Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
bot.x86.elf

Overview

General Information

Sample name:bot.x86.elf
Analysis ID:1583139
MD5:dd71487c78fb3cc5ab09c350a01d28f7
SHA1:ab30dae9842cfe912461b1fa1a098247babe8e28
SHA256:f3928fd942a8d5e9b9ffaa98e0722903f936eb895a0934ad3a24fe5a4a7495f8
Tags:elfuser-abuse_ch
Infos:

Detection

Mirai, Okiru
Score:100
Range:0 - 100
Whitelisted:false

Signatures

Antivirus / Scanner detection for submitted sample
Detected Mirai
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Suricata IDS alerts for network traffic
Yara detected Mirai
Yara detected Okiru
Connects to many ports of the same IP (likely port scanning)
Machine Learning detection for sample
Detected TCP or UDP traffic on non-standard ports
Enumerates processes within the "proc" file system
Found strings indicative of a multi-platform dropper
Sample contains strings indicative of BusyBox which embeds multiple Unix commands in a single executable
Sample has stripped symbol table
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Yara signature match

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1583139
Start date and time:2025-01-02 02:51:06 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 26s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:bot.x86.elf
Detection:MAL
Classification:mal100.troj.linELF@0/0@20/0
Command:/tmp/bot.x86.elf
PID:6241
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
done.
Standard Error:
  • system is lnxubuntu20
  • bot.x86.elf (PID: 6241, Parent: 6167, MD5: dd71487c78fb3cc5ab09c350a01d28f7) Arguments: /tmp/bot.x86.elf
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
MiraiMirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese. Nowadays it targets a wide range of networked embedded devices such as IP cameras, home routers (many vendors involved), and other IoT devices. Since the source code was published on "Hack Forums" many variants of the Mirai family appeared, infecting mostly home networks all around the world.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/elf.mirai
SourceRuleDescriptionAuthorStrings
bot.x86.elfJoeSecurity_OkiruYara detected OkiruJoe Security
    bot.x86.elfJoeSecurity_Mirai_3Yara detected MiraiJoe Security
      bot.x86.elfJoeSecurity_Mirai_8Yara detected MiraiJoe Security
        bot.x86.elfLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
        • 0xf6b8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0xf6cc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0xf6e0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0xf6f4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0xf708:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0xf71c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0xf730:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0xf744:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0xf758:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0xf76c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0xf780:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0xf794:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0xf7a8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0xf7bc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0xf7d0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0xf7e4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0xf7f8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0xf80c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0xf820:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0xf834:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0xf848:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        bot.x86.elfLinux_Trojan_Mirai_b14f4c5dunknownunknown
        • 0x32f0:$a: 53 31 DB 8B 4C 24 0C 8B 54 24 08 83 F9 01 76 15 66 8B 02 83 E9 02 25 FF FF 00 00 83 C2 02 01 C3 83 F9 01 77 EB 49 75 05 0F BE 02 01 C3
        Click to see the 5 entries
        SourceRuleDescriptionAuthorStrings
        6241.1.0000000008048000.000000000805a000.r-x.sdmpJoeSecurity_OkiruYara detected OkiruJoe Security
          6241.1.0000000008048000.000000000805a000.r-x.sdmpJoeSecurity_Mirai_3Yara detected MiraiJoe Security
            6241.1.0000000008048000.000000000805a000.r-x.sdmpJoeSecurity_Mirai_8Yara detected MiraiJoe Security
              6241.1.0000000008048000.000000000805a000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
              • 0xf6b8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
              • 0xf6cc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
              • 0xf6e0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
              • 0xf6f4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
              • 0xf708:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
              • 0xf71c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
              • 0xf730:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
              • 0xf744:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
              • 0xf758:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
              • 0xf76c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
              • 0xf780:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
              • 0xf794:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
              • 0xf7a8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
              • 0xf7bc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
              • 0xf7d0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
              • 0xf7e4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
              • 0xf7f8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
              • 0xf80c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
              • 0xf820:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
              • 0xf834:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
              • 0xf848:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
              6241.1.0000000008048000.000000000805a000.r-x.sdmpLinux_Trojan_Mirai_b14f4c5dunknownunknown
              • 0x32f0:$a: 53 31 DB 8B 4C 24 0C 8B 54 24 08 83 F9 01 76 15 66 8B 02 83 E9 02 25 FF FF 00 00 83 C2 02 01 C3 83 F9 01 77 EB 49 75 05 0F BE 02 01 C3
              Click to see the 9 entries
              TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
              2025-01-02T02:51:49.224916+010020304901Malware Command and Control Activity Detected192.168.2.2351750160.191.175.18743957TCP
              2025-01-02T02:51:54.078810+010020304901Malware Command and Control Activity Detected192.168.2.2351752160.191.175.18743957TCP
              2025-01-02T02:52:04.946028+010020304901Malware Command and Control Activity Detected192.168.2.2351754160.191.175.18743957TCP
              2025-01-02T02:52:08.790763+010020304901Malware Command and Control Activity Detected192.168.2.2351756160.191.175.18743957TCP
              2025-01-02T02:52:19.653054+010020304901Malware Command and Control Activity Detected192.168.2.2351758160.191.175.18743957TCP
              2025-01-02T02:52:23.512886+010020304901Malware Command and Control Activity Detected192.168.2.2351760160.191.175.18743957TCP
              2025-01-02T02:52:27.401265+010020304901Malware Command and Control Activity Detected192.168.2.2351762160.191.175.18743957TCP
              2025-01-02T02:52:31.256623+010020304901Malware Command and Control Activity Detected192.168.2.2351764160.191.175.18743957TCP
              2025-01-02T02:52:33.094730+010020304901Malware Command and Control Activity Detected192.168.2.2351766160.191.175.18743957TCP
              2025-01-02T02:52:36.948372+010020304901Malware Command and Control Activity Detected192.168.2.2351768160.191.175.18743957TCP
              2025-01-02T02:52:44.823225+010020304901Malware Command and Control Activity Detected192.168.2.2351770160.191.175.18743957TCP
              2025-01-02T02:52:53.662268+010020304901Malware Command and Control Activity Detected192.168.2.2351772160.191.175.18743957TCP
              2025-01-02T02:53:02.521685+010020304901Malware Command and Control Activity Detected192.168.2.2351774160.191.175.18743957TCP
              2025-01-02T02:53:10.373177+010020304901Malware Command and Control Activity Detected192.168.2.2351776160.191.175.18743957TCP
              2025-01-02T02:53:21.221830+010020304901Malware Command and Control Activity Detected192.168.2.2351778160.191.175.18743957TCP
              2025-01-02T02:53:23.116860+010020304901Malware Command and Control Activity Detected192.168.2.2351780160.191.175.18743957TCP
              2025-01-02T02:53:29.968975+010020304901Malware Command and Control Activity Detected192.168.2.2351782160.191.175.18743957TCP
              2025-01-02T02:53:36.850192+010020304901Malware Command and Control Activity Detected192.168.2.2351784160.191.175.18743957TCP
              2025-01-02T02:53:45.701356+010020304901Malware Command and Control Activity Detected192.168.2.2351786160.191.175.18743957TCP
              2025-01-02T02:53:50.547752+010020304901Malware Command and Control Activity Detected192.168.2.2351788160.191.175.18743957TCP

              Click to jump to signature section

              Show All Signature Results

              AV Detection

              barindex
              Source: bot.x86.elfAvira: detected
              Source: bot.x86.elfReversingLabs: Detection: 63%
              Source: bot.x86.elfJoe Sandbox ML: detected
              Source: bot.x86.elfString: HTTP/1.1 200 OKtop1hbt.armtop1hbt.arm5top1hbt.arm6top1hbt.arm7top1hbt.mipstop1hbt.mpsltop1hbt.x86_64top1hbt.sh4/proc/proc/%d/cmdlinenetstatwgetcurl/bin/busybox/proc//proc/%s/exe/proc/self/exevar/Challengeapp/hi3511gmDVRiboxusr/dvr_main _8182T_1108mnt/mtd/app/guivar/Kylinl0 c/udevdvar/tmp/soniahicorestm_hi3511_dvr/usr/lib/systemd/systemdshellmnt/sys/boot/media/srv/var/run/sbin/lib/etc/dev/home/Davincitelnetsshwatchdog/var/spool/var/Sofiasshd/usr/compress/bin//compress/bin/compress/usr/bashhttpdtelnetddropbearencodersystem/root/dvr_gui//root/dvr_app//anko-app//opt/anko-app/ankosample _8182T_1104/usr/libexec/openssh/sftp-serverabcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ3f

              Networking

              barindex
              Source: Network trafficSuricata IDS: 2030490 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) : 192.168.2.23:51754 -> 160.191.175.187:43957
              Source: Network trafficSuricata IDS: 2030490 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) : 192.168.2.23:51780 -> 160.191.175.187:43957
              Source: Network trafficSuricata IDS: 2030490 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) : 192.168.2.23:51772 -> 160.191.175.187:43957
              Source: Network trafficSuricata IDS: 2030490 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) : 192.168.2.23:51760 -> 160.191.175.187:43957
              Source: Network trafficSuricata IDS: 2030490 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) : 192.168.2.23:51778 -> 160.191.175.187:43957
              Source: Network trafficSuricata IDS: 2030490 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) : 192.168.2.23:51762 -> 160.191.175.187:43957
              Source: Network trafficSuricata IDS: 2030490 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) : 192.168.2.23:51774 -> 160.191.175.187:43957
              Source: Network trafficSuricata IDS: 2030490 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) : 192.168.2.23:51758 -> 160.191.175.187:43957
              Source: Network trafficSuricata IDS: 2030490 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) : 192.168.2.23:51756 -> 160.191.175.187:43957
              Source: Network trafficSuricata IDS: 2030490 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) : 192.168.2.23:51770 -> 160.191.175.187:43957
              Source: Network trafficSuricata IDS: 2030490 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) : 192.168.2.23:51782 -> 160.191.175.187:43957
              Source: Network trafficSuricata IDS: 2030490 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) : 192.168.2.23:51776 -> 160.191.175.187:43957
              Source: Network trafficSuricata IDS: 2030490 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) : 192.168.2.23:51784 -> 160.191.175.187:43957
              Source: Network trafficSuricata IDS: 2030490 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) : 192.168.2.23:51750 -> 160.191.175.187:43957
              Source: Network trafficSuricata IDS: 2030490 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) : 192.168.2.23:51752 -> 160.191.175.187:43957
              Source: Network trafficSuricata IDS: 2030490 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) : 192.168.2.23:51766 -> 160.191.175.187:43957
              Source: Network trafficSuricata IDS: 2030490 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) : 192.168.2.23:51786 -> 160.191.175.187:43957
              Source: Network trafficSuricata IDS: 2030490 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) : 192.168.2.23:51788 -> 160.191.175.187:43957
              Source: Network trafficSuricata IDS: 2030490 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) : 192.168.2.23:51768 -> 160.191.175.187:43957
              Source: Network trafficSuricata IDS: 2030490 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) : 192.168.2.23:51764 -> 160.191.175.187:43957
              Source: global trafficTCP traffic: 160.191.175.187 ports 43957,3,4,5,7,9
              Source: global trafficTCP traffic: 192.168.2.23:51750 -> 160.191.175.187:43957
              Source: global trafficTCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
              Source: global trafficTCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
              Source: global trafficTCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
              Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
              Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
              Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
              Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
              Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
              Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
              Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
              Source: global trafficDNS traffic detected: DNS query: botnetdolly.zapto.org
              Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443

              System Summary

              barindex
              Source: bot.x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
              Source: bot.x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_b14f4c5d Author: unknown
              Source: bot.x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_5f7b67b8 Author: unknown
              Source: bot.x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_88de437f Author: unknown
              Source: bot.x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_389ee3e9 Author: unknown
              Source: bot.x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_cc93863b Author: unknown
              Source: bot.x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_8aa7b5d3 Author: unknown
              Source: 6241.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
              Source: 6241.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_b14f4c5d Author: unknown
              Source: 6241.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_5f7b67b8 Author: unknown
              Source: 6241.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_88de437f Author: unknown
              Source: 6241.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_389ee3e9 Author: unknown
              Source: 6241.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_cc93863b Author: unknown
              Source: 6241.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_8aa7b5d3 Author: unknown
              Source: Process Memory Space: bot.x86.elf PID: 6241, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
              Source: Initial sampleString containing 'busybox' found: /bin/busybox
              Source: Initial sampleString containing 'busybox' found: HTTP/1.1 200 OKtop1hbt.armtop1hbt.arm5top1hbt.arm6top1hbt.arm7top1hbt.mipstop1hbt.mpsltop1hbt.x86_64top1hbt.sh4/proc/proc/%d/cmdlinenetstatwgetcurl/bin/busybox/proc//proc/%s/exe/proc/self/exevar/Challengeapp/hi3511gmDVRiboxusr/dvr_main _8182T_1108mnt/mtd/app/guivar/Kylinl0 c/udevdvar/tmp/soniahicorestm_hi3511_dvr/usr/lib/systemd/systemdshellmnt/sys/boot/media/srv/var/run/sbin/lib/etc/dev/home/Davincitelnetsshwatchdog/var/spool/var/Sofiasshd/usr/compress/bin//compress/bin/compress/usr/bashhttpdtelnetddropbearencodersystem/root/dvr_gui//root/dvr_app//anko-app//opt/anko-app/ankosample _8182T_1104/usr/libexec/openssh/sftp-serverabcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ3f
              Source: ELF static info symbol of initial sample.symtab present: no
              Source: bot.x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
              Source: bot.x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_b14f4c5d os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = a70d052918dd2fbc66db241da6438015130f0fb6929229bfe573546fe98da817, id = b14f4c5d-054f-46e6-9fa8-3588f1ef68b7, last_modified = 2021-09-16
              Source: bot.x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_5f7b67b8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 6cb5fb0b7c132e9c11ac72da43278025b60810ea3733c9c6d6ca966163185940, id = 5f7b67b8-3d7b-48a4-8f03-b6f2c92be92e, last_modified = 2021-09-16
              Source: bot.x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_88de437f reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = c19eb595c2b444a809bef8500c20342c9f46694d3018e268833f9b884133a1ea, id = 88de437f-9c98-4e1d-96c0-7b433c99886a, last_modified = 2021-09-16
              Source: bot.x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_389ee3e9 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 59f2359dc1f41d385d639d157b4cd9fc73d76d8abb7cc09d47632bb4c9a39e6e, id = 389ee3e9-70c1-4c93-a999-292cf6ff1652, last_modified = 2022-01-26
              Source: bot.x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_cc93863b reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = f3ecd30f0b511a8e92cfa642409d559e7612c3f57a1659ca46c77aca809a00ac, id = cc93863b-1050-40ba-9d02-5ec9ce6a3a28, last_modified = 2022-01-26
              Source: bot.x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_8aa7b5d3 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 02a2c18c362df4b1fceb33f3b605586514ba9a00c7afedf71c04fa54d8146444, id = 8aa7b5d3-e1eb-4b55-b36a-0d3a242c06e9, last_modified = 2022-01-26
              Source: 6241.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
              Source: 6241.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_b14f4c5d os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = a70d052918dd2fbc66db241da6438015130f0fb6929229bfe573546fe98da817, id = b14f4c5d-054f-46e6-9fa8-3588f1ef68b7, last_modified = 2021-09-16
              Source: 6241.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_5f7b67b8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 6cb5fb0b7c132e9c11ac72da43278025b60810ea3733c9c6d6ca966163185940, id = 5f7b67b8-3d7b-48a4-8f03-b6f2c92be92e, last_modified = 2021-09-16
              Source: 6241.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_88de437f reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = c19eb595c2b444a809bef8500c20342c9f46694d3018e268833f9b884133a1ea, id = 88de437f-9c98-4e1d-96c0-7b433c99886a, last_modified = 2021-09-16
              Source: 6241.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_389ee3e9 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 59f2359dc1f41d385d639d157b4cd9fc73d76d8abb7cc09d47632bb4c9a39e6e, id = 389ee3e9-70c1-4c93-a999-292cf6ff1652, last_modified = 2022-01-26
              Source: 6241.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_cc93863b reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = f3ecd30f0b511a8e92cfa642409d559e7612c3f57a1659ca46c77aca809a00ac, id = cc93863b-1050-40ba-9d02-5ec9ce6a3a28, last_modified = 2022-01-26
              Source: 6241.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_8aa7b5d3 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 02a2c18c362df4b1fceb33f3b605586514ba9a00c7afedf71c04fa54d8146444, id = 8aa7b5d3-e1eb-4b55-b36a-0d3a242c06e9, last_modified = 2022-01-26
              Source: Process Memory Space: bot.x86.elf PID: 6241, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
              Source: classification engineClassification label: mal100.troj.linELF@0/0@20/0
              Source: /tmp/bot.x86.elf (PID: 6243)File opened: /proc/1582/cmdlineJump to behavior
              Source: /tmp/bot.x86.elf (PID: 6243)File opened: /proc/3088/cmdlineJump to behavior
              Source: /tmp/bot.x86.elf (PID: 6243)File opened: /proc/230/cmdlineJump to behavior
              Source: /tmp/bot.x86.elf (PID: 6243)File opened: /proc/110/cmdlineJump to behavior
              Source: /tmp/bot.x86.elf (PID: 6243)File opened: /proc/231/cmdlineJump to behavior
              Source: /tmp/bot.x86.elf (PID: 6243)File opened: /proc/111/cmdlineJump to behavior
              Source: /tmp/bot.x86.elf (PID: 6243)File opened: /proc/232/cmdlineJump to behavior
              Source: /tmp/bot.x86.elf (PID: 6243)File opened: /proc/1579/cmdlineJump to behavior
              Source: /tmp/bot.x86.elf (PID: 6243)File opened: /proc/112/cmdlineJump to behavior
              Source: /tmp/bot.x86.elf (PID: 6243)File opened: /proc/233/cmdlineJump to behavior
              Source: /tmp/bot.x86.elf (PID: 6243)File opened: /proc/1699/cmdlineJump to behavior
              Source: /tmp/bot.x86.elf (PID: 6243)File opened: /proc/113/cmdlineJump to behavior
              Source: /tmp/bot.x86.elf (PID: 6243)File opened: /proc/234/cmdlineJump to behavior
              Source: /tmp/bot.x86.elf (PID: 6243)File opened: /proc/1335/cmdlineJump to behavior
              Source: /tmp/bot.x86.elf (PID: 6243)File opened: /proc/1698/cmdlineJump to behavior
              Source: /tmp/bot.x86.elf (PID: 6243)File opened: /proc/114/cmdlineJump to behavior
              Source: /tmp/bot.x86.elf (PID: 6243)File opened: /proc/235/cmdlineJump to behavior
              Source: /tmp/bot.x86.elf (PID: 6243)File opened: /proc/1334/cmdlineJump to behavior
              Source: /tmp/bot.x86.elf (PID: 6243)File opened: /proc/1576/cmdlineJump to behavior
              Source: /tmp/bot.x86.elf (PID: 6243)File opened: /proc/2302/cmdlineJump to behavior
              Source: /tmp/bot.x86.elf (PID: 6243)File opened: /proc/115/cmdlineJump to behavior
              Source: /tmp/bot.x86.elf (PID: 6243)File opened: /proc/236/cmdlineJump to behavior
              Source: /tmp/bot.x86.elf (PID: 6243)File opened: /proc/116/cmdlineJump to behavior
              Source: /tmp/bot.x86.elf (PID: 6243)File opened: /proc/237/cmdlineJump to behavior
              Source: /tmp/bot.x86.elf (PID: 6243)File opened: /proc/117/cmdlineJump to behavior
              Source: /tmp/bot.x86.elf (PID: 6243)File opened: /proc/118/cmdlineJump to behavior
              Source: /tmp/bot.x86.elf (PID: 6243)File opened: /proc/910/cmdlineJump to behavior
              Source: /tmp/bot.x86.elf (PID: 6243)File opened: /proc/6227/cmdlineJump to behavior
              Source: /tmp/bot.x86.elf (PID: 6243)File opened: /proc/119/cmdlineJump to behavior
              Source: /tmp/bot.x86.elf (PID: 6243)File opened: /proc/912/cmdlineJump to behavior
              Source: /tmp/bot.x86.elf (PID: 6243)File opened: /proc/10/cmdlineJump to behavior
              Source: /tmp/bot.x86.elf (PID: 6243)File opened: /proc/2307/cmdlineJump to behavior
              Source: /tmp/bot.x86.elf (PID: 6243)File opened: /proc/11/cmdlineJump to behavior
              Source: /tmp/bot.x86.elf (PID: 6243)File opened: /proc/918/cmdlineJump to behavior
              Source: /tmp/bot.x86.elf (PID: 6243)File opened: /proc/12/cmdlineJump to behavior
              Source: /tmp/bot.x86.elf (PID: 6243)File opened: /proc/13/cmdlineJump to behavior
              Source: /tmp/bot.x86.elf (PID: 6243)File opened: /proc/6243/cmdlineJump to behavior
              Source: /tmp/bot.x86.elf (PID: 6243)File opened: /proc/14/cmdlineJump to behavior
              Source: /tmp/bot.x86.elf (PID: 6243)File opened: /proc/6242/cmdlineJump to behavior
              Source: /tmp/bot.x86.elf (PID: 6243)File opened: /proc/15/cmdlineJump to behavior
              Source: /tmp/bot.x86.elf (PID: 6243)File opened: /proc/16/cmdlineJump to behavior
              Source: /tmp/bot.x86.elf (PID: 6243)File opened: /proc/17/cmdlineJump to behavior
              Source: /tmp/bot.x86.elf (PID: 6243)File opened: /proc/18/cmdlineJump to behavior
              Source: /tmp/bot.x86.elf (PID: 6243)File opened: /proc/1594/cmdlineJump to behavior
              Source: /tmp/bot.x86.elf (PID: 6243)File opened: /proc/120/cmdlineJump to behavior
              Source: /tmp/bot.x86.elf (PID: 6243)File opened: /proc/121/cmdlineJump to behavior
              Source: /tmp/bot.x86.elf (PID: 6243)File opened: /proc/1349/cmdlineJump to behavior
              Source: /tmp/bot.x86.elf (PID: 6243)File opened: /proc/1/cmdlineJump to behavior
              Source: /tmp/bot.x86.elf (PID: 6243)File opened: /proc/122/cmdlineJump to behavior
              Source: /tmp/bot.x86.elf (PID: 6243)File opened: /proc/243/cmdlineJump to behavior
              Source: /tmp/bot.x86.elf (PID: 6243)File opened: /proc/123/cmdlineJump to behavior
              Source: /tmp/bot.x86.elf (PID: 6243)File opened: /proc/2/cmdlineJump to behavior
              Source: /tmp/bot.x86.elf (PID: 6243)File opened: /proc/124/cmdlineJump to behavior
              Source: /tmp/bot.x86.elf (PID: 6243)File opened: /proc/3/cmdlineJump to behavior
              Source: /tmp/bot.x86.elf (PID: 6243)File opened: /proc/4/cmdlineJump to behavior
              Source: /tmp/bot.x86.elf (PID: 6243)File opened: /proc/125/cmdlineJump to behavior
              Source: /tmp/bot.x86.elf (PID: 6243)File opened: /proc/126/cmdlineJump to behavior
              Source: /tmp/bot.x86.elf (PID: 6243)File opened: /proc/1344/cmdlineJump to behavior
              Source: /tmp/bot.x86.elf (PID: 6243)File opened: /proc/1465/cmdlineJump to behavior
              Source: /tmp/bot.x86.elf (PID: 6243)File opened: /proc/1586/cmdlineJump to behavior
              Source: /tmp/bot.x86.elf (PID: 6243)File opened: /proc/127/cmdlineJump to behavior
              Source: /tmp/bot.x86.elf (PID: 6243)File opened: /proc/6/cmdlineJump to behavior
              Source: /tmp/bot.x86.elf (PID: 6243)File opened: /proc/248/cmdlineJump to behavior
              Source: /tmp/bot.x86.elf (PID: 6243)File opened: /proc/128/cmdlineJump to behavior
              Source: /tmp/bot.x86.elf (PID: 6243)File opened: /proc/249/cmdlineJump to behavior
              Source: /tmp/bot.x86.elf (PID: 6243)File opened: /proc/1463/cmdlineJump to behavior
              Source: /tmp/bot.x86.elf (PID: 6243)File opened: /proc/800/cmdlineJump to behavior
              Source: /tmp/bot.x86.elf (PID: 6243)File opened: /proc/9/cmdlineJump to behavior
              Source: /tmp/bot.x86.elf (PID: 6243)File opened: /proc/801/cmdlineJump to behavior
              Source: /tmp/bot.x86.elf (PID: 6243)File opened: /proc/20/cmdlineJump to behavior
              Source: /tmp/bot.x86.elf (PID: 6243)File opened: /proc/21/cmdlineJump to behavior
              Source: /tmp/bot.x86.elf (PID: 6243)File opened: /proc/1900/cmdlineJump to behavior
              Source: /tmp/bot.x86.elf (PID: 6243)File opened: /proc/22/cmdlineJump to behavior
              Source: /tmp/bot.x86.elf (PID: 6243)File opened: /proc/23/cmdlineJump to behavior
              Source: /tmp/bot.x86.elf (PID: 6243)File opened: /proc/24/cmdlineJump to behavior
              Source: /tmp/bot.x86.elf (PID: 6243)File opened: /proc/25/cmdlineJump to behavior
              Source: /tmp/bot.x86.elf (PID: 6243)File opened: /proc/26/cmdlineJump to behavior
              Source: /tmp/bot.x86.elf (PID: 6243)File opened: /proc/27/cmdlineJump to behavior
              Source: /tmp/bot.x86.elf (PID: 6243)File opened: /proc/28/cmdlineJump to behavior
              Source: /tmp/bot.x86.elf (PID: 6243)File opened: /proc/29/cmdlineJump to behavior
              Source: /tmp/bot.x86.elf (PID: 6243)File opened: /proc/491/cmdlineJump to behavior
              Source: /tmp/bot.x86.elf (PID: 6243)File opened: /proc/250/cmdlineJump to behavior
              Source: /tmp/bot.x86.elf (PID: 6243)File opened: /proc/130/cmdlineJump to behavior
              Source: /tmp/bot.x86.elf (PID: 6243)File opened: /proc/251/cmdlineJump to behavior
              Source: /tmp/bot.x86.elf (PID: 6243)File opened: /proc/252/cmdlineJump to behavior
              Source: /tmp/bot.x86.elf (PID: 6243)File opened: /proc/132/cmdlineJump to behavior
              Source: /tmp/bot.x86.elf (PID: 6243)File opened: /proc/253/cmdlineJump to behavior
              Source: /tmp/bot.x86.elf (PID: 6243)File opened: /proc/254/cmdlineJump to behavior
              Source: /tmp/bot.x86.elf (PID: 6243)File opened: /proc/255/cmdlineJump to behavior
              Source: /tmp/bot.x86.elf (PID: 6243)File opened: /proc/4509/cmdlineJump to behavior
              Source: /tmp/bot.x86.elf (PID: 6243)File opened: /proc/256/cmdlineJump to behavior
              Source: /tmp/bot.x86.elf (PID: 6243)File opened: /proc/1599/cmdlineJump to behavior
              Source: /tmp/bot.x86.elf (PID: 6243)File opened: /proc/257/cmdlineJump to behavior
              Source: /tmp/bot.x86.elf (PID: 6243)File opened: /proc/1477/cmdlineJump to behavior
              Source: /tmp/bot.x86.elf (PID: 6243)File opened: /proc/379/cmdlineJump to behavior
              Source: /tmp/bot.x86.elf (PID: 6243)File opened: /proc/258/cmdlineJump to behavior
              Source: /tmp/bot.x86.elf (PID: 6243)File opened: /proc/1476/cmdlineJump to behavior
              Source: /tmp/bot.x86.elf (PID: 6243)File opened: /proc/259/cmdlineJump to behavior
              Source: /tmp/bot.x86.elf (PID: 6243)File opened: /proc/1475/cmdlineJump to behavior
              Source: /tmp/bot.x86.elf (PID: 6243)File opened: /proc/936/cmdlineJump to behavior
              Source: /tmp/bot.x86.elf (PID: 6243)File opened: /proc/30/cmdlineJump to behavior
              Source: /tmp/bot.x86.elf (PID: 6243)File opened: /proc/2208/cmdlineJump to behavior
              Source: /tmp/bot.x86.elf (PID: 6243)File opened: /proc/35/cmdlineJump to behavior
              Source: /tmp/bot.x86.elf (PID: 6243)File opened: /proc/1809/cmdlineJump to behavior
              Source: /tmp/bot.x86.elf (PID: 6243)File opened: /proc/1494/cmdlineJump to behavior

              Stealing of Sensitive Information

              barindex
              Source: Yara matchFile source: bot.x86.elf, type: SAMPLE
              Source: Yara matchFile source: 6241.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORY
              Source: Yara matchFile source: Process Memory Space: bot.x86.elf PID: 6241, type: MEMORYSTR
              Source: Yara matchFile source: bot.x86.elf, type: SAMPLE
              Source: Yara matchFile source: 6241.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORY
              Source: Yara matchFile source: Process Memory Space: bot.x86.elf PID: 6241, type: MEMORYSTR

              Remote Access Functionality

              barindex
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)
              Source: Yara matchFile source: bot.x86.elf, type: SAMPLE
              Source: Yara matchFile source: 6241.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORY
              Source: Yara matchFile source: Process Memory Space: bot.x86.elf PID: 6241, type: MEMORYSTR
              Source: Yara matchFile source: bot.x86.elf, type: SAMPLE
              Source: Yara matchFile source: 6241.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORY
              Source: Yara matchFile source: Process Memory Space: bot.x86.elf PID: 6241, type: MEMORYSTR
              ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
              Gather Victim Identity Information1
              Scripting
              Valid AccountsWindows Management Instrumentation1
              Scripting
              Path InterceptionDirect Volume Access1
              OS Credential Dumping
              System Service DiscoveryRemote ServicesData from Local System1
              Encrypted Channel
              Exfiltration Over Other Network MediumAbuse Accessibility Features
              CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
              Non-Standard Port
              Exfiltration Over BluetoothNetwork Denial of Service
              Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
              Non-Application Layer Protocol
              Automated ExfiltrationData Encrypted for Impact
              Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture2
              Application Layer Protocol
              Traffic DuplicationData Destruction
              No configs have been found
              Hide Legend

              Legend:

              • Process
              • Signature
              • Created File
              • DNS/IP Info
              • Is Dropped
              • Number of created Files
              • Is malicious
              • Internet
              SourceDetectionScannerLabelLink
              bot.x86.elf63%ReversingLabsLinux.Backdoor.Mirai
              bot.x86.elf100%AviraEXP/ELF.Mirai.Z.A
              bot.x86.elf100%Joe Sandbox ML
              No Antivirus matches
              No Antivirus matches
              No Antivirus matches
              NameIPActiveMaliciousAntivirus DetectionReputation
              botnetdolly.zapto.org
              160.191.175.187
              truefalse
                high
                • No. of IPs < 25%
                • 25% < No. of IPs < 50%
                • 50% < No. of IPs < 75%
                • 75% < No. of IPs
                IPDomainCountryFlagASNASN NameMalicious
                160.191.175.187
                botnetdolly.zapto.orgunknown
                2907SINET-ASResearchOrganizationofInformationandSystemsNfalse
                109.202.202.202
                unknownSwitzerland
                13030INIT7CHfalse
                91.189.91.43
                unknownUnited Kingdom
                41231CANONICAL-ASGBfalse
                91.189.91.42
                unknownUnited Kingdom
                41231CANONICAL-ASGBfalse
                MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                160.191.175.187bot.x86_64.elfGet hashmaliciousMirai, Gafgyt, OkiruBrowse
                  bot.ppc.elfGet hashmaliciousMirai, Gafgyt, OkiruBrowse
                    bot.mpsl.elfGet hashmaliciousMirai, Gafgyt, OkiruBrowse
                      bot.mips.elfGet hashmaliciousMirai, Gafgyt, OkiruBrowse
                        bot.arm5.elfGet hashmaliciousMirai, Gafgyt, OkiruBrowse
                          bot.arm7.elfGet hashmaliciousMirai, OkiruBrowse
                            109.202.202.202kpLwzBouH4.elfGet hashmaliciousUnknownBrowse
                            • ch.archive.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_92.0%2bbuild3-0ubuntu0.20.04.1_amd64.deb
                            91.189.91.43bot.x86_64.elfGet hashmaliciousMirai, Gafgyt, OkiruBrowse
                              bot.ppc.elfGet hashmaliciousMirai, Gafgyt, OkiruBrowse
                                x86.elfGet hashmaliciousMiraiBrowse
                                  45.95.169.120-mips-2025-01-02T00_17_36.elfGet hashmaliciousMiraiBrowse
                                    bot.mpsl.elfGet hashmaliciousMirai, Gafgyt, OkiruBrowse
                                      bot.mips.elfGet hashmaliciousMirai, Gafgyt, OkiruBrowse
                                        bot.arm7.elfGet hashmaliciousMirai, OkiruBrowse
                                          x86.elfGet hashmaliciousUnknownBrowse
                                            woega6.elfGet hashmaliciousMiraiBrowse
                                              wrjkngh4.elfGet hashmaliciousMiraiBrowse
                                                91.189.91.42bot.x86_64.elfGet hashmaliciousMirai, Gafgyt, OkiruBrowse
                                                  bot.ppc.elfGet hashmaliciousMirai, Gafgyt, OkiruBrowse
                                                    x86.elfGet hashmaliciousMiraiBrowse
                                                      45.95.169.120-mips-2025-01-02T00_17_36.elfGet hashmaliciousMiraiBrowse
                                                        bot.mpsl.elfGet hashmaliciousMirai, Gafgyt, OkiruBrowse
                                                          bot.mips.elfGet hashmaliciousMirai, Gafgyt, OkiruBrowse
                                                            bot.arm7.elfGet hashmaliciousMirai, OkiruBrowse
                                                              x86.elfGet hashmaliciousUnknownBrowse
                                                                woega6.elfGet hashmaliciousMiraiBrowse
                                                                  wrjkngh4.elfGet hashmaliciousMiraiBrowse
                                                                    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                    botnetdolly.zapto.orgbot.x86_64.elfGet hashmaliciousMirai, Gafgyt, OkiruBrowse
                                                                    • 160.191.175.187
                                                                    bot.ppc.elfGet hashmaliciousMirai, Gafgyt, OkiruBrowse
                                                                    • 160.191.175.187
                                                                    bot.mpsl.elfGet hashmaliciousMirai, Gafgyt, OkiruBrowse
                                                                    • 160.191.175.187
                                                                    bot.mips.elfGet hashmaliciousMirai, Gafgyt, OkiruBrowse
                                                                    • 160.191.175.187
                                                                    bot.arm5.elfGet hashmaliciousMirai, Gafgyt, OkiruBrowse
                                                                    • 160.191.175.187
                                                                    bot.arm7.elfGet hashmaliciousMirai, OkiruBrowse
                                                                    • 160.191.175.187
                                                                    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                    CANONICAL-ASGBbot.x86_64.elfGet hashmaliciousMirai, Gafgyt, OkiruBrowse
                                                                    • 91.189.91.42
                                                                    bot.ppc.elfGet hashmaliciousMirai, Gafgyt, OkiruBrowse
                                                                    • 91.189.91.42
                                                                    x86.elfGet hashmaliciousMiraiBrowse
                                                                    • 91.189.91.42
                                                                    45.95.169.120-mips-2025-01-02T00_17_36.elfGet hashmaliciousMiraiBrowse
                                                                    • 91.189.91.42
                                                                    bot.mpsl.elfGet hashmaliciousMirai, Gafgyt, OkiruBrowse
                                                                    • 91.189.91.42
                                                                    bot.mips.elfGet hashmaliciousMirai, Gafgyt, OkiruBrowse
                                                                    • 91.189.91.42
                                                                    bot.arm5.elfGet hashmaliciousMirai, Gafgyt, OkiruBrowse
                                                                    • 185.125.190.26
                                                                    bot.arm7.elfGet hashmaliciousMirai, OkiruBrowse
                                                                    • 91.189.91.42
                                                                    earm5.elfGet hashmaliciousUnknownBrowse
                                                                    • 185.125.190.26
                                                                    x86.elfGet hashmaliciousUnknownBrowse
                                                                    • 91.189.91.42
                                                                    CANONICAL-ASGBbot.x86_64.elfGet hashmaliciousMirai, Gafgyt, OkiruBrowse
                                                                    • 91.189.91.42
                                                                    bot.ppc.elfGet hashmaliciousMirai, Gafgyt, OkiruBrowse
                                                                    • 91.189.91.42
                                                                    x86.elfGet hashmaliciousMiraiBrowse
                                                                    • 91.189.91.42
                                                                    45.95.169.120-mips-2025-01-02T00_17_36.elfGet hashmaliciousMiraiBrowse
                                                                    • 91.189.91.42
                                                                    bot.mpsl.elfGet hashmaliciousMirai, Gafgyt, OkiruBrowse
                                                                    • 91.189.91.42
                                                                    bot.mips.elfGet hashmaliciousMirai, Gafgyt, OkiruBrowse
                                                                    • 91.189.91.42
                                                                    bot.arm5.elfGet hashmaliciousMirai, Gafgyt, OkiruBrowse
                                                                    • 185.125.190.26
                                                                    bot.arm7.elfGet hashmaliciousMirai, OkiruBrowse
                                                                    • 91.189.91.42
                                                                    earm5.elfGet hashmaliciousUnknownBrowse
                                                                    • 185.125.190.26
                                                                    x86.elfGet hashmaliciousUnknownBrowse
                                                                    • 91.189.91.42
                                                                    SINET-ASResearchOrganizationofInformationandSystemsNbot.x86_64.elfGet hashmaliciousMirai, Gafgyt, OkiruBrowse
                                                                    • 160.191.175.187
                                                                    bot.ppc.elfGet hashmaliciousMirai, Gafgyt, OkiruBrowse
                                                                    • 160.191.175.187
                                                                    bot.mpsl.elfGet hashmaliciousMirai, Gafgyt, OkiruBrowse
                                                                    • 160.191.175.187
                                                                    bot.mips.elfGet hashmaliciousMirai, Gafgyt, OkiruBrowse
                                                                    • 160.191.175.187
                                                                    bot.arm5.elfGet hashmaliciousMirai, Gafgyt, OkiruBrowse
                                                                    • 160.191.175.187
                                                                    bot.arm7.elfGet hashmaliciousMirai, OkiruBrowse
                                                                    • 160.191.175.187
                                                                    loligang.mips.elfGet hashmaliciousMiraiBrowse
                                                                    • 150.86.9.143
                                                                    loligang.x86.elfGet hashmaliciousMiraiBrowse
                                                                    • 133.220.199.235
                                                                    kwari.ppc.elfGet hashmaliciousUnknownBrowse
                                                                    • 163.54.130.99
                                                                    kwari.mpsl.elfGet hashmaliciousUnknownBrowse
                                                                    • 202.245.170.205
                                                                    INIT7CHbot.x86_64.elfGet hashmaliciousMirai, Gafgyt, OkiruBrowse
                                                                    • 109.202.202.202
                                                                    bot.ppc.elfGet hashmaliciousMirai, Gafgyt, OkiruBrowse
                                                                    • 109.202.202.202
                                                                    x86.elfGet hashmaliciousMiraiBrowse
                                                                    • 109.202.202.202
                                                                    45.95.169.120-mips-2025-01-02T00_17_36.elfGet hashmaliciousMiraiBrowse
                                                                    • 109.202.202.202
                                                                    bot.mpsl.elfGet hashmaliciousMirai, Gafgyt, OkiruBrowse
                                                                    • 109.202.202.202
                                                                    bot.mips.elfGet hashmaliciousMirai, Gafgyt, OkiruBrowse
                                                                    • 109.202.202.202
                                                                    bot.arm7.elfGet hashmaliciousMirai, OkiruBrowse
                                                                    • 109.202.202.202
                                                                    x86.elfGet hashmaliciousUnknownBrowse
                                                                    • 109.202.202.202
                                                                    woega6.elfGet hashmaliciousMiraiBrowse
                                                                    • 109.202.202.202
                                                                    wrjkngh4.elfGet hashmaliciousMiraiBrowse
                                                                    • 109.202.202.202
                                                                    No context
                                                                    No context
                                                                    No created / dropped files found
                                                                    File type:ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, stripped
                                                                    Entropy (8bit):5.714966505237118
                                                                    TrID:
                                                                    • ELF Executable and Linkable format (Linux) (4029/14) 50.16%
                                                                    • ELF Executable and Linkable format (generic) (4004/1) 49.84%
                                                                    File name:bot.x86.elf
                                                                    File size:89'576 bytes
                                                                    MD5:dd71487c78fb3cc5ab09c350a01d28f7
                                                                    SHA1:ab30dae9842cfe912461b1fa1a098247babe8e28
                                                                    SHA256:f3928fd942a8d5e9b9ffaa98e0722903f936eb895a0934ad3a24fe5a4a7495f8
                                                                    SHA512:ac5e285f1d20f498e7536997349f718d895239d6d4361ac2e97f362dad78abc4dda855fe20b8b306816ca47fa7b9e097ae1157540fb5fb75245563b89af9182e
                                                                    SSDEEP:1536:xpmWc2AcighsZ82fJxfcUHH1mSsM8y6Q+gBQ9TnkISGtAdy0xZ:xpmX2riED2frf7HVmL1Q1Q9kVTy0x
                                                                    TLSH:DC936CC5F683D4F5E89304B1613AEB339B33F0B52019EA43D7799932ECA1511EA16B6C
                                                                    File Content Preview:.ELF....................d...4...X\......4. ...(......................................................G..8...........Q.td............................U..S........$...h........[]...$.............U......= ....t..5...................u........t....h............

                                                                    ELF header

                                                                    Class:ELF32
                                                                    Data:2's complement, little endian
                                                                    Version:1 (current)
                                                                    Machine:Intel 80386
                                                                    Version Number:0x1
                                                                    Type:EXEC (Executable file)
                                                                    OS/ABI:UNIX - System V
                                                                    ABI Version:0
                                                                    Entry Point Address:0x8048164
                                                                    Flags:0x0
                                                                    ELF Header Size:52
                                                                    Program Header Offset:52
                                                                    Program Header Size:32
                                                                    Number of Program Headers:3
                                                                    Section Header Offset:89176
                                                                    Section Header Size:40
                                                                    Number of Section Headers:10
                                                                    Header String Table Index:9
                                                                    NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                                                    NULL0x00x00x00x00x0000
                                                                    .initPROGBITS0x80480940x940x1c0x00x6AX001
                                                                    .textPROGBITS0x80480b00xb00xf1360x00x6AX0016
                                                                    .finiPROGBITS0x80571e60xf1e60x170x00x6AX001
                                                                    .rodataPROGBITS0x80572000xf2000x22900x00x2A0032
                                                                    .ctorsPROGBITS0x805a4940x114940xc0x00x3WA004
                                                                    .dtorsPROGBITS0x805a4a00x114a00x80x00x3WA004
                                                                    .dataPROGBITS0x805a4c00x114c00x47580x00x3WA0032
                                                                    .bssNOBITS0x805ec200x15c180x49ac0x00x3WA0032
                                                                    .shstrtabSTRTAB0x00x15c180x3e0x00x0001
                                                                    TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                                    LOAD0x00x80480000x80480000x114900x114906.58860x5R E0x1000.init .text .fini .rodata
                                                                    LOAD0x114940x805a4940x805a4940x47840x91380.36430x6RW 0x1000.ctors .dtors .data .bss
                                                                    GNU_STACK0x00x00x00x00x00.00000x6RW 0x4
                                                                    TimestampSIDSignatureSeveritySource IPSource PortDest IPDest PortProtocol
                                                                    2025-01-02T02:51:49.224916+01002030490ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)1192.168.2.2351750160.191.175.18743957TCP
                                                                    2025-01-02T02:51:54.078810+01002030490ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)1192.168.2.2351752160.191.175.18743957TCP
                                                                    2025-01-02T02:52:04.946028+01002030490ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)1192.168.2.2351754160.191.175.18743957TCP
                                                                    2025-01-02T02:52:08.790763+01002030490ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)1192.168.2.2351756160.191.175.18743957TCP
                                                                    2025-01-02T02:52:19.653054+01002030490ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)1192.168.2.2351758160.191.175.18743957TCP
                                                                    2025-01-02T02:52:23.512886+01002030490ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)1192.168.2.2351760160.191.175.18743957TCP
                                                                    2025-01-02T02:52:27.401265+01002030490ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)1192.168.2.2351762160.191.175.18743957TCP
                                                                    2025-01-02T02:52:31.256623+01002030490ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)1192.168.2.2351764160.191.175.18743957TCP
                                                                    2025-01-02T02:52:33.094730+01002030490ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)1192.168.2.2351766160.191.175.18743957TCP
                                                                    2025-01-02T02:52:36.948372+01002030490ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)1192.168.2.2351768160.191.175.18743957TCP
                                                                    2025-01-02T02:52:44.823225+01002030490ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)1192.168.2.2351770160.191.175.18743957TCP
                                                                    2025-01-02T02:52:53.662268+01002030490ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)1192.168.2.2351772160.191.175.18743957TCP
                                                                    2025-01-02T02:53:02.521685+01002030490ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)1192.168.2.2351774160.191.175.18743957TCP
                                                                    2025-01-02T02:53:10.373177+01002030490ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)1192.168.2.2351776160.191.175.18743957TCP
                                                                    2025-01-02T02:53:21.221830+01002030490ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)1192.168.2.2351778160.191.175.18743957TCP
                                                                    2025-01-02T02:53:23.116860+01002030490ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)1192.168.2.2351780160.191.175.18743957TCP
                                                                    2025-01-02T02:53:29.968975+01002030490ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)1192.168.2.2351782160.191.175.18743957TCP
                                                                    2025-01-02T02:53:36.850192+01002030490ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)1192.168.2.2351784160.191.175.18743957TCP
                                                                    2025-01-02T02:53:45.701356+01002030490ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)1192.168.2.2351786160.191.175.18743957TCP
                                                                    2025-01-02T02:53:50.547752+01002030490ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)1192.168.2.2351788160.191.175.18743957TCP
                                                                    TimestampSource PortDest PortSource IPDest IP
                                                                    Jan 2, 2025 02:51:49.220005035 CET5175043957192.168.2.23160.191.175.187
                                                                    Jan 2, 2025 02:51:49.224838972 CET4395751750160.191.175.187192.168.2.23
                                                                    Jan 2, 2025 02:51:49.224884987 CET5175043957192.168.2.23160.191.175.187
                                                                    Jan 2, 2025 02:51:49.224915981 CET5175043957192.168.2.23160.191.175.187
                                                                    Jan 2, 2025 02:51:49.229682922 CET4395751750160.191.175.187192.168.2.23
                                                                    Jan 2, 2025 02:51:50.065045118 CET4395751750160.191.175.187192.168.2.23
                                                                    Jan 2, 2025 02:51:50.065104961 CET5175043957192.168.2.23160.191.175.187
                                                                    Jan 2, 2025 02:51:50.069895029 CET4395751750160.191.175.187192.168.2.23
                                                                    Jan 2, 2025 02:51:51.478696108 CET43928443192.168.2.2391.189.91.42
                                                                    Jan 2, 2025 02:51:54.074001074 CET5175243957192.168.2.23160.191.175.187
                                                                    Jan 2, 2025 02:51:54.078746080 CET4395751752160.191.175.187192.168.2.23
                                                                    Jan 2, 2025 02:51:54.078809977 CET5175243957192.168.2.23160.191.175.187
                                                                    Jan 2, 2025 02:51:54.078809977 CET5175243957192.168.2.23160.191.175.187
                                                                    Jan 2, 2025 02:51:54.083591938 CET4395751752160.191.175.187192.168.2.23
                                                                    Jan 2, 2025 02:51:54.915374041 CET4395751752160.191.175.187192.168.2.23
                                                                    Jan 2, 2025 02:51:54.918735027 CET5175243957192.168.2.23160.191.175.187
                                                                    Jan 2, 2025 02:51:54.923533916 CET4395751752160.191.175.187192.168.2.23
                                                                    Jan 2, 2025 02:51:56.854101896 CET42836443192.168.2.2391.189.91.43
                                                                    Jan 2, 2025 02:51:58.389748096 CET4251680192.168.2.23109.202.202.202
                                                                    Jan 2, 2025 02:52:04.941149950 CET5175443957192.168.2.23160.191.175.187
                                                                    Jan 2, 2025 02:52:04.945950031 CET4395751754160.191.175.187192.168.2.23
                                                                    Jan 2, 2025 02:52:04.946002960 CET5175443957192.168.2.23160.191.175.187
                                                                    Jan 2, 2025 02:52:04.946027994 CET5175443957192.168.2.23160.191.175.187
                                                                    Jan 2, 2025 02:52:04.950820923 CET4395751754160.191.175.187192.168.2.23
                                                                    Jan 2, 2025 02:52:05.777779102 CET4395751754160.191.175.187192.168.2.23
                                                                    Jan 2, 2025 02:52:05.778067112 CET5175443957192.168.2.23160.191.175.187
                                                                    Jan 2, 2025 02:52:05.782869101 CET4395751754160.191.175.187192.168.2.23
                                                                    Jan 2, 2025 02:52:08.785846949 CET5175643957192.168.2.23160.191.175.187
                                                                    Jan 2, 2025 02:52:08.790667057 CET4395751756160.191.175.187192.168.2.23
                                                                    Jan 2, 2025 02:52:08.790714025 CET5175643957192.168.2.23160.191.175.187
                                                                    Jan 2, 2025 02:52:08.790762901 CET5175643957192.168.2.23160.191.175.187
                                                                    Jan 2, 2025 02:52:08.795567989 CET4395751756160.191.175.187192.168.2.23
                                                                    Jan 2, 2025 02:52:09.641000986 CET4395751756160.191.175.187192.168.2.23
                                                                    Jan 2, 2025 02:52:09.641103029 CET5175643957192.168.2.23160.191.175.187
                                                                    Jan 2, 2025 02:52:09.646066904 CET4395751756160.191.175.187192.168.2.23
                                                                    Jan 2, 2025 02:52:11.699856997 CET43928443192.168.2.2391.189.91.42
                                                                    Jan 2, 2025 02:52:19.648143053 CET5175843957192.168.2.23160.191.175.187
                                                                    Jan 2, 2025 02:52:19.652976036 CET4395751758160.191.175.187192.168.2.23
                                                                    Jan 2, 2025 02:52:19.653033018 CET5175843957192.168.2.23160.191.175.187
                                                                    Jan 2, 2025 02:52:19.653053999 CET5175843957192.168.2.23160.191.175.187
                                                                    Jan 2, 2025 02:52:19.657846928 CET4395751758160.191.175.187192.168.2.23
                                                                    Jan 2, 2025 02:52:20.498334885 CET4395751758160.191.175.187192.168.2.23
                                                                    Jan 2, 2025 02:52:20.498420954 CET5175843957192.168.2.23160.191.175.187
                                                                    Jan 2, 2025 02:52:20.503166914 CET4395751758160.191.175.187192.168.2.23
                                                                    Jan 2, 2025 02:52:23.507982016 CET5176043957192.168.2.23160.191.175.187
                                                                    Jan 2, 2025 02:52:23.512814999 CET4395751760160.191.175.187192.168.2.23
                                                                    Jan 2, 2025 02:52:23.512860060 CET5176043957192.168.2.23160.191.175.187
                                                                    Jan 2, 2025 02:52:23.512886047 CET5176043957192.168.2.23160.191.175.187
                                                                    Jan 2, 2025 02:52:23.517648935 CET4395751760160.191.175.187192.168.2.23
                                                                    Jan 2, 2025 02:52:23.986109018 CET42836443192.168.2.2391.189.91.43
                                                                    Jan 2, 2025 02:52:24.387521982 CET4395751760160.191.175.187192.168.2.23
                                                                    Jan 2, 2025 02:52:24.387820005 CET5176043957192.168.2.23160.191.175.187
                                                                    Jan 2, 2025 02:52:24.392651081 CET4395751760160.191.175.187192.168.2.23
                                                                    Jan 2, 2025 02:52:27.396363974 CET5176243957192.168.2.23160.191.175.187
                                                                    Jan 2, 2025 02:52:27.401104927 CET4395751762160.191.175.187192.168.2.23
                                                                    Jan 2, 2025 02:52:27.401164055 CET5176243957192.168.2.23160.191.175.187
                                                                    Jan 2, 2025 02:52:27.401264906 CET5176243957192.168.2.23160.191.175.187
                                                                    Jan 2, 2025 02:52:27.406060934 CET4395751762160.191.175.187192.168.2.23
                                                                    Jan 2, 2025 02:52:28.081530094 CET4251680192.168.2.23109.202.202.202
                                                                    Jan 2, 2025 02:52:28.243118048 CET4395751762160.191.175.187192.168.2.23
                                                                    Jan 2, 2025 02:52:28.243376017 CET5176243957192.168.2.23160.191.175.187
                                                                    Jan 2, 2025 02:52:28.248099089 CET4395751762160.191.175.187192.168.2.23
                                                                    Jan 2, 2025 02:52:31.251648903 CET5176443957192.168.2.23160.191.175.187
                                                                    Jan 2, 2025 02:52:31.256529093 CET4395751764160.191.175.187192.168.2.23
                                                                    Jan 2, 2025 02:52:31.256623030 CET5176443957192.168.2.23160.191.175.187
                                                                    Jan 2, 2025 02:52:31.256623030 CET5176443957192.168.2.23160.191.175.187
                                                                    Jan 2, 2025 02:52:31.261398077 CET4395751764160.191.175.187192.168.2.23
                                                                    Jan 2, 2025 02:52:32.080945969 CET4395751764160.191.175.187192.168.2.23
                                                                    Jan 2, 2025 02:52:32.081043959 CET5176443957192.168.2.23160.191.175.187
                                                                    Jan 2, 2025 02:52:32.085905075 CET4395751764160.191.175.187192.168.2.23
                                                                    Jan 2, 2025 02:52:33.089726925 CET5176643957192.168.2.23160.191.175.187
                                                                    Jan 2, 2025 02:52:33.094605923 CET4395751766160.191.175.187192.168.2.23
                                                                    Jan 2, 2025 02:52:33.094686031 CET5176643957192.168.2.23160.191.175.187
                                                                    Jan 2, 2025 02:52:33.094729900 CET5176643957192.168.2.23160.191.175.187
                                                                    Jan 2, 2025 02:52:33.099456072 CET4395751766160.191.175.187192.168.2.23
                                                                    Jan 2, 2025 02:52:33.933235884 CET4395751766160.191.175.187192.168.2.23
                                                                    Jan 2, 2025 02:52:33.933408022 CET5176643957192.168.2.23160.191.175.187
                                                                    Jan 2, 2025 02:52:33.938251972 CET4395751766160.191.175.187192.168.2.23
                                                                    Jan 2, 2025 02:52:36.943564892 CET5176843957192.168.2.23160.191.175.187
                                                                    Jan 2, 2025 02:52:36.948312044 CET4395751768160.191.175.187192.168.2.23
                                                                    Jan 2, 2025 02:52:36.948359966 CET5176843957192.168.2.23160.191.175.187
                                                                    Jan 2, 2025 02:52:36.948371887 CET5176843957192.168.2.23160.191.175.187
                                                                    Jan 2, 2025 02:52:36.953190088 CET4395751768160.191.175.187192.168.2.23
                                                                    Jan 2, 2025 02:52:37.779728889 CET4395751768160.191.175.187192.168.2.23
                                                                    Jan 2, 2025 02:52:37.779835939 CET5176843957192.168.2.23160.191.175.187
                                                                    Jan 2, 2025 02:52:37.784632921 CET4395751768160.191.175.187192.168.2.23
                                                                    Jan 2, 2025 02:52:44.818279982 CET5177043957192.168.2.23160.191.175.187
                                                                    Jan 2, 2025 02:52:44.823122025 CET4395751770160.191.175.187192.168.2.23
                                                                    Jan 2, 2025 02:52:44.823189020 CET5177043957192.168.2.23160.191.175.187
                                                                    Jan 2, 2025 02:52:44.823225021 CET5177043957192.168.2.23160.191.175.187
                                                                    Jan 2, 2025 02:52:44.827971935 CET4395751770160.191.175.187192.168.2.23
                                                                    Jan 2, 2025 02:52:45.648361921 CET4395751770160.191.175.187192.168.2.23
                                                                    Jan 2, 2025 02:52:45.648509979 CET5177043957192.168.2.23160.191.175.187
                                                                    Jan 2, 2025 02:52:45.653367043 CET4395751770160.191.175.187192.168.2.23
                                                                    Jan 2, 2025 02:52:52.654113054 CET43928443192.168.2.2391.189.91.42
                                                                    Jan 2, 2025 02:52:53.657371998 CET5177243957192.168.2.23160.191.175.187
                                                                    Jan 2, 2025 02:52:53.662203074 CET4395751772160.191.175.187192.168.2.23
                                                                    Jan 2, 2025 02:52:53.662250996 CET5177243957192.168.2.23160.191.175.187
                                                                    Jan 2, 2025 02:52:53.662267923 CET5177243957192.168.2.23160.191.175.187
                                                                    Jan 2, 2025 02:52:53.667074919 CET4395751772160.191.175.187192.168.2.23
                                                                    Jan 2, 2025 02:52:54.508245945 CET4395751772160.191.175.187192.168.2.23
                                                                    Jan 2, 2025 02:52:54.508548021 CET5177243957192.168.2.23160.191.175.187
                                                                    Jan 2, 2025 02:52:54.513340950 CET4395751772160.191.175.187192.168.2.23
                                                                    Jan 2, 2025 02:53:02.516602993 CET5177443957192.168.2.23160.191.175.187
                                                                    Jan 2, 2025 02:53:02.521538973 CET4395751774160.191.175.187192.168.2.23
                                                                    Jan 2, 2025 02:53:02.521631956 CET5177443957192.168.2.23160.191.175.187
                                                                    Jan 2, 2025 02:53:02.521684885 CET5177443957192.168.2.23160.191.175.187
                                                                    Jan 2, 2025 02:53:02.526470900 CET4395751774160.191.175.187192.168.2.23
                                                                    Jan 2, 2025 02:53:03.360812902 CET4395751774160.191.175.187192.168.2.23
                                                                    Jan 2, 2025 02:53:03.360925913 CET5177443957192.168.2.23160.191.175.187
                                                                    Jan 2, 2025 02:53:03.365776062 CET4395751774160.191.175.187192.168.2.23
                                                                    Jan 2, 2025 02:53:10.368294001 CET5177643957192.168.2.23160.191.175.187
                                                                    Jan 2, 2025 02:53:10.373099089 CET4395751776160.191.175.187192.168.2.23
                                                                    Jan 2, 2025 02:53:10.373164892 CET5177643957192.168.2.23160.191.175.187
                                                                    Jan 2, 2025 02:53:10.373177052 CET5177643957192.168.2.23160.191.175.187
                                                                    Jan 2, 2025 02:53:10.378046989 CET4395751776160.191.175.187192.168.2.23
                                                                    Jan 2, 2025 02:53:11.210091114 CET4395751776160.191.175.187192.168.2.23
                                                                    Jan 2, 2025 02:53:11.210211039 CET5177643957192.168.2.23160.191.175.187
                                                                    Jan 2, 2025 02:53:11.214988947 CET4395751776160.191.175.187192.168.2.23
                                                                    Jan 2, 2025 02:53:21.216835976 CET5177843957192.168.2.23160.191.175.187
                                                                    Jan 2, 2025 02:53:21.221765995 CET4395751778160.191.175.187192.168.2.23
                                                                    Jan 2, 2025 02:53:21.221817017 CET5177843957192.168.2.23160.191.175.187
                                                                    Jan 2, 2025 02:53:21.221829891 CET5177843957192.168.2.23160.191.175.187
                                                                    Jan 2, 2025 02:53:21.226666927 CET4395751778160.191.175.187192.168.2.23
                                                                    Jan 2, 2025 02:53:22.078203917 CET4395751778160.191.175.187192.168.2.23
                                                                    Jan 2, 2025 02:53:22.078337908 CET5177843957192.168.2.23160.191.175.187
                                                                    Jan 2, 2025 02:53:22.083268881 CET4395751778160.191.175.187192.168.2.23
                                                                    Jan 2, 2025 02:53:23.111851931 CET5178043957192.168.2.23160.191.175.187
                                                                    Jan 2, 2025 02:53:23.116733074 CET4395751780160.191.175.187192.168.2.23
                                                                    Jan 2, 2025 02:53:23.116821051 CET5178043957192.168.2.23160.191.175.187
                                                                    Jan 2, 2025 02:53:23.116859913 CET5178043957192.168.2.23160.191.175.187
                                                                    Jan 2, 2025 02:53:23.121699095 CET4395751780160.191.175.187192.168.2.23
                                                                    Jan 2, 2025 02:53:23.956180096 CET4395751780160.191.175.187192.168.2.23
                                                                    Jan 2, 2025 02:53:23.956315994 CET5178043957192.168.2.23160.191.175.187
                                                                    Jan 2, 2025 02:53:23.961219072 CET4395751780160.191.175.187192.168.2.23
                                                                    Jan 2, 2025 02:53:29.963987112 CET5178243957192.168.2.23160.191.175.187
                                                                    Jan 2, 2025 02:53:29.968858957 CET4395751782160.191.175.187192.168.2.23
                                                                    Jan 2, 2025 02:53:29.968934059 CET5178243957192.168.2.23160.191.175.187
                                                                    Jan 2, 2025 02:53:29.968975067 CET5178243957192.168.2.23160.191.175.187
                                                                    Jan 2, 2025 02:53:29.973790884 CET4395751782160.191.175.187192.168.2.23
                                                                    Jan 2, 2025 02:53:30.805890083 CET4395751782160.191.175.187192.168.2.23
                                                                    Jan 2, 2025 02:53:30.806154013 CET5178243957192.168.2.23160.191.175.187
                                                                    Jan 2, 2025 02:53:30.811041117 CET4395751782160.191.175.187192.168.2.23
                                                                    Jan 2, 2025 02:53:36.845248938 CET5178443957192.168.2.23160.191.175.187
                                                                    Jan 2, 2025 02:53:36.850109100 CET4395751784160.191.175.187192.168.2.23
                                                                    Jan 2, 2025 02:53:36.850169897 CET5178443957192.168.2.23160.191.175.187
                                                                    Jan 2, 2025 02:53:36.850192070 CET5178443957192.168.2.23160.191.175.187
                                                                    Jan 2, 2025 02:53:36.854933977 CET4395751784160.191.175.187192.168.2.23
                                                                    Jan 2, 2025 02:53:37.688843966 CET4395751784160.191.175.187192.168.2.23
                                                                    Jan 2, 2025 02:53:37.689069033 CET5178443957192.168.2.23160.191.175.187
                                                                    Jan 2, 2025 02:53:37.693866014 CET4395751784160.191.175.187192.168.2.23
                                                                    Jan 2, 2025 02:53:45.696435928 CET5178643957192.168.2.23160.191.175.187
                                                                    Jan 2, 2025 02:53:45.701241970 CET4395751786160.191.175.187192.168.2.23
                                                                    Jan 2, 2025 02:53:45.701344967 CET5178643957192.168.2.23160.191.175.187
                                                                    Jan 2, 2025 02:53:45.701355934 CET5178643957192.168.2.23160.191.175.187
                                                                    Jan 2, 2025 02:53:45.706147909 CET4395751786160.191.175.187192.168.2.23
                                                                    Jan 2, 2025 02:53:46.535331964 CET4395751786160.191.175.187192.168.2.23
                                                                    Jan 2, 2025 02:53:46.535531044 CET5178643957192.168.2.23160.191.175.187
                                                                    Jan 2, 2025 02:53:46.540266991 CET4395751786160.191.175.187192.168.2.23
                                                                    Jan 2, 2025 02:53:50.542784929 CET5178843957192.168.2.23160.191.175.187
                                                                    Jan 2, 2025 02:53:50.547652960 CET4395751788160.191.175.187192.168.2.23
                                                                    Jan 2, 2025 02:53:50.547739029 CET5178843957192.168.2.23160.191.175.187
                                                                    Jan 2, 2025 02:53:50.547751904 CET5178843957192.168.2.23160.191.175.187
                                                                    Jan 2, 2025 02:53:50.552520037 CET4395751788160.191.175.187192.168.2.23
                                                                    Jan 2, 2025 02:53:51.382443905 CET4395751788160.191.175.187192.168.2.23
                                                                    Jan 2, 2025 02:53:51.382539034 CET5178843957192.168.2.23160.191.175.187
                                                                    Jan 2, 2025 02:53:51.387363911 CET4395751788160.191.175.187192.168.2.23
                                                                    TimestampSource PortDest PortSource IPDest IP
                                                                    Jan 2, 2025 02:51:49.213238955 CET3537753192.168.2.238.8.8.8
                                                                    Jan 2, 2025 02:51:49.219904900 CET53353778.8.8.8192.168.2.23
                                                                    Jan 2, 2025 02:51:54.065805912 CET4574153192.168.2.238.8.8.8
                                                                    Jan 2, 2025 02:51:54.073899031 CET53457418.8.8.8192.168.2.23
                                                                    Jan 2, 2025 02:52:04.933830023 CET3883653192.168.2.238.8.8.8
                                                                    Jan 2, 2025 02:52:04.941071987 CET53388368.8.8.8192.168.2.23
                                                                    Jan 2, 2025 02:52:08.778594971 CET4563453192.168.2.238.8.8.8
                                                                    Jan 2, 2025 02:52:08.785763979 CET53456348.8.8.8192.168.2.23
                                                                    Jan 2, 2025 02:52:19.641036987 CET5368653192.168.2.238.8.8.8
                                                                    Jan 2, 2025 02:52:19.648040056 CET53536868.8.8.8192.168.2.23
                                                                    Jan 2, 2025 02:52:23.499186993 CET4227653192.168.2.238.8.8.8
                                                                    Jan 2, 2025 02:52:23.507886887 CET53422768.8.8.8192.168.2.23
                                                                    Jan 2, 2025 02:52:27.388950109 CET4406553192.168.2.238.8.8.8
                                                                    Jan 2, 2025 02:52:27.396205902 CET53440658.8.8.8192.168.2.23
                                                                    Jan 2, 2025 02:52:31.244400024 CET5715853192.168.2.238.8.8.8
                                                                    Jan 2, 2025 02:52:31.251554012 CET53571588.8.8.8192.168.2.23
                                                                    Jan 2, 2025 02:52:33.082129002 CET4097653192.168.2.238.8.8.8
                                                                    Jan 2, 2025 02:52:33.089572906 CET53409768.8.8.8192.168.2.23
                                                                    Jan 2, 2025 02:52:36.934222937 CET4066653192.168.2.238.8.8.8
                                                                    Jan 2, 2025 02:52:36.943468094 CET53406668.8.8.8192.168.2.23
                                                                    Jan 2, 2025 02:52:44.779858112 CET4244653192.168.2.238.8.8.8
                                                                    Jan 2, 2025 02:52:44.818166018 CET53424468.8.8.8192.168.2.23
                                                                    Jan 2, 2025 02:52:53.648458004 CET4590953192.168.2.238.8.8.8
                                                                    Jan 2, 2025 02:52:53.657282114 CET53459098.8.8.8192.168.2.23
                                                                    Jan 2, 2025 02:53:02.509002924 CET4675553192.168.2.238.8.8.8
                                                                    Jan 2, 2025 02:53:02.516439915 CET53467558.8.8.8192.168.2.23
                                                                    Jan 2, 2025 02:53:10.361032963 CET3870753192.168.2.238.8.8.8
                                                                    Jan 2, 2025 02:53:10.368201017 CET53387078.8.8.8192.168.2.23
                                                                    Jan 2, 2025 02:53:21.209739923 CET5076153192.168.2.238.8.8.8
                                                                    Jan 2, 2025 02:53:21.216721058 CET53507618.8.8.8192.168.2.23
                                                                    Jan 2, 2025 02:53:23.079066992 CET5284353192.168.2.238.8.8.8
                                                                    Jan 2, 2025 02:53:23.111716986 CET53528438.8.8.8192.168.2.23
                                                                    Jan 2, 2025 02:53:29.956708908 CET4553853192.168.2.238.8.8.8
                                                                    Jan 2, 2025 02:53:29.963814974 CET53455388.8.8.8192.168.2.23
                                                                    Jan 2, 2025 02:53:36.806510925 CET4835253192.168.2.238.8.8.8
                                                                    Jan 2, 2025 02:53:36.845114946 CET53483528.8.8.8192.168.2.23
                                                                    Jan 2, 2025 02:53:45.689078093 CET5809553192.168.2.238.8.8.8
                                                                    Jan 2, 2025 02:53:45.696310043 CET53580958.8.8.8192.168.2.23
                                                                    Jan 2, 2025 02:53:50.536082983 CET4217553192.168.2.238.8.8.8
                                                                    Jan 2, 2025 02:53:50.542668104 CET53421758.8.8.8192.168.2.23
                                                                    TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                                                    Jan 2, 2025 02:51:49.213238955 CET192.168.2.238.8.8.80x4875Standard query (0)botnetdolly.zapto.orgA (IP address)IN (0x0001)false
                                                                    Jan 2, 2025 02:51:54.065805912 CET192.168.2.238.8.8.80x4a7cStandard query (0)botnetdolly.zapto.orgA (IP address)IN (0x0001)false
                                                                    Jan 2, 2025 02:52:04.933830023 CET192.168.2.238.8.8.80xe2d0Standard query (0)botnetdolly.zapto.orgA (IP address)IN (0x0001)false
                                                                    Jan 2, 2025 02:52:08.778594971 CET192.168.2.238.8.8.80xc49fStandard query (0)botnetdolly.zapto.orgA (IP address)IN (0x0001)false
                                                                    Jan 2, 2025 02:52:19.641036987 CET192.168.2.238.8.8.80x9fdStandard query (0)botnetdolly.zapto.orgA (IP address)IN (0x0001)false
                                                                    Jan 2, 2025 02:52:23.499186993 CET192.168.2.238.8.8.80x1c9eStandard query (0)botnetdolly.zapto.orgA (IP address)IN (0x0001)false
                                                                    Jan 2, 2025 02:52:27.388950109 CET192.168.2.238.8.8.80x26a5Standard query (0)botnetdolly.zapto.orgA (IP address)IN (0x0001)false
                                                                    Jan 2, 2025 02:52:31.244400024 CET192.168.2.238.8.8.80x675dStandard query (0)botnetdolly.zapto.orgA (IP address)IN (0x0001)false
                                                                    Jan 2, 2025 02:52:33.082129002 CET192.168.2.238.8.8.80xbf33Standard query (0)botnetdolly.zapto.orgA (IP address)IN (0x0001)false
                                                                    Jan 2, 2025 02:52:36.934222937 CET192.168.2.238.8.8.80xb05eStandard query (0)botnetdolly.zapto.orgA (IP address)IN (0x0001)false
                                                                    Jan 2, 2025 02:52:44.779858112 CET192.168.2.238.8.8.80x1ed4Standard query (0)botnetdolly.zapto.orgA (IP address)IN (0x0001)false
                                                                    Jan 2, 2025 02:52:53.648458004 CET192.168.2.238.8.8.80xd83aStandard query (0)botnetdolly.zapto.orgA (IP address)IN (0x0001)false
                                                                    Jan 2, 2025 02:53:02.509002924 CET192.168.2.238.8.8.80x1e1dStandard query (0)botnetdolly.zapto.orgA (IP address)IN (0x0001)false
                                                                    Jan 2, 2025 02:53:10.361032963 CET192.168.2.238.8.8.80x4187Standard query (0)botnetdolly.zapto.orgA (IP address)IN (0x0001)false
                                                                    Jan 2, 2025 02:53:21.209739923 CET192.168.2.238.8.8.80x609dStandard query (0)botnetdolly.zapto.orgA (IP address)IN (0x0001)false
                                                                    Jan 2, 2025 02:53:23.079066992 CET192.168.2.238.8.8.80x2283Standard query (0)botnetdolly.zapto.orgA (IP address)IN (0x0001)false
                                                                    Jan 2, 2025 02:53:29.956708908 CET192.168.2.238.8.8.80x538eStandard query (0)botnetdolly.zapto.orgA (IP address)IN (0x0001)false
                                                                    Jan 2, 2025 02:53:36.806510925 CET192.168.2.238.8.8.80x8c31Standard query (0)botnetdolly.zapto.orgA (IP address)IN (0x0001)false
                                                                    Jan 2, 2025 02:53:45.689078093 CET192.168.2.238.8.8.80x6bd0Standard query (0)botnetdolly.zapto.orgA (IP address)IN (0x0001)false
                                                                    Jan 2, 2025 02:53:50.536082983 CET192.168.2.238.8.8.80xb0c6Standard query (0)botnetdolly.zapto.orgA (IP address)IN (0x0001)false
                                                                    TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                                                    Jan 2, 2025 02:51:49.219904900 CET8.8.8.8192.168.2.230x4875No error (0)botnetdolly.zapto.org160.191.175.187A (IP address)IN (0x0001)false
                                                                    Jan 2, 2025 02:51:54.073899031 CET8.8.8.8192.168.2.230x4a7cNo error (0)botnetdolly.zapto.org160.191.175.187A (IP address)IN (0x0001)false
                                                                    Jan 2, 2025 02:52:04.941071987 CET8.8.8.8192.168.2.230xe2d0No error (0)botnetdolly.zapto.org160.191.175.187A (IP address)IN (0x0001)false
                                                                    Jan 2, 2025 02:52:08.785763979 CET8.8.8.8192.168.2.230xc49fNo error (0)botnetdolly.zapto.org160.191.175.187A (IP address)IN (0x0001)false
                                                                    Jan 2, 2025 02:52:19.648040056 CET8.8.8.8192.168.2.230x9fdNo error (0)botnetdolly.zapto.org160.191.175.187A (IP address)IN (0x0001)false
                                                                    Jan 2, 2025 02:52:23.507886887 CET8.8.8.8192.168.2.230x1c9eNo error (0)botnetdolly.zapto.org160.191.175.187A (IP address)IN (0x0001)false
                                                                    Jan 2, 2025 02:52:27.396205902 CET8.8.8.8192.168.2.230x26a5No error (0)botnetdolly.zapto.org160.191.175.187A (IP address)IN (0x0001)false
                                                                    Jan 2, 2025 02:52:31.251554012 CET8.8.8.8192.168.2.230x675dNo error (0)botnetdolly.zapto.org160.191.175.187A (IP address)IN (0x0001)false
                                                                    Jan 2, 2025 02:52:33.089572906 CET8.8.8.8192.168.2.230xbf33No error (0)botnetdolly.zapto.org160.191.175.187A (IP address)IN (0x0001)false
                                                                    Jan 2, 2025 02:52:36.943468094 CET8.8.8.8192.168.2.230xb05eNo error (0)botnetdolly.zapto.org160.191.175.187A (IP address)IN (0x0001)false
                                                                    Jan 2, 2025 02:52:44.818166018 CET8.8.8.8192.168.2.230x1ed4No error (0)botnetdolly.zapto.org160.191.175.187A (IP address)IN (0x0001)false
                                                                    Jan 2, 2025 02:52:53.657282114 CET8.8.8.8192.168.2.230xd83aNo error (0)botnetdolly.zapto.org160.191.175.187A (IP address)IN (0x0001)false
                                                                    Jan 2, 2025 02:53:02.516439915 CET8.8.8.8192.168.2.230x1e1dNo error (0)botnetdolly.zapto.org160.191.175.187A (IP address)IN (0x0001)false
                                                                    Jan 2, 2025 02:53:10.368201017 CET8.8.8.8192.168.2.230x4187No error (0)botnetdolly.zapto.org160.191.175.187A (IP address)IN (0x0001)false
                                                                    Jan 2, 2025 02:53:21.216721058 CET8.8.8.8192.168.2.230x609dNo error (0)botnetdolly.zapto.org160.191.175.187A (IP address)IN (0x0001)false
                                                                    Jan 2, 2025 02:53:23.111716986 CET8.8.8.8192.168.2.230x2283No error (0)botnetdolly.zapto.org160.191.175.187A (IP address)IN (0x0001)false
                                                                    Jan 2, 2025 02:53:29.963814974 CET8.8.8.8192.168.2.230x538eNo error (0)botnetdolly.zapto.org160.191.175.187A (IP address)IN (0x0001)false
                                                                    Jan 2, 2025 02:53:36.845114946 CET8.8.8.8192.168.2.230x8c31No error (0)botnetdolly.zapto.org160.191.175.187A (IP address)IN (0x0001)false
                                                                    Jan 2, 2025 02:53:45.696310043 CET8.8.8.8192.168.2.230x6bd0No error (0)botnetdolly.zapto.org160.191.175.187A (IP address)IN (0x0001)false
                                                                    Jan 2, 2025 02:53:50.542668104 CET8.8.8.8192.168.2.230xb0c6No error (0)botnetdolly.zapto.org160.191.175.187A (IP address)IN (0x0001)false

                                                                    System Behavior

                                                                    Start time (UTC):01:51:48
                                                                    Start date (UTC):02/01/2025
                                                                    Path:/tmp/bot.x86.elf
                                                                    Arguments:/tmp/bot.x86.elf
                                                                    File size:89576 bytes
                                                                    MD5 hash:dd71487c78fb3cc5ab09c350a01d28f7

                                                                    Start time (UTC):01:51:48
                                                                    Start date (UTC):02/01/2025
                                                                    Path:/tmp/bot.x86.elf
                                                                    Arguments:-
                                                                    File size:89576 bytes
                                                                    MD5 hash:dd71487c78fb3cc5ab09c350a01d28f7

                                                                    Start time (UTC):01:51:48
                                                                    Start date (UTC):02/01/2025
                                                                    Path:/tmp/bot.x86.elf
                                                                    Arguments:-
                                                                    File size:89576 bytes
                                                                    MD5 hash:dd71487c78fb3cc5ab09c350a01d28f7