Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
sh4.elf

Overview

General Information

Sample name:sh4.elf
Analysis ID:1582139
MD5:54e492e0988026371162dca7bf042cc3
SHA1:59505120bf5a0d58b472121d02e9db3b89975adf
SHA256:2da1fc9acf98e44dbfa39976cfd44e686dbfeb3e9440b2391f5a5d19f3b5bc58
Tags:elfuser-abuse_ch
Infos:

Detection

Score:56
Range:0 - 100
Whitelisted:false

Signatures

Multi AV Scanner detection for submitted file
Suricata IDS alerts for network traffic
Detected TCP or UDP traffic on non-standard ports
Sample has stripped symbol table
Sample listens on a socket
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1582139
Start date and time:2024-12-30 02:48:34 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 5m 6s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:sh4.elf
Detection:MAL
Classification:mal56.linELF@0/0@2/0
Command:/tmp/sh4.elf
PID:5656
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
$UICIDEBOY$
Standard Error:
  • system is lnxubuntu20
  • sh4.elf (PID: 5656, Parent: 5583, MD5: 8943e5f8f8c280467b4472c15ae93ba9) Arguments: /tmp/sh4.elf
    • sh4.elf New Fork (PID: 5658, Parent: 5656)
  • cleanup
No yara matches
TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
2024-12-30T02:49:32.987909+010028498161A Network Trojan was detected192.168.2.154079685.239.34.1346666TCP

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: sh4.elfVirustotal: Detection: 22%Perma Link
Source: sh4.elfReversingLabs: Detection: 23%

Networking

barindex
Source: Network trafficSuricata IDS: 2849816 - Severity 1 - ETPRO MALWARE ELF/Multiverze CnC Checkin : 192.168.2.15:40796 -> 85.239.34.134:6666
Source: global trafficTCP traffic: 192.168.2.15:40796 -> 85.239.34.134:6666
Source: /tmp/sh4.elf (PID: 5656)Socket: 0.0.0.0:9902Jump to behavior
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: global trafficDNS traffic detected: DNS query: daisy.ubuntu.com
Source: ELF static info symbol of initial sample.symtab present: no
Source: classification engineClassification label: mal56.linELF@0/0@2/0
Source: /tmp/sh4.elf (PID: 5656)Queries kernel information via 'uname': Jump to behavior
Source: sh4.elf, 5656.1.00007fffb9e15000.00007fffb9e36000.rw-.sdmpBinary or memory string: /usr/bin/qemu-sh4
Source: sh4.elf, 5656.1.00005599e7b50000.00005599e7bb3000.rw-.sdmpBinary or memory string: U5!/etc/qemu-binfmt/sh4
Source: sh4.elf, 5656.1.00005599e7b50000.00005599e7bb3000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/sh4
Source: sh4.elf, 5656.1.00007fffb9e15000.00007fffb9e36000.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-sh4/tmp/sh4.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/sh4.elf
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath InterceptionDirect Volume AccessOS Credential Dumping11
Security Software Discovery
Remote ServicesData from Local System1
Non-Standard Port
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
SourceDetectionScannerLabelLink
sh4.elf22%VirustotalBrowse
sh4.elf24%ReversingLabsLinux.Backdoor.Gafgyt
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
daisy.ubuntu.com
162.213.35.25
truefalse
    high
    • No. of IPs < 25%
    • 25% < No. of IPs < 50%
    • 50% < No. of IPs < 75%
    • 75% < No. of IPs
    IPDomainCountryFlagASNASN NameMalicious
    85.239.34.134
    unknownRussian Federation
    134121RAINBOW-HKRainbownetworklimitedHKtrue
    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
    85.239.34.134x86.elfGet hashmaliciousUnknownBrowse
      spc.elfGet hashmaliciousUnknownBrowse
        212.64.215.71-arm-2024-12-25T12_31_55.elfGet hashmaliciousUnknownBrowse
          ppc.elfGet hashmaliciousMiraiBrowse
            sh4.elfGet hashmaliciousMiraiBrowse
              mips.elfGet hashmaliciousMiraiBrowse
                spc.elfGet hashmaliciousMiraiBrowse
                  arm6.elfGet hashmaliciousMiraiBrowse
                    arm.elfGet hashmaliciousMiraiBrowse
                      m68k.elfGet hashmaliciousMiraiBrowse
                        MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                        daisy.ubuntu.comrebirth.m68.elfGet hashmaliciousGafgytBrowse
                        • 162.213.35.25
                        rebirth.mpsl.elfGet hashmaliciousGafgytBrowse
                        • 162.213.35.25
                        rebirth.mips.elfGet hashmaliciousGafgytBrowse
                        • 162.213.35.25
                        x86.elfGet hashmaliciousUnknownBrowse
                        • 162.213.35.24
                        spc.elfGet hashmaliciousUnknownBrowse
                        • 162.213.35.24
                        rebirth.arm4.elfGet hashmaliciousGafgytBrowse
                        • 162.213.35.24
                        dlr.arm5.elfGet hashmaliciousUnknownBrowse
                        • 162.213.35.24
                        rebirth.arm5.elfGet hashmaliciousGafgytBrowse
                        • 162.213.35.24
                        rebirth.i686.elfGet hashmaliciousGafgytBrowse
                        • 162.213.35.25
                        loligang.m68k.elfGet hashmaliciousMiraiBrowse
                        • 162.213.35.24
                        MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                        RAINBOW-HKRainbownetworklimitedHKx86.elfGet hashmaliciousUnknownBrowse
                        • 85.239.34.134
                        spc.elfGet hashmaliciousUnknownBrowse
                        • 85.239.34.134
                        1C6ljtnwXP.exeGet hashmaliciousLummaCBrowse
                        • 85.239.54.77
                        212.64.215.71-arm-2024-12-25T12_31_55.elfGet hashmaliciousUnknownBrowse
                        • 85.239.34.134
                        armv5l.elfGet hashmaliciousUnknownBrowse
                        • 185.152.92.158
                        statmentt.exeGet hashmaliciousScreenConnect ToolBrowse
                        • 85.239.34.190
                        ppc.elfGet hashmaliciousMiraiBrowse
                        • 85.239.34.134
                        sh4.elfGet hashmaliciousMiraiBrowse
                        • 85.239.34.134
                        mips.elfGet hashmaliciousMiraiBrowse
                        • 85.239.34.134
                        spc.elfGet hashmaliciousMiraiBrowse
                        • 85.239.34.134
                        No context
                        No context
                        No created / dropped files found
                        File type:ELF 32-bit LSB executable, Renesas SH, version 1 (SYSV), statically linked, stripped
                        Entropy (8bit):6.679169228311048
                        TrID:
                        • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                        File name:sh4.elf
                        File size:33'360 bytes
                        MD5:54e492e0988026371162dca7bf042cc3
                        SHA1:59505120bf5a0d58b472121d02e9db3b89975adf
                        SHA256:2da1fc9acf98e44dbfa39976cfd44e686dbfeb3e9440b2391f5a5d19f3b5bc58
                        SHA512:f3eebf5ccda68f4980a1d575eb40d2e2f2c212bbebc4653eab505522c253e57c389fbfeef9326de4b3d9a45aebe4dcf23530cdcc7026878758b7acf99f98bfd7
                        SSDEEP:384:I+Vj9q6BHt9KdChVjoPw6+CvrJqqXDW8OR/b+PJusT8oib9B1+b1QR3LmKKq:I+34dSVjoPjnn0TOwDb9Z1mK
                        TLSH:CAE24B67D5706F63C416EBFA7036DB3C032B0631814A6EB4642BC7A80547D8DF9897E8
                        File Content Preview:.ELF..............*.......@.4... .......4. ...(...............@...@.,}..,}..............,}..,.@.,.@.....\1...............}....@...@.................Q.td............................././"O.n........#.*@........#.*@,w...o&O.n...l.............................

                        ELF header

                        Class:ELF32
                        Data:2's complement, little endian
                        Version:1 (current)
                        Machine:<unknown>
                        Version Number:0x1
                        Type:EXEC (Executable file)
                        OS/ABI:UNIX - System V
                        ABI Version:0
                        Entry Point Address:0x4001c0
                        Flags:0x9
                        ELF Header Size:52
                        Program Header Offset:52
                        Program Header Size:32
                        Number of Program Headers:4
                        Section Header Offset:32800
                        Section Header Size:40
                        Number of Section Headers:14
                        Header String Table Index:13
                        NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                        NULL0x00x00x00x00x0000
                        .initPROGBITS0x4000b40xb40x300x00x6AX004
                        .textPROGBITS0x4001000x1000x77400x00x6AX0032
                        .finiPROGBITS0x4078400x78400x240x00x6AX004
                        .rodataPROGBITS0x4078640x78640x4c80x00x2A004
                        .eh_framePROGBITS0x408d2c0x7d2c0x7c0x00x3WA004
                        .tbssNOBITS0x408da80x7da80x80x00x403WAT004
                        .ctorsPROGBITS0x408da80x7da80x80x00x3WA004
                        .dtorsPROGBITS0x408db00x7db00x80x00x3WA004
                        .jcrPROGBITS0x408db80x7db80x40x00x3WA004
                        .dataPROGBITS0x408dbc0x7dbc0x1f80x00x3WA004
                        .gotPROGBITS0x408fb40x7fb40x140x40x3WA004
                        .bssNOBITS0x408fc80x7fc80x2ec00x00x3WA004
                        .shstrtabSTRTAB0x00x7fc80x580x00x0001
                        TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                        LOAD0x00x4000000x4000000x7d2c0x7d2c6.75510x5R E0x1000.init .text .fini .rodata
                        LOAD0x7d2c0x408d2c0x408d2c0x29c0x315c3.81440x6RW 0x1000.eh_frame .tbss .ctors .dtors .jcr .data .got .bss
                        TLS0x7da80x408da80x408da80x00x80.00000x4R 0x4.tbss
                        GNU_STACK0x00x00x00x00x00.00000x7RWE0x4
                        TimestampSIDSignatureSeveritySource IPSource PortDest IPDest PortProtocol
                        2024-12-30T02:49:32.987909+01002849816ETPRO MALWARE ELF/Multiverze CnC Checkin1192.168.2.154079685.239.34.1346666TCP
                        TimestampSource PortDest PortSource IPDest IP
                        Dec 30, 2024 02:49:32.963231087 CET407966666192.168.2.1585.239.34.134
                        Dec 30, 2024 02:49:32.968290091 CET66664079685.239.34.134192.168.2.15
                        Dec 30, 2024 02:49:32.968656063 CET407966666192.168.2.1585.239.34.134
                        Dec 30, 2024 02:49:32.987909079 CET407966666192.168.2.1585.239.34.134
                        Dec 30, 2024 02:49:32.992775917 CET66664079685.239.34.134192.168.2.15
                        Dec 30, 2024 02:49:37.720180035 CET66664079685.239.34.134192.168.2.15
                        Dec 30, 2024 02:49:37.720458031 CET407966666192.168.2.1585.239.34.134
                        Dec 30, 2024 02:49:37.720510006 CET407966666192.168.2.1585.239.34.134
                        Dec 30, 2024 02:49:37.725450039 CET66664079685.239.34.134192.168.2.15
                        Dec 30, 2024 02:49:42.755839109 CET66664079685.239.34.134192.168.2.15
                        Dec 30, 2024 02:49:42.756330967 CET407966666192.168.2.1585.239.34.134
                        Dec 30, 2024 02:49:42.756330967 CET407966666192.168.2.1585.239.34.134
                        Dec 30, 2024 02:49:42.761259079 CET66664079685.239.34.134192.168.2.15
                        Dec 30, 2024 02:49:43.389441013 CET66664079685.239.34.134192.168.2.15
                        Dec 30, 2024 02:49:43.389739037 CET407966666192.168.2.1585.239.34.134
                        Dec 30, 2024 02:49:43.389739990 CET407966666192.168.2.1585.239.34.134
                        Dec 30, 2024 02:49:43.394588947 CET66664079685.239.34.134192.168.2.15
                        Dec 30, 2024 02:49:47.767067909 CET66664079685.239.34.134192.168.2.15
                        Dec 30, 2024 02:49:47.767368078 CET407966666192.168.2.1585.239.34.134
                        Dec 30, 2024 02:49:47.772285938 CET66664079685.239.34.134192.168.2.15
                        Dec 30, 2024 02:49:52.777554989 CET66664079685.239.34.134192.168.2.15
                        Dec 30, 2024 02:49:52.778013945 CET407966666192.168.2.1585.239.34.134
                        Dec 30, 2024 02:49:52.782915115 CET66664079685.239.34.134192.168.2.15
                        Dec 30, 2024 02:49:57.788158894 CET66664079685.239.34.134192.168.2.15
                        Dec 30, 2024 02:49:57.788598061 CET407966666192.168.2.1585.239.34.134
                        Dec 30, 2024 02:49:57.793544054 CET66664079685.239.34.134192.168.2.15
                        Dec 30, 2024 02:49:58.448625088 CET66664079685.239.34.134192.168.2.15
                        Dec 30, 2024 02:49:58.449038029 CET407966666192.168.2.1585.239.34.134
                        Dec 30, 2024 02:49:58.454015970 CET66664079685.239.34.134192.168.2.15
                        Dec 30, 2024 02:50:02.835669041 CET66664079685.239.34.134192.168.2.15
                        Dec 30, 2024 02:50:02.835987091 CET407966666192.168.2.1585.239.34.134
                        Dec 30, 2024 02:50:02.840831995 CET66664079685.239.34.134192.168.2.15
                        Dec 30, 2024 02:50:07.855724096 CET66664079685.239.34.134192.168.2.15
                        Dec 30, 2024 02:50:07.856200933 CET407966666192.168.2.1585.239.34.134
                        Dec 30, 2024 02:50:07.861099958 CET66664079685.239.34.134192.168.2.15
                        Dec 30, 2024 02:50:12.868119001 CET66664079685.239.34.134192.168.2.15
                        Dec 30, 2024 02:50:12.868510962 CET407966666192.168.2.1585.239.34.134
                        Dec 30, 2024 02:50:12.873467922 CET66664079685.239.34.134192.168.2.15
                        Dec 30, 2024 02:50:13.463011026 CET66664079685.239.34.134192.168.2.15
                        Dec 30, 2024 02:50:13.463285923 CET407966666192.168.2.1585.239.34.134
                        Dec 30, 2024 02:50:13.468255997 CET66664079685.239.34.134192.168.2.15
                        Dec 30, 2024 02:50:17.881999969 CET66664079685.239.34.134192.168.2.15
                        Dec 30, 2024 02:50:17.882353067 CET407966666192.168.2.1585.239.34.134
                        Dec 30, 2024 02:50:17.887265921 CET66664079685.239.34.134192.168.2.15
                        Dec 30, 2024 02:50:22.934453011 CET66664079685.239.34.134192.168.2.15
                        Dec 30, 2024 02:50:22.934712887 CET407966666192.168.2.1585.239.34.134
                        Dec 30, 2024 02:50:22.939606905 CET66664079685.239.34.134192.168.2.15
                        Dec 30, 2024 02:50:27.940630913 CET66664079685.239.34.134192.168.2.15
                        Dec 30, 2024 02:50:27.940916061 CET407966666192.168.2.1585.239.34.134
                        Dec 30, 2024 02:50:27.945945978 CET66664079685.239.34.134192.168.2.15
                        Dec 30, 2024 02:50:28.469842911 CET66664079685.239.34.134192.168.2.15
                        Dec 30, 2024 02:50:28.470004082 CET407966666192.168.2.1585.239.34.134
                        Dec 30, 2024 02:50:28.474917889 CET66664079685.239.34.134192.168.2.15
                        Dec 30, 2024 02:50:32.951021910 CET66664079685.239.34.134192.168.2.15
                        Dec 30, 2024 02:50:32.951458931 CET407966666192.168.2.1585.239.34.134
                        Dec 30, 2024 02:50:32.956353903 CET66664079685.239.34.134192.168.2.15
                        Dec 30, 2024 02:50:37.962429047 CET66664079685.239.34.134192.168.2.15
                        Dec 30, 2024 02:50:37.962601900 CET407966666192.168.2.1585.239.34.134
                        Dec 30, 2024 02:50:37.967540979 CET66664079685.239.34.134192.168.2.15
                        Dec 30, 2024 02:50:42.974689007 CET66664079685.239.34.134192.168.2.15
                        Dec 30, 2024 02:50:42.975141048 CET407966666192.168.2.1585.239.34.134
                        Dec 30, 2024 02:50:42.980079889 CET66664079685.239.34.134192.168.2.15
                        Dec 30, 2024 02:50:43.477437019 CET66664079685.239.34.134192.168.2.15
                        Dec 30, 2024 02:50:43.477643967 CET407966666192.168.2.1585.239.34.134
                        Dec 30, 2024 02:50:43.482574940 CET66664079685.239.34.134192.168.2.15
                        Dec 30, 2024 02:50:47.984457970 CET66664079685.239.34.134192.168.2.15
                        Dec 30, 2024 02:50:47.984785080 CET407966666192.168.2.1585.239.34.134
                        Dec 30, 2024 02:50:47.989753962 CET66664079685.239.34.134192.168.2.15
                        Dec 30, 2024 02:50:53.060791016 CET66664079685.239.34.134192.168.2.15
                        Dec 30, 2024 02:50:53.061110973 CET407966666192.168.2.1585.239.34.134
                        Dec 30, 2024 02:50:53.066091061 CET66664079685.239.34.134192.168.2.15
                        Dec 30, 2024 02:50:58.081981897 CET66664079685.239.34.134192.168.2.15
                        Dec 30, 2024 02:50:58.082400084 CET407966666192.168.2.1585.239.34.134
                        Dec 30, 2024 02:50:58.087338924 CET66664079685.239.34.134192.168.2.15
                        Dec 30, 2024 02:51:03.120269060 CET66664079685.239.34.134192.168.2.15
                        Dec 30, 2024 02:51:03.120404959 CET407966666192.168.2.1585.239.34.134
                        Dec 30, 2024 02:51:03.125382900 CET66664079685.239.34.134192.168.2.15
                        Dec 30, 2024 02:51:08.164526939 CET66664079685.239.34.134192.168.2.15
                        Dec 30, 2024 02:51:08.164767027 CET407966666192.168.2.1585.239.34.134
                        Dec 30, 2024 02:51:08.169754028 CET66664079685.239.34.134192.168.2.15
                        Dec 30, 2024 02:51:13.183931112 CET66664079685.239.34.134192.168.2.15
                        Dec 30, 2024 02:51:13.184242010 CET407966666192.168.2.1585.239.34.134
                        Dec 30, 2024 02:51:13.189218998 CET66664079685.239.34.134192.168.2.15
                        Dec 30, 2024 02:51:13.519588947 CET66664079685.239.34.134192.168.2.15
                        Dec 30, 2024 02:51:13.519745111 CET407966666192.168.2.1585.239.34.134
                        Dec 30, 2024 02:51:13.524595022 CET66664079685.239.34.134192.168.2.15
                        Dec 30, 2024 02:51:18.224903107 CET66664079685.239.34.134192.168.2.15
                        Dec 30, 2024 02:51:18.225106955 CET407966666192.168.2.1585.239.34.134
                        Dec 30, 2024 02:51:18.230058908 CET66664079685.239.34.134192.168.2.15
                        Dec 30, 2024 02:51:23.236985922 CET66664079685.239.34.134192.168.2.15
                        Dec 30, 2024 02:51:23.237209082 CET407966666192.168.2.1585.239.34.134
                        Dec 30, 2024 02:51:23.242126942 CET66664079685.239.34.134192.168.2.15
                        Dec 30, 2024 02:51:28.248864889 CET66664079685.239.34.134192.168.2.15
                        Dec 30, 2024 02:51:28.249094009 CET407966666192.168.2.1585.239.34.134
                        Dec 30, 2024 02:51:28.253987074 CET66664079685.239.34.134192.168.2.15
                        Dec 30, 2024 02:51:28.557719946 CET66664079685.239.34.134192.168.2.15
                        Dec 30, 2024 02:51:28.557868958 CET407966666192.168.2.1585.239.34.134
                        Dec 30, 2024 02:51:28.562704086 CET66664079685.239.34.134192.168.2.15
                        Dec 30, 2024 02:51:33.259578943 CET66664079685.239.34.134192.168.2.15
                        Dec 30, 2024 02:51:33.259805918 CET407966666192.168.2.1585.239.34.134
                        Dec 30, 2024 02:51:33.264770985 CET66664079685.239.34.134192.168.2.15
                        Dec 30, 2024 02:51:38.270056009 CET66664079685.239.34.134192.168.2.15
                        Dec 30, 2024 02:51:38.270441055 CET407966666192.168.2.1585.239.34.134
                        Dec 30, 2024 02:51:38.275440931 CET66664079685.239.34.134192.168.2.15
                        Dec 30, 2024 02:51:43.281749010 CET66664079685.239.34.134192.168.2.15
                        Dec 30, 2024 02:51:43.282219887 CET407966666192.168.2.1585.239.34.134
                        Dec 30, 2024 02:51:43.287071943 CET66664079685.239.34.134192.168.2.15
                        Dec 30, 2024 02:51:43.568056107 CET66664079685.239.34.134192.168.2.15
                        Dec 30, 2024 02:51:43.568363905 CET407966666192.168.2.1585.239.34.134
                        Dec 30, 2024 02:51:43.573307037 CET66664079685.239.34.134192.168.2.15
                        Dec 30, 2024 02:51:48.324321032 CET66664079685.239.34.134192.168.2.15
                        Dec 30, 2024 02:51:48.324570894 CET407966666192.168.2.1585.239.34.134
                        Dec 30, 2024 02:51:48.329509020 CET66664079685.239.34.134192.168.2.15
                        Dec 30, 2024 02:51:53.330701113 CET66664079685.239.34.134192.168.2.15
                        Dec 30, 2024 02:51:53.331043959 CET407966666192.168.2.1585.239.34.134
                        Dec 30, 2024 02:51:53.335980892 CET66664079685.239.34.134192.168.2.15
                        Dec 30, 2024 02:51:58.345699072 CET66664079685.239.34.134192.168.2.15
                        Dec 30, 2024 02:51:58.346076012 CET407966666192.168.2.1585.239.34.134
                        Dec 30, 2024 02:51:58.351048946 CET66664079685.239.34.134192.168.2.15
                        Dec 30, 2024 02:51:58.574455023 CET66664079685.239.34.134192.168.2.15
                        Dec 30, 2024 02:51:58.574717045 CET407966666192.168.2.1585.239.34.134
                        Dec 30, 2024 02:51:58.579670906 CET66664079685.239.34.134192.168.2.15
                        Dec 30, 2024 02:52:03.370582104 CET66664079685.239.34.134192.168.2.15
                        Dec 30, 2024 02:52:03.370845079 CET407966666192.168.2.1585.239.34.134
                        Dec 30, 2024 02:52:03.375690937 CET66664079685.239.34.134192.168.2.15
                        Dec 30, 2024 02:52:08.382225037 CET66664079685.239.34.134192.168.2.15
                        Dec 30, 2024 02:52:08.382663965 CET407966666192.168.2.1585.239.34.134
                        Dec 30, 2024 02:52:08.387650013 CET66664079685.239.34.134192.168.2.15
                        Dec 30, 2024 02:52:13.388444901 CET66664079685.239.34.134192.168.2.15
                        Dec 30, 2024 02:52:13.388807058 CET407966666192.168.2.1585.239.34.134
                        Dec 30, 2024 02:52:13.393696070 CET66664079685.239.34.134192.168.2.15
                        Dec 30, 2024 02:52:13.580110073 CET66664079685.239.34.134192.168.2.15
                        Dec 30, 2024 02:52:13.580473900 CET407966666192.168.2.1585.239.34.134
                        Dec 30, 2024 02:52:13.585351944 CET66664079685.239.34.134192.168.2.15
                        Dec 30, 2024 02:52:18.424926996 CET66664079685.239.34.134192.168.2.15
                        Dec 30, 2024 02:52:18.425087929 CET407966666192.168.2.1585.239.34.134
                        Dec 30, 2024 02:52:18.429963112 CET66664079685.239.34.134192.168.2.15
                        Dec 30, 2024 02:52:19.669473886 CET5576253192.168.2.158.8.8.8
                        Dec 30, 2024 02:52:19.674367905 CET53557628.8.8.8192.168.2.15
                        Dec 30, 2024 02:52:19.674427986 CET5576253192.168.2.158.8.8.8
                        Dec 30, 2024 02:52:19.674457073 CET5576253192.168.2.158.8.8.8
                        Dec 30, 2024 02:52:19.674469948 CET5576253192.168.2.158.8.8.8
                        Dec 30, 2024 02:52:19.679290056 CET53557628.8.8.8192.168.2.15
                        Dec 30, 2024 02:52:19.679302931 CET53557628.8.8.8192.168.2.15
                        Dec 30, 2024 02:52:20.097558022 CET53557628.8.8.8192.168.2.15
                        Dec 30, 2024 02:52:20.097779036 CET5576253192.168.2.158.8.8.8
                        Dec 30, 2024 02:52:22.097723007 CET53557628.8.8.8192.168.2.15
                        Dec 30, 2024 02:52:22.098138094 CET5576253192.168.2.158.8.8.8
                        Dec 30, 2024 02:52:22.103085995 CET53557628.8.8.8192.168.2.15
                        Dec 30, 2024 02:52:23.435375929 CET66664079685.239.34.134192.168.2.15
                        Dec 30, 2024 02:52:23.435683966 CET407966666192.168.2.1585.239.34.134
                        Dec 30, 2024 02:52:23.440504074 CET66664079685.239.34.134192.168.2.15
                        Dec 30, 2024 02:52:28.442930937 CET66664079685.239.34.134192.168.2.15
                        Dec 30, 2024 02:52:28.443197012 CET407966666192.168.2.1585.239.34.134
                        Dec 30, 2024 02:52:28.448133945 CET66664079685.239.34.134192.168.2.15
                        Dec 30, 2024 02:52:28.621092081 CET66664079685.239.34.134192.168.2.15
                        Dec 30, 2024 02:52:28.621349096 CET407966666192.168.2.1585.239.34.134
                        Dec 30, 2024 02:52:28.626214027 CET66664079685.239.34.134192.168.2.15
                        Dec 30, 2024 02:52:33.452774048 CET66664079685.239.34.134192.168.2.15
                        Dec 30, 2024 02:52:33.453125000 CET407966666192.168.2.1585.239.34.134
                        Dec 30, 2024 02:52:33.457914114 CET66664079685.239.34.134192.168.2.15
                        Dec 30, 2024 02:52:38.468338013 CET66664079685.239.34.134192.168.2.15
                        Dec 30, 2024 02:52:38.468636990 CET407966666192.168.2.1585.239.34.134
                        Dec 30, 2024 02:52:38.473601103 CET66664079685.239.34.134192.168.2.15
                        Dec 30, 2024 02:52:43.489451885 CET66664079685.239.34.134192.168.2.15
                        Dec 30, 2024 02:52:43.489622116 CET407966666192.168.2.1585.239.34.134
                        Dec 30, 2024 02:52:43.494534016 CET66664079685.239.34.134192.168.2.15
                        Dec 30, 2024 02:52:43.663676023 CET66664079685.239.34.134192.168.2.15
                        Dec 30, 2024 02:52:43.663857937 CET407966666192.168.2.1585.239.34.134
                        Dec 30, 2024 02:52:43.668685913 CET66664079685.239.34.134192.168.2.15
                        Dec 30, 2024 02:52:48.526566982 CET66664079685.239.34.134192.168.2.15
                        Dec 30, 2024 02:52:48.526793957 CET407966666192.168.2.1585.239.34.134
                        Dec 30, 2024 02:52:48.531564951 CET66664079685.239.34.134192.168.2.15
                        Dec 30, 2024 02:52:53.539283991 CET66664079685.239.34.134192.168.2.15
                        Dec 30, 2024 02:52:53.539685965 CET407966666192.168.2.1585.239.34.134
                        Dec 30, 2024 02:52:53.544637918 CET66664079685.239.34.134192.168.2.15
                        Dec 30, 2024 02:52:58.547427893 CET66664079685.239.34.134192.168.2.15
                        Dec 30, 2024 02:52:58.547712088 CET407966666192.168.2.1585.239.34.134
                        Dec 30, 2024 02:52:58.552654028 CET66664079685.239.34.134192.168.2.15
                        Dec 30, 2024 02:52:58.720758915 CET66664079685.239.34.134192.168.2.15
                        Dec 30, 2024 02:52:58.720933914 CET407966666192.168.2.1585.239.34.134
                        Dec 30, 2024 02:52:58.726851940 CET66664079685.239.34.134192.168.2.15
                        Dec 30, 2024 02:53:03.558295012 CET66664079685.239.34.134192.168.2.15
                        Dec 30, 2024 02:53:03.558645010 CET407966666192.168.2.1585.239.34.134
                        Dec 30, 2024 02:53:03.563551903 CET66664079685.239.34.134192.168.2.15
                        TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                        Dec 30, 2024 02:52:19.674457073 CET192.168.2.158.8.8.80x9ec6Standard query (0)daisy.ubuntu.comA (IP address)IN (0x0001)false
                        Dec 30, 2024 02:52:19.674469948 CET192.168.2.158.8.8.80x3128Standard query (0)daisy.ubuntu.com28IN (0x0001)false
                        TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                        Dec 30, 2024 02:52:20.097558022 CET8.8.8.8192.168.2.150x9ec6No error (0)daisy.ubuntu.com162.213.35.25A (IP address)IN (0x0001)false
                        Dec 30, 2024 02:52:20.097558022 CET8.8.8.8192.168.2.150x9ec6No error (0)daisy.ubuntu.com162.213.35.24A (IP address)IN (0x0001)false

                        System Behavior

                        Start time (UTC):01:49:31
                        Start date (UTC):30/12/2024
                        Path:/tmp/sh4.elf
                        Arguments:/tmp/sh4.elf
                        File size:4139976 bytes
                        MD5 hash:8943e5f8f8c280467b4472c15ae93ba9

                        Start time (UTC):01:49:31
                        Start date (UTC):30/12/2024
                        Path:/tmp/sh4.elf
                        Arguments:-
                        File size:4139976 bytes
                        MD5 hash:8943e5f8f8c280467b4472c15ae93ba9