Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
mips.elf

Overview

General Information

Sample name:mips.elf
Analysis ID:1581450
MD5:16a4575da9194762a94e186c9c672d69
SHA1:d5e3253eb795b156a044cbbc77f2e3f3a01a2e6a
SHA256:2484754793dfc38e0f5508d6b01b78b0fcaaecbb93be0ee17a9c6604a5dfbaa5
Tags:elfuser-abuse_ch
Infos:

Detection

Score:56
Range:0 - 100
Whitelisted:false

Signatures

Antivirus / Scanner detection for submitted sample
Multi AV Scanner detection for submitted file
Sample has stripped symbol table
Sample listens on a socket
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Tries to resolve domain names, but no domain seems valid (expired dropper behavior)
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1581450
Start date and time:2024-12-27 18:47:04 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 24s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:mips.elf
Detection:MAL
Classification:mal56.linELF@0/0@45/0
  • VT rate limit hit for: mips.elf
Command:/tmp/mips.elf
PID:6222
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
[INFO] Project @RebirthLTD (06-01-2024)
Standard Error:
  • system is lnxubuntu20
  • mips.elf (PID: 6222, Parent: 6134, MD5: 0083f1f0e77be34ad27f849842bbb00c) Arguments: /tmp/mips.elf
    • mips.elf New Fork (PID: 6224, Parent: 6222)
      • mips.elf New Fork (PID: 6226, Parent: 6224)
  • cleanup
No yara matches
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: mips.elfAvira: detected
Source: mips.elfReversingLabs: Detection: 21%
Source: /tmp/mips.elf (PID: 6222)Socket: 127.0.0.1:13291Jump to behavior
Source: global trafficTCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
Source: global trafficTCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
Source: global trafficTCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
Source: unknownDNS traffic detected: query: dns.stresse.pro replaycode: Name error (3)
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownUDP traffic detected without corresponding DNS query: 208.76.51.51
Source: unknownUDP traffic detected without corresponding DNS query: 208.76.51.51
Source: unknownUDP traffic detected without corresponding DNS query: 208.76.51.51
Source: unknownUDP traffic detected without corresponding DNS query: 208.76.51.51
Source: unknownUDP traffic detected without corresponding DNS query: 208.76.51.51
Source: unknownUDP traffic detected without corresponding DNS query: 8.20.247.20
Source: unknownUDP traffic detected without corresponding DNS query: 8.20.247.20
Source: unknownUDP traffic detected without corresponding DNS query: 8.20.247.20
Source: unknownUDP traffic detected without corresponding DNS query: 8.20.247.20
Source: unknownUDP traffic detected without corresponding DNS query: 8.20.247.20
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 51.77.149.139
Source: unknownUDP traffic detected without corresponding DNS query: 51.77.149.139
Source: unknownUDP traffic detected without corresponding DNS query: 51.77.149.139
Source: unknownUDP traffic detected without corresponding DNS query: 51.77.149.139
Source: unknownUDP traffic detected without corresponding DNS query: 51.77.149.139
Source: unknownUDP traffic detected without corresponding DNS query: 208.67.220.220
Source: unknownUDP traffic detected without corresponding DNS query: 208.67.220.220
Source: unknownUDP traffic detected without corresponding DNS query: 208.67.220.220
Source: unknownUDP traffic detected without corresponding DNS query: 208.67.220.220
Source: unknownUDP traffic detected without corresponding DNS query: 208.67.220.220
Source: unknownUDP traffic detected without corresponding DNS query: 194.36.144.87
Source: unknownUDP traffic detected without corresponding DNS query: 194.36.144.87
Source: unknownUDP traffic detected without corresponding DNS query: 194.36.144.87
Source: unknownUDP traffic detected without corresponding DNS query: 194.36.144.87
Source: unknownUDP traffic detected without corresponding DNS query: 194.36.144.87
Source: unknownUDP traffic detected without corresponding DNS query: 208.76.50.50
Source: unknownUDP traffic detected without corresponding DNS query: 208.76.50.50
Source: unknownUDP traffic detected without corresponding DNS query: 208.76.50.50
Source: unknownUDP traffic detected without corresponding DNS query: 208.76.50.50
Source: unknownUDP traffic detected without corresponding DNS query: 208.76.50.50
Source: unknownUDP traffic detected without corresponding DNS query: 8.26.56.26
Source: unknownUDP traffic detected without corresponding DNS query: 8.26.56.26
Source: unknownUDP traffic detected without corresponding DNS query: 8.26.56.26
Source: unknownUDP traffic detected without corresponding DNS query: 8.26.56.26
Source: unknownUDP traffic detected without corresponding DNS query: 8.26.56.26
Source: unknownUDP traffic detected without corresponding DNS query: 208.76.51.51
Source: unknownUDP traffic detected without corresponding DNS query: 208.76.51.51
Source: unknownUDP traffic detected without corresponding DNS query: 208.76.51.51
Source: global trafficDNS traffic detected: DNS query: dns.stresse.pro
Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443
Source: ELF static info symbol of initial sample.symtab present: no
Source: classification engineClassification label: mal56.linELF@0/0@45/0
Source: /tmp/mips.elf (PID: 6222)Queries kernel information via 'uname': Jump to behavior
Source: mips.elf, 6222.1.000056061854a000.00005606185f4000.rw-.sdmpBinary or memory string: V!/etc/qemu-binfmt/mips
Source: mips.elf, 6222.1.000056061854a000.00005606185f4000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/mips
Source: mips.elf, 6222.1.00007ffffe9d3000.00007ffffe9f4000.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-mips/tmp/mips.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/mips.elf
Source: mips.elf, 6222.1.00007ffffe9d3000.00007ffffe9f4000.rw-.sdmpBinary or memory string: /usr/bin/qemu-mips
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath InterceptionDirect Volume AccessOS Credential Dumping11
Security Software Discovery
Remote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive2
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1581450 Sample: mips.elf Startdate: 27/12/2024 Architecture: LINUX Score: 56 14 109.202.202.202, 80 INIT7CH Switzerland 2->14 16 91.189.91.42, 443 CANONICAL-ASGB United Kingdom 2->16 18 2 other IPs or domains 2->18 20 Antivirus / Scanner detection for submitted sample 2->20 22 Multi AV Scanner detection for submitted file 2->22 8 mips.elf 2->8         started        signatures3 process4 process5 10 mips.elf 8->10         started        process6 12 mips.elf 10->12         started       
SourceDetectionScannerLabelLink
mips.elf21%ReversingLabsLinux.Backdoor.Mirai
mips.elf100%AviraEXP/ELF.Agent.J.8
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
dns.stresse.pro
unknown
unknownfalse
    unknown
    • No. of IPs < 25%
    • 25% < No. of IPs < 50%
    • 50% < No. of IPs < 75%
    • 75% < No. of IPs
    IPDomainCountryFlagASNASN NameMalicious
    109.202.202.202
    unknownSwitzerland
    13030INIT7CHfalse
    91.189.91.43
    unknownUnited Kingdom
    41231CANONICAL-ASGBfalse
    91.189.91.42
    unknownUnited Kingdom
    41231CANONICAL-ASGBfalse
    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
    109.202.202.202kpLwzBouH4.elfGet hashmaliciousUnknownBrowse
    • ch.archive.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_92.0%2bbuild3-0ubuntu0.20.04.1_amd64.deb
    91.189.91.43mips.elfGet hashmaliciousUnknownBrowse
      byte.mpsl.elfGet hashmaliciousMirai, OkiruBrowse
        dlr.arm.elfGet hashmaliciousUnknownBrowse
          byte.mpsl.elfGet hashmaliciousMirai, OkiruBrowse
            byte.ppc.elfGet hashmaliciousMirai, OkiruBrowse
              llklllklld.x86.elfGet hashmaliciousMirai, OkiruBrowse
                .i.elfGet hashmaliciousUnknownBrowse
                  sh4.elfGet hashmaliciousMiraiBrowse
                    Space.spc.elfGet hashmaliciousMiraiBrowse
                      Space.arm5.elfGet hashmaliciousUnknownBrowse
                        91.189.91.42mips.elfGet hashmaliciousUnknownBrowse
                          byte.mpsl.elfGet hashmaliciousMirai, OkiruBrowse
                            dlr.arm.elfGet hashmaliciousUnknownBrowse
                              byte.mpsl.elfGet hashmaliciousMirai, OkiruBrowse
                                byte.ppc.elfGet hashmaliciousMirai, OkiruBrowse
                                  llklllklld.x86.elfGet hashmaliciousMirai, OkiruBrowse
                                    .i.elfGet hashmaliciousUnknownBrowse
                                      sh4.elfGet hashmaliciousMiraiBrowse
                                        Space.spc.elfGet hashmaliciousMiraiBrowse
                                          Space.arm5.elfGet hashmaliciousUnknownBrowse
                                            No context
                                            MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                            CANONICAL-ASGBmips.elfGet hashmaliciousUnknownBrowse
                                            • 91.189.91.42
                                            byte.mpsl.elfGet hashmaliciousMirai, OkiruBrowse
                                            • 91.189.91.42
                                            drp.x86.elfGet hashmaliciousMirai, OkiruBrowse
                                            • 185.125.190.26
                                            dlr.arm.elfGet hashmaliciousUnknownBrowse
                                            • 91.189.91.42
                                            byte.mpsl.elfGet hashmaliciousMirai, OkiruBrowse
                                            • 91.189.91.42
                                            byte.ppc.elfGet hashmaliciousMirai, OkiruBrowse
                                            • 91.189.91.42
                                            llklllklld.x86.elfGet hashmaliciousMirai, OkiruBrowse
                                            • 91.189.91.42
                                            .i.elfGet hashmaliciousUnknownBrowse
                                            • 91.189.91.42
                                            sh4.elfGet hashmaliciousMiraiBrowse
                                            • 91.189.91.42
                                            ppc.elfGet hashmaliciousMiraiBrowse
                                            • 185.125.190.26
                                            CANONICAL-ASGBmips.elfGet hashmaliciousUnknownBrowse
                                            • 91.189.91.42
                                            byte.mpsl.elfGet hashmaliciousMirai, OkiruBrowse
                                            • 91.189.91.42
                                            drp.x86.elfGet hashmaliciousMirai, OkiruBrowse
                                            • 185.125.190.26
                                            dlr.arm.elfGet hashmaliciousUnknownBrowse
                                            • 91.189.91.42
                                            byte.mpsl.elfGet hashmaliciousMirai, OkiruBrowse
                                            • 91.189.91.42
                                            byte.ppc.elfGet hashmaliciousMirai, OkiruBrowse
                                            • 91.189.91.42
                                            llklllklld.x86.elfGet hashmaliciousMirai, OkiruBrowse
                                            • 91.189.91.42
                                            .i.elfGet hashmaliciousUnknownBrowse
                                            • 91.189.91.42
                                            sh4.elfGet hashmaliciousMiraiBrowse
                                            • 91.189.91.42
                                            ppc.elfGet hashmaliciousMiraiBrowse
                                            • 185.125.190.26
                                            INIT7CHmips.elfGet hashmaliciousUnknownBrowse
                                            • 109.202.202.202
                                            byte.mpsl.elfGet hashmaliciousMirai, OkiruBrowse
                                            • 109.202.202.202
                                            dlr.arm.elfGet hashmaliciousUnknownBrowse
                                            • 109.202.202.202
                                            byte.mpsl.elfGet hashmaliciousMirai, OkiruBrowse
                                            • 109.202.202.202
                                            byte.ppc.elfGet hashmaliciousMirai, OkiruBrowse
                                            • 109.202.202.202
                                            llklllklld.x86.elfGet hashmaliciousMirai, OkiruBrowse
                                            • 109.202.202.202
                                            .i.elfGet hashmaliciousUnknownBrowse
                                            • 109.202.202.202
                                            sh4.elfGet hashmaliciousMiraiBrowse
                                            • 109.202.202.202
                                            Space.spc.elfGet hashmaliciousMiraiBrowse
                                            • 109.202.202.202
                                            Space.arm5.elfGet hashmaliciousUnknownBrowse
                                            • 109.202.202.202
                                            No context
                                            No context
                                            No created / dropped files found
                                            File type:ELF 32-bit MSB executable, MIPS, MIPS-I version 1 (SYSV), statically linked, stripped
                                            Entropy (8bit):5.051854250633193
                                            TrID:
                                            • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                                            File name:mips.elf
                                            File size:199'328 bytes
                                            MD5:16a4575da9194762a94e186c9c672d69
                                            SHA1:d5e3253eb795b156a044cbbc77f2e3f3a01a2e6a
                                            SHA256:2484754793dfc38e0f5508d6b01b78b0fcaaecbb93be0ee17a9c6604a5dfbaa5
                                            SHA512:21d1812890386aae6a0dd915d5294706374f55f9bd98b8e6b531a9510bb22866b28bc63e1e65718d89da99b3b888f231981934c3ec76860c3b451b03b7bb9574
                                            SSDEEP:1536:vH73xcepASDXSDPrDVY6cj+pA5rnOgg4KNkQOiN8Ksl7LMZofWDeLccslZ1bI9lc:vzxFUdy4E68Ksl74ZofIlZYwu/BhJcN
                                            TLSH:8E14B61A6E228F7EF76C873447B78A34A76923D627E1D684D1ACC1105F2035E641FFA8
                                            File Content Preview:.ELF.....................@.`...4...p.....4. ...(.............@...@.....p...p.................F...F....X.............dt.Q............................<...'.}\...!'.......................<...'.}8...!... ....'9... ......................<...'.}....!........'9.

                                            ELF header

                                            Class:ELF32
                                            Data:2's complement, big endian
                                            Version:1 (current)
                                            Machine:MIPS R3000
                                            Version Number:0x1
                                            Type:EXEC (Executable file)
                                            OS/ABI:UNIX - System V
                                            ABI Version:0
                                            Entry Point Address:0x400260
                                            Flags:0x1007
                                            ELF Header Size:52
                                            Program Header Offset:52
                                            Program Header Size:32
                                            Number of Program Headers:3
                                            Section Header Offset:198768
                                            Section Header Size:40
                                            Number of Section Headers:14
                                            Header String Table Index:13
                                            NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                            NULL0x00x00x00x00x0000
                                            .initPROGBITS0x4000940x940x8c0x00x6AX004
                                            .textPROGBITS0x4001200x1200x282c00x00x6AX0016
                                            .finiPROGBITS0x4283e00x283e00x5c0x00x6AX004
                                            .rodataPROGBITS0x4284400x284400x25300x00x2A0016
                                            .ctorsPROGBITS0x46b0000x2b0000xc0x00x3WA004
                                            .dtorsPROGBITS0x46b00c0x2b00c0x80x00x3WA004
                                            .data.rel.roPROGBITS0x46b0180x2b0180x4bc0x00x3WA004
                                            .dataPROGBITS0x46b4e00x2b4e00x49200x00x3WA0032
                                            .gotPROGBITS0x46fe000x2fe000xa0c0x40x10000003WAp0016
                                            .sbssNOBITS0x47080c0x3080c0x400x00x10000003WAp004
                                            .bssNOBITS0x4708500x3080c0x46a00x00x3WA0016
                                            .mdebug.abi32PROGBITS0x14ac0x3080c0x00x00x0001
                                            .shstrtabSTRTAB0x00x3080c0x640x00x0001
                                            TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                            LOAD0x00x4000000x4000000x2a9700x2a9705.41160x5R E0x10000.init .text .fini .rodata
                                            LOAD0x2b0000x46b0000x46b0000x580c0x9ef01.39580x6RW 0x10000.ctors .dtors .data.rel.ro .data .got .sbss .bss
                                            GNU_STACK0x00x00x00x00x00.00000x7RWE0x4
                                            TimestampSource PortDest PortSource IPDest IP
                                            Dec 27, 2024 18:47:46.164478064 CET43928443192.168.2.2391.189.91.42
                                            Dec 27, 2024 18:47:51.539736032 CET42836443192.168.2.2391.189.91.43
                                            Dec 27, 2024 18:47:53.075529099 CET4251680192.168.2.23109.202.202.202
                                            Dec 27, 2024 18:48:07.665458918 CET43928443192.168.2.2391.189.91.42
                                            Dec 27, 2024 18:48:17.904040098 CET42836443192.168.2.2391.189.91.43
                                            Dec 27, 2024 18:48:24.047418118 CET4251680192.168.2.23109.202.202.202
                                            Dec 27, 2024 18:48:48.619883060 CET43928443192.168.2.2391.189.91.42
                                            TimestampSource PortDest PortSource IPDest IP
                                            Dec 27, 2024 18:47:44.191565990 CET5207053192.168.2.23208.76.51.51
                                            Dec 27, 2024 18:47:49.197031021 CET4251453192.168.2.23208.76.51.51
                                            Dec 27, 2024 18:47:54.202186108 CET5417953192.168.2.23208.76.51.51
                                            Dec 27, 2024 18:47:59.218801975 CET3541353192.168.2.23208.76.51.51
                                            Dec 27, 2024 18:48:04.223937988 CET5055753192.168.2.23208.76.51.51
                                            Dec 27, 2024 18:48:14.227158070 CET3745953192.168.2.238.20.247.20
                                            Dec 27, 2024 18:48:14.473505974 CET53374598.20.247.20192.168.2.23
                                            Dec 27, 2024 18:48:14.475101948 CET3880853192.168.2.238.20.247.20
                                            Dec 27, 2024 18:48:14.729003906 CET53388088.20.247.20192.168.2.23
                                            Dec 27, 2024 18:48:14.729932070 CET3762853192.168.2.238.20.247.20
                                            Dec 27, 2024 18:48:14.976522923 CET53376288.20.247.20192.168.2.23
                                            Dec 27, 2024 18:48:14.977401018 CET3916153192.168.2.238.20.247.20
                                            Dec 27, 2024 18:48:15.234420061 CET53391618.20.247.20192.168.2.23
                                            Dec 27, 2024 18:48:15.235304117 CET5869353192.168.2.238.20.247.20
                                            Dec 27, 2024 18:48:15.478533983 CET53586938.20.247.20192.168.2.23
                                            Dec 27, 2024 18:48:20.480865002 CET4984653192.168.2.231.1.1.1
                                            Dec 27, 2024 18:48:20.952351093 CET53498461.1.1.1192.168.2.23
                                            Dec 27, 2024 18:48:20.954241037 CET4556853192.168.2.231.1.1.1
                                            Dec 27, 2024 18:48:21.094896078 CET53455681.1.1.1192.168.2.23
                                            Dec 27, 2024 18:48:21.096569061 CET4747053192.168.2.231.1.1.1
                                            Dec 27, 2024 18:48:21.237494946 CET53474701.1.1.1192.168.2.23
                                            Dec 27, 2024 18:48:21.239453077 CET3826853192.168.2.231.1.1.1
                                            Dec 27, 2024 18:48:21.379977942 CET53382681.1.1.1192.168.2.23
                                            Dec 27, 2024 18:48:21.381769896 CET3648953192.168.2.231.1.1.1
                                            Dec 27, 2024 18:48:21.520059109 CET53364891.1.1.1192.168.2.23
                                            Dec 27, 2024 18:48:26.522461891 CET4310253192.168.2.2351.77.149.139
                                            Dec 27, 2024 18:48:26.750080109 CET534310251.77.149.139192.168.2.23
                                            Dec 27, 2024 18:48:26.751873016 CET5121253192.168.2.2351.77.149.139
                                            Dec 27, 2024 18:48:26.979846001 CET535121251.77.149.139192.168.2.23
                                            Dec 27, 2024 18:48:26.981734037 CET4352153192.168.2.2351.77.149.139
                                            Dec 27, 2024 18:48:27.209012985 CET534352151.77.149.139192.168.2.23
                                            Dec 27, 2024 18:48:27.210788012 CET3591653192.168.2.2351.77.149.139
                                            Dec 27, 2024 18:48:27.450455904 CET533591651.77.149.139192.168.2.23
                                            Dec 27, 2024 18:48:27.452316999 CET3861953192.168.2.2351.77.149.139
                                            Dec 27, 2024 18:48:27.682179928 CET533861951.77.149.139192.168.2.23
                                            Dec 27, 2024 18:48:32.684890985 CET5035053192.168.2.23208.67.220.220
                                            Dec 27, 2024 18:48:33.002685070 CET5350350208.67.220.220192.168.2.23
                                            Dec 27, 2024 18:48:33.004285097 CET5214453192.168.2.23208.67.220.220
                                            Dec 27, 2024 18:48:33.218602896 CET5352144208.67.220.220192.168.2.23
                                            Dec 27, 2024 18:48:33.220170975 CET4814453192.168.2.23208.67.220.220
                                            Dec 27, 2024 18:48:33.340176105 CET5348144208.67.220.220192.168.2.23
                                            Dec 27, 2024 18:48:33.341546059 CET3671153192.168.2.23208.67.220.220
                                            Dec 27, 2024 18:48:33.462452888 CET5336711208.67.220.220192.168.2.23
                                            Dec 27, 2024 18:48:33.464293003 CET5093053192.168.2.23208.67.220.220
                                            Dec 27, 2024 18:48:33.584984064 CET5350930208.67.220.220192.168.2.23
                                            Dec 27, 2024 18:48:38.587393999 CET3588553192.168.2.23194.36.144.87
                                            Dec 27, 2024 18:48:38.826987028 CET5335885194.36.144.87192.168.2.23
                                            Dec 27, 2024 18:48:38.827961922 CET5698253192.168.2.23194.36.144.87
                                            Dec 27, 2024 18:48:39.075525999 CET5356982194.36.144.87192.168.2.23
                                            Dec 27, 2024 18:48:39.076627970 CET4690153192.168.2.23194.36.144.87
                                            Dec 27, 2024 18:48:39.316663027 CET5346901194.36.144.87192.168.2.23
                                            Dec 27, 2024 18:48:39.317714930 CET5141553192.168.2.23194.36.144.87
                                            Dec 27, 2024 18:48:39.561625957 CET5351415194.36.144.87192.168.2.23
                                            Dec 27, 2024 18:48:39.562588930 CET4451153192.168.2.23194.36.144.87
                                            Dec 27, 2024 18:48:39.815504074 CET5344511194.36.144.87192.168.2.23
                                            Dec 27, 2024 18:48:44.817899942 CET5397153192.168.2.23208.76.50.50
                                            Dec 27, 2024 18:48:49.824016094 CET3547753192.168.2.23208.76.50.50
                                            Dec 27, 2024 18:48:54.829801083 CET3378153192.168.2.23208.76.50.50
                                            Dec 27, 2024 18:48:59.835325003 CET5398153192.168.2.23208.76.50.50
                                            Dec 27, 2024 18:49:04.840910912 CET3962753192.168.2.23208.76.50.50
                                            Dec 27, 2024 18:49:14.848197937 CET5196553192.168.2.238.26.56.26
                                            Dec 27, 2024 18:49:15.096733093 CET53519658.26.56.26192.168.2.23
                                            Dec 27, 2024 18:49:15.098273039 CET5402953192.168.2.238.26.56.26
                                            Dec 27, 2024 18:49:15.343915939 CET53540298.26.56.26192.168.2.23
                                            Dec 27, 2024 18:49:15.345370054 CET4698953192.168.2.238.26.56.26
                                            Dec 27, 2024 18:49:15.592367887 CET53469898.26.56.26192.168.2.23
                                            Dec 27, 2024 18:49:15.593966007 CET3418553192.168.2.238.26.56.26
                                            Dec 27, 2024 18:49:15.845223904 CET53341858.26.56.26192.168.2.23
                                            Dec 27, 2024 18:49:15.846981049 CET3298653192.168.2.238.26.56.26
                                            Dec 27, 2024 18:49:16.094880104 CET53329868.26.56.26192.168.2.23
                                            Dec 27, 2024 18:49:21.097295046 CET3340353192.168.2.23208.76.51.51
                                            Dec 27, 2024 18:49:26.103322029 CET3837953192.168.2.23208.76.51.51
                                            Dec 27, 2024 18:49:31.109258890 CET4046053192.168.2.23208.76.51.51
                                            Dec 27, 2024 18:49:36.115101099 CET4011253192.168.2.23208.76.51.51
                                            Dec 27, 2024 18:49:41.121179104 CET5879853192.168.2.23208.76.51.51
                                            TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                            Dec 27, 2024 18:47:44.191565990 CET192.168.2.23208.76.51.510x55e6Standard query (0)dns.stresse.proA (IP address)IN (0x0001)false
                                            Dec 27, 2024 18:47:49.197031021 CET192.168.2.23208.76.51.510x55e6Standard query (0)dns.stresse.proA (IP address)IN (0x0001)false
                                            Dec 27, 2024 18:47:54.202186108 CET192.168.2.23208.76.51.510x55e6Standard query (0)dns.stresse.proA (IP address)IN (0x0001)false
                                            Dec 27, 2024 18:47:59.218801975 CET192.168.2.23208.76.51.510x55e6Standard query (0)dns.stresse.proA (IP address)IN (0x0001)false
                                            Dec 27, 2024 18:48:04.223937988 CET192.168.2.23208.76.51.510x55e6Standard query (0)dns.stresse.proA (IP address)IN (0x0001)false
                                            Dec 27, 2024 18:48:14.227158070 CET192.168.2.238.20.247.200xbf02Standard query (0)dns.stresse.proA (IP address)IN (0x0001)false
                                            Dec 27, 2024 18:48:14.475101948 CET192.168.2.238.20.247.200xbf02Standard query (0)dns.stresse.proA (IP address)IN (0x0001)false
                                            Dec 27, 2024 18:48:14.729932070 CET192.168.2.238.20.247.200xbf02Standard query (0)dns.stresse.proA (IP address)IN (0x0001)false
                                            Dec 27, 2024 18:48:14.977401018 CET192.168.2.238.20.247.200xbf02Standard query (0)dns.stresse.proA (IP address)IN (0x0001)false
                                            Dec 27, 2024 18:48:15.235304117 CET192.168.2.238.20.247.200xbf02Standard query (0)dns.stresse.proA (IP address)IN (0x0001)false
                                            Dec 27, 2024 18:48:20.480865002 CET192.168.2.231.1.1.10x24d0Standard query (0)dns.stresse.proA (IP address)IN (0x0001)false
                                            Dec 27, 2024 18:48:20.954241037 CET192.168.2.231.1.1.10x24d0Standard query (0)dns.stresse.proA (IP address)IN (0x0001)false
                                            Dec 27, 2024 18:48:21.096569061 CET192.168.2.231.1.1.10x24d0Standard query (0)dns.stresse.proA (IP address)IN (0x0001)false
                                            Dec 27, 2024 18:48:21.239453077 CET192.168.2.231.1.1.10x24d0Standard query (0)dns.stresse.proA (IP address)IN (0x0001)false
                                            Dec 27, 2024 18:48:21.381769896 CET192.168.2.231.1.1.10x24d0Standard query (0)dns.stresse.proA (IP address)IN (0x0001)false
                                            Dec 27, 2024 18:48:26.522461891 CET192.168.2.2351.77.149.1390xebd8Standard query (0)dns.stresse.proA (IP address)IN (0x0001)false
                                            Dec 27, 2024 18:48:26.751873016 CET192.168.2.2351.77.149.1390xebd8Standard query (0)dns.stresse.proA (IP address)IN (0x0001)false
                                            Dec 27, 2024 18:48:26.981734037 CET192.168.2.2351.77.149.1390xebd8Standard query (0)dns.stresse.proA (IP address)IN (0x0001)false
                                            Dec 27, 2024 18:48:27.210788012 CET192.168.2.2351.77.149.1390xebd8Standard query (0)dns.stresse.proA (IP address)IN (0x0001)false
                                            Dec 27, 2024 18:48:27.452316999 CET192.168.2.2351.77.149.1390xebd8Standard query (0)dns.stresse.proA (IP address)IN (0x0001)false
                                            Dec 27, 2024 18:48:32.684890985 CET192.168.2.23208.67.220.2200xd080Standard query (0)dns.stresse.proA (IP address)IN (0x0001)false
                                            Dec 27, 2024 18:48:33.004285097 CET192.168.2.23208.67.220.2200xd080Standard query (0)dns.stresse.proA (IP address)IN (0x0001)false
                                            Dec 27, 2024 18:48:33.220170975 CET192.168.2.23208.67.220.2200xd080Standard query (0)dns.stresse.proA (IP address)IN (0x0001)false
                                            Dec 27, 2024 18:48:33.341546059 CET192.168.2.23208.67.220.2200xd080Standard query (0)dns.stresse.proA (IP address)IN (0x0001)false
                                            Dec 27, 2024 18:48:33.464293003 CET192.168.2.23208.67.220.2200xd080Standard query (0)dns.stresse.proA (IP address)IN (0x0001)false
                                            Dec 27, 2024 18:48:38.587393999 CET192.168.2.23194.36.144.870xcb6fStandard query (0)dns.stresse.proA (IP address)IN (0x0001)false
                                            Dec 27, 2024 18:48:38.827961922 CET192.168.2.23194.36.144.870xcb6fStandard query (0)dns.stresse.proA (IP address)IN (0x0001)false
                                            Dec 27, 2024 18:48:39.076627970 CET192.168.2.23194.36.144.870xcb6fStandard query (0)dns.stresse.proA (IP address)IN (0x0001)false
                                            Dec 27, 2024 18:48:39.317714930 CET192.168.2.23194.36.144.870xcb6fStandard query (0)dns.stresse.proA (IP address)IN (0x0001)false
                                            Dec 27, 2024 18:48:39.562588930 CET192.168.2.23194.36.144.870xcb6fStandard query (0)dns.stresse.proA (IP address)IN (0x0001)false
                                            Dec 27, 2024 18:48:44.817899942 CET192.168.2.23208.76.50.500x61dcStandard query (0)dns.stresse.proA (IP address)IN (0x0001)false
                                            Dec 27, 2024 18:48:49.824016094 CET192.168.2.23208.76.50.500x61dcStandard query (0)dns.stresse.proA (IP address)IN (0x0001)false
                                            Dec 27, 2024 18:48:54.829801083 CET192.168.2.23208.76.50.500x61dcStandard query (0)dns.stresse.proA (IP address)IN (0x0001)false
                                            Dec 27, 2024 18:48:59.835325003 CET192.168.2.23208.76.50.500x61dcStandard query (0)dns.stresse.proA (IP address)IN (0x0001)false
                                            Dec 27, 2024 18:49:04.840910912 CET192.168.2.23208.76.50.500x61dcStandard query (0)dns.stresse.proA (IP address)IN (0x0001)false
                                            Dec 27, 2024 18:49:14.848197937 CET192.168.2.238.26.56.260x2e9fStandard query (0)dns.stresse.proA (IP address)IN (0x0001)false
                                            Dec 27, 2024 18:49:15.098273039 CET192.168.2.238.26.56.260x2e9fStandard query (0)dns.stresse.proA (IP address)IN (0x0001)false
                                            Dec 27, 2024 18:49:15.345370054 CET192.168.2.238.26.56.260x2e9fStandard query (0)dns.stresse.proA (IP address)IN (0x0001)false
                                            Dec 27, 2024 18:49:15.593966007 CET192.168.2.238.26.56.260x2e9fStandard query (0)dns.stresse.proA (IP address)IN (0x0001)false
                                            Dec 27, 2024 18:49:15.846981049 CET192.168.2.238.26.56.260x2e9fStandard query (0)dns.stresse.proA (IP address)IN (0x0001)false
                                            Dec 27, 2024 18:49:21.097295046 CET192.168.2.23208.76.51.510xeca2Standard query (0)dns.stresse.proA (IP address)IN (0x0001)false
                                            Dec 27, 2024 18:49:26.103322029 CET192.168.2.23208.76.51.510xeca2Standard query (0)dns.stresse.proA (IP address)IN (0x0001)false
                                            Dec 27, 2024 18:49:31.109258890 CET192.168.2.23208.76.51.510xeca2Standard query (0)dns.stresse.proA (IP address)IN (0x0001)false
                                            Dec 27, 2024 18:49:36.115101099 CET192.168.2.23208.76.51.510xeca2Standard query (0)dns.stresse.proA (IP address)IN (0x0001)false
                                            Dec 27, 2024 18:49:41.121179104 CET192.168.2.23208.76.51.510xeca2Standard query (0)dns.stresse.proA (IP address)IN (0x0001)false
                                            TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                            Dec 27, 2024 18:48:14.473505974 CET8.20.247.20192.168.2.230xbf02Name error (3)dns.stresse.prononenoneA (IP address)IN (0x0001)false
                                            Dec 27, 2024 18:48:14.729003906 CET8.20.247.20192.168.2.230xbf02Name error (3)dns.stresse.prononenoneA (IP address)IN (0x0001)false
                                            Dec 27, 2024 18:48:14.976522923 CET8.20.247.20192.168.2.230xbf02Name error (3)dns.stresse.prononenoneA (IP address)IN (0x0001)false
                                            Dec 27, 2024 18:48:15.234420061 CET8.20.247.20192.168.2.230xbf02Name error (3)dns.stresse.prononenoneA (IP address)IN (0x0001)false
                                            Dec 27, 2024 18:48:15.478533983 CET8.20.247.20192.168.2.230xbf02Name error (3)dns.stresse.prononenoneA (IP address)IN (0x0001)false
                                            Dec 27, 2024 18:48:20.952351093 CET1.1.1.1192.168.2.230x24d0Name error (3)dns.stresse.prononenoneA (IP address)IN (0x0001)false
                                            Dec 27, 2024 18:48:21.094896078 CET1.1.1.1192.168.2.230x24d0Name error (3)dns.stresse.prononenoneA (IP address)IN (0x0001)false
                                            Dec 27, 2024 18:48:21.237494946 CET1.1.1.1192.168.2.230x24d0Name error (3)dns.stresse.prononenoneA (IP address)IN (0x0001)false
                                            Dec 27, 2024 18:48:21.379977942 CET1.1.1.1192.168.2.230x24d0Name error (3)dns.stresse.prononenoneA (IP address)IN (0x0001)false
                                            Dec 27, 2024 18:48:21.520059109 CET1.1.1.1192.168.2.230x24d0Name error (3)dns.stresse.prononenoneA (IP address)IN (0x0001)false
                                            Dec 27, 2024 18:48:26.750080109 CET51.77.149.139192.168.2.230xebd8Name error (3)dns.stresse.prononenoneA (IP address)IN (0x0001)false
                                            Dec 27, 2024 18:48:26.979846001 CET51.77.149.139192.168.2.230xebd8Name error (3)dns.stresse.prononenoneA (IP address)IN (0x0001)false
                                            Dec 27, 2024 18:48:27.209012985 CET51.77.149.139192.168.2.230xebd8Name error (3)dns.stresse.prononenoneA (IP address)IN (0x0001)false
                                            Dec 27, 2024 18:48:27.450455904 CET51.77.149.139192.168.2.230xebd8Name error (3)dns.stresse.prononenoneA (IP address)IN (0x0001)false
                                            Dec 27, 2024 18:48:27.682179928 CET51.77.149.139192.168.2.230xebd8Name error (3)dns.stresse.prononenoneA (IP address)IN (0x0001)false
                                            Dec 27, 2024 18:48:33.002685070 CET208.67.220.220192.168.2.230xd080Name error (3)dns.stresse.prononenoneA (IP address)IN (0x0001)false
                                            Dec 27, 2024 18:48:33.218602896 CET208.67.220.220192.168.2.230xd080Name error (3)dns.stresse.prononenoneA (IP address)IN (0x0001)false
                                            Dec 27, 2024 18:48:33.340176105 CET208.67.220.220192.168.2.230xd080Name error (3)dns.stresse.prononenoneA (IP address)IN (0x0001)false
                                            Dec 27, 2024 18:48:33.462452888 CET208.67.220.220192.168.2.230xd080Name error (3)dns.stresse.prononenoneA (IP address)IN (0x0001)false
                                            Dec 27, 2024 18:48:33.584984064 CET208.67.220.220192.168.2.230xd080Name error (3)dns.stresse.prononenoneA (IP address)IN (0x0001)false
                                            Dec 27, 2024 18:48:38.826987028 CET194.36.144.87192.168.2.230xcb6fName error (3)dns.stresse.prononenoneA (IP address)IN (0x0001)false
                                            Dec 27, 2024 18:48:39.075525999 CET194.36.144.87192.168.2.230xcb6fName error (3)dns.stresse.prononenoneA (IP address)IN (0x0001)false
                                            Dec 27, 2024 18:48:39.316663027 CET194.36.144.87192.168.2.230xcb6fName error (3)dns.stresse.prononenoneA (IP address)IN (0x0001)false
                                            Dec 27, 2024 18:48:39.561625957 CET194.36.144.87192.168.2.230xcb6fName error (3)dns.stresse.prononenoneA (IP address)IN (0x0001)false
                                            Dec 27, 2024 18:48:39.815504074 CET194.36.144.87192.168.2.230xcb6fName error (3)dns.stresse.prononenoneA (IP address)IN (0x0001)false
                                            Dec 27, 2024 18:49:15.096733093 CET8.26.56.26192.168.2.230x2e9fName error (3)dns.stresse.prononenoneA (IP address)IN (0x0001)false
                                            Dec 27, 2024 18:49:15.343915939 CET8.26.56.26192.168.2.230x2e9fName error (3)dns.stresse.prononenoneA (IP address)IN (0x0001)false
                                            Dec 27, 2024 18:49:15.592367887 CET8.26.56.26192.168.2.230x2e9fName error (3)dns.stresse.prononenoneA (IP address)IN (0x0001)false
                                            Dec 27, 2024 18:49:15.845223904 CET8.26.56.26192.168.2.230x2e9fName error (3)dns.stresse.prononenoneA (IP address)IN (0x0001)false
                                            Dec 27, 2024 18:49:16.094880104 CET8.26.56.26192.168.2.230x2e9fName error (3)dns.stresse.prononenoneA (IP address)IN (0x0001)false

                                            System Behavior

                                            Start time (UTC):17:47:43
                                            Start date (UTC):27/12/2024
                                            Path:/tmp/mips.elf
                                            Arguments:/tmp/mips.elf
                                            File size:5777432 bytes
                                            MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                                            Start time (UTC):17:47:43
                                            Start date (UTC):27/12/2024
                                            Path:/tmp/mips.elf
                                            Arguments:-
                                            File size:5777432 bytes
                                            MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                                            Start time (UTC):17:47:43
                                            Start date (UTC):27/12/2024
                                            Path:/tmp/mips.elf
                                            Arguments:-
                                            File size:5777432 bytes
                                            MD5 hash:0083f1f0e77be34ad27f849842bbb00c