Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
mips.elf

Overview

General Information

Sample name:mips.elf
Analysis ID:1588724
MD5:c53e038457ee218f315120be3489cae9
SHA1:976012615c17ad70ce109901891850968c77fb0d
SHA256:769d08e769b7b87b75a05b81417754daf74f19dbce2292e4c9906f16c1e744fa
Tags:elfuser-abuse_ch
Infos:

Detection

Score:56
Range:0 - 100
Whitelisted:false

Signatures

Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Detected TCP or UDP traffic on non-standard ports
Executes the "rm" command used to delete files or directories
Sample has stripped symbol table
Sample listens on a socket
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Uses the "uname" system call to query kernel version information (possible evasion)
Yara signature match

Classification

Joe Sandbox version:42.0.0 Malachite
Analysis ID:1588724
Start date and time:2025-01-11 04:41:33 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 28s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:mips.elf
Detection:MAL
Classification:mal56.linELF@0/0@0/0
Command:/tmp/mips.elf
PID:5443
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
wormbot
Standard Error:
  • system is lnxubuntu20
  • dash New Fork (PID: 5411, Parent: 3578)
  • rm (PID: 5411, Parent: 3578, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.zyqSxPi4y6 /tmp/tmp.Ugs7kCUs5l /tmp/tmp.0AzLUvd8vZ
  • dash New Fork (PID: 5412, Parent: 3578)
  • rm (PID: 5412, Parent: 3578, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.zyqSxPi4y6 /tmp/tmp.Ugs7kCUs5l /tmp/tmp.0AzLUvd8vZ
  • mips.elf (PID: 5443, Parent: 5344, MD5: 0083f1f0e77be34ad27f849842bbb00c) Arguments: /tmp/mips.elf
    • mips.elf New Fork (PID: 5445, Parent: 5443)
  • cleanup
SourceRuleDescriptionAuthorStrings
mips.elfLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0xfcfc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xfd10:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xfd24:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xfd38:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xfd4c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xfd60:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xfd74:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xfd88:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xfd9c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xfdb0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xfdc4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xfdd8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xfdec:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xfe00:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xfe14:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xfe28:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xfe3c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xfe50:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xfe64:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xfe78:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xfe8c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
SourceRuleDescriptionAuthorStrings
5443.1.00007fa884400000.00007fa884411000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0xfcfc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xfd10:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xfd24:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xfd38:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xfd4c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xfd60:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xfd74:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xfd88:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xfd9c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xfdb0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xfdc4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xfdd8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xfdec:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xfe00:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xfe14:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xfe28:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xfe3c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xfe50:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xfe64:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xfe78:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xfe8c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
Process Memory Space: mips.elf PID: 5443Linux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0x370:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x384:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x398:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3ac:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3c0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3d4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3e8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3fc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x410:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x424:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x438:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x44c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x460:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x474:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x488:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x49c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x4b0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x4c4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x4d8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x4ec:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x500:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: mips.elfReversingLabs: Detection: 26%
Source: mips.elfVirustotal: Detection: 26%Perma Link
Source: global trafficTCP traffic: 192.168.2.13:45926 -> 85.239.34.134:999
Source: /tmp/mips.elf (PID: 5443)Socket: 127.0.0.1:7567Jump to behavior
Source: global trafficTCP traffic: 192.168.2.13:48202 -> 185.125.190.26:443
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 185.125.190.26
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownNetwork traffic detected: HTTP traffic on port 48202 -> 443

System Summary

barindex
Source: mips.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: 5443.1.00007fa884400000.00007fa884411000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: Process Memory Space: mips.elf PID: 5443, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: ELF static info symbol of initial sample.symtab present: no
Source: mips.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: 5443.1.00007fa884400000.00007fa884411000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: Process Memory Space: mips.elf PID: 5443, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: classification engineClassification label: mal56.linELF@0/0@0/0
Source: /usr/bin/dash (PID: 5411)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.zyqSxPi4y6 /tmp/tmp.Ugs7kCUs5l /tmp/tmp.0AzLUvd8vZJump to behavior
Source: /usr/bin/dash (PID: 5412)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.zyqSxPi4y6 /tmp/tmp.Ugs7kCUs5l /tmp/tmp.0AzLUvd8vZJump to behavior
Source: /tmp/mips.elf (PID: 5443)Queries kernel information via 'uname': Jump to behavior
Source: mips.elf, 5443.1.00007fffcb73c000.00007fffcb75d000.rw-.sdmpBinary or memory string: m8x86_64/usr/bin/qemu-mips/tmp/mips.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/mips.elf
Source: mips.elf, 5443.1.0000561041e9d000.0000561041f24000.rw-.sdmpBinary or memory string: V!/etc/qemu-binfmt/mips
Source: mips.elf, 5443.1.0000561041e9d000.0000561041f24000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/mips
Source: mips.elf, 5443.1.00007fffcb73c000.00007fffcb75d000.rw-.sdmpBinary or memory string: /usr/bin/qemu-mips
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception1
File Deletion
OS Credential Dumping11
Security Software Discovery
Remote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Non-Standard Port
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
mips.elf26%ReversingLabsLinux.Trojan.Mirai
mips.elf26%VirustotalBrowse
No Antivirus matches
No Antivirus matches
No Antivirus matches
No contacted domains info
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs
IPDomainCountryFlagASNASN NameMalicious
85.239.34.134
unknownRussian Federation
134121RAINBOW-HKRainbownetworklimitedHKfalse
185.125.190.26
unknownUnited Kingdom
41231CANONICAL-ASGBfalse
MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
85.239.34.134spc.elfGet hashmaliciousUnknownBrowse
    x86.elfGet hashmaliciousUnknownBrowse
      arm.elfGet hashmaliciousUnknownBrowse
        arm7.elfGet hashmaliciousMiraiBrowse
          arm.elfGet hashmaliciousUnknownBrowse
            arm7.elfGet hashmaliciousUnknownBrowse
              x86.elfGet hashmaliciousUnknownBrowse
                154.216.17.162-arm-2025-01-09T02_53_12.elfGet hashmaliciousUnknownBrowse
                  ppc.elfGet hashmaliciousUnknownBrowse
                    x86.elfGet hashmaliciousUnknownBrowse
                      185.125.190.26boatnet.arm7.elfGet hashmaliciousUnknownBrowse
                        boatnet.m68k.elfGet hashmaliciousUnknownBrowse
                          ssh.elfGet hashmaliciousGafgytBrowse
                            gnjqwpc.elfGet hashmaliciousUnknownBrowse
                              Space.arm6.elfGet hashmaliciousUnknownBrowse
                                main_sh4.elfGet hashmaliciousMiraiBrowse
                                  fenty.arm4.elfGet hashmaliciousMiraiBrowse
                                    Space.x86.elfGet hashmaliciousUnknownBrowse
                                      boatnet.mpsl.elfGet hashmaliciousMiraiBrowse
                                        wind.arm5.elfGet hashmaliciousMiraiBrowse
                                          No context
                                          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                          RAINBOW-HKRainbownetworklimitedHKspc.elfGet hashmaliciousUnknownBrowse
                                          • 85.239.34.134
                                          x86.elfGet hashmaliciousUnknownBrowse
                                          • 85.239.34.134
                                          arm.elfGet hashmaliciousUnknownBrowse
                                          • 85.239.34.134
                                          arm7.elfGet hashmaliciousMiraiBrowse
                                          • 85.239.34.134
                                          arm.elfGet hashmaliciousUnknownBrowse
                                          • 85.239.34.134
                                          arm7.elfGet hashmaliciousUnknownBrowse
                                          • 85.239.34.134
                                          x86.elfGet hashmaliciousUnknownBrowse
                                          • 85.239.34.134
                                          154.216.17.162-arm-2025-01-09T02_53_12.elfGet hashmaliciousUnknownBrowse
                                          • 85.239.34.134
                                          ppc.elfGet hashmaliciousUnknownBrowse
                                          • 85.239.34.134
                                          x86.elfGet hashmaliciousUnknownBrowse
                                          • 85.239.34.134
                                          CANONICAL-ASGBspc.elfGet hashmaliciousUnknownBrowse
                                          • 91.189.91.42
                                          sse.elfGet hashmaliciousGafgytBrowse
                                          • 91.189.91.42
                                          ssp.elfGet hashmaliciousGafgytBrowse
                                          • 91.189.91.42
                                          2.elfGet hashmaliciousUnknownBrowse
                                          • 91.189.91.42
                                          12.elfGet hashmaliciousUnknownBrowse
                                          • 91.189.91.42
                                          Space.arm.elfGet hashmaliciousMiraiBrowse
                                          • 91.189.91.42
                                          arm.elfGet hashmaliciousUnknownBrowse
                                          • 91.189.91.42
                                          ss.elfGet hashmaliciousGafgytBrowse
                                          • 91.189.91.42
                                          boatnet.arm7.elfGet hashmaliciousUnknownBrowse
                                          • 185.125.190.26
                                          boatnet.x86.elfGet hashmaliciousUnknownBrowse
                                          • 91.189.91.42
                                          No context
                                          No context
                                          No created / dropped files found
                                          File type:ELF 32-bit MSB executable, MIPS, MIPS-I version 1 (SYSV), statically linked, stripped
                                          Entropy (8bit):5.414246201375075
                                          TrID:
                                          • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                                          File name:mips.elf
                                          File size:72'972 bytes
                                          MD5:c53e038457ee218f315120be3489cae9
                                          SHA1:976012615c17ad70ce109901891850968c77fb0d
                                          SHA256:769d08e769b7b87b75a05b81417754daf74f19dbce2292e4c9906f16c1e744fa
                                          SHA512:c0334b2d16ef762041e6c8d51476d3d33d1b10650c2eb26751d10599f71c26aac2c273bc1dce57ad0de51607013a5879307c6301ac5edcdc9f2eac89e80e7881
                                          SSDEEP:768:TeXPD4F4KDYz4rid2Vn/fyLCW6ab4M8+pMdXGlTe3T+XkYqK/Up222TwwBsv5iTg:ldyLCxM4n+OpKXJjENjIZlg
                                          TLSH:4B63D85E6E118F7CF28DC63447B79E2596682BC627D1C081E26CE6102E2175F681FFE8
                                          File Content Preview:.ELF.....................@.....4.........4. ...(.............@...@...........................A...A..... ..9................D.A.D.A.D................dt.Q............................<...'..l...!'.......................<...'..H...!........'9... .............

                                          ELF header

                                          Class:ELF32
                                          Data:2's complement, big endian
                                          Version:1 (current)
                                          Machine:MIPS R3000
                                          Version Number:0x1
                                          Type:EXEC (Executable file)
                                          OS/ABI:UNIX - System V
                                          ABI Version:0
                                          Entry Point Address:0x400290
                                          Flags:0x1007
                                          ELF Header Size:52
                                          Program Header Offset:52
                                          Program Header Size:32
                                          Number of Program Headers:4
                                          Section Header Offset:72332
                                          Section Header Size:40
                                          Number of Section Headers:16
                                          Header String Table Index:15
                                          NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                          NULL0x00x00x00x00x0000
                                          .initPROGBITS0x4000b40xb40x8c0x00x6AX004
                                          .textPROGBITS0x4001400x1400xfa800x00x6AX0016
                                          .finiPROGBITS0x40fbc00xfbc00x5c0x00x6AX004
                                          .rodataPROGBITS0x40fc200xfc200x10d00x00x2A0016
                                          .eh_framePROGBITS0x4110000x110000x440x00x3WA004
                                          .tbssNOBITS0x4110440x110440x80x00x403WAT004
                                          .ctorsPROGBITS0x4110440x110440x80x00x3WA004
                                          .dtorsPROGBITS0x41104c0x1104c0x80x00x3WA004
                                          .jcrPROGBITS0x4110540x110540x40x00x3WA004
                                          .dataPROGBITS0x4110600x110600x3c40x00x3WA0016
                                          .gotPROGBITS0x4114300x114300x5f00x40x10000003WAp0016
                                          .sbssNOBITS0x411a200x11a200x380x00x10000003WAp004
                                          .bssNOBITS0x411a600x11a200x2f200x00x3WA0016
                                          .mdebug.abi32PROGBITS0xb520x11a200x00x00x0001
                                          .shstrtabSTRTAB0x00x11a200x6c0x00x0001
                                          TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                          LOAD0x00x4000000x4000000x10cf00x10cf05.47730x5R E0x1000.init .text .fini .rodata
                                          LOAD0x110000x4110000x4110000xa200x39804.19860x6RW 0x1000.eh_frame .tbss .ctors .dtors .jcr .data .got .sbss .bss
                                          TLS0x110440x4110440x4110440x00x80.00000x4R 0x4.tbss
                                          GNU_STACK0x00x00x00x00x00.00000x7RWE0x4
                                          TimestampSource PortDest PortSource IPDest IP
                                          Jan 11, 2025 04:42:14.455997944 CET45926999192.168.2.1385.239.34.134
                                          Jan 11, 2025 04:42:14.460895061 CET9994592685.239.34.134192.168.2.13
                                          Jan 11, 2025 04:42:14.460988998 CET45926999192.168.2.1385.239.34.134
                                          Jan 11, 2025 04:42:14.461153984 CET45926999192.168.2.1385.239.34.134
                                          Jan 11, 2025 04:42:14.466084957 CET9994592685.239.34.134192.168.2.13
                                          Jan 11, 2025 04:42:14.466135979 CET45926999192.168.2.1385.239.34.134
                                          Jan 11, 2025 04:42:14.471041918 CET9994592685.239.34.134192.168.2.13
                                          Jan 11, 2025 04:42:16.234395027 CET9994592685.239.34.134192.168.2.13
                                          Jan 11, 2025 04:42:16.234829903 CET45926999192.168.2.1385.239.34.134
                                          Jan 11, 2025 04:42:16.239756107 CET9994592685.239.34.134192.168.2.13
                                          Jan 11, 2025 04:42:17.237108946 CET45928999192.168.2.1385.239.34.134
                                          Jan 11, 2025 04:42:17.242043018 CET9994592885.239.34.134192.168.2.13
                                          Jan 11, 2025 04:42:17.242121935 CET45928999192.168.2.1385.239.34.134
                                          Jan 11, 2025 04:42:17.242163897 CET45928999192.168.2.1385.239.34.134
                                          Jan 11, 2025 04:42:17.246993065 CET9994592885.239.34.134192.168.2.13
                                          Jan 11, 2025 04:42:17.247046947 CET45928999192.168.2.1385.239.34.134
                                          Jan 11, 2025 04:42:17.251893997 CET9994592885.239.34.134192.168.2.13
                                          Jan 11, 2025 04:42:19.011693001 CET9994592885.239.34.134192.168.2.13
                                          Jan 11, 2025 04:42:19.012008905 CET45928999192.168.2.1385.239.34.134
                                          Jan 11, 2025 04:42:19.016904116 CET9994592885.239.34.134192.168.2.13
                                          Jan 11, 2025 04:42:20.014631033 CET45930999192.168.2.1385.239.34.134
                                          Jan 11, 2025 04:42:20.019617081 CET9994593085.239.34.134192.168.2.13
                                          Jan 11, 2025 04:42:20.019714117 CET45930999192.168.2.1385.239.34.134
                                          Jan 11, 2025 04:42:20.019757032 CET45930999192.168.2.1385.239.34.134
                                          Jan 11, 2025 04:42:20.024660110 CET9994593085.239.34.134192.168.2.13
                                          Jan 11, 2025 04:42:20.024753094 CET45930999192.168.2.1385.239.34.134
                                          Jan 11, 2025 04:42:20.029624939 CET9994593085.239.34.134192.168.2.13
                                          Jan 11, 2025 04:42:21.806794882 CET9994593085.239.34.134192.168.2.13
                                          Jan 11, 2025 04:42:21.807086945 CET45930999192.168.2.1385.239.34.134
                                          Jan 11, 2025 04:42:21.812005043 CET9994593085.239.34.134192.168.2.13
                                          Jan 11, 2025 04:42:22.809333086 CET45932999192.168.2.1385.239.34.134
                                          Jan 11, 2025 04:42:22.814440012 CET9994593285.239.34.134192.168.2.13
                                          Jan 11, 2025 04:42:22.814532995 CET45932999192.168.2.1385.239.34.134
                                          Jan 11, 2025 04:42:22.814554930 CET45932999192.168.2.1385.239.34.134
                                          Jan 11, 2025 04:42:22.820508003 CET9994593285.239.34.134192.168.2.13
                                          Jan 11, 2025 04:42:22.820585966 CET45932999192.168.2.1385.239.34.134
                                          Jan 11, 2025 04:42:22.825812101 CET9994593285.239.34.134192.168.2.13
                                          Jan 11, 2025 04:42:23.727597952 CET48202443192.168.2.13185.125.190.26
                                          Jan 11, 2025 04:42:24.556734085 CET9994593285.239.34.134192.168.2.13
                                          Jan 11, 2025 04:42:24.557091951 CET45932999192.168.2.1385.239.34.134
                                          Jan 11, 2025 04:42:24.562005997 CET9994593285.239.34.134192.168.2.13
                                          Jan 11, 2025 04:42:25.560167074 CET45934999192.168.2.1385.239.34.134
                                          Jan 11, 2025 04:42:25.564990997 CET9994593485.239.34.134192.168.2.13
                                          Jan 11, 2025 04:42:25.565085888 CET45934999192.168.2.1385.239.34.134
                                          Jan 11, 2025 04:42:25.565143108 CET45934999192.168.2.1385.239.34.134
                                          Jan 11, 2025 04:42:25.569919109 CET9994593485.239.34.134192.168.2.13
                                          Jan 11, 2025 04:42:25.570030928 CET45934999192.168.2.1385.239.34.134
                                          Jan 11, 2025 04:42:25.574784994 CET9994593485.239.34.134192.168.2.13
                                          Jan 11, 2025 04:42:27.306015968 CET9994593485.239.34.134192.168.2.13
                                          Jan 11, 2025 04:42:27.306375980 CET45934999192.168.2.1385.239.34.134
                                          Jan 11, 2025 04:42:27.311299086 CET9994593485.239.34.134192.168.2.13
                                          Jan 11, 2025 04:42:28.308691978 CET45936999192.168.2.1385.239.34.134
                                          Jan 11, 2025 04:42:28.313652039 CET9994593685.239.34.134192.168.2.13
                                          Jan 11, 2025 04:42:28.313767910 CET45936999192.168.2.1385.239.34.134
                                          Jan 11, 2025 04:42:28.313790083 CET45936999192.168.2.1385.239.34.134
                                          Jan 11, 2025 04:42:28.318605900 CET9994593685.239.34.134192.168.2.13
                                          Jan 11, 2025 04:42:28.318675995 CET45936999192.168.2.1385.239.34.134
                                          Jan 11, 2025 04:42:28.323534966 CET9994593685.239.34.134192.168.2.13
                                          Jan 11, 2025 04:42:30.088495970 CET9994593685.239.34.134192.168.2.13
                                          Jan 11, 2025 04:42:30.088913918 CET45936999192.168.2.1385.239.34.134
                                          Jan 11, 2025 04:42:30.093919992 CET9994593685.239.34.134192.168.2.13
                                          Jan 11, 2025 04:42:31.091813087 CET45938999192.168.2.1385.239.34.134
                                          Jan 11, 2025 04:42:31.097088099 CET9994593885.239.34.134192.168.2.13
                                          Jan 11, 2025 04:42:31.097153902 CET45938999192.168.2.1385.239.34.134
                                          Jan 11, 2025 04:42:31.097167969 CET45938999192.168.2.1385.239.34.134
                                          Jan 11, 2025 04:42:31.102560997 CET9994593885.239.34.134192.168.2.13
                                          Jan 11, 2025 04:42:31.102622986 CET45938999192.168.2.1385.239.34.134
                                          Jan 11, 2025 04:42:31.107516050 CET9994593885.239.34.134192.168.2.13
                                          Jan 11, 2025 04:42:32.857709885 CET9994593885.239.34.134192.168.2.13
                                          Jan 11, 2025 04:42:32.858222008 CET45938999192.168.2.1385.239.34.134
                                          Jan 11, 2025 04:42:32.863121033 CET9994593885.239.34.134192.168.2.13
                                          Jan 11, 2025 04:42:33.863717079 CET45940999192.168.2.1385.239.34.134
                                          Jan 11, 2025 04:42:33.868633032 CET9994594085.239.34.134192.168.2.13
                                          Jan 11, 2025 04:42:33.868731022 CET45940999192.168.2.1385.239.34.134
                                          Jan 11, 2025 04:42:33.868731022 CET45940999192.168.2.1385.239.34.134
                                          Jan 11, 2025 04:42:33.873637915 CET9994594085.239.34.134192.168.2.13
                                          Jan 11, 2025 04:42:33.873733044 CET45940999192.168.2.1385.239.34.134
                                          Jan 11, 2025 04:42:33.878532887 CET9994594085.239.34.134192.168.2.13
                                          Jan 11, 2025 04:42:35.653819084 CET9994594085.239.34.134192.168.2.13
                                          Jan 11, 2025 04:42:35.654123068 CET45940999192.168.2.1385.239.34.134
                                          Jan 11, 2025 04:42:35.659086943 CET9994594085.239.34.134192.168.2.13
                                          Jan 11, 2025 04:42:36.656354904 CET45942999192.168.2.1385.239.34.134
                                          Jan 11, 2025 04:42:36.661413908 CET9994594285.239.34.134192.168.2.13
                                          Jan 11, 2025 04:42:36.661498070 CET45942999192.168.2.1385.239.34.134
                                          Jan 11, 2025 04:42:36.661498070 CET45942999192.168.2.1385.239.34.134
                                          Jan 11, 2025 04:42:36.666354895 CET9994594285.239.34.134192.168.2.13
                                          Jan 11, 2025 04:42:36.666454077 CET45942999192.168.2.1385.239.34.134
                                          Jan 11, 2025 04:42:36.671278000 CET9994594285.239.34.134192.168.2.13
                                          Jan 11, 2025 04:42:38.433907986 CET9994594285.239.34.134192.168.2.13
                                          Jan 11, 2025 04:42:38.434257984 CET45942999192.168.2.1385.239.34.134
                                          Jan 11, 2025 04:42:38.439137936 CET9994594285.239.34.134192.168.2.13
                                          Jan 11, 2025 04:42:39.437488079 CET45944999192.168.2.1385.239.34.134
                                          Jan 11, 2025 04:42:39.442451000 CET9994594485.239.34.134192.168.2.13
                                          Jan 11, 2025 04:42:39.442532063 CET45944999192.168.2.1385.239.34.134
                                          Jan 11, 2025 04:42:39.442599058 CET45944999192.168.2.1385.239.34.134
                                          Jan 11, 2025 04:42:39.447453022 CET9994594485.239.34.134192.168.2.13
                                          Jan 11, 2025 04:42:39.447516918 CET45944999192.168.2.1385.239.34.134
                                          Jan 11, 2025 04:42:39.452378988 CET9994594485.239.34.134192.168.2.13
                                          Jan 11, 2025 04:42:41.218930006 CET9994594485.239.34.134192.168.2.13
                                          Jan 11, 2025 04:42:41.219353914 CET45944999192.168.2.1385.239.34.134
                                          Jan 11, 2025 04:42:41.224319935 CET9994594485.239.34.134192.168.2.13
                                          Jan 11, 2025 04:42:42.221239090 CET45946999192.168.2.1385.239.34.134
                                          Jan 11, 2025 04:42:42.226119995 CET9994594685.239.34.134192.168.2.13
                                          Jan 11, 2025 04:42:42.226269960 CET45946999192.168.2.1385.239.34.134
                                          Jan 11, 2025 04:42:42.226269960 CET45946999192.168.2.1385.239.34.134
                                          Jan 11, 2025 04:42:42.231187105 CET9994594685.239.34.134192.168.2.13
                                          Jan 11, 2025 04:42:42.231277943 CET45946999192.168.2.1385.239.34.134
                                          Jan 11, 2025 04:42:42.236183882 CET9994594685.239.34.134192.168.2.13
                                          Jan 11, 2025 04:42:43.983647108 CET9994594685.239.34.134192.168.2.13
                                          Jan 11, 2025 04:42:43.983858109 CET45946999192.168.2.1385.239.34.134
                                          Jan 11, 2025 04:42:43.988722086 CET9994594685.239.34.134192.168.2.13
                                          Jan 11, 2025 04:42:44.986360073 CET45948999192.168.2.1385.239.34.134
                                          Jan 11, 2025 04:42:44.991262913 CET9994594885.239.34.134192.168.2.13
                                          Jan 11, 2025 04:42:44.991343021 CET45948999192.168.2.1385.239.34.134
                                          Jan 11, 2025 04:42:44.991362095 CET45948999192.168.2.1385.239.34.134
                                          Jan 11, 2025 04:42:44.996217012 CET9994594885.239.34.134192.168.2.13
                                          Jan 11, 2025 04:42:44.996278048 CET45948999192.168.2.1385.239.34.134
                                          Jan 11, 2025 04:42:45.001368999 CET9994594885.239.34.134192.168.2.13
                                          Jan 11, 2025 04:42:46.764611006 CET9994594885.239.34.134192.168.2.13
                                          Jan 11, 2025 04:42:46.764882088 CET45948999192.168.2.1385.239.34.134
                                          Jan 11, 2025 04:42:46.769802094 CET9994594885.239.34.134192.168.2.13
                                          Jan 11, 2025 04:42:47.766832113 CET45950999192.168.2.1385.239.34.134
                                          Jan 11, 2025 04:42:47.772413015 CET9994595085.239.34.134192.168.2.13
                                          Jan 11, 2025 04:42:47.772520065 CET45950999192.168.2.1385.239.34.134
                                          Jan 11, 2025 04:42:47.772588968 CET45950999192.168.2.1385.239.34.134
                                          Jan 11, 2025 04:42:47.777446032 CET9994595085.239.34.134192.168.2.13
                                          Jan 11, 2025 04:42:47.777506113 CET45950999192.168.2.1385.239.34.134
                                          Jan 11, 2025 04:42:47.782357931 CET9994595085.239.34.134192.168.2.13
                                          Jan 11, 2025 04:42:49.525719881 CET9994595085.239.34.134192.168.2.13
                                          Jan 11, 2025 04:42:49.526225090 CET45950999192.168.2.1385.239.34.134
                                          Jan 11, 2025 04:42:49.531115055 CET9994595085.239.34.134192.168.2.13
                                          Jan 11, 2025 04:42:50.528023005 CET45952999192.168.2.1385.239.34.134
                                          Jan 11, 2025 04:42:50.532915115 CET9994595285.239.34.134192.168.2.13
                                          Jan 11, 2025 04:42:50.533004045 CET45952999192.168.2.1385.239.34.134
                                          Jan 11, 2025 04:42:50.533070087 CET45952999192.168.2.1385.239.34.134
                                          Jan 11, 2025 04:42:50.537869930 CET9994595285.239.34.134192.168.2.13
                                          Jan 11, 2025 04:42:50.537942886 CET45952999192.168.2.1385.239.34.134
                                          Jan 11, 2025 04:42:50.542748928 CET9994595285.239.34.134192.168.2.13
                                          Jan 11, 2025 04:42:52.320251942 CET9994595285.239.34.134192.168.2.13
                                          Jan 11, 2025 04:42:52.320528984 CET45952999192.168.2.1385.239.34.134
                                          Jan 11, 2025 04:42:52.325367928 CET9994595285.239.34.134192.168.2.13
                                          Jan 11, 2025 04:42:53.322974920 CET45954999192.168.2.1385.239.34.134
                                          Jan 11, 2025 04:42:53.329782963 CET9994595485.239.34.134192.168.2.13
                                          Jan 11, 2025 04:42:53.329915047 CET45954999192.168.2.1385.239.34.134
                                          Jan 11, 2025 04:42:53.329932928 CET45954999192.168.2.1385.239.34.134
                                          Jan 11, 2025 04:42:53.336510897 CET9994595485.239.34.134192.168.2.13
                                          Jan 11, 2025 04:42:53.336570978 CET45954999192.168.2.1385.239.34.134
                                          Jan 11, 2025 04:42:53.343106985 CET9994595485.239.34.134192.168.2.13
                                          Jan 11, 2025 04:42:54.703125000 CET48202443192.168.2.13185.125.190.26
                                          Jan 11, 2025 04:42:55.121525049 CET9994595485.239.34.134192.168.2.13
                                          Jan 11, 2025 04:42:55.121736050 CET45954999192.168.2.1385.239.34.134
                                          Jan 11, 2025 04:42:55.126610041 CET9994595485.239.34.134192.168.2.13
                                          Jan 11, 2025 04:42:56.123752117 CET45956999192.168.2.1385.239.34.134
                                          Jan 11, 2025 04:42:56.128654003 CET9994595685.239.34.134192.168.2.13
                                          Jan 11, 2025 04:42:56.128948927 CET45956999192.168.2.1385.239.34.134
                                          Jan 11, 2025 04:42:56.128948927 CET45956999192.168.2.1385.239.34.134
                                          Jan 11, 2025 04:42:56.133809090 CET9994595685.239.34.134192.168.2.13
                                          Jan 11, 2025 04:42:56.133956909 CET45956999192.168.2.1385.239.34.134
                                          Jan 11, 2025 04:42:56.138818026 CET9994595685.239.34.134192.168.2.13
                                          Jan 11, 2025 04:42:57.885797977 CET9994595685.239.34.134192.168.2.13
                                          Jan 11, 2025 04:42:57.886022091 CET45956999192.168.2.1385.239.34.134
                                          Jan 11, 2025 04:42:57.890815973 CET9994595685.239.34.134192.168.2.13
                                          Jan 11, 2025 04:42:58.887934923 CET45958999192.168.2.1385.239.34.134
                                          Jan 11, 2025 04:42:58.892987967 CET9994595885.239.34.134192.168.2.13
                                          Jan 11, 2025 04:42:58.893157959 CET45958999192.168.2.1385.239.34.134
                                          Jan 11, 2025 04:42:58.893157959 CET45958999192.168.2.1385.239.34.134
                                          Jan 11, 2025 04:42:58.898067951 CET9994595885.239.34.134192.168.2.13
                                          Jan 11, 2025 04:42:58.898169041 CET45958999192.168.2.1385.239.34.134
                                          Jan 11, 2025 04:42:58.903069019 CET9994595885.239.34.134192.168.2.13
                                          Jan 11, 2025 04:43:00.650378942 CET9994595885.239.34.134192.168.2.13
                                          Jan 11, 2025 04:43:00.650676012 CET45958999192.168.2.1385.239.34.134
                                          Jan 11, 2025 04:43:00.655805111 CET9994595885.239.34.134192.168.2.13
                                          Jan 11, 2025 04:43:01.652900934 CET45960999192.168.2.1385.239.34.134
                                          Jan 11, 2025 04:43:01.657783031 CET9994596085.239.34.134192.168.2.13
                                          Jan 11, 2025 04:43:01.657913923 CET45960999192.168.2.1385.239.34.134
                                          Jan 11, 2025 04:43:01.658237934 CET45960999192.168.2.1385.239.34.134
                                          Jan 11, 2025 04:43:01.663068056 CET9994596085.239.34.134192.168.2.13
                                          Jan 11, 2025 04:43:01.663146019 CET45960999192.168.2.1385.239.34.134
                                          Jan 11, 2025 04:43:01.667998075 CET9994596085.239.34.134192.168.2.13
                                          Jan 11, 2025 04:43:11.668243885 CET45960999192.168.2.1385.239.34.134
                                          Jan 11, 2025 04:43:11.673011065 CET9994596085.239.34.134192.168.2.13
                                          Jan 11, 2025 04:43:11.891750097 CET9994596085.239.34.134192.168.2.13
                                          Jan 11, 2025 04:43:11.891911030 CET45960999192.168.2.1385.239.34.134
                                          Jan 11, 2025 04:43:46.488090992 CET9994596085.239.34.134192.168.2.13
                                          Jan 11, 2025 04:43:46.488423109 CET45960999192.168.2.1385.239.34.134
                                          Jan 11, 2025 04:43:46.493258953 CET9994596085.239.34.134192.168.2.13
                                          Jan 11, 2025 04:43:47.490744114 CET45962999192.168.2.1385.239.34.134
                                          Jan 11, 2025 04:43:47.495562077 CET9994596285.239.34.134192.168.2.13
                                          Jan 11, 2025 04:43:47.495656013 CET45962999192.168.2.1385.239.34.134
                                          Jan 11, 2025 04:43:47.495728016 CET45962999192.168.2.1385.239.34.134
                                          Jan 11, 2025 04:43:47.500543118 CET9994596285.239.34.134192.168.2.13
                                          Jan 11, 2025 04:43:47.500617027 CET45962999192.168.2.1385.239.34.134
                                          Jan 11, 2025 04:43:47.505377054 CET9994596285.239.34.134192.168.2.13
                                          Jan 11, 2025 04:43:49.260859013 CET9994596285.239.34.134192.168.2.13
                                          Jan 11, 2025 04:43:49.261071920 CET45962999192.168.2.1385.239.34.134
                                          Jan 11, 2025 04:43:49.265872002 CET9994596285.239.34.134192.168.2.13
                                          Jan 11, 2025 04:43:50.262486935 CET45964999192.168.2.1385.239.34.134
                                          Jan 11, 2025 04:43:50.267594099 CET9994596485.239.34.134192.168.2.13
                                          Jan 11, 2025 04:43:50.267654896 CET45964999192.168.2.1385.239.34.134
                                          Jan 11, 2025 04:43:50.267688036 CET45964999192.168.2.1385.239.34.134
                                          Jan 11, 2025 04:43:50.272490025 CET9994596485.239.34.134192.168.2.13
                                          Jan 11, 2025 04:43:50.272555113 CET45964999192.168.2.1385.239.34.134
                                          Jan 11, 2025 04:43:50.277350903 CET9994596485.239.34.134192.168.2.13
                                          Jan 11, 2025 04:44:09.422074080 CET9994596485.239.34.134192.168.2.13
                                          Jan 11, 2025 04:44:09.422475100 CET45964999192.168.2.1385.239.34.134
                                          Jan 11, 2025 04:44:09.427335024 CET9994596485.239.34.134192.168.2.13
                                          Jan 11, 2025 04:44:10.424335003 CET45966999192.168.2.1385.239.34.134
                                          Jan 11, 2025 04:44:10.429198980 CET9994596685.239.34.134192.168.2.13
                                          Jan 11, 2025 04:44:10.429256916 CET45966999192.168.2.1385.239.34.134
                                          Jan 11, 2025 04:44:10.429279089 CET45966999192.168.2.1385.239.34.134
                                          Jan 11, 2025 04:44:10.434087992 CET9994596685.239.34.134192.168.2.13
                                          Jan 11, 2025 04:44:10.434139967 CET45966999192.168.2.1385.239.34.134
                                          Jan 11, 2025 04:44:10.439074993 CET9994596685.239.34.134192.168.2.13
                                          Jan 11, 2025 04:44:12.199331045 CET9994596685.239.34.134192.168.2.13
                                          Jan 11, 2025 04:44:12.199619055 CET45966999192.168.2.1385.239.34.134
                                          Jan 11, 2025 04:44:12.204480886 CET9994596685.239.34.134192.168.2.13
                                          Jan 11, 2025 04:44:13.201615095 CET45968999192.168.2.1385.239.34.134
                                          Jan 11, 2025 04:44:13.206530094 CET9994596885.239.34.134192.168.2.13
                                          Jan 11, 2025 04:44:13.206705093 CET45968999192.168.2.1385.239.34.134
                                          Jan 11, 2025 04:44:13.206747055 CET45968999192.168.2.1385.239.34.134
                                          Jan 11, 2025 04:44:13.211558104 CET9994596885.239.34.134192.168.2.13
                                          Jan 11, 2025 04:44:13.211627960 CET45968999192.168.2.1385.239.34.134
                                          Jan 11, 2025 04:44:13.216479063 CET9994596885.239.34.134192.168.2.13
                                          Jan 11, 2025 04:44:14.965950966 CET9994596885.239.34.134192.168.2.13
                                          Jan 11, 2025 04:44:14.966183901 CET45968999192.168.2.1385.239.34.134
                                          Jan 11, 2025 04:44:14.971081972 CET9994596885.239.34.134192.168.2.13
                                          Jan 11, 2025 04:44:15.968161106 CET45970999192.168.2.1385.239.34.134
                                          Jan 11, 2025 04:44:15.973018885 CET9994597085.239.34.134192.168.2.13
                                          Jan 11, 2025 04:44:15.973095894 CET45970999192.168.2.1385.239.34.134
                                          Jan 11, 2025 04:44:15.973157883 CET45970999192.168.2.1385.239.34.134
                                          Jan 11, 2025 04:44:15.978019953 CET9994597085.239.34.134192.168.2.13
                                          Jan 11, 2025 04:44:15.978070021 CET45970999192.168.2.1385.239.34.134
                                          Jan 11, 2025 04:44:15.982850075 CET9994597085.239.34.134192.168.2.13
                                          Jan 11, 2025 04:44:17.729671955 CET9994597085.239.34.134192.168.2.13
                                          Jan 11, 2025 04:44:17.730113983 CET45970999192.168.2.1385.239.34.134
                                          Jan 11, 2025 04:44:17.734966993 CET9994597085.239.34.134192.168.2.13
                                          Jan 11, 2025 04:44:18.732402086 CET45972999192.168.2.1385.239.34.134
                                          Jan 11, 2025 04:44:18.737199068 CET9994597285.239.34.134192.168.2.13
                                          Jan 11, 2025 04:44:18.737263918 CET45972999192.168.2.1385.239.34.134
                                          Jan 11, 2025 04:44:18.737293005 CET45972999192.168.2.1385.239.34.134
                                          Jan 11, 2025 04:44:18.742042065 CET9994597285.239.34.134192.168.2.13
                                          Jan 11, 2025 04:44:18.742090940 CET45972999192.168.2.1385.239.34.134
                                          Jan 11, 2025 04:44:18.746818066 CET9994597285.239.34.134192.168.2.13

                                          System Behavior

                                          Start time (UTC):03:42:05
                                          Start date (UTC):11/01/2025
                                          Path:/usr/bin/dash
                                          Arguments:-
                                          File size:129816 bytes
                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                          Start time (UTC):03:42:05
                                          Start date (UTC):11/01/2025
                                          Path:/usr/bin/rm
                                          Arguments:rm -f /tmp/tmp.zyqSxPi4y6 /tmp/tmp.Ugs7kCUs5l /tmp/tmp.0AzLUvd8vZ
                                          File size:72056 bytes
                                          MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b

                                          Start time (UTC):03:42:05
                                          Start date (UTC):11/01/2025
                                          Path:/usr/bin/dash
                                          Arguments:-
                                          File size:129816 bytes
                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                          Start time (UTC):03:42:05
                                          Start date (UTC):11/01/2025
                                          Path:/usr/bin/rm
                                          Arguments:rm -f /tmp/tmp.zyqSxPi4y6 /tmp/tmp.Ugs7kCUs5l /tmp/tmp.0AzLUvd8vZ
                                          File size:72056 bytes
                                          MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b

                                          Start time (UTC):03:42:13
                                          Start date (UTC):11/01/2025
                                          Path:/tmp/mips.elf
                                          Arguments:/tmp/mips.elf
                                          File size:5777432 bytes
                                          MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                                          Start time (UTC):03:42:13
                                          Start date (UTC):11/01/2025
                                          Path:/tmp/mips.elf
                                          Arguments:-
                                          File size:5777432 bytes
                                          MD5 hash:0083f1f0e77be34ad27f849842bbb00c