Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
ppc.elf

Overview

General Information

Sample name:ppc.elf
Analysis ID:1582161
MD5:c3efdf251eeee0d1ba7c08ed9124e94e
SHA1:1e29aa226a1efd085451b556dbfc1b12d8c0f33a
SHA256:f93ef9fa52efcf0f438767ec7db0bf85490a9c282dbfa4d76c56d0061368ab7c
Tags:elfuser-abuse_ch
Infos:

Detection

Score:56
Range:0 - 100
Whitelisted:false

Signatures

Multi AV Scanner detection for submitted file
Suricata IDS alerts for network traffic
Detected TCP or UDP traffic on non-standard ports
Sample has stripped symbol table
Sample listens on a socket
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1582161
Start date and time:2024-12-30 03:14:13 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 5m 4s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:ppc.elf
Detection:MAL
Classification:mal56.linELF@0/0@2/0
Command:/tmp/ppc.elf
PID:5591
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
$UICIDEBOY$
Standard Error:
  • system is lnxubuntu20
  • ppc.elf (PID: 5591, Parent: 5506, MD5: ae65271c943d3451b7f026d1fadccea6) Arguments: /tmp/ppc.elf
    • ppc.elf New Fork (PID: 5593, Parent: 5591)
  • cleanup
No yara matches
TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
2024-12-30T03:15:11.544776+010028498161A Network Trojan was detected192.168.2.145077285.239.34.1346666TCP

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: ppc.elfVirustotal: Detection: 22%Perma Link
Source: ppc.elfReversingLabs: Detection: 23%

Networking

barindex
Source: Network trafficSuricata IDS: 2849816 - Severity 1 - ETPRO MALWARE ELF/Multiverze CnC Checkin : 192.168.2.14:50772 -> 85.239.34.134:6666
Source: global trafficTCP traffic: 192.168.2.14:50772 -> 85.239.34.134:6666
Source: /tmp/ppc.elf (PID: 5591)Socket: 0.0.0.0:9902Jump to behavior
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: global trafficDNS traffic detected: DNS query: daisy.ubuntu.com
Source: ELF static info symbol of initial sample.symtab present: no
Source: classification engineClassification label: mal56.linELF@0/0@2/0
Source: /tmp/ppc.elf (PID: 5591)Queries kernel information via 'uname': Jump to behavior
Source: ppc.elf, 5591.1.0000560290fe3000.0000560291093000.rw-.sdmpBinary or memory string: !/etc/qemu-binfmt/ppc11!hotpluggableq
Source: ppc.elf, 5591.1.00007ffc0f91c000.00007ffc0f93d000.rw-.sdmpBinary or memory string: Eyx86_64/usr/bin/qemu-ppc/tmp/ppc.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/ppc.elf
Source: ppc.elf, 5591.1.0000560290fe3000.0000560291093000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/ppc
Source: ppc.elf, 5591.1.00007ffc0f91c000.00007ffc0f93d000.rw-.sdmpBinary or memory string: /usr/bin/qemu-ppc
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath InterceptionDirect Volume AccessOS Credential Dumping11
Security Software Discovery
Remote ServicesData from Local System1
Non-Standard Port
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
ppc.elf22%VirustotalBrowse
ppc.elf24%ReversingLabsLinux.Backdoor.Gafgyt
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
daisy.ubuntu.com
162.213.35.24
truefalse
    high
    • No. of IPs < 25%
    • 25% < No. of IPs < 50%
    • 50% < No. of IPs < 75%
    • 75% < No. of IPs
    IPDomainCountryFlagASNASN NameMalicious
    85.239.34.134
    unknownRussian Federation
    134121RAINBOW-HKRainbownetworklimitedHKtrue
    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
    85.239.34.134mips.elfGet hashmaliciousUnknownBrowse
      arm6.elfGet hashmaliciousUnknownBrowse
        m68k.elfGet hashmaliciousUnknownBrowse
          sh4.elfGet hashmaliciousUnknownBrowse
            x86.elfGet hashmaliciousUnknownBrowse
              spc.elfGet hashmaliciousUnknownBrowse
                212.64.215.71-arm-2024-12-25T12_31_55.elfGet hashmaliciousUnknownBrowse
                  ppc.elfGet hashmaliciousMiraiBrowse
                    sh4.elfGet hashmaliciousMiraiBrowse
                      mips.elfGet hashmaliciousMiraiBrowse
                        MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                        daisy.ubuntu.comrebirth.ppc.elfGet hashmaliciousGafgytBrowse
                        • 162.213.35.24
                        mips.elfGet hashmaliciousUnknownBrowse
                        • 162.213.35.24
                        zmap.x86_64.elfGet hashmaliciousOkiruBrowse
                        • 162.213.35.24
                        rebirth.arm6.elfGet hashmaliciousGafgytBrowse
                        • 162.213.35.24
                        rebirth.x86.elfGet hashmaliciousGafgytBrowse
                        • 162.213.35.25
                        arm6.elfGet hashmaliciousUnknownBrowse
                        • 162.213.35.24
                        rebirth.sh4.elfGet hashmaliciousGafgytBrowse
                        • 162.213.35.25
                        sh4.elfGet hashmaliciousUnknownBrowse
                        • 162.213.35.25
                        MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                        RAINBOW-HKRainbownetworklimitedHKmips.elfGet hashmaliciousUnknownBrowse
                        • 85.239.34.134
                        arm6.elfGet hashmaliciousUnknownBrowse
                        • 85.239.34.134
                        m68k.elfGet hashmaliciousUnknownBrowse
                        • 85.239.34.134
                        sh4.elfGet hashmaliciousUnknownBrowse
                        • 85.239.34.134
                        x86.elfGet hashmaliciousUnknownBrowse
                        • 85.239.34.134
                        spc.elfGet hashmaliciousUnknownBrowse
                        • 85.239.34.134
                        1C6ljtnwXP.exeGet hashmaliciousLummaCBrowse
                        • 85.239.54.77
                        212.64.215.71-arm-2024-12-25T12_31_55.elfGet hashmaliciousUnknownBrowse
                        • 85.239.34.134
                        armv5l.elfGet hashmaliciousUnknownBrowse
                        • 185.152.92.158
                        statmentt.exeGet hashmaliciousScreenConnect ToolBrowse
                        • 85.239.34.190
                        No context
                        No context
                        No created / dropped files found
                        File type:ELF 32-bit MSB executable, PowerPC or cisco 4500, version 1 (SYSV), statically linked, stripped
                        Entropy (8bit):5.723089109849778
                        TrID:
                        • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                        File name:ppc.elf
                        File size:38'232 bytes
                        MD5:c3efdf251eeee0d1ba7c08ed9124e94e
                        SHA1:1e29aa226a1efd085451b556dbfc1b12d8c0f33a
                        SHA256:f93ef9fa52efcf0f438767ec7db0bf85490a9c282dbfa4d76c56d0061368ab7c
                        SHA512:f61bc3f767d7a1ad414d20b8b049601871d23167baa54bea649ef97ec59c51486e2c953327e7025d1a9119639bdc69aa780c1780b6ae6d226b0859ddef9dfa00
                        SSDEEP:768:zEO+7tup2236opOoRAC+ZAYVBAcDjGK5awwwwwwL6wwwwwo0/waew09Sr:Az7d2qoAoKCaBVSr
                        TLSH:F103D913A30A0F5BE5675EF4363F1BE2939F9ED120F59A4A391F79818572A3201C2D8D
                        File Content Preview:.ELF...........................4.........4. ...(....................... ... ...........................p..+................T...T...T................dt.Q.............................!..|......$H...H.~E...$8!. |...N.. .!..|.......?.............../...@..`= .

                        ELF header

                        Class:ELF32
                        Data:2's complement, big endian
                        Version:1 (current)
                        Machine:PowerPC
                        Version Number:0x1
                        Type:EXEC (Executable file)
                        OS/ABI:UNIX - System V
                        ABI Version:0
                        Entry Point Address:0x10000218
                        Flags:0x0
                        ELF Header Size:52
                        Program Header Offset:52
                        Program Header Size:32
                        Number of Program Headers:4
                        Section Header Offset:37592
                        Section Header Size:40
                        Number of Section Headers:16
                        Header String Table Index:15
                        NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                        NULL0x00x00x00x00x0000
                        .initPROGBITS0x100000b40xb40x240x00x6AX004
                        .textPROGBITS0x100000d80xd80x7e9c0x00x6AX004
                        .finiPROGBITS0x10007f740x7f740x200x00x6AX004
                        .rodataPROGBITS0x10007f940x7f940x88c0x00x2A004
                        .eh_framePROGBITS0x100090000x90000x540x00x3WA004
                        .tbssNOBITS0x100090540x90540x80x00x403WAT004
                        .ctorsPROGBITS0x100090540x90540x80x00x3WA004
                        .dtorsPROGBITS0x1000905c0x905c0x80x00x3WA004
                        .jcrPROGBITS0x100090640x90640x40x00x3WA004
                        .dataPROGBITS0x100090680x90680x1c80x00x3WA004
                        .gotPROGBITS0x100092300x92300x100x40x7WAX004
                        .sdataPROGBITS0x100092400x92400x300x00x3WA004
                        .sbssNOBITS0x100092700x92700x580x00x3WA004
                        .bssNOBITS0x100092c80x92700x29240x00x3WA004
                        .shstrtabSTRTAB0x00x92700x650x00x0001
                        TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                        LOAD0x00x100000000x100000000x88200x88205.99340x5R E0x1000.init .text .fini .rodata
                        LOAD0x90000x100090000x100090000x2700x2bec3.77530x7RWE0x1000.eh_frame .tbss .ctors .dtors .jcr .data .got .sdata .sbss .bss
                        TLS0x90540x100090540x100090540x00x80.00000x4R 0x4.tbss
                        GNU_STACK0x00x00x00x00x00.00000x6RW 0x4
                        TimestampSIDSignatureSeveritySource IPSource PortDest IPDest PortProtocol
                        2024-12-30T03:15:11.544776+01002849816ETPRO MALWARE ELF/Multiverze CnC Checkin1192.168.2.145077285.239.34.1346666TCP
                        TimestampSource PortDest PortSource IPDest IP
                        Dec 30, 2024 03:15:11.537697077 CET507726666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:15:11.542568922 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:15:11.542620897 CET507726666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:15:11.544775963 CET507726666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:15:11.549563885 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:15:14.674320936 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:15:14.674582958 CET507726666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:15:14.674726963 CET507726666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:15:14.679449081 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:15:15.580405951 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:15:15.580629110 CET507726666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:15:15.580629110 CET507726666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:15:15.585423946 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:15:19.680586100 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:15:19.680716991 CET507726666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:15:19.680789948 CET507726666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:15:19.685566902 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:15:24.719575882 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:15:24.719883919 CET507726666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:15:24.724756956 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:15:29.757441044 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:15:29.757812023 CET507726666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:15:29.762669086 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:15:30.588228941 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:15:30.588658094 CET507726666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:15:30.593502045 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:15:34.774585009 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:15:34.774878025 CET507726666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:15:34.779647112 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:15:39.819505930 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:15:39.819756985 CET507726666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:15:39.824615955 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:15:44.855632067 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:15:44.855823994 CET507726666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:15:44.860615969 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:15:45.626327038 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:15:45.626487017 CET507726666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:15:45.631319046 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:15:49.869333982 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:15:49.869631052 CET507726666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:15:49.874542952 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:15:54.885335922 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:15:54.885731936 CET507726666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:15:54.890589952 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:15:59.955573082 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:15:59.955741882 CET507726666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:15:59.960500956 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:16:00.637916088 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:16:00.638194084 CET507726666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:16:00.643065929 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:16:04.961999893 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:16:04.962414026 CET507726666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:16:04.967287064 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:16:09.973017931 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:16:09.973323107 CET507726666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:16:09.978146076 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:16:15.007186890 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:16:15.007392883 CET507726666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:16:15.012298107 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:16:15.649616957 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:16:15.649804115 CET507726666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:16:15.654663086 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:16:20.059992075 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:16:20.060303926 CET507726666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:16:20.065159082 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:16:25.066203117 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:16:25.066596031 CET507726666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:16:25.071386099 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:16:30.076833010 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:16:30.077125072 CET507726666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:16:30.082005978 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:16:30.661087036 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:16:30.661298037 CET507726666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:16:30.666130066 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:16:35.119441986 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:16:35.119796038 CET507726666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:16:35.124783039 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:16:40.126446962 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:16:40.126621008 CET507726666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:16:40.131943941 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:16:45.139565945 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:16:45.139919996 CET507726666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:16:45.144821882 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:16:50.150767088 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:16:50.150953054 CET507726666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:16:50.155755043 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:16:55.166490078 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:16:55.166639090 CET507726666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:16:55.171417952 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:17:00.991189957 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:17:00.991594076 CET507726666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:17:00.992202997 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:17:00.992229939 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:17:00.992316961 CET507726666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:17:00.992316961 CET507726666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:17:00.996479988 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:17:00.996545076 CET507726666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:17:00.996604919 CET507726666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:17:01.043432951 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:17:05.220326900 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:17:05.220544100 CET507726666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:17:05.220603943 CET507726666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:17:05.225363016 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:17:10.235726118 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:17:10.235963106 CET507726666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:17:10.236007929 CET507726666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:17:10.240770102 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:17:15.252789974 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:17:15.253182888 CET507726666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:17:15.257978916 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:17:15.751825094 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:17:15.752271891 CET507726666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:17:15.757086039 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:17:20.259133101 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:17:20.259573936 CET507726666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:17:20.264389992 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:17:25.271668911 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:17:25.272059917 CET507726666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:17:25.276912928 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:17:30.282926083 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:17:30.283173084 CET507726666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:17:30.288038015 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:17:30.762664080 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:17:30.762866020 CET507726666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:17:30.767709970 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:17:35.324007988 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:17:35.324173927 CET507726666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:17:35.329035997 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:17:40.335416079 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:17:40.335937977 CET507726666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:17:40.340763092 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:17:45.347681999 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:17:45.347857952 CET507726666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:17:45.352721930 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:17:45.778634071 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:17:45.778904915 CET507726666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:17:45.783752918 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:17:50.363257885 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:17:50.363641024 CET507726666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:17:50.368552923 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:17:55.377690077 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:17:55.377973080 CET507726666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:17:55.382841110 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:17:57.916218042 CET4516053192.168.2.148.8.8.8
                        Dec 30, 2024 03:17:57.921082020 CET53451608.8.8.8192.168.2.14
                        Dec 30, 2024 03:17:57.921168089 CET4516053192.168.2.148.8.8.8
                        Dec 30, 2024 03:17:57.921168089 CET4516053192.168.2.148.8.8.8
                        Dec 30, 2024 03:17:57.921209097 CET4516053192.168.2.148.8.8.8
                        Dec 30, 2024 03:17:57.925996065 CET53451608.8.8.8192.168.2.14
                        Dec 30, 2024 03:17:57.926011086 CET53451608.8.8.8192.168.2.14
                        Dec 30, 2024 03:17:58.353569031 CET53451608.8.8.8192.168.2.14
                        Dec 30, 2024 03:17:58.353681087 CET4516053192.168.2.148.8.8.8
                        Dec 30, 2024 03:17:58.480202913 CET53451608.8.8.8192.168.2.14
                        Dec 30, 2024 03:17:58.481225014 CET4516053192.168.2.148.8.8.8
                        Dec 30, 2024 03:18:00.354048014 CET53451608.8.8.8192.168.2.14
                        Dec 30, 2024 03:18:00.354345083 CET4516053192.168.2.148.8.8.8
                        Dec 30, 2024 03:18:00.359262943 CET53451608.8.8.8192.168.2.14
                        Dec 30, 2024 03:18:00.385282040 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:18:00.385499001 CET507726666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:18:00.390343904 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:18:00.786534071 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:18:00.786798954 CET507726666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:18:00.791646957 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:18:05.461632967 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:18:05.461870909 CET507726666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:18:05.466778040 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:18:10.482847929 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:18:10.483179092 CET507726666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:18:10.488085985 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:18:15.525830984 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:18:15.526119947 CET507726666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:18:15.530976057 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:18:15.857845068 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:18:15.858004093 CET507726666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:18:15.862958908 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:18:20.542035103 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:18:20.542201996 CET507726666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:18:20.547066927 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:18:25.557607889 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:18:25.557815075 CET507726666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:18:25.562647104 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:18:30.567300081 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:18:30.567675114 CET507726666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:18:30.572489977 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:18:30.873251915 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:18:30.873496056 CET507726666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:18:30.878416061 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:18:35.577481031 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:18:35.577687025 CET507726666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:18:35.582561970 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:18:40.583722115 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:18:40.583971024 CET507726666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:18:40.588841915 CET66665077285.239.34.134192.168.2.14
                        TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                        Dec 30, 2024 03:17:57.921168089 CET192.168.2.148.8.8.80x5914Standard query (0)daisy.ubuntu.comA (IP address)IN (0x0001)false
                        Dec 30, 2024 03:17:57.921209097 CET192.168.2.148.8.8.80xf960Standard query (0)daisy.ubuntu.com28IN (0x0001)false
                        TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                        Dec 30, 2024 03:17:58.480202913 CET8.8.8.8192.168.2.140x5914No error (0)daisy.ubuntu.com162.213.35.24A (IP address)IN (0x0001)false
                        Dec 30, 2024 03:17:58.480202913 CET8.8.8.8192.168.2.140x5914No error (0)daisy.ubuntu.com162.213.35.25A (IP address)IN (0x0001)false

                        System Behavior

                        Start time (UTC):02:15:10
                        Start date (UTC):30/12/2024
                        Path:/tmp/ppc.elf
                        Arguments:/tmp/ppc.elf
                        File size:5388968 bytes
                        MD5 hash:ae65271c943d3451b7f026d1fadccea6

                        Start time (UTC):02:15:10
                        Start date (UTC):30/12/2024
                        Path:/tmp/ppc.elf
                        Arguments:-
                        File size:5388968 bytes
                        MD5 hash:ae65271c943d3451b7f026d1fadccea6