Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
mpsl.elf

Overview

General Information

Sample name:mpsl.elf
Analysis ID:1582210
MD5:725c9b84e51f47bf60cd550ceeeb6901
SHA1:affe55fa5fbd59ddf843062110aec861128bed28
SHA256:e56601764d0e0613cd34dfb1fd57bdcdf59ec7fa0ccb1c5fe61b3f81efd05dbc
Tags:elfGafgytuser-abuse_ch
Infos:

Detection

Score:56
Range:0 - 100
Whitelisted:false

Signatures

Multi AV Scanner detection for submitted file
Suricata IDS alerts for network traffic
Detected TCP or UDP traffic on non-standard ports
Sample has stripped symbol table
Sample listens on a socket
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1582210
Start date and time:2024-12-30 04:08:40 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 56s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:mpsl.elf
Detection:MAL
Classification:mal56.linELF@0/0@2/0
Command:/tmp/mpsl.elf
PID:5531
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
$UICIDEBOY$
Standard Error:
  • system is lnxubuntu20
  • mpsl.elf (PID: 5531, Parent: 5451, MD5: 0d6f61f82cf2f781c6eb0661071d42d9) Arguments: /tmp/mpsl.elf
    • mpsl.elf New Fork (PID: 5533, Parent: 5531)
  • cleanup
No yara matches
TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
2024-12-30T04:09:27.463081+010028498161A Network Trojan was detected192.168.2.154078885.239.34.1346666TCP

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: mpsl.elfReversingLabs: Detection: 23%
Source: mpsl.elfVirustotal: Detection: 20%Perma Link

Networking

barindex
Source: Network trafficSuricata IDS: 2849816 - Severity 1 - ETPRO MALWARE ELF/Multiverze CnC Checkin : 192.168.2.15:40788 -> 85.239.34.134:6666
Source: global trafficTCP traffic: 192.168.2.15:40788 -> 85.239.34.134:6666
Source: /tmp/mpsl.elf (PID: 5531)Socket: 0.0.0.0:9902Jump to behavior
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: global trafficDNS traffic detected: DNS query: daisy.ubuntu.com
Source: ELF static info symbol of initial sample.symtab present: no
Source: classification engineClassification label: mal56.linELF@0/0@2/0
Source: /tmp/mpsl.elf (PID: 5531)Queries kernel information via 'uname': Jump to behavior
Source: mpsl.elf, 5531.1.000055bb4b596000.000055bb4b61d000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/mipsel
Source: mpsl.elf, 5531.1.000055bb4b596000.000055bb4b61d000.rw-.sdmpBinary or memory string: U!/etc/qemu-binfmt/mipsel
Source: mpsl.elf, 5531.1.00007ffee4495000.00007ffee44b6000.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-mipsel/tmp/mpsl.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/mpsl.elf
Source: mpsl.elf, 5531.1.00007ffee4495000.00007ffee44b6000.rw-.sdmpBinary or memory string: /usr/bin/qemu-mipsel
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath InterceptionDirect Volume AccessOS Credential Dumping11
Security Software Discovery
Remote ServicesData from Local System1
Non-Standard Port
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
mpsl.elf24%ReversingLabsLinux.Backdoor.Gafgyt
mpsl.elf21%VirustotalBrowse
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
daisy.ubuntu.com
162.213.35.24
truefalse
    high
    • No. of IPs < 25%
    • 25% < No. of IPs < 50%
    • 50% < No. of IPs < 75%
    • 75% < No. of IPs
    IPDomainCountryFlagASNASN NameMalicious
    85.239.34.134
    unknownRussian Federation
    134121RAINBOW-HKRainbownetworklimitedHKtrue
    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
    85.239.34.134arm5.elfGet hashmaliciousUnknownBrowse
      ppc.elfGet hashmaliciousUnknownBrowse
        mips.elfGet hashmaliciousUnknownBrowse
          arm6.elfGet hashmaliciousUnknownBrowse
            m68k.elfGet hashmaliciousUnknownBrowse
              sh4.elfGet hashmaliciousUnknownBrowse
                x86.elfGet hashmaliciousUnknownBrowse
                  spc.elfGet hashmaliciousUnknownBrowse
                    212.64.215.71-arm-2024-12-25T12_31_55.elfGet hashmaliciousUnknownBrowse
                      ppc.elfGet hashmaliciousMiraiBrowse
                        MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                        daisy.ubuntu.comrebirth.arm4t.elfGet hashmaliciousGafgytBrowse
                        • 162.213.35.24
                        arm5.elfGet hashmaliciousUnknownBrowse
                        • 162.213.35.25
                        debug.dbg.elfGet hashmaliciousMirai, OkiruBrowse
                        • 162.213.35.25
                        rebirth.mips.elfGet hashmaliciousGafgytBrowse
                        • 162.213.35.25
                        rebirth.arm6.elfGet hashmaliciousGafgytBrowse
                        • 162.213.35.24
                        rebirth.spc.elfGet hashmaliciousGafgytBrowse
                        • 162.213.35.25
                        .Sarm6.elfGet hashmaliciousUnknownBrowse
                        • 162.213.35.25
                        arm5.elfGet hashmaliciousUnknownBrowse
                        • 162.213.35.24
                        woega6.elfGet hashmaliciousMiraiBrowse
                        • 162.213.35.25
                        MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                        RAINBOW-HKRainbownetworklimitedHKarm5.elfGet hashmaliciousUnknownBrowse
                        • 85.239.34.134
                        ppc.elfGet hashmaliciousUnknownBrowse
                        • 85.239.34.134
                        mips.elfGet hashmaliciousUnknownBrowse
                        • 85.239.34.134
                        arm6.elfGet hashmaliciousUnknownBrowse
                        • 85.239.34.134
                        m68k.elfGet hashmaliciousUnknownBrowse
                        • 85.239.34.134
                        sh4.elfGet hashmaliciousUnknownBrowse
                        • 85.239.34.134
                        x86.elfGet hashmaliciousUnknownBrowse
                        • 85.239.34.134
                        spc.elfGet hashmaliciousUnknownBrowse
                        • 85.239.34.134
                        1C6ljtnwXP.exeGet hashmaliciousLummaCBrowse
                        • 85.239.54.77
                        212.64.215.71-arm-2024-12-25T12_31_55.elfGet hashmaliciousUnknownBrowse
                        • 85.239.34.134
                        No context
                        No context
                        No created / dropped files found
                        File type:ELF 32-bit LSB executable, MIPS, MIPS-I version 1 (SYSV), statically linked, stripped
                        Entropy (8bit):5.271578742897592
                        TrID:
                        • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                        File name:mpsl.elf
                        File size:48'588 bytes
                        MD5:725c9b84e51f47bf60cd550ceeeb6901
                        SHA1:affe55fa5fbd59ddf843062110aec861128bed28
                        SHA256:e56601764d0e0613cd34dfb1fd57bdcdf59ec7fa0ccb1c5fe61b3f81efd05dbc
                        SHA512:a0e64e3d0cc74a14057196139d80dd49405acb67607f4f1ee7b7109652735a9ff637ecb9c4d5d51de8594085de114d6a4e08cbe7df2f56a7c7ea89cc2ef01f4b
                        SSDEEP:768:4XX2nnT8pKoN7Rt8XCYZ36acuRyXi7kvX63TVi8ocMT:4nGTjoN7Rt8XCsqac/voL
                        TLSH:9C23C9059F610E7FD82ECE3301960B8225CCDA5661A6B7AA3174FC1CF65B54B4BE3C58
                        File Content Preview:.ELF......................@.4...L.......4. ...(...............@...@...........................@...@......6..............D...D.@.D.@.................Q.td...............................<.E.'!......'.......................<.E.'!.............9'.. ............

                        ELF header

                        Class:ELF32
                        Data:2's complement, little endian
                        Version:1 (current)
                        Machine:MIPS R3000
                        Version Number:0x1
                        Type:EXEC (Executable file)
                        OS/ABI:UNIX - System V
                        ABI Version:0
                        Entry Point Address:0x400290
                        Flags:0x1007
                        ELF Header Size:52
                        Program Header Offset:52
                        Program Header Size:32
                        Number of Program Headers:4
                        Section Header Offset:47948
                        Section Header Size:40
                        Number of Section Headers:16
                        Header String Table Index:15
                        NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                        NULL0x00x00x00x00x0000
                        .initPROGBITS0x4000b40xb40x8c0x00x6AX004
                        .textPROGBITS0x4001400x1400xa9a00x00x6AX0016
                        .finiPROGBITS0x40aae00xaae00x5c0x00x6AX004
                        .rodataPROGBITS0x40ab400xab400x8c00x00x2A0016
                        .eh_framePROGBITS0x40c4000xb4000x440x00x3WA004
                        .tbssNOBITS0x40c4440xb4440x80x00x403WAT004
                        .ctorsPROGBITS0x40c4440xb4440x80x00x3WA004
                        .dtorsPROGBITS0x40c44c0xb44c0x80x00x3WA004
                        .jcrPROGBITS0x40c4540xb4540x40x00x3WA004
                        .dataPROGBITS0x40c4600xb4600x2440x00x3WA0016
                        .gotPROGBITS0x40c6b00xb6b00x4300x40x10000003WAp0016
                        .sbssNOBITS0x40cae00xbae00x400x00x10000003WAp004
                        .bssNOBITS0x40cb200xbae00x2ee80x00x3WA0016
                        .mdebug.abi32PROGBITS0x84c0xbae00x00x00x0001
                        .shstrtabSTRTAB0x00xbae00x6c0x00x0001
                        TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                        LOAD0x00x4000000x4000000xb4000xb4005.31040x5R E0x1000.init .text .fini .rodata
                        LOAD0xb4000x40c4000x40c4000x6e00x36083.73560x6RW 0x1000.eh_frame .tbss .ctors .dtors .jcr .data .got .sbss .bss
                        TLS0xb4440x40c4440x40c4440x00x80.00000x4R 0x4.tbss
                        GNU_STACK0x00x00x00x00x00.00000x7RWE0x4
                        TimestampSIDSignatureSeveritySource IPSource PortDest IPDest PortProtocol
                        2024-12-30T04:09:27.463081+01002849816ETPRO MALWARE ELF/Multiverze CnC Checkin1192.168.2.154078885.239.34.1346666TCP
                        TimestampSource PortDest PortSource IPDest IP
                        Dec 30, 2024 04:09:27.440890074 CET407886666192.168.2.1585.239.34.134
                        Dec 30, 2024 04:09:27.445754051 CET66664078885.239.34.134192.168.2.15
                        Dec 30, 2024 04:09:27.445816994 CET407886666192.168.2.1585.239.34.134
                        Dec 30, 2024 04:09:27.463080883 CET407886666192.168.2.1585.239.34.134
                        Dec 30, 2024 04:09:27.467955112 CET66664078885.239.34.134192.168.2.15
                        Dec 30, 2024 04:09:28.830542088 CET66664078885.239.34.134192.168.2.15
                        Dec 30, 2024 04:09:28.830630064 CET407886666192.168.2.1585.239.34.134
                        Dec 30, 2024 04:09:28.830827951 CET407886666192.168.2.1585.239.34.134
                        Dec 30, 2024 04:09:28.835573912 CET66664078885.239.34.134192.168.2.15
                        Dec 30, 2024 04:09:33.837898016 CET66664078885.239.34.134192.168.2.15
                        Dec 30, 2024 04:09:33.838238001 CET407886666192.168.2.1585.239.34.134
                        Dec 30, 2024 04:09:33.838273048 CET407886666192.168.2.1585.239.34.134
                        Dec 30, 2024 04:09:33.843050957 CET66664078885.239.34.134192.168.2.15
                        Dec 30, 2024 04:09:35.381068945 CET66664078885.239.34.134192.168.2.15
                        Dec 30, 2024 04:09:35.381196022 CET407886666192.168.2.1585.239.34.134
                        Dec 30, 2024 04:09:35.381225109 CET407886666192.168.2.1585.239.34.134
                        Dec 30, 2024 04:09:35.385996103 CET66664078885.239.34.134192.168.2.15
                        Dec 30, 2024 04:09:38.849118948 CET66664078885.239.34.134192.168.2.15
                        Dec 30, 2024 04:09:38.849353075 CET407886666192.168.2.1585.239.34.134
                        Dec 30, 2024 04:09:38.854223013 CET66664078885.239.34.134192.168.2.15
                        Dec 30, 2024 04:09:43.868551970 CET66664078885.239.34.134192.168.2.15
                        Dec 30, 2024 04:09:43.868838072 CET407886666192.168.2.1585.239.34.134
                        Dec 30, 2024 04:09:43.873641968 CET66664078885.239.34.134192.168.2.15
                        Dec 30, 2024 04:09:48.889898062 CET66664078885.239.34.134192.168.2.15
                        Dec 30, 2024 04:09:48.890198946 CET407886666192.168.2.1585.239.34.134
                        Dec 30, 2024 04:09:48.894922018 CET66664078885.239.34.134192.168.2.15
                        Dec 30, 2024 04:09:50.390450001 CET66664078885.239.34.134192.168.2.15
                        Dec 30, 2024 04:09:50.390717030 CET407886666192.168.2.1585.239.34.134
                        Dec 30, 2024 04:09:50.395555019 CET66664078885.239.34.134192.168.2.15
                        Dec 30, 2024 04:09:53.898122072 CET66664078885.239.34.134192.168.2.15
                        Dec 30, 2024 04:09:53.898474932 CET407886666192.168.2.1585.239.34.134
                        Dec 30, 2024 04:09:53.903299093 CET66664078885.239.34.134192.168.2.15
                        Dec 30, 2024 04:09:58.963562965 CET66664078885.239.34.134192.168.2.15
                        Dec 30, 2024 04:09:58.963845968 CET407886666192.168.2.1585.239.34.134
                        Dec 30, 2024 04:09:58.968703985 CET66664078885.239.34.134192.168.2.15
                        Dec 30, 2024 04:10:03.969815969 CET66664078885.239.34.134192.168.2.15
                        Dec 30, 2024 04:10:03.970122099 CET407886666192.168.2.1585.239.34.134
                        Dec 30, 2024 04:10:03.974930048 CET66664078885.239.34.134192.168.2.15
                        Dec 30, 2024 04:10:05.431627035 CET66664078885.239.34.134192.168.2.15
                        Dec 30, 2024 04:10:05.431989908 CET407886666192.168.2.1585.239.34.134
                        Dec 30, 2024 04:10:05.436858892 CET66664078885.239.34.134192.168.2.15
                        Dec 30, 2024 04:10:08.984858036 CET66664078885.239.34.134192.168.2.15
                        Dec 30, 2024 04:10:08.985050917 CET407886666192.168.2.1585.239.34.134
                        Dec 30, 2024 04:10:08.989881992 CET66664078885.239.34.134192.168.2.15
                        Dec 30, 2024 04:10:14.032891035 CET66664078885.239.34.134192.168.2.15
                        Dec 30, 2024 04:10:14.033288002 CET407886666192.168.2.1585.239.34.134
                        Dec 30, 2024 04:10:14.038146019 CET66664078885.239.34.134192.168.2.15
                        Dec 30, 2024 04:10:19.045691967 CET66664078885.239.34.134192.168.2.15
                        Dec 30, 2024 04:10:19.046076059 CET407886666192.168.2.1585.239.34.134
                        Dec 30, 2024 04:10:19.050816059 CET66664078885.239.34.134192.168.2.15
                        Dec 30, 2024 04:10:20.441603899 CET66664078885.239.34.134192.168.2.15
                        Dec 30, 2024 04:10:20.441879034 CET407886666192.168.2.1585.239.34.134
                        Dec 30, 2024 04:10:20.446803093 CET66664078885.239.34.134192.168.2.15
                        Dec 30, 2024 04:10:24.057267904 CET66664078885.239.34.134192.168.2.15
                        Dec 30, 2024 04:10:24.057687998 CET407886666192.168.2.1585.239.34.134
                        Dec 30, 2024 04:10:24.062638998 CET66664078885.239.34.134192.168.2.15
                        Dec 30, 2024 04:10:29.064781904 CET66664078885.239.34.134192.168.2.15
                        Dec 30, 2024 04:10:29.065244913 CET407886666192.168.2.1585.239.34.134
                        Dec 30, 2024 04:10:29.070091963 CET66664078885.239.34.134192.168.2.15
                        Dec 30, 2024 04:10:34.073671103 CET66664078885.239.34.134192.168.2.15
                        Dec 30, 2024 04:10:34.073973894 CET407886666192.168.2.1585.239.34.134
                        Dec 30, 2024 04:10:34.079814911 CET66664078885.239.34.134192.168.2.15
                        Dec 30, 2024 04:10:35.448852062 CET66664078885.239.34.134192.168.2.15
                        Dec 30, 2024 04:10:35.449094057 CET407886666192.168.2.1585.239.34.134
                        Dec 30, 2024 04:10:35.455003977 CET66664078885.239.34.134192.168.2.15
                        Dec 30, 2024 04:10:39.084117889 CET66664078885.239.34.134192.168.2.15
                        Dec 30, 2024 04:10:39.084356070 CET407886666192.168.2.1585.239.34.134
                        Dec 30, 2024 04:10:39.089224100 CET66664078885.239.34.134192.168.2.15
                        Dec 30, 2024 04:10:44.161717892 CET66664078885.239.34.134192.168.2.15
                        Dec 30, 2024 04:10:44.161986113 CET407886666192.168.2.1585.239.34.134
                        Dec 30, 2024 04:10:44.166810989 CET66664078885.239.34.134192.168.2.15
                        Dec 30, 2024 04:10:49.170696974 CET66664078885.239.34.134192.168.2.15
                        Dec 30, 2024 04:10:49.170974016 CET407886666192.168.2.1585.239.34.134
                        Dec 30, 2024 04:10:49.175860882 CET66664078885.239.34.134192.168.2.15
                        Dec 30, 2024 04:10:50.463519096 CET66664078885.239.34.134192.168.2.15
                        Dec 30, 2024 04:10:50.463793039 CET407886666192.168.2.1585.239.34.134
                        Dec 30, 2024 04:10:50.468732119 CET66664078885.239.34.134192.168.2.15
                        Dec 30, 2024 04:10:54.184232950 CET66664078885.239.34.134192.168.2.15
                        Dec 30, 2024 04:10:54.184475899 CET407886666192.168.2.1585.239.34.134
                        Dec 30, 2024 04:10:54.189280033 CET66664078885.239.34.134192.168.2.15
                        Dec 30, 2024 04:10:59.224980116 CET66664078885.239.34.134192.168.2.15
                        Dec 30, 2024 04:10:59.225128889 CET407886666192.168.2.1585.239.34.134
                        Dec 30, 2024 04:10:59.229904890 CET66664078885.239.34.134192.168.2.15
                        Dec 30, 2024 04:11:04.266659975 CET66664078885.239.34.134192.168.2.15
                        Dec 30, 2024 04:11:04.266827106 CET407886666192.168.2.1585.239.34.134
                        Dec 30, 2024 04:11:04.271709919 CET66664078885.239.34.134192.168.2.15
                        Dec 30, 2024 04:11:05.472814083 CET66664078885.239.34.134192.168.2.15
                        Dec 30, 2024 04:11:05.473009109 CET407886666192.168.2.1585.239.34.134
                        Dec 30, 2024 04:11:05.477894068 CET66664078885.239.34.134192.168.2.15
                        Dec 30, 2024 04:11:09.279082060 CET66664078885.239.34.134192.168.2.15
                        Dec 30, 2024 04:11:09.279361010 CET407886666192.168.2.1585.239.34.134
                        Dec 30, 2024 04:11:09.284157991 CET66664078885.239.34.134192.168.2.15
                        Dec 30, 2024 04:11:14.292388916 CET66664078885.239.34.134192.168.2.15
                        Dec 30, 2024 04:11:14.292782068 CET407886666192.168.2.1585.239.34.134
                        Dec 30, 2024 04:11:14.297600985 CET66664078885.239.34.134192.168.2.15
                        Dec 30, 2024 04:11:19.293694019 CET66664078885.239.34.134192.168.2.15
                        Dec 30, 2024 04:11:19.294070005 CET407886666192.168.2.1585.239.34.134
                        Dec 30, 2024 04:11:19.298918962 CET66664078885.239.34.134192.168.2.15
                        Dec 30, 2024 04:11:20.484272957 CET66664078885.239.34.134192.168.2.15
                        Dec 30, 2024 04:11:20.484508991 CET407886666192.168.2.1585.239.34.134
                        Dec 30, 2024 04:11:20.489337921 CET66664078885.239.34.134192.168.2.15
                        Dec 30, 2024 04:11:24.357319117 CET66664078885.239.34.134192.168.2.15
                        Dec 30, 2024 04:11:24.357536077 CET407886666192.168.2.1585.239.34.134
                        Dec 30, 2024 04:11:24.362386942 CET66664078885.239.34.134192.168.2.15
                        Dec 30, 2024 04:11:29.364308119 CET66664078885.239.34.134192.168.2.15
                        Dec 30, 2024 04:11:29.364535093 CET407886666192.168.2.1585.239.34.134
                        Dec 30, 2024 04:11:29.369364977 CET66664078885.239.34.134192.168.2.15
                        Dec 30, 2024 04:11:34.380213976 CET66664078885.239.34.134192.168.2.15
                        Dec 30, 2024 04:11:34.380449057 CET407886666192.168.2.1585.239.34.134
                        Dec 30, 2024 04:11:34.385335922 CET66664078885.239.34.134192.168.2.15
                        Dec 30, 2024 04:11:35.494872093 CET66664078885.239.34.134192.168.2.15
                        Dec 30, 2024 04:11:35.495093107 CET407886666192.168.2.1585.239.34.134
                        Dec 30, 2024 04:11:35.499878883 CET66664078885.239.34.134192.168.2.15
                        Dec 30, 2024 04:11:39.457144022 CET66664078885.239.34.134192.168.2.15
                        Dec 30, 2024 04:11:39.457365990 CET407886666192.168.2.1585.239.34.134
                        Dec 30, 2024 04:11:39.462223053 CET66664078885.239.34.134192.168.2.15
                        Dec 30, 2024 04:11:44.477052927 CET66664078885.239.34.134192.168.2.15
                        Dec 30, 2024 04:11:44.477305889 CET407886666192.168.2.1585.239.34.134
                        Dec 30, 2024 04:11:44.482090950 CET66664078885.239.34.134192.168.2.15
                        Dec 30, 2024 04:11:49.489108086 CET66664078885.239.34.134192.168.2.15
                        Dec 30, 2024 04:11:49.489483118 CET407886666192.168.2.1585.239.34.134
                        Dec 30, 2024 04:11:49.494360924 CET66664078885.239.34.134192.168.2.15
                        Dec 30, 2024 04:11:50.532847881 CET66664078885.239.34.134192.168.2.15
                        Dec 30, 2024 04:11:50.533032894 CET407886666192.168.2.1585.239.34.134
                        Dec 30, 2024 04:11:50.537974119 CET66664078885.239.34.134192.168.2.15
                        Dec 30, 2024 04:11:54.530538082 CET66664078885.239.34.134192.168.2.15
                        Dec 30, 2024 04:11:54.530901909 CET407886666192.168.2.1585.239.34.134
                        Dec 30, 2024 04:11:54.535808086 CET66664078885.239.34.134192.168.2.15
                        Dec 30, 2024 04:11:59.541811943 CET66664078885.239.34.134192.168.2.15
                        Dec 30, 2024 04:11:59.542318106 CET407886666192.168.2.1585.239.34.134
                        Dec 30, 2024 04:11:59.547147989 CET66664078885.239.34.134192.168.2.15
                        Dec 30, 2024 04:12:04.555206060 CET66664078885.239.34.134192.168.2.15
                        Dec 30, 2024 04:12:04.555464983 CET407886666192.168.2.1585.239.34.134
                        Dec 30, 2024 04:12:04.560333967 CET66664078885.239.34.134192.168.2.15
                        Dec 30, 2024 04:12:05.544872046 CET66664078885.239.34.134192.168.2.15
                        Dec 30, 2024 04:12:05.545031071 CET407886666192.168.2.1585.239.34.134
                        Dec 30, 2024 04:12:05.549949884 CET66664078885.239.34.134192.168.2.15
                        Dec 30, 2024 04:12:09.579416990 CET66664078885.239.34.134192.168.2.15
                        Dec 30, 2024 04:12:09.579648018 CET407886666192.168.2.1585.239.34.134
                        Dec 30, 2024 04:12:09.584574938 CET66664078885.239.34.134192.168.2.15
                        Dec 30, 2024 04:12:14.585417986 CET66664078885.239.34.134192.168.2.15
                        Dec 30, 2024 04:12:14.585520983 CET407886666192.168.2.1585.239.34.134
                        Dec 30, 2024 04:12:14.590426922 CET66664078885.239.34.134192.168.2.15
                        Dec 30, 2024 04:12:19.661592007 CET66664078885.239.34.134192.168.2.15
                        Dec 30, 2024 04:12:19.661892891 CET407886666192.168.2.1585.239.34.134
                        Dec 30, 2024 04:12:19.666805029 CET66664078885.239.34.134192.168.2.15
                        Dec 30, 2024 04:12:20.555229902 CET66664078885.239.34.134192.168.2.15
                        Dec 30, 2024 04:12:20.555480003 CET407886666192.168.2.1585.239.34.134
                        Dec 30, 2024 04:12:20.560247898 CET66664078885.239.34.134192.168.2.15
                        Dec 30, 2024 04:12:24.669220924 CET66664078885.239.34.134192.168.2.15
                        Dec 30, 2024 04:12:24.669655085 CET407886666192.168.2.1585.239.34.134
                        Dec 30, 2024 04:12:24.674520016 CET66664078885.239.34.134192.168.2.15
                        Dec 30, 2024 04:12:29.682425022 CET66664078885.239.34.134192.168.2.15
                        Dec 30, 2024 04:12:29.682811975 CET407886666192.168.2.1585.239.34.134
                        Dec 30, 2024 04:12:29.687702894 CET66664078885.239.34.134192.168.2.15
                        Dec 30, 2024 04:12:34.731792927 CET66664078885.239.34.134192.168.2.15
                        Dec 30, 2024 04:12:34.731961012 CET407886666192.168.2.1585.239.34.134
                        Dec 30, 2024 04:12:34.736741066 CET66664078885.239.34.134192.168.2.15
                        Dec 30, 2024 04:12:35.562320948 CET66664078885.239.34.134192.168.2.15
                        Dec 30, 2024 04:12:35.562469006 CET407886666192.168.2.1585.239.34.134
                        Dec 30, 2024 04:12:35.567302942 CET66664078885.239.34.134192.168.2.15
                        Dec 30, 2024 04:12:39.731931925 CET66664078885.239.34.134192.168.2.15
                        Dec 30, 2024 04:12:39.732351065 CET407886666192.168.2.1585.239.34.134
                        Dec 30, 2024 04:12:39.737176895 CET66664078885.239.34.134192.168.2.15
                        Dec 30, 2024 04:12:44.739685059 CET66664078885.239.34.134192.168.2.15
                        Dec 30, 2024 04:12:44.739959955 CET407886666192.168.2.1585.239.34.134
                        Dec 30, 2024 04:12:44.744823933 CET66664078885.239.34.134192.168.2.15
                        Dec 30, 2024 04:12:49.754306078 CET66664078885.239.34.134192.168.2.15
                        Dec 30, 2024 04:12:49.754543066 CET407886666192.168.2.1585.239.34.134
                        Dec 30, 2024 04:12:49.759394884 CET66664078885.239.34.134192.168.2.15
                        Dec 30, 2024 04:12:50.569686890 CET66664078885.239.34.134192.168.2.15
                        Dec 30, 2024 04:12:50.569848061 CET407886666192.168.2.1585.239.34.134
                        Dec 30, 2024 04:12:50.574740887 CET66664078885.239.34.134192.168.2.15
                        Dec 30, 2024 04:12:54.773369074 CET66664078885.239.34.134192.168.2.15
                        Dec 30, 2024 04:12:54.773614883 CET407886666192.168.2.1585.239.34.134
                        Dec 30, 2024 04:12:54.778436899 CET66664078885.239.34.134192.168.2.15
                        Dec 30, 2024 04:12:59.788445950 CET66664078885.239.34.134192.168.2.15
                        Dec 30, 2024 04:12:59.788579941 CET407886666192.168.2.1585.239.34.134
                        Dec 30, 2024 04:12:59.793380976 CET66664078885.239.34.134192.168.2.15
                        TimestampSource PortDest PortSource IPDest IP
                        Dec 30, 2024 04:12:13.470210075 CET5293353192.168.2.151.1.1.1
                        Dec 30, 2024 04:12:13.470251083 CET5907253192.168.2.151.1.1.1
                        Dec 30, 2024 04:12:13.477099895 CET53590721.1.1.1192.168.2.15
                        Dec 30, 2024 04:12:13.477528095 CET53529331.1.1.1192.168.2.15
                        TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                        Dec 30, 2024 04:12:13.470210075 CET192.168.2.151.1.1.10x144dStandard query (0)daisy.ubuntu.comA (IP address)IN (0x0001)false
                        Dec 30, 2024 04:12:13.470251083 CET192.168.2.151.1.1.10x4146Standard query (0)daisy.ubuntu.com28IN (0x0001)false
                        TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                        Dec 30, 2024 04:12:13.477528095 CET1.1.1.1192.168.2.150x144dNo error (0)daisy.ubuntu.com162.213.35.24A (IP address)IN (0x0001)false
                        Dec 30, 2024 04:12:13.477528095 CET1.1.1.1192.168.2.150x144dNo error (0)daisy.ubuntu.com162.213.35.25A (IP address)IN (0x0001)false

                        System Behavior

                        Start time (UTC):03:09:26
                        Start date (UTC):30/12/2024
                        Path:/tmp/mpsl.elf
                        Arguments:/tmp/mpsl.elf
                        File size:5773336 bytes
                        MD5 hash:0d6f61f82cf2f781c6eb0661071d42d9

                        Start time (UTC):03:09:26
                        Start date (UTC):30/12/2024
                        Path:/tmp/mpsl.elf
                        Arguments:-
                        File size:5773336 bytes
                        MD5 hash:0d6f61f82cf2f781c6eb0661071d42d9