Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
boatnet.spc.elf

Overview

General Information

Sample name:boatnet.spc.elf
Analysis ID:1589462
MD5:030f3b9cf5a4d91999ac1cb627771aee
SHA1:f4ab0fcf14f94b3ca9f718eca5ff5a18f11f9ab7
SHA256:4a46d6b0b9115beddecd18b09c15275e12c8b2d06aa0e48bf087d0dbec80df43
Tags:elfuser-abuse_ch
Infos:

Detection

Mirai
Score:84
Range:0 - 100
Whitelisted:false

Signatures

Antivirus / Scanner detection for submitted sample
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Yara detected Mirai
Sample tries to kill multiple processes (SIGKILL)
Detected TCP or UDP traffic on non-standard ports
Enumerates processes within the "proc" file system
Executes the "systemctl" command used for controlling the systemd system and service manager
Reads system version information
Sample has stripped symbol table
Sample tries to kill a process (SIGKILL)
Uses the "uname" system call to query kernel version information (possible evasion)
Yara signature match

Classification

Joe Sandbox version:42.0.0 Malachite
Analysis ID:1589462
Start date and time:2025-01-12 15:48:16 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 5m 52s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:boatnet.spc.elf
Detection:MAL
Classification:mal84.spre.troj.linELF@0/0@2/0
Command:/tmp/boatnet.spc.elf
PID:5706
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
lzrd cock fest"/proc/"/exe
Standard Error:
  • system is lnxubuntu20
  • wrapper-2.0 (PID: 5715, Parent: 3147, MD5: ac0b8a906f359a8ae102244738682e76) Arguments: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libsystray.so 6 12582920 systray "Notification Area" "Area where notification icons appear"
  • wrapper-2.0 (PID: 5716, Parent: 3147, MD5: ac0b8a906f359a8ae102244738682e76) Arguments: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libstatusnotifier.so 7 12582921 statusnotifier "Status Notifier Plugin" "Provides a panel area for status notifier items (application indicators)"
  • wrapper-2.0 (PID: 5719, Parent: 3147, MD5: ac0b8a906f359a8ae102244738682e76) Arguments: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libpulseaudio-plugin.so 8 12582922 pulseaudio "PulseAudio Plugin" "Adjust the audio volume of the PulseAudio sound system"
  • wrapper-2.0 (PID: 5720, Parent: 3147, MD5: ac0b8a906f359a8ae102244738682e76) Arguments: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libxfce4powermanager.so 9 12582923 power-manager-plugin "Power Manager Plugin" "Display the battery levels of your devices and control the brightness of your display"
  • wrapper-2.0 (PID: 5721, Parent: 3147, MD5: ac0b8a906f359a8ae102244738682e76) Arguments: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libnotification-plugin.so 10 12582924 notification-plugin "Notification Plugin" "Notification plugin for the Xfce panel"
  • wrapper-2.0 (PID: 5722, Parent: 3147, MD5: ac0b8a906f359a8ae102244738682e76) Arguments: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libactions.so 14 12582925 actions "Action Buttons" "Log out, lock or other system actions"
  • systemd New Fork (PID: 5763, Parent: 1)
  • snap-failure (PID: 5763, Parent: 1, MD5: 69136a7d575731ce62349f2e4d3e5c36) Arguments: /usr/lib/snapd/snap-failure snapd
    • systemctl (PID: 5779, Parent: 5763, MD5: 4deddfb6741481f68aeac522cc26ff4b) Arguments: systemctl stop snapd.socket
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
MiraiMirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese. Nowadays it targets a wide range of networked embedded devices such as IP cameras, home routers (many vendors involved), and other IoT devices. Since the source code was published on "Hack Forums" many variants of the Mirai family appeared, infecting mostly home networks all around the world.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/elf.mirai
SourceRuleDescriptionAuthorStrings
boatnet.spc.elfJoeSecurity_Mirai_5Yara detected MiraiJoe Security
    boatnet.spc.elfJoeSecurity_Mirai_8Yara detected MiraiJoe Security
      boatnet.spc.elfLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
      • 0x12558:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x1256c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x12580:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x12594:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x125a8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x125bc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x125d0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x125e4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x125f8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x1260c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x12620:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x12634:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x12648:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x1265c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x12670:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x12684:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x12698:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x126ac:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x126c0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x126d4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x126e8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      boatnet.spc.elfLinux_Trojan_Gafgyt_ea92cca8unknownunknown
      • 0x12ab8:$a: 53 65 6C 66 20 52 65 70 20 46 75 63 6B 69 6E 67 20 4E 65 54 69 53 20 61 6E 64
      boatnet.spc.elfMirai_Botnet_MalwareDetects Mirai Botnet MalwareFlorian Roth
      • 0x124a0:$x1: POST /cdn-cgi/
      • 0x13338:$s1: LCOGQGPTGP
      Click to see the 1 entries
      SourceRuleDescriptionAuthorStrings
      5706.1.00007f2b6c011000.00007f2b6c025000.r-x.sdmpJoeSecurity_Mirai_5Yara detected MiraiJoe Security
        5706.1.00007f2b6c011000.00007f2b6c025000.r-x.sdmpJoeSecurity_Mirai_8Yara detected MiraiJoe Security
          5706.1.00007f2b6c011000.00007f2b6c025000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
          • 0x12558:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x1256c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x12580:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x12594:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x125a8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x125bc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x125d0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x125e4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x125f8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x1260c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x12620:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x12634:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x12648:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x1265c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x12670:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x12684:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x12698:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x126ac:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x126c0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x126d4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x126e8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          5706.1.00007f2b6c011000.00007f2b6c025000.r-x.sdmpLinux_Trojan_Gafgyt_ea92cca8unknownunknown
          • 0x12ab8:$a: 53 65 6C 66 20 52 65 70 20 46 75 63 6B 69 6E 67 20 4E 65 54 69 53 20 61 6E 64
          5706.1.00007f2b6c011000.00007f2b6c025000.r-x.sdmpMirai_Botnet_MalwareDetects Mirai Botnet MalwareFlorian Roth
          • 0x124a0:$x1: POST /cdn-cgi/
          • 0x13338:$s1: LCOGQGPTGP
          Click to see the 10 entries
          No Suricata rule has matched

          Click to jump to signature section

          Show All Signature Results

          AV Detection

          barindex
          Source: boatnet.spc.elfAvira: detected
          Source: boatnet.spc.elfVirustotal: Detection: 62%Perma Link
          Source: boatnet.spc.elfReversingLabs: Detection: 71%
          Source: global trafficTCP traffic: 192.168.2.13:50156 -> 94.158.245.27:3778
          Source: unknownTCP traffic detected without corresponding DNS query: 94.158.245.27
          Source: unknownTCP traffic detected without corresponding DNS query: 94.158.245.27
          Source: unknownTCP traffic detected without corresponding DNS query: 94.158.245.27
          Source: unknownTCP traffic detected without corresponding DNS query: 94.158.245.27
          Source: unknownTCP traffic detected without corresponding DNS query: 94.158.245.27
          Source: unknownTCP traffic detected without corresponding DNS query: 94.158.245.27
          Source: unknownTCP traffic detected without corresponding DNS query: 94.158.245.27
          Source: unknownTCP traffic detected without corresponding DNS query: 94.158.245.27
          Source: unknownTCP traffic detected without corresponding DNS query: 94.158.245.27
          Source: unknownTCP traffic detected without corresponding DNS query: 94.158.245.27
          Source: unknownTCP traffic detected without corresponding DNS query: 94.158.245.27
          Source: unknownTCP traffic detected without corresponding DNS query: 94.158.245.27
          Source: unknownTCP traffic detected without corresponding DNS query: 94.158.245.27
          Source: unknownTCP traffic detected without corresponding DNS query: 94.158.245.27
          Source: unknownTCP traffic detected without corresponding DNS query: 94.158.245.27
          Source: unknownTCP traffic detected without corresponding DNS query: 94.158.245.27
          Source: unknownTCP traffic detected without corresponding DNS query: 94.158.245.27
          Source: unknownTCP traffic detected without corresponding DNS query: 94.158.245.27
          Source: unknownTCP traffic detected without corresponding DNS query: 94.158.245.27
          Source: unknownTCP traffic detected without corresponding DNS query: 94.158.245.27
          Source: unknownTCP traffic detected without corresponding DNS query: 94.158.245.27
          Source: unknownTCP traffic detected without corresponding DNS query: 94.158.245.27
          Source: unknownTCP traffic detected without corresponding DNS query: 94.158.245.27
          Source: unknownTCP traffic detected without corresponding DNS query: 94.158.245.27
          Source: unknownTCP traffic detected without corresponding DNS query: 94.158.245.27
          Source: unknownTCP traffic detected without corresponding DNS query: 94.158.245.27
          Source: unknownTCP traffic detected without corresponding DNS query: 94.158.245.27
          Source: unknownTCP traffic detected without corresponding DNS query: 94.158.245.27
          Source: unknownTCP traffic detected without corresponding DNS query: 94.158.245.27
          Source: unknownTCP traffic detected without corresponding DNS query: 94.158.245.27
          Source: unknownTCP traffic detected without corresponding DNS query: 94.158.245.27
          Source: unknownTCP traffic detected without corresponding DNS query: 94.158.245.27
          Source: unknownTCP traffic detected without corresponding DNS query: 94.158.245.27
          Source: unknownTCP traffic detected without corresponding DNS query: 94.158.245.27
          Source: unknownTCP traffic detected without corresponding DNS query: 94.158.245.27
          Source: unknownTCP traffic detected without corresponding DNS query: 94.158.245.27
          Source: unknownTCP traffic detected without corresponding DNS query: 94.158.245.27
          Source: unknownTCP traffic detected without corresponding DNS query: 94.158.245.27
          Source: unknownTCP traffic detected without corresponding DNS query: 94.158.245.27
          Source: unknownTCP traffic detected without corresponding DNS query: 94.158.245.27
          Source: unknownTCP traffic detected without corresponding DNS query: 94.158.245.27
          Source: unknownTCP traffic detected without corresponding DNS query: 94.158.245.27
          Source: unknownTCP traffic detected without corresponding DNS query: 94.158.245.27
          Source: unknownTCP traffic detected without corresponding DNS query: 94.158.245.27
          Source: unknownTCP traffic detected without corresponding DNS query: 94.158.245.27
          Source: unknownTCP traffic detected without corresponding DNS query: 94.158.245.27
          Source: unknownTCP traffic detected without corresponding DNS query: 94.158.245.27
          Source: unknownTCP traffic detected without corresponding DNS query: 94.158.245.27
          Source: unknownTCP traffic detected without corresponding DNS query: 94.158.245.27
          Source: unknownTCP traffic detected without corresponding DNS query: 94.158.245.27
          Source: global trafficDNS traffic detected: DNS query: daisy.ubuntu.com

          System Summary

          barindex
          Source: boatnet.spc.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
          Source: boatnet.spc.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown
          Source: boatnet.spc.elf, type: SAMPLEMatched rule: Detects Mirai Botnet Malware Author: Florian Roth
          Source: boatnet.spc.elf, type: SAMPLEMatched rule: Detects ELF malware Mirai related Author: Florian Roth
          Source: 5706.1.00007f2b6c011000.00007f2b6c025000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
          Source: 5706.1.00007f2b6c011000.00007f2b6c025000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown
          Source: 5706.1.00007f2b6c011000.00007f2b6c025000.r-x.sdmp, type: MEMORYMatched rule: Detects Mirai Botnet Malware Author: Florian Roth
          Source: 5706.1.00007f2b6c011000.00007f2b6c025000.r-x.sdmp, type: MEMORYMatched rule: Detects ELF malware Mirai related Author: Florian Roth
          Source: 5711.1.00007f2b6c011000.00007f2b6c025000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
          Source: 5711.1.00007f2b6c011000.00007f2b6c025000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown
          Source: 5711.1.00007f2b6c011000.00007f2b6c025000.r-x.sdmp, type: MEMORYMatched rule: Detects Mirai Botnet Malware Author: Florian Roth
          Source: 5711.1.00007f2b6c011000.00007f2b6c025000.r-x.sdmp, type: MEMORYMatched rule: Detects ELF malware Mirai related Author: Florian Roth
          Source: Process Memory Space: boatnet.spc.elf PID: 5706, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
          Source: Process Memory Space: boatnet.spc.elf PID: 5706, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown
          Source: /tmp/boatnet.spc.elf (PID: 5709)SIGKILL sent: pid: 3104, result: successfulJump to behavior
          Source: /tmp/boatnet.spc.elf (PID: 5709)SIGKILL sent: pid: 3161, result: successfulJump to behavior
          Source: /tmp/boatnet.spc.elf (PID: 5709)SIGKILL sent: pid: 3162, result: successfulJump to behavior
          Source: /tmp/boatnet.spc.elf (PID: 5709)SIGKILL sent: pid: 3163, result: successfulJump to behavior
          Source: /tmp/boatnet.spc.elf (PID: 5709)SIGKILL sent: pid: 3164, result: successfulJump to behavior
          Source: /tmp/boatnet.spc.elf (PID: 5709)SIGKILL sent: pid: 3165, result: successfulJump to behavior
          Source: /tmp/boatnet.spc.elf (PID: 5709)SIGKILL sent: pid: 3170, result: successfulJump to behavior
          Source: /tmp/boatnet.spc.elf (PID: 5709)SIGKILL sent: pid: 3182, result: successfulJump to behavior
          Source: /tmp/boatnet.spc.elf (PID: 5709)SIGKILL sent: pid: 3208, result: successfulJump to behavior
          Source: /tmp/boatnet.spc.elf (PID: 5709)SIGKILL sent: pid: 3212, result: successfulJump to behavior
          Source: /tmp/boatnet.spc.elf (PID: 5709)SIGKILL sent: pid: 5715, result: successfulJump to behavior
          Source: /tmp/boatnet.spc.elf (PID: 5709)SIGKILL sent: pid: 5716, result: successfulJump to behavior
          Source: /tmp/boatnet.spc.elf (PID: 5709)SIGKILL sent: pid: 5719, result: successfulJump to behavior
          Source: /tmp/boatnet.spc.elf (PID: 5709)SIGKILL sent: pid: 5720, result: successfulJump to behavior
          Source: /tmp/boatnet.spc.elf (PID: 5709)SIGKILL sent: pid: 5721, result: successfulJump to behavior
          Source: /tmp/boatnet.spc.elf (PID: 5709)SIGKILL sent: pid: 5722, result: successfulJump to behavior
          Source: ELF static info symbol of initial sample.symtab present: no
          Source: /tmp/boatnet.spc.elf (PID: 5709)SIGKILL sent: pid: 3104, result: successfulJump to behavior
          Source: /tmp/boatnet.spc.elf (PID: 5709)SIGKILL sent: pid: 3161, result: successfulJump to behavior
          Source: /tmp/boatnet.spc.elf (PID: 5709)SIGKILL sent: pid: 3162, result: successfulJump to behavior
          Source: /tmp/boatnet.spc.elf (PID: 5709)SIGKILL sent: pid: 3163, result: successfulJump to behavior
          Source: /tmp/boatnet.spc.elf (PID: 5709)SIGKILL sent: pid: 3164, result: successfulJump to behavior
          Source: /tmp/boatnet.spc.elf (PID: 5709)SIGKILL sent: pid: 3165, result: successfulJump to behavior
          Source: /tmp/boatnet.spc.elf (PID: 5709)SIGKILL sent: pid: 3170, result: successfulJump to behavior
          Source: /tmp/boatnet.spc.elf (PID: 5709)SIGKILL sent: pid: 3182, result: successfulJump to behavior
          Source: /tmp/boatnet.spc.elf (PID: 5709)SIGKILL sent: pid: 3208, result: successfulJump to behavior
          Source: /tmp/boatnet.spc.elf (PID: 5709)SIGKILL sent: pid: 3212, result: successfulJump to behavior
          Source: /tmp/boatnet.spc.elf (PID: 5709)SIGKILL sent: pid: 5715, result: successfulJump to behavior
          Source: /tmp/boatnet.spc.elf (PID: 5709)SIGKILL sent: pid: 5716, result: successfulJump to behavior
          Source: /tmp/boatnet.spc.elf (PID: 5709)SIGKILL sent: pid: 5719, result: successfulJump to behavior
          Source: /tmp/boatnet.spc.elf (PID: 5709)SIGKILL sent: pid: 5720, result: successfulJump to behavior
          Source: /tmp/boatnet.spc.elf (PID: 5709)SIGKILL sent: pid: 5721, result: successfulJump to behavior
          Source: /tmp/boatnet.spc.elf (PID: 5709)SIGKILL sent: pid: 5722, result: successfulJump to behavior
          Source: boatnet.spc.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
          Source: boatnet.spc.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16
          Source: boatnet.spc.elf, type: SAMPLEMatched rule: Mirai_Botnet_Malware date = 2016-10-04, hash5 = 420bf9215dfb04e5008c5e522eee9946599e2b323b17f17919cd802ebb012175, hash4 = 2efa09c124f277be2199bee58f49fc0ce6c64c0bef30079dfb3d94a6de492a69, hash3 = 20683ff7a5fec1237fc09224af40be029b9548c62c693844624089af568c89d4, hash2 = 05c78c3052b390435e53a87e3d31e9fb17f7c76bb4df2814313bca24735ce81c, hash1 = 05c78c3052b390435e53a87e3d31e9fb17f7c76bb4df2814313bca24735ce81c, author = Florian Roth, description = Detects Mirai Botnet Malware, hash10 = c61bf95146c68bfbbe01d7695337ed0e93ea759f59f651799f07eecdb339f83f, hash11 = d9573c3850e2ae35f371dff977fc3e5282a5e67db8e3274fd7818e8273fd5c89, hash12 = f1100c84abff05e0501e77781160d9815628e7fd2de9e53f5454dbcac7c84ca5, hash9 = bf0471b37dba7939524a30d7d5afc8fcfb8d4a7c9954343196737e72ea4e2dc4, hash8 = 89570ae59462e6472b6769545a999bde8457e47ae0d385caaa3499ab735b8147, hash7 = 70bb0ec35dd9afcfd52ec4e1d920e7045dc51dca0573cd4c753987c9d79405c0, hash6 = 62cdc8b7fffbaf5683a466f6503c03e68a15413a90f6afd5a13ba027631460c6, reference = Internal Research, license = https://creativecommons.org/licenses/by-nc/4.0/, hash13 = fb713ccf839362bf0fbe01aedd6796f4d74521b133011b408e42c1fd9ab8246b
          Source: boatnet.spc.elf, type: SAMPLEMatched rule: MAL_ELF_LNX_Mirai_Oct10_2 date = 2018-10-27, hash1 = fa0018e75f503f9748a5de0d14d4358db234f65e28c31c8d5878cc58807081c9, author = Florian Roth, description = Detects ELF malware Mirai related, reference = Internal Research
          Source: 5706.1.00007f2b6c011000.00007f2b6c025000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
          Source: 5706.1.00007f2b6c011000.00007f2b6c025000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16
          Source: 5706.1.00007f2b6c011000.00007f2b6c025000.r-x.sdmp, type: MEMORYMatched rule: Mirai_Botnet_Malware date = 2016-10-04, hash5 = 420bf9215dfb04e5008c5e522eee9946599e2b323b17f17919cd802ebb012175, hash4 = 2efa09c124f277be2199bee58f49fc0ce6c64c0bef30079dfb3d94a6de492a69, hash3 = 20683ff7a5fec1237fc09224af40be029b9548c62c693844624089af568c89d4, hash2 = 05c78c3052b390435e53a87e3d31e9fb17f7c76bb4df2814313bca24735ce81c, hash1 = 05c78c3052b390435e53a87e3d31e9fb17f7c76bb4df2814313bca24735ce81c, author = Florian Roth, description = Detects Mirai Botnet Malware, hash10 = c61bf95146c68bfbbe01d7695337ed0e93ea759f59f651799f07eecdb339f83f, hash11 = d9573c3850e2ae35f371dff977fc3e5282a5e67db8e3274fd7818e8273fd5c89, hash12 = f1100c84abff05e0501e77781160d9815628e7fd2de9e53f5454dbcac7c84ca5, hash9 = bf0471b37dba7939524a30d7d5afc8fcfb8d4a7c9954343196737e72ea4e2dc4, hash8 = 89570ae59462e6472b6769545a999bde8457e47ae0d385caaa3499ab735b8147, hash7 = 70bb0ec35dd9afcfd52ec4e1d920e7045dc51dca0573cd4c753987c9d79405c0, hash6 = 62cdc8b7fffbaf5683a466f6503c03e68a15413a90f6afd5a13ba027631460c6, reference = Internal Research, license = https://creativecommons.org/licenses/by-nc/4.0/, hash13 = fb713ccf839362bf0fbe01aedd6796f4d74521b133011b408e42c1fd9ab8246b
          Source: 5706.1.00007f2b6c011000.00007f2b6c025000.r-x.sdmp, type: MEMORYMatched rule: MAL_ELF_LNX_Mirai_Oct10_2 date = 2018-10-27, hash1 = fa0018e75f503f9748a5de0d14d4358db234f65e28c31c8d5878cc58807081c9, author = Florian Roth, description = Detects ELF malware Mirai related, reference = Internal Research
          Source: 5711.1.00007f2b6c011000.00007f2b6c025000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
          Source: 5711.1.00007f2b6c011000.00007f2b6c025000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16
          Source: 5711.1.00007f2b6c011000.00007f2b6c025000.r-x.sdmp, type: MEMORYMatched rule: Mirai_Botnet_Malware date = 2016-10-04, hash5 = 420bf9215dfb04e5008c5e522eee9946599e2b323b17f17919cd802ebb012175, hash4 = 2efa09c124f277be2199bee58f49fc0ce6c64c0bef30079dfb3d94a6de492a69, hash3 = 20683ff7a5fec1237fc09224af40be029b9548c62c693844624089af568c89d4, hash2 = 05c78c3052b390435e53a87e3d31e9fb17f7c76bb4df2814313bca24735ce81c, hash1 = 05c78c3052b390435e53a87e3d31e9fb17f7c76bb4df2814313bca24735ce81c, author = Florian Roth, description = Detects Mirai Botnet Malware, hash10 = c61bf95146c68bfbbe01d7695337ed0e93ea759f59f651799f07eecdb339f83f, hash11 = d9573c3850e2ae35f371dff977fc3e5282a5e67db8e3274fd7818e8273fd5c89, hash12 = f1100c84abff05e0501e77781160d9815628e7fd2de9e53f5454dbcac7c84ca5, hash9 = bf0471b37dba7939524a30d7d5afc8fcfb8d4a7c9954343196737e72ea4e2dc4, hash8 = 89570ae59462e6472b6769545a999bde8457e47ae0d385caaa3499ab735b8147, hash7 = 70bb0ec35dd9afcfd52ec4e1d920e7045dc51dca0573cd4c753987c9d79405c0, hash6 = 62cdc8b7fffbaf5683a466f6503c03e68a15413a90f6afd5a13ba027631460c6, reference = Internal Research, license = https://creativecommons.org/licenses/by-nc/4.0/, hash13 = fb713ccf839362bf0fbe01aedd6796f4d74521b133011b408e42c1fd9ab8246b
          Source: 5711.1.00007f2b6c011000.00007f2b6c025000.r-x.sdmp, type: MEMORYMatched rule: MAL_ELF_LNX_Mirai_Oct10_2 date = 2018-10-27, hash1 = fa0018e75f503f9748a5de0d14d4358db234f65e28c31c8d5878cc58807081c9, author = Florian Roth, description = Detects ELF malware Mirai related, reference = Internal Research
          Source: Process Memory Space: boatnet.spc.elf PID: 5706, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
          Source: Process Memory Space: boatnet.spc.elf PID: 5706, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16
          Source: classification engineClassification label: mal84.spre.troj.linELF@0/0@2/0
          Source: /tmp/boatnet.spc.elf (PID: 5709)File opened: /proc/3122/cmdlineJump to behavior
          Source: /tmp/boatnet.spc.elf (PID: 5709)File opened: /proc/3638/cmdlineJump to behavior
          Source: /tmp/boatnet.spc.elf (PID: 5709)File opened: /proc/3117/cmdlineJump to behavior
          Source: /tmp/boatnet.spc.elf (PID: 5709)File opened: /proc/3114/cmdlineJump to behavior
          Source: /tmp/boatnet.spc.elf (PID: 5709)File opened: /proc/5534/cmdlineJump to behavior
          Source: /tmp/boatnet.spc.elf (PID: 5709)File opened: /proc/914/cmdlineJump to behavior
          Source: /tmp/boatnet.spc.elf (PID: 5709)File opened: /proc/518/cmdlineJump to behavior
          Source: /tmp/boatnet.spc.elf (PID: 5709)File opened: /proc/519/cmdlineJump to behavior
          Source: /tmp/boatnet.spc.elf (PID: 5709)File opened: /proc/917/cmdlineJump to behavior
          Source: /tmp/boatnet.spc.elf (PID: 5709)File opened: /proc/3134/cmdlineJump to behavior
          Source: /tmp/boatnet.spc.elf (PID: 5709)File opened: /proc/3375/cmdlineJump to behavior
          Source: /tmp/boatnet.spc.elf (PID: 5709)File opened: /proc/3132/cmdlineJump to behavior
          Source: /tmp/boatnet.spc.elf (PID: 5709)File opened: /proc/3095/cmdlineJump to behavior
          Source: /tmp/boatnet.spc.elf (PID: 5709)File opened: /proc/1745/cmdlineJump to behavior
          Source: /tmp/boatnet.spc.elf (PID: 5709)File opened: /proc/1866/cmdlineJump to behavior
          Source: /tmp/boatnet.spc.elf (PID: 5709)File opened: /proc/1588/cmdlineJump to behavior
          Source: /tmp/boatnet.spc.elf (PID: 5709)File opened: /proc/884/cmdlineJump to behavior
          Source: /tmp/boatnet.spc.elf (PID: 5709)File opened: /proc/1982/cmdlineJump to behavior
          Source: /tmp/boatnet.spc.elf (PID: 5709)File opened: /proc/765/cmdlineJump to behavior
          Source: /tmp/boatnet.spc.elf (PID: 5709)File opened: /proc/3246/cmdlineJump to behavior
          Source: /tmp/boatnet.spc.elf (PID: 5709)File opened: /proc/767/cmdlineJump to behavior
          Source: /tmp/boatnet.spc.elf (PID: 5709)File opened: /proc/800/cmdlineJump to behavior
          Source: /tmp/boatnet.spc.elf (PID: 5709)File opened: /proc/1906/cmdlineJump to behavior
          Source: /tmp/boatnet.spc.elf (PID: 5709)File opened: /proc/802/cmdlineJump to behavior
          Source: /tmp/boatnet.spc.elf (PID: 5709)File opened: /proc/803/cmdlineJump to behavior
          Source: /tmp/boatnet.spc.elf (PID: 5709)File opened: /proc/1748/cmdlineJump to behavior
          Source: /tmp/boatnet.spc.elf (PID: 5709)File opened: /proc/5429/cmdlineJump to behavior
          Source: /tmp/boatnet.spc.elf (PID: 5709)File opened: /proc/3420/cmdlineJump to behavior
          Source: /tmp/boatnet.spc.elf (PID: 5709)File opened: /proc/1482/cmdlineJump to behavior
          Source: /tmp/boatnet.spc.elf (PID: 5709)File opened: /proc/490/cmdlineJump to behavior
          Source: /tmp/boatnet.spc.elf (PID: 5709)File opened: /proc/1480/cmdlineJump to behavior
          Source: /tmp/boatnet.spc.elf (PID: 5709)File opened: /proc/1755/cmdlineJump to behavior
          Source: /tmp/boatnet.spc.elf (PID: 5709)File opened: /proc/1238/cmdlineJump to behavior
          Source: /tmp/boatnet.spc.elf (PID: 5709)File opened: /proc/1875/cmdlineJump to behavior
          Source: /tmp/boatnet.spc.elf (PID: 5709)File opened: /proc/2964/cmdlineJump to behavior
          Source: /tmp/boatnet.spc.elf (PID: 5709)File opened: /proc/5719/cmdlineJump to behavior
          Source: /tmp/boatnet.spc.elf (PID: 5709)File opened: /proc/3413/cmdlineJump to behavior
          Source: /tmp/boatnet.spc.elf (PID: 5709)File opened: /proc/1751/cmdlineJump to behavior
          Source: /tmp/boatnet.spc.elf (PID: 5709)File opened: /proc/1872/cmdlineJump to behavior
          Source: /tmp/boatnet.spc.elf (PID: 5709)File opened: /proc/2961/cmdlineJump to behavior
          Source: /tmp/boatnet.spc.elf (PID: 5709)File opened: /proc/1475/cmdlineJump to behavior
          Source: /tmp/boatnet.spc.elf (PID: 5709)File opened: /proc/656/cmdlineJump to behavior
          Source: /tmp/boatnet.spc.elf (PID: 5709)File opened: /proc/778/cmdlineJump to behavior
          Source: /tmp/boatnet.spc.elf (PID: 5709)File opened: /proc/657/cmdlineJump to behavior
          Source: /tmp/boatnet.spc.elf (PID: 5709)File opened: /proc/658/cmdlineJump to behavior
          Source: /tmp/boatnet.spc.elf (PID: 5709)File opened: /proc/659/cmdlineJump to behavior
          Source: /tmp/boatnet.spc.elf (PID: 5709)File opened: /proc/418/cmdlineJump to behavior
          Source: /tmp/boatnet.spc.elf (PID: 5709)File opened: /proc/936/cmdlineJump to behavior
          Source: /tmp/boatnet.spc.elf (PID: 5709)File opened: /proc/419/cmdlineJump to behavior
          Source: /tmp/boatnet.spc.elf (PID: 5709)File opened: /proc/5713/cmdlineJump to behavior
          Source: /tmp/boatnet.spc.elf (PID: 5709)File opened: /proc/816/cmdlineJump to behavior
          Source: /tmp/boatnet.spc.elf (PID: 5709)File opened: /proc/1879/cmdlineJump to behavior
          Source: /tmp/boatnet.spc.elf (PID: 5709)File opened: /proc/5715/cmdlineJump to behavior
          Source: /tmp/boatnet.spc.elf (PID: 5709)File opened: /proc/5716/cmdlineJump to behavior
          Source: /tmp/boatnet.spc.elf (PID: 5709)File opened: /proc/5690/cmdlineJump to behavior
          Source: /tmp/boatnet.spc.elf (PID: 5709)File opened: /proc/5691/cmdlineJump to behavior
          Source: /tmp/boatnet.spc.elf (PID: 5709)File opened: /proc/1891/cmdlineJump to behavior
          Source: /tmp/boatnet.spc.elf (PID: 5709)File opened: /proc/3310/cmdlineJump to behavior
          Source: /tmp/boatnet.spc.elf (PID: 5709)File opened: /proc/3153/cmdlineJump to behavior
          Source: /tmp/boatnet.spc.elf (PID: 5709)File opened: /proc/780/cmdlineJump to behavior
          Source: /tmp/boatnet.spc.elf (PID: 5709)File opened: /proc/660/cmdlineJump to behavior
          Source: /tmp/boatnet.spc.elf (PID: 5709)File opened: /proc/1921/cmdlineJump to behavior
          Source: /tmp/boatnet.spc.elf (PID: 5709)File opened: /proc/783/cmdlineJump to behavior
          Source: /tmp/boatnet.spc.elf (PID: 5709)File opened: /proc/1765/cmdlineJump to behavior
          Source: /tmp/boatnet.spc.elf (PID: 5709)File opened: /proc/2974/cmdlineJump to behavior
          Source: /tmp/boatnet.spc.elf (PID: 5709)File opened: /proc/1400/cmdlineJump to behavior
          Source: /tmp/boatnet.spc.elf (PID: 5709)File opened: /proc/1884/cmdlineJump to behavior
          Source: /tmp/boatnet.spc.elf (PID: 5709)File opened: /proc/3424/cmdlineJump to behavior
          Source: /tmp/boatnet.spc.elf (PID: 5709)File opened: /proc/2972/cmdlineJump to behavior
          Source: /tmp/boatnet.spc.elf (PID: 5709)File opened: /proc/3147/cmdlineJump to behavior
          Source: /tmp/boatnet.spc.elf (PID: 5709)File opened: /proc/2970/cmdlineJump to behavior
          Source: /tmp/boatnet.spc.elf (PID: 5709)File opened: /proc/1881/cmdlineJump to behavior
          Source: /tmp/boatnet.spc.elf (PID: 5709)File opened: /proc/3146/cmdlineJump to behavior
          Source: /tmp/boatnet.spc.elf (PID: 5709)File opened: /proc/3300/cmdlineJump to behavior
          Source: /tmp/boatnet.spc.elf (PID: 5709)File opened: /proc/5566/cmdlineJump to behavior
          Source: /tmp/boatnet.spc.elf (PID: 5709)File opened: /proc/5720/cmdlineJump to behavior
          Source: /tmp/boatnet.spc.elf (PID: 5709)File opened: /proc/5721/cmdlineJump to behavior
          Source: /tmp/boatnet.spc.elf (PID: 5709)File opened: /proc/5722/cmdlineJump to behavior
          Source: /tmp/boatnet.spc.elf (PID: 5709)File opened: /proc/1805/cmdlineJump to behavior
          Source: /tmp/boatnet.spc.elf (PID: 5709)File opened: /proc/1925/cmdlineJump to behavior
          Source: /tmp/boatnet.spc.elf (PID: 5709)File opened: /proc/1804/cmdlineJump to behavior
          Source: /tmp/boatnet.spc.elf (PID: 5709)File opened: /proc/1648/cmdlineJump to behavior
          Source: /tmp/boatnet.spc.elf (PID: 5709)File opened: /proc/1922/cmdlineJump to behavior
          Source: /tmp/boatnet.spc.elf (PID: 5709)File opened: /proc/3429/cmdlineJump to behavior
          Source: /tmp/boatnet.spc.elf (PID: 5709)File opened: /proc/3442/cmdlineJump to behavior
          Source: /tmp/boatnet.spc.elf (PID: 5709)File opened: /proc/3165/cmdlineJump to behavior
          Source: /tmp/boatnet.spc.elf (PID: 5709)File opened: /proc/3164/cmdlineJump to behavior
          Source: /tmp/boatnet.spc.elf (PID: 5709)File opened: /proc/3163/cmdlineJump to behavior
          Source: /tmp/boatnet.spc.elf (PID: 5709)File opened: /proc/3162/cmdlineJump to behavior
          Source: /tmp/boatnet.spc.elf (PID: 5709)File opened: /proc/790/cmdlineJump to behavior
          Source: /tmp/boatnet.spc.elf (PID: 5709)File opened: /proc/3161/cmdlineJump to behavior
          Source: /tmp/boatnet.spc.elf (PID: 5709)File opened: /proc/792/cmdlineJump to behavior
          Source: /tmp/boatnet.spc.elf (PID: 5709)File opened: /proc/793/cmdlineJump to behavior
          Source: /tmp/boatnet.spc.elf (PID: 5709)File opened: /proc/672/cmdlineJump to behavior
          Source: /tmp/boatnet.spc.elf (PID: 5709)File opened: /proc/1930/cmdlineJump to behavior
          Source: /tmp/boatnet.spc.elf (PID: 5709)File opened: /proc/795/cmdlineJump to behavior
          Source: /tmp/boatnet.spc.elf (PID: 5709)File opened: /proc/674/cmdlineJump to behavior
          Source: /tmp/boatnet.spc.elf (PID: 5709)File opened: /proc/3315/cmdlineJump to behavior
          Source: /tmp/boatnet.spc.elf (PID: 5709)File opened: /proc/1411/cmdlineJump to behavior
          Source: /tmp/boatnet.spc.elf (PID: 5709)File opened: /proc/2984/cmdlineJump to behavior
          Source: /tmp/boatnet.spc.elf (PID: 5709)File opened: /proc/1410/cmdlineJump to behavior
          Source: /tmp/boatnet.spc.elf (PID: 5709)File opened: /proc/797/cmdlineJump to behavior
          Source: /tmp/boatnet.spc.elf (PID: 5709)File opened: /proc/676/cmdlineJump to behavior
          Source: /tmp/boatnet.spc.elf (PID: 5709)File opened: /proc/3434/cmdlineJump to behavior
          Source: /tmp/boatnet.spc.elf (PID: 5709)File opened: /proc/3158/cmdlineJump to behavior
          Source: /usr/lib/snapd/snap-failure (PID: 5779)Systemctl executable: /usr/bin/systemctl -> systemctl stop snapd.socketJump to behavior
          Source: /usr/lib/snapd/snap-failure (PID: 5763)Reads version info: /proc/versionJump to behavior
          Source: /tmp/boatnet.spc.elf (PID: 5706)Queries kernel information via 'uname': Jump to behavior
          Source: boatnet.spc.elf, 5706.1.00007fff8adb7000.00007fff8add8000.rw-.sdmp, boatnet.spc.elf, 5711.1.00007fff8adb7000.00007fff8add8000.rw-.sdmpBinary or memory string: "x86_64/usr/bin/qemu-sparc/tmp/boatnet.spc.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/boatnet.spc.elf
          Source: boatnet.spc.elf, 5706.1.000055a0dc28f000.000055a0dc314000.rw-.sdmp, boatnet.spc.elf, 5711.1.000055a0dc28f000.000055a0dc314000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/sparc
          Source: boatnet.spc.elf, 5706.1.000055a0dc28f000.000055a0dc314000.rw-.sdmp, boatnet.spc.elf, 5711.1.000055a0dc28f000.000055a0dc314000.rw-.sdmpBinary or memory string: U!/etc/qemu-binfmt/sparc
          Source: boatnet.spc.elf, 5706.1.00007fff8adb7000.00007fff8add8000.rw-.sdmp, boatnet.spc.elf, 5711.1.00007fff8adb7000.00007fff8add8000.rw-.sdmpBinary or memory string: /usr/bin/qemu-sparc

          Stealing of Sensitive Information

          barindex
          Source: Yara matchFile source: boatnet.spc.elf, type: SAMPLE
          Source: Yara matchFile source: 5706.1.00007f2b6c011000.00007f2b6c025000.r-x.sdmp, type: MEMORY
          Source: Yara matchFile source: 5711.1.00007f2b6c011000.00007f2b6c025000.r-x.sdmp, type: MEMORY
          Source: Yara matchFile source: Process Memory Space: boatnet.spc.elf PID: 5706, type: MEMORYSTR

          Remote Access Functionality

          barindex
          Source: Yara matchFile source: boatnet.spc.elf, type: SAMPLE
          Source: Yara matchFile source: 5706.1.00007f2b6c011000.00007f2b6c025000.r-x.sdmp, type: MEMORY
          Source: Yara matchFile source: 5711.1.00007f2b6c011000.00007f2b6c025000.r-x.sdmp, type: MEMORY
          Source: Yara matchFile source: Process Memory Space: boatnet.spc.elf PID: 5706, type: MEMORYSTR
          ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
          Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management Instrumentation1
          Systemd Service
          1
          Systemd Service
          Direct Volume Access1
          OS Credential Dumping
          11
          Security Software Discovery
          Remote ServicesData from Local System1
          Non-Standard Port
          Exfiltration Over Other Network Medium1
          Service Stop
          CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS Memory1
          System Information Discovery
          Remote Desktop ProtocolData from Removable Media1
          Non-Application Layer Protocol
          Exfiltration Over BluetoothNetwork Denial of Service
          Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
          Application Layer Protocol
          Automated ExfiltrationData Encrypted for Impact
          No configs have been found
          Hide Legend

          Legend:

          • Process
          • Signature
          • Created File
          • DNS/IP Info
          • Is Dropped
          • Number of created Files
          • Is malicious
          • Internet
          behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1589462 Sample: boatnet.spc.elf Startdate: 12/01/2025 Architecture: LINUX Score: 84 26 94.158.245.27, 3778, 50156, 50158 MIVOCLOUDMD Moldova Republic of 2->26 28 daisy.ubuntu.com 2->28 30 Malicious sample detected (through community Yara rule) 2->30 32 Antivirus / Scanner detection for submitted sample 2->32 34 Multi AV Scanner detection for submitted file 2->34 36 Yara detected Mirai 2->36 7 boatnet.spc.elf 2->7         started        9 systemd snap-failure 2->9         started        11 xfce4-panel wrapper-2.0 2->11         started        13 5 other processes 2->13 signatures3 process4 process5 15 boatnet.spc.elf 7->15         started        18 boatnet.spc.elf 7->18         started        20 boatnet.spc.elf 7->20         started        22 snap-failure systemctl 9->22         started        24 snap-failure 9->24         started        signatures6 38 Sample tries to kill multiple processes (SIGKILL) 15->38

          This section contains all screenshots as thumbnails, including those not shown in the slideshow.


          windows-stand
          SourceDetectionScannerLabelLink
          boatnet.spc.elf62%VirustotalBrowse
          boatnet.spc.elf71%ReversingLabsLinux.Trojan.Mirai
          boatnet.spc.elf100%AviraEXP/ELF.Gafgyt.Z.F
          No Antivirus matches
          No Antivirus matches
          No Antivirus matches
          NameIPActiveMaliciousAntivirus DetectionReputation
          daisy.ubuntu.com
          162.213.35.24
          truefalse
            high
            • No. of IPs < 25%
            • 25% < No. of IPs < 50%
            • 50% < No. of IPs < 75%
            • 75% < No. of IPs
            IPDomainCountryFlagASNASN NameMalicious
            94.158.245.27
            unknownMoldova Republic of
            39798MIVOCLOUDMDfalse
            MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
            94.158.245.27boatnet.mpsl.elfGet hashmaliciousMiraiBrowse
              boatnet.x86_64.elfGet hashmaliciousMiraiBrowse
                boatnet.ppc.elfGet hashmaliciousMiraiBrowse
                  boatnet.arm.elfGet hashmaliciousMiraiBrowse
                    boatnet.arm7.elfGet hashmaliciousMiraiBrowse
                      boatnet.x86.elfGet hashmaliciousMiraiBrowse
                        MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                        daisy.ubuntu.comboatnet.mpsl.elfGet hashmaliciousMiraiBrowse
                        • 162.213.35.24
                        boatnet.x86_64.elfGet hashmaliciousMiraiBrowse
                        • 162.213.35.25
                        2.elfGet hashmaliciousUnknownBrowse
                        • 162.213.35.24
                        boatnet.arm7.elfGet hashmaliciousMiraiBrowse
                        • 162.213.35.25
                        boatnet.x86.elfGet hashmaliciousMiraiBrowse
                        • 162.213.35.25
                        arm6.elfGet hashmaliciousUnknownBrowse
                        • 162.213.35.25
                        camp.arm6.elfGet hashmaliciousMiraiBrowse
                        • 162.213.35.25
                        2.elfGet hashmaliciousUnknownBrowse
                        • 162.213.35.25
                        x86_64.elfGet hashmaliciousUnknownBrowse
                        • 162.213.35.24
                        MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                        MIVOCLOUDMDboatnet.mpsl.elfGet hashmaliciousMiraiBrowse
                        • 94.158.245.27
                        boatnet.x86_64.elfGet hashmaliciousMiraiBrowse
                        • 94.158.245.27
                        boatnet.ppc.elfGet hashmaliciousMiraiBrowse
                        • 94.158.245.27
                        boatnet.arm.elfGet hashmaliciousMiraiBrowse
                        • 94.158.245.27
                        boatnet.arm7.elfGet hashmaliciousMiraiBrowse
                        • 94.158.245.27
                        boatnet.x86.elfGet hashmaliciousMiraiBrowse
                        • 94.158.245.27
                        camp.x86_64.elfGet hashmaliciousMiraiBrowse
                        • 5.181.159.16
                        camp.arm7.elfGet hashmaliciousMiraiBrowse
                        • 5.181.159.16
                        camp.sh4.elfGet hashmaliciousMiraiBrowse
                        • 5.181.159.16
                        camp.i686.elfGet hashmaliciousMiraiBrowse
                        • 5.181.159.16
                        No context
                        No context
                        No created / dropped files found
                        File type:ELF 32-bit MSB executable, SPARC, version 1 (SYSV), statically linked, stripped
                        Entropy (8bit):6.190458212325357
                        TrID:
                        • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                        File name:boatnet.spc.elf
                        File size:82'952 bytes
                        MD5:030f3b9cf5a4d91999ac1cb627771aee
                        SHA1:f4ab0fcf14f94b3ca9f718eca5ff5a18f11f9ab7
                        SHA256:4a46d6b0b9115beddecd18b09c15275e12c8b2d06aa0e48bf087d0dbec80df43
                        SHA512:aa566dade2d65bcee5a469dae04b1864947abd8404b98cba2d6f8cb3dc70dea6ebad13e18a67c63c71b77b50a38e494d49a46fd258013cb15cad63f5c82ea8a1
                        SSDEEP:1536:TKHfnkeT5w0gDLW+/Vu7nISHC1UlbotP0RjzvQ5BzKgk+MLZEm+o:G/k4d7Ni1URes/Q59KgbMtEm+o
                        TLSH:A8835C21B53E2B13D0E5F47E21BB8755B2E16ACE26A4C64E7E720E4FFF2155028439B4
                        File Content Preview:.ELF...........................4..Bx.....4. ...(......................?X..?X..............@...@...@....8...x........dt.Q................................@..(....@.H.................#.....b8..`.....!..... ...@.....".........`......$ ... ...@...........`....

                        ELF header

                        Class:ELF32
                        Data:2's complement, big endian
                        Version:1 (current)
                        Machine:Sparc
                        Version Number:0x1
                        Type:EXEC (Executable file)
                        OS/ABI:UNIX - System V
                        ABI Version:0
                        Entry Point Address:0x101a4
                        Flags:0x0
                        ELF Header Size:52
                        Program Header Offset:52
                        Program Header Size:32
                        Number of Program Headers:3
                        Section Header Offset:82552
                        Section Header Size:40
                        Number of Section Headers:10
                        Header String Table Index:9
                        NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                        NULL0x00x00x00x00x0000
                        .initPROGBITS0x100940x940x1c0x00x6AX004
                        .textPROGBITS0x100b00xb00x123dc0x00x6AX004
                        .finiPROGBITS0x2248c0x1248c0x140x00x6AX004
                        .rodataPROGBITS0x224a00x124a00x1ab80x00x2A008
                        .ctorsPROGBITS0x340000x140000x80x00x3WA004
                        .dtorsPROGBITS0x340080x140080x80x00x3WA004
                        .dataPROGBITS0x340180x140180x2200x00x3WA008
                        .bssNOBITS0x342380x142380x4400x00x3WA004
                        .shstrtabSTRTAB0x00x142380x3e0x00x0001
                        TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                        LOAD0x00x100000x100000x13f580x13f586.21750x5R E0x10000.init .text .fini .rodata
                        LOAD0x140000x340000x340000x2380x6782.94530x6RW 0x10000.ctors .dtors .data .bss
                        GNU_STACK0x00x00x00x00x00.00000x6RW 0x4
                        TimestampSource PortDest PortSource IPDest IP
                        Jan 12, 2025 15:49:56.373574972 CET501563778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:49:56.378657103 CET37785015694.158.245.27192.168.2.13
                        Jan 12, 2025 15:49:56.378746986 CET501563778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:49:56.448508024 CET501563778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:49:56.453516006 CET37785015694.158.245.27192.168.2.13
                        Jan 12, 2025 15:49:56.453603029 CET501563778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:49:56.458498955 CET37785015694.158.245.27192.168.2.13
                        Jan 12, 2025 15:49:57.083431005 CET37785015694.158.245.27192.168.2.13
                        Jan 12, 2025 15:49:57.083538055 CET501563778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:49:57.083705902 CET501563778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:49:57.083852053 CET37785015694.158.245.27192.168.2.13
                        Jan 12, 2025 15:49:57.083872080 CET37785015694.158.245.27192.168.2.13
                        Jan 12, 2025 15:49:57.083884001 CET37785015694.158.245.27192.168.2.13
                        Jan 12, 2025 15:49:57.083940029 CET501563778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:49:57.083940983 CET501563778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:49:57.083940983 CET501563778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:49:57.083976030 CET37785015694.158.245.27192.168.2.13
                        Jan 12, 2025 15:49:57.083988905 CET37785015694.158.245.27192.168.2.13
                        Jan 12, 2025 15:49:57.084006071 CET37785015694.158.245.27192.168.2.13
                        Jan 12, 2025 15:49:57.084018946 CET37785015694.158.245.27192.168.2.13
                        Jan 12, 2025 15:49:57.084027052 CET501563778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:49:57.084027052 CET501563778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:49:57.084044933 CET37785015694.158.245.27192.168.2.13
                        Jan 12, 2025 15:49:57.084059954 CET501563778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:49:57.084059954 CET501563778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:49:57.084089041 CET501563778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:49:57.086045980 CET501583778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:49:57.090879917 CET37785015894.158.245.27192.168.2.13
                        Jan 12, 2025 15:49:57.092899084 CET501583778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:49:57.097181082 CET501583778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:49:57.101934910 CET37785015894.158.245.27192.168.2.13
                        Jan 12, 2025 15:49:57.101984978 CET501583778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:49:57.107549906 CET37785015894.158.245.27192.168.2.13
                        Jan 12, 2025 15:49:57.820823908 CET37785015894.158.245.27192.168.2.13
                        Jan 12, 2025 15:49:57.820888996 CET37785015894.158.245.27192.168.2.13
                        Jan 12, 2025 15:49:57.820909023 CET501583778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:49:57.820928097 CET37785015894.158.245.27192.168.2.13
                        Jan 12, 2025 15:49:57.820961952 CET501583778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:49:57.820970058 CET37785015894.158.245.27192.168.2.13
                        Jan 12, 2025 15:49:57.820993900 CET501583778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:49:57.820993900 CET501583778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:49:57.821006060 CET37785015894.158.245.27192.168.2.13
                        Jan 12, 2025 15:49:57.821042061 CET37785015894.158.245.27192.168.2.13
                        Jan 12, 2025 15:49:57.821075916 CET37785015894.158.245.27192.168.2.13
                        Jan 12, 2025 15:49:57.821096897 CET501583778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:49:57.821096897 CET501583778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:49:57.821096897 CET501583778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:49:57.821110010 CET37785015894.158.245.27192.168.2.13
                        Jan 12, 2025 15:49:57.821122885 CET501583778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:49:57.821146965 CET37785015894.158.245.27192.168.2.13
                        Jan 12, 2025 15:49:57.821156025 CET501583778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:49:57.821183920 CET501583778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:49:57.821187019 CET37785015894.158.245.27192.168.2.13
                        Jan 12, 2025 15:49:57.821233034 CET501583778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:49:57.843739986 CET501603778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:49:57.848648071 CET37785016094.158.245.27192.168.2.13
                        Jan 12, 2025 15:49:57.848961115 CET501603778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:49:57.879334927 CET501603778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:49:57.884218931 CET37785016094.158.245.27192.168.2.13
                        Jan 12, 2025 15:49:57.884279013 CET501603778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:49:57.889105082 CET37785016094.158.245.27192.168.2.13
                        Jan 12, 2025 15:49:58.549983978 CET37785016094.158.245.27192.168.2.13
                        Jan 12, 2025 15:49:58.550050974 CET37785016094.158.245.27192.168.2.13
                        Jan 12, 2025 15:49:58.550051928 CET501603778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:49:58.550091982 CET501603778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:49:58.550121069 CET501603778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:49:58.550129890 CET37785016094.158.245.27192.168.2.13
                        Jan 12, 2025 15:49:58.550188065 CET37785016094.158.245.27192.168.2.13
                        Jan 12, 2025 15:49:58.550203085 CET501603778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:49:58.550216913 CET37785016094.158.245.27192.168.2.13
                        Jan 12, 2025 15:49:58.550251961 CET37785016094.158.245.27192.168.2.13
                        Jan 12, 2025 15:49:58.550266027 CET501603778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:49:58.550273895 CET501603778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:49:58.550286055 CET37785016094.158.245.27192.168.2.13
                        Jan 12, 2025 15:49:58.550292969 CET501603778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:49:58.550322056 CET37785016094.158.245.27192.168.2.13
                        Jan 12, 2025 15:49:58.550326109 CET501603778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:49:58.550359964 CET37785016094.158.245.27192.168.2.13
                        Jan 12, 2025 15:49:58.550374985 CET501603778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:49:58.550391912 CET37785016094.158.245.27192.168.2.13
                        Jan 12, 2025 15:49:58.550406933 CET501603778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:49:58.550435066 CET501603778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:49:58.555252075 CET37785016094.158.245.27192.168.2.13
                        Jan 12, 2025 15:49:58.555295944 CET501603778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:49:58.560931921 CET501623778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:49:58.565757036 CET37785016294.158.245.27192.168.2.13
                        Jan 12, 2025 15:49:58.565948963 CET501623778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:49:58.577296019 CET501623778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:49:58.582139015 CET37785016294.158.245.27192.168.2.13
                        Jan 12, 2025 15:49:58.582252026 CET501623778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:49:58.587089062 CET37785016294.158.245.27192.168.2.13
                        Jan 12, 2025 15:49:59.252082109 CET37785016294.158.245.27192.168.2.13
                        Jan 12, 2025 15:49:59.252127886 CET37785016294.158.245.27192.168.2.13
                        Jan 12, 2025 15:49:59.252161026 CET37785016294.158.245.27192.168.2.13
                        Jan 12, 2025 15:49:59.252163887 CET501623778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:49:59.252163887 CET501623778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:49:59.252197981 CET501623778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:49:59.252213955 CET37785016294.158.245.27192.168.2.13
                        Jan 12, 2025 15:49:59.252226114 CET501623778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:49:59.252249956 CET37785016294.158.245.27192.168.2.13
                        Jan 12, 2025 15:49:59.252254009 CET501623778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:49:59.252285004 CET37785016294.158.245.27192.168.2.13
                        Jan 12, 2025 15:49:59.252294064 CET501623778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:49:59.252321005 CET37785016294.158.245.27192.168.2.13
                        Jan 12, 2025 15:49:59.252334118 CET501623778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:49:59.252351046 CET37785016294.158.245.27192.168.2.13
                        Jan 12, 2025 15:49:59.252363920 CET501623778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:49:59.252386093 CET37785016294.158.245.27192.168.2.13
                        Jan 12, 2025 15:49:59.252394915 CET501623778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:49:59.252422094 CET37785016294.158.245.27192.168.2.13
                        Jan 12, 2025 15:49:59.252427101 CET501623778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:49:59.252465010 CET501623778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:49:59.253004074 CET501643778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:49:59.262001038 CET37785016494.158.245.27192.168.2.13
                        Jan 12, 2025 15:49:59.262089014 CET501643778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:49:59.264497995 CET501643778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:49:59.269340992 CET37785016494.158.245.27192.168.2.13
                        Jan 12, 2025 15:49:59.269387007 CET501643778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:49:59.274233103 CET37785016494.158.245.27192.168.2.13
                        Jan 12, 2025 15:49:59.959794998 CET37785016494.158.245.27192.168.2.13
                        Jan 12, 2025 15:49:59.959861040 CET501643778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:49:59.959945917 CET501643778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:49:59.960104942 CET37785016494.158.245.27192.168.2.13
                        Jan 12, 2025 15:49:59.960160017 CET37785016494.158.245.27192.168.2.13
                        Jan 12, 2025 15:49:59.960166931 CET501643778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:49:59.960195065 CET37785016494.158.245.27192.168.2.13
                        Jan 12, 2025 15:49:59.960212946 CET501643778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:49:59.960228920 CET37785016494.158.245.27192.168.2.13
                        Jan 12, 2025 15:49:59.960237980 CET501643778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:49:59.960264921 CET37785016494.158.245.27192.168.2.13
                        Jan 12, 2025 15:49:59.960272074 CET501643778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:49:59.960297108 CET37785016494.158.245.27192.168.2.13
                        Jan 12, 2025 15:49:59.960304976 CET501643778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:49:59.960331917 CET37785016494.158.245.27192.168.2.13
                        Jan 12, 2025 15:49:59.960335016 CET501643778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:49:59.960366964 CET37785016494.158.245.27192.168.2.13
                        Jan 12, 2025 15:49:59.960371971 CET501643778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:49:59.960406065 CET501643778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:49:59.960527897 CET501663778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:49:59.965367079 CET37785016694.158.245.27192.168.2.13
                        Jan 12, 2025 15:49:59.965478897 CET501663778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:49:59.967132092 CET501663778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:49:59.971987009 CET37785016694.158.245.27192.168.2.13
                        Jan 12, 2025 15:49:59.972059965 CET501663778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:49:59.976918936 CET37785016694.158.245.27192.168.2.13
                        Jan 12, 2025 15:50:00.666512012 CET37785016694.158.245.27192.168.2.13
                        Jan 12, 2025 15:50:00.666604996 CET37785016694.158.245.27192.168.2.13
                        Jan 12, 2025 15:50:00.666616917 CET501663778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:50:00.666641951 CET37785016694.158.245.27192.168.2.13
                        Jan 12, 2025 15:50:00.666677952 CET37785016694.158.245.27192.168.2.13
                        Jan 12, 2025 15:50:00.666703939 CET501663778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:50:00.666704893 CET501663778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:50:00.666707993 CET37785016694.158.245.27192.168.2.13
                        Jan 12, 2025 15:50:00.666704893 CET501663778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:50:00.666743040 CET37785016694.158.245.27192.168.2.13
                        Jan 12, 2025 15:50:00.666743994 CET501663778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:50:00.666743994 CET501663778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:50:00.666774988 CET501663778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:50:00.666776896 CET37785016694.158.245.27192.168.2.13
                        Jan 12, 2025 15:50:00.666806936 CET37785016694.158.245.27192.168.2.13
                        Jan 12, 2025 15:50:00.666838884 CET501663778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:50:00.666840076 CET37785016694.158.245.27192.168.2.13
                        Jan 12, 2025 15:50:00.666838884 CET501663778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:50:00.666876078 CET37785016694.158.245.27192.168.2.13
                        Jan 12, 2025 15:50:00.666908979 CET501663778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:50:00.666908979 CET501663778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:50:00.671736956 CET37785016694.158.245.27192.168.2.13
                        Jan 12, 2025 15:50:00.674588919 CET501663778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:50:00.682979107 CET501683778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:50:00.687915087 CET37785016894.158.245.27192.168.2.13
                        Jan 12, 2025 15:50:00.690395117 CET501683778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:50:00.777873993 CET501683778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:50:00.783045053 CET37785016894.158.245.27192.168.2.13
                        Jan 12, 2025 15:50:00.783147097 CET501683778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:50:00.788074970 CET37785016894.158.245.27192.168.2.13
                        Jan 12, 2025 15:50:01.402164936 CET37785016894.158.245.27192.168.2.13
                        Jan 12, 2025 15:50:01.402224064 CET37785016894.158.245.27192.168.2.13
                        Jan 12, 2025 15:50:01.402252913 CET37785016894.158.245.27192.168.2.13
                        Jan 12, 2025 15:50:01.402270079 CET37785016894.158.245.27192.168.2.13
                        Jan 12, 2025 15:50:01.402283907 CET37785016894.158.245.27192.168.2.13
                        Jan 12, 2025 15:50:01.402299881 CET37785016894.158.245.27192.168.2.13
                        Jan 12, 2025 15:50:01.402317047 CET37785016894.158.245.27192.168.2.13
                        Jan 12, 2025 15:50:01.402329922 CET37785016894.158.245.27192.168.2.13
                        Jan 12, 2025 15:50:01.402348042 CET37785016894.158.245.27192.168.2.13
                        Jan 12, 2025 15:50:01.402364016 CET37785016894.158.245.27192.168.2.13
                        Jan 12, 2025 15:50:01.402390957 CET501683778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:50:01.402390957 CET501683778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:50:01.402390957 CET501683778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:50:01.402390957 CET501683778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:50:01.402390957 CET501683778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:50:01.402390957 CET501683778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:50:01.402390957 CET501683778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:50:01.402390957 CET501683778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:50:01.402451038 CET501683778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:50:01.402451038 CET501683778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:50:01.402451038 CET501683778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:50:01.402770042 CET501703778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:50:01.407457113 CET37785016894.158.245.27192.168.2.13
                        Jan 12, 2025 15:50:01.407474995 CET37785016894.158.245.27192.168.2.13
                        Jan 12, 2025 15:50:01.407522917 CET501683778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:50:01.407561064 CET501683778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:50:01.407594919 CET37785017094.158.245.27192.168.2.13
                        Jan 12, 2025 15:50:01.407659054 CET501703778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:50:01.408533096 CET501703778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:50:01.413467884 CET37785017094.158.245.27192.168.2.13
                        Jan 12, 2025 15:50:01.413515091 CET501703778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:50:01.418328047 CET37785017094.158.245.27192.168.2.13
                        Jan 12, 2025 15:50:02.118011951 CET37785017094.158.245.27192.168.2.13
                        Jan 12, 2025 15:50:02.118114948 CET37785017094.158.245.27192.168.2.13
                        Jan 12, 2025 15:50:02.118124008 CET501703778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:50:02.118124008 CET501703778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:50:02.118156910 CET37785017094.158.245.27192.168.2.13
                        Jan 12, 2025 15:50:02.118192911 CET37785017094.158.245.27192.168.2.13
                        Jan 12, 2025 15:50:02.118228912 CET37785017094.158.245.27192.168.2.13
                        Jan 12, 2025 15:50:02.118242025 CET501703778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:50:02.118242025 CET501703778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:50:02.118242025 CET501703778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:50:02.118266106 CET37785017094.158.245.27192.168.2.13
                        Jan 12, 2025 15:50:02.118272066 CET501703778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:50:02.118297100 CET37785017094.158.245.27192.168.2.13
                        Jan 12, 2025 15:50:02.118316889 CET501703778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:50:02.118331909 CET37785017094.158.245.27192.168.2.13
                        Jan 12, 2025 15:50:02.118336916 CET501703778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:50:02.118369102 CET37785017094.158.245.27192.168.2.13
                        Jan 12, 2025 15:50:02.118393898 CET501703778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:50:02.118406057 CET37785017094.158.245.27192.168.2.13
                        Jan 12, 2025 15:50:02.118441105 CET501703778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:50:02.118510008 CET501703778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:50:02.118513107 CET501723778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:50:02.128031969 CET37785017294.158.245.27192.168.2.13
                        Jan 12, 2025 15:50:02.128110886 CET501723778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:50:02.129240036 CET501723778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:50:02.134062052 CET37785017294.158.245.27192.168.2.13
                        Jan 12, 2025 15:50:02.134138107 CET501723778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:50:02.139010906 CET37785017294.158.245.27192.168.2.13
                        Jan 12, 2025 15:50:02.841171026 CET37785017294.158.245.27192.168.2.13
                        Jan 12, 2025 15:50:02.841243982 CET501723778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:50:02.841276884 CET501723778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:50:02.841325998 CET37785017294.158.245.27192.168.2.13
                        Jan 12, 2025 15:50:02.841341972 CET37785017294.158.245.27192.168.2.13
                        Jan 12, 2025 15:50:02.841371059 CET37785017294.158.245.27192.168.2.13
                        Jan 12, 2025 15:50:02.841382980 CET501723778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:50:02.841382980 CET501723778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:50:02.841387033 CET37785017294.158.245.27192.168.2.13
                        Jan 12, 2025 15:50:02.841409922 CET37785017294.158.245.27192.168.2.13
                        Jan 12, 2025 15:50:02.841413975 CET501723778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:50:02.841413975 CET501723778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:50:02.841425896 CET37785017294.158.245.27192.168.2.13
                        Jan 12, 2025 15:50:02.841435909 CET501723778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:50:02.841440916 CET37785017294.158.245.27192.168.2.13
                        Jan 12, 2025 15:50:02.841455936 CET37785017294.158.245.27192.168.2.13
                        Jan 12, 2025 15:50:02.841459990 CET501723778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:50:02.841459990 CET501723778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:50:02.841471910 CET37785017294.158.245.27192.168.2.13
                        Jan 12, 2025 15:50:02.841495037 CET501723778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:50:02.841495037 CET501723778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:50:02.858743906 CET501743778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:50:02.863555908 CET37785017494.158.245.27192.168.2.13
                        Jan 12, 2025 15:50:02.866065979 CET501743778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:50:02.974608898 CET501743778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:50:02.979446888 CET37785017494.158.245.27192.168.2.13
                        Jan 12, 2025 15:50:02.979521990 CET501743778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:50:02.984479904 CET37785017494.158.245.27192.168.2.13
                        Jan 12, 2025 15:50:03.553226948 CET37785017494.158.245.27192.168.2.13
                        Jan 12, 2025 15:50:03.553416967 CET37785017494.158.245.27192.168.2.13
                        Jan 12, 2025 15:50:03.553455114 CET37785017494.158.245.27192.168.2.13
                        Jan 12, 2025 15:50:03.553486109 CET37785017494.158.245.27192.168.2.13
                        Jan 12, 2025 15:50:03.553524971 CET501743778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:50:03.553524971 CET501743778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:50:03.553524971 CET501743778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:50:03.553524971 CET501743778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:50:03.553580999 CET501743778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:50:03.553896904 CET37785017494.158.245.27192.168.2.13
                        Jan 12, 2025 15:50:03.553951979 CET37785017494.158.245.27192.168.2.13
                        Jan 12, 2025 15:50:03.553953886 CET501743778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:50:03.553993940 CET501743778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:50:03.554003000 CET37785017494.158.245.27192.168.2.13
                        Jan 12, 2025 15:50:03.554039001 CET37785017494.158.245.27192.168.2.13
                        Jan 12, 2025 15:50:03.554042101 CET501743778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:50:03.554074049 CET37785017494.158.245.27192.168.2.13
                        Jan 12, 2025 15:50:03.554083109 CET501743778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:50:03.554109097 CET37785017494.158.245.27192.168.2.13
                        Jan 12, 2025 15:50:03.554115057 CET501743778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:50:03.554158926 CET501763778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:50:03.554167032 CET501743778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:50:03.558417082 CET37785017494.158.245.27192.168.2.13
                        Jan 12, 2025 15:50:03.558460951 CET501743778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:50:03.563110113 CET37785017694.158.245.27192.168.2.13
                        Jan 12, 2025 15:50:03.563152075 CET501763778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:50:03.565840960 CET501763778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:50:03.570668936 CET37785017694.158.245.27192.168.2.13
                        Jan 12, 2025 15:50:03.570883989 CET501763778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:50:03.575750113 CET37785017694.158.245.27192.168.2.13
                        Jan 12, 2025 15:50:04.246938944 CET37785017694.158.245.27192.168.2.13
                        Jan 12, 2025 15:50:04.247003078 CET37785017694.158.245.27192.168.2.13
                        Jan 12, 2025 15:50:04.247049093 CET37785017694.158.245.27192.168.2.13
                        Jan 12, 2025 15:50:04.247082949 CET37785017694.158.245.27192.168.2.13
                        Jan 12, 2025 15:50:04.247098923 CET501763778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:50:04.247098923 CET501763778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:50:04.247113943 CET37785017694.158.245.27192.168.2.13
                        Jan 12, 2025 15:50:04.247139931 CET501763778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:50:04.247139931 CET501763778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:50:04.247139931 CET501763778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:50:04.247167110 CET501763778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:50:04.247174025 CET37785017694.158.245.27192.168.2.13
                        Jan 12, 2025 15:50:04.247211933 CET37785017694.158.245.27192.168.2.13
                        Jan 12, 2025 15:50:04.247220039 CET501763778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:50:04.247246027 CET37785017694.158.245.27192.168.2.13
                        Jan 12, 2025 15:50:04.247299910 CET37785017694.158.245.27192.168.2.13
                        Jan 12, 2025 15:50:04.247337103 CET501763778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:50:04.247338057 CET501763778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:50:04.247353077 CET37785017694.158.245.27192.168.2.13
                        Jan 12, 2025 15:50:04.247359037 CET501763778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:50:04.247395992 CET501763778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:50:04.247596025 CET501783778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:50:04.252211094 CET37785017694.158.245.27192.168.2.13
                        Jan 12, 2025 15:50:04.252520084 CET501763778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:50:04.257167101 CET37785017894.158.245.27192.168.2.13
                        Jan 12, 2025 15:50:04.257267952 CET501783778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:50:04.258524895 CET501783778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:50:04.263370991 CET37785017894.158.245.27192.168.2.13
                        Jan 12, 2025 15:50:04.263422012 CET501783778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:50:04.268311024 CET37785017894.158.245.27192.168.2.13
                        Jan 12, 2025 15:50:14.265851974 CET501783778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:50:14.271157026 CET37785017894.158.245.27192.168.2.13
                        Jan 12, 2025 15:50:14.478859901 CET37785017894.158.245.27192.168.2.13
                        Jan 12, 2025 15:50:14.479041100 CET501783778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:51:14.525654078 CET501783778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:51:14.530888081 CET37785017894.158.245.27192.168.2.13
                        Jan 12, 2025 15:51:14.743957043 CET37785017894.158.245.27192.168.2.13
                        Jan 12, 2025 15:51:14.744306087 CET501783778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:52:14.793450117 CET501783778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:52:14.798789978 CET37785017894.158.245.27192.168.2.13
                        Jan 12, 2025 15:52:15.006916046 CET37785017894.158.245.27192.168.2.13
                        Jan 12, 2025 15:52:15.007083893 CET501783778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:53:15.053433895 CET501783778192.168.2.1394.158.245.27
                        Jan 12, 2025 15:53:15.058414936 CET37785017894.158.245.27192.168.2.13
                        Jan 12, 2025 15:53:15.267028093 CET37785017894.158.245.27192.168.2.13
                        Jan 12, 2025 15:53:15.267231941 CET501783778192.168.2.1394.158.245.27
                        TimestampSource PortDest PortSource IPDest IP
                        Jan 12, 2025 15:52:38.684946060 CET4525953192.168.2.131.1.1.1
                        Jan 12, 2025 15:52:38.684993982 CET4477353192.168.2.131.1.1.1
                        Jan 12, 2025 15:52:38.692198038 CET53447731.1.1.1192.168.2.13
                        Jan 12, 2025 15:52:38.692455053 CET53452591.1.1.1192.168.2.13
                        TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                        Jan 12, 2025 15:52:38.684946060 CET192.168.2.131.1.1.10xb6b0Standard query (0)daisy.ubuntu.comA (IP address)IN (0x0001)false
                        Jan 12, 2025 15:52:38.684993982 CET192.168.2.131.1.1.10x8b57Standard query (0)daisy.ubuntu.com28IN (0x0001)false
                        TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                        Jan 12, 2025 15:52:38.692455053 CET1.1.1.1192.168.2.130xb6b0No error (0)daisy.ubuntu.com162.213.35.24A (IP address)IN (0x0001)false
                        Jan 12, 2025 15:52:38.692455053 CET1.1.1.1192.168.2.130xb6b0No error (0)daisy.ubuntu.com162.213.35.25A (IP address)IN (0x0001)false

                        System Behavior

                        Start time (UTC):14:49:55
                        Start date (UTC):12/01/2025
                        Path:/tmp/boatnet.spc.elf
                        Arguments:/tmp/boatnet.spc.elf
                        File size:4379400 bytes
                        MD5 hash:7dc1c0e23cd5e102bb12e5c29403410e

                        Start time (UTC):14:49:55
                        Start date (UTC):12/01/2025
                        Path:/tmp/boatnet.spc.elf
                        Arguments:-
                        File size:4379400 bytes
                        MD5 hash:7dc1c0e23cd5e102bb12e5c29403410e

                        Start time (UTC):14:49:55
                        Start date (UTC):12/01/2025
                        Path:/tmp/boatnet.spc.elf
                        Arguments:-
                        File size:4379400 bytes
                        MD5 hash:7dc1c0e23cd5e102bb12e5c29403410e

                        Start time (UTC):14:49:55
                        Start date (UTC):12/01/2025
                        Path:/tmp/boatnet.spc.elf
                        Arguments:-
                        File size:4379400 bytes
                        MD5 hash:7dc1c0e23cd5e102bb12e5c29403410e

                        Start time (UTC):14:49:56
                        Start date (UTC):12/01/2025
                        Path:/usr/bin/xfce4-panel
                        Arguments:-
                        File size:375768 bytes
                        MD5 hash:a15b657c7d54ac1385f1f15004ea6784

                        Start time (UTC):14:49:56
                        Start date (UTC):12/01/2025
                        Path:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
                        Arguments:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libsystray.so 6 12582920 systray "Notification Area" "Area where notification icons appear"
                        File size:35136 bytes
                        MD5 hash:ac0b8a906f359a8ae102244738682e76

                        Start time (UTC):14:49:56
                        Start date (UTC):12/01/2025
                        Path:/usr/bin/xfce4-panel
                        Arguments:-
                        File size:375768 bytes
                        MD5 hash:a15b657c7d54ac1385f1f15004ea6784

                        Start time (UTC):14:49:56
                        Start date (UTC):12/01/2025
                        Path:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
                        Arguments:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libstatusnotifier.so 7 12582921 statusnotifier "Status Notifier Plugin" "Provides a panel area for status notifier items (application indicators)"
                        File size:35136 bytes
                        MD5 hash:ac0b8a906f359a8ae102244738682e76

                        Start time (UTC):14:49:56
                        Start date (UTC):12/01/2025
                        Path:/usr/bin/xfce4-panel
                        Arguments:-
                        File size:375768 bytes
                        MD5 hash:a15b657c7d54ac1385f1f15004ea6784

                        Start time (UTC):14:49:56
                        Start date (UTC):12/01/2025
                        Path:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
                        Arguments:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libpulseaudio-plugin.so 8 12582922 pulseaudio "PulseAudio Plugin" "Adjust the audio volume of the PulseAudio sound system"
                        File size:35136 bytes
                        MD5 hash:ac0b8a906f359a8ae102244738682e76

                        Start time (UTC):14:49:56
                        Start date (UTC):12/01/2025
                        Path:/usr/bin/xfce4-panel
                        Arguments:-
                        File size:375768 bytes
                        MD5 hash:a15b657c7d54ac1385f1f15004ea6784

                        Start time (UTC):14:49:56
                        Start date (UTC):12/01/2025
                        Path:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
                        Arguments:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libxfce4powermanager.so 9 12582923 power-manager-plugin "Power Manager Plugin" "Display the battery levels of your devices and control the brightness of your display"
                        File size:35136 bytes
                        MD5 hash:ac0b8a906f359a8ae102244738682e76

                        Start time (UTC):14:49:57
                        Start date (UTC):12/01/2025
                        Path:/usr/bin/xfce4-panel
                        Arguments:-
                        File size:375768 bytes
                        MD5 hash:a15b657c7d54ac1385f1f15004ea6784

                        Start time (UTC):14:49:57
                        Start date (UTC):12/01/2025
                        Path:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
                        Arguments:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libnotification-plugin.so 10 12582924 notification-plugin "Notification Plugin" "Notification plugin for the Xfce panel"
                        File size:35136 bytes
                        MD5 hash:ac0b8a906f359a8ae102244738682e76

                        Start time (UTC):14:49:57
                        Start date (UTC):12/01/2025
                        Path:/usr/bin/xfce4-panel
                        Arguments:-
                        File size:375768 bytes
                        MD5 hash:a15b657c7d54ac1385f1f15004ea6784

                        Start time (UTC):14:49:57
                        Start date (UTC):12/01/2025
                        Path:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
                        Arguments:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libactions.so 14 12582925 actions "Action Buttons" "Log out, lock or other system actions"
                        File size:35136 bytes
                        MD5 hash:ac0b8a906f359a8ae102244738682e76

                        Start time (UTC):14:50:33
                        Start date (UTC):12/01/2025
                        Path:/usr/lib/systemd/systemd
                        Arguments:-
                        File size:1620224 bytes
                        MD5 hash:9b2bec7092a40488108543f9334aab75

                        Start time (UTC):14:50:33
                        Start date (UTC):12/01/2025
                        Path:/usr/lib/snapd/snap-failure
                        Arguments:/usr/lib/snapd/snap-failure snapd
                        File size:4764904 bytes
                        MD5 hash:69136a7d575731ce62349f2e4d3e5c36

                        Start time (UTC):14:50:34
                        Start date (UTC):12/01/2025
                        Path:/usr/lib/snapd/snap-failure
                        Arguments:-
                        File size:4764904 bytes
                        MD5 hash:69136a7d575731ce62349f2e4d3e5c36

                        Start time (UTC):14:50:34
                        Start date (UTC):12/01/2025
                        Path:/usr/bin/systemctl
                        Arguments:systemctl stop snapd.socket
                        File size:996584 bytes
                        MD5 hash:4deddfb6741481f68aeac522cc26ff4b

                        Start time (UTC):14:50:34
                        Start date (UTC):12/01/2025
                        Path:/usr/lib/snapd/snap-failure
                        Arguments:-
                        File size:4764904 bytes
                        MD5 hash:69136a7d575731ce62349f2e4d3e5c36