Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
boatnet.spc.elf

Overview

General Information

Sample name:boatnet.spc.elf
Analysis ID:1581786
MD5:f5a5456d440cc82220128f62a70172b4
SHA1:d3a0361a7e6d42eee17fcc67aa04687d6143d104
SHA256:6e7a50cdd079411288c416a0e8e80978f68d1f31be43be83a831b77f9502d123
Tags:elfuser-abuse_ch
Infos:

Detection

Mirai
Score:76
Range:0 - 100
Whitelisted:false

Signatures

Antivirus / Scanner detection for submitted sample
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Yara detected Mirai
Sample tries to kill multiple processes (SIGKILL)
Detected TCP or UDP traffic on non-standard ports
Enumerates processes within the "proc" file system
Sample has stripped symbol table
Sample tries to kill a process (SIGKILL)
Uses the "uname" system call to query kernel version information (possible evasion)
Yara signature match

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1581786
Start date and time:2024-12-29 00:09:36 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 5m 5s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:boatnet.spc.elf
Detection:MAL
Classification:mal76.spre.troj.linELF@0/0@2/0
  • VT rate limit hit for: boatnet.spc.elf
Command:/tmp/boatnet.spc.elf
PID:5582
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
lzrd cock fest"/proc/"/exe
Standard Error:
  • system is lnxubuntu20
  • wrapper-2.0 (PID: 5591, Parent: 3172, MD5: ac0b8a906f359a8ae102244738682e76) Arguments: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libsystray.so 6 12582920 systray "Notification Area" "Area where notification icons appear"
  • wrapper-2.0 (PID: 5592, Parent: 3172, MD5: ac0b8a906f359a8ae102244738682e76) Arguments: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libstatusnotifier.so 7 12582921 statusnotifier "Status Notifier Plugin" "Provides a panel area for status notifier items (application indicators)"
  • wrapper-2.0 (PID: 5593, Parent: 3172, MD5: ac0b8a906f359a8ae102244738682e76) Arguments: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libpulseaudio-plugin.so 8 12582922 pulseaudio "PulseAudio Plugin" "Adjust the audio volume of the PulseAudio sound system"
  • wrapper-2.0 (PID: 5594, Parent: 3172, MD5: ac0b8a906f359a8ae102244738682e76) Arguments: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libxfce4powermanager.so 9 12582923 power-manager-plugin "Power Manager Plugin" "Display the battery levels of your devices and control the brightness of your display"
  • wrapper-2.0 (PID: 5595, Parent: 3172, MD5: ac0b8a906f359a8ae102244738682e76) Arguments: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libnotification-plugin.so 10 12582924 notification-plugin "Notification Plugin" "Notification plugin for the Xfce panel"
  • wrapper-2.0 (PID: 5596, Parent: 3172, MD5: ac0b8a906f359a8ae102244738682e76) Arguments: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libactions.so 14 12582925 actions "Action Buttons" "Log out, lock or other system actions"
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
MiraiMirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese. Nowadays it targets a wide range of networked embedded devices such as IP cameras, home routers (many vendors involved), and other IoT devices. Since the source code was published on "Hack Forums" many variants of the Mirai family appeared, infecting mostly home networks all around the world.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/elf.mirai
SourceRuleDescriptionAuthorStrings
boatnet.spc.elfJoeSecurity_Mirai_8Yara detected MiraiJoe Security
    boatnet.spc.elfLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
    • 0xc958:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xc96c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xc980:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xc994:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xc9a8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xc9bc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xc9d0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xc9e4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xc9f8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xca0c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xca20:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xca34:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xca48:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xca5c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xca70:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xca84:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xca98:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xcaac:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xcac0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xcad4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xcae8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    boatnet.spc.elfLinux_Trojan_Gafgyt_ea92cca8unknownunknown
    • 0xceb8:$a: 53 65 6C 66 20 52 65 70 20 46 75 63 6B 69 6E 67 20 4E 65 54 69 53 20 61 6E 64
    SourceRuleDescriptionAuthorStrings
    5582.1.00007f0244011000.00007f024401f000.r-x.sdmpJoeSecurity_Mirai_8Yara detected MiraiJoe Security
      5582.1.00007f0244011000.00007f024401f000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
      • 0xc958:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xc96c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xc980:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xc994:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xc9a8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xc9bc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xc9d0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xc9e4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xc9f8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xca0c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xca20:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xca34:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xca48:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xca5c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xca70:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xca84:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xca98:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xcaac:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xcac0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xcad4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xcae8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      5582.1.00007f0244011000.00007f024401f000.r-x.sdmpLinux_Trojan_Gafgyt_ea92cca8unknownunknown
      • 0xceb8:$a: 53 65 6C 66 20 52 65 70 20 46 75 63 6B 69 6E 67 20 4E 65 54 69 53 20 61 6E 64
      5585.1.00007f0244011000.00007f024401f000.r-x.sdmpJoeSecurity_Mirai_8Yara detected MiraiJoe Security
        5585.1.00007f0244011000.00007f024401f000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
        • 0xc958:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0xc96c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0xc980:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0xc994:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0xc9a8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0xc9bc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0xc9d0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0xc9e4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0xc9f8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0xca0c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0xca20:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0xca34:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0xca48:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0xca5c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0xca70:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0xca84:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0xca98:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0xcaac:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0xcac0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0xcad4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0xcae8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        Click to see the 7 entries
        No Suricata rule has matched

        Click to jump to signature section

        Show All Signature Results

        AV Detection

        barindex
        Source: boatnet.spc.elfAvira: detected
        Source: boatnet.spc.elfReversingLabs: Detection: 64%
        Source: global trafficTCP traffic: 192.168.2.14:56774 -> 109.71.252.43:3778
        Source: unknownTCP traffic detected without corresponding DNS query: 109.71.252.43
        Source: unknownTCP traffic detected without corresponding DNS query: 109.71.252.43
        Source: unknownTCP traffic detected without corresponding DNS query: 109.71.252.43
        Source: unknownTCP traffic detected without corresponding DNS query: 109.71.252.43
        Source: unknownTCP traffic detected without corresponding DNS query: 109.71.252.43
        Source: unknownTCP traffic detected without corresponding DNS query: 109.71.252.43
        Source: unknownTCP traffic detected without corresponding DNS query: 109.71.252.43
        Source: unknownTCP traffic detected without corresponding DNS query: 109.71.252.43
        Source: unknownTCP traffic detected without corresponding DNS query: 109.71.252.43
        Source: unknownTCP traffic detected without corresponding DNS query: 109.71.252.43
        Source: unknownTCP traffic detected without corresponding DNS query: 109.71.252.43
        Source: unknownTCP traffic detected without corresponding DNS query: 109.71.252.43
        Source: unknownTCP traffic detected without corresponding DNS query: 109.71.252.43
        Source: unknownTCP traffic detected without corresponding DNS query: 109.71.252.43
        Source: unknownTCP traffic detected without corresponding DNS query: 109.71.252.43
        Source: unknownTCP traffic detected without corresponding DNS query: 109.71.252.43
        Source: unknownTCP traffic detected without corresponding DNS query: 109.71.252.43
        Source: unknownTCP traffic detected without corresponding DNS query: 109.71.252.43
        Source: unknownTCP traffic detected without corresponding DNS query: 109.71.252.43
        Source: unknownTCP traffic detected without corresponding DNS query: 109.71.252.43
        Source: unknownTCP traffic detected without corresponding DNS query: 109.71.252.43
        Source: unknownTCP traffic detected without corresponding DNS query: 109.71.252.43
        Source: unknownTCP traffic detected without corresponding DNS query: 109.71.252.43
        Source: unknownTCP traffic detected without corresponding DNS query: 109.71.252.43
        Source: unknownTCP traffic detected without corresponding DNS query: 109.71.252.43
        Source: unknownTCP traffic detected without corresponding DNS query: 109.71.252.43
        Source: unknownTCP traffic detected without corresponding DNS query: 109.71.252.43
        Source: unknownTCP traffic detected without corresponding DNS query: 109.71.252.43
        Source: unknownTCP traffic detected without corresponding DNS query: 109.71.252.43
        Source: unknownTCP traffic detected without corresponding DNS query: 109.71.252.43
        Source: unknownTCP traffic detected without corresponding DNS query: 109.71.252.43
        Source: unknownTCP traffic detected without corresponding DNS query: 109.71.252.43
        Source: unknownTCP traffic detected without corresponding DNS query: 109.71.252.43
        Source: unknownTCP traffic detected without corresponding DNS query: 109.71.252.43
        Source: unknownTCP traffic detected without corresponding DNS query: 109.71.252.43
        Source: unknownTCP traffic detected without corresponding DNS query: 109.71.252.43
        Source: unknownTCP traffic detected without corresponding DNS query: 109.71.252.43
        Source: unknownTCP traffic detected without corresponding DNS query: 109.71.252.43
        Source: unknownTCP traffic detected without corresponding DNS query: 109.71.252.43
        Source: unknownTCP traffic detected without corresponding DNS query: 109.71.252.43
        Source: unknownTCP traffic detected without corresponding DNS query: 109.71.252.43
        Source: unknownTCP traffic detected without corresponding DNS query: 109.71.252.43
        Source: unknownTCP traffic detected without corresponding DNS query: 109.71.252.43
        Source: unknownTCP traffic detected without corresponding DNS query: 109.71.252.43
        Source: unknownTCP traffic detected without corresponding DNS query: 109.71.252.43
        Source: unknownTCP traffic detected without corresponding DNS query: 109.71.252.43
        Source: unknownTCP traffic detected without corresponding DNS query: 109.71.252.43
        Source: unknownTCP traffic detected without corresponding DNS query: 109.71.252.43
        Source: unknownTCP traffic detected without corresponding DNS query: 109.71.252.43
        Source: unknownTCP traffic detected without corresponding DNS query: 109.71.252.43
        Source: global trafficDNS traffic detected: DNS query: daisy.ubuntu.com

        System Summary

        barindex
        Source: boatnet.spc.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
        Source: boatnet.spc.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown
        Source: 5582.1.00007f0244011000.00007f024401f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
        Source: 5582.1.00007f0244011000.00007f024401f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown
        Source: 5585.1.00007f0244011000.00007f024401f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
        Source: 5585.1.00007f0244011000.00007f024401f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown
        Source: Process Memory Space: boatnet.spc.elf PID: 5582, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
        Source: Process Memory Space: boatnet.spc.elf PID: 5582, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown
        Source: Process Memory Space: boatnet.spc.elf PID: 5585, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
        Source: Process Memory Space: boatnet.spc.elf PID: 5585, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown
        Source: /tmp/boatnet.spc.elf (PID: 5584)SIGKILL sent: pid: 3129, result: successfulJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5584)SIGKILL sent: pid: 3184, result: successfulJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5584)SIGKILL sent: pid: 3187, result: successfulJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5584)SIGKILL sent: pid: 3188, result: successfulJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5584)SIGKILL sent: pid: 3189, result: successfulJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5584)SIGKILL sent: pid: 3190, result: successfulJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5584)SIGKILL sent: pid: 3193, result: successfulJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5584)SIGKILL sent: pid: 3207, result: successfulJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5584)SIGKILL sent: pid: 3215, result: successfulJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5584)SIGKILL sent: pid: 3235, result: successfulJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5584)SIGKILL sent: pid: 5591, result: successfulJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5584)SIGKILL sent: pid: 5592, result: successfulJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5584)SIGKILL sent: pid: 5593, result: successfulJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5584)SIGKILL sent: pid: 5594, result: successfulJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5584)SIGKILL sent: pid: 5595, result: successfulJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5584)SIGKILL sent: pid: 5596, result: successfulJump to behavior
        Source: ELF static info symbol of initial sample.symtab present: no
        Source: /tmp/boatnet.spc.elf (PID: 5584)SIGKILL sent: pid: 3129, result: successfulJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5584)SIGKILL sent: pid: 3184, result: successfulJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5584)SIGKILL sent: pid: 3187, result: successfulJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5584)SIGKILL sent: pid: 3188, result: successfulJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5584)SIGKILL sent: pid: 3189, result: successfulJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5584)SIGKILL sent: pid: 3190, result: successfulJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5584)SIGKILL sent: pid: 3193, result: successfulJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5584)SIGKILL sent: pid: 3207, result: successfulJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5584)SIGKILL sent: pid: 3215, result: successfulJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5584)SIGKILL sent: pid: 3235, result: successfulJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5584)SIGKILL sent: pid: 5591, result: successfulJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5584)SIGKILL sent: pid: 5592, result: successfulJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5584)SIGKILL sent: pid: 5593, result: successfulJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5584)SIGKILL sent: pid: 5594, result: successfulJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5584)SIGKILL sent: pid: 5595, result: successfulJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5584)SIGKILL sent: pid: 5596, result: successfulJump to behavior
        Source: boatnet.spc.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
        Source: boatnet.spc.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16
        Source: 5582.1.00007f0244011000.00007f024401f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
        Source: 5582.1.00007f0244011000.00007f024401f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16
        Source: 5585.1.00007f0244011000.00007f024401f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
        Source: 5585.1.00007f0244011000.00007f024401f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16
        Source: Process Memory Space: boatnet.spc.elf PID: 5582, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
        Source: Process Memory Space: boatnet.spc.elf PID: 5582, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16
        Source: Process Memory Space: boatnet.spc.elf PID: 5585, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
        Source: Process Memory Space: boatnet.spc.elf PID: 5585, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16
        Source: classification engineClassification label: mal76.spre.troj.linELF@0/0@2/0
        Source: /tmp/boatnet.spc.elf (PID: 5584)File opened: /proc/3760/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5584)File opened: /proc/3761/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5584)File opened: /proc/2672/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5584)File opened: /proc/1583/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5584)File opened: /proc/3244/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5584)File opened: /proc/3120/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5584)File opened: /proc/3361/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5584)File opened: /proc/3239/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5584)File opened: /proc/1577/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5584)File opened: /proc/1610/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5584)File opened: /proc/512/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5584)File opened: /proc/1299/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5584)File opened: /proc/3235/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5584)File opened: /proc/514/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5584)File opened: /proc/519/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5584)File opened: /proc/2946/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5584)File opened: /proc/3878/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5584)File opened: /proc/5418/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5584)File opened: /proc/917/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5584)File opened: /proc/3134/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5584)File opened: /proc/1593/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5584)File opened: /proc/3011/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5584)File opened: /proc/3094/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5584)File opened: /proc/3406/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5584)File opened: /proc/1589/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5584)File opened: /proc/3129/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5584)File opened: /proc/1588/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5584)File opened: /proc/3402/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5584)File opened: /proc/3125/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5584)File opened: /proc/3246/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5584)File opened: /proc/3245/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5584)File opened: /proc/767/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5584)File opened: /proc/800/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5584)File opened: /proc/888/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5584)File opened: /proc/3762/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5584)File opened: /proc/801/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5584)File opened: /proc/3763/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5584)File opened: /proc/769/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5584)File opened: /proc/803/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5584)File opened: /proc/806/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5584)File opened: /proc/807/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5584)File opened: /proc/928/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5584)File opened: /proc/2956/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5584)File opened: /proc/5560/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5584)File opened: /proc/3420/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5584)File opened: /proc/490/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5584)File opened: /proc/3142/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5584)File opened: /proc/1635/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5584)File opened: /proc/1633/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5584)File opened: /proc/1599/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5584)File opened: /proc/3139/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5584)File opened: /proc/1873/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5584)File opened: /proc/1630/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5584)File opened: /proc/3412/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5584)File opened: /proc/657/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5584)File opened: /proc/658/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5584)File opened: /proc/659/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5584)File opened: /proc/418/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5584)File opened: /proc/419/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5584)File opened: /proc/1639/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5584)File opened: /proc/5559/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5584)File opened: /proc/1638/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5584)File opened: /proc/3398/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5584)File opened: /proc/1371/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5584)File opened: /proc/3392/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5584)File opened: /proc/780/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5584)File opened: /proc/660/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5584)File opened: /proc/661/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5584)File opened: /proc/782/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5584)File opened: /proc/1369/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5584)File opened: /proc/3304/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5584)File opened: /proc/3425/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5584)File opened: /proc/785/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5584)File opened: /proc/1642/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5584)File opened: /proc/940/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5584)File opened: /proc/941/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5584)File opened: /proc/1640/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5584)File opened: /proc/3147/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5584)File opened: /proc/3268/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5584)File opened: /proc/1364/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5584)File opened: /proc/548/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5584)File opened: /proc/3700/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5584)File opened: /proc/1647/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5584)File opened: /proc/2991/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5584)File opened: /proc/1383/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5584)File opened: /proc/1382/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5584)File opened: /proc/1381/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5584)File opened: /proc/791/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5584)File opened: /proc/671/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5584)File opened: /proc/794/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5584)File opened: /proc/1655/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5584)File opened: /proc/2986/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5584)File opened: /proc/795/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5584)File opened: /proc/674/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5584)File opened: /proc/1653/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5584)File opened: /proc/797/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5584)File opened: /proc/2983/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5584)File opened: /proc/3159/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5584)File opened: /proc/678/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5584)File opened: /proc/1650/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5584)File opened: /proc/3157/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5584)File opened: /proc/679/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5584)File opened: /proc/1659/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5584)File opened: /proc/3319/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5584)File opened: /proc/5591/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5582)Queries kernel information via 'uname': Jump to behavior
        Source: boatnet.spc.elf, 5582.1.0000563193a49000.0000563193ace000.rw-.sdmp, boatnet.spc.elf, 5585.1.0000563193a49000.0000563193ace000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/sparc
        Source: boatnet.spc.elf, 5582.1.00007fffbf805000.00007fffbf826000.rw-.sdmp, boatnet.spc.elf, 5585.1.00007fffbf805000.00007fffbf826000.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-sparc/tmp/boatnet.spc.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/boatnet.spc.elf
        Source: boatnet.spc.elf, 5582.1.0000563193a49000.0000563193ace000.rw-.sdmp, boatnet.spc.elf, 5585.1.0000563193a49000.0000563193ace000.rw-.sdmpBinary or memory string: 1V!/etc/qemu-binfmt/sparc
        Source: boatnet.spc.elf, 5582.1.00007fffbf805000.00007fffbf826000.rw-.sdmp, boatnet.spc.elf, 5585.1.00007fffbf805000.00007fffbf826000.rw-.sdmpBinary or memory string: /usr/bin/qemu-sparc

        Stealing of Sensitive Information

        barindex
        Source: Yara matchFile source: boatnet.spc.elf, type: SAMPLE
        Source: Yara matchFile source: 5582.1.00007f0244011000.00007f024401f000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 5585.1.00007f0244011000.00007f024401f000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: Process Memory Space: boatnet.spc.elf PID: 5582, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: boatnet.spc.elf PID: 5585, type: MEMORYSTR

        Remote Access Functionality

        barindex
        Source: Yara matchFile source: boatnet.spc.elf, type: SAMPLE
        Source: Yara matchFile source: 5582.1.00007f0244011000.00007f024401f000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 5585.1.00007f0244011000.00007f024401f000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: Process Memory Space: boatnet.spc.elf PID: 5582, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: boatnet.spc.elf PID: 5585, type: MEMORYSTR
        ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
        Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath InterceptionDirect Volume Access1
        OS Credential Dumping
        11
        Security Software Discovery
        Remote ServicesData from Local System1
        Non-Standard Port
        Exfiltration Over Other Network Medium1
        Service Stop
        CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
        Non-Application Layer Protocol
        Exfiltration Over BluetoothNetwork Denial of Service
        Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
        Application Layer Protocol
        Automated ExfiltrationData Encrypted for Impact
        No configs have been found
        Hide Legend

        Legend:

        • Process
        • Signature
        • Created File
        • DNS/IP Info
        • Is Dropped
        • Number of created Files
        • Is malicious
        • Internet
        behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1581786 Sample: boatnet.spc.elf Startdate: 29/12/2024 Architecture: LINUX Score: 76 22 109.71.252.43, 3778, 56774, 56776 ATLANTIACLOUDNL Germany 2->22 24 daisy.ubuntu.com 2->24 26 Malicious sample detected (through community Yara rule) 2->26 28 Antivirus / Scanner detection for submitted sample 2->28 30 Multi AV Scanner detection for submitted file 2->30 32 Yara detected Mirai 2->32 7 boatnet.spc.elf 2->7         started        9 xfce4-panel wrapper-2.0 2->9         started        11 xfce4-panel wrapper-2.0 2->11         started        13 4 other processes 2->13 signatures3 process4 process5 15 boatnet.spc.elf 7->15         started        18 boatnet.spc.elf 7->18         started        20 boatnet.spc.elf 7->20         started        signatures6 34 Sample tries to kill multiple processes (SIGKILL) 15->34

        This section contains all screenshots as thumbnails, including those not shown in the slideshow.


        windows-stand
        SourceDetectionScannerLabelLink
        boatnet.spc.elf65%ReversingLabsLinux.Backdoor.Mirai
        boatnet.spc.elf100%AviraEXP/ELF.Gafgyt.D
        No Antivirus matches
        No Antivirus matches
        No Antivirus matches
        NameIPActiveMaliciousAntivirus DetectionReputation
        daisy.ubuntu.com
        162.213.35.25
        truefalse
          high
          • No. of IPs < 25%
          • 25% < No. of IPs < 50%
          • 50% < No. of IPs < 75%
          • 75% < No. of IPs
          IPDomainCountryFlagASNASN NameMalicious
          109.71.252.43
          unknownGermany
          207770ATLANTIACLOUDNLfalse
          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
          109.71.252.43109.71.252.43-boatnet.sh4-2024-12-28T20_30_38.elfGet hashmaliciousMiraiBrowse
            boatnet.mpsl.elfGet hashmaliciousMiraiBrowse
              boatnet.mips.elfGet hashmaliciousMiraiBrowse
                boatnet.x86.elfGet hashmaliciousMiraiBrowse
                  109.71.252.43-boatnet.arm-2024-12-28T20_30_37.elfGet hashmaliciousMiraiBrowse
                    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                    daisy.ubuntu.com45.200.149.186-boatnet.mpsl-2024-12-28T01_23_00.elfGet hashmaliciousMiraiBrowse
                    • 162.213.35.25
                    45.200.149.186-boatnet.arm7-2024-12-28T01_23_01.elfGet hashmaliciousMiraiBrowse
                    • 162.213.35.24
                    45.200.149.186-boatnet.x86-2024-12-28T01_22_59.elfGet hashmaliciousMiraiBrowse
                    • 162.213.35.25
                    109.71.252.43-boatnet.sh4-2024-12-28T20_30_38.elfGet hashmaliciousMiraiBrowse
                    • 162.213.35.25
                    db0fa4b8db0333367e9bda3ab68b8042.arc.elfGet hashmaliciousGafgyt, MiraiBrowse
                    • 162.213.35.25
                    kqibeps.elfGet hashmaliciousMiraiBrowse
                    • 162.213.35.24
                    ngwa5.elfGet hashmaliciousMiraiBrowse
                    • 162.213.35.25
                    boatnet.mpsl.elfGet hashmaliciousMiraiBrowse
                    • 162.213.35.25
                    boatnet.x86.elfGet hashmaliciousMiraiBrowse
                    • 162.213.35.24
                    109.71.252.43-boatnet.arm-2024-12-28T20_30_37.elfGet hashmaliciousMiraiBrowse
                    • 162.213.35.24
                    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                    ATLANTIACLOUDNL109.71.252.43-boatnet.sh4-2024-12-28T20_30_38.elfGet hashmaliciousMiraiBrowse
                    • 109.71.252.43
                    boatnet.mpsl.elfGet hashmaliciousMiraiBrowse
                    • 109.71.252.43
                    boatnet.mips.elfGet hashmaliciousMiraiBrowse
                    • 109.71.252.43
                    boatnet.x86.elfGet hashmaliciousMiraiBrowse
                    • 109.71.252.43
                    109.71.252.43-boatnet.arm-2024-12-28T20_30_37.elfGet hashmaliciousMiraiBrowse
                    • 109.71.252.43
                    REQUEST FOR QUOTATION.docx.docGet hashmaliciousAgentTesla, PureLog StealerBrowse
                    • 109.71.253.25
                    https://cranky-almeida.109-71-253-24.plesk.page/app/Get hashmaliciousUnknownBrowse
                    • 109.71.253.24
                    java.exeGet hashmaliciousUnknownBrowse
                    • 109.71.252.45
                    Dhl Waybill Document.docGet hashmaliciousFormBookBrowse
                    • 109.71.253.24
                    No context
                    No context
                    No created / dropped files found
                    File type:ELF 32-bit MSB executable, SPARC, version 1 (SYSV), statically linked, stripped
                    Entropy (8bit):6.0664096378589285
                    TrID:
                    • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                    File name:boatnet.spc.elf
                    File size:58'376 bytes
                    MD5:f5a5456d440cc82220128f62a70172b4
                    SHA1:d3a0361a7e6d42eee17fcc67aa04687d6143d104
                    SHA256:6e7a50cdd079411288c416a0e8e80978f68d1f31be43be83a831b77f9502d123
                    SHA512:a72b223349638abc963a7c822dbc94cda0431ccef3e573df6d937983997c4c70b9435db8546ecf8a41b7c50560feacff2f05c489daaab9cc930116803472a295
                    SSDEEP:768:RqowmZPu9wtnfbltWgC6BSJsBcfDSTFIuQKqgESnmC/xO+KpAwy:RqtmZPuutfbltZFBSJsBcfDSTFI+BEy
                    TLSH:42432921B63A1F13D0E0A47D21FB4B59B1A15ADE26A4C64E7D720F4FFF11680A943DB8
                    File Content Preview:.ELF...........................4...x.....4. ...(.......................................................8...P........dt.Q................................@..(....@.2.................#.....b8..`.....!..... ...@.....".........`......$ ... ...@...........`....

                    ELF header

                    Class:ELF32
                    Data:2's complement, big endian
                    Version:1 (current)
                    Machine:Sparc
                    Version Number:0x1
                    Type:EXEC (Executable file)
                    OS/ABI:UNIX - System V
                    ABI Version:0
                    Entry Point Address:0x101a4
                    Flags:0x0
                    ELF Header Size:52
                    Program Header Offset:52
                    Program Header Size:32
                    Number of Program Headers:3
                    Section Header Offset:57976
                    Section Header Size:40
                    Number of Section Headers:10
                    Header String Table Index:9
                    NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                    NULL0x00x00x00x00x0000
                    .initPROGBITS0x100940x940x1c0x00x6AX004
                    .textPROGBITS0x100b00xb00xc8880x00x6AX004
                    .finiPROGBITS0x1c9380xc9380x140x00x6AX004
                    .rodataPROGBITS0x1c9500xc9500x11b00x00x2A008
                    .ctorsPROGBITS0x2e0000xe0000x80x00x3WA004
                    .dtorsPROGBITS0x2e0080xe0080x80x00x3WA004
                    .dataPROGBITS0x2e0180xe0180x2200x00x3WA008
                    .bssNOBITS0x2e2380xe2380x3180x00x3WA004
                    .shstrtabSTRTAB0x00xe2380x3e0x00x0001
                    TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                    LOAD0x00x100000x100000xdb000xdb006.17290x5R E0x10000.init .text .fini .rodata
                    LOAD0xe0000x2e0000x2e0000x2380x5502.92290x6RW 0x10000.ctors .dtors .data .bss
                    GNU_STACK0x00x00x00x00x00.00000x6RW 0x4
                    TimestampSource PortDest PortSource IPDest IP
                    Dec 29, 2024 00:10:33.979821920 CET567743778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:10:34.099421978 CET377856774109.71.252.43192.168.2.14
                    Dec 29, 2024 00:10:34.099519014 CET567743778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:10:34.119649887 CET567743778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:10:34.239253998 CET377856774109.71.252.43192.168.2.14
                    Dec 29, 2024 00:10:34.239345074 CET567743778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:10:34.359030962 CET377856774109.71.252.43192.168.2.14
                    Dec 29, 2024 00:10:35.449604988 CET377856774109.71.252.43192.168.2.14
                    Dec 29, 2024 00:10:35.449717999 CET567743778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:10:35.449940920 CET567743778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:10:35.450843096 CET567763778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:10:35.570307970 CET377856776109.71.252.43192.168.2.14
                    Dec 29, 2024 00:10:35.570378065 CET567763778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:10:35.572345972 CET567763778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:10:35.691850901 CET377856776109.71.252.43192.168.2.14
                    Dec 29, 2024 00:10:35.691904068 CET567763778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:10:35.811435938 CET377856776109.71.252.43192.168.2.14
                    Dec 29, 2024 00:10:36.866666079 CET377856776109.71.252.43192.168.2.14
                    Dec 29, 2024 00:10:36.866766930 CET567763778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:10:36.866766930 CET567763778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:10:36.867338896 CET567783778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:10:36.986888885 CET377856778109.71.252.43192.168.2.14
                    Dec 29, 2024 00:10:36.986974955 CET567783778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:10:36.988929033 CET567783778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:10:37.108686924 CET377856778109.71.252.43192.168.2.14
                    Dec 29, 2024 00:10:37.108769894 CET567783778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:10:37.228355885 CET377856778109.71.252.43192.168.2.14
                    Dec 29, 2024 00:10:38.283013105 CET377856778109.71.252.43192.168.2.14
                    Dec 29, 2024 00:10:38.283087015 CET567783778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:10:38.283132076 CET567783778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:10:38.283960104 CET567803778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:10:38.403512955 CET377856780109.71.252.43192.168.2.14
                    Dec 29, 2024 00:10:38.403587103 CET567803778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:10:38.405401945 CET567803778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:10:38.524856091 CET377856780109.71.252.43192.168.2.14
                    Dec 29, 2024 00:10:38.524915934 CET567803778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:10:38.644443989 CET377856780109.71.252.43192.168.2.14
                    Dec 29, 2024 00:10:39.706293106 CET377856780109.71.252.43192.168.2.14
                    Dec 29, 2024 00:10:39.706352949 CET567803778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:10:39.706393957 CET567803778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:10:39.707531929 CET567823778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:10:39.827105999 CET377856782109.71.252.43192.168.2.14
                    Dec 29, 2024 00:10:39.827203035 CET567823778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:10:39.828900099 CET567823778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:10:39.948354959 CET377856782109.71.252.43192.168.2.14
                    Dec 29, 2024 00:10:39.948498964 CET567823778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:10:40.068037987 CET377856782109.71.252.43192.168.2.14
                    Dec 29, 2024 00:10:41.131647110 CET377856782109.71.252.43192.168.2.14
                    Dec 29, 2024 00:10:41.131778002 CET567823778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:10:41.131800890 CET567823778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:10:41.139089108 CET567843778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:10:41.258543968 CET377856784109.71.252.43192.168.2.14
                    Dec 29, 2024 00:10:41.258734941 CET567843778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:10:41.263724089 CET567843778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:10:41.383672953 CET377856784109.71.252.43192.168.2.14
                    Dec 29, 2024 00:10:41.383785009 CET567843778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:10:41.504978895 CET377856784109.71.252.43192.168.2.14
                    Dec 29, 2024 00:10:42.517195940 CET377856784109.71.252.43192.168.2.14
                    Dec 29, 2024 00:10:42.517452002 CET567843778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:10:42.517452955 CET567843778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:10:42.517942905 CET567863778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:10:42.637578011 CET377856786109.71.252.43192.168.2.14
                    Dec 29, 2024 00:10:42.637837887 CET567863778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:10:42.638577938 CET567863778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:10:42.758013010 CET377856786109.71.252.43192.168.2.14
                    Dec 29, 2024 00:10:42.758229971 CET567863778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:10:42.877744913 CET377856786109.71.252.43192.168.2.14
                    Dec 29, 2024 00:10:43.980241060 CET377856786109.71.252.43192.168.2.14
                    Dec 29, 2024 00:10:43.980283976 CET567863778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:10:43.980317116 CET567863778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:10:43.980643034 CET567883778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:10:44.100400925 CET377856788109.71.252.43192.168.2.14
                    Dec 29, 2024 00:10:44.100636005 CET567883778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:10:44.101212978 CET567883778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:10:44.222418070 CET377856788109.71.252.43192.168.2.14
                    Dec 29, 2024 00:10:44.222543955 CET567883778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:10:44.343579054 CET377856788109.71.252.43192.168.2.14
                    Dec 29, 2024 00:10:45.398952961 CET377856788109.71.252.43192.168.2.14
                    Dec 29, 2024 00:10:45.399291039 CET567883778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:10:45.399291992 CET567883778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:10:45.399717093 CET567903778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:10:45.519335032 CET377856790109.71.252.43192.168.2.14
                    Dec 29, 2024 00:10:45.519582987 CET567903778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:10:45.520225048 CET567903778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:10:45.639863968 CET377856790109.71.252.43192.168.2.14
                    Dec 29, 2024 00:10:45.640234947 CET567903778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:10:45.759804964 CET377856790109.71.252.43192.168.2.14
                    Dec 29, 2024 00:10:46.861804008 CET377856790109.71.252.43192.168.2.14
                    Dec 29, 2024 00:10:46.861939907 CET567903778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:10:46.861995935 CET567903778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:10:46.862549067 CET567923778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:10:46.983566046 CET377856792109.71.252.43192.168.2.14
                    Dec 29, 2024 00:10:46.983648062 CET567923778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:10:46.984327078 CET567923778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:10:47.105501890 CET377856792109.71.252.43192.168.2.14
                    Dec 29, 2024 00:10:47.105583906 CET567923778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:10:47.226619005 CET377856792109.71.252.43192.168.2.14
                    Dec 29, 2024 00:10:48.235858917 CET377856792109.71.252.43192.168.2.14
                    Dec 29, 2024 00:10:48.236032963 CET567923778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:10:48.236063957 CET567923778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:10:48.236565113 CET567943778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:10:48.356355906 CET377856794109.71.252.43192.168.2.14
                    Dec 29, 2024 00:10:48.356472969 CET567943778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:10:48.357254982 CET567943778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:10:48.477993965 CET377856794109.71.252.43192.168.2.14
                    Dec 29, 2024 00:10:48.478233099 CET567943778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:10:48.599277020 CET377856794109.71.252.43192.168.2.14
                    Dec 29, 2024 00:10:49.608778954 CET377856794109.71.252.43192.168.2.14
                    Dec 29, 2024 00:10:49.608943939 CET567943778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:10:49.609065056 CET567943778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:10:49.609728098 CET567963778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:10:49.729218006 CET377856796109.71.252.43192.168.2.14
                    Dec 29, 2024 00:10:49.729322910 CET567963778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:10:49.729979992 CET567963778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:10:49.850857019 CET377856796109.71.252.43192.168.2.14
                    Dec 29, 2024 00:10:49.850946903 CET567963778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:10:49.971771955 CET377856796109.71.252.43192.168.2.14
                    Dec 29, 2024 00:10:51.087491989 CET377856796109.71.252.43192.168.2.14
                    Dec 29, 2024 00:10:51.087626934 CET567963778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:10:51.087678909 CET567963778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:10:51.088329077 CET567983778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:10:51.209194899 CET377856798109.71.252.43192.168.2.14
                    Dec 29, 2024 00:10:51.209311962 CET567983778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:10:51.210139036 CET567983778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:10:51.331218958 CET377856798109.71.252.43192.168.2.14
                    Dec 29, 2024 00:10:51.331298113 CET567983778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:10:51.452414989 CET377856798109.71.252.43192.168.2.14
                    Dec 29, 2024 00:10:52.461186886 CET377856798109.71.252.43192.168.2.14
                    Dec 29, 2024 00:10:52.461289883 CET567983778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:10:52.461330891 CET567983778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:10:52.461787939 CET568003778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:10:52.583173037 CET377856800109.71.252.43192.168.2.14
                    Dec 29, 2024 00:10:52.583241940 CET568003778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:10:52.583862066 CET568003778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:10:52.706000090 CET377856800109.71.252.43192.168.2.14
                    Dec 29, 2024 00:10:52.706063032 CET568003778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:10:52.827611923 CET377856800109.71.252.43192.168.2.14
                    Dec 29, 2024 00:10:53.882334948 CET377856800109.71.252.43192.168.2.14
                    Dec 29, 2024 00:10:53.882596970 CET568003778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:10:53.882683039 CET568003778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:10:53.883429050 CET568023778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:10:54.002914906 CET377856802109.71.252.43192.168.2.14
                    Dec 29, 2024 00:10:54.003016949 CET568023778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:10:54.004168987 CET568023778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:10:54.123902082 CET377856802109.71.252.43192.168.2.14
                    Dec 29, 2024 00:10:54.124011993 CET568023778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:10:54.243489981 CET377856802109.71.252.43192.168.2.14
                    Dec 29, 2024 00:10:55.353626013 CET377856802109.71.252.43192.168.2.14
                    Dec 29, 2024 00:10:55.353749037 CET568023778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:10:55.353825092 CET568023778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:10:55.354373932 CET568043778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:10:55.473877907 CET377856804109.71.252.43192.168.2.14
                    Dec 29, 2024 00:10:55.474069118 CET568043778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:10:55.475291967 CET568043778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:10:55.594945908 CET377856804109.71.252.43192.168.2.14
                    Dec 29, 2024 00:10:55.595051050 CET568043778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:10:55.714566946 CET377856804109.71.252.43192.168.2.14
                    Dec 29, 2024 00:10:56.823448896 CET377856804109.71.252.43192.168.2.14
                    Dec 29, 2024 00:10:56.823613882 CET568043778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:10:56.823683023 CET568043778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:10:56.824299097 CET568063778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:10:56.943892002 CET377856806109.71.252.43192.168.2.14
                    Dec 29, 2024 00:10:56.944134951 CET568063778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:10:56.944958925 CET568063778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:10:57.064387083 CET377856806109.71.252.43192.168.2.14
                    Dec 29, 2024 00:10:57.064502954 CET568063778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:10:57.184079885 CET377856806109.71.252.43192.168.2.14
                    Dec 29, 2024 00:10:58.240626097 CET377856806109.71.252.43192.168.2.14
                    Dec 29, 2024 00:10:58.240955114 CET568063778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:10:58.240955114 CET568063778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:10:58.241390944 CET568083778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:10:58.360832930 CET377856808109.71.252.43192.168.2.14
                    Dec 29, 2024 00:10:58.360975027 CET568083778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:10:58.361912012 CET568083778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:10:58.735469103 CET568083778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:10:58.982316017 CET377856808109.71.252.43192.168.2.14
                    Dec 29, 2024 00:10:58.982335091 CET377856808109.71.252.43192.168.2.14
                    Dec 29, 2024 00:11:00.120311022 CET377856808109.71.252.43192.168.2.14
                    Dec 29, 2024 00:11:00.120443106 CET568083778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:11:00.120470047 CET568083778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:11:00.121156931 CET568103778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:11:00.241872072 CET377856810109.71.252.43192.168.2.14
                    Dec 29, 2024 00:11:00.241981983 CET568103778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:11:00.242974997 CET568103778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:11:00.364141941 CET377856810109.71.252.43192.168.2.14
                    Dec 29, 2024 00:11:00.364223003 CET568103778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:11:00.485490084 CET377856810109.71.252.43192.168.2.14
                    Dec 29, 2024 00:11:01.493737936 CET377856810109.71.252.43192.168.2.14
                    Dec 29, 2024 00:11:01.493992090 CET568103778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:11:01.493993044 CET568103778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:11:01.494504929 CET568123778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:11:01.615592957 CET377856812109.71.252.43192.168.2.14
                    Dec 29, 2024 00:11:01.615689039 CET568123778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:11:01.616566896 CET568123778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:11:01.737303972 CET377856812109.71.252.43192.168.2.14
                    Dec 29, 2024 00:11:01.737514973 CET568123778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:11:01.858457088 CET377856812109.71.252.43192.168.2.14
                    Dec 29, 2024 00:11:02.925136089 CET377856812109.71.252.43192.168.2.14
                    Dec 29, 2024 00:11:02.925379038 CET568123778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:11:02.925458908 CET568123778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:11:02.926274061 CET568143778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:11:03.045793056 CET377856814109.71.252.43192.168.2.14
                    Dec 29, 2024 00:11:03.045913935 CET568143778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:11:03.046863079 CET568143778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:11:03.166650057 CET377856814109.71.252.43192.168.2.14
                    Dec 29, 2024 00:11:03.166739941 CET568143778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:11:03.287985086 CET377856814109.71.252.43192.168.2.14
                    Dec 29, 2024 00:11:04.343945980 CET377856814109.71.252.43192.168.2.14
                    Dec 29, 2024 00:11:04.344180107 CET568143778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:11:04.344180107 CET568143778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:11:04.344810009 CET568163778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:11:04.464390993 CET377856816109.71.252.43192.168.2.14
                    Dec 29, 2024 00:11:04.464560032 CET568163778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:11:04.465284109 CET568163778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:11:04.584724903 CET377856816109.71.252.43192.168.2.14
                    Dec 29, 2024 00:11:04.584798098 CET568163778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:11:04.704395056 CET377856816109.71.252.43192.168.2.14
                    Dec 29, 2024 00:11:05.770893097 CET377856816109.71.252.43192.168.2.14
                    Dec 29, 2024 00:11:05.770987034 CET568163778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:11:05.771119118 CET568163778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:11:05.772028923 CET568183778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:11:05.891529083 CET377856818109.71.252.43192.168.2.14
                    Dec 29, 2024 00:11:05.891671896 CET568183778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:11:05.893065929 CET568183778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:11:06.012636900 CET377856818109.71.252.43192.168.2.14
                    Dec 29, 2024 00:11:06.012871027 CET568183778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:11:06.132479906 CET377856818109.71.252.43192.168.2.14
                    Dec 29, 2024 00:11:07.241297007 CET377856818109.71.252.43192.168.2.14
                    Dec 29, 2024 00:11:07.241519928 CET568183778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:11:07.241519928 CET568183778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:11:07.242141962 CET568203778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:11:07.363033056 CET377856820109.71.252.43192.168.2.14
                    Dec 29, 2024 00:11:07.363126040 CET568203778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:11:07.364207983 CET568203778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:11:07.485522985 CET377856820109.71.252.43192.168.2.14
                    Dec 29, 2024 00:11:07.485753059 CET568203778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:11:07.605335951 CET377856820109.71.252.43192.168.2.14
                    Dec 29, 2024 00:11:08.614938021 CET377856820109.71.252.43192.168.2.14
                    Dec 29, 2024 00:11:08.615190983 CET568203778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:11:08.615190983 CET568203778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:11:08.615984917 CET568223778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:11:08.737360001 CET377856822109.71.252.43192.168.2.14
                    Dec 29, 2024 00:11:08.737565041 CET568223778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:11:08.738420010 CET568223778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:11:08.859693050 CET377856822109.71.252.43192.168.2.14
                    Dec 29, 2024 00:11:08.859976053 CET568223778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:11:08.981147051 CET377856822109.71.252.43192.168.2.14
                    Dec 29, 2024 00:11:10.043567896 CET377856822109.71.252.43192.168.2.14
                    Dec 29, 2024 00:11:10.043874025 CET568223778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:11:10.043909073 CET568223778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:11:10.044641972 CET568243778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:11:10.165689945 CET377856824109.71.252.43192.168.2.14
                    Dec 29, 2024 00:11:10.165904999 CET568243778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:11:10.167104959 CET568243778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:11:10.288583040 CET377856824109.71.252.43192.168.2.14
                    Dec 29, 2024 00:11:10.288676023 CET568243778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:11:10.409521103 CET377856824109.71.252.43192.168.2.14
                    Dec 29, 2024 00:11:11.529087067 CET377856824109.71.252.43192.168.2.14
                    Dec 29, 2024 00:11:11.529381037 CET568243778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:11:11.529381037 CET568243778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:11:11.530214071 CET568263778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:11:11.650635958 CET377856826109.71.252.43192.168.2.14
                    Dec 29, 2024 00:11:11.650813103 CET568263778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:11:11.652157068 CET568263778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:11:11.772494078 CET377856826109.71.252.43192.168.2.14
                    Dec 29, 2024 00:11:11.772679090 CET568263778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:11:11.893395901 CET377856826109.71.252.43192.168.2.14
                    Dec 29, 2024 00:11:12.909646988 CET377856826109.71.252.43192.168.2.14
                    Dec 29, 2024 00:11:12.910005093 CET568263778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:11:12.910005093 CET568263778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:11:12.910634041 CET568283778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:11:13.030175924 CET377856828109.71.252.43192.168.2.14
                    Dec 29, 2024 00:11:13.030352116 CET568283778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:11:13.031250000 CET568283778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:11:13.150799036 CET377856828109.71.252.43192.168.2.14
                    Dec 29, 2024 00:11:13.151010036 CET568283778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:11:13.270664930 CET377856828109.71.252.43192.168.2.14
                    Dec 29, 2024 00:11:14.381102085 CET377856828109.71.252.43192.168.2.14
                    Dec 29, 2024 00:11:14.381342888 CET568283778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:11:14.381370068 CET568283778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:11:14.381963968 CET568303778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:11:14.501518011 CET377856830109.71.252.43192.168.2.14
                    Dec 29, 2024 00:11:14.501887083 CET568303778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:11:14.502968073 CET568303778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:11:14.622490883 CET377856830109.71.252.43192.168.2.14
                    Dec 29, 2024 00:11:14.622832060 CET568303778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:11:14.742641926 CET377856830109.71.252.43192.168.2.14
                    Dec 29, 2024 00:11:15.805120945 CET377856830109.71.252.43192.168.2.14
                    Dec 29, 2024 00:11:15.805409908 CET568303778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:11:15.805409908 CET568303778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:11:15.806220055 CET568323778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:11:15.925806046 CET377856832109.71.252.43192.168.2.14
                    Dec 29, 2024 00:11:15.925915003 CET568323778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:11:15.927231073 CET568323778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:11:16.272731066 CET377856832109.71.252.43192.168.2.14
                    Dec 29, 2024 00:11:16.272995949 CET568323778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:11:16.392817020 CET377856832109.71.252.43192.168.2.14
                    Dec 29, 2024 00:11:17.449668884 CET377856832109.71.252.43192.168.2.14
                    Dec 29, 2024 00:11:17.449934006 CET568323778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:11:17.449934006 CET568323778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:11:17.450659990 CET568343778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:11:17.570316076 CET377856834109.71.252.43192.168.2.14
                    Dec 29, 2024 00:11:17.570420027 CET568343778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:11:17.571753979 CET568343778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:11:17.692589045 CET377856834109.71.252.43192.168.2.14
                    Dec 29, 2024 00:11:17.692833900 CET568343778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:11:17.813913107 CET377856834109.71.252.43192.168.2.14
                    Dec 29, 2024 00:11:18.932209969 CET377856834109.71.252.43192.168.2.14
                    Dec 29, 2024 00:11:18.932554007 CET568343778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:11:18.932554007 CET568343778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:11:18.933240891 CET568363778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:11:19.052824974 CET377856836109.71.252.43192.168.2.14
                    Dec 29, 2024 00:11:19.053055048 CET568363778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:11:19.054153919 CET568363778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:11:19.173715115 CET377856836109.71.252.43192.168.2.14
                    Dec 29, 2024 00:11:19.173921108 CET568363778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:11:19.293531895 CET377856836109.71.252.43192.168.2.14
                    Dec 29, 2024 00:11:20.310173988 CET377856836109.71.252.43192.168.2.14
                    Dec 29, 2024 00:11:20.310355902 CET568363778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:11:20.310355902 CET568363778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:11:20.310836077 CET568383778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:11:20.431488991 CET377856838109.71.252.43192.168.2.14
                    Dec 29, 2024 00:11:20.431647062 CET568383778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:11:20.432411909 CET568383778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:11:20.551904917 CET377856838109.71.252.43192.168.2.14
                    Dec 29, 2024 00:11:20.551974058 CET568383778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:11:20.671463966 CET377856838109.71.252.43192.168.2.14
                    Dec 29, 2024 00:11:21.774882078 CET377856838109.71.252.43192.168.2.14
                    Dec 29, 2024 00:11:21.775161028 CET568383778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:11:21.775161028 CET568383778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:11:21.775886059 CET568403778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:11:21.896950960 CET377856840109.71.252.43192.168.2.14
                    Dec 29, 2024 00:11:21.897192955 CET568403778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:11:21.898268938 CET568403778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:11:22.019438028 CET377856840109.71.252.43192.168.2.14
                    Dec 29, 2024 00:11:22.019639969 CET568403778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:11:22.141025066 CET377856840109.71.252.43192.168.2.14
                    Dec 29, 2024 00:11:23.202795982 CET377856840109.71.252.43192.168.2.14
                    Dec 29, 2024 00:11:23.203032017 CET568403778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:11:23.203032017 CET568403778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:11:23.203742981 CET568423778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:11:23.323204041 CET377856842109.71.252.43192.168.2.14
                    Dec 29, 2024 00:11:23.323318958 CET568423778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:11:23.324765921 CET568423778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:11:23.444215059 CET377856842109.71.252.43192.168.2.14
                    Dec 29, 2024 00:11:23.444438934 CET568423778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:11:23.563973904 CET377856842109.71.252.43192.168.2.14
                    Dec 29, 2024 00:11:33.334276915 CET568423778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:11:33.455421925 CET377856842109.71.252.43192.168.2.14
                    Dec 29, 2024 00:11:33.745189905 CET377856842109.71.252.43192.168.2.14
                    Dec 29, 2024 00:11:33.745299101 CET568423778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:12:33.779726028 CET568423778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:12:33.900120020 CET377856842109.71.252.43192.168.2.14
                    Dec 29, 2024 00:12:34.189989090 CET377856842109.71.252.43192.168.2.14
                    Dec 29, 2024 00:12:34.190119028 CET568423778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:13:21.213706970 CET4522453192.168.2.148.8.8.8
                    Dec 29, 2024 00:13:21.333261013 CET53452248.8.8.8192.168.2.14
                    Dec 29, 2024 00:13:21.333403111 CET4522453192.168.2.148.8.8.8
                    Dec 29, 2024 00:13:21.333403111 CET4522453192.168.2.148.8.8.8
                    Dec 29, 2024 00:13:21.337282896 CET4522453192.168.2.148.8.8.8
                    Dec 29, 2024 00:13:21.454680920 CET53452248.8.8.8192.168.2.14
                    Dec 29, 2024 00:13:21.458471060 CET53452248.8.8.8192.168.2.14
                    Dec 29, 2024 00:13:22.511609077 CET53452248.8.8.8192.168.2.14
                    Dec 29, 2024 00:13:22.511668921 CET4522453192.168.2.148.8.8.8
                    Dec 29, 2024 00:13:22.762207031 CET53452248.8.8.8192.168.2.14
                    Dec 29, 2024 00:13:22.769237995 CET4522453192.168.2.148.8.8.8
                    Dec 29, 2024 00:13:24.552165031 CET53452248.8.8.8192.168.2.14
                    Dec 29, 2024 00:13:24.552311897 CET4522453192.168.2.148.8.8.8
                    Dec 29, 2024 00:13:24.786916018 CET53452248.8.8.8192.168.2.14
                    Dec 29, 2024 00:13:34.233429909 CET568423778192.168.2.14109.71.252.43
                    Dec 29, 2024 00:13:34.353074074 CET377856842109.71.252.43192.168.2.14
                    Dec 29, 2024 00:13:34.642977953 CET377856842109.71.252.43192.168.2.14
                    Dec 29, 2024 00:13:34.643102884 CET568423778192.168.2.14109.71.252.43
                    TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                    Dec 29, 2024 00:13:21.333403111 CET192.168.2.148.8.8.80xa62aStandard query (0)daisy.ubuntu.comA (IP address)IN (0x0001)false
                    Dec 29, 2024 00:13:21.337282896 CET192.168.2.148.8.8.80x3be2Standard query (0)daisy.ubuntu.com28IN (0x0001)false
                    TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                    Dec 29, 2024 00:13:22.762207031 CET8.8.8.8192.168.2.140xa62aNo error (0)daisy.ubuntu.com162.213.35.25A (IP address)IN (0x0001)false
                    Dec 29, 2024 00:13:22.762207031 CET8.8.8.8192.168.2.140xa62aNo error (0)daisy.ubuntu.com162.213.35.24A (IP address)IN (0x0001)false

                    System Behavior

                    Start time (UTC):23:10:33
                    Start date (UTC):28/12/2024
                    Path:/tmp/boatnet.spc.elf
                    Arguments:/tmp/boatnet.spc.elf
                    File size:4379400 bytes
                    MD5 hash:7dc1c0e23cd5e102bb12e5c29403410e

                    Start time (UTC):23:10:33
                    Start date (UTC):28/12/2024
                    Path:/tmp/boatnet.spc.elf
                    Arguments:-
                    File size:4379400 bytes
                    MD5 hash:7dc1c0e23cd5e102bb12e5c29403410e

                    Start time (UTC):23:10:33
                    Start date (UTC):28/12/2024
                    Path:/tmp/boatnet.spc.elf
                    Arguments:-
                    File size:4379400 bytes
                    MD5 hash:7dc1c0e23cd5e102bb12e5c29403410e

                    Start time (UTC):23:10:33
                    Start date (UTC):28/12/2024
                    Path:/tmp/boatnet.spc.elf
                    Arguments:-
                    File size:4379400 bytes
                    MD5 hash:7dc1c0e23cd5e102bb12e5c29403410e

                    Start time (UTC):23:10:33
                    Start date (UTC):28/12/2024
                    Path:/usr/bin/xfce4-panel
                    Arguments:-
                    File size:375768 bytes
                    MD5 hash:a15b657c7d54ac1385f1f15004ea6784

                    Start time (UTC):23:10:33
                    Start date (UTC):28/12/2024
                    Path:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
                    Arguments:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libsystray.so 6 12582920 systray "Notification Area" "Area where notification icons appear"
                    File size:35136 bytes
                    MD5 hash:ac0b8a906f359a8ae102244738682e76

                    Start time (UTC):23:10:33
                    Start date (UTC):28/12/2024
                    Path:/usr/bin/xfce4-panel
                    Arguments:-
                    File size:375768 bytes
                    MD5 hash:a15b657c7d54ac1385f1f15004ea6784

                    Start time (UTC):23:10:33
                    Start date (UTC):28/12/2024
                    Path:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
                    Arguments:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libstatusnotifier.so 7 12582921 statusnotifier "Status Notifier Plugin" "Provides a panel area for status notifier items (application indicators)"
                    File size:35136 bytes
                    MD5 hash:ac0b8a906f359a8ae102244738682e76

                    Start time (UTC):23:10:33
                    Start date (UTC):28/12/2024
                    Path:/usr/bin/xfce4-panel
                    Arguments:-
                    File size:375768 bytes
                    MD5 hash:a15b657c7d54ac1385f1f15004ea6784

                    Start time (UTC):23:10:33
                    Start date (UTC):28/12/2024
                    Path:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
                    Arguments:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libpulseaudio-plugin.so 8 12582922 pulseaudio "PulseAudio Plugin" "Adjust the audio volume of the PulseAudio sound system"
                    File size:35136 bytes
                    MD5 hash:ac0b8a906f359a8ae102244738682e76

                    Start time (UTC):23:10:33
                    Start date (UTC):28/12/2024
                    Path:/usr/bin/xfce4-panel
                    Arguments:-
                    File size:375768 bytes
                    MD5 hash:a15b657c7d54ac1385f1f15004ea6784

                    Start time (UTC):23:10:33
                    Start date (UTC):28/12/2024
                    Path:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
                    Arguments:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libxfce4powermanager.so 9 12582923 power-manager-plugin "Power Manager Plugin" "Display the battery levels of your devices and control the brightness of your display"
                    File size:35136 bytes
                    MD5 hash:ac0b8a906f359a8ae102244738682e76

                    Start time (UTC):23:10:34
                    Start date (UTC):28/12/2024
                    Path:/usr/bin/xfce4-panel
                    Arguments:-
                    File size:375768 bytes
                    MD5 hash:a15b657c7d54ac1385f1f15004ea6784

                    Start time (UTC):23:10:34
                    Start date (UTC):28/12/2024
                    Path:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
                    Arguments:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libnotification-plugin.so 10 12582924 notification-plugin "Notification Plugin" "Notification plugin for the Xfce panel"
                    File size:35136 bytes
                    MD5 hash:ac0b8a906f359a8ae102244738682e76

                    Start time (UTC):23:10:34
                    Start date (UTC):28/12/2024
                    Path:/usr/bin/xfce4-panel
                    Arguments:-
                    File size:375768 bytes
                    MD5 hash:a15b657c7d54ac1385f1f15004ea6784

                    Start time (UTC):23:10:34
                    Start date (UTC):28/12/2024
                    Path:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
                    Arguments:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libactions.so 14 12582925 actions "Action Buttons" "Log out, lock or other system actions"
                    File size:35136 bytes
                    MD5 hash:ac0b8a906f359a8ae102244738682e76