Edit tour

Linux Analysis Report
x86_64.elf

Overview

General Information

Sample name:x86_64.elf
Analysis ID:1617244
MD5:7d8b5422bc2a2d6f5baa8955d03e098e
SHA1:99642c81ef37270bda01cf6be39b1d6e03df5d23
SHA256:974ddcb0443cbc3cf8c948169df34bddea3217c6d26de30e0ca1985af7adf2a8
Tags:elfuser-abuse_ch
Infos:

Detection

Mirai, Moobot
Score:84
Range:0 - 100

Signatures

Antivirus / Scanner detection for submitted sample
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Yara detected Mirai
Yara detected Moobot
Sample deletes itself
Enumerates processes within the "proc" file system
Sample has stripped symbol table
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Tries to resolve domain names, but no domain seems valid (expired dropper behavior)
Yara signature match

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
Joe Sandbox version:42.0.0 Malachite
Analysis ID:1617244
Start date and time:2025-02-17 17:01:47 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 22s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:x86_64.elf
Detection:MAL
Classification:mal84.troj.evad.linELF@0/0@135/0
  • VT rate limit hit for: zcjs888.cfd
Command:/tmp/x86_64.elf
PID:5482
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
done.
Standard Error:
  • system is lnxubuntu20
  • x86_64.elf (PID: 5482, Parent: 5404, MD5: 7d8b5422bc2a2d6f5baa8955d03e098e) Arguments: /tmp/x86_64.elf
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
MiraiMirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese. Nowadays it targets a wide range of networked embedded devices such as IP cameras, home routers (many vendors involved), and other IoT devices. Since the source code was published on "Hack Forums" many variants of the Mirai family appeared, infecting mostly home networks all around the world.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/elf.mirai
NameDescriptionAttributionBlogpost URLsLink
MooBotNo Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/elf.moobot
SourceRuleDescriptionAuthorStrings
x86_64.elfJoeSecurity_MoobotYara detected MoobotJoe Security
    x86_64.elfJoeSecurity_Mirai_8Yara detected MiraiJoe Security
      x86_64.elfLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
      • 0xb428:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xb43c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xb450:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xb464:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xb478:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xb48c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xb4a0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xb4b4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xb4c8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xb4dc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xb4f0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xb504:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xb518:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xb52c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xb540:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xb554:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xb568:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xb57c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xb590:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xb5a4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xb5b8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      x86_64.elfLinux_Trojan_Gafgyt_9e9530a7unknownunknown
      • 0x7b48:$a: F6 48 63 FF B8 36 00 00 00 0F 05 48 3D 00 F0 FF FF 48 89 C3
      x86_64.elfLinux_Trojan_Gafgyt_807911a2unknownunknown
      • 0x8337:$a: FE 48 39 F3 0F 94 C2 48 83 F9 FF 0F 94 C0 84 D0 74 16 4B 8D
      Click to see the 9 entries
      SourceRuleDescriptionAuthorStrings
      5482.1.0000000000400000.000000000040d000.r-x.sdmpJoeSecurity_MoobotYara detected MoobotJoe Security
        5482.1.0000000000400000.000000000040d000.r-x.sdmpJoeSecurity_Mirai_8Yara detected MiraiJoe Security
          5482.1.0000000000400000.000000000040d000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
          • 0xb428:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xb43c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xb450:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xb464:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xb478:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xb48c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xb4a0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xb4b4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xb4c8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xb4dc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xb4f0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xb504:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xb518:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xb52c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xb540:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xb554:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xb568:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xb57c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xb590:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xb5a4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xb5b8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          5482.1.0000000000400000.000000000040d000.r-x.sdmpLinux_Trojan_Gafgyt_9e9530a7unknownunknown
          • 0x7b48:$a: F6 48 63 FF B8 36 00 00 00 0F 05 48 3D 00 F0 FF FF 48 89 C3
          5482.1.0000000000400000.000000000040d000.r-x.sdmpLinux_Trojan_Gafgyt_807911a2unknownunknown
          • 0x8337:$a: FE 48 39 F3 0F 94 C2 48 83 F9 FF 0F 94 C0 84 D0 74 16 4B 8D
          Click to see the 11 entries
          No Suricata rule has matched

          Click to jump to signature section

          Show All Signature Results

          AV Detection

          barindex
          Source: x86_64.elfAvira: detected
          Source: x86_64.elfVirustotal: Detection: 45%Perma Link
          Source: x86_64.elfReversingLabs: Detection: 55%
          Source: global trafficTCP traffic: 192.168.2.14:46540 -> 185.125.190.26:443
          Source: unknownDNS traffic detected: query: zcjs888.cfd replaycode: Name error (3)
          Source: unknownTCP traffic detected without corresponding DNS query: 185.125.190.26
          Source: unknownTCP traffic detected without corresponding DNS query: 185.125.190.26
          Source: global trafficDNS traffic detected: DNS query: zcjs888.cfd
          Source: unknownNetwork traffic detected: HTTP traffic on port 46540 -> 443

          System Summary

          barindex
          Source: x86_64.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
          Source: x86_64.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_9e9530a7 Author: unknown
          Source: x86_64.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_807911a2 Author: unknown
          Source: x86_64.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_d4227dbf Author: unknown
          Source: x86_64.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_d996d335 Author: unknown
          Source: x86_64.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_620087b9 Author: unknown
          Source: x86_64.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_33b4111a Author: unknown
          Source: x86_64.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_1e0c5ce0 Author: unknown
          Source: x86_64.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_520deeb8 Author: unknown
          Source: x86_64.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_6a77af0f Author: unknown
          Source: x86_64.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_01e4a728 Author: unknown
          Source: x86_64.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_e0cf29e2 Author: unknown
          Source: 5482.1.0000000000400000.000000000040d000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
          Source: 5482.1.0000000000400000.000000000040d000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_9e9530a7 Author: unknown
          Source: 5482.1.0000000000400000.000000000040d000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_807911a2 Author: unknown
          Source: 5482.1.0000000000400000.000000000040d000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d4227dbf Author: unknown
          Source: 5482.1.0000000000400000.000000000040d000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d996d335 Author: unknown
          Source: 5482.1.0000000000400000.000000000040d000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_620087b9 Author: unknown
          Source: 5482.1.0000000000400000.000000000040d000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_33b4111a Author: unknown
          Source: 5482.1.0000000000400000.000000000040d000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_1e0c5ce0 Author: unknown
          Source: 5482.1.0000000000400000.000000000040d000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_520deeb8 Author: unknown
          Source: 5482.1.0000000000400000.000000000040d000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_6a77af0f Author: unknown
          Source: 5482.1.0000000000400000.000000000040d000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_01e4a728 Author: unknown
          Source: 5482.1.0000000000400000.000000000040d000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_e0cf29e2 Author: unknown
          Source: Process Memory Space: x86_64.elf PID: 5482, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
          Source: ELF static info symbol of initial sample.symtab present: no
          Source: x86_64.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
          Source: x86_64.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_9e9530a7 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = d6ad6512051e87c8c35dc168d82edd071b122d026dce21d39b9782b3d6a01e50, id = 9e9530a7-ad4d-4a44-b764-437b7621052f, last_modified = 2021-09-16
          Source: x86_64.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_807911a2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = f409037091b7372f5a42bbe437316bd11c655e7a5fe1fcf83d1981cb5c4a389f, id = 807911a2-f6ec-4e65-924f-61cb065dafc6, last_modified = 2021-09-16
          Source: x86_64.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_d4227dbf reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 58c4b1d4d167876b64cfa10f609911a80284180e4db093917fea16fae8ccd4e3, id = d4227dbf-6ab4-4637-a6ba-0e604acaafb4, last_modified = 2021-09-16
          Source: x86_64.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_d996d335 reference_sample = b511eacd4b44744c8cf82d1b4a9bc6f1022fe6be7c5d17356b171f727ddc6eda, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = e9ccb8412f32187c309b0e9afcc3a6da21ad2f1ffa251c27f9f720ccb284e3ac, id = d996d335-e049-4052-bf36-6cd07c911a8b, last_modified = 2021-09-16
          Source: x86_64.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_620087b9 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 06cd7e6eb62352ec2ccb9ed48e58c0583c02fefd137cd048d053ab30b5330307, id = 620087b9-c87d-4752-89e8-ca1c16486b28, last_modified = 2021-09-16
          Source: x86_64.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_33b4111a reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 9c3b63b9a0f54006bae12abcefdb518904a85f78be573f0780f0a265b12d2d6e, id = 33b4111a-e59e-48db-9d74-34ca44fcd9f5, last_modified = 2021-09-16
          Source: x86_64.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_1e0c5ce0 reference_sample = 5b1f95840caebf9721bf318126be27085ec08cf7881ec64a884211a934351c2d, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 8e45538b59f9c9b8bc49661069044900c8199e487714c715c1b1f970fd528e3b, id = 1e0c5ce0-3b76-4da4-8bed-2e5036b6ce79, last_modified = 2021-09-16
          Source: x86_64.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_520deeb8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = f4dfd1d76e07ff875eedfe0ef4f861bee1e4d8e66d68385f602f29cc35e30cca, id = 520deeb8-cbc0-4225-8d23-adba5e040471, last_modified = 2021-09-16
          Source: x86_64.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_6a77af0f os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 4e436f509e7e732e3d0326bcbdde555bba0653213ddf31b43cfdfbe16abb0016, id = 6a77af0f-31fa-4793-82aa-10b065ba1ec0, last_modified = 2021-09-16
          Source: x86_64.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_01e4a728 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = d90477364982bdc6cd22079c245d866454475749f762620273091f2fab73c196, id = 01e4a728-7c1c-479b-aed0-cb76d64dbb02, last_modified = 2021-09-16
          Source: x86_64.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_e0cf29e2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 3f124c3c9f124264dfbbcca1e4b4d7cfcf3274170d4bf8966b6559045873948f, id = e0cf29e2-88d7-4aa4-b60a-c24626f2b246, last_modified = 2021-09-16
          Source: 5482.1.0000000000400000.000000000040d000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
          Source: 5482.1.0000000000400000.000000000040d000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_9e9530a7 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = d6ad6512051e87c8c35dc168d82edd071b122d026dce21d39b9782b3d6a01e50, id = 9e9530a7-ad4d-4a44-b764-437b7621052f, last_modified = 2021-09-16
          Source: 5482.1.0000000000400000.000000000040d000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_807911a2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = f409037091b7372f5a42bbe437316bd11c655e7a5fe1fcf83d1981cb5c4a389f, id = 807911a2-f6ec-4e65-924f-61cb065dafc6, last_modified = 2021-09-16
          Source: 5482.1.0000000000400000.000000000040d000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d4227dbf reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 58c4b1d4d167876b64cfa10f609911a80284180e4db093917fea16fae8ccd4e3, id = d4227dbf-6ab4-4637-a6ba-0e604acaafb4, last_modified = 2021-09-16
          Source: 5482.1.0000000000400000.000000000040d000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d996d335 reference_sample = b511eacd4b44744c8cf82d1b4a9bc6f1022fe6be7c5d17356b171f727ddc6eda, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = e9ccb8412f32187c309b0e9afcc3a6da21ad2f1ffa251c27f9f720ccb284e3ac, id = d996d335-e049-4052-bf36-6cd07c911a8b, last_modified = 2021-09-16
          Source: 5482.1.0000000000400000.000000000040d000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_620087b9 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 06cd7e6eb62352ec2ccb9ed48e58c0583c02fefd137cd048d053ab30b5330307, id = 620087b9-c87d-4752-89e8-ca1c16486b28, last_modified = 2021-09-16
          Source: 5482.1.0000000000400000.000000000040d000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_33b4111a reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 9c3b63b9a0f54006bae12abcefdb518904a85f78be573f0780f0a265b12d2d6e, id = 33b4111a-e59e-48db-9d74-34ca44fcd9f5, last_modified = 2021-09-16
          Source: 5482.1.0000000000400000.000000000040d000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_1e0c5ce0 reference_sample = 5b1f95840caebf9721bf318126be27085ec08cf7881ec64a884211a934351c2d, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 8e45538b59f9c9b8bc49661069044900c8199e487714c715c1b1f970fd528e3b, id = 1e0c5ce0-3b76-4da4-8bed-2e5036b6ce79, last_modified = 2021-09-16
          Source: 5482.1.0000000000400000.000000000040d000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_520deeb8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = f4dfd1d76e07ff875eedfe0ef4f861bee1e4d8e66d68385f602f29cc35e30cca, id = 520deeb8-cbc0-4225-8d23-adba5e040471, last_modified = 2021-09-16
          Source: 5482.1.0000000000400000.000000000040d000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_6a77af0f os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 4e436f509e7e732e3d0326bcbdde555bba0653213ddf31b43cfdfbe16abb0016, id = 6a77af0f-31fa-4793-82aa-10b065ba1ec0, last_modified = 2021-09-16
          Source: 5482.1.0000000000400000.000000000040d000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_01e4a728 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = d90477364982bdc6cd22079c245d866454475749f762620273091f2fab73c196, id = 01e4a728-7c1c-479b-aed0-cb76d64dbb02, last_modified = 2021-09-16
          Source: 5482.1.0000000000400000.000000000040d000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_e0cf29e2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 3f124c3c9f124264dfbbcca1e4b4d7cfcf3274170d4bf8966b6559045873948f, id = e0cf29e2-88d7-4aa4-b60a-c24626f2b246, last_modified = 2021-09-16
          Source: Process Memory Space: x86_64.elf PID: 5482, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
          Source: classification engineClassification label: mal84.troj.evad.linELF@0/0@135/0
          Source: /tmp/x86_64.elf (PID: 5484)File opened: /proc/1583/cmdlineJump to behavior
          Source: /tmp/x86_64.elf (PID: 5484)File opened: /proc/2672/cmdlineJump to behavior
          Source: /tmp/x86_64.elf (PID: 5484)File opened: /proc/110/cmdlineJump to behavior
          Source: /tmp/x86_64.elf (PID: 5484)File opened: /proc/111/cmdlineJump to behavior
          Source: /tmp/x86_64.elf (PID: 5484)File opened: /proc/112/cmdlineJump to behavior
          Source: /tmp/x86_64.elf (PID: 5484)File opened: /proc/113/cmdlineJump to behavior
          Source: /tmp/x86_64.elf (PID: 5484)File opened: /proc/234/cmdlineJump to behavior
          Source: /tmp/x86_64.elf (PID: 5484)File opened: /proc/1577/cmdlineJump to behavior
          Source: /tmp/x86_64.elf (PID: 5484)File opened: /proc/114/cmdlineJump to behavior
          Source: /tmp/x86_64.elf (PID: 5484)File opened: /proc/235/cmdlineJump to behavior
          Source: /tmp/x86_64.elf (PID: 5484)File opened: /proc/115/cmdlineJump to behavior
          Source: /tmp/x86_64.elf (PID: 5484)File opened: /proc/116/cmdlineJump to behavior
          Source: /tmp/x86_64.elf (PID: 5484)File opened: /proc/117/cmdlineJump to behavior
          Source: /tmp/x86_64.elf (PID: 5484)File opened: /proc/118/cmdlineJump to behavior
          Source: /tmp/x86_64.elf (PID: 5484)File opened: /proc/119/cmdlineJump to behavior
          Source: /tmp/x86_64.elf (PID: 5484)File opened: /proc/10/cmdlineJump to behavior
          Source: /tmp/x86_64.elf (PID: 5484)File opened: /proc/917/cmdlineJump to behavior
          Source: /tmp/x86_64.elf (PID: 5484)File opened: /proc/11/cmdlineJump to behavior
          Source: /tmp/x86_64.elf (PID: 5484)File opened: /proc/12/cmdlineJump to behavior
          Source: /tmp/x86_64.elf (PID: 5484)File opened: /proc/13/cmdlineJump to behavior
          Source: /tmp/x86_64.elf (PID: 5484)File opened: /proc/14/cmdlineJump to behavior
          Source: /tmp/x86_64.elf (PID: 5484)File opened: /proc/15/cmdlineJump to behavior
          Source: /tmp/x86_64.elf (PID: 5484)File opened: /proc/16/cmdlineJump to behavior
          Source: /tmp/x86_64.elf (PID: 5484)File opened: /proc/17/cmdlineJump to behavior
          Source: /tmp/x86_64.elf (PID: 5484)File opened: /proc/18/cmdlineJump to behavior
          Source: /tmp/x86_64.elf (PID: 5484)File opened: /proc/19/cmdlineJump to behavior
          Source: /tmp/x86_64.elf (PID: 5484)File opened: /proc/1593/cmdlineJump to behavior
          Source: /tmp/x86_64.elf (PID: 5484)File opened: /proc/240/cmdlineJump to behavior
          Source: /tmp/x86_64.elf (PID: 5484)File opened: /proc/120/cmdlineJump to behavior
          Source: /tmp/x86_64.elf (PID: 5484)File opened: /proc/3094/cmdlineJump to behavior
          Source: /tmp/x86_64.elf (PID: 5484)File opened: /proc/121/cmdlineJump to behavior
          Source: /tmp/x86_64.elf (PID: 5484)File opened: /proc/242/cmdlineJump to behavior
          Source: /tmp/x86_64.elf (PID: 5484)File opened: /proc/3406/cmdlineJump to behavior
          Source: /tmp/x86_64.elf (PID: 5484)File opened: /proc/1/cmdlineJump to behavior
          Source: /tmp/x86_64.elf (PID: 5484)File opened: /proc/122/cmdlineJump to behavior
          Source: /tmp/x86_64.elf (PID: 5484)File opened: /proc/243/cmdlineJump to behavior
          Source: /tmp/x86_64.elf (PID: 5484)File opened: /proc/2/cmdlineJump to behavior
          Source: /tmp/x86_64.elf (PID: 5484)File opened: /proc/123/cmdlineJump to behavior
          Source: /tmp/x86_64.elf (PID: 5484)File opened: /proc/244/cmdlineJump to behavior
          Source: /tmp/x86_64.elf (PID: 5484)File opened: /proc/1589/cmdlineJump to behavior
          Source: /tmp/x86_64.elf (PID: 5484)File opened: /proc/3/cmdlineJump to behavior
          Source: /tmp/x86_64.elf (PID: 5484)File opened: /proc/124/cmdlineJump to behavior
          Source: /tmp/x86_64.elf (PID: 5484)File opened: /proc/245/cmdlineJump to behavior
          Source: /tmp/x86_64.elf (PID: 5484)File opened: /proc/1588/cmdlineJump to behavior
          Source: /tmp/x86_64.elf (PID: 5484)File opened: /proc/125/cmdlineJump to behavior
          Source: /tmp/x86_64.elf (PID: 5484)File opened: /proc/4/cmdlineJump to behavior
          Source: /tmp/x86_64.elf (PID: 5484)File opened: /proc/246/cmdlineJump to behavior
          Source: /tmp/x86_64.elf (PID: 5484)File opened: /proc/3402/cmdlineJump to behavior
          Source: /tmp/x86_64.elf (PID: 5484)File opened: /proc/126/cmdlineJump to behavior
          Source: /tmp/x86_64.elf (PID: 5484)File opened: /proc/5/cmdlineJump to behavior
          Source: /tmp/x86_64.elf (PID: 5484)File opened: /proc/247/cmdlineJump to behavior
          Source: /tmp/x86_64.elf (PID: 5484)File opened: /proc/127/cmdlineJump to behavior
          Source: /tmp/x86_64.elf (PID: 5484)File opened: /proc/6/cmdlineJump to behavior
          Source: /tmp/x86_64.elf (PID: 5484)File opened: /proc/248/cmdlineJump to behavior
          Source: /tmp/x86_64.elf (PID: 5484)File opened: /proc/128/cmdlineJump to behavior
          Source: /tmp/x86_64.elf (PID: 5484)File opened: /proc/7/cmdlineJump to behavior
          Source: /tmp/x86_64.elf (PID: 5484)File opened: /proc/249/cmdlineJump to behavior
          Source: /tmp/x86_64.elf (PID: 5484)File opened: /proc/8/cmdlineJump to behavior
          Source: /tmp/x86_64.elf (PID: 5484)File opened: /proc/129/cmdlineJump to behavior
          Source: /tmp/x86_64.elf (PID: 5484)File opened: /proc/800/cmdlineJump to behavior
          Source: /tmp/x86_64.elf (PID: 5484)File opened: /proc/9/cmdlineJump to behavior
          Source: /tmp/x86_64.elf (PID: 5484)File opened: /proc/801/cmdlineJump to behavior
          Source: /tmp/x86_64.elf (PID: 5484)File opened: /proc/803/cmdlineJump to behavior
          Source: /tmp/x86_64.elf (PID: 5484)File opened: /proc/20/cmdlineJump to behavior
          Source: /tmp/x86_64.elf (PID: 5484)File opened: /proc/806/cmdlineJump to behavior
          Source: /tmp/x86_64.elf (PID: 5484)File opened: /proc/21/cmdlineJump to behavior
          Source: /tmp/x86_64.elf (PID: 5484)File opened: /proc/807/cmdlineJump to behavior
          Source: /tmp/x86_64.elf (PID: 5484)File opened: /proc/928/cmdlineJump to behavior
          Source: /tmp/x86_64.elf (PID: 5484)File opened: /proc/22/cmdlineJump to behavior
          Source: /tmp/x86_64.elf (PID: 5484)File opened: /proc/23/cmdlineJump to behavior
          Source: /tmp/x86_64.elf (PID: 5484)File opened: /proc/24/cmdlineJump to behavior
          Source: /tmp/x86_64.elf (PID: 5484)File opened: /proc/25/cmdlineJump to behavior
          Source: /tmp/x86_64.elf (PID: 5484)File opened: /proc/26/cmdlineJump to behavior
          Source: /tmp/x86_64.elf (PID: 5484)File opened: /proc/27/cmdlineJump to behavior
          Source: /tmp/x86_64.elf (PID: 5484)File opened: /proc/28/cmdlineJump to behavior
          Source: /tmp/x86_64.elf (PID: 5484)File opened: /proc/29/cmdlineJump to behavior
          Source: /tmp/x86_64.elf (PID: 5484)File opened: /proc/3420/cmdlineJump to behavior
          Source: /tmp/x86_64.elf (PID: 5484)File opened: /proc/490/cmdlineJump to behavior
          Source: /tmp/x86_64.elf (PID: 5484)File opened: /proc/250/cmdlineJump to behavior
          Source: /tmp/x86_64.elf (PID: 5484)File opened: /proc/130/cmdlineJump to behavior
          Source: /tmp/x86_64.elf (PID: 5484)File opened: /proc/251/cmdlineJump to behavior
          Source: /tmp/x86_64.elf (PID: 5484)File opened: /proc/131/cmdlineJump to behavior
          Source: /tmp/x86_64.elf (PID: 5484)File opened: /proc/252/cmdlineJump to behavior
          Source: /tmp/x86_64.elf (PID: 5484)File opened: /proc/132/cmdlineJump to behavior
          Source: /tmp/x86_64.elf (PID: 5484)File opened: /proc/253/cmdlineJump to behavior
          Source: /tmp/x86_64.elf (PID: 5484)File opened: /proc/254/cmdlineJump to behavior
          Source: /tmp/x86_64.elf (PID: 5484)File opened: /proc/255/cmdlineJump to behavior
          Source: /tmp/x86_64.elf (PID: 5484)File opened: /proc/135/cmdlineJump to behavior
          Source: /tmp/x86_64.elf (PID: 5484)File opened: /proc/256/cmdlineJump to behavior
          Source: /tmp/x86_64.elf (PID: 5484)File opened: /proc/1599/cmdlineJump to behavior
          Source: /tmp/x86_64.elf (PID: 5484)File opened: /proc/257/cmdlineJump to behavior
          Source: /tmp/x86_64.elf (PID: 5484)File opened: /proc/378/cmdlineJump to behavior
          Source: /tmp/x86_64.elf (PID: 5484)File opened: /proc/258/cmdlineJump to behavior
          Source: /tmp/x86_64.elf (PID: 5484)File opened: /proc/3412/cmdlineJump to behavior
          Source: /tmp/x86_64.elf (PID: 5484)File opened: /proc/259/cmdlineJump to behavior
          Source: /tmp/x86_64.elf (PID: 5484)File opened: /proc/30/cmdlineJump to behavior
          Source: /tmp/x86_64.elf (PID: 5484)File opened: /proc/35/cmdlineJump to behavior
          Source: /tmp/x86_64.elf (PID: 5484)File opened: /proc/1371/cmdlineJump to behavior
          Source: /tmp/x86_64.elf (PID: 5484)File opened: /proc/260/cmdlineJump to behavior
          Source: /tmp/x86_64.elf (PID: 5484)File opened: /proc/261/cmdlineJump to behavior
          Source: /tmp/x86_64.elf (PID: 5484)File opened: /proc/262/cmdlineJump to behavior
          Source: /tmp/x86_64.elf (PID: 5484)File opened: /proc/142/cmdlineJump to behavior
          Source: /tmp/x86_64.elf (PID: 5484)File opened: /proc/263/cmdlineJump to behavior
          Source: /tmp/x86_64.elf (PID: 5484)File opened: /proc/264/cmdlineJump to behavior
          Source: /tmp/x86_64.elf (PID: 5484)File opened: /proc/265/cmdlineJump to behavior

          Hooking and other Techniques for Hiding and Protection

          barindex
          Source: /tmp/x86_64.elf (PID: 5482)File: /tmp/x86_64.elfJump to behavior

          Stealing of Sensitive Information

          barindex
          Source: Yara matchFile source: x86_64.elf, type: SAMPLE
          Source: Yara matchFile source: 5482.1.0000000000400000.000000000040d000.r-x.sdmp, type: MEMORY
          Source: Yara matchFile source: Process Memory Space: x86_64.elf PID: 5482, type: MEMORYSTR
          Source: Yara matchFile source: x86_64.elf, type: SAMPLE
          Source: Yara matchFile source: 5482.1.0000000000400000.000000000040d000.r-x.sdmp, type: MEMORY

          Remote Access Functionality

          barindex
          Source: Yara matchFile source: x86_64.elf, type: SAMPLE
          Source: Yara matchFile source: 5482.1.0000000000400000.000000000040d000.r-x.sdmp, type: MEMORY
          Source: Yara matchFile source: Process Memory Space: x86_64.elf PID: 5482, type: MEMORYSTR
          Source: Yara matchFile source: x86_64.elf, type: SAMPLE
          Source: Yara matchFile source: 5482.1.0000000000400000.000000000040d000.r-x.sdmp, type: MEMORY
          ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
          Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception1
          File Deletion
          1
          OS Credential Dumping
          System Service DiscoveryRemote ServicesData from Local System1
          Encrypted Channel
          Exfiltration Over Other Network MediumAbuse Accessibility Features
          CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
          Non-Application Layer Protocol
          Exfiltration Over BluetoothNetwork Denial of Service
          Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive2
          Application Layer Protocol
          Automated ExfiltrationData Encrypted for Impact
          No configs have been found
          Hide Legend

          Legend:

          • Process
          • Signature
          • Created File
          • DNS/IP Info
          • Is Dropped
          • Number of created Files
          • Is malicious
          • Internet
          behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1617244 Sample: x86_64.elf Startdate: 17/02/2025 Architecture: LINUX Score: 84 20 zcjs888.cfd 2->20 22 185.125.190.26, 443 CANONICAL-ASGB United Kingdom 2->22 24 Malicious sample detected (through community Yara rule) 2->24 26 Antivirus / Scanner detection for submitted sample 2->26 28 Multi AV Scanner detection for submitted file 2->28 30 2 other signatures 2->30 9 x86_64.elf 2->9         started        signatures3 process4 signatures5 32 Sample deletes itself 9->32 12 x86_64.elf 9->12         started        process6 process7 14 x86_64.elf 12->14         started        16 x86_64.elf 12->16         started        process8 18 x86_64.elf 14->18         started       

          This section contains all screenshots as thumbnails, including those not shown in the slideshow.


          windows-stand
          SourceDetectionScannerLabelLink
          x86_64.elf45%VirustotalBrowse
          x86_64.elf56%ReversingLabsLinux.Backdoor.Mirai
          x86_64.elf100%AviraEXP/ELF.Mirai.Z.A
          No Antivirus matches
          No Antivirus matches
          No Antivirus matches

          Download Network PCAP: filteredfull

          NameIPActiveMaliciousAntivirus DetectionReputation
          zcjs888.cfd
          unknown
          unknowntrue
            unknown
            • No. of IPs < 25%
            • 25% < No. of IPs < 50%
            • 50% < No. of IPs < 75%
            • 75% < No. of IPs
            IPDomainCountryFlagASNASN NameMalicious
            185.125.190.26
            unknownUnited Kingdom
            41231CANONICAL-ASGBfalse
            MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
            185.125.190.26sh4.elfGet hashmaliciousUnknownBrowse
              kre4per.mpsl.elfGet hashmaliciousUnknownBrowse
                kre4per.x86.elfGet hashmaliciousUnknownBrowse
                  kre4per.arm7.elfGet hashmaliciousMiraiBrowse
                    sh4.elfGet hashmaliciousUnknownBrowse
                      na.elfGet hashmaliciousPrometeiBrowse
                        a-r.m-4.Sakura.elfGet hashmaliciousGafgyt, MiraiBrowse
                          m-6.8-k.Sakura.elfGet hashmaliciousGafgyt, MiraiBrowse
                            main_x86.elfGet hashmaliciousMiraiBrowse
                              na.elfGet hashmaliciousPrometeiBrowse
                                No context
                                MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                CANONICAL-ASGBsh4.elfGet hashmaliciousMirai, MoobotBrowse
                                • 91.189.91.42
                                QBPATWb3X7Get hashmaliciousUnknownBrowse
                                • 91.189.91.42
                                na.elfGet hashmaliciousPrometeiBrowse
                                • 91.189.91.42
                                na.elfGet hashmaliciousPrometeiBrowse
                                • 91.189.91.42
                                wget.elfGet hashmaliciousGafgyt, MiraiBrowse
                                • 91.189.91.42
                                enVDLZ8dqX.elfGet hashmaliciousAkiraBrowse
                                • 91.189.91.42
                                openssh.elfGet hashmaliciousGafgyt, MiraiBrowse
                                • 91.189.91.42
                                ntpd.elfGet hashmaliciousGafgyt, MiraiBrowse
                                • 91.189.91.42
                                ppc.elfGet hashmaliciousUnknownBrowse
                                • 91.189.91.42
                                nsharm6.elfGet hashmaliciousUnknownBrowse
                                • 91.189.91.42
                                No context
                                No context
                                No created / dropped files found
                                File type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), statically linked, stripped
                                Entropy (8bit):6.230014653549537
                                TrID:
                                • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                                File name:x86_64.elf
                                File size:55'104 bytes
                                MD5:7d8b5422bc2a2d6f5baa8955d03e098e
                                SHA1:99642c81ef37270bda01cf6be39b1d6e03df5d23
                                SHA256:974ddcb0443cbc3cf8c948169df34bddea3217c6d26de30e0ca1985af7adf2a8
                                SHA512:162a1825a8ef207ea0cb78191d5f0ed541d43ffa7d2a3edc12cfeaf2bbf4abf88c2562ad74615387264567a13196ec9eae931803a3aff5903d90e2f171a04020
                                SSDEEP:1536:Ru31CxXVpHlCrxsNnVfvj5Laa2r4DaEXzd0OCUjCYk:Y1sXV5lCKNVfvj5d0GaEDOVUjCYk
                                TLSH:70330907F681C0FDC49AC174476BBA3AE93771ED0238F2A67BE4EA223D95E611D19C44
                                File Content Preview:.ELF..............>.......@.....@...................@.8...@.......................@.......@...............................................P.......P.............(...............Q.td....................................................H...._........H........

                                ELF header

                                Class:ELF64
                                Data:2's complement, little endian
                                Version:1 (current)
                                Machine:Advanced Micro Devices X86-64
                                Version Number:0x1
                                Type:EXEC (Executable file)
                                OS/ABI:UNIX - System V
                                ABI Version:0
                                Entry Point Address:0x400194
                                Flags:0x0
                                ELF Header Size:64
                                Program Header Offset:64
                                Program Header Size:56
                                Number of Program Headers:3
                                Section Header Offset:54464
                                Section Header Size:64
                                Number of Section Headers:10
                                Header String Table Index:9
                                NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                NULL0x00x00x00x00x0000
                                .initPROGBITS0x4000e80xe80x130x00x6AX001
                                .textPROGBITS0x4001000x1000xae460x00x6AX0016
                                .finiPROGBITS0x40af460xaf460xe0x00x6AX001
                                .rodataPROGBITS0x40af600xaf600x1f300x00x2A0032
                                .ctorsPROGBITS0x50d0000xd0000x100x00x3WA008
                                .dtorsPROGBITS0x50d0100xd0100x100x00x3WA008
                                .dataPROGBITS0x50d0400xd0400x4400x00x3WA0032
                                .bssNOBITS0x50d4800xd4800x29a80x00x3WA0032
                                .shstrtabSTRTAB0x00xd4800x3e0x00x0001
                                TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                LOAD0x00x4000000x4000000xce900xce906.34610x5R E0x100000.init .text .fini .rodata
                                LOAD0xd0000x50d0000x50d0000x4800x2e282.15810x6RW 0x100000.ctors .dtors .data .bss
                                GNU_STACK0x00x00x00x00x00.00000x6RW 0x8

                                Download Network PCAP: filteredfull

                                • Total Packets: 137
                                • 443 (HTTPS)
                                • 53 (DNS)
                                TimestampSource PortDest PortSource IPDest IP
                                Feb 17, 2025 17:02:45.047221899 CET46540443192.168.2.14185.125.190.26
                                Feb 17, 2025 17:03:15.510077953 CET46540443192.168.2.14185.125.190.26
                                TimestampSource PortDest PortSource IPDest IP
                                Feb 17, 2025 17:02:36.399701118 CET4573553192.168.2.148.8.8.8
                                Feb 17, 2025 17:02:36.406045914 CET53457358.8.8.8192.168.2.14
                                Feb 17, 2025 17:02:36.407618999 CET4666153192.168.2.148.8.8.8
                                Feb 17, 2025 17:02:36.414427042 CET53466618.8.8.8192.168.2.14
                                Feb 17, 2025 17:02:36.416109085 CET5392553192.168.2.148.8.8.8
                                Feb 17, 2025 17:02:36.423068047 CET53539258.8.8.8192.168.2.14
                                Feb 17, 2025 17:02:36.424602985 CET4661553192.168.2.148.8.8.8
                                Feb 17, 2025 17:02:36.434861898 CET53466158.8.8.8192.168.2.14
                                Feb 17, 2025 17:02:36.436629057 CET5763753192.168.2.148.8.8.8
                                Feb 17, 2025 17:02:36.442944050 CET53576378.8.8.8192.168.2.14
                                Feb 17, 2025 17:02:45.446916103 CET4880953192.168.2.148.8.8.8
                                Feb 17, 2025 17:02:45.452995062 CET53488098.8.8.8192.168.2.14
                                Feb 17, 2025 17:02:45.453780890 CET4068953192.168.2.148.8.8.8
                                Feb 17, 2025 17:02:45.459867001 CET53406898.8.8.8192.168.2.14
                                Feb 17, 2025 17:02:45.460602045 CET3299753192.168.2.148.8.8.8
                                Feb 17, 2025 17:02:45.467355967 CET53329978.8.8.8192.168.2.14
                                Feb 17, 2025 17:02:45.468040943 CET3837353192.168.2.148.8.8.8
                                Feb 17, 2025 17:02:45.474294901 CET53383738.8.8.8192.168.2.14
                                Feb 17, 2025 17:02:45.474983931 CET4220453192.168.2.148.8.8.8
                                Feb 17, 2025 17:02:45.481266022 CET53422048.8.8.8192.168.2.14
                                Feb 17, 2025 17:02:48.483789921 CET4907353192.168.2.148.8.8.8
                                Feb 17, 2025 17:02:48.490113974 CET53490738.8.8.8192.168.2.14
                                Feb 17, 2025 17:02:48.491334915 CET4966353192.168.2.148.8.8.8
                                Feb 17, 2025 17:02:48.497596025 CET53496638.8.8.8192.168.2.14
                                Feb 17, 2025 17:02:48.498516083 CET5225253192.168.2.148.8.8.8
                                Feb 17, 2025 17:02:48.504740000 CET53522528.8.8.8192.168.2.14
                                Feb 17, 2025 17:02:48.505600929 CET4251853192.168.2.148.8.8.8
                                Feb 17, 2025 17:02:48.513457060 CET53425188.8.8.8192.168.2.14
                                Feb 17, 2025 17:02:48.514379025 CET5884753192.168.2.148.8.8.8
                                Feb 17, 2025 17:02:48.520745993 CET53588478.8.8.8192.168.2.14
                                Feb 17, 2025 17:02:58.551242113 CET3792353192.168.2.148.8.8.8
                                Feb 17, 2025 17:02:58.557899952 CET53379238.8.8.8192.168.2.14
                                Feb 17, 2025 17:02:58.559528112 CET3613653192.168.2.148.8.8.8
                                Feb 17, 2025 17:02:58.565853119 CET53361368.8.8.8192.168.2.14
                                Feb 17, 2025 17:02:58.571038008 CET5642553192.168.2.148.8.8.8
                                Feb 17, 2025 17:02:58.577399015 CET53564258.8.8.8192.168.2.14
                                Feb 17, 2025 17:02:58.578923941 CET3440153192.168.2.148.8.8.8
                                Feb 17, 2025 17:02:58.585410118 CET53344018.8.8.8192.168.2.14
                                Feb 17, 2025 17:02:58.608791113 CET5573453192.168.2.148.8.8.8
                                Feb 17, 2025 17:02:58.616641998 CET53557348.8.8.8192.168.2.14
                                Feb 17, 2025 17:03:05.640125990 CET4807853192.168.2.148.8.8.8
                                Feb 17, 2025 17:03:05.647265911 CET53480788.8.8.8192.168.2.14
                                Feb 17, 2025 17:03:05.648547888 CET5038753192.168.2.148.8.8.8
                                Feb 17, 2025 17:03:05.655380964 CET53503878.8.8.8192.168.2.14
                                Feb 17, 2025 17:03:05.656308889 CET3955553192.168.2.148.8.8.8
                                Feb 17, 2025 17:03:05.664475918 CET53395558.8.8.8192.168.2.14
                                Feb 17, 2025 17:03:05.665420055 CET4413353192.168.2.148.8.8.8
                                Feb 17, 2025 17:03:05.673465014 CET53441338.8.8.8192.168.2.14
                                Feb 17, 2025 17:03:05.674460888 CET4563253192.168.2.148.8.8.8
                                Feb 17, 2025 17:03:05.682539940 CET53456328.8.8.8192.168.2.14
                                Feb 17, 2025 17:03:10.685039997 CET3764153192.168.2.148.8.8.8
                                Feb 17, 2025 17:03:10.691497087 CET53376418.8.8.8192.168.2.14
                                Feb 17, 2025 17:03:10.692457914 CET4083253192.168.2.148.8.8.8
                                Feb 17, 2025 17:03:10.699090004 CET53408328.8.8.8192.168.2.14
                                Feb 17, 2025 17:03:10.700074911 CET3655453192.168.2.148.8.8.8
                                Feb 17, 2025 17:03:10.706641912 CET53365548.8.8.8192.168.2.14
                                Feb 17, 2025 17:03:10.707581043 CET3342153192.168.2.148.8.8.8
                                Feb 17, 2025 17:03:10.713687897 CET53334218.8.8.8192.168.2.14
                                Feb 17, 2025 17:03:10.714639902 CET5069053192.168.2.148.8.8.8
                                Feb 17, 2025 17:03:10.720978975 CET53506908.8.8.8192.168.2.14
                                Feb 17, 2025 17:03:19.724951029 CET5844253192.168.2.148.8.8.8
                                Feb 17, 2025 17:03:19.731327057 CET53584428.8.8.8192.168.2.14
                                Feb 17, 2025 17:03:19.733163118 CET3896753192.168.2.148.8.8.8
                                Feb 17, 2025 17:03:19.739705086 CET53389678.8.8.8192.168.2.14
                                Feb 17, 2025 17:03:19.741102934 CET4222153192.168.2.148.8.8.8
                                Feb 17, 2025 17:03:19.747343063 CET53422218.8.8.8192.168.2.14
                                Feb 17, 2025 17:03:19.748361111 CET3573253192.168.2.148.8.8.8
                                Feb 17, 2025 17:03:19.754611969 CET53357328.8.8.8192.168.2.14
                                Feb 17, 2025 17:03:19.755924940 CET4232753192.168.2.148.8.8.8
                                Feb 17, 2025 17:03:19.764019012 CET53423278.8.8.8192.168.2.14
                                Feb 17, 2025 17:03:26.768881083 CET3512653192.168.2.148.8.8.8
                                Feb 17, 2025 17:03:26.777945042 CET53351268.8.8.8192.168.2.14
                                Feb 17, 2025 17:03:26.779258966 CET5223853192.168.2.148.8.8.8
                                Feb 17, 2025 17:03:26.788014889 CET53522388.8.8.8192.168.2.14
                                Feb 17, 2025 17:03:26.789625883 CET3731653192.168.2.148.8.8.8
                                Feb 17, 2025 17:03:26.798253059 CET53373168.8.8.8192.168.2.14
                                Feb 17, 2025 17:03:26.799660921 CET5710153192.168.2.148.8.8.8
                                Feb 17, 2025 17:03:26.806013107 CET53571018.8.8.8192.168.2.14
                                Feb 17, 2025 17:03:26.807370901 CET3601753192.168.2.148.8.8.8
                                Feb 17, 2025 17:03:26.814589024 CET53360178.8.8.8192.168.2.14
                                Feb 17, 2025 17:03:36.819519043 CET4201553192.168.2.148.8.8.8
                                Feb 17, 2025 17:03:36.826324940 CET53420158.8.8.8192.168.2.14
                                Feb 17, 2025 17:03:36.827759027 CET4502753192.168.2.148.8.8.8
                                Feb 17, 2025 17:03:36.834363937 CET53450278.8.8.8192.168.2.14
                                Feb 17, 2025 17:03:36.835627079 CET4294753192.168.2.148.8.8.8
                                Feb 17, 2025 17:03:36.842057943 CET53429478.8.8.8192.168.2.14
                                Feb 17, 2025 17:03:36.843197107 CET4434653192.168.2.148.8.8.8
                                Feb 17, 2025 17:03:36.849618912 CET53443468.8.8.8192.168.2.14
                                Feb 17, 2025 17:03:36.850805998 CET4156053192.168.2.148.8.8.8
                                Feb 17, 2025 17:03:36.857027054 CET53415608.8.8.8192.168.2.14
                                Feb 17, 2025 17:03:43.861517906 CET5353453192.168.2.148.8.8.8
                                Feb 17, 2025 17:03:43.868664980 CET53535348.8.8.8192.168.2.14
                                Feb 17, 2025 17:03:43.870328903 CET4992353192.168.2.148.8.8.8
                                Feb 17, 2025 17:03:43.877221107 CET53499238.8.8.8192.168.2.14
                                Feb 17, 2025 17:03:43.878696918 CET4484853192.168.2.148.8.8.8
                                Feb 17, 2025 17:03:43.885158062 CET53448488.8.8.8192.168.2.14
                                Feb 17, 2025 17:03:43.886667013 CET5876653192.168.2.148.8.8.8
                                Feb 17, 2025 17:03:43.893287897 CET53587668.8.8.8192.168.2.14
                                Feb 17, 2025 17:03:43.894819975 CET4445153192.168.2.148.8.8.8
                                Feb 17, 2025 17:03:43.901366949 CET53444518.8.8.8192.168.2.14
                                Feb 17, 2025 17:03:45.906358004 CET3708353192.168.2.148.8.8.8
                                Feb 17, 2025 17:03:45.912796021 CET53370838.8.8.8192.168.2.14
                                Feb 17, 2025 17:03:45.914505959 CET4013453192.168.2.148.8.8.8
                                Feb 17, 2025 17:03:45.920800924 CET53401348.8.8.8192.168.2.14
                                Feb 17, 2025 17:03:45.922183037 CET4428653192.168.2.148.8.8.8
                                Feb 17, 2025 17:03:45.928514957 CET53442868.8.8.8192.168.2.14
                                Feb 17, 2025 17:03:45.929903984 CET4742953192.168.2.148.8.8.8
                                Feb 17, 2025 17:03:45.936414957 CET53474298.8.8.8192.168.2.14
                                Feb 17, 2025 17:03:45.938062906 CET5366553192.168.2.148.8.8.8
                                Feb 17, 2025 17:03:45.944430113 CET53536658.8.8.8192.168.2.14
                                Feb 17, 2025 17:03:49.949440956 CET4463553192.168.2.148.8.8.8
                                Feb 17, 2025 17:03:49.955818892 CET53446358.8.8.8192.168.2.14
                                Feb 17, 2025 17:03:49.957597017 CET3290053192.168.2.148.8.8.8
                                Feb 17, 2025 17:03:49.963758945 CET53329008.8.8.8192.168.2.14
                                Feb 17, 2025 17:03:49.965570927 CET4123553192.168.2.148.8.8.8
                                Feb 17, 2025 17:03:49.971729994 CET53412358.8.8.8192.168.2.14
                                Feb 17, 2025 17:03:49.973768950 CET4249453192.168.2.148.8.8.8
                                Feb 17, 2025 17:03:49.980348110 CET53424948.8.8.8192.168.2.14
                                Feb 17, 2025 17:03:49.982637882 CET4515353192.168.2.148.8.8.8
                                Feb 17, 2025 17:03:49.988720894 CET53451538.8.8.8192.168.2.14
                                Feb 17, 2025 17:03:50.993782997 CET4998353192.168.2.148.8.8.8
                                Feb 17, 2025 17:03:51.000412941 CET53499838.8.8.8192.168.2.14
                                Feb 17, 2025 17:03:51.002053022 CET3749853192.168.2.148.8.8.8
                                Feb 17, 2025 17:03:51.010584116 CET53374988.8.8.8192.168.2.14
                                Feb 17, 2025 17:03:51.012522936 CET4007953192.168.2.148.8.8.8
                                Feb 17, 2025 17:03:51.021245003 CET53400798.8.8.8192.168.2.14
                                Feb 17, 2025 17:03:51.023267984 CET4699453192.168.2.148.8.8.8
                                Feb 17, 2025 17:03:51.029664040 CET53469948.8.8.8192.168.2.14
                                Feb 17, 2025 17:03:51.031157970 CET4797653192.168.2.148.8.8.8
                                Feb 17, 2025 17:03:51.037899971 CET53479768.8.8.8192.168.2.14
                                Feb 17, 2025 17:03:59.043638945 CET4203553192.168.2.148.8.8.8
                                Feb 17, 2025 17:03:59.050441027 CET53420358.8.8.8192.168.2.14
                                Feb 17, 2025 17:03:59.052397013 CET5309753192.168.2.148.8.8.8
                                Feb 17, 2025 17:03:59.059184074 CET53530978.8.8.8192.168.2.14
                                Feb 17, 2025 17:03:59.060830116 CET5866553192.168.2.148.8.8.8
                                Feb 17, 2025 17:03:59.067182064 CET53586658.8.8.8192.168.2.14
                                Feb 17, 2025 17:03:59.068784952 CET5448653192.168.2.148.8.8.8
                                Feb 17, 2025 17:03:59.075423956 CET53544868.8.8.8192.168.2.14
                                Feb 17, 2025 17:03:59.077083111 CET4293553192.168.2.148.8.8.8
                                Feb 17, 2025 17:03:59.083892107 CET53429358.8.8.8192.168.2.14
                                Feb 17, 2025 17:04:03.089149952 CET5699153192.168.2.148.8.8.8
                                Feb 17, 2025 17:04:03.096191883 CET53569918.8.8.8192.168.2.14
                                Feb 17, 2025 17:04:03.097711086 CET4135153192.168.2.148.8.8.8
                                Feb 17, 2025 17:04:03.104326963 CET53413518.8.8.8192.168.2.14
                                Feb 17, 2025 17:04:03.105405092 CET4801453192.168.2.148.8.8.8
                                Feb 17, 2025 17:04:03.112179995 CET53480148.8.8.8192.168.2.14
                                Feb 17, 2025 17:04:03.113415003 CET5350553192.168.2.148.8.8.8
                                Feb 17, 2025 17:04:03.120007038 CET53535058.8.8.8192.168.2.14
                                Feb 17, 2025 17:04:03.121396065 CET3864953192.168.2.148.8.8.8
                                Feb 17, 2025 17:04:03.127991915 CET53386498.8.8.8192.168.2.14
                                Feb 17, 2025 17:04:10.132764101 CET4859053192.168.2.148.8.8.8
                                Feb 17, 2025 17:04:10.139559984 CET53485908.8.8.8192.168.2.14
                                Feb 17, 2025 17:04:10.141031027 CET3397453192.168.2.148.8.8.8
                                Feb 17, 2025 17:04:10.147975922 CET53339748.8.8.8192.168.2.14
                                Feb 17, 2025 17:04:10.149513960 CET5440653192.168.2.148.8.8.8
                                Feb 17, 2025 17:04:10.156172991 CET53544068.8.8.8192.168.2.14
                                Feb 17, 2025 17:04:10.157660961 CET3517753192.168.2.148.8.8.8
                                Feb 17, 2025 17:04:10.164210081 CET53351778.8.8.8192.168.2.14
                                Feb 17, 2025 17:04:10.165680885 CET4836153192.168.2.148.8.8.8
                                Feb 17, 2025 17:04:10.172077894 CET53483618.8.8.8192.168.2.14
                                Feb 17, 2025 17:04:11.177341938 CET5080153192.168.2.148.8.8.8
                                Feb 17, 2025 17:04:11.184497118 CET53508018.8.8.8192.168.2.14
                                Feb 17, 2025 17:04:11.186566114 CET4542953192.168.2.148.8.8.8
                                Feb 17, 2025 17:04:11.193257093 CET53454298.8.8.8192.168.2.14
                                Feb 17, 2025 17:04:11.195813894 CET5840053192.168.2.148.8.8.8
                                Feb 17, 2025 17:04:11.202105045 CET53584008.8.8.8192.168.2.14
                                Feb 17, 2025 17:04:11.204067945 CET3871353192.168.2.148.8.8.8
                                Feb 17, 2025 17:04:11.210467100 CET53387138.8.8.8192.168.2.14
                                Feb 17, 2025 17:04:11.212996006 CET4212453192.168.2.148.8.8.8
                                Feb 17, 2025 17:04:11.219460011 CET53421248.8.8.8192.168.2.14
                                Feb 17, 2025 17:04:19.226186991 CET5470353192.168.2.148.8.8.8
                                Feb 17, 2025 17:04:19.232533932 CET53547038.8.8.8192.168.2.14
                                Feb 17, 2025 17:04:19.234905005 CET4280253192.168.2.148.8.8.8
                                Feb 17, 2025 17:04:19.241224051 CET53428028.8.8.8192.168.2.14
                                Feb 17, 2025 17:04:19.243767977 CET3732853192.168.2.148.8.8.8
                                Feb 17, 2025 17:04:19.250144958 CET53373288.8.8.8192.168.2.14
                                Feb 17, 2025 17:04:19.252650023 CET3803253192.168.2.148.8.8.8
                                Feb 17, 2025 17:04:19.258616924 CET53380328.8.8.8192.168.2.14
                                Feb 17, 2025 17:04:19.260597944 CET3511753192.168.2.148.8.8.8
                                Feb 17, 2025 17:04:19.266916037 CET53351178.8.8.8192.168.2.14
                                Feb 17, 2025 17:04:20.273397923 CET3406953192.168.2.148.8.8.8
                                Feb 17, 2025 17:04:20.279954910 CET53340698.8.8.8192.168.2.14
                                Feb 17, 2025 17:04:20.282032013 CET4710253192.168.2.148.8.8.8
                                Feb 17, 2025 17:04:20.289313078 CET53471028.8.8.8192.168.2.14
                                Feb 17, 2025 17:04:20.291816950 CET3383753192.168.2.148.8.8.8
                                Feb 17, 2025 17:04:20.298371077 CET53338378.8.8.8192.168.2.14
                                Feb 17, 2025 17:04:20.300729990 CET5064153192.168.2.148.8.8.8
                                Feb 17, 2025 17:04:20.309258938 CET53506418.8.8.8192.168.2.14
                                Feb 17, 2025 17:04:20.311578035 CET4878153192.168.2.148.8.8.8
                                Feb 17, 2025 17:04:20.317955971 CET53487818.8.8.8192.168.2.14
                                Feb 17, 2025 17:04:21.324513912 CET3779553192.168.2.148.8.8.8
                                Feb 17, 2025 17:04:21.331433058 CET53377958.8.8.8192.168.2.14
                                Feb 17, 2025 17:04:21.333899975 CET4195453192.168.2.148.8.8.8
                                Feb 17, 2025 17:04:21.340255976 CET53419548.8.8.8192.168.2.14
                                Feb 17, 2025 17:04:21.342442989 CET3480153192.168.2.148.8.8.8
                                Feb 17, 2025 17:04:21.348867893 CET53348018.8.8.8192.168.2.14
                                Feb 17, 2025 17:04:21.350899935 CET3898853192.168.2.148.8.8.8
                                Feb 17, 2025 17:04:21.358453035 CET53389888.8.8.8192.168.2.14
                                Feb 17, 2025 17:04:21.360570908 CET5634353192.168.2.148.8.8.8
                                Feb 17, 2025 17:04:21.366890907 CET53563438.8.8.8192.168.2.14
                                Feb 17, 2025 17:04:23.372143984 CET5012153192.168.2.148.8.8.8
                                Feb 17, 2025 17:04:23.378561020 CET53501218.8.8.8192.168.2.14
                                Feb 17, 2025 17:04:23.380142927 CET4375453192.168.2.148.8.8.8
                                Feb 17, 2025 17:04:23.386554003 CET53437548.8.8.8192.168.2.14
                                Feb 17, 2025 17:04:23.387943029 CET4899253192.168.2.148.8.8.8
                                Feb 17, 2025 17:04:23.394186974 CET53489928.8.8.8192.168.2.14
                                Feb 17, 2025 17:04:23.395620108 CET5356053192.168.2.148.8.8.8
                                Feb 17, 2025 17:04:23.401799917 CET53535608.8.8.8192.168.2.14
                                Feb 17, 2025 17:04:23.403114080 CET4617853192.168.2.148.8.8.8
                                Feb 17, 2025 17:04:23.409508944 CET53461788.8.8.8192.168.2.14
                                Feb 17, 2025 17:04:24.415307999 CET4416853192.168.2.148.8.8.8
                                Feb 17, 2025 17:04:24.421385050 CET53441688.8.8.8192.168.2.14
                                Feb 17, 2025 17:04:24.423244953 CET3786453192.168.2.148.8.8.8
                                Feb 17, 2025 17:04:24.429461002 CET53378648.8.8.8192.168.2.14
                                Feb 17, 2025 17:04:24.431535959 CET5495353192.168.2.148.8.8.8
                                Feb 17, 2025 17:04:24.437741995 CET53549538.8.8.8192.168.2.14
                                Feb 17, 2025 17:04:24.439909935 CET4880053192.168.2.148.8.8.8
                                Feb 17, 2025 17:04:24.446532965 CET53488008.8.8.8192.168.2.14
                                Feb 17, 2025 17:04:24.448349953 CET5547353192.168.2.148.8.8.8
                                Feb 17, 2025 17:04:24.454608917 CET53554738.8.8.8192.168.2.14
                                Feb 17, 2025 17:04:26.459965944 CET6041253192.168.2.148.8.8.8
                                Feb 17, 2025 17:04:26.470542908 CET53604128.8.8.8192.168.2.14
                                Feb 17, 2025 17:04:26.472410917 CET5356753192.168.2.148.8.8.8
                                Feb 17, 2025 17:04:26.478795052 CET53535678.8.8.8192.168.2.14
                                Feb 17, 2025 17:04:26.480664968 CET5208853192.168.2.148.8.8.8
                                Feb 17, 2025 17:04:26.486973047 CET53520888.8.8.8192.168.2.14
                                Feb 17, 2025 17:04:26.488746881 CET3505353192.168.2.148.8.8.8
                                Feb 17, 2025 17:04:26.498615980 CET53350538.8.8.8192.168.2.14
                                Feb 17, 2025 17:04:26.500119925 CET5756653192.168.2.148.8.8.8
                                Feb 17, 2025 17:04:26.509342909 CET53575668.8.8.8192.168.2.14
                                Feb 17, 2025 17:04:29.516037941 CET4650853192.168.2.148.8.8.8
                                Feb 17, 2025 17:04:29.522838116 CET53465088.8.8.8192.168.2.14
                                Feb 17, 2025 17:04:29.524733067 CET3892653192.168.2.148.8.8.8
                                Feb 17, 2025 17:04:29.531611919 CET53389268.8.8.8192.168.2.14
                                Feb 17, 2025 17:04:29.533566952 CET5291753192.168.2.148.8.8.8
                                Feb 17, 2025 17:04:29.540396929 CET53529178.8.8.8192.168.2.14
                                Feb 17, 2025 17:04:29.542151928 CET3379753192.168.2.148.8.8.8
                                Feb 17, 2025 17:04:29.548712969 CET53337978.8.8.8192.168.2.14
                                Feb 17, 2025 17:04:29.550362110 CET4342753192.168.2.148.8.8.8
                                Feb 17, 2025 17:04:29.557244062 CET53434278.8.8.8192.168.2.14
                                Feb 17, 2025 17:04:36.562568903 CET3521453192.168.2.148.8.8.8
                                Feb 17, 2025 17:04:36.571309090 CET53352148.8.8.8192.168.2.14
                                Feb 17, 2025 17:04:36.573216915 CET5077353192.168.2.148.8.8.8
                                Feb 17, 2025 17:04:36.581371069 CET53507738.8.8.8192.168.2.14
                                Feb 17, 2025 17:04:36.583237886 CET3297053192.168.2.148.8.8.8
                                Feb 17, 2025 17:04:36.589445114 CET53329708.8.8.8192.168.2.14
                                Feb 17, 2025 17:04:36.590953112 CET4512953192.168.2.148.8.8.8
                                Feb 17, 2025 17:04:36.597332001 CET53451298.8.8.8192.168.2.14
                                Feb 17, 2025 17:04:36.599121094 CET4210553192.168.2.148.8.8.8
                                Feb 17, 2025 17:04:36.605710983 CET53421058.8.8.8192.168.2.14
                                Feb 17, 2025 17:04:40.609882116 CET5257653192.168.2.148.8.8.8
                                Feb 17, 2025 17:04:40.616555929 CET53525768.8.8.8192.168.2.14
                                Feb 17, 2025 17:04:40.617752075 CET5218753192.168.2.148.8.8.8
                                Feb 17, 2025 17:04:40.624200106 CET53521878.8.8.8192.168.2.14
                                Feb 17, 2025 17:04:40.625695944 CET4102353192.168.2.148.8.8.8
                                Feb 17, 2025 17:04:40.633024931 CET53410238.8.8.8192.168.2.14
                                Feb 17, 2025 17:04:40.634677887 CET3411953192.168.2.148.8.8.8
                                Feb 17, 2025 17:04:40.641664982 CET53341198.8.8.8192.168.2.14
                                Feb 17, 2025 17:04:40.643474102 CET5655453192.168.2.148.8.8.8
                                Feb 17, 2025 17:04:40.650151968 CET53565548.8.8.8192.168.2.14
                                Feb 17, 2025 17:04:41.654629946 CET4415253192.168.2.148.8.8.8
                                Feb 17, 2025 17:04:41.661277056 CET53441528.8.8.8192.168.2.14
                                Feb 17, 2025 17:04:41.662844896 CET5532353192.168.2.148.8.8.8
                                Feb 17, 2025 17:04:41.669815063 CET53553238.8.8.8192.168.2.14
                                Feb 17, 2025 17:04:41.671689034 CET4170153192.168.2.148.8.8.8
                                Feb 17, 2025 17:04:41.678128958 CET53417018.8.8.8192.168.2.14
                                Feb 17, 2025 17:04:41.679480076 CET5109753192.168.2.148.8.8.8
                                Feb 17, 2025 17:04:41.686042070 CET53510978.8.8.8192.168.2.14
                                Feb 17, 2025 17:04:41.687603951 CET5005253192.168.2.148.8.8.8
                                Feb 17, 2025 17:04:41.694180012 CET53500528.8.8.8192.168.2.14
                                TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                Feb 17, 2025 17:02:36.399701118 CET192.168.2.148.8.8.80xbd8Standard query (0)zcjs888.cfdA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:02:36.407618999 CET192.168.2.148.8.8.80xbd8Standard query (0)zcjs888.cfdA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:02:36.416109085 CET192.168.2.148.8.8.80xbd8Standard query (0)zcjs888.cfdA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:02:36.424602985 CET192.168.2.148.8.8.80xbd8Standard query (0)zcjs888.cfdA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:02:36.436629057 CET192.168.2.148.8.8.80xbd8Standard query (0)zcjs888.cfdA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:02:45.446916103 CET192.168.2.148.8.8.80x5067Standard query (0)zcjs888.cfdA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:02:45.453780890 CET192.168.2.148.8.8.80x5067Standard query (0)zcjs888.cfdA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:02:45.460602045 CET192.168.2.148.8.8.80x5067Standard query (0)zcjs888.cfdA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:02:45.468040943 CET192.168.2.148.8.8.80x5067Standard query (0)zcjs888.cfdA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:02:45.474983931 CET192.168.2.148.8.8.80x5067Standard query (0)zcjs888.cfdA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:02:48.483789921 CET192.168.2.148.8.8.80xd247Standard query (0)zcjs888.cfdA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:02:48.491334915 CET192.168.2.148.8.8.80xd247Standard query (0)zcjs888.cfdA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:02:48.498516083 CET192.168.2.148.8.8.80xd247Standard query (0)zcjs888.cfdA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:02:48.505600929 CET192.168.2.148.8.8.80xd247Standard query (0)zcjs888.cfdA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:02:48.514379025 CET192.168.2.148.8.8.80xd247Standard query (0)zcjs888.cfdA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:02:58.551242113 CET192.168.2.148.8.8.80x1284Standard query (0)zcjs888.cfdA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:02:58.559528112 CET192.168.2.148.8.8.80x1284Standard query (0)zcjs888.cfdA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:02:58.571038008 CET192.168.2.148.8.8.80x1284Standard query (0)zcjs888.cfdA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:02:58.578923941 CET192.168.2.148.8.8.80x1284Standard query (0)zcjs888.cfdA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:02:58.608791113 CET192.168.2.148.8.8.80x1284Standard query (0)zcjs888.cfdA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:03:05.640125990 CET192.168.2.148.8.8.80x64b7Standard query (0)zcjs888.cfdA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:03:05.648547888 CET192.168.2.148.8.8.80x64b7Standard query (0)zcjs888.cfdA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:03:05.656308889 CET192.168.2.148.8.8.80x64b7Standard query (0)zcjs888.cfdA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:03:05.665420055 CET192.168.2.148.8.8.80x64b7Standard query (0)zcjs888.cfdA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:03:05.674460888 CET192.168.2.148.8.8.80x64b7Standard query (0)zcjs888.cfdA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:03:10.685039997 CET192.168.2.148.8.8.80xd15cStandard query (0)zcjs888.cfdA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:03:10.692457914 CET192.168.2.148.8.8.80xd15cStandard query (0)zcjs888.cfdA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:03:10.700074911 CET192.168.2.148.8.8.80xd15cStandard query (0)zcjs888.cfdA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:03:10.707581043 CET192.168.2.148.8.8.80xd15cStandard query (0)zcjs888.cfdA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:03:10.714639902 CET192.168.2.148.8.8.80xd15cStandard query (0)zcjs888.cfdA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:03:19.724951029 CET192.168.2.148.8.8.80xd811Standard query (0)zcjs888.cfdA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:03:19.733163118 CET192.168.2.148.8.8.80xd811Standard query (0)zcjs888.cfdA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:03:19.741102934 CET192.168.2.148.8.8.80xd811Standard query (0)zcjs888.cfdA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:03:19.748361111 CET192.168.2.148.8.8.80xd811Standard query (0)zcjs888.cfdA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:03:19.755924940 CET192.168.2.148.8.8.80xd811Standard query (0)zcjs888.cfdA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:03:26.768881083 CET192.168.2.148.8.8.80x3e1Standard query (0)zcjs888.cfdA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:03:26.779258966 CET192.168.2.148.8.8.80x3e1Standard query (0)zcjs888.cfdA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:03:26.789625883 CET192.168.2.148.8.8.80x3e1Standard query (0)zcjs888.cfdA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:03:26.799660921 CET192.168.2.148.8.8.80x3e1Standard query (0)zcjs888.cfdA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:03:26.807370901 CET192.168.2.148.8.8.80x3e1Standard query (0)zcjs888.cfdA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:03:36.819519043 CET192.168.2.148.8.8.80xb536Standard query (0)zcjs888.cfdA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:03:36.827759027 CET192.168.2.148.8.8.80xb536Standard query (0)zcjs888.cfdA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:03:36.835627079 CET192.168.2.148.8.8.80xb536Standard query (0)zcjs888.cfdA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:03:36.843197107 CET192.168.2.148.8.8.80xb536Standard query (0)zcjs888.cfdA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:03:36.850805998 CET192.168.2.148.8.8.80xb536Standard query (0)zcjs888.cfdA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:03:43.861517906 CET192.168.2.148.8.8.80xe735Standard query (0)zcjs888.cfdA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:03:43.870328903 CET192.168.2.148.8.8.80xe735Standard query (0)zcjs888.cfdA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:03:43.878696918 CET192.168.2.148.8.8.80xe735Standard query (0)zcjs888.cfdA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:03:43.886667013 CET192.168.2.148.8.8.80xe735Standard query (0)zcjs888.cfdA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:03:43.894819975 CET192.168.2.148.8.8.80xe735Standard query (0)zcjs888.cfdA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:03:45.906358004 CET192.168.2.148.8.8.80x69ceStandard query (0)zcjs888.cfdA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:03:45.914505959 CET192.168.2.148.8.8.80x69ceStandard query (0)zcjs888.cfdA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:03:45.922183037 CET192.168.2.148.8.8.80x69ceStandard query (0)zcjs888.cfdA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:03:45.929903984 CET192.168.2.148.8.8.80x69ceStandard query (0)zcjs888.cfdA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:03:45.938062906 CET192.168.2.148.8.8.80x69ceStandard query (0)zcjs888.cfdA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:03:49.949440956 CET192.168.2.148.8.8.80xe713Standard query (0)zcjs888.cfdA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:03:49.957597017 CET192.168.2.148.8.8.80xe713Standard query (0)zcjs888.cfdA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:03:49.965570927 CET192.168.2.148.8.8.80xe713Standard query (0)zcjs888.cfdA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:03:49.973768950 CET192.168.2.148.8.8.80xe713Standard query (0)zcjs888.cfdA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:03:49.982637882 CET192.168.2.148.8.8.80xe713Standard query (0)zcjs888.cfdA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:03:50.993782997 CET192.168.2.148.8.8.80x33d5Standard query (0)zcjs888.cfdA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:03:51.002053022 CET192.168.2.148.8.8.80x33d5Standard query (0)zcjs888.cfdA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:03:51.012522936 CET192.168.2.148.8.8.80x33d5Standard query (0)zcjs888.cfdA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:03:51.023267984 CET192.168.2.148.8.8.80x33d5Standard query (0)zcjs888.cfdA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:03:51.031157970 CET192.168.2.148.8.8.80x33d5Standard query (0)zcjs888.cfdA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:03:59.043638945 CET192.168.2.148.8.8.80xb3efStandard query (0)zcjs888.cfdA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:03:59.052397013 CET192.168.2.148.8.8.80xb3efStandard query (0)zcjs888.cfdA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:03:59.060830116 CET192.168.2.148.8.8.80xb3efStandard query (0)zcjs888.cfdA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:03:59.068784952 CET192.168.2.148.8.8.80xb3efStandard query (0)zcjs888.cfdA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:03:59.077083111 CET192.168.2.148.8.8.80xb3efStandard query (0)zcjs888.cfdA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:04:03.089149952 CET192.168.2.148.8.8.80xf244Standard query (0)zcjs888.cfdA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:04:03.097711086 CET192.168.2.148.8.8.80xf244Standard query (0)zcjs888.cfdA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:04:03.105405092 CET192.168.2.148.8.8.80xf244Standard query (0)zcjs888.cfdA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:04:03.113415003 CET192.168.2.148.8.8.80xf244Standard query (0)zcjs888.cfdA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:04:03.121396065 CET192.168.2.148.8.8.80xf244Standard query (0)zcjs888.cfdA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:04:10.132764101 CET192.168.2.148.8.8.80x5616Standard query (0)zcjs888.cfdA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:04:10.141031027 CET192.168.2.148.8.8.80x5616Standard query (0)zcjs888.cfdA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:04:10.149513960 CET192.168.2.148.8.8.80x5616Standard query (0)zcjs888.cfdA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:04:10.157660961 CET192.168.2.148.8.8.80x5616Standard query (0)zcjs888.cfdA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:04:10.165680885 CET192.168.2.148.8.8.80x5616Standard query (0)zcjs888.cfdA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:04:11.177341938 CET192.168.2.148.8.8.80x296dStandard query (0)zcjs888.cfdA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:04:11.186566114 CET192.168.2.148.8.8.80x296dStandard query (0)zcjs888.cfdA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:04:11.195813894 CET192.168.2.148.8.8.80x296dStandard query (0)zcjs888.cfdA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:04:11.204067945 CET192.168.2.148.8.8.80x296dStandard query (0)zcjs888.cfdA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:04:11.212996006 CET192.168.2.148.8.8.80x296dStandard query (0)zcjs888.cfdA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:04:19.226186991 CET192.168.2.148.8.8.80x1d26Standard query (0)zcjs888.cfdA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:04:19.234905005 CET192.168.2.148.8.8.80x1d26Standard query (0)zcjs888.cfdA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:04:19.243767977 CET192.168.2.148.8.8.80x1d26Standard query (0)zcjs888.cfdA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:04:19.252650023 CET192.168.2.148.8.8.80x1d26Standard query (0)zcjs888.cfdA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:04:19.260597944 CET192.168.2.148.8.8.80x1d26Standard query (0)zcjs888.cfdA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:04:20.273397923 CET192.168.2.148.8.8.80x486cStandard query (0)zcjs888.cfdA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:04:20.282032013 CET192.168.2.148.8.8.80x486cStandard query (0)zcjs888.cfdA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:04:20.291816950 CET192.168.2.148.8.8.80x486cStandard query (0)zcjs888.cfdA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:04:20.300729990 CET192.168.2.148.8.8.80x486cStandard query (0)zcjs888.cfdA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:04:20.311578035 CET192.168.2.148.8.8.80x486cStandard query (0)zcjs888.cfdA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:04:21.324513912 CET192.168.2.148.8.8.80xa656Standard query (0)zcjs888.cfdA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:04:21.333899975 CET192.168.2.148.8.8.80xa656Standard query (0)zcjs888.cfdA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:04:21.342442989 CET192.168.2.148.8.8.80xa656Standard query (0)zcjs888.cfdA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:04:21.350899935 CET192.168.2.148.8.8.80xa656Standard query (0)zcjs888.cfdA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:04:21.360570908 CET192.168.2.148.8.8.80xa656Standard query (0)zcjs888.cfdA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:04:23.372143984 CET192.168.2.148.8.8.80xbStandard query (0)zcjs888.cfdA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:04:23.380142927 CET192.168.2.148.8.8.80xbStandard query (0)zcjs888.cfdA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:04:23.387943029 CET192.168.2.148.8.8.80xbStandard query (0)zcjs888.cfdA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:04:23.395620108 CET192.168.2.148.8.8.80xbStandard query (0)zcjs888.cfdA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:04:23.403114080 CET192.168.2.148.8.8.80xbStandard query (0)zcjs888.cfdA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:04:24.415307999 CET192.168.2.148.8.8.80x64d8Standard query (0)zcjs888.cfdA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:04:24.423244953 CET192.168.2.148.8.8.80x64d8Standard query (0)zcjs888.cfdA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:04:24.431535959 CET192.168.2.148.8.8.80x64d8Standard query (0)zcjs888.cfdA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:04:24.439909935 CET192.168.2.148.8.8.80x64d8Standard query (0)zcjs888.cfdA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:04:24.448349953 CET192.168.2.148.8.8.80x64d8Standard query (0)zcjs888.cfdA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:04:26.459965944 CET192.168.2.148.8.8.80xbc74Standard query (0)zcjs888.cfdA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:04:26.472410917 CET192.168.2.148.8.8.80xbc74Standard query (0)zcjs888.cfdA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:04:26.480664968 CET192.168.2.148.8.8.80xbc74Standard query (0)zcjs888.cfdA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:04:26.488746881 CET192.168.2.148.8.8.80xbc74Standard query (0)zcjs888.cfdA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:04:26.500119925 CET192.168.2.148.8.8.80xbc74Standard query (0)zcjs888.cfdA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:04:29.516037941 CET192.168.2.148.8.8.80xf6c2Standard query (0)zcjs888.cfdA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:04:29.524733067 CET192.168.2.148.8.8.80xf6c2Standard query (0)zcjs888.cfdA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:04:29.533566952 CET192.168.2.148.8.8.80xf6c2Standard query (0)zcjs888.cfdA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:04:29.542151928 CET192.168.2.148.8.8.80xf6c2Standard query (0)zcjs888.cfdA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:04:29.550362110 CET192.168.2.148.8.8.80xf6c2Standard query (0)zcjs888.cfdA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:04:36.562568903 CET192.168.2.148.8.8.80xba2bStandard query (0)zcjs888.cfdA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:04:36.573216915 CET192.168.2.148.8.8.80xba2bStandard query (0)zcjs888.cfdA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:04:36.583237886 CET192.168.2.148.8.8.80xba2bStandard query (0)zcjs888.cfdA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:04:36.590953112 CET192.168.2.148.8.8.80xba2bStandard query (0)zcjs888.cfdA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:04:36.599121094 CET192.168.2.148.8.8.80xba2bStandard query (0)zcjs888.cfdA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:04:40.609882116 CET192.168.2.148.8.8.80xe070Standard query (0)zcjs888.cfdA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:04:40.617752075 CET192.168.2.148.8.8.80xe070Standard query (0)zcjs888.cfdA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:04:40.625695944 CET192.168.2.148.8.8.80xe070Standard query (0)zcjs888.cfdA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:04:40.634677887 CET192.168.2.148.8.8.80xe070Standard query (0)zcjs888.cfdA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:04:40.643474102 CET192.168.2.148.8.8.80xe070Standard query (0)zcjs888.cfdA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:04:41.654629946 CET192.168.2.148.8.8.80xcb07Standard query (0)zcjs888.cfdA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:04:41.662844896 CET192.168.2.148.8.8.80xcb07Standard query (0)zcjs888.cfdA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:04:41.671689034 CET192.168.2.148.8.8.80xcb07Standard query (0)zcjs888.cfdA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:04:41.679480076 CET192.168.2.148.8.8.80xcb07Standard query (0)zcjs888.cfdA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:04:41.687603951 CET192.168.2.148.8.8.80xcb07Standard query (0)zcjs888.cfdA (IP address)IN (0x0001)false
                                TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                Feb 17, 2025 17:02:36.406045914 CET8.8.8.8192.168.2.140xbd8Name error (3)zcjs888.cfdnonenoneA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:02:36.414427042 CET8.8.8.8192.168.2.140xbd8Name error (3)zcjs888.cfdnonenoneA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:02:36.423068047 CET8.8.8.8192.168.2.140xbd8Name error (3)zcjs888.cfdnonenoneA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:02:36.434861898 CET8.8.8.8192.168.2.140xbd8Name error (3)zcjs888.cfdnonenoneA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:02:36.442944050 CET8.8.8.8192.168.2.140xbd8Name error (3)zcjs888.cfdnonenoneA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:02:45.452995062 CET8.8.8.8192.168.2.140x5067Name error (3)zcjs888.cfdnonenoneA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:02:45.459867001 CET8.8.8.8192.168.2.140x5067Name error (3)zcjs888.cfdnonenoneA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:02:45.467355967 CET8.8.8.8192.168.2.140x5067Name error (3)zcjs888.cfdnonenoneA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:02:45.474294901 CET8.8.8.8192.168.2.140x5067Name error (3)zcjs888.cfdnonenoneA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:02:45.481266022 CET8.8.8.8192.168.2.140x5067Name error (3)zcjs888.cfdnonenoneA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:02:48.490113974 CET8.8.8.8192.168.2.140xd247Name error (3)zcjs888.cfdnonenoneA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:02:48.497596025 CET8.8.8.8192.168.2.140xd247Name error (3)zcjs888.cfdnonenoneA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:02:48.504740000 CET8.8.8.8192.168.2.140xd247Name error (3)zcjs888.cfdnonenoneA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:02:48.513457060 CET8.8.8.8192.168.2.140xd247Name error (3)zcjs888.cfdnonenoneA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:02:48.520745993 CET8.8.8.8192.168.2.140xd247Name error (3)zcjs888.cfdnonenoneA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:02:58.557899952 CET8.8.8.8192.168.2.140x1284Name error (3)zcjs888.cfdnonenoneA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:02:58.565853119 CET8.8.8.8192.168.2.140x1284Name error (3)zcjs888.cfdnonenoneA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:02:58.577399015 CET8.8.8.8192.168.2.140x1284Name error (3)zcjs888.cfdnonenoneA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:02:58.585410118 CET8.8.8.8192.168.2.140x1284Name error (3)zcjs888.cfdnonenoneA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:02:58.616641998 CET8.8.8.8192.168.2.140x1284Name error (3)zcjs888.cfdnonenoneA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:03:05.647265911 CET8.8.8.8192.168.2.140x64b7Name error (3)zcjs888.cfdnonenoneA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:03:05.655380964 CET8.8.8.8192.168.2.140x64b7Name error (3)zcjs888.cfdnonenoneA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:03:05.664475918 CET8.8.8.8192.168.2.140x64b7Name error (3)zcjs888.cfdnonenoneA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:03:05.673465014 CET8.8.8.8192.168.2.140x64b7Name error (3)zcjs888.cfdnonenoneA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:03:05.682539940 CET8.8.8.8192.168.2.140x64b7Name error (3)zcjs888.cfdnonenoneA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:03:10.691497087 CET8.8.8.8192.168.2.140xd15cName error (3)zcjs888.cfdnonenoneA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:03:10.699090004 CET8.8.8.8192.168.2.140xd15cName error (3)zcjs888.cfdnonenoneA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:03:10.706641912 CET8.8.8.8192.168.2.140xd15cName error (3)zcjs888.cfdnonenoneA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:03:10.713687897 CET8.8.8.8192.168.2.140xd15cName error (3)zcjs888.cfdnonenoneA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:03:10.720978975 CET8.8.8.8192.168.2.140xd15cName error (3)zcjs888.cfdnonenoneA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:03:19.739705086 CET8.8.8.8192.168.2.140xd811Name error (3)zcjs888.cfdnonenoneA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:03:19.747343063 CET8.8.8.8192.168.2.140xd811Name error (3)zcjs888.cfdnonenoneA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:03:19.754611969 CET8.8.8.8192.168.2.140xd811Name error (3)zcjs888.cfdnonenoneA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:03:19.764019012 CET8.8.8.8192.168.2.140xd811Name error (3)zcjs888.cfdnonenoneA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:03:26.777945042 CET8.8.8.8192.168.2.140x3e1Name error (3)zcjs888.cfdnonenoneA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:03:26.788014889 CET8.8.8.8192.168.2.140x3e1Name error (3)zcjs888.cfdnonenoneA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:03:26.798253059 CET8.8.8.8192.168.2.140x3e1Name error (3)zcjs888.cfdnonenoneA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:03:26.806013107 CET8.8.8.8192.168.2.140x3e1Name error (3)zcjs888.cfdnonenoneA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:03:26.814589024 CET8.8.8.8192.168.2.140x3e1Name error (3)zcjs888.cfdnonenoneA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:03:36.834363937 CET8.8.8.8192.168.2.140xb536Name error (3)zcjs888.cfdnonenoneA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:03:36.849618912 CET8.8.8.8192.168.2.140xb536Name error (3)zcjs888.cfdnonenoneA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:03:43.893287897 CET8.8.8.8192.168.2.140xe735Name error (3)zcjs888.cfdnonenoneA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:03:43.901366949 CET8.8.8.8192.168.2.140xe735Name error (3)zcjs888.cfdnonenoneA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:03:45.912796021 CET8.8.8.8192.168.2.140x69ceName error (3)zcjs888.cfdnonenoneA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:03:45.936414957 CET8.8.8.8192.168.2.140x69ceName error (3)zcjs888.cfdnonenoneA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:03:45.944430113 CET8.8.8.8192.168.2.140x69ceName error (3)zcjs888.cfdnonenoneA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:03:51.029664040 CET8.8.8.8192.168.2.140x33d5Name error (3)zcjs888.cfdnonenoneA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:03:59.067182064 CET8.8.8.8192.168.2.140xb3efName error (3)zcjs888.cfdnonenoneA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:04:03.127991915 CET8.8.8.8192.168.2.140xf244Name error (3)zcjs888.cfdnonenoneA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:04:11.210467100 CET8.8.8.8192.168.2.140x296dName error (3)zcjs888.cfdnonenoneA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:04:24.446532965 CET8.8.8.8192.168.2.140x64d8Name error (3)zcjs888.cfdnonenoneA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:04:26.470542908 CET8.8.8.8192.168.2.140xbc74Name error (3)zcjs888.cfdnonenoneA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:04:26.478795052 CET8.8.8.8192.168.2.140xbc74Name error (3)zcjs888.cfdnonenoneA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:04:29.531611919 CET8.8.8.8192.168.2.140xf6c2Name error (3)zcjs888.cfdnonenoneA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:04:40.633024931 CET8.8.8.8192.168.2.140xe070Name error (3)zcjs888.cfdnonenoneA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:04:40.650151968 CET8.8.8.8192.168.2.140xe070Name error (3)zcjs888.cfdnonenoneA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:04:41.661277056 CET8.8.8.8192.168.2.140xcb07Name error (3)zcjs888.cfdnonenoneA (IP address)IN (0x0001)false
                                Feb 17, 2025 17:04:41.669815063 CET8.8.8.8192.168.2.140xcb07Name error (3)zcjs888.cfdnonenoneA (IP address)IN (0x0001)false

                                System Behavior

                                Start time (UTC):16:02:35
                                Start date (UTC):17/02/2025
                                Path:/tmp/x86_64.elf
                                Arguments:/tmp/x86_64.elf
                                File size:55104 bytes
                                MD5 hash:7d8b5422bc2a2d6f5baa8955d03e098e

                                Start time (UTC):16:02:35
                                Start date (UTC):17/02/2025
                                Path:/tmp/x86_64.elf
                                Arguments:-
                                File size:55104 bytes
                                MD5 hash:7d8b5422bc2a2d6f5baa8955d03e098e

                                Start time (UTC):16:02:35
                                Start date (UTC):17/02/2025
                                Path:/tmp/x86_64.elf
                                Arguments:-
                                File size:55104 bytes
                                MD5 hash:7d8b5422bc2a2d6f5baa8955d03e098e

                                Start time (UTC):16:02:35
                                Start date (UTC):17/02/2025
                                Path:/tmp/x86_64.elf
                                Arguments:-
                                File size:55104 bytes
                                MD5 hash:7d8b5422bc2a2d6f5baa8955d03e098e

                                Start time (UTC):16:02:35
                                Start date (UTC):17/02/2025
                                Path:/tmp/x86_64.elf
                                Arguments:-
                                File size:55104 bytes
                                MD5 hash:7d8b5422bc2a2d6f5baa8955d03e098e