Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
zmap.mips.elf

Overview

General Information

Sample name:zmap.mips.elf
Analysis ID:1576219
MD5:8ae4ac18a3b34fba963f59a42ff02fb7
SHA1:e9f75cf21972b2c953163d64d3cb89bd6a93cc1b
SHA256:c485a846f4b7c5d410762291758175ca0775ca919da52ef05047f3000045020a
Tags:elfuser-abuse_ch
Infos:

Detection

Mirai, Okiru
Score:84
Range:0 - 100
Whitelisted:false

Signatures

Antivirus / Scanner detection for submitted sample
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Yara detected Mirai
Yara detected Okiru
Sample deletes itself
Detected TCP or UDP traffic on non-standard ports
Sample has stripped symbol table
Sample listens on a socket
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Uses the "uname" system call to query kernel version information (possible evasion)
Yara signature match

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1576219
Start date and time:2024-12-16 16:53:07 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 36s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:zmap.mips.elf
Detection:MAL
Classification:mal84.troj.evad.linELF@0/0@10/0
  • VT rate limit hit for: zmap.mips.elf
Command:/tmp/zmap.mips.elf
PID:6204
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
VagneRHere
Standard Error:
  • system is lnxubuntu20
  • zmap.mips.elf (PID: 6204, Parent: 6122, MD5: 0083f1f0e77be34ad27f849842bbb00c) Arguments: /tmp/zmap.mips.elf
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
MiraiMirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese. Nowadays it targets a wide range of networked embedded devices such as IP cameras, home routers (many vendors involved), and other IoT devices. Since the source code was published on "Hack Forums" many variants of the Mirai family appeared, infecting mostly home networks all around the world.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/elf.mirai
SourceRuleDescriptionAuthorStrings
zmap.mips.elfJoeSecurity_OkiruYara detected OkiruJoe Security
    zmap.mips.elfJoeSecurity_Mirai_8Yara detected MiraiJoe Security
      zmap.mips.elfLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
      • 0x141d0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x141e4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x141f8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x1420c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x14220:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x14234:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x14248:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x1425c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x14270:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x14284:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x14298:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x142ac:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x142c0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x142d4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x142e8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x142fc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x14310:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x14324:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x14338:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x1434c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x14360:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      SourceRuleDescriptionAuthorStrings
      6208.1.00007f1cfc400000.00007f1cfc417000.r-x.sdmpJoeSecurity_OkiruYara detected OkiruJoe Security
        6208.1.00007f1cfc400000.00007f1cfc417000.r-x.sdmpJoeSecurity_Mirai_8Yara detected MiraiJoe Security
          6208.1.00007f1cfc400000.00007f1cfc417000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
          • 0x141d0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x141e4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x141f8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x1420c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x14220:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x14234:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x14248:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x1425c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x14270:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x14284:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x14298:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x142ac:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x142c0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x142d4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x142e8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x142fc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x14310:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x14324:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x14338:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x1434c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x14360:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          6204.1.00007f1cfc400000.00007f1cfc417000.r-x.sdmpJoeSecurity_OkiruYara detected OkiruJoe Security
            6204.1.00007f1cfc400000.00007f1cfc417000.r-x.sdmpJoeSecurity_Mirai_8Yara detected MiraiJoe Security
              Click to see the 7 entries
              No Suricata rule has matched

              Click to jump to signature section

              Show All Signature Results

              AV Detection

              barindex
              Source: zmap.mips.elfAvira: detected
              Source: zmap.mips.elfReversingLabs: Detection: 57%
              Source: global trafficTCP traffic: 192.168.2.23:60038 -> 185.196.11.47:59962
              Source: /tmp/zmap.mips.elf (PID: 6204)Socket: 127.0.0.1:39148Jump to behavior
              Source: global trafficTCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
              Source: global trafficTCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
              Source: global trafficTCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
              Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
              Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
              Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
              Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
              Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
              Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
              Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
              Source: global trafficDNS traffic detected: DNS query: servers.vlrt-gap.com
              Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443

              System Summary

              barindex
              Source: zmap.mips.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
              Source: 6208.1.00007f1cfc400000.00007f1cfc417000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
              Source: 6204.1.00007f1cfc400000.00007f1cfc417000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
              Source: Process Memory Space: zmap.mips.elf PID: 6204, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
              Source: Process Memory Space: zmap.mips.elf PID: 6208, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
              Source: ELF static info symbol of initial sample.symtab present: no
              Source: zmap.mips.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
              Source: 6208.1.00007f1cfc400000.00007f1cfc417000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
              Source: 6204.1.00007f1cfc400000.00007f1cfc417000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
              Source: Process Memory Space: zmap.mips.elf PID: 6204, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
              Source: Process Memory Space: zmap.mips.elf PID: 6208, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
              Source: classification engineClassification label: mal84.troj.evad.linELF@0/0@10/0

              Hooking and other Techniques for Hiding and Protection

              barindex
              Source: /tmp/zmap.mips.elf (PID: 6204)File: /tmp/zmap.mips.elfJump to behavior
              Source: /tmp/zmap.mips.elf (PID: 6204)Queries kernel information via 'uname': Jump to behavior
              Source: zmap.mips.elf, 6204.1.00007ffdcd2ee000.00007ffdcd30f000.rw-.sdmp, zmap.mips.elf, 6208.1.00007ffdcd2ee000.00007ffdcd30f000.rw-.sdmpBinary or memory string: Zwx86_64/usr/bin/qemu-mips/tmp/zmap.mips.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/zmap.mips.elf
              Source: zmap.mips.elf, 6204.1.0000560925a2f000.0000560925ab6000.rw-.sdmp, zmap.mips.elf, 6208.1.0000560925a2f000.0000560925ab6000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/mips
              Source: zmap.mips.elf, 6204.1.0000560925a2f000.0000560925ab6000.rw-.sdmp, zmap.mips.elf, 6208.1.0000560925a2f000.0000560925ab6000.rw-.sdmpBinary or memory string: %V!/etc/qemu-binfmt/mips
              Source: zmap.mips.elf, 6204.1.00007ffdcd2ee000.00007ffdcd30f000.rw-.sdmp, zmap.mips.elf, 6208.1.00007ffdcd2ee000.00007ffdcd30f000.rw-.sdmpBinary or memory string: /usr/bin/qemu-mips

              Stealing of Sensitive Information

              barindex
              Source: Yara matchFile source: zmap.mips.elf, type: SAMPLE
              Source: Yara matchFile source: 6208.1.00007f1cfc400000.00007f1cfc417000.r-x.sdmp, type: MEMORY
              Source: Yara matchFile source: 6204.1.00007f1cfc400000.00007f1cfc417000.r-x.sdmp, type: MEMORY
              Source: Yara matchFile source: Process Memory Space: zmap.mips.elf PID: 6204, type: MEMORYSTR
              Source: Yara matchFile source: Process Memory Space: zmap.mips.elf PID: 6208, type: MEMORYSTR
              Source: Yara matchFile source: zmap.mips.elf, type: SAMPLE
              Source: Yara matchFile source: 6208.1.00007f1cfc400000.00007f1cfc417000.r-x.sdmp, type: MEMORY
              Source: Yara matchFile source: 6204.1.00007f1cfc400000.00007f1cfc417000.r-x.sdmp, type: MEMORY
              Source: Yara matchFile source: Process Memory Space: zmap.mips.elf PID: 6204, type: MEMORYSTR
              Source: Yara matchFile source: Process Memory Space: zmap.mips.elf PID: 6208, type: MEMORYSTR

              Remote Access Functionality

              barindex
              Source: Yara matchFile source: zmap.mips.elf, type: SAMPLE
              Source: Yara matchFile source: 6208.1.00007f1cfc400000.00007f1cfc417000.r-x.sdmp, type: MEMORY
              Source: Yara matchFile source: 6204.1.00007f1cfc400000.00007f1cfc417000.r-x.sdmp, type: MEMORY
              Source: Yara matchFile source: Process Memory Space: zmap.mips.elf PID: 6204, type: MEMORYSTR
              Source: Yara matchFile source: Process Memory Space: zmap.mips.elf PID: 6208, type: MEMORYSTR
              Source: Yara matchFile source: zmap.mips.elf, type: SAMPLE
              Source: Yara matchFile source: 6208.1.00007f1cfc400000.00007f1cfc417000.r-x.sdmp, type: MEMORY
              Source: Yara matchFile source: 6204.1.00007f1cfc400000.00007f1cfc417000.r-x.sdmp, type: MEMORY
              Source: Yara matchFile source: Process Memory Space: zmap.mips.elf PID: 6204, type: MEMORYSTR
              Source: Yara matchFile source: Process Memory Space: zmap.mips.elf PID: 6208, type: MEMORYSTR
              ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
              Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception1
              File Deletion
              OS Credential Dumping11
              Security Software Discovery
              Remote ServicesData from Local System1
              Encrypted Channel
              Exfiltration Over Other Network MediumAbuse Accessibility Features
              CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
              Non-Standard Port
              Exfiltration Over BluetoothNetwork Denial of Service
              Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
              Non-Application Layer Protocol
              Automated ExfiltrationData Encrypted for Impact
              Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture2
              Application Layer Protocol
              Traffic DuplicationData Destruction
              No configs have been found
              Hide Legend

              Legend:

              • Process
              • Signature
              • Created File
              • DNS/IP Info
              • Is Dropped
              • Number of created Files
              • Is malicious
              • Internet
              SourceDetectionScannerLabelLink
              zmap.mips.elf58%ReversingLabsLinux.Trojan.Mirai
              zmap.mips.elf100%AviraEXP/ELF.Mirai.Z.A
              No Antivirus matches
              No Antivirus matches
              No Antivirus matches
              NameIPActiveMaliciousAntivirus DetectionReputation
              servers.vlrt-gap.com
              185.196.11.47
              truefalse
                high
                • No. of IPs < 25%
                • 25% < No. of IPs < 50%
                • 50% < No. of IPs < 75%
                • 75% < No. of IPs
                IPDomainCountryFlagASNASN NameMalicious
                185.196.11.47
                servers.vlrt-gap.comSwitzerland
                42624SIMPLECARRIERCHfalse
                109.202.202.202
                unknownSwitzerland
                13030INIT7CHfalse
                91.189.91.43
                unknownUnited Kingdom
                41231CANONICAL-ASGBfalse
                91.189.91.42
                unknownUnited Kingdom
                41231CANONICAL-ASGBfalse
                MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                185.196.11.47zmap.x86.elfGet hashmaliciousOkiruBrowse
                  zmap.arm7.elfGet hashmaliciousMirai, OkiruBrowse
                    debug.dbg.elfGet hashmaliciousMirai, OkiruBrowse
                      zmap.m68k.elfGet hashmaliciousMirai, OkiruBrowse
                        zmap.arm.elfGet hashmaliciousMirai, OkiruBrowse
                          zmap.sh4.elfGet hashmaliciousMirai, OkiruBrowse
                            zmap.spc.elfGet hashmaliciousMirai, OkiruBrowse
                              109.202.202.202kpLwzBouH4.elfGet hashmaliciousUnknownBrowse
                              • ch.archive.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_92.0%2bbuild3-0ubuntu0.20.04.1_amd64.deb
                              91.189.91.43arm6.elfGet hashmaliciousMiraiBrowse
                                arm.elfGet hashmaliciousMiraiBrowse
                                  m68k.elfGet hashmaliciousMiraiBrowse
                                    x86.elfGet hashmaliciousMiraiBrowse
                                      mpsl.elfGet hashmaliciousMiraiBrowse
                                        arm5.elfGet hashmaliciousMiraiBrowse
                                          arm5.elfGet hashmaliciousMiraiBrowse
                                            zmap.arm7.elfGet hashmaliciousMirai, OkiruBrowse
                                              skid.mips.elfGet hashmaliciousUnknownBrowse
                                                arm.elfGet hashmaliciousUnknownBrowse
                                                  91.189.91.42arm6.elfGet hashmaliciousMiraiBrowse
                                                    arm.elfGet hashmaliciousMiraiBrowse
                                                      m68k.elfGet hashmaliciousMiraiBrowse
                                                        x86.elfGet hashmaliciousMiraiBrowse
                                                          mpsl.elfGet hashmaliciousMiraiBrowse
                                                            arm5.elfGet hashmaliciousMiraiBrowse
                                                              arm5.elfGet hashmaliciousMiraiBrowse
                                                                zmap.arm7.elfGet hashmaliciousMirai, OkiruBrowse
                                                                  skid.mips.elfGet hashmaliciousUnknownBrowse
                                                                    arm.elfGet hashmaliciousUnknownBrowse
                                                                      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                      servers.vlrt-gap.comzmap.x86.elfGet hashmaliciousOkiruBrowse
                                                                      • 185.196.11.47
                                                                      zmap.arm7.elfGet hashmaliciousMirai, OkiruBrowse
                                                                      • 185.196.11.47
                                                                      debug.dbg.elfGet hashmaliciousMirai, OkiruBrowse
                                                                      • 185.196.11.47
                                                                      zmap.m68k.elfGet hashmaliciousMirai, OkiruBrowse
                                                                      • 185.196.11.47
                                                                      zmap.arm.elfGet hashmaliciousMirai, OkiruBrowse
                                                                      • 185.196.11.47
                                                                      zmap.sh4.elfGet hashmaliciousMirai, OkiruBrowse
                                                                      • 185.196.11.47
                                                                      zmap.spc.elfGet hashmaliciousMirai, OkiruBrowse
                                                                      • 185.196.11.47
                                                                      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                      CANONICAL-ASGBarm6.elfGet hashmaliciousMiraiBrowse
                                                                      • 91.189.91.42
                                                                      arm.elfGet hashmaliciousMiraiBrowse
                                                                      • 91.189.91.42
                                                                      m68k.elfGet hashmaliciousMiraiBrowse
                                                                      • 91.189.91.42
                                                                      x86.elfGet hashmaliciousMiraiBrowse
                                                                      • 91.189.91.42
                                                                      mpsl.elfGet hashmaliciousMiraiBrowse
                                                                      • 91.189.91.42
                                                                      zmap.x86.elfGet hashmaliciousOkiruBrowse
                                                                      • 185.125.190.26
                                                                      arm5.elfGet hashmaliciousMiraiBrowse
                                                                      • 91.189.91.42
                                                                      arm5.elfGet hashmaliciousMiraiBrowse
                                                                      • 91.189.91.42
                                                                      zmap.arm7.elfGet hashmaliciousMirai, OkiruBrowse
                                                                      • 91.189.91.42
                                                                      skid.mips.elfGet hashmaliciousUnknownBrowse
                                                                      • 91.189.91.42
                                                                      CANONICAL-ASGBarm6.elfGet hashmaliciousMiraiBrowse
                                                                      • 91.189.91.42
                                                                      arm.elfGet hashmaliciousMiraiBrowse
                                                                      • 91.189.91.42
                                                                      m68k.elfGet hashmaliciousMiraiBrowse
                                                                      • 91.189.91.42
                                                                      x86.elfGet hashmaliciousMiraiBrowse
                                                                      • 91.189.91.42
                                                                      mpsl.elfGet hashmaliciousMiraiBrowse
                                                                      • 91.189.91.42
                                                                      zmap.x86.elfGet hashmaliciousOkiruBrowse
                                                                      • 185.125.190.26
                                                                      arm5.elfGet hashmaliciousMiraiBrowse
                                                                      • 91.189.91.42
                                                                      arm5.elfGet hashmaliciousMiraiBrowse
                                                                      • 91.189.91.42
                                                                      zmap.arm7.elfGet hashmaliciousMirai, OkiruBrowse
                                                                      • 91.189.91.42
                                                                      skid.mips.elfGet hashmaliciousUnknownBrowse
                                                                      • 91.189.91.42
                                                                      SIMPLECARRIERCHzmap.x86.elfGet hashmaliciousOkiruBrowse
                                                                      • 185.196.11.47
                                                                      zmap.arm7.elfGet hashmaliciousMirai, OkiruBrowse
                                                                      • 185.196.11.47
                                                                      debug.dbg.elfGet hashmaliciousMirai, OkiruBrowse
                                                                      • 185.196.11.47
                                                                      zmap.m68k.elfGet hashmaliciousMirai, OkiruBrowse
                                                                      • 185.196.11.47
                                                                      zmap.arm.elfGet hashmaliciousMirai, OkiruBrowse
                                                                      • 185.196.11.47
                                                                      zmap.sh4.elfGet hashmaliciousMirai, OkiruBrowse
                                                                      • 185.196.11.47
                                                                      zmap.spc.elfGet hashmaliciousMirai, OkiruBrowse
                                                                      • 185.196.11.47
                                                                      7rTjhbfF6L.exeGet hashmaliciousUnknownBrowse
                                                                      • 185.196.9.156
                                                                      93z4kPX7B6.exeGet hashmaliciousAgentTesla, PureLog Stealer, zgRATBrowse
                                                                      • 185.196.9.150
                                                                      GZC0n65Ggl.exeGet hashmaliciousAgentTeslaBrowse
                                                                      • 185.196.9.150
                                                                      INIT7CHarm6.elfGet hashmaliciousMiraiBrowse
                                                                      • 109.202.202.202
                                                                      arm.elfGet hashmaliciousMiraiBrowse
                                                                      • 109.202.202.202
                                                                      m68k.elfGet hashmaliciousMiraiBrowse
                                                                      • 109.202.202.202
                                                                      x86.elfGet hashmaliciousMiraiBrowse
                                                                      • 109.202.202.202
                                                                      mpsl.elfGet hashmaliciousMiraiBrowse
                                                                      • 109.202.202.202
                                                                      arm5.elfGet hashmaliciousMiraiBrowse
                                                                      • 109.202.202.202
                                                                      arm5.elfGet hashmaliciousMiraiBrowse
                                                                      • 109.202.202.202
                                                                      zmap.arm7.elfGet hashmaliciousMirai, OkiruBrowse
                                                                      • 109.202.202.202
                                                                      skid.mips.elfGet hashmaliciousUnknownBrowse
                                                                      • 109.202.202.202
                                                                      arm.elfGet hashmaliciousUnknownBrowse
                                                                      • 109.202.202.202
                                                                      No context
                                                                      No context
                                                                      No created / dropped files found
                                                                      File type:ELF 32-bit MSB executable, MIPS, MIPS-I version 1 (SYSV), statically linked, stripped
                                                                      Entropy (8bit):5.484876545192541
                                                                      TrID:
                                                                      • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                                                                      File name:zmap.mips.elf
                                                                      File size:97'100 bytes
                                                                      MD5:8ae4ac18a3b34fba963f59a42ff02fb7
                                                                      SHA1:e9f75cf21972b2c953163d64d3cb89bd6a93cc1b
                                                                      SHA256:c485a846f4b7c5d410762291758175ca0775ca919da52ef05047f3000045020a
                                                                      SHA512:af6a9fb41fc94fdb3c1448e2477190f403b14eca2502e93c1ab6a1c8cf0eaada47dedd81df94f15bc6efa8ae29d68f3a6368c67283514c88f3f8e28519bf6bb0
                                                                      SSDEEP:1536:mF4tsbv54o+3bPhXhWxZJlwYdPAL+fyecpeo6XNLty:mF4tsr54o+rPhkxlwYdoL+fyecIXNLY
                                                                      TLSH:5393940D7E269F7DFBA9823447B78E22675833D637D0D585D19CE6002E6028E241FFA5
                                                                      File Content Preview:.ELF.....................@.`...4..yD.....4. ...(.............@...@....c...c...............p..Ep..Ep.......-.........dt.Q............................<...'..\...!'.......................<...'..8...!... ....'9... ......................<...'......!........'9@

                                                                      ELF header

                                                                      Class:ELF32
                                                                      Data:2's complement, big endian
                                                                      Version:1 (current)
                                                                      Machine:MIPS R3000
                                                                      Version Number:0x1
                                                                      Type:EXEC (Executable file)
                                                                      OS/ABI:UNIX - System V
                                                                      ABI Version:0
                                                                      Entry Point Address:0x400260
                                                                      Flags:0x1007
                                                                      ELF Header Size:52
                                                                      Program Header Offset:52
                                                                      Program Header Size:32
                                                                      Number of Program Headers:3
                                                                      Section Header Offset:96580
                                                                      Section Header Size:40
                                                                      Number of Section Headers:13
                                                                      Header String Table Index:12
                                                                      NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                                                      NULL0x00x00x00x00x0000
                                                                      .initPROGBITS0x4000940x940x8c0x00x6AX004
                                                                      .textPROGBITS0x4001200x1200x140400x00x6AX0016
                                                                      .finiPROGBITS0x4141600x141600x5c0x00x6AX004
                                                                      .rodataPROGBITS0x4141c00x141c00x21e00x00x2A0016
                                                                      .ctorsPROGBITS0x4570000x170000x80x00x3WA004
                                                                      .dtorsPROGBITS0x4570080x170080x80x00x3WA004
                                                                      .dataPROGBITS0x4570200x170200x3e00x00x3WA0016
                                                                      .gotPROGBITS0x4574000x174000x4ec0x40x10000003WAp0016
                                                                      .sbssNOBITS0x4578ec0x178ec0x1c0x00x10000003WAp004
                                                                      .bssNOBITS0x4579100x178ec0x23f80x00x3WA0016
                                                                      .mdebug.abi32PROGBITS0x9a20x178ec0x00x00x0001
                                                                      .shstrtabSTRTAB0x00x178ec0x570x00x0001
                                                                      TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                                      LOAD0x00x4000000x4000000x163a00x163a05.63680x5R E0x10000.init .text .fini .rodata
                                                                      LOAD0x170000x4570000x4570000x8ec0x2d083.75760x6RW 0x10000.ctors .dtors .data .got .sbss .bss
                                                                      GNU_STACK0x00x00x00x00x00.00000x7RWE0x4
                                                                      TimestampSource PortDest PortSource IPDest IP
                                                                      Dec 16, 2024 16:53:51.802378893 CET6003859962192.168.2.23185.196.11.47
                                                                      Dec 16, 2024 16:53:51.922348976 CET5996260038185.196.11.47192.168.2.23
                                                                      Dec 16, 2024 16:53:51.922717094 CET6003859962192.168.2.23185.196.11.47
                                                                      Dec 16, 2024 16:53:51.924288034 CET6003859962192.168.2.23185.196.11.47
                                                                      Dec 16, 2024 16:53:52.044061899 CET5996260038185.196.11.47192.168.2.23
                                                                      Dec 16, 2024 16:53:52.044337988 CET6003859962192.168.2.23185.196.11.47
                                                                      Dec 16, 2024 16:53:52.165541887 CET5996260038185.196.11.47192.168.2.23
                                                                      Dec 16, 2024 16:53:53.200042963 CET5996260038185.196.11.47192.168.2.23
                                                                      Dec 16, 2024 16:53:53.200516939 CET6003859962192.168.2.23185.196.11.47
                                                                      Dec 16, 2024 16:53:53.200516939 CET6003859962192.168.2.23185.196.11.47
                                                                      Dec 16, 2024 16:53:53.338319063 CET6004059962192.168.2.23185.196.11.47
                                                                      Dec 16, 2024 16:53:53.458287001 CET5996260040185.196.11.47192.168.2.23
                                                                      Dec 16, 2024 16:53:53.458414078 CET6004059962192.168.2.23185.196.11.47
                                                                      Dec 16, 2024 16:53:53.459800005 CET6004059962192.168.2.23185.196.11.47
                                                                      Dec 16, 2024 16:53:53.580710888 CET5996260040185.196.11.47192.168.2.23
                                                                      Dec 16, 2024 16:53:53.581031084 CET6004059962192.168.2.23185.196.11.47
                                                                      Dec 16, 2024 16:53:53.700896025 CET5996260040185.196.11.47192.168.2.23
                                                                      Dec 16, 2024 16:53:54.265404940 CET42836443192.168.2.2391.189.91.43
                                                                      Dec 16, 2024 16:53:54.757935047 CET5996260040185.196.11.47192.168.2.23
                                                                      Dec 16, 2024 16:53:54.758229971 CET6004059962192.168.2.23185.196.11.47
                                                                      Dec 16, 2024 16:53:54.758229971 CET6004059962192.168.2.23185.196.11.47
                                                                      Dec 16, 2024 16:53:55.156941891 CET6004259962192.168.2.23185.196.11.47
                                                                      Dec 16, 2024 16:53:55.276956081 CET5996260042185.196.11.47192.168.2.23
                                                                      Dec 16, 2024 16:53:55.277129889 CET6004259962192.168.2.23185.196.11.47
                                                                      Dec 16, 2024 16:53:55.279205084 CET6004259962192.168.2.23185.196.11.47
                                                                      Dec 16, 2024 16:53:55.399288893 CET5996260042185.196.11.47192.168.2.23
                                                                      Dec 16, 2024 16:53:55.399595976 CET6004259962192.168.2.23185.196.11.47
                                                                      Dec 16, 2024 16:53:55.519862890 CET5996260042185.196.11.47192.168.2.23
                                                                      Dec 16, 2024 16:53:55.545116901 CET4251680192.168.2.23109.202.202.202
                                                                      Dec 16, 2024 16:53:56.574764013 CET5996260042185.196.11.47192.168.2.23
                                                                      Dec 16, 2024 16:53:56.574939013 CET6004259962192.168.2.23185.196.11.47
                                                                      Dec 16, 2024 16:53:56.575020075 CET6004259962192.168.2.23185.196.11.47
                                                                      Dec 16, 2024 16:53:56.712708950 CET6004459962192.168.2.23185.196.11.47
                                                                      Dec 16, 2024 16:53:56.834315062 CET5996260044185.196.11.47192.168.2.23
                                                                      Dec 16, 2024 16:53:56.834546089 CET6004459962192.168.2.23185.196.11.47
                                                                      Dec 16, 2024 16:53:56.835952044 CET6004459962192.168.2.23185.196.11.47
                                                                      Dec 16, 2024 16:53:56.956118107 CET5996260044185.196.11.47192.168.2.23
                                                                      Dec 16, 2024 16:53:56.956412077 CET6004459962192.168.2.23185.196.11.47
                                                                      Dec 16, 2024 16:53:57.076397896 CET5996260044185.196.11.47192.168.2.23
                                                                      Dec 16, 2024 16:53:58.114152908 CET5996260044185.196.11.47192.168.2.23
                                                                      Dec 16, 2024 16:53:58.114600897 CET6004459962192.168.2.23185.196.11.47
                                                                      Dec 16, 2024 16:53:58.114600897 CET6004459962192.168.2.23185.196.11.47
                                                                      Dec 16, 2024 16:53:58.252568960 CET6004659962192.168.2.23185.196.11.47
                                                                      Dec 16, 2024 16:53:58.372744083 CET5996260046185.196.11.47192.168.2.23
                                                                      Dec 16, 2024 16:53:58.373138905 CET6004659962192.168.2.23185.196.11.47
                                                                      Dec 16, 2024 16:53:58.375185013 CET6004659962192.168.2.23185.196.11.47
                                                                      Dec 16, 2024 16:53:58.495378017 CET5996260046185.196.11.47192.168.2.23
                                                                      Dec 16, 2024 16:53:58.495722055 CET6004659962192.168.2.23185.196.11.47
                                                                      Dec 16, 2024 16:53:58.616090059 CET5996260046185.196.11.47192.168.2.23
                                                                      Dec 16, 2024 16:53:59.652836084 CET5996260046185.196.11.47192.168.2.23
                                                                      Dec 16, 2024 16:53:59.653112888 CET6004659962192.168.2.23185.196.11.47
                                                                      Dec 16, 2024 16:53:59.653112888 CET6004659962192.168.2.23185.196.11.47
                                                                      Dec 16, 2024 16:53:59.790695906 CET6004859962192.168.2.23185.196.11.47
                                                                      Dec 16, 2024 16:53:59.910888910 CET5996260048185.196.11.47192.168.2.23
                                                                      Dec 16, 2024 16:53:59.911206961 CET6004859962192.168.2.23185.196.11.47
                                                                      Dec 16, 2024 16:53:59.912890911 CET6004859962192.168.2.23185.196.11.47
                                                                      Dec 16, 2024 16:54:00.033514977 CET5996260048185.196.11.47192.168.2.23
                                                                      Dec 16, 2024 16:54:00.033637047 CET6004859962192.168.2.23185.196.11.47
                                                                      Dec 16, 2024 16:54:00.156636000 CET5996260048185.196.11.47192.168.2.23
                                                                      Dec 16, 2024 16:54:01.190063953 CET5996260048185.196.11.47192.168.2.23
                                                                      Dec 16, 2024 16:54:01.190357924 CET6004859962192.168.2.23185.196.11.47
                                                                      Dec 16, 2024 16:54:01.190402031 CET6004859962192.168.2.23185.196.11.47
                                                                      Dec 16, 2024 16:54:01.317747116 CET6005059962192.168.2.23185.196.11.47
                                                                      Dec 16, 2024 16:54:01.437793016 CET5996260050185.196.11.47192.168.2.23
                                                                      Dec 16, 2024 16:54:01.437971115 CET6005059962192.168.2.23185.196.11.47
                                                                      Dec 16, 2024 16:54:01.440098047 CET6005059962192.168.2.23185.196.11.47
                                                                      Dec 16, 2024 16:54:01.560260057 CET5996260050185.196.11.47192.168.2.23
                                                                      Dec 16, 2024 16:54:01.560507059 CET6005059962192.168.2.23185.196.11.47
                                                                      Dec 16, 2024 16:54:01.680449963 CET5996260050185.196.11.47192.168.2.23
                                                                      Dec 16, 2024 16:54:02.718563080 CET5996260050185.196.11.47192.168.2.23
                                                                      Dec 16, 2024 16:54:02.718899012 CET6005059962192.168.2.23185.196.11.47
                                                                      Dec 16, 2024 16:54:02.718899012 CET6005059962192.168.2.23185.196.11.47
                                                                      Dec 16, 2024 16:54:02.861465931 CET6005259962192.168.2.23185.196.11.47
                                                                      Dec 16, 2024 16:54:02.981841087 CET5996260052185.196.11.47192.168.2.23
                                                                      Dec 16, 2024 16:54:02.982130051 CET6005259962192.168.2.23185.196.11.47
                                                                      Dec 16, 2024 16:54:02.983865023 CET6005259962192.168.2.23185.196.11.47
                                                                      Dec 16, 2024 16:54:03.104815960 CET5996260052185.196.11.47192.168.2.23
                                                                      Dec 16, 2024 16:54:03.105072975 CET6005259962192.168.2.23185.196.11.47
                                                                      Dec 16, 2024 16:54:03.225886106 CET5996260052185.196.11.47192.168.2.23
                                                                      Dec 16, 2024 16:54:04.263287067 CET5996260052185.196.11.47192.168.2.23
                                                                      Dec 16, 2024 16:54:04.263506889 CET6005259962192.168.2.23185.196.11.47
                                                                      Dec 16, 2024 16:54:04.263542891 CET6005259962192.168.2.23185.196.11.47
                                                                      Dec 16, 2024 16:54:04.402960062 CET6005459962192.168.2.23185.196.11.47
                                                                      Dec 16, 2024 16:54:04.528978109 CET5996260054185.196.11.47192.168.2.23
                                                                      Dec 16, 2024 16:54:04.529253006 CET6005459962192.168.2.23185.196.11.47
                                                                      Dec 16, 2024 16:54:04.531524897 CET6005459962192.168.2.23185.196.11.47
                                                                      Dec 16, 2024 16:54:04.651384115 CET5996260054185.196.11.47192.168.2.23
                                                                      Dec 16, 2024 16:54:04.651632071 CET6005459962192.168.2.23185.196.11.47
                                                                      Dec 16, 2024 16:54:04.771902084 CET5996260054185.196.11.47192.168.2.23
                                                                      Dec 16, 2024 16:54:05.807455063 CET5996260054185.196.11.47192.168.2.23
                                                                      Dec 16, 2024 16:54:05.807696104 CET6005459962192.168.2.23185.196.11.47
                                                                      Dec 16, 2024 16:54:05.807696104 CET6005459962192.168.2.23185.196.11.47
                                                                      Dec 16, 2024 16:54:05.948121071 CET6005659962192.168.2.23185.196.11.47
                                                                      Dec 16, 2024 16:54:06.068447113 CET5996260056185.196.11.47192.168.2.23
                                                                      Dec 16, 2024 16:54:06.068798065 CET6005659962192.168.2.23185.196.11.47
                                                                      Dec 16, 2024 16:54:06.070578098 CET6005659962192.168.2.23185.196.11.47
                                                                      Dec 16, 2024 16:54:06.190490007 CET5996260056185.196.11.47192.168.2.23
                                                                      Dec 16, 2024 16:54:06.190829992 CET6005659962192.168.2.23185.196.11.47
                                                                      Dec 16, 2024 16:54:06.311108112 CET5996260056185.196.11.47192.168.2.23
                                                                      Dec 16, 2024 16:54:09.623295069 CET43928443192.168.2.2391.189.91.42
                                                                      Dec 16, 2024 16:54:16.079698086 CET6005659962192.168.2.23185.196.11.47
                                                                      Dec 16, 2024 16:54:16.199508905 CET5996260056185.196.11.47192.168.2.23
                                                                      Dec 16, 2024 16:54:16.489656925 CET5996260056185.196.11.47192.168.2.23
                                                                      Dec 16, 2024 16:54:16.489808083 CET6005659962192.168.2.23185.196.11.47
                                                                      Dec 16, 2024 16:54:19.861701965 CET42836443192.168.2.2391.189.91.43
                                                                      Dec 16, 2024 16:54:26.004843950 CET4251680192.168.2.23109.202.202.202
                                                                      Dec 16, 2024 16:54:50.577495098 CET43928443192.168.2.2391.189.91.42
                                                                      Dec 16, 2024 16:55:11.054713964 CET42836443192.168.2.2391.189.91.43
                                                                      Dec 16, 2024 16:55:16.533824921 CET6005659962192.168.2.23185.196.11.47
                                                                      Dec 16, 2024 16:55:16.653639078 CET5996260056185.196.11.47192.168.2.23
                                                                      Dec 16, 2024 16:55:16.944006920 CET5996260056185.196.11.47192.168.2.23
                                                                      Dec 16, 2024 16:55:16.944267035 CET6005659962192.168.2.23185.196.11.47
                                                                      TimestampSource PortDest PortSource IPDest IP
                                                                      Dec 16, 2024 16:53:51.425906897 CET4674853192.168.2.238.8.8.8
                                                                      Dec 16, 2024 16:53:51.800600052 CET53467488.8.8.8192.168.2.23
                                                                      Dec 16, 2024 16:53:53.201750040 CET3387753192.168.2.238.8.8.8
                                                                      Dec 16, 2024 16:53:53.337270021 CET53338778.8.8.8192.168.2.23
                                                                      Dec 16, 2024 16:53:54.759710073 CET3841753192.168.2.238.8.8.8
                                                                      Dec 16, 2024 16:53:55.155939102 CET53384178.8.8.8192.168.2.23
                                                                      Dec 16, 2024 16:53:56.577104092 CET5018953192.168.2.238.8.8.8
                                                                      Dec 16, 2024 16:53:56.711569071 CET53501898.8.8.8192.168.2.23
                                                                      Dec 16, 2024 16:53:58.116391897 CET4042953192.168.2.238.8.8.8
                                                                      Dec 16, 2024 16:53:58.250788927 CET53404298.8.8.8192.168.2.23
                                                                      Dec 16, 2024 16:53:59.654942989 CET4983053192.168.2.238.8.8.8
                                                                      Dec 16, 2024 16:53:59.789458990 CET53498308.8.8.8192.168.2.23
                                                                      Dec 16, 2024 16:54:01.192656994 CET4100053192.168.2.238.8.8.8
                                                                      Dec 16, 2024 16:54:01.316428900 CET53410008.8.8.8192.168.2.23
                                                                      Dec 16, 2024 16:54:02.721211910 CET4231153192.168.2.238.8.8.8
                                                                      Dec 16, 2024 16:54:02.860054016 CET53423118.8.8.8192.168.2.23
                                                                      Dec 16, 2024 16:54:04.266032934 CET4084653192.168.2.238.8.8.8
                                                                      Dec 16, 2024 16:54:04.401326895 CET53408468.8.8.8192.168.2.23
                                                                      Dec 16, 2024 16:54:05.809725046 CET5297753192.168.2.238.8.8.8
                                                                      Dec 16, 2024 16:54:05.946531057 CET53529778.8.8.8192.168.2.23
                                                                      TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                                                      Dec 16, 2024 16:53:51.425906897 CET192.168.2.238.8.8.80x109fStandard query (0)servers.vlrt-gap.comA (IP address)IN (0x0001)false
                                                                      Dec 16, 2024 16:53:53.201750040 CET192.168.2.238.8.8.80x7151Standard query (0)servers.vlrt-gap.comA (IP address)IN (0x0001)false
                                                                      Dec 16, 2024 16:53:54.759710073 CET192.168.2.238.8.8.80x3d74Standard query (0)servers.vlrt-gap.comA (IP address)IN (0x0001)false
                                                                      Dec 16, 2024 16:53:56.577104092 CET192.168.2.238.8.8.80x6b86Standard query (0)servers.vlrt-gap.comA (IP address)IN (0x0001)false
                                                                      Dec 16, 2024 16:53:58.116391897 CET192.168.2.238.8.8.80x4ac6Standard query (0)servers.vlrt-gap.comA (IP address)IN (0x0001)false
                                                                      Dec 16, 2024 16:53:59.654942989 CET192.168.2.238.8.8.80xc3c5Standard query (0)servers.vlrt-gap.comA (IP address)IN (0x0001)false
                                                                      Dec 16, 2024 16:54:01.192656994 CET192.168.2.238.8.8.80xf8ecStandard query (0)servers.vlrt-gap.comA (IP address)IN (0x0001)false
                                                                      Dec 16, 2024 16:54:02.721211910 CET192.168.2.238.8.8.80x9f28Standard query (0)servers.vlrt-gap.comA (IP address)IN (0x0001)false
                                                                      Dec 16, 2024 16:54:04.266032934 CET192.168.2.238.8.8.80x7521Standard query (0)servers.vlrt-gap.comA (IP address)IN (0x0001)false
                                                                      Dec 16, 2024 16:54:05.809725046 CET192.168.2.238.8.8.80xe638Standard query (0)servers.vlrt-gap.comA (IP address)IN (0x0001)false
                                                                      TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                                                      Dec 16, 2024 16:53:51.800600052 CET8.8.8.8192.168.2.230x109fNo error (0)servers.vlrt-gap.com185.196.11.47A (IP address)IN (0x0001)false
                                                                      Dec 16, 2024 16:53:53.337270021 CET8.8.8.8192.168.2.230x7151No error (0)servers.vlrt-gap.com185.196.11.47A (IP address)IN (0x0001)false
                                                                      Dec 16, 2024 16:53:55.155939102 CET8.8.8.8192.168.2.230x3d74No error (0)servers.vlrt-gap.com185.196.11.47A (IP address)IN (0x0001)false
                                                                      Dec 16, 2024 16:53:56.711569071 CET8.8.8.8192.168.2.230x6b86No error (0)servers.vlrt-gap.com185.196.11.47A (IP address)IN (0x0001)false
                                                                      Dec 16, 2024 16:53:58.250788927 CET8.8.8.8192.168.2.230x4ac6No error (0)servers.vlrt-gap.com185.196.11.47A (IP address)IN (0x0001)false
                                                                      Dec 16, 2024 16:53:59.789458990 CET8.8.8.8192.168.2.230xc3c5No error (0)servers.vlrt-gap.com185.196.11.47A (IP address)IN (0x0001)false
                                                                      Dec 16, 2024 16:54:01.316428900 CET8.8.8.8192.168.2.230xf8ecNo error (0)servers.vlrt-gap.com185.196.11.47A (IP address)IN (0x0001)false
                                                                      Dec 16, 2024 16:54:02.860054016 CET8.8.8.8192.168.2.230x9f28No error (0)servers.vlrt-gap.com185.196.11.47A (IP address)IN (0x0001)false
                                                                      Dec 16, 2024 16:54:04.401326895 CET8.8.8.8192.168.2.230x7521No error (0)servers.vlrt-gap.com185.196.11.47A (IP address)IN (0x0001)false
                                                                      Dec 16, 2024 16:54:05.946531057 CET8.8.8.8192.168.2.230xe638No error (0)servers.vlrt-gap.com185.196.11.47A (IP address)IN (0x0001)false

                                                                      System Behavior

                                                                      Start time (UTC):15:53:50
                                                                      Start date (UTC):16/12/2024
                                                                      Path:/tmp/zmap.mips.elf
                                                                      Arguments:/tmp/zmap.mips.elf
                                                                      File size:5777432 bytes
                                                                      MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                                                                      Start time (UTC):15:53:50
                                                                      Start date (UTC):16/12/2024
                                                                      Path:/tmp/zmap.mips.elf
                                                                      Arguments:-
                                                                      File size:5777432 bytes
                                                                      MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                                                                      Start time (UTC):15:53:50
                                                                      Start date (UTC):16/12/2024
                                                                      Path:/tmp/zmap.mips.elf
                                                                      Arguments:-
                                                                      File size:5777432 bytes
                                                                      MD5 hash:0083f1f0e77be34ad27f849842bbb00c