Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
arm.elf

Overview

General Information

Sample name:arm.elf
Analysis ID:1589163
MD5:436f659b243018cde3661a2504754379
SHA1:a28edeced9da46ef133f366b2ce8d46a31cf9626
SHA256:fe4724af2151cebbcc41e1dac2e8c119fc269f90f21328bfebdb869ca39832d3
Tags:elfuser-abuse_ch
Infos:

Detection

Mirai, Moobot
Score:100
Range:0 - 100
Whitelisted:false

Signatures

Antivirus / Scanner detection for submitted sample
Detected Mirai
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Suricata IDS alerts for network traffic
Yara detected Mirai
Yara detected Moobot
Sample deletes itself
Detected TCP or UDP traffic on non-standard ports
Enumerates processes within the "proc" file system
Sample has stripped symbol table
Uses the "uname" system call to query kernel version information (possible evasion)
Yara signature match

Classification

Joe Sandbox version:42.0.0 Malachite
Analysis ID:1589163
Start date and time:2025-01-11 14:32:20 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 35s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:arm.elf
Detection:MAL
Classification:mal100.troj.evad.linELF@0/0@22/0
Command:/tmp/arm.elf
PID:5544
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
done.
Standard Error:
  • system is lnxubuntu20
  • arm.elf (PID: 5544, Parent: 5462, MD5: 5ebfcae4fe2471fcc5695c2394773ff1) Arguments: /tmp/arm.elf
    • arm.elf New Fork (PID: 5546, Parent: 5544)
      • arm.elf New Fork (PID: 5548, Parent: 5546)
      • arm.elf New Fork (PID: 5550, Parent: 5546)
        • arm.elf New Fork (PID: 5552, Parent: 5550)
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
MiraiMirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese. Nowadays it targets a wide range of networked embedded devices such as IP cameras, home routers (many vendors involved), and other IoT devices. Since the source code was published on "Hack Forums" many variants of the Mirai family appeared, infecting mostly home networks all around the world.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/elf.mirai
NameDescriptionAttributionBlogpost URLsLink
MooBotNo Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/elf.moobot
SourceRuleDescriptionAuthorStrings
arm.elfJoeSecurity_MoobotYara detected MoobotJoe Security
    arm.elfJoeSecurity_Mirai_8Yara detected MiraiJoe Security
      arm.elfLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
      • 0xd170:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xd184:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xd198:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xd1ac:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xd1c0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xd1d4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xd1e8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xd1fc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xd210:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xd224:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xd238:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xd24c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xd260:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xd274:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xd288:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xd29c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xd2b0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xd2c4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xd2d8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xd2ec:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xd300:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      SourceRuleDescriptionAuthorStrings
      5544.1.00007fb008017000.00007fb008026000.r-x.sdmpJoeSecurity_MoobotYara detected MoobotJoe Security
        5544.1.00007fb008017000.00007fb008026000.r-x.sdmpJoeSecurity_Mirai_8Yara detected MiraiJoe Security
          5544.1.00007fb008017000.00007fb008026000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
          • 0xd170:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xd184:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xd198:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xd1ac:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xd1c0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xd1d4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xd1e8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xd1fc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xd210:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xd224:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xd238:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xd24c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xd260:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xd274:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xd288:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xd29c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xd2b0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xd2c4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xd2d8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xd2ec:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xd300:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          Process Memory Space: arm.elf PID: 5544JoeSecurity_MoobotYara detected MoobotJoe Security
            Process Memory Space: arm.elf PID: 5544JoeSecurity_Mirai_8Yara detected MiraiJoe Security
              Click to see the 1 entries
              TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
              2025-01-11T14:33:13.001701+010020304911Malware Command and Control Activity Detected192.168.2.1549326154.213.187.1181314TCP
              2025-01-11T14:33:18.617736+010020304911Malware Command and Control Activity Detected192.168.2.1549328154.213.187.1181314TCP
              2025-01-11T14:33:26.236792+010020304911Malware Command and Control Activity Detected192.168.2.1549330154.213.187.1181314TCP
              2025-01-11T14:33:29.861047+010020304911Malware Command and Control Activity Detected192.168.2.1549332154.213.187.1181314TCP
              2025-01-11T14:33:36.732684+010020304911Malware Command and Control Activity Detected192.168.2.1549334154.213.187.1181314TCP
              2025-01-11T14:33:41.539952+010020304911Malware Command and Control Activity Detected192.168.2.1549336154.213.187.1181314TCP
              2025-01-11T14:33:50.356211+010020304911Malware Command and Control Activity Detected192.168.2.1549338154.213.187.1181314TCP
              2025-01-11T14:33:58.995937+010020304911Malware Command and Control Activity Detected192.168.2.1549340154.213.187.1181314TCP
              2025-01-11T14:34:08.634868+010020304911Malware Command and Control Activity Detected192.168.2.1549342154.213.187.1181314TCP
              2025-01-11T14:34:16.275637+010020304911Malware Command and Control Activity Detected192.168.2.1549344154.213.187.1181314TCP
              2025-01-11T14:34:23.916333+010020304911Malware Command and Control Activity Detected192.168.2.1549346154.213.187.1181314TCP
              2025-01-11T14:34:26.537546+010020304911Malware Command and Control Activity Detected192.168.2.1549348154.213.187.1181314TCP
              2025-01-11T14:34:34.324338+010020304911Malware Command and Control Activity Detected192.168.2.1549350154.213.187.1181314TCP
              2025-01-11T14:34:37.967535+010020304911Malware Command and Control Activity Detected192.168.2.1549352154.213.187.1181314TCP
              2025-01-11T14:34:45.594443+010020304911Malware Command and Control Activity Detected192.168.2.1549354154.213.187.1181314TCP
              2025-01-11T14:34:48.207134+010020304911Malware Command and Control Activity Detected192.168.2.1549356154.213.187.1181314TCP
              2025-01-11T14:34:49.826937+010020304911Malware Command and Control Activity Detected192.168.2.1549358154.213.187.1181314TCP
              2025-01-11T14:34:58.447326+010020304911Malware Command and Control Activity Detected192.168.2.1549360154.213.187.1181314TCP
              2025-01-11T14:35:06.086941+010020304911Malware Command and Control Activity Detected192.168.2.1549362154.213.187.1181314TCP
              2025-01-11T14:35:07.699774+010020304911Malware Command and Control Activity Detected192.168.2.1549364154.213.187.1181314TCP
              2025-01-11T14:35:10.334534+010020304911Malware Command and Control Activity Detected192.168.2.1549366154.213.187.1181314TCP
              2025-01-11T14:35:13.958232+010020304911Malware Command and Control Activity Detected192.168.2.1549368154.213.187.1181314TCP

              Click to jump to signature section

              Show All Signature Results

              AV Detection

              barindex
              Source: arm.elfAvira: detected
              Source: arm.elfVirustotal: Detection: 57%Perma Link
              Source: arm.elfReversingLabs: Detection: 60%

              Networking

              barindex
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.15:49332 -> 154.213.187.118:1314
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.15:49346 -> 154.213.187.118:1314
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.15:49326 -> 154.213.187.118:1314
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.15:49336 -> 154.213.187.118:1314
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.15:49330 -> 154.213.187.118:1314
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.15:49352 -> 154.213.187.118:1314
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.15:49348 -> 154.213.187.118:1314
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.15:49338 -> 154.213.187.118:1314
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.15:49350 -> 154.213.187.118:1314
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.15:49364 -> 154.213.187.118:1314
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.15:49360 -> 154.213.187.118:1314
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.15:49356 -> 154.213.187.118:1314
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.15:49366 -> 154.213.187.118:1314
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.15:49344 -> 154.213.187.118:1314
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.15:49342 -> 154.213.187.118:1314
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.15:49368 -> 154.213.187.118:1314
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.15:49362 -> 154.213.187.118:1314
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.15:49334 -> 154.213.187.118:1314
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.15:49354 -> 154.213.187.118:1314
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.15:49340 -> 154.213.187.118:1314
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.15:49358 -> 154.213.187.118:1314
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.15:49328 -> 154.213.187.118:1314
              Source: global trafficTCP traffic: 192.168.2.15:49326 -> 154.213.187.118:1314
              Source: global trafficDNS traffic detected: DNS query: webhorizon.icu

              System Summary

              barindex
              Source: arm.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
              Source: 5544.1.00007fb008017000.00007fb008026000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
              Source: Process Memory Space: arm.elf PID: 5544, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
              Source: ELF static info symbol of initial sample.symtab present: no
              Source: arm.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
              Source: 5544.1.00007fb008017000.00007fb008026000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
              Source: Process Memory Space: arm.elf PID: 5544, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
              Source: classification engineClassification label: mal100.troj.evad.linELF@0/0@22/0
              Source: /tmp/arm.elf (PID: 5548)File opened: /proc/3882/cmdlineJump to behavior
              Source: /tmp/arm.elf (PID: 5548)File opened: /proc/110/cmdlineJump to behavior
              Source: /tmp/arm.elf (PID: 5548)File opened: /proc/231/cmdlineJump to behavior
              Source: /tmp/arm.elf (PID: 5548)File opened: /proc/111/cmdlineJump to behavior
              Source: /tmp/arm.elf (PID: 5548)File opened: /proc/112/cmdlineJump to behavior
              Source: /tmp/arm.elf (PID: 5548)File opened: /proc/233/cmdlineJump to behavior
              Source: /tmp/arm.elf (PID: 5548)File opened: /proc/113/cmdlineJump to behavior
              Source: /tmp/arm.elf (PID: 5548)File opened: /proc/114/cmdlineJump to behavior
              Source: /tmp/arm.elf (PID: 5548)File opened: /proc/235/cmdlineJump to behavior
              Source: /tmp/arm.elf (PID: 5548)File opened: /proc/115/cmdlineJump to behavior
              Source: /tmp/arm.elf (PID: 5548)File opened: /proc/1333/cmdlineJump to behavior
              Source: /tmp/arm.elf (PID: 5548)File opened: /proc/116/cmdlineJump to behavior
              Source: /tmp/arm.elf (PID: 5548)File opened: /proc/1695/cmdlineJump to behavior
              Source: /tmp/arm.elf (PID: 5548)File opened: /proc/117/cmdlineJump to behavior
              Source: /tmp/arm.elf (PID: 5548)File opened: /proc/118/cmdlineJump to behavior
              Source: /tmp/arm.elf (PID: 5548)File opened: /proc/5379/cmdlineJump to behavior
              Source: /tmp/arm.elf (PID: 5548)File opened: /proc/119/cmdlineJump to behavior
              Source: /tmp/arm.elf (PID: 5548)File opened: /proc/911/cmdlineJump to behavior
              Source: /tmp/arm.elf (PID: 5548)File opened: /proc/914/cmdlineJump to behavior
              Source: /tmp/arm.elf (PID: 5548)File opened: /proc/10/cmdlineJump to behavior
              Source: /tmp/arm.elf (PID: 5548)File opened: /proc/917/cmdlineJump to behavior
              Source: /tmp/arm.elf (PID: 5548)File opened: /proc/11/cmdlineJump to behavior
              Source: /tmp/arm.elf (PID: 5548)File opened: /proc/12/cmdlineJump to behavior
              Source: /tmp/arm.elf (PID: 5548)File opened: /proc/13/cmdlineJump to behavior
              Source: /tmp/arm.elf (PID: 5548)File opened: /proc/14/cmdlineJump to behavior
              Source: /tmp/arm.elf (PID: 5548)File opened: /proc/15/cmdlineJump to behavior
              Source: /tmp/arm.elf (PID: 5548)File opened: /proc/16/cmdlineJump to behavior
              Source: /tmp/arm.elf (PID: 5548)File opened: /proc/17/cmdlineJump to behavior
              Source: /tmp/arm.elf (PID: 5548)File opened: /proc/18/cmdlineJump to behavior
              Source: /tmp/arm.elf (PID: 5548)File opened: /proc/19/cmdlineJump to behavior
              Source: /tmp/arm.elf (PID: 5548)File opened: /proc/1591/cmdlineJump to behavior
              Source: /tmp/arm.elf (PID: 5548)File opened: /proc/120/cmdlineJump to behavior
              Source: /tmp/arm.elf (PID: 5548)File opened: /proc/121/cmdlineJump to behavior
              Source: /tmp/arm.elf (PID: 5548)File opened: /proc/1/cmdlineJump to behavior
              Source: /tmp/arm.elf (PID: 5548)File opened: /proc/122/cmdlineJump to behavior
              Source: /tmp/arm.elf (PID: 5548)File opened: /proc/243/cmdlineJump to behavior
              Source: /tmp/arm.elf (PID: 5548)File opened: /proc/2/cmdlineJump to behavior
              Source: /tmp/arm.elf (PID: 5548)File opened: /proc/123/cmdlineJump to behavior
              Source: /tmp/arm.elf (PID: 5548)File opened: /proc/3/cmdlineJump to behavior
              Source: /tmp/arm.elf (PID: 5548)File opened: /proc/124/cmdlineJump to behavior
              Source: /tmp/arm.elf (PID: 5548)File opened: /proc/1588/cmdlineJump to behavior
              Source: /tmp/arm.elf (PID: 5548)File opened: /proc/125/cmdlineJump to behavior
              Source: /tmp/arm.elf (PID: 5548)File opened: /proc/4/cmdlineJump to behavior
              Source: /tmp/arm.elf (PID: 5548)File opened: /proc/246/cmdlineJump to behavior
              Source: /tmp/arm.elf (PID: 5548)File opened: /proc/126/cmdlineJump to behavior
              Source: /tmp/arm.elf (PID: 5548)File opened: /proc/5/cmdlineJump to behavior
              Source: /tmp/arm.elf (PID: 5548)File opened: /proc/127/cmdlineJump to behavior
              Source: /tmp/arm.elf (PID: 5548)File opened: /proc/6/cmdlineJump to behavior
              Source: /tmp/arm.elf (PID: 5548)File opened: /proc/1585/cmdlineJump to behavior
              Source: /tmp/arm.elf (PID: 5548)File opened: /proc/128/cmdlineJump to behavior
              Source: /tmp/arm.elf (PID: 5548)File opened: /proc/7/cmdlineJump to behavior
              Source: /tmp/arm.elf (PID: 5548)File opened: /proc/129/cmdlineJump to behavior
              Source: /tmp/arm.elf (PID: 5548)File opened: /proc/8/cmdlineJump to behavior
              Source: /tmp/arm.elf (PID: 5548)File opened: /proc/800/cmdlineJump to behavior
              Source: /tmp/arm.elf (PID: 5548)File opened: /proc/9/cmdlineJump to behavior
              Source: /tmp/arm.elf (PID: 5548)File opened: /proc/802/cmdlineJump to behavior
              Source: /tmp/arm.elf (PID: 5548)File opened: /proc/803/cmdlineJump to behavior
              Source: /tmp/arm.elf (PID: 5548)File opened: /proc/804/cmdlineJump to behavior
              Source: /tmp/arm.elf (PID: 5548)File opened: /proc/20/cmdlineJump to behavior
              Source: /tmp/arm.elf (PID: 5548)File opened: /proc/21/cmdlineJump to behavior
              Source: /tmp/arm.elf (PID: 5548)File opened: /proc/3407/cmdlineJump to behavior
              Source: /tmp/arm.elf (PID: 5548)File opened: /proc/22/cmdlineJump to behavior
              Source: /tmp/arm.elf (PID: 5548)File opened: /proc/23/cmdlineJump to behavior
              Source: /tmp/arm.elf (PID: 5548)File opened: /proc/24/cmdlineJump to behavior
              Source: /tmp/arm.elf (PID: 5548)File opened: /proc/25/cmdlineJump to behavior
              Source: /tmp/arm.elf (PID: 5548)File opened: /proc/26/cmdlineJump to behavior
              Source: /tmp/arm.elf (PID: 5548)File opened: /proc/27/cmdlineJump to behavior
              Source: /tmp/arm.elf (PID: 5548)File opened: /proc/28/cmdlineJump to behavior
              Source: /tmp/arm.elf (PID: 5548)File opened: /proc/29/cmdlineJump to behavior
              Source: /tmp/arm.elf (PID: 5548)File opened: /proc/1484/cmdlineJump to behavior
              Source: /tmp/arm.elf (PID: 5548)File opened: /proc/490/cmdlineJump to behavior
              Source: /tmp/arm.elf (PID: 5548)File opened: /proc/250/cmdlineJump to behavior
              Source: /tmp/arm.elf (PID: 5548)File opened: /proc/130/cmdlineJump to behavior
              Source: /tmp/arm.elf (PID: 5548)File opened: /proc/251/cmdlineJump to behavior
              Source: /tmp/arm.elf (PID: 5548)File opened: /proc/131/cmdlineJump to behavior
              Source: /tmp/arm.elf (PID: 5548)File opened: /proc/132/cmdlineJump to behavior
              Source: /tmp/arm.elf (PID: 5548)File opened: /proc/133/cmdlineJump to behavior
              Source: /tmp/arm.elf (PID: 5548)File opened: /proc/1479/cmdlineJump to behavior
              Source: /tmp/arm.elf (PID: 5548)File opened: /proc/378/cmdlineJump to behavior
              Source: /tmp/arm.elf (PID: 5548)File opened: /proc/258/cmdlineJump to behavior
              Source: /tmp/arm.elf (PID: 5548)File opened: /proc/259/cmdlineJump to behavior
              Source: /tmp/arm.elf (PID: 5548)File opened: /proc/931/cmdlineJump to behavior
              Source: /tmp/arm.elf (PID: 5548)File opened: /proc/1595/cmdlineJump to behavior
              Source: /tmp/arm.elf (PID: 5548)File opened: /proc/812/cmdlineJump to behavior
              Source: /tmp/arm.elf (PID: 5548)File opened: /proc/933/cmdlineJump to behavior
              Source: /tmp/arm.elf (PID: 5548)File opened: /proc/30/cmdlineJump to behavior
              Source: /tmp/arm.elf (PID: 5548)File opened: /proc/3419/cmdlineJump to behavior
              Source: /tmp/arm.elf (PID: 5548)File opened: /proc/35/cmdlineJump to behavior
              Source: /tmp/arm.elf (PID: 5548)File opened: /proc/3310/cmdlineJump to behavior
              Source: /tmp/arm.elf (PID: 5548)File opened: /proc/260/cmdlineJump to behavior
              Source: /tmp/arm.elf (PID: 5548)File opened: /proc/261/cmdlineJump to behavior
              Source: /tmp/arm.elf (PID: 5548)File opened: /proc/262/cmdlineJump to behavior
              Source: /tmp/arm.elf (PID: 5548)File opened: /proc/142/cmdlineJump to behavior
              Source: /tmp/arm.elf (PID: 5548)File opened: /proc/263/cmdlineJump to behavior
              Source: /tmp/arm.elf (PID: 5548)File opened: /proc/264/cmdlineJump to behavior
              Source: /tmp/arm.elf (PID: 5548)File opened: /proc/265/cmdlineJump to behavior
              Source: /tmp/arm.elf (PID: 5548)File opened: /proc/145/cmdlineJump to behavior
              Source: /tmp/arm.elf (PID: 5548)File opened: /proc/266/cmdlineJump to behavior
              Source: /tmp/arm.elf (PID: 5548)File opened: /proc/267/cmdlineJump to behavior
              Source: /tmp/arm.elf (PID: 5548)File opened: /proc/268/cmdlineJump to behavior
              Source: /tmp/arm.elf (PID: 5548)File opened: /proc/3303/cmdlineJump to behavior
              Source: /tmp/arm.elf (PID: 5548)File opened: /proc/269/cmdlineJump to behavior
              Source: /tmp/arm.elf (PID: 5548)File opened: /proc/1486/cmdlineJump to behavior
              Source: /tmp/arm.elf (PID: 5548)File opened: /proc/1806/cmdlineJump to behavior
              Source: /tmp/arm.elf (PID: 5548)File opened: /proc/3440/cmdlineJump to behavior

              Hooking and other Techniques for Hiding and Protection

              barindex
              Source: /tmp/arm.elf (PID: 5544)File: /tmp/arm.elfJump to behavior
              Source: /tmp/arm.elf (PID: 5544)Queries kernel information via 'uname': Jump to behavior
              Source: arm.elf, 5544.1.00007ffc3befa000.00007ffc3bf1b000.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-arm/tmp/arm.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/arm.elf
              Source: arm.elf, 5544.1.00005607820e5000.0000560782213000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/arm
              Source: arm.elf, 5544.1.00007ffc3befa000.00007ffc3bf1b000.rw-.sdmpBinary or memory string: /usr/bin/qemu-arm
              Source: arm.elf, 5544.1.00005607820e5000.0000560782213000.rw-.sdmpBinary or memory string: V!/etc/qemu-binfmt/arm

              Stealing of Sensitive Information

              barindex
              Source: Yara matchFile source: arm.elf, type: SAMPLE
              Source: Yara matchFile source: 5544.1.00007fb008017000.00007fb008026000.r-x.sdmp, type: MEMORY
              Source: Yara matchFile source: Process Memory Space: arm.elf PID: 5544, type: MEMORYSTR
              Source: Yara matchFile source: arm.elf, type: SAMPLE
              Source: Yara matchFile source: 5544.1.00007fb008017000.00007fb008026000.r-x.sdmp, type: MEMORY
              Source: Yara matchFile source: Process Memory Space: arm.elf PID: 5544, type: MEMORYSTR

              Remote Access Functionality

              barindex
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: Yara matchFile source: arm.elf, type: SAMPLE
              Source: Yara matchFile source: 5544.1.00007fb008017000.00007fb008026000.r-x.sdmp, type: MEMORY
              Source: Yara matchFile source: Process Memory Space: arm.elf PID: 5544, type: MEMORYSTR
              Source: Yara matchFile source: arm.elf, type: SAMPLE
              Source: Yara matchFile source: 5544.1.00007fb008017000.00007fb008026000.r-x.sdmp, type: MEMORY
              Source: Yara matchFile source: Process Memory Space: arm.elf PID: 5544, type: MEMORYSTR
              ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
              Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception1
              File Deletion
              1
              OS Credential Dumping
              11
              Security Software Discovery
              Remote ServicesData from Local System1
              Non-Standard Port
              Exfiltration Over Other Network MediumAbuse Accessibility Features
              CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
              Non-Application Layer Protocol
              Exfiltration Over BluetoothNetwork Denial of Service
              Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
              Application Layer Protocol
              Automated ExfiltrationData Encrypted for Impact
              No configs have been found
              Hide Legend

              Legend:

              • Process
              • Signature
              • Created File
              • DNS/IP Info
              • Is Dropped
              • Number of created Files
              • Is malicious
              • Internet
              behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1589163 Sample: arm.elf Startdate: 11/01/2025 Architecture: LINUX Score: 100 20 webhorizon.icu 154.213.187.118, 1314, 49326, 49328 DDOSING-BGP-NETWORKUS Seychelles 2->20 22 Suricata IDS alerts for network traffic 2->22 24 Malicious sample detected (through community Yara rule) 2->24 26 Antivirus / Scanner detection for submitted sample 2->26 28 4 other signatures 2->28 9 arm.elf 2->9         started        signatures3 process4 signatures5 30 Sample deletes itself 9->30 12 arm.elf 9->12         started        process6 process7 14 arm.elf 12->14         started        16 arm.elf 12->16         started        process8 18 arm.elf 14->18         started       
              SourceDetectionScannerLabelLink
              arm.elf57%VirustotalBrowse
              arm.elf61%ReversingLabsLinux.Trojan.Mirai
              arm.elf100%AviraEXP/ELF.Mirai.Z.A
              No Antivirus matches
              No Antivirus matches
              No Antivirus matches
              NameIPActiveMaliciousAntivirus DetectionReputation
              webhorizon.icu
              154.213.187.118
              truefalse
                high
                • No. of IPs < 25%
                • 25% < No. of IPs < 50%
                • 50% < No. of IPs < 75%
                • 75% < No. of IPs
                IPDomainCountryFlagASNASN NameMalicious
                154.213.187.118
                webhorizon.icuSeychelles
                22769DDOSING-BGP-NETWORKUSfalse
                MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                154.213.187.118m68k.elfGet hashmaliciousMirai, MoobotBrowse
                  x86.elfGet hashmaliciousMirai, MoobotBrowse
                    mpsl.elfGet hashmaliciousMirai, MoobotBrowse
                      mips.elfGet hashmaliciousMirai, MoobotBrowse
                        x86_64.elfGet hashmaliciousMirai, MoobotBrowse
                          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                          webhorizon.icum68k.elfGet hashmaliciousMirai, MoobotBrowse
                          • 154.213.187.118
                          x86.elfGet hashmaliciousMirai, MoobotBrowse
                          • 154.213.187.118
                          mpsl.elfGet hashmaliciousMirai, MoobotBrowse
                          • 154.213.187.118
                          mips.elfGet hashmaliciousMirai, MoobotBrowse
                          • 154.213.187.118
                          x86_64.elfGet hashmaliciousMirai, MoobotBrowse
                          • 154.213.187.118
                          arm.elfGet hashmaliciousMirai, MoobotBrowse
                          • 38.55.246.3
                          m68k.elfGet hashmaliciousMirai, MoobotBrowse
                          • 38.55.246.3
                          ppc.elfGet hashmaliciousMirai, MoobotBrowse
                          • 38.55.246.3
                          mpsl.elfGet hashmaliciousMirai, MoobotBrowse
                          • 38.55.246.3
                          debug.dbg.elfGet hashmaliciousMirai, MoobotBrowse
                          • 38.55.246.3
                          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                          DDOSING-BGP-NETWORKUSm68k.elfGet hashmaliciousMirai, MoobotBrowse
                          • 154.213.187.118
                          x86.elfGet hashmaliciousMirai, MoobotBrowse
                          • 154.213.187.118
                          mpsl.elfGet hashmaliciousMirai, MoobotBrowse
                          • 154.213.187.118
                          mips.elfGet hashmaliciousMirai, MoobotBrowse
                          • 154.213.187.118
                          x86_64.elfGet hashmaliciousMirai, MoobotBrowse
                          • 154.213.187.118
                          4.elfGet hashmaliciousUnknownBrowse
                          • 41.93.138.131
                          armv5l.elfGet hashmaliciousUnknownBrowse
                          • 41.93.222.47
                          gmpsl.elfGet hashmaliciousUnknownBrowse
                          • 154.213.187.125
                          garm5.elfGet hashmaliciousUnknownBrowse
                          • 154.213.187.125
                          garm7.elfGet hashmaliciousMiraiBrowse
                          • 154.213.187.125
                          No context
                          No context
                          No created / dropped files found
                          File type:ELF 32-bit LSB executable, ARM, version 1 (ARM), statically linked, stripped
                          Entropy (8bit):6.097917883380458
                          TrID:
                          • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                          File name:arm.elf
                          File size:61'256 bytes
                          MD5:436f659b243018cde3661a2504754379
                          SHA1:a28edeced9da46ef133f366b2ce8d46a31cf9626
                          SHA256:fe4724af2151cebbcc41e1dac2e8c119fc269f90f21328bfebdb869ca39832d3
                          SHA512:a43f3f9dd3af4d85ee79d7ae2c69997f3f9169322777857a8ec5d0a33edec053dc6c1ed3459d1c0644289b4b92d7d398fac1656235ff06d0504b4e2e12fea6d3
                          SSDEEP:1536:qfM5Ug0HC5oqTJA9hB7JkGQ8DGgLgv6nw:2MfoxJ88it6nw
                          TLSH:5F533951F8815623C6D1127BF66E428D3B2623E8E2DF73079D225F2037C692B0DABE55
                          File Content Preview:.ELF...a..........(.........4...........4. ...(.....................................................h...<%..........Q.td..................................-...L."....3..........0@-.\P...0....S.0...P@...0... ....R......0...0...........0... ....R..... 0....S

                          ELF header

                          Class:ELF32
                          Data:2's complement, little endian
                          Version:1 (current)
                          Machine:ARM
                          Version Number:0x1
                          Type:EXEC (Executable file)
                          OS/ABI:ARM - ABI
                          ABI Version:0
                          Entry Point Address:0x8190
                          Flags:0x202
                          ELF Header Size:52
                          Program Header Offset:52
                          Program Header Size:32
                          Number of Program Headers:3
                          Section Header Offset:60856
                          Section Header Size:40
                          Number of Section Headers:10
                          Header String Table Index:9
                          NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                          NULL0x00x00x00x00x0000
                          .initPROGBITS0x80940x940x180x00x6AX004
                          .textPROGBITS0x80b00xb00xcfd00x00x6AX0016
                          .finiPROGBITS0x150800xd0800x140x00x6AX004
                          .rodataPROGBITS0x150940xd0940x19780x00x2A004
                          .ctorsPROGBITS0x1ea100xea100x80x00x3WA004
                          .dtorsPROGBITS0x1ea180xea180x80x00x3WA004
                          .dataPROGBITS0x1ea240xea240x3540x00x3WA004
                          .bssNOBITS0x1ed780xed780x21d40x00x3WA004
                          .shstrtabSTRTAB0x00xed780x3e0x00x0001
                          TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                          LOAD0x00x80000x80000xea0c0xea0c6.13580x5R E0x8000.init .text .fini .rodata
                          LOAD0xea100x1ea100x1ea100x3680x253c2.64340x6RW 0x8000.ctors .dtors .data .bss
                          GNU_STACK0x00x00x00x00x00.00000x7RWE0x4
                          TimestampSIDSignatureSeveritySource IPSource PortDest IPDest PortProtocol
                          2025-01-11T14:33:13.001701+01002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.1549326154.213.187.1181314TCP
                          2025-01-11T14:33:18.617736+01002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.1549328154.213.187.1181314TCP
                          2025-01-11T14:33:26.236792+01002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.1549330154.213.187.1181314TCP
                          2025-01-11T14:33:29.861047+01002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.1549332154.213.187.1181314TCP
                          2025-01-11T14:33:36.732684+01002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.1549334154.213.187.1181314TCP
                          2025-01-11T14:33:41.539952+01002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.1549336154.213.187.1181314TCP
                          2025-01-11T14:33:50.356211+01002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.1549338154.213.187.1181314TCP
                          2025-01-11T14:33:58.995937+01002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.1549340154.213.187.1181314TCP
                          2025-01-11T14:34:08.634868+01002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.1549342154.213.187.1181314TCP
                          2025-01-11T14:34:16.275637+01002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.1549344154.213.187.1181314TCP
                          2025-01-11T14:34:23.916333+01002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.1549346154.213.187.1181314TCP
                          2025-01-11T14:34:26.537546+01002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.1549348154.213.187.1181314TCP
                          2025-01-11T14:34:34.324338+01002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.1549350154.213.187.1181314TCP
                          2025-01-11T14:34:37.967535+01002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.1549352154.213.187.1181314TCP
                          2025-01-11T14:34:45.594443+01002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.1549354154.213.187.1181314TCP
                          2025-01-11T14:34:48.207134+01002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.1549356154.213.187.1181314TCP
                          2025-01-11T14:34:49.826937+01002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.1549358154.213.187.1181314TCP
                          2025-01-11T14:34:58.447326+01002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.1549360154.213.187.1181314TCP
                          2025-01-11T14:35:06.086941+01002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.1549362154.213.187.1181314TCP
                          2025-01-11T14:35:07.699774+01002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.1549364154.213.187.1181314TCP
                          2025-01-11T14:35:10.334534+01002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.1549366154.213.187.1181314TCP
                          2025-01-11T14:35:13.958232+01002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.1549368154.213.187.1181314TCP
                          TimestampSource PortDest PortSource IPDest IP
                          Jan 11, 2025 14:33:12.993225098 CET493261314192.168.2.15154.213.187.118
                          Jan 11, 2025 14:33:12.998066902 CET131449326154.213.187.118192.168.2.15
                          Jan 11, 2025 14:33:12.998119116 CET493261314192.168.2.15154.213.187.118
                          Jan 11, 2025 14:33:13.001701117 CET493261314192.168.2.15154.213.187.118
                          Jan 11, 2025 14:33:13.006441116 CET131449326154.213.187.118192.168.2.15
                          Jan 11, 2025 14:33:13.600378036 CET131449326154.213.187.118192.168.2.15
                          Jan 11, 2025 14:33:13.600770950 CET493261314192.168.2.15154.213.187.118
                          Jan 11, 2025 14:33:13.605684042 CET131449326154.213.187.118192.168.2.15
                          Jan 11, 2025 14:33:18.612025023 CET493281314192.168.2.15154.213.187.118
                          Jan 11, 2025 14:33:18.616895914 CET131449328154.213.187.118192.168.2.15
                          Jan 11, 2025 14:33:18.617003918 CET493281314192.168.2.15154.213.187.118
                          Jan 11, 2025 14:33:18.617736101 CET493281314192.168.2.15154.213.187.118
                          Jan 11, 2025 14:33:18.622526884 CET131449328154.213.187.118192.168.2.15
                          Jan 11, 2025 14:33:19.219906092 CET131449328154.213.187.118192.168.2.15
                          Jan 11, 2025 14:33:19.220290899 CET493281314192.168.2.15154.213.187.118
                          Jan 11, 2025 14:33:19.225425959 CET131449328154.213.187.118192.168.2.15
                          Jan 11, 2025 14:33:26.230961084 CET493301314192.168.2.15154.213.187.118
                          Jan 11, 2025 14:33:26.235872030 CET131449330154.213.187.118192.168.2.15
                          Jan 11, 2025 14:33:26.235974073 CET493301314192.168.2.15154.213.187.118
                          Jan 11, 2025 14:33:26.236792088 CET493301314192.168.2.15154.213.187.118
                          Jan 11, 2025 14:33:26.241671085 CET131449330154.213.187.118192.168.2.15
                          Jan 11, 2025 14:33:26.842020988 CET131449330154.213.187.118192.168.2.15
                          Jan 11, 2025 14:33:26.842458010 CET493301314192.168.2.15154.213.187.118
                          Jan 11, 2025 14:33:26.847387075 CET131449330154.213.187.118192.168.2.15
                          Jan 11, 2025 14:33:29.854696989 CET493321314192.168.2.15154.213.187.118
                          Jan 11, 2025 14:33:29.859906912 CET131449332154.213.187.118192.168.2.15
                          Jan 11, 2025 14:33:29.859991074 CET493321314192.168.2.15154.213.187.118
                          Jan 11, 2025 14:33:29.861047029 CET493321314192.168.2.15154.213.187.118
                          Jan 11, 2025 14:33:29.865983963 CET131449332154.213.187.118192.168.2.15
                          Jan 11, 2025 14:33:30.463063955 CET131449332154.213.187.118192.168.2.15
                          Jan 11, 2025 14:33:30.463361979 CET493321314192.168.2.15154.213.187.118
                          Jan 11, 2025 14:33:30.468569040 CET131449332154.213.187.118192.168.2.15
                          Jan 11, 2025 14:33:36.726988077 CET493341314192.168.2.15154.213.187.118
                          Jan 11, 2025 14:33:36.731889009 CET131449334154.213.187.118192.168.2.15
                          Jan 11, 2025 14:33:36.731945992 CET493341314192.168.2.15154.213.187.118
                          Jan 11, 2025 14:33:36.732683897 CET493341314192.168.2.15154.213.187.118
                          Jan 11, 2025 14:33:36.737523079 CET131449334154.213.187.118192.168.2.15
                          Jan 11, 2025 14:33:37.342895031 CET131449334154.213.187.118192.168.2.15
                          Jan 11, 2025 14:33:37.343123913 CET493341314192.168.2.15154.213.187.118
                          Jan 11, 2025 14:33:37.347989082 CET131449334154.213.187.118192.168.2.15
                          Jan 11, 2025 14:33:41.533610106 CET493361314192.168.2.15154.213.187.118
                          Jan 11, 2025 14:33:41.538472891 CET131449336154.213.187.118192.168.2.15
                          Jan 11, 2025 14:33:41.538548946 CET493361314192.168.2.15154.213.187.118
                          Jan 11, 2025 14:33:41.539952040 CET493361314192.168.2.15154.213.187.118
                          Jan 11, 2025 14:33:41.544806004 CET131449336154.213.187.118192.168.2.15
                          Jan 11, 2025 14:33:42.149480104 CET131449336154.213.187.118192.168.2.15
                          Jan 11, 2025 14:33:42.149652958 CET493361314192.168.2.15154.213.187.118
                          Jan 11, 2025 14:33:42.154532909 CET131449336154.213.187.118192.168.2.15
                          Jan 11, 2025 14:33:50.350260973 CET493381314192.168.2.15154.213.187.118
                          Jan 11, 2025 14:33:50.355195045 CET131449338154.213.187.118192.168.2.15
                          Jan 11, 2025 14:33:50.355284929 CET493381314192.168.2.15154.213.187.118
                          Jan 11, 2025 14:33:50.356210947 CET493381314192.168.2.15154.213.187.118
                          Jan 11, 2025 14:33:50.361118078 CET131449338154.213.187.118192.168.2.15
                          Jan 11, 2025 14:33:50.978710890 CET131449338154.213.187.118192.168.2.15
                          Jan 11, 2025 14:33:50.979013920 CET493381314192.168.2.15154.213.187.118
                          Jan 11, 2025 14:33:50.983838081 CET131449338154.213.187.118192.168.2.15
                          Jan 11, 2025 14:33:58.989875078 CET493401314192.168.2.15154.213.187.118
                          Jan 11, 2025 14:33:58.994880915 CET131449340154.213.187.118192.168.2.15
                          Jan 11, 2025 14:33:58.995066881 CET493401314192.168.2.15154.213.187.118
                          Jan 11, 2025 14:33:58.995937109 CET493401314192.168.2.15154.213.187.118
                          Jan 11, 2025 14:33:59.001163960 CET131449340154.213.187.118192.168.2.15
                          Jan 11, 2025 14:33:59.617307901 CET131449340154.213.187.118192.168.2.15
                          Jan 11, 2025 14:33:59.617650986 CET493401314192.168.2.15154.213.187.118
                          Jan 11, 2025 14:33:59.622572899 CET131449340154.213.187.118192.168.2.15
                          Jan 11, 2025 14:34:08.628129005 CET493421314192.168.2.15154.213.187.118
                          Jan 11, 2025 14:34:08.633857012 CET131449342154.213.187.118192.168.2.15
                          Jan 11, 2025 14:34:08.633925915 CET493421314192.168.2.15154.213.187.118
                          Jan 11, 2025 14:34:08.634867907 CET493421314192.168.2.15154.213.187.118
                          Jan 11, 2025 14:34:08.640255928 CET131449342154.213.187.118192.168.2.15
                          Jan 11, 2025 14:34:09.256731033 CET131449342154.213.187.118192.168.2.15
                          Jan 11, 2025 14:34:09.257095098 CET493421314192.168.2.15154.213.187.118
                          Jan 11, 2025 14:34:09.262006044 CET131449342154.213.187.118192.168.2.15
                          Jan 11, 2025 14:34:16.269062042 CET493441314192.168.2.15154.213.187.118
                          Jan 11, 2025 14:34:16.273988962 CET131449344154.213.187.118192.168.2.15
                          Jan 11, 2025 14:34:16.274085999 CET493441314192.168.2.15154.213.187.118
                          Jan 11, 2025 14:34:16.275636911 CET493441314192.168.2.15154.213.187.118
                          Jan 11, 2025 14:34:16.280467033 CET131449344154.213.187.118192.168.2.15
                          Jan 11, 2025 14:34:16.897344112 CET131449344154.213.187.118192.168.2.15
                          Jan 11, 2025 14:34:16.897918940 CET493441314192.168.2.15154.213.187.118
                          Jan 11, 2025 14:34:16.903177977 CET131449344154.213.187.118192.168.2.15
                          Jan 11, 2025 14:34:23.909953117 CET493461314192.168.2.15154.213.187.118
                          Jan 11, 2025 14:34:23.914911985 CET131449346154.213.187.118192.168.2.15
                          Jan 11, 2025 14:34:23.915016890 CET493461314192.168.2.15154.213.187.118
                          Jan 11, 2025 14:34:23.916332960 CET493461314192.168.2.15154.213.187.118
                          Jan 11, 2025 14:34:23.921186924 CET131449346154.213.187.118192.168.2.15
                          Jan 11, 2025 14:34:24.518811941 CET131449346154.213.187.118192.168.2.15
                          Jan 11, 2025 14:34:24.519067049 CET493461314192.168.2.15154.213.187.118
                          Jan 11, 2025 14:34:24.524147987 CET131449346154.213.187.118192.168.2.15
                          Jan 11, 2025 14:34:26.531194925 CET493481314192.168.2.15154.213.187.118
                          Jan 11, 2025 14:34:26.536200047 CET131449348154.213.187.118192.168.2.15
                          Jan 11, 2025 14:34:26.536287069 CET493481314192.168.2.15154.213.187.118
                          Jan 11, 2025 14:34:26.537545919 CET493481314192.168.2.15154.213.187.118
                          Jan 11, 2025 14:34:26.542417049 CET131449348154.213.187.118192.168.2.15
                          Jan 11, 2025 14:34:27.140183926 CET131449348154.213.187.118192.168.2.15
                          Jan 11, 2025 14:34:27.140355110 CET493481314192.168.2.15154.213.187.118
                          Jan 11, 2025 14:34:27.145370960 CET131449348154.213.187.118192.168.2.15
                          Jan 11, 2025 14:34:34.318039894 CET493501314192.168.2.15154.213.187.118
                          Jan 11, 2025 14:34:34.323026896 CET131449350154.213.187.118192.168.2.15
                          Jan 11, 2025 14:34:34.323118925 CET493501314192.168.2.15154.213.187.118
                          Jan 11, 2025 14:34:34.324337959 CET493501314192.168.2.15154.213.187.118
                          Jan 11, 2025 14:34:34.329180002 CET131449350154.213.187.118192.168.2.15
                          Jan 11, 2025 14:34:34.945431948 CET131449350154.213.187.118192.168.2.15
                          Jan 11, 2025 14:34:34.945799112 CET493501314192.168.2.15154.213.187.118
                          Jan 11, 2025 14:34:34.950670004 CET131449350154.213.187.118192.168.2.15
                          Jan 11, 2025 14:34:37.960819006 CET493521314192.168.2.15154.213.187.118
                          Jan 11, 2025 14:34:37.965750933 CET131449352154.213.187.118192.168.2.15
                          Jan 11, 2025 14:34:37.965847969 CET493521314192.168.2.15154.213.187.118
                          Jan 11, 2025 14:34:37.967535019 CET493521314192.168.2.15154.213.187.118
                          Jan 11, 2025 14:34:37.972299099 CET131449352154.213.187.118192.168.2.15
                          Jan 11, 2025 14:34:38.576356888 CET131449352154.213.187.118192.168.2.15
                          Jan 11, 2025 14:34:38.576814890 CET493521314192.168.2.15154.213.187.118
                          Jan 11, 2025 14:34:38.581706047 CET131449352154.213.187.118192.168.2.15
                          Jan 11, 2025 14:34:45.588248968 CET493541314192.168.2.15154.213.187.118
                          Jan 11, 2025 14:34:45.593216896 CET131449354154.213.187.118192.168.2.15
                          Jan 11, 2025 14:34:45.593327999 CET493541314192.168.2.15154.213.187.118
                          Jan 11, 2025 14:34:45.594443083 CET493541314192.168.2.15154.213.187.118
                          Jan 11, 2025 14:34:45.599311113 CET131449354154.213.187.118192.168.2.15
                          Jan 11, 2025 14:34:46.188832045 CET131449354154.213.187.118192.168.2.15
                          Jan 11, 2025 14:34:46.189138889 CET493541314192.168.2.15154.213.187.118
                          Jan 11, 2025 14:34:46.194118977 CET131449354154.213.187.118192.168.2.15
                          Jan 11, 2025 14:34:48.200874090 CET493561314192.168.2.15154.213.187.118
                          Jan 11, 2025 14:34:48.205801010 CET131449356154.213.187.118192.168.2.15
                          Jan 11, 2025 14:34:48.205885887 CET493561314192.168.2.15154.213.187.118
                          Jan 11, 2025 14:34:48.207134008 CET493561314192.168.2.15154.213.187.118
                          Jan 11, 2025 14:34:48.212027073 CET131449356154.213.187.118192.168.2.15
                          Jan 11, 2025 14:34:48.810123920 CET131449356154.213.187.118192.168.2.15
                          Jan 11, 2025 14:34:48.810410023 CET493561314192.168.2.15154.213.187.118
                          Jan 11, 2025 14:34:48.815476894 CET131449356154.213.187.118192.168.2.15
                          Jan 11, 2025 14:34:49.821069002 CET493581314192.168.2.15154.213.187.118
                          Jan 11, 2025 14:34:49.826010942 CET131449358154.213.187.118192.168.2.15
                          Jan 11, 2025 14:34:49.826077938 CET493581314192.168.2.15154.213.187.118
                          Jan 11, 2025 14:34:49.826936960 CET493581314192.168.2.15154.213.187.118
                          Jan 11, 2025 14:34:49.831883907 CET131449358154.213.187.118192.168.2.15
                          Jan 11, 2025 14:34:50.429404974 CET131449358154.213.187.118192.168.2.15
                          Jan 11, 2025 14:34:50.429675102 CET493581314192.168.2.15154.213.187.118
                          Jan 11, 2025 14:34:50.434529066 CET131449358154.213.187.118192.168.2.15
                          Jan 11, 2025 14:34:58.440939903 CET493601314192.168.2.15154.213.187.118
                          Jan 11, 2025 14:34:58.445935965 CET131449360154.213.187.118192.168.2.15
                          Jan 11, 2025 14:34:58.446007967 CET493601314192.168.2.15154.213.187.118
                          Jan 11, 2025 14:34:58.447325945 CET493601314192.168.2.15154.213.187.118
                          Jan 11, 2025 14:34:58.452219963 CET131449360154.213.187.118192.168.2.15
                          Jan 11, 2025 14:34:59.069704056 CET131449360154.213.187.118192.168.2.15
                          Jan 11, 2025 14:34:59.069889069 CET493601314192.168.2.15154.213.187.118
                          Jan 11, 2025 14:34:59.074740887 CET131449360154.213.187.118192.168.2.15
                          Jan 11, 2025 14:35:06.080892086 CET493621314192.168.2.15154.213.187.118
                          Jan 11, 2025 14:35:06.085797071 CET131449362154.213.187.118192.168.2.15
                          Jan 11, 2025 14:35:06.085922956 CET493621314192.168.2.15154.213.187.118
                          Jan 11, 2025 14:35:06.086941004 CET493621314192.168.2.15154.213.187.118
                          Jan 11, 2025 14:35:06.091782093 CET131449362154.213.187.118192.168.2.15
                          Jan 11, 2025 14:35:06.680855036 CET131449362154.213.187.118192.168.2.15
                          Jan 11, 2025 14:35:06.681206942 CET493621314192.168.2.15154.213.187.118
                          Jan 11, 2025 14:35:06.686074018 CET131449362154.213.187.118192.168.2.15
                          Jan 11, 2025 14:35:07.693423986 CET493641314192.168.2.15154.213.187.118
                          Jan 11, 2025 14:35:07.698344946 CET131449364154.213.187.118192.168.2.15
                          Jan 11, 2025 14:35:07.698419094 CET493641314192.168.2.15154.213.187.118
                          Jan 11, 2025 14:35:07.699774027 CET493641314192.168.2.15154.213.187.118
                          Jan 11, 2025 14:35:07.704632998 CET131449364154.213.187.118192.168.2.15
                          Jan 11, 2025 14:35:08.309583902 CET131449364154.213.187.118192.168.2.15
                          Jan 11, 2025 14:35:08.310002089 CET493641314192.168.2.15154.213.187.118
                          Jan 11, 2025 14:35:08.314965963 CET131449364154.213.187.118192.168.2.15
                          Jan 11, 2025 14:35:10.325186014 CET493661314192.168.2.15154.213.187.118
                          Jan 11, 2025 14:35:10.332626104 CET131449366154.213.187.118192.168.2.15
                          Jan 11, 2025 14:35:10.332734108 CET493661314192.168.2.15154.213.187.118
                          Jan 11, 2025 14:35:10.334533930 CET493661314192.168.2.15154.213.187.118
                          Jan 11, 2025 14:35:10.340935946 CET131449366154.213.187.118192.168.2.15
                          Jan 11, 2025 14:35:10.940207005 CET131449366154.213.187.118192.168.2.15
                          Jan 11, 2025 14:35:10.940640926 CET493661314192.168.2.15154.213.187.118
                          Jan 11, 2025 14:35:10.945564032 CET131449366154.213.187.118192.168.2.15
                          Jan 11, 2025 14:35:13.952295065 CET493681314192.168.2.15154.213.187.118
                          Jan 11, 2025 14:35:13.957153082 CET131449368154.213.187.118192.168.2.15
                          Jan 11, 2025 14:35:13.957216978 CET493681314192.168.2.15154.213.187.118
                          Jan 11, 2025 14:35:13.958231926 CET493681314192.168.2.15154.213.187.118
                          Jan 11, 2025 14:35:13.963057995 CET131449368154.213.187.118192.168.2.15
                          Jan 11, 2025 14:35:14.587990046 CET131449368154.213.187.118192.168.2.15
                          Jan 11, 2025 14:35:14.588315010 CET493681314192.168.2.15154.213.187.118
                          Jan 11, 2025 14:35:14.593226910 CET131449368154.213.187.118192.168.2.15
                          TimestampSource PortDest PortSource IPDest IP
                          Jan 11, 2025 14:33:12.983997107 CET4352453192.168.2.158.8.8.8
                          Jan 11, 2025 14:33:12.991223097 CET53435248.8.8.8192.168.2.15
                          Jan 11, 2025 14:33:18.603840113 CET4655353192.168.2.158.8.8.8
                          Jan 11, 2025 14:33:18.611557961 CET53465538.8.8.8192.168.2.15
                          Jan 11, 2025 14:33:26.223011971 CET3786353192.168.2.158.8.8.8
                          Jan 11, 2025 14:33:26.230456114 CET53378638.8.8.8192.168.2.15
                          Jan 11, 2025 14:33:29.845959902 CET5170753192.168.2.158.8.8.8
                          Jan 11, 2025 14:33:29.853636980 CET53517078.8.8.8192.168.2.15
                          Jan 11, 2025 14:33:36.466473103 CET4719153192.168.2.158.8.8.8
                          Jan 11, 2025 14:33:36.726121902 CET53471918.8.8.8192.168.2.15
                          Jan 11, 2025 14:33:41.345504045 CET5585253192.168.2.158.8.8.8
                          Jan 11, 2025 14:33:41.532088995 CET53558528.8.8.8192.168.2.15
                          Jan 11, 2025 14:33:50.152496099 CET3383453192.168.2.158.8.8.8
                          Jan 11, 2025 14:33:50.349303961 CET53338348.8.8.8192.168.2.15
                          Jan 11, 2025 14:33:58.981708050 CET4696153192.168.2.158.8.8.8
                          Jan 11, 2025 14:33:58.989018917 CET53469618.8.8.8192.168.2.15
                          Jan 11, 2025 14:34:08.620182991 CET3334753192.168.2.158.8.8.8
                          Jan 11, 2025 14:34:08.627475977 CET53333478.8.8.8192.168.2.15
                          Jan 11, 2025 14:34:16.260442019 CET4146153192.168.2.158.8.8.8
                          Jan 11, 2025 14:34:16.268199921 CET53414618.8.8.8192.168.2.15
                          Jan 11, 2025 14:34:23.902266026 CET4031953192.168.2.158.8.8.8
                          Jan 11, 2025 14:34:23.909204960 CET53403198.8.8.8192.168.2.15
                          Jan 11, 2025 14:34:26.523051977 CET5814753192.168.2.158.8.8.8
                          Jan 11, 2025 14:34:26.530464888 CET53581478.8.8.8192.168.2.15
                          Jan 11, 2025 14:34:34.144319057 CET4440553192.168.2.158.8.8.8
                          Jan 11, 2025 14:34:34.316905975 CET53444058.8.8.8192.168.2.15
                          Jan 11, 2025 14:34:37.949697018 CET4516153192.168.2.158.8.8.8
                          Jan 11, 2025 14:34:37.959894896 CET53451618.8.8.8192.168.2.15
                          Jan 11, 2025 14:34:45.580427885 CET3357953192.168.2.158.8.8.8
                          Jan 11, 2025 14:34:45.587491989 CET53335798.8.8.8192.168.2.15
                          Jan 11, 2025 14:34:48.192852974 CET5374853192.168.2.158.8.8.8
                          Jan 11, 2025 14:34:48.200048923 CET53537488.8.8.8192.168.2.15
                          Jan 11, 2025 14:34:49.813302040 CET3320253192.168.2.158.8.8.8
                          Jan 11, 2025 14:34:49.820559978 CET53332028.8.8.8192.168.2.15
                          Jan 11, 2025 14:34:58.433152914 CET5464153192.168.2.158.8.8.8
                          Jan 11, 2025 14:34:58.440227985 CET53546418.8.8.8192.168.2.15
                          Jan 11, 2025 14:35:06.072943926 CET3937553192.168.2.158.8.8.8
                          Jan 11, 2025 14:35:06.080137968 CET53393758.8.8.8192.168.2.15
                          Jan 11, 2025 14:35:07.685117006 CET5905853192.168.2.158.8.8.8
                          Jan 11, 2025 14:35:07.692523003 CET53590588.8.8.8192.168.2.15
                          Jan 11, 2025 14:35:10.313694954 CET4335753192.168.2.158.8.8.8
                          Jan 11, 2025 14:35:10.324153900 CET53433578.8.8.8192.168.2.15
                          Jan 11, 2025 14:35:13.944036961 CET5966853192.168.2.158.8.8.8
                          Jan 11, 2025 14:35:13.951380014 CET53596688.8.8.8192.168.2.15
                          TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                          Jan 11, 2025 14:33:12.983997107 CET192.168.2.158.8.8.80xb402Standard query (0)webhorizon.icuA (IP address)IN (0x0001)false
                          Jan 11, 2025 14:33:18.603840113 CET192.168.2.158.8.8.80x5df5Standard query (0)webhorizon.icuA (IP address)IN (0x0001)false
                          Jan 11, 2025 14:33:26.223011971 CET192.168.2.158.8.8.80x177bStandard query (0)webhorizon.icuA (IP address)IN (0x0001)false
                          Jan 11, 2025 14:33:29.845959902 CET192.168.2.158.8.8.80x8468Standard query (0)webhorizon.icuA (IP address)IN (0x0001)false
                          Jan 11, 2025 14:33:36.466473103 CET192.168.2.158.8.8.80xd75fStandard query (0)webhorizon.icuA (IP address)IN (0x0001)false
                          Jan 11, 2025 14:33:41.345504045 CET192.168.2.158.8.8.80x723fStandard query (0)webhorizon.icuA (IP address)IN (0x0001)false
                          Jan 11, 2025 14:33:50.152496099 CET192.168.2.158.8.8.80xb18eStandard query (0)webhorizon.icuA (IP address)IN (0x0001)false
                          Jan 11, 2025 14:33:58.981708050 CET192.168.2.158.8.8.80xce81Standard query (0)webhorizon.icuA (IP address)IN (0x0001)false
                          Jan 11, 2025 14:34:08.620182991 CET192.168.2.158.8.8.80xca1bStandard query (0)webhorizon.icuA (IP address)IN (0x0001)false
                          Jan 11, 2025 14:34:16.260442019 CET192.168.2.158.8.8.80xe77fStandard query (0)webhorizon.icuA (IP address)IN (0x0001)false
                          Jan 11, 2025 14:34:23.902266026 CET192.168.2.158.8.8.80x8248Standard query (0)webhorizon.icuA (IP address)IN (0x0001)false
                          Jan 11, 2025 14:34:26.523051977 CET192.168.2.158.8.8.80x73a5Standard query (0)webhorizon.icuA (IP address)IN (0x0001)false
                          Jan 11, 2025 14:34:34.144319057 CET192.168.2.158.8.8.80xbf6aStandard query (0)webhorizon.icuA (IP address)IN (0x0001)false
                          Jan 11, 2025 14:34:37.949697018 CET192.168.2.158.8.8.80x494eStandard query (0)webhorizon.icuA (IP address)IN (0x0001)false
                          Jan 11, 2025 14:34:45.580427885 CET192.168.2.158.8.8.80xd3abStandard query (0)webhorizon.icuA (IP address)IN (0x0001)false
                          Jan 11, 2025 14:34:48.192852974 CET192.168.2.158.8.8.80xbd20Standard query (0)webhorizon.icuA (IP address)IN (0x0001)false
                          Jan 11, 2025 14:34:49.813302040 CET192.168.2.158.8.8.80x317dStandard query (0)webhorizon.icuA (IP address)IN (0x0001)false
                          Jan 11, 2025 14:34:58.433152914 CET192.168.2.158.8.8.80x3ae4Standard query (0)webhorizon.icuA (IP address)IN (0x0001)false
                          Jan 11, 2025 14:35:06.072943926 CET192.168.2.158.8.8.80xf5acStandard query (0)webhorizon.icuA (IP address)IN (0x0001)false
                          Jan 11, 2025 14:35:07.685117006 CET192.168.2.158.8.8.80xe5f9Standard query (0)webhorizon.icuA (IP address)IN (0x0001)false
                          Jan 11, 2025 14:35:10.313694954 CET192.168.2.158.8.8.80x3409Standard query (0)webhorizon.icuA (IP address)IN (0x0001)false
                          Jan 11, 2025 14:35:13.944036961 CET192.168.2.158.8.8.80x3470Standard query (0)webhorizon.icuA (IP address)IN (0x0001)false
                          TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                          Jan 11, 2025 14:33:12.991223097 CET8.8.8.8192.168.2.150xb402No error (0)webhorizon.icu154.213.187.118A (IP address)IN (0x0001)false
                          Jan 11, 2025 14:33:18.611557961 CET8.8.8.8192.168.2.150x5df5No error (0)webhorizon.icu154.213.187.118A (IP address)IN (0x0001)false
                          Jan 11, 2025 14:33:26.230456114 CET8.8.8.8192.168.2.150x177bNo error (0)webhorizon.icu154.213.187.118A (IP address)IN (0x0001)false
                          Jan 11, 2025 14:33:29.853636980 CET8.8.8.8192.168.2.150x8468No error (0)webhorizon.icu154.213.187.118A (IP address)IN (0x0001)false
                          Jan 11, 2025 14:33:36.726121902 CET8.8.8.8192.168.2.150xd75fNo error (0)webhorizon.icu154.213.187.118A (IP address)IN (0x0001)false
                          Jan 11, 2025 14:33:41.532088995 CET8.8.8.8192.168.2.150x723fNo error (0)webhorizon.icu154.213.187.118A (IP address)IN (0x0001)false
                          Jan 11, 2025 14:33:50.349303961 CET8.8.8.8192.168.2.150xb18eNo error (0)webhorizon.icu154.213.187.118A (IP address)IN (0x0001)false
                          Jan 11, 2025 14:33:58.989018917 CET8.8.8.8192.168.2.150xce81No error (0)webhorizon.icu154.213.187.118A (IP address)IN (0x0001)false
                          Jan 11, 2025 14:34:08.627475977 CET8.8.8.8192.168.2.150xca1bNo error (0)webhorizon.icu154.213.187.118A (IP address)IN (0x0001)false
                          Jan 11, 2025 14:34:16.268199921 CET8.8.8.8192.168.2.150xe77fNo error (0)webhorizon.icu154.213.187.118A (IP address)IN (0x0001)false
                          Jan 11, 2025 14:34:23.909204960 CET8.8.8.8192.168.2.150x8248No error (0)webhorizon.icu154.213.187.118A (IP address)IN (0x0001)false
                          Jan 11, 2025 14:34:26.530464888 CET8.8.8.8192.168.2.150x73a5No error (0)webhorizon.icu154.213.187.118A (IP address)IN (0x0001)false
                          Jan 11, 2025 14:34:34.316905975 CET8.8.8.8192.168.2.150xbf6aNo error (0)webhorizon.icu154.213.187.118A (IP address)IN (0x0001)false
                          Jan 11, 2025 14:34:37.959894896 CET8.8.8.8192.168.2.150x494eNo error (0)webhorizon.icu154.213.187.118A (IP address)IN (0x0001)false
                          Jan 11, 2025 14:34:45.587491989 CET8.8.8.8192.168.2.150xd3abNo error (0)webhorizon.icu154.213.187.118A (IP address)IN (0x0001)false
                          Jan 11, 2025 14:34:48.200048923 CET8.8.8.8192.168.2.150xbd20No error (0)webhorizon.icu154.213.187.118A (IP address)IN (0x0001)false
                          Jan 11, 2025 14:34:49.820559978 CET8.8.8.8192.168.2.150x317dNo error (0)webhorizon.icu154.213.187.118A (IP address)IN (0x0001)false
                          Jan 11, 2025 14:34:58.440227985 CET8.8.8.8192.168.2.150x3ae4No error (0)webhorizon.icu154.213.187.118A (IP address)IN (0x0001)false
                          Jan 11, 2025 14:35:06.080137968 CET8.8.8.8192.168.2.150xf5acNo error (0)webhorizon.icu154.213.187.118A (IP address)IN (0x0001)false
                          Jan 11, 2025 14:35:07.692523003 CET8.8.8.8192.168.2.150xe5f9No error (0)webhorizon.icu154.213.187.118A (IP address)IN (0x0001)false
                          Jan 11, 2025 14:35:10.324153900 CET8.8.8.8192.168.2.150x3409No error (0)webhorizon.icu154.213.187.118A (IP address)IN (0x0001)false
                          Jan 11, 2025 14:35:13.951380014 CET8.8.8.8192.168.2.150x3470No error (0)webhorizon.icu154.213.187.118A (IP address)IN (0x0001)false

                          System Behavior

                          Start time (UTC):13:33:12
                          Start date (UTC):11/01/2025
                          Path:/tmp/arm.elf
                          Arguments:/tmp/arm.elf
                          File size:4956856 bytes
                          MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                          Start time (UTC):13:33:12
                          Start date (UTC):11/01/2025
                          Path:/tmp/arm.elf
                          Arguments:-
                          File size:4956856 bytes
                          MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                          Start time (UTC):13:33:12
                          Start date (UTC):11/01/2025
                          Path:/tmp/arm.elf
                          Arguments:-
                          File size:4956856 bytes
                          MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                          Start time (UTC):13:33:12
                          Start date (UTC):11/01/2025
                          Path:/tmp/arm.elf
                          Arguments:-
                          File size:4956856 bytes
                          MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                          Start time (UTC):13:33:12
                          Start date (UTC):11/01/2025
                          Path:/tmp/arm.elf
                          Arguments:-
                          File size:4956856 bytes
                          MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1