2.23
                                              Nov 1, 2024 15:19:28.375909090 CET5996235808154.216.16.38192.168.2.23
                                              Nov 1, 2024 15:19:28.376036882 CET3580859962192.168.2.23154.216.16.38
                                              Nov 1, 2024 15:19:39.811902046 CET42836443192.168.2.2391.189.91.43
                                              Nov 1, 2024 15:19:41.859590054 CET4251680192.168.2.23109.202.202.202
                                              Nov 1, 2024 15:20:08.479943991 CET43928443192.168.2.2391.189.91.42
                                              Nov 1, 2024 15:20:28.419225931 CET3580859962192.168.2.23154.216.16.38
                                              Nov 1, 2024 15:20:28.424355984 CET5996235808154.216.16.38192.168.2.23
                                              Nov 1, 2024 15:20:28.680691957 CET5996235808154.216.16.38192.168.2.23
                                              Nov 1, 2024 15:20:28.681015015 CET3580859962192.168.2.23154.216.16.38
                                              TimestampSource PortDest PortSource IPDest IP
                                              Nov 1, 2024 15:19:06.555700064 CET5351753192.168.2.238.8.8.8
                                              Nov 1, 2024 15:19:06.563589096 CET53535178.8.8.8192.168.2.23
                                              Nov 1, 2024 15:19:07.467375994 CET5446553192.168.2.238.8.8.8
                                              Nov 1, 2024 15:19:07.474379063 CET53544658.8.8.8192.168.2.23
                                              Nov 1, 2024 15:19:08.351711988 CET4172653192.168.2.238.8.8.8
                                              Nov 1, 2024 15:19:08.362550974 CET53417268.8.8.8192.168.2.23
                                              Nov 1, 2024 15:19:09.238270044 CET4511653192.168.2.238.8.8.8
                                              Nov 1, 2024 15:19:09.245150089 CET53451168.8.8.8192.168.2.23
                                              Nov 1, 2024 15:19:10.120381117 CET5712353192.168.2.238.8.8.8
                                              Nov 1, 2024 15:19:10.130059004 CET53571238.8.8.8192.168.2.23
                                              Nov 1, 2024 15:19:11.007211924 CET5157153192.168.2.238.8.8.8
                                              Nov 1, 2024 15:19:11.014571905 CET53515718.8.8.8192.168.2.23
                                              Nov 1, 2024 15:19:11.892985106 CET5824753192.168.2.238.8.8.8
                                              Nov 1, 2024 15:19:11.900158882 CET53582478.8.8.8192.168.2.23
                                              Nov 1, 2024 15:19:12.782847881 CET5752553192.168.2.238.8.8.8
                                              Nov 1, 2024 15:19:12.791295052 CET53575258.8.8.8192.168.2.23
                                              Nov 1, 2024 15:19:14.067979097 CET5446353192.168.2.238.8.8.8
                                              Nov 1, 2024 15:19:14.076095104 CET53544638.8.8.8192.168.2.23
                                              Nov 1, 2024 15:19:14.954386950 CET5991053192.168.2.238.8.8.8
                                              Nov 1, 2024 15:19:14.962344885 CET53599108.8.8.8192.168.2.23
                                              Nov 1, 2024 15:19:15.840500116 CET4482153192.168.2.238.8.8.8
                                              Nov 1, 2024 15:19:15.847903013 CET53448218.8.8.8192.168.2.23
                                              Nov 1, 2024 15:19:16.734693050 CET4893253192.168.2.238.8.8.8
                                              Nov 1, 2024 15:19:16.741945982 CET53489328.8.8.8192.168.2.23
                                              Nov 1, 2024 15:19:17.810132027 CET4209753192.168.2.238.8.8.8
                                              Nov 1, 2024 15:19:18.096424103 CET53420978.8.8.8192.168.2.23
                                              TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                              Nov 1, 2024 15:19:06.555700064 CET192.168.2.238.8.8.80x9944Standard query (0)server.dico-inside.comA (IP address)IN (0x0001)false
                                              Nov 1, 2024 15:19:07.467375994 CET192.168.2.238.8.8.80x4041Standard query (0)server.dico-inside.comA (IP address)IN (0x0001)false
                                              Nov 1, 2024 15:19:08.351711988 CET192.168.2.238.8.8.80xbf94Standard query (0)server.dico-inside.comA (IP address)IN (0x0001)false
                                              Nov 1, 2024 15:19:09.238270044 CET192.168.2.238.8.8.80x98ddStandard query (0)server.dico-inside.comA (IP address)IN (0x0001)false
                                              Nov 1, 2024 15:19:10.120381117 CET192.168.2.238.8.8.80xa744Standard query (0)server.dico-inside.comA (IP address)IN (0x0001)false
                                              Nov 1, 2024 15:19:11.007211924 CET192.168.2.238.8.8.80x299eStandard query (0)server.dico-inside.comA (IP address)IN (0x0001)false
                                              Nov 1, 2024 15:19:11.892985106 CET192.168.2.238.8.8.80x21a6Standard query (0)server.dico-inside.comA (IP address)IN (0x0001)false
                                              Nov 1, 2024 15:19:12.782847881 CET192.168.2.238.8.8.80x8239Standard query (0)server.dico-inside.comA (IP address)IN (0x0001)false
                                              Nov 1, 2024 15:19:14.067979097 CET192.168.2.238.8.8.80x7293Standard query (0)server.dico-inside.comA (IP address)IN (0x0001)false
                                              Nov 1, 2024 15:19:14.954386950 CET192.168.2.238.8.8.80xe21eStandard query (0)server.dico-inside.comA (IP address)IN (0x0001)false
                                              Nov 1, 2024 15:19:15.840500116 CET192.168.2.238.8.8.80xfbe4Standard query (0)server.dico-inside.comA (IP address)IN (0x0001)false
                                              Nov 1, 2024 15:19:16.734693050 CET192.168.2.238.8.8.80x30e5Standard query (0)server.dico-inside.comA (IP address)IN (0x0001)false
                                              Nov 1, 2024 15:19:17.810132027 CET192.168.2.238.8.8.80x9cfcStandard query (0)server.dico-inside.comA (IP address)IN (0x0001)false
                                              TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                              Nov 1, 2024 15:19:06.563589096 CET8.8.8.8192.168.2.230x9944No error (0)server.dico-inside.com154.216.16.38A (IP address)IN (0x0001)false
                                              Nov 1, 2024 15:19:07.474379063 CET8.8.8.8192.168.2.230x4041No error (0)server.dico-inside.com154.216.16.38A (IP address)IN (0x0001)false
                                              Nov 1, 2024 15:19:08.362550974 CET8.8.8.8192.168.2.230xbf94No error (0)server.dico-inside.com154.216.16.38A (IP address)IN (0x0001)false
                                              Nov 1, 2024 15:19:09.245150089 CET8.8.8.8192.168.2.230x98ddNo error (0)server.dico-inside.com154.216.16.38A (IP address)IN (0x0001)false
                                              Nov 1, 2024 15:19:10.130059004 CET8.8.8.8192.168.2.230xa744No error (0)server.dico-inside.com154.216.16.38A (IP address)IN (0x0001)false
                                              Nov 1, 2024 15:19:11.014571905 CET8.8.8.8192.168.2.230x299eNo error (0)server.dico-inside.com154.216.16.38A (IP address)IN (0x0001)false
                                              Nov 1, 2024 15:19:11.900158882 CET8.8.8.8192.168.2.230x21a6No error (0)server.dico-inside.com154.216.16.38A (IP address)IN (0x0001)false
                                              Nov 1, 2024 15:19:12.791295052 CET8.8.8.8192.168.2.230x8239No error (0)server.dico-inside.com154.216.16.38A (IP address)IN (0x0001)false
                                              Nov 1, 2024 15:19:14.076095104 CET8.8.8.8192.168.2.230x7293No error (0)server.dico-inside.com154.216.16.38A (IP address)IN (0x0001)false
                                              Nov 1, 2024 15:19:14.962344885 CET8.8.8.8192.168.2.230xe21eNo error (0)server.dico-inside.com154.216.16.38A (IP address)IN (0x0001)false
                                              Nov 1, 2024 15:19:15.847903013 CET8.8.8.8192.168.2.230xfbe4No error (0)server.dico-inside.com154.216.16.38A (IP address)IN (0x0001)false
                                              Nov 1, 2024 15:19:16.741945982 CET8.8.8.8192.168.2.230x30e5No error (0)server.dico-inside.com154.216.16.38A (IP address)IN (0x0001)false
                                              Nov 1, 2024 15:19:18.096424103 CET8.8.8.8192.168.2.230x9cfcNo error (0)server.dico-inside.com154.216.16.38A (IP address)IN (0x0001)false

                                              System Behavior

                                              Start time (UTC):14:19:05
                                              Start date (UTC):01/11/2024
                                              Path:/tmp/zmap.arm.elf
                                              Arguments:/tmp/zmap.arm.elf
                                              File size:4956856 bytes
                                              MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                              Start time (UTC):14:19:05
                                              Start date (UTC):01/11/2024
                                              Path:/tmp/zmap.arm.elf
                                              Arguments:-
                                              File size:4956856 bytes
                                              MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                              Start time (UTC):14:19:05
                                              Start date (UTC):01/11/2024
                                              Path:/tmp/zmap.arm.elf
                                              Arguments:-
                                              File size:4956856 bytes
                                              MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1