Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
arm6.elf

Overview

General Information

Sample name:arm6.elf
Analysis ID:1582146
MD5:bad36d8fc61c2a221c2609dd5ff792af
SHA1:bc71c073a75c4847334fccdf7f6d0be3eedf18ea
SHA256:e5364f3baf34c9911eed614ca6c35fc032c854efb6c5ce45b2fc82b9c250cf53
Tags:elfuser-abuse_ch
Infos:

Detection

Score:56
Range:0 - 100
Whitelisted:false

Signatures

Multi AV Scanner detection for submitted file
Suricata IDS alerts for network traffic
Detected TCP or UDP traffic on non-standard ports
Sample has stripped symbol table
Sample listens on a socket
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1582146
Start date and time:2024-12-30 02:56:45 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 5m 9s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:arm6.elf
Detection:MAL
Classification:mal56.linELF@0/0@2/0
Command:/tmp/arm6.elf
PID:5475
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
$UICIDEBOY$
Standard Error:
  • system is lnxubuntu20
  • arm6.elf (PID: 5475, Parent: 5393, MD5: 5ebfcae4fe2471fcc5695c2394773ff1) Arguments: /tmp/arm6.elf
    • arm6.elf New Fork (PID: 5477, Parent: 5475)
  • cleanup
No yara matches
TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
2024-12-30T02:57:45.631520+010028498161A Network Trojan was detected192.168.2.135363285.239.34.1346666TCP

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: arm6.elfVirustotal: Detection: 23%Perma Link
Source: arm6.elfReversingLabs: Detection: 26%

Networking

barindex
Source: Network trafficSuricata IDS: 2849816 - Severity 1 - ETPRO MALWARE ELF/Multiverze CnC Checkin : 192.168.2.13:53632 -> 85.239.34.134:6666
Source: global trafficTCP traffic: 192.168.2.13:53632 -> 85.239.34.134:6666
Source: /tmp/arm6.elf (PID: 5475)Socket: 0.0.0.0:9902Jump to behavior
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: global trafficDNS traffic detected: DNS query: daisy.ubuntu.com
Source: ELF static info symbol of initial sample.symtab present: no
Source: classification engineClassification label: mal56.linELF@0/0@2/0
Source: /tmp/arm6.elf (PID: 5475)Queries kernel information via 'uname': Jump to behavior
Source: arm6.elf, 5475.1.0000564c00611000.0000564c0073f000.rw-.sdmpBinary or memory string: bLV!/etc/qemu-binfmt/arm
Source: arm6.elf, 5475.1.00007fffbb36f000.00007fffbb390000.rw-.sdmpBinary or memory string: 6x86_64/usr/bin/qemu-arm/tmp/arm6.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/arm6.elf
Source: arm6.elf, 5475.1.0000564c00611000.0000564c0073f000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/arm
Source: arm6.elf, 5475.1.00007fffbb36f000.00007fffbb390000.rw-.sdmpBinary or memory string: /usr/bin/qemu-arm
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath InterceptionDirect Volume AccessOS Credential Dumping11
Security Software Discovery
Remote ServicesData from Local System1
Non-Standard Port
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
arm6.elf24%VirustotalBrowse
arm6.elf26%ReversingLabsLinux.Backdoor.Gafgyt
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
daisy.ubuntu.com
162.213.35.24
truefalse
    high
    • No. of IPs < 25%
    • 25% < No. of IPs < 50%
    • 50% < No. of IPs < 75%
    • 75% < No. of IPs
    IPDomainCountryFlagASNASN NameMalicious
    85.239.34.134
    unknownRussian Federation
    134121RAINBOW-HKRainbownetworklimitedHKtrue
    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
    85.239.34.134m68k.elfGet hashmaliciousUnknownBrowse
      sh4.elfGet hashmaliciousUnknownBrowse
        x86.elfGet hashmaliciousUnknownBrowse
          spc.elfGet hashmaliciousUnknownBrowse
            212.64.215.71-arm-2024-12-25T12_31_55.elfGet hashmaliciousUnknownBrowse
              ppc.elfGet hashmaliciousMiraiBrowse
                sh4.elfGet hashmaliciousMiraiBrowse
                  mips.elfGet hashmaliciousMiraiBrowse
                    spc.elfGet hashmaliciousMiraiBrowse
                      arm6.elfGet hashmaliciousMiraiBrowse
                        MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                        daisy.ubuntu.comrebirth.sh4.elfGet hashmaliciousGafgytBrowse
                        • 162.213.35.25
                        sh4.elfGet hashmaliciousUnknownBrowse
                        • 162.213.35.25
                        rebirth.m68.elfGet hashmaliciousGafgytBrowse
                        • 162.213.35.25
                        rebirth.mpsl.elfGet hashmaliciousGafgytBrowse
                        • 162.213.35.25
                        rebirth.mips.elfGet hashmaliciousGafgytBrowse
                        • 162.213.35.25
                        x86.elfGet hashmaliciousUnknownBrowse
                        • 162.213.35.24
                        spc.elfGet hashmaliciousUnknownBrowse
                        • 162.213.35.24
                        rebirth.arm4.elfGet hashmaliciousGafgytBrowse
                        • 162.213.35.24
                        dlr.arm5.elfGet hashmaliciousUnknownBrowse
                        • 162.213.35.24
                        rebirth.arm5.elfGet hashmaliciousGafgytBrowse
                        • 162.213.35.24
                        MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                        RAINBOW-HKRainbownetworklimitedHKm68k.elfGet hashmaliciousUnknownBrowse
                        • 85.239.34.134
                        sh4.elfGet hashmaliciousUnknownBrowse
                        • 85.239.34.134
                        x86.elfGet hashmaliciousUnknownBrowse
                        • 85.239.34.134
                        spc.elfGet hashmaliciousUnknownBrowse
                        • 85.239.34.134
                        1C6ljtnwXP.exeGet hashmaliciousLummaCBrowse
                        • 85.239.54.77
                        212.64.215.71-arm-2024-12-25T12_31_55.elfGet hashmaliciousUnknownBrowse
                        • 85.239.34.134
                        armv5l.elfGet hashmaliciousUnknownBrowse
                        • 185.152.92.158
                        statmentt.exeGet hashmaliciousScreenConnect ToolBrowse
                        • 85.239.34.190
                        ppc.elfGet hashmaliciousMiraiBrowse
                        • 85.239.34.134
                        sh4.elfGet hashmaliciousMiraiBrowse
                        • 85.239.34.134
                        No context
                        No context
                        No created / dropped files found
                        File type:ELF 32-bit LSB executable, ARM, EABI4 version 1 (SYSV), statically linked, stripped
                        Entropy (8bit):5.82221209455016
                        TrID:
                        • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                        File name:arm6.elf
                        File size:30'564 bytes
                        MD5:bad36d8fc61c2a221c2609dd5ff792af
                        SHA1:bc71c073a75c4847334fccdf7f6d0be3eedf18ea
                        SHA256:e5364f3baf34c9911eed614ca6c35fc032c854efb6c5ce45b2fc82b9c250cf53
                        SHA512:f40171a5ce6209d8cd3826704d34f12aae126a48ed68a77b2e6b5351828a1d9a47345894e70b550fa84fc6e35f3eccacbcb02084241fea3fcc86b5d3c7134406
                        SSDEEP:768:jenflWCgSKMJbDKmTbRI+VZi5A/oTgQHc1V0h:jenflWnwJb/ZIQi5AATgQH
                        TLSH:4FD20996F9819F11C5D1127AFA0E164E73131B2CF3EE77226E156F2067874BB0E3A816
                        File Content Preview:.ELF..............(.....T...4...4u......4. ...(......................q...q...............q...q...q.......&..........Q.td..................................-...L..................@-.,@...0....S..... 0....S.........../..0...0...@..../..t.......q....-.@0....S

                        ELF header

                        Class:ELF32
                        Data:2's complement, little endian
                        Version:1 (current)
                        Machine:ARM
                        Version Number:0x1
                        Type:EXEC (Executable file)
                        OS/ABI:UNIX - System V
                        ABI Version:0
                        Entry Point Address:0x8154
                        Flags:0x4000002
                        ELF Header Size:52
                        Program Header Offset:52
                        Program Header Size:32
                        Number of Program Headers:3
                        Section Header Offset:30004
                        Section Header Size:40
                        Number of Section Headers:14
                        Header String Table Index:13
                        NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                        NULL0x00x00x00x00x0000
                        .initPROGBITS0x80940x940x100x00x6AX004
                        .textPROGBITS0x80b00xb00x6c9c0x00x6AX0016
                        .finiPROGBITS0xed4c0x6d4c0x100x00x6AX004
                        .rodataPROGBITS0xed5c0x6d5c0x4940x00x2A004
                        .eh_framePROGBITS0x171f00x71f00x40x00x3WA004
                        .init_arrayINIT_ARRAY0x171f40x71f40x40x00x3WA004
                        .fini_arrayFINI_ARRAY0x171f80x71f80x40x00x3WA004
                        .jcrPROGBITS0x171fc0x71fc0x40x00x3WA004
                        .gotPROGBITS0x172000x72000x740x40x3WA004
                        .dataPROGBITS0x172740x72740x2440x00x3WA004
                        .bssNOBITS0x174b80x74b80x23dc0x00x3WA004
                        .ARM.attributesARM_ATTRIBUTES0x00x74b80x100x00x0001
                        .shstrtabSTRTAB0x00x74c80x6c0x00x0001
                        TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                        LOAD0x00x80000x80000x71f00x71f05.87390x5R E0x8000.init .text .fini .rodata
                        LOAD0x71f00x171f00x171f00x2c80x26a43.51360x6RW 0x8000.eh_frame .init_array .fini_array .jcr .got .data .bss
                        GNU_STACK0x00x00x00x00x00.00000x7RWE0x4
                        TimestampSIDSignatureSeveritySource IPSource PortDest IPDest PortProtocol
                        2024-12-30T02:57:45.631520+01002849816ETPRO MALWARE ELF/Multiverze CnC Checkin1192.168.2.135363285.239.34.1346666TCP
                        TimestampSource PortDest PortSource IPDest IP
                        Dec 30, 2024 02:57:45.618562937 CET536326666192.168.2.1385.239.34.134
                        Dec 30, 2024 02:57:45.623558998 CET66665363285.239.34.134192.168.2.13
                        Dec 30, 2024 02:57:45.623617887 CET536326666192.168.2.1385.239.34.134
                        Dec 30, 2024 02:57:45.631520033 CET536326666192.168.2.1385.239.34.134
                        Dec 30, 2024 02:57:45.636378050 CET66665363285.239.34.134192.168.2.13
                        Dec 30, 2024 02:57:49.769591093 CET66665363285.239.34.134192.168.2.13
                        Dec 30, 2024 02:57:49.769711971 CET536326666192.168.2.1385.239.34.134
                        Dec 30, 2024 02:57:49.769885063 CET536326666192.168.2.1385.239.34.134
                        Dec 30, 2024 02:57:49.774660110 CET66665363285.239.34.134192.168.2.13
                        Dec 30, 2024 02:57:54.781241894 CET66665363285.239.34.134192.168.2.13
                        Dec 30, 2024 02:57:54.781501055 CET536326666192.168.2.1385.239.34.134
                        Dec 30, 2024 02:57:54.781502008 CET536326666192.168.2.1385.239.34.134
                        Dec 30, 2024 02:57:54.786493063 CET66665363285.239.34.134192.168.2.13
                        Dec 30, 2024 02:57:59.125097036 CET66665363285.239.34.134192.168.2.13
                        Dec 30, 2024 02:57:59.125255108 CET536326666192.168.2.1385.239.34.134
                        Dec 30, 2024 02:57:59.125308037 CET536326666192.168.2.1385.239.34.134
                        Dec 30, 2024 02:57:59.130160093 CET66665363285.239.34.134192.168.2.13
                        Dec 30, 2024 02:57:59.819967985 CET66665363285.239.34.134192.168.2.13
                        Dec 30, 2024 02:57:59.820158958 CET536326666192.168.2.1385.239.34.134
                        Dec 30, 2024 02:57:59.825062037 CET66665363285.239.34.134192.168.2.13
                        Dec 30, 2024 02:58:04.857590914 CET66665363285.239.34.134192.168.2.13
                        Dec 30, 2024 02:58:04.857888937 CET536326666192.168.2.1385.239.34.134
                        Dec 30, 2024 02:58:04.862785101 CET66665363285.239.34.134192.168.2.13
                        Dec 30, 2024 02:58:09.872098923 CET66665363285.239.34.134192.168.2.13
                        Dec 30, 2024 02:58:09.872332096 CET536326666192.168.2.1385.239.34.134
                        Dec 30, 2024 02:58:09.877321959 CET66665363285.239.34.134192.168.2.13
                        Dec 30, 2024 02:58:14.136725903 CET66665363285.239.34.134192.168.2.13
                        Dec 30, 2024 02:58:14.136903048 CET536326666192.168.2.1385.239.34.134
                        Dec 30, 2024 02:58:14.141838074 CET66665363285.239.34.134192.168.2.13
                        Dec 30, 2024 02:58:14.879164934 CET66665363285.239.34.134192.168.2.13
                        Dec 30, 2024 02:58:14.879334927 CET536326666192.168.2.1385.239.34.134
                        Dec 30, 2024 02:58:14.884191036 CET66665363285.239.34.134192.168.2.13
                        Dec 30, 2024 02:58:19.884844065 CET66665363285.239.34.134192.168.2.13
                        Dec 30, 2024 02:58:19.885102034 CET536326666192.168.2.1385.239.34.134
                        Dec 30, 2024 02:58:19.890022993 CET66665363285.239.34.134192.168.2.13
                        Dec 30, 2024 02:58:24.956624031 CET66665363285.239.34.134192.168.2.13
                        Dec 30, 2024 02:58:24.957279921 CET536326666192.168.2.1385.239.34.134
                        Dec 30, 2024 02:58:24.962222099 CET66665363285.239.34.134192.168.2.13
                        Dec 30, 2024 02:58:29.153701067 CET66665363285.239.34.134192.168.2.13
                        Dec 30, 2024 02:58:29.154056072 CET536326666192.168.2.1385.239.34.134
                        Dec 30, 2024 02:58:29.158924103 CET66665363285.239.34.134192.168.2.13
                        Dec 30, 2024 02:58:29.974155903 CET66665363285.239.34.134192.168.2.13
                        Dec 30, 2024 02:58:29.974442959 CET536326666192.168.2.1385.239.34.134
                        Dec 30, 2024 02:58:29.979352951 CET66665363285.239.34.134192.168.2.13
                        Dec 30, 2024 02:58:34.983551025 CET66665363285.239.34.134192.168.2.13
                        Dec 30, 2024 02:58:34.983659029 CET536326666192.168.2.1385.239.34.134
                        Dec 30, 2024 02:58:34.988636017 CET66665363285.239.34.134192.168.2.13
                        Dec 30, 2024 02:58:40.051960945 CET66665363285.239.34.134192.168.2.13
                        Dec 30, 2024 02:58:40.052269936 CET536326666192.168.2.1385.239.34.134
                        Dec 30, 2024 02:58:40.057194948 CET66665363285.239.34.134192.168.2.13
                        Dec 30, 2024 02:58:44.156881094 CET66665363285.239.34.134192.168.2.13
                        Dec 30, 2024 02:58:44.157161951 CET536326666192.168.2.1385.239.34.134
                        Dec 30, 2024 02:58:44.162100077 CET66665363285.239.34.134192.168.2.13
                        Dec 30, 2024 02:58:45.069504023 CET66665363285.239.34.134192.168.2.13
                        Dec 30, 2024 02:58:45.069799900 CET536326666192.168.2.1385.239.34.134
                        Dec 30, 2024 02:58:45.074685097 CET66665363285.239.34.134192.168.2.13
                        Dec 30, 2024 02:58:50.080955982 CET66665363285.239.34.134192.168.2.13
                        Dec 30, 2024 02:58:50.081604004 CET536326666192.168.2.1385.239.34.134
                        Dec 30, 2024 02:58:50.086551905 CET66665363285.239.34.134192.168.2.13
                        Dec 30, 2024 02:58:55.124850035 CET66665363285.239.34.134192.168.2.13
                        Dec 30, 2024 02:58:55.125174046 CET536326666192.168.2.1385.239.34.134
                        Dec 30, 2024 02:58:55.130084038 CET66665363285.239.34.134192.168.2.13
                        Dec 30, 2024 02:58:59.169323921 CET66665363285.239.34.134192.168.2.13
                        Dec 30, 2024 02:58:59.169629097 CET536326666192.168.2.1385.239.34.134
                        Dec 30, 2024 02:58:59.174601078 CET66665363285.239.34.134192.168.2.13
                        Dec 30, 2024 02:59:00.136609077 CET66665363285.239.34.134192.168.2.13
                        Dec 30, 2024 02:59:00.136894941 CET536326666192.168.2.1385.239.34.134
                        Dec 30, 2024 02:59:00.141896009 CET66665363285.239.34.134192.168.2.13
                        Dec 30, 2024 02:59:05.147859097 CET66665363285.239.34.134192.168.2.13
                        Dec 30, 2024 02:59:05.148248911 CET536326666192.168.2.1385.239.34.134
                        Dec 30, 2024 02:59:05.153213978 CET66665363285.239.34.134192.168.2.13
                        Dec 30, 2024 02:59:10.159460068 CET66665363285.239.34.134192.168.2.13
                        Dec 30, 2024 02:59:10.159781933 CET536326666192.168.2.1385.239.34.134
                        Dec 30, 2024 02:59:10.164659023 CET66665363285.239.34.134192.168.2.13
                        Dec 30, 2024 02:59:14.185374975 CET66665363285.239.34.134192.168.2.13
                        Dec 30, 2024 02:59:14.185699940 CET536326666192.168.2.1385.239.34.134
                        Dec 30, 2024 02:59:14.190634012 CET66665363285.239.34.134192.168.2.13
                        Dec 30, 2024 02:59:15.169172049 CET66665363285.239.34.134192.168.2.13
                        Dec 30, 2024 02:59:15.169411898 CET536326666192.168.2.1385.239.34.134
                        Dec 30, 2024 02:59:15.174339056 CET66665363285.239.34.134192.168.2.13
                        Dec 30, 2024 02:59:20.180269957 CET66665363285.239.34.134192.168.2.13
                        Dec 30, 2024 02:59:20.180587053 CET536326666192.168.2.1385.239.34.134
                        Dec 30, 2024 02:59:20.185518980 CET66665363285.239.34.134192.168.2.13
                        Dec 30, 2024 02:59:25.219510078 CET66665363285.239.34.134192.168.2.13
                        Dec 30, 2024 02:59:25.220029116 CET536326666192.168.2.1385.239.34.134
                        Dec 30, 2024 02:59:25.225013018 CET66665363285.239.34.134192.168.2.13
                        Dec 30, 2024 02:59:29.254153967 CET66665363285.239.34.134192.168.2.13
                        Dec 30, 2024 02:59:29.254487991 CET536326666192.168.2.1385.239.34.134
                        Dec 30, 2024 02:59:29.259455919 CET66665363285.239.34.134192.168.2.13
                        Dec 30, 2024 02:59:30.259890079 CET66665363285.239.34.134192.168.2.13
                        Dec 30, 2024 02:59:30.260263920 CET536326666192.168.2.1385.239.34.134
                        Dec 30, 2024 02:59:30.265243053 CET66665363285.239.34.134192.168.2.13
                        Dec 30, 2024 02:59:35.273374081 CET66665363285.239.34.134192.168.2.13
                        Dec 30, 2024 02:59:35.273636103 CET536326666192.168.2.1385.239.34.134
                        Dec 30, 2024 02:59:35.278556108 CET66665363285.239.34.134192.168.2.13
                        Dec 30, 2024 02:59:40.321480989 CET66665363285.239.34.134192.168.2.13
                        Dec 30, 2024 02:59:40.321887016 CET536326666192.168.2.1385.239.34.134
                        Dec 30, 2024 02:59:40.326983929 CET66665363285.239.34.134192.168.2.13
                        Dec 30, 2024 02:59:44.262125969 CET66665363285.239.34.134192.168.2.13
                        Dec 30, 2024 02:59:44.262491941 CET536326666192.168.2.1385.239.34.134
                        Dec 30, 2024 02:59:44.267394066 CET66665363285.239.34.134192.168.2.13
                        Dec 30, 2024 02:59:45.330933094 CET66665363285.239.34.134192.168.2.13
                        Dec 30, 2024 02:59:45.331465006 CET536326666192.168.2.1385.239.34.134
                        Dec 30, 2024 02:59:45.336389065 CET66665363285.239.34.134192.168.2.13
                        Dec 30, 2024 02:59:50.340199947 CET66665363285.239.34.134192.168.2.13
                        Dec 30, 2024 02:59:50.340490103 CET536326666192.168.2.1385.239.34.134
                        Dec 30, 2024 02:59:50.346164942 CET66665363285.239.34.134192.168.2.13
                        Dec 30, 2024 02:59:55.352575064 CET66665363285.239.34.134192.168.2.13
                        Dec 30, 2024 02:59:55.352979898 CET536326666192.168.2.1385.239.34.134
                        Dec 30, 2024 02:59:55.359070063 CET66665363285.239.34.134192.168.2.13
                        Dec 30, 2024 03:00:00.361077070 CET66665363285.239.34.134192.168.2.13
                        Dec 30, 2024 03:00:00.361404896 CET536326666192.168.2.1385.239.34.134
                        Dec 30, 2024 03:00:00.366395950 CET66665363285.239.34.134192.168.2.13
                        Dec 30, 2024 03:00:05.374866009 CET66665363285.239.34.134192.168.2.13
                        Dec 30, 2024 03:00:05.375340939 CET536326666192.168.2.1385.239.34.134
                        Dec 30, 2024 03:00:05.380285025 CET66665363285.239.34.134192.168.2.13
                        Dec 30, 2024 03:00:10.419771910 CET66665363285.239.34.134192.168.2.13
                        Dec 30, 2024 03:00:10.420043945 CET536326666192.168.2.1385.239.34.134
                        Dec 30, 2024 03:00:10.427011967 CET66665363285.239.34.134192.168.2.13
                        Dec 30, 2024 03:00:14.323437929 CET66665363285.239.34.134192.168.2.13
                        Dec 30, 2024 03:00:14.323997021 CET536326666192.168.2.1385.239.34.134
                        Dec 30, 2024 03:00:14.328857899 CET66665363285.239.34.134192.168.2.13
                        Dec 30, 2024 03:00:15.468075991 CET66665363285.239.34.134192.168.2.13
                        Dec 30, 2024 03:00:15.468394041 CET536326666192.168.2.1385.239.34.134
                        Dec 30, 2024 03:00:15.473372936 CET66665363285.239.34.134192.168.2.13
                        Dec 30, 2024 03:00:20.480803967 CET66665363285.239.34.134192.168.2.13
                        Dec 30, 2024 03:00:20.480982065 CET536326666192.168.2.1385.239.34.134
                        Dec 30, 2024 03:00:20.485944033 CET66665363285.239.34.134192.168.2.13
                        Dec 30, 2024 03:00:25.551759005 CET66665363285.239.34.134192.168.2.13
                        Dec 30, 2024 03:00:25.552045107 CET536326666192.168.2.1385.239.34.134
                        Dec 30, 2024 03:00:25.556905031 CET66665363285.239.34.134192.168.2.13
                        Dec 30, 2024 03:00:29.345689058 CET66665363285.239.34.134192.168.2.13
                        Dec 30, 2024 03:00:29.346007109 CET536326666192.168.2.1385.239.34.134
                        Dec 30, 2024 03:00:29.350797892 CET66665363285.239.34.134192.168.2.13
                        Dec 30, 2024 03:00:30.562424898 CET66665363285.239.34.134192.168.2.13
                        Dec 30, 2024 03:00:30.562536001 CET536326666192.168.2.1385.239.34.134
                        Dec 30, 2024 03:00:30.568104029 CET66665363285.239.34.134192.168.2.13
                        Dec 30, 2024 03:00:35.577301025 CET66665363285.239.34.134192.168.2.13
                        Dec 30, 2024 03:00:35.577469110 CET536326666192.168.2.1385.239.34.134
                        Dec 30, 2024 03:00:35.582324982 CET66665363285.239.34.134192.168.2.13
                        Dec 30, 2024 03:00:40.587140083 CET66665363285.239.34.134192.168.2.13
                        Dec 30, 2024 03:00:40.587409019 CET536326666192.168.2.1385.239.34.134
                        Dec 30, 2024 03:00:40.592246056 CET66665363285.239.34.134192.168.2.13
                        Dec 30, 2024 03:00:44.371689081 CET66665363285.239.34.134192.168.2.13
                        Dec 30, 2024 03:00:44.372004986 CET536326666192.168.2.1385.239.34.134
                        Dec 30, 2024 03:00:44.376904011 CET66665363285.239.34.134192.168.2.13
                        Dec 30, 2024 03:00:45.651693106 CET66665363285.239.34.134192.168.2.13
                        Dec 30, 2024 03:00:45.651887894 CET536326666192.168.2.1385.239.34.134
                        Dec 30, 2024 03:00:45.656712055 CET66665363285.239.34.134192.168.2.13
                        Dec 30, 2024 03:00:50.658427954 CET66665363285.239.34.134192.168.2.13
                        Dec 30, 2024 03:00:50.658736944 CET536326666192.168.2.1385.239.34.134
                        Dec 30, 2024 03:00:50.663608074 CET66665363285.239.34.134192.168.2.13
                        Dec 30, 2024 03:00:55.665345907 CET66665363285.239.34.134192.168.2.13
                        Dec 30, 2024 03:00:55.665549040 CET536326666192.168.2.1385.239.34.134
                        Dec 30, 2024 03:00:55.670435905 CET66665363285.239.34.134192.168.2.13
                        Dec 30, 2024 03:00:59.384677887 CET66665363285.239.34.134192.168.2.13
                        Dec 30, 2024 03:00:59.384994984 CET536326666192.168.2.1385.239.34.134
                        Dec 30, 2024 03:00:59.391382933 CET66665363285.239.34.134192.168.2.13
                        Dec 30, 2024 03:01:00.672554970 CET66665363285.239.34.134192.168.2.13
                        Dec 30, 2024 03:01:00.672911882 CET536326666192.168.2.1385.239.34.134
                        Dec 30, 2024 03:01:00.677794933 CET66665363285.239.34.134192.168.2.13
                        Dec 30, 2024 03:01:05.678678989 CET66665363285.239.34.134192.168.2.13
                        Dec 30, 2024 03:01:05.678941965 CET536326666192.168.2.1385.239.34.134
                        Dec 30, 2024 03:01:05.683762074 CET66665363285.239.34.134192.168.2.13
                        Dec 30, 2024 03:01:10.686405897 CET66665363285.239.34.134192.168.2.13
                        Dec 30, 2024 03:01:10.686959028 CET536326666192.168.2.1385.239.34.134
                        Dec 30, 2024 03:01:10.691768885 CET66665363285.239.34.134192.168.2.13
                        Dec 30, 2024 03:01:14.450656891 CET66665363285.239.34.134192.168.2.13
                        Dec 30, 2024 03:01:14.450824022 CET536326666192.168.2.1385.239.34.134
                        Dec 30, 2024 03:01:14.457017899 CET66665363285.239.34.134192.168.2.13
                        Dec 30, 2024 03:01:15.723196030 CET66665363285.239.34.134192.168.2.13
                        Dec 30, 2024 03:01:15.723361969 CET536326666192.168.2.1385.239.34.134
                        Dec 30, 2024 03:01:15.728251934 CET66665363285.239.34.134192.168.2.13
                        TimestampSource PortDest PortSource IPDest IP
                        Dec 30, 2024 03:00:30.669470072 CET4792553192.168.2.131.1.1.1
                        Dec 30, 2024 03:00:30.669470072 CET4148853192.168.2.131.1.1.1
                        Dec 30, 2024 03:00:30.676075935 CET53479251.1.1.1192.168.2.13
                        Dec 30, 2024 03:00:30.676662922 CET53414881.1.1.1192.168.2.13
                        TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                        Dec 30, 2024 03:00:30.669470072 CET192.168.2.131.1.1.10xe6e7Standard query (0)daisy.ubuntu.comA (IP address)IN (0x0001)false
                        Dec 30, 2024 03:00:30.669470072 CET192.168.2.131.1.1.10xacStandard query (0)daisy.ubuntu.com28IN (0x0001)false
                        TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                        Dec 30, 2024 03:00:30.676075935 CET1.1.1.1192.168.2.130xe6e7No error (0)daisy.ubuntu.com162.213.35.24A (IP address)IN (0x0001)false
                        Dec 30, 2024 03:00:30.676075935 CET1.1.1.1192.168.2.130xe6e7No error (0)daisy.ubuntu.com162.213.35.25A (IP address)IN (0x0001)false

                        System Behavior

                        Start time (UTC):01:57:44
                        Start date (UTC):30/12/2024
                        Path:/tmp/arm6.elf
                        Arguments:/tmp/arm6.elf
                        File size:4956856 bytes
                        MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                        Start time (UTC):01:57:44
                        Start date (UTC):30/12/2024
                        Path:/tmp/arm6.elf
                        Arguments:-
                        File size:4956856 bytes
                        MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1