Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
mpsl.elf

Overview

General Information

Sample name:mpsl.elf
Analysis ID:1581478
MD5:1486509aaee4935fead5397140adc696
SHA1:ca896bcb122acc0ce35cc9abb876cf102e2b4cca
SHA256:2e9958508e56357ca8d0e43bf843a93df3c315d229cb1c4d82261876c90e7afa
Tags:elfuser-abuse_ch
Infos:

Detection

Score:48
Range:0 - 100
Whitelisted:false

Signatures

Multi AV Scanner detection for submitted file
Sample has stripped symbol table
Sample listens on a socket
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Tries to resolve domain names, but no domain seems valid (expired dropper behavior)
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1581478
Start date and time:2024-12-27 21:07:06 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 29s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:mpsl.elf
Detection:MAL
Classification:mal48.linELF@0/0@41/0
  • VT rate limit hit for: mpsl.elf
Command:/tmp/mpsl.elf
PID:6234
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
[INFO] Project @RebirthLTD (06-01-2024)
Standard Error:
  • system is lnxubuntu20
  • mpsl.elf (PID: 6234, Parent: 6158, MD5: 0d6f61f82cf2f781c6eb0661071d42d9) Arguments: /tmp/mpsl.elf
    • mpsl.elf New Fork (PID: 6236, Parent: 6234)
      • mpsl.elf New Fork (PID: 6238, Parent: 6236)
  • cleanup
No yara matches
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: mpsl.elfReversingLabs: Detection: 21%
Source: /tmp/mpsl.elf (PID: 6234)Socket: 127.0.0.1:13291Jump to behavior
Source: global trafficTCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
Source: global trafficTCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
Source: global trafficTCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
Source: unknownDNS traffic detected: query: dns.stresse.pro replaycode: Name error (3)
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownUDP traffic detected without corresponding DNS query: 51.77.149.139
Source: unknownUDP traffic detected without corresponding DNS query: 51.77.149.139
Source: unknownUDP traffic detected without corresponding DNS query: 51.77.149.139
Source: unknownUDP traffic detected without corresponding DNS query: 51.77.149.139
Source: unknownUDP traffic detected without corresponding DNS query: 51.77.149.139
Source: unknownUDP traffic detected without corresponding DNS query: 208.76.51.51
Source: unknownUDP traffic detected without corresponding DNS query: 208.76.51.51
Source: unknownUDP traffic detected without corresponding DNS query: 208.76.51.51
Source: unknownUDP traffic detected without corresponding DNS query: 208.76.51.51
Source: unknownUDP traffic detected without corresponding DNS query: 208.76.51.51
Source: unknownUDP traffic detected without corresponding DNS query: 8.26.56.26
Source: unknownUDP traffic detected without corresponding DNS query: 8.26.56.26
Source: unknownUDP traffic detected without corresponding DNS query: 8.26.56.26
Source: unknownUDP traffic detected without corresponding DNS query: 8.26.56.26
Source: unknownUDP traffic detected without corresponding DNS query: 8.26.56.26
Source: unknownUDP traffic detected without corresponding DNS query: 208.76.50.50
Source: unknownUDP traffic detected without corresponding DNS query: 208.76.50.50
Source: unknownUDP traffic detected without corresponding DNS query: 208.76.50.50
Source: unknownUDP traffic detected without corresponding DNS query: 208.76.50.50
Source: unknownUDP traffic detected without corresponding DNS query: 208.76.50.50
Source: unknownUDP traffic detected without corresponding DNS query: 208.76.51.51
Source: unknownUDP traffic detected without corresponding DNS query: 208.76.51.51
Source: unknownUDP traffic detected without corresponding DNS query: 208.76.51.51
Source: unknownUDP traffic detected without corresponding DNS query: 208.76.51.51
Source: unknownUDP traffic detected without corresponding DNS query: 208.76.51.51
Source: unknownUDP traffic detected without corresponding DNS query: 194.36.144.87
Source: unknownUDP traffic detected without corresponding DNS query: 194.36.144.87
Source: unknownUDP traffic detected without corresponding DNS query: 194.36.144.87
Source: unknownUDP traffic detected without corresponding DNS query: 194.36.144.87
Source: unknownUDP traffic detected without corresponding DNS query: 194.36.144.87
Source: unknownUDP traffic detected without corresponding DNS query: 194.36.144.87
Source: unknownUDP traffic detected without corresponding DNS query: 194.36.144.87
Source: unknownUDP traffic detected without corresponding DNS query: 194.36.144.87
Source: unknownUDP traffic detected without corresponding DNS query: 194.36.144.87
Source: unknownUDP traffic detected without corresponding DNS query: 194.36.144.87
Source: unknownUDP traffic detected without corresponding DNS query: 208.76.50.50
Source: global trafficDNS traffic detected: DNS query: dns.stresse.pro
Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443
Source: ELF static info symbol of initial sample.symtab present: no
Source: classification engineClassification label: mal48.linELF@0/0@41/0
Source: /tmp/mpsl.elf (PID: 6234)Queries kernel information via 'uname': Jump to behavior
Source: mpsl.elf, 6234.1.0000560424ae6000.0000560424b90000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/mipsel
Source: mpsl.elf, 6234.1.0000560424ae6000.0000560424b90000.rw-.sdmpBinary or memory string: V!/etc/qemu-binfmt/mipsel
Source: mpsl.elf, 6234.1.00007ffc99b81000.00007ffc99ba2000.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-mipsel/tmp/mpsl.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/mpsl.elf
Source: mpsl.elf, 6234.1.00007ffc99b81000.00007ffc99ba2000.rw-.sdmpBinary or memory string: /usr/bin/qemu-mipsel
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath InterceptionDirect Volume AccessOS Credential Dumping11
Security Software Discovery
Remote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive2
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1581478 Sample: mpsl.elf Startdate: 27/12/2024 Architecture: LINUX Score: 48 14 109.202.202.202, 80 INIT7CH Switzerland 2->14 16 91.189.91.42, 443 CANONICAL-ASGB United Kingdom 2->16 18 2 other IPs or domains 2->18 20 Multi AV Scanner detection for submitted file 2->20 8 mpsl.elf 2->8         started        signatures3 process4 process5 10 mpsl.elf 8->10         started        process6 12 mpsl.elf 10->12         started       
SourceDetectionScannerLabelLink
mpsl.elf21%ReversingLabsLinux.Backdoor.Mirai
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
dns.stresse.pro
unknown
unknownfalse
    unknown
    • No. of IPs < 25%
    • 25% < No. of IPs < 50%
    • 50% < No. of IPs < 75%
    • 75% < No. of IPs
    IPDomainCountryFlagASNASN NameMalicious
    109.202.202.202
    unknownSwitzerland
    13030INIT7CHfalse
    91.189.91.43
    unknownUnited Kingdom
    41231CANONICAL-ASGBfalse
    91.189.91.42
    unknownUnited Kingdom
    41231CANONICAL-ASGBfalse
    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
    109.202.202.202kpLwzBouH4.elfGet hashmaliciousUnknownBrowse
    • ch.archive.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_92.0%2bbuild3-0ubuntu0.20.04.1_amd64.deb
    91.189.91.43https://greensofttech1-my.sharepoint.com/:f:/g/personal/stella_huang_greensofttech1_onmicrosoft_com/EuOSopXBEUpFhaHAwqFRDM8BeWLY-Gsl0U9Az2fOy4x80A?e=GhPegT&xsdata=MDV8MDJ8TVB1Z2FAaHljaXRlLmNvbXxjMDM5NmJhZjcxOTM0YzBkMTc3ZDA4ZGQxMzcwNWQ3MnxmYzVjNjhmNjk3ZjM0ZWZlYjY4OWViNWMxMjM0ZjgyMXwwfDB8NjM4Njg4MDk1NTQ0NTA0NzA2fFVua25vd258VFdGcGJHWnNiM2Q4ZXlKRmJYQjBlVTFoY0draU9uUnlkV1VzSWxZaU9pSXdMakF1TURBd01DSXNJbEFpT2lKWGFXNHpNaUlzSWtGT0lqb2lUV0ZwYkNJc0lsZFVJam95ZlE9PXwwfHx8&sdata=SVpsejJNYUlwY213VjNreGxSNU1LaFJXcnpXS3pwWjhYR2k5ZUthLzlsMD0%3dGet hashmaliciousHTMLPhisherBrowse
      Electrum-bch-4.4.2-x86_64.AppImage.elfGet hashmaliciousUnknownBrowse
        mips.elfGet hashmaliciousUnknownBrowse
          mips.elfGet hashmaliciousUnknownBrowse
            byte.mpsl.elfGet hashmaliciousMirai, OkiruBrowse
              dlr.arm.elfGet hashmaliciousUnknownBrowse
                byte.mpsl.elfGet hashmaliciousMirai, OkiruBrowse
                  byte.ppc.elfGet hashmaliciousMirai, OkiruBrowse
                    llklllklld.x86.elfGet hashmaliciousMirai, OkiruBrowse
                      .i.elfGet hashmaliciousUnknownBrowse
                        91.189.91.42https://greensofttech1-my.sharepoint.com/:f:/g/personal/stella_huang_greensofttech1_onmicrosoft_com/EuOSopXBEUpFhaHAwqFRDM8BeWLY-Gsl0U9Az2fOy4x80A?e=GhPegT&xsdata=MDV8MDJ8TVB1Z2FAaHljaXRlLmNvbXxjMDM5NmJhZjcxOTM0YzBkMTc3ZDA4ZGQxMzcwNWQ3MnxmYzVjNjhmNjk3ZjM0ZWZlYjY4OWViNWMxMjM0ZjgyMXwwfDB8NjM4Njg4MDk1NTQ0NTA0NzA2fFVua25vd258VFdGcGJHWnNiM2Q4ZXlKRmJYQjBlVTFoY0draU9uUnlkV1VzSWxZaU9pSXdMakF1TURBd01DSXNJbEFpT2lKWGFXNHpNaUlzSWtGT0lqb2lUV0ZwYkNJc0lsZFVJam95ZlE9PXwwfHx8&sdata=SVpsejJNYUlwY213VjNreGxSNU1LaFJXcnpXS3pwWjhYR2k5ZUthLzlsMD0%3dGet hashmaliciousHTMLPhisherBrowse
                          Electrum-bch-4.4.2-x86_64.AppImage.elfGet hashmaliciousUnknownBrowse
                            mips.elfGet hashmaliciousUnknownBrowse
                              mips.elfGet hashmaliciousUnknownBrowse
                                byte.mpsl.elfGet hashmaliciousMirai, OkiruBrowse
                                  dlr.arm.elfGet hashmaliciousUnknownBrowse
                                    byte.mpsl.elfGet hashmaliciousMirai, OkiruBrowse
                                      byte.ppc.elfGet hashmaliciousMirai, OkiruBrowse
                                        llklllklld.x86.elfGet hashmaliciousMirai, OkiruBrowse
                                          .i.elfGet hashmaliciousUnknownBrowse
                                            No context
                                            MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                            CANONICAL-ASGBhttps://greensofttech1-my.sharepoint.com/:f:/g/personal/stella_huang_greensofttech1_onmicrosoft_com/EuOSopXBEUpFhaHAwqFRDM8BeWLY-Gsl0U9Az2fOy4x80A?e=GhPegT&xsdata=MDV8MDJ8TVB1Z2FAaHljaXRlLmNvbXxjMDM5NmJhZjcxOTM0YzBkMTc3ZDA4ZGQxMzcwNWQ3MnxmYzVjNjhmNjk3ZjM0ZWZlYjY4OWViNWMxMjM0ZjgyMXwwfDB8NjM4Njg4MDk1NTQ0NTA0NzA2fFVua25vd258VFdGcGJHWnNiM2Q4ZXlKRmJYQjBlVTFoY0draU9uUnlkV1VzSWxZaU9pSXdMakF1TURBd01DSXNJbEFpT2lKWGFXNHpNaUlzSWtGT0lqb2lUV0ZwYkNJc0lsZFVJam95ZlE9PXwwfHx8&sdata=SVpsejJNYUlwY213VjNreGxSNU1LaFJXcnpXS3pwWjhYR2k5ZUthLzlsMD0%3dGet hashmaliciousHTMLPhisherBrowse
                                            • 91.189.91.42
                                            Electrum-bch-4.4.2-x86_64.AppImage.elfGet hashmaliciousUnknownBrowse
                                            • 91.189.91.42
                                            mips.elfGet hashmaliciousUnknownBrowse
                                            • 91.189.91.42
                                            mips.elfGet hashmaliciousUnknownBrowse
                                            • 91.189.91.42
                                            byte.mpsl.elfGet hashmaliciousMirai, OkiruBrowse
                                            • 91.189.91.42
                                            drp.x86.elfGet hashmaliciousMirai, OkiruBrowse
                                            • 185.125.190.26
                                            dlr.arm.elfGet hashmaliciousUnknownBrowse
                                            • 91.189.91.42
                                            byte.mpsl.elfGet hashmaliciousMirai, OkiruBrowse
                                            • 91.189.91.42
                                            byte.ppc.elfGet hashmaliciousMirai, OkiruBrowse
                                            • 91.189.91.42
                                            llklllklld.x86.elfGet hashmaliciousMirai, OkiruBrowse
                                            • 91.189.91.42
                                            CANONICAL-ASGBhttps://greensofttech1-my.sharepoint.com/:f:/g/personal/stella_huang_greensofttech1_onmicrosoft_com/EuOSopXBEUpFhaHAwqFRDM8BeWLY-Gsl0U9Az2fOy4x80A?e=GhPegT&xsdata=MDV8MDJ8TVB1Z2FAaHljaXRlLmNvbXxjMDM5NmJhZjcxOTM0YzBkMTc3ZDA4ZGQxMzcwNWQ3MnxmYzVjNjhmNjk3ZjM0ZWZlYjY4OWViNWMxMjM0ZjgyMXwwfDB8NjM4Njg4MDk1NTQ0NTA0NzA2fFVua25vd258VFdGcGJHWnNiM2Q4ZXlKRmJYQjBlVTFoY0draU9uUnlkV1VzSWxZaU9pSXdMakF1TURBd01DSXNJbEFpT2lKWGFXNHpNaUlzSWtGT0lqb2lUV0ZwYkNJc0lsZFVJam95ZlE9PXwwfHx8&sdata=SVpsejJNYUlwY213VjNreGxSNU1LaFJXcnpXS3pwWjhYR2k5ZUthLzlsMD0%3dGet hashmaliciousHTMLPhisherBrowse
                                            • 91.189.91.42
                                            Electrum-bch-4.4.2-x86_64.AppImage.elfGet hashmaliciousUnknownBrowse
                                            • 91.189.91.42
                                            mips.elfGet hashmaliciousUnknownBrowse
                                            • 91.189.91.42
                                            mips.elfGet hashmaliciousUnknownBrowse
                                            • 91.189.91.42
                                            byte.mpsl.elfGet hashmaliciousMirai, OkiruBrowse
                                            • 91.189.91.42
                                            drp.x86.elfGet hashmaliciousMirai, OkiruBrowse
                                            • 185.125.190.26
                                            dlr.arm.elfGet hashmaliciousUnknownBrowse
                                            • 91.189.91.42
                                            byte.mpsl.elfGet hashmaliciousMirai, OkiruBrowse
                                            • 91.189.91.42
                                            byte.ppc.elfGet hashmaliciousMirai, OkiruBrowse
                                            • 91.189.91.42
                                            llklllklld.x86.elfGet hashmaliciousMirai, OkiruBrowse
                                            • 91.189.91.42
                                            INIT7CHhttps://greensofttech1-my.sharepoint.com/:f:/g/personal/stella_huang_greensofttech1_onmicrosoft_com/EuOSopXBEUpFhaHAwqFRDM8BeWLY-Gsl0U9Az2fOy4x80A?e=GhPegT&xsdata=MDV8MDJ8TVB1Z2FAaHljaXRlLmNvbXxjMDM5NmJhZjcxOTM0YzBkMTc3ZDA4ZGQxMzcwNWQ3MnxmYzVjNjhmNjk3ZjM0ZWZlYjY4OWViNWMxMjM0ZjgyMXwwfDB8NjM4Njg4MDk1NTQ0NTA0NzA2fFVua25vd258VFdGcGJHWnNiM2Q4ZXlKRmJYQjBlVTFoY0draU9uUnlkV1VzSWxZaU9pSXdMakF1TURBd01DSXNJbEFpT2lKWGFXNHpNaUlzSWtGT0lqb2lUV0ZwYkNJc0lsZFVJam95ZlE9PXwwfHx8&sdata=SVpsejJNYUlwY213VjNreGxSNU1LaFJXcnpXS3pwWjhYR2k5ZUthLzlsMD0%3dGet hashmaliciousHTMLPhisherBrowse
                                            • 109.202.202.202
                                            Electrum-bch-4.4.2-x86_64.AppImage.elfGet hashmaliciousUnknownBrowse
                                            • 109.202.202.202
                                            mips.elfGet hashmaliciousUnknownBrowse
                                            • 109.202.202.202
                                            mips.elfGet hashmaliciousUnknownBrowse
                                            • 109.202.202.202
                                            byte.mpsl.elfGet hashmaliciousMirai, OkiruBrowse
                                            • 109.202.202.202
                                            dlr.arm.elfGet hashmaliciousUnknownBrowse
                                            • 109.202.202.202
                                            byte.mpsl.elfGet hashmaliciousMirai, OkiruBrowse
                                            • 109.202.202.202
                                            byte.ppc.elfGet hashmaliciousMirai, OkiruBrowse
                                            • 109.202.202.202
                                            llklllklld.x86.elfGet hashmaliciousMirai, OkiruBrowse
                                            • 109.202.202.202
                                            .i.elfGet hashmaliciousUnknownBrowse
                                            • 109.202.202.202
                                            No context
                                            No context
                                            No created / dropped files found
                                            File type:ELF 32-bit LSB executable, MIPS, MIPS-I version 1 (SYSV), statically linked, stripped
                                            Entropy (8bit):5.046220257894713
                                            TrID:
                                            • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                                            File name:mpsl.elf
                                            File size:203'424 bytes
                                            MD5:1486509aaee4935fead5397140adc696
                                            SHA1:ca896bcb122acc0ce35cc9abb876cf102e2b4cca
                                            SHA256:2e9958508e56357ca8d0e43bf843a93df3c315d229cb1c4d82261876c90e7afa
                                            SHA512:04c85892b1cd903b706e56246203133a4ddf01ba5ef4ef94d3b9c59a80d72dc92dd590341e9cf78a5ddf3786880bd4b8d680973044c90cd09288520d662d4e78
                                            SSDEEP:3072:d7IhOzVDmMUe5/qAHNSRDMYRj7QQoRgBMFjY:dlzVBUezNWMI3QzMuj
                                            TLSH:0B14C709AF550FFBD86FDE3702E90B0529CCA51722A43B3A3674D528F54A94F49E3C68
                                            File Content Preview:.ELF....................`.@.4...p.......4. ...(...............@...@...........................F...F..X..............Q.td...............................<\..'!......'.......................<8..'!... .........9'.. ........................<...'!.............9

                                            ELF header

                                            Class:ELF32
                                            Data:2's complement, little endian
                                            Version:1 (current)
                                            Machine:MIPS R3000
                                            Version Number:0x1
                                            Type:EXEC (Executable file)
                                            OS/ABI:UNIX - System V
                                            ABI Version:0
                                            Entry Point Address:0x400260
                                            Flags:0x1007
                                            ELF Header Size:52
                                            Program Header Offset:52
                                            Program Header Size:32
                                            Number of Program Headers:3
                                            Section Header Offset:202864
                                            Section Header Size:40
                                            Number of Section Headers:14
                                            Header String Table Index:13
                                            NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                            NULL0x00x00x00x00x0000
                                            .initPROGBITS0x4000940x940x8c0x00x6AX004
                                            .textPROGBITS0x4001200x1200x28ed00x00x6AX0016
                                            .finiPROGBITS0x428ff00x28ff00x5c0x00x6AX004
                                            .rodataPROGBITS0x4290500x290500x25300x00x2A0016
                                            .ctorsPROGBITS0x46c0000x2c0000xc0x00x3WA004
                                            .dtorsPROGBITS0x46c00c0x2c00c0x80x00x3WA004
                                            .data.rel.roPROGBITS0x46c0180x2c0180x4bc0x00x3WA004
                                            .dataPROGBITS0x46c4e00x2c4e00x49200x00x3WA0032
                                            .gotPROGBITS0x470e000x30e000xa0c0x40x10000003WAp0016
                                            .sbssNOBITS0x47180c0x3180c0x400x00x10000003WAp004
                                            .bssNOBITS0x4718500x3180c0x46a00x00x3WA0016
                                            .mdebug.abi32PROGBITS0x14ac0x3180c0x00x00x0001
                                            .shstrtabSTRTAB0x00x3180c0x640x00x0001
                                            TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                            LOAD0x00x4000000x4000000x2b5800x2b5805.41590x5R E0x10000.init .text .fini .rodata
                                            LOAD0x2c0000x46c0000x46c0000x580c0x9ef01.39600x6RW 0x10000.ctors .dtors .data.rel.ro .data .got .sbss .bss
                                            GNU_STACK0x00x00x00x00x00.00000x7RWE0x4
                                            TimestampSource PortDest PortSource IPDest IP
                                            Dec 27, 2024 21:07:52.028362989 CET43928443192.168.2.2391.189.91.42
                                            Dec 27, 2024 21:07:57.403584957 CET42836443192.168.2.2391.189.91.43
                                            Dec 27, 2024 21:07:59.195338964 CET4251680192.168.2.23109.202.202.202
                                            Dec 27, 2024 21:08:11.993551970 CET43928443192.168.2.2391.189.91.42
                                            Dec 27, 2024 21:08:24.279846907 CET42836443192.168.2.2391.189.91.43
                                            Dec 27, 2024 21:08:30.423156023 CET4251680192.168.2.23109.202.202.202
                                            Dec 27, 2024 21:08:52.948008060 CET43928443192.168.2.2391.189.91.42
                                            TimestampSource PortDest PortSource IPDest IP
                                            Dec 27, 2024 21:07:50.178582907 CET4124353192.168.2.238.8.8.8
                                            Dec 27, 2024 21:07:50.534722090 CET53412438.8.8.8192.168.2.23
                                            Dec 27, 2024 21:07:50.535881042 CET3509353192.168.2.238.8.8.8
                                            Dec 27, 2024 21:07:50.815603971 CET53350938.8.8.8192.168.2.23
                                            Dec 27, 2024 21:07:50.817625999 CET3667553192.168.2.238.8.8.8
                                            Dec 27, 2024 21:07:51.316262007 CET53366758.8.8.8192.168.2.23
                                            Dec 27, 2024 21:07:51.317948103 CET4777953192.168.2.238.8.8.8
                                            Dec 27, 2024 21:07:51.451838970 CET53477798.8.8.8192.168.2.23
                                            Dec 27, 2024 21:07:51.454224110 CET3991853192.168.2.238.8.8.8
                                            Dec 27, 2024 21:07:51.588515997 CET53399188.8.8.8192.168.2.23
                                            Dec 27, 2024 21:07:56.590050936 CET4395653192.168.2.2351.77.149.139
                                            Dec 27, 2024 21:07:56.821784973 CET534395651.77.149.139192.168.2.23
                                            Dec 27, 2024 21:07:56.822459936 CET3581253192.168.2.2351.77.149.139
                                            Dec 27, 2024 21:07:57.631477118 CET533581251.77.149.139192.168.2.23
                                            Dec 27, 2024 21:07:57.632191896 CET3497953192.168.2.2351.77.149.139
                                            Dec 27, 2024 21:07:58.019835949 CET533497951.77.149.139192.168.2.23
                                            Dec 27, 2024 21:07:58.020518064 CET3491053192.168.2.2351.77.149.139
                                            Dec 27, 2024 21:07:58.284337044 CET533491051.77.149.139192.168.2.23
                                            Dec 27, 2024 21:07:58.285051107 CET4909753192.168.2.2351.77.149.139
                                            Dec 27, 2024 21:07:58.564064026 CET534909751.77.149.139192.168.2.23
                                            Dec 27, 2024 21:08:03.564713001 CET4896453192.168.2.23208.76.51.51
                                            Dec 27, 2024 21:08:08.565582991 CET3323353192.168.2.23208.76.51.51
                                            Dec 27, 2024 21:08:13.570573092 CET5159253192.168.2.23208.76.51.51
                                            Dec 27, 2024 21:08:18.575550079 CET3730553192.168.2.23208.76.51.51
                                            Dec 27, 2024 21:08:23.580513954 CET3340253192.168.2.23208.76.51.51
                                            Dec 27, 2024 21:08:33.587368965 CET4506253192.168.2.238.26.56.26
                                            Dec 27, 2024 21:08:33.831547976 CET53450628.26.56.26192.168.2.23
                                            Dec 27, 2024 21:08:33.832910061 CET5393553192.168.2.238.26.56.26
                                            Dec 27, 2024 21:08:34.077846050 CET53539358.26.56.26192.168.2.23
                                            Dec 27, 2024 21:08:34.079287052 CET5212953192.168.2.238.26.56.26
                                            Dec 27, 2024 21:08:34.325156927 CET53521298.26.56.26192.168.2.23
                                            Dec 27, 2024 21:08:34.326432943 CET5979953192.168.2.238.26.56.26
                                            Dec 27, 2024 21:08:34.574742079 CET53597998.26.56.26192.168.2.23
                                            Dec 27, 2024 21:08:34.576112986 CET5923153192.168.2.238.26.56.26
                                            Dec 27, 2024 21:08:34.825372934 CET53592318.26.56.26192.168.2.23
                                            Dec 27, 2024 21:08:39.827516079 CET5210553192.168.2.23208.76.50.50
                                            Dec 27, 2024 21:08:44.833374977 CET3887153192.168.2.23208.76.50.50
                                            Dec 27, 2024 21:08:49.838773012 CET3425053192.168.2.23208.76.50.50
                                            Dec 27, 2024 21:08:54.840713024 CET4319853192.168.2.23208.76.50.50
                                            Dec 27, 2024 21:08:59.846246958 CET4963753192.168.2.23208.76.50.50
                                            Dec 27, 2024 21:09:09.851979971 CET5790553192.168.2.23208.76.51.51
                                            Dec 27, 2024 21:09:14.855982065 CET5913953192.168.2.23208.76.51.51
                                            Dec 27, 2024 21:09:19.860580921 CET3360053192.168.2.23208.76.51.51
                                            Dec 27, 2024 21:09:24.866219044 CET4100853192.168.2.23208.76.51.51
                                            Dec 27, 2024 21:09:29.867636919 CET3882253192.168.2.23208.76.51.51
                                            Dec 27, 2024 21:09:39.875191927 CET3941253192.168.2.23194.36.144.87
                                            Dec 27, 2024 21:09:40.120007992 CET5339412194.36.144.87192.168.2.23
                                            Dec 27, 2024 21:09:40.121730089 CET5854053192.168.2.23194.36.144.87
                                            Dec 27, 2024 21:09:40.366425037 CET5358540194.36.144.87192.168.2.23
                                            Dec 27, 2024 21:09:40.368180037 CET5635053192.168.2.23194.36.144.87
                                            Dec 27, 2024 21:09:40.608937025 CET5356350194.36.144.87192.168.2.23
                                            Dec 27, 2024 21:09:40.610455990 CET4994153192.168.2.23194.36.144.87
                                            Dec 27, 2024 21:09:40.857656956 CET5349941194.36.144.87192.168.2.23
                                            Dec 27, 2024 21:09:40.859093904 CET4329253192.168.2.23194.36.144.87
                                            Dec 27, 2024 21:09:41.109091997 CET5343292194.36.144.87192.168.2.23
                                            Dec 27, 2024 21:09:46.111310005 CET5015353192.168.2.23194.36.144.87
                                            Dec 27, 2024 21:09:46.357880116 CET5350153194.36.144.87192.168.2.23
                                            Dec 27, 2024 21:09:46.359317064 CET4450653192.168.2.23194.36.144.87
                                            Dec 27, 2024 21:09:46.602221966 CET5344506194.36.144.87192.168.2.23
                                            Dec 27, 2024 21:09:46.603604078 CET4665053192.168.2.23194.36.144.87
                                            Dec 27, 2024 21:09:46.856178999 CET5346650194.36.144.87192.168.2.23
                                            Dec 27, 2024 21:09:46.857598066 CET4774353192.168.2.23194.36.144.87
                                            Dec 27, 2024 21:09:47.102444887 CET5347743194.36.144.87192.168.2.23
                                            Dec 27, 2024 21:09:47.103696108 CET3471453192.168.2.23194.36.144.87
                                            Dec 27, 2024 21:09:47.344180107 CET5334714194.36.144.87192.168.2.23
                                            Dec 27, 2024 21:09:52.346577883 CET4267853192.168.2.23208.76.50.50
                                            TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                            Dec 27, 2024 21:07:50.178582907 CET192.168.2.238.8.8.80xf8e7Standard query (0)dns.stresse.proA (IP address)IN (0x0001)false
                                            Dec 27, 2024 21:07:50.535881042 CET192.168.2.238.8.8.80xf8e7Standard query (0)dns.stresse.proA (IP address)IN (0x0001)false
                                            Dec 27, 2024 21:07:50.817625999 CET192.168.2.238.8.8.80xf8e7Standard query (0)dns.stresse.proA (IP address)IN (0x0001)false
                                            Dec 27, 2024 21:07:51.317948103 CET192.168.2.238.8.8.80xf8e7Standard query (0)dns.stresse.proA (IP address)IN (0x0001)false
                                            Dec 27, 2024 21:07:51.454224110 CET192.168.2.238.8.8.80xf8e7Standard query (0)dns.stresse.proA (IP address)IN (0x0001)false
                                            Dec 27, 2024 21:07:56.590050936 CET192.168.2.2351.77.149.1390xa372Standard query (0)dns.stresse.proA (IP address)IN (0x0001)false
                                            Dec 27, 2024 21:07:56.822459936 CET192.168.2.2351.77.149.1390xa372Standard query (0)dns.stresse.proA (IP address)IN (0x0001)false
                                            Dec 27, 2024 21:07:57.632191896 CET192.168.2.2351.77.149.1390xa372Standard query (0)dns.stresse.proA (IP address)IN (0x0001)false
                                            Dec 27, 2024 21:07:58.020518064 CET192.168.2.2351.77.149.1390xa372Standard query (0)dns.stresse.proA (IP address)IN (0x0001)false
                                            Dec 27, 2024 21:07:58.285051107 CET192.168.2.2351.77.149.1390xa372Standard query (0)dns.stresse.proA (IP address)IN (0x0001)false
                                            Dec 27, 2024 21:08:03.564713001 CET192.168.2.23208.76.51.510x2645Standard query (0)dns.stresse.proA (IP address)IN (0x0001)false
                                            Dec 27, 2024 21:08:08.565582991 CET192.168.2.23208.76.51.510x2645Standard query (0)dns.stresse.proA (IP address)IN (0x0001)false
                                            Dec 27, 2024 21:08:13.570573092 CET192.168.2.23208.76.51.510x2645Standard query (0)dns.stresse.proA (IP address)IN (0x0001)false
                                            Dec 27, 2024 21:08:18.575550079 CET192.168.2.23208.76.51.510x2645Standard query (0)dns.stresse.proA (IP address)IN (0x0001)false
                                            Dec 27, 2024 21:08:23.580513954 CET192.168.2.23208.76.51.510x2645Standard query (0)dns.stresse.proA (IP address)IN (0x0001)false
                                            Dec 27, 2024 21:08:33.587368965 CET192.168.2.238.26.56.260x7fe2Standard query (0)dns.stresse.proA (IP address)IN (0x0001)false
                                            Dec 27, 2024 21:08:33.832910061 CET192.168.2.238.26.56.260x7fe2Standard query (0)dns.stresse.proA (IP address)IN (0x0001)false
                                            Dec 27, 2024 21:08:34.079287052 CET192.168.2.238.26.56.260x7fe2Standard query (0)dns.stresse.proA (IP address)IN (0x0001)false
                                            Dec 27, 2024 21:08:34.326432943 CET192.168.2.238.26.56.260x7fe2Standard query (0)dns.stresse.proA (IP address)IN (0x0001)false
                                            Dec 27, 2024 21:08:34.576112986 CET192.168.2.238.26.56.260x7fe2Standard query (0)dns.stresse.proA (IP address)IN (0x0001)false
                                            Dec 27, 2024 21:08:39.827516079 CET192.168.2.23208.76.50.500x7914Standard query (0)dns.stresse.proA (IP address)IN (0x0001)false
                                            Dec 27, 2024 21:08:44.833374977 CET192.168.2.23208.76.50.500x7914Standard query (0)dns.stresse.proA (IP address)IN (0x0001)false
                                            Dec 27, 2024 21:08:49.838773012 CET192.168.2.23208.76.50.500x7914Standard query (0)dns.stresse.proA (IP address)IN (0x0001)false
                                            Dec 27, 2024 21:08:54.840713024 CET192.168.2.23208.76.50.500x7914Standard query (0)dns.stresse.proA (IP address)IN (0x0001)false
                                            Dec 27, 2024 21:08:59.846246958 CET192.168.2.23208.76.50.500x7914Standard query (0)dns.stresse.proA (IP address)IN (0x0001)false
                                            Dec 27, 2024 21:09:09.851979971 CET192.168.2.23208.76.51.510x7fb8Standard query (0)dns.stresse.proA (IP address)IN (0x0001)false
                                            Dec 27, 2024 21:09:14.855982065 CET192.168.2.23208.76.51.510x7fb8Standard query (0)dns.stresse.proA (IP address)IN (0x0001)false
                                            Dec 27, 2024 21:09:19.860580921 CET192.168.2.23208.76.51.510x7fb8Standard query (0)dns.stresse.proA (IP address)IN (0x0001)false
                                            Dec 27, 2024 21:09:24.866219044 CET192.168.2.23208.76.51.510x7fb8Standard query (0)dns.stresse.proA (IP address)IN (0x0001)false
                                            Dec 27, 2024 21:09:29.867636919 CET192.168.2.23208.76.51.510x7fb8Standard query (0)dns.stresse.proA (IP address)IN (0x0001)false
                                            Dec 27, 2024 21:09:39.875191927 CET192.168.2.23194.36.144.870x1395Standard query (0)dns.stresse.proA (IP address)IN (0x0001)false
                                            Dec 27, 2024 21:09:40.121730089 CET192.168.2.23194.36.144.870x1395Standard query (0)dns.stresse.proA (IP address)IN (0x0001)false
                                            Dec 27, 2024 21:09:40.368180037 CET192.168.2.23194.36.144.870x1395Standard query (0)dns.stresse.proA (IP address)IN (0x0001)false
                                            Dec 27, 2024 21:09:40.610455990 CET192.168.2.23194.36.144.870x1395Standard query (0)dns.stresse.proA (IP address)IN (0x0001)false
                                            Dec 27, 2024 21:09:40.859093904 CET192.168.2.23194.36.144.870x1395Standard query (0)dns.stresse.proA (IP address)IN (0x0001)false
                                            Dec 27, 2024 21:09:46.111310005 CET192.168.2.23194.36.144.870x2d87Standard query (0)dns.stresse.proA (IP address)IN (0x0001)false
                                            Dec 27, 2024 21:09:46.359317064 CET192.168.2.23194.36.144.870x2d87Standard query (0)dns.stresse.proA (IP address)IN (0x0001)false
                                            Dec 27, 2024 21:09:46.603604078 CET192.168.2.23194.36.144.870x2d87Standard query (0)dns.stresse.proA (IP address)IN (0x0001)false
                                            Dec 27, 2024 21:09:46.857598066 CET192.168.2.23194.36.144.870x2d87Standard query (0)dns.stresse.proA (IP address)IN (0x0001)false
                                            Dec 27, 2024 21:09:47.103696108 CET192.168.2.23194.36.144.870x2d87Standard query (0)dns.stresse.proA (IP address)IN (0x0001)false
                                            Dec 27, 2024 21:09:52.346577883 CET192.168.2.23208.76.50.500x7d35Standard query (0)dns.stresse.proA (IP address)IN (0x0001)false
                                            TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                            Dec 27, 2024 21:07:50.534722090 CET8.8.8.8192.168.2.230xf8e7Name error (3)dns.stresse.prononenoneA (IP address)IN (0x0001)false
                                            Dec 27, 2024 21:07:50.815603971 CET8.8.8.8192.168.2.230xf8e7Name error (3)dns.stresse.prononenoneA (IP address)IN (0x0001)false
                                            Dec 27, 2024 21:07:51.316262007 CET8.8.8.8192.168.2.230xf8e7Name error (3)dns.stresse.prononenoneA (IP address)IN (0x0001)false
                                            Dec 27, 2024 21:07:51.451838970 CET8.8.8.8192.168.2.230xf8e7Name error (3)dns.stresse.prononenoneA (IP address)IN (0x0001)false
                                            Dec 27, 2024 21:07:51.588515997 CET8.8.8.8192.168.2.230xf8e7Name error (3)dns.stresse.prononenoneA (IP address)IN (0x0001)false
                                            Dec 27, 2024 21:07:56.821784973 CET51.77.149.139192.168.2.230xa372Name error (3)dns.stresse.prononenoneA (IP address)IN (0x0001)false
                                            Dec 27, 2024 21:07:57.631477118 CET51.77.149.139192.168.2.230xa372Name error (3)dns.stresse.prononenoneA (IP address)IN (0x0001)false
                                            Dec 27, 2024 21:07:58.019835949 CET51.77.149.139192.168.2.230xa372Name error (3)dns.stresse.prononenoneA (IP address)IN (0x0001)false
                                            Dec 27, 2024 21:07:58.284337044 CET51.77.149.139192.168.2.230xa372Name error (3)dns.stresse.prononenoneA (IP address)IN (0x0001)false
                                            Dec 27, 2024 21:07:58.564064026 CET51.77.149.139192.168.2.230xa372Name error (3)dns.stresse.prononenoneA (IP address)IN (0x0001)false
                                            Dec 27, 2024 21:08:33.831547976 CET8.26.56.26192.168.2.230x7fe2Name error (3)dns.stresse.prononenoneA (IP address)IN (0x0001)false
                                            Dec 27, 2024 21:08:34.077846050 CET8.26.56.26192.168.2.230x7fe2Name error (3)dns.stresse.prononenoneA (IP address)IN (0x0001)false
                                            Dec 27, 2024 21:08:34.325156927 CET8.26.56.26192.168.2.230x7fe2Name error (3)dns.stresse.prononenoneA (IP address)IN (0x0001)false
                                            Dec 27, 2024 21:08:34.574742079 CET8.26.56.26192.168.2.230x7fe2Name error (3)dns.stresse.prononenoneA (IP address)IN (0x0001)false
                                            Dec 27, 2024 21:08:34.825372934 CET8.26.56.26192.168.2.230x7fe2Name error (3)dns.stresse.prononenoneA (IP address)IN (0x0001)false
                                            Dec 27, 2024 21:09:40.120007992 CET194.36.144.87192.168.2.230x1395Name error (3)dns.stresse.prononenoneA (IP address)IN (0x0001)false
                                            Dec 27, 2024 21:09:40.366425037 CET194.36.144.87192.168.2.230x1395Name error (3)dns.stresse.prononenoneA (IP address)IN (0x0001)false
                                            Dec 27, 2024 21:09:40.608937025 CET194.36.144.87192.168.2.230x1395Name error (3)dns.stresse.prononenoneA (IP address)IN (0x0001)false
                                            Dec 27, 2024 21:09:40.857656956 CET194.36.144.87192.168.2.230x1395Name error (3)dns.stresse.prononenoneA (IP address)IN (0x0001)false
                                            Dec 27, 2024 21:09:41.109091997 CET194.36.144.87192.168.2.230x1395Name error (3)dns.stresse.prononenoneA (IP address)IN (0x0001)false
                                            Dec 27, 2024 21:09:46.357880116 CET194.36.144.87192.168.2.230x2d87Name error (3)dns.stresse.prononenoneA (IP address)IN (0x0001)false
                                            Dec 27, 2024 21:09:46.602221966 CET194.36.144.87192.168.2.230x2d87Name error (3)dns.stresse.prononenoneA (IP address)IN (0x0001)false
                                            Dec 27, 2024 21:09:46.856178999 CET194.36.144.87192.168.2.230x2d87Name error (3)dns.stresse.prononenoneA (IP address)IN (0x0001)false
                                            Dec 27, 2024 21:09:47.102444887 CET194.36.144.87192.168.2.230x2d87Name error (3)dns.stresse.prononenoneA (IP address)IN (0x0001)false
                                            Dec 27, 2024 21:09:47.344180107 CET194.36.144.87192.168.2.230x2d87Name error (3)dns.stresse.prononenoneA (IP address)IN (0x0001)false

                                            System Behavior

                                            Start time (UTC):20:07:49
                                            Start date (UTC):27/12/2024
                                            Path:/tmp/mpsl.elf
                                            Arguments:/tmp/mpsl.elf
                                            File size:5773336 bytes
                                            MD5 hash:0d6f61f82cf2f781c6eb0661071d42d9

                                            Start time (UTC):20:07:49
                                            Start date (UTC):27/12/2024
                                            Path:/tmp/mpsl.elf
                                            Arguments:-
                                            File size:5773336 bytes
                                            MD5 hash:0d6f61f82cf2f781c6eb0661071d42d9

                                            Start time (UTC):20:07:49
                                            Start date (UTC):27/12/2024
                                            Path:/tmp/mpsl.elf
                                            Arguments:-
                                            File size:5773336 bytes
                                            MD5 hash:0d6f61f82cf2f781c6eb0661071d42d9