Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
arm5.elf

Overview

General Information

Sample name:arm5.elf
Analysis ID:1582183
MD5:7f0cbc115d5a177c16b3969c294fe023
SHA1:97fd0bcd903ac80804231a568386d77937f20a88
SHA256:abdbb122771ebfc211f8ea24b5c009923e5b0028bfad001d740cbd4ea3b79ca0
Tags:elfuser-abuse_ch
Infos:

Detection

Score:56
Range:0 - 100
Whitelisted:false

Signatures

Multi AV Scanner detection for submitted file
Suricata IDS alerts for network traffic
Detected TCP or UDP traffic on non-standard ports
Sample has stripped symbol table
Sample listens on a socket
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1582183
Start date and time:2024-12-30 03:35:08 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 5m 5s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:arm5.elf
Detection:MAL
Classification:mal56.linELF@0/0@2/0
Command:/tmp/arm5.elf
PID:5574
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
$UICIDEBOY$
Standard Error:
  • system is lnxubuntu20
  • arm5.elf (PID: 5574, Parent: 5493, MD5: 5ebfcae4fe2471fcc5695c2394773ff1) Arguments: /tmp/arm5.elf
    • arm5.elf New Fork (PID: 5578, Parent: 5574)
  • cleanup
No yara matches
TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
2024-12-30T03:36:05.226874+010028498161A Network Trojan was detected192.168.2.145077285.239.34.1346666TCP

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: arm5.elfReversingLabs: Detection: 28%
Source: arm5.elfVirustotal: Detection: 25%Perma Link

Networking

barindex
Source: Network trafficSuricata IDS: 2849816 - Severity 1 - ETPRO MALWARE ELF/Multiverze CnC Checkin : 192.168.2.14:50772 -> 85.239.34.134:6666
Source: global trafficTCP traffic: 192.168.2.14:50772 -> 85.239.34.134:6666
Source: /tmp/arm5.elf (PID: 5574)Socket: 0.0.0.0:9902Jump to behavior
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: global trafficDNS traffic detected: DNS query: daisy.ubuntu.com
Source: ELF static info symbol of initial sample.symtab present: no
Source: classification engineClassification label: mal56.linELF@0/0@2/0
Source: /tmp/arm5.elf (PID: 5574)Queries kernel information via 'uname': Jump to behavior
Source: arm5.elf, 5574.1.00007fff82fde000.00007fff82fff000.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-arm/tmp/arm5.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/arm5.elf
Source: arm5.elf, 5574.1.000055ade9dc6000.000055ade9ef4000.rw-.sdmpBinary or memory string: U!/etc/qemu-binfmt/arm
Source: arm5.elf, 5574.1.000055ade9dc6000.000055ade9ef4000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/arm
Source: arm5.elf, 5574.1.00007fff82fde000.00007fff82fff000.rw-.sdmpBinary or memory string: /usr/bin/qemu-arm
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath InterceptionDirect Volume AccessOS Credential Dumping11
Security Software Discovery
Remote ServicesData from Local System1
Non-Standard Port
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
arm5.elf29%ReversingLabsLinux.Backdoor.Gafgyt
arm5.elf25%VirustotalBrowse
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
daisy.ubuntu.com
162.213.35.24
truefalse
    high
    • No. of IPs < 25%
    • 25% < No. of IPs < 50%
    • 50% < No. of IPs < 75%
    • 75% < No. of IPs
    IPDomainCountryFlagASNASN NameMalicious
    85.239.34.134
    unknownRussian Federation
    134121RAINBOW-HKRainbownetworklimitedHKtrue
    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
    85.239.34.134ppc.elfGet hashmaliciousUnknownBrowse
      mips.elfGet hashmaliciousUnknownBrowse
        arm6.elfGet hashmaliciousUnknownBrowse
          m68k.elfGet hashmaliciousUnknownBrowse
            sh4.elfGet hashmaliciousUnknownBrowse
              x86.elfGet hashmaliciousUnknownBrowse
                spc.elfGet hashmaliciousUnknownBrowse
                  212.64.215.71-arm-2024-12-25T12_31_55.elfGet hashmaliciousUnknownBrowse
                    ppc.elfGet hashmaliciousMiraiBrowse
                      sh4.elfGet hashmaliciousMiraiBrowse
                        MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                        daisy.ubuntu.comwoega6.elfGet hashmaliciousMiraiBrowse
                        • 162.213.35.25
                        rebirth.arm5.elfGet hashmaliciousGafgytBrowse
                        • 162.213.35.24
                        rebirth.x86.elfGet hashmaliciousGafgytBrowse
                        • 162.213.35.25
                        ppc.elfGet hashmaliciousUnknownBrowse
                        • 162.213.35.24
                        rebirth.ppc.elfGet hashmaliciousGafgytBrowse
                        • 162.213.35.24
                        mips.elfGet hashmaliciousUnknownBrowse
                        • 162.213.35.24
                        zmap.x86_64.elfGet hashmaliciousOkiruBrowse
                        • 162.213.35.24
                        rebirth.arm6.elfGet hashmaliciousGafgytBrowse
                        • 162.213.35.24
                        MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                        RAINBOW-HKRainbownetworklimitedHKppc.elfGet hashmaliciousUnknownBrowse
                        • 85.239.34.134
                        mips.elfGet hashmaliciousUnknownBrowse
                        • 85.239.34.134
                        arm6.elfGet hashmaliciousUnknownBrowse
                        • 85.239.34.134
                        m68k.elfGet hashmaliciousUnknownBrowse
                        • 85.239.34.134
                        sh4.elfGet hashmaliciousUnknownBrowse
                        • 85.239.34.134
                        x86.elfGet hashmaliciousUnknownBrowse
                        • 85.239.34.134
                        spc.elfGet hashmaliciousUnknownBrowse
                        • 85.239.34.134
                        1C6ljtnwXP.exeGet hashmaliciousLummaCBrowse
                        • 85.239.54.77
                        212.64.215.71-arm-2024-12-25T12_31_55.elfGet hashmaliciousUnknownBrowse
                        • 85.239.34.134
                        armv5l.elfGet hashmaliciousUnknownBrowse
                        • 185.152.92.158
                        No context
                        No context
                        No created / dropped files found
                        File type:ELF 32-bit LSB executable, ARM, EABI4 version 1 (SYSV), statically linked, stripped
                        Entropy (8bit):5.862695178498935
                        TrID:
                        • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                        File name:arm5.elf
                        File size:44'176 bytes
                        MD5:7f0cbc115d5a177c16b3969c294fe023
                        SHA1:97fd0bcd903ac80804231a568386d77937f20a88
                        SHA256:abdbb122771ebfc211f8ea24b5c009923e5b0028bfad001d740cbd4ea3b79ca0
                        SHA512:a375feb0ce4a7d6a053fdd7bd417ac17008ef11af4f6a7f58f054c673044b4a59202b11ee46a8da226dfb853d83b806fe4f103afcc51d1fccc4cba624385ca06
                        SSDEEP:768:WQnS2KQZYJoLXRhC5dcKw2l/8i2QD05/1WYtEk+2G/e:WQnS2KQu4XRhC5Tw2l/8iM5/wEc/
                        TLSH:3D13E74AF9816F00D4E521BAFF4E124933535B6CE3FE7102AE155F2563CAA6B0F76812
                        File Content Preview:.ELF..............(.........4...........4. ...(........p.....%...%.. ... ....................................................6...6......l1...................6...6..................Q.td..................................-...L..................@-.,@...0....S

                        ELF header

                        Class:ELF32
                        Data:2's complement, little endian
                        Version:1 (current)
                        Machine:ARM
                        Version Number:0x1
                        Type:EXEC (Executable file)
                        OS/ABI:UNIX - System V
                        ABI Version:0
                        Entry Point Address:0x8194
                        Flags:0x4000002
                        ELF Header Size:52
                        Program Header Offset:52
                        Program Header Size:32
                        Number of Program Headers:5
                        Section Header Offset:43496
                        Section Header Size:40
                        Number of Section Headers:17
                        Header String Table Index:16
                        NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                        NULL0x00x00x00x00x0000
                        .initPROGBITS0x80d40xd40x100x00x6AX004
                        .textPROGBITS0x80f00xf00x9fa00x00x6AX0016
                        .finiPROGBITS0x120900xa0900x100x00x6AX004
                        .rodataPROGBITS0x120a00xa0a00x4c80x00x2A004
                        .ARM.extabPROGBITS0x125680xa5680x180x00x2A004
                        .ARM.exidxARM_EXIDX0x125800xa5800x1200x00x82AL204
                        .eh_framePROGBITS0x136a00xa6a00x40x00x3WA004
                        .tbssNOBITS0x136a40xa6a40x80x00x403WAT004
                        .init_arrayINIT_ARRAY0x136a40xa6a40x40x00x3WA004
                        .fini_arrayFINI_ARRAY0x136a80xa6a80x40x00x3WA004
                        .jcrPROGBITS0x136ac0xa6ac0x40x00x3WA004
                        .gotPROGBITS0x136b00xa6b00xa80x40x3WA004
                        .dataPROGBITS0x137580xa7580x1f00x00x3WA004
                        .bssNOBITS0x139480xa9480x2ec40x00x3WA004
                        .ARM.attributesARM_ATTRIBUTES0x00xa9480x160x00x0001
                        .shstrtabSTRTAB0x00xa95e0x880x00x0001
                        TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                        EXIDX0xa5800x125800x125800x1200x1204.40180x4R 0x4.ARM.exidx
                        LOAD0x00x80000x80000xa6a00xa6a05.89450x5R E0x1000.init .text .fini .rodata .ARM.extab .ARM.exidx
                        LOAD0xa6a00x136a00x136a00x2a80x316c3.75870x6RW 0x1000.eh_frame .tbss .init_array .fini_array .jcr .got .data .bss
                        TLS0xa6a40x136a40x136a40x00x80.00000x4R 0x4.tbss
                        GNU_STACK0x00x00x00x00x00.00000x7RWE0x4
                        TimestampSIDSignatureSeveritySource IPSource PortDest IPDest PortProtocol
                        2024-12-30T03:36:05.226874+01002849816ETPRO MALWARE ELF/Multiverze CnC Checkin1192.168.2.145077285.239.34.1346666TCP
                        TimestampSource PortDest PortSource IPDest IP
                        Dec 30, 2024 03:36:05.215487003 CET507726666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:36:05.220462084 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:36:05.220557928 CET507726666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:36:05.226874113 CET507726666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:36:05.231656075 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:36:09.983390093 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:36:09.983566999 CET507726666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:36:09.983715057 CET507726666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:36:09.988486052 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:36:15.056134939 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:36:15.056569099 CET507726666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:36:15.056622028 CET507726666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:36:15.061405897 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:36:17.551392078 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:36:17.551641941 CET507726666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:36:17.551641941 CET507726666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:36:17.556504965 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:36:20.066874027 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:36:20.067086935 CET507726666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:36:20.071954966 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:36:25.073812962 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:36:25.074174881 CET507726666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:36:25.078995943 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:36:30.120126963 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:36:30.120800972 CET507726666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:36:30.125634909 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:36:32.564282894 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:36:32.564675093 CET507726666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:36:32.569487095 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:36:35.131449938 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:36:35.131902933 CET507726666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:36:35.136718035 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:36:40.140542030 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:36:40.140794992 CET507726666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:36:40.145592928 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:36:45.155520916 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:36:45.155785084 CET507726666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:36:45.160659075 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:36:50.166575909 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:36:50.166733027 CET507726666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:36:50.171603918 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:36:55.174747944 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:36:55.174892902 CET507726666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:36:55.181607008 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:37:00.192265987 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:37:00.192656040 CET507726666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:37:00.197479963 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:37:02.587376118 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:37:02.587774992 CET507726666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:37:02.592634916 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:37:05.220431089 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:37:05.220683098 CET507726666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:37:05.225611925 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:37:10.262913942 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:37:10.263128042 CET507726666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:37:10.267952919 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:37:15.279196024 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:37:15.279426098 CET507726666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:37:15.284282923 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:37:17.625365973 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:37:17.625688076 CET507726666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:37:17.630624056 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:37:20.320941925 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:37:20.321216106 CET507726666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:37:20.326675892 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:37:25.354368925 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:37:25.354610920 CET507726666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:37:25.359442949 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:37:30.415759087 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:37:30.415992975 CET507726666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:37:30.420852900 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:37:32.636032104 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:37:32.636305094 CET507726666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:37:32.641153097 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:37:35.366134882 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:37:35.366298914 CET507726666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:37:35.371136904 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:37:40.373039961 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:37:40.373306990 CET507726666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:37:40.378108978 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:37:45.382261992 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:37:45.382517099 CET507726666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:37:45.387356043 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:37:47.643100023 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:37:47.643435955 CET507726666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:37:47.648288012 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:37:50.428101063 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:37:50.428442001 CET507726666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:37:50.433326006 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:37:55.447001934 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:37:55.447171926 CET507726666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:37:55.452084064 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:38:00.461107016 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:38:00.461592913 CET507726666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:38:00.466454983 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:38:02.653383017 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:38:02.653774977 CET507726666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:38:02.658622026 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:38:05.468367100 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:38:05.468650103 CET507726666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:38:05.473505020 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:38:10.474829912 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:38:10.475155115 CET507726666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:38:10.480021954 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:38:15.485239983 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:38:15.485768080 CET507726666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:38:15.490638018 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:38:17.663964033 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:38:17.664438963 CET507726666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:38:17.669365883 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:38:20.555413008 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:38:20.555844069 CET507726666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:38:20.560762882 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:38:25.574847937 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:38:25.575140953 CET507726666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:38:25.580064058 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:38:30.620263100 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:38:30.620605946 CET507726666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:38:30.625449896 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:38:32.675435066 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:38:32.675664902 CET507726666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:38:32.680583954 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:38:35.655566931 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:38:35.656095982 CET507726666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:38:35.660984993 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:38:40.668328047 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:38:40.668611050 CET507726666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:38:40.673454046 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:38:45.673958063 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:38:45.674285889 CET507726666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:38:45.679101944 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:38:47.684108019 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:38:47.684335947 CET507726666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:38:47.689186096 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:38:50.685597897 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:38:50.685862064 CET507726666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:38:50.690740108 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:38:52.108278990 CET4516053192.168.2.148.8.8.8
                        Dec 30, 2024 03:38:52.113178015 CET53451608.8.8.8192.168.2.14
                        Dec 30, 2024 03:38:52.113235950 CET4516053192.168.2.148.8.8.8
                        Dec 30, 2024 03:38:52.113265991 CET4516053192.168.2.148.8.8.8
                        Dec 30, 2024 03:38:52.113276958 CET4516053192.168.2.148.8.8.8
                        Dec 30, 2024 03:38:52.118056059 CET53451608.8.8.8192.168.2.14
                        Dec 30, 2024 03:38:52.118066072 CET53451608.8.8.8192.168.2.14
                        Dec 30, 2024 03:38:52.556046963 CET53451608.8.8.8192.168.2.14
                        Dec 30, 2024 03:38:52.556153059 CET4516053192.168.2.148.8.8.8
                        Dec 30, 2024 03:38:54.556122065 CET53451608.8.8.8192.168.2.14
                        Dec 30, 2024 03:38:54.556634903 CET4516053192.168.2.148.8.8.8
                        Dec 30, 2024 03:38:54.561496973 CET53451608.8.8.8192.168.2.14
                        Dec 30, 2024 03:38:55.755680084 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:38:55.756073952 CET507726666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:38:55.760953903 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:39:00.782382011 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:39:00.782761097 CET507726666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:39:00.787580013 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:39:02.720112085 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:39:02.720709085 CET507726666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:39:02.725720882 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:39:05.850806952 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:39:05.851205111 CET507726666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:39:05.855994940 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:39:10.866936922 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:39:10.867326975 CET507726666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:39:10.872198105 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:39:15.878767014 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:39:15.879246950 CET507726666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:39:15.884011030 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:39:17.727273941 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:39:17.727652073 CET507726666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:39:17.732496023 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:39:20.890930891 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:39:20.891568899 CET507726666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:39:20.896429062 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:39:25.956726074 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:39:25.957093954 CET507726666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:39:25.961952925 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:39:30.964694023 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:39:30.964904070 CET507726666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:39:30.969858885 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:39:32.739902020 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:39:32.740092039 CET507726666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:39:32.744952917 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:39:36.057076931 CET66665077285.239.34.134192.168.2.14
                        Dec 30, 2024 03:39:36.057410002 CET507726666192.168.2.1485.239.34.134
                        Dec 30, 2024 03:39:36.062316895 CET66665077285.239.34.134192.168.2.14
                        TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                        Dec 30, 2024 03:38:52.113265991 CET192.168.2.148.8.8.80x984fStandard query (0)daisy.ubuntu.comA (IP address)IN (0x0001)false
                        Dec 30, 2024 03:38:52.113276958 CET192.168.2.148.8.8.80x5415Standard query (0)daisy.ubuntu.com28IN (0x0001)false
                        TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                        Dec 30, 2024 03:38:52.556046963 CET8.8.8.8192.168.2.140x984fNo error (0)daisy.ubuntu.com162.213.35.24A (IP address)IN (0x0001)false
                        Dec 30, 2024 03:38:52.556046963 CET8.8.8.8192.168.2.140x984fNo error (0)daisy.ubuntu.com162.213.35.25A (IP address)IN (0x0001)false

                        System Behavior

                        Start time (UTC):02:36:04
                        Start date (UTC):30/12/2024
                        Path:/tmp/arm5.elf
                        Arguments:/tmp/arm5.elf
                        File size:4956856 bytes
                        MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                        Start time (UTC):02:36:04
                        Start date (UTC):30/12/2024
                        Path:/tmp/arm5.elf
                        Arguments:-
                        File size:4956856 bytes
                        MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1