Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
arm.elf

Overview

General Information

Sample name:arm.elf
Analysis ID:1579456
MD5:589e7fce814766cf406c20949af6cf4a
SHA1:51541c7f6a63149749d4da9de094cc1f429dc4b0
SHA256:e1bfa3b4009b55e0f99b1fb8b6b27fa355642e9e49fcca1e78c9f56af4a7b37a
Tags:elfuser-abuse_ch
Infos:

Detection

Score:48
Range:0 - 100
Whitelisted:false

Signatures

Drops files in suspicious directories
Sample tries to kill multiple processes (SIGKILL)
Detected TCP or UDP traffic on non-standard ports
Executes commands using a shell command-line interpreter
Found strings indicative of a multi-platform dropper
Sample has stripped symbol table
Sample tries to kill a process (SIGKILL)
Uses the "uname" system call to query kernel version information (possible evasion)
Writes ELF files to disk

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1579456
Start date and time:2024-12-22 13:26:14 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 5m 42s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:arm.elf
Detection:MAL
Classification:mal48.spre.evad.linELF@0/2@12/0
Command:/tmp/arm.elf
PID:5519
Exit Code:
Exit Code Info:
Killed:True
Standard Output:

Standard Error:Error opening rc.local: No such file or directory
  • system is lnxubuntu20
  • arm.elf (PID: 5519, Parent: 5435, MD5: 5ebfcae4fe2471fcc5695c2394773ff1) Arguments: /tmp/arm.elf
    • arm.elf New Fork (PID: 5521, Parent: 5519)
    • sh (PID: 5521, Parent: 5519, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "cp /tmp/arm.elf /usr/bin/bot"
      • sh New Fork (PID: 5527, Parent: 5521)
      • cp (PID: 5527, Parent: 5521, MD5: 40f10ae7ea3e44218d1a8c306f79c83f) Arguments: cp /tmp/arm.elf /usr/bin/bot
    • arm.elf New Fork (PID: 5528, Parent: 5519)
  • sh (PID: 5530, Parent: 1498, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-housekeeping
  • gsd-housekeeping (PID: 5530, Parent: 1498, MD5: b55f3394a84976ddb92a2915e5d76914) Arguments: /usr/libexec/gsd-housekeeping
  • gdm3 New Fork (PID: 5561, Parent: 1333)
  • Default (PID: 5561, Parent: 1333, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /etc/gdm3/PrimeOff/Default
  • gdm3 New Fork (PID: 5562, Parent: 1333)
  • Default (PID: 5562, Parent: 1333, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /etc/gdm3/PrimeOff/Default
  • systemd New Fork (PID: 5606, Parent: 1)
  • systemd-user-runtime-dir (PID: 5606, Parent: 1, MD5: d55f4b0847f88131dbcfb07435178e54) Arguments: /lib/systemd/systemd-user-runtime-dir stop 127
  • cleanup
No yara matches
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results
Source: arm.elfString: Sent architecture info: %sUDP socket creation failedTCP socket creation failedwgetcurlpingpstcpdumppythonvim
Source: bot.16.drString: Sent architecture info: %sUDP socket creation failedTCP socket creation failedwgetcurlpingpstcpdumppythonvim
Source: global trafficTCP traffic: 192.168.2.15:40894 -> 92.249.48.36:5000
Source: unknownTCP traffic detected without corresponding DNS query: 92.249.48.36
Source: unknownTCP traffic detected without corresponding DNS query: 92.249.48.36
Source: unknownTCP traffic detected without corresponding DNS query: 92.249.48.36
Source: unknownTCP traffic detected without corresponding DNS query: 92.249.48.36
Source: unknownTCP traffic detected without corresponding DNS query: 92.249.48.36
Source: unknownTCP traffic detected without corresponding DNS query: 92.249.48.36
Source: unknownTCP traffic detected without corresponding DNS query: 92.249.48.36
Source: unknownTCP traffic detected without corresponding DNS query: 92.249.48.36
Source: unknownTCP traffic detected without corresponding DNS query: 92.249.48.36
Source: unknownTCP traffic detected without corresponding DNS query: 92.249.48.36
Source: unknownTCP traffic detected without corresponding DNS query: 92.249.48.36
Source: unknownTCP traffic detected without corresponding DNS query: 92.249.48.36
Source: unknownTCP traffic detected without corresponding DNS query: 92.249.48.36
Source: unknownTCP traffic detected without corresponding DNS query: 92.249.48.36
Source: unknownTCP traffic detected without corresponding DNS query: 92.249.48.36
Source: unknownTCP traffic detected without corresponding DNS query: 92.249.48.36
Source: unknownTCP traffic detected without corresponding DNS query: 92.249.48.36
Source: unknownTCP traffic detected without corresponding DNS query: 92.249.48.36
Source: unknownTCP traffic detected without corresponding DNS query: 92.249.48.36
Source: unknownTCP traffic detected without corresponding DNS query: 92.249.48.36
Source: unknownTCP traffic detected without corresponding DNS query: 92.249.48.36
Source: unknownTCP traffic detected without corresponding DNS query: 92.249.48.36
Source: unknownTCP traffic detected without corresponding DNS query: 92.249.48.36
Source: unknownTCP traffic detected without corresponding DNS query: 92.249.48.36
Source: unknownTCP traffic detected without corresponding DNS query: 92.249.48.36
Source: unknownTCP traffic detected without corresponding DNS query: 92.249.48.36
Source: unknownTCP traffic detected without corresponding DNS query: 92.249.48.36
Source: unknownTCP traffic detected without corresponding DNS query: 92.249.48.36
Source: unknownTCP traffic detected without corresponding DNS query: 92.249.48.36
Source: unknownTCP traffic detected without corresponding DNS query: 92.249.48.36
Source: unknownTCP traffic detected without corresponding DNS query: 92.249.48.36
Source: unknownTCP traffic detected without corresponding DNS query: 92.249.48.36
Source: unknownTCP traffic detected without corresponding DNS query: 92.249.48.36
Source: unknownTCP traffic detected without corresponding DNS query: 92.249.48.36
Source: unknownTCP traffic detected without corresponding DNS query: 92.249.48.36
Source: unknownTCP traffic detected without corresponding DNS query: 92.249.48.36
Source: unknownTCP traffic detected without corresponding DNS query: 92.249.48.36
Source: unknownTCP traffic detected without corresponding DNS query: 92.249.48.36
Source: unknownTCP traffic detected without corresponding DNS query: 92.249.48.36
Source: unknownTCP traffic detected without corresponding DNS query: 92.249.48.36
Source: unknownTCP traffic detected without corresponding DNS query: 92.249.48.36
Source: unknownTCP traffic detected without corresponding DNS query: 92.249.48.36
Source: unknownTCP traffic detected without corresponding DNS query: 92.249.48.36
Source: unknownTCP traffic detected without corresponding DNS query: 92.249.48.36
Source: unknownTCP traffic detected without corresponding DNS query: 92.249.48.36
Source: unknownTCP traffic detected without corresponding DNS query: 92.249.48.36
Source: unknownTCP traffic detected without corresponding DNS query: 92.249.48.36
Source: unknownTCP traffic detected without corresponding DNS query: 92.249.48.36
Source: unknownTCP traffic detected without corresponding DNS query: 92.249.48.36
Source: unknownTCP traffic detected without corresponding DNS query: 92.249.48.36
Source: global trafficDNS traffic detected: DNS query: daisy.ubuntu.com

System Summary

barindex
Source: /tmp/arm.elf (PID: 5528)SIGKILL sent: pid: 793, result: successfulJump to behavior
Source: /tmp/arm.elf (PID: 5528)SIGKILL sent: pid: 888, result: successfulJump to behavior
Source: /tmp/arm.elf (PID: 5528)SIGKILL sent: pid: 917, result: successfulJump to behavior
Source: /tmp/arm.elf (PID: 5528)SIGKILL sent: pid: 931, result: successfulJump to behavior
Source: /tmp/arm.elf (PID: 5528)SIGKILL sent: pid: 1729, result: successfulJump to behavior
Source: /tmp/arm.elf (PID: 5528)SIGKILL sent: pid: 3273, result: successfulJump to behavior
Source: /tmp/arm.elf (PID: 5528)SIGKILL sent: pid: 3278, result: successfulJump to behavior
Source: /tmp/arm.elf (PID: 5528)SIGKILL sent: pid: 3407, result: successfulJump to behavior
Source: /tmp/arm.elf (PID: 5528)SIGKILL sent: pid: 5530, result: successfulJump to behavior
Source: /tmp/arm.elf (PID: 5528)SIGKILL sent: pid: 5685, result: successfulJump to behavior
Source: /tmp/arm.elf (PID: 5528)SIGKILL sent: pid: 5695, result: successfulJump to behavior
Source: /tmp/arm.elf (PID: 5528)SIGKILL sent: pid: 5705, result: successfulJump to behavior
Source: /tmp/arm.elf (PID: 5528)SIGKILL sent: pid: 5714, result: successfulJump to behavior
Source: /tmp/arm.elf (PID: 5528)SIGKILL sent: pid: 5722, result: successfulJump to behavior
Source: /tmp/arm.elf (PID: 5528)SIGKILL sent: pid: 5731, result: successfulJump to behavior
Source: /tmp/arm.elf (PID: 5528)SIGKILL sent: pid: 5740, result: successfulJump to behavior
Source: /tmp/arm.elf (PID: 5528)SIGKILL sent: pid: 5748, result: successfulJump to behavior
Source: /tmp/arm.elf (PID: 5528)SIGKILL sent: pid: 5758, result: successfulJump to behavior
Source: ELF static info symbol of initial sample.symtab present: no
Source: /tmp/arm.elf (PID: 5528)SIGKILL sent: pid: 793, result: successfulJump to behavior
Source: /tmp/arm.elf (PID: 5528)SIGKILL sent: pid: 888, result: successfulJump to behavior
Source: /tmp/arm.elf (PID: 5528)SIGKILL sent: pid: 917, result: successfulJump to behavior
Source: /tmp/arm.elf (PID: 5528)SIGKILL sent: pid: 931, result: successfulJump to behavior
Source: /tmp/arm.elf (PID: 5528)SIGKILL sent: pid: 1729, result: successfulJump to behavior
Source: /tmp/arm.elf (PID: 5528)SIGKILL sent: pid: 3273, result: successfulJump to behavior
Source: /tmp/arm.elf (PID: 5528)SIGKILL sent: pid: 3278, result: successfulJump to behavior
Source: /tmp/arm.elf (PID: 5528)SIGKILL sent: pid: 3407, result: successfulJump to behavior
Source: /tmp/arm.elf (PID: 5528)SIGKILL sent: pid: 5530, result: successfulJump to behavior
Source: /tmp/arm.elf (PID: 5528)SIGKILL sent: pid: 5685, result: successfulJump to behavior
Source: /tmp/arm.elf (PID: 5528)SIGKILL sent: pid: 5695, result: successfulJump to behavior
Source: /tmp/arm.elf (PID: 5528)SIGKILL sent: pid: 5705, result: successfulJump to behavior
Source: /tmp/arm.elf (PID: 5528)SIGKILL sent: pid: 5714, result: successfulJump to behavior
Source: /tmp/arm.elf (PID: 5528)SIGKILL sent: pid: 5722, result: successfulJump to behavior
Source: /tmp/arm.elf (PID: 5528)SIGKILL sent: pid: 5731, result: successfulJump to behavior
Source: /tmp/arm.elf (PID: 5528)SIGKILL sent: pid: 5740, result: successfulJump to behavior
Source: /tmp/arm.elf (PID: 5528)SIGKILL sent: pid: 5748, result: successfulJump to behavior
Source: /tmp/arm.elf (PID: 5528)SIGKILL sent: pid: 5758, result: successfulJump to behavior
Source: classification engineClassification label: mal48.spre.evad.linELF@0/2@12/0
Source: /tmp/arm.elf (PID: 5521)Shell command executed: sh -c "cp /tmp/arm.elf /usr/bin/bot"Jump to behavior
Source: /usr/bin/cp (PID: 5527)File written: /usr/bin/botJump to dropped file

Hooking and other Techniques for Hiding and Protection

barindex
Source: /usr/bin/cp (PID: 5527)File: /usr/bin/botJump to dropped file
Source: /tmp/arm.elf (PID: 5519)Queries kernel information via 'uname': Jump to behavior
Source: arm.elf, 5519.1.000055602b2b2000.000055602b3e0000.rw-.sdmpBinary or memory string: ,+`U!/etc/qemu-binfmt/arm
Source: arm.elf, 5519.1.00007ffe22d4e000.00007ffe22d6f000.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-arm/tmp/arm.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/arm.elf
Source: arm.elf, 5519.1.000055602b2b2000.000055602b3e0000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/arm
Source: arm.elf, 5519.1.00007ffe22d4e000.00007ffe22d6f000.rw-.sdmpBinary or memory string: /usr/bin/qemu-arm
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity Information2
Scripting
Valid AccountsWindows Management Instrumentation2
Scripting
Path Interception1
Masquerading
OS Credential Dumping11
Security Software Discovery
Remote ServicesData from Local System1
Non-Standard Port
Exfiltration Over Other Network Medium1
Service Stop
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1579456 Sample: arm.elf Startdate: 22/12/2024 Architecture: LINUX Score: 48 26 92.249.48.36, 40894, 40896, 40898 M247GB Germany 2->26 28 daisy.ubuntu.com 2->28 7 arm.elf 2->7         started        9 gnome-session-binary sh gsd-housekeeping 2->9         started        11 gdm3 Default 2->11         started        13 2 other processes 2->13 process3 process4 15 arm.elf sh 7->15         started        17 arm.elf 7->17         started        signatures5 20 sh cp 15->20         started        30 Sample tries to kill multiple processes (SIGKILL) 17->30 process6 file7 24 /usr/bin/bot, ELF 20->24 dropped 32 Drops files in suspicious directories 20->32 signatures8

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
arm.elf5%ReversingLabs
SourceDetectionScannerLabelLink
/usr/bin/bot5%ReversingLabs
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
daisy.ubuntu.com
162.213.35.24
truefalse
    high
    • No. of IPs < 25%
    • 25% < No. of IPs < 50%
    • 50% < No. of IPs < 75%
    • 75% < No. of IPs
    IPDomainCountryFlagASNASN NameMalicious
    92.249.48.36
    unknownGermany
    9009M247GBfalse
    No context
    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
    daisy.ubuntu.combyte.x86.elfGet hashmaliciousMirai, OkiruBrowse
    • 162.213.35.25
    x86_64.nn.elfGet hashmaliciousMirai, OkiruBrowse
    • 162.213.35.24
    m68k.nn.elfGet hashmaliciousMirai, OkiruBrowse
    • 162.213.35.24
    vlxx.arm6.elfGet hashmaliciousMirai, OkiruBrowse
    • 162.213.35.25
    la.bot.powerpc.elfGet hashmaliciousMiraiBrowse
    • 162.213.35.24
    la.bot.sh4.elfGet hashmaliciousMiraiBrowse
    • 162.213.35.25
    la.bot.mipsel.elfGet hashmaliciousMiraiBrowse
    • 162.213.35.25
    la.bot.mips.elfGet hashmaliciousMiraiBrowse
    • 162.213.35.24
    la.bot.mipsel.elfGet hashmaliciousMiraiBrowse
    • 162.213.35.25
    la.bot.arm7.elfGet hashmaliciousMiraiBrowse
    • 162.213.35.25
    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
    M247GBpowerpc.nn.elfGet hashmaliciousMirai, OkiruBrowse
    • 38.204.189.65
    hmips.elfGet hashmaliciousMiraiBrowse
    • 38.207.37.102
    nshppc.elfGet hashmaliciousMiraiBrowse
    • 185.120.145.21
    la.bot.powerpc.elfGet hashmaliciousMiraiBrowse
    • 196.18.78.47
    x86_32.nn.elfGet hashmaliciousMirai, OkiruBrowse
    • 196.16.89.5
    powerpc.nn.elfGet hashmaliciousMirai, OkiruBrowse
    • 193.37.253.255
    mipsel.nn.elfGet hashmaliciousMirai, OkiruBrowse
    • 212.103.49.57
    arm5.nn.elfGet hashmaliciousMirai, OkiruBrowse
    • 185.94.197.148
    file.exeGet hashmaliciousLummaC, Amadey, Cryptbot, LummaC Stealer, Poverty Stealer, RHADAMANTHYS, XmrigBrowse
    • 185.244.212.106
    67618a47ee8c5.vbsGet hashmaliciousMint StealerBrowse
    • 45.11.180.77
    No context
    No context
    Process:/usr/libexec/gsd-housekeeping
    File Type:very short file (no magic)
    Category:dropped
    Size (bytes):1
    Entropy (8bit):0.0
    Encrypted:false
    SSDEEP:3::
    MD5:93B885ADFE0DA089CDF634904FD59F71
    SHA1:5BA93C9DB0CFF93F52B521D7420E43F6EDA2784F
    SHA-256:6E340B9CFFB37A989CA544E6BB780A2C78901D3FB33738768511A30617AFA01D
    SHA-512:B8244D028981D693AF7B456AF8EFA4CAD63D282E19FF14942C246E50D9351D22704A802A71C3580B6370DE4CEB293C324A8423342557D4E5C38438F0E36910EE
    Malicious:false
    Reputation:high, very likely benign file
    Preview:.
    Process:/usr/bin/cp
    File Type:ELF 32-bit LSB executable, ARM, version 1 (ARM), statically linked, stripped
    Category:dropped
    Size (bytes):57160
    Entropy (8bit):6.096505055204254
    Encrypted:false
    SSDEEP:1536:qGdU5fkXfvQ/yRdVgOZSFAlyUrjEhfjCxB+xH6vRjHj:AMXfvd1VMFAlyUrjYfjCxB+xodHj
    MD5:589E7FCE814766CF406C20949AF6CF4A
    SHA1:51541C7F6A63149749D4DA9DE094CC1F429DC4B0
    SHA-256:E1BFA3B4009B55E0F99B1FB8B6B27FA355642E9E49FCCA1E78C9F56AF4A7B37A
    SHA-512:20655BCD294C2E1EFD73D85CF09DF175D97683BF4598C01554D97F233A5C194E74A60B7CB49475FB370D7B2EFB8FBCE455A2012301A41DF108C89C9FD36A0E28
    Malicious:true
    Antivirus:
    • Antivirus: ReversingLabs, Detection: 5%
    Reputation:low
    Preview:.ELF...a..........(.........4...........4. ...(..........................................................&..........Q.td..................................-...L."..............0@-.\P...0....S.0...P@...0... ....R......0...0.........0... ....R..... 0....S............0...0..0....... .............-....<0....S...-.4...4.........,....0....S.... 0....S...................................-................ ... -...-.......-......0.........<<................-...L.R.M.4...........0.. 0.. 0....S............A....1...0....K..0...0........... .. 0.......>K.........0...0...0...0..............0...0...0....S............%...Q>K..0C..0C..........+...0......Q>K..0C..0C.........!....0....S.....t........................... ..k.......P.... .................{...........0...t.....K.....P<..`<...<...<...<...<...<...<...<...<...=........-...L...M.....40...0..........0........... ...0..^................K.....H=..\=........-...L.8.M.0...4...8 ..<0...0..2K.40...8..#8......z....0..2K.(0K..0..
    File type:ELF 32-bit LSB executable, ARM, version 1 (ARM), statically linked, stripped
    Entropy (8bit):6.096505055204254
    TrID:
    • ELF Executable and Linkable format (generic) (4004/1) 100.00%
    File name:arm.elf
    File size:57'160 bytes
    MD5:589e7fce814766cf406c20949af6cf4a
    SHA1:51541c7f6a63149749d4da9de094cc1f429dc4b0
    SHA256:e1bfa3b4009b55e0f99b1fb8b6b27fa355642e9e49fcca1e78c9f56af4a7b37a
    SHA512:20655bcd294c2e1efd73d85cf09df175d97683bf4598c01554d97f233a5c194e74a60b7cb49475fb370d7b2efb8fbce455a2012301a41df108c89c9fd36a0e28
    SSDEEP:1536:qGdU5fkXfvQ/yRdVgOZSFAlyUrjEhfjCxB+xH6vRjHj:AMXfvd1VMFAlyUrjYfjCxB+xodHj
    TLSH:FE432B45B65A8F02C5C320B7FF9F82483A166FADD2F57212A934EFA123874D61D77212
    File Content Preview:.ELF...a..........(.........4...........4. ...(..........................................................&..........Q.td..................................-...L."...............0@-.\P...0....S.0...P@...0... ....R......0...0...........0... ....R..... 0....S

    ELF header

    Class:ELF32
    Data:2's complement, little endian
    Version:1 (current)
    Machine:ARM
    Version Number:0x1
    Type:EXEC (Executable file)
    OS/ABI:ARM - ABI
    ABI Version:0
    Entry Point Address:0x8190
    Flags:0x202
    ELF Header Size:52
    Program Header Offset:52
    Program Header Size:32
    Number of Program Headers:3
    Section Header Offset:56600
    Section Header Size:40
    Number of Section Headers:14
    Header String Table Index:13
    NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
    NULL0x00x00x00x00x0000
    .initPROGBITS0x80940x940x180x00x6AX004
    .textPROGBITS0x80b00xb00xbb8c0x00x6AX0016
    .finiPROGBITS0x13c3c0xbc3c0x140x00x6AX004
    .rodataPROGBITS0x13c500xbc500x13700x00x2A004
    .eh_framePROGBITS0x1d0000xd0000x40x00x3WA004
    .ctorsPROGBITS0x1d0040xd0040x80x00x3WA004
    .dtorsPROGBITS0x1d00c0xd00c0x80x00x3WA004
    .jcrPROGBITS0x1d0140xd0140x40x00x3WA004
    .dataPROGBITS0x1d0180xd0180x1b00x00x3WA004
    .bssNOBITS0x1d1c80xd1c80x24380x00x3WA004
    .commentPROGBITS0x00xd1c80xad80x00x0001
    .ARM.attributesARM_ATTRIBUTES0x00xdca00x100x00x0001
    .shstrtabSTRTAB0x00xdcb00x660x00x0001
    TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
    LOAD0x00x80000x80000xcfc00xcfc06.07700x5R E0x8000.init .text .fini .rodata
    LOAD0xd0000x1d0000x1d0000x1c80x26001.59190x6RW 0x8000.eh_frame .ctors .dtors .jcr .data .bss
    GNU_STACK0x00x00x00x00x00.00000x7RWE0x4
    TimestampSource PortDest PortSource IPDest IP
    Dec 22, 2024 13:27:01.398758888 CET408945000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:01.518860102 CET50004089492.249.48.36192.168.2.15
    Dec 22, 2024 13:27:01.518948078 CET408945000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:01.519891024 CET408945000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:01.639905930 CET50004089492.249.48.36192.168.2.15
    Dec 22, 2024 13:27:01.639972925 CET408945000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:01.760401011 CET50004089492.249.48.36192.168.2.15
    Dec 22, 2024 13:27:02.751591921 CET50004089492.249.48.36192.168.2.15
    Dec 22, 2024 13:27:02.752186060 CET408945000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:02.753639936 CET408965000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:02.872236013 CET50004089492.249.48.36192.168.2.15
    Dec 22, 2024 13:27:02.873480082 CET50004089692.249.48.36192.168.2.15
    Dec 22, 2024 13:27:02.873684883 CET408965000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:02.874933958 CET408965000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:02.994927883 CET50004089692.249.48.36192.168.2.15
    Dec 22, 2024 13:27:02.995141983 CET408965000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:03.115401030 CET50004089692.249.48.36192.168.2.15
    Dec 22, 2024 13:27:04.136435986 CET50004089692.249.48.36192.168.2.15
    Dec 22, 2024 13:27:04.137018919 CET408965000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:04.138320923 CET408985000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:04.257102966 CET50004089692.249.48.36192.168.2.15
    Dec 22, 2024 13:27:04.258291006 CET50004089892.249.48.36192.168.2.15
    Dec 22, 2024 13:27:04.258526087 CET408985000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:04.259885073 CET408985000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:04.620223999 CET50004089892.249.48.36192.168.2.15
    Dec 22, 2024 13:27:04.620441914 CET408985000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:04.740510941 CET50004089892.249.48.36192.168.2.15
    Dec 22, 2024 13:27:05.795600891 CET50004089892.249.48.36192.168.2.15
    Dec 22, 2024 13:27:05.795980930 CET408985000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:05.797086954 CET409005000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:05.915549994 CET50004089892.249.48.36192.168.2.15
    Dec 22, 2024 13:27:05.916557074 CET50004090092.249.48.36192.168.2.15
    Dec 22, 2024 13:27:05.916991949 CET409005000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:05.918597937 CET409005000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:06.038060904 CET50004090092.249.48.36192.168.2.15
    Dec 22, 2024 13:27:06.038332939 CET409005000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:06.158175945 CET50004090092.249.48.36192.168.2.15
    Dec 22, 2024 13:27:07.159347057 CET50004090092.249.48.36192.168.2.15
    Dec 22, 2024 13:27:07.159749985 CET409005000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:07.161355019 CET409025000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:07.279511929 CET50004090092.249.48.36192.168.2.15
    Dec 22, 2024 13:27:07.281290054 CET50004090292.249.48.36192.168.2.15
    Dec 22, 2024 13:27:07.281506062 CET409025000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:07.282058954 CET409025000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:07.401887894 CET50004090292.249.48.36192.168.2.15
    Dec 22, 2024 13:27:07.402044058 CET409025000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:07.521995068 CET50004090292.249.48.36192.168.2.15
    Dec 22, 2024 13:27:08.517748117 CET50004090292.249.48.36192.168.2.15
    Dec 22, 2024 13:27:08.517992973 CET409025000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:08.519021034 CET409045000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:08.637846947 CET50004090292.249.48.36192.168.2.15
    Dec 22, 2024 13:27:08.638618946 CET50004090492.249.48.36192.168.2.15
    Dec 22, 2024 13:27:08.638844013 CET409045000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:08.639590979 CET409045000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:08.759104967 CET50004090492.249.48.36192.168.2.15
    Dec 22, 2024 13:27:08.759172916 CET409045000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:08.879533052 CET50004090492.249.48.36192.168.2.15
    Dec 22, 2024 13:27:09.897362947 CET50004090492.249.48.36192.168.2.15
    Dec 22, 2024 13:27:09.897466898 CET409045000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:09.898381948 CET409065000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:10.017038107 CET50004090492.249.48.36192.168.2.15
    Dec 22, 2024 13:27:10.017987013 CET50004090692.249.48.36192.168.2.15
    Dec 22, 2024 13:27:10.018131018 CET409065000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:10.018657923 CET409065000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:10.138638973 CET50004090692.249.48.36192.168.2.15
    Dec 22, 2024 13:27:10.138767958 CET409065000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:10.258734941 CET50004090692.249.48.36192.168.2.15
    Dec 22, 2024 13:27:11.292629957 CET50004090692.249.48.36192.168.2.15
    Dec 22, 2024 13:27:11.292788982 CET409065000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:11.293627977 CET409085000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:11.412720919 CET50004090692.249.48.36192.168.2.15
    Dec 22, 2024 13:27:11.413538933 CET50004090892.249.48.36192.168.2.15
    Dec 22, 2024 13:27:11.413893938 CET409085000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:11.414880991 CET409085000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:11.534694910 CET50004090892.249.48.36192.168.2.15
    Dec 22, 2024 13:27:11.534810066 CET409085000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:11.654788017 CET50004090892.249.48.36192.168.2.15
    Dec 22, 2024 13:27:12.673782110 CET50004090892.249.48.36192.168.2.15
    Dec 22, 2024 13:27:12.674144983 CET409085000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:12.674932003 CET409105000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:12.794187069 CET50004090892.249.48.36192.168.2.15
    Dec 22, 2024 13:27:12.794855118 CET50004091092.249.48.36192.168.2.15
    Dec 22, 2024 13:27:12.795069933 CET409105000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:12.795588017 CET409105000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:12.915184021 CET50004091092.249.48.36192.168.2.15
    Dec 22, 2024 13:27:12.915430069 CET409105000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:13.035131931 CET50004091092.249.48.36192.168.2.15
    Dec 22, 2024 13:27:14.038789988 CET50004091092.249.48.36192.168.2.15
    Dec 22, 2024 13:27:14.039138079 CET409105000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:14.040111065 CET409125000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:14.159081936 CET50004091092.249.48.36192.168.2.15
    Dec 22, 2024 13:27:14.159708023 CET50004091292.249.48.36192.168.2.15
    Dec 22, 2024 13:27:14.159815073 CET409125000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:14.161600113 CET409125000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:14.281646967 CET50004091292.249.48.36192.168.2.15
    Dec 22, 2024 13:27:14.281955004 CET409125000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:14.401972055 CET50004091292.249.48.36192.168.2.15
    Dec 22, 2024 13:27:15.400147915 CET50004091292.249.48.36192.168.2.15
    Dec 22, 2024 13:27:15.400516987 CET409125000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:15.401168108 CET409145000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:15.520426989 CET50004091292.249.48.36192.168.2.15
    Dec 22, 2024 13:27:15.521215916 CET50004091492.249.48.36192.168.2.15
    Dec 22, 2024 13:27:15.521512032 CET409145000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:15.523201942 CET409145000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:15.643758059 CET50004091492.249.48.36192.168.2.15
    Dec 22, 2024 13:27:15.643996954 CET409145000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:15.764806032 CET50004091492.249.48.36192.168.2.15
    Dec 22, 2024 13:27:16.763503075 CET50004091492.249.48.36192.168.2.15
    Dec 22, 2024 13:27:16.763922930 CET409145000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:16.764597893 CET409165000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:16.883833885 CET50004091492.249.48.36192.168.2.15
    Dec 22, 2024 13:27:16.884237051 CET50004091692.249.48.36192.168.2.15
    Dec 22, 2024 13:27:16.884442091 CET409165000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:16.885356903 CET409165000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:17.005105019 CET50004091692.249.48.36192.168.2.15
    Dec 22, 2024 13:27:17.005167007 CET409165000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:17.124970913 CET50004091692.249.48.36192.168.2.15
    Dec 22, 2024 13:27:18.137320995 CET50004091692.249.48.36192.168.2.15
    Dec 22, 2024 13:27:18.137516975 CET409165000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:18.138859987 CET409185000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:18.257622004 CET50004091692.249.48.36192.168.2.15
    Dec 22, 2024 13:27:18.259005070 CET50004091892.249.48.36192.168.2.15
    Dec 22, 2024 13:27:18.259082079 CET409185000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:18.260278940 CET409185000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:18.380038977 CET50004091892.249.48.36192.168.2.15
    Dec 22, 2024 13:27:18.380261898 CET409185000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:18.500406027 CET50004091892.249.48.36192.168.2.15
    Dec 22, 2024 13:27:19.492507935 CET50004091892.249.48.36192.168.2.15
    Dec 22, 2024 13:27:19.492721081 CET409185000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:19.494240999 CET409205000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:19.612688065 CET50004091892.249.48.36192.168.2.15
    Dec 22, 2024 13:27:19.614068985 CET50004092092.249.48.36192.168.2.15
    Dec 22, 2024 13:27:19.614412069 CET409205000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:19.615572929 CET409205000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:19.736103058 CET50004092092.249.48.36192.168.2.15
    Dec 22, 2024 13:27:19.736440897 CET409205000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:19.857115984 CET50004092092.249.48.36192.168.2.15
    Dec 22, 2024 13:27:20.855493069 CET50004092092.249.48.36192.168.2.15
    Dec 22, 2024 13:27:20.855671883 CET409205000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:20.856719017 CET409225000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:20.975816011 CET50004092092.249.48.36192.168.2.15
    Dec 22, 2024 13:27:20.976520061 CET50004092292.249.48.36192.168.2.15
    Dec 22, 2024 13:27:20.976584911 CET409225000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:20.977828026 CET409225000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:21.098421097 CET50004092292.249.48.36192.168.2.15
    Dec 22, 2024 13:27:21.098722935 CET409225000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:21.219413042 CET50004092292.249.48.36192.168.2.15
    Dec 22, 2024 13:27:22.217472076 CET50004092292.249.48.36192.168.2.15
    Dec 22, 2024 13:27:22.217849970 CET409225000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:22.219696045 CET409245000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:22.337969065 CET50004092292.249.48.36192.168.2.15
    Dec 22, 2024 13:27:22.339402914 CET50004092492.249.48.36192.168.2.15
    Dec 22, 2024 13:27:22.339708090 CET409245000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:22.341101885 CET409245000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:22.461076975 CET50004092492.249.48.36192.168.2.15
    Dec 22, 2024 13:27:22.461184978 CET409245000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:22.581675053 CET50004092492.249.48.36192.168.2.15
    Dec 22, 2024 13:27:23.587016106 CET50004092492.249.48.36192.168.2.15
    Dec 22, 2024 13:27:23.587240934 CET409245000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:23.587240934 CET409245000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:23.588485003 CET409265000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:23.707060099 CET50004092492.249.48.36192.168.2.15
    Dec 22, 2024 13:27:23.708547115 CET50004092692.249.48.36192.168.2.15
    Dec 22, 2024 13:27:23.708704948 CET409265000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:23.710302114 CET409265000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:23.829987049 CET50004092692.249.48.36192.168.2.15
    Dec 22, 2024 13:27:23.830332994 CET409265000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:23.950483084 CET50004092692.249.48.36192.168.2.15
    Dec 22, 2024 13:27:24.953653097 CET50004092692.249.48.36192.168.2.15
    Dec 22, 2024 13:27:24.953968048 CET409265000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:24.955435038 CET409285000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:25.074023008 CET50004092692.249.48.36192.168.2.15
    Dec 22, 2024 13:27:25.075052977 CET50004092892.249.48.36192.168.2.15
    Dec 22, 2024 13:27:25.075177908 CET409285000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:25.076283932 CET409285000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:25.195907116 CET50004092892.249.48.36192.168.2.15
    Dec 22, 2024 13:27:25.196384907 CET409285000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:25.315927029 CET50004092892.249.48.36192.168.2.15
    Dec 22, 2024 13:27:26.307892084 CET50004092892.249.48.36192.168.2.15
    Dec 22, 2024 13:27:26.308330059 CET409285000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:26.309497118 CET409305000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:26.428457022 CET50004092892.249.48.36192.168.2.15
    Dec 22, 2024 13:27:26.429322004 CET50004093092.249.48.36192.168.2.15
    Dec 22, 2024 13:27:26.429672003 CET409305000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:26.430944920 CET409305000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:26.550894976 CET50004093092.249.48.36192.168.2.15
    Dec 22, 2024 13:27:26.551137924 CET409305000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:26.671199083 CET50004093092.249.48.36192.168.2.15
    Dec 22, 2024 13:27:27.663914919 CET50004093092.249.48.36192.168.2.15
    Dec 22, 2024 13:27:27.664499998 CET409305000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:27.665683031 CET409325000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:27.784569979 CET50004093092.249.48.36192.168.2.15
    Dec 22, 2024 13:27:27.785896063 CET50004093292.249.48.36192.168.2.15
    Dec 22, 2024 13:27:27.786026955 CET409325000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:27.787363052 CET409325000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:27.907141924 CET50004093292.249.48.36192.168.2.15
    Dec 22, 2024 13:27:27.907250881 CET409325000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:28.027230978 CET50004093292.249.48.36192.168.2.15
    Dec 22, 2024 13:27:29.036838055 CET50004093292.249.48.36192.168.2.15
    Dec 22, 2024 13:27:29.037133932 CET409325000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:29.038352013 CET409345000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:29.156847954 CET50004093292.249.48.36192.168.2.15
    Dec 22, 2024 13:27:29.157984018 CET50004093492.249.48.36192.168.2.15
    Dec 22, 2024 13:27:29.158054113 CET409345000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:29.159269094 CET409345000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:29.279062033 CET50004093492.249.48.36192.168.2.15
    Dec 22, 2024 13:27:29.279134989 CET409345000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:29.398957968 CET50004093492.249.48.36192.168.2.15
    Dec 22, 2024 13:27:30.451235056 CET50004093492.249.48.36192.168.2.15
    Dec 22, 2024 13:27:30.451431990 CET409345000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:30.452300072 CET409365000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:30.571438074 CET50004093492.249.48.36192.168.2.15
    Dec 22, 2024 13:27:30.571943998 CET50004093692.249.48.36192.168.2.15
    Dec 22, 2024 13:27:30.572324991 CET409365000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:30.573194981 CET409365000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:30.693068981 CET50004093692.249.48.36192.168.2.15
    Dec 22, 2024 13:27:30.693324089 CET409365000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:30.813107014 CET50004093692.249.48.36192.168.2.15
    Dec 22, 2024 13:27:31.813307047 CET50004093692.249.48.36192.168.2.15
    Dec 22, 2024 13:27:31.813671112 CET409365000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:31.815099001 CET409385000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:31.933557034 CET50004093692.249.48.36192.168.2.15
    Dec 22, 2024 13:27:31.934971094 CET50004093892.249.48.36192.168.2.15
    Dec 22, 2024 13:27:31.935216904 CET409385000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:31.935818911 CET409385000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:32.056032896 CET50004093892.249.48.36192.168.2.15
    Dec 22, 2024 13:27:32.056332111 CET409385000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:32.176872969 CET50004093892.249.48.36192.168.2.15
    Dec 22, 2024 13:27:33.167958021 CET50004093892.249.48.36192.168.2.15
    Dec 22, 2024 13:27:33.168569088 CET409385000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:33.169040918 CET409405000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:33.289546967 CET50004093892.249.48.36192.168.2.15
    Dec 22, 2024 13:27:33.290997982 CET50004094092.249.48.36192.168.2.15
    Dec 22, 2024 13:27:33.291102886 CET409405000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:33.291781902 CET409405000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:33.411910057 CET50004094092.249.48.36192.168.2.15
    Dec 22, 2024 13:27:33.412075996 CET409405000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:33.532124043 CET50004094092.249.48.36192.168.2.15
    Dec 22, 2024 13:27:34.529864073 CET50004094092.249.48.36192.168.2.15
    Dec 22, 2024 13:27:34.530419111 CET409405000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:34.531354904 CET409425000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:34.650444031 CET50004094092.249.48.36192.168.2.15
    Dec 22, 2024 13:27:34.650928974 CET50004094292.249.48.36192.168.2.15
    Dec 22, 2024 13:27:34.651082039 CET409425000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:34.652079105 CET409425000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:34.771925926 CET50004094292.249.48.36192.168.2.15
    Dec 22, 2024 13:27:34.772219896 CET409425000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:34.892327070 CET50004094292.249.48.36192.168.2.15
    Dec 22, 2024 13:27:35.894828081 CET50004094292.249.48.36192.168.2.15
    Dec 22, 2024 13:27:35.895124912 CET409425000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:35.896023035 CET409445000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:36.015491962 CET50004094292.249.48.36192.168.2.15
    Dec 22, 2024 13:27:36.016330004 CET50004094492.249.48.36192.168.2.15
    Dec 22, 2024 13:27:36.016575098 CET409445000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:36.017239094 CET409445000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:36.136836052 CET50004094492.249.48.36192.168.2.15
    Dec 22, 2024 13:27:36.137273073 CET409445000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:36.258898973 CET50004094492.249.48.36192.168.2.15
    Dec 22, 2024 13:27:37.257229090 CET50004094492.249.48.36192.168.2.15
    Dec 22, 2024 13:27:37.257708073 CET409445000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:37.258450031 CET409465000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:37.377669096 CET50004094492.249.48.36192.168.2.15
    Dec 22, 2024 13:27:37.378262043 CET50004094692.249.48.36192.168.2.15
    Dec 22, 2024 13:27:37.378405094 CET409465000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:37.379465103 CET409465000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:37.499954939 CET50004094692.249.48.36192.168.2.15
    Dec 22, 2024 13:27:37.500101089 CET409465000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:37.620002031 CET50004094692.249.48.36192.168.2.15
    Dec 22, 2024 13:27:38.617803097 CET50004094692.249.48.36192.168.2.15
    Dec 22, 2024 13:27:38.618199110 CET409465000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:38.619247913 CET409485000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:38.739279985 CET50004094692.249.48.36192.168.2.15
    Dec 22, 2024 13:27:38.739358902 CET50004094892.249.48.36192.168.2.15
    Dec 22, 2024 13:27:38.739556074 CET409485000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:38.740437984 CET409485000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:38.860404968 CET50004094892.249.48.36192.168.2.15
    Dec 22, 2024 13:27:38.860647917 CET409485000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:38.980839014 CET50004094892.249.48.36192.168.2.15
    Dec 22, 2024 13:27:39.980087042 CET50004094892.249.48.36192.168.2.15
    Dec 22, 2024 13:27:39.980457067 CET409485000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:39.981492996 CET409505000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:40.100363970 CET50004094892.249.48.36192.168.2.15
    Dec 22, 2024 13:27:40.101077080 CET50004095092.249.48.36192.168.2.15
    Dec 22, 2024 13:27:40.101217985 CET409505000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:40.102097988 CET409505000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:40.221787930 CET50004095092.249.48.36192.168.2.15
    Dec 22, 2024 13:27:40.222070932 CET409505000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:40.342004061 CET50004095092.249.48.36192.168.2.15
    Dec 22, 2024 13:27:41.334002972 CET50004095092.249.48.36192.168.2.15
    Dec 22, 2024 13:27:41.334652901 CET409505000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:41.335587025 CET409525000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:41.454653978 CET50004095092.249.48.36192.168.2.15
    Dec 22, 2024 13:27:41.455822945 CET50004095292.249.48.36192.168.2.15
    Dec 22, 2024 13:27:41.456096888 CET409525000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:41.457020998 CET409525000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:41.576736927 CET50004095292.249.48.36192.168.2.15
    Dec 22, 2024 13:27:41.576858044 CET409525000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:41.697577000 CET50004095292.249.48.36192.168.2.15
    Dec 22, 2024 13:27:42.696050882 CET50004095292.249.48.36192.168.2.15
    Dec 22, 2024 13:27:42.696329117 CET409525000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:42.696960926 CET409545000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:42.816032887 CET50004095292.249.48.36192.168.2.15
    Dec 22, 2024 13:27:42.816549063 CET50004095492.249.48.36192.168.2.15
    Dec 22, 2024 13:27:42.816648960 CET409545000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:42.817584038 CET409545000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:42.937298059 CET50004095492.249.48.36192.168.2.15
    Dec 22, 2024 13:27:42.937711954 CET409545000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:43.059144020 CET50004095492.249.48.36192.168.2.15
    Dec 22, 2024 13:27:44.048675060 CET50004095492.249.48.36192.168.2.15
    Dec 22, 2024 13:27:44.048935890 CET409545000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:44.050055981 CET409565000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:44.168957949 CET50004095492.249.48.36192.168.2.15
    Dec 22, 2024 13:27:44.169965982 CET50004095692.249.48.36192.168.2.15
    Dec 22, 2024 13:27:44.170239925 CET409565000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:44.171025038 CET409565000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:44.290858030 CET50004095692.249.48.36192.168.2.15
    Dec 22, 2024 13:27:44.291093111 CET409565000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:44.411402941 CET50004095692.249.48.36192.168.2.15
    Dec 22, 2024 13:27:45.405656099 CET50004095692.249.48.36192.168.2.15
    Dec 22, 2024 13:27:45.406063080 CET409565000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:45.406979084 CET409585000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:45.525779963 CET50004095692.249.48.36192.168.2.15
    Dec 22, 2024 13:27:45.526618004 CET50004095892.249.48.36192.168.2.15
    Dec 22, 2024 13:27:45.526675940 CET409585000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:45.527483940 CET409585000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:45.647243023 CET50004095892.249.48.36192.168.2.15
    Dec 22, 2024 13:27:45.647425890 CET409585000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:45.775471926 CET50004095892.249.48.36192.168.2.15
    Dec 22, 2024 13:27:46.439065933 CET409585000192.168.2.1592.249.48.36
    Dec 22, 2024 13:27:46.559349060 CET50004095892.249.48.36192.168.2.15
    Dec 22, 2024 13:27:46.559551954 CET409585000192.168.2.1592.249.48.36
    TimestampSource PortDest PortSource IPDest IP
    Dec 22, 2024 13:29:45.436209917 CET3801453192.168.2.151.1.1.1
    Dec 22, 2024 13:29:45.436259985 CET6021053192.168.2.151.1.1.1
    Dec 22, 2024 13:29:45.573426962 CET53602101.1.1.1192.168.2.15
    Dec 22, 2024 13:29:45.573985100 CET53380141.1.1.1192.168.2.15
    Dec 22, 2024 13:29:52.237710953 CET5534153192.168.2.151.1.1.1
    Dec 22, 2024 13:29:52.375420094 CET53553411.1.1.1192.168.2.15
    Dec 22, 2024 13:30:02.248073101 CET3969453192.168.2.151.1.1.1
    Dec 22, 2024 13:30:02.387505054 CET53396941.1.1.1192.168.2.15
    Dec 22, 2024 13:30:12.291372061 CET4381253192.168.2.151.1.1.1
    Dec 22, 2024 13:30:12.428500891 CET53438121.1.1.1192.168.2.15
    Dec 22, 2024 13:30:22.278250933 CET4118053192.168.2.151.1.1.1
    Dec 22, 2024 13:30:22.416404009 CET53411801.1.1.1192.168.2.15
    Dec 22, 2024 13:30:32.415997982 CET6099953192.168.2.151.1.1.1
    Dec 22, 2024 13:30:32.553800106 CET53609991.1.1.1192.168.2.15
    Dec 22, 2024 13:30:42.444464922 CET4882753192.168.2.151.1.1.1
    Dec 22, 2024 13:30:42.444519043 CET5231353192.168.2.151.1.1.1
    Dec 22, 2024 13:30:42.584199905 CET53523131.1.1.1192.168.2.15
    Dec 22, 2024 13:30:42.753303051 CET53488271.1.1.1192.168.2.15
    Dec 22, 2024 13:30:52.449110031 CET5862253192.168.2.151.1.1.1
    Dec 22, 2024 13:30:52.586726904 CET53586221.1.1.1192.168.2.15
    Dec 22, 2024 13:31:02.550120115 CET3990353192.168.2.151.1.1.1
    Dec 22, 2024 13:31:02.687568903 CET53399031.1.1.1192.168.2.15
    Dec 22, 2024 13:31:12.465337992 CET5759453192.168.2.151.1.1.1
    Dec 22, 2024 13:31:12.602797985 CET53575941.1.1.1192.168.2.15
    TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
    Dec 22, 2024 13:29:45.436209917 CET192.168.2.151.1.1.10xc02aStandard query (0)daisy.ubuntu.comA (IP address)IN (0x0001)false
    Dec 22, 2024 13:29:45.436259985 CET192.168.2.151.1.1.10x1867Standard query (0)daisy.ubuntu.com28IN (0x0001)false
    Dec 22, 2024 13:29:52.237710953 CET192.168.2.151.1.1.10xff45Standard query (0)daisy.ubuntu.com28IN (0x0001)false
    Dec 22, 2024 13:30:02.248073101 CET192.168.2.151.1.1.10x7709Standard query (0)daisy.ubuntu.com28IN (0x0001)false
    Dec 22, 2024 13:30:12.291372061 CET192.168.2.151.1.1.10x2030Standard query (0)daisy.ubuntu.com28IN (0x0001)false
    Dec 22, 2024 13:30:22.278250933 CET192.168.2.151.1.1.10xc408Standard query (0)daisy.ubuntu.com28IN (0x0001)false
    Dec 22, 2024 13:30:32.415997982 CET192.168.2.151.1.1.10x5fdaStandard query (0)daisy.ubuntu.com28IN (0x0001)false
    Dec 22, 2024 13:30:42.444464922 CET192.168.2.151.1.1.10x9c5bStandard query (0)daisy.ubuntu.comA (IP address)IN (0x0001)false
    Dec 22, 2024 13:30:42.444519043 CET192.168.2.151.1.1.10xbd68Standard query (0)daisy.ubuntu.com28IN (0x0001)false
    Dec 22, 2024 13:30:52.449110031 CET192.168.2.151.1.1.10x6308Standard query (0)daisy.ubuntu.com28IN (0x0001)false
    Dec 22, 2024 13:31:02.550120115 CET192.168.2.151.1.1.10x6b2Standard query (0)daisy.ubuntu.com28IN (0x0001)false
    Dec 22, 2024 13:31:12.465337992 CET192.168.2.151.1.1.10xd2dbStandard query (0)daisy.ubuntu.com28IN (0x0001)false
    TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
    Dec 22, 2024 13:29:45.573985100 CET1.1.1.1192.168.2.150xc02aNo error (0)daisy.ubuntu.com162.213.35.24A (IP address)IN (0x0001)false
    Dec 22, 2024 13:29:45.573985100 CET1.1.1.1192.168.2.150xc02aNo error (0)daisy.ubuntu.com162.213.35.25A (IP address)IN (0x0001)false
    Dec 22, 2024 13:30:42.753303051 CET1.1.1.1192.168.2.150x9c5bNo error (0)daisy.ubuntu.com162.213.35.24A (IP address)IN (0x0001)false
    Dec 22, 2024 13:30:42.753303051 CET1.1.1.1192.168.2.150x9c5bNo error (0)daisy.ubuntu.com162.213.35.25A (IP address)IN (0x0001)false

    System Behavior

    Start time (UTC):12:27:00
    Start date (UTC):22/12/2024
    Path:/tmp/arm.elf
    Arguments:/tmp/arm.elf
    File size:4956856 bytes
    MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

    Start time (UTC):12:27:00
    Start date (UTC):22/12/2024
    Path:/tmp/arm.elf
    Arguments:-
    File size:4956856 bytes
    MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

    Start time (UTC):12:27:00
    Start date (UTC):22/12/2024
    Path:/bin/sh
    Arguments:sh -c "cp /tmp/arm.elf /usr/bin/bot"
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):12:27:00
    Start date (UTC):22/12/2024
    Path:/bin/sh
    Arguments:-
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):12:27:00
    Start date (UTC):22/12/2024
    Path:/usr/bin/cp
    Arguments:cp /tmp/arm.elf /usr/bin/bot
    File size:153976 bytes
    MD5 hash:40f10ae7ea3e44218d1a8c306f79c83f

    Start time (UTC):12:27:00
    Start date (UTC):22/12/2024
    Path:/tmp/arm.elf
    Arguments:-
    File size:4956856 bytes
    MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

    Start time (UTC):12:27:00
    Start date (UTC):22/12/2024
    Path:/usr/libexec/gnome-session-binary
    Arguments:-
    File size:334664 bytes
    MD5 hash:d9b90be4f7db60cb3c2d3da6a1d31bfb

    Start time (UTC):12:27:00
    Start date (UTC):22/12/2024
    Path:/bin/sh
    Arguments:/bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-housekeeping
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):12:27:00
    Start date (UTC):22/12/2024
    Path:/usr/libexec/gsd-housekeeping
    Arguments:/usr/libexec/gsd-housekeeping
    File size:51840 bytes
    MD5 hash:b55f3394a84976ddb92a2915e5d76914

    Start time (UTC):12:27:10
    Start date (UTC):22/12/2024
    Path:/usr/sbin/gdm3
    Arguments:-
    File size:453296 bytes
    MD5 hash:2492e2d8d34f9377e3e530a61a15674f

    Start time (UTC):12:27:10
    Start date (UTC):22/12/2024
    Path:/etc/gdm3/PrimeOff/Default
    Arguments:/etc/gdm3/PrimeOff/Default
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):12:27:10
    Start date (UTC):22/12/2024
    Path:/usr/sbin/gdm3
    Arguments:-
    File size:453296 bytes
    MD5 hash:2492e2d8d34f9377e3e530a61a15674f

    Start time (UTC):12:27:10
    Start date (UTC):22/12/2024
    Path:/etc/gdm3/PrimeOff/Default
    Arguments:/etc/gdm3/PrimeOff/Default
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):12:27:21
    Start date (UTC):22/12/2024
    Path:/usr/lib/systemd/systemd
    Arguments:-
    File size:1620224 bytes
    MD5 hash:9b2bec7092a40488108543f9334aab75

    Start time (UTC):12:27:21
    Start date (UTC):22/12/2024
    Path:/lib/systemd/systemd-user-runtime-dir
    Arguments:/lib/systemd/systemd-user-runtime-dir stop 127
    File size:22672 bytes
    MD5 hash:d55f4b0847f88131dbcfb07435178e54