Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
mpsl.elf

Overview

General Information

Sample name:mpsl.elf
Analysis ID:1589155
MD5:aa1bbc743b1d280af074ea83e1cd43d3
SHA1:c20d691b104ff184a601c5cd262be33336d7e15a
SHA256:d99e652690875b33e274832efd83d2cfef20da7ed7ff7428e71fbf34d1848071
Tags:elfuser-abuse_ch
Infos:

Detection

Mirai, Moobot
Score:100
Range:0 - 100
Whitelisted:false

Signatures

Antivirus / Scanner detection for submitted sample
Detected Mirai
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Suricata IDS alerts for network traffic
Yara detected Mirai
Yara detected Moobot
Sample deletes itself
Detected TCP or UDP traffic on non-standard ports
Enumerates processes within the "proc" file system
Sample has stripped symbol table
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Uses the "uname" system call to query kernel version information (possible evasion)
Yara signature match

Classification

Joe Sandbox version:42.0.0 Malachite
Analysis ID:1589155
Start date and time:2025-01-11 14:22:11 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 40s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:mpsl.elf
Detection:MAL
Classification:mal100.troj.evad.linELF@0/0@22/0
Command:/tmp/mpsl.elf
PID:6227
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
done.
Standard Error:
  • system is lnxubuntu20
  • mpsl.elf (PID: 6227, Parent: 6151, MD5: 0d6f61f82cf2f781c6eb0661071d42d9) Arguments: /tmp/mpsl.elf
    • mpsl.elf New Fork (PID: 6230, Parent: 6227)
      • mpsl.elf New Fork (PID: 6232, Parent: 6230)
      • mpsl.elf New Fork (PID: 6233, Parent: 6230)
        • mpsl.elf New Fork (PID: 6236, Parent: 6233)
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
MiraiMirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese. Nowadays it targets a wide range of networked embedded devices such as IP cameras, home routers (many vendors involved), and other IoT devices. Since the source code was published on "Hack Forums" many variants of the Mirai family appeared, infecting mostly home networks all around the world.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/elf.mirai
NameDescriptionAttributionBlogpost URLsLink
MooBotNo Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/elf.moobot
SourceRuleDescriptionAuthorStrings
mpsl.elfJoeSecurity_MoobotYara detected MoobotJoe Security
    mpsl.elfJoeSecurity_Mirai_8Yara detected MiraiJoe Security
      mpsl.elfLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
      • 0x1024c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x10260:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x10274:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x10288:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x1029c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x102b0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x102c4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x102d8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x102ec:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x10300:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x10314:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x10328:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x1033c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x10350:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x10364:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x10378:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x1038c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x103a0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x103b4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x103c8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x103dc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      SourceRuleDescriptionAuthorStrings
      6227.1.00007f01e4400000.00007f01e4412000.r-x.sdmpJoeSecurity_MoobotYara detected MoobotJoe Security
        6227.1.00007f01e4400000.00007f01e4412000.r-x.sdmpJoeSecurity_Mirai_8Yara detected MiraiJoe Security
          6227.1.00007f01e4400000.00007f01e4412000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
          • 0x1024c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x10260:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x10274:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x10288:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x1029c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x102b0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x102c4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x102d8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x102ec:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x10300:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x10314:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x10328:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x1033c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x10350:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x10364:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x10378:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x1038c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x103a0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x103b4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x103c8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x103dc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          Process Memory Space: mpsl.elf PID: 6227JoeSecurity_MoobotYara detected MoobotJoe Security
            Process Memory Space: mpsl.elf PID: 6227JoeSecurity_Mirai_8Yara detected MiraiJoe Security
              Click to see the 1 entries
              TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
              2025-01-11T14:23:01.089221+010020304911Malware Command and Control Activity Detected192.168.2.2349684154.213.187.1181314TCP
              2025-01-11T14:23:04.990837+010020304911Malware Command and Control Activity Detected192.168.2.2349686154.213.187.1181314TCP
              2025-01-11T14:23:11.816270+010020304911Malware Command and Control Activity Detected192.168.2.2349688154.213.187.1181314TCP
              2025-01-11T14:23:18.436504+010020304911Malware Command and Control Activity Detected192.168.2.2349690154.213.187.1181314TCP
              2025-01-11T14:23:24.058746+010020304911Malware Command and Control Activity Detected192.168.2.2349692154.213.187.1181314TCP
              2025-01-11T14:23:29.832687+010020304911Malware Command and Control Activity Detected192.168.2.2349694154.213.187.1181314TCP
              2025-01-11T14:23:32.454274+010020304911Malware Command and Control Activity Detected192.168.2.2349696154.213.187.1181314TCP
              2025-01-11T14:23:42.093377+010020304911Malware Command and Control Activity Detected192.168.2.2349698154.213.187.1181314TCP
              2025-01-11T14:23:48.719472+010020304911Malware Command and Control Activity Detected192.168.2.2349700154.213.187.1181314TCP
              2025-01-11T14:23:59.339001+010020304911Malware Command and Control Activity Detected192.168.2.2349702154.213.187.1181314TCP
              2025-01-11T14:24:09.956938+010020304911Malware Command and Control Activity Detected192.168.2.2349704154.213.187.1181314TCP
              2025-01-11T14:24:12.584557+010020304911Malware Command and Control Activity Detected192.168.2.2349706154.213.187.1181314TCP
              2025-01-11T14:24:14.665452+010020304911Malware Command and Control Activity Detected192.168.2.2349708154.213.187.1181314TCP
              2025-01-11T14:24:17.304619+010020304911Malware Command and Control Activity Detected192.168.2.2349710154.213.187.1181314TCP
              2025-01-11T14:24:27.922779+010020304911Malware Command and Control Activity Detected192.168.2.2349712154.213.187.1181314TCP
              2025-01-11T14:24:30.670212+010020304911Malware Command and Control Activity Detected192.168.2.2349714154.213.187.1181314TCP
              2025-01-11T14:24:38.281905+010020304911Malware Command and Control Activity Detected192.168.2.2349716154.213.187.1181314TCP
              2025-01-11T14:24:46.893491+010020304911Malware Command and Control Activity Detected192.168.2.2349718154.213.187.1181314TCP
              2025-01-11T14:24:52.530883+010020304911Malware Command and Control Activity Detected192.168.2.2349720154.213.187.1181314TCP
              2025-01-11T14:24:56.148464+010020304911Malware Command and Control Activity Detected192.168.2.2349722154.213.187.1181314TCP
              2025-01-11T14:24:59.836539+010020304911Malware Command and Control Activity Detected192.168.2.2349724154.213.187.1181314TCP
              2025-01-11T14:25:02.445465+010020304911Malware Command and Control Activity Detected192.168.2.2349726154.213.187.1181314TCP

              Click to jump to signature section

              Show All Signature Results

              AV Detection

              barindex
              Source: mpsl.elfAvira: detected
              Source: mpsl.elfVirustotal: Detection: 60%Perma Link
              Source: mpsl.elfReversingLabs: Detection: 57%

              Networking

              barindex
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.23:49710 -> 154.213.187.118:1314
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.23:49686 -> 154.213.187.118:1314
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.23:49684 -> 154.213.187.118:1314
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.23:49700 -> 154.213.187.118:1314
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.23:49712 -> 154.213.187.118:1314
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.23:49692 -> 154.213.187.118:1314
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.23:49702 -> 154.213.187.118:1314
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.23:49688 -> 154.213.187.118:1314
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.23:49696 -> 154.213.187.118:1314
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.23:49708 -> 154.213.187.118:1314
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.23:49704 -> 154.213.187.118:1314
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.23:49714 -> 154.213.187.118:1314
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.23:49690 -> 154.213.187.118:1314
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.23:49722 -> 154.213.187.118:1314
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.23:49724 -> 154.213.187.118:1314
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.23:49726 -> 154.213.187.118:1314
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.23:49694 -> 154.213.187.118:1314
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.23:49698 -> 154.213.187.118:1314
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.23:49706 -> 154.213.187.118:1314
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.23:49718 -> 154.213.187.118:1314
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.23:49716 -> 154.213.187.118:1314
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.23:49720 -> 154.213.187.118:1314
              Source: global trafficTCP traffic: 192.168.2.23:49684 -> 154.213.187.118:1314
              Source: global trafficTCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
              Source: global trafficTCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
              Source: global trafficTCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
              Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
              Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
              Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
              Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
              Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
              Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
              Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
              Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
              Source: global trafficDNS traffic detected: DNS query: webhorizon.icu
              Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443

              System Summary

              barindex
              Source: mpsl.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
              Source: 6227.1.00007f01e4400000.00007f01e4412000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
              Source: Process Memory Space: mpsl.elf PID: 6227, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
              Source: ELF static info symbol of initial sample.symtab present: no
              Source: mpsl.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
              Source: 6227.1.00007f01e4400000.00007f01e4412000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
              Source: Process Memory Space: mpsl.elf PID: 6227, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
              Source: classification engineClassification label: mal100.troj.evad.linELF@0/0@22/0
              Source: /tmp/mpsl.elf (PID: 6232)File opened: /proc/6233/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6232)File opened: /proc/6236/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6232)File opened: /proc/1582/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6232)File opened: /proc/3088/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6232)File opened: /proc/230/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6232)File opened: /proc/110/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6232)File opened: /proc/231/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6232)File opened: /proc/111/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6232)File opened: /proc/232/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6232)File opened: /proc/1579/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6232)File opened: /proc/112/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6232)File opened: /proc/233/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6232)File opened: /proc/1699/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6232)File opened: /proc/113/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6232)File opened: /proc/234/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6232)File opened: /proc/1335/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6232)File opened: /proc/1698/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6232)File opened: /proc/114/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6232)File opened: /proc/235/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6232)File opened: /proc/1334/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6232)File opened: /proc/1576/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6232)File opened: /proc/2302/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6232)File opened: /proc/115/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6232)File opened: /proc/236/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6232)File opened: /proc/116/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6232)File opened: /proc/237/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6232)File opened: /proc/117/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6232)File opened: /proc/118/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6232)File opened: /proc/910/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6232)File opened: /proc/119/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6232)File opened: /proc/912/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6232)File opened: /proc/10/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6232)File opened: /proc/2307/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6232)File opened: /proc/11/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6232)File opened: /proc/918/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6232)File opened: /proc/12/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6232)File opened: /proc/13/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6232)File opened: /proc/14/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6232)File opened: /proc/15/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6232)File opened: /proc/16/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6232)File opened: /proc/17/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6232)File opened: /proc/18/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6232)File opened: /proc/1594/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6232)File opened: /proc/120/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6232)File opened: /proc/121/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6232)File opened: /proc/1349/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6232)File opened: /proc/1/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6232)File opened: /proc/122/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6232)File opened: /proc/243/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6232)File opened: /proc/123/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6232)File opened: /proc/2/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6232)File opened: /proc/124/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6232)File opened: /proc/3/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6232)File opened: /proc/4/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6232)File opened: /proc/125/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6232)File opened: /proc/126/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6232)File opened: /proc/1344/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6232)File opened: /proc/1465/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6232)File opened: /proc/1586/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6232)File opened: /proc/127/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6232)File opened: /proc/6/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6232)File opened: /proc/248/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6232)File opened: /proc/128/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6232)File opened: /proc/249/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6232)File opened: /proc/1463/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6232)File opened: /proc/800/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6232)File opened: /proc/9/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6232)File opened: /proc/801/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6232)File opened: /proc/20/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6232)File opened: /proc/21/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6232)File opened: /proc/1900/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6232)File opened: /proc/22/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6232)File opened: /proc/6252/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6232)File opened: /proc/23/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6232)File opened: /proc/6251/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6232)File opened: /proc/24/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6232)File opened: /proc/6254/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6232)File opened: /proc/25/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6232)File opened: /proc/6253/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6232)File opened: /proc/26/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6232)File opened: /proc/6256/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6232)File opened: /proc/27/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6232)File opened: /proc/6255/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6232)File opened: /proc/28/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6232)File opened: /proc/6258/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6232)File opened: /proc/29/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6232)File opened: /proc/6257/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6232)File opened: /proc/491/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6232)File opened: /proc/250/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6232)File opened: /proc/130/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6232)File opened: /proc/251/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6232)File opened: /proc/6250/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6232)File opened: /proc/252/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6232)File opened: /proc/132/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6232)File opened: /proc/253/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6232)File opened: /proc/254/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6232)File opened: /proc/255/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6232)File opened: /proc/256/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6232)File opened: /proc/1599/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6232)File opened: /proc/257/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6232)File opened: /proc/1477/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6232)File opened: /proc/379/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6232)File opened: /proc/258/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6232)File opened: /proc/1476/cmdlineJump to behavior
              Source: /tmp/mpsl.elf (PID: 6232)File opened: /proc/259/cmdlineJump to behavior

              Hooking and other Techniques for Hiding and Protection

              barindex
              Source: /tmp/mpsl.elf (PID: 6227)File: /tmp/mpsl.elfJump to behavior
              Source: /tmp/mpsl.elf (PID: 6227)Queries kernel information via 'uname': Jump to behavior
              Source: mpsl.elf, 6227.1.00007ffc6acca000.00007ffc6aceb000.rw-.sdmpBinary or memory string: jx86_64/usr/bin/qemu-mipsel/tmp/mpsl.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/mpsl.elf
              Source: mpsl.elf, 6227.1.000055887b0b5000.000055887b13c000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/mipsel
              Source: mpsl.elf, 6227.1.000055887b0b5000.000055887b13c000.rw-.sdmpBinary or memory string: U!/etc/qemu-binfmt/mipsel
              Source: mpsl.elf, 6227.1.00007ffc6acca000.00007ffc6aceb000.rw-.sdmpBinary or memory string: /usr/bin/qemu-mipsel

              Stealing of Sensitive Information

              barindex
              Source: Yara matchFile source: mpsl.elf, type: SAMPLE
              Source: Yara matchFile source: 6227.1.00007f01e4400000.00007f01e4412000.r-x.sdmp, type: MEMORY
              Source: Yara matchFile source: Process Memory Space: mpsl.elf PID: 6227, type: MEMORYSTR
              Source: Yara matchFile source: mpsl.elf, type: SAMPLE
              Source: Yara matchFile source: 6227.1.00007f01e4400000.00007f01e4412000.r-x.sdmp, type: MEMORY
              Source: Yara matchFile source: Process Memory Space: mpsl.elf PID: 6227, type: MEMORYSTR

              Remote Access Functionality

              barindex
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: Yara matchFile source: mpsl.elf, type: SAMPLE
              Source: Yara matchFile source: 6227.1.00007f01e4400000.00007f01e4412000.r-x.sdmp, type: MEMORY
              Source: Yara matchFile source: Process Memory Space: mpsl.elf PID: 6227, type: MEMORYSTR
              Source: Yara matchFile source: mpsl.elf, type: SAMPLE
              Source: Yara matchFile source: 6227.1.00007f01e4400000.00007f01e4412000.r-x.sdmp, type: MEMORY
              Source: Yara matchFile source: Process Memory Space: mpsl.elf PID: 6227, type: MEMORYSTR
              ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
              Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception1
              File Deletion
              1
              OS Credential Dumping
              11
              Security Software Discovery
              Remote ServicesData from Local System1
              Encrypted Channel
              Exfiltration Over Other Network MediumAbuse Accessibility Features
              CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
              Non-Standard Port
              Exfiltration Over BluetoothNetwork Denial of Service
              Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
              Non-Application Layer Protocol
              Automated ExfiltrationData Encrypted for Impact
              Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture2
              Application Layer Protocol
              Traffic DuplicationData Destruction
              No configs have been found
              Hide Legend

              Legend:

              • Process
              • Signature
              • Created File
              • DNS/IP Info
              • Is Dropped
              • Number of created Files
              • Is malicious
              • Internet
              behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1589155 Sample: mpsl.elf Startdate: 11/01/2025 Architecture: LINUX Score: 100 20 109.202.202.202, 80 INIT7CH Switzerland 2->20 22 webhorizon.icu 154.213.187.118, 1314, 49684, 49686 DDOSING-BGP-NETWORKUS Seychelles 2->22 24 2 other IPs or domains 2->24 26 Suricata IDS alerts for network traffic 2->26 28 Malicious sample detected (through community Yara rule) 2->28 30 Antivirus / Scanner detection for submitted sample 2->30 32 4 other signatures 2->32 9 mpsl.elf 2->9         started        signatures3 process4 signatures5 34 Sample deletes itself 9->34 12 mpsl.elf 9->12         started        process6 process7 14 mpsl.elf 12->14         started        16 mpsl.elf 12->16         started        process8 18 mpsl.elf 14->18         started       
              SourceDetectionScannerLabelLink
              mpsl.elf60%VirustotalBrowse
              mpsl.elf58%ReversingLabsLinux.Trojan.Mirai
              mpsl.elf100%AviraEXP/ELF.Mirai.Z.A
              No Antivirus matches
              No Antivirus matches
              No Antivirus matches
              NameIPActiveMaliciousAntivirus DetectionReputation
              webhorizon.icu
              154.213.187.118
              truefalse
                high
                • No. of IPs < 25%
                • 25% < No. of IPs < 50%
                • 50% < No. of IPs < 75%
                • 75% < No. of IPs
                IPDomainCountryFlagASNASN NameMalicious
                154.213.187.118
                webhorizon.icuSeychelles
                22769DDOSING-BGP-NETWORKUSfalse
                109.202.202.202
                unknownSwitzerland
                13030INIT7CHfalse
                91.189.91.43
                unknownUnited Kingdom
                41231CANONICAL-ASGBfalse
                91.189.91.42
                unknownUnited Kingdom
                41231CANONICAL-ASGBfalse
                MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                109.202.202.202kpLwzBouH4.elfGet hashmaliciousUnknownBrowse
                • ch.archive.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_92.0%2bbuild3-0ubuntu0.20.04.1_amd64.deb
                91.189.91.43ARMV6L.elfGet hashmaliciousUnknownBrowse
                  I586.elfGet hashmaliciousUnknownBrowse
                    POWERPC.elfGet hashmaliciousUnknownBrowse
                      SH4.elfGet hashmaliciousUnknownBrowse
                        sss.elfGet hashmaliciousGafgytBrowse
                          ARMV5L.elfGet hashmaliciousUnknownBrowse
                            SPARC.elfGet hashmaliciousUnknownBrowse
                              M68K.elfGet hashmaliciousUnknownBrowse
                                Space.i686.elfGet hashmaliciousUnknownBrowse
                                  Space.x86_64.elfGet hashmaliciousUnknownBrowse
                                    91.189.91.42ARMV6L.elfGet hashmaliciousUnknownBrowse
                                      I586.elfGet hashmaliciousUnknownBrowse
                                        POWERPC.elfGet hashmaliciousUnknownBrowse
                                          SH4.elfGet hashmaliciousUnknownBrowse
                                            sss.elfGet hashmaliciousGafgytBrowse
                                              ARMV5L.elfGet hashmaliciousUnknownBrowse
                                                SPARC.elfGet hashmaliciousUnknownBrowse
                                                  M68K.elfGet hashmaliciousUnknownBrowse
                                                    Space.i686.elfGet hashmaliciousUnknownBrowse
                                                      Space.mips.elfGet hashmaliciousUnknownBrowse
                                                        MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                        webhorizon.icuarm.elfGet hashmaliciousMirai, MoobotBrowse
                                                        • 38.55.246.3
                                                        m68k.elfGet hashmaliciousMirai, MoobotBrowse
                                                        • 38.55.246.3
                                                        ppc.elfGet hashmaliciousMirai, MoobotBrowse
                                                        • 38.55.246.3
                                                        mpsl.elfGet hashmaliciousMirai, MoobotBrowse
                                                        • 38.55.246.3
                                                        debug.dbg.elfGet hashmaliciousMirai, MoobotBrowse
                                                        • 38.55.246.3
                                                        x86_64.elfGet hashmaliciousMirai, MoobotBrowse
                                                        • 38.55.246.3
                                                        arm7.elfGet hashmaliciousMirai, MoobotBrowse
                                                        • 38.55.246.3
                                                        sh4.elfGet hashmaliciousMirai, MoobotBrowse
                                                        • 38.55.246.3
                                                        mips.elfGet hashmaliciousMirai, MoobotBrowse
                                                        • 38.55.246.3
                                                        spc.elfGet hashmaliciousMirai, MoobotBrowse
                                                        • 38.55.246.3
                                                        MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                        CANONICAL-ASGBARMV6L.elfGet hashmaliciousUnknownBrowse
                                                        • 91.189.91.42
                                                        I586.elfGet hashmaliciousUnknownBrowse
                                                        • 91.189.91.42
                                                        POWERPC.elfGet hashmaliciousUnknownBrowse
                                                        • 91.189.91.42
                                                        SH4.elfGet hashmaliciousUnknownBrowse
                                                        • 91.189.91.42
                                                        sst.elfGet hashmaliciousGafgytBrowse
                                                        • 185.125.190.26
                                                        sss.elfGet hashmaliciousGafgytBrowse
                                                        • 91.189.91.42
                                                        ARMV5L.elfGet hashmaliciousUnknownBrowse
                                                        • 91.189.91.42
                                                        SPARC.elfGet hashmaliciousUnknownBrowse
                                                        • 91.189.91.42
                                                        M68K.elfGet hashmaliciousUnknownBrowse
                                                        • 91.189.91.42
                                                        Space.i686.elfGet hashmaliciousUnknownBrowse
                                                        • 91.189.91.42
                                                        CANONICAL-ASGBARMV6L.elfGet hashmaliciousUnknownBrowse
                                                        • 91.189.91.42
                                                        I586.elfGet hashmaliciousUnknownBrowse
                                                        • 91.189.91.42
                                                        POWERPC.elfGet hashmaliciousUnknownBrowse
                                                        • 91.189.91.42
                                                        SH4.elfGet hashmaliciousUnknownBrowse
                                                        • 91.189.91.42
                                                        sst.elfGet hashmaliciousGafgytBrowse
                                                        • 185.125.190.26
                                                        sss.elfGet hashmaliciousGafgytBrowse
                                                        • 91.189.91.42
                                                        ARMV5L.elfGet hashmaliciousUnknownBrowse
                                                        • 91.189.91.42
                                                        SPARC.elfGet hashmaliciousUnknownBrowse
                                                        • 91.189.91.42
                                                        M68K.elfGet hashmaliciousUnknownBrowse
                                                        • 91.189.91.42
                                                        Space.i686.elfGet hashmaliciousUnknownBrowse
                                                        • 91.189.91.42
                                                        DDOSING-BGP-NETWORKUS4.elfGet hashmaliciousUnknownBrowse
                                                        • 41.93.138.131
                                                        armv5l.elfGet hashmaliciousUnknownBrowse
                                                        • 41.93.222.47
                                                        gmpsl.elfGet hashmaliciousUnknownBrowse
                                                        • 154.213.187.125
                                                        garm5.elfGet hashmaliciousUnknownBrowse
                                                        • 154.213.187.125
                                                        garm7.elfGet hashmaliciousMiraiBrowse
                                                        • 154.213.187.125
                                                        garm.elfGet hashmaliciousUnknownBrowse
                                                        • 154.213.187.125
                                                        gmips.elfGet hashmaliciousUnknownBrowse
                                                        • 154.213.187.125
                                                        byte.x86.elfGet hashmaliciousMirai, OkiruBrowse
                                                        • 154.213.190.254
                                                        byte.ppc.elfGet hashmaliciousMirai, OkiruBrowse
                                                        • 154.213.190.254
                                                        byte.mpsl.elfGet hashmaliciousMirai, OkiruBrowse
                                                        • 154.213.190.246
                                                        INIT7CHARMV6L.elfGet hashmaliciousUnknownBrowse
                                                        • 109.202.202.202
                                                        I586.elfGet hashmaliciousUnknownBrowse
                                                        • 109.202.202.202
                                                        POWERPC.elfGet hashmaliciousUnknownBrowse
                                                        • 109.202.202.202
                                                        SH4.elfGet hashmaliciousUnknownBrowse
                                                        • 109.202.202.202
                                                        sss.elfGet hashmaliciousGafgytBrowse
                                                        • 109.202.202.202
                                                        ARMV5L.elfGet hashmaliciousUnknownBrowse
                                                        • 109.202.202.202
                                                        SPARC.elfGet hashmaliciousUnknownBrowse
                                                        • 109.202.202.202
                                                        M68K.elfGet hashmaliciousUnknownBrowse
                                                        • 109.202.202.202
                                                        Space.i686.elfGet hashmaliciousUnknownBrowse
                                                        • 109.202.202.202
                                                        Space.mips.elfGet hashmaliciousUnknownBrowse
                                                        • 109.202.202.202
                                                        No context
                                                        No context
                                                        No created / dropped files found
                                                        File type:ELF 32-bit LSB executable, MIPS, MIPS-I version 1 (SYSV), statically linked, stripped
                                                        Entropy (8bit):5.488786593444635
                                                        TrID:
                                                        • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                                                        File name:mpsl.elf
                                                        File size:76'384 bytes
                                                        MD5:aa1bbc743b1d280af074ea83e1cd43d3
                                                        SHA1:c20d691b104ff184a601c5cd262be33336d7e15a
                                                        SHA256:d99e652690875b33e274832efd83d2cfef20da7ed7ff7428e71fbf34d1848071
                                                        SHA512:ea827660028028d6a71685d947de1b5d936d103b5b1710b6f9bb2f6c3f1f82e344f8871d4dff68b077d40870e257ac4a964ff9b0ce37d8a44f2bef811d513ed4
                                                        SSDEEP:768:sD7fxbOUp9+goKPsJtN1hCeF56eYOiKfrwwuaYbZdkWFXi2U7n/eYYTEOCwn8Ik:snxbRFs8Y56vO82wZdn+n/nYTvn8
                                                        TLSH:4273D715FF550FB7DCABCD3705A9170239CC558A22E47B3A7934D828B65B20B49E3CA8
                                                        File Content Preview:.ELF....................`.@.4...X(......4. ...(...............@...@.P...P................ ... E.. E..... *..........Q.td...............................<...'!......'.......................<...'!... .........9'.. ........................<...'!.............9

                                                        ELF header

                                                        Class:ELF32
                                                        Data:2's complement, little endian
                                                        Version:1 (current)
                                                        Machine:MIPS R3000
                                                        Version Number:0x1
                                                        Type:EXEC (Executable file)
                                                        OS/ABI:UNIX - System V
                                                        ABI Version:0
                                                        Entry Point Address:0x400260
                                                        Flags:0x1007
                                                        ELF Header Size:52
                                                        Program Header Offset:52
                                                        Program Header Size:32
                                                        Number of Program Headers:3
                                                        Section Header Offset:75864
                                                        Section Header Size:40
                                                        Number of Section Headers:13
                                                        Header String Table Index:12
                                                        NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                                        NULL0x00x00x00x00x0000
                                                        .initPROGBITS0x4000940x940x8c0x00x6AX004
                                                        .textPROGBITS0x4001200x1200xfff00x00x6AX0016
                                                        .finiPROGBITS0x4101100x101100x5c0x00x6AX004
                                                        .rodataPROGBITS0x4101700x101700x1ae00x00x2A0016
                                                        .ctorsPROGBITS0x4520000x120000x80x00x3WA004
                                                        .dtorsPROGBITS0x4520080x120080x80x00x3WA004
                                                        .dataPROGBITS0x4520200x120200x3a00x00x3WA0016
                                                        .gotPROGBITS0x4523c00x123c00x4400x40x10000003WAp0016
                                                        .sbssNOBITS0x4528000x128000x1c0x00x10000003WAp004
                                                        .bssNOBITS0x4528200x128000x22000x00x3WA0016
                                                        .mdebug.abi32PROGBITS0x9000x128000x00x00x0001
                                                        .shstrtabSTRTAB0x00x128000x570x00x0001
                                                        TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                        LOAD0x00x4000000x4000000x11c500x11c505.57130x5R E0x10000.init .text .fini .rodata
                                                        LOAD0x120000x4520000x4520000x8000x2a203.69990x6RW 0x10000.ctors .dtors .data .got .sbss .bss
                                                        GNU_STACK0x00x00x00x00x00.00000x7RWE0x4
                                                        TimestampSIDSignatureSeveritySource IPSource PortDest IPDest PortProtocol
                                                        2025-01-11T14:23:01.089221+01002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.2349684154.213.187.1181314TCP
                                                        2025-01-11T14:23:04.990837+01002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.2349686154.213.187.1181314TCP
                                                        2025-01-11T14:23:11.816270+01002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.2349688154.213.187.1181314TCP
                                                        2025-01-11T14:23:18.436504+01002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.2349690154.213.187.1181314TCP
                                                        2025-01-11T14:23:24.058746+01002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.2349692154.213.187.1181314TCP
                                                        2025-01-11T14:23:29.832687+01002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.2349694154.213.187.1181314TCP
                                                        2025-01-11T14:23:32.454274+01002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.2349696154.213.187.1181314TCP
                                                        2025-01-11T14:23:42.093377+01002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.2349698154.213.187.1181314TCP
                                                        2025-01-11T14:23:48.719472+01002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.2349700154.213.187.1181314TCP
                                                        2025-01-11T14:23:59.339001+01002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.2349702154.213.187.1181314TCP
                                                        2025-01-11T14:24:09.956938+01002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.2349704154.213.187.1181314TCP
                                                        2025-01-11T14:24:12.584557+01002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.2349706154.213.187.1181314TCP
                                                        2025-01-11T14:24:14.665452+01002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.2349708154.213.187.1181314TCP
                                                        2025-01-11T14:24:17.304619+01002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.2349710154.213.187.1181314TCP
                                                        2025-01-11T14:24:27.922779+01002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.2349712154.213.187.1181314TCP
                                                        2025-01-11T14:24:30.670212+01002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.2349714154.213.187.1181314TCP
                                                        2025-01-11T14:24:38.281905+01002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.2349716154.213.187.1181314TCP
                                                        2025-01-11T14:24:46.893491+01002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.2349718154.213.187.1181314TCP
                                                        2025-01-11T14:24:52.530883+01002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.2349720154.213.187.1181314TCP
                                                        2025-01-11T14:24:56.148464+01002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.2349722154.213.187.1181314TCP
                                                        2025-01-11T14:24:59.836539+01002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.2349724154.213.187.1181314TCP
                                                        2025-01-11T14:25:02.445465+01002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.2349726154.213.187.1181314TCP
                                                        TimestampSource PortDest PortSource IPDest IP
                                                        Jan 11, 2025 14:23:00.668971062 CET43928443192.168.2.2391.189.91.42
                                                        Jan 11, 2025 14:23:01.081562996 CET496841314192.168.2.23154.213.187.118
                                                        Jan 11, 2025 14:23:01.086452007 CET131449684154.213.187.118192.168.2.23
                                                        Jan 11, 2025 14:23:01.086515903 CET496841314192.168.2.23154.213.187.118
                                                        Jan 11, 2025 14:23:01.089221001 CET496841314192.168.2.23154.213.187.118
                                                        Jan 11, 2025 14:23:01.094069958 CET131449684154.213.187.118192.168.2.23
                                                        Jan 11, 2025 14:23:01.682029009 CET131449684154.213.187.118192.168.2.23
                                                        Jan 11, 2025 14:23:01.682293892 CET496841314192.168.2.23154.213.187.118
                                                        Jan 11, 2025 14:23:01.687199116 CET131449684154.213.187.118192.168.2.23
                                                        Jan 11, 2025 14:23:04.985238075 CET496861314192.168.2.23154.213.187.118
                                                        Jan 11, 2025 14:23:04.990118027 CET131449686154.213.187.118192.168.2.23
                                                        Jan 11, 2025 14:23:04.990255117 CET496861314192.168.2.23154.213.187.118
                                                        Jan 11, 2025 14:23:04.990837097 CET496861314192.168.2.23154.213.187.118
                                                        Jan 11, 2025 14:23:04.995637894 CET131449686154.213.187.118192.168.2.23
                                                        Jan 11, 2025 14:23:05.594065905 CET131449686154.213.187.118192.168.2.23
                                                        Jan 11, 2025 14:23:05.594218969 CET496861314192.168.2.23154.213.187.118
                                                        Jan 11, 2025 14:23:05.599010944 CET131449686154.213.187.118192.168.2.23
                                                        Jan 11, 2025 14:23:06.040397882 CET42836443192.168.2.2391.189.91.43
                                                        Jan 11, 2025 14:23:07.320142031 CET4251680192.168.2.23109.202.202.202
                                                        Jan 11, 2025 14:23:11.809784889 CET496881314192.168.2.23154.213.187.118
                                                        Jan 11, 2025 14:23:11.814764977 CET131449688154.213.187.118192.168.2.23
                                                        Jan 11, 2025 14:23:11.814824104 CET496881314192.168.2.23154.213.187.118
                                                        Jan 11, 2025 14:23:11.816270113 CET496881314192.168.2.23154.213.187.118
                                                        Jan 11, 2025 14:23:11.821156979 CET131449688154.213.187.118192.168.2.23
                                                        Jan 11, 2025 14:23:12.421816111 CET131449688154.213.187.118192.168.2.23
                                                        Jan 11, 2025 14:23:12.422036886 CET496881314192.168.2.23154.213.187.118
                                                        Jan 11, 2025 14:23:12.428092957 CET131449688154.213.187.118192.168.2.23
                                                        Jan 11, 2025 14:23:18.430907011 CET496901314192.168.2.23154.213.187.118
                                                        Jan 11, 2025 14:23:18.435889959 CET131449690154.213.187.118192.168.2.23
                                                        Jan 11, 2025 14:23:18.435955048 CET496901314192.168.2.23154.213.187.118
                                                        Jan 11, 2025 14:23:18.436503887 CET496901314192.168.2.23154.213.187.118
                                                        Jan 11, 2025 14:23:18.441359043 CET131449690154.213.187.118192.168.2.23
                                                        Jan 11, 2025 14:23:19.042520046 CET131449690154.213.187.118192.168.2.23
                                                        Jan 11, 2025 14:23:19.042733908 CET496901314192.168.2.23154.213.187.118
                                                        Jan 11, 2025 14:23:19.047651052 CET131449690154.213.187.118192.168.2.23
                                                        Jan 11, 2025 14:23:21.910243034 CET43928443192.168.2.2391.189.91.42
                                                        Jan 11, 2025 14:23:24.052788973 CET496921314192.168.2.23154.213.187.118
                                                        Jan 11, 2025 14:23:24.057755947 CET131449692154.213.187.118192.168.2.23
                                                        Jan 11, 2025 14:23:24.057832003 CET496921314192.168.2.23154.213.187.118
                                                        Jan 11, 2025 14:23:24.058746099 CET496921314192.168.2.23154.213.187.118
                                                        Jan 11, 2025 14:23:24.063678026 CET131449692154.213.187.118192.168.2.23
                                                        Jan 11, 2025 14:23:24.668704987 CET131449692154.213.187.118192.168.2.23
                                                        Jan 11, 2025 14:23:24.669019938 CET496921314192.168.2.23154.213.187.118
                                                        Jan 11, 2025 14:23:24.673954010 CET131449692154.213.187.118192.168.2.23
                                                        Jan 11, 2025 14:23:29.825875998 CET496941314192.168.2.23154.213.187.118
                                                        Jan 11, 2025 14:23:29.830883026 CET131449694154.213.187.118192.168.2.23
                                                        Jan 11, 2025 14:23:29.830967903 CET496941314192.168.2.23154.213.187.118
                                                        Jan 11, 2025 14:23:29.832686901 CET496941314192.168.2.23154.213.187.118
                                                        Jan 11, 2025 14:23:29.837563992 CET131449694154.213.187.118192.168.2.23
                                                        Jan 11, 2025 14:23:30.434322119 CET131449694154.213.187.118192.168.2.23
                                                        Jan 11, 2025 14:23:30.435003996 CET496941314192.168.2.23154.213.187.118
                                                        Jan 11, 2025 14:23:30.439966917 CET131449694154.213.187.118192.168.2.23
                                                        Jan 11, 2025 14:23:32.148865938 CET42836443192.168.2.2391.189.91.43
                                                        Jan 11, 2025 14:23:32.447649002 CET496961314192.168.2.23154.213.187.118
                                                        Jan 11, 2025 14:23:32.452579975 CET131449696154.213.187.118192.168.2.23
                                                        Jan 11, 2025 14:23:32.452747107 CET496961314192.168.2.23154.213.187.118
                                                        Jan 11, 2025 14:23:32.454273939 CET496961314192.168.2.23154.213.187.118
                                                        Jan 11, 2025 14:23:32.459156036 CET131449696154.213.187.118192.168.2.23
                                                        Jan 11, 2025 14:23:33.075532913 CET131449696154.213.187.118192.168.2.23
                                                        Jan 11, 2025 14:23:33.075654030 CET496961314192.168.2.23154.213.187.118
                                                        Jan 11, 2025 14:23:33.080758095 CET131449696154.213.187.118192.168.2.23
                                                        Jan 11, 2025 14:23:38.291848898 CET4251680192.168.2.23109.202.202.202
                                                        Jan 11, 2025 14:23:42.086683989 CET496981314192.168.2.23154.213.187.118
                                                        Jan 11, 2025 14:23:42.091540098 CET131449698154.213.187.118192.168.2.23
                                                        Jan 11, 2025 14:23:42.091640949 CET496981314192.168.2.23154.213.187.118
                                                        Jan 11, 2025 14:23:42.093377113 CET496981314192.168.2.23154.213.187.118
                                                        Jan 11, 2025 14:23:42.098304033 CET131449698154.213.187.118192.168.2.23
                                                        Jan 11, 2025 14:23:42.703136921 CET131449698154.213.187.118192.168.2.23
                                                        Jan 11, 2025 14:23:42.703629971 CET496981314192.168.2.23154.213.187.118
                                                        Jan 11, 2025 14:23:42.709188938 CET131449698154.213.187.118192.168.2.23
                                                        Jan 11, 2025 14:23:48.713663101 CET497001314192.168.2.23154.213.187.118
                                                        Jan 11, 2025 14:23:48.718528032 CET131449700154.213.187.118192.168.2.23
                                                        Jan 11, 2025 14:23:48.718611002 CET497001314192.168.2.23154.213.187.118
                                                        Jan 11, 2025 14:23:48.719471931 CET497001314192.168.2.23154.213.187.118
                                                        Jan 11, 2025 14:23:48.724313974 CET131449700154.213.187.118192.168.2.23
                                                        Jan 11, 2025 14:23:49.323354006 CET131449700154.213.187.118192.168.2.23
                                                        Jan 11, 2025 14:23:49.323870897 CET497001314192.168.2.23154.213.187.118
                                                        Jan 11, 2025 14:23:49.329916000 CET131449700154.213.187.118192.168.2.23
                                                        Jan 11, 2025 14:23:59.333313942 CET497021314192.168.2.23154.213.187.118
                                                        Jan 11, 2025 14:23:59.338227987 CET131449702154.213.187.118192.168.2.23
                                                        Jan 11, 2025 14:23:59.338311911 CET497021314192.168.2.23154.213.187.118
                                                        Jan 11, 2025 14:23:59.339000940 CET497021314192.168.2.23154.213.187.118
                                                        Jan 11, 2025 14:23:59.343858004 CET131449702154.213.187.118192.168.2.23
                                                        Jan 11, 2025 14:23:59.941633940 CET131449702154.213.187.118192.168.2.23
                                                        Jan 11, 2025 14:23:59.941941977 CET497021314192.168.2.23154.213.187.118
                                                        Jan 11, 2025 14:23:59.946916103 CET131449702154.213.187.118192.168.2.23
                                                        Jan 11, 2025 14:24:02.864545107 CET43928443192.168.2.2391.189.91.42
                                                        Jan 11, 2025 14:24:09.950599909 CET497041314192.168.2.23154.213.187.118
                                                        Jan 11, 2025 14:24:09.955585003 CET131449704154.213.187.118192.168.2.23
                                                        Jan 11, 2025 14:24:09.955712080 CET497041314192.168.2.23154.213.187.118
                                                        Jan 11, 2025 14:24:09.956938028 CET497041314192.168.2.23154.213.187.118
                                                        Jan 11, 2025 14:24:09.961803913 CET131449704154.213.187.118192.168.2.23
                                                        Jan 11, 2025 14:24:10.568124056 CET131449704154.213.187.118192.168.2.23
                                                        Jan 11, 2025 14:24:10.568425894 CET497041314192.168.2.23154.213.187.118
                                                        Jan 11, 2025 14:24:10.573254108 CET131449704154.213.187.118192.168.2.23
                                                        Jan 11, 2025 14:24:12.578591108 CET497061314192.168.2.23154.213.187.118
                                                        Jan 11, 2025 14:24:12.583478928 CET131449706154.213.187.118192.168.2.23
                                                        Jan 11, 2025 14:24:12.583575010 CET497061314192.168.2.23154.213.187.118
                                                        Jan 11, 2025 14:24:12.584557056 CET497061314192.168.2.23154.213.187.118
                                                        Jan 11, 2025 14:24:12.589371920 CET131449706154.213.187.118192.168.2.23
                                                        Jan 11, 2025 14:24:13.646538973 CET131449706154.213.187.118192.168.2.23
                                                        Jan 11, 2025 14:24:13.646691084 CET131449706154.213.187.118192.168.2.23
                                                        Jan 11, 2025 14:24:13.646883965 CET497061314192.168.2.23154.213.187.118
                                                        Jan 11, 2025 14:24:13.646996021 CET131449706154.213.187.118192.168.2.23
                                                        Jan 11, 2025 14:24:13.647044897 CET497061314192.168.2.23154.213.187.118
                                                        Jan 11, 2025 14:24:13.647087097 CET497061314192.168.2.23154.213.187.118
                                                        Jan 11, 2025 14:24:13.651813030 CET131449706154.213.187.118192.168.2.23
                                                        Jan 11, 2025 14:24:14.659001112 CET497081314192.168.2.23154.213.187.118
                                                        Jan 11, 2025 14:24:14.664010048 CET131449708154.213.187.118192.168.2.23
                                                        Jan 11, 2025 14:24:14.664122105 CET497081314192.168.2.23154.213.187.118
                                                        Jan 11, 2025 14:24:14.665452003 CET497081314192.168.2.23154.213.187.118
                                                        Jan 11, 2025 14:24:14.670326948 CET131449708154.213.187.118192.168.2.23
                                                        Jan 11, 2025 14:24:15.286792040 CET131449708154.213.187.118192.168.2.23
                                                        Jan 11, 2025 14:24:15.287134886 CET497081314192.168.2.23154.213.187.118
                                                        Jan 11, 2025 14:24:15.292025089 CET131449708154.213.187.118192.168.2.23
                                                        Jan 11, 2025 14:24:17.298268080 CET497101314192.168.2.23154.213.187.118
                                                        Jan 11, 2025 14:24:17.303217888 CET131449710154.213.187.118192.168.2.23
                                                        Jan 11, 2025 14:24:17.303314924 CET497101314192.168.2.23154.213.187.118
                                                        Jan 11, 2025 14:24:17.304619074 CET497101314192.168.2.23154.213.187.118
                                                        Jan 11, 2025 14:24:17.309501886 CET131449710154.213.187.118192.168.2.23
                                                        Jan 11, 2025 14:24:17.906311989 CET131449710154.213.187.118192.168.2.23
                                                        Jan 11, 2025 14:24:17.906790018 CET497101314192.168.2.23154.213.187.118
                                                        Jan 11, 2025 14:24:17.911720991 CET131449710154.213.187.118192.168.2.23
                                                        Jan 11, 2025 14:24:23.341722012 CET42836443192.168.2.2391.189.91.43
                                                        Jan 11, 2025 14:24:27.916712046 CET497121314192.168.2.23154.213.187.118
                                                        Jan 11, 2025 14:24:27.921535015 CET131449712154.213.187.118192.168.2.23
                                                        Jan 11, 2025 14:24:27.921614885 CET497121314192.168.2.23154.213.187.118
                                                        Jan 11, 2025 14:24:27.922779083 CET497121314192.168.2.23154.213.187.118
                                                        Jan 11, 2025 14:24:27.927570105 CET131449712154.213.187.118192.168.2.23
                                                        Jan 11, 2025 14:24:28.597469091 CET131449712154.213.187.118192.168.2.23
                                                        Jan 11, 2025 14:24:28.597789049 CET497121314192.168.2.23154.213.187.118
                                                        Jan 11, 2025 14:24:28.602685928 CET131449712154.213.187.118192.168.2.23
                                                        Jan 11, 2025 14:24:30.663775921 CET497141314192.168.2.23154.213.187.118
                                                        Jan 11, 2025 14:24:30.668683052 CET131449714154.213.187.118192.168.2.23
                                                        Jan 11, 2025 14:24:30.668767929 CET497141314192.168.2.23154.213.187.118
                                                        Jan 11, 2025 14:24:30.670212030 CET497141314192.168.2.23154.213.187.118
                                                        Jan 11, 2025 14:24:30.675112009 CET131449714154.213.187.118192.168.2.23
                                                        Jan 11, 2025 14:24:31.264000893 CET131449714154.213.187.118192.168.2.23
                                                        Jan 11, 2025 14:24:31.264470100 CET497141314192.168.2.23154.213.187.118
                                                        Jan 11, 2025 14:24:31.269464970 CET131449714154.213.187.118192.168.2.23
                                                        Jan 11, 2025 14:24:38.275557995 CET497161314192.168.2.23154.213.187.118
                                                        Jan 11, 2025 14:24:38.280503035 CET131449716154.213.187.118192.168.2.23
                                                        Jan 11, 2025 14:24:38.280576944 CET497161314192.168.2.23154.213.187.118
                                                        Jan 11, 2025 14:24:38.281904936 CET497161314192.168.2.23154.213.187.118
                                                        Jan 11, 2025 14:24:38.286812067 CET131449716154.213.187.118192.168.2.23
                                                        Jan 11, 2025 14:24:38.876522064 CET131449716154.213.187.118192.168.2.23
                                                        Jan 11, 2025 14:24:38.876882076 CET497161314192.168.2.23154.213.187.118
                                                        Jan 11, 2025 14:24:38.881848097 CET131449716154.213.187.118192.168.2.23
                                                        Jan 11, 2025 14:24:46.887413979 CET497181314192.168.2.23154.213.187.118
                                                        Jan 11, 2025 14:24:46.892426968 CET131449718154.213.187.118192.168.2.23
                                                        Jan 11, 2025 14:24:46.892488956 CET497181314192.168.2.23154.213.187.118
                                                        Jan 11, 2025 14:24:46.893491030 CET497181314192.168.2.23154.213.187.118
                                                        Jan 11, 2025 14:24:46.898309946 CET131449718154.213.187.118192.168.2.23
                                                        Jan 11, 2025 14:24:47.513967037 CET131449718154.213.187.118192.168.2.23
                                                        Jan 11, 2025 14:24:47.514209032 CET497181314192.168.2.23154.213.187.118
                                                        Jan 11, 2025 14:24:47.519076109 CET131449718154.213.187.118192.168.2.23
                                                        Jan 11, 2025 14:24:52.524132013 CET497201314192.168.2.23154.213.187.118
                                                        Jan 11, 2025 14:24:52.529815912 CET131449720154.213.187.118192.168.2.23
                                                        Jan 11, 2025 14:24:52.529885054 CET497201314192.168.2.23154.213.187.118
                                                        Jan 11, 2025 14:24:52.530883074 CET497201314192.168.2.23154.213.187.118
                                                        Jan 11, 2025 14:24:52.535670996 CET131449720154.213.187.118192.168.2.23
                                                        Jan 11, 2025 14:24:53.132774115 CET131449720154.213.187.118192.168.2.23
                                                        Jan 11, 2025 14:24:53.132987022 CET497201314192.168.2.23154.213.187.118
                                                        Jan 11, 2025 14:24:53.137818098 CET131449720154.213.187.118192.168.2.23
                                                        Jan 11, 2025 14:24:56.142256021 CET497221314192.168.2.23154.213.187.118
                                                        Jan 11, 2025 14:24:56.147376060 CET131449722154.213.187.118192.168.2.23
                                                        Jan 11, 2025 14:24:56.147447109 CET497221314192.168.2.23154.213.187.118
                                                        Jan 11, 2025 14:24:56.148463964 CET497221314192.168.2.23154.213.187.118
                                                        Jan 11, 2025 14:24:56.153414011 CET131449722154.213.187.118192.168.2.23
                                                        Jan 11, 2025 14:24:56.819735050 CET131449722154.213.187.118192.168.2.23
                                                        Jan 11, 2025 14:24:56.820245981 CET497221314192.168.2.23154.213.187.118
                                                        Jan 11, 2025 14:24:56.825221062 CET131449722154.213.187.118192.168.2.23
                                                        Jan 11, 2025 14:24:59.830439091 CET497241314192.168.2.23154.213.187.118
                                                        Jan 11, 2025 14:24:59.835361004 CET131449724154.213.187.118192.168.2.23
                                                        Jan 11, 2025 14:24:59.835445881 CET497241314192.168.2.23154.213.187.118
                                                        Jan 11, 2025 14:24:59.836539030 CET497241314192.168.2.23154.213.187.118
                                                        Jan 11, 2025 14:24:59.841407061 CET131449724154.213.187.118192.168.2.23
                                                        Jan 11, 2025 14:25:00.427683115 CET131449724154.213.187.118192.168.2.23
                                                        Jan 11, 2025 14:25:00.428108931 CET497241314192.168.2.23154.213.187.118
                                                        Jan 11, 2025 14:25:00.433120966 CET131449724154.213.187.118192.168.2.23
                                                        Jan 11, 2025 14:25:02.439244986 CET497261314192.168.2.23154.213.187.118
                                                        Jan 11, 2025 14:25:02.444145918 CET131449726154.213.187.118192.168.2.23
                                                        Jan 11, 2025 14:25:02.444219112 CET497261314192.168.2.23154.213.187.118
                                                        Jan 11, 2025 14:25:02.445465088 CET497261314192.168.2.23154.213.187.118
                                                        Jan 11, 2025 14:25:02.450336933 CET131449726154.213.187.118192.168.2.23
                                                        Jan 11, 2025 14:25:03.039503098 CET131449726154.213.187.118192.168.2.23
                                                        Jan 11, 2025 14:25:03.039803028 CET497261314192.168.2.23154.213.187.118
                                                        Jan 11, 2025 14:25:03.044621944 CET131449726154.213.187.118192.168.2.23
                                                        TimestampSource PortDest PortSource IPDest IP
                                                        Jan 11, 2025 14:23:00.770426035 CET6001653192.168.2.238.8.8.8
                                                        Jan 11, 2025 14:23:01.079451084 CET53600168.8.8.8192.168.2.23
                                                        Jan 11, 2025 14:23:04.684567928 CET4867553192.168.2.238.8.8.8
                                                        Jan 11, 2025 14:23:04.984570026 CET53486758.8.8.8192.168.2.23
                                                        Jan 11, 2025 14:23:11.596616983 CET5175653192.168.2.238.8.8.8
                                                        Jan 11, 2025 14:23:11.809112072 CET53517568.8.8.8192.168.2.23
                                                        Jan 11, 2025 14:23:18.423060894 CET3311253192.168.2.238.8.8.8
                                                        Jan 11, 2025 14:23:18.430434942 CET53331128.8.8.8192.168.2.23
                                                        Jan 11, 2025 14:23:24.044393063 CET4412353192.168.2.238.8.8.8
                                                        Jan 11, 2025 14:23:24.051990032 CET53441238.8.8.8192.168.2.23
                                                        Jan 11, 2025 14:23:29.671751022 CET5645753192.168.2.238.8.8.8
                                                        Jan 11, 2025 14:23:29.824505091 CET53564578.8.8.8192.168.2.23
                                                        Jan 11, 2025 14:23:32.439016104 CET5681653192.168.2.238.8.8.8
                                                        Jan 11, 2025 14:23:32.446811914 CET53568168.8.8.8192.168.2.23
                                                        Jan 11, 2025 14:23:42.078533888 CET4628253192.168.2.238.8.8.8
                                                        Jan 11, 2025 14:23:42.085741043 CET53462828.8.8.8192.168.2.23
                                                        Jan 11, 2025 14:23:48.706260920 CET4829053192.168.2.238.8.8.8
                                                        Jan 11, 2025 14:23:48.713119030 CET53482908.8.8.8192.168.2.23
                                                        Jan 11, 2025 14:23:59.325417995 CET4074153192.168.2.238.8.8.8
                                                        Jan 11, 2025 14:23:59.332886934 CET53407418.8.8.8192.168.2.23
                                                        Jan 11, 2025 14:24:09.943069935 CET5080953192.168.2.238.8.8.8
                                                        Jan 11, 2025 14:24:09.950064898 CET53508098.8.8.8192.168.2.23
                                                        Jan 11, 2025 14:24:12.571052074 CET6090653192.168.2.238.8.8.8
                                                        Jan 11, 2025 14:24:12.577857971 CET53609068.8.8.8192.168.2.23
                                                        Jan 11, 2025 14:24:14.650671005 CET4561853192.168.2.238.8.8.8
                                                        Jan 11, 2025 14:24:14.658123970 CET53456188.8.8.8192.168.2.23
                                                        Jan 11, 2025 14:24:17.290405035 CET3366053192.168.2.238.8.8.8
                                                        Jan 11, 2025 14:24:17.297502041 CET53336608.8.8.8192.168.2.23
                                                        Jan 11, 2025 14:24:27.908974886 CET3361553192.168.2.238.8.8.8
                                                        Jan 11, 2025 14:24:27.915909052 CET53336158.8.8.8192.168.2.23
                                                        Jan 11, 2025 14:24:30.601218939 CET4250353192.168.2.238.8.8.8
                                                        Jan 11, 2025 14:24:30.662441015 CET53425038.8.8.8192.168.2.23
                                                        Jan 11, 2025 14:24:38.267360926 CET4930653192.168.2.238.8.8.8
                                                        Jan 11, 2025 14:24:38.274745941 CET53493068.8.8.8192.168.2.23
                                                        Jan 11, 2025 14:24:46.879633904 CET4274353192.168.2.238.8.8.8
                                                        Jan 11, 2025 14:24:46.886809111 CET53427438.8.8.8192.168.2.23
                                                        Jan 11, 2025 14:24:52.516130924 CET5927053192.168.2.238.8.8.8
                                                        Jan 11, 2025 14:24:52.523592949 CET53592708.8.8.8192.168.2.23
                                                        Jan 11, 2025 14:24:56.135085106 CET5060653192.168.2.238.8.8.8
                                                        Jan 11, 2025 14:24:56.141720057 CET53506068.8.8.8192.168.2.23
                                                        Jan 11, 2025 14:24:59.822698116 CET3460053192.168.2.238.8.8.8
                                                        Jan 11, 2025 14:24:59.829952955 CET53346008.8.8.8192.168.2.23
                                                        Jan 11, 2025 14:25:02.431529999 CET5422753192.168.2.238.8.8.8
                                                        Jan 11, 2025 14:25:02.438579082 CET53542278.8.8.8192.168.2.23
                                                        TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                                        Jan 11, 2025 14:23:00.770426035 CET192.168.2.238.8.8.80xb30eStandard query (0)webhorizon.icuA (IP address)IN (0x0001)false
                                                        Jan 11, 2025 14:23:04.684567928 CET192.168.2.238.8.8.80x3809Standard query (0)webhorizon.icuA (IP address)IN (0x0001)false
                                                        Jan 11, 2025 14:23:11.596616983 CET192.168.2.238.8.8.80x4245Standard query (0)webhorizon.icuA (IP address)IN (0x0001)false
                                                        Jan 11, 2025 14:23:18.423060894 CET192.168.2.238.8.8.80x3c91Standard query (0)webhorizon.icuA (IP address)IN (0x0001)false
                                                        Jan 11, 2025 14:23:24.044393063 CET192.168.2.238.8.8.80xde44Standard query (0)webhorizon.icuA (IP address)IN (0x0001)false
                                                        Jan 11, 2025 14:23:29.671751022 CET192.168.2.238.8.8.80x4063Standard query (0)webhorizon.icuA (IP address)IN (0x0001)false
                                                        Jan 11, 2025 14:23:32.439016104 CET192.168.2.238.8.8.80x46ffStandard query (0)webhorizon.icuA (IP address)IN (0x0001)false
                                                        Jan 11, 2025 14:23:42.078533888 CET192.168.2.238.8.8.80xe179Standard query (0)webhorizon.icuA (IP address)IN (0x0001)false
                                                        Jan 11, 2025 14:23:48.706260920 CET192.168.2.238.8.8.80x7c40Standard query (0)webhorizon.icuA (IP address)IN (0x0001)false
                                                        Jan 11, 2025 14:23:59.325417995 CET192.168.2.238.8.8.80x9156Standard query (0)webhorizon.icuA (IP address)IN (0x0001)false
                                                        Jan 11, 2025 14:24:09.943069935 CET192.168.2.238.8.8.80x1a30Standard query (0)webhorizon.icuA (IP address)IN (0x0001)false
                                                        Jan 11, 2025 14:24:12.571052074 CET192.168.2.238.8.8.80xef1aStandard query (0)webhorizon.icuA (IP address)IN (0x0001)false
                                                        Jan 11, 2025 14:24:14.650671005 CET192.168.2.238.8.8.80x86f2Standard query (0)webhorizon.icuA (IP address)IN (0x0001)false
                                                        Jan 11, 2025 14:24:17.290405035 CET192.168.2.238.8.8.80xdb9fStandard query (0)webhorizon.icuA (IP address)IN (0x0001)false
                                                        Jan 11, 2025 14:24:27.908974886 CET192.168.2.238.8.8.80x127cStandard query (0)webhorizon.icuA (IP address)IN (0x0001)false
                                                        Jan 11, 2025 14:24:30.601218939 CET192.168.2.238.8.8.80x3a6eStandard query (0)webhorizon.icuA (IP address)IN (0x0001)false
                                                        Jan 11, 2025 14:24:38.267360926 CET192.168.2.238.8.8.80x9211Standard query (0)webhorizon.icuA (IP address)IN (0x0001)false
                                                        Jan 11, 2025 14:24:46.879633904 CET192.168.2.238.8.8.80xe200Standard query (0)webhorizon.icuA (IP address)IN (0x0001)false
                                                        Jan 11, 2025 14:24:52.516130924 CET192.168.2.238.8.8.80x72f3Standard query (0)webhorizon.icuA (IP address)IN (0x0001)false
                                                        Jan 11, 2025 14:24:56.135085106 CET192.168.2.238.8.8.80xd58eStandard query (0)webhorizon.icuA (IP address)IN (0x0001)false
                                                        Jan 11, 2025 14:24:59.822698116 CET192.168.2.238.8.8.80x92c3Standard query (0)webhorizon.icuA (IP address)IN (0x0001)false
                                                        Jan 11, 2025 14:25:02.431529999 CET192.168.2.238.8.8.80x6d38Standard query (0)webhorizon.icuA (IP address)IN (0x0001)false
                                                        TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                                        Jan 11, 2025 14:23:01.079451084 CET8.8.8.8192.168.2.230xb30eNo error (0)webhorizon.icu154.213.187.118A (IP address)IN (0x0001)false
                                                        Jan 11, 2025 14:23:04.984570026 CET8.8.8.8192.168.2.230x3809No error (0)webhorizon.icu154.213.187.118A (IP address)IN (0x0001)false
                                                        Jan 11, 2025 14:23:11.809112072 CET8.8.8.8192.168.2.230x4245No error (0)webhorizon.icu154.213.187.118A (IP address)IN (0x0001)false
                                                        Jan 11, 2025 14:23:18.430434942 CET8.8.8.8192.168.2.230x3c91No error (0)webhorizon.icu154.213.187.118A (IP address)IN (0x0001)false
                                                        Jan 11, 2025 14:23:24.051990032 CET8.8.8.8192.168.2.230xde44No error (0)webhorizon.icu154.213.187.118A (IP address)IN (0x0001)false
                                                        Jan 11, 2025 14:23:29.824505091 CET8.8.8.8192.168.2.230x4063No error (0)webhorizon.icu154.213.187.118A (IP address)IN (0x0001)false
                                                        Jan 11, 2025 14:23:32.446811914 CET8.8.8.8192.168.2.230x46ffNo error (0)webhorizon.icu154.213.187.118A (IP address)IN (0x0001)false
                                                        Jan 11, 2025 14:23:42.085741043 CET8.8.8.8192.168.2.230xe179No error (0)webhorizon.icu154.213.187.118A (IP address)IN (0x0001)false
                                                        Jan 11, 2025 14:23:48.713119030 CET8.8.8.8192.168.2.230x7c40No error (0)webhorizon.icu154.213.187.118A (IP address)IN (0x0001)false
                                                        Jan 11, 2025 14:23:59.332886934 CET8.8.8.8192.168.2.230x9156No error (0)webhorizon.icu154.213.187.118A (IP address)IN (0x0001)false
                                                        Jan 11, 2025 14:24:09.950064898 CET8.8.8.8192.168.2.230x1a30No error (0)webhorizon.icu154.213.187.118A (IP address)IN (0x0001)false
                                                        Jan 11, 2025 14:24:12.577857971 CET8.8.8.8192.168.2.230xef1aNo error (0)webhorizon.icu154.213.187.118A (IP address)IN (0x0001)false
                                                        Jan 11, 2025 14:24:14.658123970 CET8.8.8.8192.168.2.230x86f2No error (0)webhorizon.icu154.213.187.118A (IP address)IN (0x0001)false
                                                        Jan 11, 2025 14:24:17.297502041 CET8.8.8.8192.168.2.230xdb9fNo error (0)webhorizon.icu154.213.187.118A (IP address)IN (0x0001)false
                                                        Jan 11, 2025 14:24:27.915909052 CET8.8.8.8192.168.2.230x127cNo error (0)webhorizon.icu154.213.187.118A (IP address)IN (0x0001)false
                                                        Jan 11, 2025 14:24:30.662441015 CET8.8.8.8192.168.2.230x3a6eNo error (0)webhorizon.icu154.213.187.118A (IP address)IN (0x0001)false
                                                        Jan 11, 2025 14:24:38.274745941 CET8.8.8.8192.168.2.230x9211No error (0)webhorizon.icu154.213.187.118A (IP address)IN (0x0001)false
                                                        Jan 11, 2025 14:24:46.886809111 CET8.8.8.8192.168.2.230xe200No error (0)webhorizon.icu154.213.187.118A (IP address)IN (0x0001)false
                                                        Jan 11, 2025 14:24:52.523592949 CET8.8.8.8192.168.2.230x72f3No error (0)webhorizon.icu154.213.187.118A (IP address)IN (0x0001)false
                                                        Jan 11, 2025 14:24:56.141720057 CET8.8.8.8192.168.2.230xd58eNo error (0)webhorizon.icu154.213.187.118A (IP address)IN (0x0001)false
                                                        Jan 11, 2025 14:24:59.829952955 CET8.8.8.8192.168.2.230x92c3No error (0)webhorizon.icu154.213.187.118A (IP address)IN (0x0001)false
                                                        Jan 11, 2025 14:25:02.438579082 CET8.8.8.8192.168.2.230x6d38No error (0)webhorizon.icu154.213.187.118A (IP address)IN (0x0001)false

                                                        System Behavior

                                                        Start time (UTC):13:22:59
                                                        Start date (UTC):11/01/2025
                                                        Path:/tmp/mpsl.elf
                                                        Arguments:/tmp/mpsl.elf
                                                        File size:5773336 bytes
                                                        MD5 hash:0d6f61f82cf2f781c6eb0661071d42d9

                                                        Start time (UTC):13:22:59
                                                        Start date (UTC):11/01/2025
                                                        Path:/tmp/mpsl.elf
                                                        Arguments:-
                                                        File size:5773336 bytes
                                                        MD5 hash:0d6f61f82cf2f781c6eb0661071d42d9

                                                        Start time (UTC):13:22:59
                                                        Start date (UTC):11/01/2025
                                                        Path:/tmp/mpsl.elf
                                                        Arguments:-
                                                        File size:5773336 bytes
                                                        MD5 hash:0d6f61f82cf2f781c6eb0661071d42d9

                                                        Start time (UTC):13:22:59
                                                        Start date (UTC):11/01/2025
                                                        Path:/tmp/mpsl.elf
                                                        Arguments:-
                                                        File size:5773336 bytes
                                                        MD5 hash:0d6f61f82cf2f781c6eb0661071d42d9

                                                        Start time (UTC):13:22:59
                                                        Start date (UTC):11/01/2025
                                                        Path:/tmp/mpsl.elf
                                                        Arguments:-
                                                        File size:5773336 bytes
                                                        MD5 hash:0d6f61f82cf2f781c6eb0661071d42d9