Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
arm7.elf

Overview

General Information

Sample name:arm7.elf
Analysis ID:1582213
MD5:3cb8a7c57880d6679e781a6e29ea55c4
SHA1:2c1fea37dc23576db8d477e14aedad15a2078e6d
SHA256:b5f7265ab3e9c1189cace3f86d6fefc159964a7e4f0835452adca7b2172d4af6
Tags:elfuser-abuse_ch
Infos:

Detection

Score:56
Range:0 - 100
Whitelisted:false

Signatures

Multi AV Scanner detection for submitted file
Suricata IDS alerts for network traffic
Detected TCP or UDP traffic on non-standard ports
Sample has stripped symbol table
Sample listens on a socket
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1582213
Start date and time:2024-12-30 04:12:17 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 47s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:arm7.elf
Detection:MAL
Classification:mal56.linELF@0/0@2/0
Command:/tmp/arm7.elf
PID:5425
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
$UICIDEBOY$
Standard Error:
  • system is lnxubuntu20
  • arm7.elf (PID: 5425, Parent: 5348, MD5: 5ebfcae4fe2471fcc5695c2394773ff1) Arguments: /tmp/arm7.elf
    • arm7.elf New Fork (PID: 5427, Parent: 5425)
  • cleanup
No yara matches
TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
2024-12-30T04:12:58.521455+010028498161A Network Trojan was detected192.168.2.135362685.239.34.1346666TCP

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: arm7.elfVirustotal: Detection: 25%Perma Link
Source: arm7.elfReversingLabs: Detection: 28%

Networking

barindex
Source: Network trafficSuricata IDS: 2849816 - Severity 1 - ETPRO MALWARE ELF/Multiverze CnC Checkin : 192.168.2.13:53626 -> 85.239.34.134:6666
Source: global trafficTCP traffic: 192.168.2.13:53626 -> 85.239.34.134:6666
Source: /tmp/arm7.elf (PID: 5425)Socket: 0.0.0.0:9902Jump to behavior
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: global trafficDNS traffic detected: DNS query: daisy.ubuntu.com
Source: ELF static info symbol of initial sample.symtab present: no
Source: classification engineClassification label: mal56.linELF@0/0@2/0
Source: /tmp/arm7.elf (PID: 5425)Queries kernel information via 'uname': Jump to behavior
Source: arm7.elf, 5425.1.000055d943507000.000055d943635000.rw-.sdmpBinary or memory string: U!/etc/qemu-binfmt/arm
Source: arm7.elf, 5425.1.000055d943507000.000055d943635000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/arm
Source: arm7.elf, 5425.1.00007ffdd17e9000.00007ffdd180a000.rw-.sdmpBinary or memory string: /usr/bin/qemu-arm
Source: arm7.elf, 5425.1.00007ffdd17e9000.00007ffdd180a000.rw-.sdmpBinary or memory string: Zx86_64/usr/bin/qemu-arm/tmp/arm7.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/arm7.elf
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath InterceptionDirect Volume AccessOS Credential Dumping11
Security Software Discovery
Remote ServicesData from Local System1
Non-Standard Port
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
arm7.elf25%VirustotalBrowse
arm7.elf29%ReversingLabsLinux.Backdoor.Gafgyt
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
daisy.ubuntu.com
162.213.35.24
truefalse
    high
    • No. of IPs < 25%
    • 25% < No. of IPs < 50%
    • 50% < No. of IPs < 75%
    • 75% < No. of IPs
    IPDomainCountryFlagASNASN NameMalicious
    85.239.34.134
    unknownRussian Federation
    134121RAINBOW-HKRainbownetworklimitedHKtrue
    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
    85.239.34.134mpsl.elfGet hashmaliciousUnknownBrowse
      arm5.elfGet hashmaliciousUnknownBrowse
        ppc.elfGet hashmaliciousUnknownBrowse
          mips.elfGet hashmaliciousUnknownBrowse
            arm6.elfGet hashmaliciousUnknownBrowse
              m68k.elfGet hashmaliciousUnknownBrowse
                sh4.elfGet hashmaliciousUnknownBrowse
                  x86.elfGet hashmaliciousUnknownBrowse
                    spc.elfGet hashmaliciousUnknownBrowse
                      212.64.215.71-arm-2024-12-25T12_31_55.elfGet hashmaliciousUnknownBrowse
                        MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                        daisy.ubuntu.commpsl.elfGet hashmaliciousUnknownBrowse
                        • 162.213.35.24
                        rebirth.arm4t.elfGet hashmaliciousGafgytBrowse
                        • 162.213.35.24
                        arm5.elfGet hashmaliciousUnknownBrowse
                        • 162.213.35.25
                        debug.dbg.elfGet hashmaliciousMirai, OkiruBrowse
                        • 162.213.35.25
                        rebirth.mips.elfGet hashmaliciousGafgytBrowse
                        • 162.213.35.25
                        rebirth.arm6.elfGet hashmaliciousGafgytBrowse
                        • 162.213.35.24
                        rebirth.spc.elfGet hashmaliciousGafgytBrowse
                        • 162.213.35.25
                        .Sarm6.elfGet hashmaliciousUnknownBrowse
                        • 162.213.35.25
                        arm5.elfGet hashmaliciousUnknownBrowse
                        • 162.213.35.24
                        MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                        RAINBOW-HKRainbownetworklimitedHKmpsl.elfGet hashmaliciousUnknownBrowse
                        • 85.239.34.134
                        arm5.elfGet hashmaliciousUnknownBrowse
                        • 85.239.34.134
                        ppc.elfGet hashmaliciousUnknownBrowse
                        • 85.239.34.134
                        mips.elfGet hashmaliciousUnknownBrowse
                        • 85.239.34.134
                        arm6.elfGet hashmaliciousUnknownBrowse
                        • 85.239.34.134
                        m68k.elfGet hashmaliciousUnknownBrowse
                        • 85.239.34.134
                        sh4.elfGet hashmaliciousUnknownBrowse
                        • 85.239.34.134
                        x86.elfGet hashmaliciousUnknownBrowse
                        • 85.239.34.134
                        spc.elfGet hashmaliciousUnknownBrowse
                        • 85.239.34.134
                        1C6ljtnwXP.exeGet hashmaliciousLummaCBrowse
                        • 85.239.54.77
                        No context
                        No context
                        No created / dropped files found
                        File type:ELF 32-bit LSB executable, ARM, EABI4 version 1 (SYSV), statically linked, stripped
                        Entropy (8bit):5.863318214016611
                        TrID:
                        • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                        File name:arm7.elf
                        File size:44'096 bytes
                        MD5:3cb8a7c57880d6679e781a6e29ea55c4
                        SHA1:2c1fea37dc23576db8d477e14aedad15a2078e6d
                        SHA256:b5f7265ab3e9c1189cace3f86d6fefc159964a7e4f0835452adca7b2172d4af6
                        SHA512:cae61b94ae5ba946e6e2ed2e2b5e19c9dca2a00b167e23b0e32e68e9ed7b8ae347969fd94a9e43e3211907d6de395c48a5f57e9c18af0357c32ab8af157bc34b
                        SSDEEP:768:EQnS2KQZYJoLXRhC5dcKw2l/8i2QD05/1WYtEk+2G/e:EQnS2KQu4XRhC5Tw2l/8iM5/wEc/
                        TLSH:5513E74AF9816F01D4E521BAFF4E124933935B6CE3FE7102AE151F2563CAA6B0F76412
                        File Content Preview:.ELF..............(.........4...........4. ...(........p.....%...%.. ... ....................................................6...6......l1...................6...6..................Q.td..................................-...L..................@-.,@...0....S

                        ELF header

                        Class:ELF32
                        Data:2's complement, little endian
                        Version:1 (current)
                        Machine:ARM
                        Version Number:0x1
                        Type:EXEC (Executable file)
                        OS/ABI:UNIX - System V
                        ABI Version:0
                        Entry Point Address:0x8194
                        Flags:0x4000002
                        ELF Header Size:52
                        Program Header Offset:52
                        Program Header Size:32
                        Number of Program Headers:5
                        Section Header Offset:43456
                        Section Header Size:40
                        Number of Section Headers:16
                        Header String Table Index:15
                        NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                        NULL0x00x00x00x00x0000
                        .initPROGBITS0x80d40xd40x100x00x6AX004
                        .textPROGBITS0x80f00xf00x9fa00x00x6AX0016
                        .finiPROGBITS0x120900xa0900x100x00x6AX004
                        .rodataPROGBITS0x120a00xa0a00x4c80x00x2A004
                        .ARM.extabPROGBITS0x125680xa5680x180x00x2A004
                        .ARM.exidxARM_EXIDX0x125800xa5800x1200x00x82AL204
                        .eh_framePROGBITS0x136a00xa6a00x40x00x3WA004
                        .tbssNOBITS0x136a40xa6a40x80x00x403WAT004
                        .init_arrayINIT_ARRAY0x136a40xa6a40x40x00x3WA004
                        .fini_arrayFINI_ARRAY0x136a80xa6a80x40x00x3WA004
                        .jcrPROGBITS0x136ac0xa6ac0x40x00x3WA004
                        .gotPROGBITS0x136b00xa6b00xa80x40x3WA004
                        .dataPROGBITS0x137580xa7580x1f00x00x3WA004
                        .bssNOBITS0x139480xa9480x2ec40x00x3WA004
                        .shstrtabSTRTAB0x00xa9480x780x00x0001
                        TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                        EXIDX0xa5800x125800x125800x1200x1204.40180x4R 0x4.ARM.exidx
                        LOAD0x00x80000x80000xa6a00xa6a05.89450x5R E0x1000.init .text .fini .rodata .ARM.extab .ARM.exidx
                        LOAD0xa6a00x136a00x136a00x2a80x316c3.75870x6RW 0x1000.eh_frame .tbss .init_array .fini_array .jcr .got .data .bss
                        TLS0xa6a40x136a40x136a40x00x80.00000x4R 0x4.tbss
                        GNU_STACK0x00x00x00x00x00.00000x7RWE0x4
                        TimestampSIDSignatureSeveritySource IPSource PortDest IPDest PortProtocol
                        2024-12-30T04:12:58.521455+01002849816ETPRO MALWARE ELF/Multiverze CnC Checkin1192.168.2.135362685.239.34.1346666TCP
                        TimestampSource PortDest PortSource IPDest IP
                        Dec 30, 2024 04:12:58.511074066 CET536266666192.168.2.1385.239.34.134
                        Dec 30, 2024 04:12:58.515933037 CET66665362685.239.34.134192.168.2.13
                        Dec 30, 2024 04:12:58.515989065 CET536266666192.168.2.1385.239.34.134
                        Dec 30, 2024 04:12:58.521455050 CET536266666192.168.2.1385.239.34.134
                        Dec 30, 2024 04:12:58.526236057 CET66665362685.239.34.134192.168.2.13
                        Dec 30, 2024 04:12:59.788543940 CET66665362685.239.34.134192.168.2.13
                        Dec 30, 2024 04:12:59.788708925 CET536266666192.168.2.1385.239.34.134
                        Dec 30, 2024 04:12:59.788784981 CET536266666192.168.2.1385.239.34.134
                        Dec 30, 2024 04:12:59.793585062 CET66665362685.239.34.134192.168.2.13
                        Dec 30, 2024 04:13:04.797760010 CET66665362685.239.34.134192.168.2.13
                        Dec 30, 2024 04:13:04.797962904 CET536266666192.168.2.1385.239.34.134
                        Dec 30, 2024 04:13:04.797962904 CET536266666192.168.2.1385.239.34.134
                        Dec 30, 2024 04:13:04.802719116 CET66665362685.239.34.134192.168.2.13
                        Dec 30, 2024 04:13:09.866857052 CET66665362685.239.34.134192.168.2.13
                        Dec 30, 2024 04:13:09.867008924 CET536266666192.168.2.1385.239.34.134
                        Dec 30, 2024 04:13:09.867057085 CET536266666192.168.2.1385.239.34.134
                        Dec 30, 2024 04:13:09.872000933 CET66665362685.239.34.134192.168.2.13
                        Dec 30, 2024 04:13:14.883802891 CET66665362685.239.34.134192.168.2.13
                        Dec 30, 2024 04:13:14.883991003 CET536266666192.168.2.1385.239.34.134
                        Dec 30, 2024 04:13:14.889987946 CET66665362685.239.34.134192.168.2.13
                        Dec 30, 2024 04:13:19.893074036 CET66665362685.239.34.134192.168.2.13
                        Dec 30, 2024 04:13:19.893383026 CET536266666192.168.2.1385.239.34.134
                        Dec 30, 2024 04:13:19.898190022 CET66665362685.239.34.134192.168.2.13
                        Dec 30, 2024 04:13:20.625179052 CET66665362685.239.34.134192.168.2.13
                        Dec 30, 2024 04:13:20.625585079 CET536266666192.168.2.1385.239.34.134
                        Dec 30, 2024 04:13:20.630390882 CET66665362685.239.34.134192.168.2.13
                        Dec 30, 2024 04:13:24.930892944 CET66665362685.239.34.134192.168.2.13
                        Dec 30, 2024 04:13:24.931349039 CET536266666192.168.2.1385.239.34.134
                        Dec 30, 2024 04:13:24.936132908 CET66665362685.239.34.134192.168.2.13
                        Dec 30, 2024 04:13:29.937824965 CET66665362685.239.34.134192.168.2.13
                        Dec 30, 2024 04:13:29.938069105 CET536266666192.168.2.1385.239.34.134
                        Dec 30, 2024 04:13:29.942902088 CET66665362685.239.34.134192.168.2.13
                        Dec 30, 2024 04:13:34.950932026 CET66665362685.239.34.134192.168.2.13
                        Dec 30, 2024 04:13:34.951205015 CET536266666192.168.2.1385.239.34.134
                        Dec 30, 2024 04:13:34.955997944 CET66665362685.239.34.134192.168.2.13
                        Dec 30, 2024 04:13:35.633380890 CET66665362685.239.34.134192.168.2.13
                        Dec 30, 2024 04:13:35.633649111 CET536266666192.168.2.1385.239.34.134
                        Dec 30, 2024 04:13:35.638488054 CET66665362685.239.34.134192.168.2.13
                        Dec 30, 2024 04:13:39.964082956 CET66665362685.239.34.134192.168.2.13
                        Dec 30, 2024 04:13:39.964603901 CET536266666192.168.2.1385.239.34.134
                        Dec 30, 2024 04:13:39.970242977 CET66665362685.239.34.134192.168.2.13
                        Dec 30, 2024 04:13:44.970829010 CET66665362685.239.34.134192.168.2.13
                        Dec 30, 2024 04:13:44.971024990 CET536266666192.168.2.1385.239.34.134
                        Dec 30, 2024 04:13:44.975958109 CET66665362685.239.34.134192.168.2.13
                        Dec 30, 2024 04:13:49.977014065 CET66665362685.239.34.134192.168.2.13
                        Dec 30, 2024 04:13:49.977209091 CET536266666192.168.2.1385.239.34.134
                        Dec 30, 2024 04:13:49.981996059 CET66665362685.239.34.134192.168.2.13
                        Dec 30, 2024 04:13:50.641715050 CET66665362685.239.34.134192.168.2.13
                        Dec 30, 2024 04:13:50.642107010 CET536266666192.168.2.1385.239.34.134
                        Dec 30, 2024 04:13:50.647027969 CET66665362685.239.34.134192.168.2.13
                        Dec 30, 2024 04:13:54.983781099 CET66665362685.239.34.134192.168.2.13
                        Dec 30, 2024 04:13:54.983987093 CET536266666192.168.2.1385.239.34.134
                        Dec 30, 2024 04:13:54.989610910 CET66665362685.239.34.134192.168.2.13
                        Dec 30, 2024 04:13:59.993767977 CET66665362685.239.34.134192.168.2.13
                        Dec 30, 2024 04:13:59.994051933 CET536266666192.168.2.1385.239.34.134
                        Dec 30, 2024 04:13:59.998821020 CET66665362685.239.34.134192.168.2.13
                        Dec 30, 2024 04:14:05.040993929 CET66665362685.239.34.134192.168.2.13
                        Dec 30, 2024 04:14:05.041172028 CET536266666192.168.2.1385.239.34.134
                        Dec 30, 2024 04:14:05.046015978 CET66665362685.239.34.134192.168.2.13
                        Dec 30, 2024 04:14:05.652725935 CET66665362685.239.34.134192.168.2.13
                        Dec 30, 2024 04:14:05.653090954 CET536266666192.168.2.1385.239.34.134
                        Dec 30, 2024 04:14:05.657972097 CET66665362685.239.34.134192.168.2.13
                        Dec 30, 2024 04:14:10.053154945 CET66665362685.239.34.134192.168.2.13
                        Dec 30, 2024 04:14:10.053589106 CET536266666192.168.2.1385.239.34.134
                        Dec 30, 2024 04:14:10.058520079 CET66665362685.239.34.134192.168.2.13
                        Dec 30, 2024 04:14:15.067996979 CET66665362685.239.34.134192.168.2.13
                        Dec 30, 2024 04:14:15.068466902 CET536266666192.168.2.1385.239.34.134
                        Dec 30, 2024 04:14:15.073282957 CET66665362685.239.34.134192.168.2.13
                        Dec 30, 2024 04:14:20.084647894 CET66665362685.239.34.134192.168.2.13
                        Dec 30, 2024 04:14:20.085180044 CET536266666192.168.2.1385.239.34.134
                        Dec 30, 2024 04:14:20.090020895 CET66665362685.239.34.134192.168.2.13
                        Dec 30, 2024 04:14:20.659308910 CET66665362685.239.34.134192.168.2.13
                        Dec 30, 2024 04:14:20.659538031 CET536266666192.168.2.1385.239.34.134
                        Dec 30, 2024 04:14:20.664338112 CET66665362685.239.34.134192.168.2.13
                        Dec 30, 2024 04:14:25.081654072 CET66665362685.239.34.134192.168.2.13
                        Dec 30, 2024 04:14:25.081892967 CET536266666192.168.2.1385.239.34.134
                        Dec 30, 2024 04:14:25.086663008 CET66665362685.239.34.134192.168.2.13
                        Dec 30, 2024 04:14:30.088995934 CET66665362685.239.34.134192.168.2.13
                        Dec 30, 2024 04:14:30.089340925 CET536266666192.168.2.1385.239.34.134
                        Dec 30, 2024 04:14:30.094322920 CET66665362685.239.34.134192.168.2.13
                        Dec 30, 2024 04:14:35.151868105 CET66665362685.239.34.134192.168.2.13
                        Dec 30, 2024 04:14:35.152245045 CET536266666192.168.2.1385.239.34.134
                        Dec 30, 2024 04:14:35.157150984 CET66665362685.239.34.134192.168.2.13
                        Dec 30, 2024 04:14:35.667711020 CET66665362685.239.34.134192.168.2.13
                        Dec 30, 2024 04:14:35.667993069 CET536266666192.168.2.1385.239.34.134
                        Dec 30, 2024 04:14:35.672775984 CET66665362685.239.34.134192.168.2.13
                        Dec 30, 2024 04:14:40.167323112 CET66665362685.239.34.134192.168.2.13
                        Dec 30, 2024 04:14:40.167507887 CET536266666192.168.2.1385.239.34.134
                        Dec 30, 2024 04:14:40.172388077 CET66665362685.239.34.134192.168.2.13
                        Dec 30, 2024 04:14:45.175673962 CET66665362685.239.34.134192.168.2.13
                        Dec 30, 2024 04:14:45.175930023 CET536266666192.168.2.1385.239.34.134
                        Dec 30, 2024 04:14:45.180747986 CET66665362685.239.34.134192.168.2.13
                        Dec 30, 2024 04:14:50.189956903 CET66665362685.239.34.134192.168.2.13
                        Dec 30, 2024 04:14:50.190236092 CET536266666192.168.2.1385.239.34.134
                        Dec 30, 2024 04:14:50.195024014 CET66665362685.239.34.134192.168.2.13
                        Dec 30, 2024 04:14:50.686549902 CET66665362685.239.34.134192.168.2.13
                        Dec 30, 2024 04:14:50.686790943 CET536266666192.168.2.1385.239.34.134
                        Dec 30, 2024 04:14:50.691636086 CET66665362685.239.34.134192.168.2.13
                        Dec 30, 2024 04:14:55.225462914 CET66665362685.239.34.134192.168.2.13
                        Dec 30, 2024 04:14:55.225636959 CET536266666192.168.2.1385.239.34.134
                        Dec 30, 2024 04:14:55.230472088 CET66665362685.239.34.134192.168.2.13
                        Dec 30, 2024 04:15:00.272384882 CET66665362685.239.34.134192.168.2.13
                        Dec 30, 2024 04:15:00.272850990 CET536266666192.168.2.1385.239.34.134
                        Dec 30, 2024 04:15:00.277664900 CET66665362685.239.34.134192.168.2.13
                        Dec 30, 2024 04:15:05.284768105 CET66665362685.239.34.134192.168.2.13
                        Dec 30, 2024 04:15:05.285187006 CET536266666192.168.2.1385.239.34.134
                        Dec 30, 2024 04:15:05.290045023 CET66665362685.239.34.134192.168.2.13
                        Dec 30, 2024 04:15:05.725729942 CET66665362685.239.34.134192.168.2.13
                        Dec 30, 2024 04:15:05.726022005 CET536266666192.168.2.1385.239.34.134
                        Dec 30, 2024 04:15:05.730854988 CET66665362685.239.34.134192.168.2.13
                        Dec 30, 2024 04:15:10.291876078 CET66665362685.239.34.134192.168.2.13
                        Dec 30, 2024 04:15:10.292383909 CET536266666192.168.2.1385.239.34.134
                        Dec 30, 2024 04:15:10.297172070 CET66665362685.239.34.134192.168.2.13
                        Dec 30, 2024 04:15:15.357794046 CET66665362685.239.34.134192.168.2.13
                        Dec 30, 2024 04:15:15.358135939 CET536266666192.168.2.1385.239.34.134
                        Dec 30, 2024 04:15:15.362973928 CET66665362685.239.34.134192.168.2.13
                        Dec 30, 2024 04:15:20.373279095 CET66665362685.239.34.134192.168.2.13
                        Dec 30, 2024 04:15:20.373594046 CET536266666192.168.2.1385.239.34.134
                        Dec 30, 2024 04:15:20.378396988 CET66665362685.239.34.134192.168.2.13
                        Dec 30, 2024 04:15:20.761246920 CET66665362685.239.34.134192.168.2.13
                        Dec 30, 2024 04:15:20.761573076 CET536266666192.168.2.1385.239.34.134
                        Dec 30, 2024 04:15:20.766349077 CET66665362685.239.34.134192.168.2.13
                        Dec 30, 2024 04:15:25.385514021 CET66665362685.239.34.134192.168.2.13
                        Dec 30, 2024 04:15:25.385912895 CET536266666192.168.2.1385.239.34.134
                        Dec 30, 2024 04:15:25.390746117 CET66665362685.239.34.134192.168.2.13
                        Dec 30, 2024 04:15:30.461704016 CET66665362685.239.34.134192.168.2.13
                        Dec 30, 2024 04:15:30.461899996 CET536266666192.168.2.1385.239.34.134
                        Dec 30, 2024 04:15:30.466703892 CET66665362685.239.34.134192.168.2.13
                        Dec 30, 2024 04:15:35.468770027 CET66665362685.239.34.134192.168.2.13
                        Dec 30, 2024 04:15:35.469055891 CET536266666192.168.2.1385.239.34.134
                        Dec 30, 2024 04:15:35.473921061 CET66665362685.239.34.134192.168.2.13
                        Dec 30, 2024 04:15:35.767865896 CET66665362685.239.34.134192.168.2.13
                        Dec 30, 2024 04:15:35.767956972 CET536266666192.168.2.1385.239.34.134
                        Dec 30, 2024 04:15:35.773464918 CET66665362685.239.34.134192.168.2.13
                        Dec 30, 2024 04:15:40.477323055 CET66665362685.239.34.134192.168.2.13
                        Dec 30, 2024 04:15:40.477499962 CET536266666192.168.2.1385.239.34.134
                        Dec 30, 2024 04:15:40.482346058 CET66665362685.239.34.134192.168.2.13
                        Dec 30, 2024 04:15:45.516439915 CET66665362685.239.34.134192.168.2.13
                        Dec 30, 2024 04:15:45.516541958 CET536266666192.168.2.1385.239.34.134
                        Dec 30, 2024 04:15:45.521347046 CET66665362685.239.34.134192.168.2.13
                        Dec 30, 2024 04:15:50.568085909 CET66665362685.239.34.134192.168.2.13
                        Dec 30, 2024 04:15:50.568233967 CET536266666192.168.2.1385.239.34.134
                        Dec 30, 2024 04:15:50.573100090 CET66665362685.239.34.134192.168.2.13
                        Dec 30, 2024 04:15:55.581532001 CET66665362685.239.34.134192.168.2.13
                        Dec 30, 2024 04:15:55.581657887 CET536266666192.168.2.1385.239.34.134
                        Dec 30, 2024 04:15:55.586518049 CET66665362685.239.34.134192.168.2.13
                        Dec 30, 2024 04:16:00.592978001 CET66665362685.239.34.134192.168.2.13
                        Dec 30, 2024 04:16:00.593245983 CET536266666192.168.2.1385.239.34.134
                        Dec 30, 2024 04:16:00.598115921 CET66665362685.239.34.134192.168.2.13
                        Dec 30, 2024 04:16:05.663259983 CET66665362685.239.34.134192.168.2.13
                        Dec 30, 2024 04:16:05.663672924 CET536266666192.168.2.1385.239.34.134
                        Dec 30, 2024 04:16:05.668507099 CET66665362685.239.34.134192.168.2.13
                        Dec 30, 2024 04:16:05.834450960 CET66665362685.239.34.134192.168.2.13
                        Dec 30, 2024 04:16:05.834813118 CET536266666192.168.2.1385.239.34.134
                        Dec 30, 2024 04:16:05.839898109 CET66665362685.239.34.134192.168.2.13
                        Dec 30, 2024 04:16:10.670412064 CET66665362685.239.34.134192.168.2.13
                        Dec 30, 2024 04:16:10.670778990 CET536266666192.168.2.1385.239.34.134
                        Dec 30, 2024 04:16:10.675622940 CET66665362685.239.34.134192.168.2.13
                        Dec 30, 2024 04:16:15.676707029 CET66665362685.239.34.134192.168.2.13
                        Dec 30, 2024 04:16:15.676892996 CET536266666192.168.2.1385.239.34.134
                        Dec 30, 2024 04:16:15.681730986 CET66665362685.239.34.134192.168.2.13
                        Dec 30, 2024 04:16:20.687131882 CET66665362685.239.34.134192.168.2.13
                        Dec 30, 2024 04:16:20.687402010 CET536266666192.168.2.1385.239.34.134
                        Dec 30, 2024 04:16:20.692224026 CET66665362685.239.34.134192.168.2.13
                        Dec 30, 2024 04:16:20.850408077 CET66665362685.239.34.134192.168.2.13
                        Dec 30, 2024 04:16:20.850687027 CET536266666192.168.2.1385.239.34.134
                        Dec 30, 2024 04:16:20.855520010 CET66665362685.239.34.134192.168.2.13
                        Dec 30, 2024 04:16:25.727319956 CET66665362685.239.34.134192.168.2.13
                        Dec 30, 2024 04:16:25.727530003 CET536266666192.168.2.1385.239.34.134
                        Dec 30, 2024 04:16:25.732381105 CET66665362685.239.34.134192.168.2.13
                        Dec 30, 2024 04:16:30.737077951 CET66665362685.239.34.134192.168.2.13
                        Dec 30, 2024 04:16:30.737245083 CET536266666192.168.2.1385.239.34.134
                        Dec 30, 2024 04:16:30.742060900 CET66665362685.239.34.134192.168.2.13
                        TimestampSource PortDest PortSource IPDest IP
                        Dec 30, 2024 04:15:44.529457092 CET5539953192.168.2.138.8.8.8
                        Dec 30, 2024 04:15:44.529510021 CET5293553192.168.2.138.8.8.8
                        Dec 30, 2024 04:15:44.535846949 CET53553998.8.8.8192.168.2.13
                        Dec 30, 2024 04:15:44.535923958 CET53529358.8.8.8192.168.2.13
                        TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                        Dec 30, 2024 04:15:44.529457092 CET192.168.2.138.8.8.80x564bStandard query (0)daisy.ubuntu.comA (IP address)IN (0x0001)false
                        Dec 30, 2024 04:15:44.529510021 CET192.168.2.138.8.8.80x922dStandard query (0)daisy.ubuntu.com28IN (0x0001)false
                        TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                        Dec 30, 2024 04:15:44.535846949 CET8.8.8.8192.168.2.130x564bNo error (0)daisy.ubuntu.com162.213.35.24A (IP address)IN (0x0001)false
                        Dec 30, 2024 04:15:44.535846949 CET8.8.8.8192.168.2.130x564bNo error (0)daisy.ubuntu.com162.213.35.25A (IP address)IN (0x0001)false

                        System Behavior

                        Start time (UTC):03:12:57
                        Start date (UTC):30/12/2024
                        Path:/tmp/arm7.elf
                        Arguments:/tmp/arm7.elf
                        File size:4956856 bytes
                        MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                        Start time (UTC):03:12:57
                        Start date (UTC):30/12/2024
                        Path:/tmp/arm7.elf
                        Arguments:-
                        File size:4956856 bytes
                        MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1