Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
zmap.ppc.elf

Overview

General Information

Sample name:zmap.ppc.elf
Analysis ID:1580406
MD5:45225829413203a55f6a1294380b04e8
SHA1:33215ac191a20b7efa09ef7de2ace7aa5688ec4d
SHA256:8d0d65c5d87bcc3fd8a088b4d05afc56046c5c2ca9efca8dd3eadfe644cf62c2
Tags:elfuser-abuse_ch
Infos:

Detection

Mirai, Okiru
Score:84
Range:0 - 100
Whitelisted:false

Signatures

Antivirus / Scanner detection for submitted sample
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Yara detected Mirai
Yara detected Okiru
Sample deletes itself
Detected TCP or UDP traffic on non-standard ports
Sample has stripped symbol table
Sample listens on a socket
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Uses the "uname" system call to query kernel version information (possible evasion)
Yara signature match

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1580406
Start date and time:2024-12-24 13:32:08 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 34s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:zmap.ppc.elf
Detection:MAL
Classification:mal84.troj.evad.linELF@0/0@10/0
  • VT rate limit hit for: zmap.ppc.elf
Command:/tmp/zmap.ppc.elf
PID:6217
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
VagneRHere
Standard Error:
  • system is lnxubuntu20
  • zmap.ppc.elf (PID: 6217, Parent: 6139, MD5: ae65271c943d3451b7f026d1fadccea6) Arguments: /tmp/zmap.ppc.elf
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
MiraiMirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese. Nowadays it targets a wide range of networked embedded devices such as IP cameras, home routers (many vendors involved), and other IoT devices. Since the source code was published on "Hack Forums" many variants of the Mirai family appeared, infecting mostly home networks all around the world.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/elf.mirai
SourceRuleDescriptionAuthorStrings
zmap.ppc.elfJoeSecurity_OkiruYara detected OkiruJoe Security
    zmap.ppc.elfJoeSecurity_Mirai_8Yara detected MiraiJoe Security
      zmap.ppc.elfLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
      • 0xeca4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xecb8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xeccc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xece0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xecf4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xed08:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xed1c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xed30:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xed44:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xed58:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xed6c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xed80:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xed94:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xeda8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xedbc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xedd0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xede4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xedf8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xee0c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xee20:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xee34:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      SourceRuleDescriptionAuthorStrings
      6222.1.00007f50b4001000.00007f50b4012000.r-x.sdmpJoeSecurity_OkiruYara detected OkiruJoe Security
        6222.1.00007f50b4001000.00007f50b4012000.r-x.sdmpJoeSecurity_Mirai_8Yara detected MiraiJoe Security
          6222.1.00007f50b4001000.00007f50b4012000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
          • 0xeca4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xecb8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xeccc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xece0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xecf4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xed08:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xed1c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xed30:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xed44:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xed58:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xed6c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xed80:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xed94:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xeda8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xedbc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xedd0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xede4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xedf8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xee0c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xee20:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xee34:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          6217.1.00007f50b4001000.00007f50b4012000.r-x.sdmpJoeSecurity_OkiruYara detected OkiruJoe Security
            6217.1.00007f50b4001000.00007f50b4012000.r-x.sdmpJoeSecurity_Mirai_8Yara detected MiraiJoe Security
              Click to see the 7 entries
              No Suricata rule has matched

              Click to jump to signature section

              Show All Signature Results

              AV Detection

              barindex
              Source: zmap.ppc.elfAvira: detected
              Source: zmap.ppc.elfReversingLabs: Detection: 60%
              Source: global trafficTCP traffic: 192.168.2.23:39528 -> 185.196.8.105:59962
              Source: /tmp/zmap.ppc.elf (PID: 6217)Socket: 127.0.0.1:39148Jump to behavior
              Source: global trafficTCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
              Source: global trafficTCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
              Source: global trafficTCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
              Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
              Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
              Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
              Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
              Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
              Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
              Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
              Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
              Source: global trafficDNS traffic detected: DNS query: srvy.vlrt-gap.com
              Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443

              System Summary

              barindex
              Source: zmap.ppc.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
              Source: 6222.1.00007f50b4001000.00007f50b4012000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
              Source: 6217.1.00007f50b4001000.00007f50b4012000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
              Source: Process Memory Space: zmap.ppc.elf PID: 6217, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
              Source: Process Memory Space: zmap.ppc.elf PID: 6222, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
              Source: ELF static info symbol of initial sample.symtab present: no
              Source: zmap.ppc.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
              Source: 6222.1.00007f50b4001000.00007f50b4012000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
              Source: 6217.1.00007f50b4001000.00007f50b4012000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
              Source: Process Memory Space: zmap.ppc.elf PID: 6217, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
              Source: Process Memory Space: zmap.ppc.elf PID: 6222, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
              Source: classification engineClassification label: mal84.troj.evad.linELF@0/0@10/0

              Hooking and other Techniques for Hiding and Protection

              barindex
              Source: /tmp/zmap.ppc.elf (PID: 6217)File: /tmp/zmap.ppc.elfJump to behavior
              Source: /tmp/zmap.ppc.elf (PID: 6217)Queries kernel information via 'uname': Jump to behavior
              Source: zmap.ppc.elf, 6217.1.000056511f964000.000056511fa14000.rw-.sdmpBinary or memory string: !/etc/qemu-binfmt/ppc11!hotpluggableq
              Source: zmap.ppc.elf, 6222.1.000056511f964000.000056511fa14000.rw-.sdmpBinary or memory string: !/etc/qemu-binfmt/ppc1
              Source: zmap.ppc.elf, 6217.1.000056511f964000.000056511fa14000.rw-.sdmp, zmap.ppc.elf, 6222.1.000056511f964000.000056511fa14000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/ppc
              Source: zmap.ppc.elf, 6217.1.00007fff98720000.00007fff98741000.rw-.sdmp, zmap.ppc.elf, 6222.1.00007fff98720000.00007fff98741000.rw-.sdmpBinary or memory string: /usr/bin/qemu-ppc
              Source: zmap.ppc.elf, 6217.1.00007fff98720000.00007fff98741000.rw-.sdmp, zmap.ppc.elf, 6222.1.00007fff98720000.00007fff98741000.rw-.sdmpBinary or memory string: >x86_64/usr/bin/qemu-ppc/tmp/zmap.ppc.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/zmap.ppc.elf

              Stealing of Sensitive Information

              barindex
              Source: Yara matchFile source: zmap.ppc.elf, type: SAMPLE
              Source: Yara matchFile source: 6222.1.00007f50b4001000.00007f50b4012000.r-x.sdmp, type: MEMORY
              Source: Yara matchFile source: 6217.1.00007f50b4001000.00007f50b4012000.r-x.sdmp, type: MEMORY
              Source: Yara matchFile source: Process Memory Space: zmap.ppc.elf PID: 6217, type: MEMORYSTR
              Source: Yara matchFile source: Process Memory Space: zmap.ppc.elf PID: 6222, type: MEMORYSTR
              Source: Yara matchFile source: zmap.ppc.elf, type: SAMPLE
              Source: Yara matchFile source: 6222.1.00007f50b4001000.00007f50b4012000.r-x.sdmp, type: MEMORY
              Source: Yara matchFile source: 6217.1.00007f50b4001000.00007f50b4012000.r-x.sdmp, type: MEMORY
              Source: Yara matchFile source: Process Memory Space: zmap.ppc.elf PID: 6217, type: MEMORYSTR
              Source: Yara matchFile source: Process Memory Space: zmap.ppc.elf PID: 6222, type: MEMORYSTR

              Remote Access Functionality

              barindex
              Source: Yara matchFile source: zmap.ppc.elf, type: SAMPLE
              Source: Yara matchFile source: 6222.1.00007f50b4001000.00007f50b4012000.r-x.sdmp, type: MEMORY
              Source: Yara matchFile source: 6217.1.00007f50b4001000.00007f50b4012000.r-x.sdmp, type: MEMORY
              Source: Yara matchFile source: Process Memory Space: zmap.ppc.elf PID: 6217, type: MEMORYSTR
              Source: Yara matchFile source: Process Memory Space: zmap.ppc.elf PID: 6222, type: MEMORYSTR
              Source: Yara matchFile source: zmap.ppc.elf, type: SAMPLE
              Source: Yara matchFile source: 6222.1.00007f50b4001000.00007f50b4012000.r-x.sdmp, type: MEMORY
              Source: Yara matchFile source: 6217.1.00007f50b4001000.00007f50b4012000.r-x.sdmp, type: MEMORY
              Source: Yara matchFile source: Process Memory Space: zmap.ppc.elf PID: 6217, type: MEMORYSTR
              Source: Yara matchFile source: Process Memory Space: zmap.ppc.elf PID: 6222, type: MEMORYSTR
              ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
              Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception1
              File Deletion
              OS Credential Dumping11
              Security Software Discovery
              Remote ServicesData from Local System1
              Encrypted Channel
              Exfiltration Over Other Network MediumAbuse Accessibility Features
              CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
              Non-Standard Port
              Exfiltration Over BluetoothNetwork Denial of Service
              Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
              Non-Application Layer Protocol
              Automated ExfiltrationData Encrypted for Impact
              Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture2
              Application Layer Protocol
              Traffic DuplicationData Destruction
              No configs have been found
              Hide Legend

              Legend:

              • Process
              • Signature
              • Created File
              • DNS/IP Info
              • Is Dropped
              • Number of created Files
              • Is malicious
              • Internet
              SourceDetectionScannerLabelLink
              zmap.ppc.elf61%ReversingLabsLinux.Backdoor.Mirai
              zmap.ppc.elf100%AviraEXP/ELF.Mirai.Z.A
              No Antivirus matches
              No Antivirus matches
              No Antivirus matches
              NameIPActiveMaliciousAntivirus DetectionReputation
              srvy.vlrt-gap.com
              185.196.8.105
              truefalse
                high
                • No. of IPs < 25%
                • 25% < No. of IPs < 50%
                • 50% < No. of IPs < 75%
                • 75% < No. of IPs
                IPDomainCountryFlagASNASN NameMalicious
                185.196.8.105
                srvy.vlrt-gap.comSwitzerland
                34888SIMPLECARRER2ITfalse
                109.202.202.202
                unknownSwitzerland
                13030INIT7CHfalse
                91.189.91.43
                unknownUnited Kingdom
                41231CANONICAL-ASGBfalse
                91.189.91.42
                unknownUnited Kingdom
                41231CANONICAL-ASGBfalse
                MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                185.196.8.105zmap.sh4.elfGet hashmaliciousMirai, OkiruBrowse
                  zmap.mpsl.elfGet hashmaliciousMirai, OkiruBrowse
                    zmap.spc.elfGet hashmaliciousMirai, OkiruBrowse
                      zmap.x86.elfGet hashmaliciousOkiruBrowse
                        zmap.arm.elfGet hashmaliciousMirai, OkiruBrowse
                          109.202.202.202kpLwzBouH4.elfGet hashmaliciousUnknownBrowse
                          • ch.archive.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_92.0%2bbuild3-0ubuntu0.20.04.1_amd64.deb
                          91.189.91.43zmap.sh4.elfGet hashmaliciousMirai, OkiruBrowse
                            x86.elfGet hashmaliciousUnknownBrowse
                              zmap.mpsl.elfGet hashmaliciousMirai, OkiruBrowse
                                zmap.spc.elfGet hashmaliciousMirai, OkiruBrowse
                                  zmap.x86.elfGet hashmaliciousOkiruBrowse
                                    zmap.arm.elfGet hashmaliciousMirai, OkiruBrowse
                                      most-m68k.elfGet hashmaliciousUnknownBrowse
                                        arm7.elfGet hashmaliciousUnknownBrowse
                                          x86_64.nn.elfGet hashmaliciousOkiruBrowse
                                            nshppc.elfGet hashmaliciousUnknownBrowse
                                              91.189.91.42zmap.sh4.elfGet hashmaliciousMirai, OkiruBrowse
                                                x86.elfGet hashmaliciousUnknownBrowse
                                                  zmap.mpsl.elfGet hashmaliciousMirai, OkiruBrowse
                                                    zmap.spc.elfGet hashmaliciousMirai, OkiruBrowse
                                                      zmap.x86.elfGet hashmaliciousOkiruBrowse
                                                        zmap.arm.elfGet hashmaliciousMirai, OkiruBrowse
                                                          most-m68k.elfGet hashmaliciousUnknownBrowse
                                                            arm7.elfGet hashmaliciousUnknownBrowse
                                                              x86_64.nn.elfGet hashmaliciousOkiruBrowse
                                                                nshppc.elfGet hashmaliciousUnknownBrowse
                                                                  MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                  srvy.vlrt-gap.comzmap.sh4.elfGet hashmaliciousMirai, OkiruBrowse
                                                                  • 185.196.8.105
                                                                  zmap.mpsl.elfGet hashmaliciousMirai, OkiruBrowse
                                                                  • 185.196.8.105
                                                                  zmap.spc.elfGet hashmaliciousMirai, OkiruBrowse
                                                                  • 185.196.8.105
                                                                  zmap.x86.elfGet hashmaliciousOkiruBrowse
                                                                  • 185.196.8.105
                                                                  zmap.arm.elfGet hashmaliciousMirai, OkiruBrowse
                                                                  • 185.196.8.105
                                                                  MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                  CANONICAL-ASGBzmap.sh4.elfGet hashmaliciousMirai, OkiruBrowse
                                                                  • 91.189.91.42
                                                                  x86.elfGet hashmaliciousUnknownBrowse
                                                                  • 91.189.91.42
                                                                  zmap.mpsl.elfGet hashmaliciousMirai, OkiruBrowse
                                                                  • 91.189.91.42
                                                                  zmap.spc.elfGet hashmaliciousMirai, OkiruBrowse
                                                                  • 91.189.91.42
                                                                  zmap.x86.elfGet hashmaliciousOkiruBrowse
                                                                  • 91.189.91.42
                                                                  zmap.arm.elfGet hashmaliciousMirai, OkiruBrowse
                                                                  • 91.189.91.42
                                                                  most-m68k.elfGet hashmaliciousUnknownBrowse
                                                                  • 91.189.91.42
                                                                  arm7.elfGet hashmaliciousUnknownBrowse
                                                                  • 91.189.91.42
                                                                  x86_64.nn.elfGet hashmaliciousOkiruBrowse
                                                                  • 91.189.91.42
                                                                  nshppc.elfGet hashmaliciousUnknownBrowse
                                                                  • 91.189.91.42
                                                                  CANONICAL-ASGBzmap.sh4.elfGet hashmaliciousMirai, OkiruBrowse
                                                                  • 91.189.91.42
                                                                  x86.elfGet hashmaliciousUnknownBrowse
                                                                  • 91.189.91.42
                                                                  zmap.mpsl.elfGet hashmaliciousMirai, OkiruBrowse
                                                                  • 91.189.91.42
                                                                  zmap.spc.elfGet hashmaliciousMirai, OkiruBrowse
                                                                  • 91.189.91.42
                                                                  zmap.x86.elfGet hashmaliciousOkiruBrowse
                                                                  • 91.189.91.42
                                                                  zmap.arm.elfGet hashmaliciousMirai, OkiruBrowse
                                                                  • 91.189.91.42
                                                                  most-m68k.elfGet hashmaliciousUnknownBrowse
                                                                  • 91.189.91.42
                                                                  arm7.elfGet hashmaliciousUnknownBrowse
                                                                  • 91.189.91.42
                                                                  x86_64.nn.elfGet hashmaliciousOkiruBrowse
                                                                  • 91.189.91.42
                                                                  nshppc.elfGet hashmaliciousUnknownBrowse
                                                                  • 91.189.91.42
                                                                  SIMPLECARRER2ITzmap.sh4.elfGet hashmaliciousMirai, OkiruBrowse
                                                                  • 185.196.8.105
                                                                  zmap.mpsl.elfGet hashmaliciousMirai, OkiruBrowse
                                                                  • 185.196.8.105
                                                                  zmap.spc.elfGet hashmaliciousMirai, OkiruBrowse
                                                                  • 185.196.8.105
                                                                  zmap.x86.elfGet hashmaliciousOkiruBrowse
                                                                  • 185.196.8.105
                                                                  zmap.arm.elfGet hashmaliciousMirai, OkiruBrowse
                                                                  • 185.196.8.105
                                                                  DQmU06kq9I.exeGet hashmaliciousLiteHTTP BotBrowse
                                                                  • 185.208.159.109
                                                                  file.exeGet hashmaliciousLummaC, Amadey, Credential Flusher, LiteHTTP Bot, LummaC Stealer, Stealc, XmrigBrowse
                                                                  • 185.208.159.109
                                                                  file.exeGet hashmaliciousScreenConnect Tool, Amadey, RHADAMANTHYS, XWorm, XmrigBrowse
                                                                  • 185.196.8.237
                                                                  file.exeGet hashmaliciousAsyncRAT, VenomRATBrowse
                                                                  • 185.208.158.187
                                                                  Ziraat Bankasi Swift Mesaji.dqy.dllGet hashmaliciousAsyncRAT, VenomRATBrowse
                                                                  • 185.208.158.187
                                                                  INIT7CHzmap.sh4.elfGet hashmaliciousMirai, OkiruBrowse
                                                                  • 109.202.202.202
                                                                  x86.elfGet hashmaliciousUnknownBrowse
                                                                  • 109.202.202.202
                                                                  zmap.mpsl.elfGet hashmaliciousMirai, OkiruBrowse
                                                                  • 109.202.202.202
                                                                  zmap.spc.elfGet hashmaliciousMirai, OkiruBrowse
                                                                  • 109.202.202.202
                                                                  zmap.x86.elfGet hashmaliciousOkiruBrowse
                                                                  • 109.202.202.202
                                                                  zmap.arm.elfGet hashmaliciousMirai, OkiruBrowse
                                                                  • 109.202.202.202
                                                                  most-m68k.elfGet hashmaliciousUnknownBrowse
                                                                  • 109.202.202.202
                                                                  arm7.elfGet hashmaliciousUnknownBrowse
                                                                  • 109.202.202.202
                                                                  x86_64.nn.elfGet hashmaliciousOkiruBrowse
                                                                  • 109.202.202.202
                                                                  nshppc.elfGet hashmaliciousUnknownBrowse
                                                                  • 109.202.202.202
                                                                  No context
                                                                  No context
                                                                  No created / dropped files found
                                                                  File type:ELF 32-bit MSB executable, PowerPC or cisco 4500, version 1 (SYSV), statically linked, stripped
                                                                  Entropy (8bit):6.287589897684645
                                                                  TrID:
                                                                  • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                                                                  File name:zmap.ppc.elf
                                                                  File size:71'128 bytes
                                                                  MD5:45225829413203a55f6a1294380b04e8
                                                                  SHA1:33215ac191a20b7efa09ef7de2ace7aa5688ec4d
                                                                  SHA256:8d0d65c5d87bcc3fd8a088b4d05afc56046c5c2ca9efca8dd3eadfe644cf62c2
                                                                  SHA512:81eb28a8f735c885d14a7d757697052b81d0dfac50016f43c351253db225409a4e53b5741487ddbe6d55acddb2c16e2b3657f1c003b051dad828aac4b0f7e300
                                                                  SSDEEP:1536:mbxeCDlX+i4eReTgrE7Yoks3tp5MGk6Z9:ODlOFgJ+pGG5Z9
                                                                  TLSH:DD634B02B3180D03C5A359B0253F5BE097FEE9D132E0B689291F9B9A8A31E775185FCD
                                                                  File Content Preview:.ELF...........................4.........4. ...(.......................P...P..............................'x........dt.Q.............................!..|......$H...H..q...$8!. |...N.. .!..|.......?.............../...@..\?........+../...A..$8...})......N..

                                                                  ELF header

                                                                  Class:ELF32
                                                                  Data:2's complement, big endian
                                                                  Version:1 (current)
                                                                  Machine:PowerPC
                                                                  Version Number:0x1
                                                                  Type:EXEC (Executable file)
                                                                  OS/ABI:UNIX - System V
                                                                  ABI Version:0
                                                                  Entry Point Address:0x100001f0
                                                                  Flags:0x0
                                                                  ELF Header Size:52
                                                                  Program Header Offset:52
                                                                  Program Header Size:32
                                                                  Number of Program Headers:3
                                                                  Section Header Offset:70648
                                                                  Section Header Size:40
                                                                  Number of Section Headers:12
                                                                  Header String Table Index:11
                                                                  NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                                                  NULL0x00x00x00x00x0000
                                                                  .initPROGBITS0x100000940x940x240x00x6AX004
                                                                  .textPROGBITS0x100000b80xb80xebc80x00x6AX004
                                                                  .finiPROGBITS0x1000ec800xec800x200x00x6AX004
                                                                  .rodataPROGBITS0x1000eca00xeca00x20b00x00x2A008
                                                                  .ctorsPROGBITS0x100210000x110000x80x00x3WA004
                                                                  .dtorsPROGBITS0x100210080x110080x80x00x3WA004
                                                                  .dataPROGBITS0x100210180x110180x3540x00x3WA008
                                                                  .sdataPROGBITS0x1002136c0x1136c0x400x00x3WA004
                                                                  .sbssNOBITS0x100213ac0x113ac0x600x00x3WA004
                                                                  .bssNOBITS0x1002140c0x113ac0x236c0x00x3WA004
                                                                  .shstrtabSTRTAB0x00x113ac0x4b0x00x0001
                                                                  TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                                  LOAD0x00x100000000x100000000x10d500x10d506.37000x5R E0x10000.init .text .fini .rodata
                                                                  LOAD0x110000x100210000x100210000x3ac0x27783.18490x6RW 0x10000.ctors .dtors .data .sdata .sbss .bss
                                                                  GNU_STACK0x00x00x00x00x00.00000x6RW 0x4
                                                                  TimestampSource PortDest PortSource IPDest IP
                                                                  Dec 24, 2024 13:32:50.549210072 CET43928443192.168.2.2391.189.91.42
                                                                  Dec 24, 2024 13:32:52.121798992 CET3952859962192.168.2.23185.196.8.105
                                                                  Dec 24, 2024 13:32:52.241791964 CET5996239528185.196.8.105192.168.2.23
                                                                  Dec 24, 2024 13:32:52.241895914 CET3952859962192.168.2.23185.196.8.105
                                                                  Dec 24, 2024 13:32:52.242805004 CET3952859962192.168.2.23185.196.8.105
                                                                  Dec 24, 2024 13:32:52.362468004 CET5996239528185.196.8.105192.168.2.23
                                                                  Dec 24, 2024 13:32:52.362757921 CET3952859962192.168.2.23185.196.8.105
                                                                  Dec 24, 2024 13:32:52.482445002 CET5996239528185.196.8.105192.168.2.23
                                                                  Dec 24, 2024 13:32:53.544869900 CET5996239528185.196.8.105192.168.2.23
                                                                  Dec 24, 2024 13:32:53.545034885 CET3952859962192.168.2.23185.196.8.105
                                                                  Dec 24, 2024 13:32:53.545242071 CET3952859962192.168.2.23185.196.8.105
                                                                  Dec 24, 2024 13:32:53.787507057 CET3953059962192.168.2.23185.196.8.105
                                                                  Dec 24, 2024 13:32:53.907109022 CET5996239530185.196.8.105192.168.2.23
                                                                  Dec 24, 2024 13:32:53.907282114 CET3953059962192.168.2.23185.196.8.105
                                                                  Dec 24, 2024 13:32:53.908143997 CET3953059962192.168.2.23185.196.8.105
                                                                  Dec 24, 2024 13:32:54.028347015 CET5996239530185.196.8.105192.168.2.23
                                                                  Dec 24, 2024 13:32:54.028558969 CET3953059962192.168.2.23185.196.8.105
                                                                  Dec 24, 2024 13:32:54.148088932 CET5996239530185.196.8.105192.168.2.23
                                                                  Dec 24, 2024 13:32:55.224771976 CET5996239530185.196.8.105192.168.2.23
                                                                  Dec 24, 2024 13:32:55.225027084 CET3953059962192.168.2.23185.196.8.105
                                                                  Dec 24, 2024 13:32:55.225027084 CET3953059962192.168.2.23185.196.8.105
                                                                  Dec 24, 2024 13:32:55.589893103 CET3953259962192.168.2.23185.196.8.105
                                                                  Dec 24, 2024 13:32:55.709419012 CET5996239532185.196.8.105192.168.2.23
                                                                  Dec 24, 2024 13:32:55.709513903 CET3953259962192.168.2.23185.196.8.105
                                                                  Dec 24, 2024 13:32:55.710571051 CET3953259962192.168.2.23185.196.8.105
                                                                  Dec 24, 2024 13:32:55.830055952 CET5996239532185.196.8.105192.168.2.23
                                                                  Dec 24, 2024 13:32:55.830238104 CET3953259962192.168.2.23185.196.8.105
                                                                  Dec 24, 2024 13:32:55.924508095 CET42836443192.168.2.2391.189.91.43
                                                                  Dec 24, 2024 13:32:55.949822903 CET5996239532185.196.8.105192.168.2.23
                                                                  Dec 24, 2024 13:32:56.948477030 CET4251680192.168.2.23109.202.202.202
                                                                  Dec 24, 2024 13:32:57.007340908 CET5996239532185.196.8.105192.168.2.23
                                                                  Dec 24, 2024 13:32:57.007626057 CET3953259962192.168.2.23185.196.8.105
                                                                  Dec 24, 2024 13:32:57.007663965 CET3953259962192.168.2.23185.196.8.105
                                                                  Dec 24, 2024 13:32:57.143935919 CET3953459962192.168.2.23185.196.8.105
                                                                  Dec 24, 2024 13:32:57.263623953 CET5996239534185.196.8.105192.168.2.23
                                                                  Dec 24, 2024 13:32:57.263827085 CET3953459962192.168.2.23185.196.8.105
                                                                  Dec 24, 2024 13:32:57.264821053 CET3953459962192.168.2.23185.196.8.105
                                                                  Dec 24, 2024 13:32:57.384887934 CET5996239534185.196.8.105192.168.2.23
                                                                  Dec 24, 2024 13:32:57.384965897 CET3953459962192.168.2.23185.196.8.105
                                                                  Dec 24, 2024 13:32:57.504437923 CET5996239534185.196.8.105192.168.2.23
                                                                  Dec 24, 2024 13:32:58.340590000 CET5996239534185.196.8.105192.168.2.23
                                                                  Dec 24, 2024 13:32:58.340895891 CET3953459962192.168.2.23185.196.8.105
                                                                  Dec 24, 2024 13:32:58.460381985 CET5996239534185.196.8.105192.168.2.23
                                                                  Dec 24, 2024 13:32:59.478950024 CET3953659962192.168.2.23185.196.8.105
                                                                  Dec 24, 2024 13:32:59.598439932 CET5996239536185.196.8.105192.168.2.23
                                                                  Dec 24, 2024 13:32:59.598685026 CET3953659962192.168.2.23185.196.8.105
                                                                  Dec 24, 2024 13:32:59.599741936 CET3953659962192.168.2.23185.196.8.105
                                                                  Dec 24, 2024 13:32:59.719170094 CET5996239536185.196.8.105192.168.2.23
                                                                  Dec 24, 2024 13:32:59.719335079 CET3953659962192.168.2.23185.196.8.105
                                                                  Dec 24, 2024 13:32:59.838823080 CET5996239536185.196.8.105192.168.2.23
                                                                  Dec 24, 2024 13:33:00.894669056 CET5996239536185.196.8.105192.168.2.23
                                                                  Dec 24, 2024 13:33:00.894936085 CET3953659962192.168.2.23185.196.8.105
                                                                  Dec 24, 2024 13:33:00.894936085 CET3953659962192.168.2.23185.196.8.105
                                                                  Dec 24, 2024 13:33:01.135811090 CET3953859962192.168.2.23185.196.8.105
                                                                  Dec 24, 2024 13:33:01.255450964 CET5996239538185.196.8.105192.168.2.23
                                                                  Dec 24, 2024 13:33:01.255731106 CET3953859962192.168.2.23185.196.8.105
                                                                  Dec 24, 2024 13:33:01.256866932 CET3953859962192.168.2.23185.196.8.105
                                                                  Dec 24, 2024 13:33:01.376840115 CET5996239538185.196.8.105192.168.2.23
                                                                  Dec 24, 2024 13:33:01.377063036 CET3953859962192.168.2.23185.196.8.105
                                                                  Dec 24, 2024 13:33:01.496562004 CET5996239538185.196.8.105192.168.2.23
                                                                  Dec 24, 2024 13:33:02.552647114 CET5996239538185.196.8.105192.168.2.23
                                                                  Dec 24, 2024 13:33:02.552930117 CET3953859962192.168.2.23185.196.8.105
                                                                  Dec 24, 2024 13:33:02.552930117 CET3953859962192.168.2.23185.196.8.105
                                                                  Dec 24, 2024 13:33:02.690699100 CET3954059962192.168.2.23185.196.8.105
                                                                  Dec 24, 2024 13:33:02.810271025 CET5996239540185.196.8.105192.168.2.23
                                                                  Dec 24, 2024 13:33:02.810408115 CET3954059962192.168.2.23185.196.8.105
                                                                  Dec 24, 2024 13:33:02.811364889 CET3954059962192.168.2.23185.196.8.105
                                                                  Dec 24, 2024 13:33:02.930937052 CET5996239540185.196.8.105192.168.2.23
                                                                  Dec 24, 2024 13:33:02.931107044 CET3954059962192.168.2.23185.196.8.105
                                                                  Dec 24, 2024 13:33:03.050632000 CET5996239540185.196.8.105192.168.2.23
                                                                  Dec 24, 2024 13:33:04.110716105 CET5996239540185.196.8.105192.168.2.23
                                                                  Dec 24, 2024 13:33:04.110924006 CET3954059962192.168.2.23185.196.8.105
                                                                  Dec 24, 2024 13:33:04.111136913 CET3954059962192.168.2.23185.196.8.105
                                                                  Dec 24, 2024 13:33:04.247773886 CET3954259962192.168.2.23185.196.8.105
                                                                  Dec 24, 2024 13:33:04.367894888 CET5996239542185.196.8.105192.168.2.23
                                                                  Dec 24, 2024 13:33:04.368093014 CET3954259962192.168.2.23185.196.8.105
                                                                  Dec 24, 2024 13:33:04.369060040 CET3954259962192.168.2.23185.196.8.105
                                                                  Dec 24, 2024 13:33:04.488534927 CET5996239542185.196.8.105192.168.2.23
                                                                  Dec 24, 2024 13:33:04.488805056 CET3954259962192.168.2.23185.196.8.105
                                                                  Dec 24, 2024 13:33:04.608275890 CET5996239542185.196.8.105192.168.2.23
                                                                  Dec 24, 2024 13:33:05.675453901 CET5996239542185.196.8.105192.168.2.23
                                                                  Dec 24, 2024 13:33:05.675595045 CET3954259962192.168.2.23185.196.8.105
                                                                  Dec 24, 2024 13:33:05.675649881 CET3954259962192.168.2.23185.196.8.105
                                                                  Dec 24, 2024 13:33:06.040246964 CET3954459962192.168.2.23185.196.8.105
                                                                  Dec 24, 2024 13:33:06.160156965 CET5996239544185.196.8.105192.168.2.23
                                                                  Dec 24, 2024 13:33:06.160420895 CET3954459962192.168.2.23185.196.8.105
                                                                  Dec 24, 2024 13:33:06.161628962 CET3954459962192.168.2.23185.196.8.105
                                                                  Dec 24, 2024 13:33:06.281233072 CET5996239544185.196.8.105192.168.2.23
                                                                  Dec 24, 2024 13:33:06.281481981 CET3954459962192.168.2.23185.196.8.105
                                                                  Dec 24, 2024 13:33:06.401108027 CET5996239544185.196.8.105192.168.2.23
                                                                  Dec 24, 2024 13:33:07.456286907 CET5996239544185.196.8.105192.168.2.23
                                                                  Dec 24, 2024 13:33:07.456537008 CET3954459962192.168.2.23185.196.8.105
                                                                  Dec 24, 2024 13:33:07.456537008 CET3954459962192.168.2.23185.196.8.105
                                                                  Dec 24, 2024 13:33:07.699963093 CET3954659962192.168.2.23185.196.8.105
                                                                  Dec 24, 2024 13:33:07.819670916 CET5996239546185.196.8.105192.168.2.23
                                                                  Dec 24, 2024 13:33:07.819987059 CET3954659962192.168.2.23185.196.8.105
                                                                  Dec 24, 2024 13:33:07.821167946 CET3954659962192.168.2.23185.196.8.105
                                                                  Dec 24, 2024 13:33:07.940707922 CET5996239546185.196.8.105192.168.2.23
                                                                  Dec 24, 2024 13:33:07.940947056 CET3954659962192.168.2.23185.196.8.105
                                                                  Dec 24, 2024 13:33:08.060499907 CET5996239546185.196.8.105192.168.2.23
                                                                  Dec 24, 2024 13:33:11.282404900 CET43928443192.168.2.2391.189.91.42
                                                                  Dec 24, 2024 13:33:17.829658031 CET3954659962192.168.2.23185.196.8.105
                                                                  Dec 24, 2024 13:33:17.949213028 CET5996239546185.196.8.105192.168.2.23
                                                                  Dec 24, 2024 13:33:18.249084949 CET5996239546185.196.8.105192.168.2.23
                                                                  Dec 24, 2024 13:33:18.249372005 CET3954659962192.168.2.23185.196.8.105
                                                                  Dec 24, 2024 13:33:21.521094084 CET42836443192.168.2.2391.189.91.43
                                                                  Dec 24, 2024 13:33:27.664119959 CET4251680192.168.2.23109.202.202.202
                                                                  Dec 24, 2024 13:33:52.236774921 CET43928443192.168.2.2391.189.91.42
                                                                  Dec 24, 2024 13:34:12.713972092 CET42836443192.168.2.2391.189.91.43
                                                                  Dec 24, 2024 13:34:18.299947977 CET3954659962192.168.2.23185.196.8.105
                                                                  Dec 24, 2024 13:34:18.419533968 CET5996239546185.196.8.105192.168.2.23
                                                                  Dec 24, 2024 13:34:18.719552040 CET5996239546185.196.8.105192.168.2.23
                                                                  Dec 24, 2024 13:34:18.719728947 CET3954659962192.168.2.23185.196.8.105
                                                                  TimestampSource PortDest PortSource IPDest IP
                                                                  Dec 24, 2024 13:32:51.976341009 CET3538753192.168.2.238.8.8.8
                                                                  Dec 24, 2024 13:32:52.111135006 CET53353878.8.8.8192.168.2.23
                                                                  Dec 24, 2024 13:32:53.546741962 CET3534653192.168.2.238.8.8.8
                                                                  Dec 24, 2024 13:32:53.786129951 CET53353468.8.8.8192.168.2.23
                                                                  Dec 24, 2024 13:32:55.225997925 CET3769053192.168.2.238.8.8.8
                                                                  Dec 24, 2024 13:32:55.589224100 CET53376908.8.8.8192.168.2.23
                                                                  Dec 24, 2024 13:32:57.008805990 CET4307353192.168.2.238.8.8.8
                                                                  Dec 24, 2024 13:32:57.143037081 CET53430738.8.8.8192.168.2.23
                                                                  Dec 24, 2024 13:32:59.343476057 CET4306453192.168.2.238.8.8.8
                                                                  Dec 24, 2024 13:32:59.478064060 CET53430648.8.8.8192.168.2.23
                                                                  Dec 24, 2024 13:33:00.896209002 CET3345753192.168.2.238.8.8.8
                                                                  Dec 24, 2024 13:33:01.134562969 CET53334578.8.8.8192.168.2.23
                                                                  Dec 24, 2024 13:33:02.554390907 CET4318053192.168.2.238.8.8.8
                                                                  Dec 24, 2024 13:33:02.689815044 CET53431808.8.8.8192.168.2.23
                                                                  Dec 24, 2024 13:33:04.112152100 CET4031353192.168.2.238.8.8.8
                                                                  Dec 24, 2024 13:33:04.246862888 CET53403138.8.8.8192.168.2.23
                                                                  Dec 24, 2024 13:33:05.676989079 CET5834553192.168.2.238.8.8.8
                                                                  Dec 24, 2024 13:33:06.039542913 CET53583458.8.8.8192.168.2.23
                                                                  Dec 24, 2024 13:33:07.457402945 CET4604953192.168.2.238.8.8.8
                                                                  Dec 24, 2024 13:33:07.699018002 CET53460498.8.8.8192.168.2.23
                                                                  TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                                                  Dec 24, 2024 13:32:51.976341009 CET192.168.2.238.8.8.80x5813Standard query (0)srvy.vlrt-gap.comA (IP address)IN (0x0001)false
                                                                  Dec 24, 2024 13:32:53.546741962 CET192.168.2.238.8.8.80x6b5cStandard query (0)srvy.vlrt-gap.comA (IP address)IN (0x0001)false
                                                                  Dec 24, 2024 13:32:55.225997925 CET192.168.2.238.8.8.80x6316Standard query (0)srvy.vlrt-gap.comA (IP address)IN (0x0001)false
                                                                  Dec 24, 2024 13:32:57.008805990 CET192.168.2.238.8.8.80xd6c5Standard query (0)srvy.vlrt-gap.comA (IP address)IN (0x0001)false
                                                                  Dec 24, 2024 13:32:59.343476057 CET192.168.2.238.8.8.80x842cStandard query (0)srvy.vlrt-gap.comA (IP address)IN (0x0001)false
                                                                  Dec 24, 2024 13:33:00.896209002 CET192.168.2.238.8.8.80x5194Standard query (0)srvy.vlrt-gap.comA (IP address)IN (0x0001)false
                                                                  Dec 24, 2024 13:33:02.554390907 CET192.168.2.238.8.8.80x3d3eStandard query (0)srvy.vlrt-gap.comA (IP address)IN (0x0001)false
                                                                  Dec 24, 2024 13:33:04.112152100 CET192.168.2.238.8.8.80xd054Standard query (0)srvy.vlrt-gap.comA (IP address)IN (0x0001)false
                                                                  Dec 24, 2024 13:33:05.676989079 CET192.168.2.238.8.8.80x82aeStandard query (0)srvy.vlrt-gap.comA (IP address)IN (0x0001)false
                                                                  Dec 24, 2024 13:33:07.457402945 CET192.168.2.238.8.8.80x873eStandard query (0)srvy.vlrt-gap.comA (IP address)IN (0x0001)false
                                                                  TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                                                  Dec 24, 2024 13:32:52.111135006 CET8.8.8.8192.168.2.230x5813No error (0)srvy.vlrt-gap.com185.196.8.105A (IP address)IN (0x0001)false
                                                                  Dec 24, 2024 13:32:53.786129951 CET8.8.8.8192.168.2.230x6b5cNo error (0)srvy.vlrt-gap.com185.196.8.105A (IP address)IN (0x0001)false
                                                                  Dec 24, 2024 13:32:55.589224100 CET8.8.8.8192.168.2.230x6316No error (0)srvy.vlrt-gap.com185.196.8.105A (IP address)IN (0x0001)false
                                                                  Dec 24, 2024 13:32:57.143037081 CET8.8.8.8192.168.2.230xd6c5No error (0)srvy.vlrt-gap.com185.196.8.105A (IP address)IN (0x0001)false
                                                                  Dec 24, 2024 13:32:59.478064060 CET8.8.8.8192.168.2.230x842cNo error (0)srvy.vlrt-gap.com185.196.8.105A (IP address)IN (0x0001)false
                                                                  Dec 24, 2024 13:33:01.134562969 CET8.8.8.8192.168.2.230x5194No error (0)srvy.vlrt-gap.com185.196.8.105A (IP address)IN (0x0001)false
                                                                  Dec 24, 2024 13:33:02.689815044 CET8.8.8.8192.168.2.230x3d3eNo error (0)srvy.vlrt-gap.com185.196.8.105A (IP address)IN (0x0001)false
                                                                  Dec 24, 2024 13:33:04.246862888 CET8.8.8.8192.168.2.230xd054No error (0)srvy.vlrt-gap.com185.196.8.105A (IP address)IN (0x0001)false
                                                                  Dec 24, 2024 13:33:06.039542913 CET8.8.8.8192.168.2.230x82aeNo error (0)srvy.vlrt-gap.com185.196.8.105A (IP address)IN (0x0001)false
                                                                  Dec 24, 2024 13:33:07.699018002 CET8.8.8.8192.168.2.230x873eNo error (0)srvy.vlrt-gap.com185.196.8.105A (IP address)IN (0x0001)false

                                                                  System Behavior

                                                                  Start time (UTC):12:32:50
                                                                  Start date (UTC):24/12/2024
                                                                  Path:/tmp/zmap.ppc.elf
                                                                  Arguments:/tmp/zmap.ppc.elf
                                                                  File size:5388968 bytes
                                                                  MD5 hash:ae65271c943d3451b7f026d1fadccea6

                                                                  Start time (UTC):12:32:50
                                                                  Start date (UTC):24/12/2024
                                                                  Path:/tmp/zmap.ppc.elf
                                                                  Arguments:-
                                                                  File size:5388968 bytes
                                                                  MD5 hash:ae65271c943d3451b7f026d1fadccea6

                                                                  Start time (UTC):12:32:50
                                                                  Start date (UTC):24/12/2024
                                                                  Path:/tmp/zmap.ppc.elf
                                                                  Arguments:-
                                                                  File size:5388968 bytes
                                                                  MD5 hash:ae65271c943d3451b7f026d1fadccea6