Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
zmap.sh4.elf

Overview

General Information

Sample name:zmap.sh4.elf
Analysis ID:1547472
MD5:072034caacd2f00a0ecb21c2cd8d089c
SHA1:8e03db8c54dd27dd41557211f0487063a8edb95c
SHA256:aa06b7f54a62bb858c5e32ae4f52160052c32430388af5f4f7d1fd28a211fdcc
Tags:elfuser-abuse_ch
Infos:

Detection

Mirai, Okiru
Score:84
Range:0 - 100
Whitelisted:false

Signatures

Antivirus / Scanner detection for submitted sample
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Yara detected Mirai
Yara detected Okiru
Sample deletes itself
Detected TCP or UDP traffic on non-standard ports
Sample has stripped symbol table
Sample listens on a socket
Uses the "uname" system call to query kernel version information (possible evasion)
Yara signature match

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1547472
Start date and time:2024-11-02 15:37:12 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 29s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:zmap.sh4.elf
Detection:MAL
Classification:mal84.troj.evad.linELF@0/0@24/0
  • VT rate limit hit for: zmap.sh4.elf
Command:/tmp/zmap.sh4.elf
PID:5491
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
VagneRHere
Standard Error:
  • system is lnxubuntu20
  • zmap.sh4.elf (PID: 5491, Parent: 5416, MD5: 8943e5f8f8c280467b4472c15ae93ba9) Arguments: /tmp/zmap.sh4.elf
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
MiraiMirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese. Nowadays it targets a wide range of networked embedded devices such as IP cameras, home routers (many vendors involved), and other IoT devices. Since the source code was published on "Hack Forums" many variants of the Mirai family appeared, infecting mostly home networks all around the world.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/elf.mirai
SourceRuleDescriptionAuthorStrings
zmap.sh4.elfJoeSecurity_OkiruYara detected OkiruJoe Security
    zmap.sh4.elfJoeSecurity_Mirai_8Yara detected MiraiJoe Security
      zmap.sh4.elfLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
      • 0xd548:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xd55c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xd570:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xd584:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xd598:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xd5ac:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xd5c0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xd5d4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xd5e8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xd5fc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xd610:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xd624:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xd638:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xd64c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xd660:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xd674:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xd688:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xd69c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xd6b0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xd6c4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xd6d8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      SourceRuleDescriptionAuthorStrings
      5491.1.00007fa8d0400000.00007fa8d0410000.r-x.sdmpJoeSecurity_OkiruYara detected OkiruJoe Security
        5491.1.00007fa8d0400000.00007fa8d0410000.r-x.sdmpJoeSecurity_Mirai_8Yara detected MiraiJoe Security
          5491.1.00007fa8d0400000.00007fa8d0410000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
          • 0xd548:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xd55c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xd570:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xd584:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xd598:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xd5ac:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xd5c0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xd5d4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xd5e8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xd5fc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xd610:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xd624:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xd638:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xd64c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xd660:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xd674:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xd688:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xd69c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xd6b0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xd6c4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xd6d8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          5499.1.00007fa8d0400000.00007fa8d0410000.r-x.sdmpJoeSecurity_OkiruYara detected OkiruJoe Security
            5499.1.00007fa8d0400000.00007fa8d0410000.r-x.sdmpJoeSecurity_Mirai_8Yara detected MiraiJoe Security
              Click to see the 7 entries
              No Suricata rule has matched

              Click to jump to signature section

              Show All Signature Results

              AV Detection

              barindex
              Source: zmap.sh4.elfAvira: detected
              Source: zmap.sh4.elfReversingLabs: Detection: 57%
              Source: global trafficTCP traffic: 192.168.2.14:47360 -> 154.216.16.38:59962
              Source: /tmp/zmap.sh4.elf (PID: 5491)Socket: 127.0.0.1:39148Jump to behavior
              Source: global trafficDNS traffic detected: DNS query: server.myway-ing.win

              System Summary

              barindex
              Source: zmap.sh4.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
              Source: 5491.1.00007fa8d0400000.00007fa8d0410000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
              Source: 5499.1.00007fa8d0400000.00007fa8d0410000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
              Source: Process Memory Space: zmap.sh4.elf PID: 5491, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
              Source: Process Memory Space: zmap.sh4.elf PID: 5499, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
              Source: ELF static info symbol of initial sample.symtab present: no
              Source: zmap.sh4.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
              Source: 5491.1.00007fa8d0400000.00007fa8d0410000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
              Source: 5499.1.00007fa8d0400000.00007fa8d0410000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
              Source: Process Memory Space: zmap.sh4.elf PID: 5491, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
              Source: Process Memory Space: zmap.sh4.elf PID: 5499, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
              Source: classification engineClassification label: mal84.troj.evad.linELF@0/0@24/0

              Hooking and other Techniques for Hiding and Protection

              barindex
              Source: /tmp/zmap.sh4.elf (PID: 5491)File: /tmp/zmap.sh4.elfJump to behavior
              Source: /tmp/zmap.sh4.elf (PID: 5491)Queries kernel information via 'uname': Jump to behavior
              Source: zmap.sh4.elf, 5491.1.00007ffca9798000.00007ffca97b9000.rw-.sdmp, zmap.sh4.elf, 5499.1.00007ffca9798000.00007ffca97b9000.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-sh4/tmp/zmap.sh4.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/zmap.sh4.elf
              Source: zmap.sh4.elf, 5491.1.00007ffca9798000.00007ffca97b9000.rw-.sdmp, zmap.sh4.elf, 5499.1.00007ffca9798000.00007ffca97b9000.rw-.sdmpBinary or memory string: /usr/bin/qemu-sh4
              Source: zmap.sh4.elf, 5491.1.0000562edc9ec000.0000562edca4f000.rw-.sdmp, zmap.sh4.elf, 5499.1.0000562edc9ec000.0000562edca4f000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/sh4
              Source: zmap.sh4.elf, 5491.1.0000562edc9ec000.0000562edca4f000.rw-.sdmp, zmap.sh4.elf, 5499.1.0000562edc9ec000.0000562edca4f000.rw-.sdmpBinary or memory string: .V5!/etc/qemu-binfmt/sh4

              Stealing of Sensitive Information

              barindex
              Source: Yara matchFile source: zmap.sh4.elf, type: SAMPLE
              Source: Yara matchFile source: 5491.1.00007fa8d0400000.00007fa8d0410000.r-x.sdmp, type: MEMORY
              Source: Yara matchFile source: 5499.1.00007fa8d0400000.00007fa8d0410000.r-x.sdmp, type: MEMORY
              Source: Yara matchFile source: Process Memory Space: zmap.sh4.elf PID: 5491, type: MEMORYSTR
              Source: Yara matchFile source: Process Memory Space: zmap.sh4.elf PID: 5499, type: MEMORYSTR
              Source: Yara matchFile source: zmap.sh4.elf, type: SAMPLE
              Source: Yara matchFile source: 5491.1.00007fa8d0400000.00007fa8d0410000.r-x.sdmp, type: MEMORY
              Source: Yara matchFile source: 5499.1.00007fa8d0400000.00007fa8d0410000.r-x.sdmp, type: MEMORY
              Source: Yara matchFile source: Process Memory Space: zmap.sh4.elf PID: 5491, type: MEMORYSTR
              Source: Yara matchFile source: Process Memory Space: zmap.sh4.elf PID: 5499, type: MEMORYSTR

              Remote Access Functionality

              barindex
              Source: Yara matchFile source: zmap.sh4.elf, type: SAMPLE
              Source: Yara matchFile source: 5491.1.00007fa8d0400000.00007fa8d0410000.r-x.sdmp, type: MEMORY
              Source: Yara matchFile source: 5499.1.00007fa8d0400000.00007fa8d0410000.r-x.sdmp, type: MEMORY
              Source: Yara matchFile source: Process Memory Space: zmap.sh4.elf PID: 5491, type: MEMORYSTR
              Source: Yara matchFile source: Process Memory Space: zmap.sh4.elf PID: 5499, type: MEMORYSTR
              Source: Yara matchFile source: zmap.sh4.elf, type: SAMPLE
              Source: Yara matchFile source: 5491.1.00007fa8d0400000.00007fa8d0410000.r-x.sdmp, type: MEMORY
              Source: Yara matchFile source: 5499.1.00007fa8d0400000.00007fa8d0410000.r-x.sdmp, type: MEMORY
              Source: Yara matchFile source: Process Memory Space: zmap.sh4.elf PID: 5491, type: MEMORYSTR
              Source: Yara matchFile source: Process Memory Space: zmap.sh4.elf PID: 5499, type: MEMORYSTR
              ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
              Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception1
              File Deletion
              OS Credential Dumping11
              Security Software Discovery
              Remote ServicesData from Local System1
              Non-Standard Port
              Exfiltration Over Other Network MediumAbuse Accessibility Features
              CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
              Non-Application Layer Protocol
              Exfiltration Over BluetoothNetwork Denial of Service
              Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
              Application Layer Protocol
              Automated ExfiltrationData Encrypted for Impact
              No configs have been found
              Hide Legend

              Legend:

              • Process
              • Signature
              • Created File
              • DNS/IP Info
              • Is Dropped
              • Number of created Files
              • Is malicious
              • Internet
              SourceDetectionScannerLabelLink
              zmap.sh4.elf58%ReversingLabsLinux.Trojan.Mirai
              zmap.sh4.elf100%AviraEXP/ELF.Mirai.Z.A
              No Antivirus matches
              No Antivirus matches
              No Antivirus matches
              NameIPActiveMaliciousAntivirus DetectionReputation
              server.myway-ing.win
              154.216.16.38
              truefalse
                unknown
                • No. of IPs < 25%
                • 25% < No. of IPs < 50%
                • 50% < No. of IPs < 75%
                • 75% < No. of IPs
                IPDomainCountryFlagASNASN NameMalicious
                154.216.16.38
                server.myway-ing.winSeychelles
                135357SKHT-ASShenzhenKatherineHengTechnologyInformationCofalse
                MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                154.216.16.38zmap.mips.elfGet hashmaliciousMirai, OkiruBrowse
                  zmap.x86.elfGet hashmaliciousOkiruBrowse
                    zmap.mpsl.elfGet hashmaliciousMirai, OkiruBrowse
                      debug.dbg.elfGet hashmaliciousMirai, OkiruBrowse
                        zmap.m68k.elfGet hashmaliciousMirai, OkiruBrowse
                          zmap.mpsl.elfGet hashmaliciousMirai, OkiruBrowse
                            zmap.mips.elfGet hashmaliciousMirai, OkiruBrowse
                              zmap.arm.elfGet hashmaliciousMirai, OkiruBrowse
                                zmap.spc.elfGet hashmaliciousMirai, OkiruBrowse
                                  zmap.sh4.elfGet hashmaliciousMirai, OkiruBrowse
                                    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                    server.myway-ing.winzmap.mips.elfGet hashmaliciousMirai, OkiruBrowse
                                    • 154.216.16.38
                                    zmap.x86.elfGet hashmaliciousOkiruBrowse
                                    • 154.216.16.38
                                    zmap.mpsl.elfGet hashmaliciousMirai, OkiruBrowse
                                    • 154.216.16.38
                                    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                    SKHT-ASShenzhenKatherineHengTechnologyInformationCozmap.mips.elfGet hashmaliciousMirai, OkiruBrowse
                                    • 154.216.16.38
                                    zmap.x86.elfGet hashmaliciousOkiruBrowse
                                    • 154.216.16.38
                                    zmap.mpsl.elfGet hashmaliciousMirai, OkiruBrowse
                                    • 154.216.16.38
                                    qkehusl.elfGet hashmaliciousMiraiBrowse
                                    • 154.216.19.76
                                    jwwofba5.elfGet hashmaliciousMiraiBrowse
                                    • 154.216.19.76
                                    wheiuwa4.elfGet hashmaliciousMiraiBrowse
                                    • 154.216.19.76
                                    dvwkja7.elfGet hashmaliciousMiraiBrowse
                                    • 154.216.19.76
                                    vsbeps.elfGet hashmaliciousMiraiBrowse
                                    • 154.216.19.76
                                    qkbfi86.elfGet hashmaliciousMiraiBrowse
                                    • 154.216.19.76
                                    boatnet.m68k.elfGet hashmaliciousMiraiBrowse
                                    • 154.216.19.64
                                    No context
                                    No context
                                    No created / dropped files found
                                    File type:ELF 32-bit LSB executable, Renesas SH, version 1 (SYSV), statically linked, stripped
                                    Entropy (8bit):6.906975450842153
                                    TrID:
                                    • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                                    File name:zmap.sh4.elf
                                    File size:64'316 bytes
                                    MD5:072034caacd2f00a0ecb21c2cd8d089c
                                    SHA1:8e03db8c54dd27dd41557211f0487063a8edb95c
                                    SHA256:aa06b7f54a62bb858c5e32ae4f52160052c32430388af5f4f7d1fd28a211fdcc
                                    SHA512:2311565b506ec54a9a70c7ee9bd336babba09be44e1baadc30e990cd153a9f05195e6cf4700dbfa79c7418787f3e914d745ea1714fe3b69ca63b89962ff8bf96
                                    SSDEEP:1536:axqlNEqXAcC9s/mRH2Gy2BX3tlzYN2KWNxXrCZQCZr2JY:axQ+cAcC9s/mRH2Gy2BX9l83W3CZQpJY
                                    TLSH:08539E7AE42A2984C5450434A0B88F741FA3B1C4935B6EFB1ADDC6B5604BEBCF449FE4
                                    File Content Preview:.ELF..............*.......@.4...........4. ...(...............@...@...........................A...A......'..........Q.td............................././"O.n........#.*@........#.*@,....o&O.n...l..............................././.../.a"O.!...n...a.b("...q.

                                    ELF header

                                    Class:ELF32
                                    Data:2's complement, little endian
                                    Version:1 (current)
                                    Machine:<unknown>
                                    Version Number:0x1
                                    Type:EXEC (Executable file)
                                    OS/ABI:UNIX - System V
                                    ABI Version:0
                                    Entry Point Address:0x4001a0
                                    Flags:0x9
                                    ELF Header Size:52
                                    Program Header Offset:52
                                    Program Header Size:32
                                    Number of Program Headers:3
                                    Section Header Offset:63916
                                    Section Header Size:40
                                    Number of Section Headers:10
                                    Header String Table Index:9
                                    NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                    NULL0x00x00x00x00x0000
                                    .initPROGBITS0x4000940x940x300x00x6AX004
                                    .textPROGBITS0x4000e00xe00xd4400x00x6AX0032
                                    .finiPROGBITS0x40d5200xd5200x240x00x6AX004
                                    .rodataPROGBITS0x40d5440xd5440x20840x00x2A004
                                    .ctorsPROGBITS0x41f5cc0xf5cc0x80x00x3WA004
                                    .dtorsPROGBITS0x41f5d40xf5d40x80x00x3WA004
                                    .dataPROGBITS0x41f5e00xf5e00x38c0x00x3WA004
                                    .bssNOBITS0x41f96c0xf96c0x24300x00x3WA004
                                    .shstrtabSTRTAB0x00xf96c0x3e0x00x0001
                                    TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                    LOAD0x00x4000000x4000000xf5c80xf5c86.95340x5R E0x10000.init .text .fini .rodata
                                    LOAD0xf5cc0x41f5cc0x41f5cc0x3a00x27d03.12370x6RW 0x10000.ctors .dtors .data .bss
                                    GNU_STACK0x00x00x00x00x00.00000x7RWE0x4
                                    TimestampSource PortDest PortSource IPDest IP
                                    Nov 2, 2024 15:38:00.295809031 CET4736059962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:00.300612926 CET5996247360154.216.16.38192.168.2.14
                                    Nov 2, 2024 15:38:00.300668955 CET4736059962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:00.307323933 CET4736059962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:00.312163115 CET5996247360154.216.16.38192.168.2.14
                                    Nov 2, 2024 15:38:00.312205076 CET4736059962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:00.324250937 CET5996247360154.216.16.38192.168.2.14
                                    Nov 2, 2024 15:38:01.189470053 CET5996247360154.216.16.38192.168.2.14
                                    Nov 2, 2024 15:38:01.189769983 CET4736059962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:01.189769983 CET4736059962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:01.198340893 CET4736259962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:01.203181028 CET5996247362154.216.16.38192.168.2.14
                                    Nov 2, 2024 15:38:01.203254938 CET4736259962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:01.203908920 CET4736259962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:01.209089041 CET5996247362154.216.16.38192.168.2.14
                                    Nov 2, 2024 15:38:01.209134102 CET4736259962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:01.214088917 CET5996247362154.216.16.38192.168.2.14
                                    Nov 2, 2024 15:38:02.082496881 CET5996247362154.216.16.38192.168.2.14
                                    Nov 2, 2024 15:38:02.082510948 CET5996247362154.216.16.38192.168.2.14
                                    Nov 2, 2024 15:38:02.082609892 CET4736259962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:02.082609892 CET4736259962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:02.082690954 CET4736259962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:02.090620995 CET4736459962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:02.095457077 CET5996247364154.216.16.38192.168.2.14
                                    Nov 2, 2024 15:38:02.095518112 CET4736459962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:02.096115112 CET4736459962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:02.100944042 CET5996247364154.216.16.38192.168.2.14
                                    Nov 2, 2024 15:38:02.100990057 CET4736459962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:02.105797052 CET5996247364154.216.16.38192.168.2.14
                                    Nov 2, 2024 15:38:03.002341986 CET5996247364154.216.16.38192.168.2.14
                                    Nov 2, 2024 15:38:03.002605915 CET4736459962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:03.002607107 CET4736459962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:03.043574095 CET4736659962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:03.048499107 CET5996247366154.216.16.38192.168.2.14
                                    Nov 2, 2024 15:38:03.048554897 CET4736659962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:03.049115896 CET4736659962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:03.053996086 CET5996247366154.216.16.38192.168.2.14
                                    Nov 2, 2024 15:38:03.054043055 CET4736659962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:03.059020042 CET5996247366154.216.16.38192.168.2.14
                                    Nov 2, 2024 15:38:03.963859081 CET5996247366154.216.16.38192.168.2.14
                                    Nov 2, 2024 15:38:03.963967085 CET4736659962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:03.964121103 CET4736659962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:03.972405910 CET4736859962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:03.977350950 CET5996247368154.216.16.38192.168.2.14
                                    Nov 2, 2024 15:38:03.977407932 CET4736859962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:03.978003025 CET4736859962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:03.982769012 CET5996247368154.216.16.38192.168.2.14
                                    Nov 2, 2024 15:38:03.982822895 CET4736859962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:03.988888979 CET5996247368154.216.16.38192.168.2.14
                                    Nov 2, 2024 15:38:04.860703945 CET5996247368154.216.16.38192.168.2.14
                                    Nov 2, 2024 15:38:04.861105919 CET4736859962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:04.861107111 CET4736859962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:04.869196892 CET4737059962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:04.874027014 CET5996247370154.216.16.38192.168.2.14
                                    Nov 2, 2024 15:38:04.874093056 CET4737059962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:04.874727011 CET4737059962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:04.879571915 CET5996247370154.216.16.38192.168.2.14
                                    Nov 2, 2024 15:38:04.879617929 CET4737059962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:04.884443045 CET5996247370154.216.16.38192.168.2.14
                                    Nov 2, 2024 15:38:05.760056973 CET5996247370154.216.16.38192.168.2.14
                                    Nov 2, 2024 15:38:05.760158062 CET4737059962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:05.760232925 CET4737059962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:05.760293007 CET5996247370154.216.16.38192.168.2.14
                                    Nov 2, 2024 15:38:05.760351896 CET4737059962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:05.768824100 CET4737259962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:05.773706913 CET5996247372154.216.16.38192.168.2.14
                                    Nov 2, 2024 15:38:05.773772955 CET4737259962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:05.774491072 CET4737259962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:05.779350042 CET5996247372154.216.16.38192.168.2.14
                                    Nov 2, 2024 15:38:05.779393911 CET4737259962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:05.784260988 CET5996247372154.216.16.38192.168.2.14
                                    Nov 2, 2024 15:38:06.674825907 CET5996247372154.216.16.38192.168.2.14
                                    Nov 2, 2024 15:38:06.674896002 CET5996247372154.216.16.38192.168.2.14
                                    Nov 2, 2024 15:38:06.675056934 CET4737259962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:06.675056934 CET4737259962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:06.675056934 CET4737259962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:06.683270931 CET4737459962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:06.688087940 CET5996247374154.216.16.38192.168.2.14
                                    Nov 2, 2024 15:38:06.688136101 CET4737459962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:06.688926935 CET4737459962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:06.693731070 CET5996247374154.216.16.38192.168.2.14
                                    Nov 2, 2024 15:38:06.693772078 CET4737459962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:06.698605061 CET5996247374154.216.16.38192.168.2.14
                                    Nov 2, 2024 15:38:07.592345953 CET5996247374154.216.16.38192.168.2.14
                                    Nov 2, 2024 15:38:07.592619896 CET4737459962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:07.592619896 CET4737459962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:07.602118015 CET4737659962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:07.606867075 CET5996247376154.216.16.38192.168.2.14
                                    Nov 2, 2024 15:38:07.606925011 CET4737659962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:07.607847929 CET4737659962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:07.612575054 CET5996247376154.216.16.38192.168.2.14
                                    Nov 2, 2024 15:38:07.612637997 CET4737659962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:07.618452072 CET5996247376154.216.16.38192.168.2.14
                                    Nov 2, 2024 15:38:08.493181944 CET5996247376154.216.16.38192.168.2.14
                                    Nov 2, 2024 15:38:08.493385077 CET4737659962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:08.493385077 CET4737659962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:08.502052069 CET4737859962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:08.507383108 CET5996247378154.216.16.38192.168.2.14
                                    Nov 2, 2024 15:38:08.507478952 CET4737859962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:08.508299112 CET4737859962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:08.513101101 CET5996247378154.216.16.38192.168.2.14
                                    Nov 2, 2024 15:38:08.513199091 CET4737859962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:08.517968893 CET5996247378154.216.16.38192.168.2.14
                                    Nov 2, 2024 15:38:09.381093025 CET5996247378154.216.16.38192.168.2.14
                                    Nov 2, 2024 15:38:09.381383896 CET4737859962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:09.381485939 CET4737859962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:09.389822006 CET4738059962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:09.394696951 CET5996247380154.216.16.38192.168.2.14
                                    Nov 2, 2024 15:38:09.394757032 CET4738059962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:09.395626068 CET4738059962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:09.400350094 CET5996247380154.216.16.38192.168.2.14
                                    Nov 2, 2024 15:38:09.400403023 CET4738059962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:09.405214071 CET5996247380154.216.16.38192.168.2.14
                                    Nov 2, 2024 15:38:11.137495041 CET5996247380154.216.16.38192.168.2.14
                                    Nov 2, 2024 15:38:11.137690067 CET4738059962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:11.137718916 CET4738059962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:11.138674021 CET5996247380154.216.16.38192.168.2.14
                                    Nov 2, 2024 15:38:11.138748884 CET4738059962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:11.138894081 CET5996247380154.216.16.38192.168.2.14
                                    Nov 2, 2024 15:38:11.138945103 CET4738059962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:11.139383078 CET5996247380154.216.16.38192.168.2.14
                                    Nov 2, 2024 15:38:11.139463902 CET4738059962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:11.149511099 CET4738259962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:11.154628038 CET5996247382154.216.16.38192.168.2.14
                                    Nov 2, 2024 15:38:11.154726982 CET4738259962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:11.155854940 CET4738259962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:11.160672903 CET5996247382154.216.16.38192.168.2.14
                                    Nov 2, 2024 15:38:11.160739899 CET4738259962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:11.165481091 CET5996247382154.216.16.38192.168.2.14
                                    Nov 2, 2024 15:38:12.025686026 CET5996247382154.216.16.38192.168.2.14
                                    Nov 2, 2024 15:38:12.026022911 CET4738259962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:12.026057959 CET4738259962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:12.034792900 CET4738459962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:12.039582014 CET5996247384154.216.16.38192.168.2.14
                                    Nov 2, 2024 15:38:12.039685965 CET4738459962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:12.040759087 CET4738459962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:12.045514107 CET5996247384154.216.16.38192.168.2.14
                                    Nov 2, 2024 15:38:12.045581102 CET4738459962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:12.050327063 CET5996247384154.216.16.38192.168.2.14
                                    Nov 2, 2024 15:38:12.951064110 CET5996247384154.216.16.38192.168.2.14
                                    Nov 2, 2024 15:38:12.951440096 CET4738459962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:12.951440096 CET4738459962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:12.960381985 CET4738659962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:12.965432882 CET5996247386154.216.16.38192.168.2.14
                                    Nov 2, 2024 15:38:12.965523958 CET4738659962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:12.966603041 CET4738659962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:12.972376108 CET5996247386154.216.16.38192.168.2.14
                                    Nov 2, 2024 15:38:12.972444057 CET4738659962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:12.977266073 CET5996247386154.216.16.38192.168.2.14
                                    Nov 2, 2024 15:38:13.870620966 CET5996247386154.216.16.38192.168.2.14
                                    Nov 2, 2024 15:38:13.870884895 CET4738659962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:13.870884895 CET4738659962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:13.881287098 CET4738859962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:13.886140108 CET5996247388154.216.16.38192.168.2.14
                                    Nov 2, 2024 15:38:13.886236906 CET4738859962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:13.887171984 CET4738859962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:13.891968012 CET5996247388154.216.16.38192.168.2.14
                                    Nov 2, 2024 15:38:13.892067909 CET4738859962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:13.896914959 CET5996247388154.216.16.38192.168.2.14
                                    Nov 2, 2024 15:38:14.770572901 CET5996247388154.216.16.38192.168.2.14
                                    Nov 2, 2024 15:38:14.770587921 CET5996247388154.216.16.38192.168.2.14
                                    Nov 2, 2024 15:38:14.770914078 CET4738859962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:14.770914078 CET4738859962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:14.771049023 CET4738859962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:14.780493021 CET4739059962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:14.785336018 CET5996247390154.216.16.38192.168.2.14
                                    Nov 2, 2024 15:38:14.785402060 CET4739059962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:14.786360025 CET4739059962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:14.791439056 CET5996247390154.216.16.38192.168.2.14
                                    Nov 2, 2024 15:38:14.791492939 CET4739059962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:14.796351910 CET5996247390154.216.16.38192.168.2.14
                                    Nov 2, 2024 15:38:15.653098106 CET5996247390154.216.16.38192.168.2.14
                                    Nov 2, 2024 15:38:15.653516054 CET4739059962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:15.653516054 CET4739059962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:15.662092924 CET4739259962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:15.666940928 CET5996247392154.216.16.38192.168.2.14
                                    Nov 2, 2024 15:38:15.667037964 CET4739259962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:15.667892933 CET4739259962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:15.672733068 CET5996247392154.216.16.38192.168.2.14
                                    Nov 2, 2024 15:38:15.672802925 CET4739259962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:15.677745104 CET5996247392154.216.16.38192.168.2.14
                                    Nov 2, 2024 15:38:16.567812920 CET5996247392154.216.16.38192.168.2.14
                                    Nov 2, 2024 15:38:16.568049908 CET4739259962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:16.568120956 CET4739259962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:16.576822042 CET4739459962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:16.581708908 CET5996247394154.216.16.38192.168.2.14
                                    Nov 2, 2024 15:38:16.581765890 CET4739459962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:16.582545996 CET4739459962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:16.587532043 CET5996247394154.216.16.38192.168.2.14
                                    Nov 2, 2024 15:38:16.587584972 CET4739459962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:16.592643976 CET5996247394154.216.16.38192.168.2.14
                                    Nov 2, 2024 15:38:17.483061075 CET5996247394154.216.16.38192.168.2.14
                                    Nov 2, 2024 15:38:17.483097076 CET5996247394154.216.16.38192.168.2.14
                                    Nov 2, 2024 15:38:17.483299971 CET4739459962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:17.483299971 CET4739459962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:17.483519077 CET4739459962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:17.493541002 CET4739659962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:17.498383045 CET5996247396154.216.16.38192.168.2.14
                                    Nov 2, 2024 15:38:17.498469114 CET4739659962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:17.499583006 CET4739659962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:17.504406929 CET5996247396154.216.16.38192.168.2.14
                                    Nov 2, 2024 15:38:17.504467964 CET4739659962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:17.509260893 CET5996247396154.216.16.38192.168.2.14
                                    Nov 2, 2024 15:38:18.378031969 CET5996247396154.216.16.38192.168.2.14
                                    Nov 2, 2024 15:38:18.378228903 CET4739659962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:18.378233910 CET5996247396154.216.16.38192.168.2.14
                                    Nov 2, 2024 15:38:18.378293991 CET4739659962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:18.378365993 CET4739659962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:18.387245893 CET4739859962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:18.392146111 CET5996247398154.216.16.38192.168.2.14
                                    Nov 2, 2024 15:38:18.392225981 CET4739859962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:18.393280983 CET4739859962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:18.398040056 CET5996247398154.216.16.38192.168.2.14
                                    Nov 2, 2024 15:38:18.398106098 CET4739859962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:18.402874947 CET5996247398154.216.16.38192.168.2.14
                                    Nov 2, 2024 15:38:19.299143076 CET5996247398154.216.16.38192.168.2.14
                                    Nov 2, 2024 15:38:19.299323082 CET4739859962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:19.299360991 CET4739859962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:19.528168917 CET5996247398154.216.16.38192.168.2.14
                                    Nov 2, 2024 15:38:19.528466940 CET4739859962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:19.530745983 CET4740059962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:19.535628080 CET5996247400154.216.16.38192.168.2.14
                                    Nov 2, 2024 15:38:19.535696030 CET4740059962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:19.536726952 CET4740059962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:19.541480064 CET5996247400154.216.16.38192.168.2.14
                                    Nov 2, 2024 15:38:19.541524887 CET4740059962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:19.546480894 CET5996247400154.216.16.38192.168.2.14
                                    Nov 2, 2024 15:38:20.420366049 CET5996247400154.216.16.38192.168.2.14
                                    Nov 2, 2024 15:38:20.420387030 CET5996247400154.216.16.38192.168.2.14
                                    Nov 2, 2024 15:38:20.420408964 CET5996247400154.216.16.38192.168.2.14
                                    Nov 2, 2024 15:38:20.420491934 CET4740059962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:20.420491934 CET4740059962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:20.420491934 CET4740059962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:20.420684099 CET4740059962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:20.429454088 CET4740259962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:20.434372902 CET5996247402154.216.16.38192.168.2.14
                                    Nov 2, 2024 15:38:20.434448004 CET4740259962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:20.435400009 CET4740259962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:20.440217972 CET5996247402154.216.16.38192.168.2.14
                                    Nov 2, 2024 15:38:20.440279961 CET4740259962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:20.445163965 CET5996247402154.216.16.38192.168.2.14
                                    Nov 2, 2024 15:38:21.358680964 CET5996247402154.216.16.38192.168.2.14
                                    Nov 2, 2024 15:38:21.358846903 CET4740259962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:21.358995914 CET4740259962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:21.367994070 CET4740459962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:21.372844934 CET5996247404154.216.16.38192.168.2.14
                                    Nov 2, 2024 15:38:21.372916937 CET4740459962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:21.374588013 CET4740459962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:21.379354000 CET5996247404154.216.16.38192.168.2.14
                                    Nov 2, 2024 15:38:21.379406929 CET4740459962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:21.384131908 CET5996247404154.216.16.38192.168.2.14
                                    Nov 2, 2024 15:38:22.282627106 CET5996247404154.216.16.38192.168.2.14
                                    Nov 2, 2024 15:38:22.282809973 CET4740459962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:22.282872915 CET4740459962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:22.292066097 CET4740659962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:22.298268080 CET5996247406154.216.16.38192.168.2.14
                                    Nov 2, 2024 15:38:22.298340082 CET4740659962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:22.299335957 CET4740659962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:22.304197073 CET5996247406154.216.16.38192.168.2.14
                                    Nov 2, 2024 15:38:22.304264069 CET4740659962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:22.309120893 CET5996247406154.216.16.38192.168.2.14
                                    Nov 2, 2024 15:38:32.306417942 CET4740659962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:38:32.311323881 CET5996247406154.216.16.38192.168.2.14
                                    Nov 2, 2024 15:38:32.571492910 CET5996247406154.216.16.38192.168.2.14
                                    Nov 2, 2024 15:38:32.571706057 CET4740659962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:39:32.606683969 CET4740659962192.168.2.14154.216.16.38
                                    Nov 2, 2024 15:39:32.611737967 CET5996247406154.216.16.38192.168.2.14
                                    Nov 2, 2024 15:39:32.870861053 CET5996247406154.216.16.38192.168.2.14
                                    Nov 2, 2024 15:39:32.871057034 CET4740659962192.168.2.14154.216.16.38
                                    TimestampSource PortDest PortSource IPDest IP
                                    Nov 2, 2024 15:38:00.248895884 CET5059053192.168.2.148.8.8.8
                                    Nov 2, 2024 15:38:00.255628109 CET53505908.8.8.8192.168.2.14
                                    Nov 2, 2024 15:38:01.190677881 CET5648853192.168.2.148.8.8.8
                                    Nov 2, 2024 15:38:01.197784901 CET53564888.8.8.8192.168.2.14
                                    Nov 2, 2024 15:38:02.083508968 CET3906153192.168.2.148.8.8.8
                                    Nov 2, 2024 15:38:02.090195894 CET53390618.8.8.8192.168.2.14
                                    Nov 2, 2024 15:38:03.003510952 CET4711253192.168.2.148.8.8.8
                                    Nov 2, 2024 15:38:03.042954922 CET53471128.8.8.8192.168.2.14
                                    Nov 2, 2024 15:38:03.964941025 CET5079053192.168.2.148.8.8.8
                                    Nov 2, 2024 15:38:03.972016096 CET53507908.8.8.8192.168.2.14
                                    Nov 2, 2024 15:38:04.861912012 CET4238253192.168.2.148.8.8.8
                                    Nov 2, 2024 15:38:04.868834019 CET53423828.8.8.8192.168.2.14
                                    Nov 2, 2024 15:38:05.761450052 CET4158353192.168.2.148.8.8.8
                                    Nov 2, 2024 15:38:05.768170118 CET53415838.8.8.8192.168.2.14
                                    Nov 2, 2024 15:38:06.675770044 CET4209253192.168.2.148.8.8.8
                                    Nov 2, 2024 15:38:06.682918072 CET53420928.8.8.8192.168.2.14
                                    Nov 2, 2024 15:38:07.593676090 CET5140753192.168.2.148.8.8.8
                                    Nov 2, 2024 15:38:07.601325989 CET53514078.8.8.8192.168.2.14
                                    Nov 2, 2024 15:38:08.494215012 CET3602353192.168.2.148.8.8.8
                                    Nov 2, 2024 15:38:08.501648903 CET53360238.8.8.8192.168.2.14
                                    Nov 2, 2024 15:38:09.382649899 CET6094653192.168.2.148.8.8.8
                                    Nov 2, 2024 15:38:09.389367104 CET53609468.8.8.8192.168.2.14
                                    Nov 2, 2024 15:38:11.139053106 CET4552753192.168.2.148.8.8.8
                                    Nov 2, 2024 15:38:11.149015903 CET53455278.8.8.8192.168.2.14
                                    Nov 2, 2024 15:38:12.027287006 CET5039153192.168.2.148.8.8.8
                                    Nov 2, 2024 15:38:12.034184933 CET53503918.8.8.8192.168.2.14
                                    Nov 2, 2024 15:38:12.952636003 CET4006153192.168.2.148.8.8.8
                                    Nov 2, 2024 15:38:12.959769011 CET53400618.8.8.8192.168.2.14
                                    Nov 2, 2024 15:38:13.872041941 CET4218453192.168.2.148.8.8.8
                                    Nov 2, 2024 15:38:13.880661964 CET53421848.8.8.8192.168.2.14
                                    Nov 2, 2024 15:38:14.772461891 CET3614253192.168.2.148.8.8.8
                                    Nov 2, 2024 15:38:14.779997110 CET53361428.8.8.8192.168.2.14
                                    Nov 2, 2024 15:38:15.654563904 CET3833253192.168.2.148.8.8.8
                                    Nov 2, 2024 15:38:15.661633968 CET53383328.8.8.8192.168.2.14
                                    Nov 2, 2024 15:38:16.569240093 CET5010453192.168.2.148.8.8.8
                                    Nov 2, 2024 15:38:16.576322079 CET53501048.8.8.8192.168.2.14
                                    Nov 2, 2024 15:38:17.484961987 CET4782653192.168.2.148.8.8.8
                                    Nov 2, 2024 15:38:17.492938995 CET53478268.8.8.8192.168.2.14
                                    Nov 2, 2024 15:38:18.379832029 CET5602453192.168.2.148.8.8.8
                                    Nov 2, 2024 15:38:18.386615992 CET53560248.8.8.8192.168.2.14
                                    Nov 2, 2024 15:38:19.300539017 CET3938853192.168.2.148.8.8.8
                                    Nov 2, 2024 15:38:19.529891014 CET53393888.8.8.8192.168.2.14
                                    Nov 2, 2024 15:38:20.421919107 CET3442053192.168.2.148.8.8.8
                                    Nov 2, 2024 15:38:20.428924084 CET53344208.8.8.8192.168.2.14
                                    Nov 2, 2024 15:38:21.360435009 CET3916953192.168.2.148.8.8.8
                                    Nov 2, 2024 15:38:21.367463112 CET53391698.8.8.8192.168.2.14
                                    Nov 2, 2024 15:38:22.284084082 CET5494053192.168.2.148.8.8.8
                                    Nov 2, 2024 15:38:22.291555882 CET53549408.8.8.8192.168.2.14
                                    TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                    Nov 2, 2024 15:38:00.248895884 CET192.168.2.148.8.8.80x17f3Standard query (0)server.myway-ing.winA (IP address)IN (0x0001)false
                                    Nov 2, 2024 15:38:01.190677881 CET192.168.2.148.8.8.80x2100Standard query (0)server.myway-ing.winA (IP address)IN (0x0001)false
                                    Nov 2, 2024 15:38:02.083508968 CET192.168.2.148.8.8.80x22a4Standard query (0)server.myway-ing.winA (IP address)IN (0x0001)false
                                    Nov 2, 2024 15:38:03.003510952 CET192.168.2.148.8.8.80xd09bStandard query (0)server.myway-ing.winA (IP address)IN (0x0001)false
                                    Nov 2, 2024 15:38:03.964941025 CET192.168.2.148.8.8.80xb06dStandard query (0)server.myway-ing.winA (IP address)IN (0x0001)false
                                    Nov 2, 2024 15:38:04.861912012 CET192.168.2.148.8.8.80x27dfStandard query (0)server.myway-ing.winA (IP address)IN (0x0001)false
                                    Nov 2, 2024 15:38:05.761450052 CET192.168.2.148.8.8.80xf26dStandard query (0)server.myway-ing.winA (IP address)IN (0x0001)false
                                    Nov 2, 2024 15:38:06.675770044 CET192.168.2.148.8.8.80x6b36Standard query (0)server.myway-ing.winA (IP address)IN (0x0001)false
                                    Nov 2, 2024 15:38:07.593676090 CET192.168.2.148.8.8.80x66f4Standard query (0)server.myway-ing.winA (IP address)IN (0x0001)false
                                    Nov 2, 2024 15:38:08.494215012 CET192.168.2.148.8.8.80xe322Standard query (0)server.myway-ing.winA (IP address)IN (0x0001)false
                                    Nov 2, 2024 15:38:09.382649899 CET192.168.2.148.8.8.80x58ffStandard query (0)server.myway-ing.winA (IP address)IN (0x0001)false
                                    Nov 2, 2024 15:38:11.139053106 CET192.168.2.148.8.8.80x6413Standard query (0)server.myway-ing.winA (IP address)IN (0x0001)false
                                    Nov 2, 2024 15:38:12.027287006 CET192.168.2.148.8.8.80xb11Standard query (0)server.myway-ing.winA (IP address)IN (0x0001)false
                                    Nov 2, 2024 15:38:12.952636003 CET192.168.2.148.8.8.80x5c97Standard query (0)server.myway-ing.winA (IP address)IN (0x0001)false
                                    Nov 2, 2024 15:38:13.872041941 CET192.168.2.148.8.8.80x6cd4Standard query (0)server.myway-ing.winA (IP address)IN (0x0001)false
                                    Nov 2, 2024 15:38:14.772461891 CET192.168.2.148.8.8.80x295bStandard query (0)server.myway-ing.winA (IP address)IN (0x0001)false
                                    Nov 2, 2024 15:38:15.654563904 CET192.168.2.148.8.8.80x4f50Standard query (0)server.myway-ing.winA (IP address)IN (0x0001)false
                                    Nov 2, 2024 15:38:16.569240093 CET192.168.2.148.8.8.80x6b72Standard query (0)server.myway-ing.winA (IP address)IN (0x0001)false
                                    Nov 2, 2024 15:38:17.484961987 CET192.168.2.148.8.8.80x5918Standard query (0)server.myway-ing.winA (IP address)IN (0x0001)false
                                    Nov 2, 2024 15:38:18.379832029 CET192.168.2.148.8.8.80xb2acStandard query (0)server.myway-ing.winA (IP address)IN (0x0001)false
                                    Nov 2, 2024 15:38:19.300539017 CET192.168.2.148.8.8.80x9469Standard query (0)server.myway-ing.winA (IP address)IN (0x0001)false
                                    Nov 2, 2024 15:38:20.421919107 CET192.168.2.148.8.8.80xc489Standard query (0)server.myway-ing.winA (IP address)IN (0x0001)false
                                    Nov 2, 2024 15:38:21.360435009 CET192.168.2.148.8.8.80x3fc6Standard query (0)server.myway-ing.winA (IP address)IN (0x0001)false
                                    Nov 2, 2024 15:38:22.284084082 CET192.168.2.148.8.8.80xaeceStandard query (0)server.myway-ing.winA (IP address)IN (0x0001)false
                                    TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                    Nov 2, 2024 15:38:00.255628109 CET8.8.8.8192.168.2.140x17f3No error (0)server.myway-ing.win154.216.16.38A (IP address)IN (0x0001)false
                                    Nov 2, 2024 15:38:01.197784901 CET8.8.8.8192.168.2.140x2100No error (0)server.myway-ing.win154.216.16.38A (IP address)IN (0x0001)false
                                    Nov 2, 2024 15:38:02.090195894 CET8.8.8.8192.168.2.140x22a4No error (0)server.myway-ing.win154.216.16.38A (IP address)IN (0x0001)false
                                    Nov 2, 2024 15:38:03.042954922 CET8.8.8.8192.168.2.140xd09bNo error (0)server.myway-ing.win154.216.16.38A (IP address)IN (0x0001)false
                                    Nov 2, 2024 15:38:03.972016096 CET8.8.8.8192.168.2.140xb06dNo error (0)server.myway-ing.win154.216.16.38A (IP address)IN (0x0001)false
                                    Nov 2, 2024 15:38:04.868834019 CET8.8.8.8192.168.2.140x27dfNo error (0)server.myway-ing.win154.216.16.38A (IP address)IN (0x0001)false
                                    Nov 2, 2024 15:38:05.768170118 CET8.8.8.8192.168.2.140xf26dNo error (0)server.myway-ing.win154.216.16.38A (IP address)IN (0x0001)false
                                    Nov 2, 2024 15:38:06.682918072 CET8.8.8.8192.168.2.140x6b36No error (0)server.myway-ing.win154.216.16.38A (IP address)IN (0x0001)false
                                    Nov 2, 2024 15:38:07.601325989 CET8.8.8.8192.168.2.140x66f4No error (0)server.myway-ing.win154.216.16.38A (IP address)IN (0x0001)false
                                    Nov 2, 2024 15:38:08.501648903 CET8.8.8.8192.168.2.140xe322No error (0)server.myway-ing.win154.216.16.38A (IP address)IN (0x0001)false
                                    Nov 2, 2024 15:38:09.389367104 CET8.8.8.8192.168.2.140x58ffNo error (0)server.myway-ing.win154.216.16.38A (IP address)IN (0x0001)false
                                    Nov 2, 2024 15:38:11.149015903 CET8.8.8.8192.168.2.140x6413No error (0)server.myway-ing.win154.216.16.38A (IP address)IN (0x0001)false
                                    Nov 2, 2024 15:38:12.034184933 CET8.8.8.8192.168.2.140xb11No error (0)server.myway-ing.win154.216.16.38A (IP address)IN (0x0001)false
                                    Nov 2, 2024 15:38:12.959769011 CET8.8.8.8192.168.2.140x5c97No error (0)server.myway-ing.win154.216.16.38A (IP address)IN (0x0001)false
                                    Nov 2, 2024 15:38:13.880661964 CET8.8.8.8192.168.2.140x6cd4No error (0)server.myway-ing.win154.216.16.38A (IP address)IN (0x0001)false
                                    Nov 2, 2024 15:38:14.779997110 CET8.8.8.8192.168.2.140x295bNo error (0)server.myway-ing.win154.216.16.38A (IP address)IN (0x0001)false
                                    Nov 2, 2024 15:38:15.661633968 CET8.8.8.8192.168.2.140x4f50No error (0)server.myway-ing.win154.216.16.38A (IP address)IN (0x0001)false
                                    Nov 2, 2024 15:38:16.576322079 CET8.8.8.8192.168.2.140x6b72No error (0)server.myway-ing.win154.216.16.38A (IP address)IN (0x0001)false
                                    Nov 2, 2024 15:38:17.492938995 CET8.8.8.8192.168.2.140x5918No error (0)server.myway-ing.win154.216.16.38A (IP address)IN (0x0001)false
                                    Nov 2, 2024 15:38:18.386615992 CET8.8.8.8192.168.2.140xb2acNo error (0)server.myway-ing.win154.216.16.38A (IP address)IN (0x0001)false
                                    Nov 2, 2024 15:38:19.529891014 CET8.8.8.8192.168.2.140x9469No error (0)server.myway-ing.win154.216.16.38A (IP address)IN (0x0001)false
                                    Nov 2, 2024 15:38:20.428924084 CET8.8.8.8192.168.2.140xc489No error (0)server.myway-ing.win154.216.16.38A (IP address)IN (0x0001)false
                                    Nov 2, 2024 15:38:21.367463112 CET8.8.8.8192.168.2.140x3fc6No error (0)server.myway-ing.win154.216.16.38A (IP address)IN (0x0001)false
                                    Nov 2, 2024 15:38:22.291555882 CET8.8.8.8192.168.2.140xaeceNo error (0)server.myway-ing.win154.216.16.38A (IP address)IN (0x0001)false

                                    System Behavior

                                    Start time (UTC):14:37:59
                                    Start date (UTC):02/11/2024
                                    Path:/tmp/zmap.sh4.elf
                                    Arguments:/tmp/zmap.sh4.elf
                                    File size:4139976 bytes
                                    MD5 hash:8943e5f8f8c280467b4472c15ae93ba9

                                    Start time (UTC):14:37:59
                                    Start date (UTC):02/11/2024
                                    Path:/tmp/zmap.sh4.elf
                                    Arguments:-
                                    File size:4139976 bytes
                                    MD5 hash:8943e5f8f8c280467b4472c15ae93ba9

                                    Start time (UTC):14:37:59
                                    Start date (UTC):02/11/2024
                                    Path:/tmp/zmap.sh4.elf
                                    Arguments:-
                                    File size:4139976 bytes
                                    MD5 hash:8943e5f8f8c280467b4472c15ae93ba9