Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
spc.elf

Overview

General Information

Sample name:spc.elf
Analysis ID:1582130
MD5:e2cc455ffa4a01e70b803a10dce92d82
SHA1:69bfde17d1a670c25067528124edb2a5a089b35b
SHA256:df45feb29996518c5b50c2aad7ad61a089f75dc91a1d453117b4dc0d9942eb2f
Tags:elfuser-abuse_ch
Infos:

Detection

Score:56
Range:0 - 100
Whitelisted:false

Signatures

Multi AV Scanner detection for submitted file
Suricata IDS alerts for network traffic
Detected TCP or UDP traffic on non-standard ports
Sample has stripped symbol table
Sample listens on a socket
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1582130
Start date and time:2024-12-30 02:39:09 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 5m 23s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:spc.elf
Detection:MAL
Classification:mal56.linELF@0/0@2/0
Command:/tmp/spc.elf
PID:5870
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
$UICIDEBOY$
Standard Error:
  • system is lnxubuntu20
  • spc.elf (PID: 5870, Parent: 5793, MD5: 7dc1c0e23cd5e102bb12e5c29403410e) Arguments: /tmp/spc.elf
    • spc.elf New Fork (PID: 5872, Parent: 5870)
  • cleanup
No yara matches
TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
2024-12-30T02:40:25.705833+010028498161A Network Trojan was detected192.168.2.154080685.239.34.1346666TCP

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: spc.elfVirustotal: Detection: 22%Perma Link
Source: spc.elfReversingLabs: Detection: 26%

Networking

barindex
Source: Network trafficSuricata IDS: 2849816 - Severity 1 - ETPRO MALWARE ELF/Multiverze CnC Checkin : 192.168.2.15:40806 -> 85.239.34.134:6666
Source: global trafficTCP traffic: 192.168.2.15:40806 -> 85.239.34.134:6666
Source: /tmp/spc.elf (PID: 5870)Socket: 0.0.0.0:9902Jump to behavior
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: global trafficDNS traffic detected: DNS query: daisy.ubuntu.com
Source: ELF static info symbol of initial sample.symtab present: no
Source: classification engineClassification label: mal56.linELF@0/0@2/0
Source: /tmp/spc.elf (PID: 5870)Queries kernel information via 'uname': Jump to behavior
Source: spc.elf, 5870.1.000055ac30691000.000055ac306f6000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/sparc
Source: spc.elf, 5870.1.000055ac30691000.000055ac306f6000.rw-.sdmpBinary or memory string: U!/etc/qemu-binfmt/sparc
Source: spc.elf, 5870.1.00007ffef8728000.00007ffef8749000.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-sparc/tmp/spc.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/spc.elf
Source: spc.elf, 5870.1.00007ffef8728000.00007ffef8749000.rw-.sdmpBinary or memory string: /usr/bin/qemu-sparc
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath InterceptionDirect Volume AccessOS Credential Dumping11
Security Software Discovery
Remote ServicesData from Local System1
Non-Standard Port
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
SourceDetectionScannerLabelLink
spc.elf22%VirustotalBrowse
spc.elf26%ReversingLabsLinux.Backdoor.Gafgyt
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
daisy.ubuntu.com
162.213.35.24
truefalse
    high
    • No. of IPs < 25%
    • 25% < No. of IPs < 50%
    • 50% < No. of IPs < 75%
    • 75% < No. of IPs
    IPDomainCountryFlagASNASN NameMalicious
    85.239.34.134
    unknownRussian Federation
    134121RAINBOW-HKRainbownetworklimitedHKtrue
    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
    85.239.34.134212.64.215.71-arm-2024-12-25T12_31_55.elfGet hashmaliciousUnknownBrowse
      ppc.elfGet hashmaliciousMiraiBrowse
        sh4.elfGet hashmaliciousMiraiBrowse
          mips.elfGet hashmaliciousMiraiBrowse
            spc.elfGet hashmaliciousMiraiBrowse
              arm6.elfGet hashmaliciousMiraiBrowse
                arm.elfGet hashmaliciousMiraiBrowse
                  m68k.elfGet hashmaliciousMiraiBrowse
                    arm7.elfGet hashmaliciousMiraiBrowse
                      x86.elfGet hashmaliciousMiraiBrowse
                        MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                        daisy.ubuntu.comrebirth.arm4.elfGet hashmaliciousGafgytBrowse
                        • 162.213.35.24
                        dlr.arm5.elfGet hashmaliciousUnknownBrowse
                        • 162.213.35.24
                        rebirth.arm5.elfGet hashmaliciousGafgytBrowse
                        • 162.213.35.24
                        rebirth.i686.elfGet hashmaliciousGafgytBrowse
                        • 162.213.35.25
                        loligang.m68k.elfGet hashmaliciousMiraiBrowse
                        • 162.213.35.24
                        dlr.arm.elfGet hashmaliciousUnknownBrowse
                        • 162.213.35.25
                        loligang.arm5.elfGet hashmaliciousMiraiBrowse
                        • 162.213.35.24
                        loligang.arm6.elfGet hashmaliciousMiraiBrowse
                        • 162.213.35.24
                        mips.elfGet hashmaliciousMirai, MoobotBrowse
                        • 162.213.35.25
                        sh4.elfGet hashmaliciousMirai, MoobotBrowse
                        • 162.213.35.25
                        MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                        RAINBOW-HKRainbownetworklimitedHK1C6ljtnwXP.exeGet hashmaliciousLummaCBrowse
                        • 85.239.54.77
                        212.64.215.71-arm-2024-12-25T12_31_55.elfGet hashmaliciousUnknownBrowse
                        • 85.239.34.134
                        armv5l.elfGet hashmaliciousUnknownBrowse
                        • 185.152.92.158
                        statmentt.exeGet hashmaliciousScreenConnect ToolBrowse
                        • 85.239.34.190
                        ppc.elfGet hashmaliciousMiraiBrowse
                        • 85.239.34.134
                        sh4.elfGet hashmaliciousMiraiBrowse
                        • 85.239.34.134
                        mips.elfGet hashmaliciousMiraiBrowse
                        • 85.239.34.134
                        spc.elfGet hashmaliciousMiraiBrowse
                        • 85.239.34.134
                        arm6.elfGet hashmaliciousMiraiBrowse
                        • 85.239.34.134
                        arm.elfGet hashmaliciousMiraiBrowse
                        • 85.239.34.134
                        No context
                        No context
                        No created / dropped files found
                        File type:ELF 32-bit MSB executable, SPARC, version 1 (SYSV), statically linked, stripped
                        Entropy (8bit):5.669563179131732
                        TrID:
                        • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                        File name:spc.elf
                        File size:46'576 bytes
                        MD5:e2cc455ffa4a01e70b803a10dce92d82
                        SHA1:69bfde17d1a670c25067528124edb2a5a089b35b
                        SHA256:df45feb29996518c5b50c2aad7ad61a089f75dc91a1d453117b4dc0d9942eb2f
                        SHA512:9acee01b5789df735ab0e61cc64e84582d38c1909d5ad9fb79265137aa4de58e58cfd088552e33e3a92477b8a01da5684c384ded187a39515eb1baf4136ebb34
                        SSDEEP:384:W0lZgIt0pOLOdKCCFU+pd5/uyePHUPqUsGHQ1Yerz7lG66SiS2GAn5o/KtyX+Smk:nngInoKCCO+V/3f6XP2GIeASmnqE3o/
                        TLSH:0923E8A27BA90B27C4F0957890E7A36FB3FA47892434860B7E914D4C7B98D7131533E9
                        File Content Preview:.ELF...........................4.........4. ...(.......................................................h..2@...............H...H...H................dt.Q................................@..(....@.)h................#..l..ch..`.....!..l..!t..@.....".........`

                        ELF header

                        Class:ELF32
                        Data:2's complement, big endian
                        Version:1 (current)
                        Machine:Sparc
                        Version Number:0x1
                        Type:EXEC (Executable file)
                        OS/ABI:UNIX - System V
                        ABI Version:0
                        Entry Point Address:0x101c4
                        Flags:0x0
                        ELF Header Size:52
                        Program Header Offset:52
                        Program Header Size:32
                        Number of Program Headers:4
                        Section Header Offset:46016
                        Section Header Size:40
                        Number of Section Headers:14
                        Header String Table Index:13
                        NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                        NULL0x00x00x00x00x0000
                        .initPROGBITS0x100b40xb40x1c0x00x6AX004
                        .textPROGBITS0x100d00xd00xa5d80x00x6AX004
                        .finiPROGBITS0x1a6a80xa6a80x140x00x6AX004
                        .rodataPROGBITS0x1a6c00xa6c00x4c80x00x2A008
                        .eh_framePROGBITS0x1b0000xb0000x480x00x3WA004
                        .tbssNOBITS0x1b0480xb0480x80x00x403WAT004
                        .ctorsPROGBITS0x1b0480xb0480x80x00x3WA004
                        .dtorsPROGBITS0x1b0500xb0500x80x00x3WA004
                        .jcrPROGBITS0x1b0580xb0580x40x00x3WA004
                        .gotPROGBITS0x1b05c0xb05c0x1140x40x3WA004
                        .dataPROGBITS0x1b1700xb1700x1f80x00x3WA004
                        .bssNOBITS0x1b3680xb3680x2ed80x00x3WA008
                        .shstrtabSTRTAB0x00xb3680x580x00x0001
                        TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                        LOAD0x00x100000x100000xab880xab885.77220x5R E0x1000.init .text .fini .rodata
                        LOAD0xb0000x1b0000x1b0000x3680x32404.21750x6RW 0x1000.eh_frame .tbss .ctors .dtors .jcr .got .data .bss
                        TLS0xb0480x1b0480x1b0480x00x80.00000x4R 0x4.tbss
                        GNU_STACK0x00x00x00x00x00.00000x6RW 0x4
                        TimestampSIDSignatureSeveritySource IPSource PortDest IPDest PortProtocol
                        2024-12-30T02:40:25.705833+01002849816ETPRO MALWARE ELF/Multiverze CnC Checkin1192.168.2.154080685.239.34.1346666TCP
                        TimestampSource PortDest PortSource IPDest IP
                        Dec 30, 2024 02:40:25.671957016 CET408066666192.168.2.1585.239.34.134
                        Dec 30, 2024 02:40:25.677047968 CET66664080685.239.34.134192.168.2.15
                        Dec 30, 2024 02:40:25.677113056 CET408066666192.168.2.1585.239.34.134
                        Dec 30, 2024 02:40:25.705832958 CET408066666192.168.2.1585.239.34.134
                        Dec 30, 2024 02:40:25.710684061 CET66664080685.239.34.134192.168.2.15
                        Dec 30, 2024 02:40:27.649667025 CET66664080685.239.34.134192.168.2.15
                        Dec 30, 2024 02:40:27.649908066 CET408066666192.168.2.1585.239.34.134
                        Dec 30, 2024 02:40:27.650289059 CET408066666192.168.2.1585.239.34.134
                        Dec 30, 2024 02:40:27.655139923 CET66664080685.239.34.134192.168.2.15
                        Dec 30, 2024 02:40:30.292246103 CET66664080685.239.34.134192.168.2.15
                        Dec 30, 2024 02:40:30.292519093 CET408066666192.168.2.1585.239.34.134
                        Dec 30, 2024 02:40:30.292565107 CET408066666192.168.2.1585.239.34.134
                        Dec 30, 2024 02:40:30.297451973 CET66664080685.239.34.134192.168.2.15
                        Dec 30, 2024 02:40:35.361032963 CET66664080685.239.34.134192.168.2.15
                        Dec 30, 2024 02:40:35.361437082 CET408066666192.168.2.1585.239.34.134
                        Dec 30, 2024 02:40:35.361511946 CET408066666192.168.2.1585.239.34.134
                        Dec 30, 2024 02:40:35.366383076 CET66664080685.239.34.134192.168.2.15
                        Dec 30, 2024 02:40:40.373023033 CET66664080685.239.34.134192.168.2.15
                        Dec 30, 2024 02:40:40.373368025 CET408066666192.168.2.1585.239.34.134
                        Dec 30, 2024 02:40:40.378242016 CET66664080685.239.34.134192.168.2.15
                        Dec 30, 2024 02:40:42.659625053 CET66664080685.239.34.134192.168.2.15
                        Dec 30, 2024 02:40:42.659838915 CET408066666192.168.2.1585.239.34.134
                        Dec 30, 2024 02:40:42.664817095 CET66664080685.239.34.134192.168.2.15
                        Dec 30, 2024 02:40:45.383049011 CET66664080685.239.34.134192.168.2.15
                        Dec 30, 2024 02:40:45.383440018 CET408066666192.168.2.1585.239.34.134
                        Dec 30, 2024 02:40:45.388267994 CET66664080685.239.34.134192.168.2.15
                        Dec 30, 2024 02:40:50.452497959 CET66664080685.239.34.134192.168.2.15
                        Dec 30, 2024 02:40:50.453054905 CET408066666192.168.2.1585.239.34.134
                        Dec 30, 2024 02:40:50.458034992 CET66664080685.239.34.134192.168.2.15
                        Dec 30, 2024 02:40:55.472912073 CET66664080685.239.34.134192.168.2.15
                        Dec 30, 2024 02:40:55.473478079 CET408066666192.168.2.1585.239.34.134
                        Dec 30, 2024 02:40:55.478404999 CET66664080685.239.34.134192.168.2.15
                        Dec 30, 2024 02:41:00.490603924 CET66664080685.239.34.134192.168.2.15
                        Dec 30, 2024 02:41:00.490988016 CET408066666192.168.2.1585.239.34.134
                        Dec 30, 2024 02:41:00.495852947 CET66664080685.239.34.134192.168.2.15
                        Dec 30, 2024 02:41:05.530550957 CET66664080685.239.34.134192.168.2.15
                        Dec 30, 2024 02:41:05.530951023 CET408066666192.168.2.1585.239.34.134
                        Dec 30, 2024 02:41:05.535923004 CET66664080685.239.34.134192.168.2.15
                        Dec 30, 2024 02:41:10.541773081 CET66664080685.239.34.134192.168.2.15
                        Dec 30, 2024 02:41:10.542407036 CET408066666192.168.2.1585.239.34.134
                        Dec 30, 2024 02:41:10.547360897 CET66664080685.239.34.134192.168.2.15
                        Dec 30, 2024 02:41:12.675900936 CET66664080685.239.34.134192.168.2.15
                        Dec 30, 2024 02:41:12.676347017 CET408066666192.168.2.1585.239.34.134
                        Dec 30, 2024 02:41:12.681251049 CET66664080685.239.34.134192.168.2.15
                        Dec 30, 2024 02:41:15.550031900 CET66664080685.239.34.134192.168.2.15
                        Dec 30, 2024 02:41:15.550220966 CET408066666192.168.2.1585.239.34.134
                        Dec 30, 2024 02:41:15.556976080 CET66664080685.239.34.134192.168.2.15
                        Dec 30, 2024 02:41:20.555871010 CET66664080685.239.34.134192.168.2.15
                        Dec 30, 2024 02:41:20.556056023 CET408066666192.168.2.1585.239.34.134
                        Dec 30, 2024 02:41:20.560991049 CET66664080685.239.34.134192.168.2.15
                        Dec 30, 2024 02:41:25.563755035 CET66664080685.239.34.134192.168.2.15
                        Dec 30, 2024 02:41:25.563915968 CET408066666192.168.2.1585.239.34.134
                        Dec 30, 2024 02:41:25.568814993 CET66664080685.239.34.134192.168.2.15
                        Dec 30, 2024 02:41:27.686777115 CET66664080685.239.34.134192.168.2.15
                        Dec 30, 2024 02:41:27.686963081 CET408066666192.168.2.1585.239.34.134
                        Dec 30, 2024 02:41:27.691879988 CET66664080685.239.34.134192.168.2.15
                        Dec 30, 2024 02:41:30.575151920 CET66664080685.239.34.134192.168.2.15
                        Dec 30, 2024 02:41:30.575597048 CET408066666192.168.2.1585.239.34.134
                        Dec 30, 2024 02:41:30.580539942 CET66664080685.239.34.134192.168.2.15
                        Dec 30, 2024 02:41:35.582791090 CET66664080685.239.34.134192.168.2.15
                        Dec 30, 2024 02:41:35.582978964 CET408066666192.168.2.1585.239.34.134
                        Dec 30, 2024 02:41:35.587918043 CET66664080685.239.34.134192.168.2.15
                        Dec 30, 2024 02:41:40.620362997 CET66664080685.239.34.134192.168.2.15
                        Dec 30, 2024 02:41:40.620726109 CET408066666192.168.2.1585.239.34.134
                        Dec 30, 2024 02:41:40.625699043 CET66664080685.239.34.134192.168.2.15
                        Dec 30, 2024 02:41:45.650260925 CET66664080685.239.34.134192.168.2.15
                        Dec 30, 2024 02:41:45.650641918 CET408066666192.168.2.1585.239.34.134
                        Dec 30, 2024 02:41:45.655543089 CET66664080685.239.34.134192.168.2.15
                        Dec 30, 2024 02:41:50.673307896 CET66664080685.239.34.134192.168.2.15
                        Dec 30, 2024 02:41:50.673537970 CET408066666192.168.2.1585.239.34.134
                        Dec 30, 2024 02:41:50.678417921 CET66664080685.239.34.134192.168.2.15
                        Dec 30, 2024 02:41:55.681863070 CET66664080685.239.34.134192.168.2.15
                        Dec 30, 2024 02:41:55.682372093 CET408066666192.168.2.1585.239.34.134
                        Dec 30, 2024 02:41:55.687297106 CET66664080685.239.34.134192.168.2.15
                        Dec 30, 2024 02:41:57.759751081 CET66664080685.239.34.134192.168.2.15
                        Dec 30, 2024 02:41:57.760171890 CET408066666192.168.2.1585.239.34.134
                        Dec 30, 2024 02:41:57.765052080 CET66664080685.239.34.134192.168.2.15
                        Dec 30, 2024 02:42:00.720422983 CET66664080685.239.34.134192.168.2.15
                        Dec 30, 2024 02:42:00.720591068 CET408066666192.168.2.1585.239.34.134
                        Dec 30, 2024 02:42:00.725483894 CET66664080685.239.34.134192.168.2.15
                        Dec 30, 2024 02:42:05.729163885 CET66664080685.239.34.134192.168.2.15
                        Dec 30, 2024 02:42:05.729403019 CET408066666192.168.2.1585.239.34.134
                        Dec 30, 2024 02:42:05.734348059 CET66664080685.239.34.134192.168.2.15
                        Dec 30, 2024 02:42:10.741103888 CET66664080685.239.34.134192.168.2.15
                        Dec 30, 2024 02:42:10.741342068 CET408066666192.168.2.1585.239.34.134
                        Dec 30, 2024 02:42:10.746349096 CET66664080685.239.34.134192.168.2.15
                        Dec 30, 2024 02:42:12.777987003 CET66664080685.239.34.134192.168.2.15
                        Dec 30, 2024 02:42:12.778403997 CET408066666192.168.2.1585.239.34.134
                        Dec 30, 2024 02:42:12.783341885 CET66664080685.239.34.134192.168.2.15
                        Dec 30, 2024 02:42:15.753144979 CET66664080685.239.34.134192.168.2.15
                        Dec 30, 2024 02:42:15.753644943 CET408066666192.168.2.1585.239.34.134
                        Dec 30, 2024 02:42:15.758646965 CET66664080685.239.34.134192.168.2.15
                        Dec 30, 2024 02:42:20.760128975 CET66664080685.239.34.134192.168.2.15
                        Dec 30, 2024 02:42:20.760622978 CET408066666192.168.2.1585.239.34.134
                        Dec 30, 2024 02:42:20.765597105 CET66664080685.239.34.134192.168.2.15
                        Dec 30, 2024 02:42:25.770677090 CET66664080685.239.34.134192.168.2.15
                        Dec 30, 2024 02:42:25.770941019 CET408066666192.168.2.1585.239.34.134
                        Dec 30, 2024 02:42:25.775887012 CET66664080685.239.34.134192.168.2.15
                        Dec 30, 2024 02:42:27.785006046 CET66664080685.239.34.134192.168.2.15
                        Dec 30, 2024 02:42:27.785459995 CET408066666192.168.2.1585.239.34.134
                        Dec 30, 2024 02:42:27.790343046 CET66664080685.239.34.134192.168.2.15
                        Dec 30, 2024 02:42:30.783799887 CET66664080685.239.34.134192.168.2.15
                        Dec 30, 2024 02:42:30.784200907 CET408066666192.168.2.1585.239.34.134
                        Dec 30, 2024 02:42:30.789134026 CET66664080685.239.34.134192.168.2.15
                        Dec 30, 2024 02:42:35.854403019 CET66664080685.239.34.134192.168.2.15
                        Dec 30, 2024 02:42:35.854645014 CET408066666192.168.2.1585.239.34.134
                        Dec 30, 2024 02:42:35.859520912 CET66664080685.239.34.134192.168.2.15
                        Dec 30, 2024 02:42:40.865303040 CET66664080685.239.34.134192.168.2.15
                        Dec 30, 2024 02:42:40.865605116 CET408066666192.168.2.1585.239.34.134
                        Dec 30, 2024 02:42:40.870524883 CET66664080685.239.34.134192.168.2.15
                        Dec 30, 2024 02:42:42.820321083 CET66664080685.239.34.134192.168.2.15
                        Dec 30, 2024 02:42:42.820724010 CET408066666192.168.2.1585.239.34.134
                        Dec 30, 2024 02:42:42.825795889 CET66664080685.239.34.134192.168.2.15
                        Dec 30, 2024 02:42:45.871694088 CET66664080685.239.34.134192.168.2.15
                        Dec 30, 2024 02:42:45.872100115 CET408066666192.168.2.1585.239.34.134
                        Dec 30, 2024 02:42:45.877017021 CET66664080685.239.34.134192.168.2.15
                        Dec 30, 2024 02:42:50.884955883 CET66664080685.239.34.134192.168.2.15
                        Dec 30, 2024 02:42:50.885278940 CET408066666192.168.2.1585.239.34.134
                        Dec 30, 2024 02:42:50.890232086 CET66664080685.239.34.134192.168.2.15
                        Dec 30, 2024 02:42:55.957010031 CET66664080685.239.34.134192.168.2.15
                        Dec 30, 2024 02:42:55.957422972 CET408066666192.168.2.1585.239.34.134
                        Dec 30, 2024 02:42:55.962353945 CET66664080685.239.34.134192.168.2.15
                        Dec 30, 2024 02:42:57.822839975 CET66664080685.239.34.134192.168.2.15
                        Dec 30, 2024 02:42:57.823055983 CET408066666192.168.2.1585.239.34.134
                        Dec 30, 2024 02:42:57.828241110 CET66664080685.239.34.134192.168.2.15
                        Dec 30, 2024 02:43:00.967413902 CET66664080685.239.34.134192.168.2.15
                        Dec 30, 2024 02:43:00.967735052 CET408066666192.168.2.1585.239.34.134
                        Dec 30, 2024 02:43:00.972700119 CET66664080685.239.34.134192.168.2.15
                        Dec 30, 2024 02:43:05.981244087 CET66664080685.239.34.134192.168.2.15
                        Dec 30, 2024 02:43:05.981878996 CET408066666192.168.2.1585.239.34.134
                        Dec 30, 2024 02:43:05.986926079 CET66664080685.239.34.134192.168.2.15
                        Dec 30, 2024 02:43:11.054279089 CET66664080685.239.34.134192.168.2.15
                        Dec 30, 2024 02:43:11.054641008 CET408066666192.168.2.1585.239.34.134
                        Dec 30, 2024 02:43:11.059700012 CET66664080685.239.34.134192.168.2.15
                        Dec 30, 2024 02:43:12.828861952 CET66664080685.239.34.134192.168.2.15
                        Dec 30, 2024 02:43:12.828986883 CET408066666192.168.2.1585.239.34.134
                        Dec 30, 2024 02:43:12.834043980 CET66664080685.239.34.134192.168.2.15
                        Dec 30, 2024 02:43:16.060234070 CET66664080685.239.34.134192.168.2.15
                        Dec 30, 2024 02:43:16.060615063 CET408066666192.168.2.1585.239.34.134
                        Dec 30, 2024 02:43:16.065466881 CET66664080685.239.34.134192.168.2.15
                        Dec 30, 2024 02:43:21.069214106 CET66664080685.239.34.134192.168.2.15
                        Dec 30, 2024 02:43:21.069735050 CET408066666192.168.2.1585.239.34.134
                        Dec 30, 2024 02:43:21.074616909 CET66664080685.239.34.134192.168.2.15
                        Dec 30, 2024 02:43:26.121010065 CET66664080685.239.34.134192.168.2.15
                        Dec 30, 2024 02:43:26.121326923 CET408066666192.168.2.1585.239.34.134
                        Dec 30, 2024 02:43:26.126219988 CET66664080685.239.34.134192.168.2.15
                        Dec 30, 2024 02:43:27.835171938 CET66664080685.239.34.134192.168.2.15
                        Dec 30, 2024 02:43:27.835457087 CET408066666192.168.2.1585.239.34.134
                        Dec 30, 2024 02:43:27.840349913 CET66664080685.239.34.134192.168.2.15
                        Dec 30, 2024 02:43:31.128133059 CET66664080685.239.34.134192.168.2.15
                        Dec 30, 2024 02:43:31.128777027 CET408066666192.168.2.1585.239.34.134
                        Dec 30, 2024 02:43:31.133754015 CET66664080685.239.34.134192.168.2.15
                        Dec 30, 2024 02:43:36.140837908 CET66664080685.239.34.134192.168.2.15
                        Dec 30, 2024 02:43:36.141279936 CET408066666192.168.2.1585.239.34.134
                        Dec 30, 2024 02:43:36.146209955 CET66664080685.239.34.134192.168.2.15
                        Dec 30, 2024 02:43:41.159924030 CET66664080685.239.34.134192.168.2.15
                        Dec 30, 2024 02:43:41.160572052 CET408066666192.168.2.1585.239.34.134
                        Dec 30, 2024 02:43:41.165350914 CET66664080685.239.34.134192.168.2.15
                        Dec 30, 2024 02:43:42.845973015 CET66664080685.239.34.134192.168.2.15
                        Dec 30, 2024 02:43:42.846307039 CET408066666192.168.2.1585.239.34.134
                        Dec 30, 2024 02:43:42.851130962 CET66664080685.239.34.134192.168.2.15
                        Dec 30, 2024 02:43:46.173985004 CET66664080685.239.34.134192.168.2.15
                        Dec 30, 2024 02:43:46.174228907 CET408066666192.168.2.1585.239.34.134
                        Dec 30, 2024 02:43:46.180044889 CET66664080685.239.34.134192.168.2.15
                        Dec 30, 2024 02:43:51.258622885 CET66664080685.239.34.134192.168.2.15
                        Dec 30, 2024 02:43:51.258934975 CET408066666192.168.2.1585.239.34.134
                        Dec 30, 2024 02:43:51.263830900 CET66664080685.239.34.134192.168.2.15
                        Dec 30, 2024 02:43:56.264508963 CET66664080685.239.34.134192.168.2.15
                        Dec 30, 2024 02:43:56.264678955 CET408066666192.168.2.1585.239.34.134
                        Dec 30, 2024 02:43:56.269507885 CET66664080685.239.34.134192.168.2.15
                        Dec 30, 2024 02:43:57.857361078 CET66664080685.239.34.134192.168.2.15
                        Dec 30, 2024 02:43:57.857800007 CET408066666192.168.2.1585.239.34.134
                        Dec 30, 2024 02:43:57.862685919 CET66664080685.239.34.134192.168.2.15
                        TimestampSource PortDest PortSource IPDest IP
                        Dec 30, 2024 02:43:12.473917007 CET3942653192.168.2.151.1.1.1
                        Dec 30, 2024 02:43:12.473964930 CET5722153192.168.2.151.1.1.1
                        Dec 30, 2024 02:43:12.489609003 CET53394261.1.1.1192.168.2.15
                        Dec 30, 2024 02:43:12.489628077 CET53572211.1.1.1192.168.2.15
                        TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                        Dec 30, 2024 02:43:12.473917007 CET192.168.2.151.1.1.10x3be0Standard query (0)daisy.ubuntu.comA (IP address)IN (0x0001)false
                        Dec 30, 2024 02:43:12.473964930 CET192.168.2.151.1.1.10x1fe9Standard query (0)daisy.ubuntu.com28IN (0x0001)false
                        TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                        Dec 30, 2024 02:43:12.489609003 CET1.1.1.1192.168.2.150x3be0No error (0)daisy.ubuntu.com162.213.35.24A (IP address)IN (0x0001)false
                        Dec 30, 2024 02:43:12.489609003 CET1.1.1.1192.168.2.150x3be0No error (0)daisy.ubuntu.com162.213.35.25A (IP address)IN (0x0001)false

                        System Behavior

                        Start time (UTC):01:40:24
                        Start date (UTC):30/12/2024
                        Path:/tmp/spc.elf
                        Arguments:/tmp/spc.elf
                        File size:4379400 bytes
                        MD5 hash:7dc1c0e23cd5e102bb12e5c29403410e

                        Start time (UTC):01:40:24
                        Start date (UTC):30/12/2024
                        Path:/tmp/spc.elf
                        Arguments:-
                        File size:4379400 bytes
                        MD5 hash:7dc1c0e23cd5e102bb12e5c29403410e