Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
byte.mpsl.elf

Overview

General Information

Sample name:byte.mpsl.elf
Analysis ID:1584296
MD5:a37689908d6fa7fd6656fe40fce39472
SHA1:e4d5e2f18875171f2d194b6daa64c795361aec61
SHA256:112860299121bd6f04f0036948433b4d34e0870ae68ce398c84a6a4b92ebc87e
Tags:elfuser-abuse_ch
Infos:

Detection

Mirai
Score:72
Range:0 - 100
Whitelisted:false

Signatures

Antivirus detection for dropped file
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Yara detected Mirai
Executes the "rm" command used to delete files or directories
HTTP GET or POST without a user agent
Sample has stripped symbol table
Uses the "uname" system call to query kernel version information (possible evasion)
Writes ELF files to disk
Yara signature match

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1584296
Start date and time:2025-01-05 05:32:06 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 36s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:byte.mpsl.elf
Detection:MAL
Classification:mal72.troj.linELF@0/1@0/0
  • Some HTTP raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
Command:/tmp/byte.mpsl.elf
PID:6228
Exit Code:5
Exit Code Info:
Killed:False
Standard Output:
Loadinggg
Downloaddd
Standard Error:
  • system is lnxubuntu20
  • byte.mpsl.elf (PID: 6228, Parent: 6150, MD5: 0d6f61f82cf2f781c6eb0661071d42d9) Arguments: /tmp/byte.mpsl.elf
  • dash New Fork (PID: 6230, Parent: 4331)
  • rm (PID: 6230, Parent: 4331, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.HTSwZ7hgR7 /tmp/tmp.4CrYHjT7GE /tmp/tmp.NAxXVrsEuU
  • dash New Fork (PID: 6231, Parent: 4331)
  • rm (PID: 6231, Parent: 4331, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.HTSwZ7hgR7 /tmp/tmp.4CrYHjT7GE /tmp/tmp.NAxXVrsEuU
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
MiraiMirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese. Nowadays it targets a wide range of networked embedded devices such as IP cameras, home routers (many vendors involved), and other IoT devices. Since the source code was published on "Hack Forums" many variants of the Mirai family appeared, infecting mostly home networks all around the world.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/elf.mirai
SourceRuleDescriptionAuthorStrings
dump.pcapLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0x269bb:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x269cf:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x269e3:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x269f7:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x26a0b:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x26a1f:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x26a33:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x26a47:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x26a5b:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x26a6f:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x26a83:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x26a97:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x26aab:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x26abf:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x26ad3:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x26ae7:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x26afb:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x26b0f:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x26b23:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x26b37:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x26b4b:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
SourceRuleDescriptionAuthorStrings
/tmp/condi72JoeSecurity_Mirai_8Yara detected MiraiJoe Security
    /tmp/condi72Linux_Trojan_Gafgyt_28a2fe0cunknownunknown
    • 0x22e94:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x22ea8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x22ebc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x22ed0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x22ee4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x22ef8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x22f0c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x22f20:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x22f34:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x22f48:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x22f5c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x22f70:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x22f84:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x22f98:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x22fac:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x22fc0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x22fd4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x22fe8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x22ffc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x23010:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x23024:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    No Suricata rule has matched

    Click to jump to signature section

    Show All Signature Results

    AV Detection

    barindex
    Source: /tmp/condi72Avira: detection malicious, Label: EXP/ELF.Mirai.Z.A
    Source: byte.mpsl.elfVirustotal: Detection: 44%Perma Link
    Source: byte.mpsl.elfReversingLabs: Detection: 44%
    Source: global trafficHTTP traffic detected: GET /main_mpsl HTTP/1.0Data Raw: 00 44 6f 77 6e 6c 6f Data Ascii: Downlo
    Source: unknownTCP traffic detected without corresponding DNS query: 185.255.135.104
    Source: unknownTCP traffic detected without corresponding DNS query: 185.255.135.104
    Source: unknownTCP traffic detected without corresponding DNS query: 185.255.135.104
    Source: unknownTCP traffic detected without corresponding DNS query: 54.171.230.55
    Source: unknownTCP traffic detected without corresponding DNS query: 185.255.135.104
    Source: unknownTCP traffic detected without corresponding DNS query: 185.255.135.104
    Source: unknownTCP traffic detected without corresponding DNS query: 185.255.135.104
    Source: unknownTCP traffic detected without corresponding DNS query: 185.255.135.104
    Source: unknownTCP traffic detected without corresponding DNS query: 185.255.135.104
    Source: unknownTCP traffic detected without corresponding DNS query: 185.255.135.104
    Source: unknownTCP traffic detected without corresponding DNS query: 185.255.135.104
    Source: unknownTCP traffic detected without corresponding DNS query: 185.255.135.104
    Source: unknownTCP traffic detected without corresponding DNS query: 185.255.135.104
    Source: unknownTCP traffic detected without corresponding DNS query: 185.255.135.104
    Source: unknownTCP traffic detected without corresponding DNS query: 185.255.135.104
    Source: unknownTCP traffic detected without corresponding DNS query: 185.255.135.104
    Source: unknownTCP traffic detected without corresponding DNS query: 185.255.135.104
    Source: unknownTCP traffic detected without corresponding DNS query: 185.255.135.104
    Source: unknownTCP traffic detected without corresponding DNS query: 185.255.135.104
    Source: unknownTCP traffic detected without corresponding DNS query: 185.255.135.104
    Source: unknownTCP traffic detected without corresponding DNS query: 185.255.135.104
    Source: unknownTCP traffic detected without corresponding DNS query: 185.255.135.104
    Source: unknownTCP traffic detected without corresponding DNS query: 185.255.135.104
    Source: unknownTCP traffic detected without corresponding DNS query: 185.255.135.104
    Source: unknownTCP traffic detected without corresponding DNS query: 185.255.135.104
    Source: unknownTCP traffic detected without corresponding DNS query: 185.255.135.104
    Source: unknownTCP traffic detected without corresponding DNS query: 185.255.135.104
    Source: unknownTCP traffic detected without corresponding DNS query: 185.255.135.104
    Source: unknownTCP traffic detected without corresponding DNS query: 185.255.135.104
    Source: unknownTCP traffic detected without corresponding DNS query: 185.255.135.104
    Source: unknownTCP traffic detected without corresponding DNS query: 185.255.135.104
    Source: unknownTCP traffic detected without corresponding DNS query: 185.255.135.104
    Source: unknownTCP traffic detected without corresponding DNS query: 185.255.135.104
    Source: unknownTCP traffic detected without corresponding DNS query: 185.255.135.104
    Source: unknownTCP traffic detected without corresponding DNS query: 185.255.135.104
    Source: unknownTCP traffic detected without corresponding DNS query: 185.255.135.104
    Source: unknownTCP traffic detected without corresponding DNS query: 185.255.135.104
    Source: unknownTCP traffic detected without corresponding DNS query: 185.255.135.104
    Source: unknownTCP traffic detected without corresponding DNS query: 185.255.135.104
    Source: unknownTCP traffic detected without corresponding DNS query: 185.255.135.104
    Source: unknownTCP traffic detected without corresponding DNS query: 185.255.135.104
    Source: unknownTCP traffic detected without corresponding DNS query: 185.255.135.104
    Source: unknownTCP traffic detected without corresponding DNS query: 185.255.135.104
    Source: unknownTCP traffic detected without corresponding DNS query: 185.255.135.104
    Source: unknownTCP traffic detected without corresponding DNS query: 185.255.135.104
    Source: unknownTCP traffic detected without corresponding DNS query: 185.255.135.104
    Source: unknownTCP traffic detected without corresponding DNS query: 185.255.135.104
    Source: unknownTCP traffic detected without corresponding DNS query: 185.255.135.104
    Source: unknownTCP traffic detected without corresponding DNS query: 185.255.135.104
    Source: unknownTCP traffic detected without corresponding DNS query: 185.255.135.104
    Source: global trafficHTTP traffic detected: GET /main_mpsl HTTP/1.0Data Raw: 00 44 6f 77 6e 6c 6f Data Ascii: Downlo
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 33606
    Source: unknownNetwork traffic detected: HTTP traffic on port 33606 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443

    System Summary

    barindex
    Source: dump.pcap, type: PCAPMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
    Source: /tmp/condi72, type: DROPPEDMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
    Source: ELF static info symbol of initial sample.symtab present: no
    Source: dump.pcap, type: PCAPMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
    Source: /tmp/condi72, type: DROPPEDMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
    Source: classification engineClassification label: mal72.troj.linELF@0/1@0/0
    Source: /usr/bin/dash (PID: 6230)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.HTSwZ7hgR7 /tmp/tmp.4CrYHjT7GE /tmp/tmp.NAxXVrsEuUJump to behavior
    Source: /usr/bin/dash (PID: 6231)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.HTSwZ7hgR7 /tmp/tmp.4CrYHjT7GE /tmp/tmp.NAxXVrsEuUJump to behavior
    Source: /tmp/byte.mpsl.elf (PID: 6228)File written: /tmp/condi72Jump to dropped file
    Source: /tmp/byte.mpsl.elf (PID: 6228)Queries kernel information via 'uname': Jump to behavior
    Source: byte.mpsl.elf, 6228.1.00007ffc0862f000.00007ffc08650000.rw-.sdmpBinary or memory string: Yx86_64/usr/bin/qemu-mipsel/tmp/byte.mpsl.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/byte.mpsl.elf
    Source: byte.mpsl.elf, 6228.1.000056129d43d000.000056129d4c4000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/mipsel
    Source: byte.mpsl.elf, 6228.1.000056129d43d000.000056129d4c4000.rw-.sdmpBinary or memory string: V!/etc/qemu-binfmt/mipsel
    Source: byte.mpsl.elf, 6228.1.00007ffc0862f000.00007ffc08650000.rw-.sdmpBinary or memory string: /usr/bin/qemu-mipsel

    Stealing of Sensitive Information

    barindex
    Source: Yara matchFile source: /tmp/condi72, type: DROPPED

    Remote Access Functionality

    barindex
    Source: Yara matchFile source: /tmp/condi72, type: DROPPED
    ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
    Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception1
    File Deletion
    OS Credential Dumping11
    Security Software Discovery
    Remote ServicesData from Local System1
    Encrypted Channel
    Exfiltration Over Other Network MediumAbuse Accessibility Features
    CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
    Non-Application Layer Protocol
    Exfiltration Over BluetoothNetwork Denial of Service
    Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive2
    Application Layer Protocol
    Automated ExfiltrationData Encrypted for Impact
    Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture1
    Ingress Tool Transfer
    Traffic DuplicationData Destruction
    No configs have been found
    Hide Legend

    Legend:

    • Process
    • Signature
    • Created File
    • DNS/IP Info
    • Is Dropped
    • Number of created Files
    • Is malicious
    • Internet
    SourceDetectionScannerLabelLink
    byte.mpsl.elf44%VirustotalBrowse
    byte.mpsl.elf45%ReversingLabsLinux.Backdoor.Mirai
    SourceDetectionScannerLabelLink
    /tmp/condi72100%AviraEXP/ELF.Mirai.Z.A
    No Antivirus matches
    No Antivirus matches
    No contacted domains info
    • No. of IPs < 25%
    • 25% < No. of IPs < 50%
    • 50% < No. of IPs < 75%
    • 75% < No. of IPs
    IPDomainCountryFlagASNASN NameMalicious
    54.171.230.55
    unknownUnited States
    16509AMAZON-02USfalse
    185.255.135.104
    unknownRussian Federation
    50113SUPERSERVERSDATACENTERRUfalse
    109.202.202.202
    unknownSwitzerland
    13030INIT7CHfalse
    91.189.91.43
    unknownUnited Kingdom
    41231CANONICAL-ASGBfalse
    91.189.91.42
    unknownUnited Kingdom
    41231CANONICAL-ASGBfalse
    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
    54.171.230.55Space.m68k.elfGet hashmaliciousMiraiBrowse
      la.bot.arc.elfGet hashmaliciousMiraiBrowse
        main.arm.elfGet hashmaliciousMiraiBrowse
          i686.elfGet hashmaliciousMiraiBrowse
            Space.x86.elfGet hashmaliciousUnknownBrowse
              Space.m68k.elfGet hashmaliciousUnknownBrowse
                Fantazy.arc.elfGet hashmaliciousUnknownBrowse
                  bot.ppc.elfGet hashmaliciousMirai, Gafgyt, OkiruBrowse
                    ub8ehJSePAfc9FYqZIT6.i686.elfGet hashmaliciousUnknownBrowse
                      154.216.18.23-boatnet.arm7-2025-01-03T11_41_00.elfGet hashmaliciousMiraiBrowse
                        109.202.202.202kpLwzBouH4.elfGet hashmaliciousUnknownBrowse
                        • ch.archive.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_92.0%2bbuild3-0ubuntu0.20.04.1_amd64.deb
                        91.189.91.43main_mips.elfGet hashmaliciousMiraiBrowse
                          i.elfGet hashmaliciousGafgytBrowse
                            sshd.elfGet hashmaliciousUnknownBrowse
                              fenty.arm6.elfGet hashmaliciousMiraiBrowse
                                fenty.arm4.elfGet hashmaliciousMiraiBrowse
                                  Space.m68k.elfGet hashmaliciousMiraiBrowse
                                    armv4eb.elfGet hashmaliciousUnknownBrowse
                                      fenty.arm7.elfGet hashmaliciousMiraiBrowse
                                        Space.x86.elfGet hashmaliciousUnknownBrowse
                                          Space.x86_64.elfGet hashmaliciousUnknownBrowse
                                            No context
                                            MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                            CANONICAL-ASGBmain_mips.elfGet hashmaliciousMiraiBrowse
                                            • 91.189.91.42
                                            i.elfGet hashmaliciousGafgytBrowse
                                            • 91.189.91.42
                                            sshd.elfGet hashmaliciousUnknownBrowse
                                            • 91.189.91.42
                                            fenty.arm6.elfGet hashmaliciousMiraiBrowse
                                            • 91.189.91.42
                                            fenty.arm4.elfGet hashmaliciousMiraiBrowse
                                            • 91.189.91.42
                                            Space.m68k.elfGet hashmaliciousMiraiBrowse
                                            • 91.189.91.42
                                            armv4eb.elfGet hashmaliciousUnknownBrowse
                                            • 91.189.91.42
                                            fenty.arm7.elfGet hashmaliciousMiraiBrowse
                                            • 91.189.91.42
                                            Space.x86.elfGet hashmaliciousUnknownBrowse
                                            • 91.189.91.42
                                            Space.x86_64.elfGet hashmaliciousUnknownBrowse
                                            • 91.189.91.42
                                            AMAZON-02UShttps://bit.ly/3VYGxmhGet hashmaliciousCAPTCHA Scam ClickFix, PhisherBrowse
                                            • 18.245.31.49
                                            Space.m68k.elfGet hashmaliciousMiraiBrowse
                                            • 54.171.230.55
                                            armv5l.elfGet hashmaliciousUnknownBrowse
                                            • 44.255.115.105
                                            la.bot.arc.elfGet hashmaliciousMiraiBrowse
                                            • 54.171.230.55
                                            Yoranis Setup.exeGet hashmaliciousUnknownBrowse
                                            • 45.112.123.126
                                            2.elfGet hashmaliciousUnknownBrowse
                                            • 13.253.163.160
                                            1.elfGet hashmaliciousUnknownBrowse
                                            • 108.158.128.89
                                            main.arm.elfGet hashmaliciousMiraiBrowse
                                            • 54.171.230.55
                                            main.x86.elfGet hashmaliciousMiraiBrowse
                                            • 34.249.145.219
                                            main.mpsl.elfGet hashmaliciousMiraiBrowse
                                            • 34.249.145.219
                                            SUPERSERVERSDATACENTERRUla.bot.mipsel.elfGet hashmaliciousMiraiBrowse
                                            • 185.206.2.20
                                            http://osregist.xyz/tdrig/CNBR.htmlGet hashmaliciousUnknownBrowse
                                            • 185.255.135.223
                                            Clienter.dll.dllGet hashmaliciousUnknownBrowse
                                            • 185.40.4.94
                                            boatnet.sh4.elfGet hashmaliciousMiraiBrowse
                                            • 147.78.65.71
                                            boatnet.spc.elfGet hashmaliciousMiraiBrowse
                                            • 147.78.65.71
                                            boatnet.m68k.elfGet hashmaliciousMiraiBrowse
                                            • 147.78.65.71
                                            boatnet.arm7.elfGet hashmaliciousMiraiBrowse
                                            • 147.78.65.71
                                            boatnet.mips.elfGet hashmaliciousMiraiBrowse
                                            • 147.78.65.71
                                            boatnet.x86.elfGet hashmaliciousMiraiBrowse
                                            • 147.78.65.71
                                            boatnet.mpsl.elfGet hashmaliciousMiraiBrowse
                                            • 147.78.65.71
                                            INIT7CHmain_mips.elfGet hashmaliciousMiraiBrowse
                                            • 109.202.202.202
                                            i.elfGet hashmaliciousGafgytBrowse
                                            • 109.202.202.202
                                            sshd.elfGet hashmaliciousUnknownBrowse
                                            • 109.202.202.202
                                            fenty.arm6.elfGet hashmaliciousMiraiBrowse
                                            • 109.202.202.202
                                            fenty.arm4.elfGet hashmaliciousMiraiBrowse
                                            • 109.202.202.202
                                            Space.m68k.elfGet hashmaliciousMiraiBrowse
                                            • 109.202.202.202
                                            armv4eb.elfGet hashmaliciousUnknownBrowse
                                            • 109.202.202.202
                                            fenty.arm7.elfGet hashmaliciousMiraiBrowse
                                            • 109.202.202.202
                                            Space.x86.elfGet hashmaliciousUnknownBrowse
                                            • 109.202.202.202
                                            Space.x86_64.elfGet hashmaliciousUnknownBrowse
                                            • 109.202.202.202
                                            No context
                                            No context
                                            Process:/tmp/byte.mpsl.elf
                                            File Type:ELF 32-bit LSB executable, MIPS, MIPS-I version 1 (SYSV), statically linked, missing section headers at 173816
                                            Category:dropped
                                            Size (bytes):166777
                                            Entropy (8bit):5.113735935009161
                                            Encrypted:false
                                            SSDEEP:1536:y6YrYSSftdt+XWj4cjIkFPdyu8g84/W/BhUL5SUvSt6GZMjmHogM5EsAdqrq9CIn:yvJSfwXk4uFdZtSaS/e95EVdqS7
                                            MD5:D9E9DC4021953E54B3E9D4A764D27D31
                                            SHA1:0BE9A5D7CD9D1227620BCB0C9C4AA66895BD728B
                                            SHA-256:9AF1D1B9B2CC04AEBD5956463C3E3F5B4C917C7A6BC819FA5DBEFFE6C11984E7
                                            SHA-512:56067B1F190FCA5FD063F35A84444EE7FED127ED82078BC70C9ADD3CB4A72F529CC506AEDCD9B9C9319117774F9EEB4B9BB6E7BF2BBDC79CCBFF7759981860FF
                                            Malicious:true
                                            Yara Hits:
                                            • Rule: JoeSecurity_Mirai_8, Description: Yara detected Mirai, Source: /tmp/condi72, Author: Joe Security
                                            • Rule: Linux_Trojan_Gafgyt_28a2fe0c, Description: unknown, Source: /tmp/condi72, Author: unknown
                                            Antivirus:
                                            • Antivirus: Avira, Detection: 100%
                                            Reputation:low
                                            Preview:.ELF....................`.@.4..........4. ...(...............@...@..P...P...............P...PF..PF..S..............Q.td...............................<|..'!......'.......................<X..'!...$.........9'.. ........................<(..'!... .......p(9'.. ......................... ..'...<...'!......' ........................".......@.............`Q........Y....... ...B$.. .`Q..`Q........Y....... ...B$h.........@....$ ...h......... ..P.$.......$.". ...............(..'...<4..'!......'........ .......`...`....P.$..@..$.. ......................P........@..P.$.. ........... . ..'............ ..'....!..............<...'!...!..............'...$$.....'....T...................$......... ............................<@..'!......'........$......H..$.. ....$....! .....!(.....$.. .!8.....$......C................. ..'H......... ....$...<...'!......'........H......... ....$...<...'!......'0...,...(...$... ...............l...!...!......0H..... ....0....!.@.l......$..p...C...`.....0...,...(...
                                            File type:ELF 32-bit LSB executable, MIPS, MIPS-I version 1 (SYSV), statically linked, stripped
                                            Entropy (8bit):4.773917360859231
                                            TrID:
                                            • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                                            File name:byte.mpsl.elf
                                            File size:2'032 bytes
                                            MD5:a37689908d6fa7fd6656fe40fce39472
                                            SHA1:e4d5e2f18875171f2d194b6daa64c795361aec61
                                            SHA256:112860299121bd6f04f0036948433b4d34e0870ae68ce398c84a6a4b92ebc87e
                                            SHA512:b52b217f6a5a8eef690f24c85d861c8ce2745cf0a1e3f812ac499400e6dd8dbc385027346de99a8aa3ef8383e366cb904b42ed66189b56715f231c27cc2c05fe
                                            SSDEEP:24:WNBj3HsSimpHtFuixVuDa9mG05JJL4mmlZ9ccpe4g+/qc+UTK8WKUlu/eT1R25wW:UQ2jruDS2J6df9ch+SMTLWPkeTnFCXp
                                            TLSH:2E41F0191F901F36DDA6CC36454A2B523ACC842FA16A23926234D9A4BD3F601E7D38A8
                                            File Content Preview:.ELF......................@.4...........4. ...(...............@...@.P...P...............P...P.D.P.D.T...p...........Q.td...........................................0.,...&..% .....0...0% ...2..%0...".....0.......0.....6..%.C.%0......%.F....<T..'!...\...!(.

                                            ELF header

                                            Class:ELF32
                                            Data:2's complement, little endian
                                            Version:1 (current)
                                            Machine:MIPS R3000
                                            Version Number:0x1
                                            Type:EXEC (Executable file)
                                            OS/ABI:UNIX - System V
                                            ABI Version:0
                                            Entry Point Address:0x4004e4
                                            Flags:0x1007
                                            ELF Header Size:52
                                            Program Header Offset:52
                                            Program Header Size:32
                                            Number of Program Headers:3
                                            Section Header Offset:1752
                                            Section Header Size:40
                                            Number of Section Headers:7
                                            Header String Table Index:6
                                            NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                            NULL0x00x00x00x00x0000
                                            .textPROGBITS0x4000a00xa00x5600x00x6AX0016
                                            .rodataPROGBITS0x4006000x6000x500x10x32AMS004
                                            .gotPROGBITS0x4406500x6500x540x40x10000003WAp0016
                                            .bssNOBITS0x4406b00x6a40x100x00x3WA0016
                                            .mdebug.abi32PROGBITS0x480x6a40x00x00x0001
                                            .shstrtabSTRTAB0x00x6a40x310x00x0001
                                            TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                            LOAD0x00x4000000x4000000x6500x6505.08510x5R E0x10000.text .rodata
                                            LOAD0x6500x4406500x4406500x540x702.63630x6RW 0x10000.got .bss
                                            GNU_STACK0x00x00x00x00x00.00000x7RWE0x4
                                            TimestampSource PortDest PortSource IPDest IP
                                            Jan 5, 2025 05:32:48.743464947 CET4229880192.168.2.23185.255.135.104
                                            Jan 5, 2025 05:32:48.748312950 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:48.748397112 CET4229880192.168.2.23185.255.135.104
                                            Jan 5, 2025 05:32:48.749491930 CET4229880192.168.2.23185.255.135.104
                                            Jan 5, 2025 05:32:48.755487919 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:49.374778986 CET4433360654.171.230.55192.168.2.23
                                            Jan 5, 2025 05:32:49.375068903 CET33606443192.168.2.2354.171.230.55
                                            Jan 5, 2025 05:32:49.379918098 CET4433360654.171.230.55192.168.2.23
                                            Jan 5, 2025 05:32:49.419259071 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:49.419271946 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:49.419289112 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:49.419300079 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:49.419318914 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:49.419353008 CET4229880192.168.2.23185.255.135.104
                                            Jan 5, 2025 05:32:49.419369936 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:49.419373035 CET4229880192.168.2.23185.255.135.104
                                            Jan 5, 2025 05:32:49.419373035 CET4229880192.168.2.23185.255.135.104
                                            Jan 5, 2025 05:32:49.419379950 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:49.419414997 CET4229880192.168.2.23185.255.135.104
                                            Jan 5, 2025 05:32:49.419414997 CET4229880192.168.2.23185.255.135.104
                                            Jan 5, 2025 05:32:49.419416904 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:49.419426918 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:49.419437885 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:49.419454098 CET4229880192.168.2.23185.255.135.104
                                            Jan 5, 2025 05:32:49.419454098 CET4229880192.168.2.23185.255.135.104
                                            Jan 5, 2025 05:32:49.419466019 CET4229880192.168.2.23185.255.135.104
                                            Jan 5, 2025 05:32:49.424182892 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:49.424200058 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:49.424226046 CET4229880192.168.2.23185.255.135.104
                                            Jan 5, 2025 05:32:49.424226046 CET4229880192.168.2.23185.255.135.104
                                            Jan 5, 2025 05:32:49.424407959 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:49.424446106 CET4229880192.168.2.23185.255.135.104
                                            Jan 5, 2025 05:32:49.424451113 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:49.424479008 CET4229880192.168.2.23185.255.135.104
                                            Jan 5, 2025 05:32:49.505979061 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:49.506019115 CET4229880192.168.2.23185.255.135.104
                                            Jan 5, 2025 05:32:49.533183098 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:49.533217907 CET4229880192.168.2.23185.255.135.104
                                            Jan 5, 2025 05:32:49.533224106 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:49.533262014 CET4229880192.168.2.23185.255.135.104
                                            Jan 5, 2025 05:32:49.533340931 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:49.533359051 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:49.533369064 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:49.533385038 CET4229880192.168.2.23185.255.135.104
                                            Jan 5, 2025 05:32:49.533607960 CET4229880192.168.2.23185.255.135.104
                                            Jan 5, 2025 05:32:49.533709049 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:49.533719063 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:49.533729076 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:49.534086943 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:49.534096956 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:49.534106970 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:49.534216881 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:49.534226894 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:49.534235954 CET4229880192.168.2.23185.255.135.104
                                            Jan 5, 2025 05:32:49.534784079 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:49.534794092 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:49.534806013 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:49.534849882 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:49.534859896 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:49.534859896 CET4229880192.168.2.23185.255.135.104
                                            Jan 5, 2025 05:32:49.534873009 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:49.535502911 CET4229880192.168.2.23185.255.135.104
                                            Jan 5, 2025 05:32:49.535753012 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:49.535763025 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:49.535773039 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:49.535860062 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:49.535870075 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:49.535878897 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:49.536137104 CET4229880192.168.2.23185.255.135.104
                                            Jan 5, 2025 05:32:49.620011091 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:49.620022058 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:49.620870113 CET4229880192.168.2.23185.255.135.104
                                            Jan 5, 2025 05:32:49.647377968 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:49.647397041 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:49.647406101 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:49.647500992 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:49.647547960 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:49.647558928 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:49.647620916 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:49.647893906 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:49.647912025 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:49.647922039 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:49.648053885 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:49.648063898 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:49.648403883 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:49.648458958 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:49.648468971 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:49.648565054 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:49.648575068 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:49.648585081 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:49.648595095 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:49.648849010 CET4229880192.168.2.23185.255.135.104
                                            Jan 5, 2025 05:32:49.649209976 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:49.649221897 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:49.649231911 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:49.650379896 CET4229880192.168.2.23185.255.135.104
                                            Jan 5, 2025 05:32:49.653700113 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:49.653709888 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:49.653719902 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:49.655015945 CET4229880192.168.2.23185.255.135.104
                                            Jan 5, 2025 05:32:49.770140886 CET4229880192.168.2.23185.255.135.104
                                            Jan 5, 2025 05:32:49.775170088 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:49.775181055 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:49.775191069 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:49.775235891 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:49.775244951 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:49.775254965 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:49.775265932 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:49.775295973 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:49.775347948 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:49.775579929 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:49.775590897 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:49.775602102 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:49.775640965 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:49.775650978 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:49.775660038 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:49.776288033 CET4229880192.168.2.23185.255.135.104
                                            Jan 5, 2025 05:32:49.991661072 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:49.991705894 CET4229880192.168.2.23185.255.135.104
                                            Jan 5, 2025 05:32:50.008517027 CET4229880192.168.2.23185.255.135.104
                                            Jan 5, 2025 05:32:50.013272047 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:50.013314009 CET4229880192.168.2.23185.255.135.104
                                            Jan 5, 2025 05:32:50.013319969 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:50.013330936 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:50.013417006 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:50.013427973 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:50.013438940 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:50.013556957 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:50.013566971 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:50.013576031 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:50.013765097 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:50.013881922 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:50.013891935 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:50.014084101 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:50.014094114 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:50.014105082 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:50.014230967 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:50.014242887 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:50.014251947 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:50.014655113 CET4229880192.168.2.23185.255.135.104
                                            Jan 5, 2025 05:32:50.227686882 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:50.227727890 CET4229880192.168.2.23185.255.135.104
                                            Jan 5, 2025 05:32:50.248898029 CET4229880192.168.2.23185.255.135.104
                                            Jan 5, 2025 05:32:50.253669024 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:50.253742933 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:50.253752947 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:50.254173040 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:50.254206896 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:50.254218102 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:50.255079031 CET4229880192.168.2.23185.255.135.104
                                            Jan 5, 2025 05:32:50.255099058 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:50.255156040 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:50.255168915 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:50.256151915 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:50.256162882 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:50.256172895 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:50.256611109 CET4229880192.168.2.23185.255.135.104
                                            Jan 5, 2025 05:32:50.257066011 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:50.257076979 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:50.257087946 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:50.257951975 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:50.257961988 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:50.258131027 CET4229880192.168.2.23185.255.135.104
                                            Jan 5, 2025 05:32:50.259860992 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:50.259907007 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:50.261236906 CET4229880192.168.2.23185.255.135.104
                                            Jan 5, 2025 05:32:50.261431932 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:50.261445999 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:50.262788057 CET4229880192.168.2.23185.255.135.104
                                            Jan 5, 2025 05:32:50.475675106 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:50.475717068 CET4229880192.168.2.23185.255.135.104
                                            Jan 5, 2025 05:32:50.495173931 CET4229880192.168.2.23185.255.135.104
                                            Jan 5, 2025 05:32:50.500017881 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:50.500202894 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:50.500242949 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:50.500252962 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:50.501113892 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:50.501180887 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:50.501190901 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:50.501215935 CET4229880192.168.2.23185.255.135.104
                                            Jan 5, 2025 05:32:50.502043962 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:50.502091885 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:50.502101898 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:50.502744913 CET4229880192.168.2.23185.255.135.104
                                            Jan 5, 2025 05:32:50.503010035 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:50.503026962 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:50.503038883 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:50.504272938 CET4229880192.168.2.23185.255.135.104
                                            Jan 5, 2025 05:32:50.506036043 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:50.506047010 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:50.507299900 CET4229880192.168.2.23185.255.135.104
                                            Jan 5, 2025 05:32:50.727668047 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:50.727714062 CET4229880192.168.2.23185.255.135.104
                                            Jan 5, 2025 05:32:50.946695089 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:50.946749926 CET4229880192.168.2.23185.255.135.104
                                            Jan 5, 2025 05:32:50.987905979 CET4229880192.168.2.23185.255.135.104
                                            Jan 5, 2025 05:32:50.992719889 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:50.992742062 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:50.992767096 CET4229880192.168.2.23185.255.135.104
                                            Jan 5, 2025 05:32:50.992791891 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:50.993143082 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:50.993213892 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:50.993225098 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:50.994066954 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:50.994077921 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:50.994092941 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:50.994719028 CET4229880192.168.2.23185.255.135.104
                                            Jan 5, 2025 05:32:50.994894981 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:50.994904995 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:50.994915009 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:50.997020006 CET4229880192.168.2.23185.255.135.104
                                            Jan 5, 2025 05:32:51.027977943 CET43928443192.168.2.2391.189.91.42
                                            Jan 5, 2025 05:32:52.160074949 CET4229880192.168.2.23185.255.135.104
                                            Jan 5, 2025 05:32:52.164952040 CET8042298185.255.135.104192.168.2.23
                                            Jan 5, 2025 05:32:56.659285069 CET42836443192.168.2.2391.189.91.43
                                            Jan 5, 2025 05:32:58.195022106 CET4251680192.168.2.23109.202.202.202
                                            Jan 5, 2025 05:33:11.505269051 CET43928443192.168.2.2391.189.91.42
                                            Jan 5, 2025 05:33:23.791507959 CET42836443192.168.2.2391.189.91.43
                                            Jan 5, 2025 05:33:27.886975050 CET4251680192.168.2.23109.202.202.202
                                            Jan 5, 2025 05:33:52.459657907 CET43928443192.168.2.2391.189.91.42
                                            Session IDSource IPSource PortDestination IPDestination Port
                                            0192.168.2.2342298185.255.135.10480
                                            TimestampBytes transferredDirectionData
                                            Jan 5, 2025 05:32:48.749491930 CET46OUTGET /main_mpsl HTTP/1.0
                                            Data Raw: 00 44 6f 77 6e 6c 6f
                                            Data Ascii: Downlo
                                            Jan 5, 2025 05:32:49.419259071 CET1236INHTTP/1.1 200 OK
                                            Date: Sun, 05 Jan 2025 04:32:49 GMT
                                            Server: Apache/2.4.6 (CentOS)
                                            Last-Modified: Thu, 02 Jan 2025 08:25:43 GMT
                                            ETag: "2a720-62ab4e87cff6d"
                                            Accept-Ranges: bytes
                                            Content-Length: 173856
                                            Connection: close
                                            Data Raw: 7f 45 4c 46 01 01 01 00 00 00 00 00 00 00 00 00 02 00 08 00 01 00 00 00 60 02 40 00 34 00 00 00 f0 a4 02 00 07 10 00 00 34 00 20 00 03 00 28 00 0e 00 0d 00 01 00 00 00 00 00 00 00 00 00 40 00 00 00 40 00 d0 50 02 00 d0 50 02 00 05 00 00 00 00 00 01 00 01 00 00 00 d4 50 02 00 d4 50 46 00 d4 50 46 00 b8 53 00 00 8c ab 00 00 06 00 00 00 00 00 01 00 51 e5 74 64 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 07 00 00 00 04 00 00 00 07 00 1c 3c 7c 1a 9c 27 21 e0 99 03 e0 ff bd 27 10 00 bc af 1c 00 bf af 18 00 bc af 01 00 11 04 00 00 00 00 07 00 1c 3c 58 1a 9c 27 21 e0 9f 03 24 80 99 8f 00 00 00 00 dc 01 39 27 09 f8 20 03 00 00 00 00 10 00 bc 8f 00 00 00 00 01 00 11 04 00 00 00 00 07 00 1c 3c 28 1a 9c 27 21 e0 9f 03 20 80 99 8f 00 00 00 00 70 28 39 27 09 f8 20 03 00 00 00 00 10 00 bc 8f 00 00 00 00 1c 00 bf 8f 00 00 00 00 08 00 e0 03 20 00 bd 27 07 00 1c 3c f0 19 9c 27 21 e0 99 03 d8 ff bd 27 20 00 bf af 1c 00 b1 af 18 00 b0 af 10 00 bc af 18 80 91 8f 00 00 00 00 e0 a4 22 92 00 00 00 00 1d 00 [TRUNCATED]
                                            Data Ascii: ELF`@44 (@@PPPPFPFSQtd<|'!'<X'!$9' <('! p(9' '<'!' "@`QY B$ `Q`QY B$h@$ h P$$" ('<4'!' ``P$@$ P@P$ ' '!<'!!'$$'T$ <@'!'$H$ $! !($ !8$C 'H $<'!'H $<'!'0,($ l!!0H 0!@l$pC`0,(
                                            Jan 5, 2025 05:32:49.419271946 CET1236INData Raw: 00 b4 8f 24 00 b3 8f 20 00 b2 8f 1c 00 b1 8f 18 00 b0 8f 08 00 e0 03 38 00 bd 27 6c 85 99 8f 00 00 00 00 09 f8 20 03 00 00 00 00 10 00 bc 8f 21 18 40 00 38 86 82 8f 15 00 70 10 00 00 43 ac 17 00 60 14 00 00 00 00 d8 87 99 8f 00 00 00 00 09 f8 20
                                            Data Ascii: $ 8'l !@8pC` ! ! @ $H ! FCdQ!($d
                                            Jan 5, 2025 05:32:49.419289112 CET1236INData Raw: 88 99 8f 21 28 60 02 21 30 20 02 21 20 40 00 83 ff 40 10 c0 b0 15 00 09 f8 20 03 00 00 00 00 0c 00 42 92 23 20 91 02 21 28 33 02 2b 10 a2 02 10 00 bc 8f fe ff 94 24 02 00 b3 24 c9 ff 40 10 ff ff 86 24 0b 00 80 10 00 00 00 00 10 00 42 8e 00 00 a3
                                            Data Ascii: !(`!0 ! @@ B# !(3+$$@$B!C+@DD QSd $`! !R&D&@! @ rD ! O$<x'
                                            Jan 5, 2025 05:32:49.419300079 CET720INData Raw: 00 84 24 00 00 71 ac 00 00 42 ae 00 00 04 a2 08 00 05 24 09 f8 20 03 01 00 04 24 10 00 bc 8f 00 00 05 92 74 87 83 8f 21 88 40 00 00 00 44 8e b0 85 99 8f 0a 00 02 24 80 28 05 00 00 00 23 ae 04 00 22 a2 09 f8 20 03 04 00 a5 24 00 00 04 92 10 00 bc
                                            Data Ascii: $qB$ $t!@D$(#" $!b$Bq$ $('<'!P'0! `$0 !! !(
                                            Jan 5, 2025 05:32:49.419318914 CET1236INData Raw: 30 00 00 00 02 07 24 09 f8 20 03 21 90 40 00 18 00 bc 8f 21 20 00 02 14 84 99 8f 21 28 20 02 01 00 06 24 01 00 07 24 09 f8 20 03 40 00 a2 af 18 00 bc 8f 00 16 02 00 84 86 83 8f 4c 88 99 8f 00 00 67 8c 03 16 02 00 21 20 00 02 21 28 20 02 19 00 06
                                            Data Ascii: 0$ !@! !( $$ @Lg! !( $ <8$$ $$jPTD$$T !($ 'XP322e` X@&&`(B$hD-1Q2
                                            Jan 5, 2025 05:32:49.419369936 CET248INData Raw: 21 03 00 c0 18 03 00 23 20 83 00 21 20 89 00 00 ff 03 32 14 00 86 90 02 2a 05 00 00 26 10 00 00 1a 03 00 02 86 10 00 25 18 64 00 25 80 05 02 25 80 03 02 06 10 c2 00 21 80 02 02 ff 00 02 3c 24 18 02 02 00 ff 02 32 02 1a 03 00 00 26 10 00 00 12 02
                                            Data Ascii: !# ! 2*&%d%%!<$2&%%D8%$b0d 4"d "d "d hBd
                                            Jan 5, 2025 05:32:49.419379950 CET1236INData Raw: 85 99 8f 00 00 00 00 09 f8 20 03 00 00 00 00 64 00 a9 8f 18 00 bc 8f 87 ff 30 15 04 00 42 ae 64 85 99 8f 00 00 00 00 09 f8 20 03 00 00 00 00 18 00 bc 8f 08 00 42 ae 3c 00 a2 8f 00 00 00 00 81 ff 40 10 00 00 00 00 fc 85 99 8f 40 00 a5 8f 09 f8 20
                                            Data Ascii: d0Bd B<@@ ($&zXT '@@(B$6`t$72<\'!p'|xt
                                            Jan 5, 2025 05:32:49.419416904 CET248INData Raw: ff 04 24 24 10 44 00 05 00 42 34 18 00 02 ae 54 00 a2 8f 10 00 03 ae 01 00 22 a2 50 00 a2 8f 34 00 a3 8f 30 00 a4 8f 08 00 22 a2 02 00 23 a6 4c 00 a3 8f 00 00 00 00 03 00 60 10 04 00 24 a6 40 00 04 24 06 00 24 a6 11 00 02 24 09 f8 20 03 09 00 22
                                            Data Ascii: $$DB4T"P40"#L`$@$$$ "C$"@@'#X ! |xtplh'HHB$4c$`d ! @#
                                            Jan 5, 2025 05:32:49.419426918 CET1236INData Raw: 10 43 00 94 00 a3 8f 00 00 00 00 21 28 43 00 80 18 04 00 5c 00 a4 8f 14 00 a2 90 21 18 64 00 00 00 71 8c 20 00 42 2c 18 00 32 26 4c 00 40 14 2c 00 33 26 58 00 a3 8f ff ff 02 24 6e 00 62 10 00 00 00 00 ff ff 10 34 72 00 f0 12 00 00 00 00 7b 00 d0
                                            Data Ascii: C!(C\!dq B,2&L@,3&X$nb4r{@"BD@! $ ! @"$ @B<f`! @!(` ` @!#
                                            Jan 5, 2025 05:32:49.419437885 CET1236INData Raw: f8 20 03 48 00 a2 af 18 00 bc 8f 21 28 00 02 14 84 99 8f 21 20 20 02 0f 00 06 24 01 00 07 24 09 f8 20 03 44 00 a2 af 18 00 bc 8f 21 28 00 02 14 84 99 8f 21 20 20 02 10 00 06 24 21 38 00 00 09 f8 20 03 21 f0 40 00 18 00 bc 8f 21 90 40 00 84 86 82
                                            Data Ascii: H!(! $$ D!(! $!8 !@!@LG!(! $0$$ $$wP!@D$$ ! !($ 'eP2P224` L
                                            Jan 5, 2025 05:32:49.424182892 CET1236INData Raw: 40 07 24 20 00 a3 8f 18 00 bc 8f 01 00 64 24 2a 10 93 00 b6 ff 40 14 20 00 a4 af af ff 60 1a 00 00 00 00 b0 ff 00 10 20 00 a0 af 64 85 99 8f 10 00 b0 8c 09 f8 20 03 00 00 00 00 20 00 a3 8f 24 28 1e 02 40 21 03 00 c0 18 03 00 23 20 83 00 a4 00 a3
                                            Data Ascii: @$ d$*@ ` d $(@!# *! 2&%d%%!$2&%D%0%$0d 4"d "


                                            System Behavior

                                            Start time (UTC):04:32:47
                                            Start date (UTC):05/01/2025
                                            Path:/tmp/byte.mpsl.elf
                                            Arguments:/tmp/byte.mpsl.elf
                                            File size:5773336 bytes
                                            MD5 hash:0d6f61f82cf2f781c6eb0661071d42d9

                                            Start time (UTC):04:32:48
                                            Start date (UTC):05/01/2025
                                            Path:/usr/bin/dash
                                            Arguments:-
                                            File size:129816 bytes
                                            MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                            Start time (UTC):04:32:48
                                            Start date (UTC):05/01/2025
                                            Path:/usr/bin/rm
                                            Arguments:rm -f /tmp/tmp.HTSwZ7hgR7 /tmp/tmp.4CrYHjT7GE /tmp/tmp.NAxXVrsEuU
                                            File size:72056 bytes
                                            MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b

                                            Start time (UTC):04:32:48
                                            Start date (UTC):05/01/2025
                                            Path:/usr/bin/dash
                                            Arguments:-
                                            File size:129816 bytes
                                            MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                            Start time (UTC):04:32:48
                                            Start date (UTC):05/01/2025
                                            Path:/usr/bin/rm
                                            Arguments:rm -f /tmp/tmp.HTSwZ7hgR7 /tmp/tmp.4CrYHjT7GE /tmp/tmp.NAxXVrsEuU
                                            File size:72056 bytes
                                            MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b