Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
harm4.elf

Overview

General Information

Sample name:harm4.elf
Analysis ID:1552992
MD5:648de4e8238d1565b3b40bf88f84ff12
SHA1:c6ccc773cdff3e37e5466d0e7a0d7eb656d61cd3
SHA256:0cddf21d0971458dc4aa374b1345e8455ca213cb3bb6b3f541bb0acad1f884e4
Tags:elfuser-abuse_ch
Infos:

Detection

Score:52
Range:0 - 100
Whitelisted:false

Signatures

Multi AV Scanner detection for submitted file
Connects to many ports of the same IP (likely port scanning)
Detected TCP or UDP traffic on non-standard ports
Executes the "rm" command used to delete files or directories
Sample has stripped symbol table
Sample listens on a socket
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1552992
Start date and time:2024-11-10 06:07:03 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 30s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:harm4.elf
Detection:MAL
Classification:mal52.troj.linELF@0/0@8/0
Command:/tmp/harm4.elf
PID:6225
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
you are now apart of hail cock botnet
Standard Error:
  • system is lnxubuntu20
  • harm4.elf (PID: 6225, Parent: 6143, MD5: 5ebfcae4fe2471fcc5695c2394773ff1) Arguments: /tmp/harm4.elf
  • dash New Fork (PID: 6267, Parent: 4334)
  • rm (PID: 6267, Parent: 4334, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.Qfksf9HK6a /tmp/tmp.FvTNS7bE3S /tmp/tmp.VgzGYBwJ5D
  • dash New Fork (PID: 6268, Parent: 4334)
  • rm (PID: 6268, Parent: 4334, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.Qfksf9HK6a /tmp/tmp.FvTNS7bE3S /tmp/tmp.VgzGYBwJ5D
  • cleanup
No yara matches
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: harm4.elfReversingLabs: Detection: 13%

Networking

barindex
Source: global trafficTCP traffic: 91.149.238.18 ports 6320,14180,0,2,3,6
Source: global trafficTCP traffic: 192.168.2.23:57748 -> 31.13.248.89:7299
Source: global trafficTCP traffic: 192.168.2.23:58554 -> 91.149.238.18:6320
Source: global trafficTCP traffic: 192.168.2.23:37044 -> 86.107.100.80:2982
Source: /tmp/harm4.elf (PID: 6225)Socket: 127.0.0.1:1172Jump to behavior
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 54.171.230.55
Source: unknownTCP traffic detected without corresponding DNS query: 54.171.230.55
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownUDP traffic detected without corresponding DNS query: 178.254.22.166
Source: unknownUDP traffic detected without corresponding DNS query: 51.158.108.203
Source: unknownUDP traffic detected without corresponding DNS query: 5.161.109.23
Source: unknownUDP traffic detected without corresponding DNS query: 64.176.6.48
Source: unknownUDP traffic detected without corresponding DNS query: 178.254.22.166
Source: unknownUDP traffic detected without corresponding DNS query: 81.169.136.222
Source: unknownUDP traffic detected without corresponding DNS query: 65.21.1.106
Source: unknownUDP traffic detected without corresponding DNS query: 185.181.61.24
Source: global trafficDNS traffic detected: DNS query: kingstonwikkerink.dyn
Source: harm4.elf, 6225.1.00007f6d0802e000.00007f6d08031000.rw-.sdmpString found in binary or memory: http://hailcocks.ru/wget.sh;
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 33606
Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 33606 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443
Source: ELF static info symbol of initial sample.symtab present: no
Source: classification engineClassification label: mal52.troj.linELF@0/0@8/0
Source: /usr/bin/dash (PID: 6267)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.Qfksf9HK6a /tmp/tmp.FvTNS7bE3S /tmp/tmp.VgzGYBwJ5DJump to behavior
Source: /usr/bin/dash (PID: 6268)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.Qfksf9HK6a /tmp/tmp.FvTNS7bE3S /tmp/tmp.VgzGYBwJ5DJump to behavior
Source: /tmp/harm4.elf (PID: 6225)Queries kernel information via 'uname': Jump to behavior
Source: harm4.elf, 6225.1.000056466a0f5000.000056466a249000.rw-.sdmpBinary or memory string: jFV!/etc/qemu-binfmt/arm
Source: harm4.elf, 6225.1.000056466a0f5000.000056466a249000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/arm
Source: harm4.elf, 6225.1.00007ffc7762e000.00007ffc7764f000.rw-.sdmpBinary or memory string: /usr/bin/qemu-arm
Source: harm4.elf, 6225.1.00007ffc7762e000.00007ffc7764f000.rw-.sdmpBinary or memory string: bx86_64/usr/bin/qemu-arm/tmp/harm4.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/harm4.elf
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception1
File Deletion
OS Credential Dumping11
Security Software Discovery
Remote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Non-Standard Port
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
Non-Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture2
Application Layer Protocol
Traffic DuplicationData Destruction
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1552992 Sample: harm4.elf Startdate: 10/11/2024 Architecture: LINUX Score: 52 15 91.149.238.18, 14180, 37756, 58554 MARTON-ASPL Poland 2->15 17 31.13.248.89, 57748, 7299 NETERRA-ASBG Bulgaria 2->17 19 6 other IPs or domains 2->19 21 Multi AV Scanner detection for submitted file 2->21 23 Connects to many ports of the same IP (likely port scanning) 2->23 7 harm4.elf 2->7         started        9 dash rm 2->9         started        11 dash rm 2->11         started        signatures3 process4 process5 13 harm4.elf 7->13         started       
SourceDetectionScannerLabelLink
harm4.elf13%ReversingLabsLinux.Backdoor.Mirai
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
kingstonwikkerink.dyn
193.233.193.45
truefalse
    high
    NameSourceMaliciousAntivirus DetectionReputation
    http://hailcocks.ru/wget.sh;harm4.elf, 6225.1.00007f6d0802e000.00007f6d08031000.rw-.sdmpfalse
      high
      • No. of IPs < 25%
      • 25% < No. of IPs < 50%
      • 50% < No. of IPs < 75%
      • 75% < No. of IPs
      IPDomainCountryFlagASNASN NameMalicious
      109.202.202.202
      unknownSwitzerland
      13030INIT7CHfalse
      31.13.248.89
      unknownBulgaria
      34224NETERRA-ASBGfalse
      86.107.100.80
      unknownRomania
      38995AMG-ASROfalse
      54.171.230.55
      unknownUnited States
      16509AMAZON-02USfalse
      91.149.238.18
      unknownPoland
      41952MARTON-ASPLtrue
      91.189.91.43
      unknownUnited Kingdom
      41231CANONICAL-ASGBfalse
      91.189.91.42
      unknownUnited Kingdom
      41231CANONICAL-ASGBfalse
      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
      54.171.230.55dlr.x86.elfGet hashmaliciousMirai, OkiruBrowse
        tyo2831qq.mips.elfGet hashmaliciousGafgyt, MiraiBrowse
          vsbeps.elfGet hashmaliciousGafgyt, MiraiBrowse
            .i.elfGet hashmaliciousUnknownBrowse
              SecuriteInfo.com.Trojan.Linux.GenericKD.24576.21247.15812.elfGet hashmaliciousUnknownBrowse
                .i.elfGet hashmaliciousUnknownBrowse
                  SecuriteInfo.com.Trojan.Linux.GenericKD.24482.28831.19228.elfGet hashmaliciousUnknownBrowse
                    ub8ehJSePAfc9FYqZIT6.x86_64.elfGet hashmaliciousUnknownBrowse
                      linux_ppc64el.elfGet hashmaliciousChaosBrowse
                        main_mpsl.elfGet hashmaliciousMiraiBrowse
                          109.202.202.202kpLwzBouH4.elfGet hashmaliciousUnknownBrowse
                          • ch.archive.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_92.0%2bbuild3-0ubuntu0.20.04.1_amd64.deb
                          31.13.248.89nshsh4.elfGet hashmaliciousUnknownBrowse
                            nsharm7.elfGet hashmaliciousUnknownBrowse
                              nshppc.elfGet hashmaliciousUnknownBrowse
                                nshmips.elfGet hashmaliciousUnknownBrowse
                                  harm5.elfGet hashmaliciousUnknownBrowse
                                    arm7.elfGet hashmaliciousUnknownBrowse
                                      mpsl.elfGet hashmaliciousUnknownBrowse
                                        arm4.elfGet hashmaliciousUnknownBrowse
                                          tarm6.elfGet hashmaliciousMiraiBrowse
                                            mpsl.elfGet hashmaliciousUnknownBrowse
                                              86.107.100.80nsharm7.elfGet hashmaliciousUnknownBrowse
                                                nsharm5.elfGet hashmaliciousUnknownBrowse
                                                  nsharm.elfGet hashmaliciousUnknownBrowse
                                                    nshppc.elfGet hashmaliciousUnknownBrowse
                                                      nshmips.elfGet hashmaliciousUnknownBrowse
                                                        harm5.elfGet hashmaliciousUnknownBrowse
                                                          harm4.elfGet hashmaliciousUnknownBrowse
                                                            mpsl.elfGet hashmaliciousUnknownBrowse
                                                              arm5.elfGet hashmaliciousUnknownBrowse
                                                                arm4.elfGet hashmaliciousUnknownBrowse
                                                                  MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                  kingstonwikkerink.dynnshsh4.elfGet hashmaliciousUnknownBrowse
                                                                  • 81.29.149.178
                                                                  nsharm7.elfGet hashmaliciousUnknownBrowse
                                                                  • 91.149.218.232
                                                                  nsharm5.elfGet hashmaliciousUnknownBrowse
                                                                  • 217.28.130.41
                                                                  nsharm.elfGet hashmaliciousUnknownBrowse
                                                                  • 81.29.149.178
                                                                  nshppc.elfGet hashmaliciousUnknownBrowse
                                                                  • 217.28.130.41
                                                                  nshmips.elfGet hashmaliciousUnknownBrowse
                                                                  • 31.13.248.89
                                                                  ppc.elfGet hashmaliciousMiraiBrowse
                                                                  • 91.149.238.18
                                                                  tarm7.elfGet hashmaliciousMiraiBrowse
                                                                  • 213.182.204.57
                                                                  tppc.elfGet hashmaliciousMiraiBrowse
                                                                  • 88.151.195.22
                                                                  harm5.elfGet hashmaliciousUnknownBrowse
                                                                  • 217.28.130.41
                                                                  MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                  NETERRA-ASBGnshsh4.elfGet hashmaliciousUnknownBrowse
                                                                  • 31.13.248.89
                                                                  nsharm7.elfGet hashmaliciousUnknownBrowse
                                                                  • 31.13.248.89
                                                                  nshppc.elfGet hashmaliciousUnknownBrowse
                                                                  • 31.13.248.89
                                                                  nshmips.elfGet hashmaliciousUnknownBrowse
                                                                  • 31.13.248.89
                                                                  harm5.elfGet hashmaliciousUnknownBrowse
                                                                  • 31.13.248.89
                                                                  arm7.elfGet hashmaliciousUnknownBrowse
                                                                  • 31.13.248.89
                                                                  mpsl.elfGet hashmaliciousUnknownBrowse
                                                                  • 31.13.248.89
                                                                  arm4.elfGet hashmaliciousUnknownBrowse
                                                                  • 31.13.248.89
                                                                  tarm6.elfGet hashmaliciousMiraiBrowse
                                                                  • 31.13.248.89
                                                                  sora.arm7.elfGet hashmaliciousUnknownBrowse
                                                                  • 87.121.79.128
                                                                  AMAZON-02USfile.exeGet hashmaliciousPureCrypter, LummaC, Amadey, LummaC Stealer, Stealc, VidarBrowse
                                                                  • 18.244.18.27
                                                                  file.exeGet hashmaliciousAmadey, Stealc, VidarBrowse
                                                                  • 18.154.84.35
                                                                  mpsl.elfGet hashmaliciousMirai, MoobotBrowse
                                                                  • 157.175.231.10
                                                                  x86.elfGet hashmaliciousMirai, MoobotBrowse
                                                                  • 44.244.38.47
                                                                  bot.x86_64.elfGet hashmaliciousMirai, OkiruBrowse
                                                                  • 34.249.145.219
                                                                  https://qrco.de/bfYBpcGet hashmaliciousHtmlDropper, HTMLPhisherBrowse
                                                                  • 3.161.82.88
                                                                  arm7.elfGet hashmaliciousMirai, MoobotBrowse
                                                                  • 54.127.50.241
                                                                  file.exeGet hashmaliciousPureCrypter, LummaC, Amadey, LummaC Stealer, Stealc, VidarBrowse
                                                                  • 108.156.211.71
                                                                  main_ppc.elfGet hashmaliciousUnknownBrowse
                                                                  • 34.249.145.219
                                                                  main_mpsl.elfGet hashmaliciousUnknownBrowse
                                                                  • 34.243.160.129
                                                                  INIT7CHarm.elfGet hashmaliciousUnknownBrowse
                                                                  • 109.202.202.202
                                                                  sshd.elfGet hashmaliciousUnknownBrowse
                                                                  • 109.202.202.202
                                                                  sh4.elfGet hashmaliciousUnknownBrowse
                                                                  • 109.202.202.202
                                                                  arm6.elfGet hashmaliciousUnknownBrowse
                                                                  • 109.202.202.202
                                                                  arm5.elfGet hashmaliciousUnknownBrowse
                                                                  • 109.202.202.202
                                                                  ppc.elfGet hashmaliciousUnknownBrowse
                                                                  • 109.202.202.202
                                                                  arm.elfGet hashmaliciousUnknownBrowse
                                                                  • 109.202.202.202
                                                                  m68k.elfGet hashmaliciousUnknownBrowse
                                                                  • 109.202.202.202
                                                                  x86.elfGet hashmaliciousUnknownBrowse
                                                                  • 109.202.202.202
                                                                  spc.elfGet hashmaliciousUnknownBrowse
                                                                  • 109.202.202.202
                                                                  AMG-ASROnsharm7.elfGet hashmaliciousUnknownBrowse
                                                                  • 86.107.100.80
                                                                  nsharm5.elfGet hashmaliciousUnknownBrowse
                                                                  • 86.107.100.80
                                                                  nsharm.elfGet hashmaliciousUnknownBrowse
                                                                  • 86.107.100.80
                                                                  nshppc.elfGet hashmaliciousUnknownBrowse
                                                                  • 86.107.100.80
                                                                  nshmips.elfGet hashmaliciousUnknownBrowse
                                                                  • 86.107.100.80
                                                                  harm5.elfGet hashmaliciousUnknownBrowse
                                                                  • 86.107.100.80
                                                                  harm4.elfGet hashmaliciousUnknownBrowse
                                                                  • 86.107.100.80
                                                                  mpsl.elfGet hashmaliciousUnknownBrowse
                                                                  • 86.107.100.80
                                                                  arm5.elfGet hashmaliciousUnknownBrowse
                                                                  • 86.107.100.80
                                                                  arm4.elfGet hashmaliciousUnknownBrowse
                                                                  • 86.107.100.80
                                                                  No context
                                                                  No context
                                                                  No created / dropped files found
                                                                  File type:ELF 32-bit LSB executable, ARM, version 1 (ARM), statically linked, stripped
                                                                  Entropy (8bit):6.1256368507240735
                                                                  TrID:
                                                                  • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                                                                  File name:harm4.elf
                                                                  File size:61'456 bytes
                                                                  MD5:648de4e8238d1565b3b40bf88f84ff12
                                                                  SHA1:c6ccc773cdff3e37e5466d0e7a0d7eb656d61cd3
                                                                  SHA256:0cddf21d0971458dc4aa374b1345e8455ca213cb3bb6b3f541bb0acad1f884e4
                                                                  SHA512:0186300389bc2b2441823bd85f2b6d93b466a2b628b9d19a616462554b35ba59e03ac7c2480d1ddadb31ebefd30d85c58e4578c709b110bdfacacc618a703175
                                                                  SSDEEP:768:CeFqmcoUh1NDbyonPcl+1LHcfiERCmz1Nd96zV6mtMa/10VIIacHVJ8lvYy4mI:pF2vxL8f96hOaLIdYlvp
                                                                  TLSH:82534B80BD819A13C6D412BBFB6E418D372713A8D2EE7207DD259F21378696F0D7B641
                                                                  File Content Preview:.ELF...a..........(.........4...X.......4. ...(.........................................................l%..........Q.td..................................-...L."....5..........0@-.\P...0....S.0...P@...0... ....R......0...0...........0... ....R..... 0....S

                                                                  ELF header

                                                                  Class:ELF32
                                                                  Data:2's complement, little endian
                                                                  Version:1 (current)
                                                                  Machine:ARM
                                                                  Version Number:0x1
                                                                  Type:EXEC (Executable file)
                                                                  OS/ABI:ARM - ABI
                                                                  ABI Version:0
                                                                  Entry Point Address:0x8190
                                                                  Flags:0x202
                                                                  ELF Header Size:52
                                                                  Program Header Offset:52
                                                                  Program Header Size:32
                                                                  Number of Program Headers:3
                                                                  Section Header Offset:61016
                                                                  Section Header Size:40
                                                                  Number of Section Headers:11
                                                                  Header String Table Index:10
                                                                  NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                                                  NULL0x00x00x00x00x0000
                                                                  .initPROGBITS0x80940x940x180x00x6AX004
                                                                  .textPROGBITS0x80b00xb00xd6900x00x6AX0016
                                                                  .finiPROGBITS0x157400xd7400x140x00x6AX004
                                                                  .rodataPROGBITS0x157540xd7540x132c0x00x2A004
                                                                  .eh_framePROGBITS0x16a800xea800x40x00x2A004
                                                                  .ctorsPROGBITS0x1ea840xea840x80x00x3WA004
                                                                  .dtorsPROGBITS0x1ea8c0xea8c0x80x00x3WA004
                                                                  .dataPROGBITS0x1ea980xea980x3780x00x3WA004
                                                                  .bssNOBITS0x1ee100xee100x21e00x00x3WA004
                                                                  .shstrtabSTRTAB0x00xee100x480x00x0001
                                                                  TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                                  LOAD0x00x80000x80000xea840xea846.16410x5R E0x8000.init .text .fini .rodata .eh_frame
                                                                  LOAD0xea840x1ea840x1ea840x38c0x256c2.81240x6RW 0x8000.ctors .dtors .data .bss
                                                                  GNU_STACK0x00x00x00x00x00.00000x7RWE0x4
                                                                  TimestampSource PortDest PortSource IPDest IP
                                                                  Nov 10, 2024 06:07:48.004532099 CET43928443192.168.2.2391.189.91.42
                                                                  Nov 10, 2024 06:07:50.398462057 CET577487299192.168.2.2331.13.248.89
                                                                  Nov 10, 2024 06:07:50.403295040 CET72995774831.13.248.89192.168.2.23
                                                                  Nov 10, 2024 06:07:50.403342962 CET577487299192.168.2.2331.13.248.89
                                                                  Nov 10, 2024 06:07:50.403456926 CET577487299192.168.2.2331.13.248.89
                                                                  Nov 10, 2024 06:07:50.408204079 CET72995774831.13.248.89192.168.2.23
                                                                  Nov 10, 2024 06:07:50.408252001 CET577487299192.168.2.2331.13.248.89
                                                                  Nov 10, 2024 06:07:50.412986994 CET72995774831.13.248.89192.168.2.23
                                                                  Nov 10, 2024 06:07:51.413741112 CET72995774831.13.248.89192.168.2.23
                                                                  Nov 10, 2024 06:07:51.414087057 CET577487299192.168.2.2331.13.248.89
                                                                  Nov 10, 2024 06:07:51.414170980 CET577487299192.168.2.2331.13.248.89
                                                                  Nov 10, 2024 06:07:53.379759073 CET42836443192.168.2.2391.189.91.43
                                                                  Nov 10, 2024 06:07:54.915605068 CET4251680192.168.2.23109.202.202.202
                                                                  Nov 10, 2024 06:08:08.481595039 CET43928443192.168.2.2391.189.91.42
                                                                  Nov 10, 2024 06:08:11.461867094 CET585546320192.168.2.2391.149.238.18
                                                                  Nov 10, 2024 06:08:11.466691971 CET63205855491.149.238.18192.168.2.23
                                                                  Nov 10, 2024 06:08:11.466754913 CET585546320192.168.2.2391.149.238.18
                                                                  Nov 10, 2024 06:08:11.466799974 CET585546320192.168.2.2391.149.238.18
                                                                  Nov 10, 2024 06:08:11.471625090 CET63205855491.149.238.18192.168.2.23
                                                                  Nov 10, 2024 06:08:11.471673012 CET585546320192.168.2.2391.149.238.18
                                                                  Nov 10, 2024 06:08:11.476519108 CET63205855491.149.238.18192.168.2.23
                                                                  Nov 10, 2024 06:08:12.347404003 CET63205855491.149.238.18192.168.2.23
                                                                  Nov 10, 2024 06:08:12.347539902 CET585546320192.168.2.2391.149.238.18
                                                                  Nov 10, 2024 06:08:12.347585917 CET585546320192.168.2.2391.149.238.18
                                                                  Nov 10, 2024 06:08:17.376641989 CET3775614180192.168.2.2391.149.238.18
                                                                  Nov 10, 2024 06:08:17.381534100 CET141803775691.149.238.18192.168.2.23
                                                                  Nov 10, 2024 06:08:17.381652117 CET3775614180192.168.2.2391.149.238.18
                                                                  Nov 10, 2024 06:08:17.381671906 CET3775614180192.168.2.2391.149.238.18
                                                                  Nov 10, 2024 06:08:17.386610031 CET141803775691.149.238.18192.168.2.23
                                                                  Nov 10, 2024 06:08:17.386691093 CET3775614180192.168.2.2391.149.238.18
                                                                  Nov 10, 2024 06:08:17.391529083 CET141803775691.149.238.18192.168.2.23
                                                                  Nov 10, 2024 06:08:18.251246929 CET141803775691.149.238.18192.168.2.23
                                                                  Nov 10, 2024 06:08:18.251463890 CET3775614180192.168.2.2391.149.238.18
                                                                  Nov 10, 2024 06:08:18.251548052 CET3775614180192.168.2.2391.149.238.18
                                                                  Nov 10, 2024 06:08:20.767817974 CET42836443192.168.2.2391.189.91.43
                                                                  Nov 10, 2024 06:08:23.287868977 CET370442982192.168.2.2386.107.100.80
                                                                  Nov 10, 2024 06:08:23.292823076 CET29823704486.107.100.80192.168.2.23
                                                                  Nov 10, 2024 06:08:23.292918921 CET370442982192.168.2.2386.107.100.80
                                                                  Nov 10, 2024 06:08:23.292939901 CET370442982192.168.2.2386.107.100.80
                                                                  Nov 10, 2024 06:08:23.297758102 CET29823704486.107.100.80192.168.2.23
                                                                  Nov 10, 2024 06:08:23.297821045 CET370442982192.168.2.2386.107.100.80
                                                                  Nov 10, 2024 06:08:23.302777052 CET29823704486.107.100.80192.168.2.23
                                                                  Nov 10, 2024 06:08:24.708735943 CET33606443192.168.2.2354.171.230.55
                                                                  Nov 10, 2024 06:08:24.715873957 CET4433360654.171.230.55192.168.2.23
                                                                  Nov 10, 2024 06:08:24.716146946 CET33606443192.168.2.2354.171.230.55
                                                                  Nov 10, 2024 06:08:24.863101006 CET4251680192.168.2.23109.202.202.202
                                                                  Nov 10, 2024 06:08:33.301680088 CET370442982192.168.2.2386.107.100.80
                                                                  Nov 10, 2024 06:08:33.306602001 CET29823704486.107.100.80192.168.2.23
                                                                  Nov 10, 2024 06:08:33.866852999 CET29823704486.107.100.80192.168.2.23
                                                                  Nov 10, 2024 06:08:33.867113113 CET370442982192.168.2.2386.107.100.80
                                                                  Nov 10, 2024 06:08:49.435642004 CET43928443192.168.2.2391.189.91.42
                                                                  TimestampSource PortDest PortSource IPDest IP
                                                                  Nov 10, 2024 06:07:45.376969099 CET4364753192.168.2.23178.254.22.166
                                                                  Nov 10, 2024 06:07:50.382458925 CET4855753192.168.2.2351.158.108.203
                                                                  Nov 10, 2024 06:07:50.397749901 CET534855751.158.108.203192.168.2.23
                                                                  Nov 10, 2024 06:07:56.416402102 CET6047253192.168.2.235.161.109.23
                                                                  Nov 10, 2024 06:08:01.422065973 CET5748953192.168.2.2364.176.6.48
                                                                  Nov 10, 2024 06:08:06.427800894 CET4983953192.168.2.23178.254.22.166
                                                                  Nov 10, 2024 06:08:11.434017897 CET4028553192.168.2.2381.169.136.222
                                                                  Nov 10, 2024 06:08:11.461129904 CET534028581.169.136.222192.168.2.23
                                                                  Nov 10, 2024 06:08:17.349225998 CET3348853192.168.2.2365.21.1.106
                                                                  Nov 10, 2024 06:08:17.376144886 CET533348865.21.1.106192.168.2.23
                                                                  Nov 10, 2024 06:08:23.253739119 CET5700653192.168.2.23185.181.61.24
                                                                  Nov 10, 2024 06:08:23.286825895 CET5357006185.181.61.24192.168.2.23
                                                                  TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                                                  Nov 10, 2024 06:07:45.376969099 CET192.168.2.23178.254.22.1660x3d99Standard query (0)kingstonwikkerink.dynA (IP address)IN (0x0001)false
                                                                  Nov 10, 2024 06:07:50.382458925 CET192.168.2.2351.158.108.2030xc772Standard query (0)kingstonwikkerink.dynA (IP address)IN (0x0001)false
                                                                  Nov 10, 2024 06:07:56.416402102 CET192.168.2.235.161.109.230x9f99Standard query (0)kingstonwikkerink.dynA (IP address)IN (0x0001)false
                                                                  Nov 10, 2024 06:08:01.422065973 CET192.168.2.2364.176.6.480xbae9Standard query (0)kingstonwikkerink.dynA (IP address)IN (0x0001)false
                                                                  Nov 10, 2024 06:08:06.427800894 CET192.168.2.23178.254.22.1660x8b5cStandard query (0)kingstonwikkerink.dynA (IP address)IN (0x0001)false
                                                                  Nov 10, 2024 06:08:11.434017897 CET192.168.2.2381.169.136.2220x3c4dStandard query (0)kingstonwikkerink.dynA (IP address)IN (0x0001)false
                                                                  Nov 10, 2024 06:08:17.349225998 CET192.168.2.2365.21.1.1060xfd4bStandard query (0)kingstonwikkerink.dynA (IP address)IN (0x0001)false
                                                                  Nov 10, 2024 06:08:23.253739119 CET192.168.2.23185.181.61.240xd068Standard query (0)kingstonwikkerink.dynA (IP address)IN (0x0001)false
                                                                  TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                                                  Nov 10, 2024 06:07:50.397749901 CET51.158.108.203192.168.2.230xc772No error (0)kingstonwikkerink.dyn193.233.193.45A (IP address)IN (0x0001)false
                                                                  Nov 10, 2024 06:07:50.397749901 CET51.158.108.203192.168.2.230xc772No error (0)kingstonwikkerink.dyn81.29.149.178A (IP address)IN (0x0001)false
                                                                  Nov 10, 2024 06:07:50.397749901 CET51.158.108.203192.168.2.230xc772No error (0)kingstonwikkerink.dyn91.149.218.232A (IP address)IN (0x0001)false
                                                                  Nov 10, 2024 06:07:50.397749901 CET51.158.108.203192.168.2.230xc772No error (0)kingstonwikkerink.dyn88.151.195.22A (IP address)IN (0x0001)false
                                                                  Nov 10, 2024 06:07:50.397749901 CET51.158.108.203192.168.2.230xc772No error (0)kingstonwikkerink.dyn213.182.204.57A (IP address)IN (0x0001)false
                                                                  Nov 10, 2024 06:07:50.397749901 CET51.158.108.203192.168.2.230xc772No error (0)kingstonwikkerink.dyn86.107.100.80A (IP address)IN (0x0001)false
                                                                  Nov 10, 2024 06:07:50.397749901 CET51.158.108.203192.168.2.230xc772No error (0)kingstonwikkerink.dyn91.149.238.18A (IP address)IN (0x0001)false
                                                                  Nov 10, 2024 06:07:50.397749901 CET51.158.108.203192.168.2.230xc772No error (0)kingstonwikkerink.dyn31.13.248.89A (IP address)IN (0x0001)false
                                                                  Nov 10, 2024 06:07:50.397749901 CET51.158.108.203192.168.2.230xc772No error (0)kingstonwikkerink.dyn217.28.130.41A (IP address)IN (0x0001)false
                                                                  Nov 10, 2024 06:08:11.461129904 CET81.169.136.222192.168.2.230x3c4dNo error (0)kingstonwikkerink.dyn217.28.130.41A (IP address)IN (0x0001)false
                                                                  Nov 10, 2024 06:08:11.461129904 CET81.169.136.222192.168.2.230x3c4dNo error (0)kingstonwikkerink.dyn91.149.218.232A (IP address)IN (0x0001)false
                                                                  Nov 10, 2024 06:08:11.461129904 CET81.169.136.222192.168.2.230x3c4dNo error (0)kingstonwikkerink.dyn88.151.195.22A (IP address)IN (0x0001)false
                                                                  Nov 10, 2024 06:08:11.461129904 CET81.169.136.222192.168.2.230x3c4dNo error (0)kingstonwikkerink.dyn31.13.248.89A (IP address)IN (0x0001)false
                                                                  Nov 10, 2024 06:08:11.461129904 CET81.169.136.222192.168.2.230x3c4dNo error (0)kingstonwikkerink.dyn193.233.193.45A (IP address)IN (0x0001)false
                                                                  Nov 10, 2024 06:08:11.461129904 CET81.169.136.222192.168.2.230x3c4dNo error (0)kingstonwikkerink.dyn86.107.100.80A (IP address)IN (0x0001)false
                                                                  Nov 10, 2024 06:08:11.461129904 CET81.169.136.222192.168.2.230x3c4dNo error (0)kingstonwikkerink.dyn91.149.238.18A (IP address)IN (0x0001)false
                                                                  Nov 10, 2024 06:08:11.461129904 CET81.169.136.222192.168.2.230x3c4dNo error (0)kingstonwikkerink.dyn81.29.149.178A (IP address)IN (0x0001)false
                                                                  Nov 10, 2024 06:08:11.461129904 CET81.169.136.222192.168.2.230x3c4dNo error (0)kingstonwikkerink.dyn213.182.204.57A (IP address)IN (0x0001)false
                                                                  Nov 10, 2024 06:08:17.376144886 CET65.21.1.106192.168.2.230xfd4bNo error (0)kingstonwikkerink.dyn91.149.218.232A (IP address)IN (0x0001)false
                                                                  Nov 10, 2024 06:08:17.376144886 CET65.21.1.106192.168.2.230xfd4bNo error (0)kingstonwikkerink.dyn91.149.238.18A (IP address)IN (0x0001)false
                                                                  Nov 10, 2024 06:08:17.376144886 CET65.21.1.106192.168.2.230xfd4bNo error (0)kingstonwikkerink.dyn217.28.130.41A (IP address)IN (0x0001)false
                                                                  Nov 10, 2024 06:08:17.376144886 CET65.21.1.106192.168.2.230xfd4bNo error (0)kingstonwikkerink.dyn213.182.204.57A (IP address)IN (0x0001)false
                                                                  Nov 10, 2024 06:08:17.376144886 CET65.21.1.106192.168.2.230xfd4bNo error (0)kingstonwikkerink.dyn81.29.149.178A (IP address)IN (0x0001)false
                                                                  Nov 10, 2024 06:08:17.376144886 CET65.21.1.106192.168.2.230xfd4bNo error (0)kingstonwikkerink.dyn31.13.248.89A (IP address)IN (0x0001)false
                                                                  Nov 10, 2024 06:08:17.376144886 CET65.21.1.106192.168.2.230xfd4bNo error (0)kingstonwikkerink.dyn88.151.195.22A (IP address)IN (0x0001)false
                                                                  Nov 10, 2024 06:08:17.376144886 CET65.21.1.106192.168.2.230xfd4bNo error (0)kingstonwikkerink.dyn193.233.193.45A (IP address)IN (0x0001)false
                                                                  Nov 10, 2024 06:08:17.376144886 CET65.21.1.106192.168.2.230xfd4bNo error (0)kingstonwikkerink.dyn86.107.100.80A (IP address)IN (0x0001)false
                                                                  Nov 10, 2024 06:08:23.286825895 CET185.181.61.24192.168.2.230xd068No error (0)kingstonwikkerink.dyn193.233.193.45A (IP address)IN (0x0001)false
                                                                  Nov 10, 2024 06:08:23.286825895 CET185.181.61.24192.168.2.230xd068No error (0)kingstonwikkerink.dyn91.149.218.232A (IP address)IN (0x0001)false
                                                                  Nov 10, 2024 06:08:23.286825895 CET185.181.61.24192.168.2.230xd068No error (0)kingstonwikkerink.dyn91.149.238.18A (IP address)IN (0x0001)false
                                                                  Nov 10, 2024 06:08:23.286825895 CET185.181.61.24192.168.2.230xd068No error (0)kingstonwikkerink.dyn31.13.248.89A (IP address)IN (0x0001)false
                                                                  Nov 10, 2024 06:08:23.286825895 CET185.181.61.24192.168.2.230xd068No error (0)kingstonwikkerink.dyn86.107.100.80A (IP address)IN (0x0001)false
                                                                  Nov 10, 2024 06:08:23.286825895 CET185.181.61.24192.168.2.230xd068No error (0)kingstonwikkerink.dyn217.28.130.41A (IP address)IN (0x0001)false
                                                                  Nov 10, 2024 06:08:23.286825895 CET185.181.61.24192.168.2.230xd068No error (0)kingstonwikkerink.dyn88.151.195.22A (IP address)IN (0x0001)false
                                                                  Nov 10, 2024 06:08:23.286825895 CET185.181.61.24192.168.2.230xd068No error (0)kingstonwikkerink.dyn81.29.149.178A (IP address)IN (0x0001)false
                                                                  Nov 10, 2024 06:08:23.286825895 CET185.181.61.24192.168.2.230xd068No error (0)kingstonwikkerink.dyn213.182.204.57A (IP address)IN (0x0001)false

                                                                  System Behavior

                                                                  Start time (UTC):05:07:44
                                                                  Start date (UTC):10/11/2024
                                                                  Path:/tmp/harm4.elf
                                                                  Arguments:/tmp/harm4.elf
                                                                  File size:4956856 bytes
                                                                  MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                                  Start time (UTC):05:07:44
                                                                  Start date (UTC):10/11/2024
                                                                  Path:/tmp/harm4.elf
                                                                  Arguments:-
                                                                  File size:4956856 bytes
                                                                  MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                                  Start time (UTC):05:08:23
                                                                  Start date (UTC):10/11/2024
                                                                  Path:/usr/bin/dash
                                                                  Arguments:-
                                                                  File size:129816 bytes
                                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                  Start time (UTC):05:08:23
                                                                  Start date (UTC):10/11/2024
                                                                  Path:/usr/bin/rm
                                                                  Arguments:rm -f /tmp/tmp.Qfksf9HK6a /tmp/tmp.FvTNS7bE3S /tmp/tmp.VgzGYBwJ5D
                                                                  File size:72056 bytes
                                                                  MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b

                                                                  Start time (UTC):05:08:23
                                                                  Start date (UTC):10/11/2024
                                                                  Path:/usr/bin/dash
                                                                  Arguments:-
                                                                  File size:129816 bytes
                                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                  Start time (UTC):05:08:23
                                                                  Start date (UTC):10/11/2024
                                                                  Path:/usr/bin/rm
                                                                  Arguments:rm -f /tmp/tmp.Qfksf9HK6a /tmp/tmp.FvTNS7bE3S /tmp/tmp.VgzGYBwJ5D
                                                                  File size:72056 bytes
                                                                  MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b