Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
hmips.elf

Overview

General Information

Sample name:hmips.elf
Analysis ID:1565786
MD5:b8cec1a4da7de702bdc2d2fd9dfb5cbf
SHA1:a9d8ed06939bcda786c20c07df2add6c4bfc381a
SHA256:d84b893cb2bd195d6f3bb8aeae48c59e67e06649f24fd34b9a893f26e72bd50c
Tags:elfuser-abuse_ch
Infos:

Detection

Score:52
Range:0 - 100
Whitelisted:false

Signatures

Multi AV Scanner detection for submitted file
Sample reads /proc/mounts (often used for finding a writable filesystem)
Detected TCP or UDP traffic on non-standard ports
Sample has stripped symbol table
Sample listens on a socket
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1565786
Start date and time:2024-11-30 20:17:06 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 32s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:hmips.elf
Detection:MAL
Classification:mal52.troj.linELF@0/0@4/0
  • VT rate limit hit for: hmips.elf
Command:/tmp/hmips.elf
PID:6234
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
I just wanna look after my cats, man.
Standard Error:
  • system is lnxubuntu20
  • hmips.elf (PID: 6234, Parent: 6161, MD5: 0083f1f0e77be34ad27f849842bbb00c) Arguments: /tmp/hmips.elf
  • cleanup
No yara matches
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: hmips.elfReversingLabs: Detection: 13%
Source: global trafficTCP traffic: 192.168.2.23:48764 -> 185.22.155.213:9739
Source: global trafficTCP traffic: 192.168.2.23:54634 -> 45.147.200.148:5641
Source: global trafficTCP traffic: 192.168.2.23:42096 -> 166.88.130.30:7082
Source: /tmp/hmips.elf (PID: 6234)Socket: 127.0.0.1:1172Jump to behavior
Source: global trafficTCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
Source: global trafficTCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
Source: global trafficTCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
Source: unknownTCP traffic detected without corresponding DNS query: 185.22.155.213
Source: unknownTCP traffic detected without corresponding DNS query: 185.22.155.213
Source: unknownTCP traffic detected without corresponding DNS query: 185.22.155.213
Source: unknownTCP traffic detected without corresponding DNS query: 185.22.155.213
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 185.22.155.213
Source: unknownTCP traffic detected without corresponding DNS query: 185.22.155.213
Source: unknownTCP traffic detected without corresponding DNS query: 185.22.155.213
Source: unknownTCP traffic detected without corresponding DNS query: 185.22.155.213
Source: unknownTCP traffic detected without corresponding DNS query: 185.22.155.213
Source: unknownTCP traffic detected without corresponding DNS query: 185.22.155.213
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 45.147.200.148
Source: unknownTCP traffic detected without corresponding DNS query: 45.147.200.148
Source: unknownTCP traffic detected without corresponding DNS query: 45.147.200.148
Source: unknownTCP traffic detected without corresponding DNS query: 45.147.200.148
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 45.147.200.148
Source: unknownTCP traffic detected without corresponding DNS query: 45.147.200.148
Source: unknownTCP traffic detected without corresponding DNS query: 185.22.155.213
Source: unknownTCP traffic detected without corresponding DNS query: 185.22.155.213
Source: unknownTCP traffic detected without corresponding DNS query: 166.88.130.30
Source: unknownTCP traffic detected without corresponding DNS query: 166.88.130.30
Source: unknownTCP traffic detected without corresponding DNS query: 166.88.130.30
Source: unknownTCP traffic detected without corresponding DNS query: 166.88.130.30
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 166.88.130.30
Source: unknownTCP traffic detected without corresponding DNS query: 166.88.130.30
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 185.22.155.213
Source: unknownTCP traffic detected without corresponding DNS query: 166.88.130.30
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 185.22.155.213
Source: unknownTCP traffic detected without corresponding DNS query: 185.22.155.213
Source: unknownTCP traffic detected without corresponding DNS query: 166.88.130.30
Source: unknownTCP traffic detected without corresponding DNS query: 166.88.130.30
Source: unknownTCP traffic detected without corresponding DNS query: 166.88.130.30
Source: unknownTCP traffic detected without corresponding DNS query: 185.22.155.213
Source: unknownUDP traffic detected without corresponding DNS query: 194.36.144.87
Source: unknownUDP traffic detected without corresponding DNS query: 194.36.144.87
Source: unknownUDP traffic detected without corresponding DNS query: 81.169.136.222
Source: unknownUDP traffic detected without corresponding DNS query: 168.138.12.137
Source: global trafficDNS traffic detected: DNS query: catvision.dyn
Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443
Source: ELF static info symbol of initial sample.symtab present: no
Source: classification engineClassification label: mal52.troj.linELF@0/0@4/0

Persistence and Installation Behavior

barindex
Source: /tmp/hmips.elf (PID: 6236)File: /proc/6236/mountsJump to behavior
Source: /tmp/hmips.elf (PID: 6234)Queries kernel information via 'uname': Jump to behavior
Source: hmips.elf, 6234.1.00007ffff99e6000.00007ffff9a07000.rw-.sdmp, hmips.elf, 6236.1.00007ffff99e6000.00007ffff9a07000.rw-.sdmpBinary or memory string: Tx86_64/usr/bin/qemu-mips/tmp/hmips.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/hmips.elf
Source: hmips.elf, 6234.1.000055d6e3609000.000055d6e36d5000.rw-.sdmp, hmips.elf, 6236.1.000055d6e3609000.000055d6e36d5000.rw-.sdmpBinary or memory string: U!/etc/qemu-binfmt/mips
Source: hmips.elf, 6234.1.000055d6e3609000.000055d6e36d5000.rw-.sdmp, hmips.elf, 6236.1.000055d6e3609000.000055d6e36d5000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/mips
Source: hmips.elf, 6236.1.000055d6e3609000.000055d6e36d5000.rw-.sdmpBinary or memory string: /usr/bin/vmtoolsd
Source: hmips.elf, 6234.1.00007ffff99e6000.00007ffff9a07000.rw-.sdmp, hmips.elf, 6236.1.00007ffff99e6000.00007ffff9a07000.rw-.sdmpBinary or memory string: /usr/bin/qemu-mips
Source: hmips.elf, 6236.1.000055d6e3609000.000055d6e36d5000.rw-.sdmpBinary or memory string: U!/usr/bin/vmtoolsd
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath InterceptionDirect Volume AccessOS Credential Dumping11
Security Software Discovery
Remote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS Memory1
File and Directory Discovery
Remote Desktop ProtocolData from Removable Media1
Non-Standard Port
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
Non-Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture2
Application Layer Protocol
Traffic DuplicationData Destruction
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1565786 Sample: hmips.elf Startdate: 30/11/2024 Architecture: LINUX Score: 52 17 109.202.202.202, 80 INIT7CH Switzerland 2->17 19 166.88.130.30, 42096, 7082 EGIHOSTINGUS United States 2->19 21 5 other IPs or domains 2->21 23 Multi AV Scanner detection for submitted file 2->23 8 hmips.elf 2->8         started        signatures3 process4 process5 10 hmips.elf 8->10         started        13 hmips.elf 8->13         started        signatures6 25 Sample reads /proc/mounts (often used for finding a writable filesystem) 10->25 15 hmips.elf 10->15         started        process7
SourceDetectionScannerLabelLink
hmips.elf13%ReversingLabsLinux.Trojan.Mirai
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
catvision.dyn
unknown
unknownfalse
    unknown
    • No. of IPs < 25%
    • 25% < No. of IPs < 50%
    • 50% < No. of IPs < 75%
    • 75% < No. of IPs
    IPDomainCountryFlagASNASN NameMalicious
    185.22.155.213
    unknownRussian Federation
    51659ASBAXETRUfalse
    166.88.130.30
    unknownUnited States
    18779EGIHOSTINGUSfalse
    109.202.202.202
    unknownSwitzerland
    13030INIT7CHfalse
    45.147.200.148
    unknownRussian Federation
    51659ASBAXETRUfalse
    91.189.91.43
    unknownUnited Kingdom
    41231CANONICAL-ASGBfalse
    91.189.91.42
    unknownUnited Kingdom
    41231CANONICAL-ASGBfalse
    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
    185.22.155.213arm4.elfGet hashmaliciousUnknownBrowse
      mips.elfGet hashmaliciousUnknownBrowse
        hmips.elfGet hashmaliciousUnknownBrowse
          mpsl.elfGet hashmaliciousUnknownBrowse
            harm4.elfGet hashmaliciousUnknownBrowse
              arm.elfGet hashmaliciousUnknownBrowse
                hmips.elfGet hashmaliciousUnknownBrowse
                  166.88.130.30arm4.elfGet hashmaliciousUnknownBrowse
                    mips.elfGet hashmaliciousUnknownBrowse
                      ppc.elfGet hashmaliciousUnknownBrowse
                        hmips.elfGet hashmaliciousUnknownBrowse
                          109.202.202.202kpLwzBouH4.elfGet hashmaliciousUnknownBrowse
                          • ch.archive.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_92.0%2bbuild3-0ubuntu0.20.04.1_amd64.deb
                          No context
                          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                          EGIHOSTINGUSarm4.elfGet hashmaliciousUnknownBrowse
                          • 166.88.130.30
                          mips.elfGet hashmaliciousUnknownBrowse
                          • 166.88.130.30
                          ppc.elfGet hashmaliciousUnknownBrowse
                          • 166.88.130.30
                          ppc.elfGet hashmaliciousMiraiBrowse
                          • 107.187.170.14
                          botx.spc.elfGet hashmaliciousMiraiBrowse
                          • 172.120.171.253
                          botx.mpsl.elfGet hashmaliciousMiraiBrowse
                          • 192.177.179.65
                          loligang.ppc.elfGet hashmaliciousMiraiBrowse
                          • 166.88.53.250
                          loligang.mpsl-20241128-1536.elfGet hashmaliciousMiraiBrowse
                          • 166.93.166.82
                          x86.elfGet hashmaliciousMirai, MoobotBrowse
                          • 107.164.228.81
                          mpsl.elfGet hashmaliciousMirai, MoobotBrowse
                          • 142.253.190.113
                          ASBAXETRUarm4.elfGet hashmaliciousUnknownBrowse
                          • 45.140.169.21
                          mips.elfGet hashmaliciousUnknownBrowse
                          • 176.32.39.112
                          ppc.elfGet hashmaliciousUnknownBrowse
                          • 176.32.39.112
                          hmips.elfGet hashmaliciousUnknownBrowse
                          • 185.22.155.152
                          PAYMENT_ADVICE.exeGet hashmaliciousFormBookBrowse
                          • 176.32.38.183
                          specifications.exeGet hashmaliciousFormBook, PureLog StealerBrowse
                          • 176.32.38.130
                          mpsl.elfGet hashmaliciousUnknownBrowse
                          • 45.140.169.21
                          harm4.elfGet hashmaliciousUnknownBrowse
                          • 45.147.200.148
                          harm5.elfGet hashmaliciousUnknownBrowse
                          • 45.140.168.235
                          mips.elfGet hashmaliciousUnknownBrowse
                          • 176.32.39.112
                          INIT7CHm68k.elfGet hashmaliciousUnknownBrowse
                          • 109.202.202.202
                          mips.elfGet hashmaliciousUnknownBrowse
                          • 109.202.202.202
                          ppc.elfGet hashmaliciousUnknownBrowse
                          • 109.202.202.202
                          x86.elfGet hashmaliciousUnknownBrowse
                          • 109.202.202.202
                          .i.elfGet hashmaliciousUnknownBrowse
                          • 109.202.202.202
                          arm7.elfGet hashmaliciousUnknownBrowse
                          • 109.202.202.202
                          .i.elfGet hashmaliciousUnknownBrowse
                          • 109.202.202.202
                          spc.elfGet hashmaliciousUnknownBrowse
                          • 109.202.202.202
                          sh4.elfGet hashmaliciousUnknownBrowse
                          • 109.202.202.202
                          arm.elfGet hashmaliciousUnknownBrowse
                          • 109.202.202.202
                          No context
                          No context
                          No created / dropped files found
                          File type:ELF 32-bit MSB executable, MIPS, MIPS-I version 1 (SYSV), statically linked, stripped
                          Entropy (8bit):5.4392099640846565
                          TrID:
                          • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                          File name:hmips.elf
                          File size:70'080 bytes
                          MD5:b8cec1a4da7de702bdc2d2fd9dfb5cbf
                          SHA1:a9d8ed06939bcda786c20c07df2add6c4bfc381a
                          SHA256:d84b893cb2bd195d6f3bb8aeae48c59e67e06649f24fd34b9a893f26e72bd50c
                          SHA512:24e7487adefa66d17a818bff6c896671be1e00b7a16107dfff28ecd3a0ad063c922bae8c095a5614c15c44ce618f5fa64ca4bfc47bb52171a0c089e00078d280
                          SSDEEP:1536:tjgMuQn9y+VWOVWriWkbB9yOiMeBj5TbenZlvwbZi:eMuQ9y69yOiRj5owb0
                          TLSH:6B63B84E6E32CFEDF66CC33047B74A31A76963D522E18685D2ACD2141F7024E585FBA8
                          File Content Preview:.ELF.....................@.`...4.........4. ...(.............@...@...........................E...E.....h..Z$........dt.Q............................<...'......!'.......................<...'......!... ....'9... ......................<...'......!........'9.

                          ELF header

                          Class:ELF32
                          Data:2's complement, big endian
                          Version:1 (current)
                          Machine:MIPS R3000
                          Version Number:0x1
                          Type:EXEC (Executable file)
                          OS/ABI:UNIX - System V
                          ABI Version:0
                          Entry Point Address:0x400260
                          Flags:0x1007
                          ELF Header Size:52
                          Program Header Offset:52
                          Program Header Size:32
                          Number of Program Headers:3
                          Section Header Offset:69520
                          Section Header Size:40
                          Number of Section Headers:14
                          Header String Table Index:13
                          NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                          NULL0x00x00x00x00x0000
                          .initPROGBITS0x4000940x940x8c0x00x6AX004
                          .textPROGBITS0x4001200x1200xed600x00x6AX0016
                          .finiPROGBITS0x40ee800xee800x5c0x00x6AX004
                          .rodataPROGBITS0x40eee00xeee00x16e00x00x2A0016
                          .ctorsPROGBITS0x4505c40x105c40x80x00x3WA004
                          .dtorsPROGBITS0x4505cc0x105cc0x80x00x3WA004
                          .data.rel.roPROGBITS0x4505d80x105d80x40x00x3WA004
                          .dataPROGBITS0x4505e00x105e00x3c80x00x3WA0016
                          .gotPROGBITS0x4509b00x109b00x57c0x40x10000003WAp0016
                          .sbssNOBITS0x450f2c0x10f2c0x1c0x00x10000003WAp004
                          .bssNOBITS0x450f500x10f2c0x50980x00x3WA0016
                          .mdebug.abi32PROGBITS0xc060x10f2c0x00x00x0001
                          .shstrtabSTRTAB0x00x10f2c0x640x00x0001
                          TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                          LOAD0x00x4000000x4000000x105c00x105c05.48640x5R E0x10000.init .text .fini .rodata
                          LOAD0x105c40x4505c40x4505c40x9680x5a243.55450x6RW 0x10000.ctors .dtors .data.rel.ro .data .got .sbss .bss
                          GNU_STACK0x00x00x00x00x00.00000x7RWE0x4
                          TimestampSource PortDest PortSource IPDest IP
                          Nov 30, 2024 20:17:50.833818913 CET487649739192.168.2.23185.22.155.213
                          Nov 30, 2024 20:17:50.953188896 CET487669739192.168.2.23185.22.155.213
                          Nov 30, 2024 20:17:50.954747915 CET973948764185.22.155.213192.168.2.23
                          Nov 30, 2024 20:17:50.955780029 CET487649739192.168.2.23185.22.155.213
                          Nov 30, 2024 20:17:50.955780029 CET487649739192.168.2.23185.22.155.213
                          Nov 30, 2024 20:17:51.067338943 CET43928443192.168.2.2391.189.91.42
                          Nov 30, 2024 20:17:51.074137926 CET973948766185.22.155.213192.168.2.23
                          Nov 30, 2024 20:17:51.074239016 CET487669739192.168.2.23185.22.155.213
                          Nov 30, 2024 20:17:51.074692011 CET487669739192.168.2.23185.22.155.213
                          Nov 30, 2024 20:17:51.076595068 CET973948764185.22.155.213192.168.2.23
                          Nov 30, 2024 20:17:51.076752901 CET487649739192.168.2.23185.22.155.213
                          Nov 30, 2024 20:17:51.195414066 CET973948766185.22.155.213192.168.2.23
                          Nov 30, 2024 20:17:51.195549965 CET487669739192.168.2.23185.22.155.213
                          Nov 30, 2024 20:17:51.197738886 CET973948764185.22.155.213192.168.2.23
                          Nov 30, 2024 20:17:51.317634106 CET973948766185.22.155.213192.168.2.23
                          Nov 30, 2024 20:17:52.667123079 CET973948764185.22.155.213192.168.2.23
                          Nov 30, 2024 20:17:52.667247057 CET487649739192.168.2.23185.22.155.213
                          Nov 30, 2024 20:17:52.667541981 CET487649739192.168.2.23185.22.155.213
                          Nov 30, 2024 20:17:56.698486090 CET42836443192.168.2.2391.189.91.43
                          Nov 30, 2024 20:17:57.911206007 CET546345641192.168.2.2345.147.200.148
                          Nov 30, 2024 20:17:58.031227112 CET56415463445.147.200.148192.168.2.23
                          Nov 30, 2024 20:17:58.031351089 CET546345641192.168.2.2345.147.200.148
                          Nov 30, 2024 20:17:58.031533957 CET546345641192.168.2.2345.147.200.148
                          Nov 30, 2024 20:17:58.151422977 CET56415463445.147.200.148192.168.2.23
                          Nov 30, 2024 20:17:58.151745081 CET546345641192.168.2.2345.147.200.148
                          Nov 30, 2024 20:17:58.234102964 CET4251680192.168.2.23109.202.202.202
                          Nov 30, 2024 20:17:58.272906065 CET56415463445.147.200.148192.168.2.23
                          Nov 30, 2024 20:17:59.672971964 CET56415463445.147.200.148192.168.2.23
                          Nov 30, 2024 20:17:59.673084974 CET546345641192.168.2.2345.147.200.148
                          Nov 30, 2024 20:17:59.673125982 CET546345641192.168.2.2345.147.200.148
                          Nov 30, 2024 20:18:01.083786011 CET487669739192.168.2.23185.22.155.213
                          Nov 30, 2024 20:18:01.203921080 CET973948766185.22.155.213192.168.2.23
                          Nov 30, 2024 20:18:01.696378946 CET973948766185.22.155.213192.168.2.23
                          Nov 30, 2024 20:18:01.697340012 CET487669739192.168.2.23185.22.155.213
                          Nov 30, 2024 20:18:05.073733091 CET420967082192.168.2.23166.88.130.30
                          Nov 30, 2024 20:18:05.194751024 CET708242096166.88.130.30192.168.2.23
                          Nov 30, 2024 20:18:05.194895029 CET420967082192.168.2.23166.88.130.30
                          Nov 30, 2024 20:18:05.194943905 CET420967082192.168.2.23166.88.130.30
                          Nov 30, 2024 20:18:05.316261053 CET708242096166.88.130.30192.168.2.23
                          Nov 30, 2024 20:18:05.316354036 CET420967082192.168.2.23166.88.130.30
                          Nov 30, 2024 20:18:05.436322927 CET708242096166.88.130.30192.168.2.23
                          Nov 30, 2024 20:18:11.800187111 CET43928443192.168.2.2391.189.91.42
                          Nov 30, 2024 20:18:15.200180054 CET420967082192.168.2.23166.88.130.30
                          Nov 30, 2024 20:18:15.323554993 CET708242096166.88.130.30192.168.2.23
                          Nov 30, 2024 20:18:15.562429905 CET708242096166.88.130.30192.168.2.23
                          Nov 30, 2024 20:18:15.562530994 CET420967082192.168.2.23166.88.130.30
                          Nov 30, 2024 20:18:24.086565018 CET42836443192.168.2.2391.189.91.43
                          Nov 30, 2024 20:18:25.648442984 CET973948766185.22.155.213192.168.2.23
                          Nov 30, 2024 20:18:25.648725033 CET487669739192.168.2.23185.22.155.213
                          Nov 30, 2024 20:18:25.839932919 CET708242096166.88.130.30192.168.2.23
                          Nov 30, 2024 20:18:25.840220928 CET420967082192.168.2.23166.88.130.30
                          Nov 30, 2024 20:18:28.181967974 CET4251680192.168.2.23109.202.202.202
                          Nov 30, 2024 20:18:52.754519939 CET43928443192.168.2.2391.189.91.42
                          Nov 30, 2024 20:19:25.698343992 CET487669739192.168.2.23185.22.155.213
                          Nov 30, 2024 20:19:25.818397045 CET973948766185.22.155.213192.168.2.23
                          Nov 30, 2024 20:19:26.298269987 CET973948766185.22.155.213192.168.2.23
                          Nov 30, 2024 20:19:26.298448086 CET487669739192.168.2.23185.22.155.213
                          Nov 30, 2024 20:19:35.888361931 CET420967082192.168.2.23166.88.130.30
                          Nov 30, 2024 20:19:36.008513927 CET708242096166.88.130.30192.168.2.23
                          Nov 30, 2024 20:19:36.247261047 CET708242096166.88.130.30192.168.2.23
                          Nov 30, 2024 20:19:36.247379065 CET420967082192.168.2.23166.88.130.30
                          Nov 30, 2024 20:19:38.299905062 CET708242096166.88.130.30192.168.2.23
                          Nov 30, 2024 20:19:38.300086975 CET420967082192.168.2.23166.88.130.30
                          Nov 30, 2024 20:19:38.369750977 CET973948766185.22.155.213192.168.2.23
                          Nov 30, 2024 20:19:38.369970083 CET487669739192.168.2.23185.22.155.213
                          TimestampSource PortDest PortSource IPDest IP
                          Nov 30, 2024 20:17:50.577225924 CET4840853192.168.2.23194.36.144.87
                          Nov 30, 2024 20:17:50.701244116 CET5120453192.168.2.23194.36.144.87
                          Nov 30, 2024 20:17:50.832627058 CET5348408194.36.144.87192.168.2.23
                          Nov 30, 2024 20:17:50.951937914 CET5351204194.36.144.87192.168.2.23
                          Nov 30, 2024 20:17:57.669287920 CET4919353192.168.2.2381.169.136.222
                          Nov 30, 2024 20:17:57.910260916 CET534919381.169.136.222192.168.2.23
                          Nov 30, 2024 20:18:04.675445080 CET3975953192.168.2.23168.138.12.137
                          Nov 30, 2024 20:18:05.072802067 CET5339759168.138.12.137192.168.2.23
                          TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                          Nov 30, 2024 20:17:50.577225924 CET192.168.2.23194.36.144.870xf372Standard query (0)catvision.dynA (IP address)IN (0x0001)false
                          Nov 30, 2024 20:17:50.701244116 CET192.168.2.23194.36.144.870xf372Standard query (0)catvision.dynA (IP address)IN (0x0001)false
                          Nov 30, 2024 20:17:57.669287920 CET192.168.2.2381.169.136.2220xed36Standard query (0)catvision.dynA (IP address)IN (0x0001)false
                          Nov 30, 2024 20:18:04.675445080 CET192.168.2.23168.138.12.1370x6ea0Standard query (0)catvision.dynA (IP address)IN (0x0001)false

                          System Behavior

                          Start time (UTC):19:17:50
                          Start date (UTC):30/11/2024
                          Path:/tmp/hmips.elf
                          Arguments:/tmp/hmips.elf
                          File size:5777432 bytes
                          MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                          Start time (UTC):19:17:50
                          Start date (UTC):30/11/2024
                          Path:/tmp/hmips.elf
                          Arguments:-
                          File size:5777432 bytes
                          MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                          Start time (UTC):19:17:50
                          Start date (UTC):30/11/2024
                          Path:/tmp/hmips.elf
                          Arguments:-
                          File size:5777432 bytes
                          MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                          Start time (UTC):19:17:50
                          Start date (UTC):30/11/2024
                          Path:/tmp/hmips.elf
                          Arguments:-
                          File size:5777432 bytes
                          MD5 hash:0083f1f0e77be34ad27f849842bbb00c