Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
zerarm5.elf

Overview

General Information

Sample name:zerarm5.elf
Analysis ID:1580197
MD5:ac337219e9a43a565056d52291706eda
SHA1:e551b3116f04e5848559e3d0e441c8c655ebf924
SHA256:296999268ed5f4a3406552febfd889b8bd2acdf512ce0be9c756f32cef7843a1
Tags:elfuser-abuse_ch
Infos:

Detection

Score:56
Range:0 - 100
Whitelisted:false

Signatures

Multi AV Scanner detection for submitted file
Connects to many ports of the same IP (likely port scanning)
Sends malformed DNS queries
Detected TCP or UDP traffic on non-standard ports
Executes the "rm" command used to delete files or directories
Sample contains strings indicative of BusyBox which embeds multiple Unix commands in a single executable
Sample has stripped symbol table
Sample listens on a socket
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1580197
Start date and time:2024-12-24 04:09:40 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 26s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:zerarm5.elf
Detection:MAL
Classification:mal56.troj.linELF@0/0@11/0
Command:/tmp/zerarm5.elf
PID:5443
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
The Peoples Bank of China.
Standard Error:
  • system is lnxubuntu20
  • dash New Fork (PID: 5412, Parent: 3582)
  • rm (PID: 5412, Parent: 3582, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.FqQRvUdAvt /tmp/tmp.BpvDYSP9bx /tmp/tmp.uDbJAauplH
  • dash New Fork (PID: 5413, Parent: 3582)
  • rm (PID: 5413, Parent: 3582, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.FqQRvUdAvt /tmp/tmp.BpvDYSP9bx /tmp/tmp.uDbJAauplH
  • zerarm5.elf (PID: 5443, Parent: 5347, MD5: 5ebfcae4fe2471fcc5695c2394773ff1) Arguments: /tmp/zerarm5.elf
  • cleanup
No yara matches
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: zerarm5.elfReversingLabs: Detection: 44%
Source: zerarm5.elfVirustotal: Detection: 46%Perma Link

Networking

barindex
Source: global trafficTCP traffic: 154.216.16.244 ports 38241,1,2,3,4,8
Source: global trafficTCP traffic: 209.38.192.73 ports 38241,1,2,3,4,8
Source: global trafficDNS traffic detected: malformed DNS query: serisbot.geek. [malformed]
Source: global trafficTCP traffic: 192.168.2.13:48448 -> 209.38.192.73:38241
Source: global trafficTCP traffic: 192.168.2.13:44654 -> 154.216.16.244:38241
Source: /tmp/zerarm5.elf (PID: 5443)Socket: 127.0.0.1:39148Jump to behavior
Source: global trafficTCP traffic: 192.168.2.13:48202 -> 185.125.190.26:443
Source: unknownTCP traffic detected without corresponding DNS query: 185.125.190.26
Source: unknownTCP traffic detected without corresponding DNS query: 185.125.190.26
Source: unknownUDP traffic detected without corresponding DNS query: 51.158.108.203
Source: unknownUDP traffic detected without corresponding DNS query: 81.169.136.222
Source: unknownUDP traffic detected without corresponding DNS query: 81.169.136.222
Source: unknownUDP traffic detected without corresponding DNS query: 202.61.197.122
Source: unknownUDP traffic detected without corresponding DNS query: 168.235.111.72
Source: unknownUDP traffic detected without corresponding DNS query: 51.158.108.203
Source: unknownUDP traffic detected without corresponding DNS query: 168.235.111.72
Source: unknownUDP traffic detected without corresponding DNS query: 185.181.61.24
Source: unknownUDP traffic detected without corresponding DNS query: 168.235.111.72
Source: unknownUDP traffic detected without corresponding DNS query: 194.36.144.87
Source: unknownUDP traffic detected without corresponding DNS query: 51.158.108.203
Source: global trafficDNS traffic detected: DNS query: serisbot.geek
Source: global trafficDNS traffic detected: DNS query: serisontop.dyn
Source: global trafficDNS traffic detected: DNS query: serisbot.geek. [malformed]
Source: unknownNetwork traffic detected: HTTP traffic on port 48202 -> 443
Source: Initial sampleString containing 'busybox' found: /bin/busybox echo -ne
Source: Initial sampleString containing 'busybox' found: /bin/busybox echo -ne >> > .d
Source: ELF static info symbol of initial sample.symtab present: no
Source: classification engineClassification label: mal56.troj.linELF@0/0@11/0
Source: /usr/bin/dash (PID: 5412)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.FqQRvUdAvt /tmp/tmp.BpvDYSP9bx /tmp/tmp.uDbJAauplHJump to behavior
Source: /usr/bin/dash (PID: 5413)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.FqQRvUdAvt /tmp/tmp.BpvDYSP9bx /tmp/tmp.uDbJAauplHJump to behavior
Source: /tmp/zerarm5.elf (PID: 5443)Queries kernel information via 'uname': Jump to behavior
Source: zerarm5.elf, 5443.1.000055c1e39d2000.000055c1e3b00000.rw-.sdmpBinary or memory string: U!/etc/qemu-binfmt/arm
Source: zerarm5.elf, 5443.1.000055c1e39d2000.000055c1e3b00000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/arm
Source: zerarm5.elf, 5443.1.00007ffc2a382000.00007ffc2a3a3000.rw-.sdmpBinary or memory string: /usr/bin/qemu-arm
Source: zerarm5.elf, 5443.1.00007ffc2a382000.00007ffc2a3a3000.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-arm/tmp/zerarm5.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/zerarm5.elf
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception1
File Deletion
OS Credential Dumping11
Security Software Discovery
Remote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Non-Standard Port
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
Non-Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture2
Application Layer Protocol
Traffic DuplicationData Destruction
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
zerarm5.elf45%ReversingLabsLinux.Backdoor.Mirai
zerarm5.elf47%VirustotalBrowse
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
serisontop.dyn
209.38.192.73
truefalse
    high
    serisbot.geek
    209.38.192.73
    truefalse
      high
      serisbot.geek. [malformed]
      unknown
      unknownfalse
        high
        • No. of IPs < 25%
        • 25% < No. of IPs < 50%
        • 50% < No. of IPs < 75%
        • 75% < No. of IPs
        IPDomainCountryFlagASNASN NameMalicious
        154.216.16.244
        unknownSeychelles
        135357SKHT-ASShenzhenKatherineHengTechnologyInformationCotrue
        185.125.190.26
        unknownUnited Kingdom
        41231CANONICAL-ASGBfalse
        209.38.192.73
        serisontop.dynUnited States
        7018ATT-INTERNET4USfalse
        MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
        154.216.16.244nabx86.elfGet hashmaliciousUnknownBrowse
          nabsh4.elfGet hashmaliciousUnknownBrowse
            nabmpsl.elfGet hashmaliciousUnknownBrowse
              nabmips.elfGet hashmaliciousUnknownBrowse
                zerspc.elfGet hashmaliciousUnknownBrowse
                  zerarm.elfGet hashmaliciousUnknownBrowse
                    zerx86.elfGet hashmaliciousUnknownBrowse
                      185.125.190.26zermips.elfGet hashmaliciousUnknownBrowse
                        bot.arm.elfGet hashmaliciousMirai, Gafgyt, OkiruBrowse
                          sh4.nn.elfGet hashmaliciousOkiruBrowse
                            jackmymips64.elfGet hashmaliciousGafgyt, MiraiBrowse
                              arm5.nn.elfGet hashmaliciousOkiruBrowse
                                arm.nn-20241223-1416.elfGet hashmaliciousOkiruBrowse
                                  hidakibest.arm5.elfGet hashmaliciousGafgyt, MiraiBrowse
                                    vlxx.mpsl.elfGet hashmaliciousMirai, Gafgyt, OkiruBrowse
                                      la.bot.m68k.elfGet hashmaliciousMiraiBrowse
                                        nsharm6.elfGet hashmaliciousMiraiBrowse
                                          209.38.192.73zermips.elfGet hashmaliciousUnknownBrowse
                                            zersh4.elfGet hashmaliciousUnknownBrowse
                                              zerspc.elfGet hashmaliciousUnknownBrowse
                                                zerm68k.elfGet hashmaliciousUnknownBrowse
                                                  zermpsl.elfGet hashmaliciousUnknownBrowse
                                                    zerarm.elfGet hashmaliciousUnknownBrowse
                                                      zerx86.elfGet hashmaliciousUnknownBrowse
                                                        MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                        serisontop.dynnabx86.elfGet hashmaliciousUnknownBrowse
                                                        • 154.216.16.244
                                                        splmips.elfGet hashmaliciousUnknownBrowse
                                                        • 154.216.16.250
                                                        nabppc.elfGet hashmaliciousUnknownBrowse
                                                        • 209.38.192.73
                                                        nabsh4.elfGet hashmaliciousUnknownBrowse
                                                        • 154.216.16.244
                                                        zersh4.elfGet hashmaliciousUnknownBrowse
                                                        • 154.216.16.250
                                                        nklm68k.elfGet hashmaliciousUnknownBrowse
                                                        • 154.216.16.244
                                                        nabmpsl.elfGet hashmaliciousUnknownBrowse
                                                        • 154.216.16.250
                                                        splmpsl.elfGet hashmaliciousUnknownBrowse
                                                        • 209.38.192.73
                                                        nabmips.elfGet hashmaliciousUnknownBrowse
                                                        • 209.38.192.73
                                                        serisbot.geeksplmpsl.elfGet hashmaliciousUnknownBrowse
                                                        • 209.38.192.73
                                                        splppc.elfGet hashmaliciousUnknownBrowse
                                                        • 209.38.192.73
                                                        MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                        CANONICAL-ASGBzermips.elfGet hashmaliciousUnknownBrowse
                                                        • 185.125.190.26
                                                        zerm68k.elfGet hashmaliciousUnknownBrowse
                                                        • 91.189.91.42
                                                        zerarm6.elfGet hashmaliciousUnknownBrowse
                                                        • 91.189.91.42
                                                        armv4eb.elfGet hashmaliciousUnknownBrowse
                                                        • 91.189.91.42
                                                        x86_32.nn.elfGet hashmaliciousOkiruBrowse
                                                        • 91.189.91.42
                                                        tftp.elfGet hashmaliciousUnknownBrowse
                                                        • 91.189.91.42
                                                        arm5.nn-20241224-0050.elfGet hashmaliciousOkiruBrowse
                                                        • 91.189.91.42
                                                        bot.sh4.elfGet hashmaliciousMirai, Gafgyt, OkiruBrowse
                                                        • 91.189.91.42
                                                        mipsel.nn.elfGet hashmaliciousOkiruBrowse
                                                        • 91.189.91.42
                                                        powerpc.nn.elfGet hashmaliciousOkiruBrowse
                                                        • 91.189.91.42
                                                        ATT-INTERNET4USsplarm5.elfGet hashmaliciousUnknownBrowse
                                                        • 104.50.152.60
                                                        splsh4.elfGet hashmaliciousUnknownBrowse
                                                        • 12.167.12.161
                                                        nabx86.elfGet hashmaliciousUnknownBrowse
                                                        • 68.76.208.129
                                                        splmips.elfGet hashmaliciousUnknownBrowse
                                                        • 32.49.33.160
                                                        zermips.elfGet hashmaliciousUnknownBrowse
                                                        • 209.38.192.73
                                                        nabppc.elfGet hashmaliciousUnknownBrowse
                                                        • 70.137.219.150
                                                        nabsh4.elfGet hashmaliciousUnknownBrowse
                                                        • 162.207.61.13
                                                        zersh4.elfGet hashmaliciousUnknownBrowse
                                                        • 209.38.192.73
                                                        nklm68k.elfGet hashmaliciousUnknownBrowse
                                                        • 70.254.163.117
                                                        nabmpsl.elfGet hashmaliciousUnknownBrowse
                                                        • 12.178.23.37
                                                        SKHT-ASShenzhenKatherineHengTechnologyInformationConabx86.elfGet hashmaliciousUnknownBrowse
                                                        • 154.216.16.244
                                                        nabsh4.elfGet hashmaliciousUnknownBrowse
                                                        • 154.216.16.244
                                                        nabmpsl.elfGet hashmaliciousUnknownBrowse
                                                        • 154.216.16.244
                                                        nabmips.elfGet hashmaliciousUnknownBrowse
                                                        • 154.216.16.244
                                                        arm.elfGet hashmaliciousUnknownBrowse
                                                        • 45.207.239.67
                                                        zerspc.elfGet hashmaliciousUnknownBrowse
                                                        • 154.216.16.250
                                                        zermpsl.elfGet hashmaliciousUnknownBrowse
                                                        • 154.216.16.250
                                                        zerarm.elfGet hashmaliciousUnknownBrowse
                                                        • 154.216.16.250
                                                        zerx86.elfGet hashmaliciousUnknownBrowse
                                                        • 154.216.16.250
                                                        x86_32.nn.elfGet hashmaliciousOkiruBrowse
                                                        • 154.216.19.139
                                                        No context
                                                        No context
                                                        No created / dropped files found
                                                        File type:ELF 32-bit LSB executable, ARM, version 1 (ARM), statically linked, stripped
                                                        Entropy (8bit):5.954315775946027
                                                        TrID:
                                                        • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                                                        File name:zerarm5.elf
                                                        File size:47'736 bytes
                                                        MD5:ac337219e9a43a565056d52291706eda
                                                        SHA1:e551b3116f04e5848559e3d0e441c8c655ebf924
                                                        SHA256:296999268ed5f4a3406552febfd889b8bd2acdf512ce0be9c756f32cef7843a1
                                                        SHA512:790a2eec6c466024407023d418c7d1ccfb3860a62c582bc969b80f628e46d1ec7e33bdd7bf0d0021d53b1574c89c43836afc7550ca0a744afc997c4d5bdfeb75
                                                        SSDEEP:768:NBu0TFCEfCkPTQSlghpsvW692N8jaabj0GkozlFozCRxyNqRW+ql1iTs:f5FZfFcps+69G8Z/0urxMkT
                                                        TLSH:A3230741BC819A13C5D413BEF66E429D372523B8E2EFB217DC222F15778A82B0DB7645
                                                        File Content Preview:.ELF...a..........(.........4...........4. ...(.....................................................................Q.td..................................-...L."....+..........0@-.\P...0....S.0...P@...0... ....R......0...0...........0... ....R..... 0....S

                                                        ELF header

                                                        Class:ELF32
                                                        Data:2's complement, little endian
                                                        Version:1 (current)
                                                        Machine:ARM
                                                        Version Number:0x1
                                                        Type:EXEC (Executable file)
                                                        OS/ABI:ARM - ABI
                                                        ABI Version:0
                                                        Entry Point Address:0x8190
                                                        Flags:0x2
                                                        ELF Header Size:52
                                                        Program Header Offset:52
                                                        Program Header Size:32
                                                        Number of Program Headers:3
                                                        Section Header Offset:47296
                                                        Section Header Size:40
                                                        Number of Section Headers:11
                                                        Header String Table Index:10
                                                        NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                                        NULL0x00x00x00x00x0000
                                                        .initPROGBITS0x80940x940x180x00x6AX004
                                                        .textPROGBITS0x80b00xb00xae900x00x6AX0016
                                                        .finiPROGBITS0x12f400xaf400x140x00x6AX004
                                                        .rodataPROGBITS0x12f540xaf540x7a40x00x2A004
                                                        .ctorsPROGBITS0x1b6fc0xb6fc0x80x00x3WA004
                                                        .dtorsPROGBITS0x1b7040xb7040x80x00x3WA004
                                                        .jcrPROGBITS0x1b70c0xb70c0x40x00x3WA004
                                                        .dataPROGBITS0x1b7100xb7100x16c0x00x3WA004
                                                        .bssNOBITS0x1b87c0xb87c0x1780x00x3WA004
                                                        .shstrtabSTRTAB0x00xb87c0x430x00x0001
                                                        TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                        LOAD0x00x80000x80000xb6f80xb6f85.99280x5R E0x8000.init .text .fini .rodata
                                                        LOAD0xb6fc0x1b6fc0x1b6fc0x1800x2f80.84270x6RW 0x8000.ctors .dtors .jcr .data .bss
                                                        GNU_STACK0x00x00x00x00x00.00000x7RWE0x4
                                                        TimestampSource PortDest PortSource IPDest IP
                                                        Dec 24, 2024 04:10:19.399625063 CET4844838241192.168.2.13209.38.192.73
                                                        Dec 24, 2024 04:10:19.519130945 CET3824148448209.38.192.73192.168.2.13
                                                        Dec 24, 2024 04:10:19.519220114 CET4844838241192.168.2.13209.38.192.73
                                                        Dec 24, 2024 04:10:19.520355940 CET4844838241192.168.2.13209.38.192.73
                                                        Dec 24, 2024 04:10:19.639826059 CET3824148448209.38.192.73192.168.2.13
                                                        Dec 24, 2024 04:10:19.639945984 CET4844838241192.168.2.13209.38.192.73
                                                        Dec 24, 2024 04:10:19.759433985 CET3824148448209.38.192.73192.168.2.13
                                                        Dec 24, 2024 04:10:29.528861046 CET4844838241192.168.2.13209.38.192.73
                                                        Dec 24, 2024 04:10:29.648333073 CET3824148448209.38.192.73192.168.2.13
                                                        Dec 24, 2024 04:10:29.950885057 CET3824148448209.38.192.73192.168.2.13
                                                        Dec 24, 2024 04:10:29.951231003 CET4844838241192.168.2.13209.38.192.73
                                                        Dec 24, 2024 04:10:30.070842981 CET3824148448209.38.192.73192.168.2.13
                                                        Dec 24, 2024 04:10:30.718027115 CET48202443192.168.2.13185.125.190.26
                                                        Dec 24, 2024 04:10:31.193133116 CET4845038241192.168.2.13209.38.192.73
                                                        Dec 24, 2024 04:10:31.312606096 CET3824148450209.38.192.73192.168.2.13
                                                        Dec 24, 2024 04:10:31.312738895 CET4845038241192.168.2.13209.38.192.73
                                                        Dec 24, 2024 04:10:31.314148903 CET4845038241192.168.2.13209.38.192.73
                                                        Dec 24, 2024 04:10:31.433599949 CET3824148450209.38.192.73192.168.2.13
                                                        Dec 24, 2024 04:10:31.433815956 CET4845038241192.168.2.13209.38.192.73
                                                        Dec 24, 2024 04:10:31.553329945 CET3824148450209.38.192.73192.168.2.13
                                                        Dec 24, 2024 04:10:42.425910950 CET3824148450209.38.192.73192.168.2.13
                                                        Dec 24, 2024 04:10:42.426337957 CET4845038241192.168.2.13209.38.192.73
                                                        Dec 24, 2024 04:10:42.545969963 CET3824148450209.38.192.73192.168.2.13
                                                        Dec 24, 2024 04:10:43.669998884 CET4845238241192.168.2.13209.38.192.73
                                                        Dec 24, 2024 04:10:43.789638042 CET3824148452209.38.192.73192.168.2.13
                                                        Dec 24, 2024 04:10:43.789835930 CET4845238241192.168.2.13209.38.192.73
                                                        Dec 24, 2024 04:10:43.791383982 CET4845238241192.168.2.13209.38.192.73
                                                        Dec 24, 2024 04:10:43.910983086 CET3824148452209.38.192.73192.168.2.13
                                                        Dec 24, 2024 04:10:43.911166906 CET4845238241192.168.2.13209.38.192.73
                                                        Dec 24, 2024 04:10:44.030662060 CET3824148452209.38.192.73192.168.2.13
                                                        Dec 24, 2024 04:10:54.902745008 CET3824148452209.38.192.73192.168.2.13
                                                        Dec 24, 2024 04:10:54.903114080 CET4845238241192.168.2.13209.38.192.73
                                                        Dec 24, 2024 04:10:55.022664070 CET3824148452209.38.192.73192.168.2.13
                                                        Dec 24, 2024 04:10:56.155603886 CET4465438241192.168.2.13154.216.16.244
                                                        Dec 24, 2024 04:10:56.275058985 CET3824144654154.216.16.244192.168.2.13
                                                        Dec 24, 2024 04:10:56.275186062 CET4465438241192.168.2.13154.216.16.244
                                                        Dec 24, 2024 04:10:56.276900053 CET4465438241192.168.2.13154.216.16.244
                                                        Dec 24, 2024 04:10:56.396388054 CET3824144654154.216.16.244192.168.2.13
                                                        Dec 24, 2024 04:10:56.396526098 CET4465438241192.168.2.13154.216.16.244
                                                        Dec 24, 2024 04:10:56.516036987 CET3824144654154.216.16.244192.168.2.13
                                                        Dec 24, 2024 04:11:02.206008911 CET48202443192.168.2.13185.125.190.26
                                                        Dec 24, 2024 04:11:07.383824110 CET3824144654154.216.16.244192.168.2.13
                                                        Dec 24, 2024 04:11:07.383960962 CET4465438241192.168.2.13154.216.16.244
                                                        Dec 24, 2024 04:11:07.503545046 CET3824144654154.216.16.244192.168.2.13
                                                        Dec 24, 2024 04:11:08.706823111 CET4465638241192.168.2.13154.216.16.244
                                                        Dec 24, 2024 04:11:08.826514006 CET3824144656154.216.16.244192.168.2.13
                                                        Dec 24, 2024 04:11:08.826622009 CET4465638241192.168.2.13154.216.16.244
                                                        Dec 24, 2024 04:11:08.828180075 CET4465638241192.168.2.13154.216.16.244
                                                        Dec 24, 2024 04:11:08.947684050 CET3824144656154.216.16.244192.168.2.13
                                                        Dec 24, 2024 04:11:08.947971106 CET4465638241192.168.2.13154.216.16.244
                                                        Dec 24, 2024 04:11:09.067578077 CET3824144656154.216.16.244192.168.2.13
                                                        Dec 24, 2024 04:11:19.936494112 CET3824144656154.216.16.244192.168.2.13
                                                        Dec 24, 2024 04:11:19.936778069 CET4465638241192.168.2.13154.216.16.244
                                                        Dec 24, 2024 04:11:20.056334019 CET3824144656154.216.16.244192.168.2.13
                                                        Dec 24, 2024 04:11:21.181216002 CET4465838241192.168.2.13154.216.16.244
                                                        Dec 24, 2024 04:11:21.410368919 CET3824144658154.216.16.244192.168.2.13
                                                        Dec 24, 2024 04:11:21.410722971 CET4465838241192.168.2.13154.216.16.244
                                                        Dec 24, 2024 04:11:21.412506104 CET4465838241192.168.2.13154.216.16.244
                                                        Dec 24, 2024 04:11:21.646828890 CET3824144658154.216.16.244192.168.2.13
                                                        Dec 24, 2024 04:11:21.647161961 CET4465838241192.168.2.13154.216.16.244
                                                        Dec 24, 2024 04:11:21.766633034 CET3824144658154.216.16.244192.168.2.13
                                                        Dec 24, 2024 04:11:32.703114986 CET3824144658154.216.16.244192.168.2.13
                                                        Dec 24, 2024 04:11:32.703509092 CET4465838241192.168.2.13154.216.16.244
                                                        Dec 24, 2024 04:11:32.823041916 CET3824144658154.216.16.244192.168.2.13
                                                        Dec 24, 2024 04:11:34.022164106 CET4466038241192.168.2.13154.216.16.244
                                                        Dec 24, 2024 04:11:34.141663074 CET3824144660154.216.16.244192.168.2.13
                                                        Dec 24, 2024 04:11:34.141762018 CET4466038241192.168.2.13154.216.16.244
                                                        Dec 24, 2024 04:11:34.143435955 CET4466038241192.168.2.13154.216.16.244
                                                        Dec 24, 2024 04:11:34.262835026 CET3824144660154.216.16.244192.168.2.13
                                                        Dec 24, 2024 04:11:34.262953997 CET4466038241192.168.2.13154.216.16.244
                                                        Dec 24, 2024 04:11:34.427306890 CET3824144660154.216.16.244192.168.2.13
                                                        Dec 24, 2024 04:11:44.145045042 CET4466038241192.168.2.13154.216.16.244
                                                        Dec 24, 2024 04:11:44.264484882 CET3824144660154.216.16.244192.168.2.13
                                                        Dec 24, 2024 04:11:44.566169024 CET3824144660154.216.16.244192.168.2.13
                                                        Dec 24, 2024 04:11:44.566312075 CET4466038241192.168.2.13154.216.16.244
                                                        Dec 24, 2024 04:11:44.685754061 CET3824144660154.216.16.244192.168.2.13
                                                        Dec 24, 2024 04:11:45.826572895 CET4466238241192.168.2.13154.216.16.244
                                                        Dec 24, 2024 04:11:45.946516991 CET3824144662154.216.16.244192.168.2.13
                                                        Dec 24, 2024 04:11:45.946671963 CET4466238241192.168.2.13154.216.16.244
                                                        Dec 24, 2024 04:11:45.948409081 CET4466238241192.168.2.13154.216.16.244
                                                        Dec 24, 2024 04:11:46.067828894 CET3824144662154.216.16.244192.168.2.13
                                                        Dec 24, 2024 04:11:46.067955971 CET4466238241192.168.2.13154.216.16.244
                                                        Dec 24, 2024 04:11:46.189475060 CET3824144662154.216.16.244192.168.2.13
                                                        Dec 24, 2024 04:11:57.051892996 CET3824144662154.216.16.244192.168.2.13
                                                        Dec 24, 2024 04:11:57.052243948 CET4466238241192.168.2.13154.216.16.244
                                                        Dec 24, 2024 04:11:57.171713114 CET3824144662154.216.16.244192.168.2.13
                                                        Dec 24, 2024 04:11:58.364291906 CET4466438241192.168.2.13154.216.16.244
                                                        Dec 24, 2024 04:11:58.483728886 CET3824144664154.216.16.244192.168.2.13
                                                        Dec 24, 2024 04:11:58.483983040 CET4466438241192.168.2.13154.216.16.244
                                                        Dec 24, 2024 04:11:58.485707998 CET4466438241192.168.2.13154.216.16.244
                                                        Dec 24, 2024 04:11:58.605149031 CET3824144664154.216.16.244192.168.2.13
                                                        Dec 24, 2024 04:11:58.605220079 CET4466438241192.168.2.13154.216.16.244
                                                        Dec 24, 2024 04:11:58.724725008 CET3824144664154.216.16.244192.168.2.13
                                                        Dec 24, 2024 04:12:09.591270924 CET3824144664154.216.16.244192.168.2.13
                                                        Dec 24, 2024 04:12:09.591408968 CET4466438241192.168.2.13154.216.16.244
                                                        Dec 24, 2024 04:12:09.710922956 CET3824144664154.216.16.244192.168.2.13
                                                        Dec 24, 2024 04:12:10.837810993 CET4466638241192.168.2.13154.216.16.244
                                                        Dec 24, 2024 04:12:10.957366943 CET3824144666154.216.16.244192.168.2.13
                                                        Dec 24, 2024 04:12:10.957458019 CET4466638241192.168.2.13154.216.16.244
                                                        Dec 24, 2024 04:12:10.958700895 CET4466638241192.168.2.13154.216.16.244
                                                        Dec 24, 2024 04:12:11.078211069 CET3824144666154.216.16.244192.168.2.13
                                                        Dec 24, 2024 04:12:11.078279018 CET4466638241192.168.2.13154.216.16.244
                                                        Dec 24, 2024 04:12:11.197820902 CET3824144666154.216.16.244192.168.2.13
                                                        Dec 24, 2024 04:12:22.064682007 CET3824144666154.216.16.244192.168.2.13
                                                        Dec 24, 2024 04:12:22.064919949 CET4466638241192.168.2.13154.216.16.244
                                                        Dec 24, 2024 04:12:22.184638977 CET3824144666154.216.16.244192.168.2.13
                                                        Dec 24, 2024 04:12:23.307070971 CET4466838241192.168.2.13154.216.16.244
                                                        TimestampSource PortDest PortSource IPDest IP
                                                        Dec 24, 2024 04:10:19.159781933 CET3541753192.168.2.1351.158.108.203
                                                        Dec 24, 2024 04:10:19.398626089 CET533541751.158.108.203192.168.2.13
                                                        Dec 24, 2024 04:10:30.954899073 CET3906553192.168.2.1381.169.136.222
                                                        Dec 24, 2024 04:10:31.192255020 CET533906581.169.136.222192.168.2.13
                                                        Dec 24, 2024 04:10:43.429497957 CET4252553192.168.2.1381.169.136.222
                                                        Dec 24, 2024 04:10:43.669300079 CET534252581.169.136.222192.168.2.13
                                                        Dec 24, 2024 04:10:55.907196045 CET5114353192.168.2.13202.61.197.122
                                                        Dec 24, 2024 04:10:56.154481888 CET5351143202.61.197.122192.168.2.13
                                                        Dec 24, 2024 04:11:08.386436939 CET4289053192.168.2.13168.235.111.72
                                                        Dec 24, 2024 04:11:08.705656052 CET5342890168.235.111.72192.168.2.13
                                                        Dec 24, 2024 04:11:20.941044092 CET4978953192.168.2.1351.158.108.203
                                                        Dec 24, 2024 04:11:21.179781914 CET534978951.158.108.203192.168.2.13
                                                        Dec 24, 2024 04:11:33.706809998 CET5235053192.168.2.13168.235.111.72
                                                        Dec 24, 2024 04:11:34.021044970 CET5352350168.235.111.72192.168.2.13
                                                        Dec 24, 2024 04:11:45.569688082 CET4591653192.168.2.13185.181.61.24
                                                        Dec 24, 2024 04:11:45.825277090 CET5345916185.181.61.24192.168.2.13
                                                        Dec 24, 2024 04:11:58.055666924 CET4798853192.168.2.13168.235.111.72
                                                        Dec 24, 2024 04:11:58.363323927 CET5347988168.235.111.72192.168.2.13
                                                        Dec 24, 2024 04:12:10.594264984 CET5565153192.168.2.13194.36.144.87
                                                        Dec 24, 2024 04:12:10.836684942 CET5355651194.36.144.87192.168.2.13
                                                        Dec 24, 2024 04:12:23.067543030 CET4410653192.168.2.1351.158.108.203
                                                        Dec 24, 2024 04:12:23.306457043 CET534410651.158.108.203192.168.2.13
                                                        TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                                        Dec 24, 2024 04:10:19.159781933 CET192.168.2.1351.158.108.2030x7d27Standard query (0)serisbot.geekA (IP address)IN (0x0001)false
                                                        Dec 24, 2024 04:10:30.954899073 CET192.168.2.1381.169.136.2220x2922Standard query (0)serisbot.geekA (IP address)IN (0x0001)false
                                                        Dec 24, 2024 04:10:43.429497957 CET192.168.2.1381.169.136.2220xfe78Standard query (0)serisontop.dynA (IP address)IN (0x0001)false
                                                        Dec 24, 2024 04:10:55.907196045 CET192.168.2.13202.61.197.1220xd1a5Standard query (0)serisontop.dynA (IP address)IN (0x0001)false
                                                        Dec 24, 2024 04:11:08.386436939 CET192.168.2.13168.235.111.720xf7ecStandard query (0)serisontop.dynA (IP address)IN (0x0001)false
                                                        Dec 24, 2024 04:11:20.941044092 CET192.168.2.1351.158.108.2030xfc4aStandard query (0)serisontop.dynA (IP address)IN (0x0001)false
                                                        Dec 24, 2024 04:11:33.706809998 CET192.168.2.13168.235.111.720xf481Standard query (0)serisbot.geek. [malformed]256358false
                                                        Dec 24, 2024 04:11:45.569688082 CET192.168.2.13185.181.61.240x6b29Standard query (0)serisontop.dynA (IP address)IN (0x0001)false
                                                        Dec 24, 2024 04:11:58.055666924 CET192.168.2.13168.235.111.720xae29Standard query (0)serisbot.geek. [malformed]256382false
                                                        Dec 24, 2024 04:12:10.594264984 CET192.168.2.13194.36.144.870xf8b5Standard query (0)serisbot.geek. [malformed]256394false
                                                        Dec 24, 2024 04:12:23.067543030 CET192.168.2.1351.158.108.2030x99aStandard query (0)serisbot.geek. [malformed]256407false
                                                        TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                                        Dec 24, 2024 04:10:19.398626089 CET51.158.108.203192.168.2.130x7d27No error (0)serisbot.geek209.38.192.73A (IP address)IN (0x0001)false
                                                        Dec 24, 2024 04:10:31.192255020 CET81.169.136.222192.168.2.130x2922Refused (5)serisbot.geeknonenoneA (IP address)IN (0x0001)false
                                                        Dec 24, 2024 04:10:43.669300079 CET81.169.136.222192.168.2.130xfe78Refused (5)serisontop.dynnonenoneA (IP address)IN (0x0001)false
                                                        Dec 24, 2024 04:10:56.154481888 CET202.61.197.122192.168.2.130xd1a5No error (0)serisontop.dyn209.38.192.73A (IP address)IN (0x0001)false
                                                        Dec 24, 2024 04:10:56.154481888 CET202.61.197.122192.168.2.130xd1a5No error (0)serisontop.dyn154.216.16.250A (IP address)IN (0x0001)false
                                                        Dec 24, 2024 04:10:56.154481888 CET202.61.197.122192.168.2.130xd1a5No error (0)serisontop.dyn154.216.16.244A (IP address)IN (0x0001)false
                                                        Dec 24, 2024 04:11:08.705656052 CET168.235.111.72192.168.2.130xf7ecNo error (0)serisontop.dyn209.38.192.73A (IP address)IN (0x0001)false
                                                        Dec 24, 2024 04:11:08.705656052 CET168.235.111.72192.168.2.130xf7ecNo error (0)serisontop.dyn154.216.16.244A (IP address)IN (0x0001)false
                                                        Dec 24, 2024 04:11:08.705656052 CET168.235.111.72192.168.2.130xf7ecNo error (0)serisontop.dyn154.216.16.250A (IP address)IN (0x0001)false
                                                        Dec 24, 2024 04:11:21.179781914 CET51.158.108.203192.168.2.130xfc4aNo error (0)serisontop.dyn154.216.16.250A (IP address)IN (0x0001)false
                                                        Dec 24, 2024 04:11:21.179781914 CET51.158.108.203192.168.2.130xfc4aNo error (0)serisontop.dyn154.216.16.244A (IP address)IN (0x0001)false
                                                        Dec 24, 2024 04:11:21.179781914 CET51.158.108.203192.168.2.130xfc4aNo error (0)serisontop.dyn209.38.192.73A (IP address)IN (0x0001)false
                                                        Dec 24, 2024 04:11:45.825277090 CET185.181.61.24192.168.2.130x6b29No error (0)serisontop.dyn154.216.16.250A (IP address)IN (0x0001)false
                                                        Dec 24, 2024 04:11:45.825277090 CET185.181.61.24192.168.2.130x6b29No error (0)serisontop.dyn154.216.16.244A (IP address)IN (0x0001)false
                                                        Dec 24, 2024 04:11:45.825277090 CET185.181.61.24192.168.2.130x6b29No error (0)serisontop.dyn209.38.192.73A (IP address)IN (0x0001)false
                                                        Dec 24, 2024 04:12:10.836684942 CET194.36.144.87192.168.2.130xf8b5Format error (1)serisbot.geek. [malformed]nonenone256394false
                                                        Dec 24, 2024 04:12:23.306457043 CET51.158.108.203192.168.2.130x99aFormat error (1)serisbot.geek. [malformed]nonenone256407false

                                                        System Behavior

                                                        Start time (UTC):03:10:13
                                                        Start date (UTC):24/12/2024
                                                        Path:/usr/bin/dash
                                                        Arguments:-
                                                        File size:129816 bytes
                                                        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                        Start time (UTC):03:10:13
                                                        Start date (UTC):24/12/2024
                                                        Path:/usr/bin/rm
                                                        Arguments:rm -f /tmp/tmp.FqQRvUdAvt /tmp/tmp.BpvDYSP9bx /tmp/tmp.uDbJAauplH
                                                        File size:72056 bytes
                                                        MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b

                                                        Start time (UTC):03:10:13
                                                        Start date (UTC):24/12/2024
                                                        Path:/usr/bin/dash
                                                        Arguments:-
                                                        File size:129816 bytes
                                                        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                        Start time (UTC):03:10:13
                                                        Start date (UTC):24/12/2024
                                                        Path:/usr/bin/rm
                                                        Arguments:rm -f /tmp/tmp.FqQRvUdAvt /tmp/tmp.BpvDYSP9bx /tmp/tmp.uDbJAauplH
                                                        File size:72056 bytes
                                                        MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b

                                                        Start time (UTC):03:10:17
                                                        Start date (UTC):24/12/2024
                                                        Path:/tmp/zerarm5.elf
                                                        Arguments:/tmp/zerarm5.elf
                                                        File size:4956856 bytes
                                                        MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                        Start time (UTC):03:10:17
                                                        Start date (UTC):24/12/2024
                                                        Path:/tmp/zerarm5.elf
                                                        Arguments:-
                                                        File size:4956856 bytes
                                                        MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                        Start time (UTC):03:10:17
                                                        Start date (UTC):24/12/2024
                                                        Path:/tmp/zerarm5.elf
                                                        Arguments:-
                                                        File size:4956856 bytes
                                                        MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1