Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
zmap.ppc.elf

Overview

General Information

Sample name:zmap.ppc.elf
Analysis ID:1547471
MD5:a4b7bd853b1e50fbab80670db90d5001
SHA1:97f916bc169a4055bde65416df97ef82bfb10f0b
SHA256:c7cb6b08de79a87bb7af358f1678a62333244452c2fcc5019a68584db7c7092b
Tags:elfuser-abuse_ch
Infos:

Detection

Mirai, Okiru
Score:84
Range:0 - 100
Whitelisted:false

Signatures

Antivirus / Scanner detection for submitted sample
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Yara detected Mirai
Yara detected Okiru
Sample deletes itself
Detected TCP or UDP traffic on non-standard ports
Sample has stripped symbol table
Sample listens on a socket
Uses the "uname" system call to query kernel version information (possible evasion)
Yara signature match

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1547471
Start date and time:2024-11-02 15:37:10 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 29s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:zmap.ppc.elf
Detection:MAL
Classification:mal84.troj.evad.linELF@0/0@17/0
  • VT rate limit hit for: zmap.ppc.elf
Command:/tmp/zmap.ppc.elf
PID:5437
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
VagneRHere
Standard Error:
  • system is lnxubuntu20
  • zmap.ppc.elf (PID: 5437, Parent: 5359, MD5: ae65271c943d3451b7f026d1fadccea6) Arguments: /tmp/zmap.ppc.elf
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
MiraiMirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese. Nowadays it targets a wide range of networked embedded devices such as IP cameras, home routers (many vendors involved), and other IoT devices. Since the source code was published on "Hack Forums" many variants of the Mirai family appeared, infecting mostly home networks all around the world.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/elf.mirai
SourceRuleDescriptionAuthorStrings
zmap.ppc.elfJoeSecurity_OkiruYara detected OkiruJoe Security
    zmap.ppc.elfJoeSecurity_Mirai_8Yara detected MiraiJoe Security
      zmap.ppc.elfLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
      • 0xeca4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xecb8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xeccc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xece0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xecf4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xed08:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xed1c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xed30:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xed44:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xed58:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xed6c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xed80:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xed94:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xeda8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xedbc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xedd0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xede4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xedf8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xee0c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xee20:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xee34:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      SourceRuleDescriptionAuthorStrings
      5441.1.00007f0d84001000.00007f0d84012000.r-x.sdmpJoeSecurity_OkiruYara detected OkiruJoe Security
        5441.1.00007f0d84001000.00007f0d84012000.r-x.sdmpJoeSecurity_Mirai_8Yara detected MiraiJoe Security
          5441.1.00007f0d84001000.00007f0d84012000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
          • 0xeca4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xecb8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xeccc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xece0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xecf4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xed08:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xed1c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xed30:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xed44:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xed58:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xed6c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xed80:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xed94:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xeda8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xedbc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xedd0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xede4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xedf8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xee0c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xee20:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xee34:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          5437.1.00007f0d84001000.00007f0d84012000.r-x.sdmpJoeSecurity_OkiruYara detected OkiruJoe Security
            5437.1.00007f0d84001000.00007f0d84012000.r-x.sdmpJoeSecurity_Mirai_8Yara detected MiraiJoe Security
              Click to see the 7 entries
              No Suricata rule has matched

              Click to jump to signature section

              Show All Signature Results

              AV Detection

              barindex
              Source: zmap.ppc.elfAvira: detected
              Source: zmap.ppc.elfReversingLabs: Detection: 57%
              Source: global trafficTCP traffic: 192.168.2.13:55700 -> 154.216.16.38:59962
              Source: /tmp/zmap.ppc.elf (PID: 5437)Socket: 127.0.0.1:39148Jump to behavior
              Source: global trafficDNS traffic detected: DNS query: server.myway-ing.win

              System Summary

              barindex
              Source: zmap.ppc.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
              Source: 5441.1.00007f0d84001000.00007f0d84012000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
              Source: 5437.1.00007f0d84001000.00007f0d84012000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
              Source: Process Memory Space: zmap.ppc.elf PID: 5437, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
              Source: Process Memory Space: zmap.ppc.elf PID: 5441, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
              Source: ELF static info symbol of initial sample.symtab present: no
              Source: zmap.ppc.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
              Source: 5441.1.00007f0d84001000.00007f0d84012000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
              Source: 5437.1.00007f0d84001000.00007f0d84012000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
              Source: Process Memory Space: zmap.ppc.elf PID: 5437, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
              Source: Process Memory Space: zmap.ppc.elf PID: 5441, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
              Source: classification engineClassification label: mal84.troj.evad.linELF@0/0@17/0

              Hooking and other Techniques for Hiding and Protection

              barindex
              Source: /tmp/zmap.ppc.elf (PID: 5437)File: /tmp/zmap.ppc.elfJump to behavior
              Source: /tmp/zmap.ppc.elf (PID: 5437)Queries kernel information via 'uname': Jump to behavior
              Source: zmap.ppc.elf, 5437.1.0000560a89922000.0000560a899d2000.rw-.sdmpBinary or memory string: !/etc/qemu-binfmt/ppc11!hotpluggableq
              Source: zmap.ppc.elf, 5441.1.0000560a89922000.0000560a899d2000.rw-.sdmpBinary or memory string: !/etc/qemu-binfmt/ppc1
              Source: zmap.ppc.elf, 5437.1.0000560a89922000.0000560a899d2000.rw-.sdmp, zmap.ppc.elf, 5441.1.0000560a89922000.0000560a899d2000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/ppc
              Source: zmap.ppc.elf, 5437.1.00007ffecdfcd000.00007ffecdfee000.rw-.sdmp, zmap.ppc.elf, 5441.1.00007ffecdfcd000.00007ffecdfee000.rw-.sdmpBinary or memory string: /usr/bin/qemu-ppc
              Source: zmap.ppc.elf, 5437.1.00007ffecdfcd000.00007ffecdfee000.rw-.sdmp, zmap.ppc.elf, 5441.1.00007ffecdfcd000.00007ffecdfee000.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-ppc/tmp/zmap.ppc.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/zmap.ppc.elf

              Stealing of Sensitive Information

              barindex
              Source: Yara matchFile source: zmap.ppc.elf, type: SAMPLE
              Source: Yara matchFile source: 5441.1.00007f0d84001000.00007f0d84012000.r-x.sdmp, type: MEMORY
              Source: Yara matchFile source: 5437.1.00007f0d84001000.00007f0d84012000.r-x.sdmp, type: MEMORY
              Source: Yara matchFile source: Process Memory Space: zmap.ppc.elf PID: 5437, type: MEMORYSTR
              Source: Yara matchFile source: Process Memory Space: zmap.ppc.elf PID: 5441, type: MEMORYSTR
              Source: Yara matchFile source: zmap.ppc.elf, type: SAMPLE
              Source: Yara matchFile source: 5441.1.00007f0d84001000.00007f0d84012000.r-x.sdmp, type: MEMORY
              Source: Yara matchFile source: 5437.1.00007f0d84001000.00007f0d84012000.r-x.sdmp, type: MEMORY
              Source: Yara matchFile source: Process Memory Space: zmap.ppc.elf PID: 5437, type: MEMORYSTR
              Source: Yara matchFile source: Process Memory Space: zmap.ppc.elf PID: 5441, type: MEMORYSTR

              Remote Access Functionality

              barindex
              Source: Yara matchFile source: zmap.ppc.elf, type: SAMPLE
              Source: Yara matchFile source: 5441.1.00007f0d84001000.00007f0d84012000.r-x.sdmp, type: MEMORY
              Source: Yara matchFile source: 5437.1.00007f0d84001000.00007f0d84012000.r-x.sdmp, type: MEMORY
              Source: Yara matchFile source: Process Memory Space: zmap.ppc.elf PID: 5437, type: MEMORYSTR
              Source: Yara matchFile source: Process Memory Space: zmap.ppc.elf PID: 5441, type: MEMORYSTR
              Source: Yara matchFile source: zmap.ppc.elf, type: SAMPLE
              Source: Yara matchFile source: 5441.1.00007f0d84001000.00007f0d84012000.r-x.sdmp, type: MEMORY
              Source: Yara matchFile source: 5437.1.00007f0d84001000.00007f0d84012000.r-x.sdmp, type: MEMORY
              Source: Yara matchFile source: Process Memory Space: zmap.ppc.elf PID: 5437, type: MEMORYSTR
              Source: Yara matchFile source: Process Memory Space: zmap.ppc.elf PID: 5441, type: MEMORYSTR
              ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
              Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception1
              File Deletion
              OS Credential Dumping11
              Security Software Discovery
              Remote ServicesData from Local System1
              Non-Standard Port
              Exfiltration Over Other Network MediumAbuse Accessibility Features
              CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
              Non-Application Layer Protocol
              Exfiltration Over BluetoothNetwork Denial of Service
              Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
              Application Layer Protocol
              Automated ExfiltrationData Encrypted for Impact
              No configs have been found
              Hide Legend

              Legend:

              • Process
              • Signature
              • Created File
              • DNS/IP Info
              • Is Dropped
              • Number of created Files
              • Is malicious
              • Internet
              SourceDetectionScannerLabelLink
              zmap.ppc.elf58%ReversingLabsLinux.Trojan.Mirai
              zmap.ppc.elf100%AviraEXP/ELF.Mirai.Z.A
              No Antivirus matches
              No Antivirus matches
              No Antivirus matches
              NameIPActiveMaliciousAntivirus DetectionReputation
              server.myway-ing.win
              154.216.16.38
              truefalse
                unknown
                • No. of IPs < 25%
                • 25% < No. of IPs < 50%
                • 50% < No. of IPs < 75%
                • 75% < No. of IPs
                IPDomainCountryFlagASNASN NameMalicious
                154.216.16.38
                server.myway-ing.winSeychelles
                135357SKHT-ASShenzhenKatherineHengTechnologyInformationCofalse
                MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                154.216.16.38zmap.mips.elfGet hashmaliciousMirai, OkiruBrowse
                  zmap.x86.elfGet hashmaliciousOkiruBrowse
                    zmap.mpsl.elfGet hashmaliciousMirai, OkiruBrowse
                      debug.dbg.elfGet hashmaliciousMirai, OkiruBrowse
                        zmap.m68k.elfGet hashmaliciousMirai, OkiruBrowse
                          zmap.mpsl.elfGet hashmaliciousMirai, OkiruBrowse
                            zmap.mips.elfGet hashmaliciousMirai, OkiruBrowse
                              zmap.arm.elfGet hashmaliciousMirai, OkiruBrowse
                                zmap.spc.elfGet hashmaliciousMirai, OkiruBrowse
                                  zmap.sh4.elfGet hashmaliciousMirai, OkiruBrowse
                                    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                    server.myway-ing.winzmap.mips.elfGet hashmaliciousMirai, OkiruBrowse
                                    • 154.216.16.38
                                    zmap.x86.elfGet hashmaliciousOkiruBrowse
                                    • 154.216.16.38
                                    zmap.mpsl.elfGet hashmaliciousMirai, OkiruBrowse
                                    • 154.216.16.38
                                    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                    SKHT-ASShenzhenKatherineHengTechnologyInformationCozmap.mips.elfGet hashmaliciousMirai, OkiruBrowse
                                    • 154.216.16.38
                                    zmap.x86.elfGet hashmaliciousOkiruBrowse
                                    • 154.216.16.38
                                    zmap.mpsl.elfGet hashmaliciousMirai, OkiruBrowse
                                    • 154.216.16.38
                                    qkehusl.elfGet hashmaliciousMiraiBrowse
                                    • 154.216.19.76
                                    jwwofba5.elfGet hashmaliciousMiraiBrowse
                                    • 154.216.19.76
                                    wheiuwa4.elfGet hashmaliciousMiraiBrowse
                                    • 154.216.19.76
                                    dvwkja7.elfGet hashmaliciousMiraiBrowse
                                    • 154.216.19.76
                                    vsbeps.elfGet hashmaliciousMiraiBrowse
                                    • 154.216.19.76
                                    qkbfi86.elfGet hashmaliciousMiraiBrowse
                                    • 154.216.19.76
                                    boatnet.m68k.elfGet hashmaliciousMiraiBrowse
                                    • 154.216.19.64
                                    No context
                                    No context
                                    No created / dropped files found
                                    File type:ELF 32-bit MSB executable, PowerPC or cisco 4500, version 1 (SYSV), statically linked, stripped
                                    Entropy (8bit):6.288154789993549
                                    TrID:
                                    • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                                    File name:zmap.ppc.elf
                                    File size:71'128 bytes
                                    MD5:a4b7bd853b1e50fbab80670db90d5001
                                    SHA1:97f916bc169a4055bde65416df97ef82bfb10f0b
                                    SHA256:c7cb6b08de79a87bb7af358f1678a62333244452c2fcc5019a68584db7c7092b
                                    SHA512:243258e2a34e52e0488a91beb40e7a8b0d9bac29e9734dec23f718c5a079dadb600cdc10083edb1d90c3d2bdf2edfda17d514132b1425a020ccacbdc545e05a4
                                    SSDEEP:1536:mbxeCDlX+i4eRxH2ObELk0g439pdMGk6Mx:ODlOqHZlqpSG5Mx
                                    TLSH:30634B02B3180D07C5A359B0253F5BE0D7FEE9D022E0B689291F9BAA4A71E775185FCD
                                    File Content Preview:.ELF...........................4.........4. ...(.......................P...P..............................'x........dt.Q.............................!..|......$H...H..q...$8!. |...N.. .!..|.......?.............../...@..\?........+../...A..$8...})......N..

                                    ELF header

                                    Class:ELF32
                                    Data:2's complement, big endian
                                    Version:1 (current)
                                    Machine:PowerPC
                                    Version Number:0x1
                                    Type:EXEC (Executable file)
                                    OS/ABI:UNIX - System V
                                    ABI Version:0
                                    Entry Point Address:0x100001f0
                                    Flags:0x0
                                    ELF Header Size:52
                                    Program Header Offset:52
                                    Program Header Size:32
                                    Number of Program Headers:3
                                    Section Header Offset:70648
                                    Section Header Size:40
                                    Number of Section Headers:12
                                    Header String Table Index:11
                                    NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                    NULL0x00x00x00x00x0000
                                    .initPROGBITS0x100000940x940x240x00x6AX004
                                    .textPROGBITS0x100000b80xb80xebc80x00x6AX004
                                    .finiPROGBITS0x1000ec800xec800x200x00x6AX004
                                    .rodataPROGBITS0x1000eca00xeca00x20b00x00x2A008
                                    .ctorsPROGBITS0x100210000x110000x80x00x3WA004
                                    .dtorsPROGBITS0x100210080x110080x80x00x3WA004
                                    .dataPROGBITS0x100210180x110180x3540x00x3WA008
                                    .sdataPROGBITS0x1002136c0x1136c0x400x00x3WA004
                                    .sbssNOBITS0x100213ac0x113ac0x600x00x3WA004
                                    .bssNOBITS0x1002140c0x113ac0x236c0x00x3WA004
                                    .shstrtabSTRTAB0x00x113ac0x4b0x00x0001
                                    TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                    LOAD0x00x100000000x100000000x10d500x10d506.37060x5R E0x10000.init .text .fini .rodata
                                    LOAD0x110000x100210000x100210000x3ac0x27783.18990x6RW 0x10000.ctors .dtors .data .sdata .sbss .bss
                                    GNU_STACK0x00x00x00x00x00.00000x6RW 0x4
                                    TimestampSource PortDest PortSource IPDest IP
                                    Nov 2, 2024 15:38:02.702202082 CET5570059962192.168.2.13154.216.16.38
                                    Nov 2, 2024 15:38:02.707101107 CET5996255700154.216.16.38192.168.2.13
                                    Nov 2, 2024 15:38:02.707163095 CET5570059962192.168.2.13154.216.16.38
                                    Nov 2, 2024 15:38:02.720802069 CET5570059962192.168.2.13154.216.16.38
                                    Nov 2, 2024 15:38:02.725728989 CET5996255700154.216.16.38192.168.2.13
                                    Nov 2, 2024 15:38:02.725789070 CET5570059962192.168.2.13154.216.16.38
                                    Nov 2, 2024 15:38:02.730665922 CET5996255700154.216.16.38192.168.2.13
                                    Nov 2, 2024 15:38:03.617085934 CET5996255700154.216.16.38192.168.2.13
                                    Nov 2, 2024 15:38:03.617100000 CET5996255700154.216.16.38192.168.2.13
                                    Nov 2, 2024 15:38:03.617218018 CET5570059962192.168.2.13154.216.16.38
                                    Nov 2, 2024 15:38:03.617218971 CET5570059962192.168.2.13154.216.16.38
                                    Nov 2, 2024 15:38:03.617383957 CET5570059962192.168.2.13154.216.16.38
                                    Nov 2, 2024 15:38:03.627564907 CET5570259962192.168.2.13154.216.16.38
                                    Nov 2, 2024 15:38:03.632872105 CET5996255702154.216.16.38192.168.2.13
                                    Nov 2, 2024 15:38:03.632958889 CET5570259962192.168.2.13154.216.16.38
                                    Nov 2, 2024 15:38:03.633846045 CET5570259962192.168.2.13154.216.16.38
                                    Nov 2, 2024 15:38:03.638777018 CET5996255702154.216.16.38192.168.2.13
                                    Nov 2, 2024 15:38:03.638855934 CET5570259962192.168.2.13154.216.16.38
                                    Nov 2, 2024 15:38:03.643691063 CET5996255702154.216.16.38192.168.2.13
                                    Nov 2, 2024 15:38:04.729603052 CET5996255702154.216.16.38192.168.2.13
                                    Nov 2, 2024 15:38:04.729736090 CET5570259962192.168.2.13154.216.16.38
                                    Nov 2, 2024 15:38:04.729736090 CET5570259962192.168.2.13154.216.16.38
                                    Nov 2, 2024 15:38:04.732223034 CET5996255702154.216.16.38192.168.2.13
                                    Nov 2, 2024 15:38:04.732281923 CET5570259962192.168.2.13154.216.16.38
                                    Nov 2, 2024 15:38:04.737696886 CET5570459962192.168.2.13154.216.16.38
                                    Nov 2, 2024 15:38:04.742551088 CET5996255704154.216.16.38192.168.2.13
                                    Nov 2, 2024 15:38:04.742609978 CET5570459962192.168.2.13154.216.16.38
                                    Nov 2, 2024 15:38:04.743344069 CET5570459962192.168.2.13154.216.16.38
                                    Nov 2, 2024 15:38:04.748080969 CET5996255704154.216.16.38192.168.2.13
                                    Nov 2, 2024 15:38:04.748141050 CET5570459962192.168.2.13154.216.16.38
                                    Nov 2, 2024 15:38:04.753041029 CET5996255704154.216.16.38192.168.2.13
                                    Nov 2, 2024 15:38:05.641280890 CET5996255704154.216.16.38192.168.2.13
                                    Nov 2, 2024 15:38:05.641303062 CET5996255704154.216.16.38192.168.2.13
                                    Nov 2, 2024 15:38:05.641442060 CET5570459962192.168.2.13154.216.16.38
                                    Nov 2, 2024 15:38:05.641442060 CET5570459962192.168.2.13154.216.16.38
                                    Nov 2, 2024 15:38:05.641529083 CET5570459962192.168.2.13154.216.16.38
                                    Nov 2, 2024 15:38:05.649770021 CET5570659962192.168.2.13154.216.16.38
                                    Nov 2, 2024 15:38:05.654620886 CET5996255706154.216.16.38192.168.2.13
                                    Nov 2, 2024 15:38:05.654706001 CET5570659962192.168.2.13154.216.16.38
                                    Nov 2, 2024 15:38:05.655375004 CET5570659962192.168.2.13154.216.16.38
                                    Nov 2, 2024 15:38:05.660219908 CET5996255706154.216.16.38192.168.2.13
                                    Nov 2, 2024 15:38:05.660267115 CET5570659962192.168.2.13154.216.16.38
                                    Nov 2, 2024 15:38:05.665066004 CET5996255706154.216.16.38192.168.2.13
                                    Nov 2, 2024 15:38:06.565112114 CET5996255706154.216.16.38192.168.2.13
                                    Nov 2, 2024 15:38:06.565138102 CET5996255706154.216.16.38192.168.2.13
                                    Nov 2, 2024 15:38:06.565365076 CET5570659962192.168.2.13154.216.16.38
                                    Nov 2, 2024 15:38:06.565365076 CET5570659962192.168.2.13154.216.16.38
                                    Nov 2, 2024 15:38:06.565365076 CET5570659962192.168.2.13154.216.16.38
                                    Nov 2, 2024 15:38:06.573749065 CET5570859962192.168.2.13154.216.16.38
                                    Nov 2, 2024 15:38:06.578668118 CET5996255708154.216.16.38192.168.2.13
                                    Nov 2, 2024 15:38:06.578739882 CET5570859962192.168.2.13154.216.16.38
                                    Nov 2, 2024 15:38:06.579428911 CET5570859962192.168.2.13154.216.16.38
                                    Nov 2, 2024 15:38:06.584233046 CET5996255708154.216.16.38192.168.2.13
                                    Nov 2, 2024 15:38:06.584281921 CET5570859962192.168.2.13154.216.16.38
                                    Nov 2, 2024 15:38:06.589096069 CET5996255708154.216.16.38192.168.2.13
                                    Nov 2, 2024 15:38:07.484213114 CET5996255708154.216.16.38192.168.2.13
                                    Nov 2, 2024 15:38:07.484464884 CET5570859962192.168.2.13154.216.16.38
                                    Nov 2, 2024 15:38:07.484464884 CET5570859962192.168.2.13154.216.16.38
                                    Nov 2, 2024 15:38:07.493171930 CET5571059962192.168.2.13154.216.16.38
                                    Nov 2, 2024 15:38:07.498002052 CET5996255710154.216.16.38192.168.2.13
                                    Nov 2, 2024 15:38:07.498054028 CET5571059962192.168.2.13154.216.16.38
                                    Nov 2, 2024 15:38:07.498665094 CET5571059962192.168.2.13154.216.16.38
                                    Nov 2, 2024 15:38:07.503520966 CET5996255710154.216.16.38192.168.2.13
                                    Nov 2, 2024 15:38:07.503585100 CET5571059962192.168.2.13154.216.16.38
                                    Nov 2, 2024 15:38:07.508430004 CET5996255710154.216.16.38192.168.2.13
                                    Nov 2, 2024 15:38:08.389070988 CET5996255710154.216.16.38192.168.2.13
                                    Nov 2, 2024 15:38:08.389188051 CET5571059962192.168.2.13154.216.16.38
                                    Nov 2, 2024 15:38:08.389233112 CET5571059962192.168.2.13154.216.16.38
                                    Nov 2, 2024 15:38:08.397830009 CET5571259962192.168.2.13154.216.16.38
                                    Nov 2, 2024 15:38:08.402664900 CET5996255712154.216.16.38192.168.2.13
                                    Nov 2, 2024 15:38:08.402724028 CET5571259962192.168.2.13154.216.16.38
                                    Nov 2, 2024 15:38:08.403352022 CET5571259962192.168.2.13154.216.16.38
                                    Nov 2, 2024 15:38:08.408644915 CET5996255712154.216.16.38192.168.2.13
                                    Nov 2, 2024 15:38:08.408694029 CET5571259962192.168.2.13154.216.16.38
                                    Nov 2, 2024 15:38:08.413506031 CET5996255712154.216.16.38192.168.2.13
                                    Nov 2, 2024 15:38:09.287410975 CET5996255712154.216.16.38192.168.2.13
                                    Nov 2, 2024 15:38:09.287566900 CET5571259962192.168.2.13154.216.16.38
                                    Nov 2, 2024 15:38:09.287600994 CET5571259962192.168.2.13154.216.16.38
                                    Nov 2, 2024 15:38:09.295176983 CET5571459962192.168.2.13154.216.16.38
                                    Nov 2, 2024 15:38:09.300048113 CET5996255714154.216.16.38192.168.2.13
                                    Nov 2, 2024 15:38:09.300117970 CET5571459962192.168.2.13154.216.16.38
                                    Nov 2, 2024 15:38:09.300721884 CET5571459962192.168.2.13154.216.16.38
                                    Nov 2, 2024 15:38:09.305470943 CET5996255714154.216.16.38192.168.2.13
                                    Nov 2, 2024 15:38:09.305531979 CET5571459962192.168.2.13154.216.16.38
                                    Nov 2, 2024 15:38:09.310467958 CET5996255714154.216.16.38192.168.2.13
                                    Nov 2, 2024 15:38:11.137470007 CET5996255714154.216.16.38192.168.2.13
                                    Nov 2, 2024 15:38:11.137593985 CET5571459962192.168.2.13154.216.16.38
                                    Nov 2, 2024 15:38:11.137613058 CET5996255714154.216.16.38192.168.2.13
                                    Nov 2, 2024 15:38:11.137650967 CET5571459962192.168.2.13154.216.16.38
                                    Nov 2, 2024 15:38:11.137670040 CET5571459962192.168.2.13154.216.16.38
                                    Nov 2, 2024 15:38:11.138761044 CET5996255714154.216.16.38192.168.2.13
                                    Nov 2, 2024 15:38:11.138803005 CET5571459962192.168.2.13154.216.16.38
                                    Nov 2, 2024 15:38:11.139337063 CET5996255714154.216.16.38192.168.2.13
                                    Nov 2, 2024 15:38:11.139380932 CET5571459962192.168.2.13154.216.16.38
                                    Nov 2, 2024 15:38:11.146033049 CET5571659962192.168.2.13154.216.16.38
                                    Nov 2, 2024 15:38:11.150871992 CET5996255716154.216.16.38192.168.2.13
                                    Nov 2, 2024 15:38:11.150923967 CET5571659962192.168.2.13154.216.16.38
                                    Nov 2, 2024 15:38:11.151573896 CET5571659962192.168.2.13154.216.16.38
                                    Nov 2, 2024 15:38:11.156318903 CET5996255716154.216.16.38192.168.2.13
                                    Nov 2, 2024 15:38:11.156363964 CET5571659962192.168.2.13154.216.16.38
                                    Nov 2, 2024 15:38:11.161118984 CET5996255716154.216.16.38192.168.2.13
                                    Nov 2, 2024 15:38:12.028333902 CET5996255716154.216.16.38192.168.2.13
                                    Nov 2, 2024 15:38:12.028455973 CET5571659962192.168.2.13154.216.16.38
                                    Nov 2, 2024 15:38:12.028492928 CET5571659962192.168.2.13154.216.16.38
                                    Nov 2, 2024 15:38:12.028501987 CET5996255716154.216.16.38192.168.2.13
                                    Nov 2, 2024 15:38:12.028551102 CET5571659962192.168.2.13154.216.16.38
                                    Nov 2, 2024 15:38:12.036518097 CET5571859962192.168.2.13154.216.16.38
                                    Nov 2, 2024 15:38:12.041311979 CET5996255718154.216.16.38192.168.2.13
                                    Nov 2, 2024 15:38:12.041373968 CET5571859962192.168.2.13154.216.16.38
                                    Nov 2, 2024 15:38:12.041997910 CET5571859962192.168.2.13154.216.16.38
                                    Nov 2, 2024 15:38:12.046720982 CET5996255718154.216.16.38192.168.2.13
                                    Nov 2, 2024 15:38:12.046770096 CET5571859962192.168.2.13154.216.16.38
                                    Nov 2, 2024 15:38:12.051572084 CET5996255718154.216.16.38192.168.2.13
                                    Nov 2, 2024 15:38:12.938642979 CET5996255718154.216.16.38192.168.2.13
                                    Nov 2, 2024 15:38:12.938654900 CET5996255718154.216.16.38192.168.2.13
                                    Nov 2, 2024 15:38:12.938838959 CET5571859962192.168.2.13154.216.16.38
                                    Nov 2, 2024 15:38:12.938838959 CET5571859962192.168.2.13154.216.16.38
                                    Nov 2, 2024 15:38:12.938862085 CET5571859962192.168.2.13154.216.16.38
                                    Nov 2, 2024 15:38:12.947880983 CET5572059962192.168.2.13154.216.16.38
                                    Nov 2, 2024 15:38:12.952641964 CET5996255720154.216.16.38192.168.2.13
                                    Nov 2, 2024 15:38:12.952724934 CET5572059962192.168.2.13154.216.16.38
                                    Nov 2, 2024 15:38:12.953373909 CET5572059962192.168.2.13154.216.16.38
                                    Nov 2, 2024 15:38:12.958117008 CET5996255720154.216.16.38192.168.2.13
                                    Nov 2, 2024 15:38:12.958184958 CET5572059962192.168.2.13154.216.16.38
                                    Nov 2, 2024 15:38:12.962949991 CET5996255720154.216.16.38192.168.2.13
                                    Nov 2, 2024 15:38:13.829459906 CET5996255720154.216.16.38192.168.2.13
                                    Nov 2, 2024 15:38:13.829562902 CET5572059962192.168.2.13154.216.16.38
                                    Nov 2, 2024 15:38:13.829716921 CET5572059962192.168.2.13154.216.16.38
                                    Nov 2, 2024 15:38:13.840742111 CET5572259962192.168.2.13154.216.16.38
                                    Nov 2, 2024 15:38:13.848491907 CET5996255722154.216.16.38192.168.2.13
                                    Nov 2, 2024 15:38:13.848563910 CET5572259962192.168.2.13154.216.16.38
                                    Nov 2, 2024 15:38:13.849596024 CET5572259962192.168.2.13154.216.16.38
                                    Nov 2, 2024 15:38:13.854347944 CET5996255722154.216.16.38192.168.2.13
                                    Nov 2, 2024 15:38:13.854424953 CET5572259962192.168.2.13154.216.16.38
                                    Nov 2, 2024 15:38:13.859237909 CET5996255722154.216.16.38192.168.2.13
                                    Nov 2, 2024 15:38:14.730631113 CET5996255722154.216.16.38192.168.2.13
                                    Nov 2, 2024 15:38:14.730680943 CET5996255722154.216.16.38192.168.2.13
                                    Nov 2, 2024 15:38:14.730798960 CET5572259962192.168.2.13154.216.16.38
                                    Nov 2, 2024 15:38:14.730798960 CET5572259962192.168.2.13154.216.16.38
                                    Nov 2, 2024 15:38:14.730837107 CET5572259962192.168.2.13154.216.16.38
                                    Nov 2, 2024 15:38:14.739156008 CET5572459962192.168.2.13154.216.16.38
                                    Nov 2, 2024 15:38:14.744076967 CET5996255724154.216.16.38192.168.2.13
                                    Nov 2, 2024 15:38:14.744151115 CET5572459962192.168.2.13154.216.16.38
                                    Nov 2, 2024 15:38:14.744992018 CET5572459962192.168.2.13154.216.16.38
                                    Nov 2, 2024 15:38:14.749778032 CET5996255724154.216.16.38192.168.2.13
                                    Nov 2, 2024 15:38:14.749830961 CET5572459962192.168.2.13154.216.16.38
                                    Nov 2, 2024 15:38:14.754688025 CET5996255724154.216.16.38192.168.2.13
                                    Nov 2, 2024 15:38:15.629066944 CET5996255724154.216.16.38192.168.2.13
                                    Nov 2, 2024 15:38:15.629185915 CET5572459962192.168.2.13154.216.16.38
                                    Nov 2, 2024 15:38:15.629232883 CET5572459962192.168.2.13154.216.16.38
                                    Nov 2, 2024 15:38:15.637537003 CET5572659962192.168.2.13154.216.16.38
                                    Nov 2, 2024 15:38:15.642436981 CET5996255726154.216.16.38192.168.2.13
                                    Nov 2, 2024 15:38:15.642507076 CET5572659962192.168.2.13154.216.16.38
                                    Nov 2, 2024 15:38:15.643465996 CET5572659962192.168.2.13154.216.16.38
                                    Nov 2, 2024 15:38:15.648361921 CET5996255726154.216.16.38192.168.2.13
                                    Nov 2, 2024 15:38:15.648422003 CET5572659962192.168.2.13154.216.16.38
                                    Nov 2, 2024 15:38:15.653392076 CET5996255726154.216.16.38192.168.2.13
                                    Nov 2, 2024 15:38:16.528692961 CET5996255726154.216.16.38192.168.2.13
                                    Nov 2, 2024 15:38:16.528837919 CET5572659962192.168.2.13154.216.16.38
                                    Nov 2, 2024 15:38:16.528868914 CET5572659962192.168.2.13154.216.16.38
                                    Nov 2, 2024 15:38:16.536672115 CET5572859962192.168.2.13154.216.16.38
                                    Nov 2, 2024 15:38:16.541654110 CET5996255728154.216.16.38192.168.2.13
                                    Nov 2, 2024 15:38:16.541702032 CET5572859962192.168.2.13154.216.16.38
                                    Nov 2, 2024 15:38:16.542283058 CET5572859962192.168.2.13154.216.16.38
                                    Nov 2, 2024 15:38:16.547101974 CET5996255728154.216.16.38192.168.2.13
                                    Nov 2, 2024 15:38:16.547138929 CET5572859962192.168.2.13154.216.16.38
                                    Nov 2, 2024 15:38:16.552042961 CET5996255728154.216.16.38192.168.2.13
                                    Nov 2, 2024 15:38:17.428392887 CET5996255728154.216.16.38192.168.2.13
                                    Nov 2, 2024 15:38:17.428414106 CET5996255728154.216.16.38192.168.2.13
                                    Nov 2, 2024 15:38:17.428514004 CET5572859962192.168.2.13154.216.16.38
                                    Nov 2, 2024 15:38:17.428514004 CET5572859962192.168.2.13154.216.16.38
                                    Nov 2, 2024 15:38:17.428587914 CET5572859962192.168.2.13154.216.16.38
                                    Nov 2, 2024 15:38:17.438745022 CET5573059962192.168.2.13154.216.16.38
                                    Nov 2, 2024 15:38:17.444861889 CET5996255730154.216.16.38192.168.2.13
                                    Nov 2, 2024 15:38:17.444921017 CET5573059962192.168.2.13154.216.16.38
                                    Nov 2, 2024 15:38:17.445528030 CET5573059962192.168.2.13154.216.16.38
                                    Nov 2, 2024 15:38:17.452205896 CET5996255730154.216.16.38192.168.2.13
                                    Nov 2, 2024 15:38:17.452274084 CET5573059962192.168.2.13154.216.16.38
                                    Nov 2, 2024 15:38:17.457247972 CET5996255730154.216.16.38192.168.2.13
                                    Nov 2, 2024 15:38:18.333064079 CET5996255730154.216.16.38192.168.2.13
                                    Nov 2, 2024 15:38:18.333224058 CET5573059962192.168.2.13154.216.16.38
                                    Nov 2, 2024 15:38:18.333252907 CET5573059962192.168.2.13154.216.16.38
                                    Nov 2, 2024 15:38:18.340790033 CET5573259962192.168.2.13154.216.16.38
                                    Nov 2, 2024 15:38:18.345649958 CET5996255732154.216.16.38192.168.2.13
                                    Nov 2, 2024 15:38:18.345721960 CET5573259962192.168.2.13154.216.16.38
                                    Nov 2, 2024 15:38:18.346352100 CET5573259962192.168.2.13154.216.16.38
                                    Nov 2, 2024 15:38:18.351249933 CET5996255732154.216.16.38192.168.2.13
                                    Nov 2, 2024 15:38:18.351294041 CET5573259962192.168.2.13154.216.16.38
                                    Nov 2, 2024 15:38:18.356132030 CET5996255732154.216.16.38192.168.2.13
                                    Nov 2, 2024 15:38:28.356626987 CET5573259962192.168.2.13154.216.16.38
                                    Nov 2, 2024 15:38:28.361955881 CET5996255732154.216.16.38192.168.2.13
                                    Nov 2, 2024 15:38:28.628505945 CET5996255732154.216.16.38192.168.2.13
                                    Nov 2, 2024 15:38:28.628679991 CET5573259962192.168.2.13154.216.16.38
                                    Nov 2, 2024 15:39:28.683527946 CET5573259962192.168.2.13154.216.16.38
                                    Nov 2, 2024 15:39:28.688457012 CET5996255732154.216.16.38192.168.2.13
                                    Nov 2, 2024 15:39:28.953351021 CET5996255732154.216.16.38192.168.2.13
                                    Nov 2, 2024 15:39:28.953541040 CET5573259962192.168.2.13154.216.16.38
                                    TimestampSource PortDest PortSource IPDest IP
                                    Nov 2, 2024 15:38:02.683450937 CET5405053192.168.2.138.8.8.8
                                    Nov 2, 2024 15:38:02.690443993 CET53540508.8.8.8192.168.2.13
                                    Nov 2, 2024 15:38:03.618216038 CET5135553192.168.2.138.8.8.8
                                    Nov 2, 2024 15:38:03.626888037 CET53513558.8.8.8192.168.2.13
                                    Nov 2, 2024 15:38:04.730781078 CET5200653192.168.2.138.8.8.8
                                    Nov 2, 2024 15:38:04.737200975 CET53520068.8.8.8192.168.2.13
                                    Nov 2, 2024 15:38:05.642379999 CET4386753192.168.2.138.8.8.8
                                    Nov 2, 2024 15:38:05.649353981 CET53438678.8.8.8192.168.2.13
                                    Nov 2, 2024 15:38:06.566257000 CET3483153192.168.2.138.8.8.8
                                    Nov 2, 2024 15:38:06.573343992 CET53348318.8.8.8192.168.2.13
                                    Nov 2, 2024 15:38:07.485235929 CET5927053192.168.2.138.8.8.8
                                    Nov 2, 2024 15:38:07.492799997 CET53592708.8.8.8192.168.2.13
                                    Nov 2, 2024 15:38:08.390151024 CET5442953192.168.2.138.8.8.8
                                    Nov 2, 2024 15:38:08.397408009 CET53544298.8.8.8192.168.2.13
                                    Nov 2, 2024 15:38:09.288389921 CET3522853192.168.2.138.8.8.8
                                    Nov 2, 2024 15:38:09.294806004 CET53352288.8.8.8192.168.2.13
                                    Nov 2, 2024 15:38:11.138485909 CET4847453192.168.2.138.8.8.8
                                    Nov 2, 2024 15:38:11.145669937 CET53484748.8.8.8192.168.2.13
                                    Nov 2, 2024 15:38:12.029407024 CET4659553192.168.2.138.8.8.8
                                    Nov 2, 2024 15:38:12.036137104 CET53465958.8.8.8192.168.2.13
                                    Nov 2, 2024 15:38:12.939770937 CET3602753192.168.2.138.8.8.8
                                    Nov 2, 2024 15:38:12.947488070 CET53360278.8.8.8192.168.2.13
                                    Nov 2, 2024 15:38:13.831031084 CET3340153192.168.2.138.8.8.8
                                    Nov 2, 2024 15:38:13.840164900 CET53334018.8.8.8192.168.2.13
                                    Nov 2, 2024 15:38:14.731703997 CET5376853192.168.2.138.8.8.8
                                    Nov 2, 2024 15:38:14.738734961 CET53537688.8.8.8192.168.2.13
                                    Nov 2, 2024 15:38:15.630037069 CET5735853192.168.2.138.8.8.8
                                    Nov 2, 2024 15:38:15.637180090 CET53573588.8.8.8192.168.2.13
                                    Nov 2, 2024 15:38:16.529634953 CET6029153192.168.2.138.8.8.8
                                    Nov 2, 2024 15:38:16.536329031 CET53602918.8.8.8192.168.2.13
                                    Nov 2, 2024 15:38:17.429388046 CET5182353192.168.2.138.8.8.8
                                    Nov 2, 2024 15:38:17.438357115 CET53518238.8.8.8192.168.2.13
                                    Nov 2, 2024 15:38:18.334014893 CET5065453192.168.2.138.8.8.8
                                    Nov 2, 2024 15:38:18.340385914 CET53506548.8.8.8192.168.2.13
                                    TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                    Nov 2, 2024 15:38:02.683450937 CET192.168.2.138.8.8.80x6e0dStandard query (0)server.myway-ing.winA (IP address)IN (0x0001)false
                                    Nov 2, 2024 15:38:03.618216038 CET192.168.2.138.8.8.80x995eStandard query (0)server.myway-ing.winA (IP address)IN (0x0001)false
                                    Nov 2, 2024 15:38:04.730781078 CET192.168.2.138.8.8.80x9b90Standard query (0)server.myway-ing.winA (IP address)IN (0x0001)false
                                    Nov 2, 2024 15:38:05.642379999 CET192.168.2.138.8.8.80x24baStandard query (0)server.myway-ing.winA (IP address)IN (0x0001)false
                                    Nov 2, 2024 15:38:06.566257000 CET192.168.2.138.8.8.80x46aeStandard query (0)server.myway-ing.winA (IP address)IN (0x0001)false
                                    Nov 2, 2024 15:38:07.485235929 CET192.168.2.138.8.8.80x5525Standard query (0)server.myway-ing.winA (IP address)IN (0x0001)false
                                    Nov 2, 2024 15:38:08.390151024 CET192.168.2.138.8.8.80x4c2fStandard query (0)server.myway-ing.winA (IP address)IN (0x0001)false
                                    Nov 2, 2024 15:38:09.288389921 CET192.168.2.138.8.8.80x351dStandard query (0)server.myway-ing.winA (IP address)IN (0x0001)false
                                    Nov 2, 2024 15:38:11.138485909 CET192.168.2.138.8.8.80xaa15Standard query (0)server.myway-ing.winA (IP address)IN (0x0001)false
                                    Nov 2, 2024 15:38:12.029407024 CET192.168.2.138.8.8.80xd638Standard query (0)server.myway-ing.winA (IP address)IN (0x0001)false
                                    Nov 2, 2024 15:38:12.939770937 CET192.168.2.138.8.8.80x2f96Standard query (0)server.myway-ing.winA (IP address)IN (0x0001)false
                                    Nov 2, 2024 15:38:13.831031084 CET192.168.2.138.8.8.80x794aStandard query (0)server.myway-ing.winA (IP address)IN (0x0001)false
                                    Nov 2, 2024 15:38:14.731703997 CET192.168.2.138.8.8.80x6eb8Standard query (0)server.myway-ing.winA (IP address)IN (0x0001)false
                                    Nov 2, 2024 15:38:15.630037069 CET192.168.2.138.8.8.80xa995Standard query (0)server.myway-ing.winA (IP address)IN (0x0001)false
                                    Nov 2, 2024 15:38:16.529634953 CET192.168.2.138.8.8.80xff83Standard query (0)server.myway-ing.winA (IP address)IN (0x0001)false
                                    Nov 2, 2024 15:38:17.429388046 CET192.168.2.138.8.8.80x5e1aStandard query (0)server.myway-ing.winA (IP address)IN (0x0001)false
                                    Nov 2, 2024 15:38:18.334014893 CET192.168.2.138.8.8.80xab96Standard query (0)server.myway-ing.winA (IP address)IN (0x0001)false
                                    TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                    Nov 2, 2024 15:38:02.690443993 CET8.8.8.8192.168.2.130x6e0dNo error (0)server.myway-ing.win154.216.16.38A (IP address)IN (0x0001)false
                                    Nov 2, 2024 15:38:03.626888037 CET8.8.8.8192.168.2.130x995eNo error (0)server.myway-ing.win154.216.16.38A (IP address)IN (0x0001)false
                                    Nov 2, 2024 15:38:04.737200975 CET8.8.8.8192.168.2.130x9b90No error (0)server.myway-ing.win154.216.16.38A (IP address)IN (0x0001)false
                                    Nov 2, 2024 15:38:05.649353981 CET8.8.8.8192.168.2.130x24baNo error (0)server.myway-ing.win154.216.16.38A (IP address)IN (0x0001)false
                                    Nov 2, 2024 15:38:06.573343992 CET8.8.8.8192.168.2.130x46aeNo error (0)server.myway-ing.win154.216.16.38A (IP address)IN (0x0001)false
                                    Nov 2, 2024 15:38:07.492799997 CET8.8.8.8192.168.2.130x5525No error (0)server.myway-ing.win154.216.16.38A (IP address)IN (0x0001)false
                                    Nov 2, 2024 15:38:08.397408009 CET8.8.8.8192.168.2.130x4c2fNo error (0)server.myway-ing.win154.216.16.38A (IP address)IN (0x0001)false
                                    Nov 2, 2024 15:38:09.294806004 CET8.8.8.8192.168.2.130x351dNo error (0)server.myway-ing.win154.216.16.38A (IP address)IN (0x0001)false
                                    Nov 2, 2024 15:38:11.145669937 CET8.8.8.8192.168.2.130xaa15No error (0)server.myway-ing.win154.216.16.38A (IP address)IN (0x0001)false
                                    Nov 2, 2024 15:38:12.036137104 CET8.8.8.8192.168.2.130xd638No error (0)server.myway-ing.win154.216.16.38A (IP address)IN (0x0001)false
                                    Nov 2, 2024 15:38:12.947488070 CET8.8.8.8192.168.2.130x2f96No error (0)server.myway-ing.win154.216.16.38A (IP address)IN (0x0001)false
                                    Nov 2, 2024 15:38:13.840164900 CET8.8.8.8192.168.2.130x794aNo error (0)server.myway-ing.win154.216.16.38A (IP address)IN (0x0001)false
                                    Nov 2, 2024 15:38:14.738734961 CET8.8.8.8192.168.2.130x6eb8No error (0)server.myway-ing.win154.216.16.38A (IP address)IN (0x0001)false
                                    Nov 2, 2024 15:38:15.637180090 CET8.8.8.8192.168.2.130xa995No error (0)server.myway-ing.win154.216.16.38A (IP address)IN (0x0001)false
                                    Nov 2, 2024 15:38:16.536329031 CET8.8.8.8192.168.2.130xff83No error (0)server.myway-ing.win154.216.16.38A (IP address)IN (0x0001)false
                                    Nov 2, 2024 15:38:17.438357115 CET8.8.8.8192.168.2.130x5e1aNo error (0)server.myway-ing.win154.216.16.38A (IP address)IN (0x0001)false
                                    Nov 2, 2024 15:38:18.340385914 CET8.8.8.8192.168.2.130xab96No error (0)server.myway-ing.win154.216.16.38A (IP address)IN (0x0001)false

                                    System Behavior

                                    Start time (UTC):14:38:01
                                    Start date (UTC):02/11/2024
                                    Path:/tmp/zmap.ppc.elf
                                    Arguments:/tmp/zmap.ppc.elf
                                    File size:5388968 bytes
                                    MD5 hash:ae65271c943d3451b7f026d1fadccea6

                                    Start time (UTC):14:38:01
                                    Start date (UTC):02/11/2024
                                    Path:/tmp/zmap.ppc.elf
                                    Arguments:-
                                    File size:5388968 bytes
                                    MD5 hash:ae65271c943d3451b7f026d1fadccea6

                                    Start time (UTC):14:38:01
                                    Start date (UTC):02/11/2024
                                    Path:/tmp/zmap.ppc.elf
                                    Arguments:-
                                    File size:5388968 bytes
                                    MD5 hash:ae65271c943d3451b7f026d1fadccea6