Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
mips.elf

Overview

General Information

Sample name:mips.elf
Analysis ID:1582156
MD5:2f181e3de0868c522db24f49cb523aef
SHA1:5a3ead5cab99849fdf9c4be5c716e65b8ebf1798
SHA256:fa15665c6bf6fe55b2f10da21589d7be0b531bc0a0de1e1110c3621d8f93509a
Tags:elfuser-abuse_ch
Infos:

Detection

Score:56
Range:0 - 100
Whitelisted:false

Signatures

Multi AV Scanner detection for submitted file
Suricata IDS alerts for network traffic
Detected TCP or UDP traffic on non-standard ports
Sample has stripped symbol table
Sample listens on a socket
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1582156
Start date and time:2024-12-30 03:09:28 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 5m 13s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:mips.elf
Detection:MAL
Classification:mal56.linELF@0/0@2/0
Command:/tmp/mips.elf
PID:5796
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
$UICIDEBOY$
Standard Error:
  • system is lnxubuntu20
  • mips.elf (PID: 5796, Parent: 5720, MD5: 0083f1f0e77be34ad27f849842bbb00c) Arguments: /tmp/mips.elf
    • mips.elf New Fork (PID: 5798, Parent: 5796)
  • cleanup
No yara matches
TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
2024-12-30T03:10:34.033306+010028498161A Network Trojan was detected192.168.2.145078285.239.34.1346666TCP

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: mips.elfVirustotal: Detection: 22%Perma Link
Source: mips.elfReversingLabs: Detection: 26%

Networking

barindex
Source: Network trafficSuricata IDS: 2849816 - Severity 1 - ETPRO MALWARE ELF/Multiverze CnC Checkin : 192.168.2.14:50782 -> 85.239.34.134:6666
Source: global trafficTCP traffic: 192.168.2.14:50782 -> 85.239.34.134:6666
Source: /tmp/mips.elf (PID: 5796)Socket: 0.0.0.0:9902Jump to behavior
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: global trafficDNS traffic detected: DNS query: daisy.ubuntu.com
Source: ELF static info symbol of initial sample.symtab present: no
Source: classification engineClassification label: mal56.linELF@0/0@2/0
Source: /tmp/mips.elf (PID: 5796)Queries kernel information via 'uname': Jump to behavior
Source: mips.elf, 5796.1.000055c63824d000.000055c6382d4000.rw-.sdmpBinary or memory string: U!/etc/qemu-binfmt/mips
Source: mips.elf, 5796.1.000055c63824d000.000055c6382d4000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/mips
Source: mips.elf, 5796.1.00007ffe7b883000.00007ffe7b8a4000.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-mips/tmp/mips.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/mips.elf
Source: mips.elf, 5796.1.00007ffe7b883000.00007ffe7b8a4000.rw-.sdmpBinary or memory string: /usr/bin/qemu-mips
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath InterceptionDirect Volume AccessOS Credential Dumping11
Security Software Discovery
Remote ServicesData from Local System1
Non-Standard Port
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
mips.elf22%VirustotalBrowse
mips.elf26%ReversingLabsLinux.Backdoor.Gafgyt
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
daisy.ubuntu.com
162.213.35.24
truefalse
    high
    • No. of IPs < 25%
    • 25% < No. of IPs < 50%
    • 50% < No. of IPs < 75%
    • 75% < No. of IPs
    IPDomainCountryFlagASNASN NameMalicious
    85.239.34.134
    unknownRussian Federation
    134121RAINBOW-HKRainbownetworklimitedHKtrue
    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
    85.239.34.134arm6.elfGet hashmaliciousUnknownBrowse
      m68k.elfGet hashmaliciousUnknownBrowse
        sh4.elfGet hashmaliciousUnknownBrowse
          x86.elfGet hashmaliciousUnknownBrowse
            spc.elfGet hashmaliciousUnknownBrowse
              212.64.215.71-arm-2024-12-25T12_31_55.elfGet hashmaliciousUnknownBrowse
                ppc.elfGet hashmaliciousMiraiBrowse
                  sh4.elfGet hashmaliciousMiraiBrowse
                    mips.elfGet hashmaliciousMiraiBrowse
                      spc.elfGet hashmaliciousMiraiBrowse
                        MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                        daisy.ubuntu.comzmap.x86_64.elfGet hashmaliciousOkiruBrowse
                        • 162.213.35.24
                        rebirth.arm6.elfGet hashmaliciousGafgytBrowse
                        • 162.213.35.24
                        rebirth.x86.elfGet hashmaliciousGafgytBrowse
                        • 162.213.35.25
                        arm6.elfGet hashmaliciousUnknownBrowse
                        • 162.213.35.24
                        rebirth.sh4.elfGet hashmaliciousGafgytBrowse
                        • 162.213.35.25
                        sh4.elfGet hashmaliciousUnknownBrowse
                        • 162.213.35.25
                        rebirth.m68.elfGet hashmaliciousGafgytBrowse
                        • 162.213.35.25
                        rebirth.mpsl.elfGet hashmaliciousGafgytBrowse
                        • 162.213.35.25
                        MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                        RAINBOW-HKRainbownetworklimitedHKarm6.elfGet hashmaliciousUnknownBrowse
                        • 85.239.34.134
                        m68k.elfGet hashmaliciousUnknownBrowse
                        • 85.239.34.134
                        sh4.elfGet hashmaliciousUnknownBrowse
                        • 85.239.34.134
                        x86.elfGet hashmaliciousUnknownBrowse
                        • 85.239.34.134
                        spc.elfGet hashmaliciousUnknownBrowse
                        • 85.239.34.134
                        1C6ljtnwXP.exeGet hashmaliciousLummaCBrowse
                        • 85.239.54.77
                        212.64.215.71-arm-2024-12-25T12_31_55.elfGet hashmaliciousUnknownBrowse
                        • 85.239.34.134
                        armv5l.elfGet hashmaliciousUnknownBrowse
                        • 185.152.92.158
                        statmentt.exeGet hashmaliciousScreenConnect ToolBrowse
                        • 85.239.34.190
                        ppc.elfGet hashmaliciousMiraiBrowse
                        • 85.239.34.134
                        No context
                        No context
                        No created / dropped files found
                        File type:ELF 32-bit MSB executable, MIPS, MIPS-I version 1 (SYSV), statically linked, stripped
                        Entropy (8bit):5.270322729161104
                        TrID:
                        • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                        File name:mips.elf
                        File size:48'252 bytes
                        MD5:2f181e3de0868c522db24f49cb523aef
                        SHA1:5a3ead5cab99849fdf9c4be5c716e65b8ebf1798
                        SHA256:fa15665c6bf6fe55b2f10da21589d7be0b531bc0a0de1e1110c3621d8f93509a
                        SHA512:cf99cbd5069d6ef73fc85afc6528540cd6c4db78114d9eb10702f7e89b6ece496e0ca9e94e92c721c907b92258203bd38811092f21cedabecb82cdb37846d1f8
                        SSDEEP:768:66jdXr45I+LRiGwgIDXuKGDPLJUPyLjcAs8XHLFcCr3lYFAWQ:6GV8m+LagpDj1tDcCrVkQ
                        TLSH:B823A76A2F228FACF66CC23547B71E1556692B9263E1C1C0E2ACF5042F2065F585FFE4
                        File Content Preview:.ELF.....................@.....4.........4. ...(.............@...@...........................@...@........6..................@...@..................dt.Q............................<...'.D....!'.......................<...'.Dx...!........'9... .............

                        ELF header

                        Class:ELF32
                        Data:2's complement, big endian
                        Version:1 (current)
                        Machine:MIPS R3000
                        Version Number:0x1
                        Type:EXEC (Executable file)
                        OS/ABI:UNIX - System V
                        ABI Version:0
                        Entry Point Address:0x400290
                        Flags:0x1007
                        ELF Header Size:52
                        Program Header Offset:52
                        Program Header Size:32
                        Number of Program Headers:4
                        Section Header Offset:47612
                        Section Header Size:40
                        Number of Section Headers:16
                        Header String Table Index:15
                        NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                        NULL0x00x00x00x00x0000
                        .initPROGBITS0x4000b40xb40x8c0x00x6AX004
                        .textPROGBITS0x4001400x1400xa8500x00x6AX0016
                        .finiPROGBITS0x40a9900xa9900x5c0x00x6AX004
                        .rodataPROGBITS0x40a9f00xa9f00x8c00x00x2A0016
                        .eh_framePROGBITS0x40c2b00xb2b00x440x00x3WA004
                        .tbssNOBITS0x40c2f40xb2f40x80x00x403WAT004
                        .ctorsPROGBITS0x40c2f40xb2f40x80x00x3WA004
                        .dtorsPROGBITS0x40c2fc0xb2fc0x80x00x3WA004
                        .jcrPROGBITS0x40c3040xb3040x40x00x3WA004
                        .dataPROGBITS0x40c3100xb3100x2440x00x3WA0016
                        .gotPROGBITS0x40c5600xb5600x4300x40x10000003WAp0016
                        .sbssNOBITS0x40c9900xb9900x400x00x10000003WAp004
                        .bssNOBITS0x40c9d00xb9900x2ee80x00x3WA0016
                        .mdebug.abi32PROGBITS0x84c0xb9900x00x00x0001
                        .shstrtabSTRTAB0x00xb9900x6c0x00x0001
                        TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                        LOAD0x00x4000000x4000000xb2b00xb2b05.30890x5R E0x1000.init .text .fini .rodata
                        LOAD0xb2b00x40c2b00x40c2b00x6e00x36083.72100x6RW 0x1000.eh_frame .tbss .ctors .dtors .jcr .data .got .sbss .bss
                        TLS0xb2f40x40c2f40x40c2f40x00x80.00000x4R 0x4.tbss
                        GNU_STACK0x00x00x00x00x00.00000x7RWE0x4
                        TimestampSIDSignatureSeveritySource IPSource PortDest IPDest PortProtocol
                        2024-12-30T03:10:34.033306+01002849816ETPRO MALWARE ELF/Multiverze CnC Checkin1192.168.2.145078285.239.34.1346666TCP
                        TimestampSource PortDest PortSource IPDest IP
                        Dec 30, 2024 03:10:34.020191908 CET507826666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:10:34.025109053 CET66665078285.239.34.134192.168.2.14
                        Dec 30, 2024 03:10:34.025152922 CET507826666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:10:34.033305883 CET507826666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:10:34.038465977 CET66665078285.239.34.134192.168.2.14
                        Dec 30, 2024 03:10:38.388077974 CET66665078285.239.34.134192.168.2.14
                        Dec 30, 2024 03:10:38.388371944 CET507826666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:10:38.388489962 CET507826666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:10:38.393274069 CET66665078285.239.34.134192.168.2.14
                        Dec 30, 2024 03:10:43.419946909 CET66665078285.239.34.134192.168.2.14
                        Dec 30, 2024 03:10:43.420474052 CET507826666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:10:43.420474052 CET507826666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:10:43.425378084 CET66665078285.239.34.134192.168.2.14
                        Dec 30, 2024 03:10:45.184483051 CET66665078285.239.34.134192.168.2.14
                        Dec 30, 2024 03:10:45.184680939 CET507826666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:10:45.184719086 CET507826666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:10:45.189413071 CET66665078285.239.34.134192.168.2.14
                        Dec 30, 2024 03:10:48.458971024 CET66665078285.239.34.134192.168.2.14
                        Dec 30, 2024 03:10:48.459322929 CET507826666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:10:48.464163065 CET66665078285.239.34.134192.168.2.14
                        Dec 30, 2024 03:10:53.471301079 CET66665078285.239.34.134192.168.2.14
                        Dec 30, 2024 03:10:53.471611023 CET507826666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:10:53.476409912 CET66665078285.239.34.134192.168.2.14
                        Dec 30, 2024 03:10:58.550302029 CET66665078285.239.34.134192.168.2.14
                        Dec 30, 2024 03:10:58.550537109 CET507826666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:10:58.555371046 CET66665078285.239.34.134192.168.2.14
                        Dec 30, 2024 03:11:00.231518030 CET66665078285.239.34.134192.168.2.14
                        Dec 30, 2024 03:11:00.232074976 CET507826666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:11:00.236933947 CET66665078285.239.34.134192.168.2.14
                        Dec 30, 2024 03:11:03.562275887 CET66665078285.239.34.134192.168.2.14
                        Dec 30, 2024 03:11:03.562784910 CET507826666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:11:03.567656040 CET66665078285.239.34.134192.168.2.14
                        Dec 30, 2024 03:11:08.572721004 CET66665078285.239.34.134192.168.2.14
                        Dec 30, 2024 03:11:08.573041916 CET507826666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:11:08.578429937 CET66665078285.239.34.134192.168.2.14
                        Dec 30, 2024 03:11:13.584321976 CET66665078285.239.34.134192.168.2.14
                        Dec 30, 2024 03:11:13.584758043 CET507826666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:11:13.589725971 CET66665078285.239.34.134192.168.2.14
                        Dec 30, 2024 03:11:15.249490023 CET66665078285.239.34.134192.168.2.14
                        Dec 30, 2024 03:11:15.249659061 CET507826666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:11:15.254594088 CET66665078285.239.34.134192.168.2.14
                        Dec 30, 2024 03:11:18.655828953 CET66665078285.239.34.134192.168.2.14
                        Dec 30, 2024 03:11:18.656114101 CET507826666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:11:18.661005020 CET66665078285.239.34.134192.168.2.14
                        Dec 30, 2024 03:11:23.667625904 CET66665078285.239.34.134192.168.2.14
                        Dec 30, 2024 03:11:23.668085098 CET507826666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:11:23.673055887 CET66665078285.239.34.134192.168.2.14
                        Dec 30, 2024 03:11:28.680294037 CET66665078285.239.34.134192.168.2.14
                        Dec 30, 2024 03:11:28.680632114 CET507826666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:11:28.685635090 CET66665078285.239.34.134192.168.2.14
                        Dec 30, 2024 03:11:30.255067110 CET66665078285.239.34.134192.168.2.14
                        Dec 30, 2024 03:11:30.255290031 CET507826666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:11:30.260238886 CET66665078285.239.34.134192.168.2.14
                        Dec 30, 2024 03:11:33.724308014 CET66665078285.239.34.134192.168.2.14
                        Dec 30, 2024 03:11:33.724539995 CET507826666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:11:33.729372025 CET66665078285.239.34.134192.168.2.14
                        Dec 30, 2024 03:11:38.732477903 CET66665078285.239.34.134192.168.2.14
                        Dec 30, 2024 03:11:38.733026028 CET507826666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:11:38.737948895 CET66665078285.239.34.134192.168.2.14
                        Dec 30, 2024 03:11:43.738851070 CET66665078285.239.34.134192.168.2.14
                        Dec 30, 2024 03:11:43.739188910 CET507826666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:11:43.744055033 CET66665078285.239.34.134192.168.2.14
                        Dec 30, 2024 03:11:45.262883902 CET66665078285.239.34.134192.168.2.14
                        Dec 30, 2024 03:11:45.263158083 CET507826666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:11:45.268018007 CET66665078285.239.34.134192.168.2.14
                        Dec 30, 2024 03:11:48.750447035 CET66665078285.239.34.134192.168.2.14
                        Dec 30, 2024 03:11:48.750852108 CET507826666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:11:48.756762028 CET66665078285.239.34.134192.168.2.14
                        Dec 30, 2024 03:11:53.777851105 CET66665078285.239.34.134192.168.2.14
                        Dec 30, 2024 03:11:53.778162956 CET507826666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:11:53.783103943 CET66665078285.239.34.134192.168.2.14
                        Dec 30, 2024 03:11:58.824455023 CET66665078285.239.34.134192.168.2.14
                        Dec 30, 2024 03:11:58.824647903 CET507826666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:11:58.829529047 CET66665078285.239.34.134192.168.2.14
                        Dec 30, 2024 03:12:00.273380995 CET66665078285.239.34.134192.168.2.14
                        Dec 30, 2024 03:12:00.273689985 CET507826666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:12:00.278713942 CET66665078285.239.34.134192.168.2.14
                        Dec 30, 2024 03:12:03.836692095 CET66665078285.239.34.134192.168.2.14
                        Dec 30, 2024 03:12:03.837028027 CET507826666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:12:03.841873884 CET66665078285.239.34.134192.168.2.14
                        Dec 30, 2024 03:12:08.853529930 CET66665078285.239.34.134192.168.2.14
                        Dec 30, 2024 03:12:08.853837013 CET507826666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:12:08.858776093 CET66665078285.239.34.134192.168.2.14
                        Dec 30, 2024 03:12:13.874579906 CET66665078285.239.34.134192.168.2.14
                        Dec 30, 2024 03:12:13.874834061 CET507826666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:12:13.879725933 CET66665078285.239.34.134192.168.2.14
                        Dec 30, 2024 03:12:15.285465956 CET66665078285.239.34.134192.168.2.14
                        Dec 30, 2024 03:12:15.285778999 CET507826666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:12:15.290611982 CET66665078285.239.34.134192.168.2.14
                        Dec 30, 2024 03:12:18.883717060 CET66665078285.239.34.134192.168.2.14
                        Dec 30, 2024 03:12:18.884115934 CET507826666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:12:18.888993025 CET66665078285.239.34.134192.168.2.14
                        Dec 30, 2024 03:12:23.925642967 CET66665078285.239.34.134192.168.2.14
                        Dec 30, 2024 03:12:23.925935030 CET507826666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:12:23.930882931 CET66665078285.239.34.134192.168.2.14
                        Dec 30, 2024 03:12:28.942204952 CET66665078285.239.34.134192.168.2.14
                        Dec 30, 2024 03:12:28.942493916 CET507826666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:12:28.947355032 CET66665078285.239.34.134192.168.2.14
                        Dec 30, 2024 03:12:30.361253023 CET66665078285.239.34.134192.168.2.14
                        Dec 30, 2024 03:12:30.361673117 CET507826666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:12:30.366580963 CET66665078285.239.34.134192.168.2.14
                        Dec 30, 2024 03:12:33.961359024 CET66665078285.239.34.134192.168.2.14
                        Dec 30, 2024 03:12:33.961642027 CET507826666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:12:33.966490030 CET66665078285.239.34.134192.168.2.14
                        Dec 30, 2024 03:12:38.977046013 CET66665078285.239.34.134192.168.2.14
                        Dec 30, 2024 03:12:38.977341890 CET507826666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:12:38.982235909 CET66665078285.239.34.134192.168.2.14
                        Dec 30, 2024 03:12:43.988022089 CET66665078285.239.34.134192.168.2.14
                        Dec 30, 2024 03:12:43.988368988 CET507826666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:12:43.993221045 CET66665078285.239.34.134192.168.2.14
                        Dec 30, 2024 03:12:45.371416092 CET66665078285.239.34.134192.168.2.14
                        Dec 30, 2024 03:12:45.371790886 CET507826666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:12:45.376626015 CET66665078285.239.34.134192.168.2.14
                        Dec 30, 2024 03:12:49.068489075 CET66665078285.239.34.134192.168.2.14
                        Dec 30, 2024 03:12:49.068870068 CET507826666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:12:49.073823929 CET66665078285.239.34.134192.168.2.14
                        Dec 30, 2024 03:12:54.079898119 CET66665078285.239.34.134192.168.2.14
                        Dec 30, 2024 03:12:54.080442905 CET507826666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:12:54.085227013 CET66665078285.239.34.134192.168.2.14
                        Dec 30, 2024 03:12:59.157087088 CET66665078285.239.34.134192.168.2.14
                        Dec 30, 2024 03:12:59.157464027 CET507826666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:12:59.162362099 CET66665078285.239.34.134192.168.2.14
                        Dec 30, 2024 03:13:00.377259970 CET66665078285.239.34.134192.168.2.14
                        Dec 30, 2024 03:13:00.377583981 CET507826666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:13:00.382441044 CET66665078285.239.34.134192.168.2.14
                        Dec 30, 2024 03:13:04.158648968 CET66665078285.239.34.134192.168.2.14
                        Dec 30, 2024 03:13:04.159061909 CET507826666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:13:04.163938046 CET66665078285.239.34.134192.168.2.14
                        Dec 30, 2024 03:13:09.168380976 CET66665078285.239.34.134192.168.2.14
                        Dec 30, 2024 03:13:09.168699980 CET507826666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:13:09.173649073 CET66665078285.239.34.134192.168.2.14
                        Dec 30, 2024 03:13:14.181231976 CET66665078285.239.34.134192.168.2.14
                        Dec 30, 2024 03:13:14.181499958 CET507826666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:13:14.186335087 CET66665078285.239.34.134192.168.2.14
                        Dec 30, 2024 03:13:15.383672953 CET66665078285.239.34.134192.168.2.14
                        Dec 30, 2024 03:13:15.383862972 CET507826666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:13:15.388672113 CET66665078285.239.34.134192.168.2.14
                        Dec 30, 2024 03:13:19.222951889 CET66665078285.239.34.134192.168.2.14
                        Dec 30, 2024 03:13:19.223201990 CET507826666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:13:19.228029966 CET66665078285.239.34.134192.168.2.14
                        Dec 30, 2024 03:13:19.874438047 CET4517053192.168.2.148.8.8.8
                        Dec 30, 2024 03:13:19.879390001 CET53451708.8.8.8192.168.2.14
                        Dec 30, 2024 03:13:19.879442930 CET4517053192.168.2.148.8.8.8
                        Dec 30, 2024 03:13:19.879473925 CET4517053192.168.2.148.8.8.8
                        Dec 30, 2024 03:13:19.879504919 CET4517053192.168.2.148.8.8.8
                        Dec 30, 2024 03:13:19.884268045 CET53451708.8.8.8192.168.2.14
                        Dec 30, 2024 03:13:19.884280920 CET53451708.8.8.8192.168.2.14
                        Dec 30, 2024 03:13:20.312150955 CET53451708.8.8.8192.168.2.14
                        Dec 30, 2024 03:13:20.312216043 CET4517053192.168.2.148.8.8.8
                        Dec 30, 2024 03:13:22.310693026 CET53451708.8.8.8192.168.2.14
                        Dec 30, 2024 03:13:22.310894012 CET4517053192.168.2.148.8.8.8
                        Dec 30, 2024 03:13:22.315684080 CET53451708.8.8.8192.168.2.14
                        Dec 30, 2024 03:13:24.239388943 CET66665078285.239.34.134192.168.2.14
                        Dec 30, 2024 03:13:24.239712954 CET507826666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:13:24.244575024 CET66665078285.239.34.134192.168.2.14
                        Dec 30, 2024 03:13:29.246809006 CET66665078285.239.34.134192.168.2.14
                        Dec 30, 2024 03:13:29.247148037 CET507826666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:13:29.251950979 CET66665078285.239.34.134192.168.2.14
                        Dec 30, 2024 03:13:30.419869900 CET66665078285.239.34.134192.168.2.14
                        Dec 30, 2024 03:13:30.420063972 CET507826666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:13:30.424963951 CET66665078285.239.34.134192.168.2.14
                        Dec 30, 2024 03:13:34.253118038 CET66665078285.239.34.134192.168.2.14
                        Dec 30, 2024 03:13:34.253355980 CET507826666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:13:34.258249998 CET66665078285.239.34.134192.168.2.14
                        Dec 30, 2024 03:13:39.264046907 CET66665078285.239.34.134192.168.2.14
                        Dec 30, 2024 03:13:39.264285088 CET507826666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:13:39.269141912 CET66665078285.239.34.134192.168.2.14
                        Dec 30, 2024 03:13:44.275485039 CET66665078285.239.34.134192.168.2.14
                        Dec 30, 2024 03:13:44.275650024 CET507826666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:13:44.280523062 CET66665078285.239.34.134192.168.2.14
                        Dec 30, 2024 03:13:45.456758976 CET66665078285.239.34.134192.168.2.14
                        Dec 30, 2024 03:13:45.456926107 CET507826666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:13:45.464337111 CET66665078285.239.34.134192.168.2.14
                        Dec 30, 2024 03:13:49.289251089 CET66665078285.239.34.134192.168.2.14
                        Dec 30, 2024 03:13:49.289468050 CET507826666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:13:49.294270039 CET66665078285.239.34.134192.168.2.14
                        Dec 30, 2024 03:13:54.359447002 CET66665078285.239.34.134192.168.2.14
                        Dec 30, 2024 03:13:54.359702110 CET507826666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:13:54.364554882 CET66665078285.239.34.134192.168.2.14
                        Dec 30, 2024 03:13:59.370117903 CET66665078285.239.34.134192.168.2.14
                        Dec 30, 2024 03:13:59.370348930 CET507826666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:13:59.375233889 CET66665078285.239.34.134192.168.2.14
                        Dec 30, 2024 03:14:00.463402033 CET66665078285.239.34.134192.168.2.14
                        Dec 30, 2024 03:14:00.463573933 CET507826666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:14:00.468367100 CET66665078285.239.34.134192.168.2.14
                        Dec 30, 2024 03:14:04.382577896 CET66665078285.239.34.134192.168.2.14
                        Dec 30, 2024 03:14:04.383021116 CET507826666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:14:04.387959957 CET66665078285.239.34.134192.168.2.14
                        TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                        Dec 30, 2024 03:13:19.879473925 CET192.168.2.148.8.8.80xd95bStandard query (0)daisy.ubuntu.comA (IP address)IN (0x0001)false
                        Dec 30, 2024 03:13:19.879504919 CET192.168.2.148.8.8.80x8fStandard query (0)daisy.ubuntu.com28IN (0x0001)false
                        TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                        Dec 30, 2024 03:13:20.312150955 CET8.8.8.8192.168.2.140xd95bNo error (0)daisy.ubuntu.com162.213.35.24A (IP address)IN (0x0001)false
                        Dec 30, 2024 03:13:20.312150955 CET8.8.8.8192.168.2.140xd95bNo error (0)daisy.ubuntu.com162.213.35.25A (IP address)IN (0x0001)false

                        System Behavior

                        Start time (UTC):02:10:33
                        Start date (UTC):30/12/2024
                        Path:/tmp/mips.elf
                        Arguments:/tmp/mips.elf
                        File size:5777432 bytes
                        MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                        Start time (UTC):02:10:33
                        Start date (UTC):30/12/2024
                        Path:/tmp/mips.elf
                        Arguments:-
                        File size:5777432 bytes
                        MD5 hash:0083f1f0e77be34ad27f849842bbb00c